Secret key verification method, processor and vehicle

By acquiring and verifying the identifiers and verification information in the broadcast messages generated by the roadside unit, and combining the public and private keys, the problem of low network key verification efficiency caused by limited vehicle computing resources is solved, and real-time communication and security improvement of the vehicle-mounted ad hoc network are achieved.

CN121001084APending Publication Date: 2025-11-21CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511163430.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Limited computing resources in vehicles result in low verification efficiency of complex encryption algorithms in vehicular ad hoc network communication, making it difficult to meet real-time communication requirements.

Method used

By acquiring the identification and verification information from the broadcast messages generated by the roadside unit, target verification information is generated, and the matching of the networking key is verified based on this information. The combination of public and private keys is used for identity and key verification, and the validity of the information is ensured by combining the timestamp.

Benefits of technology

It improves the verification efficiency of networking keys, meets the real-time communication requirements of vehicle-mounted ad hoc networks, and enhances the security and efficiency of the verification process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121001084A_ABST
    Figure CN121001084A_ABST
Patent Text Reader

Abstract

The invention discloses a secret key verification method, a processor and a vehicle, the method is applied to the vehicle, the vehicle and a road side unit are in the same network, and the method comprises the following steps: acquiring a broadcast message generated by the road side unit for the vehicle; extracting first identification information and first target verification information from the broadcast message, and generating second target verification information based on the first identification information; based on the first target verification information and the second target verification information, a first networking key of the road side unit and a second networking key of the vehicle are verified, a first verification result is obtained, the first networking key is used for representing a key generated by the road side unit for networking, and the second networking key is used for representing a key generated by the vehicle for networking; the first verification result is used for representing whether the first networking key is the same as the second networking key. According to the invention, the technical problem of low efficiency of verifying the networking key is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicles, and more specifically, to a key verification method, a processor, and a vehicle. Background Technology

[0002] Currently, complex encryption algorithms are used in the communication of vehicular ad hoc networks, such as asymmetric encryption algorithms based on large number factorization or discrete logarithm problems.

[0003] However, while these algorithms offer high security, they also involve high computational complexity. Due to the limited computing resources of vehicles, running these complex algorithms consumes significant amounts of computation time and resources, making it difficult to meet the real-time communication requirements of vehicular ad hoc networks. This results in the technical problem of inefficient verification of network keys.

[0004] There is currently no effective solution to the technical problem of low efficiency in verifying network keys. Summary of the Invention

[0005] This application provides a key verification method, processor, and vehicle to at least solve the technical problem of low efficiency in verifying network keys.

[0006] According to one aspect of the embodiments of this application, a key verification method is provided. The method is applied to a vehicle, where the vehicle and a roadside unit are in the same network. The method includes: acquiring a broadcast message generated by the roadside unit for the vehicle, wherein the broadcast message includes first identification information of the vehicle and first target verification information, the first identification information being used to identify the vehicle, and the first target verification information being used to represent a verification message generated by the roadside unit for the vehicle; extracting the first identification information and the first target verification information from the broadcast message, and generating second target verification information based on the first identification information, wherein the second target verification information is used to represent a verification message generated by the vehicle for the roadside unit; and verifying a first network key of the roadside unit and a second network key of the vehicle based on the first target verification information and the second target verification information to obtain a first verification result, wherein the first network key is used to represent a key generated by the roadside unit for the network, the second network key is used to represent a key generated by the vehicle for the network, and the first verification result is used to indicate whether the first network key and the second network key are the same.

[0007] Furthermore, the method also includes: obtaining a first public key of the roadside unit and a second public key of the vehicle, wherein the first public key and the first private key of the roadside unit are a key pair for the roadside unit, and the second public key and the second private key of the vehicle are a key pair for the vehicle; generating second target verification information based on first identification information, including: combining the first identification information, the first public key and the second private key to obtain first initial verification information, wherein the first initial verification information corresponds to the second initial verification information, and the second initial verification information is obtained by combining the first identification information, the second public key and the first private key; and combining the first initial verification information with a second networking key to obtain second target verification information.

[0008] Further, based on the first target verification information and the second target verification information, the first network key of the roadside unit and the second network key of the vehicle are verified to obtain a first verification result, including: in response to the first target verification information and the second target verification information being the same, the identity of the roadside unit is verified to obtain a second verification result, wherein the second verification result is used to represent the relationship between the identity of the roadside unit and the target identity; in response to the second verification result indicating that the identity of the roadside unit is the same as the target identity, the first network key and the second network key are verified to obtain the first verification result that the first network key and the second network key are the same.

[0009] Furthermore, the broadcast message includes: a first timestamp, which indicates the time when the broadcast message was generated; wherein, extracting the first identification information and the first target verification information from the broadcast message includes: extracting the first timestamp from the broadcast message and obtaining a second timestamp of the broadcast message, wherein the second timestamp indicates the time when the broadcast message was received; determining a first time difference between the first timestamp and the second timestamp; and, in response to the first time difference being within a preset time difference range, extracting the first identification information and the first target verification information from the broadcast message.

[0010] According to one aspect of the embodiments of this application, a key verification method is provided. The method is applied to a roadside unit, where the roadside unit and a vehicle are in the same network. The method includes: generating a broadcast message for the vehicle, wherein the broadcast message includes: first identification information of the vehicle and first target verification information, the first identification information being used to identify the vehicle, and the first target verification information being used to represent a verification message generated by the roadside unit for the vehicle, wherein the first identification information and the first target verification information are extracted from the broadcast message; sending the broadcast message to the vehicle to verify a first network key of the roadside unit and a second network key of the vehicle based on the first target verification information and the second target verification information, thereby obtaining a first verification result, wherein the second target verification information is used to represent a verification message generated by the vehicle for the roadside unit, the second target verification information being generated based on the first identification information, the first network key being used to represent a key generated by the roadside unit for the network, the second network key being used to represent a key generated by the vehicle for the network, and the first verification result being used to indicate whether the first network key and the second network key are the same.

[0011] Furthermore, the method further includes: receiving a distribution message generated by the distribution unit for the roadside unit, and a third timestamp of the distribution message, wherein the distribution message includes a fourth timestamp, the fourth timestamp being used to indicate the time when the distribution message is generated, and the third timestamp being used to indicate the time when the distribution message is received; extracting the third timestamp from the distribution message; determining a second time difference between the third timestamp and the fourth timestamp; in response to the second time difference being within a preset time difference range, extracting distribution content from the distribution message, wherein the distribution content includes second identification information of the roadside unit, the second identification information being used to identify the roadside unit; and generating first target distribution information based on the distribution content, wherein the first target distribution information is used to indicate that the roadside unit... The distribution information generated for network formation; broadcasting messages to vehicles, including: in response to the first target distribution information being the same as the second target distribution information, generating third target verification information for the roadside unit based on the first private key of the roadside unit, the third public key of the distribution unit, and the second identification information, wherein the second target distribution information is used to represent the distribution information generated by the distribution unit for network formation, the first private key and the first public key of the roadside unit are key pairs of the roadside unit, and the third target verification information includes the first network key; in response to the third target verification information being the same as the fourth target verification information of the distribution unit, broadcasting messages to vehicles, wherein the fourth target verification information includes the third network key, and the third network key is used to represent the key generated by the distribution unit for network formation.

