Enqueue authentication method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202611289501.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-25
- Publication Date
- 2026-09-22
AI Technical Summary
[0037]本发明实施例中,服务器响应于用于授权目标车辆入队的授权令牌申请请求,根据获取的目标车辆的所有权证明信息确定目标车辆的车辆所有权是否合法,根据目标车辆的车辆所有权的合法性验证结果生成授权令牌,FMS获取目标车辆的授权令牌,FMS向服务器发送目标车辆的入队请求,入队请求携带有目标车辆的授权令牌,服务器对目标车辆的授权令牌进行验证,根据授权令牌的验证结果确定是否允许目标车辆入队。由此,在对车辆所有权安全验证的基础上生成授权令牌,并通过授权令牌对入队请求进行验证,可确保基于车辆所有权的合法性进行入队,防止非法使用车辆产生的非法入队,提高车辆入队的安全性,同时无需硬件令牌,安全且适用范围广。
Smart Images

Figure CN122802286A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of fleet management technology, and in particular to a method and device for fleet entry authentication, an electronic device and a storage medium. Background Technology
[0002] Vehicle platooning refers to the process of incorporating vehicles into the Fleet Management Server (FMS) for management. It is a crucial step in deploying digital keys in scenarios such as car sharing, logistics fleets, and government vehicle fleets. After platooning, the FMS gains vehicle management permissions and can distribute digital keys to drivers or users.
[0003] The existing CCC (Car Connectivity Consortium) standard relies primarily on two verification methods for vehicle queuing: hardware token (physical key) verification or FMS certificate verification. Both methods have a fundamental flaw—they can only prove "who holds the key," not "who is the legal owner of the vehicle."
[0004] The core problem with existing vehicle registration methods lies in the blurring of ownership and usage rights. The physical key holder may be a driver, employee, or chauffeur, not the actual asset owner. This leads to serious security risks: unauthorized physical key holders could maliciously register vehicles, binding them to unauthorized vehicle management systems (FMS), thereby gaining remote control of the vehicle. Addressing the issue of unauthorized registration based on vehicle usage rights is therefore essential. Summary of the Invention
[0005] This invention provides a queuing authentication method, apparatus, electronic device, and storage medium. It generates an authorization token based on the verification result of vehicle ownership authenticity, verifies the vehicle queuing request based on the authorization token, and thus queuing is based on vehicle ownership, preventing illegal queuing caused by unauthorized vehicle use, ensuring the security of vehicle queuing, and the authentication process does not rely on hardware tokens, and is applicable to queuing authentication of all vehicles.
[0006] In a first aspect, embodiments of the present invention provide a queuing authentication method, applied to a queuing authentication system, the queuing authentication system comprising: a server and an FMS connected by communication; the method comprising:
[0007] In response to the authorization token application request for authorizing the target vehicle to join the convoy, the server determines whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle.
[0008] The FMS obtains the authorization token of the target vehicle, and the FMS sends an enqueue request for the target vehicle to the server, the enqueue request carrying the authorization token of the target vehicle;
[0009] The server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0010] As one embodiment, the server includes: a first server and a second server, wherein the second server pre-stores the digital certificate of the first server; correspondingly, the method includes:
[0011] In response to the authorization token application request for authorizing the target vehicle to join the queue, the first server determines whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generates an authorization token based on the legality verification result of the ownership of the target vehicle.
[0012] The FMS obtains the authorization token of the target vehicle, and the FMS sends an enqueue request for the target vehicle to the second server, the enqueue request carrying the authorization token of the target vehicle;
[0013] The second server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0014] As one embodiment, the authorization token includes: authorization information and the server's signature on the authorization information, wherein the authorization information includes: token validity period, the identifier of the target vehicle, and the identifier of the authorized FMS; correspondingly, the server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the platoon based on the verification result of the authorization token, including:
[0015] The server determines whether to allow the target vehicle to join the queue based on the following verification results: the verification result of the authorization token of the target vehicle, whether the queueing request is within the validity period of the authorization token of the target vehicle, and whether the queueing relationship of the vehicle requesting to join the queue is the same as the queueing relationship represented by the authorization token.
