Method for constructing a safety self - coordination model for a group of driverless vehicles

By adopting a dynamic evolution method based on risk assessment utility and a key update protocol based on revocation polynomials in the driverless vehicle group, a security self-cooperation model is built, which solves the problem that the safety of the driverless vehicle group is difficult to maintain during the dynamic evolution process, and the high-safe motion behavior of the vehicle group in complex environments is achieved.

CN114169725BActive Publication Date: 2025-05-27TONGJI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111436520.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-29
Publication Date
2025-05-27
Estimated Expiration
2041-11-29

AI Technical Summary

Technical Problem

It is difficult for existing driverless vehicle groups to maintain safety during the dynamic evolution process, especially when nodes join and leave, which may lead to splitting, merging and reorganizing the vehicle groups, and the certificates are difficult to maintain.

Method used

A dynamic evolution method of driverless vehicle groups based on risk assessment utility is adopted, and combined with a key update protocol based on revocation polynomials, a self-cooperation model for driverless vehicle groups is built to ensure that the vehicle groups remain safe during dynamic evolution and to achieve easy maintenance of certificates.

Benefits of technology

Through this method, the driverless car group can maintain the safety of movement behavior during the highly dynamic evolution process in complex environments, effectively eliminate malicious nodes, and ensure that the wide application of the vehicle group is safe.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114169725B_ABST
    Figure CN114169725B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of driverless, and proposes a method for constructing a safe self - coordination model for a driverless vehicle fleet. Specifically, it includes the following steps: Step 1. A dynamic evolution method for a driverless vehicle fleet based on risk - assessment utility; Step 1.1 Related definitions; Step 1.2 Driverless vehicle fleet events and processing algorithms; Step 1.3 Driverless vehicle fleet evolution algorithms; Step 2. A safe self - coordination model for a driverless vehicle fleet; Step 2.1 Related definitions; Step 2.2 A key update protocol based on revocation polynomials; Step 2.3 A safe self - coordination model for a driverless vehicle fleet. The present invention provides a security method that can ensure that the driverless vehicle fleet continuously maintains intelligent autonomous collaborative motion behavior, so that the driverless vehicle fleet can be safely applied in complex scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of driverless, and particularly to a method for constructing a safety self - coordination model for driverless vehicle groups. Background Art

[0002] With the development of artificial intelligence technology, technology giants at home and abroad have begun to compete in the layout of the driverless field. Relevant enterprises have invested heavily in researching and developing related technologies, which has accelerated the development of driverless technology. According to the latest driverless industry prediction, driverless cars are expected to achieve L5 - level full autonomous driving without a driver and be put on the market and legally used in some regions by the end of the 2020s of this century. The initial driverless vehicles may have a high cost and limited performance. Starting from the 2030s or 40s of this century, the cost of driverless cars will gradually decrease and become popular among the public.

[0003] Although driverless technology is considered to be able to significantly reduce traffic accidents caused by human factors, relieve traffic congestion, and improve exhaust pollution emissions, however, at the present stage, driverless technology is still in its infancy. At the same time, the co - existence of driverless and manned driving will also inevitably lead to new problems such as traffic safety, traffic congestion, and air pollution. As the latest form of the development of intelligent transportation, the combination of driverless with wireless communication technology provides a new means to solve the above - mentioned problems. Driverless vehicles no longer rely on single - body intelligent decision - making, but through information sharing among vehicles, they can obtain more comprehensive information such as road conditions, and then achieve efficient cooperation among vehicles, avoid traffic accidents, and improve vehicle passing efficiency, realizing the transformation from single - vehicle intelligence to group intelligence.

[0004] Due to the complex road conditions and the rapid movement of vehicles, phenomena such as node joining and leaving frequently occur in driverless vehicle groups. The departure of some key nodes may also lead to the splitting, merging, and reorganization of driverless vehicle groups. Dynamic evolution is common throughout the entire life cycle of driverless vehicle groups. There are a large number of communication behaviors among vehicles during the evolution process of the vehicle group, and secure communication methods are required to ensure information security.

[0005] Currently, there is no research on a safe driverless self - coordination model. To achieve safe and intelligent coordination of the motion behavior of driverless vehicle groups, the following problems need to be solved:

[0006] (1) Safe state perception and countermeasures: According to the environment where the driverless vehicle group is located and its own characteristics, it is necessary to implement safe state perception and measures to deal with network security attack events during the dynamic evolution process. In the key steps of network evolution events, once an important node in the vehicle group is invaded by the network, it will disrupt the evolution behavior of the vehicle group and threaten the safety of the entire vehicle group.

[0007] (2) Difficulty in maintaining member certificates: Most existing solutions rely on fixed devices to act as certification authorities (CAs). However, for unmanned vehicle swarms, more consideration needs to be given to the collaboration among internal nodes of the swarm. Coupled with the interference of the external complex environment, the swarm itself has a high degree of dynamicity. If a single vehicle acts as the CA, when the vehicle managing the CA leaves the swarm, it is necessary to frequently migrate the certificates to trusted nodes within the swarm, which makes it difficult to maintain the certificates of the swarm. Summary of the Invention

[0008] Object of the Invention:

[0009] In view of the above problems, based on "A Method for Constructing a Secure Unmanned Vehicle Swarm Based on Risk Assessment Utility" (applicant: Tongji University, patent application number: 2021103659275) applied by inventors Cheng Jiujun et al. on April 13, 2021), the present invention provides a method for dynamically evolving the security of an unmanned vehicle swarm, enabling the unmanned vehicle swarm to maintain security during key events of dynamic evolution. At the same time, a key distribution and certificate revocation scheme that does not rely on a certification authority is provided, improving the maintainability of the identities of swarm members and enabling the unmanned vehicle swarm to effectively exclude malicious nodes in the face of security intrusions; combined with the security evolution method, a secure self-coordination model for unmanned driving is given, enabling the swarm to return to a secure evolution state. Thus, during the highly dynamic evolution process of the unmanned vehicle swarm in a complex environment, its motion behavior always remains secure, providing a security guarantee for the wide application of the unmanned vehicle swarm.

[0010] The technical solution provided by this application of the present invention is as follows:

[0011] A method for constructing a secure self-coordination model for an unmanned vehicle swarm, characterized in that it specifically includes the following steps:

[0012] Step 1. A method for dynamically evolving an unmanned vehicle swarm based on risk assessment utility

[0013] Step 1.1 Related definitions

[0014] Step 1.2 Unmanned vehicle swarm events and processing algorithms

[0015] (1) Unmanned vehicle swarm growth event

[0016] (2) Unmanned vehicle swarm reduction event

[0017] (3) Unmanned vehicle swarm merging event

[0018] (4) Unmanned vehicle swarm splitting event

[0019] Step 1.3 Unmanned vehicle swarm evolution algorithm

[0020] Step 2. Unmanned Vehicle Cluster Security Self-Coordination Model

[0021] Step 2.1 Related Definitions

[0022] Step 2.2 Key Update Protocol Based on Revocation Polynomial

[0023] Step 2.3 Unmanned Vehicle Cluster Security Self-Coordination Model

[0024] Beneficial Effects

[0025] The purpose of the present invention is to disclose a method for ensuring the safety of intelligent autonomous cooperative motion behavior of an unmanned vehicle cluster in a complex scenario, so that the unmanned vehicle cluster can be safely applied in a complex scenario.

