Communication method and related apparatus

By employing a dual-server architecture for identity authentication and information forwarding mechanisms, the network security risks in remote interaction between terminals and vehicles are resolved, enabling highly secure and convenient remote interaction, and enhancing user experience and system protection capabilities.

WO2026076597A9PCT designated stage Publication Date: 2026-05-15YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
YINWANG INTELLIGENT TECHNOLOGIES CO LTD
Filing Date
2024-10-09
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In existing technologies, remote interaction between terminals and vehicles poses cybersecurity risks. Public networks and vehicle cloud platforms are easily hijacked, leading to data tampering and forgery, which may result in the leakage or loss of control of vehicle privacy data, endangering public safety.

Method used

A dual-server architecture is adopted, with the first server used for issuing identity authentication credentials and the second server used for information forwarding. This dual authentication enhances security, ensures the integrity and confidentiality of interactive information, and prevents tampering and impersonation.

Benefits of technology

It improves the security of terminal-vehicle interaction, reduces the complexity of user operation, enhances the security protection of remote interaction, and improves user experience and the difficulty of system attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024123682_15052026_PF_FP_ABST
    Figure CN2024123682_15052026_PF_FP_ABST
Patent Text Reader

Abstract

A communication method and a related apparatus, which are applied to the technical fields of internet of vehicles and intelligent vehicles. In the present application, a first terminal applies for a first credential from a first server to prove its own identity to a first vehicle; interaction information sent by the first terminal to the first vehicle is signed with a first private key corresponding to a first public key in the credential to prevent tampering and forgery; moreover, the interaction information between the first terminal and the first vehicle is forwarded by means of a second server. In the present application, the first server and the second server are designed as different servers, remote security verification for the identity and permissions of a vehicle control terminal and remote communication between the vehicle control terminal and vehicles are implemented by means of the two servers, and high-level security protection is performed on remote interaction between the terminal and the vehicles, thus improving the interaction security while ensuring the convenience of the interaction.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and related apparatus Technical Field

[0001] This application relates to the fields of vehicle networking and intelligent vehicle technology, and in particular to a communication method and related device. Background Technology

[0002] As the network capabilities of smart cars enhance, mobile devices (such as smartphones and smartwatches) can interact with vehicles more extensively to facilitate the use of automotive services. In particular, remote vehicle interaction functions, such as remote vehicle control and status checks via mobile devices, bring immense convenience to consumers. Furthermore, through remote vehicle interaction, automakers and dealerships can offer more value-added services, such as online vehicle diagnostics and car-sharing, meeting people's car usage needs. However, along with convenience and benefits, remote vehicle interaction also brings significant cybersecurity and social security risks.

[0003] Secure interaction between terminals and vehicles relies on the security of public networks and vehicle-to-everything (V2X) systems, which are precisely the high-risk areas for cyberattacks. If public networks and V2X systems are compromised, the data exchanged between terminals and vehicles can be tampered with and forged. This could result in the theft of vehicle privacy data or vehicle loss, or even, in severe cases, mass loss of vehicles, endangering public safety.

[0004] Summary of the Invention

[0005] This application provides a communication method and related apparatus. The first server and the second server are designed as different servers. The first server is used to issue identity authentication credentials to the terminal, and the second server is used to forward the interaction information between the terminal and the vehicle. By using dual servers, the identity and permissions of the vehicle control terminal and the remote communication between the vehicle control terminal and the vehicle are remotely realized. The remote interaction between the terminal and the vehicle is protected by a high level of security, which ensures the convenience of the interaction while improving the security of the interaction.

[0006] In a first aspect, this application provides a communication method, comprising: sending first information to a first server, receiving a first credential from the first server, sending the first credential to a second server, and sending first interactive information to the second server. The first information includes the identity information of a first user and a first public key. The first credential includes authentication content and a first signature; the authentication content includes the first public key, and the first signature is a signature of the authentication content. The first credential is sent when the first user has authority to control a vehicle, and the first credential is used to authenticate the identity of the first terminal. The first interactive information is signed with a first private key, and the first private key and the first public key form a public-private key pair. The second server is used to forward the first credential and the first interactive information to the first vehicle, and the second server is communicatively connected to the first vehicle. The first server and the second server are different.

[0007] This communication method can be applied to a first terminal, which is a device with communication capabilities. Optionally, the communication method can be executed by a software module, a hardware module, or a combined software and hardware functional module in the first terminal, such as by a chip or processor module of the first terminal. For ease of description, the following explanation uses the first terminal as the executing entity.

[0008] In this application, the first terminal applies for a first credential to prove its identity to the first vehicle. The interactive information sent by the first terminal to the first vehicle is signed with the first private key corresponding to the first public key in the credential to prevent tampering and forgery, thereby enhancing the security of the interaction between the first terminal and the first vehicle. The information exchanged between the first terminal and the first vehicle is forwarded through a second server.

[0009] This application designs a first server that issues credentials to the terminal and a second server that forwards the interaction information between the terminal and the vehicle as two different servers. Credential issuance depends on the first server, and the interaction process depends on the second server. By isolating the first server and the second server, an attacker can only tamper with and impersonate the interaction between the first terminal and the first vehicle if he or she hijacks at least two servers, which greatly improves the security of the interaction between the first terminal and the first vehicle.

[0010] Furthermore, this application enables remote interaction between the terminal and the vehicle. The entire authentication and interaction process can be completed remotely, with fewer user-side operations. It does not rely on close-range communication between the terminal and the first vehicle, nor does it require cumbersome operations such as scanning codes or entering verification codes on the vehicle side, greatly improving the convenience of vehicle use for users.

[0011] In one possible implementation of the first aspect, the first server and the second server belong to different cloud infrastructures, or the first server and the second server are different computing instances within the same cloud infrastructure, or the first server and the second server are different software programs, or the first server and the second server are different microservices. A computing instance includes at least one of a server, an operating system, a container, or a virtual machine.

[0012] In the above implementation, the first server and the second server are isolated from each other, which increases the difficulty of attacking the system, improves the system's security performance, and ensures the safe interaction between the first terminal and the first vehicle.

[0013] Furthermore, the higher the degree of isolation between the first and second servers—for example, if they are physically completely isolated, belong to different server rooms, different data centers, or are located in different geographical locations—the stronger the network security defense capability. Conversely, the weaker the isolation between the first and second servers, the weaker the network security capability, but it still provides an isolation effect. The mutual isolation between the first and second servers ensures that an attacker's breach of one server does not automatically mean the breach of the other; the attacker must make additional effort to breach the other cloud entity, thus increasing the difficulty of the attack. Any dual-server design that provides both isolation and increased attack difficulty falls within the scope of the isolation settings described in this application.

[0014] In another possible implementation of the first aspect, the first server and the second server have different communication addresses. Different communication addresses indicate that the first server and the second server have different network locations, providing isolation from a network perspective and improving system security.

[0015] In another possible implementation of the first aspect, the first server and the second server share the same communication address but use different communication ports. For example, the first server and the second server may be different cloud services with different service interfaces, and they may be isolated from each other at the virtual service level, which can improve the security performance of the system.

[0016] In another possible implementation of the first aspect, the identity information of the first user is used by the authentication server to verify whether the first user has the authority to control the vehicle. The authentication server has a communication connection with the first server. The authentication server is different from the first server and different from the second server.

[0017] In the above implementation, an authentication server is added to verify the vehicle's authority to control the vehicle. This allows identity authentication, authority verification, and security verification of the interaction process to be implemented through three different servers, which can further increase the difficulty of attacking the system, improve the system's security, and ensure the security of the interaction between the first terminal and the first vehicle.

[0018] Furthermore, in some implementations, permission verification includes preliminary verification and secondary verification. In this case, the preliminary verification and secondary verification can be performed separately on different servers. The system can then include four isolated servers, further increasing the difficulty of attacking the system, enhancing system security, and ensuring the secure interaction between the first terminal and the first vehicle.

[0019] In another possible implementation of the first aspect, the first information further includes the identifier of the first vehicle, and the authentication content includes the identifier of the first vehicle. In the above implementation, the content notarized by the first server also includes the identifier of the first vehicle. After obtaining the first credential, the vehicle can verify whether the identifier of the first vehicle in the first credential matches its own identifier, which can further enhance the verification of the identity and permissions of the first terminal and improve the security of the interaction.

[0020] In another possible implementation of the first aspect, the method further includes: receiving first feedback information from a first vehicle, the first feedback information being forwarded by a second server, the first feedback information being used to instruct the first vehicle to request first credentials; and sending the first credentials to the second server, including: in response to the first feedback information, sending the first credentials to the second server.

[0021] In the above implementation, the first credential can be sent even if the first vehicle reports that it does not have a certificate, which supports vehicle-side feedback on whether a credential exists, improving the user experience. If the vehicle already has the first credential, there is no need to send it separately, reducing network resource consumption and further improving the user experience.

[0022] In another possible implementation of the first aspect, the first credential and the first interaction information are carried in the same message, or the first credential and the first interaction information are carried in different messages.

[0023] In another possible implementation of the first aspect, the first interactive information includes control instructions for controlling the first vehicle. In the above implementation, the first terminal can use a first private key to sign the control instructions for controlling the first vehicle, ensuring the integrity of the control instructions, preventing tampering or forgery of the control instructions, and improving the security of remote vehicle control scenarios.

[0024] In yet another possible implementation of the first aspect, the method further includes: generating a second signature based on a first private key and first interaction information; and sending the first interaction information to a second server, including sending the first interaction information and the second signature to the second server.

[0025] The above implementation provides a signature mechanism. A first terminal can generate a signature using a first private key and the interaction information, and carry this signature when sending the interaction information. Correspondingly, the receiver can verify the signature of the interaction information based on the public key and the interaction information, thereby ensuring the integrity of the interaction information and preventing it from being tampered with or forged.

[0026] In yet another possible implementation of the first aspect, the method further includes: receiving second interactive information from a first vehicle, the second interactive information being encrypted using a first public key; and decrypting the second interactive information using a first private key to obtain the plaintext of the second interactive information.

[0027] In the above implementation, the first public key authenticated by the first credential can be used to encrypt the interactive information on the vehicle side, while only the first terminal holding the first private key can decrypt the plaintext of the interactive information. This can prevent the information sent by the vehicle from being obtained by other attackers and ensure the confidentiality of the information interacting between the vehicle and the terminal.

[0028] In another possible implementation of the first aspect, the method further includes: negotiating with the first vehicle to obtain a master key, wherein during the key negotiation process, the key negotiation public key provided by the first terminal to the first vehicle is signed by the first private key.

[0029] In another possible implementation of the first aspect, the first interaction information includes a second public key. Sending the first interaction information to a second server includes: sending the second public key and a third signature to the second server, wherein the second public key is associated with a second private key and the third public key is used for key negotiation, and the third signature is a signature of the second public key based on the first private key; the second server is also used to forward the second public key and the third signature to the first vehicle.

[0030] The method also includes: receiving a third public key from the first vehicle, and obtaining a master key based on the third public key and the second private key. The third public key is used for key negotiation and is forwarded through the second server.

[0031] Furthermore, the method also includes: deriving a session key based on the master key, the session key being used to securely protect the information transmitted between the first terminal and the first vehicle.

[0032] In the above implementation, based on the certificate that has been transmitted and trusted above, the first terminal can negotiate a key with the first vehicle to obtain a master key. The master key is a symmetric key between the first vehicle and the first terminal. The master key can be used directly or indirectly to encrypt the information exchanged between the first vehicle and the first terminal. Other devices will find it difficult to obtain the encrypted messages, which makes the interaction between the first terminal and the first vehicle highly confidential, prevents the leakage of privacy data, and further improves the security of the interaction.

[0033] In another possible implementation of the first aspect, the method further includes: establishing a communication connection with the first vehicle, negotiating a master key based on the communication connection with the first vehicle, the master key being used to securely protect information transmitted between the first terminal and the first vehicle. Here, the master key can be directly used to encrypt and decrypt information, or a session key can be derived from the master key, and information can be encrypted and decrypted based on the session key.

[0034] In the above embodiments, the communication connection may include a point-to-point communication connection, without involving other devices, such as a communication connection based on short-range communication technology. Thus, the above scheme can support the first terminal and the vehicle to negotiate symmetric keys via a point-to-point communication connection. The master key can be used directly or indirectly to encrypt the information exchanged between the first vehicle and the first terminal. Other devices will find it difficult to obtain the encrypted messages, making the interaction between the first terminal and the first vehicle highly confidential, preventing the leakage of private data, and further enhancing the security of the interaction.

[0035] In yet another possible implementation of the first aspect, the method further includes: receiving third interaction information from the first vehicle, the third interaction information being encrypted using a session key; and decrypting the third interaction information using the session key to obtain the plaintext of the third interaction information.

[0036] In the above embodiment, the information sent from the first vehicle to the first terminal can be encrypted using a session key. The encrypted interactive information has a high level of confidentiality protection, further enhancing the security of the interaction.

[0037] In yet another possible implementation of the first aspect, the method further includes: sending fourth interactive information to a second server, the fourth interactive information being encrypted with a session key, the fourth interactive information including control instructions for controlling the first vehicle.

[0038] In the above embodiment, the vehicle control command sent from the first terminal to the first vehicle can be encrypted based on a session key. The encrypted vehicle control command has a high level of confidentiality protection, further enhancing the security of remote vehicle control.

[0039] Optionally, for the information sent from the first terminal to the first vehicle, the first key can still be used for signing on the basis of encryption, ensuring confidentiality while preventing the information from being tampered with, thus further enhancing security.

