Secure transmission method and system for intelligent network connection vehicle data and electronic equipment

By implementing graded processing of vehicle-mounted data and differentiated storage management in the cloud, the problem of full-process control of various types of sensitive data in intelligent driving scenarios has been solved, achieving a balance between data security and efficiency, and providing a secure solution for the use of intelligent driving data.

CN121966994APending Publication Date: 2026-05-01FAW JIEFANG AUTOMOTIVE CO
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FAW JIEFANG AUTOMOTIVE CO
Filing Date
2026-01-27
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies cannot effectively balance the full-process control of multiple types of sensitive data in intelligent driving scenarios, and cannot simultaneously meet the needs of data security compliance, efficient and in-depth utilization, and real-time processing efficiency.

Method used

By preprocessing vehicle-mounted data in a hierarchical manner to distinguish between sensitive and non-sensitive data, and by using feature extraction and asymmetric encryption to generate encrypted feature data, differentiated storage management is implemented in the cloud, and a full lifecycle access control and data integrity verification mechanism is established to form an end-to-end secure data pipeline.

Benefits of technology

While ensuring data security, it significantly reduces computational overhead, ensures data processing efficiency, provides a foundation for the safe use of intelligent driving data, and meets data security regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966994A_ABST
    Figure CN121966994A_ABST
Patent Text Reader

Abstract

The invention discloses a secure transmission method and system for intelligent network connection vehicle data and electronic equipment, and relates to the field of vehicle data transmission, and the method comprises the steps: carrying out the real-time recognition and classification of collected multi-modal data, and distinguishing sensitive and non-sensitive data; sensitive data is subjected to special feature extraction and encryption to generate encrypted feature data, and non-sensitive data is subjected to standardization preprocessing to generate structured feature data; and adding security verification information and a full-life-cycle identifier to the processed data, and carrying out shunting processing according to the identifier. The encrypted feature data adopts an encrypted storage scheme matched with a vehicle-mounted key strategy, a cloud key library is synchronously updated, and storage and access states are monitored; structured feature data adopts an efficient storage scheme, a retention period is configured according to an identifier, and an access control and integrity verification mechanism based on a full-life-cycle identifier is established. According to the scheme, through classification processing and differential storage of the collected data, an access control and integrity verification mechanism is established in combination with the full-life-cycle identifier, and data security management is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle data transmission, and in particular to a secure transmission method for intelligent connected vehicle data, a secure transmission system for intelligent connected vehicle data, an electronic device, and a storage medium. Background Technology

[0002] In the field of data security and privacy protection, especially in scenarios such as intelligent driving where there are extremely high requirements for data processing efficiency and security, how to achieve the secure transmission, processing and utilization of sensitive data has become a core research topic in the industry.

[0003] The current technological approach faces two major challenges. First, if a full cloud transmission model is adopted, the transmission and storage of original personal information / sensitive personal information / important data pose an uncontrollable risk of leakage, and directly violates the bottom line of data protection regulations in various countries. Second, if terminal privacy protection technologies such as full encryption are adopted, they face severe efficiency and functional constraints: the computational overhead of full asymmetric encryption makes it difficult to put into practical applications.

[0004] For example, a Chinese patent, titled "A Method and System for Transmitting Encrypted Data," application number CN202511408100.2, discloses a method that analyzes the local complexity and local sensitivity of the data to be encrypted, divides the data into independent and joint data units, and dynamically selects a suitable encryption method based on the network environment's transmission link connectivity. It employs either asymmetric or symmetric encryption to achieve a balance between security and efficiency. However, this patent does not cover the core characteristics of sensitive data in intelligent driving scenarios. It focuses on data transmission and does not manage the terminal preprocessing and storage of the original sensitive data. The solution only adjusts the encryption strategy based on link fluctuations, failing to consider the balance between encryption computational overhead and real-time decision-making response in intelligent driving scenarios.

[0005] For example, a Chinese patent, titled "Security Analysis Method and Device for Personalized Privacy Protection of Image Data," patent number CN202511373701.4, specifically discloses a method for determining target scenes through sensitive metadata extraction, performing encryption processing based on personalized parameters, and conducting multi-resolution perceptual feature similarity mapping and visual security scoring to optimize security analysis. This patent focuses on privacy protection and security analysis of image data, fundamentally addressing the visual security evaluation problem after image encryption. However, it has significant shortcomings in its applicability to intelligent driving scenarios.

