Cross-domain security multi-party computing method, system and device based on Internet of Vehicles and medium
By introducing a three-layer secure computing framework into the Internet of Vehicles, dynamically adjusting the privacy protection level and optimizing data transmission, the problems of inflexible privacy protection strategies and isolated modules in existing technologies are solved, and efficient and secure cross-domain data processing is achieved.
Patent Information
- Application Number
- CN202510962119.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-10-31
AI Technical Summary
Existing technologies lack flexible privacy protection strategies in the Internet of Vehicles, resulting in low computational efficiency or waste of resources. Furthermore, edge processing, secure multi-party computation, and decentralized trust mechanisms are designed in isolation, making it difficult to cope with complex cross-domain attacks and resulting in insufficient overall security.
It adopts a three-layer secure computing framework, including an edge-aware layer, an SMPC coordination layer, and a blockchain notarization layer. Through a trusted execution environment, configurable SMPC, and lightweight blockchain, it dynamically adjusts the privacy protection level, performs data processing and joint computation, and optimizes data transmission through zero-knowledge proofs and geographic sharding.
It achieves a dynamic balance between privacy and efficiency while ensuring data security, improves the security and computational efficiency of cross-domain data processing, adapts to the dynamic changes of the V2X environment, and enhances the overall security and scalability of the system.
Smart Images

Figure CN120880648A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle network technology, and in particular to a cross-domain secure multi-party computation method, system, device and medium based on vehicle network. Background Technology
[0002] In modern intelligent transportation systems, Vehicle-to-Everything (V2X) communication technology significantly improves traffic efficiency and driving safety by enabling data interaction between vehicles, road infrastructure, and cloud platforms. However, existing technologies employ the same privacy protection strategies across different application scenarios. This leads to low computational efficiency in scenarios with high privacy requirements and resource waste in scenarios with low privacy requirements. Furthermore, existing technologies typically treat edge processing, secure multi-party computation, and decentralized trust mechanisms as independent modules, lacking a unified framework design. This results in insufficient overall system security, making it difficult to cope with complex cross-domain attacks.
[0003] Therefore, how to improve the security and computational efficiency of cross-domain data processing is a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] This application provides a cross-domain secure multi-party computation method, system, device, and medium based on the Internet of Vehicles (IoV) to improve the security and computational efficiency of cross-domain data processing.
[0005] In a first aspect, this application provides a cross-domain secure multi-party computation method based on the Internet of Vehicles (IoV), wherein the cross-domain secure multi-party computation method is applied to the edge perception layer, and includes:
[0006] Raw data is collected from the vehicle terminal;
[0007] Determine the current privacy protection level corresponding to the original data;
[0008] The original data is processed using the current privacy protection level to generate processed original data;
[0009] The processed raw data is encrypted using a trusted execution environment to generate the target data;
[0010] The target data is sent to the SMPC coordination layer, so that the SMPC coordination layer can perform joint calculations on the target data using the SMPC protocol and the current privacy protection level, and upload the joint calculation results to the blockchain notary layer. After the blockchain notary layer verifies the joint calculation results, they are recorded in the blockchain system.
[0011] Optionally, after collecting raw data from the vehicle terminal, the process further includes:
[0012] Extract vehicle location information and time information from the raw data;
[0013] The vehicle location information, the time information, and the B-spline interpolation algorithm are used to correct the vehicle location information and time information of the original data.
[0014] Optionally, determining the current privacy protection level corresponding to the original data includes:
[0015] Determine the current application scenario of the vehicle terminal;
[0016] Determine the data type of the original data;
[0017] The current privacy protection level is determined based on the current application scenario and the data type.
[0018] Optionally, processing the original data using the current privacy protection level to generate processed original data includes:
[0019] Determine the target processing operation corresponding to the current privacy protection level; wherein the target processing operation includes at least one of: SMPC protocol processing operation, double masking processing operation, and differential privacy processing operation;
[0020] The original data is processed through the target processing operation to generate processed original data.
[0021] Optionally, if the target processing operation is a double masking operation, then the original data is processed by the target processing operation to generate processed original data, including:
[0022] Obtain the first random mask and the second random mask;
[0023] The first random mask and the second random mask are added to the original data to obtain the processed original data.
[0024] Optionally, sending the target data to the SMPC coordination layer includes:
[0025] The target SMPC coordination node is determined from the SMPC coordination layer; wherein the current edge device and the target SMPC coordination node belong to the same geographical region;
[0026] Send the target data of each task batch to the target SMPC coordination node;
[0027] Accordingly, the SMPC coordination layer uploads the joint computation results to the blockchain notary layer by: the target SMPC coordination node determining the target blockchain node from the blockchain notary layer and uploading the joint computation results to the target blockchain node; the target SMPC coordination node and the target blockchain node belong to the same geographical region.
[0028] Secondly, this application provides a cross-domain secure multi-party computation method based on the Internet of Vehicles (IoV), the method being applied to the SMPC coordination layer, the method comprising:
[0029] The system receives target data sent by the edge perception layer; wherein the edge perception layer collects raw data from the vehicle terminal, determines the current privacy protection level corresponding to the raw data, processes the raw data using the current privacy protection level, and encrypts the processed raw data through a trusted execution environment to generate the target data.
