Internet of vehicles data encryption processing method and device, electronic equipment and medium

By detecting the security level in vehicle network communications and performing dynamic encryption and signing, the problems of vehicle network data being easily cracked and having high computing load are solved, a balance is achieved between security and resource optimization, and the risks of vehicle communications are reduced.

CN120751373APending Publication Date: 2025-10-03ICLOUDSHIELD SECURITY TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510880977.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Existing Internet of Vehicles (IoV) data encryption methods are prone to being cracked, consume high power consumption for vehicle computing loads, and affect vehicle usage, and fail to effectively protect data security and integrity.

Method used

By detecting the security level of Internet of Vehicles communication, encrypting the data based on the communication level, and signing the encryption result with the signature key of the initiator's hardware security domain, the communication security level is dynamically set, combined with an identity-based cryptographic system, and different encryption algorithms and signature mechanisms are adopted.

Benefits of technology

It achieves the security and data integrity protection of vehicle network communications, balances vehicle status and computing load, optimizes resource utilization, and reduces the risk of vehicle communications being eavesdropped.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751373A_ABST
    Figure CN120751373A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of Internet of Vehicles, in particular to an Internet of Vehicles data encryption processing method and device, electronic equipment and a medium. The method comprises the steps of determining a communication security level when to-be-transmitted data initiated by an initiating end of the Internet of Vehicles to a receiving end is detected; encrypting the to-be-transmitted data based on the communication security level, and signing an encryption result by using a signature key pre-stored in a hardware security domain of the initiating end to obtain a signature result; and sending the signature result to a receiving end. And meanwhile, by combining an identifier-based password system, the purposes of security upgrading and cost optimization of the Internet of Vehicles data encryption technology are achieved, and the risk that vehicle communication is eavesdropped is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and in particular to a method, device, electronic device, and medium for encrypting and processing data in an Internet of Vehicles (IoV). Background Art

[0002] With the rapid development of intelligent connected vehicles (ICVs), vehicle-to-everything (V2X) communications have become a core technology for enabling autonomous driving, real-time road condition sharing, and remote vehicle management. The wireless nature of current V2X data transmission exposes it to severe security threats such as data eavesdropping, data tampering, and identity forgery. For example, attackers could intercept sensitive data (such as location, speed, and control commands) transmitted between a vehicle and the cloud, other vehicles, or infrastructure. Maliciously modifying communication content could cause vehicle malfunction or even accidents, or forge legitimate device identities to launch man-in-the-middle (MITM) attacks or denial-of-service (DoS) attacks.

[0003] Currently, Internet of Vehicles (IoV) data is commonly protected using cryptographic techniques. This encryption method focuses solely on the data being encrypted, without regard to the type, size, or power consumption of the vehicle. This results in encryption methods that are easily crackable, consume high power for vehicle computing loads, and even affect vehicle usability. Summary of the Invention

[0004] In view of this, one of the technical problems solved by the embodiments of the present application is to provide a method, device, electronic device and medium for encrypting and processing data in an Internet of Vehicles, which solves the problem of ensuring the security and integrity of data during Internet of Vehicles communication.

[0005] According to a first aspect of an embodiment of the present application, a method for encrypting data in an Internet of Vehicles is provided, the method comprising:

[0006] When detecting data to be transmitted from the initiator to the receiver of the Internet of Vehicles, determine the communication security level;

[0007] Encrypt the data to be transmitted based on the communication security level, and sign the encrypted result using the signature key pre-stored in the initiator's hardware security domain to obtain a signature result;

[0008] Send the signature result to the receiving end.

[0009] In a second aspect of an embodiment of the present application, a vehicle network data encryption processing device is disclosed, the device comprising:

[0010] A security level determination module is used to determine the communication security level when detecting data to be transmitted from the initiator of the Internet of Vehicles to the receiver;

[0011] The data encryption processing module is used to encrypt the data to be transmitted based on the communication security level and sign the encryption result using the signature key pre-stored in the hardware security domain of the initiator to obtain a signature result;

[0012] The data transmission processing module is used to send the signature result to the receiving end.

