Intelligent networked automobile information security multi-source dynamic intrusion protection method

By deploying the multi-source dynamic protection model PDPN in the intelligent connected vehicle system, an intrusion detection and adversarial network defense mechanism is built, the intrusion detection problem in the vehicle parking cloud convergence environment is solved, and the security and stability of the system are improved.

CN120456029APending Publication Date: 2025-08-08SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510806271.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-06-13
Filing Date
2025-06-17
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

In the existing intelligent connected vehicle system, there is a lack of effective multi-source intrusion detection and protection mechanism under the cloud convergence environment of the parking lot, and it is impossible to locate and protect intruded data nodes, resulting in security problems.

Method used

Deploy a multi-source dynamic protection model PDPN on vehicle terminals, user mobile terminals and field edge cloud platforms, build an intrusion detection mechanism and an adversarial network defense mechanism, and establish a security framework model on the server side to realize real-time monitoring and protection of each data source node.

Benefits of technology

It improves the safety and stability of the intelligent connected vehicle system, reduces protection costs and time, enhances the robustness and robustness of the system, and has a wide range of applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120456029A_ABST
    Figure CN120456029A_ABST
Patent Text Reader

Abstract

The invention relates to an intelligent network automobile information security multi-source dynamic intrusion protection method, which relates to the field of intelligent network automobile information security, and comprises the following steps: deploying a multi-source dynamic protection model by a vehicle-mounted terminal, a user mobile terminal and a field end edge cloud sub-platform, and constructing an intrusion detection mechanism based on the vehicle-mounted terminal, the user mobile terminal and the field end edge cloud sub-platform, and an intrusion adversarial network defense mechanism is generated. According to the method, the multi-source dynamic protection models are deployed at different terminals, a detection mechanism is established to realize dynamic detection of multi-source intrusion, an adversarial network defense mechanism is generated aiming at abnormal features, detection and defense of multi-source intrusion data can be effectively realized, a security framework model is established at a server, and the security of the multi-source intrusion data is improved. The security of intelligent network automobile information interaction is improved, the potential security risk is reduced, and the security of the parking lot cloud fusion intelligent network connection automobile information system is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent connected vehicles, and in particular to a multi-source dynamic intrusion protection method for information security of intelligent connected vehicles. Technical Background

[0002] With the rapid development and iteration of intelligent driving vehicle technology in recent years, the technology has gradually expanded from single-vehicle intelligence to a collaborative intelligent approach encompassing vehicle-side, field-side, cloud-side, and user terminals. Intelligent connected vehicles based on vehicle-field collaboration utilize various devices on the vehicle, field-side, and cloud-side to collaborate on information processing and data computation. This significantly improves the safety, stability, and reliability of intelligent driving systems at a technical level, while also significantly enhancing perception, decision-making, and computational capabilities, as well as the human-machine interaction experience. This also reduces the cost of vehicle-side equipment and increases the public availability of field-side information. With the increasing interaction of information between vehicles, fields, clouds and user terminals in the field of intelligent connected vehicles, and the deepening of information interaction, there are many nodes and access devices in the vehicle-field-cloud integration, user mobile terminals, field-side edge cloud sub-platforms and cloud service terminals involved in the interaction between vehicles, fields and clouds. The software and hardware systems used are different. For known security risks and unknown security threats, there is no relevant systematic method to effectively detect intrusions, locate the nodes of intrusion data, and effectively protect the links of intrusion transmission. This will cause great security problems in the system, leading to functional abnormalities or unexpected security incidents. This is unacceptable for intelligent network vehicles that are related to the life safety of traffic participants and drivers and passengers. Summary of the Invention

[0003] In order to solve the problems existing in the existing parking lot cloud integrated intelligent connected vehicle data information security system, the present invention provides a multi-source dynamic intrusion protection method for intelligent connected vehicle information security. According to the formulated method, a multi-source dynamic protection model is deployed in each terminal in the system, which can realize real-time monitoring of each data source node, establish intrusion detection mechanism and protection mechanism, and establish a security framework model on the server side to ensure the security of the parking lot cloud-based intelligent driving vehicle information system and the stability and reliability of the intelligent driving vehicle function application.

[0004] The present invention provides a multi-source dynamic intrusion protection method for information security of intelligent connected vehicles. The multi-sources include: an on-board terminal, a user mobile terminal, and a field-side edge cloud sub-platform. The on-board terminal exchanges information with the field-side edge cloud sub-platform via a field-side base station; the user mobile terminal device exchanges information with the field-side edge cloud sub-platform via a field-side base station; and the field-side edge cloud sub-platform is connected to a server-side information security platform.

