Double-end onion head safety model implementation method oriented to control process

The dual-end onion peel security model for unmanned vehicles addresses security gaps by verifying operator identity and command integrity, enhancing the safety and reliability of remote control operations.

CN120315330APending Publication Date: 2025-07-15CHINA NORTH VEHICLE RES INST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510355882.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

The prior art is difficult to effectively evaluate and improve the safety of the unmanned vehicle control process, especially under complex communication conditions, where there are problems with the tampering of the control information and the effectiveness of the control command.

Method used

The dual-end onion head security model is adopted to evaluate the security of the control process through five-level policy steps, including identity authentication, information encryption, and effectiveness of control instructions on the control end and unmanned vehicle end. Technical means such as face recognition, permission management, RSA encryption algorithm and validity period of control instructions are adopted.

Benefits of technology

It improves the safety of the unmanned vehicle control process, prevents control information from being tampered with, and ensures the effectiveness of control commands, and enhances the reliability and safety of the control process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120315330A_ABST
    Figure CN120315330A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of unmanned vehicle safety control, and particularly relates to a control process-oriented double-end onion head safety model implementation method, which comprises five stages of implementation strategy steps: step 1, judging whether a control end is controllable or not; 2, judging whether the control end can be controlled or not; 3, whether the control information is tampered or not is judged at the control end and the unmanned vehicle end; 4, judging whether the control source of the unmanned vehicle end is legal or not; and 5, judging whether the control instruction of the unmanned vehicle end is valid or not. According to the method, a five-level strategy is adopted, the safety of meta-operation in each control task is evaluated, and the problems of whether the control end is controllable or not, whether the control information of the control end and the unmanned vehicle end is tampered or not, whether the control source of the unmanned vehicle end is legal or not, whether the control instruction is effective or not and the like are analyzed; a double-end onion head safety model is innovatively provided, and the safety of the whole control process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of unmanned vehicle safety control, and particularly relates to an implementation method of a dual-end onion safety model for a control process, which can be applied to the scenario of remotely controlling an unmanned vehicle. Background Art

[0002] Safety is a key factor considered during the execution of unmanned vehicle tasks, especially an important guarantee for the unmanned platform to complete tasks safely and reliably in the formation operation mode of a vehicle fleet. In order to improve the control safety of unmanned vehicles, a dual-end onion safety model is innovatively proposed. Based on the control process of tasks, the safety of meta-operations in each meta-task control process is evaluated to improve the control safety in all dimensions. Summary of the Invention

[0003] (1) Technical Problems to be Solved

[0004] The technical problem to be solved by the present invention is: how to provide an implementation method of a dual-end onion safety model for a control process.

[0005] (2) Technical Solutions

[0006] To solve the above technical problems, the present invention provides an implementation method of a dual-end onion safety model for a control process. The two ends of the dual-end onion safety model for a control process are a control end and an unmanned vehicle end, and "peeling the onion" is performed layer by layer from the outside to the inside, including five-level implementation strategy steps:

[0007] Step 1: Determine whether the control end is controllable;

[0008] Step 2: Determine whether the control end can be controlled;

[0009] Step 3: Determine whether the control information is tampered with at the control end and the unmanned vehicle end respectively;

[0010] Step 4: Determine whether the control source at the unmanned vehicle end is legal;

[0011] Step 5: Determine whether the control instruction at the unmanned vehicle end is valid.

[0012] Among them, in the above Step 1, determine whether the control end is controllable;

[0013] Starting from "whether it is controllable", the control end considers the design of the crew control entry and control permission authentication as the first line of defense for control safety;

[0014] In terms of hardware, a face recognition function is set on the intelligent control terminal. Only the operator with a legal identity registered in the face database can use the control terminal; the control terminal is provided with an emergency self-destruction switch for destroying the data in the control terminal in response to the self-destruction signal sent by the IO and the bus network.

[0015] On the software, an entry design for password authentication is set at the display and control interface, and a permission management function is designed. Only the operator who passes the password verification and has legal permissions can use the control functions corresponding to the permissions; an emergency self-destruction soft switch for the unmanned platform is designed in the display and control interface to send a self-destruction instruction to the designated unmanned platform.