[0013] In a third aspect of an embodiment of the present application, an electronic device is disclosed. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.

[0014] In a fourth aspect of the embodiments of the present application, a computer-readable storage medium is disclosed, which stores a computer program. When the computer program is executed by a processor, the steps of the above method are implemented.

[0015] The embodiment of the present application determines the communication security level while detecting the data to be transmitted initiated by the initiator of the Internet of Vehicles to the receiving end, encrypts the data to be transmitted based on the communication security level, and signs the encryption result using the signature key pre-stored in the hardware security domain of the initiator, and then sends the signature result to the receiving end. This method of dynamically setting the communication security level according to the specific scenarios and needs of the Internet of Vehicles communication can not only ensure the security of the Internet of Vehicles communication, balance the vehicle status with the vehicle computing load and its power consumption, and optimize the resource utilization rate, but also achieves the purpose of security upgrade and cost optimization of Internet of Vehicles data encryption technology by combining with the identity-based cryptographic system, and reduces the risk of vehicle communications being eavesdropped. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0017] Figure 1 A flowchart of a method for encrypting data in an Internet of Vehicles (IoV) according to one embodiment of the present application is provided;

[0018] Figure 2 A schematic diagram of the structure of a vehicle network data encryption processing device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0019] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0020] It should be noted that although the functional modules are divided in the device schematic and the logical order is shown in the flowchart, in some cases, the steps shown or described can be performed in a different order than the module division in the device or the order in the flowchart.

[0021] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0022] According to an embodiment of the present application, a method for encrypting data in an Internet of Vehicles is provided. Figure 1 As shown, the method includes step S101, step S102 and step S103.

[0023] Step S101: upon detecting data to be transmitted from an initiator of the Internet of Vehicles to a receiver, determining a communication security level.

[0024] Specifically, before the initiator initiates communication with the receiver, mutual identity authentication is required to prevent middlemen from disguising themselves as legitimate devices to access the network. After the identity authentication is completed, the initiator initiates the data to be transmitted to the receiver. The data to be transmitted may include text, audio, video, firmware installation packages and their update packages, etc.

[0025] Specifically, the communication security level is used to characterize the degree of encryption of Internet of Vehicles data communications. More specifically, it can be set to a high security level, a low security level, and a general security level based on the preset security level influencing factors, or it can be set to security requirements from high to level 1, level 2, level 3, etc. When applied, the security level influencing factors may include the sensitivity of the data, the real-time transmission requirements, the network status, potential security threats, etc. For example, if the security level influencing factor is the network status, then the communication security level can be set to level 1 when the network speed is greater than the first threshold, the communication security level can be set to level 2 when the network speed is not greater than the first threshold and not less than the second threshold, and the communication security level can be set to level 3 when the network speed is less than the second threshold.

[0026] Step S102: Encrypt the data to be transmitted based on the communication security level, and sign the encryption result using the signature key pre-stored in the initiator hardware security domain to obtain a signature result.

[0027] Specifically, different communication security levels utilize different encryption algorithms and their corresponding operating modes. For example, when the communication security level is high, the algorithm used is SM4-CTR. Different communication security levels utilize different encryption algorithms to adapt to different vehicle states. For example, when the vehicle is in a low-battery state, a simple encryption algorithm can be used; when the vehicle is in an emergency state (such as an emergency braking scenario), an encryption algorithm with low latency and high security requirements is required. During application, the key service system can obtain the SM4 session key through key negotiation using the encryption algorithm used in the encryption mode. Then, based on the session key and timestamp, random number, message counter, and other information, a key derivation function provided by the corresponding encryption algorithm is used to generate a message key, which is then used for encryption. The key key is determined by at least one of the session key timestamp, random number message counter, and other information generated during the key negotiation process. Furthermore, the key negotiation can be updated according to a preset key rotation mechanism, such as once every 100 messages.

