WO2018076564A1 - 车辆通信中的隐私保护方法及隐私保护装置 - Google Patents
车辆通信中的隐私保护方法及隐私保护装置 Download PDFInfo
- Publication number
- WO2018076564A1 WO2018076564A1 PCT/CN2017/072672 CN2017072672W WO2018076564A1 WO 2018076564 A1 WO2018076564 A1 WO 2018076564A1 CN 2017072672 W CN2017072672 W CN 2017072672W WO 2018076564 A1 WO2018076564 A1 WO 2018076564A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- vehicle terminal
- pmsi
- key
- operator
- vehicle
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1491—Countermeasures against malicious traffic using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/30—Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
Definitions
- the present invention relates to the field of vehicle communication technologies, and in particular, to a privacy protection method in vehicle communication and a privacy protection device in vehicle communication.
- LTE Long Term Evolution
- V2X Vehicle To X, the vehicle communicates with the outside world.
- Fig. 1 In order to solve the above problem, the solution proposed in the related art is as shown in Fig. 1, in which an entity called a Pseudonym Certificate Authority is employed.
- the MNO Mobile Network Operator
- K PERIOD encrypted pseudonym ID prseudonymous Mobile Subscriber ID, referred to as the PMSI
- K PMSI K PMSI
- PMSI, K PMSI K PMSI
- the MNO can obtain the identity information of the malicious vehicle by inquiring the PCA.
- a one-to-one long-term key needs to be maintained between the PCA and the V-UE to ensure the security of the communication channel, and the keystore storing the keys is maintained by the PCA,
- the keystore With the popularity of Internet of Vehicles technology, more and more vehicles are connected to the Internet of Vehicles, and the maintenance of the keystore is becoming more and more difficult.
- the keystore is easy to become the target of hacker attacks, and there are major security risks.
- the invention is based on at least one of the above technical problems, and proposes a new privacy protection scheme in vehicle communication, so that there is no need to maintain a one-to-one long-term key between the vehicle terminal and the certification management center, and the certification management center is lowered.
- the management burden on the key, and the need to maintain the keystore also effectively avoids the security risks caused by the attack of the keystore, and greatly improves the privacy security in the vehicle communication process.
- the privacy protection method is applicable to a vehicle terminal, and specifically includes the following steps:
- the received at least one pair (PMSI, KPMSI ) is decrypted based on the first key and the private key of the vehicle terminal, and vehicle communication is performed based on the decrypted (PMSI, KPMSI ).
- the request for signing the public key of the vehicle terminal is transmitted by the vehicle terminal to the operator, and after the operator passes the identity verification of the vehicle terminal, the public key of the vehicle terminal is used by the operator's private key.
- the signature is sent, and the signature result is sent by the vehicle terminal to the authentication management center, and the authentication management center verifies the signature result according to the public key of the operator device, so that the communication between the vehicle terminal and the authentication management center can be public and private.
- the key is used to ensure the security of the communication, and there is no need to maintain a one-to-one long-term key between the vehicle terminal and the authentication management center, thereby reducing the management burden of the certificate by the authentication management center, and since the keystore is not required to be maintained, It also effectively avoids the security risks caused by the attack of the keystore, and greatly improves the privacy security of the vehicle communication process.
- the identification code of the vehicle terminal may be an IMSI (International Mobile Subscriber Identification Number) or an IMEI (International Mobile Equipment Identity); the PMSI is a pseudonym ID, and the KPMSI is corresponding to the PMSI.
- the key the vehicle terminal communicates using the pseudonym ID when performing vehicle communication, and can perform identification by K PMSI .
- the operator can query the certification management center through the pseudonym ID of the vehicle terminal to obtain the real identity information of the corresponding vehicle, thereby ensuring that the operator can recognize that there is a vehicle network.
- Vehicles with malicious behavior can also avoid the problem of the operator's privacy leakage caused by the operator's willingness to obtain vehicle information in the Internet of Vehicles.
- a privacy protection method in a vehicle communication is also proposed.
- the privacy protection method is applicable to a carrier device, and specifically includes the following steps:
- the public key of the vehicle terminal is signed using the private key of the operator device, and the signature result is returned to the vehicle terminal;
- the signature result is used for the vehicle terminal to send to the authentication management center for verification, so that the authentication management center sends at least one pair (PMSI) to the vehicle terminal after verifying the signature result. , K PMSI ) for vehicle communication.
- the operator device verifies the identity of the vehicle terminal by receiving a request for signing the public key of the vehicle terminal transmitted by the vehicle terminal, and uses the private key of the operator to the public key of the vehicle terminal. After signing, returning to the vehicle terminal, the vehicle terminal can send the signature result to the certification management center, and the authentication management center performs verification, so that the communication between the vehicle terminal and the authentication management center can be performed by means of a public-private key.
- the authentication management center performs verification, so that the communication between the vehicle terminal and the authentication management center can be performed by means of a public-private key.
- a privacy protection method in a vehicle communication is also proposed.
- the privacy protection method is applicable to the authentication management device, and specifically includes the following steps:
- the vehicle terminal Receiving, by the vehicle terminal, an identification code of the vehicle terminal, a public key of the vehicle terminal, and a signature result of the operator's public key to the vehicle terminal, wherein the signature result is performed by the operation After the identity verification of the vehicle terminal is passed, the public key of the vehicle terminal is signed using the private key of the operator;
- the signature result is obtained by the authentication management device according to the public key of the operator. Perform verification to make the vehicle terminal and the authentication management device
- the communication security can be ensured by means of a public-private key, and there is no need to maintain a one-to-one long-term key between the vehicle terminal and the authentication management device, thereby reducing the management burden on the key by the authentication management device. Since the keystore is not required to be maintained, the security risks caused by the attack of the keystore are effectively avoided, and the privacy security in the vehicle communication process is greatly improved.
- the relationship between the identification code of the vehicle terminal and the assigned to the vehicle terminal (PMSI, KPMSI ) is maintained in the authentication management device, so that the carrier can pass the vehicle after the malicious behavior of the vehicle terminal in the vehicle network is discovered.
- the pseudonym ID of the terminal is used to query the authentication management device to obtain the real identity information of the corresponding vehicle.
- a privacy protection device in a vehicle communication where the privacy protection device is applicable to a vehicle terminal, and specifically includes:
- An acquiring unit configured to acquire a first key assigned by an operator, wherein the operator passes the first pair of keys (PMSI, KPMSI ) after allocating the first key to a vehicle terminal Encrypted and sent to the Certification Management Center;
- a first interaction unit configured to send, to the operator, a request for signing a public key of the vehicle terminal, and receive a signature result returned by the operator, where the operator is in the vehicle terminal After the authentication is passed, the public key of the vehicle terminal is signed using the private key of the operator;
- a second interaction unit configured to send an identifier of the vehicle terminal, a public key of the vehicle terminal, and the signature result to the authentication management center, and receive the use of the vehicle terminal by the authentication management center Public key and at least one pair (PMSI, K PMSI ) of the first key encryption, wherein the at least one pair (PMSI, K PMSI ) is based on the operator's public key by the authentication management center After the verification of the signature result is passed, the plurality of pairs (PMSI, K PMSI ) are selected;
- a processing unit configured to decrypt the at least one pair (PMSI, KPMSI ) received by the second interaction unit according to the first key and a private key of the vehicle terminal, and based on the decrypted ( PMSI, K PMSI ) performs vehicle communication.
- the operator sends a request for signing the public key of the vehicle terminal to the operator, and the operator uses the operator after the identity verification of the vehicle terminal is passed.
- the private key signs the public key of the vehicle terminal, and then the vehicle terminal sends the signature result to the certification management center, and the certification management center verifies the signature result according to the public key of the operator equipment, so that the vehicle terminal and the certification management center
- the communication security can be ensured by means of a public-private key, and there is no need to maintain a one-to-one long-term key between the vehicle terminal and the authentication management center, thereby reducing the management burden of the key by the authentication management center.
- the keystore since the keystore is not required to be maintained, the security risks caused by the attack of the keystore are effectively avoided, and the privacy security in the vehicle communication process is greatly improved.
- the identification code of the vehicle terminal may be an IMSI or an IMEI; the PMSI is a pseudonym ID, and the K PMSI is a key corresponding to the PMSI, and the vehicle terminal communicates using a pseudonym ID when performing vehicle communication, and can be performed by K PMSI Identification.
- the operator can query the certification management center through the pseudonym ID of the vehicle terminal to obtain the real identity information of the corresponding vehicle, thereby ensuring that the operator can recognize that there is a vehicle network.
- Vehicles with malicious behavior can also avoid the problem of the operator's privacy leakage caused by the operator's willingness to obtain vehicle information in the Internet of Vehicles.
- a privacy protection device in a vehicle communication where the privacy protection device is applicable to a carrier device, and specifically includes:
- An allocating unit configured to allocate a first key to the vehicle terminal
- a first sending unit configured to be encrypted by the first pair of keys (PMSI, KPMSI ) and sent to an authentication management center;
- a processing unit configured to verify an identity of the vehicle terminal when receiving a request for signing a public key of the vehicle terminal sent by the vehicle terminal, after the identity verification of the vehicle terminal passes Signing the public key of the vehicle terminal using the private key of the carrier device and returning the signature result to the vehicle terminal;
- the signature result is used for the vehicle terminal to send to the authentication management center for verification, so that the authentication management center sends at least one pair (PMSI) to the vehicle terminal after verifying the signature result. , K PMSI ) for vehicle communication.
- the operator device verifies the identity of the vehicle terminal by receiving a request for signing the public key of the vehicle terminal transmitted by the vehicle terminal, and uses the private key of the operator to the public key of the vehicle terminal. Return to the vehicle terminal after signing, so that the vehicle terminal can The signature result is sent to the certification management center, and the certification management center performs verification, so that the communication between the vehicle terminal and the certification management center can ensure the security of the communication through the public-private key, without the vehicle terminal and the authentication management.
- the one-to-one long-term key is maintained between the centers, which reduces the management burden of the certificate by the authentication management center.
- the keystore since the keystore is not maintained, the security risks caused by the attack of the keystore are effectively avoided. Greatly improve the privacy of the vehicle communication process.
