A vehicle networking system communication method and a vehicle networking system
By using system initialization parameters and vehicle reputation parameters in the vehicle-to-everything (V2X) system to verify message trustworthiness and generate offline communication reports, the secure communication problem of the V2X system in scenarios with insufficient infrastructure is solved, achieving sustainable secure communication between vehicles and the system and saving computing overhead.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUIZHOU UNIV
- Filing Date
- 2026-02-11
- Publication Date
- 2026-05-01
AI Technical Summary
Existing vehicle-to-everything (V2X) authentication schemes struggle to achieve real-time identity verification in scenarios with weak or missing infrastructure, leading to a strong dependence on infrastructure and increased computational overhead for vehicle-to-everything (V2X) communication.
By obtaining system initialization parameters and vehicle reputation parameters from trusted facilities between the vehicle and the in-vehicle system, generating in-vehicle communication messages using message construction rules, verifying message trustworthiness, generating offline communication reports, and updating vehicle reputation parameters, sustainable and secure communication between the vehicle and the in-vehicle system can be achieved.
It reduces the dependence of vehicle-to-vehicle communication on infrastructure, simplifies the interaction process, saves communication computing overhead, and enables secure communication between vehicles and the vehicle in offline mode.
Smart Images

Figure CN121692111B_ABST
Abstract
Description
A communication method and a vehicle networking system Technical Field
[0001] This invention relates to the field of vehicle networking technology, and in particular to a vehicle networking system communication method and a vehicle networking system. Background Technology
[0002] Vehicle-to-everything (V2X) communication technologies, including vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication, enable real-time information exchange. As a core supporting technology for intelligent transportation systems, V2X is primarily applied in critical scenarios such as intelligent navigation, cooperative driving, and emergency warnings. Its security directly impacts the reliable operation of transportation networks and the safety of people and property. Identity authentication protocols, serving as the first line of defense in V2X security, ensure the legitimacy of communicating entities and the integrity of messages, preventing unauthorized access and malicious attacks.
[0003] Current mainstream vehicle-to-everything (V2X) authentication schemes generally rely on fixed infrastructure for authentication, such as roadside units and trusted institutions. Their authentication paradigms can be divided into two main categories: one is based on public key infrastructure (PKI), and the other uses identity-based cryptography or attribute-based signature authentication. Both require real-time online access to key parameters or certificate revocation lists. In scenarios with weak or missing infrastructure, such as mountainous areas, tunnels, and remote regions, the inability to obtain the latest parameters and certificates makes it difficult for these authentication schemes to achieve real-time identity verification, severely limiting their applicability. Summary of the Invention
[0004] This invention provides a vehicle-to-everything (V2X) communication method and a V2X system, aiming to achieve sustainable and secure communication between vehicles and the system without relying on fixed infrastructure. This reduces the strong dependence of vehicle-to-everything communication on infrastructure, simplifies the interaction process in V2X communication, and saves communication computing overhead.
[0005] In a first aspect, embodiments of the present invention provide a vehicle-to-everything (V2X) system communication method, applied to a V2X system comprising a trusted facility terminal, at least one first communication vehicle terminal, and at least one second communication vehicle terminal, including:
[0006] The first and second vehicle-mounted communication terminals acquire system initialization parameters and vehicle reputation parameters provided by the trusted facility in the vehicle-mounted network state; wherein, the vehicle reputation parameters are parameters obtained by any vehicle-mounted terminal from the trusted facility describing the degree of trustworthiness of the vehicle-mounted terminal currently recognized by all terminals in the vehicle-mounted network system;
[0007] The first communication vehicle terminal generates and sends vehicle communication messages to the second communication vehicle terminal based on message construction rules, according to the system initialization parameters and the vehicle terminal reputation parameters;
[0008] When the second communication vehicle terminal receives the vehicle communication message, it performs message trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain the message verification result.
[0009] If the message verification result is successful, the second communication vehicle terminal accepts the vehicle communication message and generates an offline communication report based on the message verification result;
[0010] When the vehicle is connected to the network, the second communication vehicle terminal sends the offline communication report to the trusted facility terminal, so that the trusted facility terminal updates the vehicle reputation parameters based on the offline communication report.
[0011] Optionally, when the second communication vehicle terminal receives the vehicle communication message, it performs message trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain a message verification result, including:
[0012] Based on the message construction rules, the system initialization parameters are used to perform signature trust verification on the vehicle-to-machine communication message to obtain the signature verification result.
[0013] If the signature verification result is successful, obtain the current reputation value of the vehicle communication message;
[0014] Based on the current reputation value, the vehicle-to-vehicle communication message is subjected to reputation trust verification to obtain a reputation verification result;
[0015] If the reputation verification result is successful, the message verification result is determined to be successful.
[0016] Optionally, if the signature verification result is successful, obtaining the current reputation value of the vehicle-to-everything (V2X) communication message includes:
[0017] Calculate the time difference data between the current time and the reputation update timestamp of the vehicle-to-everything (V2X) communication message;
[0018] Using an exponential decay mode, the current reputation value is calculated based on the time difference data and the initial reputation of the vehicle in the vehicle communication message;
[0019] The step of performing reputation trust verification on the vehicle-to-everything (V2X) communication message based on the current reputation value to obtain a reputation verification result includes:
[0020] Determine whether the current reputation value is higher than a preset reputation threshold;
[0021] If the current reputation value is determined to be higher than the preset reputation threshold, the reputation verification result is determined to be verified successfully.
[0022] Optionally, the message construction rules include: content combination rules and signature generation rules;
[0023] The process of performing signature verification on the vehicle-to-everything (V2X) communication message based on the message construction rules and using the system initialization parameters to obtain the signature verification result includes:
[0024] Based on the content combination rules, the message content and message signature in the vehicle-to-everything (V2X) communication message are obtained;
[0025] Based on the signature generation rules, the verification signature of the vehicle-to-everything (V2X) communication message is obtained according to the system initialization parameters and the message content.
[0026] If the message signature matches the verification signature, the signature verification result is determined to be successful.
[0027] Optionally, after obtaining the message content and message signature in the vehicle-to-everything (V2X) communication message based on the content combination rules, the method further includes:
[0028] Based on the current timestamp in the message content, determine whether the vehicle-to-everything (V2X) communication message has time validity.
[0029] If it is determined that the vehicle-to-everything (V2X) communication message does not have the required time validity, the signature verification result is determined to be verification failure.
