Multi-source information fusion priority control method based on trusted module

The integration of TPM-based prioritization in autonomous systems ensures trustworthy control commands are prioritized over fused data, enhancing security and reliability by using digital signatures and remote matching to prevent erroneous decisions.

CN120321604APending Publication Date: 2025-07-15BEIJING INST OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510446371.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

Existing unmanned systems have multi-source information fusion methods that are susceptible to noise, delay or attacks in complex environments, resulting in data inconsistency. TPM technology lacks the priority coordination mechanism for multi-source information fusion results, resulting in insufficient system security.

Method used

The Trusted Module (TPM) is introduced as the core decision-making component, and the trustworthiness and legality of control instructions are ensured through digital signature and remote matching technology, and given it the highest priority, combining adaptive weight allocation and multi-sensor data fusion to optimize the decision-making process.

Benefits of technology

It improves the security and reliability of unmanned systems, prevents malicious attacks, and ensures the credibility and real-timeness of decisions, especially for autonomous systems such as drones and unmanned vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005352712800000021
    Figure BDA0005352712800000021
  • Figure BDA0005352712800000022
    Figure BDA0005352712800000022
  • Figure BDA0005352712800000023
    Figure BDA0005352712800000023
Patent Text Reader

Abstract

The invention discloses a multi-source information fusion priority control method based on a trusted module, and the method comprises the steps: collecting environment data, and carrying out the data preprocessing; obtaining a self-adaptive weight; carrying out weighted fusion on the sensor data; a TPM instruction is generated and signed; generating an identity verification identifier; the instruction receiving end extracts the TPM instruction abstract and the digital signature to obtain an original instruction; comparing the TPM instruction with a multi-source information fusion result; judging priorities of the credible decision and the information fusion decision; the receiving end checks whether the instruction carries a digital signature and an identity verification identifier; the remote authentication compares the instruction with the security policy through the receiving end; the digital signature ensures that the instruction is not tampered; the remote matching guarantee instruction is from a remote control party or a TPM module; and if the digital signature verification is passed and the remote matching confirms that the instruction is credible, the instruction enters a decision execution process, and the system makes a decision according to the instruction priority and the security policy. According to the method, the credible control instruction is ensured to have the highest priority in all decisions when information conflicts occur.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the information processing and decision control technology of unmanned systems, and particularly to a multi-source information fusion priority control method based on a Trusted Platform Module (TPM). Background Art

[0002] In autonomous systems such as unmanned aerial vehicles and unmanned vehicles, multi-source information fusion technology is the key to improving environmental perception ability and decision-making accuracy. However, in a complex environment, sensor data may be affected by noise, loss, delay, or spoofing attacks, resulting in data inconsistency. Existing multi-source information fusion methods usually rely on the confidence calculation of different sensors and use methods such as Bayesian inference, Kalman filtering, and particle filtering for information fusion. However, relying solely on these methods may lead to incorrect decisions, especially when the environmental interference is severe or the system is under external attacks.

[0003] As a secure hardware module, the Trusted Platform Module (TPM) can provide trusted identity authentication, data integrity verification, and key decision control functions. By adopting digital signature and remote matching technology, the TPM can ensure the reliability of the source of control instructions and match the correct security policy through remote identity authentication. However, in the existing technology, although the TPM technology can ensure the trustworthiness of the instruction source through digital signature and remote authentication, it lacks a priority coordination mechanism with the multi-source information fusion result, resulting in insufficient system security when instructions conflict, and further leading to the system executing incorrect decisions. Therefore, there is an urgent need for a method to ensure that TPM instructions have the highest priority when multi-source information fusion conflicts with trusted control instructions, avoid potential safety hazards, and further improve the security and reliability of the system by combining remote matching technology. Summary of the Invention

[0004] Object of the Invention: Aiming at the problems of severe environmental interference, vulnerability to attacks, and conflicts between instructions and criteria in the secure and trusted management and control of unmanned systems, the present invention proposes a multi-source information fusion priority control method based on a trusted module to ensure that in the case of information conflicts, trusted control instructions have the highest priority among all decisions, while the multi-source information fusion criteria only serve as an auxiliary level to optimize the final decision of the system and improve the security, reliability, and real-time performance of the system. This method introduces the Trusted Platform Module (TPM) as the core decision-making component, utilizes its powerful identity authentication, data integrity verification, and remote matching capabilities to perform trusted verification on system control instructions, and assigns the highest priority to trusted control instructions in the case of information conflicts, while the multi-source information fusion criteria only serve as an auxiliary level to optimize the final decision.