[0016] As one embodiment, the method includes:
[0017] The authorization token request is initiated by the vehicle owner's device, and the server sends the generated authorization token to the vehicle owner's device. The FMS obtains the authorization token through the vehicle owner's device; or the authorization token request is initiated by the FMS, and the server sends the generated authorization token to the FMS.
[0018] Secondly, embodiments of the present invention also provide an enqueue authentication method applied to FMS, the method comprising:
[0019] The FMS obtains the authorization token of the target vehicle;
[0020] The FMS sends an enqueue request for the target vehicle to the server, and the enqueue request carries the authorization token of the target vehicle.
[0021] The server is configured to: respond to an authorization token application request for authorizing a target vehicle to join the queue, determine whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generate an authorization token based on the legality verification result of the ownership of the target vehicle; and verify the authorization token of the target vehicle in response to the joining request, and determine whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0022] Thirdly, embodiments of the present invention also provide a queuing authentication method, applied to a server, the method comprising:
[0023] In response to the authorization token application request for authorizing the target vehicle to join the convoy, the server determines whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle.
[0024] The server responds to the enqueue request by verifying the authorization token of the target vehicle, and determines whether to allow the target vehicle to enqueue based on the verification result of the authorization token.
[0025] The FMS is configured to: obtain the authorization token of the target vehicle, and send an enqueue request for the target vehicle to the server, wherein the enqueue request carries the authorization token of the target vehicle.
[0026] Fourthly, embodiments of the present invention provide an in-line authentication device configured in an FMS, the device comprising:
[0027] The acquisition module is used by FMS to obtain the authorization token of the target vehicle;
[0028] The request module is used by the FMS to send an enqueue request for the target vehicle to the server, the enqueue request carrying the authorization token of the target vehicle;
[0029] The server is configured to: respond to an authorization token application request for authorizing a target vehicle to join the queue, determine whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generate an authorization token based on the legality verification result of the ownership of the target vehicle; and verify the authorization token of the target vehicle in response to the joining request, and determine whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0030] Fifthly, embodiments of the present invention provide an enqueue authentication device configured on a server, the device comprising:
[0031] The token generation module is used by the server to respond to the authorization token application request for authorizing the target vehicle to join the queue, determine whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generate an authorization token based on the legality verification result of the ownership of the target vehicle.
[0032] The queuing verification module is used by the server to verify the authorization token of the target vehicle in response to the queuing request, and to determine whether to allow the target vehicle to join the queuing based on the verification result of the authorization token.
[0033] The FMS is configured to: obtain the authorization token of the target vehicle, and send an enqueue request for the target vehicle to the server, wherein the enqueue request carries the authorization token of the target vehicle.
[0034] In a sixth aspect, embodiments of the present invention provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the queuing authentication method as described above.
[0035] In a seventh aspect, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the queuing authentication method as described above.
