A driving data encryption cloud storage method and system for automatic driving
Patent Information
- Application Number
- CN202310938611.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-28
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2043-07-28
AI Technical Summary
[0004]1.驾驶员安全问题:驾驶习惯数据中有驾驶员制动或加速的信息,若有人恶意篡改(比如把制动改成加速),则会造成生命危险
[0026]本发明公开一种用于自动驾驶的行车数据加密云存储方法与系统,初始化阶段:利用哈希算法,BLS签名算法和双线性映射算法来对驾驶习惯数据进行加密签名,保证驾驶习惯数据在传输过程中不被篡改;查询阶段:当遇到不可信的云端服务器篡改数据时,车辆能够验证云端服务器中的数据是否被篡改;更新阶段:云端服务器验证最新的驾驶习惯数据是否合法,验证通过后才会更新数据库中对应位置的驾驶习惯数据,从而保证了存储在云端服务器中数据的安全性。
Smart Images

Figure CN116723503B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of autonomous driving, and in particular to a method and system for encrypted cloud storage of driving data for autonomous driving. Background Technology
[0002] With the rapid development of autonomous driving, more and more cars are beginning to use autonomous driving functions. Depending on the driver, their driving habits also vary. Nowadays, vehicles store their driving data in vehicle memory or cloud storage. Compared with in-vehicle memory, cloud storage has advantages such as data backup and recovery, cross-device access, real-time data updates, and data sharing and collaboration.
[0003] While storing driving data in the cloud offers numerous conveniences, data security and privacy protection must be considered during the process. For example, measures need to be taken to protect data from unauthorized access, and relevant laws, regulations, and ethical guidelines must be followed to ensure the legal use of the data. Driving habit data stored in a cloud environment may face the following issues:
[0004] 1. Driver safety issues: Driving habit data contains information about the driver's braking or acceleration. If someone maliciously tampers with this data (for example, changing braking to acceleration), it could cause a life-threatening situation.
[0005] 2. Privacy issues: Driving habit data contains information about an individual's driving behavior, such as vehicle speed and driving route. If this data is leaked, it may lead to an infringement of personal privacy.
[0006] 3. Data security issues: Data stored in the cloud environment may be vulnerable to hacking and malware. Unauthorized access to data could lead to the leakage of personal information and data tampering.
[0007] 4. Data usage issues: If driving habit data is misused, it may have adverse effects on individuals.
[0008] To address the above issues, it is necessary to encrypt data during transmission and storage in the cloud to ensure that data is not tampered with during transmission and to guarantee the security of data stored on cloud servers. Summary of the Invention
[0009] The purpose of this invention is to provide a method and system for encrypted cloud storage of driving data for autonomous driving, which can ensure the security of driving habit data stored in a cloud server.
[0010] To achieve the above objectives, the present invention provides the following solution:
[0011] A method for encrypted cloud storage of vehicle data for autonomous driving, comprising:
[0012] During the system initialization phase, a private key for the cloud server is generated, and a public-private key pair for the vehicle is generated using a hash algorithm.
[0013] Based on the vehicle's private key, the original data is encrypted using the BLS signature algorithm and the bilinear mapping algorithm; the original data is driving habit data from the vehicle that needs to be uploaded to the cloud server.
[0014] Based on the private key of the cloud server, the cloud server uses the BLS signature algorithm to perform BLS aggregation verification on the encrypted original data, and stores the encrypted and signed original data in the database of the cloud server, while determining the system public key.
[0015] When the vehicle starts in autonomous driving mode, after receiving the query request sent by the vehicle, the cloud server queries the driving habit data stored in the corresponding location in the database to obtain the query results.
[0016] The cloud server calculates the proof based on the system public key and the query result, and sends the query result and the proof together to the vehicle;
[0017] Using the vehicle's public key, the query result received by the vehicle and the proof are verified, and the query result is decrypted after the verification is passed;
[0018] When a driver uploads the latest driving habit data to the cloud server, the cloud server verifies whether the latest driving habit data is valid, and updates the driving habit data in the corresponding location in the database after the verification is passed.
[0019] An encrypted cloud storage system for autonomous driving data includes: a sensing module, a processor, a vehicle controller, a communication module, and a cloud server;
[0020] The sensing module is connected to the processor, the processor is connected to the vehicle controller, and the vehicle controller is connected to the cloud server through the communication module.
[0021] The sensing module is used to measure the vehicle's driving data and send the driving data to the processor; the processor is used to send the driving data of a preset driving distance or a preset driving time to the vehicle controller.
[0022] System initialization phase: The vehicle controller is used to: generate a public-private key pair for the vehicle using a hash algorithm; encrypt the original data using the BLS signature algorithm and bilinear mapping algorithm based on the vehicle's private key; the original data is the data in the vehicle that needs to be uploaded to the cloud server; the cloud server is used to: generate its own private key; verify the signature of the encrypted original data using the BLS signature algorithm based on the cloud server's private key, and store the encrypted and signed original data in the cloud server's database, while simultaneously determining the system public key;
[0023] Query Phase: When the vehicle is in autonomous driving mode, the vehicle controller sends a query request for driving habit data to the cloud server. The cloud server, upon receiving the query request from the vehicle, queries the driving habit data stored in the corresponding location in the database to obtain the query result; calculates a proof based on the system public key and the query result, and sends the query result and the proof to the vehicle. The vehicle controller is also used to verify the query result and the proof received by the vehicle using the vehicle's public key, and decrypts the query result after successful verification.
