Safety verification method and device and vehicle

By performing a two-factor verification mechanism on the permissions of the terminal to access the ECU, the problem of the ECU being illegally accessed is solved, ensuring that the legal terminal is accessed normally, and the illegal terminal cannot pass the verification, improving the security of the vehicle.

CN120498705APending Publication Date: 2025-08-15BYD CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510122760.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the electronic control unit (ECU) of a vehicle has a problem of low security in illegal access by an illegal terminal, resulting in insufficient overall safety of the vehicle.

Method used

The two-factor verification mechanism is adopted to perform security verification at least twice on the terminal's permission to access the ECU. After the first verification is passed, the response indicating that the re-verification is sent will be sent. The legal terminal will know and perform re-verification, while the illegal terminal will not know the secondary verification mechanism and cannot pass the verification.

Benefits of technology

Improve the security of the ECU, thereby improving the overall security of the vehicle and preventing malicious access of illegal terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498705A_ABST
    Figure CN120498705A_ABST
Patent Text Reader

Abstract

The invention provides a safety verification method and device and a vehicle. The complete verification process of performing security verification on the access authority of the first terminal to access the second terminal involves at least two times of verification, and the second terminal opens the access authority to access the second terminal for the first terminal and sends a second response to the first terminal only when the two times of verification are passed respectively, so that the access authority of the first terminal to access the second terminal is completely verified. After the first terminal receives the second response, the first terminal can know that the security verification is passed, two times of verification involved in the complete verification process are completed, the first terminal has the access authority to access the second terminal, verification does not need to be continued, and the first terminal can normally access the second terminal subsequently. Through a secondary verification mechanism, the complexity of safety verification can be improved, and the situation that verification can be passed through one-time verification is avoided, so that the safety of the second terminal can be improved, and the safety of the vehicle is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent vehicle technology, and in particular to a safety verification method, device and vehicle. Background Art

[0002] Current vehicles often have an onboard controller, including an electronic control unit (ECU). This controller is used to control the vehicle, for example, its powertrain, body, and chassis systems. The ECU is equipped with control software or programs to perform these functions.

[0003] When the ECU needs to be maintained or updated, the terminal (external device) needs to access the ECU to update or modify the ECU program.

[0004] In order to improve the security of the ECU, before the terminal accesses the ECU, the ECU needs to perform security verification on the terminal's access rights to the ECU.

[0005] However, the inventors have found that even if security verification is performed on the access rights of the terminal to the ECU, there is still a situation where the ECU is illegally accessed by an illegal terminal, and the security of the ECU is low, resulting in low security of the vehicle. Summary of the Invention

[0006] The embodiments of the present invention provide a security verification method, device and vehicle to solve the problem in the prior art that an ECU is illegally accessed by an illegal terminal, the security of the ECU is low, and thus the security of the vehicle is low.

[0007] In a first aspect, an embodiment of the present invention provides a security verification method, applied to a first terminal, the method comprising:

[0008] Sending a first verification request to the second terminal;

[0009] In response to a first response sent by the second terminal, a second verification request is sent to the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request, when a first preset security verification condition is met; the first response is used to instruct the first terminal to send the second verification request.

[0010] In a second aspect, an embodiment of the present invention provides a security verification method, applied to a second terminal, the method comprising:

[0011] In response to a first verification request sent by the first terminal, determining whether a first preset security verification condition is met;

[0012] In response to satisfying a first preset security verification condition, a first response is sent to the first terminal, where the first response is used to instruct the first terminal to send a second verification request.

[0013] In a third aspect, an embodiment of the present invention provides a security verification method, applied to a cloud, comprising:

[0014] generating a first key in response to a first random seed sent by the first terminal; the first random seed is sent to the cloud in response to the first random seed sent by the second terminal after the first terminal sends a first verification request to the second terminal;

[0015] Sending a first key to a first terminal; causing the first terminal to respond to the first key, sending the first key to a second terminal; causing the second terminal to respond to the first key and determine whether a first preset security verification condition is satisfied;

[0016] generating a second key in response to a second random seed sent by the first terminal; the second random seed is sent to the cloud by the first terminal in response to the second random seed sent by the second terminal after the first terminal sends a second verification request to the second terminal; the second verification request is sent by the first terminal to the second terminal in response to a first response sent by the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request if a first preset security verification condition is met; the first response is used to instruct the first terminal to send a second verification request to the second terminal;

[0017] Sending a second key to the first terminal; causing the first terminal to respond to the second key, sending the second key to the second terminal; causing the second terminal to respond to the second key, and determining whether a second preset security verification condition is met.

[0018] In a fourth aspect, an embodiment of the present invention provides a security verification device, applied to a first terminal, the device comprising:

[0019] A first sending module, configured to send a first verification request to the second terminal;

[0020] The second sending module is used to send a second verification request to the second terminal in response to the first response sent by the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request when a first preset security verification condition is met; the first response is used to instruct the first terminal to send the second verification request.

[0021] In a fifth aspect, an embodiment of the present invention provides a security verification device, applied to a second terminal, the device comprising:

[0022] A first determining module, configured to determine whether a first preset security verification condition is satisfied in response to a first verification request sent by the first terminal;

[0023] The fifth sending module is configured to send a first response to the first terminal in response to satisfying a first preset security verification condition, where the first response is used to instruct the first terminal to send a second verification request.

[0024] In a sixth aspect, an embodiment of the present invention provides a security verification device, applied to a cloud, comprising:

[0025] a first generating module, configured to generate a first key in response to a first random seed sent by the first terminal; the first random seed is sent to the cloud in response to the first random seed sent by the second terminal after the first terminal sends a first verification request to the second terminal;

[0026] An eighth sending module, configured to send the first key to the first terminal; so that the first terminal responds to the first key and sends the first key to the second terminal; so that the second terminal responds to the first key and determines whether a first preset security verification condition is met;

[0027] a second generation module configured to generate a second key in response to a second random seed sent by the first terminal; the second random seed is sent to the cloud by the first terminal in response to the second random seed sent by the second terminal after the first terminal sends a second verification request to the second terminal; the second verification request is sent by the first terminal to the second terminal in response to a first response sent by the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request if a first preset security verification condition is met; the first response is used to instruct the first terminal to send a second verification request to the second terminal;

[0028] The ninth sending module is configured to send the second key to the first terminal, so that the first terminal responds to the second key and sends the second key to the second terminal, so that the second terminal responds to the second key and determines whether a second preset security verification condition is met.

[0029] In a seventh aspect, an embodiment of the present invention provides an electronic device, including:

[0030] Memory for storing computer programs;

[0031] The processor is configured to implement the steps of the security verification method described in any one of the above aspects when executing the program stored in the memory.

[0032] In an eighth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the security verification method described in any of the above aspects.

[0033] In a ninth aspect, an embodiment of the present invention provides a computer program product, which, when the instructions in the computer program product are executed by a processor of an electronic device, enables the electronic device to execute the steps in the security verification method described in any of the above aspects.

[0034] In a tenth aspect, an embodiment of the present invention provides a vehicle, comprising: a second terminal as described in any one of the above aspects.

[0035] Compared with the prior art, the present invention has the following advantages:

[0036] Generally, the complete verification process of "performing security verification on the access authority of the first terminal to the second terminal" involves only one verification.

[0037] The first terminal sends a verification request to the second terminal, and the second terminal performs security verification on the access permission of the first terminal to the second terminal according to the verification request sent by the first terminal.

[0038] If the security verification passes, the second terminal will open the access permission for the first terminal to access the second terminal and send a positive response to the first terminal. After receiving the positive response, the first terminal will know that the security verification has passed and the complete verification process has been completed. The first terminal already has the access permission to access the second terminal and does not need to continue the verification process. The first terminal can subsequently access the second terminal normally.

[0039] Alternatively, if the security verification fails, the second terminal will not open the access permission for the first terminal to access the second terminal, and will send a negative response to the first terminal. After receiving the negative response, the first terminal will know that the security verification has failed, the complete verification process has been completed, the first terminal does not have the access permission to access the second terminal, and the first terminal will not be able to access the second terminal subsequently.

[0040] If the first terminal needs to access the second terminal later, the first terminal will re-initiate a complete verification process.

[0041] Based on the above one-time verification mechanism, criminals may forge an illegal first terminal and attempt to perform illegal security verification on the access right of the illegal first terminal to the second terminal.

[0042] For example, a criminal could illegally calculate the verification method used by the second terminal to perform security verification on the first terminal's access rights to the second terminal in response to the verification request through brute force, and then forge the verification request based on that verification method. For example, a criminal could illegally calculate the method used by the second terminal to determine whether a preset security verification condition is satisfied in response to the verification request, and then forge the verification request based on that determination method.

[0043] The illegal first terminal sends a forged verification request to the second terminal, and the second terminal performs a security verification on the access right of the illegal first terminal to the second terminal based on the forged verification request sent by the illegal first terminal, for example, determining whether a preset security verification condition is met in response to the forged verification request.

[0044] Since the forged verification request is forged by criminals through brute force cracking and other illegal statistical verification methods (for example, a method of determining whether a preset security verification condition is met in response to a verification request), the security verification is easily passed.

[0045] If the security verification passes (for example, the preset security verification conditions are met), the second terminal will open the access permission for the illegal first terminal to access the second terminal, and will send a positive response to the illegal first terminal. After receiving the positive response, the illegal first terminal will know that the security verification passes (for example, the preset security verification conditions are met), and the illegal first terminal has the access permission to access the second terminal. There is no need to continue the verification process, and the illegal first terminal can subsequently access the second terminal normally.

[0046] Alternatively, if the security verification fails (e.g., the preset security verification conditions are not met), the second terminal will not grant the illegal first terminal access to the second terminal and will send a negative response to the illegal first terminal. After receiving the negative response, the illegal first terminal will know that the security verification failed (e.g., the preset security verification conditions are not met) and that the illegal first terminal does not have access to the second terminal. Subsequently, the illegal first terminal will be unable to access the second terminal. If the illegal first terminal subsequently needs to access the second terminal, the illegal first terminal will re-initiate a complete verification process.

[0047] Therefore, the inventors have discovered that the complete verification process of “performing security verification on the access authority of the first terminal to the second terminal” only involves one verification, which results in low security.

[0048] In the present application, the complete verification process of "security verification of the access rights of the first terminal to the second terminal" involves at least two verifications. For example, in the two verifications, the first verification request is the first security verification in the complete verification process initiated by the first terminal, and the subsequent second verification request is the re-security verification in the complete verification process initiated by the first terminal. Only when both verifications are passed, the second terminal will open the access rights for the first terminal to access the second terminal and send a second response to the first terminal. After receiving the second response, the first terminal will know that this security verification has passed, and the two verifications involved in the complete verification process have been completed. The first terminal already has the access rights to access the second terminal and does not need to continue verification. The first terminal can subsequently access the second terminal normally.

[0049] For example, the second terminal performs security verification on the access right of the first terminal to the second terminal based on the first verification request sent by the first terminal (determining whether the first preset security verification condition is met in response to the first verification request sent by the first terminal). This is the first security verification. If the security verification passes (for example, the first preset security verification condition is met), the second terminal does not send a second response to the first terminal, but sends a first response to the first terminal. The first response is used to instruct the first terminal to send a second verification request, for example, to instruct the first terminal to perform security verification again on the access right of the first terminal to the second terminal, so that the first terminal initiates the re-security verification in the complete verification process.

