Lightweight privacy protection vehicle formation building method

Through multi-level encryption mechanism and dynamic bucket mapping technology, the problem of incomplete privacy protection in the formation of vehicle fleets is solved, lightweight computing and communication optimization and dynamic security enhancement are achieved, and it is suitable for the coordination of logistics fleets, urban intelligent buses and autonomous vehicle groups.

CN120452180APending Publication Date: 2025-08-08GUILIN UNIV OF ELECTRONIC TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510812507.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing vehicle fleet formation method has incomplete privacy protection, high computing overhead and insufficient dynamic adaptability, which cannot effectively resist attacks from trusted third parties, and there is a risk of reputation data leakage.

Method used

A multi-level encryption mechanism is adopted, including randomized order-preserved encryption of buckets, improved asymmetric scalar product reserve encryption and Paillier homomorphic encryption, combined with dynamic bucket mapping and random vector perturbation, to achieve privacy protection of vehicle attribute matching and feedback reports, and reduce computing and communication overhead.

Benefits of technology

It realizes privacy protection throughout the life cycle, reduces computing and communication loads, enhances dynamic security, ensures the confidentiality and integrity of vehicle attributes, reputation and feedback data, and is suitable for coordinated transportation of logistics fleets, urban intelligent bus fleet scheduling and autonomous vehicle group coordination.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120452180A_ABST
    Figure CN120452180A_ABST
Patent Text Reader

Abstract

The invention discloses a lightweight privacy protection vehicle formation building method, which adopts a multi-level encryption mechanism from pilot vehicle selection and member attribute matching in a formation forming stage to feedback aggregation and reputation updating in a formation disintegration stage, and ensures the confidentiality and integrity of sensitive data (such as reputation values, attributes and feedback reports). Through dynamic bucket mapping, random vector perturbation and lightweight ciphertext calculation, the method significantly reduces calculation and communication overhead while guaranteeing privacy, and solves the core problems that a traditional scheme depends on a trusted third party, is susceptible to association attacks, is insufficient in dynamic adaptability and the like. The technical framework can be widely applied to logistics fleet collaborative transportation, urban intelligent bus formation scheduling, automatic driving vehicle group collaboration and other scenes, and safe and reliable technical support is provided for large-scale deployment of an intelligent traffic system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle network security technology, and specifically to a vehicle formation method and system with lightweight privacy protection. Background Art

[0002] As a core application of intelligent transportation systems, vehicle platooning management methods significantly improve road resource utilization and reduce energy consumption by optimizing multi-vehicle coordinated driving. The core challenge of this technology lies in achieving highly reliable platooning service quality while maintaining privacy throughout the entire lifecycle. Existing solutions still have significant shortcomings in balancing these two aspects.

[0003] In the field of platoon service quality optimization, reputation-based evaluation mechanisms are the mainstream method for selecting high-reliability lead vehicles. In 2018, Datta et al. [1] proposed a reputation-based optimal allocation model to ensure fairness by balancing the size of the platoon and the reputation score of the lead vehicle. However, their model did not consider the need for real-time reputation updates in dynamic scenarios and lacked an active defense mechanism against malicious vehicles. In 2019, Hu et al. [2] designed a trusted lead vehicle recommendation scheme called REPLACE based on an iterative filtering algorithm, which suppressed the influence of malicious ratings by aggregating user feedback, but its computational complexity was as high as O(n 2 ), making it difficult to apply to large-scale platooning scenarios. In 2020, Li et al. [3] introduced blockchain technology to build a decentralized reputation management system, using on-chain immutable records to elect trusted leader vehicles. However, the blockchain consensus mechanism increased the delay in platoon formation by 30%-50%, which could not meet real-time requirements.

[0004] In terms of privacy protection, existing solutions generally have functional deficiencies or excessive resource overhead. For example, the PPVF scheme [4] protects privacy in the reputation feedback phase through anonymization, but it relies on a semi-trusted server to store reputation data and does not introduce a vehicle weight factor, resulting in a high error rate in score updates. The PPRT scheme [5] proposed in 2021 combines homomorphic encryption and truth discovery technology to achieve accurate reputation updates under privacy protection, but the formation and disbanding of the formation require the real-time participation of trusted institutions, resulting in a 2.3-fold increase in communication overhead. The BTMPP scheme [6] uses Bloom filters and private set intersection (PSI) technology to achieve fuzzy reputation matching, but it cannot support horizontal reputation comparison between multiple vehicles. In 2023, the RPPM scheme [7] achieves cloud-based reputation aggregation based on the secure comparison protocol (SCP), but does not encrypt vehicle attributes and feedback reports, making it vulnerable to man-in-the-middle attacks. The EMPPC scheme [8] proposed in 2025 constructs a multi-dimensional privacy protection framework, but in the lead vehicle election phase, two servers need to frequently interact to calculate the highest reputation score, resulting in expensive computing overhead, and the server holding the homomorphic private key may cause data leakage.

