Communication gateway device based on DBC encryption
By using the RK3576 and RK3588 chip stacking structure and various scrambling algorithms, encryption processing of multiple vehicle protocols is achieved, solving the compatibility and latency issues of existing gateway devices and improving the security and stability of vehicle network communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-03-24
AI Technical Summary
In existing vehicle-to-everything (V2X) communication systems, gateway devices lack targeted encryption mechanisms, are incompatible with multiple vehicle protocols, suffer from high communication latency, and employ a single encryption algorithm. This makes data transmission vulnerable to malicious attacks, and the confidentiality and integrity of the data cannot be effectively guaranteed.
Employing a stacked structure of RK3576 and RK3588 chips and various scrambling algorithms, it achieves encrypted processing of multi-protocol data such as CAN-FD, LIN, and FlexRay. Through a multi-channel independent bidirectional communication design and high-performance chip support, it reduces communication latency and supports encryption of multiple protocol files such as DBC, LDF, and XML, making it compatible with different vehicle communication scenarios.
It ensures the confidentiality and integrity of data, reduces communication latency, meets the real-time communication needs of vehicles, effectively prevents data leakage and tampering, and improves the stability and security of the vehicle networking system.
Smart Images

Figure CN121728374A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of encrypted communication gateways, and particularly relates to a DBC-based encrypted communication gateway device. BACKGROUND
[0002] With the rapid development of intelligent transportation technology, the Internet of Vehicles has become a core hub connecting vehicles, roads and clouds, and the security of data transmission thereof is directly related to vehicle driving safety and user information protection. As a key intermediate node for communication between ECUs and external devices in the Internet of Vehicles, a gateway bears the core role of data forwarding and protocol conversion, and the security thereof directly determines the reliability of data transmission in the Internet of Vehicles, and is of great significance to guarantee stable operation of a vehicle-mounted system and prevent malicious attacks. DBC is a standard protocol database file for describing CAN network signal and message structure, and is a basic specification for vehicle-mounted communication data interaction. DBC encrypted communication refers to encrypted processing of vehicle-mounted communication data based on the DBC protocol, and ensures that data is not leaked or tampered with in the transmission process by standardizing data encryption rules and clearly defining encryption objects and processes, thereby providing security support for vehicle-mounted multi-protocol communication and being one of the core technologies for improving communication security in the Internet of Vehicles.
[0003] However, the existing gateway device in the existing Internet of Vehicles communication system still has certain defects. The existing gateway device lacks a targeted encryption mechanism and relies on a single communication protocol, cannot be compatible with CAN-FD, LIN, FlexRay and other vehicle-mounted protocols, and is difficult to meet the needs of complex vehicle-mounted communication scenarios. The performance of the processing chip used is insufficient, and the multi-channel independent bidirectional communication cannot be realized, which causes high communication delay and affects the real-time communication effect of the vehicle-mounted system. The encryption algorithm is single, and the encryption support for DBC, LDF, XML and other protocol files is insufficient, and the encryption file acquisition method is limited, which causes the data transmission to be vulnerable to malicious attacks, and the confidentiality, integrity and availability cannot be effectively guaranteed. Therefore, it is of great significance to develop a DBC-based encrypted communication gateway device. SUMMARY
[0004] The application aims to make up for the deficiencies in the prior art, and provides a DBC-based encrypted communication gateway device, which can realize encrypted processing of CAN-FD, LIN, FlexRay and other multi-protocol data by adopting an RK3576 and RK3588 chip stacking structure and a variety of scrambling algorithms, guarantee data confidentiality and integrity, reduce communication delay by means of multi-channel independent bidirectional communication design and high-performance chip support, meet the needs of real-time vehicle-mounted communication, support DBC, LDF, XML and other protocol file encryption by means of Ethernet remote and USB local encryption file acquisition, and be compatible with different vehicle-mounted communication scenarios.
[0005] The application provides the following technical scheme to solve the above technical problems: a DBC-based encrypted communication gateway device, which comprises a device shell, a communication interface module, an encryption processing module, a storage module, a power supply module and a control module, wherein the communication interface module, the encryption processing module, the storage module, the power supply module and the control module are all installed inside the device shell. The communication interface module comprises a CAN-FD channel, a LIN channel, a FlexRay channel, an Ethernet interface and a USB interface, receives bidirectional data of an ECU and a bench device and transmits the data to the encryption processing module, and simultaneously obtains encrypted files through the Ethernet interface or the USB interface and transmits the files to the storage module. The encryption processing module adopts an RK3576 and RK3588 chip stacking structure, carries multiple scrambling algorithms, calls encrypted files and adaptive algorithms from the storage module, and feeds back the encrypted and decrypted data of the communication interface module to the communication interface module. The storage module receives and stores encrypted files, vehicle-mounted communication protocol data and communication cache data, and responds to data reading requests of each module. The power supply module is electrically connected with each module to provide power supply, and the control module is electrically connected with each module to schedule the work flow of each module and coordinate the data transmission and processing timing.
