WO2023284658A1 - Vehicle communication method and device - Google Patents

Vehicle communication method and device Download PDF

Info

Publication number
WO2023284658A1
WO2023284658A1 PCT/CN2022/104804 CN2022104804W WO2023284658A1 WO 2023284658 A1 WO2023284658 A1 WO 2023284658A1 CN 2022104804 W CN2022104804 W CN 2022104804W WO 2023284658 A1 WO2023284658 A1 WO 2023284658A1
Authority
WO
WIPO (PCT)
Prior art keywords
vehicle
pilot
certificate
session key
car
Prior art date
Application number
PCT/CN2022/104804
Other languages
French (fr)
Chinese (zh)
Inventor
彭宇才
朱锦涛
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2023284658A1 publication Critical patent/WO2023284658A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/009Security arrangements; Authentication; Protecting privacy or anonymity specially adapted for networks, e.g. wireless sensor networks, ad-hoc networks, RFID networks or cloud networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • H04W12/033Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/30Services specially adapted for particular environments, situations or purposes
    • H04W4/40Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
    • H04W4/46Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P] for vehicle-to-vehicle communication [V2V]

Definitions

  • the present application relates to the technical field of automatic driving, and in particular to a method and device for vehicle communication.
  • the front vehicle can act as a "leading vehicle”, and then it is composed of several self-driving vehicles, which advance in a formation. Members maintain a certain distance between vehicles and a stable speed, and cruise in an orderly driving state.
  • V2X vehicle to everything, vehicle to everything
  • V2X is based on an open wireless communication network, which is easier than traditional networks. Being attacked will also cause greater damage to the field of vehicle platooning mainly based on V2X communication. Therefore, in the scenario of autonomous vehicle platooning, higher requirements are put forward for the security of V2X communication.
  • Embodiments of the present application provide a vehicle communication method and device for implementing secure communication between vehicles.
  • the embodiment of the present application provides a method for vehicle communication, which can be applied to the pilot car, and the method includes: receiving a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used for Instructing the target vehicle to request entry into the team; in response to the entry request message, sending an entry response message to the target vehicle; wherein the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle, and the pilot car's certificate, the first ciphertext is obtained by the pilot car encrypting the first session key according to the public key of the target vehicle's certificate; and the first identification can be used to indicate that the target vehicle encrypts the first session key according to the private key of its own certificate.
  • a ciphertext is decrypted to obtain the first session key and the certificate of the pilot car.
  • the pilot car uses the public key of the target vehicle's certificate to encrypt and transmit the first session key.
  • the security and reliability of key transmission can be effectively improved, thereby enabling safe communication between vehicles, thereby effectively improving the information security and network security performance of vehicle communication.
  • the pilot car may also generate a first session key before receiving the queue entry request message.
  • the first session key is used to encrypt the broadcast information between vehicles, and then the pilot car can encrypt the first session key and transmit it to other vehicles in the fleet, so that other vehicles can use the first session
  • the key encrypts and transmits the broadcast information.
  • the pilot vehicle can generate the first session key without performing key negotiation with multiple vehicles before receiving the queue request message. In this way, the time delay of key generation is effectively reduced, so that the target vehicles waiting to join the queue can use the first session key to encrypt and transmit the broadcast information more quickly.
  • the pilot vehicle can also receive a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests to dequeue; and then the pilot vehicle can send a dequeue response message in response to the dequeue request message to Instruct the target vehicle to perform dequeue operation.
  • the pilot car can manage the vehicles in the fleet, and when receiving the request message of the target vehicle leaving the team, the pilot car can respond to instruct the target vehicle to leave the team.
  • the pilot car after the pilot car sends the team-out response message, it can also send a first notification message to other vehicles in the convoy where the pilot car is located; wherein, the first notification message includes the first signature information, the pilot The second identification and the second ciphertext corresponding to the certificates of other vehicles in the vehicle fleet, the first signature information is used to indicate the identity information of the pilot car, and the second ciphertext is the public key pair of the pilot car according to the certificate of the other vehicle obtained by encrypting the second session key; furthermore, the second identification is used to instruct the other vehicle to decrypt the second ciphertext according to the private key of its certificate, so as to obtain the second session key, The first notification message is used to instruct other vehicles to verify the identity of the pilot car according to the certificate of the pilot car and the first signature information.
  • the pilot vehicle encrypts and transmits the second session key to other vehicles in the team according to the public key of the other vehicle's certificate. In this way, the transmission of the second session key is made more reliable, which helps to improve the security of communication between vehicles.
  • the pilot vehicle may also generate a second session key; the second session key is used to encrypt broadcast information between vehicles.
  • broadcast information between vehicles may be broadcast information between any two vehicles in the convoy, or may be broadcast information between the pilot vehicle and other vehicles, and there is no specific limitation here.
  • the pilot car can generate a new session key (that is, the second session key) after the target vehicle that requests to leave the team, and encrypt and transmit the second session key to other vehicles in the fleet .
  • a new session key that is, the second session key
  • updating the session key in time helps to improve the security and reliability of communication between vehicles.
  • the embodiment of the present application also provides a vehicle communication method, which can be applied to the target vehicle, and the method includes: sending a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used for Instructing the target vehicle to request entry into the team; receiving the entry response message corresponding to the entry request message; the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle and the certificate of the pilot car, the first encryption
  • the text is obtained by the pilot car encrypting the first session key according to the public key of the target vehicle's certificate, and the first identifier can be used to indicate that the target vehicle encrypts the first session key according to the private key of its own certificate. Decrypt the text to obtain the first session key, and obtain the certificate of the pilot car; decrypt the first ciphertext according to the private key of the certificate of the target vehicle to obtain the first session key, and obtain the pilot car's Certificate.
  • the target vehicle may also send a dequeue request message; the dequeue request message is used to instruct the target vehicle to request dequeue; receive a dequeue response message corresponding to the dequeue request message, and execute the dequeue operation.
  • the embodiment of the present application also provides a vehicle communication method, which can be applied to the original pilot vehicle.
  • the original pilot vehicle can initiate a pilot vehicle switching request
  • the target pilot vehicle can also initiate a switching request.
  • Mode 1 The original pilot vehicle receives a switching request message from the target pilot vehicle; in response to the switching request message, the original pilot vehicle sends a switching response message to the target pilot vehicle, and the switching request response message is used to instruct the target pilot vehicle to switch the pilot vehicle.
  • Mode 2 The original pilot car sends a switch request message to the target pilot car, and receives a switch response message corresponding to the switch request message, the switch response message is used to instruct the original pilot car to switch the pilot car; Toggle to get the updated fleet.
  • the original pilot car may initiate a pilot car switching request to the target pilot car, or may receive a switching request from the pilot car and perform pilot car switching.
  • the flexible management of the fleet is realized, which can effectively meet the business needs of different scenarios.
  • the original pilot car can also send a second notification message; wherein, the second notification message includes the second signature information and the certificate of the target pilot car, and the second signature information is used to indicate the identity information of the original pilot car ;
  • the second notification message is used to instruct the original pilot car to verify the identity of the original pilot car according to the certificate of the original pilot car and the second signature information according to other vehicles in the fleet, and obtain the certificate of the target pilot car when the verification is passed.
  • the original pilot car sends a second notification message to other vehicles in its convoy after switching the pilot car to notify other vehicles to update the certificate of the pilot car. In this way, other vehicles in the convoy can obtain the information of the target leading vehicle in time.
  • the embodiment of the present application provides a vehicle communication method, which can be applied to the target pilot vehicle.
  • the original pilot vehicle can initiate the pilot vehicle switching request, and the target pilot vehicle can also initiate the switching request.
  • Mode 1 The target pilot vehicle sends a switching request message to the original pilot vehicle; the target pilot vehicle receives a switching response message corresponding to the switching request message, and the switching response message is used to instruct the target pilot vehicle to switch the pilot vehicle; Toggle to get the updated fleet.
  • Mode 2 The target pilot vehicle receives a switching request message from the original pilot vehicle; in response to the switching request message, the target pilot vehicle sends a switching response message to the original pilot vehicle, and the switching response message is used to instruct the original pilot vehicle to switch the pilot vehicle.
  • the target pilot vehicle may also generate a third session key after the pilot vehicle switches, and the third session key is used to encrypt broadcast information between vehicles.
  • the target pilot vehicle can generate the third session key after the pilot vehicle switch is successful. In this way, updating the session key in time helps to improve the security and reliability of the communication between vehicles.
  • the target pilot vehicle after the target pilot vehicle generates the third session key, it can also send a third notification message; wherein, the third notification message includes the third signature information, and the third session key corresponding to the target pilot vehicle certificate.
  • the third signature information is used to indicate the identity information of the target pilot vehicle, and the third ciphertext is obtained by the target pilot vehicle encrypting the third session key according to the first session key;
  • the third identification is used to indicate that other vehicles in the updated convoy except the target pilot vehicle decrypt the third ciphertext according to the first session key to obtain the third session key;
  • the third notification message is used to indicate that after the update Vehicles other than the target pilot vehicle in the convoy verify the identity of the target pilot vehicle according to the certificate of the target pilot vehicle and the third signature information.
  • the target pilot vehicle will use the first session key to encrypt and transmit the third session key, and transmit its own third signature information to other vehicles in the updated fleet.
  • other vehicles can verify the identity of the target pilot car and decrypt the encrypted new key according to the original session key, thereby reducing the time delay for other vehicles to obtain a new session key, which helps to improve communication between vehicles safety and reliability.
  • the target pilot vehicle after the target pilot vehicle sends the third notification message, it can also receive pilot vehicle update response information from other vehicles; the pilot vehicle update response message is used to indicate that other vehicles have obtained the information of the target pilot vehicle; Furthermore, the target pilot vehicle may send a fourth notification message to instruct other vehicles to use the third session key to encrypt the broadcast information.
  • the target pilot car after receiving the pilot car update response message from other vehicles, the target pilot car sends a notification message to the other vehicle to instruct other vehicles to use the third session key to encrypt the broadcast information. In this way, it helps to improve the safety and reliability of communication between vehicles.
  • the embodiment of the present application also provides a vehicle communication method, which can be applied to a server, and the method includes: receiving a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message Including the identification of the fleet and the vehicle identification in the fleet; in response to the fleet creation notification message, a first response message is sent; the first response message is used to instruct the pilot car to obtain the first session key, and the first session key is used for Broadcast messages between vehicles in the fleet are encrypted.
  • the server may receive the fleet creation notification message, and in response to the fleet creation notification message, send the first session key to the pilot car, so that the broadcast information between vehicles in the fleet can be based on the first session key. key to encrypt. In this way, the server can manage the fleet, which helps to improve the safety and reliability of communication between vehicles.
  • the server may also receive an entry request notification message; the entry request notification message is used to indicate that the first vehicle requests entry into the queue; in response to the entry request notification message, the first session key is sent to the second vehicle. a vehicle.
  • the server can realize the management of the session key of the fleet, and when it is determined that there are vehicles to be entered, the first session key is sent to the vehicle to be entered, so that the vehicle to be entered can use the first session key pair Broadcast information is encrypted. In this way, it helps to improve the safety and reliability of communication between vehicles.
  • the server may also receive a dequeue request notification message; the dequeue request notification message is used to indicate that the second vehicle requests to dequeue, and the dequeue request notification message includes the identifier of the fleet and the vehicle identifier of the second vehicle; In response to the notification message of the request to leave the team, according to the identification of the fleet and the vehicle identification of the second vehicle, determine the updated fleet, and send the second session key to each vehicle in the updated fleet; the second session key Used to encrypt broadcast messages between vehicles in the updated fleet.
  • the server can realize the management of the session key of the fleet, and after determining that a vehicle leaves the team, send the updated session key (ie, the second session key) to the updated fleet, so that the updated Other vehicles in the fleet can encrypt broadcast messages using the second session key. In this way, it helps to improve the safety and reliability of communication between vehicles.
  • the server can also receive the pilot car switching notification message; the pilot car switching notification message also includes the identification of the fleet and the vehicle identification of the target pilot car; in response to the pilot vehicle switching notification message, according to the identification of the fleet and The vehicle identification of the target pilot car to switch the pilot car.
  • the server can realize the flexible management of the fleet, and can flexibly switch the pilot car according to the needs of the vehicles in the fleet, which helps to improve the safety and reliability of the communication between vehicles.
  • the server can also generate a third session key, and send the third session key to other vehicles in the fleet, and the third session key is used to The broadcast information between vehicles is encrypted.
  • the server can realize the management of the session key of the fleet. After the pilot car is switched, a new session key (ie, the third session key) is generated so that other vehicles in the updated fleet can use The new session key encrypts broadcast information. In this way, updating the session key in time helps to improve the security and reliability of communication between vehicles.
  • a new session key ie, the third session key
  • the embodiment of the present application also provides a vehicle communication method, which can be applied to the pilot car, and the method includes: sending a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot car has created a fleet; the fleet creation notification The message includes the identification of the fleet and the vehicle identification in the fleet; receiving the first response message corresponding to the creation notification message of the fleet; the first response message carries the first session key; the first session key is used for the communication between the vehicles Broadcast information is encrypted.
  • the pilot vehicle may also send a queue entry request notification message; the queue entry request notification message is used to indicate that the first vehicle requests to enter the queue.
  • the pilot car can also send a team-out request notification message; the team-out request notification message is used to indicate that the second vehicle requests to leave the team, and the team-out request notification message includes the identification of the team and the vehicle identification of the second vehicle ; Receive a second response message corresponding to the dequeue request notification message; the second response message carries a second session key, and the second session key is used to broadcast information between vehicles in the updated fleet Encryption; the updated fleet is determined according to the identifier of the fleet and the vehicle identifier of the second vehicle.
  • the pilot car can also send a pilot car switching notification message;
  • the pilot car switching notification message includes the identification of the fleet and the vehicle identification of the target pilot car;
  • the pilot car switching notification message is used to instruct the server to and the vehicle identification of the target pilot car to switch the pilot car.
  • the pilot vehicle can also receive the third session key, and encrypt the broadcast information between vehicles in the convoy according to the third session key.
  • the embodiment of the present application provides a device for vehicle communication.
  • the device may include:
  • a receiving module configured to receive a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used to indicate that the target vehicle requests to join the team;
  • a sending module configured to send a queue-entry response message to the target vehicle in response to the queue-entry request message
  • the entry response message includes a first ciphertext, a first identification corresponding to the certificate of the target vehicle, and a certificate of the pilot vehicle
  • the first ciphertext is the ciphertext of the pilot vehicle according to the certificate of the target vehicle.
  • the first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key key, and obtain the certificate of the pilot car.
  • the embodiment of the present application provides a vehicle communication device.
  • the device includes:
  • a sending module configured to send a team entry request message;
  • the team entry request message includes the certificate of the target vehicle, and the team entry request message is used to indicate that the target vehicle requests to join the team;
  • a receiving module configured to receive an entry response message corresponding to the entry request message;
  • the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle, and the certificate of the pilot vehicle, so
  • the first ciphertext is obtained by the pilot car encrypting the first session key according to the public key of the target vehicle's certificate, and the first identifier is used to indicate that the target vehicle key to decrypt the first ciphertext to obtain the first session key, and obtain the certificate of the pilot car;
  • a processing module configured to decrypt the first ciphertext according to the private key of the target vehicle's certificate to obtain the first session key, and obtain the pilot vehicle's certificate.
  • the embodiment of the present application provides a device for vehicle communication.
  • the device may include:
  • the receiving module is configured to receive a switch request message from the target pilot vehicle; the sending module is configured to send a switch response message to the target pilot vehicle in response to the switch request message, and the switch request response message is used to indicate the The target pilot car performs pilot car switching; or,
  • a sending module configured to send a switching request message to the target pilot vehicle;
  • a receiving module configured to receive a switching response message corresponding to the switching request message, and the switching response message is used to instruct the original pilot vehicle to switch the pilot vehicle;
  • the embodiment of the present application provides a vehicle communication device.
  • the device includes:
  • the sending module is used to send a switching request message to the original pilot vehicle; the receiving module is used to receive a switching response message corresponding to the switching request message, and the switching response message is used to instruct the target pilot vehicle to switch the pilot vehicle; processing Module, used to switch the pilot car to get the updated fleet; or,
  • the receiving module is configured to receive a switch request message from the original pilot vehicle; the sending module is configured to send a switch response message to the original pilot vehicle in response to the switch request message, and the switch response message is used to instruct the original pilot vehicle to perform Pilot car switch.
  • the embodiment of the present application provides a vehicle communication device, which can be used to realize the function of a server.
  • the device may include:
  • the receiving module is configured to receive a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message includes the identification of the fleet and the vehicle identification in the fleet;
  • a sending module configured to send a first response message in response to the fleet creation notification message; the first response message is used to instruct the pilot vehicle to acquire a first session key, and the first session key is used for Broadcast messages between vehicles in the fleet are encrypted.
  • the embodiment of the present application provides a vehicle communication device.
  • the device includes:
  • the sending module is used to send a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message includes the identification of the fleet and the vehicle identification in the fleet;
  • a receiving module configured to receive a first response message corresponding to the fleet creation notification message; the first response message carries a first session key; the first session key is used to perform broadcast information between vehicles encryption.
  • the embodiment of the present application provides a server, where the server includes a processor, and the processor is configured to execute the method described in the above fifth aspect and any possible design of the above fifth aspect.
  • the server is a single server or a server cluster composed of multiple sub-servers.
  • the server is a server cluster composed of multiple sub-servers
  • the multiple sub-servers jointly perform the above fifth aspect and any of the above fifth aspects.
  • a possible design is described in the method.
  • the embodiment of the present application provides a vehicle, the vehicle may include a processor, and the processor is used to execute the above-mentioned first to fourth aspects, and the sixth aspect, and the above-mentioned first to fourth aspects, and the first aspect Any of the six possible designs are described in the method.
  • the embodiment of the present application provides a chip system, the chip system includes at least one processor, when the program instructions are executed in the at least one processor, so that the above first to sixth aspects and the above first The method described in any one of the optional designs from the aspect to the sixth aspect is realized.
  • the chip system further includes a communication interface, which is used for inputting or outputting information.
  • the system-on-a-chip further includes a memory, which is coupled to the processor through a communication interface and used to store the above-mentioned instructions, so that the processor can read the instructions stored in the memory through the communication interface.
  • the foregoing processor may be a processing circuit, which is not limited in the present application.
  • the embodiment of the present application also provides a computer program product including instructions, when it is run on the above-mentioned device, to execute the above-mentioned first to sixth aspects and the above-mentioned first to sixth aspects Any one of the described methods is implemented in an alternative design.
  • an embodiment of the present application provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is run, the above-mentioned first to sixth aspects and the above-mentioned first The method described in any one of the optional designs from the aspect to the sixth aspect.
  • FIG. 1 is a schematic diagram of a system architecture provided by an embodiment of the present application.
  • FIG. 2 is a schematic diagram of another system architecture provided by the embodiment of the present application.
  • FIG. 3 is a schematic flowchart of a vehicle communication method provided in Embodiment 1 of the present application.
  • FIG. 4 is a schematic flowchart of another vehicle communication method provided in Embodiment 1 of the present application.
  • FIG. 5 is a schematic flowchart of another vehicle communication method provided in Embodiment 1 of the present application.
  • FIG. 6 is a schematic flowchart of a vehicle communication method provided in Embodiment 2 of the present application.
  • FIG. 7 is a schematic flowchart of another vehicle communication method provided in Embodiment 2 of the present application.
  • FIG. 8 is a schematic flowchart of another vehicle communication method provided in Embodiment 2 of the present application.
  • FIG. 9 is a schematic flowchart of another vehicle communication method provided in Embodiment 2 of the present application.
  • FIG. 10 is a schematic structural diagram of a vehicle communication device provided in an embodiment of the present application.
  • Fig. 11 is a schematic structural diagram of another vehicle communication device provided by an embodiment of the present application.
  • FIG. 12 is a schematic structural diagram of a chip system provided by an embodiment of the present application.
  • Certificate refers to a digital certificate, which is a document digitally signed by a certificate authority (CA) that contains public key owner information and a public key, and is used for identity authentication of both communication parties.
  • a certificate generally includes certificate version number (version), serial number (serial number), signature algorithm identifier (signature), issuer name (issuer), subject public key information (subject public key info), validity period (validity) and other information; It can also contain the issuer's identifier (issuer unique identifier), subject identifier (subject unique identifier) and other extended information (extensions).
  • the embodiment of this application relates to the certificate of the vehicle, which corresponds to a public key and a private key, and in the process of communication between vehicles, the vehicle can use the public key and private key of the certificate to perform corresponding encryption and decryption operations.
  • Signature information Refers to a digital certificate, which is a document digitally signed by a certificate authority (CA) that contains public key owner information and a public key, and is used for identity authentication of both communication parties.
  • CA certificate authority
  • the signature information in this embodiment of the application is used to verify the identity information of the vehicle.
  • Pilot car used to manage the vehicle information of any vehicle in the fleet, such as vehicle identification, vehicle number or vehicle certificate, etc.
  • the pilot vehicle is also used to determine a session key and send the session key to other vehicles in the fleet so that the other vehicles use the session key for encrypted communications.
  • Target vehicle In some embodiments, the target vehicle is a free vehicle to be enqueued. In some other embodiments, the target vehicle is a follow-up vehicle for applying to leave the team. The target vehicle is mainly used to interact with the pilot car, determine the session key, and use the session key for encrypted communication.
  • Follower car refers to the vehicle that follows the lead car in the convoy.
  • Free vehicles Refers to vehicles outside the convoy that have not joined the convoy.
  • the vehicle number is a continuous and non-repeating positive integer.
  • the vehicle numbers are 1, 2, 3...n, n is a positive integer, and each vehicle in the fleet has a different vehicle number.
  • the communication manner between the vehicle and the application server may be a V2X communication manner.
  • the server may be a vehicle network application server (V2X application server, V2X AS).
  • PC5 direct connection communication interface: the communication interface between terminals, that is, the short-distance direct communication interface between vehicles, people, and road infrastructure; its characteristics are: through direct connection, broadcasting, and network scheduling Realize low-latency, high-capacity, and highly reliable communications.
  • the term “multiple” in the embodiments of the present application means two or more.
  • “And/or” describes the association relationship of associated objects, indicating that there can be three types of relationships, for example, A and/or B, which can mean: A exists alone, A and B exist at the same time, and B exists alone, where A, B can be singular or plural.
  • the character “/” generally indicates that the contextual objects are an “or” relationship.
  • “At least one of the following” or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one item (piece) of a, b, or c may represent: a, b, c, a and b, a and c, b and c, or a and b and c.
  • first and second are used to distinguish multiple objects, and are not used to limit the order, timing, priority or priority of multiple objects. Importance.
  • first notification message and the second notification message are only for distinguishing different notification messages, and do not represent the difference in content, priority or importance of the two notification messages.
  • an embodiment of the present application provides a vehicle communication method and device.
  • the pilot vehicle communicates with the target vehicle, and uses the public key of the target vehicle's certificate to encrypt the first session.
  • the key is encrypted and transmitted, so that the target vehicle can safely obtain the session key, thereby effectively improving the security and reliability of the key transmission, thereby enabling safe communication between vehicles, thereby reducing the risk of confidential information being stolen between vehicles risk.
  • the first embodiment please refer to the first embodiment below.
  • the embodiment of the present application also provides another vehicle communication method and device, in this method, the pilot vehicle and the server communicate and interact to obtain the first session key, And based on the first session key, the broadcast information is encrypted and transmitted, thereby effectively improving the security and reliability of key transmission, thereby enabling safe communication between vehicles, and the first session key is generated by the server, which can effectively reduce Delay for other vehicles in the fleet to obtain session keys.
  • the second embodiment please refer to the second embodiment below.
  • FIG. 1 shows a schematic diagram of a system architecture applicable to this embodiment of the present application.
  • the system architecture includes a leading car 1, a following car 2, a following car 3, a following car 4 and a free car 5.
  • the leading car 1, the following car 2, the following car 3 and the following car 4 form a fleet, and the following car 2, the following car 3 and the following car 4 travel under the leadership of the leading car 1; any two cars can A communication connection is established through a communication network for communication interaction.
  • the pilot car 1 can generate the first session key, and encrypt and transmit the first session key to the following car 2, the following car 3, and the following car 4, and then the following car 2, the following car 3, and the following car 4 can be based on
  • the first session key encrypts and transmits the broadcast information between them, so as to improve the security of the communication between the vehicles.
  • free car 5 is a free car outside the convoy.
  • the pilot vehicle 1 can communicate with the free vehicle 5 .
  • the free car 5 can send an enlisting request message containing the certificate of the free car 5 to the pilot car 1, and the pilot car 1 responds to the request message, and the pilot car encrypts the first session key with the public key of the certificate of the free car 5 Transmit to free car 5, and send the certificate of the pilot car of lead car 1 to free car 5, so that free car 5 can join the team.
  • the two vehicles shown in Fig. 1 are only an example, and are not intended to limit this application. In practical applications, more vehicles may be included in a fleet, and this application does not limit the number of vehicles in the fleet.
  • the architecture shown in Figure 1 can be applied to various communication scenarios, for example, the fifth generation (the 5th generation, 5G) communication system, the future sixth generation communication system and other evolved communication systems, the fourth generation (the 4th generation, 4G) communication system, vehicle to everything (V2X), long-term evolution-vehicle networking (LTE-vehicle, LTE-V), vehicle to vehicle (vehicle to vehicle, V2V), vehicle networking, machine Communications such as machine type communications (MTC), Internet of things (IoT), long-term evolution-machine to machine (LTE-machine to machine, LTE-M), machine to machine (machine to machine, M2M) In the scenario, this application does not limit it.
  • MTC machine type communications
  • IoT Internet of things
  • LTE-machine to machine LTE
  • system architecture applicable to the embodiments of the present application may further include a server.
  • FIG. 2 shows a schematic diagram of another system architecture applicable to this embodiment of the present application.
  • the server 6 can communicate with any vehicle in the fleet.
  • the server 6 may receive the fleet creation notification message from the pilot car 1, and in response to the fleet creation notification message, send the first session key to the pilot car 1, so that the pilot car 1
  • the session key encrypts the data that needs to be interacted between vehicles, so as to realize secure communication between vehicles.
  • the free car 5 in the stationary or driving state initiates a broadcast message "creating a fleet" to other vehicles in the preset driving area. Broadcast the information of the pilot car.
  • the attribute and role of the free car 5 are transformed into a following car, and its own driving state is set as a following state, and broadcasts its own state information. If the pilot car 1 does not agree with the free car 5 to join the team, then ignore the free car 5, and the role of the free car 5 continues to maintain the free car type.
  • Follower car 2 sends an application message to lead car 1. After receiving the message, lead car 1 agrees to leave the team with follower car 2 and sends a response message to follower car 2. After receiving the response message, follower car 2 Finally, set the driving state of the vehicle to leave the team, and broadcast until the follower car 2 completely leaves the team, and set its own role as a free car; the lead car 1 confirms that the follower car 2 can leave the team, and then removes the vehicle identification of the follower car 2 from the team Information list, and added to the queue list.
  • the pilot car 1 can send a pilot car switching request message to the following car 2, and after receiving the confirmation response from the following car 2, switch the pilot car; or, the following car 2 can send a message to the pilot car 1.
  • the pilot car switching request message, and after receiving the confirmation response from the pilot car A, the pilot car switching is performed.
  • the free car 5 , the following car 2 , and the leading car 1 described above are only exemplary descriptions given in conjunction with FIG. 1 , and are not limited in this embodiment of the present application.
  • Fig. 3 shows a vehicle communication method provided by Embodiment 1 of the present application. This method can be applied to the system architecture shown in Fig. 1. This method mainly involves the scene where the target vehicle requests to join the team. The method includes the following process :
  • the target vehicle sends a queue entry request message to the pilot vehicle, and the pilot vehicle receives the queue entry request message.
  • the entry request message carries the certificate of the target vehicle.