[0012] Furthermore, based on the first private key of the roadside unit, the third public key of the distribution unit, and the second identification information, the third target verification information of the roadside unit is generated, including: combining the first private key, the third public key, and the second identification information to obtain the third initial verification information of the roadside unit; and combining the third initial verification information with the first network key to obtain the third target verification information.

[0013] Furthermore, the third public key and the third private key of the distribution unit are a key pair for the distribution unit. The method also includes: determining the first network key based on the fifth target verification information of the distribution unit, the random number of the roadside unit and the third initial verification information, wherein the fifth target verification information is obtained by summing the third network key, the random number and the fifth initial verification information of the distribution unit, and the fifth initial verification information is obtained by combining the third private key, the first public key and the second identification information.

[0014] According to another aspect of the embodiments of this application, a key verification device is also provided. The device may include: a first acquisition unit, configured to acquire a broadcast message generated by a roadside unit for a vehicle, wherein the broadcast message includes first identification information of the vehicle and first target verification information, the first identification information being used to identify the vehicle, and the first target verification information being used to represent a verification message generated by the roadside unit for the vehicle; a processing unit, configured to extract the first identification information and the first target verification information from the broadcast message, and to generate second target verification information based on the first identification information, wherein the second target verification information is used to represent a verification message generated by the vehicle for the roadside unit; and a verification unit, configured to verify a first network key of the roadside unit and a second network key of the vehicle based on the first target verification information and the second target verification information, to obtain a first verification result, wherein the first network key is used to represent a key generated by the roadside unit for the network, the second network key is used to represent a key generated by the vehicle for the network, and the first verification result is used to indicate whether the first network key and the second network key are the same.

[0015] According to another aspect of the embodiments of this application, a key verification device is also provided. The device may include: a generation unit, configured to generate a broadcast message for a vehicle, wherein the broadcast message includes: first identification information of the vehicle and first target verification information, the first identification information being used to identify the vehicle, and the first target verification information being used to represent a verification message generated by a roadside unit for the vehicle, the first identification information and the first target verification information being extracted from the broadcast message; and a sending unit, configured to send the broadcast message to the vehicle to verify a first network key of the roadside unit and a second network key of the vehicle based on the first target verification information and the second target verification information, thereby obtaining a first verification result, wherein the second target verification information is used to represent a verification message generated by the vehicle for the roadside unit, the second target verification information being generated based on the first identification information, the first network key being used to represent a key generated by the roadside unit for the network, the second network key being used to represent a key generated by the vehicle for the network, and the first verification result being used to indicate whether the first network key and the second network key are the same.

[0016] According to another aspect of the embodiments of this application, a vehicle is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods in various embodiments of this application when it runs.

[0017] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0018] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0019] According to another aspect of the embodiments of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0020] According to another aspect of the embodiments of this application, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of this application.

[0021] In this embodiment, when verifying the network key of a vehicle, a broadcast message generated by the roadside unit for the vehicle can be obtained. From the obtained broadcast message, first identification information and first target verification information can be extracted. Based on the extracted first identification information, second target verification information can be generated. Based on the extracted first target verification information and the generated second target verification information, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain a first verification result. Since this embodiment, based on the first identification information and first target verification information extracted from the obtained broadcast message, can verify the first network key of the roadside unit and the second network key of the vehicle based on the extracted first target verification information and the second target verification information generated based on the extracted first identification information to obtain a first verification result, it can determine whether the first network key and the second network key are the same. This achieves the goal of meeting the requirements of real-time communication of vehicular ad hoc networks, thereby solving the technical problem of low efficiency in verifying network keys and achieving the technical effect of improving the efficiency of verifying network keys. Attached Figure Description

[0022] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0023] Figure 1(a) is a schematic diagram of an application scenario of a key verification method according to an embodiment of the present invention;

[0024] Figure 1(b) is a flowchart of a key verification method according to an embodiment of the present invention;

[0025] Figure 2 This is a flowchart of another key verification method according to an embodiment of the present invention;

[0026] Figure 3 This is a schematic diagram of a group key distribution method based on a vehicle-mounted ad hoc network according to an embodiment of the present invention;

[0027] Figure 4 This is a structural block diagram of a key verification device according to an embodiment of the present invention;

[0028] Figure 5 This is a structural block diagram of another key verification device according to an embodiment of the present invention. Detailed Implementation

[0029] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0031] According to an embodiment of this application, an embodiment of a key verification method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0032] As an optional implementation, the above-described key verification method can be applied, but is not limited to, the application scenario shown in Figure 1(a). Figure 1(a) is a schematic diagram of an application scenario of a key verification method according to an embodiment of the present invention. As shown in Figure 1(a), in the application scenario, the terminal device 10 can communicate with the server 13 via the network 11, but is not limited to. The server 13 can perform operations on the database, such as writing or reading data. The terminal device 10 can include, but is not limited to, a human-computer interaction screen, a processor, and a memory. The human-computer interaction screen can be used, but is not limited to, to display a virtual machine on the mobile terminal 10. The vehicle 12 can be used, but is not limited to, to respond to the above-described human-computer interaction operation, execute the corresponding operation, or generate the corresponding instruction and send the generated instruction to the server 13.

[0033] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here. Specifically, the key verification method in this application may include: step S102, obtaining a broadcast message generated by the roadside unit for the vehicle; step S104, extracting first identification information and first target verification information from the broadcast message, and generating second target verification information based on the first identification information; and step S106, verifying the first network key of the roadside unit and the second network key of the vehicle based on the first target verification information and the second target verification information, to obtain a first verification result.

[0034] It should be noted that the relevant information (including but not limited to broadcast messages, first identification information, first target verification information and second target verification information, etc.) and data (including but not limited to the first network key and the second network key, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0035] Figure 1(b) is a flowchart of a key verification method according to an embodiment of the present invention. As shown in Figure 1(b), the method can be applied to vehicles, where the vehicle and the roadside unit are in the same network, and includes the following steps:

[0036] Step S112: Obtain a broadcast message generated by the roadside unit for the vehicle. The broadcast message includes the vehicle's first identification information and first target verification information. The first identification information is used to identify the vehicle, and the first target verification information is used to represent the verification message generated by the roadside unit for the vehicle.

[0037] In the technical solution provided in step S112 of the present invention, the vehicle, the roadside unit (RSU), and the key distribution center (KDC) can be in the same network. For example, the network can be of different types, including: ad-hoc network, mesh network, cluster-based network, and hybrid network, etc., which are only examples and are not specifically limited here.

[0038] In this embodiment, the broadcast message may include first identification information and first target verification information for the vehicle. The first identification information can be used to identify the vehicle, and the first target verification information can be used to represent a verification message generated by the roadside unit for the vehicle. For example, the vehicle may include multiple vehicles, and the multiple vehicles can be represented by V. i This can be represented as follows: the first identification information mentioned above may include the identification code (ID) of each vehicle; the first target verification information mentioned above may include the V issued by the RSU to each vehicle. i The generated verification message Ai.

[0039] In this embodiment, broadcast messages generated by the roadside unit for vehicles are obtained. Optionally, this embodiment utilizes the fact that each vehicle and the roadside unit are in the same network, and can receive broadcast messages sent by the roadside unit to each vehicle, thereby obtaining the broadcast messages generated by the roadside unit for vehicles.

