Data encryption processing method and system, electronic equipment and computer program product
By combining the key, count value and controller LAN identifier to generate the target mask under the CAN protocol, and using chaotic mapping and byte position permutation table for encryption, the problem that encryption algorithms under the CAN protocol are difficult to take into account security and real-time, achieving efficient and secure data transmission.
Patent Information
- Application Number
- CN202510780549.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-06-11
AI Technical Summary
The encryption algorithm under the existing CAN protocol is difficult to take into account the security and real-time nature of data transmission. The existing encryption solutions have problems such as poor real-time and insufficient security.
Dynamic encryption is achieved by obtaining the first key of the first node, the count value of the transmitted data frame and the controller LAN identifier, combining the chaotic mapping to generate the target mask, and using the byte position permutation table generated by the target mask to encrypt the transmitted data.
It realizes efficient security and real-time balance of data transmission, avoids key search and loading delays, and improves data transmission security and real-timeness.
Smart Images

Figure CN120474814A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and in particular to a data encryption processing method, system, electronic device, and computer program product. Background Art
[0002] In fields such as automotive electronics and industrial control, the Controller Area Network (CAN) protocol has become a core communication protocol due to its high reliability and low cost. However, the CAN protocol lacks a native encryption mechanism, making transmitted data vulnerable to theft. Existing data transmission solutions enhance the security of CAN data by introducing encryption algorithms, such as the Rivest-Shamir-Adleman (RSA) algorithm, proposed by Ronald Rivest, Adi Shamir, and Leonard Adleman, the Advanced Encryption Standard (AES), and Elliptic Curve Cryptography (ECC). Encryption algorithms like RSA require the pre-storage of a large number of keys and suffer from poor real-time performance. Encryption algorithms like AES use static key systems with a globally pre-shared key. Once the key is compromised, data security is compromised. The ECC encryption algorithm has vulnerabilities, making it prone to information leakage. It is computationally complex, and lacks real-time performance and security. That is, when existing encryption algorithms process data transmitted under the CAN protocol, it is difficult to balance the security and real-time performance of data transmission. Summary of the Invention
[0003] The embodiments of the present application provide a data encryption processing method, system, electronic device and computer program product to solve the problem that the encryption algorithm under the CAN protocol in the prior art is difficult to take into account both data transmission security and real-time performance.
[0004] A first aspect of an embodiment of the present application provides a data encryption processing method, including: Obtaining a first key of the first node, a count value of transmitted data frames, data to be transmitted, and a controller area network identifier of the data to be transmitted; generating a target mask based on the first key, the count value, and the controller area network identifier in combination with a chaotic map; The data to be transmitted is encrypted based on the target mask and a byte position substitution table generated by the target mask to obtain a ciphertext of the data to be transmitted.
[0005] A second aspect of an embodiment of the present application provides a data encryption processing system, including: an acquisition module, configured to acquire a first key of the first node, a count value of transmitted data frames, data to be transmitted, and a controller area network identifier of the data to be transmitted; a generating module, configured to generate a target mask based on the first key, the count value, and the controller area network identifier in combination with a chaotic map; An encryption module is used to encrypt the data to be transmitted based on the target mask and a byte position substitution table generated by the target mask to obtain a ciphertext of the data to be transmitted.
[0006] A third aspect of an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in the first aspect when executing the computer program.
[0007] A fourth aspect of an embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the method described in the first aspect.
[0008] A fifth aspect of an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the method described in the first aspect are implemented.
[0009] As can be seen from the above, this application is based on the first key of the first node, the real-time updated count value of the transmitted data frame and the controller LAN identifier of the data to be transmitted, and generates a unique target mask according to the current data transmission requirements in combination with chaotic mapping, avoiding the overhead of pre-storing a large number of keys, eliminating key search and loading delays, and quickly completing the mask derivation and data encryption required for encryption, reducing encryption delays, and ensuring real-time data transmission. At the same time, the target mask is generated based on the changing count value and the controller LAN identifier, ensuring that the target mask cannot be reused, so that attackers cannot crack the encryption logic through historical masks. The byte position permutation table generated by the target mask is also used in the data encryption process to achieve double encryption, effectively improving the security of data transmission. This application improves encryption efficiency and security through a dynamic generation mechanism, achieving efficient and secure data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0011] Figure 1 This is a process of a data encryption processing method provided by the embodiment of the present application Figure 1 ; Figure 2 This is a process of a data encryption processing method provided by the embodiment of the present application Figure 2 ; Figure 3 This is a structural diagram of a data encryption processing system provided in an embodiment of the present application; Figure 4 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0012] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0013] It will be understood that when used in this specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0014] It should also be understood that the terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit the present application. As used in this specification and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0015] It should be further understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0016] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0017] In specific implementations, the terminals described in the embodiments of the present application include, but are not limited to, other portable devices such as mobile phones, laptop computers, or tablet computers with touch-sensitive surfaces (e.g., touch screen displays and / or touch pads). It should also be understood that in some embodiments, the device is not a portable communication device, but a desktop computer with a touch-sensitive surface (e.g., touch screen displays and / or touch pads).