[0040] In yet another possible implementation of the first aspect, before receiving the first credential from the first server, the method further includes: sending a first check code to the first server, the first check code being used to verify the permissions of the first user.

[0041] In the above implementation, the first terminal can provide a check code to the first server to perform additional verification of the terminal's permissions in combination with the check code, which can improve the security performance of the system.

[0042] In another possible implementation of the first aspect, the first credential includes a digital certificate. A digital certificate is an identity verification document with a specific format that can be used to authenticate the identity of a terminal. Using a digital certificate allows for a formal, standard authentication process for the first terminal, enhancing security.

[0043] In yet another possible implementation of the first aspect, the first interaction information further includes replay verification information, which includes a timestamp and / or a freshness parameter.

[0044] Secondly, this application provides a communication method, comprising: receiving first information from a first terminal; verifying, at least based on the identity information of a first user, whether the first user has authority to control a vehicle; and, if the first user has authority to control the vehicle, sending a first credential to the first terminal. The first credential includes authentication content and a first signature, wherein the authentication content includes a first public key, and the first signature is a signature of the authentication content. The first information includes the identity information of the first user and the first public key, and the first credential is used for the first vehicle to authenticate the first terminal.

[0045] Information exchanged between the first terminal and the first vehicle is forwarded through the second server, and the first server and the second server are different.

[0046] This communication method can be applied to a first server, which is a device with communication and computing capabilities. Optionally, the method can be executed by a software module, a hardware module, or a combined software and hardware functional module in the first server, such as by a chip or processor module of the first server. For ease of description, the following explanation uses the first server as the executing entity.

[0047] In one possible implementation of the second aspect, the first server and the second server belong to different cloud infrastructures, or the first server and the second server are different computing instances within the same cloud infrastructure, or the first server and the second server are different software programs, or the first server and the second server are different microservices. A computing instance includes at least one of a server, an operating system, a container, or a virtual machine.

[0048] In another possible implementation of the second aspect, the communication addresses of the first server and the second server are different, or the communication addresses of the first server and the second server are the same but the communication ports of the first server and the second server are different.

[0049] In another possible implementation of the second aspect, the first information further includes the identifier of the first vehicle. Verifying whether the first user has permission to control the vehicle, at least based on the first user's identity information, includes: verifying whether the first user has permission to control the first vehicle based on the first user's identity information and the identifier of the first vehicle.

[0050] The above-described embodiments provide a method for verifying the vehicle control authority of a first terminal. A first server can be used to verify whether the first terminal has the authority to control the first vehicle. If the first terminal has the authority to control the first vehicle, the first server issues a first credential to the first terminal so that the identity of the first terminal can be authenticated by the first vehicle, thereby improving the security of remote interaction between the first terminal and the first vehicle.

[0051] In another possible implementation of the second aspect, the first information further includes the identifier of the first vehicle. Verifying whether the first user has permission to control the vehicle, based at least on the first user's identity information, includes: determining whether the first user's preliminary authentication has passed based on the first user's identity information and the identifier of the first vehicle; receiving a first check code from the first terminal; and comparing the first check code with the check code corresponding to the first vehicle to determine whether the first user's secondary authentication has passed. If both the preliminary and secondary authentications pass, the first user has permission to control the first vehicle.

[0052] The above implementation provides another method for verifying the vehicle control permissions of the first terminal. The initial permission verification uses the identity of the first terminal and the identifier of the first vehicle to statically verify the user's permissions. The secondary verification combines the check code provided by the first terminal to additionally verify the permissions of the first terminal. The above two-factor verification process can greatly improve the comprehensiveness of the authentication process and further enhance the security of remote interaction between the first terminal and the first vehicle.

[0053] In another possible implementation of the second aspect, the verification code corresponding to the first vehicle is an authorization verification code provided to the communication number of the owner of the first vehicle, or a preset password corresponding to the first vehicle.

[0054] In another possible implementation of the second aspect, the aforementioned preliminary verification and secondary verification can be partially or entirely performed by the authentication server. The first server can provide the information to be verified to the authentication server and receive the verification result from the authentication server. Based on the verification result, it can be determined whether the first user has the authority to control the vehicle. Here, the authentication server is different from the first server and different from the second server.

[0055] For example, verifying whether the first user has the authority to control the first vehicle includes: providing the first user's identity information to the authentication server, receiving the authentication result from the authentication server, and the authentication result being used to indicate whether the first user has the authority to control the vehicle.

[0056] As another example, verifying whether the first user has the authority to control the first vehicle includes: providing the first user's identity information and the identifier of the first vehicle to the authentication server, and receiving the authentication result from the authentication server, wherein the authentication result is used to indicate whether the first user has the authority to control the first vehicle.

[0057] For example, the first information also includes the identifier of the first vehicle. Verifying whether the first user has permission to control the vehicle, based at least on the first user's identity information, includes: determining whether the first user's preliminary authentication has passed based on the first user's identity information and the identifier of the first vehicle; receiving a first check code from the first terminal; providing the first check code to the authentication server; and receiving a secondary authentication result from the authentication server. The secondary authentication result indicates whether the first user's secondary authentication has passed. If both the preliminary and secondary authentications pass, the first user has permission to control the first vehicle. The first check code is used to compare with the check code corresponding to the first vehicle for secondary authentication.

[0058] In another possible implementation of the second aspect, the first information further includes the identifier of the first vehicle, and the authentication content also includes the identifier of the first vehicle.

[0059] In another possible implementation of the second aspect, the method further includes: receiving credential sharing information from a second user of a second terminal, receiving login information from a first user of a first terminal, and granting the first user permission to control a first vehicle. The credential sharing information includes the first user's identity information and the identifier of the first vehicle, and is used to indicate that permission to control the first vehicle is granted to the first user.

[0060] In the above implementation, a second user on the second terminal can share vehicle control permissions with a first user on the first terminal. After the second user shares credentials, the first server can authorize the first user after the first user logs in. In other words, the second user does not need to wait online in real time after sharing. The credential sharing function does not require the sharer and the shared user to be online at the same time. The sharer, the shared user, and the vehicle can be connected to the network at different times. The interaction between the shared user and the vehicle can be realized remotely in one go, which improves the convenience of use for both the sharer and the shared user.

[0061] Thirdly, this application also provides a communication method, comprising: receiving a first credential from a first terminal, verifying the first credential, receiving first interactive information from the first terminal, and verifying the signature of the first interactive information based on a first public key. The first credential includes authentication content and a first signature; the authentication content includes the first public key, and the first signature is a signature of the authentication content. The first interactive information is signed based on a first private key, and the first private key and the first public key form a public-private key pair. The first credential is provided to the first terminal by a second server, and the first credential is provided if the first user has permission to control the vehicle. The first interactive information and the first credential are forwarded by a second server, and the first server and the second server are different.

[0062] In one possible implementation of the third aspect, before receiving the first credential from the first terminal, the method further includes: sending first feedback information to the first terminal, the first feedback information being used to indicate a request for the first credential, the first feedback information being forwarded by a second server.

[0063] In another possible implementation of the third aspect, the first interaction information is used to indicate a first control operation on the first vehicle, and the method further includes: performing the first control operation if the signature of the first interaction information is verified to be valid based on the first public key.

[0064] In another possible implementation of the third aspect, the method further includes: encrypting the second interaction information with the first public key, sending the encrypted second interaction information to the first terminal, and forwarding the encrypted second interaction information to the first terminal by the second server.

[0065] In another possible implementation of the third aspect, the first interaction information includes a second public key. Receiving the first interaction information from the first terminal includes: receiving the second public key and a third signature from the first terminal, wherein the third signature is a signature of the second public key based on the first private key, and the second public key and the third signature are forwarded by the second server.

[0066] The method further includes: verifying a third signature based on a first public key and a second public key; if the verification of the third signature is successful, obtaining a master key based on the second public key and a third private key; deriving a session key based on the master key; and sending the third public key to the first terminal. The third public key is related to the third private key and is used for key negotiation; the third public key is forwarded from the second server to the first terminal.

[0067] In another possible implementation of the third aspect, the method further includes: encrypting the third interaction information with a session key, sending the encrypted third interaction information to the first terminal, and forwarding the encrypted third interaction information to the first terminal by the second server.

[0068] In another possible implementation of the third aspect, the first credential further includes an identifier of the first vehicle. The method further includes verifying whether the identifier of the first vehicle included in the first credential matches the actual identifier of the first vehicle.

[0069] Fourthly, this application provides a communication device, which includes units or modules for performing the methods described in the first aspect or any possible implementation of the first aspect.

[0070] And / or, the communication device includes a unit or module for performing the method described in the second aspect or any possible implementation of the second aspect.

[0071] And / or, the communication device includes a unit or module for performing the method described in the third aspect or any possible implementation of the third aspect.

[0072] And / or, the communication device includes a unit or module for performing the method described in the fourth aspect or any possible implementation of the fourth aspect.

[0073] For example, the communication device includes a processing unit and / or a communication unit. The processing unit is used to process information, such as generating information, encrypting, decrypting, signing, and verifying information, or performing one or more of these operations. The communication unit is used to perform one or more operations such as sending and receiving. Further, the communication unit may include a sending unit and a receiving unit, whereby the sending unit sends information (or signals) and the receiving unit receives information (or signals).

[0074] For example, the communication device is a terminal, or the communication device is included in a terminal.

[0075] As another example, the communication device is a server, or the communication device is included in the server.

[0076] As another example, the communication device is in a vehicle, or the communication device is included in a vehicle.

[0077] Fifthly, this application provides a communication device, which includes a processor and a memory. The memory is used to store computer instructions, and the processor is used to invoke the computer instructions stored in the memory to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect.

[0078] For example, the communication device is a terminal, or the communication device is included in the terminal.

[0079] As another example, the communication device is a server, or the communication device is included in the server.

[0080] As another example, the communication equipment is in a vehicle, or the communication equipment is included in a vehicle.

[0081] In one possible implementation, the processor and memory can be integrated together, or they can be set up separately.

[0082] In one possible implementation, the at least one memory is located outside the communication device.

[0083] In yet another possible implementation, the at least one memory is located within the communication device.

[0084] In another possible implementation, a portion of the memory of the at least one memory is located within the communication device, while another portion of the memory is located outside the communication device.

[0085] Sixthly, this application provides a chip including at least one processor and an interface circuit. The interface circuit is used to receive signals from other communication devices and transmit them to the processor, or to send signals from the processor to other communication devices. The processor implements the aforementioned communication method through logic circuits or executing code instructions.

[0086] For example, the processor is used to implement the method described in the first aspect or any possible implementation of the first aspect, and / or to implement the method described in the second aspect or any possible implementation of the second aspect, and / or the method described in the third aspect or any possible implementation of the third aspect.

[0087] In a seventh aspect, this application provides a terminal, which includes the communication device of the fourth aspect, the communication equipment of the fifth aspect, or the chip of the sixth aspect. The terminal is used to implement the method described in the first aspect or any possible implementation thereof.

[0088] Eighthly, this application provides a server that includes the communication device of the fourth aspect, the communication equipment of the fifth aspect, or the chip of the sixth aspect. The server is used to implement the methods described in the second aspect or any possible implementation thereof.

[0089] Ninthly, this application provides a server that includes the communication device of the fourth aspect, the communication equipment of the fifth aspect, or the chip of the sixth aspect. The server is used to implement the methods described in the third aspect or any possible implementation thereof.

[0090] In a tenth aspect, this application provides a communication system including a terminal, a first server, a second server, and a vehicle. The terminal is used to implement the method described in the first aspect or any possible implementation thereof. The first server is used to implement the method described in the second aspect or any possible implementation thereof. The second server is used to forward information exchanged between the terminal and the vehicle. The vehicle is used to implement the method described in the third aspect or any possible implementation thereof.

[0091] Eleventhly, this application provides a readable storage medium for storing a computer program that, when executed by a processor, causes a communication device including a processor to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect.

[0092] In a twelfth aspect, this application provides a computer program product that, when executed by a processor, causes a communication device including the processor to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect.

[0093] For some of the beneficial effects of the technical solutions in aspects two through twelfth of this application, please refer to the beneficial effects of the technical solutions in aspect one. Attached Figure Description

[0094] The accompanying drawings used in the description of the embodiments will be briefly introduced below.

[0095] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this application;

[0096] Figure 2 is a schematic diagram of the architecture of another communication system provided in an embodiment of this application;

[0097] Figure 3 is a schematic diagram of the architecture of another communication system provided in an embodiment of this application;

[0098] Figure 4 is a schematic diagram of the architecture of another communication system provided in an embodiment of this application;

[0099] Figure 5 is a flowchart illustrating a communication method provided in an embodiment of this application;

[0100] Figure 6 is a schematic diagram of a signature chain verification process provided in an embodiment of this application;

[0101] Figure 7 is a schematic diagram of a signature and verification process provided in an embodiment of this application;

[0102] Figure 8 is a schematic diagram of a key negotiation process provided in an embodiment of this application;

[0103] Figure 9 is a schematic diagram of another key negotiation process provided in an embodiment of this application;

[0104] Figure 10 is a flowchart illustrating another communication method provided in an embodiment of this application;

[0105] Figure 11 is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0106] Figure 12 is a schematic diagram of the structure of another communication device provided in an embodiment of this application. Detailed Implementation

[0107] The embodiments of this application will now be described in detail with reference to the accompanying drawings. For ease of understanding, some terms that may be used in this application will be introduced first.