[0006] Further, the encryption processing module performs the following operations when performing encryption processing on communication data: receives original communication data transmitted by the communication interface module, and simultaneously calls corresponding encrypted files and scrambling algorithms adaptive to the current communication protocol from the storage module; performs format analysis on the original communication data, extracts valid information fields and eliminates redundant data; preliminarily encrypts the analyzed valid information fields through an RK3576 chip, generates intermediate encrypted data by using a hybrid encryption function, and the calculation formula is as follows: wherein, is the preliminary encrypted data, is the analyzed valid information field, is a basic encryption function based on data bit operation, is an auxiliary encryption function based on data checksum, , is a weighting coefficient, is an offset, and based on the transmission characteristics of different protocols of CAN-FD, LIN and FlexRay, 1000 groups of measured communication data are trained and calibrated to obtain is a preset fixed value in the encrypted file, which corresponds to the protocol type one by one. The intermediate encrypted data is transmitted to the RK3588 chip, and secondary encryption is performed through another scrambling algorithm to form final encrypted data, and the calculation formula is: wherein, is the final encrypted data, is a deep encryption function based on a nonlinear transformation, is a strength adjustment coefficient, is a key segment extracted from the encrypted file, is an exclusive or operation, is determined by the control module based on historical encryption success rate according to the data sensitivity level, is a key segment stored in the encrypted file according to the protocol type, and is extracted by synchronously verifying when obtained through an Ethernet or USB interface; The final encrypted data is fed back to the communication interface module and transmitted to the target device through the corresponding channel.
[0007] Further, the communication interface module performs the following operations when obtaining encrypted files and transmitting data: According to the application scenario, the encrypted file acquisition method is selected, and when remotely acquiring, the Ethernet interface is connected with the cloud server, and when locally acquiring, the USB interface is connected with the storage medium; Verify the legality and stability of the connection, complete the encrypted file transmission and reception, and the encrypted file includes protocol files in DBC format, LDF format and XML format; According to the communication protocol type, the corresponding channel is selected, the CAN-FD channel is used for high data rate and large capacity data transmission, the LIN channel is used for low speed communication scene, and the FlexRay channel is used for high speed real-time communication scene; The received encrypted file is transmitted to the storage module, and the data to be transmitted is transmitted to the encryption processing module, and after encryption is completed, the data is transmitted through the selected channel.
[0008] Further, the control module performs the following operations when performing multi-channel scheduling and module coordination: Real-time acquisition of communication interface module channel connection state, data transmission request and encryption processing module workload data; According to the channel data transmission priority and the encryption processing module load condition, a scheduling strategy is made, and independent communication resources are allocated to each channel to prevent data conflict between channels; Send control instructions to the encryption processing module to specify the data processing order and the scrambling algorithm type; Real-time monitoring of the storage capacity of the storage module, sending data cleaning instructions when reaching the preset threshold, retaining core data and deleting expired cache data; The power supply module outputs parameters are monitored, and a shutdown protection instruction is sent when an abnormality occurs to cut off the power supply of the non-core module.
[0009] Further, the storage module performs the following operations when storing and managing data: Receiving encrypted files and various encrypted data transmitted by the encryption processing module and the communication interface module, establishing classified storage directories according to data types, separately dividing storage areas for encrypted files and setting access permissions; Performing integrity checking on received storage data to detect whether the data is missing or damaged, and sending an alarm signal to the control module when an abnormality is found; Setting storage priorities according to data usage frequency and validity period, storing high-frequency usage data in a high-speed storage area, and storing low-frequency usage data in a normal storage area; Receiving read instructions from the control module and the encryption processing module, retrieving target data and feeding back to the request module, and recording data read time and usage times.
[0010] Further, the encryption processing module is equipped with a scrambling algorithm including a symmetric encryption algorithm and an asymmetric encryption algorithm, the symmetric encryption algorithm is used for encryption and decryption of regular communication data, and the asymmetric encryption algorithm is used for encryption and decryption of encrypted files and key data, the asymmetric encryption of key data uses the formula: wherein, is the encrypted key data key, is the receiver's public key, is the original key data key, is the key validity verification parameter, is the device identity factor, is carried in the encrypted file obtained by the Ethernet interface, which is a 256-bit public key data, is obtained by taking the modulus 100 of the CRC32 check code of the encrypted file in the storage module, is a parameter solidified by the unique hardware identification of the device, and the value is the decimal value converted from the device MAC address, the RK3576 chip and the RK3588 chip are connected through a high-speed data bus to realize encrypted data interaction, and the chip stacking structure is designed with heat dissipation optimization, the chip surface is attached to a heat pad, and the end of the heat pad away from the chip is connected to the inner wall of the device shell to improve the heat conduction efficiency.
