A Malicious Vehicle Detection Method Based on Trust Score in the Internet of Vehicles Environment
By adopting a trust-based malicious vehicle detection method and a distributed architecture trust evaluation system in the Internet of Vehicles environment, the security threat of malicious vehicles sending error messages and the lack of scalability of the trust platform is solved, efficient and accurate detection and processing of malicious vehicles are achieved, and information security of the Internet of Vehicles environment is ensured.
Patent Information
- Application Number
- CN202410074979.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-18
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-01-18
AI Technical Summary
There is a risk of malicious vehicles sending error messages in the Internet of Vehicles environment, which leads to security threats. The existing technology trust platform lacks scalability and real-time performance, making it difficult to meet the requirements of Internet of Vehicles for real-time, reliability and scalability.
A distributed architecture trust evaluation system is established through the process of system initialization, vehicle registration, cloud supervision system registration, malicious vehicle reporting and trust score addition and decrease, and a distributed architecture is used to schedule and load balancing the cloud supervision system nodes to improve the robustness and performance of the system.
It realizes efficient and accurate detection and processing of malicious vehicles, ensures the information security of the Internet of Vehicles environment, improves the robustness of the trust mechanism and system performance, and is suitable for Internet of Vehicles scenarios with high real-time requirements.
Smart Images

Figure CN118945664B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle safety communication, and particularly relates to a malicious vehicle detection method based on trust scores in a vehicle networking environment. Background Art
[0002] With the rapid development of information technology and the rise of intelligent transportation systems, vehicle networking, as a new type of network application mode, has become the focus of extensive attention and research. Especially the rise of 5G technology has brought major changes and development opportunities to the field of vehicle networking. Vehicle networking connects vehicles to the Internet and realizes efficient communication and information exchange between vehicles, between vehicles and road networks, and between vehicles and people through various sensors. By making decisions instantly through communication and information sharing between vehicles, traffic jams can be avoided, traffic efficiency can be improved, and functions such as navigation and online entertainment can be provided for users, thus better meeting user needs.
[0003] Although vehicle networking provides many conveniences for people, it also faces a series of challenges and problems, especially security and privacy protection issues. First, there is information interaction between vehicles, but each vehicle cannot quickly judge the correctness of this information. If a malicious vehicle sends incorrect information, it will lead to serious consequences and even threaten the lives of drivers. Therefore, a malicious behavior monitoring and processing mechanism needs to be established between vehicles to prevent such problems. At the same time, the cooperation and communication between vehicles also face trust issues, and establishing a trustworthy mechanism is an important and complex task. To solve the attacks of malicious devices, it is particularly important to construct a reliable trust system between devices. In addition, vehicle networking vehicles also need to meet the requirements of real-time performance, reliability, and scalability to cope with complex and changeable traffic environments.
[0004] To detect malicious vehicles in vehicle networking, researchers have proposed relevant solutions using means such as cryptographic technology, identity authentication, and access control. For example, aiming at the problem that the transmission and sharing of vehicle networking data in different regions may encounter cross-domain issues, a federated detection hierarchical mechanism is proposed to achieve unified evaluation between devices and improve the speed of identity authentication and the detection accuracy of malicious devices. However, some solutions use blockchain to build a trust platform, which has problems such as low detection efficiency and limited scalability and is not suitable for vehicle networking scenarios with high real-time requirements. Summary of the Invention
[0005] The purpose of the present invention is to provide a malicious vehicle detection method based on trust scores in a vehicle networking environment to solve the problems existing in the above-mentioned prior art.
[0006] A malicious vehicle detection method based on trust scores in a vehicle networking environment provided by the present invention includes:
[0007] The system initializes to generate system public parameters;
[0008] Vehicle user registration and cloud supervision system node registration are respectively carried out. The successfully registered vehicle users and cloud supervision system nodes obtain parameter information based on the system public parameters;
[0009] After multiple vehicle users log in successfully based on the parameter information, they send messages to each other by establishing a session key between two entities. The two entities evaluate the received messages and send the reported information to the cluster head vehicle;
[0010] The cluster head vehicle sends the reported information and the identity information of the reported vehicle to the authoritative center. The authoritative center selects available cloud supervision system nodes. The available cloud supervision system nodes judge the reported information and the identity information of the reported vehicle, and send the judgment result to the authoritative center;
[0011] The authoritative center increases or decreases the trust scores of the two entities that establish the session key based on the judgment result.
