Data transmission method and apparatus, and vehicle
By building an encrypted data transmission channel between the vehicle controller and the server, and using encryption and signature verification mechanisms, the security risks in vehicle data transmission are solved and the security and accuracy of data transmission are ensured.
Patent Information
- Application Number
- PCT/CN2024/111851
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2024-08-13
- Publication Date
- 2025-07-03
AI Technical Summary
In the prior art, data transmission between vehicles and servers poses security risks, especially low confidentiality, which leads to data leakage and tampering.
The application information is constructed through the controller identification, a handshake request is initiated and a data transmission channel is established, and the encryption and signature verification mechanisms are used to ensure the security of data transmission, including the generation of temporary public and private keys, hash processing, digital signatures and certificate verification and other technical means.
It realizes secure data transmission between the vehicle and the server, ensures the accuracy and integrity of the data, and avoids the risk of data being tampered with and leaked.
Smart Images

Figure CN2024111851_03072025_PF_FP_ABST
Abstract
Description
Data transmission method, device and vehicle Technical Field
[0001] The present disclosure relates to the field of data transmission, and in particular to a data transmission method, device, and vehicle. Background Art
[0002] With the increasing application of internet technology in the automotive sector, various functional modules and electronic control systems on vehicles are increasingly required to exchange data with cloud servers in real time to implement intelligent data distribution, resource sharing, and fault collection. However, some of the data generated and collected by vehicles requires confidentiality, such as driving trajectory reports, map data packages, and firmware upgrade information. Current data transmission methods often offer low confidentiality, leading to the high risk of data leakage and tampering during transmission.
[0003] To address the above-mentioned problems, no effective solutions have been proposed so far.
[0004] Summary of the Invention
[0005] The embodiments of the present disclosure provide a data transmission method, device, and vehicle to at least solve the technical problem in the related art that there are security risks when a controller and a server transmit data.
[0006] According to one aspect of an embodiment of the present disclosure, a data transmission method is provided, which is applied to a controller on a vehicle, including: in response to controller startup, constructing application information based on a controller identifier of the controller, wherein the application information is used to apply to a server for target data of a preset type; initiating a handshake request to the server, and establishing a data transmission channel after the handshake is successful; sending the application information to the server through the data transmission channel, and receiving a response message sent by the server based on the application information; performing security verification on the response message in a first manner, and extracting the target data from the response message if the response message is secure.
[0007] Optionally, constructing application information based on the controller identifier of the controller includes: obtaining at least one data application request corresponding to the controller identifier, wherein the data application request is used to obtain target data from the server; in response to the preset type corresponding to the target data being a first type, constructing application information based on the data application request; in response to the preset type corresponding to the target data being a second type, encrypting the data application request based on preset parameters to obtain application information.
[0008] Optionally, the data application request is encrypted based on preset parameters to obtain application information, including: generating a temporary public key and a temporary private key based on a random number generation module; constructing temporary identity information based on the temporary public key, the controller identifier of the controller and the current timestamp; hashing the temporary identity information to generate summary information, and signing the summary information based on the temporary private key to obtain a digital signature; encrypting the data application request based on the temporary identity information and the digital signature to obtain application information.
[0009] Optionally, the response message is security verified according to the first method, including: extracting the root certificate signature and the temporary public key signature from the response message, wherein the root certificate signature is used to represent the signature generated by the server when processing the target data based on the preset root certificate private key, and the temporary public key signature is used to represent the signature generated by the server when processing the target data based on the temporary public key; verifying the root certificate signature using the preset root certificate public key to obtain a first verification result; in response to the first verification result being that the root certificate signature verification is successful, verifying the temporary public key signature using the temporary private key to obtain a second verification result; in response to the second verification result being that the temporary public key signature verification is successful, determining that the response message is secure.
[0010] Optionally, the server includes a first digital certificate, the controller includes a second digital certificate, initiates a handshake request to the server, and establishes a data transmission channel after the handshake is successful, including: obtaining the first digital certificate of the server based on the handshake request, and sending the second digital certificate to the server; verifying the validity of the second digital certificate to obtain a first verification result, and receiving a second verification result obtained by the server verifying the validity of the second digital certificate; in response to the first verification result being that the first digital certificate is valid and the second verification result being that the second digital certificate is valid, receiving session information sent by the server, wherein the session information is used to represent the information obtained by the server encrypting the session key and session identifier based on the temporary public key; using the temporary private key to decrypt the session information to obtain the session identifier and session key, and establishing a data transmission channel based on the session key and session identifier.
[0011] According to another aspect of an embodiment of the present disclosure, a data transmission method is also provided, which is applied to a server, and includes: receiving a handshake request sent by a controller, and establishing a data transmission channel after a successful handshake; in response to application information received through the data transmission channel, performing security verification on the application information according to a second method; when the application information is secure, obtaining target data that matches the controller identifier contained in the application information; performing security authentication on the target data to obtain a response message, and sending the response message to the controller through the data transmission channel.
[0012] Optionally, the application information is security verified according to a second method, including: extracting a digital signature and temporary identity information from the application information; verifying the digital signature based on a temporary public key generated by the controller to obtain the controller identity information; in response to a successful match between the controller identity information and the temporary identity information, determining that the application information is secure; in response to a failure to match between the controller identity information and the temporary identity information, determining that the application information is at risk.
[0013] Optionally, security authentication is performed on the target data to obtain a response message, including: signing the target data based on a preset root certificate private key to obtain a root certificate signature; signing the target data based on a temporary public key to obtain a temporary public key signature; and generating a response message based on the root certificate signature, the temporary public key signature and the target data.
[0014] According to another aspect of an embodiment of the present disclosure, a data transmission device is also provided, which is applied to a controller on a vehicle, including: an information construction module, which is configured to construct application information based on a controller identifier of the controller in response to controller startup, wherein the application information is used to apply to a server for target data of a preset type; a channel establishment module, which is configured to initiate a handshake request to the server and establish a data transmission channel after the handshake is successful; a message receiving module, which is configured to send application information to the server through the data transmission channel and receive a response message sent by the server based on the application information; a data extraction module, which is configured to perform security verification on the response message in a first manner and extract target data from the response message if the response message is secure.
[0015] Optionally, the information construction module is further configured to: obtain at least one data application request corresponding to the controller identifier, wherein the data application request is used to obtain target data from the server; in response to the preset type corresponding to the target data being the first type, construct application information based on the data application request; in response to the preset type corresponding to the target data being the second type, encrypt the data application request based on preset parameters to obtain application information.
[0016] Optionally, the information construction module is also configured to: generate a temporary public key and a temporary private key based on the random number generation module; construct temporary identity information based on the temporary public key, the controller identifier of the controller and the current timestamp; hash the temporary identity information to generate summary information, and sign the summary information based on the temporary private key to obtain a digital signature; encrypt the data application request based on the temporary identity information and the digital signature to obtain application information.
