Vehicle communication method and device
By integrating the data to be transmitted, historical vehicle data and external intelligence data to be transferred, and dynamically adjusting the encryption strategy and key parameters, the problem that fixed encryption algorithms in the prior art cannot dynamically adapt to real-time risk changes is solved, and the security protection effect of vehicle communication is improved.
Patent Information
- Application Number
- CN202510282345.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-06-20
AI Technical Summary
Existing vehicle-mounted communication equipment cannot dynamically adapt to real-time risk changes using fixed encryption algorithms, resulting in poor safety protection of vehicle communications.
By obtaining the data to be transmitted, historical vehicle data and external intelligence data, the communication risk score is calculated, and the target communication encryption strategy is determined based on the score and dynamic risk threshold, and the key parameters are adjusted to encrypt the data to be transmitted.
It enhances the accuracy of communication risk scores, identifies the security level of vehicle communication in real time, and improves the security protection effect of vehicle communication by dynamically adjusting encryption policies and key parameters.
Smart Images

Figure CN120185873A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a vehicle communication method and apparatus. Background Art
[0002] Generally, a vehicle communicates with the cloud through an in-vehicle communication device to transmit vehicle-related data. The transmitted vehicle-related data may be subject to network attacks and data tampering. Currently, in order to ensure communication security, a fixed encryption algorithm is generally used for communication encryption between the in-vehicle communication device and the cloud. However, the fixed encryption algorithm cannot dynamically adapt to real-time risk changes and cannot achieve dynamic adaptive adjustment and optimization, resulting in poor vehicle communication security protection effect. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a vehicle communication method and apparatus, which enhance the accuracy of communication risk scoring, identify the vehicle communication security level, and improve the vehicle communication security protection effect.
[0004] To achieve the above object, according to one aspect of the embodiments of the present invention, a vehicle communication method is provided, including:
[0005] Obtaining to-be-transmitted data related to a vehicle;
[0006] Fusing the to-be-transmitted data, historical vehicle data, and external intelligence data, and calculating a communication risk score for the to-be-transmitted data;
[0007] Determining a target communication encryption policy based on the communication risk score and a dynamic risk threshold, and adjusting key parameters based on the communication risk score;
[0008] Encrypting the to-be-transmitted data by using the target communication encryption policy and the adjusted key parameters, and transmitting the encrypted to-be-transmitted data.
[0009] Optionally, the method further includes: respectively assigning corresponding preset weight coefficients to the to-be-transmitted data, the historical vehicle data, and the external intelligence data;
[0010] The calculating the communication risk score for the to-be-transmitted data includes:
[0011] Based on the preset weight coefficients, fusing the data characteristics of the to-be-transmitted data, the historical vehicle data, and the external intelligence data to generate a feature vector;
[0012] Inputting the feature vector into a deep fusion model to obtain a communication risk score, where the deep fusion model is obtained by fusing a deep neural network model and a random forest algorithm.
[0013] Optionally, the above deep fusion model includes a deep neural network layer, a random forest algorithm layer, and a fusion layer;
[0014] The above process of inputting the above feature vectors into the deep fusion model to obtain a communication risk score includes:
[0015] Input the above feature vectors into the above deep neural network layer and the above random forest algorithm layer respectively to obtain a first risk score output by the above deep neural network layer and a second risk score output by the above random forest algorithm layer;
[0016] Based on the above first risk score, the first risk weight coefficient corresponding to the first risk score, the above second risk score, and the second risk weight coefficient corresponding to the second risk score, calculate the communication risk score through the fusion layer.
[0017] Optionally, the above process of determining the target communication encryption policy based on the above communication risk score and the dynamic risk threshold includes:
[0018] In response to the above communication risk score being greater than the above dynamic risk threshold, synthesize the asymmetric encryption algorithm and the symmetric encryption algorithm as the above target communication encryption policy;
[0019] In response to the above communication risk score being less than or equal to the above dynamic risk threshold, use the above symmetric encryption algorithm as the above target communication encryption policy.
[0020] Optionally, the above key parameters include the key length;
[0021] The above process of adjusting the key parameters based on the above communication risk score includes:
[0022] Use the above communication risk score, a preset benchmark risk score, a preset benchmark encryption intensity, and a preset upper limit value of the risk score to calculate the encryption intensity;
[0023] Use a preset minimum key length, a preset maximum key length, the above benchmark risk score, and the above upper limit value of the risk score to calculate the transitional key length;
[0024] Adjust the current key length according to the above encryption intensity and the above transitional key length.
[0025] Optionally, the above method is implemented based on a service system including multiple edge nodes.
[0026] Optionally, the above method further includes:
[0027] Encrypt the above data to be transmitted using the above target communication encryption policy and the adjusted key parameters, and encapsulate the encrypted data to be transmitted into an encryption task;
[0028] Allocate the above encryption task to edge nodes.
[0029] Optionally, allocating the above encryption task to edge nodes includes:
[0030] For each of the above edge nodes, execute steps N1 to N3:
[0031] Step N1, obtain the real-time load data of the above edge node;
[0032] Step N2, determine the computing power of the above edge node based on the above real-time load data;
[0033] Step N3, allocate the above encryption task to the above edge node according to the computing power of the above edge node.
[0034] Optionally, the above method further includes:
[0035] Deploy the step of determining the target communication encryption policy based on the above communication risk score and the dynamic risk threshold and adjusting the key parameters based on the above communication risk score in the smart contract of the blockchain;
[0036] In response to a change in the comparison result between the above communication risk score and the dynamic risk threshold, trigger the smart contract of the above blockchain to cause the smart contract to execute the steps of determining the target communication encryption policy and adjusting the key parameters.
[0037] Optionally, the above method further includes:
[0038] Record the changes in the above target communication encryption policy and the changes in the above key parameters on the blockchain.
[0039] Optionally, the above method further includes:
[0040] Obtain the proportion of the number of times the above communication risk score is greater than the dynamic risk threshold in the preset historical time period to the number of times the communication risk score changes;
[0041] Update the above dynamic risk threshold by using a preset tuning coefficient, the above proportion, and a preset high-risk expected proportion.
