COMMUNICATION METHOD, APPARATUS, AND DEVICE

By employing distinct security mechanisms and protocol layers for V2X communication, the method addresses information leakage risks in unicast services, improving security and reliability through appropriate processing indications.

JP7733744B2Active Publication Date: 2025-09-03YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023557220
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-03-18
Filing Date
2022-03-09
Publication Date
2025-09-03
Estimated Expiration
2042-03-09

AI Technical Summary

Technical Problem

Current V2X communication security mechanisms are specific to broadcast services and are known to various receiving ends, posing a risk of information leakage and inferior security for unicast services.

Method used

Implementing a communication method that uses different security mechanisms and protocol layers for V2X end-to-end communication, where a first device indicates the security mechanism and protocol layer to a second device, allowing them to perform appropriate security processing on service data.

Benefits of technology

This approach reduces the risk of information leakage and improves the reliability of V2X end-to-end communication by ensuring that different devices use appropriate security mechanisms based on indicated protocols, enhancing security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007733744000001
    Figure 0007733744000001
  • Figure 0007733744000002
    Figure 0007733744000002
  • Figure 0007733744000003
    Figure 0007733744000003
Patent Text Reader

Abstract

The present application provides a communication method, an apparatus, and a device that can be applied to Internet of Vehicles. The communication method may include a first device obtaining service data and performing security processing on the service data. The first device transmits the service data and indication information to a second device. The indication information indicates a security mechanism used to perform the security processing on the service data, or indicates a protocol layer used to perform the security processing on the service data. According to the present application, the risk of information leakage can be reduced and the security of V2X end-to-end communication can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0002] The present application relates to the field of Internet of Vehicles, and in particular to communication methods, apparatus, and devices. [Background technology]

[0003] With the continued development of society, automobiles are becoming increasingly prevalent. To enhance driving safety, reduce congestion, and increase traffic efficiency, vehicles may obtain timely road condition information through certain methods, such as vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-pedestrian (V2P) communication, or vehicle-to-network (V2N) communication. These communication methods are sometimes collectively referred to as "vehicle-to-everything (V2X) communication," where X stands for "everything." The network used for V2X communication is called the Internet of Vehicles. Internet of Vehicles communication based on cellular networks is currently an important communication means, such as V2X (LTE-V2X) communication based on long term evolution (LTE) communication technology or V2X (5G-V2X) communication based on fifth generation (5G) communication technology.

[0004] Currently, with the continuous development of V2X services, V2X communication is no longer limited to service data supporting broadcast services. For example, a vehicle broadcasts basic vehicle information, such as its location, speed, and heading, to other vehicles or devices, and also seeks service data supporting unicast services, such as sensor data exchange between vehicles or between a vehicle and a roadside unit, or communication between a vehicle and a roadside unit, for example, to perform near-field charging or identity information query and management. However, current V2X security mechanisms are specific to broadcast services and are therefore known to various receiving ends. As a result, if current security mechanisms are still used to perform security processing on service data of unicast services, there may be a risk of information leakage, resulting in inferior security. Summary of the Invention [Means for solving the problem]

[0005] The present application provides communication methods, apparatus, and devices for improving the security of V2X end-to-end communications.

[0006] According to a first aspect, the present application provides a communication method. The communication method may be applied to a first device in an Internet of Vehicles. The first device may be, for example, an on-board unit (OBU) or a roadside unit (RSU). The method includes the first device obtaining service data and performing security processing on the service data. The first device transmits the service data and first indication information to a second device. The first indication information indicates a security mechanism used to perform the security processing on the service data or a protocol layer used to perform the security processing on the service data.

[0007] In the present application, the first device may perform security processing on the service data by using different security mechanisms. For example, the first device may perform security processing on the service data by using a first security mechanism, or may perform security processing on the service data by using a second security mechanism, or may perform security processing on the service data by using both the first security mechanism and the second security mechanism.

[0008] In some possible implementations, the first security mechanism may be understood as a general-purpose security mechanism applicable to V2X services of different service types, such as broadcast service and unicast service, and the second security mechanism may be understood as a dedicated security mechanism applicable to a pre-set service type of V2X service, such as unicast service or a specific service in the unicast service, such as near-field payment, electronic toll collection, vehicle identity management, or motor vehicle electronic identifier management.

[0009] In some possible implementations, the first security mode may be understood as a V2X-based security mechanism (e.g., an LTE-V2X security mechanism), e.g., a security mechanism provided at a security layer in the LTE-V2X protocol stack, and the second security mode may be understood as a security mechanism configured for a certain service type, e.g., a security mechanism provided at an application layer or a message layer in the LTE-V2X protocol stack for a unicast service or a specific service in the unicast service.

[0010] In some possible implementations, the first security mechanism may be understood as a security mechanism used to perform security processing at the security layer, and the second security mechanism may be understood as a security mechanism used to perform security processing at the application layer or message layer.

[0011] In the present application, the first device may further perform security processing on the service data at different protocol layers. For example, the first device may perform security processing on the service data at a security layer (e.g., a security layer in a V2X protocol stack), or the first device may perform security processing on the service data at an application layer (e.g., an application layer in a V2X protocol stack) or a message layer (e.g., a message layer in a V2X protocol stack), or the first device may perform security processing on the service data at both the application layer and the security layer, or the first device may perform security processing on the service data at both the message layer and the security layer.

[0012] In the present application, the first device indicates to the second device the security mechanism or protocol layer used to perform security processing on the service data, so that the second device can perform security processing on the service data by using a corresponding security mechanism based on the indication of the first indication information. This reduces the risk of information leakage, thereby improving the security of V2X end-to-end communication. Furthermore, the first device indicates to the second device the security mechanism or protocol layer used to perform security processing on the service data, so that the second device can perform security processing on the service data by using a corresponding security mechanism based on the indication of the first indication information. Because different security mechanisms are used, this reduces cases where the first device and the second device cannot communicate, thereby improving the reliability of V2X end-to-end communication.

[0013] In some possible implementations, the method may further include the first device transmitting identification information to the second device, the identification information identifying a service type of the service data.

[0014] It can be understood that in addition to transmitting the service data and the first indication information to the second device, the first device can further transmit identification information to the second device to indicate the service type of the service data to the second device. In this case, if the first indication information indicates that security processing on the service data is performed at the application layer, the second device can perform security processing on the service data in a security processing manner corresponding to the service type based on the service type indicated by the identification information.

[0015] Optionally, the service type may be near field payment, electronic toll collection, vehicle identity management, motor vehicle electronic identifier management, and the like.

[0016] In some possible implementations, the method may further include the first device transmitting second indication information to the second device, the second indication information indicating the content of the security processing, where the content of the security processing may be understood as a specific processing method corresponding to the security mechanism.

[0017] In the present application, the first indication information and the second indication information may be present in different messages. Alternatively, the first indication information and the second indication information may be located in two different information fields within the same message.

[0018] Specifically, when the first indication information and the second indication information can be located in two different information fields in the same message, the first indication information and the second indication information can be conveyed by using an N-bit string. The first K bits can indicate the security mechanism used to perform security processing on the service data. The last (NK) bits can indicate the content of the security processing performed on the service data. N is a positive integer, and K is a positive integer less than N.

[0019] In some possible implementations, when the security mechanism used for the security processing is the first security mechanism, the content of the security processing may include no encryption and no signature, only signature and no encryption, or signature and encryption.

[0020] In some possible implementations, when a second security mechanism is used for the security processing, the content of the security processing may include a first part and a second part related to the first part. The first part may include supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, or supporting security authentication and requiring encrypted communication. The second part may include asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication.

[0021] In this specification, the first part may be understood as a security mode, and the second part may be understood as a security function. The security mode is associated with the security function. The security mode indicates a security processing capability for a V2X service, and the security function indicates a security function used in a specific security mode. The security mode and the security function may cooperatively indicate a specific security processing to be performed on service data so that the second device can perform corresponding security processing on service data to implement V2X end-to-end secure communication.

[0022] In some possible implementations, the first device transmitting the service data and the indication information to the second device may specifically include the first device transmitting a data frame to the second device. The data frame includes a frame header and a payload. The indication information is carried in the frame header, and the service data is carried in the payload. The indication information may be only the first indication information, or may be the first indication information and the second indication information.

[0023] In some possible implementations, the frame header includes an extension field and extension field indication information. When the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

[0024] In some possible implementations, the frame header further includes association indication information, which indicates whether the indication information is associated with service data in the payload.

[0025] When the association indication information is set to a value of true, the association indication information indicates that the indication information is associated with the service data in the payload. When the association indication information is set to a value of false, the association indication information indicates that the indication information is not associated with the service data in the payload.

[0026] In some possible implementations, before the first device transmits the data frame to the second device, the method further includes the first device forwarding the service data and the indication information at the message layer to the network layer, and the first device encapsulating the service data and the indication information in the data frame at the network layer.

[0027] According to a second aspect, the present application further provides a communication method. The communication method may be applied to a second device in an Internet of Vehicles. The second device may be, for example, an OBU or an RSU. The method may include the second device receiving service data and first indication information from the first device. The second device performs security processing on the service data based on the first indication information. The first indication information indicates a security mechanism used to perform the security processing on the service data.

[0028] In some possible implementations, the method further includes the second device receiving identification information from the first device, the identification information identifying a service type of the service data.

[0029] In addition to transmitting the service data and the first indication information to the second device, the first device may further transmit identification information to the second device to indicate the service type of the service data and the protocol layer used to perform security processing on the service data to the second device. In this case, if the first indication information indicates that security processing on the service data is performed at the application layer, the second device may perform security processing on the service data in a security processing manner corresponding to the service type based on the service type indicated by the identification information.

[0030] Optionally, the service type may be near field payment, electronic toll collection, vehicle identity management, motor vehicle electronic identifier management, and the like.

[0031] In some possible implementations, in addition to the first indication information, the indication information received by the second device from the first device further includes second indication information, which indicates the content of the security processing. Here, the content of the security processing may be understood as a specific processing method corresponding to the security mechanism.

