A method for constructing a VANET covert channel based on data packet length
By constructing a covert channel based on packet length, optimizing information embedding through block coding and arithmetic coding, and combining vehicle relative position sharing rules and information entropy adjustment, the problem of poor covert channel concealment in VANET is solved, achieving more efficient information security transmission.
Patent Information
- Application Number
- CN202310763849.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-26
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2043-06-26
AI Technical Summary
Existing methods for constructing covert channels in VANET suffer from poor concealment and susceptibility to network jitter in vehicular ad hoc networks. Furthermore, traditional methods already have interference cancellation strategies, making it difficult to effectively protect the secure transmission of information.
A covert channel construction method based on data packet length is adopted. The efficiency of covert information embedding is improved by block coding and arithmetic coding. The length, difference and normal transmission modes are constructed, a sharing rule of vehicle relative position threshold is introduced, and integrity verification and information entropy adjustment schemes are designed to realize the random distribution of carrier data packets and non-carrier data packets.
It improves the concealment of the covert channel and the success rate of information reception, reduces the data packet distribution gap between the covert channel and the normal channel, enhances the security and concealment of information transmission, and can resist information entropy and length distribution detection.
Smart Images

Figure CN116707944B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of network information transmission security technology, and relates to a VANET covert channel construction method based on data packet length. BACKGROUND
[0002] In a vehicular ad hoc network (VANET), when vehicles want to communicate with each other or share data, the possibility of data being invaded in the network is inevitable, and preventing unauthorized access to confidential data becomes a problem to be solved. In order to protect the secure transmission of data, researchers have developed various security technologies, such as communication encryption, network division and isolation, network anomaly flow monitoring, etc. Among them, although the encryption technology hides the content of the message from the attacker, it cannot hide the existence of the message itself. When the information is transmitted on the line, the encrypted data is easy to attract the attention of the attacker. Therefore, seeking a data secure transmission method that can realize message hiding without attracting the attention of the attacker has important significance for guaranteeing the secure transmission of VANET communication information.
[0003] Covert channel technology allows secret data to be sent to the receiver without attracting the attention of the attacker, and realizes the exchange of secret information between two terminal application programs. There are many methods for constructing a covert channel, and in the classification method based on embedding data in a carrier, there are two categories: storage-type covert channel and time-type covert channel. Among them, the storage-type covert channel refers to a channel in which the sender embeds data in the message header used by the other end of the node or in the protocol used by the sender. Although various types of network protocols provide design materials for the construction of storage-type covert channels, the types of network protocols are always limited, and are easy to be targeted by attackers, with poor concealment. The time-type covert channel refers to a channel in which data is embedded through the time-varying characteristics of system resources. This time-type covert channel construction method has fewer choices, and the time characteristics are affected by network jitter, which will cause large decoding errors and be easy to be eliminated by interference. In order to optimize the deficiencies existing in the construction of storage-type and time-type covert channels, the covert channel construction technology based on data packet length has attracted widespread attention. It embeds covert information through the length of the data packet transmitted in the network, has strong anti-detection ability, and this construction method is universally applicable to protocols that meet the data packet length requirements of the carrier, and breaks away from the dependence of traditional storage-type covert channel construction methods on specific protocols.
[0004] At present, there is a certain research on protecting VANET information transmission security based on traditional storage covert channel and time covert channel, but since the two traditional methods have interference elimination strategies after a large number of studies, there are few reports on the research on constructing a covert channel based on data packet length to protect VANET data transmission. Therefore, in order to protect the safe transmission of VANET information, it is urgent to develop a covert channel construction technology that avoids the defects of traditional covert channel construction and is suitable for VANET scenarios. SUMMARY
[0005] Therefore, the purpose of the present application is to provide a VANET covert channel construction method based on data packet length, which is aimed at the problem that VANET is vulnerable to network attacks due to vehicle maneuverability, and uses a data packet length covert channel construction technology based on vehicle relative position and shared rule replacement, which uses grouping coding and arithmetic coding to improve the embedding efficiency of covert information; three transmission modes of length, difference and normal transmission mode are constructed to realize the random distribution of carrier data packets and non-carrier data packets, and the concept of vehicle relative position threshold is introduced to realize the real-time replacement of the shared rule, thereby improving the concealment of the covert channel; and an integrity check and information entropy adjustment scheme is designed to improve the success rate of receiving covert information and reduce the distribution gap between the covert channel and the normal channel data packets.
[0006] To achieve the above purpose, the present application provides the following technical scheme:
[0007] A VANET covert channel construction method based on data packet length, specifically comprising the following steps:
[0008] S1: Selection and division of reference data packet length sequence: the vehicle sender and receiver of the covert information collect normal data through legal communication, which is used as the reference data packet length sequence for embedding the covert information; at the same time, the reference data packet length sequence is sorted from small to large, and the carrier is divided according to the pre-agreed rule to generate the carrier length sequence and the optional length sequence;
[0009] S2: Encoding and decoding scheme: grouping coding and arithmetic coding are used to optimize the information embedding efficiency of the covert channel;
[0010] S3: Shared rule transformation: the vehicle sender replaces the shared rule generated in steps S1 and S2 according to the pre-agreed rule and transmits it; the receiver receives the shared rule replacement information and judges it to realize the replacement of the decoding rule;
[0011] S4: Modulation and demodulation algorithm: the vehicle sender embeds the covert information by selecting different data packet lengths in the carrier length sequence; the receiver receives the information and judges the position of the data packet length in the carrier length sequence to obtain the covert information;
[0012] S5: Information entropy adjustment: The information entropy adjustment is performed to conceal the information by imitating the packet distribution of the normal channel, to reduce the difference between the packet distribution of the covert channel and that of the normal channel, and to improve the concealment of the covert channel;
[0013] S6: Integrity check: After the covert communication, the vehicle sender sends a data packet containing the hash value of the covert information; the receiver receives the hash value data packet and compares it with the hash value of the covert information in the covert communication stage to determine whether to require the vehicle sender to retransmit the data.
