Detection method and apparatus, and vehicle
Patent Information
- Application Number
- PCT/CN2025/085972
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2026-10-01
Smart Images

Figure CN2025085972_01102026_PF_FP_ABST
Abstract
Description
Detection methods, devices and vehicles Technical Field
[0001] This application relates to the field of intelligent vehicles, and more specifically, to a detection method, apparatus, and vehicle. Background Technology
[0002] As a critical component of vehicles, the main challenge for in-vehicle communication systems is ensuring secure communication between onboard devices. During the electrical testing phase, each component can negotiate and persistently store the communication keys of all peers. When transmitting service data between components, session keys can be derived from the communication keys, and these session keys can be used in each power-on cycle. Currently, there is a lack of methods to detect the validity of the communication keys upon which secure communication depends. Summary of the Invention
[0003] This application provides a detection method, apparatus, and vehicle that can detect the validity of a communication key when the key is not in use, thereby helping to avoid communication loss between components.
[0004] In a first aspect, this application provides a detection method, which includes: if it is detected within a first time period that a first component has not generated a session key through a first communication key, generating a first session key based on the first communication key, wherein the first communication key is the communication key used when the first component communicates with a second component; requesting to establish a first communication link with the second component based on the first session key; and performing corresponding operations based on the establishment result of the first communication link.
[0005] Based on the above technical solution, a session key can be generated using the communication key before transmitting business data. A communication link can then be established based on the session key to verify the validity of the communication key. This avoids communication loss caused by the failure of the communication key during business data transmission, which would otherwise result in communication loss due to the approximately 3-second delay in negotiating the communication key via Transport Layer Security (TLS) to establish a connection. This helps improve the security and reliability of communication between components.
[0006] In some possible implementations, the first communication link is established based on a pre-shared key (PSK).
[0007] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: acquiring first service data when the establishment result indicates that the first communication link has been successfully established; determining a second session key based on the first communication key; establishing a second communication link with the second component based on the second session key; determining a third session key based on the first communication key during the process of sending the first service data encrypted with the second session key to the second component through the second communication link; requesting the establishment of a third communication link with the second component based on the third session key; and performing corresponding operations on the second communication link based on the first message sent and the second message received on the third communication link.
[0008] Based on the above technical solution, the first component can actively monitor anomalies (e.g., latency anomalies) on the second communication link via the third communication link. This provides an active monitoring mechanism to detect the status of the communication link, enabling rapid monitoring of anomalies in the communication link used for service transmission, real-time connection to the operational status of the communication link used for service data transmission, and timely detection and resolution of potential problems. This helps improve the reliability of the communication link, thereby contributing to enhanced vehicle safety.
[0009] In some possible implementations, if the establishment result indicates that the first communication link has been successfully established, the first service data is acquired, including: if the establishment result indicates that the first communication link has been successfully established and the first component and the second component have successfully switched to the power-on state, the first service data is acquired.
[0010] In conjunction with the first aspect, in some implementations of the first aspect, corresponding operations are performed on the second communication link based on the first message sent and the second message received on the third communication link, including: determining the delay of the third communication link based on the first message and the second message; and disconnecting the second communication link when the delay of the third communication link meets a preset condition.
[0011] Based on the above technical solution, the first component can determine whether the communication key (or the second communication link used for service transmission) is abnormal based on the latency of the third communication link. When latency is abnormal, potential problems can be detected and resolved promptly, which helps improve the reliability of the communication link and thus enhances vehicle safety.
[0012] In some possible implementations, the delay of the third communication link meets preset conditions, including: the delay of the third communication link is greater than or equal to the preset delay.
[0013] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: determining a fourth session key based on a second communication key, wherein the second communication key is another communication key used when the first component communicates with the second component; establishing a fourth communication link with the second component based on the fourth session key; and sending encrypted first service data to the second component through the fourth communication link.
[0014] Based on the above technical solution, after the delay of the third communication link meets the condition, another communication link for transmitting the first service data can be established based on another communication key, so that the first component can continue to transmit the first service data to the second component.
[0015] In some possible implementations, the second communication key is a backup communication key pre-set during the electrical inspection process, or it can be a communication key obtained through TLS connection negotiation.
[0016] In conjunction with the first aspect, in some implementations of the first aspect, the first communication key and the second communication key are keys preset in the first component.
[0017] Based on the above technical solution, the first communication key and the second communication key are keys pre-installed in the first component. This allows for rapid switching between the first and second communication keys when the first communication key fails, avoiding the time-consuming negotiation of communication keys during TLS connection establishment, and helping to ensure the continuity and security of the communication process.
[0018] In conjunction with the first aspect, in some implementations of the first aspect, the first communication key is located in a first storage area in the first component, and the method further includes: establishing a Transport Layer Security (TLS) link with the second component; negotiating a third communication key with the second component through the TLS link; and updating the key in the first storage area from the first communication key to the third communication key.
[0019] Based on the above technical solution, during the process of establishing a communication link using the second communication key, the first component can also negotiate with the second component to obtain a third communication key, and use the third communication key to overwrite the first communication key originally stored in the first storage area. This allows for rapid switching between the second and third communication keys when the second communication key becomes invalid, avoiding the time-consuming negotiation of communication keys during TLS link establishment, and helping to ensure the continuity and security of the communication process.
[0020] In conjunction with the first aspect, in some implementations of the first aspect, the first message includes a first timestamp when the first component sends the first message, and the second message includes a second timestamp when the second component sends the second message, wherein determining the delay of the third communication link based on the first message and the second message includes: determining the delay based on the first timestamp and the second timestamp.
[0021] In conjunction with the first aspect, in certain implementations of the first aspect, corresponding operations are performed based on the establishment result of the first communication link, including: when the establishment result indicates that the first communication link has been successfully established, sending first information encrypted with the first session key to the second component; receiving second information encrypted by the second component through the first communication link, wherein the second information is a response to the first information; decrypting the second information encrypted with the first session key to obtain the second information; acquiring second service data when the second information meets preset conditions; and sending the second service data to the second component based on the first communication key.
[0022] Based on the above technical solution, when the first communication link is successfully established and the second information received by the first component meets the preset conditions, the operation of transmitting service data can be performed based on the first communication key. In this way, the validity of the first communication key can be detected through the establishment of the communication link and the data received by the first component, which helps to avoid communication loss caused by communication key negotiation during TLS connection establishment due to communication key failure during service data transmission, and helps to improve the security and reliability of communication between components.
[0023] In conjunction with the first aspect, in certain implementations of the first aspect, sending the first information encrypted with the first session key to the second component includes: sending the first state switching message encrypted with the first session key to the second component; receiving the encrypted second information sent by the second component through the first communication link includes: receiving the encrypted second state switching message sent by the second component through the first communication link; and obtaining the second service data when the second information meets preset conditions includes: obtaining the second service data when the state of the first component switches to the power-on state and the second state switching message indicates that the state of the second component switches to the power-on state.
[0024] Based on the above technical solution, the validity of the first communication key can be ensured after the communication link is successfully established and both the first and second components successfully switch to the power-on state. This guarantees that the communication link can be successfully established using the first communication key, and that both the first and second components can successfully switch to the power-on state, thus ensuring that the communication key used for business data transmission is valid. This avoids communication loss caused by communication key invalidation during TLS connection establishment and negotiation, thus contributing to improved security and reliability of inter-component communication.
[0025] In conjunction with the first aspect, in certain implementations of the first aspect, based on the establishment result of the first communication link, corresponding operations are performed, including: if the establishment result indicates that the first communication link was not successfully established, or if the establishment result indicates that the first communication link was successfully established but the first component failed to switch to the power-on state, or if the establishment result indicates that the first communication link was successfully established but the second component failed to switch to the power-on state, a fifth session key is generated based on the fourth communication key, wherein the fourth communication key is another communication key used when the first component communicates with the second component; a request is made to establish a fifth communication link with the second component based on the fifth session key; and corresponding operations are performed based on the establishment result of the fifth communication link.
[0026] Based on the above technical solution, if the validity check of the first communication key fails, the validity check of the fourth communication key used for communication between the first and second components can continue. In this way, the first and second communication keys can be verified separately before transmitting service data, ensuring that a valid communication key can be used for data transmission when service data is being transmitted. Simultaneously, serial detection avoids excessive link occupation, thus preventing disruption to service data transmission between the first component and other components.
