WO2018076377A1 - Procédé de transmission de données, terminal, dispositif de nœud, et système - Google Patents

Procédé de transmission de données, terminal, dispositif de nœud, et système Download PDF

Info

Publication number
WO2018076377A1
WO2018076377A1 PCT/CN2016/104139 CN2016104139W WO2018076377A1 WO 2018076377 A1 WO2018076377 A1 WO 2018076377A1 CN 2016104139 W CN2016104139 W CN 2016104139W WO 2018076377 A1 WO2018076377 A1 WO 2018076377A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
key
digital signature
public key
node device
Prior art date
Application number
PCT/CN2016/104139
Other languages
English (en)
Chinese (zh)
Inventor
熊晓春
黄正安
付建军
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201680090122.1A priority Critical patent/CN109845185B/zh
Priority to PCT/CN2016/104139 priority patent/WO2018076377A1/fr
Publication of WO2018076377A1 publication Critical patent/WO2018076377A1/fr

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a data transmission method, a terminal, a node device, and a system.
  • LTE-V is designed to achieve a vehicle-to-vehicle (V2V), a vehicle-to-Pedestrian (V2P) and even a vehicle-to-Everything (V2X).
  • V2V vehicle-to-vehicle
  • V2P vehicle-to-Pedestrian
  • V2X vehicle-to-Everything
  • 3GPP has not clearly proposed how to improve the security of LTE-V based data transmission.
  • the Institute of Electrical and Electronics Engineers adopts a digital certificate-based method to improve the security of V2V broadcast messages, that is, each broadcast message of a vehicle needs to carry and transmit in addition to the digital signature carrying the message.
  • the party's digital certificate guarantees the legitimacy of the broadcast source through digital certificates and digital signatures.
  • the vehicle needs to carry a digital certificate every time data is transmitted, and the amount of data transmitted is large.
  • the digital certificate of the vehicle needs to be periodically updated, that is, the certificate authority (CA) needs to periodically issue digital certificates to each vehicle, which is expensive.
  • Embodiments of the present invention provide a data transmission method, a terminal, a node device, and a system, which can reduce overhead and transmit data amount on the basis of ensuring the legitimacy of a broadcast message source.
  • the first aspect of the present invention provides a data transmission method.
  • the first terminal may acquire the second public key of the key management system based on the system identifier, and based on the second public key pair.
  • the first digital signature is verified.
  • the second terminal is identified as a valid terminal, and the first terminal may perform verification on the second digital signature based on the first public key. Process broadcast messages.
  • the broadcast security information may include a broadcast message, a second digital signature of the broadcast message, a first digital signature of the second terminal, a first public key of the second terminal, and a system identifier of the key management system.
  • the first digital signature is obtained by the key management system calculating the first public key based on the second private key of the key management system.
  • the second digital signature is obtained by the second terminal calculating the broadcast message based on the first private key of the second terminal.
  • the first terminal checks the first digital signature based on the second public key of the key management system, and can identify the identity of the second terminal, and avoid sending a broadcast message by using a fake identity, a fraudulent identity, or an expired identity.
  • the second digital signature may be verified based on the first public key, which ensures the legitimacy of the broadcast message source.
  • the CA needs to periodically issue a digital certificate to each vehicle, and each broadcast message of the vehicle needs to carry the digital certificate of the sender.
  • the first terminal can sign the first digital The manner of verifying identifies the validity and legitimacy of the temporary identity of the second terminal, which can reduce overhead and reduce the amount of transmitted data.
  • the first digital signature is obtained by the key management system calculating the effective start time of the second private key, the first public key, and the first private key by using a preset signature algorithm.
  • the broadcast security information further includes a valid start time and a generation time of the second digital signature
  • the first terminal may obtain the second public key of the key management system based on the system identifier, and may be based on the preset time parameter and valid Determining a valid interval of the first private key.
  • the generation time is within the effective interval
  • the first terminal determines that the first private key is a valid private key
  • the generation time is outside the valid interval
  • the first terminal determines the first private The key is an invalid private key.
  • the first terminal may obtain the receiving time of the broadcast security information, where the difference between the receiving time and the generating time is less than the pre-predetermined time parameter.
  • the time threshold is set, the first terminal is triggered to determine the effective interval of the first private key based on the preset time parameter and the effective start time; when the difference between the receiving time and the generating time is greater than or equal to the preset time threshold, A terminal may determine that the received broadcast security information is playback information, and then delete the broadcast security information.
  • the first terminal checks the first digital signature based on the second public key, where the first terminal can use the preset verification algorithm to the second public key, the first public key, the effective start time, and the first One number
  • the word signature is processed to obtain a verification result of the first digital signature.
  • the verification result of the first digital signature is equal to 1
  • the first terminal determines that the verification of the first digital signature is successful; when the verification result of the first digital signature is When it is equal to 0, the first terminal may determine that the second terminal is an invalid terminal, and then delete the received broadcast security information.
  • the first terminal may send a trusted credential obtaining request to the first node device, so that the first node device sends the trusted credential request information to the key management. And receiving, by the key management system, feedback information of the first terminal forwarded by the first node device, where the feedback information of the first terminal includes the system identifier and the updated second public key of the key management system.
  • the first terminal may generate a correspondence between the system identifier and the updated second public key, and store the system identifier and its corresponding After the updated second public key, when the original second public key corresponding to the system identifier exists in the local database of the first terminal, the first terminal deletes the original second public key after a preset duration.
  • the first terminal obtains the second public key of the key management system based on the system identifier, and performs verification on the first digital signature based on the second public key, where the first terminal obtains the update corresponding to the system identifier.
  • the first terminal when the verification is successful, identifies that the second terminal is a valid terminal, and specifically, when the first verification result is equal to 1 or the second verification result is equal to 1, the first terminal determines the second terminal. For an effective terminal.
  • the first terminal obtains the second public key of the key management system based on the system identifier, where the first terminal may be based on the preset trusted address when the local database of the first terminal does not have the second public key.
  • the second public key is downloaded from the designated node device, wherein the second public key of all the key management systems is stored in the designated node device.
  • the first terminal checks the second digital signature based on the first public key, and when the verification succeeds, the broadcast message is processed, where the first terminal uses the preset verification algorithm to the first public key. And processing the second digital signature and the broadcast security information to obtain a check result of the broadcast message.
  • the check result of the broadcast message is equal to 1
  • the first terminal determines that the broadcast message is a valid broadcast message, and broadcasts The message is processed; when the verification result of the broadcast message is equal to 0, the first terminal determines that the broadcast message is an invalid broadcast message, and deletes the broadcast security information.
  • a second aspect of the present invention provides a data transmission method. After receiving the feedback information of the second terminal sent by the key management system, the second terminal may calculate the broadcast message based on the first private key to obtain a second digital signature of the broadcast message. And sending broadcast security information to the first terminal.
  • the feedback information includes a trust credential of the second terminal and a first digital signature of the second terminal.
  • the trust credential includes a first private key and a first public key.
  • the first digital signature is obtained by the key management system calculating the first public key based on the second private key of the key management system.
  • the broadcast security information includes a broadcast message, a second digital signature, a first digital signature, a first public key, and a system identification of the key management system.
  • the second terminal receives the feedback information of the second terminal sent by the key management system, where the second terminal sends the trusted credential obtaining request to the first node device, so that the first node device sends the trusted credential request information.
  • the second terminal can also receive the feedback information forwarded by the key management system through the first node device.
  • the second terminal sends a trust credential acquisition request to the first node device, so that the first node device sends the trust credential request information to the key management system, where the second terminal sends the trust to the first node device.
  • a credential obtaining request so that the first node device sends an authentication request to the second node device, and when the local database of the second node device includes the broadcast service authorization information for the second terminal, the second node device sends the broadcast service authorization information To the first node device, the first node device sends the trusted credential request information to the key management system.
  • the second terminal sends a trust credential acquisition request to the first node device, so that the first node device sends the trust credential request information to the key management system, where the second terminal sends the trust to the first node device.
  • a credential obtaining request so that the first node device sends an authentication request to the second node device, and when the local database of the second node device includes the broadcast service authorization information for the second terminal, the second node device sends the broadcast service authorization information
  • the first node device sends the broadcast service authorization information to the base station of the cell where the second terminal is located, and the first node device sends the trust credential request information to the key management system.
  • the time-frequency resource acquisition request may be sent to the base station, so that the base station detects whether the local database of the base station is stored.
  • the broadcast service authorization information of the second terminal when the broadcast service authorization information of the second terminal exists in the local database of the base station, the base station allocates time-frequency resources to the second terminal, and the second terminal can use the time-frequency resource allocated by the base station.
  • the broadcast security information is sent to the first terminal.
  • the second terminal may send a time-frequency resource acquisition request to the base station of the cell where the second terminal is located, so that the base station sends the second node device to the second node device.
  • the authorization information acquisition request of the terminal when the base station receives the broadcast service authorization information sent by the second node device to the second terminal, the base station allocates the time-frequency resource to the second terminal, and the second terminal uses the time-frequency resource allocated by the base station.
  • the broadcast security information is sent to the first terminal.
  • the second terminal sends a time-frequency resource acquisition request to the base station of the cell where the second terminal is located, so that the base station sends a request for obtaining the authorization information to the second terminal to the second node device, which may be:
  • the base station of the cell in which the second terminal is located sends a time-frequency resource acquisition request, so that the base station detects whether the broadcast service authorization information of the second terminal exists in the local database of the base station, and when the broadcast service authorization information of the second terminal exists in the local database of the base station, The base station allocates time-frequency resources to the second terminal.
  • the base station sends an authorization information acquisition request to the second terminal to the second node device.
  • the trusted credential request information may carry a valid start time of the credential credential
  • the first digital signature is a second private key, a first public key, and a valid key management system of the key management system by using a preset signature algorithm. The starting time is calculated.
  • the feedback information may further include the system identifier and the updated second public key of the key management system, and after the second terminal receives the feedback information of the second terminal sent by the key management system, the system identifier and the update may be generated. Corresponding relationship of the second public key, and storing the system identifier and the corresponding updated second public key.
  • the second terminal The original second public key can be deleted after a preset duration.
  • the second terminal calculates the broadcast message to obtain the second digital signature of the broadcast message, where the second terminal may use the preset signature algorithm to use the preset private key, the broadcast message, the first public key, and the trusted certificate.
  • the effective start time, the first digital signature, the system identifier, and the generation time of the second digital signature are calculated to obtain second digital signature information.
  • a third aspect of the present invention provides a data transmission method, where a first node device receives a second terminal After the trusted credential obtaining request is sent, the trusted credential request information may be sent to the key management system according to the trusted credential obtaining request, and the feedback information of the second terminal sent by the key management system is received, and the feedback information is sent to the second terminal.
  • the feedback information may include a trust credential of the second terminal and a first digital signature of the second terminal, the trust credential may include a first private key and a first public key, and the first digital signature is a key management system based on the key management system The second private key is calculated from the first public key.
  • the first node device may send an authentication request to the second node device, so that the second node device detects the local database of the second node device.
  • the second node device Whether the broadcast service authorization information for the second terminal is included, and when the local database of the second node device includes the broadcast service authorization information for the second terminal, the second node device sends the broadcast service authorization information of the second terminal to the first A node device, the first node device receives broadcast service authorization information sent by the second node device to the second terminal.
  • the first node device sends the trusted credential request information to the key management system according to the trusted credential obtaining request, where the first node device generates a valid start time of the trusted credential, and sends the trusted credential request information to the secret.
  • the key management system, the trusted credential request information carries a valid start time.
  • the first digital signature is obtained by the key management system calculating the second private key, the first public key, and the effective start time of the key management system by using a preset signature algorithm, where the feedback information may include a trusted credential, The first digital signature, the effective start time, and the second public key of the key management system.
  • the first node device may generate a correspondence between the terminal identifier of the second terminal and the feedback information, and store the terminal identifier and the corresponding feedback information.
  • a fourth aspect of the present invention provides a computer storage medium, wherein the computer storage medium stores a program, and the program includes all or part of the steps of the data transmission method provided by the first aspect of the embodiment of the present invention.