[0014] Further, in step S1, the vehicle sender and the receiver simultaneously sort the data packet length elements in the sequence Reference_d = {l1, l2,..., ln} from small to large, and the number of data in the sequence is N; the first n data packets in the sorted sequence are used to form the carrier length sequence Carrier_d = {l1, l2,..., ln}, n < N, and the remaining data packet lengths form the optional length sequence Residue_d = {ln+1, ln+2,..., ln+N-n}. N} in the sequence Reference_d = {l1, l2,..., ln} from small to large, and the number of data in the sequence is N; the first n data packets in the sorted sequence are used to form the carrier length sequence Carrier_d = {l1, l2,..., ln}, n < N, and the remaining data packet lengths form the optional length sequence Residue_d = {ln+1, ln+2,..., ln+N-n}. n} in the sequence Reference_d = {l1, l2,..., ln} from small to large, and the number of data in the sequence is N; the first n data packets in the sorted sequence are used to form the carrier length sequence Carrier_d = {l1, l2,..., ln}, n < N, and the remaining data packet lengths form the optional length sequence Residue_d = {ln+1, ln+2,..., ln+N-n}. n+1 n+2 N} in the sequence Reference_d = {l1, l2,..., ln} from small to large, and the number of data in the sequence is N; the first n data packets in the sorted sequence are used to form the carrier length sequence Carrier_d = {l1, l2,..., ln}, n < N, and the remaining data packet lengths form the optional length sequence Residue_d = {ln+1, ln+2,..., ln+N-n}.
[0015] Further, in step S2, the sender encodes the to-be-sent covert information by grouping encoding and arithmetic encoding, which specifically includes the following steps:
[0016] S201: The sender divides the data packet elements in the carrier length sequence Carrier_d into m parts to form m packet length category sequences Group_set j ,j = 1, 2,..., m, each sequence having W j number of packet length elements; these m packet length categories form a command set Order_d = {d i | 0 ≤ i ≤ m} for encoding; different numbers of commands are selected from the set Order_d in turn, and a full permutation is performed on them, so that the m commands can finally form M different combinations, as shown in equation (1):
[0017]
[0018] wherein, wherein, represents the result of arranging i commands selected from the m commands;
[0019] S202: Calculate the number of packet length elements that can be allocated in each packet length category sequence Group_set j , which is shown in equations (2) and (3):
[0020]
[0021] W m = n - (W1+ W2+... + Wn) (3) j
[0022] where n is the total number of packet lengths in the sequence Carrier_d, P" j is the probability of the command d j appearing, as shown in equations (4) and (5):
[0023]
[0024]
[0025] where t i is the number of times the bit string R i appears, bin is the set of bit strings, W j is the number of packet lengths in the sequence Group_set j ; assuming that two commands d1d2 are needed to form the bit string R1, and two commands d1d3 are needed to form the bit string R2, then the probability of selecting the d1 command is P1"= (P1+P2) / 2;
[0026] S203: Set the number of elements in the packet length type sequence Group_set j to be Max, and when the number of elements in the packet length type sequence Group_set j is less than Max, use a random algorithm to select q j elements from the selectable length sequence Residue_d and fill them into the packet length type sequence Group_set j , so that the number of elements in the packet length type sequence Group_set j is Max; at this time, the m packet length type sequences can form an m*Max dimensional packet length matrix Group_M; after the matrix Group_M is processed as described above, it is shown in equation (6):
[0027]
[0028] wherein, represents the length of the i-th data packet in the sequence Group_set m corresponding to the command d m ;
[0029] S204: The receiver combines the mapping relationship between the command combination and the covert information and the mapping relationship between the command combination and the covert information according to formula (6) to randomly select the carrier package length by row, form a to-be-sent package length sequence Primary_d1, and complete the encoding process of the covert information.
[0030] S205: The sender embeds the probability P" formed by the grouping encoding in the middle of the package to form a to-be-sent sequence Primary_d2. j Convert the binary sequence into a binary sequence, and perform arithmetic coding on each k-bit binary sequence to obtain i random numbers {r1, r2,..., r i} between the intervals [0, 1) and 2 k k binary sequence combinations form a probability about the number of times of "0" and "1", and the probability is converted into a binary number to constitute a sequence Probability_d = {p 1_0 , p 1_1 , p 2_0 , p 2_1 ,..., p k_0 , p k_1};
[0031] S206: Convert the random numbers in {r1, r2,..., r i} into corresponding package lengths; remove the "0" of each random number and the decimal point to obtain an integer L j greater than 0 as the data package length; if the integer cannot find a matching data package length in the sequence Carrier_d, replace L j by adding, subtracting or combining multiple package lengths to reduce the gap between the covert channel and the legal channel, and obtain the to-be-sent sequence Primary_d2 after the processing, and complete the encoding process of the grouping probability information.
[0032] Further, in step S2, the specific steps of the vehicle receiver data decoding are as follows:
[0033] S211: The receiver receives the data transmitted by the sender and reads the data package length of each message;
[0034] S212: The receiver compares the read data length with the mapping relationship between the command combination and the covert information and the mapping relationship between the package length category and the package length sequence constructed by the receiver, and decodes the covert information.