[0027] In conjunction with the first aspect, in some implementations of the first aspect, the first communication key and the fourth communication key are keys preset in the first component.
[0028] Based on the above technical solution, the first communication key and the fourth communication key can be pre-installed in the first component. This way, if the verification of the first communication key fails, the pre-installed fourth communication key can be used directly to continue the verification, which helps improve the efficiency of verifying the validity of the communication keys.
[0029] In conjunction with the first aspect, in some implementations of the first aspect, the first communication key is located in a first storage area in the first component, and the method further includes: establishing a TLS link with the second component; negotiating a fifth communication key with the second component through the TLS link; and updating the key in the first storage area from the first communication key to the fifth communication key.
[0030] Based on the above technical solution, during the process of detecting the validity of the fourth communication key, the first component can also negotiate with the second component to obtain a fifth communication key, and use the fifth communication key to overwrite the first communication key originally stored in the first storage area.
[0031] In some possible implementations, after the validity of the fourth communication key is checked, the validity of the fifth communication key can also be checked.
[0032] Secondly, this application provides a detection device, which includes: a session key generation unit, configured to generate a first session key based on a first communication key when a first component fails to generate a session key using a first communication key within a first time period, wherein the first communication key is a communication key used when the first component communicates with a second component; a communication link establishment unit, configured to establish a first communication link with the second component based on the first session key request; and a processing unit, configured to perform corresponding operations based on the establishment result of the first communication link.
[0033] In conjunction with the second aspect, in some implementations of the second aspect, the apparatus further includes an acquisition unit, a determination unit, and a data transmission unit. The acquisition unit is used to acquire first service data when the establishment result indicates that the first communication link has been successfully established. The determination unit is used to determine a second session key based on the first communication key. The communication link establishment unit is also used to establish a second communication link with the second component based on the second session key. The determination unit is also used to determine a third session key based on the first communication key during the process of the data transmission unit sending the first service data encrypted with the second session key to the second component through the second communication link. The communication link establishment unit is also used to request the establishment of a third communication link with the second component based on the third session key. The processing unit is used to perform corresponding operations on the second communication link based on the first message sent and the second message received on the third communication link.
[0034] In conjunction with the second aspect, in some implementations of the second aspect, a determining unit is used to determine the delay of the third communication link based on the first message and the second message; and a processing unit is used to disconnect the second communication link when the delay of the third communication link meets a preset condition.
[0035] In conjunction with the second aspect, in some implementations of the second aspect, the determining unit is further configured to determine a fourth session key based on the second communication key, wherein the second communication key is another communication key used when the first component communicates with the second component; the communication link establishing unit is further configured to establish a fourth communication link with the second component based on the fourth session key; and the data transmission unit is further configured to send encrypted first service data to the second component through the fourth communication link.
[0036] In conjunction with the second aspect, in some implementations of the second aspect, the first communication key and the second communication key are keys preset in the first component.
[0037] In conjunction with the second aspect, in some implementations of the second aspect, the first communication key is located in the first storage area of the first component, and the device further includes a key negotiation unit, a communication link establishment unit, and a key negotiation unit for establishing a TLS link with the second component; the key negotiation unit is used to negotiate with the second component through the TLS link to obtain a third communication key; and the processing unit is used to update the key in the first storage area from the first communication key to the third communication key.
[0038] In conjunction with the second aspect, in some implementations of the second aspect, the first message includes a first timestamp when the first component sends the first message, and the second message includes a second timestamp when the second component sends the second message, wherein the determining unit is configured to: determine the delay based on the first timestamp and the second timestamp.
[0039] In conjunction with the second aspect, in some implementations of the second aspect, the device further includes a data transmission unit, a decryption unit, and an acquisition unit. The data transmission unit is used to send first information encrypted with a first session key to the second component when the establishment result indicates that the first communication link has been successfully established. The data transmission unit is also used to receive encrypted second information sent by the second component via the first communication link; the second information is a response to the first information. The decryption unit is used to decrypt the encrypted second information according to the first session key to obtain the second information. The acquisition unit is used to acquire second service data when the second information meets preset conditions. The data transmission unit is also used to send the second service data to the second component according to the first communication key.
[0040] In conjunction with the second aspect, in some implementations of the second aspect, the data transmission unit is used to send a first state switching message encrypted with a first session key to the second component; receive an encrypted second state switching message sent by the second component through a first communication link; and the acquisition unit is used to acquire second service data when the state of the first component switches to the power-on state and the second state switching message indicates that the state of the second component switches to the power-on state.
[0041] In conjunction with the second aspect, in some implementations of the second aspect, the session key generation unit is configured to: generate a fifth session key based on a fourth communication key, wherein the fourth communication key is another communication key used when the first component communicates with the second component, in the case that the establishment result indicates that the first communication link was not successfully established, or the establishment result indicates that the first communication link was successfully established but the first component failed to switch to the power-on state, or the establishment result indicates that the first communication link was successfully established but the second component failed to switch to the power-on state; the communication link establishment unit is configured to request the establishment of a fifth communication link with the second component based on the fifth session key; and the processing unit is configured to perform corresponding operations based on the establishment result of the fifth communication link.
[0042] In conjunction with the second aspect, in some implementations of the second aspect, the first communication key and the fourth communication key are keys preset in the first component.
[0043] In conjunction with the second aspect, in some implementations of the second aspect, the first communication key is located in the first storage area of the first component, and the device further includes a key negotiation unit, a communication link establishment unit for establishing a TLS link with the second component; a key negotiation unit for negotiating with the second component through the TLS link to obtain a fifth communication key; and a processing unit for updating the key in the first storage area from the first communication key to the fifth communication key.
[0044] Thirdly, this application provides a detection device including a processor and a memory, wherein the memory is used to store instructions, and the processor executes the instructions stored in the memory to cause the device to perform any of the possible methods in the first aspect.
[0045] Fourthly, this application provides a vehicle that includes any of the possible devices described in the second or third aspect above.
[0046] Fifthly, this application provides a computer program product comprising: computer program code, which, when run on a computer, causes the computer to perform any of the possible methods described in the first aspect above.
[0047] It should be noted that the above-mentioned computer program code can be stored in whole or in part on the first storage medium, wherein the first storage medium can be packaged together with the processor or packaged separately from the processor. This application embodiment does not specifically limit this.
[0048] In a sixth aspect, this application provides a computer-readable storage medium storing program code that, when executed on a computer, causes the computer to perform any of the possible methods described in the first aspect above.
[0049] In a seventh aspect, this application provides a chip system including circuitry for performing any of the possible methods described in the first aspect above. Attached Figure Description
[0050] Figure 1 is a functional block diagram of the vehicle provided in an embodiment of this application.
[0051] Figure 2 is a schematic flowchart of the detection method provided in the embodiments of this application.
[0052] Figure 3 is a schematic diagram of the system architecture provided in an embodiment of this application.
[0053] Figure 4 is an architecture diagram of the AOS system, taking MDC as an example, provided in the embodiments of this application.
[0054] Figure 5 is an architecture diagram of a VOS system using VIU as an example, provided in an embodiment of this application.
[0055] Figure 6 is a schematic diagram of the system composed of components 310 and 320 provided in the embodiments of this application.
[0056] Figure 7 is another schematic flowchart of the detection method provided in the embodiments of this application.
[0057] Figure 8 is another schematic flowchart of the detection method provided in the embodiments of this application.
[0058] Figure 9 is a schematic block diagram of component 310 provided in an embodiment of this application.
[0059] Figure 10 is another schematic flowchart of the detection method provided in the embodiments of this application.
[0060] Figure 11 is a schematic diagram of the interaction between components 310 and 320 provided in an embodiment of this application.
[0061] Figure 12 is a schematic block diagram of the detection device provided in an embodiment of this application. Detailed Implementation
[0062] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; "and / or" in this document is merely a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. "At least one" refers to one or more. For example, "at least one of A and B," similar to "A and / or B," describes the association relationship between related objects, indicating that three relationships can exist. For example, at least one of A and B can represent: A existing alone, A and B existing simultaneously, and B existing alone.
