Pseudo identity determination method and device, first vehicle and computer readable storage medium
By adopting the method of dynamically determining the target promulgator and selecting the target vehicle's pseudo-identity method in the Internet of Vehicles, the problem of vehicle location privacy leakage is solved, and higher location privacy protection and security are achieved.
Patent Information
- Application Number
- CN202510137834.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-13
AI Technical Summary
In the security application system of the Internet of Vehicles, vehicles leak location privacy through broadcast beacon messages, causing attackers to track and reconstruct vehicle users' driving trajectory, increasing the difficulty of location privacy protection.
Using vehicle pseudonym technology, the difficulty of attackers tracking and reconstructing the vehicle's driving trajectory is increased by dynamically determining the target promulgator and selecting the target vehicle's pseudo-identity. The specific method includes determining the target issuing party based on vehicle information, which may be the target issuing agency LPIA or the second vehicle, and obtaining the target vehicle's pseudo-identity for use through the target issuing party.
It effectively reduces the complexity of issuing pseudo-identity, reduces the burden on central agencies, improves the level of protection of vehicle location privacy, and is safer than traditional technology.
Smart Images

Figure CN119997026A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle technology, and in particular to a pseudo-identity determination method, device, first vehicle and computer-readable storage medium. Background Art
[0002] In the security application system of the Internet of Vehicles, vehicles periodically broadcast beacon messages containing key information such as vehicle identity, real-time location, and driving status, which effectively promotes driving safety and enables vehicle users to obtain road conditions in a timely manner, thereby avoiding potential traffic accident risks in advance. However, this mechanism also brings the hidden danger of location privacy leakage: attackers may use advanced multi-target tracking technology to track and reconstruct the driving trajectory of vehicle users based on these broadcast information, and then track vehicle users. Therefore, ensuring the protection of vehicle location privacy in the security application of the Internet of Vehicles has become an important issue that needs to be solved urgently. In order to effectively respond to the challenge of vehicle location privacy leakage, it is currently proposed to use vehicle pseudonym technology in the transmission of beacon messages in the Internet of Vehicles. The core of this technology is that vehicles no longer directly use their real identities to communicate, but use a series of regularly changed vehicle pseudonyms (vehicle pseudo identities) as identity identifiers.
[0003] At present, the implementation method of vehicle pseudonym technology is pseudonym preloading method. Under this strategy, whenever a vehicle user applies for a pseudonym, a central agency will generate a large number of pseudonyms for each vehicle in advance.
[0004] However, in actual use, vehicle users only need to use one of the pseudonyms each time they change their pseudonyms, which puts a huge pressure on the central agency in terms of pseudonym management and storage. Not only does it need to maintain a huge pseudonym library, but it also needs to ensure the security and efficiency of pseudonym allocation and use, which undoubtedly increases the system complexity and operating costs. Summary of the invention
[0005] Based on this, it is necessary to provide a pseudo-identity determination method, device, first vehicle and computer-readable storage medium that can reduce the complexity of pseudo-identity issuance in order to address the above technical problems.
[0006] In a first aspect, the present application provides a pseudo identity determination method, which is applied to a first vehicle and includes:
[0007] In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle;
[0008] The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0009] In one embodiment, determining a target issuing party capable of providing a pseudo identity for the first vehicle according to vehicle information of the first vehicle includes:
[0010] In a case where the pseudo-identity demand is a pseudo-identity allocation demand, determining, based on the location information of the first vehicle, a target LPIA that can provide a pseudo-identity for the first vehicle;
[0011] In the case where the pseudo-identity requirement is a pseudo-identity replacement requirement, a second vehicle that can provide a pseudo-identity for the first vehicle is determined according to vehicle speed information and driving environment information of the first vehicle.
[0012] In one embodiment, determining a target LPIA capable of providing a pseudo identity for the first vehicle based on the location information of the first vehicle includes:
[0013] determining a communication range of the first vehicle based on the location information and the communication capability of the first vehicle;
[0014] A candidate LPIA that falls within the communication range of the first vehicle is determined as a target LPIA that can provide a pseudo identity for the first vehicle.
[0015] In one of the embodiments, the driving environment information includes vehicle density information and roadside unit RSU presence in the target area;
[0016] The target area is located within the communication range of the first vehicle; the vehicle density information of the target area is determined by the total number of vehicles in the target area and the area of the target area; the vehicles in the target area include the first vehicle and other vehicles.
[0017] In one embodiment, determining a second vehicle capable of providing a pseudo identity for the first vehicle based on vehicle speed information and driving environment information of the first vehicle includes:
[0018] If the RSU existence condition indicates that there is no RSU in the target area, selecting a second vehicle that can provide a pseudo identity for the first vehicle from other vehicles according to vehicle density information of the target area and vehicle pseudo identities of other vehicles in the target area;
[0019] If the RSU existence condition indicates that there is an RSU in the target area, a second vehicle that can provide a pseudo identity for the first vehicle is selected from other vehicles according to the vehicle speed information of the first vehicle, the vehicle density information of the target area and the vehicle pseudo identities of other vehicles in the target area.
[0020] In one embodiment, according to vehicle density information of a target area and vehicle pseudo identities of other vehicles in the target area, selecting a second vehicle capable of providing a pseudo identity for a first vehicle from other vehicles includes:
[0021] When the vehicle density information is greater than the density threshold, the vehicle initiating the vehicle pseudo-identity sharing request is selected from other vehicles in the target area as the inviting vehicle, and a second vehicle capable of providing a pseudo-identity for the first vehicle is selected from the inviting vehicles according to the vehicle pseudo-identity of the inviting vehicle;
[0022] When the vehicle density information is less than or equal to the density threshold, a collaboration request is initiated to other vehicles in the target area, and the vehicles among other vehicles that participate in the collaboration based on the collaboration request are regarded as collaborative vehicles, and based on the vehicle pseudo-identities of the collaborative vehicles, a second vehicle that can provide a pseudo-identity for the first vehicle is selected from the collaborative vehicles.
[0023] In one embodiment, selecting a second vehicle capable of providing a pseudo identity for a first vehicle according to the vehicle pseudo identity of the cooperating vehicle includes:
[0024] Determine the pseudo-identity cracking probability corresponding to the vehicle pseudo-identity of each cooperating vehicle; wherein the pseudo-identity cracking probability corresponding to the vehicle pseudo-identity of each cooperating vehicle is the probability of successful cracking when the current vehicle pseudo-identity of the first vehicle is replaced with the vehicle pseudo-identity corresponding to the cooperating vehicle;
[0025] The cooperative vehicle corresponding to the smallest probability of cracking the pseudo-identity is used as the second vehicle that can provide a pseudo-identity for the first vehicle.
[0026] In one embodiment, selecting a second vehicle capable of providing a pseudo identity for the first vehicle from other vehicles based on vehicle speed information of the first vehicle, vehicle density information of the target area, and vehicle pseudo identities of other vehicles in the target area includes:
[0027] When the vehicle density information and vehicle speed information meet the vehicle teaming conditions, the RSU is controlled to initiate a teaming request to other vehicles in the target area, and the vehicles that participate in the teaming based on the teaming request are used as teaming vehicles. According to the vehicle pseudo-identities of the teaming vehicles, a second vehicle that can provide a pseudo-identity for the first vehicle is selected from the teaming vehicles.
[0028] In one embodiment, selecting a second vehicle capable of providing a pseudo identity for a first vehicle from the platoon vehicles according to the vehicle pseudo identities of the platoon vehicles includes:
[0029] Determining the pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle; wherein the pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle is used to characterize the difficulty of successfully cracking when the current vehicle pseudo-identity of the first vehicle is replaced with the vehicle pseudo-identity of the platoon vehicle;
[0030] The teaming vehicle corresponding to the greatest pseudo-identity confusion degree is used as a second vehicle capable of providing a pseudo-identity for the first vehicle;
[0031] The vehicle platooning condition includes that the vehicle density information is greater than a density threshold; or, the vehicle platooning condition includes that the vehicle density information is less than or equal to the density threshold, and the vehicle speed information is less than a speed threshold.
