Highway networking toll collection data transmission method and device
The encrypted data packets are generated through public key encryption and symmetric key encryption combined with digest algorithms, which solves the problem of insufficient security in the transmission of highway networked toll data, realizes the confidentiality, integrity and undeniability of the data, and improves transmission security by regularly updating the symmetric key.
Patent Information
- Application Number
- CN202510367933.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-08-08
AI Technical Summary
In the prior art, highway networked toll data lacks effective security during transmission, especially confidentiality, integrity and undeniability cannot be guaranteed.
The combination of public key encryption, symmetric key encryption and digest algorithms is adopted to generate data digests and sign, encrypt transaction data, form encrypted data packets, and transmit them through a dedicated protocol, while achieving timing updates of symmetric keys.
Ensure the confidentiality, integrity and undeniability of highway networked toll data, improve the security of data transmission, and further enhance the security through timed updates of symmetric keys.
Smart Images

Figure CN120454981A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of highway transaction data, and in particular to a method and device for transmitting highway network toll data. Background Art
[0002] After the cancellation of provincial highway toll stations, the country's highways have entered a new stage of "one network operation, integrated service". Toll data relies on wide-area wireless networks for dynamic transmission, exposing more complex security threats, namely, the confidentiality, integrity and non-repudiation of a large amount of networked toll data cannot be effectively guaranteed.
[0003] Currently, a large amount of networked toll collection data is aggregated at provincial and ministerial network centers. Although transmitted within industry-specific networks, it is typically transmitted in plain text, making it difficult to guarantee data security during transmission. Therefore, improving the security of networked toll collection data transmission for highways is a pressing technical challenge. Summary of the Invention
[0004] In view of this, an embodiment of the present invention provides a method and apparatus for transmitting data for networked highway toll collection, so as to eliminate or improve one or more defects in the prior art.
[0005] One aspect of the present invention provides a method for transmitting networked toll data on expressways, the method comprising:
[0006] The toll station security device generates a first public key, a first private key, and a first symmetric key, and receives a second public key sent by the road network service security center. The toll station security device encrypts the first symmetric key based on the second public key to obtain a first symmetric key ciphertext. The toll station security device sends the first public key and the first symmetric key ciphertext to the road network service security center, so that the road network service security center sends the first public key and the first symmetric key to the provincial network center security device.
[0007] The toll station security device receives first transaction data sent by the toll station application, generates a first data digest based on the first transaction data using a digest algorithm, signs the first data digest using the first private key to obtain first signature data, and encrypts the first signature data and the first transaction data using the first symmetric key to obtain a first data ciphertext;
[0008] The toll station security device assembles the first data ciphertext and the first protocol header to obtain an encrypted data packet, and the encrypted data packet is used to send to the provincial network center application corresponding to the provincial network center security device; wherein, the first protocol header includes the number information of the toll station security device and the first public key information.
[0009] In some embodiments of the present invention, the method comprises:
[0010] The provincial network center security device generates a third public key and a third private key, and sends the third public key to the road network business security center;
[0011] The road network service security center decrypts the first symmetric key ciphertext based on its second private key to obtain a decrypted second symmetric key, and re-encrypts the decrypted second symmetric key based on the third public key to obtain a second symmetric key ciphertext. The road network service security center is used to send the second symmetric key ciphertext to the provincial network center security device, so that the provincial network center security device decrypts the second symmetric key ciphertext based on the third private key to obtain a decrypted third symmetric key.
[0012] In some embodiments of the present invention, the method comprises:
[0013] The provincial network center security device receives the encrypted data packet sent by the provincial network center application, and parses the encrypted data packet to obtain the parsed second protocol header and the second data ciphertext;
[0014] The provincial network center security device decrypts the second data ciphertext based on the third symmetric key to obtain second transaction data, and sends the second transaction data to the provincial network center application.
[0015] In some embodiments of the present invention, sending the second transaction data to the provincial network center application includes:
[0016] The provincial network center security device generates a second data digest based on the second transaction data through a digest algorithm, and decrypts the first signature data based on the first public key to obtain the decrypted first data digest. The provincial network center security device compares the second data digest and the first data digest, and sends the second transaction data to the provincial network center application if the second data digest and the first data digest are consistent.