[0030] Optionally, the system initialization parameters include: a system hash function. System generator P and system public key Wherein, the system generator P is defined in the finite field F P Generators on the target non-singular elliptic curve E; system public key , Indicates the system private key;
[0031] The message content includes: the random number pseudonym of the first communication vehicle terminal. The initial reputation of the first communication vehicle terminal Original message and current timestamp ; wherein, the random number pseudonym , are random numbers and ;
[0032] The signature generation rules include: the message signature. ;in, The message hash generated in the first communication vehicle terminal. The reputation signature pre-stored in the first communication vehicle terminal;
[0033] The step of obtaining the verification signature of the vehicle-to-everything (V2X) communication message based on the signature generation rule, the system initialization parameters, and the message content includes:
[0034] Solving the following formula yields the verification signature. :
[0035] .
[0036] Optionally, the vehicle system reputation parameters include: the vehicle system's initial reputation. The reputation signature And vehicle system public key ;
[0037] The first communication vehicle terminal generates and sends vehicle communication messages to the second communication vehicle terminal based on message construction rules, according to the system initialization parameters and the vehicle terminal reputation parameters, including:
[0038] The original message exists. In the case of this, a random number is obtained based on the message construction rules. And according to the random number Generate the random number pseudonym ;
[0039] Get the current timestamp And calculate the message hash ;
[0040] Calculate the message signature based on the signature generation rules. ;
[0041] Based on the content combination rules, and according to the message signature The random number pseudonym The initial reputation of the vehicle system The original message and the current timestamp Generate the vehicle-to-everything (V2X) communication message;
[0042] Send the vehicle communication message to the second communication vehicle terminal.
[0043] Optionally, the first and second communication vehicle terminals, when in a vehicle-to-everything (V2X) network state, obtain system initialization parameters and V2X reputation parameters provided by the trusted facility, including:
[0044] Receive the system initialization parameters broadcast by the trusted facility;
[0045] Generate random challenges And use the vehicle's built-in physical non-cloning function to calculate the hardware fingerprint response. ;
[0046] According to the formula Hardware fingerprint response Perform fuzzy extraction to obtain the hardware key. and assist in data recovery ;
[0047] According to the hardware key and the system hash function Generate vehicle infotainment system private key ;
[0048] According to the vehicle's private key Vehicle identification data Send a vehicle registration request to the trusted facility to obtain the vehicle public key returned by the trusted facility. The initial reputation of the vehicle system and the reputation signature And enable the trusted facility to access the vehicle's public key. and the vehicle identification data Perform the corresponding storage.
[0049] Optionally, after the second communication vehicle terminal sends the offline communication report to the trusted facility terminal while the vehicle terminal is connected to the network, the method further includes:
[0050] Upon receiving the offline communication report, the trusted facility performs a report trust verification on the offline communication report and obtains the report verification result.
[0051] If the report verification result is successful, the vehicle reputation parameter is updated based on the offline communication report.
[0052] Secondly, embodiments of the present invention provide a vehicle-to-everything (V2X) system, including: a trusted facility terminal, at least one first communication vehicle terminal, and at least one second communication vehicle terminal, for implementing the V2X system communication method provided in any embodiment of the present invention.
[0053] This invention provides a vehicle-to-everything (V2X) communication method and system. In a V2X connected state, a first and a second vehicle-to-everything (V2X) terminal acquire system initialization parameters and vehicle reputation parameters provided by a trusted facility. The first V2X terminal generates and sends a V2X communication message to the second V2X terminal based on message construction rules, the system initialization parameters, and the V2X reputation parameters. Upon receiving the V2X communication message, the second V2X terminal performs message trust verification based on the message construction rules and the system initialization parameters, obtaining a verification result. If the verification result is successful, the second V2X terminal accepts the V2X communication message and generates an offline communication report based on the verification result. In a V2X connected state, the offline communication report is sent to the trusted facility, allowing the trusted facility to update the V2X reputation parameters based on the offline communication report. This solves the problem of secure inter-vehicle communication when the communication connection between the vehicle and the trusted facility is offline. It achieves sustainable and secure inter-vehicle communication without relying on fixed infrastructure, reduces the strong dependence of V2X communication on infrastructure, simplifies the interaction process in V2X communication, and saves communication computational overhead. Attached Figure Description
[0054] Figure 1 is a flowchart of a vehicle networking system communication method provided in Embodiment 1 of the present invention;
[0055] Figure 2 is a flowchart of a vehicle networking system communication method provided in Embodiment 2 of the present invention;
[0056] Figure 3 is a schematic diagram of a vehicle networking system provided in Embodiment 3 of the present invention. Detailed Implementation
[0057] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.
[0058] Example 1
[0059] Figure 1 is a flowchart of a vehicle-to-everything (V2X) system communication method provided in Embodiment 1 of the present invention. This embodiment is applicable to secure communication between at least two vehicle-mounted terminals within the same V2X system. The method can be executed by the V2X system, which may include a trusted facility terminal, at least one first communication vehicle-mounted terminal, and at least one second communication vehicle-mounted terminal. The method specifically includes:
[0060] Step 110: The first and second communication vehicle terminals obtain the system initialization parameters and vehicle reputation parameters provided by the trusted facility terminal when the vehicle is connected to the network.
[0061] In this embodiment, both the first and second communication vehicle-mounted terminals are vehicle-mounted terminals in the vehicle-to-everything (V2X) system. The use of "first" and "second" to distinguish between the terminals is intended to describe their respective roles as the sender and receiver in the communication scenario provided, and not to limit any other attributes of them. Typically, any vehicle-mounted terminal in the V2X system that has a message sending requirement in the application scenario can act as the first communication vehicle-mounted terminal, sending communication messages to one or more other vehicle-mounted terminals within a certain range. For example, it could broadcast messages within a certain range. The second communication vehicle-mounted terminal can be a vehicle-mounted terminal near the first communication vehicle-mounted terminal that receives its broadcast message. The trusted facility terminal can include a fixed infrastructure in the V2X system that possesses authority and credibility and is recognized by all terminals. It can be used to provide basic security services such as identity authentication, key management, and trust endorsement. Optionally, the trusted facility terminal can be a Trusted Authority (TA).
[0062] Furthermore, the vehicle-to-everything (V2X) connectivity status can refer to the state where the V2X terminal and the trusted facility maintain a communication connection and are capable of communication. Therefore, when the first and second communicating V2X terminals are in the V2X connectivity status, they can obtain system initialization parameters and V2X reputation parameters provided by the trusted facility. System initialization parameters can be parameters commonly recognized and used by all terminals in the V2X system for encrypting and decrypting communication messages. Since any V2X terminal can obtain system initialization parameters in the V2X connectivity status, it can use these parameters to conduct encrypted communication with other nearby V2X terminals when it is offline and unable to communicate with the trusted facility. V2X reputation parameters can be parameters obtained by any V2X terminal from the trusted facility that describe the trustworthiness of the V2X terminal currently recognized by all terminals in the V2X system. By providing its own V2X reputation parameters to each V2X terminal, the trusted facility enables each V2X terminal to use its own V2X reputation parameters to describe its trustworthiness in communication with other V2X terminals.