[0035] Further, in step S3, the sharing rule transformation specifically includes: using the non-carrier data package in the matrix Group_M, transmitting the covert sharing rule information by using the non-carrier package length through the embedding method based on the data package difference; the sender and the receiver select the first x elements in the sequence Residue_d to constitute a package difference sequence Difference_d = {ln+1 ,l n+2 ,...,l n+x}, 0 < x < (Nn); If the length of the non-carrier packet randomly selected in Group_M is l m When it belongs to the sequence Difference_d, the packet length needs to be randomly selected in the sequence Difference_d according to the formula (7) to form the difference concealment mode;
[0036]
[0037] In the covert channel embedding method of the present invention, only four shared rules need to be changed for the block coding process: k, n, x, and matrix Group_M scrambling; while the arithmetic coding process needs to share the probability of "0" and "1" appearing for each packet length in the sequence of packet lengths to be sent; the rule changing steps are as follows:
[0038] 1) According to equation (8), the sender and receiver initialize the srand function using the agreed-upon key:
[0039] srand(key) (8)
[0040] 2) Use equation (9) to generate random numbers between A and (A+B-1):
[0041] rand()%B+A (9)
[0042] 3) The sending and receiving parties agree in advance on the selectable values of k, n, and x, and form a sequence of candidate values, with each value in the sequence corresponding to a sequence number; a sequence of candidate operations is also formed for the scrambling operation; the corresponding value is selected from the candidate value sequence according to the sequence number by generating a random number, and the same operation is performed in the candidate operation sequence to select the matrix transformation command;
[0043] 4) Bin_m is defined as "0" to represent a scrambling operation, and "1" to represent the replacement of k, n, and x; when a single "1" appears in the value of bin_m in the channel, k is replaced; when two consecutive "1"s appear, n is replaced; when three consecutive "1"s appear, x is replaced.
[0044] 5) Sort the elements in the sequence Probability_d in ascending order of the number of "0"s and convert them into binary sequences. The packet lengths in the sequence Difference_d form a difference pattern, which is used to transmit the probability of "0" and "1" appearing for each packet length in the sequence of packet lengths to be sent.
[0045] The sender changes the shared rules required during the encoding process based on the relative positions of the vehicles during their travels. Both communicating parties set a distance threshold for the rule change, and when the relative position of the two vehicles exceeds the position threshold, step 4) rule change is executed. The receiver knows that the sender has executed the shared rule change based on the relative position, and parses the changed rule according to step 3). This method achieves synchronization of rule changes between the sender and receiver. Finally, the sender sends the shared probability formed in the encoding process in step 5) to achieve information sharing.
[0046] Furthermore, in step S5, the information entropy adjustment specifically includes the following steps:
[0047] S51: Let window_r be a window that divides the unsorted sequence Reference_d into L elements; window_p be a window that divides Primary_d1 into L elements;
[0048] S52: Statistics window window_p contains entries for the same command d i The frequency of elements in a packet of length i = 1, 2, ..., m forms a sequence Q. i ={r i_1 ,r i_2 ,...,r i_m}; Count the frequency of elements belonging to the same packet length, and form a sequence q. j ={r j_1 ,r j_2 ,...,r j_y}, sequence L_q j ={a j_1 ,a j_2 ,...,a j_y} for Q i The data packet length corresponding to each frequency in the sequence; where the frequencies in the sequence are sorted from largest to smallest, and a Q is created. i '、L_q' j and q' j This is a copy of the original sequence; the sequence P = {p1, p2, ..., p...} y} represents the frequency of elements with the same packet length in the window window_r, where L_P = {b1, b2, ..., b s} represents the packet length corresponding to the frequency.
[0049] S53: Combine the first element of sequence P with q j Compare all elements in the table; if p1 = r, then... j_i Then r j_i In sequence q j Remove from Q and update Q. i and L_q j; then the next element in sequence P is compared;
[0050] S54: if p1≠r j_i , then p1 is subtracted from its Q i element to form sequence T = {t1, t2,..., t m}, and the elements in sequence T are sorted in ascending order; if the minimum value is t i >0, then all packet length elements corresponding to command d i in Q j ' and L_q' i are changed to r, r∈Group_set i , where Group_set i is the packet length type sequence corresponding to command d i , and r is a randomly selected packet length element in sequence Group_set i ; if the minimum value is t i <0, then p1 packet length elements corresponding to command d i in Q i ' and L_q' j are changed to r; finally, q' j is updated; the modified elements are removed from the original sequence, and the next element in sequence P is compared;
[0051] S55: repeat S53 and S54 to complete the operation on all windows, and the copy sequence is the adjusted data.
[0052] Further, in step S6, an integrity verification process is added to the covert channel model, specifically: the sender transmits the digest Z(bin) data packet of the covert information to the receiver, the receiver calculates the digest Z'(bin) from the decoded covert information, and then compares Z(bin) and Z'(bin); when calculating the digest, the covert information is calculated in blocks, which facilitates the receiver to locate the position of the incomplete information to request the sender to retransmit the covert information; the specific steps of the integrity verification are as follows:
[0053] S61: the sender sends the digest of the covert information transmitted in the first communication to the receiver in the second communication;
[0054] S62: the receiver needs to calculate whether Z(bin) and Z'(bin) are equal, if they are equal, step S63 is performed; if they are not equal, step S64 is performed;
[0055] S63: When Z'(bin)=Z(bin), the receiving party transmits data elements in the transmission sequences Difference_d and Carrier_d, and embeds information in the agreed position range; the appearance of consecutive even non-carrier packet lengths is taken as a session start mark, and the appearance of consecutive odd non-carrier packet lengths is taken as a session end mark; elements in the sequences Carrier_d and Difference_d are randomly selected in the session, and the number of selected elements in Carrier_d is required to be greater than the number of elements in Difference_d; after receiving the information, the sending party determines that no data needs to be retransmitted by comparing the number of packet lengths in the two sequences; wherein, in order to avoid decoding errors caused by packet loss, the number of packet lengths selected in the sequences Carrier_d and Difference_d should have a large difference;
[0056] S64: When Z'(bin)≠Z(bin), elements in the sequences Carrier_d and Difference_d are randomly selected in the session, and the number of selected elements in Carrier_d is required to be less than the number of elements in Difference_d; after receiving the information, the sending party determines that data needs to be retransmitted by comparing the number of packet lengths in the two sequences; wherein, the range of the number difference between the sequences Carrier_d and Difference_d needs to be determined to represent the position of the incomplete information.