[0018] In the following discussion, a terminal including a display and a touch-sensitive surface is described. However, it should be understood that the terminal may include one or more other physical user interface devices such as a physical keyboard, mouse, and / or joystick.
[0019] The terminal supports various applications, such as one or more of the following: a drawing application, a presentation application, a word processing application, a website creation application, a disk burning application, a spreadsheet application, a game application, a phone application, a video conferencing application, an email application, an instant messaging application, a workout support application, a photo management application, a digital camera application, a digital video camera application, a web browsing application, a digital music player application, and / or a digital video player application.
[0020] Various applications that can be executed on the terminal can use at least one common physical user interface device, such as a touch-sensitive surface. One or more functions of the touch-sensitive surface and corresponding information displayed on the terminal can be adjusted and / or changed between applications and / or within a corresponding application. In this way, the common physical architecture of the terminal (e.g., the touch-sensitive surface) can support a variety of applications with user interfaces that are intuitive and transparent to the user.
[0021] It should be understood that the size of the serial numbers of each step in this embodiment does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of this application.
[0022] There are various encryption schemes under the existing CAN protocol, each with its own advantages and disadvantages.
[0023] The RSA encryption algorithm implements data encryption under the CAN protocol through hardware. However, its large-number exponentiation modular operations result in high latency, making it difficult to meet high real-time requirements. XTS stands for XOR Encryption (XOR, XEX)-based Tweaked Codebook mode with Stealth. The AES / XTS encryption algorithm combines AES and XTS, using a stream cipher mode to improve encryption speed. However, key management is static, and the extended frame padding method requires dedicated hardware modules, resulting in poor security and limited flexibility. Furthermore, these hardware encryption solutions rely on dedicated chips, increasing cost, design complexity, and resource consumption.
[0024] Software encryption solutions require more memory resources such as read-only memory (ROM) or random access memory (RAM), affecting real-time performance.
[0025] Existing encryption schemes also rely on static keys or simple counters to implement a single mechanism. These schemes have poor dynamic adaptability and are vulnerable to replay attacks. Pre-setting key slots can alleviate this problem to a certain extent, but they require secure storage to store dynamic keys and match key slots to message IDs, which requires additional storage space. Furthermore, key updates are infrequent, making them vulnerable to cracking by attackers. More importantly, existing encryption schemes struggle to balance data transmission security and real-time performance.
[0026] In order to solve the above problems, the present application provides a data encryption processing method, system, electronic device and computer program product.
[0027] The data encryption processing method provided in this application fully utilizes the characteristics of the CAN protocol, has strong dynamic adaptability and compatibility, can reduce hardware investment costs, and improves the security and real-time performance of data transmission through a multi-level encryption mechanism, achieving an effective balance between security and real-time performance, preventing attackers from intercepting and tampering with data, resulting in the leakage of key control instructions (such as brake signals and turn signals), and ensuring the normal operation of CAN protocol-based devices and systems such as automobiles.
[0028] In order to illustrate the technical solution described in this application, specific embodiments are provided below.
[0029] See also Figure 1 , Figure 1 This is a process of a data encryption processing method provided by the embodiment of the present application Figure 1 .like Figure 1 As shown, a data encryption processing method includes the following steps: Step 101: Obtain a first key of a first node, a count value of transmitted data frames, data to be transmitted, and a controller area network identifier of the data to be transmitted.
[0030] The first node is a communication node with data transmission and reception capabilities, such as the Electronic Control Unit (ECU) in the vehicle network. ECUs in the vehicle network implement multi-node coordinated control via the CAN bus, ensuring the safety and real-time performance of vehicle functions. These ECUs, such as the engine control module and brake controller, are all communication nodes with data transmission and reception capabilities.
[0031] The first node pre-stores at least one key, such as a root key, a master key, and a device key. The root key is the unique starting point of the key derivation tree and can be used with the encryption algorithm to derive subkeys such as the master key. The master key is an intermediate key derived from the root key and can be further used to generate device keys. The device key is a unique identifier for the node and is used for two-way authentication or encrypted communication.
[0032] The first key is a key pre-stored by the first node and used for data encryption and decryption. The first key can be a root key, a master key, or other key that can be shared by multiple communication nodes.
[0033] In some embodiments, the first key may be a 128-bit key, such as a 128-bit root key, to improve encryption performance.
[0034] The first node is equipped with a counter for recording the number of transmitted data frames. Each time the first node successfully transmits a data frame, the counter increments by one. For example, the initial value of ECU A's counter for recording the number of transmitted data frames is 0x00000001. After successfully transmitting a data frame, the counter increments from 0x00000001 to 0x00000002.
[0035] In some embodiments, the counter is a 32-bit up-counter.
[0036] The data to be transmitted is the original information content that needs to be transmitted via the CAN bus, which may include control instructions, sensor readings and / or status information.
[0037] The CAN ID is used to identify the data to be transmitted. Different data to be transmitted corresponds to different CAN IDs.
[0038] In some embodiments, standard frames and extended frames are two CAN data frame formats. The CAN ID of a standard frame is 11 bits, and the CAN ID of an extended frame is 29 bits.