[0063] Step 120: The first communication vehicle terminal generates and sends a vehicle communication message to the second communication vehicle terminal based on the message construction rules, according to the system initialization parameters and vehicle reputation parameters.
[0064] Among them, message construction rules can be standardized conventions for the syntax, format, structure, and content composition of communication messages in a vehicle-to-everything (V2X) system. These conventions ensure that messages can be accurately identified, parsed, and processed by both communicating parties. Vehicle-to-everything (V2X) communication messages can be messages that conform to the conventions in the message construction rules and contain the specific content that needs to be communicated.
[0065] Specifically, message construction rules can be pre-agreed between the various terminals of the vehicle-to-everything (V2X) system. When the first communication vehicle-mounted terminal contains specific content that needs to be sent to the second communication vehicle-mounted terminal, it can construct the required content, along with other content specified in the message construction rules, into a vehicle-mounted communication message according to the specific format agreed upon in the message construction rules, using system initialization parameters and its own vehicle-mounted terminal reputation parameters. Typically, based on the message construction rules, specific calculations can be performed on the raw data using system initialization parameters, and the data can be added to the vehicle-mounted communication message in a specific format. This can include the first communication vehicle-mounted terminal's own vehicle-mounted terminal reputation parameters, ensuring that the content of the vehicle-mounted communication message reflects the credibility of the first communication vehicle-mounted terminal.
[0066] Step 130: When the second communication vehicle terminal receives the vehicle communication message, it performs message trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain the message verification result.
[0067] Among them, message trust verification can be an operation to determine whether the vehicle-to-vehicle communication message can be trusted. If the vehicle-to-vehicle communication message is found to be trustworthy, the message verification result will be "verification passed".
[0068] Specifically, when the second communication vehicle terminal receives a vehicle communication message, it can identify and parse the content of the vehicle communication message based on the pre-agreed message construction rules and the system initialization parameters commonly recognized by all terminals of the vehicle network system. For example, it can obtain the credibility of the first communication vehicle terminal as described by the vehicle reputation parameter in the vehicle communication message, thereby performing message credibility verification on the vehicle communication message and obtaining the message verification result.
[0069] Optionally, message trust verification may include verifying the timeliness of vehicle-to-vehicle communication messages, verifying whether the content of vehicle-to-vehicle communication messages can be correctly decrypted, and verifying whether the first vehicle-to-vehicle communication terminal that sent the vehicle-to-vehicle communication messages can be trusted.
[0070] Step 140: If the message verification result is successful, the second communication vehicle terminal accepts the vehicle communication message and generates an offline communication report based on the message verification result.
[0071] Among them, the offline communication report can be data that summarizes and records the reliability of vehicle communication messages locally on the second communication vehicle terminal in a specific form.
[0072] Specifically, a successful message verification result indicates that the first and second communication vehicle-mounted terminals use the same system initialization parameters and message construction rules. Furthermore, the first communication vehicle-mounted terminal described in the vehicle-mounted communication message has a high degree of trustworthiness. Therefore, the vehicle-mounted communication message can be trusted, and the second communication vehicle-mounted terminal can accept the message to enable the transmission of communication content between the two terminals, completing the secure communication between them. Further, the second communication vehicle-mounted terminal can generate an offline communication report locally, recording the content of the vehicle-mounted communication message and / or the trustworthiness of the current message verification result.
[0073] Step 150: When the vehicle-mounted terminal is connected to the network, the second communication vehicle terminal sends an offline communication report to the trusted facility terminal so that the trusted facility terminal updates the vehicle-mounted terminal reputation parameters based on the offline communication report.
[0074] Specifically, when the second communication vehicle-mounted terminal is in a vehicle-to-everything (V2X) network state and establishes a communication connection with the trusted facility, it can send a locally generated offline communication report to the trusted facility. The trusted facility can then update the vehicle-mounted terminal's reputation parameters based on the reliability of the V2X communication messages recorded in the offline communication report. This ensures that the updated V2X reputation parameters recorded in the trusted facility reflect the timely reliability of the vehicle-mounted terminal, allowing any V2X terminal in a V2X network state to use the latest V2X reputation parameters in subsequent communications, thus ensuring communication security.
[0075] The technical solution of this embodiment obtains system initialization parameters and vehicle reputation parameters provided by a trusted facility in the vehicle-to-everything (V2X) state by a first and a second communication vehicle-to-everything (V2X) terminal. The first communication vehicle-to-everything (V2X) terminal generates and sends a V2X communication message to the second communication vehicle-to-everything (V2X) terminal based on message construction rules, the system initialization parameters, and the received V2X communication message. Upon receiving the V2X communication message, the second communication vehicle-to-everything (V2X) terminal performs message trust verification based on the message construction rules and the system initialization parameters, obtaining a message verification result. If the verification result is successful, the second communication vehicle-to-everything (V2X) terminal accepts the V2X communication message and generates an offline communication report based on the verification result. In the V2X state, the offline communication report is sent to the trusted facility, allowing the trusted facility to update the V2X reputation parameters based on the offline communication report. This solves the problem of secure V2X communication being impossible when the communication connection between the vehicle-to-everything (V2X) and the trusted facility is offline. It achieves sustainable and secure V2X communication without relying on fixed infrastructure, reduces the strong dependence of V2X communication on infrastructure, simplifies the interaction process in V2X communication, and saves communication computation overhead.
[0076] Example 2
[0077] Figure 2 is a flowchart of a vehicle-to-everything (V2X) system communication method provided in Embodiment 2 of the present invention. This embodiment further refines the above technical solution, and after the second communication vehicle terminal sends the offline communication report to the trusted facility terminal in the V2X network state, it further includes: upon receiving the offline communication report, the trusted facility terminal performs a report trust verification on the offline communication report to obtain a report verification result; if the report verification result is successful, the vehicle-to-everything reputation parameter is updated based on the offline communication report. The method specifically includes:
[0078] Step 210: The first and second communication vehicle terminals obtain the system initialization parameters and vehicle reputation parameters provided by the trusted facility terminal when the vehicle is connected to the network.
[0079] In one optional implementation, system initialization parameters may include: a system hash function. System generator P and system public key .
