WO2022218205A1 - Data transmission method and data processing apparatus - Google Patents

Data transmission method and data processing apparatus Download PDF

Info

Publication number
WO2022218205A1
WO2022218205A1 PCT/CN2022/085552 CN2022085552W WO2022218205A1 WO 2022218205 A1 WO2022218205 A1 WO 2022218205A1 CN 2022085552 W CN2022085552 W CN 2022085552W WO 2022218205 A1 WO2022218205 A1 WO 2022218205A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
signature
communication unit
module
data processing
Prior art date
Application number
PCT/CN2022/085552
Other languages
French (fr)
Chinese (zh)
Inventor
李添泽
余志洋
郑益红
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2022218205A1 publication Critical patent/WO2022218205A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/30Services specially adapted for particular environments, situations or purposes
    • H04W4/40Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/30Services specially adapted for particular environments, situations or purposes
    • H04W4/40Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
    • H04W4/48Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P] for in-vehicle communication

Definitions

  • the present application relates to the field of communications, and in particular, to a data transmission method and a data processing device.
  • V2X Vehicle to Everything
  • a data transmission method and data processing device are proposed, which can improve the reliability of V2X information and improve the safety of vehicle motion decision-making and control without upgrading and upgrading existing equipment hardware as much as possible.
  • an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the arithmetic unit communicates with an application layer The first V2X information of the Internet of Vehicles is processed by the first signature, and the second V2X information is obtained, and the second V2X information includes the first V2X information and the first signature; the computing unit sends the second V2X information to the communication unit; the communication unit performs a second signature process on the second V2X information to obtain third V2X information, where the third V2X information includes the second V2X information and a second signature; the communication unit The third V2X information is sent.
  • the computing unit performs the first signature processing on the V2X information of the application layer, so that when the computing unit meets the functional safety level requirements, the functional security of the V2X information of the application layer can be guaranteed.
  • the communication unit performs the second signature processing on the V2X information that has undergone the first signature processing, thus ensuring the application Layer V2X information security during network transmission. Therefore, in the embodiments of the present application, the reliability of V2X information can be improved, and the safety of vehicle motion decision-making and control can be improved without changing and upgrading existing equipment hardware as much as possible.
  • the first signature processing includes: one or more of an information excerpt, a cyclic redundancy CRC check, and a digital signature, wherein , the digital signature includes a digital signature based on a root certificate issued by a national certification agency platform, or a digital signature based on a root certificate issued by a car company self-inspection certification agency platform, or a digital signature based on the root certificate issued by the ecological alliance certification agency platform .
  • the data processing apparatus is a vehicle-mounted device, and the arithmetic unit includes a mobile The data center MDC, the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device, and the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • the reliability of the V2X information provided by the roadside equipment to the vehicle can be improved, thereby helping to improve the safety of vehicle motion decision-making and control.
  • the computing unit sends the second V2X information to the
  • the communication unit includes: the operation unit sends the second V2X information to the communication unit through Ethernet.
  • V2X information between the computing unit and the communication unit is realized through the Ethernet, which can improve the transmission efficiency, simplify the information structure, and reduce the cost.
  • an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the arithmetic unit communicates with an application layer The first V2X information of the Internet of Vehicles is processed by the first signature, and the second V2X information is obtained, and the second V2X information includes the first V2X information and the first signature; the computing unit communicates with the communication unit through the The secure channel sends the second V2X information to the communication unit; the communication unit sends the second V2X information.
  • the signature processing process of the second V2X information by the communication unit can be omitted, thereby reducing the complexity of the first communication unit. Functional requirements, reducing the cost of the first communication unit.
  • the first signature processing includes: a digital signature based on a root certificate issued by a platform of a national certification authority, or based on a self-inspection by a car company The digital signature of the root certificate of the certification authority platform, or the digital signature based on the root certificate issued by the certification authority platform of the Ecological Alliance.
  • the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data
  • the central MDC the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device, and the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the communication unit receives a third Internet of Vehicles V2X information, the third V2X information includes second V2X information and a second signature, and the second V2X information includes the first V2X information and first signature of the application layer; the communication unit writes the second signature to the verifying; in the case that the verification of the second signature is successful, the communication unit sends the second V2X information to the computing unit; the computing unit verifies the first signature; If the verification is successful, the operation unit performs information processing on the first V2X information.
  • the second communication unit can directly forward the received V2X information to the second computing unit through the secure channel, and the second computing unit performs signature verification.
  • V2X information without signature verification can be prevented from adversely affecting other components in the vehicle, and on the other hand, the functional requirements of the second communication unit can be reduced, thereby reducing the cost of the second communication unit.
  • the second operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide guarantee for functional safety.
  • the verification by the communication unit of the second signature includes: the communication unit performs information extraction processing on the second V2X information , to obtain a first digest; the communication unit decrypts the second signature to obtain a second digest; in the case that the first digest and the second digest are the same, the communication unit determines that the first digest is the same as the second digest. Second signature verification succeeded.
  • the operation unit verifying the first signature includes: the The arithmetic unit performs information extraction verification on the first signature, or performs cyclic redundancy CRC verification, or performs digital signature verification, wherein the digital signature verification includes digital signature verification based on the root certificate issued by the national certification authority platform. , or, based on the digital signature verification of the root certificate of the car company's self-inspection certification agency platform, or, based on the digital signature verification of the root certificate issued by the ecological alliance certification agency platform.
  • the data processing apparatus is a vehicle-mounted device
  • the computing unit includes a mobile data center MDC
  • the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside equipment
  • the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • the communication The unit sending the second V2X information to the operation unit includes: in the case that the verification of the second signature is successful, the communication unit sends the second V2X information to the operation unit through the Ethernet.
  • an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the communication unit receives a second Internet of Vehicles V2X information, the second V2X information includes the first V2X information and the first signature of the application layer; the communication unit sends the second V2X information to the The operation unit; the operation unit verifies the first signature; in the case that the first signature is successfully verified, the operation unit performs information processing on the first V2X information.
  • the communication unit sends the second V2X information to the computing unit through the secure channel, so that the unverified V2X information can be sent to the dedicated channel, thereby reducing the impact on other components in the data processing device;
  • the first signature in the message is verified, which can prevent problems such as message corruption and message insertion, and provide a guarantee for functional safety.
  • the verifying the first signature by the first signature includes: performing, by the computing unit, country-based authentication on the first signature The digital signature verification of the root certificate issued by the agency platform, or the digital signature verification based on the root certificate of the car company's self-inspection certification agency platform, or the digital signature verification based on the root certificate issued by the ecological alliance certification agency platform.
  • the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data
  • the central MDC the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device, and the arithmetic unit includes Signal, the communication unit includes a roadside unit RSU.
  • an embodiment of the present application provides a data processing device, the data processing device includes an operation unit and a communication unit, the operation unit includes a first signature module and a first sending module, and the communication unit includes a first signature module and a first sending module. Two signature modules and a second sending module;
  • the first signature module is configured to perform first signature processing on the first V2X information of the Internet of Vehicles at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
  • the first sending module configured to send the second V2X information obtained by the first signature module to the second signature module;
  • the second signature module is configured to perform second signature processing on the second V2X information sent by the first sending module to obtain third V2X information, where the third V2X information includes the second V2X information and the second V2X information. sign;
  • the second sending module is configured to send the third V2X information obtained by the second signature module.
  • the first signature processing includes: one or more of information extraction, cyclic redundancy CRC check and digital signature, wherein , the digital signature includes a digital signature based on a root certificate issued by a national certification agency platform, or a digital signature based on a root certificate issued by a car company self-inspection certification agency platform, or a digital signature based on the root certificate issued by the ecological alliance certification agency platform .
  • the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data
  • the central MDC the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device, and the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • the first sending module is further configured to send the The second V2X information is sent to the second signature module.
  • an embodiment of the present application provides a data processing device, the data processing device includes an operation unit and a communication unit, the operation unit is connected to the communication unit through a secure channel, and the operation unit includes a first a signature module and a first sending module, the communication unit includes a second sending module;
  • the first signature module is configured to perform first signature processing on the first V2X information of the Internet of Vehicles at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
  • the first sending module configured to send the second V2X information to the second sending module through the secure channel
  • the second sending module is configured to send the second V2X information.
  • the first signature processing includes: one or more of an information excerpt, a cyclic redundancy CRC check, and a digital signature, wherein , the digital signature includes a digital signature based on a root certificate issued by a national certification agency platform, or a digital signature based on a root certificate issued by a car company self-inspection certification agency platform, or a digital signature based on the root certificate issued by the ecological alliance certification agency platform .
  • the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data
  • the central MDC the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device, and the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • an embodiment of the present application provides a data processing device, the data processing device includes an arithmetic unit and a communication unit, the communication unit includes a receiving module, a first signature verification module and a sending module, the arithmetic unit Including a second signature verification module and a processing module;
  • the receiving module is configured to receive the third V2X information of the Internet of Vehicles, the third V2X information of the Internet of Vehicles includes the second V2X information and the second signature, and the second V2X information includes the first V2X information and the first V2X information of the application layer. sign;
  • the first signature verification module configured to verify the second signature in the third V2X information received by the receiving module
  • the sending module configured to send the second V2X information to the second signature verification module when the first signature verification module successfully verifies the second signature
  • the second signature verification module configured to verify the first signature in the second V2X information sent by the sending module
  • the processing module is configured to perform information processing on the first V2X information when the second signature verification module successfully verifies the first signature.
  • the first signature verification module is further configured to:
  • the second signature verification module is further configured to:
  • the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, or , based on the digital signature verification of the root certificate of the car company's self-inspection certification agency platform, or, based on the digital signature verification of the root certificate issued by the ecological alliance certification agency platform.
  • the data processing apparatus is a vehicle-mounted The device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a side equipment
  • the arithmetic unit includes a signal machine
  • the communication unit includes a roadside unit RSU.
  • the sending module is further configured to: in the first signature verification When the module successfully verifies the second signature, it sends the second V2X information to the second signature verification module through Ethernet.
  • an embodiment of the present application provides a data processing device, the data processing device includes a communication unit and an operation unit, the communication unit and the operation unit are connected through a secure channel, and the communication unit includes a receiving module and a sending module, the arithmetic unit includes a signature verification module and a processing module;
  • the receiving module is configured to receive the second V2X information of the Internet of Vehicles, where the second V2X information includes the first V2X information and the first signature of the application layer;
  • the sending module configured to send the second V2X information received by the receiving module to the signature verification module through the secure channel;
  • the signature verification module configured to verify the first signature in the second V2X information sent by the sending module
  • the processing module is configured to perform information processing on the first V2X information when the signature verification module successfully verifies the first signature.
  • the signature verification module is further configured to:
  • the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data
  • the central MDC the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device, and the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • an embodiment of the present application provides a data processing apparatus, and the data processing apparatus can execute the first aspect or one or more of the data transmission methods in multiple possible implementations of the first aspect, Either execute the above second aspect or one or more of the possible implementations of the second aspect, or execute the third aspect or one of the multiple possible implementations of the third aspect or several data transmission methods, or perform one or more data transmission methods of the fourth aspect or multiple possible implementation manners of the fourth aspect.
  • embodiments of the present application provide a computer program product, comprising computer-readable codes, or a computer-readable storage medium carrying computer-readable codes, which are implemented when the computer-readable codes are executed by a processor
  • FIG. 1 shows a schematic diagram of the architecture of a V2X communication system provided by an embodiment of the present application
  • FIG. 2 shows a schematic diagram of a transmission process of V2X information in a V2I scenario
  • FIG. 3a shows a schematic diagram of the architecture of a data transmission system provided by an embodiment of the present application
  • FIG. 3b shows a schematic structural diagram of an electronic device provided by an embodiment of the present application.
  • FIG. 3c shows an interactive schematic diagram of the data transmission method provided by the embodiment of the present application.
  • FIG. 3d shows an interactive schematic diagram of a data transmission method provided by an embodiment of the present application
  • FIG. 4a shows a schematic diagram of the architecture of a data transmission system in a V2I scenario provided by an embodiment of the present application
  • FIG. 4b shows a schematic diagram of the architecture of a data transmission system in a V2I scenario provided by an embodiment of the present application
  • 4c shows a schematic diagram of the architecture of a data transmission system in a V2V scenario provided by an embodiment of the present application
  • 4d shows a schematic diagram of the architecture of a data transmission system in a V2V scenario provided by an embodiment of the present application
  • FIG. 5 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application
  • FIG. 6 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
  • FIG. 7 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
  • FIG. 8 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
  • V2X communication refers to the communication between vehicles and anything in the outside world.
  • FIG. 1 shows a schematic structural diagram of a V2X communication system provided by an embodiment of the present application.
  • V2X communication includes vehicle-to-vehicle communication (Vehicle to Vehicle, V2V), vehicle-to-pedestrian communication (Vehicle to Pedestrian, V2P), and vehicle-to-infrastructure (Vehicle to Infrastructure, V2I) communication.
  • V2X communication direct communication is possible between devices.
  • RSUs Road Side Units
  • devices in the V2X system can communicate directly based on communication protocols such as Dedicated Short Range Communication (DSRC), Long Term Evolution-Vehicle (LTE-V), etc.
  • DSRC Dedicated Short Range Communication
  • LTE-V Long Term Evolution-Vehicle
  • This application implements The example does not limit the communication protocol between devices in the V2X communication system.
  • the equipment involved on the roadside includes signal machines, V2X servers, and roadside units, etc.
  • the equipment involved on the vehicle side includes on-board communication units, gateways (GateWay, GW), on-board computing platforms, and controllers.
  • the in-vehicle communication unit may include a telematics processor (Telematics BOX, TBox), the in-vehicle computing platform may include a mobile data center (Mobile Data Center, MDC), and the controller may include a vehicle control unit (Vehicle Control Unit, VCU).
  • Telematics BOX Telematics BOX
  • MDC Mobile Data Center
  • VCU Vehicle Control Unit
  • the data transmission method provided in the embodiment of the present application relates to the functional safety of the V2X communication system, that is, to improve the transmission of V2X information input to an automatic driving system (Auto Driving System, ADS) or an automatic driving assistance system (Auto Driving Assistance System, ADAS) reliability, thereby improving the safety of vehicle motion decision-making and control.
  • ADS automatic driving system
  • ADAS Automatic Driving Assistance System
  • the data transmission method provided by the embodiment of the present application may be applied to a V2I scenario or a V2V scenario.
  • a V2I scenario when a vehicle is driving on an urban road, the roadside equipment sends traffic light information to the vehicle using V2X information, and the on-board computing platform in the vehicle can perceive the traffic light information provided by the roadside equipment and the in-vehicle sensors. The received information is fused to help the vehicle perform the correct operation.
  • the data transmission method provided by the embodiments of the present application can be used to transmit traffic light information, improve the reliability of the traffic light information, and further improve the safety of vehicle motion decision-making and control.
  • V2V Vehicle in front will use V2X information to send decision information such as acceleration, braking, lane change or maintaining the status quo to the following vehicle, and periodically send Blind Spot Monitoring (BSM) information and computer-aided manufacturing ( Computer Aided Drafting, CAM) information.
  • BSM Blind Spot Monitoring
  • CAM Computer Aided Drafting
  • the on-board computing platform in the following vehicle can fuse decision-making information, BSM information, CAM information, and information sensed by in-vehicle sensors to help the following vehicle perform correct operations and avoid not seeing the rear when driving in parallel with the preceding vehicle. Vehicles are scratched and collided due to oncoming vehicles.
  • the data transmission method provided in the embodiment of the present application can be used to transmit decision information, BSM information and CAM information, so as to improve the reliability of decision information, BSM information and CAM information, thereby improving the safety of vehicle motion decision and control.
  • the following describes the transmission process of V2X information in a V2I scenario with reference to FIG. 2 as an example.
  • V2X information in the V2V scenario reference may be made to the transmission process of V2X information in the V2I scenario, which will not be repeated here.
  • FIG. 2 shows a schematic diagram of a transmission process of V2X information in a V2I scenario.
  • the traffic signal control system transmits the traffic light information to the signal through the traffic private network, and the signal can control the display of the traffic light according to the received traffic light information, and send the received traffic light information to the roadside unit.
  • the V2X server can send some traffic control information and road condition information to the roadside unit.
  • the traffic light information, traffic control information and road condition information here will be transmitted in the V2X communication system later, and the security of these information needs to be guaranteed.
  • the roadside unit is responsible for broadcasting the received V2X information such as traffic light information, traffic control information and road condition information to the vehicle.
  • the in-vehicle communication unit in the vehicle can send the received V2X information such as traffic light information, traffic control information and road condition information to the in-vehicle computing platform through the gateway.
  • the in-vehicle computing platform fuses the received V2X information such as traffic light information, traffic control information, and road condition information based on the data obtained by sensors such as radar and cameras (such as radar signals, images, etc.) to obtain fusion information. Then, the in-vehicle computing platform can send the fusion information to the controller, so that the controller can make motion decision and control of the vehicle based on the fusion information.
  • the traffic light information received by the in-vehicle computing platform is a red light
  • the red light captured by the camera is also a red light
  • the in-vehicle computing platform can obtain the fusion information as a red light.
  • the controller After the in-vehicle computing platform sends the fusion information to the controller, the controller generates a braking command according to the red light, and then controls the vehicle to brake automatically.
  • the traffic control information received by the on-board computing platform is the maximum speed limit of 40km/h in the construction section
  • the speed limit sign captured by the camera is also the maximum speed limit of 40km/h
  • the high-precision map shows that the vehicle enters after 100 meters.
  • the vehicle-mounted computing platform can obtain the fusion information that the speed is lower than 40km/h. After the in-vehicle computing platform sends the fusion information to the controller, the controller determines whether it is necessary to control the deceleration according to the speed lower than 40km/h, and automatically decelerates when it is necessary to control the deceleration of the vehicle.
  • the equipment involved in the transmission of V2X information such as traffic light information, traffic control information, and road condition information includes roadside signals (or V2X servers) and roadside units, as well as vehicle-side on-board communication units, gateways and In-vehicle computing platform
  • the transmission paths involved in the transmission of V2X information include: signal (or V2X server) to roadside unit, roadside unit to vehicle communication unit, vehicle communication unit to gateway, and gateway to vehicle computing platform.
  • V2X information is required.
  • the software and hardware development of all equipment involved in the transmission process is designed, developed and verified in accordance with the ISO26262 system and reaches the functional safety level of ASIL-B.
  • roadside equipment such as signals, V2X servers and roadside units, etc.
  • the feasibility is low.
  • the on-board communication unit and gateway on the vehicle side reach the functional safety level of ASIL-B, which will increase the vehicle cost and is not conducive to the development of ADS or ADAS.
  • the data transmission method provided by the embodiments of the present application improves the reliability of V2X information, and further improves the safety of vehicle motion decision-making and control, without modifying and upgrading existing equipment hardware as much as possible.
  • FIG. 3 a shows a schematic structural diagram of a data transmission system provided by an embodiment of the present application.
  • the data transmission system includes a first operation unit 11 , a first communication unit 12 , a second communication unit 13 and a second operation unit 14 .
  • the V2X information whose reliability needs to be guaranteed is referred to as the first V2X information.
  • the first operation unit 11 shown in FIG. 3 a is used to represent a device that provides the first V2X information, and the first V2X information comes from the application layer of the first operation unit 11 .
  • the second operation unit 14 is used to represent a device using the first V2X information.
  • the essence of ensuring the reliability of the first V2X information is to make the first V2X information provided by the first operation unit 11 consistent with the first V2X information that reaches the second operation unit 14 and is used by the second operation unit 14 .
  • the first communication unit 12 is used for sending the V2X information from the first operation unit 11
  • the second communication unit 13 is used for receiving the V2X information from the first communication unit 12 and sending the V2X information to the second operation unit 14 .
  • the first arithmetic unit 11 and the first communication unit 12 belong to the data processing apparatus of the transmitting end.
  • the second arithmetic unit 14 and the second communication unit 13 belong to the data processing device of the receiving end.
  • the first computing unit 11 and the second computing unit 14 shown in FIG. 3a are designed, developed, and verified in accordance with the ISO26262 system to achieve the functional safety level of ASIL-B, and the first communication unit shown in FIG. 3a 12 and the second communication unit 13 and other devices involved in the first V2X information transmission process have no functional safety requirements.
  • the functional safety level requirements for the equipment in the V2X communication system are effectively reduced, and the existing equipment can be compatible as much as possible, thereby reducing the cost.
  • the data transmission method provided in the embodiment of the present application may be applied to a V2I scenario or a V2V scenario.
  • the roadside equipment can provide the first V2X information to the in-vehicle equipment.
  • the data processing device at the transmitting end shown in Figure 3a is the roadside equipment, and the data output device at the receiving end is the in-vehicle equipment.
  • the first computing unit 11 may be a signal or a V2X server
  • the first communication unit 12 may be a roadside unit
  • the second communication unit 13 may be a telematics processor
  • the second computing unit 14 may be a mobile data center.
  • the in-vehicle device can also provide the first V2X information to the roadside device.
  • the first computing unit 11 shown in FIG. 3a can be a mobile data center
  • the first communication unit 12 can be a telematics processor
  • the second communication unit 13 may be a roadside unit
  • the second computing unit 14 may be a signal or a V2X server.
  • the vehicles can provide each other with the first V2X information.
  • the first computing unit 11 shown in FIG. 3a can be the mobile data center of the vehicle A
  • the first communication unit 12 can be the telematics processing of the vehicle A.
  • the second communication unit 13 may be the telematics processor of the vehicle B
  • the second computing unit 14 may be the mobile data center of the vehicle B.
  • first and “second” in the first and second operation units involved in the embodiments of the present application are only used to distinguish different operation units, and the first operation unit represents the data processing of the sending end The arithmetic unit in the device, and the second arithmetic unit represents the arithmetic unit in the data processing device at the receiving end, and both are arithmetic units. It can be understood that, in one scenario, one computing unit may serve as the first computing unit in the sending end, and in another scenario, the same computing unit may serve as the second computing unit in the receiving end.
  • first and “second” in the first communication unit and the second communication unit involved in the embodiments of the present application are only used to distinguish different communication units, and the first communication unit represents the communication unit in the data processing apparatus of the sender , and the second communication unit represents a communication unit in the data processing device at the receiving end, both of which are communication units.
  • a communication unit can be used as the first communication unit in the sending end in one scenario, and can be the second communication unit in the receiving end in another scenario. In the embodiment of the present application, there is no restriction on whether the computing unit and the communication unit are the sending end or the receiving end.
  • the first computing unit, the first communication unit, the second communication unit, and the second computing unit involved in the embodiments of the present application may be deployed in an electronic device having a communication function (wireless communication function and/or wired communication function).
  • FIG. 3b shows a schematic structural diagram of an electronic device provided by an embodiment of the present application.
  • the electronic device may include at least one processor 301 , a memory 302 , an input and output device 303 and a bus 304 .
  • processor 301 the electronic device may include at least one processor 301 , a memory 302 , an input and output device 303 and a bus 304 .
  • the processor 301 is the control center of the electronic device, and may be a processor or a general term for multiple processing elements.
  • the processor 301 is a central processing unit (Central Processing Unit, CPU), may also be a specific integrated circuit (Application Specific Integrated Circuit, ASIC), or is configured to implement one or more integrated circuits of the embodiments of the present application , for example: one or more microprocessors (Digital Signal Processor, DSP), or, one or more Field Programmable Gate Array (Field Programmable Gate Array, FPGA).
  • CPU Central Processing Unit
  • ASIC Application Specific Integrated Circuit
  • the processor 301 can execute various functions of the electronic device by running or executing software programs stored in the memory 302 and calling data stored in the memory 302 .
  • the processor may be configured to perform first signature processing on the first V2X information, second signature processing on the second V2X information, verification of the first signature, verification of the second signature, and the like.
  • the processor 301 may include one or more CPUs, such as CPU 0 and CPU 1 shown in the figure.
  • the electronic device may include multiple processors, such as the processor 301 and the processor 305 shown in FIG. 3b.
  • processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU).
  • a processor herein may refer to one or more devices, circuits, and/or processing cores for processing data (eg, computer program instructions).
  • Memory 302 may be Read-Only Memory (ROM) or other types of static storage devices that can store static information and instructions, Random Access Memory (RAM), or other types of information and instructions that can be stored It can also be an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, optical disk storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or capable of carrying or storing desired program code in the form of instructions or data structures and capable of being executed by a computer Access any other medium without limitation.
  • ROM Read-Only Memory
  • RAM Random Access Memory
  • EEPROM Electrically erasable programmable Read-only memory
  • CD-ROM Compact disc read-only memory
  • CD-ROM compact disc read-only memory
  • optical disk storage including compact discs, laser discs, optical discs, digital versatile discs
  • the memory 302 may exist independently, and is connected to the processor 301 through the bus 304.
  • the memory 302 may also be integrated with the processor 301 .
  • the memory may be used to store the first V2X information, the second V2X information, or the third V2X information, or a private key, a public key, and the like.
  • Input and output devices 303 for communicating with other devices or communication networks. For example, it is used to communicate with communication networks such as Ethernet, Radio access network (RAN), Wireless Local Area Networks (WLAN).
  • the input-output device 303 may include all or part of a baseband processor, and may optionally include a radio frequency (Radio Frequency, RF) processor.
  • the RF processor is used to transmit and receive RF signals
  • the baseband processor is used to realize the processing of the baseband signal converted by the RF signal or the baseband signal to be converted into the RF signal.
  • the input-output device 303 may include a transmitter and a receiver.
  • the transmitter is used for sending signals to other devices or communication networks, and the receiver is used for receiving signals sent by other devices or communication networks.
  • the transmitter and receiver can exist independently or can be integrated.
  • the input and output device may be used to send and receive: first V2X information, second V2X information, or third V2X information.
  • the bus 304 can be an industry standard architecture (Industry Standard Architecture, ISA) bus, a peripheral device interconnect (Peripheral Component Interconnect, PCI) bus, or an extended industry standard architecture (Extended Industry Standard Architecture, EISA) bus and the like.
  • ISA Industry Standard Architecture
  • PCI peripheral device interconnect
  • EISA Extended Industry Standard Architecture
  • the bus can be divided into address bus, data bus, control bus and so on. For ease of presentation, only one thick line is used in Figure 3b, but it does not mean that there is only one bus or one type of bus.
  • the device structure shown in FIG. 3b does not constitute a limitation to the electronic device, and may include more or less components than shown, or combine some components, or arrange different components.
  • the first V2X information may represent V2X information whose reliability needs to be guaranteed.
  • the first V2X information is provided by the application layer of the first operation unit for use by the second operation unit.
  • the first V2X information starts from the first computing unit and reaches the second computing unit via the first communication unit and the second communication unit.
  • the first V2X information includes traffic light information provided by the signal, traffic control information provided by the V2X server, road condition information provided by the V2X server, or decision information, BSM information, and CAM information provided by the in-vehicle computing platform. This embodiment of the present application does not limit the content of the first V2X information.
  • the second V2X information may represent V2X information obtained by performing the first signature processing on the first V2X information.
  • the second V2X information includes the first V2X information and the first signature.
  • the first operation unit sends the first V2X information
  • the first V2X information needs to pass through the application layer, the transport layer, the network layer, the access layer and the physical layer of the first operation unit in sequence.
  • a first signature processing function is added to the application layer of the first operation unit, and the first operation unit can perform first signature processing on the first V2X information after acquiring the first V2X information from its application layer. , so as to obtain the second V2X information.
  • the first signature process includes, but is not limited to, one or more of an information excerpt (eg, using a hash function to calculate the information excerpt), a Cyclic Redundancy Check (CRC) check, and a digital signature.
  • an information excerpt eg, using a hash function to calculate the information excerpt
  • CRC Cyclic Redundancy Check
  • digital signature includes the digital signature based on the root certificate issued by the national certification authority platform, or the digital signature based on the root certificate of the vehicle enterprise self-inspection certification authority platform, or the digital signature based on the root certificate issued by the ecological alliance certification authority platform.
  • the third V2X information may represent V2X information obtained by performing the second signature processing on the second V2X information.
  • the third V2X information includes the second V2X information and the second signature. That is, the third V2X information includes the first V2X information, the first signature and the second signature, wherein the first V2X information and the first signature constitute the second V2X information.
  • the second V2X information reaches the physical layer of the first communication unit from the physical layer of the first operation unit, and then sequentially passes through the access layer, network layer and transport layer of the first communication unit to reach the first pass unit application layer.
