An Internet of Vehicles (IoV) knowledge sharing method, device, equipment and storage medium

By employing the hidden knowledge-sharing method based on graph-structured blockchain IOTA in the Internet of Vehicles (IoV), combined with AES encryption and asymmetric elliptic cryptography, the problems of information tampering and insufficient timeliness in IoV trajectory privacy protection are solved, achieving secure information transmission and subject anonymity, and preventing malicious node attacks.

CN118233142BActive Publication Date: 2025-12-19TIANJIN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410195371.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-22
Publication Date
2025-12-19
Estimated Expiration
2044-02-22

AI Technical Summary

Technical Problem

Existing methods for protecting vehicle-to-everything (V2X) trajectory privacy still have some significant shortcomings in intelligent connected vehicles, including insufficient information tampering and timeliness, as well as inadequate subject anonymity.

Method used

We adopt a hidden knowledge-sharing method based on the graph-structured blockchain IOTA, combining AES encryption and asymmetric elliptic cryptography. Through ring signatures and reputation value assessment mechanisms, we utilize network multi-hop relay technology to conceal the path and the subject, ensuring that the information is not tampered with on the chain and improving timeliness.

Benefits of technology

It ensures the immutability and timeliness of information, while guaranteeing the anonymity of the subject, effectively preventing malicious node attacks, and improving the security and anonymity of vehicle network knowledge sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118233142B_ABST
    Figure CN118233142B_ABST
Patent Text Reader

Abstract

The application relates to a vehicle networking hidden knowledge sharing method and device, equipment and a storage medium, wherein the vehicle networking hidden knowledge sharing method comprises the following steps: in a message sharing stage, an initial encryption is performed on a message, and ring signature members are selected to perform ring signature on the encrypted message; before a vehicle enters a new area to obtain a message, whether the vehicle can be connected to obtain the message is determined according to a reputation value of the vehicle; when the message is obtained, network multi-hop relay technology is used, asymmetric encryption is combined to perform path hiding and subject hiding, and the required message is broadcasted on a chain; a block on the chain obtains the message by itself, and the message is decrypted through a specific private key in a self area to obtain the message that a subject wants to obtain. The application can guarantee the hiding of message uploading and the hiding of subject obtaining.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a car networking hidden knowledge sharing method, device and equipment and storage medium. BACKGROUND

[0002] In intelligent networked vehicles, the trajectory information generated by the vehicle during operation can feedback the behavior patterns of the vehicle and the driving users, the vehicle trajectory is an important part of the privacy of the vehicle and the user, and the vehicle trajectory information is generally composed of continuous trajectory points updated by the vehicle. In active safety applications, vehicles participating in safety services are required to periodically broadcast beacon messages containing position, speed and other information, the purpose being to inform other vehicles of their own position information. There are four types of car networking trajectory privacy protection ideas, namely trajectory fuzzing, pseudonym replacement, trajectory encryption and differential privacy. The trajectory fuzzing model confuses the real vehicle users corresponding to multiple trajectories through continuous anonymous switching, so that the attacker cannot identify the vehicle user corresponding to the path from the trajectory set. The trajectory privacy protection method based on pseudonym replacement mainly includes a hybrid area-based method and a path confusion-based method, the implementation principle being to confound or hide the real path trajectory of the user, achieve information concealment, and prevent continuous tracking. The privacy protection method based on trajectory encryption uses cryptography to encrypt the real position of the user, which is completely invisible to LBS or other entities, thereby achieving trajectory privacy protection, and the technologies implemented include a PIR protocol-based method and a space conversion-based method. Although such schemes have been widely applied in car networking technology, they still have some non-negligible shortcomings.

[0003] Therefore, the present application provides a car networking hidden knowledge sharing method, device, equipment and storage medium. SUMMARY

[0004] (1) Technical problem to be solved

[0005] The present application provides a car networking hidden knowledge sharing method, device, equipment and storage medium, and the technical problem to be solved is that the existing car networking trajectory privacy protection method still has some non-negligible shortcomings.

[0006] (2) Technical solution

[0007] In a first aspect, the present application provides a car networking hidden knowledge sharing method, comprising:

[0008] In the message sharing stage, the message is initially encrypted, and a ring signature member is selected to perform ring signature on the encrypted message;

[0009] Before the vehicle enters a new area to obtain a message, it is determined whether the vehicle can be chained to obtain the message according to the reputation value of the vehicle;

[0010] When obtaining the message, the network multi-hop relay technology is used, path concealment and subject concealment are combined through asymmetric cryptography, and the required message is broadcasted on the chain;

[0011] The on-chain block obtains the message by itself, and decrypts the message through a specific private key in the region to obtain the message that the subject wants to obtain.

