Vehicle communication data encryption method, decryption method, device and system

By using dual hash encryption and encryption reconstruction technology in vehicle communication data, the vehicle Ethernet communication data is encrypted, which solves the problem that plain text data is easily cracked and achieves high-security transmission of data.

CN120200857AActive Publication Date: 2025-06-24CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510677294.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-06-24
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

Vehicle Ethernet communication data is usually transmitted in plain text, which is easily cracked and leads to data leakage.

Method used

The dual hash encryption method is used to encrypt and reconstruct the vehicle communication data. By obtaining the first mask, message identifier and source payload of the message to be sent, the combined hash data is generated, and the source payload is encrypted and reconstructed, breaking its original rules and making the data become irregular data.

Benefits of technology

It improves the security of vehicle communication data, prevents data leakage and cracking, and enhances the security and anti-cracking capabilities of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200857A_ABST
    Figure CN120200857A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a vehicle communication data encryption method, decryption method, device and system, and relates to the technical field of vehicle data security. The method comprises the following steps: acquiring a first mask corresponding to a message to be sent; obtaining a first hash value according to the message identifier of the to-be-sent message and the first mask; obtaining a second hash value according to the source load of the message to be sent and the first mask; obtaining combined hash data according to the first hash value and the second hash value; encrypting and reconstructing the source load according to the combined hash data to obtain a reconstructed load; and updating and sending the to-be-sent message based on the reconstructed load. According to the method, dual hash encryption is adopted, data are reconstructed, plaintext data are changed into irregular data, the data security is improved, and the problem of data leakage caused by the fact that vehicle Ethernet communication data are easy to crack is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of vehicle data security. Specifically, it relates to a method and device for encrypting and decrypting vehicle communication data, and a system. Background Art

[0002] With the application of the SOMEIP communication middleware based on Ethernet technology in the automotive field, the requirements for network information security and communication data security are becoming more stringent. The Ethernet communication data in the vehicle is usually transmitted in plain text, which is easily cracked and leads to data leakage. Summary of the Invention

[0003] The purpose of the embodiments of this application is to provide a method and device for encrypting and decrypting vehicle communication data, and a system. Double hashing encryption is used, and the data is reconstructed to turn the plaintext data into irregular data, improving data security and solving the problem that the Ethernet communication data of the vehicle is easily cracked and leads to data leakage.

[0004] In a first aspect, this application provides a method for encrypting vehicle communication data, which is applied to a sending end. The method includes: obtaining a first mask corresponding to a message to be sent; obtaining a first hash value according to the message identifier of the message to be sent and the first mask; obtaining a second hash value according to the source payload of the message to be sent and the first mask; obtaining combined hash data according to the first hash value and the second hash value; encrypting and reconstructing the source payload according to the combined hash data to obtain a reconstructed payload; updating the message to be sent based on the reconstructed payload and sending it.

[0005] In the technical solution of the embodiments of this application, double hashing encryption is used. The message identifier and the source payload are respectively subjected to hashing operations with the first mask. The hash values obtained from the two hashing calculations are respectively screened, and then the screening results are combined. The combined result is used to encrypt and reconstruct the source payload data, breaking the original rule of the source payload data, so that the plaintext data becomes irregular data through complex reconstruction rules, improving security.

[0006] In some embodiments, obtaining combined hash data based on a first hash value and a second hash value includes: respectively reordering the first hash value and the second hash value to obtain a reordered first hash value and a reordered second hash value; respectively screening the reordered first hash value and the reordered second hash value to obtain first verification data and second verification data; recombining the first verification data and the second verification data to generate combined hash data. By respectively sorting and then screening the first hash value and the second hash value, and then recombining the screening results, the obtained combined hash data is irregular data. For an attacker, it is impossible to know the original first hash value and second hash value through the combined hash data, ensuring that the reconstructed payload reconstructed through the combined hash data is also irregular data.

[0007] In some embodiments, respectively reordering the first hash value and the second hash value to obtain a reordered first hash value and a reordered second hash value includes: randomly generating a relatively prime number corresponding to the number of digits of the first hash value or the second hash value; using the relatively prime number to establish a mapping relationship table from the current sorting of the numerical values of each digit of the hash value to the target sorting; respectively reordering the first hash value and the second hash value based on the mapping relationship table to obtain a reordered first hash value and a reordered second hash value; repeating the above steps to reorder the second hash value to obtain a reordered second hash value. Using the mapping relationship table to respectively reorder the first hash value and the second hash value, disrupting the original order, enhances the irregularity and randomness of the reordered first hash value and the reordered second hash value.

[0008] In some embodiments, using the relatively prime number to establish a mapping relationship table from the current sorting of the numerical values of each digit of the hash value to the target sorting includes: generating a mapping relationship table based on a derivation formula, and the derivation formula is expressed as: , and ; where represents the position subscript corresponding to the target sorting, represents the position subscript corresponding to the current sorting, takes values from 0 to , represents the number of digits of the first hash value, is 's relatively prime number, and % represents the modulo operation. Generating a mapping relationship table using the derivation formula maps the original position of the hash value to a new position according to the mapping table, thereby obtaining a new sorting, enhancing randomness.

[0009] In some embodiments, screening the rearranged first hash value and the rearranged second hash value respectively to obtain first verification data and second verification data, including: obtaining partial hash values from the rearranged first hash value based on a preset first screening rule as the first verification data; obtaining partial hash values from the rearranged second hash value by using a preset second screening rule as the second verification data. After screening, only using partial hash values as verification data to participate in the reconstruction of the source payload can reduce the possibility of the reconstructed source payload being cracked, with higher security. Moreover, the first verification data and the second verification data obtained through reordering and screening have higher randomness and irregularity.

[0010] In some embodiments, obtaining partial hash values from the rearranged first hash value based on a preset first screening rule as the first verification data, including: obtaining the even bits in the rearranged first hash value as the first verification data. Taking out the even bits enhances the degree of irregularity of the first verification data and avoids the attacker discovering the encryption rule.

[0011] In some embodiments, obtaining partial hash values from the rearranged second hash value by using a preset second screening rule as the second verification data, including: obtaining the odd bits in the rearranged second hash value as the second verification data. Taking out the odd bits makes a distinction from the first screening rule, increases the diversity of the screening rules, and further enhances the degree of irregularity of the encryption method.