[0005] The above analysis reveals the following issues with existing technologies: Traditional methods rely on a trusted third party or dual-server architecture for reputation comparison and attribute matching, resulting in high computational and communication overhead and inability to mitigate the privacy risks of semi-trusted servers. Furthermore, existing attribute matching techniques based on asymmetric scalar product-preserving encryption can easily expose sensitive vehicle attributes. Current privacy-preserving reputation management relies on complex cryptographic operations such as homomorphic encryption and private set intersection, failing to balance privacy and real-time performance. Feedback reports are transmitted in plaintext or in unweighted aggregates, exposing data tampering and traceability vulnerabilities.

[0006] [1]Datta S, Nikolaou P, Michael MK (2023) Reputation-based user vehicle assignment in intelligent and connected vehicle platoons. In: 2023IEEEInternational Conference on Omnilayer Intelligent Systems (COINS), IEEE, pp1–6;

[0007] [2]Hu H, Lu R, Zhang Z, et al (2016) Replace: A reliable trust-based platform service recommendation scheme in vanet. IEEE Transactions on VehicularTechnology 66(2):1786–1797;

[0008] [3] Li Q, Malip A, Martin KM, et al (2012) A reputation-based announcement scheme for vanets. IEEE Transactions on Vehicular Technology 61(9):4095–4108;

[0009] [4]Cheng H,Shojafar M,Alazab M,et al(2021)ppvf:privacy-preservingprotocol for vehicle feedback in cloud-assisted vanet.IEEE transactions onintelligent transportation systems 23(7):9391–9403;

[0010] [5]Cheng H,Zhang X,Yang J,et al(2023)Pprt:Privacy preserving andreliable trust-aware platoon recommendation scheme in iov.IEEE SystemsJournal 17(3):4922–4933;

[0011] [6]Liu Z,Huang F,Weng J,et al(2020)BTMPP:Balancing trust managementand privacy preservation for emergency message dissemination in vehicularnetworks.IEEE Internet of Things Journal 8(7):5386–5407;

[0012] [7]Li R,Liu Z,Ma Y,et al(2023)Rppm:A reputation-based and privacy-preserving platoon management scheme in vehicular networks.IEEE Transactionson Intelligent Transportation Systems;

[0013] [8] Xu N, Liu Z, Han X, et al (2025) An efficient and multi-dimensional privacy-preserving platoon communication scheme in vehicular networks. IEEE Transactions on Intelligent Transportation Systems pp 1–17. Summary of the Invention

[0014] In order to solve the problems of incomplete privacy protection, high computational overhead and insufficient dynamic adaptability in vehicle platoon formation, the present invention proposes a lightweight full-cycle privacy protection vehicle platoon formation method and system.

[0015] The technical solution for achieving the purpose of the present invention is:

[0016] A lightweight privacy-preserving vehicle platooning method is based on a vehicle platooning system, the system comprising a trusted authority (TA), a roadside unit (RSU), a server (CS), and vehicles.

[0017] The trusted authority TA is responsible for generating mapping tables, distributing reputation ciphertexts, distributing keys, and regularly updating vehicle reputation values;

[0018] The server CS is responsible for selecting the lead vehicle and follower vehicles to form a vehicle formation, aggregating feedback reports after the trip, and submitting them to the trusted authority TA;

[0019] Roadside Unit RSU, used to facilitate communication between the vehicle and the trusted authority TA and server CS;

[0020] The method comprises the following steps:

[0021] (1) Pilot vehicle selection:

[0022] The trusted authority (TA) first runs a bucket-based mapping algorithm for reputation values based on a hypergeometric distribution to generate a mapping table. Its purpose is to map the plaintext domain of reputation values to randomly sized intervals, preserving the order of the values. Based on this mapping table and the reputation values from the EncodeORE algorithm, the TA assigns reputation ciphertexts to vehicles through a secure channel.

[0023] The vehicle sends the reputation ciphertext to the nearby roadside unit (RSU). The ciphertext is forwarded by the RSU and submitted to the server (CS). The server (CS) runs a ciphertext comparison algorithm locally to determine the vehicle with the highest reputation value as the pilot vehicle.