  • a fifth aspect of the present invention provides a computer storage medium, wherein the computer storage medium stores a program, and the program includes all or part of the steps of the data transmission method provided by the second aspect of the embodiment of the present invention.
  • a sixth aspect of the present invention provides a computer storage medium, wherein the computer storage medium stores a program, and the program includes all or part of the steps of the data transmission method provided by the third aspect of the embodiment of the present invention.
  • a seventh aspect of the present invention provides a terminal, where the terminal includes:
  • the broadcast security information receiving module is configured to receive broadcast security information sent by the second terminal, where the broadcast security information includes a broadcast message, a second digital signature of the broadcast message, a first digital signature of the second terminal, and a first public key of the second terminal. And a system identifier of the key management system, wherein the first digital signature is obtained by the key management system calculating the first public key based on the second private key of the key management system, and the second digital signature is that the second terminal is based on the second terminal The first private key is calculated for the broadcast message.
  • the verification module is configured to obtain the second public key of the key management system based on the system identifier, and verify the first digital signature based on the second public key. When the verification succeeds, the second terminal is identified as a valid terminal.
  • the verification module is further configured to perform verification on the second digital signature based on the first public key, and process the broadcast message when the verification is successful.
  • the first digital signature is obtained by the key management system calculating the effective start time of the second private key, the first public key, and the first private key by using a preset signature algorithm.
  • the broadcast security information further includes a valid start time and a generation time of the second digital signature
  • the terminal may further include:
  • a determining module configured to determine a valid interval of the first private key based on the preset time parameter and the effective start time before the verification module obtains the second public key of the key management system based on the system identifier, when the generating time is within the effective interval When the first private key is determined to be a valid private key.
  • the terminal may further include:
  • the receiving time obtaining module is configured to determine, according to the preset time parameter and the effective starting time, the module to obtain the receiving time of the broadcast security information before determining the effective interval of the first private key.
  • the determining module is further configured to determine an effective interval of the first private key based on the preset time parameter and the effective start time when a difference between the receiving time and the generating time is less than a preset time threshold.
  • the verification module verifies the first digital signature based on the second public key, specifically:
  • Passing the verification algorithm to the second public key, the first public key, the effective start time, and the first digital signature The name is processed to obtain a verification result of the first digital signature; when the verification result of the first digital signature is equal to 1, it is determined that the verification of the first digital signature is successful.
  • the terminal may further include:
  • a request sending module configured to send, by the verification module, a trust credential acquisition request to the first node device, before the second public key of the key management system is obtained, so that the first node device sends the trusted credential request information to the key Management system.
  • the feedback information receiving module is configured to receive feedback information of the first terminal forwarded by the key management system by the first node device, where the feedback information of the first terminal includes the system identifier and the updated second public key of the key management system.
  • the terminal may further include:
  • a storage module configured to: after receiving the feedback information of the first terminal forwarded by the first node device by the key management system, generate a correspondence between the system identifier and the updated second public key, and store the system identifier and Corresponding updated second public key.
  • the deleting module is configured to delete the original second public key after a preset duration, when the original second public key corresponding to the system identifier exists in the local database of the terminal.
  • the verification module obtains the second public key of the key management system based on the system identifier, and performs verification on the first digital signature based on the second public key, specifically:
  • the first digital signature is verified based on the updated second public key to obtain a first verification result of the first digital signature.
  • the first digital signature is verified based on the original second public key to obtain a second verification result of the first digital signature.
  • the verification module identifies the second terminal as a valid terminal, specifically for:
  • An eighth aspect of the present invention provides a terminal, the terminal comprising a processor, an input device, an output device, and a memory, and the processor, the input device, and the output device can be used to implement some or all of the steps in conjunction with the first aspect.
  • a ninth aspect of the present invention provides a terminal, the terminal comprising a processor, an input device, an output device, and a memory, and the processor, the input device, and the output device can be used to implement some or all of the steps in conjunction with the second aspect.
  • a tenth aspect of the present invention provides a node device, where the node device may include:
  • the request receiving module is configured to receive a trusted credential obtaining request sent by the second terminal.
  • the request information sending module is configured to send the trust credential request information to the key management system according to the trust credential obtaining request.
  • a feedback information receiving module configured to receive feedback information of the second terminal sent by the key management system, where the feedback information includes a trusted credential of the second terminal and a first digital signature of the second terminal, where the trusted credential includes the first private key and the first The public key, the first digital signature is obtained by the key management system calculating the first public key based on the second private key of the key management system.
  • the feedback information sending module is configured to send the feedback information to the second terminal.
  • the node device may further include:
  • a request sending module configured to: before requesting the information sending module to send the trusted credential request information to the key management system according to the trusted credential obtaining request, sending an authentication request to the second node device, so that the second node device detects the locality of the second node device Whether the broadcast service authorization information for the second terminal is included in the database, and when the local database of the second node device includes the broadcast service authorization information for the second terminal, the second node device sends the broadcast service authorization information of the second terminal. Give the node device.
  • the authorization information receiving module is configured to receive broadcast service authorization information sent by the second node device to the second terminal.
  • the request information sending module is specifically configured to:
  • the effective start time for generating a trust credential is the effective start time for generating a trust credential.
  • the trust credential request information is sent to the key management system, and the trust credential request information carries a valid start time.
  • the first digital signature is obtained by the key management system by using a preset signature algorithm to calculate a second private key, a first public key, and a valid start time of the key management system.
  • the feedback information includes a trust credential, a first digital signature, a valid start time, and a second public key of the key management system.
  • the node device may further include:
  • the storage module is configured to: after receiving the feedback information sent by the key management system, the feedback information receiving module generates a correspondence between the terminal identifier and the feedback information of the second terminal, and stores the terminal identifier and the corresponding feedback information.
  • An eleventh aspect of the present invention provides a node device, which includes a processor, an input device, an output device, and a memory, and the processor, the input device, and the output device may be used to implement some or all of the steps in combination with the third aspect. .
  • a twelfth aspect of the present invention provides a data transmission system, comprising the terminal according to the eighth aspect, the terminal according to the ninth aspect, and the node device according to the eleventh aspect.
  • FIG. 1 is a schematic structural diagram of a data transmission system according to an embodiment of the present invention.
  • FIG. 2 is a schematic flowchart of a data transmission method according to an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of a data transmission method according to another embodiment of the present invention.
  • FIG. 4 is a schematic structural diagram of a terminal according to an embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of a node device according to an embodiment of the present disclosure.
  • FIG. 9 is a schematic structural diagram of a node device according to another embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of a data transmission system according to an embodiment of the present invention.
  • each broadcast message of the vehicle needs to carry the digital certificate of the sender, and the amount of data transmitted is large, and the CA needs to periodically send numbers to each vehicle. Certificate, the cost is large.
  • the embodiment of the present invention provides a data transmission method, where the first terminal receives the broadcast security information sent by the second terminal, and obtains the second public key of the key management system according to the system identifier of the key management system included in the broadcast security information, based on The second public key checks the first digital signature of the second terminal. When the verification succeeds, the second terminal is identified as a valid terminal, and the second digital signature of the broadcast message is performed based on the first public key of the second terminal. Verification, when the verification is successful, the broadcast message is processed, and the overhead and the amount of data transmitted can be reduced on the basis of ensuring the legitimacy of the broadcast message source.
  • the broadcast security information includes a broadcast message, a second digital signature, a first digital signature, a first public key, and a system identifier of the key management system.
  • the first digital signature is a second private key management system based on the key management system.
  • the key is calculated by calculating the first public key, and the second digital signature is obtained by the second terminal calculating the broadcast message based on the first private key of the second terminal.
  • an embodiment of the present invention provides a schematic diagram of a data transmission system.
  • the system architecture may be deployed in a 3GPP cellular network or a future 5G network.
  • the 3GPP cellular network may include an LTE-V, a device-to-device (device).
  • the future 5G network may include an evolved car to the eV2X system.
  • the architecture of the data transmission system may include at least: a first terminal 101, a second terminal 102, and a Key Management System (KMS) 103.
  • KMS Key Management System
  • the second terminal 102 may receive the feedback information of the second terminal 102 sent by the KMS 103, where the feedback information may include the trust credential of the second terminal 102 and the first digital signature of the second terminal 102, and the trust credential may include the first
  • the private key and the first public key are obtained by the KMS 103 calculating the first public key based on the second private key of the KMS 103; when the second terminal 102 needs to send the broadcast message to the first terminal 101, the broadcast may be The message is calculated and processed to get the a second digital signature of the broadcast message, wherein the second digital signature is obtained by the second terminal 102 calculating the broadcast message based on the first private key, and the second terminal 102 may generate broadcast security information, where the broadcast security information may include a broadcast message, The second digital signature of the broadcast message, the first digital signature, the first public key, and the system identifier of the KMS 103, and the second terminal 102 transmits the broadcast security information to the first terminal 101; the first terminal 101 receives the second terminal 103
  • the architecture of the data transmission system may further include the first node device 104.
  • the second terminal 102 may send a trust credential acquisition request to the first node device 104, and the first node device 104 sends a trust credential request to the KMS 103 according to the trust credential acquisition request.
  • the KMS 103 can generate a trust credential according to the credential credential request information
  • the trust credential can include the first public key of the second terminal 102 and the first private key thereof
  • the KMS 103 can calculate the first public key based on the second private key of the KMS 103.
  • the first digital signature transmits the trust credential and the first digital signature to the first node device 104, and the first node device 104 can transmit the trust credential and the first digital signature to the second terminal 102.
  • the architecture of the data transmission system may further include the second node device 105.
  • the first node device 104 Before the first node device 104 sends the trust credential request information to the KMS 103 according to the trust credential acquisition request sent by the second terminal 102, the first node device 104 may send an authentication request to the second node device 105, when the local database of the second node device 105 includes the second When the terminal 102 broadcasts the service authorization information, the second node device 105 may transmit the broadcast service authorization information of the second terminal 102 to the first node device 104, and the first node device 104 transmits the trust credential request information to the KMS 103.
  • the architecture of the data transmission system may further include a Home Subscriber Server (HSS) 107.
  • HSS Home Subscriber Server
  • the first node device 104 transmits the authentication request to the second terminal 102 to the second node device 105
  • the second node device 105 may send authentication request information to the second terminal 102 to the HSS 107.
  • the HSS 107 may generate broadcast service authorization information for the second terminal 102, and may serve the broadcast of the second terminal 102.
  • the authorization information is forwarded to the first node device 104 by the second node device 105.
  • the architecture of the data transmission system may further include the base station 106 of the cell where the second terminal 102 is located.
  • the base station 106 may send a time-frequency resource acquisition request to the base station 106, and the base station 106 detects whether the broadcast service authorization information of the second terminal 102 exists in the local database of the base station 106, and the local database exists in the base station 106.
  • the base station 106 may allocate the time-frequency resource to the second terminal 102; when the broadcast service authorization information of the second terminal 102 does not exist in the local database of the base station 106, the base station 106 may go to the second node.
  • the device 105 sends an authentication request to the second terminal 102.
  • the second node device 105 can provide a broadcast service to the second terminal 102.
  • the authorization information is sent to the base station 106, the base station 106 can allocate the time-frequency resource to the second terminal 102, and the second terminal 102 transmits the broadcast security information to the first terminal 101 by using the time-frequency resource allocated by the base station 106.
  • the first terminal 101 and the second terminal 102 may be referred to as user equipment (UE, User Equipment), mobile station, access terminal, subscriber unit, subscriber station, mobile station, remote station, remote terminal, mobile device, terminal,
  • a wireless communication device, a user agent, or a user device, etc. may specifically be a station (ST, Station) in a WLAN, a cellular phone, a cordless phone, a Session Initiation Protocol (SIP), a wireless local loop (WLL, Wireless Local Loop), personal digital processing (PDA, Personal Digital Assistant), handheld devices with wireless communication capabilities, computing devices, other processing devices connected to wireless modems, in-vehicle devices, wearable devices, mobile in future 5G networks Any one of stations and terminal devices in a future evolved PLMN network.