[0012] Further, the method further comprises the following steps before the ring signature member performs ring signature on the encrypted message after the initial encryption of the message in the message sharing stage:

[0013] If the number of vehicles applying for sharing knowledge is less than the set threshold, the information of road safety is sent as the confusion information.

[0014] Further, the step of selecting the ring signature member to perform ring signature on the encrypted message comprises:

[0015] The vehicles that need to share information and the vehicles in each region chain are combined to form a ring signature member, and the respective information is ring signed.

[0016] Further, the step of determining whether the vehicle can be chained to obtain the message according to the reputation value of the vehicle before the vehicle enters a new region to obtain the message comprises:

[0017] When the vehicle crosses the region and needs road condition information, a request is sent.

[0018] The reputation value of the vehicle is evaluated, and if the reputation value of the vehicle is greater than a set threshold, the vehicle is chained to perform information demand operation.

[0019] Further, the method further comprises the following steps after the step of determining whether the vehicle can be chained to obtain the message according to the reputation value of the vehicle before the vehicle enters a new region to obtain the message:

[0020] According to the DAG structure and the corresponding reputation value weight, the optimal path is selected, and the relay node is randomly changed in combination with the surrounding interactive vehicles.

[0021] Further, the step of obtaining the message by using the network multi-hop relay technology, combining the asymmetric cryptography to perform path concealment and subject concealment, and chaining the required message to broadcast comprises:

[0022] The found path is encrypted by the first group of public key and private key of elliptic cryptography to ensure the concealment of the path;

[0023] The information is encrypted by the second group of elliptic cryptography to ensure that the relay node can only obtain the address of the previous hop and the address of the next hop, and cannot know the complete path information;

[0024] After the request is responded, decryption is performed, the area position of the information requiring the uplink is relocated, and the uplink of the information decryption is performed.

[0025] Further, the on-chain block obtains the message by itself and decrypts the message by using the specific private key in the area to obtain the message that the subject wants to obtain, including:

[0026] The vehicle needs to download the information on the chain and decrypt the information by using the private key of the area to determine the information.

[0027] In the second aspect, the application provides a vehicle networking anonymous knowledge sharing device, including:

[0028] The encryption module is configured to, in the message sharing stage, perform initial encryption on the message, and select a ring signature member to perform ring signature on the encrypted message.

[0029] The judgment module is configured to, before the vehicle enters a new area to obtain the message, determine whether the vehicle can obtain the message on the chain according to the reputation value of the vehicle.

[0030] The anonymity module is configured to, when obtaining the message, perform path anonymity and subject anonymity by using network multi-hop relay technology and combining asymmetric cryptography, and broadcast the required message on the chain.

[0031] The decryption module is configured to, obtain the message by the on-chain block, and decrypt the message by using the specific private key in the area to obtain the message that the subject wants to obtain.

[0032] In the third aspect, the application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the vehicle networking anonymous knowledge sharing method as described above when executing the computer program.

[0033] In the fourth aspect, the application provides a computer readable storage medium, and the computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the vehicle networking anonymous knowledge sharing method as described above.

[0034] (3) Advantageous effects

[0035] The above technical solutions of the application have the following advantages:

[0036] The vehicle networking anonymous knowledge sharing method provided in the first aspect of the application is based on the IOTA of the graph structure block chain to chain the shared related data, guarantees the non-tamperability of the information and the timeliness of the chaining, and combines the encryption algorithm to encrypt the information, combines the proposed asymmetric elliptic cipher encryption method to guarantee the subject anonymity of the data interaction of the two parties. First, in the message sharing stage, a double encryption means is adopted, the message is initially encrypted by using the AES, and the encrypted message is subjected to the ring signature based on the SM2 by selecting the ring signature member, secondly, before the vehicle enters a new area to obtain the message, the initial reputation of the vehicle is scored, and only when the score is greater than the basic trust threshold of the architecture design, the vehicle can chain the message to obtain the message, otherwise the service is refused, in the reputation evaluation stage, the score of the last stage and the RSU and the edge vehicle are used to update the periodic reputation value of the vehicle, and the corresponding incentive mechanism is carried out according to the processed message, when obtaining the message, the network multi-hop relay technology is used, the asymmetric cipher is combined to realize the path anonymity and the subject anonymity, the required message is chained and broadcasted, the block on the chain can obtain the message by itself, and the message is decrypted by using the specific private key in the area to obtain the message that the subject wants to obtain. The anonymity of the message uploading and the anonymity of the subject obtaining are guaranteed.

