Data security verification method, related device and vehicle
By using the certificate-free password algorithm to sign and verify the EDR data in the automotive event data recording system, the problem of poor security in the data reading process is solved, the legality and integrity verification of the data is realized, and the data reading rate and security are improved.
Patent Information
- Application Number
- PCT/CN2024/136887
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-21
- Filing Date
- 2024-12-04
- Publication Date
- 2025-06-26
AI Technical Summary
The prior art has security threats when reading data from the Automobile Event Data Recording System (EDR) and cannot determine the legality of the data, resulting in the data being illegally read, tampered with or deleted.
The certificate-free password algorithm is used to sign the stored data using the private key of the car event data recording system, generate a digital signature, and verify it during the data transmission process to ensure the integrity of the data and identity legality.
Through digital signature verification, we ensure the security of EDR data during the reading process, avoid illegal tampering or deletion of data, improve the data reading rate, and improve the credibility and integrity of EDR data.
Smart Images

Figure CN2024136887_26062025_PF_FP_ABST
Abstract
Description
Data security verification method, related equipment and vehicle
[0001] This application claims priority to patent application number 2023117750945 filed with the China Patent Office on December 21, 2023, entitled “Data Security Verification Method, Related Equipment and Vehicle,” the entire contents of which are incorporated herein by reference. Technical Field
[0002] The present application relates to the field of vehicle data security technology, and in particular to a data security verification method, related equipment, and a vehicle. Background Art
[0003] Currently, newly manufactured passenger vehicles are required to be equipped with an Event Data Recorder (EDR) system to meet safety requirements. EDRs can record a vehicle's operating parameters and safety status information during the pre-crash, collision, and post-crash phases. These parameters and safety status information are read in real time via the vehicle's CAN / LIN bus. Currently, security threats still exist when reading EDR data, as the data reader cannot determine whether the EDR data is legitimate. Therefore, a method for effective authentication during the EDR data reading process is urgently needed to prevent EDR data from being illegally read and misused, or illegally tampered with or deleted.
[0004] Technical content
[0005] In view of this, the purpose of this application is to propose a data security verification method, related equipment and vehicle to solve the problem of poor security when reading EDR data.
[0006] Based on the above objectives, the first aspect of the present application provides a data security verification method applied to an automobile event data recording system, the method comprising:
[0007] Using a certificateless cryptographic algorithm, the stored data is signed using a first private key of the automobile event data recording system to generate a first digital signature;
[0008] In response to receiving a data transmission request sent by a receiving end, determining stored data associated with the data transmission request;
[0009] The first digital signature associated with the data transmission request and the stored data are sent to the receiving end, so that the receiving end verifies the received first digital signature based on the stored data.
[0010] Optionally, a certificateless cryptographic algorithm is used to sign the stored data using the first private key of the automobile event data recording system to generate a first digital signature, including:
[0011] Based on the first identifier of the automobile event data recording system, elliptic curve system parameters, random numbers, stored data and / or the first private key, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate a first digital signature.
[0012] Optionally, if the cryptographic service system is a certificateless system, generating a first digital signature using a digital signature generation algorithm in a certificateless cryptographic algorithm based on the first identifier of the vehicle event data recording system, elliptic curve system parameters, random numbers, stored data, and / or the first private key includes:
[0013] Performing a cryptographic hash calculation on a string generated by concatenating the first identifier, the elliptic curve system parameters, and the master public key of the cryptographic server to obtain a first hash value;
[0014] Calculating the product of the elliptic curve system parameter and the random number, and performing a sum operation on the product and a multiple of the elliptic curve system parameter to obtain a first public key component of the automobile event data recording system;
[0015] The stored data is signed using an elliptic curve system parameter, a first hash value, a first public key component, and a first private key, and a digital signature generation algorithm in a certificateless cryptographic algorithm is adopted to generate a first digital signature.
[0016] Optionally, if the cryptographic service system is an implicit certificate system, generating a first digital signature using a digital signature generation algorithm in a certificateless cryptographic algorithm based on the first identifier of the vehicle event data recording system, elliptic curve system parameters, random numbers, stored data, and / or the first private key includes:
[0017] The stored data is signed by using the elliptic curve system parameters, the implicit certificate of the automobile event data recording system and the first private key, and a digital signature generation algorithm in a certificateless cryptographic algorithm is adopted to generate a first digital signature.
[0018] Optionally, calculating a first public key component of the vehicle event data recording system based on elliptic curve system parameters and a random number includes:
[0019] The product of the elliptic curve system parameter and the random number is calculated, and the product and the multiple of the elliptic curve system parameter are summed to obtain a first public key component of the automobile event data recording system.
[0020] Optionally, the data security verification method also includes:
[0021] Recording the vehicle's initial event data;
[0022] Based on the end time of the initial event data, the digital signature generation algorithm in the certificateless public key cryptography algorithm is used to sign the initial event data, generate a timestamp, and use the timestamp and the initial event data as the stored data.
[0023] Optionally, based on the endpoint time of the initial event data, the digital signature generation algorithm in the certificateless public key cryptography algorithm is used to sign the initial event data to generate a timestamp, including:
[0024] Performing hash calculation on the initial event data using a hash algorithm to obtain a first hash value;
[0025] The first hash value and the end time of the initial event data are sent to a timestamp service center, so that the timestamp service center generates a timestamp based on the first hash value and the end time.
[0026] A second aspect of the present application further provides a data security verification method, which is applied to a receiving end. The data security verification method includes:
[0027] Sending a data transmission request to the vehicle event data recording system;
[0028] receiving a first digital signature and stored data returned by the automobile event data recording system according to a data transmission request;
[0029] The first digital signature is verified based on the stored data using a certificateless cryptographic algorithm.
[0030] Optionally, verifying the first digital signature based on the stored data using a certificateless cryptographic algorithm includes:
[0031] Obtaining a first public key of the automobile event data recording system based on a first identifier of the automobile event data recording system, an elliptic curve system parameter, and a random number;
[0032] The first digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm based on the first identifier, elliptic curve system parameters, random numbers, stored data and / or the first public key.