[0017] Optionally, the data extraction module is further configured to: extract the root certificate signature and the temporary public key signature from the response message, wherein the root certificate signature is used to represent the signature generated by the server based on the preset root certificate private key to process the target data, and the temporary public key signature is used to represent the signature generated by the server based on the temporary public key to process the target data; verify the root certificate signature using the preset root certificate public key to obtain a first verification result; in response to the first verification result being that the root certificate signature verification is successful, verify the temporary public key signature using the temporary private key to obtain a second verification result; in response to the second verification result being that the temporary public key signature verification is successful, determine that the response message is secure.
[0018] Optionally, the server includes a first digital certificate, the controller includes a second digital certificate, and the channel establishment module is further configured to: obtain the first digital certificate of the server based on a handshake request, and send the second digital certificate to the server; verify the validity of the second digital certificate to obtain a first verification result, and receive a second verification result obtained by the server verifying the validity of the second digital certificate; in response to the first verification result being that the first digital certificate is valid and the second verification result being that the second digital certificate is valid, receive session information sent by the server, wherein the session information is used to represent the information obtained by the server encrypting the session key and session identifier based on the temporary public key; use the temporary private key to decrypt the session information to obtain the session identifier and session key, and establish a data transmission channel based on the session key and session identifier.
[0019] According to another aspect of an embodiment of the present disclosure, a data transmission device is also provided, which is applied to a server and includes: a channel establishment module, which is configured to receive a handshake request sent by a controller and establish a data transmission channel after a successful handshake; an information verification module, which is configured to respond to application information received through the data transmission channel and perform security verification on the application information in a second manner; a data acquisition module, which is configured to obtain target data that matches the controller identifier contained in the application information when the application information is secure; and a data sending module, which is configured to perform security authentication on the target data to obtain a response message and send the response message to the controller through the data transmission channel.
[0020] Optionally, the information verification module is also configured to: extract a digital signature and temporary identity information from the application information; verify the digital signature based on a temporary public key generated by the controller to obtain the controller identity information; in response to a successful match between the controller identity information and the temporary identity information, determine that the application information is secure; in response to a failure to match between the controller identity information and the temporary identity information, determine that there is a risk in the application information.
[0021] Optionally, the data sending module is also configured to: sign the target data based on a preset root certificate private key to obtain a root certificate signature; sign the target data based on a temporary public key to obtain a temporary public key signature; and generate a response message based on the root certificate signature, the temporary public key signature and the target data.
[0022] According to another aspect of an embodiment of the present disclosure, a computer-readable storage medium is further provided. The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute any of the above-mentioned data transmission methods.
[0023] According to another aspect of an embodiment of the present disclosure, a processor is further provided, and the processor is configured to run a program, wherein any of the above-mentioned data transmission methods is executed when the program is run.
[0024] According to another aspect of an embodiment of the present disclosure, optionally, a vehicle is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute any one of the above-mentioned data transmission methods.
[0025] In an embodiment of the present disclosure, in response to the controller startup, application information is constructed based on the controller identifier of the controller, wherein the application information is used to apply for target data of a preset type from the server; a handshake request is initiated to the server, and a data transmission channel is established after the handshake is successful; the application information is sent to the server through the data transmission channel, and a response message sent by the server based on the application information is received; the response message is securely verified in accordance with the first method, and the target data is extracted from the response message when the response message is secure. By constructing the application information based on the controller identifier, the accuracy of the target data applied for to the server can be guaranteed. By establishing a data transmission channel when the handshake between the controller and the server is successful, and using the data transmission channel to transmit the application information and target data, the security of the data transmission process can be guaranteed. At the same time, after receiving the response message sent by the server, the controller further verifies the response message, which can avoid the response message sent by the server from being tampered with, resulting in a security risk, thereby further ensuring the security of data transmission, and thus solving the technical problem in the related art that there is a security risk when the controller and the server transmit data. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The exemplary embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:
[0027] FIG1 is a flow chart showing a data transmission method according to an embodiment of the present disclosure;
[0028] FIG2 is a flow chart showing another data transmission method according to an embodiment of the present disclosure;
[0029] FIG3 is a schematic diagram illustrating a data transmission process according to an embodiment of the present disclosure;
[0030] FIG4 is a structural block diagram of a data transmission device according to an embodiment of the present disclosure;
[0031] FIG5 is a structural block diagram of another data transmission device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0032] In order to enable those skilled in the art to better understand the solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present disclosure.
[0033] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0034] Example 1
[0035] According to an embodiment of the present disclosure, an embodiment of a method for data transmission on the controller side of a vehicle is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0036] FIG1 is a flow chart of a data transmission method according to an embodiment of the present disclosure. As shown in FIG1 , the method includes the following steps:
[0037] Step S102 : in response to the controller being started, constructing application information based on the controller identification of the controller.
[0038] The application information is used to apply for target data of a preset type from the server.
[0039] The target data may refer to data related to vehicle driving safety, including but not limited to vehicle navigation data, driving trajectory reports, map data packages, firmware upgrade information, etc., which may be stored in a cloud server. The controller may refer to a controller that uses the target data.
[0040] In an optional solution of this embodiment, considering that there are many numbers and types of controllers deployed on the vehicle, and the target data that different controllers need to obtain may be different, when it is detected that the controller is started, that is, the controller needs to obtain the corresponding target data, the data transmission system can first construct an application information for applying for the above-mentioned target data from the server based on the controller identification of the controller, so that the controller can obtain the currently required data in a targeted manner. For example, the data transmission system can first obtain the data type and data address of the target data required by the controller based on the controller identification of the controller, and then quickly generate the above-mentioned application information based on the data type and data address to avoid errors in obtaining target data.
[0041] Step S104: Initiate a handshake request to the server, and establish a data transmission channel after the handshake is successful.
[0042] In an optional scheme of this embodiment, considering that the above-mentioned target data has a certain confidentiality, if this data is transmitted in plain text, security risks such as data leakage and data tampering may occur. Therefore, in order to ensure the security of the controller on the vehicle when obtaining the target data, after constructing the application information, the data transmission system can control the above-mentioned controller to initiate a handshake request to the server where the target data is located, and after the handshake between the controller and the server is successful, a data transmission channel with a higher security factor is established according to the controller identifier of the controller and the server identifier of the corresponding server, and the above-mentioned application information or target data is transmitted through the data transmission channel to avoid the application information or target data being intercepted, tampered with, etc., so as to ensure the security of the data transmission process.
[0043] Step S106: sending application information to the server through the data transmission channel, and receiving a response message sent by the server based on the application information.