[0030] Using the SMPC protocol and the current privacy protection level, joint computation is performed on the target data to generate joint computation results;
[0031] The joint calculation result is uploaded to the blockchain notary layer, and after the joint calculation result is verified by the blockchain notary layer, it is recorded in the blockchain system.
[0032] Thirdly, this application provides a cross-domain secure multi-party computation system based on the Internet of Vehicles, including:
[0033] The edge awareness layer is used to collect raw data from the vehicle terminal, determine the current privacy protection level corresponding to the raw data, process the raw data using the current privacy protection level, encrypt the processed raw data through a trusted execution environment, generate target data, and send the target data to the SMPC coordination layer.
[0034] The SMPC coordination layer is used to receive the target data, perform joint computation on the target data using the SMPC protocol and the current privacy protection level, generate joint computation results, and upload the joint computation results to the blockchain notary layer.
[0035] The blockchain notary layer is used to verify the joint calculation result and record the verified joint calculation result to the blockchain system.
[0036] Fourthly, this application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0037] Memory, used to store computer programs;
[0038] When a processor executes a program stored in memory, it implements the steps of the cross-domain secure multi-party computation method described above.
[0039] Fifthly, this application provides a computer storage medium storing computer-executable instructions for use in the above-described cross-domain secure multi-party computation method steps.
[0040] Compared with the prior art, the technical solutions provided in this application have the following advantages: This application discloses a cross-domain secure multi-party computation method, system, device, and medium based on the Internet of Vehicles; in this solution, the edge perception layer collects raw data from the vehicle terminal and processes the raw data according to the current privacy protection level, thereby dynamically balancing privacy and efficiency through the current privacy protection level, and improving computational efficiency while ensuring data security; this application can encrypt the processed raw data through a trusted execution environment to ensure the security of the data processing process and the raw data; furthermore, the SMPC coordination layer performs joint computation on the target data through the SMPC protocol and the current privacy protection level, and uploads the joint computation result to the blockchain notary layer, which verifies and records it in the blockchain system, further ensuring the integrity and immutability of the joint computation result. Attached Figure Description
[0041] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0043] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.
[0044] Figure 1 A schematic diagram of a cross-domain secure multi-party computation system architecture based on the Internet of Vehicles provided in this application embodiment;
[0045] Figure 2 A schematic diagram of a system framework provided for an embodiment of this application;
[0046] Figure 3A flowchart of a cross-domain secure multi-party computation method based on the Internet of Vehicles provided in this application embodiment;
[0047] Figure 4 The system framework interaction flowchart provided in the embodiments of this application;
[0048] Figure 5 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. Detailed Implementation
[0049] Vehicle-to-everything (V2X) communication technology significantly improves traffic efficiency and driving safety by enabling data interaction between vehicles, road infrastructure, and cloud platforms. However, this cross-domain collaboration brings serious privacy and security challenges. This paper describes in detail the existing technologies in V2X communication across three areas: privacy-preserving computing, decentralized trust mechanisms, and edge-cloud collaborative architecture, and analyzes their technical shortcomings.
[0050] I. Privacy-Preserving Computation: Privacy-preserving computing technology aims to achieve data sharing and collaborative computing without disclosing the original data. It mainly includes the following technologies:
[0051] 1.1 Secure Multi-Party Computation (SMPC):
[0052] SMPC is a cryptographic protocol that allows multiple participants to collaboratively compute a function without revealing their individual inputs. Its core mechanisms include secret sharing and homomorphic encryption. In secret sharing, data is divided into multiple pieces and distributed to the participants; the result can only be recovered through collaboration. In homomorphic encryption, encrypted data can be directly computed, and decryption yields the correct result.
[0053] In V2X systems, Smart Traffic Flow (SMPC) is commonly used for scenarios such as traffic flow prediction and accident warning. For example, multiple vehicles can share speed and location data through SMPC to calculate regional traffic density without exposing the precise information of individual vehicles. Existing practical safety aggregation schemes achieve parameter sharing in distributed learning through optimization combined with SMPC, supporting multi-party joint modeling.
[0054] 1.2 Differential Privacy (DP):
[0055] Differential privacy protects privacy by adding carefully designed noise to the data, ensuring that the impact of a single data point on the computational result is negligible. Its privacy protection strength is controlled by a privacy budget parameter ε; the smaller ε is, the stronger the privacy protection, but the lower the data accuracy. Differential privacy is used in V2X to protect the privacy of shared data, for example, by adding noise in traffic data analysis to prevent reverse inference of individual vehicle information.
[0056] 1.3 Combination of Secure Multi-Party Computation (SMPC) and Differential Privacy (DP):
[0057] Combining SMPC with DP can improve computational efficiency while preserving privacy. For example, researchers have proposed a scheme combining SMPC and DP for traffic prediction tasks, where SMPC ensures the security of multi-party joint modeling, and DP protects the privacy of the output results by adding noise. This combination demonstrates good privacy protection in distributed environments.
[0058] 1.4 Application Examples:
[0059] SMPC and DP have made progress in V2X applications. For example, some research schemes support parameter sharing in distributed learning, and others are used for traffic flow prediction. However, these schemes are usually designed for static scenarios and do not fully consider the dynamic characteristics of the V2X environment.