[0026] Appendix Explanation

[0027] Table 1 Symbol Explanation in the Present Invention

[0028] Table 2 Attack Classification

[0029] Table 3 Simulation Experiment Configuration

[0030] Table 4 Vehicle Basic Safety Attribute Settings

[0031] Table 5 Vehicle Lifecycle Safety Attribute Settings

[0032] Table 6 Vehicle Environment Safety Attribute Settings Explanation of the Drawings

[0033] Figure 1 Two-Layer Architecture Vehicle Cluster Merging

[0034] Figure 2 Two-Layer Architecture Vehicle Cluster Incorporating into Three-Layer Architecture Vehicle Cluster

[0035] Figure 3 Node Joining Flowchart

[0036] Figure 4 Node Leaving Flowchart

[0037] Figure 5 Vehicle Cluster Merging Flowchart

[0038] Figure 6 Vehicle Cluster Splitting Flowchart

[0039] Figure 7 Main Node Leaving and Vehicle Cluster Reorganization Process

[0040] Figure 8 Core Node Leaving Process

[0041] Figure 9 Unmanned Vehicle Cluster Security Evolution Algorithm Flowchart

[0042] Figure 10 Key update process based on revocation polynomial

[0043] Figure 11 Security self - cooperation model state transition diagram

[0044] Figure 12 SUMO simulation software and simulation scenario schematic diagram

[0045] Figure 13 Survival time of master nodes at different speeds

[0046] Figure 14 Survival time of core nodes at different speeds

[0047] Figure 15 Survival time of boundary points at different speeds

[0048] Figure 16 Curve of the strength of the vehicle group structure varying with time when the maximum vehicle speed is 5m / s

[0049] Figure 17 Curve of the strength of the vehicle group structure varying with time when the maximum vehicle speed is 10m / s

[0050] Figure 18 Curve of the strength of the vehicle group structure varying with time when the maximum vehicle speed is 15m / s

[0051] Figure 19 Curve of the strength of the vehicle group structure varying with time when the maximum vehicle speed is 20m / s

[0052] Figure 20 Curve of the strength of the vehicle group structure varying with time when the maximum vehicle speed is 25m / s

[0053] Figure 21 Curve of the strength of the vehicle group structure varying with time when the maximum vehicle speed is 30m / s

[0054] Figure 22 Curve of AREU varying with time when the maximum vehicle speed is 5m / s

[0055] Figure 23 Curve of AREU varying with time when the maximum vehicle speed is 10m / s

[0056] Figure 24 Curve of AREU varying with time when the maximum vehicle speed is 15m / s

[0057] Figure 25 Curve of AREU varying with time when the maximum vehicle speed is 20m / s

[0058] Figure 26The curve of AREU varying with time when the maximum vehicle speed is 25m / s

[0059] Figure 27 The curve of AREU varying with time when the maximum vehicle speed is 30m / s

[0060] Figure 28 This is the flowchart of the method of the present invention Detailed implementation manners

[0061] The specific implementation process of the present invention is as Figure 28 shown, including the following four aspects:

[0062] ① The dynamic evolution method of driverless vehicle groups based on risk assessment utility

[0063] ② The safety self - coordination model of driverless vehicle groups

[0064] ③ The relevant properties and safety proof of the safety self - coordination model of driverless vehicle groups

[0065] ④ Simulation experiment verification

[0066] ① Dynamic Evolution Method of Driverless Vehicle Swarm Based on Risk Assessment Utility

[0067] The present invention provides a dynamic evolution method of driverless vehicle groups based on risk assessment utility, which processes evolution events such as merging and splitting existing in the driverless vehicle groups, enables the vehicle group to maintain a relatively high risk assessment utility value during the verification evolution process, and ensures its safety during the evolution process.

[0068] (1) Related definitions

[0069] Definition 1 Distance function dist: The vehicle group formation algorithm uses the Euclidean distance to measure the distance between two vehicle nodes, that is:

[0070]

[0071] where v i ,, v j represent vehicle nodes, and (x, y, z) are the coordinates of the vehicle nodes in three - dimensional space.

[0072] Definition 2 Risk assessment utility REU: The risk of driverless vehicle group nodes is evaluated from three aspects: the estimated loss level (ELL), threat, and vulnerability, and the risk evaluation utility (REU) is given as a safety metric for the vehicle group. The REU of the driverless vehicle node v i at time t is:

[0073]

[0074] Among them, the int function is used to convert the ELL level to the corresponding positive real value, and generally a monotonically increasing function is selected; the value of α is set according to the value range of the int function to make the REU value have obvious discrimination; CVSS [2] is an industry public standard, which is designed to evaluate the severity of vulnerabilities and help applications determine the urgency and importance of the responses required for vulnerabilities. They respectively correspond to the basic index score, the lifecycle index score, and the environmental index score in the CVSS scoring system. The higher the score, the higher the severity of the vulnerability.

[0075] Definition 3 Core Node CN (Core Node): When the number of neighbor nodes of a node within the ε neighborhood reaches τ and the REU is higher than more than half of the neighbor nodes, this node is called a core node. At this time, the REU of the node needs to be recalculated according to formula (1.1):

[0076]

[0077] Among them, V is the set of all nodes within the ε neighborhood of the node (including the node itself), and |V| is the number of elements in the set V. It can be seen from formula (1.1) that after the core node is updated, will be less than that at the previous moment This can reflect that the risk of the original ordinary node increases and the safety factor decreases after becoming a key node in the vehicle group. The core node mainly shares the communication and computing loads of the master node.

[0078] Definition 4 Master Node MN (Master Node): The core node needs to be upgraded to the master node through an election mechanism. A node can be upgraded to the master node only when it meets the following conditions:

[0079] (1) This node is a core node;

[0080] (2) The REU value is higher than more than half of the neighbor core nodes, or there are no other core nodes.

[0081] The neighbor core nodes of the master node act as secondary nodes, responsible for maintaining the communication between its sub-vehicle group and the master node. When there is only one core node in the vehicle group, this core node is still upgraded to the master node, and there are no secondary nodes in the vehicle group at this time. The REU of the master node needs to be updated according to formula (1.2)

[0082]

[0083] Among them, V is the set of the core nodes subordinate to the master node and their sub-vehicle groups.

[0084] Definition 5: Border Node: If a noise point is in the ε neighborhood of a core node, it will be upgraded to a border node after receiving the heartbeat packet (a message sent regularly to maintain communication between vehicles) from the core node. At this time, the node officially joins the swarm. That is, the node can join the swarm if it meets the following conditions:

[0085]

[0086] Among them, N i is node v i The neighbor set of v c It is a core node in its neighbor set.

[0087] Definition 6: Noise Node NN: It is neither a core node nor a boundary node. There is no core node or master node in the neighborhood of this node. If there is a core node in its neighborhood, the node can be added to the topological network of the vehicle group; otherwise, the node does not participate in the construction of the vehicle group.

[0088] (1) The growth of driverless vehicles

[0089] The swarm growth event indicates that a new node has joined the autonomous swarm. When a new node is not in the ε neighborhood of any core node in the autonomous swarm, the node is considered to be outside the swarm. When the new node is in the ε neighborhood of a core node in the swarm, it can join the swarm and become a boundary node after receiving the heartbeat message from the core node.

[0090] As shown in Algorithm 1, the steps for processing a group growth event are as follows:

[0091] 1) Core Node CN in the Car Group m Send broadcasts to the surroundings, such as noisy nodes NN i In response, the core node calculates the distance dist(CN m ,NN i ).

[0092] 2) If the distance is less than ε, a heartbeat packet is sent, and the noise node becomes a boundary node, and NN i The parent is set to CN m .

[0093]

[0094] The Chinese description of node algorithm 1 is as follows:

[0095]

[0096] Algorithm 1 node joining flowchart is as follows Figure 3 shown.

[0097] (2) Unmanned vehicle cluster reduction event

[0098] The vehicle cluster reduction event means that a boundary node leaves the unmanned vehicle cluster, and there will be no large-scale changes to the vehicle cluster. After the core node does not receive the heartbeat message of the boundary node it manages for a period of time, this boundary node will be reset to a noise node.

[0099] As shown in Algorithm 2, the processing steps of the vehicle cluster reduction event are mainly as follows:

[0100] 1) Core node CN m Does not receive the heartbeat message of a certain boundary node BN i for some time.

[0101] 2) This boundary node will be reset to a noise node, and the superior node of BN i will be set to empty.

[0102]

[0103] The Chinese description of the node departure algorithm 2 is as follows:

[0104]

[0105] The flowchart of Algorithm 2 for node departure is as Figure 4 shown.

