Encrypted communication system and communication node in Internet of Vehicles

By employing quantum-resistant components and communication mode switching components in the Internet of Vehicles, a secure session is established using quantum-resistant encryption and signature algorithms, and a backup mode is switched when the conditions for quantum resistance are not met. This solves the problem of insufficient security of quantum computing against existing asymmetric encryption technologies, and achieves higher communication security and continuity.

CN121193418APending Publication Date: 2025-12-23CHINA AUTOMOTIVE INNOVATION CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511347391.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-19
Publication Date
2025-12-23

AI Technical Summary

Technical Problem

Existing asymmetric encryption technologies such as ECC and RSA are less secure when faced with quantum computing and cannot meet quantum-resistant security standards, resulting in insufficient data transmission security in vehicle-to-everything (V2X) scenarios.

Method used

It employs quantum-resistant components and communication mode switching components, uses quantum-resistant encryption algorithms and signature algorithms to establish secure sessions, and switches to backup mode when communication conditions do not meet the quantum-resistant standard, using asymmetric encryption algorithms and signature algorithms for communication.

Benefits of technology

It improves the security of vehicle-to-everything (V2X) data transmission, ensures the continuity and accuracy of communication, enhances the system's disaster recovery capabilities, and resists quantum attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121193418A_ABST
    Figure CN121193418A_ABST
Patent Text Reader

Abstract

The invention relates to an encryption communication system and a communication node in the Internet of Vehicles, and belongs to the technical field of encryption communication. In the system, a first communication node is used for encrypting and signing a session establishment request through an anti-quantum component; the second communication node is used for carrying out decryption and signature verification through an anti-quantum algorithm so as to establish a security session of an anti-quantum mode, and when the communication time delay and the error rate do not meet the anti-quantum communication condition, the security session of the anti-quantum mode is switched through a communication mode switching component in the second communication node. The secure session is switched to a standby mode that is encrypted and signed using a conventional encryption and signature algorithm. The anti-quantum component can enable the system to have the quantum attack resistance, and the communication security in the system is improved; and the communication mode switching component can degrade the communication mode to the standby mode under the condition that the quantum communication resisting condition is not met, so that the communication continuity and accuracy can be ensured, the disaster recovery capability is improved, and the communication security is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of encrypted communication, and particularly relates to an encrypted communication system in vehicle networking and a communication node. BACKGROUND

[0002] With the development of vehicle networking technology, the vehicle-to-vehicle communication, vehicle-to-cloud communication and vehicle-to-road communication and other vehicle networking scenarios have higher and higher requirements for the security of data transmission, and therefore, in the vehicle networking scenario, an encrypted communication technology is usually used, that is, a cryptography algorithm is used to convert original data into a cipher during data transmission, so as to ensure the security of data transmission.

[0003] In the related art, an Elliptic Curve Cryptography (ECC) or Rivest-Shamir-Adleman (RSA) encryption and other asymmetric encryption technologies are used to encrypt the data transmitted in vehicle networking. Asymmetric encryption refers to the use of two different keys, a public key and a private key, for encryption and decryption. The sender encrypts the data using the public key of the receiver, and the receiver decrypts using its own private key.

[0004] However, with the development of quantum computing, the mathematical problems on which ECC and RSA and other asymmetric encryption technologies depend will be efficiently cracked by quantum computers using the Shor algorithm, which reduces the security of data transmission in the vehicle networking scenario and cannot meet the quantum-resistant security standard (NIST). SUMMARY

[0005] The present application provides an encrypted communication system in vehicle networking and a communication node, which can improve the security of data transmission in the vehicle networking scenario. The technical solutions of the present application are as follows.

[0006] According to a first aspect of the embodiments of the present application, an encrypted communication system in vehicle networking is provided, which comprises a first communication node and a second communication node. The first communication node comprises an anti-quantum component, and the second communication node comprises a communication mode switching component.

[0007] The first communication node is configured to use an anti-quantum encryption algorithm and an anti-quantum signature algorithm to encrypt and sign a session establishment request through the anti-quantum component, and send the encrypted and signed session establishment request to the second communication node.

[0008] The second communication node is used to verify and decrypt the encrypted and signed session establishment request using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. After the signature verification and decryption are successful, it sends a response to the session establishment request to the first communication node to establish a secure session in quantum-resistant mode between the first and second communication nodes.

[0009] The second communication node is also used to switch the secure session between the first and second communication nodes from quantum-resistant mode to standby mode through a communication mode switching component when the communication latency and bit error rate of the secure session in quantum-resistant mode do not meet the latency and bit error rate conditions of quantum-resistant communication. In standby mode, asymmetric encryption algorithms and asymmetric signature algorithms are used for encryption and signing.

[0010] In one possible implementation, the session establishment request includes a session key and session identification information, and the quantum-resistant component is configured with a quantum-resistant key encapsulation module and a quantum-resistant signature module; the first communication node is used for:

[0011] The quantum-resistant key encapsulation module in the quantum-resistant component uses the modular key encapsulation algorithm ML-KEM to encrypt the session key in the session establishment request and generate ciphertext.

[0012] The quantum-resistant signature module in the quantum-resistant component uses the Modular Digital Signature Algorithm (ML-DSA) to sign the session key and session identifier information in the session establishment request, generating a signature.

[0013] In one possible implementation, the quantum-resistant component is further configured with a polynomial operation module, which includes multiple computational units adapted for parallel computation of multiple coefficients of a sparse polynomial ring; the first communication node is used for:

[0014] The ML-KEM algorithm on the quantum-resistant key encapsulation module is executed through the polynomial operation module in the quantum-resistant component to encrypt and encapsulate the session key in the session establishment request and generate ciphertext.

[0015] The polynomial operation module in the quantum-resistant component executes the ML-DSA algorithm on the quantum-resistant signature module to sign the session key and session identification information in the session establishment request, generating a signature.

[0016] In one possible implementation, the first communication node is further configured with a quantum-resistant algorithm instruction set, which includes multiple hardware instructions for executing the quantum-resistant algorithm; the first communication node is used for:

[0017] By using the polynomial operation module in the quantum-resistant component, at least one hardware instruction from the quantum-resistant algorithm instruction set is called to execute the ML-KEM algorithm, encrypt the session key in the session establishment request, and generate ciphertext;

[0018] By using the polynomial operation module in the quantum-resistant component, at least one hardware instruction from the quantum-resistant algorithm instruction set is called to execute the ML-DSA algorithm, sign the session key and session identification information in the session establishment request, and generate a signature.

[0019] In one possible implementation, the communication mode switching component includes a channel monitoring module for monitoring communication latency and bit error rate; the second communication node is used for:

[0020] The communication latency and bit error rate are monitored in real time through the channel monitoring module in the communication mode switching component;

[0021] When the communication delay of the secure session in quantum-resistant mode exceeds the preset delay or the bit error rate exceeds the preset bit error rate, a communication mode switching notification is sent to the first communication node through the communication mode switching component, so that the secure session between the first communication node and the second communication node switches from quantum-resistant mode to standby mode.

[0022] In one possible implementation, the second communication node is further used for:

[0023] When the communication latency and bit error rate of the secure session in standby mode meet the latency and bit error rate conditions for quantum-resistant communication, the secure session between the first communication node and the second communication node is switched from standby mode to quantum-resistant mode through the communication mode switching component.

[0024] In one possible implementation, the first communication node and the second communication node are each configured with a key recovery counter, which is used to indicate the number of key updates and the key state in quantum-resistant mode and standby mode; the first communication node and the second communication node are also used for:

[0025] Whenever the second communication node switches the communication mode of the secure session between the first and second communication nodes from standby mode to quantum-resistant mode, it synchronously updates its respective key recovery calculator.

[0026] In one possible implementation, the first and second communication nodes are further used for:

[0027] When the secure session between the first communication node and the second communication node is in quantum-resistant mode, the session key in quantum-resistant mode is updated based on the first update cycle.

[0028] When the secure session between the first communication node and the second communication node is in standby mode, the session key in standby mode is updated based on the second update cycle;

[0029] The second update cycle is shorter than the first update cycle.

[0030] In one possible implementation, the first update cycle is determined based on real-time traffic flow density and a first safety factor;

[0031] The second update cycle is determined based on real-time traffic flow density and a second safety factor.

[0032] The first security factor indicates the communication security in quantum-resistant mode, and the second security factor indicates the communication security in standby mode.

[0033] In one possible implementation, the first and second communication nodes are further used for:

[0034] After establishing a secure quantum-resistant session between the first and second communication nodes, communication between the first and second communication nodes is based on a lightweight message authentication code (MAC).

[0035] In one possible implementation, the first communication node is any one of an on-board unit, a roadside unit, or a cloud platform; the second communication node is any one of an on-board unit, a roadside unit, and a cloud platform.

[0036] According to a second aspect of the embodiments of this application, a communication node is provided, the communication node including a quantum-resistant component, the communication node being a communication node in an encrypted communication system in a vehicle network; the communication node is used for:

[0037] The session establishment request is encrypted and signed using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm through a quantum-resistant component. The encrypted and signed session establishment request is then sent to a second communication node in the encrypted communication system. The second communication node includes a communication mode switching component.

[0038] Receive a response to a session establishment request sent by the second communication node to establish a secure session with the second communication node in a quantum-resistant mode;

[0039] When the communication latency and bit error rate of the secure session in quantum-resistant mode do not meet the latency and bit error rate conditions of quantum-resistant communication, a secure session in backup mode is established with the second communication node through the quantum-resistant component. The backup mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

[0040] According to a third aspect of the embodiments of this application, a communication node is provided, the communication node including a communication mode switching component, the communication node being a communication node in an encrypted communication system in a vehicle network; the communication node is used for:

[0041] The system receives an encrypted and signed session establishment request from the first communication node in the encrypted communication system. The session establishment request is obtained by the first communication node through a quantum-resistant component, using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm to encrypt and sign the session establishment request.

[0042] The encrypted and signed session establishment request is verified and decrypted using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. After the signature verification and decryption are successful, a response to the session establishment request is sent to the first communication node to establish a secure session in quantum-resistant mode with the first communication node.

[0043] When the communication latency and bit error rate of the secure session in quantum-resistant mode do not meet the latency and bit error rate conditions for quantum-resistant communication, the secure session with the first communication node is switched from quantum-resistant mode to standby mode through the communication mode switching component. In standby mode, asymmetric encryption algorithm and asymmetric signature algorithm are used for encryption and signing.

[0044] According to a fourth aspect of the embodiments of this application, an encrypted communication method in a vehicle network is provided, applied to an encrypted communication system in a vehicle network. The encrypted communication system includes a first communication node and a second communication node. The first communication node includes a quantum-resistant component, and the second communication node includes a communication mode switching component. The method includes:

[0045] The first communication node uses a quantum-resistant component to encrypt and sign the session establishment request using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm, and then sends the encrypted and signed session establishment request to the second communication node.

[0046] The second communication node verifies and decrypts the encrypted and signed session establishment request using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. After successful verification and decryption, it sends a response to the session establishment request to the first communication node to establish a secure session in quantum-resistant mode between the first and second communication nodes.