[0060] 1.5 Technical Disadvantages:
[0061] Lack of flexibility: SMPC and DP typically employ fixed privacy protection strategies, making it difficult to dynamically adjust the trade-off between privacy and efficiency according to scenario requirements. For example, the SMPC-DP combination does not offer configurable privacy-efficiency options, limiting its applicability in different V2X scenarios (such as real-time accident warnings or long-term traffic planning).
[0062] Unoptimized dynamic environments: Existing SMPC protocols struggle to maintain consistency and security in dynamic V2X environments. High-speed vehicle movement and network fluctuations can cause protocol interruptions or delays, impacting real-time performance.
[0063] Coarse-grained privacy protection: Existing solutions cannot precisely control the granularity of privacy protection. For example, noise addition by DP may apply the same privacy budget to all data types, failing to distinguish between highly sensitive data (such as location) and low-sensitivity data (such as speed).
[0064] II. Decentralized Trust Mechanism: The decentralized trust mechanism provides a verifiable trust foundation for the V2X system through blockchain technology, mainly including the following technologies:
[0065] 2.1. A blockchain-based federated learning framework:
[0066] Federated learning allows multiple parties to collaboratively train machine learning models without sharing raw data, while blockchain is used to verify the integrity of model parameters. For example, BFRT (Blockchain-enhanced Federated Learning for Real-Time Trust) uses blockchain to record parameter updates during the federated learning process, ensuring traceability and security of the training process. IoV-SFL (Internet of Vehicles-Secure Federated Learning) focuses on secure federated learning in V2X environments, using blockchain to verify model parameters and prevent malicious actors from tampering with data. These frameworks typically employ lightweight consensus mechanisms to adapt to resource-constrained V2X environments, such as Practical Byzantine Fault Tolerance (PBFT).
[0067] 2.2 Crowdsourced Verification Blockchain System:
[0068] Solutions like Smartverse enhance data credibility through crowdsourced verification mechanisms. Vehicles and roadside units, acting as nodes, participate in verifying the authenticity of shared data, using a simple voting mechanism (such as majority voting) to determine data credibility. This mechanism is suitable for verifying traffic events or road condition information.
[0069] 2.3 The combination of blockchain and edge computing:
[0070] BEVEC (Blockchain-Enabled Vehicular Edge Computing) and ChainFL (Chain-based Federated Learning) combine blockchain with edge computing to support V2X services by running lightweight consensus protocols on edge devices. For example, BEVEC proposes a utility-based consensus protocol that prioritizes high-priority V2X tasks, such as accident warnings.
[0071] 2.4 Technical disadvantages:
[0072] Limitations of focus: Existing blockchain solutions primarily verify model parameters or transaction records, rather than the integrity of raw sensor data. For example, BFRT and IoV-SFL cannot ensure the authenticity of vehicle sensor data, posing a risk of data forgery.
[0073] Lack of cross-layer security analysis: These solutions do not incorporate holistic security design across the edge, compute, and trust layers. For example, BEVEC failed to analyze potential vulnerabilities between the blockchain and the SMPC compute layer, which could lead to cross-layer attacks.
[0074] Performance limitations: Blockchain consensus mechanisms suffer from latency issues in high-concurrency V2X scenarios, especially on resource-constrained edge devices, where lightweight consensus protocols still struggle to meet real-time requirements.
[0075] III. Edge Cloud Collaboration Architecture: The edge cloud collaboration architecture optimizes the resource utilization and real-time performance of V2X systems by distributing computing tasks to edge devices and the cloud. It mainly includes the following technologies:
[0076] 3.1 ADMM (Alternating Direction Method of Multipliers) - Accelerating Model Predictive Control:
[0077] Model Predictive Control (MPC) is an optimization control method that optimizes control inputs by predicting the future state of the system. One research proposed an MPC scheme based on the Alternating Direction Multiplier Method (ADMM) to accelerate the computation of single-vehicle trajectory tracking. ADMM significantly reduces computational complexity by decomposing the optimization problem into multiple subproblems, making it suitable for real-time control tasks.
[0078] 3.2 EC-Drive:
[0079] EC-Drive (Edge Cloud Drive) is an edge cloud collaboration framework that uses drift detection to determine when to offload computing tasks from edge devices to the cloud. Drift detection dynamically adjusts resource allocation based on changes in data distribution, optimizing the execution efficiency of V2X tasks.
[0080] 3.3 AIGC Architecture:
[0081] The AIGC (Artificial Intelligence Generated Content) architecture proposes a three-layer cloud-edge-device collaboration model that supports adaptive resource allocation. Edge devices handle real-time tasks, the cloud handles complex computations, and terminal devices (such as vehicles) provide data input. This architecture optimizes task allocation through a dynamic scheduling algorithm to adapt to the dynamic changes in the V2X environment.
[0082] 3.4 Technical Disadvantages
[0083] Lack of formal privacy guarantees: These architectures do not provide mathematically provable privacy protection mechanisms. For example, EC-Drive lacks encryption protection for data transmission from the edge to the cloud, posing a risk of data breaches.
[0084] Insufficient integration: The edge and cloud modules are designed in isolation, lacking deep integration with SMPC or blockchain. For example, the AIGC architecture does not provide privacy protection mechanisms, limiting its application in scenarios with high privacy requirements.