[0042] To achieve the above object, according to another aspect of the embodiments of the present invention, there is provided a vehicle communication device, including:
[0043] An acquisition module for acquiring data to be transmitted related to a vehicle;
[0044] A calculation module for fusing the above data to be transmitted, historical vehicle data, and external intelligence data, and calculating a communication risk score for the above data to be transmitted;
[0045] A determination module, configured to determine a target communication encryption policy based on the above-mentioned communication risk score and dynamic risk threshold, and adjust a key based on the above-mentioned communication risk score;
[0046] An encryption module, configured to encrypt the above-mentioned data to be transmitted by using the above-mentioned target communication encryption policy and the adjusted key, and transmit the encrypted data to be transmitted.
[0047] To achieve the above object, according to another aspect of the embodiments of the present invention, there is provided an electronic device for vehicle communication, including: one or more processors; a storage device, configured to store one or more programs, when the above-mentioned one or more programs are executed by the above-mentioned one or more processors, enabling the above-mentioned one or more processors to implement a vehicle communication method according to an embodiment of the present invention.
[0048] To achieve the above object, according to still another aspect of the embodiments of the present invention, there is provided a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements a vehicle communication method according to an embodiment of the present invention.
[0049] One embodiment of the above invention has the following advantages or beneficial effects: The above-mentioned data to be transmitted, historical vehicle data, and external intelligence data can be fused to calculate a communication risk score for the above-mentioned data to be transmitted; compare the communication risk score with the dynamic risk threshold, determine the target communication encryption policy, and adjust the key parameters; encrypt and transmit the data to be transmitted. Through the fusion of multi-source data, the accuracy of communication risk scoring is enhanced, the communication risk level of vehicle communication can be accurately determined in real time, the security level of vehicle communication can be identified, and appropriate measures can be taken for encrypted transmission to improve the security protection effect of vehicle communication.
[0050] At the same time, when the comparison result between the communication risk score and the dynamic risk threshold is different, different communication encryption algorithms are used as the target communication encryption policy. When the communication risk level is relatively low, a symmetric encryption algorithm with lower complexity and smaller computational amount is used to reduce the computational burden; when the communication risk level is relatively high, an asymmetric encryption algorithm and a symmetric encryption algorithm are fused to increase the encryption intensity and reduce the risk of vehicle communication data being stolen and the vehicle communication network being attacked and damaged.
[0051] The further effects of the above-mentioned non-conventional optional methods will be described in combination with specific embodiments below. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them:
[0053] Figure 1 is a schematic flowchart of a vehicle communication method according to an embodiment of the present invention;
[0054] Figure 2 It is a schematic flow diagram of adjusting key parameters according to an embodiment of the present invention;
[0055] Figure 3 It is a schematic flow diagram of a vehicle communication method according to another embodiment of the present invention;
[0056] Figure 4 It is a schematic diagram of the main modules of a vehicle communication device according to an embodiment of the present invention;
[0057] Figure 5 It is an exemplary system architecture diagram to which an embodiment of the present invention can be applied;
[0058] Figure 6 It is a schematic structural diagram of a computer system of a service system suitable for implementing an embodiment of the present invention. Detailed implementation manners
[0059] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings, including various details of the embodiments of the present invention to facilitate understanding, which should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted below.
[0060] It should be noted that, without conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0061] Figure 1 It is a schematic diagram of the main steps of a vehicle communication method according to an embodiment of the present invention.
[0062] As Figure 1 shown, the vehicle communication method of the embodiment of the present invention mainly includes the following step S101:
[0063] Step S101, obtaining data to be transmitted related to the vehicle;
[0064] Among them, the data to be transmitted is the data collected in real time by various in-vehicle sensors of the vehicle, including but not limited to vehicle basic status data, power-related data, driving data, location data, transmission delay data, etc. Among them, the vehicle basic status data includes but not limited to data related to the basic working status of the vehicle such as whether the vehicle is started, whether the doors are closed, and the vehicle handbrake status; the power-related data includes battery data such as battery voltage, current, and power, and engine data such as engine speed and valve opening; the driving data includes data such as the current vehicle speed, driving mileage, acceleration, and road type; the location data represents the location data of the current vehicle, etc.; the transmission delay data includes the average delay time for transmitting the data to be transmitted in the preset number of historical uploads, the current network signal strength, etc.
[0065] It should be noted that in the case where the transmission delay data indicates that the average delay time exceeds the historical normal delay time level, there may be interference or potential attacks on the vehicle communication network.
[0066] Step S102: Integrate the above data to be transmitted, historical vehicle data, and external intelligence data, and calculate the communication risk score for the above data to be transmitted.
[0067] Among them, the historical vehicle data is extracted from the upload log of the data to be transmitted, including but not limited to the number of historical attack events, the average delay time for transmitting the historical data to be transmitted, failed transmission events, and the proportion of reissued data in the historical data to be transmitted, etc.
[0068] The external intelligence data can be obtained through a predefined external threat intelligence interface, including but not limited to the recent security warning level, known vulnerability database updates, abnormal traffic alarm data in specific regions, real-time threat indices of security vendors, etc.
[0069] Thus, by comprehensively considering the data to be transmitted, historical vehicle data, and external intelligence data, the communication risk score of the data to be transmitted can be more accurately determined through multi-source data combination.
[0070] Step S103: Determine the target communication encryption strategy based on the above communication risk score and dynamic risk threshold, and adjust the key parameters based on the above communication risk score.
[0071] Compare the communication risk score with the dynamic risk threshold. In the case of different comparison results, different target communication encryption strategies are adopted.
[0072] Specifically, in response to the above communication risk score being greater than the above dynamic risk threshold, which indicates a relatively high communication risk level for transmitting the data to be transmitted. At this time, the asymmetric encryption algorithm and the symmetric encryption algorithm can be combined as the above target communication encryption strategy. Among them, the asymmetric encryption algorithm is an encryption algorithm that uses two keys (i.e., public key and private key) for encryption and decryption, including but not limited to the RSA encryption algorithm, Elliptic Curves Cryptography (ECC) algorithm, etc. The symmetric encryption algorithm is an encryption algorithm that uses the same key for encryption and decryption, including but not limited to the Advanced Encryption Standard (AES) algorithm, Data Encryption Standard (DES) algorithm, etc. Since the asymmetric encryption algorithm uses different keys for encryption and decryption, it has a better encryption effect compared to the symmetric encryption algorithm that uses the same key for encryption and decryption. Therefore, in the case of a relatively high communication risk level, the asymmetric encryption algorithm and the symmetric encryption algorithm are used as the target communication encryption strategy.
