Message retransmission improper behavior detection

By comparing the first message with its corresponding aspects of the resend message in the computing device, identifying and responding to resend improper behavior in wireless communication, the problem of message resend attack in wireless communication is solved, and the security and reliability of the system are improved.

CN120077597APending Publication Date: 2025-05-30QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380074091.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-25
Filing Date
2023-10-17
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Retransmission of messages in wireless communications may be attacked, causing the receiving device to receive conflicts or false information, affecting the security and reliability of the communication system, especially in communication systems of intelligent transportation systems or autonomous vehicles.

Method used

Some aspects of the first message are compared by the computing device with the corresponding aspects of the second message claimed to be resented by the first message, and the resent misconduct in the second message is identified and corresponding actions are taken, such as generating a report of misconduct.

Benefits of technology

Effectively identify and respond to improper behaviors in message retransmission, improve the security and reliability of the communication system, prevent false information from spreading in the system, and protect human security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120077597A_ABST
    Figure CN120077597A_ABST
Patent Text Reader

Abstract

Various embodiments include methods and systems for performing improper behavior detection in message retransmission. In various embodiments, a computing device may compare a first aspect of a first message to a second aspect of a second message that is claimed to be a retransmission of the first message, identify an improper retransmission behavior in the second message based on the comparison, and take an action in response to identifying the improper retransmission behavior in the second message.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related Applications

[0002] This application claims the benefit of priority to U.S. Non - Provisional Application No. 18 / 049,400, filed on October 25, 2022, the entire content of which is incorporated herein by reference. Background Art

[0003] Message retransmission of wireless communication packets enables accurate communication of information in environments where such wireless signals may be lost, corrupted, or not fully received. In some implementations, a sending device may send an information packet two, three, or more times so that a receiving device can receive the information. Even if parts of the information are lost during transmission, multiple copies of the received information can enable the receiving device to reconstruct or otherwise recover the transmitted information.

[0004] However, the retransmission of wireless message packets can be attacked. For example, a malicious actor can send a message claiming to be a retransmission of another device's information, but which is actually different from the original message. In this way, an attacker attempts to introduce conflicting information into the communication system, which can hinder or disrupt the operation of the communication system. In some cases, in communication systems such as intelligent transportation systems or autonomous or semi - autonomous vehicles, the propagation of false information among receiving devices can pose a threat to human safety. Summary of the Invention

[0005] Aspects include methods for detecting misbehavior in message retransmission that can be performed by a computing device. In some aspects, the computing device can compare a first aspect of a first message with a second aspect of a second message that claims to be a retransmission of the first message, can identify misbehavior in the retransmission of the second message based on the comparison, and can take an action in response to identifying the misbehavior in the retransmission of the second message.

[0006] In some aspects, comparing the first aspect of the first message with the second aspect of the second message can include: comparing a first computing resource consumed by the first message with a second computing resource consumed by the second message. Some aspects can include: in response to determining that the computing resources consumed by the first message and the computing resources consumed by the second message are the same, comparing the first message content of the first message with the second message content of the second message. In such aspects, identifying misbehavior in the retransmission of the second message based on the comparison can include: in response to determining that the first message content of the first message and the second message content of the second message are different, identifying misbehavior in the retransmission of the second message.

[0007] In some aspects, comparing a first aspect of a first message with a second aspect of a second message may include comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second message. In some aspects, comparing a first aspect of a first message with a second aspect of a second message may include comparing one or more layer 1 or layer 2 decoding metrics of the first message with one or more layer 1 or layer 2 decoding metrics of the second message. In some aspects, comparing a first aspect of a first message and a second aspect of a second message may include comparing a first combination of the first message and a third message claimed to be a retransmission of the first message with a second combination of the second message and the third message.

[0008] In some aspects, comparing a first aspect of a first message with a second aspect of a second message may include comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second message, and selecting the first message or the second message for combination with a third message claimed to be a retransmission of the first message based on the comparison of the one or more first decoding metrics of the first message with the one or more second decoding metrics of the second message. In such aspects, identifying a retransmission misbehavior in the second message based on the comparison may include identifying a retransmission behavior in the first message or the second message that was not selected based on the comparison of the one or more first decoding metrics of the first message with the one or more second decoding metrics of the second message. In some aspects, the computing device may include a vehicle-to-everything (V2X) processing system.

[0009] Additional aspects include a computing device that includes a memory and a processor, the processor being configured to perform the operations of any of the methods outlined above. Additional aspects may include a computing device having various components for performing functions corresponding to any of the methods outlined above. Additional aspects may include a non-transitory processor-readable storage medium having processor-executable instructions stored thereon, the processor-executable instructions being configured to cause a processor of the computing device to perform various operations corresponding to any of the methods outlined above. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The drawings incorporated herein and constituting a part of this specification illustrate exemplary embodiments of the claims and, together with the general description given above and the detailed description given below, serve to explain the features herein.

[0011] Figure 1A is a system block diagram showing an example communication system suitable for implementing various embodiments.

[0012] Figure 1Bis a system block diagram showing an example disaggregated base station architecture suitable for implementing various embodiments.

[0013] Figure 1C is a system block diagram showing a communication system suitable for implementing various embodiments.

[0014] Figure 2 is a component diagram of an exemplary vehicle V2X processing system suitable for implementing various embodiments.

[0015] Figure 3A is a block diagram showing components of a system-on-chip for use in a vehicle V2X processing system according to various embodiments.

[0016] Figure 3B is a component block diagram showing elements of a vehicle V2X processing system configured according to various embodiments.

[0017] Figure 4A and Figure 4B is a conceptual diagram of an example replay attack in a message replay scenario.

[0018] Figure 5A is a process flow diagram of an example method for detecting misbehavior in message replay executed by a processor of a computing device.

[0019] Figures 5B to 5E is a process flow diagram of an example operation and can be executed by a processor of a computing device as part of a method for detecting misbehavior in message replay.

[0020] Figure 6 is a component block diagram of a computing device suitable for use with various embodiments. Detailed Description

[0021] Various embodiments will be described in detail with reference to the accompanying drawings. Where possible, the same reference numerals will be used throughout the drawings to refer to the same or like parts. References to specific examples and implementations are for illustrative purposes and are not intended to limit the scope of the claims.

[0022] Various embodiments include methods for detecting misbehavior (“replay misbehavior”) of a claim in a message that is a retransmission of an earlier message and computing devices implementing such methods. In various embodiments, a computing device may include one or more processors and / or other components configured to perform operations for detecting replay misbehavior. In various embodiments, the computing device may compare a first aspect of a first message with a second aspect of a second message that claims to be a retransmission of the first message. Based on the comparison, the computing device may identify misbehavior in the second message that incorrectly claims to be a retransmission of the first message. In response to identifying replay misbehavior in the second message, the computing device may take an action, such as sending a misbehavior report. In some embodiments, the computing device may be implemented in a vehicle-to-everything (V2X) processing system of a vehicle. In some embodiments, the computing device may be implemented in a network element of a V2X system, such as a roadside unit (RSU), an edge computing device, or another suitable network element.

[0023] As used herein, the term “vehicle” generally refers to any one of an automobile, a motorcycle, a truck, a bus, a train, a ship, and any other type of vehicle system with V2X capabilities that can be configured to manage the sending of misbehavior reports.

[0024] The term “system-on-a-chip” (SOC) is used herein to refer to a single integrated circuit (IC) chip that includes multiple resources and / or processors integrated on a single substrate. A single SOC may include circuitry for digital, analog, mixed-signal, and radio frequency functions. A single SOC may also include any number of general-purpose and / or dedicated processors (such as digital signal processors, modem processors, video processors, etc.), memory blocks (such as ROM, RAM, flash memory, etc.), and resources (such as timers, voltage regulators, oscillators, etc.). The SOC may also include software for controlling the integrated resources and processors and for controlling peripheral devices.

[0025] The term “system-in-package” (SIP) may be used herein to refer to a single module or package that includes multiple resources, computing units, cores, and / or processors on two or more IC chips, substrates, or SoCs. For example, an SIP may include a single substrate with multiple IC chips or semiconductor dies stacked thereon in a vertical configuration. Similarly, an SIP may include one or more multi-chip modules with multiple ICs or semiconductor dies encapsulated into a unified substrate. An SIP may also include multiple independent SOCs coupled together via high-speed communication circuitry and encapsulated in close proximity (such as on a single motherboard or in a single wireless device). The proximity of the SOCs facilitates high-speed communication as well as sharing of memory and resources.

