Multi-Server Data Transmission Method Applicable to the Internet of Vehicles and Supporting Users to Hide Their Identities
Through the multi-server data transmission method, the separation management of the data transmission hub and the navigation center is used, combined with random jump and symmetric encryption technology, the problems of user identity privacy and data transmission security in the Internet of Vehicles are solved, achieving higher security and stability.
Patent Information
- Application Number
- CN202310455359.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-25
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2043-04-25
AI Technical Summary
In the Internet of Vehicles, the privacy of user identity and data transmission security face threats such as traffic analysis, injection attacks, and time attacks, and the uneven allocation of network resources affects the real-time and accuracy of data.
The multi-server data transmission method is adopted, through the separation management of the data transmission hub and the data navigation center, the random jump strategy and symmetric encryption technology are used, combined with the three-color node method and traffic/path obfuscation, to ensure the security and stability of data transmission.
Effectively prevent traffic analysis and malicious attacks, reduce data transmission errors, improve the stability and security of the transmission process, reduce server resource waste, and enhance user privacy protection.
Smart Images

Figure CN116506174B_ABST
Abstract
Description
Technical Field
[0001] The present technical solution relates to the technical field of data transmission, and more specifically to the privacy security and data security of vehicle data and user data in the Internet of Vehicles during transmission. Specifically, the present technical solution relates to a multi-server data transmission method suitable for the Internet of Vehicles that supports users to hide their identities. Background Art
[0002] As the application of Internet of Vehicles becomes more and more widespread, information is easily monitored, tampered with or forged during transmission. When the information is received by the Internet of Vehicles service provider, some companies will also collect and analyze the owner's personal information, vehicle usage habits, driving routes and other sensitive data, and then use it for commercial activities. In addition, if the service provider's security measures are not perfect, it may also be attacked by hackers, resulting in user information leakage. In order to solve the privacy problem of Internet of Vehicles, Xu et al. proposed a certificateless signature scheme based on bilinear pairings: the on-board unit signs the routing related information, and then aggregates all signatures to generate an aggregate signature and send it to the corresponding trusted institution; Mistareehi, Islam and Manivannan proposed a distributed VANET architecture, which combines digital signatures and symmetric encryption technology to construct a cloud that can efficiently process different servers, thereby improving the privacy of the vehicle; Mei et al. proposed that the trusted center can generate multiple sets of pseudonymous identities for the vehicle at one time, and then frequently change the pseudonyms to avoid the risk of the vehicle being tracked, thereby achieving strong privacy protection; Zha ng et al. introduced temporary identities to achieve strong privacy protection for vehicles. Vehicles do not need to accept and store multiple temporary identities and corresponding partial private keys; Tolba and Ayman proposed a three-layer secure Internet of Vehicles architecture, which adopts reputation-based vehicle-assisted communication, in which the central agency is located in the first layer to perform node verification, and the roadside unit is retained in the second layer, so that the third layer nodes can communicate from vehicle to facility; Wang et al. proposed a new Internet of Vehicles reputation model based on blockchain technology, which uses a multi-key fully homomorphic encryption algorithm to encrypt data, and designs a backtracking time interval adaptive adjustment strategy, which effectively protects user privacy and improves the detection rate of malicious vehicle behavior.
[0003] In terms of multi-node data transmission, in order to effectively hide the identities and behaviors of users, Chaum designed the Mix-Net system. It hides the sender and receiver of messages by storing and forwarding information. The sender selects several intermediate nodes locally. These intermediate nodes are called Mix nodes. The message is encrypted multiple times according to the routing and then sent. Each time it passes through an intermediate node, it will be decrypted and re-encrypted to obtain a new ciphertext. After reaching the last intermediate node, the server forwards the plaintext obtained by decryption to the receiver. However, a system based on store-and-forward cannot implement some real-time applications. Therefore, Tor emerged: an open-source connection-oriented data transmission system that can provide users with visual operations such as web browsing. In Tor, the sender establishes a data transmission path through a proxy and uses the Diffie-Hellman key exchange protocol. This data transmission path consists of multiple onion routers as intermediate nodes, and negotiates the encryption algorithm and key with each onion router on the path in sequence, and uses the AES algorithm to replace the public key encryption in the onion router to achieve forward secrecy.
[0004] With the development of network forensics, the security of Tor has been increasingly threatened. Therefore, some new data transmission schemes have emerged. Atom adopts the ElGamal variant encryption scheme. The sender does not need to select a route but rearranges and forwards at each layer of Mix nodes to ensure the security of data transmission; Loopix uses a mixed strategy of concealing traffic and Possion-Mix to provide the security of both communication parties; DiceMix divides the transmission process into 4 stages, with a difference of two stages between each round and runs in a pipeline manner to reduce the impact of malicious nodes on performance. The Express system only generates a fixed silver overhead for each message and only uses symmetric encryption primitives, improving the message throughput and reducing latency; The Pynchon Gate combines the Mix network and PIR technology to achieve the privacy security of email senders and receivers. Defects of the existing technologies:
[0005] With the rapid development of the Internet of Vehicles, the privacy of user identities and the security of data transmission have become increasingly important. During data transmission, vehicles need to transmit information such as vehicle location, driving speed, and vehicle condition to Internet of Vehicles service providers. Such information can use relatively secure network systems like Tor to ensure the security of data transmission. However, if the number of data packets processed during transmission is too large, it is easy to attract the attention of attackers. In addition, this information also contains relevant information about user identities. Therefore, this information is very likely to be subject to malicious acts such as interception, replay, and tampering by attackers. With the development of attack techniques, the Internet of Vehicles system is also difficult to avoid new attack methods such as fingerprint attacks and Sniper attacks, resulting in a further reduction in the security of data during network transmission. User information may also be collected and analyzed by illegal enterprises for commercial purposes, and any party may expose their identity during use, thus threatening the safety of vehicles, drivers, and passengers. The Internet of Vehicles also needs to consider the network efficiency issue during data transmission. If network resources are unevenly allocated, it will affect the timeliness and accuracy of vehicle data. Summary of the Invention
[0006] The purpose of this technical solution is to address the deficiencies of the prior art and provide a multi-server data transmission method applicable to the Internet of Vehicles that supports users in hiding their identities. This method can prevent third parties from conducting traffic analysis, injection attacks, and timing attacks, reduce data transmission errors caused by network reasons when re-establishing a new link during data link congestion, improve the stability during transmission, and prevent malicious sending during communication.
