Key dynamic distribution method and system for intelligent network connection vehicle
By dynamically allocating shared keys and combining data impact levels with communication requirements, the problem of fixed keys being easily cracked in intelligent connected vehicles is solved, achieving higher data communication security and reliability.
Patent Information
- Application Number
- CN202511732556.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-24
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2045-11-24
AI Technical Summary
In existing intelligent connected vehicle communication, fixed key algorithms and negotiated keys are at risk of being cracked, which increases the possibility of data leakage. Existing technologies have not been able to effectively solve the problem of dynamically generating shared keys.
By comprehensively considering data impact level, communication rate requirements, key rated security strength, security tolerance, and vehicle-side capability level, shared keys are dynamically allocated, and negotiated keys are switched according to data communication time and quantity thresholds during communication sessions. An agent training algorithm is used for key generation and allocation.
It improves the security of data communication, reduces the risk of data leakage, and enhances the reliability and security of communication.
Smart Images

Figure CN121547170A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the field of vehicle communication information security and technology, and more particularly to a dynamic key allocation method and system for intelligent networked vehicles. BACKGROUND
[0002] The intelligent networked vehicle interacts with the cloud server with a very large amount of data. With the development of technology, the communication security requirements for data are becoming higher and higher. The key allocation method plays a key role. At present, the commonly used data communication mode mostly adopts a fixed key algorithm to negotiate a key, and a fixed negotiation key is adopted in the same communication session window, and encryption and decryption are performed in the whole communication process. The fixed key algorithm and the fixed negotiation key have the risk of data leakage due to the cracking of the key and the negotiation method in the long-term use.
[0003] The Chinese invention patent with the publication number CN119483939A discloses a dynamic management method and system for keys, which dynamically adjusts the shared key according to network quality parameters and communication data sensitivity levels, thereby effectively ensuring the security and efficiency of data transmission and reducing management complexity. The application only changes the shared key at the end of the communication session or the time threshold, and does not provide an algorithm for dynamically generating a shared key.
[0004] The Chinese invention patent with the application publication number CN118741497A discloses an Internet of Vehicles AES encryption method based on multi-agent reinforcement learning, which constructs a system state based on the message category and vehicle position at the current time, the channel gain, encryption and decryption, and transmission delay at the last time, and the security level of communication, adopts a multi-agent reinforcement learning algorithm to optimize the mode and key length of the vehicle end using the AES algorithm to encrypt the message, thereby reducing the encryption delay and the information leakage probability due to eavesdropping or interception, improving the communication security level, and further improving the reliability and security of information transmission in the Internet of Vehicles. The invention patent only dynamically allocates the key of the AES algorithm. SUMMARY
[0005] The application provides a dynamic key allocation method and system for intelligent networked vehicles, which generates a dynamic shared key by dynamic allocation, improves the security of data communication, and reduces the risk of data leakage.
[0006] The application adopts the following technical solutions: A dynamic key allocation method for intelligent networked vehicles, comprising the following steps: Step 1: setting and storing key information, including data impact level , communication speed requirement , key security tolerance , vehicle end capability level , key rating security strength, key allocation strategy, data communication threshold value and key information storage; Step two, the vehicle end and the cloud server establish a secure communication channel, and the key allocation process is as follows: (1) The cloud server calculates the key strength requirement value QKS according to the data impact level , communication rate requirement , key security tolerance , vehicle end capability level , key allocation strategy , wherein: represents the data impact level weight value, represents the communication rate weight value, represents the key security tolerance weight value, represents the vehicle end capability level weight value, , , , According to the key allocation strategy, the intelligent agent is trained to obtain the key strength requirement value QKS and the key rating security strength value (2) Compare the key strength requirement value QKS and the key rating security strength value , and obtain the key strength requirement level QKG; (3) Obtain the key type supported by the vehicle end with the key rating security strength level QKG from the key information library; when the key type is multiple, a random algorithm is used to select the key type, that is, the shared key type of the communication session with the same key strength requirement level is not the same; (4) Calculate the shared key value according to the selected shared key type; (5) The cloud server transmits the shared key information to the vehicle end; Step three, when the communication session ends or reaches the data communication time threshold or reaches the data communication volume, the key is replaced.
[0007] The above data impact level is specifically classified according to relevant standards according to the communication data, assuming that it is divided into k levels, the larger the value of k, the greater the data impact, and the corresponding data impact level value is .
[0008] The above communication data message between the vehicle end and the cloud server contains multiple data levels, and the largest impact level is set as the communication data message. The flag indicating whether the communication data message contains data of a certain data impact level is represented as , wherein: * ), .
