Unmanned sweeper and cloud platform data interaction system based on hybrid encryption
Through the hybrid encryption system dynamically matching the data interaction between the driverless sweeper and the cloud platform, the data is easily intercepted, the encryption mechanism is inadaptable and the network fault tolerance, and the data transmission security and resource efficiency are improved, ensuring priority processing of critical tasks and system stability.
Patent Information
- Application Number
- CN202510639341.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-05-19
AI Technical Summary
During the data interaction between the driverless sweeper and the cloud platform, there are problems such as data being easily intercepted or tampered, the encryption mechanism lacks task adaptability, the fault tolerance mechanism under the network disconnection, and the scheduling process does not consider the importance of data flow.
The data interaction system of unmanned driving sweepers and cloud platform based on hybrid encryption is adopted, including permission authentication module, data encryption module, master-slave authentication control module, horizontal trust management module and communication scheduling module. Through the task scoring function, the encryption policy and key template are dynamically matched, and offline identity authentication, horizontal trust signature and channel switching mechanism are supported to improve the security of data transmission and system fault tolerance.
It realizes automatic selection of the optimal encryption algorithm and key level in different task scenarios, improves data confidentiality and computing resource efficiency, ensures priority processing of critical task data, and improves the system's trust security level and task stability.
Smart Images

Figure CN120264270A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of communication interaction information security. More specifically, the present invention relates to a data interaction system between an unmanned cleaning vehicle and a cloud platform based on hybrid encryption. Background Art
[0002] In recent years, with the continuous advancement of urban intelligent management, unmanned cleaning vehicles, as a new generation of urban service terminal devices, have gradually been put into actual use in scenarios such as parks, communities, and municipal roads. Such devices usually have capabilities such as path planning, obstacle recognition, autonomous driving, and task scheduling. They can sense the environmental state through sensors and upload task data to the platform in real time for scheduling optimization and supervision records.
[0003] At the same time, as the task control center and data convergence hub of unmanned cleaning vehicles, the cloud platform undertakes core functions such as multi-vehicle coordination, task distribution, operation record, and algorithm update. To achieve efficient management, the cleaning vehicle needs to upload various types of data to the cloud platform regularly or in real time, including but not limited to: operation trajectories, images and videos, device status, task completion, etc. The cloud platform needs to send down task parameters, policy updates, temporary instructions, etc.
[0004] However, the traditional data interaction mechanism faces the following challenges: data in the communication process is easily intercepted or tampered with: cleaning vehicles are usually in an open network environment and lack stable private network isolation, resulting in threats such as eavesdropping and man-in-the-middle attacks to the data during transmission; The encryption mechanism lacks task adaptability: existing systems mostly adopt fixed encryption algorithms, which are difficult to flexibly adjust the encryption strategy according to the task sensitivity level or network environment, easily leading to waste of computing power resources or insufficient security level; There is a lack of a fault tolerance mechanism in the case of network disconnection: when the communication between the cleaning vehicle and the cloud platform is interrupted, the data caching mechanism or task authorization mechanism is imperfect, easily leading to task execution failure or security risks; The importance difference of data streams is not considered in the scheduling process: during task scheduling and data uploading, the value and urgency of different data are not distinguished, and there is a situation where important information occupies the channel by low-priority data.
[0005] Therefore, the present invention proposes a data interaction system between an unmanned cleaning vehicle and a cloud platform based on hybrid encryption in order to solve the above problems. Summary of the Invention
[0006] To achieve the above object, the present invention provides the following technical solutions: A data interaction system between an unmanned cleaning vehicle and a cloud platform based on hybrid encryption, comprising: The permission authentication module is configured to parse the device identity identifier and short-cycle authentication token distributed by the cloud platform, and perform identity authentication based on the cached signature token when the platform connection is unavailable; The data encryption module has a key pool mechanism. Multiple levels of session keys are pre-configured on the device side, and keys for encrypting in-vehicle data are dynamically selected from the key pool according to the current task status; The information processing module establishes a mapping relationship between the task status and the encryption level. When the task is switched, the corresponding encryption algorithm and key template are automatically matched according to the level corresponding to the current task. If the matching fails, data transmission is blocked and a secure re-negotiation is initiated; The master-slave authentication control module sets multiple levels of identity verification paths. When the primary authentication path fails, the slave authentication mechanism is automatically enabled for local authorization, and the scope and validity period of the activated task are limited; The horizontal trust management module generates role signature credentials for the sweeper during task collaboration, and proves its task legality and authorization time to neighboring devices through a structured signature chain; The communication scheduling module has a pre-loaded key channel and an instant key negotiation mechanism, and decides whether to trigger the primary key negotiation process according to the task sensitivity, or use the historical session key to encrypt the initial state data; Among them, the task encryption level mapping model in the information processing module is constructed based on the task content, real-time requirements, and information sensitivity, so that the data encryption intensity changes dynamically with the task, improving the task completion rate and data security of the sweeping operation.
[0007] In a preferred embodiment, the key pool in the data encryption module is hierarchically managed according to a tree-like hierarchical structure. The lowest layer is the task-level key, the middle layer is the task group common key, and the top layer is the platform authorization key. The key call at each layer is controlled by the task scoring function F(Tscore,Slevel); the task scoring function is obtained by weighted summation of the task complexity score Tscore and the sensitivity level score Slevel; The task complexity score Tscore is calculated by combining four indicators: the task scheduling instruction length, logical depth, types of in-vehicle resources required, and running duration, corresponding to T1 to T4 respectively. Each indicator is normalized and weighted to form a total score. The sensitivity level score Slevel comes from the result of the level determination model feedback by the information processing module, and the scoring range is 1 to 4, corresponding to ordinary, device-level, platform-level, and regulatory-level information respectively; When the encryption policy is called, the result of the scoring function F is calculated and matched with the encryption security value corresponding to each layer of the key. The key layer corresponding to the encryption security value that is closest but not lower than the scoring function F is selected. If the result of the function F is lower than the lowest key call threshold K1, the system enters the protection state, does not perform encryption, and does not allow the task data to be uploaded.
[0008] In a preferred embodiment, the mapping relationship between the task status and the encryption level is constructed based on a state transition diagram. Any task status node is constructed with reference to three dimensions: the real-time factor R1, the information sensitivity S1, and the task content importance N1. Among them, the transition probability P(i→j) is obtained by calculating the Euclidean distance between the transition vector composed of the real-time factor R1, the information sensitivity S1, and the task content importance N1 and the preset standard vector. The transition probability P(i→j) represents the probability of transitioning from state i to state j. There is a preset standard security level vector set Vi (i ∈ {1, 2, 3}). The level i corresponding to the Vi with the smallest distance from the transition vector is selected as the "security level of the current task", and the "security level of the current task" corresponds to a unique level in the tree-like hierarchical structure. When any node switches to a task with a different security level, the mapping mechanism forces a fallback to the key renegotiation state and clears the mapping cache.
[0009] In a preferred embodiment, the task window limit parameter Tauth is bound when the authentication mechanism is locally activated. This parameter is generated by the device self-check module at the start of authentication and is subjected to a difference operation with the task timeliness value Ttask. If |Tauth - Ttask| is greater than the task offset threshold R2, it is determined that the authentication fails.
[0010] In a preferred embodiment, the dual-channel strategy in communication scheduling includes a key negotiation channel and a historical key fast call channel. The switching mechanism is controlled by the key critical factor Kdyn. When Kdyn is less than the negotiation trigger threshold B3, the historical key is called and the first-round handshake authentication is performed with the signature cache; When Kdyn is greater than or equal to B2, the platform negotiation key initialization process is carried out. A one-time negotiation parameter is introduced in the process, and the parameter is generated by superimposing a hash random number, a vehicle-mounted geographical location tag, and a timestamp; the dual-channel state machine is recorded by the state flag Sflag. After the Sflag value enters the renegotiation flag state, the task instruction push is automatically suspended to avoid mis-triggering of task synchronization caused by communication errors.