[0039] In order to ensure data transmission security, the data to be transmitted needs to be encrypted. The first key, the count value and the controller area network identifier are important parameters for implementing data encryption to ensure communication security.
[0040] Step 102: Generate a target mask based on the first key, the count value, and the CAN identifier in combination with a chaotic map.
[0041] The target mask is a byte sequence generated based on the first key, the count value, and the CAN identifier through an encryption algorithm combined with a chaotic map. The target mask is used to encrypt the data to be transmitted.
[0042] CAN IDs are naturally random, and their count values change dynamically with the number of data frames transmitted. Accordingly, the target mask generated based on this is bound to the lifecycle of the data to be transmitted in the current frame, achieving a one-frame-one-key mechanism. Each target mask is used only to encrypt the data to be transmitted in the current frame. The target mask used to encrypt the next frame's data is regenerated based on the controller area network identifier and count value of the next frame's data, demonstrating strong dynamic adaptability. This eliminates the need to retain the target mask required for encryption, saving resources and reducing communication latency. Furthermore, attackers cannot reverse engineer the target mask through storage media. Even if the target mask for a particular frame is cracked, the resulting target mask cannot be used to decrypt data in other frames. Dynamic changes in the target mask prevent replay attacks and achieve high-quality forward security.
[0043] In some embodiments, the target mask is generated based on the first key, the count value and the controller local area network identifier in combination with a chaotic map, including: using the first key to encrypt a spliced sequence formed by splicing the controller local area network identifier and the count value to obtain a second key; using the second key to encrypt the spliced sequence to obtain an initial mask; extracting a target parameter value from the second key; performing chaotic mapping iteration and data conversion based on the target parameter value to obtain a chaotic stream; performing an XOR operation on the initial mask and the chaotic stream to obtain the target mask.
[0044] The second key is a subkey derived from the first key and is used to generate the initial mask. It also serves as a parameter source for the chaotic system iteration, providing the target parameter values required for the chaotic system iteration and helping to generate the target mask. The initial mask is a preliminary mask generated by re-encrypting the same spliced sequence using the second key and is used to generate the target mask. The target parameter values are the initialization parameters of the chaotic system extracted from the second key, such as state variables and control parameters, which are used to drive the chaotic system to perform chaotic mapping iterations.
[0045] There are many types of chaotic mapping, among which the logistic chaotic mapping is a lightweight chaotic mapping with low computational complexity, small memory usage, and high randomness. Its simplification features are outstanding, namely dimensionality simplification, computational simplification, and implementation simplification. It can improve iteration speed while ensuring high randomness.
[0046] The controller area network identifier and the count value are concatenated to obtain a concatenated sequence. Key derivation is performed based on the first key, and a chaotic map is introduced to achieve multi-level encryption. The introduction of chaotic flow breaks the linear characteristics of the encryption process, resists statistical analysis attacks, increases the key derivation level, and isolates the direct connection between the first key and the final target mask. The multi-level isolation between the first key and the target mask increases the difficulty of cracking, making it difficult for attackers to reverse-infer the first key from the target mask, reducing the risk of exposing the first key. The count value and controller area network identifier are different in each frame, ensuring that the target mask is unique and cannot be reused. The exclusive OR operation superimposes the initial mask with the randomness of the chaotic flow, significantly increasing the complexity of the mask. The exclusive OR operation is efficient and easy to implement in hardware, efficiently generating the target mask required for encryption, improving encryption speed, and ensuring real-time data transmission.
[0047] In some embodiments, the chaotic mapping iteration and data conversion based on the target parameter value to obtain a chaotic flow includes: inputting the target parameter value into a first chaotic system, performing chaotic mapping iteration on the first chaotic system with transient effects until the transient effects are eliminated to obtain a second chaotic system; performing chaotic mapping iteration on the second chaotic system a set number of times to obtain a set number of chaotic sequences output by the second chaotic system; performing fixed-point number operations and binarization processing on the set number of chaotic sequences to obtain the chaotic flow.
[0048] A chaotic system is a nonlinear dynamic system. The first chaotic system and the second chaotic system are the same chaotic system in different states. The first chaotic system corresponds to a state in which transient effects exist, while the second chaotic system corresponds to a steady-state state in which transient effects are eliminated. A chaotic sequence is a sequence of state values, such as a numerical sequence, generated by iterative chaotic mapping. A chaotic stream is a byte sequence, or byte stream, resulting from the conversion of a chaotic sequence, such as 0xA5 or 0x3F.
[0049] A high-complexity chaotic flow is generated iteratively through chaotic mapping to confuse the initial mask and then generate the target mask.
[0050] In some embodiments, the chaotic map is a Logistic chaotic map, and accordingly, the chaotic system is a Logistic chaotic system. The first chaotic system is a Logistic chaotic system in a transient effect stage, and the second chaotic system is a Logistic chaotic system in a steady state stage after the transient effect is eliminated.