- a privacy protection device in a vehicle communication where the privacy protection device is applicable to an authentication management device, and specifically includes:
- a first receiving unit configured to receive a plurality of pairs (PMSI, KPMSI ) encrypted by the operator by using the first key, where the first key is allocated by the operator to the vehicle terminal;
- a second receiving unit configured to receive an identifier of the vehicle terminal sent by the vehicle terminal, a public key of the vehicle terminal, and a signature result of the operator to a public key of the vehicle terminal, where The signature result is obtained by signing the public key of the vehicle terminal by using the private key of the operator after the operator passes the identity verification of the vehicle terminal;
- a processing unit configured to verify the signature result based on the public key of the operator, and select at least one pair (PMSI, PMSI, KPMSI ) after verifying the signature result K PMSI ), and re-encrypting the at least one pair (PMSI, K PMSI ) encrypted by the first key by a public key of the vehicle terminal;
- a sending unit configured to send the at least one pair (PMSI, KPMSI ) encrypted by the public key of the vehicle terminal and the first key to the vehicle terminal, for the vehicle terminal to decrypt The vehicle communication is then performed using the at least one pair (PMSI, K PMSI ).
- the signature result is obtained by the authentication management device according to the public key of the operator.
- the verification is performed so that the communication between the vehicle terminal and the authentication management device can ensure the security of the communication by means of a public-private key, and the long-term key corresponding to the one-to-one correspondence between the vehicle terminal and the authentication management device is not required, thereby being able to reduce
- the authentication management device has a burden on the management of the key.
- the keystore since the keystore is not required to be maintained, the security risk caused by the attack of the keystore is effectively avoided, and the privacy of the vehicle communication process is greatly improved. Sex.
- the authentication management apparatus maintains the vehicle identification code assigned to the vehicle terminal, the terminal (PMSI, K PMSI) the relationship between, so that the vehicle terminal in the vehicle is found networking malicious behavior, by the vehicle operator
- the pseudonym ID of the terminal is used to query the authentication management device to obtain the real identity information of the corresponding vehicle.
- FIG. 1 is a schematic diagram showing a privacy protection scheme in vehicle communication proposed in the related art
- FIG. 2 is a flow chart showing a privacy protection method in vehicle communication according to a first embodiment of the present invention
- Figure 3 is a schematic block diagram of a privacy protection device in vehicle communication in accordance with a first embodiment of the present invention
- FIG. 4 is a flow chart showing a privacy protection method in vehicle communication according to a second embodiment of the present invention.
- FIG. 5 is a schematic block diagram of a privacy protection device in vehicle communication according to a second embodiment of the present invention.
- FIG. 6 is a flow chart showing a privacy protection method in vehicle communication according to a third embodiment of the present invention.
- Figure 7 is a schematic block diagram of a privacy protection device in vehicle communication in accordance with a third embodiment of the present invention.
- FIG. 8 is a block diagram showing an overall flow of a privacy protection scheme in vehicle communication according to an embodiment of the present invention.
- Figure 9 shows a schematic block diagram of a vehicle terminal in accordance with an embodiment of the present invention.
- Figure 10 shows a schematic block diagram of a carrier device in accordance with an embodiment of the present invention.
- FIG. 11 shows a schematic block diagram of an authentication management device in accordance with an embodiment of the present invention.
- the technical solution of the present invention mainly adopts a public-private key technology to solve the security problem of a communication channel between a vehicle terminal and an authentication management center, and the entities involved mainly include an operator device, a vehicle terminal, and an authentication management device, and the following are respectively The angle of the three entities is explained:
- the privacy protection method in vehicle communication includes the following steps:
- Step S20 Acquire a first key assigned by the operator, where the operator encrypts the multiple pairs (PMSI, KPMSI ) by the first key after allocating the first key to the vehicle terminal. Send to the Certification Management Center.
- the first key may be a periodic key.
- Step S22 sending a request for signing the public key of the vehicle terminal to the operator, and receiving a signature result returned by the operator, wherein the operator after verifying the identity of the vehicle terminal
- the public key of the vehicle terminal is signed using the private key of the operator.
- Step S24 transmitting the identification code of the vehicle terminal, the public key of the vehicle terminal, and the signature result to the authentication management center, and receiving the public key and the public key of the vehicle terminal sent by the authentication management center.
- At least one pair (PMSI, K PMSI ) of the first key encryption wherein the at least one pair (PMSI, K PMSI ) is the signature of the authentication management center based on the operator's public key
- they are selected from the multiple pairs (PMSI, K PMSI ).
- Step S26 decrypting the received at least one pair (PMSI, KPMSI ) according to the first key and the private key of the vehicle terminal, and performing vehicle communication based on the decrypted (PMSI, KPMSI ) .
- the executive body of the technical solution shown in FIG. 2 is a vehicle terminal.
- the request for signing the public key of the vehicle terminal is transmitted to the operator by the vehicle terminal, and the operator uses the private key of the operator after the identity verification of the vehicle terminal is passed.
- the public key of the terminal is signed, and then the vehicle terminal sends the signature result to the authentication management center, and the authentication management center verifies the signature result according to the public key of the operator device, so that the communication between the vehicle terminal and the authentication management center is performed.
- the security of the communication can be ensured by means of the public-private key, and the long-term key of the one-to-one correspondence between the vehicle terminal and the authentication management center is not required, thereby reducing the management burden of the key of the authentication management center, and
- the key pool therefore, also effectively avoids the security risks caused by the attack of the keystore, and greatly improves the privacy security in the vehicle communication process.
- the identification code of the vehicle terminal may be an IMSI or an IMEI; the PMSI is a pseudonym ID, and the K PMSI is a key corresponding to the PMSI, and the vehicle terminal communicates using a pseudonym ID when performing vehicle communication, and can be performed by K PMSI Identification.
- the operator can query the certification management center through the pseudonym ID of the vehicle terminal to obtain the real identity information of the corresponding vehicle, thereby ensuring that the operator can recognize that there is a vehicle network.
- Vehicles with malicious behavior can also avoid the problem of the operator's privacy leakage caused by the operator's willingness to obtain vehicle information in the Internet of Vehicles.
- Fig. 3 shows a schematic block diagram of a privacy protection device in a vehicle communication according to a first embodiment of the present invention, which is applicable to a vehicle terminal.
- the privacy protection apparatus 300 in vehicle communication includes an acquisition unit 302, a first interaction unit 304, a second interaction unit 306, and a processing unit 308.
- the obtaining unit 302 is configured to acquire a first key allocated by the operator, where the operator passes the first key pair after the first key is allocated to the vehicle terminal (PMSI, K) PMSI ) is encrypted and sent to the Certification Management Center;
- the first interaction unit 304 is configured to send a request for signing the public key of the vehicle terminal to the operator, and receive a signature result returned by the operator, where the operator is in the vehicle terminal After the authentication is passed, the vehicle is terminated using the private key of the operator.
- the public key of the end is signed;
- the second interaction unit 306 is configured to send an identifier of the vehicle terminal, a public key of the vehicle terminal, and the signature result to the authentication management center, and receive the use of the vehicle terminal by the authentication management center.
- the plurality of pairs (PMSI, K PMSI ) are selected;
- the processing unit 308 is configured to decrypt the at least one pair (PMSI, K PMSI ) received by the second interaction unit 306 according to the first key and the private key of the vehicle terminal, and based on the decrypted (PMSI, K PMSI ) for vehicle communication.
- the request for signing the public key of the vehicle terminal is transmitted by the vehicle terminal to the operator, and after the operator passes the identity verification of the vehicle terminal, the public key of the vehicle terminal is used by the operator's private key.
- the signature is sent, and the signature result is sent by the vehicle terminal to the authentication management center, and the authentication management center verifies the signature result according to the public key of the operator device, so that the communication between the vehicle terminal and the authentication management center can be public and private.
- the key is used to ensure the security of the communication, and there is no need to maintain a one-to-one long-term key between the vehicle terminal and the authentication management center, thereby reducing the management burden of the certificate by the authentication management center, and since the keystore is not required to be maintained, It also effectively avoids the security risks caused by the attack of the keystore, and greatly improves the privacy security of the vehicle communication process.
- the identification code of the vehicle terminal may be an IMSI or an IMEI; the PMSI is a pseudonym ID, and the K PMSI is a key corresponding to the PMSI, and the vehicle terminal communicates using a pseudonym ID when performing vehicle communication, and can be performed by K PMSI Identification.
- the operator can query the certification management center through the pseudonym ID of the vehicle terminal to obtain the real identity information of the corresponding vehicle, thereby ensuring that the operator can recognize that there is a vehicle network.
- Vehicles with malicious behavior can also avoid the problem of the operator's privacy leakage caused by the operator's willingness to obtain vehicle information in the Internet of Vehicles.
- the first key may be a periodic key.
- the privacy protector in vehicle communication includes the following steps:
- Step S40 assigning a first key to the vehicle terminal, and encrypting the plurality of pairs (PMSI, KPMSI ) by the first key pair, and sending the result to the authentication management center;
- Step S42 when receiving the request for signing the public key of the vehicle terminal sent by the vehicle terminal, verifying the identity of the vehicle terminal;
- Step S44 after the identity verification of the vehicle terminal is passed, the public key of the vehicle terminal is signed using the private key of the operator device, and the signature result is returned to the vehicle terminal;
- the signature result is used for the vehicle terminal to send to the authentication management center for verification, so that the authentication management center sends at least one pair (PMSI) to the vehicle terminal after verifying the signature result. , K PMSI ) for vehicle communication.
- the privacy protection method in the vehicle communication shown in FIG. 4 further includes: transmitting a public key of the operator device to the authentication management center, where the authentication management center is based on the public key pair of the carrier device The signature result is verified.
- the public key of the vehicle terminal is signed using the private key of the operator device
- the public key of the carrier device is sent to the authentication management center, so that the authentication management center can be based on the public key of the carrier device.
- the signature result is verified to avoid the security risks and key management burdens that need to maintain a one-to-one long-term key between the vehicle terminal and the authentication management center.
- the executive body of the technical solution shown in FIG. 4 is a carrier device.
- the operator equipment verifies the identity of the vehicle terminal by receiving the request for signing the public key of the vehicle terminal transmitted by the vehicle terminal, and uses the private key of the operator to the vehicle.
- the public key of the terminal is signed and returned to the vehicle terminal, so that the vehicle terminal can send the signature result to the authentication management center, and the authentication management center performs verification, so that the communication between the vehicle terminal and the authentication management center can be public and private.