[0108] A terminal is a device with communication capabilities, capable of communicating with other devices. In some solutions, a terminal can be used to receive user input information and / or, for outputting information, etc. Exemplarily, terminals include portable devices such as mobile phones, tablets, handheld computers, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cellular phones, and personal digital assistants (PDAs), as well as smart home devices such as smart TVs and smart cameras, wearable devices such as smart bracelets, smartwatches, and smart glasses, and extended reality (XR) devices such as augmented reality (AR), virtual reality (VR), and mixed reality (MR), and smart city devices, etc.

[0109] A certificate, also known as a digital certificate, is a digital authentication method used in internet communication to identify and authenticate the identities of parties involved. Certificates are typically issued by a Certificate Authority (CA). An applicant generates a public-private key pair (including a private key and a public key) and provides the CA with their identity and the public key from the public-private key pair. The CA then issues a certificate to the applicant corresponding to that public key. The purpose of the certificate is to prove that the applicant listed in the certificate legitimately possesses the public key listed in the certificate. The digital signature of the CA prevents attackers from forging and tampering with the certificate.

[0110] The signature mechanism works as follows: when an applicant sends information to a destination device, they use their private key to sign the information and provide a certificate issued by a CA (Certificate Authority). The destination device can verify the signature of the certificate based on the public key of the CA and use the public key in the certificate to verify the signature of the information sent by the applicant, thereby ensuring that the source of the information is indeed the applicant and that the applicant's identity is trustworthy.

[0111] A session key is a key used to securely protect transmitted information. Security protection includes one or more of the following: confidentiality protection, integrity protection, and authentication encryption. Confidentiality protection requires the use of an encryption key or an authentication encryption key. Integrity protection requires the use of an integrity protection key or an authentication encryption key.

[0112] Key negotiation is the process by which two communicating parties negotiate and obtain a key by exchanging a set of parameters. The algorithm used for key negotiation is called a key negotiation algorithm. Some exemplary key negotiation algorithms include the Diffie-Hellman key exchange (DH) algorithm, the DH (ECDH) algorithm based on elliptic curve cryptosystems (ECC), the two-basis password exponential key exchange (TBPEKE) algorithm, and Chinese national cryptographic algorithms (such as SM2). It should be noted that a key negotiation algorithm can also be viewed as a key negotiation protocol; that is, for the two communicating parties, the key negotiation algorithm defines the rules for key generation.

[0113] Key derivation refers to the process of deriving a new secret value from a given secret value. Key derivation requires the use of a key derivation function (KDF). In addition to the input secret value, the key derivation process often requires the use of fresh parameters (such as random numbers, counter values, strings, etc.) to ensure the uniqueness of the derived secret value. Generally, the specific values ​​of the fresh parameters change after each generation, ensuring that the values ​​of the fresh parameters determined each time are different from those determined previously, thus improving security. For example, a new secret value DK derived from a secret value Key can be represented as: DK = KDF(Key, Salt). Key represents the input secret value, DK is the derived new secret value, and salt represents the fresh parameters participating in the key derivation process. Of course, Key and Salt are just examples here; in actual implementations, other parameters can also participate in the key derivation process.

[0114] The terminology explained above can be applied to the examples below.

[0115] The following describes the architecture and business scenarios of a communication system to which embodiments of this application can be applied. It should be noted that the system architecture and business scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. It should be understood that as system architectures evolve and new business scenarios emerge, the technical solutions provided in this application are also applicable to similar technical problems.

[0116] Please refer to Figures 1 and 2. Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this application, and Figure 2 is a functional block diagram of a communication system provided in an embodiment of this application. The communication system 100 may include a terminal 10, a first server 20, a second server 30, and a vehicle 40.

[0117] Terminal 10 possesses communication and computing capabilities, and can communicate with the first server 20 and the second server 30. The computing capabilities of Terminal 10 are manifested in its ability to perform calculations and information processing. For example, Terminal 10 can generate public and private keys, such as the first public key and the first private key shown in Figure 2. Furthermore, the terminal can perform information processing operations such as credential application, signature generation, and information encapsulation. In some solutions, Terminal 10 may include a remote control module (as shown in Figure 1, a remote control SDK). This remote control module is used for remote interaction with vehicle 40. The remote control module may include a credential application module and a signature application module. The credential application module is used to apply for credentials that can prove the identity of Terminal 10, and the signature generation module is used to sign the interacted information based on a private key (such as the first private key). In this embodiment, the user of terminal 10 includes a first user, or terminal 10 is associated with a first user. For example, the first user may be a user logged into a remote control module. When terminal 10 communicates with other devices, the first user's identity information can be carried in the communication information. The first user's identity information may include the first user's login information, such as one or more of the following: account, password, token, etc. The account includes, but is not limited to, one or more of the following: identification (ID), communication number (such as the number in the user identification module), username, email address, etc. It should be understood that the first user's identity information described in this embodiment is collected with the user's consent, and the storage, transmission, and use of the information comply with the regulations of the current location of the communication system 100.

[0118] The first server 20 has communication and computing capabilities and can communicate with the terminal 10. In some solutions, the first server 20 can perform authentication and credential issuance. When the terminal 10 (or its user) has vehicle control authority, the first server 20 issues a first credential to the terminal 10, which proves the identity of the terminal 10. Exemplarily, the first credential is a certificate or a piece of information signed with a public key by a CA. In some possible implementations, the first credential may be generated by a CA. Further, the first server 20 is connected to a CA, or a CA may be configured within the first server 20. In this embodiment, the first credential can be used to prove the identity of the terminal 10 and also to securely protect the information exchanged between the terminal 10 and the vehicle 40. Exemplarily, the credential may support a signature mechanism. Based on the first credential, the terminal 10 signs the information sent to the vehicle 40 to prevent the exchanged information between the terminal 10 and the vehicle 40 from being counterfeited or tampered with.

[0119] The second server 30 has communication capabilities and further computing capabilities. The second server 30 can be used to forward information exchanged between the terminal 10 and the vehicle 40, including information sent from the terminal 10 to the vehicle 40 and information sent from the vehicle 40 to the terminal 10. In some possible implementations, the information transmitted between the terminal 10 and the second server 30 uses a secure channel, and the information transmitted between the second server 30 and the vehicle 40 also uses a secure channel, thus further enhancing the security of the interaction between the terminal 10 and the vehicle 40. For example, the secure channel includes a transmission channel established using a communication protocol based on transport layer security (TLS), such as a secure channel established using the TLS-based Hypertext Transfer Protocol Secure (HTTPS) protocol, or a secure channel established using the TLS-based Message Queuing Telemetry Transport (MQTT) protocol. Optionally, the second server also supports authentication and / or legitimacy verification to verify the permissions of terminal 10 or check the legitimacy of the account of the first user logged in on terminal 10, thereby further improving the security of interaction and enhancing the security performance of vehicle 40 and terminal 10.

[0120] In this embodiment, the first server 20 and the second server 30 are different servers. For example, the first server 20 and the second server 30 belong to different cloud infrastructures. Even more exemplarily, the first server 20 and the second server 30 are different computing instances within the same cloud infrastructure, wherein a computing instance includes one or more of the following: a server (or host), an operating system, a container, or a virtual machine. Even more exemplarily, the first server and the second server are different software programs. Even more exemplarily, the first server and the second server are different microservices.

[0121] Vehicle 40 is a means of transportation with mobility and communication capabilities. Vehicle 40 may include a communication module and one or more of one or more in-vehicle devices and functions, such as a vehicle lock module, windows, air conditioning, navigation, seats, in-vehicle display devices, Bluetooth, etc. Some in-vehicle devices and functions can be controlled remotely; terminal 10 can send control commands to vehicle 40 to remotely control these in-vehicle devices and functions. In other embodiments, vehicle 40 may also remotely provide vehicle status data, such as data collected by sensors (e.g., vehicle location, or monitoring images of the vehicle's surroundings) or status data reported by components in the vehicle (e.g., interior temperature, lock status, battery level, or fuel level), to terminal 10 so that the user of terminal 10 can understand the current status of vehicle 40. Information sent by the vehicle to terminal 10, such as the aforementioned vehicle status data, is also forwarded to terminal 10 via the first server 20. In this embodiment, vehicle 40 can authenticate the identity of terminal 10 based on the credentials of terminal 10. For example, a CA's certificate may be pre-set or pre-obtained in vehicle 40. This CA's certificate is used to verify the CA's signature, thereby verifying the credentials generated by the CA, such as the first credential.

[0122] It should be understood that "vehicle 40" is a vehicle in a broad sense, which can be a means of transportation (such as commercial vehicles, passenger cars, motorcycles, electric bicycles, flying cars, trains, etc.), industrial vehicles (such as forklifts, trailers, tractors, etc.), engineering vehicles (such as excavators, bulldozers, cranes, etc.), agricultural equipment (such as lawnmowers, harvesters, etc.), etc. The aforementioned "vehicle 40" can also be replaced by other networked terminals. For example, "vehicle 40" can be replaced by robots, robotic arms, smart home devices (such as security facilities, refrigerators, home gateways, televisions, curtain boxes, etc.), smart city facilities, and other remotely communicating devices. Furthermore, the "server" referred to in "first server," "second server," and "third server" and "fourth server" below is used to exemplarily describe the server-side and does not necessarily refer to an independent server host. In some solutions, some or all of the descriptions of "server" in "first server," "second server," and "third server" and "fourth server" below can be designed with other names, such as cloud entity, service example, etc. For example, the first server can be called the first cloud entity, the first service example, etc.

[0123] In the communication system shown in Figure 1, the first server 20 can communicate with the terminal 10, and the second server 30 can communicate with both the terminal 10 and the vehicle 40. This communication can be implemented based on wired communication technology and / or wireless communication technology, such as long-distance communication technology.

[0124] The aforementioned first server 20 and second server 30 involve permission verification. In some possible implementations, permission verification can be implemented by a separate server, or permission verification can include multiple verification stages, which can be performed by different servers respectively.

[0125] In some possible implementations, referring to Figure 3, the communication system 100 further includes a third server 50, which can be used to handle part or all of the verification process. The first server 20 can communicate with the third server 50, providing the third server 50 with the identity information of the first user (optionally including other information, such as vehicle 40 information, check codes submitted by terminal 10, etc.). The third server 50 verifies one or more of the first user's permissions or legitimacy, and returns the verification result to the first server 20. This decoupling or partial decoupling of permission verification and credential issuance further enhances system security and deployment flexibility. Similarly, the second server 30 can also connect to the third server 50, providing the second server 30 with permission verification and / or login verification services.

[0126] Optionally, when a third server 50 is configured, the first server 20 may retain some verification services. For example, the first server 20 may retain credential request verification, which is used to verify whether the user of terminal 10 and vehicle 40 have a binding relationship, thereby determining whether credentials can be issued to terminal 10. Furthermore, permission verification is divided into two stages: preliminary verification and secondary verification. Some verification stages can be completed by the first server 20, and some by the third server 50 (described below).

[0127] Similarly, with the third server 50 configured, some verification services can be retained in the second server 30.

[0128] In some possible implementations, referring to Figures 3 and 4, the communication system 100 also includes a fourth server 60. The fourth server 60 differs from the aforementioned first server 20, second server 30, and third server 50. The fourth server 60 is used to share some of the aforementioned verification processes or to implement part of the credential distribution process, thereby further isolating the functions provided by the servers in the communication system 100 across more servers, further increasing the difficulty of attacking the communication system 100 and enhancing system security.

[0129] Alternatively, the device responsible for issuing certificates may be a separate public key infrastructure (PKI), or the device responsible for issuing certificates may be a key management service (KMS) integrated into the server.

[0130] For example, as shown in Figure 3, the CA can be set in the fourth server 60. In this case, the generation and issuance of certificates are implemented by different servers, which further enhances the security of the system.

[0131] For example, when issuing credentials, the legitimacy and permissions of the first user need to be verified. As shown in Figure 4, the first server 20 is equipped with a credential request verification module, which is used to verify the legitimacy of the first user, such as verifying whether the first user is bound to the first vehicle 40. The third server 50 is equipped with a login verification module, which is used to verify the login status of the first user, such as verifying the account and password in the first user's identity information, or verifying the first user's login credentials, thereby verifying the first user's login status. The fourth server 60 is equipped with a CA and a secondary verification module, which is used to verify whether the check code entered in the terminal 10 is correct. As a possible example of secondary verification, the terminal 10 is designed with a check code input module, where the user can input a check code. This check code is provided to the fourth server 60 (optionally forwarded through the first server 20). The fourth server 60 compares the check code entered in the terminal with a preset check code to dynamically verify the authenticity and legitimacy of the user.

[0132] In the embodiment shown in Figure 4, the first server 20, the third server 50 and the fourth server 60 are all equipped with modules to verify the legitimacy or permissions of the first user. By using multiple separate verification modules to verify the first user multiple times, the security of the system can be further improved.

[0133] Referring to Figures 1 to 4 above, in this embodiment, terminal 10 requests a first credential from first server 20. The first credential proves the identity of terminal 10, and the signature mechanism supported by the first credential ensures the security of information exchanged between terminal 10 and vehicle 40, thereby improving the security of the interaction between the first terminal and the first vehicle. For example, terminal 10 can send signed interaction information to vehicle 40 based on a private key signature mechanism. This signature is generated based on the private key corresponding to the first credential. The signed interaction information can be forwarded to vehicle 40 via second server 30. After receiving the signed interaction information, vehicle 40 can verify the signature to prevent the interaction information from being tampered with or forged. As another example, for information sent from vehicle 40 to terminal 10, vehicle 40 can encrypt it using the public key in the first credential, and terminal 10 can decrypt the encrypted information using its own private key to obtain plaintext.