[0024] Update phase: The vehicle controller uploads the latest driving habit data to the cloud server; the cloud server verifies the validity of the latest driving habit data and updates the corresponding driving habit data in the database after verification.
[0025] According to specific embodiments provided by the present invention, the present invention discloses the following technical effects:
[0026] This invention discloses a method and system for encrypted cloud storage of driving data for autonomous driving. In the initialization phase, a hash algorithm, BLS signature algorithm, and bilinear mapping algorithm are used to encrypt and sign driving habit data, ensuring that the data is not tampered with during transmission. In the query phase, when an untrusted cloud server tamperes with the data, the vehicle can verify whether the data in the cloud server has been altered. In the update phase, the cloud server verifies the legitimacy of the latest driving habit data; only after successful verification will the corresponding driving habit data in the database be updated, thus ensuring the security of the data stored in the cloud server. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1A flowchart illustrating a method for encrypted cloud storage of driving data for autonomous driving, provided in Embodiment 1 of the present invention;
[0029] Figure 2 A flowchart of the system initialization phase, query phase, and verification phase provided in Embodiment 1 of the present invention;
[0030] Figure 3 A flowchart of the update phase provided in Embodiment 1 of the present invention;
[0031] Figure 4 This is a plan view of a cloud storage system for encrypted vehicle data used in autonomous driving, provided in Embodiment 2 of the present invention.
[0032] Figure 5 This is a structural diagram of the vehicle interior provided in Embodiment 2 of the present invention;
[0033] Figure 6 This is a schematic diagram illustrating the working principle of a cloud storage system for encrypted vehicle data used in autonomous driving, provided in Embodiment 2 of the present invention.
[0034] Symbol explanation:
[0035] 1-Camera, 2-Telescopic steering wheel, 3-Retractable lever, 4-Display screen, 5-Seat, 6-Seat adjuster, 7-Cloud server, 8-Receive driver driving data link, 9-Send driver driving data link, 10-Communication module, 11-Wireless module, 12-Bluetooth module, 13-Cellular module, 14-Battery module, 15-Vehicle controller, 16-Temporary storage, 17-Processor, 18-Three-axis accelerometer, 19-Steering wheel angle sensor, 20-Pressure sensor, 21-Ultrasonic radar, 22-Left front wheel, 23-Left rear wheel, 24-Right front wheel, 25-Right rear wheel. Detailed Implementation
[0036] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0037] This invention primarily stores driver data in the cloud and encrypts the data during transmission and storage. Compared to directly storing data on a server, this invention utilizes cryptographic hash algorithms, BLS signature algorithms, and bilinear mapping algorithms to encrypt and sign the data, ensuring that the data is not tampered with during transmission and guaranteeing the security of the data stored on the cloud server. When an untrusted cloud server tamperes with the data, the vehicle can verify whether the data on the cloud server has been altered, thereby ensuring data security.
[0038] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0039] Example 1
[0040] like Figure 1 As shown, this embodiment of the invention provides a method for encrypted cloud storage of driving data for autonomous driving, including:
[0041] Step 1: During the system initialization phase, generate the private key for cloud server 7 and use a hash algorithm to generate the public and private key pair for the vehicle.
[0042] The vehicle and cloud server 7 respectively generate public and private keys, α, Y = g α and β, S=g β Where Y / α is the vehicle's public / private key, and S / β is the cloud server's public / private key. α, as the vehicle's private key sk, is generated from the driver's facial features using a hash algorithm. The legitimacy of Y and S is guaranteed by a trusted third-party CA.
[0043] Step 2: Based on the vehicle's private key, encrypt the original data using the BLS signature algorithm and the bilinear mapping algorithm; the original data is the driving habit data of the vehicle that needs to be uploaded to the cloud server 7.
[0044] The specific process is as follows:
[0045] The vehicle generates safety parameters k; based on safety parameters k, two multiplicative cyclic groups of prime order p are determined. and And construct bilinear pairs Among them, the multiplication cyclic group The generator is g; based on the multiplicative cyclic group Determine the bilinear mapping function e and the hash function. Select random number Based on the random number z i ,use 1≤i, j≤q, i≠j, calculate {h} i}1≤i≤q and {h i,j} 1≤i,j≤q,i≠j Where q represents the number of original data entries, and h i and h i,j This represents a portion of the public key generated by random numbers, {h i} 1≤i≤q h i The set composed of {h i,j} 1≤i,j≤q,i≠j h i,j The set that constitutes;
[0046] Based on the vehicle's private key α and {h i} 1≤i≤q ,in accordance with and v i =(ENC(m i ), 0), to encrypt the data in the vehicle that needs to be uploaded to the cloud server 7; among which, C represents the original encrypted value set for the i-th original data. R Represents a vector commitment. This indicates that each value in the vector is related to h. i Perform exponentiation, v i m represents the encrypted value on the i-th piece of original data. i Let i represent the message in the i-th original data, and ENC represent the symmetric encryption algorithm.
