Internet of Things Information Security Access Control Method and System

By identifying abnormal access times and groups of vehicles with similar information in the Internet of Vehicles system, combined with the memory capacity of the edge server and the possibility of vehicle abnormalities, secure access control of the Internet of Vehicles system is achieved, solving the problem of information leakage caused by malicious nodes and ensuring system stability and privacy protection.

CN119767307BActive Publication Date: 2025-09-12SHENZHEN YUNTA IOT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411970454.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-09-12
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

Malicious nodes hidden in the Internet of Vehicles system lead to the leakage of IoT information during access. Especially when the edge server is overloaded or fails, it is difficult to effectively identify and prevent customer privacy information from being stolen.

Method used

By collecting the vehicle location, direction and remaining memory capacity of the edge server, identifying abnormal access times, dividing vehicles into groups with similar information, determining the possibility of vehicle abnormality, and stopping the edge server from authorizing abnormal nodes, secure access control is achieved by combining the remaining memory capacity of the edge server and the possibility of vehicle abnormality.

Benefits of technology

Effectively identify and prevent access from malicious nodes, protect the stability and information security of the Internet of Vehicles system, avoid information leakage, and reduce the computing pressure of edge servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119767307B_ABST
    Figure CN119767307B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of Internet of Things access control technology, and proposes an Internet of Things information security access control method and system, including: collecting vehicle location, vehicle direction, remaining memory capacity of an edge server, and access volume; determining abnormal access time and abnormal access time set; marking the target abnormal access time, a first vehicle, and a second vehicle, determining the similarity of vehicle information of the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set, dividing similar information vehicles into similar information vehicle groups, determining the vehicle abnormality probability of any vehicle in the time period corresponding to the abnormal access time set, determining abnormal nodes and normal nodes, stopping all edge servers from authorizing all abnormal nodes; determining matching priorities, and implementing Internet of Things information security access control for the current collection time according to the matching priorities. The present invention filters out malicious nodes hidden in the Internet of Vehicles, ensuring secure access to Internet of Things information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things access control, and in particular to an Internet of Things information security access control method and system. Background Art

[0002] The Internet of Vehicles (IoV) leverages IoT technology to exchange information between vehicles and infrastructure, providing services for vehicle operation. Consequently, IoV systems extract a large amount of customer privacy information. To prevent this information from being stolen or maliciously attacked, access control is required.

[0003] To alleviate the computational pressure on the vehicle's computing unit, the IoV system typically transmits some data to the cloud or nearby edge servers for processing. When malicious nodes appear, some edge servers may become overloaded or malfunction, potentially leading to the leakage of customer privacy information. Therefore, it is necessary to screen and identify malicious nodes within the IoV system, deny their access, protect customer privacy information, and ensure the stable and secure operation of the IoV access control system. Summary of the Invention

[0004] The present invention provides an Internet of Things information security access control method and system to solve the problem of Internet of Things information leakage during access caused by malicious nodes hidden in the Internet of Vehicles. The technical solutions adopted are as follows:

[0005] In a first aspect, an embodiment of the present invention provides an Internet of Things information security access control method, the method comprising the following steps:

[0006] Collect the vehicle location, vehicle direction, remaining memory capacity and access volume of the edge server at the current collection time and a preset number of collection times before;

[0007] Record any collection time as the target collection time, and determine the abnormal access time and the abnormal access time set based on the access volume of all edge servers at the target collection time and the collection time adjacent to the target collection time;

[0008] Record any abnormal access moment in the abnormal access moment set as the target abnormal access moment, record any two different vehicles in the vehicle network as the first vehicle and the second vehicle, determine the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set based on the difference and distance between the vehicle positions of the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set and adjacent moments of the abnormal access moment, and the angle between the vehicle directions of the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set, divide similar information vehicles and similar information vehicle groups based on the vehicle information similarity, determine the vehicle abnormality possibility of any vehicle in the time period corresponding to the abnormal access moment set based on the difference between the vehicle directions of any vehicle and other vehicles in the similar information vehicle group, and the difference between the vehicle information similarities, determine the abnormal node and the normal node based on the vehicle abnormality possibility, and stop all edge servers from authorizing all abnormal nodes;

[0009] Any normal node is recorded as the target normal node, and any edge server is recorded as the target edge server. According to the position relationship of the target normal node relative to the target edge server at the current collection time and the adjacent collection time, the remaining memory capacity of all edge servers, and the possibility of vehicle abnormality in the target normal node in the time period corresponding to the abnormal access time set, the IoT information security access control at the current collection time is realized.

[0010] Furthermore, the method of determining the abnormal access time and the abnormal access time set based on the access volume of all edge servers at the target collection time and the collection time adjacent to the target collection time includes the following specific methods:

[0011] The average of the visits to all edge servers at all collection times before the target collection time is recorded as the historical average of the visits at the target collection time;

[0012] The cumulative sum of the visits to all edge servers at the target collection time is recorded as the cumulative visits at the target collection time. The difference between the cumulative visits at the target collection time and the collection time before the target collection time is recorded as the differential cumulative visits at the target collection time. The product of the differential cumulative visits at the target collection time and the cumulative visits is recorded as the first product at the target collection time.