[0063] The prefixes such as "first" and "second" used in this application embodiment are merely for distinguishing different descriptive objects and do not limit the position, order, priority, quantity, or content of the described objects. The use of ordinal numbers and other prefixes used to distinguish descriptive objects in this application embodiment does not constitute a limitation on the described objects. The description of the described objects is given in the claims or the context of the embodiments, and should not constitute unnecessary limitations due to the use of such prefixes. Furthermore, in the description of this embodiment, unless otherwise stated, "multiple" means two or more.
[0064] Figure 1 is a functional block diagram of a vehicle 100 provided in an embodiment of this application.
[0065] As shown in Figure 1, the vehicle 100 may include a perception system 110 and a computing platform 120. The perception system 110 may include one or more sensors for sensing information about the environment surrounding the vehicle 100. For example, the perception system 110 may include a positioning system, which may be a Global Positioning System (GPS), a BeiDou Navigation Satellite System, or another positioning system. Alternatively, the perception system 110 may include one or more of the following: an inertial measurement unit (IMU), an accelerometer, a lidar, millimeter-wave radar, ultrasonic radar, and a camera device. Furthermore, the perception system 110 may include one or more collision sensors.
[0066] Some or all of the functions of vehicle 100 can be controlled by computing platform 120. Computing platform 120 may include one or more processors, such as processors 121 to 12n (n being a positive integer). A processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a central processing unit (CPU), microprocessor, graphics processing unit (GPU) (which can be understood as a type of microprocessor), or digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. These logical relationships are fixed or reconfigurable. For example, the processor may be a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as a field-programmable gate array (FPGA). In reconfigurable hardware circuits, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement some or all of the functions of the aforementioned units. Furthermore, the processor can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), etc. In addition, the computing platform 120 may also include a memory for storing instructions. Some or all of the processors 121 to 12n can call the instructions in the memory to implement the corresponding functions.
[0067] Optionally, the structure of the vehicle 100 described above is merely illustrative. In actual applications, various components of the vehicle 100 may be added or removed as needed.
[0068] The vehicle 100 in this application may include: road vehicles, water vehicles, air vehicles, industrial equipment, agricultural equipment, or entertainment equipment, etc. For example, vehicle 100 may be a means of transportation (such as commercial vehicles, passenger cars, motorcycles, flying cars, trains, etc.), industrial vehicles (such as forklifts, trailers, tractors, etc.), engineering vehicles (such as excavators, bulldozers, cranes, etc.), agricultural equipment (such as lawnmowers, harvesters, etc.), amusement equipment, toy vehicles, etc. The embodiments of this application do not specifically limit the type of vehicle.
[0069] As mentioned earlier, the main challenge for in-vehicle communication systems, as a critical component of vehicles, is ensuring secure communication between in-vehicle devices. During the electrical testing phase, each component can negotiate and persistently store the communication keys of all its counterparts. When transmitting service data between components, session keys can be derived from the communication keys, and these session keys can be used in each power-on cycle. Currently, there is a lack of means to detect the validity of the communication keys that secure communication relies on. For example, there may be a secure communication service between component A and component B, but component A has not yet deployed secure communication services with other components. For component A, only the communication key with component B is used; the communication keys with other components are not used. After these communication keys are uniformly distributed and persistently stored during the electrical testing phase, most of them are not immediately effective, and there is a lack of effective means to detect whether these keys are usable.
[0070] This application provides a detection method, apparatus, and vehicle that can generate a session key using a communication key before transmitting service data, and then establish a communication link based on the session key to verify the validity of the communication key. This avoids communication loss caused by the communication key expiring during TLS connection establishment negotiation (approximately 3 seconds) due to communication key failure during service data transmission, thereby contributing to improved security and reliability of inter-component communication.
[0071] Figure 2 shows a schematic flowchart of the detection method 200 provided in an embodiment of this application. The method 200 can be executed by the vehicle 100; or, the method 200 can be executed by the computing platform 120; or, the method 200 can be executed by a processor, chip, or circuit in the computing platform 120. The method 200 includes:
[0072] S210, if it is detected that the first component has not generated a session key through the first communication key within the first time period, a first session key is generated according to the first communication key, wherein the first communication key is the communication key when the first component communicates with the second component.
[0073] Optionally, the first communication key can be the master communication key.
[0074] For example, at an electrical inspection process node, each component can negotiate and persistently store the master communication key for all counterparts. The first component can store communication key 1 for the second component. Correspondingly, the second component can also store communication key 1 for the first component.
[0075] Optionally, if it is detected that the first component has not generated a session key through the first communication key within a first time period, generating a first session key according to the first communication key includes: generating a first session key according to the first communication key if it is detected that the first component has not generated a session key through the first communication key within a first preset time period from the power-on of the first component.
[0076] For example, the first preset duration can be 5 minutes.
[0077] The above process of generating the first session key based on the first communication key can also be understood as deriving the first session key based on the first communication key.
[0078] S220, establish a first communication link with the second component according to the first session key request.
[0079] For example, if the first component detects that it has not generated a session key through communication key 1 within 5 minutes of power-on, it can generate session key 1 based on communication key 1, thereby initiating the establishment of a PSK link with the second component based on session key 1.
[0080] Correspondingly, if the second component detects that it has not generated a session key through communication key 1 within 5 minutes of power-on, it can also generate session key 2 based on communication key 1, thereby enabling the second component to establish a PSK link based on session key 2.
[0081] The above session key 1 can be the first session key mentioned above.
[0082] S230, based on the establishment result of the first communication link, perform the corresponding operation.
[0083] Optionally, based on the establishment result of the first communication link, corresponding operations are performed, including: if the establishment result indicates that the first communication link has been successfully established, sending first information encrypted with the first session key to the second component; receiving second information encrypted by the second component through the first communication link, wherein the second information is a response to the first information; decrypting the second information encrypted with the first session key to obtain the second information; if the second information meets preset conditions, acquiring second service data; and sending the second service data to the second component according to the first communication key.
[0084] For example, the second component stores a communication key 1 for the first component. When establishing a PSK link with the first component, the second component can also generate a session key 2 based on this communication key 1. Thus, the first and second components can establish a PSK link based on their respective generated session keys. For example, if session key 1 and session key 2 are the same, the first and second components can successfully establish a PSK link. After establishing the PSK link, the first component can send first information encrypted with session key 1 to the second component. After receiving the first information encrypted with session key 1, the second component can decrypt it based on session key 2 to obtain the first information. The second component can then send second information encrypted with session key 2 to the first component based on the first information. The first component can decrypt the second information encrypted with session key 2 based on session key 1 to obtain the second information. If the second information meets preset conditions, the first component can determine that communication key 1 is valid. Therefore, when the first component needs to communicate securely with the second component, it can use communication key 1 to send business data to the second component.
[0085] Optionally, sending the first information encrypted with the first session key to the second component includes: sending the first state switching message encrypted with the first session key to the second component; receiving the encrypted second information sent by the second component through the first communication link includes: receiving the encrypted second state switching message sent by the second component through the first communication link; and obtaining the second service data when the second information meets preset conditions includes: obtaining the second service data when the state of the first component switches to the power-on state and the second state switching message indicates that the state of the second component switches to the power-on state.
[0086] For example, the first information can be a first state switching message. After successfully switching to the power-on state, the first component can send a first state switching message encrypted with session key 1 to the second component. The first state switching message indicates that the first component has successfully switched to the power-on state. In response to receiving the first state switching message encrypted with session key 1, the second component can decrypt it using session key 2 to obtain the first state switching message. After successfully switching to the power-on state, the second component can send a second state switching message encrypted with session key 2 to the first component. The second state switching message indicates that the second component has successfully switched to the power-on state. In response to receiving the second state switching message encrypted with session key 2, the first component can decrypt it using session key 1 to obtain the second state switching message. After determining that both the first and second components have successfully switched to the power-on state, the first component can determine that the communication key 1 stored in the first component is valid. Similarly, after determining that both the first and second components have successfully switched to the power-on state, the second component can determine that the communication key 1 stored in the second component is valid.
[0087] Optionally, sending the first information encrypted with the first session key to the second component includes: sending the first random number encrypted with the first session key to the second component; receiving the encrypted second information sent by the second component through the first communication link includes: receiving the encrypted second random number sent by the second component through the first communication link; and obtaining the second service data when the second information meets preset conditions includes: obtaining the second service data when the first random number and the second random number match.