[0036] Compared with the prior art, the technical solution provided by the embodiments of the present invention has at least the following positive effects:
[0037] In this embodiment of the invention, in response to an authorization token application request for authorizing a target vehicle to join the queue, the server determines whether the vehicle ownership of the target vehicle is legitimate based on the obtained ownership proof information. Based on the verification result of the vehicle ownership legitimacy, an authorization token is generated. The FMS obtains the authorization token and sends a queue entry request for the target vehicle to the server, carrying the authorization token. The server verifies the authorization token and determines whether to allow the target vehicle to join the queue based on the verification result. Therefore, by generating an authorization token based on secure verification of vehicle ownership and verifying the queue entry request using the authorization token, queue entry is ensured based on the legitimacy of vehicle ownership, preventing unauthorized queue entry due to unauthorized vehicle use, thus improving the security of vehicle queuing. Furthermore, it eliminates the need for hardware tokens, making it secure and widely applicable. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0039] Figure 1 This is a flowchart of the queuing authentication method based on the queuing authentication system provided in Embodiment 1 of the present invention;
[0040] Figure 2 A flowchart of another queuing authentication method provided in Embodiment 1 of the present invention;
[0041] Figure 3 A flowchart of another queuing authentication method provided in Embodiment 1 of the present invention;
[0042] Figure 4 This is a flowchart of the queuing authentication method on the FMS side provided in Embodiment 2 of the present invention;
[0043] Figure 5 This is a flowchart of the server-side queuing authentication method provided in Embodiment 3 of the present invention;
[0044] Figure 6 This is a flowchart of the queuing authentication method in an interactive scenario provided in Embodiment 4 of the present invention;
[0045] Figure 7 This is a schematic diagram of the queuing authentication device provided in Embodiment 5 of the present invention;
[0046] Figure 8 This is a schematic diagram of the queuing authentication device provided in Embodiment Six of the present invention;
[0047] Figure 9 This is a schematic diagram of the structure of the electronic device provided in Embodiment 7 of the present invention. Detailed Implementation
[0048] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.
[0049] The following description, with reference to the accompanying drawings, outlines an enqueue authentication method, apparatus, electronic device, and storage medium according to embodiments of this application. Addressing the risk of unauthorized enqueueing inherent in background art methods based on hardware tokens and FMS certificates, which rely solely on vehicle usage rights for authentication, this application provides an enqueue authentication method, apparatus, electronic device, and storage medium. In this application, an authorization token is generated based on the verification result of vehicle ownership legitimacy, and the enqueue request to FMS is authenticated using the authorization token. This ensures vehicle enqueueing is based on the legitimacy of vehicle ownership, prevents unauthorized enqueueing based on vehicle usage rights authentication, improves vehicle enqueue security, and eliminates the need for hardware tokens, making it widely applicable to all vehicle enqueue authentication methods.
[0050] Figure 1 This is a flowchart illustrating the queuing authentication method provided in Embodiment 1 of the present invention. This method is used to implement queuing authentication based on vehicle ownership. The method of this application is applied to a queuing authentication system, which includes a server connected via communication and an FMS (Fulfilled Management System). The embodiment of the present invention specifically includes steps 101 to 103.
[0051] Step 101: In response to the authorization token application request for authorizing the target vehicle to join the queue, the server determines whether the ownership of the target vehicle is legal based on the obtained ownership certificate information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle.
[0052] Step 102: FMS obtains the authorization token of the target vehicle and sends an enqueue request for the target vehicle to the server. The enqueue request carries the authorization token of the target vehicle.
[0053] Step 103: The server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0054] The following provides a detailed description of steps 101 to 103 of the queuing authentication method in this embodiment.
[0055] In this embodiment, the server that generates the authorization token and executes the queuing request can both be the car manufacturer's server, such as... Figure 2 As shown, the queuing authentication method in this embodiment includes steps 201 to 203.
[0056] Step 201: The car manufacturer's server responds to the authorization token application request for authorizing the target vehicle to join the queue, determines whether the vehicle ownership of the target vehicle is legal based on the obtained ownership certificate information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle.
[0057] Step 202: FMS obtains the authorization token of the target vehicle and sends an enqueue request for the target vehicle to the vehicle manufacturer's server. The enqueue request carries the authorization token of the target vehicle.
[0058] Step 203: The car manufacturer's server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the platoon based on the verification result of the authorization token.
[0059] Optionally, the first server generating the authorization token can be a server of a third-party organization trusted by the car manufacturer's server, while the second server executing the enqueue request is the car manufacturer's server, such as... Figure 3 As shown, the queuing authentication method in this embodiment includes steps 301 to 303.