[0006] The solution only assesses the encryption security of image data and does not extend to other types of sensitive data such as voice, trajectory, and sensor data in intelligent driving scenarios. Furthermore, it only focuses on "security score after encryption" and does not involve full-process control of data transmission, processing, and utilization, thus failing to form an end-to-end security solution.

[0007] The core objective of this solution is to improve the accuracy of secure analysis of encrypted images, but it does not consider the efficient utilization of encrypted data. In intelligent driving scenarios, sensitive data needs to be used for in-depth applications such as model training and algorithm optimization. Full encryption would render the data unusable, and this solution does not provide a balance strategy between "encryption protection and data usability," thus failing to meet the needs of in-depth utilization.

[0008] In summary, existing technologies cannot meet the needs of intelligent driving scenarios for full-process control of multiple types of sensitive data, and fail to effectively balance the relationship between data security compliance, efficient and in-depth utilization, and real-time processing efficiency. Summary of the Invention

[0009] In view of this, the purpose of the present invention is to provide a secure transmission method for intelligent connected vehicle data, a secure transmission system for intelligent connected vehicle data, an electronic device and a storage medium, in order to solve the technical problems in the prior art.

[0010] This invention provides the following solution:

[0011] According to one aspect of the present invention, a method for secure transmission of data for intelligent connected vehicles is provided, comprising the following steps:

[0012] Vehicle-mounted data classification and preprocessing steps: Based on preset classification rules, the collected multimodal data of intelligent connected vehicles is identified and classified in real time to distinguish between sensitive data and non-sensitive data;

[0013] A dedicated feature extraction process is used to extract features from sensitive data, and the extracted feature vectors are encrypted to generate encrypted feature data.

[0014] Perform standardized preprocessing on non-sensitive data to generate structured feature data;

[0015] Add security verification information and data lifecycle identifiers to all processed feature data;

[0016] Cloud-based differentiated storage management steps: Based on the full lifecycle identification of data types and governance requirements, the received feature data is processed in a stream-based manner;

[0017] For encrypted feature data, an encrypted storage strategy matching the vehicle-mounted key management strategy is adopted, the cloud key store is updated synchronously, and the data storage status and access logs are recorded in real time based on cloud data monitoring rules;

[0018] An efficient storage strategy is adopted for structured feature data, and the data retention period is configured based on the full lifecycle identifier;

[0019] Establish an access control mechanism and a data integrity verification mechanism based on full lifecycle identification; the access control mechanism is associated with key version and access permissions, and the data integrity verification mechanism is consistent with the verification rules of the vehicle terminal.

[0020] Furthermore, the vehicle-mounted data classification preprocessing step also includes: based on preset vehicle-mounted data monitoring rules, real-time verification of the integrity and transmission status of encrypted feature data and structured feature data, and uploading through a secure transmission channel after verification.

[0021] Furthermore, the key management strategy includes: key generation at the vehicle-mounted terminal, hierarchical storage, and dynamic update rules.

[0022] Furthermore, including:

[0023] The entire lifecycle identifier is associated with the data source, processing time, key version, and destruction trigger conditions.

[0024] Furthermore, the multimodal data of intelligent connected vehicles includes: vehicle speed data, acceleration data, steering wheel angle data, cockpit video stream, and in-vehicle voice data.

[0025] Furthermore, the preset classification rule is: to use a lightweight deep neural network to classify the data.

[0026] Furthermore, the encryption processing of the extracted feature vectors includes: encrypting the extracted feature vectors using an asymmetric encryption algorithm to generate encrypted feature data; the asymmetric encryption algorithm includes the RSA algorithm.

[0027] According to a second aspect of the present invention, a secure transmission system for data of intelligent connected vehicles is provided, comprising:

[0028] The system includes a data identification and classification module, a sensitive data processing module, a non-sensitive data processing module, an information appending module, a stream splitting processing module, an encrypted feature storage module, a structured feature storage module, and a verification module.

