Internet of vehicles trust management system and method
By building a blockchain system for vehicles, roadside units and trusted institutions, the problems of data consistency and low trust management efficiency in cross-regional areas of the Internet of Vehicles are solved, and fast and accurate trust evaluation and malicious node identification are achieved, which improves the security and privacy protection capabilities of the Internet of Vehicles are improved.
Patent Information
- Application Number
- CN202510698274.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-05-28
AI Technical Summary
There is a lack of cross-regional data consistency in the Internet of Vehicles. The traditional trust management system generates trust values slowly, fails to make full use of computing resources from trusted sources, and there is a threat from malicious vehicles and roadside units, affecting data security and privacy protection.
A trust management system consisting of vehicles, roadside units, trusted institutions, edge layer blockchains and core layer blockchains is adopted to manage the trust ledgers of vehicles and roadside units through network access certificates and endorsement certificates. The hyperledger technology is used to achieve cross-regional data consistency and rapid trust evaluation, and the trust value of vehicles and roadside units is calculated in combination with multi-dimensional indicators, and data reliability is ensured through a two-factor verification mechanism.
It improves the efficiency and security of trust management in the Internet of Vehicles, ensures cross-regional data consistency, accurately identify and isolate malicious vehicles and roadside units, protects user privacy, and improves the trustworthiness and security of the system.
Smart Images

Figure CN120358499A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of vehicle networking, and particularly relates to a vehicle networking trust management system and method. Background Art
[0002] With the rapid development of vehicle networking technology, the information exchange between vehicles has become increasingly frequent and crucial. These information exchanges are not only vital for enhancing road safety, but also for optimizing traffic flow and improving the driving experience. However, with the increase in information exchange, significant security and privacy challenges have also emerged. Protecting the data security and user privacy during these exchanges has become an urgent problem to be solved.
[0003] In a vehicle networking environment, vehicles can share key information with each other, such as location, speed, driving behavior, road conditions, and emergency operations. This information is crucial for improving road safety, optimizing traffic flow, and enhancing the driving experience. However, this data contains a large amount of sensitive information, such as location data, identity information, communication content, and user behavior data. Therefore, it is necessary to anonymize vehicle information to protect privacy. In addition, the data security issue in vehicle networking has become increasingly prominent.
[0004] Malicious vehicles may send false information or deliberately discard data packets, resulting in data forwarding failures. These behaviors not only undermine the reliability and efficiency of the network, but also pose a serious threat to road safety. Specifically, malicious behaviors include, but are not limited to: (1) Spreading false information: Attackers may deliberately spread incorrect data, such as providing inaccurate location information or false road condition updates, misleading the driving decisions of other vehicles, thereby increasing the risk of traffic accidents. (2) Interfering with data transmission: Malicious vehicles may deliberately ignore forwarding received data packets or tamper with them during data transmission. This behavior will result in the inability to accurately convey information, affecting the effectiveness of the entire traffic management system and the coordinated operation between vehicles.
[0005] In view of these challenges, it is particularly important to develop a vehicle networking trust management method that can ensure data security, maintain the authenticity and integrity of information, and at the same time protect user privacy. Such a method will help improve the credibility of the vehicle networking system, enhance user confidence, and ensure public safety.
[0006] In the vehicle networking environment, the information transmission between vehicles must ensure the authenticity, integrity, and privacy of messages to prevent malicious attacks and information tampering. Cryptography-based methods can guarantee the legitimacy of data sources but cannot solve the problem of legitimate vehicles being manipulated; while trust management effectively solves this problem by evaluating the behaviors of different vehicles transmitting data to calculate different vehicle trust values and handling vehicles with low trust values in a blacklist. However, traditional distributed trust management has the following defects: lack of cross-regional data consistency, slow trust value generation speed, and failure to fully utilize the computing resources of trusted sources (such as roadside units). Summary of the Invention
[0007] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a vehicle networking trust management system and method to solve the problem of lack of cross-regional data consistency in vehicle networking and improve the efficiency and security of vehicle networking trust management.
[0008] To solve the above technical problems, the present invention is implemented by adopting the following technical solutions:
[0009] In the first aspect, the present invention provides a vehicle networking trust management system, including vehicles, roadside units, trusted institutions, and an edge-layer blockchain and a core-layer blockchain based on Hyperledger; the vehicles interact with the edge-layer blockchain through the network access certificates issued by the trusted institutions; the roadside units, as blockchain edge-layer nodes, upload information to manage the vehicle trust ledger of the edge-layer Hyperledger and interact with the core-layer trusted institution data through the network access certificates and endorsement certificates issued by the trusted institutions; the vehicle trust ledger records the vehicle trust situation, and the change of the vehicle trust ledger is endorsed by a single roadside unit; the trusted institution, as a blockchain core-layer node, manages the certificate ledger of the core-layer Hyperledger and the roadside unit trust ledger; the certificate ledger records the certificate situations of vehicles and roadside units, and the roadside unit trust ledger records the roadside unit trust situation.
[0010] In the second aspect, the present invention provides a vehicle networking trust management method based on the vehicle networking trust management system in the first aspect, including:
[0011] S1: Initialize the vehicle networking trust management system, and the trusted institution issues network access certificates and endorsement certificates to the networked roadside units;
[0012] S2: Authenticate the identity of the vehicles newly entering the network and apply for pseudonyms and network access certificates from the trusted institution;
[0013] S3: Conduct trust management on the vehicles entering the network in step S2 and the roadside units entering the network in step S1 respectively;
[0014] The trust management in step S3 includes: repeatedly executing step S3. When it is determined that the vehicle attempting to access the network is a malicious vehicle, cancel its eligibility to access the network; when it is determined that the roadside unit uploads incorrect information, cancel its endorsement eligibility; when it is determined that the roadside unit is a malicious roadside unit, cancel its eligibility to access the network.
[0015] For the aforementioned vehicle networking trust management method, the trust management of the vehicles accessing the network in step S2 in step S3 includes:
[0016] C1: The vehicles accessing the network calculate the trust values among themselves and the roadside unit calculates the global trust value of the vehicles accessing the network;
[0017] C2: Integrate the trust values calculated in step C1, calculate the final trust value of the vehicles finally accessing the network, and determine whether the vehicles accessing the network are malicious vehicles according to a preset final trust value threshold;
[0018] In step C1, the vehicles accessing the network calculate the trust values among themselves, including: other vehicles calculate the trust value of a single vehicle:
[0019] CC11: The vehicles directly interacting with vehicle j calculate the direct trust value of vehicle j according to their direct interaction records with vehicle j, and upload the calculated direct trust value to the vehicle trust ledger through the roadside unit;
[0020] CC12: The vehicles not directly interacting with vehicle j calculate the indirect trust value of vehicle j according to the direct trust values provided by the vehicles directly interacting with vehicle j on the vehicle trust ledger, and upload it to the vehicle trust ledger through the roadside unit.
[0021] For the aforementioned vehicle networking trust management method, calculating the direct trust in vehicle j in step CC11 includes:
[0022] CC111: The vehicles directly interacting with vehicle j calculate the transmission reliability, forgetting factor, and cooperation metric of vehicle j according to their direct interaction records with vehicle j; vehicle i is a vehicle that has directly interacted with vehicle j. At the current time t, vehicle i calculates the transmission reliability of vehicle j The calculation formula is:
[0023] ,
[0024] In the formula, is the number of times vehicle j has successfully forwarded data packets recorded by vehicle i from the initial time to time t; is the total number of data packets sent by vehicle i to vehicle j recorded by vehicle i from the initial time to time t; successfully forwarding a data packet means that the data packet forwarded by vehicle j is complete and not tampered with; and The data is sourced from the direct interaction records between vehicle i and vehicle j;
[0025] At the current moment t, vehicle i calculates the forgetting factor of vehicle j The calculation formula is:
[0026] ,
[0027] In the formula, is the interaction moment, and the data is sourced from the direct interaction records between vehicle i and vehicle j; is the preset forgetting coefficient;
[0028] At the current moment t, vehicle i calculates the cooperation metric of vehicle j The calculation formula is:
[0029] ,
[0030] In the formula, is the number of vehicles that have directly interacted with vehicle j from the initial moment to moment t; M is the total number of vehicles in the vehicle networking; is the maximum value of the number of data packets forwarded by a single vehicle from the initial moment to moment t; is the number of data packets forwarded by vehicle j from the initial moment to moment t; , M, and The data is sourced from the vehicle networking system;
[0031] CC112: Calculate the direct trust value of the vehicle interacting with vehicle j for vehicle j based on the transmission reliability, forgetting factor, and cooperation metric of vehicle j obtained in step CC111;
[0032] At the current moment t, vehicle i calculates the direct trust value of vehicle j The calculation formula is:
[0033] ,
[0034] In the formula, is the preset transmission reliability weight coefficient;
[0035] CC113: Upload the pseudonyms of the vehicles interacting with vehicle j in step CC112 and the corresponding calculated direct trust values for vehicle j to the vehicle calculation trust table in the vehicle trust ledger through the roadside unit;
[0036] The calculation of the indirect trust value for vehicle j in step CC12 includes:
[0037] CC121: A vehicle that has no direct interaction with vehicle j calculates the trust similarity between itself and the vehicles that have direct interaction with vehicle j based on the direct trust values of the same vehicle for itself and the vehicles that have direct interaction with vehicle j.
[0038] Vehicle l is a vehicle that has no direct interaction with vehicle j, vehicle h is a vehicle that has had direct interaction with vehicle j, and vehicle x is a vehicle that has had direct interaction with both vehicle l and vehicle h. At the current time t, the trust similarity between vehicle l and vehicle h is calculated by the formula:
[0039] ,
[0040] In the formula, is the set of vehicle x, is the number of vehicle x, is the direct trust value of vehicle l for vehicle x, is the direct trust value of vehicle h for vehicle x, is the absolute value operation, is the summation operation;
[0041] CC122: A vehicle that has no direct interaction with vehicle j calculates the trust weight for the vehicles that have direct interaction with vehicle j based on the trust similarity calculated in step CC121.
[0042] At the current time t, the trust weight of vehicle l for vehicle h is calculated by the formula:
[0043] ,
[0044] In the formula, is the direct trust value of vehicle l for vehicle h. If vehicle l has no direct interaction with vehicle h, then takes the value of 0.5;
[0045] CC123: A vehicle that has no direct interaction with vehicle j calculates the indirect trust value for vehicle j based on the trust weight calculated in step CC122.