[0013] The normalized value of the ratio of the first product of the target collection time and the average of the historical visit volume is recorded as the malicious attack possibility at the target collection time;

[0014] When the malicious attack possibility of the target collection moment is greater than the preset abnormal access threshold, the target collection moment is marked as an abnormal access moment, and the set of consecutive abnormal access moments including the current collection moment is recorded as the abnormal access moment set.

[0015] Furthermore, the method of determining the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set based on the difference and distance between the vehicle positions of the first vehicle and the second vehicle at all abnormal access times and adjacent times included in the abnormal access time set, and the angle between the vehicle directions of the first vehicle and the second vehicle at all abnormal access times included in the abnormal access time set, includes the following specific methods:

[0016] The distance between the vehicle's position at the target abnormal access time and the vehicle's position at the moment before the target abnormal access time is recorded as the vehicle's displacement at the target abnormal access time; the absolute value of the difference between the displacements of the first vehicle and the second vehicle at the target abnormal access time is recorded as the displacement difference between the first vehicle and the second vehicle at the target abnormal access time; the mean of the displacement differences of all different vehicles in the vehicle network at all abnormal access times included in the abnormal access time set is recorded as the mean displacement difference for the time period corresponding to the abnormal access time set;

[0017] The angle between the vehicle directions of the first vehicle and the second vehicle at the target abnormal access time is recorded as the vehicle direction difference between the first vehicle and the second vehicle at the target abnormal access time;

[0018] The distance between the vehicle positions of the first vehicle and the second vehicle at the target abnormal access time is recorded as the vehicle distance between the first vehicle and the second vehicle at the target abnormal access time. The average of the vehicle distances between the first vehicle and the second vehicle at all abnormal access times included in the abnormal access time set is recorded as the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set. The average of the vehicle distances between all different vehicles in the vehicle network at the same abnormal access time included in the abnormal access time set is recorded as the comparative vehicle average distance in the time period corresponding to the abnormal access time set.

[0019] Based on the displacement differences and vehicle direction differences of the first vehicle and the second vehicle in all abnormal access moments contained in the abnormal access moment set, the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set, the mean of the displacement differences in the time period corresponding to the abnormal access moment set and the compared average vehicle distance, the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set is determined.

[0020] Furthermore, the method of determining the vehicle information similarity between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set based on the displacement differences and vehicle direction differences of the first vehicle and the second vehicle at all abnormal access time moments included in the abnormal access time set, the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set, the mean of the displacement differences and the compared average vehicle distance, includes the following specific methods:

[0021] The maximum value of the displacement differences between the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set is recorded as the maximum displacement difference between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set. The ratio of the mean displacement differences in the time period corresponding to the abnormal access moment set to the maximum displacement difference between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set is recorded as the first ratio.

[0022] The ratio of the average distance of the comparison vehicles in the time period corresponding to the abnormal access time set to the average distance of the vehicles between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set is recorded as a second ratio;

[0023] The ratio of the number 1 to the average of the vehicle direction differences between the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set is recorded as a third ratio;

[0024] The normalized value of the product of the first ratio, the second ratio, and the third ratio is recorded as the vehicle information similarity between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set.

[0025] Furthermore, the method of dividing similar information vehicles and similar information vehicle groups according to vehicle information similarity includes the following specific methods:

[0026] Two different vehicles corresponding to vehicle information similarities greater than a preset similarity division threshold are divided into a group of similar information vehicles, and all similar information vehicles divided from the same abnormal access time set are recorded as a similar information vehicle group.

[0027] Furthermore, the method of determining the possibility of vehicle abnormality of any one vehicle in the time period corresponding to the abnormal access time set based on the difference between the vehicle directions of any one vehicle and other vehicles in the similar information vehicle group and the difference between the vehicle information similarities includes the following specific methods:

[0028] The mean of the vehicle directions of all the similar information vehicles included in the similar information vehicle group at all the abnormal access moments included in the abnormal access moment set is recorded as the first overall heading direction of the similar information vehicle group in the time period corresponding to the abnormal access moment set, the mean of the vehicle directions of all the abnormal access moments included in the abnormal access moment set of the target similar information vehicle is recorded as the second overall heading direction of the target similar information vehicle in the time period corresponding to the abnormal access moment set, and the angle between the first overall heading direction of the similar information vehicle group in the time period corresponding to the abnormal access moment set and the second overall heading direction of the target similar information vehicle in the time period corresponding to the abnormal access moment set is recorded as the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access moment set;

[0029] The maximum value of the vehicle information similarity between the target similar information vehicle and other vehicles in the time period corresponding to the abnormal access time set is recorded as the first vehicle information similarity of the target similar information vehicle; the maximum value of the vehicle information similarity in the time period corresponding to the abnormal access time set of all two different vehicles is recorded as the second vehicle information similarity; the ratio of the second vehicle information similarity to the first vehicle information similarity of the target similar information vehicle is recorded as the third vehicle information similarity of the target similar information vehicle in the time period corresponding to the abnormal access time set;

[0030] The vehicle abnormality possibility of the target similar information vehicle in the time period corresponding to the abnormal access time set is determined based on the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the third vehicle information similarity.