  • SIP Session Initiation Protocol
  • WLL Wireless Local Loop
  • PDA Personal Digital Assistant
  • the first terminal 101 may be configured to receive data.
  • the first terminal 101 may also be used to send data to other terminals, where the number of the first terminals 101 may be at least one;
  • the second terminal 102 may be configured to send data.
  • the second terminal 102 may also be configured to receive data sent by other terminals.
  • the number of the second terminals 102 may be at least one, which is not specifically implemented by the present invention. The limitations of the example.
  • the KMS 103 may specifically be a V2X KMS, which is mentioned in 3GPP TR 33.885 V0.3.0. Its function is to generate a temporary public-private key pair of the user and digitally sign the temporary public key to provide proof of legality of the temporary public key. It should be noted that the data transmission system in the embodiment of the present invention may include at least one KMS 103.
  • the first node device 104 may specifically be a Temporary ID Management Function, which is mentioned in 3GPP TR 33.885 V0.4.0. Its function is as follows:
  • the direct communication between the terminal and the KMS 103 can be avoided to expose the connection location of the KMS 103, thereby leaking sensitive information stored in the KMS 103, such as the second public key and the second private key of the KMS 103.
  • the temporary public-private key pair generated by KMS103 and the first digital signature calculated by calculating the temporary public key can improve the security of the feedback information.
  • the KMS 103 maintains the independence of the KMS 103 function, that is, the KMS 103 only communicates directly with the first node device 104.
  • the KMS 103 is only used to generate the temporary public-private key pair of the user, and digitally sign the temporary public key without the temporary public-private of the terminal.
  • the key pair is associated with the terminal identifier and stored.
  • the second node device 105 may specifically be a vehicle to a V2X Control Function (V2X Control Function), which is mentioned in 3GPP TR 23.785v1.1.0.
  • V2X Control Function is a logic unit that provides network related functions required by the V2X.
  • the logic unit provides V2X service authorization information of the terminal.
  • the base station 106 may be a base station (NB, NodeB) in Wideband Code Division Multiple Access (WCDMA) or an evolved base station (eNB) in an LTE system.
  • NB NodeB
  • WCDMA Wideband Code Division Multiple Access
  • eNB evolved base station
  • the user profile of the HSS 107 stores the user profile and performs user authentication and authorization.
  • the information that the HSS can process includes: user identification; user security information, that is, network access control information for authentication and authorization.
  • Digital signature refers to a string of digits generated only by the sender and not forged by others. This digit string is also a valid proof of the authenticity of the data sent by the sender.
  • the digital signature can provide integrity, identity authentication and non-repudiation. Sexual protection.
  • the digital signature consists of three algorithms: the key generation algorithm Gen, the signature algorithm Sign, and the verification algorithm Verf.
  • the key generation algorithm Gen is used to generate a digitally signed public-private key pair (PK, SK), which is denoted as (PK, SK) ⁇ Gen.
  • the signature algorithm Sign generates a signature Sig by inputting the signature private key SK and the message msg, which is denoted as Sig ⁇ Sign(SK, msg).
  • Msg broadcast message, that is, the content of the message that the second terminal 102 needs to broadcast at the application layer, such as the speed of the vehicle or the current location.
  • the data length of the broadcast message may be less than 300 bytes.
  • SKA The first private key of the second terminal 102 is used to generate a second digital signature.
  • PKA, SKA is a temporary public-private key pair generated by KMS103.
  • the update frequency of the temporary public-private key pair is determined by the anti-tracking demand parameter in the operator policy and standard, that is, KMS103 generates different temporary public and private keys based on the preset update frequency. Correct.
  • PKA The first public key of the second terminal 102, which is also the temporary identity of the second terminal 102, is used to verify the second digital signature.
  • Time The effective start time of the temporary public-private key pair.
  • the validity period of the temporary public-private key pair is determined by the anti-tracking requirement parameter in the operator's policy and standard. For example, if the validity period specified by the operator is the time parameter duration (for example, 5 minutes), the temporary public-private key pair is The valid range is [Time, Time+Duration].
  • the valid interval for verifying the PKA is not explicitly given, because the second terminal 102 calculates the broadcast message based on the first private key to obtain the second digital signature, and sends the broadcast security information to the first.
  • the terminal 101 first detects whether the broadcast message is valid based on the generation time of the broadcast security information, generates a timestamp, and then detects whether the SKA is expired based on the effective start time, because the configured timestamp is small, for example 100ms, the detection time of the SKA is compared with the time of the SKA, up to 100ms later. This length of time is negligible in the key validity period, which ensures that the detection time of the verification SKA is not too late than the SKA usage time.
  • the first terminal 101 detects that the SKA has expired, it is not necessary to further detect whether the PKA is expired. When the first terminal 101 determines that the SKA is valid, it can also determine that the PKA is valid; when the first terminal 101 determines that the SKA expires, the PKA can also be determined. Expired.
  • Duration A time parameter used to indicate the validity period of the first public key, which is specified by the operator (or uniformly specified by the 3GPP standard).
  • the first digital signature is that the KMS 103 uses the second private key KSAK of the KMS 103, the first public key PKA, and the valid start time Time as input, and invokes the digital signature generated by the signature algorithm Sign.
  • the purpose of the first digital signature is to enable the first terminal 101 to verify the validity and legitimacy of the temporary identity PKA of the second terminal 102.
  • KMS ID is the identity of KMS103.
  • a KMS103 has only one KMS ID and a unique pair of digital signature key pairs (KPAK, KSAK), the KMS ID remains fixed, (KPAK, KSAK) can remain fixed, optional, (KPAK, KSAK) ) can be updated periodically.
  • the first terminal 101 determines the second public key KPAK of the corresponding KMS 103 based on the KMS ID , and verifies the first digital signature based on the KPAK.
  • KSKA The second private key of KMS 103 for generating the first digital signature.
  • KPKA The second public key of KMS 103 for verifying the first digital signature.
  • Timestamp The timestamp of the broadcast message.
  • the time stamp is the generation time when the second terminal 102 generates the second digital signature.
  • the first terminal 101 After receiving the broadcast security information, the first terminal 101 first detects the timestamp timestamp, that is, subtracts the timestamp from the receiving time of receiving the broadcast security information, and if the obtained value is greater than the preset time threshold, determines that the broadcast security information is replayed. Information, refuse to process the broadcast security information; otherwise, detect whether the first public key expires.
  • the preset time threshold may be a preset duration, such as 200 ms or 1 s.
  • the second digital signature is the second terminal 102 with the first private key SKA and (msg, PKA, Time, The KMS ID , timestamp) is used as an input to call the digital signature generated by the signature algorithm Sign.
  • the role of the second digital signature is to enable the first terminal 101 to verify (msg, PKA, Time, The legality of the source of KMS ID , timestamp).
  • the broadcast security information may be (msg, PKA, Time, KMS ID, timestamp, Sig).
  • FIG. 2 is a schematic flowchart of a data transmission method according to an embodiment of the present invention, and the data transmission method in the embodiment of the present invention is shown in FIG. Can include:
  • the second terminal sends an authentication request to the second node device, where the authentication request carries the terminal identifier of the second terminal.
  • the second terminal may perform the EPS-AKA protocol and negotiates the network attached storage (NAS) layer key and the application server (AS) layer key
  • the second terminal may
  • the two-node device for example, the V2X Control Function
  • sends an authentication request and the authentication request carries the terminal identifier (for example, IDA) of the UEA.
  • the first terminal performs the EPS-AKA protocol, and after negotiating the NAS layer key and the AS layer key, may send an authentication request to the V2X Control Function, where the authentication request carries the terminal identifier of the UEB ( For example IDB).
  • the terminal identifier may be used to uniquely identify the terminal.
  • the terminal identifier may include an Internet Protocol Address (IP) of the terminal or an International Mobile Equipment Identity (IMEI).
  • IP Internet Protocol Address
  • IMEI International Mobile Equipment Identity
  • the UEA may configure a Subscriber Identity Module (SIM) related information and a required parameter for secure communication with the first node device (eg, Temporary ID Management Function). .
  • the UEA may establish a ⁇ (KMS ID , KPAK) ⁇ list, initially an empty table, for storing the system identifier (eg, KMS ID ) of the Key Management System (KMS) sent by the Temporary ID Management Function and its corresponding Two public keys (such as KPAK).
  • the trusted address can be configured for the UEA.
  • the trusted address can be the access path of the KPAK of any KMS.
  • each KMS can send the current KPAK of the KMS to the designated node device, and then specify the node device to store.
  • the KMS ID of each KMS and its corresponding KPAK when the UEA needs to acquire the KPAK of the specified KMS, the UEA can access the designated node device based on the preset trusted address, and download the KPAK corresponding to the KMSID of the specified KMS from the designated node device.
  • the UEA can also configure necessary security parameters, such as an anti-replay requirement parameter (ie, a preset time threshold), and a validity period of the first public key (ie, a time parameter Duration).
  • the UEB may configure the SIM card related information and the necessary parameters for secure communication with the Temporary ID Management Function.
  • the UEB may establish a ⁇ (KMS ID , KPAK) ⁇ list, initially an empty table, for storing the system identifier (eg, KMS ID ) of the Key Management System (KMS) sent by the Temporary ID Management Function and its corresponding Two public keys (such as KPAK).
  • KMS Key Management System
  • the UEB can also be configured with a trusted address, which can be an access path for obtaining KPAK of any KMS.
  • the UEB may also be configured with necessary security parameters, such as an anti-replay requirement parameter (ie, a preset time threshold), and a validity period of the first public key (ie, a time parameter Duration).
  • the base station (for example, an eNB) may be configured to process related parameters of the time-frequency resource acquisition request.
  • the parameter configured for the eNB may include a shortest time interval for the user to request time-frequency resources. The shortest time interval is determined by the operator based on operational strategy and standard requirements.
  • the home subscriber server (for example, HSS) may be configured with the subscription authorization information of the LTE-V user and related parameters of communication between the HSS and the V2X Control Function.
  • the HSS may store the terminal identifier of the terminal that has opened the V2X service.
  • the V2X Control Function can be configured with related information, including parameters related to communication between the terminal, the HSS or the Temporary ID Management Function, and the broadcast service authorization information of the terminal that has opened the V2X service.
  • the Temporary ID Management Function can be configured with related parameters, including related parameters for communication with the terminal, the V2X Control Function, or the KMS.
  • the local database of the Temporary ID Management Function can store the terminal identifier and its corresponding feedback information.
  • KMS can be configured with relevant information, including parameters related to its communication with the Temporary ID Management Function, and the KMS ID and key information (KPAK, KSAK) of the KMS.
  • KPAK KMS ID and key information
  • the second node device sends the terminal identifier of the second terminal and the broadcast service grant information to the base station of the cell where the second terminal is located.
  • the V2X Control Function may search for the broadcast service authorization information of the UEA in the local database of the V2X Control Function according to the terminal identifier of the UEA, and the local database of the V2X Control Function includes the broadcast of the UEA.
  • the V2X Control Function may send the terminal identifier of the UEA and its broadcast service grant information to the base station (eg, eNB) of the cell where the UEA is located; and when the local database of the V2X Control Function does not include the broadcast service grant information of the UEA, the V2X The control function may send an authentication request to the HSS, and the authentication request carries the terminal identifier of the UEA.
  • the HSS may detect the V2X service provisioning of the UEA according to the authentication request.
  • the HSS may generate The broadcast service authorization information of the UEA is sent to the V2X Control Function, and the V2X Control Function can store the broadcast service authorization information of the UEA, and send the broadcast service authorization information of the UEA to the eNB; when the UEA does not open the V2X service
  • the HSS sends the V2X service to the V2X service.
  • the V2X Control Function stores the V2X service of the UEA.
  • the V2X Control Function sends the V2X service to the eNB.
  • the eNB determines that the UEA does not receive the broadcast service. Authorization.
  • the V2X Control Function may search for the broadcast service authorization information of the UEB in the local database of the V2X Control Function according to the terminal identifier of the UEB, where the local database of the V2X Control Function includes the broadcast of the UEB.
  • the V2X Control Function may send the terminal identifier of the UEB and its broadcast service grant information to the base station (eg, eNB) of the cell where the UEB is located; when the local database of the V2X Control Function does not include the broadcast service grant information of the UEB, the V2X
  • the control function may send an authentication request to the HSS, and the authentication request carries the terminal identifier of the UEB.
  • the HSS may detect the V2X service provisioning of the UEB according to the authentication request.
  • the HSS may generate the broadcast service authorization information of the UEB. And transmitting the broadcast service authorization information to the V2X Control Function, where the V2X Control Function can store the broadcast service authorization information of the UEB, and send the broadcast service authorization information of the UEB to the eNB; when the UEB does not enable the V2X service, the HSS does not Send V2X service to V2X Control F
  • the V2X Control Function stores the V2X service provisioning of the UEB.
  • the V2X Control Function sends the UE2 to the eNB without the V2X service being enabled.
  • the eNB determines that the UEB is not authorized by the broadcast service.
  • the V2X Control Function may determine the base station of the cell where the UEA is currently located, and send the broadcast service authorization information of the UEA to the determined base station.
  • the V2X Control Function may determine the base station of the cell where the UEB is currently located, and send the broadcast service authorization information of the UEB to the determined base station.
  • the second terminal sends a trusted credential obtaining request to the first node device, where the trusted credential obtaining request carries the terminal identifier of the second terminal.
  • the UEA may send a trusted credential obtaining request to the Temporary ID Management Function through the secure channel every preset time interval, and the trusted credential obtaining request carries the terminal identifier of the UEA.
  • the UEB may send a trusted credential obtaining request to the Temporary ID Management Function through the secure channel, where the trusted credential obtaining request may carry the terminal identifier of the UEB.
  • the UEB may send a trusted credential obtaining request to the Temporary ID Management Function through the secure channel every preset time interval, and the trusted credential obtaining request carries the terminal identifier of the UEB.
  • the preset duration may be less than or equal to the update frequency of the temporary public-private key pair, which is not limited by the embodiment of the present invention.
  • the first node device sends an authentication request to the second node device, where the authentication request carries the terminal identifier of the second terminal.
