Vehicle-to-vehicle high-security encryption communication method and related equipment
By using cloud-based verification and quantum key set encryption communication through a quantum key management platform, the security threats in vehicle-to-vehicle direct communication are resolved, achieving highly secure and low-latency encrypted communication and ensuring the secure transmission of data between vehicles.
Patent Information
- Application Number
- CN202511787509.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-02-03
AI Technical Summary
In existing vehicle-to-vehicle direct communication, broadcast messages are easily stolen or tampered with, leading to security threats, especially in autonomous driving and vehicle control scenarios, where there are serious security risks.
The vehicle identity is verified through a cloud-based vehicle-to-everything (V2X) platform, a vehicle-to-cloud communication connection is established, and a quantum key set is periodically distributed using a quantum key management platform. Based on the quantum key set, the direct communication between the sending and receiving vehicles is encrypted, and the SM4 encryption algorithm and MAC calculation are used to ensure communication security.
It achieves high security in vehicle-to-vehicle communication, prevents data leakage and tampering, is suitable for low-latency scenarios, and ensures the legitimacy and integrity of communication.
Smart Images

Figure CN121463033A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication encryption technology, and in particular to a vehicle-to-vehicle high-security encrypted communication method and related equipment. Background Technology
[0002] Currently, secure vehicle-to-vehicle (V2X) communication in intelligent connected vehicles primarily uses broadcast messages and employs certificates for authentication, ensuring message integrity and legitimacy. However, with the continuous development of vehicle-road-cloud integration, V2X is no longer limited to message alerts and assisted driving scenarios; it also has applications in autonomous driving and vehicle control. Therefore, it faces the following security threats: Risk 1: PC5 port broadcast messages are in plaintext. If intercepted by illegal vehicles or attackers, they can steal key vehicle control commands and critical information, and then launch attacks, posing a threat to traffic safety.
[0003] Risk 2: If the control commands and critical information transmitted in the vehicle-to-vehicle communication link are forged and tampered with by hackers, receiving incorrect or forged information will pose a serious security threat to the Internet of Vehicles. Summary of the Invention
[0004] The main objective of this invention is to propose a vehicle-to-vehicle high-security encrypted communication method and related equipment, in order to solve at least one problem in the prior art.
[0005] To achieve the above objectives, one aspect of the present invention proposes a vehicle-to-vehicle high-security encrypted communication method, the method comprising the following steps: In response to the communication connection request of the target vehicle, the target vehicle is identified through the cloud-based vehicle networking platform, thereby establishing a vehicle-to-cloud communication connection between the target vehicle and the cloud-based vehicle networking platform, and marking the target vehicle as a trusted and safe vehicle. Based on the quantum key management platform, quantum key sets are periodically distributed to trusted and secure vehicles through a cloud-based vehicle networking platform. Encryption of direct communication between sending and receiving vehicles is achieved using quantum key sets.
[0006] In some embodiments, in response to a communication connection request from a target vehicle, the target vehicle is authenticated through a cloud-based vehicle networking platform, including the following steps: In response to a communication connection request initiated by the target vehicle through the communication system equipment, authentication information is sent to the cloud-based vehicle networking platform; The authentication information includes the result of the target vehicle encrypting its identity information using a pre-charged first quantum key; Identity verification is performed based on authentication information through a cloud-based vehicle networking platform.
[0007] In some embodiments, establishing a vehicle-to-cloud communication connection between the target vehicle and the cloud-based vehicle networking platform includes the following steps: If the identity verification result is successful, apply for a vehicle-cloud session key from the quantum key management platform through the cloud-based vehicle networking platform; The cloud-based vehicle networking platform distributes the vehicle-to-cloud session key to the target vehicle as an encrypted communication protection key for the vehicle-to-cloud communication connection, enabling the target vehicle to establish a vehicle-to-cloud communication connection with the cloud-based vehicle networking platform.
[0008] In some embodiments, based on a quantum key management platform, a quantum key set is periodically distributed to a trusted and secure vehicle via a cloud-based vehicle networking platform, including the following steps: A batch of quantum keys are generated periodically through a quantum key management platform, and the validity period of the quantum keys is marked. These are then compiled into a quantum key set. The quantum key set generated by the quantum key management platform is distributed to trusted and secure vehicles through a cloud-based vehicle networking platform.