[0031] Furthermore, the method of determining the vehicle abnormality possibility of the target similar information vehicle in the time period corresponding to the abnormal access time set based on the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the third vehicle information similarity includes the following specific methods:

[0032] The normalized value of the product of the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the third vehicle information similarity is recorded as the vehicle abnormality possibility of the target similar information vehicle in the time period corresponding to the abnormal access time set.

[0033] Furthermore, the method of determining abnormal nodes and normal nodes according to the possibility of vehicle abnormality and stopping all edge servers from authorizing all abnormal nodes includes:

[0034] Vehicles with a probability of abnormality greater than or equal to a preset abnormal classification threshold are marked as abnormal nodes, and all edge servers are stopped from authorizing all abnormal nodes;

[0035] Vehicles whose abnormality probability is less than the preset abnormality classification threshold are recorded as normal nodes, and the edge server maintains authorization for all normal nodes.

[0036] Furthermore, the method of implementing IoT information security access control at the current collection moment based on the positional relationship of the target normal node relative to the target edge server at the current collection moment and the adjacent collection moments, the remaining memory capacity of all edge servers, and the probability of vehicle abnormality in the time period corresponding to the target normal node in the abnormal access moment set includes the following specific methods:

[0037] The calculation formula for the matching priority between the target normal node and the target edge server at the current collection time is:

[0038]

[0039] Where q k,w,i represents the matching priority between the target normal node k and the target edge server w at the current collection time i; s k,w,i-1 represents the distance between the target normal node k and the target edge server w at the previous collection time i-1 before the current collection time; s k,w,i M represents the distance between the target normal node k and the target edge server w at the current collection time i; w represents the remaining memory capacity of the target edge server w; represents the mean of the remaining memory capacity of all edge servers in the Internet of Vehicles; V k represents the probability of vehicle abnormality at the target normal node k in the time period corresponding to the abnormal access time set;

[0040] Obtain the matching priority between the target normal node and any edge server, and use the edge server corresponding to the largest matching priority as the edge server matching the target normal node;

[0041] Obtain the edge server that matches any normal node, and send the vehicle information of the normal node at the current collection time to the matching edge server to achieve IoT information security access control.

[0042] In a second aspect, an embodiment of the present invention further provides an Internet of Things information security access control system, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of any one of the above methods when executing the computer program.

[0043] The beneficial effects of the present invention are:

[0044] Based on the characteristic that malicious attacks often disguise themselves as a large number of vehicles transmitting vehicle information to the same edge server, causing a sudden increase in the number of visits to the edge server, the present application divides the collection time into abnormal access moments and abnormal access moment sets according to the target collection time and the number of visits to all edge servers at the collection times adjacent to the target collection time; considering that normally operating vehicles are restricted by roads during their movement on the road, the displacement and movement direction of vehicles in the adjacent range are similar, while the vehicle information disguised as malicious attacks is random, which will cause mutations in vehicle information, and cannot guarantee the similarity between vehicle information and the information of real vehicles in the adjacent range, based on the abnormal access time, the application divides similar information vehicles and similar information vehicle groups in combination with the information of vehicle location, and further combines any vehicle in the similar information vehicle group The difference between the vehicle directions of the target vehicle and other vehicles, as well as the difference between the vehicle information similarities, is used to determine the possibility of malicious attacks on any vehicle in the time period corresponding to the abnormal access time set. The vehicle abnormality possibility is obtained, and the abnormal nodes and normal nodes are determined based on the vehicle abnormality possibility. The authorization of all edge servers to all abnormal nodes is stopped to avoid the risk of information leakage caused by hidden malicious nodes. Finally, according to the position relationship of the target normal node relative to the target edge server at the current collection time and the adjacent collection time, the remaining memory capacity of all edge servers, and the vehicle abnormality possibility of the target normal node in the time period corresponding to the abnormal access time set, the IoT information security access control at the current collection time is realized to solve the problem of IoT information leakage during the access process caused by hidden malicious nodes in the Internet of Vehicles. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0046] Figure 1 A flowchart of a method for controlling information security access to the Internet of Things provided by one embodiment of the present invention;

[0047] Figure 2 A flowchart of obtaining the possibility of malicious attacks provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0049] See also Figure 1 , which shows a flow chart of an Internet of Things information security access control method provided by an embodiment of the present invention, the method comprising the following steps:

[0050] Step S001: Collect the vehicle position, vehicle direction, remaining memory capacity and access volume of the edge server at the current collection time and a preset number of collection times before.