[0012] In some embodiments, encrypting and reconstructing the source payload according to the combined hash data to obtain a reconstructed payload: inserting relatively prime numbers and the combined hash data into the source payload according to a preset reconstruction rule to obtain the reconstructed payload. Reconstructing the source payload to obtain irregular data makes it difficult to discover the encryption rule even for a plaintext message, enhancing data security.

[0013] In some embodiments, inserting the combined hash data into the source payload according to a preset reconstruction rule to obtain the reconstructed payload, including: inserting a relatively prime number and every 2 bytes of the combined hash data behind each byte of the source payload until all the relatively prime numbers and the combined hash data are completely inserted into the source payload; if the length of the source payload is less than half of the total length of the relatively prime numbers and the combined hash data, then splicing the remaining combined hash data at the end of the source payload. A specific reconstruction rule is given. Using this reconstruction rule, an irregular reconstructed payload can be obtained, turning the plaintext data into irregular data, making it impossible for the attacker to obtain valid data, greatly improving data security and reducing the risk of being cracked.

[0014] In some embodiments, obtaining the first mask corresponding to the message to be sent includes: obtaining the message attributes of the message to be sent, where the message attributes include source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol, source PORT, and destination PORT; and looking up the corresponding first mask from the local mapping table based on the message attributes, where the local mapping table includes its own mask and the mask of the communication counterparty. Each communication component only knows its own mask and the mask of the communication counterparty, which improves security and prevents mask leakage.

[0015] In a second aspect, the present application provides a method for decrypting vehicle communication data, which is applied to the receiving end corresponding to the sending end in the first aspect. The method includes: obtaining a second mask corresponding to the received encrypted message; obtaining a third hash value according to the message identifier of the encrypted message and the second mask; parsing the encrypted message according to a preset reconstruction rule to obtain two relatively prime numbers, first verification data, second verification data, and a source payload; obtaining a fourth hash value according to the source payload and the second mask; and verifying the encrypted message according to the relatively prime numbers, first verification data, second verification data, third hash value, and fourth hash value. Using the first verification data, second verification data, third hash value, and fourth hash value for verification ensures the reliability of the received message data and can effectively avoid being tampered with by an attacker.

[0016] In some embodiments, verifying the encrypted message according to the relatively prime numbers, first verification data, second verification data, third hash value, and fourth hash value includes: obtaining a rearranged third hash value corresponding to the third hash value and a rearranged fourth hash value corresponding to the fourth hash value based on the relatively prime numbers; performing identity verification based on the rearranged third hash value and the first verification data to obtain an identity verification result; and if the identity verification result is yes, performing data verification based on the rearranged fourth hash value and the second verification data. Using a dual verification method of identity verification and data verification, only the data that passes both verification methods is retained, fully ensuring the security of the received data.

[0017] In some embodiments, performing identity verification based on the rearranged third hash value and the first verification data includes: obtaining third verification data using a preset first screening rule; and if the first verification data is equal to the third verification data, the identity verification is successful. Ensuring the correct identities of both communication parties through identity verification.

[0018] In some embodiments, performing data verification based on the rearranged fourth hash value and the second verification data includes: obtaining fourth verification data using a preset second screening rule; and if the second verification data is equal to the fourth verification data, the data verification is successful. Ensuring that the received data is valid and not tampered with through data verification.

[0019] In a third aspect, the present application provides a vehicle communication data encryption device, which is applied to a sending end. The device includes: a first mask acquisition module, configured to acquire a first mask corresponding to a message to be sent; a first hash acquisition module, configured to obtain a first hash value according to a message identifier of the message to be sent and the first mask; a second hash acquisition module, configured to obtain a second hash value according to a source payload of the message to be sent and the first mask; a combination module, configured to obtain combined hash data according to the first hash value and the second hash value; a reconstruction module, configured to perform encrypted reconstruction on the source payload according to the combined hash data to obtain a reconstructed payload; and an update module, configured to update the message to be sent based on the reconstructed payload and send it. By using double hash encryption and data reconstruction, plaintext data is converted into irregular data, so that an attacker cannot obtain valid data, improving the security of data transmission and the risk of being cracked.

[0020] In a fourth aspect, the present application provides a vehicle communication data verification device, which is applied to a receiving end. The device includes: a second mask acquisition module, configured to acquire a second mask corresponding to an encrypted message received; a third hash acquisition module, configured to obtain a third hash value according to a message identifier of the encrypted message and the second mask; a message parsing module, configured to parse the encrypted message by using a preset reconstruction rule to obtain two relatively prime numbers, first verification data, second verification data, and a source payload; a fourth hash acquisition module, configured to obtain a fourth hash value according to the relatively prime numbers, the source payload, and the second mask; and a verification module, configured to verify the encrypted message according to the first verification data, the second verification data, the third hash value, and the fourth hash value. Through a double verification method of identity verification and data verification, the security and accuracy of both communication parties and the received data are ensured.

[0021] In a fifth aspect, the present application provides a vehicle communication data encryption system, which includes the sending end described in the first aspect and the receiving end described in the second aspect. At the sending end, data is encrypted by using double hash and data reconstruction methods, and at the receiving end, identity verification and data verification are performed on the received data. Only the data that passes the double verification can be retained. This system can achieve encrypted transmission of vehicle data, making the data not easily tampered with, cracked, or subject to replay attacks. The irregular data transmission and high-strength verification process make it impossible for attackers to start, thus having high security.

[0022] In a sixth aspect, the present application provides an electronic device, which includes a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the above-mentioned vehicle communication data encryption method.

[0023] Seventh aspect, the present application provides a readable storage medium storing computer program instructions, which, when read and executed by a processor, execute the above-mentioned vehicle communication data encryption method. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative efforts.

[0025] Figure 1 It is a flowchart of a vehicle communication data encryption method provided by an embodiment of the present application; Figure 2 It is a flowchart for obtaining the first mask provided by an embodiment of the present application; Figure 3 It is a flowchart for generating combined hash data provided by an embodiment of the present application; Figure 4 It is a flowchart for sorting hash values provided by an embodiment of the present application; Figure 5 It is a flowchart for screening provided by an embodiment of the present application; Figure 6 It is a specific implementation flowchart of the vehicle communication data encryption method provided by an embodiment of the present application; Figure 7 It is a flowchart of a vehicle communication data decryption method provided by an embodiment of the present application; Figure 8 It is a flowchart for verification provided by an embodiment of the present application; Figure 9 It is a specific implementation flowchart of the vehicle communication data decryption method provided by an embodiment of the present application; Figure 10 It is a structural block diagram of a vehicle communication data encryption device provided by an embodiment of the present application; Figure 11 It is a structural block diagram of a vehicle communication data decryption device provided by an embodiment of the present application; Figure 12 It is a specific implementation flowchart of a vehicle communication data encryption system provided by an embodiment of the present application.