[0046] At the current time t, the indirect trust value of vehicle l for vehicle j is calculated by the formula:
[0047] ,
[0048] In the formula, is the set of vehicle h, is the number of vehicle h, is the direct trust value of vehicle h for vehicle j;
[0049] CC124: Upload the vehicle pseudonyms that have no direct interaction with vehicle j in step CC123 and the corresponding indirectly calculated trust values for vehicle j to the vehicle calculation trust table in the vehicle trust ledger through the roadside unit.
[0050] In the aforementioned vehicle networking trust management method, the roadside unit calculates the global trust value of the networked vehicles in step C1, including:
[0051] CL11: The roadside unit selects trusted vehicles from the vehicles with malicious behavior of 0; the roadside unit sets the initial malicious behavior of the networked vehicles to be 0, ;
[0052] CL12: The trusted vehicle sends a detection packet to the target vehicle. After receiving the detection packet, the target vehicle forwards the detection packet to the roadside unit in step CL11 according to a preset program; the preset program includes: forwarding the detection packet to the roadside unit in step CL11 within a preset time period;
[0053] The current moment The trusted vehicle sends a detection packet to the target vehicle where, is the detection message; is the hash value of the detection message; is the digital signature generated by the trusted vehicle using its private key to sign the detection message; using its private key to sign the detection message;
[0054] CL13: After the preset time period, the roadside unit verifies the reception status of the detection packet;
[0055] The reception status includes: whether the detection packet is received within the preset time period and whether the received detection packet data is consistent with the content of the sent data packet;
[0056] CL14: If the roadside unit does not receive the detection packet within the preset time period or the received detection packet is inconsistent with the content of the sent data packet, record that the malicious behavior of the target vehicle is incremented by 1;
[0057] CL15: Loop through steps CL11 to CL14 until the preset moment;
[0058] CL16: Calculate the global trust value of the networked vehicles according to the malicious behavior recorded by the roadside unit;
[0059] At the current moment t, the global trust value of vehicle j is calculated by the formula:
[0060] ;
[0061] In the formula, is the number of malicious behaviors of vehicle j from time t-1 to time t; is the global trust weight from time t-1 to time t, = , is the maximum value of the number of malicious behaviors of a single vehicle in the networked vehicles M from time t-1 to time t;
[0062] CL17: The roadside unit uploads the pseudonym of the target vehicle in step CL16 and the calculated global trust value to the global trust table of the vehicle trust ledger;
[0063] The roadside unit also uploads the recorded malicious behaviors in the form of malicious behavior verification codes to the vehicle trust ledger; among them, the malicious behavior verification code includes the trusted vehicle pseudonym of the detected target vehicle, digital signature of the trusted vehicle and the hash value of the detection message , and the storage form of the malicious behavior verification code is:
[0064] < pseudonym>,
[0065] The roadside unit stores the malicious behavior verification code correspondingly in the global trust table of the target vehicle.
[0066] For the aforementioned vehicle network trust management method, step C2 includes:
[0067] C21: Calculate the final trust value of the finally networked vehicles, and upload it to the vehicle final trust table of the vehicle trust ledger through the roadside unit. The final trust value of vehicle j at the current time t has the following calculation formula:
[0068] ,
[0069] In the formula, is M-1; is other vehicles other than vehicle j among the networked vehicles, and ; is the preset final trust value weight coefficient; is the direct trust value of vehicle to vehicle j at the current time t;
[0070] C22: Judge whether the networked vehicle is a malicious vehicle according to the preset final trust value threshold , including:
[0071] If , then it is determined that vehicle j is a malicious vehicle, the current network access qualification of vehicle j is cancelled, and the network access certificate of vehicle j is added to the revocation list; if , then it is determined that vehicle j is a normal vehicle.
[0072] For the above vehicle networking trust management method, the trust management of the roadside units accessing the network in step S3 includes:
[0073] Detect the endorsement qualification of the roadside unit, and judge whether the roadside unit uploads incorrect information to the blockchain according to the vehicle trust ledger and the roadside unit trust ledger; when it is judged that the roadside unit uploads incorrect information, cancel the endorsement qualification of the roadside unit;
[0074] Detect the network access qualification of the roadside unit, including:
[0075] R1: The trusted institution detects whether the roadside unit sends incorrect information to the trusted institution through data comparison;
[0076] R2: When step R1 detects that the roadside unit sends incorrect information to the trusted institution, the trusted institution uses the maximum likelihood ratio to detect whether the roadside unit is a malicious roadside unit; when it is judged that the roadside unit is a malicious roadside unit, cancel the network access qualification of the roadside unit.
[0077] For the above vehicle networking trust management method, the detection of the endorsement qualification of the roadside unit includes:
[0078] B1: The trusted institution obtains the malicious behavior verification code recorded in the global trust table in the vehicle trust ledger, and judges whether the roadside unit forges the vehicle malicious behavior record according to the verification function. If the roadside unit forges the vehicle malicious behavior record, cancel the endorsement qualification of the roadside unit;
[0079] Obtain the malicious behavior verification code in the global trust table:
[0080] , through the pseudonym to find the corresponding public key , and then judge according to the output result of the verification function ;
[0081] If the output result of the verification function is True, it indicates that the roadside unit does not forge the vehicle malicious behavior;
[0082] If the output result of the verification function is , it indicates that the roadside unit forges the vehicle malicious behavior. The trusted institution cancels the endorsement qualification of the roadside unit, adds the endorsement certificate of the roadside unit to the revocation list, and updates the status of the roadside unit to the roadside unit trust ledger; the status of the roadside unit includes: cancelled endorsement qualification, cancelled network access qualification, and normal;
[0083] B2: The trusted institution calculates the corresponding roadside unit trust value based on the vehicle trust ledger managed by the roadside unit, and determines whether the roadside unit uploads incorrect information to the blockchain according to the roadside unit trust value; Step B2 includes:
[0084] B21: The trusted institution calculates the trust distance between each roadside unit based on the vehicle trust ledger managed by each roadside unit;
[0085] The current moment Roadside unit and roadside unit The trust distance The calculation formula is:
[0086] ,
[0087] In the formula, Is the final trust value of vehicle j calculated by roadside unit at the current moment t; Is the final trust value of vehicle j calculated by roadside unit at the current moment t;
[0088] B22: According to the trust distance between each roadside unit obtained in step B21, calculate the -adjacent trust distance between each roadside unit;
[0089] The current moment Roadside unit and roadside unit The -adjacent trust distance The calculation formula is:
[0090] = ,
[0091] In the formula, Represents the current moment Roadside unit The k-th largest among the R-1 trust distance values of is the trust distance between roadside unit and roadside unit , And , where R is the total number of roadside units in the vehicle network;
[0092] B23: According to the -adjacent trust distance between each roadside unit obtained in step B22, calculate the -adjacent trust density of each roadside unit;
[0093] Current moment Roadside unit of -proximity trust density The calculation formula is as follows:
[0094] ,
[0095] ,
[0096] ,
[0097] ,
[0098] In the formula, is the current moment roadside unit and roadside unit the -proximity trust distance; represents that at the current moment roadside unit the largest among the R - 1 trust distance values of is the trust distance between roadside unit and roadside unit and and ; represents that at the current moment roadside unit the k - th largest among the R - 1 trust distance values of is the trust distance between roadside unit and roadside unit and and ; is the current moment roadside unit and roadside unit the -proximity trust distance; represents that at the current moment roadside unit the second largest among the R - 1 trust distance values of is the trust distance and ; represents that at the current moment roadside unit the k - th largest among the R - 1 trust distance values of is the trust distance ; is the current moment roadside unit and roadside unit the -proximity trust distance; Indicates the current moment Roadside unit Among the R - 1 trust distance values of the roadside unit, the k - th largest is the trust distance And ; Indicates the current moment Roadside unit Among the R - 1 trust distance values of the roadside unit, the k - th largest is the trust distance ; Is the roadside unit The total number of; Is the reciprocal operation;
[0099] B24: For each roadside unit obtained according to step B23 - Proximity trust density, calculate the corresponding roadside unit trust value;
[0100] Current moment Roadside unit Trust value The calculation formula is:
[0101] ,
[0102] In the formula, Is the previous moment Roadside unit Trust value;
[0103] B25: According to the trust values of each roadside unit calculated in step B24 and the preset roadside unit trust value threshold , determine whether the roadside unit uploads error information to the blockchain; if , then determine the roadside unit Uploads error information to the blockchain, and the trusted institution cancels the endorsement qualification of the roadside unit , adds the endorsement certificate of the roadside unit To the revocation list, and updates the roadside unit trust value and roadside unit status to the roadside unit trust ledger; if , then the trusted institution updates the roadside unit trust value to the roadside unit trust ledger.
[0104] The aforementioned vehicle - to - everything trust management method, step R1 includes:
[0105] R11: The vehicle establishes a communication connection with the roadside unit, and vehicle j sends a data packet To the trusted node c through the roadside unit , and vehicle j generates an authentication parameter based on bitwise exclusive - or according to the sent data packet , and the authentication parameter The expression of is:
[0106] ,
[0107] wherein, is the first data packet sent by vehicle j to the roadside unit ; is the th data packet sent by vehicle j to the roadside unit ; is the binary representation of the total number of data packets sent by vehicle j to the trusted node through the roadside unit ; is a hash function, is the private key of vehicle j;
[0108] R12: Vehicle j uses the public key of the trusted agency c to encrypt the authentication parameter generated in step R11 to generate a feedback packet , and when vehicle j enters the coverage area of another roadside unit and establishes communication, send the feedback packet to the trusted agency c through it;
[0109] R13: After receiving the data packet sent by the roadside unit and the feedback packet sent by another roadside unit, the trusted agency c recalculates the authentication parameter , and uses the own key of the trusted agency c to decrypt the feedback packet to obtain the authentication parameter ;
[0110] The calculation formula for recalculating the authentication parameter is:
[0111] ,
[0112] wherein, is the first data packet received by the trusted agency c through the roadside unit ; is the th data packet received by the trusted agency c through the roadside unit ; is the binary representation of the total number of data packets received by the trusted agency through the roadside unit ;
[0113] R14: The trusted node compares the authentication parameter recalculated in step R13 with the authentication parameter obtained by decryption to determine whether the error message is caused by the roadside unit; if , the error message is caused by the roadside unit .