[0060] Step 301: The first server responds to the authorization token application request for authorizing the target vehicle to join the queue, determines whether the ownership of the target vehicle is legal based on the obtained ownership certificate information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle.
[0061] Step 302: FMS obtains the authorization token of the target vehicle and sends an enqueue request for the target vehicle to the second server. The enqueue request carries the authorization token of the target vehicle.
[0062] Step 303: The second server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0063] The ownership certificate information of the target vehicle is used to prove the legality (i.e. authenticity) of the owner's ownership of the target vehicle. The owner can be a corporate owner or a private owner. A corporate owner can be a fleet. The fleet's ownership of the vehicle can be ownership of the vehicle purchased by the owner or ownership of the vehicle by the fleet after the private owner transfers the vehicle to the fleet. For example, a private owner can apply to transfer their personal vehicle to the fleet manufacturer through the car manufacturer's app or other official channels. The car manufacturer's server verifies the owner's identity through the owner information entered in the background and then allows the private owner to transfer the ownership of the vehicle to the fleet manufacturer.
[0064] When the vehicle owner is a fleet, the ownership certificate information of the target vehicle may include: the vehicle purchase invoice, the vehicle ownership certificate issued by a credible institution such as the vehicle management office, or other documents that can prove that the fleet owns the vehicle. FMS sends the ownership certificate information of the target vehicle to the server. The server verifies the authenticity of the obtained ownership certificate information of the target vehicle to determine whether the fleet is the legal owner of the target vehicle, that is, whether the fleet legally owns the target vehicle.
[0065] When the vehicle owner is a private car owner, the ownership certificate information for the target vehicle can be provided by the owner's device. The owner's device can perform strong identity authentication on the private car owner. After successful authentication, the owner's device can send the private car owner's identity information and electronic driver's license to the server. The server then determines whether the private car owner's ownership of the target vehicle is legal based on the received identity information and electronic driver's license. It is understood that this embodiment of the invention does not impose specific restrictions on the vehicle ownership verification method, as long as the authenticity of the owner's vehicle ownership can be proven.
[0066] When the vehicle owner is a private owner, the authorization token application request can be initiated by the owner's device. The server will generate an authorization token and send it to the owner's device. The owner's device will then forward the authorization token to the FMS (Fulfilled Management System), and the FMS will obtain the authorization token through the owner's device. When the vehicle owner is a fleet or other corporate owner, the authorization token application request can be initiated by the FMS. The server will generate an authorization token and send it to the FMS, enabling the FMS to obtain the authorization token for the target vehicle. The party initiating the authorization token application request provides the server with proof of ownership information for the target vehicle. If the server determines that the vehicle's ownership is legitimate based on the proof of ownership information, it will generate an authorization token according to the application request. Specifically, the server generates an authorization token when it determines that the vehicle's ownership is legitimate and the target vehicle meets the unique fleet entry conditions. The unique fleet entry conditions mean that the target vehicle has no authorization token generation record or the target vehicle with an existing authorization token is in the demobilized state. That is, there is only one authorization token for a vehicle at any given time. A vehicle can only apply for a new authorization token after leaving the previous fleet, ensuring that the target vehicle can only join a unique fleet at a time.
[0067] When the vehicle owner is a private car owner, the application request initiated by the owner's device can carry the target vehicle identifier and the target FMS identifier. The server generates an authorization token based on the target vehicle identifier and the target FMS identifier. The authorization token includes: authorization information and the server's signature on the authorization information. The authorization information may include: the token validity period, the target vehicle identifier, and the identifier of the authorized FMS.
[0068] When the vehicle owner is a fleet manufacturer or other corporate owner, the FMS sends an authorization token request to the server. This request may include the target vehicle's identifier. The server generates an authorization token based on the target vehicle's identifier and the FMS's identifier. The authorization token includes authorization information and the server's signature on that information. The authorization information may include the token's validity period, the target vehicle's identifier, and the identifier of the authorized FMS. It is understood that the authorization token generated by the server based on the FMS's request may not necessarily include the FMS's identifier.