[0033] Optionally, if the cryptographic service system is a certificateless system, a digital signature verification algorithm in a certificateless cryptographic algorithm is used to verify the first digital signature, including:
[0034] Performing a cryptographic hash calculation on a character string generated by concatenating the first identifier, the elliptic curve system parameters, and the master public key of the cryptographic service system to obtain a second hash value;
[0035] Calculating the product of the elliptic curve system parameter and the random number, and performing a sum operation on the product and a multiple of the elliptic curve system parameter to obtain a third public key component of the vehicle event data recording system;
[0036] The first digital signature is verified by using a digital signature verification algorithm in a certificateless cryptographic algorithm using the elliptic curve system parameter, the second hash value, the third public key component, the stored data and the first public key.
[0037] A third aspect of the present application provides a data security verification device, which is applied to an automobile event data recording system. The device includes: a processor, wherein the processor is configured to execute the following program modules stored in a memory:
[0038] a determination module configured to use a certificateless cryptographic algorithm to sign the stored data using a first private key of the automobile event data recording system to generate a first digital signature;
[0039] a signature module configured to, in response to receiving a data transmission request sent by a receiving end, determine stored data associated with the data transmission request;
[0040] The sending module is configured to send the first digital signature associated with the data transmission request and the stored data to the receiving end, so that the receiving end verifies the received first digital signature based on the stored data.
[0041] A fourth aspect of the present application provides a data security verification device, which is applied to an accident data recovery device. The device includes: a processor, wherein the processor is configured to execute the following program modules stored in a memory:
[0042] a request module configured to send a data transmission request to the automobile event data recording system;
[0043] A receiving module configured to receive the first digital signature and stored data returned by the automobile event data recording system according to the data transmission request;
[0044] The verification module is configured to verify the first digital signature based on the stored data using a certificateless cryptographic algorithm.
[0045] The fifth aspect of the present application provides an automobile event data recording system, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the first aspect when executing the program.
[0046] The sixth aspect of the present application provides an accident data recovery device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the second aspect when executing the program.
[0047] The seventh aspect of the present application further provides a vehicle, which includes the automobile event data recording system as described in the fifth aspect.
[0048] As can be seen from the foregoing, the data security verification method, related equipment, and vehicle provided by this application include using a certificateless cryptographic algorithm to sign stored data using the first private key of the automobile event data recording system to generate a first digital signature. The first digital signature can be used to verify the integrity of the stored data. The certificateless cryptographic algorithm used in the process of generating the first digital signature eliminates the calculations associated with the digital certificate, achieving an independent issuance of public and private keys without relying on the digital certificate, and increasing the speed of public and private key generation. Furthermore, the elimination of the digital certificate reduces the communication resource usage of the digital certificate during communication transmission and reduces the computing power required during digital signature verification, thereby effectively improving the computing speed and better matching the data processing capabilities of the automobile event data recording system. In response to receiving a data transmission request sent by a receiving end, the stored data associated with the data transmission request is determined. Specifically, the stored data corresponding to the data transmission request is determined in the automobile event data recording system based on the data transmission request. The first digital signature associated with the data transmission request and the stored data are sent to the receiving end, so that the receiving end verifies the received first digital signature based on the stored data. If the verification is successful, it indicates that the identity of the automobile event data recording system is legitimate and the stored data has not been tampered with, thereby increasing the security of data reading. The data security verification method provided in this application can verify the legitimacy of the identity of the automobile event data recording system, preventing the stored data from being tampered with, and the certificateless cryptographic algorithm used in the data security verification method can also improve the data verification rate, thereby improving the EDR data reading rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in this application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are merely embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0050] FIG1 is a schematic diagram of the interaction between the automobile event data recording system and the receiving end according to an embodiment of the present application;
[0051] FIG2 is a schematic diagram of a flow chart of a data security verification method according to an embodiment of the present application;
[0052] FIG3 is a schematic flow chart of a method for generating a first digital signature according to an embodiment of the present application;
[0053] FIG4 is a flow chart of a data security verification method according to another embodiment of the present application;
[0054] FIG5 is a schematic diagram of a flow chart of a method for verifying a first digital signature according to an embodiment of the present application;
[0055] FIG6 is a schematic structural diagram of a data security verification device according to an embodiment of the present application;
[0056] FIG7 is a schematic structural diagram of a data security verification device according to another embodiment of the present application;
[0057] FIG8 is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0058] In order to make the objectives, technical solutions and advantages of this application more clear, this application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.
[0059] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the usual meanings understood by people with ordinary skills in the field to which this application belongs. The "first", "second" and similar words used in the embodiments of the present application do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0060] EDRs record vehicle driving information. In the event of an emergency, such as speeding or an abrupt stop, EDRs will promptly record this data for a period of time until the emergency is resolved. EDR data can serve as crucial evidence to determine accident liability. While the widespread use of EDRs has greatly facilitated vehicle forensics, EDRs also present data security challenges. Whether it's the automaker, the owner, or a third party, data could be tampered with for their own benefit, rendering the EDR data incapable of objectively reconstructing the true nature of the accident. Therefore, tamper prevention and integrity protection of EDR data are crucial.
[0061] To ensure the security of EDR data, the reader must be authenticated during the reading process. Currently, the PKI-CA systems built by domestic automakers are based on the RSA algorithm (RSA2048), a mainstream encryption standard for cybersecurity. Public and private key certificates generated by the RSA algorithm are used to authenticate the reader. The RSA algorithm is an asymmetric encryption algorithm that generates a pair of RSA keys—a public key and a private key. The public key is provided to the caller to perform public-key encryption and private-key decryption, as well as private-key signature and public-key verification. However, in 2017, RSA1024 was announced to have been cracked (1024 represents 1024 bits for the public and private keys, respectively). Now, cracking methods exist for RSA2048 (2048 represents 2048 bits for the public and private keys, respectively), and theoretically, it has been cracked. This algorithm cracking poses a threat to communication security. In addition to the algorithm being cracked, the RSA algorithm's long encryption length imposes significant overhead on the application side, resulting in slower computation and relatively low efficiency.
