Secure data transmission method, electronic device, and vehicle
By using two-way identity authentication with a certificate-free password algorithm between the automotive event data recording system and the zero-trust server and the gateway, the security risks of EDR and cloud data interaction are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- PCT/CN2024/136886
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-21
- Filing Date
- 2024-12-04
- Publication Date
- 2025-06-26
AI Technical Summary
The automotive event data record system (EDR) and the cloud have security risks during data interaction, and fail to effectively ensure the security of data.
Two-way identity authentication is performed using certificate-free password algorithm to ensure identity authentication between EDR and zero-trust server and gateway, thereby realizing secure data transmission with the service server.
Through two-way identity authentication, the security during data transmission is improved, illegal terminal access and malicious attacks are prevented, and the security of data access transmission in the Internet of Vehicles is ensured.
Smart Images

Figure CN2024136886_26062025_PF_FP_ABST
Abstract
Description
Data security transmission method, electronic device and vehicle
[0001] This application claims priority to the patent application number 2023117751505 filed with the China Patent Office on December 21, 2023, entitled “Data Security Transmission Method, Electronic Device and Vehicle,” the entire contents of which are incorporated herein by reference. Technical Field
[0002] The present application relates to the technical field of data transmission, and in particular to a data security transmission method, electronic equipment, and vehicle. Background Art
[0003] Currently, newly manufactured passenger vehicles are required to be equipped with an Event Data Recorder (EDR) system to meet safety requirements. EDR can record the vehicle's operating parameters and safety status information in three stages: before, during, and after a collision. In order to further analyze the vehicle's collision event, frequent data access and data transmission are required between the EDR and the cloud. Typically, data access and transmission between the EDR and the cloud uses a connection-first, then authentication method. No identity authentication process is performed when establishing the connection, resulting in a greater risk in this connection method. The security of the data interaction between the EDR and the cloud cannot be guaranteed.
[0004] Technical content
[0005] In view of this, the purpose of this application is to propose a data security transmission method, electronic device and vehicle to solve the problem that data security cannot be guaranteed when EDR interacts with the cloud.
[0006] Based on the above objectives, the first aspect of the present application provides a data security transmission method applied to an automobile event data recording system, comprising:
[0007] Use certificateless cryptographic algorithm to perform first two-way identity authentication with the zero-trust server;
[0008] In response to the first two-way identity authentication being passed, performing a second two-way identity authentication with the gateway using a certificateless cryptographic algorithm;
[0009] In response to the second two-way identity authentication being passed, data transmission is performed with the business service end based on the business data transmission port allocated by the gateway.
[0010] Optionally, use a certificateless cryptographic algorithm to perform a first two-way identity authentication with the zero-trust server, including:
[0011] Generate authentication request information;
[0012] Based on the authentication request information, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate a first digital signature;
[0013] Sending the authentication request information and the first digital signature to the zero trust server, so that the zero trust server verifies the first digital signature;
[0014] Receive authentication request feedback information and a second digital signature sent by the zero-trust server after verifying the first digital signature;
[0015] The second digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm to complete the first two-way identity authentication.
[0016] Optionally, based on the authentication request information, using a digital signature generation algorithm in a certificateless cryptographic algorithm to generate a first digital signature includes:
[0017] Based on the elliptic curve system parameters, random numbers, authentication request information and / or the private key of the vehicle event data recording system, a digital signature generation algorithm in the certificateless cryptographic algorithm is used to generate a first digital signature.
[0018] Optionally, a digital signature verification algorithm in a certificateless cryptographic algorithm is used to verify the second digital signature, including:
[0019] The public key of the zero trust server is calculated based on the identifier of the zero trust server, the elliptic curve system parameters and the random number; based on the identifier of the zero trust server, the elliptic curve system parameters, the random number, the authentication request feedback information and / or the public key of the zero trust server, the digital signature verification algorithm in the certificateless cryptographic algorithm is used to verify the second digital signature.
[0020] Optionally, in response to the first two-way identity authentication being successful, performing a second two-way identity authentication with the gateway using a certificateless cryptographic algorithm includes:
[0021] In response to the first two-way identity authentication being passed, receiving the authentication token, access control security policy, and gateway port identifier sent by the zero trust server;
[0022] Establish a communication connection with the gateway by accessing the gateway port corresponding to the gateway port identifier;
[0023] Generate a data transmission request based on the authentication token and the access control security policy, and send the data transmission request to the gateway through the gateway port, so that the gateway authenticates the vehicle event data recording system based on the data transmission request and the authentication token received in advance from the zero trust server;
[0024] The receiving gateway sends a third digital signature after passing the identity authentication of the vehicle event data recording system;
[0025] The third digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm to complete the second two-way identity authentication.
[0026] A second aspect of the present application provides a data security transmission method, which is applied to a zero-trust server, and the method includes:
[0027] Adopting certificate-less cryptographic algorithm to conduct first two-way identity authentication with the vehicle event data recording system;
[0028] In response to the first two-way identity authentication being passed, the automobile event data recording system and the gateway perform a second two-way identity authentication. In response to the second two-way identity authentication being passed, the automobile event data recording system performs data transmission with the business service end based on the business data transmission port allocated by the gateway.
[0029] Optionally, before the vehicle event data recording system and the gateway perform a second two-way identity authentication, the following steps are included:
[0030] Conduct trust assessments on automotive event data recording systems;
[0031] In response to the trust evaluation result satisfying the preset evaluation condition, the vehicle event data recording system and the gateway perform a second two-way identity authentication.
[0032] A third aspect of the present application provides a data security transmission method, applied to a gateway, comprising:
[0033] A certificateless cryptographic algorithm is used to perform a second two-way identity authentication with the vehicle event data recording system. The second two-way identity authentication is performed after the vehicle event data recording system and the zero-trust server have successfully completed the first two-way identity authentication.
[0034] In response to the second two-way identity authentication being passed, the automobile event data recording system transmits data with the business service end through the business data transmission port allocated by the gateway.
[0035] Optionally, before performing a second two-way authentication with the vehicle event data recording system, the following steps may be performed:
[0036] Receive a gateway port identifier; wherein the gateway port identifier is sent by the zero trust server after the vehicle event data recording system and the zero trust server have passed the first two-way identity authentication;
[0037] Open the corresponding gateway port according to the gateway port identifier;
[0038] Receive a data transmission request sent by the vehicle event data recording system from the gateway port.
[0039] Optionally, the method further includes: closing the gateway port in response to not receiving a data transmission request from the gateway port within a preset time period.
[0040] A fourth aspect of the present application provides a data security transmission device, which is applied to an automobile event data recording system. The device includes: a processor, wherein the processor is configured to execute the following program modules stored in a memory:
[0041] The first authentication module is configured to use a certificateless cryptographic algorithm to perform a first two-way identity authentication with the zero-trust server;
[0042] a second authentication module configured to perform a second two-way identity authentication with the gateway using a certificateless cryptographic algorithm in response to the first two-way identity authentication being passed;
[0043] The data transmission module is configured to transmit data with the business service end based on the business data transmission port allocated by the gateway in response to the passing of the second two-way identity authentication.
[0044] A fifth aspect of the present application provides a data security transmission method, which is applied to a zero-trust server. The device includes: a processor, wherein the processor is configured to execute the following program modules stored in a memory:
[0045] The third authentication module is configured to use a certificateless cryptographic algorithm to perform a first two-way identity authentication with the automobile event data recording system; in response to the first two-way identity authentication being passed, the automobile event data recording system is enabled to perform a second two-way identity authentication with the gateway; in response to the second two-way identity authentication being passed, the automobile event data recording system is enabled to transmit data with the business service end based on the business data transmission port allocated by the gateway.