[0012] Optionally, the process of vehicle user registration includes:
[0013] The vehicle user sends a unique identity identification and password to the authoritative center to obtain authentication information parameters;
[0014] The authoritative center judges whether the current vehicle user is a new user based on the authentication information parameters. When the current vehicle user is a new user, the authoritative center generates anti-attack parameters and sends them to the vehicle user;
[0015] The vehicle user calculates and generates RIW i , K i , Q i , B i ;
[0016] The authoritative center calculates and generates A i .
[0017] Optionally, the calculation formulas for generating RIW i , K i , Q i , B i and A i are as follows:
[0018]
[0019] B i =P i *H 1 (RIW i ||VID i ||Ki )
[0020]
[0021] In the formula, H 1 represents a hash function, UID i represents the user's unique identification, AID i represents the user's unique anonymous identification, UPW i represents the password, P i represents the public key generated by the authority center, B i represents the vehicle user User i the calculated result, VID i represents the vehicle's unique identification, RIW i , K i , B i , Q i , A i represents the result of formula calculation, r represents the random number generated by the user, s i represents the random number generated by the authority center, || represents the string concatenation operation, represents the exclusive OR operation.
[0022] Optionally, the process of registering the cloud supervision system node includes:
[0023] Randomly generate a random number u and the unique identification CID of the cloud supervision system based on a pseudo-random number generator i ;
[0024] Based on the random number u and the unique identification CID of the cloud supervision system i Calculate D i , where
[0025] Send D i to the authority center, and the authority center generates a random number v;
[0026] The authority center calculates E i based on D i , where and send E i to the cloud supervision system node to complete the registration.
[0027] In the formula, D i , E i represents the result of formula calculation. || represents the string concatenation operation, represents the exclusive OR operation.
[0028] Optionally, the process of the vehicle user logging in to the vehicle system includes:
[0029] Input the unique identification and password of the user vehicle, and the system automatically calculates C i , and generates a timestamp CT i , where
[0030] The vehicle determines the validity of the verification time based on the threshold between the current time and the timestamp;
[0031] When the verification time is valid, the vehicle calculates K i , B i to verify the correctness of the password. When B i = B i , the user logs in successfully and a verification success message is returned; otherwise, the user logs in fails and a verification failure message is returned, where
[0032] Optionally, before the authority center selects an available cloud supervision system node, the authority center performs a serviceability determination on the cloud supervision system node based on a heartbeat ratio protection mechanism. The process of the serviceability determination is as follows:
[0033] The heartbeat ratio protection mechanism sets a ratio threshold;
[0034] The cloud supervision system node sends a heartbeat to the authority center every specified threshold time;
[0035] When the heartbeat within the specified threshold time is lower than the ratio threshold, the cloud supervision system node is removed; otherwise, the cloud supervision system node is retained.
[0036] Optionally, the metrics for the entity to independently evaluate the received messages include: the time ratio of the successfully transmitted information of the vehicle entity sending information to the total messages sent by the vehicle, the ratio of the number of forwarded messages of the vehicle to the number of all correctly received messages, and the ratio of the number of lost data packets to the total number of sent data packets.
[0037] Optionally, the process by which the cluster head vehicle sends the reported information and the identity information of the reported vehicle to the authority center and makes a judgment on the reported information and the identity information of the reported vehicle based on the available cloud supervision system node includes:
[0038] When the authority center receives a data request from the cluster head vehicle, the authority center performs identity verification based on the timestamp and the user password;
[0039] After the identity verification is passed, the authority center selects an available cloud supervision system node, and the available cloud supervision system node calculates the data information of the cluster head vehicle and obtains an information truth or false result based on the data information;
[0040] The cloud supervision system node sends the information truth result and the timestamp of the sent information to the authoritative center, and the authoritative center judges the timestamp of the sent information. When the timestamp of the sent information is within the specified delay time, the trust scores of all reported vehicles are statistically calculated respectively;
[0041] When the trust score of the reported vehicle satisfies TS i <TTS, the vehicle can report, otherwise the vehicle cannot report, where TS i represents the trust score of vehicle V i and TTS represents the threshold of the trust score;
[0042] When the vehicle can report and the information truth result is true, rewards are given to the reported vehicle and the vehicle being reported;
[0043] When the vehicle can report and the information truth result is false, punishments are given to the reported vehicle and the vehicle being reported.