[0028] Specifically, the key service system may send the data to be transmitted to the initiator hardware security domain (such as a SIM card) to complete the signature using the signature key stored in the initiator hardware security domain.

[0029] Step S103: Send the signature result to the receiving end.

[0030] The embodiment of the present application determines the communication security level while detecting the data to be transmitted initiated by the initiator of the Internet of Vehicles to the receiving end, encrypts the data to be transmitted based on the communication security level, and signs the encryption result using the signature key pre-stored in the hardware security domain of the initiator, and then sends the signature result to the receiving end. This method of dynamically setting the communication security level according to the specific scenarios and needs of the Internet of Vehicles communication can not only ensure the security of the Internet of Vehicles communication, balance the vehicle status with the vehicle computing load and its power consumption, and optimize the resource utilization rate, but also achieves the purpose of security upgrade and cost optimization of Internet of Vehicles data encryption technology by combining with the identity-based cryptographic system, and reduces the risk of vehicle communications being eavesdropped.

[0031] In some embodiments, step S101 further includes:

[0032] Step S1011 (not shown): Determine the communication security level based on at least one of the data type of the data to be transmitted, the network status, and the security threat.

[0033] Specifically, the communication security level can be determined based on at least one of the data type, network status, and security threat. For example, when the communication security level is determined based on the three factors of data type, network status, and security threat, a parameter table corresponding to each of the data type, network status, and security threat can be provided. For example, when the data type is a predetermined type of control instruction (such as a vehicle startup control instruction), the value is A; when the network speed range is S1, the value is B; when the security threat is eavesdropping, the value is C. The data type, network status, and security threat are weighted and summed to calculate the communication security value, and the corresponding level is determined based on the communication security value. For example, when the communication security level is determined based on the network status, different network link speed ranges can be set to correspond to the communication level to determine the communication security level.

[0034] In some embodiments, the data type includes vehicle-related information and firmware packages, the vehicle-related information includes vehicle speed, V2X communication frequency, battery voltage, and vehicle shutdown time, and the step of determining the communication security level based on the data type of the data to be transmitted further includes:

[0035] If the vehicle speed is greater than a predetermined speed threshold and the V2X communication frequency domain is greater than a preset communication frequency threshold, the communication security level is determined to be a high security level;

[0036] If the battery voltage is less than a predetermined voltage threshold and the vehicle is off for a longer time than a threshold, the communication security level is determined to be a low security level;

[0037] If the data to be transmitted is a firmware package and the data volume of the firmware package is greater than the predetermined number threshold, or the vehicle speed is not greater than the predetermined vehicle speed threshold and the V2X communication frequency domain is not greater than the preset communication frequency threshold, or the battery voltage is not less than the predetermined voltage threshold and the vehicle shutdown time is not greater than the shutdown time threshold, then the communication security level is determined to be a general security level.

[0038] In this embodiment, the general security level is the conventional communication mode SM4-XTS, the high security level is the dynamic driving mode SM4-CTR, and the low security level is the low power mode SM4-ECB. The dynamic driving mode SM4-CTR features low latency and high throughput, making it suitable for real-time communication with millisecond-level response times and supports parallel computing, resulting in faster encryption speeds. The low power mode SM4-ECB features low power consumption and small code size, making its computations suitable for resource-constrained scenarios (such as low battery voltage) and for non-sensitive data (such as broadcast data). The conventional communication mode SM4-XTS features secure and tamper-resistant storage, making it suitable for block encryption and resumable downloads of large files.

[0039] In some embodiments, the signing key includes a first key and a second key, and step S102 further includes:

[0040] Determine the scenario type corresponding to the data to be transmitted;

[0041] If the scenario type is the first application scenario, the encrypted data is signed using the first key and the second key pre-stored in the initiator hardware security domain;

[0042] If the scenario type is the second application scenario, the first key is used for signing;

[0043] If the scenario type is the third application scenario, the second key is used for signing.