[0026] ICON: 110 - First mask acquisition module; 120 - First hash acquisition module; 130 - Second hash acquisition module; 140 - Combination module; 150 - Reconstruction module; 160 - Update module; 210 - Second mask acquisition module; 220 - Third hash acquisition module; 230 - Message parsing module; 240 - Fourth hash acquisition module; 250 - Verification module. Detailed implementation

[0027] The following will describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application.

[0028] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0029] With the application of the SOMEIP (Scalable service - Oriented Middleware over IP) communication middleware, when transmitting vehicle Ethernet data, it is usually transmitted in plaintext. Even when using the E2E encryption (End - to - End Encryption) method, attackers can crack it according to the change rules of communication data, resulting in data leakage.

[0030] In view of the above - mentioned technical problems, the embodiments of the present application provide a vehicle communication data encryption method. This method uses double - hash encryption, uses masks to perform hash encryption on the message identifier and source payload data of the message respectively, then performs a series of operations such as sorting, screening, and recombination on the encryption results, and then uses the recombined hash data to reconstruct the source payload data. After the above process, the plaintext data is transformed into irregular data, making it impossible for attackers to crack according to the change rules of the data, ensuring data security.

[0031] Please refer to Figure 1 , Figure 1 which is a flowchart of a vehicle communication data encryption method provided by the embodiments of the present application. The method includes the following steps: S110: Obtain the first mask corresponding to the message to be sent; S120: Obtain the first hash value according to the message identifier of the message to be sent and the first mask; S130: Obtain the second hash value according to the source payload of the message to be sent and the first mask; S140: Obtain combined hash data according to the first hash value and the second hash value; S150: Encrypt and reconstruct the source payload according to the combined hash data to obtain a reconstructed payload; S160: Update the message to be sent based on the reconstructed payload and send it to the receiving end.

[0032] Exemplarily, the message to be sent can be a SOMEIP message. The message structure of the SOMEIP message includes a message identifier and a source payload. Hash encryption is performed on the message identifier and the source payload respectively to achieve double hash encryption of the SOMEIP message, which increases the verification difficulty for attackers. Here, the hash algorithm can be, for example, the SHA-256 hash algorithm, which has not been cracked, enhancing the data's anti-tampering and anti-cracking capabilities, greatly improving data security and reducing the risk of being cracked. Performing a hash operation on the first mask and the message identifier can be used to verify the identities of both communication parties later; performing a hash operation on the first mask and the source payload can be used to verify the validity of the data later.

[0033] Screen and combine the double hash encryption results, and reorganize the source payload according to the reconstruction rules for the combined results to achieve the reconstruction of the source payload data. The new source payload obtained is obtained by scrambling the source payload data and converting it into unstructured data compared with the original source payload. Using double hash encryption and data reconstruction increases the degree of unstructuredness of the valid data. Even if the data is intercepted and leaked, attackers cannot deduce the valid data from the unstructured data, increasing the difficulty of cracking the data, thereby realizing the secure transmission of vehicle SOMEIP Ethernet data.

[0034] The message identifier includes a Service ID, a Method ID, and a Session ID. Among them, the Session ID is used to distinguish different sessions. Therefore, during the communication process, the Session ID is constantly changing. Incorporating the Session ID into the hash operation avoids the possibility of data replay attacks.

[0035] Please refer to Figure 2 , Figure 2 For the flowchart of obtaining the first mask. In some embodiments, obtaining the first mask corresponding to the message to be sent includes: S111: Obtain the message attributes of the message to be sent. The message attributes include the source IP, source MAC (the physical address of the network card at the sending end), destination IP, destination MAC (the physical address of the network card at the receiving end), VLAN (Virtual Local Area Network) ID, transport protocol (UDP / TCP), source PORT (port), and destination PORT; S112: Look up the corresponding first mask in the local mapping table based on the message attributes. The local mapping table includes its own mask and the communication partner's mask.

[0036] The vehicle manufacturer configures and manages the mask according to the message attributes in Ethernet communication: For mask generation, the vehicle manufacturer can generate random and different masks of the same length for each communication component. The longer the mask length, the better the encryption effect. In addition, the mask can be updated regularly to prevent leakage and tampering.

[0037] For mask distribution, the vehicle manufacturer strictly encrypts and distributes the mask to the Ethernet communication components to ensure that only the two communication components know their own masks and the communication partner's masks. For example, when A communicates with B, for A, A needs to know the mask sent by A to B and also the mask replied by B to A; similarly, for B, B needs to know the mask sent by B to A and also the mask replied by A to B. Therefore, the first mask refers to the sender's own mask. When the message to be sent is sent to different receivers, the first masks obtained through the mapping table are also different.

[0038] For the mapping table, it is locally managed at the sender or receiver to establish the mapping relationship between the message attributes and the mask. When sending and receiving SOMEIP messages, it is necessary to find the mask corresponding to the message in the mapping table to perform subsequent data construction and verification, which initially ensures the security of the data.

[0039] Please refer to Figure 3 , Figure 3 as the flowchart for generating the combined hash data. In some embodiments, obtaining the combined hash data based on the first hash value and the second hash value includes: S141: Reorder the first hash value and the second hash value respectively to obtain the reordered first hash value and the reordered second hash value; S142: Screen the reordered first hash value and the reordered second hash value respectively to obtain the first verification data and the second verification data; S143: Recombine the first verification data and the second verification data to generate the combined hash data.

[0040] By sorting and then screening the first hash value and the second hash value respectively, only a part of the values are selected as the first verification data and the second verification data respectively. After sorting and screening, it makes it impossible for the attacker to obtain the original first hash value and the second hash value based on the first verification data and the second verification data, which has high security. In addition, only a part of the values are selected as the first verification data and the second verification data respectively, and are subsequently used for encrypting and reconstructing the payload, which can control the length of the reconstructed payload and avoid the reconstructed payload from being too long.

[0041] Sorting refers to rearranging the positions of hash values (including the first hash value and the second hash value) so that the position of each hash value changes, and each hash value (except the first one) cannot return to its original position. In this way, the rearranged first hash value and the rearranged second hash value obtained after rearrangement are irregular. The first verification data and the second verification data obtained after screening are more random, further enhancing the security.