- the key method ensures the security of communication, and does not require a one-to-one long-term key between the vehicle terminal and the authentication management center, which reduces the management burden of the certificate by the authentication management center, and also requires no maintenance of the key pool. It effectively avoids the security risks caused by the attack of the keystore, and greatly improves the privacy security of the vehicle communication process.
- FIG. 5 shows a privacy protection device in vehicle communication according to a second embodiment of the present invention
- the privacy protection device 500 in vehicle communication includes an allocating unit 502, a first transmitting unit 504, and a processing unit 506.
- the allocating unit 502 is configured to allocate a first key to the vehicle terminal
- the first sending unit 504 is configured to encrypt the first pair of keys (PMSI, K PMSI ) and send it to the authentication management center;
- the processing unit 506 is configured to verify the identity of the vehicle terminal when receiving the request for signing the public key of the vehicle terminal sent by the vehicle terminal, after the identity verification of the vehicle terminal is passed, Signing the public key of the vehicle terminal using the private key of the carrier device and returning the signature result to the vehicle terminal;
- the signature result is used for the vehicle terminal to send to the authentication management center for verification, so that the authentication management center sends at least one pair (PMSI) to the vehicle terminal after verifying the signature result. , K PMSI ) for vehicle communication.
- the operator device verifies the identity of the vehicle terminal by receiving a request for signing the public key of the vehicle terminal transmitted by the vehicle terminal, and uses the private key of the operator to the public key of the vehicle terminal. After signing, returning to the vehicle terminal, the vehicle terminal can send the signature result to the certification management center, and the authentication management center performs verification, so that the communication between the vehicle terminal and the authentication management center can be performed by means of a public-private key.
- the authentication management center performs verification, so that the communication between the vehicle terminal and the authentication management center can be performed by means of a public-private key.
- the first sending unit 504 is further configured to: send the public key of the operator device to the authentication management center, where the authentication management center performs verification on the signature result according to the public key of the carrier device. .
- the public key of the vehicle terminal is signed using the private key of the operator device
- the public key of the carrier device is sent to the authentication management center, so that the authentication management center can be based on the public key of the carrier device.
- the signature result is verified to avoid the security risks and key management that need to maintain a one-to-one long-term key between the vehicle terminal and the authentication management center. burden.
- a privacy protection method in vehicle communication includes the following steps:
- Step S60 receiving a plurality of pairs (PMSI, KPMSI ) encrypted by the first key by the operator, where the first key is allocated by the operator to the vehicle terminal;
- Step S62 receiving an identification code of the vehicle terminal sent by the vehicle terminal, a public key of the vehicle terminal, and a signature result of the operator's public key of the vehicle terminal, where the signature result is After the operator passes the identity verification of the vehicle terminal, the public key of the vehicle terminal is signed by using the private key of the operator;
- Step S64 the operator based on the public key of the signature verification result, after the signature verification results by selecting at least one pair (from the plurality of the PMSI (PMSI, K PMSI) in, K PMSI And re-encrypting the at least one pair (PMSI, KPMSI ) encrypted by the first key by a public key of the vehicle terminal;
- Step S66 transmitting the at least one pair (PMSI, KPMSI ) encrypted by the public key of the vehicle terminal and the first key to the vehicle terminal, so that the vehicle terminal is used after decryption.
- the at least one pair (PMSI, K PMSI ) performs vehicle communication.
- the execution subject of the technical solution shown in FIG. 6 is an authentication management device.
- the public key of the operator is determined by the authentication management device.
- the communication between the vehicle terminal and the authentication management device can ensure the security of the communication by means of the public-private key, and the long-term key of the one-to-one correspondence between the vehicle terminal and the authentication management device is not required.
- the management burden of the authentication management device on the key can be reduced, and since the keystore is not maintained, the security risk caused by the attack of the keystore is effectively avoided, and the privacy of the vehicle communication process is greatly improved. Sex.
- the relationship between the identification code of the vehicle terminal and the assigned to the vehicle terminal (PMSI, KPMSI ) is maintained in the authentication management device, so that the carrier can pass the vehicle after the malicious behavior of the vehicle terminal in the vehicle network is discovered.
- the pseudonym ID of the terminal is used to query the authentication management device to obtain the real identity information of the corresponding vehicle.
- Fig. 7 is a schematic block diagram showing a privacy protection device in vehicle communication according to a third embodiment of the present invention, which is applicable to an authentication management device.
- the privacy protection apparatus 700 in vehicle communication includes a first receiving unit 702, a second receiving unit 704, a processing unit 706, and a transmitting unit 708.
- the first receiving unit 702 is configured to receive a plurality of pairs (PMSI, K PMSI ) encrypted by the operator by using the first key, where the first key is allocated by the operator to the vehicle terminal. ;
- the second receiving unit 704 is configured to receive an identifier of the vehicle terminal sent by the vehicle terminal, a public key of the vehicle terminal, and a signature result of the operator to a public key of the vehicle terminal, where The signature result is obtained by signing the public key of the vehicle terminal by using the private key of the operator after the operator passes the identity verification of the vehicle terminal;
- the processing unit 706 is configured to verify the signature result based on the public key of the operator, and select at least one pair (PMSI, PMSI, KPMSI ) after verifying the signature result. K PMSI ), and re-encrypting the at least one pair (PMSI, K PMSI ) encrypted by the first key by a public key of the vehicle terminal;
- the transmitting unit 708 is configured to send the at least one pair (PMSI, KPMSI ) encrypted by the public key of the vehicle terminal and the first key to the vehicle terminal, for the vehicle terminal to decrypt The vehicle communication is then performed using the at least one pair (PMSI, K PMSI ).
- the signature result is obtained by the authentication management device according to the public key of the operator.
- the verification is performed so that the communication between the vehicle terminal and the authentication management device can ensure the security of the communication by means of a public-private key, and the long-term key corresponding to the one-to-one correspondence between the vehicle terminal and the authentication management device is not required, thereby being able to reduce
- the authentication management device imposes a burden on the key, and at the same time, since the keystore is not required to be maintained, the security risk caused by the attack of the keystore is effectively avoided, and the privacy security in the vehicle communication process is greatly improved.
- the relationship between the identification code of the vehicle terminal and the assigned to the vehicle terminal (PMSI, KPMSI ) is maintained in the authentication management device, so that the carrier can pass the vehicle after the malicious behavior of the vehicle terminal in the vehicle network is discovered.
- the pseudonym ID of the terminal is used to query the authentication management device to obtain the real identity information of the corresponding vehicle.
- the carrier device is an MNO.
- the vehicle terminal is the V-UE, and the authentication management device can be the PCA:
- the MNO holds a public-private key pair (PK MNO , SK MNO ) for digital signature, wherein PK MNO is a public key and SK MNO is a private key;
- the V-UE holds a public-private key pair (PK v , SK v ) for encryption and decryption, wherein PK v is a public key and an SK v private key;
- the PCA verifies the identity of the V-UE by verifying the digital signature from the MNO, while the PCA selects several (PMSI, K PMSI ) and encrypts it by PK v and then sends it to the V-UE.
- the V-UE obtains the key K PERIOD from the MNO. Specifically, V-UE acquires K PERIOD MNO sends a request, then K PERIOD MNO assigned to the V-UE. Among them, K PERIOD is a periodic key generated by the MNO (for example, one per week), and K PERIOD is used to encrypt (PMSI, K PMSI ).
- Step 804 the MNO sends a plurality of pairs (PMSI, K PMSI ) encrypted by K PERIOD to the PCA, wherein the number of (PMSI, K PMSI ) depends on the size of the system, for example, may be 1000000 pairs.
- step 806 the V-UE requests the MNO to sign the PK v .
- Step 808 the MNO signs the PK v using the private key SK MNO after verifying the identity of the V-UE, and returns the signature result to the V-UE.
- the MNO verifies that the identity of the V-UE is similar to the registration process of the UE.
- the V-UE sends the signature result of its own IMSI (or IMEI), PK v , MNO to PK v to the PCA.
- IMSI or IMEI
- step 812 the PCA verifies the signature of the PK v based on the public key PK MNO of the MNO .
- the MNO needs to notify the PCA of the public key PK MNO , so that the PCA verifies the signature of the PK v in this step.
- Step 814 After the PCA passes the verification of the signature of the PK v , the PCA selects at least one pair (PMSI, K PMSI ) encrypted by K PERIOD , and encrypts it with PK v and sends it to the V-UE.
- Step 816 the V-UE received (PMSI, K PMSI) for double decrypted (PMSI, K PMSI) value. Specifically, the V-UE is first decrypted with its own private key SK v and then decrypted with K PERIOD .
- the vehicle communication can be performed based on the PMSI, and the K PMSI is used for identification.
- the V-UE communication process after decryption may each be a period of time used to replace PMSI.
- the MNO can query the PCA through the PMSI of the V-UE, since the PCA maintains the true identity of the V-UE (IMSI/IMEI) and (PMSI, K PMSI )
- the relationship between the PCA can obtain the real identity information of the V-UE, and the real identity obtained can be returned to the MNO. It can be seen that the technical solution of the present invention ensures that the operator can identify the vehicle with malicious behavior in the Internet of Vehicles. It can also avoid the problem that operators are willing to obtain vehicle information in the Internet of Vehicles and cause leakage of vehicle privacy.
- Figure 9 shows a schematic block diagram of a vehicle terminal in accordance with an embodiment of the present invention.
- a vehicle terminal includes a processor 1, an input device 2, an output device 3, and a memory 5.
- the processor 1, the input device 2, the output device 3, and the memory 5 may be connected by a bus 4 or the like, as exemplified by the connection through the bus 4 in FIG.
- the memory 5 is used to store a set of program codes, and the processor 1 calls the program code stored in the memory 5 for performing the following operations:
- the received at least one pair (PMSI, KPMSI ) is decrypted according to the first key and the private key of the vehicle terminal, and the vehicle communication is performed based on the decrypted (PMSI, KPMSI ).
- Figure 10 shows a schematic block diagram of a carrier device in accordance with an embodiment of the present invention.
- a carrier device includes a processor 1', an input device 2', an output device 3', and a memory 5'.
- the processor 1', the input device 2', the output device 3', and the memory 5' may be connected by a bus 4' or other means, as exemplified by the connection through the bus 4' in FIG.