[0106] (3) Unmanned vehicle cluster merging event

[0107] There are two types of vehicle clusters in the unmanned vehicle cluster: one is a three-layer architecture vehicle cluster including "master node - core node - boundary node", and the other is a two-layer architecture vehicle cluster including "core node - boundary node". Based on this unmanned vehicle cluster, the vehicle cluster merging event is mainly divided into two types: (1) The situation where two smaller two-layer architecture vehicle clusters are merged into a larger vehicle cluster; (2) A smaller two-layer architecture vehicle cluster is incorporated into a larger three-layer architecture vehicle cluster.

[0108] As shown in Algorithm 3, the processing steps of the vehicle cluster merging event are mainly as follows:

[0109] 1) Assume that the current vehicle cluster is a two-layer architecture vehicle cluster C i , and its core node is CN m . CN m waits to receive the message of the head node h j of another vehicle cluster C n .

[0110] 2) As Figure 1 shown, if C j is a two-layer architecture vehicle cluster, compare CN m and hn The risk assessment utility REU value. If REU n is less than REU n , set the superior of CN m to h n , and send a message agreeing to merge to h n ; otherwise, CN m send a message requesting to merge to h n .

[0111] 3) As Figure 2 shown, if C j is a three - layer architecture vehicle group, set the superior of CN m to h n , and send a message agreeing to merge to h n .

[0112] 4) When CN m receives a message from another vehicle group requesting to merge, CN m is upgraded to the master node, sets its superior to itself, and updates its REU value.

[0113] 5) When CN m sets its valid superior, it exits the algorithm.

[0114]

[0115]

[0116] The Chinese description of the vehicle group merging algorithm 3 is as follows:

[0117]

[0118]

[0119] The flow chart of Algorithm 3 vehicle group merging is as Figure 5 shown.

[0120] (4) Unmanned vehicle group splitting event

[0121] The loss of a key node in the unmanned vehicle group will lead to the occurrence of a vehicle group splitting event, and the structure of the vehicle group will change greatly. The splitting events are mainly divided into the following two situations:

[0122] (1) The sub - vehicle group detaches from the main vehicle group due to the loss of the core node;

[0123] (2) The entire vehicle group structure splits into multiple sub - vehicle groups due to the loss of the master node.

[0124] If the master node leaves and the core node does not receive a heartbeat message (a timed message sent by the master node to the core node to confirm the status of the master node) for a period of time, the core node will then break away from the vehicle cluster and become an independent two-layer vehicle cluster. At the same time, it will start to execute the logic of vehicle cluster merging and prepare to reorganize a new three-layer architecture vehicle cluster. As Figure 4 shown, according to the logic of vehicle cluster evolution, multiple results may occur.

[0125] If the core node leaves, the boundary nodes will be reset to noise nodes, and the evolution process is as Figure 5 shown.

[0126]

[0127] The Chinese description of the vehicle cluster splitting algorithm 4 is as follows:

[0128]

[0129]

[0130] The flowchart of algorithm 4 for vehicle cluster splitting is as Figure 6 shown.

[0131] (4) Unmanned vehicle cluster evolution algorithm (algorithm 5)

[0132] Integrating algorithms 1 to 4 gives the complete method for safe evolution of unmanned vehicle clusters. As shown in algorithm 5, the specific steps of this algorithm are as follows:

[0133] 1) Traverse the set of evolution events of the vehicle cluster, and this set is continuously updated during the life cycle of the vehicle cluster.

[0134] 2) For growth events, execute the node addition algorithm; for reduction events, execute the node departure algorithm; for merging events, execute the vehicle cluster merging algorithm; for growth events, execute the vehicle cluster splitting algorithm.

[0135] 3) Update the vehicle set V after processing the evolution events n .

[0136]

[0137] The Chinese of the safe evolution algorithm for unmanned vehicle clusters is as follows:

[0138]

[0139]

[0140] The flowchart corresponding to the safe evolution algorithm 5 for unmanned vehicle clusters is as Figure 7 shown.

[0141] ②

[0142] Safety Self-Coordination Model of Driverless Vehicle Swarm

[0143] In the traditional vehicle group communication model, a certificate authority (CA) is relied on to manage the certificates of members. However, in the evolution process of driverless vehicle groups, if a single vehicle acts as the CA, when the vehicle managing the CA leaves the vehicle group, it is necessary to frequently migrate the certificates to trusted nodes within the vehicle group, which makes it difficult to maintain the certificates of the vehicle group. Therefore, the CA that centrally manages certificates is not applicable to this scenario. Thus, the present invention provides a key update protocol based on revocation polynomials to achieve secure key exchange; at the same time, a secure self-coordination model for driverless vehicle groups is given in combination with the dynamic evolution method of driverless vehicle groups.

[0144] (1) Related Definitions

[0145] Definition 1 Vehicle identity real number vid: vid is calculated by (1):

[0146] vid i =H(ELP i , MAC i ) (1)

[0147] Wherein, ELP represents the electronic license plate of the vehicle, and MAC represents the MAC address used by the vehicle in network communication. The ELP and the MAC address are converted into the vehicle identity real number vid through the binary mapping function H to uniquely identify a specific vehicle.

[0148] Definition 2 Public revocation polynomial R(x): This polynomial is jointly maintained by the vehicle group and is used to replace the Certificate Revocation List (CRL) used in the traditional CA. It is defined by formula (2):

[0149]

[0150] Wherein, S r is the set of vehicle identity real numbers corresponding to the vehicle nodes excluded by the vehicle group. It can be seen from the definition that for any r i ∈S r , R(r i ) = 0.

[0151] Definition 3 Private revocation polynomial r(x): This polynomial is generated based on R(x). When a new malicious node is discovered, its vid is added to r(x). r(x) is used to temporarily replace the CRL and is separately maintained by the vehicle node. Its definition is as follows:

[0152]

[0153] Among them, t is the lowest degree of the polynomial, and r′ j is a real number randomly generated to complement the degree of the polynomial. It can be seen from the definition that R(x) is a factor of r(x). Equation (3) defines the generation of the revocation certificate polynomial, and the finally used polynomial is the result of its calculation, as shown in formula (4):

[0154]

[0155] Definition 4 Mask polynomial s(x): This polynomial is used for confusion to prevent the key from being cracked. The mask polynomial of vehicle v i is separately saved by this vehicle and will not be leaked to other vehicles. Its form is:

[0156]

[0157] Among them, n is the degree of r(x), so the degrees of s i (x) and r(x) are the same.

[0158] Definition 5 Key polynomial φ(x): This polynomial is generated by the revocation certificate polynomial, the mask polynomial, and the public key PK i of vehicle node v i and is used to transmit the key. Its definition is:

[0159] φ i (x) = PK i r(x) + ε t s i (x) (6)

[0160] Among them, ε t is a coefficient randomly generated temporarily during communication. When vehicle node v i transmits the key to vehicle node v j , the key polynomial is

[0161]

[0162] Use Δ i,j to replace ε t s i (j). When node v j obtains Δ i,j and r(x), the calculation method of the public key PK i can be obtained:

[0163]

[0164] Definition 6 Vehicle group attribute set M: This set is the set of all attributes involved in the vehicle group in the secure self - coordination model and can be represented by the following five - tuple:

[0165] The set of attributes can be represented by the following five - tuple:

[0166] M = <V, G, S, F, R(x)> (9)

[0167] Wherein, V = {v i | i = 1, 2…, n} represents the set of all vehicle nodes, G = {G i | i = 1, 2…, n} represents the set of all vehicle groups, R(x) represents the revocation polynomial, which is used to maintain the communication security between vehicle groups. G = {f i | i = 1, 2…, n} represents the vehicle group evolution event, and the events are mainly divided into seven events: node joining f 1 , vehicle group joining f 2 , boundary point leaving f 3 , core / master node leaving f 4 , boundary point exclusion f 5 , core / master node exclusion f 6 , attack detection f 7 . Different events will cause corresponding state changes. S represents the state of the vehicle group, and seven states are defined in this model, namely initialization state S 0 , growth state S 1 , reduction state S 2 , merging state S 3 , splitting state S 4 , non-secure state S 5 and secure self-coordination state S 6 .