[0017] In some embodiments of the present invention, the method comprises:
[0018] The toll station security device obtains the symmetric key update request sent by the road network service security center, and the toll station security device updates the first symmetric key based on the symmetric key update request to obtain an updated symmetric key.
[0019] In some embodiments of the present invention, the toll station security device updates the first symmetric key based on the symmetric key update request to obtain an updated symmetric key, including:
[0020] The toll station security device determines whether the first symmetric key meets the update condition;
[0021] When the update conditions are met and an update confirmation notification sent by the provincial network center security device is received, the first symmetric key is updated to obtain an updated symmetric key.
[0022] In some embodiments of the present invention, the key update request includes a key update frequency or a key update interval.
[0023] In some embodiments of the present invention, the digest algorithm is the SM3 cryptographic digest algorithm.
[0024] According to another aspect of the present invention, a highway network toll collection data transmission system is also disclosed. The system includes a processor, a memory, and a computer program stored in the memory. The processor is used to execute the computer program. When the computer program is executed, the system implements the steps of the method described in any of the above embodiments.
[0025] According to yet another aspect of the present invention, a computer-readable storage medium is disclosed, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in any of the above embodiments are implemented.
[0026] In the method for transmitting networked highway toll data disclosed in the above-mentioned embodiment of the present invention, toll station security equipment generates a data digest based on transaction data using a digest algorithm, signs the data digest using its private key to obtain signature data, and encrypts the signature data and transaction data using a symmetric key to obtain data ciphertext. The data ciphertext is then assembled with a protocol header to obtain an encrypted data packet, which is then sent to a provincial network center application. This method ensures that networked highway toll data is transmitted in ciphertext, thereby protecting the confidentiality, integrity, and non-repudiation of the data and improving the security of data transmission.
[0027] In addition to the above, the highway network toll data transmission method also obtains a symmetric key update request sent by the road network business security center, and the toll station security device updates the first symmetric key based on the symmetric key update request to obtain an updated symmetric key; this method enables the toll station security device to update the symmetric key based on the update request, ensuring the distribution security of the symmetric key, thereby further improving the security of data transmission.
[0028] Additional advantages, objects, and features of the present invention will be set forth in part in the following description and will become apparent to those skilled in the art upon examination of the following or may be learned from practice of the present invention. The objects and other advantages of the present invention may be realized and obtained by the structures particularly pointed out in the description and drawings.
[0029] Those skilled in the art will understand that the purposes and advantages that can be achieved by the present invention are not limited to the above specific descriptions, and the above and other purposes that can be achieved by the present invention will be more clearly understood based on the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The drawings described herein are intended to provide a further understanding of the present invention, constitute a part of this application, and do not constitute a limitation of the present invention. The components in the drawings are not drawn to scale, but are merely for the purpose of illustrating the principles of the present invention. To facilitate the illustration and description of some parts of the present invention, corresponding parts in the drawings may be exaggerated, that is, they may be larger than other components in an exemplary device actually manufactured according to the present invention. In the drawings:
[0031] Figure 1 This is a flow chart of a method for transmitting data for highway network toll collection according to an embodiment of the present application.
[0032] Figure 2 This is a timing diagram of a method for transmitting data for highway network toll collection according to an embodiment of the present application.
[0033] Figure 3 This is a registration flowchart of a security device according to an embodiment of the present application. DETAILED DESCRIPTION
[0034] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments and the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0035] It should also be noted that, in order to avoid obscuring the present invention due to unnecessary details, the accompanying drawings only show structures and / or processing steps closely related to the solutions according to the present invention, while other details that are not closely related to the present invention are omitted.
[0036] It should be emphasized that the term "include / comprises" when used herein refers to the existence of features, elements, steps or components, but does not exclude the existence or addition of one or more other features, elements, steps or components.
[0037] It should also be noted here that, unless otherwise specified, the term "connection" in this article can refer not only to a direct connection, but also to an indirect connection with an intermediary, and not only to a wired connection but also to a wireless connection, and the specific connection can be changed based on the actual application scenario.
[0038] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In the accompanying drawings, the same reference numerals represent the same or similar components, or the same or similar steps.
[0039] Figure 1 This is a flow chart of a method for transmitting data through a networked toll collection service of a highway according to an embodiment of the present application. Figure 1 As shown, the highway network toll collection data transmission method includes at least steps S10 to S30.
