Trust management based on dynamic supervised learning
By introducing trust management entities and hidden Markov models into the C-ITS system, the credibility of the C-ITS station is evaluated, and the protection of data confidentiality and integrity is solved, and the security and reliability of the system are achieved.
Patent Information
- Application Number
- CN202411882039.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-12-19
- Publication Date
- 2025-06-24
AI Technical Summary
In collaborative intelligent transportation systems (C-ITS), the prior art is difficult to effectively protect the confidentiality and integrity of data and prevent malicious parties from accessing and manipulating data.
Using trust management entities, the trust management entity is used to evaluate the credibility of the C-ITS station and determine its trust rate through the Hidden Markov Model (HMM) and the trust manager, so as to make trust decisions.
It realizes effective protection of C-ITS station data, ensures the confidentiality and integrity of the data, prevents malicious access and manipulation, and improves the security of the system.
Smart Images

Figure CN120201413A_ABST
Abstract
Description
Technical Field
[0001] Various example embodiments relate to wireless communication. Background Art
[0002] A cooperative intelligent transport system (C-ITS) is a transport system that includes two or more C-ITS stations (including, for example, individuals, vehicles, roadside, and / or central subsystems) that cooperate with each other in order to enable and provide intelligent transport system (ITS) services, which offer better quality and an enhanced level of service compared to the same ITS services provided by only one of the ITS subsystems. Ideally, data sent within a C-ITS station, between C-ITS stations, and / or from a C-ITS station should be protected to ensure its confidentiality and integrity. However, in some cases, a malicious party may still be able to access and manipulate the data (e.g., cause a change in the position, speed, or other internal parameters of a vehicle C-ITS station). Therefore, there is also a need for a reliable trust mechanism for making trust decisions regarding C-ITS stations, i.e., for determining whether a given C-ITS station will be trusted. Summary of the Invention
[0003] According to one aspect, the subject matter of the independent claims is provided. Embodiments are defined in the dependent claims.
[0004] One or more examples of implementations are set forth in greater detail in the drawings and the following description. Other features will be apparent from the description and drawings, and from the claims. Brief Description of the Drawings
[0005] Figure 1 Shows a system in which some embodiments may be applied;
[0006] Figure 2 Shows a system according to some embodiments;
[0007] Figure 3 、 4 、5A and 5B show a process according to some embodiments;
[0008] Figure 6 Shows a process according to some embodiments;
[0009] Figure 7 Shows an apparatus according to some embodiments. Detailed Description
[0010] The following embodiments are presented only as examples. Although the present specification may refer to "an", "one", or "some" embodiments and / or examples at several places in the text, this does not necessarily mean that each reference points to the same (multiple) embodiment or (multiple) examples, or that a particular feature applies only to a single embodiment and / or example. Individual features of different embodiments and / or examples may also be combined to provide other embodiments and / or examples.
[0011] As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrases, where the list of two or more elements is joined by "and" or "or", means at least any one element, or at least any two or more elements, or at least all elements.
[0012] Hereinafter, different exemplary embodiments will be described using a radio access architecture based on Long Term Evolution Advanced (LTE-A) or New Radio (NR, 5G) as an example of an access architecture to which the embodiments can be applied. However, the embodiments are not limited to such an architecture. It will be apparent to those skilled in the art that, by appropriately adjusting parameters and processes, these embodiments can also be applied to other types of communication networks having suitable means. Some examples of other options for suitable systems include Universal Mobile Telecommunications System (UMTS) radio access network (UTRAN or E-UTRAN), Long Term Evolution (LTE, same as E-UTRA), Wireless Local Area Network (WLAN or WiFi), Worldwide Interoperability for Microwave Access (WiMAX), Personal Communication Service (PCS), Wideband Code Division Multiple Access (WCDMA), systems using Ultra-Wideband (UWB) technology, sensor networks, Mobile Ad-hoc NETworks (MANET), and Internet Protocol Multimedia Subsystem (IMS) or any combination thereof.
[0013] Figure 1 An example of a simplified system architecture is depicted, showing only some elements and functional entities, all of which are logical units and their implementation may be different from that shown. Figure 1 The connections shown are logical connections; the actual physical connections may be different. It will be apparent to those skilled in the art that the system generally also includes other functions and structures in addition to Figure 1 those shown.
[0014] However, the embodiments are not limited to the system given as an example, and those skilled in the art can apply the solution to other communication systems having the necessary attributes.
[0015] Figure 1The example of shows a part of an exemplary radio access network.
[0016] A communication system typically includes more than one (e / g)NodeB. In this case, the (e / g)NodeBs can also be configured to communicate with each other via wired or wireless links designed for this purpose. These links can be used for signaling purposes. An (e / g)NodeB is a computing device configured to control the radio resources of the communication system to which it is coupled. A NodeB can also be referred to as a base station, an access point, or any other type of interface device, including a relay station capable of operating in a wireless environment. An (e / g)NodeB includes or is coupled to a transceiver. From the transceiver of the (e / g)NodeB, a connection is provided to an antenna unit that establishes a two-way radio link to a user equipment. The antenna unit can include multiple antennas or antenna elements. The (e / g)NodeB is also connected to a core network 110 (CN or Next Generation Core NGC). Depending on the system, the corresponding party on the CN side can be a Serving Gateway (S-GW, routing and forwarding user data packets), a Packet Data Network Gateway (P-GW) for providing connectivity of the user equipment (UE) to an external packet data network, or a Mobility Management Entity (MME), etc.
[0017] A user equipment (also referred to as UE, user device, user terminal, terminal device, etc.) shows a device to which resources on an air interface are allocated and assigned. Thus, any feature described herein with respect to a user equipment can be implemented with a corresponding device (such as a relay node). An example of such a relay node is a layer 3 relay (self-backhaul relay) towards a base station. A user equipment can include a mobile device and at least one Universal Integrated Circuit Card (UICC).
[0018] A user equipment generally refers to a portable computing device, which includes a wireless mobile communication device operating with or without a subscriber identity module (SIM) or UICC, including but not limited to the following types of devices: mobile station (mobile phone), smart phone, personal digital assistant (PDA), cellular phone, device using a wireless modem (such as an alarm or measurement device), laptop and / or touch screen computer, tablet computer, game console, notebook, and multimedia device. It should be understood that the user equipment may also be an almost exclusive uplink-only device, an example of which is a camera or video camera that loads images or video clips onto a network. The user equipment may also be a device capable of operating in an Internet of Things (IoT) network, which is a scenario where objects are provided with the ability to transport data over a network without human-to-human or human-to-computer interaction. Thus, the user equipment may not support direct user interaction or may only support limited user interaction (e.g., during setup). The user equipment (or in some embodiments, a layer 3 relay node) is configured to perform one or more of the user equipment functions. The user equipment may also be referred to as a terminal device, subscriber unit, mobile station, remote terminal, access terminal, user terminal, or user equipment (UE), to name just a few.
[0019] The various techniques described herein may also be applied to cyber-physical systems (CPS) (systems of collaborative computing elements that control physical entities). CPS can enable the implementation and utilization of a large number of interconnected ICT devices (sensors, actuators, processor microcontrollers, etc.) embedded in physical objects at different locations. Mobile cyber-physical systems are a subcategory of cyber-physical systems, where the physical systems under discussion have inherent mobility. Examples of mobile physical systems include mobile robots and electronic devices transported by humans or animals.
[0020] It should be understood that, in Figure 1 , for clarity only, the user equipment is depicted as including only 2 antennas. The number of receive and / or transmit antennas can naturally vary according to the current implementation.
[0021] In addition, although these devices have been described as a single entity, different units, processors, and / or memory units ( Figure 1 not all shown in
[0022] 5G supports the use of multiple-input multiple-output (MIMO) antennas, far more base stations or nodes than LTE (the so-called small cell concept), including macro sites operating in cooperation with smaller stations, and employs various radio technologies depending on service requirements, use cases, and / or available spectrum. 5G mobile communications supports a wide range of use cases and related applications, including video streaming, augmented reality, different ways of data sharing, and various forms of machine-type applications, including vehicle safety, different sensors, and real-time control. 5G is expected to have multiple radio interfaces, namely below 6 GHz, cmWave, and mmWave, and can also be integrated with existing traditional radio access technologies such as LTE. At least in the early stages, the integration with LTE can be achieved as a system where macro coverage is provided by LTE while 5G radio interface access is through small cells aggregated to LTE. In other words, 5G is planned to support inter-RAT interoperability (such as LTE-5G) and inter-RI interoperability (inter-radio interface interoperability, such as below 6 GHz - cmWave, below 6 GHz - cmWave - mmWave). One of the concepts considered for use in 5G networks is network slicing, where multiple independent and dedicated virtual sub-networks (network instances) can be created within the same infrastructure to run services with different requirements for latency, reliability, throughput, and mobility.
[0023] The current architecture in LTE networks is fully distributed in the radio and fully centralized in the core network. Low-latency applications and services in 5G require bringing content closer to the radio, thus causing local breakout and multi-access edge computing (MEC). 5G enables analysis and knowledge generation to be performed at the data source. This approach requires leveraging resources that may not be continuously connected to the network, such as laptops, smartphones, tablets, and sensors. MEC provides a distributed computing environment for application and service hosting. It is also capable of storing and processing content close to cellular subscribers to accelerate response times. Edge computing encompasses a wide range of technologies, such as wireless sensor networks, mobile data collection, mobile signature analysis, collaborative distributed peer-to-peer ad hoc networking and processing, and can also be classified as local cloud / fog computing and grid / mesh computing, dew computing, mobile edge computing, thin cloud, distributed data storage and retrieval, self-healing autonomous networks, remote cloud services, augmented and virtual reality, data caching, Internet of Things (massive connectivity and / or latency-critical), critical communications (autonomous vehicles, traffic safety, real-time analytics, time-critical control, healthcare applications).