[0073] In response to the above communication risk score being less than or equal to the above dynamic risk threshold, the communication risk level for transmitting the data to be transmitted is relatively low. At this time, the above symmetric encryption algorithm can be used as the above target communication encryption strategy.
[0074] Preferably, the RSA encryption algorithm can be used for the asymmetric encryption algorithm, and the AES algorithm can be used for the symmetric encryption algorithm.
[0075] Optionally, in the case of using the asymmetric encryption algorithm and the symmetric encryption algorithm together as the target communication encryption strategy, the key of the symmetric encryption algorithm can be encrypted using the asymmetric encryption algorithm, and then the encrypted key of the symmetric encryption algorithm is used to encrypt the data to be transmitted.
[0076] The key parameters include the key length and the refresh frequency. After determining the target communication encryption strategy, the key length and the refresh frequency can also be adjusted according to the communication risk score to make the key more complex and more suitable for the current communication risk level. For example, in the case of a relatively large communication risk score, the communication risk level is relatively high. The key length can be increased and the refresh frequency of the key can be increased according to the communication risk score to obtain a better protection effect and reduce the risk of the key being cracked. It can be understood that the communication risk score is positively correlated with the communication risk level, that is, the larger the communication risk score, the higher the communication risk level.
[0077] Step S104, encrypt the above data to be transmitted using the above target communication encryption strategy and the adjusted key parameters, and transmit the encrypted data to be transmitted.
[0078] Encrypt the data to be transmitted according to the target communication encryption policy and the adjusted key parameters, so that the data to be transmitted has higher security, and then transmit the encrypted data to be transmitted, thereby reducing the possibility that the data to be transmitted is obtained by an attacker during the transmission process.
[0079] In an alternative embodiment, the above method further includes: respectively assigning corresponding preset weight coefficients to the above data to be transmitted, the above historical vehicle data, and the above external intelligence data.
[0080] The above calculation of the communication risk score for the above data to be transmitted includes: based on the above preset weight coefficients, fusing the data characteristics of the above data to be transmitted, the above historical vehicle data, and the above external intelligence data to generate a feature vector; inputting the above feature vector into a deep fusion model to obtain a communication risk score; wherein, the above deep fusion model is obtained by fusing a deep neural network model and a random forest algorithm.
[0081] In order to determine the importance of the three types of data for the communication risk score, corresponding preset weight coefficients can be assigned to the three types of data in advance. The preset weight coefficients can include a first preset weight coefficient corresponding to the data to be transmitted, a second preset weight coefficient corresponding to the historical vehicle data, and a third preset weight coefficient corresponding to the external intelligence data.
[0082] According to their respective corresponding weight coefficients, the data characteristics of the three types of data can be fused to generate a feature vector. Based on the feature vector, a communication risk score is obtained through a pre-trained deep fusion model. As an example, the first preset weight coefficient corresponding to the data to be transmitted a is 1, the second preset weight coefficient corresponding to the historical vehicle data b is 2, and the third preset weight coefficient corresponding to the external intelligence data c is 3. Through feature engineering, the above three types of data can generate a feature vector Xi=(a, 2b, 3c) based on their respective corresponding weight coefficients.
[0083] In an alternative embodiment, the above deep fusion model includes a deep neural network layer, a random forest algorithm layer, and a fusion layer;
[0084] The above inputting the above feature vector into the deep fusion model to obtain a communication risk score includes:
[0085] Inputting the above feature vector into the above deep neural network layer and the above random forest algorithm layer respectively to obtain a first risk score output by the above deep neural network layer and a second risk score output by the above random forest algorithm layer;
[0086] Based on the above first risk score, the first risk weight coefficient corresponding to the first risk score, the above second risk score, and the second risk weight coefficient corresponding to the second risk score, calculate a communication risk score through the fusion layer.
[0087] By fusing and training a deep neural network model and a random forest algorithm, a deep fusion model including a deep neural network layer, a random forest algorithm layer, and a fusion layer can be obtained. The two models can be combined to overcome the deficiencies of both models, thereby improving the prediction accuracy of communication risk scores. Among them, the fusion layer is the last layer of the deep fusion model.
[0088] In the process of continuously calculating the communication risk score using the fusion layer, new communication risk scores are continuously generated. In order to update the deep fusion model to make it have better model performance, a part of the continuously generated new communication risk scores can be used as a validation set to evaluate the model performance of the deep fusion model for new data. Thus, the first risk weight and the second risk weight are dynamically adjusted according to the performance of the deep fusion model evaluated by the validation set.
[0089] Furthermore, it can be triggered to use a part of the continuously generated new communication risk scores as a validation set according to a preset update time or when the newly generated communication risk scores reach a certain data volume, so as to evaluate the model performance and adjust the first risk weight and the second risk weight.
[0090] In addition, the feature vector used as the input of the deep neural network layer and the random forest algorithm layer contains three features. After the feature vector is respectively input into the deep neural network layer and the random forest algorithm layer, the attention mechanism of the deep neural network layer can learn the importance degree of each feature and assign different attention weights to each feature; the importance score of each feature calculated by the random forest algorithm layer is obtained to get the feature importance ranking. Furthermore, the preset weight coefficients corresponding to the data to be transmitted, historical vehicle data, and external intelligence data can be updated according to the attention weights of the attention mechanism of the deep neural network layer and the feature importance ranking of the random forest algorithm layer, so as to adjust the importance degree of the three types of data. As an example, when the feature importance ranking of the random forest algorithm layer indicates that the contribution of the data to be transmitted to predicting the communication risk score increases, the first preset weight coefficient corresponding to the data to be transmitted is increased. As another example, when the attention weight of the attention mechanism of the deep neural network layer indicates that the contribution of the historical vehicle data to predicting the communication risk score decreases, the second preset weight coefficient corresponding to the historical vehicle data is decreased.