[0040] Step S114: Extract the first identification information and the first target verification information from the broadcast message, and generate the second target verification information based on the first identification information, wherein the second target verification information is used to represent the verification message generated by the vehicle for the roadside unit.

[0041] In the technical solution provided by step S114 of the present invention, the second target verification information can be used to represent the verification message generated by the vehicle for the roadside unit. For example, the second target verification information may include the verification message generated by the RSU for each vehicle V i The generated verification message Ai'.

[0042] In this embodiment, after obtaining the broadcast message generated by the roadside unit for the vehicle, first identification information and first target verification information are extracted from the broadcast message, and second target verification information is generated based on the first identification information. Optionally, based on obtaining the broadcast message, this embodiment can extract the first identification information and first target verification information from the broadcast message according to different information types; based on the extracted first identification information, the first private key of the roadside unit, and the second public key of the vehicle, the second target verification information can be generated, thereby achieving the purpose of obtaining the verification message generated by the vehicle for the roadside unit.

[0043] Optionally, second target verification information can be generated based on the extracted first identification information, the first private key of the roadside unit, and the second public key of the vehicle. For example, first initial verification information can be generated based on the first identification information, the first private key, and the second public key; second target verification information can be generated based on the generated first initial verification information and the second networking key of the vehicle.

[0044] Optionally, hashing the first identification information, the first private key, and the second public key can yield the first initial verification information; hashing the generated first initial verification information and the vehicle's second networking key can yield the second target verification information.

[0045] Step S116: Based on the first target verification information and the second target verification information, verify the first networking key of the roadside unit and the second networking key of the vehicle to obtain a first verification result. The first networking key is used to represent the key generated by the roadside unit for networking, the second networking key is used to represent the key generated by the vehicle for networking, and the first verification result is used to indicate whether the first networking key and the second networking key are the same.

[0046] In the technical solution provided by step S116 of the present invention, the first networking key can be used to represent the key generated by the roadside unit for networking.

[0047] In this embodiment, the second networking key can be used to represent the key generated by the vehicle for networking.

[0048] In this embodiment, the first verification result can be used to indicate whether the first network key and the second network key are the same. For example, the first verification result can be that the first network key and the second network key are the same, or it can be that the first network key and the second network key are different. This is only an example and is not specifically limited.

[0049] In this embodiment, after extracting the first identification information and the first target verification information from the broadcast message, and generating the second target verification information based on the first identification information, the first network key of the roadside unit and the second network key of the vehicle are verified based on the first and second target verification information to obtain a first verification result. Optionally, based on the extraction of the first target verification information and the generation of the second target verification information, this embodiment can determine the association between the first and second target verification information; according to the determined association, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain the first verification result, thereby achieving the purpose of determining whether the first network key and the second network key are the same.

[0050] Optionally, based on the determined association, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain a first verification result. For example, if the determined association indicates that the first target verification information and the second target verification information are the same, then based on the identity of the roadside unit, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain a first verification result.

[0051] It should be noted that the method described above for verifying the first network key of the roadside unit and the second network key of the vehicle to obtain the first verification result is merely an illustrative example and is not specifically limited here. Any process or method that can verify the first network key of the roadside unit and the second network key of the vehicle based on the first target verification information and the second target verification information to obtain the first verification result is within the protection scope of the embodiments of this application, and will not be described in detail here.

[0052] In steps S112 to S116 of this application, when verifying the network key of a vehicle, a broadcast message generated by the roadside unit for the vehicle can be obtained. From the obtained broadcast message, first identification information and first target verification information can be extracted. Based on the extracted first identification information, second target verification information can be generated. Based on the extracted first target verification information and the generated second target verification information, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain a first verification result. Since this embodiment of the application, based on the first identification information and first target verification information extracted from the obtained broadcast message, can verify the first network key of the roadside unit and the second network key of the vehicle based on the extracted first target verification information and the second target verification information generated based on the extracted first identification information to obtain a first verification result, that is, it can determine whether the first network key and the second network key are the same, thereby achieving the goal of meeting the requirements of real-time communication of vehicular ad hoc networks, thus solving the technical problem of low efficiency in verifying network keys, and thus achieving the technical effect of improving the efficiency of verifying network keys.

[0053] As an optional embodiment, the method further includes: obtaining a first public key of the roadside unit and a second public key of the vehicle, wherein the first public key and the first private key of the roadside unit are a key pair of the roadside unit, and the second public key and the second private key of the vehicle are a key pair of the vehicle; step S114, generating second target verification information based on the first identification information, including: combining the first identification information, the first public key and the second private key to obtain first initial verification information, wherein the first initial verification information corresponds to the second initial verification information, and the second initial verification information is obtained by combining the first identification information, the second public key and the first private key; combining the first initial verification information with the second networking key to obtain the second target verification information.

[0054] In this embodiment, the first public key and the first private key of the roadside unit can be a key pair for the roadside unit. For example, the first public key can be a PK (Primary Key). RSU To represent this, the first private key mentioned above can be represented by SK.RSU To express.

[0055] In this embodiment, the second public key and the vehicle's second private key can be a key pair for the vehicle. For example, the second public key can be a PK (Primary Key). i This can be represented by SK. i To express.

[0056] In this embodiment, the first public key of the roadside unit and the second public key of the vehicle are obtained. Optionally, in this embodiment, each vehicle can access the roadside unit to obtain the first public key of the roadside unit by utilizing the same network in which the vehicle and the roadside unit are located; and each vehicle can directly retrieve its own public key to obtain the second public key of the vehicle, thereby achieving the purpose of obtaining the first public key and the second public key.

[0057] In this embodiment, the first initial verification information can correspond to the second initial verification information. The second initial verification information can be obtained by combining the first identifier information, the second public key, and the first private key. For example, the first initial verification information can be represented by Π. i The second initial verification information mentioned above can be represented by Π. i To express.

[0058] In this embodiment, after obtaining the broadcast message generated by the roadside unit for the vehicle, the first identification information, the first public key, and the second private key are combined to obtain the first initial verification information; the first initial verification information is then combined with the second network key to obtain the second target verification information. Optionally, this embodiment, based on obtaining the broadcast message, combines the first identification information, the first public key, and the second private key extracted from the broadcast message to obtain the first initial verification information; then, the obtained first initial verification information is combined with the second network key to obtain the second target verification information. This achieves the goal of obtaining the verification message generated by the vehicle for the roadside unit, thereby improving the security of the verification message.

[0059] Optionally, the first identification information, the first private key, and the second public key are imported into a hash processing model for hash processing to obtain the first initial verification information; the generated first initial verification information and the vehicle's second network key are imported into the hash processing model for hash processing to obtain the second target verification information. The hash processing model can be an information processing model based on a hash function, for example, the hash function can be denoted as, but is not limited to, h0.

[0060] The following description further explains the method of verifying the first network key of the roadside unit and the second network key of the vehicle based on the first target verification information and the second target verification information to obtain the first verification result.