[0044] In an optional scheme of this embodiment, after constructing the above-mentioned data transmission channel, the data transmission system can control the aforementioned controller to transmit the aforementioned constructed application information to the corresponding server through the data transmission channel, and control the aforementioned controller to receive the response message sent by the server based on the application information through the data transmission channel, thereby improving the security of the data transmission process.
[0045] Step S108: Perform security verification on the response message according to the first method, and extract target data from the response message if the response message is safe.
[0046] In an optional scheme of this embodiment, considering that the server itself may be at risk of being attacked, the corresponding response message sent by the server may also be at risk. Therefore, after receiving the response message, the response message can also be verified, for example, whether there is security identification, authentication data and other information in the response message, so as to determine whether the received response message is safe. If the result of the security verification of the response message is that the response message is safe, the data transmission system can control the aforementioned controller to extract the required target data from the response message; if the result of the security verification of the response message is that the response message is unsafe, the data transmission system can control the aforementioned controller to discard the target data and mark the server.
[0047] Among them, marking the server can mean that if the number of unsafe response messages sent by the server to the controller is small, for example, less than a preset number threshold, then the server can be preliminarily marked as possibly being attacked and there is a security risk; if the number of unsafe response messages sent by the server to the controller is large, for example, greater than or equal to a preset number threshold, then the server can be further marked as being attacked and there is a security risk. At this time, the controller can no longer send application information to the server, and display the current application status to the user to remind the user that the target data currently obtained is abnormally unavailable.
[0048] In an embodiment of the present disclosure, in response to the controller startup, application information is constructed based on the controller identifier of the controller, wherein the application information is used to apply for target data of a preset type from the server; a handshake request is initiated to the server, and a data transmission channel is established after the handshake is successful; the application information is sent to the server through the data transmission channel, and a response message sent by the server based on the application information is received; the response message is securely verified in accordance with the first method, and the target data is extracted from the response message when the response message is secure. By constructing the application information based on the controller identifier, the accuracy of the target data applied for to the server can be guaranteed. By establishing a data transmission channel when the handshake between the controller and the server is successful, and using the data transmission channel to transmit the application information and target data, the security of the data transmission process can be guaranteed. At the same time, after receiving the response message sent by the server, the controller further verifies the response message, which can avoid the response message sent by the server from being tampered with, resulting in a security risk, thereby further ensuring the security of data transmission, and thus solving the technical problem in the related art that there is a security risk when the controller and the server transmit data.
[0049] Optionally, constructing application information based on the controller identifier of the controller includes: obtaining at least one data application request corresponding to the controller identifier, wherein the data application request is used to obtain target data from the server; in response to the preset type corresponding to the target data being a first type, constructing application information based on the data application request; in response to the preset type corresponding to the target data being a second type, encrypting the data application request based on preset parameters to obtain application information.
[0050] The data request may be a pre-set request for obtaining target data from a server, and may be a default request. The first type may refer to target data currently required by the controller without regard to the risk of attack, such as data unrelated to vehicle driving safety. The second type may refer to target data currently required by the controller without regard to the risk of attack, such as data related to vehicle driving safety.
[0051] In an optional solution of this embodiment, when constructing application information based on the controller identifier of the controller, in addition to constructing the above-mentioned application information in real time based on the controller identifier of the controller, in order to improve construction efficiency and ensure that the controller can quickly obtain the required target data, the data transmission system can quickly obtain at least one of the above-mentioned data application requests from a preset request database based on the above-mentioned controller identifier. If the preset type corresponding to the target data currently required by the controller is the first type, it means that the importance of the target data is relatively low. In this case, the data transmission system can directly construct the above-mentioned application information based on the obtained data application request, for example, updating the address information such as the source address and the target address in the data application request to the address of the controller and the address of the server, or modifying the date range, data volume, and other information for obtaining the target data in the data application request to quickly obtain the above-mentioned application information. If the preset type corresponding to the target data currently required by the controller is the second type, it means that the importance of the target data is relatively high. In this case, in addition to performing the above-mentioned modification on the data application information, the above-mentioned data application request can also be encrypted based on preset parameters, such as the current time, the current geographical location of the vehicle, and other parameters, to obtain application information with higher confidentiality, thereby ensuring the security of obtaining the target data using the application information.
[0052] Optionally, the data application request is encrypted based on preset parameters to obtain application information, including: generating a temporary public key and a temporary private key based on a random number generation module; constructing temporary identity information based on the temporary public key, the controller identifier of the controller and the current timestamp; hashing the temporary identity information to generate summary information, and signing the summary information based on the temporary private key to obtain a digital signature; encrypting the data application request based on the temporary identity information and the digital signature to obtain application information.
[0053] In an optional scheme of this embodiment, when encrypting a data application request, the data transmission system can first use a random number generation module in the controller, such as a hardware random number generator stored in the security chip of the controller, to generate a pair of preset bit numbers, such as an 8048-bit RSA (Rivest-Shamir-Adleman, asymmetric encryption algorithm) temporary public key and temporary private key, and store the temporary public key and temporary private key in a preset secure storage area to avoid leakage of the temporary public key and temporary private key. After constructing the above-mentioned temporary public key and temporary private key, in order to further ensure the confidentiality of the encrypted application information, the data transmission system can construct a temporary identity information for the controller based on the above-mentioned temporary public key, the controller identifier of the controller, such as the MAC address (Media Access Control Address) of the controller and the current timestamp, and then hash the temporary identity information, for example, using SHA (Secure Hash Algorithm)-256, SHA-512, SHA-3 and other hash algorithms to process the temporary identity information to produce summary information of the temporary identity information, and then sign the summary information according to the above-mentioned temporary private key to produce a corresponding digital signature, and finally use the temporary identity information and data signature to encrypt the above-mentioned data application request to obtain the above-mentioned application information with a higher security factor.
[0054] For ease of understanding, the format of the temporary identity information may be in JSON format (a data exchange format), which may be:
[0055] Optionally, the response message is security verified according to the first method, including: extracting the root certificate signature and the temporary public key signature from the response message, wherein the root certificate signature is used to represent the signature generated by the server when processing the target data based on the preset root certificate private key, and the temporary public key signature is used to represent the signature generated by the server when processing the target data based on the temporary public key; verifying the root certificate signature using the preset root certificate public key to obtain a first verification result; in response to the first verification result being that the root certificate signature verification is successful, verifying the temporary public key signature using the temporary private key to obtain a second verification result; in response to the second verification result being that the temporary public key signature verification is successful, determining that the response message is secure.