[0057] The beneficial effects of the present application are:
[0058] The method of the present application improves the embedding efficiency of the hidden information by introducing grouping encoding and arithmetic encoding, and does not increase the number of packet lengths in the channel too much. At the same time, three transmission modes such as length hiding mode, difference hiding mode and normal transmission mode are constructed to realize the random distribution of carrier data packets and non-carrier data packets, and improve the concealment of information transmission. Secondly, the integrity check and information entropy adjustment scheme are designed to improve the success rate of receiving hidden information and reduce the difference between the distribution of hidden channel and normal channel data packets. Through experiments and evaluation, the hidden channel can better meet the statistical characteristics of the normal channel, can resist information entropy and length distribution detection, not only enhances the concealment of the hidden communication, but also improves the embedding efficiency of the hidden information.
[0059] Other advantages, objects, and features of the present application will be apparent to those skilled in the art from the following specification, which is to be taken in conjunction with the accompanying drawings, wherein: BRIEF DESCRIPTION OF DRAWINGS
[0060] In order to make the objects, technical solutions and advantages of the present application clearer, the preferred embodiments of the present application will be described in detail below with reference to the drawings, in which:
[0061] Figure 1 A schematic diagram of packet length distribution in the embodiment of the present application;
[0062] Figure 2 A schematic diagram of the architecture of the packet length covert channel scheme based on data packet length in the embodiment of the present application;
[0063] Figure 3 A schematic diagram of data packet distribution in the embodiment of the present application;
[0064] Figure 4 A schematic diagram of reading of the carrier length in the embodiment of the present application;
[0065] Figure 5 A schematic diagram of modulation in the embodiment of the present application. DETAILED DESCRIPTION
[0066] The embodiments of the present application will be described in detail below with reference to specific examples. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in the specification. The present application can also be implemented or applied in different specific embodiments, and the details in the specification can be modified or changed in different ways without departing from the spirit of the present application. It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present application in a schematic manner, and the features in the following embodiments and examples can be combined with each other without conflict.
[0067] Please refer to Figures 1-5 The embodiment of the present application provides a data packet length covert channel construction method based on vehicle relative position change sharing rule, which is used to improve the security of information transmission in VANET.
[0068] When the data packet length is used as the carrier of the covert channel, it is required that the selected data packet length is randomly distributed and the packet length has a sharp change, and the protocol data packet length containing a large amount of repeated data is not suitable as the carrier. By capturing the normal communication data of the UDP protocol through the wireshark network analyzer, 10000 legal channel data packet lengths are obtained as the carrier of the covert information. In order to better show the distribution of the data packet length, 500 data are selected for statistics, as shown in Figure 1 It can be observed that the packet length of the UDP protocol is suitable as the carrier of this type of covert channel.
[0069] The method includes six parts, which are the selection and division of the reference data packet length sequence, the encoding and decoding scheme, the sharing rule transformation, the modulation and demodulation algorithm, the information entropy adjustment and the integrity check. The completion process is as followsFigure 2 are shown, specifically including:
[0070] 1. Selection and division of reference data packet length sequence
[0071] The vehicle sender participating in covert communication needs to process the covert information to be sent, and the sender and receiver also need to collect data packet carriers through legal communication and process them, and the steps are as follows:
[0072] 1) The vehicle sender converts the covert information into a binary bit stream according to the ASCII code table, and the bit stream length is bin_len. Secondly, the bit stream is divided according to k bits, and thus the bit string set bin = R1R2,...,R T , T = bin_len / k, R i = b1b2,..., b k , i = 1, 2,..., T.
[0073] 2) The vehicle sender and receiver collect normal data through legal communication, and use the packet length as the reference length to form the sequence Reference_d = {l1,l2,...,l N}.
[0074] 3) The vehicle sender and receiver simultaneously sort the data packet length elements in the sequence Reference_d from small to large. The number of data in the sequence is N.
[0075] 4) The first n (n < N) data packets after sorting are used to form the carrier length sequence Carrier_d = {l1,l2,...,l n}, n < N elements, and the remaining data packet lengths form the optional length sequence Residue_d = {l n+1 ,l n+2 ,...,l N}. When duplicate data packets appear, fill the duplicate data packets into the previous sequence. The values of k and n are shared by the sender and receiver.
[0076] 2. Encoding and decoding scheme
[0077] The sender encodes the covert information to be sent through grouping encoding and arithmetic encoding, and the steps are as follows:
[0078] 1) The sender divides the data packet elements in the carrier length sequence Carrier_d into m parts to form m packet length category sequences Group_set j , j = 1, 2,... m, each sequence has W jm packet length elements. The m packet length categories in turn constitute the command set Order_d participating in encoding i |0≤i≤m}. Different numbers of commands are selected in turn from the set Order_d and full permutations are performed thereon, and m commands can finally form M different combinations, as shown in equation (1) :
[0079]
[0080] wherein, wherein, represents the result of selecting i commands from the m commands for permutation.