  • a second signature processing function is added to the application layer of the first communication unit, and after the first communication unit obtains the second V2X information from its application layer, the second signature processing is performed on the second V2X information, thereby Get third V2X information. After that, the third V2X information is sent out through the application layer, the transport layer, the network layer, the access layer and the physical layer of the first communication unit. In this way, when the protected data (ie the first V2X information) is transmitted together with the second signature in the V2X network (ie between the first communication unit and the second communication unit), the protected data (ie the first V2X information) can be verified ) is denied or forged in the network transmission, so as to ensure the security of network transmission.
  • the second signature processing may include digital signature, adding a token, and the like.
  • the second V2X information obtained through the first signature processing may be transmitted between the first communication unit and the second communication unit, and the third V2X information obtained through the first signature processing and the second signature processing may also be transmitted. information. .
  • FIG. 3c shows an interactive schematic diagram of the data transmission method provided by the embodiment of the present application. This method can be applied to the data transmission system shown in Figure 3a. As shown in Figure 3c, the method may include:
  • Step S401 the first operation unit acquires the first V2X information of the application layer.
  • Step S402 the first operation unit performs first signature processing on the first V2X information to obtain second V2X information including the first V2X information and the first signature.
  • Step S403 the first computing unit sends the second V2X information to the first communication unit.
  • Step S404 the first communication unit receives the second V2X information sent by the first operation unit.
  • Step S405 the first communication unit performs second signature processing on the second V2X information to obtain third V2X information including the second V2X information and the second signature.
  • Step S406 the first communication unit broadcasts the third V2X information.
  • the first computing unit performs the first signature processing on the first V2X information, which can prevent problems such as message corruption and message insertion and provide guarantee for functional security; the first communication unit performs the second signature processing on the second V2X information , which can prevent message denial and message forgery, and provide guarantee for network security.
  • the application layer of the first operation unit obtains the first V2X information, and performs the first signature processing on the first V2X information to obtain the second V2X information.
  • the first operation unit sends the second V2X information to the first communication unit through the Ethernet or other physical bus.
  • the application layer of the first communication unit After acquiring the second V2X information, the application layer of the first communication unit performs the second signature processing on the second V2X information to obtain the third V2X information, and then passes through the transport layer, network layer, access layer, and physical layer, and finally passes through the V2X network (eg DSRC or LTE-V) to other devices (eg the second communication unit).
  • V2X network eg DSRC or LTE-V
  • Step S407 the second communication unit receives the third V2X information sent by the first communication unit.
  • Step S408 the second communication unit verifies the second signature in the third V2X information.
  • step S408 may include: the second communication unit performs information extraction processing on the second V2X information in the third V2X information to obtain the first abstract;
  • the second signature is decrypted to obtain a second digest; if the first digest and the second digest are the same, the second communication unit determines that the verification of the second signature is successful; if the first digest and the second digest are different, the third The second communication unit determines that the verification of the second signature fails.
  • the second communication unit can determine the second signature verification success.
  • the manner in which the second communication unit verifies the second signature may also be other manners agreed upon with the first communication unit, which is not limited in this application.
  • Step S409 in the case that the verification of the second signature is successful, the second communication unit sends the second V2X information in the third V2X information to the second computing unit.
  • Step S410 the second operation unit receives the second V2X information sent by the second communication unit.
  • Step S411 the second operation unit verifies the first signature in the second V2X information.
  • Step S412 in the case that the first signature verification is successful, the second operation unit performs information processing on the first V2X information.
  • the second computing unit may obtain fusion information by performing information processing on the first V2X information, and the second computing unit may send the fusion information to the controller, so that the controller can make motion decision and control based on the fusion information. control.
  • the second communication unit verifies the second signature in the third V2X information, which can prevent message denial and message forgery during network transmission and provide guarantee for network security; the second computing unit verifies the second V2X information.
  • the first signature in the message is verified, which can prevent problems such as message corruption and message insertion, and provide a guarantee for functional safety.
  • the third V2X information reaches the application layer of the second communication unit through the V2X network, the physical layer, the access layer, the network layer, and the transport layer.
  • the application layer of the second communication unit verifies the second signature in the third V2X information. If the verification of the second signature in the third V2X information fails, the second communication unit does not forward the second V2X information in the third V2X information.
  • the second communication unit forwards the second V2X information in the third V2X message through the transport layer, the network layer, the access layer, and the physical layer.
  • the second V2X information reaches the application layer of the second computing unit through the physical layer, the access layer, the network layer, and the transport layer.
  • the application layer of the second operation unit verifies the first signature in the second V2X information. If the verification of the first signature in the second V2X information fails, it indicates that the first V2X information has been changed and is incomplete. In order to ensure functional safety, the second computing unit cannot use the first V2X information for subsequent processing. If the verification of the first signature that can only be performed by the second V2X information is successful, indicating that the first V2X information has not been changed and is complete, the second operation unit may perform subsequent processing based on the first V2X information.
  • the functional safety level requirements of link ASIL-B are decomposed into: QM requirements for transmission channels and ASIL-B requirements for information processing, and the first communication unit and the second communication unit have no functional safety requirements , the first operation unit and the second operation unit can be designed, developed, and verified according to the ISO26262 system to achieve the functional safety of ASIL-B, etc., thereby reducing the functional safety level requirements of the transmission channel.
  • the first signature processing and the first signature verification are performed in the first operation unit and the second operation unit to ensure the functional security (ie integrity) of the V2X information;
  • the second signature processing and the second signature verification performed by the two communication units ensure the network security of the V2X information. Therefore, the embodiment of the present application can improve the reliability of the V2X information without changing and upgrading the hardware of the existing equipment as much as possible. This in turn improves the safety of vehicle motion decision-making and control.
  • FIG. 4a shows a schematic structural diagram of a data transmission system in a V2I scenario provided by an embodiment of the present application.
  • the data transmission system includes a signal machine, a roadside unit, a vehicle-mounted communication unit, a gateway and a vehicle-mounted computing platform.
  • the signal machine corresponds to the first computing unit 11 shown in FIG. 3a
  • the roadside unit corresponds to the first communication unit 12 shown in FIG. 3a
  • the vehicle-mounted communication unit corresponds to the second communication unit 13 shown in FIG. 3a
  • the computing platform corresponds to the second arithmetic unit 14 shown in Fig. 3a.
  • the method shown in Fig. 3c can be applied to the data transmission system shown in Fig. 4a.
  • the application layer of the signal device obtains information such as traffic light signals, and uses the obtained information as the first V2X information.
  • the application layer of the signal machine performs the first signature processing on the first V2X information, and obtains the second V2X information including the first V2X information and the first signature.
  • the second V2X information is transmitted layer by layer (including the transport layer, network layer, access layer, and physical layer) in the signal machine, and finally reaches the physical layer of the roadside unit through Ethernet or other buses. After that, the second V2X information is transmitted layer by layer (including physical layer, access layer, network layer, and transport layer) in the roadside unit to the application layer of the roadside unit.
  • the application layer of the roadside unit performs second signature processing on the second V2X information to obtain third V2X information including the second V2X information and the second signature.
  • the third V2X information is transmitted layer by layer in the roadside unit, and finally sent to the in-vehicle communication unit through a V2X network (eg DSEC or LTE-V).
  • a V2X network eg DSEC or LTE-V.
  • the third V2X information is transmitted layer by layer in the in-vehicle communication unit to the application side of the in-vehicle communication unit. Then, the application layer verifies the second signature against the third V2X information.
  • the in-vehicle communication unit transmits layer by layer, and finally forwards the second V2X information in the third V2X information to the in-vehicle computing platform through the gateway.
  • the application layer of the in-vehicle computing platform receives the second V2X information through layer-by-layer transmission, and then the application layer of the in-vehicle computing platform verifies the first signature in the second V2X information. In the case that the verification of the first signature in the second V2X information is successful, the in-vehicle computing platform performs subsequent processing based on the first V2X information in the second V2X information.
  • FIG. 4b shows a schematic structural diagram of a data transmission system in a V2I scenario provided by an embodiment of the present application.
  • the data transmission system includes an in-vehicle computing platform, a gateway, an in-vehicle communication unit, a roadside unit and a V2X server.
  • the in-vehicle computing platform corresponds to the first computing unit 11 shown in FIG. 3a
  • the in-vehicle communication unit corresponds to the first communication unit 12 shown in FIG. 3a
  • the roadside unit corresponds to the second communication unit 13 shown in FIG. 3a
  • the V2X server corresponds to the second arithmetic unit 14 shown in Fig. 3a.
  • the method shown in Fig. 3c can be applied to the data transmission system shown in Fig. 4b.
  • the application layer of the in-vehicle computing platform obtains information such as decision information, and uses the obtained information as the first V2X information.
  • the application layer of the in-vehicle computing platform performs the first signature processing on the first V2X information to obtain the second V2X information including the first V2X information and the first signature.
  • the second V2X information is transmitted layer by layer on the in-vehicle computing platform, and finally the second V2X information is forwarded to the physical layer of the in-vehicle communication unit through the gateway. After that, the second V2X information is transmitted layer by layer in the in-vehicle communication unit to the application layer of the in-vehicle communication unit.
  • the application layer of the in-vehicle communication unit performs a second signature process on the second V2X information to obtain third V2X information including the second V2X information and the second signature.
  • the third V2X information is transmitted layer by layer in the in-vehicle communication unit, and finally sent to the roadside unit through a V2X network (eg, DSEC or LTE-V).
  • a V2X network eg, DSEC or LTE-V.
  • the third V2X information is transmitted in the roadside unit layer by layer to receive the third V2X information and arrive at the application layer of the roadside unit. Then, the application layer of the RSU verifies the second signature in the third V2X information. In the case that the verification of the second signature in the third V2X information is successful, the roadside unit transmits layer by layer, and finally sends the second V2X information in the third V2X information to the V2X server through Ethernet or other buses.
  • the application layer of the V2X server receives the second V2X information through layer-by-layer transmission, and then the application layer of the V2X server verifies the first signature in the second V2X information. In the case that the verification of the first signature in the second V2X information is successful, the V2X server performs subsequent processing based on the first V2X information in the second V2X information.
  • FIG. 4c shows a schematic structural diagram of a data transmission system in a V2V scenario provided by an embodiment of the present application.
  • the data transmission system includes the vehicle-mounted computing platform of vehicle A, the gateway of vehicle A, the vehicle-mounted communication unit of vehicle A, the vehicle-mounted communication unit of vehicle B, the gateway of vehicle B, and the vehicle-mounted computing platform of vehicle B.
  • the in-vehicle computing platform of vehicle A corresponds to the first computing unit 11 shown in FIG. 3a
  • the in-vehicle communication unit of vehicle A corresponds to the first communication unit 12 shown in FIG. 3a
  • the in-vehicle communication unit of vehicle B corresponds to FIG. 3a
  • the shown second communication unit 13, the on-board computing platform of the vehicle B corresponds to the second computing unit 14 shown in FIG. 3a.
  • the method shown in Fig. 3c can be applied to the data transmission system shown in Fig. 4c.
  • the application layer of the vehicle-mounted computing platform of vehicle A obtains information such as decision information, and uses the obtained information as the first V2X information.
  • the application layer of the in-vehicle computing platform of vehicle A performs the first signature processing on the first V2X information to obtain the second V2X information including the first V2X information and the first signature.
  • the in-vehicle computing platform of vehicle A goes through layers of transmission, and finally forwards the second V2X information to the in-vehicle communication unit of vehicle A through the gateway.
  • the application layer of the in-vehicle communication unit of vehicle A receives the second V2X information through layer-by-layer transmission.
  • the application layer of the in-vehicle communication unit of vehicle A performs second signature processing on the second V2X information to obtain third V2X information including the second V2X information and the second signature.
  • the in-vehicle communication unit of vehicle A transmits layer by layer, and finally sends the third V2X information to the in-vehicle communication unit of vehicle B through a V2X network (eg, DSEC or LTE-V).
  • a V2X network eg, DSEC or LTE-V.
  • the application layer of the in-vehicle communication unit of vehicle B receives the third V2X information through layer-by-layer transmission. Then, the application layer of the in-vehicle communication unit of vehicle B verifies the second signature in the third V2X information. When the verification of the second signature in the third V2X information is successful, the on-board communication unit of vehicle B transmits layer by layer, and finally forwards the second V2X information in the third V2X information to the on-board computing platform of vehicle B through the gateway.
  • the application layer of the vehicle-mounted computing platform of vehicle B receives the second V2X information through layer-by-layer transmission, and then the application layer of the vehicle-mounted computing platform of vehicle B verifies the first signature in the second V2X information. In the case that the verification of the first signature in the second V2X information is successful, the in-vehicle computing platform of vehicle B performs subsequent processing based on the first V2X information in the second V2X information.
  • FIG. 3d shows an interactive schematic diagram of the data transmission method provided by the embodiment of the present application. This method can be applied to the data transmission system shown in Figure 3a. As shown in Figure 3d, the method may include:
  • Step S501 the first operation unit acquires the first V2X information of the application layer.
  • Step S502 the first operation unit performs first signature processing on the first V2X information to obtain second V2X information including the first V2X information and the first signature.
  • the first operation unit may perform first signature processing on the first V2X information by performing digital signature processing on the first V2X information.
  • the root certificate of the national certification authority (Certificate Authority, CA) platform method can be used for digital signature processing, so as to realize the interconnection between vehicles produced by different car companies;
  • the root certificate of the car company's self-check CA platform can be used for Digital signature processing, so that the interconnection between vehicles produced by the same car company can be realized;
  • the root certificate issued by the ecological alliance CA platform can also be used for digital signature processing, so as to realize the interconnection between vehicles produced by car companies under the same ecological alliance Intercommunication.
  • Step S503 the first computing unit sends the second V2X information to the first communication unit through the secure channel with the first communication unit.
  • a secure channel may be established between the first computing unit and the first communication unit.
  • the first computing unit and the first communication unit generate a session key through link session key negotiation, and use the session key to encrypt transmission data, thereby establishing a secure channel.
  • the first computing unit and the first communication unit are respectively configured with a secure communication module, and the secure communication modules at both ends implement encryption and decryption of the transmitted data, thereby realizing the establishment of a secure channel.
  • the embodiments of the present application do not limit the manner of establishing the secure channel, do not limit the encryption/decryption method adopted for the secure channel, and do not limit the key employed for the secure channel.
  • Step S504 the first communication unit receives the second V2X information through the secure channel with the first computing unit.
  • Step S505 the first communication unit broadcasts the second V2X information.
  • the V2X information received by the first communication unit through the secure channel is the V2X information processed by the first signature.
  • the first communication unit does not need to perform the second signature processing on the received V2X information, which can also ensure the function of the application layer V2X information. safety.
  • the first communication unit directly broadcasts the second V2X information, which can reduce the functional requirements for the first communication unit, thereby reducing the cost of the first communication unit.
  • Step S506 the second communication unit receives the second V2X information sent by the first communication unit.
  • Step S507 the second communication unit sends the second V2X information to the second operation unit through the secure channel with the second operation unit.
  • a secure channel may be established between the second communication unit and the second computing unit.
  • the manner of establishing the secure channel between the second communication unit and the second operation unit may refer to the manner of establishing the secure channel between the first operation unit and the first communication unit, which will not be repeated here.
  • the second communication unit can directly forward the received V2X information to the second computing unit through the secure channel, and the second computing unit performs signature verification , on the one hand, the V2X information that has not been verified by the signature can be concentrated into the second computing unit, to prevent the V2X information that has not been verified by the signature from adversely affecting other components in the vehicle, and on the other hand, it can reduce the impact on the second communication unit. functional requirements, thereby reducing the cost of the second communication unit.
  • Step S508 the second computing unit receives the second V2X information through the secure channel with the second communication unit.
  • Step S509 the second operation unit verifies the first signature in the second V2X information.
  • Step S510 in the case that the verification of the first signature is successful, the second operation unit performs information processing on the first V2X information in the second V2X information.
  • the second computing unit may obtain fusion information by performing information processing on the first V2X information, and the second computing unit may send the fusion information to the controller, so that the controller can make motion decision and control based on the fusion information. control.
  • the second communication unit sends the second V2X information to the second computing unit through the secure channel, so that the unverified V2X information can be sent to the dedicated channel and the impact on other components in the data processing device is reduced;
  • the first signature in the second V2X information is verified, which can prevent problems such as message corruption and message insertion, and provide guarantee for functional safety.
  • the functional safety level requirements of link ASIL-B are decomposed into: QM requirements for transmission channels and ASIL-B requirements for information processing, and the first communication unit and the second communication unit have no functional safety requirements , the first operation unit and the second operation unit can be designed, developed, verified according to the ISO26262 system, and can achieve the functional safety of ASIL-B, etc., thereby reducing the functional safety level requirements of the transmission channel.
  • Signature processing, transmitting the second V2X information in the secure channel not only ensures the functional security (that is, the integrity) of the V2X information, but also ensures the network security of the V2X information.
  • the embodiment of the present application simplifies the information transmission process between the first operation unit and the first communication unit and the information transmission process between the second communication unit and the second operation unit, and reduces the need for the first communication unit and the second communication unit. functional requirements, thereby reducing the cost of the first communication unit and the second communication unit.
  • FIG. 4d shows a schematic structural diagram of a data transmission system in a V2V scenario provided by an embodiment of the present application.
  • the data transmission system includes the vehicle-mounted computing platform of vehicle A, the gateway of vehicle A, the vehicle-mounted communication unit of vehicle A, the vehicle-mounted communication unit of vehicle B, the gateway of vehicle B, and the vehicle-mounted computing platform of vehicle B .
  • the in-vehicle computing platform of vehicle A corresponds to the first computing unit 11 shown in FIG. 3a
  • the in-vehicle communication unit of vehicle A corresponds to the first communication unit 12 shown in FIG. 3a
  • the in-vehicle communication unit of vehicle B corresponds to FIG. 3a
  • the shown second communication unit 13, the on-board computing platform of the vehicle B corresponds to the second computing unit 14 shown in FIG. 3a.
  • the method shown in Fig. 3d can be applied to the data transmission system shown in Fig. 4d.
  • a secure channel is established between the vehicle-mounted computing platform of vehicle A and the vehicle-mounted communication unit of vehicle A.
  • the application layer of the in-vehicle computing platform of vehicle A obtains the first V2X information, and performs first signature processing on the first V2X information to obtain V2X information including the first V2X information and the first signature.
  • the in-vehicle computing platform of vehicle A transmits the second V2X information to the in-vehicle communication unit of vehicle A through a pre-established secure channel.
  • the in-vehicle communication unit of vehicle A broadcasts the second V2X information through the V2X network.
  • a secure channel is established between the receiving end: the on-board computing platform of vehicle B and the on-board communication unit of vehicle B.
  • the vehicle-mounted communication unit of vehicle B After receiving the second V2X information, the vehicle-mounted communication unit of vehicle B sends the second V2X information to the vehicle-mounted computing platform of vehicle B through the pre-established security channel.
  • the application layer of the in-vehicle computing platform of vehicle B verifies the first signature in the second V2X information. In the case that the verification of the first signature is successful, the in-vehicle computing platform of vehicle B may perform subsequent processing based on the first V2X information in the second V2X information.
  • FIG. 5 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
  • the apparatus can be used to perform the method shown in Figure 3c.
  • the data processing apparatus 50 may include: an operation unit 51 and a communication unit 52, wherein the operation unit 51 includes a first signature module 511 and a first sending module 512, and the communication unit 52 includes a second signature module 521 and The second sending module 522 .
  • the first signature module 511 is configured to perform first signature processing on the first V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
  • the first sending module 512 is configured to send the second V2X information obtained by the first signature module 511 to the second signature module;
  • the second signature module 521 is configured to perform second signature processing on the second V2X information sent by the first sending module 512 to obtain third V2X information, where the third V2X information includes the second V2X information and second signature;
  • the second sending module 522 is configured to send the third V2X information obtained by the second signature module 521 .
  • the computing unit performs the first signature processing on the V2X information of the application layer, so that when the computing unit meets the functional safety level requirements, the functional security of the V2X information of the application layer can be guaranteed.
  • the communication unit performs the second signature processing on the V2X information that has undergone the first signature processing, thus ensuring the application Layer V2X information security during network transmission. Therefore, in the embodiments of the present application, the reliability of V2X information can be improved, and the safety of vehicle motion decision-making and control can be improved without changing and upgrading existing equipment hardware as much as possible.
  • the first signature processing includes one or more of: information extraction, cyclic redundancy CRC check and digital signature, wherein the digital signature includes issuance based on a national certification authority platform The digital signature of the root certificate, or the digital signature based on the root certificate of the car company's self-inspection certification agency platform, or the digital signature based on the root certificate issued by the ecological alliance certification agency platform.
  • the data processing apparatus is a vehicle-mounted device
  • the computing unit includes a mobile data center MDC
  • the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device
  • the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • the first sending module is further configured to: send the second V2X information to the second signature module through Ethernet.
  • FIG. 6 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
  • the apparatus can be used to perform the method shown in Figure 3d.
  • the data processing device 60 includes an operation unit 61 and a communication unit 62 , the operation unit 61 is connected with the communication unit 62 through a secure channel 63 , and the operation unit 61 includes a first signature module 611 and a first signature module 611 .
  • a sending module 612 , the communication unit 62 includes a second sending module 621 .
  • the first signature module 611 is configured to perform first signature processing on the first V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
  • the first sending module 612 configured to send the second V2X information to the second sending module 621 through the secure channel 63;
  • the second sending module 621 is configured to send the second V2X information.
  • the signature processing process of the second V2X information by the communication unit can be omitted, thereby reducing the complexity of the first communication unit. Functional requirements, reducing the cost of the first communication unit.
  • the first signature processing includes one or more of: information extraction, cyclic redundancy CRC check and digital signature, wherein the digital signature includes issuance based on a national certification authority platform The digital signature of the root certificate, or the digital signature based on the root certificate of the car company's self-inspection certification agency platform, or the digital signature based on the root certificate issued by the ecological alliance certification agency platform.
  • the data processing apparatus is a vehicle-mounted device
  • the computing unit includes a mobile data center MDC
  • the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device
  • the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • FIG. 7 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
  • the apparatus can be used to perform the method shown in Figure 3c.
  • the data processing device 70 includes a communication unit 71 and an operation unit 72
  • the communication unit 71 includes a receiving module 711 , a first signature verification module 712 and a sending module 713
  • the operation unit 72 includes a second verification module 713 .
  • the receiving module 711 is configured to receive third V2X information, where the third IoV V2X information includes second V2X information and a second signature, and the second V2X information includes first V2X information and a first signature at the application layer ;
  • the first signature verification module 712 is configured to verify the second signature in the third V2X information received by the receiving module 711;
  • the sending module 713 is configured to send the second V2X information to the second signature verification module 721 when the first signature verification module 712 successfully verifies the second signature;
  • the second signature verification module 721 is configured to verify the first signature in the second V2X information sent by the sending module 713;
  • the processing module 722 is configured to perform information processing on the first V2X information when the second signature verification module 721 successfully verifies the first signature.
  • the second communication unit can directly forward the received V2X information to the second computing unit through the secure channel, and the second computing unit performs signature verification.
  • V2X information without signature verification can be prevented from adversely affecting other components in the vehicle, and on the other hand, the functional requirements of the second communication unit can be reduced, thereby reducing the cost of the second communication unit.
  • the second operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide guarantee for functional safety.
  • the first signature verification module is also used for:
  • the second signature verification module is also used for:
  • the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, or , based on the digital signature verification of the root certificate of the car company's self-inspection certification agency platform, or, based on the digital signature verification of the root certificate issued by the ecological alliance certification agency platform.
  • the data processing apparatus is a vehicle-mounted device
  • the computing unit includes a mobile data center MDC
  • the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device
  • the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • the sending module is further configured to: send the second V2X information to the second signature through Ethernet when the first signature verification module successfully verifies the second signature Second signature verification module.
  • FIG. 8 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
  • the apparatus can be used to perform the method shown in Figure 3d.
  • the data processing device 80 includes a communication unit 81 and an operation unit 82 , the communication unit 81 and the operation unit 82 are connected through a secure channel 83 , and the communication unit 81 includes a receiving module 811 and a sending module 812, the operation unit 82 includes a signature verification module 821 and a processing module 822;
  • the receiving module 811 is configured to receive second V2X information, where the second V2X information includes the first V2X information and the first signature of the application layer;
  • the sending module 812 is configured to send the second V2X information received by the receiving module 811 to the signature verification module 821 through the secure channel 83;
  • the signature verification module 821 is configured to verify the first signature in the second V2X information sent by the sending module 812;
  • the processing module 822 is configured to perform information processing on the first V2X information when the signature verification module 821 successfully verifies the first signature.
  • the communication unit sends the second V2X information to the computing unit through the secure channel, so that the unverified V2X information can be sent to the dedicated channel, thereby reducing the impact on other components in the data processing device;
  • the first signature in the message is verified, which can prevent problems such as message corruption and message insertion, and provide a guarantee for functional safety.
  • the signature verification module is also used for:
  • the data processing apparatus is a vehicle-mounted device
  • the computing unit includes a mobile data center MDC
  • the communication unit includes a telematics processor TBox.
  • the data processing apparatus is a roadside device
  • the arithmetic unit includes a signal
  • the communication unit includes a roadside unit RSU.
  • An embodiment of the present application provides a data processing apparatus, including: a processor and a memory for storing instructions executable by the processor; wherein the processor is configured to implement the above method when executing the instructions.
  • Embodiments of the present application provide a non-volatile computer-readable storage medium on which computer program instructions are stored, and when the computer program instructions are executed by a processor, implement the above method.
  • Embodiments of the present application provide a computer program product, including computer-readable codes, or a non-volatile computer-readable storage medium carrying computer-readable codes, when the computer-readable codes are stored in a processor of an electronic device When running in the electronic device, the processor in the electronic device executes the above method.
  • a computer-readable storage medium may be a tangible device that can hold and store instructions for use by the instruction execution device.
  • the computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing.
  • Computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read only memory (ROM), erasable programmable read-only memory (Electrically Programmable Read-Only-Memory, EPROM or flash memory), static random access memory (Static Random-Access Memory, SRAM), portable compact disk read-only memory (Compact Disc Read-Only Memory, CD - ROM), Digital Video Disc (DVD), memory sticks, floppy disks, mechanically encoded devices, such as punch cards or raised structures in grooves on which instructions are stored, and any suitable combination of the foregoing .
  • RAM random access memory
  • ROM read only memory
  • EPROM erasable programmable read-only memory
  • EPROM Errically Programmable Read-Only-Memory
  • SRAM static random access memory
  • portable compact disk read-only memory Compact Disc Read-Only Memory
  • CD - ROM Compact Disc Read-Only Memory
  • DVD Digital Video Disc
  • memory sticks floppy disks
  • Computer readable program instructions or code described herein may be downloaded to various computing/processing devices from a computer readable storage medium, or to an external computer or external storage device over a network such as the Internet, a local area network, a wide area network and/or a wireless network.
  • the network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and/or edge servers.
  • a network adapter card or network interface in each computing/processing device receives computer-readable program instructions from a network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing/processing device .
  • the computer program instructions used to perform the operations of the present application may be assembly instructions, Instruction Set Architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or in one or more source or object code written in any combination of programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages.
  • the computer readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server implement.
  • the remote computer may be connected to the user's computer through any kind of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or, may be connected to an external computer (eg, use an internet service provider to connect via the internet).
  • electronic circuits such as programmable logic circuits, Field-Programmable Gate Arrays (FPGA), or Programmable Logic Arrays (Programmable Logic Arrays), are personalized by utilizing state information of computer-readable program instructions.
  • Logic Array, PLA the electronic circuit can execute computer readable program instructions to implement various aspects of the present application.
  • These computer readable program instructions may be provided to a processor of a general purpose computer, special purpose computer or other programmable data processing apparatus to produce a machine that causes the instructions when executed by the processor of the computer or other programmable data processing apparatus , resulting in means for implementing the functions/acts specified in one or more blocks of the flowchart and/or block diagrams.
  • These computer readable program instructions can also be stored in a computer readable storage medium, these instructions cause the computer, programmable data processing apparatus and/or other equipment to operate in a specific manner, so that the computer readable medium storing the instructions includes An article of manufacture comprising instructions for implementing various aspects of the functions/acts specified in one or more blocks of the flowchart and/or block diagrams.
  • Computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other equipment to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other equipment to produce a computer-implemented process , thereby causing instructions executing on a computer, other programmable data processing apparatus, or other device to implement the functions/acts specified in one or more blocks of the flowcharts and/or block diagrams.
  • each block in the flowchart or block diagrams may represent a module, segment, or portion of instructions, which comprises one or more functions for implementing the specified logical function(s) executable instructions.
  • the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved.
  • each block of the block diagrams and/or flowchart illustrations, and combinations of blocks in the block diagrams and/or flowchart illustrations can be implemented in hardware (eg, circuits or ASICs (Application) that perform the corresponding functions or actions. Specific Integrated Circuit, application-specific integrated circuit)), or can be implemented by a combination of hardware and software, such as firmware.

