Vehicle control method and apparatus, terminal, and telematics device
The terminal negotiates with the vehicle's telematics equipment to determine the session key and encrypts the remote vehicle control instructions, solving the problem of insufficient security of vehicle remote control in the prior art, achieving higher security and reliability.
Patent Information
- Application Number
- PCT/CN2024/132472
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-11-15
- Publication Date
- 2025-06-26
AI Technical Summary
The existing remote control method of vehicles has security problems, and attackers can tamper with remote vehicle control instructions by attacking the cloud.
The terminal negotiates with the vehicle's telematics equipment to determine the session key, and use the key to encrypt the remote vehicle control instructions. Different links are used during transmission to ensure that the attacker cannot obtain the key and tamper with the instructions.
It effectively improves the security of remote control of the vehicle, prevents attackers from tampering with vehicle control instructions, and ensures the safety and reliability of vehicle operations.
Smart Images

Figure CN2024132472_26062025_PF_FP_ABST
Abstract
Description
Vehicle control method and device, terminal and telematics processing equipment
[0001] This application claims priority to Chinese patent application No. 202311749851.1, filed on December 18, 2023, entitled “Vehicle Control Method and Device, Terminal and Telematics Processing Equipment,” the entire contents of which are incorporated herein by reference. Technical Field
[0002] The present application relates to the field of vehicle technology, and in particular to a vehicle control method and device, a terminal, and a telematics processing device. Background Art
[0003] As vehicles become more intelligent, drivers can control the vehicle remotely through terminals (such as mobile phones) in addition to operating the vehicle inside the vehicle.
[0004] In the related art, a vehicle control method implemented remotely through a terminal is provided, which includes: the terminal obtains a key provided by the cloud; the terminal sends an encrypted remote vehicle control instruction to the vehicle's telematics device (such as a telematics box (T-BOX)) through the cloud; after receiving the remote vehicle control instruction, the telematics device controls the vehicle according to the remote vehicle control instruction.
[0005] In the above scheme, attackers can tamper with remote vehicle control instructions by attacking the cloud, making the above vehicle control method less secure. Summary of the Invention
[0006] The present application provides a vehicle control method and apparatus, a terminal, and a telematics processing device, which can ensure the security of vehicle remote control.
[0007] In a first aspect, the present application provides a vehicle control method, which is executed by a terminal. The method includes:
[0008] The terminal negotiates with the vehicle's telematics device to determine a session key through a first link; the terminal encrypts a remote vehicle control command using the session key; and the terminal sends the encrypted remote vehicle control command to the telematics device through a second link, which is different from the first link.
[0009] In this implementation, the terminal uses the first link when negotiating the session key with the remote information processing device, and then transmits the encrypted remote vehicle control command through the second link. That is to say, the key of this application is obtained through negotiation, and even if the cloud is attacked, the key cannot be obtained. Moreover, the link used to negotiate the key is different from the transmission link. Even if the cloud is attacked while the command is transmitted through the cloud, the attacker cannot tamper with the vehicle control command, thereby ensuring the security of the vehicle control method.
[0010] Exemplarily, the terminal may be a mobile terminal, such as a mobile phone, a tablet computer, a smart watch or other smart wearable device.
[0011] Exemplarily, the telematics device may be a T-BOX.
[0012] Exemplarily, the first link includes a link between the terminal and a vehicle-mounted device of the vehicle, and a link between the vehicle-mounted device and a telematics device; or, the first link includes a link between the terminal and the telematics device.
[0013] Exemplarily, the vehicle-mounted device may be a smart cockpit device (such as a smart cockpit domain controller), or other smart interactive devices in the vehicle that can provide human-computer interaction and are connected to the telematics device.
[0014] Exemplarily, the second link includes a link between the terminal and the cloud, and a link between the cloud and the telematics device; or, the second link includes a link between the terminal and the telematics device.
[0015] In some cases, the telematics device and the terminal cannot communicate directly. Therefore, key negotiation requires the assistance of a third party, such as a vehicle-mounted device, that the telematics device trusts and can communicate with both the terminal and the telematics device. This approach ensures the security of key negotiation.
[0016] This application takes the example of a first link including a link between a terminal and a vehicle's on-board device, and a link between the on-board device and a telematics device, and a second link including a link between a terminal and a cloud, and a link between the cloud and a telematics device, to exemplify the vehicle control method:
[0017] In this case, the terminal can first establish a binding relationship with the telematics device and then negotiate a key. Once the binding relationship is established, the terminal negotiates a session key with the telematics device. This binding-first-then-negotiated session key ensures security. Subsequent transmission of remote vehicle control commands via the cloud is encrypted using the negotiated session key. This ensures the security of the vehicle control method even if the cloud is attacked, the attacker cannot tamper with the vehicle control commands.
[0018] The following uses the vehicle-mounted device as an example to illustrate the binding process between the terminal and the telematics device:
[0019] The terminal determines the symmetric key between itself and the vehicle's on-board device; the terminal encrypts the binding request using the symmetric key; the terminal sends the encrypted binding request to the on-board device, so that the on-board device decrypts the encrypted binding request and sends it to the telematics device; the terminal receives the binding response encrypted and forwarded by the on-board device, and the binding response is fed back to the on-board device by the telematics device; the terminal decrypts the encrypted binding response using the symmetric key to complete the binding.
[0020] In this implementation, the vehicle-mounted device and the telematics device are connected via the vehicle's internal network, such as the in-vehicle Ethernet or bus, ensuring the security of the line between them. However, the vehicle-mounted device and the terminal are connected via a network outside the vehicle, making security unreliable. Therefore, in this implementation, information transmitted between the terminal and the telematics device is encrypted using a symmetric key to enhance security. This network and information transmission method ensure the security of the binding process between the terminal and the telematics device.
[0021] During the above binding process, the vehicle-mounted device is responsible for encrypting, decrypting and forwarding the information transmitted between the terminal and the telematics device. The information from the terminal to the telematics device is first decrypted and then forwarded, while the information from the telematics device to the terminal is first encrypted and then forwarded.
[0022] In one possible implementation of the present application, the terminal determines a symmetric key between the terminal and the vehicle's onboard equipment, including:
[0023] The terminal obtains the same secret factor as the vehicle device; the terminal determines the symmetric key based on the secret factor.
[0024] In this implementation, by obtaining the same secret factor as the vehicle equipment, the terminal determines the symmetric key based on the secret factor, thereby providing a basis for the encryption of subsequent information transmission.
[0025] In one example, the secret factor includes at least one of an encryption password, a random salt value and an iteration number, and a vehicle unique identification code.
[0026] For example, secret factors include the encryption password, the random salt value and the iteration number, and the vehicle unique identification code.
[0027] In other examples, the secret factor may also be composed of other parameters, which is not limited in this application.
[0028] The terminal and the vehicle device can be connected based on a Bluetooth or wireless high-fidelity (WIFI) network. After the terminal and the vehicle device are connected, the vehicle device sends the above-mentioned secret factor to the terminal.
[0029] In one example, the encryption password in the secret factor may be an encryption password used when the terminal and the vehicle device realize Bluetooth connection or WIFI connection.
[0030] In another example, the encryption password in the secret factor can be a separately set encryption password, which is input through the vehicle-mounted large screen or the terminal after the connection between the terminal and the vehicle device is completed.
[0031] After the terminal receives the secret factor, the terminal calculates the symmetric key in the same way as the vehicle equipment. This method can be a mature key algorithm in the relevant technology, or a key algorithm designed based on the encryption needs of this application. This application does not impose any restrictions on this.
[0032] The above-mentioned key algorithm can be stored in the terminal and the vehicle-mounted device in advance, or can be negotiated and determined after the terminal and the vehicle-mounted device are connected. This application does not impose any restrictions on this.
[0033] Accordingly, in addition to determining the symmetric key based on the secret factor, the terminal also determines the symmetric key based on the secret factor. Because the determination method is the same, the keys determined by both are the same. This method avoids direct key transmission, thus reducing the risk of exposure, while ensuring key consistency.
[0034] In other possible implementations of the present application, the content of the secret factor transmitted between the terminal and the vehicle-mounted device may include more or fewer parameters, or the secret factor may be transmitted from the terminal to the vehicle-mounted device, etc. The present application does not impose too many restrictions on these implementation details.
[0035] In one possible implementation of the present application, the terminal uses a session key to encrypt a remote vehicle control command, including:
[0036] The terminal encrypts the remote vehicle control instruction and the first count value using the session key so that the telematics device verifies the legitimacy of the remote vehicle control instruction based on the first count value, where the first count value is the count value of the remote vehicle control instruction.