[0009] In some embodiments, communication encryption is performed on direct communication between the transmitting vehicle and the receiving vehicle based on a quantum key set, including the following steps: In response to a communication transmission request from the transmitting vehicle, a first target key is determined using the quantum key set on the transmitting vehicle, and then the communication data is encrypted to obtain an encrypted message and a first message verification code. The encrypted message, the first message verification code, and the key ID of the first target key are transmitted from the sending vehicle to the receiving vehicle via direct communication, so that the receiving vehicle can decrypt the encrypted message based on the key ID.
[0010] In some embodiments, a first target key is determined by a quantum key set on the transmitting vehicle, and then the communication data is encrypted to obtain an encrypted message and a first message verification code, including the following steps: A quantum key is randomly selected from the quantum key set on the transmitting vehicle as the first target key; The communication data to be sent by the sending vehicle is encrypted using the SM4 encryption algorithm to obtain an encrypted message; The MAC calculation of the encrypted message is performed using the first target key to obtain the first message verification code; Mark the status of the first target key as expired.
[0011] In some embodiments, the receiving vehicle decrypts the encrypted message based on the key ID, including the following steps: The second target key is retrieved from the quantum key set on the receiving vehicle based on the key ID, and the validity period marked in the second target key is used to determine whether the second target key is within the valid time. When the second target key is within the valid time, use the second target key to perform MAC calculation on the encrypted message to obtain the second message verification code; If the first message verification code matches the second message verification code, the encrypted message is decrypted using the encryption algorithm of the communication data encryption application to obtain the decrypted plaintext. Mark the status of the second target key as expired.
[0012] To achieve the above objectives, another aspect of the present invention provides a vehicle-to-vehicle high-security encrypted communication device, comprising: The communication connection module is used to respond to the communication connection request of the target vehicle, authenticate the target vehicle through the cloud vehicle network platform, establish a vehicle-cloud communication connection between the target vehicle and the cloud vehicle network platform, and mark the target vehicle as a trusted and safe vehicle. The key management module is used to periodically distribute quantum key sets to trusted and secure vehicles through a cloud-based vehicle networking platform, based on the quantum key management platform. The communication encryption module is used to encrypt direct communication between the sending and receiving vehicles based on a quantum key set.
[0013] To achieve the above objectives, another aspect of the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described vehicle-to-vehicle high-security encrypted communication method.
[0014] To achieve the above objectives, another aspect of the present invention provides a computer program product, including a computer program that, when executed by a processor, implements the above-described vehicle-to-vehicle high-security encrypted communication method.
[0015] This invention, in response to a communication connection request from a target vehicle, authenticates the target vehicle through a cloud-based vehicle-to-everything (V2X) platform, thereby establishing a vehicle-to-cloud (V2X) communication connection between the target vehicle and the cloud-based V2X platform, and marking the target vehicle as a trusted and secure vehicle. Based on a quantum key management platform, the cloud-based V2X platform periodically distributes quantum key sets to the trusted and secure vehicle. Communication encryption is then applied to the direct communication between the sending and receiving vehicles based on the quantum key set. To prevent data leakage during secure vehicle-to-vehicle communication, this invention first verifies the vehicle's security through the cloud-based V2X platform, and then employs quantum key encryption technology for trusted and secure vehicles. This enables secure encryption and decryption of communication between vehicles based on periodically distributed quantum key sets, ensuring highly secure encrypted communication. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of an implementation environment for high-security encrypted vehicle-to-vehicle communication provided by an embodiment of the present invention; Figure 2 A flowchart illustrating a vehicle-to-vehicle high-security encrypted communication method provided in an embodiment of the present invention; Figure 3 A schematic diagram of the vehicle-to-vehicle safety communication system framework provided in an embodiment of the present invention; Figure 4 This is a schematic diagram illustrating the architecture principle of the vehicle-to-vehicle high-security encrypted communication method provided in an embodiment of the present invention. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0018] It should be noted that although functional modules are divided in the system diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first / S100," "second / S200," etc., in the specification, claims, and the aforementioned figures are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0019] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0020] To facilitate understanding of the technical solutions of the embodiments of the present invention, the professional knowledge that may be involved in the technical solutions of the present invention will first be explained: QRNG devices / QDK devices: QRNG - quantum random number generator devices, QKD - quantum key distribution devices, highly secure quantum key sources.