[0005] The method comprises the following steps:

[0006] S1: Deploy a multi-source dynamic protection model;

[0007] S2: Build an intrusion detection mechanism based on vehicle terminals, user mobile terminals, and field-side edge cloud sub-platforms;

[0008] S3: Generate intrusion-resistant network defense mechanisms;

[0009] S4: Establish a security framework model.

[0010] Furthermore, the step S1 deploys a multi-source dynamic protection model on the vehicle terminal, the user mobile terminal, and the field-side edge cloud sub-platform, including:

[0011] A multi-source dynamic protection model (PDPN) is deployed in the system. The dynamic changes in the positions of markers in the PDPN model can represent different states of the system. The implementation rules of the system's dynamic behavior are defined as follows:

[0012] S, T, and W are the dynamic protection nets in the PDPN model, where S is the position / state, T is the migration, and W is the weight;

[0013] K: S→N+∪{∞} is the state / position accommodation function;

[0014] F: W→N+ is the weight function;

[0015] I o : S→N is the initial state;

[0016] Define the multi-source dynamic protection model PDPN = (S, T, W, K, F, I0, A), where (S, T, W, K, F, I0, A) are in a network system and A is the average filtering rate;

[0017] The T transfer learning in the multi-source dynamic protection model PDPN includes two subsets, namely the time transfer set and the instantaneous transfer set. The delay reference of the time transfer is a random variable with exponential distribution. The time transfer set T t ={t1, t2, ..., t k}, the time delay of transient migration is zero, the transient migration set T i ={t k+1 , t k+2 ,…,t k+n};

[0018] The dynamic protection model based on the vehicle terminal is deployed in the vehicle terminal:

[0019]

[0020] The dynamic protection model based on the user's mobile terminal is deployed in the user's mobile terminal device:

[0021]

[0022] The dynamic protection model based on the field-side edge cloud deployed in the field-side edge cloud sub-platform is:

[0023]

[0024] Apply the multi-source dynamic protection model PDPN to solve the probability that the system is in a stable state, define the executable set of PDPN as G, and divide it into two subsets G D and G H , where G D is the transient migration in the dominant state, G H For the transient migration in the hidden state, the probability matrix of the stable state of the multi-source dynamic protection system is constructed:

[0025]

[0026] in,

[0027] P HH is the recessive state G H the probability of transient migration to the latent state;

[0028] P HD is the recessive state G H the probability of transient migration to the dominant state;

[0029] P DH G is the dominant state D The probability of transition to the latent state;

[0030] P DD G is the dominant state D Internal migration probability.

[0031] In the process of system state migration, the implicit state does not consume time, so the implicit state can be eliminated from the executable set G, and its influence on the system is transferred to the explicit state for consideration. All states are rearranged, with all implicit states in front and explicit states in the back, and their influence is merged into the explicit state, which is composed of direct migration within the explicit state and indirect migration through the implicit state. The effective migration probability matrix of the explicit state can be obtained:

[0032] M=P DD +P DH (1-P HH )P HD

[0033] Where, P DH (1-PHH )P HD is the probability that a dominant state migrates to another dominant state through a recessive path.

[0034] Furthermore, in step S2, an intrusion detection mechanism is constructed in the vehicle terminal, user mobile terminal, and field edge cloud sub-platform based on the multi-source dynamic protection model, including: a data preprocessing module, a sampling module, an autoencoding module, and an intrusion training module.

[0035] The data preprocessing module includes: data acquisition, data cleaning and normalization processing. The data acquisition receives data packets from the vehicle terminal, user mobile terminal, and field edge cloud sub-platform, and obtains data by continuously removing the header and tail of the data packet;

[0036] The data cleaning is used to check the error values, duplicate values, missing values and abnormal values in the acquired data, remove or correct the error values in the checked data, delete the duplicate values, interpolate and fill the missing values, check the abnormal values using statistics and standard deviation strategies and perform corresponding cleaning processing.

[0037] The normalization processing is based on the data scale and dimension between different features of the data after data cleaning, and the original data is divided and aggregated and standardized into a unified data interval and range, the minimum value is mapped to the minimum value of the target range, the maximum value is mapped to the maximum value of the target range, and the relative position relationship of other values within this range is maintained.