[0024] The communication system is also capable of communicating with other networks (such as the public switched telephone network or the Internet 112) or leveraging the services provided by them. The communication network may also be able to support the use of cloud services. For example, at least part of the core network operations can be performed as cloud services (this is in Figure 1which is represented by the "cloud" 114). The communication system may also include a central control entity, etc., to provide a cooperation facility for the networks of different operators, such as in spectrum sharing.
[0025] The edge cloud can be introduced into the RAN by leveraging Network Function Virtualization (NVF) and Software Defined Network (SDN). Using the edge cloud may mean that the access node operations are at least partially performed in a server, host, or node that is operationally coupled to a remote radio head or unit (RU) or a base station operation including radio components. The node operations may also be distributed among multiple servers, nodes, or hosts. The application of the cloudRAN architecture enables the RAN real-time functions to be executed on the RAN side (in the distributed unit DU 104), and the non-real-time functions to be executed in a centralized manner (in the central or centralized unit CU 108). Thus, in summary, the RAN may include at least one distributed access node, including a central unit, one or more distributed units communicatively connected to the central unit, and one or more (remote) radio heads or units, each radio head or unit being communicatively connected to at least one of the one or more distributed units.
[0026] It should also be understood that the labor distribution between core network operation and base station operation may be different from that of LTE or even non-existent. Some other possible technological advancements are big data and all-IP, which may change the way the network is built and managed. The 5G (or New Radio NR) network is designed to support multiple hierarchies, where the MEC server can be placed between the core and the base station or Node B (gNB). It should be understood that MEC can also be applied to the 4G network.
[0027] 5G can also utilize satellite communication to enhance or supplement the coverage of 5G services, such as by providing backhaul. Possible use cases are to provide service continuity for machine-to-machine (M2M) or Internet of Things (IoT) devices or in-vehicle passengers, or to ensure service availability for critical communications and future railway / maritime / aviation communications. Satellite communication can utilize the geostationary orbit (GEO) satellite system or the low Earth orbit (LEO) satellite system, especially the mega-constellation (a system in which hundreds of (nano) satellites are deployed). Each satellite 106 in the mega-constellation can cover several satellite-enabled network entities that create a ground cell. The ground cell can be created by a ground relay node 104 or by a gNB located on the ground or in a satellite.
[0028] For those skilled in the art, it is obvious that the depicted system is only an example of a part of a radio access system. In practice, the system may include multiple (e / g)NodeBs, user equipment may have access to multiple radio cells, and the system may also include other devices, such as physical layer relay nodes or other network elements, etc. At least one (e / g)NodeB may be a home (e / g)nodeB. Additionally, in the geographical area of a radio communication system, multiple different types of radio cells and multiple radio cells may be provided. A radio cell may be a macro cell (or umbrella cell), which is a large cell, usually with a diameter up to dozens of kilometers, or a smaller cell, such as a micro, femto, or pico cell. Figure 1 The (e / g)NodeBs in Figure 1 may provide any of these types of cells. A cellular radio system may be implemented as a multi-layer network including several types of cells. Generally, in a multi-layer network, one access node provides one or several types of cells, so multiple (e / g)NodeBs are required to provide such a network structure.
[0029] To meet the requirements for the deployment and performance of an improved communication system, the concept of "plug and play" (e / g)NodeB has been introduced. Generally, a network capable of using "plug and play" (e / g)Node B includes, in addition to a home (e / g)NodeB (H(e / g)nodeB), a home node B gateway or HNB-GW ( Figure 1 not shown in Figure 1 ). The HNB gateway (HNB-GW), which is usually installed within the operator's network, can aggregate traffic from a large number of HNBs back to the core network.
[0030] The 6G architecture aims to achieve easy integration of everything, such as networks of networks, joint communication and sensing, non-terrestrial networks, and terrestrial communication. The 6G system is envisioned to include machine learning algorithms as well as local and distributed computing capabilities, where virtualized network functions can be distributed across core and edge computing resources. Far-edge computing, where computing resources are pushed to the very edge of the network, will become part of the distributed computing environment, for example, in "zero-latency" scenarios. The 5G system can also adopt such capabilities. More generally, an actual (radio) communication system is envisioned to include one or more computer programs executed within a programmable infrastructure, such as general computing entities (servers, processors, etc.).
[0031] Figure 2 Shows the architecture of system 100 according to an embodiment. Figure 2 Shows a simplified system architecture that only shows some elements and functional entities. For those skilled in the art, it is obvious that the system may also include other functions and structures.
[0032] System 200 corresponds to a Cooperative Intelligent Transport System (C-ITS). Figure 2 The distributed monitoring system 200 includes a C-ITS wireless communication system (or network) 210 and a C-ITS edge cloud 230 connected to the distributed C-ITS communication system. The C-ITS edge cloud 230 includes a trust management entity (or module or function) 220.
[0033] The C-ITS wireless communication system (or network) 210 includes a plurality of C-ITS stations 211 to 213 distributed in a transportation (or specifically, road) environment. A C-ITS station can generally be defined as a collection of hardware and software components for (or configured to) collect, store, process, receive, and send secure and trusted messages in order to enable the provision of C-ITS services. That is, the plurality of C-ITS stations 211 to 213 cooperate with each other in order to implement and provide ITS services, which offer better quality and enhanced service levels compared to the same ITS services provided by only one of the ITS subsystems.
[0034] Although Figure 2 the plurality of C-ITS stations 211 to 213 are shown as cars, the plurality of C-ITS stations 211 to 213 can generally include, for example, one or more personal C-ITS stations (e.g., user equipment for pedestrians, cyclists, and / or motorcyclists), one or more vehicle C-ITS stations (e.g., cars, trains, and / or trams), and / or one or more (stationary) roadside C-ITS stations. Thus, C-ITS communication can occur between vehicles (vehicle-to-vehicle V2V), between a vehicle and road infrastructure (vehicle-to-infrastructure V2I or I2V), between a vehicle and other (vulnerable) road users such as pedestrians, cyclists, or motorcyclists (vehicle-to-everything V2X), and between elements of road infrastructure (infrastructure-to-infrastructure I2I), such as traffic lights, cameras, sensors, variable message signs (VMS), and / or traffic information centers (TMC).
[0035] The plurality of C-ITS stations 211 to 213 can communicate with each other by exchanging C-ITS messages. These C-ITS messages can also be shared with the C-ITS edge cloud 230. These C-ITS messages can include, for example, cooperative awareness messages (CAM) and / or decentralized environmental notification messages (DENM).
[0036] Examples of functions provided by the C-ITS wireless communication system 210 (i.e., functions provided by the associated C-ITS services) can include sharing sensor data (e.g., video from a car in front of your own car), sharing control information to allow vehicles to drive closely, saving road space, and exchanging vehicle trajectories to prevent collisions.
[0037] Data transmitted within, between, or from multiple C-ITS stations 211 to 213 can be protected using security schemes to ensure the confidentiality and integrity of the transmitted data. This can be particularly important when the multiple C-ITS stations 211 to 213 are on-vehicle C-ITS stations (as incorrect / manipulated data reception can potentially cause serious accidents). Depending on the protection requirements, different security schemes can be used. For example, ISO 15764 defines an extended security scheme. It not only restricts access to the data but also protects the data when transmitted over a data link. Protection is provided against spoofing, replay, eavesdropping, manipulation, and denial. Additionally, before starting a secure data transmission, the data link must be established as a secure link. ISO 15764 provides two methods for this:
[0038] a) Both devices participating in the data transmission have pre-established secret encryption keys. This key is used to establish the secure link and excludes all third parties without access to it from participating in the secure link. This method is based on symmetric keys and is suitable for devices with limited processing capabilities and memory.
[0039] b) If the devices have private keys and security certificates for the corresponding public keys, the secure link can be established between any devices. This method involves asymmetric encryption and requires a higher amount of processing power and memory at the devices.
[0040] A public key is an encryption key that is publicly available and is linked to a private key, which is kept secret by the device that owns it. There are two ways to use a public key / private key pair:
[0041] a) The device that owns the private key can add an electronic signature to the data it sends out. The signature is specific to the data sent out and can only be generated using the private key. Different data strings to be signed and different private keys will both result in different signatures. Any other device that owns the corresponding public key can verify the signature, thus confirming that the data string originated from the device that owns the private key and has not been changed after being sent out.
[0042] b) Any device that owns the public key can use it to encrypt the data before sending it to the device that owns the private key. Since the data can only be decrypted using the private key, no other device can correctly interpret the data sent out.
[0043] But how does the user of a public key know that it is using the correct one? A malicious third party could send its own public key, pretending that it comes from a trusted device and potentially hoping to gain access to secure data transmissions. For each secure data transmission domain, there must be an authority (or several of them) that decides which devices can be trusted. This is called a certification authority. For trusted devices, it issues security certificates that confirm that the public key comes from that device (meaning that the device owns the corresponding private key).