[0047] When the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions for quantum-resistant communication, the second communication node switches the secure session between the first and second communication nodes from the quantum-resistant mode to the backup mode through the communication mode switching component. The backup mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

[0048] According to a fifth aspect of the present application, an encrypted communication device for a vehicle network is provided, applied to a first communication node in an encrypted communication system of the vehicle network, the first communication node including a quantum-resistant component; the device includes:

[0049] The sending module is used to encrypt and sign the session establishment request using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm through a quantum-resistant component, and send the encrypted and signed session establishment request to a second communication node in the encrypted communication system. The second communication node includes a communication mode switching component.

[0050] The receiving module is used to receive the response to the session establishment request sent by the second communication node, so as to establish a secure session against quantum mode between the first communication node and the second communication node.

[0051] The switching module is used to establish a backup secure session between the first and second communication nodes through the quantum-resistant component when the communication latency and bit error rate of the secure session in quantum-resistant mode do not meet the latency and bit error rate conditions of quantum-resistant communication. The backup mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

[0052] According to a sixth aspect of the present application, an encrypted communication device for a vehicle network is provided, which is applied to a second communication node in an encrypted communication system of a vehicle network, the second communication node including a communication mode switching component; the device includes:

[0053] The receiving module is used to receive the encrypted and signed session establishment request sent by the first communication node. The session establishment request is obtained by the first communication node through a quantum-resistant component, using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm to encrypt and sign the session establishment request.

[0054] The sending module is used to verify and decrypt the encrypted and signed session establishment request using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. After the signature verification and decryption are successful, it sends a response to the session establishment request to the first communication node to establish a secure session in quantum-resistant mode between the first communication node and the second communication node.

[0055] The switching module is used to switch the secure session between the first communication node and the second communication node from the quantum-resistant mode to the standby mode through the communication mode switching component when the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions of the quantum-resistant communication. The standby mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

[0056] According to a seventh aspect of the present application, a quantum-resistant component is provided, applied to a first communication node in an encrypted communication system in a vehicle network, the quantum-resistant component being used for:

[0057] The session establishment request is encrypted and signed using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm. The encrypted and signed session establishment request is sent to a second communication node in the encrypted communication system. The second communication node includes a communication mode switching component.

[0058] Receive a response to a session establishment request sent by the second communication node to establish a secure session against quantum mode between the first and second communication nodes;

[0059] When the communication latency and bit error rate of the secure session in quantum-resistant mode do not meet the latency and bit error rate conditions for quantum-resistant communication, a secure session in backup mode is established between the first communication node and the second communication node. The backup mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

[0060] According to an eighth aspect of the present application, a computer storage medium is provided, which stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor of a first communication node to perform the function of the first communication node in an encrypted communication system in a vehicle network as provided in the first aspect or any possible embodiment of the first aspect.

[0061] According to a ninth aspect of the present application, a computer storage medium is provided, which stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor of a second communication node to perform the function of the second communication node in an encrypted communication system in a vehicle network as provided in the first aspect or any possible embodiment of the first aspect.

[0062] According to a tenth aspect of the present application, a computer program product is provided, including a computer program that, when executed by a processor of a first communication node, implements the functions of the first communication node in an encrypted communication system in a vehicle network provided by the first aspect or any possible embodiment of the first aspect.

[0063] According to the eleventh aspect of the embodiments of this application, a computer program product is provided, including a computer program that, when executed by the processor of a second communication node, implements the function of the second communication node in the encrypted communication system of the Internet of Vehicles provided by the first aspect or any possible embodiment of the first aspect.

[0064] The technical solutions provided by the embodiments of this application have at least the following beneficial effects:

[0065] The first communication node encrypts and signs session establishment requests using a quantum-resistant component. The second communication node decrypts and verifies the signature using a quantum-resistant algorithm, thus establishing a secure session in quantum-resistant mode. When communication latency and bit error rate do not meet the conditions for quantum-resistant communication, the communication mode switching component in the second communication node switches the secure session to a backup mode that uses traditional encryption and signature algorithms for encryption and signing. The quantum-resistant component enables the system to resist quantum attacks, improving the security of communication within the system. The communication mode switching component can downgrade the communication mode to a backup mode when the conditions for quantum-resistant communication are not met, thus ensuring communication continuity and accuracy, improving disaster recovery capabilities, and further enhancing communication security.

[0066] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0067] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application, and do not constitute an undue limitation of this application.

[0068] Figure 1 This is an example diagram of the architecture of an encrypted communication system 100 in a vehicle network provided in an embodiment of this application;

[0069] Figure 2 This is a flowchart illustrating the session establishment process of the first and second communication nodes in an encrypted communication method for a vehicle network provided in this application embodiment.

[0070] Figure 3 This is a flowchart illustrating the switching of a secure session between a first communication node and a second communication node from quantum-resistant mode to a standby mode in an encrypted communication method for a vehicle network provided in this application embodiment;

[0071] Figure 4 This is a flowchart illustrating the switching of the communication mode of the first communication node and the second communication node from a standby mode to a quantum-resistant mode in an encrypted communication method in a vehicle network provided in this application embodiment;

[0072] Figure 5 This is a flowchart illustrating an encrypted communication method in a vehicle network provided in an embodiment of this application;

[0073] Figure 6 This is a structural block diagram of an encrypted communication device in a vehicle network provided in an embodiment of this application;

[0074] Figure 7 This is a structural block diagram of an encrypted communication device in a vehicle network provided in an embodiment of this application. Detailed Implementation

[0075] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0076] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of methods and systems consistent with some aspects of this application as detailed in the appended claims.

[0077] In this application, the terms "first," "second," etc., are used to distinguish identical or similar items with substantially the same function. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor does it limit the quantity or order of execution. It should also be understood that although the following description uses the terms "first," "second," etc., to describe various elements, these elements should not be limited by the terms. These terms are merely used to distinguish one element from another. In this application, "at least one" means one or more, while "multiple" means two or more.

[0078] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals designed in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0079] First, for ease of understanding, the relevant terms involved in the embodiments of this application will be explained.

[0080] 1. Internet of Vehicles (IoV): IoV refers to an intelligent network system with vehicles as the core nodes. It utilizes wireless communication technologies (such as 5G / 6G, WiFi, Bluetooth, Dedicated Short-Range Communications (DSRC), etc.), sensing technologies, satellite positioning technologies, and artificial intelligence to achieve real-time information exchange between vehicles (V2V), between vehicles and road infrastructure (V2I), between vehicles and cloud platforms (V2C), and between vehicles and pedestrians (V2P). Its core objectives are to improve driving safety, optimize traffic efficiency, enhance the driving experience, and provide support for applications such as autonomous driving and intelligent traffic management. For example, while driving, vehicles can obtain real-time speed and braking status of surrounding vehicles through V2V communication, and provide early warning of collision risks; smart cameras (V2I devices) on the roadside can upload traffic congestion information ahead to the cloud platform, which will then push it to nearby vehicles to guide drivers in planning detour routes.

[0081] 2. NIST Standards (National Institute of Standards and Technology Standards): NIST standards provide secure encryption solutions for connected vehicles and also provide specifications for device authentication within connected vehicles. Its authentication and electronic certification standards ensure the security and reliability of communication between vehicles and between vehicles and infrastructure. For example, in connected vehicles, NIST standards can be used to authenticate vehicle devices; only authenticated devices can communicate, thus ensuring the security of connected vehicle communication. Furthermore, NIST's cybersecurity framework provides fundamental principles for managing cybersecurity risks in connected vehicles, covering core functions such as identification, protection, discovery, response, and recovery, helping connected vehicle systems better cope with cybersecurity threats.

[0082] 3. Module-Lattice Key-Encapsulation Mechanism (ML-KEM): The ML-KEM algorithm is the standard key encapsulation mechanism (KEM) algorithm selected by the NIST quantum-resistant cryptography standardization project. Based on the "module" mathematical problem, its core function is to securely negotiate a shared session key between communicating parties in an insecure communication channel. This key is used to encrypt and protect subsequently transmitted data, and it can resist attacks from quantum computers (traditional cryptographic algorithms based on large integer factorization and discrete logarithm problems are easily cracked by quantum computers). Its workflow is roughly as follows: The sender first generates a public key and private key pair and sends the public key to the receiver; the receiver uses the public key to generate a shared key and "encapsulation information" and sends the encapsulation information to the sender; the sender uses the private key and decapsulation information to finally calculate the shared key that matches the receiver's. For example, in V2C communication in vehicle-to-everything (V2C) communication, the on-board unit and the cloud platform can negotiate a session key using the ML-KEM algorithm to ensure the security of subsequent vehicle status data and control command transmissions.

[0083] 4. Module-Lattice Digital Signature Algorithm (ML-DSA): The ML-DSA algorithm is the digital signature algorithm standard selected by the NIST quantum-resistant cryptography standardization project. Also based on the modular mathematical problem, it is mainly used to verify the integrity, authenticity, and non-repudiation of data. That is, it ensures that data has not been tampered with during transmission or storage, proves the sender's identity, and that the sender cannot deny sending the data. Its core process is as follows: The signer generates a public key and private key pair, uses the private key to sign the data (generating a unique "signature message"), and sends the data and signature message together to the verifier. The verifier obtains the signer's public key and verifies the data and signature message using the public key. If the verification passes, it confirms that the data has not been tampered with and comes from a legitimate sender; otherwise, the data is deemed invalid.

[0084] 5. Lightweight Message Authentication Code (Lightweight MAC): Lightweight MAC is a message authentication code algorithm designed specifically for resource-constrained devices (such as IoT sensors, embedded devices, smart cards, and low-power vehicle sensors in the Internet of Vehicles). While ensuring basic data integrity and authentication functions, it significantly reduces the algorithm's computational complexity, storage space usage, and energy consumption (compared to traditional MAC algorithms, lightweight MAC has fewer computational steps and requires less memory). Its working principle is as follows: The sender and receiver pre-share a "key." The sender calculates a fixed-length "authentication tag" (i.e., MAC value) for the data to be transmitted and sends the data along with the authentication tag. Upon receiving the data, the receiver recalculates the MAC value using the same shared key and the same algorithm. If the MAC value matches the received authentication tag, it indicates that the data has not been tampered with and comes from the legitimate sender holding the shared key.

[0085] 6. Post-Quantum Cryptography Instruction Set (PQC Instruction Set): The PQC instruction set is a processor instruction set specifically designed to improve the running efficiency of quantum-resistant cryptographic algorithms (such as the ML-KEM algorithm and the ML-DSA algorithm). It belongs to the hardware-level optimization technology. Because the computation process of quantum-resistant cryptographic algorithms (especially those based on lattices, hashes, and codes) involves a large number of repetitive and complex basic operations (such as polynomial multiplication, modular arithmetic, and vector addition), traditional general-purpose processor instructions struggle to efficiently handle these operations, resulting in slow algorithm execution speed and high energy consumption. The PQC instruction set encapsulates these high-frequency complex operations into one or several dedicated hardware instructions, allowing the processor to execute them directly, significantly reducing computation steps and lowering CPU utilization. For example, when an onboard unit runs the ML-KEM algorithm for key negotiation, it can call dedicated PQC instructions to shorten the algorithm execution time, avoiding the impact of excessive cryptographic computation time on real-time vehicle-to-everything (V2X) communication (such as emergency braking command transmission in autonomous driving).