[0051] All vehicles included in the Internet of Vehicles are equipped with wireless communication on-board units, and information exchange between vehicles in the Internet of Vehicles can be achieved through the wireless communication on-board units. Specifically, the wireless communication on-board unit is required to realize communication between the vehicle and the edge server. The edge server uploads the received vehicle information to the cloud computing machine. The cloud computing machine selects the edge server where another vehicle that needs to exchange information between vehicles is located, and uploads the vehicle information to the edge server selected by the cloud computing machine. After receiving the information, the edge server transmits the vehicle information to the other vehicle that needs to exchange information between vehicles.

[0052] The vehicle position and direction are collected using a wireless communication vehicle-mounted unit.

[0053] Collect the remaining memory capacity and access volume of each edge server included in the Internet of Vehicles.

[0054] It should be understood that before a vehicle included in the Internet of Vehicles accesses each edge server included in the Internet of Vehicles and other vehicles included in the Internet of Vehicles, authorization from the edge server is required.

[0055] Preferably, in one embodiment of the present application, when collecting vehicle location, vehicle direction, edge server remaining memory capacity, and page views, the data collection interval in this embodiment is 1 second, and data is collected within the current collection time and the previous day. In actual application, as other implementation methods, implementers can determine the collection interval and sampling number of vehicle location, vehicle direction, edge server remaining memory capacity, and page views based on actual conditions, and this application does not impose any special restrictions.

[0056] At this point, the vehicle location, vehicle direction, remaining memory capacity of the edge server, and access volume are obtained.

[0057] Step S002: record any collection time as a target collection time, and determine an abnormal access time and an abnormal access time set according to the access volume of all edge servers at the target collection time and adjacent collection times of the target collection time.

[0058] When the IoV is attacked by malicious actors, they often disguise themselves as a large number of vehicles transmitting information to the same edge server. This can cause a sudden surge in traffic to the edge server, overloading it and significantly reducing its data processing capacity, impacting the normal flow of information through the IoV. However, not all sudden increases in traffic to the edge server indicate a malicious attack. This can also occur when traffic increases suddenly, such as during rush hour on weekdays. Therefore, it's necessary to identify malicious attacks based on the traffic to the edge server.

[0059] Any collection time is recorded as the target collection time.

[0060] The malicious attack possibility at the target collection time is determined based on the access volume of all edge servers at the target collection time and the collection time adjacent to the target collection time.

[0061] Preferably, as an embodiment of the present application, the average of the visits to all edge servers at all collection moments before the target collection moment is recorded as the average of the historical visits at the target collection moment; the cumulative sum of the visits to all edge servers at the target collection moment is recorded as the cumulative visits at the target collection moment; the difference between the cumulative visits at the target collection moment and the previous collection moment is recorded as the differential cumulative visits at the target collection moment; the product of the differential cumulative visits at the target collection moment and the cumulative visits is recorded as the first product at the target collection moment; and the normalized value of the ratio of the first product at the target collection moment to the average of the historical visits is recorded as the possibility of malicious attack at the target collection moment.

[0062] It should be noted that this embodiment uses the Z-Score standard normalization method to calculate the normalized value. In actual application, the implementer can use other existing methods such as maximum and minimum value normalization method, sigmoid function, etc. to calculate the normalized value, which is not limited here; in the process of calculating the ratio, in order to avoid the denominator being zero, it is necessary to add a preset value to the denominator, and the preset value in the embodiment is 1.

[0063] It is understandable that the malicious attack possibility at the first collection moment cannot be calculated according to the above method, so the malicious attack possibility at the first collection moment is directly assigned a value of 0.

[0064] The greater the difference between the number of visits to all edge servers at the target collection time and the adjacent collection time of the target collection time, the greater the possibility of malicious attack at the target collection time, and the greater the possibility of the Internet of Vehicles being attacked by malicious attacks at the target collection time. The flowchart for obtaining the possibility of malicious attacks is shown in Figure 2. Figure 2 shown.

[0065] Set an abnormal access threshold. In this implementation, the abnormal access threshold is set to 0.75. When the malicious attack probability at the target collection moment is greater than the abnormal access threshold, the target collection moment is marked as an abnormal access moment.

[0066] The same method can be used to determine abnormal access moments among all collection moments.

[0067] The set of continuous abnormal access moments including the current collection moment is recorded as the abnormal access moment set.

[0068] It should be noted that the latest collection time included in the abnormal access time set is the current collection time.

[0069] It is understandable that there may be multiple sets of continuous abnormal access times. For example, if all collection times from 10:20 to 11:00 are abnormal access times, and all collection times from 11:30 to 11:40 are abnormal access times, then all collection times from 10:20 to 11:00 constitute one set of continuous abnormal access times, and all collection times from 11:30 to 11:40 constitute another set of continuous abnormal access times. It is also understandable that if the current collection time is 11:00, all collection times from 10:20 to 11:00 constitute the time period corresponding to the abnormal access time set, namely, the time period from 10:20 to 11:00.

[0070] At this point, the abnormal access time and the abnormal access time set are determined.