[0134] Furthermore, this application designs the first server 20 and the second server 30 as different servers. The first server 20 is used to issue credentials to the terminal, and the second server 30 is used to forward the interaction information between the terminal and the vehicle. By using dual servers, the identity and permissions of the vehicle control terminal and the remote communication between the vehicle control terminal and the vehicle are remotely verified. This provides a high level of security protection for the remote interaction between the terminal and the vehicle, ensuring the convenience of the interaction while improving the security of the interaction.

[0135] In this embodiment, the entire authentication and interaction process can be completed remotely, reducing the number of user-side operations and eliminating the need for the user to perform cumbersome operations such as scanning a code on the terminal 10 or entering a verification code on the vehicle 40 side. This greatly improves the convenience of using the vehicle for the user.

[0136] The methods provided in the embodiments of this application will be described below.

[0137] Please refer to Figure 5, which is a flowchart illustrating a communication method provided in an embodiment of this application. Optionally, this method can be implemented based on the communication system shown in Figures 1, 2, 3, or 4. The communication method shown in Figure 5 may include one or more steps from S501 to S509. It should be understood that, for ease of description, the order of S501 to S509 is used here, and it is not intended to limit the execution to the above order. This application embodiment does not limit the order of execution, the execution time, or the number of executions of the above one or more steps. Steps S501 to S509 are as follows:

[0138] Step S501: The first terminal sends first information to the first server. Correspondingly, the first server receives the first information from the first terminal.

[0139] The first terminal is a device with communication and computing capabilities, such as including a communication module and a processor. For example, the first terminal can be a mobile phone, watch, earphones, tablet, computer, or television, etc. For further details on the specific implementation of the first terminal, please refer to the aforementioned explanation of terms or the system architecture section.

[0140] The first server is a device with both communication and computing capabilities. Typically, the first server is located in a computing instance where computing resources are concentrated. The computing instance includes one or more of the following: cloud, host (such as rack server, blade server, etc.), operating system, container, or virtual machine.

[0141] The first information includes the first user's identity information and the first public key. The first user's identity information is used to identify the first user and may include the first user's own information. In some schemes, the first user belongs to the user of the first terminal; therefore, in some scenarios, the identifier of the first terminal can also be used to identify the first user. For example, the first user's identity information includes one or more of the following: the first user's identification (ID), the user's login information on the first terminal, and the information of the first terminal (e.g., the terminal's device identifier, the identifier of the user identification module inserted in the terminal, etc.). The first user's ID may include one or more of the following: the user's registration ID, communication number, etc. The login information may include one or more of the following: account, password, token, etc. The account includes, but is not limited to, one or more of the following: ID, communication number (such as the number in the user identification module), username, email address, etc. For example, a first application is installed on the first terminal, and the first user's account is logged in on the first application. The first terminal then stores the first user's identity information. It should be understood that the first user's identity information described in the embodiments of this application is obtained and stored with the user's consent, and the storage, transmission, and use of the information comply with the regulations of the current location of the first terminal.

[0142] In some possible implementations, the first user's identity information includes two parts: one part indicates the first user's identity, and the other part includes the first user's login information on the first terminal. These two parts may overlap, but their usage may differ. The first user's login information on the first terminal is primarily used to verify the first user's login, while the information indicating the first user's identity is used to participate in the certificate process and / or to verify vehicle control permissions.

[0143] The first public key is the public key in the public-private key pair generated by the first terminal. The public-private key pair also includes the first private key. Information signed with the first private key can be verified using the first public key, and information encrypted with the first public key can be decrypted using the first private key to obtain plaintext.

[0144] In some possible implementations, the first terminal generates a public-private key pair (including a first public key and a fourth private key) and sends a credential request message (such as a certificate request) to the first server. The credential request message carries the first user's identity information and the first public key. For example, the credential request message includes a certificate request file, such as a certificate signing request (CSR), which includes the first user's identity information and the first public key. The message format of the credential request message is a predefined format (such as the CSR format), ensuring that the credential request process is compliant and follows uniform regulations, thus improving system efficiency.

[0145] Optionally, the first information also includes an identifier for the first vehicle, which is used to indicate the first vehicle, such as uniquely identifying the first vehicle. For example, the first information includes one or more of the first vehicle's vehicle identification number (VIN), vehicle equipment number, etc. Optionally, the identifier for the first vehicle can be input by a user or provided to the first terminal by other devices.

[0146] In some possible implementations, the first terminal may also provide a first check code to the first server (or other server, such as the fourth server 60 shown in Figure 4) to facilitate the first server (or other server) in verifying the first terminal's permissions. Further, the first terminal may obtain the first check code before providing it. For example, the first check code may be input by the user or obtained through other means (e.g., read from SMS content or email content). Of course, the reading of SMS content or email content is implemented after obtaining the user's consent. For example, the verification code corresponding to the first vehicle may be an authorization verification code provided to the communication number (e.g., mobile phone number, email address, internal communication number, etc.) of the owner of the first vehicle, or a preset password corresponding to the first vehicle.

[0147] In some possible implementations, a secure channel is established between the first terminal and the first server, and information transmitted between them is transmitted through this secure channel. For example, the secure channel may include a secure channel established using the TLS-based HTTPS protocol.

[0148] In some possible implementations, the first terminal is a terminal associated with the owner of the first vehicle. For example, the first terminal is equipped with a remote control module, and the user account logged into the remote control module is an account associated with the owner of the first vehicle.

[0149] In some scenarios, a vehicle owner can share control of the vehicle with other users. For example, when sharing permissions, the vehicle owner can submit the account information of the person being shared with to the server through their logged-in terminal. The server can then obtain the account information of both the sharer (i.e., the vehicle owner) and the shared account information. Optionally, the shared account information can be submitted to one or more servers, such as a first server, a second server, and an authentication server (e.g., a third server and / or a fourth server). Alternatively, the shared account information can be submitted to any server (which can be pre-specified), and the information can be synchronized between servers. For instance, the shared account information can be submitted to the first server, which then synchronizes the sharer's and the shared account information to one or more other servers. Alternatively, the aforementioned account information can be replaced with user identification information or other user identity information.

[0150] Since vehicle control permissions can be shared, in some possible implementations, the first terminal is not necessarily the terminal associated with the owner of the first vehicle; for example, it could be the terminal logged into by the person whose account is being shared.

[0151] In some possible implementations, continuing with the example of a first server, the first server may receive credential sharing information from a second user on a second terminal. This credential sharing information is used to instruct the first user to be granted permission to control the first vehicle. Further, the first server receives login information from the first user on the first terminal and grants the first user permission to control the first vehicle.

[0152] Similarly, the first server can be replaced by other servers, such as a second server or an authentication server. Alternatively, the first server can synchronize the credential sharing information with other servers. In this way, the first user has the authority to control the first vehicle, and during subsequent certificate applications and interactions with the vehicle, the server can verify the user's permissions based on the credential sharing information.

[0153] It should be understood that the description of the user of the first terminal is intended to exemplify some applicable scenarios for vehicle remote control and is not intended to limit the identity of the user of the first terminal. The issued credentials include a unique vehicle identifier, ensuring that the credentials are limited to controlling a specific vehicle.

[0154] Step S502: The first server verifies whether the first user has the authority to control the vehicle, based at least on the first user's identity information.

[0155] The first server may have permission verification capabilities, or the first server may be connected to a device with authentication functions (such as an authentication server), so that the first server can verify whether the first user has the permission to control the vehicle, at least based on the first user's identity information.

[0156] In some possible solutions, the operation performed by the second server to verify whether the first user has the authority to control the vehicle is an account check process and does not involve verifying the authority to control a specific vehicle. Optionally, the first server may verify one or more of the following: whether the first user's account is correct, whether the user is a legitimate user, whether the user's account login status is normal, and whether the user is a non-violation user, to determine whether the first user has the authority to control the vehicle. For example, the first user's identity information includes the account and password (or token) entered by the first user on the first terminal. The first server verifies the correctness of the first user's account on the first terminal, that is, verifies the password or token uploaded by the first terminal. If the first user's account and password are correct or the token is valid, the first user has the authority to control the vehicle.

[0157] In some possible solutions, the second server verifies whether the first user has permission to control the vehicle, including verifying whether the first user has permission to control the first vehicle. As one possible implementation, the first server verifies whether the first user has permission to control the first vehicle based on the first user's identity information and the identifier of the first vehicle. For example, the first user's identity information includes the account and password (or token) entered by the first user on the first terminal. The first server verifies the correctness of the first user's account on the first terminal, that is, verifies the password or token uploaded by the first terminal, and checks the vehicles that the first user's account can control. When the first user's account can control the first vehicle, the first user has permission to control the first vehicle.

[0158] In some other possible solutions, the second server connects to a device with authentication capabilities (such as an authentication server). The second server can utilize the authentication server to complete part or all of the verification process.

[0159] The foregoing has introduced several possible solutions. For ease of understanding, the following are three possible permission verification methods exemplified below:

[0160] In one method, the first server possesses authentication capabilities, enabling it to verify whether the first user has the authority to control the vehicle. For example, the first server can verify the correctness of the first user's identity information and check the vehicles the first user can control to confirm their authority. Alternatively, the first server can obtain the first user's identity information, determine the first user's account status, and verify whether the first user has the authority to control the vehicle.

[0161] Furthermore, the first server can further verify whether the first user has the authority to use the first vehicle.

[0162] For example, the first server can obtain permission information for multiple vehicles. Each vehicle's permission information corresponds to a vehicle identifier, and each vehicle's permission information includes the identity information of the user who can control that vehicle. The first server can query the permission information of the first vehicle based on its identifier and compare it to see if the first user is a user who can control that vehicle. If the first user is a user who can control that vehicle, the first user has the permission to control the first vehicle; otherwise, the first user does not have the permission to control the first vehicle.

[0163] As another example, the first server may query the identifiers of user-controllable vehicles and compare whether the identifiers of user-controllable vehicles include the identifier of the first vehicle. If the identifiers of user-controllable vehicles include the identifier of the first vehicle, the first user has the authority to control the first vehicle; otherwise, the first user does not have the authority to control the first vehicle.

[0164] Method two involves two authentication phases: a preliminary authentication phase and a secondary authentication phase. If both phases pass, the first user has the authority to control the vehicle; otherwise, the first user does not. In some scenarios, this two-phase authentication method is referred to as two-factor authentication.

[0165] As one possible design, initial authentication involves static permission verification based on permission information (such as permission information corresponding to the vehicle or the user), while secondary authentication involves dynamic authentication based on a verification code. For example, dynamic authentication can be performed by sending a verification code to the user's communication number (e.g., the mobile phone number bound to the owner of the first vehicle) or instant messaging number (e.g., email address, APP internal ID, etc.), or by prompting the user to enter a predefined password, thereby enhancing security.

[0166] In one possible implementation, the first server performs preliminary authentication based on the first user's identity information (i.e., determines whether the preliminary authentication passes), receives a check code from the first terminal, and performs secondary authentication based on the check code. If both the preliminary and secondary authentications pass, the first user has the authority to control the vehicle. If either the preliminary or secondary authentication fails, the first user does not have the authority to control the vehicle. Optionally, if the preliminary authentication fails, the first user does not have the authority to control the vehicle, and secondary authentication may not be performed.

[0167] For example, the check code may include an input SMS verification code, email verification code, password, etc. received by the first terminal.

[0168] In one possible implementation, the first server may perform preliminary authentication based on the identity of the first user and the information of the first vehicle, and receive a first check code from the first terminal. Secondary authentication is then performed based on the first check code and the verification code corresponding to the first vehicle. If both preliminary and secondary authentication pass, the first user has the authority to control the vehicle. If either preliminary or secondary authentication fails, the first user does not have the authority to control the vehicle. Optionally, if preliminary authentication fails, the first user does not have the authority to control the first vehicle, and secondary authentication may not be performed.

[0169] Optionally, the verification code corresponding to the first vehicle is either an authorization verification code provided to the communication number of the owner of the first vehicle, or a preset password corresponding to the first vehicle. In the former case, the first server can send the authorization verification code to the communication number of the owner of the first vehicle, and the first user can enter the authorization verification code in the first terminal and provide it to the first server for verification (i.e., the first verification code), thus verifying the identity of the first user. In the latter case, the first vehicle can be pre-defined with a password (i.e., a preset password), and the first user can enter the preset password in the first terminal and provide it to the first server for verification (i.e., the first verification code).

[0170] In method three, the first server can provide input information to the authentication server and request authentication. The authentication server can obtain the authentication result based on the input information and feed it back to the first server. For example, the authentication server is, for instance, the third server 50 shown in Figure 3. The first server can determine whether the first user has the authority to control the vehicle based on the authentication result, and further determine whether the first user has the authority to control the first vehicle.

[0171] In other words, the aforementioned authentication process can be completed by the authentication server. The authentication server can obtain the authentication result based on the information provided by other servers, so as to indicate whether the specified user has the authority to control the vehicle (or even control the specified vehicle).

[0172] In one possible implementation, the first server provides the identity information of the first user to the authentication server and receives the authentication result from the authentication server. The authentication result is used to indicate whether the first user has the authority to control the vehicle.

[0173] In one possible implementation, the first server provides the authentication server with the identity information of the first user and the identifier of the first vehicle, and receives the authentication result from the authentication server. The authentication result is used to indicate whether the first user has the authority to control the first vehicle.

[0174] In one possible implementation, when the permission verification includes multiple authentication stages, all authentication stages can be implemented by an authentication server, or some authentication stages can be implemented by the authentication server and some authentication stages can be implemented by a second server.

