Interconnection method and electronic equipment
By utilizing broadcast messages and automatic identity authentication between the vehicle and the device in the trust ring, the problem of low interconnection efficiency between the vehicle and other devices is solved, and the effect of invisible ad hoc networking and simplified process is achieved.
Patent Information
- Application Number
- CN202311872208.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2043-12-29
AI Technical Summary
In the prior art, the efficiency of interconnecting vehicles with other electronic devices is low, and users need to manually input the connection code, resulting in cumbersome processes.
By using broadcast messages to realize automatic interconnection in the trust ring between the vehicle computer and the interconnected device, the device does not require the user to enter the connection code, and directly authenticates and automatically connects the vehicle computer registration information based on the vehicle computer registration information.
The interconnection process between car machines and other devices has been simplified, interconnection efficiency and user experience have been improved, and sensorless self-organizing network has been realized.
Smart Images

Figure CN120282115A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to an interconnection method and an electronic device. Background Art
[0002] With the development of technologies, in-vehicle infotainment (IVI) systems in vehicles are becoming more and more intelligent. To facilitate users' use, an electronic device (such as a mobile phone) can be interconnected with the IVI system, that is, a session connection is established to transmit service data with the IVI system, such as super desktop service data, so that the IVI system can display applications on the mobile phone. Among them, the general process of the first interconnection between the mobile phone and the IVI system is that the IVI system displays a connection code, and the IVI system triggers the mobile phone to display an input control for the user to input the connection code. Then, the mobile phone performs identity authentication with the IVI system based on the connection code. After the identity authentication is successful, the IVI system can be interconnected with the mobile phone.
[0003] However, when a user wants other devices he / she uses to be interconnected with the IVI system, the other devices still need to go through the above interconnection process with the IVI system, resulting in low interconnection efficiency, that is, low session connection establishment efficiency. Summary of the Invention
[0004] In view of this, this application provides an interconnection method and an electronic device, which realize automatic interconnection between the IVI system and the device, thereby improving the interconnection efficiency.
[0005] In a first aspect, this application provides an interconnection method applied to a first device. After the first device approaches the IVI system, the first device can receive a first broadcast message sent by the IVI system. The first broadcast message includes a first account logged in by a second device already interconnected with the IVI system, that is, includes the first account corresponding to the trust ring already joined by the IVI system. The first device logs in to the first account, the IVI system logs in to the second account, the first account is different from the second account, and the first device logs in to the first account.
[0006] In response to the first broadcast message, the first device displays a first interconnection success prompt message indicating that the first device is interconnected with the IVI system.
[0007] In this application, when the IVI system is interconnected with a second device logged in to the first account, it indicates that the IVI system has joined the trust ring corresponding to the first account. After the first device in the trust ring receives the first broadcast message sent by the IVI system, it can be automatically interconnected with the IVI system without any operation by the user on the first device (such as without inputting a connection code), realizing a seamless self-organizing network, simplifying the interconnection process between the IVI system and the first device, thereby improving the interconnection efficiency and the user experience.
[0008] In a possible design, the process of the first device displaying the first interconnection success prompt message in response to the first broadcast message may include:
[0009] First, the first device can perform identity authentication with the in-vehicle unit based on the in-vehicle unit registration information in response to the first broadcast message. Among them, the in-vehicle unit registration information is sent by the device cloud to the devices in the trust ring corresponding to the first account after the in-vehicle unit successfully registers with the device cloud; the devices in the trust ring corresponding to the first account include the first device.
[0010] After that, when the identity authentication is successful, the first device displays a first successful interconnection prompt message.
[0011] In this application, the first device can perform identity authentication with the in-vehicle unit based on the in-vehicle unit registration information synchronized by the device cloud, so that the in-vehicle unit can verify whether the first device is trustworthy. When the identity authentication is successful, it indicates that the first device is trustworthy, and then the in-vehicle unit and the first device can be automatically interconnected to ensure the security of the interconnection.
[0012] Optionally, the above in-vehicle unit registration information includes the public key of the in-vehicle unit and the authorization code of the in-vehicle unit. The in-vehicle unit registration information can be registered by the in-vehicle unit with the device cloud through the second device.
[0013] In a possible design, the process of performing identity authentication with the in-vehicle unit based on the in-vehicle unit registration information may include: First, the first device can encrypt the authorization code of the in-vehicle unit based on the public key of the in-vehicle unit to obtain the first encrypted data;
[0014] After that, the first device can send a first device identity authentication request carrying the first encrypted data to the in-vehicle unit, so that the in-vehicle unit can verify whether the identity of the first device is trustworthy by verifying the first encrypted data, and then send a corresponding response message (such as a first authentication success response message or a first authentication failure response message) to implement identity authentication and determine whether the first device is trustworthy.
[0015] In a possible design, the process of performing identity authentication based on the above first encrypted data may include:
[0016] First, the first device encrypts the first random number, the public key of the first device, and the authorization code based on the public key of the in-vehicle unit to obtain the first encrypted data. Among them, the first random number can be randomly generated by the first device.
[0017] After that, the first device can send the first encrypted data to the in-vehicle unit to trigger the in-vehicle unit to decrypt the first encrypted data using the private key of the in-vehicle unit to obtain the first random number, the public key of the first device, and the authorization code, so that the in-vehicle unit obtains the public key of the first device.
[0018] After that, the first device receives the second encrypted data sent by the in-vehicle unit. The second encrypted data is obtained by the in-vehicle unit encrypting the second random number with the public key of the first device when it determines that the authorization code is correct; among them, the second random number is randomly generated by the in-vehicle unit.
[0019] After that, the first device decrypts the second encrypted data based on the private key of the first device to obtain a second random number.
[0020] After that, the first device encrypts the first random number and the second random number on the first device to obtain a first session key; the first session key is used to encrypt the data sent from the first device to the in-vehicle unit.
[0021] After that, the first device sends the first session key to the in-vehicle unit, so that the in-vehicle unit sends a first authentication success response message or a first authentication failure response message by determining whether the first session key is the same as the second session key; the second session key is obtained by the in-vehicle unit encrypting the first random number and the second random number on the in-vehicle unit, and the encryption algorithms used to obtain the first session key and the second session key are the same.
[0022] Based on this, when the public key and authorization code of the in-vehicle unit on the first device are not registered by the in-vehicle unit with the device cloud, then the private key of the in-vehicle unit cannot decrypt the first encrypted data, and the authorization code is not registered by the in-vehicle unit either. Thus, the in-vehicle unit can determine that the first device is untrusted. Also, if the first random number on the in-vehicle unit is not sent by the first device, then the first session key and the second session key are different, resulting in a failure of identity authentication. Therefore, the verification of the identities of both parties can be achieved.
[0023] In a possible design, since the above first session key has a validity period, after the first device and the in-vehicle unit are successfully interconnected, after a first preset time, the first device performs a secondary identity authentication with the in-vehicle unit based on the first session key to update the first session key. Among them, the second session key will also be updated to ensure the security of the interconnection between the in-vehicle unit and the first device.
[0024] In a possible design, the above first broadcast message may further include a first identification code. After receiving the first broadcast message, the first device can determine whether the first identification code belongs to a first preset identification code. When the first identification code belongs to the first preset identification code, the first device can normally process the first broadcast message, interconnect with the in-vehicle unit, and display a first interconnection success prompt message. When the first identification code does not belong to the first preset identification code, the first device can not process the first broadcast message to avoid processing unnecessary first broadcast messages.
[0025] In a second aspect, the present application provides an interconnection method applied to a second device. The second device performs identity authentication with the in-vehicle unit. The second device logs in to a first account. When the identity authentication is successful, the second device receives the in-vehicle unit registration information sent by the in-vehicle unit. After that, the second device sends the in-vehicle unit registration information to the device cloud and displays a second interconnection success prompt message, where the second interconnection success prompt message indicates that the second device and the in-vehicle unit are successfully interconnected.
[0026] Among them, the in-vehicle unit registration information is used for the second device to synchronize the in-vehicle unit registration information to the devices in the trust ring corresponding to the first account through the device cloud, so that the devices in the trust ring can be interconnected with the in-vehicle unit when approaching the in-vehicle unit.
[0027] In this application, during the interconnection between the second device and the in-vehicle unit, the second device and the in-vehicle unit perform identity authentication. After the identity authentication is successful, the second device registers the in-vehicle unit registration information sent by the in-vehicle unit to the device cloud, so that the device cloud can synchronize the in-vehicle unit registration information to the devices in the trust ring corresponding to the first account, and further enables the devices in the trust ring to automatically interconnect with the in-vehicle unit using the in-vehicle unit registration information, simplifying the interconnection process between the in-vehicle unit and the devices in the trust ring.
[0028] In a possible design, the above-mentioned second device can perform identity authentication with the in-vehicle unit based on a connection code. The specific process may include: the second device receives a second broadcast message sent by the in-vehicle unit; among them, the second broadcast message includes in-vehicle unit information; the second device logs in to the first account, and the in-vehicle unit logs in to the second account, where the second account is different from the first account;
[0029] In response to the second broadcast message, the second device displays a first interface, and the first interface includes an input control;
[0030] The second device receives a first connection code input in the input control;
[0031] The second device performs identity authentication with the in-vehicle unit based on the first connection code.
[0032] In a possible design, the process of the above-mentioned second device sending the in-vehicle unit registration information to the device cloud and displaying a second interconnection success prompt message may include:
[0033] The second device sends a device registration request to the device cloud; among them, the device registration request includes the in-vehicle unit registration information; the in-vehicle unit registration information includes the public key of the in-vehicle unit and the authorization code of the in-vehicle unit; the second device receives a registration success response message sent by the device cloud. After that, in response to the registration success response message, the second device displays a second interconnection success prompt message. Based on this, proxy registration of the in-vehicle unit is achieved, and after the in-vehicle unit registration is successful, the second device is interconnected with the in-vehicle unit.
[0034] In a possible design, the device registration request includes the in-vehicle unit registration information and a first digital signature corresponding to the in-vehicle unit registration information; the above-mentioned registration success response message is sent after the first digital signature is successfully verified. Based on this, the registration security is ensured through signature verification, and the interconnection security can be guaranteed.
[0035] In a possible design, the process of the second device performing identity authentication with the in-vehicle unit based on the first connection code may include: The second device encrypts the first connection code based on the first algorithm to obtain a third session key; The second device sends the third session key to the in-vehicle unit; wherein, the in-vehicle unit registration information is sent by the in-vehicle unit when the third session key is the same as the fourth session key; The fourth session key is obtained by the in-vehicle unit encrypting the second connection code displayed on the in-vehicle unit based on the first algorithm.
[0036] In a possible design, the second device sending the third session key to the in-vehicle unit includes:
[0037] The second device sends an in-vehicle unit identity authentication request to the in-vehicle unit; wherein, the in-vehicle unit identity authentication request includes the third session key. Correspondingly, the second device receiving the in-vehicle unit registration information sent by the in-vehicle unit includes: The second device receives the second authentication success response message sent by the in-vehicle unit; In response to the second authentication success response message, the second device performs digital certificate verification with the in-vehicle unit; After the verification is successful, the second device receives the in-vehicle unit registration information sent by the in-vehicle unit. Based on this, the security of the interconnection is ensured, and the security of the registration is guaranteed.
[0038] In a possible design, the second broadcast message includes a second identification code. After receiving the second broadcast message, the second device can determine whether the second identification code belongs to the second preset identification code. When the second identification code belongs to the second preset identification code, the second device can normally process the second broadcast message and perform identity authentication with the in-vehicle unit. When the second identification code does not belong to the second preset identification code, the second device can not process the second broadcast message to avoid processing unnecessary second broadcast messages.
[0039] In a third aspect, the present application provides an interconnection method applied to an in-vehicle unit. The in-vehicle unit sends a first broadcast message; wherein, the first broadcast message includes the first account logged in by the second device that has been interconnected with the in-vehicle unit, and the in-vehicle unit logs in to a second account, and the second account is different from the first account;
[0040] When the first device logged in to the first account approaches the in-vehicle unit, the in-vehicle unit displays a third interconnection success prompt message, and the third interconnection success prompt message indicates that the in-vehicle unit and the first device are interconnected successfully. Wherein, when the first device approaches the in-vehicle unit, the first device can receive the first broadcast message for using the first broadcast message to interconnect with the in-vehicle unit.