[0071] Step S003: record any abnormal access moment in the abnormal access moment set as the target abnormal access moment, record any two different vehicles in the vehicle network as the first vehicle and the second vehicle, and determine the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set based on the difference and distance between the vehicle positions of the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set and adjacent moments of the abnormal access moments, and the angle between the vehicle directions of the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set. Divide similar information vehicles and similar information vehicle groups based on the vehicle information similarity. Determine the vehicle abnormality possibility of any vehicle in the time period corresponding to the abnormal access moment set based on the difference between the vehicle directions of any vehicle and other vehicles in the similar information vehicle group, and the difference between the vehicle information similarities. Determine abnormal nodes and normal nodes based on the vehicle abnormality possibility, and stop all edge servers from authorizing all abnormal nodes.

[0072] Normally operating vehicles on the road have similar displacements and movement directions due to road restrictions. However, maliciously generated vehicle information is random, resulting in sudden changes and no guarantee of similarity to real vehicles in the area. Therefore, analysis is based on the time of abnormal access and combined with vehicle location information.

[0073] Any abnormal access time in the abnormal access time set is recorded as the target abnormal access time, and any two different vehicles in the vehicle network are recorded as the first vehicle and the second vehicle.

[0074] The distance between the vehicle's position at the target abnormal access time and the vehicle's position immediately before the target abnormal access time is recorded as the vehicle's displacement at the target abnormal access time. The absolute value of the difference between the displacements of the first and second vehicles at the target abnormal access time is recorded as the displacement difference between the first and second vehicles at the target abnormal access time. The mean of the displacement differences of all different vehicles in the vehicle network at all abnormal access times included in the abnormal access time set is recorded as the displacement difference mean for the time period corresponding to the abnormal access time set.

[0075] The angle between the vehicle directions of the first vehicle and the second vehicle at the target abnormal access time is recorded as the vehicle direction difference between the first vehicle and the second vehicle at the target abnormal access time.

[0076] The distance between the first and second vehicles at the target abnormal access time is recorded as the vehicle distance between the first and second vehicles at the target abnormal access time. The average of the vehicle distances between the first and second vehicles at all abnormal access times within the abnormal access time set is recorded as the average vehicle distance between the first and second vehicles for the time period corresponding to the abnormal access time set. The average of the vehicle distances between all different vehicles in the network of vehicles at the same abnormal access time within the abnormal access time set is recorded as the average vehicle distance for the time period corresponding to the abnormal access time set.

[0077] Based on the displacement differences and vehicle direction differences of the first vehicle and the second vehicle in all abnormal access moments contained in the abnormal access moment set, the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set, the mean of the displacement differences in the time period corresponding to the abnormal access moment set and the compared average vehicle distance, the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set is determined.

[0078] The maximum value of the displacement difference between the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set is recorded as the maximum displacement difference between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set; the ratio of the mean displacement difference in the time period corresponding to the abnormal access moment set to the maximum displacement difference between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set is recorded as the first ratio; the ratio of the average comparison vehicle distance in the time period corresponding to the abnormal access moment set to the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set is recorded as the second ratio; the ratio of the number 1 to the mean value of the vehicle direction difference between the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set is recorded as the third ratio; the normalized value of the product of the first ratio, the second ratio and the third ratio is recorded as the vehicle information similarity between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set.

[0079] It should be noted that this embodiment uses the Z-Score standard normalization method to calculate the normalized value. In actual application, the implementer can use other existing methods such as the maximum and minimum normalization method, the sigmoid function, etc. to calculate the normalized value, which is not limited here; in the process of calculating the ratio of the first ratio, the second ratio and the third ratio, in order to avoid the denominator being zero, it is necessary to add a preset value to the denominator. The preset value in the embodiment is 0.01.

[0080] The more similar the vehicle displacement information and vehicle direction information of the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set are, the larger the first ratio and the second ratio are. At the same time, the smaller the difference in vehicle direction between the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set is, the larger the third ratio is. At this time, the similarity between the vehicle information at all abnormal access moments included in the abnormal access moment set and the information of real vehicles in the nearby range is greater.

[0081] A similarity threshold is set. In this implementation, the threshold is set to 0.8. For a set of unusual access times, when the vehicle information similarity exceeds the threshold, two vehicles with similar information are grouped together as a similar vehicle group. All similar vehicles from the same unusual access time set are grouped together as a similar vehicle group.

[0082] Any vehicle in the similar information vehicle group is recorded as the target similar information vehicle.