[0024] (2) Member vehicle recruitment:

[0025] Vehicles use an improved asymmetric scalar product-preserving encryption algorithm to encrypt their own attribute vectors and send them to nearby RSUs. The RSUs forward the messages to the server, which efficiently performs privacy-preserving matching of vehicle attributes based on vector inner product operations, thereby dividing members into groups.

[0026] (3) Service quality evaluation and reputation value update:

[0027] When the vehicle formation is disbanded at the end of the trip, all members generate feedback reports on the service quality of this trip, encrypt the service quality score using the Paillier algorithm, and submit it to the nearby RSU. The RSU sends the received feedback report to the server CS, which runs the aggregation algorithm and sends the result to the TA. After decryption, the TA queries the local database and updates the reputation value of the pilot vehicle.

[0028] The lightweight privacy-preserving vehicle formation management method proposed in this invention adopts a multi-level encryption mechanism from the selection of the pilot vehicle and the matching of member attributes in the formation phase to the feedback aggregation and reputation update in the formation disbanding phase to ensure the confidentiality and integrity of sensitive data (such as reputation values, attributes, and feedback reports). Through dynamic bucket mapping, random vector perturbation, and lightweight ciphertext calculation, this method significantly reduces the computational and communication overhead while ensuring privacy, solving the core problems of traditional solutions such as reliance on trusted third parties, susceptibility to correlation attacks, and lack of dynamic adaptability. Its technical framework can be widely used in scenarios such as collaborative transportation of logistics fleets, urban intelligent bus formation scheduling, and autonomous driving vehicle group collaboration, providing safe and reliable technical support for the large-scale deployment of intelligent transportation systems.

[0029] The beneficial effects of the method of the present invention are:

[0030] (1) Privacy protection throughout the entire lifecycle. Reputation value privacy is protected through bucket-randomized order-preserving encryption (ORE), ensuring that the server can compare encrypted reputation values without decrypting the specific values. Improved asymmetric scalar product-preserving encryption (ASPE) is combined with high-dimensional expansion and random perturbations of attribute vectors to resist known sample attacks and achieve IND-CPA security in the attribute matching process. Paillier homomorphic encryption is used to aggregate member feedback reports to avoid the leakage of sensitive scores. The above mechanisms work together to cover the entire formation, operation, and disbandment stages, protecting the privacy of vehicle attributes, reputation, and feedback data.

[0031] (2) Lightweight computing and communication optimization. Single-server reputation comparison: A ciphertext comparison algorithm based on order-preserving encryption replaces traditional security protocols that rely on multi-server collaboration through bucket mapping and direct comparison mechanisms in the ciphertext domain, eliminating the complexity and delays brought by cross-server interactions and significantly reducing computing and communication loads. Attribute matching acceleration: Using improved asymmetric scalar product-preserving encryption technology, the encrypted attribute matching process is optimized through high-dimensional vector expansion and random linear transformation, avoiding the complex decryption operations required for traditional plaintext similarity calculations, and achieving efficient and privacy-preserving attribute grouping. Feedback aggregation with low overhead: Combined with Paillier homomorphic encryption technology, feedback score weighted aggregation is completed directly in the ciphertext domain, reducing the communication redundancy of plaintext transmission and repeated encryption and decryption, and achieving efficient and privacy-preserving feedback data processing.

[0032] (3) Dynamic security enhancement. Hypergeometric distribution dynamic bucket mapping: Periodically updates the mapping interval parameters of ORE to resist long-term statistical inference attacks and ensure that reputation values are uncorrelated. Random vector expansion: Introduces high-dimensional spherical random vectors in ASPE encryption, making it impossible for attackers to reversely deduce the original attributes. Hierarchical weight mechanism: Dynamically generates feedback weights based on the vehicle's historical reputation, suppressing malicious scoring interference and reducing the error rate of reputation updates. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 This is a model diagram of the vehicle platooning system of the present invention. DETAILED DESCRIPTION

[0034] The present invention will be further described in detail below with reference to the embodiments and drawings, but the present invention is not limited thereto.

[0035] Example 1

[0036] A lightweight privacy-preserving vehicle platoon formation system, referring to Figure 1 ,The system includes: a trusted authority TA, a roadside unit RSU, a server CS and a vehicle;

[0037] The trusted authority TA is responsible for generating mapping tables, distributing reputation ciphertexts, distributing keys, and regularly updating vehicle reputation values;

[0038] The server CS is responsible for selecting the lead vehicle and follower vehicles to form a vehicle formation, aggregating feedback reports after the trip, and submitting them to the trusted authority TA;

[0039] Roadside Unit RSU is used to facilitate communication between vehicles and trusted authorities TA and servers CS.