[0168] Define 7 initialization state S 0 : A new vehicle group G i is formed, where v i represents the master node. At this time, the vehicle group set G = G ∪ G i . The master node broadcasts the revocation polynomial R(x) to all nodes in the vehicle group. At this time, for , it is necessary to verify the reliability of the surrounding neighbor vehicles through R(x), and then use the ECDH method to exchange keys with the verified reliable nodes.

[0169] Define 8 growth state S 1 : When the node v j joins the vehicle group G i at time t, the state of the model is updated as follows:

[0170]

[0171] At this time, v j obtains the revocation polynomial R(x) from the master node, and then uses the ECDH method to exchange keys with the surrounding reliable nodes.

[0172] Definition 9 Reduction State S 2 : When the boundary node v at time t j leaves the vehicle group G i , the state of the model is updated as follows:

[0173]

[0174] Definition 10 Merge State S 3 : When the secondary structure vehicle group G at time t j merges into another vehicle group G i , the state of the model is updated as follows:

[0175]

[0176] At this time, the master node updates the revocation polynomial R(x), and the nodes originally belonging to vehicle group G j and vehicle group G i exchange public keys with each other.

[0177] Definition 11 Split State S 4 : When the secondary structure vehicle group G at time t j detaches from vehicle group G i , the state of the model is updated as follows:

[0178]

[0179] At this time, the master node updates the revocation polynomial R(x) according to the existing nodes in the vehicle group and broadcasts it to the vehicle group members.

[0180] Definition 12 Non-Secure State S 5 : For a vehicle group G i , when a forged message is detected, after node v j confirms the identity of the forger v k , the key update process starts. After the process ends, the non-malicious nodes in the vehicle group complete the key update, and at the same time exclude the forger from the vehicle group and add it to the revocation polynomial R(x), the revocation polynomial R(x) will be updated. The state of the model is updated as follows:

[0181]

[0182] Definition 13 Secure Self-Conformance State S 6 : After the vehicle group undergoes an evolution event caused by normal node changes or exclusion of malicious nodes, it returns to the secure self-conformance state, that is, other evolution states ultimately return to the secure self-conformance state.

[0183] (2) Key Update Protocol Based on Revocation Polynomial

[0184] In the initialization stage of vehicular communication, vehicle nodes exchange public keys through the Elliptic Curve Diffie-Hellman (ECDH) key exchange method. When a malicious node is detected in the vehicular network, this protocol can be used to update the keys so that the malicious node cannot obtain the new keys. As Figure 10 shown, the steps of this protocol are as follows:

[0185] 1) Nodes v i and v j exchange keys through ECDH in the initialization stage of the vehicular network;

[0186] 2) Node v i detects a new malicious node v r in the vehicular network, prepares to update its own public key and sends this message. Node v i first constructs a revocation polynomial r(x) according to the vid of node v r and R(x);

[0187] 3) Node v i generates a masking polynomial s i (x) to ensure that the degrees of s i (x) and r(x) are the same;

[0188] 4) Node v i broadcasts the message tuple <vid i , φ i (x)> to all nodes in the vehicular network;

[0189] 5) After receiving the message, node v j first verifies that R(vid i ) ≠ 0, otherwise it ignores this message. Then it encrypts its own vid with the old public key of node v j and sends it to node v j ;

[0190] 6) Node v i calculates Δ i,j = ε t s i (vid j ), and then encrypts the message tuple <r(x), Δ i,j > with the public key of node v j and sends it to node v j ;

[0191] 7) When node v j gets Δ i,j and r(x), it can calculate the new public key of v i using formula (8).

[0192] (3) Unmanned Vehicular Network Secure Self-Coordination Model

[0193] 1) Attack Model

[0194] This attack model takes into account attackers both inside and outside the vehicle group. Both the message sender and receiver may act as internal attackers. External attackers act as intruders, and it is assumed that their attack types are limited to eavesdropping. According to the attack behavior, attacks can be divided into active attacks and passive attacks. Passive attacks mainly refer to eavesdropping attacks, and active attacks are to inject forged messages into the vehicle group network. Since there are only vehicle nodes in the communication system of the driverless vehicle group, the possible attack types are relatively single. Table 2 lists all the attack types.

[0195] 2) Security Objectives

[0196] a. Message Integrity: This self - coordination model of the driverless vehicle group can maintain the integrity of messages. The message content sent by the sending vehicle should be guaranteed not to be modified when delivered to the receiving vehicle.

[0197] b. Eavesdropping Resistance: Except for the designated message - receiving vehicle, other vehicles cannot crack the message.

[0198] c. Vehicle Revocability: Once the vehicle identity is revoked, the vehicle is excluded from the vehicle group and cannot join the vehicle group network again.

[0199] 3) Security Assumptions

[0200] a. The identities of the nodes in the vehicle group are public and real - name.

[0201] b. When an attacker performs a passive attack, it cannot be actively discovered by the vehicle group. Because when nodes that are far apart in the vehicle group cannot communicate directly, relay nodes are needed to forward messages, and it is impossible to prevent the message from being eavesdropped during this process.

[0202] c. When an attacker performs an active attack (such as forging a message), it can be detected by the vehicle group and its identity can be known. This can be achieved by tracing the nodes on the message propagation path. In the vehicle group model of this paper, there are at most 3 relay nodes between two nodes.

[0203] d. All members in the vehicle group can ensure the security of their encryption credentials (such as private keys and masking polynomials).

[0204] e. Potential attackers are regarded as ordinary nodes before being discovered.

[0205] f. There is no collusion among attackers.

[0206] 4) Security Self - Coordination Model

[0207] Based on the key update protocol based on the revocation polynomial and the dynamic evolution method of the security of the driverless vehicle group, the security self - coordination model of the driverless vehicle group can be obtained as follows:

[0208]

[0209] Among them, f t ∈F, S t ∈S, and the state S t triggered by f t changes in accordance with the constraints in Definitions 7 to 13.

[0210] The vehicle group processes safety events and vehicle group changes following the above rules. After the evolution event ends, it finally reaches the safe self-coordination state, specifically as Figure 11 shown.

[0211] ③

[0212] Relevant Properties and Safety Proof of Safety Self-Coordination Model of Driverless Vehicle Swarm

[0213] (1) Related properties of the safe self-coordination model of driverless vehicle groups

[0214] 1) Message integrity: After completing the initialization of the vehicle group, it is necessary to ensure the integrity of message transmission in each state S 1~6 of the vehicle group other than the initial state. For example, when vehicle v i sends a message to vehicle v j , when vehicle v i sends out the message text i , it will attach a signature sign i . This signature can enable the vehicle receiving the message to determine whether the message has been tampered with. Among them, under normal circumstances, the vehicle receiving the message can calculate the public key PK i of the sending vehicle through formula (8), and use the public key to decrypt the hash value of the message and then compare it with the hash value obtained by performing a hash operation on the actually received message. If they are the same, it means the message has not been tampered with. Therefore, this model can maintain the integrity of the message without being tampered with.

[0215] 2) Anti-eavesdropping property: Except for the initial state S 0 , the vehicles in the vehicle group may need to send messages to non-adjacent node vehicles. At this time, adjacent nodes are required to act as intermediaries to transmit the messages, but the messages sent are encrypted using the public key of the recipient, and the plaintext of the message can only be obtained by decrypting it with the private key of the recipient. Therefore, this model ensures that the intermediary nodes cannot obtain private messages.

[0216] 3) Vehicle revocability: Vehicle revocability means that when the system detects the existence of malicious vehicles in the vehicle group, it can promptly exclude the malicious vehicles so that they cannot receive any information in the vehicle group normally. In During the evolution process, the vehicle group uses formula (2) to maintain a public revocation polynomial R(x). For example, when a vehicle v i is detected as a malicious vehicle by the system, its vehicle identifier r i will be added to the public revocation polynomial to reconstitute a private revocation polynomial and sent to other vehicles in the vehicle group for updating the public revocation polynomial. Other vehicles will update their public keys, and the vehicles in the vehicle group will update the public keys of other vehicles through communication again. At this time, when another vehicle v j in the vehicle group sends the key polynomial φ i to vehicle v j (vid i ), vehicle v i cannot obtain the public key of vehicle v j through formula (8), and the vehicle cannot decrypt any received message. Therefore, this model ensures the revocability of vehicles.