[0091] In an alternative embodiment, the key parameters of the target communication encryption policy can be adjusted according to the communication risk score. As Figure 2 shown, the adjustment of the key parameters based on the above communication risk score includes the following steps S201 to step S203:
[0092] Step S201: Calculate the encryption strength by using the above communication risk score, a preset benchmark risk score, a preset benchmark encryption strength, and a preset upper limit value of the risk score, as shown in the following formula:
[0093]
[0094] Among them, S(t) represents the encryption strength, S 基线 represents the preset benchmark encryption strength, R(t) represents the communication risk score, and R 基线 represents the preset benchmark risk score, and R 上限 represents the preset upper limit value of the risk score. The encryption strength is positively correlated with the communication risk score. When the communication risk score is larger, it indicates a higher communication risk level. Therefore, a higher encryption strength can be set to achieve a better encryption effect. As an example, when the data to be transmitted indicates that the vehicle is in a place where the network signal strength fluctuates greatly, such as in a tunnel, or the current network signal strength is weak, then the current is vulnerable to physical attacks by attackers, and the communication risk score increases. Correspondingly, the encryption strength increases.
[0095] Step S202: Calculate the transitional key length by using a preset minimum key length, a preset maximum key length, the above benchmark risk score, and the above upper limit value of the risk score, as shown in the following formula
[0096]
[0097] Among them, L(t) represents the transitional key length, and L 最小 represents the preset minimum key length, and L 最大 represents the preset maximum key length. The transitional key length is positively correlated with the communication risk score. When the communication risk score is larger, it indicates a higher communication risk level. Therefore, a longer transitional key length can be set to increase the difficulty of cracking the key.
[0098] Step S203: Adjust the current key length according to the above encryption strength and the above transitional key length.
[0099] The current key length can be the key length used when the target communication encryption policy encrypted the previous data to be transmitted, or it can be the shortest key length of the target communication encryption policy. As an example, the key lengths of the AES algorithm include 128 bits, 192 bits, 256 bits, etc. When the target communication encryption policy is the AES algorithm, the current key length can be its shortest key length of 128 bits.
[0100] Adjust the current key length according to the encryption strength and the transitional key length. When the current key length is the shortest key length, specifically, in the case where the encryption strength is less than the encryption strength threshold and the transitional key length is less than the transitional key length, it indicates that the current communication risk level is relatively low, and the current key length is the shortest key length of the target communication encryption policy; in the case where the encryption strength is less than the encryption strength threshold and the transitional key length is greater than the transitional key length, or in the case where the encryption strength is greater than the encryption strength threshold and the transitional key length is less than the transitional key length, it indicates that there is a certain communication risk currently, and adjust the current key length from the shortest key length to the medium key length; in the case where the encryption strength is greater than the encryption strength threshold and the transitional key length is greater than the transitional key length, it indicates that the current communication risk level is relatively high, and adjust the current key length from the shortest key length to the longest key length.
[0101] As an example, the key length of the RSA encryption algorithm has no fixed value. The shortest key length can be set to 1024 bits, the medium key length can be set to 2048 bits, and the longest key length can be set to 4096 bits, so that the key length of the RSA encryption algorithm can be adjusted according to the encryption strength and the transitional key length.
[0102] In addition, the key parameter of the target communication encryption policy can also include the refresh frequency of the key, and the refresh frequency can be adjusted according to the communication risk score. Specifically, the refresh frequency can be positively correlated with the communication risk score, so as to increase the refresh frequency of the key in the case where the communication risk score indicates an increase in the communication risk level, so as to enhance the security of the key.
[0103] In an alternative embodiment, the above method is implemented based on a service system including multiple edge nodes.
[0104] An edge node is a node of an in-vehicle communication device close to the vehicle end, mainly used for content distribution and caching, reducing the latency of the data to be transmitted to the cloud. In the embodiment of the present invention, the service system includes an edge computing platform and edge nodes, wherein the edge computing platform is used to execute step S101, step S102 and step S103, and the edge nodes are used to execute step S104.
[0105] In an alternative embodiment, the above method further includes:
[0106] Encrypt the data to be transmitted by using the above target communication encryption policy and the adjusted key parameters, and encapsulate the encrypted data to be transmitted into an encryption task;
[0107] Allocate the above encryption task to the edge nodes.
[0108] Specifically, the edge computing platform can encapsulate the encryption and uploading of data to be transmitted into an encryption task and allocate it to each edge node, so that each edge node executes the encryption task.
[0109] In an alternative embodiment, the allocation of the encryption task to the edge node includes:
[0110] For each of the above-mentioned edge nodes, perform steps N1 to N3:
[0111] Step N1, obtain the real-time load data of the above-mentioned edge node;
[0112] Step N2, determine the computing power of the above-mentioned edge node based on the above-mentioned real-time load data;
[0113] Step N3, allocate the above-mentioned encryption task to the edge node according to the computing power of the above-mentioned edge node.
[0114] The edge computing platform can obtain the real-time load data of each edge node. Among them, the real-time load data includes but is not limited to the Central Processing Unit (CPU) occupancy rate, Graphics Processing Unit (GPU) utilization rate, network bandwidth, and network latency. There is a certain correlation between the computing power of each edge node and its real-time load data, as follows:
[0115] C i (t) ∝ Available CPU / GPU FLOPS, Network BW, Latency
[0116] Among them, C i (t) represents the computing power of the i-th edge node, Available CPU represents the CPU occupancy rate of the i-th edge node, GPU FLOPS represents the GPU utilization rate of the i-th edge node, Network BW represents the network bandwidth of the i-th edge node, and Latency represents the network latency of the i-th edge node.
[0117] The CPU occupancy rate represents the proportion of the CPU used within a unit of time. When the CPU occupancy rate is high, it indicates that the current edge node is processing a large number of computing tasks and has relatively weak computing power for encryption tasks. The GPU utilization rate reflects the degree to which GPU resources are being used. When the GPU utilization rate is high, it means that the current edge node is making full use of the GPU to process tasks but has relatively weak computing power for encryption tasks. Network bandwidth represents the amount of data transmitted through the network within a unit of time. Sufficient network bandwidth can ensure fast and stable data transmission. When the network bandwidth is insufficient, it will affect the data transmission efficiency, thereby preventing the computing power of the current edge node from being fully utilized. Network latency represents the time required for data to be transmitted from one edge node to another. When the network latency is high, it will affect the data transmission efficiency, thus preventing the computing power of the current edge node from being fully utilized. Among them, only one of the two data, namely the CPU occupancy rate and the GPU utilization rate, of the edge node can be obtained, and combined with other real-time load data to jointly determine the computing power of the edge node. As an example, the computing power of edge node 1 can be determined by the CPU occupancy rate, network bandwidth, and network latency; the computing power of edge node 2 can be determined by the GPU utilization rate, network bandwidth, and network latency.