[0029] The data identification and classification module is used to identify and classify the collected multimodal data of intelligent connected vehicles in real time based on preset classification rules, and to distinguish between sensitive data and non-sensitive data.

[0030] The sensitive data processing module is used to extract and encrypt sensitive data features based on a preset key management strategy, and generate encrypted feature data.

[0031] The non-sensitive data processing module is used to perform standardized preprocessing on non-sensitive data to generate structured feature data;

[0032] The information appending module is used to append security verification information and data lifecycle identifiers to all processed feature data.

[0033] The traffic splitting module is used to split the received feature data and identify data types and governance requirements based on the full lifecycle identifier.

[0034] The encrypted feature storage module is used to adopt an encrypted storage strategy that matches the key management strategy of the vehicle terminal for encrypted feature data, synchronously update the cloud key library, and record the data storage status and access logs in real time based on the cloud data monitoring rules.

[0035] The structured feature storage module is used to employ efficient storage strategies for structured feature data and configure the data retention period based on the full lifecycle identifier.

[0036] The verification module is used to establish an access control mechanism and a data integrity verification mechanism based on the full lifecycle identifier; the access control mechanism is associated with the key version and access permissions, and the data integrity verification mechanism is consistent with the verification rules of the vehicle terminal.

[0037] According to three aspects of the present invention, an electronic device is provided, comprising: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0038] The memory stores a computer program, which, when executed by a processor, causes the processor to perform steps of a method for secure transmission of data for intelligent connected vehicles.

[0039] According to four aspects of the present invention, a computer-readable storage medium is provided that stores a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform the steps of a method for secure transmission of data for intelligent connected vehicles.

[0040] Compared with the prior art, the present invention has the following advantages:

[0041] This application establishes a comprehensive privacy protection system covering all aspects of data collection, transmission, storage, and use through in-vehicle and cloud processing steps, ensuring data availability and providing a reliable technical foundation for the safe use of intelligent driving data.

[0042] This application employs a differentiated security processing method driven by data classification. This technology utilizes an intelligent data identification and classification mechanism on the vehicle side to accurately segment multimodal data at its source and execute differentiated security processing strategies based on the classification results. For identified sensitive data, the system adopts a dual protection mechanism combining feature extraction and asymmetric encryption, significantly reducing computational overhead while ensuring data security. For non-sensitive data, data processing efficiency is ensured through optimized processing flows. This classification-centric security processing architecture spans the entire data lifecycle from collection and transmission to storage, forming a complete end-to-end secure data pipeline. While strictly meeting data security regulatory requirements, it provides a system-level solution for the efficient utilization of intelligent driving data. Attached Figure Description

[0043] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0044] Figure 1 This is a flowchart of a secure data transmission method for intelligent connected vehicles provided by one or more embodiments of the present invention.

[0045] Figure 2 This is a structural diagram of a secure data transmission system for intelligent connected vehicles provided by one or more embodiments of the present invention.

[0046] Figure 3 This is a flowchart of a secure data transmission system for intelligent connected vehicles, according to a specific embodiment of the present invention.

[0047] Figure 4 This is a block diagram of an electronic device structure for a secure data transmission method for intelligent connected vehicles, provided by one or more embodiments of the present invention. Detailed Implementation

[0048] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0049] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to limit the application. The singular forms “a,” “said,” and “the” used in the embodiments of this application and the appended claims are also intended to include the plural forms, and “multiple” generally includes at least two unless the context clearly indicates otherwise.

[0050] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0051] It should be understood that although the terms first, second, third, etc., may be used in the embodiments of this application, these descriptions should not be limited to these terms. These terms are only used to distinguish the descriptions. For example, first may also be referred to as second without departing from the scope of the embodiments of this application, and similarly, second may also be referred to as first.

[0052] Depending on the context, the words “if” or “suppose” as used here can be interpreted as “when” or “in response to determination” or “in response to detection.” Similarly, depending on the context, the phrases “if determination” or “if detection (of the stated condition or event)” can be interpreted as “when determination” or “in response to determination” or “when detection (of the stated condition or event)” or “in response to detection (of the stated condition or event).”