[0081] 2) Calculate the number of packet length elements that can be allocated in each packet length category sequence Group_set j , which is shown in equations (2) and (3) :
[0082]
[0083] W m = n - (W1 + W2 +... + W j ) (3)
[0084] wherein, n is the total number of packet lengths in the sequence Carrier_d, P" j is the probability of the command d j appearing, as shown in equations (4) and (5) :
[0085]
[0086]
[0087] wherein, t i is the number of times the bit string R i appears, bin is the set of bit strings, W j is the number of packet lengths in the sequence Group_set j ; assuming that two commands d1d2 are required to form the bit string R1 and two commands d1d3 are required to form the bit string R2, then the probability of selecting the d1 command is P1" = (P1 + P2) / 2.
[0088] 3) Set the maximum number of elements in the packet length category sequence Group_set j to Max, and when the number of elements in a packet length category sequence Group_set is less than Max, a random algorithm is required to select q jThe elements are filled into the package length category sequence Group_set, so that the number of elements in Group_set is Max. At this time, the m package length category sequences can constitute an m*Max dimensional package length matrix Group_M. After the matrix Group_M is processed as described above, it is shown in equation (6):
[0089]
[0090] wherein, wherein, represents the command d m corresponding sequence Group_set m The length of the ith data packet.
[0091] 4) The receiver selects the carrier package length according to the row number in equation (6) according to the mapping relationship shown in Tables 1 and 2 to form a to-be-sent package length sequence Primary_d1, completing the encoding process of the covert information. Tables 1 and 2 are described by taking m=4 as an example. L_MAX is an arbitrary data packet length greater than l N , which can represent all-zero covert information.
[0092] Table 1 Command combination and covert information mapping relationship
[0093]
[0094] Table 2 Package length category and package length sequence mapping relationship
[0095]
[0096] 5) The sender converts the package encoding embedded in the formed subpackage probability P" j into a binary sequence, and performs arithmetic coding on each k-bit binary sequence to obtain i random numbers {r1, r2,..., r i} between the interval [0, 1), and 2 k binary sequence combinations form k pairs of probabilities about the number of times "0" and "1" appear. Convert the probability into a binary number to constitute the sequence Probability_d={p 1_0 ,p 1_1 ,p 2_0 ,p 2_1 ,...,p k_0 ,p k_1}.
[0097] 6) Convert the random numbers in {r1, r2,..., r i} into corresponding package lengths. Remove the "0" of the last digit and the decimal point of each random number to obtain an integer L jAs the data packet length. If the integer cannot find a matching data packet length in the sequence Carrier_d, replace L by the sum, difference or combination of multiple packet lengths j , reduce the gap between the covert channel and the legal channel, and obtain the to-be-sent sequence Primary_d2 after the processing, thereby completing the encoding process of the packet probability information.
[0098] In addition, since there are data packets unrelated to the transmission of covert information in the matrix Group_M, random selection according to the mapping rule will form a random distribution of covert carrier data packets and non-carrier data packets, as shown in Figure 3 . In this scenario, the communication between vehicles can be switched from the length covert mode in which covert carrier data exists to the normal transmission mode in which non-carrier data exists. Even if the attacker successfully breaks through the security protection of the data, the attacker cannot identify the embedded carrier of the covert information in the channel.
[0099] The data decoding process of the vehicle receiver, the steps of which are as follows:
[0100] 1) The receiver receives the data transmitted by the sender and reads the data packet length of each message, and the reading position of the packet length is as shown in Figure 4 .
[0101] 2) The receiver compares the read data length with the mapping table constructed by the receiver, as shown in Tables 1 and 2, and decodes the covert information.
[0102] 3, shared rule transformation
[0103] The non-carrier data packets in the matrix Group_M are used to transmit the covert shared rule information by using the embedding method based on the difference value of the data packet. The transmitting and receiving parties select the first x elements in the sequence Residue_d to form the difference value sequence Difference_d={l n+1 ,l n+2 ,...,l n+x}, 0<x<(N-n). If the non-carrier packet length l m randomly selected in Group_M belongs to the sequence Difference_d, the difference value covert mode needs to be randomly selected in the sequence Difference_d according to formula (7) to form the difference value.
[0104]
[0105] In the steganographic channel embedding method of the present application, only four shared rules of k, n, x and matrix Group_M permutation need to be replaced for the packet encoding process; and the arithmetic encoding process needs to share the probability of "0" and "1" occurrence corresponding to each packet length in the sequence of shared to-be-sent packet lengths. The replacement rule steps are as follows:
[0106] 1) According to formula (8), the sender and the receiver use the agreed key to initialize the srand function:
[0107] srand (key) (8)
[0108] 2) Use formula (9) to generate a random number between A and (A+B-1):
[0109] rand() % B + A (9)
[0110] 3) The sender and the receiver agree on the values of k, n and x that can be selected in advance, and form a sequence of to-be-selected values respectively, each value in the sequence corresponding to a sequence number; a sequence of to-be-selected operations is also formed for the permutation operation. By generating a random number, the corresponding value in the sequence of to-be-selected values is selected according to the sequence number, and the same operation is performed in the sequence of to-be-selected operations to select the matrix transformation command.
[0111] 4) It is specified that bin_m represents the permutation operation when it is "0", and represents the replacement of k, n and x when it is "1". When a single "1" appears in the value of bin_m in the channel, k is replaced; when two consecutive "1"s appear, n is replaced; and when three consecutive "1"s appear, x is replaced.
[0112] 5) The elements in the sequence Probability_d are sorted according to the number of "0"s from small to large and converted into a binary sequence, and the packet lengths in the sequence Difference_d form a difference pattern, which is used to transmit the probability of "0" and "1" occurrence corresponding to each packet length in the sequence of to-be-sent packet lengths.
[0113] The shared rules needed by the sender in the encoding process are replaced according to the relative position during the vehicle driving process. The two parties of the communication set the distance threshold for replacement, and when the relative position of the two vehicles is greater than the position threshold, step 4) rule replacement is started. The receiver knows that the receiver has performed the replacement of the shared rules according to the relative position, and the replaced rules are analyzed according to step 3). By this method, the synchronization of rule replacement of the sender and the receiver is realized; finally, the sender transmits the shared probability formed in step 5) in the encoding to realize information sharing.