[0038] The aggregate calculation is as follows:

[0039] Calculate multi-source data X(x i ,sum i ,q_sum i >, process the sliced data, the specific processing algorithm is:

[0040]

[0041] Among them, p j Indicates the characteristic value of the jth data in the data source X shard, x i Indicates the number of data entries in the data source X shard, sum i Represents the sum of all features of data source X, q_sum i Represents the sum of squares of all eigenvalues of data source X;

[0042] The data source X includes a vehicle-mounted terminal data source V, a user mobile terminal data source U, and a field-side edge cloud sub-platform data source P.

[0043] Then the data processed by the above slicing data is globally aggregated to calculate the global expectation and global variance of the features;

[0044] The global feature expectation is:

[0045] The global feature variance is:

[0046] After obtaining the global feature expectation and global feature variance after the above aggregation, the features are normalized based on the Z-Score, which is expressed as:

[0047]

[0048] Among them, z i represents the features before normalization, Represents the normalized features;

[0049] The sampling module is used to control the amount of training data and reduce the training complexity of the model, thereby improving the intrusion detection efficiency of the model. The sampling module is used to obtain a data set with high representative features in the data with a large number of multi-source data, approximate the optimal feature clustering center, and minimize the sum of the distances between the data points and the feature clustering center, which can be expressed as:

[0050]

[0051] Among them, C is the feature cluster center set, y i The data points of the data sample of the data source X shards;

[0052] The autoencoding module converts the feature clustering structured data samples processed by the sampling module after normalizing the data source X slices into a sequence form;

[0053] The autoencoder module first maps the numerical features of the feature clustering samples to the classification embedding vector through the multi-head self-attention mechanism sublayer, and then normalizes the obtained classification embedding vector and dynamic position encoding. After processing through the feedforward neural network, the global feature weighted cross entropy is obtained, which can be:

[0054]

[0055] Among them, W c is the feature clustering weight, y c is the distance from the data point to the special cluster center, p c is the clustering eigenvalue of the data, and γ is the characteristic clustering parameter (usually set to 2);

[0056] The intrusion training module adopts an unsupervised anomaly detection method to perform intrusion detection on multi-source data based on feature clustering and global feature weights;

[0057] Multi-source intrusion dynamic global feature clustering weight fusion algorithm:

[0058]

[0059] Among them, y i,c is the distance from the data point of the data source X shard to the feature cluster center, p i,c The clustering feature value of the data in the data source X shard.

[0060] Furthermore, in step S3, based on the multi-source dynamic protection model and intrusion detection mechanism, an adversarial network defense mechanism is generated:

[0061]

[0062] in, The dynamic global feature clustering parameter vector at time t after training the data of the data source X shards.

[0063] To prevent attackers from reverse engineering and obtaining the feature weight mechanism, we periodically introduce small random perturbations D to the non-critical features of the data source X. X , defined as:

[0064]

[0065] Where ∈ is the random disturbance amplitude coefficient, and r is the normal distribution random variable coefficient.

[0066] As a preferred implementation scheme of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, the field-side base station serves as a field-side data wireless interaction device, which is used for data interaction between the vehicle-mounted terminal and the field-side edge cloud sub-platform, and for data interaction between the user mobile terminal device and the field-side edge cloud sub-platform.

[0067] In the embodiment of the present application, the field-side edge cloud sub-platform includes a plurality of field-side edge cloud sub-platforms established in different geographical locations;

[0068] In one possible implementation, the field-side edge cloud sub-platform has a built-in information transceiver processing module, in which a field-side edge cloud sub-platform dynamic protection model is deployed. The field-side edge cloud sub-platform dynamic protection model filters all received information of the information transceiver module.

[0069] In a possible implementation, the information transceiver module establishes data interaction with the vehicle-mounted terminal and the user mobile terminal, and requires identity authentication, authorization, and access control before information interaction;

[0070] In a possible implementation, the information transceiver processing module receives the vehicle positioning information and environmental information transmitted by the vehicle-mounted terminal, and sends the information to the field-side information processing module after data analysis;

[0071] In a possible implementation, the information transceiver processing module receives the user location information of the user mobile terminal device, and sends it to the field information processing module after data decryption processing;

[0072] In an embodiment of the present invention, the information transceiver processing module securely processes, receives, and sends field-cloud information interaction data with the server-side information security platform, wherein the field-cloud interaction data includes the interaction between field-side map information and cloud-side map information and POI point information;

[0073] In an embodiment of the present invention, the information transceiver processing module receives and processes the device information data of the field-side positioning device sent by the field-side positioning device manager, obtains the firmware information and real-time working status information of the corresponding field-side positioning device, and sends it to the field-side information processing module.