  • the certificate of the target vehicle is issued for the target vehicle by the vehicle certification authority, and is used to uniquely identify the legal identity of the target vehicle.
  • the certificate of the target vehicle may be pre-configured in the target vehicle by the vehicle manager, or may be obtained through communication and interaction between the target vehicle and the vehicle certificate issuing authority, which is not limited in this embodiment of the present application.
  • the pilot vehicle sends a queue entry response message to the target vehicle, and the target vehicle receives the queue entry response message.
  • the entry response message carries the first ciphertext, the first identification corresponding to the certificate of the target vehicle, and the certificate of the pilot vehicle.
  • the certificate of the pilot car can be used to verify the identity of the pilot car.
  • the first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key, and to obtain the certificate of the pilot vehicle.
  • the first identifier may be a HashID corresponding to the certificate of the target vehicle.
  • the pilot vehicle may encrypt the first session key according to the public key of the certificate of the target vehicle to obtain the first ciphertext. In this way, the secure transmission of the first session key is effectively realized, and the risk of the first session key being stolen is effectively reduced.
  • first session key may be pre-generated by the pilot vehicle and stored locally, or may be generated by the pilot vehicle after receiving the enqueue request message from the target vehicle, which is not specifically limited here.
  • the process of creating a fleet by the pilot car can be: the pilot car selects one or more free vehicles in the preset area of the pilot car to form a fleet with the pilot car according to information such as the position and driving direction of the vehicle, One or more free cars send fleet creation requests; after the one or more free cars agree to form a fleet, they send a confirmation response message to the pilot car, and the pilot car receives the confirmation response message and compiles one or more free cars in the fleet number.
  • the team leader car may also store information such as certificates and vehicle identifications of each vehicle in the convoy.
  • the identifier of the vehicle may be a vehicle identification number (vehicle identification number, VIN).
  • VIN vehicle identification number
  • the VIN may be assigned to the vehicle by the manufacturer, and each vehicle has its own unique VIN.
  • the target vehicle decrypts the first ciphertext according to the private key of its own certificate, so as to obtain the first session key.
  • the first session key may include an encryption key and an encryption algorithm, and then after the target vehicle obtains the first session key through decryption, it can compare the encryption key and the encryption algorithm with Broadcast messages between other vehicles in the fleet are encrypted.
  • the first session key may include an encryption key credential and an encryption algorithm, so that after the pilot vehicle sends the first session key to the target vehicle, the target vehicle encrypts the encryption key according to a preset algorithm.
  • the key credentials are processed to generate an encryption key; then based on the encryption key and encryption algorithm, the broadcast information between it and other vehicles in the fleet is encrypted.
  • the preset algorithm may be SM4, AES, 3DES, etc., which are not limited in this embodiment of the present application.
  • the target vehicle obtains the certificate of the pilot vehicle.
  • the target vehicle after the target vehicle obtains the certificate of the pilot car, it can save the certificate locally, so that after the target vehicle receives the information of the pilot car, it can verify the identity of the pilot car according to the certificate.
  • the target vehicle initiates a queue entry request to the pilot vehicle, and the pilot vehicle uses the public key of the target vehicle's certificate to encrypt and transmit the first session key to the target vehicle.
  • the security and reliability of key transmission are effectively improved, thereby effectively realizing secure communication between vehicles.
  • FIG. 4 shows another vehicle communication method provided by Embodiment 1 of the present application. This method can be applied to the architecture shown in FIG. 1. This method involves the scene where the target vehicle requests to leave the team. The method includes the following process:
  • the target vehicle sends a dequeue request message to the pilot vehicle, and the pilot vehicle receives the dequeue request message.
  • the dequeue request message includes the vehicle identification of the target vehicle.
  • the pilot vehicle receives the dequeue request message, deletes the vehicle identifier of the target vehicle from the vehicle information list in the fleet, and updates the vehicle list in the fleet.
  • the original fleet list of the fleet where the pilot car is located is shown in Table 1.
  • the updated fleet list shown in Table 2 is obtained.
  • the pilot vehicle sends a dequeue response message to the target vehicle in response to the dequeue request message, and the target vehicle receives the dequeue response message.
  • the target vehicle executes a dequeue operation.
  • the process for the target vehicle to perform the operation of leaving the team may be: setting its own vehicle driving state as the leaving state, and broadcasting to all vehicles in the team, and setting its own role as a free vehicle .
  • the pilot car generates a second session key, and encrypts the second session key according to the public keys of the certificates of the team members' vehicles in the convoy where it is located, to obtain a second ciphertext.
  • the second ciphertext can be understood as one or more ciphertexts, and each ciphertext can be obtained by the pilot car encrypting the second session key according to the public key of the certificate of each team member vehicle.
  • the second ciphertext is ciphertext 1, ciphertext 2, and ciphertext 3, wherein ciphertext 1 is based on the
  • the ciphertext 2 is obtained by encrypting the public key of the certificate of the member vehicle 2
  • the ciphertext 3 is obtained by encrypting the public key of the certificate of the member vehicle 3.
  • the pilot car generates a first notification message based on the first signature information, the second identification corresponding to the certificates of other vehicles in the fleet where the pilot car is located, and the second ciphertext, and sends the first notification message to other vehicles, and other The vehicle receives the first notification message.
  • the second identifier corresponding to the certificate of the other vehicle is used to instruct the other vehicle to decrypt the second ciphertext according to the private key of the certificate, so as to obtain the second session key.
  • the second identifier may be a HashID corresponding to a certificate of another vehicle.
  • the first signature information is obtained after the pilot car performs a signature operation using the private key of the certificate corresponding to the pilot car.
  • the embodiment of the present application does not limit the signature algorithm, and some examples are listed below, and the signature algorithm may be ECDSA or SM2-based signature algorithm.
  • the other vehicle verifies the identity of the pilot car according to the certificate of the pilot car and the first signature information.
  • the certificate and the first signature information verify the identity of the pilot car.
  • the process of verifying the identity of the leading car for each following car is similar. Taking a following car as an example, the process of verifying the identity of the leading car by the following car 2 is described as an example.
  • the process for the follower car 2 to verify the identity of the lead car includes: follower car 2 obtains the public key of the lead car contained in the certificate of the lead car, and uses the public key of the lead car to decrypt the first signature information , if the decryption fails, the identity verification of the pilot car is not passed; if the decryption is successful, the identity verification of the pilot car passes, and the execution of S407 is continued.
  • the other vehicle decrypts the second ciphertext according to the private key of its own certificate, so as to obtain the second session key.
  • each following vehicle corresponds to one ciphertext. If other vehicles involve multiple following vehicles, each following vehicle decrypts its corresponding ciphertext according to the private key of its own certificate.
  • other vehicles can also send a key update response message to the pilot car; the pilot car receives the key update response message and confirms that all vehicles in the fleet have After a correct response, send a first indication message to the team members' vehicles to instruct the team members' vehicles to use the second session key to encrypt and transmit the broadcast information of the PC5 port.
  • the pilot car after the pilot car determines that the target vehicle in the fleet leaves the team, it can generate a new session key (ie, the second session key), and issue the new key to the vehicle in the fleet. other team member vehicles, so that the team member vehicles can encrypt the broadcast information between vehicles according to the new session key. In this way, secure communication between vehicles is effectively realized.
  • a new session key ie, the second session key
  • Fig. 5 shows another vehicle communication method provided by Embodiment 1 of the present application. This method can be applied to the architecture shown in Fig. 1. This method mainly involves the switching scene of the pilot car, and the method includes the following process:
  • the target pilot vehicle sends a switching request message to the original pilot vehicle, and the original pilot vehicle receives the switching request message.
  • the switching request message is used to instruct the target pilot vehicle to request switching of the pilot vehicle, and the switching request message carries the vehicle identification of the target pilot vehicle.
  • the original pilot car can be understood as the pilot car of the current fleet
  • the target pilot car can be the pilot car of the fleet obtained after the pilot car is switched.
  • the original pilot vehicle sends a switch response message to the target pilot vehicle, and the target pilot vehicle receives the switch response message.
  • the switching response message is used to instruct the target pilot vehicle to switch the pilot vehicle.
  • the target pilot car switches the pilot car.
  • the target pilot car switches the pilot car, sets its vehicle driving state as the leading state, and sets its own role as the leading car.
  • S501A-S503A can be replaced by S501B-S503B. That is to say, the switching of the pilot car can be initiated by the target pilot car or by the original pilot car.
  • the original pilot vehicle sends a switching request message to the target pilot vehicle, and the target pilot vehicle receives the switching request message.
  • the switching request message is used to indicate that the original pilot vehicle requests to switch the pilot vehicle.
  • the target pilot vehicle sends a switching response message to the original pilot vehicle in response to the switching request message, and the original pilot vehicle receives the switching response message.
  • the switch response message is used to instruct the original pilot vehicle to switch the pilot vehicle.
  • the original pilot car switches the pilot car, sets its own vehicle driving state to the following state, and sets its own role to the following car; and sets the vehicle driving state of the target pilot car to Team status, the role of the target pilot car is set to the pilot car.
  • the original pilot vehicle sends a second notification message to other vehicles.
  • the second notification message includes the second signature information and the certificate of the target pilot vehicle, and the second signature information is used to indicate the identity information of the original pilot vehicle.
  • the other vehicles here refer to the following vehicles in the convoy where the original leading vehicle is located, and there may be one or more vehicles, which are not limited in this embodiment of the present application.
  • the second notification message here is the broadcast message sent by the original leading vehicle.
  • the other vehicle verifies the identity of the original pilot car according to the certificate of the original pilot car and the second signature information, and obtains the certificate of the target pilot car.
  • the second signature information is generated according to the private key of the original pilot car certificate, and then other vehicles can decrypt the second signature information according to the public key of the original pilot car certificate. , then the identity verification of the original pilot car is successful, and other vehicles obtain the certificate of the target pilot car and save it locally; if the decryption fails, the identity verification of the original pilot car fails, and other vehicles are prohibited from saving the certificate of the target pilot car.
  • the target pilot vehicle generates a third session key.
  • the target pilot vehicle sends a third notification message to other vehicles.
  • the third notification message includes third signature information, a third identifier corresponding to the certificate of the target pilot vehicle, and a third ciphertext. Other vehicles receive the third notification message.
  • the third identifier may be used to instruct other vehicles in the updated convoy except the target pilot vehicle to decrypt the third ciphertext according to the first session key to obtain the third session key.
  • the third identifier may be the HashID corresponding to the certificate of the target pilot vehicle.
  • the other vehicle verifies the identity of the target pilot vehicle according to the third signature information and the certificate of the target pilot vehicle.
  • the third signature information is generated according to the private key of the certificate of the target pilot car, and then other vehicles can decrypt the third signature information according to the public key of the certificate of the target pilot car. , the identity verification of the target pilot car is successful, and the other vehicles continue to execute S509; if the decryption fails, the identity verification of the target pilot car fails.
  • the other vehicle decrypts the third ciphertext according to the first session key to obtain the third session key.
  • the third ciphertext is obtained by the target pilot car encrypting the third session key according to the first session key.
  • the target pilot vehicle sends third instruction information to other vehicles, and other vehicles receive the third instruction information.
  • the third instruction information is used to instruct other vehicles to encrypt broadcast information between vehicles based on the third session key.
  • the other vehicles are following car 2, following car 3, and following car 4, after receiving the third indication information, following car 2 can broadcast between following car 2 and following car 4 based on the third session key
  • the information is encrypted and transmitted, and the broadcast message that the following vehicle 2 is going to broadcast to the following vehicle 3, the following vehicle 4 and the target pilot vehicle can also be encrypted and transmitted.
  • both the original pilot car and the target pilot car can initiate a pilot car switching request, and after the pilot car switches successfully, the target pilot car can also generate a new session key (that is, the third session key key), and utilize the old session key (i.e. the first session key) to encrypt and transmit the new session key to other vehicles in the fleet.
  • the target pilot car can also generate a new session key (that is, the third session key key), and utilize the old session key (i.e. the first session key) to encrypt and transmit the new session key to other vehicles in the fleet.
  • Fig. 6 shows a vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in Fig. 2. This method mainly involves the scene where the pilot vehicle creates a fleet. The method includes the following process:
  • the pilot car can send a fleet formation request to the server to instruct the server to build a fleet for the pilot car.
  • One or more vehicles in the fleet form a convoy with the lead car.
  • the pilot car forms a fleet by itself, and the pilot car selects one or more vehicles in the preset area of the pilot car to form a fleet with the pilot car according to information such as the position and driving direction of the vehicle, and executes S601 , to send a fleet creation notification message to the server.
  • the pilot car sends a fleet creation notification message to the server, and the server receives the fleet creation notification message.
  • the fleet creation notification message includes the fleet identifier and the identifiers of the vehicles in the fleet. It should be understood that the identification of the vehicle in the fleet may be a vehicle identification and/or a vehicle number.
  • the identifications of the vehicles in the fleet include vehicle identifications (VIN_1, VIN_2, VIN_3, VIN_4) and vehicle numbers (1, 2, 3, 4), where the vehicle identification and vehicle number One-to-one correspondence according to the order of arrangement.
  • the identification representation of the vehicles in the fleet may be: the vehicle number of the vehicle with the vehicle identification VIN_1 is 1, the vehicle number of the vehicle with the vehicle identification VIN_2 is 2, and so on.
  • the identification of vehicles in the fleet sent by the pilot car to the server may be a combination of vehicle identification and vehicle number, for example: (VIN_1, 1), (VIN_2, 2), (VIN_3, 3) and (VIN_4, 4).
  • the server generates a first session key.
  • the server stores the certificates of each vehicle, and after receiving the fleet creation notification message, the server can verify the identity information of each vehicle in the fleet according to the fleet identifier and the identifiers of the vehicles in the fleet , when the verification is passed, execute S602 to generate a first session key; if there is a vehicle in the fleet that fails the verification, the server sends a fleet creation failure response message to the pilot car.
  • the server may generate the first session secret according to a preset algorithm.
  • the preset algorithm may include but not limited to a symmetric algorithm (such as SM4, AES, etc.), a random number generation algorithm, a time Any algorithm, such as a generative algorithm.
  • the server sends the first session key to the pilot car, and the pilot car receives the first session key.
  • the pilot car after the pilot car receives the first session key, it can encrypt and transmit the first session key to each follower car according to the public key corresponding to the certificate of each follower car in its convoy, so as to Allow each following vehicle to encrypt broadcast information between vehicles.
  • the server may also directly send the first session key to each follower vehicle in the convoy where the lead vehicle is located, and facilitate the public key corresponding to the certificate of each follower vehicle to perform the first session key
  • the encryption is transmitted to the corresponding following vehicle, so that the following vehicle can encrypt the broadcast information between vehicles.
  • the pilot car sends a fleet creation notification message to the server, and then the server can verify the identity information of each vehicle in the fleet, and when the verification is passed, generate a first session key and send the first
  • the session key is delivered to the pilot car, so that the pilot car encrypts the broadcast information between vehicles according to the first session key.
  • Fig. 7 shows a vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in Fig. 2. This method mainly involves the scene where a free vehicle applies for joining the team. The method includes the following process :
  • the pilot vehicle determines that the first vehicle requests to join the team.
  • the first vehicle takes the free car 5 as an example, the pilot car receives the queue entry request message of the free car 5, and then may respond to the message to determine that the free car 5 wants to join the team of the pilot car.
  • the pilot car sends a queue entry request notification message to the server, and the server receives the queue entry request notification message; the queue entry request notification message includes a fleet identifier and a vehicle identifier of the first vehicle.
  • the server stores the certificate of the first vehicle locally, and then the server can verify the identity information of the first vehicle according to the certificate of the first vehicle and the identification of the first vehicle, and when the verification passes, execute S702. Send the first session key to the first vehicle.
  • the server sends the first session key to the first vehicle, and the first vehicle receives the first session key.
  • the first vehicle receives the first session key, and can encrypt the broadcast information between it and the pilot vehicle according to the first session key, or Encrypt the broadcast information between vehicles.
  • the server can realize the management of the session key of the fleet, and when it is determined that there is a vehicle to enter the queue, the pilot car can send a queue request notification message to the server, and the server responds to the notification message and waits to enter the queue.
  • the identity verification of the entering vehicle passes, the first session key is sent to the waiting vehicle, so that the waiting vehicle can use the first session key to encrypt the broadcast information. In this way, it helps to improve the safety and reliability of communication between vehicles.
  • Fig. 8 shows another vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in Fig. 2. This method mainly involves the scene of following the vehicle to apply for leaving the team. The method includes the following process:
  • the pilot vehicle determines that the second vehicle requests to leave the team.
  • the second vehicle takes the follower car 4 as an example, and the lead car receives the dequeue request message of the follower car 4, and then may respond to the message and determine that the follower car 4 satisfies the dequeue condition (for example, there is no ongoing operation task), agree to follow car 4 out of the team.
  • the lead car receives the dequeue request message of the follower car 4, and then may respond to the message and determine that the follower car 4 satisfies the dequeue condition (for example, there is no ongoing operation task), agree to follow car 4 out of the team.
  • the pilot car sends a queue-out request notification message to the server, and the server receives the queue-out request notification message; the queue-entry request notification message includes a fleet identifier and a second vehicle identifier.
  • the server receives the dequeue request notification message, removes the second vehicle identifier from the vehicle list in the fleet, obtains an updated vehicle list, and executes S802.
  • the server generates a second session key.
  • the server sends the second session key to other vehicles, and the other vehicles receive the second session key.
  • other vehicles receive the second session key, and can encrypt the broadcast information between them and the leading vehicle according to the second session key, or the broadcast information between them and other following vehicles The information is encrypted.
  • the server can realize the management of the session key of the fleet, and after determining that a vehicle leaves the team, send the updated session key (ie, the second session key) to the updated fleet , so that other vehicles in the updated fleet can use the second session key to encrypt the broadcast information. In this way, it helps to improve the safety and reliability of communication between vehicles.
  • FIG. 9 shows another vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in FIG. 2. This method mainly involves the scene of pilot vehicle switching. The method includes the following process:
  • pilot car Determine the target pilot car.
  • pilot car determines the target pilot car, including but not limited to the following ways:
  • the pilot vehicle sends a switching request message to the target pilot vehicle, receives a switching response message corresponding to the switching request message, and determines the target pilot vehicle according to the switching response message.
  • the pilot car receives the switch request message from the target pilot car, and determines the target pilot car when it is determined that the target pilot car satisfies the pilot car switching conditions.
  • the pilot car sends a pilot car switching notification message to the server, and the server receives the pilot car switching notification message.
  • the pilot car switching notification message includes the fleet identification and the vehicle identification of the target pilot car.
  • the server locally stores the certificate of the target pilot car, and then the server can verify the identity information of the target pilot car according to the certificate of the target pilot car, and when the verification is passed, execute S902 to switch the pilot car .
  • the server generates a pilot car switch and updates the fleet according to the fleet ID and the vehicle ID of the target pilot car.
  • the server generates a third session key
  • the server sends the third session key to other vehicles.
  • the server can realize the management of the session key of the fleet, and after receiving the pilot car switching notification message, perform pilot car switching according to the identification of the fleet and the vehicle identification of the target pilot car; generate the second Three session keys, and send the third session key to other vehicles in the fleet, so that other vehicles in the updated fleet can use the third session key to encrypt broadcast information.
  • updating the session key in time helps to improve the security and reliability of communication between vehicles.
  • FIG. 10 shows a possible structural diagram of a vehicle communication device involved in the above embodiments of the present application.
  • the device 1000 can be used to implement the functions of the vehicle shown in FIG. 1 or FIG. 2 above.
  • device 1000 may include:
  • the receiving module 1001 is configured to receive an entry request message; the entry request message includes the certificate of the target vehicle, and the entry request message is used to indicate that the target vehicle requests entry;
  • a sending module 1002 configured to send a queue-entry response message to the target vehicle in response to the queue-entry request message
  • the entry response message includes a first ciphertext, a first identification corresponding to the certificate of the target vehicle, and a certificate of the pilot vehicle
  • the first ciphertext is the ciphertext of the pilot vehicle according to the certificate of the target vehicle.
  • the first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key key, and obtain the certificate of the pilot car.
  • the first identifier may be the HashID corresponding to the certificate of the target vehicle.
  • the device 1000 further includes a processing module 1003, and before the receiving module 1001 is configured to receive the enqueue request message, the processing module 1003 is also configured to: generate the first session key, the second A session key is used to encrypt broadcast messages between vehicles.
  • the receiving module 1001 is also used to receive a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests dequeue; the sending module 1002 is also used to respond to the dequeue A request message, sending a dequeue response message; the dequeue response message is used to instruct the target vehicle to perform a dequeue operation.
  • the sending module 1002 sends a first notification message after sending the team-out response message; wherein, the first notification message includes the first signature information, other vehicles in the fleet where the pilot car is located The second identification and the second ciphertext corresponding to the certificate, the first signature information is used to indicate the identity information of the pilot car, and the second ciphertext is the obtained by encrypting the second session key with the public key of the certificate; the second identifier is used to instruct the other vehicle to decrypt the second ciphertext according to the private key of the certificate to obtain the second The session key, the first notification message is used to instruct other vehicles to verify the identity of the pilot car according to the certificate of the pilot car and the first signature information, and decrypt the second ciphertext according to the private key of the certificate of other vehicles to obtain the first Two session keys.
  • the processing module 1003 is further configured to generate a second session key before the sending module 1002 sends the first notification message; the second session key is used for broadcasting between the vehicles The information is encrypted.
  • FIG. 11 shows a possible structural diagram of a vehicle communication device involved in the above-mentioned embodiments of the present application.
  • the device 1100 can be used to realize the functions of the server shown in FIG. 2 above.
  • device 1100 may include:
  • the receiving module 1101 is configured to receive a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message includes the identification of the fleet and the vehicle identification in the fleet;
  • the sending module 1102 is configured to send a first response message in response to the fleet creation notification message; the first response message is used to instruct the pilot car to obtain a first session key, and the first session key is used for Encrypting broadcast messages between vehicles in the fleet.
  • the receiving module 1101 is also used to receive a queue entry request notification message; the queue entry request notification message is used to indicate that the first vehicle requests to join the queue; the sending module 1102 is also used to respond to the queue entry A team request notification message, sending the first session key to the first vehicle.
  • the receiving module 1101 is also configured to receive a request notification message for leaving the team; the request notification message for leaving the team is used to indicate that the second vehicle requests to leave the team, and the request notification message for leaving the team includes the and the vehicle identification of the second vehicle; the sending module 1102 is also configured to determine the updated fleet according to the identification of the fleet and the vehicle identification of the second vehicle in response to the departure request notification message, and A second session key is sent to each vehicle in the updated fleet; the second session key is used to encrypt broadcast information between vehicles in the updated fleet.
  • the device 1100 further includes a processing module 1103, and the receiving module 1101 is also configured to receive a pilot car switching notification message; the pilot car switching notification message includes the identification of the fleet and the vehicle of the target pilot car Identification; the processing module 1103 is used to respond to the pilot car switching notification message, perform pilot car switching according to the identification of the fleet and the vehicle identification of the target pilot car, generate a third session key, and send a message to the team in the fleet The other vehicles send a third session key used to encrypt broadcast information between vehicles in the fleet.
  • An embodiment of the present application also provides a vehicle, and the vehicle may include a processor configured to execute the vehicle communication method in any of the embodiments shown in FIGS. 3-9 .
  • a memory is also included for storing computer programs or instructions.
  • a transceiver is further included, configured to receive or send information.
  • the embodiment of the present application also provides a server, the server includes a processor, and the processor is configured to implement the functions of the server in the embodiments shown in FIGS. 6-9 above, so as to implement the vehicle communication method provided in the embodiment of the present application.
  • a memory is also included for storing computer programs or instructions.
  • a transceiver is further included, configured to receive or send information.
  • the server is a single server or a server cluster composed of multiple sub-servers.
  • the server is a server cluster composed of multiple sub-servers
  • the multiple sub-servers jointly execute the above-mentioned server 6 shown in FIG. 2 function.
  • the embodiment of the present application also provides a chip system. Please refer to FIG. 12.
  • the chip system 1200 includes at least one processor. When program instructions are executed in at least one processor 1201, any A vehicle communication method in an embodiment is realized.
  • the chip system further includes a communication interface 1203, which is used for inputting or outputting information.
  • the chip system further includes a memory 1202 , which is coupled to the processor through the communication interface 1203 and configured to store the above-mentioned instructions, so that the processor can read the instructions stored in the memory through the communication interface 1203 .
  • connection medium among the foregoing processor 1201, memory 1202, and communication interface 1203 is not limited in this embodiment of the present application.
  • the memory 1202, the processor 1201, and the communication interface 1203 are connected through a communication bus 1204.
  • the bus is represented by a thick line in FIG. , is not limited.
  • the bus may include an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is used in FIG. 12 , but it does not mean that there is only one bus or one type of bus.
  • the embodiment of the present application also provides a computer program product including instructions, when running on the above device, to execute the vehicle communication method in any of the above embodiments shown in FIGS. 3-9 .
  • An embodiment of the present application provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is run, the vehicle communication method in any of the above-mentioned embodiments shown in Figures 3-9 is implemented .
  • the methods provided in the embodiments of the present application are introduced from the perspective of interaction between various devices.
  • the first terminal, the second terminal and the network device may include a hardware structure and/or a software module in the form of a hardware structure, a software module, or a hardware structure plus a software module to realize the above functions. Whether one of the above-mentioned functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.
  • each functional module in each embodiment of the present application may be integrated into one processor, or physically exist separately, or two or more modules may be integrated into one module.
  • the above-mentioned integrated modules can be implemented in the form of hardware or in the form of software function modules.
  • the memory may be a non-volatile memory, such as a hard disk (hard disk drive, HDD) or a solid-state drive (solid-state drive, SSD), etc., and may also be a volatile memory (volatile memory), such as Random-access memory (RAM).
  • a memory is, but is not limited to, any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer.
  • the memory in the embodiment of the present application may also be a circuit or any other device capable of implementing a storage function, and is used for storing program instructions and/or data.
  • the methods provided in the embodiments of the present application may be implemented in whole or in part by software, hardware, firmware or any combination thereof.
  • software When implemented using software, it may be implemented in whole or in part in the form of a computer program product.
  • the computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, the processes or functions according to the embodiments of the present application will be generated in whole or in part.
  • the computer may be a general purpose computer, a special purpose computer, a computer network, network equipment, user equipment or other programmable devices.
  • the computer instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website, computer, server or data center Transmission to another website site, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.).
  • the computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center integrated with one or more available media.
  • the available medium may be a magnetic medium (for example, a floppy disk, a hard disk, or a magnetic tape), an optical medium (for example, a digital video disc (digital video disc, DVD for short)), or a semiconductor medium (for example, SSD).
  • a magnetic medium for example, a floppy disk, a hard disk, or a magnetic tape
  • an optical medium for example, a digital video disc (digital video disc, DVD for short)
  • a semiconductor medium for example, SSD
  • the various embodiments may refer to each other, for example, the methods and/or terms between the method embodiments may refer to each other, such as the functions and/or terms between the device embodiments Or terms may refer to each other, for example, functions and/or terms between the apparatus embodiment and the method embodiment may refer to each other.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Traffic Control Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The present application embodiment provides a vehicle communication method and a device, applicable in the technical field of autonomous driving, the method comprising: receiving an enqueue request message; the enqueue request message comprising a certificate of a target vehicle, and the enqueue request message being used to instruct a target vehicle to request to enqueue; in response to the enqueue request message, sending an enqueue response message to the target vehicle; wherein, the enqueue response message comprises a first ciphertext, a first identifier corresponding to the certificate of the target vehicle, and a certificate of a pilot vehicle, the first ciphertext being obtained by the pilot vehicle by encrypting a first session key in accordance with the certificate of the target vehicle and a public key; the enqueue response message can be further used to instruct the target vehicle to decrypt the first ciphertext in accordance with a private key of the certificate of said target vehicle, so as to obtain the first session key, and to obtain the certificate of the pilot vehicle. In this way, the security and reliability of key transmission are effectively improved, thereby enabling secure communication between vehicles, thus effectively improving the information security of vehicle communication and also network security performance.