[0044] The C-ITS edge cloud 230 includes computing resources (e.g., processors, memories, etc.) and / or a distributed network of computing devices or a distributed network that are also C-ITS edge nodes. According to the basic edge computing concept, the C-ITS edge cloud 230 is located at the edge of the C-ITS wireless communication system 210 to enable low-latency data processing and real-time decision-making.
[0045] In combination with the embodiments, the C-ITS edge cloud 230 is assumed to include or implement a trust management entity (or module or function) 220 for establishing the trustworthiness of multiple C-ITS stations 211 to 213. Specifically, the trust management entity can be implemented by a specific C-ITS edge node of the C-ITS edge cloud 230. The trust management entity 220 can be, for example, or form part of an edge network controller for controlling the C-ITS edge cloud 230.
[0046] In the following, the functions associated with elements 221 to 224 are only briefly discussed, and a more detailed description of these functions is provided below in combination with Figure 3 、 4 、5A, 5B and 6.
[0047] The trust management entity 220 can include the following four logical elements: a data processing function (or entity) 221, a Hidden Markov Model builder 222, an observer 223, and a trust manager 224.
[0048] The data processing function 221 is configured to receive raw C-ITS message data from multiple C-ITS stations 211 to 213 and process it for use by other functions 222 to 224. For each of the multiple C-ITS stations, this operation may be performed periodically (e.g., every ten minutes) or regularly. The processing of the raw C-ITS message data may include determining values of one or more operating parameters of each of the C-ITS stations 211 to 213 based on the raw C-ITS message data over a (predefined) sliding time window (subsequent analysis thereof being performed based thereon). The one or more operating parameters may include, for example, end-to-end (E2E) delay, throughput, bandwidth, location, speed, rate, acceleration, direction of movement, and / or transmission frequency. Finally, the data processing function may determine whether any road interruptions or events (e.g., accidents) have occurred during the sliding time window based on the raw C-ITS message data.
[0049] As the name implies, the HMM builder 222 is configured to generate and update one or more HMMs based on values of one or more operating parameters of each of the C-ITS stations 211 to 213 obtained via the data processing function 213. That is, each of the one or more operating parameters defined for the C-ITS stations 211 to 213 may be associated with a dedicated HMM configured to model the behavior of that operating parameter.
[0050] According to a general definition, a hidden Markov model (HMM) is a finite model that describes the probability distribution of an infinite number of possible sequences. A hidden Markov model may equivalently be referred to as a hidden Markov chain. An HMM includes multiple states, which may correspond to positions in a 3D structure or multiple aligned columns. Each state "emits" symbols (residues) according to a symbol emission probability, and the states are interconnected by state transition probabilities. Starting from a certain initial state, a sequence of states is generated by moving from one state to another according to the state transition probabilities until a final state is reached. Then, each state emits symbols according to the emission probability distribution of that state, thereby creating an observable sequence of symbols. The sequence of states is a Markov chain because the choice of the next state to occupy depends on the identity of the current state. However, this sequence of states is unobservable: it is hidden. Only the sequence of symbols generated by these hidden states is observed. The most likely sequence of states must be inferred from the alignment of the HMM with the observed sequence. A more specific definition of the (multiple) HMMs used in the embodiments is provided in conjunction with Figure 3 is provided.
[0051] Observer 223 is configured to determine, for each of C-ITS stations 211 to 213, a value of an uncertainty measure corresponding to a sliding time window, based on a value of a classification error detection rate performed by trust manager 224 and a probability of a road interruption (or event) of a previous road interruption detected by data processing function 221. Here, the uncertainty measure is a measure that quantifies the degree of correlation of an atypical (or abnormal) change (e.g., a sudden change) in one or more operation parameters with the credibility of the C-ITS station. The assumption here is that if there are a large number of road interruptions within a certain time gap, it is expected that a given (vehicle) C-ITS station will likely not operate in a normal or typical manner, and thus such an atypical operation (which can actually be considered typical considering the prevalent special circumstances) should not significantly affect the credibility of the C-ITS station. On the other hand, if there are no road interruptions, it should be expected that the C-ITS station will operate in a normal or nominal manner. To evaluate the error detection rate, observer 223 can be configured to periodically or regularly obtain information about the behavior of C-ITS stations 211 to 213 from data processing function 221 via C-ITS stations 211 to 213.
[0052] Trust manager 224 can include two separate functional entities: a trust rate calculator and a trust classifier. The trust rate calculator is configured to calculate, based on the value of the uncertainty measure obtained via observer 223 and the probability of the most likely hidden state sequence (or at least based on said probability), a value of the trust rate of the operation parameters of each C-ITS station. The uncertainty measure is a measure that quantifies the degree of correlation of an atypical (or abnormal) change (e.g., a sudden change) in one or more operation parameters with the credibility of the C-ITS station. The uncertainty measure may depend on the information obtained via the observer (i.e., the error detection rate and / or the probability of a road interruption or event). The probability of the most likely hidden state sequence is determined based on the associated trained hidden Markov model obtained via HMM builder 222. The trust classifier is configured to classify each of the plurality of C-ITS stations as trusted or untrusted based on the calculated trust rate value. This classification can be updated periodically or regularly.
[0053] Figure 3 A process for evaluating the credibility of a C-ITS station according to an embodiment is shown. Figure 3 The process can be executed by a C-ITS edge cloud node or another device or system included in or connected to the C-ITS edge cloud. Performing Figure 3 The device for performing the process can correspond to Figure 2 element 220. The functions shown can be performed by one or more physical devices (e.g., servers). Hereinafter, for simplicity, performing Figure 3An entity in the process is called a device.
[0054] Reference Figure 3 , in block 301, the device obtains one or more trained Hidden Markov Models (HMMs) for modeling the behavior of one or more operating parameters of a C-ITS station (e.g., an on-vehicle C-ITS station) over time. According to the general definition of an HMM, each of the one or more HMMs includes a set of hidden states (which are not directly observable) and a set of observation (or observable) states (also called emissions), where the transitions between the hidden states are controlled by probabilities. Here, the hidden states of the one or more trained HMMs define the expected future behavior of the one or more operating parameters, and the observation states of the one or more trained HMMs define the current state of the corresponding one or more operating parameters.
[0055] An observable sequence of observation states can be obtained and used as input for each of the one or more HMMs. The observation sequence can correspond to a predefined sliding time window. For a given HMM, the observation sequence can be defined as
[0056] Y = {y1, y2,..., y T}, (1)
[0057] where 1, 2,..., T are time indices corresponding to time instances within a predefined sliding time window (i.e., "1" indicates the initial observation within a period of time, and "T" indicates the T-th and last observation within that time window). Each of the one or more HMMs may be associated with a different (but equal-length) observation sequence. Each of the observation states y1, y2,..., y T is selected from an observation state space O, which is defined as
[0058] O = {o1, o2,..., o N}, (2)
[0059] where o1, o2,..., o N are the states that can be observed at a given time t, and N is a positive integer indicating the total number of different observation states. Thus, 1, 2,..., N are indices corresponding to different possible observation states. For example, o1, o2,..., o N can describe the observed behavior of a given operating parameter (e.g., "normal operation" and "abnormal operation"). Thus, for a certain observation time window Y = {o3, o3, o3, o1, o2, o2, o1}, the observation sequence Y can have, for example, the following form.
[0060] The set of hidden states can be defined for each of one or more hidden Markov models. The set of hidden states correspondingly corresponds to an observed state sequence observed over a predefined sliding time window. Each state of the set of hidden states can be a state included in a hidden state space S, which defines all different types of hidden states. Mathematically, the hidden state space S for the operating parameters for each of one or more hidden Markov models can be defined as
[0061] S = {s1, s2, …, s K}, (3)
[0062] where 1, 2, …, K are indices corresponding to different hidden states (e.g., a state indicating an increasing value of an operating parameter, a state indicating a decreasing value of an operating parameter, etc.). Thus, K is a positive integer. How individual states can be defined is discussed separately below.
[0063] For a given hidden Markov model, an array Π (π1, π2, ..., π K ) defining the initial probabilities of transitions between hidden states can be defined as
[0064] Π = {π1, π2, ..., π K}, (4)
[0065] where π i is the probability that the given hidden Markov model will start in state s i (i having an integer value from 1 to K). The initial probability array Π can be defined such that the following conditions are satisfied:
[0066]
[0067] The probabilities in the array Π can be initialized by the device, for example, using a random uniform distribution, giving values between 0 and 1. State transitions can be collected into a transition matrix A of size K×K such that the element A ij stores the transition probability from state s i to state s j .
[0068] An emission matrix B of size K×N such that B ij stores the probability of observing the observed state o i from the hidden state s j . Given that the state at the corresponding time is s i , then it is the probability that the hidden state generates the output v i . The device can evenly divide the training data and calculate for each segment s iInitialize the emission matrix B with the global mean and variance. Alternatively, the device may obtain a trained emission matrix B from another device.
[0069] In some embodiments, each of the one or more trained hidden Markov models has (different) hidden states (s1, s2,..., s K ) that at least include (or consist of):
[0070] · One or more states indicating a (predicted) future increase in one or more corresponding different magnitudes of the associated operating parameter,
[0071] · One or more states indicating a (predicted) future decrease in one or more corresponding different magnitudes of the associated operating parameter, and
[0072] · A state indicating that the associated operating parameter will remain substantially unchanged in the future.