[0088] For example, the first component can send a random number 1 encrypted with session key 1 to the second component. Upon receiving the random number 1 encrypted with session key 1, the second component can decrypt it using session key 2 to obtain the random number 1. The second component can then send a random number 1 encrypted with session key 2 to the first component. Upon receiving the random number 1 encrypted with session key 2, the first component can decrypt it using session key 1 to obtain the random number 1. If the random number sent by the first component is the same as the random number received by the first component, the first component can determine that the communication key 1 is valid. Similarly, after successfully decrypting the random number 1 encrypted with session key 1 using session key 2, the second component can determine that the communication key 1 is valid.
[0089] Optionally, based on the establishment result of the first communication link, perform corresponding operations, including: if the establishment result indicates that the first communication link was not successfully established, or if the establishment result indicates that the first communication link was successfully established but the first component failed to switch to the power-on state, or if the establishment result indicates that the first communication link was successfully established but the second component failed to switch to the power-on state, generate a fifth session key based on the fourth communication key, wherein the fourth communication key is another communication key used when the first component communicates with the second component; request the establishment of a fifth communication link with the second component based on the fifth session key; and perform corresponding operations based on the establishment result of the fifth communication link.
[0090] For example, if communication link 1 between the first component and the second component fails to be established, or if communication link 1 is established successfully but the first component fails to switch to the power-on state, or if communication link 1 is established successfully but the second component fails to switch to the power-on state, then the first component can determine that the communication key 1 stored in the first component for the second component is invalid. In this case, the first component can generate a session key 3 based on communication key 2, and establish communication link 2 with the second component based on session key 3. The first component can perform corresponding operations based on the establishment result of communication link 2. The process of the first component performing corresponding operations based on the establishment result of communication link 2 can be referred to the process of the first component performing corresponding operations based on the establishment result of communication link 1, and will not be repeated here.
[0091] The above communication link 1 can be the first communication link mentioned above, communication key 1 can be the first communication key mentioned above, communication key 2 can be the fourth communication key mentioned above, and communication link 2 can be the fifth communication link mentioned above.
[0092] For example, if the communication key 1 stored in the first component is valid and the communication key 1 stored in the second component is invalid, the second component may generate a session key different from the session key 1 based on the invalid communication key (session key 1 and session key 2 are different), which will cause the first component and the second component to fail to establish a PSK link.
[0093] For example, the fourth communication key may be a communication key negotiated by the first component and the second component after establishing a link via TLS.
[0094] Optionally, the first communication key and the fourth communication key are keys preset in the first component.
[0095] For example, the fourth communication key can be another communication key stored in the first component during the electrical inspection process. Thus, during the electrical inspection process, the first component can persistently store both the first and fourth communication keys used for communication with the second component. The fourth communication key can also be referred to as a backup communication key.
[0096] Optionally, the first communication key is located in a first storage area in the first component, and the method further includes: establishing a TLS link with the second component; negotiating a fifth communication key with the second component through the TLS link; and updating the key in the first storage area from the first communication key to the fifth communication key.
[0097] For example, during the verification of the validity of the fourth communication key, the first component can establish a TLS link with the second component to negotiate a fifth communication key. The first component can then update the communication key in the first storage area from the first communication key to the fifth communication key.
[0098] Optionally, after verifying the validity of the fourth communication key, the validity of the fifth communication key can be verified. The process for verifying the validity of the fifth communication key can refer to the process for verifying the validity of the first communication key described above, and will not be repeated here.
[0099] Optionally, the method 200 further includes: acquiring first service data when the establishment result indicates that the first communication link has been successfully established; determining a second session key based on the first communication key; establishing a second communication link with the second component based on the second session key; determining a third session key based on the first communication key during the process of sending the first service data encrypted with the second session key to the second component through the second communication link; requesting to establish a third communication link with the second component based on the third session key; and performing corresponding operations on the second communication link based on the first message sent and the second message received on the third communication link.
[0100] In this embodiment, the first component can actively monitor anomalies (e.g., latency anomalies) on the second communication link via the third communication link. This enables rapid monitoring of anomalies in the communication link used for service transmission, real-time connection to the operational status of the communication link used for service transmission, timely detection and resolution of potential problems, and improved reliability of the communication link.
[0101] Optionally, based on the first message sent and the second message received on the third communication link, corresponding operations are performed on the second communication link, including: determining the delay of the third communication link based on the first and second messages; and disconnecting the second communication link when the delay of the third communication link meets a preset condition. In this way, the second communication link transmitting service data can be disconnected promptly when the delay of the third communication link is abnormal, preventing the second communication link transmitting service data from being abnormal and affecting the security and reliability of communication between the first and second components.
[0102] Optionally, the first message includes a first timestamp when the first component sends the first message, and the second message includes a second timestamp when the second component sends the second message. Determining the delay of the third communication link based on the first message and the second message includes: determining the delay based on the first timestamp and the second timestamp.
[0103] Optionally, the method 200 further includes: determining a fourth session key based on a second communication key, wherein the second communication key is another communication key used when the first component communicates with the second component; establishing a fourth communication link with the second component based on the fourth session key; and sending encrypted first service data to the second component through the fourth communication link. In this way, if the delay of the third communication link is abnormal, a new communication link can be established based on the second communication key, thereby allowing the transmission of service data to continue.
[0104] For example, if communication link 1 between the first component and the second component is successfully established and the second information received by the first component meets the preset conditions, then the first component can determine that the communication key 1 stored in the first component for the second component is invalid. When it is necessary to transmit service data to the second component, the first component can generate a session key 4 based on communication key 1, and establish a communication link 3 with the second component based on session key 4. This communication link 3 is used to transmit service data 1. At the same time, the first component can also generate a session key 5 based on communication key 1, and establish a communication link 4 with the second component based on session key 5. This communication link 4 is used to transmit messages. If it is determined through the messages sent and received on communication link 4 that the delay of communication link 4 is abnormal, the first component can disconnect communication link 3. The first component can generate a session key 6 based on communication key 3 and establish a communication link 5 with the second component based on session key 6. This communication link 5 can be used to transmit service data 1.
[0105] The above session key 4 can be the second session key, the communication link 3 can be the second communication link, the session key 5 can be the third session key, the communication link 4 can be the third communication link, the communication key 3 can be the second communication key, and the session key 6 can be the fourth session key.
[0106] Optionally, the method 200 further includes: determining another session key based on the second communication key; establishing another communication link with the second component based on the other session key; and performing corresponding operations on the fourth communication link based on the messages sent and received on the other communication link.
[0107] For example, the second communication key may be a communication key negotiated by the first component and the second component after establishing a link via TLS.
[0108] Optionally, the first communication key and the second communication key are keys preset in the first component.
[0109] In this embodiment of the application, when the first communication key is abnormal and causes the delay of the third communication link to be abnormal, the second communication link used for transmitting service data can be disconnected, and the fourth communication link used for transmitting service data can be quickly established by quickly switching between the first communication key and the second communication key. This avoids the time consumption in the first component and the second component through TLS link establishment negotiation, and helps to ensure the continuity and security of the communication process.
[0110] Optionally, the first communication key is located in a first storage area in the first component, and the method 200 further includes: establishing a TLS link with the second component; negotiating a third communication key with the second component through the TLS link; and updating the key in the first storage area from the first communication key to the third communication key.
[0111] Figure 3 illustrates a schematic diagram of the system architecture provided in an embodiment of this application. This system architecture includes components 310 and 320. Component 310 includes a secure communication module 311, a key distribution module 312, and secure hardware 313. Component 320 includes a secure communication module 321, a key distribution module 322, and secure hardware 323. Both secure hardware 313 and secure hardware 323 include communication key 1. Communication key 1 is the communication key required for data transmission between components 310 and 320. For example, when components 310 and 320 transmit service data 1, component 310 can derive session key 1 based on communication key 1, and component 320 can also derive session key 2 based on communication key 1. Component 310 can use session key 1 to establish a PSK link with component 320. After successfully establishing the PSK link, service data 1 encrypted with session key 1 can be sent from secure communication module 311 to secure communication module 321.
[0112] For example, the communication key 1 in security hardware 313 and the communication key 1 in security hardware 323 can be communication keys obtained during the electrical inspection process.
[0113] The key distribution module 312 in component 310 and the key distribution module 322 in component 320 can be used for negotiating communication keys. For example, key distribution module 312 can establish a TLS link with key distribution module 322, thereby negotiating other communication keys used for secure communication between components 310 and 320.