Abstract

The present application relates to a data transmission method and a data processing apparatus. The method comprises: in a data processing apparatus at a sending end: an arithmetic unit performs first signature processing on first V2X information of an application layer to obtain second V2X information comprising the first V2X information and a first signature; a communication unit performs second signature processing on the second V2X information to obtain third V2X information comprising the second V2X information and a second signature; after that, the communication unit sends the third V2X information; and in the data processing apparatus at a receiving end: a communication unit receives the third V2X information and verifies the second signature thereof; when the second signature is successfully verified, the arithmetic unit verifies the first signature; and when the first signature is successfully verified, the arithmetic unit performs information processing on the first V2X information. The data transmission method and data processing apparatus provided by the present application are able to improve the reliability of V2X information.

Description

数据传输方法及数据处理装置Data transmission method and data processing device
本申请要求于2021年04月16日提交中国专利局、申请号为202110412576.9、申请名称为“数据传输方法及数据处理装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims the priority of the Chinese patent application with the application number 202110412576.9 and the application name "Data Transmission Method and Data Processing Device" filed with the China Patent Office on April 16, 2021, the entire contents of which are incorporated into this application by reference .
技术领域technical field
本申请涉及通信领域,尤其涉及一种数据传输方法及数据处理装置。The present application relates to the field of communications, and in particular, to a data transmission method and a data processing device.
背景技术Background technique
随着社会发展,人们对车辆的需求量逐年增加。车辆在给人们提供出行方便的同时,也带来了交通拥堵和交通事故频发等问题。基于此,车联网(Vehicle to Everything,V2X)技术应运而生。车辆可以通过车辆与车辆之间(Vehicle to Vehicle,V2V)通信或者车辆与路边基础设施(Vehicle to Infrastructure,V2I)通信来及时获取道路交通信息、安全预警信息等,从而在一定程度上提高通行效率、降低交通安全风险。With the development of society, people's demand for vehicles increases year by year. While vehicles provide people with convenience, they also bring about problems such as traffic congestion and frequent traffic accidents. Based on this, Vehicle to Everything (V2X) technology came into being. Vehicles can obtain road traffic information, safety warning information, etc. in time through vehicle-to-vehicle (V2V) communication or vehicle-to-vehicle (V2I) communication, thereby improving traffic flow to a certain extent. efficiency and reduce traffic safety risks.
随着车联网技术的发展,车辆从支持低自动驾驶等级逐渐朝着高自动驾驶等级发展,车联网技术的应用也逐渐从基础安全预警应用和交通效率应用,向着协同控制等方向发展。车辆中的安全预警应用和交通效率应用不参与车辆的运动决策和控制,因此,需要具备的安全等级的要求为与安全管理无关的质量管理(Quality Management,QM)。协同控制类应用由于涉及了车辆运动决策和控制,因此,需要具备更高的可靠性和功能安全的等级要求,例如需要达到汽车安全完整性等级(Automotive Safety Integration Level,ASIL)的B级或者以上(例如C级或者D级)。With the development of the Internet of Vehicles technology, vehicles gradually develop from supporting low automatic driving levels to high automatic driving levels, and the application of Internet of Vehicles technology has gradually developed from basic safety early warning applications and traffic efficiency applications to collaborative control and other directions. The safety warning application and the traffic efficiency application in the vehicle do not participate in the motion decision-making and control of the vehicle. Therefore, the requirement of the required safety level is Quality Management (QM) which is not related to safety management. Since collaborative control applications involve vehicle motion decision-making and control, higher reliability and functional safety requirements are required, such as the need to reach the Automotive Safety Integration Level (ASIL) level B or above. (eg C or D).
目前,在V2X通信系统中,无论是路侧设备还是车载设备均未达到ASIL的B级(即ASIL-B)。V2X信息在以上路侧设备或者车载设备中传输后,不能成为自动驾驶系统(Auto Driving System,ADS)或者自动驾驶辅助系统(Auto Driving Assistance System,ADAS)中车辆运动决策和控制的有效且可靠的输入。At present, in the V2X communication system, neither the roadside equipment nor the in-vehicle equipment has reached the ASIL level B (ie ASIL-B). After the V2X information is transmitted in the above roadside equipment or in-vehicle equipment, it cannot become an effective and reliable tool for vehicle motion decision-making and control in the Auto Driving System (ADS) or Auto Driving Assistance System (ADAS). enter.
发明内容SUMMARY OF THE INVENTION
有鉴于此,提出了一种数据传输方法及数据处理装置,在尽量不对现有设备硬件改造升级的情况下,提升了V2X信息的可靠性,进而提升了车辆运动决策和控制的安全性。In view of this, a data transmission method and data processing device are proposed, which can improve the reliability of V2X information and improve the safety of vehicle motion decision-making and control without upgrading and upgrading existing equipment hardware as much as possible.
第一方面,本申请的实施例提供了一种数据传输方法,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:所述运算单元对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;所述运算单元将所述第二V2X信息发送至所述通信单元;所述通信单元对所述第二V2X信息进行第二签名处理,得到第三V2X信息,所述第三V2X信息包括所述第二V2X信息和第二签名;所述通信单元发送所述第三V2X信息。In a first aspect, an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the arithmetic unit communicates with an application layer The first V2X information of the Internet of Vehicles is processed by the first signature, and the second V2X information is obtained, and the second V2X information includes the first V2X information and the first signature; the computing unit sends the second V2X information to the communication unit; the communication unit performs a second signature process on the second V2X information to obtain third V2X information, where the third V2X information includes the second V2X information and a second signature; the communication unit The third V2X information is sent.
在本申请实施例中,在运算单元对应用层的V2X信息进行第一签名处理,这样在运算单元达到功能安全等级要求的情况下,即可保证应用层V2X信息的功能安全性,对通信单元无 功能安全需求,且降低了对运算单元和通信单元之间的传输通道的功能安全等级要求;然后,在通信单元对经过第一签名处理的V2X信息进行第二签名处理,这样,保证了应用层V2X信息在网络传输过程中的安全性。因此,本申请实施例,可以在尽量不对现有设备硬件改造升级的情况下,提升V2X信息的可靠性,进而提升车辆运动决策和控制的安全性。In the embodiment of the present application, the computing unit performs the first signature processing on the V2X information of the application layer, so that when the computing unit meets the functional safety level requirements, the functional security of the V2X information of the application layer can be guaranteed. There is no functional safety requirement, and the functional safety level requirements for the transmission channel between the computing unit and the communication unit are reduced; then, the communication unit performs the second signature processing on the V2X information that has undergone the first signature processing, thus ensuring the application Layer V2X information security during network transmission. Therefore, in the embodiments of the present application, the reliability of V2X information can be improved, and the safety of vehicle motion decision-making and control can be improved without changing and upgrading existing equipment hardware as much as possible.
根据第一方面,在所述数据传输方法的第一种可能的实现方式中,所述第一签名处理包括:信息摘录、循环冗余CRC校验和数字签名中的一者或多者,其中,所述数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。According to the first aspect, in a first possible implementation manner of the data transmission method, the first signature processing includes: one or more of an information excerpt, a cyclic redundancy CRC check, and a digital signature, wherein , the digital signature includes a digital signature based on a root certificate issued by a national certification agency platform, or a digital signature based on a root certificate issued by a car company self-inspection certification agency platform, or a digital signature based on the root certificate issued by the ecological alliance certification agency platform .
这样,有利于及时发现第一V2X信息是否存在消息腐败或者消息插入的情况,为功能安全性提供了保障。In this way, it is helpful to find out in time whether there is message corruption or message insertion in the first V2X information, which provides a guarantee for functional safety.
根据第一方面,或者第一方面的第一种可能的实现方式中,在所述数据传输方法的第二种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the first aspect, or in the first possible implementation manner of the first aspect, in the second possible implementation manner of the data transmission method, the data processing apparatus is a vehicle-mounted device, and the arithmetic unit includes a mobile The data center MDC, the communication unit includes a telematics processor TBox.
这样,可以提高车辆向V2X网络中其他设备提供的V2X信息的可靠性。In this way, the reliability of the V2X information provided by the vehicle to other devices in the V2X network can be improved.
根据第一方面,或者第一方面的第一种可能的实现方式,在所述数据传输方法的第三种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the first aspect, or the first possible implementation manner of the first aspect, in a third possible implementation manner of the data transmission method, the data processing apparatus is a roadside device, and the arithmetic unit includes a signal The communication unit includes a roadside unit RSU.
这样,可以提高路侧设备向车辆提供的V2X信息的可靠性,进而有利于提升车辆运动决策和控制的安全性。In this way, the reliability of the V2X information provided by the roadside equipment to the vehicle can be improved, thereby helping to improve the safety of vehicle motion decision-making and control.
根据第一方面,或者以上第一方面的任意一种可能的实现方式,在所述数据传输方法的第四种可能的实现方式中,所述运算单元将所述第二V2X信息发送至所述通信单元包括:所述运算单元通过以太网将所述第二V2X信息发送至所述通信单元。According to the first aspect, or any one possible implementation manner of the above first aspect, in a fourth possible implementation manner of the data transmission method, the computing unit sends the second V2X information to the The communication unit includes: the operation unit sends the second V2X information to the communication unit through Ethernet.
这样,通过以太网实现运算单元和通信单元之间V2X信息的传输,可以提高传输效率、简化信息结构,降低成本。In this way, the transmission of V2X information between the computing unit and the communication unit is realized through the Ethernet, which can improve the transmission efficiency, simplify the information structure, and reduce the cost.
第二方面,本申请的实施例提供了一种数据传输方法,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:所述运算单元对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;所述运算单元通过与所述通信单元之间的安全通道将所述第二V2X信息发送至所述通信单元;所述通信单元发送所述第二V2X信息。In a second aspect, an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the arithmetic unit communicates with an application layer The first V2X information of the Internet of Vehicles is processed by the first signature, and the second V2X information is obtained, and the second V2X information includes the first V2X information and the first signature; the computing unit communicates with the communication unit through the The secure channel sends the second V2X information to the communication unit; the communication unit sends the second V2X information.
在本申请实施例中,通过在运算单元和通信单元之间的安全通道中传输第二V2X信息,可以省去通信单元对第二V2X信息的签名处理过程,从而降低了对第一通信单元的功能要求,降低了第一通信单元的成本。In the embodiment of the present application, by transmitting the second V2X information in the secure channel between the computing unit and the communication unit, the signature processing process of the second V2X information by the communication unit can be omitted, thereby reducing the complexity of the first communication unit. Functional requirements, reducing the cost of the first communication unit.
根据第二方面,在所述数据传输方法的第一种可能的实现方式中,所述述第一签名处理包括:基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。According to the second aspect, in a first possible implementation manner of the data transmission method, the first signature processing includes: a digital signature based on a root certificate issued by a platform of a national certification authority, or based on a self-inspection by a car company The digital signature of the root certificate of the certification authority platform, or the digital signature based on the root certificate issued by the certification authority platform of the Ecological Alliance.
根据第二方面,或者第二方面的第一种可能的实现方式,在所述数据传输方法的第二种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the second aspect, or the first possible implementation manner of the second aspect, in the second possible implementation manner of the data transmission method, the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data The central MDC, the communication unit includes a telematics processor TBox.
根据第二方面,或者第二方面的第一种可能的实现方式,在所述数据传输方法的第三种 可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the second aspect, or the first possible implementation manner of the second aspect, in a third possible implementation manner of the data transmission method, the data processing apparatus is a roadside device, and the arithmetic unit includes a signal The communication unit includes a roadside unit RSU.
第三方面,本申请的实施例提供了一种数据传输方法,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:所述通信单元接收第三车联网V2X信息,所述第三V2X信息包括第二V2X信息和第二签名,所述第二V2X信息包括应用层的第一V2X信息和第一签名;所述通信单元对所述第二签名进行验证;在所述第二签名验证成功的情况下,所述通信单元将第二V2X信息发送至所述运算单元;所述运算单元对所述第一签名进行验证;在所述第一签名验证成功的情况下,所述运算单元对所述第一V2X信息进行信息处理。In a third aspect, an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the communication unit receives a third Internet of Vehicles V2X information, the third V2X information includes second V2X information and a second signature, and the second V2X information includes the first V2X information and first signature of the application layer; the communication unit writes the second signature to the verifying; in the case that the verification of the second signature is successful, the communication unit sends the second V2X information to the computing unit; the computing unit verifies the first signature; If the verification is successful, the operation unit performs information processing on the first V2X information.
在本申请实施例中,第二通信单元可以将接收到的V2X信息直接通过安全通道转发至第二运算单元,由第二运算单元进行签名验证,这样一方面可以将未经过签名验证的V2X信息集中到第二运算单元中,防止没有经过签名验证的V2X信息对车辆中的其他部件造成不利影响,另一方面可以降低对第二通信单元的功能要求,从而降低第二通信单元的成本。同时,第二运算单元对第二V2X信息中的第一签名进行验证,可防消息腐败和消息插入等问题,为功能安全性提供保障。In this embodiment of the present application, the second communication unit can directly forward the received V2X information to the second computing unit through the secure channel, and the second computing unit performs signature verification. Centralized in the second computing unit, V2X information without signature verification can be prevented from adversely affecting other components in the vehicle, and on the other hand, the functional requirements of the second communication unit can be reduced, thereby reducing the cost of the second communication unit. At the same time, the second operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide guarantee for functional safety.
根据第三方面,在所述数据传输方法的第一种可能的实现方式中,所述通信单元对所述第二签名进行验证包括:所述通信单元对所述第二V2X信息进行信息摘录处理,得到第一摘要;所述通信单元对所述第二签名进行解密处理,得到第二摘要;在所述第一摘要和所述第二摘要相同的情况下,所述通信单元确定所述第二签名验证成功。According to a third aspect, in a first possible implementation manner of the data transmission method, the verification by the communication unit of the second signature includes: the communication unit performs information extraction processing on the second V2X information , to obtain a first digest; the communication unit decrypts the second signature to obtain a second digest; in the case that the first digest and the second digest are the same, the communication unit determines that the first digest is the same as the second digest. Second signature verification succeeded.
根据第三方面,或者第三方面的第一种可能的实现方式,在所述数据传输方法的第二种可能的实现方式中,所述运算单元对所述第一签名进行验证包括:所述运算单元对所述第一签名进行信息摘录校验,或者进行循环冗余CRC校验,或者进行数字签名验证,其中,所述数字签名验证包括基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。According to the third aspect, or the first possible implementation manner of the third aspect, in a second possible implementation manner of the data transmission method, the operation unit verifying the first signature includes: the The arithmetic unit performs information extraction verification on the first signature, or performs cyclic redundancy CRC verification, or performs digital signature verification, wherein the digital signature verification includes digital signature verification based on the root certificate issued by the national certification authority platform. , or, based on the digital signature verification of the root certificate of the car company's self-inspection certification agency platform, or, based on the digital signature verification of the root certificate issued by the ecological alliance certification agency platform.
根据第三方面,或者第三方面的第一种可能的实现方式或者第二种可能的实现方式,在所述数据传输方法的第三种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the third aspect, or the first possible implementation manner or the second possible implementation manner of the third aspect, in the third possible implementation manner of the data transmission method, the data processing apparatus is a vehicle-mounted device , the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
根据第三方面,或者第三方面的第一种可能的实现方式或者第二种可能的实现方式,在所述数据传输方法的第四种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the third aspect, or the first possible implementation manner or the second possible implementation manner of the third aspect, in the fourth possible implementation manner of the data transmission method, the data processing apparatus is a roadside equipment, the arithmetic unit includes a signal, and the communication unit includes a roadside unit RSU.
根据第三方面,或者以上第三方面的任意一种可能的实现方式,在所述数据传输方法的第五种可能的实现方式中,在所述第二签名验证成功的情况下,所述通信单元将第二V2X信息发送至所述运算单元包括:在所述第二签名验证成功的情况下,所述通信单元通过以太网将第二V2X信息发送至所述运算单元。According to the third aspect, or any one possible implementation manner of the above third aspect, in a fifth possible implementation manner of the data transmission method, in the case that the verification of the second signature is successful, the communication The unit sending the second V2X information to the operation unit includes: in the case that the verification of the second signature is successful, the communication unit sends the second V2X information to the operation unit through the Ethernet.
第四方面,本申请的实施例提供了一种数据传输方法,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:所述通信单元接收第二车联网V2X信息,所述第二V2X信息包括应用层的第一V2X信息和第一签名;所述通信单元通过与所述运算单元之间的安全通道,将所述第二V2X信息发送至所述运算单元;所述运算单元对 所述第一签名进行验证;在所述第一签名验证成功的情况下,所述运算单元对所述第一V2X信息进行信息处理。In a fourth aspect, an embodiment of the present application provides a data transmission method, the method is applied to a data processing apparatus, the data processing apparatus includes an arithmetic unit and a communication unit, and the method includes: the communication unit receives a second Internet of Vehicles V2X information, the second V2X information includes the first V2X information and the first signature of the application layer; the communication unit sends the second V2X information to the The operation unit; the operation unit verifies the first signature; in the case that the first signature is successfully verified, the operation unit performs information processing on the first V2X information.
在本申请实施例中,通信单元通过安全通道向运算单元发送第二V2X信息,可以使未经验证的V2X信息走专用通道,降低对数据处理装置中其他部件的影响;运算单元对第二V2X信息中的第一签名进行验证,可防消息腐败和消息插入等问题,为功能安全性提供保障。In the embodiment of the present application, the communication unit sends the second V2X information to the computing unit through the secure channel, so that the unverified V2X information can be sent to the dedicated channel, thereby reducing the impact on other components in the data processing device; The first signature in the message is verified, which can prevent problems such as message corruption and message insertion, and provide a guarantee for functional safety.
根据第四方面,在所述数据传输方法的第一种可能的实现方式中,所述第一签名对所述第一签名进行验证包括:所述运算单元对所述第一签名进行基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。According to a fourth aspect, in a first possible implementation manner of the data transmission method, the verifying the first signature by the first signature includes: performing, by the computing unit, country-based authentication on the first signature The digital signature verification of the root certificate issued by the agency platform, or the digital signature verification based on the root certificate of the car company's self-inspection certification agency platform, or the digital signature verification based on the root certificate issued by the ecological alliance certification agency platform.
根据第四方面,或者第四方面的第一种可能的实现方式,在所述数据传输方法的第二种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the fourth aspect, or the first possible implementation manner of the fourth aspect, in the second possible implementation manner of the data transmission method, the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data The central MDC, the communication unit includes a telematics processor TBox.
根据第四方面,或者第四方面的第一种可能的实现方式,在所述数据传输方法的第三种可能的实现方式中,所述数据处理处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the fourth aspect, or the first possible implementation manner of the fourth aspect, in a third possible implementation manner of the data transmission method, the data processing apparatus is a roadside device, and the arithmetic unit includes Signal, the communication unit includes a roadside unit RSU.
第五方面,本申请的实施例提供了一种数据处理装置,所述数据处理装置包括运算单元和通信单元,所述运算单元包括第一签名模块和第一发送模块,所述通信单元包括第二签名模块和第二发送模块;In a fifth aspect, an embodiment of the present application provides a data processing device, the data processing device includes an operation unit and a communication unit, the operation unit includes a first signature module and a first sending module, and the communication unit includes a first signature module and a first sending module. Two signature modules and a second sending module;
所述第一签名模块,用于对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The first signature module is configured to perform first signature processing on the first V2X information of the Internet of Vehicles at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
所述第一发送模块,用于将所述第一签名模块获得的第二V2X信息发送至所述第二签名模块;the first sending module, configured to send the second V2X information obtained by the first signature module to the second signature module;
所述第二签名模块,用于对所述第一发送模块发送的第二V2X信息进行第二签名处理,得到第三V2X信息,所述第三V2X信息包括所述第二V2X信息和第二签名;The second signature module is configured to perform second signature processing on the second V2X information sent by the first sending module to obtain third V2X information, where the third V2X information includes the second V2X information and the second V2X information. sign;
所述第二发送模块,用于发送所述第二签名模块获得的第三V2X信息。The second sending module is configured to send the third V2X information obtained by the second signature module.
根据第五方面,在所述数据处理装置的第一种可能的实现方式中,所述第一签名处理包括:信息摘录、循环冗余CRC校验和数字签名中的一者或多者,其中,所述数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。According to a fifth aspect, in a first possible implementation manner of the data processing apparatus, the first signature processing includes: one or more of information extraction, cyclic redundancy CRC check and digital signature, wherein , the digital signature includes a digital signature based on a root certificate issued by a national certification agency platform, or a digital signature based on a root certificate issued by a car company self-inspection certification agency platform, or a digital signature based on the root certificate issued by the ecological alliance certification agency platform .
根据第五方面,或者第五方面的第一种可能的实现方式,在所述数据处理装置的第二种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the fifth aspect, or the first possible implementation manner of the fifth aspect, in a second possible implementation manner of the data processing apparatus, the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data The central MDC, the communication unit includes a telematics processor TBox.
根据第五方面,或者第五方面的第一种可能的实现方式,在所述数据处理装置的第三种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the fifth aspect, or the first possible implementation manner of the fifth aspect, in a third possible implementation manner of the data processing apparatus, the data processing apparatus is a roadside device, and the arithmetic unit includes a signal The communication unit includes a roadside unit RSU.
根据第五方面,或者以上第五方面的任意一种可能的实现方式,在所述数据处理装置的第五种可能的实现方式中,所述第一发送模块还用于通过以太网将所述第二V2X信息发送至所述第二签名模块。According to the fifth aspect, or any one possible implementation manner of the above fifth aspect, in a fifth possible implementation manner of the data processing apparatus, the first sending module is further configured to send the The second V2X information is sent to the second signature module.
第六方面,本申请的实施例提供了一种数据处理装置,所述数据处理装置包括运算单元 和通信单元,所述运算单元与所述通信单元通过安全通道连接,所述运算单元包括第一签名模块和第一发送模块,所述通信单元包括第二发送模块;In a sixth aspect, an embodiment of the present application provides a data processing device, the data processing device includes an operation unit and a communication unit, the operation unit is connected to the communication unit through a secure channel, and the operation unit includes a first a signature module and a first sending module, the communication unit includes a second sending module;
所述第一签名模块,用于对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The first signature module is configured to perform first signature processing on the first V2X information of the Internet of Vehicles at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
所述第一发送模块,用于通过所述安全通道将所述第二V2X信息发送至所述第二发送模块;the first sending module, configured to send the second V2X information to the second sending module through the secure channel;
所述第二发送模块,用于发送所述第二V2X信息。The second sending module is configured to send the second V2X information.
根据第六方面,在所述数据处理装置的第一种可能的实现方式中,所述第一签名处理包括:信息摘录、循环冗余CRC校验和数字签名中的一者或多者,其中,所述数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。According to a sixth aspect, in a first possible implementation manner of the data processing apparatus, the first signature processing includes: one or more of an information excerpt, a cyclic redundancy CRC check, and a digital signature, wherein , the digital signature includes a digital signature based on a root certificate issued by a national certification agency platform, or a digital signature based on a root certificate issued by a car company self-inspection certification agency platform, or a digital signature based on the root certificate issued by the ecological alliance certification agency platform .
根据第六方面,或者第六方面的第一种可能的实现方式,在所述数据处理装置的第二种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the sixth aspect, or the first possible implementation manner of the sixth aspect, in a second possible implementation manner of the data processing apparatus, the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data The central MDC, the communication unit includes a telematics processor TBox.
根据第六方面,或者第六方面的第一种可能的实现方式,在所述数据处理装置的第三种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the sixth aspect, or the first possible implementation manner of the sixth aspect, in a third possible implementation manner of the data processing apparatus, the data processing apparatus is a roadside device, and the arithmetic unit includes a signal The communication unit includes a roadside unit RSU.
第七方面,本申请的实施例提供了一种数据处理装置,所述数据处理装置包括运算单元和通信单元,所述通信单元包括接收模块、第一验签模块和发送模块,所述运算单元包括第二验签模块和处理模块;In a seventh aspect, an embodiment of the present application provides a data processing device, the data processing device includes an arithmetic unit and a communication unit, the communication unit includes a receiving module, a first signature verification module and a sending module, the arithmetic unit Including a second signature verification module and a processing module;
所述接收模块,用于接收第三车联网V2X信息,所述第三车联网V2X信息包括第二V2X信息和第二签名,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The receiving module is configured to receive the third V2X information of the Internet of Vehicles, the third V2X information of the Internet of Vehicles includes the second V2X information and the second signature, and the second V2X information includes the first V2X information and the first V2X information of the application layer. sign;
所述第一验签模块,用于对所述接收模块接收的第三V2X信息中的第二签名进行验证;the first signature verification module, configured to verify the second signature in the third V2X information received by the receiving module;
所述发送模块,用于在所述第一验签模块对第二签名验证成功的情况下,将所述第二V2X信息发送至所述第二验签模块;the sending module, configured to send the second V2X information to the second signature verification module when the first signature verification module successfully verifies the second signature;
所述第二验签模块,用于对所述发送模块发送的第二V2X信息中的第一签名进行验证;the second signature verification module, configured to verify the first signature in the second V2X information sent by the sending module;
所述处理模块,用于在所述第二验签模块对第一签名验证成功的情况下,对所述第一V2X信息进行信息处理。The processing module is configured to perform information processing on the first V2X information when the second signature verification module successfully verifies the first signature.
根据第七方面,在所述数据处理装置的第一种可能的实现方式中,所述第一验签模块还用于:According to the seventh aspect, in a first possible implementation manner of the data processing device, the first signature verification module is further configured to:
对所述第二V2X信息进行信息摘录处理,得到第一摘要;performing information extraction processing on the second V2X information to obtain a first abstract;
对所述第二签名进行解密处理,得到第二摘要;Decrypting the second signature to obtain a second digest;
在所述第一摘要和所述第二摘要相同的情况下,确定所述第二签名验证成功。In the case that the first digest and the second digest are the same, it is determined that the verification of the second signature is successful.
根据第七方面,或者第七方面的第一种可能的实现方式,在所述数据处理装置的第二种可能的实现方式中,所述第二验签模块还用于:According to the seventh aspect, or the first possible implementation manner of the seventh aspect, in the second possible implementation manner of the data processing apparatus, the second signature verification module is further configured to:
对所述第一签名进行信息摘录校验、或者进行循环冗余CRC校验,或者进行数字签名验证,其中,所述数字签名验证包括基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。Performing information extract verification, or performing cyclic redundancy CRC verification, or performing digital signature verification on the first signature, wherein the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, or , based on the digital signature verification of the root certificate of the car company's self-inspection certification agency platform, or, based on the digital signature verification of the root certificate issued by the ecological alliance certification agency platform.
根据第七方面,或者,第七方面的第一种可能的实现方式或者第二种可能的实现方式,在所述数据处理装置的第三种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the seventh aspect, or the first possible implementation manner or the second possible implementation manner of the seventh aspect, in the third possible implementation manner of the data processing apparatus, the data processing apparatus is a vehicle-mounted The device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
根据第七方面,或者,第七方面的第一种可能的实现方式或者第二种可能的实现方式,在所述数据处理装置的第四种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the seventh aspect, or the first possible implementation manner or the second possible implementation manner of the seventh aspect, in the fourth possible implementation manner of the data processing apparatus, the data processing apparatus is a side equipment, the arithmetic unit includes a signal machine, and the communication unit includes a roadside unit RSU.
根据第七方面,或者以上第七方面的任意一种可能的实现方式,在所述数据处理装置的第五种可能的实现方式中,所述发送模块还用于:在所述第一验签模块对第二签名验证成功的情况下,通过以太网将所述第二V2X信息发送至所述第二验签模块。According to the seventh aspect, or any one possible implementation manner of the above seventh aspect, in a fifth possible implementation manner of the data processing apparatus, the sending module is further configured to: in the first signature verification When the module successfully verifies the second signature, it sends the second V2X information to the second signature verification module through Ethernet.
第八方面,本申请的实施例提供了一种数据处理装置,所述数据处理装置包括通信单元和运算单元,所述通信单元和所述运算单元通过安全通道连接,所述通信单元包括接收模块和发送模块,所述运算单元包括验签模块和处理模块;In an eighth aspect, an embodiment of the present application provides a data processing device, the data processing device includes a communication unit and an operation unit, the communication unit and the operation unit are connected through a secure channel, and the communication unit includes a receiving module and a sending module, the arithmetic unit includes a signature verification module and a processing module;
所述接收模块,用于接收第二车联网V2X信息,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The receiving module is configured to receive the second V2X information of the Internet of Vehicles, where the second V2X information includes the first V2X information and the first signature of the application layer;
所述发送模块,用于通过所述安全通道将所述接收模块接收到的第二V2X信息发送至所述验签模块;the sending module, configured to send the second V2X information received by the receiving module to the signature verification module through the secure channel;
所述验签模块,用于对所述发送模块发送的第二V2X信息中的第一签名进行验证;the signature verification module, configured to verify the first signature in the second V2X information sent by the sending module;