[0021] Quantum key management platform: manages quantum keys.
[0022] TSP: TSPs play a core role in the connected vehicle ecosystem. They are responsible for trusted vehicle management, interfacing with quantum key management platforms, and providing quantum key management services for vehicles.
[0023] TBOX: A communication system in a car that supports 4G / 5G cellular remote communication, PC5 port and other direct communication.
[0024] SE security chip: Integrated into the TBOX, it provides secure storage and encryption functions for quantum keys. During vehicle manufacturing, the quantum keys are pre-charged and pre-stored in batches on the production line.
[0025] It is understood that the vehicle-to-vehicle high-security encrypted communication method provided in this embodiment of the invention can be applied to any computer device with data processing and computing capabilities (such as an in-vehicle terminal device or a vehicle-related control system), and this computer device can be various types of terminals or servers. When the computer device in the embodiment is a server, the server is an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. In some embodiments, the terminal is a smartphone, tablet computer, laptop computer, or desktop computer, but it is not limited to these.
[0026] like Figure 1 The diagram shown is a schematic representation of an implementation environment provided by an embodiment of the invention. (Refer to...) Figure 1 The implementation environment includes at least one terminal 102 and a server 101. The terminal 102 and the server 101 can be connected via a network, either wirelessly or via a wired connection, to complete data transmission and exchange.
[0027] Server 101 can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0028] Additionally, server 101 can also be a node server in a blockchain network. Blockchain is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms.
[0029] Terminal 102 can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, etc. It can also be a vehicle-mounted terminal of the various device types described above, but is not limited to these. Terminal 102 and server 101 can be directly or indirectly connected via wired or wireless communication, and this embodiment of the invention does not impose any limitations.
[0030] Exemplary based on Figure 1 The implementation environment shown in this embodiment of the invention provides a vehicle-to-vehicle high-security encrypted communication method. The following description uses the application of this vehicle-to-vehicle high-security encrypted communication method in server 101 as an example. It can be understood that this vehicle-to-vehicle high-security encrypted communication method can also be applied in terminal 102.
[0031] Reference Figure 2 , Figure 2 This is a flowchart illustrating a vehicle-to-vehicle high-security encrypted communication method applied to a server, provided in an embodiment of the present invention. The executing entity of this vehicle-to-vehicle high-security encrypted communication method can be any of the aforementioned computer devices (including servers or terminals). (Refer to...) Figure 2 The method may include the following steps: S100: In response to the communication connection request of the target vehicle, the target vehicle is authenticated through the cloud vehicle network platform, and then a vehicle-to-cloud communication connection is established between the target vehicle and the cloud vehicle network platform, marking the target vehicle as a trusted and safe vehicle. It should be noted that, in some embodiments, in response to a communication connection request from a target vehicle, the authentication of the target vehicle through the cloud-based vehicle networking platform may include the following steps: in response to a communication connection request initiated by the target vehicle through a communication system device, sending authentication information to the cloud-based vehicle networking platform; wherein, the authentication information includes the result of the target vehicle encrypting its identity information based on a pre-charged first quantum key; and authenticating the vehicle through the cloud-based vehicle networking platform based on the authentication information.
[0032] It should be noted that, in some embodiments, establishing a vehicle-to-cloud communication connection between the target vehicle and the cloud-based vehicle networking platform may include the following steps: when the authentication result is successful, the vehicle-to-cloud session key is applied for from the quantum key management platform through the cloud-based vehicle networking platform; the vehicle-to-cloud session key is distributed to the target vehicle through the cloud-based vehicle networking platform as an encrypted communication protection key for the vehicle-to-cloud communication connection, so that the target vehicle and the cloud-based vehicle networking platform can establish a vehicle-to-cloud communication connection.
[0033] For example, in some specific implementations, a connection is first established with the cloud to form a trusted vehicle-cloud connection, which can be achieved as follows: 1. The vehicle-side TBOX device establishes a communication connection with the cloud-based vehicle networking TSP platform via a 4G / 5G network, and uses pre-charged quantum keys to encrypt vehicle identity information, etc., and performs identity authentication with the TSP cloud.
[0034] 2. The TSP checks the TBOX information. After successful authentication, the TSP applies for a vehicle-to-cloud session key through the quantum key management platform and sends it to the vehicle to serve as an encrypted communication protection key for vehicle-to-cloud communication.