[0040] Step S10: The toll station security device generates a first public key, a first private key and a first symmetric key, and receives a second public key sent by the road network business security center. The toll station security device encrypts the first symmetric key based on the second public key to obtain a first symmetric key ciphertext. The toll station security device sends the first public key and the first symmetric key ciphertext to the road network business security center, so that the road network business security center sends the first public key and the first symmetric key to the provincial network center security device.
[0041] In order to ensure that the toll station security equipment can effectively send the public key and symmetric key ciphertext to the road network business security center, it is necessary to first install and deploy the toll station security equipment on the toll station application side, install and deploy the provincial network center security equipment on the provincial network center side, and establish the connection between the toll station security equipment and the road network business security center, and the connection between the provincial network center security equipment and the road network business security center, and complete the registration of the toll station security equipment and the provincial network center security equipment. The registration flow chart of the security equipment is as follows: Figure 3 shown.
[0042] The above-mentioned security devices are configured with a device identification ID assigned by the road network business security center when leaving the factory. This ID is the legal mark of the security device. After the security device is deployed and put into operation, the following operations are completed: power on self-test and obtain its own public key; access the road network business security center and establish a connection with the road network business security center through a private protocol; upload device information and its own public key information to the road network business security center to complete device registration; and send heartbeat information to the road network business security center at regular intervals.
[0043] In the above step S10, the toll station security device on the toll station side generates a symmetric key and a public and private key, and the road network business security center also generates its own public and private keys. The public key of the road network business security center is further sent to the toll station security device. The toll station security device encrypts the symmetric key based on the public key of the road network business security center it receives to obtain a symmetric key ciphertext, and the toll station security device sends its public key and symmetric key ciphertext to the road network business security center. Figure 2 As shown, when the road network business security center receives the public key and symmetric key ciphertext sent by the toll station security equipment, the road network business security center will decrypt the symmetric key ciphertext based on its own private key to obtain the decrypted symmetric key (the symmetric key is the first symmetric key generated by the road network business security center), and since the provincial network center security equipment on the provincial network center side is connected to the road network business security center, the road network business security center can further send the public key generated by the toll station security equipment and the decrypted symmetric key to the provincial network center security equipment.
[0044] Step S20: The toll station security device receives the first transaction data sent by the toll station application, and generates a first data digest based on the first transaction data through a digest algorithm. The toll station security device signs the first data digest based on the first private key to obtain first signature data, and encrypts the first signature data and the first transaction data based on the first symmetric key to obtain a first data ciphertext.
[0045] In this step, the toll booth application sends the specific transaction data to the toll booth security device. The toll booth security device first generates a summary of the transaction data and signs the summary using its own private key to obtain signature data. Furthermore, the toll booth security device symmetrically encrypts the signature data and the transaction data using the symmetric key it generated, producing the symmetrically encrypted data ciphertext.
[0046] Step S30: The toll station security device assembles the first data ciphertext and the first protocol header to obtain an encrypted data packet, and the encrypted data packet is used to send to the provincial network center application corresponding to the provincial network center security device; wherein, the first protocol header includes the numbering information of the toll station security device and the first public key information.
[0047] In this step, the toll station security device further assembles the protocol header with the data ciphertext obtained in step S20 to obtain an encrypted data packet for sending to the provincial network center application, wherein the protocol header includes the number information of the toll station security device and the public key of the toll station security device.
[0048] In order to ensure that the road network business security center can securely send the encrypted data packets sent by the toll station security device to the provincial network center security device, the highway network toll data transmission method can also include the following steps: the provincial network center security device generates a third public key and a third private key, and sends the third public key to the road network business security center; the road network business security center decrypts the first symmetric key ciphertext based on its second private key to obtain the decrypted second symmetric key, and re-encrypts the decrypted second symmetric key based on the third public key to obtain the second symmetric key ciphertext, and the road network business security center is used to send the second symmetric key ciphertext to the provincial network center security device, so that the provincial network center security device decrypts the second symmetric key ciphertext based on the third private key to obtain the decrypted third symmetric key.