[0080] Wherein, the system generator P is defined in the finite field F P Generators on the target non-singular elliptic curve E; system public key , This represents the system's private key.
[0081] Optionally, before the first and second communication vehicle terminals obtain the system initialization parameters and vehicle reputation parameters provided by the trusted facility terminal in the vehicle-to-everything (V2X) state, the process may further include: the trusted facility terminal selecting a value defined in the finite field F. P The target is a non-singular elliptic curve E, whose equation can be expressed as: , Choose a generator P on curve E, whose order is a large prime number q, i.e. If O is a point at infinity, then all points on curve E and O can form an additive cyclic group. Generate system private key Choose a random integer. And calculate the public key. , Among them, public key It can be the system public key used for authentication during communication between the first communication vehicle-to-vehicle unit and the second communication locomotive. This can be a key used by the trusted facility to authenticate the second communication vehicle terminal when the second communication vehicle terminal sends an offline communication report to the trusted facility terminal; a hash function can be selected. , and ; Release system initialization parameters .
[0082] In one optional implementation, the vehicle infotainment system reputation parameter may include: the vehicle infotainment system's initial reputation. Reputation signature And vehicle system public key Among them, the initial reputation of the vehicle system This can be data describing the level of trustworthiness of the vehicle's infotainment system as currently recognized by various terminals within the connected vehicle system. (Reputation signature) This could be a signature obtained from the vehicle's initial reputation through specific computation. (Vehicle's public key) It can be key data that is currently recognized by each terminal of the vehicle networking system for identifying the vehicle terminal and can only be obtained and identified by each terminal of the vehicle networking system.
[0083] In one optional implementation, the vehicle's initial reputation It can be the initial reputation ancestor ,in, This is the initial reputation score, which can specifically be a numerical value corresponding to the level of trustworthiness. It is the initial reputation value update date. It is a reputation feedback value.
[0084] In an optional implementation, the first and second communication vehicle terminals, in the vehicle-to-everything (V2X) network state, obtain system initialization parameters and vehicle reputation parameters provided by the trusted facility. This may include: receiving system initialization parameters broadcast by the trusted facility; and generating random challenges. It also uses the vehicle's built-in Physical Unclonable Function (PUF) to calculate the hardware fingerprint response. According to the formula Hardware fingerprint response Perform fuzzy extraction to obtain the hardware key. and assist in data recovery Where Gen() can represent the generation algorithm for the fuzzy extraction process; based on the hardware key and system hash function Generate vehicle infotainment system private key According to the vehicle's private key Vehicle identification data Send vehicle registration request to trusted facility To obtain the vehicle's public key from the trusted facility. Initial reputation of in-vehicle infotainment system and reputation signature And enable trusted facilities to access the vehicle's public key. Vehicle identification data Perform the corresponding storage.
[0085] Where 'i' represents the vehicle terminal identifier, the first communication vehicle terminal or the second communication vehicle terminal can be the vehicle terminal express.
[0086] Specifically, optionally, the trusted facility receives the vehicle-mounted system registration request. Then, calculate the vehicle's onboard computer. public key The trusted facility can generate an initial reputation tuple. And calculate reputation signature Trusted facility-side storage and will Send to the vehicle's infotainment system .
[0087] In an optional implementation, after the first and second communication vehicle-mounted terminals obtain the system initialization parameters and vehicle reputation parameters provided by the trusted facility in the vehicle-mounted network state, the implementation may further include: the first and second communication vehicle-mounted terminals receiving the user password sent by the vehicle-mounted user. ;Calculate based on user password, system initialization parameters, and vehicle reputation parameters , , and ; Store local encrypted text .
[0088] Accordingly, in an optional implementation, before the first communication vehicle terminal generates and sends a vehicle communication message to the second communication vehicle terminal based on message construction rules, system initialization parameters, and vehicle reputation parameters, it may further include: receiving vehicle identification data sent by the vehicle user. 'and user password ';calculate , , , and and verify The system checks whether the condition is true or false, where Rep() can represent the regeneration algorithm corresponding to the fuzzy extraction process; if true, the current vehicle system user is allowed to log in using the vehicle system's private key. Decrypt to obtain reputation signature and determine its vehicle system public key. .
[0089] Step 220: The first communication vehicle terminal generates and sends vehicle communication messages to the second communication vehicle terminal based on the message construction rules, according to the system initialization parameters and vehicle reputation parameters.
[0090] In one optional implementation, the message construction rules may include: content combination rules and signature generation rules. The signature generation rules may be rules that perform specific operations on specific data content in the vehicle-to-everything (V2X) communication message to obtain a message signature. The content combination rules may be rules governing the data content that needs to be included in the V2X communication message and the specific format in which each data content constitutes the V2X communication message.
[0091] Specifically, in the process of generating vehicle communication messages, the first communication vehicle terminal can first obtain relevant data content and calculate the message signature based on the signature generation rules. Then, based on the content combination rules, it can construct the various data contents, including the message signature, into the final vehicle communication message sent to the second communication vehicle terminal in a specific order and combination manner.
[0092] In one optional implementation, the signature generation rules may include: message signatures. .in, The message hash generated in the first communication vehicle terminal, The reputation signature is pre-stored in the vehicle's infotainment system for the first communication. The vehicle communication messages may include a message signature obtained according to the signature generation rules. And other message content added according to the content combination rules.
[0093] In one optional implementation, the message content may include: a random number pseudonym from the first communication vehicle terminal. The initial reputation of the vehicle's first communication terminal Original message and current timestamp Among them, random number kana. , are random numbers and .
[0094] In an optional implementation, the first communication vehicle terminal generates and sends a vehicle communication message to the second communication vehicle terminal based on message construction rules, according to system initialization parameters and vehicle reputation parameters. This may include: when an original message exists... In this case, random numbers are obtained based on message construction rules. And based on random numbers Generate random number kana Get the current timestamp And calculate message hash Calculate the message signature based on the signature generation rules. Based on content composition rules, according to message signature Random number kana Initial reputation of in-vehicle infotainment system Original message and current timestamp Generate vehicle-to-vehicle communication messages; send vehicle-to-vehicle communication messages to the second communication vehicle terminal.
[0095] Among them, the original message If the primary in-vehicle infotainment system needs to send a message to other nearby in-vehicle infotainment systems in a given application scenario, then this content needs to be securely included in the in-vehicle communication message. Therefore, a specific form of in-vehicle communication message can be generated based on message construction rules.
[0096] In an optional implementation, the first communication vehicle terminal generates and sends vehicle communication messages to the second communication vehicle terminal based on message construction rules, system initialization parameters, and vehicle reputation parameters. This may further include: calculating a reputation hash. .