[0011] Further, the CAN-FD channel transmission rate of the communication interface module is higher than that of the traditional CAN protocol, the LIN channel adopts a master-slave communication architecture, supports simultaneous access of multiple slave devices, the FlexRay channel adopts a dual-channel design, the Ethernet interface supports a gigabit network transmission rate, the USB interface adopts the USB3.0 standard, each channel is configured with an independent signal isolation module, the signal isolation module is externally wrapped with an electromagnetic shielding layer, and the inner wall of the device shell is provided with a grounding shielding layer, thereby reducing the interference of external electromagnetic signals on data transmission.
[0012] Further, the power supply module includes a power input interface, a power conversion unit, a filter unit and an overvoltage and overcurrent protection unit, the power input interface penetrates through the device shell and is fixed, supports a wide voltage input range, and is suitable for different vehicle power supply environments, the power conversion unit converts the input voltage into the working voltage required by each module, the filter unit adopts a capacitor filter circuit to filter the noise signals in the power input, and the overvoltage and overcurrent protection unit monitors the output voltage and current parameters in real time and automatically cuts off the power output circuit when the parameters exceed the preset safety range.
[0013] Further, the device further includes a state monitoring module, which is electrically connected with the control module and installed inside the device shell, the state monitoring module collects working parameters of each module in real time, including the chip temperature of the encryption processing module, the channel transmission rate of the communication interface module, the remaining storage capacity of the storage module and the output voltage and current of the power supply module, the state monitoring module converts the collected analog parameters into digital signals and transmits them to the control module, the device shell is provided with an indicator light, and the control module is connected with the indicator light on the surface of the device shell and controls the display state of the indicator light according to the received digital signals to feed back the running conditions of each module.
[0014] Compared with the prior art, the DBC encryption communication gateway device has the following beneficial effects: By adopting the RK3576 and RK3588 chip stacking structure and the multi-scrambling algorithm, the DBC encryption communication gateway device realizes encryption processing of CAN-FD, LIN, FlexRay and other multi-protocol data, solves the problems of missing encryption mechanism and single algorithm in the prior art, guarantees data confidentiality and integrity, reduces communication delay by means of the multi-channel independent bidirectional communication design and high-performance chip support, meets the real-time communication requirements of vehicles, supports encryption of DBC, LDF, XML and other protocol files by means of remote Ethernet and local USB encryption file acquisition, is compatible with different vehicle communication scenarios, effectively prevents data leakage and tampering risks, and improves the stability and security of the vehicle networking system.
[0015] Additional advantages, objects, and features of the application will be apparent to those skilled in the art upon examination of the following detailed description, it being understood that each of the foregoing general statements are intended to be limiting on the application described herein. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0017] Figure 1 It is a structure schematic diagram of a DBC encryption communication gateway device. Figure 2 It is a working flow chart of a DBC encryption communication gateway device. Figure 3 It is a structure schematic diagram of a device shell in a DBC encryption communication gateway device. DETAILED DESCRIPTION
[0018] In order to further illustrate the technical means and effects adopted by the present application to achieve the predetermined application purposes, the specific embodiments, structures, features and effects according to the present application are described in detail below in combination with the drawings and preferred embodiments.
[0019] Embodiment one In the vehicle networking system of the intelligent connected vehicle, the ECU needs to interact with the cloud server and the bench test equipment through CAN-FD, LIN, FlexRay and other protocols, and these data contain sensitive contents such as vehicle driving state, control instructions and user information. If there is no effective encryption mechanism, it is easy to be attacked by malicious attacks such as leakage and tampering. At the same time, the data transmission characteristics of different protocols are quite different, and the existing gateway device is difficult to compatible with multi-protocol encryption and has high communication delay, which cannot meet the real-time communication requirements of vehicle-mounted communication. The DBC encryption communication gateway device provided in the embodiment is applied to the vehicle-mounted communication scene of the intelligent connected vehicle, and through the cooperative work of multiple modules, the safe and efficient transmission of multi-protocol data is realized, the reliability and security of vehicle networking communication are ensured, and the specific content of the embodiment is as follows: Figure 1 、 Figure 2 and Figure 3 In the specific implementation of the embodiment, the modules of the device cooperatively operate according to the preset process. First, the encrypted file acquisition process is started by the communication interface module. According to the current environment of the vehicle, if the vehicle is driving on an urban road and the network signal is stable, the communication interface module establishes a connection with the authorized cloud server through the Ethernet interface; if the vehicle is in a network signal weak area such as an underground garage or needs to update the encrypted file locally, the communication interface module establishes a connection with the encrypted storage medium through the USB interface. After the connection is established, the communication interface module verifies the legality of the connection object, confirms that the other party is an authorized subject and the connection link is stable, receives the encrypted file sent by the cloud server or the storage medium, and the received encrypted file covers the DBC format CAN network signal description file, the LDF format LIN protocol configuration file and the XML format general protocol data file. After the file transmission is completed, the communication interface module transmits the real-time data to the storage module for storage.