[0032] In the present application, the first indication information and the second indication information may be present in different messages. Alternatively, the first indication information and the second indication information may be located in two different information fields within the same message.

[0033] Specifically, when the first and second indication information may be located in two different information fields in the same message, the indication information including the first and second indication information may be carried using an N-bit string. The first K bits indicate the security mechanism used for the security process. The last (NK) bits of the string indicate the content of the security process. N is a positive integer, and K is a positive integer less than N.

[0034] In some possible implementations, when the security mechanism used for the security processing is the first security mechanism, the content of the security processing may include no encryption and no signature, a signature and no encryption, or a signature and encryption.

[0035] In some possible implementations, when the security mechanism used for the security processing is the second security mechanism, the content of the security processing may include a first part and a second part related to the first part. The first part may include supporting security authentication, not supporting security authentication, supporting security authentication but not requiring secure communication, or supporting security authentication and requiring secure communication. The second part may include asymmetric encryption, symmetric encryption, exclusive-OR two-way authentication, exclusive-OR one-way authentication, or symmetric encryption and one-way authentication.

[0036] In this specification, the first part may be understood as a security mode, and the second part may be understood as a security function. The security mode is associated with the security function. The security mode indicates a security processing capability for a V2X service, and the security function indicates a security function used in a specific security mode. The security mode and the security function may cooperatively indicate a specific security processing to be performed on service data so that the second device can perform corresponding security processing on service data to implement V2X end-to-end secure communication.

[0037] In some possible implementations, receiving the service data and the indication information from the first device by the second device may specifically include receiving a data frame from the first device by the second device. The data frame includes a frame header and a payload. The indication information is carried in the frame header, and the service data is carried in the payload. The indication information may be only the first indication information, or may be the first indication information and the second indication information.

[0038] In some possible implementations, the frame header includes an extension field and extension field indication information. When the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

[0039] In some possible implementations, the frame header further includes association indication information, which indicates whether the indication information is associated with service data in the payload.

[0040] When the association indication information is set to a value of true, the association indication information indicates that the indication information is associated with the service data in the payload. When the association indication information is set to a value of false, the association indication information indicates that the indication information is not associated with the service data in the payload.

[0041] In some possible implementations, after the second device receives the data frame from the first device, the method may further include the second device acquiring the service data and the indication information in the data frame at a network layer, the second device forwarding the service data and the indication information at the network layer to a message layer, and the second device performing security processing on the service data at the message layer based on the indication of the indication information.

[0042] In some possible implementations, the second device performing security processing on the service data at the message layer based on the indication of the first indication information may include: if the first indication information indicates that a first security mechanism is used for the security processing, the second device transferring the service data to the security layer at the message layer and performing security processing on the service data at the security layer by using the first security mechanism. Alternatively, if the first indication information indicates that a second security mechanism is used for the security processing, the second device transferring the service data to the application layer at the message layer and performing security processing on the service data at the application layer by using the second security mechanism. Optionally, if the first indication information indicates that a second security mechanism is used for the security processing, the second device performing security processing on the service data at the message layer by using the second security mechanism.

[0043] In some other possible implementations, the second device performing security processing on the service data at the message layer based on the indication of the first indication information may alternatively include, if the first indication information indicates that the first security mechanism and the second security mechanism are used for security processing, the second device transferring the service data to the security layer at the message layer. The second device performs security processing on the service data at the security layer by using the first security mechanism. The second device transfers the processed service data to the message layer at the security layer. The second device performs security processing on the processed service data at the message layer based on the second security mechanism. Optionally, the second device may transfer the processed service data to the application layer at the message layer and perform security processing on the processed service data at the application layer by using the second security mechanism. Alternatively, the second device may perform security processing on the processed service data at the message layer by using the second security mechanism.

[0044] In some possible implementations, the second device performing security processing on the service data at the message layer based on the indication of the first indication information may include, if the first indication information indicates performing security processing on the service data at the security layer, the second device transferring the service data to the security layer at the message layer and performing security processing on the service data at the security layer. Alternatively, if the first indication information indicates performing security processing on the service data at the application layer, the second device transferring the service data to the application layer at the message layer and performing security processing on the service data at the application layer. Alternatively, if the first indication information indicates performing security processing on the service data at the message layer, the second device performing security processing on the service data at the message layer.

[0045] In some other possible implementations, the second device performing security processing on the service data at the message layer based on the indication of the first indication information may alternatively include, if the first indication information indicates performing security processing on the service data at the security layer and the application layer, the second device transferring the service data at the message layer to the security layer; the second device performing security processing on the service data at the security layer; the second device transferring the processed service data at the security layer to the message layer; the second device transferring the processed service data at the message layer to the application layer and performing security processing on the processed service data at the application layer.

[0046] Optionally, the second device performing security processing on the service data at the message layer based on the indication of the first indication information may alternatively include, if the first indication information indicates performing security processing on the service data at the security layer and the message layer, the second device transferring the service data to the security layer at the message layer. The second device performs security processing on the service data at the security layer. The second device transfers the processed service data to the message layer at the security layer. The second device performs security processing on the processed service data at the message layer.

[0047] According to a third aspect, the present application provides a communication device. The communication device may be a first device in an Internet of Vehicles, a chip or system-on-chip in the first device, or a functional module configured to implement the method according to any one of the first aspect and possible implementations thereof and residing in the first device. The communication device may implement the functions performed by the first device in the aforementioned aspects or possible implementations. The functions may be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions. The communication device includes a processing module configured to obtain service data and perform security processing on the service data, and a transmission module configured to transmit the service data and indicia information to a second device. The indicia information indicates a security mechanism used to perform the security processing on the service data, or indicates a protocol layer used to perform the security processing on the service data.

[0048] In some possible implementations, the sending module is further configured to send identification information to the second device, the identification information identifying a service type of the service data.

[0049] In some possible implementations, the indication information further indicates the content of the security process.

[0050] In some possible implementations, the indication information is an N-bit string. The first K bits of the string indicate the security mechanism used for the security operation. The last (NK) bits of the string indicate the content of the security operation. N is a positive integer, and K is a positive integer less than N.

[0051] In some possible implementations, the indication information indicates a first security mechanism to be used for the security processing, or indicates a second security mechanism to be used for the security processing, or indicates the first security mechanism and the second security mechanism to be used for the security processing. Alternatively, the indication information indicates that security processing on the service data is to be performed at the application layer, at the security layer, or at the application layer and the security layer.

[0052] In some possible implementations, the first security mechanism is a V2X-based security mechanism, and the second security mechanism is a security mechanism configured for the service type.

[0053] In some possible implementations, when the security mechanism used for the security processing is the first security mechanism, the content of the security processing includes no encryption and no signature, signature only and no encryption, or signature and encryption.

[0054] In some possible implementations, when the security mechanism used for the security processing is the second security mechanism, the content of the security processing includes a first part and a second part related to the first part. The first part includes supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, or supporting security authentication and requiring encrypted communication. The second part includes asymmetric encryption, symmetric encryption, exclusive-OR two-way authentication, exclusive-OR one-way authentication, or symmetric encryption and one-way authentication.

[0055] In some possible implementations, the first device transmitting the service data and the indication information to the second device includes the first device transmitting a data frame to the second device, the data frame including a frame header and a payload, the indication information being carried in the frame header and the service data being carried in the payload.

[0056] In some possible implementations, the frame header includes an extension field and extension field indication information. When the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

[0057] In some possible implementations, the frame header further includes association indication information, which indicates whether the indication information is associated with service data in the payload.

[0058] In some possible implementations, the processing module is further configured to forward the service data and the indication information at the message layer to the network layer and encapsulate the service data and the indication information in the data frame at the network layer before the transmitting module transmits the data frame to the second device.

[0059] According to a fourth aspect, the present application provides a communication device. The communication device may be a second device in an Internet of Vehicles, or a chip or system-on-chip in the second device. Alternatively, the communication device may be a functional module in the second device configured to implement the method according to any one of the second aspect and possible implementations of the second aspect. The communication device may implement the functions performed by the second device in the aforementioned aspects or possible implementations. The functions may be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions. The communication device includes: a receiving module configured to receive a data frame from a first device, the data frame including service data and indicia information; and a processing module configured to perform security processing on the service data based on the indicia information. The indicia information indicates a security mechanism used to perform the security processing on the service data or indicates a protocol layer used to perform the security processing on the service data.

[0060] In some possible implementations, the receiving module is further configured to receive identification information from the first device, the identification information identifying a service type of the service data.

[0061] In some possible implementations, the indication information further indicates the content of the security process.

[0062] In some possible implementations, the indication information is an N-bit string. The first K bits of the string indicate the security mechanism used for the security operation. The last (NK) bits of the string indicate the content of the security operation. N is a positive integer, and K is a positive integer less than N.

[0063] In some possible implementations, the indication information indicates a first security mechanism to be used for the security processing, or indicates a second security mechanism to be used for the security processing, or indicates the first security mechanism and the second security mechanism to be used for the security processing. Alternatively, the indication information indicates that security processing on the service data is to be performed at the application layer, at the security layer, or at the application layer and the security layer.

[0064] In some possible implementations, the first security mechanism is a V2X-based security mechanism, and the second security mechanism is a security mechanism configured for the service type.

[0065] In some possible implementations, when the security mechanism used for the security processing is the first security mechanism, the content of the security processing includes no encryption and no signature, signature only and no encryption, or signature and encryption.

[0066] In some possible implementations, when the security mechanism used for the security processing is the second security mechanism, the content of the security processing includes a first part and a second part related to the first part. The first part includes supporting security authentication, not supporting security authentication, supporting security authentication but not requiring secure communication, or supporting security authentication and requiring secure communication. The second part includes asymmetric encryption, symmetric encryption, exclusive-OR two-way authentication, exclusive-OR one-way authentication, or symmetric encryption and one-way authentication.