[0083] The mean of the vehicle directions of all similar vehicles in the similar information vehicle group at all abnormal access times in the abnormal access time set is recorded as the first overall heading direction of the similar information vehicle group in the time period corresponding to the abnormal access time set. The mean of the vehicle directions of the target similar information vehicle at all abnormal access times in the abnormal access time set is recorded as the second overall heading direction of the target similar information vehicle in the time period corresponding to the abnormal access time set. The angle between the first overall heading direction of the similar information vehicle group in the time period corresponding to the abnormal access time set and the second overall heading direction of the target similar information vehicle in the time period corresponding to the abnormal access time set is recorded as the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set. The maximum value of the vehicle information similarity between the target similar information vehicle and other vehicles in the time period corresponding to the abnormal access time set is recorded as the first vehicle information similarity of the target similar information vehicle. The maximum value of the vehicle information similarity between all two different vehicles in the time period corresponding to the abnormal access time set is recorded as the second vehicle information similarity. The ratio of the second vehicle information similarity to the first vehicle information similarity of the target similar information vehicle in the time period corresponding to the abnormal access time set is recorded as the third vehicle information similarity of the target similar information vehicle in the time period corresponding to the abnormal access time set.

[0084] The vehicle abnormality possibility of the target similar information vehicle in the time period corresponding to the abnormal access time set is determined based on the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the third vehicle information similarity.

[0085] Preferably, as an embodiment of the present application, the normalized value of the product of the directional deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the third vehicle information similarity is recorded as the vehicle abnormality possibility of the target similar information vehicle in the time period corresponding to the abnormal access time set.

[0086] It should be noted that this embodiment uses the Z-Score standard normalization method to calculate the normalized value. In actual application, the implementer can use other existing methods such as maximum and minimum value normalization method, sigmoid function, etc. to calculate the normalized value, which is not limited here.

[0087] The vehicle abnormality possibility is a significance evaluation of the malicious attack characteristics presented by the target similar information vehicle in the time period corresponding to the abnormal access time set. The greater the vehicle abnormality possibility, the greater the possibility that the target similar information vehicle corresponds to the virtual information generated by the malicious attack.

[0088] Set an abnormal classification threshold. In this implementation, the abnormal classification threshold is set to 0.5. Vehicles with a probability of abnormality greater than or equal to the abnormal classification threshold are marked as abnormal nodes. All edge servers are deprived of authorization for all abnormal nodes, and all abnormal nodes are unable to access all edge servers within the vehicle network. Vehicles with a probability of abnormality less than the abnormal classification threshold are marked as normal nodes. The edge servers maintain authorization for all normal nodes, and all normal nodes can access all edge servers within the vehicle network normally.

[0089] At this point, abnormal nodes and normal nodes are identified, and all edge servers are stopped from authorizing all abnormal nodes.

[0090] In step S004, any normal node is recorded as a target normal node, and any edge server is recorded as a target edge server. Based on the positional relationship of the target normal node relative to the target edge server at the current collection moment and the adjacent collection moment, the remaining memory capacity of all edge servers, and the possibility of vehicle abnormality in the target normal node in the time period corresponding to the abnormal access moment set, security access control of the Internet of Things information at the current collection moment is implemented.

[0091] When a normal node accesses an edge server within the IoV, it must determine the matching edge server for the normal node. As the distance between the normal node and the edge server decreases, the normal node's movement relative to the edge server becomes more stable. Furthermore, as the remaining memory capacity of an edge server decreases, the edge server is more likely to be selected as the matching edge server for the normal node.

[0092] Any normal node is recorded as the target normal node, and any edge server is recorded as the target edge server. The matching priority between the target normal node and the target edge server at the current collection time is determined based on the position relationship of the target normal node relative to the target edge server at the current collection time and the adjacent collection time, the remaining memory capacity of all edge servers, and the possibility of vehicle abnormality in the time period corresponding to the target normal node in the abnormal access time set.

[0093]

[0094] Where q k,w,i represents the matching priority between the target normal node k and the target edge server w at the current collection time i; s k,w,i-1 represents the distance between the target normal node k and the target edge server w at the previous collection time i-1 before the current collection time; s k,w,i M represents the distance between the target normal node k and the target edge server w at the current collection time i; w represents the remaining memory capacity of the target edge server w; represents the mean of the remaining memory capacity of all edge servers in the Internet of Vehicles; V k It represents the probability of vehicle abnormality of the target normal node k in the time period corresponding to the abnormal access time set.

[0095] Among them, the location of the edge server is fixed and is known information when the vehicle network is constructed. Therefore, based on the location of the edge server and the vehicle location of the normal node, the distance between the normal node and the edge server can be obtained.

[0096] The matching priority between the target normal node and any edge server can be obtained in the same manner, and the edge server corresponding to the highest matching priority is used as the edge server matching the target normal node.

[0097] The same method can be used to obtain the edge server that matches any normal node.

[0098] It should be noted that when the remaining memory capacity of the edge server matching the normal node is 0, the edge server corresponding to the second largest matching priority is selected as the edge server matching the target normal node. When the remaining memory capacity of the edge server corresponding to the largest matching priority and the edge server corresponding to the second largest matching priority are both 0, the edge server corresponding to the third largest matching priority is selected as the edge server matching the target normal node. And so on, the edge server matching any normal node is determined.

[0099] The vehicle information of the normal node at the current collection moment is sent to the matching edge server to achieve IoT information security access control.

[0100] Based on the same inventive concept as the above method, an embodiment of the present invention also provides an Internet of Things information security access control system, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of any one of the above-mentioned Internet of Things information security access control methods are implemented.