[0037] It can be understood that the beneficial effects of the second aspect, the third aspect and the fourth aspect can be referred to the related description in the first aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the specific embodiments or prior art of the present application, the drawings needed in the specific embodiments or prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creating any creative labor.

[0039] Figure 1 The flowchart of the vehicle networking anonymous knowledge sharing method provided by the present application is shown in the figure.

[0040] Figure 2 The AES encryption related operation schematic diagram provided by the present application is shown in the figure.

[0041] Figure 3 The ring signature flowchart provided by the present application is shown in the figure.

[0042] Figure 4 The vehicle reputation value updating flowchart provided by the present application is shown in the figure.

[0043] Figure 5 The PSI protocol schematic diagram provided by the present application is shown in the figure.

[0044] Figure 6A malicious node attack schematic diagram provided for the present application;

[0045] Figure 7 A structure schematic diagram of the Internet of Vehicles anonymous knowledge sharing device provided for the present application;

[0046] Figure 8 A structure schematic diagram of the electronic device provided for the present application. DETAILED DESCRIPTION

[0047] In the following description, for the purpose of explanation and not limitation, specific details are set forth, such as particular system configurations, techniques, etc., in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the present application with unnecessary detail.

[0048] It should be understood that the term "comprise" as used in the specification and the appended claims, indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0049] In addition, in the description of the specification and the appended claims of the present application, the terms "first", "second", "third", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.

[0050] In the present application, the reference "one embodiment" or "some embodiments" means that the specific features, structures or characteristics described in connection with the embodiment are included in one or more embodiments of the present application. Therefore, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in further some embodiments" and the like appearing in different places in the specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "include", "contain", "have" and their variants mean "include but not limited to", unless otherwise specifically emphasized. "Multiple" means "two or more".

[0051] In the intelligent networked vehicle, the trajectory information generated by the vehicle during operation can feedback the behavior patterns of the vehicle and the driving users, the vehicle trajectory is an important part of the privacy of the vehicle and the user, and the vehicle trajectory information is generally composed of continuous trajectory points updated by the vehicle. In the active safety application, the vehicle participating in the safety service is required to periodically broadcast a beacon message containing position, speed and other information, the purpose being to inform other vehicles of its own position information.

[0052] Li et al. proposed a new three-layer network architecture model in the edge computing layer, and proposed a computing scheme for mutual cooperation between edge devices to reduce the communication delay between them. The main ideas of trajectory privacy protection in vehicle networking include four categories: trajectory fuzzing, pseudonym replacement, trajectory encryption, and differential privacy. The specific implementation methods are mainly based on real trajectory methods and virtual trajectory methods, hybrid area-based methods and path confusion-based methods, PIR protocol-based methods and space conversion-based methods.

[0053] The trajectory fuzzing model confuses the real vehicle users corresponding to multiple trajectories through continuous anonymous switching, so that the attacker cannot identify the vehicle user corresponding to the path from the trajectory set. The trajectory privacy protection method based on pseudonym replacement mainly includes hybrid area-based methods and path confusion-based methods. The implementation principle is to confuse or hide the real path trajectory of the user, realize information concealment, and prevent continuous tracking. The privacy protection method based on trajectory encryption uses cryptography to encrypt the real position of the user, which is completely invisible to LBS or other entities, realizing trajectory privacy protection. The implemented technologies include PIR protocol-based methods and space conversion-based methods. Although such schemes have been widely applied in vehicle networking technology, they still have some non-negligible shortcomings.

[0054] To solve the above problems, the application provides a blockchain-based vehicle networking hidden knowledge sharing method. The related data shared is chained based on the graph structure blockchain IOTA, ensuring the tamper resistance of the information and the timeliness of the chaining, and combining the encryption algorithm to encrypt the information, combining the proposed asymmetric elliptic encryption method to ensure the subject anonymity of the two-party data interaction.

[0055] The specific embodiments of the application will be described in further detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate the application, but not to limit the scope of the application.

[0056] As shown in Figure 1 The vehicle networking hidden knowledge sharing method provided by the embodiment includes:

[0057] S100, in the message sharing stage, the message is initially encrypted, and the ring signature member is selected to sign the encrypted message.

[0058] In some embodiments, after the message is initially encrypted in the message sharing stage, before the ring signature member is selected to sign the encrypted message, it further includes: judging whether the number of vehicles applying for sharing knowledge is greater than a set threshold, if less than the threshold, sending the information of road safety as the confusion information.

[0059] In some embodiments, the ring signature member selects the encrypted message, including: the vehicle that needs to share information and each regional chain to verify the on-chain vehicle public combination to form a ring signature member, and respectively ring sign each information.