[0020] At the same time, the communication interface module continuously receives bidirectional data from various control units such as the vehicle engine ECU and automatic driving ECU, as well as test calibration data sent by the bench device, and selects an appropriate channel according to the communication protocol type corresponding to the data: high-speed large-capacity operating parameter data transmitted by the engine ECU is received through the CAN-FD channel, low-speed control data such as window control and seat adjustment is received through the LIN channel, real-time decision instruction data of the automatic driving system is received through the FlexRay channel, and all data to be processed is transmitted to the encryption processing module after being received.
[0021] After receiving the data to be processed, the encryption processing module first performs data preprocessing, formats the original communication data according to the data packet structure specification of the corresponding protocol, extracts the effective field containing the core information, automatically removes the redundant padding data generated in the data transmission process, and reduces the influence of invalid data on the encryption efficiency.
[0022] In the specific implementation of the embodiment, the RK3576 chip performs preliminary encryption on the parsed effective information field, generates intermediate encrypted data using a hybrid encryption function, and the specific calculation formula is as follows: wherein is the preliminary encrypted data, is the parsed effective information field, is a basic encryption function based on data bit operation, which realizes preliminary data confusion by performing shift, XOR and other operations on data binary bits, is an auxiliary encryption function based on data checksum, which further improves the confusion effect by calculating the checksum of the effective information field and performing encryption transformation. and is a weighting coefficient, which is based on the transmission rate, transmission delay and other transmission characteristics of different protocols of CAN-FD, LIN and FlexRay, and is obtained by training and calibration of multiple sets of measured communication data, and can accurately adapt to the encryption needs of different protocol data. is a preset fixed value in the encryption file, and the protocol type corresponding to the current processing data is one-to-one, ensuring the protocol adaptability of the encryption process.
[0023] After preliminary encryption, the intermediate encrypted data is transmitted to the RK3588 chip through a high-speed data bus, and the chip performs secondary encryption through another scrambling algorithm to form the final encrypted data. In the specific implementation process of the embodiment, the calculation formula of the secondary encryption is as follows: , wherein is the final encrypted data, is a deep encryption function based on nonlinear transformation, which further processes the intermediate encrypted data through complex mathematical transformation, significantly improving the encryption strength of the data. is a strength adjustment coefficient, which is determined according to the sensitivity level of the current data and dynamically adjusted by the control module based on the historical encryption success rate. The higher the data sensitivity, the greater the encryption strength coefficient. is a key segment stored in the encryption file according to the protocol type, which is verified and extracted synchronously when the encryption file is obtained through the Ethernet or USB interface, ensuring the integrity and legality of the key segment. is an XOR operation, which further enhances the anti-cracking ability of the encrypted data by performing XOR operation between the key segment and the intermediate data after nonlinear transformation.
[0024] In addition, the scrambling algorithm carried by the encryption processing module includes symmetric encryption algorithm and asymmetric encryption algorithm. The symmetric encryption algorithm is used for encryption and decryption processing of regular communication data, which balances encryption efficiency while ensuring encryption security. The asymmetric encryption algorithm is used for encryption and decryption processing of encryption files and key data, further improving the security level of core data.
[0025] For key encryption of vehicle control instructions, user privacy information and other key data, an asymmetric encryption algorithm is used, and the specific calculation formula is as follows: , wherein is the encrypted key data, PubKey is the receiver's public key, which is carried in the encryption file obtained through the Ethernet interface is the original key data, is a key validity verification parameter, which is obtained by taking the modulus of the CRC32 check code of the encryption file in the storage module, The device identity factor is a parameter of a unique hardware identification of the device, and is a decimal value converted from a MAC address of the device.
[0026] During the entire encrypted transmission process, the control module plays a core role in multi-channel scheduling and module coordination. The control module collects the connection state, data transmission request, and workload data of the encryption processing module of each channel of the communication interface module in real time, formulates a dynamic scheduling strategy according to the priority of data transmission of each channel, such as the real-time decision data priority of the FlexRay channel being higher than the low-speed control data priority of the LIN channel, and allocates independent communication resources for each channel, effectively preventing data transmission conflicts between different channels.