[0035] 3. A vehicle that has established secure communication with the TSP cloud is a trusted and secure vehicle.
[0036] S200, based on a quantum key management platform, periodically distributes quantum key sets to trusted and secure vehicles through a cloud-based vehicle networking platform; It should be noted that in some embodiments, the process of periodically distributing quantum key sets to trusted and secure vehicles through a cloud-based vehicle networking platform based on a quantum key management platform may include the following steps: periodically generating a batch of quantum keys and marking their validity period through the quantum key management platform, and organizing them into a quantum key set; and distributing the quantum key set generated by the quantum key management platform to trusted and secure vehicles through the cloud-based vehicle networking platform.
[0037] For example, in some specific implementations, after the trusted vehicle-to-cloud connection is established, a quantum key set is pushed periodically, which can be achieved as follows: 1. The quantum key management platform generates a batch of quantum keys at regular intervals, with each key marked with an expiration date (e.g., 1 hour), and distributes them to trusted vehicles through a secure link between the TSP and the vehicle.
[0038] 2. After receiving the quantum key set, the trusted vehicle stores it in a secure environment such as an SE.
[0039] S300: Encrypt direct communication between the transmitting and receiving vehicles based on quantum key sets; It should be noted that, in some embodiments, communication encryption for direct communication between the transmitting vehicle and the receiving vehicle based on a quantum key set may include the following steps: in response to a communication transmission request from the transmitting vehicle, a first target key is determined using the quantum key set on the transmitting vehicle, and then the communication data is encrypted to obtain an encrypted message and a first message verification code; the encrypted message, the first message verification code, and the key ID of the first target key are transmitted from the transmitting vehicle to the receiving vehicle via direct communication, so that the receiving vehicle can decrypt the encrypted message based on the key ID.
[0040] It should be noted that in some embodiments, determining the first target key through the quantum key set on the transmitting vehicle, and then encrypting the communication data to obtain the encrypted message and the first message verification code, may include the following steps: randomly selecting a quantum key from the quantum key set on the transmitting vehicle as the first target key; encrypting the communication data to be sent by the transmitting vehicle using the SM4 encryption algorithm to obtain the encrypted message; performing MAC calculation on the encrypted message using the first target key to obtain the first message verification code; and marking the status of the first target key as expired.
[0041] It should be noted that in some embodiments, the receiving vehicle decrypts the encrypted message based on the key ID, which may include the following steps: retrieving a second target key from the quantum key set on the receiving vehicle based on the key ID; determining whether the second target key is within its validity period based on the validity period marked in the second target key; if the second target key is within its validity period, performing MAC calculation on the encrypted message using the second target key to obtain a second message verification code; if the first message verification code matches the second message verification code, performing a decryption operation on the encrypted message based on the encryption algorithm of the communication data encryption application to obtain the decrypted plaintext; and marking the status of the second target key as expired.
[0042] For example, in some specific implementations, secure encryption of direct vehicle-to-vehicle communication can be achieved as follows: 1. The TBOX terminal randomly selects a quantum key from the SE quantum key set to encrypt the control commands or critical messages to be transmitted (encryption algorithm SM4). Then, using this quantum key, it performs a MAC (Message Authentication Codes, a hash function based on the secret key used to generate message verification codes) calculation (SM4-CMAC) on all message information (KEYID [key ID] + timestamp + encrypted message instruction). The message format is as follows: KEYID + timestamp + encrypted message instruction + MAC; 2. After receiving the command, the other TBOX reads the KEYID, calls the quantum key in the SE quantum key set through the KEYID, and determines whether the key is within the valid time. If it is valid, it uses the key to perform MAC calculation on all message information and compares it with the received MAC. If the MAC is consistent, the message source is trustworthy and has not been tampered with.
[0043] 3. After verifying the legality and integrity of the message, decrypt the encrypted message instructions to obtain the plaintext and execute the relevant instructions.
[0044] 4. Both the message sender and the message receiver manage the quantum key set. Once the key has been used, it is marked as invalid at the vehicle end, ensuring a one-time pad encryption communication mechanism.