[0061] As an optional embodiment, step S116, based on the first target verification information and the second target verification information, verifies the first network key of the roadside unit and the second network key of the vehicle to obtain a first verification result, including: in response to the first target verification information and the second target verification information being the same, verifying the identity of the roadside unit to obtain a second verification result, wherein the second verification result is used to represent the relationship between the identity of the roadside unit and the target identity; in response to the second verification result indicating that the identity of the roadside unit is the same as the target identity, verifying the first network key and the second network key to obtain the first verification result that the first network key and the second network key are the same.

[0062] In this embodiment, the second verification result can be used to represent the relationship between the identity of the roadside unit and the target identity. For example, the second verification result can be that the identity of the roadside unit is the same as the target identity, or it can be that the identity of the roadside unit is different from the target identity; the target identity can include: valid identity and compliant identity, etc., which are only examples and are not specifically limited here.

[0063] In this embodiment, after extracting the first identification information and the first target verification information from the broadcast message, and generating the second target verification information based on the first identification information, the identity of the roadside unit is verified in response to the first target verification information and the second target verification information being the same, thus obtaining a second verification result. Optionally, based on the extraction of the first target verification information and the generation of the second target verification information, this embodiment can determine the association relationship between the first target verification information and the second target verification information. If the determined association relationship indicates that the first target verification information and the second target verification information are the same, then verifying the identity of the roadside unit can yield a second verification result that the identity of the roadside unit is the same as the target identity, thereby achieving the purpose of determining the relationship between the identity of the roadside unit and the target identity.

[0064] Optionally, if the determined association indicates that the first target verification information and the second target verification information are different, then verifying the identity of the roadside unit can yield a second verification result that the identity of the roadside unit is different from the target identity.

[0065] In this embodiment, after verifying the identity of the roadside unit in response to the first target verification information and the second target verification information being the same, and obtaining a second verification result, in response to the second verification result indicating that the identity of the roadside unit is the same as the target identity, the first network key and the second network key are verified, resulting in a first verification result that the first network key and the second network key are the same. Optionally, based on obtaining the second verification result, if the second verification result indicates that the identity of the roadside unit is the same as the target identity, then verifying the first network key and the second network key can yield a first verification result that the first network key and the second network key are the same. This achieves the purpose of determining whether the first network key and the second network key are the same, thereby realizing the technical effect of improving key security.

[0066] The method for extracting the first identification information and the first target verification information from the broadcast message described in this embodiment will be further explained below.

[0067] As an optional embodiment, the broadcast message includes: a first timestamp, which is used to indicate the time when the broadcast message is generated. Step S114, extracting first identification information and first target verification information from the broadcast message, includes: extracting the first timestamp from the broadcast message and obtaining a second timestamp of the broadcast message, where the second timestamp is used to indicate the time when the broadcast message is received; determining a first time difference between the first timestamp and the second timestamp; and, in response to the first time difference being within a preset time difference range, extracting the first identification information and the first target verification information from the broadcast message.

[0068] In this embodiment, the broadcast message may include a first timestamp. The first timestamp can be used to represent the time when the broadcast message was generated, and the first timestamp can be represented by T. i To express.

[0069] In this embodiment, the second timestamp can be used to represent the time when the broadcast message is received, and the second timestamp can be represented by T. n To express.

[0070] In this embodiment, after acquiring the broadcast message generated by the roadside unit for the vehicle, a first timestamp and a second timestamp of the broadcast message are extracted from the broadcast message. Optionally, based on the acquired broadcast message, this embodiment can extract the first timestamp from the broadcast message according to different information types, and record the time of receiving the broadcast message as the second timestamp.

[0071] In this embodiment, after extracting the first timestamp and obtaining the second timestamp from the broadcast message, a first time difference between the first and second timestamps is determined. In response to the first time difference being within a preset time difference range, first identification information and first target verification information are extracted from the broadcast message. Optionally, based on extracting the first timestamp and obtaining the second timestamp, this embodiment performs a difference operation on the first and second timestamps to obtain the first time difference between them. The relationship between the obtained first time difference and the preset time difference range is then judged. If it is determined that the first time difference is within the preset time difference range, then according to the different types of information, the first identification information and the first target verification information can be extracted from the broadcast message, thereby achieving the purpose of obtaining the first identification information and the first target verification information.

[0072] In this embodiment of the invention, when verifying the network key of a vehicle, a broadcast message generated by the roadside unit for the vehicle can be obtained. From the obtained broadcast message, first identification information and first target verification information can be extracted. Based on the extracted first identification information, second target verification information can be generated. Based on the extracted first target verification information and the generated second target verification information, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain a first verification result. Since this embodiment of the application, based on the first identification information and first target verification information extracted from the obtained broadcast message, can verify the first network key of the roadside unit and the second network key of the vehicle based on the extracted first target verification information and the second target verification information generated based on the extracted first identification information to obtain a first verification result, that is, it can determine whether the first network key and the second network key are the same, thereby achieving the goal of meeting the requirements of real-time communication of vehicular ad hoc networks, thus solving the technical problem of low efficiency in verifying network keys, and thus achieving the technical effect of improving the efficiency of verifying network keys.

[0073] Figure 2 This is a flowchart of another vehicle data communication method according to an embodiment of the present invention, such as... Figure 2 As shown, the vehicle's data communication method can be applied to roadside units, where the roadside unit and the vehicle are in the same network, and includes the following steps:

[0074] Step S202: Generate a broadcast message for the vehicle, wherein the broadcast message includes: first identification information and first target verification information of the vehicle, the first identification information is used to identify the vehicle, the first target verification information is used to indicate the verification message generated by the roadside unit for the vehicle, and the first identification information and the first target verification information are extracted from the broadcast message.

[0075] In the technical solution provided by step S202 of the present invention, the broadcast message may include: first identification information of the vehicle and first target verification information. The first identification information can be used to identify the vehicle, and the first target verification information can be used to represent a verification message generated by the roadside unit for the vehicle.

[0076] In this embodiment, the first identification information and the first target verification information can be extracted from the broadcast message.

[0077] In this embodiment, a broadcast message for the vehicle is generated. Optionally, based on the distribution message sent by the distribution unit, this embodiment can generate first target distribution information; and based on the first target distribution information and the second target distribution information, a broadcast message for each vehicle can be generated.

[0078] Step S204: A broadcast message is sent to the vehicle to verify the first networking key of the roadside unit and the second networking key of the vehicle based on the first target verification information and the second target verification information, and to obtain a first verification result. The second target verification information is used to represent the verification message generated by the vehicle for the roadside unit. The second target verification information is generated based on the first identification information. The first networking key is used to represent the key generated by the roadside unit for the network. The second networking key is used to represent the key generated by the vehicle for the network. The first verification result is used to indicate whether the first networking key and the second networking key are the same.

[0079] In the technical solution provided by step S204 of the present invention, the second target verification information can be used to represent the verification message generated by the vehicle for the roadside unit, and the second target verification information can be generated based on the first identification information.

[0080] In this embodiment, the first networking key can be used to represent the key generated by the roadside unit for networking, and the second networking key can be used to represent the key generated by the vehicle for networking.

[0081] In this embodiment, the first verification result can be used to indicate whether the first network key and the second network key are the same. For example, the first verification result can be that the first network key and the second network key are the same, or it can be that the first network key and the second network key are different. This is only an example and is not specifically limited.