[0011] In a preferred embodiment, the role signature credential structure includes a task number, a permission granularity, a timeliness tag, and a device ID hash. Among them, the task number is temporarily allocated and generated by the edge node before each task collaboration. The permission granularity is restricted according to the task sensitive area division. The role signature credential generates a device signature map in a hashed aggregation form locally. The map structure has a circular structure detection mechanism to prevent the formation of an authority amplification path due to a repeated authorization link; the signature map maintenance period is bound to the task update period. When the number of collaborative device nodes exceeds the collaboration density threshold P4, a trust reduction algorithm is forcibly introduced to limit the horizontal chain expansion rate.
[0012] In a preferred embodiment, different encryption algorithms are provided in the key pool of each level. The encryption algorithms include symmetric encryption methods and asymmetric encryption methods. The combination usage strategy of each encryption algorithm is determined according to a preset encryption cost function Cenc and an authentication strength function Sauth. The functional relationship is: Selection scheme = max{Cenc(i) / Sauth(i)}, where i is the candidate algorithm set number, and the combination scheme with the largest ratio is selected and applied to the current task. If all the ratios obtained at the current level are lower than the calculated security threshold Z5, initiate a hierarchical encryption algorithm switch and perform two-round handshake confirmation.
[0013] In a preferred embodiment, the sensitive level determination mechanism includes an edge feature extraction unit and a task classification model. The edge feature extraction unit collects three behavioral features of the task data: format complexity, control instruction set distribution, and transmission timing pattern. Each feature is scored F1, F2, and F3 respectively and normalized and combined into a task feature vector Vtask. The task classification model is a shallow convolutional neural network structure. Based on historical task data, a classification decision boundary is generated, and the tasks are divided into four sensitive levels from C1 to C4, which represent general information, device configuration information, platform key information, and regulatory interface information respectively. The classification boundary is automatically incrementally trained and updated every fixed time window. When a new task is input, if the offset of its Vtask from the original classification boundary exceeds the adjustment threshold E, that is, the classification confidence of the model for this task decreases, the task is not directly assigned a level, but is marked as "pending confirmation status", and is handed over to the platform for manual label confirmation and determination. Then, its sensitive level is re-established and fed back to the information processing module for subsequent key matching and invocation.
[0014] In a preferred embodiment, the communication scheduling module configures a dynamic transmission priority mechanism, calculates the ratio of the result of the task scoring function F to the data volume in the data packet to obtain a priority index Px, evaluates the Px values of each data to be uploaded at a fixed period, and selects the data with the highest priority index to enter the encryption channel first. When the distribution of Px values fluctuates, that is, the standard deviation is greater than the adjustment threshold V, a preset temporary flow limiting strategy is triggered.
[0015] The technical effects and advantages of the present invention: The present invention constructs a key hierarchical call mechanism based on a task scoring function, establishing a dynamic mapping relationship between task complexity, data sensitivity levels, and encryption policies in the key pool. This enables the system to automatically select the encryption algorithm and key hierarchy with the optimal matching degree in different task scenarios, avoiding the problems of wasted computing resources or insufficient security strength caused by a fixed encryption mechanism. At the same time, when the scoring result is lower than the security threshold, the system rejects data transmission and triggers renegotiation, effectively preventing the incorrect execution of tasks with low security levels. This mechanism not only enhances data confidentiality during the task execution of driverless cleaning vehicles but also optimizes the allocation efficiency of the vehicle's overall computing resources, especially suitable for intelligent scheduling scenarios with multi-task parallel execution and weak network communication environments.
[0016] The present invention introduces multiple-level identity verification paths in the master-slave authentication control module, supporting the activation of the local authentication mechanism when the cloud platform connection fails or the network is interrupted, and judging the authentication validity through the difference comparison of the "task window limit parameter" and the "task timeliness value", thereby ensuring the security and controllability of the task authorization process. At the same time, the horizontal trust management module generates role signature credentials based on the task number, permission granularity, timeliness label, and device ID hash, constructs a local signature map, realizes the ring structure detection and collaborative permission convergence between devices, prevents permission amplification attacks or the access of disguised devices, and improves the overall trust security level and task stability of the system during the collaborative execution of multiple devices.
[0017] The present invention introduces a calculation method of the ratio of the task scoring function to the data packet size in the communication scheduling module to form a priority index Px. Through this index, the dynamic sorting of multiple types of data to be uploaded in the encryption channel is realized, improving the transmission priority of critical task data. At the same time, when the system detects that the distribution fluctuation of the priority index is too large, that is, the standard deviation exceeds the adjustment threshold, it automatically triggers a temporary flow-limiting strategy to limit the transmission rhythm of low-priority data, so as to ensure the priority processing of high-sensitivity and high-real-time task data in scenarios where network resources are limited or fluctuate violently. This mechanism effectively improves the intelligence level of the data scheduling strategy and reduces the risk of delay or packet loss of important tasks caused by network congestion. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] For the convenience of those skilled in the art to understand, the present invention will be further described below in conjunction with the drawings; Figure 1 It is the schematic diagram of the data interaction system between the driverless cleaning vehicle based on hybrid encryption and the cloud platform in the present invention.
[0019] Figure 2 It is the data interaction flow chart between the device side and the cloud platform in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0020] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0021] Reference Figure 1-2 The following embodiments are obtained: Embodiment 1: A data interaction system between an unmanned road sweeper and a cloud platform based on hybrid encryption, comprising: The authorization authentication module is configured to parse the device identity and short-term authentication tokens distributed by the cloud platform. When the platform connection is unavailable, the authentication is performed based on the cached signature token; the device identity (such as unique ID, public key certificate) distributed by the cloud platform is parsed; the short-term authentication token is processed to ensure that each communication access is authenticated; when the platform connection is unavailable, the offline temporary authentication is performed based on the locally cached signature token. Solve the problem of device startup being blocked in extreme network environments after disasters; improve the system's anti-connection dependence and ensure the minimum availability of equipment; prevent forged device access and ensure the integrity of the end-to-end trust chain of task scheduling.
[0022] The data encryption module has a key pool mechanism. The device side pre-configures multiple levels of session keys, and dynamically selects the key used to encrypt the vehicle data from the key pool according to the current task status. The key pool structure is built in, and the keys are divided into multiple levels (such as task level, task group level, and platform level). The appropriate key is dynamically called according to the current task status. It supports switching between symmetric encryption (high efficiency) and asymmetric encryption (strong security). It avoids attacks such as illegal acquisition of task data and tampering by middlemen. It supports "on-demand encryption" and "hierarchical encryption" strategies, taking into account computing power and security. It ensures the privacy and integrity of the transmission data such as the information reported by the sweeper and the video stream.
[0023] The information processing module establishes a mapping relationship between task status and encryption level. When switching tasks, the corresponding encryption algorithm and key template are automatically matched according to the level corresponding to the current task. If the match fails, data transmission is blocked and a security renegotiation is initiated; the current task status (such as cleaning, inspection, escape, emergency) is analyzed; a mapping model of "task status → encryption level" is constructed; the key level is matched, and the encryption template (algorithm type, key bit number, etc.) is selected; if the match fails, the data flow is blocked and a renegotiation is initiated. The "task execution logic" is embedded in the "secure communication strategy"; a higher level of encryption strategy is adopted for sensitive tasks (such as cleaning outside the hospital area and classified monitoring); and the intelligent security adaptability of the communication system is realized.