[0086] 7. Single Instruction Multiple Data Parallel Architecture (SIMD): SIMD is a processor parallel computing technology. Its core feature is "one instruction processes multiple data simultaneously." That is, a processor's arithmetic unit (such as the Arithmetic and Logic Unit, ALU) receives one instruction and multiple sets of data of the same type within the same instruction cycle, performing the same operations on these data simultaneously. This significantly improves data processing efficiency, making it particularly suitable for scenarios requiring repetitive computations on large amounts of data (such as image processing, audio processing, cryptographic operations, and artificial intelligence inference). For example, when running the ML-KEM algorithm, multiple sets of polynomial data need to be multiplied and modularly operated on. A processor based on SIMD architecture can process multiple sets of polynomial data operations simultaneously with a single instruction. Compared to the traditional Single Instruction Single Data (SISD) architecture, where "one instruction processes one data," the computation speed can be increased several times.

[0087] The relevant terms used in the embodiments of this application have been introduced above. The implementation environment of the embodiments of this application is described below. The implementation environment of the embodiments of this application is an encrypted communication system in a vehicle-to-everything (V2X) network. This encrypted communication system includes a first communication node and a second communication node. The first communication node can be any one of an on-board unit, a roadside unit, and a cloud platform, and the second communication node can be any one of an on-board unit, a roadside unit, and a cloud platform. For example, if both the first and second communication nodes are on-board units, the encrypted communication system is applied to a V2V scenario in a V2X network; or, if both the first and second communication nodes are on-board units, the encrypted communication system is applied to a V2I scenario in a V2X network; or, if both the first and second communication nodes are on-board units, the encrypted communication system is applied to a V2C scenario in a V2X network. It should be noted that the above description of the first and second communication nodes in the encrypted communication system is merely exemplary. The first and second communication nodes can be any two communicable nodes in the vehicle network. Furthermore, the encrypted communication system may include more first communication nodes and more second communication nodes. This application embodiment only uses the first and second communication nodes in the encrypted communication system as examples for illustration. In addition, in some embodiments, the first communication node can act as the second communication node, and the second communication node can act as the first communication node. This application embodiment divides the communication nodes in the encrypted communication system of the vehicle network into first and second communication nodes from the perspective of the initiator and receiver of the session, that is, it is divided according to the "role" played by the communication node, rather than according to the function or category of the communication node. It can be understood that the same communication node can switch to different "roles" in different communication scenarios. For example, in the Internet of Vehicles (IoV), if vehicle-mounted unit A initiates a conversation with roadside unit B, then in this scenario, vehicle-mounted unit A is the first communication node and roadside unit B is the second communication node; if vehicle-mounted unit C initiates a conversation with vehicle-mounted unit A, then in this scenario, vehicle-mounted unit C is the first communication node and vehicle-mounted unit A is the second communication node.

[0088] The encrypted communication system in this vehicle network will be introduced below, taking the first communication node as the vehicle-mounted unit and the second communication node as the roadside unit as an example. Figure 1 This is an example diagram illustrating the architecture of an encrypted communication system 100 in a vehicle-to-everything (V2X) network, as provided in an embodiment of this application. The encrypted communication system 100 includes an on-board unit 110 and a roadside unit 120. The on-board unit 110 is capable of communicating with the roadside unit 120.

[0089] The On-Board Unit (OBU) 110 is an intelligent terminal installed on the vehicle for interacting with roadside units, cloud platforms, etc. Its core functions are to collect vehicle data, receive external information, and assist vehicle control. The OBU 110 can be one of an embedded integrated OBU, a stand-alone external OBU, or a mobile terminal multiplexed OBU. The OBU 110 includes an In-Vehicle Main Control System onChip (SoC) 111 and a Quantum Security Module (HSM) 112. The SoC 111 and the HSM communicate with each other via a secure bus. The HSM 112 includes a polynomial operation module 1121, which comprises multiple computation units adapted for parallel computation of multiple coefficients of a sparse polynomial ring. The polynomial operation module 1121 can adopt a SIMD parallel architecture. For example, the vehicle-mounted main control system-on-a-chip 111 can trigger the vehicle-mounted unit 110 to initiate a session establishment request to the roadside unit 120 through its built-in V2X protocol stack, and initiate a session reconnection or handover request after the session is interrupted. The quantum-resistant component 112 is configured with a quantum-resistant key encapsulation module and a quantum-resistant signature module. The quantum-resistant key encapsulation module is used to perform quantum-resistant encryption on the session key initiated by the vehicle-mounted main control system-on-a-chip 111 using the ML-KEM algorithm to generate ciphertext. This quantum-resistant key encapsulation module supports the indistinguishability under adaptive Chosen Ciphertext Attack (IND-CCA2) security level. The quantum-resistant signature module is used to generate a signature for the vehicle-mounted unit 110 using the ML-DSA algorithm. It should be noted that the quantum-resistant key encapsulation module and the quantum-resistant signature module can share the polynomial operation module 1121. That is, the algorithms of both the quantum-resistant key encapsulation module and the quantum-resistant signature module are calculated using the computational power of multiple computing units of the polynomial operation module 1121. Alternatively, the quantum-resistant key encapsulation module and the quantum-resistant signature module can each use a separate polynomial operation module for calculation; this embodiment does not limit this. It should also be noted that the quantum-resistant key encapsulation module and the quantum-resistant signature module can be software modules (exemplarily, the quantum-resistant key encapsulation module and the quantum-resistant signature module in software module form...). Figure 1 (Using dashed lines for identification), or its function can be integrated into hardware as a hardware module; this application embodiment does not limit this; the polynomial operation module 1121 is a hardware module (exemplarily, a polynomial operation module in hardware module form in... Figure 1 (Use solid lines to indicate).

[0090] The Roadside Unit (RSU) 120 is an intelligent device deployed along roads (such as intersections, toll booths, and highway service areas). Its core functions are to sense road conditions, communicate with the onboard unit 110, and upload data to the cloud. The Roadside Unit 120 can be one of the following: a fixed intersection roadside unit, a highway-dedicated roadside unit, a temporarily deployed roadside unit, or a smart roadside pile integrated roadside unit. For example, the Roadside Unit 120 can receive encrypted and signed session requests sent by the onboard unit 110, and decrypt and verify the session request according to the algorithm corresponding to the communication mode negotiated with the onboard unit. After successful decryption and signature verification, it returns a session response to the onboard unit 110, thereby communicating with the onboard unit 110. The Roadside Unit 120 includes a communication mode switching component 121, which includes a channel monitoring module 1211 and a communication mode switching module 1212. The channel monitoring module 1211 is used to monitor the communication delay and bit error rate when other communication nodes in the vehicle network communicate with the roadside unit 121. The communication mode switching module 1212 is used to switch the communication mode between the roadside unit 120 and the vehicle-mounted unit 110 based on the communication quality between the vehicle-mounted unit 110 and the roadside unit 120. For example, if the communication delay is greater than a preset delay and the bit error rate is greater than a preset bit error rate, the communication mode between the roadside unit 120 and the vehicle-mounted unit 110 is switched from quantum-resistant mode to standby mode; or, if the communication delay is less than a preset delay and the bit error rate is less than a preset bit error rate, the communication mode between the roadside unit 120 and the vehicle-mounted unit is switched from standby mode to quantum-resistant mode. Quantum-resistant mode refers to communication between the vehicle-mounted unit 110 and the roadside unit 120 being encrypted and signed using a quantum-resistant algorithm. Standby mode refers to communication between the vehicle-mounted unit 110 and the roadside unit 120 being encrypted and signed using an asymmetric encryption algorithm and an asymmetric signature algorithm. Figure 1 The example uses the ECC-256 algorithm for both asymmetric encryption and asymmetric signature. In some embodiments, the quantum-resistant mode communication between the roadside unit 120 and the vehicle-mounted unit 110 is referred to as PQC-based logic channel communication, and the backup mode communication between the roadside unit 120 and the vehicle-mounted unit 110 is referred to as ECC-based logic channel communication. It should be noted that the communication mode switching module 1212 can be a software module, or its functions can be integrated into hardware to become a hardware module (exemplarily, the hardware module form of the communication mode switching module 1212 is...). Figure 1 (The solid lines used for marking are not limited in this application embodiment).

[0091] In some embodiments, the vehicle unit 110 and the roadside unit 120 communicate using Dedicated Short-Range Communications (DSRC), Cellular Vehicle-to-Everything (C-V2X), Bluetooth, or Wireless Fidelity (WiFi).

[0092] The above describes an encrypted communication system in a vehicle-to-everything (V2X) network provided by embodiments of this application. The following describes an encrypted communication method in a V2X network provided by embodiments of this application. This method is applied to the aforementioned encrypted communication system, which includes a first communication node and a second communication node. The first communication node includes a quantum-resistant component, and the second communication node includes a communication mode switching component. The method includes: the first communication node encrypts and signs a session establishment request using a quantum-resistant algorithm through the quantum-resistant component, and sends the encrypted and signed session establishment request to the second communication node; the second communication node verifies and decrypts the encrypted and signed session establishment request using the quantum-resistant algorithm, and after successful verification and decryption, sends a response to the session establishment request to the first communication node to establish a secure session in quantum-resistant mode between the first and second communication nodes; when the communication latency and bit error rate of the secure session in quantum-resistant mode do not meet the latency and bit error rate conditions for quantum-resistant communication, the second communication node switches the secure session between the first and second communication nodes from quantum-resistant mode to a backup mode through the communication mode switching component. The backup mode uses an asymmetric encryption algorithm and an asymmetric signature algorithm for encryption and signing. In the above method, a quantum-resistant component is configured on the first communication node in the vehicle network, and a communication mode switching component is configured on the second communication node. The quantum-resistant component enables the system to resist quantum attacks, thereby improving the security of communication in the system. At the same time, when the latency and bit error rate do not meet the conditions for quantum-resistant communication, the system can dynamically downgrade the communication mode to the backup traditional encryption mode to ensure the continuity and accuracy of communication, improve the disaster recovery capability of communication in the system, and further improve the security of communication in the system.

[0093] The following section describes the session establishment process between the first and second communication nodes in the above method. Figure 2 This is a flowchart illustrating the session establishment process of the first and second communication nodes in an encrypted communication method for a vehicle network provided in this application embodiment. Figure 2 As shown, this process is applied to the above-mentioned encrypted communication system, and the process includes the following steps 201 to 205.

[0094] Step 201: The first communication node sends a first session notification to the second communication node.

[0095] The first session notification is used to notify the second communication node to negotiate a session key to establish a secure session between the two communication nodes. The first session notification includes the identifier of the first communication node and current communication environment parameters. For example, the current communication environment parameters are vehicle speed and signal strength.

[0096] The first session notification is generated by the control unit on the first communication node. For example, the first communication node is an in-vehicle unit, the control unit on the in-vehicle unit is an in-vehicle main control system-on-a-chip, and the first session notification is generated by the in-vehicle main control system-on-a-chip.