  • the Temporary ID Management Function may send an authentication request to the V2X Control Function to determine whether the UEA has broadcast authority, and the authentication request may carry the terminal identifier of the UEA.
  • the Temporary ID Management Function may send an authentication request to the V2X Control Function to determine whether the UEB has the broadcast right, and the authentication request may carry the terminal identifier of the UEB.
  • the second node device sends the terminal identifier of the second terminal and the broadcast service authorization information to the first node device.
  • the V2X Control Function may search for the broadcast service authorization information of the UEA in the local database of the V2X Control Function according to the terminal identifier of the UEA carried in the authentication request.
  • the V2X Control Function sends the terminal identifier of the UEA and its broadcast service authorization information to the Temporary ID Management Function.
  • the V2X Control Function may send an authentication request to the HSS, where the authentication request carries the terminal identifier of the UEA, and the HSS may obtain the V2X service provisioning of the UEA.
  • the HSS may generate the broadcast service authorization information for the UEA, and send the broadcast service authorization information of the UEA to the V2X Control Function, where the V2X Control Function may store the terminal identifier of the UEA and its corresponding broadcast service authorization. Information and send the UEA's broadcast service authorization information to the Temporary ID Management Function.
  • the HSS may generate indication information indicating that the UEA does not open the V2X service, and send the indication information to the V2X Control Function, and the V2X Control Function sends the indication information to the Temporary ID Management Function.
  • the obtained feedback information is sent to the terminal, so that the terminal sends a broadcast message to another terminal based on the feedback information. Users who do not have broadcast rights, steal broadcast rights, or use expired rights to send broadcast messages can improve the legitimacy of broadcast sources.
  • the V2X Control Function may search for the broadcast service authorization information of the UEB in the local database of the V2X Control Function according to the terminal identifier of the UEB carried in the authentication request.
  • the local database of the V2X Control Function includes the broadcast service grant information of the UEB
  • the V2X Control Function sends the terminal identifier of the UEB and its broadcast service grant information to the Temporary ID Management Function.
  • the first node device sends the trusted credential request information to the key management system according to the trust credential acquisition request.
  • the Temporary ID Management Function may determine that the UEA has the broadcast right, and then send the trusted credential request information to the KMS according to the trust credential acquisition request sent by the UEA.
  • the Temporary ID Management Function may select a KMS with the highest degree of idleness according to the service situation (such as the idleness of each KMS), and send the trusted credential request information to the selected KMS.
  • the trust credential request information sent by the Temporary ID Management Function to the KMS may carry a valid start time Time of the credential credential, and the trust credential request information may not carry the terminal identifier of the UEA.
  • the Temporary ID Management Function may send a reject message to the UEA that refuses to process the trust credential acquisition request sent by the UEA, and the reject message may carry the rejection message.
  • the reason for the rejection processing may be “UEA does not open V2X service, and does not have broadcast rights”.
  • the Temporary ID Management Function receives the V2X Control Function. After the broadcast service authorization information of the UEB is sent, it may be determined that the UEB has the broadcast right, and then the trusted credential request information is sent to the KMS according to the trust credential acquisition request sent by the UEB.
  • the key management system generates a trust credential according to the trust credential request information, where the trust credential includes the first public key of the second terminal and the first private key thereof.
  • the KMS may invoke the preset key generating algorithm Gen to generate the trusted credential, and the trusted credential may include the first public key PKA of the UEA and Its first private key, SKA.
  • the trust credential can be updated periodically, and the update frequency is determined by the anti-tracking demand parameter in the operator policy and standard. It should be noted that, when the Temporary ID Management Function sends the trust credential request information to the KMS without carrying the terminal identifier, the KMS does not know the specific terminal that receives the credential credential. In the embodiment of the present invention, the trusted credential is periodically updated, and the third party cannot identify the identity of the terminal by which the first public key is used to prevent the user from being tracked.
  • the KMS may invoke the preset key generating algorithm Gen to generate the trusted credential of the UEB, where the trusted credential may include the first public of the UEB. The key and the first private key of the UEB.
  • the key management system calculates the first public key based on the second private key of the key management system to obtain a first digital signature.
  • any KMS is configured with a unique system identifier KMSID and a second private key KSAK of the KMS and a second public key KPAK.
  • the PKA can be calculated based on the KSAK to obtain the first digital signature.
  • the trusted credential request information may carry a valid start time of the credential credential, wherein the valid start time of the credential credential is a valid start time of the first public key or a valid start time of the first private key, and the KMS may invoke Pre-signature algorithm Sig, signing PKA and Time with KSAK to get the first digital signature which is (KSAK, (PKA, Time)).
  • the first digital signature of the UEB may be obtained by calculating the first public key of the UEB based on the KSAK.
  • the trust credential request information sent by the Temporary ID Management Function to the KMS according to the trust credential acquisition request sent by the UEB may carry the valid start time of the trust credential of the UEB, where the credential credential has The effective start time is the effective start time of the first public key of the UEB or the effective start time of the first private key of the UEB.
  • the KMS can invoke the preset signature algorithm to use the KSAK to trust the first public key of the UEB and the UEB.
  • the valid start time of the voucher is signed to obtain the first digital signature of the UEB.
  • the key management system sends the feedback information to the first node device, where the feedback information includes a trust credential, a first digital signature, a system identifier of the key management system, and a second public key.
  • the feedback information of the UEA may be generated, and the feedback information of the UEA is sent to the Temporary ID Management Function, where the feedback information may include the trust credential of the UEA and the first digital signature of the UEA.
  • the feedback information may include: PKA, SKA, Time, And KPAK.
  • the Temporary ID Management Function can be accessed via a secure channel (PKA, SKA, Time, KMSID, KPAK) is sent to UEA.
  • the Temporary ID Management Function receives the trust credential acquisition request sent by the UEA, sends the trust credential request information to the KMS according to the trust credential acquisition request, and after receiving the feedback information sent by the KMS, may send the feedback information to the UEA terminal.
  • the identifiers are associated.
  • the Temporary ID Management Function may generate the correspondence between the terminal identifier of the UEA and the PKA, Time, KMSID, and KPAK, and store the terminal identifier of the UEA and its corresponding PKA, Time, KMSID, and KPAK, ie (IDA, PKA) , Time, KMSID, KPAK) are stored in the local database of the Temporary ID Management Function.
  • the Temporary ID Management Function can delete (IDA, PKA, Time, KMSID, KPAK) in the local database.
  • the sender can be found according to the Temporary ID Management Function (IDA, PKA, Time, KMSID, KPAK), which can be used to implement broadcast message auditing. .
  • the feedback information of the UEB may be generated, and the feedback information of the UEB is sent to the Temporary ID Management Function, where the feedback information may include the trusted credential of the UEB and the first digital signature of the UEB.
  • the feedback information of the UEB may include: the trusted credential of the UEB , UEB Valid start time of the trust credential, the first digital signature of the UEB, and KPAK.
  • the Temporary ID Management Function receives the trust credential acquisition request sent by the UEB, sends the trust credential request information to the KMS according to the trust credential acquisition request, and after receiving the feedback information sent by the KMS, may send the feedback information of the UEB to the UEB.
  • the terminal identifiers are associated with each other.
  • the Temporary ID Management Function may generate a terminal identifier of the UEB, a first public key of the UEB, a valid start time of the UEB's trusted credentials, a KMSID, and a KPAK, and store the terminal identifier of the UEB and Corresponding UEB's first public key, UEB's trusted credential effective start time, KMSID, and KPAK.
  • the Temporary ID Management Function may delete the terminal identifier of the UEB in the local database and the corresponding first public key of the UEB, the effective start time of the UEB's trust credential, the KMSID, and the KPAK.
  • the first node device sends the feedback information to the second terminal.
  • the Temporary ID Management Function may send the feedback information of the UEA to the UEA.
  • the UEA may obtain the KMSID and the KPAK in the feedback information, generate a correspondence between the KMSID and the KPAK, and store the KMSID in the local database of the UEA. Corresponding KPAK.
  • the KMS KKK and the KSAK that are pre-configured by the KMS may be periodically updated.
  • the KPAK corresponding to the KMSID received by the UEA last time may not be the same as the KPAK corresponding to the currently received KMSID. Based on this, the UEA is local to the UEA.
  • the original KPAK corresponding to the KMSID may be detected in the local database of the UEA.
  • the UEA may pass the Delete the original KPAK after the preset duration.
  • the preset duration may be a pre-configured time period, such as 1s or 2s.
  • the feedback information may also carry the KMSID of other KMSs in the vicinity and the KPAK of each KMS.
  • the UEA may generate the KMSID and Correspondence of KPAK, and store the KMSID and its corresponding KPAK in the local database of UEA.
  • the UEA stores the KMSID and its corresponding one in the local database of the UEA. After the new KPAK, the original KPAK corresponding to the KMSID exists in the local database of the UEA.
  • the UEA may delete the original KPAK after the preset duration.
  • the KPAK sent by the Temporary ID Management Function is the updated KPAK corresponding to the KMS, and the UEA may update the KPAK of each KMS to ensure the accuracy of the KPAK.
  • the Temporary ID Management Function may send the feedback information of the UEB to the UEB.
  • the feedback information may also carry the KMSID of other KMSs in the vicinity and the KPAK of each KMS.
  • the UEB may generate the KMSID and Correspondence of KPAK, and store the KMSID and its corresponding KPAK in the local database of the UEB.
  • the UEB may detect whether the original KPAK corresponding to the KMSID exists in the local database of the UEB, and the KMSID corresponding to the local database in the UEB exists.
  • the UEB can delete the original KPAK after a preset duration.
  • the KPAK sent by the Temporary ID Management Function is the updated KPAK corresponding to the KMS, and the UEB may update the KPAK of each KMS to ensure the accuracy of the KPAK.
  • the UEB may obtain the KMSID and the KPAK in the feedback information, generate a correspondence between the KMSID and the KPAK, and store the KMSID in the local database of the UEB. Corresponding KPAK.
  • the KMS KKK and the KSAK that are pre-configured by the KMS may be periodically updated, and the KPAK corresponding to the KMSID received by the UEB and the KPAK corresponding to the currently received KMSID may be different. Based on this, the UEB is local to the UEB.
  • the original KPAK corresponding to the KMSID may be detected in the local database of the UEB.
  • the UEB may pass the Delete the original KPAK after the preset duration.
  • the second terminal sends a time-frequency resource acquisition request to the base station, where the time-frequency resource acquisition request carries the terminal identifier of the second terminal.
  • the UE may send a time-frequency resource acquisition request to the base station eNB of the cell where the UEA is located, where the time-frequency resource acquisition request carries the terminal identifier of the UEA.
  • the base station allocates time-frequency resources to the second terminal.
  • the eNB may search for the broadcast service authorization information of the UEA in the local database of the eNB.
  • the eNB may The UEA allocates a time-frequency resource; when the local database of the eNB does not include the broadcast service grant information of the UEA, the eNB may send a reject message rejecting the allocation of the time-frequency resource to the UEA, and the reject message may carry the reject assignment reason, exemplary, rejecting the allocation
  • the reason may be that "UEA does not have broadcast service rights and cannot allocate time-frequency resources to UEA."
  • the base station needs to detect whether the sending end has the broadcast right, and allocates the time-frequency resource to the sending end when the sending end has the broadcast right, which can prevent the wireless resource from being abused by the malicious user.
  • the second terminal calculates the broadcast message based on the first private key to obtain a second digital signature.
  • the UEA may generate a broadcast message msg, and calculate the msg based on the SKA to obtain a second digital signature.
  • the generation time timestamp of the second digital signature may be generated. For example, the system time for the UEA to start calculating the msg is 10:00 on October 25, 2016, and the UEA may determine The second digital signature is generated at 10:00 on October 25, 2016.
  • the UEA can invoke the preset signature algorithm sig, using the SKA pair (msg, PKA, Time, KMSID, KPAK, timestamp) is signed to obtain the second digital signature sig, ie Sig ⁇ Sign(SKA,(msg,PKA,Time, KMSID, timestamp)).
  • the second terminal sends the broadcast security information to the first terminal by using the time-frequency resource allocated by the base station, where the broadcast security information includes a broadcast message, a second digital signature, a first digital signature, a first public key, and a system identifier.
  • the broadcast security information may be generated, where the broadcast security information may be (msg, PKA, Time, The KMSID, timestamp, sig), the UEA may send the broadcast security information to the UEB by using the time-frequency resource allocated by the eNB.
  • the broadcast security information may be (msg, PKA, Time, The KMSID, timestamp, sig)
  • the UEA may send the broadcast security information to the UEB by using the time-frequency resource allocated by the eNB.
  • the first terminal acquires a second public key corresponding to the system identifier, and performs verification on the first digital signature based on the second public key. When the verification succeeds, the second terminal is identified as a valid terminal.
  • the first digital signature is verified to detect whether the sending end is a false identity or a fraudulent identity, and the third party may be prevented from using a false identity or a fraudulent identity to send a broadcast message, thereby improving the legitimacy of the broadcast message source.
  • the UEB may obtain the broadcast security information receiving time, and obtain the second digital signature generation time timestamp in the broadcast security information, where the difference between the receiving time and the timestamp is less than the preset.
  • the UEB may determine that the broadcast security information is not a playback message; when the difference between the receiving time and the timestamp is greater than or equal to a preset time threshold and is less than or equal to 0, the UEB may determine the broadcast.
  • the security information is a replay message, which in turn deletes the broadcast security information.
  • the embodiment of the present invention detects whether the value of the broadcast security information and the second digital signature is less than the preset time threshold, and can identify whether the broadcast security information is repeatedly sent by a third party, causing information confusion and preventing Broadcast messages are repeated attacks.
  • the UEB may determine the valid interval of the trust credential based on the preset time parameters Duration and Time, that is, the valid interval of the trust credential is [Time, Time+Duration], when timestamp When located in the valid interval, the UEB may determine that the trust credential is a valid trust credential; when the timestamp is outside the valid interval, the UEB may determine that the trust credential expires, thereby deleting the broadcast security information.