[0217] (2) Security proof of the self-coordination model of driverless vehicle groups

[0218] The present invention proves and analyzes the security of the self-coordination model of driverless vehicle groups from three aspects: unbreakable information encryption, exclusion of threat nodes, and maintaining normal evolution when under security attacks, as follows:

[0219] Theorem 1: The communication between all vehicles in the self-coordination model of driverless vehicle groups cannot be cracked externally.

[0220] Proof: All communications in this model use Ellipse Curve Cryptography (ECC). The ECC algorithm defines K = kG over a finite field, where K and G are points on the elliptic curve E, n is the order of G, and k is an integer less than n. Given k and point P, it is easy to calculate K, but it is difficult to solve for k given K and G. In actual use, the ECC algorithm takes advantage of the difficulty of solving the elliptic curve discrete logarithm problem, makes n very large, selects a large number k as the private key, and generates the public key K. Therefore, it can be guaranteed from a mathematical principle that the private key cannot be cracked for the communication between all vehicles within a finite time.

[0221] Theorem 2: The self-coordination model of driverless vehicle groups can promptly exclude malicious nodes in the vehicle group.

[0222] Proof: When a certain vehicle node v r is detected as a malicious node, the attack detection event f 7 is triggered at this time. The identity information of this node will be added to the revocation integer list R(x) by the vehicle that accepts the malicious report, and its own key information will be updated and sent to other vehicles. At this time, vehicle v iSend the private revocation polynomial to its set of adjacent nodes This message conveys malicious node information and is encrypted using the recipient's public key. After other vehicles receive the polynomial, they update it and re-update their respective public keys. If a malicious node forges a false message <r′(x),Δ i,j > and sends it to the malicious node, the malicious node will not be able to calculate the correct public key PK i . Even if it receives the correct message <r(x),Δ j > sent to vehicle v i,j as a relay node, it cannot decrypt the sender's public key PK j without the corresponding private key SK i . Therefore, the self-coordination model can promptly exclude malicious nodes from the vehicle group.

[0223] Theorem 3: After detecting an attack event, the self-coordination model of driverless vehicle groups can ensure the normal evolution of the vehicle group.

[0224] Proof:

[0225] a) When the master node is a malicious node, event f is triggered 4 . When the core nodes and their subordinates in the vehicle group notify each other and update their keys, they immediately leave the vehicle group and enter the vehicle group splitting state S 4 . The out-of-group vehicle nodes reconstitute a vehicle group or join a new vehicle group according to the dynamic evolution method, and the vehicle group returns to the safe self-coordination state S 6 .

[0226] b) When the core node is a malicious node, event f is triggered 4 and it enters the vehicle group reduction and splitting state S 4 . If its subordinate member nodes receive a private notice to learn about the malicious node information, they will break away from the control of this core node and enter the communication range of other trusted nodes; if the malicious node deliberately does not forward information, its subordinate nodes will actively leave the vehicle group and become out-of-group nodes after not receiving messages from other vehicles for a certain period of time, and the vehicle group returns to the safe self-coordination state S 6 .

[0227] c) When the boundary node is a malicious node, event f is triggered 5 and it enters the vehicle group reduction state S 2 . After the core node updates the malicious node information, it will no longer send information to this malicious node, and the vehicle group returns to the safe self-coordination state S 6 .

[0228] Therefore, in the above three cases, the self-coordination model of driverless vehicle groups can ensure the normal evolution of the vehicle group.

[0229] ④

[0230] Simulation Experiment Verification

[0231] To verify the safety self - coordination model of driverless vehicle swarms, the present invention uses simulation experiments to simulate the behaviors of vehicle swarms, including the movement of vehicles and the communication behaviors between vehicles, and statistically analyzes the experimental results to verify the safety of the safety self - coordination model of driverless vehicle swarms.

[0232] (1) Simulation experiment data and methods

[0233] NS3 is an open - source discrete - event network simulator mainly for research and educational purposes. SUMO is an open - source tool developed by employees of the Institute of Transportation Systems of the German Aerospace Center, which can simulate microscopic and continuous traffic flow and aims to handle large - scale networks. The present invention uses NS3 (version 3.30) to simulate the communication behaviors of driverless vehicles and uses SUMO to simulate the movement behaviors of vehicles. The exported vehicle movement model can be used by NS3.

[0234] As Figure 9 shown, SUMO is used to simulate an intersection with a size of 10 km horizontally and vertically. There are 200 simulated vehicles in total. 200 seconds during the entire simulation process are intercepted. The vehicle flow near the intersection is the largest during this period, which is suitable for vehicle analysis. To cover various driving scenarios from low speed to high speed, the maximum speed of driverless vehicles is set in the range of 5 m / s to 30 m / s. Six relatively representative speed scenarios are selected at intervals of 5 m / s. The wireless communication range in network simulation is set to 150 m, and vehicles communicate through the WAVE protocol (IEEE 802.11p). The frequencies of collecting vehicle position information and network data in the experiment are both 1 time per second. Other configuration parameters adopt the default values of SUMO, as shown in Table 3.

[0235] The basic safety attributes of vehicles are shown in Table 4. Assuming that there are vulnerabilities in the vehicle communication system on driverless vehicles, in the driverless vehicle swarm scenario, the attack path is set to adjacent; the attack complexity is set to high; if the vulnerability needs to be exploited, the attacker needs to have a high privilege; the interaction between vehicle swarms is default to require user participation; the vulnerability of this system will also affect the entire vehicle, so the safety range is set to be changed; the impacts of this vulnerability on confidentiality, integrity, and availability are all set to low.

[0236] The life - cycle attributes of vehicles are shown in Table 5. Assuming that the code of this system has not leaked out, the degree of leaked code is set to unproven; assuming that vehicle manufacturers will continuously maintain the software system of vehicles, the repair levels of vehicles are set to temporary repair and official repair, and their proportions are shown in Table 6; assuming that the vulnerability information of this system has not been made public.

[0237] The environmental attributes of the vehicle are shown in Table 5. The estimated loss level of the vehicle is allocated in the ratio of low: medium: high = 3:4:3. An int function that converts the estimated loss level into a numerical value is also given, and the corresponding α value is 10; the requirements for confidentiality, integrity and availability are all set to high; the MUI, MC, MI and MA settings in the variable basic indicators are allocated to the vehicles according to the corresponding proportions.

[0238] In order to simulate the vehicle node leaving the vehicle group due to network attack, a mechanism for the node to actively leave the vehicle group is added. The boundary node, core node and main node all have a certain probability of leaving the vehicle group due to "network attack". i When creating, a time t is randomly generated (t is within the simulation duration), and at time t v i The probability of leaving the group due to a network attack is:

[0239]

[0240] From formula (16), we can see that the higher the risk assessment utility REU of a vehicle is, the lower the probability of it being successfully attacked is.

[0241] To verify the performance of the Security Oriented Cooperation Model (SOCM) model, we used another swarm evolution method, NDCE, to test the performance of the Security Oriented Cooperation Model (SOCM) model. [1] Compare the following indicators:

[0242] 1) Vehicle node survival time: including the survival time of the main node, core node and boundary point. This indicator is closely related to the survival time of the vehicle group. In an environment subject to network attacks, the longer the vehicle survival time, the higher the security of the vehicle group.

[0243] 2) Modularity: It is used to measure the structural strength of the swarm. Its value range is [-0.5, 1). The closer the modularity value is to 1, the better the structural strength of the swarm. Cyber ​​attacks can cause changes in the structure of the swarm. In an environment subject to cyber attacks, the higher the structural strength of the swarm, the higher the safety of the swarm.

[0244] (3) Average risk assessment utility of vehicle group: This indicator reflects the overall safety of the vehicle group.