[0175] For example, the authorization verification includes two stages: preliminary authentication and secondary authentication. Preliminary authentication is performed by the first server, and secondary authentication by the authentication server. In the preliminary authentication stage, the first server determines whether the first user's preliminary authentication has passed based on the first user's identity information and the first vehicle's identifier. In the secondary authentication stage, the first server receives a first check code from the first terminal, provides the first check code to the authentication server, and receives the secondary authentication result from the authentication server. The secondary authentication result indicates whether the first user's secondary authentication has passed. If both preliminary and secondary authentication pass, the first user has the authority to control the first vehicle. The first check code is used to compare with the check code corresponding to the first vehicle for secondary authentication. This example assumes that the first server still receives the first check code in the secondary authentication stage. In actual implementation, the first terminal's first check code can also be directly submitted to the authentication server; in this case, the first server does not need to receive the first check code from the first terminal, nor does it need to provide the first check code to the authentication server.

[0176] For example, the authorization verification includes two stages: preliminary authentication and secondary authentication. Preliminary authentication is performed by the first server, and secondary authentication by the authentication server. In the preliminary authentication stage, the first server provides the authentication server with the identity information of the first user and the identifier of the first vehicle, and receives the preliminary authentication result, which indicates whether the preliminary authentication of the first user has passed. In the secondary authentication stage, the first server receives a first check code from the first terminal and determines whether the secondary authentication has passed based on the first check code and the verification code of the first vehicle. If both preliminary and secondary authentication pass, the first user has the authority to control the first vehicle.

[0177] It should be understood that the above authentication process is only an example, and there may be more or fewer authentication processes in specific implementations.

[0178] Step S503: The first server sends the first credential to the first terminal. Accordingly, the first terminal receives the first credential from the first server.

[0179] The first credential includes authentication content and a first signature. The authentication content includes a first public key, and the first signature is a signature of the authentication content. The signature of the authentication content is a signature of a trusted authority; for example, the first signature is a signature generated based on the trusted authority's private key and the authentication content. For example, the trusted authority is a CA, a public key infrastructure (PKI) including a CA, or a key management service (KMS). Optionally, the trusted authority can be integrated into the first server, or the trusted authority can be set up independently of the first server, for example, set up in the fourth server 60 shown in Figure 3 or Figure 4.

[0180] For example, the first credential is a digital certificate, which is a credential issued by a trusted authority to prove that the applicant (i.e., the first user or the first terminal) legally possesses the first public key in the certificate; that is, the authentication content includes the first public key. The digital certificate also includes the trusted authority's signature on the authentication content. In some schemes, the certificate also includes the identifier of the first vehicle, and optionally includes one or more of the following: the applicant's information, the trusted authority's information, and the certificate's validity period.

[0181] For another example, the first credential is a predefined piece of information that has been signed. That is, the first terminal can send first data or a first file to the first server. The first data and the first file can be predefined or customized by the first terminal. The first server can sign the first data or the first file using the private key of a trusted authority, and the terminal can subsequently verify the signature in the certificate using the public key of the trusted authority.

[0182] Optionally, the first credential may include the identifier of the first vehicle, such as a VIN code. In this case, the first credential is limited to controlling a specific vehicle or group of vehicles, such as the first vehicle.

[0183] Step S504: The first terminal sends the first credential to the second server. Accordingly, the second server receives the first credential from the first terminal.

[0184] The second server is used to forward the first credential to the first vehicle. Of course, the first credential can also be understood as being sent to the first vehicle, but sending it to the first vehicle requires sending it to the second server so that the second server can forward the first credential to the first vehicle.

[0185] In some possible implementations, the first terminal also provides the first user's identity information to the second server, enabling the first server to verify the first user's legitimacy and / or vehicle control permissions. That is, the second server also needs to verify the first user's legitimacy and / or vehicle control permissions; if the verification passes, the second server can forward the first credential to the first vehicle. This verification process can refer to the verification process on the first server side, and will not be described in detail here.

[0186] In some possible implementations, step S504 is not necessarily required. For example, the first vehicle may check whether it possesses the credentials of the first terminal and send feedback information to the first terminal, indicating a request for the first credential. This feedback information may be forwarded to the first terminal via a second server. Upon receiving the first feedback information from the first vehicle, the first terminal, in response, sends the first credential to the second server.

[0187] In some other possible implementations, the first terminal may periodically or non-periodically send the first credential to the vehicle (e.g., by default in the first message of each dialogue session). Of course, the above two implementations can be combined; for example, the first terminal may periodically or non-periodically provide the first credential to the first vehicle, and in addition to the above mechanism, if feedback information is received from the first vehicle, the first credential may be provided to the first vehicle again.

[0188] Step S505: The first vehicle receives the first credential.

[0189] The first server forwards the first credential to the first vehicle, and the first vehicle can receive the first credential forwarded by the first server from the first terminal.

[0190] Step S506: The first vehicle verifies the first credential.

[0191] The first credential is signed using the private key of a trusted authority. The first vehicle can verify the signature of the first credential using the public key of the trusted authority. The first credential can prove the identity of the second terminal, and the authentication content of the first credential includes the first public key.

[0192] In some possible implementations, the public key of the trusted authority may be pre-installed in the first vehicle or provided to the first vehicle by other devices (such as a CA, a first server, a second server, or a first terminal). For example, the first vehicle may have a pre-installed root CA certificate containing the public key of the trusted authority, which can be used to verify the credentials of a terminal (such as the first terminal).

[0193] Step S507: The first terminal sends first interaction information to the second server. Correspondingly, the second server receives the first interaction information from the first terminal.

[0194] The first terminal can generate the first interaction information and send it to the first vehicle. The first interaction information is then forwarded to the first vehicle via the second server. For example, the first interaction information includes vehicle control commands, such as commands to unlock the vehicle or set the operating status of onboard components. More exemplarily, the first interaction information may include information exchanged with the vehicle, such as public keys or security parameters (e.g., algorithm parameters, freshness parameters) exchanged during key negotiation.

[0195] Optionally, the first interactive information may include one or more of the following: replay verification information, such as fresh parameters or timestamps, to defend against replay attacks.

[0196] The first interaction information is signed with the first private key. Specifically, the first terminal can generate a signature of the first interaction information based on the first private key and the first interaction information, and the signature of the first interaction is sent to the first vehicle along with the first interaction information.

[0197] In some possible cases, when the first terminal needs to send the first interaction information and the first credential, the first interaction information and the first credential may be sent in the same message or in different messages.

[0198] It should be understood that the first interaction information refers to the interaction information sent by the first terminal to the first vehicle, and is not intended to refer to a specific piece of interaction information. For example, the first interaction information may include multiple pieces of interaction information.

[0199] Step S508: The first vehicle receives the first interactive information.

[0200] The first server forwards the first interactive information to the first vehicle, and the first vehicle can receive the first interactive information forwarded by the first server from the first terminal.

[0201] Step S509: The first vehicle verifies the signature of the first interaction information based on the first public key.

[0202] The first vehicle, based on the first public key in the verified first credential, can verify the signature of the first interaction information, thereby checking the integrity of the first interaction information. Please refer to Figure 6, which illustrates a signature chain verification process provided in an embodiment of this application. The first vehicle verifies the first credential based on the public key in the root CA certificate (i.e., the CA's public key). If the verification of the first credential passes, the first credential is valid, and the first vehicle can obtain the authentication content in the first credential, which includes the first public key. Based on the first public key, the first terminal can verify the integrity of the interaction information from the first terminal.

[0203] Please refer to Figure 7, which is a schematic diagram of the signing and verification process. As shown in Figure 7(a), the sender, such as the first terminal, sends a message including interaction information and a signature of the interaction information. The signature of the interaction information is obtained by signing the interaction using the first private key. As shown in Figure 7(b), the receiver, such as the first vehicle, receives a message that includes interaction information and a signature of the interaction information. The first vehicle uses the first public key to verify the signature of the interaction information and obtains a check value. If the interaction information and its signature have not been tampered with, the interaction information received by the receiver and the check value obtained from the verification should be consistent. Therefore, when the first vehicle compares the check value with the content of the interaction information, it indicates that the verification is successful, the interaction information has not been tampered with, and the integrity check is successful. Conversely, if the first vehicle compares the check value with the content of the interaction information, it indicates that the verification is unsuccessful, the interaction information or its signature has been tampered with, and the integrity check is unsuccessful.

[0204] In one possible implementation, the first interaction information includes interaction information C1, which includes a vehicle control command. The first vehicle receives the first interaction information and, if the first interaction information passes verification, executes the vehicle control command to control onboard components or functions within the first vehicle. For example, the vehicle control command includes turning on the front air conditioning and adjusting it to a specified temperature. After receiving the vehicle control command, the first vehicle controls the corresponding onboard components to operate, causing the front air conditioning to turn on and adjust to the specified temperature.

[0205] In some possible implementations, the first vehicle can negotiate a master key (described below) with the first terminal. Based on the master key, information between the first vehicle and the first terminal can be secured, further enhancing the privacy of the interacting information. Optionally, the master key can be directly used for information security protection, or the master key can be used to derive a session key, which is then used for security protection. Further, during the key negotiation process, information sent from the first terminal to the first vehicle can be signed with a first private key, enabling the first vehicle to verify the authenticity of the information's source. For example, in some schemes, the first interactive information may include information used for key negotiation, such as one or more of the following: the first terminal's public key, parameters of the key negotiation algorithm determined by the first terminal (e.g., a prime number p and a random number g as shown below), and fresh parameters used during key derivation.

[0206] In some cases, the information exchanged between the first vehicle and the first terminal during the key negotiation process can be forwarded through a second server. In other cases, the key negotiation process between the first terminal and the first vehicle can be achieved through a point-to-point communication connection. For example, the first terminal and the first vehicle can establish a connection through short-range communication technology, and the first terminal and the first vehicle can exchange parameters during the key negotiation process through this communication connection to determine the master key (i.e., the negotiated key).

[0207] In the embodiment shown in Figure 5, the first server and the second server are designed as different servers. The first server is used to issue authentication credentials to the terminal, and the second server is used to forward the interaction information between the terminal and the vehicle. By using dual servers, the identity and permissions of the vehicle control terminal and the remote communication between the vehicle control terminal and the vehicle are remotely verified. This provides a high level of security protection for the remote interaction between the terminal and the vehicle, ensuring the convenience of the interaction while improving its security.

[0208] This application embodiment achieves secure interaction between the terminal and the vehicle through credentials and signature mechanisms. The entire authentication and interaction process can be completed remotely, with fewer user-side operations. It does not rely on close-range communication between the terminal and the first vehicle, nor does it require cumbersome operations such as scanning codes or entering verification codes on the vehicle side, greatly improving the convenience of vehicle use for users.

[0209] The aforementioned method mentions that key negotiation can be performed between the first terminal and the first vehicle. Two possible key negotiation processes are described below with reference to Figures 8 and 9. The embodiments shown below can be combined with the aforementioned embodiments. It should be noted that the order of steps in the flowcharts provided in this application is merely an example; in specific implementations, the execution order of steps may be designed differently.

[0210] Please refer to Figure 8, which is a schematic diagram of a key negotiation process provided in an embodiment of this application. The specific steps are as follows:

[0211] Step 81: The first terminal determines the second private key and the second public key.

[0212] The second private key and the second public key are parameters generated by the first terminal for the key negotiation process.

[0213] In one possible implementation, the second public key is calculated based on the second private key; that is, the second public key is associated with the second private key. It's important to note that the second private key and the second public key here are the public and private keys used in the key negotiation process. The second private key is typically stored locally on the first terminal, while the second public key is provided to the other side of the key negotiation, i.e., the first vehicle. In some schemes, the public and private keys provided by the same side during the key negotiation process can be considered as a public-private key pair, such as the second public key and the second private key forming a public-private key pair.

[0214] To facilitate understanding, the following describes a key negotiation process using the DH algorithm as an example. The first terminal determines a second private key 'a' and a second public key 'A' based on a prime number 'p' and a random number 'p'. The second public key 'A' is calculated as follows: A = g a mod p

[0215] Here, mod represents the modulo operation, and the values ​​of prime numbers p and random numbers p are usually large.

[0216] Step 82: The first terminal sends the second public key to the first vehicle.

[0217] Optionally, the second public key may be forwarded through a second server. For example, the first terminal sends interaction information C3 to the second server, and interaction information C3 includes the second public key.

[0218] Optionally, the second public key or the interaction information C3 is signed with the first private key. Of course, the interaction information C3 includes the signature of the second public key, and the signing of the interaction information C3 with the first private key ensures that the second public key is also signed with the first private key.

[0219] For example, the first terminal signs the second public key based on the first private key to obtain the second signature, and the interaction information C3 includes the second public key and the signature of the second public key.

[0220] [According to Rule 91, amended 28.11.2024] Step 83 (optional): The first vehicle verifies the signature of the second public key.

[0221] When the second public key is signed with the first private key, the first vehicle can verify the signature using the first public key in the credential, thereby confirming the origin of the second public key and preventing man-in-the-middle attacks from affecting the key negotiation process.

[0222] Step 84: The first vehicle determines the third private key and the third public key.

[0223] Similarly, the third private key and the third public key are parameters generated by the first vehicle for the key negotiation process. In one possible implementation, the third public key is calculated based on the third private key; that is, the third public key is associated with the third private key. It is important to note that the third private key and the third public key here are the public and private keys used in the key negotiation process. In some schemes, the public and private keys provided by the same side during the key negotiation process can be a public-private key pair, such as the third public key and the third private key. The third private key is typically stored locally on the first vehicle, while the third public key is provided to the other side of the key negotiation, i.e., the first terminal.

