Vehicle-cloud data transmission method and apparatus, storage medium, and electronic apparatus

By establishing a communication channel between the DDS and MQTT components between the vehicle and the cloud server, combining the session key and the dynamic configuration parameters of QoS information, the problem of signal delay and TLS/SSL protocol complexity in traditional vehicle-mounted communication systems is solved, and efficient and flexible vehicle cloud data transmission is achieved.

WO2025148730A1PCT designated stage expired Publication Date: 2025-07-17CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/143417
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-08
Filing Date
2024-12-27
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Due to the signal transmission delay and the performance and complexity of the TLS/SSL protocol, traditional vehicle communication systems are difficult to meet the security communication needs between vehicles and cloud servers, especially in the lack of flexibility and efficiency in vehicle cloud communication.

Method used

The communication channel of the data distribution service DDS component and message queue telemetry transmits the MQTT component, and the security configuration parameters and traffic control parameters are dynamically configured in combination with the session key and quality of service QoS information to realize secure data transmission between the vehicle and the cloud server.

Benefits of technology

It improves the efficiency and flexibility of vehicle communication, reduces the complexity and performance overhead of traditional TLS/SSL protocols, ensures data confidentiality and integrity, and adapts to the specific needs of vehicle cloud communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024143417_17072025_PF_FP_ABST
    Figure CN2024143417_17072025_PF_FP_ABST
Patent Text Reader

Abstract

A vehicle-cloud data transmission method and apparatus, a storage medium, and an electronic apparatus. The method comprises: establishing a communication channel from a data distribution service (DDS) component to a message queuing telemetry transport (MQTT) component between a vehicle and a cloud server, wherein the DDS component is installed on the vehicle, and the MQTT component is installed on the cloud server; transmitting an MQTT message to the cloud server via the communication channel, wherein the MQTT message carries a session key between the vehicle and the cloud server; dynamically configuring a security configuration parameter and a traffic control parameter of the communication channel on the basis of quality of service (QoS) information of the vehicle; and transmitting a data packet to the cloud server on the basis of the session key, the security configuration parameter, and the traffic control parameter.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle-to-cloud data transmission method and device, storage medium, and electronic device

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This disclosure claims priority to Chinese patent application number 202410033091.2, filed with the China Patent Office on January 8, 2024, entitled “Method and device, storage medium, and electronic device for transmitting vehicle-to-cloud data,” the entire contents of which are incorporated by reference into this disclosure. Technical Field

[0003] The present invention relates to the field of smart cars, and more specifically, to a method and device for transmitting vehicle-to-cloud data, a storage medium, and an electronic device. Background Art

[0004] Vehicle safety is a core issue in the connected vehicle (IoV) technology. Vehicles require secure communication with road infrastructure and other vehicles to avoid collisions and other dangerous situations. This safety communication encompasses aspects such as accident prevention, emergency notifications, and road management. Traditional in-vehicle communication systems typically utilize the CAN bus or LIN bus for communication. However, due to issues such as signal transmission latency, traditional CAN buses for transmitting vehicle signals are no longer able to meet the safety requirements of increasingly complex automotive electronic systems and the vehicle-to-cloud communication needs of SOA (Service-Oriented Architecture) services.

[0005] In related technologies, vehicles use security protocols such as TLS (Transport Layer Security) / SSL (Secure Socket Layer) for data encryption and authentication. Traditional TLS / SSL has performance and complexity issues and poor flexibility.

[0006] For the above-mentioned problems existing in related technologies, no efficient and accurate solutions have been found yet. Summary of the Invention

[0007] The present invention provides a vehicle-to-cloud data transmission method and device, a storage medium, and an electronic device to solve technical problems in related technologies.

[0008] According to one embodiment of the present invention, a method for transmitting vehicle-cloud data is provided, which is applied in a vehicle and includes: establishing a communication channel between the vehicle and a cloud server from a data distribution service DDS component to a message queue telemetry transmission MQTT component, wherein the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server; using the communication channel to transmit MQTT messages to the cloud server, wherein the MQTT messages carry a session key between the vehicle and the cloud server; dynamically configuring security configuration parameters and flow control parameters of the communication channel according to the vehicle's quality of service QoS information; and transmitting data packets to the cloud server according to the session key, the security configuration parameters, and the flow control parameters.