[0097] This application does not limit the timing of the first communication node sending the first session notification to the second communication node. The first communication node can send the first session notification to the second communication node as needed. For example, the first session notification can be sent when the vehicle first enters the vehicle network system. For instance, when a vehicle first accesses the vehicle network, it needs to establish a secure communication connection with the roadside unit. At this time, the on-board unit (first communication node) will send the first session notification to the roadside unit (second communication node) to negotiate the session key used for subsequent communication, ensuring the security of vehicle authentication and data transmission. Another example is that the first session notification can be sent during the communication session initialization phase. For instance, at the start of each new communication session, in order to ensure data security during the session, the on-board unit (first communication node) will send the first session notification to the roadside unit (second communication node) to negotiate the session key specific to this session. For example, the first session notification may be sent when a key update is required. For instance, to improve communication security and prevent data leakage due to session key breaches, the vehicle-mounted unit (first communication node) and the roadside unit (second communication node) periodically update the session key. When a preset key update cycle is reached or specific key update conditions are met, the vehicle-mounted unit will initiate a first session notification to the roadside unit to negotiate a new session key. Another example is when the first session notification is sent after a security authentication failure and re-authentication. For instance, if the security authentication process between the vehicle-mounted unit (first communication node) and the roadside unit (second communication node) fails, such as signature verification failure or decryption failure, the vehicle-mounted unit will again initiate a first session notification to the roadside unit to negotiate a new session key or re-verify the validity of the session key in order to re-establish secure communication. Yet another example is when the first session notification is sent after a communication mode switch. For example, when the communication mode of the vehicle network switches from one mode to another, such as from quantum-resistant mode to standby mode, the on-board unit (first communication node) needs to re-negotiate the session key with the roadside unit (second communication node) to adapt to the security requirements of the new communication mode.

[0098] Step 202: The second communication node receives the first session notification. If the communication delay is less than the preset delay and the bit error rate is less than the preset bit error rate, the second communication node sends a first negotiation notification to the first communication node through the communication mode switching component. The first negotiation notification is used to instruct the first communication node to negotiate the session key through the quantum-resistant mode.

[0099] The second communication node includes a channel monitoring module, which monitors the latency and bit error rate (BER) of communication between the second communication node and other communication nodes in the encrypted communication system of the vehicle network in real time. In some embodiments, the second communication node estimates the latency and BER of the current communication based on historical interaction data between itself and other communication nodes in the encrypted communication system of the vehicle network. For example, the second communication node estimates the latency and BER of the current communication based on historical interaction data using a sliding window algorithm. The size of the sliding window can be set as needed; for example, if the sliding window size is 5, the latency and BER of the current communication are estimated based on the latency and BER of the last 5 communications between the second communication node and other communication nodes. In the above embodiments, the channel monitoring module uses the sliding window method to estimate the latency and BER of the current communication based on historical interaction data. This method saves storage and computing resources, adapts to channel changes in real time and dynamically, effectively resists sudden interference, stabilizes output results, and captures channel quality change trends by comprehensively analyzing the data within the window. This efficiently supports channel status judgment and improves the accuracy of the determined latency and BER of the current communication.

[0100] The preset latency and preset bit error rate can be set as needed. For example, the preset latency can be set to 45 milliseconds (ms), and the preset bit error rate can be set to 0.1%. This application does not limit the magnitude of the preset latency and preset bit error rate.

[0101] The communication mode switching component is used to switch the communication mode between the first communication node and the second communication node based on communication latency and bit error rate. Specifically, when the communication latency is greater than a preset latency or the bit error rate is greater than a preset bit error rate, the communication mode between the first communication node and the second communication node is set to quantum-resistant mode; when the communication latency is less than a preset latency or the bit error rate is less than a preset bit error rate, the communication mode between the first communication node and the second communication node is set to standby mode.

[0102] In some embodiments, the communication mode switching component includes a communication mode switching module, through which the second communication node performs communication mode switching. In some embodiments, the communication mode switching component is further configured with an ML-KEM / ML-DSA algorithm module and an ECC-256 algorithm module. These modules can be software or hardware modules. When the three algorithm modules are software modules, the communication mode switching component performs communication mode switching by switching the algorithm module invoked by the communication mode switching module. When these two algorithm modules are hardware modules, the communication mode switching component performs communication mode switching by switching the algorithm module connected to the communication mode switching module.

[0103] In some embodiments, the communication mode switching component and the channel monitoring module are two components in the second communication node. In other embodiments, the communication mode switching component integrates the channel monitoring module, that is, the communication mode switching component includes the channel monitoring module. This application does not limit this aspect.

[0104] In some embodiments, sending a first negotiation notification to a first communication node via a communication mode switching component includes: determining, via the communication mode switching component, that the communication mode corresponding to the communication delay and bit error rate is a quantum-resistant mode; generating the first negotiation notification corresponding to the quantum-resistant mode via the communication mode switching component; and sending the first negotiation notification to the first communication node. It should be noted that the above description of the generation and sending process of the first negotiation notification is merely exemplary, and this application does not limit the scope of the embodiments.

[0105] This application does not limit the manner in which the first negotiation notification indicates the quantum resistance mode. Those skilled in the art can set the manner in which the first negotiation notification indicates the quantum resistance mode according to actual needs. For example, it can indicate the mode by adding an identifier for the quantum resistance mode to the first negotiation notification, or by adding a communication mode field to the first negotiation notification and setting that communication mode field to a first value. This application does not limit this approach.

[0106] In step 202 above, the first communication node and the second communication node initiate quantum-resistant session key negotiation only if the communication link quality meets the standard. This avoids key negotiation process timeout failure due to excessive link latency or transmission errors of negotiation information due to excessive bit error rate, ensuring the success rate and effectiveness of quantum-resistant key negotiation. It also prevents the forced initiation of complex quantum-resistant negotiation process when the link is unstable, reducing ineffective computing power consumption and communication resource waste. At the same time, it ensures that subsequent secure sessions established based on quantum-resistant mode can achieve stable and secure data interaction by relying on high-quality links.

[0107] It should be noted that step 202 above is illustrated using the case where the communication latency is less than a preset latency and the bit error rate is less than a preset bit error rate. In some embodiments, the estimated latency for the second communication node to receive the first session notification is greater than the preset latency or the bit error rate is greater than the preset bit error rate. In this case, the second communication node sends a second negotiation notification to the first communication node through the communication mode switching component. This second negotiation notification is used to instruct the first communication node to negotiate the session key through the standby mode. This process is similar to step 301 below and will be described in step 301, so it will not be repeated here.

[0108] It should be noted that steps 201 and 202 above are optional steps. In some embodiments, the first communication node directly encrypts and signs the first session establishment request using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm through a quantum-resistant component, and sends the encrypted and signed first session establishment request to the second communication node, without performing the sending of the first session notification and the generation and sending of the first negotiation notification as shown in steps 201 and 202 above. This application embodiment does not limit this.

[0109] Step 203: The first communication node receives the first negotiation notification, and through the quantum-resistant component, uses a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm to encrypt and sign the first session establishment request, and sends the encrypted and signed first session establishment request to the second communication node.

[0110] The first session establishment request includes a first session key and first session identification information. The first session key is a temporary key specifically generated for this session and is used to encrypt subsequent data transmitted during this session. The first session identification information is used to identify this session; for example, the first session identification information includes a session identifier and a timestamp.

[0111] The encryption and signing of the first session establishment request using quantum-resistant encryption and signature algorithms refers to: encrypting the first session key using a quantum-resistant encryption algorithm to obtain first ciphertext; and signing the first session key and the first session identification information using a quantum-resistant signature algorithm to obtain a first signature. The encrypted and signed first session establishment request includes the first ciphertext and the first signature. Encrypting the first session key using a quantum-resistant algorithm is essentially encapsulating the first session key. The first signature is used to verify the identity of the first communication node.

[0112] Specifically, encrypting the first session key using a quantum-resistant encryption algorithm to obtain the first ciphertext includes: randomly generating a first public key, a first private key, and a first session key for the first communication node using a quantum-resistant encryption algorithm; and encrypting the first session key using the public key of the second communication node pre-stored by the first communication node, employing a quantum-resistant encryption algorithm to obtain the first ciphertext. Signing the first session key and the first session identification information using a quantum-resistant signature algorithm to obtain the first signature includes: using the first private key of the first communication node, and employing a quantum-resistant signature algorithm to sign the first session key and the first session identification information to obtain the first signature.

[0113] In one possible implementation, the quantum-resistant component is configured with a quantum-resistant key encapsulation module and a quantum-resistant signature module; the first communication node is used to: encrypt the first session key in the first session establishment request using the ML-KEM algorithm through the quantum-resistant key encapsulation module in the quantum-resistant component to generate a first ciphertext; and sign the first session key and the first session identification information in the first session establishment request using the ML-DSA algorithm through the quantum-resistant signature module in the quantum-resistant component to generate a first signature. In the above embodiments, the first session key is encrypted by the quantum-resistant key encapsulation module of the quantum-resistant component to generate the first ciphertext. Then, the first session key and the first session identification information are jointly signed by the quantum-resistant signature module to generate the first signature. This not only relies on the NIST-standardized quantum-resistant algorithm to resist the risk of quantum computing cracking and ensure long-term security in a quantum environment, but also ensures the confidentiality of the session by ensuring that the first session key can only be decrypted by the legitimate recipient through the ML-KEM algorithm. The ML-DSA algorithm simultaneously verifies the sender's identity and the integrity of key information, effectively preventing impersonation, tampering, and session confusion, and achieving dual security protection for key transmission and identity verification. At the same time, completing two operations in a single request can reduce the number of communication interactions and adapt to the needs of efficient and highly secure communication in scenarios such as vehicle networking. It should be noted that the above embodiment is an implementation method in which the session key is encrypted and ciphertext is generated by using the modular key encapsulation algorithm ML-KEM in the anti-quantum component's anti-quantum key encapsulation module; and the signature is generated by using the modular digital signature algorithm ML-DSA in the anti-quantum component's anti-quantum signature module. In some embodiments, the process is also implemented based on other methods, which are not limited in this application embodiment.

[0114] In some embodiments, the first communication node is an on-board unit (OIN). The OIN is configured with a quantum-resistant key encapsulation module and a quantum-resistant signature module by deeply integrating the ML-KEM and ML-DSA algorithms into the OIN's AUTOSAR communication stack and supporting the PQC extension field of the IEEE 1609.2 standard certificate format. In the above embodiments, the existing V2X communication protocol stack can be seamlessly upgraded to a quantum-resistant form, solving the problem in related technologies where OINs do not have pre-reserved compatibility interfaces for quantum-resistant algorithms, and improving the compatibility of encrypted communication systems in vehicle networks.