[0024] Master-slave authentication control module, which sets multiple levels of identity verification paths, automatically enables the slave authentication mechanism for local authorization when the master authentication path fails, and limits the scope and validity period of the activation tasks; sets the master authentication path (platform online verification) and the slave authentication path (local verification); automatically switches to slave authentication when master authentication fails; limits the scope of activation tasks and the time validity period of slave authentication. Ensure that the system can operate in a degraded mode in scenarios such as platform network failure and regional network disconnection; improve the continuous availability of the system and the ability to keep tasks uninterrupted; control the scope of slave authentication authorization to prevent the misuse of device identities.
[0025] Horizontal trust management module, which generates role signature credentials for the sweeper during task collaboration and proves its task legitimacy and authorization time to neighboring devices through a structured signature chain; generates role signature credentials among sweepers during collaborative tasks; constructs a signature chain graph to form a mutual trust relationship among multiple workshops; adds a permission granularity and ring structure detection mechanism to the graph to prevent link abuse. Realize device-to-device verification during the task collaboration process without the need for real-time intervention by the platform; improve the security and efficiency of large-scale deployment of sweeper cluster scheduling; support "distributed autonomous communication" to form a trusted edge network.
[0026] Communication scheduling module, which has a pre-loaded key channel and an instant key negotiation mechanism, decides whether to trigger the main key negotiation process according to the task sensitivity, or uses the historical session key to encrypt the initial state data; manages the key channel selection (pre-loaded vs instant negotiation); dynamically judges whether to trigger key negotiation according to the task sensitivity; manages the communication priority and decides the data sending order. Realize task priority control in a bandwidth-constrained environment; ensure that critical data is prioritized and a secure channel is established first; avoid delays or failures of important instructions caused by network fluctuations.
[0027] Among them, the task encryption level mapping model in the information processing module is constructed based on the task content, real-time requirements, and information sensitivity, so that the data encryption intensity changes dynamically with the task, improving the task completion rate and data security of the cleaning operation.
[0028] The key pool in the data encryption module is hierarchically managed according to a tree-like hierarchical structure. The lowest layer is the task-level key, the middle layer is the task group common key, and the top layer is the platform authorization key. The call of each layer of key is controlled by the task scoring function F(Tscore, Slevel); the task scoring function is obtained by weighted summation of the task complexity score Tscore and the sensitivity level score Slevel; The task complexity score Tscore is calculated based on a combination of four indicators: the length of the task scheduling instruction, the logical depth, the types of in-vehicle resources required, and the running duration, corresponding to T1 to T4 respectively. Each indicator is normalized and weighted to form the total score. The sensitivity level score Slevel is derived from the result of the level determination model feedback by the information processing module, and the scoring range is from 1 to 4, corresponding to ordinary, device-level, platform-level, and regulatory-level information respectively; When the encryption policy is invoked, calculate the result of the scoring function F and match it with the encryption security value corresponding to each layer of the key. Select the key level corresponding to the encryption security value that is closest but not lower than the scoring function F. If the result of the function F is lower than the lowest key invocation threshold K1, the system enters the protection state, does not perform encryption, and does not allow the upload of task data.
[0029] The data encryption module of the present invention has a key pool mechanism. The key pool is hierarchically managed according to a tree-like hierarchical structure, including three logical levels: the lowest level is the task-level key, the middle level is the task group common key, and the top level is the platform authorization key. The key set of each level is pre-deployed on the device side and has corresponding key attribute tags, including information such as the key algorithm type (such as AES, RSA, SM4), bit strength, and security level number.
[0030] The control mechanism for key selection: Before the device executes a task, the information processing module first generates the current task state based on the basic attributes of the task, and then calculates the result of the task scoring function F(Tscore, Slevel). The scoring function consists of two parts: Tscore (task complexity score): The task complexity score is composed of the following four indicators, denoted as T1, T2, T3, and T4 respectively: T1: The length of the task scheduling instruction (unit: byte), which reflects the number of task call interfaces; T2: The logical depth (unit: number of levels), that is, the number of nested control structures or the number of branch logics; T3: The types of in-vehicle resources (unit: number of resource items), such as cameras, radars, communication units, etc.; T4: The running duration (unit: second), which refers to the continuously expected execution time scheduled by the system.
[0031] Each indicator is processed by maximum-minimum normalization (or Z-score standardization) and unified to the interval [0, 1]. The final weighted sum is: Tscore = w1·T1 + w2·T2 + w3·T3 + w4·T4; where w1 to w4 are the task type weight parameters preset by the system.
[0032] Slevel (Sensitivity Level Score): The sensitivity level score is determined by the task classification model in the information processing module, ranging from 1 to 4, corresponding to general information (C1), device configuration information (C2), platform key information (C3), and regulatory interface information (C4) respectively, with scores of 1, 2, 3, and 4 for the four levels.
[0033] The result of the final scoring function is: F(Tscore, Slevel) = α·Tscore + β·Slevel; where α and β are weighting coefficients, reflecting the relative importance of the system for complexity and sensitivity level.
[0034] Key invocation process: After the system calculates the result of the scoring function, it will compare this value with the encryption security values marked at each level in the key pool. A security threshold range is preset for each key level. For example: Level 1 (task-level key) corresponds to the encryption security value range: [0.0, 1.5); Level 2 (task group general key) corresponds to the range: [1.5, 2.5); Level 3 (platform authorization key) corresponds to the range: [2.5, 4.0]; The system searches from top to bottom, selects the key level that is closest to and not lower than the result of the scoring function, and selects a key from this level to complete key loading.
[0035] For example, the current task is "An unmanned sweeper performs key obstacle clearing tasks in the peripheral area of a post-disaster hospital", and its task attributes are as follows: T1 (Instruction Length): 1200 bytes, normalized to 0.75; T2 (Logical Depth): 5 layers, normalized to 0.6; T3 (Resource Types): camera, radar, 5G communication, normalized to 0.7; T4 (Estimated Running Duration): 300 seconds, normalized to 0.9; Weight settings: w1 = 0.3, w2 = 0.2, w3 = 0.2, w4 = 0.3; Tscore = 0.3×0.75 + 0.2×0.6 + 0.2×0.7 + 0.3×0.9 = 0.765; After evaluation by the information processing module, this task involves sensitive data of platform scheduling, Slevel = 3; System parameter settings α = 1, β = 0.8; F = 1×0.765 + 0.8×3 = 3.165. At this time, the system compares the scoring result F = 3.165 with each level of the key pool: The maximum security value of the task-level key level 1 = 1.5 (insufficient); The maximum security value of the task group general key level 2 = 2.5 (still insufficient); The range of the platform authorization key level 3 is [2.5, 4.0], and the match is successful. Therefore, the system will select a key from the platform authorization key level (level 3) to encrypt the task data and sign it before uploading. If the result of the scoring function is lower than the lowest key invocation threshold K1 (for example: K1 = 0.6), then the system enters the protection state, does not perform encryption, and does not allow the upload of this task data.
[0036] The mapping relationship between task status and encryption level is constructed based on the state transition graph. Any task status node constructs the mapping with reference to three dimensions: real-time factor R1, information sensitivity S1, and task content importance N1. Among them, the transition probability P(i→j) is obtained by calculating the Euclidean distance between the transition vector composed of the real-time factor R1, information sensitivity S1, and task content importance N1 and the preset standard vector. The transition probability P(i→j) represents the probability of transitioning from state i to state j. There is a preset standard security level vector set Vi (i ∈ {1, 2, 3}). The level i corresponding to the Vi with the smallest distance from the transition vector is selected as the "security level of the current task", and the "security level of the current task" corresponds to a unique level in the tree-like hierarchical structure. When any node switches to a task with a different security level, the mapping mechanism forces a fallback to the key renegotiation state and clears the mapping cache.