[0074] As a preferred implementation scheme of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, the field information processing module processes the vehicle status information, vehicle positioning information, environmental information obtained from the on-board terminal, the user positioning information obtained from the user mobile terminal, and the field map information to generate visual scenes and interactive instructions.

[0075] In a possible implementation, the visualization scene is to integrate vehicle status information, vehicle positioning information, environmental information, and user positioning information; the interactive command vehicle is the interactive operation command information for the vehicle-mounted device terminal and the mobile phone / mobile terminal to control the vehicle.

[0076] As a preferred embodiment of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, the server-side information security platform includes a platform service unit, a third-party service unit, and a data storage unit; the server-side information security platform securely processes information transmitted from different field-side edge cloud sub-platforms;

[0077] As a preferred embodiment of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, the server-side information security platform deploys and establishes a security framework model in the platform service unit, synchronizes the multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to the platform service unit, and the platform service unit then synchronizes the synchronized multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to multiple other field-side edge cloud sub-platforms and third-party server units established in different geographical locations. The third-party service unit then synchronizes the synchronized multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to the vehicle-mounted terminal and user mobile terminal that do not detect the intrusion source data;

[0078] As a preferred embodiment of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, wherein: a security framework model is deployed and established in the platform service unit, and a method based on the PDPN model is combined with multi-source and steady-state probability characteristics to cluster the dynamic global characteristics of the multi-source dynamic protection model intrusion sent by different field-side edge cloud sub-platforms and third-party service units and generate adversarial network defense information; the security matrix has a quantifiable and measurable multi-source dynamic protection model to complete a given task based on relatively correct axioms and independent multi-source data, satisfying the following equation:

[0079] and

[0080] Among them, α is the probability limit value (range is (0,0.05]), I j Input vector for data source X, assuming the executable set is E1, E2, ..., E n The vector input set G of the generated intrusion features 1j , G 2j ,…,G nj , there is a vector set g with common invasion characteristics j , j = 1, 2, ..., m, that is, there exists:

[0081]

[0082] Vector input set of intrusion signatures from data source X The number of output vectors in is recorded as and Collection g j The number of output vectors in is recorded as Define τ j For the set g j Elements in, assuming that for any execution body E i ∈E, in response to the data source X input vector I jWhen the data source X intrusion feature vector set From the above, we can conclude that the probability of events with the same data source, at the same time, and with common intrusion characteristics is:

[0083]

[0084] Among them, the types of intrusion feature outputs from the same data source that may be generated by the execution body are unpredictable, and there is heterogeneity between the execution bodies. When the output vector set of the intrusion feature The larger the value, the probability P that all execution bodies generate intrusion feature output vectors and all are consistent. j The smaller it is;

[0085] According to the real detection scenario, the input sequence H of the same data source in the state S at different time t is composed of a finite number of input vectors in the input vector set I, which is recorded as The probability of an event based on the execution bodies at each moment having common intrusion characteristics is:

[0086]

[0087] Based on the event probability algorithm of the above-mentioned intrusion characteristics, the security framework model can be constructed, which has the characteristics of quantification, measurability and screening based on different dimensions of intrusion characteristics, thereby improving the security level of the platform service unit.

[0088] Compared with the prior art, the advantages of the present invention are as follows:

[0089] 1. In the process of building and deploying a multi-source dynamic protection model, model training based on a large amount of data is no longer necessary. Instead, only a small amount of data is needed to verify the intrusion signature generation mechanism algorithm. This significantly reduces the cost and time of model training and optimization based on large amounts of data in existing intelligent connected vehicle information security protection solutions.

[0090] 2. Compared to existing ICV information security solutions that deploy protection models on a single terminal, the multi-source dynamic protection model deploys intrusion detection and defense mechanisms across the vehicle terminal, user mobile terminal, and field-side edge cloud sub-platform. This distributed, decoupled approach makes the ICV security system more robust and robust.