所述处理模块,用于在所述验签模块对所述第一签名验证成功的情况下,对所述第一V2X信息进行信息处理。The processing module is configured to perform information processing on the first V2X information when the signature verification module successfully verifies the first signature.
根据第八方面,在所述数据处理装置的第一种可能的实现方式中,所述验签模块还用于:According to the eighth aspect, in a first possible implementation manner of the data processing device, the signature verification module is further configured to:
对所述第一签名进行基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。Perform digital signature verification on the first signature based on the root certificate issued by the national certification authority platform, or based on the digital signature verification of the root certificate of the vehicle enterprise self-inspection certification authority platform, or based on the root certificate issued by the ecological alliance certification authority platform digital signature verification.
根据第八方面,或者第八方面的第一种可能的实现方式,在所述数据处理装置的第二种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。According to the eighth aspect, or the first possible implementation manner of the eighth aspect, in a second possible implementation manner of the data processing apparatus, the data processing apparatus is a vehicle-mounted device, and the computing unit includes mobile data The central MDC, the communication unit includes a telematics processor TBox.
根据第八方面,或者第八方面的第一种可能的实现方式,在所述数据处理装置的第三种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。According to the eighth aspect, or the first possible implementation manner of the eighth aspect, in a third possible implementation manner of the data processing apparatus, the data processing apparatus is a roadside device, and the arithmetic unit includes a signal The communication unit includes a roadside unit RSU.
第九方面,本申请的实施例提供了一种数据处理装置,该数据处理装置可以执行上述第一方面或者第一方面的多种可能的实现方式中的一种或几种的数据传输方法,或者执行上述第二方面或者第二方面的多种可能的实现方式中的一种或几种的数据传输方法,或者执行上述第三方面或者第三方面的多种可能的实现方式中的一种或几种的数据传输方法,或者执行上述第四方面或者第四方面的多种可能的实现方式中的一种或几种的数据传输方法。In a ninth aspect, an embodiment of the present application provides a data processing apparatus, and the data processing apparatus can execute the first aspect or one or more of the data transmission methods in multiple possible implementations of the first aspect, Either execute the above second aspect or one or more of the possible implementations of the second aspect, or execute the third aspect or one of the multiple possible implementations of the third aspect or several data transmission methods, or perform one or more data transmission methods of the fourth aspect or multiple possible implementation manners of the fourth aspect.
第十方面,本申请的实施例提供了一种计算机程序产品,包括计算机可读代码,或者承载有计算机可读代码的计算机可读存储介质,当所述计算机可读代码被处理器执行时实现上述第二方面或者第二方面的多种可能的实现方式中的一种或几种的数据传输方法,或者执行上述第三方面或者第三方面的多种可能的实现方式中的一种或几种的数据传输方法,或者执行上述第四方面或者第四方面的多种可能的实现方式中的一种或几种的数据传输方法。In a tenth aspect, embodiments of the present application provide a computer program product, comprising computer-readable codes, or a computer-readable storage medium carrying computer-readable codes, which are implemented when the computer-readable codes are executed by a processor The data transmission method of the second aspect or one or more of the multiple possible implementations of the second aspect, or to execute one or more of the third aspect or the multiple possible implementations of the third aspect. A data transmission method, or a data transmission method that performs one or more of the fourth aspect or multiple possible implementation manners of the fourth aspect.
本申请的这些和其他方面在以下(多个)实施例的描述中会更加简明易懂。These and other aspects of the present application will be more clearly understood in the following description of the embodiment(s).
附图说明Description of drawings
包含在说明书中并且构成说明书的一部分的附图与说明书一起示出了本申请的示例性实施例、特征和方面,并且用于解释本申请的原理。The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate exemplary embodiments, features and aspects of the application and together with the description, serve to explain the principles of the application.
图1示出本申请实施例提供的V2X通信系统的架构示意图;FIG. 1 shows a schematic diagram of the architecture of a V2X communication system provided by an embodiment of the present application;
图2示出V2X信息在V2I场景下的传输过程示意图;FIG. 2 shows a schematic diagram of a transmission process of V2X information in a V2I scenario;
图3a示出本申请实施例提供的数据传输系统的架构示意图;FIG. 3a shows a schematic diagram of the architecture of a data transmission system provided by an embodiment of the present application;
图3b示出本申请实施例提供的电子设备的结构示意图;FIG. 3b shows a schematic structural diagram of an electronic device provided by an embodiment of the present application;
图3c示出本申请实施例提供的数据传输方法的交互示意图;FIG. 3c shows an interactive schematic diagram of the data transmission method provided by the embodiment of the present application;
图3d示出本申请实施例提供的数据传输方法的交互示意图;FIG. 3d shows an interactive schematic diagram of a data transmission method provided by an embodiment of the present application;
图4a示出本申请实施例提供的V2I场景下数据传输系统的架构示意图;4a shows a schematic diagram of the architecture of a data transmission system in a V2I scenario provided by an embodiment of the present application;
图4b示出本申请实施例提供的V2I场景下数据传输系统的架构示意图;FIG. 4b shows a schematic diagram of the architecture of a data transmission system in a V2I scenario provided by an embodiment of the present application;
图4c示出本申请实施例提供的V2V场景下数据传输系统的架构示意图;4c shows a schematic diagram of the architecture of a data transmission system in a V2V scenario provided by an embodiment of the present application;
图4d示出本申请实施例提供的V2V场景下数据传输系统的架构示意图;4d shows a schematic diagram of the architecture of a data transmission system in a V2V scenario provided by an embodiment of the present application;
图5示出本申请实施例提供的数据处理装置的结构示意图;FIG. 5 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application;
图6示出本申请实施例提供的数据处理装置的结构示意图;FIG. 6 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application;
图7示出本申请实施例提供的数据处理装置的结构示意图;FIG. 7 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application;
图8示出本申请实施例提供的数据处理装置的结构示意图。FIG. 8 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application.
具体实施方式Detailed ways
以下将参考附图详细说明本申请的各种示例性实施例、特征和方面。附图中相同的附图标记表示功能相同或相似的元件。尽管在附图中示出了实施例的各种方面,但是除非特别指出,不必按比例绘制附图。Various exemplary embodiments, features and aspects of the present application will be described in detail below with reference to the accompanying drawings. The same reference numbers in the figures denote elements that have the same or similar functions. While various aspects of the embodiments are shown in the drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.
在这里专用的词“示例性”意为“用作例子、实施例或说明性”。这里作为“示例性”所说明的任何实施例不必解释为优于或好于其它实施例。The word "exemplary" is used exclusively herein to mean "serving as an example, embodiment, or illustration." Any embodiment described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments.
另外,为了更好的说明本申请,在下文的具体实施方式中给出了众多的具体细节。本领域技术人员应当理解,没有某些具体细节,本申请同样可以实施。在一些实例中,对于本领域技术人员熟知的方法、手段、元件和电路未作详细描述,以便于凸显本申请的主旨。In addition, in order to better illustrate the present application, numerous specific details are given in the following detailed description. It should be understood by those skilled in the art that the present application may be practiced without certain specific details. In some instances, methods, means, components and circuits well known to those skilled in the art have not been described in detail so as not to obscure the subject matter of the present application.
车联网(Vehicle to Everything,V2X)通信是指车辆与外界的任何事物之间的通信。图1示出本申请实施例提供的V2X通信系统的架构示意图。如图1所示,V2X通信包括车与车的通信(Vehicle to Vehicle,V2V)、车与行人的通信(Vehicle to Pedestrian,V2P)以及车与基础设施的通信(Vehicle to Infrastructure,V2I)等。在V2X通信系统中,设备之间可以进行直接通信。举例来说,如图1所示,车辆与车辆之间可以直接通信、车辆与路侧单元(Road Side Unit,RSU)之间可以直接通信。在实施中,V2X系统中设备之间可以基于专用短程通信技术(Dedicated Short Range Communication,DSRC)、长期演进-车辆(Long Term Evolution-Vehicle,LTE-V)等通信协议进行直接通信,本申请实施例对V2X通信系统中设备之间的通信协议不做限制。在V2X通信系统中,路侧涉及的设备包括信号机、V2X服 务器、路侧单元等,车侧涉及的设备包括车载通信单元、网关(GateWay,GW)、车载计算平台和控制器等。在一个示例中,车载通信单元可以包括远程信息处理器(Telematics BOX,TBox),车载计算平台可以包括移动数据中心(Mobile Data Center,MDC),控制器可以包括整车控制器(Vehicle Control Unit,VCU)。Vehicle to Everything (V2X) communication refers to the communication between vehicles and anything in the outside world. FIG. 1 shows a schematic structural diagram of a V2X communication system provided by an embodiment of the present application. As shown in Figure 1, V2X communication includes vehicle-to-vehicle communication (Vehicle to Vehicle, V2V), vehicle-to-pedestrian communication (Vehicle to Pedestrian, V2P), and vehicle-to-infrastructure (Vehicle to Infrastructure, V2I) communication. In a V2X communication system, direct communication is possible between devices. For example, as shown in FIG. 1 , there can be direct communication between vehicles and vehicles, and direct communication between vehicles and Road Side Units (RSUs). In implementation, devices in the V2X system can communicate directly based on communication protocols such as Dedicated Short Range Communication (DSRC), Long Term Evolution-Vehicle (LTE-V), etc. This application implements The example does not limit the communication protocol between devices in the V2X communication system. In the V2X communication system, the equipment involved on the roadside includes signal machines, V2X servers, and roadside units, etc., and the equipment involved on the vehicle side includes on-board communication units, gateways (GateWay, GW), on-board computing platforms, and controllers. In one example, the in-vehicle communication unit may include a telematics processor (Telematics BOX, TBox), the in-vehicle computing platform may include a mobile data center (Mobile Data Center, MDC), and the controller may include a vehicle control unit (Vehicle Control Unit, VCU).
功能安全是将电子电气系统失效导致的危害降低到可接受的范围内,其主要目的是保护人身安全。而可靠性是电子电气系统无故障工作的能力,其主要目的是不发生故障,保证可用性。因此,可靠性是“基础”,功能安全是“上层建筑”。本申请实施例提供的数据传输方法涉及的是V2X通信系统的功能安全问题,即提高输入自动驾驶系统(Auto Driving System,ADS)或者自动驾驶辅助系统(Auto Driving Assistance System,ADAS)的V2X信息的可靠性,进而提高车辆运动决策和控制的安全性。Functional safety is to reduce the harm caused by the failure of electrical and electronic systems to an acceptable range, and its main purpose is to protect personal safety. Reliability is the ability of electronic and electrical systems to work without failure, and its main purpose is to ensure availability without failure. Therefore, reliability is the "foundation" and functional safety is the "superstructure". The data transmission method provided in the embodiment of the present application relates to the functional safety of the V2X communication system, that is, to improve the transmission of V2X information input to an automatic driving system (Auto Driving System, ADS) or an automatic driving assistance system (Auto Driving Assistance System, ADAS) reliability, thereby improving the safety of vehicle motion decision-making and control.
本申请实施例提供的数据传输方法可以应用于V2I场景或者V2V场景中。举例来说,在V2I场景下,当车辆行驶在城市道路上,路侧设备将红绿灯信息利用V2X信息发送至车辆,车辆中的车载计算平台可以对路侧设备提供的红绿灯信息以及车内传感器感知到的信息进行融合,从而帮助车辆执行正确的操作。此时,本申请实施例提供的数据传输方法可以用于传输红绿灯信息,提高红绿灯信息的可靠性,进而提高车辆运动决策和控制的安全性。在V2V场景下,前车将加速、制动、变道或者保持现状等决策信息利用V2X信息发送至跟随车辆,并周期性的发送盲点检测系统(Blind Spot Monitoring,BSM)信息和计算机辅助制造(Computer Aided Drafting,CAM)信息。跟随车辆中的车载计算平台可以对决策信息、BSM信息、CAM信息以及车内传感器感知到的信息进行融合,从而帮助跟随车辆执行正确的操作,避免与前车并线行驶时因未看到后方来车而造成车辆剐蹭、碰撞。此时,本申请实施例提供的数据传输方法可以用于传输决策信息、BSM信息和CAM信息,提高决策信息、BSM信息和CAM信息的可靠性,进而提高车辆运动决策和控制的安全性。下面结合图2,以V2X信息在V2I场景下的传输过程为例进行说明。V2X信息在V2V场景中的传输过程可以参照V2X信息在V2I场景中的传输过程,这里不再赘述。The data transmission method provided by the embodiment of the present application may be applied to a V2I scenario or a V2V scenario. For example, in a V2I scenario, when a vehicle is driving on an urban road, the roadside equipment sends traffic light information to the vehicle using V2X information, and the on-board computing platform in the vehicle can perceive the traffic light information provided by the roadside equipment and the in-vehicle sensors. The received information is fused to help the vehicle perform the correct operation. At this time, the data transmission method provided by the embodiments of the present application can be used to transmit traffic light information, improve the reliability of the traffic light information, and further improve the safety of vehicle motion decision-making and control. In the V2V scenario, the vehicle in front will use V2X information to send decision information such as acceleration, braking, lane change or maintaining the status quo to the following vehicle, and periodically send Blind Spot Monitoring (BSM) information and computer-aided manufacturing ( Computer Aided Drafting, CAM) information. The on-board computing platform in the following vehicle can fuse decision-making information, BSM information, CAM information, and information sensed by in-vehicle sensors to help the following vehicle perform correct operations and avoid not seeing the rear when driving in parallel with the preceding vehicle. Vehicles are scratched and collided due to oncoming vehicles. At this time, the data transmission method provided in the embodiment of the present application can be used to transmit decision information, BSM information and CAM information, so as to improve the reliability of decision information, BSM information and CAM information, thereby improving the safety of vehicle motion decision and control. The following describes the transmission process of V2X information in a V2I scenario with reference to FIG. 2 as an example. For the transmission process of V2X information in the V2V scenario, reference may be made to the transmission process of V2X information in the V2I scenario, which will not be repeated here.
图2示出V2X信息在V2I场景下的传输过程示意图。如图2所示,在V2I场景下,交通信号控制系统通过交通专网将红绿灯信息传输到信号机,信号机可以根据接收到的红绿灯信息控制红绿灯的显示,并将接收到的红绿灯信息发送至路侧单元。V2X服务器可以将一些交通管制信息和路况信息发送至路侧单元。这里的红绿灯信息、交通管制信息和路况信息后续将在V2X通信系统中进行传输,需要保证这些信息的安全性。路侧单元负责将接收到的红绿灯信息、交通管制信息和路况信息等V2X信息广播给车辆。车辆中的车载通信单元可以将接收到的红绿灯信息、交通管制信息和路况信息等V2X信息通过网关发送至车载计算平台。车载计算平台根据雷达、摄像头等传感器获得的数据(例如雷达信号、图像等),与接收到的红绿灯信息、交通管制信息和路况信息等V2X信息进行融合,得到融合信息。然后,车载计算平台可以将融合信息发送至控制器,以便于控制器基于融合信息进行车辆的运动决策和控制。在一个示例中,车载计算平台接收到的红绿灯信息是红灯,摄像头拍摄到的也是红灯,则车载计算平台可以得到融合信息为红灯。车载计算平台将融合信息发送至控制器后,控制器根据红灯生成刹车命令,进而控制车辆自动刹车。在又一示例中,车载计算平台接收到的交通管制信息为施工路段最高限速40km/h,摄像头拍摄到的限速牌也为最高限速40km/h,高精地图显示车辆100米后进入施工路段,则车载计算平台可以得到融合信息为速度低于40km/h。 车载计算平台将融合信息发送至控制器后,控制器根据速度低于40km/h确定是否需要控制减速,在需要控制车辆减速的情况下,自动减速。FIG. 2 shows a schematic diagram of a transmission process of V2X information in a V2I scenario. As shown in Figure 2, in the V2I scenario, the traffic signal control system transmits the traffic light information to the signal through the traffic private network, and the signal can control the display of the traffic light according to the received traffic light information, and send the received traffic light information to the roadside unit. The V2X server can send some traffic control information and road condition information to the roadside unit. The traffic light information, traffic control information and road condition information here will be transmitted in the V2X communication system later, and the security of these information needs to be guaranteed. The roadside unit is responsible for broadcasting the received V2X information such as traffic light information, traffic control information and road condition information to the vehicle. The in-vehicle communication unit in the vehicle can send the received V2X information such as traffic light information, traffic control information and road condition information to the in-vehicle computing platform through the gateway. The in-vehicle computing platform fuses the received V2X information such as traffic light information, traffic control information, and road condition information based on the data obtained by sensors such as radar and cameras (such as radar signals, images, etc.) to obtain fusion information. Then, the in-vehicle computing platform can send the fusion information to the controller, so that the controller can make motion decision and control of the vehicle based on the fusion information. In an example, the traffic light information received by the in-vehicle computing platform is a red light, and the red light captured by the camera is also a red light, so the in-vehicle computing platform can obtain the fusion information as a red light. After the in-vehicle computing platform sends the fusion information to the controller, the controller generates a braking command according to the red light, and then controls the vehicle to brake automatically. In another example, the traffic control information received by the on-board computing platform is the maximum speed limit of 40km/h in the construction section, the speed limit sign captured by the camera is also the maximum speed limit of 40km/h, and the high-precision map shows that the vehicle enters after 100 meters. For the construction section, the vehicle-mounted computing platform can obtain the fusion information that the speed is lower than 40km/h. After the in-vehicle computing platform sends the fusion information to the controller, the controller determines whether it is necessary to control the deceleration according to the speed lower than 40km/h, and automatically decelerates when it is necessary to control the deceleration of the vehicle.
参照图2可知,红绿灯信息、交通管制信息和路况信息等V2X信息的传输过程中涉及的设备包括路侧的信号机(或者V2X服务器)和路侧单元,以及车侧的车载通信单元、网关和车载计算平台,红绿灯信息、交通管制信息和路况信息等V2X信息的传输过程中涉及的传输路径包括:信号机(或者V2X服务器)至路侧单元、路侧单元至车载通信单元、车载通信单元至网关,以及网关至车载计算平台。相关技术中,为了保证车载计算平台接收到的V2X信息与信号机(或V2X服务器)提供的V2X信息一致(即车载计算平台接收到的V2X信息达到ASIL-B的功能安全等级),需要V2X信息传输过程中涉及的所有设备的软硬件开发都按照ISO26262体系进行设计、开发和验证并达到ASIL-B的功能安全等级。然而,要求路侧设备(例如信号机、V2X服务器和路侧单元等)都达到ASIL-B的功能安全等级,会造成路侧设备成本大幅提成,且现存的路侧设备无法满足功能安全等级的要求,可行性较低。同时,要求车侧的车载通信单元和网关等设备达到ASIL-B的功能安全等级,会造成车辆成本提升,不利于ADS或者ADAS的发展。Referring to Figure 2, it can be seen that the equipment involved in the transmission of V2X information such as traffic light information, traffic control information, and road condition information includes roadside signals (or V2X servers) and roadside units, as well as vehicle-side on-board communication units, gateways and In-vehicle computing platform, the transmission paths involved in the transmission of V2X information such as traffic light information, traffic control information and road condition information include: signal (or V2X server) to roadside unit, roadside unit to vehicle communication unit, vehicle communication unit to gateway, and gateway to vehicle computing platform. In the related art, in order to ensure that the V2X information received by the in-vehicle computing platform is consistent with the V2X information provided by the signal (or V2X server) (that is, the V2X information received by the in-vehicle computing platform reaches the ASIL-B functional safety level), V2X information is required. The software and hardware development of all equipment involved in the transmission process is designed, developed and verified in accordance with the ISO26262 system and reaches the functional safety level of ASIL-B. However, requiring roadside equipment (such as signals, V2X servers and roadside units, etc.) to reach the functional safety level of ASIL-B will result in a substantial increase in the cost of roadside equipment, and the existing roadside equipment cannot meet the functional safety level. requirements, the feasibility is low. At the same time, it is required that the on-board communication unit and gateway on the vehicle side reach the functional safety level of ASIL-B, which will increase the vehicle cost and is not conducive to the development of ADS or ADAS.
本申请实施例提供的数据传输方法,在尽量不对现有设备硬件改造升级的情况下,提升了V2X信息的可靠性,进而提升了车辆运动决策和控制的安全性。The data transmission method provided by the embodiments of the present application improves the reliability of V2X information, and further improves the safety of vehicle motion decision-making and control, without modifying and upgrading existing equipment hardware as much as possible.
图3a示出本申请实施例提供的数据传输系统的架构示意图。如图3a所示,该数据传输系统包括第一运算单元11、第一通信单元12、第二通信单元13和第二运算单元14。在本申请实施例中,将需要保证可靠性的V2X信息称为第一V2X信息。图3a所示的第一运算单元11用于表示提供第一V2X信息的设备,第一V2X信息来自于第一运算单元11的应用层。第二运算单元14用于表示使用第一V2X信息的设备。保证第一V2X信息的可靠性实质就是使第一运算单元11提供的第一V2X信息,与到达第二运算单元14、供第二运算单元14使用的第一V2X信息一致。第一通信单元12用于发送来自第一运算单元11的V2X信息,第二通信单元13用于接收来自第一通信单元12的V2X信息,以及向第二运算单元14发送V2X信息。FIG. 3 a shows a schematic structural diagram of a data transmission system provided by an embodiment of the present application. As shown in FIG. 3 a , the data transmission system includes a first operation unit 11 , a first communication unit 12 , a second communication unit 13 and a second operation unit 14 . In this embodiment of the present application, the V2X information whose reliability needs to be guaranteed is referred to as the first V2X information. The first operation unit 11 shown in FIG. 3 a is used to represent a device that provides the first V2X information, and the first V2X information comes from the application layer of the first operation unit 11 . The second operation unit 14 is used to represent a device using the first V2X information. The essence of ensuring the reliability of the first V2X information is to make the first V2X information provided by the first operation unit 11 consistent with the first V2X information that reaches the second operation unit 14 and is used by the second operation unit 14 . The first communication unit 12 is used for sending the V2X information from the first operation unit 11 , and the second communication unit 13 is used for receiving the V2X information from the first communication unit 12 and sending the V2X information to the second operation unit 14 .
如图3a所示,第一运算单元11与第一通信单元12属于发送端的数据处理装置。第二运算单元14和第二通信单元13属于接收端的数据处理装置。As shown in FIG. 3a, the first arithmetic unit 11 and the first communication unit 12 belong to the data processing apparatus of the transmitting end. The second arithmetic unit 14 and the second communication unit 13 belong to the data processing device of the receiving end.
在本申请实施例中,图3a所示的第一运算单元11和第二运算单元14按照ISO26262体系设计、开发、验证并达到ASIL-B的功能安全等级,图3a所示的第一通信单元12和第二通信单元13等其他第一V2X信息传输过程中涉及的设备无功能安全需求。这样,有效的降低了对V2X通信系统中设备的功能安全等级要求,可以尽可能的兼容现有设备,降低成本。In the embodiment of the present application, the first computing unit 11 and the second computing unit 14 shown in FIG. 3a are designed, developed, and verified in accordance with the ISO26262 system to achieve the functional safety level of ASIL-B, and the first communication unit shown in FIG. 3a 12 and the second communication unit 13 and other devices involved in the first V2X information transmission process have no functional safety requirements. In this way, the functional safety level requirements for the equipment in the V2X communication system are effectively reduced, and the existing equipment can be compatible as much as possible, thereby reducing the cost.
如前所述,本申请实施例提供的数据传输方法可以应用于V2I场景或者V2V场景。在V2I场景下,路侧设备可以向车载设备提供第一V2X信息,此时图3a所示的发送端的数据处理装置即为路侧设备,接收端的数据出来装置即为车载设备,第一运算单元11可以为信号机或者V2X服务器,第一通信单元12可以为路侧单元,第二通信单元13可以为远程信息处理器,第二运算单元14可以为移动数据中心。当然,在V2I场景下,车载设备也可以向路侧设备提供第一V2X信息,此时图3a所示的第一运算单元11可以为移动数据中心,第一通信单元12可以为远程信息处理器,第二通信单元13可以为路侧单元,第二运算单元14可以为信号机或者V2X服务器。在V2V场景下,车辆之间可以互相提供第一V2X信息,此时图3a所示的第一运算单元11可以为车辆A的移动数据中心,第一通信单元12可以为车辆A的远程信息处 理器,第二通信单元13可以为车辆B的远程信息处理器,第二运算单元14可以为车辆B的移动数据中心。As described above, the data transmission method provided in the embodiment of the present application may be applied to a V2I scenario or a V2V scenario. In the V2I scenario, the roadside equipment can provide the first V2X information to the in-vehicle equipment. At this time, the data processing device at the transmitting end shown in Figure 3a is the roadside equipment, and the data output device at the receiving end is the in-vehicle equipment. The first computing unit 11 may be a signal or a V2X server, the first communication unit 12 may be a roadside unit, the second communication unit 13 may be a telematics processor, and the second computing unit 14 may be a mobile data center. Of course, in the V2I scenario, the in-vehicle device can also provide the first V2X information to the roadside device. At this time, the first computing unit 11 shown in FIG. 3a can be a mobile data center, and the first communication unit 12 can be a telematics processor , the second communication unit 13 may be a roadside unit, and the second computing unit 14 may be a signal or a V2X server. In the V2V scenario, the vehicles can provide each other with the first V2X information. At this time, the first computing unit 11 shown in FIG. 3a can be the mobile data center of the vehicle A, and the first communication unit 12 can be the telematics processing of the vehicle A. The second communication unit 13 may be the telematics processor of the vehicle B, and the second computing unit 14 may be the mobile data center of the vehicle B.
需要说明的是,本申请实施例中涉及的第一运算单元和第二运算单元中的“第一”和“第二”仅用于区分不同的运算单元,第一运算单元表示发送端的数据处理装置中的运算单元,第二运算单元表示接收端的数据处理装置中的运算单元,两者均为运算单元。可以理解的是,在一个场景下,一个运算单元可以作为发送端中的第一运算单元,在另一场景下,同一运算单元又可以作为接收端中的第二运算单元。本申请实施例中涉及的第一通信单元和第二通信单元中的“第一”和“第二”仅用于区分不同的通信单元,第一通信单元表示发送端的数据处理装置中的通信单元,第二通信单元表示接收端的数据处理装置中的通信单元,两者均为通信单元。一个通信单元,在一个场景下可以作为发送端中的第一通信单元,在另一场景下可以作为接收端中的第二通信单元。本申请实施例中,对运算单元和通信单元是发送端还是接收端不做限制。It should be noted that “first” and “second” in the first and second operation units involved in the embodiments of the present application are only used to distinguish different operation units, and the first operation unit represents the data processing of the sending end The arithmetic unit in the device, and the second arithmetic unit represents the arithmetic unit in the data processing device at the receiving end, and both are arithmetic units. It can be understood that, in one scenario, one computing unit may serve as the first computing unit in the sending end, and in another scenario, the same computing unit may serve as the second computing unit in the receiving end. The “first” and “second” in the first communication unit and the second communication unit involved in the embodiments of the present application are only used to distinguish different communication units, and the first communication unit represents the communication unit in the data processing apparatus of the sender , and the second communication unit represents a communication unit in the data processing device at the receiving end, both of which are communication units. A communication unit can be used as the first communication unit in the sending end in one scenario, and can be the second communication unit in the receiving end in another scenario. In the embodiment of the present application, there is no restriction on whether the computing unit and the communication unit are the sending end or the receiving end.
本申请实施例涉及的第一运算单元、第一通信单元、第二通信单元、第二运算单元可以部署在具有通信功能(无线通信功能和/或有线通信功能)的电子设备。图3b示出本申请实施例提供的电子设备的结构示意图。The first computing unit, the first communication unit, the second communication unit, and the second computing unit involved in the embodiments of the present application may be deployed in an electronic device having a communication function (wireless communication function and/or wired communication function). FIG. 3b shows a schematic structural diagram of an electronic device provided by an embodiment of the present application.
如图3b所示,电子设备可以包括至少一个处理器301,存储器302、输入输出设备303以及总线304。下面结合图3b对电子设备的各个构成部件进行具体的介绍:As shown in FIG. 3 b , the electronic device may include at least one processor 301 , a memory 302 , an input and output device 303 and a bus 304 . Below in conjunction with Fig. 3b, each constituent element of the electronic device will be introduced in detail:
处理器301是电子设备的控制中心,可以是一个处理器,也可以是多个处理元件的统称。例如,处理器301是一个中央处理器(Central Processing Unit,CPU),也可以是特定集成电路(Application Specific Integrated Circuit,ASIC),或者是被配置成实施本申请实施例的一个或多个集成电路,例如:一个或多个微处理器(Digital Signal Processor,DSP),或,一个或者多个现场可编程门阵列(Field Programmable Gate Array,FPGA)。The processor 301 is the control center of the electronic device, and may be a processor or a general term for multiple processing elements. For example, the processor 301 is a central processing unit (Central Processing Unit, CPU), may also be a specific integrated circuit (Application Specific Integrated Circuit, ASIC), or is configured to implement one or more integrated circuits of the embodiments of the present application , for example: one or more microprocessors (Digital Signal Processor, DSP), or, one or more Field Programmable Gate Array (Field Programmable Gate Array, FPGA).
其中,处理器301可以通过运行或执行存储在存储器302内的软件程序,以及调用存储在存储器302内的数据,执行电子设备的各种功能。在本申请实施例中,处理器可以用于对第一V2X信息进行第一签名处理、对第二V2X信息进行第二签名处理、对第一签名进行验证或者对第二签名进行验证等。The processor 301 can execute various functions of the electronic device by running or executing software programs stored in the memory 302 and calling data stored in the memory 302 . In this embodiment of the present application, the processor may be configured to perform first signature processing on the first V2X information, second signature processing on the second V2X information, verification of the first signature, verification of the second signature, and the like.
在具体的实现中,作为一种实施例,处理器301可以包括一个或多个CPU,例如图中所示的CPU 0和CPU 1。In a specific implementation, as an embodiment, the processor 301 may include one or more CPUs, such as CPU 0 and CPU 1 shown in the figure.
在具体实现中,作为一种实施例,电子设备可以包括多个处理器,例如图3b中所示的处理器301和处理器305。这些处理器中的每一个可以是一个单核处理器(single-CPU),也可以是一个多核处理器(multi-CPU)。这里的处理器可以指一个或多个设备、电路、和/或用于处理数据(例如计算机程序指令)的处理核。In a specific implementation, as an embodiment, the electronic device may include multiple processors, such as the processor 301 and the processor 305 shown in FIG. 3b. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein may refer to one or more devices, circuits, and/or processing cores for processing data (eg, computer program instructions).
存储器302可以是只读存储器(Read-Only Memory,ROM)或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器(Random Access Memory,RAM)或者可存储信息和指令的其他类型的动态存储设备,也可以是电可擦可编程只读存储器(Electrically Erasable Programmable Read-Only Memory,EEPROM)、只读光盘(Compact Disc Read-Only Memory,CD-ROM)或其他光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。存储器 302可以是独立存在,通过总线304与处理器301相连接。存储器302也可以和处理器301集成在一起。在本申请实施例中,存储器可以用于存储第一V2X信息、第二V2X信息或者第三V2X信息,或者私钥、公钥等。Memory 302 may be Read-Only Memory (ROM) or other types of static storage devices that can store static information and instructions, Random Access Memory (RAM), or other types of information and instructions that can be stored It can also be an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, optical disk storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or capable of carrying or storing desired program code in the form of instructions or data structures and capable of being executed by a computer Access any other medium without limitation. The memory 302 may exist independently, and is connected to the processor 301 through the bus 304. The memory 302 may also be integrated with the processor 301 . In this embodiment of the present application, the memory may be used to store the first V2X information, the second V2X information, or the third V2X information, or a private key, a public key, and the like.
输入输出设备303,用于与其他设备或通信网络通信。如用于与以太网,无线接入网(Radio access network,RAN),无线局域网(Wireless Local Area Networks,WLAN)等通信网络通信。输入输出设备303可以包括基带处理器的全部或部分,以及还可选择性地包括无线射频(Radio Frequency,RF)处理器。RF处理器用于收发RF信号,基带处理器则用于实现由RF信号转换的基带信号或即将转换为RF信号的基带信号的处理。Input and output devices 303 for communicating with other devices or communication networks. For example, it is used to communicate with communication networks such as Ethernet, Radio access network (RAN), Wireless Local Area Networks (WLAN). The input-output device 303 may include all or part of a baseband processor, and may optionally include a radio frequency (Radio Frequency, RF) processor. The RF processor is used to transmit and receive RF signals, and the baseband processor is used to realize the processing of the baseband signal converted by the RF signal or the baseband signal to be converted into the RF signal.
在具体实现中,作为一种实施例,输入输出设备303可以包括发射器和接收器。其中,发射器用于向其他设备或通信网络发送信号,接收器用于接收其他设备或通信网络发送的信号。发射器和接收器可以独立存在,也可以集成在一起。在本申请实施例中,输入输出设备可以用于收发:第一V2X信息、第二V2X信息或者第三V2X信息。In a specific implementation, as an embodiment, the input-output device 303 may include a transmitter and a receiver. The transmitter is used for sending signals to other devices or communication networks, and the receiver is used for receiving signals sent by other devices or communication networks. The transmitter and receiver can exist independently or can be integrated. In this embodiment of the present application, the input and output device may be used to send and receive: first V2X information, second V2X information, or third V2X information.
总线304,可以是工业标准体系结构(Industry Standard Architecture,ISA)总线、外部设备互连(Peripheral Component Interconnect,PCI)总线或扩展工业标准体系结构(Extended Industry Standard Architecture,EISA)总线等。该总线可以分为地址总线、数据总线、控制总线等。为便于表示,图3b中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。The bus 304 can be an industry standard architecture (Industry Standard Architecture, ISA) bus, a peripheral device interconnect (Peripheral Component Interconnect, PCI) bus, or an extended industry standard architecture (Extended Industry Standard Architecture, EISA) bus and the like. The bus can be divided into address bus, data bus, control bus and so on. For ease of presentation, only one thick line is used in Figure 3b, but it does not mean that there is only one bus or one type of bus.