[0073] The expression "substantially unchanged" (or equivalently "substantially constant") can be defined herein and hereinafter as a change within a predefined range. Thus, if the change in the operating parameter is not within this predefined range, the hidden state here is equal to one of the one or more states indicating a future increase or the one or more states indicating a future decrease. Different magnitudes of increase / decrease (herein and in the following definitions) may be associated with different ranges of the positive / negative slope (or gradient) of the associated operating parameter. To give a more specific non-limiting example, the hidden state space of each of the one or more hidden Markov models may include the following different (mutually exclusive) states: a major future increase in the value of the operating parameter, a minor future increase in the value of the operating parameter, a major future decrease in the value of the operating parameter, a minor future decrease in the value of the operating parameter, and the value of the operating parameter remaining substantially constant in the future.
[0074] In a particular case of the embodiment described in the previous paragraph, each of the one or more trained hidden Markov models has hidden states (s1, s2,..., s K ) that at least include (or consist of): a state indicating a future increase in the associated operating parameter, a state indicating a future decrease in the associated operating parameter, and a state indicating that the associated operating parameter will remain substantially unchanged in the future. The expression "substantially unchanged" can be defined to mean a change within a predefined range. Thus, if the change in the operating parameter is not within this predefined range, the hidden state is equal to the state indicating a future increase in the associated operating parameter or the state indicating a future decrease in the associated operating parameter.
[0075] The observation states can be defined in a manner similar to the hidden states. Thus, in some embodiments, the observation states (o1, o2, ..., o N ) of each of the one or more trained hidden Markov models include (or consist of) at least: one or more states indicating an increase in one or more corresponding different magnitudes of the associated operating parameter, one or more states indicating a decrease in one or more corresponding different magnitudes of the associated operating parameter, and a state indicating that the associated operating parameter remains substantially unchanged. For example, the observation states of each of the one or more trained hidden Markov models can include (consist of) at least the following (mutually exclusive) states: a state indicating an increase in the associated operating parameter, a state indicating a decrease in the associated operating parameter, and a state indicating that the associated operating parameter remains substantially unchanged. As another non-limiting example, the hidden state space of each of the one or more trained hidden Markov models can include the following different (mutually exclusive) states: a major increase in the value of the operating parameter, a slight increase in the value of the operating parameter, a major decrease in the value of the operating parameter, a slight decrease in the value of the operating parameter, and the value of the operating parameter remaining substantially unchanged. It should be emphasized that the increase / decrease / unchange in the value of the operating parameter as discussed in this paragraph refers to the observed increase / decrease / unchange, rather than the predicted future increase / decrease / unchange as in the case of the hidden states.
[0076] In some alternative embodiments, the observation states can be defined in an alternative manner. That is, the observation states of each of the one or more trained hidden Markov models include at least: a state indicating that the associated operating parameter has a normal or nominal value and a state indicating that the associated operating parameter has an outlier value. The outlier value can correspond to, for example, a sufficiently sharp increase or decrease in the value of the operating parameter.
[0077] The obtaining of the one or more trained hidden Markov models in block 301 can correspond to the training by the device itself of one or more (predefined) hidden Markov models based on training data or obtaining or receiving one or more trained hidden Markov models from another device. In the latter case, the other device may have trained the one or more trained hidden Markov models.
[0078] In block 302, the device receives one or more C-ITS messages from a C-ITS station. The one or more C-ITS messages include values of one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window. The plurality of consecutive time instances may correspond to the predefined sliding time window. In some embodiments, the one or more C-ITS messages may further include information about one or more road disruptions or events that occur at the respective one or more time instances within the predefined sliding time window. The one or more C-ITS messages may be received via at least one C-ITS edge (cloud) node.
[0079] In some embodiments, one or more operating parameters of the device may include at least one of the following: end-to-end (E2E) delay, throughput, bandwidth, location, speed, rate, acceleration, direction of movement, or transmission frequency.
[0080] In some embodiments, the one or more C-ITS messages may be or include one or more Cooperative Awareness Messages (CAMs). The one or more CAMs may include all or at least some of the values of one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window.
[0081] A CAM is a C-ITS broadcast message that vehicles send to each other to share important information about their current state and the surrounding environment. A CAM may include, for example, basic vehicle information (e.g., the size, type, and / or unique identifier of the vehicle), location and speed information (e.g., the current location, heading, and speed of the vehicle), acceleration and deceleration information, heading and orientation information, vehicle dynamics information (e.g., yaw rate or wheel slip), and / or the state of vehicle systems (e.g., information about the state of critical vehicle systems such as lights, brakes, or stability control).
[0082] In some embodiments, the one or more C-ITS messages may include one or more Decentralized Environmental Notification Messages (DENMs), as will be described in further detail in conjunction with Figure 4 Further detailed description.
[0083] In block 303, the device determines a set of one or more consecutive observation states based on the one or more C-ITS messages. The one or more sets are correspondingly related to one or more operating parameters. In other words, the one or more sets are specific to the operating parameters. The observation states correspond to the observation states of one or more of the Hidden Markov Models defined above. The set of consecutive observation states may also be referred to as a sequence of observation states Y, as described above.
[0084] In block 304, the device determines one or more probability distributions of the most likely paths through one or more hidden Markov models (i.e., the most likely sequence of hidden states) based on one or more sets of consecutive observed states, using the Viterbi algorithm. In other words, for each of the one or more hidden Markov models (which are specific to the operating parameters), the device determines the probability distribution of the most likely path through the hidden Markov model based on the associated set of consecutive observed states. The Viterbi algorithm is a well-known dynamic programming algorithm that is specifically designed to find the most likely sequence of hidden states in a hidden Markov model that will generate a given sequence of observations. A path through a hidden Markov model corresponds to a set of consecutive hidden states, i.e., a sequence of hidden states. Thus, in block 304, the device determines one or more probability distributions for the set of consecutive hidden states for the corresponding one or more hidden Markov models, i.e., {V t,k} 1,...,n list.
[0085] In some embodiments, before determining one or more probability distributions of the most likely paths through one or more hidden Markov models in block 304, the device may initialize one or more hidden Markov models by randomly assigning initial hidden states to each of the one or more hidden Markov models.
[0086] In block 305, the device determines one or more values of the trust rate based at least on the discrete quantity in one or more probability distributions of the most likely paths. The one or more values of the trust rate correspondingly correspond here to one or more operating parameters of the C-ITS station or equally correspond to one or more hidden Markov models (specific to the operating parameters). If the discrete quantity of the probability distribution of the most likely path is low, then the most likely path of the hidden Markov model is likely to correspond to reality. On the other hand, if the discrete quantity of the probability distribution of the most likely path is high, then multiple paths of the hidden Markov model
[0087] The discrete quantity of one or more probability distributions in block 305 can be quantified, for example, as the standard deviation of one or more probability distributions. Thus, in block 305, the device may determine each value of the trust rate based at least on the standard deviation of the probability distribution of the most likely path. The trust rate can be defined such that as the value of the standard deviation increases, the trust rate value increases, and as the value of the standard deviation increases, the trust rate value decreases. For example, the trust rate can be defined as being inversely proportional to the standard deviation, or inversely proportional to the nth power of the standard deviation, where n is a real number, such as 2.
[0088] In some embodiments, the determination of the trust rate in block 305 may also be based on the value of an uncertainty metric that quantifies the uncertainty about the degree of correlation between an atypical change (e.g., a sudden change) in one or more operating parameters and the credibility of the C-ITS station (as will be described in detail in conjunction with Figure 4 ).
[0089] In block 306, the device classifies the C-ITS station as trusted or untrusted based on one or more values of the trust rate.
[0090] In some embodiments, the classification in block 306 may be performed using a decision tree classifier. A decision tree classifier is a machine learning model that uses a tree data structure to make decisions or predictions based on input features. Here, the (input) features of the decision tree classifier are the values (or, in some embodiments, the normalized values) of one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window, and the (output) label of the decision tree classifier is the class for the C-ITS station (i.e., "trusted" and "untrusted"). Additionally, the class weights of the decision tree classifier for different classes (i.e., "trusted" and "untrusted") are defined (or trained) based on one or more values of the trust rate (i.e., {tr} 1,...,n ). According to the general definition, class weights are hyperparameters of the decision tree that are used to adjust an imbalanced dataset where one class constitutes the majority of the data (here, most C-ITS stations are typically trusted C-ITS stations). In other words, different (class) weights are assigned to each class during the training phase so that the contribution of each class is balanced. The class weight modification is used to evaluate the criteria for splitting points in the tree in order to consider the importance of each class. Therefore, the decision tree classifier can be specifically a weighted decision tree classifier (i.e., a decision tree classifier that employs weighted splitting points).
[0091] The (weighted) decision tree classifier may have been previously trained by the device itself based on a training dataset. Alternatively, the (weighted) decision tree classifier may have been previously trained by another device based on a training dataset and subsequently sent to the device that performs Figure 3 the process. The other device may also be located in the C-ITS edge cloud.
[0092] In some embodiments, the device may output classification data (i.e., the class assigned to the C-ITS station) via at least one interface. For example, the device may output the classification data via the at least one interface to another device for making a decision to grant or revoke a security or trust certificate for the C-ITS station based at least on the classification. Additionally or alternatively, the device may store the classification data in at least one memory.