[0047] Step 3: Based on the private key of cloud server 7, cloud server 7 uses the BLS signature algorithm to perform BLS aggregation verification signature on the encrypted original data, and stores the encrypted and signed original data in the database of cloud server 7, while determining the system public key.
[0048] Specifically, this includes: cloud server 7 using the BLS signature algorithm to aggregate and verify the encrypted value of the original data; and using the formula based on the private key β of cloud server 7. Calculate the signature σ; based on the signature v, use the BLS signature algorithm to perform a BLS aggregation signature on the encrypted original data, and store the encrypted and signed original data in the database of cloud server 7; combine two multiplicative cyclic groups of prime order p. and Multiplication Cyclic Group Generator g, bilinear mapping function e, hash function {h i} 1≤i≤q and {h i,j} 1≤i,j≤q,i≠j Obtain common parameters Set the auxiliary verification information aux as: aux = {cux1, ..., cux}q}; where aux is the auxiliary verification information of the i-th original data. i satisfy Based on the common parameters PP and C R And auxiliary verification information aux, based on PK=(PP, C R , aux), determine the system public key PK.
[0049] Steps 1 to 3 constitute the system initialization phase. Based on the security parameter k and the vehicle's original data, the vehicle and cloud server 7 generate a public key PK and a private key SK (the vehicle's private key α). The public key PK is sent to the cloud server, and the private key SK is saved locally in the vehicle for subsequent update operations.
[0050] Step 4: When the vehicle starts in autonomous driving mode, after receiving the query request sent by the vehicle, the cloud server 7 queries the driving habit data stored in the corresponding location in the database to obtain the query results.
[0051] After the vehicle activates autonomous driving mode, the cloud server 7 receives the vehicle's request and queries driving habit data.
[0052] Step 5: The cloud server 7 calculates the proof based on the system public key and the query result, and sends the query result and the proof together to the vehicle.
[0053] The implementation process of this step is as follows: based on the system public key and the query result, using the formula... Calculate and prove π x ; where v x This represents the query results, specifically the data in the database indexed by x. This means taking h from the public key. x,j And perform v x Exponentiation;
[0054] The query results and the aforementioned proof are processed according to... Send to the vehicle; where T x T represents the counter for data updates at index x in the database. x The initial value is 0; This represents the Tth data in the database with index x. x The hash value after the next update and These represent the 1st and Tth occurrences of the data with index x in the database, respectively. x The updated bit position, τ, represents the proof generated by the server.
[0055] Step 6: Use the vehicle's public key to verify the query result and the proof received by the vehicle, and decrypt the query result after the verification is successful.
[0056] Determine whether the value of the counter received by the vehicle is less than the value of the counter in the signature stored locally in the vehicle, and obtain the determination result;
[0057] If the judgment result indicates yes, then the query result is determined to be historical invalid data, and the vehicle resends the query request to the cloud server 7;
[0058] If the judgment result is negative, then verify whether the query result received by the vehicle and the proof are valid; the valid judgment condition is as follows: and In the formula, This means taking h from the public key. x And perform v x Exponentiation, h x Y represents the value in the public key corresponding to index x in the database, and Y represents the public key of the vehicle.
[0059] After verifying the validity of the query result received by the vehicle and the proof, the vehicle decrypts the query result v using a decryption algorithm. x Decryption yields message m x and combined According to the formula Decryption yields the latest record Here, DEC represents the symmetric decryption algorithm.
[0060] As can be seen, after the vehicle interacts and verifies with the cloud server 7, the public key PK is set to (PP, C). R (aux). Steps 4 and 5 constitute the query phase, and step 6 is the verification phase. The process for steps 1 to 6 is as follows: Figure 2 .
[0061] Step 7: When the driver uploads the latest driving habit data to the cloud server 7, the cloud server 7 verifies whether the latest driving habit data is valid, and updates the driving habit data in the corresponding location in the database after the verification is passed.
[0062] Update Phase: Drivers upload their latest driving habit data to the cloud server. The cloud server verifies the data's legitimacy and modifies the data in the database after verification. This ensures the data source is legal and reliable.