[0044] In the embodiment of the present application, the first key is stored in the SIM card of the initiator, and the second key is stored in other hardware locations of the initiator, such as flash memory. The International Mobile Subscriber Identity (IMSI) of the SIM card is used as the public key identifier, and the private key is injected and securely stored by the operator when the SIM card is issued. It is protected by the SIM card hardware security domain (SE), deeply integrating the Internet of Vehicles data encryption with the SIM card management system. When applied, the first key and the second key can also be stored in the same area according to business needs, such as both stored in the SIM, or both stored in other hardware locations of the initiator.

[0045] In an embodiment of the present application, different scenario types correspond to different levels of signature mechanisms. Specifically, the corresponding scenario type can be determined according to the data type. For example, highly sensitive data (such as high-security control instructions) corresponds to the first application scenario, and this scenario type adopts a dual signature mechanism, that is, a first key and a second key are used for signing. Specifically, signing with the first key is mainly used to determine the identity of the device, and signing with the second key is mainly used to prevent tampering. Low-sensitivity data is signed with the first key or the second key.

[0046] Specifically, the second application scenario is generally the preceding vehicle sudden braking warning, intersection collision warning, etc., and the third application scenario is generally the collaborative adaptive cruise mode in the Internet of Vehicles.

[0047] When applied, the first key can use the SM9 algorithm, and the second key can use the SM2 algorithm. SM9 signatures are faster than SM2 signatures and can meet millisecond-level response requirements such as emergency braking. SM2 signatures provide sufficient tamper resistance, so the key provided by the SM2 algorithm is used to sign vehicle status broadcast messages. This embodiment of the application controls the signing mechanism by determining the type of data to be transmitted, thereby achieving the goal of balancing security and performance in signatures.

[0048] Specifically, high-safety control instructions may include engine start, door unlocking, ADAS control instructions, OTA firmware update and other instructions.

[0049] In some embodiments, step S102 further includes:

[0050] Determine the message key based on a predefined key rotation mechanism;

[0051] Use the message key to encrypt the data to be transmitted to obtain the ciphertext;

[0052] Determine the current timestamp;

[0053] A hash calculation is performed based on the ciphertext and timestamp to obtain a hash value to sign the hash value.

[0054] Specifically, the key rotation mechanism can be determined based on information such as network status (such as signal strength), message sensitivity, and man-in-the-middle attacks. For example, the key update frequency can be adjusted when the number of messages reaches a threshold or a man-in-the-middle attack is detected. Specifically, the message key is derived from the session key, timestamp, random number, and message counter.

[0055] An embodiment of the present application provides a vehicle network data encryption processing device, such as Figure 2 As shown, the device 20 includes: a security level determination module 201, a data encryption processing module 202 and a data transmission processing module 203.

[0056] The security level determination module 201 is configured to determine the communication security level when detecting data to be transmitted from the initiator to the receiver of the Internet of Vehicles;

[0057] The data encryption processing module 202 is used to encrypt the data to be transmitted based on the communication security level and sign the encryption result using the signature key pre-stored in the hardware security domain of the initiator to obtain a signature result;

[0058] The data transmission processing module 203 is used to send the signature result to the receiving end.

[0059] The embodiment of the present application determines the communication security level while detecting the data to be transmitted initiated by the initiator of the Internet of Vehicles to the receiving end, encrypts the data to be transmitted based on the communication security level, and signs the encryption result using the signature key pre-stored in the hardware security domain of the initiator, and then sends the signature result to the receiving end. This method of dynamically setting the communication security level according to the specific scenarios and needs of the Internet of Vehicles communication can not only ensure the security of the Internet of Vehicles communication, balance the vehicle status with the vehicle computing load and its power consumption, and optimize the resource utilization rate, but also achieves the purpose of security upgrade and cost optimization of Internet of Vehicles data encryption technology by combining with the identity-based cryptographic system, and reduces the risk of vehicle communications being eavesdropped.