[0046] A sixth aspect of the present application provides a data security transmission method, which is applied to a gateway. The device includes: a processor, wherein the processor is configured to execute the following program modules stored in a memory:
[0047] The fourth authentication module is configured to use a certificateless cryptographic algorithm to perform a second two-way identity authentication with the automobile event data recording system; wherein, the second two-way identity authentication is performed after the automobile event data recording system and the zero-trust server pass the first two-way identity authentication; in response to the second two-way identity authentication being passed, the automobile event data recording system transmits data with the business server through the business data transmission port allocated by the gateway.
[0048] The seventh aspect of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the first aspect when executing the program.
[0049] An eighth aspect of the present application provides a vehicle, the vehicle comprising the electronic device as described in the fourth aspect.
[0050] As can be seen from the above, the data security transmission method provided by the present application is applied to the automobile event data recording system. The method includes: using a certificateless cryptographic algorithm to perform a first two-way identity authentication with a zero-trust server. The zero-trust server and the automobile event data recording system can ensure the legitimacy of each other's identities through the first two-way identity authentication. In response to the first two-way identity authentication being passed, the automobile event data recording system establishes a connection with the gateway, achieving authentication before connection with the gateway, and ensuring the security of the communication connection with the gateway. Afterwards, the automobile event data recording system performs a second two-way identity authentication with the gateway, and the cryptographic algorithm in the second two-way identity authentication also uses a certificateless cryptographic algorithm. The gateway and the automobile event data recording system can ensure the legitimacy of each other's identities through the second two-way identity authentication. In response to the second two-way identity authentication being passed, the automobile event data recording system establishes a connection with the business server, achieving authentication before connection with the business server, and ensuring the security of the communication connection with the business server, and then transmits data with the business server based on the business data transmission port allocated by the gateway. In other words, only after two rounds of bidirectional identity authentication are passed can the vehicle event data recording system and the business server transmit data. This prevents illegal terminals from directly accessing the business server to steal data or launching malicious attacks on the business server, posing a data security threat, and improves the security of data access and transmission in the Internet of Vehicles. Among them, the certificateless cryptographic algorithm is a lightweight cryptographic algorithm that eliminates digital certificates, enabling the issuance of public and private keys independent of digital certificates, and achieving a faster public and private key generation rate. At the same time, the removal of digital certificates reduces the communication resource usage of digital certificates during communication transmission and reduces the computing power required during digital signature verification, thereby effectively improving the identity authentication rate during data transmission between the vehicle event data recording system and the business server and reducing communication resource consumption. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions in this application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are merely embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0052] FIG1 is a schematic diagram of information interaction among an automobile event data recording system, a zero-trust server, and a gateway according to an embodiment of the present application;
[0053] FIG2 is a schematic diagram of a flow chart of a data security transmission method according to an embodiment of the present application;
[0054] FIG3 is a schematic diagram of a flow chart of a first two-way identity authentication method according to an embodiment of the present application;
[0055] FIG4 is a schematic diagram of a flow chart of a second two-way identity authentication method according to an embodiment of the present application;
[0056] FIG5 is a schematic diagram of a flow chart of a data security transmission method according to another embodiment of the present application;
[0057] FIG6 is a schematic flow chart of a data security transmission method according to another embodiment of the present application;
[0058] FIG7 is a schematic structural diagram of a data security transmission device according to an embodiment of the present application;
[0059] FIG8 is a schematic structural diagram of a data security transmission device according to another embodiment of the present application;
[0060] FIG9 is a schematic structural diagram of a data security transmission device according to another embodiment of the present application;
[0061] FIG10 is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0062] In order to make the objectives, technical solutions and advantages of this application more clear, this application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.
[0063] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the usual meanings understood by people with ordinary skills in the field to which this application belongs. The "first", "second" and similar words used in the embodiments of the present application do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0064] EDR can record vehicle driving information. When a vehicle experiences an emergency, such as speeding or an emergency stop, EDR will promptly record this data for a period of time until the emergency is resolved. EDR data can serve as crucial evidence to determine responsibility for an accident, and the widespread adoption of EDR has greatly facilitated vehicle forensics. To facilitate the protection and analysis of EDR data, EDR must upload or download data to or from the cloud. However, in related technologies, the commonly used data transmission method is connect first, then authenticate. This means that the EDR and the cloud first establish a communication connection and then verify the other party's legitimacy. Before establishing the communication connection, neither party undergoes any identity authentication, resulting in security risks during the connection process and making EDR and cloud data vulnerable to illegal attacks.
[0065] In view of this, the present application proposes a method for secure data transmission. In the process of data interaction, in order to ensure data security, a verification method based on a zero-trust network architecture is used for data transmission. The zero-trust network breaks the existing concept of trust in the internal network in the Internet of Vehicles network security and data security protection. It assumes that the internal network is the same as the external network, which is untrustworthy and unsafe. Any connection to any person, any device, any system, or any application in the network needs to be authenticated and dynamically authorized according to the current status to achieve access control. From system-centric security protection to identity-centric security protection, the access to data changes the existing connection-first-then-authentication mode to a new authentication-first-then-connection mode, that is, data access for all devices, users, and applications adopts authentication, authorization, and encrypted transmission, which solves the protection shortcomings of Internet of Vehicles data security. In the identity authentication process, a certificateless cryptographic algorithm is used to authenticate the identity of each end. On the basis of ensuring the security of data transmission, it reduces the consumption of communication resources, improves the identity authentication rate, and thus improves the data transmission rate.
[0066] Figure 1 shows a schematic diagram of information interaction between the automobile event data recording system, the zero-trust server and the gateway. The automobile event data recording system 01, the zero-trust server 02 and the gateway 03 can exchange information with each other. Before implementing the data security transmission method provided in this application, the automobile event data recording system, the zero-trust server and the gateway need to meet some prerequisites, including: the automobile event data recording system completes the installation and deployment of the public key / private key pair or the identifier / private key pair when the entire vehicle is offline, and sets the public key / private key pair or the identifier / private key pair for the automobile event data recording system, the zero-trust server and the gateway through a secure channel, as well as the public key or identifier setting of other device ends except itself. The zero-trust server needs to register the automobile event data recording system and gateway it manages. The registration information includes EDR identification, EDR information, EDR status, hidden port information used to achieve connection with the EDR, and the evaluation value of the initial trust evaluation based on the vehicle-side authentication request information.
[0067] The embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0068] This application provides a data security transmission method, which is applied to an automobile event data recording system. Referring to FIG2 , the method includes the following steps:
[0069] Step 102: Use a certificateless cryptographic algorithm to perform a first two-way identity authentication with the zero-trust server.
[0070] Specifically, before establishing a communication connection with the business server and transmitting data, the EDR system must perform two-way authentication with both the zero-trust server and the gateway. Once the legitimate identity is confirmed, a communication connection is established with the business server for subsequent data transmission, effectively defending against illegal external attacks on the connected vehicle network. Two-way authentication involves a first two-way authentication between the EDR and the server, and a second two-way authentication between the EDR and the gateway. This double authentication improves authentication security.
[0071] The zero-trust server is a server that can provide dynamic trust assessment services to each end in the zero-trust network architecture. In this application, the zero-trust server can provide dynamic trust assessment services for EDR and gateways to complete registration and assessment tasks. EDR establishes a communication connection with the zero-trust server through the hidden port agreed upon during the offline certification registration, and opens the hidden port of the zero-trust server through port knocking technology. The hidden port is a port that is invisible to the outside world. When the EDR needs to access the hidden port, it can use port knocking technology, that is, transmit agreed information with the hidden port to open the hidden port, realize data interaction with the zero-trust server, and perform the first two-way identity authentication with the zero-trust server. The zero-trust server can dynamically evaluate the EDR according to the trust assessment algorithm, adjust the access control security policy of the EDR in real time, and if the assessment passes, dynamically authorize the EDR so that the EDR can further establish a communication connection with the gateway. Fine-grained permission control of the EDR is achieved through the zero-trust server, effectively avoiding outdated and excessive permissions of the EDR terminal.