[0063] Figure 3 This is a flowchart for the update phase. More detailed update steps are as follows:
[0064] Specifically, it includes:
[0065] 7.1 The vehicle initiates a data query request to the cloud server 7, executes the query and verification request, and verifies the BLS signature of the data corresponding to index x. Whether it is legal, and to verify the vehicle against the counter T in the database. x Whether to synchronize;
[0066] 7.2 After verifying legitimacy and synchronizing the verification, the vehicle calculates the T-th data in the database with index x based on the updated data. x Bit position after +1 update
[0067] 7.3 According to By iteratively updating the signature algorithm, using the formula Calculate signature t′ x and will Send to cloud server 7; among which, This represents the Tth data in the database with index x. x The hash value after +1 update;
[0068] 7.4 Cloud server 7 uses incremental encryption, based on the formula and Will Add it to the data with index x in the database; where v′ x express The data obtained after adding it to the data with index x in the database, m′ x This represents the modified value of index x in the database. Indicates passage and The newly generated bit ciphertext, This represents the current bit ciphertext. This represents the same value as P1, where P1 represents the bit position of the value with index 1 in the database. This represents the bits after the value at index x in the database has been modified.
[0069] 7.5 Cloud Server 7 Based on Update the signature and send the updated signature σ′ to the vehicle for verification;
[0070] 7.6 If the updated signature σ′ passes vehicle verification, then update the vehicle's local counter to T. x +1;
[0071] 7.7 The vehicle calculates a new token t′ based on the private key α. x And send the triple (x, t′) x , v′ x) to cloud server 7;
[0072] 7.8 If the cloud server verifies t′ x If valid, then cloud server 7 will update the data indexed as x in the database and update the system public key PK.
[0073] Data encryption occurs both during upload and upon arrival at the cloud. The encryption process primarily comprises four parts: system initialization, query phase, verification phase, and update phase. These encryption steps can be summarized as follows:
[0074] 1. During the system initialization phase, the vehicle and the cloud server generate a public key PK and a private key SK based on the security parameter k and the vehicle's original data. The public key PK is sent to the cloud server, and the private key SK is saved locally for subsequent update operations.
[0075] 2. Query Phase: After the vehicle activates autonomous driving mode, it reads driving habit data stored in the cloud. Upon receiving the vehicle's request, the cloud returns the driving habit data to the vehicle and generates a certificate based on the returned data and the public key.
[0076] 3. Verification Phase: After the vehicle receives the driving habit data and corresponding proof from the cloud server, it undergoes verification. The data is used only after successful verification. This ensures the data on the cloud server is authentic.
[0077] 4. Update Phase: Drivers upload their latest driving habit data to the cloud server. The cloud server verifies the data's legality and modifies the data in the database after verification. This ensures the data source is legal and reliable.
[0078] Compared to storing driving data directly in the cloud server 7, this invention uses cryptographic hash algorithms, BLS signature algorithms, and bilinear mapping algorithms to encrypt and sign the data, ensuring that the data is not tampered with during transmission and guaranteeing the security of the data stored in the cloud server 7.
[0079] When an untrusted cloud server 7 tampers with the data, the vehicle can verify whether the data in the cloud server 7 has been tampered with, thereby ensuring data security.
[0080] Because vehicles need to sign data before it can be verified by the cloud server, only those with the vehicle's private key can upload and modify data in the database, thus ensuring the reliability of the data source.
[0081] Example 2
[0082] To implement the method corresponding to Embodiment 1 above and achieve the corresponding functions and technical effects, a cloud storage system for encrypted vehicle data for autonomous driving is provided below, such as... Figure 4 As shown, it includes: a sensing module, a processor 17, a vehicle controller 15, a communication module 10, and a cloud server 7.
[0083] The sensing module is connected to the processor 17, the processor 17 is connected to the vehicle controller 15, and the vehicle controller 15 is connected to the cloud server 7 via the communication module 10. The sensing module is used to measure the vehicle's driving data and send the driving data to the processor 17; the processor 17 is used to send driving data for a preset driving distance or a preset driving time to the vehicle controller 15.
[0084] System initialization phase: The vehicle controller 15 is used to: generate a public-private key pair for the vehicle using a hash algorithm; encrypt the original data using the BLS signature algorithm and bilinear mapping algorithm based on the vehicle's private key; the original data is the data in the vehicle that needs to be uploaded to the cloud server 7; the cloud server 7 is used to: generate the private key for the cloud server 7; perform BLS aggregation verification signature on the encrypted original data using the BLS signature algorithm based on the private key of the cloud server 7, and store the encrypted and signed original data in the database of the cloud server 7, while determining the system public key.
[0085] Query Phase: When the vehicle starts in autonomous driving mode, the vehicle controller 15 sends a query request for driving habit data to the cloud server 7; the cloud server 7 is used to: after receiving the query request sent by the vehicle, query the driving habit data stored in the corresponding location in the database to obtain the query result; calculate a proof based on the system public key and the query result, and send the query result and the proof together to the vehicle; the vehicle controller 15 is also used to: use the vehicle's public key to verify the query result and the proof received by the vehicle, and decrypt the query result after passing the verification.
[0086] Update phase: The vehicle controller 15 is used to upload the latest driving habit data to the cloud server 7; the cloud server 7 is used to verify whether the latest driving habit data is valid, and after verification, it updates the driving habit data in the corresponding position in the database.