[0085] Poor dynamic adaptability: Existing solutions struggle to adapt to dynamic changes in the V2X environment. For example, ADMM-MPC only optimizes single-vehicle scenarios and does not extend to multi-party collaboration, resulting in limited applicability in complex V2X scenarios.
[0086] The above analysis of the existing technology reveals the following technical problems:
[0087] 1. Lack of flexibility in privacy settings: The inability to dynamically adjust the level of privacy protection results in insufficient efficiency or privacy protection.
[0088] 2. Isolated component design: Modules such as edge processing, SMPC and blockchain are designed independently, lacking overall integration.
[0089] 3. Static resource allocation: unable to adapt to dynamic changes in the V2X environment, such as vehicle movement or network fluctuations.
[0090] 4. Insufficient inter-layer security integration: Failed to provide end-to-end security protection from data collection to result verification.
[0091] As can be seen, the aforementioned technical problems in existing solutions limit the scalability, privacy protection capabilities, and computational efficiency of V2X networks, necessitating a comprehensive and adaptable solution. Therefore, this application discloses a cross-domain secure multi-party computation method, system, device, and medium based on vehicle-to-everything (V2X) networks. This solution integrates a three-layer framework of a trusted execution environment, configurable SMPC, and lightweight blockchain, aiming to solve the aforementioned technical problems and improve the security and computational efficiency of cross-domain data processing.
[0092] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0093] The following disclosure provides numerous different embodiments or examples for implementing various structures of the invention. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of the invention. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.
[0094] See Figure 1 This is a schematic diagram of a cross-domain secure multi-party computation system based on the Internet of Vehicles (IoV) provided in an embodiment of this application. The system includes:
[0095] Edge awareness layer 11 is used to collect raw data from vehicle terminals, determine the current privacy protection level corresponding to the raw data, process the raw data using the current privacy protection level, encrypt the processed raw data through a trusted execution environment, generate target data, and send the target data to the SMPC coordination layer.
[0096] SMPC Coordination Layer 12 is used to receive target data, perform joint computation on the target data using the SMPC protocol and the current privacy protection level, generate joint computation results, and upload the joint computation results to the blockchain notary layer;
[0097] Blockchain notary layer 13 is used to verify the joint computation results and record the verified joint computation results to the blockchain system.
[0098] In this application, the cross-domain secure multi-party computation system mainly comprises: an Edge Perception Layer, an SMPC Coordination Layer, and a Blockchain Notarization Layer. The Edge Perception Layer is responsible for secure data collection and preliminary processing on edge devices, utilizing Trusted Execution Environments (TEEs) to provide hardware-level trust assurance. The SMPC Coordination Layer manages secure multi-party computation, supports configurable privacy modes, and ensures joint computation without disclosing original data. The Blockchain Notarization Layer provides a decentralized trust mechanism, ensuring data integrity and immutability through the blockchain.
[0099] See Figure 2The figure illustrates a system framework provided in this application embodiment. As shown, the edge perception layer (A) collects raw data from the vehicle terminal, encrypts and processes it using TEEs, and uploads the processed target data to the SMPC coordination layer (B). Multiple participants perform joint computation via the SMPC protocol to generate a joint computation result, which is then uploaded to the blockchain notary layer (C). The joint computation result is recorded on the blockchain to ensure data integrity and trust. The data flow is: edge perception layer (A) → SMPC coordination layer (B) → blockchain notary layer (C). The joint computation result recorded on the blockchain can be accessed by the cloud platform or other participants.
[0100] In existing solutions, edge processing, secure multi-party computation, and decentralized trust mechanisms (such as blockchain) are usually treated as independent modules, lacking a unified framework design, resulting in insufficient overall system security and difficulty in dealing with complex cross-domain attacks. In this system, a three-layer secure computation framework is proposed. This solution seamlessly integrates the edge awareness layer, SMPC coordination layer, and blockchain notarization layer to form a unified security model. Furthermore, through Trusted Execution Environments (TEEs), Configurable Secure Multi-Party Computation (SMPC), and a lightweight blockchain mechanism, the security and privacy challenges in V2X communication are addressed.
[0101] See Figure 3 The flowchart below illustrates a cross-domain secure multi-party computation method based on the Internet of Vehicles (IoV) as provided in this application embodiment. This cross-domain secure multi-party computation method is applied to the edge perception layer and includes:
[0102] S101. Collect raw data from the vehicle terminal;
[0103] In this embodiment, the cross-domain secure multi-party computation method is applied to the edge perception layer, which is the foundation of this system framework and includes multiple edge devices. Each edge device collects and processes data using the cross-domain secure multi-party computation method described in this application. The edge device currently collecting and processing the raw data is referred to as the current edge device. This edge device can be an on-board unit, a roadside unit, etc., and is not specifically limited here. The type of raw data collected from the vehicle terminal can be set according to actual needs; for example, the raw data may include vehicle speed, acceleration, location, etc., and is not specifically limited here.