[0007] The technical solution for achieving the purpose of this technical solution is as follows:
[0008] A multi-server data transmission method applicable to the Internet of Vehicles that supports users in hiding their identities, including the following steps:
[0009] 1) Define the structure of the data transmission system: The data transmission system is equipped with a group of servers, which are provided and managed by a trusted institution, namely the government or a communication operator. The servers are divided into a data transmission hub and a data navigation center. The sender in the data transmission system is a vehicle, and the receiver is a data processing center, i.e., a manufacturer providing vehicle networking services. Among them, the data transmission hub is equipped with a group of servers, which are called data transmission servers. The resource configurations of each data transmission server are different, but all are used for transmitting data. Before the data transmission path is generated by the data navigation center, no active communication can occur between any data transmission servers in the data transmission hub. The data navigation center is equipped with a main server and a group of backup servers. The data navigation center is the server that the vehicle needs to request before sending data. It is mainly responsible for managing all data transmission servers in the data transmission hub, including managing the IP addresses and current status of these data transmission servers, and is responsible for generating a trusted data transmission path from the vehicle to the data processing center. At the same time, this technical solution also needs to ensure the normal operation of the data navigation center, so multiple backup servers can be set up in case of emergencies. There are three databases in the data navigation center, namely the server information database, the link cache database, and the sender status database;
[0010] 2) System initialization: After the sender has collected the data to be sent, it first requests the data navigation center. The data navigation center generates a data transmission link based on the number of surviving servers in the current data transmission hub and the amount of data that can be tolerated. This data transmission link contains multiple data transmission servers, which are called intermediate nodes between the sender and the receiver. The sum of the number of these intermediate nodes is defined as the number of hops of the data in the data transmission hub. After the data transmission link is established, the first intermediate node, i.e., the hub entrance, and the last intermediate node, i.e., the hub exit, will respectively verify the sender and the receiver. If the verification passes, they will be saved in the link cache database. Specifically:
[0011] 2-1) The number of hops of the data has a logarithmic relationship with the number of surviving servers in the data transmission hub. Among them, the total number of all servers in the data transmission hub is N. When all servers are alive, and the total number of servers N is greater than 4 and less than or equal to 256, the data packet jumps times in the data transmission hub, and the result is rounded down; when all servers are alive, and the total number of servers N is greater than 256, the data packet jumps times in the data transmission hub, and the result is rounded down; when there is a problem with the servers, i.e., the number of surviving servers is less than the total number of servers N, the data packet jumps Next, round down the result. If the calculated result is 0 or 1, it means that the data transmission hub cannot work properly. Therefore, after waiting for 15 minutes, the sender re-asks the data navigation center. If it still doesn't work the second time, it means that the current data transmission hub has failed, and the sender cannot use this system to transmit data;
[0012] 2-2) When the data transmission hub is running normally, the receiver waits for a server in the data transmission hub to send a connection establishment request to it. The sender first establishes a secure TLS connection with the data navigation center. In the system initialization stage, the link cache database is empty. At this time, the data navigation center generates the first available data transmission link. This data transmission link contains multiple intermediate nodes. The server connected to the sender is called the hub entrance, and the server connected to the receiver is called the hub exit. The data navigation center sends the relevant information of the hub entrance to the sender and the relevant information of the sender to the hub entrance. When the sender receives the connection establishment request sent by the hub entrance, if it is consistent with the information received by the sender from the data navigation center, then a connection is established. When the hub exit establishes a connection with the receiver, the hub exit needs to ensure whether the current receiver's information is consistent with the information held by the sender. If they are consistent, a connection is established;
[0013] 2-3) For the generated data transmission path in the data navigation center, that is, the establishment of the data transmission link, a random jump transmission strategy is adopted. Since the data transmission hub cannot be overloaded during use, the data navigation center counts the amount of data to be processed by each data transmission server in the data transmission hub during the transmission process and records the status of these data transmission servers. To prevent server overload, the threshold of the amount of data that each server may carry is set to 3 / 4 of the maximum bearable data volume. If the amount of data received or transmitted by any data transmission server in the data transmission hub is less than 3 / 4 of the set value, the current data transmission server is added to the alternative queue. If the amount of data received or transmitted by all data transmission hubs is greater than 3 / 4 of the set value, the earliest requested data transmission server is put into the alternative queue. These earliest data transmission processing servers release the required resource space over time and due to the completion of data transmission. After detecting the status of all servers, the number of servers in the alternative queue is greater than or equal to the current server's hop count, and the alternative queue is shuffled using a shuffling algorithm, and the first few servers are selected as the servers of the transmission link;