[0037] The present invention establishes a mapping relationship between task status and encryption level through an information processing module to support the unmanned sweeper in dynamically matching an appropriate encryption level, algorithm template, and key call path according to the specific characteristics of the task currently being executed. The core structure of this mapping relationship is constructed based on the state transition graph model. Each task status node is defined as a state node in the graph, and the encryption level associated with each node is determined through a feature mapping mechanism.
[0038] Construction of the task status feature vector: Each task status node constructs a state feature vector with reference to three dimensions, specifically including: Real-time factor R1: It represents the sensitivity of the task to the response time. The higher the value, the stronger the real-time requirement; Information sensitivity S1: It represents the sensitive level of the data processed in the task, such as whether it contains identity information, scheduling instructions, platform interfaces, etc.; Task content importance N1: It represents the global scheduling priority of the task in the current cleaning cycle, involving path selection, core area cleaning, emergency handling, etc. The real-time factor R1, information sensitivity S1, and task content importance N1 can all be obtained through the expert assignment method or other existing technologies that achieve the same purpose, which will not be elaborated here. The three together constitute a three-dimensional vector, denoted as: V0 = (R1, S1, N1). This vector is used to determine the "encryption security level" corresponding to the current task in the system.
[0039] Security level determination mechanism and state transition control: The system pre-sets a set of standard security level vectors: V1, V2, V3, corresponding to three security levels respectively; each standard level vector Vi is also a three-dimensional vector, representing the reference feature structure of level i. The system calculates the Euclidean distance between the current task vector V0 and each standard vector Vi; selects the Vi with the smallest distance, and the corresponding number i is the security level to which the current task belongs. There is a pre-set mapping relationship between this level i and the hierarchical structure of the tree-shaped key pool in the data encryption module. For example: Security level 1 (i = 1) → Key pool level 1 (task-level key); Security level 2 (i = 2) → Key pool level 2 (task group key); Security level 3 (i = 3) → Key pool level 3 (platform authorization key).
[0040] Task state transition control logic: The system records the current task state as i. If the security level number mapped by the next task state is j, it is considered that a state transition has occurred: The transition probability P(i→j) represents the possibility of transitioning from state i to state j. In this embodiment, the system does not introduce an explicit transition matrix of the Markov model, but uses "whether the security level changes" as the state transition trigger criterion. When i≠j, the system immediately performs the following operations: Clear the key mapping cache in the original task state; Forcefully enter the key renegotiation state; Prohibit data from continuing to be transmitted along the old encryption channel; Load the key level corresponding to the new level j and re-select the encryption algorithm template. This mechanism ensures that data is always processed and transmitted within the correct security level coverage range, preventing security risks such as key level degradation or mismatch during task state switching.
[0041] Taking the "task switching scenario" as an example: Suppose the current task executed by a certain unmanned cleaning vehicle is "regional boundary inspection", with corresponding features: R1 = 0.4 (low to medium real-time), S1 = 0.5 (data contains path data), N1 = 0.3 (low priority), calculate the vector V0 = (0.4, 0.5, 0.3); The pre-set security level vectors in the system are: V1 = (0.2, 0.4, 0.3), V2 = (0.6, 0.6, 0.5), V3 = (0.8, 0.9, 0.9); Calculate the Euclidean distance: D1≈0.22; D2≈0.33; D3≈0.78 Select V1 (i = 1), the current task security level is 1, corresponding to key pool level 1. If the task switches to "disaster area core area obstacle clearance", its V0 = (0.8, 0.9, 0.8), and the system determines it to be security level 3 (i = 3) after recalculation. Since 1≠3, it triggers state transition and key renegotiation.
[0042] When the authentication mechanism is locally activated, the task window limit parameter Tauth is bound. This parameter is generated by the device self-check module at the start of authentication and is used for a difference operation with the task time limit value Ttask. If |Tauth - Ttask| is greater than the task offset threshold R2, the authentication is determined to have failed.
[0043] The master-slave authentication control module of the present invention aims to enable the driverless sweeper to still have limited and secure data processing and task execution capabilities in the case of unavailable network connection or platform failure. This module sets up multiple levels of identity verification paths, including the master authentication path and the slave authentication path: Master authentication path: It is the verification of the device identity legality by the cloud platform under standard circumstances; Slave authentication path: It is the local authorization process based on historical authentication records and hardware signature caches by the local module in the case of failed master authentication or unreachable platform. Through the linkage mechanism of master-slave authentication, the system ensures that the device can still execute some key tasks in the scenario of post-disaster network disconnection or edge communication failure, while controlling its execution scope and time limit to avoid risks of identity fraud and unauthorized use.
[0044] Activation and constraint mechanism of the slave authentication mechanism: When the slave authentication mechanism is activated, the system binds a parameter called the task window limit parameter Tauth, which is generated by the device through the device self-check module at the start of authentication.
[0045] The self-check module will collect the following status information of the current device: local timestamp (synchronized with the last authentication); local system load status; remaining value of the validity period of the last authentication; local security cache integrity verification result. Based on the above information, the system generates Tauth, which represents the "maximum continuous execution window" that the device is allowed to activate tasks at the current moment. The unit of Tauth is a time dimension (such as minutes, seconds, etc.), representing the "trust validity period" tolerated locally. At the same time, the system will obtain the task time limit value Ttask pushed by the task scheduling module, which represents the expected continuous running time of the task from the current moment. The system makes a judgment through the following rule: If |Tauth - Ttask| > the task offset threshold R2, the local authentication is determined to have failed. Where R2 is the maximum offset tolerance preset by the system, such as 60 seconds, 5 minutes, etc., and different values can be set according to the task sensitivity level. This threshold is used to control whether the required execution duration of the task exceeds the locally tolerable trust period to prevent unauthorized behavior caused by overly long tasks.
[0046] Authentication result behavior logic: If authentication is successful (|Tauth−Ttask|≤R2): The system generates a "temporary local authorization token"; starts the task execution process; the token is attached with a time limit flag in the background; all subsequent data encryption and task result uploads carry this token for permission identification; once the platform reconnects, the system verifies whether the token has completed the task within the window period; if the task times out or the token expires, an abnormal task behavior log will be recorded. If authentication fails (|Tauth−Ttask|>R2): The system refuses to execute the current task; generates a local warning message; records the audit log and notifies the platform (synchronizes after reconnecting); clears the task instruction cache.
[0047] Suppose the driverless sweeper is currently unable to connect to the platform, and the device enters the secondary authentication process. The device self-check module generates Tauth = 180 seconds (3 minutes), indicating that the maximum single-task execution window allowed by the device's local policy is 180 seconds. The task scheduling module simultaneously pushes cleaning task X and estimates Ttask = 210 seconds. The system calculates: |Tauth−Ttask| = |180−210| = 30 seconds; if the task offset threshold R2 set by the system is 60 seconds, then 30 seconds < R2, and the authentication passes. The system issues a "temporary local execution token" for this task, and the device enters the local task execution process. If the Ttask of another task Y is 300 seconds, the difference is 120 seconds, exceeding the offset threshold R2. At this time, the authentication fails, and the system refuses to execute task Y.
[0048] In the communication scheduling, the dual-channel strategy includes a key negotiation channel and a historical key quick call channel. The switching mechanism is controlled by the key critical factor Kdyn. When Kdyn is less than the negotiation trigger threshold B3, the historical key is called and the first-round handshake authentication is performed using the signature cache; When Kdyn is greater than or equal to B2, the platform negotiation key initialization process is carried out. In the process, a one-time negotiation parameter is introduced, which is generated by superimposing a hash random number, a vehicle-mounted geographical location tag, and a timestamp; the dual-channel state machine is recorded by the state flag Sflag. After the Sflag value enters the renegotiation flag state, the task instruction push is automatically paused to avoid mis-triggering of task synchronization caused by communication errors.