[0101] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for controlling information security access to the Internet of Things, characterized in that: The method comprises the following steps: Collect the vehicle location, vehicle direction, remaining memory capacity and access volume of the edge server at the current collection time and a preset number of collection times before; Record any collection time as the target collection time, and determine the abnormal access time and the abnormal access time set based on the access volume of all edge servers at the target collection time and the collection time adjacent to the target collection time; Record any abnormal access moment in the abnormal access moment set as the target abnormal access moment, record any two different vehicles in the vehicle network as the first vehicle and the second vehicle, determine the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set based on the difference and distance between the vehicle positions of the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set and adjacent moments of the abnormal access moment, and the angle between the vehicle directions of the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set, divide similar information vehicles and similar information vehicle groups based on the vehicle information similarity, determine the vehicle abnormality possibility of any vehicle in the time period corresponding to the abnormal access moment set based on the difference between the vehicle directions of any vehicle and other vehicles in the similar information vehicle group, and the difference between the vehicle information similarities, determine the abnormal node and the normal node based on the vehicle abnormality possibility, and stop all edge servers from authorizing all abnormal nodes; Record any normal node as the target normal node, and any edge server as the target edge server. Based on the positional relationship of the target normal node relative to the target edge server at the current collection time and the adjacent collection time, the remaining memory capacity of all edge servers, and the probability of vehicle abnormality in the time period corresponding to the target normal node in the abnormal access time set, implement IoT information security access control at the current collection time. The method of determining the possibility of vehicle abnormality of any vehicle in the time period corresponding to the abnormal access time set based on the difference between the vehicle directions of any vehicle in the similar information vehicle group and other vehicles, and the difference between the vehicle information similarities, includes the following specific methods: The mean of the vehicle directions of all the similar information vehicles included in the similar information vehicle group at all the abnormal access moments included in the abnormal access moment set is recorded as the first overall heading direction of the similar information vehicle group in the time period corresponding to the abnormal access moment set, the mean of the vehicle directions of all the abnormal access moments included in the abnormal access moment set of the target similar information vehicle is recorded as the second overall heading direction of the target similar information vehicle in the time period corresponding to the abnormal access moment set, and the angle between the first overall heading direction of the similar information vehicle group in the time period corresponding to the abnormal access moment set and the second overall heading direction of the target similar information vehicle in the time period corresponding to the abnormal access moment set is recorded as the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access moment set; The maximum value of the vehicle information similarity between the target similar information vehicle and other vehicles in the time period corresponding to the abnormal access time set is recorded as the first vehicle information similarity of the target similar information vehicle; the maximum value of the vehicle information similarity in the time period corresponding to the abnormal access time set of all two different vehicles is recorded as the second vehicle information similarity; the ratio of the second vehicle information similarity to the first vehicle information similarity of the target similar information vehicle is recorded as the third vehicle information similarity of the target similar information vehicle in the time period corresponding to the abnormal access time set; Determining the probability of a vehicle abnormality of the target similar information vehicle in the time period corresponding to the abnormal access time set based on the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the similarity of the third vehicle information; The method of implementing IoT information security access control at the current collection moment based on the positional relationship of the target normal node relative to the target edge server at the current collection moment and the adjacent collection moments, the remaining memory capacity of all edge servers, and the probability of vehicle abnormality in the time period corresponding to the target normal node in the abnormal access moment set includes the following specific methods: The calculation formula for the matching priority between the target normal node and the target edge server at the current collection time is: Where q k,w,i represents the matching priority between the target normal node k and the target edge server w at the current collection time i; s k,w,i-1 represents the distance between the target normal node k and the target edge server w at the previous collection time i-1 before the current collection time; s k,w,i M represents the distance between the target normal node k and the target edge server w at the current collection time i; w represents the remaining memory capacity of the target edge server w; represents the mean of the remaining memory capacity of all edge servers in the Internet of Vehicles; V k represents the probability of vehicle abnormality at the target normal node k in the time period corresponding to the abnormal access time set; Obtain the matching priority between the target normal node and any edge server, and use the edge server corresponding to the largest matching priority as the edge server matching the target normal node; Obtain the edge server that matches any normal node, and send the vehicle information of the normal node at the current collection time to the matching edge server to achieve IoT information security access control.

2. The method for controlling information security access to the Internet of Things according to claim 1, wherein: The specific method of determining the abnormal access time and the abnormal access time set according to the access volume of all edge servers at the target collection time and the collection time adjacent to the target collection time is as follows: The average of the visits to all edge servers at all collection times before the target collection time is recorded as the historical average of the visits at the target collection time; The cumulative sum of the visits to all edge servers at the target collection time is recorded as the cumulative visits at the target collection time. The difference between the cumulative visits at the target collection time and the collection time before the target collection time is recorded as the differential cumulative visits at the target collection time. The product of the differential cumulative visits at the target collection time and the cumulative visits is recorded as the first product at the target collection time. The normalized value of the ratio of the first product of the target collection time and the average of the historical visit volume is recorded as the malicious attack possibility at the target collection time; When the malicious attack possibility of the target collection moment is greater than the preset abnormal access threshold, the target collection moment is marked as an abnormal access moment, and the set of consecutive abnormal access moments including the current collection moment is recorded as the abnormal access moment set.