[0027] At the same time, the control module sends control instructions to the encryption processing module to clearly define the order of data processing and the type of adaptive scrambling algorithm, ensuring accurate matching of encryption processing and data transmission requirements. In addition, the control module monitors the storage capacity of the storage module in real time, and when the storage capacity reaches a preset threshold, sends a data cleaning instruction to retain core data such as encrypted files and vehicle communication protocol data, and delete expired communication cache data; at the same time, it continuously monitors the output voltage, current and other parameters of the power supply module, and when abnormal conditions such as overvoltage and overcurrent occur, it immediately sends a shutdown protection instruction to cut off the power supply of non-core modules, ensuring the safe operation of the core components of the device.
[0028] After receiving the encrypted files transmitted by the communication interface module and various encrypted data transmitted by the encryption processing module, the storage module establishes a classified storage directory according to the data type, separately divides a dedicated storage area for encrypted files and sets strict access permissions, allowing only the encryption processing module and the control module to access after authorization, preventing encrypted files from being tampered with or stolen illegally.
[0029] At the same time, the storage module performs integrity checking on all received storage data, detects whether the data is missing or damaged through a dedicated checking algorithm, and immediately sends an alarm signal to the control module if the data is found to be abnormal, which is fed back to the indicator light by the state monitoring module. In addition, the storage module sets storage priorities according to the usage frequency and validity period of the data, stores high-frequency usage data such as DBC files in a high-speed storage area to improve data reading speed, and stores low-frequency usage historical communication cache data in a normal storage area to optimize storage resource allocation, ensuring efficient operation of the storage system.
[0030] The power supply module provides power support for stable operation of the entire device, and the power input interface penetrates through the device shell and is fixed, supports a wide voltage input range, and can adapt to different vehicle-mounted power supply environments. The power conversion unit converts the input vehicle-mounted voltage into the operating voltage required by each module, ensuring that the communication interface module, encryption processing module, and other modules receive stable voltage supply; the filter unit uses a capacitor filter circuit to effectively filter the noise signals in the power input, avoiding interference from noise signals on data transmission and encryption processing; the overvoltage and overcurrent protection unit monitors output voltage and current parameters in real time, and automatically cuts off the power output circuit when the parameters exceed the preset safety range, preventing voltage and current abnormalities from damaging module components.
[0031] The state monitoring module is electrically connected to the control module and collects the working parameters of each module in real time, including the operating temperature of RK3576 and RK3588 chips in the encryption processing module, the transmission rate of each channel of the communication interface module, the remaining storage capacity of the storage module, and the output voltage and current of the power supply module. The state monitoring module converts the collected analog parameters into digital signals and transmits them to the control module. The indicator lights installed on the surface of the device shell are connected to the control module, which controls the display state of the indicator lights according to the received digital signals. For example, the indicator lights display green when the chip temperature is normal, yellow when the temperature is too high, orange when the storage capacity is insufficient, and red when the power supply is abnormal. This intuitively reflects the operation of each module, making it easy for workers to monitor the device status in real time.
[0032] In summary, the embodiment realizes the complete encryption transmission process of vehicle-mounted multi-protocol data through the cooperative work of each module. The DBC encryption communication gateway device based on the RK3576 and RK3588 chip stacking structure and multiple scrambling algorithms successfully solves the problems of missing encryption mechanism and single algorithm in existing gateway devices, can efficiently encrypt CAN-FD, LIN, FlexRay, and other multi-protocol data, and guarantees the confidentiality and integrity of data transmission. With the support of multi-channel independent bidirectional communication design and high-performance chips, communication delay is effectively reduced, fully meeting the stringent requirements of vehicle-mounted real-time communication. Through Ethernet remote and USB local encryption file acquisition methods, encryption support for DBCLDFXML and other multi-protocol files is realized, and different vehicle-mounted communication scenarios can be compatible.
[0033] Embodiment Two In the vehicle-road cooperation system of a new energy intelligent connected vehicle, the vehicle needs to interact with the cloud management platform of the charging pile roadside sensing unit, the on-board internal ECU and the bench test equipment in multiple dimensions, involving charging parameter transmission, real-time road condition feedback, vehicle state reporting, remote control instruction issuance and other scenarios. In such scenarios, the data types are complex, including high-sensitive charging payment information and vehicle control instructions, as well as high-frequency road condition data and equipment state data. Moreover, the communication environments of different interactive objects differ greatly, and there are problems such as network fluctuations and electromagnetic interference, which put higher requirements on the multi-protocol compatibility, encryption flexibility and anti-interference of the gateway device. The DBC encryption communication gateway device provided in the embodiment optimizes the multi-device interaction adaptation capability and dynamic encryption strategy on the basis of the foregoing embodiment and is applied to the vehicle-road cooperation scenario of the new energy intelligent connected vehicle to realize the safe and stable transmission of multi-source data. For details, see Figure 1 , Figure 2 and Figure 3 The specific content of the embodiment is as follows: In the specific implementation process of the embodiment, the device completes initialization configuration after starting, and the communication interface module starts the encryption file management process according to the preset strategy. On the basis of the encryption file acquisition method in the foregoing embodiment, a regular encryption file updating mechanism is added, the device establishes a connection with the cloud management platform through the Ethernet interface at regular time intervals, verifies the consistency of the current encryption file version and the latest version on the cloud, and if there is an update, automatically receives the new version of the encryption file, which covers the extended DBC file for adapting the communication of the charging pile, the LDF file special for the roadside unit and the XML format vehicle-road cooperation protocol configuration file. If the network is interrupted or the version verification fails, version update is performed through the USB interface to access the local encryption storage device.