[0049] The communication scheduling module is the core unit for realizing secure and efficient data interaction between the vehicle end and the cloud platform in the present invention. Its responsibility is to switch between different key channels according to the sensitivity of the current task and the communication environment status to ensure the security, stability, and resource efficiency of data transmission. This module has two transmission paths: a pre-loaded key channel and an instant key negotiation mechanism, which are respectively used for: performing the first-round encryption based on historical authentication information when quickly starting a task; triggering the master key negotiation to establish a new secure channel when the task is highly sensitive or the authentication status is unstable.
[0050] Dual-channel Structure and Switching Mechanism: Channel Type: Key Negotiation Channel (Primary Channel): Based on a TLS-like structure, it negotiates with the cloud platform in real time to generate a new key; supports the introduction of one-time negotiation parameters to enhance the ability to prevent replay attacks; applicable to highly sensitive tasks or when the current connection authentication status is uncertain. Historical Key Quick Call Channel (Auxiliary Channel): Utilizes the historical session keys cached locally on the device; supports quick communication recovery under weak network conditions; completes the initial encryption and handshake process in combination with the local signature cache file.
[0051] Channel Switching Mechanism: The communication scheduling module uses a variable named Key Critical Factor Kdyn as the dynamic switching basis. Kdyn is a floating-point value that can be obtained through a pre-trained machine learning model, such as a convolutional neural network model. The input data can include but is not limited to the following: The current task sensitivity level (provided by the information processing module); the device authentication status (primary / slave authentication, remaining token time); the current network quality score (packet loss rate, latency, bandwidth, etc.), and the output data is the key critical factor Kdyn.
[0052] Specifically: The generation model of Kdyn adopts a multi-input convolutional neural network structure. The model has three main input channels, which respectively receive feature information from different internal modules of the system: Model Input: Task Sensitivity Level Index (provided by the information processing module): The value ranges from 1 to 4, corresponding to ordinary level, device level, platform level, and regulatory level; it can be converted into a one-hot encoded vector form and input into the model.
[0053] Device Authentication Status Index: Includes the current primary authentication / slave authentication flag; the remaining valid duration of the current device token (in seconds); the authentication path stability score (such as the number of successful handshakes in the past 24 hours).
[0054] Current Network Quality Index: Network packet loss rate (0 - 1); average latency (in milliseconds); Real-time bandwidth utilization rate (0 - 1); network volatility (such as latency standard deviation).
[0055] After these data are normalized by the preprocessing module, they enter the three-way convolutional network structure as three groups of input vectors, and are concatenated and fully connected at the high-level feature fusion stage. Finally, a numerical value is output as Kdyn.
[0056] Model Training Principle and Process: The training dataset of this model consists of historical task execution records and system status logs. The specific training process is as follows: Data collection phase: Collect the communication channel selection history during the execution of the multi-round sweeper task scheduling; each data record includes the task type, network status, authentication status, and channel decision result (using the historical key or platform negotiation); each piece of data is finally labeled with a "recommended channel level label"; construct the input feature vector and expected output based on this data.
[0057] Model training phase: Iteratively train the model to minimize the distance between the actual output Kdyn and the "recommended channel level"; map the channel level label to a floating-point value to form a continuous objective function; at the same time, constrain the output Kdyn distribution to fluctuate within a set range (such as [0.5, 4.5]) for subsequent threshold judgment applications.
[0058] Model verification and deployment phase: Evaluate the model accuracy on the validation dataset; deploy it to the device side after tuning.
[0059] Switching rule: If Kdyn < B3 (negotiation trigger threshold): The system determines that the current task is in the normal level or communication stable state; select to use the historical key channel; use the cached signature and the platform's most recent public key certificate for the first-round handshake authentication; encrypt the initial state data (such as start state, task number, location coordinates, etc.). If Kdyn ≥ B2 (negotiation strong trigger threshold): The system immediately enters the key negotiation process, introducing a one-time negotiation parameter Pnonce as a handshake extension: Pnonce = Hash(random number || current geographical location label || timestamp) for the "extra identity label" field in the key negotiation message to prevent man-in-the-middle attacks. The thresholds B2 and B3 can overlap or be set at intervals to support scenario-specific policy configuration.
[0060] Status management mechanism: The communication scheduling module uses the status flag variable Sflag to represent the current channel status, and the status definitions are as follows: Sflag = S0: Default idle state, no channel is started; Sflag = S1: In the historical key call state; Sflag = S2: In the key negotiation initialization state; Sflag = S3: Negotiation fails, enter the communication blocking state; Sflag = S4: Negotiation is completed, and a new secure channel is established.
[0061] When Sflag = S2, if abnormal situations such as handshake failure, parameter verification exception, timeout occur, the system enters the Sflag = S3 state. In the Sflag = S3 state, the system performs the following actions: Pause the push of all task instructions; intercept new task scheduling messages; lock the encryption module to prohibit the use of invalid keys; enter the recovery re-negotiation process.
[0062] Assume the current task is "Risk area cleaning task under platform takeover", and its sensitivity level is evaluated as Slevel = 4 (supervisory level). The device's main authentication is still within the valid period, but the network has intermittent interruptions. The system's real-time evaluation of the Kdyn value is 3.2, which is higher than the platform-set B2 = 2.5. According to the rule: The communication scheduling module determines that the main key negotiation process should be entered; generate one-time negotiation parameters: random number R = 10393, geographical location tag L = GZ - HZ block 45; timestamp T = 2025 - 04 - 08 09:35:11.
[0063] Pnonce = Hash(R||L||T), set Sflag = S2, and start the TLS-like handshake; after successful negotiation, the status changes to Sflag = S4, and normal communication begins. If the task is interrupted and a new task is reallocated, the system then determines whether to degrade and switch to the historical key channel based on the newly updated Kdyn value in real-time.
[0064] It should be noted that: in each channel call process, it is necessary to first determine the key pool level to be accessed according to the result of the current task scoring function F; in this level, calculate the optimal encryption combination strategy according to the encryption cost function Cenc(i) and the authentication strength function Sauth(i). The channel only decides whether to directly obtain the policy key through the historical cache or enter the negotiation process to obtain a new session key.
[0065] During the execution of the cleaning vehicle involved in the present invention, there are task data of different levels and variable network states. If the key negotiation process is always forced, it will lead to: network congestion, increased probability of negotiation failure; high consumption of computing power resources, especially unfavorable for low-sensitivity, frequent, and fragmented tasks; long time for establishing the encryption channel, affecting real-time performance. On the contrary, if historical cache keys are used uniformly, it may also lead to: decreased security strength due to repeated use of keys; risk of data leakage for some high-sensitivity tasks due to insufficient key levels. Therefore, it is necessary to introduce a dynamic judgment mechanism in the communication scheduling module to reasonably select whether to use cached keys or negotiate new keys according to factors such as task scoring, authentication status, and network quality, so as to achieve an adaptive balance between encryption strength and system efficiency.
[0066] In the typical operating environment of driverless cleaning vehicles, such as the edge of the park, underground passages, disaster areas, etc., unstable platform connections are the norm. If the system must negotiate keys online, it will be unable to execute tasks when encountering temporary network outages. Introducing a historical key quick call mechanism, combined with signature caching and authentication fallback paths, can complete the initial stage of the task under short-term offline conditions, ensuring that the cleaning task does not interrupt and the system does not crash. At the same time, after communication is restored, enter the key renegotiation process to achieve an asynchronous security closed-loop.
[0067] Different task sensitivity levels (C1 - C4) correspond to different data confidentiality requirements. The communication scheduling module derives the key pool level through the result of the task scoring function and determines the communication path through the key critical factor Kdyn. For tasks with low sensitivity and high transmission frequency (such as general location information, navigation status), using historical keys can meet the security requirements without starting a complete key negotiation process every time, thus significantly reducing the key calculation and handshake overhead.