[0067] In some possible implementations, the receiving module is particularly configured to receive a data frame from the first device, the data frame including a frame header and a payload, the indication information being carried in the frame header and the service data being carried in the payload.

[0068] In some implementations, the frame header includes an extension field and extension field indication information. When the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

[0069] In some possible implementations, the frame header further includes association indication information. The association indication information indicates whether the indication information is associated with the service data in the payload. When the association indication information is set to a value of true, the association indication information indicates that the indication information is associated with the service data in the payload. When the association indication information is set to a value of false, the association indication information indicates that the indication information is not associated with the service data in the payload.

[0070] In some possible implementations, after the second device receives the data frame sent by the first device, the apparatus further includes a processing module configured to obtain service data and indication information in the data frame at a network layer, forward the service data and indication information at the network layer to a message layer, and perform security processing on the service data at the message layer based on the indication of the indication information.

[0071] According to a fifth aspect, the present application provides a communication device, for example, a first device in an Internet of Vehicles. The communication device may include a processor and a memory. The processor is coupled to the memory. The processor is configured to read and execute instructions in the memory to implement a communication method according to any one of the first aspect and possible implementation forms of the first aspect.

[0072] According to a sixth aspect, the present application provides a communication device, for example, a second device in an Internet of Vehicles. The communication device includes a processor and a memory. The processor is coupled to the memory. The processor is configured to read and execute instructions in the memory to implement a communication method according to any one of the second aspect and possible implementation forms of the second aspect.

[0073] According to a seventh aspect, the present application provides a computer-readable storage medium storing instructions, the instructions being executable on a computer to perform the communication method according to any one of the first and second aspects.

[0074] According to an eighth aspect, the present application provides a computer program or computer program product, which, when run on a computer, enables the computer to perform the communication method according to any one of the first and second aspects.

[0075] It should be understood that the technical solutions of the third to eighth aspects of the present application are consistent with the technical solutions of the first and second aspects of the present application, and the beneficial effects achieved by the aspects and corresponding possible implementations are similar, and the details will not be described again.

[0076] In order to explain the technical solutions of the embodiments of the present application more clearly, the following describes the accompanying drawings used in the embodiments of the present application. [Brief explanation of the drawings]

[0077] [Figure 1] FIG. 1 is a schematic diagram of vehicle-to-vehicle and vehicle-to-infrastructure communication according to an embodiment of the present application. [Figure 2] FIG. 1 is a schematic diagram of a V2X deployment scenario according to an embodiment of the present application; [Figure 3] FIG. 1 is a schematic diagram of a V2X end-to-end protocol stack according to an embodiment of the present application. [Figure 4a] 1 is a schematic diagram of a V2X communication system according to an embodiment of the present application; FIG. [Figure 4b] 1 is a schematic diagram of a V2X communication system according to an embodiment of the present application; FIG. [Figure 5] 1 is a schematic flowchart of a communication method according to an embodiment of the present application; [Figure 6] 1 is a schematic diagram of labeling information according to an embodiment of the present application; [Figure 7] FIG. 2 is a schematic diagram of a data frame according to an embodiment of the present application; [Figure 8] 4 is a schematic flowchart of another communication method according to an embodiment of the present application; [Figure 9] 1 is a schematic diagram of the structure of a communication device according to an embodiment of the present application; [Figure 10] FIG. 2 is a schematic diagram of the structure of another communication device according to an embodiment of the present application; [Figure 11] 1 is a schematic diagram of the structure of a communication device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0078] The following describes embodiments of the present application with reference to the accompanying drawings in embodiments of the present application. In the following description, reference is made to the accompanying drawings that form a part of this application and show, by way of example, specific aspects of the embodiments of the present application or in which the embodiments of the present application may be used. It should be understood that the embodiments of the present application may be used in other ways and may include structural or logical changes not shown in the accompanying drawings. Therefore, the following detailed description should not be taken in a limiting sense, and the scope of the present application is defined by the appended claims. For example, it should be understood that the present disclosure relating to a described method may also apply to a corresponding device or system for performing the method, and vice versa. For example, when one or more particular method steps are described, the corresponding device may include one or more units, such as functional units, for performing the described method steps (e.g., one unit performing one or more steps, or multiple units each performing one or more of the steps), even if such one or more units are not explicitly depicted or shown in the accompanying drawings. Additionally, for example, when a particular apparatus is described based on one or more units, such as functional units, a corresponding method may include a step for implementing the functionality of the one or more units (e.g., a step for implementing the functionality of one or more units, or multiple steps, each for implementing the functionality of one or more units among the multiple units), even if one or more of such steps are not explicitly delineated or shown in the accompanying drawings. Furthermore, it should be understood that the features of various exemplary embodiments and / or aspects described in this application may be combined with each other, unless otherwise specified.

[0079] In an embodiment of the present application, FIG. 1 is a schematic diagram of vehicle-to-vehicle communication and vehicle-to-infrastructure communication according to an embodiment of the present application. Please refer to FIG. 1. A vehicle may timely obtain road condition information or perform cooperative communication with another device through V2V communication or V2I communication to improve driving safety, reduce congestion, increase traffic efficiency, etc. A vehicle may further obtain richer services by communicating with another device, for example, may perform instantaneous communication through V2P communication, vehicle-to-device (V2D) communication, or V2N communication to obtain more services. The aforementioned communication methods may be collectively referred to as V2X communication. A network used for V2X communication is called the Internet of Vehicles.

[0080] For example, further refer to FIG. 1. V2V communication and V2I communication are used as examples. Vehicle 11a may broadcast information about vehicle 11a to surrounding vehicles (e.g., vehicle 11b) through V2V communication. The information includes, for example, at least one of the following information: vehicle speed, direction of travel, vehicle location, whether emergency braking will be activated, etc. By obtaining such information, the driver can be more aware of traffic conditions outside of their field of view in order to predict and avoid dangers in advance. In V2I communication, in addition to the exchange of safety information mentioned above, infrastructure 12 may further provide various types of service information and data network access for vehicle 11a. Features such as electronic fare collection and in-vehicle entertainment all significantly enhance traffic intelligence.

[0081] Currently, dedicated short-range communications (DSRC) and V2X (C-V2X) communications based on cellular networks are important communication means for Internet vehicles, such as V2X communications based on long-term evolution (LTE) communications technology (LTE-V2X) or V2X communications based on fifth-generation (5G) communications technology (5G-V2X) in C-V2X communications. FIG. 2 is a schematic diagram of a V2X deployment scenario according to an embodiment of the present application. Please refer to FIG. 2. Regarding the deployment scenario, there may be a scenario with network coverage (as shown in FIG. 2(a)) and a scenario without network coverage (as shown in FIG. 2(b)). In a scenario with network coverage, transmission resources in the Internet of Vehicles may be allocated by the base station 21, and a terminal (e.g., an on board unit (OBU) 221 or a road side unit (RSU) 222) may perform data transmission on the transmission resources allocated by the base station 21. In a scenario without network coverage, a terminal (e.g., an OBU 221a, an OBU 221b, or an RSU 222) may obtain a configuration of a transmission resource pool by using preconfigured information, then autonomously select resources from the corresponding transmission resource pool, and perform direct communication between the terminals by using the autonomously selected transmission resources.

[0082] In some possible implementations, Figure 3 is a schematic diagram of a V2X end-to-end protocol stack according to an embodiment of the present application. See Figure 3. The protocol stack 300 may include an application layer 31, a security layer 32, a message layer 33, a network layer 34, and an access layer 35.

[0083] The application layer 31 may provide or define the applications used for communication and provide an interface to the underlying network for transmitting information. The application layer 31 may provide protocols that application processes follow during communication to communicate and collaborate between application processes in different devices for various applications or services.

[0084] The message layer 33 may provide or define the format and / or content of messages, for example, the format and / or content of message frames. The message layer 33 may define the format and / or content of messages in the form of message sets, where the format and content of message bodies for various services or contents are defined in the message sets to pack or encapsulate information or data from the application layer 31 into message frames specified in the message sets and deliver the message frames to the network layer 34. The message layer 33 may be used as an independent protocol layer between the application layer 31 and the network layer 34. Alternatively, the message layer 33 may be used as a sublayer of the application layer 31, i.e., its functionality is integrated into the application 31. The message layer 33 is connected to the network layer 34 below and supports specific user applications above.

[0085] The security layer 32 may provide or define security mechanisms, for example, may define instances where the security mechanisms for data at the message layer include at least one of the following security processes: signing, signature verification, encryption, decryption, integrity protection, etc.

[0086] The network layer 34 may provide or define network transmission protocols to support access layer transmission technologies to provide data network transmission services. For example, in one implementation, the network layer 34 may include a management layer and a data layer. The data layer mainly defines an adaptation layer, internet protocol (IP), user datagram protocol (UDP) / transmission control protocol (TCP), and dedicated short message protocol (DSMP). The data layer may transmit data streams between application layers, between management layer entities of different devices, or between management layer entities and application layers. The management layer mainly completes functions such as system configuration and maintenance. The management layer uses services in the data layer to transfer and manage data streams between different devices. A dedicated management entity (DME) is a universal set of management services, and the DME provides a management interface for data layer entities, including the DSMP protocol.

[0087] The access stratum 35 may provide or define the protocols and transmission mechanisms for wireless transmission. For example, when a C-V2X transmission mechanism is used, the access stratum may refer to the access stratum protocol of the cellular network. In another example, when a DSRC transmission mechanism is used, the access stratum may refer to the communication protocol used for DSRC.

[0088] In this embodiment of the present application, different protocol layers in the aforementioned protocol stack may be a set of one or more protocol sub-layers. For example, the application layer may include one or more service protocols (which may also be understood as application protocols) corresponding to different service types, and the security layer may include an LTE-V2X security protocol or a 5G-V2X security protocol. This is not particularly limited in this embodiment of the present application.

[0089] In relation to the aforementioned protocol stack, the transmitting end may transfer vehicle information (which may also be called service data) at the application layer to the message layer, transfer the vehicle information at the message layer by default to the security layer, perform security processing on the vehicle information at the security layer, then process the vehicle information obtained after the security processing at the message layer, network layer, and access layer in turn, and finally broadcast the processed vehicle information of the vehicle with the transmitting end to surrounding vehicles so that the receiving end may notify the driver in time when detecting a possible risk of collision to avoid an accident. The vehicle information may include, for example, at least one of the following information: vehicle speed, traveling direction, vehicle position, whether emergency braking will be activated, etc.

[0090] However, with the continuous development of V2X services, V2X is no longer limited to service data supporting broadcast services (e.g., the aforementioned vehicle information), but also seeks service data supporting unicast services (e.g., exchange of sensor data between vehicles or between vehicles and roadside units, or communication between vehicles and roadside units to perform near-field charging or identity information query and management). For unicast services, in consideration of confidentiality of end-to-end communication, when transmitting service data of unicast services, the transmitting end also performs security processing on the data. However, the security mechanism in the V2X security layer is specific to broadcast services and is known to various receiving ends. Therefore, if the security mechanism in the V2X security layer is used to perform security processing on service data of unicast services, there may be a risk of information leakage, resulting in inferior security.

[0091] A near-field payment service is used as an example. Typically, the application layer is responsible for the security mechanism. However, when LTE-V2X is used to carry a unicast service, such as near-field payment, the security layer may also be responsible for the security mechanism. It can be seen that for a V2X unicast service, there may be multiple options for the protocol layer that is responsible for the security mechanism. In addition, when security processing is performed, different encapsulation formats and interaction procedures are used in different protocol layers. If a protocol layer different from the security layer is responsible for the security mechanism, after receiving the service data, the receiving end may perform security processing on the service data by using a security mechanism different from that used by the transmitting end. As a result, the receiving end cannot perform security processing on the service data, such as signature verification or decryption, and the transmitting end cannot communicate with the receiving end, resulting in low reliability.

[0092] To solve the aforementioned problems, an embodiment of the present application provides a communication method, which can be applied to an Internet of Vehicles communication system to implement V2X end-to-end secure communication.

[0093] In one possible implementation, Figures 4(a) and 4(b) are schematic diagrams of a V2X communication system according to an embodiment of the present application. See Figure 4(a). The Internet of Vehicles communication system may include an OBU 41 and an RSU 42. The OBU 41 may include a positioning system 411, a processing unit 412, and a wireless communication subsystem 413. The RSU 42 may include a positioning system 421, a processing unit 422, and a wireless communication subsystem 423. See Figure 4(b). The Internet of Vehicles communication system 400 may include an OBU 41 and an OBU 43. The OBU 43 may include a positioning system 431, a processing unit 432, and a wireless communication subsystem 433. For the OBU 41, see the previous description. Details will not be described again.

[0094] The communication system may include one or more RSUs and one or more OBUs. The OBUs may perform direct communication, the RSUs may perform direct communication, or the OBUs and the RSUs may perform direct communication. Here, direct communication means that the RSUs or the OBUs communicate with each other via wireless transmission to perform direct communication and information exchange between vehicles, between vehicles and infrastructure, or between vehicles and pedestrians. Direct communication may also be referred to as side link or sidelink communication.

[0095] In V2X, the OBU may be referred to as an on-board unit, or an on-board device, vehicle control unit, or vehicle control device. The OBU may be located in a vehicle, or may be built into the vehicle and used as a part of the vehicle. In some possible implementations, the OBU may alternatively be a third-party device. This is not particularly limited in this embodiment of the present application. The RSU may be referred to as a roadside unit, and is generally deployed by road operators, and may transmit traffic signal information, traffic control information, road sign information, etc. This type of information has a high reliability requirement.

[0096] The following describes the communication method by using detailed embodiments.

[0097] First, it should be noted that the first device (i.e., a transmitting end device) and the second device (i.e., a receiving end device) in the following embodiments may be different types of devices in the Internet of Vehicles. For example, when a V2X communication system includes an OBU and an RSU, the first device may be an OBU and the second device may be an RSU, or the first device may be an RSU and the second device may be an OBU. Alternatively, when a V2X communication system includes an OBU and an OBU, the first device may be an OBU and the second device may be an OBU.

[0098] 5 is a schematic flowchart of a communication method according to an embodiment of the present application. Please refer to FIG. 5. The communication method may include the following steps:

[0099] S501: The first device acquires service data and performs security processing on the service data.

[0100] It can be understood that when the V2X service needs to transmit service data to the second device, the first device obtains the service data of the V2X service and performs security processing on the service data.

[0101] Optionally, the V2X service may be a unicast service or a broadcast service. For example, the service types of the V2X service may include, but are not limited to, near-field payment, electronic toll collection (e.g., electronic toll collection (ETC)), vehicle identity management, vehicle electronic identifier management, etc.

[0102] In this embodiment of the present application, the first device may perform security processing on the service data by using different security mechanisms.

[0103] For example, the first device may perform security processing on the service data by using a first security mechanism, or may perform security processing on the service data by using a second security mechanism, or may perform security processing on the service data by using both the first security mechanism and the second security mechanism.

[0104] Alternatively, the first security mechanism may be understood as a general-purpose security mechanism and is applicable to V2X services of different service types, and the second security mechanism may be understood as a dedicated security mechanism and is applicable to V2X services of a pre-configured service type, for example, near-field payment, electronic toll collection, vehicle identity management, or vehicle electronic identifier management.

[0105] Alternatively, the first security mechanism may be understood as a V2X-based security mechanism (e.g., an LTE-V2X security mechanism), e.g., a security mechanism provided at a security layer in the LTE-V2X protocol stack, and the second security mechanism may be understood as a security mechanism configured for a service type, e.g., a security mechanism provided at an application layer or a message layer in the LTE-V2X protocol stack for a particular service.

[0106] Alternatively, the first security mechanism may be understood as a security mechanism used to perform security processing at the security layer, and the second security mechanism may be understood as a security mechanism used to perform security processing at the application layer or message layer.

[0107] S502: The first device sends service data (ie, the service data obtained after security processing) and indication information to the second device.

[0108] In an embodiment, the indication information may indicate a security mechanism used to perform security processing on the service data. For example, the indication information may indicate a first security mechanism, a second security mechanism, or the first security mechanism and the second security mechanism used to perform security processing on the service data.

[0109] In some possible implementations, the indication information may further indicate the content of the security processing. It may be understood that the content of the security processing may be a specific security processing method.

[0110] In practical applications, the security mechanism and the content of the security process may be indicated by using different information fields in the same message. Of course, in another implementation, the security mechanism and the content of the security process may alternatively be indicated by using multiple different indication messages.

[0111] For example, when the security mechanism indicated by the indication information is a first security mechanism, the content of the corresponding security processing may include one of mechanisms such as no encryption and no signature, only signature and no encryption, or signature and encryption. Alternatively, when the security mechanism indicated by the indication information is a second security mechanism, the content of the corresponding security processing may include a security mode (i.e., a first part) and / or a security function (i.e., a second part). The security mode is associated with the security function. The security mode indicates security processing capabilities for the V2X service, and the security function indicates a security function used in a specific security mode. The security mode and the security function can jointly indicate a specific security processing to be performed on the service data.

[0112] In practical applications, the security modes may include, but are not limited to, supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, supporting security authentication and requiring encrypted communication, etc., and the security functions may include, but are not limited to, asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, symmetric encryption and one-way authentication, etc. For example, when the security mode supports security authentication, the associated security functions may be exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication, or when the security mode supports security authentication and requires encrypted communication, the associated security functions may include one of exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication, and one of asymmetric encryption or symmetric encryption.

[0113] In a specific implementation process, the indication information may be implemented in the form of a bitmap. The indication information may be a string of N bits. The first K bits of the string indicate a security mechanism, such as a first security mechanism and / or a second security mechanism, used to perform security processing on the service data. The last (NK) bits of the string indicate the content of the security processing, such as a security mode and / or a security function associated with the security mode. N is a positive integer, and K is a positive integer less than N. For example, FIG. 6 is a schematic diagram of indication information according to an embodiment of the present application. See (a) of FIG. 6. The indication information is assumed to be a 16-bit string. The first 4 bits (i.e., K=4) indicate a security mechanism 61a used to perform security processing on the service data. The last 12 bits indicate the content of the security processing 62.

[0114] In another embodiment, the indication information may indicate a protocol layer used to perform security processing on the service data. For example, the indication information may indicate performing security processing on the service data at a security layer, an application layer, or both a security layer and an application layer. In other words, the first device may perform security processing on the service data at a security layer (e.g., a security layer in a V2X protocol stack), or the first device may perform security processing on the service data at an application layer (e.g., an application layer in a V2X protocol stack), or the first device may perform security processing on the service data at both an application layer and a security layer.

[0115] In practical applications, the protocol layer and the content of the security process can be indicated by using different information fields in the indication information. Of course, in another implementation, the protocol layer and the content of the security process can be indicated by using multiple independent messages.

[0116] For example, when the protocol layer indicated by the indication information is a security layer, the content of the corresponding security processing may include one of mechanisms such as no encryption and no signature, only signature and no encryption, or signature and encryption. Alternatively, when the protocol layer indicated by the indication information is an application layer or a message layer, the content of the corresponding security processing may include a security mode (i.e., a first part) and / or a security function (i.e., a second part). The security mode is associated with the security function. The security mode indicates a security processing capability for the V2X service, and the security function indicates a security function used in a specific security mode. The security mode and the security function can jointly indicate a specific security processing to be performed on the service data.

[0117] In practical applications, the security modes may include, but are not limited to, supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, supporting security authentication and requiring encrypted communication, etc., and the security functions may include, but are not limited to, asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, symmetric encryption and one-way authentication, etc. For example, when the security mode supports security authentication, the associated security functions may be exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication, or when the security mode supports security authentication and requires encrypted communication, the associated security functions may include one of exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication, and one of asymmetric encryption or symmetric encryption.

[0118] In a specific implementation process, the indication information may be implemented in the form of a bitmap. The indication information may be a string of N bits. The first K bits of the string indicate the protocol layer used to perform security processing on the service data, for example, the security layer and / or the application layer / message layer. The last (NK) bits of the string indicate the content of the security processing, for example, the security mode and / or the security function related to the security mode. N is a positive integer, and K is a positive integer less than N. For example, see (b) of FIG. 6. The indication information is assumed to be a 16-bit string. The first 4 bits (i.e., K=4) indicate the protocol layer 61b used to perform security processing on the service data. The last 12 bits indicate the content of the security processing 62.

[0119] The aforementioned number of bits of the indication information is merely an example, and alternatively, another number of bits may be used for indication, for example, the first two bits indicate the security mechanism used to perform security processing on the service data, or the protocol layer used to perform security processing on the service data.

[0120] In some possible implementations, the method may further include the first device transmitting identification information to the second device, the identification information identifying a service type of the service data.

[0121] In addition to transmitting the service data and the indication information to the second device, the first device may further transmit identification information to the second device to indicate the service type of the service data to the second device. In this case, if the indication information indicates that security processing on the service data is to be performed at the application layer, the second device may perform security processing on the service data in a security processing manner corresponding to the service type based on the service type indicated by the identification information.

[0122] In this embodiment of the present application, by using the indication information, the second device can know the security mechanism used to perform security processing on the service data, and then perform the security processing by using the corresponding security mechanism. This reduces the risk of information leakage, thereby improving the security of V2X end-to-end communication. Furthermore, because different security mechanisms are used, the cases in which the first device and the second device cannot communicate are reduced, and the reliability of V2X end-to-end communication is improved.

[0123] S503: The second device performs security processing on the service data based on the indication information.

[0124] It may be understood that after receiving the service data and the indication information from the first device, the second device may perform security processing on the service data based on the security mechanism or protocol layer indicated by the indication information.

[0125] In one embodiment, if the security mechanism indicated by the indication information is the first security mechanism, the second device performs security processing on the service data by using the first security mechanism. Alternatively, if the security mechanism indicated by the indication information is the second security mechanism, the second device performs security processing on the service data by using the second security mechanism. Alternatively, if the security mechanisms indicated by the indication information are the first security mechanism and the second security mechanism, the second device performs security processing on the service data by using the first security mechanism and the second security mechanism.

[0126] Furthermore, the indication information further indicates the content of the security processing. In this case, the second device may perform the security processing on the service data based on the security mechanism and the content of the security processing indicated by the indication information. For example, if the security mechanism indicated by the indication information is a first security mechanism and the content of the security processing is a first content (e.g., with encryption and without signature), the second device performs the security processing on the service data by using the first security mechanism and the first content. Alternatively, if the security mechanism indicated by the indication information is a second security mechanism and the content of the security processing is a second content (e.g., supporting security authentication and using exclusive-OR two-way authentication), the second device performs the security processing on the service data by using the second security mechanism and the second content.

[0127] In another embodiment, if the protocol layer indicated by the indication information is a security layer, the second device performs security processing on the service data at the security layer. Alternatively, if the protocol layer indicated by the indication information is an application layer or a message layer, the second device performs security processing on the service data at the application layer or the message layer. Alternatively, if the protocol layer indicated by the indication information is a security layer and an application layer, the second device performs security processing on the service data at the security layer and the application layer. Alternatively, if the protocol layer indicated by the indication information is a security layer and a message layer, the second device performs security processing on the service data at the security layer and the message layer.

[0128] Furthermore, the indication information further indicates the content of the security processing. In this case, the second device may perform the security processing on the service data based on the protocol layer and the content of the security processing indicated by the indication information. For example, if the protocol layer indicated by the indication information is the security layer and the content of the security processing is a first content, the second device performs the security processing on the service data at the security layer by using the first content. If the protocol layer indicated by the indication information is the application layer or the message layer and the content of the security processing is a second content, the second device performs the security processing on the service data at the application layer or the message layer by using the second content.

[0129] In some possible implementations, S502 may be implemented in the following manner: A first device sends a data frame to a second device. The data frame may include a frame header and a payload. Indication information is carried in the frame header, and service data is carried in the payload.

[0130] For example, Figure 7 is a schematic diagram of a data frame according to an embodiment of the present application. See (a) and (b) of Figure 7. The structure of the data frame may include a frame header 71 and a payload 72. Indication information may be carried in the frame header 71, and service data may be carried in the payload 72.

[0131] 7(a). The frame header 71 may further include a header extension field 711 and a header extension indicator 712. When encapsulating a data frame, the first device may carry indicator information in the extension field 711. In this case, the extension field indicator 712 may be set to a value of true to indicate that the extension field of the data frame carries indicator information. In this case, the indicator information carried in the extension field 711 is associated with the service data carried in the payload 72 by default.

[0132] In some possible implementations, the first device may further carry identification information, i.e., an application identifier corresponding to the service data, in the data frame. See (a) and (b) of FIG. 7. The identification information may be carried in an application identifier (application ID, AID) field 713 in the frame header 71. Optionally, the association indication information 714 may further indicate whether there is an association relationship between the indication information and the identification information. When the association indication information 714 is set to a true value (TRUE), it indicates that the indication information is associated with the identification information. When the association indication information 714 is set to a false value (FALSE), it indicates that the indication information does not have an association relationship with the identification information.

[0133] For example, the data frame may be a data frame at the network layer, such as a dedicated short message (DSM) frame or a dedicated service advertisement frame, which is not particularly limited in this embodiment of the present application.

[0134] The following illustrates the security mechanism by which the sign information is used to perform security processing on the service data, and describes the above communication method with reference to the above V2X protocol stack by using an example in which the sign information is carried in a data frame.

[0135] 8 is a schematic flowchart of another communication method according to an embodiment of the present application. Please refer to FIG. 8. The communication method may include the following steps:

[0136] S801: A first device obtains service data of a V2X service (i.e., a first service) and performs security processing on the service data.

[0137] S802: A first device sends a data frame to a second device, where the data frame carries service data and indication information corresponding to the service data.

[0138] In this specification, the indicia indicates the security mechanism used to perform security processing on the service data.

[0139] For example, the indication information may indicate that the security mechanism used to perform security processing on the service data is an LTE-V2X security mechanism (which may be understood as a security mechanism provided in the LTE-V2X security layer in the aforementioned protocol stack). Alternatively, the indication information may indicate that a security mechanism corresponding to near-field payment (which may be understood as a security mechanism provided in a service protocol corresponding to near-field payment) is used for the service data. Alternatively, the indication information may indicate that a security mechanism corresponding to identity management (which may be understood as a security mechanism provided in a service protocol corresponding to identity management) is used for the service data. Different types of V2X services correspond to different service protocols. Therefore, the security mechanisms used for the service data of these V2X services may be provided in different service protocols.

[0140] In some possible implementations, in addition to indicating the security mechanism used for the service data, the indication information may further indicate the content of security processing. It can be understood that the content of security processing may be specific processing content corresponding to the security mechanism. For example, when the security mechanism used for the service data is the LTE-V2X security mechanism, the corresponding processing content may include one of mechanisms such as no encryption and no signature, signature only but no encryption, or signature and encryption. When the security mechanism used for the service data is a security mechanism corresponding to the V2X service, the corresponding processing content may include a security mode (i.e., a first part) and a security function (i.e., a second part). The security mode is associated with the security function. The security mode indicates security processing capabilities for the V2X service, and the security function indicates the security function used in the specific security mode. The security mode and the security function can cooperatively indicate specific security processing to be performed on the service data so that the second device can perform corresponding security processing on the service data to enhance the reliability of V2X end-to-end communication.

[0141] In practical applications, the security modes may include, but are not limited to, supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, supporting security authentication and requiring encrypted communication, etc., and the security functions may include, but are not limited to, asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, symmetric encryption and one-way authentication, etc. For example, when the security mode supports security authentication, the associated security functions may be exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication, or when the security mode supports security authentication and requires encrypted communication, the associated security functions may include one of exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication, and one of asymmetric encryption or symmetric encryption.

[0142] For example, the indication information may be implemented in the form of a bitmap. The indication information may be a string of N bits. The first K bits of the string indicate that a security mechanism provided in the protocol layer is used for the service data. The last (NK) bits of the string indicate a specific mechanism (i.e., the content of the security processing performed under the security mechanism) used for the service data. N is a positive integer, and K is a positive integer less than N.

[0143] For example, see further FIG. 6. The indication information is assumed to be a 16-bit string. The first 4 bits (i.e., K=4) indicate that a security mechanism provided in the protocol layer is used for service data. The last 12 bits indicate a specific mechanism (i.e., the content of the security processing performed under the security mechanism). In this case, if the indication information indicates that an LTE-V2X security mechanism is used for service data, the first 4 bits may be set to 0000. If the indication information indicates that a security mechanism provided in the application layer corresponding to ETC is used for service data, the first 4 bits may be set to 0001. If the indication information indicates that a security mechanism provided in the application layer corresponding to identity management is used for service data, the first 4 bits may be set to 0010.

[0144] Correspondingly, in one implementation, if the first four bits are set to 0000, the last 12 bits indicate, in ascending order, no encryption and no signature (first bit), signature only and no encryption (second bit), and signature and encryption (third bit). If a bit is set to 1, it indicates that the specific mechanism corresponding to that bit is used. Conversely, if a bit is set to 0, it indicates that the specific mechanism corresponding to that bit is not used. It can be understood that if the last 12 bits of the string are 000000000001, it indicates that the specific mechanism is no encryption and no signature. If the last 12 bits of the string are 000000000010, it indicates that the specific mechanism is signature only and no encryption. If the last 12 bits of the string are 000000000100, it indicates that the specific mechanism is signed and encrypted.

[0145] Alternatively, if the first four bits are set to 0010, in the last 12 bits, the 11th and 12th bits indicate a security mode. Here, 00 indicates that security authentication is not supported, 01 indicates that security authentication is supported, 10 indicates that security authentication is supported but encrypted communication is not required, and 11 indicates that security authentication is supported and encrypted communication is required. Bits 1 to 7 indicate security functions. Bit 1 indicates that the OBU supports exclusive-or one-way authentication for the RSU. Bit 2 indicates that the OBU supports symmetric encryption and one-way authentication for the RSU. Bit 3 indicates that the RSU supports exclusive-or one-way authentication for the OBU. Bit 4 indicates that the RSU supports symmetric encryption and one-way authentication for the OBU. Bit 5 indicates exclusive-or two-way authentication. Bit 6 indicates symmetric encryption. Bit 7 indicates encrypted communication. Similarly, if a bit among bits 1 to 7 is set to 1, it indicates that the specific security function corresponding to the bit is used. Conversely, if a bit among the first through seventh bits is set to 0, it indicates that the particular security feature corresponding to the bit is not used.

[0146] Of course, the implementation of the marking information is not limited to the above example. Those skilled in the art may set the marking information based on their own requirements, which is not particularly limited in this embodiment of the present application.

[0147] In some possible implementations, before S802, the first device acquires service data (which has undergone security processing) and corresponding indication information at the message layer. Then, the first device transfers the service data and corresponding indication information to the network layer at the message layer. Finally, the first device encapsulates the service data and corresponding indication information into a data frame at the network layer and transmits the data frame to the second device by using the access layer. After receiving the data frame, the second device may determine a security mechanism to be used for the service data based on the indication information in the data frame, and then perform corresponding security processing on the service data to enhance the reliability of V2X end-to-end communication.

[0148] In a specific implementation process, the first device may perform security processing on the service data at the application layer and then transfer the service data to the message layer.The first device may then determine the security mechanism used to perform service processing on the service data at the message layer based on the encapsulation format of the service data, and then determine the indication information corresponding to the service data.Alternatively, the first device may transfer the corresponding indication information when transferring the service data at the application layer to the message layer, and then obtain the service data and the corresponding indication information at the message layer.

[0149] In some possible implementations, before S802, the first device may further acquire, at the message layer, an application identifier corresponding to the service data. The application identifier indicates a service type corresponding to the service data. Similar to the above-described manner of acquiring indication information, the application identifier may be transferred by the first device at the application layer to the message layer, or may be determined by the first device at the message layer based on the encapsulation format of the service data. The first device may further transfer the application identifier when transferring the service data and indication information at the message layer to the network layer. In this case, the first device may encapsulate the service data, the indication information corresponding to the service data, and the application identifier into a data frame at the network layer, and then transmit the data frame to the second device by using the access layer.

[0150] Next, after S802, S803 is executed. Specifically, the second device analyzes the data frame to obtain service data and signage information.

[0151] It can be understood that the second device receives the data frame from the network layer of the first device at the network layer, then decapsulates the data frame at the network layer to extract the service data and the indication information from the data frame, and then forwards the service data and the indication information at the network layer to the message layer.

[0152] In some possible implementations, if the data frame further carries an application identifier corresponding to the service data, the second device may further extract the application identifier when decapsulating the data frame at the network layer, and then forward the application identifier corresponding to the service data to the message layer at the network layer to indicate the service type corresponding to the service data.

[0153] S804: The second device performs security processing on the service data based on the security mechanism indicated by the indication information.

[0154] It can be understood that the second device receives the service data and the indication information transferred at the network layer at the message layer. Then, the second device determines the security mechanism to be used for the service data at the message layer based on the indication of the indication information. Finally, the second device performs security processing on the service data at the message layer based on the security mechanism indicated by the indication information.

[0155] For example, when the indication information indicates that LTE-V2X security mechanism A is to be used for the service data, the second device transfers the service data to the security layer at the message layer and performs security processing on the service data at the security layer based on security mechanism A. Alternatively, when the indication information indicates that security mechanism B corresponding to near-field payment is to be used for the service data, the second device performs security processing on the service data at the message layer based on security mechanism B. In addition, when the indication information indicates that security mechanism C corresponding to identity management is to be used for the service data, the second device performs security processing on the service data at the message layer based on security mechanism C.

[0156] It should be noted that if the application layer supports a security mechanism corresponding to the V2X service, the second device may transfer service data to the application layer at the message layer, so that the second device performs security processing on the service data at the application layer by using the security mechanism corresponding to the V2X service. If the message layer supports a security mechanism corresponding to the V2X service, the second device may perform security processing on the service data at the message layer by using the security mechanism corresponding to the V2X service.

[0157] In another possible implementation, if the indication information indicates that V2X security mechanism A and security mechanism C corresponding to the identity management service are used for the service data, the second device may forward the service data to the security layer at the message layer so that security processing is first performed on the service data at the security layer based on security mechanism A. The second device may then forward the processed service data to the message layer at the security layer, and the second device may again perform security processing at the message layer based on security mechanism C on the service data obtained after processing at the security layer.

[0158] In this way, the first device and the second device implement V2X end-to-end secure communication.

[0159] The following describes the above communication method by using a specific example.

[0160] It is assumed that the first device transmits service data of service D to the second device. In this case, the above communication method may include the following steps:

[0161] Step 1: The first device transfers service data and corresponding indication information of service D to the message layer at the application layer, where the indication information indicates that the security mechanism d provided by service D at the application layer is used for the service data.

[0162] Step 2: The first device transfers the service data and corresponding indication information to the network layer at the message layer.

[0163] Step 3: The first device encapsulates the service data and corresponding indication information into a data frame at the network layer.

[0164] Step 4: The first device sends a data frame to the second device at the network layer.

[0165] Step 5: The second device extracts the service data and corresponding indication information from the data frame at the network layer.

[0166] Step 6: The second device transfers the service data and corresponding indication information to the message layer in the network layer.

[0167] Step 7: The second device transfers the service data and the corresponding indication information to the application layer at the message layer according to the indication of the indication information.

[0168] Step 8: The second device performs security processing on the service data of service D in the application layer by using security mechanism d.

[0169] From the foregoing description, it can be seen that in this embodiment of the present application, the first device indicates to the second device the security mechanism or protocol layer used to perform security processing on the service data, so that the second device can perform security processing on the service data by using the corresponding security mechanism based on the indication of the first indication information. This reduces the risk of information leakage, thereby improving the security of V2X end-to-end communication. Furthermore, the first device indicates to the second device the security mechanism or protocol layer used to perform security processing on the service data, so that the second device can perform security processing on the service data by using the corresponding security mechanism based on the indication of the first indication information. This reduces the cases where the first device and the second device cannot communicate because different security mechanisms are used, thereby improving the reliability of V2X end-to-end communication.

[0170] Based on the same inventive concept, an embodiment of the present application further provides a communication device. The communication device may be a first device in an Internet of Vehicles, a chip or a system-on-chip in the first device, or a functional module in the first device configured to implement the method according to any one of the first aspect and possible implementations of the first aspect. The communication device may implement the functions performed by the first device in the aforementioned aspect or possible implementations. The functions may be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions. FIG. 9 is a schematic diagram of the structure of a communication device according to an embodiment of the present application. See FIG. 9. The communication device 900 includes a processing module 901 configured to obtain service data and perform security processing on the service data, and a transmitting module 902 configured to transmit the service data and indicia information to a second device. The indicia information indicates a security mechanism used to perform the security processing on the service data and indicates a protocol layer used to perform the security processing on the service data.

[0171] In some possible implementations, the sending module is further configured to send identification information to the second device, the identification information identifying a service type of the service data.

[0172] In some possible implementations, the indication information further indicates the content of the security process.

[0173] In some possible implementations, the indication information is an N-bit string. The first K bits of the string indicate the security mechanism used to perform security processing on the service data. The last (NK) bits of the string indicate the content of the security processing. N is a positive integer, and K is a positive integer less than N.

[0174] In some possible implementations, the indication information indicates a first security mechanism to be used for the security processing, or indicates a second security mechanism to be used for the security processing, or indicates the first security mechanism and the second security mechanism to be used for the security processing. Alternatively, the indication information indicates that security processing on the service data is to be performed at the application layer, at the security layer, or at the application layer and the security layer.

[0175] In some possible implementations, the first security mechanism is a V2X-based security mechanism, and the second security mechanism is a security mechanism configured for the service type.

[0176] In some possible implementations, when the security mechanism used for the security processing is the first security mechanism, the content of the security processing includes no encryption and no signature, signature only and no encryption, or signature and encryption.

[0177] In some possible implementations, when the security mechanism used for the security processing is the second security mechanism, the content of the security processing includes a first part and a second part related to the first part. The first part includes supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, or supporting security authentication and requiring encrypted communication. The second part includes asymmetric encryption, symmetric encryption, exclusive-OR two-way authentication, exclusive-OR one-way authentication, or symmetric encryption and one-way authentication.

[0178] In some possible implementations, the transmitting module is particularly configured to transmit a data frame to the second device, the data frame including a frame header and a payload, the indication information being carried in the frame header and the service data being carried in the payload.

[0179] In some possible implementations, the frame header includes an extension field and extension field indication information. When the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

[0180] In some possible implementations, the frame header further includes association indication information. The association indication information indicates whether the indication information is associated with the service data in the payload. When the association indication information is set to a value of true, the association indication information indicates that the indication information is associated with the service data in the payload. When the association indication information is set to a value of false, the association indication information indicates that the indication information is not associated with the service data in the payload.

[0181] In some possible implementations, the processing module 901 is further configured to forward the service data and indication information at the message layer to the network layer and encapsulate the service data and indication information in the data frame at the network layer before the transmitting module 902 transmits the data frame to the second device.

[0182] Please note that for the specific implementation process of the processing module 901 and the processing module 902, please refer to the detailed description of the embodiments of Figures 5 to 8. For the sake of brevity, the details will not be described again here.

[0183] The transmitting module 902 referred to in this embodiment of the present application may be a transmitting interface, a transmitting circuit, a transmitter, etc. The processing module 901 may be one or more processors.

[0184] Based on the same inventive concept, an embodiment of the present application further provides a communication device. The communication device may be a second device in the Internet of Vehicles, or a chip or system-on-chip in the second device, or may be a functional module in the second device configured to implement the method according to any one of the second aspect and possible implementations of the second aspect. The communication device may implement the functions performed by the second device in the aforementioned aspect or possible implementations. The functions may be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions. FIG. 10 is a schematic diagram of the structure of another communication device according to an embodiment of the present application. See FIG. 10. The communication device 1000 includes a receiving module 1001 configured to receive service data and indication information from a first device, and a processing module 1002 configured to perform security processing on the service data based on the indication information. The indication information indicates a security mechanism used to perform the security processing on the service data, or indicates a protocol layer used to perform the security processing on the service data.

[0185] In some possible implementations, the receiving module 1001 is further configured to receive identification information from the first device, the identification information identifying a service type of the service data.

[0186] In some possible implementations, the indication information further indicates the content of the security process.

[0187] In some possible implementations, the indication information is an N-bit string. The first K bits of the string indicate the security mechanism used to perform security processing on the service data. The last (NK) bits of the string indicate the content of the security processing. N is a positive integer, and K is a positive integer less than N.

[0188] In some possible implementations, the indication information indicates a first security mechanism to be used for the security processing, or indicates a second security mechanism to be used for the security processing, or indicates the first security mechanism and the second security mechanism to be used for the security processing. Alternatively, the indication information indicates that security processing on the service data is to be performed at the application layer, at the security layer, or at the application layer and the security layer.

[0189] In some possible implementations, the first security mechanism is a V2X-based security mechanism, and the second security mechanism is a security mechanism configured for the service type.

[0190] In some possible implementations, when the security mechanism used for the security processing is the first security mechanism, the content of the security processing includes no encryption and no signature, signature only and no encryption, or signature and encryption.

[0191] In some possible implementations, when the security mechanism used for the security processing is the second security mechanism, the content of the security processing includes a first part and a second part related to the first part. The first part includes supporting security authentication, not supporting security authentication, supporting security authentication but not requiring secure communication, or supporting security authentication and requiring secure communication. The second part includes asymmetric encryption, symmetric encryption, exclusive-OR two-way authentication, exclusive-OR one-way authentication, or symmetric encryption and one-way authentication.

[0192] In some possible implementations, the receiving module 1001 is particularly configured to receive a data frame from a first device. The data frame includes a frame header and a payload. Indication information is carried in the frame header, and service data is carried in the payload.

[0193] In some possible implementations, the frame header includes an extension field and extension field indication information. When the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

[0194] In some possible implementations, the frame header further includes association indication information. The association indication information indicates whether the indication information is associated with the service data in the payload. When the association indication information is set to a value of true, the association indication information indicates that the indication information is associated with the service data in the payload. When the association indication information is set to a value of false, the association indication information indicates that the indication information is not associated with the service data in the payload.

[0195] In some possible implementations, the processing module 1002 is further configured to: after the receiving module receives the data frame from the first device, obtain the service data and the indication information in the data frame at the network layer, forward the service data and the indication information at the network layer to the message layer, and perform security processing on the service data at the message layer based on the indication information.

[0196] In some possible implementation forms, the processing module 1002 is particularly configured to transfer service data to a security layer at a message layer and perform security processing on the service data at the security layer when the protocol layer indicated by the indication information is a security layer, or to perform security processing on the service data at the application layer or message layer when the protocol layer indicated by the indication information is an application layer or a message layer.

[0197] In some possible implementation forms, the processing module 1002 is particularly configured to, when the protocol layer indicated by the indication information is a security layer and an application layer, transfer service data at the message layer to the security layer, perform security processing on the service data at the security layer, transfer the processed service data at the security layer to the message layer, and perform security processing on the processed service data at the message layer.

[0198] Please note that for the specific implementation process of the receiving module 1001 and the processing module 1002, please refer to the detailed description of the embodiments of Figures 5 to 8. For the sake of brevity, the details will not be described again here.

[0199] The receiving module 1001 referred to in this embodiment of the present application may be a receiving interface, a receiving circuit, a receiver, etc. The processing module 1002 may be one or more processors.

[0200] Based on the same inventive concept, an embodiment of the present application provides a communication device. The communication device may be the first device or the second device in one or more embodiments described above. Figure 11 is a schematic diagram of the structure of a communication device according to an embodiment of the present application. Please refer to Figure 11. The communication device 1100 uses general-purpose computer software, including a processor 1101, a memory 1102, a bus 1103, an input device 1104, and an output device 1105.

[0201] In some possible implementations, the memory 1102 may include computer storage media in the form of volatile and / or non-volatile memory, e.g., read-only and / or random-access memory. The memory 1102 may store an operating system, application programs, other program modules, executable code, program data, user data, etc.

[0202] The input device(s) 1104 may be configured to input commands and information into the communication device. The input device(s) 1104 may be a keyboard or pointing device, such as a mouse, trackball, touchpad, microphone, joystick, gamepad, satellite television dish, scanner, or similar device. These input devices may be connected to the processor 1101 through the bus 1103.

[0203] The output device 1105 may be used by the communication device to output information. In addition to a monitor, the output device 1105 may alternatively be another peripheral output device, such as a speaker and / or a printing device. These output devices may also be connected to the processor 1101 through the bus 1103.

[0204] The communication device may be connected to a network, for example, a local area network (LAN), through a network interface 1106. In a networked environment, the computer-executable instructions stored in memory may be stored in a remote storage device and are not limited to being stored locally.

[0205] When the processor 1101 in the communication device executes the executable code or application program stored in the memory 1102, the communication device executes the communication method on the first device side or on the first device side in the above-mentioned embodiment. For the specific execution process, please refer to the above-mentioned embodiment. The details will not be described again here.

[0206] In addition, the memory 1102 stores computer-executable instructions used to implement the functions of the processing module 901 and the transmitting module 902 of Figure 9. The functions / implementation processes of both the processing module 901 and the transmitting module 902 of Figure 9 can be implemented by the processor 1101 of Figure 11 by invoking the computer-executable instructions stored in the memory 1102. For specific implementation processes and functions, please refer to the related embodiments described above.

[0207] Alternatively, the memory 1102 stores computer-executable instructions used to implement the functions of the receiving module 1001 and the processing module 1002 of Figure 10. The functions / implementation processes of both the receiving module 1001 and the processing module 1002 of Figure 10 can be implemented by the processor 1101 of Figure 11 by invoking the computer-executable instructions stored in the memory 1102. For specific implementation processes and functions, please refer to the related embodiments described above.

[0208] Based on the same inventive concept, an embodiment of the present application further provides a computer-readable storage medium, which stores instructions, when executed on a computer, for performing a communication method on a first device side or a second device side in one or more of the above-mentioned embodiments.

[0209] Based on the same inventive concept, an embodiment of the present application further provides a computer program or a computer program product, which, when run on a computer, enables the computer to perform the communication method on the first device side or the second device side in one or more embodiments described above.

[0210] Those skilled in the art will recognize that the functions described with reference to the various illustrative logical blocks, modules, and algorithm steps disclosed and described herein may be implemented by hardware, software, firmware, or any combination thereof. If the functions are implemented by software, the functions described with reference to the illustrative logical blocks, modules, and steps may be stored on or transmitted via a computer-readable medium as one or more instructions or code and executed by a hardware-based processing unit. Computer-readable media may include computer-readable storage media, which correspond to tangible media, e.g., data storage media, or communication media, including any medium that facilitates transfer of a computer program from one place to another (e.g., according to a communication protocol). In this manner, computer-readable media may generally correspond to (1) non-transitory tangible computer-readable storage media or (2) communication media, e.g., signals or carriers. Data storage media may be any available medium that can be accessed by one or more computers or one or more processors to retrieve instructions, code, and / or data structures for implementing the techniques described in this application. A computer program product may include computer-readable media.

[0211] By way of example, and not limitation, such computer-readable storage media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage, flash memory, or any other medium capable of storing associated program code in the form of instructions or data structures and which can be accessed by a computer. Additionally, any connection is properly termed a computer-readable medium. For example, if instructions are transmitted from a website, server, or another remote source via coaxial cable, fiber optic, twisted pair, digital subscriber line (DSL), or wireless technology such as infrared, radio, or microwave, the coaxial cable, fiber optic, twisted pair, DSL, or wireless technology such as infrared, radio, or microwave are included within the definition of medium. However, it should be understood that computer-readable storage media and data storage media do not include connections, carriers, signals, or other transitory media, and in fact refer to non-transitory tangible storage media. As used herein, disk and disc include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), and Blu-ray discs. While disks typically reproduce data magnetically, discs also reproduce data optically by using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0212] The instructions may be executed by one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other equivalent integrated circuits or discrete logic circuits. Thus, the term "processor" as used herein may refer to the foregoing structure or any other structure that may be applied to the implementation of the techniques described herein. Additionally, in some aspects, the functionality described with reference to the exemplary logic blocks, modules, and steps described herein may be provided within dedicated hardware and / or software modules configured for encoding and decoding, or may be incorporated into a composite codec. Additionally, the techniques may be implemented in one or more circuits or logic elements.

[0213] The techniques of the present application may be implemented in a variety of apparatuses or devices, including a wireless handset, an integrated circuit (IC), or a set of ICs (e.g., a chipset). Although various components, modules, or units are described herein to coordinate functional aspects of an apparatus configured to perform the disclosed techniques, they are not necessarily implemented using different hardware units. In practice, as described above, the various units may be combined into a codec hardware unit in combination with appropriate software and / or firmware, or may be provided by interoperable hardware units (including one or more processors as described above).

[0214] In the above-described embodiments, the description of each embodiment has its own focus, and for the parts not described in detail in one embodiment, please refer to the related descriptions in other embodiments.

[0215] The foregoing description is merely an example of a specific implementation of the present application and is not intended to limit the scope of protection of the present application. Any variations or replacements that are easily understood by those skilled in the art within the technical scope disclosed in the present application shall fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the scope of protection of the claims. [Explanation of symbols]

[0216] 11a Vehicle 11b Vehicle 12 Infrastructure 21 Base station 31 Application Layer 32 Security Layers 33 Message Layer 34 Network Layer 35 Access Layer 41 On-board unit (OBU) 42 Roadside unit (RSU) 43 Onboard unit (OBU) 61a Security Mechanism 61b Protocol Layer 62 Contents of security processing 71 Frame Header 72 Payload 221 On-board unit (OBU) 222 Roadside Unit (RSU) 300 Protocol Stack 411 Positioning System 412 Processing Unit 413 Wireless Communication Subsystem 421 Positioning System 422 Processing Unit 423 Wireless Communication Subsystem 431 Positioning System 432 Processing Unit 433 Wireless Communication Subsystem 711 Extended Field 712 Extended Field Indication Information 713 Application Identifier Field 714 Association marking information 900 Communication Equipment 901 Processing Module 902 Transmitting Module 1000 Communication Equipment 1001 Receiver Module 1002 Processing Module 1100 Communication Devices 1101 processor 1102 memory 1103 Bus 1104 Input Devices 1105 Output Device 1106 Network Interface

Claims

1. obtaining, by a first device, first service data; performing security processing on the first service data to obtain second service data; transmitting, by the first device, the second service data and the indication information to a second device; The labeling information is a V2X-based first security mechanism used to perform the security processing on the first service data, the first security mechanism being applied for a broadcast service and a unicast service; and a V2X-based second security mechanism used to perform the security processing on the first service data, the second security mechanism being at least one of a unicast service or a specific service in the unicast service;

2. The method of claim 1 , further comprising the step of transmitting, by the first device, identification information to the second device, the identification information identifying a service type of the second service data.

3. The method of claim 1 , further comprising the step of transmitting, by the first device, identification information to the second device, the identification information being an application identifier.

4. The method according to claim 1 , wherein the indicator information further indicates the content of the security process.

5. 5. The method of claim 4, wherein the indication information is an N-bit string, the first K bits of the string indicate a security mechanism used for the security operation, and the last (NK) bits of the string indicate the content of the security operation, where N is a positive integer and K is a positive integer less than N.

6. 2. The method of claim 1, wherein the security mechanism used for the security processing is the first security mechanism, and the content of the security processing comprises no encryption and no signature, only signature and no encryption, or signature and encryption.

7. when the security mechanism used for the security processing is the second security mechanism, the content of the security processing comprises a first part and a second part related to the first part; 10. The method of claim 1, wherein the first portion comprises supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, or supporting security authentication and requiring encrypted communication, and the second portion comprises asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication.

8. the step of transmitting, by the first device, the second service data and the indication information to a second device, 2. The method of claim 1, comprising: transmitting, by the first device, a data frame to the second device, the data frame comprising a frame header and a payload, the indication information being carried in the frame header and the second service data being carried in the payload.

9. 9. The method of claim 8, wherein the frame header comprises an extension field and extension field indication information, the indication information being carried in the extension field, and the extension field indication information indicating that the data frame carries the indication information.

10. The method of claim 8 or 9, wherein the frame header further comprises association indication information, and the association indication information indicates whether the indication information is associated with the second service data in the payload.

11. receiving, by the second device, service data and indicia information from the first device; and performing, by the second device, a security process on the service data based on the indication information; The labeling information is a V2X-based first security mechanism used to perform the security processing on the service data, the first security mechanism being applied for broadcast services and unicast services; and A communication method, wherein the communication method indicates at least one of a V2X-based second security mechanism used to perform the security processing on the service data, the second security mechanism being applied for a unicast service or a specific service in the unicast service.

12. The method of claim 11 , further comprising receiving, by the second device, identification information from the first device, the identification information identifying a service type of the service data.

13. The method of claim 11 , further comprising receiving, by the second device, identification information from the first device, the identification information being an application identifier.

14. The method according to claim 11 , wherein the indicia further indicates the content of the security process.

15. 12. The method of claim 11, wherein when the security mechanism used for the security processing is the first security mechanism, the content of the security processing comprises no encryption and no signature, only signature and no encryption, or signature and encryption.

16. a security mechanism used for the security processing is the second security mechanism, and the content of the security processing comprises a first part and a second part related to the first part; 12. The method of claim 11, wherein the first portion comprises supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, or supporting security authentication and requiring encrypted communication, and the second portion comprises asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication.

17. said step of receiving, by the second device, service data and indication information from the first device, 12. The method of claim 11, comprising receiving, by the second device, a data frame from the first device, the data frame comprising a frame header and a payload, the indication information being carried in the frame header and the service data being carried in the payload.

18. 18. The method of claim 17, wherein the frame header comprises an extension field and extension field indication information, and when the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

19. 19. The method of claim 17 or 18, wherein the frame header further comprises association indication information, the association indication information indicating whether the indication information is associated with the service data in the payload.

20. a processing module configured to obtain first service data and perform security processing on the first service data to obtain second service data; a transmission module configured to transmit the second service data and the indication information to a second device; The labeling information is a V2X-based first security mechanism used to perform the security processing on the first service data, the first security mechanism being applied for a broadcast service and a unicast service; and A communication device indicating at least one of a V2X-based second security mechanism used to perform the security processing on the first service data, the second security mechanism being applied for a unicast service or a specific service in the unicast service.

21. 21. The apparatus of claim 20, wherein the sending module is further configured to send identification information to the second device, the identification information identifying a service type of the second service data.

22. 21. The apparatus of claim 20, wherein the transmission module is further configured to transmit identification information to the second device, the identification information being an application identifier.

23. 23. The device according to claim 20, wherein the indication information further indicates the content of the security process.

24. 21. The apparatus of claim 20, wherein when the security mechanism used for the security processing is the first security mechanism, the content of the security processing comprises no encryption and no signature, signature only and no encryption, or signature and encryption.

25. when the security mechanism used for the security processing is the second security mechanism, the content of the security processing comprises a first part and a second part related to the first part; 21. The apparatus of claim 20, wherein the first portion comprises supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, or supporting security authentication and requiring encrypted communication, and the second portion comprises asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication.

26. 21. The apparatus of claim 20, wherein the transmitting module is specifically configured to transmit a data frame to the second device, the data frame comprising a frame header and a payload, the indication information being carried in the frame header and the second service data being carried in the payload.

27. 27. The apparatus of claim 26, wherein the frame header comprises an extension field and extension field indication information, the indication information being carried in the extension field, and the extension field indication information indicating that the data frame carries the indication information.

28. 28. The apparatus of claim 26 or 27, wherein the frame header further comprises association indication information, the association indication information indicating whether the indication information is associated with the second service data in the payload.

29. a receiving module configured to receive service data and indicia information from the first device; a processing module configured to perform security processing on the service data based on the label information; The labeling information is a V2X-based first security mechanism used to perform the security processing on the service data, the first security mechanism being applied for broadcast services and unicast services; and A communication device indicating at least one of a V2X-based second security mechanism used to perform the security processing on the service data, the second security mechanism being applied for a unicast service or a specific service in the unicast service.

30. 30. The apparatus of claim 29, wherein the receiving module is further configured to receive identification information from the first device, the identification information identifying a service type of the service data.

31. 30. The apparatus of claim 29, wherein the receiving module is further configured to receive identification information from the first device, the identification information being an application identifier.

32. 32. The device according to claim 29, wherein the indicator information further indicates the content of the security process.

33. 30. The apparatus of claim 29, wherein when the security mechanism used for the security processing is the first security mechanism, the content of the security processing comprises no encryption and no signature, signature only and no encryption, or signature and encryption.

34. when the security mechanism used for the security processing is the second security mechanism, the content of the security processing comprises a first part and a second part related to the first part; 30. The apparatus of claim 29, wherein the first portion comprises supporting security authentication, not supporting security authentication, supporting security authentication but not requiring encrypted communication, or supporting security authentication and requiring encrypted communication, and the second portion comprises asymmetric encryption, symmetric encryption, exclusive-or two-way authentication, exclusive-or one-way authentication, or symmetric encryption and one-way authentication.

35. 35. The apparatus of claim 34, wherein the receiving module is specifically configured to receive a data frame from the first device, the data frame comprising a frame header and a payload, the indication information being carried in the frame header and the service data being carried in the payload.

36. 36. The apparatus of claim 35, wherein the frame header comprises an extension field and extension field indication information, and when the indication information is carried in the extension field, the extension field indication information indicates that the data frame carries the indication information.

37. 37. The apparatus of claim 35 or 36, wherein the frame header further comprises association indication information, the association indication information indicating whether the indication information is associated with the service data in the payload.

38. 11. A communications device comprising a processor and a memory, the processor coupled to the memory, the processor configured to read and execute instructions in the memory to implement the communications method of any one of claims 1 to 10.

39. 20. A communications device comprising a processor and a memory, the processor coupled to the memory, the processor configured to read and execute instructions in the memory to implement the communications method of any one of claims 11 to 19.

40. 11. A computer-readable storage medium having instructions stored thereon, the instructions being executable on a computer to perform the communication method of any one of claims 1 to 10.

41. 20. A computer-readable storage medium having instructions stored thereon, the instructions being executable on a computer to perform the communication method of any one of claims 11 to 19.

42. A computer program comprising computer instructions, which when executed by a processor cause the method of any one of claims 1 to 10 to be performed.

43. A computer program comprising computer instructions which, when executed by a processor, cause the method of any one of claims 11 to 19 to be performed.

Citation Information

Patent Citations

  • Security strategy execution method and apparatus

    WO2017210811A1