[0069] The server determines whether to allow the target vehicle to join the queue based on the following verification results: the verification result of the target vehicle's authorization token, whether the queueing request is within the validity period of the target vehicle's token, and whether the queueing relationship of the vehicle requesting to join the queue is the same as the queueing relationship represented by the authorization token.
[0070] When the authorization token is generated by the car manufacturer's server, the car manufacturer's server uses its own public key to verify the signature data in the authorization token based on the enqueue request. If the signature verification is successful and the enqueue request is within the validity period of the authorization token of the target vehicle, and whether the enqueue relationship of the vehicle requesting enqueue is the same as the vehicle enqueue relationship represented by the authorization token, then the vehicle is allowed to enqueue, and the enqueue process under the CCC standard can be executed; otherwise, the vehicle is prohibited from enqueueing.
[0071] When the authorization token is generated by the first server, the first server signs the authorization information of the token using its own private key. When the second server authenticates the enqueue request, the second server stores the digital certificate of the first server, which contains the public key of the first server. The second server uses the public key of the first server to verify the signature of the authorization token issued by the first server.
[0072] Figure 4 This is a flowchart illustrating the queuing authentication method provided in Embodiment 2 of the present invention. The method of this application can be executed by a queuing authentication device provided in this embodiment of the invention. This device can be implemented in software and configured in the FMS. Specifically, this embodiment of the invention includes steps 401 to 402.
[0073] Step 401: FMS obtains the authorization token for the target vehicle.
[0074] Step 402: FMS sends an enqueue request for the target vehicle to the server. The enqueue request carries the authorization token of the target vehicle.
[0075] The server is configured to: respond to an authorization token application request for authorizing a target vehicle to join the queue, determine whether the vehicle ownership of the target vehicle is legal based on the obtained ownership certificate information of the target vehicle, and generate an authorization token based on the verification result of the legality of the vehicle ownership of the target vehicle; and verify the authorization token of the target vehicle in response to the joining request, and determine whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0076] The parts that are the same as those in Embodiment 1 will not be repeated here.
[0077] Figure 5 This is a flowchart illustrating the queuing authentication method provided in Embodiment 3 of the present invention. The method of this application can be executed by a queuing authentication device provided in this embodiment of the invention. This device can be implemented in software and configured on a server. Specifically, this embodiment of the invention includes steps 501 to 502.
[0078] Step 501: In response to the authorization token application request for authorizing the target vehicle to join the queue, the server determines whether the vehicle ownership of the target vehicle is legal based on the obtained ownership certificate information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle.
[0079] Step 502: In response to the enqueue request, the server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to enqueue based on the verification result of the authorization token.
[0080] The FMS is configured to: obtain the authorization token of the target vehicle, and send an enqueue request for the target vehicle to the server, with the enqueue request carrying the authorization token of the target vehicle.
[0081] The parts that are the same as those in Embodiment 1 will not be repeated here.
[0082] The following describes the queuing authentication method in the queuing authentication system.
[0083] Figure 6 This is a flowchart illustrating the queuing authentication method provided in Embodiment 4 of the present invention. This method is used to implement queuing authorization based on vehicle ownership. The method can be implemented based on the queuing authentication system provided in this embodiment of the invention. The queuing authentication system includes an FMS, a server, and vehicle owner devices that are interconnected. There are multiple FMS, servers, and vehicle owner devices. The queuing authentication method of this embodiment of the invention includes two phases: Phase 1 and Phase 2.
[0084] Phase 1: Vehicle Owner Pre-authorization and Token Application
[0085] Phase 1 includes two implementation methods. The first implementation method mainly includes the following main steps:
[0086] S11. Provide vehicle ownership certificates to the vehicle manufacturer's server.
