File storage encryption management method and system
By obtaining real-time dynamic biometric data and interactive behavior data of the in-car user, the dynamic key of the car owner's characteristics is solved, and the on-car information leakage problem caused by non-car owner authentication is realized, and the secure encrypted storage and access control of the on-car information is realized.
Patent Information
- Application Number
- CN202510640166.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, car owner authentication generally adopts facial recognition, car key recognition, and NFC recognition methods. Non-car owners can authenticate their identity after blocking the face recognition camera, resulting in the problem of vehicle information leakage.
By obtaining real-time dynamic biometric data and interactive behavior data of the user in the car, real-time feature vectors are generated. After the vehicle is used, the owner's feature matching factor is generated, and the owner's feature dynamic key is generated, and the on-board file is encrypted and stored, and the dynamic key matches are verified during access and access is allowed.
Accurately identify the identity of the car owner, prevent illegal access, ensure the security of on-board information, and solve the problem of on-board information leakage.
Smart Images

Figure CN120378189A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data storage and encryption, and particularly to a file storage encryption management method and system. Background Art
[0002] In the prior art, to access a file in a vehicle storage system, the vehicle owner's identity authentication needs to be performed first. Usually, the vehicle owner authentication generally adopts one of the face recognition, car key recognition, and NFC recognition methods. However, this authentication method has drawbacks. For example, after a non-owner covers the face recognition camera and uses the car key to authenticate the vehicle owner, the non-owner can perform identity recognition and authentication in the identity of the non-owner himself / herself, enabling the non-owner to access the information in the vehicle storage system, thus leading to the problem of vehicle information leakage.
[0003] Therefore, there is an urgent need for a file storage encryption management method and system applied to a vehicle storage system. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a file storage encryption management method and system that can solve the problem in the prior art that when the vehicle owner authentication generally adopts one of the face recognition, car key recognition, and NFC recognition methods, after a non-owner covers the face recognition camera and uses the car key to authenticate the vehicle owner, the non-owner can perform identity recognition in the identity of the non-owner himself / herself, thus leading to the problem of vehicle information leakage.
[0005] The technical solution of the present invention is as follows: A file storage encryption management method applied to a vehicle storage system, the method comprising: During the use of the vehicle, acquiring real-time dynamic biometric data of an in-vehicle user and real-time interaction behavior data between the in-vehicle user and an in-vehicle electronic device, and generating a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data; After the use of the vehicle is completed, generating an owner feature matching factor according to the real-time feature vector and an original feature vector; Generating an owner feature dynamic key according to the owner feature matching factor; Encrypting the vehicle-mounted file to be stored according to the owner feature dynamic key to generate an encrypted vehicle-mounted file, and storing the encrypted vehicle-mounted file in the vehicle storage system.
[0006] Optionally, acquiring the real-time dynamic biometric data of the in-vehicle user includes: During the use of the vehicle, acquiring a set of biometric features to be evaluated of the in-vehicle user, wherein the set of biometric features to be evaluated includes a plurality of candidate biometric features; Construct a multimodal behavior resonance matrix based on the set of biometric features to be evaluated; Calculate the accuracy score of each candidate biometric feature according to the multimodal behavior resonance matrix; Set the candidate biometric features corresponding to the accuracy scores greater than or equal to the preset score threshold as real-time dynamic biometric data.
[0007] Optionally, obtain the real-time interaction behavior data of the in-vehicle user and the in-vehicle electronic device, including: Obtain the device trigger instruction for the in-vehicle user to trigger the in-vehicle electronic device; Collect information according to the device trigger instruction and generate real-time interaction behavior data.
[0008] Optionally, generate a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data, including: Obtain a preset non-linear hashing function; Generate a real-time feature vector according to the non-linear hashing function based on the real-time interaction behavior data and the real-time dynamic biometric data.
[0009] Optionally, generate a vehicle owner feature matching factor according to the real-time feature vector and the original feature vector, including: Obtain a preset non-linear mapping function; Generate a vehicle owner feature matching factor according to the non-linear mapping function based on the real-time feature vector and the original feature vector.
[0010] Optionally, generate a vehicle owner feature dynamic key according to the vehicle owner feature matching factor, including: Obtain the system clock value and the hardware random number sequence, where the hardware random number sequence is generated by the in-vehicle device security chip; Construct an encryption mapping function according to the vehicle owner feature matching factor, the system clock value and the hardware random number sequence; Generate a vehicle owner feature dynamic key according to the encryption mapping function and the key derivation function.
[0011] Optionally, encrypt the vehicle-mounted file to be stored according to the vehicle owner feature dynamic key to generate an encrypted vehicle-mounted file, including: Obtain a preset symmetric encryption algorithm; Encrypt the vehicle-mounted file to be stored according to the symmetric encryption algorithm using the vehicle owner feature dynamic key to generate an encrypted vehicle-mounted file.