[0091] 3. Compared with the existing intelligent connected vehicle information security protection solution that deploys the protection model on one terminal to realize model training and optimization, the algorithm results of the feature-based intrusion detection mechanism and the adversarial network defense mechanism in the multi-source dynamic protection model are synchronously shared through the server-side information security platform and extended horizontally to multiple field-side edge cloud sub-platforms, user vehicle terminals and user mobile terminals established in different geographical locations, making the multi-source dynamic protection model more generalized and applicable to a wider range of scope. BRIEF DESCRIPTION OF THE DRAWINGS

[0092] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the present invention will be further explained with reference to the accompanying drawings required for describing the embodiments. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0093] Figure 1 This is a schematic diagram of the system structure of an intelligent connected vehicle information security multi-source dynamic intrusion protection method based on an embodiment of the present invention;

[0094] Figure 2 This is a schematic diagram of the composition of a multi-source dynamic protection model in a multi-source dynamic intrusion protection method for information security of an intelligent connected vehicle according to an embodiment of the present invention;

[0095] Figure 3 This is a schematic diagram of the S2 process in a multi-source dynamic intrusion protection method for information security of an intelligent connected vehicle according to an embodiment of the present invention;

[0096] Figure 4 This is a schematic diagram of the S3 process in a multi-source dynamic intrusion protection method for information security of an intelligent connected vehicle according to an embodiment of the present invention;

[0097] Figure 5 This is a system information flow diagram of a multi-source dynamic intrusion protection method for intelligent connected vehicle information security according to an embodiment of the present invention. DETAILED DESCRIPTION

[0098] In order to implement the technical solution of the present invention and to make the above-mentioned objectives, features and advantages more clearly and completely described and understandable, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0099] The present invention addresses the problem that there is no relevant systematic method to effectively detect intrusions in many nodes and access devices in vehicle-mounted equipment, user mobile terminals, field-side edge cloud sub-platforms and cloud service ends involved in the interaction between vehicles, fields and clouds based on vehicle-field cloud fusion and the interaction between vehicles, fields and clouds, and the inability to locate nodes of intrusion data and effectively protect links of intrusion transmission. The present invention provides a multi-source dynamic intrusion protection method for information security of intelligent connected vehicles. According to the formulated method, a multi-source dynamic protection model is deployed in each terminal in the system, which can realize real-time monitoring of each data source node, establish intrusion detection mechanism and protection mechanism, and establish a security framework model on the server side to realize dynamic monitoring of data communication nodes of each terminal, and perform real-time monitoring, intrusion event detection and protection on data sent by different terminals. It is of great significance in the technical research and development of communication and information security between vehicles, fields and clouds in the field of intelligent network vehicles.

[0100] In the following description, many specific implementation details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0101] It should be noted that the terms "one embodiment" or "embodiment" used below refer to specific features, structures, or characteristics that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to an embodiment that is mutually exclusive with other embodiments, either individually or selectively.

[0102] Example 1

[0103] Reference Figure 1 , which is the first embodiment of the present invention, provides a method for multi-source dynamic intrusion protection for information security of intelligent connected vehicles. The method for multi-source dynamic intrusion protection for information security of intelligent connected vehicles includes:

[0104] S1: Deploy a multi-source dynamic protection model.

[0105] Furthermore, a multi-source dynamic protection model PDPN (Polygene Dynamic Protection Net) is deployed on the vehicle terminal, user mobile terminal, and field edge cloud sub-platform. The dynamic changes in the position of the marker in the PDPN model can be represented

[0106] The implementation rules of the system dynamic behavior are defined as follows:

[0107] S, T, and W are the dynamic protection nets in the PDPN model, where S is the position / state, T is the migration, and W is the weight;

[0108] K: S→N+∪{∞} is the state / position accommodation function;

[0109] F: W→N+ is the weight function;

[0110] I o : S→N is the initial state;

[0111] Define the multi-source dynamic protection model PDPN = (S, T, W, K, F, I0, A), where (S, T, W, K, F, I0, A) are in a network system and A is the average filtering rate;

[0112] The T transfer learning in the multi-source dynamic protection model PDPN includes two subsets, namely the time transfer set and the instantaneous transfer set. The delay reference of the time transfer is a random variable with exponential distribution. The time transfer set Tt ={t1, t2, ..., t k}, the time delay of transient migration is zero, the transient migration set T i ={t k+1 , t k+2 ,…,t k+n}.

[0113] It should be noted that the dynamic protection model based on the vehicle terminal is deployed in the vehicle terminal as follows:

[0114]

[0115] The dynamic protection model based on the user's mobile terminal is deployed in the user's mobile terminal device:

[0116]

[0117] The dynamic protection model based on the field-side edge cloud deployed in the field-side edge cloud sub-platform is:

[0118]

[0119] It should also be explained that the multi-source dynamic protection model PDPN solves the probability that the system is in a stable state. The executable set of PDPN is defined as G, which is divided into two subsets G D and G H , where G D is the transient migration in the dominant state, G H For the transient migration in the hidden state, the probability matrix of the stable state of the multi-source dynamic protection system is constructed:

[0120]

[0121] in,

[0122] P HH is the recessive state G H the probability of transient migration to the latent state;

[0123] P HD is the recessive state G H the probability of transient migration to the dominant state;

[0124] P DH G is the dominant state D The probability of transition to the latent state;

[0125] P DD G is the dominant state D Internal migration probability.