[0014] 3) Data processing: Before the data transfer starts, the ciphertext parameters between adjacent two servers need to be exchanged between the data transmission links generated in step 2). Decrypt according to the ciphertext parameters to obtain the symmetric encryption key, and then encrypt the data using the symmetric encryption key. Specifically:
[0015] 3-1) Initialization Phase: To ensure the security of data during transmission, the sender, the receiver, and the server in the data transmission hub all need to select a cyclic group \(G\) of prime order \(q\) with \(g\) being the generator of the cyclic group during the initialization phase. They also need to select a collision-resistant hash function \(H(\cdot)\) whose input can be of any length and output is an element in . Finally, they need to select a symmetric encryption method \(S=(Enc, Dec, key)\). Let the transmission path of data from the sender to the receiver be \(R\), which is represented as an ordered set \(R = \{R_1, R_2, \ldots, R_{ n-1}, R_{ n}\}\). There are a total of \(n\) nodes on the \(R\) path including the sender and the receiver, where \(R_1\) is the sender, \(R_{ n}\) is the receiver, and \(R_2\) to \(R_{ n-1}\) is the path of data in the data transmission hub. \(R_2\) is the hub entrance and \(R_{ n-1}\) is the hub exit. on , and finally, they also need to select a symmetric encryption method \(S=(Enc, Dec, key)\). Let the transmission path of data from the sender to the receiver be \(R\), which is represented as an ordered set \(R=\{R_1, R_2, \ldots, R_{ n-1}, R_{ n}\}\). There are a total of \(n\) nodes on the \(R\) path including the sender and the receiver, where \(R_1\) is the sender, \(R_{ n}\) is the receiver, and \(R_2\) to \(R_{ n-1}\) is the path of data in the data transmission hub. \(R_2\) is the hub entrance and \(R_{ n-1}\) is the hub exit; n-1 , \(R_{ n}\) n}\), and there are a total of \(n\) nodes on the \(R\) path including the sender and the receiver, where \(R_1\) is the sender, \(R_{ n}\) n is the receiver, and \(R_2\) to \(R_{ n-1}\) n-1 is the path of data in the data transmission hub. \(R_2\) is the hub entrance and \(R_{ n-1}\) n-1 is the hub exit;
[0016] 3-2) Symmetric Encryption Key Exchange: In the symmetric encryption key exchange phase, each node \(R_{ i}\) in \(R\) i needs to generate its own private key \(x_{ i}\) i and public key \(d_{ i}\) i , where and each node also needs to generate its own secret value \(k_{ i}\) i , where , \(\lambda_{ i}\) i is the timestamp of \(R_{ i}\) i and \(IPaddr_{ i}\) i is the IP address of \(R_{ i}\) i . For the generation of the symmetric key, if the current is the hub exit \(R_{ n-1}\) n-1 or the receiver \(R_{ n}\) n , then let \(K_{ i}\) i be equal to the secret value of the current server, that is, \(K_{ i}\) i = \(k_{ i}\) i . If it is not the hub exit \(R_{ n-1}\) n-1 or the receiver \(R_{ n}\) n , the symmetric key is obtained by XORing the symmetric encryption key sent from the next level and the secret value of the current intermediate node level by level starting from the hub exit in the data transmission path, that is, where \(K_{ i-1}\) i-1 is the symmetric key generated by the next-level server \(R_{ i}\) i . The sender does not need to generate the symmetric key \(K_{ i}\) i , and then the current node \(R_{ i}\) i randomly selects to calculate:
[0017]
[0018] π i = H(c i,1 , c i,2 , c i,3 , IPaddr l ),
[0019]
[0020] Send the parameters (c i,1 , c i,2 , c i,3 , c i,4 ) to the upper-level node R i of the current node R i-1 . After the upper-level node obtains these parameters, it first calculates:
[0021] π i ' = H(c i,1 , c i,2 , c i,3 , IPaddr i ),
[0022] Then verify:
[0023]
[0024] If it holds, then use the private key x i of the current node R i-1 to decrypt the ciphertext and calculate:
[0025]
[0026] 3 - 3) Data Encryption Verification Phase: In the data encryption verification phase, the current node R i randomly generates Let the key of symmetric encryption be key = K i , and perform the following calculations on the data M to be transmitted:
[0027]
[0028] E i = S.Enc(M, K i ),
[0029] h i = H(M||K i , H(M), V i ),
[0030] σ i = x i h i + v i ,
[0031] Then the current node goes to the next-level node R i+1 and sends the encrypted message E i , the hash value h i and the message signature σ i . After receiving these parameters, the next-level node R i+1 performs the following calculations on the message E i , the hash value h i and the message signature σ i :
[0032] M′ = S.Dec(E i , K i ),
[0033]
[0034] Then verify whether the following equation holds:
[0035]
[0036] If the equation holds, the nodes on the link continue to perform the operations in the data encryption verification phase until the data M is transmitted to the receiver;
[0037] 4) Judgment of the sender's credibility: During the data transmission process, when the sender successfully establishes a connection with the hub entrance, the data navigation center disconnects from the sender. At the same time, after disconnecting, the data navigation center saves the data transmission path generated by the current sender in the link cache database. The data navigation center has a sender status database, and there is a status field in this database to judge the credibility of the sender. The status field has three colors: green, yellow, and red. Specifically:
[0038] 4-1) For the sender marked with the color green, it indicates that the current sender is a trustworthy user for the receiver. In the initial stage, the sender is trustworthy. The sender generates a new data transmission path connection through the data navigation center and then saves this data transmission path in the link cache database. If the sender needs to establish a connection with the receiver again within less than 12 hours, then directly call the path information saved in the link cache database. If the link cache database does not have the data transmission connection established by the current sender before, then request a new data transmission path again, and the receiver and the hub exit perform re-verification, and the hub entrance re-verifies the sender. If it passes, the sender is marked as green; if it fails, the sender is marked as yellow;
[0039] 4-2) For the sender with a yellow marked color, it means that the current sender is not fully trusted by the receiver, that is, an exception occurred when the hub entrance established a connection with the sender. The data navigation center sends a warning message to the sender through the hub entrance and waits for 30 minutes to re-establish the connection. If it passes, the sender is marked green; if it fails, the sender is marked red.