[0032] In one embodiment, if the target issuer is a target LPIA, controlling the target issuer to provide the target vehicle pseudo identity to the first vehicle includes:
[0033] Initiating a pseudo-identity allocation request to a central issuing authority CA, so that the CA sends the pseudo-identity allocation request to a target LPIA; wherein the pseudo-identity allocation request includes a real vehicle identity of the first vehicle;
[0034] Receive the target vehicle pseudo identity of the first vehicle fed back by the CA; wherein the target vehicle pseudo identity is generated by the target LPIA according to the real vehicle identity of the first vehicle;
[0035] The target vehicle pseudo identity is sent to the first vehicle by the CA when the CA verifies the validity of the target LPIA according to the sending timestamp, and the sending timestamp is carried by the target LPIA when sending the target vehicle pseudo identity to the CA.
[0036] In a second aspect, the present application also provides a pseudo-identity determination device, comprising:
[0037] The issuing party selection module is used to determine a target issuing party that can provide a pseudo identity for the first vehicle according to the vehicle information of the first vehicle when there is a need for a pseudo identity; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing institution LPIA and / or the second vehicle;
[0038] The pseudo identity acquisition module is used to control the target issuing direction to provide the target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0039] In a third aspect, the present application further provides a first vehicle, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0040] In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle;
[0041] The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0042] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the following steps are implemented:
[0043] In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle;
[0044] The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0045] In a fifth aspect, the present application further provides a computer program product, including a computer program, which implements the following steps when executed by a processor:
[0046] In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle;
[0047] The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0048] The above-mentioned pseudo-identity determination method, device, first vehicle and computer-readable storage medium, in this application, allow the second vehicle as the target issuer to provide a vehicle pseudo-identity for the first vehicle, thereby reducing the burden of the central agency to generate vehicle pseudo-identities. The first vehicle can dynamically select the target issuer according to actual conditions (such as location information, vehicle speed information, driving environment information, etc.), and obtain the target vehicle pseudo-identity generated by the target issuer for use. By dynamically determining the target issuer and selecting the target vehicle pseudo-identity, the difficulty for an attacker to track and reconstruct the vehicle's driving trajectory is increased, because the attacker cannot easily predict when the vehicle will change the vehicle pseudo-identity and which vehicle pseudo-identity will be used, thereby effectively protecting the vehicle's location privacy, which is more secure than relying solely on a central agency to generate a vehicle pseudo-identity in traditional technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0050] Figure 1 A diagram showing an application environment of a pseudo-identity determination method in an embodiment;
[0051] Figure 2 is a flow chart of a pseudo-identity determination method in one embodiment;
[0052] Figure 3 A flowchart of a step of determining a target issuing party capable of providing a pseudo identity for a first vehicle in one embodiment;
[0053] Figure 4 is a schematic diagram of interaction between a first vehicle and a CA target LPIA in one embodiment;
[0054] Figure 5 A flowchart of a step of determining a second vehicle capable of providing a pseudo identity for a first vehicle in one embodiment;
[0055] Figure 6 A flowchart of a step of selecting a second vehicle capable of providing a pseudo identity for a first vehicle in one embodiment;
[0056] Figure 7 A flowchart of a step of selecting a second vehicle capable of providing a pseudo identity for a first vehicle in another embodiment;
[0057] Figure 8A flowchart of a step of selecting a second vehicle capable of providing a pseudo identity for a first vehicle in another embodiment;
[0058] Fig. 9 is a structural block diagram of a pseudo-identity determination device in one embodiment;
[0059] Fig.10 1 is a diagram of the internal structure of a first vehicle in one embodiment. DETAILED DESCRIPTION
[0060] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0061] like Figure 1 As shown, a schematic diagram of an application environment of a pseudo identity determination method is provided, the application environment diagram including a central authority (CA), a local pseudo identity issuing authority (LPIA), a law enforcement agency (LE) and at least one vehicle user.
[0062] Among them, CA is responsible for the overall management of the system, including the initialization, configuration and maintenance of the system, to ensure that the system can operate normally. At the same time, it performs authentication work, verifies and confirms the identity and authority of each entity in the system, and prevents unauthorized access and operation. CA is responsible for formulating and implementing strategies for the issuance of vehicle pseudo-identities to ensure the effectiveness and security of vehicle pseudo-identities. It supervises the use and management of vehicle pseudo-identities throughout the system to prevent abuse and forgery, thereby protecting the privacy and security of vehicle users. CA exchanges data and information with the Local Pseudo-Identity Issuing Authority (LPIA) through cloud connection to ensure the uniformity and consistency of pseudo-identity issuance. It provides necessary support and guidance to LPIA to ensure the accuracy and compliance of pseudo-identity issuance. CA collaborates with law enforcement agencies (LE) to ensure that law enforcement agencies can obtain the necessary vehicle pseudo-identity information for effective law enforcement and management. It provides necessary support and assistance to help law enforcement agencies track and manage vehicle users and maintain traffic order and safety.
[0063] LPIA is responsible for issuing vehicle pseudo-identities to vehicle users. These vehicle pseudo-identities are designed to protect the privacy of vehicle users and ensure that their communications and transactions in the system can be conducted anonymously, thereby enhancing the security of the system. LPIA works closely with law enforcement agencies to provide necessary vehicle pseudo-identity information to support law enforcement activities. This collaborative mechanism ensures that law enforcement agencies can track and manage vehicle users when necessary, while maintaining the compliance of the system. LPIA communicates with vehicle users on the road in real time to ensure that vehicle users can obtain new vehicle pseudo-identities and updated information in a timely manner. This communication and interaction mechanism ensures the real-time and effectiveness of pseudo-identity issuance and improves the overall performance of the system. As the vehicle is used for a longer time or security requirements change, LPIA is responsible for updating and replacing vehicle pseudo-identities. This function ensures the continued security and effectiveness of the system and prevents the abuse and forgery of vehicle pseudo-identities.
[0064] The main role of LE is to ensure traffic order and safety. They work closely with the Central Authority (CA) and the Local Pseudo-Identity Issuing Authority (LPIA) to obtain the necessary vehicle pseudo-identity information for effective law enforcement and management. LE uses this vehicle pseudo-identity information to track and manage vehicle users to ensure compliance with traffic rules and road safety. At the same time, LE is also responsible for monitoring and managing the behavior of vehicle users, preventing and handling traffic violations, and maintaining traffic order.
[0065] Vehicle users obtain and manage vehicle pseudo-identities by communicating with the Local Pseudo-Identity Issuing Authority (LPIA), which are used to protect the privacy and security of vehicle users and prevent unauthorized access and operation. Vehicle users can enjoy privacy protection when using vehicle pseudo-identities for communication and transactions, while still needing to comply with traffic rules and regulations to ensure road safety. They also need to maintain good communication and cooperation with law enforcement agencies (LE) to jointly maintain traffic order and road safety.
[0066] In an exemplary embodiment, Figure 2 As shown, a pseudo identity determination is provided, and the method is applied to Figure 1 Take any vehicle user in the example as an example. For the convenience of explanation, in this embodiment, any vehicle is taken as the first vehicle. The pseudo identity determination includes:
[0067] S201, when there is a need for a pseudo identity, determining a target issuing party that can provide a pseudo identity for the first vehicle according to vehicle information of the first vehicle.