[0114] The aforementioned vehicle networking trust management method, step R2 includes:
[0115] R21: Repeatedly execute step R1 to collect the communication records between the networked vehicles and the roadside unit from the historical moment to the current moment ; the communication records include the number of vehicles communicating with the roadside unit and the number of times the data of the data packet and the feedback packet are inconsistent at each moment in step R1;
[0116] R22: According to the number of times the data of the data packet and the feedback packet are inconsistent at each moment collected in step R21, construct binomial distributions under the null hypothesis condition H0 and the alternative hypothesis condition H1 respectively; the binomial distributions are constructed as follows:
[0117] Under the null hypothesis condition H0, the roadside unit is not a malicious entity, and the probability that the data of the data packet and the feedback packet are inconsistent is , at the moment the number of times the data of the data packet and the feedback packet are inconsistent follows a binomial distribution with parameters : ; where is the number of vehicles communicating with the roadside unit from the historical moment to the current moment ; ;
[0118] Under the alternative hypothesis condition H1, the roadside unit is detected as a malicious entity at the moment , and the probability that the data of the data packet and the feedback packet are inconsistent is , at the moment the number of times the data of the data packet and the feedback packet are inconsistent after the moment follows a binomial distribution with parameters : ), ;
[0119] R23: According to the binomial distributions constructed in step R22, calculate the joint probabilities under the null hypothesis condition H0 and the alternative hypothesis condition H1 respectively;
[0120] When the roadside unit is not malicious, the joint probability of observing the inconsistent situations of the data of the data packet and the feedback packet at each moment is:
[0121]
[0122] ;
[0123] When the roadside unit is malicious, the inconsistent situation between the data packets and feedback packets at each moment is observed of the joint probability is:
[0124]
[0125] ;
[0126] R24: Calculate the likelihood ratio statistic based on the joint probability calculated in step R23 , the likelihood ratio statistic The calculation formula of is:
[0127] ;
[0128] R25: Based on the likelihood ratio statistic calculated in step R24 and the preset likelihood ratio statistic threshold , determine whether the error message is caused by the malicious behavior of the roadside unit;
[0129] If > , then determine that the roadside unit is malicious, and the error message is caused by the malicious behavior of the roadside unit;
[0130] R26: When step R25 determines that the error message is caused by the malicious behavior of the roadside unit, the trusted agency cancels the network access qualification of the roadside unit, adds the network access certificate of the roadside unit to the revocation list, and updates the roadside unit status to the roadside unit trust ledger.
[0131] Compared with the prior art, the beneficial effects achieved by the present invention:
[0132] The present invention adopts a vehicle networking trust management system composed of vehicles, roadside units, trusted agencies, and an edge layer blockchain and a core layer blockchain based on Hyperledger. The vehicle certificate is issued by a trusted agency and serves as an access identity certificate and a communication permission basis; the roadside unit certificate is issued by a trusted agency, authorizing it as an endorsing node of the blockchain edge layer and verifying and signing the transactions submitted by vehicles; both types of certificates realize full life cycle management (registration / updating / revocation) through the core layer blockchain, improving the credibility of vehicle networking communication and trust evaluation.
[0133] When a vehicle moves across regions, roadside units (RSUs) or edge nodes in different geographical regions may cause inconsistencies in key data such as vehicle identity status, trust evaluation results, or transaction history due to network latency, ledger synchronization lag, or management domain differences. The present invention adopts a hierarchical ledger that coordinates the edge layer and the core layer. The RSU in the edge layer quickly responds to and processes high-frequency transactions of vehicles within its communication range, and a trusted institution in the core layer manages the global certificate lifecycle and cross-region arbitration to ensure that all global state changes (such as certificate revocation) immediately reach a consensus across the network. By combining blockchain edge caching with incremental synchronization, cross-region latency is reduced. When a vehicle enters a new region, the RSU in the new region queries the vehicle information through data interaction with the core layer and pulls data from the RSU in the old region. While ensuring cross-region data consistency, the centralized bottleneck of traditional solutions is avoided, the problem of lack of cross-region data consistency in the vehicle network is solved, and the efficiency and security of vehicle network trust management are improved.
[0134] The design of the double-layer blockchain network of the present invention isolates the edge layer and the core layer, improving the security of the vehicle network. In the edge layer with low security requirements, the RSU is authorized to manage the trust situation of vehicles; in the core layer with high security requirements, it is directly managed by a trusted institution, and the trusted institution also manages the trust situation of the RSU. The core layer and the edge layer are securely isolated. The edge layer is exempt from sorting overhead and does not need to store complete ledger information, adapting to the low-latency requirements of the vehicle network.
[0135] The vehicle network trust management method of the present invention differentiates the trust management methods for vehicles and RSUs. For vehicle trust management, the trust values of vehicles and RSUs are calculated separately, and the network access qualification of vehicles is measured based on the calculated final trust value; the RSU trust management method divides the endorsement qualification detection and network access qualification detection with differentials according to the impact of RSU behavior on the security of the vehicle network system.
[0136] The vehicle trust value calculation of the present invention includes calculating the direct trust value and the indirect trust value of the vehicle, integrating the global trust value calculated by the RSU, and obtaining the final trust value of the vehicle. This method of collecting trust opinions from multiple parties improves the accuracy of vehicle trust value calculation and reduces the error risk.
[0137] The present invention calculates the direct trust value of a vehicle through multi-dimensional indicators: evaluates the transmission reliability based on the interaction behavior between vehicles; introduces a forgetting factor to assign higher weights to recent events to reflect the timeliness impact; also screens cooperative vehicles that actively forward messages through cooperation metrics, and finally calculates the direct trust value by comprehensively considering the three indicators. This method significantly improves the accuracy of trust value calculation through multi-angle quantitative evaluation.
[0138] The RSU trust management method of the present invention achieves precise protection through hierarchical security control: when a trusted institution detects that an RSU affects the trust calculation of an access vehicle, the RSU that only affects the data security of the edge layer has its endorsement qualification cancelled but its access qualification retained, which not only isolates risks but also maintains basic services; for malicious RSUs that threaten the data of the core layer, their access qualifications are completely cancelled to ensure the security of the global ledger. This design balances the system security and availability through differential disposal, can quickly isolate risk nodes and avoid excessive punishment. At the same time, a multi-level defense system is constructed through dynamic monitoring by the trusted institution, effectively improving the overall security protection ability.
[0139] The RSU endorsement qualification detection of the present invention ensures data reliability through a dual verification mechanism: on the one hand, it detects whether the RSU forges the vehicle malicious behavior verification code to identify direct fraud behavior, and on the other hand, it evaluates its historical credibility based on the dynamically calculated RSU trust value. This dual-criterion design of "behavior evidence + trust assessment" significantly improves the accuracy of detecting the RSU endorsement qualification, prevents unilateral misjudgment and forms cross-verification. At the same time, through the calculation of continuously updated RSU trust values, dynamic monitoring of RSU behavior is realized, effectively guaranteeing the authenticity and credibility of the data uploaded from the edge layer to the blockchain, and maintaining the security of the vehicle network trust management system from the source.
[0140] The present invention realizes the precise identification and disposal of RSU malicious behavior through a dual verification mechanism: first, a dynamic authentication mechanism of data packets and feedback packets is adopted. The vehicle generates authentication parameters through exclusive OR operation and encrypts and transmits them. The trusted institution directly locates the responsible party for data tampering through data comparison; then, a statistical detection model is constructed based on historical communication data, and the quantitative determination of malicious behavior is realized through binomial distribution probability analysis and likelihood ratio test, and malicious RSUs are objectively identified in combination with a preset threshold. This solution significantly improves the reliability and security of the vehicle network trust management method through a two-layer detection architecture of "real-time data authentication + historical behavior analysis". Description of the Drawings
[0141] Figure 1 It is a schematic framework diagram of the vehicle network trust management method in Embodiment 2 of the present invention; Detailed Embodiments
[0142] The technical solution of the present invention will be described in detail below through the drawings and specific embodiments. It should be understood that the specific features in the embodiments of the present application and the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application. Without conflict, the technical features in the embodiments of the present application and the embodiments can be combined with each other. In this article, the character " / " generally indicates that the related objects before and after are in an "or" relationship.
[0143] Embodiment 1:
[0144] This embodiment introduces a vehicle networking trust management system, including:
[0145] Vehicles, roadside units, trusted institutions, and an edge-layer blockchain and a core-layer blockchain based on Hyperledger Fabric;
[0146] The vehicle interacts with the edge-layer blockchain through an access certificate issued by a trusted institution; the vehicle is equipped with an on-vehicle unit, whose computing and storage resources are limited, and is used to collect and process traffic information in real time, and call chain codes through a preset vehicle networking communication protocol to interact with neighboring blockchain entities (roadside units and other vehicles); when the vehicle first accesses the network, it needs to apply for a digital certificate from a trusted institution to obtain a legal identity, and implement anonymous authentication (such as a pseudonym certificate) based on this certificate in subsequent communications to ensure privacy protection and communication security;
[0147] The roadside unit RSU, as a semi-trusted intermediate entity, is located between the vehicle and the trusted institution, is a node of the edge layer of the blockchain, and uploads information to manage the vehicle trust ledger in the edge-layer Hyperledger Fabric as shown in Table 1 and interacts with the core-layer trusted institution data; it is responsible for communicating with the vehicle to exchange road information and expand the communication range, and at the same time submits the interaction data to the edge-layer blockchain; the vehicle trust ledger records the vehicle trust situation, and the change of the vehicle trust ledger is endorsed by a single roadside unit;
[0148] Table 1 Vehicle Trust Ledger
[0149]
[0150] The trusted institution, as the regulatory gateway of the roadside unit, is a node of the core layer of the blockchain, manages the certificate ledger shown in Table 2 and the roadside unit trust ledger shown in Table 3 of the core-layer Hyperledger Fabric; performs the functions of registering, updating, and revoking vehicle certificates, and supervises the behavior of roadside units through the core-layer blockchain, and finally maintains the consistency of the global trust value; the certificate ledger records the certificate situations of vehicles and roadside units, and the roadside unit trust ledger records the roadside unit trust situation.