[0072] In the first two-way identity authentication process, the cryptographic algorithm used is a certificateless cryptographic algorithm. The certificateless cryptographic algorithm in this embodiment is a certificateless and implicit certificate public key cryptographic algorithm based on the elliptic curve public key cryptographic algorithm, also known as a certificateless and implicit certificate public key cryptographic algorithm based on the SM2 algorithm. This algorithm solves the problems of complex certificate management and low communication efficiency based on digital certificate authentication. The digital signature generation algorithm and digital signature verification algorithm in this algorithm can realize two-way identity authentication between EDR and zero trust server, thereby improving the identity authentication rate.
[0073] Step 104: In response to the first two-way identity authentication being successful, a certificateless cryptographic algorithm is used to perform a second two-way identity authentication with the gateway.
[0074] Specifically, when the first two-way identity authentication is passed, the EDR identity is preliminarily confirmed to be legitimate. The zero-trust server will assign an accessible gateway port to the EDR, and the EDR can establish a communication connection with the gateway through the gateway port, realizing authentication before connection to ensure that the EDR and the gateway establish a secure communication connection. The EDR transmits data between the gateway and the gateway through the gateway port, and performs a second two-way identity authentication with the gateway based on the sent data transmission request. Through the second two-way identity authentication, the EDR and the gateway can confirm whether each other's identities are legitimate. In the second two-way identity authentication process, the certificateless cryptographic algorithm used is also a certificateless and implicit certificate public key cryptographic algorithm based on the elliptic curve public key cryptography algorithm, which will not be repeated here.
[0075] Step 106: In response to the second two-way identity authentication being passed, data is transmitted with the business server based on the business data transmission port allocated by the gateway.
[0076] Specifically, after the second two-way identity authentication is passed, the legitimacy of the EDR identity is further confirmed, and the gateway will allocate a business data transmission port for the EDR. The EDR can establish a communication connection with the business server through the business data transmission port allocated by the gateway, and access the business server application through the allocated application address, and realize data transmission with the business server. It realizes authentication before connection with the business server, ensuring the establishment of a secure communication connection with the business server, which can effectively prevent the EDR connection without identity authentication from accessing the business server application, and effectively avoid the access of illegal terminals or malicious attacks. The business server can perform detailed vehicle-side emergency data analysis based on the data uploaded by the EDR, objectively restore the truth of the vehicle-side accident, and provide basic analysis data for the determination of accident responsibility. The EDR can also read or download relevant information from the business server to meet the EDR's data storage needs.
[0077] Based on steps 102 to 106 above, this embodiment provides a method for secure data transmission, applicable to an automobile event data recording system, comprising: performing a first bidirectional identity authentication with a zero-trust server using a certificateless cryptographic algorithm. Through the first bidirectional identity authentication, the zero-trust server and the automobile event data recording system can ensure the legitimacy of each other's identities. In response to the success of the first bidirectional identity authentication, the automobile event data recording system can establish a connection with the gateway, implementing an authentication-before-connection process with the gateway, thereby ensuring the security of the communication connection with the gateway. Thereafter, the automobile event data recording system and the gateway perform a second bidirectional identity authentication, also using a certificateless cryptographic algorithm. Through the second bidirectional identity authentication, the gateway and the automobile event data recording system can ensure the legitimacy of each other's identities. In response to the success of the second bidirectional identity authentication, the automobile event data recording system establishes a connection with the business server, implementing an authentication-before-connection process with the business server, thereby ensuring the security of the communication connection with the business server. Data can then be transmitted with the business server using the service data transmission port allocated by the gateway. Only after two rounds of bidirectional identity authentication are passed can the vehicle event data recording system and the business server transmit data. This prevents unauthorized terminals from directly accessing the business server to steal data or launching malicious attacks on the business server, posing a data security threat, and improves the security of data access and transmission in the Internet of Vehicles. The certificateless cryptographic algorithm is a lightweight cryptographic algorithm that eliminates digital certificates, enabling the issuance of public and private keys independent of digital certificates, resulting in a faster generation rate of public and private keys. Furthermore, the removal of digital certificates reduces the communication resource usage of digital certificates during transmission and reduces the computing power required during digital signature verification, effectively improving the authentication rate during data transmission between the vehicle event data recording system and the business server, while reducing communication resource consumption.
[0078] The following describes the first two-way identity authentication process through a specific embodiment.
[0079] In some embodiments, referring to FIG3 , a certificateless cryptographic algorithm is used to perform a first two-way identity authentication with a zero-trust server, including:
[0080] Step 202: Generate authentication request information;
[0081] Step 204: Based on the authentication request information, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate a first digital signature.
[0082] Step 206: Send the authentication request information and the first digital signature to the zero-trust server, so that the zero-trust server verifies the first digital signature;
[0083] Step 208: Receive authentication request feedback information and a second digital signature sent by the zero-trust server after verifying the first digital signature;
[0084] Step 210: Use a digital signature verification algorithm in a certificateless cryptographic algorithm to verify the second digital signature to complete the first two-way identity authentication.
[0085] Specifically, the authentication request information may include an EDR identifier, or include an EDR identifier and the requested data information. The EDR identifier is the unique identity identifier of the EDR. The requested data information is the data information that the EDR needs to access or transmit with the business service end. Based on the authentication request information, a digital signature generation algorithm is used to generate a first digital signature, including: based on elliptic curve system parameters, random numbers, authentication request information and / or the EDR's private key, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate the first digital signature.
[0086] The elliptic curve system parameters are parameters of the elliptic curve cryptosystem, which uses the SM2 elliptic curve public key cryptography algorithm, a type of national secret algorithm. The random number is a random number generated by the EDR. The EDR private key is the EDR identification private key pre-generated using the key generation method.
[0087] It should be noted that in this application, the system that provides cryptographic services for the certificateless cryptographic algorithm is the ECS cryptographic service end, which is responsible for ECS master key management and provides corresponding cryptographic computing power support. The key generation method provided in this embodiment is also a key generation method under the ECS mechanism. The ECS (Elastic Certificateless Service) mechanism is a certificateless or implicit certificate public key cryptographic mechanism based on the national secret SM2 algorithm, which solves the problems of complex certificate management and low communication efficiency based on digital certificate authentication. The public key under the ECS mechanism does not need to verify the signature of the certificate itself, and can also reduce 1 / 3 of the cryptographic operations when verifying the signature at the Internet of Vehicles terminal. The cryptographic service system can be divided into a certificateless system and an implicit certificate system. There are differences between the certificateless system and the implicit certificate system in generating digital signatures, which are explained separately through specific embodiments below.
[0088] Furthermore, when the cryptographic service system is a certificateless system, when generating the first digital signature, it is necessary to sequentially calculate the hash value and the public key component, and then combine the elliptic curve system parameters, the authentication request information and the EDR's private key to generate the digital signature using the digital signature generation algorithm. Step 204 specifically includes:
[0089] Based on the EDR identifier, elliptic curve system parameters and the master public key of the cryptographic server, the hash value H is calculated. A , hash value H A The calculation method is expressed by the following formula: A =H 256 (ENTL A ‖d′ A ‖a‖b‖X G ‖Y G ‖X Pub ‖Y Pub )
[0090] Among them, H 256 () indicates a cryptographic hash algorithm with a message digest length of 256 bits, ENTL A is represented by the integer entlen A The converted two bytes, entlen A is the bit length of the EDR identifier. a‖b represents the concatenation of a and b. The data types of a and b can be bit strings or character strings. a、b、X G 、Y G is the elliptic curve system parameter, a and b are the elliptic curve equation parameters, (X G , Y G ) is the coordinate of G, which represents a base point of the elliptic curve in the elliptic curve public key cryptography algorithm. (X Pub , Y Pub ) is P PubThe coordinates of P Pub The master public key of the password server. G 、Y G 、X Pub 、Y Pub The data type is bit string.