[0056] In an optional solution of this embodiment, to ensure the security of data transmission, the server can use the stored root certificate and the above-mentioned temporary private key to encrypt the target data. For example, the target data is processed using the preset root certificate private key to obtain the root certificate signature, and the target data is processed using the above-mentioned temporary public key to obtain the temporary public key signature. The target data is then encrypted using the root certificate signature and the temporary public key signature to obtain the above-mentioned response message. Therefore, when verifying the response message sent by the server, the corresponding root certificate signature and temporary public key signature can be first extracted from the above-mentioned response message, and then the root certificate signature can be verified using the preset root certificate public key to obtain a first verification result. If the first verification result is that the root certificate signature verification is successful, the temporary public key can be verified using the above-mentioned temporary private key to obtain a second verification result. Finally, if the second verification result is that the temporary public key signature verification is successful, the response message can be determined to be secure. If the first verification result is that the root certificate signature verification is unsuccessful, or the second verification result is that the temporary public key signature verification is unsuccessful, the response message can be determined to be unsafe and can be discarded.
[0057] Optionally, the server includes a first digital certificate, the controller includes a second digital certificate, initiates a handshake request to the server, and establishes a data transmission channel after the handshake is successful, including: obtaining the first digital certificate of the server based on the handshake request, and sending the second digital certificate to the server; verifying the validity of the second digital certificate to obtain a first verification result, and receiving a second verification result obtained by the server verifying the validity of the second digital certificate; in response to the first verification result being that the first digital certificate is valid and the second verification result being that the second digital certificate is valid, receiving session information sent by the server, wherein the session information is used to represent the information obtained by the server encrypting the session key and session identifier based on the temporary public key; using the temporary private key to decrypt the session information to obtain the session identifier and session key, and establishing a data transmission channel based on the session key and session identifier.
[0058] The digital certificate may be an X.509 certificate issued by a CA (Certificate Authority).
[0059] In an optional solution of this embodiment, in the process of the controller initiating a handshake request to the server to establish a data transmission channel, considering that both the controller and the server are configured with X.509 certificates issued by the CA, the controller and the server can exchange the certificates, that is, the controller can obtain the first digital certificate held by the server based on the sent handshake request, and at the same time send the second digital certificate held by itself to the server. The controller can verify the validity of the first digital certificate to obtain the above-mentioned first verification result. At the same time, the server verifies the validity of the second digital certificate and sends the verification result to the controller, that is, receives the second verification result sent by the server. If the first verification result is that the first digital certificate is valid, and the second verification result is that the second digital certificate is valid, the controller can verify the validity of the first digital certificate to obtain the above-mentioned first verification result. If the certificate is valid, the controller can receive the session information sent by the server by encrypting the session key and session identifier according to the temporary public key, and then use the above-mentioned temporary private key to decrypt the session information to obtain the corresponding session identifier and session key. Finally, the above-mentioned data transmission channel can be established based on the session identifier and session key to ensure the security of the data transmission process; if the first verification result is that the first digital certificate is invalid, or the second verification result is that the second digital certificate is invalid, then the data transmission channel may not be established at this time, and the above-mentioned digital certificate may be re-obtained for multiple verifications until the verification is successful. If the number of verifications is too many, for example, the number of verifications is greater than the preset number threshold, then the establishment of the data transmission channel may be stopped, and the target data will no longer be transmitted. Among them, the established data transmission channel can be generated based on the TSL (Transport Layer Security) channel.
[0060] Example 2
[0061] According to another aspect of an embodiment of the present disclosure, corresponding to the above-mentioned data transmission method applied to the vehicle controller, a data transmission method is further provided, which is applied to a server. FIG2 is a flow chart of another data transmission method according to an embodiment of the present disclosure. As shown in FIG2 , the method includes:
[0062] Step S202: receiving a handshake request sent by the controller, and establishing a data transmission channel after the handshake is successful.
[0063] In an optional scheme of this embodiment, corresponding to the aforementioned controller sending a handshake request and establishing a data transmission channel, when the server receives the handshake request sent by the controller, it can first obtain the second digital certificate sent by the controller and send its own first digital certificate to the controller. The server can verify the validity of the second digital certificate and send the obtained second verification result to the controller. The controller can send the obtained first verification result to the server. If the first verification result is that the first digital certificate is valid and the second verification result is that the second digital certificate is valid, the above-mentioned data transmission channel can be established to ensure the security of the data transmission process. If the first verification result is that the first digital certificate is invalid, or the second verification result is that the second digital certificate is invalid, the data transmission channel is not established, and the above-mentioned digital certificate is re-acquired for multiple verifications until the verification is successful. If the number of verifications is too many, for example, the number of verifications is greater than the preset threshold, the establishment of the data transmission channel can be stopped and the target data will no longer be transmitted.
[0064] Step S204: In response to receiving the application information through the data transmission channel, performing security verification on the application information according to the second method.
[0065] In an optional scheme of this embodiment, the controller can send the application information to the server through the data transmission channel. Considering that the application information may be at risk of being tampered with, after receiving the application information, the server can verify the application information in a second manner, such as determining whether the sending address of the application information is the sending address of the controller, whether the generation time of the application information is the time when the controller generates the application information, etc., so as to avoid situations where the application information is at risk.
[0066] Step S206: If the application information is secure, obtain target data that matches the controller identifier included in the application information.
[0067] In an optional scheme of this embodiment, when the application information is verified to be safe, the server can obtain target data that matches the controller identifier contained in the application information to avoid the situation where the obtained target data is incorrect and the controller cannot use the target data; when the application information is verified to be unsafe, the server can disconnect from the controller to ensure the security of the data stored in the server.
[0068] Step S208: Perform security authentication on the target data to obtain a response message, and send the response message to the controller through the data transmission channel.
[0069] In an optional solution of this embodiment, in order to further improve the security of the data transmission process, the server can perform security authentication on the target data after obtaining the target data, obtain the above-mentioned response message, and transmit the response message through the established data transmission channel to avoid the response message being intercepted or tampered with.
[0070] Optionally, the application information is security verified according to a second method, including: extracting a digital signature and temporary identity information from the application information; verifying the digital signature based on a temporary public key generated by the controller to obtain the controller identity information; in response to a successful match between the controller identity information and the temporary identity information, determining that the application information is secure; in response to a failure to match between the controller identity information and the temporary identity information, determining that the application information is at risk.
[0071] In an optional scheme of this embodiment, when verifying the application information, the corresponding digital signature and temporary identity information can be first extracted from the application information, and then the digital signature can be verified using the temporary public key generated by the controller to obtain the controller identity information of the controller. Finally, the controller identity information is matched with the above-mentioned temporary identity information to realize the operation of verifying the application information. If the controller identity information and the temporary identity information match successfully, it can be determined that the application information is safe; if the controller identity information and the temporary identity information fail to match, it can be determined that the application information is at risk.