[0009] The key rated security strength represents the security strength of each type of key according to the relevant standards, assuming that the key rated security strength is m levels, and the key rated security strength value of each level represents , m>3.
[0010] The calculation formula of the key strength requirement level QKG in step two (2) is as follows: ; wherein, respectively represent =1 when The value of
[0011] The key security tolerance KST represents the adjustable key strength value under a specific communication environment, application scenario, and attack risk, and a negative value represents reducing the security key strength in the communication process, and a positive value represents improving the security key strength in the communication process.
[0012] The key allocation strategy is divided into communication rate priority and security strength priority according to self-definition, wherein the communication rate priority refers to allocating the key with the lowest key strength under the premise of meeting the security demand; and the security strength priority refers to allocating the key with the highest key strength under the premise of meeting the communication rate.
[0013] The data communication threshold is a judgment threshold for replacing the key, including a data communication time threshold or a data communication amount threshold.
[0014] When the communication session ends, the vehicle cloud waits to reestablish a new communication session, repeats step two, and allocates a new negotiation key; when the communication session does not end and reaches the data communication time threshold or reaches the data communication amount, steps (2) to (5) in step two are repeated, a new negotiation key is allocated, and the communication is continued.
[0015] The application also provides a key dynamic allocation system of an intelligent networked vehicle, comprising a cloud server and a vehicle end, wherein: The cloud server has a cloud key public opinion module, a password information library, a cloud key management module, a cloud service management module, and a cloud communication management module, the cloud key public opinion module is used to obtain the public opinion information of the key, dynamically update the key public opinion, and evaluate the attack risk; the password information library is used to store the key information, including the data influence level, the communication rate demand, the key rated security strength, the vehicle end capability level, the security tolerance, the allocation strategy, the data communication threshold, and the key type supported by the vehicle end; the cloud key management module is used to realize the allocation of the shared key, and provides services including key confirmation, key generation, and key calculation; the cloud service management module is responsible for processing different services; and the cloud communication management module is responsible for the secure communication between the cloud server and the vehicle end. The vehicle end has a communication management module, a service management module and a key management module, the communication management module is responsible for the safe communication of the vehicle end and the cloud server end, the service management module is responsible for processing different properties, and the key management module is responsible for services including key calculation and storage.
[0016] From the above description of the application, compared with the prior art, the application has the following advantages: Under the premise of establishing a safe channel between the vehicle and the cloud, the application comprehensively considers the data influence level, the communication rate requirement, the key rated security strength, the security tolerance, the vehicle end capability level, the distribution strategy, dynamically distributes and generates a dynamic shared key, and switches and negotiates the key in the same communication session window according to the data communication time threshold and the data communication volume threshold, thereby improving the security of data communication and reducing the risk of data leakage. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 The figure is a system architecture diagram of the application.
[0018] Figure 2 The figure is a method flowchart of the application. DETAILED DESCRIPTION
[0019] The specific embodiments of the application will be described below with reference to the accompanying drawings. In order to fully understand the application, many details are described below, but the application can also be implemented without these details for those skilled in the art. For well-known components, methods and processes, the following will not be described in detail.
[0020] The embodiment provides a key dynamic distribution system of an intelligent networked vehicle, referring to Figure 1 , including a cloud server end and a vehicle end. Wherein: 1. The cloud server end has a cloud key public opinion module, a password information library, a cloud key management module, a cloud service management module and a cloud communication management module.
[0021] The cloud key public opinion module: obtains the public opinion information of the key, dynamically updates the key public opinion, and evaluates the attack risk.
[0022] The password information library: stores key information, including data influence level, communication rate requirement, key rated security strength, vehicle end capability level, security tolerance, distribution strategy, data communication threshold, and key types supported by the vehicle end. The following key types are defined by key algorithm, length and working mode to represent the key type KN.
[0023] The cloud key management module: realizes shared key distribution, and provides key confirmation, key generation, key calculation and other services.
[0024] The cloud service management module: is responsible for processing different services.
[0025] Cloud communication management module: responsible for secure communication between the cloud server and the vehicle.
[0026] 2. The vehicle-mounted terminal has a communication management module, a service management module, and a key management module.
[0027] Communication Management Module: Responsible for secure communication between the vehicle and the cloud server.
[0028] Business Management Module: Responsible for processing different business processes.
[0029] Key Management Module: Responsible for key calculation, storage, and other services.
[0030] This embodiment also provides a method for dynamic key allocation for intelligent connected vehicles, referring to... Figure 2 ,include: I. Setting and storing key information 1.1 Data Impact Level Beforehand, the communication data is classified and graded according to relevant standards (the standards can be industry / enterprise, etc.). Let's assume it's divided into k levels; the larger the k value, the greater the data impact. The corresponding data impact level values are: .