- the memory 5' is used to store a set of program codes, and the processor 1' calls the program code stored in the memory 5' for performing the following operations:
- the input device 2' receives the request for signing the public key of the vehicle terminal sent by the vehicle terminal, verifying the identity of the vehicle terminal;
- the public key of the vehicle terminal is signed using the private key of the operator device, and the signature result is returned to the vehicle terminal through the output device 3';
- the signature result is used for the vehicle terminal to send to the authentication management center for verification, so that the authentication management center sends at least one pair (PMSI) to the vehicle terminal after verifying the signature result. , K PMSI ) for vehicle communication.
- the processor 1' calls the program code stored in the memory 5', and is also used to perform the following operations:
- the public key of the operator device is sent to the authentication management center through the output device 3', so that the authentication management center verifies the signature result according to the public key of the carrier device.
- FIG. 11 shows a schematic block diagram of an authentication management device in accordance with an embodiment of the present invention.
- an authentication management apparatus includes a processor 1", an input device 2", an output device 3", and a memory 5".
- the processor 1", the input device 2", the output device 3", and the memory 5" may be connected by a bus 4" or the like, as exemplified by the connection through the bus 4" in FIG.
- the memory 5" is used to store a set of program codes, and the processor 1" calls the program code stored in the memory 5" for performing the following operations:
- the units in the privacy protection device, the vehicle terminal, the operator device, and the authentication management device in the vehicle communication according to the embodiment of the present invention may be combined, divided, and deleted according to actual needs.
- the program can be stored in a computer readable storage medium, and the storage medium includes read only Memory (Read-Only Memory, ROM), Random Access Memory (RAM), Programmable Read-Only Memory (PROM), Erasable Programmable Read Only Memory (EPROM), one-time programmable only One-time Programmable Read-Only Memory (OTPROM), Electronically-Erasable Programmable Read-Only Memory (EEPROM), CD-ROM (Compact Disc Read-Only Memory, CD- ROM) or other optical disk storage, disk storage, magnetic tape storage, or any other medium readable by a computer that can be used to carry or store data.
- Read-Only Memory ROM
- RAM Random Access Memory
- PROM Programmable Read-Only Memory
- EPROM Erasable Programmable Read Only Memory
- OTPROM One-time Programmable Read-Only Memory
- OTPROM One-time Programmable Read-Only Memory
- EEPROM Electronically-Erasable Programmable Read-Only Memory
- CD-ROM Compact Disc Read-On
- the present invention proposes a new privacy protection scheme in vehicle communication, so that there is no need to maintain a one-to-one correspondence long-term key between the vehicle terminal and the authentication management center, which is reduced.
- the authentication management center has a burden on the management of the key, and because it does not need to maintain the keystore, it also effectively avoids the security risks caused by the attack of the keystore, and greatly improves the privacy security in the vehicle communication process.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本发明提供了一种车辆通信中的隐私保护方法及隐私保护装置,隐私保护方法包括:获取运营商分配的第一密钥,其中,运营商在分配第一密钥后,通过第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;向运营商发送对车辆终端的公钥进行签名的请求,并接收运营商返回的签名结果,其中,运营商使用运营商的私钥对车辆终端的公钥进行签名;将车辆终端的识别码、车辆终端的公钥和所述签名结果发送至认证管理中心,并接收认证管理中心发送的使用车辆终端的公钥和第一密钥加密的至少一对(PMSI,KPMSI);根据第一密钥和车辆终端的私钥对接收到的(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进行车辆通信。本发明极大地提升了车辆通信过程中的隐私安全性。
Description
本申请要求于2016年10月31日提交中国专利局、申请号为201610933025.6、发明名称为“车辆通信中的隐私保护方法及隐私保护装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本发明涉及车辆通信技术领域,具体而言,涉及一种车辆通信中的隐私保护方法和一种车辆通信中的隐私保护装置。
目前,LTE(Long Term Evolution,长期演进)已经将车联网通信纳入到了标准化范围,在相关规范中将车辆对外界(对其他车辆、对行人、对路边设施等)的通信简称为V2X(Vehicle to X,车辆对外界)通信。
在3GPP的相关讨论稿中,V2X规范中制定了以下两个互相矛盾的安全性和隐私性条款:
(1)为保护车辆的隐私,运营商应该不能分辨参与通信的车辆;
(2)为保护网络安全,运营商应该能够识别在车联网中发送恶意消息,或者有其他恶意行为的车辆。
由于运营商的行为不受其他实体控制,因此它完全可以使用条款(2)所赋予的车辆识别能力对条款(1)中的车辆隐私性进行侵犯。
为了解决上述问题,相关技术中提出的解决方案如图1所示,其中采用了一个称为假名中心(Pseudonym Certificate Authority)的实体。当V-UE(vehicle User Equipment,车辆终端,即接入车联网的车辆)与MNO(Mobile Network Operator,移动网络运营商)之间通信获取到密钥KPERIOD之后,MNO向PCA发送多对采用KPERIOD加密的假名ID(Pseudonymous Mobile Subscriber ID,简称PMSI)和对应的密钥KPMSI,
即(PMSI,KPMSI),进而由PCA来向V-UE分配(PMSI,KPMSI),避免MNO分辨参与通信的车辆。同时,若V-UE在车联网中执行恶意行为被发现后,MNO通过询问PCA可以获得该恶意车辆的身份信息。
此外,在图1所示的技术方案中,PCA与V-UE之间需要保持一一对应的长期密钥来保证通信信道的安全,而存储这些密钥的密钥库是由PCA维护,随着车联网技术的普及,接入车联网的车辆越来越多,密钥库的维护难度也越来越大,并且密钥库很容易成为黑客攻击的目标,存在较大的安全隐患。
发明内容
本发明正是基于上述技术问题至少之一,提出了一种新的车辆通信中的隐私保护方案,使得车辆终端与认证管理中心之间无需保持一一对应的长期密钥,降低了认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
有鉴于此,根据本发明的第一方面,提出了一种车辆通信中的隐私保护方法,该隐私保护方法适用于车辆终端,具体包括以下步骤:
获取运营商分配的第一密钥,其中,所述运营商在向车辆终端分配所述第一密钥之后,通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
向所述运营商发送对所述车辆终端的公钥进行签名的请求,并接收所述运营商返回的签名结果,其中,所述运营商在对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名;
将所述车辆终端的识别码、所述车辆终端的公钥和所述签名结果发送至所述认证管理中心,并接收所述认证管理中心发送的使用所述车辆终端的公钥和所述第一密钥加密的至少一对(PMSI,KPMSI),其中,所述至少一对(PMSI,KPMSI)是由所述认证管理中心基于所述运营商的公钥对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)选择出的;
根据所述第一密钥和所述车辆终端的私钥对接收到的所述至少一对
(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进行车辆通信。
在该技术方案中,通过由车辆终端向运营商发送对车辆终端的公钥进行签名的请求,而运营商在对车辆终端的身份验证通过之后,使用运营商的私钥对车辆终端的公钥进行签名,进而由车辆终端将签名结果发送至认证管理中心,由认证管理中心根据运营商设备的公钥来对签名结果进行验证,使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,进而能够降低认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