[0104] S102. Determine the current privacy protection level corresponding to the original data;
[0105] In existing solutions, V2X systems lack flexible privacy protection configurations on edge devices and cannot dynamically adjust privacy protection levels according to application scenarios. However, in this application, the SMPC privacy mode can be configured according to actual needs. This privacy mode includes multiple privacy protection levels to meet the privacy requirements of different scenarios. Therefore, after collecting raw data, this application needs to dynamically adjust the current privacy protection level based on factors such as application scenario and data type. For example, this application can set privacy protection levels including: no_privacy (no privacy protection), dp_only (basic protection), and high_privacy (high privacy protection). The no_privacy mode is suitable for low-sensitivity data, while the high_privacy mode is used for high-privacy scenarios. If the current vehicle terminal is in an urban area, which is a high-privacy scenario, the current privacy protection level is set to high_privacy; if the current vehicle terminal is on a highway, which is a low-privacy scenario, the current privacy protection level is set to no_privacy.
[0106] S103. Process the raw data using the current privacy protection level to generate processed raw data;
[0107] After determining the current privacy protection level, this application can process the original data based on the current privacy protection level to generate processed original data. In this application, different processing methods can be selected according to the current privacy protection level. For example, if the current privacy protection level is low, the data can be processed using the original privacy protection methods of the SMPC system, such as secret sharing mechanisms, homomorphic encryption mechanisms, etc.; if the current privacy protection level is high, the SMPC system can be combined with differential privacy technology to perform privacy protection processing on the original data.
[0108] S104. Encrypt the processed raw data using a trusted execution environment to generate target data;
[0109] It should be noted that each edge device in this application processes the raw data through a trusted execution environment. The trusted execution environment utilizes a hardware-level security environment (such as Intel SGX) to provide an isolated execution environment, ensuring that the data is not tampered with or leaked during the processing. TEEs protect sensitive data from external attacks through hardware root trust.
[0110] Furthermore, to ensure the security of the original data, this application uses encryption algorithms to encrypt the processed original data to generate the target data before sending the target data to the SMPC coordination layer. The encryption algorithms used in this application include SM4 (symmetric encryption algorithm) or AES-GCM (Advanced Encryption Standard-Galois / Counter Mode, an encryption algorithm used for data encryption and authentication), etc., to encrypt and protect the integrity of the collected original data. Among them, SM4 is suitable for domestic scenarios, while AES-GCM provides international standard compatibility.
[0111] S105. Send the target data to the SMPC coordination layer so that the SMPC coordination layer can use the SMPC protocol and the current privacy protection level to perform joint calculations on the target data, and upload the joint calculation results to the blockchain notary layer. After the blockchain notary layer verifies the joint calculation results, they are recorded in the blockchain system.
[0112] In this application, the SMPC coordination layer is responsible for managing multi-party secure computation, ensuring joint computation without disclosing the original data. The SMPC coordination layer includes multiple SMPC coordination nodes. After receiving the target data sent by the current edge device, the SMPC coordination node first decrypts the target data using the same encryption algorithm as the edge awareness layer to obtain the decrypted original data. Then, it performs joint computation on the decrypted original data using the current privacy protection level to obtain the joint computation result.
[0113] The blockchain notary layer in this application provides a decentralized trust mechanism to ensure data integrity and immutability. This layer comprises multiple blockchain nodes, each verifying and storing the joint computation results in the blockchain system using zero-knowledge proofs and a lightweight consensus mechanism, thus ensuring data integrity. Specifically, the blockchain nodes use the Groth16 zk-SNARKs protocol, allowing vehicles to prove the authenticity of their location information without disclosing their specific location. For example, a vehicle can prove it is located within a certain area, protecting location privacy. Furthermore, the blockchain nodes can employ lightweight consensus algorithms such as Proof of Work (PoW) or Proof of Stake (PoS) to reduce computational overhead, making them suitable for resource-constrained V2X environments.
[0114] See Figure 4 This is a flowchart illustrating the system framework interaction provided in the embodiments of this application. Figure 4As can be seen, the vehicle sends the raw data to the edge device, the edge device uses TEEs to process and encrypt the raw data, and sends the encrypted target data to the SMPC layer for joint computation. The SMPC layer sends the joint computation result to the blockchain layer. The blockchain layer verifies the joint computation result and records it in the blockchain system to ensure data integrity. Furthermore, the verified joint computation result can be accessed by the cloud platform or other participants.
[0115] In summary, in this application, the edge perception layer collects raw data from the vehicle terminal and processes the raw data according to the current privacy protection level, thereby dynamically balancing privacy and efficiency, and improving computational efficiency while ensuring data security. This application can encrypt the processed raw data through a trusted execution environment to ensure the security of the data processing process and the raw data. Furthermore, the SMPC coordination layer performs joint computation on the target data through the SMPC protocol and the current privacy protection level, and uploads the joint computation result to the blockchain notary layer. The blockchain notary layer verifies and records the result in the blockchain system, which further ensures the integrity and immutability of the joint computation result.
[0116] In another embodiment of this application, after the edge device of the edge perception layer collects raw data from the vehicle terminal, it is also necessary to extract the vehicle location information and time information from the raw data; and use the vehicle location information, time information and B-spline interpolation algorithm to correct the vehicle location information and time information of the raw data.
[0117] This application introduces a spatiotemporal synchronization mechanism, employing B-spline interpolation to achieve precise synchronization of vehicle position and time, ensuring data consistency between different devices. B-spline interpolation is a parametric representation-based method that generates smooth curves by calculating parametric functions. Therefore, after extracting vehicle position and time information from the original data, this application uses B-spline interpolation to fit the vehicle trajectory, correcting the vehicle position and time information and reducing timestamp deviations.