[0053] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that an article or device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such an article or device. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the article or device that includes said element.

[0054] It should be noted that any symbols and / or numbers present in the specification that are not marked in the accompanying drawings are not reference numerals.

[0055] Figure 1 This is a flowchart of a secure data transmission method for intelligent connected vehicles provided by one or more embodiments of the present invention.

[0056] like Figure 1 As shown, it includes the following steps:

[0057] Vehicle-mounted data classification and preprocessing step S1: Based on preset classification rules, the collected multimodal data of intelligent connected vehicles is identified and classified in real time to distinguish between sensitive data and non-sensitive data;

[0058] A dedicated feature extraction process is used to extract features from sensitive data, and the extracted feature vectors are encrypted to generate encrypted feature data.

[0059] Perform standardized preprocessing on non-sensitive data to generate structured feature data;

[0060] Add security verification information and data lifecycle identifiers to all processed feature data;

[0061] Specifically, the dedicated feature extraction process includes: generating high-dimensional feature vectors from face images using an optimized face recognition feature extraction model, and extracting acoustic features from speech signals using a dedicated speech feature extraction model. These feature vectors are then fed into an asymmetric encryption module for encryption using a standard asymmetric encryption algorithm.

[0062] Non-sensitive data undergoes a standardized preprocessing pipeline, where it is filtered, aligned to time series, and normalized to generate structured feature vectors. All processed data packets are appended with digital signatures and secure timestamps and transmitted through a secure encrypted tunnel.

[0063] Cloud-based differentiated storage management step S2: Based on the full lifecycle identification of data types and governance requirements, the received feature data is processed in a stream-based manner;

[0064] For encrypted feature data, an encrypted storage strategy matching the vehicle-mounted key management strategy is adopted, the cloud key store is updated synchronously, and the data storage status and access logs are recorded in real time based on cloud data monitoring rules;

[0065] An efficient storage strategy is adopted for structured feature data, and the data retention period is configured based on the full lifecycle identifier;

[0066] Establish an access control mechanism and a data integrity verification mechanism based on full lifecycle identification; the access control mechanism is associated with key version and access permissions, and the data integrity verification mechanism is consistent with the verification rules of the vehicle terminal.

[0067] Specifically, a multi-layered data receiving and storage architecture is established in the cloud. A load balancer distributes incoming data to different processing nodes, with encrypted data routed to a secure hardware security module for key management. The system employs a layered encrypted storage strategy: Level 1 storage stores the encrypted feature vector in a security-enhanced encrypted database, performing secondary encryption using standard encryption algorithms; Level 2 storage injects the plaintext feature vector into a high-performance time-series database cluster, while simultaneously establishing a distributed audit trail system. Dynamic access control is implemented at the data access level, using an attribute-based access control model combined with a multi-factor authentication mechanism to ensure that only authorized entities can obtain decryption permissions. The system also deploys a data integrity verification mechanism, periodically performing hash checks to prevent data tampering.

[0068] The system establishes a comprehensive data governance framework, including a key rotation mechanism, data retention strategies, and secure destruction procedures. The key management system employs a distributed key management scheme, storing the master key in fragments across multiple secure areas, requiring multi-party collaboration to complete key reconstruction. After data is categorized and stored, the system continuously monitors data access patterns and identifies potential security threats through anomaly detection algorithms. For decryption scenarios, the system records complete operation logs and implements dynamic anonymization to ensure that sensitive information is exposed only when necessary and in a controlled manner. Simultaneously, the system supports data traceability requirements, reconstructing the complete data flow path through timestamps and digital signatures to meet various compliance audit requirements.

[0069] Specifically, through the above steps, while ensuring data availability, a comprehensive privacy protection system covering all aspects of collection, transmission, storage, and use has been established, providing a reliable technical foundation for the safe use of intelligent driving data.

[0070] Figure 2 This is a structural diagram of a secure data transmission system for intelligent connected vehicles provided by one or more embodiments of the present invention.

[0071] like Figure 2 As shown, it includes:

[0072] The system includes a data identification and classification module, a sensitive data processing module, a non-sensitive data processing module, an information appending module, a stream splitting processing module, an encrypted feature storage module, a structured feature storage module, and a verification module.