[0082] In this embodiment, after generating a broadcast message for a vehicle, the broadcast message is sent to the vehicle to verify the first network key of the roadside unit and the second network key of the vehicle based on the first target verification information and the second target verification information, thereby obtaining a first verification result. Optionally, based on the broadcast message generated by the roadside unit, this embodiment can utilize the fact that each vehicle and the roadside unit are in the same network to send broadcast messages corresponding to each vehicle, so that each vehicle can verify the first network key of the roadside unit and the second network key of the vehicle based on the first target verification information and the second target verification information, thereby obtaining a first verification result.

[0083] In steps S202 to S204 of this application, when verifying the network key of a vehicle, based on the broadcast message generated by the roadside unit, the broadcast message corresponding to each vehicle can be sent to each vehicle using the same network in which each vehicle and the roadside unit are located. This allows each vehicle to verify the first network key of the roadside unit and the second network key of the vehicle based on the first target verification information and the second target verification information, thereby obtaining the first verification result. This achieves the goal of meeting the requirements of real-time communication of the vehicle-mounted ad hoc network, thus solving the technical problem of low efficiency in verifying the network key, and further achieving the technical effect of improving the efficiency of verifying the network key.

[0084] The method for sending broadcast messages to vehicles described in this embodiment will be further explained below.

[0085] As an optional embodiment, the method further includes: receiving a distribution message generated by a distribution unit for a roadside unit, and a third timestamp of the distribution message, wherein the distribution message includes: a fourth timestamp, the fourth timestamp indicating the time when the distribution message was generated, and the third timestamp indicating the time when the distribution message was received; extracting the third timestamp from the distribution message; determining a second time difference between the third timestamp and the fourth timestamp; in response to the second time difference being within a preset time difference range, extracting distribution content from the distribution message, wherein the distribution content includes: second identification information of the roadside unit, the second identification information indicating the roadside unit; and generating first target distribution information based on the distribution content, wherein the first target distribution information indicates that the roadside unit was generated by the distribution unit. The roadside unit generates distribution information for the network; it sends broadcast messages to vehicles, including: in response to the first target distribution information being the same as the second target distribution information, generating third target verification information for the roadside unit based on the first private key of the roadside unit, the third public key of the distribution unit, and the second identification information, wherein the second target distribution information is used to represent the distribution information generated by the distribution unit for the network, the first private key and the first public key of the roadside unit are key pairs of the roadside unit, and the third target verification information includes the first network key; in response to the third target verification information being the same as the fourth target verification information of the distribution unit, sending broadcast messages to vehicles, wherein the fourth target verification information includes the third network key, and the third network key is used to represent the key generated by the distribution unit for the network.

[0086] In this embodiment, the aforementioned third timestamp can be used to represent the time when the distribution message is received. For example, the aforementioned third timestamp can be represented by T. l To express.

[0087] In this embodiment, the fourth timestamp can be used to represent the time when the distribution message is generated. For example, the fourth timestamp can be represented by T. r To express.

[0088] In this embodiment, the distributed content may include: second identification information of the roadside unit. The second identification information can be used to identify the roadside unit. For example, the second identification information can be an ID. RSU To express.

[0089] In this embodiment, the aforementioned first target distribution information can be used to represent distribution information generated by the roadside unit for the network. For example, the aforementioned first target distribution information can be represented by Δ. r 'to indicate.

[0090] In this embodiment, a distribution message generated by the distribution unit for a roadside unit and a third timestamp of the distribution message are received; the third timestamp is extracted from the distribution message; a second time difference between the third timestamp and a fourth timestamp is determined; in response to the second time difference being within a preset time difference range, distribution content is extracted from the distribution message; and first target distribution information is generated based on the distribution content. Optionally, this embodiment utilizes a network to receive a distribution message generated by the distribution unit for a roadside unit. Furthermore, the time of receiving the distribution message is recorded as a third timestamp; the difference between the third timestamp and the fourth timestamp is calculated to obtain the second time difference between them; the relationship between the obtained second time difference and a preset time difference range is judged; if the second time difference is determined to be within the preset time difference range, the distribution content is extracted from the distribution message, and the distribution content is hashed to obtain the first target distribution information, thereby achieving the purpose of obtaining distribution information generated by the roadside unit for the network.

[0091] In this embodiment, the aforementioned second target distribution information can be used to represent distribution information generated by the distribution unit for the network. For example, the aforementioned second target distribution information can be represented by Δ. r To express.

[0092] In this embodiment, the aforementioned third public key can be a PK. KDC To express.

[0093] In this embodiment, the first private key and the first public key of the roadside unit can be a key pair for the roadside unit.

[0094] In this embodiment, the third target verification information may include the first network key. For example, the third target verification information may be represented by A'.

[0095] In this embodiment, the fourth target verification information may include the third network key. For example, the fourth target verification information can be represented by A.

[0096] In this embodiment, the third network key can be used to represent the key generated by the distribution unit for the network. For example, the third network key can be represented by GSK.

[0097] In this embodiment, after generating first target distribution information based on the distribution content, in response to the first target distribution information being the same as the second target distribution information, third target verification information of the roadside unit is generated based on the first private key of the roadside unit, the third public key of the distribution unit, and the second identification information; in response to the third target verification information being the same as the fourth target verification information of the distribution unit, a broadcast message is sent to the vehicle. Optionally, based on the generation of the first target distribution information, this embodiment can determine the association relationship between the first target distribution information and the second target distribution information; if it is determined that the above association relationship indicates that the first target distribution information is the same as the second target distribution information, then based on the first private key of the roadside unit, the third public key of the distribution unit, and the second identification information, third target verification information of the roadside unit can be generated, and in response to the third target verification information being the same as the fourth target verification information of the distribution unit, a broadcast message is sent to the vehicle.

[0098] The method for generating third target verification information of a roadside unit based on the first private key of the roadside unit, the third public key of the distribution unit, and the second identification information of the above embodiment will be further described below.

[0099] As an optional embodiment, the third target verification information of the roadside unit is generated based on the first private key of the roadside unit, the third public key of the distribution unit, and the second identification information. This includes: combining the first private key, the third public key, and the second identification information to obtain the third initial verification information of the roadside unit; and combining the third initial verification information with the first networking key to obtain the third target verification information.

[0100] In this embodiment, the aforementioned third initial verification information can be represented by H′. RSU To express.

[0101] In this embodiment, after generating first target distribution information based on the distribution content, the first private key, the third public key, and the second identification information are combined to obtain the third initial verification information of the roadside unit; the third initial verification information is then combined with the first network key to obtain the third target verification information. Optionally, in this embodiment, based on the generation of the first target distribution information, the first private key, the third public key, and the second identification information are combined to obtain the third initial verification information of the roadside unit; then, the third initial verification information is combined with the first network key to obtain the third target verification information.

[0102] Optionally, the first private key, the third public key, and the second identification information can be imported into the hash processing model for hash processing to obtain the third initial verification information; the third initial verification information and the first network key can be imported into the hash processing model for hash processing to obtain the third target verification information.

[0103] The method for determining the first network key described in this embodiment will be further explained below.