[0034] After the encryption file is received, the communication interface module first verifies the integrity of the file, and after confirming that there is no error, transmits the file to the storage module. The storage module establishes a dedicated storage partition for the newly added charging pile roadside unit data, and at the same time retains the latest three versions of the encryption file, supporting the version rollback function.
[0035] The communication interface module continuously receives multi-source data: the battery state and power system operating parameters transmitted by the on-board ECU are received through the CAN-FD channel; the charging voltage, current and charging progress data sent by the charging pile are received through the CAN-FD channel, the start and stop control of the charging pile and other low-speed instructions are received through the LIN channel; the real-time road condition and traffic warning high-speed real-time data transmitted by the roadside sensing unit are received through the FlexRay channel; and the remote diagnosis instructions and parameter configuration information issued by the cloud management platform are received through the Ethernet interface.
[0036] During all data receiving processes, the independent signal isolation modules of each channel work with the ground shielding layer of the device shell to resist electromagnetic interference generated during operation of the charging pile and electromagnetic radiation from the external environment, ensuring the stability of data transmission. After receiving the data, the communication interface module transmits the data to be encrypted to the encryption processing module, and simultaneously synchronously uploads the device self-operation state data to the control module.
[0037] After receiving the data, the encryption processing module completes format analysis and redundant data elimination along the aforementioned data preprocessing process. In the specific implementation process of the embodiment, the RK3576 chip preliminarily encrypts the effective information field according to the following formula: After preliminary encryption, the intermediate encrypted data is transmitted to the RK3588 chip for secondary encryption, and the secondary encryption formula is as follows: For key data such as charging payment keys and remote control instructions, the encryption processing module uses an asymmetric encryption algorithm for key encryption, and the formula is as follows: .
[0038] Unlike the foregoing embodiments, the control module in this embodiment collects network transmission state data and potential attack risk monitoring data in real time, and dynamically adjusts the intensity adjustment coefficient : When it is detected that the network transmission is stable and there is no attack risk, the value of is appropriately reduced to balance the encryption intensity and transmission efficiency; when it is identified that the data contains high-sensitive information or there is abnormal access behavior, the value of is increased to enhance the encryption intensity. At the same time, the RK3576 and RK3588 chips realize millisecond-level data interaction through a high-speed data bus, and the heat-conducting pad attached to the surface of the chip quickly conducts the operating heat to the device shell, so that the chip can maintain a normal operating temperature even in a high-temperature environment in a charging pile dense area, ensuring the encryption processing efficiency.
[0039] The control module undertakes the core scheduling responsibility of multi-device interaction, and collects the data transmission request of each channel of the communication interface module, the load state of the encryption processing module, and the priority identifier of the multi-source data in real time. During the charging peak period, the priority of the charging parameter data of the charging pile is raised to ensure uninterrupted data transmission during the charging process; when the roadside sensing unit sends emergency traffic warning data, it is set to the highest priority to preferentially allocate encryption processing resources and communication channels. If the communication interface module detects that the data transmission is interrupted, the control module immediately triggers the temporary caching mechanism of the storage module to temporarily store the encrypted data to be transmitted in the high-speed storage area, and continues to transmit according to the priority order after the connection is restored.
[0040] Meanwhile, the control module monitors the capacity of each partition of the storage module in real time. When the capacity of the dedicated partition reaches a threshold, the oldest non-core historical data is deleted according to the "first-in, first-out" principle. When monitoring the output parameters of the power supply module, if the voltage fluctuation caused by the charging of the charging pile exceeds the safe range, the power supply to the non-core module is immediately cut off, only the core modules such as encryption processing and communication interface are kept running, and equipment damage is avoided.
[0041] After receiving encrypted files and encrypted data, the storage module establishes a two-level storage directory according to the data source and type. Charging pile data, roadside unit data, and vehicle-mounted ECU data are stored in corresponding subdirectories. High-frequency access road condition data and device status data are stored in a high-speed storage area, and low-frequency use historical charging records and diagnostic reports are stored in a normal storage area.
[0042] During storage, integrity checking is performed on each batch of received data. If charging pile data is found to be missing or damaged, an alarm signal is immediately sent to the control module, and the control module instructs the communication interface module to request data again. At the same time, the storage module manages the version of the encrypted file, records the update time of each version and the adaptation scenario, and when a new version of the encrypted file has compatibility problems, it can quickly roll back to the previous stable version.