[0060] In the application, when a vehicle has a problem and wants to share the message, the location information of the vehicle is first located to determine whether it is within the area controlled by the RSU. The information to be shared is first encrypted (using AES encryption technology). The number of vehicles applying for sharing knowledge is determined whether it is greater than the set threshold to determine whether the information needs to be mixed. When the threshold is less than the threshold, the road safety information is sent as a mixed information to ensure safety. The vehicle that needs to share information and each regional chain to verify the on-chain vehicle public combination to form a ring signature member, respectively ring sign each information and compare with local cache, update new message, and delete redundant information. Upload to RSU to save.

[0061] In the information sharing stage, when a vehicle in the area needs to share special knowledge, the anonymity of the information uploaded to the RSU needs to be ensured. The RSU uses road information to communicate with the terminal to assist the driver in driving and ensure vehicle safety. Assuming that the members of the overall architecture of the Internet of Vehicles are semi-honest, the uploaded message will be first encrypted by AES-128, and the private key of the initial blockchain in the region will be kept to decrypt later. The AES encryption stage is as follows:

[0062] C = E(K, P)

[0063] The plaintext is grouped as P = P0P1P2…P 15

[0064] The key is also grouped as K = K0K1K2…K 15

[0065] The state matrix of the plaintext is changed as the final ciphertext output. The AES encryption related operation diagram is as shown in Figure 2

[0066] After the message is encrypted by the first AES, the next step of ring signature member selection is started. The selection method selects any two on-chain blocks of the message subject and the on-chain confirmation subject. The specific method is as follows:

[0067] The ring signature member in a certain area is (C1C2C3)

[0068] ​The large area managed by the RSU is divided into small areas with similar characteristics, three groups of members including confusion messages are determined according to the ring signature member selection mode defined above (the confusion messages refer to normal traffic information, and the number is not enough for three groups, and the confusion message is supplemented), and the finally established member group is as follows:

[0069] The ring signature members of the large area managed by the RSU are (C1C2C3), (B1B2B3), (A1A2A3).

[0070] The ring signature flowchart is as shown in Figure 3 The uploaded messages are respectively ring signed and uploaded to the RSU, and the process of the ring signature based on SM2 is as follows:

[0071] System initialization algorithm: the algorithm inputs the security parameter λ and outputs the system parameter

[0072]

[0073] Where p is a large prime number, F p is a finite field; E(F p ) is an elliptic curve defined on the finite field, is a cyclic group of the additive group of points on E(F p ), q is the order number; G is the base point of the group ; H1: {0,1} * →Z q * is a secure hash function.

[0074] Key generation algorithm: user A randomly generates d A ∈Z q * as a private key and keeps it secret, and calculates the public key P A =d A ·G.

[0075] Ring signature generation: the signer selects the public keys of n-1 users spontaneously, adds the public key of itself to form a ring public key L={P1,P2,···,P n}, the signer is the πth (1≤π≤n) user, and generates a ring signature for the message m by using the private key d π and the ring public key L through algorithm 1:

[0076]

[0077]

[0078] Ring signature verification: after receiving the message m′ and the ring signature value (c1‘,s1‘,s2‘,…,s n ‘), the verifier realizes the following steps: verifying c1‘,s1‘∈Zq * If not, the verification fails, otherwise, the next step is executed; for i = 1, 2, …, n, Z is calculated in turn i i i i i i+1 i n+1 If yes, the verification is accepted, otherwise, the verification is rejected.

[0079] S200, before the vehicle enters a new area to obtain a message, determining whether the vehicle can obtain the message on a chain according to a reputation value of the vehicle.

[0080] In some embodiments, the determining whether the vehicle can obtain the message on a chain according to the reputation value of the vehicle before the vehicle enters a new area to obtain a message comprises: when the vehicle crosses an area to demand road condition information, sending a request; performing a corresponding evaluation operation on the reputation value of the vehicle, and if the reputation value of the vehicle is greater than a set threshold, the vehicle is on a chain to perform an information demand operation.

[0081] In some embodiments, after the determining whether the vehicle can obtain the message on a chain according to the reputation value of the vehicle before the vehicle enters a new area to obtain a message, the method further comprises: selecting an optimal path according to a DAG structure and a corresponding reputation value weight, and combining surrounding interactive vehicles to randomly change a relay node.

[0082] In the application, when a vehicle crosses an area to demand road condition information, a request is sent, a corresponding evaluation operation is performed on the reputation value of the vehicle, and a reputation value updating evaluation mechanism is as follows:

[0083]

[0084] α+b+c = 1, and through experiments, the three parameters are respectively set to 0.4, 0.3, and 0.3. i dis(V, RSU) refers to the distance between the vehicle and the RSU. (If an oil vehicle is entered, the battery capacity is set to the maximum.)