[0009] Optionally, using the communication channel to transmit MQTT messages to the cloud server includes: generating a target session key for the current period locally in the vehicle, wherein the session key is a private key used by the symmetric encryption algorithm; storing the target session key in a secure hardware module of the vehicle, and deleting expired session keys of historical periods in the secure hardware module; generating an MQTT message using the target session key, and transmitting the MQTT message to the cloud server.

[0010] Optionally, using the target session key to generate an MQTT message includes: using the target session key to fill in a first message field, using a type identifier to fill in a second message field, and using a timestamp to fill in a third message field, wherein the type identifier is used to indicate the message type of the MQTT message, and the timestamp is used to verify the timeliness of the MQTT message; and using the first message field, the second message field, and the third message field to generate an MQTT message.

[0011] Optionally, dynamically configuring the security configuration parameters of the communication channel includes: reading the quality of service QoS information of the vehicle; parsing the communication environment requirements of the vehicle and the data type of the data to be transmitted based on the QoS information, wherein the data type is used to characterize the sensitivity level of the data to be transmitted; and dynamically configuring the security configuration parameters of the communication channel according to the communication environment requirements and the data type.

[0012] Optionally, dynamically configuring the security configuration parameters of the communication channel according to the communication environment requirements and the data type includes: determining whether the sensitivity level of the data type is higher than a preset level, and determining whether the communication environment requirements are for a control command transmission scenario; if the sensitivity level of the data type is higher than the preset level, enabling the session key and authentication in the communication channel, and generating a security negotiation message for the communication channel; if the sensitivity level of the data type is lower than or equal to the preset level, enabling the session key or authentication in the communication channel, and generating a security negotiation message for the communication channel; if the communication environment requirements are for a control command transmission scenario, enabling data integrity verification and authentication in the communication channel, and generating a security negotiation message for the communication channel, wherein the security negotiation message carries the security configuration parameters; and sending the security negotiation message to the cloud server based on a secure communication protocol TLS link.

[0013] Optionally, generating a security negotiation message for the communication channel includes: searching for a security configuration element that matches the communication environment requirements and the data type, wherein the security configuration element includes at least one of the following: an encryption algorithm, a key length, a verification method for identity authentication, and a verification method for data integrity verification; and using the security configuration element to generate a security negotiation message for the communication channel.

[0014] Optionally, dynamically configuring the flow control parameters of the communication channel includes: reading the quality of service QoS information of the vehicle; parsing the vehicle status information of the vehicle at the current time and the event priority of the data packet to be transmitted based on the QoS information; and configuring the following flow control parameters of the communication channel at the current time according to the vehicle status information and the event priority: bandwidth, communication frequency, and queuing priority of the data packet.

[0015] According to another embodiment of the present invention, a vehicle-cloud data transmission device is provided, which is used in a vehicle and includes: a construction module for establishing a communication channel between the vehicle and the cloud server from a data distribution service DDS component to a message queue telemetry transmission MQTT component, wherein the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server; a first transmission module for transmitting MQTT messages to the cloud server using the communication channel, wherein the MQTT message carries a session key between the vehicle and the cloud server; a configuration module for dynamically configuring security configuration parameters and flow control parameters of the communication channel according to the quality of service QoS information of the vehicle; and a second transmission module for transmitting data packets to the cloud server according to the session key, the security configuration parameters, and the flow control parameters.

[0016] Optionally, the first transmission module includes: a generation unit for generating a target session key for the current period locally in the vehicle, wherein the session key is a private key used by a symmetric encryption algorithm; a storage unit for storing the target session key in a security hardware module of the vehicle and deleting expired session keys of historical periods in the security hardware module; a transmission unit for generating an MQTT message using the target session key and transmitting the MQTT message to the cloud server.

[0017] Optionally, the generation unit includes: a filling subunit, used to fill the first message field with the target session key, fill the second message field with a type identifier, and fill the third message field with a timestamp, wherein the type identifier is used to indicate the message type of the MQTT message, and the timestamp is used to verify the timeliness of the MQTT message; a generation subunit, used to generate an MQTT message using the first message field, the second message field, and the third message field.

[0018] Optionally, the configuration module includes: a reading unit for reading the quality of service QoS information of the vehicle; a first parsing unit for parsing the communication environment requirements of the vehicle and the data type of the data to be transmitted based on the QoS information, wherein the data type is used to characterize the sensitivity level of the data to be transmitted; and a first configuration unit for dynamically configuring the security configuration parameters of the communication channel according to the communication environment requirements and the data type.