[0037] In this implementation, a first count value is encrypted along with the remote vehicle control command. The encrypted remote vehicle control command and the first count value are then transmitted together. Upon receiving the remote vehicle control command, the telematics device performs a validity check based on the first count value. The first count value increases with the number of commands sent from the terminal to the telematics device. Therefore, by verifying the first count value, it is possible to determine whether the command is legitimate or has been replayed, thereby enhancing security.
[0038] In one example, the remote vehicle control command and the first count value are encrypted as a whole; in another example, the remote vehicle control command and the first count value are encrypted separately. That is, the remote vehicle control command and the first count value can be a single message or data packet, or they can be separated into separate messages or data packets. However, the separation must ensure that the two can be linked or corresponded to each other.
[0039] In another possible implementation of the present application, the terminal does not carry the first count value when encrypting the remote vehicle control instruction, which can reduce the message size of the transmission instruction and reduce the bandwidth requirement.
[0040] In addition to transmitting remote vehicle control commands, vehicle status information can also be transmitted between the terminal and the telematics processing device.
[0041] In a possible implementation of the present application, the method further includes:
[0042] The terminal receives the encrypted vehicle status information and the second count value sent by the remote information processing device through the second link, where the second count value is the count value of the vehicle status information; the terminal uses the session key to decrypt the encrypted vehicle status information and the second count value to obtain the vehicle status information and the second count value; and the terminal verifies the legitimacy of the vehicle status information based on the second count value.
[0043] In this implementation, the second count value is encrypted along with the vehicle status information, and then transmitted together with the encrypted vehicle status information. This allows the terminal to perform a validity check based on the second count value upon receiving the vehicle status information. The second count value increases with the amount of vehicle status information sent to the terminal by the telematics device. Therefore, by verifying the second count value, it is possible to determine whether the information is legitimate or has been replayed, thereby enhancing security.
[0044] In one example, the vehicle status information and the second count value are encrypted as a whole; in another example, the vehicle status information and the second count value are encrypted separately. That is, the vehicle status information and the second count value can be sent as a single message or data packet, or they can be separated into separate messages or data packets. However, the separation must ensure that the two can be linked or corresponded to each other.
[0045] In another possible implementation of the present application, the telematics processing device does not carry the second count value when encrypting the vehicle status information, which can reduce the message size of the transmitted information and lower the bandwidth requirement.
[0046] In one possible implementation of the present application, after the terminal and the telematics processing device determine the session key through negotiation, they always use the same session key to encrypt information. In this way, the terminal and the telematics processing device have less processing power to determine the key to be used.
[0047] In another possible implementation of the present application, after the terminal and the telematics processing device determine the session key through negotiation, they will periodically update the used session key, thereby further increasing security.
[0048] In one example, the terminal updates the session key in the following manner: the terminal and the telematics device periodically update the session key through negotiation. That is, the terminal and the telematics device periodically negotiate and then use the latest negotiated session key.
[0049] In another example, the terminal updates the session key in the following manner: the terminal and the telematics device negotiate to obtain multiple session keys; based on the multiple session keys, the terminal periodically updates the session key in use. Specifically, the terminal and the telematics device negotiate to obtain multiple session keys, then select a session key to use from these multiple session keys, and periodically replace the session key in use. Of course, in this example, the terminal and the telematics device can still negotiate periodically, but unlike the first example, multiple session keys are obtained during each negotiation, and the session key is replaced between negotiation cycles.
[0050] The above description is about the vehicle control method executed by the terminal, which corresponds to the vehicle control method of the telematics device. Since the vehicle control methods on both sides correspond to each other, the steps of the methods executed by each side are also corresponding to each other, see the second aspect below:
[0051] In a second aspect, the present application provides a vehicle control method, wherein the vehicle includes a telematics processing device, and the method is executed by the telematics processing device of the vehicle. The method includes:
[0052] The telematics device negotiates with the terminal through a first link to determine a session key; the telematics device receives an encrypted remote vehicle control instruction sent by the terminal through a second link, which is different from the first link; the telematics device uses the session key to decrypt the encrypted remote vehicle control instruction to obtain the remote vehicle control instruction; the telematics device controls the vehicle according to the remote vehicle control instruction.
[0053] Optionally, the first link includes a link between the terminal and a vehicle-mounted device of the vehicle, and a link between the vehicle-mounted device and a telematics device;
[0054] Alternatively, the first link includes a link between the terminal and the telematics device.
[0055] Optionally, when the first link includes a link between the terminal and the vehicle-mounted device, and a link between the vehicle-mounted device and the telematics device, the method further includes:
[0056] The telematics processing device receives a binding request sent by the terminal through the vehicle's onboard device; the telematics processing device sends a binding response to the onboard device, so that the onboard device encrypts and forwards it to the terminal, completing the binding.
[0057] Optionally, the telematics device receives an encrypted remote vehicle control command sent by the terminal via the second link, including:
[0058] The telematics processing device receives the encrypted remote vehicle control command and the first count value sent by the terminal through the second link, where the first count value is the count value of the remote vehicle control command;
[0059] The method further includes:
[0060] The terminal verifies the legitimacy of the remote vehicle control command based on the first count value.
[0061] Optionally, the method further includes:
[0062] The telematics device encrypts the vehicle status information and the second count value using a session key, so that the terminal verifies the legitimacy of the vehicle status information based on the second count value, where the second count value is the count value of the vehicle status information; the terminal sends the encrypted vehicle status information and the second count value to the terminal via the second link.
[0063] Optionally, the second link includes a link between the terminal and the cloud, and a link between the cloud and the telematics device;
[0064] Alternatively, the second link includes a link between the terminal and the telematics device.
[0065] Optionally, the method further includes:
[0066] The telematics device and the terminal periodically update the session key through negotiation;
[0067] or,
[0068] The telematics processing device negotiates with the terminal to obtain multiple session keys. The method also includes: the telematics processing device periodically updates the used session keys based on the multiple session keys.
[0069] In a third aspect, the present application provides a vehicle control device, the device comprising:
[0070] a key negotiation unit, configured to negotiate and determine a session key with a telematics device of the vehicle via a first link;
[0071] an encryption and decryption unit, for encrypting remote vehicle control commands using a session key;
[0072] The transmission unit is used to send the encrypted remote vehicle control command to the telematics device through a second link, where the second link is different from the first link.
[0073] Optionally, the first link includes a link between the apparatus and a vehicle-mounted device of the vehicle, and a link between the vehicle-mounted device and a telematics device;
[0074] Alternatively, the first link comprises a link between the apparatus and a telematics device.
[0075] Optionally, in the case where the first link includes a link between the apparatus and the vehicle-mounted device, and a link between the vehicle-mounted device and the telematics device, the apparatus further comprises: a binding unit for determining a symmetric key with the vehicle-mounted device of the vehicle;
[0076] The encryption and decryption unit is further used to encrypt the binding request using a symmetric key;
[0077] The transmission unit is further configured to send an encrypted binding request to the vehicle-mounted device, so that the vehicle-mounted device decrypts the encrypted binding request and sends it to the telematics processing device; receive a binding response encrypted and forwarded by the vehicle-mounted device, and the binding response is fed back to the vehicle-mounted device by the telematics processing device;
[0078] The binding unit is further configured to decrypt the encrypted binding response using a symmetric key to complete the binding.
[0079] Optionally, the transmission unit is further used to obtain the same secret factor as the vehicle-mounted device;
[0080] A binding unit is used to determine a symmetric key based on a secret factor.
[0081] Optionally, the encryption and decryption unit is used to encrypt the remote vehicle control instruction and the first count value using a session key, so that the remote information processing device verifies the legitimacy of the remote vehicle control instruction based on the first count value, and the first count value is the count value of the remote vehicle control instruction.
[0082] Optionally, the transmission unit is further configured to receive the encrypted vehicle status information and a second count value sent by the telematics device through a second link, the second count value being a count value of the vehicle status information;
[0083] The encryption and decryption unit is further used to decrypt the encrypted vehicle status information and the second count value using the session key to obtain the vehicle status information and the second count value; and verify the legitimacy of the vehicle status information based on the second count value.
[0084] Optionally, the second link includes a link between the apparatus and the cloud, and a link between the cloud and the telematics device;
[0085] Alternatively, the second link comprises a link between the apparatus and a telematics device.
[0086] Optionally, the key negotiation unit is further configured to periodically update the session key through negotiation with the telematics device;
[0087] or,
[0088] A plurality of session keys are obtained through negotiation with the telematics processing device, and the key negotiation unit is further used to periodically update the used session keys based on the plurality of session keys.