[0093] In some embodiments, the output and / or stored classified data (or the output and / or stored classified data collected over time during multiple repetitions of the Figure 3 process) can then be used to make a decision on granting or denying (or revoking) a security or trust certificate for a C-ITS station, as described above. The decision can be made by the device or the other device to which the classified data is output. In the latter case, the other device can be, for example, a separate certificate revocation entity or device. The separate certificate revocation entity or device can be deployed, for example, in a C-ITS edge cloud. The certificate revocation entity or device can generally be configured to revoke the certificate of a particular vehicle C-ITS station if the behavior of the particular vehicle C-ITS station is considered suspicious (such as when the C-ITS station is classified as untrusted by a trust manager). After the denial or revocation of the security or trust certificate of a C-ITS station, other C-ITS stations can be configured to distrust any signals or data received from the C-ITS station.
[0094] Referring Figure 2 to elements 221 to 224 of
[0095] , the actions associated with blocks 301, 302, block 304, block 303, and blocks 305, 306 can be performed by data processing entity 221, HMM builder 222, observer 223, and trust manager 224, respectively.
[0096] Although the Figure 3 process has been discussed above for simplicity to evaluate the trustworthiness of a single C-ITS station, it should be understood that in practice, the process can be applied to evaluate the trustworthiness of multiple C-ITS stations.
[0097] Figure 4 FIG. Figure 4 shows another process for evaluating the trustworthiness of a C-ITS station according to an embodiment. The Figure 4 process can be executed by a C-ITS edge cloud node or another device or system included in or connected to the C-ITS edge cloud. The device that executes the Figure 2 process can correspond to element 220 of Figure 4 . The functions shown can be performed by one or more physical devices (e.g., servers). Hereinafter, for simplicity, the entity that executes the
[0098] Figure 4 process is referred to as a device. Figure 3 TheFigure 4 Blocks 401 to 404, 408 can exactly correspond to Figure 3 Blocks 301 to 304, 306. Any features discussed in relation to Figure 3 can be applicable to Figure 4 , with necessary modifications.
[0099] As described above, Figure 4 the initial steps of the process correspond to Figure 3 the initial steps of, and thus for the sake of brevity are not discussed here. Figure 3 and Figure 4 The difference between and lies in the additional steps 405, 406 for providing additional information on the value(s) that can be used to calculate the trust rate in block 407. That is, in block 405, the device determines the number of road interruptions (or road events) at the location of the C-ITS station within a predefined sliding time window (i.e., the time window used for observation) based on one or more C-ITS messages.
[0100] One or more C-ITS messages (or at least some of them) can (explicitly) include information about the detected road events or interruptions. For example, one or more C-ITS messages can include one or more Decentralized Environmental Notification Messages (DENM), which by definition include information about road events (i.e., environmental events and / or hazards).
[0101] DENM is a message used in C-ITS to facilitate communication between vehicles and infrastructure elements regarding environmental conditions. DENM plays a crucial role in improving road safety and traffic efficiency by allowing vehicles and infrastructure to share information about environmental events and hazards. DENM can include, for example, event and / or hazard information (such as environmental event or hazard information, such as accidents, road construction, adverse weather conditions or obstacles on the road), geospatial information (such as the geographical location and extent of the reported event or hazard), time information (such as the time of the reported event or hazard), event type (i.e., the type of environmental event or hazard, such as an accident, slippery road conditions or the presence of pedestrians), severity and impact information (i.e., information about the severity and potential impact of the event or hazard) and / or sender information (such as the identifier of the DENM sender).
[0102] A road disruption or event can be defined as an event or situation that is notable or significant within the road environment. A road disruption or event may have an impact on traffic, safety, or the overall mobility environment (including, for example, the road environment and associated communication systems). Environmental events or hazards (such as those described above in relation to DENM) may be types of road disruptions or events. Examples of road disruptions or events may include road accidents, collisions, traffic congestion, construction zones, road closures, adverse weather conditions (e.g., heavy rain or snow, icing, or fog), special events (e.g., parades, marathons, or festivals or other large gatherings of people), the presence of emergency vehicles, accidents involving hazardous materials, traffic signal failures, public transportation disruptions, animals (e.g., moose) crossing the road, and / or adverse road surface conditions (e.g., potholes). If a specific road disruption or event occurs on the road, the behavior of vehicle C-ITS stations (such as cars) will also be affected. Under these conditions, the behavior of C-ITS stations may change suddenly due to these external factors. Clearly, even if the behavior of C-ITS messages may be considered abnormal or irregular, this should not affect the trustworthiness of C-ITS stations. Therefore, unless these road disruptions are taken into account in the trust rate, this situation may trigger the detection of false anomaly signals.
[0103] In block 406, the apparatus determines a value of an uncertainty metric based at least on the number of road disruptions or events determined in block 405. The uncertainty metric quantifies the degree of uncertainty regarding the correlation between atypical variations (e.g., sudden variations) in one or more operating parameters and the trustworthiness of the C-ITS station. The same value of the uncertainty metric may apply to the analysis of all (i.e., for all of one or more hidden Markov models) of the one or more operating parameters, that is, the value of the uncertainty metric may not be specific to a particular operating parameter or hidden Markov model.
[0104] In some embodiments, determining the value of the uncertainty metric in block 406 may also be based on an error detection rate. The error detection rate corresponds to the failure rate of classification. The error detection may have a predefined (constant) value, or it may have a value that is dynamically updated by the apparatus. The latter alternative will be described in further detail in conjunction with Figure 5A and 5B and is further described in detail.
[0105] In some embodiments, the uncertainty metric α(t) can be defined as
[0106]
[0107] where “fdr” is the false detection rate, p(event) is the probability that a road disruption or event occurs within a predefined sliding time window, and n is the number of road disruptions or events observed within the predefined sliding time window (determined based on one or more C-ITS messages). Thus, the term (1-(1-p(event)) n ) is the probability that n road disruptions or events occur within the predefined sliding time window. Thus, if a large number of road disruptions or events are observed, the value of the uncertainty metric is very low, which indicates high uncertainty. In other words, due to the large number of road disruptions or events, it is difficult to accurately estimate the trustworthiness of the C-ITS station because the behavior of the C-ITS station may be abnormal due to those road disruptions or events in any case. In some embodiments, the false detection rate term “fdr” may be omitted from (6), or it may have a predefined constant value.
[0108] In block 407, the apparatus determines one or more values of the trust rate based on a discrete quantity of one or more probability distributions of the most likely path (as described in connection with Figure 3 block 305 above) and the value of the uncertainty metric.
[0109] In some embodiments, the trust rate “tr” for a given operating parameter (or equivalently for a given hidden Markov model) may be defined as
[0110]
[0111] where “SD” represents the standard deviation (calculated according to index k), and V t,k is the probability distribution of the most likely hidden state sequence (i.e., the most likely path). In some embodiments, the square in (7) may be omitted (i.e., the exponent “2” may be replaced with 1) or the exponent “2” may be replaced with another exponent greater than 0 (or possibly greater than 1).
[0112] Subsequently, one or more values of the trust rate are used by the apparatus to classify the C-ITS station as trusted or untrusted in block 408, similar to that described in connection with Figure 3 block 306 above.
[0113] Referring to Figure 2 elements 221 to 224, the actions related to blocks 401, 402, block 404, block 403, 405, 406, and blocks 407, 408 may be performed by data processing entity 221, HMM builder 222, observer 223, and trust manager 224, respectively.
[0114] The processes related to blocks 402 to 408 may be repeated periodically (e.g., every ten minutes) or regularly.
[0115] Figure 5A shows another process for evaluating the trustworthiness of a C-ITS station according to an embodiment, while Figure 5B further shows in detail an implementation of block 506 of FIG. 5 according to an embodiment. Figure 5A The process of 5 and / or 5B can be executed by a C-ITS edge cloud node or another device or system included in or connected to the C-ITS edge cloud. The device that executes Figure 5A the process of 5 and / or 5B can correspond to Figure 2 element 220. The functions shown can be executed by one or more physical devices (e.g., servers). Hereinafter, for simplicity, the entity that executes Figure 5A and 5B the process is referred to as a device.
[0116] Figure 5A the process of is largely corresponding to Figure 3 the process of 4 and / or 4. That is, Figure 5A blocks 501 to 505, 508 to 509 of can completely correspond to Figure 4 blocks 401 to 408 of 4. Any features discussed in relation to Figure 3 4 and / or Figure 4 can be applicable to Figure 5A , with necessary modifications.
[0117] As described above, Figure 5A the initial steps of the process of correspond to Figure 4 (and / or Figure 3 )'s initial steps, so for the sake of brevity, they will not be discussed here. Figure 5A The difference between and Figure 3 4 and Figure 4 4 lies in the additional step 506. That is, in block 506, the device tracks the error detection rate of the device classification process over time (e.g., within a predefined sliding time window). As discussed in relation to the previous embodiment, the classification process can be executed periodically or regularly for one or more C-ITS stations. During these periodic repetitions, the device monitors the error detection rate, that is, the failure rate of classification. The error detection rate can be defined as the number of error detections (i.e., misclassifications) divided by the total number of detections (or classifications).
[0118] The error detection rate can be determined as follows. The device can obtain (periodically or regularly) the behavior information on the C-ITS station (e.g., a metric value describing the number of speeding violations and / or the average distance between C-ITS stations) from the C-ITS station, perform anomaly detection based on the classification of the C-ITS station and the behavior information of the C-ITS station (i.e., whether the behavior information indicates normal or abnormal behavior), and calculate the error detection rate based on the results of the anomaly detection. According to the combination with Figure 5BIn some embodiments, after discussing Figure 5A the determination of the error detection rate is discussed in further detail.