[0019] Optionally, the first configuration unit includes: a judgment subunit, used to judge whether the sensitivity level of the data type is higher than a preset level, and to judge whether the communication environment requirement is a control command transmission scenario; a generation subunit, used to enable the session key and authentication in the communication channel if the sensitivity level of the data type is higher than the preset level, and generate a security negotiation message for the communication channel; if the sensitivity level of the data type is lower than or equal to the preset level, enable the session key or authentication in the communication channel, and generate a security negotiation message for the communication channel; if the communication environment requirement is a control command transmission scenario, enable data integrity verification and authentication in the communication channel, and generate a security negotiation message for the communication channel, wherein the security negotiation message carries the security configuration parameters; a sending subunit, used to send the security negotiation message to the cloud server based on a secure communication protocol TLS link.

[0020] Optionally, the generation subunit is used to: search for a security configuration element that matches the communication environment requirements and the data type, wherein the security configuration element includes at least one of the following: an encryption algorithm, a key length, a verification method for identity authentication, and a verification method for data integrity verification; and use the security configuration element to generate a security negotiation message for the communication channel.

[0021] Optionally, the configuration module includes: a reading unit for reading the quality of service QoS information of the vehicle; a second parsing unit for parsing the vehicle status information of the vehicle at the current time and the event priority of the data packet to be transmitted based on the QoS information; a second configuration unit for configuring the following flow control parameters of the communication channel at the current time according to the vehicle status information and the event priority: bandwidth, communication frequency, and queuing priority of the data packet.

[0022] According to another aspect of an embodiment of the present application, a storage medium is further provided, which includes a stored program, and the above steps are executed when the program is run.

[0023] According to another aspect of an embodiment of the present application, an electronic device is also provided, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; wherein: the memory is used to store computer programs; the processor is used to execute the steps in the above method by running the program stored in the memory.

[0024] An embodiment of the present application also provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the steps in the above method.

[0025] Beneficial effects of the present invention:

[0026] 1. Implemented a novel security key management mechanism that enables more efficient generation, distribution, and update of security keys to ensure data confidentiality and integrity. This reduces the encryption and decryption process, lowers performance overhead, and improves vehicle communication efficiency.

[0027] 2. QoS configuration enables highly customizable security settings to adapt to vehicle-to-cloud communications based on the nature of the communication channel and communication requirements. This greatly increases communication flexibility, enabling it to better meet the needs of specific areas such as vehicle-to-cloud communications, while reducing the complexity and performance overhead of traditional TLS / SSL protocols. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0029] FIG1 is a block diagram of the hardware structure of a computer according to an embodiment of the present invention;

[0030] FIG2 is a flow chart of a method for transmitting vehicle-to-cloud data according to an embodiment of the present invention;

[0031] FIG3 is a flow chart of a vehicle-to-cloud security key management mechanism according to an embodiment of the present invention;

[0032] 4 is a flowchart of security configuration of QoS configuration according to an embodiment of the present invention;

[0033] FIG5 is a complete interactive flow chart of vehicle-cloud communication according to an embodiment of the present invention;

[0034] FIG6 is a structural block diagram of a vehicle-to-cloud data transmission device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0035] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only embodiments of a part of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of this application. It should be noted that, in the absence of conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0036] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0037] Example 1

[0038] The method embodiment provided in Example 1 of the present application can be executed in a vehicle, a computer, a server, a vehicle communication module or a similar processing device. Taking operation on a vehicle as an example, Figure 1 is a hardware structure block diagram of a vehicle in an embodiment of the present invention. As shown in Figure 1, the vehicle may include one or more (only one is shown in Figure 1) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Optionally, the above-mentioned vehicle may also include a transmission device 106 and an input and output device 108 for communication functions. It will be understood by those skilled in the art that the structure shown in Figure 1 is only for illustration and does not limit the structure of the above-mentioned vehicle. For example, the vehicle may also include more or fewer components than shown in Figure 1, or have a configuration different from that shown in Figure 1.

[0039] The memory 104 can be used to store vehicle programs, for example, software programs and modules of application software, such as a vehicle program corresponding to a method for transmitting vehicle-to-cloud data in an embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the vehicle program stored in the memory 104, thereby implementing the above-mentioned method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the vehicle via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0040] Transmission device 106 is used to receive or transmit data via a network. A specific example of such a network may include a wireless network provided by the vehicle's communications provider. In one embodiment, transmission device 106 includes a network interface controller (NIC), which can connect to other network devices via a base station to enable communication with the Internet. In another embodiment, transmission device 106 may be a radio frequency (RF) module for wireless communication with the Internet.