Description

一种车辆通信的方法及装置Method and device for vehicle communication
相关申请的交叉引用Cross References to Related Applications
本申请要求在2021年07月12日提交中国专利局、申请号为202110783012.6、申请名称为“一种车辆通信的方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims the priority of the Chinese patent application with the application number 202110783012.6 and the application name "A Method and Device for Vehicle Communication" submitted to the China Patent Office on July 12, 2021, the entire contents of which are incorporated in this application by reference middle.
技术领域technical field
本申请涉及自动驾驶技术领域,尤其涉及一种车辆通信的方法及装置。The present application relates to the technical field of automatic driving, and in particular to a method and device for vehicle communication.
背景技术Background technique
自动驾驶应用中的一个重要场景是车辆的编队行驶,在车辆编队行驶场景中,最前车辆可以充当“领航车”的角色,其后由若干自动驾驶车辆组成,呈一个队列的行驶形态前进,车队成员保持一定的车距以及稳定的车速,在有序行驶的状态下巡航。An important scenario in the application of automatic driving is the formation driving of vehicles. In the vehicle formation driving scene, the front vehicle can act as a "leading vehicle", and then it is composed of several self-driving vehicles, which advance in a formation. Members maintain a certain distance between vehicles and a stable speed, and cruise in an orderly driving state.
在车辆编队行驶过程中,群组内的车队成员之间主要通过V2X(vehicle to everything,车到万物)方式来进行车辆间的通信,但V2X基于开放的无线通信网络,相比传统网络更容易受到攻击,对于主要基于V2X通信的车辆编队行驶领域所带来的损害也更大。因此,在自动驾驶的车辆编队行驶场景下,对V2X通信的安全性提出更高的要求。During the driving process of vehicles in formation, the team members in the group mainly communicate with each other through V2X (vehicle to everything, vehicle to everything), but V2X is based on an open wireless communication network, which is easier than traditional networks. Being attacked will also cause greater damage to the field of vehicle platooning mainly based on V2X communication. Therefore, in the scenario of autonomous vehicle platooning, higher requirements are put forward for the security of V2X communication.
并且,在农场、矿区和码头等商用车场景中,需要按照作业任务对分配的车辆临时组建车队,车队内成员车辆之间的消息涉及任务分配、费用核对和作业参数等机密信息,因此对车辆之间的消息进行安全传输显得十分重要。In addition, in commercial vehicle scenarios such as farms, mining areas, and docks, it is necessary to temporarily form a fleet of vehicles assigned according to the task, and the messages between the member vehicles in the fleet involve confidential information such as task allocation, cost verification, and operating parameters. It is very important to carry out secure transmission of messages between them.
因此,现有亟需提出一种针对自动驾驶领域中车辆编队行驶过程中车队成员之间进行安全通信的方案。Therefore, there is an urgent need to propose a solution for secure communication among team members during vehicle platooning in the field of autonomous driving.
发明内容Contents of the invention
本申请实施例提供一种车辆通信的方法及装置,用于实现车辆之间的安全通信。Embodiments of the present application provide a vehicle communication method and device for implementing secure communication between vehicles.
第一方面,本申请实施例提供一种车辆通信的方法,该方法可以应用于领航车,该方法包括:接收入队请求消息;入队请求消息包括目标车辆的证书,入队请求消息用于指示目标车辆请求入队;响应于入队请求消息,向目标车辆发送入队响应消息;其中,入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,第一密文是领航车根据目标车辆的证书的公钥对第一会话密钥进行加密得到的;进而所述第一标识可以用于指示目标车辆根据其自身的证书的私钥对第一密文进行解密以获取第一会话密钥,以及获取领航车的证书。In the first aspect, the embodiment of the present application provides a method for vehicle communication, which can be applied to the pilot car, and the method includes: receiving a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used for Instructing the target vehicle to request entry into the team; in response to the entry request message, sending an entry response message to the target vehicle; wherein the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle, and the pilot car's certificate, the first ciphertext is obtained by the pilot car encrypting the first session key according to the public key of the target vehicle's certificate; and the first identification can be used to indicate that the target vehicle encrypts the first session key according to the private key of its own certificate. A ciphertext is decrypted to obtain the first session key and the certificate of the pilot car.
在本申请实施例中,领航车在接收到来自目标车辆的入队请求消息之后,利用目标车辆的证书的公钥对第一会话密钥进行加密传输。如此,有效提升密钥传输的安全性和可靠性,进而使得车辆之间可以安全通信,从而有效提升车辆通信的信息安全和网络安全的性能。In the embodiment of the present application, after the pilot car receives the queue entry request message from the target vehicle, it uses the public key of the target vehicle's certificate to encrypt and transmit the first session key. In this way, the security and reliability of key transmission can be effectively improved, thereby enabling safe communication between vehicles, thereby effectively improving the information security and network security performance of vehicle communication.
在一种可能的设计中,领航车在接收入队请求消息之前,还可以生成第一会话密钥。 其中,第一会话密钥用于对车辆之间的广播信息进行加密,进而领航车可以将该第一会话密钥加密后传输给该车队内的其他车辆,进而使得其他车辆可以利用第一会话密钥对广播信息进行加密传输。In a possible design, the pilot car may also generate a first session key before receiving the queue entry request message. Among them, the first session key is used to encrypt the broadcast information between vehicles, and then the pilot car can encrypt the first session key and transmit it to other vehicles in the fleet, so that other vehicles can use the first session The key encrypts and transmits the broadcast information.
在该设计中,领航车在接收入队请求消息之前,无需和多个车辆进行密钥协商,就可以生成第一会话密钥。如此,有效减少密钥生成的时延,使得待入队的目标车辆能够更快地使用第一会话密钥对广播信息进行加密传输。In this design, the pilot vehicle can generate the first session key without performing key negotiation with multiple vehicles before receiving the queue request message. In this way, the time delay of key generation is effectively reduced, so that the target vehicles waiting to join the queue can use the first session key to encrypt and transmit the broadcast information more quickly.
在一种可能的设计中,领航车还可以接收出队请求消息;该出队请求消息用于指示目标车辆请求出队;进而领航车可以响应于出队请求消息,发送出队响应消息,以指示目标车辆执行出队操作。In a possible design, the pilot vehicle can also receive a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests to dequeue; and then the pilot vehicle can send a dequeue response message in response to the dequeue request message to Instruct the target vehicle to perform dequeue operation.
在该设计中,领航车可以管理车队内的车辆,在接收到目标车辆出队请求消息时,领航车可以作出响应,以指示该目标车辆出队。In this design, the pilot car can manage the vehicles in the fleet, and when receiving the request message of the target vehicle leaving the team, the pilot car can respond to instruct the target vehicle to leave the team.
在一种可能的设计中,领航车在发送出队响应消息之后,还可以向领航车所在车队中的其他车辆发送第一通知消息;其中,第一通知消息包括第一签名信息、所述领航车所在车队中的其他车辆的证书对应的第二标识和第二密文,第一签名信息用于指示领航车的身份信息,第二密文是领航车根据该其他车辆的证书的公钥对第二会话密钥进行加密得到的;进而所述第二标识用于指示所述其他车辆根据其的证书的私钥对所述第二密文进行解密,以获取所述第二会话密钥,第一通知消息用于指示其他车辆根据领航车的证书和第一签名信息,验证领航车的身份。In a possible design, after the pilot car sends the team-out response message, it can also send a first notification message to other vehicles in the convoy where the pilot car is located; wherein, the first notification message includes the first signature information, the pilot The second identification and the second ciphertext corresponding to the certificates of other vehicles in the vehicle fleet, the first signature information is used to indicate the identity information of the pilot car, and the second ciphertext is the public key pair of the pilot car according to the certificate of the other vehicle obtained by encrypting the second session key; furthermore, the second identification is used to instruct the other vehicle to decrypt the second ciphertext according to the private key of its certificate, so as to obtain the second session key, The first notification message is used to instruct other vehicles to verify the identity of the pilot car according to the certificate of the pilot car and the first signature information.
在该设计中,领航车在请求出队的目标车辆出队后,根据该其他车辆的证书的公钥将第二会话密钥加密传输给车队内的其他车辆。如此,使得第二会话密钥的传输更加可靠,有助于提升车辆之间通信的安全性。In this design, after the target vehicle that requests to leave the team leaves the team, the pilot vehicle encrypts and transmits the second session key to other vehicles in the team according to the public key of the other vehicle's certificate. In this way, the transmission of the second session key is made more reliable, which helps to improve the security of communication between vehicles.
在一种可能的设计中,领航车在发送第一通知消息之前,还可以生成第二会话密钥;第二会话密钥用于对车辆之间的广播信息进行加密。应理解,“车辆之间的广播信息”可以是车队中的任意两个车辆之间的广播信息,也可以是领航车和其他车辆之间的广播信息,这里不作具体的限制。In a possible design, before the pilot vehicle sends the first notification message, it may also generate a second session key; the second session key is used to encrypt broadcast information between vehicles. It should be understood that the "broadcast information between vehicles" may be broadcast information between any two vehicles in the convoy, or may be broadcast information between the pilot vehicle and other vehicles, and there is no specific limitation here.
在该设计中,领航车在请求出队的目标车辆出队后,可以生成新的会话密钥(即第二会话密钥),并将该第二会话密钥加密传输给车队内的其他车辆。如此,及时更新会话密钥,有助于提升车辆之间的通信的安全性和可靠性。In this design, the pilot car can generate a new session key (that is, the second session key) after the target vehicle that requests to leave the team, and encrypt and transmit the second session key to other vehicles in the fleet . In this way, updating the session key in time helps to improve the security and reliability of communication between vehicles.
第二方面,本申请实施例还提供一种车辆通信方法,该方法可以应用于目标车辆,该方法包括:发送入队请求消息;入队请求消息包括目标车辆的证书,入队请求消息用于指示目标车辆请求入队;接收与入队请求消息对应的入队响应消息;入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,第一密文是领航车根据目标车辆的证书的公钥对第一会话密钥进行加密得到的,所述第一标识可以用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书;根据目标车辆的证书的私钥对第一密文进行解密以获取第一会话密钥,以及获取领航车的证书。In the second aspect, the embodiment of the present application also provides a vehicle communication method, which can be applied to the target vehicle, and the method includes: sending a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used for Instructing the target vehicle to request entry into the team; receiving the entry response message corresponding to the entry request message; the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle and the certificate of the pilot car, the first encryption The text is obtained by the pilot car encrypting the first session key according to the public key of the target vehicle's certificate, and the first identifier can be used to indicate that the target vehicle encrypts the first session key according to the private key of its own certificate. Decrypt the text to obtain the first session key, and obtain the certificate of the pilot car; decrypt the first ciphertext according to the private key of the certificate of the target vehicle to obtain the first session key, and obtain the pilot car's Certificate.
在一种可能的设计中,目标车辆还可以发送出队请求消息;出队请求消息用于指示目标车辆请求出队;接收与出队请求消息对应的出队响应消息,执行出队操作。In a possible design, the target vehicle may also send a dequeue request message; the dequeue request message is used to instruct the target vehicle to request dequeue; receive a dequeue response message corresponding to the dequeue request message, and execute the dequeue operation.
应理解,上述第二方面的有益效果,具体请参照上述第一方面中相应设计可以达到的技术效果,这里不再重复赘述。It should be understood that for the beneficial effects of the above second aspect, please refer to the technical effects that can be achieved by the corresponding design in the above first aspect for details, and will not be repeated here.
第三方面,本申请实施例还提供一种车辆通信方法,该方法可以应用于原领航车,在该方法中可以由原领航车发起领航车切换请求,也可以由目标领航车发起切换请求。In the third aspect, the embodiment of the present application also provides a vehicle communication method, which can be applied to the original pilot vehicle. In this method, the original pilot vehicle can initiate a pilot vehicle switching request, and the target pilot vehicle can also initiate a switching request.
方式1:原领航车接收来自目标领航车的切换请求消息;原领航车响应于切换请求消息,向目标领航车发送切换响应消息,该切换请求响应消息用于指示目标领航车进行领航车切换。Mode 1: The original pilot vehicle receives a switching request message from the target pilot vehicle; in response to the switching request message, the original pilot vehicle sends a switching response message to the target pilot vehicle, and the switching request response message is used to instruct the target pilot vehicle to switch the pilot vehicle.
方式2:原领航车向目标领航车发送切换请求消息,并接收与该切换请求消息对应的切换响应消息,所述切换响应消息用于指示原领航车进行领航车切换;原领航车进行领航车切换,得到更新后的车队。Mode 2: The original pilot car sends a switch request message to the target pilot car, and receives a switch response message corresponding to the switch request message, the switch response message is used to instruct the original pilot car to switch the pilot car; Toggle to get the updated fleet.
在本申请实施例中,原领航车可以向目标领航车发起领航车切换请求,也可以接收来自领航车的切换请求,并进行领航车切换。如此,实现了对车队的灵活管理,可以有效满足不同场景的业务需求。In this embodiment of the present application, the original pilot car may initiate a pilot car switching request to the target pilot car, or may receive a switching request from the pilot car and perform pilot car switching. In this way, the flexible management of the fleet is realized, which can effectively meet the business needs of different scenarios.
在一种可能的设计中,原领航车还可以发送第二通知消息;其中,第二通知消息包括第二签名信息和目标领航车的证书,第二签名信息用于指示原领航车的身份信息;第二通知消息用于指示原领航车根据其所在车队中的其他车辆根据原领航车的证书和第二签名信息验证原领航车的身份,并在验证通过时获取目标领航车的证书。In a possible design, the original pilot car can also send a second notification message; wherein, the second notification message includes the second signature information and the certificate of the target pilot car, and the second signature information is used to indicate the identity information of the original pilot car ; The second notification message is used to instruct the original pilot car to verify the identity of the original pilot car according to the certificate of the original pilot car and the second signature information according to other vehicles in the fleet, and obtain the certificate of the target pilot car when the verification is passed.
在该设计中,原领航车在进行领航车切换之后,向其所在车队的其他车辆发送第二通知消息,以通知其他车辆更新领航车的证书。如此,使得车队内的其他车辆及时获知目标领航车的信息。In this design, the original pilot car sends a second notification message to other vehicles in its convoy after switching the pilot car to notify other vehicles to update the certificate of the pilot car. In this way, other vehicles in the convoy can obtain the information of the target leading vehicle in time.
第四方面,本申请实施例提供一种车辆通信方法,该方法可以应用于目标领航车,在该方法中可以由原领航车发起领航车切换请求,也可以由目标领航车发起切换请求。In the fourth aspect, the embodiment of the present application provides a vehicle communication method, which can be applied to the target pilot vehicle. In this method, the original pilot vehicle can initiate the pilot vehicle switching request, and the target pilot vehicle can also initiate the switching request.
方式1:目标领航车向原领航车发送切换请求消息;目标领航车接收与该切换请求消息对应的切换响应消息,该切换响应消息用于指示目标领航车进行领航车切换;目标领航车进行领航车切换,得到更新后的车队。Mode 1: The target pilot vehicle sends a switching request message to the original pilot vehicle; the target pilot vehicle receives a switching response message corresponding to the switching request message, and the switching response message is used to instruct the target pilot vehicle to switch the pilot vehicle; Toggle to get the updated fleet.
方式2:目标领航车接收来自原领航车的切换请求消息;目标领航车响应于切换请求消息,向原领航车发送切换响应消息,切换响应消息用于指示原领航车进行领航车切换。Mode 2: The target pilot vehicle receives a switching request message from the original pilot vehicle; in response to the switching request message, the target pilot vehicle sends a switching response message to the original pilot vehicle, and the switching response message is used to instruct the original pilot vehicle to switch the pilot vehicle.
应理解,该实施例的有益效果,具体请参照上述第三方面中可以达到的技术效果,这里不再重复赘述。It should be understood that for the beneficial effects of this embodiment, please refer to the technical effects that can be achieved in the third aspect above, and details will not be repeated here.
在一种可能的设计中,目标领航车在领航车切换之后,还可以生成第三会话密钥,第三会话密钥用于对车辆之间的广播信息进行加密。In a possible design, the target pilot vehicle may also generate a third session key after the pilot vehicle switches, and the third session key is used to encrypt broadcast information between vehicles.
在该设计中,目标领航车进行领航车切换成功之后,可以生成第三会话密钥,如此,及时更新会话密钥,有助于提升车辆之间的通信的安全性和可靠性。In this design, the target pilot vehicle can generate the third session key after the pilot vehicle switch is successful. In this way, updating the session key in time helps to improve the security and reliability of the communication between vehicles.
在一种可能的设计中,目标领航车在生成第三会话密钥之后,还可以发送第三通知消息;其中,第三通知消息包括第三签名信息、所述目标领航车的证书对应的第三标识和第三密文,第三签名信息用于指示目标领航车的身份信息,第三密文是目标领航车根据第一会话密钥对第三会话密钥进行加密得到的;所述第三标识用于指示更新后的车队中的除目标领航车以外的其他车辆根据第一会话密钥对第三密文进行解密,以获取第三会话密钥;第三通知消息用于指示更新后的车队中的除目标领航车以外的其他车辆根据目标领航车的证书和第三签名信息,验证目标领航车的身份。In a possible design, after the target pilot vehicle generates the third session key, it can also send a third notification message; wherein, the third notification message includes the third signature information, and the third session key corresponding to the target pilot vehicle certificate. Three identifications and a third ciphertext, the third signature information is used to indicate the identity information of the target pilot vehicle, and the third ciphertext is obtained by the target pilot vehicle encrypting the third session key according to the first session key; The third identification is used to indicate that other vehicles in the updated convoy except the target pilot vehicle decrypt the third ciphertext according to the first session key to obtain the third session key; the third notification message is used to indicate that after the update Vehicles other than the target pilot vehicle in the convoy verify the identity of the target pilot vehicle according to the certificate of the target pilot vehicle and the third signature information.
在该设计中,目标领航车将利用第一会话密钥对第三会话密钥进行加密传输,以及将自身的第三签名信息传输给更新后的车队中的其他车辆。如此,使得其他车辆可以验证目 标领航车的身份以及根据原始的会话密钥对加密的新密钥进行解密,进而减少其他车辆获取新会话密钥的时延,有助于提升车辆之间的通信的安全性和可靠性。In this design, the target pilot vehicle will use the first session key to encrypt and transmit the third session key, and transmit its own third signature information to other vehicles in the updated fleet. In this way, other vehicles can verify the identity of the target pilot car and decrypt the encrypted new key according to the original session key, thereby reducing the time delay for other vehicles to obtain a new session key, which helps to improve communication between vehicles safety and reliability.
在一种可能的设计中,目标领航车在发送第三通知消息之后,还可以接收来自其他车辆的领航车更新响应信息;领航车更新响应消息用于指示其他车辆已获取目标领航车的信息;进而目标领航车可以发送第四通知消息,以指示其他车辆使用第三会话密钥对广播信息进行加密。In a possible design, after the target pilot vehicle sends the third notification message, it can also receive pilot vehicle update response information from other vehicles; the pilot vehicle update response message is used to indicate that other vehicles have obtained the information of the target pilot vehicle; Furthermore, the target pilot vehicle may send a fourth notification message to instruct other vehicles to use the third session key to encrypt the broadcast information.
在该设计中,目标领航车在接收到其他车辆的领航车更新响应消息之后,向该其他车辆发送通知消息,以指示他车辆使用第三会话密钥对广播信息进行加密。如此,有助于提升车辆之间的通信的安全性和可靠性。In this design, after receiving the pilot car update response message from other vehicles, the target pilot car sends a notification message to the other vehicle to instruct other vehicles to use the third session key to encrypt the broadcast information. In this way, it helps to improve the safety and reliability of communication between vehicles.
第五方面,本申请实施例还提供一种车辆通信方法,该方法可以应用于服务器,该方法包括:接收车队创建通知消息;车队创建通知消息用于指示领航车已创建车队;车队创建通知消息包括车队的标识和车队内的车辆标识;响应于所述车队创建通知消息,发送第一响应消息;第一响应消息用于指示领航车获取第一会话密钥,第一会话密钥用于对车队中的车辆之间的广播信息进行加密。In the fifth aspect, the embodiment of the present application also provides a vehicle communication method, which can be applied to a server, and the method includes: receiving a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message Including the identification of the fleet and the vehicle identification in the fleet; in response to the fleet creation notification message, a first response message is sent; the first response message is used to instruct the pilot car to obtain the first session key, and the first session key is used for Broadcast messages between vehicles in the fleet are encrypted.
本申请实施例中,服务器可以接收车队创建通知消息,并响应于该车队创建通知消息,向领航车发送第一会话密钥,以使车队中的车辆之间的广播信息可以根据第一会话密钥进行加密。如此,服务器可以实现对车队的管理,有助于提升车辆之间的通信的安全性和可靠性。In this embodiment of the application, the server may receive the fleet creation notification message, and in response to the fleet creation notification message, send the first session key to the pilot car, so that the broadcast information between vehicles in the fleet can be based on the first session key. key to encrypt. In this way, the server can manage the fleet, which helps to improve the safety and reliability of communication between vehicles.
在一种可能的设计中,服务器还可以接收入队请求通知消息;入队请求通知消息用于指示第一车辆请求入队;响应于入队请求通知消息,将第一会话密钥发送至第一车辆。In a possible design, the server may also receive an entry request notification message; the entry request notification message is used to indicate that the first vehicle requests entry into the queue; in response to the entry request notification message, the first session key is sent to the second vehicle. a vehicle.
在该设计中,服务器可以实现对车队的会话密钥的管理,在确定有待入队车辆时,向待入队车辆发送第一会话密钥,使得待入队车辆可以使用第一会话密钥对广播信息进行加密。如此,有助于提升车辆之间的通信的安全性和可靠性。In this design, the server can realize the management of the session key of the fleet, and when it is determined that there are vehicles to be entered, the first session key is sent to the vehicle to be entered, so that the vehicle to be entered can use the first session key pair Broadcast information is encrypted. In this way, it helps to improve the safety and reliability of communication between vehicles.
在一种可能的设计中,服务器还可以接收出队请求通知消息;出队请求通知消息用于指示第二车辆请求出队,出队请求通知消息包括车队的标识和第二车辆的车辆标识;响应于该出队请求通知消息,根据车队的标识和第二车辆的车辆标识,确定更新后的车队,并向更新后的车队中的每辆车辆发送第二会话密钥;第二会话密钥用于对更新后的车队中的车辆之间的广播信息进行加密。In a possible design, the server may also receive a dequeue request notification message; the dequeue request notification message is used to indicate that the second vehicle requests to dequeue, and the dequeue request notification message includes the identifier of the fleet and the vehicle identifier of the second vehicle; In response to the notification message of the request to leave the team, according to the identification of the fleet and the vehicle identification of the second vehicle, determine the updated fleet, and send the second session key to each vehicle in the updated fleet; the second session key Used to encrypt broadcast messages between vehicles in the updated fleet.
在该设计中,服务器可以实现对车队的会话密钥的管理,在确定有车辆出队后,向更新后的车队发送更新后的会话密钥(即第二会话密钥),使得更新后的车队中的其他车辆可以使用第二会话密钥对广播信息进行加密。如此,有助于提升车辆之间通信的安全性和可靠性。In this design, the server can realize the management of the session key of the fleet, and after determining that a vehicle leaves the team, send the updated session key (ie, the second session key) to the updated fleet, so that the updated Other vehicles in the fleet can encrypt broadcast messages using the second session key. In this way, it helps to improve the safety and reliability of communication between vehicles.
在一种可能的设计中,服务器还可以接收领航车切换通知消息;领航车切换通知消息中还包括车队的标识和目标领航车的车辆标识;响应于领航车切换通知消息,根据车队的标识和目标领航车的车辆标识,进行领航车切换。In a possible design, the server can also receive the pilot car switching notification message; the pilot car switching notification message also includes the identification of the fleet and the vehicle identification of the target pilot car; in response to the pilot vehicle switching notification message, according to the identification of the fleet and The vehicle identification of the target pilot car to switch the pilot car.
在该设计中,服务器可以实现对车队的灵活管理,可以根据车队内车辆的需求灵活地切换领航车,有助于提升车辆之间通信的安全性和可靠性。In this design, the server can realize the flexible management of the fleet, and can flexibly switch the pilot car according to the needs of the vehicles in the fleet, which helps to improve the safety and reliability of the communication between vehicles.
在一种可能的设计中,服务器在进行领航车切换之后,还可以生成第三会话密钥,并向车队中的其他车辆发送第三会话密钥,第三会话密钥用于对车队中的车辆之间的广播信息进行加密。In a possible design, after the pilot car is switched, the server can also generate a third session key, and send the third session key to other vehicles in the fleet, and the third session key is used to The broadcast information between vehicles is encrypted.
在该设计中,服务器可以实现对车队的会话密钥的管理,在进行领航车切换之后,生成新的会话密钥(即第三会话密钥),使得更新后的车队中的其他车辆可以使用新的会话密钥对广播信息进行加密。如此,及时更新会话密钥,有助于提升车辆之间通信的安全性和可靠性。In this design, the server can realize the management of the session key of the fleet. After the pilot car is switched, a new session key (ie, the third session key) is generated so that other vehicles in the updated fleet can use The new session key encrypts broadcast information. In this way, updating the session key in time helps to improve the security and reliability of communication between vehicles.
第六方面,本申请实施例还提供一种车辆通信方法,该方法可以应用于领航车,该方法包括:发送车队创建通知消息;车队创建通知消息用于指示领航车已创建车队;车队创建通知消息包括车队的标识和车队内的车辆标识;接收与所述车队创建通知消息对应的第一响应消息;第一响应消息携带第一会话密钥;第一会话密钥用于对车辆之间的广播信息进行加密。In the sixth aspect, the embodiment of the present application also provides a vehicle communication method, which can be applied to the pilot car, and the method includes: sending a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot car has created a fleet; the fleet creation notification The message includes the identification of the fleet and the vehicle identification in the fleet; receiving the first response message corresponding to the creation notification message of the fleet; the first response message carries the first session key; the first session key is used for the communication between the vehicles Broadcast information is encrypted.
在一种可能的设计中,领航车还可以发送入队请求通知消息;入队请求通知消息用于指示第一车辆请求入队。In a possible design, the pilot vehicle may also send a queue entry request notification message; the queue entry request notification message is used to indicate that the first vehicle requests to enter the queue.
在一种可能的设计中,领航车还可以发送出队请求通知消息;出队请求通知消息用于指示第二车辆请求出队,出队请求通知消息包括车队的标识和第二车辆的车辆标识;接收与所述出队请求通知消息对应的第二响应消息;所述第二响应消息携带第二会话密钥,第二会话密钥用于对更新后的车队中的车辆之间的广播信息进行加密;所述更新后的车队是根据车队的标识和第二车辆的车辆标识确定的。In a possible design, the pilot car can also send a team-out request notification message; the team-out request notification message is used to indicate that the second vehicle requests to leave the team, and the team-out request notification message includes the identification of the team and the vehicle identification of the second vehicle ; Receive a second response message corresponding to the dequeue request notification message; the second response message carries a second session key, and the second session key is used to broadcast information between vehicles in the updated fleet Encryption; the updated fleet is determined according to the identifier of the fleet and the vehicle identifier of the second vehicle.
在一种可能的设计中,领航车还可以发送领航车切换通知消息;领航车切换通知消息中包括车队的标识和目标领航车的车辆标识;领航车切换通知消息用于指示服务器根据车队的标识和目标领航车的车辆标识,进行领航车切换。In a possible design, the pilot car can also send a pilot car switching notification message; the pilot car switching notification message includes the identification of the fleet and the vehicle identification of the target pilot car; the pilot car switching notification message is used to instruct the server to and the vehicle identification of the target pilot car to switch the pilot car.
在一种可能的设计中,领航车还可以接收第三会话密钥,并根据第三会话密钥对车队中的车辆之间的广播信息进行加密。In a possible design, the pilot vehicle can also receive the third session key, and encrypt the broadcast information between vehicles in the convoy according to the third session key.
应理解,该实施例的有益效果,具体请参照上述第五方面中可以达到的技术效果,这里不再重复赘述。It should be understood that for the beneficial effects of this embodiment, please refer to the technical effects that can be achieved in the fifth aspect above, and details will not be repeated here.
第七方面,本申请实施例提供一种车辆通信的装置,示例性的,该装置可以包括:In the seventh aspect, the embodiment of the present application provides a device for vehicle communication. Exemplarily, the device may include:
接收模块,用于接收入队请求消息;所述入队请求消息包括目标车辆的证书,所述入队请求消息用于指示所述目标车辆请求入队;A receiving module, configured to receive a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used to indicate that the target vehicle requests to join the team;
发送模块,用于响应于所述入队请求消息,向所述目标车辆发送入队响应消息;A sending module, configured to send a queue-entry response message to the target vehicle in response to the queue-entry request message;
其中,所述入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,所述第一密文是所述领航车根据所述目标车辆的证书的公钥对第一会话密钥进行加密得到的,所述第一标识用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书。Wherein, the entry response message includes a first ciphertext, a first identification corresponding to the certificate of the target vehicle, and a certificate of the pilot vehicle, and the first ciphertext is the ciphertext of the pilot vehicle according to the certificate of the target vehicle. obtained by encrypting the first session key with the public key, and the first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key key, and obtain the certificate of the pilot car.