图3b中示出的设备结构并不构成对电子设备的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。The device structure shown in FIG. 3b does not constitute a limitation to the electronic device, and may include more or less components than shown, or combine some components, or arrange different components.
下面对本申请实施例中涉及的V2X信息进行说明。The following describes the V2X information involved in the embodiments of the present application.
第一V2X信息可以表示需要保证可靠性的V2X信息。第一V2X信息由第一运算单元的应用层提供,供第二运算单元使用。第一V2X信息从第一运算单元出发经由第一通信单元和第二通信单元到达第二运算单元。第一V2X信息包括由信号机提供的红绿灯信息、由V2X服务器提供的交通管制信息、由V2X服务器提供的路况信息,或者由车载计算平台提供的决策信息、BSM信息和CAM信息等。本申请实施例对第一V2X信息的内容不做限制。The first V2X information may represent V2X information whose reliability needs to be guaranteed. The first V2X information is provided by the application layer of the first operation unit for use by the second operation unit. The first V2X information starts from the first computing unit and reaches the second computing unit via the first communication unit and the second communication unit. The first V2X information includes traffic light information provided by the signal, traffic control information provided by the V2X server, road condition information provided by the V2X server, or decision information, BSM information, and CAM information provided by the in-vehicle computing platform. This embodiment of the present application does not limit the content of the first V2X information.
第二V2X信息可以表示对第一V2X信息进行第一签名处理后得到的V2X信息。第二V2X信息包括第一V2X信息和第一签名。第一运算单元在发送第一V2X信息时,第一V2X信息依次需要经过第一运算单元的应用层、传输层、网络层、接入层和物理层。在本申请实施例中,在第一运算单元的应用层增加第一签名处理功能,第一运算单元可以从其应用层获取到第一V2X信息后,可以对第一V2X信息进行第一签名处理,从而得到第二V2X信息。第一签名处理包括但不限于信息摘录(例如,使用hash函数来计算信息摘录)、循环冗余(Cyclic Redundancy Check,CRC)校验和数字签名等中的一者或多者。这些处理方式可以保障被保护的数据(即第一V2X信息)发生变化时,对端可以检测到,防止消息腐败和消息插入等,进而保证端到端的功能安全性。其中,数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。The second V2X information may represent V2X information obtained by performing the first signature processing on the first V2X information. The second V2X information includes the first V2X information and the first signature. When the first operation unit sends the first V2X information, the first V2X information needs to pass through the application layer, the transport layer, the network layer, the access layer and the physical layer of the first operation unit in sequence. In this embodiment of the present application, a first signature processing function is added to the application layer of the first operation unit, and the first operation unit can perform first signature processing on the first V2X information after acquiring the first V2X information from its application layer. , so as to obtain the second V2X information. The first signature process includes, but is not limited to, one or more of an information excerpt (eg, using a hash function to calculate the information excerpt), a Cyclic Redundancy Check (CRC) check, and a digital signature. These processing methods can ensure that when the protected data (ie, the first V2X information) changes, the opposite end can detect it, prevent message corruption and message insertion, etc., thereby ensuring end-to-end functional security. Among them, the digital signature includes the digital signature based on the root certificate issued by the national certification authority platform, or the digital signature based on the root certificate of the vehicle enterprise self-inspection certification authority platform, or the digital signature based on the root certificate issued by the ecological alliance certification authority platform.
第三V2X信息可以表示对第二V2X信息进行第二签名处理后得到的V2X信息。第三V2X信息包括第二V2X信息和第二签名。也就是说,第三V2X信息包括第一V2X信息、第一签名和第二签名,其中,第一V2X信息和第一签名组成了第二V2X信息。在本申请实施例中,第 二V2X信息从第一运算单元的物理层到达第一通信单元的物理层,然后依次经过第一通信单元的接入层、网络层和传输层到达第一通行单元的应用层。在本申请实施例中,在第一通信单元的应用层增加第二签名处理功能,第一通信单元从其应用层获取到第二V2X信息之后,对第二V2X信息进行第二签名处理,从而得到第三V2X信息。之后,第三V2X信息经过第一通信单元的应用层、传输层、网络层、接入层和物理层发送出去。这样,被保护的数据(即第一V2X信息)与第二签名一起在V2X网络中(即第一通信单元和第二通信单元之间)传输时,可以验证被保护的数据(第一V2X信息)在网络中传输中是否被抵赖或者伪造,从而保证网络传输的安全性。在一种可能的实现方式中,第二签名处理可以包括数字签名、添加令牌等。The third V2X information may represent V2X information obtained by performing the second signature processing on the second V2X information. The third V2X information includes the second V2X information and the second signature. That is, the third V2X information includes the first V2X information, the first signature and the second signature, wherein the first V2X information and the first signature constitute the second V2X information. In this embodiment of the present application, the second V2X information reaches the physical layer of the first communication unit from the physical layer of the first operation unit, and then sequentially passes through the access layer, network layer and transport layer of the first communication unit to reach the first pass unit application layer. In this embodiment of the present application, a second signature processing function is added to the application layer of the first communication unit, and after the first communication unit obtains the second V2X information from its application layer, the second signature processing is performed on the second V2X information, thereby Get third V2X information. After that, the third V2X information is sent out through the application layer, the transport layer, the network layer, the access layer and the physical layer of the first communication unit. In this way, when the protected data (ie the first V2X information) is transmitted together with the second signature in the V2X network (ie between the first communication unit and the second communication unit), the protected data (ie the first V2X information) can be verified ) is denied or forged in the network transmission, so as to ensure the security of network transmission. In a possible implementation manner, the second signature processing may include digital signature, adding a token, and the like.
在本申请实施例中,第一通信单元和第二通信单元之间可以传输经过第一签名处理获得的第二V2X信息,也可以传输经过第一签名处理以及第二签名处理获得的第三V2X信息。。In this embodiment of the present application, the second V2X information obtained through the first signature processing may be transmitted between the first communication unit and the second communication unit, and the third V2X information obtained through the first signature processing and the second signature processing may also be transmitted. information. .
下面结合图3c对第一通信单元和第二通信单元之间传输第三V2X信息的过程进行说明。图3c示出本申请实施例提供的数据传输方法的交互示意图。该方法可以应用于图3a所示的数据传输系统。如图3c所示,该方法可以包括:The following describes the process of transmitting the third V2X information between the first communication unit and the second communication unit with reference to FIG. 3c. FIG. 3c shows an interactive schematic diagram of the data transmission method provided by the embodiment of the present application. This method can be applied to the data transmission system shown in Figure 3a. As shown in Figure 3c, the method may include:
步骤S401,第一运算单元获取应用层的第一V2X信息。Step S401, the first operation unit acquires the first V2X information of the application layer.
步骤S402,第一运算单元对第一V2X信息进行第一签名处理,得到包括第一V2X信息和第一签名的第二V2X信息。Step S402, the first operation unit performs first signature processing on the first V2X information to obtain second V2X information including the first V2X information and the first signature.
步骤S403,第一运算单元将第二V2X信息发送至第一通信单元。Step S403, the first computing unit sends the second V2X information to the first communication unit.
步骤S404,第一通信单元接收第一运算单元发送的第二V2X信息。Step S404, the first communication unit receives the second V2X information sent by the first operation unit.
步骤S405,第一通信单元对第二V2X信息进行第二签名处理,得到包括第二V2X信息和第二签名的第三V2X信息。Step S405, the first communication unit performs second signature processing on the second V2X information to obtain third V2X information including the second V2X information and the second signature.
步骤S406,第一通信单元广播第三V2X信息。Step S406, the first communication unit broadcasts the third V2X information.
在发送端,第一运算单元对第一V2X信息进行第一签名处理,可防消息腐败和消息插入等问题,为功能安全性提供保障;第一通信单元对第二V2X信息进行第二签名处理,可防消息抵赖和消息伪造,为网络安全性提供保障。在实施中,第一运算单元的应用层获取第一V2X信息,并对第一V2X信息进行第一签名处理,得到第二V2X信息。第一运算单元将第二V2X信息通过以太网或者其他物理总线发送给第一通信单元。第一通信单元的应用层获取到第二V2X信息之后对第二V2X信息进行第二签名处理,得到第三V2X信息,然后经过传输层、网络层、接入层、物理层,最后通过V2X网络(例如DSRC或者LTE-V)传递给其他设备(例如第二通信单元)。At the sending end, the first computing unit performs the first signature processing on the first V2X information, which can prevent problems such as message corruption and message insertion and provide guarantee for functional security; the first communication unit performs the second signature processing on the second V2X information , which can prevent message denial and message forgery, and provide guarantee for network security. In the implementation, the application layer of the first operation unit obtains the first V2X information, and performs the first signature processing on the first V2X information to obtain the second V2X information. The first operation unit sends the second V2X information to the first communication unit through the Ethernet or other physical bus. After acquiring the second V2X information, the application layer of the first communication unit performs the second signature processing on the second V2X information to obtain the third V2X information, and then passes through the transport layer, network layer, access layer, and physical layer, and finally passes through the V2X network (eg DSRC or LTE-V) to other devices (eg the second communication unit).
步骤S407,第二通信单元接收第一通信单元发送的第三V2X信息。Step S407, the second communication unit receives the third V2X information sent by the first communication unit.
步骤S408,第二通信单元对第三V2X信息中的第二签名进行验证。Step S408, the second communication unit verifies the second signature in the third V2X information.
在一种可能的实现方式中,步骤S408可以包括:第二通信单元对第三V2X信息中的第二V2X信息进行信息摘录处理,得到第一摘要;第二通信单元对第三V2X信息中的第二签名进行解密处理,得到第二摘要;在第一摘要和第二摘要相同的情况下,第二通信单元确定第二签名验证成功;在第一摘要和第二摘要不同的情况下,第二通信单元确定第二签名验证失败。In a possible implementation manner, step S408 may include: the second communication unit performs information extraction processing on the second V2X information in the third V2X information to obtain the first abstract; The second signature is decrypted to obtain a second digest; if the first digest and the second digest are the same, the second communication unit determines that the verification of the second signature is successful; if the first digest and the second digest are different, the third The second communication unit determines that the verification of the second signature fails.
在第一摘要和第二摘要相同的情况下,表明第三V2X信息的来源可靠,且第三V2X信息中的第二V2X信息的内容没有被篡改,因此第二通信单元可以确定第二签名验证成功。If the first digest and the second digest are the same, it indicates that the source of the third V2X information is reliable, and the content of the second V2X information in the third V2X information has not been tampered with, so the second communication unit can determine the second signature verification success.
需要说明的是,第二通信单元对第二签名进行验证的方式还可以为其他与第一通信单元 约定好的方式,对此本申请不做限制。It should be noted that the manner in which the second communication unit verifies the second signature may also be other manners agreed upon with the first communication unit, which is not limited in this application.
步骤S409,在第二签名验证成功的情况下,第二通信单元将第三V2X信息中的第二V2X信息发送至第二运算单元。Step S409, in the case that the verification of the second signature is successful, the second communication unit sends the second V2X information in the third V2X information to the second computing unit.
步骤S410,第二运算单元接收第二通信单元发送的第二V2X信息。Step S410, the second operation unit receives the second V2X information sent by the second communication unit.
步骤S411,第二运算单元对第二V2X信息中的第一签名进行验证。Step S411, the second operation unit verifies the first signature in the second V2X information.
步骤S412,在第一签名验证成功的情况下,第二运算单元对第一V2X信息进行信息处理。Step S412, in the case that the first signature verification is successful, the second operation unit performs information processing on the first V2X information.
在一种可能的实现方式中,第二运算单元对第一V2X信息进行信息处理可以得到融合信息,第二运算单元可以将融合信息发送至控制器,以便于控制器基于融合信息进行运动决策和控制。In a possible implementation manner, the second computing unit may obtain fusion information by performing information processing on the first V2X information, and the second computing unit may send the fusion information to the controller, so that the controller can make motion decision and control based on the fusion information. control.
在接收端,第二通信单元对第三V2X信息中的第二签名进行验证,可防网络传输过程中的消息抵赖和消息伪造,为网络安全性性提供保障;第二运算单元对第二V2X信息中的第一签名进行验证,可防消息腐败和消息插入等问题,为功能安全性提供保障。在实施中,第三V2X信息经过V2X网络、物理层、接入层、网络层、传输层到达第二通信单元的应用层。第二通信单元的应用层对第三V2X信息中的第二签名进行验证。如果第三V2X信息中的第二签名验证失败,则第二通信单元不转发第三V2X信息中的第二V2X信息。如果第三V2X信息中的第二签名验证成功,则第二通信单元将第三V2X消息中的第二V2X信息经过传输层、网络层、接入层、物理层进行转发。第二V2X信息经过物理层、接入层、网络层、传输层到达第二运算单元的应用层。第二运算单元的应用层对第二V2X信息中的第一签名进行验证。如果第二V2X信息中的第一签名验证失败,表明第一V2X信息发生了变更,是不完整的,为了保证功能安全性第二运算单元不能采用该第一V2X信息进行后续处理。如果第二V2X信息只能够的第一签名验证成功,表明第一V2X信息没有变更,是完整的,则第二运算单元可以基于该第一V2X信息进行后续处理。At the receiving end, the second communication unit verifies the second signature in the third V2X information, which can prevent message denial and message forgery during network transmission and provide guarantee for network security; the second computing unit verifies the second V2X information. The first signature in the message is verified, which can prevent problems such as message corruption and message insertion, and provide a guarantee for functional safety. In implementation, the third V2X information reaches the application layer of the second communication unit through the V2X network, the physical layer, the access layer, the network layer, and the transport layer. The application layer of the second communication unit verifies the second signature in the third V2X information. If the verification of the second signature in the third V2X information fails, the second communication unit does not forward the second V2X information in the third V2X information. If the verification of the second signature in the third V2X message succeeds, the second communication unit forwards the second V2X information in the third V2X message through the transport layer, the network layer, the access layer, and the physical layer. The second V2X information reaches the application layer of the second computing unit through the physical layer, the access layer, the network layer, and the transport layer. The application layer of the second operation unit verifies the first signature in the second V2X information. If the verification of the first signature in the second V2X information fails, it indicates that the first V2X information has been changed and is incomplete. In order to ensure functional safety, the second computing unit cannot use the first V2X information for subsequent processing. If the verification of the first signature that can only be performed by the second V2X information is successful, indicating that the first V2X information has not been changed and is complete, the second operation unit may perform subsequent processing based on the first V2X information.
在本申请实施例中,将链路ASIL-B的功能安全等级要求分解为:对传输通道的QM要求和对信息处理的ASIL-B要求,第一通信单元和第二通信单元无功能安全需求,第一运算单元和第二运算单元按照ISO26262体系设计、开发、验证并达到ASIL-B的功能安全等即可,从而降低了传输通道的功能安全等级要求。在本申请实施例中,通过在第一运算单元和第二运算单元进行第一签名处理和第一签名验证保证了V2X信息的功能安全性(即完整性);通过在第一通信单元和第二通信单元进行第二签名处理和第二签名验证保证了V2X信息的网络安全性,因此,本申请实施例能够在尽量不对现有设备硬件改造升级的情况下,提升了V2X信息的可靠性,进而提升了车辆运动决策和控制的安全性。In the embodiment of the present application, the functional safety level requirements of link ASIL-B are decomposed into: QM requirements for transmission channels and ASIL-B requirements for information processing, and the first communication unit and the second communication unit have no functional safety requirements , the first operation unit and the second operation unit can be designed, developed, and verified according to the ISO26262 system to achieve the functional safety of ASIL-B, etc., thereby reducing the functional safety level requirements of the transmission channel. In the embodiment of the present application, the first signature processing and the first signature verification are performed in the first operation unit and the second operation unit to ensure the functional security (ie integrity) of the V2X information; The second signature processing and the second signature verification performed by the two communication units ensure the network security of the V2X information. Therefore, the embodiment of the present application can improve the reliability of the V2X information without changing and upgrading the hardware of the existing equipment as much as possible. This in turn improves the safety of vehicle motion decision-making and control.
图4a示出本申请实施例提供的V2I场景下数据传输系统的架构示意图。如图4a所示,该数据传输系统中包括信号机、路侧单元、车载通信单元、网关和车载计算平台。其中,信号机对应于图3a所示的第一运算单元11,路侧单元对应于图3a所示的第一通信单元12,车载通信单元对应于图3a所示的第二通信单元13,车载计算平台对应于图3a所示的第二运算单元14。图3c所示的方法可以应用于图4a所示的数据传输系统。FIG. 4a shows a schematic structural diagram of a data transmission system in a V2I scenario provided by an embodiment of the present application. As shown in Figure 4a, the data transmission system includes a signal machine, a roadside unit, a vehicle-mounted communication unit, a gateway and a vehicle-mounted computing platform. The signal machine corresponds to the first computing unit 11 shown in FIG. 3a, the roadside unit corresponds to the first communication unit 12 shown in FIG. 3a, the vehicle-mounted communication unit corresponds to the second communication unit 13 shown in FIG. 3a, The computing platform corresponds to the second arithmetic unit 14 shown in Fig. 3a. The method shown in Fig. 3c can be applied to the data transmission system shown in Fig. 4a.
如图4a所示,在发送端:信号机的应用层获取红绿灯信号等信息,并将获取的信息作为第一V2X信息。信号机的应用层对第一V2X信息进行第一签名处理,得到包括第一V2X信息和第一签名的第二V2X信息。第二V2X信息在信号机中经过层层传输(包括传输层、网络层、接入层、物理层),最后通过以太网或者其他总线达到路侧单元的物理层。之后,第二V2X信 息在路侧单元经过层层传输(包括物理层、接入层、网络层、传输层)到达路侧单元的应用层。路侧单元的应用层对第二V2X信息进行第二签名处理,得到包括第二V2X信息和第二签名的第三V2X信息。第三V2X信息在路侧单元中经过层层传输,最后通过V2X网络(例如DSEC或者LTE-V)发送至车载通信单元。As shown in Figure 4a, at the sending end: the application layer of the signal device obtains information such as traffic light signals, and uses the obtained information as the first V2X information. The application layer of the signal machine performs the first signature processing on the first V2X information, and obtains the second V2X information including the first V2X information and the first signature. The second V2X information is transmitted layer by layer (including the transport layer, network layer, access layer, and physical layer) in the signal machine, and finally reaches the physical layer of the roadside unit through Ethernet or other buses. After that, the second V2X information is transmitted layer by layer (including physical layer, access layer, network layer, and transport layer) in the roadside unit to the application layer of the roadside unit. The application layer of the roadside unit performs second signature processing on the second V2X information to obtain third V2X information including the second V2X information and the second signature. The third V2X information is transmitted layer by layer in the roadside unit, and finally sent to the in-vehicle communication unit through a V2X network (eg DSEC or LTE-V).
如图4a所示,在接收端:第三V2X信息在车载通信单元中经过层层传输到达车载通信单元的应用侧。然后,应用层对第三V2X信息对第二签名进行验证。在第三V2X信息中的第二签名验证成功的情况下,车载通信单元经过层层传输,最后通过网关将第三V2X信息中的第二V2X信息转发至车载计算平台。车载计算平台的应用层经过层层传输接收第二V2X信息,然后车载计算平台的应用层对第二V2X信息中的第一签名进行验证。在第二V2X信息中的第一签名验证成功的情况下,车载计算平台基于第二V2X信息中的第一V2X信息进行后续处理。As shown in Figure 4a, at the receiving end: the third V2X information is transmitted layer by layer in the in-vehicle communication unit to the application side of the in-vehicle communication unit. Then, the application layer verifies the second signature against the third V2X information. When the verification of the second signature in the third V2X information is successful, the in-vehicle communication unit transmits layer by layer, and finally forwards the second V2X information in the third V2X information to the in-vehicle computing platform through the gateway. The application layer of the in-vehicle computing platform receives the second V2X information through layer-by-layer transmission, and then the application layer of the in-vehicle computing platform verifies the first signature in the second V2X information. In the case that the verification of the first signature in the second V2X information is successful, the in-vehicle computing platform performs subsequent processing based on the first V2X information in the second V2X information.
图4b示出本申请实施例提供的V2I场景下数据传输系统的架构示意图。如图4b所示,该数据传输系统中包括车载计算平台、网关、车载通信单元、路侧单元和V2X服务器。其中,车载计算平台对应于图3a所示的第一运算单元11,车载通信单元对应于图3a所示的第一通信单元12,路侧单元对应于图3a所示的第二通信单元13,V2X服务器对应于图3a所示的第二运算单元14。图3c所示的方法可以应用于图4b所示的数据传输系统。FIG. 4b shows a schematic structural diagram of a data transmission system in a V2I scenario provided by an embodiment of the present application. As shown in Figure 4b, the data transmission system includes an in-vehicle computing platform, a gateway, an in-vehicle communication unit, a roadside unit and a V2X server. The in-vehicle computing platform corresponds to the first computing unit 11 shown in FIG. 3a, the in-vehicle communication unit corresponds to the first communication unit 12 shown in FIG. 3a, the roadside unit corresponds to the second communication unit 13 shown in FIG. 3a, The V2X server corresponds to the second arithmetic unit 14 shown in Fig. 3a. The method shown in Fig. 3c can be applied to the data transmission system shown in Fig. 4b.
如图4b所示,在发送端:车载计算平台的应用层获取到决策信息等信息,并将获取的信息作为第一V2X信息。车载计算平台的应用层对第一V2X信息进行第一签名处理,得到包括第一V2X信息和第一签名的第二V2X信息。第二V2X信息在车载计算平台经过层层传输,最后通过网关将第二V2X信息转发到达车载通信单元的物理层。之后,第二V2X信息在车载通信单元中经过层层传输到达车载通信单元的应用层。然后,车载通信单元的应用层对第二V2X信息进行第二签名处理,得到包括第二V2X信息和第二签名的第三V2X信息。第三V2X信息在车载通信单元中经过层层传输,最后通过V2X网络(例如DSEC或者LTE-V)发送至路侧单元。As shown in Figure 4b, at the sending end: the application layer of the in-vehicle computing platform obtains information such as decision information, and uses the obtained information as the first V2X information. The application layer of the in-vehicle computing platform performs the first signature processing on the first V2X information to obtain the second V2X information including the first V2X information and the first signature. The second V2X information is transmitted layer by layer on the in-vehicle computing platform, and finally the second V2X information is forwarded to the physical layer of the in-vehicle communication unit through the gateway. After that, the second V2X information is transmitted layer by layer in the in-vehicle communication unit to the application layer of the in-vehicle communication unit. Then, the application layer of the in-vehicle communication unit performs a second signature process on the second V2X information to obtain third V2X information including the second V2X information and the second signature. The third V2X information is transmitted layer by layer in the in-vehicle communication unit, and finally sent to the roadside unit through a V2X network (eg, DSEC or LTE-V).
如图4b所示,在接收端:第三V2X信息在路侧单元中经过层层传输接收第三V2X信息到达路侧单元的应用层。然后,路侧单元的应用层对第三V2X信息中的第二签名进行验证。在第三V2X信息中的第二签名验证成功的情况下,路侧单元经过层层传输,最后通过以太网或者其他总线将第三V2X信息中的第二V2X信息发送至V2X服务器。V2X服务器的应用层经过层层传输接收第二V2X信息,然后V2X服务器的应用层对第二V2X信息中的第一签名进行验证。在第二V2X信息中的第一签名验证成功的情况下,V2X服务器基于第二V2X信息中的第一V2X信息进行后续处理。As shown in Fig. 4b, at the receiving end: the third V2X information is transmitted in the roadside unit layer by layer to receive the third V2X information and arrive at the application layer of the roadside unit. Then, the application layer of the RSU verifies the second signature in the third V2X information. In the case that the verification of the second signature in the third V2X information is successful, the roadside unit transmits layer by layer, and finally sends the second V2X information in the third V2X information to the V2X server through Ethernet or other buses. The application layer of the V2X server receives the second V2X information through layer-by-layer transmission, and then the application layer of the V2X server verifies the first signature in the second V2X information. In the case that the verification of the first signature in the second V2X information is successful, the V2X server performs subsequent processing based on the first V2X information in the second V2X information.
图4c示出本申请实施例提供的V2V场景下数据传输系统的架构示意图。如图4c所示,该数据传输系统包括车辆A的车载计算平台、车辆A的网关、车辆A的车载通信单元,以及车辆B的车载通信单元、车辆B的网关和车辆B的车载计算平台。其中,车辆A的车载计算平台对应于图3a所示的第一运算单元11,车辆A的车载通信单元对应于图3a所示的第一通信单元12,车辆B的车载通信单元对应于图3a所示的第二通信单元13,车辆B的车载计算平台对应于图3a所示的第二运算单元14。图3c所示的方法可以应用于图4c所示的数据传输系统。FIG. 4c shows a schematic structural diagram of a data transmission system in a V2V scenario provided by an embodiment of the present application. As shown in Fig. 4c, the data transmission system includes the vehicle-mounted computing platform of vehicle A, the gateway of vehicle A, the vehicle-mounted communication unit of vehicle A, the vehicle-mounted communication unit of vehicle B, the gateway of vehicle B, and the vehicle-mounted computing platform of vehicle B. The in-vehicle computing platform of vehicle A corresponds to the first computing unit 11 shown in FIG. 3a, the in-vehicle communication unit of vehicle A corresponds to the first communication unit 12 shown in FIG. 3a, and the in-vehicle communication unit of vehicle B corresponds to FIG. 3a The shown second communication unit 13, the on-board computing platform of the vehicle B corresponds to the second computing unit 14 shown in FIG. 3a. The method shown in Fig. 3c can be applied to the data transmission system shown in Fig. 4c.
如图4c所示,在发送端:车辆A的车载计算平台的应用层获取决策信息等信息,并将获取的信息作为第一V2X信息。车辆A的车载计算平台的应用层对第一V2X信息进行第一签名 处理,得到包括第一V2X信息和第一签名的第二V2X信息。车辆A的车载计算平台经过层层传输,最后通过网关将第二V2X信息转发至车辆A的车载通信单元。车辆A的车载通信单元的应用层经过层层传输接收第二V2X信息。然后,车辆A的车载通信单元的应用层对第二V2X信息进行第二签名处理,得到包括第二V2X信息和第二签名的第三V2X信息。车辆A的车载通信单元经过层层传输,最后通过V2X网络(例如DSEC或者LTE-V)将第三V2X信息发送至车辆B的车载通信单元。As shown in Figure 4c, at the sending end: the application layer of the vehicle-mounted computing platform of vehicle A obtains information such as decision information, and uses the obtained information as the first V2X information. The application layer of the in-vehicle computing platform of vehicle A performs the first signature processing on the first V2X information to obtain the second V2X information including the first V2X information and the first signature. The in-vehicle computing platform of vehicle A goes through layers of transmission, and finally forwards the second V2X information to the in-vehicle communication unit of vehicle A through the gateway. The application layer of the in-vehicle communication unit of vehicle A receives the second V2X information through layer-by-layer transmission. Then, the application layer of the in-vehicle communication unit of vehicle A performs second signature processing on the second V2X information to obtain third V2X information including the second V2X information and the second signature. The in-vehicle communication unit of vehicle A transmits layer by layer, and finally sends the third V2X information to the in-vehicle communication unit of vehicle B through a V2X network (eg, DSEC or LTE-V).
如图4c所示,在接收端:车辆B的车载通信单元的应用层经过层层传输接收第三V2X信息。然后,车辆B的车载通信单元的应用层对第三V2X信息中的第二签名进行验证。在第三V2X信息中的第二签名验证成功的情况下,车辆B的车载通信单元经过层层传输,最后通过网关将第三V2X信息中的第二V2X信息转发至车辆B的车载计算平台。车辆B的车载计算平台的应用层经过层层传输接收第二V2X信息,然后车辆B的车载计算平台的应用层对第二V2X信息中的第一签名进行验证。在第二V2X信息中的第一签名验证成功的情况下,车辆B的车载计算平台基于第二V2X信息中的第一V2X信息进行后续处理。As shown in Figure 4c, at the receiving end: the application layer of the in-vehicle communication unit of vehicle B receives the third V2X information through layer-by-layer transmission. Then, the application layer of the in-vehicle communication unit of vehicle B verifies the second signature in the third V2X information. When the verification of the second signature in the third V2X information is successful, the on-board communication unit of vehicle B transmits layer by layer, and finally forwards the second V2X information in the third V2X information to the on-board computing platform of vehicle B through the gateway. The application layer of the vehicle-mounted computing platform of vehicle B receives the second V2X information through layer-by-layer transmission, and then the application layer of the vehicle-mounted computing platform of vehicle B verifies the first signature in the second V2X information. In the case that the verification of the first signature in the second V2X information is successful, the in-vehicle computing platform of vehicle B performs subsequent processing based on the first V2X information in the second V2X information.
下面结合图3d对第一通信单元和第二通信单元之间传输经过第一签名处理获得的第二V2X信息的过程进行说明。图3d示出本申请实施例提供的数据传输方法的交互示意图。该方法可以应用于图3a所示的数据传输系统。如图3d所示,该方法可以包括:The following describes the process of transmitting the second V2X information obtained through the first signature processing between the first communication unit and the second communication unit with reference to FIG. 3d. FIG. 3d shows an interactive schematic diagram of the data transmission method provided by the embodiment of the present application. This method can be applied to the data transmission system shown in Figure 3a. As shown in Figure 3d, the method may include:
步骤S501,第一运算单元获取应用层的第一V2X信息。Step S501, the first operation unit acquires the first V2X information of the application layer.
步骤S502,第一运算单元对第一V2X信息进行第一签名处理,得到包括第一V2X信息和第一签名的第二V2X信息。Step S502, the first operation unit performs first signature processing on the first V2X information to obtain second V2X information including the first V2X information and the first signature.
在一种可能的实现方式中,第一运算单元可以通过对第一V2X信息进行数字签名处理,实现对第一V2X信息的第一签名处理。在实施中,可以使用国家认证机构(Certificate Authority,CA)平台办法的根证书进行数字签名处理,进而实现不同车企生产的车辆之间的互联互通;可以使用车企自检CA平台根证书进行数字签名处理,从而可以实现同一车企生产的车辆之间的互联互通;还可以使用生态联盟CA平台颁发的根证书进行数字签名处理,从而实现同一生态联盟下车企生产的车辆之间的互联互通。In a possible implementation manner, the first operation unit may perform first signature processing on the first V2X information by performing digital signature processing on the first V2X information. In the implementation, the root certificate of the national certification authority (Certificate Authority, CA) platform method can be used for digital signature processing, so as to realize the interconnection between vehicles produced by different car companies; the root certificate of the car company's self-check CA platform can be used for Digital signature processing, so that the interconnection between vehicles produced by the same car company can be realized; the root certificate issued by the ecological alliance CA platform can also be used for digital signature processing, so as to realize the interconnection between vehicles produced by car companies under the same ecological alliance Intercommunication.
步骤S503,第一运算单元通过与第一通信单元之间的安全通道将第二V2X信息发送至第一通信单元。Step S503, the first computing unit sends the second V2X information to the first communication unit through the secure channel with the first communication unit.
在本申请实施例中,可以在第一运算单元与第一通信单元之间建立安全通道。在一个示例中,第一运算单元和第一通信单元通过链路会话密钥协商生成会话密钥,利用会话密钥加密传输数据,进而实现安全通道的建立。在又一示例中,第一运算单元和第一通信单元分别配置安全通信模块,通过两端的安全通信模块实现传输数据的加密和解密,进而实现安全通道的建立。本申请实施例对建立安全通道的方式不做限制,对安全通道采用的加解密方式不做限制,对安全通道采用的密钥也不做限制。In this embodiment of the present application, a secure channel may be established between the first computing unit and the first communication unit. In an example, the first computing unit and the first communication unit generate a session key through link session key negotiation, and use the session key to encrypt transmission data, thereby establishing a secure channel. In yet another example, the first computing unit and the first communication unit are respectively configured with a secure communication module, and the secure communication modules at both ends implement encryption and decryption of the transmitted data, thereby realizing the establishment of a secure channel. The embodiments of the present application do not limit the manner of establishing the secure channel, do not limit the encryption/decryption method adopted for the secure channel, and do not limit the key employed for the secure channel.
步骤S504,第一通信单元通过与第一运算单元之间的安全通道接收第二V2X信息。Step S504, the first communication unit receives the second V2X information through the secure channel with the first computing unit.
步骤S505,第一通信单元广播第二V2X信息。Step S505, the first communication unit broadcasts the second V2X information.
第一通信单元通过安全通道接收到的V2X信息就是经过第一签名处理的V2X信息,此时,第一通信单元无需对接收到的V2X信息进行第二签名处理同样可以保证应用层V2X信息的功能安全性。第一通信单元直接广播第二V2X信息,可以降低对第一通信单元的功能要求,从而降低第一通信单元的成本。The V2X information received by the first communication unit through the secure channel is the V2X information processed by the first signature. At this time, the first communication unit does not need to perform the second signature processing on the received V2X information, which can also ensure the function of the application layer V2X information. safety. The first communication unit directly broadcasts the second V2X information, which can reduce the functional requirements for the first communication unit, thereby reducing the cost of the first communication unit.