  • the embodiment of the invention can detect whether the trust credential is expired, prevent the third party from using the expired identity to send the broadcast message, and improve the legality of the broadcast message source.
  • the UEB may search for the corresponding KPAK in the local database of the UEB according to the KMSID in the broadcast security information.
  • the UEB may perform the first digital signature based on the KPAK corresponding to the KMSID. If the KPAK corresponding to the KMSID does not exist in the local database of the UEB, the UEB can refer to the trusted address according to the preset
  • the KPAK is downloaded from the node device, where the second public key of all KMSs is stored in the designated node device.
  • the UEB may perform verification on the first digital signature based on the updated KPAK to obtain a first check of the first digital signature.
  • the first digital signature is verified based on the original KPAK, and a second verification result of the first digital signature is obtained.
  • the UEB may determine that the UEA is Effective terminal.
  • the first terminal checks the second digital signature based on the first public key, and processes the broadcast message when the verification succeeds.
  • the embodiment of the present invention utilizes the 3GPP-AKA authentication mechanism and introduces an asymmetric cryptosystem to protect the security of broadcast messages, which not only solves the security problem of vehicle broadcasting, but also directly relies on the cellular network, thereby greatly reducing the deployment cost of the infrastructure. At the same time, it can reduce transmission overhead and storage, and reduce management complexity.
  • the second terminal sends a trust credential acquisition request to the first node device, and the first node device acquires the broadcast service authorization information of the second terminal by using the second node device, and obtains the trust credential according to the trust credential.
  • the key management system calculates the first public key in the generated trust credential based on the second private key of the key management system, obtains the first digital signature, and includes the trust And sending, by the second terminal, the broadcast security information to the first terminal, where the first terminal performs the first digital signature based on the second public key.
  • the second terminal is identified as a valid terminal, and the first terminal checks the second digital signature based on the first public key.
  • the broadcast message is processed, and the broadcast message can be ensured. Reduce the overhead and the amount of data transferred based on the legitimacy of the source.
  • FIG. 3 is a flowchart of a data transmission method according to another embodiment of the present invention.
  • the data transmission method in the embodiment of the present invention may include:
  • the second terminal sends a trusted credential obtaining request to the first node device, where the trusted credential obtaining request carries the terminal identifier of the second terminal.
  • the UEA before the UEA sends the trust credential acquisition request to the Temporary ID Management Function, the UEA performs the EPS-AKA protocol, and after negotiating the NAS layer key and the AS layer key, may send an authentication request to the V2X Control Function, and the authentication is performed.
  • the request carries the terminal identifier of the UEA.
  • the V2X Control Function may provide the UEA with relevant service parameters.
  • the UEB before the UEB sends the trust credential acquisition request to the Temporary ID Management Function, the UEB performs the EPS-AKA protocol, and after negotiating the NAS layer key and the AS layer key, may send an authentication request to the V2X Control Function, and the authentication is performed.
  • the request carries the terminal identifier of the UEB.
  • the V2X Control Function may provide the UEB with relevant service parameters.
  • the first node device sends an authentication request to the second node device, where the authentication request carries the terminal identifier of the second terminal.
  • the second node device sends the terminal identifier of the second terminal and the broadcast service authorization information to the first node device.
  • the first node device sends the trusted credential request information to the key management system according to the trust credential obtaining request.
  • the key management system generates a trust credential according to the trust credential request information, where the trust credential includes the first public key of the second terminal and the first private key thereof.
  • the key management system calculates the first public key based on the second private key of the key management system to obtain a first digital signature.
  • the key management system sends the feedback information to the first node device, where the feedback information includes a trust credential, a first digital signature, a system identifier of the key management system, and a second public key.
  • the first node device sends the feedback information to the second terminal.
  • the second terminal sends a time-frequency resource acquisition request to the base station of the cell where the second terminal is located, where the time-frequency resource acquisition request carries the terminal identifier of the second terminal.
  • the base station allocates time-frequency resources to the second terminal.
  • the base station After receiving the time-frequency resource acquisition request sent by the UEA, the base station checks the broadcast service authorization information of the UE A in the local database of the base station, and when the local database of the base station includes the broadcast service authorization information of the second terminal, the base station may allocate the information to the second terminal.
  • the base station initiates an authentication request of the UEB to the V2X Control Function.
  • the base station may The broadcast service grant information of the UEB is stored in a local database of the base station.
  • the base station receives broadcast service authorization information of the second terminal that is sent by the second node device.
  • the base station allocates time-frequency resources to the second terminal.
  • the second terminal calculates the broadcast message based on the first private key to obtain a second digital signature.
  • the second terminal sends the broadcast security information to the first terminal by using the time-frequency resource allocated by the base station, where the broadcast security information includes a broadcast message, a second digital signature, a first digital signature, a first public key, and a system identifier.
  • the first terminal acquires a second public key corresponding to the system identifier, and performs verification on the first digital signature based on the second public key. When the verification succeeds, the second terminal is identified as a valid terminal.
  • the first terminal checks the second digital signature based on the first public key, and processes the broadcast message when the verification succeeds.
  • the second terminal sends the feedback information including the trust credential and the first digital signature to the second terminal, and the second terminal sends a time-frequency resource acquisition request to the base station, when the local database of the base station does not
  • the base station sends an authentication request to the second node device, and when the base station receives the broadcast service authorization information of the second terminal sent by the second node device, the base station allocates a time frequency to the second terminal.
  • the second terminal uses the time-frequency resource allocated by the base station to send the broadcast security information to the first terminal, and the first terminal checks the first digital signature based on the second public key, and when the verification succeeds, the second terminal is identified as An effective terminal, the first terminal is based on the first public key pair second number The signature is verified.
  • the verification is successful, the broadcast message is processed, and the overhead and the amount of data transmitted can be reduced on the basis of ensuring the legitimacy of the broadcast message source.
  • the embodiment of the present invention further provides a computer storage medium, wherein the computer storage medium can store a program, and the program includes some or all of the method embodiments shown in any one of FIG. 2 or FIG. 3 when executed. step.
  • FIG. 4 is a schematic structural diagram of a terminal according to an embodiment of the present invention.
  • the terminal may be used to implement some or all of the steps in the method embodiment shown in FIG. 2 or FIG.
  • the terminal may include at least a broadcast security information receiving module 401 and a verification module 402, where:
  • the broadcast security information receiving module 401 is configured to receive broadcast security information sent by the second terminal, where the broadcast security information includes a broadcast message, a second digital signature of the broadcast message, and a first digital signature of the second terminal. Determining a first public key of the second terminal and a system identifier of the key management system, the first digital signature being that the key management system is based on the second private key of the key management system to the first public key Calculated, the second digital signature is obtained by the second terminal calculating the broadcast message based on the first private key of the second terminal.
  • the verification module 402 is configured to acquire a second public key of the key management system based on the system identifier, and verify the first digital signature based on the second public key.
  • the second terminal is identified as a valid terminal.
  • the verification module 402 is further configured to perform verification on the second digital signature based on the first public key, and process the broadcast message when the verification is successful.
  • the first digital signature is that the key management system calculates the effective start time of the second private key, the first public key, and the first private key by using a preset signature algorithm. owned.
  • the broadcast security information further includes the valid start time and a generation time of the second digital signature.
  • terminal in the embodiment of the present invention may further include:
  • a determining module 403 configured to determine, by the verification module 402, the first public key based on the preset time parameter and the valid start time before acquiring the second public key of the key management system based on the system identifier The effective interval of the key.
  • the determining module 403 is further configured to: when the generating time is located in the valid interval, determine that the first private key is a valid private key.
  • the terminal in the embodiment of the present invention may further include:
  • the receiving time obtaining module 404 is configured to obtain the receiving time of the broadcast security information before the determining module 403 determines the effective interval of the first private key based on the preset time parameter and the valid starting time.
  • the determining module 403 is further configured to determine, according to the preset time parameter and the effective start time, when a difference between the receiving time and the generating time is less than a preset time threshold, The effective range of a private key.
  • the verification module 402 performs verification on the first digital signature based on the second public key, specifically, to:
  • the second public key, the first public key, the valid start time, and the first digital signature are processed by a preset verification algorithm to obtain a verification result of the first digital signature.
  • the terminal in the embodiment of the present invention may further include:
  • a request sending module 405, configured to send, by the verification module 402, a trust credential acquisition request to the first node device before acquiring the second public key of the key management system based on the system identifier, so that the first node The device sends the trust credential request information to the key management system.
  • the feedback information receiving module 406 is configured to receive feedback information of the first terminal that is forwarded by the key management system by using the first node device, where the feedback information of the first terminal includes the system identifier and the secret The updated second public key of the key management system.
  • the terminal in the embodiment of the present invention may further include:
  • the storage module 407 is configured to: after the feedback information receiving module 405 receives the feedback information of the first terminal that is forwarded by the key management system by the first node device, generate the system identifier and the updated Corresponding relationship of the second public key, and storing the system identifier and its corresponding updated second public key.
  • the deleting module 408 is configured to delete the original second public key after a preset duration, when the original second public key corresponding to the system identifier exists in the local database of the terminal.
  • the verification module 402 acquires a second public key of the key management system based on the system identifier, and performs verification on the first digital signature based on the second public key, specifically :
  • the verification module 402 when the verification is successful, identifies that the second terminal is a valid terminal, and is specifically configured to:
  • the verification module 402 acquires the second public key of the key management system based on the system identifier, specifically for:
  • the verification module 402 performs verification on the second digital signature based on the first public key.
  • the broadcast message is processed, specifically for:
  • the first public key, the second digital signature, and the broadcast security information are processed by a preset verification algorithm to obtain a verification result of the broadcast message.
  • the broadcast message is processed.
  • the broadcast security information receiving module 401 receives the broadcast security information sent by the second terminal, and the verification module 402 acquires the second public key of the key management system based on the system identifier, and based on the second public key pair.
  • the first digital signature is verified.
  • the second terminal is identified as a valid terminal, and the verification module 402 checks the second digital signature based on the first public key.
  • the broadcast message is sent. Processing can reduce the overhead and the amount of data transferred while ensuring the legitimacy of the broadcast message source.
  • FIG. 5 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • the terminal provided by the embodiment of the present invention may be used to implement the implementation of the embodiments of the present invention shown in FIG. 2 or FIG.
  • FIG. 2 or FIG. 2 For the convenience of description, only parts related to the embodiments of the present invention are shown. Without specific details, please refer to the embodiments of the present invention shown in FIG. 2 or FIG.
  • the terminal includes at least one processor 501, such as a CPU, at least one input device 503, at least one output device 504, a memory 505, and at least one communication bus 502.
  • the communication bus 502 is used to implement connection communication between these components.
  • the input device 503 can optionally include a standard wired interface and a wireless interface (such as a WI-FI interface) for receiving broadcast security information sent by the second terminal.
  • the output device 504 can optionally include a standard wired interface and a wireless interface for performing data interaction with the second terminal.
  • the memory 505 may include a high speed RAM memory, and may also include a non-volatile memory such as at least one disk memory.
  • a set of program codes is stored in the memory 505, and the processor 501 calls the program code stored in the memory 505 for performing the following operations:
  • the input device 503 receives the broadcast security information sent by the second terminal, where the broadcast security information includes a broadcast message, a second digital signature of the broadcast message, a first digital signature of the second terminal, and a second terminal a public key and a system identifier of the key management system, wherein the first digital signature is obtained by the key management system calculating the first public key based on a second private key of the key management system, The second digital signature is obtained by the second terminal calculating the broadcast message based on the first private key of the second terminal.
  • the processor 501 acquires a second public key of the key management system based on the system identifier, and performs verification on the first digital signature based on the second public key, and identifies the first when the verification is successful.
  • the second terminal is a valid terminal.
  • the processor 501 checks the second digital signature based on the first public key, and processes the broadcast message when the verification is successful.
  • the first digital signature is obtained by calculating, by the key management system, the effective start time of the second private key, the first public key, and the first private key by using a preset signature algorithm. .
  • the broadcast security information further includes the valid start time and the generation time of the second digital signature
  • the processor 501 obtains the second public key of the key management system based on the system identifier. , you can also do the following:
  • the processor 501 determines an effective interval of the first private key based on the preset time parameter and the valid start time.
  • the processor 501 determines that the first private key is a valid private key.
  • the processor 501 determines the valid interval of the first private key based on the preset time parameter and the valid start time, the following operations may also be performed:
  • the processor 501 acquires the reception time of the broadcast security information.
  • the processor 501 determines the effective interval of the first private key based on the preset time parameter and the valid starting time. .
  • the processor 501 performs verification on the first digital signature based on the second public key, which may be specifically:
  • the processor 501 processes the second public key, the first public key, the valid start time, and the first digital signature by using a preset verification algorithm to obtain a verification result of the first digital signature. .
  • the processor 501 determines that the first digital signature verification is successful.
  • the processor 501 acquires the second public key of the key management system based on the system identifier, the following operations may also be performed:
  • the output device 504 transmits a trust credential acquisition request to the first node device to cause the first node device to transmit the trust credential request information to the key management system.
  • the input device 503 receives feedback information of the first terminal forwarded by the key management system by the first node device, where the feedback information of the first terminal includes the system identifier and an update of the key management system After the second public key.
  • the input device 503 may further perform the following operations:
  • the processor 501 generates a correspondence between the system identifier and the updated second public key, and stores the system identifier and its corresponding updated second public key.
  • the processor 501 deletes the original second public key after a preset duration.
  • the processor 501 obtains the second public key of the key management system based on the system identifier, and performs verification on the first digital signature based on the second public key, which may be:
  • the processor 501 acquires the updated second public key and the original second public key corresponding to the system identifier.
  • the processor 501 checks the first digital signature based on the updated second public key to obtain a first verification result of the first digital signature.
  • the processor 501 checks the first digital signature based on the original second public key to obtain a second verification result of the first digital signature.
  • the processor 501 when the verification is successful, identifies that the second terminal is a valid terminal, and specifically:
  • the processor 501 determines that the second terminal is a valid terminal.
  • the processor 501 acquires the second public key of the key management system based on the system identifier, which may be specifically:
  • the output device 504 downloads the second public key from the specified node device according to the preset trusted address, and all the secrets are stored in the designated node device.
  • the second public key of the key management system is
  • the processor 501 performs the verification on the second digital signature based on the first public key, and when the verification is successful, processing the broadcast message, which may be:
  • the processor 501 processes the first public key, the second digital signature, and the broadcast security information by using a preset verification algorithm to obtain a verification result of the broadcast message.
  • the processor 501 determines that the broadcast message is a valid broadcast message.
  • the processor 501 processes the broadcast message.
  • terminal introduced in the embodiment of the present invention may be used to implement some or all of the processes in the method embodiment introduced in conjunction with FIG. 2 or FIG.
  • FIG. 6 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • the terminal may be used to implement some or all of the steps in the method embodiment shown in FIG. 2 or FIG.
  • the terminal may at least include a feedback information receiving module 601, a computing module 602, and a broadcast security information Sending module 603, wherein:
  • the feedback information receiving module 601 is configured to receive feedback information of the terminal sent by the key management system, where the feedback information includes a trusted credential of the terminal and a first digital signature of the terminal, where the trusted credential includes the first
  • the private key and the first public key are obtained by the key management system calculating the first public key based on the second private key of the key management system.
  • the calculating module 602 is configured to calculate, according to the first private key, a broadcast message, to obtain a second digital signature of the broadcast message.
  • the broadcast security information sending module 603 is configured to send broadcast security information to the first terminal, where the broadcast security information includes the broadcast message, the second digital signature, the first digital signature, the first public key, and The system identification of the key management system.
  • the feedback information receiving module 601 is specifically configured to:
  • the feedback information receiving module 601 sends a trust credential obtaining request to the first node device, so that the first node device sends the trusted credential request information to the key management system, specifically for:
  • the first node device sends an authentication request to the second node device, where the local database of the second node device includes a broadcast to the terminal
  • the second node device sends the broadcast service authorization information to the first node device
  • the first node device sends the trust credential request information to the key management system.
  • the feedback information receiving module 601 sends a trust credential obtaining request to the first node device, so that the first node device sends the trusted credential request information to the key management system, specifically for:
  • the first node device sends an authentication request to the second node device, where the local database of the second node device includes a broadcast to the terminal
  • the second node device sends the broadcast service authorization information to the first node device
  • the second node device sends the broadcast service authorization information to the The base station of the cell in which the terminal is located
  • the first node device sends the trust credential request information to the key management system.
  • the terminal in the embodiment of the present invention may further include:
  • a request sending module 604 configured to send, by the calculating module 602, the time-frequency resource acquisition request to the base station, after the calculation of the broadcast message to obtain a second digital signature of the broadcast message, so that the base station detects the Whether the broadcast service authorization information of the terminal exists in the local database of the base station, and when the broadcast service authorization information of the terminal exists in the local database of the base station, the base station allocates time-frequency resources to the terminal.
  • the broadcast security information sending module 603 is specifically configured to send the broadcast security information to the first terminal by using a time-frequency resource allocated by the base station.
  • the terminal in the embodiment of the present invention may further include:
  • the request sending module 604 is configured to send, by the calculating module 602, the time-frequency resource acquisition request to the base station of the cell where the terminal is located, before the calculation of the broadcast message to obtain the second digital signature of the broadcast message, so that the The base station sends an authorization information acquisition request to the terminal to the second node device, and when the base station receives the broadcast service authorization information sent by the second node device to the terminal, the base station allocates the information to the terminal. Time-frequency resources.
  • the broadcast security information sending module 603 is specifically configured to send the broadcast security information to the first terminal by using a time-frequency resource allocated by the base station.
  • the request sending module 604 sends a time-frequency resource acquisition request to the base station of the cell where the terminal is located, so that the base station sends an authorization information acquisition request to the terminal to the second node device, specifically, to:
  • the base station Sending a time-frequency resource acquisition request to the base station of the cell where the terminal is located, so that the base station detects whether the broadcast service authorization information of the terminal exists in the local database of the base station, where the local database exists in the base station
  • the base station allocates time-frequency resources to the terminal; when the broadcast service authorization information of the terminal does not exist in the local database of the base station, the base station sends a pair to the second node device.
  • the authorization information acquisition request of the terminal is
  • the trust credential request information carries a valid start time of the trust credential
  • the first digital signature is a second private key of the key management system by the key management system by using a preset signature algorithm.
  • the key, the first public key, and the valid start time are calculated.
  • the feedback information further includes the system identifier and the updated second public key of the key management system.
  • terminal in the embodiment of the present invention may further include:
  • the storage module 605 is configured to generate, after the feedback information receiving module 601 receives the feedback information of the terminal sent by the key management system, a correspondence between the system identifier and the updated second public key, and And storing the system identifier and its corresponding updated second public key.
  • the deleting module 606 is configured to delete the original second public key after a preset duration, when the original second public key corresponding to the system identifier exists in the local database of the terminal.
  • the calculating module 602 is specifically configured to: use, by using a preset signature algorithm, the first private key, the broadcast message, the first public key, the effective start time of the trusted credential, The first digital signature, the system identifier, and the generation time of the second digital signature are calculated to obtain the second digital signature information.
  • the feedback information receiving module 601 receives the feedback information of the terminal sent by the key management system, and the calculating module 602 calculates the second digital signature of the broadcast message by calculating the broadcast message based on the first private key.
  • the broadcast security information sending module 603 sends the broadcast security information to the first terminal, which can reduce the overhead and the amount of transmitted data on the basis of ensuring the legitimacy of the broadcast message source.
  • FIG. 7 is a schematic structural diagram of a terminal according to another embodiment of the present invention.
  • the terminal provided by the embodiment of the present invention may be used to implement the implementation of the embodiments of the present invention shown in FIG. 2 or FIG.
  • FIG. 7 For the convenience of description, only parts related to the embodiments of the present invention are shown. Without specific details, please refer to the embodiments of the present invention shown in FIG. 2 or FIG.
  • the terminal includes at least one processor 701, such as a CPU, at least one input device 703, at least one output device 704, a memory 705, and at least one communication bus 702.
  • the communication bus 702 is used to implement connection communication between these components.
  • the input device 703 can optionally include a standard wired interface and a wireless interface, and is configured to receive feedback information of the terminal sent by the key management system.
  • the output device 504 can optionally include a standard wired interface and a wireless interface, for transmitting broadcast security information to the first terminal.
  • the memory 705 may include a high speed RAM memory, and may also include a non-unstable memory such as at least one disk memory.
  • the memory 705 can optionally include at least one storage device located remotely from the aforementioned processor 701. Stored in memory 705 A set of program code is stored, and the processor 701 calls the program code stored in the memory 705 for performing the following operations:
  • the input device 703 receives the feedback information of the second terminal sent by the key management system, where the feedback information includes a trusted credential of the second terminal and a first digital signature of the second terminal, where the trusted credential includes a private key and a first public key, the first digital signature being obtained by the key management system calculating the first public key based on a second private key of the key management system.
  • the processor 701 calculates a second digital signature of the broadcast message by calculating a broadcast message based on the first private key.
  • the output device 704 transmits broadcast security information to the first terminal, the broadcast security information including the broadcast message, the second digital signature, the first digital signature, the first public key, and the key management system System ID.
  • the input device 703 receives the feedback information of the second terminal that is sent by the key management system, and specifically:
  • the output device 704 transmits a trust credential acquisition request to the first node device to cause the first node device to transmit the trust credential request information to the key management system.
  • the input device 703 receives the feedback information that the key management system forwards through the first node device.
  • the output device 704 sends a trusted credential obtaining request to the first node device, so that the first node device sends the trusted credential request information to the key management system, which may be:
  • the output device 704 sends the trust credential acquisition request to the first node device, so that the first node device sends an authentication request to the second node device, when the local database of the second node device includes the When the second terminal broadcasts the service authorization information, the second node device sends the broadcast service authorization information to the first node device, and the first node device sends the trust credential request information to the secret Key management system.
  • the output device 704 sends a trusted credential obtaining request to the first node device, so that the first node device sends the trusted credential request information to the key management system, which may be:
  • the output device 704 sends the trust credential acquisition request to the first node device, so that the first node device sends an authentication request to the second node device, when the local database of the second node device includes the When the second terminal broadcasts the service authorization information, the second node device broadcasts the broadcast The service authorization information is sent to the first node device, and the second node device sends the broadcast service authorization information to a base station of a cell where the second terminal is located, where the first node device requests the trust credential Information is sent to the key management system.
  • the processor 701 calculates the broadcast message to obtain the second digital signature of the broadcast message.
  • the following operations may also be performed:
  • the output device 704 sends a time-frequency resource acquisition request to the base station, so that the base station detects whether the broadcast service authorization information of the second terminal exists in the local database of the base station, and exists in the local database of the base station.
  • the base station allocates time-frequency resources to the second terminal.
  • the output device 704 sends the broadcast security information to the first terminal, which may be specifically:
  • the output device 704 transmits the broadcast security information to the first terminal by using a time-frequency resource allocated by the base station.
  • the processor 701 calculates the broadcast message to obtain the second digital signature of the broadcast message.
  • the following operations may also be performed:
  • the output device 704 sends a time-frequency resource acquisition request to the base station of the cell where the second terminal is located, so that the base station sends an authorization information acquisition request to the second terminal to the second node device, when the base station receives the When the second node device sends the broadcast service grant information to the second terminal, the base station allocates time-frequency resources to the second terminal.
  • the output device 704 sends the broadcast security information to the first terminal, which may be specifically:
  • the output device 704 transmits the broadcast security information to the first terminal by using a time-frequency resource allocated by the base station.
  • the output device 704 sends a time-frequency resource acquisition request to the base station of the cell where the second terminal is located, so that the base station sends an authorization information acquisition request to the second terminal to the second node device, where :