[0045] To explain in detail the principle of the technical solution of the present invention, the overall process of the present invention will be described below with reference to some specific embodiments. It is easy to understand that the following is an explanation of the technical principle of the present invention and should not be regarded as a limitation of the present invention.
[0046] First, it's important to note that the development of quantum computing technology poses a serious threat to the classical cryptographic systems currently used in vehicle-to-everything (V2X) communication, especially since asymmetric cryptographic algorithms are no longer secure. Current V2X-based security certificate authentication methods rely on the SM2 asymmetric algorithm for identity verification, but the SM2 asymmetric algorithm lacks resistance to quantum computing and does not support encrypted communication mechanisms.
[0047] Therefore, embodiments of the present invention provide a technical solution for high-security encrypted vehicle-to-vehicle communication. This high-security encrypted vehicle-to-vehicle communication solution can be applied to, for example... Figure 3 The vehicle-to-vehicle safety communication system framework shown (the meanings of the components within the framework are explained in the aforementioned professional field knowledge, and will not be repeated here). Specifically, such as... Figure 4 As shown, the vehicle-to-vehicle high-security encrypted communication in this embodiment of the invention can be implemented through the following process steps: Phase 1: Establishing a connection with the cloud to form a trusted vehicle-cloud connection; 1. The vehicle-side TBOX device establishes a communication connection with the cloud-based vehicle networking TSP platform via a 4G / 5G network, and uses pre-charged quantum keys to encrypt vehicle identity information, etc., and performs identity authentication with the TSP cloud. 2. The TSP checks the TBOX information. After successful authentication, the TSP applies for a vehicle-to-cloud session key through the quantum key management platform and sends it to the vehicle to serve as an encrypted communication protection key for vehicle-to-cloud communication.
[0048] 3. A vehicle that has established secure communication with the TSP cloud is a trusted and secure vehicle.
[0049] Phase Two: After the trusted vehicle-cloud connection is established, the quantum key set is pushed out periodically; 1. The quantum key management platform generates a batch of quantum keys at regular intervals, with each key marked with an expiration date (e.g., 1 hour), and distributes them to trusted vehicles through a secure link between the TSP and the vehicle.
[0050] 2. After receiving the quantum key set, the trusted vehicle stores it in a secure environment such as an SE.
[0051] Phase 3: Secure encryption of direct vehicle-to-vehicle communication; 1. The TBOX randomly selects a quantum key from the SE quantum key set to encrypt the control commands or critical messages to be transmitted (encryption algorithm SM4). Then, using this quantum key, it performs a MAC (Message Authentication Codes, a hash function based on the secret key used to generate message verification codes) calculation (SM4-CMAC) on all message information (KEYID + timestamp + encrypted message instruction). The message format is as follows: KEYID + timestamp + encrypted message instruction + MAC; 2. After receiving the command, the other TBOX reads the KEYID, calls the quantum key in the SE quantum key set through the KEYID, and determines whether the key is within the valid time. If it is valid, it uses the key to perform MAC calculation on all message information and compares it with the received MAC. If the MAC is consistent, the message source is trustworthy and has not been tampered with.
[0052] 3. After verifying the legality and integrity of the message, decrypt the encrypted message instructions to obtain the plaintext and execute the relevant instructions.
[0053] 4. Both the message sender and the message receiver manage the quantum key set. Once the key has been used, it is marked as invalid at the vehicle end, ensuring a one-time pad encryption communication mechanism.
[0054] In summary, to prevent data leakage during secure vehicle-to-vehicle communication, this invention employs a secure encryption algorithm combined with quantum key encryption technology. It utilizes a one-time pad security key and a secure algorithm to achieve absolute security. This enables secure encryption and decryption between vehicles, ensuring that data is not stolen or tampered with during transmission and guaranteeing highly secure encrypted communication.
[0055] Compared with the prior art, the present invention has at least the following beneficial effects: i. Secure distribution of V2X quantum key sets ensures that the keys used in vehicle-to-vehicle encrypted communication are highly secure. The quantum key source ensures the absolute randomness of quantum key generation, ensuring high security. The quantum key set is updated periodically to ensure the effective usage period of the keys, and a one-time pad security mechanism ensures the ultra-high security of the keys used for encrypted communication.
[0056] ii. By using quantum key distribution and randomly selecting security mechanisms, and identifying the use of keys through KEYID, the process of symmetric session key negotiation in vehicle-to-vehicle communication is saved, reducing interaction and communication latency, making it more suitable for low-latency scenarios in vehicle-to-vehicle communication.