[0040] Example 2

[0041] A lightweight privacy-preserving vehicle platoon formation method is based on a vehicle platoon formation system, and the method includes the following steps:

[0042] (1) Pilot vehicle selection:

[0043] The trusted authority (TA) first runs a hypergeometric distributed reputation bucket mapping algorithm to obtain a mapping table. Based on this mapping table and the reputation value of the EncodeORE algorithm, the TA assigns a reputation ciphertext to the vehicle through a secure channel.

[0044] The vehicle sends the reputation ciphertext to the nearby roadside unit (RSU). The ciphertext is forwarded by the RSU and submitted to the server (CS). The server (CS) runs a ciphertext comparison algorithm locally to determine the vehicle with the highest reputation value as the pilot vehicle.

[0045] In the hypergeometric distribution reputation value bucket mapping process, TA first initializes the reputation plaintext domain D, the mapping domain R, and a mapping cache table key_table;

[0046] Then, the mapping algorithm is run to construct a randomized interval mapping table MT from the reputation plaintext domain D to the mapping domain R. This mapping table records the unpredictable mapping of plaintext to ciphertext intervals.

[0047] For example, let D = {1, 2, 3}, R = [1, 10], and m is the plaintext in D. Then m = 1 may be mapped to [1, 4], m = 2 may be mapped to [5, 7], and m = 3 may be mapped to [8, 10]. The mapping algorithm dynamically divides the intervals through hypergeometric distribution sampling (HGD) to ensure the randomness and security of the mapping.

[0048] The algorithm steps are as follows:

[0049] (1.1) Mapping table generation algorithm:

[0050] TA initializes an empty mapping table

[0051] Then traverse the plaintext domain, call the recursive function Mapping(D,R,m,key_table) for each m∈D to calculate the mapping interval of m, and store the result in MT[m], where m is the plaintext in D;

[0052] After the recursion is completed, the constructed MT is returned;

[0053] The recursive function Mapping is divided into the following 5 steps:

[0054] (1.1.1) Parameter preprocessing, calculate the size of D and R: M←|D|, N←|R|;

[0055] M and N represent the size of the plaintext domain and mapping domain input in each recursive function respectively;

[0056] Record boundary offset: d←min(D)-1, r←min(R)-1;

[0057] d is the minimum value of the plaintext interval minus 1, and r is the minimum value of the mapped interval minus 1;

[0058] (1.1.2) Set the recursive termination condition. If M = 1, return the complete interval of R [r+1, r+N-1];

[0059] (1.1.3) Determine the partition point. First calculate the median point of R. Record query cache;

[0060] If r+y exists in key_table, get the corresponding partition point x←key_table(index,2)-d;

[0061] If the cache is not hit, hypergeometric sampling is performed, calling x←HGD(M,N,y) to generate a random partition point, and storing (r+y,d+x) in key_table;

[0062] The hypergeometric distribution sampling x←HGD(M,N,y) means that the size of the plaintext domain M is regarded as the number of good samples, the size of the mapping domain N is regarded as the number of bad samples, and y times of sampling are performed from the total sample without replacement, where x is the number of good samples drawn;

[0063] (1.1.4) Interval partitioning: if m≤d+x, then update the left subdomain D←[d+1,d+x] and the left subinterval R←[r+1,r+y];

[0064] Otherwise, update the right subdomain D←[d+x+1,d+M], right subinterval R←[r+y+1,r+N];

[0065] (1.1.5) Recursively execute the algorithm and return the result of executing the function Mapping(D, R, m, key_table) on the new subdomain.

[0066] The purpose of the entire recursive algorithm is to map a random interval R to a plaintext m. m is in the plaintext domain D. The interval partitioning here essentially uses the randomness of hypergeometric sampling to divide the plaintext domain D and the mapping domain R. The algorithm ensures that after each partition, m is always in the new subdomain D. Recursion is performed using the partitioned subdomains D and R until only m remains in D. At this point, the resulting subdomain R is the random interval corresponding to m.