[0050] If the first terminal is a legitimate first terminal, then the legitimate first terminal is aware of the secondary verification mechanism. For example, the legitimate first terminal is a first terminal authorized by the manufacturer of the second terminal or the manufacturer of the vehicle in which the second terminal is installed, and the secondary verification mechanism is developed by the manufacturer of the second terminal or the manufacturer of the vehicle in which the second terminal is installed. With the active instruction or active authorization of the manufacturer of the second terminal or the manufacturer of the vehicle in which the second terminal is installed, the secondary verification mechanism can be actively embedded in the legitimate first terminal, so that the legitimate first terminal is aware of the secondary verification mechanism.

[0051] When the legitimate first terminal receives the first response, the legitimate first terminal will believe that the complete verification process has not yet ended and will send a second verification request to the second terminal based on the first response (re-security verification). The second terminal will re-verify the legitimate first terminal's access rights to the second terminal based on the second verification request (determine whether the second preset security verification condition is met in response to the second verification request sent by the first terminal). Only when the re-security verification passes (for example, the second preset security verification condition is met) will the second terminal open access rights to the second terminal for the legitimate first terminal and send a second response to the legitimate first terminal. The second response is used to indicate that the first terminal is allowed to access the second terminal, for example, to indicate that the complete verification process has ended and the second terminal has opened access rights to the second terminal for the legitimate first terminal. When the legitimate first terminal receives the second response sent by the second terminal, it will know that the security verification has passed, the complete verification process has been completed, the legitimate first terminal has access rights to the second terminal, and there is no need to continue the verification process. The legitimate first terminal can subsequently access the second terminal normally.

[0052] Alternatively, if the first terminal is an illegal first terminal, the illegal first terminal is unaware of the secondary verification mechanism. For example, the illegal first terminal is not a first terminal authorized by the manufacturer of the second terminal or the manufacturer of the vehicle where the second terminal is located. The secondary verification mechanism is developed by the manufacturer of the second terminal or the manufacturer of the vehicle where the second terminal is located. Without the active instruction or authorization of the manufacturer of the second terminal or the manufacturer of the vehicle where the second terminal is located, the secondary verification mechanism will not be actively implanted in the illegal first terminal. In this way, the illegal first terminal is unaware of the secondary verification mechanism.

[0053] When the illegal first terminal receives the first response, the illegal first terminal will know that the second terminal has not opened access rights to the second terminal for the illegal first terminal, and will consider that the complete verification process has ended, and will no longer initiate a re-security verification in the complete verification process, that is, it will not send a second verification request (re-security verification) to the second terminal based on the first response.

[0054] Even if the illegal first terminal still wants to obtain access rights to the second terminal, the illegal first terminal needs to re-initiate another complete verification process. This causes the illegal first terminal to continuously initiate the first security verification of the next complete verification process after the first security verification of the previous complete verification process is completed, and it has been hovering at the first security verification in each complete verification process in turn, and has been unable to enter the re-security verification in any complete verification process.

[0055] If the first terminal does not enter into the security verification again, the second terminal will not grant the first terminal access rights to the second terminal, and will not send a second response to the first terminal.

[0056] Therefore, since the illegal first terminal has been unable to enter the re-security verification in the complete verification process, the second terminal will not open the access permission for the illegal first terminal to access the second terminal, nor will it send a second response to the illegal first terminal. The illegal first terminal does not have the access permission to access the second terminal, and has been unable to receive the second response sent by the second terminal. The illegal first terminal will always believe that the complete verification process is not completed, which will cause the illegal first terminal to be unable to access the second terminal.

[0057] The illegal first terminal generally does not know nor has the ability to know the secondary verification mechanism. If the illegal first terminal does not know the secondary verification mechanism, the second terminal will not grant the illegal first terminal access rights to access the second terminal, and thus the illegal first terminal will not be able to access the second terminal.

[0058] In summary, the present application can improve the complexity of security verification through the mechanism of secondary verification, avoid the situation where verification can be passed with one verification, thereby improving the security of the second terminal and further improving the safety of the vehicle.

[0059] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for describing the embodiments.

[0061] Figure 1 A schematic diagram of the structure of a security verification system provided by an embodiment of the present invention;

[0062] Figure 2 A schematic diagram of the structure of a security verification system provided by an embodiment of the present invention;

[0063] Figure 3 A flowchart of a security verification method provided by an embodiment of the present invention;

[0064] Figure 4 A flowchart of a security verification method provided by an embodiment of the present invention;

[0065] Figure 5A flowchart of a security verification method provided by an embodiment of the present invention;

[0066] Figure 6 A schematic diagram of a security verification device provided by an embodiment of the present invention;

[0067] Figure 7 A schematic diagram of a security verification device provided by an embodiment of the present invention;

[0068] Figure 8 A schematic diagram of a security verification device provided by an embodiment of the present invention;

[0069] Figure 9 A block diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0070] Exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention may be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.

[0071] Figure 1 It is a structural diagram of a security verification system provided by an embodiment of the present invention.

[0072] The security verification system includes: a first terminal and a second terminal.

[0073] The first terminal is communicatively connected to the second terminal.

[0074] The first terminal may include: a mobile phone, a tablet computer, or a PDA (Personal Digital Assistant) and the like.

[0075] In this system, the second terminal can independently perform security verification on the access rights of the first terminal to the second terminal.

[0076] The second terminal may include a vehicle-mounted controller, etc., and the second terminal may be located on the vehicle.

[0077] in addition, Figure 2 It is a structural diagram of a security verification system provided by an embodiment of the present invention.

[0078] The security verification system includes: a first terminal, a second terminal and a cloud.

[0079] The first terminal is communicatively connected to the second terminal.

[0080] The first terminal is connected to the cloud for communication.

[0081] The first terminal may include: a mobile phone, a tablet computer, or a PDA, etc.

[0082] The second terminal may include a vehicle-mounted controller, etc., and the second terminal may be located on the vehicle.

[0083] The cloud can be a cloud server, etc.

[0084] The manufacturer of the cloud and the manufacturer of the second terminal can be the same manufacturer, or the manufacturer of the cloud and the manufacturer of the vehicle where the second terminal is located can be the same manufacturer, so that the cloud can assist the second terminal in securely verifying the access rights of the first terminal to the second terminal.

[0085] In this system, the second terminal can use the cloud to jointly perform security verification on the access rights of the first terminal to the second terminal.

[0086] Figure 3 This is a flow chart of the steps of a security verification method provided by an embodiment of the present invention, which is applied to Figure 1 In the security verification system shown in or 2, the method includes:

[0087] In step S101, the first terminal sends a first verification request to the second terminal.

[0088] The first verification request is used to perform security verification on the access permission of the first terminal to the second terminal.

[0089] The second terminal may be a second terminal on a vehicle, and configuration of the vehicle often needs to be performed through the second terminal.

[0090] In one example, the vehicle may be configured using the first terminal through the second terminal. For example, the first terminal may be connected to the second terminal, and then the vehicle may be configured using the first terminal through the second terminal.

[0091] In order to prevent criminals from maliciously configuring the vehicle and to improve the safety of the vehicle, the second terminal needs to perform security verification on the access rights of the first terminal to the second terminal.

[0092] Only when the security verification is passed (indicating that the identity of the first terminal is legal) will the second terminal open access rights to the first terminal. In this way, the first terminal has access rights to the second terminal, and then the first terminal can access the second terminal and use the first terminal to configure the vehicle through the second terminal.

[0093] Alternatively, if the security verification fails (indicating that the identity of the first terminal is illegal), the second terminal does not open the access rights of the first terminal to the second terminal. In this way, the first terminal does not have the access rights to access the second terminal, the first terminal cannot access the second terminal, and the first terminal cannot be used to configure the vehicle through the second terminal to improve the safety of the vehicle.

[0094] To this end, in order to perform security verification on the access right of the first terminal to the second terminal, the first terminal may send a first verification request to the second terminal.

[0095] In step S102, the second terminal receives a first verification request sent by the first terminal.

[0096] In step S103 , the second terminal determines whether a first preset security verification condition is met in response to the first verification request sent by the first terminal.

[0097] In this way, the second terminal performs security verification on the access authority of the first terminal to the second terminal according to the first verification request.

[0098] There are multiple ways to determine whether the first preset security verification condition is met in response to the first verification request sent by the first terminal. This application does not limit which determination method is used when "determining whether the first preset security verification condition is met in response to the first verification request sent by the first terminal".

[0099] In one embodiment, the second terminal can determine by itself whether the first preset security verification condition is met (security verification of the access rights of the first terminal to the second terminal), that is, the determination method adopted by the second terminal supports the second terminal to determine by itself whether the first preset security verification condition is met.

[0100] Alternatively, in another embodiment, the second terminal may also use other devices to jointly determine whether the first preset security verification condition is met (security verification of the access rights of the first terminal to the second terminal), for example, using the cloud to jointly determine whether the first preset security verification condition is met, that is, the determination method adopted by the second terminal supports the second terminal to use other devices to jointly determine whether the first preset security verification condition is met.

[0101] In step S104 , in response to satisfying the first preset security verification condition, the second terminal sends a first response to the first terminal, where the first response is used to instruct the first terminal to send a second verification request.

[0102] For example, the first response is used to instruct the first terminal to re-perform security verification on the access authority of the first terminal to access the second terminal.

[0103] In the present application, the complete verification process of "security verification of the access rights of the first terminal to the second terminal" involves at least two verifications. For example, in the two verifications, the first verification request is the first security verification in the complete verification process initiated by the first terminal, and the subsequent second verification request is the second security verification in the complete verification process initiated by the first terminal.

[0104] The "determining whether the first preset security verification condition is satisfied in response to the first verification request sent by the first terminal" in step S103 is the first security verification in the complete verification process. If the security verification passes (the first preset security verification condition is satisfied), this is only the first security verification, and the complete verification process has not yet concluded. Therefore, the second terminal may not grant the first terminal access to the second terminal, but may instead send a first response to the first terminal. The first response is used to instruct the first terminal to send a second verification request. For example, the first response is used to instruct the first terminal to re-verify the first terminal's access to the second terminal, so that the first terminal can initiate the re-verification process.

[0105] Alternatively, if the security verification fails (the first preset security verification condition is not met), the second terminal does not open the access rights of the second terminal to the first terminal, and sends a third response to the first terminal. The third response is used to indicate that the access rights of the first terminal to the second terminal are not opened, the first preset security verification condition is not met, and the security verification fails, that is, the first terminal is not allowed to access the second terminal.

[0106] When the first terminal receives the third response, it can be known that the first preset security verification condition is not met, the security verification fails, the second terminal does not open the access right for the first terminal to access the second terminal, and the first terminal cannot access the second terminal.

[0107] In step S105 , the first terminal receives a first response sent by the second terminal.

[0108] In step S106 , the first terminal sends a second verification request to the second terminal in response to the first response sent by the second terminal.

[0109] The second verification request is used to perform security verification again on the access authority of the first terminal to the second terminal.