[0119] In block 507, the apparatus determines the value of an uncertainty measure based on the number of road disruptions or events determined in block 505 and the value of the error detection rate determined in block 506. The value of the uncertainty measure α(t) can be determined, for example, according to (6).
[0120] Figure 5A The following steps 508 to 509 in can be performed as described above, for example, in conjunction with Figure 3 blocks 305 to 306 in and / or Figure 4 blocks 407 to 408 in.
[0121] As described above, Figure 5B illustrates a process for tracking (i.e., calculating periodically or regularly) the error detection rate based on anomaly detection of the behavior information of a C-ITS station. Figure 5B The process of can be Figure 5A performed in parallel with other processes of. Figure 5B illustrates the tracking of the error detection rate for one C-ITS station (specifically, an on-vehicle C-ITS station), but it should be understood that in practice, the corresponding process can be performed in parallel for multiple C-ITS stations. Figure 5B The process of can be performed by the apparatus that performs the Figure 5A process of (e.g., by the Figure 2 trust manager 224 of ).
[0122] Initially, in block 511, the device obtains the behavior information of the C-ITS station from the C-ITS station. The behavior information of the C-ITS station (here assumed to be a vehicle C-ITS station) may include one or more values of one or more behavior metrics. The one or more behavior metrics may include, for example, the number of speeding violations and / or the number of speeding violations (e.g., exceeding the speed limit by at least a predefined amount) and / or the average distance between (vehicle) C-ITS stations (i.e., the average distance between the current C-ITS station and any other (vehicle) C-ITS station). The one or more behavior metrics may be given with respect to a predefined duration (e.g., one hour), i.e., the number of (speeding) violations in the last predefined duration and / or the average distance between (vehicle) C-ITS stations in the last predefined duration. In some embodiments, the predefined duration may correspond to a predefined sliding time window. The (multiple) C-ITS stations may be configured to send the behavior information to the device periodically or regularly (e.g., at a periodic time instance corresponding to the end of a classification operation). Alternatively, the device may poll the C-ITS stations periodically or regularly (e.g., at a periodic time instance corresponding to the end of a classification operation) in block 511 to cause them to send the behavior information to the device. In either case, the behavior information may be obtained using Figure 2 observer 223 of
[0123] The anomaly detection performed based on the behavior information obtained from the C-ITS station includes the following steps. In block 512, the device compares one or more values of each behavior metric defined in the behavior information for the C-ITS station with a predefined threshold for that behavior metric. In response to at least one value of one or more behavior metrics defined for the C-ITS station exceeding the associated predefined threshold in block 513, the device marks the C-ITS station as untrusted in block 514. On the other hand, in response to none of the values of one or more behavior metrics defined for the C-ITS station in block 513 exceeding the associated predefined threshold, the device marks the C-ITS station as trusted in block 515. Here, exceeding the predefined threshold may correspond to, for example, the number of (speeding) violations within a predefined duration (e.g., one hour) exceeding the predefined threshold for the number of (speeding) violations within the predefined duration, or correspond to the average distance between (vehicle) C-ITS stations exceeding the predefined threshold for the average distance between (vehicle) C-ITS stations. It should be emphasized that this marking operation is independent of the classification operation performed on the C-ITS station. As the last step of the anomaly detection, the device determines in block 516 whether the classification of the C-ITS corresponds to a true positive, false positive, true negative, or false negative based on the marked status (i.e., "trusted" or "untrusted") of the C-ITS station. In other words, in block 516, the device compares the latest classification of the C-ITS station with the flag status defined in block 514 or 515 to see if they match. If they do not match, an anomaly (i.e., false positive or false negative) is detected.
[0124] In response to the predefined trigger condition not being satisfied in block 517, the device repeats the actions related to blocks 511 to 517. The predefined trigger can be specific to the C-ITS station. The predefined trigger condition can be, for example, that a predefined number of repetitions of blocks 511 to 516 have been reached, or a predefined timer (corresponding to the error detection rate) has expired. During these repetitions, the actions related to Figure 5A blocks 502 to 509 are executed in parallel.
[0125] In response to the predefined trigger condition being satisfied in block 517, the device determines in block 518 the error detection rate for the C-ITS station based on the results of the anomaly detection collected (determined in one or more repetitions of block 516). The error detection rate can be simply defined as the ratio between the number of classifications considered as errors (i.e., corresponding to false positives and / or false negatives) and the total number of classifications. After the determination of the error detection rate in block 518, the predefined trigger (i.e., the timer or counter for counting the repetitions of blocks 511 to 517) can be reset by the device.
[0126] In some alternative embodiments, Figure 5BThe process can be performed by another device communicatively connected to the device performing the Figure 5A process. In such an embodiment, the other device can be configured to send a determined error detection rate to the device periodically or cyclically, or in response to the error detection rate being determined. Thus, Figure 5A tracking of the error detection rate in block 506 of
[0127] can correspond to receiving one or more values of the error detection rate for a C-ITS station (or, generally, for one or more C-ITS stations via at least one interface from the other device). Figure 3 , 4 , 5A, and 5B before (and possibly during) the execution of any one of the processes. This training can be performed by the device that also performs the "online" calculations or by another separate device. Figure 6 illustrates a process for training one or more hidden Markov models according to an embodiment. Figure 6 The process can be performed by a C-ITS edge cloud node or another device or system included in or connected to the C-ITS edge cloud. The device performing the Figure 6 process can correspond to Figure 2 element 220 of Figure 2 or a device communicatively connected to element 220 of Figure 6 The functions shown can be performed by one or more physical devices (e.g., servers). Hereinafter, for simplicity, the entity performing the
[0128] Referring to Figure 6 , in block 601, the device holds one or more untrained hidden Markov models in at least one memory for modeling the behavior of corresponding one or more operating parameters of a C-ITS station over time. The hidden states of one or more trained hidden Markov models define the expected future behavior of the corresponding one or more operating parameters, and the observed states of one or more trained hidden Markov models define the current state of the corresponding one or more operating parameters. Since the one or more hidden Markov models are untrained, the emission matrix of the one or more hidden Markov models (which defines the probability between the observed state and the hidden state) does not yet have an appropriate form for accurately modeling the behavior of the corresponding one or more operating parameters of the C-ITS station over time.
[0129] In block 602, the device obtains training data that includes a set of observed states and a corresponding set of known hidden states for each of one or more operating parameters (i.e., for each of one or more untrained hidden Markov models). The training data corresponds to the expected behavior of one or more operating parameters of the C-ITS station. The training data may have been collected / generated based on historical operating data of the C-ITS station.
[0130] In block 603, the device trains one or more emission matrices of one or more untrained hidden Markov models based on the training data to form one or more trained hidden Markov models. In other words, the device trains the probability associated with a given observed state that gives rise to a given hidden state in one or more hidden Markov models. The device may initialize each emission matrix by evenly partitioning the associated training data and calculating the global mean and variance for each segment.
[0131] If the device is also intended to perform online calculations using one or more hidden Markov models, the device performs any of the above processes associated with Figure 3 、 4 and 5A (or Figure 5A associated with Figure 5B in combination) in block 604a.
[0132] Alternatively, if the device for performing (offline) training and the device for performing online calculations are separate devices, the device outputs one or more trained hidden Markov models via at least one interface in block 604b. The one or more trained hidden Markov models may be output directly or via one or more other devices to a device configured to perform classification based on one or more hidden Markov models.
[0133] Although the embodiments discussed above are specifically directed to C-ITS use cases, in other embodiments, any of the above functions may be applied to the Industrial 4.0 space with necessary modifications. In such embodiments, the terms "C-ITS wireless communication system", "C-ITS message", and "C-ITS edge cloud" may be simply replaced, for example, with the terms "Industrial IoT wireless communication system", "message", and "edge cloud" (or "Industrial IoT edge cloud") respectively. In these embodiments, Figure 2The C-ITS stations 211 to 213 of the C-ITS wireless communication system 210 can be replaced by mobile (industrial) IoT devices (such as robots and / or drones) of the wireless communication system 210. The mobile IoT devices can be IoT devices capable of autonomous movement (such as drones or robots). Additionally, in this use case, the mobile IoT devices can be configured to exchange messages with each other and with the edge cloud. The mobile IoT devices can operate in an industrial environment, such as in a smart factory. In this use case, these embodiments can be adopted, for example, to detect improper behavior of mobile IoT devices (such as robots and drones). Based on whether the mobile IoT devices are classified as trusted or untrusted, the device to which the classification information is output or another device can grant or revoke the security or trust certification of the mobile IoT devices, similar to the detailed description related to the C-ITS use case.
[0134] Therefore, the process according to the embodiment corresponding to Figure 3 can alternatively include the following steps:
[0135] In block 301, obtain one or more trained hidden Markov models for modeling the behavior of corresponding one or more operating parameters of the mobile IoT device over time, where the hidden states of the one or more trained hidden Markov models define the expected future behavior of the corresponding one or more operating parameters, and the observation states of the one or more trained hidden Markov models define the current state of the corresponding one or more operating parameters;
[0136] In block 302, receive one or more messages from the mobile IoT device, where the one or more messages include: values for one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window;
[0137] In block 303, determine one or more sets of consecutive observation states based on the one or more messages, where the one or more sets are correspondingly related to one or more operating parameters;
[0138] In block 304, based on the one or more sets of consecutive observation states, use the Viterbi algorithm to determine one or more probability distributions of the most likely paths through the one or more hidden Markov models;
[0139] In block 305, determine one or more values of the trust rate based at least on a discrete quantity in the one or more probability distributions; and
[0140] In block 306, classify the mobile IoT device as trusted or untrusted based on the one or more values of the trust rate.