[0041] In this application, after the in-vehicle device is interconnected with a second device logged in with a first account, the in-vehicle device can send a first broadcast message, which includes the first account. When a first device logged in with the first account approaches the in-vehicle device, it can detect the first broadcast message to be interconnected with the in-vehicle device. Without any operation by the user on the in-vehicle device and without the in-vehicle device displaying a connection code, a seamless self-organizing network is realized, simplifying the interconnection process between the in-vehicle device and the first device, thereby improving the interconnection efficiency and the user experience.
[0042] In a possible design, before the in-vehicle device is interconnected with the first device, the in-vehicle device can first be interconnected with a second device in the trust ring where the first device is located. The specific interconnection process can include:
[0043] The in-vehicle device can perform identity authentication with the second device.
[0044] In the case of successful identity authentication, the in-vehicle device can send a proxy registration request to the second device, and display a fourth successful interconnection prompt message, which indicates that the in-vehicle device and the second device are interconnected successfully;
[0045] The above proxy registration request includes in-vehicle device registration information, and the proxy registration request is used to register with the device cloud through the second device, so as to synchronize the in-vehicle device registration information to the devices in the trust ring corresponding to the first account through the device cloud.
[0046] In this application, during the interconnection between the in-vehicle device and the second device, the in-vehicle device and the second device perform identity authentication. After successful identity authentication, the in-vehicle device can send a proxy registration request to the second device to register the in-vehicle device registration information with the device cloud through the second device, so that the device cloud can synchronize the in-vehicle device registration information to the devices in the trust ring corresponding to the first account, and then the devices in the trust ring can automatically interconnect with the in-vehicle device using the in-vehicle device registration information, simplifying the interconnection process between the in-vehicle device and the devices in the trust ring.
[0047] Optionally, the above in-vehicle device registration information may include the public key of the in-vehicle device and the authorization code of the in-vehicle device, where the authorization code of the in-vehicle device is randomly generated by the in-vehicle device.
[0048] In a fourth aspect, this application provides an electronic device, which can be used as the first device and / or the second device. It includes a display screen, a memory, and one or more processors; the display screen, the memory, and the processors are coupled; the display screen is used to display the images generated by the processors, the memory is used to store computer program code, and the computer program code includes computer instructions; when the processors execute the computer instructions, the electronic device is enabled to execute the interconnection method as described in the first aspect, the second aspect, and any of their possible design manners above.
[0049] Fifth aspect, the present application provides a vehicle-mounted computer, which includes a display screen, a memory, and one or more processors; the display screen, the memory, and the processor are coupled; the display screen is configured to display an image generated by the processor, the memory is configured to store computer program code, and the computer program code includes computer instructions; when the processor executes the computer instructions, the vehicle-mounted computer is caused to execute the interconnection method as described in the third aspect above and any possible design manner thereof.
[0050] Sixth aspect, the present application provides a computer-readable storage medium, including computer instructions, when the computer instructions run on an electronic device, the electronic device is caused to execute the interconnection method as described in the first aspect, the second aspect above and any possible design manner thereof.
[0051] Seventh aspect, the present application provides a computer-readable storage medium, including computer instructions, when the computer instructions run on a vehicle-mounted computer, the vehicle-mounted computer is caused to execute the interconnection method as described in the third aspect above and any possible design manner thereof.
[0052] Eighth aspect, the present application provides a computer program product, when the computer program product runs on an electronic device, the electronic device is caused to execute the application startup method as described in the first aspect, the second aspect above and any possible design manner thereof.
[0053] Ninth aspect, the present application provides a computer program product, when the computer program product runs on a vehicle-mounted computer, the electronic device is caused to execute the application startup method as described in the third aspect above and any possible design manner thereof.
[0054] It should be understood that for the beneficial effects that can be achieved by the electronic device described in the fourth aspect, the vehicle-mounted computer described in the fifth aspect, the computer storage medium described in the sixth aspect and the seventh aspect, and the computer program product described in the eighth aspect and the ninth aspect above, reference can be made to the beneficial effects in the first aspect, the second aspect, the third aspect and any possible design manner thereof, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Figure 1 Schematic diagram of vehicle-mounted computer interconnection provided by an embodiment of the present application Figure 1 ;
[0056] Figure 2 Structural schematic diagram of an electronic device provided by an embodiment of the present application;
[0057] Figure 3 Software structure block diagram of an electronic device provided by an embodiment of the present application;
[0058] Figure 4Flow schematic of an interconnection method provided by an embodiment of this application Figure 1 ;
[0059] Figure 5 Flow schematic of an interconnection method provided by an embodiment of this application Figure 2 ;
[0060] Figure 6A Schematic of vehicle head unit interconnection provided by an embodiment of this application Figure 2 ;
[0061] Figure 6B Schematic of vehicle head unit interconnection provided by an embodiment of this application Figure 3 ;
[0062] Figure 7A Schematic of vehicle head unit interconnection provided by an embodiment of this application Figure 4 ;
[0063] Figure 7B Schematic of vehicle head unit interconnection provided by an embodiment of this application Figure 5 ;
[0064] Figure 7C Schematic diagram six of vehicle head unit interconnection provided by an embodiment of this application;
[0065] Figure 7D Schematic diagram seven of vehicle head unit interconnection provided by an embodiment of this application;
[0066] Figure 7E Schematic diagram eight of vehicle head unit interconnection provided by an embodiment of this application;
[0067] Figure 8A Schematic of vehicle head unit interconnection provided by an embodiment of this application Figure 9 ;
[0068] Figure 8B Schematic of vehicle head unit interconnection provided by an embodiment of this application Figure 10 ;
[0069] Figure 8C Schematic of vehicle head unit interconnection provided by an embodiment of this application Figure 10 One;
[0070] Figure 9 Flow schematic of an interconnection method provided by an embodiment of this application Figure 3 ;
[0071] Figure 10 Flow schematic of an interconnection method provided by an embodiment of this application Figure 4 ;
[0072] Figure 11Flow schematic diagram of an interconnection method provided by an embodiment of the present application Figure 5 ;
[0073] Figure 12 It is the sixth flow schematic diagram of an interconnection method provided by an embodiment of the present application. Detailed implementation manners
[0074] Hereinafter, the terms "first" and "second" are only used for descriptive purposes, and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of this embodiment, unless otherwise specified, the meaning of "a plurality" is two or more.
[0075] To more clearly describe the solution of the present application, some knowledge related to the embodiments of the present application will be introduced first below.
[0076] Trust ring: The same user account can be logged in on different electronic devices. When two or more electronic devices under the same user account trust each other, then the two or more electronic devices form a trust ring. For an electronic device (such as electronic device 1) in the trust ring, other electronic devices (such as electronic device 2) in the trust ring can be understood as trusted devices of this electronic device 1.
[0077] Public key infrastructure (PKI): It is a security architecture based on public key cryptography, used to ensure the validity of public keys and the authentication of entity identities.
[0078] Password authenticated key exchange (PAKE) protocol: It is a security protocol used for authentication operations such as identity authentication between two entities. The PAKE protocol allows two entities to use a connection code (i.e., PIN) to establish a shared key for secure authentication and data transmission in subsequent communications. Among them, in the embodiments of the present application, this shared key can also be referred to as a session key.
[0079] In some embodiments, in the scenario of the interconnection between an electronic device (such as a mobile phone) and a vehicle head unit, the process of the mobile phone and the vehicle head unit establishing a session connection for the first time may include: First, the vehicle head unit displays a connection code (i.e., a pin code). After that, the vehicle head unit triggers the mobile phone to display a relevant interface, which includes an input control for the user to input the connection code. Then, the mobile phone authenticates its identity with the vehicle head unit based on the connection code input by the user. When the connection code input by the user is consistent with the connection code displayed by the vehicle head unit, the mobile phone and the vehicle head unit establish a session connection, that is, they are interconnected. However, the average user may hold multiple electronic devices. When other devices with the same account as the mobile phone are interconnected with the vehicle head unit, the vehicle head unit needs to unbind the mobile phone and then establish a session connection with other devices according to the above process of establishing a session connection, resulting in a cumbersome process for different devices to be interconnected with the vehicle head unit and a low interconnection efficiency.
[0080] Therefore, in view of the above problems, the present application proposes an interconnection method. After an electronic device under a user account establishes a session connection with the vehicle head unit, the vehicle head unit can bind the user account. When other devices in the trust ring corresponding to the user account approach the vehicle head unit, they can be automatically interconnected with the vehicle head unit without the need to connect through a connection code, simplifying the process of other devices being interconnected with the vehicle head unit, thereby improving the interconnection efficiency of multiple devices with the vehicle head unit. For example, as Figure 1 shown, the user account is Zhang Xiao, and the devices in the trust ring corresponding to Zhang Xiao include Mobile Phone 1, Personal Computer (PC) 1, and Tablet Computer 1. After Mobile Phone 1 establishes a session connection with the vehicle head unit, the vehicle head unit binds to the account of Zhang Xiao. When PC 1 approaches the vehicle head unit, PC 1 can automatically establish a session connection with the vehicle head unit. Similarly, when Tablet Computer 1 approaches the vehicle head unit, Tablet Computer 1 can automatically establish a connection with the vehicle head unit, thus simplifying the process of PC 1 and Tablet Computer 1 establishing a session connection with the vehicle head unit and improving the interconnection efficiency of the vehicle head unit with multiple devices.
[0081] In addition, the vehicle head unit can be bound to multiple user accounts, so that it can be interconnected with the devices in the trust ring corresponding to each user account among multiple user accounts. As described above Figure 1 shown, the vehicle head unit can not only establish a session connection with the devices in the trust ring corresponding to Zhang Xiao, but also establish a session connection with the devices (such as Mobile Phone 2, PC 2, and Tablet Computer 2) in the trust ring corresponding to Li Xiao. It can be understood that although the vehicle head unit can be interconnected with the devices in the trust rings corresponding to different user accounts, at the same time, the vehicle head unit can only establish a session connection with the devices in the trust ring corresponding to a certain user account to perform service transmission with the devices in the trust ring corresponding to the user account.
[0082] Exemplarily, the electronic device in the embodiments of the present application may be a device capable of communicating with external devices, such as a mobile phone, a tablet computer, a wearable device (such as a smart watch), a personal digital assistant (PDA), a personal computer, an Internet of Things device, etc. The embodiments of the present application do not impose special restrictions on the specific form of the electronic device.
[0083] Figure 2 Fig. shows a schematic structural diagram of the electronic device 100.
[0084] The electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc.
[0085] It can be understood that the structure schematically shown in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than those shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0086] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.
[0087] Among them, the controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to the instruction operation code and timing signal to complete the control of fetching and executing instructions.
[0088] A memory can also be set in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can save the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can directly call it from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0089] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0090] It can be understood that the interface connection relationship between the modules schematically shown in the embodiments of the present invention is only for illustrative purposes and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.
[0091] The charging management module 140 is used to receive a charging input from a charger. The power management module 141 receives the input from the battery 142 and / or the charging management module 140 to supply power to the components in the electronic device 100.
[0092] The wireless communication function of the electronic device 100 can be implemented through antenna 1, antenna 2, the mobile communication module 150, the wireless communication module 160, the modulation and demodulation processor, and the baseband processor, etc.
[0093] Antenna 1 and Antenna 2 are used for transmitting and receiving electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, Antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0094] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The mobile communication module 150 can include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves through Antenna 1, and perform filtering, amplification and other processing on the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves through Antenna 1 and radiate it out. In some embodiments, at least some functional modules of the mobile communication module 150 can be disposed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 can be disposed in the same device.
[0095] The modulation and demodulation processor can include a modulator and a demodulator. In some embodiments, the modulation and demodulation processor can be an independent device. In some other embodiments, the modulation and demodulation processor can be independent of the processor 110 and be disposed in the same device as the mobile communication module 150 or other functional modules.