[0041] In this embodiment, a method for transmitting vehicle-to-cloud data is provided. FIG2 is a flow chart of a method for transmitting vehicle-to-cloud data according to an embodiment of the present invention. As shown in FIG2 , the flow chart includes the following steps:

[0042] Step S202 , establishing a communication channel between the vehicle and the cloud server from a data distribution service DDS component to a message queue telemetry transport MQTT component, wherein the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server;

[0043] The DDS (Data Distribution Service) component of this embodiment is a high-performance data communication standard, suitable for large-scale data exchange and supporting vehicle safety communications. The MQTT (Message Queuing Telemetry Transport) component is a lightweight messaging protocol used for IoT and IoV communications.

[0044] Step S204: transmitting an MQTT message to the cloud server using a communication channel, wherein the MQTT message carries a session key between the vehicle and the cloud server;

[0045] Step S206, dynamically configuring security configuration parameters and flow control parameters of the communication channel according to the vehicle's quality of service (QoS) information;

[0046] The QoS (Quality of Service) information of this embodiment can balance performance and security requirements by flexibly adjusting parameters such as bandwidth, delay, and reliability, thereby reducing performance overhead.

[0047] Step S208: Transmitting the data packet to the cloud server according to the session key, security configuration parameters, and flow control parameters.

[0048] When transmitting data packets, the session key is used to encrypt the data packets to be transmitted. Based on the security configuration parameters, the vehicle and the cloud server authenticate the data packets and verify the data integrity, and transmit the data packets to the cloud server according to the communication frequency, flow rate, and priority in the flow control parameters.

[0049] Through the above steps, a communication channel is established between the vehicle and the cloud server from the data distribution service DDS component to the message queue telemetry transmission MQTT component, wherein the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server. The communication channel is used to transmit MQTT messages to the cloud server, wherein the MQTT message carries the session key between the vehicle and the cloud server; the security configuration parameters and flow control parameters of the communication channel are dynamically configured according to the vehicle's service quality QoS information, and data packets are transmitted to the cloud server according to the session key, security configuration parameters, and flow control parameters. The QoS information can balance performance and security requirements, thereby achieving more flexible and customizable communication security, adapting to the needs of specific fields such as vehicle-cloud communication, avoiding the defect of high communication performance overhead caused by traditional encryption and decryption algorithms, and improving the efficiency of vehicle communication.

[0050] In one implementation of this embodiment, using a communication channel to transmit an MQTT message to a cloud server includes: generating a target session key for the current period locally in the vehicle, where the session key is a private key used by a symmetric encryption algorithm; storing the target session key in a secure hardware module of the vehicle, and deleting expired session keys of historical periods in the secure hardware module; generating an MQTT message using the target session key, and transmitting the MQTT message to the cloud server.

[0051] Optionally, this embodiment may also generate a session key pair, including a private key and a public key, for implementing an asymmetric encryption algorithm.

[0052] The secure hardware module of this embodiment defends against various cyberattacks, including physical and side-channel attacks. Only authorized vehicle communication modules can access and use these keys. Hardware protection ensures the confidentiality and integrity of the keys, preventing potential key leaks.

[0053] Optionally, generating an MQTT message using a target session key includes: filling a first message field with a target session key, filling a second message field with a type identifier, and filling a third message field with a timestamp, wherein the type identifier is used to indicate the message type of the MQTT message and the timestamp is used to verify the timeliness of the MQTT message; generating an MQTT message using the first message field, the second message field, and the third message field.

[0054] In an example, the payload of an MQTT message is as follows:

[0055] The "messageType" field indicates the message type and is the second message field. The "sessionKey" field carries the generated target session key and is the first message field. The "timestamp" field, which may be used to verify the timeliness of the message, is the third message field. In actual implementation, MQTT messages can be securely delivered to the MQTT server, and appropriate measures are taken to protect the confidentiality of the key.

[0056] Figure 3 is a flowchart of the vehicle-to-cloud security key management mechanism in an embodiment of the present invention. Referring to steps S301 to S303 in Figure 3 , the security key management mechanism of this embodiment includes the following steps for secure encryption of vehicle-to-cloud communications: automatic generation and distribution of security keys; automatic key rotation; and hardware-protected key storage.