[0068] The role signature credential structure includes a task number, permission granularity, time - validity label, and device ID hash. The task number is temporarily assigned and generated by the edge node (such as a small relay controller) in the collaborative area during the task initialization stage. The permission granularity is restricted according to the task sensitivity zoning. The role signature credential generates a device signature map in a hash - aggregation form locally. The map structure has a ring - structure detection mechanism to prevent the formation of an authority - amplification path due to repeated authorization links. The maintenance period of the signature map is bound to the task update period. When the number of collaborative device nodes exceeds the collaborative density threshold P4, a trust - reduction algorithm is forcibly introduced to limit the expansion rate of the horizontal chain.
[0069] The horizontal trust management module of the present invention is used to solve the security trust problem during task collaboration between driverless cleaning vehicles. In traditional unmanned systems, device - to - device identity authentication relies on the platform - center verification mechanism. However, in scenarios where the network is unstable or the platform is offline, there is a lack of a verifiable identity and permission mechanism between adjacent devices, resulting in the risk of collaborative misjudgment or being misused.
[0070] To solve this problem, the present invention introduces a role signature credential mechanism and a structured signature chain structure (map) between cleaning vehicles. Through local generation and update, it realizes device - to - device identity confirmation, permission verification, and collaborative task authorization without relying on the platform.
[0071] Explanation of the role signature credential structure: The horizontal trust management module generates a role signature credential for the cleaning vehicle before task collaboration. This credential serves as the local authentication basis for device identity, permissions, and task relevance. Its structure includes the following four core fields: Task number: Each collaborative task is assigned a unique number, which is temporarily generated and broadcast by the edge node (such as a small relay controller) in the collaborative area during the task initialization stage; Permission granularity: Represents the permission scope of the device in this collaborative task. The permission granularity is classified and restricted according to the task sensitivity zoning. For example, it is only allowed to obtain the navigation path but not allowed to upload monitoring images; Time - validity label: Represents the valid period range of this signature credential, with the unit being an absolute timestamp or a task execution window; Device ID hash: The unique device identification information (such as hardware fingerprint, public - key digest) is hashed using SHA - series algorithms to ensure privacy protection and non - forgeable identity.
[0072] This signature credential is encrypted and signed by the device's local security module and can be verified for its authenticity and integrity by other devices.
[0073] Structured signature chain and graph generation mechanism: The role signature credentials are added to the device signature graph maintained locally. The graph consists of multiple nodes, and each node represents the role signature credential of a device. When the graph is updated, a hash aggregation mechanism is adopted, that is, the hash digests of multiple credentials are combined into the root node of the Merkle tree and stored in the device's local signature chain. The graph has a circular structure detection mechanism. That is, when it is detected that a device forms a cyclic authorization chain with itself or other devices (A trusts B, B trusts C, and C trusts A again), it is identified as an "abnormal trust chain", and the system will trigger a trust cleaning process to cancel the credential chain with the weakest permissions to prevent the occurrence of a "permission amplification path".
[0074] Trust control strategy and dynamic adjustment: The system sets a collaborative density threshold P4, which represents the maximum number of devices participating in collaboration in a certain area or task segment. For example, setting P4 = 5 means that at most 5 devices are allowed to establish a horizontal trust chain during a task collaboration process. When the number of collaborative devices exceeds the threshold P4, the system forcibly introduces a trust reduction algorithm. The algorithm in this prior art relies on evaluating the value indicators of each horizontal signature path (such as task overlap degree, device reachability), preferentially retains the path of "recent successful communication + strong permission restriction", and terminates the signature interaction for redundant or duplicate authorization paths, thereby preventing the infinite expansion of the chain, resulting in resource abuse or signature flooding. The maintenance period of the signature graph is bound to the task update period, that is, each time the task is updated, the system will synchronously update the graph, clear the expired credentials, add new authorization paths, and form a periodic trust refresh.
[0075] Suppose 6 cleaning vehicles are deployed in a cleaning area due to complex terrain, and the task number is T20250408. The edge node generates a task number for this task and sets the permission granularity level as "navigation collaboration + environmental status sharing". Each cleaning vehicle generates a signature credential according to its own role (master control, auxiliary, following): Cleaning vehicle A generates a credential: including task number T20250408, permission granularity P2, validity period 2025-04-08 10:00~10:15, and the device ID hash is H(A); After verifying this credential, cleaning vehicle B generates its own credential and broadcasts it to C; When it is detected that C attempts to sign B, and B has already signed A, the system detects that A→B→C→A forms a closed loop; The graph algorithm deletes the signature record of C and marks this path as an "abnormal path"; At this time, the collaborative density detection module finds that 6 devices have established signature paths, exceeding the threshold P4 = 5; The system introduces a trust reduction algorithm, and only retains the three trust paths of the master control A, the secondary control B, and the nearby C. Other devices only retain the permission to passively receive data.
[0076] In each level of the key pool, different encryption algorithms are set. The encryption algorithms include symmetric encryption methods and asymmetric encryption methods. The combination usage strategy of each encryption algorithm is determined according to the preset encryption cost function Cenc and authentication strength function Sauth. The functional relationship is: Selection scheme = max{Cenc(i) / Sauth(i)}, where i is the candidate algorithm set number. The combination scheme with the largest ratio is selected and applied to the current task. If all the ratios obtained at the current level are lower than the calculated security threshold Z5, a hierarchical encryption algorithm switch is initiated and two rounds of handshake confirmation are performed.
[0077] Symmetric encryption methods: such as Guomi SM4, AES-128, AES-256, etc.; Asymmetric encryption methods: such as RSA-2048, ECC, SM2, etc.; When the system is activated for each task, it will screen among all candidate encryption algorithm combinations at the corresponding level and select the optimal scheme according to the ratio of the encryption cost function Cenc(i) to the authentication strength function Sauth(i). The functional relationship is as follows: Selection scheme = max{Cenc(i) / Sauth(i)}; where i represents the number of the candidate algorithm combination.
[0078] The encryption cost function Cenc(i) is used to measure the resource overhead and encryption load required for the current candidate algorithm combination i. Generally, it can include the following prior art parameters: Encryption time per unit data: such as the number of milliseconds required to encrypt 1MB of data, from the benchmark of the open-source encryption library; Key length in bits: the number of bits required for the encryption algorithm, reflecting its key space; Processor resource consumption rate: the CPU ratio occupied during the task encryption process; Power consumption rate: the power consumption corresponding to a unit encryption operation (such as mW / s); A reference calculation method is: Cenc(i)=Tenc(i)×P(i); where: Tenc(i): the average encryption time of this algorithm combination; P(i): the power consumption per unit time of this algorithm combination.
[0079] The authentication strength function Sauth(i) is used to evaluate the comprehensive capabilities of the candidate algorithm combination in aspects such as anti-attack, anti-replay, and anti-tampering. The evaluation parameters can include: Algorithm public security level: such as RSA-2048 with a security strength of 112 bits and ECC with 128 bits; Integrity index of the authentication mechanism: whether it supports complete identity authentication and integrity verification; Anti-quantum attack ability score: such as the relative vulnerability of symmetric algorithms to quantum attacks; Known attack frequency in the current environment: whether there are public vulnerabilities, cracking reports, etc.
[0080] The reference calculation method is: Sauth(i) = Slevel(i) × B(i); where: Slevel(i): the basic security level recognized by the cryptographic community for the algorithm combination (such as the NIST recommended level); B(i): the algorithm security weight coefficient given by the platform or supervision. The encryption cost function Cenc(i) and the authentication strength function Sauth(i) can also be obtained through other calculation methods that achieve the same measurement effect in existing technologies. Without exhaustive examples here, only one implementable method is given.