[0073] The data identification and classification module is used to identify and classify the collected multimodal data of intelligent connected vehicles in real time based on preset classification rules, and to distinguish between sensitive data and non-sensitive data.

[0074] The sensitive data processing module is used to extract and encrypt sensitive data features based on a preset key management strategy, and generate encrypted feature data.

[0075] The non-sensitive data processing module is used to perform standardized preprocessing on non-sensitive data to generate structured feature data;

[0076] The information appending module is used to append security verification information and data lifecycle identifiers to all processed feature data.

[0077] The traffic splitting module is used to split the received feature data and identify data types and governance requirements based on the full lifecycle identifier.

[0078] The encrypted feature storage module is used to adopt an encrypted storage strategy that matches the key management strategy of the vehicle terminal for encrypted feature data, synchronously update the cloud key library, and record the data storage status and access logs in real time based on the cloud data monitoring rules.

[0079] The structured feature storage module is used to employ efficient storage strategies for structured feature data and configure the data retention period based on the full lifecycle identifier.

[0080] The verification module is used to establish an access control mechanism and a data integrity verification mechanism based on the full lifecycle identifier; the access control mechanism is associated with the key version and access permissions, and the data integrity verification mechanism is consistent with the verification rules of the vehicle terminal.

[0081] It is worth noting that although only some basic functional modules are disclosed in this embodiment, it does not mean that the composition of this system is limited to the above-mentioned basic functional modules. On the contrary, what this embodiment intends to express is that, based on the above-mentioned basic functional modules, those skilled in the art can arbitrarily add one or more functional modules in combination with existing technology to form an infinite number of embodiments or technical solutions. That is to say, this system is open rather than closed. The fact that this embodiment only discloses a few basic functional modules does not mean that the scope of protection of the claims of this invention is limited to the disclosed basic functional modules. At the same time, for the convenience of description, the above device is described separately according to its functions as various units and modules. Of course, in implementing this invention, the functions of each unit and module can be implemented in one or more software and / or hardware.

[0082] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0083] Figure 3This is a flowchart of a secure data transmission system for intelligent connected vehicles, according to a specific embodiment of the present invention.

[0084] like Figure 3 As shown, it includes:

[0085] 1. Implementation of the vehicle-mounted data security processing system;

[0086] The vehicle-mounted data processing system is used to perform secure preprocessing of vehicle-mounted data. This system consists of the following key modules:

[0087] Data acquisition module

[0088] This module is responsible for acquiring raw data from various vehicle sensors. Specifically, it acquires vehicle dynamic data such as speed, acceleration, and steering wheel angle via the vehicle's CAN bus interface; it acquires cockpit video streams via the camera controller interface; and it acquires in-vehicle voice data via an audio codec. All data includes precise timestamps to ensure synchronization across multiple data sources.

[0089] Data classification module

[0090] This module employs an optimized, lightweight deep neural network for data classification. Specifically, a classification network running on an embedded GPU performs real-time analysis of the video stream, accurately identifying image frames containing faces; simultaneously, a speech activity detection algorithm distinguishes speech segments from environmental noise. The module's processing latency is controlled to within 10 milliseconds, ensuring real-time performance.

[0091] Feature extraction and encryption module

[0092] For identified sensitive data, the system performs feature extraction and encryption in a chip-level secure environment. Specifically, facial images are converted into a floating-point feature vector using a pre-trained deep neural network to fully preserve detailed information; speech segments are converted into a 128-dimensional feature vector using an acoustic model. Subsequently, the system integrates an asymmetric encryption algorithm library and uses asymmetric encryption algorithms (including but not limited to RSA) public keys to encrypt the aforementioned feature vectors. The encrypted ciphertext data is approximately four times the size of the original plaintext. This inflation effect needs to be fully considered when designing the communication protocol, and sufficient buffer space needs to be reserved for data transmission.