[0044] The present invention has the following technical effects:
[0045] The present invention adopts a distributed architecture to cluster the trust institution and the cloud supervision system nodes, and uses the central node of the trust institution as the core node to manage and schedule the entire trust evaluation process. The central node of the trust institution is responsible for managing and coordinating the trust evaluation process of the entire system, and allocates tasks to the corresponding cloud supervision nodes according to different scenarios and requirements to achieve division of labor and cooperation and optimize performance, greatly improving the robustness of the vehicle networking trust mechanism.
[0046] The present invention adopts the scheduling and load balancing of the central trust node for the cloud supervision system nodes. This mechanism enables the central node to make scheduling decisions on the resources of each cloud supervision system node by the cloud supervision nodes regularly sending their own availability information to the trust evaluation central node, thereby achieving the best load balancing and system performance, and greatly improving the resource utilization efficiency.
[0047] Most of the existing technologies adopt blockchain to build a trust platform. However, the design of blockchain causes its performance to decline when dealing with a large number of transactions, and there are also limitations in scalability. For scenarios with high requirements for real-time performance such as vehicle networking, blockchain may not be able to meet its high concurrency and low latency requirements. The characteristics of vehicle networking determine that it has strict requirements for real-time performance, reliability and scalability. The present invention adopts a distributed and scalable architecture to effectively address these problems, and the present invention uses elliptic curve encryption to authenticate messages, with relatively small computational overhead, greatly improving the efficiency. Description of the Drawings
[0048] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0049] Figure 1 It is the flowchart in the embodiment of the present invention;
[0050] Figure 2 It is the vehicle registration process diagram in the embodiment of the present invention;
[0051] Figure 3 It is the cloud supervision system registration process diagram in the embodiment of the present invention;
[0052] Figure 4 It is the vehicle user login process diagram in the embodiment of the present invention;
[0053] Figure 5 It is the three-party interaction and vehicle trust score evaluation process diagram in the embodiment of the present invention. Detailed implementation manners
[0054] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0055] Embodiment 1
[0056] As Figure 1 shown, this embodiment discloses a malicious vehicle detection method based on trust score in a vehicle networking environment, including:
[0057] The present invention provides a method for detecting malicious vehicles based on trust scores in a vehicle networking environment, including processes such as system initialization, vehicle registration, cloud supervision system registration, malicious vehicle reporting, initial screening of reported information by a trusted authority, vehicle behavior detection by the cloud supervision system, and increasing or decreasing trust scores by the trusted authority according to vehicle behavior. The present invention adopts a trust aggregation method to calculate the initial trust score of a vehicle through trust evaluation. Then, based on comprehensive consideration of vehicle data, the trust score of each vehicle is further calculated to evaluate its trustworthiness. By punishing malicious vehicles and rewarding trust scores to vehicles that correctly send reported information, the environmental credibility of the entire system is further improved. The present invention clusters the trust institutions and cloud supervision system nodes using a distributed architecture, and uses the trust institution central node as the core node to manage and schedule the entire trust evaluation process. In order to effectively utilize the resource characteristics of the cloud supervision system nodes, the present invention introduces a heartbeat mechanism and adopts the trust center node to schedule and balance the load of the cloud supervision system nodes. The present invention can efficiently and accurately detect and process malicious vehicles in a vehicle networking environment, ensure the information security in the vehicle network, and has a wide application prospect.
[0058] The present invention consists of three layers, namely, numerous cloud supervision system nodes (CSSs), multiple trusted authority centers (TAIs), roadside units (RSUs), and vehicles V. The first layer consists of numerous vehicles. Data can be exchanged between vehicles, which can achieve vehicle intelligence and collaboration. To achieve data exchange, each vehicle is equipped with communication devices such as dedicated short-range communication (DSRC) and wireless access (WAVE), enabling the vehicle to communicate with the surrounding environment. The second layer is multiple trusted authority centers TAI, which is the core part of the vehicle safety system proposed by the present invention. TAI is composed of official institutions. TAI is responsible for generating and distributing public-private key pairs and registering the identity information of vehicles. When a vehicle detects the behavior of a malicious vehicle, it can send a reported information to TAI. TAI will conduct preliminary screening and verification of the received information, and then interact with CSS. CSS queries the correctness and timeliness of the reported information. According to the query results sent by CSS to TAI, and the trust scores and quantities of the reported vehicles, TAI will give corresponding rewards or punishments to the vehicles that send information and the reported vehicles. The third layer is the cloud supervision system, whose main function is to monitor the road conditions in real time and sort out relevant information, and is responsible for supervision by a camera-based traffic monitoring system. Through the collaborative work of numerous CSS nodes, this system monitors and records the movement of vehicles on the road, and uploads the collected data to the cloud for processing and analysis.