[0016] Through the above methods, it is realized to distinguish whether the operator has a legal control identity, reject illegal logins and record identity information for retrospective investigation afterwards.

[0017] Among them, in step 2, it is judged whether the control end can control.

[0018] "Whether it can control" of the control end is a consideration factor for the safety design of the control end; after the operator logs in, the relevant tools of the control terminal monitor the running state of the unmanned vehicle to be controlled in real time. If the unmanned vehicle is currently in an inoperable state, the unmanned vehicle cannot be controlled, and the crew members are informed through an information presentation method; if the current state of the unmanned vehicle is controllable, the control restriction is lifted.

[0019] Among them, in step 2, the inoperable state includes the influence states of operation factors related to safety and tasks.

[0020] Among them, in step 3, it is judged whether the control information is tampered with at the control end and the unmanned vehicle end respectively.

[0021] During the transmission of control information using the communication system, it should be protected against man-in-the-middle attacks. After the data is tampered with, a dangerous control instruction is sent to the unmanned platform; therefore, when communicating between the unmanned vehicle end and the control end, the communication protocol should be encrypted; the encryption method uses the asymmetric (RSA) encryption algorithm; as a public-key encryption algorithm, the RSA encryption algorithm can be used for both encryption and digital signature, and it can resist all known cryptographic attacks so far.

[0022] Among them, in step 3, at the control end, the public key is used to encrypt the communication data.

[0023] At the unmanned vehicle end, the private key is used to decrypt the communication data, and only the correctly decrypted data can be received and processed by the unmanned platform control software.

[0024] Among them, in step 4, it is judged whether the control source at the unmanned vehicle end is legal.

[0025] On the unmanned vehicle side, "whether the control source is legal" is the first line of defense for the controlled safety of the unmanned vehicle; after receiving the control instruction, the unmanned vehicle side decrypts the control instruction with the stored private key to obtain the plaintext information. The plaintext information contains the control source ID. If the control source ID is the same as the currently recorded control terminal ID, the control instruction is considered legal.

[0026] Among them, in step 5, it is judged whether the control instruction of the unmanned vehicle side is valid;

[0027] Under the current complex networking communication conditions, the communication problems between the control terminal and the unmanned vehicle side include weak signal strength, uncertain communication delay, large communication jitter, etc. These problems have a greater impact on the transmission of the control instruction;

[0028] When the control instruction is sent, it carries a control validity period identifier to ensure the timeliness of the control. If the legal control instruction received by the unmanned platform is within the validity period it carries, it will continue to be distributed to each controller and actuator through the in-vehicle bus network; if the instruction is not within the validity period, it is considered that the current communication conditions have seriously affected the timeliness of the control instruction and do not meet the conditions for continued execution, and it will no longer be distributed in the vehicle.

[0029] (III) Beneficial effects

[0030] Compared with the prior art, the present invention proposes a two-end onion security model for the control process. The key points of the invention are as follows: for the control process oriented to combat missions, the present invention adopts a "five-level" strategy to evaluate the security of the elementary operations in each control task, and analyzes the problems of "whether the control terminal can control" and "whether it can be controlled", the problem of "whether the control information is tampered with" between the control terminal and the unmanned vehicle side, and the problems of "whether the control source is legal" and "whether the control instruction is valid" on the unmanned vehicle side. The two-end onion security model is innovatively proposed to improve the security of the entire control process. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is a schematic diagram of the control security design based on the two-end onion model. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] To make the objectives, contents, and advantages of the present invention clearer, the following further describes in detail the specific embodiments of the present invention with reference to the drawings and embodiments.

[0033] To solve the above technical problems, the present invention provides a method for implementing a two-end onion security model for the control process. The two ends of the two-end onion security model for the control process are the control terminal and the unmanned vehicle side, and layer by layer "peel the onion" from the outside to the inside, including five-level implementation strategy steps:

[0034] Step 1: Determine whether the control terminal is controllable;

[0035] Step 2: Determine whether the control terminal can be controlled;

[0036] Step 3: Determine whether the control information has been tampered with at the control terminal and the unmanned vehicle terminal respectively;

[0037] Step 4: Determine whether the control source of the unmanned vehicle terminal is legal;

[0038] Step 5: Determine whether the control command of the unmanned vehicle terminal is valid.