[0245] (2) Analysis of simulation and experimental results

[0246] To cover various driving scenarios from low speed to high speed, six representative speed scenarios were selected in the range of 5 m / s to 30 m / s for the simulation experiment. The survival time of different nodes in the vehicle platoon, the platoon structure strength, and the average risk assessment utility of the vehicle platoon and other vehicle platoon safety evaluation indicators were tracked and recorded, and statistical analysis was carried out on them to evaluate the safety effect of the SOCM vehicle platoon model.

[0247] 1) Survival time of different nodes in the vehicle platoon

[0248] The survival time of the main node affects the overall safety of the vehicle platoon. The longer the survival time of the main node, the longer the survival time of the entire vehicle platoon, indicating that the safety of the vehicle platoon is higher. As Figure 13 shown, in the low-speed scenario (5 m / s), the survival time of the main node of the vehicle platoon using the SOCM model slightly leads that of the vehicle platoon using the NDCE evolution method; in other scenarios (10 m / s to 30 m / s), as the vehicle speed increases, the survival time of the main node of the vehicle platoon using the SOCM model significantly leads that of the vehicle platoon using the NDCE evolution method. Through the above comparison, it is found that the NDCE evolution method only has good performance in relatively low-speed scenarios, but still cannot match the SOCM model; while the SOCM model has good performance in most speed scenarios, indicating that the model can ensure the overall safety of the vehicle platoon in most speed scenarios.

[0249] The survival time of the core node reflects the safety within a local range of the driverless vehicle platoon. The longer the survival time of the core node, the higher the safety of the sub-vehicle platoon. As Figure 14 shown, in all speed scenarios in the figure, the survival time of the core node of the vehicle platoon using the SOCM model is longer than that of the vehicle platoon using the NDCE evolution method, indicating that the SOCM model can ensure the safety of the smaller-scale sub-vehicle platoon.

[0250] The survival time of the boundary point reflects the safety of the external edge nodes of the vehicle platoon. The longer the survival time of the boundary node, the closer the connection of the vehicle platoon and the safer the external edge of the vehicle platoon. As Figure 15 shown, in each speed scenario, the survival time of the boundary nodes of the vehicle platoon using the SOCM model is much longer than that of the vehicle platoon using the NDCE evolution method. It shows that the SOCM model can better handle the evolution events at the edge of the vehicle platoon and ensure the safety of individual members in the vehicle platoon.

[0251] 2) Vehicle platoon structure strength

[0252] The structural strength of a vehicle cluster is commonly measured by modularity. The closer the modularity is to 1, the stronger the vehicle cluster structure. In an environment where network attacks may occur, the vehicle cluster structure changes frequently. The stronger the vehicle cluster structure, the better the security of the vehicle cluster. In the high-altitude scenario of a driverless vehicle cluster, the relative positions of vehicle nodes change rapidly, and the modularity at each moment is different. The simulation experiment selected 6 representative speed scenarios covering from low speed to high speed in the range of 5m / s to 30m / s, tracked and recorded the vehicle cluster structure per second, and calculated the modularity second by second, obtaining the variation curve of the vehicle cluster structure strength over time.

[0253] As Figure 16 shown, in the scenario where the maximum vehicle speed is 5m / s, the vehicle cluster adopting the SOCM model achieves a relatively high structural strength at each moment. This shows that in the low-speed scenario, the SOCM model can enable the vehicle cluster to have a relatively high structural strength.

[0254] As Figure 17 shown, when the maximum vehicle speed is 10m / s, the structural strength of the vehicle cluster represented by the red line of the SOCM model is significantly higher than that represented by the green line of the NDCE evolution method. This shows that in the medium and low-speed scenarios, the SOCM model has obvious advantages in terms of vehicle cluster structural strength.

[0255] As Figure 18 shown, in the scenario where the maximum vehicle speed is 15m / s, the vehicle cluster adopting the SOCM model achieves a relatively high modularity at most moments; at some fluctuating moments, it is slightly lower than the NDCE evolution method. This shows that in the medium-speed scenario, the SOCM model can enable the vehicle cluster to have a relatively high structural strength.

[0256] As Figure 19 shown, in the scenario where the maximum vehicle speed is 20m / s, in the initial period of evolution, the structural strength of the vehicle cluster adopting the SOCM model lags slightly behind the NDCE evolution method, and in the subsequent evolution process, it significantly leads the vehicle cluster of the NDCE method. This indicates that in the medium-speed scenario, this model can achieve a slightly better vehicle cluster structural strength.

[0257] As Figure 20 shown, in the scenario where the maximum vehicle speed is 25m / s, in the initialization stage of the vehicle cluster adopting the SOCM model in the initial period of evolution, its structural strength lags slightly behind the NDCE evolution method; in the subsequent evolution process, the vehicle cluster of the SOCM model significantly leads the NDCE evolution method. This indicates that in the medium and high-speed scenario, this model can achieve a better vehicle cluster structural strength.

[0258] As Figure 21As shown in the figure, in the scenario where the maximum vehicle speed is 30 m / s, the structural strength of the vehicle group adopting the NDCE evolution method fluctuates greatly, and slightly leads the vehicle group adopting the SOCM model at individual moments. During most of the evolution process, the vehicle group adopting the SOCM model has a higher structural strength. It shows that in the high-speed scenario, the SOCM model can enable the vehicle group to achieve a higher structural strength.

[0259] The large fluctuations in the line chart are due to the fact that the experiment simulated that the vehicle was attacked by the network and separated from the vehicle group, resulting in significant changes in the vehicle group structure. Based on the above analysis, it shows that in the above-mentioned speed scenarios, the SOCM model makes the vehicle group structure have a higher strength and the vehicle group achieves better safety.

[0260] 3) Average risk assessment utility of the vehicle group

[0261] The average risk assessment utility of the vehicle group quantifies the overall safety of the vehicle group. The simulation experiment selected 6 representative speed scenarios covering low speed to high speed in the range of 5 m / s to 30 m / s, and tracked and recorded the changes in the average risk assessment utility of the vehicle group in real time.

[0262] As Figure 22 shown, in the scenario where the maximum vehicle speed is 5 m / s, the average risk assessment utility of the vehicle group adopting the SOCM model is slightly lower than that of the vehicle group adopting the NDCE evolution method at the initial stage of the vehicle group; at most subsequent moments, it is significantly higher than the NDCE evolution method. It shows that in the low-speed scenario, the SOCM model has an obvious advantage in the average risk assessment utility of the vehicle group.

[0263] As Figure 23 shown, in the scenario where the maximum vehicle speed is 10 m / s, the average risk assessment utility of the vehicle group represented by the red line of the SOCM model is lower than that of the NDCE evolution method represented by the green line at the initial stage of the vehicle group; at most subsequent moments, the red line fluctuates greatly but is higher than the green line. It shows that in the medium and low-speed scenarios, the SOCM model can keep the overall safety of the vehicle group slightly higher.

[0264] As Figure 24 shown, in the scenario where the maximum vehicle speed is 15 m / s, the average risk assessment utility of the vehicle group adopting the SOCM model is slightly lower than that of the vehicle group adopting the NDCE evolution method at the initial stage of the vehicle group; at most subsequent moments, it significantly leads the NDCE evolution method. It shows that in the medium-speed scenario, the SOCM model has a significant advantage in the average risk assessment utility of the vehicle group.

[0265] As Figure 25As shown, in multiple scenarios where the maximum vehicle speed is 20 m / s, the average risk assessment utility of the vehicle group of the SOCM model represented by the red line is lower than that of the NDCE evolution method represented by the green line during the vehicle group initialization stage; thereafter, the red line is significantly higher than the green line at most times. This shows that in medium-speed scenarios, the SOCM model can keep the overall vehicle group at a relatively high level of safety.

[0266] As Figure 26 shown, in multiple scenarios where the maximum vehicle speed is 25 m / s, the average risk assessment utility of the vehicle group of the SOCM model represented by the red line is slightly lower than that of the NDCE evolution method represented by the green line during the vehicle group initialization stage; thereafter, the red line fluctuates to some extent, but is higher than the NDCE evolution method at most times. This shows that in medium-high speed scenarios, the SOCM model can keep the overall vehicle group at a relatively high level of safety.