[0060] Furthermore, the security level determination module includes:

[0061] The level determination submodule is used to determine the communication security level based on at least one of the data type of the data to be transmitted, the network status and the security threat.

[0062] Furthermore, the data types include vehicle-related information and firmware packages. Vehicle-related information includes vehicle speed, V2X communication frequency, battery voltage, and vehicle shutdown time. The level determination submodule includes:

[0063] a first level determination unit, configured to determine that the communication security level is a high security level if the vehicle speed is greater than a predetermined vehicle speed threshold and the V2X communication frequency domain is greater than a preset communication frequency threshold;

[0064] a second level determination unit, configured to determine that the communication security level is a low security level if the battery voltage is less than a predetermined voltage threshold and the vehicle ignition off time is longer than an ignition off time threshold;

[0065] The third level determination unit is used to determine that the communication security level is a general security level if the data to be transmitted is a firmware package and the data volume of the firmware package is greater than a predetermined number threshold, or the vehicle speed is not greater than a predetermined vehicle speed threshold and the V2X communication frequency domain is not greater than a preset communication frequency threshold, or the battery voltage is not less than a predetermined voltage threshold and the vehicle shutdown time is not greater than a shutdown time threshold.

[0066] Furthermore, the signature key includes a first key and a second key, and the data encryption processing module includes:

[0067] A scene type determination submodule is used to determine the scene type corresponding to the data to be transmitted;

[0068] A dual signature processing submodule, configured to sign the encrypted data using a first key and a second key pre-stored in the initiator hardware security domain if the scenario type is the first application scenario;

[0069] A first single signature processing submodule, configured to use the first key to sign if the scenario type is the second application scenario;

[0070] The second single signature processing submodule is used to use the second key to sign if the scenario type is the third application scenario.

[0071] Furthermore, the scene type determination submodule includes:

[0072] a first scene determination unit, configured to determine the scene type as a first scene type if the data to be transmitted is a high-security control instruction;

[0073] a second scenario determining unit, configured to determine, if the data to be transmitted is a V2X safety message, that the scenario type is a second scenario type;

[0074] The third scene determination unit is configured to determine that the scene type is a third scene type if the data to be transmitted is a vehicle status broadcast message.

[0075] Furthermore, the high-security control instructions include at least engine start, door unlocking, ADAS control instructions, and OTA firmware update instructions.

[0076] The vehicle network data encryption processing device of this embodiment can execute the vehicle network data encryption processing method shown in the embodiment of this application. Its implementation principle is similar and will not be repeated here.

[0077] Another embodiment of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above method when executing the computer program.

[0078] Specifically, a processor may be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA, or other programmable logic device, a transistor logic device, a hardware component, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. A processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0079] Specifically, the processor is connected to the memory via a bus. The bus may include a path for transmitting information. The bus may be a PCI bus or an EISA bus. The bus may be divided into an address bus, a data bus, a control bus, etc.

[0080] The memory may be a ROM or other type of static storage device that can store static information and instructions, a RAM or other type of dynamic storage device that can store information and instructions, or an EEPROM, CD-ROM or other optical disk storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these.

[0081] Optionally, the memory is used to store the code of the computer program that executes the solution of the present application, and the execution is controlled by the processor. The processor is used to execute the application program code stored in the memory to implement the actions of the device provided by the above embodiment.

[0082] Another embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions for executing the method provided in the above embodiment.