[0126] In the process of system state migration, the implicit state does not consume time, so the implicit state can be eliminated from the executable set G, and its influence on the system is transferred to the explicit state for consideration. All states are rearranged, with all implicit states in front and explicit states in the back, and their influence is merged into the explicit state, which is composed of direct migration within the explicit state and indirect migration through the implicit state. The effective migration probability matrix of the explicit state can be obtained:

[0127] M=P DD +P DH (1-P HH )P HD

[0128] Where, P DH (1-P HH )P HD is the probability that a dominant state migrates to another dominant state through a recessive path.

[0129] Figure 2 A multi-source dynamic protection model according to an embodiment of the present invention is illustrated, including an intrusion detection mechanism and a generative adversarial network defense mechanism.

[0130] Figure 3 The figure illustrates the S2 process in a multi-source dynamic intrusion protection method for information security of an intelligent connected vehicle according to an embodiment of the present invention.

[0131] Furthermore, in step S2, an intrusion detection mechanism is constructed in the vehicle terminal, user mobile terminal, and field edge cloud sub-platform based on the multi-source dynamic protection model, including: a data preprocessing module, a sampling module, an autoencoding module, and an intrusion training module.

[0132] The data preprocessing module includes: data acquisition, data cleaning and normalization processing. The data acquisition will receive data packets from the vehicle-mounted terminal, user mobile terminal, and field-side edge cloud sub-platform, and obtain data by continuously removing the header and tail of the data packet; data cleaning is used to check the error values, duplicate values, missing values and abnormal values in the acquired data, remove or correct the error values in the checked data, delete the duplicate values, interpolate and fill the missing values, check the abnormal values using statistics and standard deviation strategies and perform corresponding cleaning processing; the normalization processing is based on the data scale and dimension between different features of the data after data cleaning, and the original data is segmented, aggregated and standardized into a unified data interval and range, the minimum value is mapped to the minimum value of the target range, the maximum value is mapped to the maximum value of the target range, and the relative position relationship of other values within this range is maintained.

[0133] The aggregate calculation is as follows:

[0134] Calculate multi-source data X <x i,sum i ,q_sum i >, process the sliced data, the specific processing algorithm is:

[0135]

[0136] Among them, p j Indicates the characteristic value of the jth data in the data source X shard, x i Indicates the number of data entries in the data source X shard, sum i Represents the sum of all features of data source X, q_sum i Represents the sum of squares of all eigenvalues of data source X;

[0137] The data source X includes a vehicle-mounted terminal data source V, a user mobile terminal data source U, and a field-side edge cloud sub-platform data source P.

[0138] Then the data processed by the above slicing data is globally aggregated to calculate the global expectation and global variance of the features;

[0139] The global feature expectation is:

[0140] The global feature variance is:

[0141] After obtaining the global feature expectation and global feature variance after the above aggregation, the features are normalized based on the Z-Score, which is expressed as:

[0142]

[0143] Among them, z i represents the features before normalization, Represents the normalized features;

[0144] The sampling module is used to control the amount of training data and reduce the training complexity of the model, thereby improving the intrusion detection efficiency of the model. The sampling module is used to obtain a data set with high representative features in the data with a large number of multi-source data, approximate the optimal feature clustering center, and minimize the sum of the distances between the data points and the feature clustering center, which can be expressed as:

[0145]

[0146] Among them, C is the feature cluster center set, y i The data points of the data sample of the data source X shards;

[0147] The autoencoding module converts the feature clustering structured data samples processed by the sampling module after normalizing the data source X slices into a sequence form;

[0148] The autoencoder module first maps the numerical features of the feature clustering samples to the classification embedding vector through the multi-head self-attention mechanism sublayer, and then normalizes the obtained classification embedding vector and dynamic position encoding. After processing through the feedforward neural network, the global feature weighted cross entropy is obtained, which can be:

[0149]

[0150] Among them, W c is the feature clustering weight, y c is the distance from the data point to the special cluster center, p c is the clustering eigenvalue of the data, and γ is the characteristic clustering parameter (usually set to 2);

[0151] The intrusion training module adopts an unsupervised anomaly detection method to perform intrusion detection on multi-source data based on feature clustering and global feature weights;

[0152] Multi-source intrusion dynamic global feature clustering weight fusion algorithm:

[0153]

[0154] Among them, y i,c is the distance from the data point of the data source X shard to the feature cluster center, p i,c The clustering feature value of the data in the data source X shard.