[0049] In the above embodiment, the provincial network center security device also generates a public key and a private key, and further sends its public key to the road network business security center. The road network business security center decrypts the symmetric key ciphertext sent by the toll station security device based on its own private key to obtain the decrypted symmetric key, and re-encrypts the symmetric key based on the received public key of the provincial network center security device to obtain the re-encrypted symmetric key ciphertext. Further, the road network business security center sends the re-encrypted symmetric key ciphertext to the provincial network center security device, and the provincial network center security device decrypts the received symmetric key ciphertext based on its own private key to obtain the symmetric key.
[0050] Furthermore, the provincial network center security device receives the encrypted data packet sent by the provincial network center application, and parses the encrypted data packet to obtain the parsed second protocol header and second data ciphertext; the provincial network center security device decrypts the second data ciphertext based on the third symmetric key to obtain second transaction data, and sends the second transaction data to the provincial network center application. In this embodiment, after the provincial network center security device receives the encrypted data packet sent by the toll station security device, it parses it to obtain the protocol header and data ciphertext, and the provincial network center security device further decrypts the data ciphertext based on the symmetric key to obtain decrypted transaction data, and sends the decrypted transaction data to the provincial network center application. Based on this process, the transmission of transaction data between the toll station application and the provincial network center application is realized, and the confidentiality and integrity of the transaction data are also ensured, thereby improving the transmission security of the transaction data.
[0051] In some embodiments of the present invention, sending the second transaction data to the provincial network center application may specifically include: the provincial network center security device generates a second data digest based on the second transaction data using a digest algorithm, decrypts the first signature data based on the first public key to obtain a decrypted first data digest, and the provincial network center security device compares the second data digest with the first data digest. If the second data digest and the first data digest are consistent, the provincial network center security device sends the second transaction data to the provincial network center application. In this embodiment, the provincial network center security device generates a second data digest based on the decrypted transaction data using a digest algorithm, and further decrypts the first signature data based on the public key of the toll booth security device received from the road network service security center to obtain a decrypted first data digest. The provincial network center security device then compares the second data digest with the first data digest to determine if they are consistent. If they are consistent, the provincial network center security device further sends the decrypted transaction data to the provincial network center application. It is understood that if the second data digest and the first data digest are inconsistent, the provincial network center security device will not send the transaction data to the provincial network center application. Exemplarily, the digest algorithm is the SM3 cryptographic digest algorithm. At this time, the provincial network center security device generates a second data digest based on the second transaction data through the SM3 cryptographic digest algorithm; similarly, the toll station security device can also generate a first data digest based on the first transaction data through the SM3 cryptographic digest algorithm; it can be understood that the above-mentioned generation of the first data digest and the second data digest through the SM3 cryptographic digest algorithm is only an example. In some other embodiments, the first summary data and the second summary data can also be generated through other digest algorithms.
[0052] In addition, to ensure the security of the symmetric key and to ensure that the networked toll collection service can be updated in real time based on the symmetric key, the toll station security device and the provincial network center security device in this application further implement symmetric key negotiation, thereby negotiating and updating the symmetric key according to the set symmetric key update frequency. Specifically, the highway networked toll collection data transmission method also includes the following steps: the toll station security device obtains a symmetric key update request sent by the road network service security center, and the toll station security device updates the first symmetric key based on the symmetric key update request to obtain an updated symmetric key.
[0053] In the above embodiment, the distribution of symmetric keys does not adopt the traditional mode of distribution from superiors to subordinates (offline import or direct embedding in hardware devices). Instead, when the two business parties interact with data, they generate temporary symmetric keys by calling their respective security devices, and call the service of the business security center through a proprietary interaction protocol (including security device information, etc.) to complete the negotiation of the symmetric keys between the two business parties. In addition, according to the different requirements of different business scenarios for symmetric keys, a timed update mechanism for symmetric keys is implemented to ensure the security of the symmetric keys themselves, thereby further ensuring the safe and reliable transmission of business data. Exemplarily, the toll station security device updates the first symmetric key based on the symmetric key update request to obtain an updated symmetric key, including: the toll station security device determines whether the first symmetric key meets the update conditions; when the update conditions are met and the update confirmation notification sent by the provincial network center security device is received, the first symmetric key is updated to obtain an updated symmetric key. In this embodiment, the toll station security device updates the symmetric password again after receiving the update request and negotiating and confirming with the provincial network center security device. Specifically, the key update request includes the key update frequency or the key update interval, that is, the toll station security device can update the symmetric key based on the set key update frequency, and can also update the symmetric key based on the set key update interval.