[0062] Furthermore, in the RSA algorithm, communication between all parties must be achieved through digital certificates. While this mechanism solves the key management problem, digital certificates, which carry the public key, are relatively large, typically between 2KB and 4KB. This large number of digital certificates complicates management and reduces communication efficiency.
[0063] In view of this, the present application provides a data security verification method to improve the EDR data reading rate while ensuring the safe reading of EDR data. Before implementing the method of the present application, the EDR and the reading end need to meet certain prerequisites. The specific prerequisites include: the EDR internally develops lightweight cryptographic algorithm firmware, has secure remote communication capabilities (for establishing secure communication when exporting data), and the firmware functions cover key generation, key storage, key use, key update, key distribution, key destruction, and public and private key consistency checks when lightweight certificates are issued. The receiving device needs to complete the distribution and storage of keys, secure remote communication, and the verification capability of verifiable event-stamped signatures.
[0064] The embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0065] Figure 1 shows a schematic diagram of the interaction between an automobile event data recording system and a receiving end. As shown in Figure 1, the automobile event data recording system 01 and the receiving end 02 can exchange data. This application provides a data security verification method applied to the automobile event data recording system. Referring to Figure 2, the method includes the following steps:
[0066] Step 102: Use a certificateless cryptographic algorithm and a first private key of the automobile event data recording system to sign the stored data to generate a first digital signature.
[0067] Specifically, when a vehicle emergency occurs, the vehicle event data recording system (EDR) records and stores the emergency as stored data. After the stored data is generated, it must be signed to ensure secure storage. This signature verifies the integrity of the stored data. The digital signature generation algorithm used in this embodiment is a certificateless cryptographic algorithm. This certificateless cryptographic algorithm is a certificateless and implicit certificate public key cryptography algorithm based on elliptic curve public key cryptography, also known as a certificateless and implicit certificate public key cryptography algorithm based on the SM2 algorithm. This algorithm addresses the complex certificate management and low communication efficiency issues associated with digital certificate-based authentication. This embodiment uses a digital signature generation algorithm from a certificateless cryptographic algorithm to sign the stored data using the EDR's first private key, generating a first digital signature. This first digital signature verifies the EDR's legal identity and whether the stored event has been tampered with. If verification fails, indicating that the EDR's identity is unauthorized or the stored data has been tampered with, the stored data is untrustworthy, and communication between the vehicle event data recording system and the receiving end must be terminated. If the verification is successful, it means that the EDR identity is legal and the stored data has not been tampered with, indicating that the stored data is trustworthy data. The receiving end can perform subsequent analysis based on the stored data and generate an analysis report.
[0068] Step 104: In response to receiving the data transmission request sent by the receiving end, determine the stored data associated with the data transmission request.
[0069] Specifically, when the receiving end in this embodiment is a device end capable of reading EDR data, illustratively, the receiving end can be a crash data recovery tool CDR (Crash Data Retrieval). When a user needs to read EDR data, the CDR can be used to read it. The CDR device is inserted into the EDR device through the interface, the connection is maintained at the data link layer, and the EDR data is read. The user can send a data transmission request through the CDR. The data transmission request carries the identifier of the stored event that needs to be read. Based on the identifier of the stored event, the EDR can determine the stored data associated with the data transmission request.
[0070] Step 106: Send the first digital signature associated with the data transmission request and the stored data to the receiving end, so that the receiving end verifies the received first digital signature based on the stored data.
[0071] Specifically, after the vehicle event data recording system generates a first digital signature, it transmits the first digital signature and the stored data to a receiving end. The receiving end receives the stored data and the first digital signature. The receiving end verifies the first digital signature based on the stored data using a digital signature verification algorithm used in certificateless cryptography. If the verification succeeds, indicating that the stored data has not been tampered with, the receiving end can then perform subsequent analysis based on the stored data and generate an analysis report.
[0072] Based on steps 102 to 106 above, the data security verification method provided in this embodiment includes: using a certificateless cryptographic algorithm to sign stored data using the first private key of the vehicle event data recording system to generate a first digital signature. The certificateless cryptographic algorithm used in generating the first digital signature eliminates the computation associated with the digital certificate, ensuring that the issuance of public and private keys is independent of the digital certificate, resulting in a faster generation rate of the public and private keys. Furthermore, eliminating the digital certificate reduces the communication resource usage of the digital certificate during communication transmission and reduces the computing power required during digital signature verification, thereby effectively increasing the computing speed and better matching the data processing capabilities of the vehicle event data recording system. In response to receiving a data transmission request from a receiving end, the stored data associated with the data transmission request is determined. Specifically, the stored data corresponding to the data transmission request is determined in the vehicle event data recording system based on the data transmission request. The first digital signature associated with the data transmission request and the stored data are transmitted to the receiving end, so that the receiving end verifies the received first digital signature based on the stored data. Successful verification indicates that the stored data has not been tampered with and the EDR identity is legitimate. The data security verification method provided in this application can verify the legitimacy of the identity of the automobile event data recording system to prevent the stored data from being tampered with. The certificateless cryptographic algorithm used in the data security verification method can also improve the data verification rate, thereby improving the EDR data reading rate.
[0073] The following describes the method for generating the first digital signature through a specific embodiment.
[0074] In some embodiments, a certificateless cryptographic algorithm is used to sign the stored data using a first private key of the vehicle event data recording system to generate a first digital signature, including:
[0075] Based on the first identifier of the automobile event data recording system, elliptic curve system parameters, random numbers, stored data and / or the first private key, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate a first digital signature.