[0155] Figure 4 The present invention illustrates an S3 process in a multi-source dynamic intrusion protection method for information security of an intelligent connected vehicle according to an embodiment of the present invention.

[0156] Furthermore, in step S3, based on the multi-source dynamic protection model and intrusion detection mechanism, an adversarial network defense mechanism is generated:

[0157]

[0158] in, The dynamic global feature clustering parameter vector at time t after training the data of the data source X shards.

[0159] To prevent attackers from reverse engineering and obtaining the feature weight mechanism, we periodically introduce small random perturbations D to the non-critical features of the data source X. X , defined as:

[0160]

[0161] Where ∈ is the random disturbance amplitude coefficient, and r is the normal distribution random variable coefficient.

[0162] Figure 5 The system information flow of a multi-source dynamic intrusion protection method for intelligent connected vehicle information security according to an embodiment of the present invention is shown schematically. Figure 5 The interaction of information data flows between the field-side equipment, the field-side equipment manager, the vehicle-mounted terminal, the user mobile terminal, the field-side base station, the field-side edge cloud sub-platform, and the service-side information security platform implements the security of the field-integrated intelligent vehicle information communication of the present invention. The process includes the following steps:

[0163] The field-side device is used to provide the device information of the field-side device to the vehicle-mounted terminal and the user's mobile terminal;

[0164] It should be noted that the location and number of the field-side positioning devices are determined according to the actual area of the parking lot and the coverage range of the wireless signal.

[0165] The field-side positioning devices in a parking lot at a geographical location are centrally connected to one or more field-side positioning device managers, and the field-side positioning device manager is used to obtain the working status information of all field-side positioning devices in the parking lot at the same geographical location, and send the working status information of the field-side positioning devices to the field-side edge cloud sub-platform;

[0166] In actual applications, the number of field-side positioning device managers deployed in each parking lot is determined according to the upper limit of the field-side positioning devices that can actually be supported.

[0167] The communication data sent and received by the vehicle terminal is wirelessly exchanged with the field-side edge cloud sub-platform through the field-side base station in the parking lot;

[0168] In an embodiment of the present invention, the vehicle-mounted terminal realizes vehicle-cloud data interaction through the vehicle-side mobile communication terminal and the service-side information security platform. The vehicle-cloud data interaction includes receiving vehicle controller upgrade data packets pushed by vehicle manufacturers, and sending vehicle special events and abnormal status data.

[0169] The communication data sent and received by the user's mobile terminal device is wirelessly exchanged with the field-side edge cloud sub-platform through the field-side base station;

[0170] In an embodiment of the present invention, the user mobile terminal device sends user positioning information to the field edge cloud sub-platform; the user positioning information is the location information of the person currently using the user mobile terminal device in the parking area.

[0171] In a specific embodiment, the mobile phone / mobile terminal receives the visualization scene and interactive instructions to provide the person currently using the user's mobile terminal device with vehicle status and environmental information for visualization processing and control operation interaction, and the visualization information is displayed in the human-computer interaction interface of the mobile phone / mobile terminal application.

[0172] The field-side base station involved in the present invention serves as a field-side data wireless communication interaction device, which is used for data interaction between the vehicle terminal and the field-side edge cloud sub-platform, and for data interaction between the user mobile terminal device and the field-side edge cloud sub-platform;

[0173] It should be noted that one or more field-end base stations are set up in a parking lot at a geographical location. In actual application, the location and number of the field-end base stations are determined according to the actual area of the parking lot and the coverage range of the wireless signal.

[0174] In the embodiment of the present application, the field-side edge cloud sub-platform includes multiple field-side edge cloud sub-platforms established at different geographical locations.

[0175] In the flowchart, the field-edge cloud sub-platform has a built-in information transceiver processing module, and a dynamic protection model of the field-edge cloud sub-platform is deployed in the information transceiver processing module. The information transceiver module establishes data interaction with the vehicle terminal and the user's mobile terminal, and identity authentication, authorization, and access control are required before information interaction.