[0026] Message retransmission in a wireless communication system enables accurate communication of information in an environment where the wireless signals carrying the information may be lost, damaged, or not fully received. Various communication systems can implement various retransmission mechanisms. For example, Hybrid Automatic Repeat reQuest (HARQ) has been widely implemented in various communication systems. HARQ can include a combination of Forward Error Correction (FEC) codes along with operations for performing Automatic Repeat reQuest (ARQ) error control and soft combining.

[0027] In a message retransmission operation, a transmitting device can send two copies of a data unit (such as a packet) within a determined packet delay budget time frame. In such an operation, the transmitting device can send each packet with different coding. A receiving device can receive the initial message and the retransmitted message, and use these two messages to determine the information sent by the transmitting device. In some implementations, if the receiving device is unable to decode the initial message, the receiving device can store the initial message (e.g., in a buffer memory) and monitor the second message, which in some implementations can arrive within a specified time (e.g., within 15 milliseconds) after the first message. The receiving device can combine the initial message and the retransmitted message and attempt to decode the combined message. If the receiving device can decode the initial message, the receiving device does not need to monitor the retransmitted message.

[0028] Retransmission mechanisms can be subject to various attacks. In a first type of attack, an attacker can attempt to send messages such that the receiving device receives different or conflicting information (e.g., describing the same environment or a shared environment). This type of attack can be particularly harmful in a V2X system. For example, an attacker can send an initial message (msg1) that includes a set of information, and then send a purported retransmission (msg1') that includes another set of information different from the information in the initial message. This second message sent by the attacker is sometimes referred to herein as an "attack message". A first receiving device that correctly receives the initial message msg1 can ignore the purported retransmission (attack message) msg1', and thus is not notified of the conflicting information in the attack message. However, a second receiving device that has not decoded the initial message msg1 will monitor the retransmitted message and can then receive the attack message msg1'. If this occurs, the first receiving device and the second receiving device will receive different information in messages that are purported to have the same content. Even worse, in some systems (such as Incremental Redundancy (IR) HARQ), the attacker can send the purported retransmission (attack message) msg1' with a high enough signal strength such that the second receiving device can fully decode the purported retransmission msg1' without referring to the stored version of the initial message msg1, which may have been partially decoded (i.e., the stored version of msg1 is partial, incomplete, or garbled).

[0029] In a second type of attack, an attacker can receive an initial message msg1 from a sending device and then send a purported retransmission (attack message) msg1' that includes different or conflicting information. The attacker can send the attack message with a higher transmit power than a legitimate retransmission from the legitimate sending device. A receiving device that correctly receives the initial message msg1 can ignore the purported retransmission msg1'. However, a receiving device that monitors retransmissions can receive and decode the attack message msg1' instead of the legitimate retransmission. In some attacks, the attack message msg1' can be encoded with the same or different decoding parameters (such as different redundancy versions (RVs), modulation and coding schemes (MCSs), etc.). In some embodiments, depending on specific transport block parameters, such as packet size, code rate, or MCS, a HARQ retransmission (e.g., the attack message msg1') can be decodable without reference to another message (such as the initial message msg1).

[0030] In the context of V2X communication, either type of retransmission attack can cause a first receiving vehicle and a second receiving vehicle to have different information about another vehicle (e.g., the sending vehicle), such as its location, behavior, movement, kinematic state, proposed or expected maneuvers, etc. Given that V2X communication conveys information between vehicles and intelligent highway systems for safer operation, an attacker who injects conflicting messages in this way can affect highway and vehicle safety. Thus, methods for detecting retransmission attacks and retransmission misbehavior can provide a security advantage.

[0031] Various embodiments include methods for detecting retransmission misbehavior in wireless communication and computing devices that implement such methods. In some embodiments, a computing device can compare a first aspect of a first message with a second aspect of a second message that purports to be a retransmission of the first message, identify retransmission misbehavior in the second message based on the comparison, and take an action in response to identifying the retransmission misbehavior in the second message. As used herein, according to various embodiments, the terms "first message" and "second message" each include a complete message, a partial message, a part of a message, an incomplete message, a damaged message, a corrupted message, and other suitable messages. In some embodiments, a computing device can receive a first message and a second message that purports to be a retransmission of the first message and can perform one or more operations to determine whether the first message and the second message are consistent.

[0032] In some embodiments, a computing device may compare a first computing resource consumed by a first message with a second computing resource consumed by a second message. For example, a receiving device may determine the processing resources consumed, the memory resources consumed, the amount of time consumed, and other suitable resources that may be consumed in receiving and / or attempting to decode the first message and / or the second message. In some embodiments, in response to determining that different computing resources are consumed by receiving and decoding the first message and the second message, the computing device may identify a retransmission misbehavior in the second message.

[0033] In some embodiments, in response to determining that similar or identical computing resources are consumed by receiving and decoding the first message and the second message, the computing device may compare a first message content of the first message with a second message content of the second message. In response to determining that the first message content and the second message content are not the same, the computing device may identify a retransmission misbehavior in the second message. In various embodiments, in response to identifying a retransmission misbehavior in the second message, the computing device may take actions such as ignoring the information, treating one or both of the messages as suspicious, reporting the misbehavior in the message to another party, etc. For example, the computing device may generate a misbehavior report detailing the detected retransmission misbehavior and send the misbehavior report to a misbehavior management agency and / or other network entities. In some embodiments, the computing device may include an example of the identified misbehavior with the misbehavior report or include it in the misbehavior report as evidence of the identified misbehavior.

[0034] In some embodiments, the computing device may compare a first digital signature associated with the first message with a second digital signature associated with the second message. In some embodiments, a security layer of the computing device may compare the digital signatures. In the case of a retransmission attack, the computing device may determine that the digital signature associated with the first message is different from the second digital signature associated with the second message. In some embodiments, the computing device may identify a retransmission misbehavior in the second message in response to determining that the digital signatures are different.

[0035] In some embodiments, the computing device may compare one or more first decoding metrics of the first message with one or more second decoding metrics of the second message. Comparing the decoding metrics of the first message and the second message can be used to identify retransmission behavior when the first message or the second message is not fully decoded. For example, a sending device may send a first message, but the receiving device may not be able to decode the first message. In response to a retransmission request, the sending device may retransmit the first message, but an attacker may interfere (e.g., block) the channel by sending an attack message in a subframe of the sending device, for example. The receiving device may receive the attack message and may not be able to decode the attack message or combine the first message and the attack message to correctly decode the first message.

[0036] In some embodiments, a computing device may compare decoding metrics to determine an inconsistency in decoding metrics (or decoding parameters) between a first message and a second message. In some embodiments, the decoding metrics (or decoding parameters) may include signal characteristics determined by the computing device when decoding a message. Examples of decoding metrics include demodulation reference signals (DMRS), signal-to-noise ratio (SNR), symbol error rate (SER), determined signal quality (e.g., channel log-likelihood ratio (LLR) magnitude), carrier frequency offset (CFO), and / or symbol timing offset (STO). Another example of a decoding metric includes scheduling parameters, such as whether the first message and the second message are received at the time at which they are expected (e.g., scheduled), at a time at which they are not expected (e.g., not scheduled), in an indicated or scheduled time slot, in a time slot other than the indicated or scheduled time slot, etc. In some embodiments, the decoding metrics compared by the computing device may include layer 1 decoding metrics. In some embodiments, the decoding metrics compared by the computing device may include layer 1 and / or layer 2 decoding metrics or decoding parameters. The terms "layer 1" and "layer 2" refer to the physical layer and the data link layer of the Open Systems Interconnection (OSI) model, respectively. In some embodiments, the computing device may perform operations to compare decoding metrics at layer 2 of the computing device's protocol stack to conserve the computing device's processing resources that may be consumed by passing the first message and / or the second message to higher layers of the protocol stack. In some embodiments, in response to determining that one or more of the first decoding metrics are different from one or more of the second decoding metrics, the computing device may identify a misbehavior in the resending of the second message. In some embodiments, the difference in the decoding metrics may be included in a misbehavior report as evidence of the detected misbehavior.

[0037] In some embodiments, the computing device may compare a first combination of a first message and a third message that purports to be a resend of the first message with a second combination of the second message and the third message. In some embodiments, the computing device may identify a resend in the second message based on a comparison of the two combinations. In some embodiments, the computing device may compare verification information, such as a cyclic redundancy check (CRC), for each of the two combinations. For example, if the second message is an attack message, the CRC of the second combination may fail a verification check, while the CRC of the first combination may pass.