[0085] When the reputation value of the vehicle is greater than a set threshold, the vehicle is on a chain to perform an information demand operation, an optimal path is selected according to a DAG structure and a corresponding reputation value weight, and a relay node is randomly changed in combination with surrounding interactive vehicles to guarantee the randomness and effectiveness of the path.

[0086] ​​​​​​​Once the information is successfully transmitted to the RSU, the vehicle enters a new area and retrieves the message from the RSU. This requires determining whether the vehicle is on-chain and whether its reputation value exceeds a set threshold. A reputation update mechanism is introduced, initially setting the reputation value to 0.4. This reputation value is then evaluated in conjunction with the reputation values ​​of the RSU and edge vehicles to update the rating. The evaluation formula is as follows:

[0087] Given the energy measurement calculation formula for a vehicle:

[0088] EN(V i = C (vehicle computing power) + β (battery capacity, set to maximum for gasoline vehicles)

[0089] Reputation score calculation formula:

[0090]

[0091] The specific process is as follows: Figure 4 As shown.

[0092] Simultaneously, a message incentive mechanism is introduced, which rewards or penalizes nodes based on the importance of the messages processed. The specific algorithm is shown below:

[0093]

[0094] If a message's reputation value is greater than a set threshold, it can be uploaded to the blockchain. The reputation value is also updated during on-chain message processing. When the reputation value is too low, nodes with lower reputation values ​​will be avoided as much as possible when selecting a path.

[0095] S300: When obtaining a message, it uses network multi-hop relay technology and asymmetric cryptography to conceal the path and the subject, and broadcasts the required message on the blockchain.

[0096] In some embodiments, when obtaining a message, network multi-hop relay technology is used, combined with asymmetric cryptography to conceal the path and the subject, and the required message is broadcast to the blockchain. This includes: encrypting the found path using elliptic cryptography with a first set of public and private keys to ensure the path's concealment; encrypting the information using elliptic cryptography with a second set of encryption to ensure that the relay node can only obtain the address of the previous hop and the address of the next hop, but not the complete path information; after the request receives a response, decryption is performed, the location of the area where the information to be uploaded to the blockchain is relocated, and the decrypted information is uploaded to the blockchain.

[0097] In the application, the found path is elliptic encryption of the first set of public key and private key encryption operation, to ensure the anonymity of the path, the second set of elliptic encryption of information, to ensure that the relay node can only get the address of the last hop, and the address of the next hop, but can not know the complete path information. After the response of the request, decryption is performed, and the area position of the information is relocated. The information decryption is chained.

[0098] When the vehicle is chained, the RSU can be actively found to obtain messages, and multi-hop relay technology is used to obtain messages. The trajectory information of the vehicle is in time order, and the position sequence is composed of position information collected at the same time interval. The position information in this paper is a three-dimensional spatial coordinate composed of longitude, latitude and height, which is to better fit the real world. The coordinates at a certain time are represented by loc(N, E, H), where N represents latitude, E represents longitude, and H represents height information. The trajectory information of the vehicle is generated by periodically interacting with the server through data packets, and the transmission of data is carried out by taking data packets as the carrier. The data packet sequence can be generated by intercepting within a certain time:

[0099] Seq={P1(V id ,t1,loc1),P2(V id ,t2,loc2)...P n (V id ,t n ,loc n )}

[0100] Where P n represents a data packet generated by the vehicle interacting with the server at a certain time, and V id can represent the data packet generated by the vehicle with V id as the unique id, t n represents the timestamp of sending the data packet, and loc n represents the three-dimensional space position of the vehicle at time n. The data packet also contains the real request content of the user, and the server can analyze the trajectory of a certain vehicle id within a set time period, and describe the user behavior portrait combined with the user's query content.

[0101] Periodically probe the beacon message of the surrounding equipment to generate its own surrounding relay equipment list. The beacon message broadcast by each device will be attached with the first public key bound to the device identity id (the device id and the first public key are uniquely corresponding), and the first public key is used to provide other devices to generate transmission path. Determine the number of relay transmission hops and select nodes from the relay device list to generate a non-cyclic mutual forgetting transmission path. The structure of the query packet is as follows:

[0102]

[0103] The specific path finding algorithm is as follows:

[0104]

[0105] When selecting a path, the reputation value of each upper chain node is considered, because each area is a directed acyclic graph structure, the shortest path with weight is taken to find the optimal path that meets the requirements, and the random jump of surrounding vehicles is combined to find a path that meets the requirements as a hidden path for subsequent encryption operation.