[0267] As Figure 27 shown, when the maximum vehicle speed is 30 m / s, the average risk assessment utility of the vehicle group using the SOCM model is significantly higher than that of the NDCE evolution method. This shows that in high-speed scenarios, the SOCM model can ensure the safety of the vehicle group.

[0268] There are large fluctuations in the line chart because the experiment simulated that the vehicle was attacked by the network and detached from the vehicle group, resulting in a large change in the vehicle group structure. As can be seen from the figure, during the subsequent evolution process, the average risk assessment utility of the vehicle group can quickly recover to a relatively high level.

[0269] In summary, in the above various speed scenarios, it shows that the SOCM model can enable the driverless vehicle group to obtain a relatively high average risk assessment utility and keep the overall vehicle group at a relatively high level of safety.

[0270] Innovation points

[0271] The technical solution provided by this invention application is as follows: In view of the current lack of a self-coordination model for safe driverless vehicle groups, considering the safety state perception and countermeasures in the process of the dynamic evolution method of driverless vehicle groups, as well as problems such as poor maintainability of member certificates in existing communication schemes for manned vehicle groups, a driverless safety evolution method is given. An easy-to-maintain key update protocol is given based on the revocation polynomial. A safe self-coordination model for driverless vehicle groups is given and its security is proved. Through simulation experiments, the security of the self-coordination model is verified according to the corresponding security evaluation indicators. Thus, a self-coordination model that can continuously maintain intelligent motion behavior during the high-dynamic evolution process of a safe driverless vehicle group is given, making it possible for it to be applied in actual scenarios.

[0272] Appendix of the specification

[0273] Table 1

[0274]

[0275]

[0276] Table 2

[0277]

[0278] Table 3

[0279]

[0280] Table 4

[0281]

[0282]

[0283] Table 5

[0284]

[0285] Table 6

[0286]

[0287] References

[0288] [1] Cheng J J, Cao C R, Zhou M C, et al. A Dynamic Evolution Mechanism for IoV Community in an Urban Scene[J]. IEEE Internet of Things Journal, 2020.

[0289] [2] https: / / www.first.org / cvss / 。

Claims

1. A method for constructing a secure self - coordination model for a driverless vehicle group, characterized in that, specifically includes the following steps: Step 1. A dynamic evolution method for a driverless vehicle group based on risk - assessment utility Step 1.1 Related definitions Definition 1 Distance function dist: The vehicle - group formation algorithm uses the Euclidean distance to measure the distance between two vehicle nodes, that is: Among them, v i , v j represents a vehicle node, and (x, y, z) are the coordinates of the vehicle node in three-dimensional space; Definition 2 Risk Evaluation Utility REU: The risk of the nodes of the driverless vehicle fleet is evaluated from three aspects: the estimated loss level, threats, and vulnerabilities, and the risk utility evaluation REU is given as a safety metric for the vehicle fleet; the REU of the driverless vehicle node v i at time t is as follows: Among them, the int function is used to convert the ELL level into the corresponding positive real value, and generally a monotonically increasing function is selected; the value of α is set according to the value range of the int function to make the REU value have obvious discrimination; They respectively correspond to the scores of the basic indicators, the life cycle indicators, and the environmental indicators in the CVSS scoring system. The higher the score, the higher the severity of the vulnerability; Definition 3 Core node CN: When the number of neighbor nodes of a node within the ε - neighborhood reaches τ and the REU is higher than more than half of its neighbor nodes, this node is called a core node; at this time, the REU of the node needs to be recalculated according to formula (1.1): where V is the set of all nodes within the ε - neighborhood of the node, including the node itself, and |V| is the number of elements in the set V. The core node mainly shares the communication and computing loads of the master node; Definition 4 Master node MN: A core node needs to be upgraded to a master node through an election mechanism. A node can be upgraded to a master node only when it meets the following conditions: (1) This node is a core node; (2) The REU value is higher than more than half of its neighbor core nodes, or there are no other core nodes; The neighbor core nodes of the master node act as secondary nodes, responsible for maintaining the communication between its sub - vehicle group and the master node; when there is only one core node in the vehicle group, this core node is still upgraded to the master node. At this time, there are no secondary nodes in the vehicle group, and the REU of the master node needs to be updated according to formula (1.2) where V is the set of the core nodes and their sub - vehicle groups under the master node; Definition 5 Boundary node: If a noise point is within the ε - neighborhood of a certain core node, it is upgraded to a boundary node after receiving the heartbeat packet from the core node. At this time, the node officially joins the vehicle group, that is, the node can join the vehicle group when it meets the following conditions: Among them, N i is the neighbor set of node v i , and v c is a core node in its neighbor set; Definition 6 Noise node NN: It is neither a core node nor a boundary node. There are no core nodes or master nodes within the neighborhood of such a node; if there is a core node in its neighborhood, this node can be added to the topological network formed by the vehicle group at this time; otherwise, this node does not participate in the construction of the vehicle group; Step 1.2 Driverless vehicle - group events and processing algorithms (1) Driverless vehicle - group growth event (2) Driverless vehicle - group reduction event (3) Driverless vehicle - group merger event (4) Driverless vehicle - group split event Step 1.3 Driverless vehicle - group evolution algorithm The complete secure evolution method for a driverless vehicle group is shown in Algorithm 5. The specific steps of this algorithm are as follows: 1) Traverse the evolution - event set of the vehicle group, and this set is continuously updated during the life cycle of the vehicle group; 2) For the growth event, execute the node - addition algorithm; for the reduction event, execute the node - departure algorithm; for the merger event, execute the vehicle - group merger algorithm; for the split event, execute the vehicle - group split algorithm; 3) Update the vehicle set V after processing the evolution event n ; Step 2. Secure self - coordination model for a driverless vehicle group Step 2.1 Related definitions Definition 1 Vehicle - identity real number vid: vid is obtained by calculating (1): vid i = H(ELP i , MAC i ) (1) Among them, ELP represents the electronic license plate of the vehicle, MAC represents the MAC address used by the vehicle in network communication, and the ELP and MAC address are converted into the vehicle identity real number vid through the binary mapping function H to uniquely identify a specific vehicle; Definition 2 Common revocation polynomial R(x): This polynomial is jointly maintained by the vehicle group and is used to replace the revocation - certificate list CRL used in the traditional CA. It is defined by formula (2): Among them, S r is the set of real numbers of vehicle identities corresponding to vehicle nodes excluded by the vehicle group. It can be seen from the definition that for any r i ∈S r , R(r i ) = 0; Definition 3 Private revocation polynomial r(x): This polynomial is generated based on R(x). When a new malicious node is found, its vid is added to r(x). r(x) is used to temporarily replace CRL and is maintained separately by the vehicle node. It is defined as follows: where t is the lowest degree of the polynomial, and r j ′ is a randomly generated real number used to complement the degree of the polynomial; as can be seen from the definition, R(x) is a factor of r(x), and equation (3) defines the generation of the revocation certificate polynomial. The finally used polynomial is the result after its calculation, as shown in formula (4): Definition 4 Mask polynomial s(x): This polynomial is used for obfuscation to prevent the key from being cracked. The mask polynomial of vehicle v i is separately stored by this vehicle and will not be leaked to other vehicles. Its form is: where n is the degree of r(x), so s i (x) has the same degree as r(x); Define the 5 - key polynomial φ(x): This polynomial is generated by the revoked - certificate polynomial, the masking polynomial, and the public key PK i of vehicle node v i and is used to transfer keys, and its definition is as follows: φ i (x) = PK i r(x) + ε t s i (x) (6) Among them, ε t is a coefficient randomly generated temporarily during communication. When vehicle node v i transmits a secret key to vehicle node v j the secret key polynomial is Replace ε with Δ i,j s t s i (j), when node v j Obtain Δ i,j After obtaining Δ and r(x), the public key PK i can be calculated as follows: Definition 6: The set of vehicle group attributes M is the set of all attributes involved in the vehicle group safety self-coordination model, which can be represented by the following five-tuple: M=<V,G,S,F,R(x)> (9) Among them, V = {v i | i = 1, 2…, n} represents the set of all vehicle nodes; G = {G i | i = 1, 2…, n} represents the set of all vehicle groups; R(x) is represented as a revocation polynomial, which is used to maintain the communication security between the vehicles; F = {f i | i = 1, 2…, n} represents the vehicle group evolution events, which are mainly divided into seven events: node joining f 1 , vehicle group joining f 2 , boundary point leaving f 3 , core / master node leaving f 4 , boundary point exclusion f 5 , core / master node exclusion f 6 , attack detection f 7 . Different events will cause corresponding state changes; S represents the state of the vehicle group, and seven states are defined in this model, namely the initialization state S 0 , the growth state S 1 , the reduction state S 2 , the merging state S 3 , the splitting state S 4 , the non-safe state S 5 , and the safe self-coordination state S 6 ; Define the initial state S 0 : Form a new vehicle group G i , where v i represents the main node. At this time, the vehicle group set G = G ∪ G i ; The main node broadcasts the revocation polynomial R(x) to all nodes in the vehicle group. At this time, for all need to verify the reliability of the surrounding neighbor vehicles through R(x), and then use the ECDH method to exchange keys with the verified reliable nodes; Define the growth state S 1 : When the node v at time t j joins the vehicle group G i the state of the model is updated as follows: At this time, v j Obtain the revocation polynomial R(x) from the main node, and then use the ECDH method to exchange keys with the surrounding reliable nodes; Definition 9 Reduced state S 2 : When the boundary node v j leaves the vehicle group G i at time t, the state of the model is updated as follows: Definition 10 Merging State S 3 : When the secondary structure vehicle group G j merges into another vehicle group G i at time t, the state of the model is updated as follows: At this time, the master node updates the revocation polynomial R(x), and the nodes originally belonging to vehicle group G j and vehicle group G i exchange public keys with each other; Definition 11 Split state S 4 : When at time t the secondary structure vehicle group G j detaches from the vehicle group G i the state of the model is updated as follows: At this time, the master node updates the revocation polynomial R(x) based on the existing nodes in the swarm and broadcasts it to the swarm members; Definition 12 Non-safe state S 5 : For a vehicle group G i , When a forged message is detected, node v j confirms the identity of the forger v k After that, the key update process starts; after the process ends, the non-malicious nodes in the vehicle group complete the key update, and at the same time, the forger is excluded from the vehicle group and added to the revocation polynomial R(x). The revocation polynomial R(x) will be updated; the state of the model is updated as follows: Definition 13: Secure Self-Conciliation State S 6 : After the vehicle group undergoes evolutionary events caused by regular changes in nodes or the exclusion of malicious nodes, it returns to the secure self-conciliation state, that is, other evolutionary states ultimately return to the secure self-conciliation state Step 2.2 Key update protocol based on revocation polynomial Step 2.3 Autonomous vehicle group safety self-coordination model The autonomous safety model of the unmanned vehicle group is defined as follows: 1) Attack Model This attack model considers attackers from inside and outside the swarm. Both the sender and receiver of the message may act as internal attackers. External attackers act as intruders, and their attack types are assumed to be limited to eavesdropping. According to the attack behavior, attacks can be divided into active attacks and passive attacks: passive attacks mainly refer to eavesdropping attacks, and active attacks refer to injecting forged messages into the swarm network. 2) Safety goals a. Message integrity: The autonomous vehicle swarm self-coordination model can maintain the integrity of the message; the content of the message sent by the sender vehicle should be guaranteed not to be modified when it is delivered to the recipient vehicle; b. Anti-eavesdropping: Except for the designated message recipient vehicle, other vehicles cannot decipher the message; c. Vehicle revocability: Once a vehicle's identity is revoked, it will be excluded from the vehicle group and cannot be added to the vehicle group network again; 3) Security Assumptions a. The identities of the nodes in the swarm are public and real-name; b. The attacker's passive attack will not be discovered by the swarm, because when the distant nodes in the swarm cannot communicate directly, relay nodes are needed to forward messages. In this process, eavesdropping on the messages cannot be prevented; c. The attacker can be detected by the swarm and know his identity when performing active attacks. This can be achieved by tracing the nodes on the message propagation path. In the swarm model of this paper, there are at most three relay nodes between two nodes. d. All members of the swarm can ensure the security of their encryption credentials; e. Potential attackers are considered ordinary nodes before they are discovered; f. There is no collusion among the attackers; 4) Safety self-coordination model According to the revocation polynomial-based key update protocol and the dynamic evolution method of the safety of the unmanned vehicle group, the safety self-cooperation model of the unmanned vehicle group can be obtained, as follows: where f t ∈F, S t ∈S, and the change of the state S t triggered by f t complies with the constraints in Definitions 7 to 13; The swarm follows the above steps to handle safety events and swarm changes, and finally reaches a safe self-coordination state after the evolving events are over.