[0224] The following example uses the DH algorithm. The first vehicle determines the third private key b, and the second vehicle determines the third public key B based on the prime number p and the random number p. The third public key B is calculated as follows: B = gb mod p

[0225] Here, mod represents the modulo operation, and the values ​​of prime number p and random number g are usually large.

[0226] Step 85: The first vehicle obtains the master key based on the second public key and the third private key.

[0227] The master key is the key obtained through negotiation. Taking the DH algorithm as an example, on the first vehicle side, the master key DH key is calculated as follows: DH key = A b mod p = (g a mod p)mod p=g ab mod p

[0228] Step 86: The first vehicle sends the third public key to the first terminal. Correspondingly, the first terminal receives the third public key from the first vehicle.

[0229] Optionally, the third public key may be forwarded through the second server. For example, the third terminal sends interaction information C4 to the second server, and interaction information C4 includes the third public key.

[0230] Optionally, the third public key or the interactive information C4 is encrypted using the first public key. Accordingly, the first terminal can use the first private key to decrypt the ciphertext of the third public key (or the ciphertext of the interactive information C4) to obtain the third public key.

[0231] Step 87: The first terminal obtains the master key based on the third public key and the second private key.

[0232] The master key is the key obtained through negotiation. Taking the DH algorithm as an example, on the first terminal side, the master key DH key is calculated as follows: DH key = B a mod p = (g b mod p) a mod p = g ab mod p

[0233] In this scenario, if an attacker wants to obtain the private key 'a' of the first terminal using A, g, and p, the formula for calculating 'a' is: a = log0 g A Modulo p: Since there is no fast algorithm for logarithmic operations, and prime numbers p and random numbers g are usually large, it is difficult for an attacker to obtain 'a' using the second public key A, prime number p, and random number g through logarithmic and modulo operations. Therefore, the master key obtained through the DH algorithm is secure.

[0234] It can be seen that, assuming the information exchanged between the first terminal and the first vehicle has not been tampered with, the master key calculated by the first terminal and the first vehicle based on the public key provided by the other party and their own private key is consistent.

[0235] Of course, the DH algorithm above is just an example. In the actual implementation, the master key obtained by the first terminal and the first vehicle using other key negotiation algorithms is also consistent if the information has not been tampered with. Moreover, other key negotiation algorithms are also more difficult to crack, ensuring the practicality of key negotiation.

[0236] The first terminal and the first vehicle can further securely protect the information exchanged between them based on the master key. This security protection includes one or more of encryption, integrity protection, and authentication encryption. Optionally, the master key can be directly used for information security protection, or the master key can be used to derive a session key, which is then used for security protection. The following section, in conjunction with Figure 8, describes one such security protection process.

[0237] [According to Rule 91, Corrected 28.11.2024] Step 88, the first terminal derives the session key.

[0238] The first terminal derives a session key from the master key. The session key includes one or more of the following: encryption key, integrity protection key, and authentication encryption key.

[0239] For example, the first terminal can derive a session key by combining the master key with fresh parameters. Fresh parameters are used to ensure that, for example, fresh parameters may include random numbers, counter values, predefined strings, etc., which will not be described in detail here.

[0240] [According to Rule 91 Correction 28.11.2024] Step 89, First vehicle derives session key.

[0241] The first vehicle and the first terminal can derive a symmetric session key using the same method and the same input information.

[0242] [Correction 28.11.2024 according to Rule 91] Optionally, the session key can be used to encrypt information exchanged between the first terminal and the first vehicle. Steps 810 and 811 are described below in conjunction with these steps.

[0243] [Correction 28.11.2024 according to Rule 91] Step 810: The first vehicle sends interactive information C2 to the first terminal. Accordingly, the first terminal receives the interactive information C2 from the first vehicle.

[0244] The interactive message C2 can be encrypted using a session key. Optionally, the interactive message C2 can be forwarded through a second server.

[0245] [According to Rule 91, Corrected 28.11.2024] Step 811, the first terminal uses the session key to decrypt the encrypted interactive information C2.

[0246] [Correction based on Rule 91, 28.11.2024] Of course, steps 810 and 811 are described using the example of the first vehicle sending the first terminal's interactive information C2 after encryption. In some embodiments, the interactive information C5 sent by the first terminal to the first terminal can also be encrypted using a session key. It should be noted that the process of session key encryption and the process of signing using the first private key can be combined. For example, the first terminal can encrypt the interactive information C5 to obtain the ciphertext of the interactive information C5, and generate a signature based on the key of the interactive information C5 and the first private key. In this case, the signing mechanism can ensure the integrity of the interactive information C5, while the session key encryption can ensure the confidentiality of the interactive information C5, thereby further improving the security of the interaction process.

[0247] In the key negotiation process shown in Figure 8, the information exchanged between the first terminal and the first vehicle is forwarded by the second server. However, in some schemes, key negotiation and session key determination may not involve the second server. For example, this can be achieved through a communication connection between the first terminal and the first vehicle, which can be implemented using wireless communication technology and / or wired communication technology. The wireless communication technology may include short-range communication technology or long-range communication technology. Short-range communication technologies include one or more of the following: SparkLink (or Near Link), 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), and ultra-wideband (UWB). Long-range communication technologies include one or more of the following: communication technology based on long term evolution (LTE), 5th generation mobile networks (or 5th generation wireless systems, 5th-Generation, abbreviated as 5G or 5G technology), global system for mobile communications (GSM), general packet radio service (GPRS), and universal mobile telecommunications system (UMTS).

[0248] Please refer to Figure 9, which is a schematic diagram of another key negotiation process provided in an embodiment of this application. A point-to-point communication connection, such as a short-range communication connection, can be established between the first terminal and the first vehicle through communication technology. Key negotiation can be achieved between the first terminal and the first vehicle based on this point-to-point communication connection. The specific steps are as follows:

[0249] [Correction 28.11.2024 according to Rule 91] Step 91: The first terminal determines the second private key and the second public key.

[0250] [Correction 28.11.2024 according to Rule 91] Step 92: The first terminal sends the second public key to the first vehicle. Accordingly, the first vehicle receives the second public key from the first terminal.

[0251] Specifically, the first terminal can send the second public key to the first vehicle through a communication connection with the first vehicle.

[0252] [Corrected according to Rule 91 28.11.2024] Step 93: The first vehicle determines the third private key and the third public key.

[0253] [Correction 28.11.2024 according to Rule 91] Step 94: The first vehicle obtains the master key based on the second public key and the third private key.

[0254] [According to Rule 91, Corrected 28.11.2024] Step 95: The first vehicle sends the third public key to the first terminal.

[0255] Specifically, the first vehicle can send a third public key to the first terminal through a communication connection with the first terminal.

[0256] [Correction 28.11.2024 according to Rule 91] Step 96: The first terminal obtains the master key based on the third public key and the second private key.

[0257] The above illustrates several possible implementations. For ease of understanding, one possible implementation is described below with reference to Figure 10. It should be understood that some concepts and logic in the example shown in Figure 10 can be found in the descriptions of the embodiments and their possible designs shown above.

[0258] Please refer to Figure 10, which is a flowchart illustrating another communication method provided in an embodiment of this application. The communication method includes the following steps:

[0259] Step S1001: The first terminal obtains the login information of the first user.

[0260] Specifically, the first user can log in with their own account information on the first terminal. The first terminal then obtains the first user's login information.

[0261] Optionally, step S1001 is optional. For example, in some scenarios, login information has already been saved after the last login, so there is no need to retrieve the login information again. It should be understood that login information can be collected with the user's consent, and the processes of collection, transmission, and storage comply with the relevant provisions of local laws and regulations.

[0262] Step S1002: The first terminal generates the first public key and the first private key.

[0263] In some possible implementations, the first terminal checks its own device and, in the absence of a certificate, generates a public-private key pair to request a certificate.

[0264] Step S1003: The first terminal sends a certificate request to the first server. Accordingly, the first server receives the certificate request from the first terminal.

[0265] The certificate application, such as a CSR certificate application, may include the identity information of the first user and a first public key. Furthermore, the certificate application may also include the identifier of the first vehicle, which serves as a unique identifier for the first vehicle and can be used to verify whether the first terminal has the authority to control the first vehicle.

[0266] Furthermore, the certificate application documents may include a first vehicle identifier, which can be entered into the certificate for vehicle-side authorization verification. Moreover, the certificate signature protection including the first vehicle identifier prevents tampering and forgery.

[0267] Optionally, this example uses certificate application. In some schemes, the first terminal may not need to apply for a certificate. For example, the first terminal only provides custom data or files to the second server. This custom data or file is signed with the private key of PKI (or KMS), and the first vehicle uses the public key of PKI (KMS) to verify the signature.

[0268] Step S1004: The first server issues a certificate via PKI.

[0269] In this context, PKI stands for Trusted Certificate Authority, and the first server can generate terminal certificates through PKI. Alternatively, PKI can be replaced by KMS or CA.

[0270] In one possible implementation, the first server verifies the identity information of the first user (e.g., checks the correctness of the first user's account login information) and verifies the vehicle that the first user can control. Upon verifying that the first user's account information is correct and that the user can control the first vehicle, the first server issues a certificate via PKI.

[0271] Alternatively, the first server may not verify the legitimacy of the first user, but instead provide the first user's identity information to an authentication server (such as the third server 50 shown in Figure 3), which then checks the legitimacy of the user's account. In this implementation, three different server clouds actually participate in the verification process, which can further enhance the security of remote interactions.

[0272] In some possible implementations, before issuing a certificate, the PKI can add two-factor authentication (i.e., two-factor authentication) to further verify whether the operation is performed by the authorized person (not an attacker applying for the certificate), in addition to verifying the login information of the first user (such as account password or token). The following are two exemplary implementation examples of two-factor authentication:

[0273] As a possible example, PKI sends an SMS from the authentication server (such as the fourth server 60) to the mobile phone number associated with the account logged in by the first user (e.g., the mobile phone number of the account owner), requesting the user to enter a verification code on the first terminal and submit it to the authentication server for comparison. If the comparison is successful, PKI issues a certificate.

[0274] As another possible example, each account holder can reserve a password. When the first user applies for a certificate, the first user needs to enter an additional remote control password. The PKI can compare the password entered by the first user with the reserved password. If they match, the PKI issues a certificate. Optionally, this password is different from the account password.

[0275] Step S1005: The first server sends a certificate to the first terminal. Accordingly, the first terminal receives the certificate from the first server.

[0276] Step S1006: The first terminal sends a vehicle control command and certificate to the second server. Correspondingly, the second server receives the vehicle control command and certificate from the first terminal.

[0277] Specifically, the first terminal can acquire remote control commands for the vehicle. These commands can be generated based on user input or other detection and scheduling strategies. For example, the user can remotely control the first vehicle to unlock, activate sentry mode, or perform other vehicle control operations via the first terminal. Furthermore, the first terminal can be configured with vehicle protection strategies, such as automatically turning on the vehicle's air conditioning when the interior temperature exceeds 70°C.

[0278] The remote control command is signed with the first private key, and the first terminal can send the signed vehicle control command along with the command itself. In other words, the first terminal sends the vehicle control command and its signature to the second server.

[0279] As one possible implementation, the certificate is not sent with every vehicle control command. For example, the first terminal sends the certificate when it first interacts with the first vehicle. Alternatively, the first terminal sends the certificate to the first vehicle if the first vehicle reports to the first terminal that it does not have the first terminal's certificate.

[0280] Optionally, when it is necessary to send certificate-controlled vehicle commands, there are several scenarios for sending certificates and vehicle control commands:

[0281] In scenario 1, a separate message is used to send the certificate to the first vehicle. The vehicle control command is carried in a separate message.

[0282] Scenario 2: Attach a certificate to the message containing the vehicle control command. Furthermore, the first terminal can attach the certificate with each message sent, or it can attach the certificate only when communicating with the first vehicle for the first time.

[0283] Scenario 3: The first terminal first sends a vehicle control command to the first vehicle. If it receives a notification from the first vehicle indicating that it does not have a certificate, the first terminal then reissues the certificate to the first vehicle.

[0284] Understandably, this example uses a vehicle control command to represent one possible interaction. In a more concrete implementation, the first terminal can also send other non-vehicle control command interaction information to the first vehicle.

[0285] In some possible implementations, the vehicle control commands and / or interaction information may also include replay verification information, such as timestamps or fresh parameters, which are used to prevent replay attacks. Fresh parameters may include one or more of the following: random numbers, counter values, etc.

[0286] Step S1007: The second server checks the legitimacy of the first user and the legitimacy of the first vehicle.

[0287] For example, when the second server receives a vehicle control command from the first terminal for the first vehicle, it verifies the legitimacy of the account of the first user associated with the first terminal. Typically, the first terminal sends the vehicle control command along with the identity information of the first user obtained from the first terminal. The second server can then check the legitimacy of the first user based on this identity information. For instance, the first user's identity information may include their login account, password, or token, which can be used to verify the legitimacy of the first user.

[0288] Furthermore, the first server is also used to check the legitimacy of the first vehicle, such as verifying the identification of the first vehicle and determining whether the first vehicle is in a remotely controllable state.

[0289] Step S1008: The second server forwards the vehicle control command and certificate to the first vehicle. Accordingly, the first vehicle receives the vehicle control command and certificate from the first terminal.

[0290] As one possible implementation, if the legitimacy of the first user and the legitimacy of the first vehicle are verified, the second server forwards the vehicle control command to the first vehicle. Furthermore, if the first terminal sends a certificate, the second server forwards the certificate to the first vehicle.