[0087] Vehicle owners complete strong identity authentication through the OEM's official app or other methods (such as facial recognition, electronic driver's license authentication, etc.). Vehicle owners can be private car owners or organizations or companies that own vehicles. Strong identity authentication can be performed by the vehicle manufacturer's server. The strong identity authentication process can use well-known technologies, which will not be elaborated here.
[0088] S12. The car manufacturer's server verifies whether the vehicle ownership is legitimate. If the verification is successful, an authorization token is generated.
[0089] The process involves the vehicle owner's device sending an authorization token request to the vehicle manufacturer's server. This request includes the authenticated vehicle owner's identity information, the vehicle identifier, and the identifier of the fleet management system (FMS) to which authorization is planned. The vehicle manufacturer's server verifies the validity of the vehicle owner's identity and their ownership of the target vehicle. Upon successful verification, the vehicle manufacturer's server generates a structured authorization token, which includes, but is not limited to, the following fields:
[0090] Vehicle_ID: A unique identifier for the target vehicle
[0091] FMS_ID: Identifier of the authorized fleet management system
[0092] Validity_Period: Token validity period (e.g., 24 hours)
[0093] Signature: The automaker's server uses its private key to sign the above fields.
[0094] S13, The car manufacturer's server issues an authorization token.
[0095] Another embodiment of Phase One mainly includes the following steps:
[0096] S21. The car manufacturer's server and the third-party server establish mutual trust.
[0097] The automaker's server obtains and stores the public key certificate of the third-party server. The public key certificate of the third-party server can be issued by a CA trusted by the automaker's server.
[0098] S22. Provide vehicle ownership certificates to a third-party server.
[0099] Vehicle ownership documents can be provided by the vehicle owner's equipment or FMS.
[0100] S23. The third-party server verifies whether the vehicle ownership is legitimate. If the verification is successful, an authorization token is generated.
[0101] S24. The third-party server issues an authorization token to the vehicle owner's device or FMS.
[0102] Phase Two: The fleet management provider initiates a queuing request with a token.
[0103] Phase Two includes the following main steps:
[0104] S31, Provide an authorization token.
[0105] Provide an authorization token to FMS.
[0106] S32 and FMS send a vehicle queuing request, carrying an authorization token.
[0107] When requesting to join the queue, FMS carries the authorization token obtained in Phase 1.
[0108] S33. Verify whether queuing is allowed based on the authorization token.
[0109] The vehicle manufacturer's server or its trusted third-party server verifies the authenticity of the authorization token signature using a public key. After successful verification, the following binding relationships are extracted and verified:
[0110] Verification A: Check if the Vehicle ID in the authorization token matches the VehicleId in the queuing request;
[0111] Verification B: Whether the FMS_ID in the authorization token matches the identifier in the server certificate of the FMS that initiated the enqueue request;
[0112] Verification C: Whether the enqueue request is within the validity period of the authorization token.
[0113] After all checks A through C pass, the car manufacturer's server determines that the vehicle can join the queue. At this point, S34 is executed: check passed, vehicle allowed to join the queue, and standard queuing procedures are followed. If any check A through C fails, S35 is executed: check failed, vehicle refused to join the queue.
[0114] In this embodiment of the invention, in response to an authorization token application request for authorizing a target vehicle to join the queue, the server determines the legality of the target vehicle's ownership based on the obtained ownership proof information. Based on the verification result of the target vehicle's ownership legality, an authorization token is generated. The FMS obtains the target vehicle's authorization token and sends a queue entry request to the server, carrying the target vehicle's authorization token. The server verifies the target vehicle's authorization token and determines whether to allow the target vehicle to join the queue based on the verification result. Compared with existing queue entry authentication methods based on hardware tokens, this method does not rely on hardware tokens but is based on digital authorization of vehicle ownership. It is also applicable to vehicles without hardware tokens, thus having a wide range of applications. It uses strong identity authentication initiated by the vehicle owner, rather than hardware token holder authentication, making it impossible for owners not certified by the OEM to forge authentication. The vehicle's queue entry relationship is bound to the authorization token, making tampering ineffective and highly secure, effectively preventing unauthorized queue entry after hardware token leakage.