[0096] The wireless communication module 160 can provide solutions for wireless communications including wireless local area networks (WLAN) (such as Wi-Fi (wireless fidelity) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. applied to the electronic device 100. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves through Antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive the signals to be transmitted from the processor 110, perform frequency modulation and amplification on them, and convert them into electromagnetic waves through Antenna 2 and radiate them out.
[0097] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device 100 can communicate with the network and other devices through wireless communication technologies. The wireless communication technologies may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include Global Positioning System (GPS), Global Navigation Satellite System (GLONASS), BeiDou Navigation Satellite System (BDS), Quasi-Zenith Satellite System (QZSS), and / or Satellite Based Augmentation Systems (SBAS).
[0098] The electronic device 100 implements the display function through the GPU, the display screen 194, and the application processor, etc. The GPU is a microprocessor for image processing, and is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 may include one or more GPUs, which execute program instructions to generate or change the display information.
[0099] The display screen 194 is used to display images, videos, etc. In some embodiments, the electronic device 100 may include 1 or N display screens 194, where N is a positive integer greater than 1.
[0100] The electronic device 100 can implement the shooting function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, and the application processor, etc.
[0101] The ISP is used to process the data fed back by the camera 193.
[0102] The camera 193 is used to capture still images or videos. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0103] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100.
[0104] The internal memory 121 can be used to store computer-executable program code, and the executable program code includes instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, the image playback function, etc.). The data storage area can store the data created during the use of the electronic device 100 (such as audio data, phone book, etc.). In addition, the internal memory 121 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0105] The electronic device 100 can implement audio functions through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone interface 170D, and the application processor, etc. Such as music playback, recording, etc.
[0106] The sensor module 180 may include a pressure sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a proximity light sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, etc.
[0107] The keys 190 include a power-on key, a volume key, etc. The motor 191 can generate a vibration prompt. The indicator 192 can be an indicator light.
[0108] The SIM card interface 195 is used to connect the SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation from the electronic device 100. The electronic device 100 can support one or N SIM card interfaces, where N is a positive integer greater than 1.
[0109] The software systems of the electronic device 100 and the vehicle head unit can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservices architecture, or a cloud architecture. In the embodiments of the present invention, taking the Android system with a layered architecture as an example, the software structures of the electronic device 100 and the vehicle head unit are exemplarily described.
[0110] Figure 3 It is a software structure block diagram of the electronic device and the vehicle head unit provided by the embodiments of the present application. As Figure 3 shown, the electronic device may include applications, Magic Link interface, trusted ring basic sharing service, integrated interconnection middle platform, security basic middle platform, etc. Correspondingly, the vehicle head unit may also include applications, Magic Link interface, trusted ring basic sharing service, integrated interconnection middle platform, security basic middle platform, etc.
[0111] Among them, the applications in the electronic device may include applications such as smart travel and control center. The applications in the vehicle head unit may include applications such as mobile phone interconnection.
[0112] The above Magic Link interface may be a Magic Link toolkit (kit).
[0113] The trusted ring basic sharing service in the electronic device includes services such as screen collaboration service, keyboard and mouse service, and network sharing service. The trusted ring basic sharing service enables the electronic device to perform services such as screen collaboration, keyboard and mouse, and network sharing with devices (such as the vehicle head unit) in its trusted ring. Among them, the screen collaboration service may include the super desktop service.
[0114] The integrated interconnection middle platform can implement services such as access networking service, device management service, and data transmission service.
[0115] Among them, the access networking service is used to realize the interconnection between devices with non-Honor accounts and devices with Honor accounts.
[0116] The device management service is used to implement proxying devices with non-Honor accounts to register with the device cloud, so that devices with non-Honor accounts (such as the vehicle head unit) can join the trusted ring.
[0117] The data transmission service is used when transmitting service data between devices with non-Honor accounts and devices with Honor accounts. The device with the Honor account can save the service data to a specific directory in the device with the non-Honor account to achieve cross-package name transmission.
[0118] The security basic middle platform is used for identity authentication between devices.
[0119] In some embodiments, the above electronic device and the vehicle head unit can communicate to achieve interconnection.
[0120] Among them, the above application may belong to the application layer. The above Magic Link interface, trust ring basic sharing service, fusion interconnection middle platform, and security basic middle platform may belong to the application program framework layer.
[0121] It can be understood that Figure 4 the shown structure does not constitute a specific limitation on the electronic device or the in-vehicle unit. In some other embodiments of the present application, the structure may include more or fewer services or modules than those shown, and the present application does not make any limitations.
[0122] The present application provides an interconnection method. As Figure 4 shown, the process of this interconnection method may include Step 1 - Step 13. Among them, in Step 1, when the electronic device A approaches the in-vehicle unit, the in-vehicle unit responds to the operation 1 input by the user and displays the connection code 1. Among them, the operation 1 is used to trigger the in-vehicle unit to start interconnection with the electronic device and display the connection code.
[0123] In response to the above operation 1, the in-vehicle unit may execute Step 2: The in-vehicle unit sends a Bluetooth broadcast message 1, and the Bluetooth broadcast message 1 includes in-vehicle unit information.
[0124] After that, when the electronic device A detects the Bluetooth broadcast message 1, it may execute Step 3: Display an input control, and the input control is used to input the connection code.
[0125] After that, after the electronic device A obtains the connection code input by the user, it may execute Step 4: Based on the connection code input by the user, perform identity authentication with the in-vehicle unit.
[0126] After the identity authentication is successful, it indicates that the connection code input by the user is consistent with the connection code displayed by the in-vehicle unit, and the identities of the in-vehicle unit and the electronic device A are trustworthy. The in-vehicle unit may continue to execute Step 5: Send a proxy registration request to the electronic device A to register with the device cloud through the electronic device A. Among them, the proxy registration request includes in-vehicle unit registration information. The in-vehicle unit registration information may include the public key and authorization code (authcode) of the in-vehicle unit.
[0127] After the electronic device A receives the proxy registration request, in response to the proxy registration request, it may act as a proxy for the in-vehicle unit and register the in-vehicle unit with the device cloud, that is, the electronic device A may execute Step 6: Send the in-vehicle unit registration information to the device cloud.
[0128] After receiving the in-vehicle device registration information, the Device Cloud can execute Step 7: record the in-vehicle device registration information into the trust ring list corresponding to the Honor account A logged in on the electronic device A. Moreover, the Device Cloud can send a registration success response message to the electronic device A to notify the electronic device A that the in-vehicle device registration is successful. Optionally, the Device Cloud can send the registration success response message to each device (which may include the electronic device A) in the trust ring corresponding to the Honor account A, so that each device in the trust ring knows that a new device has been successfully registered.
[0129] After that, after receiving the registration success response message, the electronic device A can execute Step 8: in response to the registration success response message, send a registration success message to the in-vehicle device, and the registration success message includes the Honor account A.
[0130] After that, after receiving the registration success message, the in-vehicle device can execute Step 9: in response to the registration success message, establish a session connection with the electronic device A to realize the interconnection between the in-vehicle device and the electronic device A.
[0131] In addition, after recording the in-vehicle device registration information into the trust ring list corresponding to the Honor account A logged in on the electronic device A, the Device Cloud can execute Step 10: synchronize the in-vehicle device registration information to other devices in the trust ring corresponding to the Honor account A, that is, devices with the same account. Optionally, the Device Cloud can also synchronize it to the electronic device A.
[0132] After that, when other devices approach, other devices can execute Step 11: receive the ad-hoc network broadcast of the in-vehicle device, and the ad-hoc network broadcast carries the Honor account A.
[0133] After that, other devices can execute Step 12: based on the in-vehicle device registration information, perform the first ad-hoc network authentication with the in-vehicle device. When the first authentication is successful, other devices can be automatically interconnected with the in-vehicle device, improving the efficiency of establishing a session connection between multiple devices and the in-vehicle device.
[0134] After that, in order to maintain the validity of the authentication, after a period of time, other devices can execute Step 13: perform a secondary ad-hoc network authentication with the in-vehicle device to ensure the security of the session connection, thereby ensuring the security of the service transmission between the in-vehicle device and other devices.
[0135] The following takes the electronic device A including a mobile phone and other devices including a tablet computer as an example to introduce in detail the above Figure 4 process of the electronic device A in the trust ring corresponding to the Honor account A establishing a session connection with the in-vehicle device for the first time, and other devices in the trust ring automatically establishing a session connection with the in-vehicle device. Among them, the process of the electronic device A in the trust ring corresponding to the Honor account A establishing a session connection with the in-vehicle device for the first time is introduced through Figure 5 the corresponding relevant content, and the process of other devices in the trust ring automatically establishing a session connection with the in-vehicle device is described in the following textFigure 9 Introduce the corresponding relevant content.
[0136] Exemplarily, as Figure 5 shown, the interconnection method may include steps S301 - S334.
[0137] S301. The in - vehicle display interface 1, and this interface 1 includes a connection control.
[0138] S302. In response to a click operation on the connection control, the in - vehicle unit sends a Bluetooth broadcast message 1, and this Bluetooth broadcast message 1 includes vehicle model information and identification code 1.
[0139] Among them, the Bluetooth broadcast message 1 is used to trigger the mobile phone to establish a Bluetooth connection with the in - vehicle unit, and the in - vehicle unit and the mobile phone are interconnected through the Bluetooth connection.
[0140] S303. The in - vehicle display interface 2, and this interface 2 includes connection code 1.
[0141] Exemplarily, the in - vehicle unit receives a click operation input by the user on an in - vehicle application (such as a mobile phone interconnection application) on the in - vehicle unit. In response to this click operation, the mobile phone interconnection application is started, and the interface 1 as Figure 6A shown is displayed. This interface 1 includes a connection control. After that, the in - vehicle unit receives a click operation of the user on the connection control. In response to this click operation, the in - vehicle unit displays the interface 2 as Figure 6B shown. This interface 2 includes "1111", and this "1111" is the above - mentioned connection code 1 (or referred to as the second connection code). It should be understood that the process of displaying the connection code 1 introduced here is only an example, and this application does not limit the process of displaying the connection code 1. In other words, this application does not limit the trigger operation for the in - vehicle unit to display the connection code 1.
[0142] In some embodiments, the above - mentioned vehicle model information represents the vehicle model of the vehicle where the in - vehicle unit is located. This vehicle model information is only an example of the in - vehicle unit information. This in - vehicle unit information can also be other types of information, as long as it can represent the in - vehicle unit, and this application does not limit it.
[0143] In the embodiments of this application, when the user wants the in - vehicle unit to be interconnected with the mobile phone (or referred to as the second device), the user can bring the mobile phone close to the in - vehicle unit. When the mobile phone and the in - vehicle unit are interconnected for the first time, the in - vehicle unit responds to the relevant trigger operation (or referred to as the first operation) input by the user, and displays the connection code 1, so that the in - vehicle unit and the mobile phone can complete the authentication connection through the connection code 1, and realize the interconnection between the in - vehicle unit and the mobile phone. Among them, the mobile phone may have logged in to a Honor account (such as Honor account A), and the account logged in by the in - vehicle unit may be a third - party account, that is, not a Honor account.
[0144] The above S301 - S303 are the above - mentioned Figure 4A possible implementation of Step 1 and Step 2 in []. Next, the possible implementation of Step 3 in the above [] will be continued to be introduced in combination with S304 - S307. Figure 4 A possible implementation of Step 3 in [].
[0145] S304. The mobile phone receives the above Bluetooth broadcast message 1.
[0146] S305. The mobile phone determines whether the identification code 1 in the Bluetooth broadcast message 1 belongs to the preset identification code 1.
[0147] In the embodiment of the present application, when the above identification code 1 does not belong to the preset identification code 1, it indicates that the Bluetooth broadcast message 1 (or alternatively described as the second broadcast message) is not the broadcast message that the mobile phone needs to process. Then the mobile phone can execute S306.