[0110] Since the first response instructs the first terminal to re-perform security verification on the access right of the first terminal to access the second terminal, in order to enable the first terminal to access the second terminal, it is also necessary to re-perform security verification on the access right of the first terminal to access the second terminal. For example, the first terminal also needs to initiate a re-security verification in the complete verification process, for example, sending a second verification request to the second terminal.

[0111] In the present application, the first verification request is not exactly the same as the second verification request. For example, the first verification request carries identification information of "first" about the first security verification to indicate that the first verification request is the first security verification in the complete verification process. The second verification request carries identification information of "again" about the re-security verification to indicate that the second verification request is the re-security verification in the complete verification process.

[0112] This allows the second terminal to determine whether the verification request is the first security verification or the second security verification based on the identification information in the verification request, and further allows the second terminal to know whether to send a first response or a second response to the first terminal after the security verification passes.

[0113] In step S107 , the second terminal receives the second verification request sent by the first terminal.

[0114] In step S108 , the second terminal determines whether a second preset security verification condition is met in response to the second verification request sent by the first terminal.

[0115] In this way, the second terminal performs security verification again on the access authority of the first terminal to the second terminal according to the second verification request.

[0116] There are multiple ways to determine whether the second preset security verification condition is met in response to the second verification request sent by the first terminal. This application does not limit which determination method is used when "determining whether the second preset security verification condition is met in response to the second verification request sent by the first terminal".

[0117] In one embodiment, the second terminal can determine by itself whether the second preset security verification condition is met (security verification is performed again on the access permission of the first terminal to access the second terminal), that is, the determination method adopted by the second terminal supports the second terminal to determine by itself whether the second preset security verification condition is met.

[0118] Alternatively, in another embodiment, the second terminal may also use other devices to jointly determine whether the second preset security verification condition is met (re-security verification of the access rights of the first terminal to the second terminal), for example, using the cloud to jointly determine whether the second preset security verification condition is met, that is, the determination method adopted by the second terminal supports the second terminal to use other devices to jointly determine whether the second preset security verification condition is met.

[0119] In step S109 , in response to satisfying the second preset security verification condition, the second terminal sends a second response to the first terminal, where the second response is used to indicate that the first terminal is allowed to access the second terminal.

[0120] For example, in response to satisfying the second preset security verification condition, the second terminal opens the access permission for the first terminal to access the second terminal, and the second terminal sends a second response to the first terminal. The second response is used to indicate that the access permission for the first terminal to access the second terminal has been opened, allowing the first terminal to access the second terminal.

[0121] The second response is also used to indicate that the full authentication process has concluded.

[0122] In the present application, the complete verification process of "security verification of the access rights of the first terminal to the second terminal" involves at least two verifications. For example, in the two verifications, the previous first verification request is the first security verification in the complete verification process initiated by the first terminal, and the second verification request is the second security verification in the complete verification process initiated by the first terminal.

[0123] The "determining whether the second preset security verification condition is satisfied in response to the second verification request sent by the first terminal" in step S108 is a second security verification in the complete verification process. If the second security verification passes (the second preset security verification condition is satisfied), the complete verification process has concluded, and both security verifications have passed (the first preset security verification condition and the second preset security verification condition are satisfied). The second terminal can grant the first terminal access to the second terminal and send a second response to the first terminal, indicating that access to the second terminal has been granted to the first terminal, allowing the first terminal to access the second terminal.

[0124] Alternatively, if the security verification fails again (the second preset security verification condition is not met), the second terminal does not open the access rights of the second terminal to the first terminal, and can send a third response to the first terminal. The third response is used to indicate that the access rights of the first terminal to the second terminal are not opened, the second preset security verification condition is not met, and the security verification fails, that is, the first terminal is not allowed to access the second terminal.

[0125] When the first terminal receives the third response, it can be known that the second preset security verification condition is not met, the security verification fails, the second terminal does not open the access right of the first terminal to the second terminal, and the first terminal cannot access the second terminal.

[0126] In step S110 , the first terminal receives a second response sent by the second terminal.

[0127] Based on the second response, the first terminal can know that the second terminal has opened access rights for the first terminal to access the second terminal. That is, the first terminal already has access rights to access the second terminal and is qualified to access the second terminal. In this way, the first terminal can access the second terminal normally, and then the second terminal can respond to the access request sent by the first terminal.

[0128] Sometimes, criminals may illegally count the above-mentioned secondary verification mechanism through brute force cracking and other methods, and illegally count the method by which the second terminal determines whether the preset security verification conditions are met through brute force cracking and other methods (for example, the method by which the second terminal performs security verification on the access rights of the first terminal to the second terminal based on the verification request).

[0129] If criminals illegally calculate the above-mentioned secondary verification mechanism through brute force hacking or other means, and illegally calculate the method by which the second terminal determines whether the preset security verification conditions are met through brute force hacking or other means, the criminals will actively implant the secondary verification mechanism in the illegal first terminal to make the illegal first terminal aware of the secondary verification mechanism.

[0130] In this way, after receiving the first response sent by the second terminal, the illegal first terminal will send a second verification request to the second terminal based on the first response, so that the second terminal receives the second verification request sent by the illegal first terminal, and responds to the second verification request sent by the first terminal to determine whether the second preset security verification condition is met (for example, the access right of the illegal first terminal to access the second terminal is re-verified based on the second verification request). In the case of passing the second security verification, in response to meeting the second preset security verification condition, the access right to the second terminal is opened to the illegal first terminal, and a second response is sent to the illegal first terminal. After that, the illegal first terminal can receive the second response sent by the second terminal, and then the illegal first terminal can illegally access the second terminal, posing a safety hazard to the second terminal, and then posing a safety hazard to the vehicle.

[0131] Thus, in order to further improve the safety of the vehicle, in another embodiment of the present application, the first preset safety verification condition is different from the second preset safety verification condition.

[0132] For example, the verification method for performing security verification on the access right of the first terminal to the second terminal according to the first verification request is different from the verification method for performing security verification on the access right of the first terminal to the second terminal according to the second verification request.

[0133] That is, in the at least two verifications involved in the complete verification process of "performing security verification on the access authority of the first terminal to the second terminal", the verification method of the first security verification is different from the verification method of the second security verification.

[0134] In this way, even if the criminals illegally count the above-mentioned secondary verification mechanism through brute force cracking or other methods, and even if the criminals illegally count the determination method of the second terminal to determine whether the first preset security verification condition is met (for example, the verification method in which the second terminal performs security verification on the access permission of the first terminal to the second terminal according to the first verification request) through brute force cracking or other methods, if the criminals have not counted the determination method of the second terminal to determine whether the second preset security verification condition is met (for example, the verification method in which the second terminal performs security verification on the access permission of the first terminal to the second terminal again according to the second verification request), then the criminals cannot forge the second verification request based on the "determination method of the second terminal to determine whether the second preset security verification condition is met (for example, the verification method in which the second terminal performs security verification on the access permission of the first terminal to the second terminal again according to the second verification request)", and thus the illegal first terminal cannot send a forged second verification request to the second terminal after receiving the first response sent by the second terminal.

[0135] As a result, the second terminal cannot determine whether the second preset security verification condition is met in response to the second verification request sent by the first terminal, and thus cannot achieve the purpose of "sending a second response to the first terminal in response to meeting the second preset security verification condition".

[0136] For example, the second terminal cannot re-verify the access authority of the illegal first terminal to the second terminal, thereby failing to achieve the purpose of "re-verifying the access authority of the illegal first terminal to the second terminal".

[0137] Alternatively, even if the second terminal forges the second verification request, since the forged second verification request is not forged according to the "determination method of the second terminal determining whether the second preset security verification condition is met (for example, the verification method of the second terminal re-security-verifying the access right of the first terminal to access the second terminal according to the second verification request)", the second preset security verification condition will hardly be met, that is, the security verification will hardly pass, and thus the purpose of "sending a second response to the first terminal in response to meeting the second preset security verification condition" cannot be achieved, for example, the purpose of "re-security-verifying the access right of the illegal first terminal to access the second terminal" cannot be achieved.

[0138] In this way, the second terminal will not grant access rights to the illegal first terminal, so that the illegal first terminal cannot access the second terminal, thereby improving the security of the second terminal and further improving the security of the vehicle.

[0139] In one embodiment of the present application, see Figure 4 , step S103 includes:

[0140] In step S201, the second terminal sends a first random seed to the first terminal in response to a first verification request.

[0141] The second terminal generates a first random seed according to the first verification request.

[0142] In the present application, the generated first random seed may be a random number, etc. For any random number generated, the key generated based on the random number is unique. That is, the keys generated based on different random numbers may be different. The encryption algorithm corresponding to the random number in the encryption algorithm library is unique. Different random numbers correspond to different encryption algorithms in the encryption algorithm library. Therefore, the key obtained by encrypting the random number according to the encryption algorithm corresponding to the random number in the encryption algorithm library is unique. That is, the keys obtained by encrypting different random numbers according to the encryption algorithms corresponding to different random numbers in the encryption algorithm library are different.

[0143] Encryption algorithms may include: CRC (Cyclic Redundancy Check), AES (Advanced Encryption Standard), CBC (Cipher Block Chaining), etc.

[0144] The encryption algorithm in this application is not fixed, but is dynamically screened based on a random seed, which can increase the difficulty of being cracked.

[0145] In step S202, the first terminal obtains a first key in response to a first random seed sent by the second terminal.

[0146] In one embodiment, this step can be implemented through the following process, including:

[0147] 2021. The first terminal sends the first random seed to the cloud in response to the first random seed sent by the second terminal.

[0148] In one embodiment, the cloud receives a first random seed sent by the first terminal. A first key is generated based on the first random seed. For example, the first encryption algorithm is located in the cloud. The cloud can encrypt the first random seed based on the first encryption algorithm to obtain the first key. The first encryption algorithm can be pre-stored in the cloud or obtained by the cloud in real time from other devices. For example, the cloud can select an encryption algorithm from a first encryption algorithm library in the cloud based on the first random seed and use it as the first encryption algorithm; the first encryption algorithm library has multiple different encryption algorithms, and the encryption algorithm selected from the first encryption algorithm library is different depending on the random seed. The first random seed is then encrypted based on the selected encryption algorithm to obtain the first key. The cloud sends the first key to the first terminal. The first terminal receives the first key sent by the cloud.

[0149] 2022. Receive a first key sent by the cloud; the first key is generated by the cloud in response to a first random seed and sent to the first terminal.

[0150] In step S203, the first terminal sends the first key to the second terminal.

[0151] In step S204, the second terminal determines whether a first preset security verification condition is met in response to the first key sent by the first terminal.

[0152] In one embodiment, the first key is obtained by encrypting a first random seed using a first encryption algorithm. For example, the first key is obtained by encrypting the first random seed using the first encryption algorithm in the cloud or on the first terminal. Thus, in this step, when the second terminal determines whether a first preset security verification condition is satisfied in response to the first key sent by the first terminal, it may obtain a third key. The third key is obtained by encrypting the first random seed using the first encryption algorithm on the second terminal. The third key may be obtained by encrypting the first random seed using the first encryption algorithm after the second terminal receives the first key sent by the first terminal, or the third key may be obtained by encrypting the first random seed using the first encryption algorithm after the second terminal generates the first random seed. The first encryption algorithm may be located on the second terminal. Alternatively, the first encryption algorithm may be located on the cloud or on the first terminal. The first key and the third key are verified to be identical. If the first key and the third key are identical, the first preset security verification condition is determined to be satisfied (determining that the security verification of the first terminal's access permission to the second terminal has passed). Alternatively, if the first key and the third key are different, the first preset security verification condition is determined to be unsatisfactory (determining that the security verification of the first terminal's access permission to the second terminal has failed).