[0051] The transition state sequence output by the first chaotic system during the transient effect phase may exhibit periodic or skewed distributions, making it easily predictable. The target parameter value is used as the initialization parameter of the chaotic system and then input into the first chaotic system. Chaotic mapping iterations are then performed until the transient effect in the first chaotic system is eliminated. This results in a second chaotic system without the transient effect. The second chaotic system can then output a chaotic sequence, improving the randomness and anti-predictability of the output content.
[0052] In some embodiments, the data field of the CAN data frame is 8 bytes, and accordingly, the set number is 8. Based on the second chaotic system, the set number of chaotic mapping iterations is performed, and the second chaotic system accordingly outputs 8 chaotic sequences to form an 8-byte chaotic stream, which is then subjected to an exclusive-OR operation to generate an 8-byte target mask, thereby achieving encryption.
[0053] The chaotic sequence output by the second chaotic system is a sequence of floating-point values. Fixed-point arithmetic is used to obtain an integer sequence to improve computational efficiency. The integer sequence is then binarized to facilitate adaptation to an exclusive-or operation. A set number of binarized integer sequences are combined into a single sequence to obtain the chaotic flow.
[0054] In some embodiments, the fixed-point operation is to multiply each floating-point value in the floating-point value sequence by 256 and round the result to generate an 8-bit unsigned integer sequence, which is the result of the fixed-point operation.
[0055] In some embodiments, a partial code example for generating a target mask based on the first key, the count value, and the CAN identifier is as follows: temp_key=derive_temp_key(RootKey,CAN_ID||Counter); / / Generate the second key; Mask=derive_Mask(temp_key,CAN_ID||Counter); / / Generate initial mask; uint32_t x=(temp_key[0]<<8)|temp_key[1]); / / Initialize x; uint32_t μ=3.0+(( temp_key [2]*0.003852140077821) / 255); / / Dynamically adjust μ, μ∈[3.0,3.99]; uint8_t GenerateChaosByte(){ x=μ*x*(1-x); / / Logistic chaotic mapping iteration; return(uint8_t)(x>>8)&0xFF; / / Fixed-point number operation and binary processing; }; / / Generate chaotic sequence; DynamicMask = Mask⊕ChaosStream; / / Generate target mask.
[0056] Here, RootKey refers to the first key, temp_key refers to the second key, CAN_ID refers to the controller area network identifier, Counter refers to the count value, Mask refers to the initial mask, GenerateChaosByte() is the function that generates the chaotic sequence, x refers to the state variable, μ refers to the control parameter, ChaosStream refers to the chaotic stream, and DynamicMask refers to the target mask.
[0057] In some embodiments, the control parameter μ is dynamically adjusted and nonlinearity is introduced to achieve chaotic system improvement, which solves the technical problems of small parameter range, uneven sequence distribution and insufficient randomness when directly applied to CAN encryption in traditional chaotic systems. It improves the randomness of subsequent chaotic sequence generation, increases the complexity and unpredictability of chaotic sequences, and thus improves encryption security.
[0058] In some embodiments, the control parameter μ may be adjusted according to the first key, the second key, or other factors.
[0059] In some embodiments, the value of the iterative function corresponding to the control parameter μ is pre-calculated and stored as a table. In the actual operation process, the table lookup replaces the real-time function calculation, thereby reducing the calculation time.
[0060] In some embodiments, encryption steps such as encrypting the spliced sequence using the first key and encrypting the spliced sequence using the second key are implemented using a lightweight encryption algorithm. The lightweight encryption algorithm is, for example, an extended tiny encryption algorithm (XTEA), whose computing speed meets the microsecond response requirement, the corresponding code size is small, and the RAM space resources occupied are small. At the same time, it is compatible with 8-bit and 16-bit microcontroller processing units (MCU), has strong hardware compatibility, does not require a dedicated encryption chip, and reduces deployment costs.
[0061] Step 103: Encrypt the data to be transmitted based on the target mask and the byte position substitution table generated by the target mask to obtain a ciphertext of the data to be transmitted.
[0062] After obtaining the target mask, a byte position permutation table is generated through the target mask, and the target mask and the byte position permutation table are used to encrypt the data to be transmitted, thereby obtaining the corresponding ciphertext, realizing data encryption, and ensuring data security.
[0063] In some embodiments, the data to be transmitted is encrypted based on the target mask and the byte position permutation table generated by the target mask to obtain the ciphertext of the data to be transmitted, including: converting the data to be transmitted into a structured data frame; performing an XOR operation on the structured data frame and the target mask to obtain mask data; generating the byte position permutation table based on the target mask; and performing position permutation on each byte value in the mask data through the byte position permutation table to obtain the ciphertext of the data to be transmitted.
[0064] The data to be transmitted is converted into a structured data frame. This conversion adapts to the data field requirements of the CAN transmission protocol. An XOR obfuscation operation based on the target mask is performed on the structured data frame, effectively eliminating the statistical characteristics and regularities of the original data. A permutation table is used to rearrange the bytes of the masked data to achieve byte-level spatial obfuscation. The XOR operation and position permutation form a multi-level protection for the data to be transmitted.