[0148] When the above identification code 1 belongs to the preset identification code 1, it indicates that the Bluetooth broadcast message 1 is the broadcast message that the mobile phone needs to process. Then the mobile phone can execute S307.
[0149] In some embodiments, the mobile phone can set the preset identification code 1 (i.e., set the filter). The number of the preset identification code 1 (or referred to as the second preset identification code) is one or more. Then, the mobile phone can use the preset identification code 1 to filter the received Bluetooth broadcast messages, avoid processing unnecessary broadcast messages, reduce the waste of resources, and avoid processing Bluetooth broadcast messages with security risks to ensure the security of the mobile phone.
[0150] S306. The mobile phone filters out the above Bluetooth broadcast message 1.
[0151] Exemplarily, when the identification code 1 (or referred to as the second identification code) does not belong to the preset identification code 1, the mobile phone does not need to process the Bluetooth broadcast message 1 carrying the identification code 1, and the mobile phone can continue to detect Bluetooth broadcast messages.
[0152] In addition, optionally, when the identification code 1 does not belong to the preset identification code 1, the mobile phone may not establish a Bluetooth connection with the in - vehicle unit. Of course, it can also continue to establish a Bluetooth connection, and the present application does not limit it.
[0153] S307. In response to the above Bluetooth broadcast message 1, the mobile phone establishes a Bluetooth connection with the in - vehicle unit and displays Interface 3, which includes Input Control 1.
[0154] Among them, the Input Control 1 (or referred to as the input control) is used to input the connection code. Optionally, the Input Control 1 can be a control such as an input box that can input characters.
[0155] The Bluetooth connection is used for data transmission between the mobile phone and the in - vehicle unit to achieve the interconnection between the in - vehicle unit and the mobile phone. Optionally, the Bluetooth connection can be a BR connection.
[0156] The above interface 3 can be the interface of the intelligent travel APP on the mobile phone. Exemplarily, in response to the above Bluetooth broadcast message 1, the mobile phone establishes a Bluetooth connection with the in-vehicle unit. The mobile phone displays a connection interface ( Figure 7A as shown), and this connection interface may include an interconnection prompt message 20, a cancel control 21, and a confirmation control 22. Among them, the interconnection prompt message 20 is used to prompt whether to interconnect with the in-vehicle unit. The cancel control 21 is used to trigger the mobile phone to stop interconnecting with the in-vehicle unit (i.e., binding). The confirmation control 22 is used to trigger the mobile phone to continue interconnecting with the in-vehicle unit. Among them, the above Figure 7A shown XXX-X can be vehicle model information.
[0157] After that, after receiving the user's click operation on the confirmation control 21, the mobile phone, in response to the click operation on the confirmation control 21, displays an interface 3 (or referred to as the first interface) as Figure 7B shown, and this interface 3 includes an input box 23. Among them, the input box 23 can be the above input control 1.
[0158] In addition, when the user clicks the above cancel control 21, it indicates that the user does not want the mobile phone to interconnect with the in-vehicle unit. Then the mobile phone rejects the interconnection with the in-vehicle unit and sends an interconnection failure response message to the in-vehicle unit to notify the in-vehicle unit that the interconnection has failed. It should be noted that the above Figure 7A - Figure 7B is only an example of the process of displaying the input control, and the present application does not limit the relevant display interfaces of this process. For example, the mobile phone may not display the above connection interface but directly display the above interface 3.
[0159] In some embodiments, the above Bluetooth broadcast message 1 may not include the above identification code 1. Correspondingly, after receiving the Bluetooth broadcast message 1, the mobile phone does not need to determine whether to filter out the Bluetooth broadcast message 1 but can directly execute S307, improving the efficiency of the interconnection between the in-vehicle unit and the mobile phone.
[0160] The above S304 - S307 introduce the process in which the mobile phone displays an input control based on the Bluetooth broadcast message 1 sent by the in-vehicle unit for the user to input a connection code. After obtaining the connection code input by the user, the mobile phone can perform identity authentication with the in-vehicle unit based on the connection code input by the user. The following will continue to introduce the process of identity authentication according to the connection code input by the user.
[0161] S308. The mobile phone receives the connection code 2 input by the user in the above input control 1.
[0162] Exemplarily, the above Figure 7B shown interface 3 may further include a cancel control 24 and a confirmation control 25. The cancel control 24 is used to trigger the mobile phone to stop interconnecting with the in-vehicle unit. The confirmation control 25 is used to trigger the mobile phone to continue interconnecting with the in-vehicle unit. In response to the user's click operation on the confirmation control 25, the mobile phone obtains the user's input in Figure 7BThe connection code entered in the input box 23 shown, that is, connection code 2, is used to authenticate the identity with the vehicle head unit using connection code 2 (or referred to as the first connection code) to achieve interconnection.
[0163] Optionally, during interconnection, such as when receiving a click operation from the user on the confirmation control 25, the mobile phone can display an interface as shown in Figure 7C The interface prompts the user that the mobile phone and the vehicle head unit are being bound.
[0164] S309. The mobile phone encrypts connection code 2 based on the PAKE protocol to obtain session key 1.
[0165] S310. The mobile phone sends authentication request 1 to the vehicle head unit based on a Bluetooth connection, where authentication request 1 includes session key 1.
[0166] S311. The vehicle head unit encrypts identification code 1 based on the PAKE protocol to obtain session key 2.
[0167] S312. When the session key 1 in authentication request 1 and session key 2 are the same, the vehicle head unit sends an authentication success response message 1 to the mobile phone based on the Bluetooth connection.
[0168] In the embodiments of the present application, first, the mobile phone can generate random number 1 (i.e., R1) and send it to the vehicle head unit. Then, the vehicle head unit receives R1 and generates random number 2 (R2). Then, the vehicle head unit sends R2 to the mobile phone. In this way, both the mobile phone and the vehicle head unit hold R1 and R2. Then, the mobile phone can encrypt R1, R2, and connection code 2 based on algorithm 1 to obtain session key 1. Then, the mobile phone sends authentication request 1 (or referred to as the second device identity authentication request) carrying session key 1 to the vehicle head unit. The vehicle head unit encrypts R1, R2, and connection code 1 based on algorithm 1 to obtain session key 2. Then, the vehicle head unit determines whether the session key 1 received by the vehicle head unit and session key 2 are the same. When session key 2 and session key 1 are the same, it indicates that the connection code 2 entered by the user on the mobile phone is consistent with the connection code 1 displayed on the vehicle head unit, and the mobile phone is the device that exchanged random numbers with the vehicle head unit before. Then, the vehicle head unit can determine that the identity of the mobile phone is legal, and the vehicle head unit sends an authentication success response message 1 to the mobile phone.
[0169] In addition, when session key 2 (or referred to as the fourth session key) and session key 1 (or referred to as the third session key) are not the same, it indicates that the connection code 2 entered by the user on the mobile phone is inconsistent with the connection code 1 displayed on the vehicle head unit, or the random numbers (such as R1, R2) are different. Then, the vehicle head unit can determine that the identity of the mobile phone may be at risk, and the authentication between the vehicle head unit and the mobile phone fails. The vehicle head unit can send an authentication failure response message 1 to the mobile phone. Then, in response to this authentication failure response message 1, the mobile phone displays an interconnection failure prompt message 1, which indicates a failure to connect to the vehicle head unit, as shown in Figure 7DThe displayed interconnection failure prompt message 26.
[0170] Optionally, the above failure prompt message 1 can also indicate the reason for the connection failure. For example, the failure prompt message indicates that the identification code entered by the user is incorrect, so that the user can understand the reason for the connection failure.
[0171] Optionally, when the session key 1 and the session key 2 are different, the in-vehicle unit can display the interconnection failure prompt message 2, such as displaying Figure 7E The displayed interconnection failure prompt message 27 to prompt the user that the interconnection between the in-vehicle unit and the mobile phone fails.
[0172] In some embodiments, the above session keys (such as session key 1 and session key 2) are symmetric keys. The above-described method of determining the session key through the PAKE protocol is only one possible implementation of determining the session key. Other symmetric encryption algorithms can also be used to encrypt the connection codes (such as the above connection code 1 and connection code 2) to obtain the session key, as long as the encryption algorithms used by both the mobile phone and the in-vehicle unit are the same. For example, the mobile phone uses symmetric encryption algorithm 1 (or called the first algorithm) to encrypt the connection code 2 to obtain the session key 1. The in-vehicle unit uses symmetric encryption algorithm 1 to encrypt the connection code 1 to obtain the session key 2.
[0173] S313. In response to the authentication success response message 1, the mobile phone encrypts the huks certificate 1 of the mobile phone based on the session key 1 to obtain the encrypted huks certificate 1.
[0174] Among them, the above authentication success response message 1 can also be called the second authentication success response message.
[0175] S314. The mobile phone sends the encrypted huks certificate 1 to the in-vehicle unit based on the Bluetooth connection.
[0176] In the embodiments of the present application, in order to verify the security of the mobile phone, after the connection code verification is successful, the mobile phone can send the huks certificate 1 of the mobile phone to the in-vehicle unit based on the Bluetooth connection, so that the in-vehicle unit can verify whether the huks certificate 1 is valid, thereby determining whether there is a risk in the mobile phone and realizing further verification of the mobile phone identity. In order to improve the security of the data transmitted on the Bluetooth channel, the mobile phone can encrypt the huks certificate 1 of the mobile phone based on the session key 1 to obtain the encrypted huks certificate 1. Then, the mobile phone can send the encrypted huks certificate 1 to the in-vehicle unit through the Bluetooth connection, so that the in-vehicle unit can verify the security of the mobile phone through the encrypted huks certificate 1 and avoid interconnection between the in-vehicle unit and devices with risks.
[0177] S315. The in-vehicle unit decrypts the encrypted huks certificate 1 based on the session key 2 to obtain the huks certificate 1.
[0178] S316. Based on the PKI certificate of the in-vehicle unit, when determining that the huks certificate 1 is valid, the in-vehicle unit sends a success response message 1 to the mobile phone via Bluetooth connection.
[0179] In the embodiment of the present application, after decrypting the huks certificate 1 of the mobile phone, the in-vehicle unit verifies whether the huks certificate 1 is valid through the PKI certificate of the in-vehicle unit, thereby realizing the verification of the identity of the mobile phone. When the huks certificate 1 is verified to be valid, it indicates that the identity of the mobile phone is trustworthy, and then the in-vehicle unit can send a success response message 1 to the mobile phone to notify the mobile phone that the verification is successful.
[0180] In addition, when the huks certificate 1 is verified to be invalid, it indicates that there may be risks with the mobile phone. Then the in-vehicle unit can send a failure response message 1 to the mobile phone to notify the mobile phone that the in-vehicle unit verification fails. In response to the failure response message 1, the mobile phone can display an interconnection failure prompt message (such as the interconnection failure prompt message 26 shown above). Optionally, the interconnection failure prompt message can also indicate the connection failure reason information, such as the connection failure reason information indicating that the connection with the Honor device cannot be normal due to the absence of a certificate in the in-vehicle unit. Figure 7D As shown above, the process of the in-vehicle unit using the huks certificate of the mobile phone to verify the identity of the mobile phone for security has been introduced. The mobile phone can also use the huks certificate of the in-vehicle unit to verify the identity of the in-vehicle unit to achieve mutual verification of the security of both devices. The process of the mobile phone verifying the identity of the in-vehicle unit will be continued below.
[0181] S317. Based on the session key 2, the in-vehicle unit encrypts the huks certificate 2 of the in-vehicle unit to obtain the encrypted huks certificate 2.
[0182] S318. Based on the Bluetooth connection, the in-vehicle unit sends the encrypted huks certificate 2 to the mobile phone.
[0183] S319. The mobile phone decrypts the encrypted huks certificate 2 based on the session key 1 to obtain the huks certificate 2.
[0184] S320. Based on the PKI certificate of the mobile phone, when determining that the huks certificate 2 is valid, the mobile phone sends a success response message 2 to the in-vehicle unit via Bluetooth connection.