[0114] In Figure 3 above, the security hardware 313 of component 310 only shows the communication key 1 used by component 310 to communicate securely with component 320. The security hardware 313 may also include the communication key used by component 310 to communicate securely with other components. Correspondingly, the security hardware 323 may also include the communication key used by component 320 to communicate securely with other components.
[0115] The technical solutions involved in the embodiments of this application can be applied to different system architectures and scenarios. For example, the components can be in-vehicle intelligent driving computing platforms / mobile data centers (MDC), vehicle domain controllers (VDC), cockpit domain controllers (CDC), vehicle integration units (VIU), and autonomous driving controllers. The deployment environment includes systems on chips (SoC) and microcontroller units (MCU). The encryption and decryption hardware involved can be configured with hardware security modules (HSM) or trusted execution environments (TEE) to provide secure storage to ensure the security of certificate private keys and related keys. The operating systems involved in the components of the embodiments of this application include, but are not limited to, Atelier operating systems (AOS) and vehicle control operating systems (VOS).
[0116] For example, Figure 4 shows the architecture diagram of an AOS system using MDC as an example provided in this application embodiment. A security process is deployed to launch the monitoring service module provided in this application embodiment during the startup phase. The monitoring service module includes functions such as configuring certificate access control, key access control, and SELinux permissions. The monitoring service module implements secure communication and renegotiation of communication keys through intra-process communication, via the secure communication module (SecCom) and the key negotiation module (KeyDist). These functions also depend on the deployment of basic modules such as communication management (CM), key management service (KMS), and certificate management. The monitoring service module can also report abnormal states through the fault management module, or record maintenance logs through the LOG logging module.
[0117] For example, Figure 5 shows the architecture diagram of a VOS system using VIU as an example provided in this application embodiment. In the task scheduling of VIU, the monitoring service module provided in this application embodiment is scheduled during the startup phase and the running state through initialization and periodic scheduling. The monitoring service module interacts with various components through the runtime environment (RTE). The monitoring service module can configure its task scheduling, and at the same time, it needs to configure the monitoring service-related software components (SwComponentType, swc) using the automotive open system architecture extensible markup language (ARXML). Through RTE and system scheduling, the monitoring service module implements secure communication functions and renegotiation of communication keys with the key and security module (KeyM&Csm) and the key negotiation (KeyDist) module. These functions also depend on the deployment of basic modules such as the communication management module (Soad), the communication protocol stack (Eth&TcpIp), and the encryption / decryption module (CryIf&Crypto). The monitoring service module can report faults in abnormal states through the fault management module; and record maintenance logs through the vehicle history record (VHR) log recording module.
[0118] Figure 6 shows a schematic diagram of the system composed of components 310 and 320 provided in an embodiment of this application. Currently, there is no business data symmetrically encrypted using communication key 1 between application 1 in component 310 and application 2 in component 320. However, new business data may be added in subsequent planning, requiring encrypted communication. However, communication key 1 is negotiated and persistently stored during the production line phase; in the absence of business data, the validity of communication key 1 cannot be verified.
[0119] Figure 7 shows a schematic flowchart of a detection method 700 provided in an embodiment of this application. The method 700 can be executed by components 310 and 320, and includes:
[0120] S701, the monitoring service module of component 310 monitors whether component 310 has derived a session key through communication key 1 within a preset time period from power-on.
[0121] For example, component 310 can start a timer after power-on, and during the operation of the timer, it can continuously detect whether component 310 has derived a session key based on communication key 1. If no session key has been derived based on communication key 1, then S702 can be executed, that is, the validity of communication key 1 can be checked. If a session key has been derived based on communication key 1, then the validity of communication key 1 does not need to be checked.
[0122] S702, if component 310 has not derived a session key, the monitoring service module of component 310 derives session key 1 based on communication key 1.
[0123] S703, the monitoring service module of component 320 determines whether component 320 has derived a session key through communication key 1 within a preset time period since power-on.
[0124] For example, if the monitoring service module of component 320 determines that component 320 has not derived a session key based on communication key 1 within a preset time period since power-on, then S704 can be executed, that is, the validity of communication key 1 can be checked. If a session key has been derived based on communication key 1, then the validity of communication key 1 can be checked without checking it.
[0125] For example, if the communication key 1 stored in both component 310 and component 320 is valid, then session key 1 and session key 2 are the same.
[0126] S704, the monitoring service module of component 320 derives session key 2 based on communication key 1.
[0127] S705, the secure communication module 311 establishes a PSK link with the secure communication module 321 based on session key 1.
[0128] Accordingly, the secure communication module 321 establishes a PSK link with the secure communication module 311 based on the session key 2.
[0129] The establishment of a PSK link between the security communication module 311 and the security communication module 321 can also be understood as the establishment of a PSK link between the monitoring service module of component 310 and the monitoring service module of component 320.
[0130] For example, if session key 1 and session key 2 are the same, then secure communication module 311 can successfully establish a PSK link with secure communication module 321 and continue to execute S707; otherwise, secure communication module 311 cannot establish a PSK link with secure communication module 321, and component 310 can determine that communication key 1 is invalid.
[0131] Optionally, the method 700 further includes: S706, after the PSK link is established, the secure communication module 321 can send a link establishment notification to the monitoring service module of component 320, which indicates that the communication link between component 310 and component 320 has been successfully established.
[0132] S707, the monitoring service module of component 310 sends information 1 encrypted with session key 1 to the secure communication module 311.
[0133] For example, the information 1 can be a random number 1.
[0134] For example, the information 1 can be a state switching message 1, which indicates that the state of component 310 is switched to the power-on state.
[0135] S708, the secure communication module 311 sends information 1 encrypted with session key 1 to the secure communication module 321.
[0136] S709, the secure communication module 321 sends information 1 encrypted with session key 1 to the monitoring service module of component 320.
[0137] S710, the monitoring service module of component 320 decrypts the encrypted information 1 according to the session key 2 to obtain the information 1.
[0138] For example, if session key 1 and session key 2 are the same, then the monitoring service module of component 320 can successfully decrypt the encrypted information 1 based on session key 2.
[0139] S711, the monitoring service module of component 320 encrypts information 2 according to session key 2.
[0140] For example, information 1 can be the same as information 2. For instance, if information 1 is a random number 1, information 2 can also be a random number 1.
[0141] S712, the monitoring service module of component 320 sends information 2 encrypted with session key 2 to the secure communication module 321.
[0142] S713, the secure communication module 321 sends information 2 encrypted with session key 2 to the secure communication module 311.
[0143] S714, the secure communication module 311 sends information 2 encrypted with session key 2 to the monitoring service module of component 310.
[0144] S715, the monitoring service module of component 310 decrypts the encrypted information 2 according to the session key 1 to obtain the decrypted information.
[0145] S716, the monitoring service module of component 310 detects the validity of communication key 1 based on the information obtained after decryption.
[0146] For example, taking information 1 as random number 1, if the monitoring service module of component 310 determines that the random number obtained after decryption is the same as the random number 1 sent to component 310, then it can be determined that communication key 1 is valid.
[0147] For example, taking information 1 as random number 1, if the monitoring service module of component 310 determines that the random number obtained after decryption is different from the random number 1 sent to component 310, then it can be determined that communication key 1 is invalid.
[0148] For example, taking information 1 as state switching message 1, if the monitoring service module of component 310 determines that the decrypted state message indicates that component 320 has successfully switched to the power-on state, then it can be determined that communication key 1 is valid.
[0149] For example, taking information 1 as state switching message 1, if the monitoring service module of component 310 determines that the message obtained after decryption does not indicate that component 320 switches to the power-on state, then it can be determined that communication key 1 is invalid.
[0150] For example, if the monitoring service module of component 310 determines that communication key 1 is invalid, the method 700 further includes: the monitoring service module of component 310 continues to verify communication key 2.
[0151] For example, during the electrical inspection process, the monitoring service module of component 310 can store communication key 1 and communication key 2, both of which are communication keys used when communicating with component 320.
[0152] For example, if the monitoring service module of component 310 determines that communication key 1 has expired, the method 700 further includes: the monitoring service module of component 310 instructs key distribution module 312 to negotiate a new communication key with key distribution module 322 of component 320.
[0153] Optionally, the method 700 further includes: the monitoring service module of component 310 replacing the communication key 1 with the negotiated communication key.