[0087] The sensing module includes a triaxial accelerometer 18, a pressure sensor 20, a steering wheel angle sensor 19, and an ultrasonic radar 21. The signal output terminals of the triaxial accelerometer 18, pressure sensor 20, steering wheel angle sensor 19, and ultrasonic radar 21 are all connected to the processor 17. The triaxial accelerometer 18 is used to measure the vehicle's longitudinal and lateral acceleration. The pressure sensor 20 is used to measure the pressure of the vehicle's brake pedal. The steering wheel angle sensor 19 is used to measure the steering wheel angle. The ultrasonic radar 21 is used to measure the following distance.
[0088] The system also includes a temporary storage device 16. The temporary storage device 16 is installed on the vehicle; the vehicle controller 15 is connected to the temporary storage device 16 via the communication module 10; when the communication module 10 fails to establish communication with the cloud server 7, a preset number of driving data entries are saved to the temporary storage device 16; after the communication module 10 and the cloud server 7 reconnect, the preset number of driving data entries in the temporary storage device 16 are uploaded to the cloud server 7 via the communication module 10.
[0089] Furthermore, the system also includes: a camera 1 and a display screen 4. The camera 1 is mounted on the vehicle's steering wheel; the display screen 4 is mounted inside the vehicle; both the camera 1 and the display screen 4 are connected to the vehicle controller 15; when the driver uses the cloud server 7 for the first time, the camera 1 performs facial recognition and inputs the driver's information, and the driver's ID number is entered on the display screen 4 and stored in the vehicle controller 15; from the second time the driver uses the cloud server 7, the camera 1 is used to perform facial recognition on the driver and transmit the identified driver's information to the vehicle controller 15; the vehicle controller 15 is used to retrieve the driver's driving data from the cloud server 7 through the communication module 10 based on the identified driver's information; the display screen 4 is used to display a message indicating successful data retrieval after the vehicle controller 15 successfully retrieves the driver's driving data in the autonomous driving environment, and to display a prompt asking whether the steering wheel needs to be folded; the vehicle controller 15 is also used to control the steering wheel to fold after vibrating twice after the driver selects to fold the steering wheel, and simultaneously control the seat 5 to adjust to the angle required by the driver in the autonomous driving environment, then start the vehicle and engage autonomous driving.
[0090] When a driver uses the cloud server 7 for the first time, they need to enter their ID card number on the vehicle's display screen 4 and undergo facial recognition via camera 1. After recognition, the driver's habit data is recorded. Afterwards, the driver no longer needs to verify their ID card information upon entering the vehicle; facial recognition can directly retrieve their driving information. Once recognition is complete, the driver's data is retrieved. In autonomous driving mode, after successful data retrieval, display screen 4 will show "Data retrieval successful." The screen will then indicate whether the steering wheel needs to be folded. If so, click "OK," and the steering wheel will fold after vibrating twice. Simultaneously, the seat 5 will adjust to the angle required by the driver in the autonomous driving mode (the angle varies depending on whether the driver is driving or not, and is set according to personal habits). The interior temperature can also be adjusted to the temperature set by the driver in the autonomous driving mode. Once all adjustments are complete, the vehicle starts and engages autonomous driving.
[0091] Figure 4This is a plan view of a cloud storage system for encrypted vehicle data used in autonomous driving, provided in Embodiment 2 of the present invention. Figure 4 The wireless module 11, Bluetooth module 12 and cellular module 13 together constitute the communication module 10. Figure 4 Also shown are the driver data receiving link 8, the driver data sending link 9, the battery module 14, the left front wheel 22, the left rear wheel 23, the right front wheel 24, and the right rear wheel 25. Figure 5 This is a structural diagram of the interior of a vehicle provided in Embodiment 2 of the present invention. Figure 5 The retractable lever 3 is responsible for retracting the steering wheel 2, and the seat adjuster 6 is responsible for adjusting the angle of the seat 5.
[0092] Figure 6 This is a schematic diagram illustrating the working principle of an encrypted cloud storage system for autonomous driving data. After the vehicle starts, the vehicle controller 15 activates a three-axis accelerometer 18, a pressure sensor 20, a steering wheel angle sensor 19, and an ultrasonic radar 21 to measure driving data. The driving data measured by each sensor is transmitted to the processor 17 for processing. If the driving distance is ≥300km or the driving time is ≥5h, the driving data is transmitted to the vehicle controller 15. The vehicle controller 15 then calls the communication module 10 to establish a connection with the cloud server 7 and finally stores the driving data on the cloud server 7. If the communication module 10 fails to establish communication with the cloud server 7, the driving data is saved to a temporary storage device 16. When the communication module 10 reconnects with the cloud server 7, the driving data in the temporary storage device 16 is uploaded back to the cloud server 7. If automatic driver data updates are enabled, data updates will be performed automatically when the driving distance is ≥300km or the driving time is ≥5h. If manual updates are enabled, only driver data is uploaded without updating the data.