3. The method for controlling information security access to the Internet of Things according to claim 1, wherein: The method of determining the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set based on the difference and distance between the vehicle positions of the first vehicle and the second vehicle at all abnormal access times and adjacent times included in the abnormal access time set, and the angle between the vehicle directions of the first vehicle and the second vehicle at all abnormal access times included in the abnormal access time set, includes the following specific methods: The distance between the vehicle's position at the target abnormal access time and the vehicle's position at the moment before the target abnormal access time is recorded as the vehicle's displacement at the target abnormal access time; the absolute value of the difference between the displacements of the first vehicle and the second vehicle at the target abnormal access time is recorded as the displacement difference between the first vehicle and the second vehicle at the target abnormal access time; the mean of the displacement differences of all different vehicles in the vehicle network at all abnormal access times included in the abnormal access time set is recorded as the mean displacement difference for the time period corresponding to the abnormal access time set; The angle between the vehicle directions of the first vehicle and the second vehicle at the target abnormal access time is recorded as the vehicle direction difference between the first vehicle and the second vehicle at the target abnormal access time; The distance between the vehicle positions of the first vehicle and the second vehicle at the target abnormal access time is recorded as the vehicle distance between the first vehicle and the second vehicle at the target abnormal access time. The average of the vehicle distances between the first vehicle and the second vehicle at all abnormal access times included in the abnormal access time set is recorded as the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set. The average of the vehicle distances between all different vehicles in the vehicle network at the same abnormal access time included in the abnormal access time set is recorded as the comparative vehicle average distance in the time period corresponding to the abnormal access time set. Based on the displacement differences and vehicle direction differences of the first vehicle and the second vehicle in all abnormal access moments contained in the abnormal access moment set, the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set, the mean of the displacement differences in the time period corresponding to the abnormal access moment set and the compared average vehicle distance, the vehicle information similarity of the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set is determined.

4. The method for controlling information security access to the Internet of Things according to claim 3, wherein: The method of determining the vehicle information similarity between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set based on the displacement differences and vehicle direction differences between the first vehicle and the second vehicle at all abnormal access time moments included in the abnormal access time set, the average vehicle distance between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set, the mean of the displacement differences and the comparison average vehicle distance, includes the following specific methods: The maximum value of the displacement differences between the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set is recorded as the maximum displacement difference between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set. The ratio of the mean displacement differences in the time period corresponding to the abnormal access moment set to the maximum displacement difference between the first vehicle and the second vehicle in the time period corresponding to the abnormal access moment set is recorded as the first ratio. The ratio of the average distance of the comparison vehicles in the time period corresponding to the abnormal access time set to the average distance of the vehicles between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set is recorded as a second ratio; The ratio of the number 1 to the average of the vehicle direction differences between the first vehicle and the second vehicle at all abnormal access moments included in the abnormal access moment set is recorded as a third ratio; The normalized value of the product of the first ratio, the second ratio, and the third ratio is recorded as the vehicle information similarity between the first vehicle and the second vehicle in the time period corresponding to the abnormal access time set.

5. The method for controlling information security access to the Internet of Things according to claim 1, wherein: The specific method of dividing similar information vehicles and similar information vehicle groups according to vehicle information similarity includes: Two different vehicles corresponding to vehicle information similarities greater than a preset similarity division threshold are divided into a group of similar information vehicles, and all similar information vehicles divided from the same abnormal access time set are recorded as a similar information vehicle group.

6. The method for controlling information security access to the Internet of Things according to claim 1, wherein: The method of determining the vehicle abnormality possibility of the target similar information vehicle in the time period corresponding to the abnormal access time set based on the direction deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the third vehicle information similarity includes: The normalized value of the product of the directional deviation of the target similar information vehicle in the time period corresponding to the abnormal access time set and the third vehicle information similarity is recorded as the vehicle abnormality possibility of the target similar information vehicle in the time period corresponding to the abnormal access time set.

7. The method for controlling information security access to the Internet of Things according to claim 1, wherein: The specific method of determining abnormal nodes and normal nodes according to the possibility of vehicle abnormality and stopping all edge servers from authorizing all abnormal nodes is as follows: Vehicles with a probability of abnormality greater than or equal to a preset abnormal classification threshold are marked as abnormal nodes, and all edge servers are stopped from authorizing all abnormal nodes; Vehicles whose abnormality probability is less than the preset abnormality classification threshold are recorded as normal nodes, and the edge server maintains authorization for all normal nodes.

8. An Internet of Things information security access control system, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Access control method and device based on block chain, and storage medium

    CN115643577A

  • Internet of vehicles malicious vehicle node behavior detection method based on credibility management

    CN115694930A