2. A method for constructing a safe autonomous model for a group of unmanned vehicles as claimed in claim 1, It is characterized in that The unmanned vehicle group event and processing algorithm are defined as follows: (1) The growth of driverless vehicles The group growth event indicates that a new node joins the autonomous vehicle group. When a new node is not in the ε neighborhood of any core node in the autonomous vehicle group, the node is considered to be outside the group. When a new node is within the ε-neighborhood of a core node in a vehicle group, after receiving the heartbeat message from the core node, the node can join the vehicle group and become a boundary node; The processing algorithm for vehicle group growth events is as follows: (2) Unmanned vehicle group reduction event The vehicle group reduction event means that a boundary node leaves the unmanned vehicle group, and the vehicle group does not change significantly. After the core node does not receive the heartbeat message of the boundary node it manages for a period of time, the boundary node will be reset to a noise node; The processing algorithm for vehicle group reduction events is as follows: (3) Unmanned vehicle group merging event The vehicle group merging event is mainly divided into two types: (1) The situation where two smaller two-layer architecture vehicle groups merge into a larger vehicle group; (2) A smaller two-layer architecture vehicle group merges into a larger three-layer architecture vehicle group; The processing algorithm for vehicle group merging events is as follows: (4) Unmanned vehicle group splitting event The loss of a key node in the unmanned vehicle group will lead to the occurrence of a vehicle group splitting event, and the structure of the vehicle group will change significantly. The splitting event is mainly divided into the following two situations: (a) The sub-vehicle group detaches from the main vehicle group due to the loss of the core node; (b) The entire vehicle group structure splits into multiple sub-vehicle groups due to the loss of the main node; If the main node leaves and the core node does not receive the heartbeat message for a period of time, at this time the core node will leave the vehicle group and become an independent two-layer structure vehicle group, and at the same time start to execute the logic of vehicle group merging, preparing to reorganize a new three-layer architecture vehicle group, which may lead to various results according to the logic of vehicle group evolution; If the core node leaves, the boundary node will be reset to a noise node, and the processing algorithm is as follows:

3. As described in claim 1, a method for constructing a security self-coordination model of an unmanned vehicle group, characterized in that, The key update protocol based on the revocation polynomial is defined as follows: In the initialization stage of vehicle group communication, vehicle nodes will exchange public keys through the elliptic curve key exchange method; When a malicious node is detected in the vehicle group, this protocol can be used to update the key so that the malicious node cannot obtain the new key; The steps of this protocol are as follows: 1) Node v i and Node v j exchange keys through ECDH during the vehicle group initialization phase; 2) Node v i A new malicious node v is found in the vehicle group r , and it is ready to update its public key and send this message out; Node v i First, construct the revocation polynomial r(x) based on the vid of node v r and R(x); 3) Node v i Generate the masking polynomial s i (x) to ensure that the degrees of s i (x) and r(x) are the same; 4) Node v i Broadcast the message tuple <vid i , φ i (x)> to all nodes in the vehicle group; 5) Node v j After receiving the message, first verify that R(vid i ) ≠ 0, otherwise ignore this message; then encrypt its own vid with the old public key of node v j and send it to node v j ; 6) Node v i Calculate Δ i,j = ε t s i (v i d j ), and then encrypt the message tuple <r(x), Δ i,j > with the public key of node v j and send it to node v j ; 7) When node v j obtains Δ i,j and r(x), the new public key of v i can be calculated using formula (8).