[0068] Specifically, when the first vehicle determines whether it has a pseudo-identity requirement, it can consider the following aspects:
[0069] 1) Check the current privacy protection settings, including whether anonymous communication, data encryption and other privacy protection functions are enabled. Evaluate the risk of privacy leakage based on the first vehicle's route, stopover location, communication content and other factors. If the risk is high, the first vehicle may need to apply for a pseudo vehicle identity to reduce the possibility of being tracked.
[0070] 2) Regularly update and understand the relevant laws and regulations on the use of vehicle pseudo-identities, including the circumstances under which vehicle pseudo-identities are allowed to be used, the validity period of vehicle pseudo-identities, the conditions that need to be met for applying for and using vehicle pseudo-identities, etc. According to the requirements of laws and regulations, the first vehicle checks whether it meets the conditions for applying for a vehicle pseudo-identity, such as whether it is a specific type of first vehicle, whether it is in a specific driving environment, etc.
[0071] 3) Analyze the current driving environment, including whether it is in a high-risk area, whether there is a potential communication conflict with other first vehicles, etc. Based on the driving environment, evaluate whether it is necessary to apply for a vehicle pseudo-identity to enhance communication security and prevent malicious attacks or information theft.
[0072] After the above considerations, if the first vehicle decides to apply for a vehicle pseudo-identity, it will search for a target issuing party that can provide it with a vehicle pseudo-identity, and will submit an application to the relevant target issuing party or parties in accordance with the established process, and provide the necessary verification information and materials. The target issuing party is the target issuing agency LPIA and / or the second vehicle. The first vehicle can select the target issuing agency LPIA and / or the second vehicle according to its own pseudo-identity needs.
[0073] For example, when the first vehicle needs an officially certified vehicle pseudo-identity to meet the requirements of laws, regulations or industry standards, it usually chooses to apply to the target issuing agency LPIA. As an official or authoritative issuing agency, LPIA can ensure the legality and validity of the vehicle pseudo-identity and meet the compliance requirements of the vehicle in various scenarios. For example, in some cases, the vehicle pseudo-identity may need to be centrally managed to ensure its uniqueness and security. As a specialized issuing agency, LPIA can provide standardized vehicle pseudo-identity generation, distribution and management services. Selecting LPIA as the target issuing party can ensure the consistency and traceability of the vehicle pseudo-identity, which is convenient for subsequent management and auditing. LPIA usually has a high reputation and reliability, and the vehicle pseudo-identity it issues is more easily accepted and trusted by other systems or participants. When a vehicle needs to use a vehicle pseudo-identity between multiple systems or platforms, selecting LPIA as the target issuing party can reduce the trust cost.
[0074] For example, in some decentralized or self-organized scenarios, vehicles may need to exchange vehicle pseudo-identities directly without going through official agencies. In this case, the second vehicle can serve as a vehicle pseudo-identity provider. This mode is suitable for situations where a trust relationship needs to be established quickly and flexibly between vehicles, and no official certification or centralized management is required. For example, if a secure communication channel has been established between the first vehicle and the second vehicle, and the second vehicle has the technical ability to generate and manage vehicle pseudo-identities, then selecting the second vehicle as the target issuer may be more efficient and convenient. In addition, if the vehicle pseudo-identity generation algorithm or protocol used by the second vehicle is compatible with the first vehicle, then this choice can ensure the validity and interoperability of the vehicle pseudo-identity between the two parties. For another example, in some specific application scenarios, such as vehicle platoon driving, collaborative driving, etc., vehicles may need to share vehicle pseudo-identities for better collaboration and communication. At this time, selecting the second vehicle as the target issuer may be more in line with actual needs.
[0075] In this embodiment, the first vehicle determines a target issuing party that can provide a pseudo identity for the first vehicle based on vehicle information of the first vehicle, wherein the vehicle information includes at least one of the position information, vehicle speed information, and driving environment information of the first vehicle.
[0076] For example, when the target issuer is determined to be the target LPIA, the influence of the position information, vehicle speed information and driving environment information on the selection of the target issuer is analyzed:
[0077] 1) Location information: Location information directly determines the physical distance between the first vehicle and the target LPIA. A shorter distance means shorter communication latency and higher data transmission rate, which is crucial for the pseudo-identity issuance process that requires real-time interaction. Therefore, when selecting the target LPIA, priority is given to LPIAs that are closer to the first vehicle to ensure the timeliness and effectiveness of pseudo-identity issuance. Location information also reflects the coverage of the target LPIA. If the first vehicle is within the coverage of a certain LPIA, then that LPIA is more likely to become the target issuer because it can directly provide services to the first vehicle. If the first vehicle is located in the cross-coverage area of multiple LPIAs, other factors need to be further considered to make a selection.
[0078] 2) Vehicle speed information: Vehicle speed information can reflect the driving status of the first vehicle. If the first vehicle is driving at high speed, the first vehicle may choose to apply for a vehicle pseudo-identity when the driving speed is slow or stopped (such as in traffic congestion or waiting at a traffic light) to avoid distracting driving attention due to the application process. In emergency situations (such as vehicle failure, accident, etc.), the first vehicle may need to quickly obtain a vehicle pseudo-identity for emergency communication or assistance. At this time, the vehicle speed information can be used as a reference factor to help LPIA quickly respond to and prioritize such applications.
[0079] 3) Driving environment information The complexity of the driving environment (such as traffic flow, road type, weather conditions, etc.) may affect the first vehicle's need and urgency for using a vehicle pseudo-identity. In a complex traffic environment, the first vehicle may need a more stable and reliable vehicle pseudo-identity to ensure the security and efficiency of communications. In certain driving environments (such as sensitive areas, private territories, etc.), the first vehicle may have higher requirements for privacy protection. Driving environment information can help the first vehicle assess its need for privacy protection and select an LPIA with higher privacy protection standards for application.
[0080] For another example, when the target issuing party is determined to be the second vehicle, the influence of the position information, the vehicle speed information and the driving environment information on the selection of the target issuing party is analyzed:
[0081] 1) Location information: Location information determines the physical proximity of the first vehicle to the second vehicle. If the two are close, the latency of direct communication will be lower and it will be easier to establish a stable communication connection. This is critical for scenarios where vehicle pseudo-identities need to be exchanged quickly for instant communication or collaboration. Location information can also help determine whether the second vehicle is within the communication coverage of the first vehicle. If the second vehicle is located in a communication blind spot or a weak signal area, selecting it as the issuer may face communication obstacles. Geographical factors: Specific geographical locations may be accompanied by specific environmental factors (such as mountainous areas, tunnels, urban high-rise buildings, etc.), which may affect the quality and stability of wireless communication. When selecting a second vehicle, it is necessary to consider the impact of these factors on communication performance.
[0082] 2) Vehicle speed information: If the relative speed of the first vehicle and the second vehicle is large, the communication between them may become unstable due to the rapidly changing network environment. In this case, selecting the second vehicle as the issuer may require additional mechanisms to ensure the continuity and stability of communication. Driving direction: The vehicle's speed information also includes the driving direction. If the first vehicle and the second vehicle are moving towards each other or in the same direction but with a large speed difference, the communication time window between them may be short. This requires that when selecting the second vehicle, its driving trajectory and speed should be considered to ensure that a stable communication connection can be established when needed.
[0083] 3) Driving environment information: Traffic conditions in driving environment information (such as traffic congestion, accident scenes, construction areas, etc.) may affect the driving and communication of vehicles. In a complex traffic environment, it may be necessary to be more cautious in selecting the second vehicle as the issuer to ensure that communication is not affected by traffic conditions. Safety considerations: In some driving environments (such as highways, night driving, etc.), safety is the primary consideration. When selecting the second vehicle as the issuer, it is necessary to evaluate whether it has sufficient security measures to protect the privacy and security of the vehicle during the exchange of pseudo-identities. If the first vehicle and the second vehicle are participating in some form of collaboration (such as vehicle platooning, cooperative driving, etc.), it may be more natural and efficient to select the second vehicle as the issuer. Because in this case, a close collaborative relationship has been established between them, and there may already be a basis for sharing information.