[0089] In a fourth aspect, the present application provides a vehicle control device, the device comprising:
[0090] A key negotiation unit, configured to negotiate with the terminal to determine a session key via the first link;
[0091] a transmission unit, configured to receive an encrypted remote vehicle control command sent by the terminal via a second link, the second link being different from the first link;
[0092] an encryption and decryption unit, configured to decrypt the encrypted remote vehicle control instruction using a session key to obtain the remote vehicle control instruction;
[0093] A control unit is used to control the vehicle according to remote vehicle control instructions.
[0094] Optionally, the first link includes a link between the terminal and a vehicle-mounted device of the vehicle, and a link between the vehicle-mounted device and the apparatus;
[0095] Alternatively, the first link includes a link between the terminal and the device.
[0096] Optionally, when the first link includes a link between the terminal and the vehicle-mounted device, and a link between the vehicle-mounted device and the apparatus, the transmission unit is also used to receive a binding request sent by the terminal through the vehicle-mounted device of the vehicle; and send a binding response to the vehicle-mounted device so that the vehicle-mounted device encrypts and forwards it to the terminal to complete the binding.
[0097] Optionally, the transmission unit is configured to receive an encrypted remote vehicle control instruction and a first count value sent by the terminal via the second link, wherein the first count value is a count value of the remote vehicle control instruction;
[0098] The encryption and decryption unit is used to verify the legitimacy of the remote vehicle control instruction based on the first count value.
[0099] Optionally, the encryption and decryption unit is also used to encrypt the vehicle status information and the second count value using a session key, so that the terminal verifies the legitimacy of the vehicle status information based on the second count value, and the second count value is the count value of the vehicle status information; the transmission unit is also used to send the encrypted vehicle status information and the second count value to the terminal through the second link.
[0100] Optionally, the second link includes a link between the terminal and the cloud, and a link between the cloud and the device;
[0101] Alternatively, the second link includes a link between the terminal and the device.
[0102] Optionally, the key negotiation unit is further configured to periodically update the session key through negotiation with the terminal;
[0103] or,
[0104] A plurality of session keys are obtained through negotiation with the terminal, and the key negotiation unit is further configured to periodically update the used session key based on the plurality of session keys.
[0105] In a fifth aspect, an electronic device is provided. The electronic device includes a processor and a memory. The memory is used to store software programs and modules.
[0106] In one example, the electronic device may be a terminal, and accordingly, the processor implements the method of the above-mentioned first aspect or any possible implementation of the first aspect by running or executing the software program and / or module stored in the memory.
[0107] In another example, the electronic device may be a vehicle-mounted device, and accordingly, the processor implements the method of the above-mentioned second aspect or any possible implementation of the second aspect by running or executing the software program and / or module stored in the memory.
[0108] Optionally, there are one or more processors and one or more memories.
[0109] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0110] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or be set on different chips. This application does not limit the type of memory and the setting method of the memory and the processor.
[0111] In a sixth aspect, a computer program product is provided. The computer program product includes computer program code, which, when executed by a computer, causes the computer to perform the method of the first aspect or any possible implementation of the first aspect, or the method of the second aspect or any possible implementation of the second aspect.
[0112] In the seventh aspect, the present application provides a computer-readable storage medium, which is used to store program codes executed by a processor, wherein the program codes include methods for implementing the above-mentioned first aspect or any possible implementation of the first aspect, or implementing the above-mentioned second aspect or any possible implementation of the second aspect.
[0113] In an eighth aspect, a chip is provided, comprising a processor, the processor being used to call and execute instructions stored in a memory from the memory, so that a communication device equipped with the chip executes the method in the above-mentioned first aspect or any possible implementation of the first aspect, or executes the above-mentioned second aspect or any possible implementation of the second aspect.
[0114] In a ninth aspect, another chip is provided. The another chip includes an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected via an internal connection path. The processor is configured to execute code in the memory. When the code is executed, the processor is configured to execute the method according to the first aspect or any possible implementation of the first aspect, or to execute the method according to the second aspect or any possible implementation of the second aspect.
[0115] In a tenth aspect, a vehicle is provided, comprising a vehicle control device as described in the fourth aspect or any possible implementation of the fourth aspect.
[0116] In an eleventh aspect, a vehicle control system is provided, which includes a terminal as described in any of the preceding items and a vehicle-mounted device as described in any of the preceding items. BRIEF DESCRIPTION OF THE DRAWINGS
[0117] FIG1 is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0118] FIG2 is a flow chart of a vehicle control method provided by an embodiment of the present application;
[0119] FIG3 is a flow chart of a vehicle control method provided by an embodiment of the present application;
[0120] FIG4 is a flow chart of a vehicle control method provided by an embodiment of the present application;
[0121] FIG5 is a vehicle control flow chart provided in an embodiment of the present application;
[0122] FIG6 is a schematic diagram of a module of a vehicle-mounted device provided in an embodiment of the present application;
[0123] FIG7 is a schematic diagram of a cloud module provided in an embodiment of the present application;
[0124] FIG8 is a flow chart of a vehicle control method provided by an embodiment of the present application;
[0125] FIG9 is a block diagram of a vehicle control device provided in an embodiment of the present application;
[0126] FIG10 is a block diagram of a vehicle control device provided in an embodiment of the present application;
[0127] FIG11 is a schematic structural diagram of a device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0128] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0129] To facilitate understanding of the technical solutions provided by the embodiments of the present application, the system architecture of the present application is first introduced in conjunction with Figures 1 and 2.
[0130] FIG1 is a schematic diagram of a system architecture provided by an embodiment of the present application. Referring to FIG1 , the system architecture includes a terminal 10 , a vehicle device 11 , a telematics device 12 , and a cloud 13 .
[0131] Among them, the vehicle device 11 and the telematics device 12 belong to the same vehicle, and the vehicle device 11 and the telematics device 12 are connected through the vehicle's internal network. For example, the vehicle device 11 and the telematics device 12 are connected through the vehicle's Ethernet or vehicle bus.
[0132] The vehicle-mounted device 11 and the terminal 10 are connected via a network outside the vehicle. For example, the vehicle-mounted device 11 and the terminal 10 can be connected based on a Bluetooth or wireless high-fidelity (WIFI) network.
[0133] The terminal 10 and the telematics device 12 are also connected to a cloud 13 , which may be a vehicle cloud platform.
[0134] Exemplarily, the terminal 10 may be a mobile terminal, such as a mobile phone, a tablet computer, a smart watch or other smart wearable device.
[0135] Exemplarily, the vehicle-mounted device 11 may be a smart cockpit device (eg, a smart cockpit domain controller), or other smart interactive devices in the vehicle that can provide human-computer interaction and are connected to a telematics device.
[0136] For example, the telematics device 12 may be a T-BOX.
[0137] In the embodiment of the present application, the above-mentioned system architecture belongs to a vehicle. In addition to road vehicles, the vehicles here can also include vehicles with flying functions and vehicles with navigation functions, and the appearance of these vehicles is not limited. For example, they can be other forms of vehicles such as aircraft or aircraft. This application does not limit the form of the vehicle.
[0138] FIG2 is a flow chart of a vehicle control method provided in an embodiment of the present application. The method is applied to the aforementioned terminal, that is, the method can be executed by the terminal in the system architecture shown in FIG1. As shown in FIG2, the method includes the following steps.
[0139] S11: The terminal negotiates with the vehicle's telematics device through the first link to determine a session key.
[0140] Exemplarily, the first link includes a link between the terminal and a vehicle-mounted device of the vehicle, and a link between the vehicle-mounted device and a telematics device; or, the first link includes a link between the terminal and the telematics device.
[0141] The first link between the terminal and the telematics processing device may be a direct link or an indirect link that does not pass through the vehicle-mounted device.
[0142] S12: The terminal uses the session key to encrypt the remote vehicle control command.
[0143] In an embodiment of the present application, the remote vehicle control command may be a vehicle start-up command, a vehicle air conditioning control command, a vehicle seat adjustment command, etc. The present application does not limit the type of the remote vehicle control command.
[0144] S13: The terminal sends the encrypted remote vehicle control instruction to the telematics device via a second link, where the second link is different from the first link.
[0145] Exemplarily, the second link includes a link between the terminal and the cloud, and a link between the cloud and the telematics device; or, the second link includes a link between the terminal and the telematics device.
[0146] Among them, the second link between the terminal and the telematics device can be a direct link or an indirect link that does not pass through the cloud.