[0005] Technical Solution: The multi-source information fusion priority control method based on a trusted module of the present invention includes the following steps:

[0006] 1) The environmental data is collected by sensors, and data preprocessing is carried out through wavelet transform denoising, 3D point cloud registration for coordinate alignment, and entropy coding data compression, and multi-sensor time synchronization is performed.

[0007] 2) Adaptive weight assignment is carried out to obtain the adaptive weight ω i :

[0008]

[0009] where h i is the accuracy rate of the sensor historical data, e i is the current environmental adaptability coefficient, and α and β are preset adjustment parameters; the accuracy rate h i of the sensor historical data is calculated using an exponentially decaying sliding window:

[0010]

[0011] λ is the decay factor, and Error i (t) is the error of the sensor data at time t;

[0012] 3) The data of each sensor is weighted and fused:

[0013]

[0014] where X fused is the fused data, X i is the data after sensor preprocessing, and ω i is the adaptive weight in step 2); and the confidence level of the fusion result is determined:

[0015]

[0016] where H fused is the fusion confidence level, and h i is the accuracy of the sensor historical data in step 2);

[0017] 4) Generate TPM instructions and sign them: The TPM performs a SHA-256 hash operation on the original data from the sensors and compares it with the reference hash stored in the TPM to verify the data source and data integrity; the TPM generates a trusted control instruction based on the sensor data and digitally signs the trusted control instruction using the RSA private key built into the TPM chip;

[0018] 5) Generate an authentication identifier: When the remote control center sends an instruction to the TPM or the target system, the instruction is attached with the process of generating the digest signature by the TPM in the digital signature in step 4);

[0019] 6) The instruction receiver extracts the TPM instruction digest and digital signature, decrypts the digital signature using the public key of the TPM module to obtain the original instruction;

[0020] 7) Compare the TPM instruction with the multi-source information fusion result:

[0021]

[0022] where Δ is the difference degree between the TPM instruction and the fusion result, x TPM is the position of the TPM instruction, v TPM is the speed of the TPM instruction, x fused is the position of the fusion result, v fused is the bit speed of the fusion result, x fused and v fused are the components of X fused in step 3);

[0023] 8) Determine the priority of the trusted decision and the information fusion decision:

[0024]

[0025] 9) After the receiver receives the instruction, it checks whether the instruction is attached with a digital signature and an authentication identifier, and the system verifies the identity of the instruction issuer through the hardware fingerprint of the trusted service platform;

[0026] 10) Build a rule library according to the usage requirements of the unmanned device. The remote authentication passes the receiver to compare the content in the instruction with the preset security policy of the system. When the instruction content matches the current system security policy, the instruction is executed;

[0027] 11) The digital signature ensures that the instruction has not been tampered with and proves the legal source of the instruction; the remote matching ensures that the instruction comes from the expected and legal remote control party or TPM module, preventing forged instructions from entering the system;

[0028] 12) If the digital signature verification passes and the remote matching confirms that the instruction source is trustworthy, the instruction enters the decision execution process of the system, and the system makes a decision according to the priority and security policy of the instruction; if the verification fails, the system refuses to execute the instruction and records the security exception.

[0029] In step 1), the environmental data is collected by the sensor, and data preprocessing is performed through wavelet transform denoising, 3D point cloud registration for coordinate alignment, and entropy coding data compression, and multi-sensor time synchronization is performed based on the IEEE 1588 protocol.

[0030] In step 2), the environmental parameters include the light intensity and the GPS signal-to-noise ratio.

[0031] In step 2), ei is the current environmental adaptability coefficient, which is mapped from environmental parameters by a fuzzy logic controller.

[0032] In step 4), the TPM generates a trusted control instruction based on sensor data. The trusted control instruction includes operation content, timestamp, security policy label, and unique serial number, and digitally signs the trusted control instruction with the RSA private key built into the TPM chip.