[0091] The first public key component of the automobile event data recording system is generated based on the elliptic curve system parameter and the random number, including: calculating the product of the elliptic curve system parameter and the random number, summing the product and the multiple of the elliptic curve system parameter to obtain the first public key component w of the automobile event data recording system. A : w A =[w]G+U A
[0092] Among them, U A is the second public key component, U A =[d′ A ]G. [d′ A ]G represents the d′ of point G on the elliptic curve A Double point, that is, [d′ A ]G=G+G+...+G, the number of G on the right side of the equation is d′ A , d′ A is a positive integer. A The random number generated by EDR, d′ A ∈[1,n-1]. [w]G represents the w-fold point G on the elliptic curve, that is, [w]G = G + G + ... + G. The number of Gs on the right side of the equation is w, where w is a positive integer. w is a random number generated by the cryptographic service system, w∈[1,n-1]. G represents a base point of the elliptic curve, whose order is a prime number, and n represents the order of the base point G.
[0093] Based on elliptic curve system parameters and hash value H A , the first public key component, the authentication request information and the EDR's private key, and the digital signature generation algorithm in the certificateless cryptographic algorithm are used to generate the first digital signature (r1, s1).
[0094] Among them, SIGN() represents the digital signature algorithm, param represents the elliptic curve system parameters, and w A The coordinates of M1 represent the authentication request information, O represents a special point on the elliptic curve, called the infinity point or zero point, which is the identity element of the elliptic curve additive group, d A Indicates the EDR private key.
[0095] Furthermore, when the cryptographic service system is an implicit certificate system, the method for generating the first digital signature includes:
[0096] Based on the elliptic curve system parameters, the implicit certificate of the vehicle event data recording system, the authentication request information and the EDR private key, the digital signature generation algorithm in the certificateless cryptographic algorithm is used to generate the first digital signature (r1, s1). The generation method of the first digital signature (r1, s1) is expressed by the following formula: (r1, s1) = SIGN (param, ZE, ICA1 ‖ M1, O, d A )
[0097] Where SIGN() represents the digital signature algorithm, param represents the elliptic curve system parameters, ZE represents an empty string, ICA1 represents the EDR implicit certificate, and ICA1 includes at least the EDR identifier and the first public key component w A , M1 represents authentication request information.
[0098] After generating the first digital signature, the EDR sends the first digital signature and authentication request information to the zero-trust server, and the zero-trust server uses a digital signature verification algorithm to verify the first digital signature. If the verification passes, authentication request feedback information is generated. The authentication request feedback information includes at least the authentication token, security access policy, and assigned gateway port identifier generated by the zero-trust server. Based on the authentication request feedback information, the zero-trust server uses a digital signature generation algorithm to generate a second digital signature. After EDR receives the authentication request feedback information and the second digital signature sent by the zero-trust server, it verifies the second digital signature. After the verification passes, the first two-way identity authentication passes, and both EDR and the zero-trust server have legal identities and can communicate securely.
[0099] Step 210 specifically includes:
[0100] The public key of the zero trust server is calculated based on the identifier of the zero trust server, the elliptic curve system parameters and the random number; based on the identifier of the zero trust server, the elliptic curve system parameters, the random number, the authentication request feedback information and / or the public key of the zero trust server, the digital signature verification algorithm in the certificateless cryptographic algorithm is used to verify the second digital signature.
[0101] Corresponding to the digital signature algorithm in the aforementioned certificateless cryptographic algorithm, the digital signature verification algorithm in the certificateless system and the implicit certificate system is also different, which will be explained separately through specific embodiments below.
[0102] Furthermore, when the cryptographic service system is a certificateless system, the method for verifying the second digital signature includes:
[0103] Based on the zero-trust server's identity, elliptic curve system parameters, and the master public key of the cryptographic server, the hash value H is calculated. B .
[0104] Specifically, the zero trust server identifier is the unique identifier of the zero trust server, and the elliptic curve system parameters are the parameters of the elliptic curve cryptographic system. The elliptic curve cryptographic system is a system that applies the SM2 elliptic curve public key cryptographic algorithm, which is a national secret algorithm. B The calculation method is expressed by the following formula: B =H 256 (ENTL B ‖d′ B ‖a‖b‖X G ‖Y G ‖X Pub ‖Y Pub )
[0105] Among them, H 256 () indicates a cryptographic hash algorithm with a message digest length of 256 bits, ENTL B is represented by the integer entlen B The converted two bytes, entlen B The bit length of the zero-trust server identifier. a‖b represents the concatenation of a and b. The data types of a and b can be bit strings or character strings. a、b、X G 、Y G is the elliptic curve system parameter, a and b are the elliptic curve equation parameters, (X G , Y G ) is the coordinate of G, which represents a base point of the elliptic curve in the elliptic curve public key cryptography algorithm. (X Pub , Y Pub ) is P Pub The coordinates of P Pub The master public key of the password server. G 、Y G 、X Pub 、Y Pub The data type of d′ is bit string. B A random number generated for the zero-trust server.
[0106] Based on elliptic curve system parameters and random number d′ B Generate the third public key component w of the server. B =[w]G+U B
[0107] Among them, U B is the fourth public key component, U B =[d′ B ]G. [d′ B ]G represents the d′ of point G on the elliptic curve B Double point, that is, [d′ B]G=G+G+...+G, the number of G on the right side of the equation is d′ B , d′ B is a positive integer. B A random number generated by the server, d′ B ∈[1,n-1]. [w]G represents the w-fold point G on the elliptic curve, that is, [w]G = G + G + ... + G. The number of Gs on the right side of the equation is w, where w is a positive integer. w is a random number generated by the cryptographic server, w∈[1,n-1]. G represents a base point of the elliptic curve, whose order is a prime number, and n represents the order of the base point G.
[0108] Based on elliptic curve system parameters and hash value H B , the third public key component, the authentication request feedback information and the public key of the zero-trust server, and the digital signature verification algorithm in the certificateless cryptographic algorithm is used to verify the second digital signature.
[0109] Specifically, the hash value H is determined through the above steps B After the third public key component, the second digital signature is verified by combining the elliptic curve system parameters, the authentication request feedback information and the public key of the zero-trust server. The second digital signature is verified by the following formula and the verification result is output after verification:
[0110] Among them, VERIFY() represents the digital signature verification algorithm, P B Represents the public key of the zero-trust server, P B =w B +[λ B ]P Pub , and w B The coordinates of (r2, s2) represent the second digital signature, M2 represents the authentication request feedback information, P Pub is the master public key of the cryptographic service system, and mod n represents the modulo-n operation. If the output result is correct, the authentication request feedback information has not been tampered with. If the output result is incorrect, the authentication request feedback information has been tampered with. After the second digital signature is verified, the first two-way identity authentication is successful.
[0111] It should be noted that if the first two-way identity authentication fails, the zero-trust server will discard the authentication request information sent by the EDR according to the principle of "abandoning and not responding". The strategy of discarding and not responding to illegal data packets can effectively reduce malicious attacks using ports and ensure the security of resources such as zero-trust servers, gateways, and business server applications. Through the first two-way identity authentication of this embodiment, the communication security between the EDR and the zero-trust server can be ensured. After confirming that the EDR identity is legitimate, the EDR can further interact with the gateway and the business server to further ensure the security of data interaction. At the same time, during the authentication process, the use of a certificateless cryptographic algorithm can effectively improve the authentication rate, thereby improving the data communication rate between the EDR, gateway, zero-trust server, and business server.