[0185] S320. Based on the PKI certificate of the mobile phone, when determining that the huks certificate 2 is valid, the mobile phone sends a success response message 2 to the in-vehicle unit via Bluetooth connection.
[0186] Among them, the process of the mobile phone using the huks certificate 2 of the in-vehicle unit to verify the security of the in-vehicle unit is similar to the process of the in-vehicle unit using the huks certificate 1 of the mobile phone to verify the security of the mobile phone, and will not be elaborated here.
[0187] In some embodiments, the huks certificate 1 of the above-mentioned mobile phone and the PKI certificate of the mobile phone can be pre-installed in the mobile phone, such as pre-installed before the mobile phone leaves the factory. Alternatively, the huks certificate 1 and the PKI certificate of the mobile phone can be downloaded by the mobile phone from the relevant server after the server verifies the trustworthiness of the mobile phone. Similarly, the huks certificate 2 of the above-mentioned vehicle-mounted device and the PKI certificate of the vehicle-mounted device can be pre-installed in the vehicle-mounted device, such as pre-installed before the vehicle-mounted device leaves the factory. Alternatively, the huks certificate 2 and the PKI certificate of the vehicle-mounted device can be downloaded by the mobile phone from the server after the server verifies the trustworthiness of the mobile phone.
[0188] It should be noted that the above-mentioned huks certificate 1 and huks certificate 2 are only examples of digital certificates. The mobile phone can also send other types of digital certificates to the vehicle-mounted device. Similarly, the vehicle-mounted device can also send other types of digital certificates to the mobile phone.
[0189] In some embodiments, after the security mutual verification between the vehicle-mounted device and the mobile phone is successful, it indicates that both the vehicle-mounted device and the mobile phone are secure, and the device authentication is completed. The vehicle-mounted device and the mobile phone can save the pairing relationship, that is, the other device information. Exemplarily, the mobile phone can save the device information of the vehicle-mounted device, and the device information of the vehicle-mounted device can include one or more of the vehicle-mounted device identifier, session key 1, and the public key of the vehicle-mounted device. Among them, the vehicle-mounted device identifier can be the hardware address (media access control, mac) of the vehicle-mounted device. Of course, it can also be other types of information, such as the vehicle model, etc. The public key of the vehicle-mounted device can be sent by the vehicle-mounted device, and it can be obtained subsequently (such as during the vehicle-mounted device proxy registration process)
[0190] Optionally, the above-mentioned vehicle-mounted device identifier and the public key of the vehicle-mounted device can be permanently saved by the mobile phone, such as saved to a specific database or file. Since the session key 1 has a validity period and needs to be updated regularly, the session key can be saved in the memory of the mobile phone. The update process of the public key of the vehicle-mounted device can refer to the secondary network authentication part introduced below.
[0191] Similarly, the vehicle-mounted device can save the device information of the mobile phone, and the device information of the mobile phone can include one or more of the mobile phone identifier, session key 1, and the public key of the mobile phone. Among them, the mobile phone identifier can be the hardware address of the mobile phone. The public key of the mobile phone can be sent by the mobile phone. For example, the mobile phone uses the session key 1 or the public key of the tablet computer to encrypt the public key of the mobile phone, and sends the encrypted public key of the mobile phone to the vehicle-mounted device for the vehicle-mounted device to decrypt to obtain the public key of the mobile phone.
[0192] In some embodiments, when the mobile phone and the vehicle-mounted device perform Bluetooth communication, session key encryption may not be used either. For example, the mobile phone can send the huks certificate of the mobile phone to the vehicle-mounted device, and the vehicle-mounted device can send the huks certificate of the vehicle-mounted device to the mobile phone, without using session encryption.
[0193] In addition, the process of the in-vehicle unit and the mobile phone performing security mutual authentication using the huks certificates can also be carried out before the identity authentication based on the PAKE protocol. After verifying that the huks certificate 1 and the huks certificate 2 are valid, the identity authentication based on the PAKE protocol can be continued.
[0194] In some embodiments, the process of the in-vehicle unit using the huks certificate 1 of the mobile phone to verify the security of the mobile phone is optional, such as the above S313 - S316 being optional. Correspondingly, the mobile phone can only use the huks certificate 2 of the in-vehicle unit to verify the security of the in-vehicle unit, such as performing the above S317 - S320. Similarly, the process of the above mobile phone using the huks certificate 2 of the in-vehicle unit to verify the security of the in-vehicle unit is optional, such as the above S317 - S320 being optional. Correspondingly, the in-vehicle unit can only use the huks certificate 1 of the mobile phone to verify the security of the mobile phone, such as performing the above S313 - S316. In addition, the process of the in-vehicle unit using the huks certificate 1 of the mobile phone to verify the security of the mobile phone and the process of the mobile phone only using the huks certificate 2 of the in-vehicle unit to verify the security of the in-vehicle unit are both optional, and the above S313 - S320 are not executed.
[0195] The above S308 - S320 are a possible implementation manner of step 4 in the above Figure 4 embodiments. After the identity authentication is successful, the device registration can be continued. Since the in-vehicle unit is not in the trust ring, such as the account logged in by the in-vehicle unit not being a Honor account, the in-vehicle unit cannot directly register with the device cloud. The in-vehicle unit can register with the device cloud through the mobile phone to achieve proxy registration. The following will continue to introduce the implementation process of proxy registration (that is, the relevant content of steps 5 - 9 in the above Figure 4 embodiments) in combination with S321 - S334.
[0196] S321. In response to the above successful response message 2, the in-vehicle unit sends a proxy registration request to the mobile phone based on the Bluetooth connection. The proxy registration request includes the in-vehicle unit registration information 1 encrypted with the session key 2. The in-vehicle unit registration information 1 includes the public key 1 of the in-vehicle unit and the authorization code 1 of the in-vehicle unit.
[0197] The above authorization code 1 (authcode) of the in-vehicle unit is randomly generated by the in-vehicle unit.
[0198] S322. The mobile phone decrypts the encrypted in-vehicle unit registration information 1 based on the session key 1 to obtain the in-vehicle unit registration information 1.
[0199] In some embodiments, the in-vehicle unit registration information 1 received by the mobile phone can also be unencrypted. Correspondingly, the mobile phone does not need to decrypt it using the session key to improve the in-vehicle unit registration efficiency.
[0200] S323. The mobile phone signs the vehicle head unit registration information 1 based on the license 1 of the mobile phone to obtain the digital signature 1.
[0201] S324. The mobile phone sends a device registration request to the device cloud, and the device registration request includes the digital signature 1 and the vehicle head unit registration information 1.
[0202] S325. In response to the device registration request, the device cloud signs the vehicle head unit registration information 1 based on the license 2 to obtain the digital signature 2.
[0203] S326. The device cloud determines whether the digital signature 1 and the digital signature 2 are the same.
[0204] In the embodiment of the present application, in order to improve security, after receiving the device registration request sent by the mobile phone, the device cloud can verify the signature to determine the security of the mobile phone, ensure the security of registration, and avoid the registration of risky devices. When the digital signature 1 (or the first digital signature) and the digital signature 2 are the same, it indicates that the license 1 of the mobile phone is valid, the mobile phone is trustworthy, and the device cloud can register normally, so the device cloud can execute S327. When the digital signature 1 and the digital signature 2 are different, it indicates that the mobile phone may be risky, and the device cloud does not register the vehicle head unit, so the device cloud can execute S332.
[0205] Among them, the license 1 of the above mobile phone is used for device cloud authentication, which is similar to the PKI certificate of the above mobile phone. It can be pre-installed in the mobile phone or a related service. For example, after the device cloud verifies that the mobile phone is trustworthy, the mobile phone downloads it from a related server.
[0206] S327. The device cloud saves the vehicle head unit registration information 1 and sends a registration success response message to the mobile phone.
[0207] Exemplarily, the device cloud can add the vehicle head unit registration information 1 to the trust ring list corresponding to the Honor account A logged in by the mobile phone to add the vehicle head unit to the trust ring corresponding to the Honor account A.
[0208] S328. In response to the registration success response message, the mobile phone displays the interface 4. Among them, the interface 4 is used to prompt that the connection between the mobile phone and the vehicle head unit is successful.
[0209] Exemplarily, the above interface 4 can further include a connection success prompt message (here or called the second connection success prompt message), such as Figure 8A the prompt message 34 shown.
[0210] Optionally, the interface 4 includes a vehicle head unit icon and a mobile phone icon. As Figure 8A shown, the interface 4 includes the vehicle head unit icon 30 and the mobile phone icon 31.
[0211] Optionally, the above interface 4 may further include icons of other devices in the trust ring where the mobile phone is located, such as the above Figure 8A As shown, the interface 4 further includes a PC icon 32, a tablet computer icon 33, etc. Among them, the tablet computer and the PC are other devices in the trust ring where the mobile phone is located.
[0212] In some embodiments, the above process of verifying the digital signature 1 is optional. The mobile phone may send a proxy registration request carrying the in-vehicle device registration information to the device cloud, and the device cloud may directly save the in-vehicle device registration information and send a registration success response message to the mobile phone.
[0213] S329. The mobile phone sends a registration success message to the in-vehicle device based on the Bluetooth connection. The registration success message includes the Honor account A logged in on the mobile phone.
[0214] S330. In response to the registration success message, the in-vehicle device displays interface 5, and this interface 5 indicates that it has been successfully connected to the mobile phone.
[0215] Exemplarily, the above interface 5 may include an interconnection success prompt message (here or referred to as the fourth interconnection success prompt message), which indicates that it has been successfully connected to the mobile phone.
[0216] Optionally, interface 5 may be a service introduction page (as Figure 8B shown), which indicates the services that can be performed with the mobile phone. In addition, after receiving the registration success message, the mobile phone needs to save the Honor account carried in the registration success message to connect to other devices in the trust ring corresponding to the Honor account.
[0217] S331. The in-vehicle device and the mobile phone establish a session connection 1.
[0218] Among them, the above session connection represents a service connection, which is used for business data interaction. For example, when the user wants to use the applications on the mobile phone on the in-vehicle device, the user can enter relevant operations on the mobile phone, such as moving the mobile phone icon displayed on the mobile phone to the in-vehicle device icon. The mobile phone responds to this movement operation, starts the super desktop service, and sends the mobile phone desktop data (such as application data) to the in-vehicle device through the session connection 1. After that, the in-vehicle device can display the applications on the mobile phone based on the mobile phone desktop data.
[0219] Optionally, after starting the super desktop service, the mobile phone may display an interface as Figure 8C shown to prompt that the mobile phone is currently starting the super desktop.
[0220] The above S327 - S331 introduce the situation where the device registration is successful when the digital signature 1 and the digital signature 2 are the same. Of course, there may also be the possibility that the digital signature 1 and the digital signature 2 are different. The following will continue to introduce the situation where the digital signature 1 and the digital signature 2 are different.
[0221] S332. The device cloud returns a registration failure response message to the mobile phone based on the Bluetooth connection.
[0222] S333. The mobile phone responds to the registration failure response message by displaying connection failure prompt information 1, and returns the registration failure message to the vehicle computer based on the Bluetooth connection.
[0223] S334. The vehicle computer responds to the registration failure message and displays a connection failure prompt message 2.
[0224] Among them, the above-mentioned connection failure prompt information 1 and connection failure prompt information 2 prompt the user that the connection between the vehicle computer and the mobile phone has failed.
[0225] In the embodiment of the present application, after the device signature verification fails, the mobile phone can be notified of the registration failure. The mobile phone prompts the user that the mobile phone and the vehicle computer have failed to connect. The mobile phone can also send a registration failure message to the vehicle computer to notify the vehicle computer of the registration failure.
[0226] It should be noted that when the mobile phone has no network (such as Wi-Fi network, mobile network (such as 5G, 4G, etc.)) or the license 1 of the mobile phone is invalid, the above-mentioned device registration failure will occur.
[0227] above Figure 5 This article introduces how the car computer connects to the first device in the trust ring (such as a mobile phone). After the car computer is connected to the mobile phone, it can automatically connect to other devices in the trust ring corresponding to the Honor account logged in by the mobile phone, realizing secondary self-organizing network without user operation, which improves the connection efficiency. Figure 9 Introduce the process of non-sensing secondary self-organizing network.