  • the output device 704 sends a time-frequency resource acquisition request to the base station of the cell where the second terminal is located, so that the base station detects whether the broadcast service authorization information of the second terminal exists in the local database of the base station, when the base station When the broadcast service authorization information of the second terminal exists in the local database, the base station allocates time-frequency resources to the second terminal; when the local database of the base station does not have the broadcast service authorization of the second terminal The information is sent by the base station to the second node device The authorization information acquisition request of the second terminal.
  • the trust credential request information carries a valid start time of the trust credential
  • the first digital signature is a second private key of the key management system by the key management system by using a preset signature algorithm.
  • the key, the first public key, and the valid start time are calculated.
  • the feedback information further includes the system identifier and the updated second public key of the key management system, and the input device 703 receives the feedback information of the second terminal sent by the key management system.
  • the processor 701 generates a correspondence between the system identifier and the updated second public key, and stores the system identifier and its corresponding updated second public key.
  • the processor 701 deletes the original second public key after a preset duration.
  • the processor 701 calculates a broadcast message to obtain a second digital signature of the broadcast message, which may be specifically:
  • the processor 701 by using a preset signature algorithm, the first private key, the broadcast message, the first public key, an effective start time of the trusted credential, the first digital signature, the system identifier, and The generation time of the second digital signature is calculated to obtain the second digital signature information.
  • terminal introduced in the embodiment of the present invention may be used to implement some or all of the processes in the method embodiment introduced in conjunction with FIG. 2 or FIG.
  • FIG. 8 is a schematic structural diagram of a node device according to an embodiment of the present invention.
  • the node device may be used to implement some or all of the steps in the method embodiment shown in FIG. 2 or FIG.
  • the node device may include at least a request receiving module 801, a request information sending module 802, a feedback information receiving module 803, and a feedback information sending module 804, where:
  • the request receiving module 801 is configured to receive a trusted credential obtaining request sent by the second terminal.
  • the request information sending module 802 is configured to send the trust credential request information to the key management system according to the trust credential obtaining request.
  • the feedback information receiving module 803 is configured to receive feedback information of the second terminal sent by the key management system, where the feedback information includes a trusted credential of the second terminal and a first digital signature of the second terminal.
  • the trust credential includes a first private key and a first public key
  • the first digital signature is The key management system calculates the first public key based on the second private key of the key management system.
  • the feedback information sending module 804 is configured to send the feedback information to the second terminal.
  • the node device in the embodiment of the present invention may further include:
  • the request sending module 805 is configured to send, by the request information sending module 802, an authentication request to the second node device according to the trusted credential obtaining request, before sending the trusted credential request information to the key management system, so that the first
  • the two-node device detects whether the local database of the second node device includes broadcast service authorization information for the second terminal, and the local database of the second node device includes a broadcast service authorization for the second terminal. And the second node device sends the broadcast service authorization information of the second terminal to the node device.
  • the authorization information receiving module 806 is configured to receive broadcast service authorization information sent by the second node device to the second terminal.
  • the request information sending module 802 is specifically configured to:
  • the effective start time of the trust credential is generated.
  • the trust credential request information carrying the valid start time.
  • the first digital signature is that the key management system calculates the second private key, the first public key, and the valid start time of the key management system by using a preset signature algorithm.
  • the obtained feedback information includes the trust credential, the first digital signature, the valid start time, and a second public key of the key management system.
  • the node device in the embodiment of the present invention may further include:
  • the storage module 807 is configured to: after the feedback information receiving module 803 receives the feedback information sent by the key management system, generate a correspondence between the terminal identifier of the second terminal and the feedback information, and store the terminal identifier. And its corresponding feedback information.
  • the request receiving module 801 receives the trust credential acquisition request sent by the second terminal, and the request information sending module 802 sends the trust credential request information to the key management system according to the trust credential obtaining request, and the feedback information receiving module
  • the 803 receives the feedback information of the second terminal sent by the key management system, and the feedback information sending module 804 sends the feedback information to the second terminal, which can reduce the overhead and the amount of data transmitted on the basis of ensuring the legitimacy of the broadcast message source.
  • FIG. 9 is a schematic structural diagram of a node device according to another embodiment of the present invention.
  • the node device provided in the embodiment of the present invention may be used to implement the foregoing embodiments of the present invention shown in FIG. 2 or FIG.
  • FIG. 2 or FIG. For the convenience of the description, only the parts related to the embodiments of the present invention are shown. The specific technical details are not disclosed. Please refer to the embodiments of the present invention shown in FIG. 2 or FIG.
  • the node device includes at least one processor 901, such as a CPU, at least one input device 903, at least one output device 904, a memory 905, and at least one communication bus 902.
  • the communication bus 902 is used to implement connection communication between these components.
  • the input device 903 can optionally include a standard wired interface and a wireless interface, and is configured to receive a trusted credential acquisition request sent by the second terminal.
  • the output device 904 optionally includes a standard wired interface and a wireless interface, and is configured to send the trusted credential request information to the key management system according to the trusted credential obtaining request.
  • the memory 905 may include a high speed RAM memory, and may also include a non-unstable memory such as at least one disk memory.
  • the memory 905 can optionally include at least one storage device located remotely from the aforementioned processor 901. A set of program codes is stored in the memory 905, and the processor 901 calls the program code stored in the memory 905 for performing the following operations:
  • the input device 903 receives the trust credential acquisition request sent by the second terminal.
  • the output device 904 transmits the trust credential request information to the key management system according to the trust credential acquisition request.
  • the input device 903 receives the feedback information of the second terminal sent by the key management system, where the feedback information includes a trust credential of the second terminal and a first digital signature of the second terminal, the trust credential The first private key and the first public key are obtained, and the first digital signature is obtained by the key management system calculating the first public key based on a second private key of the key management system.
  • the output device 904 transmits the feedback information to the second terminal.
  • the outputting device 904 may further perform the following operations:
  • the output device 904 sends an authentication request to the second node device, so that the second node device detects whether the local database of the second node device includes broadcast service authorization information for the second terminal, when the When the local database of the two-node device includes the broadcast service authorization information for the second terminal, the second node device sends the broadcast service authorization information of the second terminal to the The first node device.
  • the input device 903 receives the broadcast service authorization information sent by the second node device to the second terminal.
  • the output device 904 sends the trusted credential request information to the key management system according to the trusted credential obtaining request, which may be:
  • the processor 901 generates a valid start time of the trust credential.
  • the output device 904 transmits the trust credential request information to the key management system, and the trust credential request information carries the valid start time.
  • the first digital signature is obtained by calculating, by the key management system, the second private key, the first public key, and the valid start time of the key management system by using a preset signature algorithm.
  • the feedback information includes the trust credential, the first digital signature, the valid start time, and a second public key of the key management system.
  • the following operations may also be performed:
  • the processor 901 generates a correspondence between the terminal identifier of the second terminal and the feedback information, and stores the terminal identifier and corresponding feedback information.
  • the node device introduced in the embodiment of the present invention may be used to implement some or all of the processes in the method embodiment introduced in conjunction with FIG. 2 or FIG.
  • FIG. 10 is a schematic structural diagram of a data transmission system according to an embodiment of the present invention.
  • the data transmission system in the embodiment of the present invention may include at least a first terminal 1001, a second terminal 1002, and Key management system 1003, wherein:
  • the second terminal 1002 transmits a trust credential acquisition request to the key management system 1003.
  • the key management system 1003 sends the feedback information of the second terminal 1002 to the second terminal 1002 according to the trust credential acquisition request, where the feedback information includes the trust credential of the second terminal 1002 and the first digital signature of the second terminal 1002.
  • the trust credential includes a first private key and a first public key, the first digital signature being that the key management system 1003 pairs the first public key based on a second private key of the key management system 1003 Calculated.
  • the second terminal 1002 calculates the broadcast message based on the first private key to obtain the broadcast message. a second digital signature, and transmitting broadcast security information to the first terminal 1001, the broadcast security information including the broadcast message, the second digital signature, the first digital signature, the first public key, and The system identification of the key management system 1003.
  • the first terminal 1001 acquires the second public key of the key management system 1003 based on the system identifier, and performs verification on the first digital signature based on the second public key. When the verification succeeds, the identification is performed.
  • the second terminal 1002 is a valid terminal.
  • the first terminal 1001 verifies the second digital signature based on the first public key, and processes the broadcast message when the verification is successful.
  • the second terminal 1002 receives the feedback information of the second terminal 1002 sent by the key management system 1003, and the second terminal 1002 calculates the broadcast message based on the first private key to obtain the broadcast message.
  • Two digital signatures, and the broadcast security information is sent to the first terminal 1001.
  • the first terminal 1001 obtains the second public key of the key management system 1003 based on the system identifier, and checks the first digital signature based on the second public key. When the verification succeeds, the second terminal 1002 is identified as a valid terminal, and the first terminal 1001 checks the second digital signature based on the first public key.
  • the broadcast message is processed, and the broadcast message can be ensured. Reduce the overhead and the amount of data transferred based on the legitimacy of the source.
  • first and second are used for descriptive purposes only and are not to be construed as indicating or implying a relative importance or implicitly indicating the number of technical features indicated.
  • features defining “first” or “second” may include at least one of the features, either explicitly or implicitly.
  • the meaning of "a plurality” is at least two, such as two, three, etc., unless specifically defined otherwise.
  • a "computer-readable medium” can be any apparatus that can contain, store, communicate, propagate, or transport a program for use in an instruction execution system, apparatus, or device, or in conjunction with the instruction execution system, apparatus, or device.
  • computer readable media include the following: electrical connections (electronic devices) having one or more wires, portable computer disk cartridges (magnetic devices), random access memory (RAM), Read only memory (ROM), erasable editable read only memory (EPROM or flash memory), fiber optic devices, and portable compact disk read only memory (CDROM).
  • the computer readable medium may even be a paper or other suitable medium on which the program can be printed, as it may be optically scanned, for example by paper or other medium, followed by editing, interpretation or, if appropriate, other suitable The method is processed to obtain the program electronically and then stored in computer memory.
  • portions of the invention may be implemented in hardware, software, firmware or a combination thereof.
  • multiple steps or methods may be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system.
  • a suitable instruction execution system For example, if implemented in hardware, as in another embodiment, it can be implemented by any one or combination of the following techniques well known in the art: having logic gates for implementing logic functions on data signals. Discrete logic circuits, application specific integrated circuits with suitable combinational logic gates, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
  • each functional unit in each embodiment of the present invention may be integrated into one processing module, or each unit may exist physically separately, or two or more units may be integrated into one module.
  • the above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
  • the integrated modules, if implemented in the form of software functional modules and sold or used as stand-alone products, may also be stored in a computer readable storage medium.
  • the above mentioned storage medium may be a read only memory, a magnetic disk or an optical disk or the like.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Les modes de réalisation de la présente invention concernent un procédé de transmission de données, un terminal, un dispositif de nœud et un système, le procédé consistant à: recevoir, par un premier terminal, des informations de sécurité de diffusion envoyées par un second terminal, les informations de sécurité de diffusion comprenant un message de diffusion, une seconde signature numérique, une première signature numérique, une première clé publique et une identification de système, la première signature numérique étant obtenue au moyen d'un système de gestion de clé effectuant un calcul sur la première clé publique sur la base d'une seconde clé privée, et la seconde signature numérique étant obtenue au moyen du second terminal effectuant un calcul sur le message de diffusion sur la base d'une première clé privée; obtenir une seconde clé publique sur la base de l'identification de système, et vérifier la première signature numérique sur la base de la seconde clé publique; lorsque la vérification est réussie, identifier le second terminal en tant que terminal valide; vérifier la seconde signature numérique sur la base de la première clé publique; lorsque la vérification est réussie, traiter le message de diffusion. Au moyen des modes de réalisation de la présente invention, sur la base d'une garantie de la légitimité d'une source de message de diffusion, le coût de surdébit et la quantité de données à transmettre peuvent être réduits.
PCT/CN2016/104139 2016-10-31 2016-10-31 Procédé de transmission de données, terminal, dispositif de nœud, et système WO2018076377A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201680090122.1A CN109845185B (zh) 2016-10-31 2016-10-31 一种数据传输方法、终端、节点设备以及系统
PCT/CN2016/104139 WO2018076377A1 (fr) 2016-10-31 2016-10-31 Procédé de transmission de données, terminal, dispositif de nœud, et système