[0076] It should be noted that the cryptographic service system in this application is the ECS cryptographic service end, which is responsible for ECS master key management and provides corresponding cryptographic computing power support. The cryptographic service system can be divided into a certificateless system and an implicit certificate system. A certificateless system is a public key cryptographic system that does not rely on digital certificates to verify the authenticity of the user's public key and the key generation center does not have a key delegation function. An implicit certificate is a digital certificate that contains information such as user identification and public key restoration data but does not explicitly contain the digital signature of a certificate authority (CA). An implicit certificate system is a public key cryptographic system that relies on implicit certificates. The following will describe the method for generating the first digital signature under the certificateless system and the implicit certificate system respectively.
[0077] Furthermore, when the cryptographic service system is a certificateless system, referring to FIG3 , the method for generating the first digital signature includes the following steps:
[0078] Step 202: Perform cryptographic hash calculation on a character string generated by concatenating the first identifier, the elliptic curve system parameters, and the master public key of the cryptographic server to obtain a first hash value.
[0079] Specifically, the first identifier is a unique identifier of the receiving end, such as a receiving end ID (Identity document) or a uniquely identifiable name. The elliptic curve system parameters are parameters of an elliptic curve cryptographic system. The elliptic curve cryptographic system is a system that applies the SM2 elliptic curve public key cryptographic algorithm, which is a type of national secret algorithm.
[0080] Furthermore, according to the calculation method of the certificateless cryptographic algorithm, when generating the first digital signature, it is necessary to calculate the first hash value and the first public key component in sequence, and then use the digital signature generation algorithm to generate the first digital signature. In this step, the first hash value H A The calculation method can also be expressed by the following formula: A =H 256 (ENTL A ‖d′ A ‖a‖b‖X G ‖Y G ‖X Pub ‖Y Pub )
[0081] Among them, H 256 () indicates a cryptographic hash algorithm with a message digest length of 256 bits, ENTL A is represented by the integer entlen A The converted two bytes, entlen A is the bit length of the first identifier. a‖b represents the concatenation of a and b. The data types of a and b can be bit strings or character strings. a、b、X G 、YG is the elliptic curve system parameter, a and b are the elliptic curve equation parameters, (X G , Y G ) is the coordinate of G, which represents a base point of the elliptic curve in the elliptic curve public key cryptography algorithm. (X Pub , Y Pub ) is P Pub The coordinates of P Pub The master public key of the password server. G 、Y G 、X Pub 、Y Pub The data type is bit string.
[0082] Step 204 : Calculate the product of the elliptic curve system parameter and the random number, and perform a sum operation on the product and a multiple of the elliptic curve system parameter to obtain a first public key component of the automobile event data recording system.
[0083] In this step, the first public key component is calculated based on the elliptic curve system parameters and the random number. The random number is a random number generated by the EDR. A The specific calculation method can be expressed by the following formula: A =[w]G+U A
[0084] Among them, U A is the second public key component, U A =[d′ A ]G. [d′ A ]G represents the d′ of point G on the elliptic curve A Double point, that is, [d′ A ]G=G+G+...+G, the number of G on the right side of the equation is d′ A , d′ A is a positive integer. A The random number generated by EDR, d′ A ∈[1,n-1]. [w]G represents the w-fold point G on the elliptic curve, that is, [w]G = G + G + ... + G. The number of Gs on the right side of the equation is w, where w is a positive integer. w is a random number generated by the cryptographic service system, w∈[1,n-1]. G represents a base point of the elliptic curve, whose order is a prime number, and n represents the order of the base point G.
[0085] Step 206: Use the elliptic curve system parameters, the first hash value, the first public key component, and the first private key, and adopt a digital signature generation algorithm in a certificateless cryptographic algorithm to sign the stored data to generate a first digital signature.
[0086] In this step, after the first hash value and the first public key component are calculated in the above two steps, the stored data is signed to generate a first digital signature. The method for generating the first digital signature (r, s) is represented by the following formula:
[0087] Among them, SIGN() represents the digital signature algorithm, param represents the elliptic curve system parameters, and w A The coordinates of M represent the stored data, O represents a special point on the elliptic curve, called the infinity point or zero point, which is the identity element of the elliptic curve additive group, d A Represents the first private key.
[0088] Furthermore, when the cryptographic service system is an implicit certificate system, the method for generating the first digital signature includes:
[0089] Based on the elliptic curve system parameters, the implicit certificate of the automobile event data recording system, the stored data and the first private key, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to sign the stored data to generate a first digital signature (r, s).
[0090] Specifically, the implicit certificate system and the method for generating the first digital signature in the certificateless system are different. When generating the first digital signature, the implicit certificate system uses the digital signature generation algorithm to sign the stored data based on the elliptic curve system parameters, the implicit certificate of the vehicle event data recording system, the stored data and the first private key. The specific generation method is described by the following formula: (r, s) = SIGN (param, ZE, ICA ‖ M, O, d A )
[0091] Wherein, SIGN() represents the digital signature algorithm, param represents the elliptic curve system parameters, ZE represents the empty string, ICA represents the implicit certificate of EDR, and ICA includes at least the first identifier of EDR and the first public key component w A M represents the stored data, O represents a special point on the elliptic curve, called the infinity point or zero point, which is the identity element of the elliptic curve additive group, d A Represents the first private key. ICA‖M represents the concatenation of the implicit certificate and the stored data string.
[0092] This embodiment provides a method for generating a first digital signature for a certificateless system and an implicit certificate system. This method allows for flexible generation of corresponding first digital signatures for different cryptographic service systems. Using the digital signature generation algorithm in a certificateless cryptographic algorithm significantly improves the computational speed of the digital signature calculation process, requiring less computing power for the EDR, and facilitating faster reading of EDR data.
[0093] When an EDR records an emergency event during vehicle travel, it is necessary to ensure the authenticity and uniqueness of the recorded data. The following describes the EDR data recording method through a specific embodiment.