[0033] The digital signature and the instruction data serve as the trusted criteria for the unmanned system instruction.

[0034] In step 5), during the transmission of the instruction, the digital signature and the instruction are attached with a timestamp authentication identifier.

[0035] In step 5), the deviation between the timestamp of the instruction and the system clock is ≦ ±50 ms.

[0036] In step 10), the receiving end compares the timestamp of the generated instruction with the system time to prevent the instruction from being executed late or replay attacked.

[0037] In step 11), remote matching ensures that the instruction comes from an expected and legal remote control party or TPM module. Through authentication and timestamp verification, forged instructions are prevented from entering the system.

[0038] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0039] (1) By combining the digital signature and the remote matching mechanism, the present invention effectively prevents malicious attacks or tampering, ensures the integrity and credibility of the instruction during transmission, ensures the legality of the instruction source, and prevents illegal devices or attackers from forging instructions to interfere with the system.

[0040] (2) The present invention improves the security and stability of the overall system, ensures the reliability of decision-making and control instructions, and is particularly applicable to application scenarios such as unmanned systems and autonomous driving systems that highly rely on accurate instructions. Specific embodiments

[0041] The entire system of the present invention consists of multiple key modules, including a multi-source information acquisition module, a data fusion and processing module, a trusted decision-making module, a conflict detection and priority determination module, and a decision execution and feedback optimization module.

[0042] The multi-source information acquisition module is responsible for collecting environmental data from multiple sensors such as an inertial measurement unit (IMU), a lidar (LiDAR), a camera, and a global positioning system (GPS) in the unmanned system, and preprocessing it using time synchronization technology to ensure data time series consistency.

[0043] The data fusion and processing module uses advanced fusion algorithms to correlate and fuse the spatio-temporal information from different data sources, improving the environmental perception ability and perception accuracy.

[0044] The trusted decision-making module performs integrity verification on the collected data through digital signature and remote matching technologies, and at the same time generates trusted control instructions by combining historical state analysis and preset security policies.

[0045] The conflict detection and priority determination module is responsible for triggering the conflict detection mechanism when there is an inconsistency between the multi-source information fusion result and the trusted instructions generated by the trusted decision-making module, analyzing the data source, confidence level, and ensuring that the execution priority of the control instructions of the trusted decision-making module is higher than the calculation result of the fusion algorithm according to the preset priority rules.

[0046] The decision execution and feedback optimization module strictly executes the decision according to the trusted instructions, dynamically adjusts the multi-source information fusion parameters during the execution process, optimizes the sensor data weight allocation through the feedback mechanism, improves the system adaptability and decision accuracy, and ensures the stable operation of the autonomous system in a changing environment.

[0047] The multi-source information fusion priority control method based on the trusted module of the present invention includes the following steps:

[0048] 1) Perform multi-source information collection and preprocessing: Collect environmental data by sensors, perform data preprocessing through wavelet transform denoising, 3D point cloud registration for coordinate alignment and entropy coding data compression, and perform multi-sensor time synchronization;

[0049] 2) Adaptive weight allocation: The data with high confidence in the data collected by each sensor has a greater impact on the system decision-making. This strategy is dynamically adjusted based on the historical performance of each sensor and the adaptability to the current environment. The weight allocation is as follows:

[0050]

[0051] where h i is the accuracy rate of the sensor historical data, e i is the current environment adaptability coefficient, which is mapped by the environmental parameters (light intensity, GPS signal-to-noise ratio) through a fuzzy logic controller. α and β are preset adjustment parameters. In this embodiment, the default values are α = 0.7 and β = 0.3; where the accuracy rate h i of the sensor historical data is calculated using an exponentially decaying sliding window (window size 1000 frames):

[0052]

[0053] λ = 0.95, which is the decay factor, Error i(t) is the error of the sensor data at time t.

[0054] 3) Perform multi-source sensor information fusion: Perform weighted fusion on the data of each sensor:

[0055]

[0056] Among them, X fused is the fused data, X i is the data after sensor preprocessing, ω i is the adaptive weight in step 2); and determine the confidence of the fusion result:

[0057]

[0058] Among them, H fused is the fusion confidence, h i is the accuracy of the sensor historical data in step 2).