[0118] After determining the computing power of the edge node, the encryption tasks can be allocated to the edge node according to the following formula.
[0119]
[0120] Among them, P i (t) represents the proportion of encryption tasks of the i-th edge node. The encryption tasks are allocated based on the computing power of each edge node, so that more encryption tasks are allocated to the edge node with relatively stronger computing power. When the computing power of the edge node is insufficient, the proportion of encryption tasks allocated to this edge node can be reduced to ensure that the encryption tasks can still be completed quickly and in a timely manner even when the communication risk level is high, and to avoid problems such as transmission delays caused by complex encryption. It should be noted that when the transmission delay data of the data to be transmitted indicates that the delay time becomes longer, the service system can shorten the delay time by allocating the encryption tasks to more edge nodes so that more edge nodes share the encryption tasks, or by increasing computing resources, etc.
[0121] Furthermore, since the vehicle terminal itself has a certain data processing ability, before the edge computing platform obtains the data to be transmitted, the vehicle terminal can pre-encrypt the data to be transmitted locally in advance. The pre-encryption can use a lightweight symmetric encryption algorithm. At this time, the amount of pre-encryption by the vehicle terminal can be determined according to its processor load, available bandwidth, etc., thereby further reducing the encryption task burden of the edge node.
[0122] In an alternative embodiment, the above method further includes:
[0123] Deploy the steps of determining the target communication encryption policy based on the communication risk score and the dynamic risk threshold, and adjusting the key parameters based on the communication risk score, in the smart contract of the blockchain;
[0124] In response to a change in the comparison result between the communication risk score and the dynamic risk threshold, trigger the smart contract of the blockchain to cause the smart contract to execute the steps of determining the target communication encryption policy and adjusting the key parameters.
[0125] The service system can deploy the steps of determining the target communication encryption policy and adjusting the key parameters in the smart contract of the blockchain to respond to changes in the communication risk score in real time through the blockchain. Among them, the smart contract is an automated protocol running on the blockchain that can automatically execute specific tasks.
[0126] When the comparison result between the communication risk score and the dynamic risk threshold changes, for example, when the comparison result changes from the communication risk score being less than the dynamic risk threshold to the communication risk score being greater than the dynamic risk threshold, trigger the smart contract to cause the smart contract to automatically re-determine the target communication encryption policy according to the change in the comparison result and adjust the key parameters, so as to automatically respond to changes in the communication risk score through the smart contract.
[0127] In an alternative embodiment, the above method further includes:
[0128] Record the changes in the target communication encryption policy and the changes in the key parameters on the blockchain. Through the blockchain record, data traceability can be achieved. In the case of abnormal vehicle communication, the determination of the target communication encryption policy and the adjustment of the key parameters can be traced through the blockchain record, quickly and effectively query the source of the problem, facilitate the timely formulation of countermeasures, and avoid further damage to vehicle communication.
[0129] In an alternative embodiment, the above method further includes:
[0130] Obtain the proportion of the number of times the communication risk score is greater than the dynamic risk threshold within a preset historical time period to the number of times the communication risk score changes;
[0131] Update the dynamic risk threshold by using a preset tuning coefficient, the above proportion, and a preset high-risk expectation proportion. Please refer to the following formula,
[0132] R threshold, new = R threshold, old + δ(p - p target )
[0133] Where, R 阈值 ,new Denote the updated dynamic risk threshold as R 阈值 , old Denote the dynamic risk threshold before update, δ denote the tuning coefficient, p denote the proportion of the number of times that the above communication risk score is greater than the above dynamic risk threshold in the above preset historical time period to the number of times of change of the above communication risk score, p target Denote the preset high - risk expectation proportion. Among them, the tuning coefficient can be preset according to the actual situation. By the proportion of the number of times that the communication risk score is greater than the dynamic risk threshold to the number of times of change of the communication risk score, the dynamic update of the dynamic risk threshold is realized, ensuring that the dynamic risk threshold is more in line with the actual safety situation of vehicle communication. As an example, in the case that the communication risk score is greater than the dynamic risk threshold multiple times, it indicates that the number of occurrences of a higher communication risk level is too large, and there is a high possibility of a large number of misjudgments. The dynamic risk threshold can be correspondingly increased to reduce the occurrence of misjudgment events.
[0134] The vehicle communication method will be further elaborated through a specific embodiment below.
[0135] As Figure 3 shown, the vehicle communication method of the embodiment of the present invention includes the following steps S301 to step S308:
[0136] Step S301, the edge computing platform of the service system can obtain the data to be transmitted related to the vehicle, and fuse the data to be transmitted, historical vehicle data and external intelligence data, and generate a feature vector through feature engineering based on the respective preset weight coefficients;
[0137] Among them, the preset weight coefficient can be updated according to the attention weight of the attention mechanism of the deep neural network layer and the feature importance ranking of the random forest algorithm layer.
[0138] Step S302, the edge computing platform can input the above - mentioned feature vector into the deep fusion model to obtain a communication risk score;
[0139] Specifically, the feature vector can be respectively input into the deep neural network layer and the random forest algorithm layer of the deep fusion model to obtain the first risk score output by the above - mentioned deep neural network layer and the second risk score output by the above - mentioned random forest algorithm layer; Based on the above - mentioned first risk score, the first risk weight coefficient corresponding to the first risk score, the above - mentioned second risk score and the second risk weight coefficient corresponding to the second risk score, the communication risk score is calculated through the fusion layer, as follows,
[0140] R(t)=ω1R DNN (h(t)) + ω2R RF (t)
[0141] Among them, R(t) represents the communication risk score, and R DNN (h(t)) represents the first risk score output by the deep neural network layer, h(t) represents the high-order features extracted by the deep neural network layer for the feature vector, ω1 represents the first risk weight coefficient, and R RF (t) represents the second risk score output by the random forest algorithm layer, and ω2 represents the second risk weight coefficient.