[0040] 4-3) If the current sender is marked red, then the receiver considers the sender to be completely untrustworthy, that is, an exception occurred during the data transmission between the sender and the hub entrance. If the verification between the hub entrance and the sender fails multiple times, then the data navigation center marks the current sender red and instructs the hub entrance to abandon establishing a connection with the sender. In addition, to prevent the abuse of server resources, the data navigation center also needs to save the generated link information in the link cache database for 24 hours. If the sender needs to send a large amount of data, that is, in the case of establishing multiple transmission connections, then it needs to be judged by the data volume. If the transmitted data is all small-flow data but occupies a large amount of the data volume that the hub entrance can handle, at this time the sender may be controlled by an attacker and attack the hub entrance. The data navigation center marks the current sender red and deletes the link information of the current sender in the link cache database. When the data is sent normally, it is judged whether the data volume that the current hub entrance can handle is greater than 2 / 3 and whether the size of the transmitted data is greater than the amount that the hub entrance can handle. If so, the data is transmitted; if not, a new connection is re-established to transmit the data. If the same situation occurs again, then the receiver considers the current sender unreliable. The data navigation center has the right to notify the central node to close the connection and delete the relevant data in the link cache database, and mark the current sender as a red node. When the node is marked red, the vehicle or user needs to apply to the data processing center to regain the permission to transmit data.
[0041] 5) Traffic obfuscation and path obfuscation: To prevent data traffic from being stolen and analyzed by a third party during transmission, a masked traffic is generated. To prevent time attacks, new intermediate nodes are added during transmission. Specifically:
[0042] 5-1) Traffic Obfuscation: Before forwarding data packets, the central node determines whether to generate obfuscating traffic by flipping a coin. If it lands on heads, obfuscating traffic is generated; otherwise, it is not. That is, the probability of generating obfuscating traffic follows a 0-1 distribution. To distinguish between original data and obfuscating traffic, the obfuscating traffic is either a concatenation of partial data and random characters, or all 0s and all 1s, but it is ensured that the data length of the obfuscating traffic is equal to that of the original data. During transmission, any data transmission service records multiple nodes as alternative nodes. If the current central node needs to forward obfuscating traffic, it randomly selects one node from these alternative nodes and encrypts and sends the generated obfuscating traffic to it regardless of the status or traffic volume of this random node. Normal data is transmitted according to the known data transmission path;
[0043] 5-2) Path Obfuscation: During the data transmission phase, the sender and receiver are vulnerable to time attacks, i.e., when both the hub entrance and the hub exit are occupied by a third party, the correlation of the data is changed. That is, an additional hop between central nodes is added within time w, and a new server outside this transmission link is selected to join the intermediate nodes to increase the transmission time, thereby changing the correlation between data packets.
[0044] This technical solution addresses the problem of user information or vehicle data leakage during the data transmission process in the vehicle network. Multiple intermediate servers are added between users and vehicles and the data processing center to transmit data, thereby better protecting the identity privacy of users and vehicles. The new message passing strategy effectively reduces server resource waste, and the three-color node method effectively reduces the threat of malicious nodes to the communication process.
[0045] This method can prevent third parties from conducting traffic analysis, injection attacks, and time attacks. When re-establishing a new link during data link congestion, it reduces data transmission errors caused by network reasons and improves the stability during the transmission process. It can prevent malicious sending situations during the communication process. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 It is a schematic diagram of the system structure in the embodiment;
[0047] Figure 2 It is a flowchart in the embodiment. DETAILED IMPLEMENTATION MANNER
[0048] The following further elaborates on the content of this technical solution in conjunction with the drawings and embodiments, but does not limit this technical solution.