[0067] Further, after generating the mapping table in step (1.1), the TA assigns an initial reputation value rep to each vehicle, and then assigns reputation ciphertexts to the vehicles based on the EncodeORE algorithm. The specific steps are as follows:

[0068] (1.2) Encoding generation:

[0069] The TA looks up the corresponding domain of rep through the mapping table MT, and selects a random value s in this domain. Subsequently, the TA selects encoding parameters (h, l_1, l_2), and encodes the reputation value in scientific notation as: s = V × h^E, where V = v_1v_2...v_(l_1) and E = e_1e_2...e_(l_2) are both in binary form;

[0070] (1.3) Generating reputation ciphertext:

[0071] Concatenate V and E to get B = v_1v_2...v_(l_1)e_1e_2...e_(l_2). Select a pseudo-random function to encrypt each bit of B. For the i-th bit of B, use the first i - 1 bit values of B as the input of the pseudo-random function to generate a pseudo-random mask, add it to the i-th bit and modulo 3. Finally, obtain the reputation ciphertext E = e_1e_2...e_l and assign it to the corresponding vehicle, where l = l_1 + l_2;

[0072] Further, after receiving the reputation ciphertext sent by the vehicle, the server runs the ciphertext comparison algorithm to select the leading vehicle. For any two reputation ciphertexts E, E', the ciphertext comparison algorithm is specifically:

[0073] Let E = e_1, e_2...e_l, E' = e_1', e_2',...e_l';

[0074] Calculate 〖(e〗_i = e_i') or (e_i' = e_i + 1 mod 3) in ascending order of i;

[0075] If the result is 1, return E < E', otherwise continue to compare. When i = l, return E > E'.

[0076] Through the above method, the server can screen out high-reputation vehicles as leading vehicles without decrypting. Compared with the traditional double-server secure comparison protocol, this method greatly reduces the computational overhead, and effectively resists long-term observation attacks and statistical inferences by periodically updating the mapping interval bucket parameters.

[0077] A lightweight privacy protection method for vehicle formation also includes step (2) member vehicle recruitment:

[0078] The vehicle runs an improved asymmetric scalar product-preserving encryption algorithm, encrypts its own attribute vector and sends it to a nearby RSU. The RSU forwards the message to the server, which performs privacy-preserving matching of vehicle attributes based on the vector inner product operation, thereby dividing member vehicles into groups.

[0079] The attribute vector encryption and attribute ciphertext matching are specifically performed as follows:

[0080] (2.1) Using the improved asymmetric scalar product preserving encryption algorithm to encrypt the attribute vector:

[0081] The vehicle requests the private key sk = (S, M1, M2, Π) from the TA through a secure channel for attribute vector encryption, where S is a binary string, M1 and M2 are two (o+t)-dimensional reversible random matrices, and Π is a random permutation function;

[0082] Each time the attribute vector is encrypted, the o-dimensional attribute vector p1 is first expanded. Specifically,

[0083] First, generate a t-dimensional random vector u1;

[0084] Then normalize it to a unit vector to ensure that its modulus is 1;

[0085] Subsequently, these unit vectors are scaled to a high-dimensional spherical space with a specified radius R. Random vectors are evenly distributed on the sphere, and the Euclidean distance between any two vectors is expressed by Equation 1:

[0086]

[0087] Among them, θ represents the angle between random vectors. As the dimension increases, the average cosine value of the angle gradually approaches 0, which simplifies the Euclidean distance formula to

[0088] Next, the random vector and the attribute vector are concatenated to obtain p′1, and a random linear transformation is performed on it. The extended vector is scaled and perturbed using a random number r1 to generate p″1=r1·(-2p′1,|p′1| 2 -w 2 -d 2 ,1), where w is the preset similarity threshold, p″1 is randomly permuted to obtain P1, and the key splitting technology is used to split the vector P1 into P′1 and P″1, which are encrypted using matrices M1 and M2 respectively to obtain double ciphertext and At this point, the encryption algorithm is executed and each vehicle submits the ciphertext to the server CS;

[0089] (2.2) Attribute ciphertext matching:

[0090] The server CS calculates the inner product of the ciphertext between two vehicles a and b Determine whether the attributes of the vehicles are similar and achieve privacy-preserving attribute matching. Specifically, if the inner product is less than 0, the Euclidean distance of the attribute vectors is less than the threshold w, and the vehicles are matched; otherwise, the vehicles are not matched.

[0091] By running the matching algorithm, CS can eventually create groups for vehicles without knowing the specific attributes of the vehicles.

[0092] A lightweight privacy-preserving vehicle platoon formation method further includes step (3) service quality evaluation and reputation value update:

[0093] At the end of the trip, when the convoy disbands, all members generate feedback reports on the service quality of the trip. They encrypt the service quality scores using the Paillier algorithm and submit them to the nearby RSUs. The RSUs send the feedback reports to the server CS, which runs the aggregation algorithm and sends the results to the TA. The TA decrypts the data and queries the local database to update the reputation value of the pilot vehicle.