[0142] Furthermore, a part of the continuously generated new communication risk scores can be used as a validation set to evaluate the model performance of the deep fusion model for new data, so as to dynamically adjust the first risk weight and the second risk weight according to the performance of the deep fusion model evaluated by the validation set.
[0143] Step S303, compare the communication risk score with the dynamic risk threshold;
[0144] Among them, the dynamic risk threshold can be dynamically updated by using the proportion of the number of times that the above communication risk score is greater than the above dynamic risk threshold in the number of changes of the above communication risk score within a preset historical time period, a preset tuning coefficient, and a preset high-risk expectation proportion.
[0145] Step S304, in response to the above communication risk score being greater than the above dynamic risk threshold, synthesize the asymmetric encryption algorithm and the symmetric encryption algorithm as the above target communication encryption strategy;
[0146] Step S305, in response to the above communication risk score being less than or equal to the above dynamic risk threshold, use the above symmetric encryption algorithm as the above target communication encryption strategy;
[0147] Step S306, when the target communication encryption strategy is determined, adjust the key parameters of the target communication encryption strategy based on the above communication risk score;
[0148] Specifically, use the above communication risk score, a preset benchmark risk score, a preset benchmark encryption strength, and a preset upper limit value of the risk score to calculate the encryption strength; use a preset minimum key length, a preset maximum key length, the above benchmark risk score, and the above upper limit value of the risk score to calculate the transitional key length; adjust the current key length according to the above encryption strength and the above transitional key length.
[0149] At the same time, adjust the key refresh frequency according to the communication risk score. Among them, the refresh frequency can be positively correlated with the communication risk score.
[0150] Further, steps S304, S305, and S306 can be deployed in the smart contract of the blockchain. When the comparison result between the communication risk score and the dynamic risk threshold changes, the smart contract is triggered, so that the smart contract automatically re-determines the target communication encryption policy according to the change in the comparison result and adjusts the key parameters, thereby automatically responding to the change in the communication risk score through the smart contract.
[0151] Meanwhile, the changes in the above-mentioned target communication encryption policy and the changes in the above-mentioned key parameters are recorded on the blockchain, and data traceability is achieved through the blockchain record.
[0152] Step S307, encapsulate the encryption task for encrypting the data to be transmitted, and allocate the encryption task to each edge node according to the computing power of each edge node;
[0153] Specifically, obtain the real-time load data of the above-mentioned edge nodes; determine the computing power of the above-mentioned edge nodes based on the above-mentioned real-time load data; allocate the above-mentioned encryption task to the edge nodes according to the computing power of the above-mentioned edge nodes.
[0154] Among them, the real-time load data includes CPU occupancy, GPU utilization, network bandwidth, network latency, etc.
[0155] Step S308, the edge node assigned with the encryption task executes the encryption task, encrypts the data to be transmitted, and transmits the encrypted data to be transmitted to the cloud.
[0156] According to the vehicle communication method of the embodiment of the present invention, the above-mentioned data to be transmitted, historical vehicle data, and external intelligence data can be fused to calculate the communication risk score for the above-mentioned data to be transmitted; compare the communication risk score with the dynamic risk threshold, determine the target communication encryption policy, and adjust the key parameters; encrypt and transmit the data to be transmitted. Through the fusion of multi-source data, the accuracy of communication risk scoring is enhanced, the communication risk level of vehicle communication can be accurately determined in real time, the security level of vehicle communication can be identified, and appropriate measures can be taken for encrypted transmission to improve the vehicle communication security protection effect.
[0157] Meanwhile, in the case where the comparison result between the communication risk score and the dynamic risk threshold is different, different communication encryption algorithms are used as the target communication encryption policy. In the case of a lower communication risk level, a symmetric encryption algorithm with lower complexity and smaller computational complexity is used to reduce the computational burden; in the case of a higher communication risk level, an asymmetric encryption algorithm and a symmetric encryption algorithm are fused to increase the encryption strength and reduce the risk of vehicle communication data being stolen and the vehicle communication network being attacked and damaged.
[0158] Figure 4 It is a schematic diagram of the main modules of the vehicle communication device according to the embodiment of the present invention. AsFigure 4 As shown in Figure 4 , the vehicle communication device 400 according to an embodiment of the present invention includes: an acquisition module 401, configured to acquire data to be transmitted related to the vehicle; a calculation module 402, configured to fuse the data to be transmitted, historical vehicle data, and external intelligence data, and calculate a communication risk score for the data to be transmitted; a determination module 403, configured to determine a target communication encryption policy based on the communication risk score and a dynamic risk threshold, and adjust key parameters based on the communication risk score; and an encryption module 404, configured to encrypt the data to be transmitted by using the target communication encryption policy and the adjusted key parameters, and transmit the encrypted data to be transmitted.
[0159] In an optional embodiment of the present invention, the vehicle communication device further includes: a weight assignment module, configured to respectively assign corresponding preset weight coefficients to the data to be transmitted, the historical vehicle data, and the external intelligence data. The calculation module 402 is further configured to: based on the preset weight coefficients, fuse the data characteristics of the data to be transmitted, the historical vehicle data, and the external intelligence data to generate a feature vector; and input the feature vector into a deep fusion model to obtain a communication risk score, where the deep fusion model is obtained by fusing a deep neural network model and a random forest algorithm.
[0160] In an optional embodiment of the present invention, the deep fusion model includes a deep neural network layer, a random forest algorithm layer, and a fusion layer. The calculation module 402 is further configured to: respectively input the feature vector into the deep neural network layer and the random forest algorithm layer to obtain a first risk score output by the deep neural network layer and a second risk score output by the random forest algorithm layer; and calculate a communication risk score through the fusion layer based on the first risk score, a first risk weight coefficient corresponding to the first risk score, the second risk score, and a second risk weight coefficient corresponding to the second risk score.
[0161] In an optional embodiment of the present invention, the determination module 403 is further configured to: in response to the communication risk score being greater than the dynamic risk threshold, synthesize an asymmetric encryption algorithm and a symmetric encryption algorithm as the target communication encryption policy; and in response to the communication risk score being less than or equal to the dynamic risk threshold, use the symmetric encryption algorithm as the target communication encryption policy.