[0057] iii. By incorporating security mechanisms such as timestamps and MAC addresses into vehicle-to-vehicle security messages, it is possible to effectively prevent replay of security messages, protect their integrity and legitimacy, and prevent them from being stolen or tampered with.
[0058] This invention also provides a vehicle-to-vehicle high-security encrypted communication device, comprising: The communication connection module is used to respond to the communication connection request of the target vehicle, authenticate the target vehicle through the cloud vehicle network platform, establish a vehicle-cloud communication connection between the target vehicle and the cloud vehicle network platform, and mark the target vehicle as a trusted and safe vehicle. The key management module is used to periodically distribute quantum key sets to trusted and secure vehicles through a cloud-based vehicle networking platform, based on the quantum key management platform. The communication encryption module is used to encrypt direct communication between the sending and receiving vehicles based on a quantum key set.
[0059] It is worth noting that, since the technical solutions implemented by the module functions of the vehicle-to-vehicle high-security encrypted communication device in this embodiment correspond one-to-one with the process steps of the aforementioned vehicle-to-vehicle high-security encrypted communication method, the specific implementation methods and technical effects of the vehicle-to-vehicle high-security encrypted communication device in this embodiment can be referred to the specific implementation methods and technical effects of the vehicle-to-vehicle high-security encrypted communication method in any of the above embodiments.
[0060] This invention also provides a vehicle control device, including a memory, a processor, and a program stored in the memory and executable on the processor. When the program is executed by the processor, it implements the method described in the above embodiments.
[0061] Taking the example of a processor and memory in a vehicle controller being connected via a bus, the memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory may optionally include memory remotely located relative to the control processor, and these remote memories can be connected to the control device via a network.
[0062] The non-transitory software program and instructions required to implement the methods of the above embodiments are stored in memory and executed by the processor to perform the methods of the above embodiments.
[0063] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0064] This invention also provides a vehicle, including the vehicle control device described in the above embodiments.
[0065] The vehicle can be a private car, such as a sedan, SUV, MPV, or pickup truck. It can also be a commercial vehicle, such as a van, bus, small truck, or large semi-trailer. The vehicle must have an electric motor capable of outputting power or acting as a generator to store mechanical energy. When the vehicle is a new energy vehicle, it can be a hybrid or a pure electric vehicle.
[0066] Since the vehicle applies all the technical solutions of the above-mentioned control device or vehicle controller, it has at least all the beneficial effects brought about by the technical solutions of the above embodiments, which will not be repeated here.
[0067] Furthermore, one embodiment of the present invention provides a computer-readable storage medium storing computer-executable instructions for executing the above-described vehicle-to-vehicle high-security encrypted communication method.
[0068] It is worth noting that, since the computer-readable storage medium of the present invention can execute the vehicle-to-vehicle high-security encrypted communication method of any of the above embodiments, the specific implementation and technical effects of the computer-readable storage medium of the present invention can be referred to the specific implementation and technical effects of the vehicle-to-vehicle high-security encrypted communication method of any of the above embodiments.
[0069] Furthermore, one embodiment of the present invention also provides a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. A processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the aforementioned vehicle-to-vehicle high-security encrypted communication method.
[0070] It is worth noting that, since the computer program product of this embodiment can execute the vehicle-to-vehicle high-security encrypted communication method of any of the above embodiments, the specific implementation method and technical effects of the computer program product of this embodiment can be referred to the specific implementation method and technical effects of the vehicle-to-vehicle high-security encrypted communication method of any of the above embodiments.
[0071] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically include computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0072] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
Claims
1. A vehicle-to-vehicle high-security encrypted communication method, characterized in that, The method includes the following steps: In response to the communication connection request of the target vehicle, the target vehicle is authenticated through the cloud-based vehicle networking platform, thereby establishing a vehicle-to-cloud communication connection between the target vehicle and the cloud-based vehicle networking platform, and marking the target vehicle as a trusted and safe vehicle. Based on the quantum key management platform, quantum key sets are periodically distributed to the trusted and secure vehicle through the cloud-based vehicle network platform. The quantum key set is used to encrypt the direct communication between the sending vehicle and the receiving vehicle.