[0083] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0084] Those skilled in the art will appreciate that all or some of the steps and systems in the method disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, and the computer-readable medium can include computer storage media (or non-transitory media) and communication media (or temporary media). As known to those skilled in the art, the term computer storage media is included in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data) and is volatile and non-volatile, removable, and non-removable. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, digital versatile disks (DVD), or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage, or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0085] The above is a specific description of the preferred implementation of the present application, but the present application is not limited to the above implementation mode. Technical personnel familiar with the field can also make various equivalent modifications or substitutions without violating the spirit of the present application. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present application.

Claims

1. A method for encrypting data in an Internet of Vehicles, characterized in that: include: When detecting data to be transmitted from the initiator to the receiver of the Internet of Vehicles, determine the communication security level; Encrypting the data to be transmitted based on the communication security level, and signing the encryption result using the signature key pre-stored in the initiator hardware security domain to obtain a signature result; The signature result is sent to the receiving end.

2. The method according to claim 1, characterized in that Determining the communication security level includes: The communication security level is determined based on at least one of a data type of the data to be transmitted, a network status, and a security threat.

3. The method according to claim 2, characterized in that The data type includes vehicle-related information and firmware packages, and the vehicle-related information includes vehicle speed, V2X communication frequency, battery voltage, and vehicle shutdown time. Based on the data type of the data to be transmitted, the communication security level is determined, including: If the vehicle speed is greater than a predetermined vehicle speed threshold and the V2X communication frequency domain is greater than a preset communication frequency threshold, determining that the communication security level is a high security level; If the battery voltage is less than a predetermined voltage threshold and the vehicle shutdown time is longer than a shutdown time threshold, determining that the communication security level is a low security level; If the data to be transmitted is a firmware package and the data volume of the firmware package is greater than a predetermined quantity threshold, or the vehicle speed is not greater than a predetermined vehicle speed threshold and the V2X communication frequency domain is not greater than a preset communication frequency threshold, or the battery voltage is not less than a predetermined voltage threshold and the vehicle shutdown time is not greater than a shutdown time threshold, then the communication security level is determined to be a general security level.

4. The method according to claim 1, wherein The signature key includes a first key and a second key. The encryption result is signed using the signature key pre-stored in the initiator hardware security domain to obtain a signature result, including: Determining a scenario type corresponding to the data to be transmitted; If the scenario type is the first application scenario, signing the encrypted data using the first key and the second key pre-stored in the initiator hardware security domain; If the scenario type is the second application scenario, signing is performed using the first key; If the scenario type is the third application scenario, the second key is used for signing.

5. The method according to claim 4, characterized in that The determining the scenario type corresponding to the data to be transmitted includes: If the data to be transmitted is a high-security control instruction, determining that the scene type is a first scene type; If the data to be transmitted is a V2X safety message, determining that the scenario type is a second scenario type; If the data to be transmitted is a vehicle status broadcast message, the scene type is determined to be the third scene type.

6. The method according to claim 5, characterized in that The high-security control instructions include at least engine start, door unlock, ADAS control instructions, and OTA firmware update instructions.

7. The method according to claim 1, characterized in that The encrypting the data to be transmitted based on the communication security level and signing the encryption result using the signature key pre-stored in the initiator hardware security domain includes: Determine the message key based on a predefined key rotation mechanism; Encrypting the data to be transmitted using the message key to obtain a ciphertext; Determine the current timestamp; A hash calculation is performed based on the ciphertext and the timestamp to obtain a hash value to sign the hash value.

8. A vehicle network data encryption processing device, characterized in that: include: A security level determination module is used to determine the communication security level when detecting data to be transmitted from the initiator of the Internet of Vehicles to the receiver; a data encryption processing module, configured to encrypt the data to be transmitted based on the communication security level, and sign the encryption result using the signature key pre-stored in the initiator hardware security domain to obtain a signature result; The data transmission processing module is used to send the signature result to the receiving end.

9. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores computer-readable instructions, and the processor is configured to execute the computer-readable instructions, wherein the computer-readable instructions execute the method according to any one of claims 1 to 7 when executed.

10. A computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the method according to any one of claims 1 to 7.