[0291] Optionally, the second server does not modify the contents of the vehicle control commands and certificates. For example, the second server may pass through the vehicle control commands and certificates.

[0292] Step S1009: First vehicle inspection certificate.

[0293] For example, the first vehicle verifies the signature of the first terminal's certificate using a pre-configured PKI CA root certificate or a pre-configured CA public key. Further, if the verification of the first terminal's certificate passes, the first vehicle saves the first terminal's certificate (including the first public key). In some solutions, the first terminal's certificate may correspond to both the first terminal's identifier and the first user's identifier. Further, each terminal and each user account may correspond to one certificate.

[0294] Step S1010: First vehicle verification and control command.

[0295] Specifically, the first public key in the certificate of the first terminal of the first vehicle verifies the integrity of the vehicle control command. Optionally, when the vehicle control command (or interaction information) carries replay verification information, such as a timestamp or fresh parameters, the first vehicle can verify the replay verification information to avoid replay attacks.

[0296] Furthermore, if the integrity of the vehicle control command is verified, the first vehicle executes step S1011, as follows:

[0297] Step S1011: The first vehicle performs vehicle control operations based on the vehicle control command.

[0298] In some possible implementations, the method further includes one or more steps S1012 to S1015, as detailed below:

[0299] Step S1012: The first vehicle and the first terminal negotiate the key.

[0300] Step S1013: The first terminal derives the session key based on the master key.

[0301] Step S1014: The first vehicle derives the session key based on the master key.

[0302] Step S1015: The first vehicle sends interactive information C2 encrypted with the session key to the first server.

[0303] Step S1015: The first terminal decrypts the encrypted interactive information C2.

[0304] For related descriptions, please refer to the descriptions shown in Figures 8 and 9.

[0305] The methods of the embodiments of this application have been described in detail above. The apparatus of the embodiments of this application is provided below.

[0306] It should be understood that the division of units in the apparatus provided in this application embodiment is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units in the apparatus can be implemented by a processor calling software; for example, the apparatus includes a processor connected to a memory, which stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit of the apparatus. The processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is either internal to the apparatus or external to it. Alternatively, the units in the device can be implemented as hardware circuits. The functionality of some or all units can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the above units is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through a configuration file, thereby achieving the functionality of some or all of the above units. All units of the above device can be implemented entirely through processor-invoked software, entirely through hardware circuits, or partially through processor-invoked software with the remaining parts implemented through hardware circuits.

[0307] In this application embodiment, a processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a type of microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. These logical relationships of hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as a type of ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0308] As can be seen, each unit in the above device can be one or more processors (or processing circuits) configured to implement the above methods, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.

[0309] Furthermore, the units in the above devices can be integrated in whole or in part, or they can be implemented independently. In one implementation, these units are integrated together as a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or implementing the functions of the units in the device. The at least one processor may be of different types, such as CPU and FPGA, CPU and artificial intelligence processor, CPU and GPU, etc.

[0310] Several possible devices are listed below.

[0311] Please refer to Figure 11, which is a schematic diagram of a communication device provided in an embodiment of this application. Optionally, the communication device 110 can be an independent device, such as a terminal, server, vehicle, etc. Alternatively, the communication device 110 can also be a component in an independent device (such as a node), such as a chip or integrated circuit. The communication device 110 is used to implement the aforementioned communication method, such as the communication method shown in any one or more embodiments shown in Figures 4, 8, 9, or 10.

[0312] As shown in Figure 11, the communication device 110 includes at least two of the following: a transmitting unit 1101, a processing unit 1102, and a receiving unit 1103. The transmitting unit 1101 performs one or more operations such as sending, receiving, transmitting, and establishing a connection, and further includes other operations for implementing the communication method. The processing unit 1102 performs one or more operations such as processing, calculating, signing, verifying, issuing, checking, determining, generating, updating, encrypting, and decrypting, and further includes other operations for implementing the communication method. The receiving unit 1103 performs one or more operations such as receiving, responding, and acquiring, and further includes other operations for implementing the communication method.

[0313] In one possible design, the communication device 110 includes a transmitting unit 1101 and a receiving unit 1103, and may further include a processing unit 1102. The communication device 110 is used to implement the method on the first terminal side of the aforementioned communication method.

[0314] In one possible implementation, the sending unit 1101 is used to send first information to the first server, the receiving unit 1103 is used to receive the first credential from the first server, and the sending unit 1101 is also used to send the first credential to the second server and send the first interaction information to the second server.

[0315] In another possible implementation, the receiving unit 1103 is further configured to receive first feedback information from the first vehicle, which is forwarded by the second server, and the first feedback information is used to instruct the first vehicle to request the first credential. The sending unit 1101 is further configured to send the first credential to the second server in response to the first feedback information.

[0316] In another possible implementation, processing unit 1102 is used to generate a second signature based on the first private key and the first interaction information. Sending unit 1101 is further used to send the first interaction information and the second signature to a second server.

[0317] In another possible implementation, the receiving unit 1103 is further configured to receive second interactive information from the first vehicle, the second interactive information being encrypted using the first public key. The processing unit 1102 is further configured to decrypt the second interactive information using the first private key to obtain the plaintext of the second interactive information.

[0318] In another possible implementation, the sending unit 1101, the processing unit 1102, and the receiving unit 1103 are further configured to: negotiate with the first vehicle to obtain a master key.

[0319] In another possible implementation, the sending unit 1101 is further configured to send a second public key and a third signature to a second server, wherein the second public key is associated with a second private key and the third public key is used for key negotiation, and the third signature is a signature of the second public key based on the first private key. The second server is further configured to forward the second public key and the third signature to the first vehicle.

[0320] The receiving unit 1103 is also used to receive a third public key from the first vehicle, and obtain a master key based on the third public key and the second private key. The third public key is used for key negotiation and is forwarded through the second server.

[0321] Processing unit 1102 is also used to derive session key based on master key, and session key is used to securely protect information transmitted between first terminal and first vehicle.

[0322] In another possible implementation, the sending unit 1101, the processing unit 1102, and the receiving unit 1103 are further configured to: establish a communication connection with the first vehicle, negotiate a master key based on the communication connection with the first vehicle, and use the master key to securely protect the information transmitted between the first terminal and the first vehicle.

[0323] In another possible implementation, the receiving unit 1103 is further configured to receive third interactive information from the first vehicle, the third interactive information being encrypted with a session key. The processing unit 1102 is further configured to decrypt the third interactive information using the session key to obtain the plaintext of the third interactive information.

[0324] In another possible implementation, the sending unit 1101 is further configured to send fourth interactive information to the second server, the fourth interactive information being encrypted with a session key, and the fourth interactive information including control instructions for controlling the first vehicle.

[0325] In another possible implementation, the sending unit 1101 is further configured to send a first check code to the first server, the first check code being used to verify the permissions of the first user.

[0326] In one possible design, the communication device 110 includes a transmitting unit 1101, a receiving unit 1103, and a processing unit 1102. The communication device 110 is used to implement the method on the first server side of the aforementioned communication method.

[0327] In one possible implementation, the receiving unit 1103 is used to receive first information from the first terminal, and the processing unit 1102 is used to verify whether the first user has the authority to control the vehicle, at least based on the first user's identity information. The sending unit 1101 is used to send a first credential to the first terminal if the first user has the authority to control the vehicle. The first credential includes authentication content and a first signature; the authentication content includes a first public key, and the first signature is a signature of the authentication content. The first information includes the first user's identity information and the first public key, and the first credential is used for the first vehicle to authenticate the first terminal.

[0328] In another possible implementation, the first information further includes the identifier of the first vehicle. The processing unit 1102 is used to verify whether the first user has the authority to control the first vehicle based on the identity information of the first user and the identifier of the first vehicle.

[0329] In another possible implementation, the first information further includes the identifier of the first vehicle. Processing unit 1102 is used to determine whether the first user's preliminary authentication has passed based on the first user's identity information and the identifier of the first vehicle. Receiving unit 1103 is further used to receive a first check code from the first terminal, and processing unit 1102 is further used to compare the first check code with the check code corresponding to the first vehicle to determine whether the first user's secondary authentication has passed. If both preliminary and secondary authentication pass, the first user has the authority to control the first vehicle.

[0330] In another possible implementation, the preliminary verification and secondary verification described above may be partially or entirely performed by the authentication server. The communication device 110 may provide the information to be verified to the authentication server and receive the verification results from the authentication server. Based on the verification results, it can be determined whether the first user has the authority to control the vehicle.

[0331] For example, the sending unit 1101 is further configured to provide the identity information of the first user to the authentication server, and the receiving unit 1103 is further configured to receive the authentication result from the authentication server, the authentication result being used to indicate whether the first user has the authority to control the vehicle.

[0332] As another example, the sending unit 1101 is further configured to provide the authentication server with the identity information of the first user and the identifier of the first vehicle, and the receiving unit 1103 is further configured to receive the authentication result from the authentication server, the authentication result being used to indicate whether the first user has the authority to control the first vehicle.

[0333] In another possible implementation, the receiving unit 1103 is further configured to: receive credential sharing information from a second user of a second terminal, and receive login information from a first user of a first terminal. The processing unit 1102 is further configured to grant the first user permission to control the first vehicle. The credential sharing information includes the identity information of the first user and the identifier of the first vehicle, and is used to indicate that permission to control the first vehicle is granted to the first user.

[0334] In another possible design, the communication device 110 includes a processing unit 1102 and a receiving unit 1103, and may further include a transmitting unit 1101. The communication device 110 is used to implement the method on one side of the first vehicle in the aforementioned communication method.

[0335] In one possible implementation, the receiving unit 1103 is used to receive a first credential from the first terminal, the processing unit 1102 is used to verify the first credential, the receiving unit 1103 is also used to receive first interaction information from the first terminal, and the processing unit 1102 is used to verify the signature of the first interaction information based on the first public key.

[0336] In one possible implementation, the sending unit 1101 is used to send first feedback information to the first terminal, the first feedback information being used to indicate a request for first credentials, and the first feedback information is forwarded by the second server.

[0337] In another possible implementation, the processing unit 1102 is further configured to perform a first control operation if the signature of the first interaction information is verified to be valid based on the first public key.

[0338] In another possible implementation, the processing unit 1102 is further configured to encrypt the second interactive information using the first public key, send the encrypted second interactive information to the first terminal, and the encrypted second interactive information is forwarded to the first terminal by the second server.

[0339] In another possible implementation, the receiving unit 1103 is further configured to receive a second public key and a third signature from the first terminal, wherein the third signature is a signature of the second public key based on the first private key, and the second public key and the third signature are forwarded by the second server.

[0340] Processing unit 1102 is further configured to verify a third signature based on the first public key and the second public key. If the verification of the third signature is successful, a master key is obtained based on the second public key and the third private key, and a session key is derived based on the master key. Sending unit 1101 is further configured to send the third public key to the first terminal. The third public key is related to the third private key and is used for key negotiation. The third public key is forwarded from the second server to the first terminal.

[0341] In another possible implementation, the processing unit 1102 is further configured to encrypt the third interactive information using a session key, and the sending unit 1101 is further configured to send the encrypted third interactive information to the first terminal, wherein the encrypted third interactive information is forwarded to the first terminal by the second server.

[0342] In another possible implementation, the processing unit 1102 is also used to verify whether the identifier of the first vehicle included in the first credential is consistent with the actual identifier of the first vehicle.

[0343] Please refer to Figure 12, which is a schematic diagram of another communication device provided in an embodiment of this application. The communication device 120 can be an independent device, such as one or more of a terminal, server, or vehicle, or it can be a component included in an independent device, such as a chip, software module, or integrated circuit. The communication device 120 may include at least one processor 1201 and a communication interface 1202. Optionally, it may also include at least one memory 1203. Further optionally, it may also include a connection line 1204, wherein the processor 1201, the communication interface 1202, and / or the memory 1203 are connected through the connection line 1204, and / or communicate with each other through the connection line 1204 to transmit control signals and / or data signals. Exemplarily, the connection line may include a bus.

[0344] in:

[0345] Processor 1201 is a module that performs arithmetic and / or logical operations, and may specifically include one or more of the following modules: filter, modem, power amplifier, low noise amplifier (LNA), baseband processor, radio frequency processor, radio frequency circuit, central processing unit (CPU), application processor (AP), microcontroller unit (MCU), electronic control unit (ECU), graphics processing unit (GPU), microprocessor unit (MPU), application specific integrated circuit (ASIC), image signal processor (ISP), digital signal processor (DSP), field programmable gate array (FPGA), complex programmable logic device (CPLD), or coprocessor, etc.

[0346] The communication interface 1202 can be used to provide information input or output to the at least one processor, or to receive signals sent from the outside and / or send signals to the outside.

[0347] For example, communication interface 1202 may include interface circuitry.

[0348] For example, the communication interface 1202 may include a wired link interface such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, general wireless transmission, vehicle short-range communication technology and other short-range wireless communication technologies, etc.).

[0349] Optionally, the communication interface 1202 may also include a radio frequency transmitter, an antenna, etc. When the communication interface 1202 includes an antenna, the number of antennas can be one or more.

[0350] As one possible design, if the communication device 120 is a standalone device, the communication interface 1202 may include a receiver and a transmitter. The receiver and transmitter may be the same component or different components. When the receiver and transmitter are the same component, this component may be referred to as a transceiver.

[0351] As another possible design, if the communication device 120 is a chip or circuit, the communication interface 1202 may include an input interface and an output interface. The input interface and the output interface may be the same interface or they may be different interfaces.