[0097] In an optional implementation, the first communication vehicle terminal generates and sends vehicle communication messages to the second communication vehicle terminal based on message construction rules, system initialization parameters, and vehicle reputation parameters. This may further include: generating messages based on random numbers. Generate public key pseudonyms Based on random number kana and public key pseudonyms Constructing a pseudonym for vehicle infotainment system .
[0098] Correspondingly, alternatively, based on content composition rules, according to message signatures Random number kana Initial reputation of in-vehicle infotainment system Original message and current timestamp Generate vehicle-to-vehicle communication messages, which can specifically be... .
[0099] Step 230: When the second communication vehicle terminal receives the vehicle communication message, it performs message trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain the message verification result.
[0100] In an optional implementation, when the second communication vehicle terminal receives a vehicle communication message, it performs message trust verification on the vehicle communication message based on message construction rules and system initialization parameters to obtain a message verification result. This may include: performing signature trust verification on the vehicle communication message based on message construction rules and system initialization parameters to obtain a signature verification result; if the signature verification result is successful, obtaining the current reputation value of the vehicle communication message; performing reputation trust verification on the vehicle communication message based on the current reputation value to obtain a reputation verification result; and if the reputation verification result is successful, determining that the message verification result is successful.
[0101] Among them, signature trust verification can be an operation to determine whether the message signature in the vehicle-to-vehicle communication message is trustworthy. The message signature can be obtained by performing a specific form of operation on other content in the vehicle-to-vehicle communication message according to the message construction rules and system initialization parameters.
[0102] Specifically, according to the message construction rules, the first communication vehicle-to-vehicle terminal can use system initialization parameters to perform specific operations on specific content during the generation of vehicle-to-vehicle communication messages to generate a message signature. Therefore, the second communication vehicle-to-vehicle terminal can perform signature trust verification upon receiving a vehicle-to-vehicle communication message. Based on its pre-obtained system initialization parameters and message construction rules, the second communication vehicle-to-vehicle terminal performs specific operations on specific content in the vehicle-to-vehicle communication message, and verifies whether a message signature consistent with the received vehicle-to-vehicle communication message can be generated to achieve signature trust verification.
[0103] In one optional implementation, based on message construction rules, the signature of the vehicle-to-vehicle communication message is verified using system initialization parameters to obtain a signature verification result. This may include: obtaining the message content and message signature in the vehicle-to-vehicle communication message based on content combination rules; obtaining the verification signature of the vehicle-to-vehicle communication message based on signature generation rules, according to system initialization parameters and message content; and determining that the signature verification result is successful if the message signature and the verification signature are consistent.
[0104] Specifically, the signature verification is a message signature obtained by performing calculations on the message content of the vehicle-to-vehicle communication message actually received by the second communication vehicle-to-vehicle terminal according to a specific form of operation in the preset signature generation rules. If the first and second communication vehicle-to-vehicle terminals use the same signature generation rules and the message content is also normal, the verification signature will be consistent with the message signature of the vehicle-to-vehicle communication message. Therefore, the signature verification result can be obtained accordingly.
[0105] In an optional implementation, obtaining the verification signature of the vehicle-to-everything (V2X) communication message based on the signature generation rules, system initialization parameters, and message content may include: solving the following formula to obtain the verification signature. :
[0106] .
[0107] Specifically, the above formula can be determined based on message construction rules and the physical meaning of each system initialization parameter and vehicle reputation parameter. The specific determination process can be explained by the following formula: .
[0108] In one optional implementation, based on message construction rules, the system initialization parameters are used to perform signature trust verification on the vehicle-to-vehicle communication messages to obtain the signature verification result. Alternatively, signature trust verification can be performed on a batch of vehicle-to-vehicle communication messages. Specifically, the second communication vehicle terminal can receive n vehicle-to-vehicle communication messages from the first communication vehicle terminal, where n≥2, and a random small exponential vector can be selected. ,in , l is a very small integer, which can be used for batch verification based on small exponent testing, and can be selected according to the required security level; to verify whether it is true or false.
[0109] In an optional implementation, after obtaining the message content and message signature in the vehicle-to-everything (V2X) communication message based on the content combination rules, the method may further include: determining whether the V2X communication message has time validity based on the current timestamp in the message content; and if it is determined that the V2X communication message does not have time validity, determining that the signature verification result is verification failure.
[0110] The current timestamp can be the timestamp corresponding to the generation time of the vehicle-to-everything (V2X) communication message. By checking the freshness of the current timestamp, it can be determined whether the V2X communication message has time validity, thereby discarding invalid messages.
[0111] Specifically, the second communication vehicle terminal Received message Then, you can first check the current timestamp. Freshness is assessed, and invalid messages are discarded; subsequently, calculations can be performed. and and verify the signature. Whether it is valid or not.
[0112] Furthermore, the current reputation value can be a numerical value describing the trustworthiness of the first communication vehicle terminal at the current moment. Reputation trustworthiness verification can be an operation to determine whether the trustworthiness of the first communication vehicle terminal described by the current reputation value is high enough at the current moment. Therefore, if both signature trustworthiness verification and reputation trustworthiness verification pass simultaneously, it can be concluded that the signature of the vehicle communication message is secure and the first communication vehicle terminal is trustworthy, and the message verification result can be determined as successful.
[0113] In an optional implementation, if the signature verification result is successful, obtaining the current reputation value of the vehicle-to-everything (V2X) communication message may include: calculating the time difference data between the current time and the reputation update timestamp of the V2X communication message; and using an exponential decay mode, calculating the current reputation value based on the time difference data and the initial reputation of the V2X in the V2X communication message.
[0114] Among them, the reputation update timestamp can be the timestamp corresponding to the moment when the vehicle's initial reputation was acquired in the vehicle-to-vehicle communication message.
[0115] Specifically, considering the possible changes in the credibility of the first communication vehicle terminal between the time when it obtains the initial reputation of the vehicle terminal from the trusted facility in the vehicle-to-everything (V2X) state and the current time, the current reputation value can be calculated based on the time difference data, and the current reputation value can be used to determine whether the first communication vehicle terminal is sufficiently trustworthy at the current time.
[0116] Correspondingly, the reputation credibility verification of the vehicle-to-everything (V2X) communication message can be performed based on the current reputation value to obtain the reputation verification result. This may include: determining whether the current reputation value is higher than a preset reputation threshold; and if the current reputation value is higher than the preset reputation threshold, determining that the reputation verification result is a successful verification.