其中,车辆终端的识别码可以是IMSI(International Mobile Subscriber Identification Number,国际移动用户识别码)或IMEI(International Mobile Equipment Identity,国际移动设备标识);PMSI即为假名ID,KPMSI是与PMSI相对应的密钥,车辆终端在进行车辆通信时使用假名ID进行通信,并能够通过KPMSI来进行身份识别。当车辆终端在车联网中的恶意行为被发现后,运营商可以通过车辆终端的假名ID来询问认证管理中心,以获得相应车辆的真实身份信息,既保证运营商能够识别到在车联网中有恶意行为的车辆,也能够避免运营商肆意获取车联网中的车辆信息而导致车辆隐私泄露的问题。
根据本发明的第二方面,还提出了一种车辆通信中的隐私保护方法,该隐私保护方法适用于运营商设备,具体包括以下步骤:
向车辆终端分配第一密钥,并通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
在接收到所述车辆终端发送的对所述车辆终端的公钥进行签名的请求时,对所述车辆终端的身份进行验证;
在对所述车辆终端的身份验证通过之后,使用运营商设备的私钥对所述车辆终端的公钥进行签名,并将签名结果返回至所述车辆终端;
其中,所述签名结果用于供所述车辆终端发送至所述认证管理中心进
行验证,以使所述认证管理中心在对所述签名结果验证通过后向所述车辆终端发送至少一对(PMSI,KPMSI)进行车辆通信。
在该技术方案中,运营商设备通过在接收到车辆终端发送的对车辆终端的公钥进行签名的请求时,对车辆终端的身份进行验证,并使用运营商的私钥对车辆终端的公钥进行签名后返回至车辆终端,使得车辆终端能够将签名结果发送至认证管理中心,由认证管理中心来进行验证,进而使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,降低了认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
根据本发明的第三方面,还提出了一种车辆通信中的隐私保护方法,该隐私保护方法适用于认证管理设备,具体包括以下步骤:
接收运营商发送的通过第一密钥加密后的多对(PMSI,KPMSI),其中,所述第一密钥是由所述运营商分配给车辆终端的;
接收所述车辆终端发送的所述车辆终端的识别码、所述车辆终端的公钥和所述运营商对所述车辆终端的公钥的签名结果,其中,所述签名结果是由所述运营商对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名得到的;
基于所述运营商的公钥对所述签名结果进行验证,在对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)中选择至少一对(PMSI,KPMSI),并通过所述车辆终端的公钥对经过所述第一密钥加密后的所述至少一对(PMSI,KPMSI)进行再次加密;
将通过所述车辆终端的公钥和所述第一密钥加密后的所述至少一对(PMSI,KPMSI)发送至所述车辆终端,以供所述车辆终端在解密后使用所述至少一对(PMSI,KPMSI)进行车辆通信。
在该技术方案中,由于运营商在对车辆终端的身份验证通过之后,使用运营商的私钥对车辆终端的公钥进行签名,因此通过由认证管理设备根据运营商的公钥来对签名结果进行验证,使得车辆终端与认证管理设备之
间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理设备之间保持一一对应的长期密钥,进而能够降低认证管理设备对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
其中,认证管理设备中维护有车辆终端的识别码和分配给车辆终端的(PMSI,KPMSI)之间的关系,这样使得车辆终端在车联网中的恶意行为被发现后,运营商可以通过车辆终端的假名ID来询问认证管理设备,以获得相应车辆的真实身份信息。
根据本发明的第四方面,还提出了一种车辆通信中的隐私保护装置,该隐私保护装置适用于车辆终端,具体包括:
获取单元,用于获取运营商分配的第一密钥,其中,所述运营商在向车辆终端分配所述第一密钥之后,通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
第一交互单元,用于向所述运营商发送对所述车辆终端的公钥进行签名的请求,并接收所述运营商返回的签名结果,其中,所述运营商在对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名;
第二交互单元,用于将所述车辆终端的识别码、所述车辆终端的公钥和所述签名结果发送至所述认证管理中心,并接收所述认证管理中心发送的使用所述车辆终端的公钥和所述第一密钥加密的至少一对(PMSI,KPMSI),其中,所述至少一对(PMSI,KPMSI)是由所述认证管理中心基于所述运营商的公钥对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)选择出的;
处理单元,用于根据所述第一密钥和所述车辆终端的私钥对所述第二交互单元接收到的所述至少一对(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进行车辆通信。
在该技术方案中,通过由车辆终端向运营商发送对车辆终端的公钥进行签名的请求,而运营商在对车辆终端的身份验证通过之后,使用运营商
的私钥对车辆终端的公钥进行签名,进而由车辆终端将签名结果发送至认证管理中心,由认证管理中心根据运营商设备的公钥来对签名结果进行验证,使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,进而能够降低认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
其中,车辆终端的识别码可以是IMSI或IMEI;PMSI即为假名ID,KPMSI是与PMSI相对应的密钥,车辆终端在进行车辆通信时使用假名ID进行通信,并能够通过KPMSI来进行身份识别。当车辆终端在车联网中的恶意行为被发现后,运营商可以通过车辆终端的假名ID来询问认证管理中心,以获得相应车辆的真实身份信息,既保证运营商能够识别到在车联网中有恶意行为的车辆,也能够避免运营商肆意获取车联网中的车辆信息而导致车辆隐私泄露的问题。
根据本发明的第五方面,还提出了一种车辆通信中的隐私保护装置,该隐私保护装置适用于运营商设备,具体包括:
分配单元,用于向车辆终端分配第一密钥;
第一发送单元,用于通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
处理单元,用于在接收到所述车辆终端发送的对所述车辆终端的公钥进行签名的请求时,对所述车辆终端的身份进行验证,当对所述车辆终端的身份验证通过之后,使用运营商设备的私钥对所述车辆终端的公钥进行签名,并将签名结果返回至所述车辆终端;
其中,所述签名结果用于供所述车辆终端发送至所述认证管理中心进行验证,以使所述认证管理中心在对所述签名结果验证通过后向所述车辆终端发送至少一对(PMSI,KPMSI)进行车辆通信。
在该技术方案中,运营商设备通过在接收到车辆终端发送的对车辆终端的公钥进行签名的请求时,对车辆终端的身份进行验证,并使用运营商的私钥对车辆终端的公钥进行签名后返回至车辆终端,使得车辆终端能够
将签名结果发送至认证管理中心,由认证管理中心来进行验证,进而使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,降低了认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
根据本发明的第六方面,还提出了一种车辆通信中的隐私保护装置,该隐私保护装置适用于认证管理设备,具体包括:
第一接收单元,用于接收运营商发送的通过第一密钥加密后的多对(PMSI,KPMSI),其中,所述第一密钥是由所述运营商分配给车辆终端的;
第二接收单元,用于接收所述车辆终端发送的所述车辆终端的识别码、所述车辆终端的公钥和所述运营商对所述车辆终端的公钥的签名结果,其中,所述签名结果是由所述运营商对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名得到的;
处理单元,用于基于所述运营商的公钥对所述签名结果进行验证,在对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)中选择至少一对(PMSI,KPMSI),并通过所述车辆终端的公钥对经过所述第一密钥加密后的所述至少一对(PMSI,KPMSI)进行再次加密;
发送单元,用于将通过所述车辆终端的公钥和所述第一密钥加密后的所述至少一对(PMSI,KPMSI)发送至所述车辆终端,以供所述车辆终端在解密后使用所述至少一对(PMSI,KPMSI)进行车辆通信。
在该技术方案中,由于运营商在对车辆终端的身份验证通过之后,使用运营商的私钥对车辆终端的公钥进行签名,因此通过由认证管理设备根据运营商的公钥来对签名结果进行验证,使得车辆终端与认证管理设备之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理设备之间保持一一对应的长期密钥,进而能够降低认证管理设备对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全
性。
其中,认证管理设备中维护有车辆终端的识别码和分配给车辆终端的(PMSI,KPMSI)之间的关系,这样使得车辆终端在车联网中的恶意行为被发现后,运营商可以通过车辆终端的假名ID来询问认证管理设备,以获得相应车辆的真实身份信息。
通过以上技术方案,使得车辆终端与认证管理中心之间无需保持一一对应的长期密钥,降低了认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
图1示出了相关技术中提出的车辆通信中的隐私保护方案的示意图;
图2示出了根据本发明的第一个实施例的车辆通信中的隐私保护方法的流程示意图;
图3示出了根据本发明的第一个实施例的车辆通信中的隐私保护装置的示意框图;
图4示出了根据本发明的第二个实施例的车辆通信中的隐私保护方法的流程示意图;
图5示出了根据本发明的第二个实施例的车辆通信中的隐私保护装置的示意框图;
图6示出了根据本发明的第三个实施例的车辆通信中的隐私保护方法的流程示意图;
图7示出了根据本发明的第三个实施例的车辆通信中的隐私保护装置的示意框图;
图8示出了根据本发明的实施例的车辆通信中的隐私保护方案的整体流程示意图;
图9示出了根据本发明的实施例的车辆终端的示意框图;
图10示出了根据本发明的实施例的运营商设备的示意框图;
图11示出了根据本发明的实施例的认证管理设备的示意框图。
为了能够更清楚地理解本发明的上述目的、特征和优点,下面结合附图和具体实施方式对本发明进行进一步的详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明,但是,本发明还可以采用其他不同于在此描述的其他方式来实施,因此,本发明的保护范围并不受下面公开的具体实施例的限制。
本发明的技术方案主要是采用公私密钥技术来解决车辆终端与认证管理中心之间通信信道的安全性问题,主要涉及到的实体有运营商设备、车辆终端和认证管理设备,以下分别从这三个实体的角度进行说明:
1、车辆终端:
如图2所示,根据本发明的第一个实施例的车辆通信中的隐私保护方法,包括以下步骤:
步骤S20,获取运营商分配的第一密钥,其中,所述运营商在向车辆终端分配所述第一密钥之后,通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心。
进一步地,为了提高密钥的安全性,第一密钥可以为周期性密钥。
步骤S22,向所述运营商发送对所述车辆终端的公钥进行签名的请求,并接收所述运营商返回的签名结果,其中,所述运营商在对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名。
步骤S24,将所述车辆终端的识别码、所述车辆终端的公钥和所述签名结果发送至所述认证管理中心,并接收所述认证管理中心发送的使用所述车辆终端的公钥和所述第一密钥加密的至少一对(PMSI,KPMSI),其中,所述至少一对(PMSI,KPMSI)是由所述认证管理中心基于所述运营商的公钥对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)选择出的。
步骤S26,根据所述第一密钥和所述车辆终端的私钥对接收到的所述至少一对(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进
行车辆通信。
图2所示的技术方案的执行主体是车辆终端。在图2所示的技术方案中,通过由车辆终端向运营商发送对车辆终端的公钥进行签名的请求,而运营商在对车辆终端的身份验证通过之后,使用运营商的私钥对车辆终端的公钥进行签名,进而由车辆终端将签名结果发送至认证管理中心,由认证管理中心根据运营商设备的公钥来对签名结果进行验证,使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,进而能够降低认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