[0228] S401. The tablet computer receives the vehicle registration information 2 sent by the device cloud.
[0229] Exemplarily, the vehicle registration information 2 may include the vehicle authorization code 2 and the vehicle public key 2. Optionally, the vehicle registration information 2 may also include other information, such as vehicle information.
[0230] In the embodiment of the present application, after the mobile phone successfully registers the vehicle, the device cloud can synchronize the vehicle registration information 2 with the devices in the trust ring where the mobile phone is located (including the above-mentioned tablet computer). Among them, the trust ring where the mobile phone is located is the trust ring corresponding to the Honor account A logged in by the mobile phone.
[0231] The above S401 is the above Figure 4 In a possible implementation process of step 10 in the embodiment, after synchronizing the vehicle computer registration information 2 to the tablet computer, the tablet computer can automatically connect to the vehicle computer using the vehicle computer registration information 2. The process of automatic connection between the tablet computer and the vehicle computer will be further described below.
[0232] It is understandable that the device cloud can use the vehicle-mounted registration information corresponding to the Honor account A stored in the device cloud as the vehicle-mounted registration information 2, so that the vehicle-mounted device can determine whether the identity of the tablet computer is trustworthy based on the consistency between the content in the vehicle-mounted registration information 2 and the vehicle-mounted registration information 1.
[0233] S402. The vehicle-mounted device sends a Bluetooth broadcast message 2, and the Bluetooth broadcast message 2 includes the Honor account A and the identification code 2.
[0234] Among them, the Bluetooth broadcast message 2 (or alternatively described as the first broadcast message) is used to trigger the vehicle-mounted device to perform seamless self-networking with other devices.
[0235] The above Honor account A (or referred to as the first account) represents the Honor account already bound to the vehicle-mounted device. Optionally, since the vehicle-mounted device may be bound to multiple Honor accounts, therefore, the above Bluetooth broadcast message 2 may also include other Honor accounts, so that the vehicle-mounted device can automatically interconnect with devices logged in with any Honor account bound to it. Additionally, the vehicle-mounted device is not logged in with the Honor account A. Optionally, the account logged in to the vehicle-mounted device is a third-party account.
[0236] Exemplarily, when the vehicle-mounted device performs self-networking broadcasting, when the user wants to establish a connection between the tablet computer and the vehicle-mounted device, the user can bring the tablet computer logged in with the Honor account A close to the vehicle-mounted device, and the tablet computer can detect the Bluetooth broadcast message 2 for automatically interconnecting with the vehicle-mounted device using the Bluetooth broadcast message 2.
[0237] It should be noted that if the vehicle-mounted device does not receive a specific trigger operation input by the user, it can send the Bluetooth broadcast message 2, and when it receives a specific trigger operation input by the user, it sends a Bluetooth broadcast message corresponding to the trigger operation. For example, after the vehicle-mounted device is turned on and detects that it is bound to the Honor account A, it can send the Bluetooth broadcast message 2. Subsequently, when the vehicle-mounted device receives a click operation on the connection control by the user, it can send the Bluetooth broadcast message 1 instead of the Bluetooth broadcast message 2.
[0238] S403. The tablet computer receives the above Bluetooth broadcast message 2.
[0239] The above S402 - S403 introduce the process of self-discovery of devices with the same account, which is a possible implementation process of step 11 in the above Figure 4 Example. Next, in combination with S404 - S417, a possible implementation process of step 12 in the Figure 4 Example will be introduced.
[0240] S404. The tablet computer determines whether the identification code 2 belongs to the preset identification code 2.
[0241] In the embodiments of the present application, when the above identification code 2 (or the first identification code) does not belong to the preset identification code 2 (or the first preset identification code), it indicates that the Bluetooth broadcast message 2 is not a broadcast message that the tablet computer (or the first device) needs to process. Then, the tablet computer can execute S405.
[0242] When the above identification code 1 belongs to the preset identification code 2, it indicates that the Bluetooth broadcast message 2 is a broadcast message that the tablet computer needs to process. Then, the tablet computer can execute S406.
[0243] In some embodiments, the tablet computer sets the preset identification code 2, and the number of the preset identification code 2 is one or more. Then, the tablet computer can use the preset identification code 2 to filter the received Bluetooth broadcast messages, avoid processing unnecessary broadcast messages, reduce waste of resources, and avoid processing Bluetooth broadcast messages with security risks, ensuring the security of the tablet computer.
[0244] S405: The tablet computer filters out the above Bluetooth broadcast message 2.
[0245] Among them, the implementation process of S405 can refer to the implementation process of S306 above, and the present application does not limit it.
[0246] S406: The tablet computer responds to the above Bluetooth broadcast message 2 and establishes a Bluetooth connection with the in-vehicle unit.
[0247] Optionally, the above Bluetooth connection can be a BR connection.
[0248] In the embodiments of the present application, the in-vehicle unit sends the Bluetooth broadcast message 2, and the tablet computer detects the Bluetooth broadcast message 2 and discovers the in-vehicle unit. Then, when the identification code 2 in the Bluetooth broadcast message 2 belongs to the preset identification code 2, the tablet computer can continue to process the Bluetooth broadcast message 2 and perform the identity authentication process.
[0249] In some embodiments, the above Bluetooth broadcast message 2 may not include the above identification code 2. Correspondingly, after receiving the Bluetooth broadcast message 2, the tablet computer does not need to determine whether to filter out the Bluetooth broadcast message 2, but can directly establish a Bluetooth connection with the in-vehicle unit to interconnect with the in-vehicle unit, improving the interconnection efficiency between the in-vehicle unit and the tablet computer.
[0250] After determining that the Bluetooth broadcast message 2 needs to be processed, the tablet computer can perform identity authentication with the in-vehicle unit based on the in-vehicle unit registration information 2 it receives. Below, in combination with S407 - S417, the identity authentication process will be introduced taking the authentication based on the PAKE protocol as an example.
[0251] S407: The tablet computer encrypts the random number 3, the authorization code 2, and the public key of the tablet computer based on the public key 2 of the in-vehicle unit to obtain the encrypted data 1.
[0252] S408. The tablet computer sends encrypted data 1 to the in-vehicle unit based on Bluetooth connection.
[0253] S409. The in-vehicle unit decrypts the encrypted data 1 based on the private key of the in-vehicle unit to obtain random number 3, authorization code 2, and the public key of the tablet computer.
[0254] In some embodiments, since the in-vehicle unit itself stores authorization code 1 and the public key of the in-vehicle unit (i.e., public key 1), after receiving the above-mentioned encrypted data 1, the in-vehicle unit can use the private key of the in-vehicle unit to decrypt the encrypted data 1. If the decryption is successful, it indicates that the public key 2 of the in-vehicle unit stored on the tablet computer is correct, and identity authentication can continue, such as executing S410 below. Or, after the in-vehicle unit decrypts successfully, it determines whether authorization code 2 and authorization code 1 are consistent. If they are consistent, it indicates that the authorization code of the in-vehicle unit stored on the tablet computer is correct, and the in-vehicle unit can continue with identity authentication, such as executing S410 below.
[0255] If the decryption fails, it indicates that the public key 2 of the in-vehicle unit stored on the tablet computer is incorrect and not the public key issued by the in-vehicle unit. Then, the in-vehicle unit can send an authentication failure response message to the tablet computer. In response to this authentication failure response message, the tablet computer displays an interconnection failure prompt message, which indicates a connection failure with the in-vehicle unit.
[0256] S410. The in-vehicle unit encrypts random number 4 based on the public key of the tablet computer to obtain encrypted data 2.
[0257] S411. The in-vehicle unit sends encrypted data 2 to the tablet computer based on Bluetooth connection.
[0258] S412. The tablet computer decrypts the encrypted data 2 based on the private key of the tablet computer to obtain random number 4.
[0259] S413. The in-vehicle unit encrypts random number 3 and random number 4 to obtain session key 3.
[0260] S414. The tablet computer encrypts random number 3 and random number 4 to obtain session key 4.
[0261] S415. The tablet computer sends authentication request 2 to the in-vehicle unit based on Bluetooth connection, where the authentication request 2 includes session key 4.
[0262] S416. In response to the above authentication request 2, when session key 3 and session key 4 are the same, the in-vehicle unit sends an authentication success response message to the tablet computer.
[0263] In the embodiments of the present application, the above S407 - S416 introduce the pake authentication process based on the authorization code. The in - vehicle unit and the tablet computer interact to perform identity authentication, and both parties can obtain random number 3 (or the first random number) and random number 4 (or the second random number), so as to generate corresponding session keys (i.e., session key 3 and session key 4) using random number 3 and random number 4.
[0264] The in - vehicle unit can determine whether session key 4 (or the first session key) is the same as session key 3 to determine whether the identities of both parties are legal. When session key 4 is the same as session key 3, it indicates that the identity authentication is successful, the identities of the tablet computer and the in - vehicle unit are legal, there is no risk for the tablet computer and the in - vehicle unit, and the first authentication of the self - organizing network is achieved. The in - vehicle unit can execute S410.
[0265] In addition, when session key 4 and session key 3 are different, it indicates that the identity authentication fails and the interconnection between the tablet computer and the in - vehicle unit fails. Then the in - vehicle unit can return an authentication failure response message (or the first authentication failure response message) to the tablet computer. In response to this authentication failure response message, the tablet computer displays a prompt message indicating interconnection failure. Optionally, the authentication success response message in the above S416 can also be called the first authentication success response message.
[0266] In some embodiments, after obtaining the public key of the tablet computer, the in - vehicle unit can verify the validity of the public key of the tablet computer, such as verifying the public key of the tablet computer using the PKI certificate of the in - vehicle unit. Similarly, after obtaining the public key of the in - vehicle unit, the tablet computer can verify the validity of the public key of the in - vehicle unit, such as verifying the public key of the in - vehicle unit using the PKI certificate of the tablet computer. In addition, in the above Figure 3 embodiments, after obtaining the public key of the in - vehicle unit, the mobile phone can also verify the validity of the public key of the in - vehicle unit.
[0267] In some embodiments, the above session keys (such as session key 3 and session key 4) are symmetric keys. In addition, the process of determining the session key through the pake protocol for identity authentication introduced above is only an example. The way of identity authentication can also be other ways. For example, the above encrypted data 1 is obtained by the tablet computer encrypting the authorization code 2 and the public key of the tablet computer using the public key 2 of the in - vehicle unit. After the in - vehicle unit decrypts to obtain the public key of the tablet computer and the authorization code 2, it can determine whether the authorization code 2 is the same as the authorization code 1. If they are the same, it indicates that the identity authentication is successful. If they are different, it indicates that the identity authentication fails. Correspondingly, the public key of the above tablet computer can be used as the above session key 3. The public key of the in - vehicle unit can be used as the above session key 4. Or, the tablet computer and the in - vehicle unit do not need to determine the session key. Correspondingly, when the two parties interact, there is no need to encrypt using the session key. In other words, the above encrypted data 1 can be obtained by the tablet computer encrypting the authorization code 2 using the public key 2 of the in - vehicle unit.
[0268] In some embodiments, after the security mutual authentication between the in-vehicle device and the tablet computer is successful, it indicates that both the in-vehicle device and the mobile phone are secure, and the device authentication is completed. The in-vehicle device and the tablet computer can save the pairing relationship, that is, the information of the other device. Exemplarily, the tablet computer can save the device information of the in-vehicle device, and the device information of the in-vehicle device can include one or more of the in-vehicle device identifier, session key 4, and the public key of the in-vehicle device. Similarly, the in-vehicle device can save the device information of the tablet computer, and the device information of the tablet computer can include one or more of the tablet computer identifier, session key 3, and the public key of the tablet computer.
[0269] Optionally, the above in-vehicle device identifier and the public key of the in-vehicle device can be permanently saved in the tablet computer, such as saved to a specific database or file. Since the session key 4 has a validity period and needs to be updated regularly, the session key 4 can be saved in the memory of the tablet computer. Similarly, the above tablet computer identifier and the public key of the tablet computer can be permanently saved in the in-vehicle device, and the session key 3 can be saved in the memory of the in-vehicle device.