[0104] As an optional embodiment, the third public key and the third private key of the distribution unit are a key pair of the distribution unit. The method further includes: determining the first network key based on the fifth target verification information of the distribution unit, the random number of the roadside unit and the third initial verification information, wherein the fifth target verification information is obtained by summing the third network key, the random number and the fifth initial verification information of the distribution unit, and the fifth initial verification information is obtained by combining the third private key, the first public key and the second identification information.

[0105] In this embodiment, the fifth target verification information can be obtained by summing the third network key, the random number, and the fifth initial verification information of the distribution unit. Specifically, the fifth initial verification information can be obtained by combining the third private key, the first public key, and the second identification information. For example, the fifth initial verification information can be obtained using H... RSU The verification information for the fifth objective mentioned above can be represented by D. RSU To express.

[0106] In this embodiment, the first network key is determined based on the fifth target verification information of the distribution unit, the random number of the roadside unit, and the third initial verification information. Optionally, this embodiment can obtain the first network key by performing a difference operation on the fifth target verification information, the random number of the roadside unit, and the third initial verification information after extracting the random number of the roadside unit, thereby achieving the purpose of generating a key generated by the roadside unit for the network.

[0107] The technical solutions of the embodiments of the present invention will be illustrated below with reference to preferred embodiments.

[0108] Currently, complex encryption algorithms are used in the communication of vehicular ad hoc networks, such as asymmetric encryption algorithms based on large number factorization or discrete logarithm problems.

[0109] However, while these algorithms offer high security, they also involve high computational complexity. Due to the limited computing resources of vehicles, running these complex algorithms consumes significant amounts of computation time and resources, making it difficult to meet the real-time communication requirements of vehicular ad hoc networks. This results in the technical problem of inefficient verification of network keys.

[0110] However, this invention proposes a key verification method. Based on extracting first identification information and first target verification information from the acquired broadcast message, and according to the extracted first target verification information and the second target verification information generated based on the extracted first identification information, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain a first verification result. That is, it can be determined whether the first network key and the second network key are the same, thereby achieving the goal of meeting the requirements of real-time communication of vehicle ad hoc networks, thus solving the technical problem of low efficiency in verifying network keys, and thus achieving the technical effect of improving the efficiency of verifying network keys.

[0111] It should be noted that Table 1 is a data table and a key table. The key verification method in this application requires the data and key shown in Table 1 below:

[0112] Table 1 Data Table and Key Table

[0113]

[0114] The aforementioned KDC can be used to generate different random numbers R for each vehicle. i And record the data pairs consisting of the corresponding identity identifier and random number. The aforementioned KDC can be used to generate random numbers R for RSU. RSU The aforementioned KDC can be used to select a corresponding private key for each vehicle. And select the corresponding private key for RSU. The aforementioned vehicles can utilize the generated private key SK i Calculate the public key PK corresponding to the vehicle. i The aforementioned RSU can utilize the generated private key SK RSUi Calculate the corresponding public key PK RSU .

[0115] For example, the above-mentioned group key distribution method can be as follows: Figure 3 As shown. For example, Figure 3 This is a schematic diagram of a group key distribution method based on a vehicle-mounted ad hoc network according to an embodiment of the present invention. The key distribution center 301 can send distribution messages to the roadside unit 302, and the roadside unit 302 can send broadcast messages to the corresponding vehicles 3031, 3032 to 303n. Each vehicle can receive its own broadcast message {ID}. i Ai,V i ,Δ i ,T i}

[0116] The initialization of the aforementioned key distribution center can be achieved by performing the following steps: Selecting an elliptic curve E: y2 =x 3 +ax+b mod q, where x and y are the x and y coordinates of the elliptic curve, respectively, a,b∈Fq, and q is the security coefficient; generate the private key SK of the key distribution center. KDC PK with public key KDC Select hash function h0; and publish relevant parameters {P,q,PK}. KDC ,h0}.

[0117] After the key distribution center is initialized, a random number is generated by the key distribution center, a fixed length is truncated as the group key GSK, and the following formulas (1) to (3) are used for calculation:

[0118] H RSU =h0(SK KDC *PK RSU ID RSU (1)

[0119]

[0120] D RSU =GSK+R RSU +H RSU (3)

[0121] Among them, H RSU It can be used to represent the fourth initial verification information generated by KDC, Ω RSU It can be used to represent intermediate information generated by KDC, D RSU It can be used to represent the fifth target verification information generated by KDC.

[0122] The key distribution center calculates the fourth target verification information A = h0(GSK, H). RSU Generate the fourth timestamp T. r And calculate the second target distribution information Δ r =h0(ID) RSU ,A,Ω RSU D RSU ,Tr); then, the key distribution center distributes the message {ID} RSU ,A,Ω RSU D RSU Δ r ,Tr} is sent to the roadside unit.

[0123] Upon receiving the distribution message {ID} in the roadside unit RSU ,A,Ω RSU D RSU Δ r After ,Tr}, generate the third timestamp T. l Using the third timestamp Tl Subtract the fourth timestamp T r This allows us to obtain the difference between the aforementioned timestamps; verifying whether the difference is within a preset time difference range verifies the timeliness of the message. For example, if the difference is within the preset time difference range, the timeliness verification of the message is successful, and the message distribution content (ID) is then distributed. RSU ,A,Ω RSU D RSU Δ r ,Tr), can be used to calculate Δ r '=h0(ID RSU ,A,Ω RSU D RSU Is Tr related to Δ? r Equal to each other, thus verifying the integrity of the message; for example, if Δ r '=Δ r If the message integrity verification is successful, then the integrity verification is successful.

[0124] If both the timeliness and integrity of the message are successfully verified, the third initial verification information can be calculated using the following formula (4); and the random number R is extracted. RSU Using the following formula (5), the first network key can be calculated, as well as A' = h0(GSK', H'). RSU Verify that A' is the same as A. If they are the same, it means the key distribution center's identity is valid, thus confirming that the first network key is the correct network key, and that the first network key is the same as the third network key. Then, calculate...

[0125] H′ RSU =h0(SK RSU *PK KDC ID RSU (4)

[0126] GSK'=D RSU -R RSU -H' RSU (5)

[0127] For each vehicle, the roadside unit performs a cyclic calculation according to the following formulas (6) to (7) to generate the first target verification message Ai = h. o (GSK',Π i ), and generate the first timestamp T i Calculate the message integrity parameter Δ i =h0{ID i ,Ai,,V i ,Ti}. Package the message integrity parameters into a broadcast message corresponding to each vehicle, and send each broadcast message to the corresponding vehicle.

[0128] Π i =h o (SK RSU *PK i ,IDi) (6)

[0129] V i =GSK'+Π i +Ri (7)

[0130] After each vehicle receives the corresponding broadcast message, each vehicle verifies the corresponding first timestamp T. i With the corresponding first timestamp T n The timeliness of the broadcast message is verified by checking whether the difference between the two values ​​is within a preset time difference range. Additionally, each vehicle calculates its corresponding first initial verification message Π. i ′=h o {SK i *PK RSU ID i}, extract random number R i Then, using the following formula (8), the second network key can be calculated.

[0131] GSK'=D RSU -R RSU -H RSU (8)

[0132] Then, each vehicle calculates its own second target verification information Ai' = h0(GSK), Π' i The system verifies whether the second target verification information Ai' is the same as the first target verification information Ai. If Ai' is the same as Ai, it means that the RSU's identity is valid. This allows us to determine whether the first network key is the same as the second network key, which means that the network key obtained by the vehicle is the correct network key.