[0039] Among them, in the above-mentioned Step 1, determine whether the control terminal is controllable;

[0040] Starting from "whether it is controllable", the control terminal considers the design of the crew control entrance and control permission authentication as the first line of defense for control safety;

[0041] In terms of hardware, a face recognition function is set on the intelligent control terminal. Only the operator with a legal identity registered in the face database can use the control terminal; the control terminal is equipped with an emergency self-destruction switch to destroy the data in the control terminal in response to the self-destruction signal sent by the IO and bus network;

[0042] In terms of software, an entrance design for password authentication is set at the display and control interface, and a permission management function is designed. Only the operator who passes the password verification and has legal permissions can use the control functions corresponding to the permissions; an emergency self-destruction soft switch for the unmanned platform is designed in the display and control interface to send a self-destruction command to the specified unmanned platform;

[0043] Through the above methods, the authenticity of whether the operator has a legal control identity is verified, and illegal logins are rejected and the identity information is recorded for future traceability.

[0044] Among them, in the above-mentioned Step 2, determine whether the control terminal can be controlled;

[0045] "Whether the control terminal can be controlled" is a consideration factor for the safety design of the control terminal; after the operator logs in, the relevant tools of the control terminal monitor the running state of the unmanned vehicle to be controlled in real time. If the unmanned vehicle is currently in an inoperable state, the unmanned vehicle cannot be controlled, and the crew is informed through the information presentation method; if the current state of the unmanned vehicle is controllable, the control restriction is lifted.

[0046] Among them, in the above-mentioned Step 2, the inoperable state includes the state affected by the running factors related to safety and tasks.

[0047] Among them, in the above-mentioned Step 3, determine whether the control information has been tampered with at the control terminal and the unmanned vehicle terminal respectively;

[0048] During the transmission of control information using a communication system, it is necessary to prevent man-in-the-middle attacks. After the data is tampered with, a control instruction that is dangerous to control is sent to the unmanned platform. Therefore, when communicating between the unmanned vehicle end and the control end, the communication protocol should be encrypted. The encryption method uses the asymmetric (RSA) encryption algorithm. As a public-key encryption algorithm, the RSA encryption algorithm can be used for both encryption and digital signatures, and it can resist all known cryptographic attacks so far.

[0049] Among them, in step 3, at the control end, the public key is used to encrypt the communication data.

[0050] At the unmanned vehicle end, the private key is used to decrypt the communication data, and only the correctly decrypted data can be received and processed by the unmanned platform control software.

[0051] Among them, in step 4, it is judged whether the control source at the unmanned vehicle end is legal.

[0052] At the unmanned vehicle end, "whether the control source is legal" is the first line of defense for the controlled safety of the unmanned vehicle. After the unmanned vehicle end receives the control instruction, the stored private key is used to decrypt the control instruction to obtain the plaintext information. The plaintext information contains the control source ID. If the control source ID is consistent with the currently recorded control end ID, the control instruction is considered legal.

[0053] Among them, in step 5, it is judged whether the control instruction at the unmanned vehicle end is valid.

[0054] Under the current complex networking communication conditions, the communication problems between the control end and the unmanned vehicle end include weak signal strength, uncertain communication delay, large communication jitter, etc. These problems have a great impact on the transmission of control instructions.

[0055] When the control instruction is sent, it carries a control validity period identifier to ensure the timeliness of control. If the legal control instruction received by the unmanned platform is within the validity period it carries, it will continue to be distributed to each controller and actuator through the in-vehicle bus network. If the instruction is not within the validity period, it is considered that the current communication conditions have seriously affected the timeliness of the control instruction and do not meet the conditions for continued execution, and it will no longer be distributed in the vehicle.

[0056] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.

Claims

1. A method for implementing a double - ended onion - head security model for a control process, characterized in that, The two ends of the dual - end onion - like security model for the control process are the control end and the unmanned vehicle end. It peels the "onion" layer by layer from the outside to the inside, including five - level implementation strategy steps: Step 1: Determine whether the control end is controllable; Step 2: Determine whether the control end can be controlled; Step 3: Respectively determine whether the control information is tampered with at the control end and the unmanned vehicle end; Step 4: Determine whether the control source at the unmanned vehicle end is legal; Step 5: Determine whether the control command at the unmanned vehicle end is valid.