[0054] Figure 2 This is a timing diagram of a method for transmitting data in a networked toll collection system for a specific embodiment of the present application. In this embodiment, taking the transmission of transaction data from application A (using security device A) at a toll station to application B (using security device B) at a provincial network center as an example, the data transmission process specifically includes the following steps:
[0055] 1. Initialization: Install and deploy security device A (located at the toll station) and security device B (located at the provincial network center), register and go online, and transform application A and application B.
[0056] Security device: built-in business security center's public key PK1, public and private keys.
[0057] 2. Security device A generates a temporary key KEY1 (symmetric key) for symmetric encryption. Application A uses KEY1 to encrypt data transmission:
[0058] ① Application A calls the interface of security device A and sends transaction data to security device A;
[0059] Security device A uses digest algorithm SM3 to generate digest 1 of the transaction data.
[0060] Security device A signs digest 1 using its own private key PriKeyA.
[0061] Security device A uses KEY1 to encrypt the signature and data information to obtain ciphertext A;
[0062] Security device A assembles ciphertext A and protocol header HeadA (containing the device number of security device A and information such as the public key of security device A) according to the protocol to obtain Base64-encoded ciphertext A'.
[0063] ② Apply A to obtain ciphertext A'.
[0064] ③ Application A sends ciphertext A' to application B.
[0065] ④ After receiving the ciphertext, application B sends ciphertext A' to security device B.
[0066] ⑤ Security device B parses ciphertext A', obtains protocol header HeadA, and determines whether key KEY1 has been obtained; if so, it jumps to step ⑦; if not, it continues to step ⑥.
[0067] ⑥ Request the business security center and send the protocol header HeadA information; the security center obtains the key KEY1, encrypts it with the public key of security device B, and returns it to security device B.
[0068] ⑦ Security device B uses its own private key to decrypt and obtain KEY1 (completing the symmetric key negotiation between security devices A and B);
[0069] Security device B uses KEY1 to decrypt ciphertext A and obtain the original transaction data transmitted by application A;
[0070] Security device B calculates a digest of the decrypted original text to obtain digest 2;
[0071] Security device B uses the public key of terminal A (obtained from protocol header HeadA) to decrypt the signature and obtain the transmitted digest 1;
[0072] Security device B compares summary 1 and summary 2. If they are consistent, the transaction data is returned to application B of the provincial network center.
[0073] 3. The key KEY1 is updated regularly (security device A can configure the frequency of KEY1 updates according to different business scenarios).
[0074] The service security algorithm employed in the above-mentioned embodiments is a cryptographic device developed based on a domestically produced high-performance cryptographic card. Equipped with a high-performance CPU, a high-performance security chip, and a high-speed network port, it is suitable for various cryptographic security application systems and provides high-performance, multi-task parallel processing for cryptographic operations. It can meet the requirements of application system data signing / verification, encryption / decryption, identity authentication, secure channels, security policies, and key management, ensuring the confidentiality, integrity, and non-repudiation of transmitted information while also providing a secure and comprehensive key management mechanism. In device management, device registration uses external device information to register the device, initialize the device information, bind the device public key, and periodically send heartbeats to the road network service security center, enabling effective management of secure devices. In device key generation management, a device key is generated during device initialization and deleted during re-initialization. Key management also includes symmetric key generation management, including symmetric key generation, destruction, encrypted export, and encrypted import. Symmetric key export is protected by the central device encryption key, while encrypted import is protected by the device's own encryption key. In key negotiation, symmetric key negotiation services are provided for both parties in data exchange, and the frequency of symmetric key updates can be set to enhance security.
[0075] Through the above embodiments, it can be found that the highway network toll collection data transmission method of the present invention can ensure that the highway network toll collection data is transmitted in ciphertext, thereby protecting the confidentiality, integrity and non-repudiation of the highway network toll collection data, and improving the security of data transmission; and this method enables the toll station security equipment to update the symmetric key based on the update request, ensuring the distribution security of the symmetric key, thereby further improving the security of data transmission.
[0076] Correspondingly, the present invention also provides a highway network toll collection data transmission system, which includes a processor, a memory and a computer program stored in the memory. The processor is used to execute the computer program. When the computer program is executed, the system implements the steps of the method described in any of the above embodiments.