[0114] 4, Modulation and demodulation algorithm
[0115] The data modulation process of the sender is as follows Figure 5As shown, wherein the covert information is 0110, k = 2, m = 2, n = 8, x = 5, the steps are as follows:
[0116] 1) The sender constructs a sequence Irrelevant_d = {l n+x+1 ,l n+x+2 ,...,l N-n} representing the data sequence not participating in covert transmission, and randomly selects an even number of data packet lengths to represent the flag indicating the start of covert communication. In addition, in order to transmit all-zero covert information, a special group of packets needs to be divided in this sequence to serve the covert information.
[0117] 2) Randomly select an even number of data packet elements in the sequence Irrelevant_d to represent the flag of single covert communication, and embed the packet length sequence Primary_d1 to be sent after the flag. If the data packet length element is L_MAX, an even number of special group packet elements are used as the flag of single covert communication.
[0118] 3) When the vehicle reaches the relative position to change the sharing rule, start to execute the sharing rule change, and embed the data packet length element related to the sharing rule.
[0119] 4) After the completion of covert information transmission, randomly select an even number of data packet lengths in the sequence Irrelevant_d to represent the flag indicating the start of transmission of the packet probability information, and embed the packet length sequence Primary_d2 to be sent after the flag.
[0120] 5) After the end of covert communication, randomly select an odd number of data packet length elements in the sequence Irrelevant_d as the end of covert communication flag.
[0121] The receiving side data demodulation, the steps are as follows:
[0122] 1) The receiving side receives the data sent by the sending side, and when there are consecutive even number of data elements belonging to the sequence Irrelevant_d, it represents the start of covert communication.
[0123] 2) The receiving side reads the data and removes the data packet length elements belonging to the sequence Irrelevant_d, and saves them as covert data.
[0124] 3) When the relative position of the vehicle exceeds the set threshold, it is judged that the sender starts to transmit the sharing rule change information, and the receiving side saves the change data.
[0125] 4) When the relative position does not exceed the set threshold and the data element belonging to the sequence Difference_d is received, it is judged that the received data is the packet probability data.
[0126] 5) When receiving continuous odd number of data packets belonging to sequence Irrelevant_d, it is judged that the covert communication is over.
[0127] 5) Information entropy adjustment
[0128] Since the data packet length in sequence Primary_d1 is randomly selected, its information entropy has a certain gap with the information entropy of the legal channel. In order to make the information entropy of the channel close to the normal channel, the application designs an information entropy adjustment scheme by imitating the packet distribution of the normal channel.
[0129] 1) Let window_r be the window of dividing the unsorted sequence Reference_d into L elements; and window_p be the window of dividing Primary_d1 into L elements.
[0130] 2) Count the frequency of the packet length elements belonging to the same command d i i=1,2,...,m in window_p, and form sequence Q i ={r i_1 ,r i_2 ,...,r i_m}; count the frequency of the elements belonging to the same packet length, and form sequence q j ={r j_1 ,r j_2 ,...,r j_y}, and sequence L_q j ={a j_1 ,a j_2 ,...,a j_y} is the packet length corresponding to each frequency in Q i . In the sequence, the frequencies are sorted from large to small, and Q i ', L_q' j and q' j are the original sequence copies. Sequence P={p1,p2,...,p y} is the frequency of the same packet length elements in the statistical window window_r, and L_P={b1,b2,...,b s} is the packet length corresponding to the frequency.
[0131] 3) Compare the first element in sequence P with all elements in q j . If p1=r j_i occurs, then r j_i is removed from sequence q j , and Q i and L_q j are updated. Then the comparison of the next element in sequence P is performed.
[0132] 4) If p1≠r j_i Then p1 and its Q i Subtract the elements from each other to form the sequence T = {t1, t2, ..., t} m} and sort the elements in sequence T in ascending order. If the minimum value is t i If Q > 0, then Q i 'and L_q' j The corresponding command d in Chinese i Change all package length elements to r, r∈Group_set i Group_set i For command d i The corresponding packet length category sequence, where r is the sequence Group_set i The length element of a randomly selected packet; if the minimum value is t i If <0, then Qi' and L_q' j The corresponding command d in Chinese i Change the length of each of the p1 package elements to r. Last update q'. j The modified element is removed from the original sequence, and then the next element in sequence P is compared.
[0133] 5) Repeat steps 3) and 4) to complete the operation on all windows. The copy sequence is the adjusted data.
[0134] 6. Integrity verification
[0135] This invention incorporates an integrity verification process into the covert channel model to improve the accuracy of covert information transmission. The sender transmits a digest Z(bin) data packet of the covert information to the receiver. The receiver calculates the digest Z'(bin) using the decoded covert information and then compares Z(bin) and Z'(bin). During digest calculation, the covert information needs to be processed in blocks, allowing the receiver to locate incomplete information and request retransmission of the covert information.
[0136] The specific steps for integrity verification are as follows:
[0137] 1) In the second communication, the sender sends a digest of the covert information transmitted in the first communication to the receiver.
[0138] 2) The receiver needs to calculate whether Z(bin) and Z'(bin) are equal. If they are equal, proceed to step 3); if they are not equal, proceed to step 4.
[0139] 3) When Z'(bin)=Z(bin), the sender transmits the data elements in the sequence Difference_d and Carrier_d in the receiving direction, and embeds information in the agreed position range. The appearance of consecutive even non-carrier packet lengths as a session start mark, and the appearance of consecutive odd non-carrier packet lengths as a session end mark. Randomly select elements in the sequence Carrier_d and Difference_d in the session, and require the number of selected elements in Carrier_d to be greater than the number of elements in Difference_d. After receiving the information, the sender determines that no data needs to be retransmitted by comparing the number of packet lengths in the two sequences. In order to avoid decoding errors caused by packet loss, the number of selected packet lengths in the sequence Carrier_d and Difference_d should have a large difference.