[0133] In this embodiment, when verifying the network key of a vehicle, a broadcast message generated by the roadside unit for the vehicle can be obtained. From the obtained broadcast message, first identification information and first target verification information can be extracted. Based on the extracted first identification information, second target verification information can be generated. Based on the extracted first target verification information and the generated second target verification information, the first network key of the roadside unit and the second network key of the vehicle can be verified to obtain a first verification result. Since this embodiment of the application, based on the first identification information and first target verification information extracted from the obtained broadcast message, can verify the first network key of the roadside unit and the second network key of the vehicle based on the extracted first target verification information and the second target verification information generated based on the extracted first identification information to obtain a first verification result, that is, it can determine whether the first network key and the second network key are the same, thereby achieving the goal of meeting the requirements of real-time communication of vehicular ad hoc networks, thus solving the technical problem of low efficiency in verifying network keys, and thus achieving the technical effect of improving the efficiency of verifying network keys.

[0134] According to another aspect of the present invention, corresponding to the embodiments of the key verification method described above, the present invention also provides a key verification device. Figure 4 This is a structural block diagram of a key verification device according to an embodiment of the present invention, such as... Figure 4 As shown, the key verification device 400 may include: a first acquisition unit 402, a processing unit 404, and a verification unit 406.

[0135] The first acquisition unit 402 is used to acquire a broadcast message generated by the roadside unit for the vehicle. The broadcast message includes the vehicle's first identification information and first target verification information. The first identification information is used to identify the vehicle, and the first target verification information is used to represent the verification message generated by the roadside unit for the vehicle.

[0136] The processing unit 404 is configured to extract first identification information and first target verification information from the broadcast message, and generate second target verification information based on the first identification information, wherein the second target verification information is used to represent the verification message generated by the vehicle for the roadside unit.

[0137] The verification unit 406 is used to verify the first networking key of the roadside unit and the second networking key of the vehicle based on the first target verification information and the second target verification information, and to obtain a first verification result. The first networking key is used to represent the key generated by the roadside unit for networking, the second networking key is used to represent the key generated by the vehicle for networking, and the first verification result is used to indicate whether the first networking key and the second networking key are the same.

[0138] Optionally, the key verification device 400 may include: a second acquisition unit, used to acquire a first public key of the roadside unit and a second public key of the vehicle, wherein the first public key and the first private key of the roadside unit are a key pair of the roadside unit, and the second public key and the second private key of the vehicle are a key pair of the vehicle; the processing unit 404 may include: a first combination module, used to combine the first identification information, the first public key and the second private key to obtain first initial verification information, wherein the first initial verification information corresponds to second initial verification information, and the second initial verification information is obtained by combining the first identification information, the second public key and the first private key; and a second combination module, used to combine the first initial verification information with a second networking key to obtain second target verification information.

[0139] Optionally, the verification unit 406 may include: a first verification module, configured to verify the identity of the roadside unit in response to the first target verification information and the second target verification information being the same, and obtain a second verification result, wherein the second verification result is used to indicate the relationship between the identity of the roadside unit and the target identity; and a second verification module, configured to verify the first network key and the second network key in response to the second verification result indicating that the identity of the roadside unit is the same as the target identity, and obtain a first verification result that the first network key and the second network key are the same.

[0140] Optionally, the broadcast message includes a first timestamp, which indicates the time when the broadcast message was generated. The processing unit 404 may include: an extraction and acquisition module, used to extract the first timestamp from the broadcast message and acquire a second timestamp of the broadcast message, wherein the second timestamp indicates the time when the broadcast message was received; a determination module, used to determine a first time difference between the first timestamp and the second timestamp; and an extraction module, used to extract first identification information and first target verification information from the broadcast message in response to the first time difference being within a preset time difference range.

[0141] In this embodiment, the key verification device includes the following units: a first acquisition unit, used to acquire a broadcast message generated by the roadside unit for the vehicle, wherein the broadcast message includes first identification information of the vehicle and first target verification information, the first identification information being used to identify the vehicle, and the first target verification information being used to represent the verification message generated by the roadside unit for the vehicle; a processing unit, used to extract the first identification information and the first target verification information from the broadcast message, and to generate second target verification information based on the first identification information, wherein the second target verification information is used to represent the verification message generated by the vehicle for the roadside unit; and a verification unit, used to verify the first networking key of the roadside unit and the second networking key of the vehicle based on the first target verification information and the second target verification information, to obtain a first verification result, wherein the first networking key is used to represent the key generated by the roadside unit for the network, the second networking key is used to represent the key generated by the vehicle for the network, and the first verification result is used to indicate whether the first networking key and the second networking key are the same. This achieves the goal of meeting the requirements of real-time communication of vehicular ad hoc networks, thereby solving the technical problem of low efficiency in verifying networking keys, and thus achieving the technical effect of improving the efficiency of verifying networking keys.

[0142] According to another aspect of the present invention, corresponding to the embodiments of the key verification method described above, the present invention also provides another key verification device. Figure 5 This is a structural block diagram of another key verification device according to an embodiment of the present invention, such as... Figure 5 As shown, the key verification device 500 may include a generation unit 502 and a sending unit 504.

[0143] The generation unit 502 is used to generate a broadcast message for a vehicle, wherein the broadcast message includes: first identification information of the vehicle and first target verification information, the first identification information is used to identify the vehicle, and the first target verification information is used to represent the verification message generated by the roadside unit for the vehicle, and the first identification information and the first target verification information are extracted from the broadcast message.

[0144] The sending unit 504 is used to send a broadcast message to the vehicle to verify the first networking key of the roadside unit and the second networking key of the vehicle based on the first target verification information and the second target verification information, and to obtain a first verification result. The second target verification information is used to represent the verification message generated by the vehicle for the roadside unit. The second target verification information is generated based on the first identification information. The first networking key is used to represent the key generated by the roadside unit for the network. The second networking key is used to represent the key generated by the vehicle for the network. The first verification result is used to indicate whether the first networking key and the second networking key are the same.

[0145] Optionally, the key verification device 500 may include: a receiving unit, configured to receive a distribution message generated by the distribution unit for a roadside unit, and a third timestamp of the distribution message, wherein the distribution message includes: a fourth timestamp, the fourth timestamp indicating the time of generating the distribution message, and the third timestamp indicating the time of receiving the distribution message; a first extraction unit, configured to extract the third timestamp from the distribution message; a first determining unit, configured to determine a second time difference between the third timestamp and the fourth timestamp; a second extraction unit, configured to extract distribution content from the distribution message in response to the second time difference being within a preset time difference range, wherein the distribution content includes: second identification information of the roadside unit, the second identification information indicating the roadside unit; and a generating unit, configured to generate first target distribution information based on the distribution content. In the above, the first target distribution information is used to represent the distribution information generated by the roadside unit for the network; the sending unit 504 includes: a generation module, used to generate the third target verification information of the roadside unit based on the first private key of the roadside unit, the third public key of the distribution unit and the second identification information in response to the first target distribution information being the same as the second target distribution information, wherein the second target distribution information is used to represent the distribution information generated by the distribution unit for the network, the first private key and the first public key of the roadside unit are key pairs of the roadside unit, and the third target verification information includes the first network key; and a sending module, used to send a broadcast message to the vehicle in response to the third target verification information being the same as the fourth target verification information of the distribution unit, wherein the fourth target verification information includes the third network key, and the third network key is used to represent the key generated by the distribution unit for the network.