[0151] Table 2 Certificate Ledger
[0152]
[0153] Table 3 Roadside Unit Trust Ledger
[0154]
[0155] The double-layer blockchain is built based on Hyperledger Fabric and includes an edge layer and a core layer.
[0156] The edge layer consists of roadside units as nodes, which are responsible for local data collection and preliminary verification (such as trust data uploaded by vehicles); run lightweight edge chain codes to handle trust interactions between vehicles and roadside units (such as reputation score updates); key components include clients (vehicles), endorsement nodes (roadside units) and submission nodes to ensure the consistency of edge layer data. In other words, the edge layer is responsible for real-time trust data collection and local trust consensus between vehicles and roadside units.
[0157] The core layer is composed of trusted institutions, responsible for global trust management and certificate authority functions; running core chain codes, managing the certificate lifecycle of vehicles / roadside units and global trust consensus; key components include sorting nodes (responsible for transaction sorting and block generation) and commit nodes (complete final ledger updates). In other words, the core layer is responsible for global certificate management and trust value consistency maintenance.
[0158] Among them, certificate lifecycle management includes:
[0159] Certificate issuance: When a vehicle first joins the network or a roadside unit is deployed, a digital certificate is issued to it;
[0160] Certificate renewal: Regularly replace certificates (e.g. when the vehicle pseudonym certificate expires);
[0161] Certificate revocation: When an entity (vehicle / roadside unit) behaves abnormally (such as maliciously falsifying data), its certificate is added to the revocation list.
[0162] Certificate status synchronization: The trusted institution writes the newly issued or revoked certificate information into the core layer blockchain for real-time query by all network nodes (including edge layer RSU).
[0163] The core layer achieves global consensus through sorting nodes to ensure the consistency of transaction order and ledger status; at the same time, relying on chain code logic and certificate issuance mechanism, it maintains the global consistency of trust values between vehicles and roadside units, and ultimately achieves trusted decision-making (such as isolation of malicious vehicles / nodes).
[0164] The roadside unit and the vehicle communicate and exchange road information according to the preset Internet of Vehicles communication protocol, and submit the trust data to the edge layer blockchain; the trusted institution verifies the behavior of the roadside unit through the core layer, responds to the certificate request of the vehicle and the roadside unit, and records the certificate status in the blockchain for verification by the entire network, and coordinates cross-layer data synchronization through the Hyperledger Fabric channel mechanism: the edge layer RSU submits local trust data to the core layer for aggregation, and the core layer sends global policies (such as certificate revocation lists) to the edge layer. The system operates collaboratively through a layered architecture to achieve distributed storage, dynamic updates, and secure and efficient Internet of Vehicles communication of trust values.
[0165] Embodiment 2
[0166] Based on the same inventive concept as in Embodiment 1, as Figure 1 shown, this embodiment introduces a vehicle networking trust management method. Based on the vehicle networking trust management system described in Embodiment 1, it includes:
[0167] S1: Initialize the vehicle networking trust management system, and the trusted institution issues an access certificate and an endorsement certificate to the roadside units accessing the network;
[0168] S2: Authenticate the identity of the vehicles accessing the network for the first time, and apply for pseudonyms and access certificates from the trusted institution;
[0169] S3: Conduct trust management on the vehicles accessing the network in step S2 and the roadside units accessing the network in step S1 respectively;
[0170] The trust management in step S3 includes: repeatedly execute step S3. When it is determined that the vehicle accessing the network is a malicious vehicle, cancel the access qualification of the malicious vehicle; when it is determined that the roadside unit uploads incorrect information, cancel the endorsement qualification of the roadside unit; when it is determined that the roadside unit is a malicious roadside unit, cancel the access qualification of the roadside unit.
[0171] The following introduces the specific implementation manners of each step:
[0172] S1: Initialize the vehicle networking trust management system;
[0173] S11: Initialize cryptographic tools for vehicle networking identity authentication; support pseudonym rotation to achieve privacy protection;
[0174] S111: Deploy a public key infrastructure PKI that complies with the IEEE 1609.2 standard;
[0175] Specifically include: When initializing the system, define the following cryptographic parameters:
[0176] Define an elliptic curve , where is an additive cyclic group on , whose order is a large prime number , P is the generator of the group and ; at the same time, select two collision-resistant hash functions and , and ; the above parameters are broadcast by the trusted institution to the blockchain network.
[0177] S112: Configure the root certificate authority Root CA permission for the trusted institution, and generate a root certificate and the corresponding certificate revocation list CRL storage structure;
[0178] S12: Construct a two-layer blockchain network;
[0179] S121: Initialize the Hyperledger Fabric network, including organization definition, channel creation, and node deployment.
[0180] Organization definition includes:
[0181] Core layer organizations: Responsible for global transactions such as certificate management and cross-layer data synchronization;
[0182] Node types included in core layer organizations:
[0183] Endorsing nodes: Assumed by trusted institutions, execute chaincodes and endorse transactions in the core layer, ensure the legality and validity of transactions, and sign transactions according to the predefined endorsement policy to provide endorsements;
[0184] Ordering nodes: Assumed by trusted institutions, use the Kafka consensus algorithm to perform a total order on the network-wide transactions, then package a batch of ordered transactions (by time or size threshold) into a single block, and broadcast it to the committing nodes through the Gossip protocol;
[0185] Committing nodes: Verify the block and submit the verified block to the ledger in the core layer; The ledger in the core layer includes the roadside unit trust ledger and the certificate ledger.
[0186] Edge layer organizations: Responsible for local transactions such as vehicle-RSU real-time interaction;
[0187] Node types included in edge layer organizations:
[0188] Endorsing nodes: Assumed by RSUs, handle local transaction endorsements;
[0189] Committing nodes: Verify the edge channel block and submit the verified block to the ledger in the edge layer; The ledger in the edge layer includes the vehicle trust ledger;
[0190] Do not include ordering nodes, rely on the ordering nodes in the core layer to provide block ordering services.
[0191] Cross-layer collaboration:
[0192] Edge layer transactions are linked to the core layer ordering nodes through channels for unified ordering; Hierarchical deployment reduces the computing load of edge nodes (RSUs do not need to participate in global consensus).
[0193] Channel creation includes:
[0194] Core channel: Only allows trusted institutions to join, used for global certificate management and trust policy synchronization;
[0195] Edge channel: Allows RSUs to join, processes local trust data transactions.
[0196] Node deployment includes:
[0197] Trusted institutions: As the ordering nodes of the core channel and the certificate authority CA nodes (the endorsing nodes of the core channel);
[0198] RSU nodes: As the endorsing nodes of the edge channel, install lightweight chaincodes (such as trust score calculation logic).
[0199] In the system initialization phase, the trusted institution provides identity authentication for the roadside units, generates pseudonyms and certificates for the roadside units, as shown in Table 2, and saves the identity information such as the ID, certificate, and pseudonym of the roadside units to the certificate ledger;
[0200] The advantages of the double-layer blockchain network include:
[0201] Performance optimization: The edge layer eliminates the sorting overhead and adapts to the low-latency requirements of the vehicle networking;
[0202] Security isolation: The core layer sorting service maintains the global transaction order consistency;
[0203] Resource adaptation: Edge devices such as RSU do not need to store the complete ledger (can be configured as lightweight nodes).
[0204] To prevent the verification delay caused by the frequent rotation of vehicle certificates, the edge layer caches the hash of the valid pseudonym certificate to reduce the query pressure on the core layer.
[0205] S122: Configure different endorsement policies for different channels;
[0206] Edge channel: Adopt the OR endorsement policy, and only need a single roadside unit endorsement to pass the verification;
[0207] Core channel: Adopt a strict consensus mechanism, requiring more than two-thirds of the trusted institutions to endorse to confirm the transaction.
[0208] Step S2 includes: Uploading the vehicle identity information as shown in Table 2 to the certificate ledger;
[0209] S21: When vehicle i joins the vehicle networking, first send a certificate registration request to the trusted institution and upload the vehicle ID ;
[0210] S22: After receiving the vehicle registration request and the vehicle ID, the trusted institution generates a random number for vehicle i as the private key, and calculates the corresponding public key of vehicle i according to the private key , ,where P is a base point on a pre-defined elliptic curve;
[0211] S23: Based on the public key generated in step S22, the trusted authority generates the certificate of vehicle i and pseudonym ,
[0212] , the certificate includes the vehicle , public key , the signature of the trusted authority C and the certificate validity period to prove the identity of the vehicle;
[0213] , where represents the exclusive OR operation, is a preset hash function; the pseudonym is the basis for the anonymous communication of the vehicle, and the addition of the hash function is used to ensure the uniqueness and irreversibility of the pseudonym;
[0214] S24: The trusted authority uploads the vehicle ID, the certificate and pseudonym of vehicle i generated in step S23 to the certificate ledger.
[0215] When the certificate is about to expire or the private key is lost, vehicle i must submit a certificate update request to the trusted authority. After successful identity authentication, when the vehicle chooses to revoke the original certificate, the old certificate will be added to the certificate revocation list.
[0216] The process of step S2 not only ensures the legality and security of the vehicle identity, but also effectively protects the privacy of the vehicle through the pseudonym mechanism.
[0217] The trust management of the vehicles accessing the network in step S3 includes:
[0218] C1: The vehicles accessing the network calculate the trust values with each other and the roadside unit calculates the global trust value of the vehicles accessing the network;
[0219] C2: Integrate the trust values calculated in step C1, calculate the final trust value of the vehicles finally accessing the network, and judge whether the vehicles accessing the network are malicious vehicles according to the preset final trust value threshold;
[0220] In step C1, the vehicles accessing the network calculate the trust values with each other, including:
[0221] CC11: The vehicle directly interacting with vehicle j calculates the direct trust value of vehicle j according to its own direct interaction record with vehicle j, and uploads the calculated direct trust value to the vehicle trust ledger;
[0222] CC12: The vehicle having no direct interaction with vehicle j calculates the indirect trust value of vehicle j according to the direct trust value provided by the vehicle directly interacting with vehicle j on the vehicle trust ledger, and uploads it to the vehicle trust ledger through the roadside unit.