[0093] 2. Implementation of a cloud-based data management system;

[0094] The cloud system adopts a microservice architecture, and the cloud data management system is used to implement hierarchical storage and security management in the cloud. This system mainly includes the following service components:

[0095] Data receiving service

[0096] This service is implemented using a high-performance network framework, supporting multi-channel concurrent data reception. In practice, multiple data receiving nodes deployed behind the load balancer establish a secure connection with the vehicle terminal via the TLS 1.2 protocol, verifying the client certificate before receiving the uploaded data packets. Each data packet contains an encrypted feature vector, a plaintext feature vector, and corresponding metadata.

[0097] Secure storage service

[0098] This service implements a tiered data storage mechanism, employing differentiated storage strategies for different types of data:

[0099] For encrypted feature vectors, a database system with transparent encryption is used for storage. Data is then encrypted a second time before storage to further enhance security. Access control employs a role-based access control model to ensure that only authorized entities can access the data, while a complete operation log system is established to support end-to-end auditing.

[0100] For plaintext feature vectors, a high-performance time-series database cluster is selected for storage. By establishing a storage architecture sharded according to the time dimension, efficient organization of vehicle dynamic data is achieved. This storage scheme is particularly optimized for the performance of time-range queries and batch aggregation analysis, providing support for subsequent data mining.

[0101] Key Management Service

[0102] This service manages the entire lifecycle of asymmetric encryption algorithm keys, providing hardware security protection for the master private key and establishing a regular key rotation mechanism. In practice, distributed key management technology is used to distribute decryption keys across multiple geographically isolated secure areas. Key reconstruction requires multi-party collaborative verification, ensuring that a security event in a single geographical location will not lead to key leakage.

[0103] 3. Implementation of System Security Mechanisms

[0104] To ensure end-to-end security and reliability of the system, a multi-layered system security mechanism has been established to achieve full lifecycle data governance.

[0105] In terms of communication security, the system establishes a secure, two-way authenticated channel between the vehicle terminal and the cloud. Identity authentication is completed by deploying an X.509 digital certificate, and the AES-256-GCM algorithm is used to encrypt transmitted data, effectively ensuring the confidentiality and integrity of data during transmission.

[0106] At the access control level, the system adopts a fine-grained access control policy based on attributes. Data users must pass multi-factor authentication, and all access requests must be evaluated in real time by the policy decision engine. Only with explicit authorization can the corresponding data access permissions be obtained, thus implementing the principle of least privilege.

[0107] At the audit trail level, the system has established a complete operational audit system. All data access behaviors are recorded in tamper-proof audit logs, detailing key information such as access time, operator identity, data access scope, and operation type. Based on these logs, the system regularly generates security posture reports, providing a reliable basis for compliance reviews and security analysis.

[0108] 4. System Deployment and Maintenance

[0109] In the actual deployment scheme, the vehicle-mounted software is deployed on the vehicle's computing platform using containerization technology, and remote upgrades and maintenance are achieved through OTA technology. Cloud services are deployed on cloud infrastructure that meets the national Level 3 Information Security Protection Standard, and a multi-availability zone architecture is used to ensure high availability and business continuity of system services.

[0110] Specifically, by integrating multiple lightweight neural networks for classification, different modalities of data can be processed separately; edge computing nodes can be introduced for preliminary classification, and then the vehicle system can make the final classification decision; the encryption algorithm can be replaced with other asymmetric encryption schemes; and the storage scheme can select different database types according to the characteristics of the data.

[0111] Figure 4 This is a block diagram of an electronic device structure for a secure data transmission method for intelligent connected vehicles, provided by one or more embodiments of the present invention.

[0112] like Figure 4 As shown, this application provides an electronic device, including: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0113] The memory stores a computer program that, when executed by a processor, causes the processor to perform steps of a method for securely transmitting data for intelligent connected vehicles.

[0114] This application also provides a computer-readable storage medium storing a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform steps of a method for secure transmission of data for intelligent connected vehicles.

[0115] For the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0116] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.