[0077] Embodiments of the present invention further provide a computer-readable storage medium and a computer program product, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method described in any of the above embodiments are implemented. The computer-readable storage medium can be a tangible storage medium, such as a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a floppy disk, a hard disk, a removable storage disk, a CD-ROM, or any other form of storage medium known in the art.
[0078] It should be understood by those skilled in the art that the various exemplary components, systems and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software or a combination of the two. Whether it is specifically performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present invention are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link via a data signal carried in a carrier.
[0079] It should be understood that the present invention is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted. In the above embodiments, several specific steps are described and illustrated as examples. However, the method of the present invention is not limited to the specific steps described and illustrated. Those skilled in the art may make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present invention.
[0080] In the present invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with or replace features of other embodiments.
[0081] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
Claims
1. A method for transmitting data of highway network toll collection, characterized in that: The method comprises: The toll station security device generates a first public key, a first private key, and a first symmetric key, and receives a second public key sent by the road network service security center. The toll station security device encrypts the first symmetric key based on the second public key to obtain a first symmetric key ciphertext. The toll station security device sends the first public key and the first symmetric key ciphertext to the road network service security center, so that the road network service security center sends the first public key and the first symmetric key to the provincial network center security device. The toll station security device receives first transaction data sent by the toll station application, generates a first data digest based on the first transaction data using a digest algorithm, signs the first data digest using the first private key to obtain first signature data, and encrypts the first signature data and the first transaction data using the first symmetric key to obtain a first data ciphertext; The toll station security device assembles the first data ciphertext and the first protocol header to obtain an encrypted data packet, and the encrypted data packet is used to send to the provincial network center application corresponding to the provincial network center security device; wherein, the first protocol header includes the number information of the toll station security device and the first public key information.
2. The method for transmitting data of highway network toll collection according to claim 1, characterized in that: The method comprises: The provincial network center security device generates a third public key and a third private key, and sends the third public key to the road network business security center; The road network service security center decrypts the first symmetric key ciphertext based on its second private key to obtain a decrypted second symmetric key, and re-encrypts the decrypted second symmetric key based on the third public key to obtain a second symmetric key ciphertext. The road network service security center is used to send the second symmetric key ciphertext to the provincial network center security device, so that the provincial network center security device decrypts the second symmetric key ciphertext based on the third private key to obtain a decrypted third symmetric key.
3. The method for transmitting data of highway network toll collection according to claim 2, characterized in that: The method comprises: The provincial network center security device receives the encrypted data packet sent by the provincial network center application, and parses the encrypted data packet to obtain the parsed second protocol header and the second data ciphertext; The provincial network center security device decrypts the second data ciphertext based on the third symmetric key to obtain second transaction data, and sends the second transaction data to the provincial network center application.
4. The method for transmitting data of highway network toll collection according to claim 3, characterized in that: Sending the second transaction data to the provincial network center application includes: The provincial network center security device generates a second data digest based on the second transaction data through a digest algorithm, and decrypts the first signature data based on the first public key to obtain the decrypted first data digest. The provincial network center security device compares the second data digest and the first data digest, and sends the second transaction data to the provincial network center application if the second data digest and the first data digest are consistent.
5. The method for transmitting data for networked expressway toll collection according to any one of claims 1 to 4, characterized in that: The method comprises: The toll station security device obtains the symmetric key update request sent by the road network service security center, and the toll station security device updates the first symmetric key based on the symmetric key update request to obtain an updated symmetric key.
6. The method for transmitting data for highway network toll collection according to claim 5, characterized in that: The toll station security device updates the first symmetric key based on the symmetric key update request to obtain an updated symmetric key, including: The toll station security device determines whether the first symmetric key meets the update condition; When the update conditions are met and an update confirmation notification sent by the provincial network center security device is received, the first symmetric key is updated to obtain an updated symmetric key.
7. The method for transmitting data for highway network toll collection according to claim 6, characterized in that: The key update request includes a key update frequency or a key update interval.
8. The method for transmitting data for highway network toll collection according to claim 4, characterized in that: The digest algorithm is the SM3 cryptographic digest algorithm.
9. A highway network toll collection data transmission system, comprising a processor, a memory, and a computer program stored in the memory, characterized in that: The processor is configured to execute the computer program. When the computer program is executed, the system implements the steps of the method according to any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.