[0042] Regarding the combination method of recombining the first verification data and the second verification data, no restrictions are imposed here. For example, the first verification data and the second verification data can be concatenated, interspersed, or rearranged, etc., and can be customized according to needs. The more complex the rule, the less regular the obtained data, and the lower the possibility of the reconstructed data being cracked, and the higher the security.

[0043] Please refer to Figure 4 , Figure 4 For the flowchart of sorting the hash values, in some embodiments, the first hash value and the second hash value are respectively rearranged to obtain the rearranged first hash value and the rearranged second hash value, including: S144: Randomly generate a relatively prime number corresponding to the number of digits of the first hash value; S145: Use the relatively prime number to establish a mapping relationship table from the current sorting of the numerical values of each digit of the hash value to the target sorting; S146: Based on the mapping relationship table, rearrange the first hash value to obtain the rearranged first hash value; S147: Repeat the above steps to rearrange the second hash value to obtain the rearranged second hash value.

[0044] The relatively prime number means that the generated random number and the number of digits of the first hash value or the second hash value are relatively prime (the common factor is only 1), and there are at least two relatively prime numbers, which are two pairs here. The first pair is the generated random number and the number of digits of the first hash value, and the second pair is another generated random number and the number of digits of the second hash value. The mapping relationship table means that a new position is obtained based on the mapping relationship for the current position. The mapping relationship table established by using the relatively prime number enables each numerical value of the hash value to obtain a new position ( i except when the value of 0 is 0), so that the numerical values of each digit of the first hash value and the second hash value can be rearranged to obtain the rearranged first hash value and the rearranged second hash value respectively.

[0045] The mapping relationship table can be used to rearrange the first hash value (the process of rearranging the second hash value is the same as that of the first hash value and will not be elaborated here), completely disrupting the order of the original first hash value and the second hash value, enhancing the randomness of the rearranged first hash value and the rearranged second hash value.

[0046] In some embodiments, a mapping relationship table for mapping the current sorting of each digit value of a hash value to a target sorting is established using relatively prime numbers, including: generating the mapping relationship table based on a derivation formula, which can be expressed as: , and ; Among them, represents the position subscript corresponding to the target sorting, represents the position subscript corresponding to the current sorting, takes values from 0 to , represents the number of digits of the first hash value, is a relatively prime number of , and % represents the modulo operation.

[0047] For example, if the first hash value has a total of 32 digits, then n = 32, k is a randomly generated relatively prime number, such as k = 31. When i takes the value of 1, i takes the value of 31, that is, the hash value with the position subscript of 1 (in the second position) corresponding to the current sorting is sorted to the position with the position subscript of 31 (the 32nd position), realizing the replacement and sorting of the positions of the first hash value. Similarly, a corresponding mapping relationship table is generated using relatively prime numbers according to the total number of digits of the second hash value for sorting, which will not be elaborated here.

[0048] Please refer to Figure 5 , Figure 5 for the screening flow chart. In some embodiments, the rearranged first hash value and the rearranged second hash value are respectively screened to obtain the first verification data and the second verification data, including: S148: Based on a preset first screening rule, obtain some hash values from the rearranged first hash value as the first verification data; S149: Use a preset second screening rule to obtain some hash values from the rearranged second hash value as the second verification data.

[0049] For the screening of the rearranged first hash value and the rearranged second hash value, different screening rules can be selected, that is, the first screening rule and the second screening rule are respectively used. Compared with using the same screening rule, the complexity of the rule can be increased, and it is more difficult for an attacker to crack.

[0050] In some embodiments, based on a preset first screening rule, obtaining some hash values from the rearranged first hash value as the first verification data includes: obtaining the even-numbered bits in the rearranged first hash value and using them as the first verification data.

[0051] The first verification data is to take part of the values from the rearranged first hash value (from the message identification hash operation) to participate in the reconstruction of the source payload data, and is used at the receiving end to authenticate the identities of both communication parties using the first verification data.

[0052] Even digits are used for screening, and only a part of the rearranged first hash value is used as the first verification data, increasing the contingency and security of the data in the encrypted message and preventing it from being cracked by attackers.

[0053] In some embodiments, using a preset second screening rule, part of the hash value is obtained from the rearranged second hash value as the second verification data, including: obtaining the odd digits in the rearranged second hash value and using them as the second verification data.

[0054] The second verification data is to take part of the values from the rearranged second hash value (from the source payload hash operation) to participate in the reconstruction of the source payload data, and is used at the receiving end to verify the data validity using the second verification data.

[0055] Odd digits are used for screening, and only a part of the rearranged second hash value is used as the first verification data, increasing the contingency and security of the data in the encrypted message and preventing it from being cracked by attackers.

[0056] For the specific first screening rule and second screening rule, in this embodiment, the even digits and odd digits are respectively extracted, and other screening rules can also be used, such as limiting the quantity and position of the screening, such as only selecting a certain part of the rearranged first hash value and rearranged second hash value, such as several numerical values at the front, middle, or back. Here, it can also be customized according to needs and is not limited in any way.

[0057] The first hash value and the second hash value are respectively rearranged and screened, and the obtained first verification data and second verification data are very different from the first hash value and the second hash value. Attackers cannot obtain the corresponding first hash value and second hash value based on the first verification data and the second verification data, which has strong randomness and irregularity.

[0058] In some embodiments, the source payload is encrypted and reconstructed according to the combined hash data to obtain a reconstructed payload, including: inserting the combined hash data into the source payload according to a preset reconstruction rule to obtain the reconstructed payload.

[0059] There are two reconstructions involved here. The first is to recombine the first verification data and the second verification data to obtain combined hash data, and the second is to use the combined hash data to reconstruct the source payload data to obtain a reconstructed payload. The source payload is reconstructed using the reconstruction rules and the combined hash data. After two reconstructions, the reconstructed payload is transformed into unstructured data. For an attacker, it is impossible to know the reconstruction rules, which increases the difficulty of cracking the reconstructed payload, thereby improving the security of the data.

[0060] For the reconstruction rules, they can be customized according to actual needs. The more complex the rules are, the lower the possibility of the data being cracked and the higher the security.

[0061] In some embodiments, inserting the relatively prime numbers and the combined hash data into the source payload according to the preset reconstruction rules to obtain the reconstructed payload includes: inserting every 2 bytes of the relatively prime numbers and the combined hash data behind each byte of the source payload until all the relatively prime numbers and the combined hash data are inserted into the source payload; if the length of the source payload is less than half of the total length of the relatively prime numbers and the combined hash data, then splice the remaining combined hash data at the end of the source payload.