另外,该方面中,通信装置其他可选的实施方式可参见上述第一方面的相关内容,此处不再详述。In addition, in this aspect, for other optional implementation manners of the communication device, reference may be made to the relevant content of the above-mentioned first aspect, which will not be described in detail here.
第八方面,本申请实施例提供一种车辆通信装置,示例性的,该装置包括:In an eighth aspect, the embodiment of the present application provides a vehicle communication device. Exemplarily, the device includes:
发送模块,用于发送入队请求消息;所述入队请求消息包括目标车辆的证书,所述入队请求消息用于指示所述目标车辆请求入队;A sending module, configured to send a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used to indicate that the target vehicle requests to join the team;
接收模块,用于接收与所述入队请求消息对应的入队响应消息;所述入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,所述第一密文是所述领航车根据所述目标车辆的证书的公钥对第一会话密钥进行加密得到的,所述第一标识用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一 会话密钥,以及获取所述领航车的证书;A receiving module, configured to receive an entry response message corresponding to the entry request message; the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle, and the certificate of the pilot vehicle, so The first ciphertext is obtained by the pilot car encrypting the first session key according to the public key of the target vehicle's certificate, and the first identifier is used to indicate that the target vehicle key to decrypt the first ciphertext to obtain the first session key, and obtain the certificate of the pilot car;
处理模块,用于根据所述目标车辆的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书。A processing module, configured to decrypt the first ciphertext according to the private key of the target vehicle's certificate to obtain the first session key, and obtain the pilot vehicle's certificate.
另外,该方面中,通信装置其他可选的实施方式可参见上述第二方面的相关内容,此处不再详述。In addition, in this aspect, for other optional implementation manners of the communication device, reference may be made to the relevant content of the above-mentioned second aspect, which will not be described in detail here.
第九方面,本申请实施例提供一种车辆通信的装置,示例性的,该装置可以包括:In the ninth aspect, the embodiment of the present application provides a device for vehicle communication. Exemplarily, the device may include:
接收模块,用于接收来自目标领航车的切换请求消息;发送模块,用于响应于所述切换请求消息,向所述目标领航车发送切换响应消息,所述切换请求响应消息用于指示所述目标领航车进行领航车切换;或者,The receiving module is configured to receive a switch request message from the target pilot vehicle; the sending module is configured to send a switch response message to the target pilot vehicle in response to the switch request message, and the switch request response message is used to indicate the The target pilot car performs pilot car switching; or,
发送模块,用于向目标领航车发送切换请求消息;接收模块,用于接收与所述切换请求消息对应的切换响应消息,所述切换响应消息用于指示所述原领航车进行领航车切换;A sending module, configured to send a switching request message to the target pilot vehicle; a receiving module, configured to receive a switching response message corresponding to the switching request message, and the switching response message is used to instruct the original pilot vehicle to switch the pilot vehicle;
处理模块,进行领航车切换,得到更新后的车队。Process the module, switch the pilot car, and get the updated fleet.
另外,该方面中,通信装置其他可选的实施方式可参见上述第三方面的相关内容,此处不再详述。In addition, in this aspect, for other optional implementation manners of the communication device, reference may be made to the relevant content of the above-mentioned third aspect, which will not be described in detail here.
第十方面,本申请实施例提供一种车辆通信装置,示例性的,该装置包括:In a tenth aspect, the embodiment of the present application provides a vehicle communication device. Exemplarily, the device includes:
发送模块,用于向原领航车发送切换请求消息;接收模块,用于接收与所述切换请求消息对应的切换响应消息,所述切换响应消息用于指示所述目标领航车进行领航车切换;处理模块,用于进行领航车切换,得到更新后的车队;或者,The sending module is used to send a switching request message to the original pilot vehicle; the receiving module is used to receive a switching response message corresponding to the switching request message, and the switching response message is used to instruct the target pilot vehicle to switch the pilot vehicle; processing Module, used to switch the pilot car to get the updated fleet; or,
接收模块,用于接收来自原领航车的切换请求消息;发送模块,用于响应于所述切换请求消息,向原领航车发送切换响应消息,所述切换响应消息用于指示所述原领航车进行领航车切换。The receiving module is configured to receive a switch request message from the original pilot vehicle; the sending module is configured to send a switch response message to the original pilot vehicle in response to the switch request message, and the switch response message is used to instruct the original pilot vehicle to perform Pilot car switch.
另外,该方面中,通信装置其他可选的实施方式可参见上述第四方面的相关内容,此处不再详述。In addition, in this aspect, for other optional implementation manners of the communication device, reference may be made to the relevant content of the fourth aspect above, which will not be described in detail here.
第十一方面,本申请实施例提供一种车辆通信的装置,该装置可以用于实现服务器的功能。示例性的,该装置可以包括:In an eleventh aspect, the embodiment of the present application provides a vehicle communication device, which can be used to realize the function of a server. Exemplary, the device may include:
接收模块,用于接收车队创建通知消息;所述车队创建通知消息用于指示领航车已创建车队;所述车队创建通知消息包括所述车队的标识和所述车队内的车辆标识;The receiving module is configured to receive a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message includes the identification of the fleet and the vehicle identification in the fleet;
发送模块,用于响应于所述车队创建通知消息,发送第一响应消息;所述第一响应消息用于指示所述领航车获取第一会话密钥,所述第一会话密钥用于对所述车队中的车辆之间的广播信息进行加密。A sending module, configured to send a first response message in response to the fleet creation notification message; the first response message is used to instruct the pilot vehicle to acquire a first session key, and the first session key is used for Broadcast messages between vehicles in the fleet are encrypted.
另外,该方面中,通信装置其他可选的实施方式可参见上述第五方面的相关内容,此处不再详述。In addition, in this aspect, for other optional implementation manners of the communication device, reference may be made to the relevant content of the fifth aspect above, which will not be described in detail here.
第十二方面,本申请实施例提供一种车辆通信装置,示例性的,该装置包括:In a twelfth aspect, the embodiment of the present application provides a vehicle communication device. Exemplarily, the device includes:
发送模块,用于发送车队创建通知消息;所述车队创建通知消息用于指示领航车已创建车队;所述车队创建通知消息包括所述车队的标识和所述车队内的车辆标识;The sending module is used to send a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message includes the identification of the fleet and the vehicle identification in the fleet;
接收模块,用于与所述车队创建通知消息对应的接收第一响应消息;所述第一响应消息携带第一会话密钥;所述第一会话密钥用于对车辆之间的广播信息进行加密。A receiving module, configured to receive a first response message corresponding to the fleet creation notification message; the first response message carries a first session key; the first session key is used to perform broadcast information between vehicles encryption.
另外,该方面中,通信装置其他可选的实施方式可参见上述第六方面的相关内容,此处不再详述。In addition, in this aspect, for other optional implementation manners of the communication device, reference may be made to the relevant content of the sixth aspect above, which will not be described in detail here.
第十三方面,本申请实施例提供了一种服务器,该服务器包括处理器,处理器用于执 行上述第五方面以及上述第五方面任一可能的设计中所述的方法。In a thirteenth aspect, the embodiment of the present application provides a server, where the server includes a processor, and the processor is configured to execute the method described in the above fifth aspect and any possible design of the above fifth aspect.
在一种可能的设计中,服务器为单服务器或由多个子服务器构成的服务器集群,当服务器为由多个子服务器构成的服务器集群时,多个子服务器联合执行上述第五方面以及上述第五方面任一可能的设计中所述的方法。In a possible design, the server is a single server or a server cluster composed of multiple sub-servers. When the server is a server cluster composed of multiple sub-servers, the multiple sub-servers jointly perform the above fifth aspect and any of the above fifth aspects. A possible design is described in the method.
第十四方面,本申请实施例提供了一种车辆,该车辆可以包括处理器,处理器用于执行上述第一方面至第四方面、第六方面,以及上述第一方面至第四方面、第六方面任一可能的设计中所述的方法。In a fourteenth aspect, the embodiment of the present application provides a vehicle, the vehicle may include a processor, and the processor is used to execute the above-mentioned first to fourth aspects, and the sixth aspect, and the above-mentioned first to fourth aspects, and the first aspect Any of the six possible designs are described in the method.
第十五方面,本申请实施例提供了一种芯片系统,该芯片系统包括至少一个处理器,当程序指令在至少一个处理器中执行时,使得上述第一方面至第六方面以及上述第一方面至第六方面可选的设计中任一所述的方法得以实现。In the fifteenth aspect, the embodiment of the present application provides a chip system, the chip system includes at least one processor, when the program instructions are executed in the at least one processor, so that the above first to sixth aspects and the above first The method described in any one of the optional designs from the aspect to the sixth aspect is realized.
在一种可能的设计中,该芯片系统还包括通信接口,通信接口用于输入或输出信息。In a possible design, the chip system further includes a communication interface, which is used for inputting or outputting information.
在一种可能的设计中,该芯片系统还包括存储器,该存储器通过通信接口耦合处理器,用于存储上述指令,以便处理器通过通信接口读取存储器中存储的指令。In a possible design, the system-on-a-chip further includes a memory, which is coupled to the processor through a communication interface and used to store the above-mentioned instructions, so that the processor can read the instructions stored in the memory through the communication interface.
在一种可能的设计中,上述处理器可以为处理电路,本申请对此不作限定。In a possible design, the foregoing processor may be a processing circuit, which is not limited in the present application.
第十六方面,本申请实施例还提供了一种包括指令的计算机程序产品,当其在上述装置上运行时,以执行如上述第一方面至第六方面以及上述第一方面至第六方面可选的设计中任一所述的方法得以实现。In the sixteenth aspect, the embodiment of the present application also provides a computer program product including instructions, when it is run on the above-mentioned device, to execute the above-mentioned first to sixth aspects and the above-mentioned first to sixth aspects Any one of the described methods is implemented in an alternative design.
第十七方面,本申请实施例提供一种计算机可读存储介质,该计算机可读存储介质存储有计算机程序,当计算机程序被运行时,实现如上述第一方面至第六方面以及上述第一方面至第六方面可选的设计中任一所述的方法。In a seventeenth aspect, an embodiment of the present application provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is run, the above-mentioned first to sixth aspects and the above-mentioned first The method described in any one of the optional designs from the aspect to the sixth aspect.
上述第七方面至第十七方面的有益效果,具体请参照上述第一方面至第六方面中相应设计可以达到的技术效果,这里不再重复赘述。For the beneficial effects of the seventh to seventeenth aspects above, please refer to the technical effects that can be achieved by the corresponding designs in the first to sixth aspects above, and will not repeat them here.
附图说明Description of drawings
图1为本申请实施例提供的一种系统架构示意图;FIG. 1 is a schematic diagram of a system architecture provided by an embodiment of the present application;
图2为本申请实施例提供的另一种系统架构示意图;FIG. 2 is a schematic diagram of another system architecture provided by the embodiment of the present application;
图3为本申请实施例一提供的一种车辆通信的方法流程示意图;FIG. 3 is a schematic flowchart of a vehicle communication method provided in Embodiment 1 of the present application;
图4为本申请实施例一提供的另一种车辆通信的方法流程示意图;FIG. 4 is a schematic flowchart of another vehicle communication method provided in Embodiment 1 of the present application;
图5为本申请实施例一提供的另一种车辆通信的方法流程示意图;FIG. 5 is a schematic flowchart of another vehicle communication method provided in Embodiment 1 of the present application;
图6为本申请实施例二提供的一种车辆通信的方法流程示意图;FIG. 6 is a schematic flowchart of a vehicle communication method provided in Embodiment 2 of the present application;
图7为本申请实施例二提供的另一种车辆通信的方法流程示意图;FIG. 7 is a schematic flowchart of another vehicle communication method provided in Embodiment 2 of the present application;
图8为本申请实施例二提供的另一种车辆通信的方法流程示意图;FIG. 8 is a schematic flowchart of another vehicle communication method provided in Embodiment 2 of the present application;
图9为本申请实施例二提供的另一种车辆通信的方法流程示意图;FIG. 9 is a schematic flowchart of another vehicle communication method provided in Embodiment 2 of the present application;
图10为本申请实施例提供的一种车辆通信装置的结构示意图;FIG. 10 is a schematic structural diagram of a vehicle communication device provided in an embodiment of the present application;
图11为本申请实施例提供的另一种车辆通信装置的结构示意图;Fig. 11 is a schematic structural diagram of another vehicle communication device provided by an embodiment of the present application;
图12为本申请实施例提供的一种芯片系统的结构示意图。FIG. 12 is a schematic structural diagram of a chip system provided by an embodiment of the present application.
具体实施方式detailed description
首先,对本申请实施例中涉及的部分用语进行解释说明,以便于理解。First, some terms involved in the embodiments of the present application are explained for ease of understanding.
1)证书(certificate):指数字证书,是一个经证书认证中心(certificate authority,CA)数字签名的包含公开密钥拥有者信息以及公开密钥的文件,用于通信双方的身份认证。证书一般包含证书版本号(version)、序列号(serial number)、签名算法标识符(signature)、颁发者名称(issuer)、主体公钥信息(subject public key info)、有效期(validity)等信息;还可以包含颁发者的标识符(issuer unique identifier)、主体标识符(subject unique identifier)以及其他的扩展信息(extensions)。本申请实施例涉及车辆的证书,该证书对应一个公钥和私钥,进而在车辆之间通信的过程中,车辆可以利用这证书的公钥和私钥进行相应的加密和解密操作。1) Certificate (certificate): Refers to a digital certificate, which is a document digitally signed by a certificate authority (CA) that contains public key owner information and a public key, and is used for identity authentication of both communication parties. A certificate generally includes certificate version number (version), serial number (serial number), signature algorithm identifier (signature), issuer name (issuer), subject public key information (subject public key info), validity period (validity) and other information; It can also contain the issuer's identifier (issuer unique identifier), subject identifier (subject unique identifier) and other extended information (extensions). The embodiment of this application relates to the certificate of the vehicle, which corresponds to a public key and a private key, and in the process of communication between vehicles, the vehicle can use the public key and private key of the certificate to perform corresponding encryption and decryption operations.
2)签名信息(certificate):指数字证书,是一个经证书认证中心(certificate authority,CA)数字签名的包含公开密钥拥有者信息以及公开密钥的文件,用于通信双方的身份认证。本申请实施例中的签名信息是用于验证车辆的身份信息。2) Signature information (certificate): Refers to a digital certificate, which is a document digitally signed by a certificate authority (CA) that contains public key owner information and a public key, and is used for identity authentication of both communication parties. The signature information in this embodiment of the application is used to verify the identity information of the vehicle.
3)领航车:在编队行驶的车队中用于管理车队内任一车辆的车辆信息,例如,车辆标识、车辆编号或车辆证书等。在一些实施例中,领航车还用于确定会话密钥,并将会话密钥发送至车队内的其他车辆,以使其他车辆使用会话密钥进行加密通信。3) Pilot car: used to manage the vehicle information of any vehicle in the fleet, such as vehicle identification, vehicle number or vehicle certificate, etc. In some embodiments, the pilot vehicle is also used to determine a session key and send the session key to other vehicles in the fleet so that the other vehicles use the session key for encrypted communications.
4)目标车辆:在一些实施例中,目标车辆为待入队的自由车。在另一些实施例中,目标车辆为申请出队跟随车。目标车辆,主要用于和领航车交互,确定会话密钥,并使用会话密钥进行加密通信。4) Target vehicle: In some embodiments, the target vehicle is a free vehicle to be enqueued. In some other embodiments, the target vehicle is a follow-up vehicle for applying to leave the team. The target vehicle is mainly used to interact with the pilot car, determine the session key, and use the session key for encrypted communication.
5)跟随车:是指在车队内跟随领航车进行行驶的车辆。5) Follower car: refers to the vehicle that follows the lead car in the convoy.
6)自由车:是指车队外的未加入车队的车辆。6) Free vehicles: Refers to vehicles outside the convoy that have not joined the convoy.
7)服务器:用于和领航车进行信息交互,实现对车队的管理,包括但不限于:预先配置所管理的车队的证书、车队中各组员车辆的车辆信息,为车队中的每一车辆制定车辆编号,示例性地,车辆编号为连续且不重复的正整数。比如,车辆编号为1,2,3…n,n为正整数,车队中的每一车辆的车辆编号不同。还可以与车队中的车辆进行通信,例如,领航车辆向应用服务器发送车队创建通知,进而服务器可以实现对车队信息(车队中的每一车辆的车辆信息、编号和证书等信息)。示例性地,车辆与应用服务器之间的通信方式可以是V2X通信方式。示例性地,该服务器可以为车辆网应用服务器(V2X application server,V2X AS)。7) Server: It is used for information interaction with the pilot car to realize the management of the fleet, including but not limited to: pre-configuring the certificate of the managed fleet, the vehicle information of each team member's vehicle in the fleet, and providing information for each vehicle in the fleet Formulate the vehicle number, for example, the vehicle number is a continuous and non-repeating positive integer. For example, the vehicle numbers are 1, 2, 3...n, n is a positive integer, and each vehicle in the fleet has a different vehicle number. It is also possible to communicate with the vehicles in the fleet, for example, the pilot vehicle sends a fleet creation notification to the application server, and then the server can realize the information of the fleet (the vehicle information, serial number, certificate and other information of each vehicle in the fleet). Exemplarily, the communication manner between the vehicle and the application server may be a V2X communication manner. Exemplarily, the server may be a vehicle network application server (V2X application server, V2X AS).
8)PC5(直连通信接口):终端与终端之间的通信接口,即车、人、道路基础设施之间的短距离直接通信接口;其特点是:通过直连、广播、网络调度的形式实现低时延、高容量、高可靠的通信。8) PC5 (direct connection communication interface): the communication interface between terminals, that is, the short-distance direct communication interface between vehicles, people, and road infrastructure; its characteristics are: through direct connection, broadcasting, and network scheduling Realize low-latency, high-capacity, and highly reliable communications.
本申请实施例中的术语“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B的情况,其中A,B可以是单数或者复数。字符“/”一般表示前后关联对象是一种“或”的关系。“以下至少一项(个)”或其类似表达,是指的这些项中的任意组合,包括单项(个)或复数项(个)的任意组合。例如,a,b,或c中的至少一项(个),可以表示:a,b,c,a和b,a和c,b和c,或a和b和c。The term "multiple" in the embodiments of the present application means two or more. "And/or" describes the association relationship of associated objects, indicating that there can be three types of relationships, for example, A and/or B, which can mean: A exists alone, A and B exist at the same time, and B exists alone, where A, B can be singular or plural. The character "/" generally indicates that the contextual objects are an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one item (piece) of a, b, or c may represent: a, b, c, a and b, a and c, b and c, or a and b and c.
以及,除非有相反的说明,本申请实施例提及“第一”、“第二”等序数词是用于对多个对象进行区分,不用于限定多个对象的顺序、时序、优先级或者重要程度。例如,第一通知消息和第二通知消息,只是为了区分不同的通知消息,而并不是表示这两种通知消息的内容、优先级或者重要程度等的不同。And, unless otherwise stated, the ordinal numerals such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects, and are not used to limit the order, timing, priority or priority of multiple objects. Importance. For example, the first notification message and the second notification message are only for distinguishing different notification messages, and do not represent the difference in content, priority or importance of the two notification messages.
此外,本申请实施例和权利要求书及附图中的术语“包括”和“具有”不是排他的。例如,包括了一系列步骤或模块的过程、方法、系统、产品或设备,不限定于已列出的步骤或模块,还可以包括没有列出的步骤或模块。In addition, the terms "comprising" and "having" in the embodiments of the present application, claims and drawings are not exclusive. For example, a process, method, system, product or device that includes a series of steps or modules is not limited to the listed steps or modules, and may also include unlisted steps or modules.
为了实现车辆之间的安全通信,本申请实施例提供一种车辆通信方法及装置,在该方法中,领航车和目标车辆进行通信交互,以及利用目标车辆的证书的公钥对第一会话密钥进行加密传输,使得目标车辆可以安全地获取到会话密钥,进而有效提升密钥传输的安全性和可靠性,进而使得车辆之间可以安全通信,从而降低车辆之间的机密信息被窃取的风险。该方法中详细的技术方案请参见下文的实施例一。In order to realize secure communication between vehicles, an embodiment of the present application provides a vehicle communication method and device. In this method, the pilot vehicle communicates with the target vehicle, and uses the public key of the target vehicle's certificate to encrypt the first session. The key is encrypted and transmitted, so that the target vehicle can safely obtain the session key, thereby effectively improving the security and reliability of the key transmission, thereby enabling safe communication between vehicles, thereby reducing the risk of confidential information being stolen between vehicles risk. For the detailed technical solution in this method, please refer to the first embodiment below.
为了满足不同通信场景中的车辆之间的安全通信,本申请实施例还提供了另一种车辆通信方法及装置,在该方法中,领航车和服务器进行通信交互,获取第一会话密钥,并基于第一会话密钥对广播信息进行加密传输,进而有效提升密钥传输的安全性和可靠性,进而使得车辆之间可以安全通信,且第一会话密钥由服务器生成,进而可以有效减少队内其他车辆获取会话密钥的时延。该方法中详细的技术方案请参见下文的实施例二。In order to meet the security communication between vehicles in different communication scenarios, the embodiment of the present application also provides another vehicle communication method and device, in this method, the pilot vehicle and the server communicate and interact to obtain the first session key, And based on the first session key, the broadcast information is encrypted and transmitted, thereby effectively improving the security and reliability of key transmission, thereby enabling safe communication between vehicles, and the first session key is generated by the server, which can effectively reduce Delay for other vehicles in the fleet to obtain session keys. For the detailed technical solution in this method, please refer to the second embodiment below.
在详细介绍本申请实施例提供的技术方案之前,首先对本申请实施例所适用的系统架构进行介绍。Before introducing the technical solution provided by the embodiment of the present application in detail, the system architecture applicable to the embodiment of the present application is introduced first.
示例性的,图1示出了本申请实施例适用的一种系统架构示意图。Exemplarily, FIG. 1 shows a schematic diagram of a system architecture applicable to this embodiment of the present application.
如图1所示,该系统架构包括领航车1、跟随车2、跟随车3、跟随车4和自由车5。As shown in Figure 1, the system architecture includes a leading car 1, a following car 2, a following car 3, a following car 4 and a free car 5.
其中,领航车1、跟随车2、跟随车3和跟随车4组成了一支车队,跟随车2、跟随车3和跟随车4在领航车1的带领下进行行驶;任意两车之间可以通过通信网络建立通信连接,进行通信交互。Among them, the leading car 1, the following car 2, the following car 3 and the following car 4 form a fleet, and the following car 2, the following car 3 and the following car 4 travel under the leadership of the leading car 1; any two cars can A communication connection is established through a communication network for communication interaction.
其中,领航车1可以生成第一会话密钥,并将该第一会话密钥加密传输给跟随车2、跟随车3和跟随车4,进而跟随车2、跟随车3和跟随车4可以根据该第一会话密钥对它们之间的广播信息进行加密传输,以提升车辆之间通信的安全性。Among them, the pilot car 1 can generate the first session key, and encrypt and transmit the first session key to the following car 2, the following car 3, and the following car 4, and then the following car 2, the following car 3, and the following car 4 can be based on The first session key encrypts and transmits the broadcast information between them, so as to improve the security of the communication between the vehicles.
其中,自由车5是该车队以外的自由车。Among them, free car 5 is a free car outside the convoy.
在一种可能的实施方式中,领航车1可以和自由车5进行通信交互。例如,自由车5可以向领航车1发送包含自由车5的证书的入队请求消息,领航车1响应于该请求消息,领航车利用自由车5的证书的公钥将第一会话密钥加密传输给自由车5,以及将领航车1的领航车的证书发送给自由车5,以使自由车5入队。In a possible implementation manner, the pilot vehicle 1 can communicate with the free vehicle 5 . For example, the free car 5 can send an enlisting request message containing the certificate of the free car 5 to the pilot car 1, and the pilot car 1 responds to the request message, and the pilot car encrypts the first session key with the public key of the certificate of the free car 5 Transmit to free car 5, and send the certificate of the pilot car of lead car 1 to free car 5, so that free car 5 can join the team.
应理解,上述车辆中均设置有车载通信设备,不同车辆之间的通信交互,可以理解为不同车载通信设备之间的交互。It should be understood that the above-mentioned vehicles are all provided with in-vehicle communication devices, and the communication interaction between different vehicles may be understood as the interaction between different in-vehicle communication devices.
应理解,图1中所示出的两个车辆仅为一种示例,不作为本申请的限定。在实际应用中,一个车队中可以包括更多的车辆,本申请对车队中车辆的数量不做限定。另外,图1所示的架构可以应用到多种通信场景中,例如,第五代(the 5th generation,5G)通信系统、未来的第六代通信系统和演进的其他通信系统、第四代(the 4th generation,4G)通信系统、车到万物(vehicle to everything,V2X)、长期演进-车联网(LTE-vehicle,LTE-V)、车到车(vehicle to vehicle,V2V)、车联网、机器类通信(machine type communications,MTC)、物联网(internet of things,IoT)、长期演进-机器到机器(LTE-machine to machine,LTE-M)、机器到机器(machine to machine,M2M)等通信场景中,本申请对此不作限定。It should be understood that the two vehicles shown in Fig. 1 are only an example, and are not intended to limit this application. In practical applications, more vehicles may be included in a fleet, and this application does not limit the number of vehicles in the fleet. In addition, the architecture shown in Figure 1 can be applied to various communication scenarios, for example, the fifth generation (the 5th generation, 5G) communication system, the future sixth generation communication system and other evolved communication systems, the fourth generation ( the 4th generation, 4G) communication system, vehicle to everything (V2X), long-term evolution-vehicle networking (LTE-vehicle, LTE-V), vehicle to vehicle (vehicle to vehicle, V2V), vehicle networking, machine Communications such as machine type communications (MTC), Internet of things (IoT), long-term evolution-machine to machine (LTE-machine to machine, LTE-M), machine to machine (machine to machine, M2M) In the scenario, this application does not limit it.
在一些实施例中,本申请实施例适用的系统架构中还可以包括服务器。示例性的,图2示出了本申请实施例适用的另一种系统架构示意图。In some embodiments, the system architecture applicable to the embodiments of the present application may further include a server. Exemplarily, FIG. 2 shows a schematic diagram of another system architecture applicable to this embodiment of the present application.
如图2所示,服务器6可以和车队中的任意车辆进行通信交互。As shown in FIG. 2 , the server 6 can communicate with any vehicle in the fleet.
在一种可能的实施方式中,服务器6可以接收来自领航车1的车队创建通知消息,并响应于车队创建通知消息,向领航车1发送第一会话密钥,以使领航车1根据第一会话密钥对车辆与车辆之间需要交互的数据进行加密,以此实现车辆之间的安全通信。In a possible implementation, the server 6 may receive the fleet creation notification message from the pilot car 1, and in response to the fleet creation notification message, send the first session key to the pilot car 1, so that the pilot car 1 The session key encrypts the data that needs to be interacted between vehicles, so as to realize secure communication between vehicles.
以上介绍了本申请实施例适用的系统架构,以下介绍本申请实施例涉及的场景。The above describes the applicable system architecture of the embodiment of the present application, and the following describes the scenarios involved in the embodiment of the present application.
1、创建车队场景1. Create a convoy scene
静止或行驶状态的自由车5,向预设行驶区域内的其他车辆发起广播信息“创建车队”,在接收到其他车辆的确认指令之后,自由车5的角色变换为领航车,并向其他车辆广播领航车的信息。The free car 5 in the stationary or driving state initiates a broadcast message "creating a fleet" to other vehicles in the preset driving area. Broadcast the information of the pilot car.
2、加入车队场景2. Join the convoy scene
自由车5接收到领航车1的组队信息后,如果想要加入车队,则向领航车发起入队请求消息;领航车1接收到自由车5的入队请求消息后,确认是否让自由车5加入车队。如果接受自由车5为成员,则领航车1将车队成员管理信息中车队申请状态置为确认同意加入车队状态,并在车队信息列表中增加自由车5的车辆标识,并向队内其他车辆广播更新后的车队状态;自由车5接收到领航车1广播的确认同意加入该车队的回复,则将自由车5设置行驶状态为加入车队状态,广播状态信息,并加入车队后进行跟驰。此时自由车5的属性及角色转变为跟随车,将自身的行驶状态设置为跟驰状态,并广播自身的状态信息。若领航车1不同意自由车5加入该车队,则不理会该自由车5,自由车5的角色继续保持自由车类型。After Liberty Car 5 receives the team formation information of Pilot Car 1, if it wants to join the team, it sends a team request message to the Pilot Car; 5 to join the convoy. If Liberty Car 5 is accepted as a member, Pilot Car 1 will set the fleet application status in the team member management information to confirm the status of agreeing to join the team, and add the vehicle identification of Liberty Car 5 in the fleet information list, and broadcast to other vehicles in the team The status of the fleet after the update; Liberty car 5 receives the reply from the pilot car 1 broadcast confirming that it agrees to join the fleet, then sets the driving state of Liberty car 5 as the state of joining the convoy, broadcasts status information, and follows after joining the convoy. At this moment, the attribute and role of the free car 5 are transformed into a following car, and its own driving state is set as a following state, and broadcasts its own state information. If the pilot car 1 does not agree with the free car 5 to join the team, then ignore the free car 5, and the role of the free car 5 continues to maintain the free car type.
3、离开车队场景3. Leaving the convoy scene
跟随车2向领航车1发送出队申请消息,领航车1接收到出队申请消息后,同意跟随车2出队,向跟随车2发送出队响应信息;跟随车2在收到该响应消息后,将车辆行驶状态设置为离队,并进行广播,直到跟随车2完全离开车队,设置自身角色为自由车;领航车1确认跟随车2可以离开车队,则将跟随车2的车辆标识移出车队信息列表中,并加入到离队列表中。Follower car 2 sends an application message to lead car 1. After receiving the message, lead car 1 agrees to leave the team with follower car 2 and sends a response message to follower car 2. After receiving the response message, follower car 2 Finally, set the driving state of the vehicle to leave the team, and broadcast until the follower car 2 completely leaves the team, and set its own role as a free car; the lead car 1 confirms that the follower car 2 can leave the team, and then removes the vehicle identification of the follower car 2 from the team Information list, and added to the queue list.