[0106] The encrypted relay transmission path is generated and the encrypted real query is sent, the first public key is used, and the path is encrypted by means of elliptic cryptography. It is ensured that for the intermediate node, only the direct upstream and direct downstream can be determined, and the whole path information cannot be determined.

[0107] S400, the on-chain block obtains the message by itself, and decrypts it by a specific private key in the self area to obtain the message that the subject wants to obtain.

[0108] In some embodiments, the on-chain block obtains the message by itself, and decrypts it by a specific private key in the self area to obtain the message that the subject wants to obtain, including: the demand vehicle downloads information on the chain, and combines the private key pri key decrypts and determines the information.

[0109] In the application, the relay device parses the transmission path and transmits the request to the next hop until the end point of the transmission path is reached, at which time the end point device will send a query request to the server. When the relay transmission node receives the encrypted path transmitted from the upstream, it will use its own first private key to decrypt it. Thus, the downstream node is determined, and before transmission with the direct downstream node, the current decrypted node information is deleted from the transmission path. The downstream node follows the same specification until the last node is reached, at which time the node will send a query request to the server.

[0110] The response message is recursively returned to the real vehicle, and when the response message is received, the T ID field is extracted, the corresponding device ID node is found from the list of the self, and the ID-T ID pair is erased. The algorithm pseudo code is as follows:

[0111]

[0112] After positioning the area, the above encrypted message is decrypted by the area ring signature, and the message is chained. The demand information vehicle performs block mining, information download, and decryption operation according to the private key of the self area, so that the information in the area that the self wants to obtain can be obtained, and the anonymity of the demand vehicle information is ensured.

[0113] In the message uploading update process, in order to solve the problem of too large message load and too slow processing time, the local cache technology is adopted to determine the information that needs to be deleted in the local cache and the information that needs to be finally uploaded and updated by performing privacy set intersection (PSI) on the uploaded information and the locally cached information. A PSI protocol schematic diagram is shown in Figure 5 .

[0114] A malicious node attack schematic diagram is shown in Figure 6 . Since the data is deployed in the blockchain, the tamper-proof and data transparent characteristics of the blockchain can ensure the safe transmission of the information after being uploaded to the chain. At the same time, with the help of the DAG structure, the efficiency of block packaging and uploading to the chain and the rate of information transmission are greatly improved. The AES encryption is adopted to perform a first encryption operation on the information that needs to be shared, and the security is ensured again. Then, the ring signature is used to ensure the anonymity of the knowledge sharing subject information. The local cache and the PSI technology are used to reduce the information uploading load and ensure the timeliness of the information. When the vehicle demand information is required, an updated reputation evaluation architecture is established to ensure the honesty of the uploaded information and greatly reduce the possibility of path leakage when the subsequent jump path is determined. The elliptic curve encryption is used to perform different encryption operations on the path and vehicle related information to ensure that the relay node can only obtain the address of the previous hop and the address of the next hop, and cannot trace back to the subject of the demand information. In this way, in the entire semi-honest vehicle networking knowledge sharing framework, the malicious node directional attack can be effectively prevented, and the user can take corresponding operations. Through these security measures, the safety, timeliness and anonymity of the vehicle networking knowledge sharing are ensured, and a safe vehicle networking knowledge sharing scheme is provided.

[0115] The vehicle networking anonymous knowledge sharing method provided by the embodiments of the present application combines the vehicle networking technology with the blockchain, uses the AES encryption technology and the ring signature technology, proposes a safety method for knowledge sharing anonymity, uses the terminal multi-level continuous jump technology, combines the asymmetric password system elliptic curve encryption, encrypts the found path and information, ensures the anonymity of the message subject, establishes a reputation system architecture, updates the reputation value of the vehicle in the region, and effectively prevents the attack of the malicious node. At the same time, in order to ensure the timeliness of the information sharing, when the path is selected, the reputation value weight is selected and the blockchain of the graph structure is combined to select the optimal path, a local cache is created, the expired information and the data that need to be updated are determined according to the PSI protocol (privacy set intersection) technology, and the safety in the processing process is ensured.

[0116] The application can ensure the anonymity of the vehicle when uploading information for knowledge sharing, and can upload information to the RSU safely without exposing the location of the vehicle in the case of assuming that all members are not honest, and then obtain information. Combined with the related technology of block chain, the information on the chain is ensured not to be tampered with, and combined with the block chain of DAG architecture, the information sharing efficiency is greatly improved, the timeliness of information is ensured, and the requirements of the Internet of Vehicles environment are met. A reputation evaluation system is established, the node reputation value is updated in time, the malicious node attack is effectively resisted, and combined with the asymmetric password system, the path is transmitted anonymously to ensure the anonymity of the demand information subject and effectively resist the point attack of the malicious node.