[0117] The preset reputation threshold serves as a numerical boundary for distinguishing whether a vehicle-mounted terminal is trustworthy. If the current reputation value of any vehicle-mounted terminal is higher than the preset reputation threshold, it indicates that the terminal is trustworthy; conversely, if it is lower, it indicates that the terminal is untrustworthy. Therefore, when the current reputation value of the first communicating vehicle-mounted terminal is higher than the preset reputation threshold, the reputation verification result can be determined as successful.
[0118] Specifically, the second communication vehicle terminal For each message whose signature verification is successful It can calculate the current time. Reputation value and reputation update timestamp The difference The current reputation value is calculated using an exponential decay model. Determine the current reputation value Is it higher than the preset reputation threshold? If yes, accept the message; otherwise, discard the message.
[0119] Step 240: If the message verification result is successful, the second communication vehicle terminal accepts the vehicle communication message and generates an offline communication report based on the message verification result.
[0120] In one optional implementation, the second communication vehicle terminal For the received message It can generate offline communication reports. ,in This is the report timestamp corresponding to the offline communication report generation time. It's feedback rating. and These represent positive and negative feedback, respectively.
[0121] In an optional implementation, when the second communication vehicle terminal is in an offline state and unable to communicate with the trusted facility, offline communication reports can be stored. Since vehicle storage space is limited, optionally, when the stored offline communication reports reach their capacity limit, a dynamic storage management strategy of prioritizing and overwriting lower-weight offline communication reports can be adopted. Specifically, the weights can be determined according to the following formula: Second communication vehicle terminal storage .
[0122] Step 250: When the vehicle-mounted terminal is connected to the network, the second communication terminal sends the offline communication report to the trusted facility terminal.
[0123] Step 260: Upon receiving an offline communication report, the trusted facility verifies the trustworthiness of the offline communication report and obtains the report verification result. If the report verification result is successful, the vehicle system reputation parameters are updated based on the offline communication report.
[0124] Among them, report trust verification can be an operation to determine whether the received offline communication report is trustworthy.
[0125] Specifically, when the second communication vehicle-mounted terminal is in a vehicle-mounted network state, it can send the offline communication reports generated and / or stored therein to the trusted facility terminal through a communication connection. Upon receiving any offline communication report, the trusted facility terminal can first perform a report trust verification, which may include judging the trustworthiness of the second communication vehicle-mounted terminal. If the report verification result is successful, ensuring the trustworthiness of the offline communication report, the trusted facility terminal can update relevant vehicle-mounted terminal reputation parameters based on the communication information between the vehicle-mounted terminals recorded in the offline communication report, such as the initial reputation of the first communication vehicle-mounted terminal.
[0126] In an optional implementation, the trusted facility may include a first trusted facility and a second trusted facility. The first trusted facility may refer to a trusted facility used to store all data content recognized by the vehicle-to-everything (V2X) system, and can directly communicate with vehicle-mounted terminals in its vicinity and with each second trusted facility. The second trusted facility may refer to a trusted facility deployed over a wider area, enabling direct communication with vehicle-mounted terminals within its deployment range, thereby allowing vehicle-mounted terminals within that range to indirectly communicate with the first trusted facility through the second trusted facility.
[0127] In one optional implementation, the first trusted facility and the second trusted facility can be a TA and an RSU (Road Side Unit), respectively. Optionally, the RSU can initiate a registration request to the TA in advance, the TA generates a private key for the RSU, and stores the RSU registration information in the database to complete the RSU registration.
[0128] When the second communication vehicle-mounted unit connects to the RSU, it can communicate with the TA through the RSU. Specifically, optionally, upon receiving an offline communication report, the trusted facility verifies the report's trustworthiness and obtains a verification result; if the verification result is successful, it updates the vehicle-mounted unit's reputation parameters based on the offline communication report. This can be jointly implemented by the RSU and the TA.
[0129] In an optional implementation, when the second communication vehicle terminal Connect to trusted facility When selecting a random number Using Chebyshev polynomials to compute two temporary parameters and ; Generate kana And encrypt offline communication reports as ; Calculate authentication parameters and the authentication request Send to .in, For authentication request The corresponding current timestamp.
[0130] Trusted facility side Received message Next, verify the timestamp. The validity of the certificate is then evaluated, and the authentication parameters are calculated. and authentication message Send it to TA. Among them, For authentication messages The corresponding current timestamp.
[0131] TA inspection Freshness, and verification The legality. Then, TA calculates. and TA verification Is it true? If true, decrypt. Where D can represent the decryption operation using the symmetric encryption algorithm AES (Advanced Encryption Standard). For each feedback message... TA calculates the corresponding vehicle-mounted system. public key Find and update the database based on the public key. Reputation feedback value Reputation feedback values can represent the performance of the in-vehicle infotainment system. After a message is sent, the system receives a total of the credibility feedback from other receiving in-vehicle systems in the offline in-vehicle system report. The system can then update the corresponding in-vehicle system based on the feedback score in the message. The reputation feedback value. For vehicle-mounted systems requesting reputation updates. TA calculates its latest reputation score. Update the vehicle infotainment system The original reputation of the ancestor is ,in, This is the current timestamp. Then, TA calculates the new reputation signature. Encrypted reputation information Here, E can represent the encryption operation using AES. Finally, TA calculates the authentication parameters. and message Return to .in, For the message The corresponding current timestamp.
[0132] receive Afterwards, check The freshness, and then the message Return to vehicle infotainment system .in, For the message The corresponding current timestamp.
[0133] In-vehicle infotainment system Received message Then, check the timestamp. Freshness. Then, decipher... To obtain new reputation information, i.e. Then, verify. If the verification is successful, the authenticity of the message is ensured. Update stored reputation information and .
[0134] The technical solution of this embodiment, when the vehicle-mounted terminal briefly connects to the RSU, batches and synchronizes the other vehicle behavior feedback collected during the offline phase to the TA, and simultaneously obtains the latest reputation certificate issued by the TA. This effectively solves the trust lag caused by the offline phase. In addition, this phase only uses lightweight cryptographic operations, significantly reducing computational overhead.
[0135] Example 3
[0136] Figure 3 is a schematic diagram of a vehicle-to-everything (V2X) system according to Embodiment 3 of the present invention. As shown in Figure 3, the V2X system includes: a trusted facility terminal 310, at least one first communication vehicle terminal 320, and at least one second communication vehicle terminal 330. This V2X system can be used to implement the V2X system communication method provided in any embodiment of the present invention.
[0137] Among them, the first communication vehicle terminal 320 and the second communication vehicle terminal 330 obtain system initialization parameters and vehicle reputation parameters provided by the trusted facility terminal 310 when the vehicle terminal is connected to the network.