[0112] After the EDR completes the first two-way authentication with the Zero Trust server, the Zero Trust server will allocate a gateway port to the EDR, allowing the EDR to establish a secure communication connection with the gateway through the gateway port and perform a second two-way authentication with the gateway. The following describes the process of the second two-way authentication through a specific embodiment.
[0113] In some embodiments, referring to FIG4 , in response to the first two-way identity authentication being successful, a second two-way identity authentication is performed with the gateway using a certificateless cryptographic algorithm, including the following steps:
[0114] Step 302: In response to the first two-way identity authentication being passed, receive the authentication token, access control security policy, and gateway port identifier sent by the zero-trust server.
[0115] Specifically, after the first two-way identity authentication is passed, the zero-trust server will send an authentication token, access control security policy, and gateway port identifier to the EDR and the gateway. Among them, the authentication token is used by the gateway to authenticate the EDR, and the authentication token can prove the legitimacy of the EDR's identity. The access control security policy includes the data access and transmission permissions granted by the zero-trust server to the EDR, for example, opening read-only permissions or one-time access permissions for the EDR based on the EDR's authentication request information. The gateway port identifier is the unique identity identifier of the gateway port that the EDR can access. The gateway port identifier can be used to determine whether the corresponding gateway port can be accessed.
[0116] Step 304: Establish a communication connection with the gateway by accessing the gateway port corresponding to the gateway port identifier.
[0117] EDR determines the corresponding gateway port based on the gateway port identifier, accesses the gateway port, and establishes a communication connection with the gateway through the gateway port. Since the gateway port is a secure gateway port, EDR and the gateway can establish a secure communication connection and conduct subsequent secure data interaction.
[0118] Step 306: Generate a data transmission request based on the authentication token and access control security policy, and send the data transmission request to the gateway through the gateway port, so that the gateway authenticates the vehicle event data recording system based on the data transmission request and the authentication token received in advance from the zero trust server.
[0119] Specifically, the EDR generates a data transmission request based on the authentication token and access control security policy. The data transmission request may also include information about the data to be transmitted. The data transmission request is sent to the gateway. After the gateway receives the data transmission request, it must first verify the EDR to further determine the legitimacy of the EDR identity. The specific verification method is that the gateway determines whether the authentication token received from the zero-trust server is the same as the authentication token carried in the data transmission request. If they are the same, it means that the EDR identity is legitimate and the EDR is verified by the zero-trust server. If they are different, it means that the EDR identity is illegal and the data transmission request sent by the EDR needs to be discarded without responding to avoid being attacked by illegal attackers.
[0120] Step 308: The receiving gateway sends a third digital signature after the vehicle event data recording system passes identity authentication.
[0121] Once the gateway successfully authenticates the EDR, it returns a third digital signature to the EDR. This third digital signature is generated by the gateway using a digital signature generation algorithm. The EDR can use this third digital signature to verify the gateway's identity.
[0122] Step 310: Use the digital signature verification algorithm in the certificateless cryptographic algorithm to verify the third digital signature to complete the second two-way identity authentication.
[0123] Specifically, after the gateway passes the EDR identity authentication, it sends the third digital signature and the identifier of the business data transmission port to the EDR. The business data transmission port is the port allocated by the gateway to the EDR to access the business server application. The EDR accesses the business server through the business data transmission port. The identifier of the business data transmission port is the unique identity identifier of the business transmission port. The unique business data transmission port can be determined by the identifier of the business data transmission port. The third digital signature is generated by the gateway based on the identifier of the data transmission port using a digital signature generation algorithm. After receiving the third digital signature, the EDR uses a digital signature verification algorithm to verify the third digital signature. After the verification is passed, the second two-way identity authentication is passed. With the help of the gateway, the EDR can access the application of the business server through the business data transmission port, realizing a secure connection method of authentication first and then connection, ensuring the security of data access and transmission.
[0124] The following describes in detail the third digital signature verification method through an embodiment. Step 310 includes:
[0125] The gateway's public key is calculated based on the gateway's identity, elliptic curve system parameters, and random numbers;
[0126] The third digital signature is verified using a digital signature verification algorithm within a certificateless cryptographic algorithm based on the gateway's identifier, elliptic curve system parameters, a random number, the data transmission port identifier, and / or the gateway's public key. Similar to the aforementioned digital signature verification method, verification of the third digital signature also includes two scenarios: a certificateless system and an implicit certificate system.
[0127] Furthermore, when the cryptographic service system is a certificateless system, the method for verifying the third digital signature includes:
[0128] Based on the gateway's identity, elliptic curve system parameters and the master public key of the cryptographic server, the hash value H is calculated. C .
[0129] Specifically, the gateway identifier is the unique identity identifier of the gateway, the elliptic curve system parameters are the parameters of the elliptic curve cryptographic system, and the elliptic curve cryptographic system is a system that applies the SM2 elliptic curve public key cryptographic algorithm, which is a national secret algorithm. C The calculation method is expressed by the following formula: C =H 256 (ENTL C ‖d′ C ‖a‖b‖X G ‖Y G ‖X Pub ‖Y Pub )
[0130] Among them, H 256 () indicates a cryptographic hash algorithm with a message digest length of 256 bits, ENTL C is represented by the integer entlen C The converted two bytes, entlen C The bit length of the gateway identifier. a‖b represents the concatenation of a and b. The data types of a and b can be bit strings or character strings. a、b、X G 、Y G is the elliptic curve system parameter, a and b are the elliptic curve equation parameters, (X G , Y G ) is the coordinate of G, which represents a base point of the elliptic curve in the elliptic curve public key cryptography algorithm. (X Pub , Y Pub ) is P Pub The coordinates of PPub The master public key of the password server. G 、Y G 、X Pub 、Y Pub The data type of d′ is bit string. C A random number generated for the gateway.
[0131] The fifth public key component w of the gateway is generated based on the elliptic curve system parameters and random numbers C .w C =[w]G+U C
[0132] Among them, U C is the sixth public key component, U C =[d′ C ]G. [d′ C ]G represents the d′ of point G on the elliptic curve C Double point, that is, [d′ C ]G=G+G+...+G, the number of G on the right side of the equation is d′ C , d′ C is a positive integer. C A random number generated by the gateway, d′ C ∈[1,n-1]. [w]G represents the w-fold point G on the elliptic curve, that is, [w]G = G + G + … + G. The number of Gs on the right side of the equation is w, where w is a positive integer. w is a random number generated by the cryptographic server, w∈[1,n-1]. G represents a base point of the elliptic curve, whose order is a prime number, and n represents the order of the base point G.
[0133] Based on elliptic curve system parameters and hash value H C , the fifth public key component, the identifier of the data transmission port and the public key of the gateway, and the digital signature verification algorithm in the certificateless cryptographic algorithm is used to verify the third digital signature.
[0134] Specifically, the hash value H is determined through the above steps C After the third digital signature is verified, the third digital signature is verified by combining the elliptic curve system parameters, the identifier of the data transmission port, and the public key of the gateway. The third digital signature is verified by the following formula, and the verification result is output after verification:
[0135] Among them, VERIFY() represents the digital signature verification algorithm, P C Represents the public key of the gateway, P C =w C +[λ C ]P Pub , and wC The coordinates of (r3, s3) represent the third digital signature. M3 represents the identifier of the data transmission port. Pub is the master public key of the cryptographic service system, and mod n represents a modulo-n operation. If the output result is correct, the data transmission port identifier has not been tampered with. If the output result is incorrect, the data transmission port identifier has been tampered with. After the third digital signature is verified, the second two-way identity authentication is successful.