[0081] The system evaluates the Cenc(i) / Sauth(i) ratio of all combinations in the candidate algorithm set and selects the combination with the largest ratio as the encryption scheme for the current task. If all candidate combinations at this level satisfy: max{Cenc(i) / Sauth(i)} < Z5; that is, the security is insufficient or the cost is too high, the system triggers: the hierarchical encryption algorithm switching mechanism: switch to a higher-level key pool level (such as task group level → platform level); conduct two rounds of handshake confirmation: including device identity verification and key negotiation path verification; prevent resource abuse or delay caused by incorrect invocation of high-strength algorithms for low-level tasks.
[0082] The sensitive level determination mechanism includes an edge feature extraction unit and a task classification model. The edge feature extraction unit collects three behavioral characteristics of the task data: format complexity, control instruction set distribution, and transmission timing pattern, assigns scores F1, F2, and F3 to each feature respectively, and normalizes and combines them into a task feature vector Vtask; The task classification model is a shallow convolutional neural network structure, generates a classification decision boundary based on historical task data, and classifies tasks into four sensitive levels C1 to C4, which represent general information, device configuration information, platform key information, and regulatory interface information respectively; the classification boundary is automatically incrementally trained and updated once every fixed time window; When a new task is input, if the offset of its Vtask from the original classification boundary exceeds the adjustment threshold E, that is, the model's confidence in classifying this task decreases, the task is not directly assigned a level, but is marked as "pending confirmation status", and is handed over to the platform for manual label confirmation and determination, and then its sensitive level is re-established and fed back to the information processing module for subsequent key matching and invocation.
[0083] Structure and implementation of the edge feature extraction unit: The edge feature extraction unit is located in the local system of the cleaning vehicle, analyzes the data features of the task to be executed in real time, and extracts three-dimensional indicators from the behavioral level, namely: format complexity (F1): analyzes the hierarchy and nesting depth of the task data structure, such as whether it contains nested JSON, multi-level XML, etc.; data with high complexity is more likely to contain sensitive information such as identifiable identity, geography, and status; the system presets several format type templates, and assigns a complexity score according to the matching situation, with a range of 0-10.
[0084] Control instruction set distribution (F2): Analyze the types of instructions used in the task, such as navigation, device control, image acquisition, etc.; different instruction combinations represent the degree of invocation of the system's core functions by the task; system maintenance instruction sensitivity table, assign higher scores to highly sensitive instructions.
[0085] Transmission timing pattern (F3): Analyze the emission frequency, delay fluctuation, and timing continuity of data packets; high-frequency and stable transmission is more likely to represent real-time data streams (such as images, videos), with higher risks; calculate the mean, standard deviation, packet loss rate, etc. within a certain time window, and map them to a timing complexity score.
[0086] Normalize the three scoring values and combine them into a task feature vector: Vtask=(F1_norm,F2_norm,F3_norm), and this vector will be used as the input for the subsequent classification model.
[0087] Task classification model structure, the task classification model is a shallow convolutional neural network structure, and its design considers small model size, high computational efficiency, and easy deployment on the vehicle edge. This model performs convolution, pooling, and fully connected processing on the Vtask input vector, and outputs the classification probability of the task at four sensitivity levels. The model output is a probability vector [p1,p2,p3,p4], and the category corresponding to the maximum value is the initial judgment level of the task.
[0088] Classification offset and mechanism for pending confirmation: When a new task arrives, the model calculates the closest category corresponding to its Vtask vector. If the model determines that its classification confidence is insufficient, that is, the offset between the vector and the center of the original classification boundary exceeds the set adjustment threshold E, it is considered that the current classification result is unstable, and the system enters the following process: Mark the task as "pending confirmation status"; prevent it from entering the encryption process and data upload process; synchronously submit its feature vector and data summary to the platform; perform manual label review by the platform side; the platform label result is used to confirm the final sensitivity level of the task; the result is sent back to the information processing module to guide the matching call of the key level; this sample is included in the next round of model incremental training dataset. This process ensures that the model does not classify rashly when it cannot be confirmed, thereby improving the system security.
[0089] Assume a new task with the following characteristics: F1 = 7.5 (multi-layer nested data format); F2 = 8.0 (including advanced control instructions such as area fence unlocking); F3 = 6.8 (high-speed transmission timing); after normalization, Vtask=(0.75, 0.8, 0.68); input this vector into the convolutional neural network model, and the output probabilities are: p1 = 0.05, p2 = 0.1, p3 = 0.35, p4 = 0.5 → initially determine the supervision interface information corresponding to p4; the system calculates the Euclidean distance between the task Vtask and the central vector corresponding to the supervision interface information as 0.41, which is higher than the system-set adjustment threshold E = 0.35, determines that the classification confidence has decreased, marks it as "pending confirmation of rights", and submits it to the platform for manual confirmation.
[0090] The communication scheduling module configures a dynamic transmission priority mechanism, calculates the ratio of the result of the task scoring function F to the data volume in the data packet to obtain the priority index Px, evaluates the Px values of each piece of data to be uploaded at a fixed period, and selects the data with the highest priority index to enter the encryption channel first. When the Px value distribution fluctuates, that is, the standard deviation is greater than the adjustment threshold V, a preset temporary flow-limiting strategy is triggered.
[0091] Priority index calculation method: Each data block to be transmitted corresponds to a source task. The system first calculates the scoring function F of this task (provided by the information processing module), and then combines the data volume D of this data block to calculate the transmission priority index Px of this data block. The calculation method is as follows: Px = F / D, where: F: task scoring function, comprehensively considering task complexity (Tscore) and sensitivity level (Slevel), see the foregoing content of this specification for details; D: the data volume of this data packet; Px: priority index, indicating the importance of the task per unit of data, and the higher the value, the more important the task.
[0092] Scheduling strategy and execution mechanism: Periodic scheduling evaluation: The communication scheduling module scans the data queue to be uploaded at a fixed period (such as every 3 seconds); for each piece of data in the queue, calculates the corresponding Px index, and sorts them from largest to smallest; the data with the highest priority first enters the encryption channel for encryption processing and upload; the remaining data queues up in turn until the next scheduling period or an idle channel is available. Px fluctuation detection and flow-limiting mechanism: The priority index Px distribution of the data packets in the current scheduling period varies greatly. The system calculates its standard deviation σ (the standard deviation represents the degree of data set fluctuation); if the standard deviation σ is greater than the preset adjustment threshold V, it means that the data priority fluctuates violently, and it may occur that high-priority tasks are delayed due to low-priority traffic congestion; at this time, a temporary flow-limiting strategy is triggered, that is: only allow the top N (such as the top 3) data in the Px ranking in the current period to enter the encryption upload channel; the remaining data is postponed for processing; after setting a cooling time (such as 1 second), re-evaluate; prevent resource scheduling chaos caused by high fluctuations.
[0093] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0094] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0095] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0096] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and modules described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0097] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A data interaction system between an unmanned sweeper and a cloud platform based on hybrid encryption, characterized in that, Including: A permission authentication module, configured to parse the device identity identifier and short-cycle authentication token distributed by the cloud platform, and perform identity authentication based on the cached signature token when the platform connection is unavailable; A data encryption module, with a key pool mechanism. Multiple levels of session keys are pre-configured on the device side, and a key for encrypting in-vehicle data is dynamically selected from the key pool according to the current task status; An information processing module, which establishes a mapping relationship between the task status and the encryption level. When the task is switched, the corresponding encryption algorithm and key template are automatically matched according to the level corresponding to the current task. If the matching fails, data transmission is blocked and a secure re-negotiation is initiated; A master-slave authentication control module, which sets multiple levels of identity verification paths. When the primary authentication path fails, the slave authentication mechanism is automatically enabled for local authorization, and the scope and validity period of the activated task are limited; A horizontal trust management module, which generates role signature credentials for the sweeper during task collaboration, and proves its task legality and authorization time to neighboring devices through a structured signature chain; A communication scheduling module, with a pre-loaded key channel and an instant key negotiation mechanism, determines whether to trigger the primary key negotiation process according to the task sensitivity, or uses the historical session key to encrypt the initial state data; Among them, the task encryption level mapping model in the information processing module is constructed based on the task content, real-time requirements, and information sensitivity, so that the data encryption intensity changes dynamically with the task, improving the task completion rate and data security of the sweeping operation.