4、领航车切换场景。4. The pilot car switches scenes.
在领航车切换场景中,领航车1可以向跟随车2发送领航车切换请求消息,并在接收到跟随车2的确认响应之后,进行领航车切换;或者,跟随车2可以向领航车1发送领航车切换请求消息,并在接收到领航车A的确认响应之后,进行领航车切换。In the pilot car switching scenario, the pilot car 1 can send a pilot car switching request message to the following car 2, and after receiving the confirmation response from the following car 2, switch the pilot car; or, the following car 2 can send a message to the pilot car 1. The pilot car switching request message, and after receiving the confirmation response from the pilot car A, the pilot car switching is performed.
上述自由车5、跟随车2、领航车1仅仅为结合图1给出的示例性描述,本申请实施例对此不作限定。The free car 5 , the following car 2 , and the leading car 1 described above are only exemplary descriptions given in conjunction with FIG. 1 , and are not limited in this embodiment of the present application.
以上介绍了本申请实施例涉及的应用场景,下面结合具体的示例介绍本申请实施例提供的技术方案。The application scenarios involved in the embodiments of the present application are introduced above, and the technical solutions provided in the embodiments of the present application are introduced below in combination with specific examples.
【实施例一】[Example 1]
图3示出了本申请实施例一提供的一种车辆通信的方法,该方法可以应用于图1所示的系统架构中,该方法主要涉及目标车辆请求入队的场景,该方法包括以下流程:Fig. 3 shows a vehicle communication method provided by Embodiment 1 of the present application. This method can be applied to the system architecture shown in Fig. 1. This method mainly involves the scene where the target vehicle requests to join the team. The method includes the following process :
S301、目标车辆向领航车发送入队请求消息,领航车接收该入队请求消息。S301. The target vehicle sends a queue entry request message to the pilot vehicle, and the pilot vehicle receives the queue entry request message.
其中,入队请求消息中携带有目标车辆的证书。Wherein, the entry request message carries the certificate of the target vehicle.
应理解,目标车辆的证书为车辆证书颁发机构为该目标车辆颁发的,用于唯一标识该目标车辆的合法身份。其中,目标车辆的证书可以是车辆管理人员预配置在目标车辆中的, 也可以是目标车辆与该车辆证书颁发机构进行通信交互获得的,本申请实施例不作限定。It should be understood that the certificate of the target vehicle is issued for the target vehicle by the vehicle certification authority, and is used to uniquely identify the legal identity of the target vehicle. Wherein, the certificate of the target vehicle may be pre-configured in the target vehicle by the vehicle manager, or may be obtained through communication and interaction between the target vehicle and the vehicle certificate issuing authority, which is not limited in this embodiment of the present application.
S302、领航车向目标车辆发送入队响应消息,目标车辆接收该入队响应消息。S302. The pilot vehicle sends a queue entry response message to the target vehicle, and the target vehicle receives the queue entry response message.
其中,该入队响应消息携带有第一密文、目标车辆的证书对应的第一标识和领航车的证书。领航车的证书可以用于验证领航车的身份。所述第一标识用于指示目标车辆根据其自身的证书的私钥对第一密文进行解密以获取第一会话密钥,以及获取领航车的证书。其中,所述第一标识可以是目标车辆的证书对应的HashID。Wherein, the entry response message carries the first ciphertext, the first identification corresponding to the certificate of the target vehicle, and the certificate of the pilot vehicle. The certificate of the pilot car can be used to verify the identity of the pilot car. The first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key, and to obtain the certificate of the pilot vehicle. Wherein, the first identifier may be a HashID corresponding to the certificate of the target vehicle.
在一种可能的实施方式中,领航车可以根据目标车辆的证书的公钥对第一会话密钥进行加密得到第一密文。如此,有效实现第一会话密钥的安全传输,有效降低第一会话密钥被窃取的风险。In a possible implementation manner, the pilot vehicle may encrypt the first session key according to the public key of the certificate of the target vehicle to obtain the first ciphertext. In this way, the secure transmission of the first session key is effectively realized, and the risk of the first session key being stolen is effectively reduced.
需要说明的是,上述第一会话密钥可以是领航车预先生成并存储在本地的,也可以是领航车在接收到目标车辆的入队请求消息之后生成的,这里不作具体的限制。It should be noted that the above-mentioned first session key may be pre-generated by the pilot vehicle and stored locally, or may be generated by the pilot vehicle after receiving the enqueue request message from the target vehicle, which is not specifically limited here.
在一种可能的实施方式中,领航车在生成第一会话密钥之前,还需要创建车队。其中,领航车创建车队的过程可以是:领航车根据车辆的位置、行驶方向等信息挑选该领航车预设区域内的1个或多个自由车与该领航车组成车队,领航车向该一个或多个自由车发送车队创建请求;该一个或多个自由车同意组建车队后,向领航车发送确认响应消息,领航车接收该确认响应消息,并为一个或多个自由车编制在车队中的编号。应理解的是,领队车还可以存储有车队中各车辆的证书、车辆的标识等信息。示例性地,车辆的标识可以是车辆识别号码(vehicle identification number,VIN),VIN可以是生产商为该车辆分配的,每个车辆具有专属的VIN。In a possible implementation manner, before the pilot vehicle generates the first session key, it also needs to create a fleet. Among them, the process of creating a fleet by the pilot car can be: the pilot car selects one or more free vehicles in the preset area of the pilot car to form a fleet with the pilot car according to information such as the position and driving direction of the vehicle, One or more free cars send fleet creation requests; after the one or more free cars agree to form a fleet, they send a confirmation response message to the pilot car, and the pilot car receives the confirmation response message and compiles one or more free cars in the fleet number. It should be understood that the team leader car may also store information such as certificates and vehicle identifications of each vehicle in the convoy. Exemplarily, the identifier of the vehicle may be a vehicle identification number (vehicle identification number, VIN). The VIN may be assigned to the vehicle by the manufacturer, and each vehicle has its own unique VIN.
需要说明的是,上述组建车队的方式仅为举例,不应构成对本申请实施例组建车队的限定,任何组建车队的方式均适用于本申请实施例。It should be noted that the above method of forming a fleet is only an example, and should not be construed as a limitation on the formation of a fleet in this embodiment of the application, and any manner of forming a fleet is applicable to this embodiment of this application.
S303、目标车辆根据其自身的证书的私钥对第一密文进行解密,以获取第一会话密钥。S303. The target vehicle decrypts the first ciphertext according to the private key of its own certificate, so as to obtain the first session key.
在一种可能的实施方式中,第一会话密钥可以包括加密密钥和加密算法,进而目标车辆通过解密获得第一会话密钥之后,就可以基于该加密密钥和加密算法,对其与车队内的其他车辆之间的广播信息进行加密。In a possible implementation manner, the first session key may include an encryption key and an encryption algorithm, and then after the target vehicle obtains the first session key through decryption, it can compare the encryption key and the encryption algorithm with Broadcast messages between other vehicles in the fleet are encrypted.
在一种可能的实施方式中,第一会话密钥可以包括加密密钥凭据和加密算法,进而领航车可以将第一会话密钥发送至目标车辆之后,目标车辆根据预设的算法对加密密钥凭据进行处理,生成加密密钥;再基于该加密密钥和加密算法,对其与车队内的其他车辆之间的广播信息进行加密。其中,预设算法可以是SM4,AES,3DES等,本申请实施例不作限制。In a possible implementation, the first session key may include an encryption key credential and an encryption algorithm, so that after the pilot vehicle sends the first session key to the target vehicle, the target vehicle encrypts the encryption key according to a preset algorithm. The key credentials are processed to generate an encryption key; then based on the encryption key and encryption algorithm, the broadcast information between it and other vehicles in the fleet is encrypted. Wherein, the preset algorithm may be SM4, AES, 3DES, etc., which are not limited in this embodiment of the present application.
S304、目标车辆获取领航车的证书。S304. The target vehicle obtains the certificate of the pilot vehicle.
在一种可能的实施方式中,目标车辆获取到领航车的证书之后可以把该证书保存在本地,以便后续目标车辆接收到领航车的信息之后,可以根据该证书验证领航车的身份。In a possible implementation, after the target vehicle obtains the certificate of the pilot car, it can save the certificate locally, so that after the target vehicle receives the information of the pilot car, it can verify the identity of the pilot car according to the certificate.
在图3所示的实施例中,作为待入队车辆目标车辆向领航车发起入队请求,领航车利用目标车辆的证书的公钥将第一会话密钥加密传输给目标车辆。如此,有效提高密钥传输的安全性和可靠性,从而有效实现车辆之间的安全通信。In the embodiment shown in FIG. 3 , as a vehicle to be joined, the target vehicle initiates a queue entry request to the pilot vehicle, and the pilot vehicle uses the public key of the target vehicle's certificate to encrypt and transmit the first session key to the target vehicle. In this way, the security and reliability of key transmission are effectively improved, thereby effectively realizing secure communication between vehicles.
图4示出了本申请实施例一提供的另一种车辆通信的方法,该方法可以应用于图1所示的架构中,该方法涉及目标车辆请求出队的场景,该方法包括以下流程:FIG. 4 shows another vehicle communication method provided by Embodiment 1 of the present application. This method can be applied to the architecture shown in FIG. 1. This method involves the scene where the target vehicle requests to leave the team. The method includes the following process:
S401、目标车辆向领航车发送出队请求消息,领航车接收该出队请求消息。S401. The target vehicle sends a dequeue request message to the pilot vehicle, and the pilot vehicle receives the dequeue request message.
其中,该出队请求消息中包括目标车辆的车辆标识。Wherein, the dequeue request message includes the vehicle identification of the target vehicle.
在一种可能的实施方式中,领航车接收到该出队请求消息,将目标车辆的车辆标识从车队内的车辆信息列表中删除,更新车队中的车辆列表。示例性的,领航车所在车队的原始车队列表如表1所示,领航车将目标车辆的车辆标识从车队中的车辆列表中删除之后,得到如表2所示的更新后的车队列表。In a possible implementation manner, the pilot vehicle receives the dequeue request message, deletes the vehicle identifier of the target vehicle from the vehicle information list in the fleet, and updates the vehicle list in the fleet. Exemplarily, the original fleet list of the fleet where the pilot car is located is shown in Table 1. After the pilot car deletes the vehicle identification of the target vehicle from the vehicle list in the fleet, the updated fleet list shown in Table 2 is obtained.
表1Table 1
Figure PCTCN2022104804-appb-000001
Figure PCTCN2022104804-appb-000001
表2Table 2
Figure PCTCN2022104804-appb-000002
Figure PCTCN2022104804-appb-000002
S402、领航车响应于出队请求消息,向目标车辆发送出队响应消息,目标车辆接收该出队响应消息。S402. The pilot vehicle sends a dequeue response message to the target vehicle in response to the dequeue request message, and the target vehicle receives the dequeue response message.
S403、目标车辆执行出队操作。S403. The target vehicle executes a dequeue operation.
在一种可能的实施方式中,目标车辆执行出队操作的过程可以是:将自身的车辆行驶状态设置为离队状态,并向车队里的所有车辆进行广播,并将自身角色为设置为自由车。In a possible implementation manner, the process for the target vehicle to perform the operation of leaving the team may be: setting its own vehicle driving state as the leaving state, and broadcasting to all vehicles in the team, and setting its own role as a free vehicle .
S404、领航车生成第二会话密钥,根据其所在车队中的组员车辆的证书的公钥对第二会话密钥进行加密,得到第二密文。S404. The pilot car generates a second session key, and encrypts the second session key according to the public keys of the certificates of the team members' vehicles in the convoy where it is located, to obtain a second ciphertext.
应理解,第二密文可以理解为一个或多个密文,每个密文可以是领航车可以根据各个组员车辆的证书的公钥对第二会话密钥进行加密得到的。It should be understood that the second ciphertext can be understood as one or more ciphertexts, and each ciphertext can be obtained by the pilot car encrypting the second session key according to the public key of the certificate of each team member vehicle.
例如,该车队中有组员车辆1、组员车辆2、组员车辆3,则第二密文为密文1、密文2、密文3,其中,密文1是根据组员车辆1的证书的公钥进行加密得到的,密文2是根据组员车辆2的证书的公钥进行加密得到的,密文3是根据组员车辆3的证书的公钥进行加密得到的。For example, if there are member vehicle 1, member vehicle 2, and member vehicle 3 in the convoy, then the second ciphertext is ciphertext 1, ciphertext 2, and ciphertext 3, wherein ciphertext 1 is based on the The ciphertext 2 is obtained by encrypting the public key of the certificate of the member vehicle 2, and the ciphertext 3 is obtained by encrypting the public key of the certificate of the member vehicle 3.
S405、领航车基于第一签名信息、所述领航车所在车队中的其他车辆的证书对应的第二标识和第二密文,生成第一通知消息,并向其他车辆发送第一通知消息,其他车辆接收该第一通知消息。S405. The pilot car generates a first notification message based on the first signature information, the second identification corresponding to the certificates of other vehicles in the fleet where the pilot car is located, and the second ciphertext, and sends the first notification message to other vehicles, and other The vehicle receives the first notification message.
其中,所述其他车辆的证书对应的第二标识用于指示所述其他车辆根据其的证书的私钥对所述第二密文进行解密,以获取所述第二会话密钥。其中,所述第二标识可以其他车辆的证书对应的HashID。Wherein, the second identifier corresponding to the certificate of the other vehicle is used to instruct the other vehicle to decrypt the second ciphertext according to the private key of the certificate, so as to obtain the second session key. Wherein, the second identifier may be a HashID corresponding to a certificate of another vehicle.
在一种可能的实施方式中,第一签名信息是领航车使用领航车对应证书的私钥进行签名操作后得到的。其中,本申请实施例对签名算法不作限定,以下示例性地列举几种,签名算法可以是ECDSA或基于SM2的签名算法。In a possible implementation manner, the first signature information is obtained after the pilot car performs a signature operation using the private key of the certificate corresponding to the pilot car. Wherein, the embodiment of the present application does not limit the signature algorithm, and some examples are listed below, and the signature algorithm may be ECDSA or SM2-based signature algorithm.
S406、其他车辆根据领航车的证书和第一签名信息验证领航车的身份。S406. The other vehicle verifies the identity of the pilot car according to the certificate of the pilot car and the first signature information.
应理解,其他车辆是指领航车所在车队中的跟随车,具体可以是一个或多个车辆,本申请实施例不作限制。It should be understood that other vehicles refer to the following vehicles in the convoy where the leading vehicle is located, and may specifically be one or more vehicles, which is not limited in this embodiment of the present application.
举例来说,假设领航车所在车队中有跟随车2、跟随车3和跟随车4,则跟随车2、跟 随车3和跟随车4接收到第一通知消息后,均可以分别根据领航车的证书和第一签名信息验证领航车的身份。其中,每个跟随车验证领航车身份的过程均类似。下面以一个跟随车为例,对跟随车2对领航车身份进行验证的流程进行示例性描述。For example, assuming that there are following car 2, following car 3 and following car 4 in the convoy where the leading car is located, after receiving the first notification message, following car 2, following car 3 and following car 4 can respectively follow the lead car's The certificate and the first signature information verify the identity of the pilot car. Among them, the process of verifying the identity of the leading car for each following car is similar. Taking a following car as an example, the process of verifying the identity of the leading car by the following car 2 is described as an example.
示例性的,跟随车2对领航车身份进行验证的流程包括:跟随车2获取领航车的证书中包含的该领航车的公钥,并使用该领航车的公钥对第一签名信息进行解密,若解密失败,则领航车的身份未验证通过;若解密成功,则领航车的身份验证通过,继续执行S407。Exemplarily, the process for the follower car 2 to verify the identity of the lead car includes: follower car 2 obtains the public key of the lead car contained in the certificate of the lead car, and uses the public key of the lead car to decrypt the first signature information , if the decryption fails, the identity verification of the pilot car is not passed; if the decryption is successful, the identity verification of the pilot car passes, and the execution of S407 is continued.
S407、其他车辆根据自身的证书的私钥对第二密文进行解密,以获取第二会话密钥。S407. The other vehicle decrypts the second ciphertext according to the private key of its own certificate, so as to obtain the second session key.
应理解,其他车辆中跟随车的数量与第二密文中密文的数量相同,每个跟随车对应一个密文。若其他车辆中涉及多个跟随车,则每个跟随车根据其自身的证书的私钥,对其对应的密文进行解密。It should be understood that the number of following vehicles among other vehicles is the same as the number of ciphertexts in the second ciphertext, and each following vehicle corresponds to one ciphertext. If other vehicles involve multiple following vehicles, each following vehicle decrypts its corresponding ciphertext according to the private key of its own certificate.
在一种可能的实施方式中,其他车辆获取到第二会话密钥之后,其他车辆还可以向领航车发送密钥更新响应消息;领航车接收该密钥更新响应消息,确认车队内所有车辆都正确响应后,向组员车辆发送第一指示消息,以指示组员车辆使用第二会话密钥对PC5口的广播信息进行加密传输。In a possible implementation manner, after other vehicles obtain the second session key, other vehicles can also send a key update response message to the pilot car; the pilot car receives the key update response message and confirms that all vehicles in the fleet have After a correct response, send a first indication message to the team members' vehicles to instruct the team members' vehicles to use the second session key to encrypt and transmit the broadcast information of the PC5 port.
在图4所示的实施例中,领航车在确定车队内的目标车辆离队之后,可以生成新的会话密钥(即第二会话密钥),并将新的密钥下发到车队内的其他组员车辆,以使组员车辆根据新的会话密钥对车辆之间的广播信息进行加密。如此,有效实现车辆之间的安全通信。In the embodiment shown in Fig. 4, after the pilot car determines that the target vehicle in the fleet leaves the team, it can generate a new session key (ie, the second session key), and issue the new key to the vehicle in the fleet. other team member vehicles, so that the team member vehicles can encrypt the broadcast information between vehicles according to the new session key. In this way, secure communication between vehicles is effectively realized.
图5示出了本申请实施例一提供的另一种车辆通信的方法,该方法可以应用于图1所示的架构中,该方法主要涉及领航车切换场景,该方法包括以下流程:Fig. 5 shows another vehicle communication method provided by Embodiment 1 of the present application. This method can be applied to the architecture shown in Fig. 1. This method mainly involves the switching scene of the pilot car, and the method includes the following process:
S501A、目标领航车向原领航车发送切换请求消息,原领航车接收该切换请求消息。S501A. The target pilot vehicle sends a switching request message to the original pilot vehicle, and the original pilot vehicle receives the switching request message.
其中,切换请求消息用于指示目标领航车请求切换领航车,该切换请求消息中携带有目标领航车的车辆标识。Wherein, the switching request message is used to instruct the target pilot vehicle to request switching of the pilot vehicle, and the switching request message carries the vehicle identification of the target pilot vehicle.
应理解,原领航车可以理解为当前车队的领航车,目标领航车可以进行领航车切换后的得到的车队的领航车。It should be understood that the original pilot car can be understood as the pilot car of the current fleet, and the target pilot car can be the pilot car of the fleet obtained after the pilot car is switched.
S502A、原领航车响应于该切换请求消息,向目标领航车发送切换响应消息,目标领航车接收该切换响应消息。其中,该切换响应消息用于指示目标领航车进行领航车切换。S502A. In response to the switch request message, the original pilot vehicle sends a switch response message to the target pilot vehicle, and the target pilot vehicle receives the switch response message. Wherein, the switching response message is used to instruct the target pilot vehicle to switch the pilot vehicle.
S503A、目标领航车进行领航车切换。S503A. The target pilot car switches the pilot car.
在一种可能的实施方式中,目标领航车进行领航车切换,将自己的车辆行驶状态设置为带队状态,并将自身角色设置为领队车。In a possible implementation manner, the target pilot car switches the pilot car, sets its vehicle driving state as the leading state, and sets its own role as the leading car.
上述S501A-S503A可以替换为S501B-S503B。也就是说,领航车切换可以是目标领航车发起的,也可以是原领航车发起的。The above S501A-S503A can be replaced by S501B-S503B. That is to say, the switching of the pilot car can be initiated by the target pilot car or by the original pilot car.
S501B、原领航车向目标领航车发送切换请求消息,目标领航车接收该切换请求消息。其中,切换请求消息用于指示原领航车请求切换领航车。S501B. The original pilot vehicle sends a switching request message to the target pilot vehicle, and the target pilot vehicle receives the switching request message. Wherein, the switching request message is used to indicate that the original pilot vehicle requests to switch the pilot vehicle.
S502B、目标领航车响应于切换请求消息,向原领航车发送切换响应消息,原领航车接收该切换响应消息。S502B. The target pilot vehicle sends a switching response message to the original pilot vehicle in response to the switching request message, and the original pilot vehicle receives the switching response message.
其中,该切换响应消息用于指示原领航车进行领航车切换。Wherein, the switch response message is used to instruct the original pilot vehicle to switch the pilot vehicle.
S503B、原领航车进行领航车切换。S503B, the original pilot car is switched to the pilot car.
在一种可能的实施方式中,原领航车进行领航车切换,将自己的车辆行驶状态设置为跟驰状态,并将自身角色设置为跟随车;以及将目标领航车的车辆行驶状态设置为带队状态,目标领航车的角色设置为领航车。In a possible implementation manner, the original pilot car switches the pilot car, sets its own vehicle driving state to the following state, and sets its own role to the following car; and sets the vehicle driving state of the target pilot car to Team status, the role of the target pilot car is set to the pilot car.
S504、原领航车向其他车辆发送第二通知消息。S504. The original pilot vehicle sends a second notification message to other vehicles.
其中,第二通知消息包括第二签名信息和目标领航车的证书,第二签名信息用于指示原领航车的身份信息。应理解,这里的其他车辆是指原领航车所在车队中的跟随车,可以是一个或多个,本申请实施例不作限制。当车队中有多个跟随车时,这里的第二通知消息为原领航车发出的广播消息。Wherein, the second notification message includes the second signature information and the certificate of the target pilot vehicle, and the second signature information is used to indicate the identity information of the original pilot vehicle. It should be understood that the other vehicles here refer to the following vehicles in the convoy where the original leading vehicle is located, and there may be one or more vehicles, which are not limited in this embodiment of the present application. When there are multiple following vehicles in the convoy, the second notification message here is the broadcast message sent by the original leading vehicle.
S505、其他车辆根据原领航车的证书和第二签名信息验证原领航车的身份,以及获取目标领航车的证书。S505. The other vehicle verifies the identity of the original pilot car according to the certificate of the original pilot car and the second signature information, and obtains the certificate of the target pilot car.
在一种可能的实施方式中,第二签名信息是根据原领航车的证书的私钥生成的,进而其他车辆可以根据原领航车的证书的公钥对第二签名信息进行解密,若解密成功,则原领航车的身份验证成功,其他车辆获取目标领航车的证书,并保存在本地;若解密失败,则原领航车的身份验证失败,则其他车辆禁止保存目标领航车的证书。In a possible implementation manner, the second signature information is generated according to the private key of the original pilot car certificate, and then other vehicles can decrypt the second signature information according to the public key of the original pilot car certificate. , then the identity verification of the original pilot car is successful, and other vehicles obtain the certificate of the target pilot car and save it locally; if the decryption fails, the identity verification of the original pilot car fails, and other vehicles are prohibited from saving the certificate of the target pilot car.
S506、目标领航车生成第三会话密钥。S506. The target pilot vehicle generates a third session key.
S507、目标领航车向其他车辆发送第三通知消息,第三通知消息包括第三签名信息、所述目标领航车的证书对应的第三标识和第三密文,其他车辆接收第三通知消息。S507. The target pilot vehicle sends a third notification message to other vehicles. The third notification message includes third signature information, a third identifier corresponding to the certificate of the target pilot vehicle, and a third ciphertext. Other vehicles receive the third notification message.
其中,第三标识可以用于指示更新后的车队中的除目标领航车以外的其他车辆根据第一会话密钥对第三密文进行解密,以获取第三会话密钥。第三标识可以是目标领航车的证书对应的HashID。Wherein, the third identifier may be used to instruct other vehicles in the updated convoy except the target pilot vehicle to decrypt the third ciphertext according to the first session key to obtain the third session key. The third identifier may be the HashID corresponding to the certificate of the target pilot vehicle.
S508、其他车辆根据第三签名信息和目标领航车的证书,验证目标领航车的身份。S508. The other vehicle verifies the identity of the target pilot vehicle according to the third signature information and the certificate of the target pilot vehicle.
在一种可能的实施方式中,第三签名信息是根据目标领航车的证书的私钥生成的,进而其他车辆可以根据目标领航车的证书的公钥对第三签名信息进行解密,若解密成功,则目标领航车的身份验证成功,则其他车辆继续执行S509;若解密失败,则目标领航车的身份验证失败。In a possible implementation manner, the third signature information is generated according to the private key of the certificate of the target pilot car, and then other vehicles can decrypt the third signature information according to the public key of the certificate of the target pilot car. , the identity verification of the target pilot car is successful, and the other vehicles continue to execute S509; if the decryption fails, the identity verification of the target pilot car fails.
S509、其他车辆根据第一会话密钥对第三密文进行解密,获取第三会话密钥。S509. The other vehicle decrypts the third ciphertext according to the first session key to obtain the third session key.
在一种可能的实施方式中,第三密文是目标领航车根据第一会话密钥对第三会话密钥进行加密得到的。In a possible implementation manner, the third ciphertext is obtained by the target pilot car encrypting the third session key according to the first session key.
S510、其他车辆向目标领航车发送密钥更新响应消息,目标领航车接收该密钥更新响应消息。S510. Other vehicles send a key update response message to the target pilot vehicle, and the target pilot vehicle receives the key update response message.
S511、目标领航车向其他车辆发送第三指示信息,其他车辆接收该第三指示信息。S511. The target pilot vehicle sends third instruction information to other vehicles, and other vehicles receive the third instruction information.
其中,第三该指示信息用于指示其他车辆基于第三会话密钥,对车辆之间的广播信息进行加密。示例性的,若其他车辆为跟随车2、跟随车3和跟随车4,跟随车2接收到第三指示信息之后,可以基于第三会话密钥对跟随车2和跟随车4之间的广播信息进行加密传输,还可以对跟随车2准备广播给跟随车3、跟随车4和目标领航车的广播消息进行加密传输。Wherein, the third instruction information is used to instruct other vehicles to encrypt broadcast information between vehicles based on the third session key. Exemplarily, if the other vehicles are following car 2, following car 3, and following car 4, after receiving the third indication information, following car 2 can broadcast between following car 2 and following car 4 based on the third session key The information is encrypted and transmitted, and the broadcast message that the following vehicle 2 is going to broadcast to the following vehicle 3, the following vehicle 4 and the target pilot vehicle can also be encrypted and transmitted.
在图5所示的实施例中,原领航车和目标领航车均可以发起领航车切换请求,并且在领航车成功切换之后,目标领航车还可以生成新的会话密钥(即第三会话密钥),并且利用旧的会话密钥(即第一会话密钥)将新的会话密钥加密传输给车队内的其他车辆。如此,有效降低会话密钥被窃取的风险,进而有效实现车辆之间的安全通信。In the embodiment shown in Fig. 5, both the original pilot car and the target pilot car can initiate a pilot car switching request, and after the pilot car switches successfully, the target pilot car can also generate a new session key (that is, the third session key key), and utilize the old session key (i.e. the first session key) to encrypt and transmit the new session key to other vehicles in the fleet. In this way, the risk of the session key being stolen is effectively reduced, thereby effectively realizing secure communication between vehicles.
【实施例二】[Example 2]
图6示出了本申请实施例二提供的一种车辆通信的方法,该方法可以应用于图2所示的系统架构中,该方法主要涉及领航车创建车队的场景,该方法包括以下流程:Fig. 6 shows a vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in Fig. 2. This method mainly involves the scene where the pilot vehicle creates a fleet. The method includes the following process:
S600、领航车创建车队。Create a fleet of S600 and pilot cars.
在一种可能的实施方式中,领航车可以向服务器发送车队组建请求,以指示服务器为领航车组建车队,例如,服务器还可以根据车辆的位置、行驶方向等信息挑选该领航车预设区域内的一个或多个车辆与该领航车组成车队。In a possible implementation, the pilot car can send a fleet formation request to the server to instruct the server to build a fleet for the pilot car. One or more vehicles in the fleet form a convoy with the lead car.
在一种可能的实施方式中,领航车自身组建车队,领航车根据车辆的位置、行驶方向等信息挑选该领航车预设区域内的一个或多个车辆与该领航车组成车队,并执行S601,向服务器发送车队创建通知消息。In a possible implementation manner, the pilot car forms a fleet by itself, and the pilot car selects one or more vehicles in the preset area of the pilot car to form a fleet with the pilot car according to information such as the position and driving direction of the vehicle, and executes S601 , to send a fleet creation notification message to the server.
S601、领航车向服务器发送车队创建通知消息,服务器接收该车队创建通知消息。S601. The pilot car sends a fleet creation notification message to the server, and the server receives the fleet creation notification message.
其中,车队创建通知消息中包括车队标识和车队内车辆的标识。应理解,车队内车辆的标识可以是车辆标识和/或车辆编号。Wherein, the fleet creation notification message includes the fleet identifier and the identifiers of the vehicles in the fleet. It should be understood that the identification of the vehicle in the fleet may be a vehicle identification and/or a vehicle number.
示例性地,若车队中包括4辆车,则车队内车辆的标识包括车辆标识(VIN_1,VIN_2,VIN_3,VIN_4)和车辆编号(1,2,3,4),其中,车辆标识与车辆编号按照排列顺序一一对应。该车队内车辆的标识表征可以为:车辆标识为VIN_1的车辆的车辆编号为1,车辆标识为VIN_2的车辆的车辆编号为2,依次类推。Exemplarily, if there are 4 vehicles in the fleet, the identifications of the vehicles in the fleet include vehicle identifications (VIN_1, VIN_2, VIN_3, VIN_4) and vehicle numbers (1, 2, 3, 4), where the vehicle identification and vehicle number One-to-one correspondence according to the order of arrangement. The identification representation of the vehicles in the fleet may be: the vehicle number of the vehicle with the vehicle identification VIN_1 is 1, the vehicle number of the vehicle with the vehicle identification VIN_2 is 2, and so on.
再示例性地,领航车向服务器发送的车队内车辆的标识可以是车辆标识与车辆编号的组信息,例如:(VIN_1,1),(VIN_2,2),(VIN_3,3)和(VIN_4,4)。As another example, the identification of vehicles in the fleet sent by the pilot car to the server may be a combination of vehicle identification and vehicle number, for example: (VIN_1, 1), (VIN_2, 2), (VIN_3, 3) and (VIN_4, 4).
需要说明的是,上述车辆编号仅为举例,本申请对车辆编号的具体数值不作限定。It should be noted that the above-mentioned vehicle number is only an example, and this application does not limit the specific value of the vehicle number.
S602、服务器生成第一会话密钥。S602. The server generates a first session key.