[0223] In step CC11, calculating the direct trust in vehicle j includes:
[0224] CC111: Vehicles directly interacting with vehicle j calculate the transmission reliability, forgetting factor, and cooperation metric of vehicle j based on their direct interaction records with vehicle j;
[0225] Vehicle i is a vehicle that has directly interacted with vehicle j. At the current time t, vehicle i calculates the transmission reliability of vehicle j The calculation formula is:
[0226] ,
[0227] In the formula, is the number of times vehicle j has successfully forwarded data packets recorded by vehicle i from the initial time to time t; is the total number of data packets sent by vehicle i to vehicle j recorded by vehicle i from the initial time to time t; A successfully forwarded data packet means that the data packet forwarded by vehicle j is complete and not tampered with; and The data comes from the direct interaction records between vehicle i and vehicle j;
[0228] At the current time t, vehicle i calculates the forgetting factor of vehicle j The calculation formula is:
[0229] ,
[0230] In the formula, is the interaction time, and the data comes from the direct interaction records between vehicle i and vehicle j; is a preset forgetting coefficient;
[0231] The forgetting factor assigns higher weights to recently occurred events to reflect the impact of the timeliness of events on the direct trust value.
[0232] At the current time t, vehicle i calculates the cooperation metric of vehicle j The calculation formula is:
[0233] ,
[0234] In the formula, is the number of vehicles that have directly interacted with vehicle j from the initial time to time t; M is the total number of vehicles in the vehicle network; is the maximum value of the number of data packets forwarded by a single vehicle from the initial time to time t; is the number of data packets forwarded by vehicle j from the initial time to time t; , M, and The data is from the vehicle networking system. Considering the cooperation metric of vehicles, the aim is to screen out the vehicles that are willing to forward messages to provide services for others.
[0235] CC112: Calculate the direct trust value of the vehicles interacting with vehicle j for vehicle j according to the transmission reliability, forgetting factor, and cooperation metric of vehicle j obtained in step CC111;
[0236] At the current moment t, vehicle i calculates the direct trust value of vehicle j The calculation formula is:
[0237] ,
[0238] In the formula, is the preset transmission reliability weight coefficient;
[0239] CC113: Upload the pseudonyms of the vehicles interacting with vehicle j in step CC112 and the corresponding calculated direct trust values for vehicle j to the vehicle calculation trust table of the vehicle trust ledger through the roadside unit;
[0240] The calculation of the indirect trust value for vehicle j in step CC12 includes:
[0241] CC121: For the vehicles that have no direct interaction with vehicle j, calculate the trust similarity between their own vehicles and the vehicles that have direct interaction with vehicle j according to their own vehicles and the direct trust values of the vehicles that have direct interaction with vehicle j for the same vehicle;
[0242] Vehicle l is a vehicle that has no direct interaction with vehicle j, vehicle h is a vehicle that has had direct interaction with vehicle j, vehicle x is a vehicle that has had direct interaction with both vehicle l and vehicle h. At the current moment t, the trust similarity between vehicle l and vehicle h The calculation formula is:
[0243] ,
[0244] In the formula, is the set of vehicle x, is the number of vehicle x, is the direct trust value of vehicle l for vehicle x, is the direct trust value of vehicle h for vehicle x, is the absolute value operation, is the summation operation;
[0245] A vehicle that has no direct interaction with vehicle j cannot directly judge the trust in vehicle j based on its own direct interaction records. Therefore, it is necessary to refer to the direct trust values of other vehicles for vehicle j. To reduce the risk of accepting direct trust values provided by malicious vehicles, it is necessary to calculate the similarity between the direct trust values of its own vehicle and the vehicles providing references for the same vehicle. By the magnitude of the trust similarity, the reliability of the direct trust value provided by the vehicle is judged. The greater the trust similarity, the higher the reliability of the direct trust value provided by the vehicle. In subsequent calculations, for direct trust values with higher reliability, the adoption degree is higher.
[0246] CC122: The vehicle that has no direct interaction with vehicle j calculates the trust weight for the vehicle that has direct interaction with vehicle j according to the trust similarity calculated in step CC121;
[0247] The trust weight of vehicle l for vehicle h at the current moment t The calculation formula is:
[0248] ,
[0249] In the formula, is the direct trust value of vehicle l for vehicle h. If there is no direct interaction between vehicle l and vehicle h, the value is taken as 0.5;
[0250] The trust weight is used to measure the adoption degree of direct credit. For vehicles with a large trust similarity to its own vehicle, the adoption degree is high, and the corresponding trust weight is large; for vehicles with a small trust similarity to its own vehicle, the adoption degree is low, and the corresponding trust weight is small.
[0251] CC123: The vehicle that has no direct interaction with vehicle j calculates the indirect trust value for vehicle j according to the trust weight calculated in step CC122;
[0252] The indirect trust value of vehicle l for vehicle j at the current moment t The calculation formula is:
[0253] ,
[0254] In the formula, is the set of vehicle h, is the number of vehicle h, is the direct trust value of vehicle h for vehicle j;
[0255] CC124: The vehicle that has no direct interaction with vehicle j in step CC123, together with the corresponding indirect trust value calculated for vehicle j, uploads the vehicle pseudonym to the vehicle calculation trust table in the vehicle trust ledger through the roadside unit;
[0256] In step C1, the roadside unit calculates the global trust value of the networked vehicles, including:
[0257] CL11: The roadside unit selects trusted vehicles from the vehicles with malicious behavior of 0; the roadside unit sets the initial malicious behavior of the networked vehicles to 0, ;
[0258] CL12: The trusted vehicle sends a detection packet to the target vehicle. After receiving the detection packet, the target vehicle forwards the detection packet to the roadside unit in step CL11 according to a preset program; the preset program includes: forwarding the detection packet to the roadside unit in step CL11 within a preset time period;
[0259] The current moment The trusted vehicle sends a detection packet to the target vehicle , , , where is the detection message; is the hash value of the detection message; is the trusted vehicle using its private key to generate a digital signature for the detection message. The digital signature is mainly used to prevent the roadside unit from forging the malicious behavior of the target vehicle ;
[0260] CL13: After the preset time period, the roadside unit verifies the reception of the detection packet;
[0261] The reception situation includes: whether the detection packet is received within the preset time period and whether the received detection packet data is consistent with the content of the sent data packet;
[0262] CL14: If the roadside unit does not receive the detection packet within the preset time period or the received detection packet is inconsistent with the content of the sent data packet, record that the malicious behavior of the target vehicle is incremented by 1;
[0263] CL15: Loop through steps CL11 to CL14 until the preset moment;
[0264] CL16: Calculate the global trust value of the networked vehicle according to the malicious behavior recorded by the roadside unit;
[0265] The global trust value of vehicle j at the current moment t is calculated by the formula:
[0266] ,
[0267] In the formula, is the number of malicious behavior times of vehicle j from time t - 1 to time t; is the global trust weight from time t-1 to time t, = , is the maximum number of malicious behavior occurrences of a single vehicle among the vehicles M that access the network from time t-1 to time t;
[0268] CL17: The roadside unit uploads the pseudonym of the target vehicle in step S46 and the corresponding calculated global trust value to the global trust table of the vehicle trust ledger;
[0269] The roadside unit also uploads the recorded malicious behavior in the form of a malicious behavior verification code to the vehicle trust ledger; among them, the malicious behavior verification code includes the trusted vehicle pseudonym of the detected target vehicle, the digital signature of the trusted vehicle and the hash value of the detection message , and the storage form of the malicious behavior verification code is:
[0270] < pseudonym>,
[0271] The roadside unit stores all the corresponding malicious behavior verification codes in the global trust table of the target vehicle.
[0272] The roadside unit cooperates with trusted vehicles to detect other vehicles, increases the interaction frequency, and calculates the global trust of vehicles according to whether there is malicious behavior in vehicle-road cooperation detection.
[0273] Step C2 includes:
[0274] C21: Calculate the final trust value of the finally networked vehicles, and upload it to the vehicle final trust table of the vehicle trust ledger through the roadside unit. The final trust value of vehicle j at the current time t The calculation formula is:
[0275] ,
[0276] In the formula, is M-1; is other vehicles except vehicle j among the networked vehicles, and ; is the preset final trust value weight coefficient; is the direct trust value of vehicle to vehicle j at the current time t;
[0277] C22: Judge whether the networked vehicle is a malicious vehicle according to the preset final trust value threshold , including:
[0278] If , then it is determined that vehicle j is a malicious vehicle, the current network access qualification of vehicle j is cancelled, and the network access certificate of vehicle j is added to the revocation list;
[0279] If , then it is determined that vehicle j is a normal vehicle.
[0280] The trusted institution at the core layer of the blockchain conducts trust management on the roadside units at the edge layer; the roadside units include endorsement qualification and network access qualification; when the trusted institution detects that the roadside unit affects the trust calculation of the networked vehicles and affects the data security of the edge layer, the endorsement qualification of the roadside unit is cancelled, and the network access qualification of the roadside unit is retained; when the trusted institution detects that the roadside unit transmits incorrect information to the trusted institution and affects the data security of the core layer of the blockchain, the network access qualification of the roadside unit is cancelled.
[0281] The trust management of the roadside units networked in step S1 in step S3 includes:
[0282] Detect the endorsement qualification of the roadside unit, and judge whether the roadside unit uploads incorrect information to the blockchain according to the vehicle trust ledger and the roadside unit trust ledger; when it is judged that the roadside unit uploads incorrect information, the endorsement qualification of the roadside unit is cancelled;
[0283] Detect the network access qualification of the roadside unit, including:
[0284] R1: The trusted institution detects whether the roadside unit sends incorrect information to the trusted institution through data comparison;
[0285] R2: When step R1 detects that the roadside unit sends incorrect information to the trusted institution, the trusted institution uses the maximum likelihood ratio to detect whether the roadside unit is a malicious roadside unit; when it is judged that the roadside unit is a malicious roadside unit, the network access qualification of the roadside unit is cancelled.