[0084] S202, controlling the target issuing party to provide a target vehicle pseudo identity to the first vehicle.
[0085] The target vehicle pseudo identity is used by the first vehicle to replace the vehicle's real identity in the target communication scenario. It can be understood that the target communication scenario refers to those specific environments or situations where the first vehicle needs to hide its real identity and use the vehicle pseudo identity for communication. These scenarios usually involve communication activities with high requirements for privacy protection, anonymity, and security.
[0086] In one achievable manner, if the target issuer is a target LPIA, the first vehicle controls the target LPIA to provide the target vehicle pseudo identity to the first vehicle, including: the first vehicle sends a pseudo identity request to the LPIA through the vehicle communication system. After receiving the request, the LPIA performs identity authentication to ensure that the request comes from a legitimate first vehicle. After the verification is passed, the LPIA generates a target vehicle pseudo identity that meets the requirements according to preset algorithms and rules. This vehicle pseudo identity may not be directly associated with the real identity of the first vehicle, and it is difficult to be tracked or associated back to the real identity. The LPIA securely transmits the generated vehicle pseudo identity to the first vehicle through an encrypted secure channel. During the transmission process, a strong encryption algorithm is used to ensure that the data is not stolen or tampered with. After receiving the vehicle pseudo identity, the first vehicle decrypts and verifies it to ensure the validity and integrity of the vehicle pseudo identity. After the verification is correct, the first vehicle stores the vehicle pseudo identity in the vehicle security module for subsequent use.
[0087] In another possible implementation, if the target issuer is the second vehicle, the first vehicle controls the target LPIA to provide the target vehicle pseudo identity to the first vehicle, including: the first vehicle sends a vehicle pseudo identity exchange request to the second vehicle, and the request may include specific requirements for the vehicle pseudo identity (such as type, validity period, etc.). After receiving the request, the second vehicle decides whether to accept the vehicle pseudo identity exchange based on the request content and its own security policy. If the second vehicle agrees to exchange the vehicle pseudo identity, the second vehicle's own vehicle pseudo identity is sent to the first vehicle.
[0088] The above-mentioned pseudo-identity determination method allows the second vehicle as the target issuer to provide a vehicle pseudo-identity for the first vehicle in this application, which reduces the burden of the central agency to generate vehicle pseudo-identities. The first vehicle can dynamically select the target issuer according to actual conditions (such as location information, vehicle speed information, driving environment information, etc.), and obtain the target vehicle pseudo-identity generated by the target issuer for use. By dynamically determining the target issuer and selecting the target vehicle pseudo-identity, it is more difficult for an attacker to track and reconstruct the vehicle's driving trajectory, because the attacker cannot easily predict when the vehicle will change the vehicle pseudo-identity and which vehicle pseudo-identity will be used, thereby effectively protecting the vehicle's location privacy, which is more secure than traditional technologies that only rely on central agencies to generate vehicle pseudo-identities.
[0089] In an exemplary embodiment, Figure 3 As shown, according to the vehicle information of the first vehicle, determining a target issuing party that can provide a pseudo identity for the first vehicle includes:
[0090] S301 : When the pseudo-identity requirement is a pseudo-identity allocation requirement, determine a target LPIA that can provide a pseudo-identity for the first vehicle according to location information of the first vehicle.
[0091] Among them, the pseudo identity allocation requirement can specifically refer to the requirement of initially acquiring a pseudo identity. In the Internet of Vehicles, the Internet of Things, or other systems requiring privacy protection, when a first vehicle first joins the network, it may need one or more pseudo identities to hide its true identity and communicate with other entities securely and privacy-protected.
[0092] Specifically, according to the location information of the first vehicle, determining a target LPIA that can provide a pseudo identity for the first vehicle includes: determining a communication range of the first vehicle according to the location information and communication capability of the first vehicle; and determining a candidate LPIA that falls within the communication range of the first vehicle as a target LPIA that can provide a pseudo identity for the first vehicle.
[0093] Optionally, the first vehicle needs to obtain its own location information, which is usually achieved through on-board positioning technology. Then, the first vehicle evaluates the performance of its communication equipment, including communication distance, signal strength, data transmission rate, etc., to determine its effective communication range. Combining the location information and communication capabilities, the first vehicle can calculate the geographical range in which it can communicate stably, which is usually a circular or elliptical area centered on the current position of the vehicle.
[0094] Further, the first vehicle or its backend system maintains a list of candidate LPIAs, which are organizations known to be able to provide vehicle pseudo-identity services. Each candidate LPIA corresponds to a coverage range, which defines the geographical area where the LPIA can provide services. This information is usually pre-stored in the first vehicle or its backend system. The first vehicle compares its calculated communication range with the coverage range of each candidate LPIA to find out those LPIAs that its communication range can cover. From the candidate LPIAs within the coverage range, the first vehicle can determine one or more target LPIAs based on certain selection criteria (such as the closest distance, the highest service quality, the fastest response speed, etc.), which will be able to provide the first vehicle with a vehicle pseudo-identity. The first vehicle establishes a connection with the target LPIA through a secure communication channel.
[0095] Then, the first vehicle sends a pseudo-identity request to the target LPIA, which may contain specific requirements for the vehicle pseudo-identity (such as type, validity period, encryption algorithm, etc.). After receiving the request, the target LPIA generates the target vehicle pseudo-identity based on the request content and its own security policy, and sends it to the first vehicle through a secure communication channel. After receiving the target vehicle pseudo-identity, the first vehicle decrypts and verifies it to ensure its validity and integrity, and then stores the target vehicle pseudo-identity in the on-board security module for subsequent use.
[0096] In this embodiment, if Figure 4As shown, if the target issuer is a target LPIA, the first vehicle sends a pseudo-identity request to the target LPIA through the CA as a medium, that is, the first vehicle sends a pseudo-identity request to the CA, and the CA forwards the pseudo-identity request to the target LPIA; then, the target LPIA generates a target vehicle pseudo-identity for the first vehicle and returns the target vehicle pseudo-identity to the CA, and the CA then forwards the target vehicle pseudo-identity to the first vehicle.
[0097] Exemplarily, the pseudo-identity request sent by the first vehicle to the CA may be as follows (1):
[0098] (1)
[0099] in, It is the request content generated by the first vehicle by querying the current status information and the number of requests; is the real vehicle identity of the first vehicle; The timestamp of when the first vehicle sends the pseudo-identity request to the target LPIA.
[0100] Specifically, after receiving the application, the CA will first verify the legitimacy of the first vehicle. If the first vehicle is legitimate, it will query the nearest As the target LPIA, a vehicle pseudo identity generation command is issued to it. The vehicle pseudo identity generation command is shown in the following formula (2):
[0101] (2)
[0102] in, The real vehicle identity of the first vehicle is encrypted and concatenated with the random number string. This process will obscure the real vehicle identity of the first vehicle. In this case, the real vehicle identity of the first vehicle is only known by the CA. The timestamp when the CA sends the vehicle pseudo-identity generation command to the target LPIA.
[0103] Target LPIA (e.g. ) After receiving the message from CA, check Whether it has expired. If the message has expired, it will be discarded; if it has not expired, select , generate the target vehicle pseudo identity :
[0104]
[0105] The target LPIA will be the target vehicle pseudo-identity Sent to CA with a sending timestamp. The sending timestamp is carried when the target LPIA sends the target vehicle pseudo-identity to CA.