[0094] In some embodiments, the data security verification method further includes:
[0095] Recording the vehicle's initial event data;
[0096] Based on the end time of the initial event data, the digital signature generation algorithm in the certificateless public key cryptography algorithm is used to sign the initial event data, generate a timestamp, and use the timestamp and the initial event data as the stored data.
[0097] Specifically, when a vehicle encounters an emergency while driving, the EDR begins recording initial data. The start time is the starting time, and the end time is recorded when the event ends. The duration of the event is also recorded. Both the start and end times are taken from an authoritative time source.
[0098] To ensure the authenticity of the initial event data, a digital signature generation algorithm can be used to sign the endpoint of the initial event data and generate a timestamp. The timestamp can be used to prove the actual time when the initial event data occurred, ensuring the authenticity of the initial event data. The timestamp and the initial event data are combined as stored data and sent to the receiving end.
[0099] Preferably, the method for generating the timestamp includes: performing a hash calculation on the initial event data using a hash algorithm to obtain a first hash value;
[0100] Sending the first hash value and the end time of the initial event data to a timestamp service center, so that the timestamp service center generates a timestamp based on the first hash value and the end time;
[0101] The timestamp sent by the timestamp service center is received, and the timestamp and the initial event data are taken as the stored data.
[0102] Specifically, a hash algorithm is used to calculate the initial data to obtain a first hash value. The first hash value and the end time of the initial data are sent to a timestamp service center (TimeStamp Authority, TSA). The timestamp service center binds the initial data and the end time, and signs the first hash value and the end time to generate a timestamp. The timestamp can be used as a credential for the initial data, which can prove that the content of the initial data is complete and has not been changed. Afterwards, the timestamp service center returns the timestamp to the automobile event data recording system. The automobile event data recording system stores the timestamp and the initial data in an undeletable secure path as stored data, and assigns an identifier to the stored data, so that the receiving end can send a data transmission request based on the identifier. Through the method of this embodiment, a timestamp is applied for each initial data, which is convenient for subsequent judgment on whether the stored data has been tampered with, and provides users with a reliable basis for judgment.
[0103] It should be noted that the timestamp server is connected to the authoritative national time service center. Through effective combination with digital signatures, it can provide confidentiality, integrity, non-repudiation and other functions for driving data. The digital signature ensures the non-repudiation of content and issuer, and the timestamp provides accurate, authoritative and tamper-proof time proof and content integrity proof.
[0104] This application also provides a data security verification method, which is applied to a receiving end. Referring to FIG4 , the method includes the following steps:
[0105] Step 302: Send a data transmission request to the automobile event data recording system.
[0106] When there is a need to read data from the EDR, the user sends a data transmission request to the EDR through the receiving end. Exemplarily, the receiving end in this embodiment is a CDR. The data transmission request carries the identifier of the EDR data to be read. The EDR searches for the corresponding stored data in all the stored data based on the identifier of the EDR data. The EDR uses the digital signature generation algorithm in the certificateless cryptographic algorithm to sign the stored data using the first private key of the EDR to generate a first digital signature. The first digital signature is used to verify whether the stored event has been tampered with. If it has been tampered with, it means that the stored data is untrusted data, and the communication between the automobile event data recording system and the receiving end is terminated. If it has not been tampered with, it means that the stored data is trusted data, and the receiving end can perform subsequent analysis based on the stored data and generate an analysis report.
[0107] Step 304: Receive the first digital signature and stored data returned by the automobile event data recording system according to the data transmission request.
[0108] The EDR sends the first digital signature and the stored data to a receiving end, which then receives the first digital signature and the stored data. During the transmission of the first digital signature and the stored data, the stored data may or may not have been tampered with. Upon receiving the stored data, the receiving end determines whether the received stored data is untampered data sent by the legitimate EDR.
[0109] Step 306: Use a certificateless cryptographic algorithm to verify the first digital signature based on the stored data.
[0110] Specifically, the receiving end verifies the first digital signature based on the received stored data using a digital signature verification algorithm within a certificateless cryptographic algorithm. This digital signature verification method verifies the integrity and authenticity of the stored data. Successful verification indicates that the stored data has not been tampered with and remains intact, while also confirming the legitimacy of the EDR identity. Furthermore, certificateless cryptographic algorithms can increase the data verification rate, thereby increasing the EDR data reading rate. The receiving end can then perform subsequent analysis based on the stored data and generate an analysis report.
[0111] The following describes in detail the method for the receiving end to verify the first digital signature through an embodiment.
[0112] In some embodiments, verifying the first digital signature based on stored data using a certificateless cryptographic algorithm includes:
[0113] Step A: Calculate and obtain a first public key of the automobile event data recording system based on a first identifier of the automobile event data recording system, an elliptic curve system parameter, and a random number.
[0114] Specifically, the first identifier is the unique identifier of the EDR, such as the EDR's ID (identity document) or uniquely identifiable name. The elliptic curve system parameters are parameters of the elliptic curve cryptography system, which uses the SM2 elliptic curve public key cryptography algorithm, a type of national secret algorithm. The random number is a random number generated by the receiving end.
[0115] Furthermore, since the EDR uses the first private key to generate the signature when the first digital signature is generated, the receiving end needs to first calculate the first public key and then verify the first digital signature based on the first public key. When calculating the first public key, it is necessary to sequentially calculate the second hash value, the third public key component, the first intermediate number, and finally the first public key. Among them, the second hash value H B The calculation method can be expressed by the following formula: B =H 256 (ENTL A ‖IDA ‖a‖b‖X G ‖Y G ‖X Pub ‖Y Pub )
[0116] Among them, H 256 () indicates a cryptographic hash algorithm with a message digest length of 256 bits, ENTL A is represented by the integer entlen A The converted two bytes, entlen A is the bit length of the first identifier, ID A is the first identifier of EDR. a‖b represents the concatenation of a and b. The data types of a and b can be bit strings or character strings. a、b、X G 、Y G is the elliptic curve system parameter, a and b are the elliptic curve equation parameters, (X G , Y G ) is the coordinate of G, which represents a base point of the elliptic curve in the elliptic curve public key cryptography algorithm. (X Pub , Y Pub ) is P Pub The coordinates of P Pub The master public key of the cryptographic service system. X G 、Y G 、X Pub 、Y Pub The data type is bit string.