[0286] The detection of the endorsement qualification of the roadside unit includes:
[0287] B1: The trusted institution obtains the malicious behavior verification code recorded in the global trust table in the vehicle trust ledger, and judges whether the roadside unit forges the vehicle malicious behavior record according to the verification function. If the roadside unit forges the vehicle malicious behavior record, the endorsement qualification of the roadside unit is cancelled;
[0288] The trusted node at the core layer detects whether the roadside unit at the edge layer forges the malicious behavior record of the vehicle. Due to the immutability of the blockchain, all uploaded blocks will record which roadside unit conducts the endorsement. Therefore, it can be located which roadside unit endorses and uploads according to the block;
[0289] Obtain the malicious behavior verification code in the global trust table:
[0290] First, obtain the malicious behavior verification code in the global trust table , find the corresponding public key through the kana, and then judge according to the output result of the verification function ;
[0291] If the output result of the verification function is True, it indicates that the roadside unit has not forged malicious vehicle behavior;
[0292] If the output result of the verification function is , it indicates that the roadside unit has forged malicious vehicle behavior. The trusted agency cancels the endorsement qualification of the roadside unit, adds the endorsement certificate of the roadside unit to the revocation list, and updates the status of the roadside unit to the roadside unit trust ledger; the status of the roadside unit includes: cancellation of endorsement qualification, cancellation of network access qualification, and normal;
[0293] B2: The trusted agency calculates the corresponding roadside unit trust value according to the vehicle trust ledger managed by the roadside unit, and judges whether the roadside unit uploads incorrect information to the blockchain according to the roadside unit trust value; Step B2 includes:
[0294] B21: The trusted agency calculates the trust distance between each roadside unit according to the vehicle trust ledger managed by each roadside unit;
[0295] At the current moment roadside unit and roadside unit The trust distance between them is calculated by the formula:
[0296] ,
[0297] In the formula, is the final trust value of vehicle j calculated by roadside unit at the current moment t; is the final trust value of vehicle j calculated by roadside unit at the current moment t;
[0298] B22: According to the trust distance between each roadside unit obtained in step B21, calculate the - adjacent trust distance between each roadside unit;
[0299] At the current moment roadside unit and roadside unit The - adjacent trust distance between them is calculated by the formula:
[0300] = ,
[0301] In the formula, represents the current moment roadside unit Among the R - 1 trust distance values of the roadside unit, the k-th largest is the trust distance between the roadside unit and the roadside unit trust distance , and , where R is the total number of roadside units in the vehicle - to - everything network. In this embodiment, k takes the value of 3, refers to the roadside unit in the descending order of the R - 1 trust distance values of the roadside unit, ranked 3rd;
[0302] B23: Calculate the - adjacent trust density of each roadside unit according to the - adjacent trust distance between each roadside unit obtained in step B22; - adjacent trust density of each roadside unit;
[0303] Current moment roadside unit 's - adjacent trust density is calculated by dividing the total number of roadside units that meet the requirements by the sum of the - adjacent trust distances that meet the requirements; The total number of roadside units that meet the requirements refers to: the roadside unit with the closest trust distance to the roadside unit
[0304] , the roadside unit with the second - closest trust distance to the roadside unit , , the roadside unit with the k - th closest trust distance to the roadside unit , , , ; The sum of the - adjacent trust distances that meet the requirements refers to: the - adjacent trust distance between the roadside unit
[0305] that meets the requirements and the roadside unit and the roadside unit , the - adjacent trust distance between the roadside unit and the roadside unit , the - adjacent trust distance, , the - adjacent trust distance between the roadside unit and the roadside unit ;
[0306] Current moment roadside unit of -proximity trust density The calculation formula is as follows:
[0307] ,
[0308] ,
[0309] ,
[0310] ,
[0311] In the formula, is the current moment roadside unit and roadside unit the -proximity trust distance; represents the current moment roadside unit the largest among the R - 1 trust distance values of roadside unit and roadside unit is the trust distance and ; represents the current moment roadside unit the k - th largest among the R - 1 trust distance values of roadside unit and roadside unit is the trust distance and ; is the current moment roadside unit and roadside unit the -proximity trust distance; represents the current moment roadside unit the second largest among the R - 1 trust distance values of roadside unit is the trust distance and ; represents the current moment roadside unit the k - th largest among the R - 1 trust distance values of roadside unit is the trust distance ; is the current moment roadside unit and roadside unit the -proximity trust distance; represents the current moment roadside unit The k-th largest among the R-1 trust distance values is the trust distance and ; represents the current moment roadside unit The k-th largest among the R-1 trust distance values is the trust distance ; is the roadside unit The total number of; if the roadside units that meet the requirements are unique respectively, that is, the roadside unit There is no duplicate trust distance with the other R-1 roadside units, then ; if there are two roadside units that meet the requirements and the roadside units that meet the requirements are unique respectively, then +1; and so on; is the reciprocal operation.
[0312] If , it means that the final trust value uploaded by the roadside unit is outlier, and the trust value of the roadside unit should be reduced.
[0313] B24: Calculate the corresponding roadside unit trust value according to the -adjacent trust density of each roadside unit obtained in step B23;
[0314] The current moment roadside unit trust value The calculation formula is:
[0315] ,
[0316] In the formula, is the trust value of the roadside unit at the previous moment roadside unit Trust value; in this embodiment, the initial roadside unit trust value is 1.
[0317] B25: According to the trust values of each roadside unit calculated in step B24 and the preset roadside unit trust value threshold , determine whether the roadside unit uploads error information to the blockchain;
[0318] If , then it is determined that the roadside unit uploads error information to the blockchain, and the trusted institution cancels the endorsement qualification of the roadside unit , adds the endorsement certificate of the roadside unit to the revocation list, and updates the roadside unit trust value and roadside unit status to the roadside unit trust ledger;
[0319] If , the trusted authority updates the roadside unit trust value to the roadside unit trust ledger.
[0320] To prevent the roadside unit from tampering with information when it serves as the transmission medium for vehicles to communicate with trusted nodes, it is necessary to detect the information transmission of the roadside unit. Step R1 includes:
[0321] R11: A vehicle establishes a communication connection with the roadside unit. Vehicle j sends a data packet to the trusted node c through the roadside unit . Vehicle j generates an authentication parameter based on bitwise exclusive OR according to the sent data packet . The expression of the authentication parameter is:
[0322] ,
[0323] where is the first data packet sent by vehicle j to the roadside unit ; is the th data packet sent by vehicle j to the roadside unit ; is the binary representation of the total number of data packets sent by vehicle j to the trusted node through the roadside unit ; is a hash function, is the private key of vehicle j;
[0324] R12: Vehicle j uses the public key of the trusted authority c to encrypt the authentication parameter generated in step R11 to generate a feedback packet . When vehicle j enters the coverage area of another roadside unit and establishes communication, it sends the feedback packet to the trusted authority c through it;
[0325] R13: After receiving the data packet sent by the roadside unit and the feedback packet sent by another roadside unit, the trusted authority c recalculates the authentication parameter and uses the private key of the trusted authority c itself to decrypt the feedback packet to obtain the authentication parameter ;
[0326] The calculation formula for recalculating the authentication parameter is:
[0327] ,
[0328] In the formula, is the first data packet received by the trusted institution c through the roadside unit ; is the th data packet received by the trusted institution c through the roadside unit ; is the binary representation of the total number of data packets received by the trusted institution through the roadside unit ;
[0329] R14: The trusted node compares whether the authentication parameter recalculated in step R13 is consistent with the authentication parameter obtained by decryption , and determines whether the error message is caused by the roadside unit; if , then the error message is caused by the roadside unit ;
[0330] Step R2 includes:
[0331] R21: Loop and execute step R1 to collect the communication records between the networked vehicles and the roadside unit from the historical moment to the current moment in the vehicle networking system; the communication records include the number of vehicles communicating with the roadside unit and the number of times the data packets and feedback packets are inconsistent at each moment in step S63; in this embodiment, the historical moment is the moment when the vehicle enters the management range of the roadside unit , and the current moment is the moment when the vehicle leaves the management range of the roadside unit .
[0332] R22: According to the number of times the data packets and feedback packets are inconsistent at each moment collected in step R21, construct binomial distributions under the null hypothesis condition H0 and the alternative hypothesis condition H1 respectively;
[0333] The binomial distributions are constructed as follows:
[0334] Under the null hypothesis condition H0, the roadside unit is not a malicious entity, and the probability that the data packets and feedback packets are inconsistent is , and the number of times the data packets and feedback packets are inconsistent at the moment follows a binomial distribution with parameters : ;
[0335] In the formula, is the historical moment to the current moment , the number of vehicles communicating with the roadside unit ; ;
[0336] Under the alternative hypothesis condition H1, the roadside unit is detected as a malicious entity at time , and the probability that the data in the data packet and the feedback packet is inconsistent is , at time the number of times the data in the data packet and the feedback packet is inconsistent At time after that, it follows a binomial distribution with parameter : ), ;
[0337] R23: According to the binomial distribution constructed in step R22, calculate the joint probabilities under the null hypothesis condition H0 and the alternative hypothesis condition H1 respectively;
[0338] When the roadside unit is not malicious, observe the joint probability of the data inconsistency between the data packet and the feedback packet at each time is :
[0339]
[0340] ;
[0341] When there is malicious behavior in the roadside unit, before time , the roadside unit at time to time has no malicious behavior, and the probability that the data in the data packet and the feedback packet is inconsistent is , so ); at time after that, the probability that the data in the data packet and the feedback packet is inconsistent is , so ).
[0342] When the roadside unit is malicious, observe the joint probability of the data inconsistency between the data packet and the feedback packet at each time is :
[0343]
[0344] ;
[0345] R24: According to the joint probabilities calculated in step R23, calculate the likelihood ratio statistic , the likelihood ratio statistic The calculation formula is:
[0346] ;
[0347] R25: The likelihood ratio statistic calculated in step R24 and the preset likelihood ratio statistic threshold , determine whether the error message is caused by malicious behavior of the roadside unit;
[0348] like > , then determine the roadside unit For malicious, the error message is caused by the malicious behavior of the roadside unit;
[0349] R26: When step R25 determines that the error message is caused by malicious behavior of the roadside unit, the trusted institution cancels the roadside unit The network access qualification will be roadside units The network access certificate is added to the revocation list, and the roadside unit status is updated to the roadside unit trust ledger;
[0350] The likelihood ratio statistics calculated in step R24 include:
[0351] R241: Parameters , , as well as Perform maximum likelihood estimation and get the corresponding estimated value , , as well as ;
[0352] calculate Parameters required To perform maximum likelihood estimation, we need So that the joint probability There is a maximum value, use partial derivatives to find the maximum point:
[0353] ,
[0354] After the formula is derived, the parameters are obtained The maximum likelihood estimate of :
[0355] ;
[0356] calculate Includes: Parameters To perform maximum likelihood estimation, we need So that the joint probability There is a maximum value, use partial derivatives to find the maximum point:
[0357] ,
[0358] The maximum likelihood estimate of the parameter is obtained: :
[0359] ,
[0360] Calculating includes: performing maximum likelihood estimation on the parameter , so it is necessary to find such that the joint probability has a maximum value. Use partial derivatives to find the maximum point:
[0361] ,
[0362] The maximum likelihood estimate of the parameter is obtained: :
[0363] ;
[0364] Calculating includes: performing maximum likelihood estimation on the parameter ; To estimate , it is necessary to maximize :
[0365] ,
[0366] The maximum likelihood estimate of the parameter is obtained: :
[0367] ,
[0368] In the formula, represents when taking the maximum value, the value of the parameter ;
[0369] R242: Traverse all moments from to , calculate , , and according to the L341 method, and take the largest as ; Take the corresponding as the calculated likelihood ratio statistic.