[0072] Optionally, security authentication is performed on the target data to obtain a response message, including: signing the target data based on a preset root certificate private key to obtain a root certificate signature; signing the target data based on a temporary public key to obtain a temporary public key signature; and generating a response message based on the root certificate signature, the temporary public key signature and the target data.
[0073] In an optional solution of this embodiment, when performing security authentication on the target data, the server can first sign the target data according to the stored root certificate private key to obtain the corresponding root certificate signature, and at the same time use the above-mentioned temporary public key to sign the above-mentioned target data to obtain the corresponding temporary public key signature. Finally, according to the root certificate signature, the temporary certificate signature and the target data, the corresponding response message can be generated. By setting two signatures, the security of keeping the target data confidential can be greatly improved. The root certificate signature can be used to determine that the response message and target data come from the expected server to prevent man-in-the-middle attacks. For example, the temporary public key signature can be used to determine that the target data has not been tampered with and is bound to the temporary identity identification message of the controller. Although the purposes of the two signatures are different, the two signatures together ensure the reliability and security of the target data during transmission.
[0074] To facilitate understanding of the above-mentioned data transmission process, Figure 3 is a schematic diagram of a data transmission process shown according to an embodiment of the present disclosure. As shown in Figure 3, the process may be: the vehicle controller end first constructs application information for applying for target data, and sends a handshake request to the server to establish a data transmission channel. After the data transmission channel is successfully established, the controller can send the application information to the server through the data transmission channel. The server verifies the application information and, if the verification is successful, signs the target data to obtain a response message. The response message is then transmitted to the controller through the data transmission channel. The controller verifies the response message. If the verification is successful, the required target data can be extracted from the response message and used. If the result of the server's verification of the application information is a verification failure, the server can discard the application information and end the data transmission process. If the controller's verification of the response message is a verification failure, the controller can discard the corresponding response message and resend the application request or end the data transmission process without obtaining the target data.
[0075] Example 3
[0076] According to another aspect of an embodiment of the present disclosure, corresponding to the above-mentioned data transmission method applied to a vehicle controller, a data transmission device is also provided, which is applied to a controller on a vehicle. Figure 4 is a structural block diagram of a data transmission device according to an embodiment of the present disclosure. As shown in Figure 4, the device includes: an information construction module 402, a channel establishment module 404, a message receiving module 406 and a data extraction module 408.
[0077] Among them, the information construction module is configured to respond to the controller startup and construct application information based on the controller identifier of the controller, wherein the application information is used to apply for target data of a preset type from the server; the channel establishment module is configured to initiate a handshake request to the server and establish a data transmission channel after the handshake is successful; the message receiving module is configured to send application information to the server through the data transmission channel and receive a response message sent by the server based on the application information; the data extraction module is configured to perform security verification on the response message in a first manner and extract target data from the response message if the response message is secure.
[0078] It should be noted here that the above-mentioned information construction module 402, channel establishment module 404, message receiving module 406 and data extraction module 408 can be run in a computer terminal as part of the device, and the functions implemented by the above-mentioned modules can be executed by the processor in the computer terminal. The computer terminal can also be a smart phone (such as Android phone, IOS phone, etc.), tablet computer, PDA and mobile Internet device (Mobile Internet Devices, MID), PAD and other terminal devices.
[0079] Optionally, the information construction module is further configured to: obtain at least one data application request corresponding to the controller identifier, wherein the data application request is used to obtain target data from the server; in response to the preset type corresponding to the target data being the first type, construct application information based on the data application request; in response to the preset type corresponding to the target data being the second type, encrypt the data application request based on preset parameters to obtain application information.
[0080] Optionally, the information construction module is also configured to: generate a temporary public key and a temporary private key based on the random number generation module; construct temporary identity information based on the temporary public key, the controller identifier of the controller and the current timestamp; hash the temporary identity information to generate summary information, and sign the summary information based on the temporary private key to obtain a digital signature; encrypt the data application request based on the temporary identity information and the digital signature to obtain application information.
[0081] Optionally, the data extraction module is further configured to: extract the root certificate signature and the temporary public key signature from the response message, wherein the root certificate signature is used to represent the signature generated by the server based on the preset root certificate private key to process the target data, and the temporary public key signature is used to represent the signature generated by the server based on the temporary public key to process the target data; verify the root certificate signature using the preset root certificate public key to obtain a first verification result; in response to the first verification result being that the root certificate signature verification is successful, verify the temporary public key signature using the temporary private key to obtain a second verification result; in response to the second verification result being that the temporary public key signature verification is successful, determine that the response message is secure.
[0082] Optionally, the server includes a first digital certificate, the controller includes a second digital certificate, and the channel establishment module is further configured to: obtain the first digital certificate of the server based on a handshake request, and send the second digital certificate to the server; verify the validity of the second digital certificate to obtain a first verification result, and receive a second verification result obtained by the server verifying the validity of the second digital certificate; in response to the first verification result being that the first digital certificate is valid and the second verification result being that the second digital certificate is valid, receive session information sent by the server, wherein the session information is used to represent the information obtained by the server encrypting the session key and session identifier based on the temporary public key; use the temporary private key to decrypt the session information to obtain the session identifier and session key, and establish a data transmission channel based on the session key and session identifier.
[0083] Example 4
[0084] According to another aspect of an embodiment of the present disclosure, corresponding to the above-mentioned data transmission method applied on the server, a data transmission device is also provided, which is applied to the server. Figure 5 is a structural block diagram of another data transmission device according to an embodiment of the present disclosure. As shown in Figure 5, the device includes: a channel establishment module 502, an information verification module 504, a data acquisition module 506 and a data sending module 508.
[0085] Among them, the channel establishment module is configured to receive a handshake request sent by the controller and establish a data transmission channel after the handshake is successful; the information verification module is configured to respond to the application information received through the data transmission channel and perform security verification on the application information in accordance with the second method; the data acquisition module is configured to obtain target data that matches the controller identifier contained in the application information when the application information is secure; the data sending module is configured to perform security authentication on the target data to obtain a response message, and send the response message to the controller through the data transmission channel.
[0086] It should be noted here that the above-mentioned channel establishment module 502, information verification module 504, data acquisition module 506 and data sending module 508 can be run in a computer terminal as part of the device, and the functions implemented by the above-mentioned modules can be executed by the processor in the computer terminal. The computer terminal can also be a smart phone (such as Android phone, IOS phone, etc.), tablet computer, PDA and mobile Internet device (Mobile Internet Devices, MID), PAD and other terminal devices.
[0087] Optionally, the information verification module is also configured to: extract a digital signature and temporary identity information from the application information; verify the digital signature based on a temporary public key generated by the controller to obtain the controller identity information; in response to a successful match between the controller identity information and the temporary identity information, determine that the application information is secure; in response to a failure to match between the controller identity information and the temporary identity information, determine that there is a risk in the application information.