[0154] Figure 8 shows a schematic flowchart of the detection method 800 provided in an embodiment of this application. Method 800 is illustrated using information 1 as a state transition message as an example. Method 800 includes:
[0155] S801, a PSK link is established between the monitoring service module of component 310 and the monitoring service module of component 320.
[0156] For example, step S801 above can refer to the process of S701-S705 above, and will not be repeated here.
[0157] S802, when component 310 switches to the power-down state, the monitoring service module of component 310 sends a state switching message 2 encrypted with session key 1 to the monitoring service module of component 320. The state switching message 2 indicates that component 310 switches to the power-down state.
[0158] The monitoring service module of component 310 sends a state switching message 2 encrypted with session key 1 to the monitoring service module of component 320, including: the monitoring service module of component 310 sending the state switching message 2 encrypted with session key 1 to the secure communication module 311, the secure communication module 311 sending the state switching message 2 encrypted with session key 1 to the secure communication module 321, and the secure communication module 321 sending the state switching message 2 encrypted with session key 1 to the monitoring service module of component 320.
[0159] S803, the monitoring service module of component 320 decrypts the state switching message 2 encrypted by session key 1 based on session key 2 to obtain state switching message 2.
[0160] For example, through state switching message 2, the monitoring service module of component 320 can know that component 310 has successfully switched to the power-off state.
[0161] S804, when component 320 switches to the power-off state, the monitoring service module of component 320 sends a state switching message 3 encrypted with session key 2 to the monitoring service module of component 310. The state switching message 3 indicates that component 320 switches to the power-off state.
[0162] For example, component 310 can decrypt the state transition message 3 encrypted with session key 2 based on session key 1, thereby obtaining state transition message 3. Through state transition message 3, the monitoring service module of component 310 can know that component 320 has successfully switched to the power-off state.
[0163] S805, when component 310 switches from the power-down state to the initial state, the monitoring service module of component 310 sends a state transition message 4 encrypted with session key 1 to the monitoring service module of component 320. The state transition message 4 instructs component 310 to switch to the initial state. S806, the monitoring service module of component 320 decrypts the state transition message 4 encrypted with session key 1 based on session key 2 to obtain the state transition message 4.
[0164] For example, through state switching message 4, the monitoring service module of component 320 can know that component 310 has successfully switched to the initial state.
[0165] S807, when component 320 switches from the power-down state to the initial state, the monitoring service module of component 320 sends a state switching message 5 encrypted with session key 2 to the monitoring service module of component 310. The state switching message 5 instructs component 320 to switch to the initial state.
[0166] For example, component 310 can decrypt the state transition message 5 encrypted with session key 2 based on session key 1, thereby obtaining state transition message 5. Through state transition message 5, the monitoring service module of component 310 can know that component 320 has successfully switched to the initial state.
[0167] S808, when component 310 switches from the initial state to the power-on state, the monitoring service module of component 310 sends a state switching message 1 encrypted with session key 1 to the monitoring service module of component 320. The state switching message 1 instructs component 310 to switch to the power-on state.
[0168] S809, the monitoring service module of component 320 decrypts the state switching message 1 encrypted by session key 1 based on session key 2, and obtains the state switching message 1.
[0169] For example, through state switching message 1, the monitoring service module of component 320 can know that component 310 has successfully switched to the power-on state.
[0170] S810, when component 320 switches from the initial state to the power-on state, the monitoring service module of component 320 sends a state switching message 6 encrypted with session key 2 to the monitoring service module of component 310. The state switching message 6 instructs component 320 to switch to the power-on state.
[0171] For example, component 310 can decrypt the state transition message 6 encrypted with session key 2 based on session key 1, thereby obtaining state transition message 6. Through state transition message 6, the monitoring service module of component 310 can know that component 320 has successfully switched to the power-on state.
[0172] When component 310 switches to the power-on state and receives the state switching message 6 sent by component 320 indicating that component 320 has switched to the power-on state, it can determine that the communication key 1 stored in component 310 is valid. Similarly, when component 320 switches to the power-on state and receives the state switching message 1 sent by component 310 indicating that component 310 has switched to the power-on state, it can determine that the communication key 1 stored in component 320 is valid.
[0173] Optionally, the method 800 further includes: if it is determined that the communication key 1 is valid, the monitoring service module of component 310 can notify the key distribution module 312 that there is no need to negotiate a new communication key with component 320.
[0174] Optionally, the method 800 further includes: when a PSK link is established between the monitoring service module of component 310 and the monitoring service module of component 320, a timer is started; if component 310 does not switch to the power-on state within the timer's running time, or if no state switching message 6 is received within the timer's running time, it can be determined that the communication key 1 has expired.
[0175] The above, in conjunction with Figures 7 and 8, describes how to detect the stored communication key before components 310 and 320 transmit service data. The following, in conjunction with Figures 9 to 11, describes the process of monitoring the link between components 310 and 320 when they transmit service data.
[0176] Figure 9 shows a schematic block diagram of component 310 provided in an embodiment of this application. Component 310 includes a service port 314 and a monitoring service port 315, wherein the service port 314 is a port for transmitting service data, and the monitoring service port 315 is a port for transmitting other information. Component 310 can transmit service data on communication link 3 with component 320 through service port 314, and component 310 can transmit other information on communication link 4 with component 320 through monitoring service port 315. Communication link 3 can be established by session key 4 generated by component 310 and component 320 based on communication key 1, and communication link 4 can be established by session key 5 generated by component 310 and component 320 based on communication key 1.
[0177] In this embodiment, component 310 can monitor the status of communication link 3 through information sent and received on communication link 4. For example, the latency on communication link 4 can be determined through the information sent and received on communication link 4, thereby determining the latency when transmitting service data on communication link 3.
[0178] Figure 10 shows a schematic flowchart of a detection method 1000 provided in an embodiment of this application. The method 1000 can be executed by components 310 and 320, and includes:
[0179] S1001, the monitoring service module of component 310 has derived session key 4 based on communication key 1.
[0180] For example, when component 310 has service data that needs to be sent to component 320, session key 4 can be derived from communication key 1.
[0181] S1002, the secure communication module 311 establishes a communication link 3 with the secure communication module 321 based on the session key 4.
[0182] Accordingly, the secure communication module 321 of component 320 can derive session key 4 based on communication key 1 and establish a communication link 3 with the secure communication module 311 of component 310 based on session key 4.
[0183] For example, communication link 3 is a PSK link.
[0184] S1003, the secure communication module 311 and the secure communication module 321 transmit service data through the communication link 3.
[0185] S1004, The monitoring service module of component 310 has derived session key 5 based on communication key 1, and session key 4 is different from session key 5.
[0186] For example, when component 310 has service data that needs to be sent to component 320, session key 4 and session key 5 can be derived from communication key 1.
[0187] S1005, the secure communication module 311 establishes a communication link 4 with the secure communication module 321 based on the session key 5.
[0188] For example, communication link 4 is a PSK link.
[0189] S1006, the security communication module 311 of component 310 and the security communication module 321 of component 320 transmit messages through the communication link 4.
[0190] For example, business data between components 310 and 320 is decrypted by the secure communication module and sent to the application; messages between components 310 and 320 are sent to the monitoring service module through a fixed-allocation port and service number. The session key and secure communication link between the monitoring service module and the application are isolated, but both are temporary session keys derived from communication key 1. Communication link 4 established through the monitoring service module will not affect communication link 3 for transmitting business data.
[0191] S1007, the monitoring service module of component 310 determines the latency of communication link 4 based on the messages sent and received by communication link 4.
[0192] S1008, when the delay of communication link 4 meets the preset conditions, the monitoring service module of component 310 disconnects communication link 3.
[0193] Optionally, the method 1000 further includes: when the delay of the communication link 4 meets the preset conditions, the monitoring service module of component 310 negotiates a new communication key with component 320 through key distribution module 312.
[0194] S1009, the monitoring service module of component 310 derives session key 6 based on communication key 3.
[0195] S1010, the secure communication module 311 establishes a communication link 5 with the secure communication module 321 based on the session key 6.
[0196] Accordingly, the secure communication module 321 can derive the session key 6 based on the communication key 3, and the secure communication module 321 establishes a communication link 5 with the secure communication module 311 based on the session key 6.