[0049] Embodiment:
[0050] Refer to Figure 2, A multi-server data transmission method applicable to the vehicle network to support users in hiding their identities, including the following steps:
[0051] 1) Define the data transmission system structure: As Figure 1 shown, Figure 1 In the figure, the solid line is the normal data transfer process, the dashed line is the masking traffic generated during the transmission and sent to other servers, and the dotted line is that a new central node may be randomly selected to join the link during the transmission process. The data transmission system is provided with a group of servers, which are provided and managed by a trusted agency, namely the government or a communication operator. The servers are divided into data transmission hubs and data navigation centers. The sender in the data transmission system is a vehicle, and the receiver is a data processing center, that is, a manufacturer providing vehicle network services. Among them, the data transmission hub is provided with a group of servers, which are called data transmission servers. The resource configurations of each data transmission server are different, but all are used to transmit data. Before the data navigation center generates a data transmission path, no data transmission server in the data transmission hub can initiate communication actively. The data navigation center is provided with a main server and a group of backup servers. The data navigation center is the server that the vehicle needs to request before sending data, and is mainly responsible for managing all the servers in the data transmission hub, including managing the IP addresses and current states of these data transmission servers, and is responsible for generating a trusted data transmission path from the vehicle to the data processing center. At the same time, in this example, it is also necessary to ensure the normal operation of the data navigation center, so multiple backup servers can be made in case of emergencies. There are three databases in the data navigation center, namely the server information database, the link cache database, and the sender status database;
[0052] 2) System initialization: When the sender has collected the data to be sent, it first requests the data navigation center. The data navigation center generates a data transmission link according to the number of surviving servers in the current data transmission hub and the size of the data that can be tolerated. This data transmission link contains multiple data transmission servers, which are called intermediate nodes between the sender and the receiver. The sum of the numbers of these intermediate nodes is defined as the number of hops of the data in the data transmission hub. After the link is established, the first intermediate node, that is, the hub entrance, and the last intermediate node, that is, the hub exit, will respectively verify the sender and the receiver. If the verification is passed, it will be saved in the link cache database. Specifically:
[0053] 2-1) The number of hops of the data has a logarithmic relationship with the number of surviving servers in the data transmission hub. Among them, the total number of all servers in the data transmission hub is N. When all servers are surviving, and the total number of servers N is greater than 4 and less than or equal to 256, the data packet jumps in the data transmission hub Secondly, round down the result; when all servers are alive and the total number of servers N is greater than 256, the data packet jumps in the data transmission hub times, and round down the result; when there is a problem with the server, that is, the number of alive servers is less than the total number of servers N, the data packet jumps in the data transmission hub times, and round down the result. If the calculated result is 0 or 1, it means that the data transmission hub cannot work properly. So after waiting for 15 minutes, the sender re - asks the data navigation center. If it still doesn't work the second time, it means that the current data transmission hub fails, and the sender cannot use this system to transmit data;
[0054] 2 - 2) When the data transmission hub is running normally, the receiver waits for a server in the data transmission hub to send a connection - establishment request to it, while the sender first establishes a secure TLS connection with the data navigation center. In the system initialization stage, the link cache database is empty. At this time, the data navigation center generates the first available data transmission link. This data transmission link contains multiple intermediate nodes. The intermediate node connected to the sender is called the hub entrance, and the intermediate node connected to the receiver is called the hub exit. The data navigation center sends the relevant information of the hub entrance to the sender, and sends the relevant information of the sender to the hub entrance. When the sender receives the connection - establishment request sent by the hub entrance, if it is consistent with the information received by the sender from the data navigation center, then a connection is established. When the hub exit establishes a connection with the receiver, the hub exit needs to ensure whether the current receiver's information is consistent with the information held by the sender. If they are consistent, then a connection is established;
[0055] 2 - 3) For the generated data transmission path in the data navigation center, that is, the establishment of the data transmission link, a random - jump transmission strategy is adopted. Since the data transmission hub cannot be overloaded during use, the data navigation center counts the amount of data to be processed by each data - transmission server in the data transmission hub during the transmission process and records the status of these data - transmission servers. To prevent server overload, in this example, the threshold of the data volume that each server may carry is set to 3 / 4 of the maximum bearable data volume. If the amount of data received or transmitted by any central node in the data transmission hub is less than 3 / 4 of the set value, the current data - transmission server is added to the alternative queue. If the amount of data received or transmitted by all data - transmission hubs is greater than 3 / 4 of the set value, the earliest - requested server is put into the alternative queue. These servers that start processing data transmission earliest release the required resource space over time and due to the completion of data transmission. After detecting the status of all servers, the number of servers in the alternative queue is greater than or equal to the current server's hop count, and the alternative queue is shuffled using a shuffling algorithm, and the first few servers are selected as the servers for the transmission link;
[0056] 3) Data processing: Before the data transfer starts, the ciphertext parameters between adjacent two servers need to be exchanged first among the data transfer links generated in step 2). The symmetric encryption key is obtained by decrypting according to the ciphertext parameters, and then the data is encrypted using the symmetric encryption key. Specifically:
[0057] 3-1) Initialization phase: To ensure the security of data during the transmission process, in this example, the sender, the receiver, and the servers in the data transfer hub all need to select a cyclic group G of prime order q in the initialization phase, where g is the generator of the cyclic group. An anti-collision hash function H(·) also needs to be selected. The input of the hash function H(·) is of arbitrary length and the output is an element in. Finally, a symmetric encryption method S=(Enc, Dec, key) also needs to be selected. Let the transmission path of the data from the sender to the receiver be R, and R is represented as an ordered set as R={R1, R2, …, R n-1 , R n}, and there are a total of n nodes including the sender and the receiver on the R path. Among them, R1 is the sender, R n is the receiver, and R2 to R n-1 is the path of the data in the data transfer hub. R2 is the hub entrance, and R n-1 is the hub exit;