[0106] The CA verifies the identity of the target LPIA. If the target LPIA is legitimate, the CA will issue the target vehicle pseudo identity to the first vehicle. and The mapping relationship between them is saved and updated in real time to keep the true identity of the vehicle traceable in the subsequent process.
[0107] Based on the above process, the target issuing direction is controlled to provide the target vehicle pseudo identity to the first vehicle, including: initiating a pseudo identity allocation request to the central issuing authority CA, so that the CA sends the pseudo identity allocation request to the target LPIA; receiving the target vehicle pseudo identity of the first vehicle fed back by the CA; wherein the target vehicle pseudo identity is generated by the target LPIA according to the real vehicle identity of the first vehicle.
[0108] The pseudo identity allocation requirement includes the real vehicle identity of the first vehicle. It is understandable that the target vehicle pseudo identity is sent to the first vehicle by the CA after the CA verifies the validity of the target LPIA according to the sending timestamp and passes the validity verification.
[0109] S302: When the pseudo-identity requirement is a pseudo-identity replacement requirement, determine a second vehicle that can provide a pseudo-identity for the first vehicle according to vehicle speed information and driving environment information of the first vehicle.
[0110] Among them, the need for pseudo-identity replacement means that in certain application scenarios, an entity needs to regularly or irregularly replace its currently used pseudo-identity to further improve the level of privacy protection, enhance security, or meet other specific needs.
[0111] It is understandable that when the pseudo identity requirement is a pseudo identity replacement requirement, a second vehicle needs to be selected from multiple other vehicles to provide a new vehicle pseudo identity, and the process of selecting the second vehicle is a complex decision-making process. Therefore, the vehicle speed information and driving environment information of the first vehicle need to be comprehensively considered.
[0112] In this embodiment, the driving environment information includes vehicle density information and the existence of roadside units (RSUs) in the target area.
[0113] The target area is within the communication range of the first vehicle. The target area is the area covered by the range within which the first vehicle can effectively communicate wirelessly. The vehicle density information of the target area is determined by the total number of vehicles in the target area and the area of the target area; the vehicles in the target area include the first vehicle and other vehicles. The first vehicle exchanges vehicle pseudo-identities with surrounding vehicles through its communication equipment. In order to effectively perform such an exchange, especially when it comes to security-sensitive operations such as vehicle pseudo-identity replacement, the first vehicle needs to accurately perceive other vehicles within its communication range. This includes understanding their number, location, speed, and possible communication capabilities.
[0114] It is understandable that RSU, as the infrastructure in the Internet of Vehicles, can enhance the communication capabilities between vehicles. It can exchange information with vehicles through wireless communication technology to achieve information exchange between vehicles and between vehicles and roads. RSU can also connect to existing electronic equipment on the road to collect and analyze real-time information such as traffic flow, vehicle speed, and road conditions. Therefore, in the target area, the presence of RSU can expand the communication range of vehicles and improve the reliability and stability of communication.
[0115] In this embodiment, by distinguishing between pseudo-identity allocation requirements and pseudo-identity replacement requirements, different types of pseudo-identity requirements can be processed in a targeted manner, thereby improving the flexibility of vehicle pseudo-identity management.
[0116] Specifically, Figure 5 As shown, according to the vehicle speed information and driving environment information of the first vehicle, determining a second vehicle that can provide a pseudo identity for the first vehicle includes:
[0117] S501, if the RSU existence condition indicates that there is no RSU in the target area, a second vehicle capable of providing a pseudo identity for the first vehicle is selected from other vehicles according to vehicle density information of the target area and vehicle pseudo identities of other vehicles in the target area.
[0118] It is understandable that in some areas or situations, the RSU may be missing due to various reasons (such as lagging infrastructure construction, poor maintenance, etc.). At this time, the first vehicle needs a vehicle pseudo-identity replacement solution that does not rely on the RSU to ensure that it can continue to participate in the Internet of Vehicles communication safely and effectively.
[0119] Specifically, the first vehicle collects the number and location information of other vehicles in the target area through its on-board sensors or vehicle network communication technology. Based on the collected data, the vehicle density of the target area is calculated to evaluate the traffic congestion and communication environment in the area. In the target area, the first vehicle screens out potential candidate vehicles based on the vehicle density information. Usually, vehicles with a closer distance and better communication quality are selected as candidates. For the screened candidate vehicles, the first vehicle will further evaluate their communication capabilities, credibility, historical performance and other factors. The purpose of the evaluation is to ensure that the selected second vehicle can stably and reliably provide the vehicle pseudo-identity replacement service for the first vehicle, while reducing potential communication risks and safety hazards. After completing the evaluation of the candidate vehicles, the first vehicle will select the most suitable second vehicle based on the evaluation results. The selection criteria may include communication quality, the validity of the vehicle pseudo-identity, the vehicle's credibility, and historical cooperation records. Once the second vehicle is selected, the first vehicle will establish a communication connection with it and start the vehicle pseudo-identity replacement process.
[0120] S502, if the RSU existence condition indicates that there is an RSU in the target area, a second vehicle that can provide a pseudo identity for the first vehicle is selected from other vehicles according to the vehicle speed information of the first vehicle, the vehicle density information of the target area and the vehicle pseudo identities of other vehicles in the target area.
[0121] It can be understood that the existence of RSU provides a more stable communication infrastructure for vehicles. By utilizing the location and communication capabilities of RSU, the communication path and method between vehicles can be further optimized. By considering vehicle speed information and vehicle density information, a second vehicle with a speed close to that of the first vehicle and in a better communication environment can be selected, thereby improving communication efficiency and quality.
[0122] Specifically, the first vehicle obtains its own real-time speed information through vehicle-mounted sensors or vehicle networking communication technology. The number and location information of other vehicles in the target area are collected by using vehicle-mounted sensors or vehicle networking communication technology, and then the vehicle density is calculated. The vehicle pseudo-identity information of other vehicles in the target area is obtained through vehicle networking communication, including whether they have a valid vehicle pseudo-identity, the validity period of the vehicle pseudo-identity, etc.
[0123] Once the second vehicle is selected, the first vehicle will establish a communication connection with it and perform the vehicle pseudo-identity replacement operation according to a predetermined protocol or process, which may include sending a pseudo-identity request, receiving a vehicle pseudo-identity response, and verifying the validity of the vehicle pseudo-identity.
[0124] In an exemplary embodiment, Figure 6As shown, according to the vehicle density information of the target area and the vehicle pseudo identities of other vehicles in the target area, selecting a second vehicle that can provide a pseudo identity for the first vehicle from other vehicles includes:
[0125] S601, when the vehicle density information is greater than the density threshold, select the vehicle that initiates the vehicle pseudo-identity sharing request from other vehicles in the target area as the inviting vehicle, and select a second vehicle that can provide a pseudo-identity for the first vehicle from the inviting vehicles based on the vehicle pseudo-identity of the inviting vehicle.
[0126] It is understandable that if the vehicle density exceeds the threshold, it means that the vehicles in the current area are relatively dense, and the first vehicle can "passively" receive the vehicle pseudo-identity sharing request initiated by the inviting vehicle to exchange vehicle pseudo-identities.
[0127] Specifically, the first vehicle receives a vehicle pseudo-identity sharing request from the inviting vehicle, which should include the vehicle pseudo-identity information of the inviting vehicle, a list of available vehicle pseudo-identities (if any), and the conditions or requirements for sharing. The first vehicle analyzes its own needs and determines the required vehicle pseudo-identity type or characteristics (such as a specific geographical identifier, vehicle type identifier, etc.). The vehicle pseudo-identity information provided by the inviting vehicle is matched with the needs of the first vehicle to find a vehicle pseudo-identity that meets the requirements. Among the matched vehicle pseudo-identities, a second vehicle that can provide these vehicle pseudo-identities is further screened.