步骤S506,第二通信单元接收第一通信单元发送的第二V2X信息。Step S506, the second communication unit receives the second V2X information sent by the first communication unit.
步骤S507,第二通信单元通过与第二运算单元之间的安全通道将第二V2X信息发送至第二运算单元。Step S507, the second communication unit sends the second V2X information to the second operation unit through the secure channel with the second operation unit.
在本申请实施例中,可以在第二通信单元与第二运算单元之间建立安全通道。第二通信单元与第二运算单元之间建立安全通道的方式可以参照第一运算单元与第一通信单元之间建立安全通道的方式,这里不再赘述。In this embodiment of the present application, a secure channel may be established between the second communication unit and the second computing unit. The manner of establishing the secure channel between the second communication unit and the second operation unit may refer to the manner of establishing the secure channel between the first operation unit and the first communication unit, which will not be repeated here.
在第二通信单元与第二运算单元之间建立了安全通道的情况下,第二通信单元可以将接收到的V2X信息直接通过安全通道转发至第二运算单元,由第二运算单元进行签名验证,这样一方面可以将未经过签名验证的V2X信息集中到第二运算单元中,防止没有经过签名验证的V2X信息对车辆中的其他部件造成不利影响,另一方面可以降低对第二通信单元的功能要求,从而降低第二通信单元的成本。When a secure channel is established between the second communication unit and the second computing unit, the second communication unit can directly forward the received V2X information to the second computing unit through the secure channel, and the second computing unit performs signature verification , on the one hand, the V2X information that has not been verified by the signature can be concentrated into the second computing unit, to prevent the V2X information that has not been verified by the signature from adversely affecting other components in the vehicle, and on the other hand, it can reduce the impact on the second communication unit. functional requirements, thereby reducing the cost of the second communication unit.
步骤S508,第二运算单元通过与第二通信单元之间的安全通道接收第二V2X信息。Step S508, the second computing unit receives the second V2X information through the secure channel with the second communication unit.
步骤S509,第二运算单元对第二V2X信息中的第一签名进行验证。Step S509, the second operation unit verifies the first signature in the second V2X information.
步骤S510,在第一签名验证成功的情况下,第二运算单元对第二V2X信息中的第一V2X信息进行信息处理。Step S510, in the case that the verification of the first signature is successful, the second operation unit performs information processing on the first V2X information in the second V2X information.
在一种可能的实现方式中,第二运算单元对第一V2X信息进行信息处理可以得到融合信息,第二运算单元可以将融合信息发送至控制器,以便于控制器基于融合信息进行运动决策和控制。In a possible implementation manner, the second computing unit may obtain fusion information by performing information processing on the first V2X information, and the second computing unit may send the fusion information to the controller, so that the controller can make motion decision and control based on the fusion information. control.
在接收端,第二通信单元通过安全通道向第二运算单元发送第二V2X信息,可以使未经验证的V2X信息走专用通道,降低对数据处理装置中其他部件的影响;第二运算单元对第二V2X信息中的第一签名进行验证,可防消息腐败和消息插入等问题,为功能安全性提供保障。At the receiving end, the second communication unit sends the second V2X information to the second computing unit through the secure channel, so that the unverified V2X information can be sent to the dedicated channel and the impact on other components in the data processing device is reduced; The first signature in the second V2X information is verified, which can prevent problems such as message corruption and message insertion, and provide guarantee for functional safety.
在本申请实施例中,将链路ASIL-B的功能安全等级要求分解为:对传输通道的QM要求和对信息处理的ASIL-B要求,第一通信单元和第二通信单元无功能安全需求,第一运算单元和第二运算单元按照ISO26262体系设计、开发、验证并达到ASIL-B的功能安全等即可,从而降低了传输通道的功能安全等级要求,通过在第一运算单元进行第一签名处理,在安全通道中传输第二V2X信息,既保证了V2X信息的功能安全性(即完整性)又保证了V2X信息的网络安全性,因此,本申请实施例能够在尽量不对现有设备硬件改造升级的情况下,提升了V2X信息的可靠性,进而提升了车辆运动决策和控制的安全性。同时,本申请实施例简化了第一运算单元与第一通信单元之间信息传输流程以及第二通信单元与第二运算单元之间信息传输流程,降低了对第一通信单元和第二通信单元的功能要求,从而降低了第一通信单元和第二通信单元的成本。In the embodiment of the present application, the functional safety level requirements of link ASIL-B are decomposed into: QM requirements for transmission channels and ASIL-B requirements for information processing, and the first communication unit and the second communication unit have no functional safety requirements , the first operation unit and the second operation unit can be designed, developed, verified according to the ISO26262 system, and can achieve the functional safety of ASIL-B, etc., thereby reducing the functional safety level requirements of the transmission channel. Signature processing, transmitting the second V2X information in the secure channel, not only ensures the functional security (that is, the integrity) of the V2X information, but also ensures the network security of the V2X information. In the case of hardware modification and upgrading, the reliability of V2X information is improved, thereby improving the safety of vehicle motion decision-making and control. Meanwhile, the embodiment of the present application simplifies the information transmission process between the first operation unit and the first communication unit and the information transmission process between the second communication unit and the second operation unit, and reduces the need for the first communication unit and the second communication unit. functional requirements, thereby reducing the cost of the first communication unit and the second communication unit.
图4d示出本申请实施例提供的V2V场景下数据传输系统的架构示意图。如图4d所示,该数据传输系统中包括车辆A的车载计算平台、车辆A的网关、车辆A的车载通信单元,以及车辆B的车载通信单元、车辆B的网关和车辆B的车载计算平台。其中,车辆A的车载计算平台对应于图3a所示的第一运算单元11,车辆A的车载通信单元对应于图3a所示的第一通信单元12,车辆B的车载通信单元对应于图3a所示的第二通信单元13,车辆B的车载计算平台对应于图3a所示的第二运算单元14。图3d所示的方法可以应用于图4d所示的数据传输系统。FIG. 4d shows a schematic structural diagram of a data transmission system in a V2V scenario provided by an embodiment of the present application. As shown in Figure 4d, the data transmission system includes the vehicle-mounted computing platform of vehicle A, the gateway of vehicle A, the vehicle-mounted communication unit of vehicle A, the vehicle-mounted communication unit of vehicle B, the gateway of vehicle B, and the vehicle-mounted computing platform of vehicle B . The in-vehicle computing platform of vehicle A corresponds to the first computing unit 11 shown in FIG. 3a, the in-vehicle communication unit of vehicle A corresponds to the first communication unit 12 shown in FIG. 3a, and the in-vehicle communication unit of vehicle B corresponds to FIG. 3a The shown second communication unit 13, the on-board computing platform of the vehicle B corresponds to the second computing unit 14 shown in FIG. 3a. The method shown in Fig. 3d can be applied to the data transmission system shown in Fig. 4d.
如图4d所示,在发送端:车辆A的车载计算平台与车辆A的车载通信单元之间建立了安 全通道。车辆A的车载计算平台的应用层获取第一V2X信息,并对第一V2X信息进行第一签名处理,得到包括第一V2X信息和第一签名的V2X信息。车辆A的车载计算平台通过预先建立的安全通道将第二V2X信息传递给车辆A的车载通信单元。车辆A的车载通信单元通过V2X网络广播第二V2X信息。As shown in Figure 4d, at the sender: a secure channel is established between the vehicle-mounted computing platform of vehicle A and the vehicle-mounted communication unit of vehicle A. The application layer of the in-vehicle computing platform of vehicle A obtains the first V2X information, and performs first signature processing on the first V2X information to obtain V2X information including the first V2X information and the first signature. The in-vehicle computing platform of vehicle A transmits the second V2X information to the in-vehicle communication unit of vehicle A through a pre-established secure channel. The in-vehicle communication unit of vehicle A broadcasts the second V2X information through the V2X network.
如图4d所示,在接收端:车辆B的车载计算平台和车辆B的车载通信单元之间建立了安全通道。车辆B的车载通信单元接收到第二V2X信息后,通过预先建立的安全通道,将第二V2X信息发送至车辆B的车载计算平台。车辆B的车载计算平台的应用层对第二V2X信息中的第一签名进行验证。在第一签名验证成功的情况下,车辆B的车载计算平台可以基于第二V2X信息中的第一V2X信息进行后续处理。As shown in Figure 4d, a secure channel is established between the receiving end: the on-board computing platform of vehicle B and the on-board communication unit of vehicle B. After receiving the second V2X information, the vehicle-mounted communication unit of vehicle B sends the second V2X information to the vehicle-mounted computing platform of vehicle B through the pre-established security channel. The application layer of the in-vehicle computing platform of vehicle B verifies the first signature in the second V2X information. In the case that the verification of the first signature is successful, the in-vehicle computing platform of vehicle B may perform subsequent processing based on the first V2X information in the second V2X information.
图5示出本申请实施例提供的数据处理装置的结构示意图。该装置可以用于执行图3c所示的方法。如图5所示,该数据处理装置50可以包括:运算单元51和通信单元52,其中,运算单元51包括第一签名模块511和第一发送模块512,通信单元52包括第二签名模块521和第二发送模块522。FIG. 5 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application. The apparatus can be used to perform the method shown in Figure 3c. As shown in FIG. 5 , the data processing apparatus 50 may include: an operation unit 51 and a communication unit 52, wherein the operation unit 51 includes a first signature module 511 and a first sending module 512, and the communication unit 52 includes a second signature module 521 and The second sending module 522 .
所述第一签名模块511,用于对应用层的第一V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The first signature module 511 is configured to perform first signature processing on the first V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
所述第一发送模块512,用于将所述第一签名模块511获得的第二V2X信息发送至所述第二签名模块;The first sending module 512 is configured to send the second V2X information obtained by the first signature module 511 to the second signature module;
所述第二签名模块521,用于对所述第一发送模块512发送的第二V2X信息进行第二签名处理,得到第三V2X信息,所述第三V2X信息包括所述第二V2X信息和第二签名;The second signature module 521 is configured to perform second signature processing on the second V2X information sent by the first sending module 512 to obtain third V2X information, where the third V2X information includes the second V2X information and second signature;
所述第二发送模块522,用于发送所述第二签名模块521获得的第三V2X信息。The second sending module 522 is configured to send the third V2X information obtained by the second signature module 521 .
在本申请实施例中,在运算单元对应用层的V2X信息进行第一签名处理,这样在运算单元达到功能安全等级要求的情况下,即可保证应用层V2X信息的功能安全性,对通信单元无功能安全需求,且降低了对运算单元和通信单元之间的传输通道的功能安全等级要求;然后,在通信单元对经过第一签名处理的V2X信息进行第二签名处理,这样,保证了应用层V2X信息在网络传输过程中的安全性。因此,本申请实施例,可以在尽量不对现有设备硬件改造升级的情况下,提升V2X信息的可靠性,进而提升车辆运动决策和控制的安全性。In the embodiment of the present application, the computing unit performs the first signature processing on the V2X information of the application layer, so that when the computing unit meets the functional safety level requirements, the functional security of the V2X information of the application layer can be guaranteed. There is no functional safety requirement, and the functional safety level requirements for the transmission channel between the computing unit and the communication unit are reduced; then, the communication unit performs the second signature processing on the V2X information that has undergone the first signature processing, thus ensuring the application Layer V2X information security during network transmission. Therefore, in the embodiments of the present application, the reliability of V2X information can be improved, and the safety of vehicle motion decision-making and control can be improved without changing and upgrading existing equipment hardware as much as possible.
在一种可能的实现方式中,所述第一签名处理包括:信息摘录、循环冗余CRC校验和数字签名中的一者或多者,其中,所述数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。In a possible implementation manner, the first signature processing includes one or more of: information extraction, cyclic redundancy CRC check and digital signature, wherein the digital signature includes issuance based on a national certification authority platform The digital signature of the root certificate, or the digital signature based on the root certificate of the car company's self-inspection certification agency platform, or the digital signature based on the root certificate issued by the ecological alliance certification agency platform.
在一种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。In a possible implementation manner, the data processing apparatus is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
在一种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。In a possible implementation manner, the data processing apparatus is a roadside device, the arithmetic unit includes a signal, and the communication unit includes a roadside unit RSU.
在一种可能的实现方式中,所述第一发送模块还用于:通过以太网将所述第二V2X信息发送至所述第二签名模块。In a possible implementation manner, the first sending module is further configured to: send the second V2X information to the second signature module through Ethernet.
图6示出本申请实施例提供的数据处理装置的结构示意图。该装置可以用于执行图3d所示的方法。如图6所示,该数据处理装置60包括运算单元61和通信单元62,所述运算单元61与所述通信单元62通过安全通道63连接,所述运算单元61包括第一签名模块611和第 一发送模块612,所述通信单元62包括第二发送模块621。FIG. 6 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application. The apparatus can be used to perform the method shown in Figure 3d. As shown in FIG. 6 , the data processing device 60 includes an operation unit 61 and a communication unit 62 , the operation unit 61 is connected with the communication unit 62 through a secure channel 63 , and the operation unit 61 includes a first signature module 611 and a first signature module 611 . A sending module 612 , the communication unit 62 includes a second sending module 621 .
所述第一签名模块611,用于对应用层的第一V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The first signature module 611 is configured to perform first signature processing on the first V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
所述第一发送模块612,用于通过所述安全通道63将所述第二V2X信息发送至所述第二发送模块621;the first sending module 612, configured to send the second V2X information to the second sending module 621 through the secure channel 63;
所述第二发送模块621,用于发送所述第二V2X信息。The second sending module 621 is configured to send the second V2X information.
在本申请实施例中,通过在运算单元和通信单元之间的安全通道中传输第二V2X信息,可以省去通信单元对第二V2X信息的签名处理过程,从而降低了对第一通信单元的功能要求,降低了第一通信单元的成本。In the embodiment of the present application, by transmitting the second V2X information in the secure channel between the computing unit and the communication unit, the signature processing process of the second V2X information by the communication unit can be omitted, thereby reducing the complexity of the first communication unit. Functional requirements, reducing the cost of the first communication unit.
在一种可能的实现方式中,所述第一签名处理包括:信息摘录、循环冗余CRC校验和数字签名中的一者或多者,其中,所述数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。In a possible implementation manner, the first signature processing includes one or more of: information extraction, cyclic redundancy CRC check and digital signature, wherein the digital signature includes issuance based on a national certification authority platform The digital signature of the root certificate, or the digital signature based on the root certificate of the car company's self-inspection certification agency platform, or the digital signature based on the root certificate issued by the ecological alliance certification agency platform.
在一种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。In a possible implementation manner, the data processing apparatus is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
在一种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。In a possible implementation manner, the data processing apparatus is a roadside device, the arithmetic unit includes a signal, and the communication unit includes a roadside unit RSU.
图7示出本申请实施例提供的数据处理装置的结构示意图。该装置可以用于执行图3c所示的方法。如图7所示,该数据处理装置70包括通信单元71和运算单元72,所述通信单元71包括接收模块711、第一验签模块712和发送模块713,所述运算单元72包括第二验签模块721和处理模块722。FIG. 7 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application. The apparatus can be used to perform the method shown in Figure 3c. As shown in FIG. 7 , the data processing device 70 includes a communication unit 71 and an operation unit 72 , the communication unit 71 includes a receiving module 711 , a first signature verification module 712 and a sending module 713 , and the operation unit 72 includes a second verification module 713 . Signing module 721 and processing module 722.
所述接收模块711,用于接收第三V2X信息,所述第三车联网V2X信息包括第二V2X信息和第二签名,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The receiving module 711 is configured to receive third V2X information, where the third IoV V2X information includes second V2X information and a second signature, and the second V2X information includes first V2X information and a first signature at the application layer ;
所述第一验签模块712,用于对所述接收模块711接收的第三V2X信息中的第二签名进行验证;The first signature verification module 712 is configured to verify the second signature in the third V2X information received by the receiving module 711;
所述发送模块713,用于在所述第一验签模块712对第二签名验证成功的情况下,将所述第二V2X信息发送至所述第二验签模块721;The sending module 713 is configured to send the second V2X information to the second signature verification module 721 when the first signature verification module 712 successfully verifies the second signature;
所述第二验签模块721,用于对所述发送模块713发送的第二V2X信息中的第一签名进行验证;The second signature verification module 721 is configured to verify the first signature in the second V2X information sent by the sending module 713;
所述处理模块722,用于在所述第二验签模块721对第一签名验证成功的情况下,对所述第一V2X信息进行信息处理。The processing module 722 is configured to perform information processing on the first V2X information when the second signature verification module 721 successfully verifies the first signature.
在本申请实施例中,第二通信单元可以将接收到的V2X信息直接通过安全通道转发至第二运算单元,由第二运算单元进行签名验证,这样一方面可以将未经过签名验证的V2X信息集中到第二运算单元中,防止没有经过签名验证的V2X信息对车辆中的其他部件造成不利影响,另一方面可以降低对第二通信单元的功能要求,从而降低第二通信单元的成本。同时,第二运算单元对第二V2X信息中的第一签名进行验证,可防消息腐败和消息插入等问题,为功能安全性提供保障。In this embodiment of the present application, the second communication unit can directly forward the received V2X information to the second computing unit through the secure channel, and the second computing unit performs signature verification. Centralized in the second computing unit, V2X information without signature verification can be prevented from adversely affecting other components in the vehicle, and on the other hand, the functional requirements of the second communication unit can be reduced, thereby reducing the cost of the second communication unit. At the same time, the second operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide guarantee for functional safety.
在一种可能的实现方式中,所述第一验签模块还用于:In a possible implementation manner, the first signature verification module is also used for:
对所述第二V2X信息进行信息摘录处理,得到第一摘要;performing information extraction processing on the second V2X information to obtain a first abstract;
对所述第二签名进行解密处理,得到第二摘要;Decrypting the second signature to obtain a second digest;
在所述第一摘要和所述第二摘要相同的情况下,确定所述第二签名验证成功。In the case that the first digest and the second digest are the same, it is determined that the verification of the second signature is successful.
在一种可能的实现方式中,所述第二验签模块还用于:In a possible implementation manner, the second signature verification module is also used for:
对所述第一签名进行信息摘录校验、或者进行循环冗余CRC校验,或者进行数字签名验证,其中,所述数字签名验证包括基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。Performing information extract verification, or performing cyclic redundancy CRC verification, or performing digital signature verification on the first signature, wherein the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, or , based on the digital signature verification of the root certificate of the car company's self-inspection certification agency platform, or, based on the digital signature verification of the root certificate issued by the ecological alliance certification agency platform.
在一种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。In a possible implementation manner, the data processing apparatus is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
在一种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。In a possible implementation manner, the data processing apparatus is a roadside device, the arithmetic unit includes a signal, and the communication unit includes a roadside unit RSU.
在一种可能的实现方式中,所述发送模块还用于:在所述第一验签模块对第二签名验证成功的情况下,通过以太网将所述第二V2X信息发送至所述第二验签模块。In a possible implementation manner, the sending module is further configured to: send the second V2X information to the second signature through Ethernet when the first signature verification module successfully verifies the second signature Second signature verification module.
图8示出本申请实施例提供的数据处理装置的结构示意图。该装置可以用于执行图3d所示的方法。如图8所示,该数据处理装置80包括通信单元81和运算单元82,所述通信单元81和所述运算单元82和通过安全通道83连接,所述通信单元81包括接收模块811和发送模块812,所述运算单元82包括验签模块821和处理模块822;FIG. 8 shows a schematic structural diagram of a data processing apparatus provided by an embodiment of the present application. The apparatus can be used to perform the method shown in Figure 3d. As shown in FIG. 8 , the data processing device 80 includes a communication unit 81 and an operation unit 82 , the communication unit 81 and the operation unit 82 are connected through a secure channel 83 , and the communication unit 81 includes a receiving module 811 and a sending module 812, the operation unit 82 includes a signature verification module 821 and a processing module 822;
所述接收模块811,用于接收第二V2X信息,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The receiving module 811 is configured to receive second V2X information, where the second V2X information includes the first V2X information and the first signature of the application layer;
所述发送模块812,用于通过所述安全通道83将所述接收模块811接收到的第二V2X信息发送至所述验签模块821;The sending module 812 is configured to send the second V2X information received by the receiving module 811 to the signature verification module 821 through the secure channel 83;
所述验签模块821,用于对所述发送模块812发送的第二V2X信息中的第一签名进行验证;The signature verification module 821 is configured to verify the first signature in the second V2X information sent by the sending module 812;
所述处理模块822,用于在所述验签模块821对所述第一签名验证成功的情况下,对所述第一V2X信息进行信息处理。The processing module 822 is configured to perform information processing on the first V2X information when the signature verification module 821 successfully verifies the first signature.
在本申请实施例中,通信单元通过安全通道向运算单元发送第二V2X信息,可以使未经验证的V2X信息走专用通道,降低对数据处理装置中其他部件的影响;运算单元对第二V2X信息中的第一签名进行验证,可防消息腐败和消息插入等问题,为功能安全性提供保障。In the embodiment of the present application, the communication unit sends the second V2X information to the computing unit through the secure channel, so that the unverified V2X information can be sent to the dedicated channel, thereby reducing the impact on other components in the data processing device; The first signature in the message is verified, which can prevent problems such as message corruption and message insertion, and provide a guarantee for functional safety.
在一种可能的实现方式中,所述验签模块还用于:In a possible implementation, the signature verification module is also used for:
对所述第一签名进行基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。Perform digital signature verification on the first signature based on the root certificate issued by the national certification authority platform, or based on the digital signature verification of the root certificate of the vehicle enterprise self-inspection certification authority platform, or based on the root certificate issued by the ecological alliance certification authority platform digital signature verification.
在一种可能的实现方式中,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。In a possible implementation manner, the data processing apparatus is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
在一种可能的实现方式中,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。In a possible implementation manner, the data processing apparatus is a roadside device, the arithmetic unit includes a signal, and the communication unit includes a roadside unit RSU.
本申请的实施例提供了一种数据处理装置,包括:处理器以及用于存储处理器可执行指令的存储器;其中,所述处理器被配置为执行所述指令时实现上述方法。An embodiment of the present application provides a data processing apparatus, including: a processor and a memory for storing instructions executable by the processor; wherein the processor is configured to implement the above method when executing the instructions.
本申请的实施例提供了一种非易失性计算机可读存储介质,其上存储有计算机程序指令, 所述计算机程序指令被处理器执行时实现上述方法。Embodiments of the present application provide a non-volatile computer-readable storage medium on which computer program instructions are stored, and when the computer program instructions are executed by a processor, implement the above method.
本申请的实施例提供了一种计算机程序产品,包括计算机可读代码,或者承载有计算机可读代码的非易失性计算机可读存储介质,当所述计算机可读代码在电子设备的处理器中运行时,所述电子设备中的处理器执行上述方法。Embodiments of the present application provide a computer program product, including computer-readable codes, or a non-volatile computer-readable storage medium carrying computer-readable codes, when the computer-readable codes are stored in a processor of an electronic device When running in the electronic device, the processor in the electronic device executes the above method.
计算机可读存储介质可以是可以保持和存储由指令执行设备使用的指令的有形设备。计算机可读存储介质例如可以是(但不限于)电存储设备、磁存储设备、光存储设备、电磁存储设备、半导体存储设备或者上述的任意合适的组合。计算机可读存储介质的更具体的例子(非穷举的列表)包括:便携式计算机盘、硬盘、随机存取存储器(Random Access Memory,RAM)、只读存储器(Read Only Memory,ROM)、可擦式可编程只读存储器(Electrically Programmable Read-Only-Memory,EPROM或闪存)、静态随机存取存储器(Static Random-Access Memory,SRAM)、便携式压缩盘只读存储器(Compact Disc Read-Only Memory,CD-ROM)、数字多功能盘(Digital Video Disc,DVD)、记忆棒、软盘、机械编码设备、例如其上存储有指令的打孔卡或凹槽内凸起结构、以及上述的任意合适的组合。A computer-readable storage medium may be a tangible device that can hold and store instructions for use by the instruction execution device. The computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read only memory (ROM), erasable programmable read-only memory (Electrically Programmable Read-Only-Memory, EPROM or flash memory), static random access memory (Static Random-Access Memory, SRAM), portable compact disk read-only memory (Compact Disc Read-Only Memory, CD - ROM), Digital Video Disc (DVD), memory sticks, floppy disks, mechanically encoded devices, such as punch cards or raised structures in grooves on which instructions are stored, and any suitable combination of the foregoing .
这里所描述的计算机可读程序指令或代码可以从计算机可读存储介质下载到各个计算/处理设备,或者通过网络、例如因特网、局域网、广域网和/或无线网下载到外部计算机或外部存储设备。网络可以包括铜传输电缆、光纤传输、无线传输、路由器、防火墙、交换机、网关计算机和/或边缘服务器。每个计算/处理设备中的网络适配卡或者网络接口从网络接收计算机可读程序指令,并转发该计算机可读程序指令,以供存储在各个计算/处理设备中的计算机可读存储介质中。Computer readable program instructions or code described herein may be downloaded to various computing/processing devices from a computer readable storage medium, or to an external computer or external storage device over a network such as the Internet, a local area network, a wide area network and/or a wireless network. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and/or edge servers. A network adapter card or network interface in each computing/processing device receives computer-readable program instructions from a network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing/processing device .
用于执行本申请操作的计算机程序指令可以是汇编指令、指令集架构(Instruction Set Architecture,ISA)指令、机器指令、机器相关指令、微代码、固件指令、状态设置数据、或者以一种或多种编程语言的任意组合编写的源代码或目标代码,所述编程语言包括面向对象的编程语言—诸如Smalltalk、C++等,以及常规的过程式编程语言—诸如“C”语言或类似的编程语言。计算机可读程序指令可以完全地在用户计算机上执行、部分地在用户计算机上执行、作为一个独立的软件包执行、部分在用户计算机上部分在远程计算机上执行、或者完全在远程计算机或服务器上执行。在涉及远程计算机的情形中,远程计算机可以通过任意种类的网络—包括局域网(Local Area Network,LAN)或广域网(Wide Area Network,WAN)—连接到用户计算机,或者,可以连接到外部计算机(例如利用因特网服务提供商来通过因特网连接)。在一些实施例中,通过利用计算机可读程序指令的状态信息来个性化定制电子电路,例如可编程逻辑电路、现场可编程门阵列(Field-Programmable Gate Array,FPGA)或可编程逻辑阵列(Programmable Logic Array,PLA),该电子电路可以执行计算机可读程序指令,从而实现本申请的各个方面。The computer program instructions used to perform the operations of the present application may be assembly instructions, Instruction Set Architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or in one or more source or object code written in any combination of programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server implement. In the case of a remote computer, the remote computer may be connected to the user's computer through any kind of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or, may be connected to an external computer (eg, use an internet service provider to connect via the internet). In some embodiments, electronic circuits, such as programmable logic circuits, Field-Programmable Gate Arrays (FPGA), or Programmable Logic Arrays (Programmable Logic Arrays), are personalized by utilizing state information of computer-readable program instructions. Logic Array, PLA), the electronic circuit can execute computer readable program instructions to implement various aspects of the present application.
这里参照根据本申请实施例的方法、装置(系统)和计算机程序产品的流程图和/或框图描述了本申请的各个方面。应当理解,流程图和/或框图的每个方框以及流程图和/或框图中各方框的组合,都可以由计算机可读程序指令实现。Aspects of the present application are described herein with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the present application. It will be understood that each block of the flowchart illustrations and/or block diagrams, and combinations of blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer readable program instructions.
这些计算机可读程序指令可以提供给通用计算机、专用计算机或其它可编程数据处理装置的处理器,从而生产出一种机器,使得这些指令在通过计算机或其它可编程数据处理装置的处理器执行时,产生了实现流程图和/或框图中的一个或多个方框中规定的功能/动作的装置。也可以把这些计算机可读程序指令存储在计算机可读存储介质中,这些指令使得计算机、 可编程数据处理装置和/或其他设备以特定方式工作,从而,存储有指令的计算机可读介质则包括一个制造品,其包括实现流程图和/或框图中的一个或多个方框中规定的功能/动作的各个方面的指令。These computer readable program instructions may be provided to a processor of a general purpose computer, special purpose computer or other programmable data processing apparatus to produce a machine that causes the instructions when executed by the processor of the computer or other programmable data processing apparatus , resulting in means for implementing the functions/acts specified in one or more blocks of the flowchart and/or block diagrams. These computer readable program instructions can also be stored in a computer readable storage medium, these instructions cause the computer, programmable data processing apparatus and/or other equipment to operate in a specific manner, so that the computer readable medium storing the instructions includes An article of manufacture comprising instructions for implementing various aspects of the functions/acts specified in one or more blocks of the flowchart and/or block diagrams.
也可以把计算机可读程序指令加载到计算机、其它可编程数据处理装置、或其它设备上,使得在计算机、其它可编程数据处理装置或其它设备上执行一系列操作步骤,以产生计算机实现的过程,从而使得在计算机、其它可编程数据处理装置、或其它设备上执行的指令实现流程图和/或框图中的一个或多个方框中规定的功能/动作。Computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other equipment to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other equipment to produce a computer-implemented process , thereby causing instructions executing on a computer, other programmable data processing apparatus, or other device to implement the functions/acts specified in one or more blocks of the flowcharts and/or block diagrams.
附图中的流程图和框图显示了根据本申请的多个实施例的装置、系统、方法和计算机程序产品的可能实现的体系架构、功能和操作。在这点上,流程图或框图中的每个方框可以代表一个模块、程序段或指令的一部分,所述模块、程序段或指令的一部分包含一个或多个用于实现规定的逻辑功能的可执行指令。在有些作为替换的实现中,方框中所标注的功能也可以以不同于附图中所标注的顺序发生。例如,两个连续的方框实际上可以基本并行地执行,它们有时也可以按相反的顺序执行,这依所涉及的功能而定。The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of apparatuses, systems, methods and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of instructions, which comprises one or more functions for implementing the specified logical function(s) executable instructions. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved.
也要注意的是,框图和/或流程图中的每个方框、以及框图和/或流程图中的方框的组合,可以用执行相应的功能或动作的硬件(例如电路或ASIC(Application Specific Integrated Circuit,专用集成电路))来实现,或者可以用硬件和软件的组合,如固件等来实现。It is also noted that each block of the block diagrams and/or flowchart illustrations, and combinations of blocks in the block diagrams and/or flowchart illustrations, can be implemented in hardware (eg, circuits or ASICs (Application) that perform the corresponding functions or actions. Specific Integrated Circuit, application-specific integrated circuit)), or can be implemented by a combination of hardware and software, such as firmware.
尽管在此结合各实施例对本发明进行了描述,然而,在实施所要求保护的本发明过程中,本领域技术人员通过查看所述附图、公开内容、以及所附权利要求书,可理解并实现所述公开实施例的其它变化。在权利要求中,“包括”(comprising)一词不排除其他组成部分或步骤,“一”或“一个”不排除多个的情况。单个处理器或其它单元可以实现权利要求中列举的若干项功能。相互不同的从属权利要求中记载了某些措施,但这并不表示这些措施不能组合起来产生良好的效果。While the invention has been described herein in connection with various embodiments, those skilled in the art will understand and understand from a review of the drawings, the disclosure, and the appended claims in practicing the claimed invention. Other variations of the disclosed embodiments are implemented. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. A single processor or other unit may fulfill the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that these measures cannot be combined to advantage.
以上已经描述了本申请的各实施例,上述说明是示例性的,并非穷尽性的,并且也不限于所披露的各实施例。在不偏离所说明的各实施例的范围和精神的情况下,对于本技术领域的普通技术人员来说许多修改和变更都是显而易见的。本文中所用术语的选择,旨在最好地解释各实施例的原理、实际应用或对市场中的技术的改进,或者使本技术领域的其它普通技术人员能理解本文披露的各实施例。Various embodiments of the present application have been described above, and the foregoing descriptions are exemplary, not exhaustive, and not limiting of the disclosed embodiments. Numerous modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terminology used herein was chosen to best explain the principles of the various embodiments, the practical application or improvement over the technology in the marketplace, or to enable others of ordinary skill in the art to understand the various embodiments disclosed herein.