[0094] The feedback report generation process, i.e., the steps of service quality scoring and Paillier encryption are as follows:

[0095] (3.1) Feedback report generation:

[0096] TA initializes the Paillier cryptosystem, selects two large prime numbers p and q, and calculates the modulus n = p·q and λ = lcm(p-1,q-1), and then randomly selects the generator And through the auxiliary function Compute modular inverse Finally, the public key (n, g) and private key (λ, μ) are formed;

[0097] Each member vehicle evaluates the service quality of the pilot vehicle, denoted as SRS, and the vehicle V i Select random number Using the Paillier encryption algorithm, we get And send to server CS;

[0098] Furthermore, the server CS executes a ciphertext aggregation algorithm to aggregate the feedback report ciphertexts of all vehicles into a new ciphertext with weights;

[0099] (3.2) Feedback report aggregation:

[0100] The vehicle submits its own reputation ciphertext, and the server CS runs the ciphertext comparison algorithm to rank the vehicle reputation values from high to low to obtain an ordered list L, and then generates a dynamic weight Rank based on the vehicle reputation ranking i , the weight distribution method is:

[0101] Assume there are Z vehicles in total, then the weight of the i-th vehicle in the list L is Li. For example, if there are 4 members, and the reputation values are ranked from high to low as follows {member 2, member 3, member 4, member 1}, then the weight of each member is: {member 1: 1 member 2: 4, member 3: 3, member 4: 2}. The service quality ciphertext index operation is performed through formula 2 to achieve weighted aggregation of service quality scores:

[0102]

[0103] The ciphertext comparison algorithm run by the server CS is the same as the reputation ciphertext comparison algorithm;

[0104] Next, CS sends F to TA, and TA calculates the reputation update value using the Paillier private key (λ, μ) securely stored locally, as shown in Equation 3:

[0105]

[0106] Wherein, function L(x)=x-1 / n;

[0107] Finally, the exponential smoothing algorithm RV is used New =α·RV Old +(1-α)·e avRV Update the reputation value. In this algorithm, the old reputation value of the vehicle is represented as RV Old , α is a weight parameter, which is used to adjust the ratio between the old reputation value, the new reputation value and the reputation update value. After the new reputation value is updated, it marks the end of a vehicle formation management cycle. The system will automatically iterate and execute the above complete process to realize the periodic privacy protection vehicle formation.

[0108] In response to the privacy leakage risks and computational efficiency bottlenecks of existing solutions in reputation management, attribute matching, and vehicle formation full life cycle management, the present invention designs a privacy protection framework covering the formation, dynamic operation, and disbanding stages of formations. The lightweight privacy-protected vehicle formation method of the present invention achieves full life cycle protection through multi-dimensional encryption technology: sequential revealing encryption is used to perform bucket-by-bucket random mapping and ciphertext comparison on reputation values, so that the cloud server can select a high-reputation leading vehicle without decrypting the specific value; the asymmetric scalar product is improved to maintain encryption, and the security of attribute matching is enhanced through random vector expansion, permutation operations, and matrix partitioning. At the same time, the security issue of feedback report leakage is solved by combining homomorphic encryption technology. The method of the present invention realizes the secure matching of vehicle attributes, secure comparison of reputation values, and feedback privacy aggregation, solving the problems of attribute leakage, reputation exposure, and feedback tracking in existing solutions. At the same time, the system overhead is reduced through lightweight cryptographic design to meet the real-time requirements of large-scale vehicle networks.

Claims

1. A lightweight privacy-preserving vehicle platoon formation method based on a vehicle platoon formation system, the system comprising: Trusted authority TA, roadside unit RSU, server CS and vehicle; The trusted authority TA is responsible for generating mapping tables, distributing reputation ciphertexts, distributing keys, and regularly updating vehicle reputation values; The server CS is responsible for selecting the lead vehicle and follower vehicles to form a vehicle formation, aggregating feedback reports after the trip, and submitting them to the trusted authority TA; Roadside Unit RSU, used to facilitate communication between the vehicle and the trusted authority TA and server CS; Characterized in that the method comprises the following steps: (1) Pilot vehicle selection: The trusted authority (TA) first runs a hypergeometric distributed reputation bucket mapping algorithm to obtain a mapping table. Based on this mapping table and the reputation value of the EncodeORE algorithm, the TA assigns a reputation ciphertext to the vehicle through a secure channel. The vehicle sends the reputation ciphertext to the nearby roadside unit (RSU). The ciphertext is forwarded by the RSU and submitted to the server (CS). The server (CS) runs a ciphertext comparison algorithm locally to determine the vehicle with the highest reputation value as the pilot vehicle. (2) Member vehicle recruitment: The vehicle runs an improved asymmetric scalar product-preserving encryption algorithm, encrypts its own attribute vector and sends it to a nearby RSU. The RSU forwards the message to the server, which performs privacy-preserving matching of vehicle attributes based on the vector inner product operation, thereby dividing member vehicles into groups. (3) Service quality evaluation and reputation value update: When the vehicle formation is disbanded at the end of the trip, all members generate feedback reports on the service quality of this trip, encrypt the service quality score using the Paillier algorithm, and submit it to the nearby RSU. The RSU sends the received feedback report to the server CS, which runs the aggregation algorithm and sends the result to the TA. After decryption, the TA queries the local database and updates the reputation value of the pilot vehicle.