[0093] The specific operations performed by processor 17 on the driving data measured by the various sensors include:
[0094] 1. The steering wheel angle sensor measures the circumference of the rotating shaft surface and calculates the rotation angle. The steering wheel angle sensor 19 measures the steering wheel rotation angle. First, it converts the steering wheel rotation into an electrical signal according to the formula Vout=S*θ0+V0, which is then transmitted to the processor 17. The processor 17 then calculates the electrical signal according to the formula θ=(Vout / V range )*θ max The electrical signal is converted into steering wheel angle. Here, θ0 represents the actual angle of steering wheel rotation, Vout represents the sensor's output voltage, V0 represents the zero-point offset (i.e., the output voltage at zero steering wheel angle), and S represents the sensor's sensitivity. θ represents the calculated steering wheel rotation angle, and V... range θ represents the voltage range output by the sensor. maxThis indicates the maximum steering wheel angle.
[0095] 2. The triaxial accelerometer 18 uses MEMS technology to measure acceleration. MEMS technology refers to a micromachined manufacturing technology that allows the fabrication of tiny electromechanical systems on a chip. The triaxial accelerometer 18 uses a MEMS accelerometer sensor to measure the acceleration of an object in three different directions. The sensor is typically fabricated using a microelectromechanical system, consisting of a tiny spring and a mass. When the vehicle is subjected to a force, the tiny mass moves relative to the spring. This movement causes a slight shift in the mass relative to a fixed part of the sensor, generating an electrical signal. This electrical signal represents the magnitude of the acceleration experienced by the object in that direction. The processor 17 acquires the vehicle's lateral and longitudinal acceleration data signals through the triaxial accelerometer 18 and uses formula a... y_vehicle =a x *cos(α)+a y *sin(α) and a x_vehicle =-a x *sin(α)+a y *cos(α) represents the three-dimensional acceleration (α) output by the triaxial accelerometer 18. x a y a z Transformed to the vehicle coordinate system: lateral and longitudinal accelerations (a) y_vehicle a x_vehicle ), where α represents the rotation angle between the sensor coordinate system and the vehicle coordinate system.
[0096] 3. Pressure sensor 20 is installed at the bottom of the brake pedal, with a pressure interface on one end and a signal line interface on the other. The pressure interface is used to detect the force applied by the driver when pressing the brake pedal, and the signal line interface is connected to processor 17 via a data cable to transmit the detected brake pressure data to processor 17. Pressure sensor 20 is used to measure the pressure applied to the brake pedal when the driver presses it. Currently, piezoelectric sensors are commonly used in automobiles. Their working principle is to convert pressure into an electrical signal, which is expressed by the formula V... out =S*P+V0 converts pressure into an electrical signal and transmits it to processor 17. Processor 17 then uses the formula F=(V out -V0) / S converts the electrical signal into a pressure value; where V out S represents the sensor's output voltage, P represents the sensor's sensitivity, V0 represents the pressure applied to the sensor, and F represents the zero-point offset (output voltage when there is no pressure). V represents the pressure applied to the brake pedal. out V represents the sensor's output voltage, V0 represents the zero-point offset, i.e., the output voltage when there is no pressure, and S represents the sensor's sensitivity.
[0097] 4. The ultrasonic radar 21 is used to measure the distance to vehicles or other obstacles ahead. First, it emits ultrasonic pulses via one or more ultrasonic sensors. These pulses are reflected back after hitting the vehicle or object ahead and are received by the ultrasonic radar 21. The ultrasonic radar 21 records the time difference Δt between the emission and reception of the ultrasonic pulse and transmits it to the processor 17. The processor 17 then calculates the distance using the Time-of-Flight (TOF) method, using the formula... Calculate the distance d between this vehicle and the vehicle in front or the object in front. Where c represents the ultrasonic pulse velocity.
[0098] 5. Due to the inherent errors in the data measured by the sensors and the complex distribution characteristics of the data, the data obtained by the sensors generally cannot be used directly and needs to be processed. Each sensor transmits the measured driving data to the processor 17, and the Kalman filter is used to filter the data measured by the sensors.
[0099] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section.
[0100] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. Furthermore, those skilled in the art will recognize that, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A method for encrypted cloud storage of driving data for autonomous driving, characterized in that, include: During the system initialization phase, a private key for the cloud server is generated, and a public-private key pair for the vehicle is generated using a hash algorithm. Based on the vehicle's private key, the original data is encrypted using the BLS signature algorithm and the bilinear mapping algorithm; the original data is driving habit data from the vehicle that needs to be uploaded to the cloud server. Based on the private key of the cloud server, the cloud server uses the BLS signature algorithm to perform BLS aggregation verification on the encrypted original data, and stores the encrypted and signed original data in the database of the cloud server, while determining the system public key. When the vehicle starts in autonomous driving mode, after receiving the query request sent by the vehicle, the cloud server queries the driving habit data stored in the corresponding location in the database to obtain the query results. The cloud server calculates the proof based on the system public key and the query result, and sends the query result and the proof together to the vehicle; Using the vehicle's public key, the query result received by the vehicle and the proof are verified, and the query result is decrypted after the verification is passed; When a driver uploads the latest driving habit data to the cloud server, the cloud server verifies whether the latest driving habit data is valid, and updates the driving habit data in the corresponding location in the database after the verification is passed; Based on the vehicle's private key, the original data is encrypted using the BLS signature algorithm and the bilinear mapping algorithm, specifically including: Vehicle generates safety parameter k; Based on the safety parameter k, the order of the two prime numbers is determined as follows: Multiplication cyclic group And construct bilinear pairs Among them, the multiplication cyclic group The generator is ; Based on multiplication loop group Determine the bilinear mapping function e and hash function ; Select random number ; Based on random numbers ,use ,calculate ;in, Indicates the number of original data entries. These represent the parts of the public key generated by random numbers. express The set that is formed express The set that constitutes; Based on the vehicle's private key and ,in accordance with and The data in the vehicle that needs to be uploaded to the cloud server is encrypted; among them, This represents the original encrypted value set for the i-th original data. Represents a vector commitment. Represents each value in the vector as a pair with... Perform exponentiation. This represents the encrypted value on the i-th piece of original data. This represents the message in the i-th piece of original data. This represents a symmetric encryption algorithm.