[0197] S1011, the secure communication module 311 and the secure communication module 321 continue to transmit service data through the communication link 5.
[0198] Figure 11 illustrates the interaction between components 310 and 320 provided in this embodiment. As shown in Figure 11, when sending message a, component 310 can obtain the current time information, and thus component 310 can send message a, encrypted with session key 5, carrying the time of component 310 to component 320. When the monitoring service module of component 320 receives the encrypted message a, it can decrypt it using session key 5 and reply to message a. Component 320 can send message b, encrypted with session key 5, carrying the time of component 320 to component 310. When the monitoring service module of component 310 receives the encrypted message b, it can decrypt it using session key 5 and obtain the time information carried in message b. Based on the time information carried in message a and message b, the monitoring service module of component 310 can determine the delay of communication link 4, and thus determine whether communication link 3 for transmitting service data is abnormal.
[0199] Figure 12 shows a schematic block diagram of the detection device 1200 provided in an embodiment of this application. The device 1200 includes: a session key generation unit 1210, configured to generate a first session key based on a first communication key when it is detected that the first component has not generated a session key through a first communication key within a first time period; the first communication key is the communication key used when the first component communicates with the second component; a communication link establishment unit 1220, configured to establish a first communication link with the second component based on the first session key request; and a processing unit 1230, configured to perform corresponding operations based on the establishment result of the first communication link.
[0200] Optionally, the device 1200 further includes an acquisition unit, a determination unit, and a data transmission unit. The acquisition unit is used to acquire first service data when the establishment result indicates that the first communication link has been successfully established. The determination unit is used to determine a second session key based on the first communication key. The communication link establishment unit 1220 is also used to establish a second communication link with the second component based on the second session key. The determination unit is also used to determine a third session key based on the first communication key during the process of the data transmission unit sending the first service data encrypted with the second session key to the second component through the second communication link. The communication link establishment unit 1220 is also used to request to establish a third communication link with the second component based on the third session key. The processing unit 1230 is used to perform corresponding operations on the second communication link based on the first message sent and the second message received on the third communication link.
[0201] Optionally, the determining unit is configured to determine the delay of the third communication link based on the first message and the second message; the processing unit is configured to disconnect the second communication link when the delay of the third communication link meets a preset condition.
[0202] Optionally, the determining unit is further configured to determine a fourth session key based on the second communication key, wherein the second communication key is another communication key used when the first component communicates with the second component; the communication link establishing unit is further configured to establish a fourth communication link with the second component based on the fourth session key; and the data transmission unit is further configured to send encrypted first service data to the second component through the fourth communication link.
[0203] Optionally, the first communication key and the second communication key are keys preset in the first component.
[0204] Optionally, the first communication key is located in the first storage area of the first component, and the device further includes a key negotiation unit, a communication link establishment unit 1220, which is also used to establish a TLS link with the second component; a key negotiation unit, which is used to negotiate with the second component through the TLS link to obtain a third communication key; and a processing unit, which is used to update the key in the first storage area from the first communication key to the third communication key.
[0205] Optionally, the first message includes a first timestamp when the first component sends the first message, and the second message includes a second timestamp when the second component sends the second message, wherein the determining unit is configured to: determine the delay based on the first timestamp and the second timestamp.
[0206] Optionally, the device 1200 further includes a data transmission unit, a decryption unit, and an acquisition unit. The data transmission unit is used to send first information encrypted with a first session key to the second component when the establishment result indicates that the first communication link has been successfully established. The data transmission unit is also used to receive encrypted second information sent by the second component via the first communication link; the second information is a response to the first information. The decryption unit is used to decrypt the encrypted second information according to the first session key to obtain the second information. The acquisition unit is used to acquire second service data when the second information meets preset conditions. The data transmission unit is also used to send the second service data to the second component according to the first communication key.
[0207] Optionally, the data transmission unit is configured to send a first state switching message encrypted with a first session key to the second component; and receive a second state switching message encrypted by the second component via a first communication link; the acquisition unit is configured to acquire second service data when the state of the first component switches to the power-on state and the second state switching message indicates that the state of the second component switches to the power-on state.
[0208] Optionally, the session key generation unit 1210 is configured to: generate a fifth session key based on a fourth communication key, wherein the fourth communication key is another communication key used when the first component communicates with the second component, in the case that the establishment result indicates that the first communication link was not successfully established, or the establishment result indicates that the first communication link was successfully established but the first component failed to switch to the power-on state, or the establishment result indicates that the first communication link was successfully established but the second component failed to switch to the power-on state; the communication link establishment unit 1220 is configured to request the establishment of a fifth communication link with the second component based on the fifth session key; and the processing unit 1230 is configured to perform corresponding operations based on the establishment result of the fifth communication link.
[0209] Optionally, the first communication key and the fourth communication key are keys preset in the first component.
[0210] Optionally, the first communication key is located in the first storage area of the first component, and the device further includes a key negotiation unit, a communication link establishment unit for establishing a TLS link with the second component; a key negotiation unit for negotiating a fifth communication key with the second component through the TLS link; and a processing unit for updating the key in the first storage area from the first communication key to the fifth communication key.
[0211] It should be understood that the division of units in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units in the device can be implemented by a processor calling software; for example, the device includes a processor connected to memory, which stores instructions. The processor calls the instructions stored in memory to implement any of the above methods or to implement the functions of each unit in the device. The processor can be, for example, a general-purpose processor, such as a CPU or microprocessor, and the memory can be internal or external to the device. Alternatively, the units in the device can be implemented as hardware circuits. The functions of some or all units can be implemented through the design of the hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an ASIC, and the functions of some or all units are implemented through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a PLD, such as an FPGA, which can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby implementing the functions of some or all units. All units of the above devices can be implemented entirely through processor calling software, or entirely through hardware circuits, or partially through processor calling software with the remaining parts implemented through hardware circuits.
[0212] In this application embodiment, a processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a CPU, microprocessor, GPU, or DSP. In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. These logical relationships are fixed or reconfigurable. For example, the processor may be a hardware circuit implemented as an ASIC or PLD, such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the processor loading instructions to implement the functions of some or all of the above units. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as an NPU, TPU, or DPU.
[0213] As can be seen, each unit in the above device can be one or more processors (or processing circuits) configured to implement the above methods, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.
[0214] Furthermore, the units in the above devices can be integrated in whole or in part, or they can be implemented independently. In one implementation, these units are integrated together as a System-on-a-Chip (SoC). The SoC may include at least one processor for implementing any of the above methods or implementing the functions of the units in the device. The at least one processor may be of different types, such as CPU and FPGA, CPU and AI processor, CPU and GPU, etc.
[0215] This application also provides a detection device, which includes a processing unit and a storage unit. The storage unit is used to store instructions, and the processing unit executes the instructions stored in the storage unit to cause the device to perform the methods or steps described in the above embodiments.
[0216] Alternatively, if the detection device is located in a vehicle, the processing unit may be the processor 121-12n shown in FIG1.
[0217] This application also provides a vehicle that may include the detection device 1200 described above.
[0218] This application also provides a computer program product, which includes computer program code that, when run on a computer, causes the computer to perform the methods described in the above embodiments.
[0219] This application also provides a computer-readable medium storing program code that, when run on a computer, causes the computer to perform the methods described in the above embodiments.
[0220] This application also provides a chip, which includes a circuit for performing the methods described in the above embodiments.
[0221] In implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software. The method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules within the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, power-on erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.
[0222] It should be understood that in the embodiments of this application, the memory may include read-only memory and random access memory, and provides instructions and data to the processor.
[0223] It should also be understood that, in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0224] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0225] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0226] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0227] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0228] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0229] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0230] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be covered. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A detection method, characterized in that, include: If it is detected that the first component has not generated a session key through the first communication key within the first time period, a first session key is generated based on the first communication key, wherein the first communication key is the communication key when the first component communicates with the second component; Establish a first communication link with the second component based on the first session key request; Based on the establishment result of the first communication link, perform the corresponding operation.
2. The method according to claim 1, characterized in that, The method further includes: If the establishment result indicates that the first communication link has been successfully established, the first service data is obtained; Determine the second session key based on the first communication key; A second communication link is established with the second component based on the second session key; During the process of sending the first service data encrypted with the second session key to the second component through the second communication link, the third session key is determined based on the first communication key; A third communication link is established with the second component based on the third session key request; Based on the first message sent and the second message received on the third communication link, perform corresponding operations on the second communication link.
3. The method according to claim 2, characterized in that, The step of performing corresponding operations on the second communication link based on the first message sent and the second message received on the third communication link includes: The delay of the third communication link is determined based on the first message and the second message; When the delay of the third communication link meets the preset condition, the second communication link is disconnected.
4. The method according to claim 3, characterized in that, The method further includes: A fourth session key is determined based on the second communication key, wherein the second communication key is another communication key used when the first component communicates with the second component; A fourth communication link is established with the second component based on the fourth session key; The encrypted first service data is sent to the second component via the fourth communication link.
5. The method according to claim 4, characterized in that, The first communication key and the second communication key are keys preset in the first component.
6. The method according to claim 5, characterized in that, The first communication key is located in a first storage area in the first component, and the method further includes: Establish a Transport Layer Security (TLS) link with the second component; A third communication key is obtained by negotiating with the second component through the TLS link; Update the key of the first storage area from the first communication key to the third communication key.
7. The method according to any one of claims 3 to 6, characterized in that, The first message includes a first timestamp when the first component sends the first message, and the second message includes a second timestamp when the second component sends the second message. The step of determining the delay of the third communication link based on the first message and the second message includes: The delay is determined based on the first timestamp and the second timestamp.
8. The method according to any one of claims 1 to 7, characterized in that, The step of performing corresponding operations based on the establishment result of the first communication link includes: If the establishment result indicates that the first communication link has been successfully established, the first information encrypted with the first session key is sent to the second component. The encrypted second information sent by the second component is received through the first communication link, and the second information is a response to the first information; The encrypted second information is decrypted using the first session key to obtain the second information. If the second information meets the preset conditions, the second business data is obtained; The second service data is sent to the second component based on the first communication key.
9. The method according to claim 8, characterized in that, Sending the first information encrypted with the first session key to the second component includes: Send a first state switching message encrypted with the first session key to the second component; Receiving the encrypted second information sent by the second component through the first communication link includes: Receive the encrypted second state switching message sent by the second component through the first communication link; The step of acquiring second business data when the second information meets preset conditions includes: When the state of the first component switches to the power-on state and the second state switching message indicates that the state of the second component switches to the power-on state, the second service data is obtained.
10. The method according to any one of claims 1 to 7, characterized in that, The step of performing corresponding operations based on the establishment result of the first communication link includes: If the establishment result indicates that the first communication link was not successfully established, or if the establishment result indicates that the first communication link was successfully established and the first component failed to switch to the power-on state, or if the establishment result indicates that the first communication link was successfully established and the second component failed to switch to the power-on state, a fifth session key is generated based on the fourth communication key, wherein the fourth communication key is another communication key used when the first component communicates with the second component; Establish a fifth communication link with the second component based on the fifth session key request; Based on the establishment result of the fifth communication link, perform the corresponding operation.
11. The method according to claim 10, characterized in that, The first communication key and the fourth communication key are keys preset in the first component.
12. The method according to claim 11, characterized in that, The first communication key is located in a first storage area in the first component, and the method further includes: Establish a TLS link with the second component; The fifth communication key is obtained by negotiating with the second component through the TLS link; Update the key of the first storage area from the first communication key to the fifth communication key.
13. A detection device, characterized in that, include: The session key generation unit is used to generate a first session key based on the first communication key when it is detected that the first component has not generated a session key through the first communication key within a first time period. The first communication key is the communication key when the first component communicates with the second component. A communication link establishment unit is used to establish a first communication link with the second component according to the first session key request; The processing unit is used to perform corresponding operations based on the establishment result of the first communication link.
14. The apparatus according to claim 13, characterized in that, The device further includes an acquisition unit, a determination unit, and a data transmission unit. The acquisition unit is used to acquire first service data when the establishment result indicates that the first communication link has been successfully established; The determining unit is configured to determine a second session key based on the first communication key; The communication link establishment unit is further configured to establish a second communication link with the second component based on the second session key; The determining unit is further configured to determine a third session key based on the first communication key during the process in which the data transmission unit sends the first service data encrypted by the second session key to the second component through the second communication link; The communication link establishment unit is further configured to establish a third communication link with the second component based on the third session key request; The processing unit is configured to perform corresponding operations on the second communication link based on the first message sent and the second message received on the third communication link.
15. The apparatus according to claim 14, characterized in that, The determining unit is configured to determine the delay of the third communication link based on the first message and the second message; The processing unit is configured to disconnect the second communication link when the delay of the third communication link meets a preset condition.
16. The apparatus according to claim 15, characterized in that, The determining unit is further configured to determine a fourth session key based on a second communication key, wherein the second communication key is another communication key used when the first component communicates with the second component; The communication link establishment unit is further configured to establish a fourth communication link with the second component based on the fourth session key; The data transmission unit is further configured to send the encrypted first service data to the second component via the fourth communication link.
17. The apparatus according to claim 16, characterized in that, The first communication key and the second communication key are keys preset in the first component.
18. The apparatus according to claim 17, characterized in that, The first communication key is located in a first storage area within the first component, and the device further includes a key negotiation unit. The communication link establishment unit is also used to establish a TLS link with the second component; The key negotiation unit is used to negotiate a third communication key with the second component through the TLS link; The processing unit is configured to update the key of the first storage area from the first communication key to the third communication key.
19. The apparatus according to any one of claims 15 to 18, characterized in that, The first message includes a first timestamp when the first component sends the first message, and the second message includes a second timestamp when the second component sends the second message. The determining unit is used for: The delay is determined based on the first timestamp and the second timestamp.
20. The apparatus according to any one of claims 13 to 19, characterized in that, The device further includes a data transmission unit, a decryption unit, and an acquisition unit, wherein... The data transmission unit is used to send the first information encrypted with the first session key to the second component when the establishment result indicates that the first communication link has been successfully established. The data transmission unit is further configured to receive encrypted second information sent by the second component through the first communication link, wherein the second information is a response to the first information; The decryption unit is used to decrypt the encrypted second information according to the first session key to obtain the second information; The acquisition unit is used to acquire second business data when the second information meets preset conditions; The data transmission unit is further configured to send the second service data to the second component according to the first communication key.
21. The apparatus according to claim 20, characterized in that, The data transmission unit is used to send a first state switching message encrypted with the first session key to the second component. Receive the encrypted second state switching message sent by the second component through the first communication link; The acquisition unit is used to acquire the second service data when the state of the first component switches to the power-on state and the second state switching message indicates that the state of the second component switches to the power-on state.
22. The apparatus according to any one of claims 13 to 19, characterized in that, The session key generation unit is used for: If the establishment result indicates that the first communication link was not successfully established, or if the establishment result indicates that the first communication link was successfully established and the first component failed to switch to the power-on state, or if the establishment result indicates that the first communication link was successfully established and the second component failed to switch to the power-on state, a fifth session key is generated based on the fourth communication key, wherein the fourth communication key is another communication key used when the first component communicates with the second component; The communication link establishment unit is used to establish a fifth communication link with the second component according to the fifth session key request; The processing unit is used to perform corresponding operations based on the establishment result of the fifth communication link.
23. The apparatus according to claim 22, characterized in that, The first communication key and the fourth communication key are keys preset in the first component.
24. The apparatus according to claim 23, characterized in that, The first communication key is located in a first storage area within the first component, and the device further includes a key negotiation unit. The communication link establishment unit is used to establish a TLS link with the second component; The key negotiation unit is used to negotiate a fifth communication key with the second component through the TLS link; The processing unit is configured to update the key of the first storage area from the first communication key to the fifth communication key.
25. A detection device, characterized in that, include: Memory, used to store computer programs; A processor for executing a computer program stored in the memory to cause the apparatus to perform the method as described in any one of claims 1 to 12.
26. A vehicle, characterized in that, Includes the apparatus as described in any one of claims 13 to 25.
27. A computer-readable storage medium, characterized in that, It stores instructions that, when executed by a processor, cause the processor to implement the method as described in any one of claims 1 to 12.
28. A computer program product, characterized in that, The computer program product includes computer program code that, when run on a computer, causes the computer to perform the method as described in any one of claims 1 to 12.
29. A chip, characterized in that, The chip includes circuitry for performing the method as described in any one of claims 1 to 12.