[0117] The above technology effectively ensures the timeliness, security and anonymity of the Internet of Vehicles, prevents attacks by malicious nodes, and has undergone extensive security analysis and verification to ensure the security of the Internet of Vehicles knowledge sharing. With the increasing popularity of unmanned driving technology, the application of the proposed block chain-based Internet of Vehicles anonymous knowledge sharing scheme is of great significance, enhances the application range of information security in the Internet of Vehicles, and promotes further development. It provides a strong guarantee for the security of the subsequent development of the Internet of Vehicles.

[0118] Corresponding to the vehicle-to-everything anonymous knowledge sharing method described in the above embodiment, as shown in Figure 7 The embodiment provides a vehicle-to-everything anonymous knowledge sharing device 700, which comprises:

[0119] An encryption module 701 is configured to perform initial encryption on a message in a message sharing stage, and select a ring signature member to perform ring signature on the encrypted message.

[0120] A judgment module 702 is configured to determine whether a vehicle can obtain a message on a chain before the vehicle enters a new area to obtain the message according to a reputation value of the vehicle.

[0121] An anonymity module 703 is configured to perform path anonymity and subject anonymity by means of network multi-hop relay technology and asymmetric password when obtaining the message, and broadcast the required message on the chain.

[0122] A decryption module 704 is configured to obtain a message on a block, and decrypt the message by using a specific private key in a region to obtain a message that a subject wants to obtain.

[0123] It should be noted that the information interaction, execution process and the like between the above modules / units are based on the same concept as the method embodiment, and the specific functions and technical effects brought by the method embodiment are described in the method embodiment part, which will not be repeated here.

[0124] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the apparatus is divided into different functional units or modules to complete all or part of the above described functions. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction, and do not limit the protection scope of the present application. The specific working process of the units and modules in the system can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.

[0125] The embodiment of the present application also provides an electronic device 800, as shown in the figure, comprising a memory 801, a processor 802, and a computer program 803 stored in the memory 801 and executable on the processor 802, and the processor 802 implements the steps of the vehicle networking anonymous knowledge sharing method provided in the first aspect when executing the computer program 803. Figure 8

[0126] In application, the electronic device can include, but is not limited to, a processor and a memory, Figure 8 It is only an example of the electronic device and does not constitute a limitation on the electronic device, and can include more or fewer components than shown, or combine certain components, or different components, for example, input / output devices, network access devices, etc. The input / output device can include a camera, an audio acquisition / player device, a display screen, etc. The network access device can include a network module for wireless network with external devices.

[0127] In application, the processor can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0128] ​In applications, the storage can be an internal storage unit of the electronic device, such as a hard disk or a memory of the electronic device, in some embodiments. The storage can also be an external storage device of the electronic device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, and the like, in other embodiments. The storage can include both the internal storage unit and the external storage device of the electronic device. The storage is used to store an operating system, an application program, a boot loader, data, and other programs, such as program codes of computer programs, and the like. The storage can also be used to temporarily store data that has been output or will be output.

[0129] The embodiments of the present application further provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps in the above-mentioned various method embodiments.

[0130] The embodiments of the present application implement all or part of the processes in the above-mentioned method embodiments, which can be completed by a computer program instructing related hardware. The computer program can be stored in a computer readable storage medium, and when executed by a processor, the computer program can implement the steps in the above-mentioned various method embodiments. The computer program includes computer program codes, which can be in the form of source code, object code, executable files, or some intermediate forms, etc. The computer readable medium at least includes any entity or device capable of carrying the computer program code to an electronic device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. For example, a U disk, a mobile hard disk, a magnetic disk or an optical disk, etc.

[0131] Those skilled in the art can realize that the devices and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0132] In the embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other manners. For example, the embodiments of the device described above are merely schematic, and the mutual coupling or direct coupling or communication connection between the shown or discussed elements can be indirect coupling or communication connection through some interfaces; the indirect coupling or communication connection between the elements can be in electrical, mechanical or other forms.