[0153] In one embodiment of the present application, the inventors have observed historical statistics and found that, in general, the process from step S201, "the second terminal responds to the first verification request and sends the first random seed to the first terminal," to step S204, "the second terminal responds to the first key sent by the first terminal and determines whether the first preset security verification condition is satisfied," typically takes a short time. For example, it typically completes within a few seconds.

[0154] It was also found that the situation in which the process from step S201 "the second terminal responds to the first verification request and sends the first random seed to the first terminal" to step S204 "the second terminal responds to the first key sent by the first terminal and determines whether the first preset security verification condition is met" takes a longer time often occurs on an illegal first terminal. For example, the illegal first terminal invades the cloud and / or the second terminal through debugging, performs program breakpoints to achieve single-step testing, thereby consuming more time, which will result in the process from step S201 "the second terminal responds to the first verification request and sends the first random seed to the first terminal" to step S204 "the second terminal responds to the first key sent by the first terminal and determines whether the first preset security verification condition is met" taking a longer time.

[0155] To this end, in order to avoid an illegal first terminal posing a threat to the security of the cloud and / or the second terminal and to improve vehicle safety, in another embodiment of the present application, the second terminal determines whether it has received the first key sent by the first terminal within a third preset time period after the second terminal sends the first random seed to the first terminal.

[0156] If the second terminal does not receive the first key sent by the first terminal within a third preset time period after sending the first random seed to the first terminal, the security verification process is interrupted and a third response is sent to the first terminal, where the third response is used to indicate that the security verification failed.

[0157] Furthermore, the second terminal actively disconnects the communication connection with the first terminal to prevent the first terminal from continuing the single-step test.

[0158] The third preset time length includes: 10 seconds, 11 seconds, 12 seconds or 13 seconds, etc., which can be determined according to actual conditions and is not limited in this application.

[0159] In another embodiment of the present application, from the perspective of the cloud, the inventors have found through historical statistics that, in general, the time it takes for the cloud to receive the first random seed sent by the first terminal and send the first key to the first terminal is relatively short. For example, it usually takes only a few seconds.

[0160] It was also found that the situation where the cloud takes a longer time from receiving the first random seed sent by the first terminal to sending the first key to the first terminal often occurs on an illegal first terminal. For example, the illegal first terminal invades the cloud through debugging and performs program breakpoints to achieve single-step testing, which consumes more time. This will cause the cloud to take a longer time from receiving the first random seed sent by the first terminal to sending the first key to the first terminal.

[0161] To this end, in order to prevent an illegal first terminal from posing a threat to the security of the cloud, in another embodiment of the present application, the cloud determines whether the time between the current moment and the moment when the cloud receives the first random seed sent by the first terminal and generates the first key is greater than a second preset time.

[0162] When the time duration is greater than the second preset time duration, the cloud interrupts the process of generating the first key according to the first random seed.

[0163] The second preset time length is shorter than the third preset time length.

[0164] The second preset time length includes: 5 seconds, 6 seconds, 7 seconds or 8 seconds, etc., which can be determined according to actual conditions and is not limited in this application.

[0165] In addition, in order to confuse the illegal first terminal, the cloud can obtain an obfuscation key. The obfuscation key is different from the first key generated by the cloud based on the first random seed. The obfuscation key can be a key generated by the cloud based on other specific seeds. The specific seed is different from the first random seed sent by the second terminal to the first terminal. For example, the first random seed generated by the second terminal based on the first verification request (the first random seed sent to the first terminal) is a seed within a seed range, and the specific seed is not within the seed range. This makes the specific seed different from the first random seed generated by the second terminal based on the first verification request, and thus the obfuscation key generated by the cloud based on the specific seed is different from the first key generated by the cloud based on the first random seed.

[0166] Afterwards, the cloud can send the obfuscated key to the first terminal, so that the first terminal obtains the obfuscated key and sends the obfuscated key to the second terminal. After receiving the obfuscated key sent by the first terminal, the second terminal determines whether the first preset security verification condition is met (for example, security verification of the access permission of the first terminal to the second terminal) based on the obfuscated key and the first random seed. Since the obfuscated key is not generated based on the first random seed, after determining whether the first preset security verification condition is met (for example, security verification of the access permission of the first terminal to the second terminal), it will be determined that the first preset security verification condition is not met (for example, the verification fails). In this way, the second terminal will send a third response to the first terminal instead of sending the first response to the first terminal. If the first terminal does not receive the first response, it will not send the second verification request to the second terminal. The second terminal will not open the permission for the first terminal to access the second terminal, and the first terminal will not be able to access the second terminal, thereby improving the security of the second terminal and thus improving the safety of the vehicle.

[0167] Furthermore, the cloud proactively disconnects the communication connection with the first terminal to prevent the first terminal from continuing the single-step test.

[0168] In one embodiment of the present application, see Figure 5 , step S108 includes:

[0169] In step S301, the second terminal sends a second random seed to the first terminal in response to the second verification request.

[0170] The second terminal generates a second random seed according to the second verification request.

[0171] In the present application, the generated second random seed can be a random number, etc. For any two random numbers generated, the key generated based on the random number is unique. That is, the keys generated based on different random numbers can be different. The encryption algorithm corresponding to the random number in the encryption algorithm library is unique. Different random numbers correspond to different encryption algorithms in the encryption algorithm library. Therefore, the key obtained by encrypting the random number according to the encryption algorithm corresponding to the random number in the encryption algorithm library is unique. That is, the keys obtained by encrypting different random numbers according to the encryption algorithms corresponding to different random numbers in the encryption algorithm library are different.

[0172] Encryption algorithms may include: CRC, AES, CBC, etc.

[0173] The encryption algorithm in this application is not fixed, but is dynamically screened based on a random seed, which can increase the difficulty of being cracked.

[0174] In step S302, the first terminal obtains a second key in response to a second random seed sent by the second terminal.

[0175] The first key is obtained in response to the first random seed in a different manner than the second key is obtained in response to the second random seed.

[0176] In one embodiment, this step can be implemented through the following process, including:

[0177] 3021. The first terminal sends the second random seed to the cloud in response to the second random seed sent by the second terminal.

[0178] In one embodiment, the cloud receives a second random seed sent by the first terminal and generates a second key based on the second random seed. For example, the second encryption algorithm is located in the cloud. The cloud can encrypt the second random seed using the second encryption algorithm to obtain the second key. The second encryption algorithm can be pre-stored in the cloud or obtained in real time from another device. The first encryption algorithm and the second encryption algorithm are different. For example, the cloud can select an encryption algorithm from a second encryption algorithm library in the cloud based on the first random seed and use it as the second encryption algorithm. The second encryption algorithm library contains multiple different encryption algorithms, and the encryption algorithm selected from the second encryption algorithm library varies depending on the random seed. The second random seed is then encrypted using the selected encryption algorithm to obtain the second key. The encryption algorithms in the first encryption algorithm library do not overlap with those in the first encryption algorithm library. The encryption strength or security of any encryption algorithm in the second encryption algorithm library is greater than the encryption strength or security of any encryption algorithm in the first encryption algorithm library. The cloud sends the second key to the first terminal. The first terminal receives the second key sent by the cloud.

[0179] 3022. Receive a second key sent by the cloud; the second key is generated by the cloud in response to the second random seed and sent to the first terminal.

[0180] In step S303, the first terminal sends the second key to the second terminal.

[0181] In step S304, the second terminal determines whether a second preset security verification condition is met in response to the second key sent by the first terminal.

[0182] In one embodiment, the cloud generates the first key based on the first random seed in a different manner than the cloud generates the second key based on the second random seed.

[0183] In one embodiment, the second key is obtained by encrypting the second random seed using a second encryption algorithm. For example, the second key is obtained by encrypting the second random seed using the second encryption algorithm in the cloud or on the first terminal. Thus, in this step, when the second terminal determines whether the second preset security verification condition is met in response to the second key sent by the first terminal, it may obtain a fourth key. The fourth key is obtained by encrypting the second random seed using the second encryption algorithm. The fourth key may be obtained by encrypting the second random seed using the second encryption algorithm after the second terminal receives the second key sent by the first terminal, or the fourth key may be obtained by encrypting the second random seed using the second encryption algorithm after the second terminal generates the second random seed. The second encryption algorithm may be located on the second terminal, or alternatively, the second encryption algorithm may be located on the cloud or on the first terminal. The second key and the fourth key are verified to be identical. If the second key and the fourth key are identical, the second preset security verification condition is determined to be met (determining that the security verification of the first terminal's access permission to the second terminal has passed). Alternatively, if the second key and the fourth key are different, the second preset security verification condition is determined to be unmet (determining that the security verification of the first terminal's access permission to the second terminal has failed).

[0184] The first encryption algorithm used by the second terminal to obtain the third key is different from the second encryption algorithm used by the second terminal to obtain the fourth key.

[0185] The first key is obtained by selecting an encryption algorithm from a first encryption algorithm library based on the first random seed and encrypting the first random seed according to the selected encryption algorithm; the second key is obtained by selecting an encryption algorithm from a second encryption algorithm library based on the second random seed and encrypting the second random seed according to the selected encryption algorithm.

[0186] For example, the first key is obtained by the cloud selecting an encryption algorithm from the first encryption algorithm library in the cloud based on the first random seed and encrypting the first random seed according to the selected encryption algorithm; the second key is obtained by the cloud selecting an encryption algorithm from the second encryption algorithm library in the cloud based on the first random seed and encrypting the second random seed according to the selected encryption algorithm.

[0187] The encryption algorithms in the first encryption algorithm library do not overlap with the encryption algorithms in the second encryption algorithm library.

[0188] In addition, in one embodiment, the third key is obtained by the second terminal selecting an encryption algorithm from the first encryption algorithm library in the second terminal based on the first random seed and encrypting the first random seed according to the selected encryption algorithm; the fourth key is obtained by the second terminal selecting an encryption algorithm from the second encryption algorithm library in the second terminal based on the second random seed and encrypting the second random seed according to the selected encryption algorithm.

[0189] The encryption algorithm in the first encryption algorithm library does not overlap with the encryption algorithm in the first encryption algorithm library. The first encryption algorithm library in the second terminal is the same as the first encryption algorithm library in the cloud. The second encryption algorithm library in the second terminal is the same as the second encryption algorithm library in the cloud.

[0190] In one embodiment of the present application, the inventors have observed historical statistics and found that, in general, the process from step S301, "the second terminal responds to the second verification request and sends the second random seed to the second terminal," to step S304, "the second terminal responds to the second key sent by the first terminal and determines whether the second preset security verification condition is satisfied," typically takes a short time. For example, it typically takes only a few seconds.