[0038] In a conventional resend mechanism (such as in a decoding cycle implemented in a receiver device's modem), the receiver device may combine an initial message and a purported resend and store only the combined message. To mitigate information corruption that may be caused by such an implementation, in various embodiments, the receiving device may store the first message and the second message separately, without combining the first message and the second message.

[0039] In some embodiments, the receiving device may select one of the first message and the second message for combination with the third message instead of combining the first message with the third message and separately combining the second message with the third message. In some embodiments, the computing device may compare one or more first decoding metrics of the first message and one or more second decoding metrics of the second message and may select the first message or the second message based on the comparison of the (one or more) decoding metrics of the first message and the second message. For example, based on decoding metrics such as CFO, SER, and / or timing between the transmissions of the first message and the second message, the computing device may determine that one of the first message and the second message is more likely to be legitimate, and / or one of the first message and the second message is more likely to be an attack message. In such embodiments, the computing device may select the first message or the second message that is more likely to be legitimate and / or less likely to be an attack message. The computing device may combine the selected message with the third message and attempt to decode the combined message.

[0040] Various embodiments improve the security and efficiency of processing systems and communication systems by enabling computing devices to identify and take appropriate actions in response to detected retransmission misbehavior. Race embodiments improve the security and operation of systems in which such computing devices are deployed by enabling computing devices to reduce or eliminate communication disruptions (including disinformation or misinformation) that an attacker may attempt to inject into the retransmission process.

[0041] Figure 1A FIG. 1 is a system block diagram showing an example communication system 100 suitable for implementing various embodiments. Communication system 100 includes a 5G New Radio (NR) network, an Intelligent Transportation System (ITS) V2X wireless network, and / or any other suitable network, such as a Long-Term Evolution (LTE) network. References to 5G networks and 5G network elements in the following description are for illustrative purposes and are not intended to be limiting.

[0042] Communication system 100 may include a heterogeneous network architecture that includes a core network 140, a plurality of base stations 110, and various mobile devices, including a vehicle 102 equipped with a V2X processing system 104 that includes wireless communication capabilities. The base stations 110 may communicate with the core network 140 over a wired communication link 126. Communication system 100 may also include a roadside unit 112 that supports V2X communication with the vehicle 102 via a V2X wireless communication link 124.

[0043] Base station 110 is a network element that communicates with wireless devices (e.g., the V2X processing system 104 of vehicle 102) via a wireless communication link 122 and can be referred to as Node B, Long-Term Evolution evolved Node B (eNodeB or eNB), access point (AP), radio head, transmit-receive point (TRP), New Radio base station (NR BS), 5G NodeB (NB), next-generation NodeB (gNodeB or gNB), etc. Each base station 110 can provide communication coverage for a specific geographical area or "cell". In 3GPP, the term "cell" can refer to the coverage area of a base station, the base station subsystem serving that coverage area, or a combination thereof, depending on the context in which the term is used. The core network 140 can be any type of core network, such as an LTE core network (e.g., evolved packet core (EPC) network), a 5G core network, a disaggregated network as described in reference Figure 1B such as the disaggregated network described.

[0044] The roadside unit 112 can communicate with the core network 140 via a wired or wireless communication link 128. The roadside unit 112 can communicate with vehicle 102 equipped with a V2X processing system via a V2X wireless communication link 124 to download information useful for the autonomous and semi-autonomous driving functions of the V2X processing system and to receive information such as misbehavior reports from the V2X processing system 104.

[0045] The misbehavior authority network computing device (MA) 132 can communicate with the core network 140 via a wired or wireless communication link 127. The MA 132 can receive misbehavior reports as may be sent from time to time by the V2X processing system 104 from the V2X processing system 104.

[0046] The wireless communication link 122 can include multiple carrier signals, frequencies, or frequency bands, each of which can include multiple logical channels. The wireless communication links 122 and 124 can utilize one or more radio access technologies (RATs). Examples of RATs that can be used in a wireless communication link include 3GPP LTE, 3G, 4G, 5G (e.g., NR), GSM, code division multiple access (CDMA), wideband code division multiple access (WCDMA), Worldwide Interoperability for Microwave Access (WiMAX), time division multiple access (TDMA), and other mobile phone communication technology cellular RATs. Further examples of RATs that can be used in one or more of the various wireless communication links within the communication system 100 include medium-range protocols (such as Wi-Fi, LTE-U, LTE-Direct, LAA, MuLTEfire) and relatively short-range RATs (such as ZigBee, Bluetooth, and Bluetooth Low Energy (LE)).

[0047] Figure 1Bis a system block diagram showing an example disaggregated base station 160 architecture that can be part of a V2X and / or 5G network (e.g., communication system 100). Referring to Figure 1A and Figure 1B , the disaggregated base station 160 architecture can include one or more central units (CUs) 162, which can communicate directly with the core network 180 via a backhaul link, or indirectly with the core network 180 through one or more disaggregated base station units, such as a near-real-time (near-RT) RAN intelligent controller (RIC) 164 via an E2 link, or a non-real-time (non-RT) RIC 168 associated with a service management and orchestration (SMO) framework 166, or both. The CU 162 can communicate with one or more distributed units (DUs) 170 via a respective midhaul link (e.g., F1 interface). The DU 170 can communicate with one or more radio units (RUs) 172 via a respective fronthaul link. The RU 172 can communicate with a respective UE 120 via one or more radio frequency (RF) access links. In some implementations, a user equipment (UE), such as the V2X processing system 104, can be served simultaneously by multiple RUs 172.

[0048] Each of the units (i.e., CU 162, DU 170, RU 172) and the near-RT RIC 164, non-RT RIC 168, and SMO framework 166 can include one or more interfaces or be coupled to one or more interfaces that are configured to receive or transmit signals, data, or information (collectively referred to as signals) via a wired or wireless transmission medium. Each of the units or the associated processor or controller that provides instructions to the communication interfaces of the units can be configured to communicate with one or more of the other units via the transmission medium. For example, a unit can include a wired interface that is configured to receive signals or transmit signals to one or more of the other units via a wired transmission medium. Additionally, a unit can include a wireless interface that can include a receiver, transmitter, or transceiver (e.g., a radio frequency (RF) transceiver) that is configured to receive or transmit signals or both to one or more of the other units via a wireless transmission medium.

[0049] In some aspects, the CU 162 may host one or more higher layer control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Service Data Adaptation Protocol (SDAP), etc. Each control function may be implemented with an interface configured to communicate signals with other control functions hosted by the CU 162. The CU 162 may be configured to handle User Plane functions (i.e., Central Unit - User Plane (CU-UP)), Control Plane functions (i.e., Central Unit - Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU 162 may be logically divided into one or more CU-UP units and one or more CU-CP units. The CU-UP units may communicate bidirectionally with the CU-CP units via an interface, such as via an E1 interface when implemented in an O-RAN configuration. The CU 162 may be implemented to communicate with the DU 170 as needed for network control and signaling.

[0050] The DU 170 may correspond to a logical unit that includes one or more base station functions to control the operation of one or more RUs 172. In some aspects, the DU 170 may host one or more of the Radio Link Control (RLC) layer, the Medium Access Control (MAC) layer, and one or more high Physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation and demodulation, etc.), at least partially depending on the functional split, such as those defined by the 3rd Generation Partnership Project (3GPP). In some aspects, the DU 170 may also host one or more low PHY layers. Each layer (or module) may be implemented with an interface configured to communicate signals with other layers (and modules) hosted by the DU 170, or with control functions hosted by the CU 162.

[0051] The lower layer functions may be implemented by one or more RUs 172. In some deployments, the RUs 172 controlled by the DU 170 may correspond to logical nodes that host RF processing functions or low PHY layer functions (e.g., performing Fast Fourier Transform (FFT), inverse FFT (iFFT), digital beamforming, Physical Random Access Channel (PRACH) extraction and filtering, etc.) or both, at least partially based on a functional split (e.g., a lower layer functional split). In such an architecture, the RUs 172 may be implemented to handle over-the-air (OTA) communication with one or more UEs 120. In some implementations, the real-time and non-real-time aspects of the control and user plane communication with the RUs 172 may be controlled by the corresponding DU 170. In some scenarios, this configuration may enable the DU 170 and the CU 162 to be implemented in a cloud-based Radio Access Network (RAN) architecture, such as a vRAN architecture.