[0115] Embodiment 5 of the present invention provides an in-line authentication device configured in the FMS. For example... Figure 7 As shown, the queuing authentication device 700 includes: an acquisition module 702 and a request module 704.
[0116] The acquisition module 702 is used by FMS to acquire the authorization token of the target vehicle.
[0117] Request module 704 is used by FMS to send an enqueue request for the target vehicle to the server. The enqueue request carries the authorization token of the target vehicle.
[0118] The server is configured to: respond to an authorization token application request for authorizing a target vehicle to join the queue, determine whether the vehicle ownership of the target vehicle is legal based on the obtained ownership certificate information of the target vehicle, and generate an authorization token based on the verification result of the legality of the vehicle ownership of the target vehicle; and verify the authorization token of the target vehicle in response to the joining request, and determine whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
[0119] Compared with the prior art, the queuing authentication device of this invention generates an authorization token based on the verification of the legality of vehicle ownership, and verifies the queuing request based on the authorization token. This ensures that queuing is based on legal vehicle ownership and prevents illegal queuing caused by illegal use when queuing authentication is based on vehicle usage rights. Therefore, compared with queuing authentication methods based on vehicle usage rights, such as hardware tokens, it has higher security and wider applicability.
[0120] Embodiment 6 of the present invention provides a queuing authentication device configured on a server. For example... Figure 8 As shown, the queuing authentication device 800 includes a token generation module 802 and a queuing verification module 804.
[0121] The token generation module 802 is used by the server to respond to the authorization token application request for authorizing the target vehicle to join the queue, determine whether the vehicle ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generate an authorization token based on the legality verification result of the vehicle ownership of the target vehicle.
[0122] The queuing verification module 804 is used by the server to verify the authorization token of the target vehicle in response to the queuing request, and to determine whether the target vehicle is allowed to join the queuing based on the verification result of the authorization token.
[0123] The FMS is configured to: obtain the authorization token of the target vehicle, and send an enqueue request for the target vehicle to the server, with the enqueue request carrying the authorization token of the target vehicle.
[0124] Compared with the prior art, the queuing authentication device of this invention generates an authorization token based on the verification of the legality of vehicle ownership, and verifies the queuing request based on the authorization token. This ensures that queuing is based on legal vehicle ownership and prevents illegal queuing caused by illegal use when queuing authentication is based on vehicle usage rights. Therefore, compared with queuing authentication methods based on vehicle usage rights, such as hardware tokens, it has higher security and wider applicability.
[0125] Figure 9 This is a schematic diagram of the structure of an electronic device provided in Embodiment 8 of the present invention. The electronic device can be the FMS or server in the queuing authentication system disclosed in this embodiment. The electronic device 90 includes a memory 81, a processor 82, and a computer program stored in the memory 81 and executable on the processor 82. When the processor 82 executes the program, it implements the queuing method described in the foregoing embodiments.
[0126] Embodiment 10 of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a computer processor, is used to perform the technical solution of any method embodiment.
[0127] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or grid device, etc.) to execute the methods described in the various embodiments of the present invention.
[0128] It is worth noting that in the embodiments of the above-mentioned device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy distinction between each other and are not used to limit the scope of protection of the present invention.
[0129] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.