[0191] It was also found that the situation in which the process from step S301 "the second terminal responds to the second verification request and sends a second random seed to the first terminal" to step S304 "the second terminal responds to the second key sent by the first terminal and determines whether the second preset security verification condition is met" takes a longer time often occurs on an illegal first terminal. For example, the illegal first terminal invades the cloud and / or the second terminal through debugging, performs program breakpoints to achieve single-step testing, thereby consuming more time, which will result in the process from step S301 "the second terminal responds to the second verification request and sends a second random seed to the first terminal" to step S304 "the second terminal responds to the second key sent by the first terminal and determines whether the second preset security verification condition is met" taking a longer time.

[0192] To this end, in order to avoid the illegal first terminal posing a threat to the security of the cloud and / or the second terminal and to improve vehicle safety, in another embodiment of the present application, the second terminal determines whether it has received the second key sent by the first terminal within a third preset time period after the second terminal sends the second random seed to the first terminal.

[0193] If the second terminal does not receive the second key sent by the first terminal within a third preset time period after sending the second random seed to the first terminal, the security verification process is interrupted and a third response is sent to the first terminal. The third response is used to indicate that the security verification failed.

[0194] Furthermore, the second terminal actively disconnects the communication connection with the first terminal to prevent the first terminal from continuing the single-step test.

[0195] The third preset time length includes: 10 seconds, 11 seconds, 12 seconds or 13 seconds, etc., which can be determined according to actual conditions and is not limited in this application.

[0196] In another embodiment of the present application, from the perspective of the cloud, the inventors have found through historical statistics that, in general, the time it takes for the cloud to receive the second random seed sent by the first terminal and send the second key to the first terminal is relatively short. For example, it usually takes only a few seconds.

[0197] It was also found that the situation where the cloud takes a longer time from receiving the second random seed sent by the first terminal to sending the second key to the first terminal often occurs on an illegal first terminal. For example, the illegal first terminal invades the cloud through debugging, sets program breakpoints to achieve single-step testing, which consumes more time, resulting in the cloud taking a longer time from receiving the second random seed sent by the first terminal to sending the second key to the first terminal.

[0198] To this end, in order to prevent an illegal first terminal from posing a threat to the security of the cloud, in another embodiment of the present application, the cloud determines whether the time between the current moment and the moment when the cloud receives the second random seed sent by the first terminal and the generation of the second key is greater than a second preset time.

[0199] When the time duration is greater than the second preset time duration, the cloud interrupts the process of generating the second key according to the second random seed.

[0200] The second preset time length is shorter than the third preset time length.

[0201] The second preset time length includes: 5 seconds, 6 seconds, 7 seconds or 8 seconds, etc., which can be determined according to actual conditions and is not limited in this application.

[0202] In addition, in order to confuse the illegal first terminal, the cloud can obtain an obfuscation key, which is different from the second key generated by the cloud based on the second random seed. The obfuscation key can be a key generated by the cloud based on other specific seeds. The specific seed is different from the second random seed sent by the second terminal to the first terminal. For example, the second random seed generated by the second terminal based on the second verification request (the second random seed sent to the first terminal) is a seed within a seed range, and the specific seed is not within the seed range. This makes the specific seed different from the second random seed generated by the second terminal based on the second verification request, and thus the obfuscation key generated by the cloud based on the specific seed is different from the second key generated by the cloud based on the second random seed.

[0203] Afterwards, the cloud can send the obfuscated key to the first terminal, so that the first terminal obtains the obfuscated key and sends the obfuscated key to the second terminal. After receiving the obfuscated key sent by the first terminal, the second terminal determines whether the second preset security verification condition is met (for example, security verification of the access permission of the first terminal to the second terminal) based on the obfuscated key and the second random seed. Since the obfuscated key is not generated based on the first random seed, after determining whether the second preset security verification condition is met (for example, security verification of the access permission of the first terminal to the second terminal), it will be determined that the first preset security verification condition is not met (for example, the verification fails). In this way, the second terminal will send a third response to the first terminal instead of sending the first response to the first terminal. If the first terminal does not receive the first response, it will not send the second verification request to the second terminal. The second terminal will not open the permission for the first terminal to access the second terminal, and the first terminal will not be able to access the second terminal, thereby improving the security of the second terminal and thus improving the safety of the vehicle.

[0204] Furthermore, the cloud proactively disconnects the communication connection with the first terminal to prevent the first terminal from continuing the single-step test.

[0205] In one embodiment of the present application, in order to improve the security of the second terminal and thus improve the safety of the vehicle, in the present application, the second terminal has a time period during which verification is prohibited, and the second terminal does not process verification requests received during the time period during which verification is prohibited.

[0206] Whether the second terminal sets a time period during which authentication is prohibited and the length of the set time period during which authentication is prohibited may be determined according to different situations.

[0207] In one example, if the second terminal determines that a preset security verification condition (such as a first preset security verification condition or a second preset security verification condition) is not met in response to a verification request sent by the first terminal, for example, if the second terminal performs security verification on the access right of the first terminal to the second terminal according to a verification request and the verification fails, the second terminal can set a time period for prohibiting verification. The starting time of the time period for prohibiting verification can be the time when the verification fails, and the length of the time period for prohibiting verification can be 10 seconds, 15 seconds or 20 seconds, etc.

[0208] In another example, if the second terminal responds to multiple verification requests sent continuously by the first terminal and determines that the preset security verification conditions (such as the first preset security verification condition or the second preset security verification condition) are not met, for example, if the second terminal fails to pass the security verification after multiple consecutive security verifications on the access rights of the first terminal to the second terminal, the second terminal can set a time period for prohibiting verification. The starting time of the time period for prohibiting verification can be the time when the last verification failed, and the length of the time period for prohibiting verification can be 1 hour, 2 hours, 12 hours or 24 hours, etc.

[0209] Accordingly, in step S101, when the second terminal receives the first verification request sent by the first terminal, it can determine whether the current time of the second terminal is within the time period prohibited from verification of the second terminal in response to the first verification request sent by the first terminal.

[0210] If the second terminal is not currently within the verification-prohibited time period of the second terminal, it is determined whether the first preset security verification condition is met. For example, security verification is performed on the access permission of the first terminal to the second terminal according to the first verification request.

[0211] Alternatively, when the current moment of the second terminal is within the time period during which verification is prohibited for the second terminal, it is uncertain whether the first preset security verification condition is met, and the second terminal may directly send a third response to the first terminal.

[0212] In one embodiment of the present application, after the second terminal determines whether a first preset security verification condition is met in response to a verification request sent by the first terminal, the first preset security verification condition may be met or may not be met.

[0213] After the second terminal responds to multiple verification requests continuously sent by the first terminal and determines whether the preset security verification conditions (such as the first preset security verification condition or the second preset security verification condition) are met respectively, the preset security verification conditions may not be met for multiple consecutive times.

[0214] For example, after a second terminal performs security verification on a first terminal's access rights to a second terminal based on a verification request, the security verification may or may not be passed. Furthermore, after a second terminal performs multiple security verifications on a first terminal's access rights to a second terminal (each based on a different verification request), the verification may fail multiple times in a row.

[0215] After the inventors conducted statistics on historical situations, they found that when the first terminal is a legitimate first terminal, after the legitimate first terminal sends a verification request to the second terminal, the second terminal verifies the access permission of the legitimate first terminal to access the second terminal based on this verification request, and the verification is usually successful. In addition, the second terminal is usually not required to perform multiple security verifications on the legitimate first terminal's access to the second terminal in succession. Furthermore, there is usually no situation where "the second terminal performs multiple security verifications on the legitimate first terminal's access to the second terminal in succession but fails the security verification multiple times in succession."

[0216] It is also found that the situation where "the second terminal performs multiple security verifications on the first terminal accessing the second terminal but fails the multiple security verifications" often occurs on an illegal first terminal.

[0217] That is, after the illegal first terminal sends a verification request to the second terminal and the second terminal verifies the access permission of the illegal first terminal to the second terminal based on this verification request, the verification may fail. There may also be a situation where "the second terminal performs multiple security verifications on the illegal first terminal's access to the second terminal but fails the security verification multiple times in a row."

[0218] To this end, in order to avoid an illegal first terminal posing a threat to the security of the second terminal and thereby improve vehicle safety, in another embodiment of the present application, whenever the second terminal fails to pass a verification of the access right of a first terminal to the second terminal, for example, whenever the second terminal determines in response to a verification request sent by a first terminal that a preset security verification condition (for example, a first preset security verification condition or a second preset security verification condition) is not met, the second terminal can update the number of consecutive determinations that the preset security verification condition is not met in the security verification performed for accessing the second terminal.

[0219] It should be noted that if the second terminal subsequently passes a verification of the access permission of a first terminal to access the second terminal, for example, if the second terminal subsequently determines that a preset security verification condition (for example, a first preset security verification condition or a second preset security verification condition) is met in response to a verification request sent by the first terminal, then the "number of consecutive determinations in the security verification performed for accessing the second terminal that the preset security verification condition is not met" can be automatically cleared.

[0220] “The number of times that the preset security verification condition is continuously determined not to be satisfied in the security verification performed for accessing the second terminal” may not be cleared when the second terminal is turned off.

[0221] Accordingly, in response to the first verification request sent by the first terminal, the second terminal may determine whether the number of consecutive determinations that the preset security verification condition is not satisfied in the security verification performed for accessing the second terminal is less than a first preset number.

[0222] If the number of times that the preset security verification condition is not satisfied in the security verification performed for accessing the second terminal is less than a first preset number, it is determined whether the first preset security verification condition is satisfied.

[0223] Alternatively, when the number of consecutive determinations that the preset security verification condition is not met in the security verification performed for accessing the second terminal is greater than or equal to the first preset number of times, the operation of determining whether the first preset security verification condition is met is not performed, and the second terminal can directly send a third response to the first terminal.

[0224] The first preset number of times may include 2, 3, 4, 5 or 6, etc., which may be determined according to actual conditions and is not limited in this application.

[0225] In another embodiment of the present application, when the security verification of the access right of the first terminal to the second terminal fails according to the first verification request, or when the security verification of the access right of the first terminal to the second terminal fails again according to the second verification request, for example, in response to the first verification request sent by the first terminal, it is determined that the first preset security verification condition is not satisfied, or in response to the second verification request sent by the first terminal, it is determined that the second preset security verification condition is not satisfied, then the number of consecutive failed security verifications in the security verification performed for accessing the second terminal can be updated, for example, the number of consecutive determinations that the preset security verification condition is not satisfied (for example, the first preset security verification condition or the second preset security verification condition) in the security verification performed for accessing the second terminal is updated. For example, the value of "the number of consecutive determinations that the preset security verification condition is not satisfied in the security verification performed for accessing the second terminal" recorded in the second terminal is increased by 1.

[0226] In addition, if the security verification of the access right of the first terminal to the second terminal fails in a first verification request, or if the security verification of the access right of the first terminal to the second terminal fails again in accordance with a second verification request, for example, if it is determined that the first preset security verification condition is not satisfied in response to the first verification request sent by the first terminal, or if it is determined that the second preset security verification condition is not satisfied in response to the second verification request sent by the first terminal, a time period during which verification is prohibited for the second terminal may be set. The starting time of the time period during which verification is prohibited may be the time when verification fails (e.g., the time when the preset security verification condition is determined to be not satisfied), and the duration of the time period during which verification is prohibited may be 10 seconds, 15 seconds, or 20 seconds, etc.