[0140] 4) When Z'(bin)≠Z(bin), randomly select elements in the sequence Carrier_d and Difference_d in the session, and require the number of selected elements in Carrier_d to be less than the number of elements in Difference_d. After receiving the information, the sender determines that data needs to be retransmitted by comparing the number of packet lengths in the two sequences. In order to determine the range of the number of sequences Carrier_d and Difference_d, which represents the position of the incomplete information, such as the difference value in (0, 10] for the first data block and (10, 20] for the second data block.
[0141] Through information entropy and packet length distribution experiments, the method of the present application can make the information entropy of the covert channel closer to the normal channel, and the packet length distribution closer to the legal channel, making it more undetectable for information entropy detection and packet length distribution detection based on statistical detection, and more covert. At the same time, in network environments with packet loss rates of 5%, 10%, and 15%, the reliability of the channel is better than that of the compared covert channel construction methods; the embedding capacity and transmission rate of the covert channel are also better than those of the compared construction methods, which can ensure the safety and effectiveness of the covert channel construction scheme. After testing, it is found that the covert channel construction technology scheme proposed by the present application can effectively transmit covert information in the network, and even if the network fluctuates or is attacked by malicious attackers, it can still protect the safe transmission of information in VANET.
[0142] Finally, it should be pointed out that the above embodiments are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the present application, and all should be covered in the scope of the claims of the present application.
Claims
1. A method for constructing a VANET covert channel based on data packet length, characterized in that, The method specifically includes the following steps: S1: Selection and division of reference data packet length sequence: The vehicle sender and receiver of the concealed information collect normal data through legitimate communication and use it as a reference data packet length sequence to embed the concealed information; at the same time, the reference data packet length sequence is sorted from smallest to largest and the carrier is divided according to the pre-agreed rules to generate a carrier length sequence and an optional length sequence; S2: Encoding / decoding scheme: Optimizes the information embedding efficiency of covert channels through block coding and arithmetic coding; S3: Shared rule transformation: The vehicle sender replaces the shared rules generated in steps S1 and S2 according to the pre-agreed rules and transmits them; the receiver receives the shared rule replacement information and judges it to realize the replacement of the decoding rules. S4: Modulation and demodulation algorithm: The vehicle transmitter embeds hidden information by selecting different data packet lengths in the carrier length sequence; the receiver obtains the hidden information by receiving the information and determining the position of the data packet length in the carrier length sequence. S5: Information Entropy Adjustment: By mimicking the packet distribution of a normal channel, covert information entropy adjustment is performed to reduce the difference between the data packet distribution of the covert channel and the normal channel. S6: Integrity Verification: After covert communication ends, the vehicle sender sends a data packet containing the hash value of the covert information; the receiver receives the hash value data packet and compares it with the hash value of the covert information during the covert communication phase to determine whether to require the vehicle sender to retransmit the data. In step S1, the vehicle sender and receiver simultaneously process the sequence. The data packet length elements are sorted in ascending order, and the number of data items in the sequence is . N ; sort the first n Each data packet is used to form the carrier length sequence. The elements, and the remaining packet lengths constitute an optional length sequence. When duplicate data packets are encountered, the duplicate data packets are inserted into the previous sequence. In step S2, the sender encodes the hidden information to be sent using block coding and arithmetic coding, specifically including the following steps: S201: The sender will send the carrier length sequence Data packet elements are divided into m The components constitute m Packet length type sequence Each sequence has Each package length element; this m The length of each packet constitutes the set of commands involved in the encoding. In the set If we select different numbers of commands in sequence and perform full permutations on them, then... m The final composition of the commands M Different combinations are shown in equation (1): (1) in, Indicates selection In the command The result of arranging the commands; S202: Calculate the sequence of length categories for each package. The number of packet length elements that can be allocated in the middle is shown in equations (2) and (3): (2) (3) in, n For sequence Total number of medium-length packages For command The probability of occurrence is shown in formulas (4) and (5): (4) (5) in, bit string Number of times it appears A set of bit strings For sequence The number of packets in the array; assuming a bit string is formed. When needed Two commands to form a bit string When needed Between the two commands, choose the last one. The probability of the command is ; S203: Set a sequence of packet length types The maximum number of elements is When a certain package length category sequence The number of elements in is less than When, it is required to start from a sequence of optional length. The middle uses a random algorithm to select Each element is filled with a sequence of package length types. This makes the packet length type sequence The number of elements in the middle is ;at this time, m The sequence of package length types can form Dimensional bag length matrix ;matrix After the above processing, it is as shown in equation (6): (6) Among them, among them, Indicates command corresponding sequence The Middle The length of each data packet; S204: Based on the mapping relationship between command combinations and covert information, and the mapping relationship between packet length types and packet length sequences, the receiver randomly selects the carrier packet length according to the row number in formula (6) to form the packet length sequence to be sent. This completes the encoding process of concealed information; S205: The probability formed by the sender embedding block codes in the code Convert to binary sequence, for each k Arithmetic encoding of the bit binary sequence yields i A middle Random numbers between intervals ,as well as A combination of binary sequences k For the probability of the number of times "0" and "1" appear, convert the probability into binary numbers to form a sequence. ; S206: Will The random numbers are converted into the corresponding packet length; each random number is then processed by removing the units digit "0" and the decimal point to obtain an integer greater than 0. As the data packet length; if this integer is in the sequence When a matching packet length cannot be found, multiple packet lengths are added, subtracted, or combined to replace it. This process reduces the gap between covert and legitimate channels, resulting in the sequence to be transmitted. This