[0141] In some embodiments, the above process may further include (similar to Figure 4 blocks 405 to 406):
[0142] Determining, based on one or more messages, the number of interruptions within a predefined sliding time window at the location of the mobile IoT device during multiple consecutive time instances (e.g., interruptions in an industrial environment such as a factory floor); and
[0143] Determining a value of an uncertainty metric based at least on the number of interruptions, where the uncertainty metric quantifies the degree of uncertainty regarding the correlation between atypical variations in one or more operating parameters and the trustworthiness of the mobile IoT device.
[0144] In these embodiments, the determination of one or more values of the trust rate may also be based on the value of the uncertainty metric. One or more messages may (explicitly include information regarding the number of interruptions).
[0145] The above embodiments provide at least the following advantages:
[0146] · The trustworthiness of C-ITS stations in the C-ITS domain or (mobile) IoT devices in the (industrial) IoT domain is increased,
[0147] · The dynamic calculation of the trust rate allows for real-time implementation as it does not require a prior training step, e.g., for a neural network-based solution,
[0148] · The safety requirements of the automotive certification process are met as the embodiments comply with the need to track and detect misbehavior in connected and automated driving systems, and
[0149] · An improved guarantee of the safety of CAVs (connected and automated vehicles) can be provided,
[0150] This helps to increase the public acceptance rate of the new generation of vehicles.
[0151] The above-described blocks, related functions, and information exchanges through Figures 2 to 4 5A, 5B, and 6 are not in an absolute chronological order, and some of them may be executed simultaneously or in an order different from the given order. Other functions may also be executed between or within them, and other information may be sent and / or other rules may be applied. Some blocks or partial blocks or one or more pieces of information may also be omitted, or replaced with corresponding blocks or partial blocks or one or more pieces of information.
[0152] Figure 7 An apparatus 701 according to some embodiments is provided. Specifically, Figure 7A device 701 that communicates with an edge cloud of a wireless communication system (or network) or is included in the edge cloud may be shown. Here, the wireless communication system may be, for example, a C-ITS wireless communication system or an industrial IoT wireless communication system. The device 701 may be a device for training one or more hidden Markov models and / or for performing (online) calculations using one or more trained hidden Markov models.
[0153] The device 701 may include one or more communication control circuitry 720, such as at least one processor, and at least one memory 730, including one or more algorithms 731 (instructions), such as computer program code (software), where the at least one memory and the computer program code (software) are configured to cause the device 701 to perform any of the exemplary functions of the device described above in conjunction with the at least one processor. The at least one memory 730 may also include at least one database 732.
[0154] When one or more communication control circuitry 720 includes more than one processor, the device 701 may be a distributed device where the processing of tasks occurs in more than one physical unit. Each of the at least one processor may include one or more processor cores. The processing cores may include, for example, Cortex-A8 processing cores manufactured by ARM Holdings or Zen processing cores designed by Advanced Micro Devices Corporation. One or more communication control circuitry 720 may include at least one Qualcomm Snapdragon and / or Intel Atom processor. One or more communication control circuitry 720 may include at least one application-specific integrated circuit (ASIC). One or more control circuitry 720 may include at least one field-programmable gate array (FPGA).
[0155] Reference Figure 7 , one or more communication control circuitry 720 of the device 701 are configured to perform the functions of the device described above using one or more separate circuitry through Figures 2 to 4 , Figure 5A , Figure 5B and Figure 6 any one of. According to different embodiments, it is also feasible to implement the functions using application-specific integrated circuits (such as ASICs (application-specific integrated circuits)) or other components and devices.
[0156] Reference Figure 7, the apparatus 701 may further include different interfaces (I / F) 710, such as one or more communication interfaces, including hardware and / or software for implementing communication connectivity according to one or more communication protocols. One or more communication interfaces 710 may include, for example, at least one communication interface between the apparatus 701 and an edge cloud or one or more devices or nodes of the edge cloud. One or more communication interfaces 710 may include, for example, at least one communication interface between the apparatus 701 and one or more C-ITS stations (or one or more IoT devices in embodiments related to Industry 4.0).
[0157] In some embodiments, one or more communication interfaces 710 may include at least one communication interface between the apparatus 701 and another apparatus, where the apparatus 701 is for training one or more hidden Markov models, and the other apparatus is for performing (online) calculations using one or more trained hidden Markov models.
[0158] One or more communication interfaces 710 may include standard well-known components, such as amplifiers, filters, frequency converters, (de)modulators, and encoder / decoder circuitry controlled by corresponding control units, as well as one or more antennas. The apparatus 701 may further include one or more user interfaces.
[0159] Reference Figure 7 , the memory 730 may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory.
[0160] As used in this application, the term "circuitry" can refer to one or more or all of the following: (a) only hardware circuit implementations, such as only analog and / or digital circuitry implementations, and (b) combinations of hardware circuits and software (and / or firmware), such as (where applicable): (i) combinations of analog and / or digital hardware circuits and software / firmware, and (ii) any portion of a (multiple) hardware processor having software, including (multiple) digital signal processors, software, and (multiple) memories, which work together to enable a device, such as a terminal device or an access node, to perform various functions, and (c) (multiple) hardware circuits and (multiple) processors, such as (multiple) microprocessors or a portion of (multiple) microprocessors, which require software (e.g., firmware) to operate, but the software may be absent when the operation does not require software. This definition of "circuitry" applies to all uses of the term in this application, including any claims. As a further example, as used in this application, the term "circuitry" also encompasses implementations of only hardware circuits or processors (or multiple processors) or a portion of a hardware circuit or processor and their (or their) attendant software and / or firmware.
[0161] In an embodiment, at least some of the processes associated with Figures 2 to 4 , Figure 5A , Figure 5B and Figure 6 can be performed by a device including corresponding components for performing at least some of the processes. Some example components for performing processes can include at least one of the following: detectors, processors (including dual-core and multi-core processors), digital signal processors, controllers, receivers, transmitters, encoders, decoders, memories, RAM, ROM, software, firmware, displays, user interfaces, display circuitry, user interface circuitry, user interface software, display software, circuits, filters (low-pass, high-pass, band-pass, and / or band-stop), sensors, circuitry, inverters, capacitors, inductors, resistors, operational amplifiers, diodes, and transistors. In an embodiment, at least one processor, memory, and computer program code form a processing component or include one or more portions of computer program code for performing one or more operations in accordance with Figure 3 , Figure 4 , Figure 5A , Figure 5B and Figure 6 or an operation thereof. In some embodiments, at least some of the processes can be implemented using discrete components.
[0162] According to one embodiment, there is provided a device including components for performing the following:
[0163] Obtain one or more trained Hidden Markov Models for modeling the behavior of corresponding one or more operating parameters of a device over time, wherein the hidden states of the one or more trained Hidden Markov Models define the expected future behavior of the corresponding one or more operating parameters, and the observation states of the one or more trained Hidden Markov Models define the current state of the corresponding one or more operating parameters, and the device is a Cooperative Intelligent Transport System (C-ITS) station (e.g., an in-vehicle C-ITS station) or a Mobile Internet of Things (IoT) device;
[0164] Receive one or more messages from the device, wherein the one or more messages include values of one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window;
[0165] Based on the one or more messages, determine one or more sets of consecutive observation states, wherein the one or more sets are correspondingly related to the one or more operating parameters;
[0166] Based on the one or more sets of consecutive observation states, use the Viterbi algorithm to determine one or more probability distributions of the most likely paths through the one or more Hidden Markov Models;
[0167] Determine one or more values of a trust rate based at least on discrete quantities in the one or more probability distributions; and
[0168] Classify the device as trusted or untrusted based on the one or more values of the trust rate.
[0169] According to one embodiment, there is provided an apparatus including components for performing the following:
[0170] Maintain one or more untrained Hidden Markov Models in at least one memory for modeling the behavior of corresponding one or more operating parameters of a device over time, wherein the hidden states of the one or more trained Hidden Markov Models define the expected future behavior of the corresponding one or more operating parameters, and the observation states of the one or more trained Hidden Markov Models define the current state of the corresponding one or more operating parameters, and the device is a Cooperative Intelligent Transport System (C-ITS) station or a Mobile Internet of Things (IoT) device;
[0171] Obtain training data, which includes a set of observation states and a corresponding set of known hidden states for each of the one or more operating parameters;
[0172] Based on the training data, train one or more emission matrices of the corresponding one or more untrained Hidden Markov Models to form one or more trained Hidden Markov Models; and
[0173] Output one or more trained Hidden Markov Models via at least one interface.
[0174] The described embodiments may also be performed, wholly or at least in part, in the form of a computer process defined by a computer program or part thereof. In connection with Figure 3 、 4 、5A, 5B and 6, embodiments of the methods described may be performed by executing at least a portion of a computer program including corresponding instructions. The computer program may be provided as a computer-readable medium including program instructions stored thereon, or as a non-transitory computer-readable medium including program instructions stored thereon. The computer program may be in source code form, object code form, or some intermediate form, and it may be stored in some carrier, which may be any entity or device capable of carrying the program. For example, the computer program may be stored on a computer program distribution medium readable by a computer or a processor. The computer program medium may be, for example but not limited to, a recording medium, a computer memory, a read-only memory, an electrical carrier signal, a telecommunication signal, and a software distribution package. The computer program medium may be a non-transitory medium. The coding of the software for performing the illustrated and described embodiments is entirely within the scope of those of ordinary skill in the art.