[0227] Alternatively, in a case where the security verification of the access right of the first terminal to access the second terminal fails in the first verification request, or in a case where the security verification of the access right of the first terminal to access the second terminal fails again according to the second verification request, the number of consecutive determinations that the preset security verification condition is not satisfied in the security verification performed for accessing the second terminal can be updated first, and then it can be determined whether the updated number is greater than or equal to a third preset number.

[0228] In the case that the updated number of times is less than the third preset number of times, the time period for prohibiting authentication of the second terminal may not be set.

[0229] Alternatively, when the updated number of times is greater than or equal to the third preset number of times, the time period during which the second terminal is prohibited from verification is set again.

[0230] For example, the authentication-prohibited time period of the second terminal is set according to the updated number of times.

[0231] The greater the number of updates, the longer the duration of the authentication-prohibited time period of the second terminal is set; or the less the number of updates, the shorter the duration of the authentication-prohibited time period of the second terminal is set.

[0232] The third preset number of times can be 2, 3, 4 or 5, etc., which can be determined according to actual conditions and is not limited in this application.

[0233] For example, if the number of updates is greater than or equal to 3 and less than 10, the duration of the time period during which verification is prohibited for the second terminal is set to 10 seconds; or, if the number of updates is greater than or equal to 10, the duration of the time period during which verification is prohibited for the second terminal is set to 24 hours, etc.

[0234] In one embodiment of the present application, the inventors conducted historical statistics and found that, generally, under normal needs, there are not many legitimate external devices that need to access the second terminal. During the period from the start of the second terminal to the shutdown of the second terminal (the second terminal is in operation), if a legitimate external device needs to access the second terminal, it often only needs to access the second terminal once or twice, etc., and generally will not make more visits. For example, even if it is necessary to legally configure the vehicle through the second terminal, it often only needs to configure the vehicle once or twice through the second terminal, etc., and generally will not make more configurations.

[0235] Secondly, each time the external device needs to access the second terminal, it needs to first send a verification request to the second terminal, so that the second terminal performs security verification according to the verification request.

[0236] In summary, during the period from when the second terminal is started to when it is shut down (when the second terminal is in operation), the second terminal usually only needs to perform "security verification according to the verification request" twice (including one re-verification), or needs to perform "security verification according to the verification request" four times (including two re-verifications), and needs to perform "security verification according to the verification request" more times in sequence.

[0237] It was also found that the situation where "the second terminal performs security verification more times based on the verification request (performs more times to determine whether the preset security verification conditions are met) during the period from the second terminal being started to the second terminal being shut down (the second terminal is in operation)" often occurs on an illegal first terminal.

[0238] That is, the illegal first terminal will send more verification requests to the second terminal during the period from the time the second terminal is started to the time the second terminal is shut down (the second terminal is in operation), so that the second terminal will perform more "security verification according to the verification request (determining whether the preset security verification conditions are met in response to the verification request)".

[0239] To this end, in order to avoid the illegal first terminal posing a threat to the safety of the second terminal and thereby improve vehicle safety, in another embodiment of the present application, each time the second terminal performs security verification based on an access request, the second terminal can update the number of times the second terminal performs security verification based on the verification request (the number of times the security verification performed for accessing the second terminal determines whether the preset security verification conditions are met).

[0240] It should be noted that the number of times the second terminal performs security verification according to the verification request (the number of times of determining whether the preset security verification condition is met in the security verification performed for accessing the second terminal) can be reset when the second terminal is turned off.

[0241] Accordingly, when the second terminal receives the first verification request sent by the first terminal, the second terminal can determine whether the number of times the second terminal determines whether the preset security verification conditions are met in the security verification performed for access to the second terminal after startup is less than a second preset number.

[0242] When the second terminal determines whether the preset security verification condition is satisfied in the security verification performed for access to the second terminal after startup a number of times that is less than a second preset number, it is determined whether the first preset security verification condition is satisfied.

[0243] Alternatively, when the second terminal determines whether the preset security verification condition is met in the security verification performed for access to the second terminal after startup, the number of times is greater than or equal to the second preset number, the action of determining whether the first preset security verification condition is met is not performed, and the second terminal can directly send a third response to the first terminal.

[0244] The second preset number of times may include 3, 4, 5, 6 or 7, etc., which may be determined according to actual conditions and is not limited in this application.

[0245] In one embodiment of the present application, the inventors have found through historical statistics that, in general, the time required for a second terminal to perform security verification of a legitimate first terminal's access rights to the second terminal based on a verification request sent by a legitimate first terminal is relatively short, typically completing the process within a few seconds.

[0246] It was also found that the situation where "the time required for the second terminal to perform security verification is longer" often occurs on an illegal first terminal. For example, the illegal first terminal invades the second terminal through debugging and performs program breakpoints to achieve single-step testing, which will take more time and cause the second terminal to take a longer time to perform security verification.

[0247] To this end, in order to avoid the illegal first terminal posing a threat to the security of the second terminal and thereby improve vehicle safety, in another embodiment of the present application, in the process of performing security verification on the access rights of the first terminal to the second terminal based on the first verification request (determining whether the first preset security verification condition is met in response to the first verification request), the second terminal can determine whether the time between the current moment and the moment when the first verification request sent by the first terminal is received is greater than the first preset time.

[0248] If the time is less than or equal to the first preset time, the process returns to the step of "determining whether the time between the current moment and the moment when the first verification request sent by the first terminal is received is greater than the first preset time".

[0249] Alternatively, when the time duration is greater than the first preset time duration, the second terminal may interrupt the process of performing security verification on the access rights of the first terminal to the second terminal according to the first verification request (determining whether the first preset security verification condition is met in response to the first verification request), and send a third response to the first terminal, where the third response is used to indicate that the security verification failed.

[0250] Furthermore, the second terminal actively disconnects the communication connection with the first terminal to prevent the first terminal from continuing the single-step test.

[0251] Furthermore, in the process of re-security-verifying the access rights of the first terminal to the second terminal according to the second verification request (determining whether the second preset security verification condition is met in response to the second verification request), the second terminal can determine whether the time between the current moment and the moment when the second verification request sent by the first terminal is received is greater than the first preset time.

[0252] If the time is less than or equal to the first preset time, the process returns to the step of "determining whether the time between the current moment and the moment when the second verification request sent by the first terminal is received is greater than the first preset time".

[0253] Alternatively, when the time duration is greater than the first preset time duration, the second terminal may interrupt the process of re-verifying the access rights of the first terminal to the second terminal according to the second verification request, and send a third response to the first terminal, where the third response is used to indicate that the re-security verification failed.

[0254] The first preset duration may include 5 seconds, 6 seconds, 7 seconds or 8 seconds, etc., which may be determined according to actual conditions and is not limited in this application.

[0255] Furthermore, the second terminal actively disconnects the communication connection with the first terminal to prevent the first terminal from continuing the single-step test.

[0256] Figure 6 1 is a schematic diagram of a security verification device provided by an embodiment of the present invention, which is applied to a first terminal. The device includes:

[0257] A first sending module 11 is configured to send a first verification request to a second terminal;

[0258] The second sending module 12 is used to send a second verification request to the second terminal in response to the first response sent by the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request when a first preset security verification condition is met; the first response is used to instruct the first terminal to send the second verification request.

[0259] In an optional implementation, the apparatus further includes:

[0260] The first receiving module is used to receive a second response sent by the second terminal, where the second response is sent by the second terminal to the first terminal in response to the second verification request when a second preset security verification condition is met, and the second response is used to indicate that the first terminal is allowed to access the second terminal.

[0261] In an optional implementation, the first preset security verification condition is different from the second preset security verification condition.

[0262] In an optional implementation, the apparatus further includes:

[0263] a first acquisition module, configured to acquire a first key in response to a first random seed sent by the second terminal; the first random seed is sent by the second terminal to the first terminal in response to the first verification request;

[0264] The third sending module is configured to send the first key to the second terminal, so that the second terminal determines whether a first preset security verification condition is met in response to the first key.

[0265] In an optional implementation, the first acquisition module includes:

[0266] a first sending unit, configured to send the first random seed to a cloud in response to the first random seed sent by the second terminal;

[0267] The first receiving unit is configured to receive the first key sent by the cloud; the first key is generated by the cloud in response to the first random seed and sent to the first terminal.

[0268] In an optional implementation, the apparatus further includes:

[0269] a second obtaining module, configured to obtain a second key in response to a second random seed sent by the second terminal, where the second random seed is sent by the second terminal to the first terminal in response to the second verification request;

[0270] A fourth sending module, configured to send the second key to the second terminal, so that the second terminal determines whether a second preset security verification condition is satisfied in response to the second key;

[0271] The first key is obtained in response to the first random seed in a different manner from the second key is obtained in response to the second random seed.

[0272] In an optional implementation, the second acquisition module includes:

[0273] a second sending unit, configured to send the second random seed to the cloud in response to the second random seed sent by the second terminal;

[0274] The second receiving unit is configured to receive the second key sent by the cloud; the second key is generated by the cloud in response to the second random seed and sent to the first terminal.

[0275] In an optional implementation, the first key is obtained by encrypting the first random seed according to a first encryption algorithm;

[0276] The second key is obtained by encrypting the second random seed according to a second encryption algorithm;

[0277] The first encryption algorithm is different from the second encryption algorithm.

[0278] In an optional implementation, the first key is obtained by selecting an encryption algorithm from a first encryption algorithm library according to the first random seed and encrypting the first random seed according to the selected encryption algorithm;

[0279] The second key is obtained by selecting an encryption algorithm from a second encryption algorithm library according to the second random seed and encrypting the second random seed according to the selected encryption algorithm;

[0280] The encryption algorithms in the first encryption algorithm library do not overlap with the encryption algorithms in the second encryption algorithm library.

[0281] Figure 7 : is a schematic diagram of a security verification device provided by an embodiment of the present invention, which is applied to a second terminal, and the device includes:

[0282] A first determining module 21 is configured to determine whether a first preset security verification condition is satisfied in response to a first verification request sent by the first terminal;

[0283] The fifth sending module 22 is configured to send a first response to the first terminal in response to satisfying a first preset security verification condition, where the first response is used to instruct the first terminal to send a second verification request.

[0284] In an optional implementation, the apparatus further includes:

[0285] a second determining module, configured to determine whether a second preset security verification condition is satisfied in response to a second verification request sent by the first terminal;

[0286] The sixth sending module is configured to send a second response to the first terminal in response to a second preset security verification condition being met, where the second response is used to indicate that the first terminal is allowed to access the second terminal.

[0287] In an optional implementation, the first preset security verification condition is different from the second preset security verification condition.

[0288] In an optional implementation, the first determining module includes:

[0289] a third sending unit, configured to send a first random seed to the first terminal in response to the first verification request;

[0290] The first determining unit is configured to determine whether a first preset security verification condition is met in response to a first key sent by the first terminal, where the first key is obtained by the first terminal in response to the first random seed and sent to the second terminal.

[0291] In an optional implementation, the second determining module includes:

[0292] a fourth sending unit, configured to send a second random seed to the first terminal in response to the second verification request;

[0293] a second determining unit, configured to determine whether a second preset security verification condition is satisfied in response to a second key sent by the first terminal, where the second key is obtained by the first terminal in response to the second random seed and sent to the second terminal;

[0294] The first key is obtained in response to the first random seed in a different manner from the second key is obtained in response to the second random seed.