[0115] In one possible implementation, the quantum-resistant component is further configured with a polynomial operation module, which includes multiple computational units adapted to perform parallel computation of multiple coefficients of a sparse polynomial ring. The first communication node is used to: execute the ML-KEM algorithm on the quantum-resistant key encapsulation module through the polynomial operation module in the quantum-resistant component to encrypt the first session key in the first session establishment request, generating a first ciphertext; and execute the ML-DSA algorithm on the quantum-resistant signature module through the polynomial operation module in the quantum-resistant component to sign the first session key and the first session identification information in the first session establishment request, generating a first signature. Here, the sparse polynomial ring refers to the core mathematical structure of the quantum-resistant encryption algorithm and the quantum-resistant signature algorithm, where most coefficients are 0. For example, the sparse polynomial ring is Rq = Zq[X] / (Xn+1). The parallel computation of multiple coefficients of the sparse polynomial ring by multiple computational units means that multiple computational units can simultaneously perform computations on different coefficients in the sparse polynomial ring, rather than processing them sequentially, thereby matching the characteristics of the mathematical structure and improving computational efficiency. In the above embodiments, parallel computation of sparse polynomial ring coefficients by multiple computational units of the polynomial operation module can significantly improve the computational efficiency of the ML-KEM key encapsulation algorithm and the ML-DSA signature algorithm, solving the processing latency problem caused by the computational complexity of quantum-resistant algorithms. This is suitable for scenarios with high real-time requirements, such as vehicle-to-everything (V2X) networks, while also ensuring quantum-resistant security. Furthermore, it supports complex polynomial operations of quantum-resistant algorithms with limited computing power, addressing the problem in related technologies where V2X hardware cannot support complex mathematical operations such as lattice cryptography and modular lattices. It should be noted that the above embodiments are one implementation method where the polynomial operation module in the quantum-resistant component executes the ML-KEM algorithm on the quantum-resistant key encapsulation module to encrypt the session key and generate ciphertext; and the polynomial operation module in the quantum-resistant component executes the ML-DSA algorithm on the quantum-resistant signature module to generate a signature. In some embodiments, this process is also implemented based on other methods, which are not limited in this application.

[0116] In one possible implementation, the first communication node is further configured with a quantum-resistant algorithm instruction set, which includes multiple hardware instructions for executing the quantum-resistant algorithm. The first communication node is used to: invoke at least one hardware instruction from the quantum-resistant algorithm instruction set through the polynomial operation module in the quantum-resistant component to execute the ML-KEM algorithm, encrypt the first session key in the first session establishment request, and generate a first ciphertext; and invoke at least one hardware instruction from the quantum-resistant algorithm instruction set through the polynomial operation module in the quantum-resistant component to execute the ML-DSA algorithm, sign the first session key and the first session identifier information in the first session establishment request, and generate a first signature. Exemplarily, the quantum-resistant algorithm instruction set includes number-theoretic transform (NTT) instructions, Barrett modulo reduction instructions, and other computational instructions related to the quantum-resistant algorithm. In the above embodiments, the dedicated hardware instructions provided by the quantum-resistant algorithm instruction set, combined with the parallel computing capabilities of the polynomial operation module, can further accelerate the execution efficiency of ML-KEM encryption and ML-DSA signature. Furthermore, the hardware instructions directly correspond to the core operations of the quantum-resistant algorithm, reducing software-level instruction conversion overhead and forming a synergistic acceleration with the parallel computing unit. While ensuring quantum-resistant security, this significantly reduces algorithm runtime latency, making it more suitable for scenarios with stringent real-time requirements, such as vehicle-to-everything (V2X) networks. The above embodiments are one implementation method whereby the polynomial operation module in the quantum-resistant component calls at least one hardware instruction from the quantum-resistant algorithm instruction set to execute the ML-KEM algorithm, encrypt the session key, and generate ciphertext; and the polynomial operation module in the quantum-resistant component calls at least one hardware instruction from the quantum-resistant algorithm instruction set to execute the ML-DSA algorithm to generate a signature. In some embodiments, this process is also implemented in other ways, which are not limited in this application.

[0117] Step 204: The second communication node verifies and decrypts the encrypted and signed first session establishment request using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. After successful signature verification and decryption, the second communication node sends a response to the first session establishment request to the first communication node to establish a secure quantum-resistant session between the first and second communication nodes.

[0118] As described in step 203 above, the first session establishment request after encryption and signing includes a first ciphertext and a first signature. The second communication node performs signature verification and decryption of the first session establishment request after encryption and signing using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. This means: using a quantum-resistant signature algorithm to verify the first signature, and after the signature verification is successful, using a quantum-resistant encryption algorithm to decrypt the first ciphertext to obtain the first session key.

[0119] Specifically, verifying the first signature using a quantum-resistant signature algorithm includes: the second communication node using the pre-stored public key of the first communication node, employing the quantum-resistant signature algorithm, to generate a first verification signature; if the first verification signature matches the first signature, the first signature verification passes; if the first verification signature does not match the first signature, the first signature verification fails. Decrypting the first ciphertext using a quantum-resistant encryption algorithm includes: the second communication node using its private key, employing the quantum-resistant encryption algorithm, to decrypt the first ciphertext and obtain the first session key. It should be noted that if the first signature verification fails, the second communication node rejects the first session establishment request and does not perform decryption of the first ciphertext, thus conserving the computational resources of the second communication node.

[0120] In this context, "signature verification and decryption pass" means that the first verification signature generated by the second communication node is consistent with the first signature and the first session key is successfully decrypted from the first ciphertext.

[0121] The response to the first session establishment request is used to inform the first communication node that signature verification and ciphertext decryption have been successful, the first session key has been synchronized, and to authorize the initiation of a formal secure session based on the first session key, thus completing the two-way confirmation of the establishment of a secure session in quantum-resistant mode. The response to the first communication node includes: the second communication node encrypting the response using the first session key and sending the encrypted response to the first communication node.

[0122] Establishing a secure quantum-resistant session between the first and second communication nodes refers to establishing a session based on a first session key. This means that all subsequent data interactions within this session will be encrypted using the first session key, and the integrity and authenticity of the data will also be verified using this key to ensure that the communication content is not leaked, tampered with, or forged. For example, this first session key can be used to encrypt and verify the integrity and authenticity of interactive data such as real-time traffic data or collaborative obstacle avoidance commands.

[0123] In step 204 above, the characteristics of quantum-resistant encryption algorithms can be used to resist the risk of quantum computing breaking traditional encryption systems, ensuring the absolute security of the first session key during transmission and verification, and avoiding key leakage, information tampering, or identity forgery. At the same time, a closed-loop process of verifying identity and information legitimacy, decrypting to obtain the first session key, and sending a response can be completed to ensure that the first communication node and the second communication node achieve synchronous recognition of the session key. Finally, a stable and secure dedicated communication session under quantum-resistant mode is efficiently established, laying a solid quantum-resistant security foundation for the encrypted transmission of all business data between the two parties, while avoiding communication interruption or security risks caused by verification failure or asynchronous session keys.

[0124] Step 205: The first communication node and the second communication node communicate based on Lightweight Message Authentication Code (MAC).

[0125] Lightweight MAC refers to a MAC that has significantly lower computational complexity and resource consumption (such as memory, computing power, and energy consumption) than heavy-duty authentication mechanisms (such as digital signatures), and can be adapted to devices with limited computing power (such as communication nodes in vehicle networks).

[0126] The communication between the first and second communication nodes based on a lightweight MAC means that during data interaction, each communication node generates and carries a lightweight MAC for each transmitted session request (e.g., business data or session instructions). Both parties verify the lightweight MAC attached to the received session request using a pre-agreed first session key. If the verification passes, the session request is considered legitimate; if it fails, the session request is deemed tampered with or originates from an illegal source, and the request is rejected. The process of the sender generating the lightweight MAC includes: the sender uses the first session key and a lightweight MAC algorithm to generate the MAC for the session request to be sent, and sends this MAC along with the session request to the receiver; upon receiving the session request, the receiver recalculates the MAC using the same first session key and lightweight MAC algorithm. If the calculated MAC matches the MAC carried in the session request, the MAC verification is successful; if the calculated MAC does not match the MAC carried in the session request, the MAC verification fails.

[0127] In some embodiments, the lightweight MAC supports a 64-byte CAN FD frame length extension, which makes the MAC verification latency <10μs, thereby reducing the overall communication latency.

[0128] In step 205 above, the lightweight message authentication code (MAC) can quickly verify the integrity and legitimacy of the session request with low computing power and low bandwidth consumption. It can prevent the session request from being tampered with or forged, adapt to resource-constrained devices such as communication nodes in the Internet of Vehicles, and is also compatible with quantum-safe sessions, thus strengthening real-time security for subsequent data interaction.

[0129] It should be noted that step 205 above is an optional step. In some embodiments, step 206 is not performed, and this application embodiment does not limit this.

[0130] In some embodiments, the method further includes: when the secure session between the first communication node and the second communication node is in quantum-resistant mode, the first communication node and the second communication node update the session key in quantum-resistant mode based on a first update cycle. The first update cycle is longer than the second update cycle, and the second update cycle is the session key update cycle when the secure session between the first communication node and the second communication node is in standby mode. In the above embodiments, the session key update cycles of quantum-resistant mode and standby mode are set differently, which not only ensures the stability and efficiency of secure sessions in quantum-resistant mode, but also strengthens the security and risk response capabilities of standby mode; moreover, quantum-resistant mode itself has high security against quantum computing cracking, and setting its key update cycle (first update cycle) to be longer can reduce the communication interaction cost and computing power consumption caused by frequent key updates, and avoid the interference of frequent key negotiation on session stability; while the security of standby mode is usually weaker than that of quantum-resistant mode, setting its key update cycle (second update cycle) to be shorter can reduce the risk of leakage and cracking that may be faced by long-term key use through more frequent key iteration, thereby achieving a balance between the high efficiency and stability of quantum-resistant mode and the security backup of standby mode, taking into account the core needs of different security modes.

[0131] In some embodiments, the method further includes: a first update cycle determined based on real-time traffic flow density and a first security factor; the first security factor indicating communication security under quantum-resistant mode. In some embodiments, the real-time traffic flow density is collected in real time by a second communication node. Exemplarily, the first update cycle can be determined based on the following formula (1).

[0132] T1=s1×ρ-1 (1)

[0133] In the above formula (1), T1 represents the first update cycle, s1 represents the first safety factor, and ρ represents the real-time traffic flow density.

[0134] In the above embodiments, real-time traffic flow density can reflect the complexity of the communication environment and potential attack risks, and the first security factor can quantify the security level of the quantum-resistant mode itself. The first update cycle is determined based on the real-time traffic flow density and the first security factor, and the update frequency is dynamically adjusted. This avoids the risk of key exposure due to slow updates when traffic flow is dense and risk is high, and also prevents resource waste due to excessive updates when traffic flow is sparse and risk is low. While ensuring quantum-resistant communication security, it achieves a balance between the flexibility of key management and the efficiency of resource utilization, making the session key update cycle in the quantum-resistant mode more in line with actual security needs.

[0135] Through steps 201 to 205 above, the first and second communication nodes initiate quantum-resistant session key negotiation only when the communication link quality meets the standards. This avoids key negotiation failures due to excessive link latency or errors in the transmission of negotiated information due to excessive bit error rate, ensuring the success rate and effectiveness of quantum-resistant key negotiation. It also prevents the forced initiation of complex quantum-resistant negotiation processes when the link is unstable, reducing unnecessary computing power consumption and communication resource waste. Simultaneously, it ensures that subsequent secure sessions established based on quantum-resistant mode can achieve stable and secure data interaction relying on a high-quality link. Furthermore, the first session request is encrypted using a quantum-resistant encryption algorithm. The quantum signature algorithm signs the first session request, which not only relies on the NIST-standardized quantum-resistant algorithm to resist the risk of quantum computing cracking and ensure long-term security in a quantum environment, but also completes two operations in a single request, reducing the number of communication interactions and adapting to the needs of efficient and highly secure communication in scenarios such as vehicle-to-everything (V2X) communication. In addition, after the secure session is established, communication is based on lightweight MAC, which can quickly verify the integrity and legitimacy of the session request with low computing power and low bandwidth consumption, preventing the session request from being tampered with or forged. It is suitable for resource-constrained devices such as communication nodes in V2X, and is also compatible with quantum-resistant secure sessions, strengthening real-time security for subsequent data interactions.