[0059] A research method for a malicious vehicle detection mechanism based on trust scores in this embodiment includes the following steps:
[0060] S1: In the system initialization phase, system public parameters are generated. First, the trusted authority center TAI generates a pair of public and private keys and a random number, and then broadcasts the public key to each vehicle and the cloud supervision system. TAI is generally composed of official organizations. TAI is responsible for generating and distributing the public and private key pairs, as well as registering the identity information of vehicles. When a vehicle detects the behavior of a malicious vehicle, it can send a report message to TAI. TAI will conduct preliminary screening and verification on the received information, and then interact with CSS. CSS will verify the correctness and timeliness of the reported information. According to the verification results sent by CSS to TAI, and the trust scores and quantities of the reporting vehicles and the reported vehicles, TAI will give corresponding rewards or punishments to the reporting vehicles and the reported vehicles. In the present invention, TAI has strong anti-attack ability and will not be interfered or damaged by malicious information.
[0061] S2. The vehicle and CSS are respectively registered at TAI and obtain parameter information. Specifically, CSS sends relevant information about its available cloud supervision services to TAI, and regularly sends messages to TAI to confirm the availability of its services; TAI regularly requests services from CSS to check whether the services of CSS are still available.
[0062] S3. The vehicle user sends a request login message to TAI. The vehicle user first enters the username and password, and then encrypts them using the public key published by TAI. Subsequently, the in-vehicle system sends the encrypted message to TAI; after receiving the information, TAI will check and verify the accuracy of the message sent by the user; if the username and password sent by the user are correct, the vehicle successfully logs in. After each vehicle successfully logs in for the first time, it will obtain a basic trust score.
[0063] S4. Trust Score Increase / Decrease Phase. Each vehicle obtains a basic trust score upon its first login. For the rest, the trust score is obtained by reporting vehicles that send malicious information. Multiple user vehicles send real-time messages such as road condition information to each other; user vehicles evaluate the information of the vehicles sending real-time messages and report malicious vehicles that send incorrect information; the cluster head vehicle sends the report information of the reporting vehicle and the identity information of the reported vehicle to TAI respectively; TAI conducts preliminary screening and judgment on the vehicle identity information, processes it through the load balancing algorithm, and sends the message to CSS; CSS determines whether the messages sent by the reporting vehicle and the reported vehicle are correct and sends the message to TAI; TAI rewards vehicles that spread correct messages and correspondingly increases their trust scores. For the reported vehicles that spread malicious messages, TAI will implement punishment measures and correspondingly reduce their trust scores. For reporting vehicles, TAI will judge whether the threshold of the number of reporting vehicles meets the requirements according to the trust score of each vehicle. Only when the threshold is met can the report be successful. After the threshold is met, TAI will further determine whether the message sent by the reporting vehicle is correct. If the reporting vehicle correctly points out the behavior of the reported vehicle spreading malicious messages, TAI will implement a reward measure to increase the trust score of the reporting vehicle; otherwise, if the reporting vehicle wrongly points out the behavior of the reported vehicle spreading malicious messages, TAI will implement a punishment measure to deduct the trust score of the reporting vehicle.
[0064] The specific content of S1 is as follows:
[0065] S1-1. TAI selects a prime additive cyclic group, which is G, where G×G = G v , with order P. The public-private key pair is generated by TAI i , calculates P i = S i P, where S i is a random number and is the private key generated by TAI i . TAI generates two absolutely secure hash functions, H i : {0, 1} 1 → {0, 1} * , H: {0, 1} v → G * , TAI generates system parameters: {H v , H, P 1 , G, P}. Then TAI sends these parameters to each vehicle and CSS through a secure channel. i
[0066] TAI i nodes will complete the registration initialization steps for vehicles and Css i . Through registration, vehicles and Css iSeparate from TAI i Establish secure communication and obtain the necessary permissions and certifications to participate in the operation of the trusted transportation system. TAI i As the core institution for vehicle management and safety protection. In this system, vehicles need to register with TAI i in order to obtain various services and be protected.