[0295] In an optional implementation, the first key is obtained by encrypting the first random seed according to a first encryption algorithm;

[0296] The second key is obtained by encrypting the second random seed according to a second encryption algorithm;

[0297] The first encryption algorithm is different from the second encryption algorithm.

[0298] In an optional implementation, the first key is obtained by selecting an encryption algorithm from a first encryption algorithm library according to the first random seed and encrypting the first random seed according to the selected encryption algorithm;

[0299] The second key is obtained by selecting an encryption algorithm from a second encryption algorithm library according to the second random seed and encrypting the second random seed according to the selected encryption algorithm;

[0300] The encryption algorithms in the first encryption algorithm library do not overlap with the encryption algorithms in the second encryption algorithm library.

[0301] In an optional implementation, the first key is obtained by encrypting the first random seed according to a first encryption algorithm;

[0302] The first determining unit includes:

[0303] a first acquiring subunit, configured to acquire a third key, where the third key is obtained by encrypting the first random seed by the second terminal according to the first encryption algorithm;

[0304] a first verification subunit, configured to verify whether the first key and the third key are identical;

[0305] a first determining subunit, configured to determine that a first preset security verification condition is satisfied when the first key and the third key are the same;

[0306] or,

[0307] The first determining subunit is configured to determine that a first preset security verification condition is not satisfied when the first key is different from the third key.

[0308] In an optional implementation, the second key is obtained by encrypting the second random seed according to a second encryption algorithm;

[0309] The second determining unit includes:

[0310] a second obtaining subunit, configured to obtain a fourth key, where the fourth key is obtained by encrypting the second random seed by the second terminal according to the second encryption algorithm;

[0311] a second verification subunit, configured to verify whether the second key is identical to the fourth key;

[0312] a third determining subunit, configured to determine that a second preset security verification condition is satisfied when the second key is the same as the fourth key;

[0313] or,

[0314] a fourth determining subunit, configured to determine that a second preset security verification condition is not satisfied when the second key is different from the fourth key;

[0315] In an optional implementation, the first encryption algorithm used by the second terminal to obtain the third key is different from the second encryption algorithm used by the second terminal to obtain the fourth key.

[0316] In an optional implementation, the apparatus further includes:

[0317] a third determining module, configured to determine, in response to the first verification request sent by the first terminal, whether the current moment of the second terminal is within a time period during which verification of the second terminal is prohibited;

[0318] The first determining module is further configured to: determine whether a first preset security verification condition is satisfied when the second terminal is not currently located within a verification-prohibited time period of the second terminal.

[0319] In an optional implementation, the apparatus further includes:

[0320] a fourth determining module, configured to determine, in response to the first verification request sent by the first terminal, whether the number of consecutive determinations that a preset security verification condition is not satisfied in the security verification performed for accessing the second terminal is less than a first preset number;

[0321] The first determination module is further configured to: if the number of times is less than a first preset number, determine whether a first preset security verification condition is met.

[0322] In an optional implementation, the apparatus further includes:

[0323] a fifth determining module, configured to determine, in response to the first verification request sent by the first terminal, whether a number of determinations of whether a preset security verification condition is satisfied in security verification performed by the second terminal for access to the second terminal after startup is less than a second preset number;

[0324] The first determination module is further configured to: if the number of times is less than a second preset number, determine whether a first preset security verification condition is met.

[0325] In an optional implementation, the apparatus further includes:

[0326] a sixth determining module, configured to determine, in a process of determining whether a preset security verification condition is satisfied in response to the verification request sent by the first terminal, whether a time duration between a current moment and a moment when the verification request sent by the first terminal is received is greater than a first preset time duration;

[0327] The first interruption module is used to interrupt the process of determining whether a preset security verification condition is met in response to a verification request sent by the first terminal when the time duration is greater than a first preset time duration. The seventh sending module is used to send a third response to the first terminal, and the third response is used to indicate that the first terminal is not allowed to access the second terminal.

[0328] In an optional implementation, the apparatus further includes:

[0329] An updating module is used to update the number of consecutive determinations that the preset security verification condition is not met in the security verification performed for accessing the second terminal when the first preset security verification condition is not met, or when the second preset security verification condition is not met, and / or a setting module is used to set a time period for prohibiting verification of the second terminal.

[0330] Figure 8 Schematic diagram of a security verification device provided by an embodiment of the present invention, applied to the cloud, comprising:

[0331] A first generating module 31 is configured to generate a first key in response to a first random seed sent by the first terminal; the first random seed is sent to the cloud in response to the first random seed sent by the second terminal after the first terminal sends a first verification request to the second terminal;

[0332] An eighth sending module 32 is configured to send the first key to the first terminal; so that the first terminal responds to the first key and sends the first key to the second terminal; so that the second terminal responds to the first key and determines whether a first preset security verification condition is satisfied;

[0333] A second generation module 33 is configured to generate a second key in response to a second random seed sent by the first terminal; the second random seed is sent to the cloud by the first terminal in response to the second random seed sent by the second terminal after the first terminal sends a second verification request to the second terminal; the second verification request is sent by the first terminal to the second terminal in response to a first response sent by the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request if a first preset security verification condition is met; the first response is used to instruct the first terminal to send a second verification request to the second terminal;

[0334] The ninth sending module 34 is configured to send the second key to the first terminal, so that the first terminal responds to the second key and sends the second key to the second terminal, so that the second terminal responds to the second key and determines whether a second preset security verification condition is met.

[0335] In an optional implementation, the cloud generates the first key in response to the first random seed in a different manner than the cloud generates the second key in response to the second random seed.

[0336] In an optional implementation, the first generating module includes:

[0337] The first encryption unit is used to encrypt the first random seed according to a first encryption algorithm to obtain a first key.

[0338] In an optional implementation, the second generating module includes:

[0339] A second encryption unit, configured to encrypt a second random seed according to a second encryption algorithm to obtain a second key;

[0340] The first encryption algorithm is different from the second encryption algorithm.

[0341] In an optional implementation, the first encryption unit includes:

[0342] A first selection subunit, configured to select an encryption algorithm from a first encryption algorithm library in the cloud;

[0343] The first encryption subunit is used to encrypt the first random seed according to the selected encryption algorithm to obtain a first key.

[0344] In an optional implementation, the second encryption unit includes:

[0345] A second selection subunit is used to select an encryption algorithm from a second encryption algorithm library in the cloud;

[0346] A second encryption subunit, configured to encrypt the second random seed according to a selected encryption algorithm to obtain a second key;

[0347] The encryption algorithms in the first encryption algorithm library do not overlap with the encryption algorithms in the second encryption algorithm library.

[0348] In an optional implementation, the apparatus further includes:

[0349] A seventh determination module is configured to determine, between receiving the first random seed sent by the first terminal and generating the first key, whether a time duration between the current moment and the moment when the cloud receives the first random seed sent by the first terminal is greater than a second preset time duration;

[0350] The second interruption module is used to interrupt the process of generating the first key when the time is greater than a second preset time.

[0351] In an optional implementation, the apparatus further includes:

[0352] a third acquisition module, configured to acquire an obfuscated key, where the obfuscated key is different from a first key generated by the cloud based on the first random seed;

[0353] A tenth sending module is configured to send the obfuscated key to the first terminal.

[0354] In an optional implementation, the apparatus further includes:

[0355] The disconnection module is used to actively disconnect the communication connection with the first terminal.

[0356] For the above-mentioned device embodiment, since it is basically similar to the security verification method embodiment, the relevant parts can be referred to the partial description of the method embodiment.

[0357] The embodiment of the present invention further provides an electronic device, such as Figure 9 As shown, it includes a processor 501 , a communication interface 502 , a memory 503 and a communication bus 504 , wherein the processor 501 , the communication interface 502 and the memory 503 communicate with each other via the communication bus 504 .

[0358] The memory 503 is used to store computer programs.

[0359] When the processor 501 is used to execute the program stored in the memory 503, the following steps are implemented: sending a first verification request to the vehicle-mounted controller, so that the vehicle-mounted controller performs a security verification on the access right of the terminal to the vehicle-mounted controller according to the first verification request, and if the security verification passes, sending a first negative response to the terminal, the first negative response is used to instruct the terminal to perform a security verification on the access right of the terminal to the vehicle-mounted controller again; receiving the first negative response sent by the vehicle-mounted controller; sending a second verification request to the vehicle-mounted controller according to the first negative response; making the vehicle-mounted controller perform a security verification on the access right of the terminal to the vehicle-mounted controller again according to the second verification request, and if the security verification passes again, opening the access right of the terminal to the vehicle-mounted controller to the vehicle-mounted controller, sending a positive response to the terminal, the positive response is used to indicate that the access right of the terminal to the vehicle-mounted controller has been opened; receiving the positive response sent by the vehicle-mounted controller.

[0360] Alternatively, when the processor 501 is used to execute the program stored in the memory 503, the following steps are implemented: receiving a first verification request sent by the terminal; performing security verification on the access right of the terminal to the vehicle-mounted controller based on the first verification request; if the security verification passes, sending a first negative response to the terminal, the first negative response is used to instruct the terminal to perform security verification on the access right of the terminal to the vehicle-mounted controller again; receiving a second verification request sent by the terminal based on the first negative response; performing security verification on the access right of the terminal to the vehicle-mounted controller again based on the second verification request; if the security verification passes again, opening the access right of the terminal to the vehicle-mounted controller to the terminal, and sending a positive response to the terminal, the positive response is used to indicate that the access right of the terminal to the vehicle-mounted controller has been opened.

[0361] Alternatively, when the processor 501 is used to execute the program stored in the memory 503, the following steps are implemented: receiving a first random seed sent by the terminal; the first random seed is generated by the on-board controller and sent to the terminal according to the first verification request sent by the terminal; generating a first key according to the first random seed; sending the first key to the terminal; so that the terminal sends the first key to the on-board controller; so that the on-board controller performs security verification on the access right of the terminal to the on-board controller based on the first key and the first random seed; if the security verification passes, sending a first negative response to the terminal, the first negative response is used to instruct the terminal to re-security verify the access right of the terminal to the on-board controller; receiving a second random seed sent by the terminal; the second random seed is generated by the on-board controller and sent to the terminal according to the second verification request, the second verification request is sent by the terminal to the on-board controller according to the first negative response; generating a second key according to the second random seed; sending the second key to the terminal; so that the terminal sends the second key to the on-board controller; so that the on-board controller performs security verification on the access right of the terminal to the on-board controller based on the second key and the second random seed; if the security verification passes again, sending a positive response to the terminal, the positive response is used to indicate that the security verification passes.

[0362] The processor 501 may also implement other steps in the above security verification method, which will not be described in detail here.

[0363] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.

[0364] The communication interface is used for communication between the above electronic device and other devices.

[0365] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.

[0366] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0367] In another embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions that, when executed on a computer, enable the computer to execute the security verification method described in the above embodiment.

[0368] In another embodiment of the present invention, a computer program product including instructions is provided. When the computer program product is run on a computer, the computer executes the security verification method described in the above embodiment.