[0136] The above Figure 2 The illustrated embodiment describes the process of establishing a quantum-resistant communication connection between the first and second communication nodes. The process of switching from quantum-resistant mode to standby mode is described below. Figure 3 This is a flowchart illustrating the switching of a secure session between a first communication node and a second communication node from quantum-resistant mode to a standby mode in an encrypted communication method for a vehicle network provided in this application embodiment. Figure 3 As shown, this process is applied to the above-mentioned encrypted communication system, and the process includes the following steps 301 to 303.

[0137] Step 301: When the communication delay is greater than the preset delay or the bit error rate is greater than the preset bit error rate, the second communication node sends a second negotiation notification to the first communication node through the communication mode switching component. The second negotiation notification is used to instruct the first communication node to negotiate the session key through the backup mode. The backup mode refers to using asymmetric encryption algorithm and asymmetric signature algorithm for encryption and signing.

[0138] It should be noted that the process shown in step 301 above is performed after a secure session against quantum mode has been established between the first communication node and the second communication node.

[0139] The process by which the second communication node determines the communication delay and bit error rate is the same as the process in step 202 above, and will not be repeated here.

[0140] The settings for preset delay and preset bit error rate are the same as those in step 202 above, and will not be repeated here.

[0141] The asymmetric encryption algorithm can be: Rivest-Shamir-Adleman (RSA) algorithm, Elliptic Curve Cryptography (ECC) algorithm, Diffie-Hellman key exchange algorithm, or Elliptic Curve Diffie-Hellman key exchange algorithm; the asymmetric signature algorithm can be RSA signature algorithm or Elliptic Curve Digital Signature Algorithm (ECDSA), and this application embodiment does not limit the specific algorithm.

[0142] The process of the second communication node sending the second negotiation notification to the first communication node through the communication mode switching component is the same as the process of the second communication node sending the first negotiation notification to the first communication node through the communication mode switching component in step 202 above, and will not be repeated here.

[0143] This application does not limit the manner in which the second negotiation notification indicates the standby mode. Those skilled in the art can set the manner in which the second negotiation notification indicates the standby mode according to actual needs. For example, it can indicate the standby mode by adding an identifier to the second negotiation notification, or by adding a communication mode field to the second negotiation notification and setting that communication mode field to a second value. This application does not limit this approach.

[0144] Step 302: The first communication node receives the second negotiation notification, and through the quantum-resistant component, uses an asymmetric encryption algorithm and an asymmetric signature algorithm to encrypt and sign the second session establishment request, and sends the encrypted and signed second session establishment request to the second communication node.

[0145] The second session establishment request includes a second session key and second session identification information. The second session key is a temporary key specifically generated for this session and used to encrypt subsequent data transmitted during this session. The second session identification information is used to identify this session; for example, the second session identification information includes a session identifier and a timestamp.

[0146] The encryption and signing of the second session establishment request using asymmetric encryption and signature algorithms refers to: encrypting the second session key using an asymmetric encryption algorithm to obtain a second ciphertext; and signing the second session key and the second session identification information using an asymmetric signature algorithm to obtain a second signature. The encrypted and signed second session establishment request includes both the second ciphertext and the second signature. Encrypting the second session key using an asymmetric algorithm is essentially encapsulating the second session key. The second signature is used to verify the identity of the second communication node.

[0147] Specifically, encrypting the second session key using an asymmetric encryption algorithm to obtain the second ciphertext includes: randomly generating a second public key, a second private key, and a second session key for the second communication node using an asymmetric encryption algorithm; and encrypting the second session key using the public key pre-stored by the second communication node, employing an asymmetric encryption algorithm to obtain the second ciphertext. Signing the second session key and the second session identification information using an asymmetric signature algorithm to obtain the second signature includes: using the second private key of the second communication node, and employing an asymmetric signature algorithm to sign the second session key and the second session identification information to obtain the second signature.

[0148] Step 303: The second communication node performs signature verification and decryption using an asymmetric signature algorithm and an asymmetric encryption algorithm. After the signature verification and decryption are successful, it sends a response to the second session establishment request to the first communication node to establish a secure session in backup mode between the first and second communication nodes.

[0149] As described in step 302 above, the encrypted and signed second session establishment request includes a second ciphertext and a second signature. The second communication node performs signature verification and decryption of the encrypted and signed second session establishment request using an asymmetric encryption algorithm, which means: using an asymmetric signature algorithm to verify the second signature, and after the signature verification is successful, using an asymmetric encryption algorithm to decrypt the second ciphertext to obtain the second session key.

[0150] Specifically, verifying the second signature using an asymmetric signature algorithm includes: the second communication node using its pre-stored public key and an asymmetric signature algorithm to generate a second verification signature; if the second verification signature matches the second signature, the second signature verification passes; if the second verification signature does not match the second signature, the second signature verification fails. Decrypting the second ciphertext using an asymmetric encryption algorithm includes: the second communication node using its private key and an asymmetric encryption algorithm to decrypt the second ciphertext to obtain the second session key. It should be noted that if the second signature verification fails, the second communication node rejects the second session establishment request and does not perform decryption of the second ciphertext to conserve the second communication node's computing resources.

[0151] In this context, "signature verification and decryption pass" means that the second verification signature generated by the second communication node is consistent with the second signature and the second session key is successfully decrypted from the second ciphertext.

[0152] The response to the second session establishment request is used to inform the second communication node that signature verification and ciphertext decryption have been successful, the second session key has been synchronized, and to authorize the initiation of a formal secure session based on the second session key, completing the two-way confirmation of the establishment of a secure session in asymmetric mode. The response to the second communication node includes: the second communication node encrypting the response using the second session key and sending the encrypted response to the second communication node.

[0153] Establishing a secure asymmetric session between two second communication nodes means that the second communication nodes will subsequently conduct a session based on the second session key. In other words, all data interactions within this session will be encrypted based on the second session key, and the integrity and authenticity of the data will also be verified based on the second session key to ensure that the communication content is not leaked, tampered with, or forged.

[0154] In some embodiments, the method further includes: updating the key in the backup mode based on a second update cycle when the secure session between the first communication node and the second communication node is in standby mode. The second update cycle is shorter than the first update cycle, where the first update cycle is the session key update cycle when the secure session between the first communication node and the second communication node is in quantum-resistant mode. In the above embodiments, the session key update cycles of the quantum-resistant mode and the backup mode are set differently, which not only ensures the stability and efficiency of the secure session in the quantum-resistant mode, but also strengthens the security and risk response capabilities of the backup mode. Furthermore, the quantum-resistant mode itself has high security against quantum computing cracking. Setting its key update cycle (first update cycle) to be longer can reduce the communication interaction cost and computing power consumption caused by frequent key updates, and avoid the interference of frequent key negotiation on session stability. On the other hand, the security of the backup mode is usually weaker than that of the quantum-resistant mode. Setting its key update cycle (second update cycle) to be shorter can reduce the risk of leakage and cracking that may be faced by long-term key use through more frequent key iterations. Thus, a balance is achieved between the high efficiency and stability of the quantum-resistant mode and the security backup of the backup mode, taking into account the core needs of different security modes.

[0155] In some embodiments, the method further includes: determining the second update cycle based on real-time traffic flow density and a second safety factor; the second safety factor indicates communication security in standby mode. In some embodiments, the real-time traffic flow density is collected in real time by a second communication node. Exemplarily, the second update cycle can be determined based on the following formula (2).

[0156] T2=s2×ρ-1 (2)

[0157] In the above formula (2), T2 represents the second update cycle, s2 represents the second safety factor, and ρ represents the real-time traffic flow density.

[0158] In the above embodiments, real-time traffic flow density can reflect the complexity of the communication environment and potential attack risks, and the second security factor can quantify the security level of the quantum-resistant mode itself. The second update cycle is determined based on the real-time traffic flow density and the second security factor, and the update frequency is dynamically adjusted. For example, the session key update frequency is reduced by 60% in congested scenarios. This avoids the risk of key exposure due to slow updates when traffic flow is dense and risk is high, and also prevents resource waste due to excessive updates when traffic flow is sparse and risk is low. While ensuring quantum-resistant communication security, it achieves a balance between the flexibility of key management and the efficiency of resource utilization, making the session key update cycle in the quantum-resistant mode more in line with actual security needs.

[0159] It should be noted that steps 301 to 303 above are one way to switch the secure session between the first and second communication nodes from the quantum-resistant mode to the standby mode by means of a communication mode switching component when the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions of the quantum-resistant communication. In some embodiments, this process is also implemented in other ways, and this application does not limit this.

[0160] Through steps 301 to 303 above, when the communication link quality (latency, bit error rate) is substandard, the availability and continuity of session key negotiation can be ensured by switching to backup mode. When the link latency is too high or the bit error rate exceeds the standard, if the more complex negotiation process and the higher requirements for link stability are forcibly used in the quantum-resistant mode, it is easy to cause negotiation timeout failure or information transmission errors. The backup mode, which has a simpler process and higher tolerance for the link, can reduce the dependence on link quality, ensure that key negotiation can be completed smoothly, and avoid interruption of secure session establishment due to link problems. At the same time, this logic of automatically switching to backup when the link deteriorates can also reduce the ineffective computing power and communication resource consumption of the quantum-resistant mode on low-quality links, and achieve flexible backup between security and business continuity, ensuring that both ends of the node can always establish a basic secure session by adapting to the current link mode, and avoid communication interruption.

[0161] The following describes the process of switching the communication mode of the first and second communication nodes from standby mode to quantum-resistant mode. Figure 4 This is a flowchart illustrating the switching of the communication mode of the first and second communication nodes from a standby mode to a quantum-resistant mode in an encrypted communication method for a vehicle network provided in this application embodiment. Figure 4 As shown, the process includes the following steps 401 to 404.

[0162] Step 401: When the delay is less than the preset delay and the bit error rate is less than the preset bit error rate, the second communication node sends a third negotiation notification to the first communication node through the communication mode switching component. The third negotiation notification is used to instruct the first communication node to negotiate the session key through the quantum-resistant mode.

[0163] It should be noted that step 401 above is performed after a secure session in backup mode has been established between the first communication node and the second communication node.

[0164] Step 401 is the same as step 202 above, and will not be repeated here.

[0165] Step 402: The first communication node receives the third negotiation notification, and through the quantum-resistant component, uses a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm to encrypt and sign the third session establishment request, and sends the encrypted and signed third session establishment request to the second communication node.

[0166] Step 402 is the same as step 203 above, and will not be repeated here.

[0167] Step 403: The second communication node performs signature verification and decryption using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. After successful signature verification and decryption, it sends a response to the first communication node requesting a third session establishment, thereby establishing a secure quantum-resistant session between the first and second communication nodes.