[0067] Such as Figure 2 shown, the vehicle registration process is as follows:
[0068] S2-1 First, each user User i needs to provide a unique identification UID i to TAI i , and this UID i has global uniqueness and can accurately distinguish different user identities. At the same time, the user randomly selects a password UPW i . The vehicle user calculates and generates RIW i , K i , Q i , B i , and calculates Sends VID i , RIW i to TAI i through the vehicle, and the user provides the information required for authentication to TAI i .
[0069] S2-2 TAI i Once it receives the parameters, it will immediately query the background data through UID i to determine whether the current user's vehicle has been registered. If the vehicle data is found to be a new user, it will immediately generate a random number s i , and calculate TAI i Sends the {A i , H 1 , H} parameters to the vehicle user and stores them in the vehicle system, where TAI i generates a public-private key pair. The hash functions H 1 , H in this parameter are designed to produce a fixed-length hash value for any length in the input domain to provide an irreversible mapping of the data. This hash function has properties such as collision resistance, one-wayness, and computational efficiency to prevent intentional attacks or accidental conflicts on the input data. The user vehicle calculates B i = P i * H 1 (RIW i || VID i || K i ), and sends B iStored in the vehicle storage unit.
[0070] Generate RIW based on the user's unique identification and password i , K i , Q i , B i and A i The calculation formula for is:
[0071]
[0072]
[0073] B i = P i * H 1 (RIW i || VID i || K i )
[0074]
[0075] In the formula, H 1 represents the hash function, UID i represents the user's unique identification, AID i represents the user's unique anonymous identification, UPW i represents the password, P i represents the public key generated by the authority center, B i represents the vehicle user User i The result calculated by, VID i represents the vehicle's unique identification, RIW i , K i , B i , Q i , A i represents the result of the formula calculation, r represents the random number generated by the user, s i represents the random number generated by the authority center, || represents the string concatenation operation, represents the exclusive OR operation.
[0076] As Figure 3 shown, the process of registering the cloud supervision system is:
[0077] S2-3 Each node in the CSS registers with the TAI i and submits its identity information and relevant credentials to the certification authority for verification and storage. Each system service provider Css in the CSS i first uses a random number generation method with uniqueness and non-repetition to generate the random numbers u and CID i. To ensure the uniqueness of the generated random number u, this paper uses a pseudo-random number generator (PRNG) random number generation algorithm with relatively high cryptographic security. Then calculate Send the parameter D i to TAI i .
[0078] S2-4 TAI i After receiving the parameters sent by the nodes in the CSS, generate a random number v. This random number has independence and unpredictability, ensuring that it cannot be predicted or reused by malicious attackers. Then calculate And send E i to Css i , Css i stores E i in a secure database.
[0079] S2-5 This invention uses Css i as the registration center to ensure that each Css i can effectively provide services. Between Css i will save a registration list in each Css i through mutual registration, ensuring that each Css i knows that other Css i are available, and every once in a while TAI i periodically pulls the Css i service, checks the Css i registry to determine whether its service is available. If the service is unavailable, it will be removed from the Css i . And Css i sends a heartbeat to TAI i every once in a while. If the heartbeat time exceeds the specified threshold, the service status of this Css i will be set to unavailable. To ensure that Css i is not removed from the service by mistake, TAI i defaults to enabling the heartbeat ratio protection mechanism for Css i . TAI i Every time the specified threshold time elapses, it statistics whether the normal heartbeat ratio of Css i during this time is lower than the specified ratio threshold. If it is not lower than the specified ratio, this Css i will not be removed.
[0080] As Figure 4 shown, the user login vehicle system process is as follows:
[0081] After the vehicle and CSS complete registration, the vehicle user logs in to the vehicle system to verify the legitimacy of the user identity and the system security. The user inputs the name UID i and the password UPW i , and then calculates where H 1 is the hash function generated by TAI i . The login process uses the hash function encryption method to protect the user name and password, thus effectively preventing the leakage of sensitive credentials.
[0082] S3-2 User i sends {C i , CT i} to the vehicle V i . The vehicle first determines whether the difference between the current time and the timestamp is within the maximum threshold for verifying the timestamp validity. If it is within the allowed range, the vehicle determines whether the password entered by the user is correct. Then it calculates If B' i = B i , the user logs in successfully and returns a verification success message. Otherwise, the user logs in failed and returns a verification failure message. Where Q i , B i represent the results calculated according to the vehicle user during vehicle user registration.