在一种可能的实施方式中,服务器存储有各个车辆的证书,服务器接收到车队创建通知消息之后,可以根据车队标识和车队内车辆的标识,对车队内的各个车辆的身份信息一一进行验证,在验证通过时,执行S602,生成第一会话密钥;若该车队内出现一个车辆未验证通过,则服务器向领航车发送车队创建失败响应消息。In a possible implementation, the server stores the certificates of each vehicle, and after receiving the fleet creation notification message, the server can verify the identity information of each vehicle in the fleet according to the fleet identifier and the identifiers of the vehicles in the fleet , when the verification is passed, execute S602 to generate a first session key; if there is a vehicle in the fleet that fails the verification, the server sends a fleet creation failure response message to the pilot car.
在一种可能的实施方式中,服务器可以是根据预设的算法的生成第一会话密其中,预设的算法可以包括但不限于对称算法(如SM4,AES等)、随机数生成算法、时间生成算法等任一算法。In a possible implementation manner, the server may generate the first session secret according to a preset algorithm. The preset algorithm may include but not limited to a symmetric algorithm (such as SM4, AES, etc.), a random number generation algorithm, a time Any algorithm, such as a generative algorithm.
S603、服务器向领航车发送第一会话密钥,领航车接收第一会话密钥。S603. The server sends the first session key to the pilot car, and the pilot car receives the first session key.
在一种可能的实施方式中,领航车接收到第一会话密钥之后,可以根据其所在车队中各个跟随车的证书对应的公钥对第一会话密钥进行加密传输给各个跟随车,以使各个跟随车辆可以对车辆之间的广播信息进行加密。In a possible implementation, after the pilot car receives the first session key, it can encrypt and transmit the first session key to each follower car according to the public key corresponding to the certificate of each follower car in its convoy, so as to Allow each following vehicle to encrypt broadcast information between vehicles.
在另一种可能的实施方式中,服务器还可以直接向领航车所在车队中的每个跟随车发送第一会话密钥,并利于各个跟随车的证书对应的公钥对第一会话密钥进行加密传输给对应的跟随车,以使跟随车可以对车辆之间的广播信息进行加密。In another possible implementation manner, the server may also directly send the first session key to each follower vehicle in the convoy where the lead vehicle is located, and facilitate the public key corresponding to the certificate of each follower vehicle to perform the first session key The encryption is transmitted to the corresponding following vehicle, so that the following vehicle can encrypt the broadcast information between vehicles.
在图6所示的实施例中,领航车向服务器发送车队创建通知消息,进而服务器可以验证车队中各个车辆的身份信息,并在验证通过时,对生成第一会话密钥,并将第一会话密钥下发到领航车,以使领航车根据第一会话密钥对车辆之间的广播信息进行加密。如此,有效实现车辆之间的安全通信,且缩短了在组建车队时对车队的成员车辆进行验证的时延,并且提高了会话密钥传输的安全性和可靠性,实现了车辆之间的安全通信。In the embodiment shown in Fig. 6, the pilot car sends a fleet creation notification message to the server, and then the server can verify the identity information of each vehicle in the fleet, and when the verification is passed, generate a first session key and send the first The session key is delivered to the pilot car, so that the pilot car encrypts the broadcast information between vehicles according to the first session key. In this way, the secure communication between vehicles is effectively realized, and the time delay for verifying the member vehicles of the fleet is shortened when the fleet is formed, and the security and reliability of the session key transmission are improved, and the security between vehicles is realized. communication.
图7示出了本申请实施例二提供的一种车辆通信的方法,该方法可以应用于图2所示的系统架构中,该方法主要涉及自由车申请入队的场景,该方法包括以下流程:Fig. 7 shows a vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in Fig. 2. This method mainly involves the scene where a free vehicle applies for joining the team. The method includes the following process :
S700、领航车确定第一车辆请求入队。S700. The pilot vehicle determines that the first vehicle requests to join the team.
示例性的,第一车辆以自由车5为例,领航车接收到自由车5的入队请求消息,进而可以响应于该消息,确定自由车5想要加入领航车所在车队。Exemplarily, the first vehicle takes the free car 5 as an example, the pilot car receives the queue entry request message of the free car 5, and then may respond to the message to determine that the free car 5 wants to join the team of the pilot car.
S701、领航车向服务器发送入队请求通知消息,服务器接收该入队请求通知消息;入队请求通知消息包括车队标识和第一车辆的车辆标识。S701. The pilot car sends a queue entry request notification message to the server, and the server receives the queue entry request notification message; the queue entry request notification message includes a fleet identifier and a vehicle identifier of the first vehicle.
在一种可能的实施方式中,服务器本地存储有第一车辆的证书,进而服务器可以根据第一车辆的证书和第一车辆的标识对第一车辆的身份信息进行验证,在验证通过时,执行S702,向第一车辆发送第一会话密钥。In a possible implementation, the server stores the certificate of the first vehicle locally, and then the server can verify the identity information of the first vehicle according to the certificate of the first vehicle and the identification of the first vehicle, and when the verification passes, execute S702. Send the first session key to the first vehicle.
S702、服务器向第一车辆发送第一会话密钥,第一车辆接收第一会话密钥。S702. The server sends the first session key to the first vehicle, and the first vehicle receives the first session key.
在一种可能的实施方式中,第一车辆接收到第一会话密钥,可以根据第一会话密钥对其与领航车之间的广播信息进行加密,或者对其与领航车所在车队的其他跟随车之间的广播信息进行加密。In a possible implementation manner, the first vehicle receives the first session key, and can encrypt the broadcast information between it and the pilot vehicle according to the first session key, or Encrypt the broadcast information between vehicles.
在图7所示的实施例中,服务器可以实现对车队的会话密钥的管理,在确定有待入队车辆时,领航车可以向服务器发送入队请求通知消息,服务器响应该通知消息,在待入队车辆的身份验证通过时,向待入队车辆发送第一会话密钥,使得待入队车辆可以使用第一会话密钥对广播信息进行加密。如此,有助于提升车辆之间的通信的安全性和可靠性。In the embodiment shown in Fig. 7, the server can realize the management of the session key of the fleet, and when it is determined that there is a vehicle to enter the queue, the pilot car can send a queue request notification message to the server, and the server responds to the notification message and waits to enter the queue. When the identity verification of the entering vehicle passes, the first session key is sent to the waiting vehicle, so that the waiting vehicle can use the first session key to encrypt the broadcast information. In this way, it helps to improve the safety and reliability of communication between vehicles.
图8示出了本申请实施例二提供的另一种车辆通信的方法,该方法可以应用于图2所示的系统架构中,该方法主要涉及跟随车申请出队的场景,该方法包括以下流程:Fig. 8 shows another vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in Fig. 2. This method mainly involves the scene of following the vehicle to apply for leaving the team. The method includes the following process:
S800、领航车确定第二车辆请求出队。S800. The pilot vehicle determines that the second vehicle requests to leave the team.
示例性的,第二车辆以跟随车4为例,领航车接收到跟随车4的出队请求消息,进而可以响应于该消息,确定跟随车4满足出队条件(例如,无正在执行的作业任务),则同意跟随车4出队。Exemplarily, the second vehicle takes the follower car 4 as an example, and the lead car receives the dequeue request message of the follower car 4, and then may respond to the message and determine that the follower car 4 satisfies the dequeue condition (for example, there is no ongoing operation task), agree to follow car 4 out of the team.
S801、领航车向服务器发送出队请求通知消息,服务器接收该出队请求通知消息;入队请求通知消息包括车队标识和第二车辆标识。S801. The pilot car sends a queue-out request notification message to the server, and the server receives the queue-out request notification message; the queue-entry request notification message includes a fleet identifier and a second vehicle identifier.
在一种可能的实施方式中,服务器接收该出队请求通知消息,将第二车辆标识从车队中车辆列表中移除,得到更新后的车辆列表,并执行S802。In a possible implementation manner, the server receives the dequeue request notification message, removes the second vehicle identifier from the vehicle list in the fleet, obtains an updated vehicle list, and executes S802.
S802、服务器生成第二会话密钥。S802. The server generates a second session key.
S803、服务器向其他车辆发送第二会话密钥,其他车辆接收第二会话密钥。S803. The server sends the second session key to other vehicles, and the other vehicles receive the second session key.
应理解,这里的车辆是指更新后的车队中除领航车以外的其他跟随车。It should be understood that the vehicles here refer to other following vehicles in the updated fleet except the leading vehicle.
在一种可能的实施方式中,其他车辆接收到第二会话密钥,可以根据第二会话密钥对其与领航车之间的广播信息进行加密,或者对其与其他跟随车之间的广播信息进行加密。In a possible implementation, other vehicles receive the second session key, and can encrypt the broadcast information between them and the leading vehicle according to the second session key, or the broadcast information between them and other following vehicles The information is encrypted.
在图8所示的实施例中,服务器可以实现对车队的会话密钥的管理,在确定有车辆出队后,向更新后的车队发送更新后的会话密钥(即第二会话密钥),使得更新后的车队中的其他车辆可以使用第二会话密钥对广播信息进行加密。如此,有助于提升车辆之间通信的安全性和可靠性。In the embodiment shown in Figure 8, the server can realize the management of the session key of the fleet, and after determining that a vehicle leaves the team, send the updated session key (ie, the second session key) to the updated fleet , so that other vehicles in the updated fleet can use the second session key to encrypt the broadcast information. In this way, it helps to improve the safety and reliability of communication between vehicles.
图9示出了本申请实施例二提供的另一种车辆通信的方法,该方法可以应用于图2所示的系统架构中,该方法主要涉及领航车切换的场景,该方法包括以下流程:FIG. 9 shows another vehicle communication method provided by Embodiment 2 of the present application. This method can be applied to the system architecture shown in FIG. 2. This method mainly involves the scene of pilot vehicle switching. The method includes the following process:
S900、领航车确定目标领航车。S900, pilot car Determine the target pilot car.
其中,领航车确定目标领航车有多种实施方式,包括但不限于以下方式:Among them, there are many ways for the pilot car to determine the target pilot car, including but not limited to the following ways:
方式1,领航车向目标领航车发送切换请求消息,并接收与切换请求消息对应的切换响应消息,根据该切换响应消息确定目标领航车。Mode 1, the pilot vehicle sends a switching request message to the target pilot vehicle, receives a switching response message corresponding to the switching request message, and determines the target pilot vehicle according to the switching response message.
方式2,领航车来自目标领航车接收切换请求消息,并在确定目标领航车满足领航车切换条件时,确定该目标领航车。Mode 2, the pilot car receives the switch request message from the target pilot car, and determines the target pilot car when it is determined that the target pilot car satisfies the pilot car switching conditions.
S901、领航车向服务器发送领航车切换通知消息,服务器接收该领航车切换通知消息。领航车切换通知消息包括车队标识和目标领航车的车辆标识。S901. The pilot car sends a pilot car switching notification message to the server, and the server receives the pilot car switching notification message. The pilot car switching notification message includes the fleet identification and the vehicle identification of the target pilot car.
在一种可能的实施方式中,服务器本地存储有目标领航车的证书,进而服务器可以根据目标领航车的证书对目标领航车的身份信息进行验证,在验证通过时,执行S902,进行领航车切换。In a possible implementation, the server locally stores the certificate of the target pilot car, and then the server can verify the identity information of the target pilot car according to the certificate of the target pilot car, and when the verification is passed, execute S902 to switch the pilot car .
S902、服务器生成根据车队标识和目标领航车的车辆标识,进行领航车切换,并更新车队。S902. The server generates a pilot car switch and updates the fleet according to the fleet ID and the vehicle ID of the target pilot car.
S903、服务器生成第三会话密钥;S903. The server generates a third session key;
S904、服务器向其他车辆发送第三会话密钥。S904. The server sends the third session key to other vehicles.
在图9所示的实施例中,服务器可以实现对车队的会话密钥的管理,在接收领航车切换通知消息后,根据车队的标识和目标领航车的车辆标识,进行领航车切换;生成第三会话密钥,并向车队中的其他车辆发送第三会话密钥,使得更新后的车队中的其他车辆可以使用第三会话密钥对广播信息进行加密。如此,及时更新会话密钥,有助于提升车辆之间通信的安全性和可靠性。In the embodiment shown in Fig. 9, the server can realize the management of the session key of the fleet, and after receiving the pilot car switching notification message, perform pilot car switching according to the identification of the fleet and the vehicle identification of the target pilot car; generate the second Three session keys, and send the third session key to other vehicles in the fleet, so that other vehicles in the updated fleet can use the third session key to encrypt broadcast information. In this way, updating the session key in time helps to improve the security and reliability of communication between vehicles.
图10示出了本申请上述实施例中所涉及的一种车辆通信装置的一种可能的结构示意图,该装置1000可以用于实现上述图1或图2中所示的车辆的功能。FIG. 10 shows a possible structural diagram of a vehicle communication device involved in the above embodiments of the present application. The device 1000 can be used to implement the functions of the vehicle shown in FIG. 1 or FIG. 2 above.
示例性的,装置1000可以包括:Exemplarily, device 1000 may include:
接收模块1001,用于接收入队请求消息;所述入队请求消息包括目标车辆的证书,所述入队请求消息用于指示所述目标车辆请求入队;The receiving module 1001 is configured to receive an entry request message; the entry request message includes the certificate of the target vehicle, and the entry request message is used to indicate that the target vehicle requests entry;
发送模块1002,用于响应于所述入队请求消息,向所述目标车辆发送入队响应消息;A sending module 1002, configured to send a queue-entry response message to the target vehicle in response to the queue-entry request message;
其中,所述入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,所述第一密文是所述领航车根据所述目标车辆的证书的公钥对第一会话密钥进行加密得到的,所述第一标识用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书。其中,第一标识可以是目标车辆的证书对应的HashID。Wherein, the entry response message includes a first ciphertext, a first identification corresponding to the certificate of the target vehicle, and a certificate of the pilot vehicle, and the first ciphertext is the ciphertext of the pilot vehicle according to the certificate of the target vehicle. obtained by encrypting the first session key with the public key, and the first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key key, and obtain the certificate of the pilot car. Wherein, the first identifier may be the HashID corresponding to the certificate of the target vehicle.
在一种可能的实施方式中,装置1000还包括处理模块1003,在接收模块1001,用于接收入队请求消息之前,处理模块1003还用于:生成所述第一会话密钥,所述第一会话密钥用于对车辆之间的广播信息进行加密。In a possible implementation manner, the device 1000 further includes a processing module 1003, and before the receiving module 1001 is configured to receive the enqueue request message, the processing module 1003 is also configured to: generate the first session key, the second A session key is used to encrypt broadcast messages between vehicles.
在一种可能的实施方式中,接收模块1001还用于接收出队请求消息;所述出队请求消息用于指示所述目标车辆请求出队;发送模块1002还用于响应于所述出队请求消息,发送出队响应消息;所述出队响应消息用于指示所述目标车辆执行出队操作。In a possible implementation manner, the receiving module 1001 is also used to receive a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests dequeue; the sending module 1002 is also used to respond to the dequeue A request message, sending a dequeue response message; the dequeue response message is used to instruct the target vehicle to perform a dequeue operation.
在一种可能的实施方式中,发送模块1002在发送出队响应消息之后,发送第一通知消息;其中,所述第一通知消息包括第一签名信息、所述领航车所在车队中的其他车辆的证书对应的第二标识和第二密文,所述第一签名信息用于指示所述领航车的身份信息,所述第二密文是所述领航车根据其所在车队中的其他车辆的证书的公钥对第二会话密钥进行加密得到的;所述第二标识用于指示所述其他车辆根据其的证书的私钥对所述第二密文进行解密,以获取所述第二会话密钥,第一通知消息用于指示其他车辆根据领航车的证书和第一签名信息,验证领航车的身份,以及根据其他车辆的证书的私钥对第二密文进行解 密,以获取第二会话密钥。In a possible implementation manner, the sending module 1002 sends a first notification message after sending the team-out response message; wherein, the first notification message includes the first signature information, other vehicles in the fleet where the pilot car is located The second identification and the second ciphertext corresponding to the certificate, the first signature information is used to indicate the identity information of the pilot car, and the second ciphertext is the obtained by encrypting the second session key with the public key of the certificate; the second identifier is used to instruct the other vehicle to decrypt the second ciphertext according to the private key of the certificate to obtain the second The session key, the first notification message is used to instruct other vehicles to verify the identity of the pilot car according to the certificate of the pilot car and the first signature information, and decrypt the second ciphertext according to the private key of the certificate of other vehicles to obtain the first Two session keys.
在一种可能的实施方式中,处理模块1003还用于在发送模块1002发送第一通知消息之前,生成第二会话密钥;所述第二会话密钥用于对所述车辆之间的广播信息进行加密。In a possible implementation manner, the processing module 1003 is further configured to generate a second session key before the sending module 1002 sends the first notification message; the second session key is used for broadcasting between the vehicles The information is encrypted.
应理解,装置1000的各个实施方式对应详细描述及取得的有益效果可参见上述图3-图9所示任一实施例的相关内容,此处不再详述。It should be understood that for detailed descriptions and beneficial effects obtained by various implementations of the device 1000, reference may be made to the relevant content of any of the above-mentioned embodiments shown in FIGS. 3-9 , and will not be described in detail here.
图11示出了本申请上述实施例中所涉及的一种车辆通信装置的一种可能的结构示意图,该装置1100可以用于实现上述图2中所示的服务器的功能。FIG. 11 shows a possible structural diagram of a vehicle communication device involved in the above-mentioned embodiments of the present application. The device 1100 can be used to realize the functions of the server shown in FIG. 2 above.
示例性的,装置1100可以包括:Exemplarily, device 1100 may include:
接收模块1101,用于接收车队创建通知消息;所述车队创建通知消息用于指示领航车已创建车队;所述车队创建通知消息包括所述车队的标识和所述车队内的车辆标识;The receiving module 1101 is configured to receive a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message includes the identification of the fleet and the vehicle identification in the fleet;
发送模块1102,用于响应于所述车队创建通知消息,发送第一响应消息;所述第一响应消息用于指示所述领航车获取第一会话密钥,所述第一会话密钥用于对所述车队中的车辆之间的广播信息进行加密。The sending module 1102 is configured to send a first response message in response to the fleet creation notification message; the first response message is used to instruct the pilot car to obtain a first session key, and the first session key is used for Encrypting broadcast messages between vehicles in the fleet.
在一种可能的实施方式中,接收模块1101还用于接收入队请求通知消息;所述入队请求通知消息用于指示第一车辆请求入队;发送模块1102还用于响应于所述入队请求通知消息,将所述第一会话密钥发送至所述第一车辆。In a possible implementation manner, the receiving module 1101 is also used to receive a queue entry request notification message; the queue entry request notification message is used to indicate that the first vehicle requests to join the queue; the sending module 1102 is also used to respond to the queue entry A team request notification message, sending the first session key to the first vehicle.
在一种可能的实施方式中,接收模块1101还用于接收出队请求通知消息;所述出队请求通知消息用于指示第二车辆请求出队,所述出队请求通知消息包括所述车队的标识和所述第二车辆的车辆标识;发送模块1102还用于响应于该出队请求通知消息,根据所述车队的标识和所述第二车辆的车辆标识,确定更新后的车队,并向所述更新后的车队中的每辆车辆发送第二会话密钥;所述第二会话密钥用于对所述更新后的车队中的车辆之间的广播信息进行加密。In a possible implementation manner, the receiving module 1101 is also configured to receive a request notification message for leaving the team; the request notification message for leaving the team is used to indicate that the second vehicle requests to leave the team, and the request notification message for leaving the team includes the and the vehicle identification of the second vehicle; the sending module 1102 is also configured to determine the updated fleet according to the identification of the fleet and the vehicle identification of the second vehicle in response to the departure request notification message, and A second session key is sent to each vehicle in the updated fleet; the second session key is used to encrypt broadcast information between vehicles in the updated fleet.
在一种可能的实施方式中,装置1100还包括处理模块1103,接收模块1101还用于接收领航车切换通知消息;所述领航车切换通知消息中包括所述车队的标识和目标领航车的车辆标识;处理模块1103用于响应于领航车切换通知消息,根据所述车队的标识和所述目标领航车的车辆标识,进行领航车切换,生成第三会话密钥,并向所述车队中的其他车辆发送第三会话密钥,所述第三会话密钥用于对所述车队中的车辆之间的广播信息进行加密。In a possible implementation manner, the device 1100 further includes a processing module 1103, and the receiving module 1101 is also configured to receive a pilot car switching notification message; the pilot car switching notification message includes the identification of the fleet and the vehicle of the target pilot car Identification; the processing module 1103 is used to respond to the pilot car switching notification message, perform pilot car switching according to the identification of the fleet and the vehicle identification of the target pilot car, generate a third session key, and send a message to the team in the fleet The other vehicles send a third session key used to encrypt broadcast information between vehicles in the fleet.
应理解,装置1100的各个实施方式对应详细描述及取得的有益效果可参见上述图6-图9所示任一实施例的相关内容,此处不再详述。It should be understood that for detailed descriptions and beneficial effects obtained by various implementations of the device 1100 , reference may be made to the relevant content of any of the above-mentioned embodiments shown in FIGS. 6-9 , and will not be described in detail here.
本申请实施例还提供了一种车辆,该车辆可以包括处理器,处理器用于执行上述图3-图9所示任一实施例中的车辆通信方法。An embodiment of the present application also provides a vehicle, and the vehicle may include a processor configured to execute the vehicle communication method in any of the embodiments shown in FIGS. 3-9 .
在一种可能的实施方式中,还包括存储器,用于存储计算机程序或指令。In a possible implementation manner, a memory is also included for storing computer programs or instructions.
在一种可能的实施方式中,还包括收发器,用于接收或发送信息。In a possible implementation manner, a transceiver is further included, configured to receive or send information.
本申请实施例还提供了一种服务器,该服务器包括处理器,处理器用于实现上述图6-图9所示实施例中的服务器的功能,以实现本申请实施例提供的车辆通信方法。The embodiment of the present application also provides a server, the server includes a processor, and the processor is configured to implement the functions of the server in the embodiments shown in FIGS. 6-9 above, so as to implement the vehicle communication method provided in the embodiment of the present application.
在一种可能的实施方式中,还包括存储器,用于存储计算机程序或指令。In a possible implementation manner, a memory is also included for storing computer programs or instructions.
在一种可能的实施方式中,还包括收发器,用于接收或发送信息。In a possible implementation manner, a transceiver is further included, configured to receive or send information.
在一种可能的实施方式中,服务器为单服务器或由多个子服务器构成的服务器集群,当服务器为由多个子服务器构成的服务器集群时,多个子服务器联合执行上述图2中所示的服务器6的功能。In a possible implementation, the server is a single server or a server cluster composed of multiple sub-servers. When the server is a server cluster composed of multiple sub-servers, the multiple sub-servers jointly execute the above-mentioned server 6 shown in FIG. 2 function.
本申请实施例还提供了一种芯片系统,请参见图12,该芯片系统1200包括至少一个处理器,当程序指令在至少一个处理器1201中执行时,使得上述图3-图9所示任一实施例中的车辆通信方法得以实现。The embodiment of the present application also provides a chip system. Please refer to FIG. 12. The chip system 1200 includes at least one processor. When program instructions are executed in at least one processor 1201, any A vehicle communication method in an embodiment is realized.
在一种可能的实施方式中,该芯片系统还包括通信接口1203,通信接口用于输入或输出信息。In a possible implementation manner, the chip system further includes a communication interface 1203, which is used for inputting or outputting information.
在一种可能的实施方式中,该芯片系统还包括存储器1202,该存储器1202通过通信接口1203耦合处理器,用于存储上述指令,以便处理器通过通信接口1203读取存储器中存储的指令。In a possible implementation manner, the chip system further includes a memory 1202 , which is coupled to the processor through the communication interface 1203 and configured to store the above-mentioned instructions, so that the processor can read the instructions stored in the memory through the communication interface 1203 .
应理解,本申请实施例中不限定上述处理器1201、存储器1202以及通信接口1203之间的连接介质。本申请实施例在图12中以存储器1202、处理器1201以及通信接口1203之间通过通信总线1204连接,总线在图12中以粗线表示,其它部件之间的连接方式,仅是示意性说明,并不作为限定。所述总线可以包括地址总线、数据总线、控制总线等。为了便于表示,图12中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线等。It should be understood that the connection medium among the foregoing processor 1201, memory 1202, and communication interface 1203 is not limited in this embodiment of the present application. In the embodiment of the present application, in FIG. 12, the memory 1202, the processor 1201, and the communication interface 1203 are connected through a communication bus 1204. The bus is represented by a thick line in FIG. , is not limited. The bus may include an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is used in FIG. 12 , but it does not mean that there is only one bus or one type of bus.
本申请实施例还提供了一种包括指令的计算机程序产品,当其在上述装置上运行时,以执行如上述图3-图9所示任一实施例中的车辆通信方法。The embodiment of the present application also provides a computer program product including instructions, when running on the above device, to execute the vehicle communication method in any of the above embodiments shown in FIGS. 3-9 .
本申请实施例提供一种计算机可读存储介质,该计算机可读存储介质存储有计算机程序,当计算机程序被运行时,实现如上述图3-图9所示任一实施例中的车辆通信方法。An embodiment of the present application provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is run, the vehicle communication method in any of the above-mentioned embodiments shown in Figures 3-9 is implemented .
上述各实施例可以相互结合以实现不同的技术效果。The above embodiments can be combined with each other to achieve different technical effects.
上述本申请提供的实施例中,分别从各个设备之间交互的角度对本申请实施例提供的方法进行了介绍。为了实现上述本申请实施例提供的方法中的各功能,第一终端、第二终端与网络设备可以包括硬件结构和/或软件模块,以硬件结构、软件模块、或硬件结构加软件模块的形式来实现上述各功能。上述各功能中的某个功能以硬件结构、软件模块、还是硬件结构加软件模块的方式来执行,取决于技术方案的特定应用和设计约束条件。In the above-mentioned embodiments provided in the present application, the methods provided in the embodiments of the present application are introduced from the perspective of interaction between various devices. In order to realize the various functions in the method provided by the above embodiments of the present application, the first terminal, the second terminal and the network device may include a hardware structure and/or a software module in the form of a hardware structure, a software module, or a hardware structure plus a software module to realize the above functions. Whether one of the above-mentioned functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.
本申请实施例中对模块的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。另外,在本申请各个实施例中的各功能模块可以集成在一个处理器中,也可以是单独物理存在,也可以两个或两个以上模块集成在一个模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。The division of modules in the embodiment of the present application is schematic, and is only a logical function division, and there may be other division methods in actual implementation. In addition, each functional module in each embodiment of the present application may be integrated into one processor, or physically exist separately, or two or more modules may be integrated into one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software function modules.
在本申请实施例中,存储器可以是非易失性存储器,比如硬盘(hard disk drive,HDD)或固态硬盘(solid-state drive,SSD)等,还可以是易失性存储器(volatile memory),例如随机存取存储器(random-access memory,RAM)。存储器是能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。本申请实施例中的存储器还可以是电路或者其它任意能够实现存储功能的装置,用于存储程序指令和/或数据。In the embodiment of the present application, the memory may be a non-volatile memory, such as a hard disk (hard disk drive, HDD) or a solid-state drive (solid-state drive, SSD), etc., and may also be a volatile memory (volatile memory), such as Random-access memory (RAM). A memory is, but is not limited to, any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. The memory in the embodiment of the present application may also be a circuit or any other device capable of implementing a storage function, and is used for storing program instructions and/or data.
本申请实施例提供的方法中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、网络设备、用户设备或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通 过有线(例如同轴电缆、光纤、数字用户线(digital subscriber line,简称DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机可以存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质(例如,软盘、硬盘、磁带)、光介质(例如,数字视频光盘(digital video disc,简称DVD))、或者半导体介质(例如,SSD)等。The methods provided in the embodiments of the present application may be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, the processes or functions according to the embodiments of the present application will be generated in whole or in part. The computer may be a general purpose computer, a special purpose computer, a computer network, network equipment, user equipment or other programmable devices. The computer instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website, computer, server or data center Transmission to another website site, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center integrated with one or more available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, or a magnetic tape), an optical medium (for example, a digital video disc (digital video disc, DVD for short)), or a semiconductor medium (for example, SSD).
在本申请实施例中,在无逻辑矛盾的前提下,各实施例之间可以相互引用,例如方法实施例之间的方法和/或术语可以相互引用,例如装置实施例之间的功能和/或术语可以相互引用,例如装置实施例和方法实施例之间的功能和/或术语可以相互引用。In the embodiments of the present application, on the premise that there is no logical contradiction, the various embodiments may refer to each other, for example, the methods and/or terms between the method embodiments may refer to each other, such as the functions and/or terms between the device embodiments Or terms may refer to each other, for example, functions and/or terms between the apparatus embodiment and the method embodiment may refer to each other.
本领域的技术人员可以对本申请进行各种改动和变型而不脱离本申请的范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。Those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. In this way, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims (23)