[0117] The calculation method of the third public key component can also be expressed as follows: B =[w]G+U B
[0118] Among them, U B is the fourth public key component, U B =[d′ B ]G. [d′ B ]G represents the d′ of point G on the elliptic curve B Double point, that is, [d′ B ]G=G+G+...+G, the number of G on the right side of the equation is d′ B , d′ B is a positive integer. B is the random number generated by the receiving end, d′ B ∈[1,n-1]. [w]G represents the w-fold point G on the elliptic curve, that is, [w]G = G + G + ... + G. The number of Gs on the right side of the equation is w, where w is a positive integer. w is a random number generated by the cryptographic service system, w∈[1,n-1]. G represents a base point of the elliptic curve, whose order is a prime number, and n represents the order of the base point G.
[0119] The calculation method of the first intermediate number includes: calculating the second hash value H B and the third public key component w B The concatenated character strings are cryptographically hashed to obtain a third hash value; and a modulo operation is performed on the third hash value to obtain a first intermediate number.
[0120] The specific calculation method of the third hash value is expressed by the following formula:
[0121] Furthermore, the specific calculation method of the first intermediate number λ′ is expressed by the following formula:
[0122] in, w B 's coordinates.
[0123] After determining the second hash value, the third public key component, and the first intermediate number, the first public key is calculated. The calculation method of the first public key is expressed as: B =w B +[λ′]P Pub , and the first public key of EDR is calculated.
[0124] Step B: Based on the first identifier, elliptic curve system parameters, random numbers, stored data and / or the first public key, a digital signature verification algorithm in a certificateless cryptographic algorithm is used to verify the first digital signature.
[0125] In certificateless and implicit certificate systems, the digital signature generation methods are different, and accordingly, the digital signature verification methods are also different. The following describes the digital signature verification process in certificateless and implicit certificate systems respectively.
[0126] Further, referring to FIG5 , when the cryptographic service system is a certificateless system, the method for verifying the first digital signature includes:
[0127] Step 402: Perform cryptographic hash calculation on the character string generated by concatenating the first identifier, the elliptic curve system parameters, and the master public key of the cryptographic service system to obtain a second hash value.
[0128] Step 404 : Calculate the product of the elliptic curve system parameter and the random number, and perform a sum operation on the product and a multiple of the elliptic curve system parameter to obtain a third public key component of the automobile event data recording system.
[0129] Specifically, when verifying the first digital signature, it is necessary to sequentially calculate the second hash value and the third public key component, and then verify the first digital signature. In steps 402 and 404, the calculation methods for the second hash value and the third public key component are the same as those in step A above and are not further described here.
[0130] Step 406: Verify the first digital signature using a digital signature verification algorithm in a certificateless cryptographic algorithm using the elliptic curve system parameters, the second hash value, the third public key component, the stored data, and the first public key.
[0131] Specifically, after the second hash value and the third public key component are calculated through the aforementioned steps, the first digital signature is verified using the following formula, and the verification result is output after verification:
[0132] Among them, param represents the elliptic curve system parameters, w B The coordinates of P B represents the first public key, and (r,s) represents the first signature. If the output result is correct, it means that the stored data has not been tampered with and the EDR identity is legitimate. If the output result is incorrect, it means that the stored data has been tampered with or the EDR identity is invalid.
[0133] Furthermore, when the cryptographic service system is an implicit certificate system, the method for verifying the first digital signature includes:
[0134] The first digital signature is verified by adopting a digital signature verification algorithm in a certificateless cryptographic algorithm based on elliptic curve system parameters, an implicit certificate of the automobile event data recording system, stored data and a first public key.
[0135] Specifically, in the implicit certificate system, the first digital signature needs to be verified based on the elliptic curve system parameters, the implicit certificate of the vehicle event data recording system, the stored data, and the first public key.
[0136] Furthermore, the following formula is used to describe a method for verifying the first digital signature in the implicit certificate system, and outputs a verification result after verification:
[0137] VERIFY(param,ZE,ICA‖M,P B ,(r,s))
[0138] Where param represents the elliptic curve system parameters, ZE represents an empty string, ICA represents the EDR's implicit certificate, which includes at least the first identifier and the first public key component of the EDR, and P B represents the first public key, and (r, s) represents the first signature.
[0139] If the output result is correct, it means that the stored data has not been tampered with and the EDR identity is legal. If the output result is incorrect, it means that the stored data has been tampered with or the EDR identity is illegal.
[0140] This embodiment provides first digital signature verification methods for both certificateless and implicit certificate systems, allowing for flexible verification of first digital signatures for different cryptographic service systems. Using the digital signature verification algorithm within the certificateless cryptographic algorithm significantly improves the computational speed of the digital signature verification process, requiring less computing power for the EDR, and facilitating faster reading of EDR data.
[0141] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied in a distributed scenario and performed by multiple devices working together. In such a distributed scenario, one of the multiple devices may only perform one or more steps of the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the method.
[0142] It should be noted that the above description is limited to some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0143] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a data security verification device.
[0144] Referring to FIG6 , a data security verification device, applied to an automobile event data recording system, includes:
[0145] The determining module 502 is configured to, in response to receiving a data transmission request sent by the receiving end, determine the stored data associated with the data transmission request;
[0146] The signature module 504 is configured to use a certificateless cryptographic algorithm to sign the stored data using a first private key of the automobile event data recording system to generate a first digital signature;
[0147] The sending module 506 is configured to send the first digital signature and the stored data to the receiving end, so that the receiving end verifies the first digital signature based on the stored data.