[0088] Optionally, the data sending module is also configured to: sign the target data based on a preset root certificate private key to obtain a root certificate signature; sign the target data based on a temporary public key to obtain a temporary public key signature; and generate a response message based on the root certificate signature, the temporary public key signature and the target data.
[0089] Example 5
[0090] According to another aspect of an embodiment of the present disclosure, a computer-readable storage medium is further provided. The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute any of the above-mentioned data transmission methods.
[0091] Optionally, in this embodiment, the above-mentioned storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0092] Optionally, in this embodiment, the storage medium is configured to store program code for executing the following steps: in response to controller startup, constructing application information based on the controller identifier of the controller, wherein the application information is used to request target data of a preset type from the server; initiating a handshake request to the server and establishing a data transmission channel after the handshake is successful; sending the application information to the server through the data transmission channel, and receiving a response message sent by the server based on the application information; performing security verification on the response message in accordance with a first method, and extracting the target data from the response message if the response message is secure. Optionally, in this embodiment, the storage medium is configured to store program code for executing the following steps: obtaining at least one data application request corresponding to the controller identifier, wherein the data application request is used to obtain target data from the server; in response to the preset type corresponding to the target data being a first type, constructing application information based on the data application request; in response to the preset type corresponding to the target data being a second type, encrypting the data application request based on preset parameters to obtain application information.
[0093] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: generating a temporary public key and a temporary private key based on a random number generation module; constructing temporary identity information based on the temporary public key, the controller identifier of the controller and the current timestamp; hashing the temporary identity information to generate summary information, and signing the summary information based on the temporary private key to obtain a digital signature; encrypting the data application request based on the temporary identity information and the digital signature to obtain application information.
[0094] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: extracting a root certificate signature and a temporary public key signature from a response message, wherein the root certificate signature is used to represent the signature generated by the server based on a preset root certificate private key to process the target data, and the temporary public key signature is used to represent the signature generated by the server based on the temporary public key to process the target data; verifying the root certificate signature using the preset root certificate public key to obtain a first verification result; in response to the first verification result being that the root certificate signature verification is successful, verifying the temporary public key signature using the temporary private key to obtain a second verification result; in response to the second verification result being that the temporary public key signature verification is successful, determining that the response message is secure.
[0095] Optionally, in this embodiment, the storage medium is configured to store program code for executing the following steps: obtaining the first digital certificate of the server based on a handshake request, and sending the second digital certificate to the server; verifying the validity of the second digital certificate to obtain a first verification result, and receiving a second verification result obtained by the server verifying the validity of the second digital certificate; in response to the first verification result being that the first digital certificate is valid and the second verification result being that the second digital certificate is valid, receiving session information sent by the server, wherein the session information is used to represent the information obtained by the server encrypting the session key and session identifier based on the temporary public key; decrypting the session information using the temporary private key to obtain the session identifier and session key, and establishing a data transmission channel based on the session key and session identifier.
[0096] Optionally, in this embodiment, the storage medium is configured to store program code for executing the following steps: receiving a handshake request sent by the controller and establishing a data transmission channel after a successful handshake; in response to receiving application information through the data transmission channel, performing security verification on the application information in accordance with the second method; when the application information is secure, obtaining target data that matches the controller identifier contained in the application information; performing security authentication on the target data to obtain a response message, and sending the response message to the controller through the data transmission channel.
[0097] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: extracting a digital signature and temporary identity information from the application information; verifying the digital signature based on a temporary public key generated by the controller to obtain controller identity information; in response to a successful match between the controller identity information and the temporary identity information, determining that the application information is secure; in response to a failure to match between the controller identity information and the temporary identity information, determining that there is a risk in the application information.
[0098] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: signing the target data based on a preset root certificate private key to obtain a root certificate signature; signing the target data based on a temporary public key to obtain a temporary public key signature; and generating a response message based on the root certificate signature, the temporary public key signature and the target data.
[0099] Optionally, in this embodiment, the storage medium may also be configured to store program codes of various preferred or optional method steps provided by the method for processing the computing task.
[0100] Example 6
[0101] According to another aspect of an embodiment of the present disclosure, a processor is further provided, and the processor is configured to run a program, wherein any of the above-mentioned data transmission methods is executed when the program is run.
[0102] Optionally, in this embodiment, the processor may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0103] Optionally, in this embodiment, the processor is configured to perform the following steps: in response to controller startup, construct application information based on the controller identifier of the controller, wherein the application information is used to apply for target data of a preset type from the server; initiate a handshake request to the server, and establish a data transmission channel after the handshake is successful; send the application information to the server through the data transmission channel, and receive a response message sent by the server based on the application information; perform security verification on the response message in accordance with a first method, and extract the target data from the response message if the response message is secure. Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: obtain at least one data application request corresponding to the controller identifier, wherein the data application request is used to obtain target data from the server; in response to the preset type corresponding to the target data being a first type, construct application information based on the data application request; in response to the preset type corresponding to the target data being a second type, encrypt the data application request based on preset parameters to obtain application information.
[0104] The various functional units provided in the embodiments of the present disclosure may be run in a mobile terminal, a computer terminal, or a similar computing device, and may also be stored as part of a storage medium.
[0105] Thus, the embodiment of the present invention can provide a computer terminal, which can be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the computer terminal can also be replaced by a terminal device such as a mobile terminal.
[0106] Optionally, in this embodiment, the computer terminal may be located in at least one network device among a plurality of network devices of a computer network.
[0107] In this embodiment, the above-mentioned computer terminal can also execute the program code of the following steps in the processing method of the computing task: generate a temporary public key and a temporary private key based on a random number generation module; construct temporary identity identification information based on the temporary public key, the controller identification of the controller and the current timestamp; hash the temporary identity identification information to generate summary information, and sign the summary information based on the temporary private key to obtain a digital signature; encrypt the data application request based on the temporary identity identification information and the digital signature to obtain application information.
[0108] In this embodiment, the above-mentioned computer terminal can also execute the program code of the following steps in the processing method of the computing task: extracting the root certificate signature and the temporary public key signature from the response message, wherein the root certificate signature is used to represent the signature generated by the server based on the preset root certificate private key to process the target data, and the temporary public key signature is used to represent the signature generated by the server based on the temporary public key to process the target data; using the preset root certificate public key to verify the root certificate signature to obtain a first verification result; in response to the first verification result being that the root certificate signature verification is successful, using the temporary private key to verify the temporary public key signature to obtain a second verification result; in response to the second verification result being that the temporary public key signature verification is successful, determining that the response message is secure.