[0162] In an alternative embodiment of the present invention, the above key parameters include the key length. The encryption module 404 is further configured to: calculate the encryption strength by using the communication risk score, a preset reference risk score, a preset reference encryption strength, and a preset upper limit value of the risk score; calculate a transition key length by using a preset minimum key length, a preset maximum key length, the above reference risk score, and the above upper limit value of the risk score; and adjust the current key length according to the above encryption strength and the above transition key length.
[0163] In an alternative embodiment of the present invention, the above vehicle communication device is applicable to a service system including a plurality of edge nodes.
[0164] In an alternative embodiment of the present invention, the above vehicle communication device further includes: a task allocation module, configured to: encapsulate the data to be transmitted encrypted by using the above target communication encryption policy and the adjusted key parameters into an encryption task; and allocate the above encryption task to an edge node.
[0165] In an alternative embodiment of the present invention, the above task allocation module is further configured to: for each of the above edge nodes, perform steps N1 to N3:
[0166] Step N1, obtain the real-time load data of the above edge node;
[0167] Step N2, determine the computing power of the above edge node based on the above real-time load data;
[0168] Step N3, allocate the above encryption task to the edge node according to the computing power of the above edge node.
[0169] In an alternative embodiment of the present invention, the above vehicle communication device further includes: a deployment module, configured to: deploy the step of determining a target communication encryption policy based on the above communication risk score and a dynamic risk threshold and adjusting key parameters based on the above communication risk score to a smart contract of a blockchain; and trigger the smart contract of the above blockchain in response to a change in the comparison result between the above communication risk score and the dynamic risk threshold, so that the smart contract executes the steps of determining a target communication encryption policy and adjusting key parameters.
[0170] In an alternative embodiment of the present invention, the above deployment module is further configured to: record the change of the above target communication encryption policy and the change of the above key parameters on the blockchain.
[0171] In an alternative embodiment of the present invention, the vehicle communication device further includes an update module configured to: obtain the proportion of the number of times that the communication risk score is greater than the dynamic risk threshold within a preset historical time period to the number of times of change of the communication risk score; and update the dynamic risk threshold by using a preset tuning coefficient, the proportion, and a preset high-risk expected proportion.
[0172] According to the vehicle communication device of the embodiment of the present invention, the to-be-transmitted data, historical vehicle data, and external intelligence data can be fused to calculate a communication risk score for the to-be-transmitted data; compare the communication risk score with the dynamic risk threshold to determine a target communication encryption policy and adjust key parameters; encrypt and transmit the to-be-transmitted data. Through the fusion of multi-source data, the accuracy of communication risk scoring can be enhanced, the communication risk level of vehicle communication can be determined in real time and accurately, the vehicle communication security level can be identified, and appropriate measures can be taken for encrypted transmission.
[0173] Meanwhile, in the case where the comparison result between the communication risk score and the dynamic risk threshold is different, different communication encryption algorithms are used as the target communication encryption policy. In the case of a lower communication risk level, a symmetric encryption algorithm with lower complexity and smaller computational amount is adopted to reduce the computational burden; in the case of a higher communication risk level, an asymmetric encryption algorithm and a symmetric encryption algorithm are fused to increase the encryption intensity and reduce the risk of vehicle communication data being stolen and the vehicle communication network being attacked and damaged.
[0174] Figure 5 An exemplary system architecture 500 to which the vehicle communication method or vehicle communication device of the embodiment of the present invention can be applied is shown.
[0175] As Figure 5 shown, the system architecture 500 may include in-vehicle communication devices 501, 502, 503, a network 504, a service system 505, and a cloud 506. The network 504 is used to provide a medium for communication links between the in-vehicle communication devices 501, 502, 503 and the edge node 505, and between the service system 505 and the cloud 506. The network 504 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0176] The in-vehicle communication devices 501, 502, 503 interact with the service system 505 through the network 504 to receive or send data, etc. The in-vehicle communication devices 501, 502, 503 may be disposed in vehicles, and at least one in-vehicle communication device is disposed in each vehicle.
[0177] The service system 505 interacts with the cloud 506 via the network 504 to receive or send data. The service system 505 can be a server that provides various services, such as a management server that supports the data to be transmitted sent by the vehicle communication devices 501, 502, and 503. The management server can process the acquired data to be transmitted, such as encryption, and transmit the processing result (such as the encrypted data to be transmitted) to the cloud 506.
[0178] The cloud 506 can be a server that decrypts and processes the received data to be transmitted.
[0179] It should be noted that the vehicle communication method provided by the embodiments of the present invention is generally executed by the service system 505. Correspondingly, the vehicle communication device is generally disposed in the service system 505.
[0180] It should be understood that Figure 5 the numbers of the vehicle communication devices, networks, service systems, and clouds in
[0181] are merely illustrative. According to the implementation requirements, there can be any number of vehicle communication devices, networks, service systems, and clouds. Figure 6 is a schematic structural diagram of a computer system 600 of a service system suitable for implementing the embodiments of the present invention. Figure 6 The shown service system is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0182] As Figure 6 shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage section 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the computer system 600 are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0183] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as required. A removable medium 611 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the drive 610 as required so that a computer program read therefrom is installed into the storage section 608 as required.
[0184] Specifically, according to the embodiments disclosed by the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed by the present invention include a computer program product which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by a central processing unit (CPU) 601, the above-described functions defined in the system of the present invention are performed.
[0185] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical fiber, etc., or any suitable combination of the above.
[0186] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0187] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes an acquisition module, a calculation module, a determination module, and an encryption module. Among them, the names of these modules do not constitute a limitation to the module itself in some cases. For example, the acquisition module can also be described as "a module for acquiring data to be transmitted related to a vehicle".
[0188] As another aspect, the present invention also provides a computer-readable medium, which can be included in the device described in the above embodiments; or it can exist alone without being assembled into the device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the device, the device includes: acquiring data to be transmitted related to a vehicle; fusing the data to be transmitted, historical vehicle data, and external intelligence data, and calculating a communication risk score for the data to be transmitted; based on the communication risk score and a dynamic risk threshold, determining a target communication encryption policy, and adjusting a key parameter based on the communication risk score; using the target communication encryption policy and the adjusted key parameter to encrypt the data to be transmitted, and transmitting the encrypted data to be transmitted.