[0043] The power supply module adapts to the 12V / 24V dual-specification power supply system of new energy vehicles. After receiving the vehicle-mounted power supply, the power supply input interface converts it into the stable working voltage required by each module through a power conversion unit. The filter unit uses a capacitor filter circuit to effectively filter the voltage noise generated during the charging of the charging pile and the fluctuation signal of the vehicle-mounted power supply, ensuring the stability of the power supply to core components such as the encryption processing module and the control module. The overvoltage and overcurrent protection unit monitors the output voltage and current in real time. When it detects that abnormal charging of the charging pile causes a sudden rise in input voltage or a short circuit of the device causes excessive current, it cuts off the power output circuit within milliseconds to prevent module burning.
[0044] The state monitoring module extends the remote feedback function based on the foregoing embodiments. It collects the chip temperature of the encryption processing module, the transmission rate of each channel of the communication interface module, the remaining capacity of the storage module, the output parameters of the power supply module, and the signal interference intensity of each channel in real time. After converting the analog parameters into digital signals, on the one hand, they are transmitted to the control module to control the indicator light: the indicator light flashes yellow when the chip temperature is too high, it is constantly orange when the storage capacity is insufficient, and it flashes red quickly when the power supply is abnormal. On the other hand, they are uploaded to the cloud management platform through the Ethernet interface to realize real-time remote monitoring of the device operating state. When the signal interference intensity exceeds the threshold, the state monitoring module sends a signal enhancement instruction to the control module, and the control module adjusts the signal reception gain of the communication interface module to improve the anti-interference ability.
[0045] To sum up, the embodiment further expands the application scenario coverage of the device by optimizing multi-device adaptation, dynamic encryption adjustment, remote state monitoring and anti-interference design on the basis of the foregoing embodiment. The embodiment not only retains the core advantages of multi-protocol encryption and low-latency transmission, but also improves the flexibility of data management through encrypted file version management and multi-source data partition storage.
[0046] The above merely describes preferred embodiments of the present application and is not intended to limit the present application in any form. Although the present application has been disclosed with reference to the preferred embodiments, the present application is not intended to be limited thereto. Any person skilled in the art can make minor changes or modifications to the disclosed technical content or equivalent embodiments with equivalent changes without departing from the technical solution of the present application. Any simplification, modification, equivalent change or modification of the above embodiments made in accordance with the technical essence of the present application shall still fall within the scope of the technical solution of the present application.
Claims
1. A DBC-based encrypted communication gateway device, characterized in that, The device includes: a device housing, a communication interface module, an encryption processing module, a storage module, a power supply module, and a control module, wherein the communication interface module, encryption processing module, storage module, power supply module, and control module are all installed inside the device housing; The communication interface module includes a CAN-FD channel, a LIN channel, a FlexRay channel, an Ethernet interface, and a USB interface. The communication interface module receives bidirectional data between the ECU and the bench device and transmits it to the encryption processing module. At the same time, it obtains encrypted files through the Ethernet interface or USB interface and transmits them to the storage module. The encryption processing module adopts a stacked structure of RK3576 and RK3588 chips, and is equipped with a variety of scrambling algorithms. It calls the encrypted file and the matching algorithm from the storage module, encrypts and decrypts the data transmitted by the communication interface module, and then feeds it back to the communication interface module. The storage module receives and stores encrypted files, vehicle communication protocol data, and communication cache data, and responds to data read requests from each module. The power supply module is electrically connected to each module to provide power, and the control module is electrically connected to each module to schedule the workflow of each module and coordinate the data transmission and processing sequence.
2. The DBC-based encrypted communication gateway device according to claim 1, characterized in that, The encryption processing module performs the following operations when encrypting communication data: It receives raw communication data transmitted from the communication interface module and simultaneously retrieves the corresponding encrypted file and scrambling algorithm adapted to the current communication protocol from the storage module. The original communication data is parsed to extract valid information fields and remove redundant data. The parsed valid information fields are initially encrypted using the RK3576 chip. Intermediate encrypted data is then generated using a hybrid encryption function, calculated as follows: ,in, To initially encrypt the data, The parsed valid information fields, These are basic encryption functions based on data bit operations. For auxiliary encryption functions based on data checksums, , These are weighting coefficients. This is the offset; The intermediate encrypted data is transmitted to the RK3588 chip, where it undergoes secondary encryption using another scrambling algorithm to form the final encrypted data. The calculation formula is as follows: ,in, For the final encrypted data, This is a deep encryption function based on nonlinear transformation. This is the intensity adjustment coefficient. This is a key fragment extracted from an encrypted file. This is an XOR operation; The final encrypted data is fed back to the communication interface module and transmitted to the target device through the corresponding channel.