  1. 一种车辆通信方法,其特征在于,所述方法包括:A vehicle communication method, characterized in that the method comprises:
    接收入队请求消息;所述入队请求消息包括目标车辆的证书,所述入队请求消息用于指示所述目标车辆请求入队;Receive a request message for joining the team; the request message for joining the team includes the certificate of the target vehicle, and the request message for joining the team is used to indicate that the target vehicle requests to join the team;
    响应于所述入队请求消息,向所述目标车辆发送入队响应消息;sending a queue response message to the target vehicle in response to the queue request message;
    其中,所述入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,所述第一密文是所述领航车根据所述目标车辆的证书的公钥对第一会话密钥进行加密得到的;所述第一标识用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书。Wherein, the entry response message includes a first ciphertext, a first identification corresponding to the certificate of the target vehicle, and a certificate of the pilot vehicle, and the first ciphertext is the ciphertext of the pilot vehicle according to the certificate of the target vehicle. obtained by encrypting the first session key with the public key; the first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key key, and obtain the certificate of the pilot car.
  2. 根据权利要求1所述的方法,其特征在于,在所述接收入队请求消息之前,所述方法还包括:The method according to claim 1, wherein, before receiving the enqueue request message, the method further comprises:
    生成所述第一会话密钥,所述第一会话密钥用于对车辆之间的广播信息进行加密。The first session key is generated, and the first session key is used to encrypt broadcast information between vehicles.
  3. 根据权利要求1或2所述的方法,其特征在于,所述方法还包括:The method according to claim 1 or 2, characterized in that the method further comprises:
    接收出队请求消息;所述出队请求消息用于指示所述目标车辆请求出队;Receive a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests to dequeue;
    响应于所述出队请求消息,发送出队响应消息;所述出队响应消息用于指示所述目标车辆执行出队操作。In response to the dequeue request message, a dequeue response message is sent; the dequeue response message is used to instruct the target vehicle to perform a dequeue operation.
  4. 根据权利要求3所述的方法,其特征在于,在所述发送出队响应消息之后,所述方法还包括:The method according to claim 3, characterized in that, after the dequeue response message is sent, the method further comprises:
    发送第一通知消息;其中,所述第一通知消息包括第一签名信息、所述领航车所在车队中的其他车辆的证书对应的第二标识和第二密文,所述第一签名信息用于指示所述领航车的身份信息,所述第二密文是所述领航车根据所述其他车辆的证书的公钥对第二会话密钥进行加密得到的;所述第二标识用于指示所述其他车辆根据所述其他车辆的证书的私钥对所述第二密文进行解密,以获取所述第二会话密钥;Sending a first notification message; wherein, the first notification message includes first signature information, a second identification and a second ciphertext corresponding to the certificates of other vehicles in the convoy where the pilot vehicle is located, and the first signature information uses In order to indicate the identity information of the pilot car, the second ciphertext is obtained by the pilot car encrypting the second session key according to the public key of the certificate of the other vehicle; the second identification is used to indicate The other vehicle decrypts the second ciphertext according to the private key of the certificate of the other vehicle to obtain the second session key;
    所述第一通知消息用于指示所述其他车辆根据所述领航车的证书和所述第一签名信息,验证所述领航车的身份。The first notification message is used to instruct the other vehicles to verify the identity of the pilot car according to the certificate of the pilot car and the first signature information.
  5. 根据权利要求4所述的方法,其特征在于,在所述发送第一通知消息之前,所述方法还包括:The method according to claim 4, wherein before the sending of the first notification message, the method further comprises:
    生成第二会话密钥;所述第二会话密钥用于对所述车辆之间的广播信息进行加密。generating a second session key; the second session key is used to encrypt broadcast information between the vehicles.
  6. 一种车辆通信方法,其特征在于,所述方法包括:A vehicle communication method, characterized in that the method comprises:
    发送入队请求消息;所述入队请求消息包括目标车辆的证书,所述入队请求消息用于指示所述目标车辆请求入队;Sending a request message for joining the team; the request message for joining the team includes the certificate of the target vehicle, and the request message for joining the team is used to indicate that the target vehicle requests to join the team;
    接收与所述入队请求消息对应的入队响应消息;所述入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,所述第一密文是所述领航车根据所述目标车辆的证书的公钥对第一会话密钥进行加密得到的;所述第一标识用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书;根据所述目标车辆的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书。Receive an entry response message corresponding to the entry request message; the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle and the certificate of the pilot vehicle, the first ciphertext obtained by the pilot car encrypting the first session key according to the public key of the certificate of the target vehicle; the first identifier is used to indicate that the target vehicle encrypts the Decrypt a ciphertext to obtain the first session key, and obtain the certificate of the pilot vehicle; decrypt the first ciphertext according to the private key of the certificate of the target vehicle to obtain the first session key, and the certificate for obtaining the pilot car.
  7. 根据权利要求6所述的方法,其特征在于,所述方法还包括:The method according to claim 6, further comprising:
    发送出队请求消息;所述出队请求消息用于指示目标车辆请求出队;Send a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests to dequeue;
    接收与所述出队请求消息对应的出队响应消息;所述出队响应消息用于指示所述目标车辆执行出队操作。receiving a dequeue response message corresponding to the dequeue request message; the dequeue response message is used to instruct the target vehicle to perform a dequeue operation.
  8. 一种车辆通信装置,其特征在于,包括:A vehicle communication device, characterized by comprising:
    接收模块,用于接收入队请求消息;所述入队请求消息包括目标车辆的证书,所述入队请求消息用于指示所述目标车辆请求入队;A receiving module, configured to receive a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used to indicate that the target vehicle requests to join the team;
    发送模块,用于响应于所述入队请求消息,向所述目标车辆发送入队响应消息;A sending module, configured to send a queue-entry response message to the target vehicle in response to the queue-entry request message;
    其中,所述入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,所述第一密文是所述领航车根据所述目标车辆的证书的公钥对第一会话密钥进行加密得到的,所述第一标识用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书。Wherein, the entry response message includes a first ciphertext, a first identification corresponding to the certificate of the target vehicle, and a certificate of the pilot vehicle, and the first ciphertext is the ciphertext of the pilot vehicle according to the certificate of the target vehicle. obtained by encrypting the first session key with the public key, and the first identifier is used to instruct the target vehicle to decrypt the first ciphertext according to the private key of its own certificate to obtain the first session key key, and obtain the certificate of the pilot car.
  9. 根据权利要求8所述的装置,其特征在于,所述装置还包括处理模块,在所述接收模块接收入队请求消息之前,The device according to claim 8, wherein the device further comprises a processing module, before the receiving module receives the enqueue request message,
    所述处理模块,用于生成所述第一会话密钥,所述第一会话密钥用于对车辆之间的广播信息进行加密。The processing module is configured to generate the first session key, and the first session key is used to encrypt broadcast information between vehicles.
  10. 根据权利要求8或9所述的装置,其特征在于,所述接收模块,还用于:接收出队请求消息;所述出队请求消息用于指示所述目标车辆请求出队;The device according to claim 8 or 9, wherein the receiving module is further configured to: receive a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests dequeue;
    所述发送模块,还用于响应于所述出队请求消息,发送出队响应消息;所述出队响应消息用于指示所述目标车辆执行出队操作。The sending module is further configured to send a dequeue response message in response to the dequeue request message; the dequeue response message is used to instruct the target vehicle to perform a dequeue operation.
  11. 根据权利要求10所述的装置,其特征在于,在所述发送模块发送出队响应消息之后,The device according to claim 10, wherein after the sending module sends the dequeue response message,
    所述发送模块,还用于发送第一通知消息;其中,所述第一通知消息包括第一签名信息、所述领航车所在车队中的其他车辆的证书对应的第二标识和第二密文,所述第一签名信息用于指示所述领航车的身份信息,所述第二密文是所述领航车根据所述其他车辆的证书的公钥对第二会话密钥进行加密得到的;所述第二标识用于指示所述其他车辆根据所述其他车辆的证书的私钥对所述第二密文进行解密,以获取所述第二会话密钥;The sending module is also used to send a first notification message; wherein, the first notification message includes first signature information, a second identification corresponding to the certificates of other vehicles in the convoy where the pilot car is located, and a second ciphertext , the first signature information is used to indicate the identity information of the pilot car, and the second ciphertext is obtained by the pilot car encrypting the second session key according to the public key of the certificate of the other vehicle; The second identifier is used to instruct the other vehicle to decrypt the second ciphertext according to the private key of the other vehicle's certificate, so as to obtain the second session key;
    所述第一通知消息用于指示所述其他车辆根据所述领航车的证书和所述第一签名信息,验证所述领航车的身份。The first notification message is used to instruct the other vehicles to verify the identity of the pilot car according to the certificate of the pilot car and the first signature information.
  12. 根据权利要求11所述的装置,其特征在于,在所述发送模块发送第一通知消息之前,The device according to claim 11, wherein before the sending module sends the first notification message,
    所述处理模块,还用于生成第二会话密钥;所述第二会话密钥用于对所述车辆之间的广播信息进行加密。The processing module is further configured to generate a second session key; the second session key is used to encrypt the broadcast information between the vehicles.
  13. 一种车辆通信装置,其特征在于,包括:A vehicle communication device, characterized by comprising:
    发送模块,用于发送入队请求消息;所述入队请求消息包括目标车辆的证书,所述入队请求消息用于指示所述目标车辆请求入队;A sending module, configured to send a team entry request message; the team entry request message includes the certificate of the target vehicle, and the team entry request message is used to indicate that the target vehicle requests to join the team;
    接收模块,用于接收与所述入队请求消息对应的入队响应消息;所述入队响应消息包括第一密文、所述目标车辆的证书对应的第一标识和领航车的证书,所述第一密文是所述领航车根据所述目标车辆的证书的公钥对第一会话密钥进行加密得到的,所述第一标识用于指示所述目标车辆根据其自身的证书的私钥对所述第一密文进行解密以获取所述第一会话密钥,以及获取所述领航车的证书;A receiving module, configured to receive an entry response message corresponding to the entry request message; the entry response message includes the first ciphertext, the first identification corresponding to the certificate of the target vehicle, and the certificate of the pilot vehicle, so The first ciphertext is obtained by the pilot car encrypting the first session key according to the public key of the target vehicle's certificate, and the first identifier is used to indicate that the target vehicle key to decrypt the first ciphertext to obtain the first session key, and obtain the certificate of the pilot car;
    处理模块,用于根据所述目标车辆的证书的私钥对所述第一密文进行解密以获取所述 第一会话密钥,以及获取所述领航车的证书。A processing module, configured to decrypt the first ciphertext according to the private key of the target vehicle's certificate to obtain the first session key, and obtain the pilot vehicle's certificate.
  14. 根据权利要求13所述的装置,其特征在于,所述发送模块,还用于发送出队请求消息;所述出队请求消息用于指示目标车辆请求出队;The device according to claim 13, wherein the sending module is further configured to send a dequeue request message; the dequeue request message is used to indicate that the target vehicle requests dequeue;
    所述接收模块,还用于接收与所述出队请求消息对应的出队响应消息;所述出队响应消息用于指示所述目标车辆执行出队操作。The receiving module is further configured to receive a dequeue response message corresponding to the dequeue request message; the dequeue response message is used to instruct the target vehicle to perform a dequeue operation.
  15. 一种车辆通信方法,其特征在于,所述方法包括:A vehicle communication method, characterized in that the method comprises:
    接收车队创建通知消息;所述车队创建通知消息用于指示领航车已创建车队;所述车队创建通知消息包括车队的标识和车队内的车辆标识;Receiving a fleet creation notification message; the fleet creation notification message is used to indicate that the pilot vehicle has created a fleet; the fleet creation notification message includes the identification of the fleet and the vehicle identification in the fleet;
    发送第一响应消息;所述第一响应消息用于指示所述领航车获取第一会话密钥,第一会话密钥用于对所述车队中的车辆之间的广播信息进行加密。Sending a first response message; the first response message is used to instruct the pilot car to acquire a first session key, and the first session key is used to encrypt broadcast information between vehicles in the fleet.
  16. 根据权利要求15所述的方法,其特征在于,所述方法还包括:The method according to claim 15, further comprising:
    接收入队请求通知消息;所述入队请求通知消息用于指示第一车辆请求入队;Receiving an entry request notification message; the entry request notification message is used to indicate that the first vehicle requests entry into the group;
    响应于所述入队请求通知消息,将第一会话密钥发送至所述第一车辆。A first session key is sent to the first vehicle in response to the enqueue request notification message.
  17. 根据权利要求15或16所述的方法,其特征在于,所述方法还包括:The method according to claim 15 or 16, wherein the method further comprises:
    接收出队请求通知消息;所述出队请求通知消息用于指示第二车辆请求出队,所述出队请求通知消息包括车队的标识和所述第二车辆的车辆标识;Receive a request notification message for leaving the team; the request notification message for leaving the team is used to indicate that the second vehicle requests to leave the team, and the request notification message for leaving the team includes the identification of the team and the vehicle identification of the second vehicle;
    响应于所述出队请求通知消息,根据所述车队的标识和所述第二车辆的车辆标识,确定更新后的车队,并向所述更新后的车队中的每辆车辆发送第二会话密钥;所述第二会话密钥用于对所述更新后的车队中的车辆之间的广播信息进行加密。In response to the dequeue request notification message, determine an updated fleet according to the identifier of the fleet and the vehicle identifier of the second vehicle, and send a second session key to each vehicle in the updated fleet. key; the second session key is used to encrypt broadcast information between vehicles in the updated fleet.
  18. 根据权利要求15-17任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 15-17, wherein the method further comprises:
    接收领航车切换通知消息;所述领航车切换通知消息中还包括车队的标识和目标领航车的车辆标识;Receive the pilot car switching notification message; the pilot car switching notification message also includes the identification of the fleet and the vehicle identification of the target pilot car;
    响应于所述领航车切换通知消息,根据所述车队的标识和所述目标领航车的车辆标识,进行领航车切换。In response to the pilot car switching notification message, the pilot car is switched according to the identification of the fleet and the vehicle identification of the target pilot car.
  19. 根据权利要求18所述的方法,其特征在于,所述方法还包括:The method according to claim 18, further comprising:
    生成第三会话密钥;generating a third session key;
    向所述车队中除所述目标领航车之外的其他车辆发送第三会话密钥,所述第三会话密钥用于对所述车队中的车辆之间的广播信息进行加密。Sending a third session key to other vehicles in the convoy except the target pilot vehicle, where the third session key is used to encrypt broadcast information between vehicles in the convoy.
  20. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质中存储有计算机程序,当所述计算机程序被计算机执行时,使得所述计算机执行权利要求1-5任一项所述的方法,或执行如权利要求6-7任一项所述的方法,或执行如权利要求15-19任一项所述的方法。A computer-readable storage medium, characterized in that, a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a computer, the computer executes the computer program described in any one of claims 1-5. method, or perform the method as described in any one of claims 6-7, or perform the method as described in any one of claims 15-19.
  21. 一种芯片系统,其特征在于,所述芯片用于读取存储器中存储的计算机程序,执行如权利要求1-5任一项所述的方法,或执行如权利要求6-7任一项所述的方法,或执行如权利要求15-19任一项所述的方法。A chip system, characterized in that the chip is used to read the computer program stored in the memory, execute the method according to any one of claims 1-5, or execute the method according to any one of claims 6-7 described method, or perform the method as described in any one of claims 15-19.
  22. 一种车辆,其特征在于,包括处理器,所述处理器用于执行上述权利要求1-5中任一项所述的方法,或执行上述权利要求6-7中任一项所述的方法,或执行如权利要求15-19任一项所述的方法。A vehicle, characterized by comprising a processor configured to execute the method according to any one of claims 1-5 above, or to execute the method according to any one of claims 6-7 above, Or perform the method as described in any one of claims 15-19.
  23. 一种计算机程序产品,其特征在于,所述计算机程序产品包括指令,当所述指令被计算机执行时,使得所述计算机执行如权利要求1-5任一项所述的方法,或执行如权利要 求6-7任一项所述的方法,或执行如权利要求15-19任一项所述的方法。A computer program product, characterized in that the computer program product includes instructions, and when the instructions are executed by a computer, the computer executes the method according to any one of claims 1-5, or executes the method according to any one of claims 1-5. The method according to any one of claims 6-7, or performing the method according to any one of claims 15-19.
PCT/CN2022/104804 2021-07-12 2022-07-11 Vehicle communication method and device WO2023284658A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110783012.6A CN115604681A (en) 2021-07-12 2021-07-12 Vehicle communication method and device
CN202110783012.6 2021-07-12