[0083] As Figure 5 shown, the reporting vehicle reports malicious vehicles sending malicious information, and TAI increases the reward and decreases the penalty for the trust scores of the reporting vehicle and the reported vehicle. The three-party interaction process is as follows:
[0084] S4-1 When the authentication of User i is successful, the vehicle will send the reporting information to TAI i . After preliminary screening, TAI i will select the node Css i to query whether the reporting information is accurate. These Css i nodes will provide the ability to assist in decision-making for TAI i and take corresponding measures for real-time response and adjustment according to the instructions of TAI i . To prevent data leakage, User i encrypts the calculated data. TAI i first decrypts the encrypted information sent by the vehicle user for the received parameters to obtain the original reporting parameters. Subsequently, TAI i reviews and evaluates each node in CSS to determine whether they have the capabilities and resources to provide the required services. This process involves a comprehensive analysis of the performance, availability, load conditions, etc. of each node. TAIi Based on these evaluation results, appropriate available idle nodes will be selected as service providers.
[0085] The basic trust score between the S4-2 vehicle and the vehicle entity is calculated when sending interaction information. By two entities sending messages to each other and establishing a session key, through the session key established between the entities, a preliminary trust is established between the entities. Then v i and v j respectively judge and score the information they send and send the information to CHV i . CHV i is elected by sorting the trust scores of vehicles in the domain at regular intervals. Any vehicle within a certain area of the RSU has the opportunity to become a cluster head vehicle. v i Calculate and use the public key of v j to encrypt the data, and then send the parameter to v , v j , v j decrypts it by using the private key and judges the correctness of the information sent by v i , and then scores the vehicle v i , sorts the trust scores of vehicles in the domain, and sends the score to the CHV with the highest trust score in the domain i . v j also uses the same method to establish a session key and judges the correctness of the information sent by v i , and sends the scoring information to CHV i . CHV i adds the scored grade i to v i .
[0086] Vehicles independently measure the transmission rate, forwarding rate, and packet loss rate to obtain the initial trust score. These three indicators are one of the components of the vehicle's initial trust score. Given that vehicles with higher forwarding rates and transmission rates are recognized as more trustworthy entities, their trust scores are accordingly increased. Vehicles with a high packet loss rate indicate that there are relatively significant cases where data packets are not successfully transmitted during their data transmission process, which may be caused by various reasons, including but not limited to signal interference, network congestion, and communication device failures. In view of this situation, the trust level of the relevant vehicles should be correspondingly reduced and their trust scores decreased. By calculating the time ratio of the successfully transmitted information of the vehicle entity sending information to the total messages sent by the vehicle: where represents the time required for the vehicle entity k to successfully send data, M kIndicates the time required for a single transmission of data by vehicle entity k. The ratio of the number of messages forwarded by the vehicle to the number of all correctly received messages: where indicates vehicle entity v j will forward the data bits of the correctly received messages from other single vehicle v k in the messages sent, vehicle entity v j will forward the data size of the correctly received data from other single vehicle v k The forwarding rate here is calculated from the ratio of the data of the current sending vehicle forwarded by the other vehicle. By calculating the ratio of the number of lost data packets to the total number of data packets sent: where indicates the number of lost data in the data packets of a single message sent by vehicle entity k, D n indicates the total data volume of a single message sent by the vehicle entity.
[0087] S4-4 Vehicle V i Calculates and then selects a random number f i . Where the user User i authenticates the identity by logging in, and UID i and password UPW i are static parameters pre-stored in the vehicle user system. To ensure security and the performance of encryption and decryption, the system uses elliptic curve encryption, and then calculates G i = f i P, where P is the generating point of the elliptic curve E, P i is the public key generated by TAI i , and VID i is the unique identity of the vehicle. To optimize the transmission efficiency of vehicle reporting information and reduce communication overhead, the system uses CHV i as an intermediate node to transmit the vehicle's reporting information r i . Then the calculated parameters M i , CT i are transmitted to the TAI side through the network.