2. The implementation method of the double - ended onion security model for the manipulation process according to claim 1, wherein, In the above - mentioned Step 1, determine whether the control end is controllable; Starting from "whether it is controllable", the control end considers the design of the crew control entry and control - permission authentication as the first line of defense for control security; In terms of hardware, a face - recognition function is set on the intelligent control terminal. Only the operator with a legal identity registered in the face database can use the control terminal; the control terminal is equipped with an emergency self - destruction switch, which is used to respond to the self - destruction signal sent by the IO and bus network to destroy the data in the control terminal; In terms of software, an entry design for password authentication is set at the display and control interface, and a permission management function is designed. Only the operator who passes the password verification and has legal permissions can use the control functions corresponding to the permissions; an emergency self - destruction soft switch for the unmanned platform is designed in the display and control interface, which is used to send a self - destruction command to the specified unmanned platform; Through the above methods, the identification of whether the operator has a legal control identity is realized. Illegal logins are rejected and the identity information is recorded for future traceability.

3. The implementation method of the dual - end onion - like security model for the manipulation process as claimed in claim 1, wherein, In the above - mentioned Step 2, determine whether the control end can be controlled; "Whether it can be controlled" of the control end is a consideration factor for the safety design of the control end; after the operator logs in, the relevant tools of the control terminal monitor the running state of the unmanned vehicle to be controlled in real time. If the unmanned vehicle is currently in an inoperable state, the unmanned vehicle cannot be controlled, and the crew is informed through the information presentation method; if the current state of the unmanned vehicle is controllable, the control restriction is lifted.

4. The implementation method of the double-ended onion security model for the manipulation process according to claim 3, characterized in that, In the above - mentioned Step 2, the inoperable state includes the state affected by operation factors related to safety and tasks.

5. The implementation method of the double-ended onion security model for the manipulation process according to claim 3, characterized in that, In the above - mentioned Step 3, respectively determine whether the control information is tampered with at the control end and the unmanned vehicle end; When communicating between the unmanned vehicle end and the control end, the communication protocol is encrypted; the encryption method uses an asymmetric encryption algorithm.

6. The implementation method of the double-ended onion security model for the control process according to claim 5, characterized in that In the above - mentioned Step 3, at the control end, the public key is used to encrypt the communication data; At the unmanned vehicle end, the private key is used to decrypt the communication data, and only the correctly decrypted data can be received and processed by the unmanned platform control software.

7. The implementation method of the dual - end onion - head security model for the manipulation process according to claim 6, characterized in that, In the above - mentioned Step 4, determine whether the control source at the unmanned vehicle end is legal; At the unmanned vehicle end, "whether the control source is legal" is the first line of defense for the controlled safety of the unmanned vehicle; After receiving the control command, the unmanned vehicle end decrypts the control command with the stored private key to obtain the plain - text information; the plain - text information contains the control source ID. If the control source ID is consistent with the currently recorded control - end ID, the control command is considered legal.

8. The implementation method of the double-ended onion security model for the control process according to claim 7, characterized in that In the above - mentioned Step 5, determine whether the control command at the unmanned vehicle end is valid; When the control instruction is issued, it carries a control validity period identifier to ensure the timeliness of the control. If the legitimate control instruction received by the unmanned platform is within the validity period it carries, it will continue to be distributed to each controller and actuator through the in-vehicle bus network; if the instruction is not within the validity period, it is considered that the current communication conditions seriously affect the timeliness of the control instruction and do not meet the conditions for continued execution, and it will no longer be distributed in the vehicle.

9. The implementation method of the double-ended onion security model for the manipulation process according to claim 8, characterized in that, The method described above faces the control process of combat missions and adopts a "five-level" strategy to evaluate the safety of meta-operations in each control mission, and analyzes issues such as whether the control end "can be controlled" and "is able to control", whether the "control information has been tampered with" on both the control end and the unmanned vehicle end, as well as issues such as whether the "control source is legal" and whether the "control instruction is valid" on the unmanned vehicle end.

10. The method for implementing the double - ended onion - head security model for the manipulation process as claimed in claim 8, wherein, The method described above innovatively proposes a double-end onion security model to improve the security of the entire control process.