[0052] The SMO framework 166 can be configured to support the RAN deployment and provisioning of non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 166 can be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via an operation and maintenance interface (such as the O1 interface). For virtualized network elements, the SMO framework 166 can be configured to interact with a cloud computing platform (such as the Open Cloud (O-Cloud) 176) to perform network element lifecycle management (such as to instantiate a virtualized network element) via a cloud computing platform interface (such as the O2 interface). Such virtualized network elements can include, but are not limited to, the CU 162, DU 170, RU 172, and the near-RT RIC 164. In some implementations, the SMO framework 166 can communicate with the hardware aspects of the 4G RAN (such as the Open eNB (O-eNB) 174) via the O1 interface. Additionally, in some implementations, the SMO framework 166 can communicate directly with one or more RUs 172 via the O1 interface. The SMO framework 166 can also include a non-RT RIC 168 configured to support the functions of the SMO framework 166.

[0053] The non-RT RIC 168 can be configured to include logical functions for implementing non-real-time control and optimization of RAN elements and resources, artificial intelligence / machine learning (AI / ML) workflows including model training and updates, or policy-based guidance of applications / features in the near-RT RIC 164. The non-RT RIC 168 can be coupled to or communicate with the near-RT RIC 164 (such as via the A1 interface). The near-RT RIC 164 can be configured to include logical functions enabling the near-real-time control and optimization of RAN elements and resources through data collection and actions on an interface (such as via the E2 interface) connecting one or more CUs 162, one or more DUs 170, or both, and the O-eNB to the near-RT RIC 164.

[0054] In some implementations, to generate the AI / ML models to be deployed in the near-RT RIC 164, the non-RT RIC 168 can receive parameters or external enrichment information from an external server. Such information can be utilized by the near-RT RIC 164 and can be received from non-network data sources or from network functions at the SMO framework 166 or at the non-RT RIC 168. In some examples, the non-RT RIC 168 or the near-RT RIC 164 can be configured to tune the RAN behavior or performance. For example, the non-RT RIC 168 can monitor the long-term trends and patterns of performance and employ an AI / ML model to perform corrective actions via the SMO framework 166 (such as reconfiguration via O1) or via the creation of RAN management policies (such as A1 policies).

[0055] Figure 1C is a system block diagram showing a communication system 103 suitable for implementing various embodiments. Referring Figures 1A to 1C , the communication system 103 can include three vehicles 12, 14, 16. Each vehicle 12, 14, 16 can respectively include a V2X processing system 104, 106, 108, and each V2X processing system is configured to periodically broadcast V2X messages 30, 40, 50, such as BSM, CAM, MCM, MAP, SRM, and other types of V2X messages, for the V2X processing systems of other vehicles (e.g., 104, 106, 108) to receive and process.

[0056] By sharing vehicle position, speed, direction, braking, and other information, vehicles can maintain a safe distance and identify and avoid potential collisions. For example, a trailing vehicle 12 that receives the V2X message 40 from a leading vehicle 16 can determine the speed and position of the vehicle 16, which in turn enables the vehicle 12 to match that speed and maintain a safe distance 20.

[0057] By being informed via the V2X message 40 when the leading vehicle 16 applies the brakes, the V2X processing system 102 in the trailing vehicle 12 can simultaneously apply the brakes to maintain the safe distance 20 even when the leading vehicle 16 suddenly stops. As another example, the V2X processing system 104 within the truck vehicle 14 can receive the V2X messages 30, 50 from two vehicles 12, 16 and is thus informed that the truck vehicle 14 should stop at the intersection to avoid a collision.

[0058] Each of the vehicle V2X on-board devices 104, 106, 108 can communicate with each other using any one of various short-range communication protocols. In addition, the vehicle may be able to send data and information about detected V2X messages, as well as misbehavior reports about detected V2X misbehavior, to the original equipment manufacturer (OEM) (70, 72) and / or MA 74 (e.g., 132) via communication links 60, 61, 62 through communication network 18. The misbehavior report can be sent directly to MA 74 (e.g., via communication links 64, 66).

[0059] In some embodiments, the misbehavior report can first be sent to a misbehavior report preprocessing unit (e.g., OEM servers 70, 72) via communication links 64, 66 for preprocessing. Then, the preprocessed misbehavior report can be sent from the misbehavior report preprocessing servers 70, 72 to MA 74 via communication links 64, 66.

[0060] In some embodiments, a misbehavior report can be received at MA 74 from a vehicle (such as from vehicle 16). MA74 can relay the misbehavior report received from vehicle 16 to OEM servers 70, 72 via communication links 64, 66. In addition, OEM servers 70, 72 can provide an acknowledgment report to MA 74 via communication links 64, 66.

[0061] Figure 2 is a component diagram of an exemplary vehicle V2X processing system 200 suitable for implementing various embodiments. Refer to Figures 1A to 2 , the processing system 200 may include a vehicle 102, and the vehicle 102 includes a V2X processing system 104. The vehicle V2X processing system 104 can communicate with various systems and devices, such as in-vehicle network 210, infotainment system 212, various sensors 214, various actuators 216, and a radio module 218 coupled to an antenna 219. The vehicle V2X processing system 104 can also communicate with a roadside unit 112, a cellular communication network base station 110, and other external devices.

[0062] The V2X processing system 104 may include a processor 205, a memory 206, an input module 207, an output module 208, and a radio module 218. The processor 205 may be coupled to the memory 206 (i.e., a non-transitory storage medium), and may be configured with processor-executable instructions stored in the memory 206 to perform operations of methods according to various embodiments described herein. In addition, the processor 205 may be coupled to an output module 208 that can control an in-vehicle display, and coupled to the input module 207 to receive information from vehicle sensors and driver input.

[0063] The V2X processing system 104 may include a V2X antenna 219, which is coupled to a radio module 218 configured to communicate with one or more ITS participants (e.g., stations), roadside units 112, and base stations 110 or another suitable network access point. The V2X antenna 219 and the radio module 218 may be configured to receive dynamic traffic flow characteristic information via vehicle-to-everything (V2X) communication. In various embodiments, the V2X processing system may receive information from multiple information sources such as in-vehicle network 210, infotainment system 212, various sensors 214, various actuators 216, and radio module 218. The V2X processing system may be configured to perform autonomous or semi-autonomous driving functions using map data in addition to sensor data, as further described below.

[0064] Examples of in-vehicle network 210 include Controller Area Network (CAN), Local Interconnect Network (LIN), networks using the FlexRay protocol, Media Oriented Systems Transport (MOST) network, and Automotive Ethernet network. Examples of vehicle sensors 214 include position determination systems such as Global Navigation Satellite System (GNSS) systems, cameras, radar, lidar, ultrasonic sensors, infrared sensors, and other suitable sensor devices and systems. Examples of vehicle actuators 216 include various physical control systems such as those for steering, braking, engine operation, lights, turn signals, etc.

[0065] Figure 3A is a block diagram showing example components of a system-on-chip (SOC) 300 for use in a vehicle V2X processing system. Referring Figures 1A to 3A , the processing device SOC 300 may include several heterogeneous processors such as a Digital Signal Processor (DSP) 303, a modem processor 304, an image and object recognition processor 306, a mobile display processor 307, an application processor 308, and a Resource and Power Management (RPM) processor 317. The processing device SOC 300 may also include one or more coprocessors 310 (e.g., vector coprocessors) connected to one or more of the heterogeneous processors 303, 304, 306, 307, 308, 317.

[0066] Each of the processors may include one or more cores and independent / internal clocks. Each processor / core may perform operations independently of other processors / cores. For example, the processing device SOC 300 may include a processor that executes a first type of operating system (e.g., FreeBSD, LINUX, OS X, etc.) and a processor that executes a second type of operating system (e.g., Microsoft Windows). In some embodiments, the application processor 308 may be the main processor, central processing unit (CPU), microprocessor unit (MPU), arithmetic logic unit (ALU), etc. of the SOC 300. The graphics processor 306 may be a graphics processing unit (GPU).

[0067] The processing device SOC 300 may include analog circuits and custom circuits 314 for managing sensor data, analog-to-digital conversion, wireless data transmission, and for performing other specialized operations, such as processing encoded audio and video signals for rendering in a web browser. The processing device SOC 300 may also include system components and resources 316, such as voltage regulators, oscillators, phase-locked loops, peripheral bridges, data controllers, memory controllers, system controllers, access ports, timers, and other similar components for supporting processors and software clients (e.g., web browsers) running on a computing device.

[0068] The processing device SOC 300 also includes dedicated circuits for camera actuation and management (CAM) 305, and CAM 305 includes, provides, controls, and / or manages the operations of one or more cameras (e.g., main camera, webcam, 3D camera, etc.), video display data from camera firmware, image processing, video preprocessing, video front end (VFE), in-line JPEG, high-definition video codec, etc. CAM 305 may be an independent processing unit and / or include an independent or internal clock.

[0069] In some embodiments, the image and object recognition processor 306 may be configured with processor-executable instructions and / or dedicated hardware that is configured to perform image processing and object recognition analysis involved in various embodiments. For example, the image and object recognition processor 306 may be configured to perform operations to process images received from a camera via CAM 305 to identify and / or recognize other vehicles, and otherwise perform the functions of the camera perception layer 224 as described. In some embodiments, the processor 306 may be configured to process radar or lidar data and perform the functions of the radar and / or lidar perception layer 222 as described.

[0070] System components and resources 316, analog and custom circuitry 314, and / or CAM 305 may include circuitry for interfacing with peripheral devices such as cameras, radars, lidars, electronic displays, wireless communication devices, external memory chips, etc. Processors 303, 304, 306, 307, 308 may be interconnected to one or more memory elements 312, system components and resources 316, analog and custom circuitry 314, CAM 305, and RPM processor 317 via an interconnect / bus module 324, which may include a reconfigurable logic gate array and / or implement a bus architecture (e.g., CoreConnect, AMBA, etc.). Communication may be provided by a high - performance on - chip network (NoC) such as an advanced interconnect.

[0071] The processing device SOC 300 may also include an input / output module (not shown) for communicating with resources external to the SOC such as a clock 318 and a voltage regulator 320. Resources external to the SOC (e.g., clock 318, voltage regulator 320) may be shared by two or more of the internal SOC processors / cores (e.g., DSP 303, modem processor 304, graphics processor 306, application processor 308, etc.).

[0072] In some embodiments, the processing device SOC 300 may be included in a control unit (e.g., 140) for a vehicle (e.g., 100). The control unit may include communication links for communicating with a telephone network (e.g., 180), the Internet, and / or a network server (e.g., 184) as described.

[0073] The processing device SOC 300 may also include additional hardware and / or software components suitable for collecting sensor data from sensors, including motion sensors (e.g., accelerometers and gyroscopes of an IMU), user interface elements (e.g., input buttons, touch - screen displays, etc.), microphone arrays, sensors for monitoring physical conditions (e.g., position, orientation, motion, direction, vibration, pressure, etc.), cameras, compasses, GPS receivers, communication circuitry (e.g., Bluetooth®, WLAN, WiFi, etc.), and other well - known components of modern electronic devices.

[0074] Figure 3B is a component block diagram showing elements of a vehicle V2X processing system 104 configured according to various embodiments. Refer to Figures 1A to 3B , the V2X processing system 104 of a vehicle (e.g., 102) may be configured to communicate with a roadside unit 112, a cellular network base station 110, and / or one or more other vehicles 12, 14, 16.

[0075] The vehicle V2X processing system 104 may include one or more processors 205, a memory 206, a radio module 218, and other components. The vehicle processing system 104 may include multiple hardware, software, and / or firmware components that operate together to provide the functions attributed herein to the processor 205.

[0076] The memory 206 may include a non-transitory storage medium that stores information electronically. The electronic storage medium of the memory 206 may include system storage provided integrally (i.e., substantially non-removable) with the vehicle processing system 104, and / or one or both of removable storage removably connected to the vehicle V2X processing system 104 via, for example, a port (e.g., a Universal Serial Bus (USB) port, a FireWire port, etc.) or a drive (e.g., a disk drive, etc.). In various embodiments, the memory 206 may include one or more of a charge-based storage medium (e.g., EEPROM, RAM, etc.), a solid-state storage medium (e.g., a flash drive, etc.), an optically readable storage medium (e.g., an optical disc, etc.), a magnetically readable storage medium (e.g., a magnetic tape, a magnetic hard disk drive, a floppy disk drive, etc.), and / or other electronically readable storage media.

[0077] The memory 206 may include one or more virtual storage resources (e.g., cloud storage, a virtual private network, and / or other virtual storage resources). The memory 206 may store software algorithms, information determined by the processor(s) 205, information received from one or more other vehicles 12, 14, 16, information received from the roadside unit 112, information received from the base station 110, and / or other information that enables the vehicle V2X processing system 104 to function as described herein.

[0078] The processor(s) 205 may include one or more local processors that may be configured to provide information processing capabilities in the vehicle V2X processing system 104. Thus, the processor(s) 205 may include one or more of a digital processor, an analog processor, a digital circuit designed to process information, an analog circuit designed to process information, a state machine, and / or other mechanisms for electronically processing information. Although the processor(s) 205 is shown as a single entity in Figure 3B this is for illustrative purposes only. In some embodiments, the processor(s) 205 may include multiple processing units. These processing units may be physically located within the same device, or the processor(s) 205 may represent the processing functions of multiple devices distributed in the vehicle and operating in cooperation.

[0079] The vehicle V2X processing system 104 can be configured by machine-readable instructions 332, and the machine-readable instructions 332 can include one or more instruction modules. The instruction modules can include computer program modules. In various embodiments, the instruction modules can include one or more of a V2X message receiving module 334, a detector selection module 336, a comparison module 338, a misbehavior detection module 340, a misbehavior reporting module 342, a TX / RX module 344, and / or other modules.

[0080] The V2X message receiving module 334 can be configured to receive V2X messages from another vehicle (e.g., 12, 14, 16).

[0081] The detector selection module 336 can be configured to select a first detector based on a first V2X message type and a second detector based on a second V2X message type. The detector selection module 336 can be configured to select one or more detectors based on the V2X message type in the received V2X messages and / or the V2X messages stored in the memory 206. The detector selection module 336 can be configured to select a first field in the first V2X message and a second field in the second V2X message by identifying fields in the first V2X message and fields in the second V2X message that include similar information.

[0082] The comparison module 338 can be configured to compare a first field in a first V2X message of a first V2X message type with a second field in a second V2X message of a second V2X message type. The first V2X message type and the second V2X message type can be different. The comparison module 338 can be configured to compare a first field in a first V2X message of a first V2X message type with a second field in a second V2X message of a second V2X message type using the selected (e.g., first and second) detectors. In some embodiments, the comparison module 330 can be configured to compare the result of applying the first detector to the information in the first V2X message with the result of applying the second detector to the information in the second V2X message. The comparison module 330 can also be configured to compare time values and location values associated with a first field in a first V2X message of a first V2X message type and a second field in a second V2X message.

[0083] The misbehavior detection module 340 can be configured to identify misbehavior in the first V2X message or the second V2X message based on the comparison of the first V2X message and the second V2X message. The misbehavior detection module 340 can be configured to identify misbehavior in the first V2X message or the second V2X message when the information in the first field is inconsistent with the information in the second field.

[0084] The Misconduct Reporting Module 342 can be configured to take actions in response to identifying misconduct in the first V2X message or the second V2X message. The Misconduct Reporting Module 342 can be configured to generate a misconduct report indicating the identified misconduct. The Misconduct Reporting Module 342 can also be configured to generate a correction to the information in the first field or the second field when a time value and a location value associated with a first field in a first V2X message of the first V2X message type and a second field in the second V2X message are substantially different.

[0085] The TX / RX Module 344 can be configured to control the operation of a communication device (such as the radio module 218) of the vehicle processing system. The TX / RX Module 344 can be configured to send the generated misconduct report indicating the identified misconduct to a network computing device, such as the Misconduct Agency Computing Device 132.

[0086] The processor 207 can be configured to execute Modules 332 - 344 and / or other modules through software, hardware, firmware, some combination of software, hardware, and / or firmware, and / or other mechanisms for configuring processing capabilities on the (one or more) processors 205.

[0087] The descriptions of the functions provided by the different Modules 332 - 344 are for illustrative purposes and are not intended to be restrictive, as any one of the Modules 332 - 344 can provide more or less functionality than described. For example, one or more of the Modules 332 - 344 can be eliminated, and some or all of their functions can be provided by other modules among the Modules 332 - 344. As another example, the (one or more) processors 207 can be configured to execute one or more additional modules, and the one or more additional modules can execute some or all of the functions attributed to one of the Modules 332 - 344 below.

[0088] Figure 4A It is a conceptual diagram that is an example of a first - type replay attack 400 in a message re - transmission scenario. The illustrated replay attack 400 is an example of an attack that attempts to spread inconsistent information among various receiving devices.

[0089] Reference Figures 1A to 4A , at the first time t = 0, the attacker C (the transmitter device) can send a first message (msg1), which indicates that, for example, C's speed is "50 miles per hour" and C's steering heading is "left". The first receiving device (A) may fail to decode the first message msg1, and the second receiving device (B) can successfully decode the first message msg1. Although the first receiving device A fails to decode the first message msg1, the first receiving device A can retain an incomplete, garbled, or partially decoded version of the first message msg1.

[0090] At the second time t = 1, the attacker C can send a second message (msg1'), which claims to be a retransmission of the first message but is actually different from the first message (msg1' ≠ msg1). For example, the second message msg1' can indicate that C's speed is "10 miles per hour" and C's steering heading is "right".

[0091] After the first receiving device A successfully decodes the second message msg1', the first receiving device A and the second receiving device B have different information about C (e.g., different information about C's kinematic state). Some retransmission protocols (such as incremental redundancy HARQ) can permit the attacker C to send the second message msg1' with a high enough transmission power such that the first receiving device A can successfully decode the second message msg1' without referring to the first message msg1 or another message (e.g., the third message).

[0092] Figure 4B It is a conceptual diagram of an example of the second type of retransmission attack 410 in the message retransmission scenario. This retransmission attack 410 is an example of an attack that exploits physical layer masquerading and / or jamming.

[0093] Reference Figures 1A to 4B , at the first time t = 0, the legitimate sending device can send a first message (msg1), which indicates, for example, that C's speed is "50 miles per hour" and C's steering heading is "left". The first receiving device (A) may fail to decode the first message msg1, and the second receiving device (B) can successfully decode the first message.

[0094] In this example of the second type of retransmission attack, the second receiving device B is also the attacker. At the second time t = 1, the legitimate sending device C can send a legitimate retransmission of the first message msg1. However, simultaneously, the attacker B can send a second message msg1', which is an attack message that includes conflicting or incorrect information about the sending vehicle C (e.g., C's speed is "10 mph" and C's heading is "right").

[0095] In some attacks, the attacker B can send the second message msg1' in a way that is configured to block the legitimate retransmission of the sending device C, such as sending the second message msg1' with a higher transmission power, encoding the second message msg1' with the same or different decoding parameters (e.g., RV or MCS), etc. In some cases, depending on certain transport block parameters (e.g., packet size, MCS, code rate, etc.), the receiving device may be able to decode the second message msg1' without referring to the first message msg1 or another message (e.g., the third message).

[0096] To address replay attacks such as Figure 4A and Figure 4B shown in, various embodiments include methods that can be executed by a computing device for detecting misbehavior in a message replay event.

[0097] Figure 5A is a process flow diagram of an example method 500a for detecting misbehavior in message replay executed by a processor of a computing device. Referring to Figures 1A to 5A , method 500a can be executed by one or more processors (e.g., 205, 300) of a computing device that can be implemented in a hardware element, a software element, or a combination of hardware and software elements. Non-limiting examples of computing devices include processors of a V2X processing system or other vehicle processors (e.g., 205, 220, 300), processors of roadside units (e.g., 112), and processors of edge computing devices. To cover any of the processors, hardware elements, and software elements that may be involved in executing method 500, the element or subsystem that executes the method operations is generally referred to as a "processor".

[0098] In block 502, the processor can compare a first aspect of a first message with a second aspect of a second message that purports to be a replay of the first message. For example, a processor of receiving device A can compare some aspects of the first message (such as parts, incomplete, corrupted, garbled, partially decoded, etc. of the first message (e.g., msg1) that are received and temporarily stored in a memory) with similar aspects of a purported replay of the first message that has been received and decoded (i.e., the second message, e.g., msg1').

[0099] In block 504, the processor can identify replay misbehavior in the second message based on the comparison. For example, if the comparison of aspects of the two messages reveals that the two messages are different, such a conflict in the aspects being compared can indicate an attempted replay attack.

[0100] In block 506, the processor may take one or more actions in response to identifying a retransmission misbehavior in the second message. In the context of V2X communication, such one or more actions may be performed to enhance the security of detecting vehicles, other vehicles that may have been affected by an attack, and / or the highway system. For example, the processor may send a misbehavior report to a misbehavior management authority or another suitable network entity as part of the action taken in block 506. As another example of an action that may be taken in block 506, the processor may send a misbehavior report to one or more neighboring computing devices (e.g., another vehicle, a roadside unit, and / or the like) to notify other computing devices of the retransmission misbehavior. In some embodiments, as part of the action taken in block 506, the processor may send a misbehavior report that includes information about the conflict information or the nature of the retransmission attack such that other computing devices (e.g., other vehicles) or the highway system can determine response actions to maintain system safety and / or security.

[0101] Figure 5B is a process flow diagram of an example operation 500b that can be performed by a processor of a computing device as part of a method 500a for detecting misbehavior in message retransmission. Refer to Figures 1A to 5B , operation 500b can be performed by one or more processors (e.g., 205, 300) of a computing device, and the one or more processors can be implemented as hardware elements, software elements, or a combination of hardware and software elements. Non-limiting examples of computing devices include a V2X processing system or other vehicle processors (e.g., 205, 220, 300), a processor of a roadside unit (e.g., 112), and a processor of an edge computing device.

[0102] In block 510, the processor may compare a first computing resource consumed by a first message with a second computing resource consumed by a second message. For example, the processor may determine the processing load of receiving and / or attempting to decode the first message and the second message, such as the resources consumed, the memory resources consumed, the amount of time consumed, and other suitable resources consumed in receiving and decoding the two messages. Then, in block 510, the processor may compare the two determined resource loads.

[0103] In decision block 512, the processor may determine whether the first computing resource consumed by the first message is the same as the second computing resource consumed by the second message.

[0104] In response to determining that the first computing resource consumed by the first message and the second computing resource consumed by the second message are the same (e.g., decision block 512 = "yes"), the processor may compare the first message content of the first message with the second message content of the second message in block 514.

[0105] In determination block 516, the processor may determine whether the first message content and the second message content are the same.

[0106] In response to determining that the first message content and the second message content are the same (i.e., determination block 516 = "yes"), in block 518, the processor may determine that the second message is a legitimate retransmission of the first message.

[0107] In response to determining that the first computing resources consumed by the first message and the second computing resources consumed by the second message are not the same (e.g., determination block 512 = "no"), or in response to determining that the first message content and the second message content are not the same (i.e., determination block 516 = "no"), the processor may identify a retransmission behavior in the second message in block 520 and take an action in block 506 of the described method 500a.

[0108] Figure 5C is a process flow diagram of an example operation 500c that can be performed by a processor of a computing device as part of a method 500a for detecting improper behavior in message retransmission. Refer to Figures 1A to 5C , operation 500c can be performed by one or more processors (e.g., 205, 300) of a computing device, and the one or more processors can be implemented as hardware elements, software elements, or a combination of hardware and software elements. Non-limiting examples of computing devices include a V2X processing system or other vehicle processors (e.g., 205, 220, 300), a processor of a roadside unit (e.g., 112), and a processor of an edge computing device.

[0109] In block 530, the processor may compare one or more first decoding metrics of the first message with one or more second decoding metrics of the second metric. In some embodiments, the processor may compare one or more first decoding metrics of the first message with one or more second decoding metrics of the second metric.

[0110] In determination block 532, the processor may determine whether the first decoding metric and the second decoding metric are the same.

[0111] In response to determining that the first decoding metric and the second decoding metric are the same (i.e., determination block 532 = "yes"), the processor may determine in block 518 that the second message is a legitimate retransmission of the first message.

[0112] In response to determining that the first decoding metric and the second decoding metric are not the same (i.e., determination block 532 = "no"), the processor may identify improper retransmission behavior in the second message in block 520 and take an action in block 506 of the described method 500a.

[0113] Figure 5Dis a process flow diagram of an example operation 500d that can be executed by a processor of a computing device and that is part of method 500a for detecting misbehavior in message retransmission. Refer to Figures 1A to 5D , operation 500d can be executed by one or more processors (e.g., 205, 300) of a computing device, which can be implemented as hardware elements, software elements, or a combination of hardware and software elements. Non-limiting examples of computing devices include a V2X processing system or other vehicle processors (e.g., 205, 220, 300), processors of roadside units (e.g., 112), and processors of edge computing devices.