[0369] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0370] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0371] Each embodiment in this specification is described in a related manner. Similar portions between the various embodiments can be referenced to each other. Each embodiment focuses on the differences from other embodiments. The embodiments of the apparatus, electronic device, computer-readable storage medium, and computer program product containing instructions thereof are generally similar to the method embodiments, so their description is relatively simple. For related portions, reference can be made to the description of the method embodiments.

[0372] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the scope of protection of the present invention.

Claims

1. A security verification method, characterized in that: Applied to a first terminal, the method includes: Sending a first verification request to the second terminal; In response to a first response sent by the second terminal, a second verification request is sent to the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request, when a first preset security verification condition is met; the first response is used to instruct the first terminal to send the second verification request.

2. The method according to claim 1, characterized in that The method further comprises: Receive a second response sent by the second terminal, where the second response is sent by the second terminal to the first terminal in response to the second verification request when a second preset security verification condition is met, and the second response is used to indicate that the first terminal is allowed to access the second terminal.

3. The method according to claim 2, characterized in that The first preset security verification condition is different from the second preset security verification condition.

4. The method according to claim 2 or 3, characterized in that The method further comprises: acquiring a first key in response to a first random seed sent by the second terminal, wherein the first random seed is sent by the second terminal to the first terminal in response to the first verification request; The first key is sent to the second terminal; so that the second terminal responds to the first key and determines whether a first preset security verification condition is met.

5. The method according to claim 4, characterized in that The acquiring the first key in response to the first random seed sent by the second terminal includes: In response to the first random seed sent by the second terminal, sending the first random seed to the cloud; Receive the first key sent by the cloud; the first key is generated by the cloud in response to the first random seed and sent to the first terminal.

6. The method according to claim 4, characterized in that The method further comprises: acquiring a second key in response to a second random seed sent by the second terminal, where the second random seed is sent by the second terminal to the first terminal in response to the second verification request; sending the second key to the second terminal; so that the second terminal determines whether a second preset security verification condition is satisfied in response to the second key; The first key is obtained in response to the first random seed in a different manner from the second key is obtained in response to the second random seed.

7. The method according to claim 6, characterized in that The acquiring a second key in response to a second random seed sent by the second terminal includes: In response to the second random seed sent by the second terminal, sending the second random seed to the cloud; Receive the second key sent by the cloud; the second key is generated by the cloud in response to the second random seed and sent to the first terminal.

8. The method according to claim 6 or 7, characterized in that The first key is obtained by encrypting the first random seed according to a first encryption algorithm; The second key is obtained by encrypting the second random seed according to a second encryption algorithm; The first encryption algorithm is different from the second encryption algorithm.

9. The method according to claim 8, characterized in that The first key is obtained by selecting an encryption algorithm from a first encryption algorithm library according to the first random seed and encrypting the first random seed according to the selected encryption algorithm; The second key is obtained by selecting an encryption algorithm from a second encryption algorithm library according to the second random seed and encrypting the second random seed according to the selected encryption algorithm; The encryption algorithms in the first encryption algorithm library do not overlap with the encryption algorithms in the second encryption algorithm library.

10. A security verification method, characterized in that: Applied to the second terminal, the method includes: In response to a first verification request sent by the first terminal, determining whether a first preset security verification condition is met; In response to satisfying a first preset security verification condition, a first response is sent to the first terminal, where the first response is used to instruct the first terminal to send a second verification request.

11. The method according to claim 10, characterized in that The method further comprises: In response to the second verification request sent by the first terminal, determining whether a second preset security verification condition is met; In response to satisfying a second preset security verification condition, a second response is sent to the first terminal, where the second response is used to indicate that the first terminal is allowed to access the second terminal.

12. The method according to claim 11, characterized in that The first preset security verification condition is different from the second preset security verification condition.

13. The method according to claim 11 or 12, characterized in that The determining, in response to the first verification request sent by the first terminal, whether a first preset security verification condition is satisfied includes: In response to the first verification request, sending a first random seed to the first terminal; In response to a first key sent by the first terminal, determining whether a first preset security verification condition is met, where the first key is obtained by the first terminal in response to the first random seed and sent to the second terminal.

14. The method according to claim 13, wherein: The determining, in response to the second verification request sent by the first terminal, whether a second preset security verification condition is satisfied includes: In response to the second verification request, sending a second random seed to the first terminal; determining, in response to a second key sent by the first terminal, whether a second preset security verification condition is satisfied, where the second key is obtained by the first terminal in response to the second random seed and sent to the second terminal; The first key is obtained in response to the first random seed in a different manner from the second key is obtained in response to the second random seed.

15. The method according to claim 14, characterized in that The first key is obtained by encrypting the first random seed according to a first encryption algorithm; The second key is obtained by encrypting the second random seed according to a second encryption algorithm; The first encryption algorithm is different from the second encryption algorithm.

16. The method according to claim 15, characterized in that The first key is obtained by selecting an encryption algorithm from a first encryption algorithm library according to the first random seed and encrypting the first random seed according to the selected encryption algorithm; The second key is obtained by selecting an encryption algorithm from a second encryption algorithm library according to the second random seed and encrypting the second random seed according to the selected encryption algorithm; The encryption algorithms in the first encryption algorithm library do not overlap with the encryption algorithms in the second encryption algorithm library.

17. The method according to claim 14, characterized in that The first key is obtained by encrypting the first random seed according to a first encryption algorithm; The determining, in response to the first key sent by the first terminal, whether a first preset security verification condition is satisfied includes: Obtaining a third key, where the third key is obtained by encrypting the first random seed by the second terminal according to the first encryption algorithm; Verifying whether the first key and the third key are the same; When the first key and the third key are the same, determining that a first preset security verification condition is satisfied; Alternatively, when the first key is different from the third key, it is determined that the first preset security verification condition is not satisfied.

18. The method according to claim 17, characterized in that The second key is obtained by encrypting the second random seed according to a second encryption algorithm; The determining, in response to the second key sent by the first terminal, whether a second preset security verification condition is satisfied includes: Obtaining a fourth key, where the fourth key is obtained by the second terminal encrypting the second random seed according to the second encryption algorithm; Verifying whether the second key is the same as the fourth key; When the second key is the same as the fourth key, determining that a second preset security verification condition is satisfied; Alternatively, when the second key is different from the fourth key, it is determined that the second preset security verification condition is not satisfied.

19. The method according to claim 18, characterized in that A first encryption algorithm used by the second terminal to obtain the third key is different from a second encryption algorithm used by the second terminal to obtain the fourth key.

20. The method according to claim 10, wherein The method further comprises: In response to the first verification request sent by the first terminal, determining whether the current time of the second terminal is within a time period during which verification of the second terminal is prohibited; If the current moment of the second terminal is not within the time period during which verification of the second terminal is prohibited, it is determined whether the first preset security verification condition is met.

21. The method according to claim 10, wherein The method further comprises: In response to a first verification request sent by the first terminal, determining whether a number of consecutive determinations that a preset security verification condition is not satisfied in security verification performed for accessing the second terminal is less than a first preset number; If the number of times is less than the first preset number, it is determined whether the first preset security verification condition is met.

22. The method according to claim 10, wherein The method further comprises: In response to the first verification request sent by the first terminal, determining whether a number of determinations of whether a preset security verification condition is satisfied in security verification performed by the second terminal for access to the second terminal after startup is less than a second preset number; If the number of times is less than the second preset number, it is determined whether the first preset security verification condition is met.

23. The method according to claim 10, wherein The method further comprises: In a process of determining whether a preset security verification condition is satisfied in response to a verification request sent by a first terminal, determining whether a time duration between a current moment and a moment when the verification request sent by the first terminal is received is greater than a first preset time duration; If the duration is greater than the first preset time, the process of determining whether the preset security verification condition is met in response to the verification request sent by the first terminal is interrupted, and a third response is sent to the first terminal, where the third response is used to indicate that the first terminal is not allowed to access the second terminal.

24. The method according to claim 10, wherein The method further comprises: When the first preset security verification condition is not met, or when the second preset security verification condition is not met, the number of consecutive determinations that the preset security verification condition is not met in the security verification performed for accessing the second terminal is updated, and / or a time period for prohibiting verification of the second terminal is set.

25. A security verification method, characterized in that: Applied to the cloud, the method includes: generating a first key in response to a first random seed sent by the first terminal; the first random seed is sent to the cloud in response to the first random seed sent by the second terminal after the first terminal sends a first verification request to the second terminal; Sending a first key to a first terminal; causing the first terminal to respond to the first key, sending the first key to a second terminal; causing the second terminal to respond to the first key and determine whether a first preset security verification condition is satisfied; generating a second key in response to a second random seed sent by the first terminal; the second random seed is sent to the cloud by the first terminal in response to the second random seed sent by the second terminal after the first terminal sends a second verification request to the second terminal; the second verification request is sent by the first terminal to the second terminal in response to a first response sent by the second terminal; the first response is sent by the second terminal to the first terminal in response to the first verification request if a first preset security verification condition is met; the first response is used to instruct the first terminal to send a second verification request to the second terminal; Sending a second key to the first terminal; causing the first terminal to respond to the second key, sending the second key to the second terminal; causing the second terminal to respond to the second key, and determining whether a second preset security verification condition is met.

26. The method according to claim 25, characterized in that The cloud generates the first key in response to the first random seed in a different manner than the cloud generates the second key in response to the second random seed.

27. The method according to claim 25 or 26, characterized in that The generating a first key in response to a first random seed sent by the first terminal includes: The first random seed is encrypted according to a first encryption algorithm to obtain a first key.

28. The method according to claim 27, characterized in that The generating a second key in response to the second random seed sent by the first terminal includes: Encrypting the second random seed according to a second encryption algorithm to obtain a second key; The first encryption algorithm is different from the second encryption algorithm.

29. The method according to claim 28, characterized in that The step of encrypting the first random seed according to the first encryption algorithm to obtain the first key includes: Selecting an encryption algorithm from a first encryption algorithm library in the cloud; The first random seed is encrypted according to the selected encryption algorithm to obtain a first key.

30. The method according to claim 29, wherein The step of encrypting the second random seed according to the second encryption algorithm to obtain the second key includes: Selecting an encryption algorithm from a second encryption algorithm library in the cloud; Encrypting the second random seed according to the selected encryption algorithm to obtain a second key; The encryption algorithms in the first encryption algorithm library do not overlap with the encryption algorithms in the second encryption algorithm library.

31. The method according to claim 25, wherein The method further comprises: Between receiving the first random seed sent by the first terminal and generating the first key, determining whether the time between the current moment and the moment when the cloud receives the first random seed sent by the first terminal is greater than a second preset time; If the time is longer than the second preset time, the process of generating the first key is interrupted.

32. The method according to claim 31, wherein The method further comprises: Obtain an obfuscated key, where the obfuscated key is different from the first key generated by the cloud based on the first random seed; Sending the obfuscated key to the first terminal.

33. The method according to claim 31 or 32, characterized in that The method further comprises: Actively disconnect the communication connection with the first terminal.

34. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the method according to any one of claims 1 to 33 when executing the computer program stored in the memory.

35. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 33 is implemented.

36. A computer program product, when instructions in the computer program product are executed by a processor of an electronic device, enables the electronic device to perform the method according to any one of claims 1 to 33.

37. A vehicle, characterized in that: The vehicle comprises: the second terminal as described in claims 10-24.