其中,车辆终端的识别码可以是IMSI或IMEI;PMSI即为假名ID,KPMSI是与PMSI相对应的密钥,车辆终端在进行车辆通信时使用假名ID进行通信,并能够通过KPMSI来进行身份识别。当车辆终端在车联网中的恶意行为被发现后,运营商可以通过车辆终端的假名ID来询问认证管理中心,以获得相应车辆的真实身份信息,既保证运营商能够识别到在车联网中有恶意行为的车辆,也能够避免运营商肆意获取车联网中的车辆信息而导致车辆隐私泄露的问题。
图3示出了根据本发明的第一个实施例的车辆通信中的隐私保护装置的示意框图,该隐私保护装置适用于车辆终端。
如图3所示,根据本发明的第一个实施例的车辆通信中的隐私保护装置300,包括:获取单元302、第一交互单元304、第二交互单元306和处理单元308。
其中,获取单元302用于获取运营商分配的第一密钥,其中,所述运营商在向车辆终端分配所述第一密钥之后,通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
第一交互单元304用于向所述运营商发送对所述车辆终端的公钥进行签名的请求,并接收所述运营商返回的签名结果,其中,所述运营商在对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终
端的公钥进行签名;
第二交互单元306用于将所述车辆终端的识别码、所述车辆终端的公钥和所述签名结果发送至所述认证管理中心,并接收所述认证管理中心发送的使用所述车辆终端的公钥和所述第一密钥加密的至少一对(PMSI,KPMSI),其中,所述至少一对(PMSI,KPMSI)是由所述认证管理中心基于所述运营商的公钥对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)选择出的;
处理单元308用于根据所述第一密钥和所述车辆终端的私钥对所述第二交互单元306接收到的所述至少一对(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进行车辆通信。
在该技术方案中,通过由车辆终端向运营商发送对车辆终端的公钥进行签名的请求,而运营商在对车辆终端的身份验证通过之后,使用运营商的私钥对车辆终端的公钥进行签名,进而由车辆终端将签名结果发送至认证管理中心,由认证管理中心根据运营商设备的公钥来对签名结果进行验证,使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,进而能够降低认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
其中,车辆终端的识别码可以是IMSI或IMEI;PMSI即为假名ID,KPMSI是与PMSI相对应的密钥,车辆终端在进行车辆通信时使用假名ID进行通信,并能够通过KPMSI来进行身份识别。当车辆终端在车联网中的恶意行为被发现后,运营商可以通过车辆终端的假名ID来询问认证管理中心,以获得相应车辆的真实身份信息,既保证运营商能够识别到在车联网中有恶意行为的车辆,也能够避免运营商肆意获取车联网中的车辆信息而导致车辆隐私泄露的问题。
进一步地,为了提高密钥的安全性,第一密钥可以为周期性密钥。
2、运营商设备:
如图4所示,根据本发明的第二个实施例的车辆通信中的隐私保护方
法,包括以下步骤:
步骤S40,向车辆终端分配第一密钥,并通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
步骤S42,在接收到所述车辆终端发送的对所述车辆终端的公钥进行签名的请求时,对所述车辆终端的身份进行验证;
步骤S44,在对车辆终端的身份验证通过之后,使用运营商设备的私钥对所述车辆终端的公钥进行签名,并将签名结果返回至所述车辆终端;
其中,所述签名结果用于供所述车辆终端发送至所述认证管理中心进行验证,以使所述认证管理中心在对所述签名结果验证通过后向所述车辆终端发送至少一对(PMSI,KPMSI)进行车辆通信。
进一步地,图4所示的车辆通信中的隐私保护方法还包括:将运营商设备的公钥发送至所述认证管理中心,以供所述认证管理中心根据所述运营商设备的公钥对所述签名结果进行验证。
具体地,由于是使用运营商设备的私钥对车辆终端的公钥进行签名,因此通过将运营商设备的公钥发送至认证管理中心,使得认证管理中心能够根据运营商设备的公钥来对签名结果进行验证,避免了车辆终端与认证管理中心之间需要维持一一对应的长期密钥而存在的安全隐患和密钥管理负担。
图4所示的技术方案的执行主体是运营商设备。在图4所示的技术方案中,运营商设备通过在接收到车辆终端发送的对车辆终端的公钥进行签名的请求时,对车辆终端的身份进行验证,并使用运营商的私钥对车辆终端的公钥进行签名后返回至车辆终端,使得车辆终端能够将签名结果发送至认证管理中心,由认证管理中心来进行验证,进而使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,降低了认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
图5示出了根据本发明的第二个实施例的车辆通信中的隐私保护装置
的示意框图,该隐私保护装置适用于运营商设备。
如图5所示,根据本发明的第二个实施例的车辆通信中的隐私保护装置500,包括:分配单元502、第一发送单元504和处理单元506。
其中,分配单元502用于向车辆终端分配第一密钥;
第一发送单元504用于通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
处理单元506用于在接收到所述车辆终端发送的对所述车辆终端的公钥进行签名的请求时,对所述车辆终端的身份进行验证,当对所述车辆终端的身份验证通过之后,使用运营商设备的私钥对所述车辆终端的公钥进行签名,并将签名结果返回至所述车辆终端;
其中,所述签名结果用于供所述车辆终端发送至所述认证管理中心进行验证,以使所述认证管理中心在对所述签名结果验证通过后向所述车辆终端发送至少一对(PMSI,KPMSI)进行车辆通信。
在该技术方案中,运营商设备通过在接收到车辆终端发送的对车辆终端的公钥进行签名的请求时,对车辆终端的身份进行验证,并使用运营商的私钥对车辆终端的公钥进行签名后返回至车辆终端,使得车辆终端能够将签名结果发送至认证管理中心,由认证管理中心来进行验证,进而使得车辆终端与认证管理中心之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理中心之间保持一一对应的长期密钥,降低了认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
进一步地,第一发送单元504还用于:将运营商设备的公钥发送至所述认证管理中心,以供所述认证管理中心根据所述运营商设备的公钥对所述签名结果进行验证。
具体地,由于是使用运营商设备的私钥对车辆终端的公钥进行签名,因此通过将运营商设备的公钥发送至认证管理中心,使得认证管理中心能够根据运营商设备的公钥来对签名结果进行验证,避免了车辆终端与认证管理中心之间需要维持一一对应的长期密钥而存在的安全隐患和密钥管理
负担。
3、认证管理设备:
如图6所示,根据本发明的第三个实施例的车辆通信中的隐私保护方法,包括以下步骤:
步骤S60,接收运营商发送的通过第一密钥加密后的多对(PMSI,KPMSI),其中,所述第一密钥是由所述运营商分配给车辆终端的;
步骤S62,接收所述车辆终端发送的所述车辆终端的识别码、所述车辆终端的公钥和所述运营商对所述车辆终端的公钥的签名结果,其中,所述签名结果是由所述运营商对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名得到的;
步骤S64,基于所述运营商的公钥对所述签名结果进行验证,在对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)中选择至少一对(PMSI,KPMSI),并通过所述车辆终端的公钥对经过所述第一密钥加密后的所述至少一对(PMSI,KPMSI)进行再次加密;
步骤S66,将通过所述车辆终端的公钥和所述第一密钥加密后的所述至少一对(PMSI,KPMSI)发送至所述车辆终端,以供所述车辆终端在解密后使用所述至少一对(PMSI,KPMSI)进行车辆通信。
图6所示的技术方案的执行主体是认证管理设备。在图6所示的技术方案中,由于运营商在对车辆终端的身份验证通过之后,使用运营商的私钥对车辆终端的公钥进行签名,因此通过由认证管理设备根据运营商的公钥来对签名结果进行验证,使得车辆终端与认证管理设备之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理设备之间保持一一对应的长期密钥,进而能够降低认证管理设备对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
其中,认证管理设备中维护有车辆终端的识别码和分配给车辆终端的(PMSI,KPMSI)之间的关系,这样使得车辆终端在车联网中的恶意行为被发现后,运营商可以通过车辆终端的假名ID来询问认证管理设备,以获得相应车辆的真实身份信息。
图7示出了根据本发明的第三个实施例的车辆通信中的隐私保护装置的示意框图,该隐私保护装置适用于认证管理设备。
如图7所示,根据本发明的第三个实施例的车辆通信中的隐私保护装置700,包括:第一接收单元702、第二接收单元704、处理单元706和发送单元708。
其中,第一接收单元702用于接收运营商发送的通过第一密钥加密后的多对(PMSI,KPMSI),其中,所述第一密钥是由所述运营商分配给车辆终端的;
第二接收单元704用于接收所述车辆终端发送的所述车辆终端的识别码、所述车辆终端的公钥和所述运营商对所述车辆终端的公钥的签名结果,其中,所述签名结果是由所述运营商对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名得到的;
处理单元706用于基于所述运营商的公钥对所述签名结果进行验证,在对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)中选择至少一对(PMSI,KPMSI),并通过所述车辆终端的公钥对经过所述第一密钥加密后的所述至少一对(PMSI,KPMSI)进行再次加密;
发送单元708用于将通过所述车辆终端的公钥和所述第一密钥加密后的所述至少一对(PMSI,KPMSI)发送至所述车辆终端,以供所述车辆终端在解密后使用所述至少一对(PMSI,KPMSI)进行车辆通信。
在该技术方案中,由于运营商在对车辆终端的身份验证通过之后,使用运营商的私钥对车辆终端的公钥进行签名,因此通过由认证管理设备根据运营商的公钥来对签名结果进行验证,使得车辆终端与认证管理设备之间进行通信时能够通过公私密钥的方式来保证通信的安全性,无需车辆终端与认证管理设备之间保持一一对应的长期密钥,进而能够降低认证管理设备对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
其中,认证管理设备中维护有车辆终端的识别码和分配给车辆终端的(PMSI,KPMSI)之间的关系,这样使得车辆终端在车联网中的恶意行为
被发现后,运营商可以通过车辆终端的假名ID来询问认证管理设备,以获得相应车辆的真实身份信息。
以下分别从运营商设备、车辆终端和认证管理设备三个方面对本发明的技术方案进行了说明,以下结合图8对三者之间的具体交互过程进行说明,其中,运营商设备即为MNO、车辆终端即为V-UE、认证管理设备可以为PCA:
在介绍具体的技术方案之前,先介绍本发明提到的以下几个要点:
(1)MNO持有用于数字签名的公私密钥对(PKMNO,SKMNO),其中,PKMNO为公钥,SKMNO为私钥;
(2)V-UE持有用于加解密的公私密钥对(PKv,SKv),其中,PKv为公钥,SKv私钥;
(3)PCA通过验证来自MNO的数字签名来验证V-UE的身份,同时PCA选定数个(PMSI,KPMSI),并通过PKv加密后发送给V-UE。
具体如图8所示,包括:
步骤802,V-UE从MNO处获得密钥KPERIOD。具体地,V-UE向MNO发送获取KPERIOD的请求,之后MNO向V-UE分配KPERIOD。其中,KPERIOD是由MNO生成的一个周期性密钥(比如每周换一个),KPERIOD用来对(PMSI,KPMSI)进行加密。
步骤804,MNO向PCA发送以KPERIOD加密的多对(PMSI,KPMSI),其中,(PMSI,KPMSI)的数量取决于系统的规模,比如可以是1000000对。
步骤806,V-UE向MNO请求对PKv进行签名。
步骤808,MNO在验证V-UE的身份后使用私钥SKMNO对PKv进行签名,并将签名结果返回至V-UE。其中,MNO验证V-UE的身份类似于UE的注册过程。
步骤810,V-UE将自身的IMSI(或IMEI)、PKv、MNO对PKv的签名结果发送至PCA。
步骤812,PCA基于MNO的公钥PKMNO验证PKv的签名。其中,在步骤812之前,MNO需要将公钥PKMNO通知给PCA,以便于PCA在该
步骤中对PKv的签名进行验证。
步骤814,PCA在对PKv的签名验证通过之后,选取至少一对通过KPERIOD加密的(PMSI,KPMSI),并用PKv加密后发送给V-UE。
步骤816,V-UE对接收到的(PMSI,KPMSI)进行两重解密后得到(PMSI,KPMSI)的值。具体地,V-UE先用自己的私钥SKv解密,然后再用KPERIOD解密。