[0168] This step is the same as step 204 above, and will not be repeated here.

[0169] Step 404: The first communication node and the second communication node synchronize and update their respective key recovery calculators.

[0170] The first and second communication nodes are each equipped with their own key recovery calculators. These calculators store the number of times the session key has been updated and the key state in quantum-resistant mode.

[0171] In step 404 above, the key state consistency and validity are ensured by synchronously updating the key recovery calculators of the first and second communication nodes, replay attacks are avoided, and the stability of secure sessions in quantum-resistant mode is further enhanced.

[0172] It should be noted that step 404 above is an optional step. In some embodiments, step 404 is not performed, and this application embodiment does not limit this.

[0173] It should be noted that steps 401 to 404 above are one implementation of switching the secure session between the first communication node and the second communication node from the standby mode to the quantum-resistant mode through the communication mode switching component when the communication latency and bit error rate of the secure session in the standby mode meet the latency and bit error rate conditions of quantum-resistant communication. In some embodiments, this process is also implemented in other ways, and this application does not limit it.

[0174] Through steps 401 to 404 above, the switching mechanism between backup mode and quantum-resistant mode achieves an optimal balance between communication availability and security, ensuring business continuity while maximizing security protection levels: when link quality is substandard, backup mode ensures uninterrupted secure sessions with lower link requirements, avoiding negotiation failures or communication interruptions caused by forcibly enabling quantum-resistant mode (which has higher requirements for latency and bit error rate); while when link latency and bit error rate meet the conditions for quantum-resistant communication, the communication mode switching component automatically upgrades to quantum-resistant mode, which can improve the protection capability of secure sessions from the basic level to a high level that can resist quantum computing threats, effectively protecting the security of sensitive data transmission, while avoiding the ineffective computing power and bandwidth consumption of quantum-resistant mode on low-quality links, allowing security resources to be precisely matched with link conditions, and ultimately achieving efficient communication assurance with optimal security when the link meets the standards and uninterrupted service when the link deteriorates.

[0175] It should be noted that the above Figure 2 , Figure 3 and Figure 4 The present application describes different processes of an encrypted communication method in a vehicle network provided by the embodiments of the present application in the form of three embodiments. It does not mean that the above three embodiments are independent of each other. In some embodiments, the above three embodiments can be combined and implemented as needed. The present application does not limit the embodiments.

[0176] The following is through Figure 5 Regarding the above Figure 2 , Figure 3 and Figure 4 The process shown is illustrated with an example. Figure 5 This is a flowchart illustrating an encrypted communication method in a vehicle-to-everything (V2X) network provided in an embodiment of this application. Figure 5 As shown, Figure 5 This demonstrates the session key exchange process between the On-Board Unit (OBU) and the Roadside Unit (RSU) in quantum-resistant mode. The latency requirement for this process is <50ms, as specified in Road Vehicles—Cybersecurity Engineering (ISO) 21434. The specific steps are as follows:

[0177] ① Session Initiation (corresponding to step 201 above): The OBU sends a first session notification to the RSU, which includes the OBU's identity and current communication environment parameters (such as vehicle speed and signal strength).

[0178] ② Delay judgment (corresponding to step 202 above): The RSU estimates the delay of this communication based on historical interaction data and compares it with the threshold T (45ms): If the estimated delay ≤ T1 (satisfies real-time requirements), the PQC key negotiation process (that is, the session key negotiation in quantum-resistant mode) is entered (corresponding to step 202 above); if the estimated delay > T1 (insufficient real-time requirements), the degradation mechanism is triggered.

[0179] ③PQC key encapsulation (corresponding to step 203 above): The OBU's quantum-resistant key encapsulation module (ML-KEM) generates a random private key and a corresponding public key, and uses the RSU's pre-stored public key to encapsulate (encrypt) the session key K to generate ciphertext C, while attaching an ML-DSA signature Sig (used to verify the OBU's identity).

[0180] ④ Signature verification (corresponding to step 204 above): The RSU receives the ciphertext C and the signature Sig, and verifies the legality of Sig using the ML-DSA verification algorithm: if the verification is successful: perform ML-KEM decapsulation and restore the session key K; if the verification fails: reject the session request (process terminates).

[0181] ⑤ Session establishment (corresponding to step 204 above): The RSU uses the recovered session key K to encrypt the response message and sends the response message back to the OBU. Both parties establish a secure session based on K for subsequent V2X data transmission (such as real-time traffic conditions and cooperative obstacle avoidance commands).

[0182] ⑥ Downgrade trigger (corresponding to step 301 above): If the delay limit is exceeded in step ②, the RSU sends a downgrade notification (i.e., the second negotiation notification) to the OBU and simultaneously activates the ECC-256 backup algorithm (i.e., switches to backup mode; ECC-256 is an asymmetric encryption algorithm and an asymmetric signature algorithm).

[0183] ⑦ ECC key negotiation (corresponding to steps 302 to 303 above): OBU and RSU complete key exchange through the ECC-256 algorithm (e.g., encryption based on the normalized elliptic curve (secp256r1 curve) in ECC-256), generate a backup session key (i.e., the second session key) K', and at the same time perform identity authentication through ECDSA signature (obtained by signing based on the ECC-256 algorithm).

[0184] ⑧ Degradation session establishment (corresponding to step 303 above): Both parties establish a temporary secure session based on K'. The RSU records the degradation event and continuously monitors the channel status. After the conditions are met (delay ≤ T and BER ≤ 0.1%), the PQC session (quantum-resistant secure session) is re-initiated in the same way as step 201 above (corresponding to steps 401 to 403 above).

[0185] ⑨ Restore synchronization (corresponding to step 404 above): After the downgrade state is lifted (after switching from standby mode to quantum-resistant mode), the OBU and RSU synchronize and update the key recovery counter (to prevent replay attacks) to ensure that the key state of the PQC logical channel and the ECC logical channel of the OBU and RSU are consistent.

[0186] In step ② above, the latency estimation adopts a sliding window algorithm (window size = 5 historical interactions) to improve the accuracy of judgment. In the degraded state (corresponding to steps ⑥-⑧ above), RSU will reduce the key update cycle (for example, from the default 30s to 10s) to make up for the lack of quantum resistance in communication in ECC backup mode. The total latency of the entire process (latency of steps ①-⑤ or latency of steps ①-② and steps ⑥-⑧) is controlled within 50ms, which meets the automotive-grade real-time requirements.

[0187] It should be noted that the above Figure 5 The process shown is merely exemplary and does not limit the embodiments of this application.

[0188] The above Figure 2 , Figure 3 and Figure 4 The encrypted communication method for vehicular networks provided by the illustrated embodiment achieves NIST L3 security level resistance to quantum computing attacks in terms of security. In terms of real-time performance, the key negotiation latency for encrypted communication in vehicular networks is <50ms (meeting the ISO 21434 standard). In terms of compatibility, it supports seamless upgrades to existing V2X communication protocol stacks. Specifically, the encrypted communication method for vehicular networks employs a hybrid cryptographic system. Forward secure key negotiation uses the NIST standard quantum-resistant algorithm ML-KEM, achieving IND-CCA2 security through the LWE problem on lattices. Key encapsulation efficiency is 40% higher than the traditional RSA-2048 algorithm. Signature uses a lightweight digital signature, integrating the ML-DSA algorithm, based on the Modular Lattice Short Integer Solution (SIS) problem. The signature length is only 2.5KB, meeting the FIPS 204 standard, and the verification speed is 3 times faster than the traditional ECDSA algorithm. Furthermore, instruction set optimization was performed, specifically by extending the PQC instruction set (such as polynomial multiplication ntt and modulo reduction barrett) in the chip core, reducing the single ML-KEM packaging time from 15ms to 8ms. Additionally, a SIMD parallel architecture was adopted, specifically a 128-bit SIMD computation unit was designed for the sparse polynomial ring Rq=Zq[X] / (Xn+1), achieving coefficient-level parallel computation with a throughput of 1.2Gbps. Moreover, a dynamic degradation mechanism was employed, using RSU to collect channel bit error rate (BER) and communication latency for real-time channel monitoring; when BER > 10... -3If the latency is greater than 45ms, a downgrade is triggered. Through the disaster recovery switching protocol, the system automatically switches to the preset ECC-256 backup logical channel and synchronously updates the quantum key recovery parameters to ensure communication continuity.

[0189] Figure 6 This is a structural block diagram of an encrypted communication device in a vehicle network provided in an embodiment of this application. The device is applied to a first communication node in the encrypted communication device of the vehicle network. The first communication node includes a quantum-resistant component. The device includes a sending module 601, a receiving module 602, and a switching module 603.

[0190] The sending module 601 is used to encrypt and sign the session establishment request using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm through a quantum-resistant component, and send the encrypted and signed session establishment request to a second communication node in the encrypted communication system. The second communication node includes a communication mode switching component.

[0191] The receiving module 602 is used to receive the response to the session establishment request sent by the second communication node, so as to establish a secure session against quantum mode between the first communication node and the second communication node.

[0192] The switching module 603 is used to establish a backup mode secure session between the first and second communication nodes through the quantum-resistant component when the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions of the quantum-resistant communication. The backup mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

[0193] In one possible implementation, the session establishment request includes a session key and session identification information; the quantum-resistant component is configured with a quantum-resistant key encapsulation module and a quantum-resistant signature module; the sending module 601 includes:

[0194] The encryption unit is used to encrypt and encapsulate the session key in the session establishment request using the Modular Key Encapsulation Algorithm (ML-KEM) through the quantum-resistant key encapsulation module in the quantum-resistant component, generating ciphertext.

[0195] The signature unit is used to sign the session key and session identifier information in the session establishment request using the modular digital signature algorithm ML-DSA through the quantum-resistant signature module in the quantum-resistant component, thereby generating a signature.

[0196] In one possible implementation, the quantum-resistant component is further configured with a polynomial operation module, which includes multiple computational units adapted for parallel computation of multiple coefficients of a sparse polynomial ring.

[0197] The encryption unit includes an encryption subunit, used for:

[0198] The ML-KEM algorithm on the quantum-resistant key encapsulation module is executed through the polynomial operation module in the quantum-resistant component to encrypt the session key in the session establishment request and generate ciphertext.

[0199] This signature unit includes a signature subunit, used for:

[0200] The polynomial operation module in the quantum-resistant component executes the ML-DSA algorithm on the quantum-resistant signature module to sign the session key and session identification information in the session establishment request, generating a signature.

[0201] In one possible implementation, the first communication node is also configured with a quantum-resistant algorithm instruction set, which includes multiple hardware instructions for executing the quantum-resistant algorithm.

[0202] This encryption subunit is used to call at least one hardware instruction from the quantum-resistant algorithm instruction set through the polynomial operation module in the quantum-resistant component, execute the ML-KEM algorithm, encrypt the session key in the session establishment request, and generate ciphertext;

[0203] This signature subunit is used to execute the ML-DSA algorithm by calling at least one hardware instruction from the quantum-resistant algorithm instruction set through the polynomial operation module in the quantum-resistant component, and to sign the session key and session identification information in the session establishment request to generate a signature.