[0138] The first communication vehicle terminal 320 generates and sends vehicle communication messages to the second communication vehicle terminal 330 based on message construction rules, according to the system initialization parameters and the vehicle reputation parameters;
[0139] When the second communication vehicle terminal 330 receives the vehicle communication message, it performs message trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain the message verification result.
[0140] If the message verification result is successful, the second communication vehicle terminal 330 accepts the vehicle communication message and generates an offline communication report based on the message verification result.
[0141] When the vehicle is connected to the network, the second communication vehicle terminal 330 sends the offline communication report to the trusted facility terminal 310, so that the trusted facility terminal 310 updates the vehicle reputation parameters according to the offline communication report.
[0142] Optionally, when the second communication vehicle terminal 330 receives the vehicle communication message, it performs message trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain a message verification result. Specifically, it can be configured to: perform signature trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain a signature verification result; if the signature verification result is successful, obtain the current reputation value of the vehicle communication message; perform reputation trust verification on the vehicle communication message based on the current reputation value to obtain a reputation verification result; if the reputation verification result is successful, determine that the message verification result is successful.
[0143] Optionally, if the signature verification result is successful, the second communication vehicle terminal 330 obtains the current reputation value of the vehicle communication message. Specifically, this can be configured to: calculate the time difference data between the current time and the reputation update timestamp of the vehicle communication message; calculate the current reputation value using an exponential decay mode based on the time difference data and the initial reputation of the vehicle in the vehicle communication message; and perform reputation trust verification on the vehicle communication message based on the current reputation value to obtain a reputation verification result. Specifically, this can be configured to: determine whether the current reputation value is higher than a preset reputation threshold; and if the current reputation value is higher than the preset reputation threshold, determine that the reputation verification result is successful.
[0144] Optionally, the message construction rules may include: content combination rules and signature generation rules; the second communication vehicle terminal 330 performs signature trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain a signature verification result. Specifically, it can be configured to: obtain the message content and message signature in the vehicle communication message based on the content combination rules; obtain the verification signature of the vehicle communication message based on the signature generation rules, according to the system initialization parameters and the message content; and determine that the signature verification result is verified as successful if the message signature matches the verification signature.
[0145] Optionally, after the second communication vehicle terminal 330 obtains the message content and message signature in the vehicle communication message based on the content combination rule, it can be specifically configured to: determine whether the vehicle communication message has time validity based on the current timestamp in the message content; if it is determined that the vehicle communication message does not have time validity, determine that the signature verification result is verification failure.
[0146] Optionally, the system initialization parameters include: a system hash function. System generator P and system public key Wherein, the system generator P is defined in the finite field F P Generators on the target non-singular elliptic curve E; system public key , The message content includes: a random number pseudonym from the first communication vehicle terminal. The initial reputation of the first communication vehicle terminal Original message and current timestamp ; wherein, the random number pseudonym , are random numbers and The signature generation rules include: the message signature. ;in, The message hash generated in the first communication vehicle terminal. The first communication vehicle terminal 330 uses a reputation signature pre-stored in the system; the second communication vehicle terminal 330, based on the signature generation rule, obtains a verification signature for the vehicle communication message according to the system initialization parameters and the message content. Specifically, this can be configured to: solve the following formula to obtain the verification signature. : .
[0147] Optionally, the vehicle system reputation parameters include: the vehicle system's initial reputation. The reputation signature And vehicle system public key The first communication vehicle terminal 320 generates and sends a vehicle communication message to the second communication vehicle terminal based on message construction rules, according to the system initialization parameters and the vehicle terminal reputation parameters. Specifically, it can be configured to: when the original message exists... In the case of this, a random number is obtained based on the message construction rules. And according to the random number Generate the random number pseudonym ; Obtain the current timestamp And calculate the message hash ; Calculate the message signature based on the signature generation rules. Based on the content combination rules, and according to the message signature... The random number pseudonym The initial reputation of the vehicle system The original message and the current timestamp Generate the vehicle-to-vehicle communication message; send the vehicle-to-vehicle communication message to the second communication vehicle terminal 330.
[0148] Optionally, the first communication vehicle terminal 320 and the second communication vehicle terminal 330 obtain system initialization parameters and vehicle reputation parameters provided by the trusted facility terminal when the vehicle is connected to the network. Specifically, this can be configured to: receive the system initialization parameters broadcast by the trusted facility terminal 310; and generate random challenges. And use the vehicle's built-in physical non-cloning function to calculate the hardware fingerprint response. According to the formula Hardware fingerprint response Perform fuzzy extraction to obtain the hardware key. and assist in data recovery According to the hardware key and the system hash function Generate vehicle infotainment system private key According to the vehicle's private key Vehicle identification data Send a vehicle registration request to the trusted facility 310 to obtain the vehicle public key returned by the trusted facility 310. The initial reputation of the vehicle system and the reputation signature And enable the trusted facility terminal 310 to access the vehicle's public key. and the vehicle identification data Perform the corresponding storage.
[0149] Optionally, after the second communication vehicle terminal 330 sends the offline communication report to the trusted facility terminal 310 in the vehicle network state, the trusted facility terminal 310 can be specifically configured as follows: upon receiving the offline communication report, the trusted facility terminal 310 performs a report trust verification on the offline communication report to obtain a report verification result; if the report verification result is successful, the trusted facility terminal 310 updates the vehicle reputation parameter according to the offline communication report.
[0150] The technical solution of this embodiment obtains system initialization parameters and vehicle reputation parameters provided by a trusted facility in the vehicle-to-everything (V2X) state by a first and a second communication vehicle-to-everything (V2X) terminal. The first communication vehicle-to-everything (V2X) terminal generates and sends a V2X communication message to the second communication vehicle-to-everything (V2X) terminal based on message construction rules, the system initialization parameters, and the received V2X communication message. Upon receiving the V2X communication message, the second communication vehicle-to-everything (V2X) terminal performs message trust verification based on the message construction rules and the system initialization parameters, obtaining a message verification result. If the verification result is successful, the second communication vehicle-to-everything (V2X) terminal accepts the V2X communication message and generates an offline communication report based on the verification result. In the V2X state, the offline communication report is sent to the trusted facility, allowing the trusted facility to update the V2X reputation parameters based on the offline communication report. This solves the problem of secure V2X communication being impossible when the communication connection between the vehicle-to-everything (V2X) and the trusted facility is offline. It achieves sustainable and secure V2X communication without relying on fixed infrastructure, reduces the strong dependence of V2X communication on infrastructure, simplifies the interaction process in V2X communication, and saves communication computation overhead.