[0057] Referring to steps S3011 to S3014 in FIG3 , when establishing a DDS-to-MQTT communication channel between the vehicle and the cloud platform, the vehicle system 100 can automatically generate a one-time session key and transmit it to the cloud platform 200 via the MQTT protocol. This key generation process is protected by hardware modules within the vehicle system 100 to ensure key confidentiality. Once the session key is generated, it is used for data encryption and decryption, thereby ensuring communication security. To enhance communication security, referring to step S302 in FIG3 , this embodiment introduces an automatic key rotation mechanism. Referring to steps S3021 to S3023 in FIG3 , at preset intervals, the vehicle system 100 generates a new session key (e.g., a private key) and transmits it to the cloud platform. This session key can be the private key used in a symmetric encryption algorithm, which uses the same key for encryption and decryption. Simultaneously, the previous key is discarded. This automatic key rotation mechanism not only effectively reduces the risk of key compromise but also ensures long-term communication security. The key rotation process is seamless and does not interrupt communication. In this embodiment, the generated session key is delivered to the MQTT server as the payload of a special message. To achieve this, a field can be defined in the MQTT message payload to carry the key information. To protect the generated session key, this embodiment utilizes a hardware-based key storage mechanism, as shown in step S303 of FIG3 . Referring to step S3031 of FIG3 , the generated key is stored in the secure hardware module 101 of the vehicle system 100 .

[0058] In an example of this embodiment, dynamically configuring the security configuration parameters of the communication channel includes: reading the QoS information of the vehicle; parsing the vehicle's communication environment requirements and the data type of the data to be transmitted based on the QoS information, wherein the data type is used to characterize the sensitivity level of the data to be transmitted; and dynamically configuring the security configuration parameters of the communication channel according to the communication environment requirements and the data type.

[0059] Optionally, the sensitivity level of data is divided according to the data type or data source. For example, the owner's identity information and account password information are highly sensitive data, and the others are low-sensitivity data. The multimedia data collected by the in-vehicle camera is highly sensitive data, and the data collected by other modules is low-sensitivity data.

[0060] In some embodiments, dynamically configuring security configuration parameters of a communication channel based on communication environment requirements and data types includes: determining whether the sensitivity level of the data type is higher than a preset level, and determining whether the communication environment requirements are for a control command transmission scenario; if the sensitivity level of the data type is higher than the preset level, enabling session keys and authentication in the communication channel, and generating a security negotiation message for the communication channel; if the sensitivity level of the data type is lower than or equal to the preset level, enabling session keys or authentication in the communication channel, and generating a security negotiation message for the communication channel; if the communication environment requirements are for a control command transmission scenario, enabling data integrity verification and authentication in the communication channel, and generating a security negotiation message for the communication channel, wherein the security negotiation message carries security configuration parameters; and sending a security negotiation message to a cloud server based on a secure communication protocol TLS link.

[0061] For example, encryption and authentication can be enabled for highly sensitive data transmission, while encryption or authentication can be selectively enabled for general status data. In control command transmission scenarios, enabling data integrity checks and authentication is key. Different scenarios require different security configurations to balance privacy requirements and communication efficiency.

[0062] Optionally, generating a security negotiation message for the communication channel includes: searching for a security configuration element that matches the communication environment requirements and data type, wherein the security configuration element includes at least one of the following: an encryption algorithm, a key length, a verification method for identity authentication, and a verification method for data integrity verification; and using the security configuration element to generate a security negotiation message for the communication channel.

[0063] Data packets in TLS communication links can carry security negotiation information to inform the recipient (cloud server) how to process data sent by the vehicle. The vehicle and cloud platform can negotiate the required security level, including encryption algorithms, key lengths, and authentication methods. This real-time security negotiation ensures that the data being communicated meets the latest security standards without interrupting communication.

[0064] In another example of this embodiment, dynamically configuring the flow control parameters of the communication channel includes: reading the QoS information of the vehicle; parsing the vehicle status information of the vehicle at the current time and the event priority of the data packet to be transmitted based on the QoS information; and configuring the following flow control parameters of the communication channel at the current time according to the vehicle status information and event priority: bandwidth, communication frequency, and queuing priority of the data packet.

[0065] For example, for emergency communications, the priority of relevant data can be increased to ensure rapid transmission; while in low-energy mode, communication frequency can be reduced to preserve battery life. This dynamic adjustment makes the system more adaptable, allowing it to flexibly meet varying communication needs and environmental conditions. This dynamic and adaptive flow control ensures a balance between security and performance, adapting to real-time communication needs.