[0088] S4-5 When TAI i receives the request data from the vehicle, one important step is to verify the validity of the timestamp CT i . TAI i calculates ΔCT < |CT r - CT i| to ensure that data is generated or transmitted within the specified time. This verification process helps prevent security threats such as time-reversal attacks and data replay attacks, and ensures the timeliness and legality of the data. In the timestamp verification step, if the calculated timestamp meets the verification conditions, TAI i will decrypt the data transmitted to V i and calculate Then check if RIW i = holds. Because during the vehicle's registration phase with TAI i , the vehicle has sent RIW i for identity verification. Therefore, if TAI i can verify that the received RIW i matches the data during vehicle registration, it means the equation holds and TAI will continue with subsequent operations.
[0089] S4-6 After TAI determines through step S2-5 the Css that can provide services i , select the Css that can provide services i , Css i calculate whether D i is equal to If it holds, then Css i is a legitimate entity registered with TAI i , and then calculate CHV i for the message sent by Css i Send the calculated message to the Css capable of judging the authenticity of the information j , Css j will send the judged information M j to Css i .
[0090] S4-7 Css i will send the parameters {M j , CT i} to TAI i , TAI i will first judge whether the timestamp of the sent message is within the specified delay time. If it meets the regulation, then judge whether the inequality TS i ≤ TTS holds, where TS iIt represents the trust scores of all reported vehicles respectively. If the inequality holds, it indicates that the trust scores of the reported vehicles are within the specified thresholds. Subsequently, the quantities VNUM of the trust scores of the reported vehicles within and outside the TTS (threshold of trust score) are counted respectively. TTS represents the threshold of the trust score, and VNUM represents the threshold of the quantity of reported vehicles. If VNUM ≥ HTV holds, it means that the quantity of reported vehicles with trust scores higher than the specified threshold should be greater than or equal to the specified maximum threshold. Otherwise, LTV ≤ VNUM < HTV holds, indicating that the quantity of reported vehicles with trust scores between the specified maximum threshold HTV and the minimum threshold LTV meets the specified requirements. If the trust scores of the reported vehicles satisfy the above equations, the vehicle can make a report; otherwise, the vehicle cannot make a report. Subsequently, TAI i According to Css j Based on whether the message sent is true or false, trust scores are increased as rewards or deducted as penalties for the reported vehicles and the vehicles being reported. If the information is true, then TAI i Calculate the equation TS i =TS i +RTE to reward the reported vehicles and the vehicles being reported. Otherwise, calculate TS i =TS i -PTE to penalize the vehicles that spread malicious information among the reported vehicles and the vehicles being reported. RTE represents the trust score rewarded by TAI i to the vehicle, and PTE represents the trust score deducted as a penalty by TAI i from the vehicle
[0091] S4-8 TAI i Send the calculated trust score information M j of the reported and the vehicles being reported and the current timestamp parameter {M j , CT i} to the CHV i vehicle. CHV i Calculate whether ΔCT < |CT r -CT i | holds, and then send the trust score to the corresponding V i vehicle. V i vehicle stores the information in the vehicle system. ΔCT represents the time that the vehicle information received by TAI i can be delayed, and CT r represents the real-time time. It should be noted that when CHV i re-elects, it will synchronize the trust scores of the corresponding vehicles to the latest cluster head vehicle and delete the trust scores of other vehicles stored locally. This ensures the security of the vehicles.
[0092] The basic principles, main features and advantages of the present invention have been shown and described above. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification only illustrates the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A malicious vehicle detection method based on trust score in a vehicle networking environment, characterized in that: The following steps are involved: System initialization generates system common parameters; Registering a vehicle user and a cloud monitoring system node respectively, and the successfully registered vehicle user and the cloud monitoring system node obtain parameter information based on the system public parameters; After multiple vehicle users successfully log in based on the parameter information, they send messages to each other by establishing a session key between the two entities, and the two entities evaluate the received messages and send the report information to the cluster head vehicle; The cluster head vehicle sends the reporting information and the identity information of the reported vehicle to the authoritative center, and the authoritative center selects an available cloud monitoring system node, and the available cloud monitoring system node judges the reporting information and the identity information of the reported vehicle, and sends the judgment result to the authoritative center; The process of judging the reporting information and the identity information of the reported vehicle includes: When the authoritative center receives a data request from a cluster head vehicle, the authoritative center performs identity authentication based on a timestamp and a user password; After the identity authentication is passed, the authority center selects an available cloud monitoring system node, the available cloud monitoring system node calculates the data information of the cluster head vehicle, and obtains the true or false result of the information based on the data information; The cloud monitoring system node sends the truth or falsehood result of the information and the timestamp of sending the information to the authoritative center, and the authoritative center determines the timestamp of sending the information, and when the timestamp of sending the information is within the specified delay time, the trust scores of all reporting vehicles are counted; When the trust score of the reported vehicle meets TS i <TTS, the vehicle makes a report; otherwise, the vehicle cannot make a report. Here, TS i represents the trust score of vehicle V i , and TTS represents the threshold of the trust score; When a vehicle reports and the information is true or false, rewards are given to the reporting vehicle and the reported vehicle; When a vehicle reports and the information is false, the reporting vehicle and the reported vehicle will be punished; The authoritative center increases or decreases the trust points of the two entities that establish the session key based on the judgment result.