[0128] Among them, the screening criteria may include: 1) Validity of vehicle pseudo-identity: Ensure that the vehicle pseudo-identity is legal, valid and not used by other vehicles. 2) Credibility of the inviting vehicle: Evaluate the credibility of the inviting vehicle to ensure that the vehicle pseudo-identity it provides is reliable. 3) Position and driving direction: Consider factors such as the relative position and driving direction of the inviting vehicle and the first vehicle to select a more suitable vehicle pseudo-identity provider. 4) Communication quality: Evaluate the communication quality with the inviting vehicle to ensure that the information transmission during the vehicle pseudo-identity sharing process is stable and reliable.
[0129] Furthermore, the first vehicle negotiates with the selected second vehicle to confirm the specific details of sharing the vehicle pseudo-identity, including the time and method of sharing, and the rights and obligations of both parties, etc. After both parties reach an agreement, the vehicle pseudo-identities are exchanged or shared.
[0130] S602, when the vehicle density information is less than or equal to the density threshold, a collaboration request is initiated to other vehicles in the target area, and the vehicles among other vehicles that participate in the collaboration based on the collaboration request are regarded as collaborative vehicles, and based on the vehicle pseudo-identities of the collaborative vehicles, a second vehicle that can provide a pseudo-identity for the first vehicle is selected from the collaborative vehicles.
[0131] It is understandable that if the vehicle density exceeds the threshold, it means that the vehicles in the current area are relatively sparse, and the first vehicle needs to "actively" initiate a collaboration request and use vehicles that are willing to exchange vehicle pseudo-identities (i.e., vehicles participating in the collaboration) as collaborative vehicles.
[0132] Optionally, the collaboration request should include the first vehicle's identification, the required vehicle pseudo-identity type or condition, and the willingness and purpose of collaboration. After receiving the collaboration request, the surrounding vehicles respond according to their own conditions and willingness. The vehicles willing to participate in the collaboration (i.e., the collaborative vehicles) send a response message to the first vehicle, which should include its vehicle pseudo-identity information, the vehicle pseudo-identity type or list that can be provided, and the specific conditions or requirements for collaboration.
[0133] The first vehicle receives and parses the response message from the cooperative vehicle. Based on the vehicle pseudo-identity information of the cooperative vehicle, the type of vehicle pseudo-identity that can be provided, and the cooperative condition, the first vehicle selects a second vehicle that meets its needs. The screening criteria may include the validity of the vehicle pseudo-identity, the credibility of the cooperative vehicle, the matching degree of the location and the driving direction, and the communication quality.
[0134] Then, the first vehicle and the selected second vehicle conduct further negotiations to clarify the specific details of the exchange of vehicle pseudo-identities, including the time and method of the exchange, the rights and obligations of both parties, etc. After the two parties reach an agreement, the exchange of vehicle pseudo-identities is carried out.
[0135] In an exemplary embodiment, Figure 7 As shown, in the above S601, selecting a second vehicle that can provide a pseudo identity for the first vehicle according to the vehicle pseudo identity of the cooperating vehicle includes:
[0136] S701, determining a pseudo-identity cracking probability corresponding to a vehicle pseudo-identity of each cooperating vehicle.
[0137] The pseudo-identity cracking probability corresponding to the vehicle pseudo-identity of each cooperating vehicle is the probability of successful cracking when the current vehicle pseudo-identity of the first vehicle is replaced with the vehicle pseudo-identity corresponding to the cooperating vehicle.
[0138] For example, for the i-th cooperative vehicle V i , the pseudo-identity cracking probability corresponding to the pseudo-identity of the cooperative vehicle is P ri .
[0139] For example, P r The calculation process can be as follows (3):
[0140] (3)
[0141] Where N represents the number of successful tracking times, and M represents the number of pseudonym switching times.
[0142] It is understandable that the attacker intercepts the vehicle information by eavesdropping and obtains the direction, speed and position of each vehicle. By calculating this information at different times, the future position of each vehicle is predicted, thereby completing the tracking of the vehicle. The state estimation is performed by the Extended Kalman Filter (EKF). The details are as follows:
[0143] The attacker obtains the beacon message of t , use EKF to predict the state of t+1 , and the actual message at t+1 is , calculate the distance between the actual position and the predicted position ,if , we can infer that p i and p k belong to the same vehicle, the above N is p i and p k The number of times it belongs to the same vehicle.
[0144] In the above process, the tracking success rate refers to the proportion of vehicles that the attacker can still track after implementing the corresponding location privacy protection method. Since the attacker may make a wrong match during tracking, the tracking success rate can intuitively and effectively reflect the location privacy protection results.
[0145] S702: The cooperative vehicle corresponding to the smallest probability of cracking the pseudo-identity is used as the second vehicle that can provide a pseudo-identity for the first vehicle.
[0146] Specifically, selecting the minimum pseudo-identity cracking probability from each pseudo-identity cracking probability can be expressed as the optimization problem in the following formula (4):
[0147] (4)
[0148] Among them, P ri The smaller it is, the more difficult it is for an attacker to track the cooperative vehicle, and the higher the level of location privacy protection of the cooperative vehicle.
[0149] In an exemplary embodiment, the above S602 selects a second vehicle that can provide a pseudo identity for the first vehicle from other vehicles based on the vehicle speed information of the first vehicle, the vehicle density information of the target area, and the vehicle pseudo identities of other vehicles in the target area, including: when the vehicle density information and the vehicle speed information meet the vehicle teaming conditions, controlling the RSU to initiate a teaming request to other vehicles in the target area, and taking the vehicles among the other vehicles that participate in the teaming based on the teaming request as teaming vehicles, and selecting a second vehicle that can provide a pseudo identity for the first vehicle from the teaming vehicles based on the vehicle pseudo identities of the teaming vehicles.
[0150] Among them, the team formation condition can be when the vehicle density exceeds a certain threshold and the vehicle speed is within a certain range, etc.
[0151] In this embodiment, the vehicle platooning condition includes that the vehicle density information is greater than a density threshold; or, the vehicle platooning condition includes that the vehicle density information is less than or equal to the density threshold, and the vehicle speed information is less than a speed threshold.
[0152] It is understandable that when the vehicle density information is greater than the set density threshold, it means that there are a large number of vehicles in the current road or area and the traffic flow is large. In this case, the vehicle teaming condition is set to that the vehicle density is greater than the density threshold.
[0153] When the vehicle density information is less than or equal to the density threshold, and the vehicle speed information is less than the speed threshold, it means that the number of vehicles on the current road or area is relatively small, but the vehicle speed is slow. In this case, the vehicle teaming condition is set to vehicle density less than or equal to the density threshold and vehicle speed less than the speed threshold.
[0154] Optionally, the RSU determines whether the team formation conditions are currently met. When the team formation conditions are met, the RSU initiates a team formation request to other vehicles in the target area. This can be achieved through vehicle network broadcast messages, wireless communications, or a dedicated team formation protocol. The team formation request should include information such as the purpose and requirements of the team formation and the way to participate in the team formation. After receiving the team formation request, other vehicles respond according to their own circumstances (such as whether they are willing to participate in the team formation, whether they meet the team formation requirements, etc.). The RSU screens out vehicles willing to participate in the team formation based on the vehicle's response and marks these vehicles as team formation vehicles. Among the team formation vehicles, the RSU further screens out a second vehicle that can provide a suitable vehicle pseudo identity for the first vehicle based on the vehicle pseudo identity of the team formation vehicle. The screening criteria may include the effectiveness, safety, and matching degree of the vehicle pseudo identity with the needs of the first vehicle.