[0133] The above embodiments are merely used for describing the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that the technical solutions recorded in the foregoing embodiments can be modified or equivalent replacements can be made to some of the technical features; and the modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A method for concealed knowledge sharing in the Internet of Vehicles, characterized in that, include: During the message sharing phase, the message is initially encrypted, and ring signature members are selected to ring sign the encrypted message; Before a vehicle enters a new area to retrieve a message, its credit score is used to determine whether it is eligible to access the blockchain to retrieve the message. When retrieving messages, the network multi-hop relay technology is used in conjunction with asymmetric cryptography to conceal the path and the subject, and the required message is broadcast on the blockchain. The on-chain block retrieves the message itself and decrypts it using a specific private key within its own area to obtain the message the subject wants to obtain; The formula for calculating the reputation value is as follows: in, Indicates vehicle The reputation score at time t. Indicates vehicle The reputation score at time t-1 Indicates vehicle energy index, Represents edge vehicle nodes energy index, Indicates vehicle and RSU The distance between them express RSU The farthest vehicle in the range and RSU The distance between them As weight and ; When obtaining messages, multi-hop relay technology is used in conjunction with asymmetric cryptography to conceal the path and the subject, and the required message is broadcast on the blockchain, including: The found path is encrypted using elliptic cryptography, which involves encrypting the first set of public and private keys to ensure the path's concealment. The second encryption of the information is performed using elliptic cryptography to ensure that the relay node can only obtain the address of the previous hop and the address of the next hop, but cannot know the complete path information; After receiving a response to the request, the information is decrypted, the location of the area where the information needs to be uploaded to the blockchain is relocated, and the information is decrypted and uploaded to the blockchain.

2. The method for concealed knowledge sharing in the Internet of Vehicles as described in claim 1, characterized in that, The step of ring signing during the message sharing phase, after initial encryption of the message and before selecting a ring signature member to ring sign the encrypted message, also includes: Determine if the number of vehicles requesting knowledge sharing exceeds a set threshold. If it is less than the threshold, send road safety information as obfuscation.

3. The method for concealed knowledge sharing in the Internet of Vehicles as described in claim 1, characterized in that, The step of selecting ring signature members to perform ring signature on the encrypted message includes: A ring signature member is formed by combining the vehicles that need to share information and the vehicles on each blockchain that verify whether they are on the chain, and each of them performs a ring signature on their respective information.

4. The method for concealed knowledge sharing in the Internet of Vehicles as described in claim 1, characterized in that, The step of determining whether a vehicle can access the blockchain to retrieve messages based on its reputation value before entering a new area includes: When a vehicle needs road condition information across regions, a request is sent. The credit score of a vehicle is evaluated accordingly. If the credit score of a vehicle is greater than a set threshold, the vehicle is added to the blockchain and an information request is made.

5. The method for concealed knowledge sharing in the Internet of Vehicles as described in claim 1, characterized in that, Before a vehicle enters a new area to retrieve messages, after determining whether the vehicle is eligible to retrieve messages on the blockchain based on its reputation value, the process also includes: The optimal path is selected based on the DAG structure and the corresponding reputation value weights, and the relay nodes are randomly changed in combination with the surrounding interacting vehicles.

6. The method for concealed knowledge sharing in the Internet of Vehicles as described in claim 1, characterized in that, The on-chain block retrieves the message itself and decrypts it using a specific private key within its own region to obtain the message the subject wants, including: The requesting vehicle downloads information on the blockchain and decrypts it using its own region's private key to confirm the information.

7. A vehicle-to-everything (V2X) hidden knowledge-sharing device, characterized in that, include: The encryption module is used to initially encrypt messages during the message sharing phase and select ring signature members to ring sign the encrypted messages; The judgment module is used to determine whether a vehicle can access the blockchain to retrieve messages based on its reputation value before the vehicle enters a new area to retrieve messages. The concealment module is used to conceal the path and the subject when retrieving messages by using network multi-hop relay technology and asymmetric cryptography, and broadcasting the required messages on the blockchain. The decryption module is used by on-chain blocks to obtain messages themselves and decrypt them using a specific private key within their own area to obtain the messages that the subject wants to obtain; The formula for calculating the reputation value is as follows: in, Indicates vehicle The reputation score at time t. Indicates vehicle The reputation score at time t-1 Indicates vehicle energy index, Represents edge vehicle nodes energy index, Indicates vehicle and RSU The distance between them express RSU The farthest vehicle in the range and RSU The distance between them As weight and ; The stealth module is specifically used for: The found path is encrypted using elliptic cryptography, which involves encrypting the first set of public and private keys to ensure the path's concealment. The second encryption of the information is performed using elliptic cryptography to ensure that the relay node can only obtain the address of the previous hop and the address of the next hop, but cannot know the complete path information; After receiving a response to the request, the information is decrypted, the location of the area where the information needs to be uploaded to the blockchain is relocated, and the information is decrypted and uploaded to the blockchain.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the vehicle network hidden knowledge sharing method as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the vehicle network hidden knowledge sharing method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Privacy protection method based on certificateless ring signcryption in vehicle-mounted ad hoc network

    CN110166228A

  • Internet of Vehicles privacy protection trust model based on block chain

    CN110300107A