[0062] Intersperse the relatively prime numbers and the combined hash data into the source payload. If the source payload is short, splice the remaining hash values at the end; if the source payload is long, no more values are inserted into the remaining source payload. Other interspersing methods can also be used, such as setting the interspersed positions and the number of intervals of the source payload, which are not limited here. The relatively prime numbers interspersed into the source payload here include two pairs, namely the two relatively prime numbers used to obtain the rearranged first hash value, and the two relatively prime numbers used to obtain the rearranged second hash value.

[0063] After the above hash encryption and data reconstruction processes, the valid data has been scrambled into unstructured data. Even if the data is intercepted and leaked, an attacker cannot deduce the valid data based on the existing data, improving the anti-cracking ability of the data and greatly enhancing the security of vehicle data transmission.

[0064] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in this application will be described clearly and completely below. In some embodiments, please refer to Figure 6 , Figure 6 which is the specific implementation flowchart of the vehicle communication data encryption method. The vehicle communication data encryption method includes: S201: According to the source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol (UDP / TCP), source PORT, and destination PORT of the message to be sent, search the local mapping table to determine whether the corresponding first mask mask1 is found; if not, abandon the sending and record the problem; S202: If the first mask mask1 is found, perform a hash operation on the Service ID, Method ID, and Session ID of the SOMEIP message to be sent and the first mask mask1 to obtain the first hash value HASH1. Use relatively prime numbers k1 and n1 to reorder the first hash value HASH1 and extract all the even-bit data of the rearranged first hash value to obtain the first verification data hash1; S203: Perform a hash operation on the first mask mask1 and the source payload data1 to obtain the second hash value HASH2. Use relatively prime numbers k2 and n2 to reorder the second hash value HASH2 and extract all the odd-bit data of the rearranged second hash value to obtain the second verification data hash2; S204: Recombine to obtain the combined verification data hash1 + hash2; Insert the relatively prime numbers k1, n1, k2, n2, and hash1 + hash2 into the source payload data1 according to the reconstruction rule to obtain the reconstructed payload data11; S205: Reload the reconstructed payload data11 into the SOMEIP message, update the SOMEIP message, and then send it to the receiving end.

[0065] At the receiving end, perform identity verification and data verification on the received encrypted message. Through double verification, it is ensured that the encrypted message has not been tampered with, and at the same time, attacker identity spoofing is avoided, greatly improving the security and confidentiality of vehicle data. Therefore, the embodiment of the present application also provides a method for decrypting vehicle communication data, which is applied to the above receiving end. Please refer to Figure 7 , Figure 7 which is the flowchart of the method for decrypting vehicle communication data. The method includes: S310: Obtain the second mask corresponding to the received encrypted message; S320: Obtain the third hash value according to the message identifier of the encrypted message and the second mask; S330: Parse the encrypted message according to the preset reconstruction rule to obtain relatively prime numbers, first verification data, second verification data, and source payload; S340: Obtain the fourth hash value according to the source payload and the second mask; S350: Verify the encrypted message according to the relatively prime numbers, first verification data, second verification data, third hash value, and fourth hash value.

[0066] At the receiving end, according to the message attributes of the received encrypted message, the corresponding second mask is found, and the encrypted message is parsed according to the reconstruction method of the sending end. Similarly, the message identifier and the source payload parsed are respectively subjected to hash encryption, and the encryption result and the two encryption results of the sending end carried in the encrypted message are used for verification to ensure the security and effectiveness of the data received at the receiving end.

[0067] Please refer to Figure 8 , Figure 8 For the verification flowchart. In some embodiments, the encrypted message is verified according to the relatively prime number, the first verification data, the second verification data, the third hash value, and the fourth hash value, including: S351: Obtain the rearranged third hash value corresponding to the third hash value and the rearranged fourth hash value corresponding to the fourth hash value based on the relatively prime number; S352: Perform identity verification based on the rearranged third hash value and the first verification data to obtain an identity verification result; S353: If the identity verification result is yes, perform data verification based on the rearranged fourth hash value and the second verification data.

[0068] The specific verification method includes identity authentication and data validity verification. Whether to receive or discard the data is determined by whether the mask can be found, whether the identity authentication passes, and whether the data verification passes.

[0069] For the second mask, the receiving end looks up the local mapping table according to the source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol (UDP / TCP), source PORT, and destination PORT of the encrypted message to obtain the mask of the sending end. If the encrypted message has not been tampered with, the second mask should be the same as the first mask.

[0070] According to the reconstruction rule of the sending end, the encrypted message is parsed to obtain the relatively prime number, the first verification data, the second verification data, and the source payload. If the encrypted message has not been tampered with, the first verification data, the second verification data, and the source payload should be the same as those of the receiving end. Therefore, the identity verification of both communication parties and the data validity verification can be performed through the hash values corresponding to the two hash encryptions. After two verifications, the validity of the received encrypted message is ensured.

[0071] In some embodiments, identity verification is performed based on the rearranged third hash value and the first verification data, including: obtaining third verification data by using a preset first screening rule; if the first verification data is equal to the third verification data, the identity verification is successful. The rearranged third hash value is screened by using the preset first screening rule to obtain the third verification data. Both the third verification data and the first verification data are obtained by performing a hash operation on a message identifier, and the message identifier can be used to represent the identities of both communication parties. Therefore, identity verification can be performed through the third verification data and the first verification data.

[0072] The adoption of the identity authentication mechanism for both communication parties improves the data security strength and greatly enhances the security and reliability of the data.

[0073] If the first screening rule is to obtain the even bits, then the even bits of the rearranged third hash value are obtained and used as the third verification data. Extracting the even bits of the rearranged third hash value as the third verification data, the third verification data obtained through rearrangement and screening has strong randomness, making it impossible for an attacker to obtain the third verification data and making the verification result of the identity verification more persuasive.

[0074] In some embodiments, data verification is performed based on the rearranged fourth hash value and the second verification data, including: obtaining fourth verification data by using a preset second screening rule; if the second verification data is equal to the fourth verification data, the data verification is successful. The rearranged fourth hash value is screened by using the preset second screening rule to obtain the fourth verification data. Both the fourth verification data and the second verification data are obtained by performing a hash operation on the payload data in the packet. Therefore, the rearranged fourth hash value (which needs to be screened to obtain the fourth verification data) and the second verification data can be used for data verification.

[0075] On the basis of successful identity verification, data verification is further performed. If the data verification is successful, it proves the security and effectiveness of the encrypted packet.