[0109] In this embodiment, the above-mentioned computer terminal can also execute the program code of the following steps in the processing method of the computing task: obtaining the first digital certificate of the server based on the handshake request, and sending the second digital certificate to the server; verifying the validity of the second digital certificate to obtain a first verification result, and receiving the second verification result obtained by the server verifying the validity of the second digital certificate; in response to the first verification result being that the first digital certificate is valid and the second verification result being that the second digital certificate is valid, receiving the session information sent by the server, wherein the session information is used to represent the information obtained by the server encrypting the session key and session identifier based on the temporary public key; using the temporary private key to decrypt the session information to obtain the session identifier and session key, and establishing a data transmission channel based on the session key and session identifier.
[0110] In this embodiment, the above-mentioned computer terminal can also execute the program code of the following steps in the processing method of the computing task: receiving a handshake request sent by the controller, and establishing a data transmission channel after the handshake is successful; in response to receiving the application information through the data transmission channel, performing security verification on the application information according to the second method; when the application information is secure, obtaining target data that matches the controller identifier contained in the application information; performing security authentication on the target data to obtain a response message, and sending the response message to the controller through the data transmission channel.
[0111] In this embodiment, the above-mentioned computer terminal can also execute the program code of the following steps in the processing method of the computing task: extracting the digital signature and temporary identity information from the application information; verifying the digital signature based on the temporary public key generated by the controller to obtain the controller identity information; in response to a successful match between the controller identity information and the temporary identity information, determining that the application information is safe; in response to a failure to match between the controller identity information and the temporary identity information, determining that the application information is at risk.
[0112] In this embodiment, the above-mentioned computer terminal can also execute the program code of the following steps in the processing method of the computing task: signing the target data based on the preset root certificate private key to obtain the root certificate signature; signing the target data based on the temporary public key to obtain the temporary public key signature; generating a response message based on the root certificate signature, the temporary public key signature and the target data.
[0113] Optionally, the computer terminal may include: one or more processors, a memory, and a transmission device.
[0114] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the method and device for processing computing tasks in the embodiments of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned method for processing computing tasks. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0115] The transmission device is used to receive or send data via a network. Specific examples of the network may include wired networks and wireless networks. In one embodiment, the transmission device includes a network interface controller (NIC), which can be connected to other network devices and a router via a network cable to communicate with the Internet or a local area network. In one embodiment, the transmission device is a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0116] Specifically, the memory is used to store a set of computing tasks, a set of computing results, reference data and historical information, and application programs.
[0117] The processor can call the information and application programs stored in the memory through the transmission device to execute the program codes of the method steps of each optional or preferred embodiment in the above method embodiment.
[0118] Those skilled in the art will appreciate that the computer terminal may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, an MID, a PAD, or other terminal devices.
[0119] Example 7
[0120] According to another aspect of an embodiment of the present disclosure, a vehicle is also provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute any one of the above-mentioned data transmission methods.
[0121] Example 8
[0122] According to another aspect of an embodiment of the present disclosure, a computer program product is further provided, which includes a computer program, and when the computer program is executed by a processor, it implements any of the above-mentioned data transmission methods.
[0123] Example 9
[0124] According to another aspect of an embodiment of the present disclosure, a computer program product is further provided, which includes a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements any of the above-mentioned data transmission methods.
[0125] Example 10
[0126] According to another aspect of an embodiment of the present disclosure, a computer program is further provided, wherein when the computer program is executed by a processor, any of the above-mentioned data transmission methods is implemented.
[0127] The serial numbers of the above-mentioned embodiments of the present disclosure are for description only and do not represent the advantages or disadvantages of the embodiments.
[0128] In the above embodiments of the present disclosure, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0129] In the several embodiments provided in the present disclosure, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0130] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.
[0131] In addition, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0132] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0133] The above is only a preferred embodiment of the present disclosure. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present disclosure. These improvements and modifications should also be regarded as within the scope of protection of the present disclosure. Industrial Applicability
[0134] The solution provided in the embodiment of the present disclosure can be applied to the field of data transmission. In response to the controller startup, application information is constructed based on the controller identifier of the controller, wherein the application information is used to apply for target data of a preset type from the server; a handshake request is initiated to the server, and a data transmission channel is established after the handshake is successful; the application information is sent to the server through the data transmission channel, and a response message sent by the server based on the application information is received; the response message is securely verified according to the first method, and the target data is extracted from the response message when the response message is secure. By constructing the application information based on the controller identifier, the accuracy of the target data applied to the server can be guaranteed. By establishing the data transmission channel when the handshake between the controller and the server is successful, and using the data transmission channel to transmit the application information and target data, the security of the data transmission process can be guaranteed. At the same time, after receiving the response message sent by the server, the controller further verifies the response message, which can avoid the response message sent by the server from being tampered with, resulting in a security risk, thereby further ensuring the security of data transmission, thereby solving the technical problem of security risks when the controller and the server transmit data in the related art.
Claims
1. A data transmission method, which is applied to a controller in a vehicle and includes: In response to the startup of the controller, constructing application information based on the controller identifier of the controller, where the application information is used to apply to the server for target data of a preset type; Sending a handshake request to the server and establishing a data transmission channel after the handshake is successful; Sending the application information to the server through the data transmission channel and receiving a response message sent by the server based on the application information; Performing security verification on the response message in a first manner, and extracting the target data from the response message when the response message is secure.
2. The method according to claim 1, wherein Constructing application information based on the controller identifier of the controller includes: Obtaining at least one data application request corresponding to the controller identifier, where the data application request is used to obtain the target data from the server; In response to the preset type corresponding to the target data being the first type, constructing the application information based on the data application request; In response to the preset type corresponding to the target data being the second type, encrypting the data application request based on preset parameters to obtain the application information.
3. The method according to claim 2, wherein Encrypting the data application request based on preset parameters to obtain the application information includes: Generating a temporary public key and a temporary private key based on a random number generation module; Constructing temporary identity identification information based on the temporary public key, the controller identifier of the controller, and the current timestamp; Performing a hash process on the temporary identity identification information to generate a digest information, and signing the digest information based on the temporary private key to obtain a digital signature; Encrypting the data application request based on the temporary identity identification information and the digital signature to obtain the application information.
4. The method according to claim 3, wherein, Performing security verification on the response message in a first manner includes: Extracting a root certificate signature and a temporary public key signature from the response message, where the root certificate signature Is used to represent the signature generated by the server based on a preset root certificate private key for processing the target data, and the temporary public key signature is used to represent the signature generated by the server based on the temporary public key for processing the target data; Verifying the root certificate signature using a preset root certificate public key to obtain a first verification result; In response to the first verification result being that the root certificate signature verification is successful, verifying the temporary public key signature using the temporary private key to obtain a second verification result; In response to the second verification result being that the temporary public key signature verification is successful, determining that the response message is secure.
5. The method according to claim 4, wherein The server includes a first digital certificate, and the controller includes a second digital certificate. Sending a handshake request to the server and establishing a data transmission channel after the handshake is successful includes: Obtaining the first digital certificate of the server based on the handshake request and sending the second digital certificate to the server; Performing validity verification on the second digital certificate to obtain a first verification result, and receiving a second verification result obtained by the server for performing validity verification on the second digital certificate; In response to the first verification result indicating that the first digital certificate is valid and the second verification result indicating that the second digital certificate is valid, receive the session information sent by the server, where the session information is used to represent the information obtained by the server encrypting a session key and a session identifier based on the temporary public key; Use the temporary private key to decrypt the session information to obtain the session identifier and the session key, and establish the data transmission channel based on the session key and the session identifier.
6. A data transmission method, applied to a server, includes: Receive a handshake request sent by a controller, and establish a data transmission channel after the handshake is successful; In response to receiving application information through the data transmission channel, perform security verification on the application information in a second manner; When the application information is secure, obtain target data that matches the controller identifier included in the application information; Perform security authentication on the target data to obtain a response message, and send the response message to the controller through the data transmission channel.
7. The method according to claim 6, wherein Performing security verification on the application information in a second manner includes: Extract a digital signature and temporary identity information from the application information; Verify the digital signature based on the temporary public key generated by the controller to obtain controller identity information; In response to the successful matching of the controller identity information and the temporary identity information, determine that the application information is secure; In response to the failure of the controller identity information and the temporary identity information to match, determine that there is a risk in the application information.
8. The method according to claim 6, wherein, Performing security authentication on the target data to obtain a response message includes: Sign the target data based on a preset root certificate private key to obtain a root certificate signature; Sign the target data based on the temporary public key to obtain a temporary public key signature; Generate the response message based on the root certificate signature, the temporary public key signature, and the target data.
9. A data transmission device, applied to a controller on a vehicle, includes: An information construction module, configured to construct application information based on the controller identifier of the controller in response to the startup of the controller, where the application information is used to apply to the server for target data of a preset type; A channel establishment module, configured to send a handshake request to the server and establish a data transmission channel after the handshake is successful; A message receiving module, configured to send the application information to the server through the data transmission channel and receive the response message sent by the server based on the application information; A data extraction module, configured to perform security verification on the response message in a first manner, and extract the target data from the response message when the response message is secure.
10. A storage medium, the storage medium includes a stored program, and when the program runs, it controls the device where the storage medium is located to execute the following method: In response to the start of the controller, application information is constructed based on the controller identifier of the controller, where The application information is used to apply to the server for target data of a preset type; Send a handshake request to the server, and establish a data transmission channel after the handshake is successful; Send the application information to the server through the data transmission channel, and receive the response message sent by the server based on the application information; Perform security verification on the response message in a first manner, and extract the target data from the response message when the response message is secure.
11. The storage medium according to claim 10, when the program is running, controlling the device where the storage medium is located to further execute the following method: Obtain at least one data application request corresponding to the controller identifier, where The data application request is used to obtain the target data from the server; In response to the preset type corresponding to the target data being the first type, construct the application information based on the data application request; In response to the preset type corresponding to the target data being the second type, encrypt the data application request based on preset parameters to obtain the application information.
12. The storage medium according to claim 11, when the program is running, controlling the device where the storage medium is located to further execute the following method: Generate a temporary public key and a temporary private key based on a random number generation module; Construct temporary identity identification information based on the temporary public key, the controller identification of the controller, and the current timestamp; Perform a hash process on the temporary identity identification information to generate a digest information, and sign the digest information based on the temporary private key to obtain a digital signature; Encrypt the data application request based on the temporary identity identification information and the digital signature to obtain the application information.
13. The storage medium according to claim 12, when the program is running, controlling the device where the storage medium is located to further execute the following method: Extract the root certificate signature and the temporary public key signature from the response message, where The root certificate signature is used to represent the signature generated by the server based on the preset root certificate private key for processing the target data, and the temporary public key signature is used to represent the signature generated by the server based on the temporary public key for processing the target data; Verify the root certificate signature using the preset root certificate public key to obtain a first verification result; In response to the first verification result being that the root certificate signature verification is successful, verify the temporary public key signature using the temporary private key to obtain a second verification result; In response to the second verification result being that the temporary public key signature verification is successful, determine that the response message is secure.
14. A processor, the processor is used to run a program, and when the program is running, it executes the following method: In response to the start of the controller, application information is constructed based on the controller identifier of the controller, where The application information is used to apply to the server for target data of a preset type; Initiate a handshake request to the server, and establish a data transmission channel after the handshake is successful; Send the application information to the server through the data transmission channel, and receive the response message sent by the server based on the application information; Perform security verification on the response message in a first manner, and extract the target data from the response message when the response message is secure.
15. The processor according to claim 14, when the program is running, further executes the following method: Obtain at least one data application request corresponding to the controller identifier, where The data application request is used to obtain the target data from the server; In response to the preset type corresponding to the target data being the first type, construct the application information based on the data application request; In response to the preset type corresponding to the target data being the second type, encrypt the data application request based on preset parameters to obtain the application information.
16. The processor according to claim 15, when the program runs, further executes the following method: Generate a temporary public key and a temporary private key based on a random number generation module; Construct temporary identity identification information based on the temporary public key, the controller identification of the controller, and the current timestamp; Perform a hashing process on the temporary identity identification information to generate digest information, and sign the digest information based on the temporary private key to obtain a digital signature; Encrypt the data application request based on the temporary identity identification information and the digital signature to obtain the application information.
17. A vehicle, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the data transmission method according to any one of claims 1 to 8.
18. A computer program product, wherein, Comprising a computer program, the computer program realizes the method according to any one of claims 1 to 8 when executed by a processor.
19. A computer program product, wherein, Comprising a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium stores a computer program, and the computer program realizes the method according to any one of claims 1 to 8 when executed by a processor.
20. A computer program, wherein, The computer program realizes the method according to any one of claims 1 to 8 when executed by a processor.
Citation Information
Patent Citations
Engineering mechanical vehicle networking and communicating method and engineering mechanical vehicle networking system
CN102333071A
Internet of Vehicles safety communication method, vehicle-mounted terminal, server and system
CN106453269A
Information transmission method and device, computer equipment and storage medium
CN114745115A
Data transmission method and device and vehicle
CN117938983A
Security authentication method, readable medium, and electronic device
WO2022252857A1
Cited By
Multi-mode security authentication system of replaceable power interface and encryption communication method
CN122372334A