[0065] The data to be transmitted is combined with the low byte of the count value, and the checksum is calculated. The data to be transmitted, the low byte of the count value, and the checksum form an 8-byte structured data frame, which is convenient for performing an XOR operation with the 8-byte target mask to achieve data encryption.
[0066] In some embodiments, a code example for a structured data frame is: PlainText = [Counter_Low, Data1, Data2, Data3, Data4, Data5, Data6, Checksum], where Checksum = (Data1 ^ Data2 ^ ... ^ Data6) + Counter_Low. The PlainText array represents the structured data frame, Counter_Low represents the low byte of the counter value, Checksum represents the checksum, and Data1, Data2, Data3, Data4, Data5, and Data6 represent the data to be transmitted. Embedding the checksum into the data field reuses data space, avoiding the need for additional fields and eliminating extra length overhead, thus optimizing transmission efficiency.
[0067] Perform byte-by-byte XOR operation on the structured data frame and the target mask to obtain the mask data corresponding to the structured data frame, thus achieving one-time data encryption.
[0068] The target mask can be XORed with the structured data frame, and can also be used to generate a byte position permutation table to perturb the position of the masked data, that is, to perturb the position of each byte value in the masked data, thereby achieving secondary data encryption and obtaining the final ciphertext.
[0069] In some embodiments, a code example of performing an XOR operation on the structured data frame and the target mask to obtain mask data is: MaskedData=PlainText⊕DynamicMask, where MaskedData is mask data.
[0070] In some embodiments, the code example for generating the byte position permutation table based on the target mask is: perm_table=generate_perm_table(DynamicMask).
[0071] In some embodiments, the byte position substitution table is generated based on the target mask, including: performing position substitution on the original position of each byte value in the target mask to obtain an updated position corresponding to each original position; establishing a mapping relationship between each original position and its corresponding updated position to obtain the byte position substitution table.
[0072] The target mask is dynamically generated along with the data to be transmitted. Each frame of data to be transmitted has a unique target mask. The byte position permutation table generated based on this is a dynamic permutation table rather than a static permutation table used for a long time. This solves the problem that the permutation table is easily cracked. At the same time, the byte position permutation table changes with the target mask, and there is no need to occupy memory for a long time to store the permutation table, saving resource space.
[0073] In some embodiments, a byte position permutation table is generated based on the size of the byte values in the target mask. The original position of each byte value in the target mask is recorded. The byte values in the target mask are sorted in ascending or descending order, and the position of each byte value after the ascending or descending order is determined, that is, the updated position after the ascending or descending order. Based on the byte value, a mapping relationship between the original position and the updated position is established to obtain the byte position permutation table.
[0074] For example, the byte values are 0x30, 0x40, 0x20, and 0x10. The original positions of these four byte values are 1, 2, 3, and 4, respectively. Arranging these four byte values in ascending order yields 0x10, 0x20, 0x30, and 0x40. After the ascending order, the corresponding positions of 0x10, 0x20, 0x30, and 0x40 are 1, 2, 3, and 4. Among them, the position of 0x10 changes from 4 to 1, the position of 0x20 changes from 3 to 2, the position of 0x30 changes from 1 to 3, and the position of 0x40 changes from 2 to 4. Accordingly, original position 1 corresponds to updated position 3, original position 2 corresponds to updated position 4, original position 3 corresponds to updated position 2, and original position 4 corresponds to updated position 1. This establishes a mapping between original and updated positions, and generates a corresponding byte position permutation table.
[0075] In some embodiments, the original position of each byte value in the target mask is recorded. The position of each byte value in the target mask is perturbed using the Fisher-Yates Shuffle Algorithm. The updated position of each byte value after the perturbation based on the Fisher-Yates Shuffle Algorithm is determined. Based on the byte value, a mapping relationship between the original position and the updated position is established to obtain a byte position permutation table.
[0076] In some embodiments, the position of each byte value in the mask data is permuted through the byte position permutation table to obtain the ciphertext of the data to be transmitted, including: determining the target update position of each byte value in the mask data through the byte position permutation table; and according to the target update position, permuting the position of each byte value in the mask data to the target update position to obtain the ciphertext.
[0077] Each byte value in the masked data has its original position. The byte value in the masked data is permuted using a byte position permutation table. This position perturbation achieves data obfuscation, i.e., re-encryption.
[0078] For example, in the byte position permutation table, original position 1 corresponds to updated position 3, original position 2 corresponds to updated position 4, original position 3 corresponds to updated position 2, and original position 4 corresponds to updated position 1. If the masked data is ABCD, where A, B, C, and D are byte values, the byte position permutation table is used to permute the masked data ABCD to produce the ciphertext DCAB. This section is for illustrative purposes only.
[0079] The byte position permutation table defines the mapping between original positions and updated positions. In the byte position permutation table, original position i corresponds to updated position j, where i and j are positive integers, i, j∈[1,8]. The byte value at original position i in the masked data is moved to the target updated position j corresponding to original position i. After all byte values in the masked data are moved to the target updated positions, the ciphertext is obtained.