[0189] According to the technical solution of the embodiments of the present invention, the data to be transmitted, historical vehicle data, and external intelligence data can be fused, and a communication risk score for the data to be transmitted can be calculated; the communication risk score is compared with the dynamic risk threshold to determine a target communication encryption policy and adjust the key parameter; the data to be transmitted is encrypted and transmitted. Through the fusion of multi-source data, the accuracy of the communication risk scoring can be enhanced, the communication risk level of vehicle communication can be accurately determined in real time, the vehicle communication security level can be identified, and appropriate measures can be taken for encrypted transmission.
[0190] At the same time, in the case where the comparison result between the communication risk score and the dynamic risk threshold is different, different communication encryption algorithms are used as the target communication encryption policy. In the case of a lower communication risk level, a symmetric encryption algorithm with lower complexity and smaller calculation amount is used to reduce the calculation burden; in the case of a higher communication risk level, an asymmetric encryption algorithm and a symmetric encryption algorithm are fused to increase the encryption intensity and reduce the risk of vehicle communication data being stolen and the vehicle communication network being attacked and damaged.
[0191] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention should be included within the protection scope of the present invention.
Claims
1. A vehicle communication method, characterized in that: include: Acquire vehicle-related data to be transmitted; fusing the data to be transmitted, historical vehicle data and external intelligence data, and calculating a communication risk score for the data to be transmitted; Determining a target communication encryption strategy based on the communication risk score and the dynamic risk threshold, and adjusting key parameters based on the communication risk score; The target communication encryption strategy and the adjusted key parameters are used to encrypt the data to be transmitted, and the encrypted data to be transmitted is transmitted.
2. The vehicle communication method according to claim 1, characterized in that: The method further comprises: respectively allocating corresponding preset weight coefficients to the data to be transmitted, the historical vehicle data and the external intelligence data; The calculating a communication risk score for the data to be transmitted includes: Based on the preset weight coefficient, the data features of the data to be transmitted, the historical vehicle data and the external intelligence data are integrated to generate a feature vector; The feature vector is input into a deep fusion model to obtain a communication risk score, wherein the deep fusion model is obtained by fusing a deep neural network model and a random forest algorithm.
3. The vehicle communication method according to claim 2, characterized in that: The deep fusion model includes a deep neural network layer, a random forest algorithm layer and a fusion layer; Inputting the feature vector into a deep fusion model to obtain a communication risk score includes: Inputting the feature vectors into the deep neural network layer and the random forest algorithm layer respectively, to obtain a first risk score output by the deep neural network layer and a second risk score output by the random forest algorithm layer; A communication risk score is obtained by calculating through a fusion layer based on the first risk score, a first risk weight coefficient corresponding to the first risk score, the second risk score, and a second risk weight coefficient corresponding to the second risk score.
4. The vehicle communication method according to claim 1, characterized in that: The determining of a target communication encryption strategy based on the communication risk score and the dynamic risk threshold comprises: In response to the communication risk score being greater than the dynamic risk threshold, combining an asymmetric encryption algorithm and a symmetric encryption algorithm as the target communication encryption strategy; In response to the communication risk score being less than or equal to the dynamic risk threshold, using the symmetric encryption algorithm as the target communication encryption strategy; and / or, The key parameter includes a key length; and adjusting the key parameter based on the communication risk score includes: Calculating encryption strength using the communication risk score, a preset baseline risk score, a preset baseline encryption strength, and a preset risk score upper limit; Calculating a transition key length using a preset minimum key length, a preset maximum key length, the baseline risk score, and the risk score upper limit; The current key length is adjusted according to the encryption strength and the transitional key length.
5. The vehicle communication method according to any one of claims 1 to 4, characterized in that: It is implemented based on a service system consisting of multiple edge nodes.
6. The vehicle communication method according to claim 5, characterized in that: The method further comprises: Encrypting the data to be transmitted by using the target communication encryption strategy and the adjusted key parameters, and transmitting the encrypted data to be transmitted and encapsulating it into an encryption task; The encryption task is distributed to edge nodes.
7. The vehicle communication method according to claim 6, characterized in that: The allocating the encryption task to the edge node comprises: For each edge node, execute steps N1 to N3: Step N1, obtaining real-time load data of the service system node; Step N2, determining the computing capacity of the service system node based on the real-time load data; Step N3, allocating the encryption task to the edge node according to the computing power of the service system node.
8. The vehicle communication method according to claim 4, characterized in that: The method further comprises: Deploy the steps of determining a target communication encryption strategy based on the communication risk score and the dynamic risk threshold, and adjusting key parameters based on the communication risk score in a smart contract of a blockchain; In response to a change in the comparison result between the communication risk score and the dynamic risk threshold, triggering a smart contract of the blockchain, causing the smart contract to execute the steps of determining a target communication encryption strategy and adjusting key parameters; Preferably, the method further comprises: The changes in the target communication encryption strategy and the changes in the key parameters are recorded on the blockchain.
9. The vehicle communication method according to claim 4, characterized in that: The method further comprises: Obtaining a ratio of the number of times the communication risk score is greater than the dynamic risk threshold to the number of times the communication risk score changes within a preset historical time period; The dynamic risk threshold is updated using a preset tuning coefficient, the ratio and a preset high risk expected ratio.
10. A vehicle communication device, characterized in that: include: An acquisition module, used for acquiring vehicle-related data to be transmitted; A calculation module, used to fuse the data to be transmitted, historical vehicle data and external intelligence data, and calculate a communication risk score for the data to be transmitted; A determination module, configured to determine a target communication encryption strategy based on the communication risk score and a dynamic risk threshold, and adjust a key parameter based on the communication risk score; The encryption module is used to encrypt the data to be transmitted by using the target communication encryption strategy and the adjusted key parameters, and transmit the encrypted data to be transmitted.
Citation Information
Cited By
Data processing method and device based on Internet of Vehicles, electronic equipment and storage medium
CN121603949A
Adaptive enhancement method and system for vehicle-mounted TLS configuration
CN121711190A