[0058] 3-2) Symmetric encryption key exchange: In the symmetric encryption key exchange phase, each node R i in R needs to generate its own private key x i and public key d i , where and each node needs to generate its own secret value k i , where λ i is the timestamp of R i , and IPaddr i is the IP address of R i . For the generation of the symmetric key, if the current is the hub exit R n-1 or the receiver R n , then let K i be equal to the secret value of the current server, that is, K i =k i . If it is not the hub exit R n-1 or the receiver R n , the symmetric key obtained by XORing the symmetric encryption key transmitted from the next level and the secret value of the current intermediate node is used level by level from the hub exit in the data transmission path, that is where K i-1 is the next-level server Ri For the generated symmetric key, the sender does not need to generate the symmetric key K i , and then the current node R i randomly selects Calculate:
[0059]
[0060] π i = H(c i,1 , c i,2 , c i,3 , IPaddr l ),
[0061]
[0062] Send the parameters (c i,1 , c i,2 , c i,3 , c i,4 ) to the upper-level node R i of the current node R i-1 . After the upper-level node obtains these parameters, first calculate:
[0063] π i ′ = H(c i,1 , c i,2 , c i,3 , IPaddr i ),
[0064] Then verify:
[0065]
[0066] If it holds, then use the private key x i of the current node R i-1 to decrypt the ciphertext and calculate:
[0067]
[0068] 3-3) Data encryption verification stage: In the data encryption verification stage, the current node R i randomly generates Let the key of symmetric encryption be key = K i , and perform the following calculations on the data M to be transmitted:
[0069]
[0070] E i = S.Enc(M, K i ),
[0071] h i = H(M||Ki H(M), V i ),
[0072] σ i = x i h i + v i ,
[0073] Then the current node sends the encrypted message E i+1 to the next-level node R i , the hash value h i and the message signature σ i . After receiving these parameters, the next-level node R i+1 performs the following calculations on the message E i , the hash value h i and the message signature σ i :
[0074] M' = S.Dec(E i , K i ),
[0075]
[0076] Then verify whether the following equation holds:
[0077]
[0078] If the equation holds, the nodes on the link continue to perform the operations in the above data encryption and verification phase until the data M is passed to the receiver;
[0079] 4) Judgment of the sender's credibility: During the data transfer process, when the sender successfully establishes a connection with the hub entrance, the data navigation center disconnects from the sender. At the same time, after disconnecting, the data navigation center saves the data transfer path generated by the current sender in the link cache database. The data navigation center also has a sender status database, and there is a status field in this database to judge the credibility of the sender. The status field has three colors: green, yellow, and red. Specifically:
[0080] 4-1) For the sender with a green marked color, it indicates that the current sender is a user trusted by the receiver. In the initial stage, the sender is trusted. The sender generates a new data transmission path connection through the data navigation center and then saves this data transmission path in the link cache database. If the sender needs to establish a connection with the receiver again within 12 hours, then it directly calls the path information saved in the link cache database. If the link cache database does not have the data transmission connection established by the current sender before, it requests a new transmission path again, and the receiver and the hub exit conduct re-verification, and the hub entrance re-verifies the sender. If it passes, the current sender is marked as green; if it does not pass, the current sender is marked as yellow;
[0081] 4-2) For the sender with a yellow marked color, it represents that the current sender is not fully trusted by the receiver, that is, an exception occurs when the hub entrance establishes a connection with the sender. Due to the problem that the verification fails during the interaction between the sender and the hub exit, the sender is not fully trusted. The data navigation center sends a warning message to the sender through the hub entrance and waits for 30 minutes to re-establish the connection. If it passes, the current sender is marked as green; if it does not pass, the current sender is marked as red;
[0082] 4-3) If the current sender is marked as red, then the receiver considers the sender to be completely untrusted, that is, an exception occurs during the data transmission process between the sender and the hub entrance. If the situation where the verification between the hub entrance and the sender fails occurs multiple times, then the data navigation center marks the current sender as red and orders the hub entrance to abandon establishing a connection with the sender. In addition, in order to prevent the abuse of server resources, the data navigation center also needs to save the generated link information in the link cache database for 24 hours. If the sender needs to send a large amount of data, that is, in the case of establishing multiple transmission connections, it needs to be judged by the data volume. If the transmitted data are all small-flow data but occupy a large amount of the data volume that the hub entrance can handle, at this time the sender may be controlled by an attacker and attack the hub entrance. The data navigation center marks the current sender as red and deletes the link information of the current sender in the link cache database. When the data is sent normally, it is judged whether the data volume that the current hub entrance can handle is greater than 2 / 3 and whether the size of the transmitted data is greater than the quantity that the hub entrance can handle. If so, the data is transmitted; if not, a new connection is re-established to transmit the data; if the same situation occurs again, then the receiver considers the current sender unreliable. The data navigation center has the right to notify the central node to close the connection and delete the relevant data in the link cache database, and mark the current sender as a red node. After the node is marked as red, the vehicle or user needs to apply to the data processing center to re-obtain the permission to transmit data;
[0083] 5) Traffic Obfuscation and Route Obfuscation: To prevent third parties from stealing and analyzing data traffic during transmission, this example generates obfuscated traffic. To prevent timing attacks, this example supports adding new intermediate nodes during transmission. Specifically:
[0084] 5-1) Traffic Obfuscation: Before forwarding a data packet, the central node determines whether to generate obfuscated traffic by flipping a coin. If it lands on heads, obfuscated traffic is generated; otherwise, it is not. That is, the probability of generating obfuscated traffic follows a 0-1 distribution. To distinguish between the original data and the obfuscated traffic, the obfuscated traffic is either a concatenation of partial data and random characters, or all 0s and all 1s, but it is ensured that the data length of the obfuscated traffic is equal to that of the original data. During transmission, any data transmission service records multiple nodes as alternative nodes. If the current central node needs to forward obfuscated traffic, it randomly selects one of these alternative nodes and encrypts and sends the generated obfuscated traffic to it regardless of the status or traffic volume of this random node. Normal data is transmitted according to the known data transmission path.
[0085] 5-2) Route Obfuscation: During the data transmission phase, the sender and receiver are vulnerable to timing attacks, i.e., when both the hub entrance and the hub exit are occupied by a third party, the correlation of the data is changed. That is, an additional hop between central nodes is added within time w, and at this time, a new server outside this transmission link is selected to be added as an intermediate node to increase the transmission time, thereby changing the correlation between data packets.