[0146] Optionally, the generation module includes: a first combination submodule, used to combine the first private key, the third public key, and the second identification information to obtain the third initial verification information of the roadside unit; and a second combination submodule, used to combine the third initial verification information with the first networking key to obtain the third target verification information.

[0147] Optionally, the third public key and the third private key of the distribution unit are a key pair of the distribution unit. The key verification device 500 may include: a second determining unit, used to determine the first network key based on the fifth target verification information of the distribution unit, the random number of the roadside unit and the third initial verification information, wherein the fifth target verification information is obtained by summing the third network key, the random number and the fifth initial verification information of the distribution unit, and the fifth initial verification information is obtained by combining the third private key, the first public key and the second identification information.

[0148] Embodiments of this application also provide a vehicle, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods described in various embodiments of this application when it runs.

[0149] Embodiments of this application also provide a computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0150] Embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0151] Embodiments of this application also provide a computer program product, including a non-volatile computer-readable storage medium for storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0152] Embodiments of this application also provide a computer program that, when executed by a processor, implements the methods described in the various embodiments of this application.

[0153] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0154] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0155] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0156] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0157] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0158] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A key verification method, characterized in that, Applied to vehicles, where the vehicles and roadside units are in the same network, the method includes: Obtain a broadcast message generated by the roadside unit for the vehicle, wherein the broadcast message includes first identification information and first target verification information of the vehicle, the first identification information is used to identify the vehicle, and the first target verification information is used to represent a verification message generated by the roadside unit for the vehicle; The first identification information and the first target verification information are extracted from the broadcast message, and the second target verification information is generated based on the first identification information, wherein the second target verification information is used to represent the verification message generated by the vehicle for the roadside unit; Based on the first target verification information and the second target verification information, the first networking key of the roadside unit and the second networking key of the vehicle are verified to obtain a first verification result. The first networking key is used to represent the key generated by the roadside unit for the network, the second networking key is used to represent the key generated by the vehicle for the network, and the first verification result is used to indicate whether the first networking key and the second networking key are the same.

2. The method according to claim 1, characterized in that, The method further includes: Obtain the first public key of the roadside unit and the second public key of the vehicle, wherein the first public key and the first private key of the roadside unit are the key pair of the roadside unit, and the second public key and the second private key of the vehicle are the key pair of the vehicle. Based on the first identification information, generating second target verification information includes: combining the first identification information, the first public key, and the second private key to obtain first initial verification information, wherein the first initial verification information corresponds to the second initial verification information, and the second initial verification information is obtained by combining the first identification information, the second public key, and the first private key; The first initial verification information is combined with the second network key to obtain the second target verification information.

3. The method according to claim 1, characterized in that, Based on the first target verification information and the second target verification information, the first networking key of the roadside unit and the second networking key of the vehicle are verified to obtain a first verification result, including: In response to the first target verification information and the second target verification information being the same, the identity of the roadside unit is verified to obtain a second verification result, wherein the second verification result is used to represent the relationship between the identity of the roadside unit and the target identity; In response to the second verification result indicating that the identity of the roadside unit is the same as the target identity, the first network key and the second network key are verified, and the first verification result is that the first network key and the second network key are the same.

4. The method according to claim 1, characterized in that, The broadcast message includes: a first timestamp, which represents the time when the broadcast message was generated; and the extraction of the first identifier information and the first target verification information from the broadcast message, including: Extract the first timestamp from the broadcast message and obtain the second timestamp of the broadcast message, wherein the second timestamp is used to indicate the time when the broadcast message was received; Determine the first time difference between the first timestamp and the second timestamp; In response to the first time difference being within a preset time difference range, the first identification information and the first target verification information are extracted from the broadcast message.

5. A method for verifying a key, characterized in that, Applied to roadside units, where the roadside units and vehicles are in the same network, the method includes: Generate a broadcast message for the vehicle, wherein the broadcast message includes: first identification information and first target verification information of the vehicle, the first identification information is used to identify the vehicle, the first target verification information is used to indicate a verification message generated by the roadside unit for the vehicle, and the first identification information and the first target verification information are extracted from the broadcast message; The broadcast message is sent to the vehicle to verify the first networking key of the roadside unit and the second networking key of the vehicle based on the first target verification information and the second target verification information, and to obtain a first verification result. The second target verification information is used to represent the verification message generated by the vehicle for the roadside unit. The second target verification information is generated based on the first identification information. The first networking key is used to represent the key generated by the roadside unit for the network. The second networking key is used to represent the key generated by the vehicle for the network. The first verification result is used to indicate whether the first networking key and the second networking key are the same.

6. The method according to claim 5, characterized in that, The method further includes: The system receives a distribution message generated by the distribution unit for the roadside unit, and a third timestamp of the distribution message, wherein the distribution message includes a fourth timestamp, the fourth timestamp being used to indicate the time when the distribution message was generated, and the third timestamp being used to indicate the time when the distribution message was received; Extract the third timestamp from the distribution message; Determine the second time difference between the third timestamp and the fourth timestamp; In response to the second time difference being within a preset time difference range, the distribution content is extracted from the distribution message, wherein the distribution content includes: the second identification information of the roadside unit, the second identification information being used to identify the roadside unit; Based on the distribution content, first target distribution information is generated, wherein the first target distribution information is used to represent the distribution information generated by the roadside unit for the network; Sending the broadcast message to the vehicle includes: In response to the fact that the first target distribution information is the same as the second target distribution information, a third target verification information of the roadside unit is generated based on the first private key of the roadside unit, the third public key of the distribution unit and the second identification information. The second target distribution information is used to represent the distribution information generated by the distribution unit for the network. The first private key and the first public key of the roadside unit are the key pair of the roadside unit. The third target verification information includes the first network key. In response to the fact that the third target verification information and the fourth target verification information of the distribution unit are the same, the broadcast message is sent to the vehicle, wherein the fourth target verification information includes the third networking key, which is used to represent the key generated by the distribution unit for the network.

7. The method according to claim 6, characterized in that, Based on the first private key, the third public key of the distribution unit, and the second identification information, the third target verification information of the roadside unit is generated, including: The first private key, the third public key, and the second identification information are combined to obtain the third initial verification information of the roadside unit; The third initial verification information is combined with the first network key to obtain the third target verification information.

8. The method according to claim 7, characterized in that, The third public key and the third private key of the distribution unit constitute a key pair for the distribution unit, and the method further includes: Based on the fifth target verification information of the distribution unit, the random number of the roadside unit, and the third initial verification information, the first network key is determined, wherein the fifth target verification information is obtained by summing the third network key, the random number, and the fifth initial verification information of the distribution unit, and the fifth initial verification information is obtained by combining the third private key, the first public key, and the second identification information.

9. A processor, characterized in that, The processor is used to run a program, wherein the program, when run by the processor, performs the verification method of the key according to any one of claims 1 to 8.

10. A vehicle, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the verification method for the key according to any one of claims 1 to 8.