[0155] In this embodiment, the RSU can further communicate with the platooning vehicles to obtain more detailed vehicle pseudo-identity information or conduct negotiations. After determining the second vehicle, the RSU assists the first vehicle in exchanging vehicle pseudo-identities with the second vehicle. This can ensure the security and privacy of the exchange process through a secure communication protocol. After the exchange is completed, the RSU or the first vehicle verifies the new vehicle pseudo-identity to ensure its validity and correctness.
[0156] In an exemplary embodiment, Figure 8 As shown, according to the vehicle pseudo-identities of the platoon vehicles, selecting a second vehicle that can provide a pseudo-identity for the first vehicle from the platoon vehicles includes:
[0157] S801, determining the pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle.
[0158] The pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle is used to characterize the difficulty of successfully cracking the current vehicle pseudo-identity of the first vehicle when it is replaced with the vehicle pseudo-identity of the platoon vehicle.
[0159] For example, for the i-th platoon vehicle V i , the pseudo-identity confusion degree corresponding to the pseudo-identity of the vehicle in the team is , A larger value indicates a greater degree of confusion for attackers.
[0160] Among them, P ri is the i-th team vehicle V i The pseudo-identity cracking probability corresponding to the vehicle pseudo-identity is shown in the above formula (3).
[0161] S802, using the team vehicle corresponding to the maximum pseudo-identity confusion degree as the second vehicle that can provide a pseudo-identity for the first vehicle.
[0162] Optionally, the maximum pseudo-identity confusion degree is selected from each pseudo-identity confusion degree, which can be expressed as the optimization problem in the following formula (5):
[0163] (5)
[0164] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0165] Based on the same inventive concept, the embodiment of the present application also provides a pseudo identity determination device for implementing the above-mentioned pseudo identity determination device. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above-mentioned method, so the specific limitations in one or more pseudo identity determination device embodiments provided below can refer to the limitations on pseudo identity determination in the above text, and will not be repeated here.
[0166] In an exemplary embodiment, Fig. 9As shown, a pseudo identity determination device is provided, comprising: an issuing party selection module 11 and a pseudo identity acquisition module 12, wherein:
[0167] The issuing party selection module 11 is used to determine a target issuing party that can provide a pseudo identity for the first vehicle according to the vehicle information of the first vehicle when there is a need for a pseudo identity; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is the target issuing institution LPIA and / or the second vehicle;
[0168] The pseudo identity acquisition module 12 is used to control the target issuing direction to provide the target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0169] In one of the embodiments, the issuing party selection module 11 is further configured to: determine, in the case where the pseudo identity requirement is a pseudo identity allocation requirement, a target LPIA capable of providing a pseudo identity for the first vehicle according to the location information of the first vehicle;
[0170] In the case where the pseudo-identity requirement is a pseudo-identity replacement requirement, a second vehicle that can provide a pseudo-identity for the first vehicle is determined according to vehicle speed information and driving environment information of the first vehicle.
[0171] In one embodiment, the issuing party selection module 11 is further used to: determine the communication range of the first vehicle according to the location information and communication capability of the first vehicle;
[0172] A candidate LPIA that falls within the communication range of the first vehicle is determined as a target LPIA that can provide a pseudo identity for the first vehicle.
[0173] In one of the embodiments, the driving environment information includes vehicle density information and roadside unit RSU presence in the target area;
[0174] The target area is located within the communication range of the first vehicle; the vehicle density information of the target area is determined by the total number of vehicles in the target area and the area of the target area; and the vehicles in the target area include the first vehicle and other vehicles.
[0175] In one of the embodiments, the issuing party selection module 11 is further configured to: if the RSU existence condition indicates that there is no RSU in the target area, select a second vehicle that can provide a pseudo identity for the first vehicle from other vehicles according to vehicle density information of the target area and vehicle pseudo identities of other vehicles in the target area;
[0176] If the RSU existence condition indicates that there is an RSU in the target area, a second vehicle that can provide a pseudo identity for the first vehicle is selected from other vehicles according to the vehicle speed information of the first vehicle, the vehicle density information of the target area and the vehicle pseudo identities of other vehicles in the target area.
[0177] In one embodiment, the issuing party selection module 11 is further used to: when the vehicle density information is greater than the density threshold, select the vehicle that initiates the vehicle pseudo-identity sharing request from other vehicles in the target area as the inviting vehicle, and select a second vehicle that can provide a pseudo-identity for the first vehicle from the inviting vehicles according to the vehicle pseudo-identity of the inviting vehicle;
[0178] When the vehicle density information is less than or equal to the density threshold, a collaboration request is initiated to other vehicles in the target area, and the vehicles among other vehicles that participate in the collaboration based on the collaboration request are regarded as collaborative vehicles, and based on the vehicle pseudo-identities of the collaborative vehicles, a second vehicle that can provide a pseudo-identity for the first vehicle is selected from the collaborative vehicles.
[0179] In one embodiment, the issuing party selection module 11 is further used to: determine the pseudo-identity cracking probability corresponding to the vehicle pseudo-identity of each cooperating vehicle; wherein the pseudo-identity cracking probability corresponding to the vehicle pseudo-identity of each cooperating vehicle is the probability of successful cracking when the current vehicle pseudo-identity of the first vehicle is replaced with the vehicle pseudo-identity corresponding to the cooperating vehicle;
[0180] The cooperative vehicle corresponding to the smallest probability of cracking the pseudo-identity is used as the second vehicle that can provide a pseudo-identity for the first vehicle.
[0181] In one of the embodiments, the issuing party selection module 11 is also used to: when the vehicle density information and the vehicle speed information meet the vehicle teaming conditions, control the RSU to initiate a teaming request to other vehicles in the target area, and use the vehicles that participate in the teaming based on the teaming request as teaming vehicles, and select a second vehicle that can provide a pseudo identity for the first vehicle from the teaming vehicles according to the vehicle pseudo identity of the teaming vehicle.
[0182] In one embodiment, the issuing party selection module 11 is further used to: determine the pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle; wherein the pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle is used to represent the difficulty of successfully cracking when the current vehicle pseudo-identity of the first vehicle is replaced with the vehicle pseudo-identity of the platoon vehicle;
[0183] The team vehicle corresponding to the maximum pseudo-identity confusion degree is used as the second vehicle that can provide a pseudo-identity for the first vehicle.
[0184] In one of the embodiments, the vehicle platooning condition includes that the vehicle density information is greater than a density threshold; or, the vehicle platooning condition includes that the vehicle density information is less than or equal to the density threshold, and the vehicle speed information is less than a speed threshold.
[0185] In one embodiment, the pseudo identity acquisition module 12 is further used to: initiate a pseudo identity allocation request to a central issuing authority CA, so that the CA sends the pseudo identity allocation request to a target LPIA; wherein the pseudo identity allocation request includes the real vehicle identity of the first vehicle;
[0186] Receive the target vehicle pseudo identity of the first vehicle fed back by the CA; wherein the target vehicle pseudo identity is generated by the target LPIA according to the real vehicle identity of the first vehicle.
[0187] In one of the embodiments, the target vehicle pseudo identity is sent to the first vehicle by the CA after the CA verifies the validity of the target LPIA according to the sending timestamp, and if the validity verification passes, the CA verifies the target vehicle pseudo identity by the CA; wherein the sending timestamp is carried by the target LPIA when sending the target vehicle pseudo identity to the CA.
[0188] Each module in the above-mentioned pseudo-identity determination device can be implemented in whole or in part by software, hardware, or a combination thereof. Each module can be embedded in or independent of the processor in the first vehicle in the form of hardware, or can be stored in the memory in the first vehicle in the form of software, so that the processor can call and execute the operations corresponding to each module.