Claims
1. A multi-server data transmission method applicable to vehicle networking for supporting users to hide their identities, characterized in that The steps are as follows: 1) Define the data transmission system structure: The data transmission system is provided with a group of servers, which are provided and managed by a trusted institution. The servers are divided into a data transmission hub and a data navigation center. The sender in the data transmission system is a vehicle, and the receiver is a data processing center, i.e., a manufacturer providing vehicle networking services. Among them, the data transmission hub is provided with a group of servers, which are called data transmission servers. The resource configurations of each data transmission server are different, but all are used for transmitting data. Before the data transmission path data transmission link is generated by the data navigation center, no active communication can occur between any data transmission servers in the data transmission hub. The data navigation center is provided with a main server and a group of backup servers. The data navigation center is the server that the vehicle needs to request before sending data. It is mainly responsible for managing all data transmission servers in the data transmission hub, including managing the IP addresses and current states of these data transmission servers, and is responsible for generating a trusted data transmission path data transmission link from the vehicle to the data processing center. There are three databases in the data navigation center, namely the server information database, the link cache database, and the sender status database; 2) System initialization: When the sender has collected the data to be sent, it first requests the data navigation center. The data navigation center generates a data transmission link based on the number of surviving servers and the amount of data that can be tolerated in the current data transmission hub. This data transmission link contains multiple data transmission servers, which are called intermediate nodes between the sender and the receiver. The sum of the number of these intermediate nodes is defined as the number of hops of the data in the data transmission hub. After the data transmission link is established, the first intermediate node, i.e., the hub entrance, and the last intermediate node, i.e., the hub exit, will respectively verify the sender and the receiver. If the verification is passed, it will be saved in the link cache database. Specifically: 2-1) The hop count of the data has a logarithmic relationship with the number of surviving servers in the data transfer hub. The total number of all servers in the data transfer hub is N. When all servers are alive and the total number of servers N is greater than 4 and less than or equal to 256, the data packet hops times, and the result is rounded down; when all servers are alive and the total number of servers N is greater than 256, the data packet hops times, and the result is rounded down; when there is a situation with the servers, that is, the number of surviving servers is less than the total number of servers N, the data packet hops times, and the result is rounded down. If the calculated result is 0 or 1, it means that the data transfer hub cannot work properly. After waiting for 15 minutes, the sender re-asks the data navigation center. If it still doesn't work the second time, it means that the current data transfer hub has failed, and the sender cannot use this system to transfer data; 2-2) When the data transmission hub is running normally, the receiver waits for a connection establishment request from a certain server in the data transmission hub, and the sender first establishes a secure TLS connection with the data navigation center. In the system initialization stage, the link cache database is empty. At this time, the data navigation center generates the first available data transmission link. This data transmission link contains multiple intermediate nodes. The intermediate node connected to the sender is called the hub entrance, and the intermediate node connected to the receiver is called the hub exit. The data navigation center sends the relevant information of the hub entrance to the sender and the relevant information of the sender to the hub entrance. When the sender receives the connection establishment request sent by the hub entrance, if it is consistent with the information received by the sender from the data navigation center, then a connection is established. When the hub exit establishes a connection with the receiver, the hub exit needs to ensure whether the current receiver's information is consistent with the information held by the sender. If they are consistent, a connection is established; 2-3) For the establishment of the generated data transmission paths and data transmission links in the data navigation center, a random jump transmission strategy is adopted: The data navigation center counts the amount of data to be processed by each data transmission server in the data transmission hub during the transmission process, and records the status of these data transmission servers. Given that the threshold of the data volume that each data transmission server may carry is 3 / 4 of the maximum bearable data volume, if the amount of data received or transmitted by any data transmission server in the data transmission hub is less than 3 / 4 of the set value, the current data transmission server is added to the alternative queue. If the amount of data received or transmitted by all data transmission hubs is greater than 3 / 4 of the set value, the data transmission server that requested the earliest is placed in the alternative queue. These servers that start processing data transmission earliest release the required resource space over time and due to the reasons for the completion of data transmission. After detecting the status of all servers, the number of servers in the alternative queue is greater than or equal to the hop count of the current server, and the shuffle algorithm is used to shuffle the alternative queue, and the first few servers are selected as the servers of the transmission link; 3) Data processing: Before the data transfer starts, the ciphertext parameters between adjacent two servers need to be exchanged between the data transmission links generated in step 2). The symmetric encryption key is obtained by decrypting according to the ciphertext parameters, and then the data is encrypted with the symmetric encryption key. Specifically: 3-1) Initialization phase: In the initialization phase, the sender, the receiver, and the server in the data transmission hub all select a cyclic group \(G\) of prime order \(q\), \(g\) is the generator of the cyclic group, select a collision-resistant hash function \(H(\cdot)\), the input of the hash function \(H(\cdot)\) is of arbitrary length, and the output is an element in, select a symmetric encryption method \(S=(Enc, Dec, key)\), let the transmission path of data from the sender to the receiver be \(R\), \(R\) is represented by an ordered set as \(R = \{R_1, R_2, \ldots, R n-1 , R m \}, there are a total of \(n\) nodes on the \(R\) path including the sender and the receiver, where \(R_1\) is the sender, \(R n is the receiver, \(R_2\) to \(R n-1 is the path of data in the data transmission hub, \(R_2\) is the hub entrance, \(R n-1 is the hub exit; 3-2) Symmetric Encryption Key Exchange: In the symmetric encryption key exchange phase, each