Publications (1)

Publication Number Publication Date
WO2023284658A1 true WO2023284658A1 (en) 2023-01-19

Family

ID=84841029

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/104804 WO2023284658A1 (en) 2021-07-12 2022-07-11 Vehicle communication method and device

Country Status (2)

Country Link
CN (1) CN115604681A (en)
WO (1) WO2023284658A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104217386A (en) * 2014-09-29 2014-12-17 上海斐讯数据通信技术有限公司 Team vehicle management system and team vehicle management method
CN111641933A (en) * 2020-05-28 2020-09-08 北京百度网讯科技有限公司 Fleet management method and device and related equipment
CN110447216B (en) * 2017-04-14 2021-02-12 华为技术有限公司 Method and apparatus for group communication
CN112423262A (en) * 2020-10-14 2021-02-26 北京汽车研究总院有限公司 Fleet key negotiation method, storage medium and vehicle

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104217386A (en) * 2014-09-29 2014-12-17 上海斐讯数据通信技术有限公司 Team vehicle management system and team vehicle management method
CN110447216B (en) * 2017-04-14 2021-02-12 华为技术有限公司 Method and apparatus for group communication
CN111641933A (en) * 2020-05-28 2020-09-08 北京百度网讯科技有限公司 Fleet management method and device and related equipment
CN112423262A (en) * 2020-10-14 2021-02-26 北京汽车研究总院有限公司 Fleet key negotiation method, storage medium and vehicle

Also Published As

Publication number Publication date
CN115604681A (en) 2023-01-13

Similar Documents

Publication Publication Date Title
EP3742696B1 (en) Identity management method, equipment, communication network, and storage medium
EP3627794B1 (en) Discovery method and apparatus based on service-oriented architecture
CN109327467B (en) Management method of RSSP-II secure communication protocol key management mechanism
US10250383B1 (en) Dynamic domain key exchange for authenticated device to device communications
WO2018010474A1 (en) Method and apparatus for secure communication between vehicle-to-everything terminals
WO2019041809A1 (en) Registration method and apparatus based on service-oriented architecture
US20170111357A1 (en) Authentication method and authentication system
US10326743B2 (en) Secured data transmission using identity-based cryptography
EP4290790A1 (en) Key acquisition method and apparatus, and key management system
WO2018202109A1 (en) Certificate request message sending method and receiving method and apparatus
US20200067703A1 (en) First vehicle-side terminal, method for operating the first terminal, second vehicle-side terminal and method for operating the second vehicle-side terminal
WO2022160124A1 (en) Service authorisation management method and apparatus
CN113378230A (en) Data access control method of DDS (direct digital synthesizer) distributed system
CN116405192A (en) Certificate application method and equipment
WO2021022406A1 (en) Identity authentication method and device
CN117254910B (en) Efficient group key distribution method based on quantum random number under vehicle-mounted ad hoc network
JP7464337B2 (en) Secure communication method, apparatus, terminal device, computer program, computer storage medium, chip, and communication system
WO2023284658A1 (en) Vehicle communication method and device
CN111901335A (en) Block chain data transmission management method and system based on middle station
CN116233843A (en) B5G/6G network slice authentication method for industrial Internet
WO2022036600A1 (en) Key update methods, apparatus and devices, and storage medium
CN110858835B (en) Communication method, system and related device and computer readable storage medium
CN116390088A (en) Security authentication method and device for terminal under open loop transmission, electronic equipment and medium
CN118102310A (en) Network slice switching method, device, equipment, storage medium and product
CN117176332A (en) Identity authentication method, system, terminal equipment and storage medium

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22841294

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE