IoV Data Transmission via Peer-to-Peer Certificate Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data transmission methods for driving recorders in the Internet of Vehicles (IoV) face security risks due to the storage of keys and certificates on third-party servers, leading to potential data theft and tampering during transmission.
Innovation Solution
A peer-to-peer (P2P) network-based data transmission method where devices generate and manage their own key pairs, with identity authentication using certificates, ensuring secure and reliable data access through encrypted communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If keys and certificates are stored on a third-party server, then data access is simplified and centralized, but security and reliability of data transmission deteriorate due to potential data theft and tampering
Solution Approach 1:
The patent extracts the key and certificate storage function from the third-party server and relocates it to the terminal devices themselves. Each terminal generates and stores its own key pair and certificates locally, eliminating the security vulnerability of centralized storage while maintaining the ability to access data through direct peer-to-peer authentication between devices
Solution Approach 2:
The patent segments the centralized key management system into distributed individual key pairs stored on separate terminal devices. Instead of one central authority holding all keys, each device independently manages its own cryptographic credentials, creating a decentralized security architecture that improves both reliability and security
2Device complexity
If a centralized cloud device manages all data access, then system complexity is reduced, but security risks increase due to single point of failure and centralized attack targets
Solution Approach 1:
The patent divides the centralized cloud access architecture into multiple independent terminal devices that directly communicate with each other. Each terminal maintains its own security credentials and can authenticate others independently, eliminating the single point of failure represented by the centralized cloud device while distributing security responsibilities across multiple nodes
Solution Approach 2:
The patent introduces mutual certificate verification as an intermediary authentication mechanism between terminals. Instead of relying on a central cloud mediator that becomes a security target, devices perform direct peer-to-peer authentication using exchanged certificates, creating a trust relationship that doesn't depend on centralized control
Data Source
AI summary
A data transmission method includes receiving a first certificate transmitted by a first device, transmitting a second certificate to the first device, determining a first public key and a first terminal identity based on the first certificate in response to both the first certificate and the second certificate being valid certificates, receiving a data access request transmitted by the first device in response to both the first terminal identity and a second terminal identity being registered identities, and transmitting target data to the first device in response to the data access request.