[0147] Even if the first link and the second link both include links between the terminal and the telematics device, the nodes passed through may be different, or the protocols used by the two may be different. In these cases, the first link and the second link are still different links.
[0148] In an embodiment of the present application, the terminal uses a first link when negotiating a session key with the telematics device, and then transmits the encrypted remote vehicle control command through the second link. That is to say, the key of the present application is obtained through negotiation, and even if the cloud is attacked, the key cannot be obtained. Moreover, the link used to negotiate the key is different from the transmission link. Even if the cloud is attacked while the command is transmitted through the cloud, the attacker cannot tamper with the vehicle control command, thereby ensuring the security of the vehicle control method.
[0149] FIG3 is a flow chart of a vehicle control method provided in an embodiment of the present application. The method is applied to the aforementioned vehicle. The method can be executed by the telematics processing device in the system architecture shown in FIG1. As shown in FIG3, the method includes the following steps.
[0150] S21: The telematics device negotiates with the terminal through the first link to determine a session key.
[0151] S22: The telematics device receives the encrypted remote vehicle control command sent by the terminal via a second link, where the second link is different from the first link.
[0152] S23: The telematics processing device decrypts the encrypted remote vehicle control instruction using the session key to obtain the remote vehicle control instruction.
[0153] S24: The telematics device controls the vehicle according to the remote vehicle control command.
[0154] For example, if the remote vehicle control command is a vehicle start command, the telematics device starts the vehicle based on the remote vehicle control command.
[0155] For another example, the remote vehicle control command is a vehicle air conditioning control command, and the telematics device controls the operation of the air conditioning in the vehicle based on the remote vehicle control command.
[0156] For another example, the remote vehicle control command is a vehicle seat adjustment command, and the telematics device adjusts the seat state in the vehicle based on the remote vehicle control command.
[0157] In an embodiment of the present application, the telematics device uses a first link when negotiating a session key with the terminal, and then transmits the encrypted remote vehicle control command through the second link. That is to say, the key of the present application is obtained through negotiation, and the key cannot be obtained even if the cloud is attacked. Moreover, the link used to negotiate the key is different from the transmission link. Even if the cloud is attacked while the command is transmitted through the cloud, the attacker cannot tamper with the vehicle control command, thereby ensuring the security of the vehicle control method.
[0158] The following example illustrates the vehicle control method, using a scenario where the first link includes the link between the terminal and the vehicle's onboard equipment, as well as the link between the onboard equipment and the telematics device, and the second link includes the link between the terminal and the cloud, as well as the link between the cloud and the telematics device. If the first and second links are other types of links, the vehicle control method remains the same, requiring only adjustments to the details to accommodate the link differences. For example, steps executed by the onboard equipment and the cloud may be omitted, or steps executed by the onboard equipment or the cloud may be transferred to other nodes along the link.
[0159] FIG4 is a flow chart of a vehicle control method provided in an embodiment of the present application. The method is applied to the aforementioned vehicle. The method can be jointly executed by the terminal and telematics device in the system architecture shown in FIG1 . As shown in FIG4 , the method includes the following steps.
[0160] S31: The terminal determines the symmetric key between itself and the vehicle's onboard equipment.
[0161] In one possible implementation of the present application, the terminal determines a symmetric key between the terminal and the vehicle's onboard equipment, including:
[0162] The terminal obtains the same secret factor as the vehicle device; the terminal determines the symmetric key based on the secret factor.
[0163] In this implementation, by obtaining the same secret factor as the vehicle equipment, the terminal determines the symmetric key based on the secret factor, thereby providing a basis for the encryption of subsequent information transmission.
[0164] In one example, the secret factor includes at least one of an encryption password, a random salt value and an iteration number, and a vehicle unique identification code.
[0165] For example, secret factors include the encryption password, the random salt value and the iteration number, and the vehicle unique identification code.
[0166] In other examples, the secret factor may also be composed of other parameters, which is not limited in this application.
[0167] The terminal and the vehicle device can be connected based on a Bluetooth or wireless high-fidelity (WIFI) network. After the terminal and the vehicle device are connected, the vehicle device sends the above-mentioned secret factor to the terminal.
[0168] In one example, the encryption password in the secret factor may be an encryption password used when the terminal and the vehicle device realize Bluetooth connection or WIFI connection.
[0169] In another example, the encryption password in the secret factor can be a separately set encryption password, which is input through the vehicle-mounted large screen or the terminal after the connection between the terminal and the vehicle device is completed.
[0170] After the terminal receives the secret factor, the terminal calculates the symmetric key in the same way as the vehicle equipment. This method can be a mature key algorithm in the relevant technology, or a key algorithm designed based on the encryption needs of this application. This application does not impose any restrictions on this.
[0171] The above-mentioned key algorithm can be stored in the terminal and the vehicle-mounted device in advance, or can be negotiated and determined after the terminal and the vehicle-mounted device are connected. This application does not impose any restrictions on this.
[0172] Accordingly, in addition to determining the symmetric key based on the secret factor, the terminal also determines the symmetric key based on the secret factor. Because the determination method is the same, the keys determined by both are the same. This method avoids direct key transmission, thus reducing the risk of exposure, while ensuring key consistency.
[0173] In other possible implementations of the present application, the content of the secret factor transmitted between the terminal and the vehicle-mounted device may include more or fewer parameters, or the secret factor may be transmitted from the terminal to the vehicle-mounted device, etc. The present application does not impose too many restrictions on these implementation details.
[0174] FIG5 is a vehicle control flow chart provided in an embodiment of the present application. Referring to FIG5 , the terminal 10 is a mobile phone, the vehicle-mounted device 11 is a smart cockpit, and the telematics processing device 12 is a T-BOX as an example. The terminal 10 includes a first application and a Bluetooth module, the vehicle-mounted device 11 includes a large cockpit screen, a communication proxy application, a Bluetooth module, and an Ethernet module, and the telematics processing device 12 includes a second application and an Ethernet module. The above-mentioned first application, communication proxy application, and second application are all responsible for establishing communication connections, data encryption and decryption, and other functions. The detailed process of step S31 is described below in conjunction with the structure of FIG5 :
[0175] S311. The Bluetooth module of the terminal is paired with the Bluetooth module of the vehicle equipment to establish a communication channel.
[0176] S312: The first application on the terminal and the communication agent application on the vehicle-mounted device enter the device authentication pairing interface. The vehicle-mounted device's large screen displays a QR code, which the terminal scans to complete authentication. Alternatively, the terminal and the vehicle-mounted device each obtain a preset password entered by the user. If the obtained preset passwords are the same, authentication is completed.
[0177] Among them, the preset password can set the maximum number of trial and error times, avoiding potential attacks by limiting the number of password trial and error times between the terminal and the vehicle equipment.
[0178] Although S312 in Figure 5 is performed between the first application and the communication proxy application, it still requires the path established by the Bluetooth module. The transmission path of S312 is: first application-Bluetooth module in terminal 10-Bluetooth module in vehicle device 11-communication proxy application.
[0179] S313. The terminal obtains the same secret factor as the vehicle-mounted device through the first application.
[0180] In one example, the terminal and the vehicle device each obtain a secret factor input by the user. In this case, the secret factor can be generated by the user input.
[0181] In another example, the terminal scans the QR code provided by the large screen in the cockpit of the vehicle equipment to obtain the secret factor shared by the vehicle equipment. In this case, the secret factor can be automatically generated by the vehicle equipment or generated by the vehicle equipment based on user input.
[0182] The secret factors include the encryption password (password, pwd), random salt value (salt), number of iterations (n) and vehicle unique identification number (VIN).
[0183] For example, the number of iterations is related to the strength of the generated symmetric key, and can usually be selected as 1024 or 2048, which can ensure the key strength without occupying too much computing power resources.
[0184] Although S313 in Figure 5 is performed between the first application and the communication proxy application, it still requires the path established by the Bluetooth module. The transmission path of S313 is: transmission along the path of the communication proxy application - the Bluetooth module in the vehicle device 11 - the Bluetooth module in the terminal 10 - the first application.
[0185] S314: The terminal calculates a symmetric key based on the secret factor through the first application.
[0186] Exemplarily, the symmetric key UK (User Key) = PBKDF2 (pwd||VIN, salt, n). Since VIN is used in the symmetric key calculation process, and VIN is the vehicle's unique identification code, the above key determination can also be considered as the preliminary binding of the terminal and the telematics device.