Claims
1. A communication method for a vehicle-to-everything (V2X) system, characterized in that, An application to a vehicle-to-everything (V2X) system comprising a trusted facility, at least one first communication vehicle-mounted terminal, and at least one second communication vehicle-mounted terminal, comprising: the first and second communication vehicle-mounted terminals acquiring system initialization parameters and vehicle-mounted reputation parameters provided by the trusted facility in a V2X network state; wherein, the vehicle-mounted reputation parameters are parameters obtained by any vehicle-mounted terminal from the trusted facility describing the trustworthiness of the vehicle-mounted terminal currently commonly recognized by all terminals in the V2X system; the first communication vehicle-mounted terminal generating and sending a vehicle-mounted communication message to the second communication vehicle-mounted terminal based on message construction rules, according to the system initialization parameters and the vehicle-mounted reputation parameters; and the second communication vehicle-mounted terminal, upon receiving the vehicle-mounted communication message, performing vehicle-mounted communication based on the message construction rules and the system initialization parameters. The message undergoes message trust verification to obtain a message verification result; wherein, the message construction rules are pre-agreed among the various terminals of the vehicle network system; the message trust verification includes: obtaining the trustworthiness level of the first communication vehicle terminal described by the vehicle reputation parameter in the vehicle communication message based on the message construction rules, thereby performing the message trust verification on the vehicle communication message to obtain the message verification result; if the message verification result is successful, the second communication vehicle terminal accepts the vehicle communication message and generates an offline communication report based on the message verification result; in the vehicle network state, the second communication vehicle terminal sends the offline communication report to the trusted facility terminal, so that the trusted facility terminal updates the vehicle reputation parameter based on the offline communication report.
2. The method according to claim 1, characterized in that, When the second communication vehicle terminal receives the vehicle communication message, it performs message trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain a message verification result. This includes: performing signature trust verification on the vehicle communication message based on the message construction rules and the system initialization parameters to obtain a signature verification result; if the signature verification result is successful, obtaining the current reputation value of the vehicle communication message; performing reputation trust verification on the vehicle communication message based on the current reputation value to obtain a reputation verification result; and if the reputation verification result is successful, determining that the message verification result is successful.
3. The method according to claim 2, characterized in that, If the signature verification result is successful, obtaining the current reputation value of the vehicle-to-everything (V2X) communication message includes: calculating the time difference data between the current time and the reputation update timestamp of the V2X communication message; using an exponential decay mode, calculating the current reputation value based on the time difference data and the initial reputation of the V2X communication message; and performing reputation credibility verification on the V2X communication message based on the current reputation value to obtain a reputation verification result, including: determining whether the current reputation value is higher than a preset reputation threshold; and if the current reputation value is higher than the preset reputation threshold, determining that the reputation verification result is successful.
4. The method according to claim 2, characterized in that, The message construction rules include: content combination rules and signature generation rules; the step of performing signature trust verification on the vehicle-to-vehicle communication message based on the message construction rules and using the system initialization parameters to obtain a signature verification result includes: obtaining the message content and message signature in the vehicle-to-vehicle communication message based on the content combination rules; obtaining the verification signature of the vehicle-to-vehicle communication message based on the signature generation rules, according to the system initialization parameters and the message content; and determining that the signature verification result is verified as successful if the message signature matches the verification signature.
5. The method according to claim 4, characterized in that, After obtaining the message content and message signature in the vehicle-to-everything (V2X) communication message based on the content combination rules, the method further includes: determining whether the V2X communication message has time validity based on the current timestamp in the message content; and determining that the signature verification result is verification failure if it is determined that the V2X communication message does not have time validity.
6. The method according to claim 4, characterized in that, The system initialization parameters include: system hash function System generator P and system public key Wherein, the system generator P is defined in the finite field F P Generators on the target non-singular elliptic curve E; system public key , The message content includes: a random number pseudonym from the first communication vehicle terminal. The initial reputation of the first communication vehicle terminal Original message and current timestamp ; wherein, the random number pseudonym , are random numbers and The signature generation rules include: the message signature. ;in, The message hash generated in the first communication vehicle terminal. The first communication vehicle terminal uses a reputation signature pre-stored in the terminal; the step of obtaining a verification signature for the vehicle communication message based on the signature generation rule, the system initialization parameters, and the message content includes: solving the following formula to obtain the verification signature. : 。 7. The method according to claim 6, characterized in that, The vehicle infotainment system reputation parameters include: the initial reputation of the vehicle infotainment system. The reputation signature And vehicle system public key The first communication vehicle terminal generates and sends a vehicle communication message to the second communication vehicle terminal based on message construction rules, according to the system initialization parameters and the vehicle terminal reputation parameters, including: when the original message exists... In the case of this, a random number is obtained based on the message construction rules. And according to the random number Generate the random number pseudonym ; Obtain the current timestamp And calculate the message hash ; Calculate the message signature based on the signature generation rules. Based on the content combination rules, and according to the message signature... The random number pseudonym The initial reputation of the vehicle system The original message and the current timestamp Generate the vehicle-to-vehicle communication message; send the vehicle-to-vehicle communication message to the second communication vehicle terminal.
8. The method according to claim 7, characterized in that, When the first and second vehicle-mounted communication terminals are connected to the network, they acquire system initialization parameters and vehicle reputation parameters provided by the trusted facility terminal, including: receiving the system initialization parameters broadcast by the trusted facility terminal; and generating a random challenge. And use the vehicle's built-in physical non-cloning function to calculate the hardware fingerprint response. According to the formula Hardware fingerprint response Perform fuzzy extraction to obtain the hardware key. and assist in data recovery According to the hardware key and the system hash function Generate vehicle infotainment system private key According to the vehicle's private key Vehicle identification data Send a vehicle registration request to the trusted facility to obtain the vehicle public key returned by the trusted facility. The initial reputation of the vehicle system and the reputation signature And enable the trusted facility to access the vehicle's public key. and the vehicle identification data Perform the corresponding storage.
9. The method according to claim 1, characterized in that, After the second communication vehicle terminal sends the offline communication report to the trusted facility terminal in the vehicle network state, the method further includes: when the trusted facility terminal receives the offline communication report, it performs a report trust verification on the offline communication report to obtain a report verification result; if the report verification result is successful, it updates the vehicle reputation parameter according to the offline communication report.
10. A vehicle-to-everything (V2X) system, comprising a trusted facility terminal, at least one first communication vehicle terminal, and at least one second communication vehicle terminal, characterized in that, Used to implement the vehicle network system communication method as described in claim 1.
Citation Information
Patent Citations
Dual authentication key negotiation method for vehicle networking commuting
CN120499654A