[0076] If the second screening rule is to obtain the odd bits, then the odd bits of the rearranged fourth hash value are obtained and used as the fourth verification data. Extracting the odd bits of the rearranged fourth hash value as the fourth verification data, the fourth verification data obtained through rearrangement and screening makes it impossible for an attacker to obtain the fourth verification data, making the verification result more persuasive during the data verification process.

[0077] Adopting a high-strength verification process for identity verification and data validity verification ensures the security and effectiveness of the received data.

[0078] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in this application will be described clearly and completely below. In some embodiments, please refer to Figure 9 , Figure 9It is a specific implementation flowchart of a vehicle communication data verification method. The vehicle communication data verification method includes: S401: After receiving SOMEIP data, first look up the local mapping table through the message attributes of the received Ethernet data - source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol (UDP / TCP), source PORT, and destination PORT to determine whether the second mask mask2 is found. If not found, discard the data and record the problem. S402: If the second mask mask2 is found, use the reconstruction rule to parse out the relatively prime numbers k1, n1, k2, n2, the first verification data hash1, the second verification data hash2, and the source payload data2 (if not tampered with, data2 is the same as the source payload data1); extract the Service ID, Method ID, Session ID and perform a hash operation with the second mask mask2 to obtain the third hash value HASH3. According to the reconstruction method, use the relatively prime numbers k1, n1 to reorder HASH3 to obtain the reordered third hash value and extract all the even bits of the reordered third hash value to obtain the third verification data hash3. S403: Identity authentication: Compare whether hash1 and hash3 are equal; if hash1 and hash3 are not equal, the identity authentication fails, directly discard the data, and end. S404: If hash1 = hash3, the identity verification of both communication parties is successful, and then data verification is performed. S405: Hash the second mask mask2 and the parsed data2 to obtain the fourth hash value HASH4. According to the reconstruction method, use the relatively prime numbers k2, n2 to reorder HASH4 to obtain the reordered fourth hash value and extract all the odd bits of the reordered fourth hash value to obtain the fourth verification data hash4. S406: Payload verification: Compare whether hash2 and hash4 are equal. If they are equal, it means the data is valid, the verification is successful, and the received data can be further processed; if not equal, the verification fails, the data may be tampered with during transmission, discard the data, and record the problem.

[0079] Please refer to Figure 10 , Figure 10 which is a structural block diagram of a vehicle communication data encryption device provided by this application. It should be understood that this device corresponds to the method embodiment executed in Figure 1 and can execute the steps involved in the foregoing method. The specific functions of this device can be referred to the description above. To avoid repetition, the detailed description is appropriately omitted here. This device includes but is not limited to: The first mask acquisition module 110 is used to acquire the first mask corresponding to the message to be sent. The first hash obtaining module 120 is configured to obtain a first hash value according to the message identifier of the message to be sent and the first mask; the second hash obtaining module 130 is configured to obtain a second hash value according to the source payload of the message to be sent and the first mask; The combining module 140 is configured to obtain combined hash data according to the first hash value and the second hash value; The reconstructing module 150 is configured to encrypt and reconstruct the source payload according to the combined hash data to obtain a reconstructed payload; The updating module 160 is configured to update the message to be sent based on the reconstructed payload and send it.

[0080] In the technical solution of the embodiment of the present application, dual hash encryption is adopted, and the hash encryption result is further rearranged, screened and recombined, and the data is reconstructed by using the recombination result, converting the plaintext data into irregular data, improving the anti-cracking ability of the data, making it impossible for attackers to obtain effective data, and improving the security of the data.

[0081] According to some embodiments of the present application, the first mask obtaining module 110 is specifically configured to obtain the message attributes of the message to be sent, and the message attributes include source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol, source PORT, destination PORT; and find the corresponding first mask from the local mapping table based on the message attributes, and the local mapping table includes its own mask and the mask of the communication partner.

[0082] According to some embodiments of the present application, the combining module 140 is specifically configured to: Reorder the first hash value and the second hash value respectively to obtain a reordered first hash value and a reordered second hash value; screen the reordered first hash value and the reordered second hash value respectively to obtain first verification data and second verification data; recombine the first verification data and the second verification data to generate combined hash data.

[0083] According to some embodiments of the present application, the specific reordering process is: Randomly generate a relatively prime number corresponding to the number of digits of the first hash value; use the relatively prime number to establish a mapping relationship table between the current sorting and the target sorting of the numerical values of each bit of the hash value; reorder the first hash value based on the mapping relationship table to obtain a reordered first hash value; repeat the above steps to reorder the second hash value to obtain a reordered second hash value.

[0084] According to some embodiments of the present application, using the relatively prime number to establish a mapping relationship table between the current sorting and the target sorting of the numerical values of each bit of the hash value includes: generating a mapping relationship table based on a derivation formula, and the derivation formula is expressed as: , and ; where Indicates the position subscript corresponding to the target sorting. Indicates the position subscript corresponding to the current sorting. takes values from 0 to , Indicates the number of bits of the first hash value. is a relatively prime number of , and % represents the modulo operation.

[0085] According to some embodiments of the present application, the specific screening process is as follows: Based on a preset first screening rule, obtain partial hash values from the rearranged first hash value as the first verification data; use a preset second screening rule to obtain partial hash values from the rearranged second hash value as the second verification data.

[0086] According to some embodiments of the present application, the specific first screening rule may be: obtain the even bits in the rearranged first hash value and use them as the first verification data.

[0087] According to some embodiments of the present application, the specific second screening rule may be: obtain the odd bits in the rearranged second hash value and use them as the second verification data.

[0088] According to some embodiments of the present application, the reconstruction module 150 is specifically configured to: insert the relatively prime number and the combined hash data into the source payload according to a preset reconstruction rule to obtain a reconstructed payload.

[0089] According to some embodiments of the present application, the specific reconstruction rule is: insert every 2 bytes of the relatively prime number and the combined hash data behind each byte of the source payload until all the combined hash data is inserted into the source payload; if the length of the source payload is less than half of the total length of the relatively prime number and the combined hash data, splice the remaining combined hash data at the end of the source payload.

[0090] The update module 160 is specifically configured to use the reconstructed payload as the source payload of the message to be sent, update the message to be sent, and send the updated message to be sent to the receiving end.