[0136] The second bidirectional identity authentication in this embodiment ensures secure communication between the EDR and the gateway. Once the EDR's identity is confirmed to be legitimate, the EDR can further interact with the business server, further ensuring the security of data interaction. Furthermore, the use of a certificateless cryptographic algorithm during the authentication process can effectively increase the authentication rate, thereby increasing the data communication rate between the EDR, gateway, zero-trust server, and business server.
[0137] Accordingly, the present application also provides a data security transmission method, which is applied to a zero-trust server. Referring to FIG5 , the method includes the following steps:
[0138] Step 402: Use a certificateless cryptographic algorithm to perform a first two-way identity authentication with the automobile event data recording system.
[0139] Specifically, before establishing a communication connection with the business server and transmitting data, the EDR system must perform two-way authentication with both the zero-trust server and the gateway. Once the authentication is confirmed to be legitimate, a communication connection is established with the business server for subsequent data transmission, effectively defending against external attacks on the connected vehicle network. Two-way authentication involves a first authentication between the EDR and the zero-trust server, and a second authentication between the EDR and the gateway. This double authentication improves authentication security.
[0140] EDR establishes a communication connection with the server through the hidden port agreed upon during offline certification registration, opens the hidden port of the server through port knocking technology, realizes data interaction with the server, and performs the first two-way identity authentication with the server. In the first two-way identity authentication process, the cryptographic algorithm used is a certificateless and implicit certificate public key cryptographic algorithm based on the elliptic curve public key cryptography algorithm. The certificateless and implicit certificate public key cryptographic algorithm based on the elliptic curve public key cryptography algorithm is also called the certificateless and implicit certificate public key cryptographic algorithm based on the SM2 algorithm. This algorithm solves the problems of complex certificate management and low communication efficiency based on digital certificate authentication. The digital signature generation algorithm and digital signature verification algorithm in this algorithm can realize two-way identity authentication between EDR and the server, thereby improving the authentication rate.
[0141] Step 404: In response to the first two-way identity authentication being passed, the automobile event data recording system and the gateway perform a second two-way identity authentication. In response to the second two-way identity authentication being passed, the automobile event data recording system performs data transmission with the business service end based on the business data transmission port allocated by the gateway.
[0142] Specifically, when the first two-way identity authentication is passed, the server will assign an accessible gateway port to the EDR. The EDR can establish a secure communication connection with the gateway through the gateway port, transmit data with the gateway, and perform a second two-way identity authentication with the gateway. Through the second two-way identity authentication, the EDR and the gateway can confirm whether each other's identities are legal. After the second two-way identity authentication is passed, the EDR can establish a communication connection with the business server through the business data transmission port assigned by the gateway, and realize data transmission with the business server through the business data transmission port. The business server can perform detailed vehicle-side emergency data analysis based on the data uploaded by the EDR, objectively restore the truth of the vehicle-side accident, and provide basic analysis data for the determination of accident responsibility. The EDR can also read or download relevant information from the business server to meet the EDR's data storage needs.
[0143] Based on steps 402 to 404 above, the data security transmission method provided in this embodiment implements a first bidirectional identity authentication between the EDR and the zero-trust server, and a second bidirectional identity authentication between the EDR and the gateway. After the first bidirectional identity authentication, the EDR establishes a communication connection with the gateway, implementing authentication before connection with the gateway. After the second bidirectional identity authentication, the EDR establishes a communication connection with the business server, implementing authentication before connection with the business server, effectively ensuring data transmission security. Only after both bidirectional identity authentications are passed can the vehicle event data recording system transmit data to the cloud, improving the security of data access and transmission in the Internet of Vehicles. The certificateless cryptographic algorithm used in both identity authentication processes is a lightweight cryptographic algorithm that eliminates digital certificates, enabling the issuance of public and private keys independent of digital certificates, resulting in a faster public and private key generation rate. Furthermore, the elimination of digital certificates reduces the communication resource usage of digital certificates during communication transmission and reduces the computing power required during digital signature verification, thereby effectively improving the authentication rate during data transmission between the vehicle event data recording system and the cloud and reducing communication resource consumption.
[0144] During the first two-way identity authentication process between EDR and the zero-trust server, in order to further confirm the current legitimacy of EDR, it is also necessary to perform a trust evaluation on EDR and recalculate the current trust evaluation value of EDR to achieve dynamic authorization of EDR.
[0145] In some embodiments, before the vehicle event data recording system and the gateway perform the second two-way identity authentication, the process includes:
[0146] Conduct trust assessments on automotive event data recording systems;
[0147] In response to the trust evaluation result satisfying the preset evaluation condition, the vehicle event data recording system and the gateway perform a second two-way identity authentication.
[0148] Specifically, when the zero-trust server performs the first two-way identity authentication with the EDR, the EDR sends an authentication request message to the zero-trust server, and the zero-trust server performs a trust assessment on the EDR based on the authentication request message. The authentication request message may also include the EDR's security attribute information and device attribute information. The zero-trust server performs a new round of trust assessment on the EDR based on the security attribute information and device attribute information. The zero-trust server uses a trust assessment algorithm to dynamically evaluate the EDR's trust value based on the EDR's current security attributes and device attributes, such as device information, device location, device status, and request information, and adjusts the EDR's access control security policy in real time to achieve dynamic authorization of the EDR. The trust assessment algorithm calculates a new trust value. If the new trust value meets the preset assessment conditions, it is combined with the attributes of the business server application that the EDR wants to access to make a final judgment to determine whether the EDR can access the business server application. If access is possible, the access control security policy is determined and sent to the EDR so that the EDR can subsequently perform a second two-way identity authentication with the gateway. If the new trust value fails to meet the preset evaluation criteria, the zero-trust server will fail to authenticate the EDR and will discard the EDR's authentication request information according to the "abandon and do not respond" principle. The method in this embodiment can determine the EDR's current trust value in real time. Only when the real-time trust value meets the preset evaluation criteria can the EDR perform a second two-way authentication with the gateway, further ensuring data communication security.
[0149] Accordingly, the present application also provides a data security transmission method, which is applied to a gateway. Referring to FIG6 , the method includes the following steps:
[0150] Step 502: Use a certificateless cryptographic algorithm to perform a second two-way identity authentication with the automobile event data recording system; wherein, the second two-way identity authentication is performed after the automobile event data recording system and the zero-trust server have successfully performed the first two-way identity authentication.
[0151] Step 504 : In response to the second two-way identity authentication being passed, the automobile event data recording system transmits data to the business service end through the business data transmission port allocated by the gateway.
[0152] Specifically, before establishing a communication connection with the business server and transmitting data, the EDR system must perform two-way authentication with both the zero-trust server and the gateway. Once the authentication is confirmed to be legitimate, a communication connection is established with the business server for subsequent data transmission, effectively defending against external attacks on the connected vehicle network. Two-way authentication involves a first authentication between the EDR and the zero-trust server, and a second authentication between the EDR and the gateway. This double authentication improves authentication security.
[0153] When the first two-way identity authentication is passed, the zero-trust server will assign an accessible gateway port to the EDR. The EDR can establish a communication connection with the gateway through the gateway port and perform a second two-way identity authentication with the gateway. After passing the second two-way identity authentication, the EDR and the gateway can confirm whether each other's identities are legal. In the second two-way identity authentication process, the cryptographic algorithm used is also a certificateless cryptographic algorithm. The certificateless cryptographic algorithm is a certificateless and implicit certificate public key cryptographic algorithm based on the elliptic curve public key cryptography algorithm, also known as a certificateless and implicit certificate public key cryptographic algorithm based on the SM2 algorithm. This algorithm solves the problems of complex certificate management and low communication efficiency based on digital certificate authentication. The digital signature generation algorithm and digital signature verification algorithm in this algorithm can achieve two-way identity authentication between the EDR and the server, thereby improving the authentication rate.