[0118] In another embodiment of this application, the edge device determines the current privacy protection level corresponding to the original data by the following steps:
[0119] Determine the current application scenario of the vehicle terminal and the data type of the raw data; based on the current application scenario and the data type, determine the current privacy protection level.
[0120] Accordingly, the process by which the edge device processes the raw data using the current privacy protection level to generate processed raw data includes: determining the target processing operation corresponding to the current privacy protection level; wherein the target processing operation includes at least one of the following: SMPC protocol processing operation, double masking processing operation, and differential privacy processing operation; and processing the raw data through the target processing operation to generate processed raw data.
[0121] In this application, the current privacy protection level can be determined by comprehensively considering the current application scenario of the vehicle terminal and the data type of the raw data. The application scenario of the vehicle terminal refers to the current environment in which the vehicle terminal is located. Different application scenarios have different privacy requirements, such as urban scenarios and highway scenarios, with urban scenarios having higher privacy requirements than highway scenarios. The data type of the raw data is determined based on the specific type of data. Different data types have different privacy requirements, such as location data and acceleration data, with location data having higher privacy requirements than acceleration data.
[0122] This application determines the current privacy protection level based on the current application scenario and data type. Specifically, if both the application scenario and data type have high privacy requirements, the current privacy protection level is the highest; if either the application scenario or data type has high privacy requirements, the current privacy protection level is relatively high; and if both the application scenario and data type have low privacy requirements, the current privacy protection level is relatively low.
[0123] Furthermore, after determining the current privacy protection level, this application can select the corresponding target processing operation based on the current privacy protection level, and sequentially execute each target processing operation on the raw data to generate processed raw data. The target processing operation includes at least one of the following: SMPC protocol processing operation, double masking processing operation, and differential privacy processing operation. The higher the current privacy protection level, the more target processing operations need to be executed.
[0124] Specifically, processing operations performed through the secret sharing mechanism and / or homomorphic encryption mechanism of the SMPC protocol are SMPC protocol processing operations; processing operations that add double masks to the original data are double mask processing operations; and processing operations performed through differential privacy technology are differential privacy processing operations. For example: if the current privacy protection level is no_privacy, the target processing operation to be performed is: SMPC protocol processing operation; if the current privacy protection level is dp_only, the target processing operation to be performed is: SMPC protocol processing operation and differential privacy processing operation; if the current privacy protection level is high_privacy, the target processing operation to be performed is: SMPC protocol processing operation, double mask processing operation, and differential privacy processing operation.
[0125] In another embodiment of this application, if the target processing operation is a double-mask processing operation, the process of processing the original data through the target processing operation to generate processed original data includes: obtaining a first random mask and a second random mask; adding the first random mask and the second random mask to the original data to obtain the processed original data.
[0126] Specifically, this application can introduce a dual-mask SMPC protocol. The dual-mask SMPC protocol enhances the randomness and security of data by introducing two independent random masks (r1, r2). That is: each edge device determines its own first and second random masks, adds them to the original data, and obtains the processed original data; the SMPC coordination layer performs joint calculations on the original data with the added dual masks to obtain an initial joint calculation result, and removes the dual masks from the initial joint calculation result to obtain the final joint calculation result. The specific process of the dual-mask SMPC protocol is explained below:
[0127] Each participant generates random masks r1 and r2, combines the original data x with the masks to generate the processed original data x' = x + r1 + r2; x' is encrypted and uploaded to the SMPC coordination layer, the SMPC coordination layer decrypts x' and calculates f(x') through the SMPC protocol, where f is the objective function; the mask is removed from f(x') to obtain the final result f(x).
[0128] In summary, this application can dynamically select the current privacy protection level based on the current application scenario and data type, and select the corresponding target processing operation based on the current privacy protection level. In this way, privacy and efficiency can be dynamically balanced as needed. Furthermore, this application can significantly increase the difficulty for attackers to infer the original data through double masking processing.
[0129] In another embodiment of this application, sending target data to the SMPC coordination layer includes: determining a target SMPC coordination node from the SMPC coordination layer; wherein the current edge device and the target SMPC coordination node belong to the same geographical area; and sending each target data in the same task batch to the target SMPC coordination node.
[0130] Accordingly, the SMPC coordination layer uploads the joint computation results to the blockchain notary layer, including: the target SMPC coordination node determines the target blockchain node from the blockchain notary layer and uploads the joint computation results to the target blockchain node; wherein, the target SMPC coordination node and the target blockchain node belong to the same geographical region.
[0131] In V2X environments, the high-speed movement of vehicles and frequent changes in network conditions place high demands on the real-time performance of secure computing. However, existing technologies often suffer from inefficiency when coordinating multi-party secure computing due to synchronization congestion or excessive communication overhead, failing to meet real-time requirements. Therefore, this application proposes batch processing optimization and geographical sharding. Batch processing optimization addresses the high concurrency characteristics of V2X communication by combining multiple computing tasks into a single batch for processing, reducing communication rounds. The specific implementation includes the following steps:
[0132] 1. Batch formation: Combining multiple independent tasks into a single task batch;
[0133] 2. Batch processing: Apply the SMPC protocol to the entire task batch to reduce redundant communication; for example, if a task batch includes five computing tasks, the edge device obtains the target data of these five computing tasks and sends these five target data to the corresponding SMPC coordination layer through the SMPC protocol, thus achieving the transmission of five target data in one data communication.