[0352] Alternatively, the functions of the communication interface 1202 can be implemented by a transceiver circuit or a dedicated transceiver chip.

[0353] The memory 1203 provides storage space, in which data such as the operating system and computer programs can be stored. The memory 1203 can be one or a combination of several of the following: random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).

[0354] The functions and actions of each module or unit in the communication device 120 listed above are merely illustrative examples.

[0355] Each functional unit in the communication device 120 can be used to implement the aforementioned communication method, such as the communication method shown in Figure 5, Figure 8, Figure 9 or Figure 10.

[0356] Optionally, the processor 1201 may be a processor specifically designed to execute the aforementioned methods (for ease of distinction, referred to as a dedicated processor), or a processor that executes the aforementioned methods by calling a computer program (for ease of distinction, referred to as a dedicated processor). Optionally, at least one processor may include both dedicated processors and general-purpose processors.

[0357] Optionally, if the communication device 120 includes at least one memory 1203, and the processor 1201 implements the aforementioned communication method by calling a computer program, the computer program can be stored in the memory 1203.

[0358] This application also provides a chip, which includes logic circuitry and a communication interface. The communication interface is used to receive or transmit signals; the logic circuitry is used to receive or transmit signals through the communication interface. The chip is used to implement the aforementioned communication methods, such as the communication methods shown in Figures 5, 8, 9, or 10.

[0359] This application also provides a computer-readable storage medium storing instructions that, when executed on at least one processor (or communication device), implement the aforementioned communication method, such as the communication method shown in Figures 5, 8, 9, or 10.

[0360] This application also provides a computer program product, which includes computer instructions for implementing the aforementioned communication methods, such as the communication methods shown in Figures 5, 8, 9, or 10.

[0361] This application also provides a terminal, which includes the aforementioned communication device 110 and / or communication equipment 120.

[0362] This application also provides a server that includes the aforementioned communication device 110 and / or communication equipment 120.

[0363] This application also provides a vehicle that includes the aforementioned communication device 110 and / or communication equipment 120.

[0364] It should be noted that, in the embodiments of this application, the terms "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design scheme described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0365] In the embodiments of this application, "at least one" refers to one or more items, and "more than one" refers to two or more items. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items.

[0366] For example, at least one of a, b, or c can be represented as: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, and c can be single or multiple. "AND / OR" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects have an "OR" relationship.

[0367] Furthermore, unless otherwise stated, the use of ordinal numbers such as "first" and "second" in the embodiments of this application is for distinguishing multiple objects and is not for limiting the order, sequence, priority, or importance of multiple objects. For example, "first server" and "second server" are merely for convenience in describing different servers in different implementations, but do not indicate that their importance, structure, etc., are completely different.

[0368] In the above embodiments, the term "when..." can be interpreted, depending on the context, as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". The above descriptions are merely optional embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.

[0369] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

Claims

1. A communication method, characterized in that, Applied to a first terminal, the method includes: Send first information to the first server, the first information including the identity information of the first user and the first public key; Receive a first credential from the first server, the first credential including authentication content and a first signature, the authentication content including the first public key, the first signature being a signature of the authentication content, the first credential being sent if the first user has the authority to control the vehicle; The first credential is sent to a second server, which forwards the first credential to the first vehicle. The second server is in communication connection with the first vehicle, and the first credential is used to authenticate the identity of the first terminal. Send first interaction information to the second server, the second server is used to forward the first interaction information to the first vehicle, the first interaction information is signed by the first private key, the first private key and the first public key are a public-private key pair; The first server is different from the second server.

2. The method according to claim 1, characterized in that, The first server and the second server belong to different cloud infrastructures. Alternatively, the first server and the second server may be different computing instances within the same cloud infrastructure, and the computing instance may include at least one of a server, an operating system, a container, or a virtual machine. Alternatively, the first server and the second server may be different software programs; Alternatively, the first server and the second server may be different microservices.

3. The method according to claim 1 or 2, characterized in that, The identity information of the first user is used by the authentication server to verify whether the first user has the authority to control the vehicle. The authentication server has a communication connection with the first server. The authentication server is different from the first server, and the authentication server is different from the second server.

4. The method according to any one of claims 1-3, characterized in that, The first information also includes the identifier of the first vehicle, and the authentication content includes the identifier of the first vehicle.

5. The method according to any one of claims 1-4, characterized in that, The method further includes: Receive first feedback information from the first vehicle, the first feedback information being forwarded by the second server, the first feedback information being used to instruct the first vehicle to request the first credential; Sending the first credential to the second server includes: In response to the first feedback information, the first credential is sent to the second server.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: A second signature is generated based on the first private key and the first interaction information; Sending the first interactive information to the second server includes: The first interaction information and the second signature are sent to the second server. The first interaction information includes control instructions for controlling the first vehicle.

7. The method according to any one of claims 1-6, characterized in that, The method further includes: Receive second interactive information from the first vehicle, the second interactive information being encrypted with the first public key; The first private key is used to decrypt the second interaction information to obtain the plaintext of the second interaction information.

8. The method according to any one of claims 1-7, characterized in that, The first interaction information includes a second public key, and sending the first interaction information to the second server includes: The second public key and the third signature are sent to the second server. The second public key is associated with the second private key and the third public key is used for key negotiation. The third signature is a signature of the second public key based on the first private key. The second server is also used to forward the second public key and the third signature to the first vehicle. The method further includes: Receive a third public key from the first vehicle, the third public key being used for key negotiation, and the third public key being forwarded through the second server; Based on the third public key and the second private key, the master key is obtained; A session key is derived from the master key, and the session key is used to securely protect the information transmitted between the first terminal and the first vehicle.

9. The method according to claim 8, characterized in that, The method further includes: Receive third interaction information from the first vehicle, the third interaction information being encrypted by the session key; The session key is used to decrypt the third interaction information to obtain the plaintext of the third interaction information.

10. The method according to any one of claims 1-9, characterized in that, Before receiving the first credential from the first server, the method further includes: A first check code is sent to the first server, and the first check code is used to verify the permissions of the first user.

11. The method according to any one of claims 1-10, characterized in that, The first credential includes a digital certificate.

12. The method according to any one of claims 1-11, characterized in that, The first interactive information also includes replay verification information, which includes a timestamp and / or freshness parameters.

13. A communication method, characterized in that, Applied to a first server, the method includes: Receive first information from the first terminal, the first information including the identity information of the first user and the first public key; At least based on the identity information of the first household, verify whether the first user has the authority to control the vehicle; When the first user has the authority to control the vehicle, a first credential is sent to the first terminal. The first credential includes authentication content and a first signature. The authentication content includes the first public key, and the first signature is a signature of the authentication content. The first credential is used by the first vehicle to authenticate the first terminal, and the information exchanged between the first terminal and the first vehicle is forwarded through the second server. The first server is different from the second server.

14. The method according to claim 13, characterized in that, The first server and the second server belong to different cloud infrastructures. Alternatively, the first server and the second server may be different computing instances within the same cloud infrastructure, and the computing instance may include at least one of a server, an operating system, a container, or a virtual machine. Alternatively, the first server and the second server may be different software programs; Alternatively, the first server and the second server may be different microservices.

15. The method according to claim 13 or 14, characterized in that, The first information also includes the identifier of the first vehicle; Based at least on the identity information of the first user, verify whether the first user has the authority to control the vehicle, including: Based on the identity information of the first user and the identifier of the first vehicle, verify whether the first user has the authority to control the first vehicle.

16. The method according to claim 13 or 14, characterized in that, The first information also includes the identifier of the first vehicle; Based at least on the identity information of the first user, verify whether the first user has the authority to control the vehicle, including: Based on the identity information of the first user and the identification of the first vehicle, determine whether the preliminary authentication of the first user has been passed; Receive the first check code from the first terminal; Compare the first check code with the check code corresponding to the first vehicle to determine whether the second authentication of the first user has passed. If the initial authentication is successful and the second authentication is successful, the first user has the authority to control the first vehicle.

17. The method according to claim 16, characterized in that, The verification code corresponding to the first vehicle is either an authorization verification code provided to the communication number of the owner of the first vehicle, or a preset password corresponding to the first vehicle.

18. The method according to claim 13 or 14, characterized in that, The step of verifying whether the first user has the authority to control the first vehicle includes: Provide the authentication server with the identity information of the first user; The authentication result is received from the authentication server, and the authentication result is used to indicate whether the first user has the authority to control the vehicle. The authentication server is different from the first server and different from the second server.

19. The method according to claim 13 or 14, characterized in that, The first information also includes the identifier of the first vehicle; Based at least on the identity information of the first user, verify whether the first user has the authority to control the vehicle, including: Based on the identity information of the first user and the identification of the first vehicle, determine whether the preliminary authentication of the first user has been passed; Receive the first check code from the first terminal; The first check code is provided to the authentication server. The first check code is used to compare with the check code corresponding to the first vehicle for secondary authentication. The authentication server is different from the first server and different from the second server. Receive a secondary authentication result from the authentication server, the secondary authentication result being used to indicate whether the second authentication of the first user has passed; If the initial authentication is successful and the second authentication is successful, the first user has the authority to control the first vehicle.

20. The method according to any one of claims 13-19, characterized in that, The first information also includes the identifier of the first vehicle, and the authentication content also includes the identifier of the first vehicle.

21. The method according to any one of claims 13-20, characterized in that, The method further includes: The system receives credential sharing information from a second user on a second terminal. The credential sharing information includes the identity information of the first user and the identifier of the first vehicle. The credential sharing information is used to indicate that the first user is granted permission to control the first vehicle. Receive login information from the first user on the first terminal; Grant the first user permission to control the first vehicle.

22. A communication method, characterized in that, Applied to a first vehicle, the method includes: Receive a first credential from a first terminal, the first credential including authentication content and a first signature, the authentication content including the first public key, and the first signature being a signature of the authentication content; Verify the first credential; Receive first interactive information from the first terminal, the first interactive information is signed based on the first private key, the first private key and the first public key are a public-private key pair; Verify the signature of the first interaction information based on the first public key; The first credential is provided to the first terminal by the second server, and the first credential is provided when the first user has the authority to control the vehicle. The first interaction information and the first credential are forwarded by the second server, and the first server is different from the second server.

23. The method according to claim 22, characterized in that, Before receiving the first credential from the first terminal, the method further includes: A first feedback message is sent to the first terminal, the first feedback message being used to indicate a request for the first credential, and the first feedback message is forwarded by the second server.

24. The method according to claim 22 or 23, characterized in that, The first interactive information is used to indicate a first control operation on the first vehicle, and the method further includes: If the signature of the first interaction information is verified to be valid based on the first public key, the first control operation is executed.

25. The method according to any one of claims 22-24, characterized in that, The method further includes: The second interactive information is encrypted using the first public key; The encrypted second interaction information is sent to the first terminal, and the encrypted second interaction information is provided by the second service. The server forwards the message to the first terminal.

26. The method according to claim 22 or 23, characterized in that, The first interaction information includes a second public key, and receiving the first interaction information from the first terminal includes: The system receives a second public key and a third signature from the first terminal, wherein the third signature is a signature of the second public key based on the first private key, and the second public key and the third signature are forwarded by the second server. The method further includes: Verify the third signature based on the first public key and the second public key; If the third signature is verified to be valid, the master key is obtained based on the second public key and the third private key; Derive a session key based on the master key; A third public key is sent to the first terminal. The third public key is related to the third private key and is used for key negotiation. The third public key is forwarded to the first terminal by the second server.

27. The method according to claim 26, characterized in that, The method further includes: The third interactive information is encrypted using the session key; The encrypted third interaction information is sent to the first terminal, and the encrypted third interaction information is forwarded to the first terminal by the second server.

28. The method according to any one of claims 22-27, characterized in that, The first credential also includes the identifier of the first vehicle; the method further includes: Verify whether the identifier of the first vehicle included in the first credential matches the actual identifier of the first vehicle.

29. A communication system, characterized in that, The communication system includes a first terminal, a first server, a second server, and a first vehicle. The first terminal is used to perform the method according to any one of claims 1-12. The first server is configured to perform the method according to any one of claims 13-21. The second server is used to forward the information exchanged between the first terminal and the first vehicle; The first vehicle is used to perform the method according to any one of claims 22-28.

30. A communication device, characterized in that, The communication device includes a processing unit and a communication unit. The communication device is used to perform the method according to any one of claims 1-12, or to perform the method according to any one of claims 13-21, or to perform the method according to any one of claims 22-28.

31. A terminal, characterized in that, The terminal includes a processor and a memory. The memory provides storage space for storing computer instructions. The processor is used to invoke computer instructions stored in the memory to perform the method as described in any one of claims 1-12.

32. A server, characterized in that, The server includes a processor and memory. The memory provides storage space for storing computer instructions. The processor is used to invoke computer instructions stored in the memory to perform the method as described in any one of claims 13-21.

33. A vehicle, characterized in that, The vehicle includes a processor and a memory. The memory provides storage space for storing computer instructions. The processor is used to invoke computer instructions stored in the memory to perform the method as described in any one of claims 22-28.

34. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store computer instructions; When the instruction is executed by the processor, it causes the method as described in any one of claims 1-12 to be executed, or the method as described in any one of claims 13-21 to be executed, or the method as described in any one of claims 22-28 to be executed.

35. A computer program product, characterized in that, The computer program product includes computer language code or computer instructions; When the computer program product is executed by a processor, the method as described in any one of claims 1-12 is executed, or the method as described in any one of claims 13-21 is executed, or the method as described in any one of claims 22-28 is executed.