2. The method for encrypted cloud storage of driving data for autonomous driving according to claim 1, characterized in that, Based on the cloud server's private key, the cloud server uses the BLS signature algorithm to perform BLS aggregation verification and signature on the encrypted original data, and stores the encrypted and signed original data in the cloud server's database. Simultaneously, it determines the system public key, specifically including: The cloud server uses the BLS signature algorithm to aggregate and verify the encrypted value of the original data; Based on the private key of the cloud server Using the formula Calculate signature ; Based on signature The BLS signature algorithm is used to perform BLS aggregate signature on the encrypted original data, and the encrypted and signed original data is stored in the database of the cloud server. Combining two prime numbers of order Multiplication cyclic group Multiplication Cyclic Group generator Bilinear mapping function e Hash function , Obtain common parameters ; Set auxiliary verification information for: Among them, the auxiliary verification information of the i-th original data satisfy ; According to public parameters , and auxiliary verification information ,in accordance with Determine the system public key .
3. The method for encrypted cloud storage of driving data for autonomous driving according to claim 2, characterized in that, The cloud server calculates a proof based on the system public key and the query result, and sends the query result and the proof together to the vehicle, specifically including: Based on the system public key and the query results, using the formula Calculation proof ;in, This indicates the query result, i.e., the index in the database. x Data, This means retrieving from the public key. And carry out Exponentiation; The query results and the aforementioned proof are processed according to... Send to the vehicle; among them, This indicates that the index in the database is x The data update counter, The initial value is 0; This indicates that the index in the database is x Data No. The hash value after the next update and These respectively represent the indexes in the database as x Data 1st and 2nd The bit position after the next update This indicates the certificate generated by the server.
4. The method for encrypted cloud storage of driving data for autonomous driving according to claim 3, characterized in that, Using the vehicle's public key, the query result received by the vehicle and the aforementioned proof are verified. After successful verification, the query result is decrypted, specifically including: Determine whether the value of the counter received by the vehicle is less than the value of the counter in the signature stored locally in the vehicle, and obtain the determination result; If the judgment result indicates yes, then the query result is determined to be historical invalid data, and the vehicle resends the query request to the cloud server; If the judgment result is negative, then verify whether the query result received by the vehicle and the proof are valid; the valid judgment condition is as follows: and In the formula, This means retrieving from the public key. And carry out Exponentiation, This indicates that the index in the database is x The value corresponding to the public key, The public key representing the vehicle; After verifying the validity of the query result received by the vehicle and the proof, the vehicle decrypts the query result using a decryption algorithm. Decryption yields the message and combined According to the formula = Decryption yields the latest record ;in, This represents a symmetric decryption algorithm.
5. The method for encrypted cloud storage of driving data for autonomous driving according to claim 4, characterized in that, When a driver uploads their latest driving habit data to the cloud server, the cloud server verifies the validity of the latest driving habit data and updates the corresponding driving habit data in the database after successful verification. This includes: The vehicle sends a data query request to the cloud server, executes the query and verification requests, and verifies the index. BLS signature of the corresponding data Whether it is legal, and to verify the vehicle against the counter in the database. Whether to synchronize; After verification of legitimacy and synchronization, the vehicle calculates the index in the database based on the updated data. x Data No. Bit position after +1 update ; according to By iteratively updating the signature algorithm, using the formula Calculate signature and will ( Send to the cloud server; among which, This indicates that the index in the database is x Data No. The hash value after +1 update; The cloud server uses incremental encryption, based on the formula. , and ,Will Added to the database index as x On the data; among them, express Added to the database index as x The data obtained after processing the data This indicates that the index in the database is The modified value, Indicates passage and The newly generated bit ciphertext, This represents the current bit ciphertext. Indicates and Same value, This represents the bit position of the value with index 1 in the database. This indicates that the index in the database is The value of the modified bit; cloud server based Update the signature and display the updated signature. Send to the vehicle for verification; If the updated signature If vehicle verification is successful, update the vehicle's local counters. ; Vehicles based on private keys Calculate the new token and send triples To the cloud server; If cloud server verification If valid, the cloud server updates the index in the database as follows: x The data, and the updated system public key. .