node R in R i generates its own private key x i and public key d i , where and each node generates its own secret value k i , where λ i is the timestamp of R i and IPaddr i is the IP address of R i . For the generation of the symmetric key, if the current is the hub exit R n-1 or the receiver R n , then let K i be equal to the secret value of the current server, that is, K i = k i . If it is not the hub exit R n-1 or the receiver R n , the data transmission path starts from the hub exit and goes up level by level. At each intermediate node, the symmetric key is obtained by XORing the symmetric encryption key transmitted from the next level with the secret value of the current intermediate node, that is where K i-1 is the symmetric key generated by the next-level server R i . The sender does not need to generate the symmetric key K i , and then the current node R i randomly selects to calculate: π i = H(c i,1 , c i,2 , c i,3 , Ipaddr l ), Send the parameters (c i,1 , c i,2 , c i,3 , c i,4 ) to the previous-level node R i of the current node R i-1 . After the previous-level node obtains these parameters, it first calculates: π i ′ = H(c i,1 , c i,2 , c i,3 , IPaddr i ), Then verify: If it holds, then adopt the current node R i with the private key x i-1 to decrypt the ciphertext and calculate: 3-3) Data Encryption and Verification Phase: At the data encryption and verification phase, the current node R i randomly generates Let the key of symmetric encryption be key = K i , and perform the following calculations on the data M to be transmitted: E i = S.Enc(M, K i ) h i = H(M||K i , H(M), V i ), σ i = x i h i + v i , Then the current node goes to the next-level node R i+1 and sends the encrypted message E i , the hash value h i and the message signature σ i . After receiving these parameters, the next-level node R i+1 performs the following calculations on the message E i , the hash value h i and the message signature σ i : M′ = S.Dec(E i , K i ), Then verify whether the following equation holds: If the equation holds, then the nodes on the link continue to perform the operations in the above data encryption verification stage until the data M is transmitted to the receiver; 4) Judging the credibility of the sender: During the data transfer process, when the sender successfully establishes a connection with the hub entrance, the data navigation center disconnects the connection with the sender. At the same time, after disconnecting the connection, the data navigation center saves the data transmission path generated by the current sender in the link cache database. The data navigation center has a sender status database, and there is a status field in this database to judge the credibility of the sender. The status field has three colors: green, yellow, and red. Specifically: 4-1) For the sender marked with the color green, it means that the current sender is a user trusted by the receiver. In the initial stage, the sender is trusted. The sender generates a new data transmission path connection through the data navigation center and then saves this data transmission path in the link cache database. If the sender needs to establish a connection with the receiver again within less than 12 hours, then directly call the path information saved in the link cache database. If the link cache database does not have the data transmission connection established by the current sender before, then request a new data transmission path again, and the receiver and the hub exit conduct a re-verification, and the hub entrance conducts a re-verification of the sender. If the verification passes, the sender is marked as green. If the verification fails, the sender is marked as yellow; 4-2) For the sender with a yellow marked color, it means that the current sender is not fully trusted by the receiver, that is, an exception occurs when the hub entrance establishes a connection with the sender. The data navigation center sends a warning message to the sender through the hub entrance and waits for 30 minutes to re-establish the connection. If it passes, the sender is marked green; if not, the sender is marked red. 4-3) If the current sender is marked red, then the receiver considers the sender to be completely untrustworthy. An exception occurs during the data transmission process between the sender and the hub entrance. If the verification between the hub entrance and the sender fails multiple times, then the data navigation center marks the sender red and instructs the hub entrance to abandon establishing a connection with the sender. To prevent abuse of server resources, the data navigation center also needs to save the generated link information in the link cache database for 24 hours. If the sender needs to send a large amount of data, that is, in the case of establishing multiple transmission connections, then it needs to be judged by the data volume. If the transmitted data is all small-flow data but occupies a large amount of the data volume that the hub entrance can handle, at this time, the sender may be controlled by an attacker and attack the hub entrance. The data navigation center marks the current sender red and deletes the link information of the current sender in the link cache database. When the data is sent normally, it is judged whether the data volume that the current hub entrance can handle is greater than 2 / 3 and whether the size of the transmitted data is greater than the quantity that the hub entrance can handle. If so, the data is transmitted; if not, a new connection is re-established to transmit the data. If the same situation occurs again, then the receiver considers the current sender unreliable. The data navigation center has the right to notify the central node to close the connection and delete the relevant data in the link cache database, and mark the current sender as a red node. After the node is marked red, the vehicle or user needs to apply to the data processing center to regain the permission to transmit data. 5) Traffic obfuscation and path obfuscation: Add new intermediate nodes during the transmission process. Specifically: 5-1) Traffic obfuscation: Before forwarding the data packet, the central node judges whether to generate masking traffic by flipping a coin. If it is heads, it generates it; otherwise, it does not generate it. That is, the probability of generating masking traffic conforms to a 0-1 distribution. The masking traffic is the splicing of partial data and random characters, or all-0 data and all-1 data. The data length of the masking traffic is equal to the data length of the original data. During the transmission process, any data transmission service records multiple nodes as alternative nodes. If the current central node needs to forward the masking traffic, then it randomly selects one node from these alternative nodes and encrypts and sends the generated masking traffic to it regardless of the status or traffic size of this random node, while the normal data is transmitted according to the known data transmission path. 5-2) Path confusion: During the data transmission phase, the sender and the receiver are vulnerable to timing attacks, that is, when both the hub entrance and the hub exit are occupied by a third party, the correlation of the data is changed. That is, an additional hop between the central nodes is added within time w. At this time, a new server outside this transmission link is selected to join the intermediate nodes to increase the transmission time and change the correlation between the data packets.