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2016/104139 WO2018076377A1 (fr) 2016-10-31 2016-10-31 Procédé de transmission de données, terminal, dispositif de nœud, et système

Publications (1)

Publication Number Publication Date
WO2018076377A1 true WO2018076377A1 (fr) 2018-05-03

Family

ID=62024248

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/104139 WO2018076377A1 (fr) 2016-10-31 2016-10-31 Procédé de transmission de données, terminal, dispositif de nœud, et système

Country Status (2)

Country Link
CN (1) CN109845185B (fr)
WO (1) WO2018076377A1 (fr)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110311783A (zh) * 2019-05-30 2019-10-08 平安科技(深圳)有限公司 基于群签名的用户归属验证方法、装置和计算机设备
CN110826091A (zh) * 2018-08-14 2020-02-21 珠海金山办公软件有限公司 一种文件签名方法、装置、电子设备及可读存储介质
US11153083B2 (en) * 2017-06-16 2021-10-19 Motorola Mobility Llc Rogue unit detection information

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111131494B (zh) * 2019-12-31 2022-06-03 上海能塔智能科技有限公司 车数据的存储、验证处理方法、装置、电子设备与介质
CN112822758B (zh) * 2020-12-31 2023-05-09 深圳市晨北科技有限公司 接入网络的方法、设备及存储介质
CN112733128B (zh) * 2021-02-06 2022-06-14 深圳市云小白科技有限公司 基于非对称加密的一种无中心物联网安全认证方法
CN115226060A (zh) * 2021-04-16 2022-10-21 华为技术有限公司 数据传输方法及数据处理装置
CN116634418A (zh) * 2022-02-14 2023-08-22 华为技术有限公司 通信方法、通信装置和系统
CN114554469A (zh) * 2022-02-24 2022-05-27 盒马(中国)有限公司 数据传输方法、蓝牙通信装置、存储介质及程序产品

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102201916A (zh) * 2010-03-24 2011-09-28 通用汽车环球科技运作有限责任公司 使用前向误差校正码的车辆网络中的适应性证书分配机制
US20140298437A1 (en) * 2011-04-14 2014-10-02 GM Global Technology Operations LLC Exploiting Application Characteristics for Multiple-Authenticator Broadcast Authentication Schemes
CN104683112A (zh) * 2015-03-20 2015-06-03 江苏大学 一种基于rsu协助认证的车-车安全通信方法
CN105323753A (zh) * 2014-05-30 2016-02-10 中国电信股份有限公司 车内安全模块、车载系统与车辆间进行信息交互的方法
US20160255502A1 (en) * 2013-10-30 2016-09-01 Samsung Electronics Co., Ltd. Method and apparatus to perform device to device communication in wireless communication network

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7581105B2 (en) * 2003-12-16 2009-08-25 Sap Aktiengesellschaft Electronic signing apparatus and methods
CN101060480B (zh) * 2007-06-04 2012-07-25 武汉理工大学 基于HORSEI2的移动自组网安全QoS多播路由的建立方法
CN101296083A (zh) * 2008-05-14 2008-10-29 华为技术有限公司 一种加密数据传输方法和系统
CN101610150B (zh) * 2009-07-22 2015-08-12 中兴通讯股份有限公司 第三方数字签名方法和数据传输系统
JP5736816B2 (ja) * 2010-05-31 2015-06-17 ソニー株式会社 認証装置、認証方法、プログラム、及び署名生成装置

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102201916A (zh) * 2010-03-24 2011-09-28 通用汽车环球科技运作有限责任公司 使用前向误差校正码的车辆网络中的适应性证书分配机制
US20140298437A1 (en) * 2011-04-14 2014-10-02 GM Global Technology Operations LLC Exploiting Application Characteristics for Multiple-Authenticator Broadcast Authentication Schemes
US20160255502A1 (en) * 2013-10-30 2016-09-01 Samsung Electronics Co., Ltd. Method and apparatus to perform device to device communication in wireless communication network
CN105323753A (zh) * 2014-05-30 2016-02-10 中国电信股份有限公司 车内安全模块、车载系统与车辆间进行信息交互的方法
CN104683112A (zh) * 2015-03-20 2015-06-03 江苏大学 一种基于rsu协助认证的车-车安全通信方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
"Technical Specification Group Services and System Aspects; Study on Security Aspect for LTE support of V2X Services (Release 14", 3RD GENERATION PARTNERSHIP PROJECT, 26 August 2016 (2016-08-26), pages 31 - 33 , 36 and 37 *

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11153083B2 (en) * 2017-06-16 2021-10-19 Motorola Mobility Llc Rogue unit detection information
CN110826091A (zh) * 2018-08-14 2020-02-21 珠海金山办公软件有限公司 一种文件签名方法、装置、电子设备及可读存储介质
CN110826091B (zh) * 2018-08-14 2022-05-06 珠海金山办公软件有限公司 一种文件签名方法、装置、电子设备及可读存储介质
CN110311783A (zh) * 2019-05-30 2019-10-08 平安科技(深圳)有限公司 基于群签名的用户归属验证方法、装置和计算机设备
CN110311783B (zh) * 2019-05-30 2022-09-23 平安科技(深圳)有限公司 基于群签名的用户归属验证方法、装置和计算机设备

Also Published As

Publication number Publication date
CN109845185B (zh) 2020-11-10
CN109845185A (zh) 2019-06-04

Similar Documents

Publication Publication Date Title
WO2018076377A1 (fr) Procédé de transmission de données, terminal, dispositif de nœud, et système
CN110798833B (zh) 一种鉴权过程中验证用户设备标识的方法及装置
KR101256887B1 (ko) 티켓-기반 구성 파라미터들 확인
US10834170B2 (en) Cloud authenticated offline file sharing
JP5461563B2 (ja) チケットベースのスペクトル認証およびアクセス制御
US8819414B2 (en) Threat mitigation in a vehicle-to-vehicle communication network
US20110320802A1 (en) Authentication method, key distribution method and authentication and key distribution method
CN110475249B (zh) 一种认证方法、相关设备及系统
KR20160078426A (ko) 무선 직접통신 네트워크에서 비대칭 키를 사용하여 아이덴티티를 검증하기 위한 방법 및 장치
JP6279821B2 (ja) ワイヤレス通信においてメッセージを認証すること
WO2019042154A1 (fr) Procédé de traitement de messages et dispositif apparenté
CN111182545B (zh) 微基站认证方法、终端
CN112640387B (zh) 用于无线连接的非si设备、si设备、方法和计算机可读介质和/或微处理器可执行介质
CN112640385B (zh) 用于在si系统中使用的非si设备和si设备以及相应的方法
KR20150051568A (ko) 이동 통신 시스템 환경에서 프락시미티 기반 서비스 단말 간 발견 및 통신을 지원하기 위한 보안 방안 및 시스템
CN110351725B (zh) 通信方法和装置
JP2011504318A (ja) 一方向アクセス認証の方法
CN110583036A (zh) 网络认证方法、网络设备及核心网设备
CN111615837B (zh) 数据传输方法、相关设备以及系统
WO2017008223A1 (fr) Procédé d'authentification de communication de service de proximité, équipement utilisateur et entité de fonction de service de proximité
EP1673917A1 (fr) Attribution d'un nom a des cles de groupe 802.11 pour permettre le support de multiples diffusions et de domaines multidesinations
CN105592433B (zh) 设备到设备限制发现业务广播、监听方法、装置及系统
CN106576245B (zh) 用户设备邻近请求认证
WO2016176902A1 (fr) Procédé d'authentification de terminal, terminal de gestion et terminal d'application
CN106060810B (zh) 移动设备间连接关系的建立方法和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16920095

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16920095

Country of ref document: EP

Kind code of ref document: A1