[0114] In block 540, the processor can combine a first message and a third message that purports to be a retransmission of the first message, and can combine a second message and the third message. For example, the processor can store the first message and the second message separately and not combine the first message and the second message with each other.

[0115] In block 542, the processor can compare a first combination of the first message and the third message with a second combination of the second message and the third message. In some embodiments, the processor can attempt to decode the first combination and the second combination. In some embodiments, the processor can determine whether the decoding of the first combination or the second combination is successful. In some embodiments, the processor can compare the success of the decoding attempts of the first combination and the second combination. In some embodiments, the computing device can compare verification information, such as CRC, for each of the two combinations. For example, if the second message is an attack message, the CRC of the second combination may fail a verification check, while the CRC of the first combination can pass.

[0116] In block 520, the processor can identify misbehavior in the retransmission of the second message based on the comparison. For example, the processor can determine that an attempt to decode a first combination (of the first message and the third message) is successful and an attempt to decode a second combination (of the second message and the third message) is unsuccessful. The processor can identify misbehavior in the retransmission of the second message based on the unsuccessful decoding attempt of the second combination.

[0117] Then, the processor can take an action in block 506 of the described method 500a.

[0118] Figure 5E is a process flow diagram of an example operation 500e that can be executed by a processor of a computing device and that is part of method 500a for detecting misbehavior in message retransmission. Refer to Figures 1A to 5E, operation 500e can be performed by one or more processors (e.g., 205, 300) of a computing device, and the one or more processors can be implemented as hardware elements, software elements, or a combination of hardware and software elements. Non-limiting examples of computing devices include V2X processing systems or other vehicle processors (e.g., 205, 220, 300), processors of roadside units (e.g., 112), and processors of edge computing devices.

[0119] In block 550, the processor can compare one or more first decoding metrics of the first message with one or more second decoding metrics of the second message.

[0120] In block 552, the processor can select the first message or the second message for combination with a third message claimed to be a retransmission of the first message based on the comparison of one or more first decoding metrics of the first message with one or more second decoding metrics of the second message.

[0121] In block 554, the processor can identify retransmission behavior in the first message or the second message that was not selected based on the comparison of one or more first decoding metrics of the first message with one or more second decoding metrics of the second message.

[0122] The processor can take an action in block 506 of the described method 500a.

[0123] Figure 6 is a component block diagram of a network computing device 600 suitable for use with various embodiments. Refer to Figures 1A to 6 , various embodiments (including but not limited to the embodiments described with reference to Figures 1A to 5E ) can be implemented on a variety of computing devices, examples of which are shown in the form of server devices in Figure 6 . The network computing device 600 can include a processor 601 coupled to a volatile memory 602 and a mass non-volatile memory such as a disk drive 603. The network computing device 600 can also include a peripheral memory access device coupled to the processor 601, such as a floppy disk drive, a compact disc (CD) or digital video disc (DVD) drive 606. The network computing device 600 can also include a network access port 604 (or interface) coupled to the processor 601 for establishing a data connection with a network, such as the Internet and / or a local area network coupled to other system computers and servers. The network computing device 600 can include one or more transceivers 605 for transmitting and receiving electromagnetic radiation, and the transceivers 605 can be connected to a wireless communication link. The network computing device 600 can include additional access ports for coupling to peripheral devices, external memories, or other devices, such as USB, Firewire, Thunderbolt, etc.

[0124] The various embodiments shown and described are provided only as examples to illustrate the various features of the claims. However, the features shown and described with respect to any given embodiment are not necessarily limited to the associated embodiment and may be used or combined with other embodiments shown and described. Additionally, the claims are not intended to be limited by any one example embodiment. For example, one or more of the operations of methods and operations 500a - 500e may replace or be combined with one or more of the operations of methods or operations 500a - 500e.

[0125] Examples of implementations are described in the following paragraphs. While some of the following examples of implementations are described with respect to example methods, further example implementations may include: the example methods discussed in the following paragraphs are implemented by a computing device including a processor configured with processor - executable instructions to perform the operations of the methods of the following example implementations; the example methods discussed in the following paragraphs are implemented by a computing device including components for performing the functions of the methods of the following example implementations; and the example methods discussed in the following paragraphs may be implemented as a non - transitory processor - readable storage medium storing processor - executable instructions configured to cause a processor of a computing device to perform the operations of the methods of the following example implementations.

[0126] Example 1. A method performed by a processor of a computing device, comprising: comparing a first aspect of a first message with a second aspect of a second message claimed to be a re - transmission of the first message, identifying a re - transmission misbehavior in the second message based on the comparison, and taking an action in response to identifying the re - transmission misbehavior in the second message.

[0127] Example 2. The method according to Example 1, wherein comparing the first aspect of the first message with the second aspect of the second message comprises: comparing a first computing resource consumed by the first message and a second computing resource consumed by the second message.

[0128] Example 3. The method according to Example 2, further comprising comparing a first message content of the first message with a second message content of the second message in response to determining that the computing resource consumed by the first message and the computing resource consumed by the second message are the same, wherein identifying the re - transmission misbehavior in the second message based on the comparison comprises identifying the re - transmission misbehavior in the second message in response to determining that the first message content of the first message and the second message content of the second message are not the same.

[0129] Example 4. The method according to any one of Examples 1-3, wherein comparing a first aspect of a first message with a second aspect of a second message includes comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second metric.

[0130] Example 5. The method according to any one of Examples 1-4, wherein comparing a first aspect of a first message with a second aspect of a second message includes comparing one or more first layer 1 or layer 2 decoding metrics of the first message with one or more second layer 1 or layer 2 decoding metrics of the second metric.

[0131] Example 6. The method according to any one of Examples 1-5, wherein comparing a first aspect of a first message with a second aspect of a second message includes: comparing a first combination of the first message and a third message claimed to be a retransmission of the first message with a second combination of the second message and the third message.

[0132] Example 7. The method according to any one of Examples 1-6, wherein comparing a first aspect of a first message with a second aspect of a second message includes comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second message, and selecting the first message or the second message for combination with a third message claimed to be a retransmission of the first message based on the comparison of one or more first decoding metrics of the first message with one or more second decoding metrics of the second message, wherein identifying a retransmission misbehavior in the second message based on the comparison includes identifying a retransmission behavior in the first message or the second message that was not selected based on the comparison of one or more first decoding metrics of the first message with one or more second decoding metrics of the second message.

[0133] Example 8. The method according to any one of Examples 1 to 7, wherein the computing device includes a vehicle-to-everything (V2X) processing system.

[0134] The foregoing method descriptions and process flow diagrams are provided only as illustrative examples and are not intended to require or imply that the operations of the various embodiments must be performed in the order presented. As will be understood by those skilled in the art, the order of operations in the foregoing embodiments may be performed in any order. Words such as "thereafter," "then," "next," etc. are not intended to limit the order of operations; these words are merely used to guide the reader through the description of the method. In addition, any reference to a claim element in the singular using the articles "a," "an," or "the" should not be construed as limiting the element to the singular.

[0135] The various illustrative logical blocks, modules, circuits, and algorithmic operations described in connection with the embodiments disclosed herein may be implemented as electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and operations have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the claims.

[0136] Hardware for implementing the various illustrative logics, logical blocks, modules, and circuits described in connection with the embodiments disclosed herein may be implemented or performed using a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Alternatively, some operations or methods may be performed by circuitry that is specific to a given function.

[0137] In one or more embodiments, the described functionality may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functionality may be stored as one or more instructions or code on a non-transitory computer-readable medium or a non-transitory processor-readable medium. Operations of a method or algorithm disclosed herein may be embodied in a processor-executable software module, which may reside on a non-transitory computer-readable or processor-readable storage medium. A non-transitory computer-readable or processor-readable storage medium may be any storage medium accessible by a computer or a processor. By way of example and not limitation, such non-transitory computer-readable or processor-readable media may include RAM, ROM, EEPROM, flash memory, CD-ROM or other optical disk storage, disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code in the form of instructions or data structures and that can be accessed by a computer. As used herein, disk and optical disks include compact disk (CD), laser disk, optical disk, digital versatile disk (DVD), floppy disk, and Blu-ray disk, where disks typically reproduce data magnetically, while optical disks utilize lasers to optically reproduce data. Combinations of the above are also included within the scope of non-transitory computer-readable and processor-readable media. Additionally, operations of a method or algorithm may reside as one or any combination or collection of code and / or instructions on a non-transitory processor-readable medium and / or a computer-readable medium, which may be incorporated into a computer program product.