[0066] Figure 4 is a flow chart of security configuration based on QoS configuration in an embodiment of the present invention. Referring to steps S401, S402, and S403 in Figure 4, the process of security configuration based on QoS configuration may include customized communication link configuration, real-time responsive security negotiation, and dynamically adaptive communication flow control.

[0067] Using the QoS configuration-based method of this embodiment, as shown in step S4011 of FIG4 , allows the vehicle and cloud platform to adjust security configuration parameters on the vehicle side in real time over the communication link. This allows each data packet in the communication link to have a specific security configuration, rather than using a global TLS / SSL protocol. The vehicle and cloud platform can selectively enable security features based on data sensitivity and communication environment requirements.

[0068] The solution of this embodiment introduces a real-time security negotiation mechanism. Referring to step S4021 and step S4022 in Figure 4, the vehicle and the cloud platform can dynamically negotiate the security configuration during communication. The steps include using a communication protocol that supports dynamic negotiation, designing a specific security negotiation message format, protecting message transmission through a secure communication protocol (such as TLS), dynamically updating the security configuration, formulating a negotiation strategy that takes into account the environment and data sensitivity, and ensuring that the negotiation process is transparent without interrupting communication. Data packets in the communication link can carry security negotiation information to inform the recipient how to process the data. The vehicle and the cloud platform can negotiate with each other on the required security level, including encryption algorithm, key length, authentication method, etc. This real-time responsive security negotiation ensures that the data in the communication meets the latest security standards without interrupting communication.

[0069] This embodiment uses a dynamically adaptive communication flow control mechanism. In the related TLS / SSL protocols, the encryption and decryption processes can introduce delays, leading to flow control issues during communication. Based on this, referring to step S4031 in FIG4 , the present invention uses QoS configuration to enable the vehicle and cloud platform to adjust communication flow control parameters, including bandwidth allocation, communication frequency, packet queuing, and priority settings, in real time based on actual needs.

[0070] FIG5 is a complete interactive flow chart of vehicle-to-cloud communication according to an embodiment of the present invention, including two aspects: security configuration based on a security key management mechanism and QoS.

[0071] On the one hand, referring to steps S501 to S513 in Figure 5 , a novel security key management mechanism is employed. This mechanism enables more efficient generation, distribution, and update of security keys to ensure data confidentiality and integrity. This security key management mechanism reduces encryption and decryption processes, lowers performance overhead, and improves vehicle communication efficiency.

[0072] On the other hand, referring to steps S514 to S518 in FIG5 , QoS configuration plays a key role. Compared with the traditional TLS / SSL protocol, this method introduces QoS-based security configuration. QoS configuration allows communication parameters such as reliability, bandwidth, latency, and persistence to be dynamically adjusted according to the needs of specific applications. Through QoS configuration, highly customizable security settings can be achieved to adapt to the communication between the vehicle and the cloud based on the nature of the communication channel and the communication requirements. This innovation greatly improves the flexibility of communication, enabling it to better meet the needs of specific areas such as vehicle-cloud communication, while reducing the complexity and performance overhead of traditional TLS / SSL protocols.

[0073] The solution in this embodiment provides a more efficient and customizable solution for secure vehicle-to-cloud communications, overcoming the performance bottlenecks and complexity of traditional in-vehicle communication systems. This approach, through innovative secure key management mechanisms and QoS configuration, delivers high performance and flexibility, ensuring the safety of vehicles and passengers, and providing a reliable communication foundation for connected vehicles and autonomous driving.

[0074] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0075] Example 2

[0076] In this embodiment, a vehicle-to-cloud data transmission device is also provided. The device is used to implement the above-mentioned embodiments and preferred implementations. The details that have been described will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and contemplated.

[0077] FIG6 is a structural block diagram of a vehicle-to-cloud data transmission device according to an embodiment of the present invention. As shown in FIG6 , the device includes:

[0078] A construction module 60 is configured to establish a communication channel between a vehicle and a cloud server from a data distribution service (DDS) component to a message queue telemetry transport (MQTT) component, wherein the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server;

[0079] a first transmission module 62 for transmitting an MQTT message to the cloud server using the communication channel, wherein the MQTT message carries a session key between the vehicle and the cloud server;

[0080] a configuration module 64, configured to dynamically configure security configuration parameters and flow control parameters of the communication channel according to the quality of service (QoS) information of the vehicle;

[0081] The second transmission module 66 is configured to transmit a data packet to the cloud server according to the session key, the security configuration parameter, and the flow control parameter.