[0204] In one possible implementation, the first communication node is configured with a key recovery counter, which indicates the number of key updates and the key state in quantum-resistant mode and standby mode; the device further includes a first update module for:

[0205] Whenever the second communication node switches the communication mode of the secure session between the first and second communication nodes from standby mode to quantum-resistant mode, the key recovery calculator configured on the first communication node is updated.

[0206] In one possible implementation, the device further includes a second update module for:

[0207] When the secure session between the first communication node and the second communication node is in quantum-resistant mode, the session key in quantum-resistant mode is updated based on the first update cycle.

[0208] When the secure session between the first communication node and the second communication node is in standby mode, the session key in standby mode is updated based on the second update cycle;

[0209] The second update cycle is shorter than the first update cycle.

[0210] In one possible implementation, the first update cycle is determined based on real-time traffic flow density and a first safety factor;

[0211] The second update cycle is determined based on real-time traffic flow density and a second safety factor.

[0212] The first security factor indicates the communication security in quantum-resistant mode, and the second security factor indicates the communication security in standby mode.

[0213] In one possible implementation, the device further includes a communication module for...

[0214] After establishing a secure quantum-resistant session between the first and second communication nodes, communication between the first and second communication nodes is based on a lightweight message authentication code (MAC).

[0215] In one possible implementation, the first communication node is any one of an on-board unit, a roadside unit, or a cloud platform; the second communication node is any one of an on-board unit, a roadside unit, and a cloud platform.

[0216] It should be noted that the encrypted communication device in the vehicle network provided in the above embodiments is only illustrated by the division of the above functional modules when performing the corresponding steps. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the encrypted communication device in the vehicle network provided in the above embodiments and the encrypted communication method embodiments in the vehicle network belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.

[0217] Figure 7 This is a structural block diagram of an encrypted communication device in a vehicle network provided in an embodiment of this application. The device is applied to the second communication node in the encrypted communication device of the vehicle network. The second communication node includes a communication mode switching component. The device includes a receiving module 701, a sending module 702 and a switching module 703.

[0218] The receiving module 701 is used to receive the encrypted and signed session establishment request sent by the first communication node. The session establishment request is obtained by the first communication node through a quantum-resistant component, using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm to encrypt and sign the session establishment request.

[0219] The sending module 702 is used to decrypt and verify the encrypted and signed session establishment request using a quantum-resistant signature algorithm and a quantum-resistant encryption algorithm. After the decryption and signature verification are successful, it sends a response to the session establishment request to the first communication node to establish a secure session in quantum-resistant mode between the first communication node and the second communication node.

[0220] The switching module 703 is used to switch the secure session between the first communication node and the second communication node from the quantum-resistant mode to the standby mode through the communication mode switching component when the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions of the quantum-resistant communication. The standby mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

[0221] In one possible implementation, the communication mode switching component includes a channel monitoring module for monitoring communication latency and bit error rate; the switching module 703 is used for:

[0222] The communication latency and bit error rate are monitored in real time through the channel monitoring module in the communication mode switching component;

[0223] When the communication delay of the secure session in quantum-resistant mode exceeds the preset delay or the bit error rate exceeds the preset bit error rate, a communication mode switching notification is sent to the first communication node through the communication mode switching component, so that the secure session between the first communication node and the second communication node switches from quantum-resistant mode to standby mode.

[0224] In one possible implementation, the switching module 703 is further configured to:

[0225] When the communication latency and bit error rate of the secure session in standby mode meet the latency and bit error rate conditions for quantum-resistant communication, the secure session between the first communication node and the second communication node is switched from standby mode to quantum-resistant mode through the communication mode switching component.

[0226] In one possible implementation, the second communication node is configured with a key recovery counter, which indicates the number of key updates and the key state in quantum-resistant mode and standby mode; the device also includes a first update module for:

[0227] Whenever the second communication node switches the communication mode of the secure session between the first and second communication nodes from standby mode to quantum-resistant mode, the key recovery calculator of the second communication node is updated.

[0228] In one possible implementation, the device further includes a second update module for:

[0229] When the secure session between the first communication node and the second communication node is in quantum-resistant mode, the session key in quantum-resistant mode is updated based on the first update cycle.

[0230] When the secure session between the first communication node and the second communication node is in standby mode, the session key in standby mode is updated based on the second update cycle;

[0231] The second update cycle is shorter than the first update cycle.

[0232] In one possible implementation, the first update cycle is determined based on real-time traffic flow density and a first safety factor;

[0233] The second update cycle is determined based on real-time traffic flow density and a second safety factor.

[0234] The first security factor indicates the communication security in quantum-resistant mode, and the second security factor indicates the communication security in standby mode.

[0235] In one possible implementation, the device further includes a communication module for:

[0236] After establishing a secure quantum-resistant session between the first and second communication nodes, communication between the first and second communication nodes is based on a lightweight message authentication code (MAC).

[0237] In one possible implementation, the first communication node is any one of an on-board unit, a roadside unit, or a cloud platform; the second communication node is any one of an on-board unit, a roadside unit, and a cloud platform.

[0238] It should be noted that the encrypted communication device in the vehicle network provided in the above embodiments is only illustrated by the division of the above functional modules when performing the corresponding steps. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the encrypted communication device in the vehicle network provided in the above embodiments and the encrypted communication method embodiments in the vehicle network belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.

[0239] This application also provides a computer-readable storage medium including program code, such as a memory including program code, which can be executed by the processor of the first or second communication node to complete the encrypted communication method in the vehicle network. Optionally, the computer-readable storage medium may be read-only memory (ROM), random access memory (RAM), compact-disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.

[0240] This application also provides a computer program product, including a computer program that, when executed by the processor of a first communication node or a second communication node, implements any of the encrypted communication methods in the Internet of Vehicles provided in this application.

[0241] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0242] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. An encrypted communication system for vehicle networking, characterized in that, The encrypted communication system includes a first communication node and a second communication node. The first communication node includes a quantum-resistant component, and the second communication node includes a communication mode switching component. The first communication node is configured to encrypt and sign the session establishment request using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm through the quantum-resistant component, and send the encrypted and signed session establishment request to the second communication node. The second communication node is used to verify and decrypt the encrypted and signed session establishment request using the quantum-resistant signature algorithm and the quantum-resistant encryption algorithm. After the signature verification and decryption are successful, the node sends a response to the session establishment request to the first communication node to establish a secure session in quantum-resistant mode between the first and second communication nodes. The second communication node is further configured to, when the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions for quantum-resistant communication, switch the secure session between the first communication node and the second communication node from the quantum-resistant mode to a standby mode through the communication mode switching component. The standby mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

2. The system according to claim 1, characterized in that, The session establishment request includes a session key and session identification information; the quantum-resistant component is configured with a quantum-resistant key encapsulation module and a quantum-resistant signature module; the first communication node is used for: The quantum-resistant key encapsulation module in the quantum-resistant component uses the Modular Key Encapsulation Algorithm (ML-KEM) to encrypt the session key in the session establishment request, generating ciphertext. The quantum-resistant signature module in the quantum-resistant component uses the Modular Digital Signature Algorithm (ML-DSA) to sign the session key and session identifier information in the session establishment request, generating a signature.

3. The system according to claim 2, characterized in that, The quantum-resistant component is further configured with a polynomial operation module, which includes multiple computation units adapted for parallel computation of multiple coefficients of a sparse polynomial ring; the first communication node is used for: The ML-KEM algorithm on the quantum-resistant key encapsulation module is executed through the polynomial operation module in the quantum-resistant component to encrypt the session key in the session establishment request and generate the ciphertext. The ML-DSA algorithm on the quantum-resistant signature module is executed through the polynomial operation module in the quantum-resistant component to sign the session key and session identifier information in the session establishment request, thereby generating the signature.

4. The system according to claim 3, characterized in that, The first communication node is also configured with a quantum-resistant algorithm instruction set, which includes multiple hardware instructions for executing the quantum-resistant algorithm; the first communication node is used for: The polynomial operation module in the quantum-resistant component calls at least one hardware instruction from the quantum-resistant algorithm instruction set to execute the ML-KEM algorithm, encrypts the session key in the session establishment request, and generates the ciphertext. The polynomial operation module in the quantum-resistant component calls at least one hardware instruction from the quantum-resistant algorithm instruction set to execute the ML-DSA algorithm and generate the signature from the session key and session identifier information in the session establishment request.

5. The system according to claim 1, characterized in that, The second communication node is also used for: When the communication latency and bit error rate of the secure session in the backup mode meet the latency and bit error rate conditions for quantum-resistant communication, the secure session between the first communication node and the second communication node is switched from the backup mode to the quantum-resistant mode by the communication mode switching component.

6. The system according to claim 1, characterized in that, The first communication node and the second communication node are also used for: When the secure session between the first communication node and the second communication node is in quantum-resistant mode, the session key in the quantum-resistant mode is updated based on the first update cycle; When the secure session between the first communication node and the second communication node is in standby mode, the session key in standby mode is updated based on the second update cycle; The second update cycle is shorter than the first update cycle.

7. The system according to claim 6, characterized in that, The first update cycle is determined based on real-time traffic flow density and a first safety factor; The second update cycle is determined based on real-time traffic flow density and a second safety factor; The first security factor indicates the communication security in the quantum-resistant mode, and the second security factor indicates the communication security in the backup mode.

8. The system according to claim 1, characterized in that, The first communication node and the second communication node are also used for: After establishing a secure quantum-resistant session between the first communication node and the second communication node, communication between the first communication node and the second communication node is based on a lightweight message authentication code (MAC).

9. A communication node, characterized in that, The communication node includes a quantum-resistant component, and the communication node is a communication node in an encrypted communication system within a vehicle-to-everything (V2X) network; the communication node is used for: The quantum-resistant component is used to encrypt and sign the session establishment request using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm, and the encrypted and signed session establishment request is sent to the second communication node in the encrypted communication system. The second communication node includes a communication mode switching component. Receive a response to the session establishment request sent by the second communication node to establish a secure session with the second communication node in quantum-resistant mode; When the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions for quantum-resistant communication, a secure session in backup mode is established with the second communication node through the quantum-resistant component. The backup mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.

10. A communication node, characterized in that, The communication node includes a communication mode switching component; the communication node is a communication node in an encrypted communication system within a vehicle-to-everything (V2X) network; the communication node is used for: The system receives an encrypted and signed session establishment request sent by a first communication node in the encrypted communication system. The session establishment request is obtained by the first communication node through a quantum-resistant component, using a quantum-resistant encryption algorithm and a quantum-resistant signature algorithm to encrypt and sign the session establishment request. The encrypted and signed session establishment request is verified and decrypted using the quantum-resistant signature algorithm and the quantum-resistant encryption algorithm. After the signature verification and decryption are successful, a response to the session establishment request is sent to the first communication node to establish a secure session in quantum-resistant mode with the first communication node. When the communication latency and bit error rate of the secure session in the quantum-resistant mode do not meet the latency and bit error rate conditions for quantum-resistant communication, the secure session with the first communication node is switched from the quantum-resistant mode to a standby mode through the communication mode switching component. The standby mode uses asymmetric encryption algorithms and asymmetric signature algorithms for encryption and signing.