[0148] In some embodiments, the signature module 504 is further configured to generate a first digital signature based on the first identifier of the automobile event data recording system, the elliptic curve system parameters, the random number, the stored data and / or the first private key, using a digital signature generation algorithm in the certificateless cryptographic algorithm.
[0149] In some embodiments, if the cryptographic service system is a certificateless system, the signature module 504 is further configured to
[0150] Performing a cryptographic hash calculation on a string generated by concatenating the first identifier, the elliptic curve system parameters, and the master public key of the cryptographic server to obtain a first hash value;
[0151] Calculating the product of the elliptic curve system parameter and the random number, and performing a sum operation on the product and a multiple of the elliptic curve system parameter to obtain a first public key component of the automobile event data recording system;
[0152] The stored data is signed using an elliptic curve system parameter, a first hash value, a first public key component, and a first private key, and a digital signature generation algorithm in a certificateless cryptographic algorithm is adopted to generate a first digital signature.
[0153] In some embodiments, the signature module 504 is further configured to calculate the product of the elliptic curve system parameter and the random number, and sum the product and the multiple of the elliptic curve system parameter to obtain the first public key component of the automobile event data recording system.
[0154] In some embodiments, if the cryptographic service system is an implicit certificate system, the signature module 504 is further configured to use the elliptic curve system parameters, the implicit certificate of the vehicle event data recording system, and the first private key to sign the stored data using a digital signature generation algorithm within a certificateless cryptographic algorithm to generate a first digital signature. In some embodiments, the system further includes a storage module 508 configured to record the initial event data of the vehicle; based on the endpoint time of the initial event data, sign the initial event data using a digital signature generation algorithm within a certificateless public key cryptographic algorithm to generate a timestamp, and store the timestamp and the initial event data as the stored data.
[0155] In some embodiments, the storage module 508 is configured to use a hash algorithm to perform hash calculation on the initial event data to obtain a first hash value; and send the first hash value and the end time of the initial event data to a timestamp service center so that the timestamp service center generates a timestamp based on the first hash value and the end time.
[0156] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a data security verification device.
[0157] Referring to FIG7 , a data security verification device, applied to an accident data recovery device, includes:
[0158] The request module 602 is configured to send a data transmission request to the automobile event data recording system;
[0159] The receiving module 604 is configured to receive the first digital signature and stored data returned by the automobile event data recording system according to the data transmission request;
[0160] The verification module 606 is configured to verify the first digital signature based on the stored data using a certificateless cryptographic algorithm.
[0161] In some embodiments, the verification module 606 is further configured to calculate a first public key of the automobile event data recording system based on the first identifier of the automobile event data recording system, the elliptic curve system parameters, and the random number; and verify the first digital signature using a digital signature verification algorithm in a certificateless cryptographic algorithm based on the first identifier, the elliptic curve system parameters, the random number, the stored data, and / or the first public key. In some embodiments, if the cryptographic service system is a certificateless system, the verification module 606 is further configured to perform a cryptographic hash calculation on a string generated by concatenating the first identifier, the elliptic curve system parameters, and the server's master public key to obtain a second hash value.
[0162] Calculating the product of the elliptic curve system parameter and the random number, performing an operation on the product and a multiple of the elliptic curve system parameter to obtain a third public key component of the vehicle event data recording system;
[0163] The first digital signature is verified by using a digital signature verification algorithm in a certificateless cryptographic algorithm using the elliptic curve system parameter, the second hash value, the third public key component, the stored data and the first public key.
[0164] In some embodiments, if the cryptographic service system is an implicit certificate system, the verification module 606 is also configured to use the elliptic curve system parameters, the implicit certificate of the automobile event data recording system, the stored data and the first public key, and adopt the digital signature verification algorithm in the certificateless cryptographic algorithm to verify the first digital signature.
[0165] For the convenience of description, the above devices are described as being divided into various modules according to their functions. Of course, when implementing this application, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0166] The apparatus of the above embodiment is used to implement the corresponding data security verification method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.
[0167] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides an automobile event data recording system, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, it implements any of the data security verification methods described in the first aspect above.
[0168] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides an accident data recovery device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, it implements the data security transmission method described in the second aspect.
[0169] FIG8 shows a schematic diagram of the hardware structure of a more specific electronic device (automobile event data recording system or accident data recovery device) provided by this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other within the device via the bus 1050.
[0170] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0171] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 1020 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0172] The input / output interface 1030 is used to connect input / output modules to implement information input and output. The input / output modules can be configured as components within the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.
[0173] The communication interface 1040 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).
[0174] The bus 1050 comprises a path for transmitting information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).
[0175] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in a specific implementation, the device may also include other components necessary for normal operation. In addition, it will be understood by those skilled in the art that the above device may only include the components necessary to implement the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0176] The electronic device of the above embodiment is used to implement the corresponding data security verification method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0177] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the data security verification method described in any of the above embodiments.
[0178] The computer-readable media of this embodiment include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0179] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the data security verification method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0180] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. Within the scope of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.
[0181] In addition, for simplicity of description and discussion, and in order not to make the embodiment of the application difficult to understand, the known power supply / ground connection with integrated circuit (IC) chip and other components may or may not be shown in the accompanying drawings provided. In addition, the device can be shown in the form of a block diagram to avoid making the embodiment of the application difficult to understand, and this also takes into account the following fact, that is, the details of the embodiment of these block diagram devices are highly dependent on the platform to be implemented in the embodiment of the application (that is, these details should be fully within the scope of understanding of those skilled in the art). When specific details (for example, circuit) are set forth to describe exemplary embodiments of the application, it will be apparent to those skilled in the art that the embodiment of the application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.
[0182] Although the present invention has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may utilize the embodiments discussed.
[0183] The embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of this application.
Claims
1. A data security verification method, characterized in that: Applied to an automobile event data recording system, the method comprises: Using a certificateless cryptographic algorithm, using a first private key of the automobile event data recording system to sign the stored data to generate a first digital signature; In response to receiving a data transmission request sent by a receiving end, determining stored data associated with the data transmission request; The first digital signature associated with the data transmission request and the stored data are sent to the receiving end, so that the receiving end verifies the received first digital signature based on the stored data.