[0154] After passing the second two-way identity authentication, the EDR establishes a communication connection with the business server through the business data transmission port assigned by the gateway, and transmits data to the business server through this business data transmission port. The business server can perform detailed vehicle-side emergency data analysis based on the data uploaded by the EDR, objectively reconstructing the true nature of the vehicle-side accident and providing basic analytical data for determining accident responsibility. The EDR can also read or download relevant information from the cloud to meet the EDR's data storage needs.
[0155] Based on the above steps 502 to 504, the data security transmission method provided by this embodiment implements a first two-way identity authentication between the EDR and the zero-trust server and a second two-way identity authentication between the EDR and the gateway. After the first two-way identity authentication, the EDR establishes a communication connection with the gateway, implementing authentication before connection with the gateway. After the second two-way identity authentication, the EDR establishes a communication connection with the business server, implementing authentication before connection with the business server, effectively ensuring the security of data transmission. After two two-way identity authentications are passed, the vehicle event data recording system can transmit data with the business server, improving the security of data access and transmission in the Internet of Vehicles. Among them, the certificateless cryptographic algorithm is a lightweight cryptographic algorithm that eliminates digital certificates, implements the issuance of public and private keys without relying on digital certificates, and has a faster public and private key generation rate. At the same time, the removal of digital certificates reduces the occupation of communication resources by digital certificates during communication transmission and reduces the computing power required during digital signature verification, thereby effectively improving the authentication rate during data transmission between the vehicle event data recording system and the cloud, and reducing communication resource consumption.
[0156] In some embodiments, before performing the second two-way identity authentication with the vehicle event data recording system, the process includes:
[0157] Receive a gateway port identifier; wherein the gateway port identifier is sent by the zero trust server after the vehicle event data recording system and the zero trust server have passed the first two-way identity authentication;
[0158] Open the corresponding gateway port according to the gateway port identifier;
[0159] Receive a data transmission request sent by the vehicle event data recording system from the gateway port.
[0160] Specifically, after the first two-way authentication is successful, the Zero Trust server assigns a target gateway port to the EDR. Simultaneously, the server sends the identifier of the assigned gateway port to the gateway, which then opens the target gateway port based on the identifier, waits for the EDR to send a data transfer request, and then receives the data transfer request from the gateway port. The EDR and gateway are connected via a dedicated gateway port, effectively mitigating malicious attacks exploiting the port and ensuring gateway resource security.
[0161] Furthermore, for the sake of data access security, the duration for which the gateway opens the gateway port is set within a preset duration. If the gateway does not receive a data transmission request from the gateway port within the preset duration, the gateway port will be closed to protect the gateway port from malicious attacks and prevent illegal EDR access.
[0162] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied in a distributed scenario and performed by multiple devices working together. In such a distributed scenario, one of the multiple devices may only perform one or more steps of the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the method.
[0163] It should be noted that the above description is limited to some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0164] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a data security transmission device.
[0165] Referring to FIG7 , a data security transmission device, applied to an automobile event data recording system, includes:
[0166] The first authentication module 1002 is configured to perform a first two-way identity authentication with the zero-trust server using a certificateless cryptographic algorithm;
[0167] The second authentication module 1004 is configured to perform a second two-way authentication with the gateway using a certificateless cryptographic algorithm in response to the first two-way authentication being successful;
[0168] The data transmission module 1006 is configured to transmit data with the business server based on the business data transmission port allocated by the gateway in response to the second two-way identity authentication being passed.
[0169] In some embodiments, the first authentication module 1002 is further configured to generate authentication request information;
[0170] Based on the authentication request information, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate a first digital signature;
[0171] Sending the authentication request information and the first digital signature to the zero trust server, so that the zero trust server verifies the first digital signature;
[0172] Receive authentication request feedback information and a second digital signature sent by the zero-trust server after verifying the first digital signature;
[0173] The second digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm to complete the first two-way identity authentication.
[0174] In some embodiments, the first authentication module 1002 is further configured to generate a first digital signature based on elliptic curve system parameters, random numbers, authentication request information and / or the private key of the vehicle event data recording system using a digital signature generation algorithm in a certificateless cryptographic algorithm.
[0175] In some embodiments, the first authentication module 1002 is also configured to obtain the public key of the zero trust server based on the identifier of the zero trust server, the elliptic curve system parameters and the random number calculation; based on the identifier of the zero trust server, the elliptic curve system parameters, the random number, the authentication request feedback information and / or the public key of the zero trust server, the digital signature verification algorithm in the certificateless cryptographic algorithm is used to verify the second digital signature.
[0176] In some embodiments, the second authentication module 1004 is further configured to receive an authentication token, an access control security policy, and a gateway port identifier sent by the zero-trust server in response to the first two-way identity authentication being passed;
[0177] Establish a communication connection with the gateway by accessing the gateway port corresponding to the gateway port identifier;
[0178] Generate a data transmission request based on the authentication token and the access control security policy, and send the data transmission request to the gateway through the gateway port, so that the gateway authenticates the vehicle event data recording system based on the data transmission request and the authentication token received in advance from the zero trust server;
[0179] The receiving gateway sends a third digital signature after passing the identity authentication of the vehicle event data recording system;
[0180] The third digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm to complete the second two-way identity authentication.
[0181] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a data security transmission device.
[0182] Referring to FIG8 , a data security transmission device, applied to a zero-trust server, includes:
[0183] The third authentication module 1102 is configured to perform a first two-way identity authentication with the vehicle event data recording system using a certificateless cryptographic algorithm;
[0184] In response to the first two-way identity authentication being passed, the automobile event data recording system and the gateway perform a second two-way identity authentication. In response to the second two-way identity authentication being passed, the automobile event data recording system performs data transmission with the business service end based on the business data transmission port allocated by the gateway.
[0185] In some embodiments, before the automobile event data recording system and the gateway perform a second two-way identity authentication, the third authentication module 1102 is configured to perform a trust assessment on the automobile event data recording system; in response to the result of the trust assessment meeting the preset assessment conditions, the automobile event data recording system and the gateway perform a second two-way identity authentication.
[0186] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a data security transmission device.
[0187] Referring to FIG9 , a data security transmission device, applied to a gateway, includes:
[0188] The fourth authentication module 1202 is configured to use a certificateless cryptographic algorithm to perform a second two-way identity authentication with the vehicle event data recording system; wherein the second two-way identity authentication is performed after the vehicle event data recording system and the zero-trust server have successfully performed the first two-way identity authentication;
[0189] In response to the second two-way identity authentication being passed, the automobile event data recording system transmits data with the business service end through the business data transmission port allocated by the gateway.
[0190] In some embodiments, before performing the second two-way identity authentication with the automobile event data recording system, the fourth authentication module is also configured to receive a gateway port identifier; wherein the gateway port identifier is sent by the zero trust server after the automobile event data recording system and the zero trust server pass the first two-way identity authentication; open the corresponding gateway port according to the gateway port identifier; and receive a data transmission request sent by the automobile event data recording system from the gateway port.
[0191] In some embodiments, the fourth authentication module is further configured to close the gateway port in response to not receiving a data transmission request from the gateway port within a preset time period.
[0192] For the convenience of description, the above devices are described as being divided into various modules according to their functions. Of course, when implementing this application, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0193] The apparatus of the above embodiment is used to implement the corresponding data security transmission method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.
[0194] Based on the same technical concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, the data security transmission method described in any of the above embodiments is implemented.
[0195] FIG10 shows a more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other within the device via the bus 1050.
[0196] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0197] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 1020 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0198] The input / output interface 1030 is used to connect input / output modules to implement information input and output. The input / output modules can be configured as components within the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.