2. The lightweight privacy-preserving vehicle platooning method according to claim 1, characterized in that: In the hypergeometric distribution reputation value bucket mapping process described in step (1), TA first initializes the reputation plaintext domain D, the mapping domain R, and a mapping cache table key_table; Then, the mapping algorithm is run to construct a randomized interval mapping table MT from the reputation plaintext domain D to the mapping domain R. This mapping table records the unpredictable mapping of plaintext to ciphertext intervals. The algorithm steps are as follows: (1.1) Mapping table generation algorithm: TA initializes an empty mapping table Then traverse the plaintext domain, call the recursive function Mapping(D,R,m,key_table) for each m∈D to calculate the mapping interval of m, and store the result in MT[m], where m is the plaintext in D; After the recursion is completed, the constructed MT is returned; The recursive function Mapping is divided into the following 5 steps: (1.1.1) Parameter preprocessing, calculate the size of D and R: M←|D|, N←|R|; M and N represent the size of the plaintext domain and mapping domain input in each recursive function respectively; Record boundary offset: d←min(D)-1, r←min(R)-1; d is the minimum value of the plaintext interval minus 1, and r is the minimum value of the mapped interval minus 1; (1.1.2) Set the recursive termination condition. If M = 1, return the complete interval of R [r+1, r+N-1]; (1.1.3) Determine the partition point. First calculate the median point of R. Record query cache; If r+y exists in key_table, get the corresponding partition point x←key_table(index,2)-d; If the cache is not hit, hypergeometric sampling is performed, and the function x←HGD(M,N,y) is called to generate a random partitioning point, and (r+y,d+x) is stored in key_table; The hypergeometric distribution sampling x←HGD(M,N,y) means that the size M of the plaintext domain is regarded as the number of good samples, the size N of the mapping domain is regarded as the number of bad samples, y times are drawn without replacement from the total samples, and x is the number of good samples drawn; (1.1.4) Interval partitioning, if m≤d+x, then update the left subdomain D←[d+1,d+x], and the left subinterval R←[r+1,r+y]; Otherwise, update the right subdomain D←[d+x+1,d+M], and the right subinterval R←[r+y+1,r+N]; (1.1.5) Recursively execute the algorithm, and return the execution result of the function Mapping(D,R,m,key_table) on the new subdomain.

3. The lightweight privacy-preserving vehicle platooning method according to claim 2, characterized in that: After generating the mapping table in step (1.1), the TA assigns an initial reputation value rep to each vehicle, and then assigns reputation ciphertexts to the vehicles based on the EncodeORE algorithm. The specific steps are as follows: (1.2) Encoding generation: The TA looks up the corresponding domain of rep through the mapping table MT, and selects a random value s in this domain. Subsequently, the TA selects encoding parameters (h,l_1,l_2), and encodes the reputation value in scientific notation as: s = V×h^E, where V = v_1v_2...v_(l_1), E = e_1e_2...e_(l_2) are both in binary form; (1.3) Generating reputation ciphertext: Concatenate V and E to get B = v_1v_2...v_(l_1)e_1e_2...e_(l_2), select a pseudo-random function, encrypt each bit of B. For the i-th bit of B, use the first i-1 bit values of B as the input of the pseudo-random function to generate a pseudo-random mask, add it to the i-th bit and modulo 3. Finally, obtain the reputation ciphertext E = e_1e_2...e_l, and assign it to the corresponding vehicle, where l = l_1 + l_2; After the server obtains the reputation ciphertext sent by the vehicle, it runs the ciphertext comparison algorithm to select the leading vehicle. For any two reputation ciphertexts E,E’, the reputation ciphertext comparison algorithm is specifically: Let E = e_1,e_2...e_l, E’ = e_1',e_2',...e_l'; Calculate 〖(e〗_i = e_i')or(e_i' = e_i+1mod3) in ascending order of i; If the result is 1, return E < E’, otherwise continue to compare. When i = l, return E > E’.