Claims (25)

  1. 一种数据传输方法,其特征在于,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:A data transmission method, characterized in that the method is applied to a data processing device, the data processing device includes an arithmetic unit and a communication unit, and the method includes:
    所述运算单元对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The computing unit performs first signature processing on the first IoV V2X information at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
    所述运算单元将所述第二V2X信息发送至所述通信单元;the computing unit sends the second V2X information to the communication unit;
    所述通信单元对所述第二V2X信息进行第二签名处理,得到第三V2X信息,所述第三V2X信息包括所述第二V2X信息和第二签名;The communication unit performs second signature processing on the second V2X information to obtain third V2X information, where the third V2X information includes the second V2X information and a second signature;
    所述通信单元发送所述第三V2X信息。The communication unit sends the third V2X information.
  2. 根据权利要求1所述的方法,其特征在于,所述第一签名处理包括:信息摘录、循环冗余CRC校验和数字签名中的一者或多者,其中,所述数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。The method of claim 1, wherein the first signature processing comprises one or more of: information excerpt, cyclic redundancy CRC check, and digital signature, wherein the digital signature comprises country-based The digital signature of the root certificate issued by the certification authority platform, or the digital signature based on the root certificate of the vehicle enterprise self-inspection certification authority platform, or the digital signature based on the root certificate issued by the ecological alliance certification authority platform.
  3. 根据权利要求1或2所述的方法,其特征在于,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。The method according to claim 1 or 2, wherein the data processing device is an in-vehicle device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
  4. 根据权利要求1或2所述的方法,其特征在于,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。The method according to claim 1 or 2, wherein the data processing device is a roadside device, the arithmetic unit comprises a signal machine, and the communication unit comprises a roadside unit RSU.
  5. 一种数据传输方法,其特征在于,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:A data transmission method, characterized in that the method is applied to a data processing device, the data processing device includes an arithmetic unit and a communication unit, and the method includes:
    所述运算单元对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The computing unit performs first signature processing on the first IoV V2X information at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
    所述运算单元通过与所述通信单元之间的安全通道将所述第二V2X信息发送至所述通信单元;The computing unit sends the second V2X information to the communication unit through a secure channel with the communication unit;
    所述通信单元发送所述第二V2X信息。The communication unit sends the second V2X information.
  6. 一种数据传输方法,其特征在于,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:A data transmission method, characterized in that the method is applied to a data processing device, the data processing device includes an arithmetic unit and a communication unit, and the method includes:
    所述通信单元接收第三车联网V2X信息,所述第三V2X信息包括第二V2X信息和第二签名,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The communication unit receives third V2X information of the Internet of Vehicles, the third V2X information includes second V2X information and a second signature, and the second V2X information includes the first V2X information and the first signature of the application layer;
    所述通信单元对所述第二签名进行验证;the communication unit verifies the second signature;
    在所述第二签名验证成功的情况下,所述通信单元将第二V2X信息发送至所述运算单元;In the case that the verification of the second signature is successful, the communication unit sends the second V2X information to the operation unit;
    所述运算单元对所述第一签名进行验证;The computing unit verifies the first signature;
    在所述第一签名验证成功的情况下,所述运算单元对所述第一V2X信息进行信息处理。In the case that the verification of the first signature is successful, the operation unit performs information processing on the first V2X information.
  7. 根据权利要求6所述的方法,其特征在于,所述通信单元对所述第二签名进行验证包括:The method according to claim 6, wherein the verification of the second signature by the communication unit comprises:
    所述通信单元对所述第二V2X信息进行信息摘录处理,得到第一摘要;The communication unit performs information extraction processing on the second V2X information to obtain a first abstract;
    所述通信单元对所述第二签名进行解密处理,得到第二摘要;The communication unit decrypts the second signature to obtain a second digest;
    在所述第一摘要和所述第二摘要相同的情况下,所述通信单元确定所述第二签名验证成功。In the case where the first digest and the second digest are the same, the communication unit determines that the verification of the second signature is successful.
  8. 根据权利要求6或7所述的方法,其特征在于,所述运算单元对所述第一签名进行验证包括:The method according to claim 6 or 7, wherein the verification of the first signature by the computing unit comprises:
    所述运算单元对所述第一签名进行信息摘录校验,或者进行循环冗余CRC校验,或者进行数字签名验证,其中,所述数字签名验证包括基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。The computing unit performs information extraction verification on the first signature, or performs cyclic redundancy CRC verification, or performs digital signature verification, wherein the digital signature verification includes a digital signature based on a root certificate issued by a national certification authority platform. Signature verification, or digital signature verification based on the root certificate of the car company's self-inspection certification agency platform, or digital signature verification based on the root certificate issued by the ecological alliance certification agency platform.
  9. 根据权利要求6至8中任意一项所述的方法,其特征在于,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。The method according to any one of claims 6 to 8, wherein the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
  10. 根据权利要求6至8中任意一项所述的方法,其特征在于,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。The method according to any one of claims 6 to 8, wherein the data processing device is a roadside device, the arithmetic unit includes a signal machine, and the communication unit includes a roadside unit RSU.
  11. 一种数据传输方法,其特征在于,所述方法应用于数据处理装置,所述数据处理装置包括运算单元和通信单元,所述方法包括:A data transmission method, characterized in that the method is applied to a data processing device, the data processing device includes an arithmetic unit and a communication unit, and the method includes:
    所述通信单元接收第二车联网V2X信息,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The communication unit receives the second V2X information of the Internet of Vehicles, where the second V2X information includes the first V2X information and the first signature of the application layer;
    所述通信单元通过与所述运算单元之间的安全通道,将所述第二V2X信息发送至所述运算单元;The communication unit sends the second V2X information to the computing unit through a secure channel with the computing unit;
    所述运算单元对所述第一签名进行验证;The computing unit verifies the first signature;
    在所述第一签名验证成功的情况下,所述运算单元对所述第一V2X信息进行信息处理。In the case that the verification of the first signature is successful, the operation unit performs information processing on the first V2X information.
  12. 一种数据处理装置,其特征在于,所述数据处理装置包括运算单元和通信单元,所述运算单元包括第一签名模块和第一发送模块,所述通信单元包括第二签名模块和第二发送模 块;A data processing device, characterized in that the data processing device includes an operation unit and a communication unit, the operation unit includes a first signature module and a first sending module, and the communication unit includes a second signature module and a second sending module module;
    所述第一签名模块,用于对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The first signature module is configured to perform first signature processing on the first V2X information of the Internet of Vehicles at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
    所述第一发送模块,用于将所述第一签名模块获得的第二V2X信息发送至所述第二签名模块;the first sending module, configured to send the second V2X information obtained by the first signature module to the second signature module;
    所述第二签名模块,用于对所述第一发送模块发送的第二V2X信息进行第二签名处理,得到第三V2X信息,所述第三V2X信息包括所述第二V2X信息和第二签名;The second signature module is configured to perform second signature processing on the second V2X information sent by the first sending module to obtain third V2X information, where the third V2X information includes the second V2X information and the second V2X information. sign;
    所述第二发送模块,用于发送所述第二签名模块获得的第三V2X信息。The second sending module is configured to send the third V2X information obtained by the second signature module.
  13. 根据权利要求12所述的装置,其特征在于,所述第一签名处理包括:信息摘录、循环冗余CRC校验和数字签名中的一者或多者,其中,所述数字签名包括基于国家认证机构平台颁发的根证书的数字签名,或者,基于车企自检认证机构平台根证书的数字签名,或者,基于生态联盟认证机构平台颁发的根证书的数字签名。The apparatus of claim 12, wherein the first signature processing comprises one or more of an information excerpt, a cyclic redundancy CRC check, and a digital signature, wherein the digital signature comprises a country-based The digital signature of the root certificate issued by the certification authority platform, or the digital signature based on the root certificate of the vehicle enterprise self-inspection certification authority platform, or the digital signature based on the root certificate issued by the ecological alliance certification authority platform.
  14. 根据权利要求12或13所述的装置,其特征在于,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。The device according to claim 12 or 13, wherein the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
  15. 根据权利要求12或13所述的装置,其特征在于,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。The apparatus according to claim 12 or 13, wherein the data processing apparatus is a roadside device, the arithmetic unit comprises a signal machine, and the communication unit comprises a roadside unit RSU.
  16. 一种数据处理装置,其特征在于,所述数据处理装置包括运算单元和通信单元,所述运算单元与所述通信单元通过安全通道连接,所述运算单元包括第一签名模块和第一发送模块,所述通信单元包括第二发送模块;A data processing device, characterized in that the data processing device includes an arithmetic unit and a communication unit, the arithmetic unit is connected to the communication unit through a secure channel, and the arithmetic unit includes a first signature module and a first sending module , the communication unit includes a second sending module;
    所述第一签名模块,用于对应用层的第一车联网V2X信息进行第一签名处理,得到第二V2X信息,所述第二V2X信息包括所述第一V2X信息和第一签名;The first signature module is configured to perform first signature processing on the first V2X information of the Internet of Vehicles at the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;
    所述第一发送模块,用于通过所述安全通道将所述第二V2X信息发送至所述第二发送模块;the first sending module, configured to send the second V2X information to the second sending module through the secure channel;
    所述第二发送模块,用于发送所述第二V2X信息。The second sending module is configured to send the second V2X information.
  17. 一种数据处理装置,其特征在于,所述数据处理装置包括运算单元和通信单元,所述通信单元包括接收模块、第一验签模块和发送模块,所述运算单元包括第二验签模块和处理模块;A data processing device, characterized in that the data processing device includes an arithmetic unit and a communication unit, the communication unit includes a receiving module, a first signature verification module and a sending module, and the operational unit includes a second signature verification module and processing module;
    所述接收模块,用于接收第三车联网V2X信息,所述第三车联网V2X信息包括第二V2X信息和第二签名,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The receiving module is configured to receive the third V2X information of the Internet of Vehicles, the third V2X information of the Internet of Vehicles includes the second V2X information and the second signature, and the second V2X information includes the first V2X information and the first V2X information of the application layer. sign;
    所述第一验签模块,用于对所述接收模块接收的第三V2X信息中的第二签名进行验证;the first signature verification module, configured to verify the second signature in the third V2X information received by the receiving module;
    所述发送模块,用于在所述第一验签模块对第二签名验证成功的情况下,将所述第二V2X信息发送至所述第二验签模块;the sending module, configured to send the second V2X information to the second signature verification module when the first signature verification module successfully verifies the second signature;
    所述第二验签模块,用于对所述发送模块发送的第二V2X信息中的第一签名进行验证;the second signature verification module, configured to verify the first signature in the second V2X information sent by the sending module;
    所述处理模块,用于在所述第二验签模块对第一签名验证成功的情况下,对所述第一V2X信息进行信息处理。The processing module is configured to perform information processing on the first V2X information when the second signature verification module successfully verifies the first signature.
  18. 根据权利要求17所述的装置,其特征在于,所述第一验签模块还用于:The device according to claim 17, wherein the first signature verification module is further used for:
    对所述第二V2X信息进行信息摘录处理,得到第一摘要;performing information extraction processing on the second V2X information to obtain a first abstract;
    对所述第二签名进行解密处理,得到第二摘要;Decrypting the second signature to obtain a second digest;
    在所述第一摘要和所述第二摘要相同的情况下,确定所述第二签名验证成功。In the case that the first digest and the second digest are the same, it is determined that the verification of the second signature is successful.
  19. 根据权利要求17或18所述的装置,其特征在于,所述第二验签模块还用于:The device according to claim 17 or 18, wherein the second signature verification module is further used for:
    对所述第一签名进行信息摘录校验、或者进行循环冗余CRC校验,或者进行数字签名验证,其中,所述数字签名验证包括基于国家认证机构平台颁发的根证书的数字签名验证,或者,基于车企自检认证机构平台根证书的数字签名验证,或者,基于生态联盟认证机构平台颁发的根证书的数字签名验证。Performing information extract verification, or performing cyclic redundancy CRC verification, or performing digital signature verification on the first signature, wherein the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, or , based on the digital signature verification of the root certificate of the car company's self-inspection certification agency platform, or, based on the digital signature verification of the root certificate issued by the ecological alliance certification agency platform.
  20. 根据权利要求17至19中任意一项所述的装置,其特征在于,所述数据处理装置为车载设备,所述运算单元包括移动数据中心MDC,所述通信单元包括远程信息处理器TBox。The device according to any one of claims 17 to 19, wherein the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.
  21. 根据权利要求17至19中任意一项所述的装置,其特征在于,所述数据处理装置为路侧设备,所述运算单元包括信号机,所述通信单元包括路侧单元RSU。The device according to any one of claims 17 to 19, wherein the data processing device is a roadside device, the arithmetic unit includes a signal, and the communication unit includes a roadside unit RSU.
  22. 一种数据处理装置,其特征在于,所述数据处理装置包括通信单元和运算单元,所述通信单元和所述运算单元通过安全通道连接,所述通信单元包括接收模块和发送模块,所述运算单元包括验签模块和处理模块;A data processing device, characterized in that the data processing device includes a communication unit and an operation unit, the communication unit and the operation unit are connected through a secure channel, the communication unit includes a receiving module and a sending module, the operation unit The unit includes a signature verification module and a processing module;
    所述接收模块,用于接收第二车联网V2X信息,所述第二V2X信息包括应用层的第一V2X信息和第一签名;The receiving module is configured to receive the second V2X information of the Internet of Vehicles, where the second V2X information includes the first V2X information and the first signature of the application layer;
    所述发送模块,用于通过所述安全通道将所述接收模块接收到的第二V2X信息发送至所述验签模块;the sending module, configured to send the second V2X information received by the receiving module to the signature verification module through the secure channel;
    所述验签模块,用于对所述发送模块发送的第二V2X信息中的第一签名进行验证;the signature verification module, configured to verify the first signature in the second V2X information sent by the sending module;
    所述处理模块,用于在所述验签模块对所述第一签名验证成功的情况下,对所述第一V2X信息进行信息处理。The processing module is configured to perform information processing on the first V2X information when the signature verification module successfully verifies the first signature.
  23. 一种数据处理装置,其特征在于,包括:A data processing device, comprising:
    处理器;processor;
    用于存储处理器可执行指令的存储器;memory for storing processor-executable instructions;
    其中,所述处理器被配置为执行所述指令时实现权利要求1至4中任意一项所述的方法,或者实现权利要求5所述的方法,或者实现权利要求6至10中任意一项所述的方法,或者实现权利要求11所述的方法。wherein the processor is configured to implement the method of any one of claims 1 to 4, or to implement the method of claim 5, or to implement any one of claims 6 to 10 when executing the instructions the method, or implement the method of claim 11 .
  24. 一种计算机可读存储介质,其上存储有计算机程序指令,其特征在于,所述计算机程序指令被处理器执行时实现权利要求1至4中任意一项所述的方法,或者实现权利要求5所述的方法,或者实现权利要求6至10中任意一项所述的方法,或者实现权利要求11所述的方法。A computer-readable storage medium on which computer program instructions are stored, characterized in that, when the computer program instructions are executed by a processor, the method described in any one of claims 1 to 4 is implemented, or the method in claim 5 is implemented. The method, or implement the method of any one of claims 6 to 10, or implement the method of claim 11.
  25. 一种计算机程序产品,包括计算机可读代码,或者承载有计算机可读代码的计算机可读存储介质,当所述计算机可读代码被处理器执行时实现权利要求1至4中任意一项所述的方法,或者实现权利要求5所述的方法,或者实现权利要求6至10中任意一项所述的方法,或者实现权利要求11所述的方法。A computer program product, comprising computer-readable codes, or a computer-readable storage medium carrying computer-readable codes, when the computer-readable codes are executed by a processor, the implementation of any one of claims 1 to 4 is realized , or implement the method of claim 5 , or implement the method of any one of claims 6 to 10 , or implement the method of claim 11 .
PCT/CN2022/085552 2021-04-16 2022-04-07 Data transmission method and data processing apparatus WO2022218205A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110412576.9A CN115226060A (en) 2021-04-16 2021-04-16 Data transmission method and data processing device
CN202110412576.9 2021-04-16