[0370] The method of the present invention realizes the efficiency, security, and privacy protection of message authentication in the vehicle-to-everything (V2X) environment by integrating trust value calculation, the cooperation mechanism between roadside units and vehicles, the blockchain architecture, and privacy protection technologies. This method not only improves the throughput of the edge layer, but also performs trust management on the edge layer by the core layer, and improves the accuracy and real-time performance of trust evaluation through the vehicle-road (vehicles and roadside units) assistance detection mechanism; at the same time, the identity authentication and pseudonym mechanism effectively protects the real identity of vehicles. The method and system of the present invention can be widely applied to various scenarios in the V2X network, including but not limited to vehicle-to-vehicle information sharing, traffic flow optimization, intelligent transportation systems, and autonomous driving vehicles, etc.
[0371] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0372] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0373] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0374] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for realizing the functions in the processFigure 1 one process or multiple processes and / or boxes Figure 1 steps of the functions specified in one box or multiple boxes.
[0375] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. A vehicle networking trust management system, characterized in that Including vehicles, roadside units, trusted institutions, and edge layer blockchain and core layer blockchain based on Hyperledger; The vehicle interacts with the edge layer blockchain through a network access certificate issued by a trusted authority; The roadside unit acts as a blockchain edge layer node, and uploads information to manage the vehicle trust ledger of the edge layer hyperledger and interacts with the core layer trusted institution data through the network access certificate and endorsement certificate issued by the trusted institution; The vehicle trust ledger records the vehicle trust status, and changes to the vehicle trust ledger are endorsed by a single roadside unit; The trusted institution acts as a core layer node of the blockchain and manages the certificate ledger of the core layer hyperledger and the roadside unit trust ledger; The certificate ledger records the certificate status of vehicles and roadside units, and the roadside unit trust ledger records the trust status of roadside units.
2. A vehicle networking trust management method, characterized in that The Internet of Vehicles trust management system according to claim 1 comprises: S1: Initialize the Internet of Vehicles trust management system. The trusted institution issues a network access certificate and endorsement certificate to the roadside unit that has joined the network. S2: Authenticate the identity of the vehicle that joins the network for the first time and apply for a pseudonym and network access certificate from a trusted institution; S3: Perform trust management on the vehicles accessing the network in step S2 and the roadside units accessing the network in step S1 respectively; The trust management of step S3 includes: executing step S3 in a loop, and when it is determined that the vehicle joining the network is a malicious vehicle, cancelling the network access qualification of the malicious vehicle; when it is determined that the roadside unit uploads erroneous information, cancelling the endorsement qualification of the roadside unit; when it is determined that the roadside unit is a malicious roadside unit, cancelling the network access qualification of the roadside unit.
3. The vehicle networking trust management method according to claim 2, characterized in that, In step S3, trust management of the vehicle connected to the network in step S2 includes: C1: Networked vehicles calculate trust values for each other and roadside units calculate global trust values for networked vehicles; C2: Integrate the trust values calculated in step C1 to calculate the final trust value of the vehicle that finally joins the network, and determine whether the vehicle that joins the network is a malicious vehicle based on the preset final trust value threshold; In step C1, the mutual trust values calculated by the vehicles in the network include: Other vehicles calculate the trust value of a single vehicle: CC11: A vehicle that directly interacts with vehicle j calculates a direct trust value for vehicle j based on its direct interaction record with vehicle j, and uploads the calculated direct trust value to the vehicle trust ledger through a roadside unit; CC12: Vehicles that have no direct interaction with vehicle j calculate the indirect trust value of vehicle j based on the direct trust value provided by vehicles that directly interact with vehicle j on the vehicle trust ledger, and upload it to the vehicle trust ledger through the roadside unit.
4. The vehicle networking trust management method according to claim 3, wherein The calculation of direct trust in vehicle j in step CC11 includes: CC111: The vehicles that directly interact with vehicle j calculate the transmission reliability, forgetting factor and cooperation metric of vehicle j based on their direct interaction records with vehicle j; Vehicle i is a vehicle that has directly interacted with vehicle j. At the current moment t, vehicle i calculates the transmission reliability of vehicle j The calculation formula is as follows: , Wherein, is the number of times that vehicle j has successfully forwarded data packets recorded by vehicle i from the initial time to time t; is the total number of times that vehicle i has sent data packets to vehicle j recorded by vehicle i from the initial time to time t; successfully forwarding a data packet means that the data of the data packet forwarded by vehicle j is complete and not tampered with; and the data is sourced from the direct interaction records between vehicle i and vehicle j; At the current moment t, vehicle i calculates the forgetting factor of vehicle j The calculation formula is as follows: , In the formula, is the interaction moment, and the data is sourced from the direct interaction records between vehicle i and vehicle j; is the preset forgetting coefficient; At the current moment t, vehicle i calculates the cooperation metric of vehicle j The calculation formula is as follows: , In the formula, is the number of vehicles that have directly interacted with vehicle j from the initial time to time t; M is the total number of vehicles in the vehicle network; is the maximum value of the number of data packets forwarded by a single vehicle from the initial time to time t; is the number of data packets forwarded by vehicle j from the initial time to time t; , M, and The data is sourced from the vehicle network system; CC112: Calculate the direct trust value of the vehicle interacting with vehicle j to vehicle j based on the transmission reliability, forgetting factor and cooperation metric of vehicle j obtained in step CC111; At the current moment t, vehicle i calculates the direct trust value of vehicle j The calculation formula is as follows: , In the formula, is a preset transmission reliability weight coefficient; CC113: upload the vehicle pseudonym interacted with vehicle j in step CC112 and the corresponding direct trust value calculated for vehicle j to the vehicle calculation trust table of the vehicle trust ledger through the roadside unit; The calculation of the indirect trust value for vehicle j in step CC12 includes: CC121: For vehicles that have no direct interaction with vehicle j, based on the direct trust values of their own vehicles and the vehicles that have direct interaction with vehicle j for the same vehicle, calculate the trust similarity between their own vehicles and the vehicles that have direct interaction with vehicle j; Vehicle l is a vehicle that has no direct interaction with vehicle j. Vehicle h is a vehicle that has had direct interaction with vehicle j. Vehicle x is a vehicle that has had direct interaction with both vehicle l and vehicle h. At the current moment t, the trust similarity between vehicle l and vehicle h is calculated as follows: , In the formula, is the set of vehicles x, is the number of vehicles x, is the direct trust value of vehicle l to vehicle x, is the direct trust value of vehicle h to vehicle x, is the absolute value operation, is the summation operation; CC122: Vehicles that have no direct interaction with vehicle j calculate the trust weight for the vehicles that have direct interaction with vehicle j according to the trust similarity calculated in step CC121; The trust weight of vehicle l in vehicle h at the current moment t is calculated by the following formula: , In the formula, is the direct trust value of vehicle l to vehicle h. If there is no direct interaction between vehicle l and vehicle h, then takes a value of 0.5; CC123: Vehicles that have no direct interaction with vehicle j calculate the indirect trust value for vehicle j according to the trust weight calculated in step CC122; The indirect trust value of vehicle l for vehicle j at the current moment t The calculation formula is as follows: , In the formula, is the set of vehicles h, is the number of vehicles h, is the direct trust value of vehicle h for vehicle j; CC124: The pseudonyms of the vehicles that have no direct interaction with vehicle j in step CC123 and the corresponding calculated indirect trust values for vehicle j are uploaded to the vehicle calculation trust table in the vehicle trust ledger through the roadside unit.
5. The vehicle networking trust management method according to claim 3, wherein, The calculation of the global trust value of the networked vehicles by the roadside unit in step C1 includes: CL11: The roadside unit selects trusted vehicles from vehicles with a malicious behavior of 0; the roadside unit sets the initial malicious behavior of the vehicles accessing the network to be 0, ; CL12: The trusted vehicle sends a detection packet to the target vehicle. After receiving the detection packet, the target vehicle forwards the detection packet to the roadside unit in step CL11 according to a preset program; the preset program includes: forwarding the detection packet to the roadside unit in step CL11 within a preset time period; Current moment Trusted vehicle To the target vehicle Send a detection packet , , where is the detection message; is the hash value of the detection message; is the trusted vehicle using its private key to generate a digital signature by signing the detection message; CL13: After the preset time period, the roadside unit verifies the reception situation of the detection packet; The reception situation includes: whether the detection packet is received within the preset time period and whether the received detection packet data is consistent with the content of the sent data packet; CL14: If the roadside unit does not receive the detection packet within the preset time period or the received detection packet is inconsistent with the content of the sent data packet, record that the malicious behavior of the target vehicle is incremented by 1; CL15: Loop through steps CL11 to CL14 until the preset time; CL16: Calculate the global trust value of the networked vehicles according to the malicious behavior recorded by the roadside unit; Global trust value of vehicle j at the current moment t The calculation formula is as follows: , In the formula, is the number of malicious behaviors of vehicle j from time t-1 to time t; is the global trust weight from time t-1 to time t, = , is the maximum value of the number of malicious behaviors of a single vehicle among the M vehicles accessing the network from time t-1 to time t; CL17: The roadside unit uploads the pseudonym of the target vehicle in step CL16 and the corresponding calculated global trust value to the global trust table in the vehicle trust ledger; The roadside unit will also upload the recorded malicious behavior to the vehicle trust ledger in the form of a malicious behavior verification code; among them, the malicious behavior verification code includes the trusted vehicle pseudonym of the target vehicle to be detected, the digital signature of the trusted vehicle and the hash value of the detection message , and the storage form of the malicious behavior verification code is: < Katakana The roadside unit stores the malicious behavior verification code corresponding to the target vehicle's global trust table.