[0080] This application's data encryption processing method is a novel encryption algorithm that integrates the characteristics of the CAN protocol and balances real-time performance with security. It achieves a balance between security and real-time performance through technologies such as CAN ID binding encryption, real-time counter value updates, a lightweight encryption algorithm, a lightweight chaotic system, dynamic position perturbations based on target masks, and a multi-level encryption mechanism.
[0081] In some embodiments, the first node may selectively perform data encryption based on the controller LAN identifier whitelist, encrypting only critical data, achieving reasonable resource allocation, improving real-time data transmission, and effectively balancing security and real-time performance.
[0082] In an embodiment of the present application, based on the first key of the first node, the real-time updated count value of the transmitted data frame and the controller LAN identifier of the data to be transmitted, according to the current data transmission requirements, combined with chaotic mapping, a unique target mask is generated to avoid the overhead of pre-storing a large number of keys, eliminate key search and loading delays, quickly complete the mask derivation and data encryption required for encryption, reduce encryption delays, and ensure real-time data transmission. At the same time, the target mask is generated based on the changing count value and the controller LAN identifier, ensuring that the target mask cannot be reused, making it impossible for attackers to crack the encryption logic through historical masks. The byte position permutation table generated by the target mask is also used in the data encryption process to achieve double encryption, effectively improving the security of data transmission. The present application improves encryption efficiency and security through a dynamic generation mechanism, achieving efficient and secure data transmission.
[0083] See also Figure 2 , Figure 2 This is a process of a data encryption processing method provided by the embodiment of the present application Figure 2 .like Figure 2 As shown, a data encryption processing method includes the following steps: Step 201: Obtain a first key of a first node, a count value of transmitted data frames, data to be transmitted, and a controller area network identifier of the data to be transmitted.
[0084] The implementation process of this step is the same as the implementation process of step 101 in the aforementioned embodiment, and will not be repeated here.
[0085] Step 202: Generate a target mask based on the first key, the count value, and the CAN identifier in combination with a chaotic map.
[0086] The implementation process of this step is the same as the implementation process of step 102 in the aforementioned embodiment, and will not be repeated here.
[0087] Step 203: Encrypt the data to be transmitted based on the target mask and the byte position substitution table generated by the target mask to obtain a ciphertext of the data to be transmitted.
[0088] The implementation process of this step is the same as the implementation process of step 103 in the aforementioned embodiment, and will not be repeated here.
[0089] Step 204: Encapsulate the ciphertext, the count value, and the CAN identifier into a CAN data frame.
[0090] After the ciphertext is obtained through data encryption, the ciphertext, count value and controller area network identifier are encapsulated into a CAN data frame to facilitate data transmission through the CAN bus.
[0091] Step 205: Transmit the CAN data frame to the second node via the CAN bus. The second node decrypts the data based on a pre-stored decryption key and the count value and the CAN identifier included in the CAN data frame.
[0092] According to the transmission requirements, the first node transmits the CAN data frame to the target node, i.e., the second node, through the CAN bus to meet the transmission requirements.
[0093] Like the first node, the second node is also a communication node with data transceiver capabilities, and pre-stores at least one key, such as a root key, a master key, a device key, etc. The at least one key pre-stored on the second node includes the key used by the node for encryption and decryption.
[0094] The second node can decrypt the ciphertext in the CAN data frame according to its pre-stored decryption key, and the count value and the controller area network identifier included in the CAN data frame.
[0095] The decryption process of the second node can refer to the above steps 101 to 103. The decryption process of the second node is briefly summarized as follows: using the decryption key to encrypt the spliced sequence consisting of the controller area network identifier and the count value in the CAN data frame to obtain a third key; using the third key to encrypt the spliced sequence consisting of the controller area network identifier and the count value in the CAN data frame to obtain a decryption initial mask; extracting the decryption target parameter value from the third key as the initial input parameter of the decryption first chaotic system, performing chaotic mapping iteration until the transient effect is eliminated, and obtaining the decryption second chaotic system, and using the decryption second chaotic system to perform a set number of chaotic mapping iterations to obtain a decryption chaotic sequence, and obtaining a decryption chaotic stream through fixed-point number operations, binarization processing and data combination; performing an exclusive-OR operation on the decryption initial mask and the decryption chaotic stream to obtain a decryption target mask; generating a decryption byte position permutation table based on the decryption target mask; restoring the byte value order of the ciphertext in the CAN data frame through the decryption byte position permutation table, that is, performing inverse permutation to achieve primary decryption; removing the dynamic exclusive-OR mask through the decryption target mask to achieve secondary decryption and obtain decrypted data.
[0096] After receiving the decrypted data, the second node calculates a decryption checksum based on the data in the decrypted data and the low byte of the count value, and compares it with the checksum of the parity bit in the decrypted data. If the decryption checksum matches the checksum of the parity bit in the decrypted data, the data decryption is successful, and the second node successfully obtains the decrypted data. If the decryption checksum does not match the checksum of the parity bit in the decrypted data, the data decryption fails, and the second node discards the frame data.
[0097] In some embodiments, if the decryption key of the second node is the first key, typically, a decryption checksum calculated based on the data in the decrypted data and the low byte of the count value matches a checksum of the check bits in the decrypted data.
[0098] Based on the data encryption processing method of the present application, data encryption is realized, which ensures the security and real-time performance of data transmission. At the same time, data decryption can be realized based on the data encryption processing method of the present application, which reduces the decryption delay and realizes efficient decryption.
[0099] In some embodiments, when a first node transmits a CAN data frame to a second node via a CAN bus, if the first node has a data transmission requirement, it can generate a target mask for a new frame of data to be transmitted in parallel to achieve encryption and transmission of the new frame of data to be transmitted.
[0100] In some embodiments, after a first node successfully transmits a CAN data frame to a second node via the CAN bus, a counter value of the first node is incremented by 1. The counter value is updated in real time, thereby improving the security of the target mask.
[0101] In an embodiment of the present application, after encrypting the ciphertext of the data to be transmitted, a controller local area network data frame containing the ciphertext is encapsulated based on the ciphertext, the count value and the controller local area network identifier, and the controller local area network data frame with higher security is transmitted to the second node to achieve the purpose of data transmission and realize data security transmission.
[0102] See also Figure 3 , Figure 3 This is a structural diagram of a data encryption processing system provided in an embodiment of the present application. For the sake of convenience, only the parts related to the embodiment of the present application are shown.
[0103] The data encryption processing system 300 includes: an acquisition module 301 , a generation module 302 , and an encryption module 303 .
[0104] The acquisition module 301 is configured to acquire a first key of a first node, a count value of transmitted data frames, data to be transmitted, and a controller area network identifier of the data to be transmitted.
[0105] The generating module 302 is configured to generate a target mask based on the first key, the count value, and the CAN identifier in combination with a chaotic map.
[0106] The encryption module 303 is configured to encrypt the data to be transmitted based on the target mask and a byte position substitution table generated by the target mask to obtain a ciphertext of the data to be transmitted.
[0107] In some embodiments, the generating module is specifically configured to: Using the first key, encrypting a concatenated sequence formed by concatenating the controller area network identifier and the count value to obtain a second key; encrypting the spliced sequence using the second key to obtain an initial mask; extracting a target parameter value from the second key; Performing chaotic mapping iteration and data conversion based on the target parameter value to obtain a chaotic flow; An XOR operation is performed on the initial mask and the chaotic flow to obtain the target mask.
[0108] In some embodiments, the generating module is further configured to: Inputting the target parameter value into a first chaotic system, performing chaotic mapping iteration on the first chaotic system with transient effects until the transient effects are eliminated, thereby obtaining a second chaotic system; Performing a set number of chaotic mapping iterations on the second chaotic system to obtain a set number of chaotic sequences output by the second chaotic system; Fixed-point number operations and binarization processing are performed on the set number of chaotic sequences to obtain the chaotic flow.
[0109] In some embodiments, the encryption module is specifically configured to: Converting the data to be transmitted into a structured data frame; Performing an XOR operation on the structured data frame and the target mask to obtain mask data; generating the byte position permutation table based on the target mask; The byte position permutation table is used to permute the position of each byte value in the mask data to obtain the ciphertext of the data to be transmitted.
[0110] In some embodiments, the encryption module is further configured to: Permuting the original position of each byte value in the target mask to obtain an updated position corresponding to each original position; A mapping relationship between each original position and its corresponding updated position is established to obtain the byte position substitution table.
[0111] In some embodiments, the encryption module is further configured to: Determining a target update position of each byte value in the mask data by using the byte position substitution table; According to the target update position, the position of each byte value in the mask data is replaced to the target update position to obtain the ciphertext.
[0112] In some embodiments, the system further includes a data transmission module for: encapsulating the ciphertext, the count value, and the controller area network identifier into a controller area network data frame; The CAN data frame is transmitted to the second node via a CAN bus, and the second node decrypts the data based on a pre-stored decryption key and the count value and the CAN identifier included in the CAN data frame.
[0113] The data encryption processing system provided in the embodiment of the present application can implement each process of the embodiment of the above-mentioned data encryption processing method and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0114] Figure 4 : is a structural diagram of an electronic device provided in an embodiment of the present application. As shown in the figure, the electronic device 4 of this embodiment includes: at least one processor 40 ( Figure 4Only one is shown in the figure), a memory 41 and a computer program 42 stored in the memory 41 and executable on the at least one processor 40, wherein the processor 40 implements the steps of any of the above-mentioned method embodiments when executing the computer program 42.
[0115] The electronic device 4 can be a computing device such as a desktop computer, a notebook, a PDA, or a cloud server. The electronic device 4 can include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art will understand that Figure 4 It is only an example of the electronic device 4 and does not constitute a limitation of the electronic device 4. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.
[0116] The processor 40 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0117] The memory 41 may be an internal storage unit of the electronic device 4, such as a hard drive or memory of the electronic device 4. The memory 41 may also be an external storage device of the electronic device 4, such as a plug-in hard drive, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. Furthermore, the memory 41 may include both an internal storage unit of the electronic device 4 and an external storage device. The memory 41 is used to store the computer program and other programs and data required by the electronic device. The memory 41 may also be used to temporarily store data that has been output or is about to be output.
[0118] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0119] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0120] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0121] In the embodiments provided in this application, it should be understood that the disclosed systems / electronic devices and methods can be implemented in other ways. For example, the system / electronic device embodiments described above are merely schematic. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of the system or unit, which can be electrical, mechanical or other forms.
[0122] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0123] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0124] If the integrated module / unit is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application can implement all or part of the process steps in the above-mentioned method embodiments by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. It should be noted that the content of the computer-readable medium can be appropriately increased or decreased based on the requirements of legislation and patent practice in a jurisdiction. For example, in some jurisdictions, based on legislation and patent practice, computer-readable media does not include electric carrier signals and telecommunication signals.
[0125] The present application implements all or part of the processes in the above-mentioned embodiment methods, and may also be implemented through a computer program product. When the computer program product runs on an electronic device, the electronic device can implement the steps in the above-mentioned method embodiments when executing the computer program product.
[0126] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A data encryption processing method, characterized in that: include: Obtaining a first key of the first node, a count value of transmitted data frames, data to be transmitted, and a controller area network identifier of the data to be transmitted; generating a target mask based on the first key, the count value, and the controller area network identifier in combination with a chaotic map; The data to be transmitted is encrypted based on the target mask and a byte position substitution table generated by the target mask to obtain a ciphertext of the data to be transmitted.
2. The method according to claim 1, characterized in that The generating a target mask based on the first key, the count value, and the controller area network identifier in combination with a chaotic map includes: Using the first key, encrypting a concatenated sequence formed by concatenating the controller area network identifier and the count value to obtain a second key; encrypting the spliced sequence using the second key to obtain an initial mask; extracting a target parameter value from the second key; Performing chaotic mapping iteration and data conversion based on the target parameter value to obtain a chaotic flow; An XOR operation is performed on the initial mask and the chaotic flow to obtain the target mask.
3. The method according to claim 2, characterized in that The chaotic mapping iteration and data conversion are performed based on the target parameter value to obtain a chaotic flow, including: Inputting the target parameter value into a first chaotic system, performing chaotic mapping iteration on the first chaotic system with transient effects until the transient effects are eliminated, thereby obtaining a second chaotic system; Performing a set number of chaotic mapping iterations on the second chaotic system to obtain a set number of chaotic sequences output by the second chaotic system; Fixed-point number operations and binarization processing are performed on the set number of chaotic sequences to obtain the chaotic flow.
4. The method according to claim 1, wherein The step of encrypting the data to be transmitted based on the target mask and the byte position permutation table generated by the target mask to obtain the ciphertext of the data to be transmitted includes: Converting the data to be transmitted into a structured data frame; Performing an XOR operation on the structured data frame and the target mask to obtain mask data; generating the byte position permutation table based on the target mask; The byte position permutation table is used to permute the position of each byte value in the mask data to obtain the ciphertext of the data to be transmitted.
5. The method according to claim 4, characterized in that The step of generating the byte position substitution table based on the target mask comprises: Permuting the original position of each byte value in the target mask to obtain an updated position corresponding to each original position; A mapping relationship between each original position and its corresponding updated position is established to obtain the byte position substitution table.
6. The method according to claim 4, characterized in that The step of performing position substitution on each byte value in the mask data by using the byte position substitution table to obtain the ciphertext of the data to be transmitted includes: Determining a target update position of each byte value in the mask data by using the byte position substitution table; According to the target update position, the position of each byte value in the mask data is replaced to the target update position to obtain the ciphertext.
7. The method according to claim 1, characterized in that After encrypting the data to be transmitted based on the target mask and the byte position permutation table generated by the target mask to obtain the ciphertext of the data to be transmitted, the method further includes: encapsulating the ciphertext, the count value, and the controller area network identifier into a controller area network data frame; The CAN data frame is transmitted to the second node via a CAN bus, and the second node decrypts the data based on a pre-stored decryption key and the count value and the CAN identifier included in the CAN data frame.
8. A data encryption processing system, characterized in that: include: an acquisition module, configured to acquire a first key of the first node, a count value of transmitted data frames, data to be transmitted, and a controller area network identifier of the data to be transmitted; a generating module, configured to generate a target mask based on the first key, the count value, and the controller area network identifier in combination with a chaotic map; An encryption module is used to encrypt the data to be transmitted based on the target mask and a byte position substitution table generated by the target mask to obtain a ciphertext of the data to be transmitted.
9. An electronic device, characterized in that: The electronic device comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the electronic device implements the method according to any one of claims 1 to 7.
10. A computer program product, characterized in that The invention comprises a computer program which, when executed, causes the method according to any one of claims 1 to 7 to be performed.
Citation Information
Patent Citations
Controller regional network bus safety communication method, device and system
CN108965218A
Data transmission method and device
CN112740726A
Underwater sensor network encryption and decryption method and device, underwater equipment and storage medium
CN116743338A
Symmetric cryptosystem using cascaded chaotic maps
US20080063185A1