[0175] As used herein, the term "non-transitory" is a limitation of the medium itself (i.e., tangible, rather than a signal), rather than a limitation of data storage persistence (e.g., RAM vs. ROM).
[0176] References to one embodiment or an embodiment throughout the specification mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the solution. Thus, the phrases "in one embodiment" or "in an embodiment" that appear throughout the specification do not necessarily all refer to the same embodiment.
[0177] As used herein, for convenience, a plurality of items, structural elements, constituent elements, and / or materials may be presented in a common list. However, these lists should be interpreted as if each member of the list is individually identified as a separate and unique member. Thus, unless otherwise specified, no member of such a list should be construed as a de facto equivalent of any other member of the same list based solely on their presentation in the common group. Additionally, various embodiments and examples of the solution may be cited herein, as well as alternatives for its various components. It should be understood that these embodiments, examples, and alternatives should not be construed as de facto equivalents of one another, but rather as separate and autonomous representations of the solution.
[0178] Although the embodiments have been described above with reference to examples according to the drawings, it is obvious that the embodiments are not limited thereto, but can be modified in several ways within the scope of the appended claims. Therefore, all words and expressions should be interpreted broadly, and they are intended to illustrate rather than limit the embodiments. It will be clear to those skilled in the art that, as technology advances, the concept of the present invention can be implemented in various ways. In addition, it is clear to those skilled in the art that the embodiments can (but do not have to) be combined with other embodiments in various ways.
[0179] Industrial applicability
[0180] At least some embodiments have industrial applications in wireless communication.
Claims
1. A device for communication, comprising: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least perform: obtaining one or more trained hidden Markov models for modeling behavior of corresponding one or more operating parameters of a device over time, wherein hidden states of the one or more trained hidden Markov models define expected future behavior of the corresponding one or more operating parameters and observed states of the one or more trained hidden Markov models define current states of the corresponding one or more operating parameters, the device being a collaborative intelligent transportation system (C-ITS), a station, or a mobile Internet of Things (IoT) device; receiving one or more messages from the device, wherein the one or more messages include: values for the one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window; determining one or more sets of continuously observed states based on the one or more messages, wherein the one or more sets are respectively associated with the one or more operating parameters; determining, based on the one or more sets of consecutively observed states, one or more probability distributions of most likely paths through the one or more hidden Markov models using a Viterbi algorithm; determining one or more values of a confidence rate based at least on the discrete quantities in the one or more probability distributions; and Based on the one or more values of the trust rate, the device is classified as trusted or untrusted.
2. The apparatus of claim 1 , wherein the at least one memory and the instructions are configured, together with the at least one processor, to cause the apparatus to perform, after the classification: The classification of the device is output to another apparatus via at least one interface for making a decision regarding granting or revoking a security or trust certificate for the device based at least on the classification.
3. The apparatus according to claim 1 or 2, wherein the device is a mobile IoT device, and the mobile IoT device is a drone or a mobile robot.
4. The apparatus according to claim 1 or 2, wherein the device is the C-ITS station, and the one or more messages are C-ITS messages, and wherein the one or more C-ITS messages include: One or more collaboration awareness messages CAM, and / or one or more decentralized environment notification messages DENM.
5. The apparatus according to claim 3 or 4, wherein the at least one memory and the instructions are configured, together with the at least one processor, to cause the apparatus to: receive the one or more C-ITS messages from the C-ITS station via at least one C-ITS edge node.
6. The apparatus of claim 4, wherein the C-ITS station is a vehicle-mounted C-ITS station, and wherein the at least one memory and the instructions are configured, together with the at least one processor, to cause the apparatus to perform: determining, based on the one or more C-ITS messages, a number of road disruptions observed within the predefined sliding time window at a location of the C-ITS station; and determining a value of an uncertainty metric based at least on the number of road disruptions, wherein the uncertainty metric quantifies uncertainty regarding how atypical variations in the one or more operating parameters relate to the trustworthiness of the C-ITS station, The determination of the one or more values of the confidence rate is also based on the value of the uncertainty metric.
7. The apparatus of claim 6, wherein the at least one memory and the instructions are configured, together with the at least one processor, to cause the apparatus to perform: The receiving of the one or more messages, the determining of the one or more sets of continuous observation states, the determining of the one or more probability distributions, the determining of the number of road interruptions, the determining of the value of the uncertainty measure, the determining of the one or more values of the trust rate, and the classification are repeated periodically or regularly.
8. The apparatus of claim 7, wherein the at least one memory and the instructions are configured, together with the at least one processor, to cause the apparatus to perform: Tracking the false detection rate of the classification of the C-ITS station over time; as well as determining the value of the uncertainty metric also based on the false detection rate; The tracking of the false positive rate includes: obtaining, from the C-ITS station, behavior information about the C-ITS station; performing anomaly detection based on the classification of the C-ITS station and the behavior information of the C-ITS station; and Based on the result of the anomaly detection, the false positive rate is calculated.
9. The apparatus of any preceding claim, wherein said obtaining said one or more Hidden Markov Models comprises: maintaining in the at least one memory one or more untrained hidden Markov models for modeling behavior of corresponding one or more operating parameters of the device over time, obtaining training data, the training data comprising: a set of observed states and a corresponding set of known hidden states for each of the one or more operating parameters, and training one or more emission matrices of the corresponding one or more untrained hidden Markov models based on the training data to form the one or more trained hidden Markov models; or The one or more trained hidden Markov models are received from another device.
10. An apparatus according to any preceding claim, wherein the one or more operating parameters of the device include at least one of the following: end-to-end (E2E) latency, throughput, bandwidth, position, speed, velocity, acceleration, direction of movement, or transmission frequency.
11. An apparatus according to any preceding claim, wherein the hidden state of each of the one or more trained hidden Markov models comprises at least: a state indicating a future increase in an associated operating parameter, a state indicating a future decrease in said associated operating parameter, and a state indicating that said associated operating parameter will remain substantially unchanged in the future; or The hidden states of each of the one or more trained hidden Markov models include at least: one or more states indicating future increases of corresponding one or more different magnitudes in the associated operating parameters, one or more states indicating future decreases of corresponding one or more different magnitudes in the associated operating parameters, and a state indicating that the associated operating parameters remain substantially unchanged in the future.
12. The apparatus of any preceding claim, wherein the observed states of each of the one or more trained hidden Markov models comprise at least: a state indicating that an associated operating parameter has a normal or nominal value, and a state indicating that the associated operating parameter has an abnormal value; or wherein the observed states of each of the one or more trained hidden Markov models include at least: a state indicating an increase in an associated operating parameter, a state indicating a decrease in the associated operating parameter, and a state indicating that the associated operating parameter is substantially unchanged; or The observed states of each of the one or more trained hidden Markov models include at least: one or more states indicating an increase of one or more corresponding different magnitudes in the associated operating parameters, one or more states indicating a decrease of one or more corresponding different magnitudes in the associated operating parameters, and a state indicating that the associated operating parameters remain substantially unchanged.
13. An apparatus according to any preceding claim, wherein in the determination of the one or more values of the confidence rate, the discrete amount in the one or more probability distributions is quantified as a standard deviation in the one or more probability distributions; and The confidence rate is defined such that when the value of the standard deviation decreases, the value of the confidence rate increases, and when the value of the standard deviation increases, the value of the confidence rate decreases.
14. A method for communication, comprising: obtaining one or more trained hidden Markov models for modeling behavior of corresponding one or more operating parameters of a device over time, wherein hidden states of the one or more trained hidden Markov models define expected future behavior of the corresponding one or more operating parameters and observed states of the one or more trained hidden Markov models define current states of the corresponding one or more operating parameters, the device being a collaborative intelligent transportation system (C-ITS), a station, or a mobile Internet of Things (IoT) device; receiving one or more messages from the device, wherein the one or more messages include: values for the one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window; determining one or more sets of continuously observed states based on the one or more messages, wherein the one or more sets are respectively associated with the one or more operating parameters; determining, based on the one or more sets of consecutively observed states, one or more probability distributions of most likely paths through the one or more hidden Markov models using a Viterbi algorithm; determining one or more values of a confidence rate based at least on the discrete quantities in the one or more probability distributions; and Based on the one or more values of the trust rate, the device is classified as trusted or untrusted.
15. A non-transitory computer-readable medium having stored thereon instructions which, when executed by a computing device, cause the computing device to perform: obtaining one or more trained hidden Markov models for modeling behavior of corresponding one or more operating parameters of a device over time, wherein hidden states of the one or more trained hidden Markov models define expected future behavior of the corresponding one or more operating parameters and observed states of the one or more trained hidden Markov models define current states of the corresponding one or more operating parameters, the device being a collaborative intelligent transportation system (C-ITS), a station, or a mobile Internet of Things (IoT) device; receiving one or more messages from the device, wherein the one or more messages include: values for the one or more operating parameters for a plurality of consecutive time instances corresponding to a predefined sliding time window; determining one or more sets of continuously observed states based on the one or more messages, wherein the one or more sets are respectively associated with the one or more operating parameters; determining, based on the one or more sets of consecutively observed states, one or more probability distributions of most likely paths through the one or more hidden Markov models using a Viterbi algorithm; determining one or more values of a confidence rate based at least on the discrete quantities in the one or more probability distributions; and Based on the one or more values of the trust rate, the device is classified as trusted or untrusted.