[0134] 3. Results Separation: The SMPC coordination layer extracts individual results for each task from the batch results.
[0135] In this application, geographic sharding involves grouping nodes into multiple shards based on their geographical location. Each shard independently processes local transactions, reducing cross-shard communication. For example, the geographical location of each node in the edge awareness layer, SMPC coordination layer, and blockchain notarization layer is determined, and the nodes are divided into different groups based on their address locations. For instance, edge devices, SMPC coordination nodes, and blockchain nodes located in the same geographic area are grouped into the same task group. When the current edge device sends target data to the SMPC coordination layer, it first determines the SMPC coordination node located in the same geographic area as the current edge device. If there is only one SMPC coordination node, it is directly used as the target SMPC coordination node; if there are multiple SMPC coordination nodes, the target SMPC coordination node is selected based on the node status of each SMPC coordination node.
[0136] Similarly, when the target SMPC coordinating node sends the joint computation result to the blockchain notary layer, it also needs to determine the blockchain node located in the same geographical area as the target SMPC coordinating node. If there is only one blockchain node, it is directly used as the target blockchain node; if there are multiple blockchain nodes, the target blockchain node is selected according to the node status of each blockchain node. The node status can be: the node's performance status, load status, etc.
[0137] In summary, this application optimizes batch processing, combining multiple computational tasks into a single batch for processing, reducing communication rounds; furthermore, this application improves throughput and reduces latency through geographical sharding and local consensus.
[0138] As can be seen from the above, the system framework provided in this application has the following innovative features: Double-masked SMPC protocol: Enhances data security through double masking, suitable for V2X scenarios with high privacy requirements. Batch processing optimization: Reduces communication overhead and improves computational efficiency for high-concurrency data streams. Geographic sharding: Reduces blockchain latency and improves system throughput through sharding mechanisms. Zero-knowledge proof: Protects vehicle location privacy while ensuring data authenticity. Cross-layer security: Guarantees the overall security of the framework through formal proofs.
[0139] To illustrate the effectiveness of this solution, experiments conducted in a simulated environment using the VeReMi dataset verified the framework's effectiveness. See Table 1 for the test results provided for the embodiments of this application:
[0140] Table 1
[0141] Test Items Test Results Privacy configuration flexibility It supports five privacy modes to meet the needs of different scenarios. Batch processing performance The batch processing speed of 1000 records reaches 416 records / second. Blockchain performance Geographic sharding and zero-knowledge proofs reduce latency by approximately 30%.
[0142] As shown in Table 1, this solution supports five privacy modes by introducing privacy protection levels to meet the needs of different scenarios; it can effectively improve processing speed through batch processing optimization; and it can effectively reduce processing latency through geographical sharding and zero-knowledge proof. In other words, this system framework performs well in terms of privacy protection, computational efficiency, and practical feasibility.
[0143] See Table 2, which describes the beneficial effects provided in the embodiments of this application:
[0144] Table 2
[0145]
[0146]
[0147] As can be seen from Table 2, this application has at least the following beneficial effects:
[0148] 1. With configurable SMPC adaptive privacy mode, it supports multiple privacy modes to meet the privacy needs of different scenarios.
[0149] 2. Through the integrated design of a three-layer secure computing framework, TEEs, SMPC and blockchain are seamlessly integrated to form a unified security model.
[0150] 3. Through batch processing optimization of V2X data streams, efficient batch processing can be achieved for high-concurrency data streams, reducing communication overhead.
[0151] 4. Geographic sharding and zero-knowledge proofs at the blockchain layer: Sharding reduces latency, and zero-knowledge proofs protect location privacy;
[0152] 5. Through the innovation of the double-mask SMPC protocol, the data security and randomness are significantly improved through the double-mask mechanism.
[0153] As can be seen from the above, this application solves the privacy and security challenges in V2X communication through a cross-domain vehicle-road-cloud-chain secure multi-party computation framework. Its flexible privacy protection, integrated security, dynamic adaptability and scalability enable it to meet the complex needs of intelligent transportation systems. Experimental results further verify the practical feasibility of the framework and lay a solid foundation for the future development of the V2X ecosystem.
[0154] In another embodiment of this application, a cross-domain secure multi-party computation method based on vehicle-to-everything (V2X) communication is also disclosed. This method is applied to the SMPC coordination layer and includes:
[0155] The system receives target data sent by the edge perception layer; wherein the edge perception layer collects raw data from the vehicle terminal, determines the current privacy protection level corresponding to the raw data, processes the raw data using the current privacy protection level, and encrypts the processed raw data through a trusted execution environment to generate the target data.
[0156] Using the SMPC protocol and the current privacy protection level, joint computation is performed on the target data to generate joint computation results;
[0157] The joint calculation result is uploaded to the blockchain notary layer, and after the joint calculation result is verified by the blockchain notary layer, it is recorded in the blockchain system.
[0158] It should be noted that the cross-domain secure multi-party computation method described in this application is the same as the cross-domain secure multi-party computation method in the above embodiments, except that the executing entity is different. Therefore, the specific execution process of this embodiment can refer to any of the above method embodiments.