[0059] 4) Generate TPM instructions and sign: The TPM first performs SHA-256 hash operation on the original data from the sensor, and compares it with the reference hash stored in the TPM to verify the data source and data integrity; the TPM generates a trusted control instruction based on the sensor data. The control instruction includes operation content, timestamp, security policy label, and unique serial number, and digitally signs the instruction through the RSA private key built into the TPM chip. The private key is the only and strictly confidential key inside the TPM module to ensure the legality of instruction generation. The digital signature and the instruction data together serve as the trusted criterion for the instructions of the unmanned system (such as unmanned vehicle, unmanned aerial vehicle or other autonomous systems).

[0060] 5) Generate authentication identifier: When the remote control center (such as an operator or a remote server) issues an instruction to the TPM or the target system, the instruction also comes with a digital signature, such as the process of generating a digest signature by the TPM in step 4). During the instruction transmission process, in addition to the digital signature, the instruction also comes with a timestamp authentication identifier. If the deviation between the instruction timestamp and the system clock exceeds ±50 ms, it is regarded as illegal, further enhancing the security of the instruction.

[0061] 6) The instruction receiver receives and extracts the instruction: The receiver first extracts the TPM instruction digest and the digital signature, and decrypts the digital signature using the public key of the TPM module to obtain the original instruction.

[0062] 7) Conflict detection trigger condition: Compare the TPM instruction with the multi-source information fusion result:

[0063]

[0064] Among them, Δ is the difference degree between the TPM instruction and the fusion result, x TPMis the position of the TPM instruction, v TPM is the speed of the TPM instruction, x fused is the position of the fusion result, v fused is the speed of the fusion result bit, x fused and v fused both are components of X fused in this invention. By default, the conflict threshold Δ_theshold = 3m, and it is reduced to 2m in the indoor environment.

[0065] 8) Determine the priority of the trusted decision and the information fusion decision:

[0066]

[0067] 9) Verify the digital signature and the identity authentication identifier: After receiving the instruction, the receiving end first checks whether the instruction is attached with a valid digital signature and the identity authentication identifier. The system verifies the identity of the instruction sender through the hardware fingerprint of the trusted service platform to ensure that the identity is authorized. If the verification passes, it indicates that the instruction source is trusted.

[0068] 10) Perform instruction matching: Build a corresponding rule library according to the usage requirements of the unmanned device (for example, when the GPS signal strength of the unmanned vehicle is < 30dB, remote control is disabled). Once the remote authentication passes, the receiving end compares the content of the instruction with the system - preset security policy. Only when the instruction content matches the current system security policy, the instruction will be executed. To ensure the security of the execution process, the receiving end compares the timestamp of the generated instruction with the system time to prevent the instruction from being executed with delay or replay attack.

[0069] 11) Digital signature and remote matching work together: The digital signature and the remote matching mechanism work together. The digital signature ensures that the instruction has not been tampered with and proves the legal source of the instruction to ensure the security of the entire control instruction. Remote matching ensures that the instruction indeed comes from the expected and legal remote control party or TPM module. Through identity authentication and timestamp verification means, it prevents forged instructions from entering the system.

[0070] 12) Execute the instruction: If the digital signature verification passes and the remote matching confirms that the instruction source is trusted, the instruction will enter the decision - making and execution process of the system. The system makes decisions according to the priority and security policy of the instruction. If the verification fails at any step, the system rejects the execution of the instruction and records the security exception.