2. The method according to claim 1, characterized in that The method of using a certificateless cryptographic algorithm to sign the stored data using a first private key of the automobile event data recording system to generate a first digital signature includes: Based on the first identifier of the automobile event data recording system, elliptic curve system parameters, random numbers, the stored data and / or the first private key, a digital signature generation algorithm in a certificateless cryptographic algorithm is used to generate the first digital signature.
3. The method according to claim 2, characterized in that If the cryptographic service system is a certificateless system, the first digital signature is generated by using a digital signature generation algorithm in a certificateless cryptographic algorithm based on the first identifier of the automobile event data recording system, the elliptic curve system parameter, the random number, the stored data and / or the first private key, including: Perform cryptographic hash calculation based on the first identifier, the elliptic curve system parameter, and the master public key of the cryptographic service system to obtain a first hash value; Based on the elliptic curve system parameter and the random number, a first public key component of the automobile event data recording system is calculated; The stored data is signed using the elliptic curve system parameter, the first hash value, the first public key component and the first private key, using a digital signature generation algorithm in a certificateless cryptographic algorithm to generate the first digital signature.
4. The method according to claim 3, characterized in that The step of calculating the first public key component of the automobile event data recording system based on the elliptic curve system parameter and the random number includes: The product of the elliptic curve system parameter and the random number is calculated, and a sum operation is performed on the product and a multiple of the elliptic curve system parameter to obtain a first public key component of the automobile event data recording system.
5. The method according to claim 2, characterized in that: If the cryptographic service system is an implicit certificate system, the first digital signature is generated by using a digital signature generation algorithm in a certificateless cryptographic algorithm based on the first identifier of the automobile event data recording system, the elliptic curve system parameter, the random number, the stored data and / or the first private key, including: The stored data is signed by using the elliptic curve system parameters, the implicit certificate of the automobile event data recording system and the first private key, and a digital signature generation algorithm in a certificateless cryptographic algorithm is adopted to generate the first digital signature.
6. The method according to claim 1, characterized in that The method further comprises: Record the vehicle's initial event data; Based on the end time of the initial event data, the digital signature generation algorithm in the certificateless public key cryptography algorithm is used to sign the initial event data, generate a timestamp, and use the timestamp and the initial event data as the stored data.
7. The method according to claim 6, characterized in that The method of signing the initial event data based on the endpoint time of the initial event data using a digital signature generation algorithm in a certificateless public key cryptographic algorithm to generate a timestamp includes: Performing hash calculation on the initial event data using a hash algorithm to obtain a first hash value; The first Hash value and the end time of the initial event data are sent to a timestamp service center, so that the timestamp service center generates a timestamp based on the first Hash value and the end time.
8. A data security verification method, characterized in that: Applied to the receiving end, the method comprises: Sending a data transmission request to a vehicle event data recording system; receiving a first digital signature and stored data returned by the automobile event data recording system according to the data transmission request; The first digital signature is verified based on the stored data using a certificateless cryptographic algorithm.
9. The method according to claim 8, characterized in that The adopting a certificateless cryptographic algorithm to verify the first digital signature based on the stored data includes: Obtaining a first public key of the automobile event data recording system based on a first identifier of the automobile event data recording system, an elliptic curve system parameter and a random number; Based on the first identifier, the elliptic curve system parameters, the random number, the stored data and / or the first public key, the first digital signature is verified using a digital signature verification algorithm in a certificateless cryptographic algorithm.
10. The method according to claim 9, characterized in that If the cryptographic service system is a certificateless system, the digital signature verification algorithm in the certificateless cryptographic algorithm is used to verify the first digital signature, including: Performing cryptographic hash calculation on a character string generated by concatenating the first identifier, the elliptic curve system parameter, and the master public key of the cryptographic service system to obtain a second hash value; Calculating the product of the elliptic curve system parameter and the random number, performing a sum operation on the product and a multiple of the elliptic curve system parameter to obtain a third public key component of the automobile event data recording system; The first digital signature is verified by using the elliptic curve system parameter, the second hash value, the third public key component, the stored data and the first public key and adopting a digital signature verification algorithm in a certificateless cryptographic algorithm.
11. A data security verification device, characterized in that: Applied to an automobile event data recording system, the device comprises: a processor, wherein the processor is used to execute the following program modules stored in a memory: A determination module is configured to use a certificateless cryptographic algorithm to sign the stored data using a first private key of the automobile event data recording system to generate a first digital signature; a signature module, configured to, in response to receiving a data transmission request sent by a receiving end, determine stored data associated with the data transmission request; The sending module is configured to send the first digital signature associated with the data transmission request and the stored data to the receiving end, so that the receiving end verifies the received first digital signature based on the stored data.
12. A data security verification device, characterized in that: Applied to an accident data recovery device, the device comprises: a processor, wherein the processor is used to execute the following program modules stored in a memory: A request module, configured to send a data transmission request to the automobile event data recording system; A receiving module, configured to receive the first digital signature and stored data returned by the automobile event data recording system according to the data transmission request; The verification module is configured to use a certificateless cryptographic algorithm to verify the first digital signature based on the stored data.
13. An automobile event data recording system, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 5 is implemented.
14. An accident data recovery device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 6 to 7 is implemented.
15. A vehicle, characterized in that: The vehicle includes the automobile event data recording system of claim 8.
Citation Information
Patent Citations
Workshop data storage and access system, method and device based on alliance chain
CN109815732A
Implicit certificate key generation method based on SM2 digital signature
CN112367175A
Method and apparatus for extracting data from a vehicle
CN116631093A
Data storage method, electronic equipment and vehicle
CN117763040A
Data security verification method, related equipment and vehicle
CN117768176A
Cited By
Self-verification packaging security method and system for traffic accident digital twinborn scene
CN122310518A