[0091] Please refer to Figure 11 , Figure 11 is a structural block diagram of a vehicle communication data verification device, which is applied to the receiving end corresponding to the sending end of the above embodiments. The device includes: A second mask acquisition module 210, configured to acquire a second mask corresponding to the received encrypted message; A third hash acquisition module 220, configured to obtain a third hash value according to the message identifier and the second mask of the encrypted message; The message parsing module 230 is configured to parse the encrypted message by using a preset reconstruction rule to obtain a relatively prime number, a first verification data, a second verification data, and a source payload; The fourth hash obtaining module 240 is configured to obtain a fourth hash value according to the source payload and a second mask; The verification module 250 is configured to verify the encrypted message according to the relatively prime number, the first verification data, the second verification data, the third hash value, and the fourth hash value.

[0092] According to some embodiments of the present application, the verification module 250 is specifically configured to: obtain a rearranged third hash value corresponding to the third hash value and a rearranged fourth hash value corresponding to the fourth hash value based on the relatively prime number; perform identity verification based on the rearranged third hash value and the first verification data to obtain an identity verification result; if the identity verification result is yes, perform data verification based on the rearranged fourth hash value and the second verification data.

[0093] In the technical solution of the embodiment of the present application, a corresponding mask is found by using the encrypted message, the encrypted message is parsed by using the reconstruction rule during encryption, and the parsing result is used for identity verification and data verification. Whether to receive or discard the data is determined by whether the mask can be found, whether the identity authentication is passed, and whether the data verification is passed. Through a high-strength verification process, the possibility of data being tampered with is avoided.

[0094] According to some embodiments of the present application, the identity verification specifically includes: obtaining a third verification data by using a preset first screening rule; if the first verification data is equal to the third verification data, the identity verification is successful.

[0095] According to some embodiments of the present application, the data verification specifically includes obtaining a fourth verification data by using a preset second screening rule; if the second verification data is equal to the fourth verification data, the data verification is successful.

[0096] Please refer to Figure 12 , Figure 12 FIG. is a specific implementation flowchart of a vehicle communication data encryption system. The present application further provides a vehicle communication data encryption system, which includes the above-mentioned sending end and receiving end. Payload encryption is performed at the sending end, and identity verification and payload verification are performed at the receiving end. Through irregular data transmission and a high-strength verification process, encrypted transmission of vehicle data is achieved, and the data is not easily tampered with and cracked, having high security.

[0097] The specific implementation process of the vehicle communication data encryption system is as follows: S501: Define the mask value length, generate independent and different masks according to the message attributes involved in the vehicle: source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol (UDP / TCP), source PORT, destination PORT, and perform mask management rules, secure distribution, regular updates, etc.; S502: Local management of message attributes for each communication component: source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol (UDP / TCP), source PORT, destination PORT, and mask mapping relationship table; S503: Define the data reconstruction method to prevent plaintext transmission. Interleave the relatively prime numbers and the encrypted hash value into 1 byte every 2 bytes after the source payload data, and scramble the source payload data; S504: Define the data encryption method, use the SHA-2 hash algorithm, and use the service ID, Method ID, Session ID, the first mask, and the source payload as the data to be encrypted; S505: Payload encryption process: The sending end looks up the first mask according to the message attributes to be sent: source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol (UDP / TCP), source PORT, destination PORT, hashes the service ID, Method ID, Session ID, and the first mask to get HASH1, uses the relatively prime numbers k1, n1 to reorder the first hash value HASH1 and extract all the even bits of the reordered first hash value to get hash1; then hashes the first mask and the payload data to get HASH2, uses the relatively prime numbers k2, n2 to reorder the second hash value HASH2 and extract all the odd bits of the reordered second hash value to get hash2; recombine and interleave the relatively prime numbers k1, n1, k2, n2, hash1 + hash2 into the corresponding positions of the payload data according to the data reconstruction rules to get a new payload data; regenerate the SOMEIP message and send it to the receiving end through the bus; S506: Identity verification process: The receiving end extracts message attributes from the data received from the bus: source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol (UDP / TCP), source PORT, destination PORT, and searches for the second mask in the local mapping table; if not found, it is directly discarded; if the second mask is found, the coprime numbers k1, n1, k2, n2, the first verification data hash1, the second verification data hash2, and the source payload data2 (if not tampered with, data2 is the same as the source payload data1) are parsed using the reconstruction rule; the second mask and the extracted service ID, Method ID, and Session ID are hashed to obtain HASH3, and HASH3 is reordered using the coprime numbers k1, n1 to obtain the reordered third hash value and all even bits of the reordered third hash value are extracted to obtain hash3; the consistency between hash3 and hash1 is compared, if they are different, the message is discarded; if they are equal, the payload verification continues; S507: Payload verification process: After successful identity authentication, the extracted payload data and the second mask are subjected to a hash operation to obtain HASH4; HASH4 is reordered using the coprime numbers k2, n2 to obtain the reordered fourth hash value and all odd bits of the reordered fourth hash value are extracted to obtain hash4, and the consistency between hash4 and hash2 is compared, if they are different, it is discarded; if they are the same, the message is received.

[0098] This application provides an electronic device, which includes a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the method in any of the foregoing optional implementation manners.

[0099] This application provides a readable storage medium, in which computer program instructions are stored. When the computer program instructions are read and run by a processor, the method in any of the foregoing optional implementation manners is executed.

[0100] Among them, the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0101] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the apparatus, method, and computer program product according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0102] In addition, each functional module in various embodiments of the present application can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0103] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0104] The above are only the embodiments of this application and are not used to limit the protection scope of this application. For those skilled in the art, various changes and modifications can be made to this application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0105] As mentioned above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0106] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A method for encrypting vehicle communication data, characterized in that, Applied to the sending end, the method includes: Obtain a first mask corresponding to the message to be sent; Obtain a first hash value based on the message identifier of the message to be sent and the first mask; Obtain a second hash value based on the source payload of the message to be sent and the first mask; Obtain combined hash data based on the first hash value and the second hash value; Encrypt and reconstruct the source payload according to the combined hash data to obtain a reconstructed payload; Update the message to be sent based on the reconstructed payload and send it.

2. The vehicle communication data encryption method according to claim 1, characterized in that The obtaining combined hash data based on the first hash value and the second hash value includes: Resort the first hash value and the second hash value respectively to obtain a rearranged first hash value and a rearranged second hash value; Screen the rearranged first hash value and the rearranged second hash value respectively to obtain first verification data and second verification data; Recombine the first verification data and the second verification data to generate the combined hash data.