[0270] S417. The in-vehicle device and the tablet computer establish a session connection 2.
[0271] Among them, the above session connection 2 is used to transmit service data, such as super desktop service data. Optionally, the transmission of the service data can be encrypted by the session key.
[0272] In the embodiments of the present application, when the tablet computer approaches the in-vehicle device, the tablet computer can discover the in-vehicle device and receive the ad-hoc network broadcast of the in-vehicle device. After that, the tablet computer can perform identity authentication with the in-vehicle device. After the identity authentication, the tablet computer and the in-vehicle device are interconnected without any operation by the user, realizing the seamless ad-hoc network between the in-vehicle device and the tablet computer and improving the interconnection efficiency.
[0273] Among them, after the in-vehicle device and the tablet computer are interconnected, the content displayed on the tablet computer can refer to the content displayed on the mobile phone after the mobile phone and the in-vehicle device are successfully interconnected, such as displaying an interconnection success prompt message (or referred to as the first interconnection success prompt message), and this interconnection success prompt message indicates the successful interconnection with the in-vehicle device. The content displayed on the in-vehicle device can refer to the content displayed on the in-vehicle device after the mobile phone and the in-vehicle device are successfully interconnected, such as displaying a corresponding interconnection success prompt message (or referred to as the third interconnection success prompt message), and this interconnection success prompt message indicates the successful interconnection with the tablet computer. Of course, this is only an example, and the present application does not limit its specific displayed content.
[0274] The above introduced the first identity authentication process in the ad-hoc network. Since the session key determined in the identity authentication has a validity period (such as 1 hour), after the validity period, the session key will become invalid. Therefore, the tablet computer and the in-vehicle device can perform secondary network authentication to update the session key. The secondary network authentication process will be continued to be introduced below.
[0275] S418. After a preset time 1, the tablet computer encrypts the session key 4 and the random number 5 based on the public key 2 of the in-vehicle unit to obtain the encrypted data 3.
[0276] In the embodiments of the present application, after determining the session key 4, after a preset time 1 (or referred to as the first preset time), the tablet computer can re-authenticate its identity with the in-vehicle unit based on the PAKE protocol to update the session key between it and the in-vehicle unit. Among them, the preset time 1 is less than the validity period of the session key, that is, before the validity period arrives, the tablet computer and the in-vehicle unit update the session key.
[0277] S419. The tablet computer sends the encrypted data 3 to the in-vehicle unit based on the Bluetooth connection.
[0278] S420. The in-vehicle unit decrypts the encrypted data 3 based on the private key of the in-vehicle unit to obtain the session key 4 and the random number 5.
[0279] S421. The in-vehicle unit encrypts the random number 6 based on the public key of the tablet computer to obtain the encrypted data 4.
[0280] S422. The in-vehicle unit sends the encrypted data 4 to the tablet computer based on the Bluetooth connection.
[0281] S423. The in-vehicle unit encrypts the random number 5 and the random number 6 to obtain the updated session key 3.
[0282] S424. The tablet computer decrypts the encrypted data 4 based on the private key of the tablet computer to obtain the random number 6.
[0283] S425. The tablet computer encrypts the random number 5 and the random number 6 to obtain the updated session key 4.
[0284] S426. The tablet computer sends an authentication request 3 to the in-vehicle unit based on the Bluetooth connection, where the authentication request 3 includes the updated session key 4.
[0285] S427. In response to the above authentication request 3, when the updated session key 3 and the updated session key 4 are the same, the in-vehicle unit sends an authentication success response message to the tablet computer.
[0286] In some embodiments, when the updated session key 3 and the updated session key 4 are different, the in-vehicle unit sends an authentication failure response message to the tablet computer. The tablet computer can re-perform the secondary networking authentication after an interval. If the authentication is not successful before the validity period of the session key 4 arrives, the session connection between the tablet computer and the in-vehicle unit is disconnected.
[0287] Optionally, the in-vehicle unit can also actively send relevant data to the tablet computer after a preset time 1 to update the session key. It can be understood that the above-executed order of steps is only an example, and this application does not limit it. Among them, the above S418 - S427 is a possible implementation of the secondary network formation authentication introduced in step 13 of the above Figure 4 embodiment, and its specific implementation process can refer to the part of the ad-hoc network initial authentication above or the above Figure 5 embodiment regarding the identity authentication process based on the PAKE protocol, which will not be elaborated here.
[0288] In some embodiments, the above Figure 5 process of the in-vehicle unit corresponding to the embodiment being interconnected with the first device (i.e., the mobile phone) in the trust ring can be divided into three parts, namely the in-vehicle unit discovery part, the device authentication part, and the device proxy registration part. The following will introduce these three parts in combination with the above Figure 3 shown software structure. Exemplarily, as Figure 10 shown, the implementation processes of these three parts are as follows:
[0289] In-vehicle unit discovery part:
[0290] First, after the mobile phone interconnection application in the in-vehicle unit receives operation 1 input by the user, in response to this operation 1, it calls the Magic Link interface in the in-vehicle unit and sends a broadcast request to the fusion interconnection middle platform in the in-vehicle unit. Among them, operation 1 can be the click operation of the user on the above connection control.
[0291] After that, the fusion interconnection middle platform in the in-vehicle unit responds to this broadcast request and sends Bluetooth broadcast message 1 through the Bluetooth chip in the in-vehicle unit. Among them, Bluetooth broadcast message 1 includes in-vehicle unit information and identification code 1.
[0292] Moreover, the mobile phone interconnection application in the in-vehicle unit calls the Magic Link interface in the in-vehicle unit and sends connection code 1 to the fusion interconnection middle platform in the in-vehicle unit. And the mobile phone interconnection application in the in-vehicle unit can display connection code 1.
[0293] After that, the Bluetooth chip in the mobile phone receives Bluetooth broadcast message 1. When it determines that identification code 1 belongs to the preset identification code 1, it sends the in-vehicle unit information to the fusion interconnection middle platform in the mobile phone to notify the fusion interconnection middle platform in the mobile phone that the in-vehicle unit is discovered.
[0294] After that, the fusion interconnection middle platform in the mobile phone reports the in-vehicle unit information to the intelligent travel application in the mobile phone.
[0295] After that, the intelligent travel application in the mobile phone receives connection code 2 input by the user in the displayed input control.
[0296] Device authentication (first binding) part:
[0297] The intelligent travel application will call the Magic Link interface in the mobile phone and send the device authentication request to the integrated interconnection middle platform in the mobile phone. Among them, the device authentication request includes connection code 2.
[0298] After that, in response to the device authentication request, the integrated interconnection middle platform in the mobile phone establishes a BR connection with the integrated interconnection middle platform in the in-vehicle unit and sends an identity authentication request to the security basic middle platform in the mobile phone.
[0299] After that, in response to the identity authentication request, based on connection code 2, the security basic middle platform in the mobile phone and the security basic middle platform in the in-vehicle unit perform pake protocol authentication.
[0300] After that, after successful authentication, the security basic middle platform in the mobile phone notifies the integrated interconnection middle platform in the mobile phone that the identity authentication of the in-vehicle unit is successful. Moreover, the security basic middle platform in the in-vehicle unit notifies the integrated interconnection middle platform in the in-vehicle unit that the identity authentication of the mobile phone is successful.
[0301] After that, the integrated interconnection middle platforms in the in-vehicle unit and the mobile phone can respectively use their own PKI certificates to verify whether the other party's huks certificate is valid.
[0302] After successful verification, the integrated interconnection middle platform in the mobile phone can notify the intelligent travel application that the in-vehicle unit is online in the near field. The integrated interconnection middle platform in the in-vehicle unit can notify the mobile phone interconnection travel application that the mobile phone is online in the near field. Optionally, after notifying the online in the near field, the in-vehicle unit and the mobile phone are successfully interconnected.
[0303] Device proxy registration part:
[0304] The intelligent travel application in the mobile phone calls the Magic Link interface in the mobile phone and sends the proxy registration request to the integrated interconnection middle platform in the mobile phone.
[0305] After that, the integrated interconnection middle platform in the mobile phone and the integrated interconnection middle platform in the in-vehicle unit perform a proxy registration process to obtain the in-vehicle unit registration information 1.
[0306] After that, the integrated interconnection middle platform in the mobile phone sends a device registration request to the device cloud. The device cloud returns a corresponding response message.
[0307] After that, when the response message is a registration success response message, the integrated interconnection middle platform in the mobile phone notifies the intelligent travel application that the registration is successful, so that the intelligent travel application displays a corresponding registration success interface.
[0308] Moreover, the integrated interconnection middle platform in the mobile phone sends a registration success message to the integrated interconnection middle platform in the in-vehicle unit. Among them, the registration success message includes the Honor account A.
[0309] After that, the Fusion Interconnection Middle Platform in the in-vehicle unit notifies the mobile interconnection application of successful registration, so that the mobile interconnection application displays the corresponding successful registration interface, and successfully establishes a session connection between the in-vehicle unit and the mobile phone.
[0310] Optionally, the Fusion Interconnection Middle Platform in the in-vehicle unit may send the mapping identifier (or called ringID) corresponding to the Honor account A to the mobile interconnection application, so as to avoid directly sending the Honor account A to the mobile interconnection application, resulting in account leakage and protecting account security.
[0311] The above introduced the process of mobile phone and in-vehicle unit interconnection. After the in-vehicle unit is interconnected with the mobile phone, it joins the trust ring where the mobile phone is located, enabling the in-vehicle unit to automatically interconnect with devices (such as tablet computers) in the trust ring. The process of automatic interconnection (i.e., the process corresponding to the above Figure 9 embodiment) can be divided into three parts, namely the same-account device self-discovery part, the self-organizing network first authentication part, and the secondary network authentication part. Exemplarily, as Figure 11 shown, the implementation processes of these three parts are as follows:
[0312] Among them, the same-account device self-discovery part:
[0313] First, the device cloud synchronizes the in-vehicle unit registration information 2 to the Fusion Interconnection Middle Platform in the tablet computer.
[0314] After that, the mobile interconnection application in the in-vehicle unit calls the Magic Link interface in the in-vehicle unit and sends a self-organizing network broadcast request to the Fusion Interconnection Middle Platform in the in-vehicle unit. This self-organizing network broadcast request includes the mapping identifier corresponding to the Honor account A.
[0315] After that, the Fusion Interconnection Middle Platform in the in-vehicle unit sends a Bluetooth broadcast message 2 through the Bluetooth chip in the in-vehicle unit. Among them, the Bluetooth broadcast message 2 includes the Honor account A and the identification code 2. Among them, the Honor account A is found by the Fusion Interconnection Middle Platform in the in-vehicle unit based on the mapping identifier.
[0316] Optionally, the above Bluetooth broadcast message 2 may be a Bluetooth Low Energy (BLE) broadcast message.
[0317] After that, the Bluetooth chip in the tablet computer receives the Bluetooth broadcast message 2. When it determines that the identification code 2 belongs to the preset identification code 2, it notifies the Fusion Interconnection Middle Platform in the tablet computer that the in-vehicle unit is found.
[0318] The self-organizing network first authentication part:
[0319] The Fusion Interconnection Middle Platform in the tablet computer establishes a BR connection with the Fusion Interconnection Middle Platform in the in-vehicle unit.
[0320] After that, the Fusion Interconnection Middle Platform in the tablet computer sends an identity authentication request to the Security Foundation Middle Platform in the tablet computer. After that, the Security Foundation Middle Platform in the tablet computer conducts PAKE protocol authentication with the Security Foundation Middle Platform in the in-vehicle unit.
[0321] After that, after successful authentication, the Security Foundation Middle Platform in the tablet computer notifies the Fusion Interconnection Middle Platform in the tablet computer that the identity authentication of the in-vehicle unit is successful. Also, the Security Foundation Middle Platform in the in-vehicle unit notifies the Fusion Interconnection Middle Platform in the in-vehicle unit that the identity authentication of the tablet computer is successful.
[0322] After that, the Fusion Interconnection Middle Platform in the tablet computer can notify the Smart Mobility Application that the in-vehicle unit is online in the near field. The Fusion Interconnection Middle Platform in the in-vehicle unit can notify the Mobile Internet Mobility Application that the tablet computer is online in the near field, enabling the establishment of a session connection.
[0323] Secondary networking authentication part:
[0324] The Security Foundation Middle Platform in the tablet computer conducts PAKE protocol authentication with the Security Foundation Middle Platform in the in-vehicle unit to update the session key.
[0325] After that, after successful authentication, the Security Foundation Middle Platform in the tablet computer notifies the Fusion Interconnection Middle Platform in the tablet computer that the identity authentication of the in-vehicle unit is successful. Also, the Security Foundation Middle Platform in the in-vehicle unit notifies the Fusion Interconnection Middle Platform in the in-vehicle unit that the identity authentication of the tablet computer is successful. Optionally, the Fusion Interconnection Middle Platform in the in-vehicle unit notifies the Mobile Internet Application that the tablet computer is in the near-field online state. The Fusion Interconnection Middle Platform in the tablet computer notifies the Smart Mobility Application that the in-vehicle unit is in the near-field online state, so that the in-vehicle unit and the tablet computer can continue to transmit service data using the session connection.
[0326] After the above mobile phone or tablet computer establishes a session connection with the in-vehicle unit, it can use the session connection to transmit service data. The following combines the above Figure 3 shown software structure, taking the service data as super desktop service data as an example, and combines Figure 12 for introduction. As Figure 12 shown, the process of transmitting service data using the session connection may include:
[0327] The Control Center in the mobile phone or tablet computer registers the device interconnection status detection with the Fusion Interconnection Middle Platform in the mobile phone or tablet computer.
[0328] After the first interconnection or automatic interconnection, the Fusion Interconnection Middle Platform in the mobile phone or tablet computer notifies the Control Center that the in-vehicle unit is online in the near field.
[0329] After that, the Control Center displays the in-vehicle unit icon.
[0330] After that, the control center receives operation 2 input by the user, and this operation 2 is used to trigger the in-vehicle unit to perform the super desktop service. For example, this operation 2 can be moving the mobile phone icon onto the in-vehicle unit icon.
[0331] After that, in response to operation 2, the control center triggers the intelligent travel application to send the super desktop service data to the mobile phone interconnection application in the in-vehicle unit.
[0332] Optionally, the above intelligent travel application integrates the Magic Link SDK. The above mobile phone interconnection application integrates the Magic Ring SDK.
[0333] In some embodiments, the security basic middle platform in the mobile phone can send signature 1 of the APK corresponding to the target application (such as the trust ring application) to the security basic middle platform in the in-vehicle unit. After that, the in-vehicle unit uses the certificate signed by the above Honor platform to verify signature 1. After the signature verification is successful and the authentication based on the pake protocol is successful, it is determined that the mobile phone is legal. Among them, the APK corresponding to the target application used by the in-vehicle unit for signature verification can be sent by the mobile phone or the APK corresponding to the target application on the in-vehicle unit.
[0334] In addition, after the in-vehicle unit joins the trust ring where the mobile phone is located, even if the devices in the trust ring are not interconnected with the in-vehicle unit, the in-vehicle unit icon can still be displayed, but the in-vehicle unit icon is in the first state (such as the gray state). After the device is interconnected with the in-vehicle unit, the in-vehicle unit icon can be in the second state (such as the highlighted state).
[0335] In some embodiments, the above Bluetooth communication is only an example of short-range communication. The in-vehicle unit can also perform other types of short-range communication (such as NFC communication) with the mobile phone or tablet computer. Correspondingly, the above Bluetooth broadcast messages (such as Bluetooth broadcast message 1 and Bluetooth broadcast message 2) can also be other types of broadcast messages, and the present application does not limit them.
[0336] It should be noted that the operations performed by the above services or modules in the in-vehicle unit are only examples. The operations performed by the above services or modules can also be performed by other services or models in the in-vehicle unit, and the present application does not limit them. Similarly, the operations performed by the above services or modules in the mobile phone are only examples. The operations performed by the above services or modules can also be performed by other services or models in the mobile phone. The operations performed by the above services or modules in the tablet computer are only examples. The operations performed by the above services or modules can also be performed by other services or models in the tablet computer, and the present application does not limit them.
[0337] In some embodiments, all the operations or information involved in the first interconnection process between the above-mentioned mobile phone and the in-vehicle unit are carried out or collected under the authorization of the user. And all the operations or information involved in the automatic interconnection process between the above-mentioned tablet computer and the in-vehicle unit are also carried out or collected under the authorization of the user.
[0338] In some embodiments, the present application provides a computer storage medium, including computer instructions, which, when running on an electronic device, cause the electronic device to execute the method as described above.
[0339] In some embodiments, the present application provides a computer program product, which, when running on an electronic device, causes the electronic device to execute the method as described above.
[0340] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0341] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the module or unit is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.
[0342] The unit described as a separated component may or may not be physically separated. The component displayed as a unit may be a physical unit or multiple physical units, that is, it may be located in one place, or may be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0343] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0344] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0345] The above content is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An interconnection method, characterized in that, Applied to a first device, the method includes: The first device receives a first broadcast message sent by a vehicle head unit; wherein, the first broadcast message includes a first account logged in by a second device that has been interconnected with the vehicle head unit, and the first device logs in to the first account; the vehicle head unit logs in to a second account, and the first account is different from the second account; In response to the first broadcast message, the first device displays a first interconnection success prompt message, and the first interconnection success prompt message indicates that the first device is interconnected with the vehicle head unit.
2. The method according to claim 1, characterized in that The first device displays the first interconnection success prompt message in response to the first broadcast message, including: In response to the first broadcast message, the first device performs identity authentication with the vehicle head unit based on the vehicle head unit registration information; the vehicle head unit registration information is sent by the device cloud to the devices in the trust ring corresponding to the first account after the vehicle head unit successfully registers with the device cloud; the devices in the trust ring corresponding to the first account include the first device; In the case of successful identity authentication, the first device displays the first interconnection success prompt message.
3. The method according to claim 2, wherein The vehicle head unit registration information includes the public key of the vehicle head unit and the authorization code of the vehicle head unit; Performing identity authentication with the vehicle head unit based on the vehicle head unit registration information includes: The first device encrypts the authorization code of the vehicle head unit based on the public key of the vehicle head unit to obtain first encrypted data; The first device sends a first device identity authentication request to the vehicle head unit; wherein, the first device identity authentication request includes the first encrypted data; The first device receives a first authentication success response message or a first authentication failure response message sent by the vehicle head unit.
4. The method according to claim 3, characterized in that, The first device encrypts the authorization code of the vehicle head unit based on the public key of the vehicle head unit to obtain first encrypted data, including: The first device encrypts a first random number, the public key of the first device, and the authorization code based on the public key of the vehicle head unit to obtain the first encrypted data; The method further includes: The first device receives second encrypted data sent by the vehicle head unit, and the second encrypted data is obtained by the vehicle head unit encrypting a second random number with the public key of the first device; The first device decrypts the second encrypted data based on the private key of the first device to obtain the second random number; The first device encrypts the first random number and the second random number on the first device to obtain a first session key; the first session key is used to encrypt the data sent by the first device to the vehicle head unit; The first device sends the first session key to the vehicle head unit; the first session key is used for the vehicle head unit to send the first authentication success response message or the first authentication failure response message.
5. The method according to any one of claims 2 to 4, characterized in that After displaying the first interconnection success prompt message, the method further includes: After a first preset time, the first device performs secondary identity authentication with the vehicle head unit based on the first session key; the first session key is determined by performing identity authentication with the vehicle head unit.
6. The method according to any one of claims 1 to 5, characterized in that The first broadcast message further includes a first identification code; In response to the first broadcast message, the first device displays a first successful interconnection prompt message, including: When the first identification code belongs to a first preset identification code, the first successful interconnection prompt message is displayed.
7. An interconnection method, characterized in that, Applied to a second device, the method includes: The second device performs identity authentication with the in-vehicle unit; the second device logs in to a first account; When the identity authentication is successful, the second device receives the in-vehicle unit registration information sent by the in-vehicle unit; The second device sends the in-vehicle unit registration information to the device cloud and displays a second successful interconnection prompt message, which indicates that the second device and the in-vehicle unit are successfully interconnected; Among them, the in-vehicle unit registration information is used for the second device to synchronize the in-vehicle unit registration information to the devices in the trust ring corresponding to the first account through the device cloud, so that the devices in the trust ring can be interconnected with the in-vehicle unit when approaching the in-vehicle unit.
8. The method according to claim 7, characterized in that, The second device sends the in-vehicle unit registration information to the device cloud and displays a second successful interconnection prompt message, including: The second device sends a device registration request to the device cloud; among them, the device registration request includes the in-vehicle unit registration information and a first digital signature corresponding to the in-vehicle unit registration information; The second device receives the registration success response message sent by the device cloud; among them, the registration success response message is sent by the device cloud after successfully verifying the first digital signature based on the in-vehicle unit registration information; The second device displays the second successful interconnection prompt message in response to the registration success response message.
9. The method according to claim 7 or 8, characterized in that, Before the second device performs identity authentication with the in-vehicle unit, the method further includes: The second device sends a second broadcast message, and the second broadcast message further includes a second identification code; The second device performs identity authentication with the in-vehicle unit, including: When the second identification code belongs to a second preset identification code, the second device performs identity authentication with the in-vehicle unit.
10. An interconnection method, characterized in that, Applied to an in-vehicle unit, the method includes: The in-vehicle unit sends a first broadcast message; among them, the first broadcast message includes the first account logged in by the second device already interconnected with the in-vehicle unit, the in-vehicle unit logs in to a second account, and the second account is different from the first account; When a first device approaches the in-vehicle unit and the first device logs in to the first account, the in-vehicle unit displays a third successful interconnection prompt message, which indicates that the in-vehicle unit and the first device are successfully interconnected.
11. The method according to claim 10, wherein The method further includes: The in-vehicle unit performs identity authentication with the second device; When the identity authentication is successful, the in-vehicle unit sends a proxy registration request to the second device and displays a fourth successful interconnection prompt message, which indicates that the in-vehicle unit and the second device are successfully interconnected; The proxy registration request includes the in-vehicle unit registration information, and the proxy registration request is used to register with the device cloud through the second device, so as to synchronize the in-vehicle unit registration information to the devices in the trust ring corresponding to the first account through the device cloud, and the devices in the trust ring include the first device.
12. An electronic device, characterized in that, The electronic device includes a display screen, a memory, and one or more processors; the display screen, the memory, and the processors are coupled; the display screen is configured to display an image generated by the processors, the memory is configured to store computer program code, and the computer program code includes computer instructions; when the processors execute the computer instructions, the electronic device is caused to execute the method according to any one of claims 1 to 9.
13. A vehicle-mounted computer, characterized in that, The vehicle-mounted device includes a display screen, a memory, and one or more processors; the display screen, the memory, and the processors are coupled; the display screen is configured to display an image generated by the processors, the memory is configured to store computer program code, and the computer program code includes computer instructions; when the processors execute the computer instructions, the vehicle-mounted device is caused to execute the method according to any one of claims 10 to 11.
14. A computer storage medium, characterized in that, It includes computer instructions that, when run on an electronic device, cause the electronic device to execute the method according to any one of claims 1 to 9.
15. A computer storage medium, characterized in that, It includes computer instructions that, when run on a vehicle-mounted device, cause the vehicle-mounted device to execute the method according to any one of claims 10 to 11.
Citation Information
Patent Citations
Automobile account system and account automatic verification method
CN106850580A
Method and device for wireless connection of multiple devices
CN108702607A
Non-inductive interconnection method and device, electronic equipment and storage medium
CN117183948A
Display apparatus
JP2021002861A
Cloud based WIFI network setup for multiple access points
US20180331828A1