[0031] A single communication data packet between the vehicle and the cloud server may contain multiple data levels. The highest impact level is designated as the data level of the communication data packet, and its data level value is denoted as Td. A flag indicating whether a communication data packet contains data of a specific impact level is denoted as... .in: * ), 1.2 Communication Rate Requirements The communication rate requirements for data are pre-classified and quantified according to relevant standards (standards can be industry / enterprise, etc.). The smaller the communication rate requirement value, the faster the data encryption and decryption speed. The communication rate requirement value is divided into level j. This represents the value corresponding to the communication rate requirement level z. .
[0032] The key's rated communication rate requirement is the highest communication rate that can be satisfied for each type of key, denoted as KSq.
[0033] 1.3 Key Rated Security Strength The rated security strength of a key represents a tiered definition of security strength for each key type based on relevant standards (standards can be industry-specific or enterprise-specific). Assuming the rated security strength of a key is categorized into m levels, the rated security strength value for each level represents... , m>3. The rated security strength of the key is updated by the key public opinion management module using intelligent technology.
[0034] 1.4 Key Security Tolerance Key security tolerance represents the adjustable key strength value under specific communication environments, application scenarios, and attack risks. Negative values indicate a reduction in security key strength during communication, while positive values indicate an increase in security key strength. Key security tolerance is denoted as KST.
[0035] 1.5 Vehicle-side capability level The vehicle-side capability level (VCL) represents the key computation capability of the vehicle communication terminal.
[0036] 1.6 Key Distribution Strategy Key distribution strategies can be categorized based on user preferences, such as communication rate priority and security strength priority. Among these: Communication rate priority: Allocate the key with the lowest key strength while meeting security requirements.
[0037] Security strength priority: Assign the key with the highest key strength while meeting the communication rate requirements.
[0038] 1.7 Data Communication Threshold The data communication threshold is the threshold for determining whether to change the key, including either a data communication time threshold or a data communication volume threshold. The data communication threshold is set based on factors such as data type and application scenario.
[0039] 1.8 Key Information Storage The key type, its corresponding data impact level, communication rate requirements, key rated security strength, vehicle-side capability level, security tolerance, allocation strategy, and data communication threshold are stored in the key information database.
[0040] II. Key Distribution After establishing a secure communication channel between the vehicle and the cloud server, the two parties negotiate and share a key. The key allocation process is as follows: (1) The cloud server calculates the key strength requirement value, denoted as QKS, based on the data impact level, vehicle capability level, communication rate requirements, key security tolerance, and key distribution strategy: in: This indicates the weight value of the data's impact level; Indicates the communication rate weight value; This represents the key security tolerance weight value; This indicates the weight value of the vehicle-side capability level; , , , The settings are configured according to the key allocation strategy and derived by the agent during training.
[0041] (2) The key strength requirement value QKS and the key rated security strength value The comparison yields the key strength requirement level QKG: ; in, They represent =1 hour The value of .
[0042] (3) Obtain the key types supported by the vehicle terminal with a key rated security strength level of QKG from the key information database. When there are multiple key types, a random algorithm is used to select the key type. That is, the shared key types of communication sessions with the same key strength requirement level are not the same.
[0043] (4) Calculate the shared key value based on the selected shared key type.
[0044] (5) The cloud server transmits the shared key information to the vehicle, and the vehicle cloud uses the shared key to encrypt and transmit data.
[0045] III. Key Update The key is changed when the communication session ends, the data communication time threshold is reached, or the data communication volume is reached. Specifically: When the communication session ends, wait for the vehicle cloud to re-establish a new communication session, and repeat step two, the key allocation step, to allocate a new negotiation key.
[0046] When the communication session reaches the data communication time threshold or the data communication volume before it ends, repeat steps (3) to (5) in step two to allocate a new negotiation key and continue the communication.
[0047] The above are merely specific embodiments of the present invention, but the design concept of the present invention is not limited thereto. Any non-substantial modifications made to the present invention using this concept shall be considered as infringing upon the protection scope of the present invention.