[0159] See Figure 5 , Figure 5 A schematic diagram of an electronic device structure provided in this application embodiment includes a processor 21, a communication interface 22, a memory 23 and a communication bus 24, wherein the processor 21, the communication interface 22 and the memory 23 communicate with each other through the communication bus 24;
[0160] Memory 23 is used to store computer programs;
[0161] When the processor 21 executes the program stored in the memory 23, it implements the steps of the cross-domain secure multi-party computation method described in any of the above method embodiments, which will not be repeated here.
[0162] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0163] The communication interface is used for communication between the aforementioned terminal and other devices.
[0164] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0165] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0166] In another exemplary embodiment, a computer storage medium is also provided, wherein the program instructions, when executed by a processor, implement the steps of the cross-domain secure multi-party computation method described in any of the above method embodiments. The storage medium may include various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0167] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments, and will not be repeated here.
[0168] It should be understood that the terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also include the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in a particular order described or illustrated unless the order of performance is explicitly indicated. It should also be understood that additional or alternative steps may be used.
[0169] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A cross-domain secure multi-party computation method based on vehicle-to-everything (V2X) communication, characterized in that, The cross-domain secure multi-party computation method is applied to the edge-aware layer, including: Raw data is collected from the vehicle terminal; Determine the current privacy protection level corresponding to the original data; The original data is processed using the current privacy protection level to generate processed original data; The processed raw data is encrypted using a trusted execution environment to generate the target data; The target data is sent to the SMPC coordination layer, so that the SMPC coordination layer can perform joint calculations on the target data using the SMPC protocol and the current privacy protection level, and upload the joint calculation results to the blockchain notary layer. After the blockchain notary layer verifies the joint calculation results, they are recorded in the blockchain system.
2. The cross-domain secure multi-party computation method according to claim 1, characterized in that, After collecting raw data from the vehicle terminal, the process also includes: Extract vehicle location information and time information from the raw data; The vehicle location information, the time information, and the B-spline interpolation algorithm are used to correct the vehicle location information and time information of the original data.
3. The cross-domain secure multi-party computation method according to claim 1, characterized in that, Determining the current privacy protection level corresponding to the original data includes: Determine the current application scenario of the vehicle terminal; Determine the data type of the original data; The current privacy protection level is determined based on the current application scenario and the data type.
4. The cross-domain secure multi-party computation method according to claim 3, characterized in that, The step of processing the original data using the current privacy protection level to generate processed original data includes: Determine the target processing operation corresponding to the current privacy protection level; wherein the target processing operation includes at least one of: SMPC protocol processing operation, double masking processing operation, and differential privacy processing operation; The original data is processed through the target processing operation to generate processed original data.
5. The cross-domain secure multi-party computation method according to claim 4, characterized in that, If the target processing operation is a double masking operation, then the original data is processed by the target processing operation to generate processed original data, including: Obtain the first random mask and the second random mask; The first random mask and the second random mask are added to the original data to obtain the processed original data.
6. The cross-domain secure multi-party computation method according to any one of claims 1 to 5, characterized in that, Sending the target data to the SMPC coordination layer includes: The target SMPC coordination node is determined from the SMPC coordination layer; wherein the current edge device and the target SMPC coordination node belong to the same geographical region; Send the target data of each task batch to the target SMPC coordination node; Accordingly, the SMPC coordination layer uploads the joint computation results to the blockchain notary layer by: the target SMPC coordination node determining the target blockchain node from the blockchain notary layer and uploading the joint computation results to the target blockchain node; the target SMPC coordination node and the target blockchain node belong to the same geographical region.
7. A cross-domain secure multi-party computation method based on vehicle-to-everything (V2X) communication, characterized in that, The method is applied to the SMPC coordination layer, and the method includes: The system receives target data sent by the edge perception layer; wherein the edge perception layer collects raw data from the vehicle terminal, determines the current privacy protection level corresponding to the raw data, processes the raw data using the current privacy protection level, and encrypts the processed raw data through a trusted execution environment to generate the target data. Using the SMPC protocol and the current privacy protection level, joint computation is performed on the target data to generate joint computation results; The joint calculation result is uploaded to the blockchain notary layer. After the joint calculation result is verified by the blockchain notary layer, it is recorded in the blockchain system.
8. A cross-domain secure multi-party computation system based on vehicle-to-everything (V2X) communication, characterized in that, include: An edge awareness layer is used to collect raw data from the vehicle terminal and determine the current privacy protection level corresponding to the raw data. The original data is processed using the current privacy protection level, and the processed original data is encrypted through a trusted execution environment to generate target data, which is then sent to the SMPC coordination layer. The SMPC coordination layer is used to receive the target data, perform joint computation on the target data using the SMPC protocol and the current privacy protection level, generate joint computation results, and upload the joint computation results to the blockchain notary layer. The blockchain notary layer is used to verify the joint calculation result and record the verified joint calculation result to the blockchain system.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; When a processor executes a program stored in memory, it implements the steps of the cross-domain secure multi-party computation method as described in any one of claims 1 to 7.
10. A computer storage medium, characterized in that, The computer storage medium stores computer-executable instructions for performing the steps of the cross-domain secure multi-party computation method according to any one of claims 1 to 7.
Citation Information
Cited By
Trusted data space vehicle AI management method and system
CN121765750A