Publications (1)

Publication Number Publication Date
WO2022218205A1 true WO2022218205A1 (en) 2022-10-20

Family

ID=83604288

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/085552 WO2022218205A1 (en) 2021-04-16 2022-04-07 Data transmission method and data processing apparatus

Country Status (2)

Country Link
CN (1) CN115226060A (en)
WO (1) WO2022218205A1 (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109584595A (en) * 2019-01-14 2019-04-05 北京交通大学 Based on the road conditions method for early warning and system of block chain in vehicle-mounted net
CN111212400A (en) * 2020-01-14 2020-05-29 南京如般量子科技有限公司 Anti-quantum computing internet-of-vehicle system based on secret sharing and mobile terminal and authentication method thereof
US20200235946A1 (en) * 2019-01-23 2020-07-23 Electronics And Telecommunications Research Institute Security management system for vehicle communication, operating method thereof, and message-processing method of vehicle communication service provision system having the same
CN111447591A (en) * 2020-02-18 2020-07-24 江苏荣泽信息科技股份有限公司 Vehicle networking data exchange method based on block chain
CN109845185B (en) * 2016-10-31 2020-11-10 华为技术有限公司 Data transmission method, terminal, node equipment and system

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109845185B (en) * 2016-10-31 2020-11-10 华为技术有限公司 Data transmission method, terminal, node equipment and system
CN109584595A (en) * 2019-01-14 2019-04-05 北京交通大学 Based on the road conditions method for early warning and system of block chain in vehicle-mounted net
US20200235946A1 (en) * 2019-01-23 2020-07-23 Electronics And Telecommunications Research Institute Security management system for vehicle communication, operating method thereof, and message-processing method of vehicle communication service provision system having the same
CN111212400A (en) * 2020-01-14 2020-05-29 南京如般量子科技有限公司 Anti-quantum computing internet-of-vehicle system based on secret sharing and mobile terminal and authentication method thereof
CN111447591A (en) * 2020-02-18 2020-07-24 江苏荣泽信息科技股份有限公司 Vehicle networking data exchange method based on block chain

Also Published As

Publication number Publication date
CN115226060A (en) 2022-10-21

Similar Documents

Publication Publication Date Title
US11652643B2 (en) Verification method, verification apparatus, and storage medium including program stored therein
CN106209777A (en) A kind of automatic driving car on-vehicle information interactive system and safety communicating method
US20200235946A1 (en) Security management system for vehicle communication, operating method thereof, and message-processing method of vehicle communication service provision system having the same
US11049402B2 (en) Cryptography-based platooning mechanism for autonomous vehicle fleet management
EP3404639A1 (en) Vehicle operation
CN102984196A (en) Vehicle authentication sending method based on identity authentication and vehicle terminal
US20230246849A1 (en) Verification method, verification apparatus, and storage medium including program stored therein
WO2018108293A1 (en) Methods, devices and vehicles for authenticating a vehicle during a cooperative maneuver
Yao et al. Accident responsibility identification model for Internet of Vehicles based on lightweight blockchain
KR101086900B1 (en) Surrounding vehicles position identifying system using base station and identifying method between the base station and the vehicles
WO2022218205A1 (en) Data transmission method and data processing apparatus
US20230034996A1 (en) Data verification method and apparatus
CN112866397B (en) Data storage method and Internet of vehicles system
DE102021133367A1 (en) SESSION KEY GENERATION FOR AN OPERATION OF AUTONOMOUS VEHICLES
CN114265815A (en) Traffic media data storage method, server, storage medium and system
US11231724B2 (en) Dynamic management of insertions of vehicles
JP2022528362A (en) Safe vehicle communication architecture to improve blind spot and mileage detection
WO2022142895A1 (en) Vehicle-to-everything-based information transmission method and related device thereof
WO2023006028A1 (en) Information processing method, electronic system, electronic device, and storage medium
US20240056297A1 (en) Establishing trust by a community of vehicles
Kanáliková et al. Trends in the area of security within c2c communications
EP3618385B1 (en) Method and arrangement for encoding/decoding a signal at a first and second communication node in a road vehicle
JP2022076310A (en) Vehicle data storage method and vehicle data storage system
El-Said et al. A Lightweight Message Authentication Framework in the Intelligent Vehicles System
CN112584346A (en) New generation of car networking communication architecture based on block chain technology

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22787431

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 22787431

Country of ref document: EP

Kind code of ref document: A1