[0138] The foregoing description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the claims. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the claims. Thus, the disclosure is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the claims and the principles and novel features disclosed herein.

Claims

1. A method executed by a processor of a computing device, comprising: comparing a first aspect of a first message with a second aspect of a second message, the second message purporting to be a retransmission of the first message; identifying a retransmission misbehavior in the second message based on the comparison; and taking an action in response to identifying the retransmission misbehavior in the second message.

2. The method according to claim 1, wherein comparing the first aspect of the first message with the second aspect of the second message comprises: comparing a first computing resource consumed by the first message with a second computing resource consumed by the second message.

3. The method according to claim 2, further comprising: in response to determining that the computing resource consumed by the first message and the computing resource consumed by the second message are the same, comparing a first message content of the first message with a second message content of the second message, wherein identifying the retransmission misbehavior in the second message based on the comparison comprises: identifying the retransmission misbehavior in the second message in response to determining that the first message content of the first message and the second message content of the second message are different.

4. The method according to claim 1, wherein comparing the first aspect of the first message with the second aspect of the second message comprises: comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second message.

5. The method according to claim 1, wherein comparing the first aspect of the first message with the second aspect of the second message comprises: comparing one or more first layer 1 or layer 2 decoding metrics of the first message with one or more second layer 1 or layer 2 decoding metrics of the second message.

6. The method according to claim 1, wherein comparing the first aspect of the first message with the second aspect of the second message comprises: comparing a first combination of the first message and a third message purporting to be a retransmission of the first message with a second combination of the second message and the third message.

7. The method according to claim 1, wherein comparing the first aspect of the first message with the second aspect of the second message comprises: comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second message; and selecting the first message or the second message for combination with a third message purporting to be a retransmission of the first message based on the comparison of the one or more first decoding metrics of the first message with the one or more second decoding metrics of the second message, wherein identifying the retransmission misbehavior in the second message based on the comparison comprises: identifying the retransmission behavior in the first message or the second message that is not selected based on the comparison of the one or more first decoding metrics of the first message with the one or more second decoding metrics of the second message.

8. The method according to claim 1, wherein the computing device includes a vehicle-to-everything (V2X) processing system.

9. A computing device, Comprising: A transceiver; And A processor, coupled to the transceiver and configured to: Compare a first aspect of a first message with a second aspect of a second message, the second message purporting to be a retransmission of the first message; Identify a retransmission misbehavior in the second message based on the comparison; And Take an action in response to identifying the retransmission misbehavior in the second message.

10. The computing device according to claim 9, Wherein, The processor is further configured to compare a first computing resource consumed by the first message with a second computing resource consumed by the second message.

11. The computing device according to claim 10, Wherein, The processor is further configured to: In response to determining that the computing resources consumed by the first message and the computing resources consumed by the second message are the same, compare a first message content of the first message with a second message content of the second message; And In response to determining that the first message content of the first message and the second message content of the second message are different, identify a retransmission misbehavior in the second message.

12. The computing device according to claim 9, Wherein, The processor is further configured to compare one or more first decoding metrics of the first message with one or more second decoding metrics of the second message.

13. The computing device according to claim 9, Wherein, The processor is further configured to compare one or more first layer 1 or layer 2 decoding metrics of the first message with one or more second layer 1 or layer 2 decoding metrics of the second message.

14. The computing device according to claim 9, Wherein, The processor is further configured to compare a first combination of the first message and a third message purporting to be a retransmission of the first message with a second combination of the second message and the third message.

15. The computing device according to claim 9, Wherein, The processor is further configured to: Compare one or more first decoding metrics of the first message with one or more second decoding metrics of the second message; Based on the comparison of one or more first decoding metrics of the first message with one or more second decoding metrics of the second message, select the first message or the second message for combination with a third message purporting to be a retransmission of the first message; And Identify a retransmission behavior in the first message or the second message that is not selected based on the comparison of one or more first decoding metrics of the first message with one or more second decoding metrics of the second message.

16. The computing device according to claim 9, Wherein, The computing device includes a vehicle-to-everything (V2X) processing system.

17. A computing device, Comprising: Components for comparing a first aspect of a first message with a second aspect of a second message, the second message purporting to be a retransmission of the first message; Components for identifying a retransmission misbehavior in the second message based on the comparison; And Components for taking an action in response to identifying the retransmission misbehavior in the second message.

18. The computing device according to claim 17, wherein, the component for comparing a first aspect of a first message with a second aspect of a second message includes: a component for comparing a first computing resource consumed by the first message and a second computing resource consumed by the second message.

19. The computing device according to claim 18, further comprising: a component for comparing a first message content of the first message with a second message content of the second message in response to determining that the computing resource consumed by the first message and the computing resource consumed by the second message are the same, wherein, the component for identifying a retransmission misconduct in the second message based on the comparison includes: a component for identifying a retransmission misconduct in the second message in response to determining that the first message content of the first message and the second message content of the second message are different.

20. The computing device according to claim 17, wherein, the component for comparing a first aspect of a first message with a second aspect of a second message includes: a component for comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second metric.

21. The computing device according to claim 17, wherein, the component for comparing a first aspect of a first message with a second aspect of a second message includes: a component for comparing one or more first layer 1 or layer 2 decoding metrics of the first message with one or more second layer 1 or layer 2 decoding metrics of the second metric.

22. The computing device according to claim 17, wherein, the component for comparing a first aspect of a first message with a second aspect of a second message includes: a component for comparing a first combination of the first message and a third message claimed to be a retransmission of the first message with a second combination of the second message and the third message.

23. The computing device according to claim 17, wherein, the component for comparing a first aspect of a first message with a second aspect of a second message includes: a component for comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second message; and a component for selecting the first message or the second message for combination with a third message claimed to be a retransmission of the first message based on the comparison between one or more first decoding metrics of the first message and one or more second decoding metrics of the second message, wherein, the component for identifying a retransmission misconduct in the second message based on the comparison includes: a component for identifying a retransmission behavior in the first message or the second message that is not selected based on the comparison between one or more first decoding metrics of the first message and one or more second decoding metrics of the second message.

24. The computing device according to claim 17, wherein, the computing device includes a vehicle-to-everything (V2X) processing system.

25. A non-transitory processor-readable medium storing processor-executable instructions, the processor-executable instructions being configured to cause a processing device of a computing device to perform operations, the operations comprising: comparing a first aspect of a first message with a second aspect of a second message, the second message purporting to be a retransmission of the first message; identifying a retransmission misbehavior in the second message based on the comparison; and taking an action in response to identifying the retransmission misbehavior in the second message.

26. The non-transitory processor-readable medium according to claim 25, wherein, the stored processor-executable instructions are further configured to cause the processing device of the computing device to perform operations such that comparing the first aspect of the first message with the second aspect of the second message comprises: comparing a first computing resource consumed by the first message with a second computing resource consumed by the second message.

27. The non-transitory processor-readable medium according to claim 26, wherein, the stored processor-executable instructions are further configured to cause the processing device of the computing device to perform operations including the following: comparing a first message content of the first message with a second message content of the second message in response to determining that the computing resources consumed by the first message and the computing resources consumed by the second message are the same, wherein identifying the retransmission misbehavior in the second message based on the comparison comprises: identifying the retransmission misbehavior in the second message in response to determining that the first message content of the first message and the second message content of the second message are not the same.

28. The non-transitory processor-readable medium according to claim 25, wherein, the stored processor-executable instructions are further configured to cause the processing device of the computing device to perform operations such that comparing the first aspect of the first message with the second aspect of the second message comprises: comparing one or more first decoding metrics of the first message with one or more second decoding metrics of the second metric.

29. The non-transitory processor-readable medium according to claim 25, wherein, the stored processor-executable instructions are further configured to cause the processing device of the computing device to perform operations such that comparing the first aspect of the first message with the second aspect of the second message comprises: comparing one or more first layer 1 or layer 2 decoding metrics of the first message with one or more second layer 1 or layer 2 decoding metrics of the second metric.

30. The non-transitory processor-readable medium according to claim 25, wherein, the stored processor-executable instructions are further configured to cause the processing device of the computing device to perform operations such that comparing the first aspect of the first message with the second aspect of the second message comprises: comparing a first combination of the first message and a third message purporting to be a retransmission of the first message with a second combination of the second message and the third message.