3. The DBC-based encrypted communication gateway device according to claim 1, characterized in that, The communication interface module performs the following operations when acquiring and transmitting encrypted files: Choose the method of obtaining encrypted files according to the application scenario. When obtaining files remotely, a connection is established with the cloud server through the Ethernet interface. When obtaining files locally, a connection is established with the storage medium through the USB interface. Verify the legitimacy and stability of the connection, and complete the transmission and reception of encrypted files. The encrypted files include protocol files in DBC, LDF, and XML formats. Select the corresponding channel according to the communication protocol type. The CAN-FD channel is used for high data rate and large capacity data transmission, the LIN channel is used for low-speed communication scenarios, and the FlexRay channel is used for high-speed real-time communication scenarios. The received encrypted file is transferred to the storage module, and the data to be transmitted is transferred to the encryption processing module. After encryption, the data is transmitted bidirectionally through the selected channel.
4. The DBC-based encrypted communication gateway device according to claim 1, characterized in that, The control module performs the following operations when performing multi-channel scheduling and module coordination: Real-time acquisition of connection status of each channel of the communication interface module, data transmission requests, and workload data of the encryption processing module; Based on the data transmission priority of the channels and the load of the encryption processing module, a scheduling strategy is formulated to allocate independent communication resources to each channel; Send control commands to the encryption processing module to specify the data processing order and scrambling algorithm type; Real-time monitoring of storage module capacity; when the preset threshold is reached, a data cleanup command is sent to retain core data and delete expired cached data. Monitor the output parameters of the power supply module, and send a shutdown protection command when an abnormality occurs to cut off the power supply to non-core modules.
5. The DBC-based encrypted communication gateway device according to claim 1, characterized in that, The storage module performs the following operations when storing and managing data: It receives encrypted files and various types of encrypted data transmitted by the encryption processing module and the communication interface module, establishes classified storage directories according to data type, allocates a separate storage area for encrypted files and sets access permissions; The system performs integrity checks on the received stored data, detects whether the data is lost or corrupted, and sends an alarm signal to the control module when an anomaly is detected. Storage priorities are set according to data usage frequency and validity period, with high-frequency data stored in high-speed storage areas and low-frequency data stored in ordinary storage areas. It receives read commands from the control module and encryption processing module, retrieves the target data and sends it back to the request module, while recording the data read time and the number of times it is used.
6. The DBC-based encrypted communication gateway device according to claim 1, characterized in that, The encryption processing module is equipped with scrambling algorithms including symmetric and asymmetric encryption algorithms. Symmetric encryption algorithms are used for encrypting and decrypting regular communication data, while asymmetric encryption algorithms are used for encrypting and decrypting files and critical data. The asymmetric encryption for critical data uses the following formula: ,in, The key to the encrypted critical data. For the recipient's public key, The original key data key, This is a parameter for key validity verification. As a device identification factor, the RK3576 chip and the RK3588 chip are connected through a high-speed data bus. The chip stacking structure adopts a heat dissipation optimization design, with a thermal pad attached to the chip surface. The end of the thermal pad away from the chip is connected to the inner wall of the device casing.
7. A DBC-based encrypted communication gateway device according to claim 1, characterized in that, The CAN-FD channel of the communication interface module has a higher transmission rate than the traditional CAN protocol. The LIN channel adopts a master-slave communication architecture, supporting multiple slave devices to access simultaneously. The FlexRay channel adopts a dual-channel design. The Ethernet interface supports gigabit network transmission rates. The USB interface adopts the USB 3.0 standard. Each channel is equipped with an independent signal isolation module.
8. The DBC-based encrypted communication gateway device according to claim 1, characterized in that, The power supply module includes a power input interface, a power conversion unit, a filtering unit, and an overvoltage and overcurrent protection unit. The power conversion unit converts the input voltage into the operating voltage required by each module. The filtering unit uses a capacitor filter circuit to filter out noise signals in the power input. The overvoltage and overcurrent protection unit monitors the output voltage and current parameters in real time and automatically cuts off the power output circuit when they exceed the preset safety range.
9. A DBC-based encrypted communication gateway device according to claim 1, characterized in that, The device also includes a status monitoring module, which is electrically connected to the control module and installed inside the device housing. The status monitoring module collects the operating parameters of each module in real time, including the chip temperature of the encryption processing module, the channel transmission rate of the communication interface module, the remaining storage capacity of the storage module, and the output voltage and current of the power supply module.
Citation Information
Patent Citations
Vehicle-mounted network communication encryption system based on central computing platform and vehicle
CN115208694A
Vehicle binding method, device and equipment and computer readable storage medium
CN118646583A
Vehicle-mounted composite gateway and vehicle
CN210120567U
Vehicle Network Interface Tool
US20180063098A1