Claims
1. A method for dynamic key allocation for intelligent connected vehicles, characterized in that, Includes the following steps: Step 1: Set up and store key information, including data impact level. Communication speed requirements Key security tolerance Vehicle-side capability level Key security strength, key distribution strategy, data communication threshold, and key information storage; Step 2: Establish a secure communication channel between the vehicle and the cloud server and distribute keys. The process is as follows: (1) The cloud server bases its decisions on the data impact level. Communication speed requirements Key security tolerance Vehicle-side capability level The key distribution strategy calculates the key strength requirement value QKS: ,in: This indicates the weight value of the data's influence level. Indicates the communication rate weight value. This represents the key security tolerance weight value. This indicates the weight value of the vehicle's capability level. , , , The settings are based on the key allocation strategy and are derived from the training of the agent. (2) The key strength requirement value QKS and the key rated security strength value The comparison yields the key strength requirement level QKG; (3) Obtain the key types supported by the vehicle terminal with a key rated security strength level of QKG from the key information database; when there are multiple key types, use a random algorithm to select the key type, that is, the shared key types of communication sessions with the same key strength requirement level are not the same. (4) Calculate the shared key value based on the selected shared key type; (5) The cloud server transmits the shared key information to the vehicle terminal; Step 3: When the communication session ends, or when the data communication time threshold or data communication volume is reached, change the key.
2. The key dynamic allocation method for intelligent connected vehicles as described in claim 1, characterized in that: The data impact level is specifically determined by first classifying and grading the communication data according to relevant standards. Assuming there are k levels, the larger the value of k, the greater the data impact. The corresponding data impact level value is... .
3. The key dynamic allocation method for intelligent connected vehicles as described in claim 2, characterized in that: A communication data packet between the vehicle and the cloud server may contain multiple data levels. The highest impact level is designated as the data packet. The flag indicating whether a communication data packet contains data of a specific impact level is represented as follows: ,in: * ), 。 4. The key dynamic allocation method for intelligent connected vehicles as described in claim 3, characterized in that: The rated security strength of the key represents a hierarchical definition of the security strength of each type of key according to relevant standards. Assuming the rated security strength of the key is divided into m levels, the rated security strength value for each level is represented as follows: , ,m>
3.
5. The key dynamic allocation method for intelligent connected vehicles as described in claim 4, characterized in that: The formula for calculating the key strength requirement level QKG in step (2) is as follows: ;in, They represent =1 hour The value of .
6. The key dynamic allocation method for intelligent connected vehicles as described in claim 1, characterized in that: The key security tolerance KST represents the key strength value that can be adjusted under specific communication environments, application scenarios, and attack risks. A negative value indicates that the security key strength is reduced during communication, while a positive value indicates that the security key strength is increased during communication.
7. The key dynamic allocation method for intelligent connected vehicles as described in claim 1, characterized in that: The key allocation strategy is divided into two categories based on user-defined criteria: communication rate priority and security strength priority. Communication rate priority means allocating the key with the lowest key strength while meeting security requirements; security strength priority means allocating the key with the highest key strength while meeting communication rate requirements.
8. The key dynamic allocation method for intelligent connected vehicles as described in claim 1, characterized in that: The data communication threshold is a threshold for determining key replacement, including a data communication time threshold or a data communication volume threshold.
9. The key dynamic allocation method for intelligent connected vehicles as described in claim 1, characterized in that: When the communication session ends, wait for the vehicle cloud to re-establish a new communication session, repeat step two, and allocate a new negotiation key; when the communication session has not ended and the data communication time threshold or data communication volume is reached, repeat steps (2) to (5) in step two, allocate a new negotiation key, and continue communication.
10. A key dynamic distribution system for intelligent connected vehicles, characterized in that: This includes cloud server-side and vehicle-side components, among which: The cloud server includes a cloud-based key public opinion module, a cryptographic information database, a cloud-based key management module, a cloud-based business management module, and a cloud-based communication management module. The cloud-based key public opinion module is used to acquire public opinion information about keys, dynamically update key public opinion, and assess attack risks. The cryptographic information database stores key information, including data impact level, communication rate requirements, key rated security strength, vehicle-side capability level, security tolerance, allocation strategy, data communication threshold, and key types supported by the vehicle-side. The cloud-based key management module is used to implement shared key allocation, providing services including key confirmation, key generation, and key calculation. The cloud-based business management module is responsible for processing different business needs. The cloud-based communication management module is responsible for secure communication between the cloud server and the vehicle-side. The vehicle-mounted device has a communication management module, a service management module, and a key management module. The communication management module is responsible for secure communication between the vehicle-mounted device and the cloud server. The service management module is responsible for processing different properties. The key management module is responsible for services including key calculation and storage.
Citation Information
Patent Citations
Internet of vehicles AES encryption method based on multi-agent reinforcement learning
CN118741497A
Dynamic management method and system of secret key
CN119483939A
Multi-link-based data transmission method and system for unmanned vehicle
CN117439941A
Method for sharing cybersecurity threat analysis and defensive measures amongst a community
US20190260783A1