Claims

1. A multi-source information fusion priority control method based on a trusted module, characterized in that: It includes the following steps: 1) Collect environmental data by sensors, perform data preprocessing through wavelet transform denoising, 3D point cloud registration for coordinate alignment and entropy coding data compression, and perform multi-sensor time synchronization; 2) Perform adaptive weight allocation to obtain the adaptive weight ω i : where h i is the accuracy rate of sensor historical data, e i is the current environmental adaptability coefficient, and α, β are preset adjustment parameters; the accuracy rate h of the sensor historical data i is calculated using an exponentially decaying sliding window: λ is the attenuation factor, Error i (t) is the error of the sensor data at time t; 3) Perform weighted fusion on the data of each sensor: Among them, X fused is the fused data, and X i is the data after preprocessing by the sensor, and ω i is the adaptive weight in step 2); and determine the confidence of the fusion result: Among them, H fused is the fusion confidence, h i is the accuracy of the sensor historical data in step 2); 4) Generate TPM instructions and sign them: The TPM performs SHA-256 hashing on the original data from the sensors, compares it with the reference hash stored in the TPM to verify the data source and data integrity; the TPM generates a trusted control instruction based on the sensor data and digitally signs the trusted control instruction with the RSA private key built into the TPM chip; 5) Generate authentication identification: When the remote control center issues an instruction to the TPM or the target system, the instruction is attached with the process of generating the digest signature by the TPM in the digital signature in step 4); 6) The instruction receiving end extracts the TPM instruction digest and digital signature, and decrypts the digital signature using the public key of the TPM module to obtain the original instruction; 7) Compare the TPM instruction with the multi-source information fusion result: where Δ is the difference degree between the TPM instruction and the fusion result, x TPM is the position of the TPM instruction, v TPM is the speed of the TPM instruction, x fused is the position of the fusion result, v fused is the speed of the fusion result position, x fused and v fused are the components of X fused in step 3); 8) Determine the priority of the trusted decision and the information fusion decision: 9) After the receiving end receives the instruction, it checks whether the instruction is attached with a digital signature and an authentication identification, and the system verifies the identity of the instruction issuer through the hardware fingerprint of the trusted service platform; 10) Build a rule library according to the usage requirements of the unmanned device, and the remote authentication compares the content in the instruction with the preset security policy of the system through the receiving end. When the instruction content matches the current system security policy, the instruction is executed; 11) The digital signature ensures that the instruction has not been tampered with and proves the legal source of the instruction; the remote matching ensures that the instruction comes from the expected and legal remote control party or TPM module, preventing forged instructions from entering the system; 12) If the digital signature verification passes and the remote matching confirms that the instruction source is trusted, the instruction enters the decision execution process of the system, and the system makes a decision according to the priority and security policy of the instruction; if the verification fails, the system refuses to execute the instruction and records the security exception.

2. The multi-source information fusion priority control method based on a trusted module according to claim 1, wherein: In step 1), environmental data is collected by sensors, data preprocessing is performed through wavelet transform denoising, 3D point cloud registration for coordinate alignment and entropy coding data compression, and multi-sensor time synchronization is performed based on the IEEE 1588 protocol.

3. The multi-source information fusion priority control method based on a trusted module according to claim 1, wherein: In step 2), the environmental parameters include light intensity and GPS signal-to-noise ratio.

4. The multi-source information fusion priority control method based on a trusted module according to claim 1, wherein: In step 2), e i is the current environmental adaptability coefficient, which is mapped from environmental parameters by a fuzzy logic controller.

5. The multi-source information fusion priority control method based on a trusted module according to claim 1, wherein: In step 4), the TPM generates a trusted control instruction based on the sensor data. The trusted control instruction includes operation content, timestamp, security policy label, and unique serial number, and digitally signs the trusted control instruction with the RSA private key built into the TPM chip.

6. The multi-source information fusion priority control method based on a trusted module according to claim 1, wherein: The digital signature and instruction data serve as the trusted criteria for the unmanned system instruction.

7. The multi-source information fusion priority control method based on a trusted module according to claim 1, wherein: In step 5), during the transmission process of the instruction, the digital signature and the instruction are attached with a timestamp authentication identification.

8. The multi-source information fusion priority control method based on a trusted module according to claim 7, wherein: In step 5), the time deviation between the timestamp of the instruction and the system clock is ≦±50ms.

9. The multi-source information fusion priority control method based on a trusted module according to claim 1, characterized in that: In step 10), the receiving end compares the timestamp of the generated instruction with the system time to prevent the instruction from being executed with delay or replay attack.

10. The method for controlling the priority of multi-source information fusion based on a trusted module according to claim 1, characterized in that: In step 11), remote matching ensures that the instruction comes from an expected and legitimate remote control party or TPM module. Through authentication and timestamp verification, forged instructions are prevented from entering the system.