3. The vehicle communication data encryption method according to claim 2, characterized in that, The resorting the first hash value and the second hash value respectively to obtain a rearranged first hash value and a rearranged second hash value includes: Randomly generate a relatively prime number corresponding to the number of digits of the first hash value; Use the relatively prime number to establish a mapping relationship table from the current sorting of the individual numerical values of the hash value to the target sorting; Resort the first hash value based on the mapping relationship table to obtain the rearranged first hash value; Repeat the above steps to resort the second hash value to obtain the rearranged second hash value.

4. The vehicle communication data encryption method according to claim 3, wherein, The using the relatively prime number to establish a mapping relationship table from the current sorting of the individual numerical values of the hash value to the target sorting includes: Generate the mapping relationship table based on a derivation formula, and the derivation formula is expressed as: and ; Among them, represents the position subscript corresponding to the target sorting, represents the position subscript corresponding to the current sorting, takes values from 0 to , represents the number of bits of the first hash value, is a relatively prime number of , and % represents the modulo operation.

5. The vehicle communication data encryption method according to claim 2, characterized in that, The screening the rearranged first hash value and the rearranged second hash value respectively to obtain first verification data and second verification data includes: Based on a preset first screening rule, obtain partial hash values from the rearranged first hash value as the first verification data; Use a preset second screening rule to obtain partial hash values from the rearranged second hash value as the second verification data.

6. The vehicle communication data encryption method according to claim 5, characterized in that, The obtaining partial hash values from the rearranged first hash value based on a preset first screening rule as the first verification data includes: Obtain the even digits in the rearranged first hash value and use them as the first verification data.

7. The vehicle communication data encryption method according to claim 5, wherein The using a preset second screening rule to obtain partial hash values from the rearranged second hash value as the second verification data includes: Obtain the odd digits in the rearranged second hash value and use them as the second verification data.

8. The vehicle communication data encryption method according to claim 3, wherein The encrypting and reconstructing the source payload according to the combined hash data to obtain a reconstructed payload includes: Insert the relatively prime number and the combined hash data into the source payload according to a preset reconstruction rule to obtain the reconstructed payload.

9. The vehicle communication data encryption method according to claim 8, wherein The inserting the relatively prime number and the combined hash data into the source payload according to a preset reconstruction rule to obtain the reconstructed payload includes: Insert every two bytes of the relatively prime numbers and the combined hash data after each byte of the source payload until all the relatively prime numbers and combined hash data are inserted into the source payload; if the length of the source payload is less than half of the total length of the relatively prime numbers and combined hash data, splice the remaining combined hash data at the end of the source payload.

10. The vehicle communication data encryption method according to claim 1, wherein The obtaining of the first mask corresponding to the message to be sent includes: Obtain the message attributes of the message to be sent, where the message attributes include source IP, source MAC, destination IP, destination MAC, VLAN ID, transport protocol, source PORT, and destination PORT; Based on the message attributes, look up the corresponding first mask in the local mapping table, where the local mapping table includes its own mask and the mask of the communication partner.

11. A method for decrypting vehicle communication data, characterized in that, Applied to the receiving end corresponding to the sending end according to any one of claims 1-10, the method includes: Obtain the second mask corresponding to the received encrypted message; Obtain the third hash value according to the message identifier of the encrypted message and the second mask; Parse the encrypted message according to a preset reconstruction rule to obtain relatively prime numbers, first verification data, second verification data, and a source payload; Obtain the fourth hash value according to the source payload and the second mask; Verify the encrypted message according to the relatively prime numbers, first verification data, second verification data, third hash value, and fourth hash value.

12. The vehicle communication data decryption method according to claim 11, wherein The verifying the encrypted message according to the relatively prime numbers, first verification data, second verification data, third hash value, and fourth hash value includes: Based on the relatively prime numbers, obtain the rearranged third hash value corresponding to the third hash value, and the rearranged fourth hash value corresponding to the fourth hash value; Perform identity verification based on the rearranged third hash value and the first verification data to obtain an identity verification result; If the identity verification result is yes, perform data verification based on the rearranged fourth hash value and the second verification data.

13. The vehicle communication data decryption method according to claim 12, characterized in that, The performing identity verification based on the rearranged third hash value and the first verification data includes: Obtain the third verification data using a preset first screening rule; If the first verification data is equal to the third verification data, the identity verification is successful.

14. The vehicle communication data decryption method according to claim 12, characterized in that, The performing data verification based on the rearranged fourth hash value and the second verification data includes: Obtain the fourth verification data using a preset second screening rule; If the second verification data is equal to the fourth verification data, the data verification is successful.

15. A vehicle communication data encryption device, characterized in that, Applied to a sending end, the device includes: A first mask obtaining module, configured to obtain a first mask corresponding to a message to be sent; A first hash obtaining module, configured to obtain a first hash value according to the message identifier of the message to be sent and the first mask; A second hash obtaining module, configured to obtain a second hash value according to the source payload of the message to be sent and the first mask; A combining module, configured to obtain combined hash data according to the first hash value and the second hash value; A reconstruction module, configured to perform encrypted reconstruction on the source payload according to the combined hash data to obtain a reconstructed payload; An updating module, configured to update the message to be sent based on the reconstructed payload and send it.

16. A vehicle communication data decryption device, characterized in that, Applied to the receiving end, the device includes: A second mask acquisition module, configured to acquire a second mask corresponding to the received encrypted message; A third hash acquisition module, configured to obtain a third hash value according to the message identifier of the encrypted message and the second mask; A message parsing module, configured to parse the encrypted message by using a preset reconstruction rule to obtain two relatively prime numbers, first verification data, second verification data, and a source payload; A fourth hash acquisition module, configured to obtain a fourth hash value according to the relatively prime numbers, the source payload, and the second mask; A verification module, configured to verify the encrypted message according to the first verification data, the second verification data, the third hash value, and the fourth hash value.

17. A vehicle communication data encryption system, characterized in that, The system includes the sending end according to any one of claims 1-10, and the receiving end according to any one of claims 11-14.

18. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the vehicle communication data encryption method according to any one of claims 1 to 10.

19. A readable storage medium, characterized in that, Computer program instructions are stored in the readable storage medium, and when the computer program instructions are read and run by a processor, the vehicle communication data encryption method according to any one of claims 1 to 10 is executed.

Citation Information

Patent Citations

  • Mobile phone game data encryption and decryption method and system

    CN108549818A

  • Data encryption storage method and device and server

    CN111917535A

  • Calibration system and method of kernel module, electronic equipment and readable medium

    CN119760737A

  • Data processing method and device for vehicle bus and vehicle

    CN120090848A