6. The vehicle networking trust management method according to claim 3, wherein Step C2 includes: C21: Calculate the final trust value of the finally networked vehicles, and upload it to the vehicle final trust table in the vehicle trust ledger through the roadside unit. At the current time t, the final trust value of vehicle j is calculated by the following formula: , Wherein, is M - 1; is other vehicles except vehicle j among the vehicles accessing the network, and ; is a preset final trust value weight coefficient; is the direct trust value of vehicle for vehicle j at the current moment t. C22: According to a preset final trust value threshold Determine whether the vehicle accessing the network is a malicious vehicle, including: If , then it is determined that vehicle j is a malicious vehicle, the current network access qualification of vehicle j is cancelled, and the network access certificate of vehicle j is added to the revocation list; If , then it is determined that vehicle j is a normal vehicle.
7. The vehicle networking trust management method according to claim 5, wherein The trust management of the roadside unit that accesses the network in step S3 in step S1 includes: Detect the endorsement qualification of the roadside unit. According to the vehicle trust ledger and the roadside unit trust ledger, judge whether the roadside unit uploads incorrect information to the blockchain; when it is judged that the roadside unit uploads incorrect information, cancel the endorsement qualification of the roadside unit; Detect the network access qualification of the roadside unit, including: R1: The trusted institution detects whether the roadside unit sends incorrect information to the trusted institution through data comparison; R2: When it is detected in step R1 that the roadside unit sends incorrect information to the trusted institution, the trusted institution uses the maximum likelihood ratio to detect whether the roadside unit is a malicious roadside unit; when it is judged that the roadside unit is a malicious roadside unit, cancel the network access qualification of the roadside unit.
8. The vehicle networking trust management method according to claim 7, wherein, The detection of the endorsement qualification of the roadside unit includes: B1: The trusted institution obtains the malicious behavior verification code recorded in the global trust table of the vehicle trust ledger and judges whether the roadside unit forges the vehicle malicious behavior record according to the verification function. If the roadside unit forges the vehicle malicious behavior record, cancel the endorsement qualification of the roadside unit; Obtain the malicious behavior verification code in the global trust table: , find the corresponding public key through the kana, and then judge according to the output result of the verification function ; If the output result of the verification function is True, it indicates that the roadside unit has not forged malicious vehicle behavior; If the output result of the verification function is , it indicates that the roadside unit forges malicious vehicle behavior. The trusted institution cancels the endorsement qualification of the roadside unit, adds the endorsement certificate of the roadside unit to the revocation list, and updates the status of the roadside unit to the roadside unit trust ledger. The status of the roadside unit includes: cancellation of endorsement qualification, cancellation of network access qualification, and normal; B2: The trusted institution calculates the corresponding roadside unit trust value according to the vehicle trust ledger managed by the roadside unit, and determines whether the roadside unit uploads incorrect information to the blockchain based on the roadside unit trust value; Step B2 includes: B21: The trusted institution calculates the trust distance between each roadside unit according to the vehicle trust ledger managed by each roadside unit; Current moment Roadside unit and the roadside unit Trust distance The calculation formula is as follows: , In the formula, is the final trust value of vehicle j calculated by the roadside unit at the current time t; is the final trust value of vehicle j calculated by the roadside unit at the current time t; is the final trust value of vehicle j calculated by the roadside unit at the current time t; is the final trust value of vehicle j calculated by the roadside unit at the current time t; B22: Calculate the - proximity trust distance between each roadside unit according to the trust distances between each roadside unit obtained in step B21; Current moment Roadside unit and the roadside unit between - Proximity trust distance The calculation formula is as follows: = , Wherein, represents the current moment roadside unit Among the R-1 trust distance values of the roadside unit, the k-th largest is the trust distance between the roadside unit and the roadside unit trust distance , and , where R is the total number of roadside units in the vehicle network; B23: Based on the - proximity trust distances between each roadside unit obtained in step B22, calculate the - proximity trust density of each roadside unit; Current moment Roadside unit of - Proximity trust density The calculation formula is as follows: , , , , wherein, is the current moment roadside unit and the roadside unit the - adjacent trust distance; represents the current moment roadside unit the largest among the R - 1 trust distance values of the roadside unit and the roadside unit the trust distance between and ; represents the current moment roadside unit the k - th largest among the R - 1 trust distance values of the roadside unit and the roadside unit the trust distance between and ; is the current moment roadside unit and the roadside unit the - adjacent trust distance; represents the current moment roadside unit the second - largest among the R - 1 trust distance values of the roadside unit is the trust distance and ; represents the current moment roadside unit the k - th largest among the R - 1 trust distance values of the roadside unit is the trust distance ; is the current moment roadside unit and the roadside unit the - adjacent trust distance; represents the current moment roadside unit the k - th largest among the R - 1 trust distance values of the roadside unit is the trust distance and ; represents the current moment roadside unit the k - th largest among the R - 1 trust distance values of the roadside unit is the trust distance ; is the total number of roadside units ; is the reciprocal operation B24: Calculate the trust value of the corresponding roadside unit according to the - adjacent trust density obtained in step B23; Current moment Roadside unit Trust value The calculation formula is as follows: , In the formula, is the trust value of the roadside unit at the previous moment roadside unit trust value; B25: Each roadside unit trust value calculated according to step B24 and a preset roadside unit trust value threshold , to determine whether the roadside unit uploads error information to the blockchain; If , then it is determined that the roadside unit uploads error information to the blockchain, and the trusted institution cancels the endorsement qualification of the roadside unit , adds the endorsement certificate of the roadside unit to the revocation list, and updates the roadside unit trust value and roadside unit status to the roadside unit trust ledger; If , the trusted institution updates the roadside unit trust value to the roadside unit trust ledger.
9. The vehicle networking trust management method according to claim 8, wherein, Step R1 includes: R11: The vehicle establishes a communication connection with the roadside unit, and vehicle j sends a data packet to the trusted node c through the roadside unit and vehicle j generates an authentication parameter based on bitwise exclusive OR according to the sent data packet , and the expression of the authentication parameter is as follows: , wherein, is the first data packet sent by vehicle j to the roadside unit ; is the th data packet sent by vehicle j to the roadside unit ; is the binary representation of the total number of data packets sent by vehicle j to the trusted node through the roadside unit ; is a hash function, is the private key of vehicle j; R12: The public key of the trusted authority c used by vehicle j The authentication parameters generated in step R11 After encryption, a feedback packet is generated , and when vehicle j enters the coverage area of another roadside unit and establishes communication, the feedback packet Is sent to the trusted authority c through it; R13: Receive the roadside unit The data packet sent And the feedback packet sent by another roadside unit After that, the trusted authority c recalculates the authentication parameters according to the received data packet And uses the private key of the trusted authority c itself To decrypt the feedback packet To obtain the authentication parameters ; Recalculate the authentication parameters The calculation formula is as follows: , In the formula, is the first data packet received by the trusted authority c through the roadside unit ; is the th data packet received by the trusted authority c through the roadside unit ; is the binary representation of the total number of data packets received by the trusted authority through the roadside unit . R14: The trusted node compares the authentication parameters recalculated in step R13 with the authentication parameters obtained by decryption to determine whether they are consistent and to judge whether the error message is caused by the roadside unit; if so, the error message is caused by the roadside unit resulting in it.
10. The vehicle networking trust management method according to claim 9, characterized in that, Step R2 includes: R21: Loop through step R1 to collect historical moments to the current moment , communication records of vehicles accessing the network and roadside units ; The communication records include the number of vehicles communicating with the roadside units and the number of times the data in the data packets and feedback packets at each moment of step R1 are inconsistent; R22: According to the number of times the data packets and feedback packet data are inconsistent at each moment collected in Step R21, construct binomial distributions under the null hypothesis condition H0 and the alternative hypothesis condition H1 respectively; The binomial distribution is constructed as follows: Under the null hypothesis condition H0, the roadside unit is not a malicious entity, and the probability that the data of the data packet and the feedback packet is inconsistent is , at time The number of times the data of the data packet and the feedback packet is inconsistent follows a binomial distribution with parameters : ; In the formula, is the historical moment to the current moment , the number of vehicles communicating with the roadside unit ; ; Under the alternative hypothesis condition H1, at the moment when the roadside unit is detected as a malicious entity, the probability that the data of the data packet and the feedback packet is inconsistent is , at the moment the number of times the data of the data packet and the feedback packet is inconsistent after the moment follows a binomial distribution with parameter : ), ; R23: According to the binomial distributions constructed in Step R22, calculate the joint probabilities under the null hypothesis condition H0 and the alternative hypothesis condition H1 respectively; At the roadside unit When it is not malicious, the situation where the data of the data packet and the feedback packet are inconsistent at each moment is observed Joint probability Is: ; At the roadside unit When it is malicious, the inconsistency between the data packets and the feedback packets is observed at each moment Joint probability is as follows ; R24: Calculate the likelihood ratio statistic based on the joint probability calculated in step R23 , the likelihood ratio statistic is calculated as follows: ; R25: The likelihood ratio statistic calculated according to step R24 and a preset likelihood ratio statistic threshold , to determine whether the error message is caused by the malicious behavior of the roadside unit; If >[[]] ,then it is determined that the roadside unit is malicious, and the error message is caused by the malicious behavior of the roadside unit; R26: When it is determined in step R25 that the error message is caused by the malicious behavior of the roadside unit, the trusted institution cancels the network access qualification of the roadside unit, adds the network access certificate of the roadside unit to the revocation list, and updates the roadside unit status to the roadside unit trust ledger.
Citation Information
Patent Citations
Block chain-based node credibility authentication method in Internet of Vehicles environment
CN114745127A
Vehicle credibility measuring method based on block chain and recommendation trust
CN115941332A
Internet of vehicles message authentication method
CN118368628A
Internet of vehicles trust management method based on block chain
CN118574113A
Cooperative Internet of Vehicles trust management method based on block chain
CN119012158A