[0082] Optionally, the first transmission module includes: a generation unit for generating a target session key for the current period locally in the vehicle, wherein the session key is a private key used by a symmetric encryption algorithm; a storage unit for storing the target session key in a security hardware module of the vehicle and deleting expired session keys of historical periods in the security hardware module; a transmission unit for generating an MQTT message using the target session key and transmitting the MQTT message to the cloud server.

[0083] Optionally, the generation unit includes: a filling subunit, used to fill the first message field with the target session key, fill the second message field with a type identifier, and fill the third message field with a timestamp, wherein the type identifier is used to indicate the message type of the MQTT message, and the timestamp is used to verify the timeliness of the MQTT message; a generation subunit, used to generate an MQTT message using the first message field, the second message field, and the third message field.

[0084] Optionally, the configuration module includes: a reading unit for reading the quality of service QoS information of the vehicle; a first parsing unit for parsing the communication environment requirements of the vehicle and the data type of the data to be transmitted based on the QoS information, wherein the data type is used to characterize the sensitivity level of the data to be transmitted; and a first configuration unit for dynamically configuring the security configuration parameters of the communication channel according to the communication environment requirements and the data type.

[0085] Optionally, the first configuration unit includes: a judgment subunit, used to judge whether the sensitivity level of the data type is higher than a preset level, and to judge whether the communication environment requirement is a control command transmission scenario; a generation subunit, used to enable the session key and authentication in the communication channel if the sensitivity level of the data type is higher than the preset level, and generate a security negotiation message for the communication channel; if the sensitivity level of the data type is lower than or equal to the preset level, enable the session key or authentication in the communication channel, and generate a security negotiation message for the communication channel; if the communication environment requirement is a control command transmission scenario, enable data integrity verification and authentication in the communication channel, and generate a security negotiation message for the communication channel, wherein the security negotiation message carries the security configuration parameters; a sending subunit, used to send the security negotiation message to the cloud server based on a secure communication protocol TLS link.

[0086] Optionally, the generation subunit is used to: search for a security configuration element that matches the communication environment requirements and the data type, wherein the security configuration element includes at least one of the following: an encryption algorithm, a key length, a verification method for identity authentication, and a verification method for data integrity verification; and use the security configuration element to generate a security negotiation message for the communication channel.

[0087] Optionally, the configuration module includes: a reading unit for reading the quality of service QoS information of the vehicle; a second parsing unit for parsing the vehicle status information of the vehicle at the current time and the event priority of the data packet to be transmitted based on the QoS information; a second configuration unit for configuring the following flow control parameters of the communication channel at the current time according to the vehicle status information and the event priority: bandwidth, communication frequency, and queuing priority of the data packet.

[0088] It should be noted that the above modules can be implemented through software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.

[0089] Example 3

[0090] An embodiment of the present invention further provides a storage medium storing a computer program, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.

[0091] Optionally, in this embodiment, the storage medium may be configured to store a computer program for performing the following steps:

[0092] S1, establishing a communication channel between a vehicle and a cloud server from a data distribution service DDS component to a message queue telemetry transport MQTT component, wherein the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server;

[0093] S2, using the communication channel to transmit an MQTT message to the cloud server, wherein the MQTT message carries a session key between the vehicle and the cloud server;

[0094] S3, dynamically configuring security configuration parameters and flow control parameters of the communication channel according to the quality of service QoS information of the vehicle;

[0095] S4. Transmitting a data packet to the cloud server according to the session key, the security configuration parameter, and the flow control parameter.

[0096] Optionally, in this embodiment, the above-mentioned storage medium may include but is not limited to: a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and other media that can store computer programs.

[0097] An embodiment of the present invention further provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0098] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0099] Optionally, in this embodiment, the processor may be configured to execute the following steps through a computer program:

[0100] S1, establishing a communication channel between a vehicle and a cloud server from a data distribution service DDS component to a message queue telemetry transport MQTT component, wherein the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server;

[0101] S2, using the communication channel to transmit an MQTT message to the cloud server, wherein the MQTT message carries a session key between the vehicle and the cloud server;

[0102] S3, dynamically configuring security configuration parameters and flow control parameters of the communication channel according to the quality of service QoS information of the vehicle;

[0103] S4. Transmitting a data packet to the cloud server according to the session key, the security configuration parameter, and the flow control parameter.

[0104] Optionally, specific examples in this embodiment may refer to the examples described in the above embodiments and optional implementation modes, and this embodiment will not be described in detail here.