[0117] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A secure data transmission method for intelligent connected vehicles, characterized in that, Includes the following steps: Vehicle-mounted data classification and preprocessing steps: Based on preset classification rules, the collected multimodal data of intelligent connected vehicles is identified and classified in real time to distinguish between sensitive data and non-sensitive data; The sensitive data is subjected to a dedicated feature extraction process for feature extraction, and the extracted feature vectors are encrypted to generate encrypted feature data. Perform standardized preprocessing on the non-sensitive data to generate structured feature data; Add security verification information and data lifecycle identifiers to all processed feature data; Cloud-based differentiated storage management steps: Based on the full lifecycle identification data type and governance requirements, the received feature data is processed by traffic diversion; For the encrypted feature data, an encrypted storage strategy matching the vehicle-mounted key management strategy is adopted, the cloud key library is updated synchronously, and the data storage status and access logs are recorded in real time based on the cloud data monitoring rules. An efficient storage strategy is adopted for the structured feature data, and the data retention period is configured based on the full lifecycle identifier; Establish an access control mechanism and a data integrity verification mechanism based on full lifecycle identification; the access control mechanism is associated with key version and access permissions, and the data integrity verification mechanism is consistent with the verification rules of the vehicle terminal.

2. The secure transmission method for intelligent connected vehicle data according to claim 1, characterized in that, The vehicle-mounted data hierarchical preprocessing step further includes: based on preset vehicle-mounted data monitoring rules, performing real-time verification of the integrity and transmission status of encrypted feature data and structured feature data, and uploading them through a secure transmission channel after the verification is passed.

3. The secure transmission method for intelligent connected vehicle data according to claim 1, characterized in that, The key management strategy includes: key generation at the vehicle terminal, hierarchical storage, and dynamic update rules.

4. A secure data transmission method for intelligent connected vehicles according to claim 1, characterized in that, include: The full lifecycle identifier is associated with the data source, processing time, key version, and destruction trigger conditions.

5. A secure data transmission method for intelligent connected vehicles according to claim 1, characterized in that, The multimodal data of the intelligent connected vehicle includes: vehicle speed data, acceleration data, steering wheel angle data, cockpit video stream, and in-vehicle voice data.

6. A secure data transmission method for intelligent connected vehicles according to claim 1, characterized in that, The preset classification rule is: data classification is achieved using a lightweight deep neural network.

7. A secure data transmission method for intelligent connected vehicles according to claim 1, characterized in that, The encryption process for the extracted feature vectors includes: encrypting the extracted feature vectors using an asymmetric encryption algorithm to generate encrypted feature data; the asymmetric encryption algorithm includes the RSA algorithm.

8. A secure data transmission system for intelligent connected vehicles, characterized in that, include: The system includes a data identification and classification module, a sensitive data processing module, a non-sensitive data processing module, an information appending module, a stream splitting processing module, an encrypted feature storage module, a structured feature storage module, and a verification module. The data identification and classification module is used to identify and classify the collected multimodal data of intelligent connected vehicles in real time based on preset classification rules, and to distinguish between sensitive data and non-sensitive data. The sensitive data processing module is used to extract and encrypt the features of the sensitive data based on a preset key management strategy, and generate encrypted feature data. The non-sensitive data processing module is used to perform standardized preprocessing on the non-sensitive data to generate structured feature data; The information appending module is used to append security verification information and data lifecycle identifiers to all processed feature data. The traffic splitting module is used to split the received feature data and identify the data type and governance requirements based on the full lifecycle identifier. The encrypted feature storage module is used to adopt an encrypted storage strategy that matches the vehicle-mounted key management strategy for the encrypted feature data, synchronously update the cloud key library, and record the data storage status and access logs in real time based on the cloud data monitoring rules. The structured feature storage module is used to employ an efficient storage strategy for the structured feature data and configure the data retention period based on the full lifecycle identifier. The verification module is used to establish an access control mechanism and a data integrity verification mechanism based on the full lifecycle identifier; the access control mechanism is associated with the key version and access permissions, and the data integrity verification mechanism is consistent with the verification rules of the vehicle terminal.

9. An electronic device, characterized in that, include: The processor, communication interface, memory, and communication bus are connected, with the processor, communication interface, and memory communicating with each other via the communication bus. The memory stores a computer program, which, when executed by the processor, causes the processor to perform the steps of the secure transmission method for intelligent connected vehicle data as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, It stores a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform the steps of a secure data transmission method for intelligent connected vehicles as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Encrypted data transmission method and system

    CN120880814A

  • Security analysis methods and devices for protecting the personal privacy of image data

    CN120881213B