2. The data interaction system between the driverless sweeper based on hybrid encryption and the cloud platform according to claim 1, wherein The key pool in the data encryption module is hierarchically managed according to a tree-like hierarchical structure. The lowest layer is the task-level key, the middle layer is the task group general key, and the top layer is the platform authorization key. The call of each layer of key is controlled by the task scoring function F(Tscore, Slevel); the task scoring function is obtained by weighted summation of the task complexity score Tscore and the sensitivity level score Slevel; The task complexity score Tscore is calculated by combining four indicators: the length of the task scheduling instruction, the logical depth, the types of in-vehicle resources required, and the running duration, corresponding to T1 to T4 respectively. After each indicator is normalized, a total score is formed by weighting. The sensitivity level score Slevel comes from the result of the level determination model fed back by the information processing module, and the scoring range is 1 to 4, corresponding to general, device-level, platform-level, and regulatory-level information respectively; When the encryption policy is called, the result of the scoring function F is calculated and matched with the encryption security value corresponding to each layer of key. The key layer corresponding to the encryption security value that is closest to but not lower than the scoring function F is selected. If the result of the function F is lower than the lowest key call threshold K1, the system enters the protection state, does not perform encryption, and does not allow the task data to be uploaded.
3. The data interaction system between the driverless sweeper based on hybrid encryption and the cloud platform according to claim 2, characterized in that, The mapping relationship between task status and encryption level is constructed based on the state transition diagram. Any task status node constructs the mapping with reference to three dimensions: real-time factor R1, information sensitivity S1, and task content importance N1. Among them, the transition probability P(i→j) is obtained by calculating the Euclidean distance between the transition vector composed of real-time factor R1, information sensitivity S1, and task content importance N1 and the preset standard vector. The transition probability P(i→j) represents the probability of transitioning from state i to state j. There is a preset set of standard security level vectors Vi (i ∈ {1, 2, 3}). Select the level i corresponding to the Vi with the smallest distance from the transition vector, which is the "security level of the current task". And the "security level of the current task" corresponds to a unique level in the tree-like hierarchical structure. When any node switches to a task with a different security level, the mapping mechanism is forced to roll back to the state of re-negotiating the key and clear the mapping cache.
4. The data interaction system between the driverless sweeper based on hybrid encryption and the cloud platform according to claim 3, characterized in that, When the authentication mechanism is locally activated, the task window limit parameter Tauth is bound. This parameter is generated by the device self-check module at the start of authentication and is used for difference operation with the task time limit value Ttask. If |Tauth - Ttask| is greater than the task offset threshold R2, it is determined that the authentication fails.
5. The data interaction system between the driverless sweeper based on hybrid encryption and the cloud platform according to claim 4, characterized in that, In communication scheduling, the dual-channel strategy includes a key negotiation channel and a historical key fast call channel. The switching mechanism is controlled by the key critical factor Kdyn output by a pre-trained machine learning model. When Kdyn is less than the negotiation trigger threshold B3, the historical key is called and the first-round handshake authentication is performed with the signature cache. When Kdyn is greater than or equal to B2, the platform negotiation key initialization process is carried out. A one-time negotiation parameter is introduced in the process, and the parameter is generated by superimposing a hash random number, a vehicle-mounted geographical location tag, and a timestamp. The dual-channel state machine is recorded by the state flag Sflag. After the Sflag value enters the re-negotiation flag state, the task instruction push is automatically paused to avoid mis-triggering of task synchronization caused by communication errors.
6. The data interaction system between the unmanned cleaning vehicle based on hybrid encryption and the cloud platform according to claim 5, wherein, The role signature credential structure includes a task number, permission granularity, time limit label, and device ID hash. Among them, the task number is temporarily allocated and generated by the edge node before each task collaboration. The permission granularity is restricted according to the task sensitive area division. The role signature credential generates a device signature map locally in a hash aggregation form. The map structure has a ring structure detection mechanism to prevent the formation of a permission amplification path due to a repeated authorization link. The maintenance period of the signature map is bound to the task update period. When the number of collaborative device nodes exceeds the collaborative density threshold P4, a trust reduction algorithm is forcibly introduced to limit the expansion rate of the horizontal chain.
7. The data interaction system between the driverless sweeper based on hybrid encryption and the cloud platform according to claim 6, characterized in that, In each level of the key pool, different encryption algorithms are set. The encryption algorithms include symmetric encryption and asymmetric encryption. The combination usage strategy of each encryption algorithm is determined according to the preset encryption cost function Cenc and authentication strength function Sauth. The functional relationship is: Selection plan = max{Cenc(i) / Sauth(i)}, where i is the candidate algorithm set number. The combination plan with the largest ratio is selected and applied to the current task. If all the ratios obtained at the current level are lower than the calculated security threshold Z5, a hierarchical encryption algorithm switch is initiated and two rounds of handshake confirmation are performed.
8. The data interaction system between the unmanned sweeping vehicle based on hybrid encryption and the cloud platform according to claim 7, characterized in that, The sensitive level determination mechanism includes an edge feature extraction unit and a task classification model. The edge feature extraction unit collects three behavioral characteristics of the task data: format complexity, control instruction set distribution, and transmission timing pattern. Each feature is scored F1, F2, and F3 respectively and normalized and combined into a task feature vector Vtask. The task classification model is a shallow convolutional neural network structure. Based on historical task data, a classification decision boundary is generated, and the tasks are divided into four sensitive levels from C1 to C4, representing general information, device configuration information, platform key information, and regulatory interface information respectively. The classification boundary is automatically incrementally trained and updated every fixed time window. When a new task is input, if the offset of its Vtask from the original classification boundary exceeds the adjustment threshold E, that is, the classification confidence of the model for this task decreases, the task is not directly assigned a level, but is marked as "pending confirmation status", and is handed over to the platform for manual label confirmation and determination. Then, its sensitive level is re-established and fed back to the information processing module for subsequent key matching and invocation.
9. The data interaction system between the driverless sweeper based on hybrid encryption and the cloud platform according to claim 8, characterized in that, The communication scheduling module configures a dynamic transmission priority mechanism, calculates the ratio of the result of the task scoring function F to the data volume in the data packet to obtain the priority index Px, evaluates the Px values of each data to be uploaded at a fixed period, and selects the data with the highest priority index to enter the encryption channel first. When the distribution of Px values fluctuates, that is, the standard deviation is greater than the adjustment threshold V, a preset temporary flow limiting strategy is triggered.
Citation Information
Patent Citations
Reprogrammable security for controlling piracy and enabling interactive content
CN101364415A
System and Method for Authenticating Transactions Through a Mobile Device
US20120150742A1
Cited By
Encrypted data transmission authentication system based on security edge gateway
CN120710807A
Mobile robot adaptive following method and system based on UWB and laser radar
CN121386430A
Network security isolation system based on rail transit vehicle network information processing
CN121585462A
A network security isolation system based on rail transit vehicle network information processing
CN121585462B
Secure access and identity authentication method and system for distributed energy storage equipment
CN121887541A