[0105] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for transmitting vehicle-cloud data, characterized in that, Applied to a vehicle, including: Establish a communication channel from a Data Distribution Service (DDS) component to a Message Queuing Telemetry Transport (MQTT) component between the vehicle and a cloud server, where the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server; Transmit MQTT messages to the cloud server via the communication channel, where the MQTT messages carry a session key between the vehicle and the cloud server; Dynamically configure security configuration parameters and traffic control parameters of the communication channel according to the Quality of Service (QoS) information of the vehicle; Transmit data packets to the cloud server according to the session key, the security configuration parameters, and the traffic control parameters; 2. The method according to claim 1, characterized in that Transmitting MQTT messages to the cloud server via the communication channel includes: Generate a target session key for the current period locally on the vehicle, where the session key is a private key used by a symmetric encryption algorithm; Store the target session key in the vehicle's security hardware module and delete the expired session keys of the historical period in the security hardware module; Generate MQTT messages using the target session key and transmit the MQTT messages to the cloud server; 3. The method according to claim 2, characterized in that Generating MQTT messages using the target session key includes: Fill a first message field with the target session key, fill a second message field with a type identifier, and fill a third message field with a timestamp, where the type identifier is used to indicate the message type of the MQTT message, and the timestamp is used to verify the timeliness of the MQTT message; Generate MQTT messages using the first message field, the second message field, and the third message field; 4. The method according to any one of claims 1 to 3, characterized in that, Dynamically configuring the security configuration parameters of the communication channel includes: Read the QoS information of the vehicle; Analyze the communication environment requirements of the vehicle and the data type of the data to be transmitted based on the QoS information, where the data type is used to characterize the sensitivity level of the data to be transmitted; Dynamically configure the security configuration parameters of the communication channel according to the communication environment requirements and the data type; 5. The method according to claim 4, characterized in that, Dynamically configuring the security configuration parameters of the communication channel according to the communication environment requirements and the data type includes: Judge whether the sensitivity level of the data type is higher than a preset level, and judge whether the communication environment requirement is a control command transmission scenario; If the sensitivity level of the data type is higher than the preset level, enable the session key and authentication in the communication channel and generate a security negotiation message for the communication channel; if the sensitivity level of the data type is lower than or equal to the preset level, enable the session key or authentication in the communication channel and generate a security negotiation message for the communication channel; if the communication environment requirement is a control command transmission scenario, enable data integrity verification and authentication in the communication channel and generate a security negotiation message for the communication channel, where the security negotiation message carries the security configuration parameters; Send the security negotiation message to the cloud server based on a secure communication protocol TLS link; 6. The method according to claim 5, wherein Generating the security negotiation message for the communication channel includes: Find a security configuration element that matches the communication environment requirements and the data type, where the security configuration element includes at least one of the following: encryption algorithm, key length, authentication verification method, data integrity verification method; Generate a security negotiation message for the communication channel using the security configuration element.

7. The method according to any one of claims 1-6, characterized in that, Dynamically configure the traffic control parameters of the communication channel, including: Read the QoS information of the vehicle; Parse the vehicle status information and the event priority of the data packet to be transmitted at the current time based on the QoS information; Configure the following traffic control parameters of the communication channel at the current time according to the vehicle status information and the event priority: bandwidth, communication frequency, queuing priority of the data packet.

8. A transmission device for vehicle-cloud data, characterized in that, Applied to a vehicle, including: A construction module for establishing a communication channel between a data distribution service DDS component and a message queue telemetry transport MQTT component between the vehicle and the cloud server, where the DDS component is installed on the vehicle and the MQTT component is installed on the cloud server; A first transmission module for transmitting MQTT messages to the cloud server using the communication channel, where the MQTT messages carry the session key between the vehicle and the cloud server; A configuration module for dynamically configuring the security configuration parameters and traffic control parameters of the communication channel according to the quality of service QoS information of the vehicle; A second transmission module for transmitting data packets to the cloud server according to the session key, the security configuration parameters, and the traffic control parameters.

9. A storage medium, characterized in that, A computer program is stored in the storage medium, where the computer program is set to execute the method described in any one of claims 1 to 7 when running.

10. An electronic device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is set to run the computer program to execute the method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Communication method and related device

    CN113038461A

  • Data transmission system and method, computer equipment and storage medium

    CN116366694A

  • Vehicle cloud communication method and device and storage medium

    CN116614284A

  • Vehicle cloud data transmission method and device, storage medium and electronic device

    CN117715034A

  • Device and method for supporting quality of service in wireless communication system

    US20220386164A1