[0012] Optionally, the method further includes: In response to a to-be-confirmed visitor accessing the vehicle-mounted storage system, collect the current access feature data and the current access interaction data of the to-be-confirmed visitor; Generate a current access dynamic key based on the current access feature data and the current access interaction data; Verify whether the current access dynamic key matches the vehicle owner feature dynamic key; If the verification is a match, allow the to-be-confirmed visitor to access the vehicle-mounted storage system; If the verification does not match, reject the to-be-confirmed visitor from accessing the vehicle-mounted storage system.
[0013] Optionally, the method further includes: verifying whether the current access dynamic key matches the vehicle owner feature dynamic key, including: Calculate the Euclidean distance between the current access dynamic key and the vehicle owner feature dynamic key; Generate a key difference metric value based on the Euclidean distance; Determine whether the key difference metric value is greater than a preset difference threshold; If the determination is yes, determine that the verification is a match; if the determination is no, determine that the verification does not match.
[0014] Optionally, there is also provided a file storage encryption management system, which includes: A feature vector generation module, which is used to obtain the real-time dynamic biometric data of the in-vehicle user and the real-time interaction behavior data between the in-vehicle user and the in-vehicle electronic device during vehicle use, and generate a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data; A matching factor generation module, which is used to generate a vehicle owner feature matching factor according to the real-time feature vector and the original feature vector after vehicle use; A dynamic key generation module, which is used to generate a vehicle owner feature dynamic key according to the vehicle owner feature matching factor; A file encryption storage module, which is used to encrypt the vehicle-mounted file to be stored according to the vehicle owner feature dynamic key to generate an encrypted vehicle-mounted file, and store the encrypted vehicle-mounted file in the vehicle-mounted storage system.
[0015] Optionally, the feature vector generation module is further used to: during vehicle use, obtain a set of biometric features to be evaluated of the in-vehicle user, where the set of biometric features to be evaluated includes multiple candidate biometric features; construct a multi-modal behavior resonance matrix according to the set of biometric features to be evaluated; calculate the accuracy score of each candidate biometric feature according to the multi-modal behavior resonance matrix; set the candidate biometric features corresponding to the accuracy scores greater than or equal to the preset score threshold as the real-time dynamic biometric data.
[0016] Optionally, the feature vector generation module is further configured to: obtain a device trigger instruction for a user in the vehicle to trigger an in-vehicle electronic device; collect information according to the device trigger instruction, and generate real-time interaction behavior data.
[0017] Optionally, the feature vector generation module is further configured to: obtain a preset non-linear hashing function; generate a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data according to the non-linear hashing function.
[0018] Optionally, the matching factor generation module is further configured to: obtain a preset non-linear mapping function; generate a vehicle owner feature matching factor according to the real-time feature vector and the original feature vector according to the non-linear mapping function.
[0019] Optionally, the dynamic key generation module is further configured to: obtain a system clock value and a hardware random number sequence, where the hardware random number sequence is generated by a vehicle-mounted device security chip; construct an encryption mapping function according to the vehicle owner feature matching factor, the system clock value, and the hardware random number sequence; generate a vehicle owner feature dynamic key according to the encryption mapping function and a key derivation function.
[0020] Optionally, the file encryption storage module is further configured to: obtain a preset symmetric encryption algorithm; encrypt the vehicle-mounted file to be stored according to the symmetric encryption algorithm using the vehicle owner feature dynamic key to generate an encrypted vehicle-mounted file.
[0021] Optionally, the file encryption storage module is further configured to: in response to a to-be-confirmed visitor accessing the vehicle-mounted storage system, collect current access feature data and current access interaction data of the to-be-confirmed visitor; generate a current access dynamic key according to the current access feature data and the current access interaction data; verify whether the current access dynamic key matches the vehicle owner feature dynamic key; if the verification matches, allow the to-be-confirmed visitor to access the vehicle-mounted storage system; if the verification does not match, reject the to-be-confirmed visitor from accessing the vehicle-mounted storage system.
[0022] Optionally, the file encryption storage module is further configured to: calculate the Euclidean distance between the current access dynamic key and the vehicle owner feature dynamic key; generate a key difference metric value according to the Euclidean distance; determine whether the key difference metric value is greater than a preset difference threshold; if the determination is yes, determine that the verification matches, and if the determination is no, determine that the verification does not match.
[0023] Optionally, a computer device is further provided, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the above file storage encryption management method are implemented.
[0024] Optionally, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above file storage encryption management method are implemented.
[0025] The technical effects of the present invention are as follows: For the above file storage encryption management method and system, during the vehicle use process, real-time dynamic biometric data of the in-vehicle user and real-time interaction behavior data between the in-vehicle user and the in-vehicle electronic device are obtained, and a real-time feature vector is generated according to the real-time interaction behavior data and the real-time dynamic biometric data; after the vehicle use is completed, a vehicle owner feature matching factor is generated according to the real-time feature vector and the original feature vector; a vehicle owner feature dynamic key is generated according to the vehicle owner feature matching factor; the in-vehicle file to be stored is encrypted according to the vehicle owner feature dynamic key to generate an encrypted in-vehicle file, and the encrypted in-vehicle file is stored in the in-vehicle storage system. In this application, during the vehicle use process, real-time interaction behavior data associated with the vehicle owner among the in-vehicle users and the real-time dynamic biometric data are obtained, and a vehicle owner feature matching factor is generated according to the real-time feature vector and the original feature vector, so as to combine the original feature vector that can represent the historical use state of the vehicle owner with the real-time feature vector that can represent the current actual features, so that the generated vehicle owner feature matching factor can more accurately represent the true features of the vehicle owner in the past state and the current state. Furthermore, a vehicle owner feature dynamic key can be generated according to the vehicle owner feature matching factor, and then the in-vehicle file to be stored is encrypted according to the vehicle owner feature dynamic key to generate an encrypted in-vehicle file, and the encrypted in-vehicle file is stored in the in-vehicle storage system. Subsequently, if it is necessary to access the files in the in-vehicle storage system, the current access feature data and current access interaction data of the visitor to be confirmed need to be collected, and a current access dynamic key is generated. Only when it is verified that the current access dynamic key matches the vehicle owner feature dynamic key, can the visitor to be confirmed be allowed to access the in-vehicle storage system, thus solving the problem of vehicle information leakage in the prior art, because in the prior art, vehicle owner authentication generally uses one of the face recognition, car key recognition, and NFC recognition methods. After the face recognition camera is blocked by a non-vehicle owner, after using the car key for vehicle owner authentication, the non-vehicle owner can perform identity recognition in the identity of the non-vehicle owner himself, resulting in vehicle information leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is a schematic flowchart of a file storage encryption management method in an embodiment; Figure 2 It is a structural block diagram of a file storage encryption management system in an embodiment. DETAILED DESCRIPTION
[0027] In the following description, for purposes of illustration and not limitation, specific details such as particular system architectures, technologies, etc. are set forth in order to provide a thorough understanding of embodiments of the present application. However, those skilled in the art should understand that the present application may be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the present application with unnecessary details.
[0028] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their combinations.
[0029] It should also be understood that the term "and / or" as used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0030] As used in the specification of the present application and the appended claims, the term "if" may be construed, depending on the context, as "when" or "once" or "in response to determining" or "in response to detecting". Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, as meaning "once determined" or "in response to determining" or "once [the described condition or event] is detected" or "in response to detecting [the described condition or event]".
[0031] In addition, in the description of the specification of the present application and the appended claims, the terms "first", "second", "third", etc. are used only for descriptive distinction and should not be construed as indicating or implying relative importance.
[0032] Reference to "an embodiment" or "some embodiments" or the like described in the specification of the present application means that a particular feature, structure, or characteristic described in connection with the embodiment is included in one or more embodiments of the present application. Thus, statements such as "in an embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in another way. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in another way.
[0033] In one embodiment, a terminal is provided, which is used for: during vehicle use, acquiring real-time dynamic biometric data of the in-vehicle user and real-time interaction behavior data between the in-vehicle user and in-vehicle electronic devices, and generating a real-time feature vector based on the real-time interaction behavior data and the real-time dynamic biometric data; after vehicle use is completed, generating an owner feature matching factor based on the real-time feature vector and an original feature vector; generating an owner feature dynamic key based on the owner feature matching factor; encrypting the to-be-stored vehicle-mounted file according to the owner feature dynamic key to generate an encrypted vehicle-mounted file, and storing the encrypted vehicle-mounted file in the vehicle-mounted storage system.
[0034] The terminal can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices.
[0035] In one embodiment, as Figure 1 shown, a file storage encryption management method is provided, which is applied to a vehicle-mounted storage system. The method includes: Step S100: During vehicle use, acquire real-time dynamic biometric data of the in-vehicle user and real-time interaction behavior data between the in-vehicle user and in-vehicle electronic devices, and generate a real-time feature vector based on the real-time interaction behavior data and the real-time dynamic biometric data; Step S200: After vehicle use is completed, generate an owner feature matching factor based on the real-time feature vector and an original feature vector; Step S300: Generate an owner feature dynamic key based on the owner feature matching factor; Step 400: Encrypt the to-be-stored vehicle-mounted file according to the owner feature dynamic key to generate an encrypted vehicle-mounted file, and store the encrypted vehicle-mounted file in the vehicle-mounted storage system.
[0036] In this embodiment, during the vehicle usage, real-time interaction behavior data associated with the vehicle owner among the in-vehicle users and the real-time dynamic biometric data are acquired, and a vehicle owner feature matching factor is generated based on the real-time feature vector and the original feature vector, so as to combine the original feature vector capable of representing the historical usage state of the vehicle owner with the real-time feature vector capable of representing the current actual features, enabling the generated vehicle owner feature matching factor to more accurately represent the true features of the vehicle owner in the past and current states. Furthermore, a vehicle owner feature dynamic key can be generated according to the vehicle owner feature matching factor, and then the vehicle-mounted files to be stored are encrypted based on the vehicle owner feature dynamic key to generate encrypted vehicle-mounted files, and the encrypted vehicle-mounted files are stored in the vehicle-mounted storage system. Subsequently, if it is necessary to access the files in the vehicle-mounted storage system, the current access feature data and current access interaction data of the visitor to be confirmed need to be collected, and a current access dynamic key is generated. Only when it is verified that the current access dynamic key matches the vehicle owner feature dynamic key can the visitor to be confirmed be allowed to access the vehicle-mounted storage system, thereby solving the problem in the prior art that since the vehicle owner authentication generally adopts one of the methods of face recognition, car key recognition, and NFC recognition, when a non-vehicle owner covers the face recognition camera, after using the car key for vehicle owner authentication, the non-vehicle owner can perform identity recognition in the identity of the non-vehicle owner himself, resulting in the leakage of vehicle-mounted information.
[0037] In one embodiment, in step S100, acquiring the real-time dynamic biometric data of the in-vehicle users includes: Step S111: During the vehicle usage, acquire the set of biometric features to be evaluated of the in-vehicle users, where the set of biometric features to be evaluated includes multiple candidate biometric features; Step S112: Construct a multi-modal behavior resonance matrix based on the set of biometric features to be evaluated; Step S113: Calculate the accuracy score of each candidate biometric feature according to the multi-modal behavior resonance matrix; Step S114: Set the candidate biometric features corresponding to the accuracy scores greater than or equal to the preset score threshold as the real-time dynamic biometric data.
[0038] In this embodiment, during the use of the vehicle, a set of biometric features to be evaluated of the in-vehicle user is obtained. The set of biometric features to be evaluated is a preliminary acquisition of various possible biometric features of the vehicle owner. The set of biometric features to be evaluated may include features of non-owner individuals. If it is directly set as the features of the vehicle owner, it will lead to inaccurate problems in subsequent file encryption and decryption. Therefore, it is necessary to screen each of the candidate biometric features in the set of biometric features to be evaluated. First, a multi-modal behavior resonance matrix is constructed based on the set of biometric features to be evaluated, and then the accuracy score of each candidate biometric feature is calculated. When the accuracy score is greater than or equal to the preset score threshold, it indicates that the corresponding candidate biometric feature matches other candidate biometric features. At this time, it is determined to be that of the vehicle owner himself, and thus it is set as the real-time dynamic biometric data.
[0039] The set of biometric features to be evaluated is denoted as X ca ={x1, x2, x3,..., x N}, where x1 - x N represents the feature vectors of each candidate biometric feature, and N represents the number of candidate biometric features in the set of biometric features to be evaluated. For example, x1, x2, x3, x4 respectively represent the feature vectors of the driving action trajectory, voiceprint, eye movement trajectory, or gesture movement trajectory of the vehicle owner. For other candidate biometric features, no specific examples are given.
[0040] In step S120, the multi-modal behavior resonance matrix is as follows: , where represents the multi-modal behavior resonance matrix, represents the feature vector of the candidate biometric feature and the resonance similarity between the feature vector of the candidate biometric feature, represents the preset sensitivity coefficient, represents the time stamp when the feature vector of the candidate biometric feature is collected, represents the time stamp when the feature vector of the candidate biometric feature is collected.
[0041] By setting an exponential function form in the multi-modal behavior resonance matrix to amplify subtle differences, candidate biometric features with high similarity can be screened out. The preset sensitivity coefficient can be adjusted in real time by those skilled in the art to flexibly control the sensitivity to the differences between candidate biometric features. For the value of the sensitivity coefficient , no specific numerical limit is set in this application. Represents the time decay factor. Features collected closer to the current time are more reliable. By setting the time decay factor, it is ensured that features adjacent in time have greater weights, reflecting that real owner behaviors in reality usually exhibit temporal continuity.
[0042] Feature vector of the biometric to be selected And the feature vector of the biometric to be selected Resonance similarity between them The formula is calculated as follows: , Where, Represents the dot product between two feature vectors, Represents the modulus length of the feature vector of the biometric to be selected of, Represents the feature vector of the biometric to be selected of the modulus length, Represents a very small positive number, used to prevent the denominator from being 0, Represents the feature vector of the biometric to be selected And the feature vector of the biometric to be selected Normalized index of the number of synchronized trigger events within the same time window, The larger the value of, the stronger the synchronization between the two. The value of is limited to [0, 1].
[0043] In one embodiment, The calculation formula of is as follows: , Where, Represents the feature vector of the biometric to be selected And the feature vector of the biometric to be selected Number of events that occur simultaneously within the same time window, Represents the feature vector of the biometric to be selected Corresponding number of events, Represents the feature vector of the biometric to be selected Number of events of, Represents a very small positive number.
[0044] If any of the corresponding event numbers in the feature vector of the biometric to be selected And the feature vector of the biometric to be selected is scarce, The setting of can suppress the false amplification of the overlap rate by dense features and improve the accuracy of the result.
[0045] In step S130, calculate the accuracy score of the biometric to be selected based on the following formula: , Among them, represents the accuracy score of the biometric feature to be selected , represents the sum of the resonance matrix element values of all other feature vectors except in the set of biometric features to be evaluated. For example, when N = 3, at this time X ca ={x1, x2, x3}, then ,for x2, then , For x3, then
[0046] Therefore, by setting the accuracy score to measure the overall credibility of using the average value of the resonance values of all other features except .
[0047] In another embodiment, in step S140, the preset scoring threshold is set by those skilled in the art in advance
[0048] In another embodiment, an example of a method for setting the preset scoring threshold: Obtain the accuracy scores of all biometric features to be selected, calculate the mean and standard deviation, and set the preset scoring threshold according to the mean and standard deviation. For example, the preset scoring threshold can be calculated by the following formula: .
[0049] Among them, is a preset threshold coefficient, generally set to a value between 0.5 and 1, such as 0.7
[0050] The real-time dynamic biometric data is represented in the form of a set, specifically represented as B = {b1, b2, b3,..., b n}. The real-time dynamic biometric data includes n real-time biometric features b1, b2, b3,..., b n .
[0051] In one embodiment, in step S100, obtain the real-time interaction behavior data between the in-vehicle user and the in-vehicle electronic device, including: Step S121: Obtain the device trigger instruction triggered by the in-vehicle user for the in-vehicle electronic device; Step S122: Collect information according to the device trigger instruction and generate real-time interaction behavior data
[0052] In this embodiment, it includes but is not limited to multimedia operation habits, such as volume adjustment trajectory, song switching frequency, air conditioner setting behaviors, such as common temperature adjustment ranges, center console touch behaviors, such as touch speed, position distribution, operation gestures, and can also include navigation path selection preferences, etc. In this embodiment, the real-time interaction behavior data is represented in the form of a set, specifically represented as I = {k1, k2, k3,..., k m}. The real-time interaction behavior data includes m real-time interaction features k1, k2, k3,..., k m .
[0053] In one embodiment, in step S100, generating a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data includes: Step S110: Obtain a preset non-linear hashing function; Step S120: Generate a real-time feature vector according to the non-linear hashing function based on the real-time interaction behavior data and the real-time dynamic biometric data.
[0054] In this embodiment, the real-time feature vector is generated based on the following formula: , where, represents the real-time feature vector, represents the non-linear hashing function, which is used to reduce the dimension and compress the feature space, represents the behavior feature weight of the i-th real-time biometric feature, represents the i-th real-time biometric feature, represents the interaction feature weight of the j-th real-time interaction feature, represents the j-th real-time interaction feature, and the interaction feature weights of each of the real-time interaction features and the behavior feature weights of each of the real-time biometric features are preset by those skilled in the art themselves.
[0055] represents the weighted sum of all features, is used for normalization to ensure the consistency of the output vector strength.
[0056] By fusing all the vehicle owner behavior features and interaction features in proportion into a unified vector, the confidentiality during file encryption is improved, and further decryption of the file by non-vehicle owners is avoided.
[0057] Preferably, the non-linear hashing function adopts the SHA-3 or BLAKE3 hashing function.
[0058] In another embodiment, step S200: After the vehicle is used, generating an owner feature matching factor according to the real-time feature vector and the original feature vector, including: Step S210: Obtain a preset non-linear mapping function; Step S220: Generate an owner feature matching factor according to the real-time feature vector and the original feature vector according to the non-linear mapping function.
[0059] In this embodiment, based on the following formula, an owner feature matching factor is generated according to the real-time feature vector and the original feature vector according to the non-linear mapping function: , Wherein, represents the owner feature matching factor, represents the non-linear mapping function, represents the original feature vector.
[0060] represents the dot product calculation of the real-time feature vector and the original feature vector, and is used to represent the degree of coincidence in the same direction. represents the modulus length of the original feature vector, represents the modulus length of the real-time feature vector, represents the product of the modulus lengths of the original feature vector and the real-time feature vector, and is used to normalize the dot product, and the output range is limited to [-1, 1]. represents the direction similarity between the current operation and the owner's behavior.
[0061] In this embodiment, the original feature vector is preset. By separately collecting information from the owner in advance, specifically, collecting the same real-time interaction behavior data and real-time dynamic biometric data as in step S100. Since the information is collected separately from the owner, the actual collected data is the real-time dynamic biometric data, and there is no need to perform the data filtering steps from step S111 to step S114. Since the setting steps of the original feature vector are the same as the steps in step S100, those skilled in the art should understand how to set it. Therefore, this application will not elaborate on the setting of the original feature vector .
[0062] Preferably, the non-linear mapping function adopts the hyperbolic tangent function or the Sigmoid scaling function.
[0063] In one embodiment, step S300: Generating an owner feature dynamic key according to the owner feature matching factor, including: Step S310: Obtain the system clock value and the hardware random number sequence, where the hardware random number sequence is generated by the in-vehicle device security chip; Step S320: Construct an encryption mapping function according to the vehicle owner feature matching factor, the system clock value, and the hardware random number sequence; Step S330: Generate a vehicle owner feature dynamic key according to the encryption mapping function and the key derivation function.
[0064] In this embodiment, in order to solve the problem in the prior art that directly generating a key from behavioral features or identity factors results in insufficient entropy of the key, thereby causing the problem that it may be predicted. Therefore, in this application, the system clock value and the hardware random number sequence generated by the in-vehicle device security chip are obtained, and an encryption mapping function is constructed according to the vehicle owner feature matching factor, the system clock value, and the hardware random number sequence, so that the generated vehicle owner feature dynamic key has stronger unpredictability and significantly improves security.
[0065] The system clock value is the system real-time clock of the in-vehicle system, which can be accurate to milliseconds. The hardware random number sequence is a 256-bit hardware random number generated in real time by the in-vehicle TPM chip.
[0066] The encryption mapping function is as follows: , represents the output value of the encryption mapping function based on the vehicle owner feature matching factor of, represents a 512-bit secure hash function, such as SHA-512, represents the vehicle owner feature matching factor, represents the bitwise exclusive OR operation, represents a 256-bit hardware random number generated in real time by the in-vehicle TPM chip, represents the bit-level cross mixing operator, represents the preset system frequency, represents the phase constant preset by the system, t represents the system clock value, represents the non-linear time series modulation function based on the real-time clock.
[0067] The key derivation function is HKDF or PBKDF2. The formula for generating the vehicle owner feature dynamic key is as follows: ,where, represents the vehicle owner feature dynamic key, represents the key derivation function.
[0068] In this embodiment, by setting an encryption mapping function, on the one hand, it combines identity factors, hardware random numbers, and real-time clocks to achieve multi-dimensional entropy sources, ensuring that the key is difficult to predict. On the other hand, based on the dynamic mapping of the millisecond-level real-time clock, the key is different every millisecond, further improving the encryption level. It also uses a non-linear timing modulation function to achieve non-linear modulation, solving the problem of easy cracking caused by simple splicing or linear combination in the prior art. It also uses the combined use of bit-level cross-mixing operators and exclusive-or operations to further greatly increase the randomness of the key and the characteristic of being difficult to reverse. Finally, it outputs 512-bit random entropy through a high-strength hash function, thereby achieving further enhanced security for KDF.
[0069] In one embodiment, step 400: Encrypt the vehicle-mounted file to be stored according to the dynamic key of the vehicle owner feature to generate an encrypted vehicle-mounted file, including: Step S410: Obtain a preset symmetric encryption algorithm; Step S420: Encrypt the vehicle-mounted file to be stored according to the symmetric encryption algorithm and the dynamic key of the vehicle owner feature to generate an encrypted vehicle-mounted file.
[0070] In this embodiment, based on the following formula, encrypt the vehicle-mounted file to be stored according to the symmetric encryption algorithm and the dynamic key of the vehicle owner feature to generate an encrypted vehicle-mounted file: ; where, is the encrypted vehicle-mounted file, is the symmetric encryption algorithm, is the dynamic key of the vehicle owner feature, is the vehicle-mounted file to be stored.
[0071] Preferably, the symmetric encryption algorithm is AES-256-GCM.
[0072] It should be noted that for various algorithms in this application, only examples are given and no limitations are made. Those skilled in the art should be able to select other algorithms for encryption according to the actual situation.
[0073] In one embodiment, the method further includes: Step S510: In response to a to-be-confirmed visitor accessing the vehicle-mounted storage system, collect the current access feature data and current access interaction data of the to-be-confirmed visitor; Step S520: Generate a current access dynamic key according to the current access feature data and the current access interaction data; Step S530: Verify whether the current access dynamic key matches the dynamic key of the vehicle owner feature; Step S540: If the verification matches, allow the to-be-verified visitor to access the vehicle-mounted storage system; Step S550: If the verification does not match, reject the to-be-verified visitor from accessing the vehicle-mounted storage system.
[0074] In this embodiment, through the pre-set file encryption mode, after the file is encrypted and stored, if a user needs to access it later, verification is required. Specifically, the current access feature data and current access interaction data of the to-be-verified visitor are collected; a current access dynamic key is generated according to the current access feature data and the current access interaction data; it is verified whether the current access dynamic key matches the vehicle owner feature dynamic key. If the verification matches, allow the to-be-verified visitor to access the vehicle-mounted storage system.
[0075] The current access interaction data can prompt the to-be-verified visitor according to the real-time interaction behavior data. Taking the air conditioner setting behavior as an example, when the to-be-verified visitor accesses the vehicle-mounted storage system, set the air conditioner to a setting method different from the real-time interaction behavior data, and obtain the setting and adjustment of the air conditioner based on the current access feature data. If it is the vehicle owner himself / herself, he / she will probably adjust according to the air conditioner setting behavior corresponding to the real-time interaction behavior data. Otherwise, other adjustment data can be obtained and combined with other interaction parameters to determine that it is not the vehicle owner, and thus access is rejected.
[0076] In one embodiment, the method further includes: Step S530: Verify whether the current access dynamic key matches the vehicle owner feature dynamic key, including: Step S531: Calculate the Euclidean distance between the current access dynamic key and the vehicle owner feature dynamic key; Step S532: Generate a key difference metric value according to the Euclidean distance; Step S533: Determine whether the key difference metric value is greater than a preset difference threshold; Step S534: If the judgment is yes, judge that the verification matches; if the judgment is no, judge that the verification does not match.
[0077] In this embodiment, the Euclidean distance between the current access dynamic key and the vehicle owner feature dynamic key is calculated based on the following formula: .
[0078] Among them, represents the vehicle owner feature dynamic key, represents the current access dynamic key, represents the Euclidean distance calculation.
[0079] The key difference metric value is generated according to the Euclidean distance based on the following formula: , where is the key difference metric value, representing the similarity score, ranging from 0 to 1. The larger the value, the more similar the current access dynamic key is to the vehicle owner's characteristic dynamic key. The preset difference threshold is set in advance, such as set to 0.9. When it is determined that the key difference metric value is greater than the preset difference threshold, it indicates that the current access dynamic key is very similar to the vehicle owner's characteristic dynamic key. Therefore, at this time, it is determined that the verification is matched, and the to-be-confirmed visitor is allowed to access the vehicle-mounted storage system. On the contrary, it is determined that the verification is not matched, and the to-be-confirmed visitor is refused to access the vehicle-mounted storage system.
[0080] In one embodiment, as Figure 2 shown, there is also provided a file storage encryption management system, which includes: A feature vector generation module, which is used to obtain the real-time dynamic biometric data of the in-vehicle user and the real-time interaction behavior data between the in-vehicle user and the in-vehicle electronic device during the vehicle use process, and generate a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data; A matching factor generation module, which is used to generate a vehicle owner's characteristic matching factor according to the real-time feature vector and the original feature vector after the vehicle use is completed; A dynamic key generation module, which is used to generate a vehicle owner's characteristic dynamic key according to the vehicle owner's characteristic matching factor; A file encryption storage module, which is used to encrypt the vehicle-mounted file to be stored according to the vehicle owner's characteristic dynamic key, generate an encrypted vehicle-mounted file, and store the encrypted vehicle-mounted in the vehicle-mounted storage system.
[0081] In another embodiment, the feature vector generation module is further used to: during the vehicle use process, obtain the to-be-evaluated biometric feature set of the in-vehicle user, where the to-be-evaluated biometric feature set includes multiple candidate biometric features; construct a multi-modal behavior resonance matrix according to the to-be-evaluated biometric feature set; calculate the accuracy score of each candidate biometric feature according to the multi-modal behavior resonance matrix; set the candidate biometric feature corresponding to the accuracy score greater than or equal to the preset score threshold as the real-time dynamic biometric data.
[0082] In another embodiment, the feature vector generation module is further used to: obtain the device trigger instruction for the in-vehicle user to trigger the in-vehicle electronic device; collect information according to the device trigger instruction and generate real-time interaction behavior data.
[0083] In another embodiment, the feature vector generation module is further used to: obtain a preset non-linear hash function; generate a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data according to the non-linear hash function.
[0084] In another embodiment, the matching factor generation module is further configured to: obtain a preset non-linear mapping function; generate a vehicle owner feature matching factor according to the real-time feature vector and the original feature vector based on the non-linear mapping function.
[0085] In another embodiment, the dynamic key generation module is further configured to: obtain a system clock value and a hardware random number sequence, where the hardware random number sequence is generated by a vehicle-mounted device security chip; construct an encryption mapping function according to the vehicle owner feature matching factor, the system clock value, and the hardware random number sequence; generate a vehicle owner feature dynamic key according to the encryption mapping function and a key derivation function.
[0086] In another embodiment, the file encryption storage module is further configured to: obtain a preset symmetric encryption algorithm; encrypt a vehicle-mounted file to be stored according to the symmetric encryption algorithm using the vehicle owner feature dynamic key to generate an encrypted vehicle-mounted file.
[0087] In another embodiment, the file encryption storage module is further configured to: in response to a to-be-confirmed visitor accessing the vehicle-mounted storage system, collect current access feature data and current access interaction data of the to-be-confirmed visitor; generate a current access dynamic key according to the current access feature data and the current access interaction data; verify whether the current access dynamic key matches the vehicle owner feature dynamic key; if the verification matches, allow the to-be-confirmed visitor to access the vehicle-mounted storage system; if the verification does not match, reject the to-be-confirmed visitor from accessing the vehicle-mounted storage system.
[0088] In another embodiment, the file encryption storage module is further configured to: calculate the Euclidean distance between the current access dynamic key and the vehicle owner feature dynamic key; generate a key difference metric value according to the Euclidean distance; determine whether the key difference metric value is greater than a preset difference threshold; if the determination is yes, determine that the verification matches, and if the determination is no, determine that the verification does not match.
[0089] It should be noted that, for the information interaction, execution process, etc. between the above modules, since they are based on the same concept as the method embodiment of the present application, for their specific functions and the technical effects brought, reference may be specifically made to the method embodiment part, and details are not described herein again.
[0090] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0091] It should be noted that the information interaction, execution process, etc. between the above-mentioned modules, due to the same concept as the method embodiment of the present application, for their specific functions and the technical effects brought, reference can be made to the method embodiment part, and details will not be elaborated herein.
[0092] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0093] The embodiment of the present application also provides a network device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, the steps in any of the foregoing method embodiments are implemented.
[0094] The embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in each of the foregoing method embodiments can be implemented.
[0095] An embodiment of the present application provides a computer program product. When the computer program product runs on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned method embodiments when executed.
[0096] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-mentioned method embodiments of the present application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.
[0097] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0098] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0099] In the embodiments provided in this application, it should be understood that the disclosed device / network device and method can be implemented in other ways. For example, the device / network device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0100] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0101] The above-described embodiments are only used to illustrate the technical solutions of this application and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application and should all be included in the protection scope of this application.
[0102] An embodiment of this application also provides a computer device. The computer device of this embodiment includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, it implements the steps in any of the above method embodiments.
[0103] The computer device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above description is an example of a computer device and does not constitute a limitation on the computer device. It may include more or fewer components than the above description, or combine some components, or different components. For example, it may also include input / output devices, network access devices, etc.
[0104] The so-called processor may be a Central Processing Unit (CPU), and this processor 0 may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0105] In some embodiments, the memory may be an internal storage unit of the computer device, such as the hard disk or memory of the computer device. In other embodiments, the memory may also be an external storage device of the computer device, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the computer device. Further, the memory may also include both the internal storage unit and the external storage device of the computer device. The memory is used to store an operating system, application programs, a BootLoader, data, and other programs, such as the program code of the computer program, etc. The memory may also be used to temporarily store data that has been output or will be output.
[0106] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0107] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A file storage encryption management method, characterized in that, Applied to an in-vehicle storage system, the method includes: During vehicle use, obtain the real-time dynamic biometric data of the in-vehicle user and the real-time interaction behavior data between the in-vehicle user and the in-vehicle electronic device, and generate a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data; After vehicle use is completed, generate an owner feature matching factor according to the real-time feature vector and the original feature vector; Generate an owner feature dynamic key according to the owner feature matching factor; Encrypt the in-vehicle file to be stored according to the owner feature dynamic key to generate an encrypted in-vehicle file, and store the encrypted in-vehicle file in the in-vehicle storage system.
2. The file storage encryption management method according to claim 1, wherein Obtain the real-time dynamic biometric data of the in-vehicle user, including: During vehicle use, obtain the set of biometric features to be evaluated of the in-vehicle user, where the set of biometric features to be evaluated includes multiple candidate biometric features; Construct a multi-modal behavior resonance matrix according to the set of biometric features to be evaluated; Calculate the accuracy score of each candidate biometric feature according to the multi-modal behavior resonance matrix; Set the candidate biometric features corresponding to the accuracy scores greater than or equal to the preset score threshold as the real-time dynamic biometric data.
3. The file storage encryption management method according to claim 1, wherein, Generate a real-time feature vector according to the real-time interaction behavior data and the real-time dynamic biometric data, including: Obtain a preset non-linear hash function; Generate a real-time feature vector according to the non-linear hash function according to the real-time interaction behavior data and the real-time dynamic biometric data.
4. The file storage encryption management method according to claim 1, wherein Generate an owner feature matching factor according to the real-time feature vector and the original feature vector, including: Obtain a preset non-linear mapping function; Generate an owner feature matching factor according to the non-linear mapping function according to the real-time feature vector and the original feature vector.
5. The file storage encryption management method according to claim 1, characterized in that, Encrypt the in-vehicle file to be stored according to the owner feature dynamic key to generate an encrypted in-vehicle file, including: Obtain a preset symmetric encryption algorithm; Encrypt the in-vehicle file to be stored according to the symmetric encryption algorithm according to the owner feature dynamic key to generate an encrypted in-vehicle file.
6. The file storage encryption management method according to claim 1, characterized in that The method further includes: In response to a pending visitor accessing the in-vehicle storage system, collect the current access feature data and the current access interaction data of the pending visitor; Generate a current access dynamic key according to the current access feature data and the current access interaction data; Verify whether the current access dynamic key matches the owner feature dynamic key; If the verification matches, allow the pending visitor to access the in-vehicle storage system; If the verification does not match, reject the pending visitor from accessing the in-vehicle storage system.
7. The file storage encryption management method according to claim 6, characterized in that, The method further includes: verifying whether the current access dynamic key matches the owner feature dynamic key, including: Calculate the Euclidean distance between the current access dynamic key and the owner feature dynamic key; Generate a key difference metric value according to the Euclidean distance; Determine whether the key difference metric value is greater than a preset difference threshold; If the determination is yes, determine that the verification matches, and if the determination is no, determine that the verification does not match.
8. A file storage encryption management system, characterized in that, The system includes: A feature vector generation module, which is used to obtain real-time dynamic biometric data of in-vehicle users and real-time interaction behavior data between in-vehicle users and in-vehicle electronic devices during vehicle use, and generate real-time feature vectors according to the real-time interaction behavior data and the real-time dynamic biometric data; A matching factor generation module, which is used to generate an owner feature matching factor according to the real-time feature vector and the original feature vector after vehicle use; A dynamic key generation module, which is used to generate an owner feature dynamic key according to the owner feature matching factor; A file encryption and storage module, which is used to encrypt the vehicle-mounted file to be stored according to the owner feature dynamic key to generate an encrypted vehicle-mounted file, and store the encrypted vehicle-mounted file in the vehicle-mounted storage system.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.