6. A cloud storage system for encrypted vehicle data used in autonomous driving, characterized in that, include: Sensing modules, processors, vehicle controllers, communication modules, and cloud servers; The sensing module is connected to the processor, the processor is connected to the vehicle controller, and the vehicle controller is connected to the cloud server through the communication module. The sensing module is used to measure the vehicle's driving data and send the driving data to the processor; the processor is used to send the driving data of a preset driving distance or a preset driving time to the vehicle controller. System initialization phase: The vehicle controller is used to: generate a public-private key pair for the vehicle using a hash algorithm; encrypt the original data using the BLS signature algorithm and bilinear mapping algorithm based on the vehicle's private key; the original data is the data in the vehicle that needs to be uploaded to the cloud server; the cloud server is used to: generate its own private key; verify the signature of the encrypted original data using the BLS signature algorithm based on the cloud server's private key, and store the encrypted and signed original data in the cloud server's database, while simultaneously determining the system public key; Based on the vehicle's private key, the original data is encrypted using the BLS signature algorithm and the bilinear mapping algorithm, specifically including: Vehicle generates safety parameter k; Based on the safety parameter k, the order of the two prime numbers is determined as follows: Multiplication cyclic group And construct bilinear pairs Among them, the multiplication cyclic group The generator is ; Based on multiplication loop group Determine the bilinear mapping function e and hash function ; Select random number ; Based on random numbers ,use ,calculate ;in, Indicates the number of original data entries. These represent the parts of the public key generated by random numbers. express The set that is formed express The set that constitutes; Based on the vehicle's private key and ,in accordance with and The data in the vehicle that needs to be uploaded to the cloud server is encrypted; among them, Represented as the first i The original encryption value set for the original data. Represents a vector commitment. Represents each value in the vector as a pair with... Perform exponentiation. This represents the encrypted value on the i-th piece of original data. This represents the message in the i-th piece of original data. This represents a symmetric encryption algorithm; Query Phase: When the vehicle is in autonomous driving mode, the vehicle controller sends a query request for driving habit data to the cloud server. The cloud server, upon receiving the query request from the vehicle, queries the driving habit data stored in the corresponding location in the database to obtain the query result; calculates a proof based on the system public key and the query result, and sends the query result and the proof to the vehicle. The vehicle controller is also used to verify the query result and the proof received by the vehicle using the vehicle's public key, and decrypts the query result after successful verification. Update phase: The vehicle controller uploads the latest driving habit data to the cloud server; the cloud server verifies the validity of the latest driving habit data and updates the corresponding driving habit data in the database after verification.
7. The cloud storage system for encrypted vehicle data for autonomous driving according to claim 6, characterized in that, The sensing module includes: a three-axis accelerometer, a pressure sensor, a steering wheel angle sensor, and an ultrasonic radar; The signal output terminals of the triaxial accelerometer, pressure sensor, steering wheel angle sensor, and ultrasonic radar are all connected to the processor. The triaxial accelerometer is used to measure the longitudinal and lateral acceleration of the vehicle; The pressure sensor is used to measure the pressure of the vehicle's brake pedal. The steering wheel angle sensor is used to measure the steering wheel angle. The ultrasonic radar is used to measure the following distance.
8. The vehicle data encryption cloud storage system for autonomous driving according to claim 6, characterized in that, Also includes: Temporary storage; The temporary storage device is located on the vehicle; The vehicle controller is connected to the temporary storage via a communication module; When the communication module fails to establish communication with the cloud server, a preset number of driving data entries are saved to a temporary storage device. After the communication module and the cloud server reconnect, the preset number of driving data entries in the temporary storage device are uploaded to the cloud server through the communication module.
9. The vehicle data encryption cloud storage system for autonomous driving according to claim 6, characterized in that, Also includes: Camera and display screen; The camera is mounted on the vehicle's steering wheel; The display screen is installed inside the vehicle; Both the camera and the display screen are connected to the vehicle controller; When a driver uses the cloud server for the first time, facial recognition and data entry are performed using a camera, and the driver's ID number is entered on the display screen and stored in the vehicle controller. From the second time the driver uses the cloud server, the camera is used to perform facial recognition on the driver and transmit the recognized driver information to the vehicle controller. The vehicle controller is used to retrieve the driver's driving data from the cloud server through the communication module based on the identified driver's personal information; The display screen is used to display the message "Data retrieval successful" and a prompt asking whether the steering wheel needs to be folded after the vehicle controller successfully retrieves the driver's driving data in an autonomous driving environment. The vehicle controller is also used to control the steering wheel to fold after the driver selects to fold the steering wheel twice, and at the same time control the seat to adjust to the angle required by the driver in the autonomous driving environment, and then start the vehicle and start autonomous driving.
Citation Information
Patent Citations
Method for inquiring and verifying data of internet-of-vehicles RSU (Remote Subscriber Unit) based on cloud platform
CN104361295A
Encryption processing method and equipment for automatic driving data under 5G communication
CN112040482A