Claims
1. A method for queuing authentication, characterized in that, The method is applied to an inbound authentication system, which includes a server and an FMS connected via communication; the method includes: In response to the authorization token application request for authorizing the target vehicle to join the convoy, the server determines whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle. The FMS obtains the authorization token of the target vehicle, and the FMS sends an enqueue request for the target vehicle to the server, the enqueue request carrying the authorization token of the target vehicle; The server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
2. The method according to claim 1, characterized in that, The server includes: a first server and a second server, wherein the second server pre-stores the digital certificate of the first server; correspondingly, the method includes: In response to the authorization token application request for authorizing the target vehicle to join the queue, the first server determines whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generates an authorization token based on the legality verification result of the ownership of the target vehicle. The FMS obtains the authorization token of the target vehicle, and the FMS sends an enqueue request for the target vehicle to the second server, the enqueue request carrying the authorization token of the target vehicle; The second server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
3. The method according to claim 1, characterized in that, The authorization token includes: authorization information and the server's signature on the authorization information. The authorization information includes: token validity period, the identifier of the target vehicle, and the identifier of the authorized FMS. Accordingly, the server verifies the authorization token of the target vehicle and determines whether to allow the target vehicle to join the platoon based on the verification result of the authorization token, including: The server determines whether to allow the target vehicle to join the queue based on the following verification results: the verification result of the authorization token of the target vehicle, whether the queueing request is within the validity period of the authorization token of the target vehicle, and whether the queueing relationship of the vehicle requesting to join the queue is the same as the queueing relationship represented by the authorization token.
4. The method according to claim 1, characterized in that, The method includes: The authorization token request is initiated by the vehicle owner's device, and the server sends the generated authorization token to the vehicle owner's device. The FMS obtains the authorization token through the vehicle owner's device; or the authorization token request is initiated by the FMS, and the server sends the generated authorization token to the FMS.
5. A method for queuing authentication, characterized in that, Applied to FMS, the method includes: The FMS obtains the authorization token of the target vehicle; The FMS sends an enqueue request for the target vehicle to the server, and the enqueue request carries the authorization token of the target vehicle. The server is configured to: respond to an authorization token application request for authorizing a target vehicle to join the queue, determine whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generate an authorization token based on the legality verification result of the ownership of the target vehicle; and verify the authorization token of the target vehicle in response to the joining request, and determine whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
6. A method for queuing authentication, characterized in that, Applied to a server, the method includes: In response to the authorization token application request for authorizing the target vehicle to join the convoy, the server determines whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generates an authorization token based on the legality verification result of the vehicle ownership of the target vehicle. The server responds to the enqueue request by verifying the authorization token of the target vehicle, and determines whether to allow the target vehicle to enqueue based on the verification result of the authorization token. The FMS is configured to: obtain the authorization token of the target vehicle, and send an enqueue request for the target vehicle to the server, wherein the enqueue request carries the authorization token of the target vehicle.
7. A queue entry authentication device, characterized in that, Configured in the FMS, the device includes: The acquisition module is used by FMS to obtain the authorization token of the target vehicle; The request module is used by the FMS to send an enqueue request for the target vehicle to the server, the enqueue request carrying the authorization token of the target vehicle; The server is configured to: respond to an authorization token application request for authorizing a target vehicle to join the queue, determine whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generate an authorization token based on the legality verification result of the ownership of the target vehicle; and verify the authorization token of the target vehicle in response to the joining request, and determine whether to allow the target vehicle to join the queue based on the verification result of the authorization token.
8. A queue entry authentication device, characterized in that, Configured on a server, the device includes: The token generation module is used by the server to respond to the authorization token application request for authorizing the target vehicle to join the queue, determine whether the ownership of the target vehicle is legal based on the obtained ownership proof information of the target vehicle, and generate an authorization token based on the legality verification result of the ownership of the target vehicle. The queuing verification module is used by the server to verify the authorization token of the target vehicle in response to the queuing request, and to determine whether to allow the target vehicle to join the queuing based on the verification result of the authorization token. The FMS is configured to: obtain the authorization token of the target vehicle, and send an enqueue request for the target vehicle to the server, wherein the enqueue request carries the authorization token of the target vehicle.
9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the queuing authentication method as described in any one of claims 1 to 6.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the queuing authentication method as described in any one of claims 1 to 6.