[0189] In an exemplary embodiment, a first vehicle is provided. The first vehicle may be a terminal, and its internal structure diagram may be as follows: Fig.10As shown. The first vehicle includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. The processor of the first vehicle is used to provide computing and control capabilities. The memory of the first vehicle includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the first vehicle is used to exchange information between the processor and an external device. The communication interface of the first vehicle is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (NFC) or other technologies. When the computer program is executed by the processor, a pseudo identity determination is implemented. The display unit of the first vehicle is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the first vehicle can be a touch layer covering the display screen, or a button, trackball or touchpad set on the shell of the first vehicle, or an external keyboard, touchpad or mouse.
[0190] Those skilled in the art will understand that Fig.10 The structure shown in the figure is merely a block diagram of a partial structure related to the scheme of the present application, and does not constitute a limitation on the first vehicle to which the scheme of the present application is applied. The specific first vehicle may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0191] In an exemplary embodiment, a first vehicle is provided, comprising a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0192] In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle;
[0193] The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0194] In one embodiment, a computer readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0195] In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle;
[0196] The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0197] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:
[0198] In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle;
[0199] The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in the target communication scenario.
[0200] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0201] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.
[0202] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0203] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A pseudo-identity determination method, characterized in that: Applied to a first vehicle, the method comprises: In the case of a pseudo identity requirement, a target issuing party capable of providing a pseudo identity for the first vehicle is determined according to the vehicle information of the first vehicle; wherein the vehicle information includes at least one of the position information, vehicle speed information and driving environment information of the first vehicle; the target issuing party is a target issuing authority LPIA and / or a second vehicle; The target issuing direction is controlled to provide a target vehicle pseudo identity to the first vehicle; wherein the target vehicle pseudo identity is used for the first vehicle to replace the real vehicle identity of the first vehicle in a target communication scenario.
2. The method according to claim 1, characterized in that The step of determining, based on the vehicle information of the first vehicle, a target issuing party that can provide a pseudo identity for the first vehicle comprises: In a case where the pseudo-identity demand is a pseudo-identity allocation demand, determining, according to the location information of the first vehicle, a target LPIA that can provide a pseudo-identity for the first vehicle; In the case that the pseudo-identity requirement is a pseudo-identity replacement requirement, a second vehicle capable of providing a pseudo-identity for the first vehicle is determined according to vehicle speed information and driving environment information of the first vehicle.
3. The method according to claim 2, characterized in that The determining, according to the location information of the first vehicle, a target LPIA that can provide a pseudo identity for the first vehicle includes: determining a communication range of the first vehicle according to the location information and the communication capability of the first vehicle; A candidate LPIA that falls within the communication range of the first vehicle is determined as a target LPIA that can provide a pseudo identity for the first vehicle.
4. The method according to claim 2, characterized in that: The driving environment information includes vehicle density information and roadside unit RSU presence in the target area; Among them, the target area is located within the communication range of the first vehicle; the vehicle density information of the target area is determined by the total number of vehicles in the target area and the area of the target area; the vehicles in the target area include the first vehicle and other vehicles.
5. The method according to claim 4, characterized in that The determining, based on the vehicle speed information and the driving environment information of the first vehicle, a second vehicle that can provide a pseudo identity for the first vehicle comprises: If the RSU existence condition indicates that there is no RSU in the target area, selecting a second vehicle that can provide a pseudo identity for the first vehicle from the other vehicles according to the vehicle density information of the target area and the vehicle pseudo identities of other vehicles in the target area; If the RSU existence situation indicates that there is an RSU in the target area, a second vehicle that can provide a pseudo identity for the first vehicle is selected from the other vehicles based on the vehicle speed information of the first vehicle, the vehicle density information of the target area and the vehicle pseudo identities of other vehicles in the target area.
6. The method according to claim 5, characterized in that The selecting, from the other vehicles according to the vehicle density information of the target area and the vehicle pseudo identities of other vehicles in the target area, a second vehicle capable of providing a pseudo identity for the first vehicle comprises: When the vehicle density information is greater than a density threshold, selecting a vehicle that initiates a vehicle pseudo-identity sharing request from other vehicles in the target area as an inviting vehicle, and selecting a second vehicle that can provide a pseudo-identity for the first vehicle from the inviting vehicles according to the vehicle pseudo-identity of the inviting vehicle; When the vehicle density information is less than or equal to the density threshold, a collaboration request is initiated to other vehicles in the target area, and the vehicles among the other vehicles that participate in the collaboration based on the collaboration request are regarded as collaborative vehicles, and based on the vehicle pseudo-identity of the collaborative vehicle, a second vehicle that can provide a pseudo-identity for the first vehicle is selected from the collaborative vehicles.
7. The method according to claim 6, characterized in that The selecting, according to the vehicle pseudo-identity of the cooperating vehicle, a second vehicle capable of providing a pseudo-identity for the first vehicle comprises: Determine the pseudo-identity cracking probability corresponding to the vehicle pseudo-identity of each cooperating vehicle; wherein the pseudo-identity cracking probability corresponding to the vehicle pseudo-identity of each cooperating vehicle is the probability of successful cracking when the current vehicle pseudo-identity of the first vehicle is replaced with the vehicle pseudo-identity corresponding to the cooperating vehicle; The cooperative vehicle corresponding to the smallest probability of cracking the pseudo-identity is used as the second vehicle that can provide a pseudo-identity for the first vehicle.
8. The method according to claim 5, characterized in that The selecting, from the other vehicles, a second vehicle capable of providing a pseudo identity for the first vehicle according to the vehicle speed information of the first vehicle, the vehicle density information of the target area, and the vehicle pseudo identities of other vehicles in the target area, comprises: When the vehicle density information and the vehicle speed information meet the vehicle teaming condition, control the RSU to initiate a teaming request to other vehicles in the target area, and use the vehicles that participate in the teaming based on the teaming request as teaming vehicles, and select a second vehicle that can provide a pseudo identity for the first vehicle from the teaming vehicles according to the vehicle pseudo identities of the teaming vehicles; The vehicle platooning condition includes that the vehicle density information is greater than a density threshold; or, the vehicle platooning condition includes that the vehicle density information is less than or equal to the density threshold, and the vehicle speed information is less than a speed threshold.
9. The method according to claim 8, characterized in that The selecting, from the platoon vehicles, a second vehicle capable of providing a pseudo identity for the first vehicle according to the vehicle pseudo identities of the platoon vehicles, comprises: Determining a pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle; wherein the pseudo-identity confusion degree corresponding to the vehicle pseudo-identity of each platoon vehicle is used to characterize the difficulty of successfully cracking when the current vehicle pseudo-identity of the first vehicle is replaced with the vehicle pseudo-identity of the platoon vehicle; The team vehicle corresponding to the maximum pseudo-identity confusion degree is used as the second vehicle that can provide a pseudo-identity for the first vehicle.
10. The method according to claim 2, characterized in that If the target issuer is a target LPIA, the step of controlling the target issuer to provide the first vehicle with a target vehicle pseudo identity includes: Initiating the pseudo-identity allocation demand to a central issuing authority CA, so that the CA sends the pseudo-identity allocation demand to the target LPIA; wherein the pseudo-identity allocation demand includes the real vehicle identity of the first vehicle; Receive the target vehicle pseudo identity of the first vehicle fed back by the CA; wherein the target vehicle pseudo identity is generated by the target LPIA according to the real vehicle identity of the first vehicle; The target vehicle pseudo-identity is sent to the first vehicle by the CA after verifying the validity of the target LPIA according to the sending timestamp, and the sending timestamp is carried by the target LPIA when sending the target vehicle pseudo-identity to the CA.