[0187] In the above process, the terminal and the vehicle-mounted device first establish a basic communication link using Bluetooth, then complete the secret factor exchange and key generation. This symmetric key is subsequently used for identity authentication and data transmission protection between the terminal and the vehicle-mounted device. In the vehicle, the vehicle-mounted device and the telematics processing device communicate within the vehicle domain, and the communication link can use Ethernet communication, which is a trusted communication. Therefore, the terminal and the telematics processing device complete the establishment of a secure communication link through the vehicle-mounted device as a communication proxy, completing the negotiation of the session key between the terminal and the vehicle-mounted device.
[0188] Figure 6 is a schematic diagram of the modules of a vehicle-mounted device provided in an embodiment of the present application. Referring to Figure 6 , this module may be included in a communication proxy application within the vehicle-mounted device. The communication proxy application includes a device binding module, an identity authentication module, a communication connection and proxy module, a secret factor exchange module, and a data encryption and decryption module. These modules can resolve trust issues between user terminals and telematics devices and facilitate key negotiation between the terminals and the telematics device.
[0189] S32: The terminal encrypts the binding request using a symmetric key.
[0190] After the secure channel between the terminal and the telematics device is established, the terminal can generate and encrypt a binding request when manually triggered by the user. The terminal can also automatically generate and encrypt a binding request.
[0191] Exemplarily, the binding request may include terminal information and telematics device information, for example, the terminal information may be a user identifier or a terminal identifier, and the telematics device information may be the aforementioned VIN.
[0192] S33: The terminal sends an encrypted binding request to the vehicle device, so that the vehicle device decrypts the encrypted binding request and sends it to the telematics processing device; the telematics processing device receives the binding request sent by the terminal through the vehicle device.
[0193] After the secure channel is established, the information transmission process from the terminal to the telematics device is the same. See Figure 5. The transmission path of the binding request and other information in S33 is: first application-Bluetooth module of the terminal 10-Bluetooth module of the vehicle device 11-communication agent application-Ethernet module of the vehicle device 11-Ethernet module of the telematics device 12-second application.
[0194] S34: The telematics processing device sends a binding response to the vehicle-mounted device, so that the vehicle-mounted device encrypts and forwards the response to the terminal; the terminal receives the binding response encrypted and forwarded by the vehicle-mounted device.
[0195] After the secure channel is established, the information transmission process from the telematics device to the terminal is the same, see Figure 5, the transmission path of the binding response and other information in S34 is: second application-Ethernet module of the telematics device 12-Ethernet module of the vehicle device 11-communication agent application-Bluetooth module of the vehicle device 11-Bluetooth module of the terminal 10-first application.
[0196] S35: The terminal decrypts the encrypted binding response using the symmetric key to complete the binding.
[0197] In this implementation, the vehicle-mounted device and the telematics device are connected via the vehicle's internal network, such as the in-vehicle Ethernet or bus, ensuring the security of the line between them. However, the vehicle-mounted device and the terminal are connected via a network outside the vehicle, making security unreliable. Therefore, in this implementation, information transmitted between the terminal and the telematics device is encrypted using a symmetric key to enhance security. This network and information transmission method ensure the security of the binding process between the terminal and the telematics device.
[0198] In an embodiment of the present application, the trust relationship between the terminal and the telematics device does not depend on the cloud, and the binding is completed in the near-field communication scenario. The cloud cannot change the device binding relationship.
[0199] S36: The terminal and the telematics device negotiate to determine a session key.
[0200] In an embodiment of the present application, a mature key negotiation algorithm may be used for key negotiation between the terminal and the telematics processing device, or a customized key negotiation algorithm may be used for key negotiation between the terminal and the telematics processing device.
[0201] Exemplarily, the terminal and the telematics device may use an elliptic curve Diffie Hellman key exchange (ECDH) algorithm for key negotiation.
[0202] When using the ECDH algorithm for key negotiation, the terminal and telematics device use the certificate as the root of trust between the devices. The terminal sends the certificate, algorithm suite, and random number to the telematics device, and the telematics device sends the certificate, algorithm suite, and random number to the terminal. These certificates, algorithm suites, and random numbers are encrypted using symmetric keys when transmitted between the terminal and the vehicle.
[0203] After the certificates are exchanged, the terminal and the telematics device verify the legitimacy of the other party's certificate and continue the negotiation only if it is legitimate; otherwise, the negotiation is stopped.
[0204] After the certificate authentication is completed, the terminal and the telematics device extract the public key from the other party's certificate.
[0205] After the certificate authentication is completed, the terminal and the telematics device generate temporary public keys respectively and exchange them. During the exchange process, the public key extracted from the certificate or the temporary public key is first used for encryption, and when passing through the link between the terminal and the vehicle device, a symmetric key is also required for second-layer encryption.
[0206] After the temporary public key exchange is completed, the terminal and the remote information use the temporary public key to negotiate and generate the same session key, also known as the master key.
[0207] Although S36 in Figure 5 is performed between the first application and the second application, it still requires the path established by the Bluetooth module and the Ethernet module. The transmission path of S36 is: first application-Bluetooth module of terminal 10-Bluetooth module of vehicle device 11-communication agent application-Ethernet module of vehicle device 11-Ethernet module of telematics device 12-second application.
[0208] S37: The terminal uses the session key to encrypt the remote vehicle control command.
[0209] In one possible implementation of the present application, the terminal uses a session key to encrypt a remote vehicle control command, including:
[0210] The terminal encrypts the remote vehicle control instruction and the first count value using the session key so that the telematics device verifies the legitimacy of the remote vehicle control instruction based on the first count value, where the first count value is the count value of the remote vehicle control instruction.
[0211] In this implementation, a first count value is encrypted along with the remote vehicle control command. The encrypted remote vehicle control command and the first count value are then transmitted together. Upon receiving the remote vehicle control command, the telematics device performs a validity check based on the first count value. The first count value increases with the number of commands sent from the terminal to the telematics device. Therefore, by verifying the first count value, it is possible to determine whether the command is legitimate or has been replayed, thereby enhancing security.
[0212] The first count value increases incrementally, meaning that each time the terminal sends a message, the first count value carried by the terminal gradually increases, for example, by 1. For example, when the terminal sends the first remote vehicle control command, the first count value is 1. When the terminal sends the second remote vehicle control command, the first count value is 2, and so on. After receiving and decrypting the message, the telematics processing device determines whether the decrypted first count value is 1 higher than the first count value obtained from the previous decryption. If so, it indicates legality; otherwise, it indicates illegality.
[0213] In one example, the remote vehicle control command and the first count value are encrypted as a whole; in another example, the remote vehicle control command and the first count value are encrypted separately. That is, the remote vehicle control command and the first count value can be a single message or data packet, or they can be separated into separate messages or data packets. However, the separation must ensure that the two can be linked or corresponded to each other.
[0214] In another possible implementation of the present application, the terminal does not carry the first count value when encrypting the remote vehicle control instruction, which can reduce the message size of the transmission instruction and reduce the bandwidth requirement.
[0215] In the implementation of the present application, the user triggers the remote vehicle control command through the application in the terminal, that is, the terminal responds to the vehicle control operation in the application by the user and executes step S37. The terminal encrypts the remote vehicle control command using the negotiated session to generate a ciphertext.
[0216] S38: The terminal sends the encrypted remote vehicle control command to the telematics processing device via the cloud; the telematics processing device receives the encrypted remote vehicle control command sent by the terminal via the cloud.
[0217] Figure 7 is a schematic diagram of a cloud module provided by an embodiment of the present application. Referring to Figure 7, the cloud includes a device management module and a data forwarding module. The device management module is used to obtain the binding relationship of the terminal telematics device and, based on this binding relationship, determine the target device for the received information, such as the target telematics device or the target terminal. The data forwarding module is used to transparently forward data to the target device. During this process, the cloud cannot decrypt or tamper with the message, thus preventing attacks that could exploit the cloud-controlled vehicle vulnerability.
[0218] 5 , the transmission path of the encrypted remote vehicle control command is: terminal 10 - cloud 13 - telematics device 12 .
[0219] S39: The telematics processing device decrypts the encrypted remote vehicle control instruction using the session key to obtain the remote vehicle control instruction.
[0220] In the case where the remote vehicle control instruction carries the first count value, the telematics processing device uses the session key to decrypt to obtain the remote vehicle control instruction and the first count value, and verifies the legitimacy through the first count value.
[0221] 5 , step S39 may be performed by the second application of the telematics device 12 .
[0222] S310: The telematics device controls the vehicle according to the remote vehicle control command.
[0223] The telematics device sends remote vehicle control commands to the corresponding controller via the bus, enabling remote vehicle control, such as remote starting, air conditioning control, seat adjustment, etc. The bus can be a controller area network (CAN) bus.
[0224] In one possible implementation of the present application, after the terminal and the telematics processing device determine the session key through negotiation, they always use the same session key to encrypt information. In this way, the terminal and the telematics processing device have less processing power to determine the key to be used.
[0225] In another possible implementation of the present application, after the terminal and the telematics processing device determine the session key through negotiation, they will periodically update the used session key, thereby further increasing security.
[0226] In one example, the terminal updates the session key in the following manner: the terminal and the telematics device periodically update the session key through negotiation. That is, the terminal and the telematics device periodically negotiate and then use the latest negotiated session key.
[0227] In another example, the terminal updates the session key in the following manner: the terminal and the telematics device negotiate to obtain multiple session keys; based on the multiple session keys, the terminal periodically updates the session key in use. Specifically, the terminal and the telematics device negotiate to obtain multiple session keys, then select a session key to use from these multiple session keys, and periodically replace the session key in use. Of course, in this example, the terminal and the telematics device can still negotiate periodically, but unlike the first example, multiple session keys are obtained during each negotiation, and the session key is replaced between negotiation cycles.
[0228] In the implementation of this application, the above-mentioned negotiation period or key replacement period can be set based on security requirements and computing power and bandwidth conditions. This application does not limit the period length of the above-mentioned implementation method.
[0229] The vehicle control solution provided in this application includes two stages. The first stage completes the key negotiation between the terminal and the telematics device, and the second stage completes the transmission of the vehicle remote control command.
[0230] In the first stage, since the terminal and the telematics device cannot communicate directly in actual scenarios, it is necessary to use the vehicle-mounted device as a springboard to complete the establishment of a channel between the terminal and the telematics device, and the information during the negotiation process is transmitted in this channel.
[0231] During this phase, the terminal and telematics device use certificates to authenticate each other, confirming the legitimacy of the public key sent by the other end and preventing impersonation attacks. Both the terminal and the telematics device store session keys, from which the password cannot be reversed. Even if the terminal's authentication database is compromised, the password held by the application terminal cannot be recovered, preventing impersonation of the application device.
[0232] During key negotiation, if a temporary public key is used for data encryption transmission, even if the long-term private key based on the certificate of the terminal or telematics device is leaked, the plaintext data during the negotiation process will not be leaked.
[0233] In the second phase, because the cloud only transparently forwards data, attackers cannot control the vehicle through the cloud, ensuring the security of remote vehicle control. A count value is used as a time-varying parameter to prevent replay attacks. Furthermore, a session key update mechanism is established to further ensure session key security.
[0234] In an embodiment of the present application, the terminal negotiates a session key with the remote information processing device. The security of the session key obtained by binding first and then negotiating can be guaranteed; when the remote vehicle control instructions are subsequently transmitted through the cloud, the negotiated session key is used for encryption. In this way, even if the cloud is attacked, the attacker cannot tamper with the vehicle control instructions, thereby ensuring the security of the vehicle control method.
[0235] This solution ensures that the trust relationship between the terminal and the telematics device is independent of the cloud, preventing cloud vulnerabilities from remotely controlling the vehicle. It not only achieves identity authentication, but also ensures that data is protected by encryption algorithms and cannot be tampered with during transmission.
[0236] In the embodiment of the present application, in addition to transmitting remote vehicle control commands, vehicle status information can also be transmitted between the terminal and the telematics device.
[0237] Figure 8 is a flow chart of a vehicle control method provided in an embodiment of the present application. This method is applicable to the aforementioned vehicle. This method can be jointly executed by the terminal and telematics device in the system architecture shown in Figure 1. Since the key negotiation phase is the same as the method shown in Figure 4, this portion is omitted in Figure 8. As shown in Figure 8, the method includes the following steps.
[0238] S41: The telematics device encrypts the vehicle status information using the session key.
[0239] In the implementation of the present application, the telematics processing device may periodically execute S41, or trigger S41 based on the user's operation on the terminal or vehicle device.
[0240] S42: The telematics processing device sends the encrypted vehicle status information to the terminal via the cloud; the terminal receives the encrypted vehicle status information sent by the telematics processing device via the cloud.
[0241] In a possible implementation of the present application, the terminal receives the encrypted vehicle status information and the second count value sent by the telematics processing device through the cloud, where the second count value is the count value of the vehicle status information.
[0242] In one example, the vehicle status information and the second count value are encrypted as a whole; in another example, the vehicle status information and the second count value are encrypted separately. That is, the vehicle status information and the second count value can be sent as a single message or data packet, or they can be separated into separate messages or data packets. However, the separation must ensure that the two can be linked or corresponded to each other.
[0243] In another possible implementation of the present application, the telematics processing device does not carry the second count value when encrypting the vehicle status information, which can reduce the message size of the transmitted information and lower the bandwidth requirement.
[0244] S43: The terminal decrypts the encrypted vehicle status information using the session key to obtain the vehicle status information.
[0245] Upon receiving the encrypted vehicle status information and the second count value, the terminal decrypts the encrypted vehicle status information and the second count value using the session key to obtain the vehicle status information and the second count value. The terminal then verifies the legitimacy of the vehicle status information based on the second count value. If the information is legitimate, the terminal saves the information; if not, the terminal discards the information.
[0246] In this implementation, the second count value is encrypted along with the vehicle status information, and then transmitted together with the encrypted vehicle status information. This allows the terminal to perform a validity check based on the second count value upon receiving the vehicle status information. The second count value increases with the amount of vehicle status information sent to the terminal by the telematics device. Therefore, by verifying the second count value, it is possible to determine whether the information is legitimate or has been replayed, thereby enhancing security.
[0247] The details of steps S41 to S43 may refer to steps S37 to S39 .
[0248] Figure 9 is a block diagram of a vehicle control device provided in an embodiment of the present application. The vehicle control device can be implemented as all or part of a terminal through software, hardware, or a combination of both. The vehicle control device may include: a key negotiation unit 501, an encryption / decryption unit 502, and a transmission unit 503.
[0249] The key negotiation unit 501 is configured to negotiate with the vehicle's telematics device to determine a session key via the first link;
[0250] An encryption and decryption unit 502, configured to encrypt remote vehicle control instructions using a session key;
[0251] The transmission unit 503 is configured to send the encrypted remote vehicle control command to the telematics device via a second link, where the second link is different from the first link.
[0252] Optionally, the first link includes a link between the apparatus and a vehicle-mounted device of the vehicle, and a link between the vehicle-mounted device and a telematics device;
[0253] Alternatively, the first link comprises a link between the apparatus and a telematics device.
[0254] Optionally, in the case where the first link includes a link between the apparatus and the vehicle-mounted device, and a link between the vehicle-mounted device and the telematics device, the apparatus further comprises: a binding unit 504 for determining a symmetric key with the vehicle-mounted device of the vehicle;
[0255] The encryption and decryption unit 502 is further configured to encrypt the binding request using a symmetric key;
[0256] The transmission unit 503 is further configured to send an encrypted binding request to the vehicle-mounted device, so that the vehicle-mounted device decrypts the encrypted binding request and sends it to the telematics processing device; receive a binding response encrypted and forwarded by the vehicle-mounted device, and the binding response is fed back to the vehicle-mounted device by the telematics processing device;
[0257] The binding unit 504 is further configured to decrypt the encrypted binding response using the symmetric key to complete the binding.
[0258] Optionally, the transmission unit 503 is further configured to obtain the same secret factor as the vehicle-mounted device;
[0259] The binding unit 504 is configured to determine a symmetric key based on the secret factor.
[0260] Optionally, the encryption and decryption unit 502 is used to encrypt the remote vehicle control instruction and the first count value using a session key, so that the remote information processing device verifies the legitimacy of the remote vehicle control instruction based on the first count value, and the first count value is the count value of the remote vehicle control instruction.
[0261] Optionally, the transmission unit 503 is further configured to receive the encrypted vehicle status information and a second count value sent by the telematics device through a second link, where the second count value is a count value of the vehicle status information;
[0262] The encryption and decryption unit 502 is further configured to decrypt the encrypted vehicle status information and the second count value using the session key to obtain the vehicle status information and the second count value; and verify the legitimacy of the vehicle status information based on the second count value.
[0263] Optionally, the second link includes a link between the apparatus and the cloud, and a link between the cloud and the telematics device;
[0264] Alternatively, the second link comprises a link between the apparatus and a telematics device.
[0265] Optionally, the key negotiation unit 501 is further configured to periodically update the session key through negotiation with the telematics device;
[0266] or,
[0267] A plurality of session keys are obtained through negotiation with the telematics processing device, and the key negotiation unit 501 is further used to periodically update the used session keys based on the plurality of session keys.
[0268] It should be noted that the vehicle control device provided in the above embodiment is merely an example of the division of the above functional units when performing vehicle control. In actual applications, the above functions can be assigned to different functional units as needed, that is, the internal structure of the device can be divided into different functional units to complete all or part of the functions described above. In addition, the vehicle control device provided in the above embodiment and the vehicle control method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0269] Figure 10 is a block diagram of a vehicle control device provided in an embodiment of the present application. The vehicle control device can be implemented as all or part of a telematics device through software, hardware, or a combination of both. The vehicle control device may include a key negotiation unit 601, a transmission unit 602, an encryption / decryption unit 603, and a control unit 604.
[0270] The key negotiation unit 601 is configured to negotiate with the terminal to determine a session key through the first link;
[0271] a transmission unit 602, configured to receive an encrypted remote vehicle control command sent by a terminal via a second link, the second link being different from the first link;
[0272] The encryption and decryption unit 603 is used to decrypt the encrypted remote vehicle control instruction using the session key to obtain the remote vehicle control instruction;
[0273] The control unit 604 is configured to control the vehicle according to remote vehicle control instructions.
[0274] Optionally, the first link includes a link between the terminal and a vehicle-mounted device of the vehicle, and a link between the vehicle-mounted device and the apparatus;
[0275] Alternatively, the first link includes a link between the terminal and the device.
[0276] Optionally, when the first link includes a link between the terminal and the vehicle-mounted device, and a link between the vehicle-mounted device and the apparatus, the transmission unit 602 is also used to receive a binding request sent by the terminal through the vehicle-mounted device of the vehicle; and send a binding response to the vehicle-mounted device so that the vehicle-mounted device encrypts and forwards it to the terminal to complete the binding.
[0277] Optionally, the transmission unit 602 is configured to receive an encrypted remote vehicle control instruction and a first count value sent by the terminal via the second link, where the first count value is a count value of the remote vehicle control instruction;
[0278] The encryption and decryption unit 603 is configured to verify the legitimacy of the remote vehicle control instruction based on the first count value.
[0279] Optionally, the encryption and decryption unit 603 is also used to encrypt the vehicle status information and the second count value using a session key, so that the terminal verifies the legitimacy of the vehicle status information based on the second count value, and the second count value is the count value of the vehicle status information; the transmission unit 602 is also used to send the encrypted vehicle status information and the second count value to the terminal through the second link.
[0280] Optionally, the second link includes a link between the terminal and the cloud, and a link between the cloud and the device;
[0281] Alternatively, the second link includes a link between the terminal and the device.
[0282] Optionally, the key negotiation unit 601 is further configured to periodically update the session key through negotiation with the terminal;
[0283] or,
[0284] A plurality of session keys are obtained through negotiation with the terminal, and the key negotiation unit 601 is further configured to periodically update the used session key based on the plurality of session keys.
[0285] It should be noted that the vehicle control device provided in the above embodiment is merely an example of the division of the above functional units when performing vehicle control. In actual applications, the above functions can be assigned to different functional units as needed, that is, the internal structure of the device can be divided into different functional units to complete all or part of the functions described above. In addition, the vehicle control device provided in the above embodiment and the vehicle control method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0286] The embodiment of the present application further provides a vehicle that may include an automatic parking control device as shown in FIG10 .
[0287] Optionally, the vehicle also includes other components or systems connected to the device, such as a central control screen, an instrument screen, a cockpit audio system, a motor controller, a parking controller, etc.
[0288] Figure 11 shows a schematic diagram of the structure of a device 150 provided in an embodiment of the present application. Device 150 can be a terminal or a telematics device. Device 150 shown in Figure 11 is used to perform the operations involved in the vehicle control method shown in any of Figures 2 to 8 above. Device 150 can be implemented using a general bus architecture.
[0289] As shown in FIG. 11 , the device 150 includes at least one processor 151 , a memory 153 , and at least one communication interface 154 .
[0290] The processor 151 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 151 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute the various logic blocks, modules, and circuits described in conjunction with the disclosure of the embodiments of the present application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.
[0291] Optionally, device 150 also includes a bus. The bus is used to transmit information between the components of device 150. The bus may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. Buses can be classified as address buses, data buses, control buses, etc. For ease of illustration, FIG11 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.
[0292] The memory 153 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 153 is, for example, independent and connected to the processor 151 via a bus. The memory 153 can also be integrated with the processor 151.
[0293] The communication interface 154 uses any transceiver-like device to communicate with other devices or communication networks. The communication network can be Ethernet, a radio access network (RAN), or a wireless local area network (WLAN). The communication interface 154 can include a wired communication interface and a wireless communication interface. Specifically, the communication interface 154 can be an Ethernet interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In an embodiment of the present application, the communication interface 154 can be used for the device 150 to communicate with other devices.
[0294] In a specific implementation, as an example, the processor 151 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG11 . Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0295] In a specific implementation, as an example, device 150 may include multiple processors, such as processor 151 and processor 155 shown in FIG11 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0296] In a specific implementation, as an embodiment, the device 150 may further include an output device and an input device. The output device communicates with the processor 151 and can display information in a variety of ways. For example, the output device can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with the processor 151 and can receive user input in a variety of ways. For example, the input device can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0297] In some embodiments, the memory 153 is used to store program code 1510 for executing the solution of the present application, and the processor 151 can execute the program code 1510 stored in the memory 153. That is, the device 150 can implement the method provided by the method embodiment by executing the program code 1510 in the memory 153 through the processor 151. The program code 1510 may include one or more software modules. Optionally, the processor 151 itself may also store program code or instructions for executing the solution of the present application.
[0298] In a specific embodiment, the device 150 of the embodiment of the present application may correspond to the controller in the above-mentioned method embodiments, and the processor 151 in the device 150 reads the instructions in the memory 153, so that the device 150 shown in Figure 11 can execute all or part of the operations performed by the controller.
[0299] Specifically, the processor 151 is used to negotiate and determine a session key with the vehicle's telematics device through a first link; encrypt the remote vehicle control command using the session key; and send the encrypted remote vehicle control command to the telematics device through a second link, which is different from the first link.
[0300] Alternatively, the processor 151 is used to negotiate with the terminal through a first link to determine a session key; receive an encrypted remote vehicle control instruction sent by the terminal through a second link, where the second link is different from the first link; use the session key to decrypt the encrypted remote vehicle control instruction to obtain the remote vehicle control instruction; and control the vehicle according to the remote vehicle control instruction.
[0301] For the sake of brevity, other optional implementations will not be described here in detail.
[0302] Among them, each step of the vehicle control method shown in any of Figures 2 to 8 is completed by the hardware integrated logic circuit or software instructions in the processor of the device 150. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
[0303] An embodiment of the present application further provides a chip comprising an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected via an internal connection path. The processor is configured to execute code stored in the memory. When the code is executed, the processor is configured to perform any of the aforementioned vehicle control methods.
[0304] It should be understood that the processor may be a CPU, or other general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor supporting the ARM architecture.
[0305] Furthermore, in an optional embodiment, there are one or more processors and one or more memories. Alternatively, the memories may be integrated with the processors, or provided separately from the processors. The memories may include read-only memory and random access memory, and provide instructions and data to the processors. The memories may also include non-volatile random access memory. For example, the memories may also store reference blocks and target blocks.
[0306] The memory may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be ROM, PROM, EPROM, EEPROM, or flash memory. The volatile memory may be RAM, which serves as an external cache. By way of example and not limitation, many forms of RAM are available, including, for example, SRAM, DRAM, SDRAM, DDR SDRAM, ESDRAM, SLDRAM, and DR RAM.
[0307] In an embodiment of the present application, a computer-readable storage medium is also provided, which stores computer instructions. When the computer instructions stored in the computer-readable storage medium are executed by an electronic device, the electronic device executes the vehicle control method provided above.
[0308] In an embodiment of the present application, a computer program product containing instructions is also provided. When the computer program product is run on an electronic device, the electronic device executes the vehicle control method provided above.
[0309] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described herein are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive).
[0310] In an embodiment of the present application, a vehicle is further provided. The vehicle includes a range extender and an electronic device. The electronic device is connected to the range extender, and the electronic device is used to implement the vehicle control method provided above.
[0311] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.
[0312] The above are merely optional embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
[0313] Unless otherwise defined, the technical or scientific terms used herein shall have the usual meaning understood by persons of ordinary skill in the field to which this application belongs. The words “first”, “second”, “third” and similar terms used in the patent application specification and claims of this application do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, words such as “a” or “an” do not indicate a quantitative limitation, but rather indicate the presence of at least one. Words such as “include” or “comprising” and similar words mean that the elements or objects appearing before “include” or “comprising” cover the elements or objects listed after “include” or “comprising” and their equivalents, and do not exclude other elements or objects.
[0314] The above is only an embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A vehicle control method, characterized in that: The method comprises: The terminal negotiates with the vehicle's telematics device to determine a session key through the first link; The terminal encrypts the remote vehicle control command using the session key; The terminal sends the encrypted remote vehicle control command to the telematics device via a second link, where the second link is different from the first link.
2. The method according to claim 1, characterized in that The first link includes a link between the terminal and a vehicle machine device of the vehicle, and a link between the vehicle machine device and the telematics processing device; Alternatively, the first link includes a link between the terminal and the telematics device.
3. The method according to claim 2, characterized in that In the case where the first link includes a link between the terminal and the vehicle-mounted device, and a link between the vehicle-mounted device and the telematics processing device, the method further includes: The terminal determines a symmetric key between itself and the vehicle machine device; The terminal encrypts the binding request using the symmetric key; The terminal sends the encrypted binding request to the vehicle device, so that the vehicle device decrypts the encrypted binding request and sends it to the telematics processing device; The terminal receives the binding response encrypted and forwarded by the vehicle device, and the binding response is fed back to the vehicle device by the telematics processing device; The terminal uses the symmetric key to decrypt the encrypted binding response to complete the binding.
4. The method according to claim 3, characterized in that The terminal determines a symmetric key between itself and the vehicle machine device, including: The terminal obtains the same secret factor as the vehicle equipment; The terminal determines the symmetric key based on the secret factor.
5. The method according to any one of claims 1 to 4, characterized in that: The second link includes a link between the terminal and the cloud, and a link between the cloud and the telematics device; Alternatively, the second link includes a link between the terminal and the telematics device.
6. The method according to any one of claims 1 to 5, characterized in that: The method further includes: the terminal and the telematics device periodically updating the session key through negotiation; or, The terminal negotiates with the telematics device to obtain a plurality of session keys, and the method further comprises: The terminal periodically updates the used session key based on the plurality of session keys.
7. A vehicle control method, characterized in that: The vehicle includes a telematics device, and the method includes: The telematics device negotiates with the terminal to determine a session key via a first link; The telematics device receives the encrypted remote vehicle control command sent by the terminal via a second link, the second link being different from the first link; The telematics processing device decrypts the encrypted remote vehicle control instruction using the session key to obtain the remote vehicle control instruction; The telematics device controls the vehicle according to the remote vehicle control command.
8. The method according to claim 7, characterized in that The first link includes a link between the terminal and a vehicle machine device of the vehicle, and a link between the vehicle machine device and the telematics processing device; Alternatively, the first link includes a link between the terminal and the telematics device.
9. The method according to claim 8, characterized in that In the case where the first link includes a link between the terminal and the vehicle-mounted device, and a link between the vehicle-mounted device and the telematics processing device, the method further includes: The telematics processing device receives a binding request sent by the terminal through the vehicle device; The telematics processing device sends a binding response to the vehicle device, so that the vehicle device encrypts and forwards it to the terminal to complete the binding.
10. The method according to any one of claims 7 to 9, characterized in that: The second link includes a link between the terminal and the cloud, and a link between the cloud and the telematics device; Alternatively, the second link includes a link between the terminal and the telematics device.
11. The method according to any one of claims 7 to 10, characterized in that: The method further comprises: The telematics device and the terminal periodically update the session key through negotiation; or, The telematics device negotiates with the terminal to obtain a plurality of session keys, and the method further comprises: The telematics device periodically updates the session key to be used based on the plurality of session keys.
12. A vehicle control device, characterized in that: The device comprises: A key negotiation unit, configured to negotiate and determine a session key with a telematics device of the vehicle via a first link; an encryption and decryption unit, configured to encrypt the remote vehicle control command using the session key; A transmission unit is used to send the encrypted remote vehicle control command to the telematics device through a second link, and the second link is different from the first link.
13. The device according to claim 12, characterized in that The first link includes a link between the apparatus and a vehicle machine device of the vehicle, and a link between the vehicle machine device and the telematics processing device; Alternatively, the first link comprises a link between the apparatus and the telematics device.
14. The device according to claim 13, characterized in that In the case where the first link includes a link between the apparatus and the vehicle-mounted device, and a link between the vehicle-mounted device and the telematics device, the apparatus further includes: a binding unit, configured to determine a symmetric key with the vehicle-mounted device; The encryption and decryption unit is further used to encrypt the binding request using the symmetric key; The transmission unit is further used to send the encrypted binding request to the vehicle device, so that the vehicle device decrypts the encrypted binding request and sends it to the telematics processing device; receive the binding response encrypted and forwarded by the vehicle device, and the binding response is fed back by the telematics processing device to the vehicle device; The binding unit is further configured to use the symmetric key to decrypt the encrypted binding response to complete the binding.
15. The device according to claim 14, characterized in that The transmission unit is further used to obtain the same secret factor as the vehicle machine device; The binding unit is used to determine the symmetric key based on the secret factor.
16. The device according to any one of claims 12 to 15, characterized in that The second link includes a link between the device and the cloud, and a link between the cloud and the telematics device; Alternatively, the second link comprises a link between the apparatus and the telematics device.
17. The device according to any one of claims 12 to 16, characterized in that The key negotiation unit is further used to periodically update the session key through negotiation with the telematics processing device; or, A plurality of session keys are obtained through negotiation with the telematics processing device, and the key negotiation unit is further used to periodically update the used session key based on the plurality of session keys.
18. A vehicle control device, characterized in that: The device comprises: A key negotiation unit, configured to negotiate with the terminal to determine a session key through the first link; a transmission unit, configured to receive the encrypted remote vehicle control command sent by the terminal via a second link, wherein the second link is different from the first link; an encryption and decryption unit, configured to decrypt the encrypted remote vehicle control instruction using the session key to obtain the remote vehicle control instruction; A control unit is used to control the vehicle according to the remote vehicle control command.
19. The device according to claim 18, characterized in that The first link includes a link between the terminal and a vehicle machine device of the vehicle, and a link between the vehicle machine device and the device; Alternatively, the first link includes a link between the terminal and the device.
20. The device according to claim 19, characterized in that In the case where the first link includes a link between the terminal and the vehicle-mounted device, and a link between the vehicle-mounted device and the apparatus, the transmission unit is further configured to receive a binding request sent by the terminal through the vehicle-mounted device; A binding response is sent to the vehicle-mounted device, so that the vehicle-mounted device encrypts and forwards it to the terminal to complete the binding.
21. The device according to any one of claims 18 to 20, characterized in that The second link includes a link between the terminal and the cloud, and a link between the cloud and the device; Alternatively, the second link includes a link between the terminal and the device.
22. The device according to any one of claims 18 to 21, characterized in that The key negotiation unit is further used to periodically update the session key through negotiation with the terminal; or, A plurality of session keys are obtained through negotiation with the terminal, and the key negotiation unit is further used to periodically update the used session key based on the plurality of session keys.
23. A terminal, characterized in that: The terminal includes a processor and a memory, the memory is used to store a software program, and the processor runs or executes the software program stored in the memory so that the terminal implements the method according to any one of claims 1 to 6.
24. A telematics device, characterized in that: The telematics device comprises a processor and a memory, wherein the memory is used to store a software program, and the processor runs or executes the software program stored in the memory so that the telematics device implements the method according to any one of claims 7 to 11.
25. A vehicle control system, characterized in that: The system includes the terminal as claimed in claim 23 and the telematics device as claimed in claim 24.
26. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store program codes executed by a processor, wherein the program codes include instructions for implementing the method according to any one of claims 1 to 11.
27. A computer program product, characterized in that The computer program product comprises program codes, and when a computer runs the computer program product, the computer executes the method according to any one of claims 1 to 11.
28. A vehicle, characterized in that: The vehicle comprises the vehicle control device according to any one of claims 18 to 22.
Citation Information
Patent Citations
Vehicle control method and device, terminal and remote information processing equipment
CN120185829A
Mobile communication conversion privacy enhancing mehtod based on physical layer safety
CN104010299A
Method and equipment for performing safety communication between T_Box equipment and ECU equipment in internet of vehicles system
CN108347331A
T-BOX long link control method and system for Internet of Vehicles terminal
CN111328043A
Data processing method and device, electronic equipment and storage medium
CN115147956A