2. The method for detecting malicious vehicles based on trust points in a connected vehicle environment according to claim 1 is characterized in that: The process of vehicle user registration includes: The vehicle user sends a unique identity identification and password to the authority center to obtain identity authentication information parameters; The authoritative center determines whether the current vehicle user is a new user based on the identity authentication information parameter, and when the current vehicle user is a new user, the authoritative center generates an anti-attack parameter and sends it to the vehicle user; The vehicle user calculates and generates RIW i , K i , Q i , B i ; The authoritative center calculates and generates A i .
3. The malicious vehicle detection method based on trust score in the vehicle networking environment according to claim 2 is characterized in that: Generate RIW based on the user's unique identification and password i , K i , Q i , B i and A i The calculation formula is: B i =P i *H1(RIW i ||VID i ||K i ) Where H1 represents the hash function, UID i Indicates the user's unique identity, AID i Indicates the user's unique anonymous identity, UPW i Indicates password, P i represents the public key generated by the authority center, B i Indicates the vehicle user User i The calculated result, VID i Indicates the unique identification of the vehicle, RIW i , K i , B i , Q i , A i represents the result of the formula calculation, r represents the random number generated by the user, s i represents the random number generated by the authoritative center, || represents the string concatenation operation, Represents the exclusive OR operation.
4. The method for detecting malicious vehicles based on trust points in a connected vehicle environment according to claim 1, characterized in that: The process of cloud supervision system node registration includes: Randomly generate a random number u and a unique identity identification CID of the cloud supervision system based on a pseudo-random number generator i ; Based on the random number u and the unique identity CID of the cloud supervision system i Calculate D i ,in D i Send it to the authority center, which generates a random number v; The authoritative center is based on D i and v to calculate E i ,in And E i Send to the cloud supervision system node to complete the registration; Where D i , E i Indicates the result of formula calculation, || indicates string concatenation operation, Represents the exclusive OR operation.
5. The method for detecting malicious vehicles based on trust points in a connected vehicle environment according to claim 1, characterized in that: The process of a vehicle user logging into the vehicle system includes: Enter the unique identification and password of the user's vehicle, and the system automatically calculates C i , and generate a timestamp CT i ,in The vehicle determines the validity of the verification time based on the current time and the timestamp threshold; When the verification time is valid, the vehicle calculates K i , B′ i Verify the correctness of the password, when B′ i =B i , if the user logs in successfully, the verification success information is returned; otherwise, if the user logs in unsuccessfully, the verification failure information is returned. B′ i =P i *H1(C i ||UPW i ).
6. The method for detecting malicious vehicles based on trust points in a connected vehicle environment according to claim 1, characterized in that: Before the authoritative center selects the available cloud supervision system node, the authoritative center also performs a service determination on the cloud supervision system node based on the heartbeat ratio protection mechanism, wherein the service determination process is: The heartbeat ratio protection mechanism sets a ratio threshold; The cloud monitoring system nodes send heartbeats to the authority center at specified threshold intervals; When the heartbeat of the specified threshold time is lower than the ratio threshold, the cloud supervision system node is removed, otherwise, the cloud supervision system node is retained.
7. The method for detecting malicious vehicles based on trust points in a connected vehicle environment according to claim 1, characterized in that: Metrics used by entities to independently evaluate the messages received include: the ratio of the time that a vehicle entity successfully transmits a message to the total number of messages sent by the vehicle, the ratio of the number of messages forwarded by the vehicle to the number of all correct messages received, and the ratio of the number of packets lost to the total number of packets sent.
Citation Information
Patent Citations
Intelligent traffic light timing method based on Internet of Vehicles blockchain
CN111311932A
Access control method and device based on block chain, and storage medium
CN115643577A