4. The lightweight privacy-preserving vehicle platooning method according to claim 1, characterized in that: The attribute vector encryption and attribute ciphertext matching described in step (2) are specifically as follows: (2.1) Encrypt the attribute vector using an improved asymmetric scalar product preserving encryption algorithm: The vehicle requests a private key sk = (S,M1,M2,Π) for attribute vector encryption from the TA through a secure channel, where S is a binary string, M1,M2 are two (o+t)-dimensional invertible random matrices, and Π is a random permutation function; Each time the attribute vector is encrypted, the o-dimensional attribute vector p1 is first expanded. Specifically, First, generate a t-dimensional random vector u1; Then normalize it to a unit vector to ensure that its modulus is 1; Subsequently, these unit vectors are scaled to a high-dimensional spherical space with a specified radius R. Random vectors are evenly distributed on the sphere, and the Euclidean distance between any two vectors is expressed by Equation 1: Among them, θ represents the angle between random vectors. As the dimension increases, the average cosine value of the angle gradually approaches 0, which simplifies the Euclidean distance formula to Next, the random vector and the attribute vector are concatenated to obtain p′1, and a random linear transformation is performed on it. The extended vector is scaled and perturbed using a random number r1 to generate p″1=r1·(-2p′1,|p′1| 2 -w 2 -d 2 ,1), where w is the preset similarity threshold, p″1 is randomly permuted to obtain P1, and the key splitting technique is used to split the vector P1 into P1 ′ and P1″, respectively encrypt them using matrices M1 and M2 to obtain double ciphertext and At this point, the encryption algorithm is executed and each vehicle submits the ciphertext to the server CS; (2.2) Attribute ciphertext matching: The server CS calculates the inner product of the ciphertext between two vehicles a and b Determine whether the attributes of the vehicles are similar and achieve privacy-preserving attribute matching. Specifically, if the inner product is less than 0, the Euclidean distance of the attribute vectors is less than the threshold w, and the vehicles are matched; otherwise, the vehicles are not matched. By running the matching algorithm, CS can eventually create groups for vehicles without knowing the specific attributes of the vehicles.

5. The lightweight privacy-preserving vehicle platooning method according to claim 1, characterized in that: The feedback report generation process described in step (3), i.e., the steps of service quality scoring and Paillier encryption, is as follows: (3.1) Feedback report generation: TA initializes the Paillier cryptosystem, selects two large prime numbers p and q, and calculates the modulus n = p·q and λ = lcm(p-1,q-1), and then randomly selects the generator And through the auxiliary function Calculate the modular inverse μ=[L(g λ modn 2 )] -1 modn, ultimately forming the public key (n, g) and private key (λ, μ); Each member vehicle evaluates the service quality of the pilot vehicle, denoted as SRS, and the vehicle V i Select random number Using the Paillier encryption algorithm, we get And send to server CS; The server CS executes the ciphertext aggregation algorithm to aggregate the feedback report ciphertexts of all vehicles into a new ciphertext with weights; (3.2) Feedback report aggregation: The vehicle submits its own reputation ciphertext, and the server CS runs the ciphertext comparison algorithm to rank the vehicle reputation values from high to low to obtain an ordered list L, and then generates a dynamic weight Rank based on the vehicle reputation ranking i , the weight distribution method is: Assume there are Z vehicles in total, then the weight of the i-th vehicle in the list L is Li, and the service quality ciphertext index operation is performed through Equation 2 to achieve weighted aggregation of service quality scores: The ciphertext comparison algorithm run by the server CS is the same as the reputation ciphertext comparison algorithm; Next, CS sends F to TA, and TA calculates the reputation update value using the Paillier private key (λ, μ) securely stored locally, as shown in Equation 3: Wherein, function L(x)=x-1 / n; Finally, the exponential smoothing algorithm RV is used New =α·RV Old +(1-α)·e avRV Update the reputation value. In this algorithm, the old reputation value of the vehicle is represented as RV Old , α is a weight parameter, which is used to adjust the ratio between the old reputation value, the new reputation value and the reputation update value. After the new reputation value is updated, it marks the end of a vehicle formation management cycle. The system will automatically iterate and execute the above complete process to realize the periodic privacy protection vehicle formation.