[0199] The communication interface 1040 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).
[0200] The bus 1050 comprises a path for transmitting information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).
[0201] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in a specific implementation, the device may also include other components necessary for normal operation. In addition, it will be understood by those skilled in the art that the above device may only include the components necessary to implement the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0202] The electronic device of the above embodiment is used to implement the corresponding data security transmission method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0203] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute the data security transmission method described in any of the above embodiments.
[0204] The computer-readable media of this embodiment include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0205] The computer instructions stored in the storage medium of the above embodiment are used to enable a computer to execute the data security transmission method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0206] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. Within the scope of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.
[0207] In addition, for simplicity of description and discussion, and in order not to make the embodiment of the application difficult to understand, the known power supply / ground connection with integrated circuit (IC) chip and other components may or may not be shown in the accompanying drawings provided. In addition, the device can be shown in the form of a block diagram to avoid making the embodiment of the application difficult to understand, and this also takes into account the following fact, that is, the details of the embodiment of these block diagram devices are highly dependent on the platform to be implemented in the embodiment of the application (that is, these details should be fully within the scope of understanding of those skilled in the art). When specific details (for example, circuit) are set forth to describe exemplary embodiments of the application, it will be apparent to those skilled in the art that the embodiment of the application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.
[0208] Although the present invention has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may utilize the embodiments discussed.
[0209] The embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of this application.
Claims
1. A data security transmission method, characterized in that: Applied to an automobile event data recording system, the method comprises: Use certificateless cryptographic algorithm to perform first two-way identity authentication with zero-trust server; In response to the first two-way identity authentication being passed, performing a second two-way identity authentication with the gateway using a certificateless cryptographic algorithm; In response to the second two-way identity authentication being passed, data is transmitted with the business server based on the business data transmission port allocated by the gateway.
2. The method according to claim 1, characterized in that The certificateless cryptographic algorithm is used to perform a first two-way identity authentication with the zero-trust server, including: Generate authentication request information; Based on the authentication request information, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate a first digital signature; Sending the authentication request information and the first digital signature to the zero trust server so that the zero trust server verifies the first digital signature; Receive authentication request feedback information and a second digital signature sent by the zero-trust server after verifying the first digital signature; The second digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm to complete the first two-way identity authentication.
3. The method according to claim 2, characterized in that The step of generating a first digital signature based on the authentication request information and using a digital signature generation algorithm in a certificateless cryptographic algorithm comprises: Based on elliptic curve system parameters, random numbers, the authentication request information and / or the private key of the automobile event data recording system, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate the first digital signature.
4. The method according to claim 2, characterized in that: The adopting of a digital signature verification algorithm in a certificateless cryptographic algorithm to verify the second digital signature includes: The public key of the zero trust server is calculated based on the identifier of the zero trust server, the elliptic curve system parameters and the random number; based on the identifier of the zero trust server, the elliptic curve system parameters, the random number, the authentication request feedback information and / or the public key of the zero trust server, the digital signature verification algorithm in the certificateless cryptographic algorithm is used to verify the second digital signature.
5. The method according to claim 1, characterized in that In response to the first two-way identity authentication being passed, performing a second two-way identity authentication with the gateway using a certificateless cryptographic algorithm, including: In response to the first two-way identity authentication being passed, receiving an authentication token, an access control security policy, and a gateway port identifier sent by the zero-trust server; Establishing a communication connection with the gateway by accessing the gateway port corresponding to the gateway port identifier; generating a data transmission request according to the authentication token and the access control security policy, and sending the data transmission request to the gateway through the gateway port, so that the gateway authenticates the vehicle event data recording system based on the data transmission request and the authentication token received in advance from the zero-trust service end; receiving a third digital signature sent by the gateway after the gateway authenticates the automobile event data recording system; The third digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm to complete the second two-way identity authentication.
6. A data security transmission method, characterized in that: Applied to a zero-trust server, the method includes: Using certificateless cryptographic algorithm, the first two-way identity authentication is performed with the vehicle event data recording system; In response to the first two-way identity authentication being passed, the automobile event data recording system and the gateway perform a second two-way identity authentication. In response to the second two-way identity authentication being passed, the automobile event data recording system performs data transmission with the business service end based on the business data transmission port allocated by the gateway.
7. The method according to claim 6, characterized in that Before the automobile event data recording system performs a second two-way identity authentication with the gateway, the following steps are included: Performing a trust assessment on the automobile event data recording system; In response to the result of the trust evaluation satisfying a preset evaluation condition, the automobile event data recording system and the gateway perform a second two-way identity authentication.
8. A data security transmission method, characterized in that: Applied to a gateway, the method comprises: Using a certificateless cryptographic algorithm, a second two-way identity authentication is performed with the automobile event data recording system; wherein the second two-way identity authentication is performed after the automobile event data recording system and the zero-trust server pass the first two-way identity authentication; In response to the second two-way identity authentication being passed, the automobile event data recording system transmits data with the business service end through the business data transmission port allocated by the gateway.
9. The method according to claim 8, characterized in that Before the second two-way authentication with the vehicle event data recording system, including: Receive a gateway port identifier; wherein the gateway port identifier is sent by the zero-trust server after the automobile event data recording system and the zero-trust server pass a first two-way identity authentication; Open the corresponding gateway port according to the gateway port identifier; A data transmission request sent by the vehicle event data recording system is received from the gateway port.
10. The method according to claim 9, characterized in that Also includes: In response to not receiving the data transmission request from the gateway port within a preset time period, closing the gateway port.
11. A data security transmission device, characterized in that: Applied to an automobile event data recording system, the device comprises: a processor, wherein the processor is used to execute the following program modules stored in a memory: A first authentication module is configured to use a certificateless cryptographic algorithm to perform a first two-way identity authentication with a zero-trust server; A second authentication module is configured to perform a second two-way authentication with the gateway using a certificateless cryptographic algorithm in response to the first two-way authentication being passed; The data transmission module is configured to transmit data with the business server based on the business data transmission port allocated by the gateway in response to the passing of the second two-way identity authentication.
12. A data security transmission method, characterized in that: Applied to a zero-trust server, the device includes: a processor, wherein the processor is used to execute the following program modules stored in a memory: The third authentication module is configured to use a certificateless cryptographic algorithm to perform a first two-way authentication with the vehicle event data recording system; in response to the first two-way authentication being passed, the vehicle event data recording system performs a second two-way authentication with the gateway; in response to the second two-way authentication being passed, the vehicle event data recording system performs data transmission with the business service end based on the business data transmission port allocated by the gateway.
13. A data security transmission method, characterized in that: Applied to a gateway, the device comprises: a processor, wherein the processor is used to execute the following program modules stored in a memory: The fourth authentication module is configured to use a certificateless cryptographic algorithm to perform a second two-way identity authentication with the automobile event data recording system; wherein, the second two-way identity authentication is performed after the automobile event data recording system and the zero-trust server have passed the first two-way identity authentication; in response to the second two-way identity authentication being passed, the automobile event data recording system transmits data with the business server through the business data transmission port allocated by the gateway.
14. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 5 is implemented.
15. A vehicle, characterized in that: The vehicle includes the electronic device as claimed in claim 14.
Citation Information
Patent Citations
Vehicle networking authentication method facing vehicle differentiation
CN105792207A
Access control method and system based on zero-trust gateway
CN115913679A
Data secure transmission method, electronic equipment and vehicle
CN117768177A
Certificate token for providing a digital certificate of a user
WO2016116394A1
Cited By
Zero-trust service access method and device, equipment and storage medium
CN121547271A
Certificate-based SOCKS5 bidirectional authentication method, apparatus and device
CN122179243A
Police vehicle end electronic data evidence obtaining method and system and computer equipment
CN122293415A