2. The vehicle-to-vehicle high-security encrypted communication method according to claim 1, characterized in that, The process of authenticating the target vehicle in response to its communication connection request via a cloud-based vehicle networking platform includes the following steps: In response to the communication connection request initiated by the target vehicle through the communication system device, authentication information is sent to the cloud-based vehicle network platform; The authentication information includes the result of the target vehicle encrypting its identity information based on a pre-charged first quantum key; The identity verification is performed by the cloud-based vehicle networking platform based on the authentication information.
3. The vehicle-to-vehicle high-security encrypted communication method according to claim 1 or 2, characterized in that, Establishing a vehicle-to-cloud communication connection between the target vehicle and the cloud-based vehicle networking platform includes the following steps: If the authentication result is successful, the vehicle-to-cloud session key is requested from the quantum key management platform through the cloud-based vehicle networking platform. The cloud-based vehicle networking platform distributes the vehicle-to-cloud session key to the target vehicle as an encrypted communication protection key for the vehicle-to-cloud communication connection, thereby enabling the target vehicle to establish the vehicle-to-cloud communication connection with the cloud-based vehicle networking platform.
4. The vehicle-to-vehicle high-security encrypted communication method according to claim 1, characterized in that, The process of periodically distributing quantum key sets to the trusted and secure vehicle via the cloud-based vehicle networking platform, based on the quantum key management platform, includes the following steps: A batch of quantum keys are generated periodically through the quantum key management platform, and the validity period of the quantum keys is marked, and the quantum keys are compiled into the quantum key set. The quantum key set generated by the quantum key management platform is distributed to the trusted and secure vehicle through the cloud-based vehicle networking platform.
5. The vehicle-to-vehicle high-security encrypted communication method according to claim 1, characterized in that, The encryption of direct communication between the transmitting and receiving vehicles based on the quantum key set includes the following steps: In response to the communication transmission request from the transmitting vehicle, a first target key is determined by the quantum key set on the transmitting vehicle, and then the communication data is encrypted to obtain an encrypted message and a first message verification code. The encrypted message, the first message verification code, and the key ID of the first target key are transmitted from the sending vehicle to the receiving vehicle via the direct communication, so that the receiving vehicle can decrypt the encrypted message based on the key ID.
6. The vehicle-to-vehicle high-security encrypted communication method according to claim 5, characterized in that, The step of determining the first target key through the quantum key set on the transmitting vehicle, and then encrypting the communication data to obtain the encrypted message and the first message verification code, includes the following steps: A quantum key is randomly selected from the quantum key set on the transmitting vehicle as the first target key; The communication data to be sent by the sending vehicle is encrypted using the SM4 encryption algorithm to obtain the encrypted message; The first message verification code is obtained by performing a MAC calculation on the encrypted message using the first target key. The status of the first target key is marked as expired.
7. The vehicle-to-vehicle high-security encrypted communication method according to claim 5, characterized in that, The receiving vehicle decrypts the encrypted message based on the key ID, including the following steps: The second target key is retrieved from the quantum key set on the receiving vehicle based on the key ID, and it is determined whether the second target key is within the valid time based on the validity period marked in the second target key. When the second target key is within the valid time, the encrypted message is calculated using the second target key to obtain the second message verification code. If the first message verification code matches the second message verification code, the encrypted message is decrypted based on the encryption algorithm of the communication data encryption application to obtain the decrypted plaintext; The status of the second target key is marked as expired.
8. A vehicle-to-vehicle high-security encrypted communication device, characterized in that, include: The communication connection module is used to respond to the communication connection request of the target vehicle, authenticate the target vehicle through the cloud vehicle network platform, and then establish a vehicle-to-cloud communication connection between the target vehicle and the cloud vehicle network platform, and mark the target vehicle as a trusted and safe vehicle. The key management module is used to periodically distribute quantum key sets to the trusted and secure vehicle through the cloud-based vehicle networking platform, based on the quantum key management platform. A communication encryption module is used to encrypt direct communication between the sending vehicle and the receiving vehicle based on the quantum key set.
9. A vehicle, characterized in that, It includes a memory, a processor, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the vehicle-to-vehicle high-security encrypted communication method as described in any one of claims 1 to 7.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the vehicle-to-vehicle high-security encrypted communication method as described in any one of claims 1 to 7.