在V-UE解密后获得(PMSI,KPMSI)的值之后,可以基于PMSI来进行车辆通信,而KPMSI用于进行身份识别时使用。其中,若PCA发送了多对通过KPERIOD加密的(PMSI,KPMSI),则V-UE在解密后的通信过程中,可以每过一段时间更换一次使用的PMSI。当V-UE在车联网中的恶意行为被发现后,MNO可以通过V-UE的PMSI来询问PCA,由于PCA维护有V-UE的真实身份(IMSI/IMEI)和(PMSI,KPMSI)之间的关系,因此PCA可以获得V-UE的真实身份信息,进而可以将获得的真实身份返回给MNO,可见,本发明的技术方案既保证运营商能够识别到在车联网中有恶意行为的车辆,也能够避免运营商肆意获取车联网中的车辆信息而导致车辆隐私泄露的问题。
图9示出了根据本发明的实施例的车辆终端的示意框图。
如图9所示,根据本发明的实施例的车辆终端,包括:处理器1、输入装置2、输出装置3和存储器5。在本发明的一些实施例中,处理器1、输入装置2、输出装置3和存储器5可以通过总线4或其他方式连接,图9中以通过总线4连接为例。
其中,存储器5用于存储一组程序代码,处理器1调用存储器5中存储的程序代码,用于执行以下操作:
通过输入装置2获取运营商分配的第一密钥,其中,所述运营商在向车辆终端分配所述第一密钥之后,通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
通过输出装置3向所述运营商发送对所述车辆终端的公钥进行签名的请求,并通过输入装置2接收所述运营商返回的签名结果,其中,所述运营商在对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所
述车辆终端的公钥进行签名;
通过输出装置3将所述车辆终端的识别码、所述车辆终端的公钥和所述签名结果发送至所述认证管理中心,并通过输入装置2接收所述认证管理中心发送的使用所述车辆终端的公钥和所述第一密钥加密的至少一对(PMSI,KPMSI),其中,所述至少一对(PMSI,KPMSI)是由所述认证管理中心基于所述运营商的公钥对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)选择出的;
根据所述第一密钥和所述车辆终端的私钥对接收到的所述至少一对(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进行车辆通信。
图10示出了根据本发明的实施例的运营商设备的示意框图。
如图10所示,根据本发明的实施例的运营商设备,包括:处理器1'、输入装置2'、输出装置3'和存储器5'。在本发明的一些实施例中,处理器1'、输入装置2'、输出装置3'和存储器5'可以通过总线4'或其他方式连接,图10中以通过总线4'连接为例。
其中,存储器5'用于存储一组程序代码,处理器1'调用存储器5'中存储的程序代码,用于执行以下操作:
向车辆终端分配第一密钥,并由输出装置3'通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;
在输入装置2'接收到所述车辆终端发送的对所述车辆终端的公钥进行签名的请求时,对所述车辆终端的身份进行验证;
在对所述车辆终端的身份验证通过之后,使用运营商设备的私钥对所述车辆终端的公钥进行签名,并通过输出装置3'将签名结果返回至所述车辆终端;
其中,所述签名结果用于供所述车辆终端发送至所述认证管理中心进行验证,以使所述认证管理中心在对所述签名结果验证通过后向所述车辆终端发送至少一对(PMSI,KPMSI)进行车辆通信。
作为一种可选的实施方式,处理器1'调用存储器5'中存储的程序代码,还用于执行以下操作:
通过输出装置3'将运营商设备的公钥发送至所述认证管理中心,以供所述认证管理中心根据所述运营商设备的公钥对所述签名结果进行验证。
图11示出了根据本发明的实施例的认证管理设备的示意框图。
如图11所示,根据本发明的实施例的认证管理设备,包括:处理器1”、输入装置2”、输出装置3”和存储器5”。在本发明的一些实施例中,处理器1”、输入装置2”、输出装置3”和存储器5”可以通过总线4”或其他方式连接,图11中以通过总线4”连接为例。
其中,存储器5”用于存储一组程序代码,处理器1”调用存储器5”中存储的程序代码,用于执行以下操作:
通过输入装置2”接收运营商发送的通过第一密钥加密后的多对(PMSI,KPMSI),其中,所述第一密钥是由运营商分配给车辆终端的;
通过输入装置2”接收所述车辆终端发送的所述车辆终端的识别码、所述车辆终端的公钥和所述运营商对所述车辆终端的公钥的签名结果,其中,所述签名结果是由所述运营商对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名得到的;
基于所述运营商的公钥对所述签名结果进行验证,在对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)中选择至少一对(PMSI,KPMSI),并通过所述车辆终端的公钥对经过所述第一密钥加密后的所述至少一对(PMSI,KPMSI)进行再次加密;
通过输出装置3”将通过所述车辆终端的公钥和所述第一密钥加密后的所述至少一对(PMSI,KPMSI)发送至所述车辆终端,以供所述车辆终端在解密后使用所述至少一对(PMSI,KPMSI)进行车辆通信。
本发明实施例的方法中的步骤可以根据实际需要进行顺序调整、合并和删减。
本发明实施例的车辆通信中的隐私保护装置、车辆终端、运营商设备和认证管理设备中的单元可以根据实际需要进行合并、划分和删减。
本领域普通技术人员可以理解上述实施例的各种方法中的全部或部分步骤是可以通过程序来指令相关的硬件来完成,该程序可以存储于一计算机可读存储介质中,存储介质包括只读存储器(Read-Only Memory,
ROM)、随机存储器(Random Access Memory,RAM)、可编程只读存储器(Programmable Read-only Memory,PROM)、可擦除可编程只读存储器(Erasable Programmable Read Only Memory,EPROM)、一次可编程只读存储器(One-time Programmable Read-Only Memory,OTPROM)、电子抹除式可复写只读存储器(Electrically-Erasable Programmable Read-Only Memory,EEPROM)、只读光盘(Compact Disc Read-Only Memory,CD-ROM)或其他光盘存储器、磁盘存储器、磁带存储器、或者能够用于携带或存储数据的计算机可读的任何其他介质。
以上结合附图详细说明了本发明的技术方案,本发明提出了一种新的车辆通信中的隐私保护方案,使得车辆终端与认证管理中心之间无需保持一一对应的长期密钥,降低了认证管理中心对密钥的管理负担,同时由于无需维护密钥库,因此也有效避免了密钥库遭到攻击而造成的安全隐患,极大提升了车辆通信过程中的隐私安全性。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
Claims (10)
- 一种车辆通信中的隐私保护方法,适用于车辆终端,其特征在于,包括:获取运营商分配的第一密钥,其中,所述运营商在向车辆终端分配所述第一密钥之后,通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;向所述运营商发送对所述车辆终端的公钥进行签名的请求,并接收所述运营商返回的签名结果,其中,所述运营商在对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名;将所述车辆终端的识别码、所述车辆终端的公钥和所述签名结果发送至所述认证管理中心,并接收所述认证管理中心发送的使用所述车辆终端的公钥和所述第一密钥加密的至少一对(PMSI,KPMSI),其中,所述至少一对(PMSI,KPMSI)是由所述认证管理中心基于所述运营商的公钥对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)选择出的;根据所述第一密钥和所述车辆终端的私钥对接收到的所述至少一对(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进行车辆通信。
- 根据权利要求1所述的车辆通信中的隐私保护方法,其特征在于,所述第一密钥为周期性密钥。
- 一种车辆通信中的隐私保护方法,适用于运营商设备,其特征在于,包括:向车辆终端分配第一密钥,并通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;在接收到所述车辆终端发送的对所述车辆终端的公钥进行签名的请求时,对所述车辆终端的身份进行验证;在对所述车辆终端的身份验证通过之后,使用运营商设备的私钥对所述车辆终端的公钥进行签名,并将签名结果返回至所述车辆终端;其中,所述签名结果用于供所述车辆终端发送至所述认证管理中心进 行验证,以使所述认证管理中心在对所述签名结果验证通过后向所述车辆终端发送至少一对(PMSI,KPMSI)进行车辆通信。
- 根据权利要求3所述的车辆通信中的隐私保护方法,其特征在于,还包括:将运营商设备的公钥发送至所述认证管理中心,以供所述认证管理中心根据所述运营商设备的公钥对所述签名结果进行验证。
- 一种车辆通信中的隐私保护方法,适用于认证管理设备,其特征在于,包括:接收运营商发送的通过第一密钥加密后的多对(PMSI,KPMSI),其中,所述第一密钥是由所述运营商分配给车辆终端的;接收所述车辆终端发送的所述车辆终端的识别码、所述车辆终端的公钥和所述运营商对所述车辆终端的公钥的签名结果,其中,所述签名结果是由所述运营商对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名得到的;基于所述运营商的公钥对所述签名结果进行验证,在对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)中选择至少一对(PMSI,KPMSI),并通过所述车辆终端的公钥对经过所述第一密钥加密后的所述至少一对(PMSI,KPMSI)进行再次加密;将通过所述车辆终端的公钥和所述第一密钥加密后的所述至少一对(PMSI,KPMSI)发送至所述车辆终端,以供所述车辆终端在解密后使用所述至少一对(PMSI,KPMSI)进行车辆通信。
- 一种车辆通信中的隐私保护装置,适用于车辆终端,其特征在于,包括:获取单元,用于获取运营商分配的第一密钥,其中,所述运营商在向车辆终端分配所述第一密钥之后,通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;第一交互单元,用于向所述运营商发送对所述车辆终端的公钥进行签名的请求,并接收所述运营商返回的签名结果,其中,所述运营商在对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端 的公钥进行签名;第二交互单元,用于将所述车辆终端的识别码、所述车辆终端的公钥和所述签名结果发送至所述认证管理中心,并接收所述认证管理中心发送的使用所述车辆终端的公钥和所述第一密钥加密的至少一对(PMSI,KPMSI),其中,所述至少一对(PMSI,KPMSI)是由所述认证管理中心基于所述运营商的公钥对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)选择出的;处理单元,用于根据所述第一密钥和所述车辆终端的私钥对所述第二交互单元接收到的所述至少一对(PMSI,KPMSI)进行解密,并基于解密后的(PMSI,KPMSI)进行车辆通信。
- 根据权利要求6所述的车辆通信中的隐私保护装置,其特征在于,所述第一密钥为周期性密钥。
- 一种车辆通信中的隐私保护装置,适用于运营商设备,其特征在于,包括:分配单元,用于向车辆终端分配第一密钥;第一发送单元,用于通过所述第一密钥对多对(PMSI,KPMSI)加密后发送至认证管理中心;处理单元,用于在接收到所述车辆终端发送的对所述车辆终端的公钥进行签名的请求时,对所述车辆终端的身份进行验证,当对所述车辆终端的身份验证通过之后,使用运营商设备的私钥对所述车辆终端的公钥进行签名,并将签名结果返回至所述车辆终端;其中,所述签名结果用于供所述车辆终端发送至所述认证管理中心进行验证,以使所述认证管理中心在对所述签名结果验证通过后向所述车辆终端发送至少一对(PMSI,KPMSI)进行车辆通信。
- 根据权利要求8所述的车辆通信中的隐私保护装置,其特征在于,所述第一发送单元还用于:将运营商设备的公钥发送至所述认证管理中心,以供所述认证管理中心根据所述运营商设备的公钥对所述签名结果进行验证。
- 一种车辆通信中的隐私保护装置,适用于认证管理设备,其特征 在于,包括:第一接收单元,用于接收运营商发送的通过第一密钥加密后的多对(PMSI,KPMSI),其中,所述第一密钥是由所述运营商分配给车辆终端的;第二接收单元,用于接收所述车辆终端发送的所述车辆终端的识别码、所述车辆终端的公钥和所述运营商对所述车辆终端的公钥的签名结果,其中,所述签名结果是由所述运营商对所述车辆终端的身份验证通过之后,使用所述运营商的私钥对所述车辆终端的公钥进行签名得到的;处理单元,用于基于所述运营商的公钥对所述签名结果进行验证,在对所述签名结果验证通过后,从所述多对(PMSI,KPMSI)中选择至少一对(PMSI,KPMSI),并通过所述车辆终端的公钥对经过所述第一密钥加密后的所述至少一对(PMSI,KPMSI)进行再次加密;发送单元,用于将通过所述车辆终端的公钥和所述第一密钥加密后的所述至少一对(PMSI,KPMSI)发送至所述车辆终端,以供所述车辆终端在解密后使用所述至少一对(PMSI,KPMSI)进行车辆通信。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610933025.6A CN106506161B (zh) | 2016-10-31 | 2016-10-31 | 车辆通信中的隐私保护方法及隐私保护装置 |
| CN201610933025.6 | 2016-10-31 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018076564A1 true WO2018076564A1 (zh) | 2018-05-03 |
Family
ID=58319709
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/072672 Ceased WO2018076564A1 (zh) | 2016-10-31 | 2017-01-25 | 车辆通信中的隐私保护方法及隐私保护装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN106506161B (zh) |
| WO (1) | WO2018076564A1 (zh) |
Cited By (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109819049A (zh) * | 2019-02-28 | 2019-05-28 | 钛马信息网络技术有限公司 | 远程控制车辆的方法、系统及装置 |
| CN112153608A (zh) * | 2020-09-24 | 2020-12-29 | 南通大学 | 一种基于侧链技术信任模型的车联网跨域认证方法 |
| CN115278657A (zh) * | 2022-07-13 | 2022-11-01 | 东南大学 | 车联网中具有隐私保护的v2i通信系统及方法 |
| CN116108489A (zh) * | 2023-02-28 | 2023-05-12 | 东风汽车集团股份有限公司 | 一种V-soc安全营运方法及系统 |
| CN116264529A (zh) * | 2018-05-04 | 2023-06-16 | 诚信安全服务有限公司 | 识别异常行为的计算机化设备的系统、方法和可读介质 |
| CN116366289A (zh) * | 2023-02-24 | 2023-06-30 | 中国测绘科学研究院 | 无人机遥感数据的安全监管方法及装置 |
| CN118473740A (zh) * | 2024-05-08 | 2024-08-09 | 广州汽车集团股份有限公司 | 车载通信终端的检测方法、装置、车载通信终端及存储介质 |
| CN118972857A (zh) * | 2024-08-12 | 2024-11-15 | 黑龙江省网络空间研究中心(黑龙江省信息安全测评中心、黑龙江省国防科学技术研究院) | 一种隐私加密通信方法及系统 |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11050556B2 (en) * | 2018-07-13 | 2021-06-29 | Micron Technology, Inc. | Secure vehicular communication |
| US11240006B2 (en) * | 2019-03-25 | 2022-02-01 | Micron Technology, Inc. | Secure communication for a key exchange |
| CN110190958A (zh) * | 2019-05-30 | 2019-08-30 | 北京百度网讯科技有限公司 | 一种车辆的身份验证方法、装置、电子设备及存储介质 |
| CN112350821B (zh) * | 2019-08-06 | 2024-07-26 | 北京车和家信息技术有限公司 | 密钥的获取方法、装置及系统 |
| CN111866014B (zh) * | 2020-07-29 | 2022-02-11 | 中国联合网络通信集团有限公司 | 一种车辆信息保护方法及装置 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2008312213A (ja) * | 2007-06-15 | 2008-12-25 | Ntt Docomo Inc | 認証方法及び装置 |
| CN103618995A (zh) * | 2013-12-04 | 2014-03-05 | 西安电子科技大学 | 基于动态假名的位置隐私保护方法 |
| CN104753680A (zh) * | 2015-03-26 | 2015-07-01 | 北京航空航天大学 | 一种车载自组织网络中的隐私保护与认证方法 |
| CN105554105A (zh) * | 2015-12-14 | 2016-05-04 | 安徽大学 | 一种面向多服务与隐私保护的车联网组密钥管理方法 |
| CN105847235A (zh) * | 2016-03-14 | 2016-08-10 | 安徽大学 | 一种车联网环境下基于身份的高效匿名批认证方法 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103974255B (zh) * | 2014-05-05 | 2018-06-05 | 宇龙计算机通信科技(深圳)有限公司 | 一种车辆接入系统和方法 |
-
2016
- 2016-10-31 CN CN201610933025.6A patent/CN106506161B/zh active Active
-
2017
- 2017-01-25 WO PCT/CN2017/072672 patent/WO2018076564A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2008312213A (ja) * | 2007-06-15 | 2008-12-25 | Ntt Docomo Inc | 認証方法及び装置 |
| CN103618995A (zh) * | 2013-12-04 | 2014-03-05 | 西安电子科技大学 | 基于动态假名的位置隐私保护方法 |
| CN104753680A (zh) * | 2015-03-26 | 2015-07-01 | 北京航空航天大学 | 一种车载自组织网络中的隐私保护与认证方法 |
| CN105554105A (zh) * | 2015-12-14 | 2016-05-04 | 安徽大学 | 一种面向多服务与隐私保护的车联网组密钥管理方法 |
| CN105847235A (zh) * | 2016-03-14 | 2016-08-10 | 安徽大学 | 一种车联网环境下基于身份的高效匿名批认证方法 |
Non-Patent Citations (1)
| Title |
|---|
| LG ELECTRONICS: "Update of V2X attach identifier obfuscation solution in 6.3", 3GPP TSG SA WG3 (SECURITY) MEETING #84, S3-160996, 29 July 2016 (2016-07-29), XP051139388 * |
Cited By (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116264529A (zh) * | 2018-05-04 | 2023-06-16 | 诚信安全服务有限公司 | 识别异常行为的计算机化设备的系统、方法和可读介质 |
| CN109819049A (zh) * | 2019-02-28 | 2019-05-28 | 钛马信息网络技术有限公司 | 远程控制车辆的方法、系统及装置 |
| CN112153608A (zh) * | 2020-09-24 | 2020-12-29 | 南通大学 | 一种基于侧链技术信任模型的车联网跨域认证方法 |
| CN112153608B (zh) * | 2020-09-24 | 2022-09-30 | 南通大学 | 一种基于侧链技术信任模型的车联网跨域认证方法 |
| CN115278657A (zh) * | 2022-07-13 | 2022-11-01 | 东南大学 | 车联网中具有隐私保护的v2i通信系统及方法 |
| CN116366289A (zh) * | 2023-02-24 | 2023-06-30 | 中国测绘科学研究院 | 无人机遥感数据的安全监管方法及装置 |
| CN116108489A (zh) * | 2023-02-28 | 2023-05-12 | 东风汽车集团股份有限公司 | 一种V-soc安全营运方法及系统 |
| CN118473740A (zh) * | 2024-05-08 | 2024-08-09 | 广州汽车集团股份有限公司 | 车载通信终端的检测方法、装置、车载通信终端及存储介质 |
| CN118972857A (zh) * | 2024-08-12 | 2024-11-15 | 黑龙江省网络空间研究中心(黑龙江省信息安全测评中心、黑龙江省国防科学技术研究院) | 一种隐私加密通信方法及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN106506161A (zh) | 2017-03-15 |
| CN106506161B (zh) | 2023-08-15 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN106506161B (zh) | 车辆通信中的隐私保护方法及隐私保护装置 | |
| JP6877524B2 (ja) | ワイヤレス通信のための装置および方法 | |
| US11075752B2 (en) | Network authentication method, and related device and system | |
| US11228442B2 (en) | Authentication method, authentication apparatus, and authentication system | |
| US10638321B2 (en) | Wireless network connection method and apparatus, and storage medium | |
| CN108353279B (zh) | 一种认证方法和认证系统 | |
| CN108012266B (zh) | 一种数据传输方法及相关设备 | |
| US10009760B2 (en) | Providing network credentials | |
| WO2017114123A1 (zh) | 一种密钥配置方法及密钥管理中心、网元 | |
| WO2017185692A1 (zh) | 密钥分发、认证方法,装置及系统 | |
| CN113545115B (zh) | 一种通信方法及装置 | |
| CN102036238A (zh) | 一种基于公钥实现用户与网络认证和密钥分发的方法 | |
| CN110012467B (zh) | 窄带物联网的分组认证方法 | |
| US10834063B2 (en) | Facilitating provisioning of an out-of-band pseudonym over a secure communication channel | |
| WO2020216047A1 (zh) | 一种认证信息处理方法、终端和网络设备 | |
| CN112242976A (zh) | 一种身份认证方法及装置 | |
| CN111918289B (zh) | 终端接入方法、装置和服务器 | |
| CN104243452A (zh) | 一种云计算访问控制方法及系统 | |
| CN110138558B (zh) | 会话密钥的传输方法、设备及计算机可读存储介质 | |
| WO2009155807A1 (zh) | 预认证的方法、认证系统和装置 | |
| US8855604B2 (en) | Roaming authentication method for a GSM system | |
| CN110536289B (zh) | 密钥发放方法及其装置、移动终端、通信设备和存储介质 | |
| KR100968522B1 (ko) | 상호 인증 및 핸드오버 보안을 강화한 모바일 인증 방법 | |
| JP2023509806A (ja) | モバイルネットワークアクセスシステム、方法、記憶媒体及び電子機器 | |
| US20260129435A1 (en) | Shared Secret Key Architecture and Distribution |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17863481 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17863481 Country of ref document: EP Kind code of ref document: A1 |