completes the encoding process for the packet probability information; In step S3, the sharing rule transformation specifically includes: using a matrix Non-carrier data packets in the sequence are used to transmit covertly shared rule information by employing an embedding method based on data packet differences; the sender and receiver communicate in sequence. Before the election x The elements constitute the packet difference sequence. If the current position is in the matrix The length of the randomly selected non-carrier packet Belongs to sequence At that time, it is necessary to sequence The difference concealment mode is constructed by randomly selecting the length of the package according to formula (7); (7) For the block coding process, only k , n , x sum matrix The four shared rules that need to be replaced are scrambled; the arithmetic encoding process requires sharing the probability of "0" and "1" appearing for each packet length in the sequence of packet lengths to be sent; the steps for replacing the rules are as follows: 1) According to equation (8), the sender and receiver initialize using the agreed key. function: (8) 2) Generate using formula (9) A arrive Random numbers between: (9) 3) Both sender and receiver agree in advance on the available options. k , n and x The values are generated and a sequence of candidate values is formed, with each value in the sequence corresponding to a serial number; the scrambling operation is also formed into a sequence of candidate operations; the corresponding value is selected from the sequence of candidate values according to the serial number by generating random numbers, and the same operation is performed in the sequence of candidate operations to select the matrix transformation command; 4) Regulations A value of "0" represents a scramble operation, and a value of "1" represents... k , n , x Replacement; when in the channel When the value contains a single "1", change k Replace when two consecutive "1"s appear. n Replace when three consecutive "1"s appear. x ; 5) Change the sequence The elements are sorted in ascending order according to the number of "0"s and converted into a binary sequence. The packet lengths in the sequence form a difference pattern, which is used to transmit the probability of "0" and "1" appearing for each packet length in the sequence of packet lengths to be sent; The sender changes the shared rules required during the encoding process based on the relative positions of the vehicles during their travels. The two communicating parties set a distance threshold for the rule change, and when the relative position of the two vehicles exceeds the position threshold, step 4) rule change is executed. The receiver knows that the sender has changed the shared rules based on the relative position, and parses the changed rules according to step 3). This method achieves synchronization of rule changes between the sender and receiver. Finally, the sender sends the shared probability formed in the encoding process in step 5) to achieve information sharing. In step S5, information entropy adjustment specifically includes the following steps: S51: Let It is to sort the unsorted sequence by A window segmented by elements; It is by A window segmented by elements; S52: Statistics Window The same command The length of the packet and the frequency of its elements form a sequence. Count the frequency of elements belonging to the same packet length and form a sequence. ,sequence for The data packet length corresponding to each frequency in the sequence; where the frequencies in the sequence are sorted from largest to smallest, and a data packet is created. , and A copy of the original sequence; sequence For statistics window The frequency of elements with the same packet length in the packet. The packet length corresponding to the frequency; S53: Sequence The first element and Compare all elements in the table; if any appear Then In sequence Remove from the list and update. and Then proceed with the sequence. The comparison of the next element in the middle; S54: If Then With Subtract elements from each other to form a sequence. and for the sequence Sort the elements in ascending order; if the minimum value is Then and Corresponding command Change all package length elements to ,in For command The corresponding packet length type sequence, For sequence The length element of a randomly selected packet; if the minimum value is Then and Corresponding command of The element representing the length of a package is changed to Last updated Remove the modified elements from the original sequence, and then perform sequence reordering. The comparison of the next element in the middle; S55: Repeat S53 and S54 to complete the operation on all windows. The copy sequence is the adjusted data.
2. The VANET covert channel construction method according to claim 1, characterized in that, In step S2, the specific steps for decoding the vehicle receiver data are as follows: S211: The receiver receives the data transmitted by the sender and reads the length of the data packet for each message; S212: The receiver compares the length of the read data with the mapping relationship between the command combination and the hidden information constructed by the receiver, and the mapping relationship between the packet length type and the packet length sequence, and decodes the hidden information.
3. The VANET covert channel construction method according to claim 1, characterized in that, In step S6, an integrity verification process is added to the covert channel model. Specifically, the sender sends a digest of the covert information. The data packet is transmitted to the receiver, who calculates the digest using the decoded hidden information. Then compare and When performing digest calculation, the hidden information needs to be calculated in blocks to facilitate the receiver's location of incomplete information and request the sender to retransmit the hidden information; the specific steps of integrity verification are as follows: S61: In the second communication, the sender sends a digest of the covert information transmitted in the first communication to the receiver; S62: The receiver needs to calculate and If they are equal, proceed to step S63; if they are not equal, proceed to step S64. S63: When At that time, the receiver transmits a sequence to the sender. and Data elements are embedded within a range agreed upon by both parties; a session begins with an even number of consecutive non-carrier packet lengths and ends with an odd number of consecutive non-carrier packet lengths; sequences are randomly selected during the session. and The elements in the list, and require selection. The number of elements in is greater than The number of elements in the sequence; after receiving the information, the sender compares the number of packet lengths in the two sequences to determine which data does not need to be retransmitted; among them, to avoid decoding errors caused by packet loss, the sequence... and The number of selected packages should have a large difference; S64: When At that time, by randomly selecting a sequence in the session and The elements in the list, and require selection. The number of elements in is less than The number of elements in the sequence; after receiving the information, the sender determines which data needs to be retransmitted by comparing the number of packet lengths in the two sequences; where, the sequence needs to be... and The range of the number difference is used to characterize the location where incomplete information occurs.
Citation Information
Patent Citations
Method and system for hiding and transmitting information based on data packet length
CN104702596A
Concealed information sending system and sending method based on source address
CN108521331A