[0176] In a possible implementation, the information transceiver processing module receives the vehicle positioning information and environmental information transmitted from the vehicle-mounted terminal, and sends the information to the field-side information processing module after data analysis;

[0177] In a possible implementation, the information transceiver processing module receives the user location information of the user mobile terminal device, and sends it to the field information processing module after data decryption processing;

[0178] In an embodiment of the present invention, the information transceiver processing module securely processes, receives, and sends field-cloud information interaction data with the server-side information security platform, wherein the field-cloud interaction data includes the interaction between field-side map information and cloud-side map information and POI point information;

[0179] In an embodiment of the present invention, the information transceiver processing module receives and processes the device information data of the field-side positioning device sent by the field-side positioning device manager, obtains the firmware information and real-time working status information of the corresponding field-side positioning device, and sends it to the field-side information processing module.

[0180] As a preferred implementation scheme of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, the field information processing module processes the vehicle status information, vehicle positioning information, environmental information obtained from the on-board terminal, the user positioning information obtained from the user mobile terminal, and the field map information to generate visual scenes and interactive instructions.

[0181] In a possible implementation, the visualization scene is to integrate vehicle status information, vehicle positioning information, environmental information, and user positioning information; the interactive command vehicle is the interactive operation command information for the vehicle-mounted device terminal and the mobile phone / mobile terminal to control the vehicle.

[0182] As a preferred embodiment of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, the server-side information security platform includes a platform service unit, a third-party service unit, and a data storage unit; the server-side information security platform securely processes information transmitted from different field-side edge cloud sub-platforms;

[0183] As a preferred embodiment of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, the server-side information security platform deploys and establishes a security framework model in the platform service unit, synchronizes the multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to the platform service unit, and the platform service unit then synchronizes the synchronized multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to multiple other field-side edge cloud sub-platforms and third-party server units established in different geographical locations. The third-party service unit then synchronizes the synchronized multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to the vehicle-mounted terminal and user mobile terminal that do not detect the intrusion source data;

[0184] As a preferred embodiment of the multi-source dynamic intrusion protection method for information security of intelligent connected vehicles described in the present invention, wherein: a security framework model is deployed and established in the platform service unit, and a method based on the PDPN model is combined with multi-source and steady-state probability characteristics to cluster the dynamic global characteristics of the multi-source dynamic protection model intrusion sent by different field-side edge cloud sub-platforms and third-party service units and generate adversarial network defense information; the security matrix has a quantifiable and measurable multi-source dynamic protection model to complete a given task based on relatively correct axioms and independent multi-source data, satisfying the following equation:

[0185] and

[0186] Among them, α is the probability limit value (range is (0,0.05]), I j Input vector for data source X, assuming the executable set is E1, E2, ..., E n The vector input set G of the generated intrusion features 1j , G 2j ,…,G nj , there is a vector set g with common invasion characteristics j , j = 1, 2, ..., m, that is, there exists:

[0187]

[0188] Vector input set of intrusion signatures from data source X The number of output vectors in is recorded as and Collection g j The number of output vectors in is recorded as Define τ j For the set g j Elements in, assuming that for any execution body E i ∈E, in response to the data source X input vector I j When the data source X intrusion feature vector set From the above, we can conclude that the probability of events with the same data source, at the same time, and with common intrusion characteristics is:

[0189]

[0190] Among them, the types of intrusion feature outputs from the same data source that may be generated by the execution body are unpredictable, and there is heterogeneity between the execution bodies. When the output vector set of the intrusion feature The larger the value, the probability P that all execution bodies generate intrusion feature output vectors and all are consistent. j The smaller it is;

[0191] According to the real detection scenario, the input sequence H of the same data source in the state S at different time t is composed of a finite number of input vectors in the input vector set I, which is recorded as The probability of an event based on the execution bodies at each moment having common intrusion characteristics is:

[0192]

[0193] Based on the event probability algorithm of the above-mentioned intrusion characteristics, the security framework model can be constructed, which has the characteristics of quantification, measurability and screening based on different dimensions of intrusion characteristics, thereby improving the security level of the platform service unit.

[0194] It should be noted that the above embodiments are not intended to limit the scope of protection of the present invention, and equivalent changes or substitutions made on the basis of the above technical solutions fall within the scope of protection of the claims of the present invention.

Claims

1. A multi-source dynamic intrusion protection method for intelligent connected vehicle information security, characterized in that: The multiple sources include: vehicle terminals, user mobile terminals, and a field-side edge cloud sub-platform. The vehicle terminals exchange information with the field-side edge cloud sub-platform via a field-side base station; the user mobile terminals exchange information with the field-side edge cloud sub-platform via a field-side base station; and the field-side edge cloud sub-platform is connected to a service-side information security platform. The method comprises the following steps: S1: Deploy a multi-source dynamic protection model; S2: Build an intrusion detection mechanism based on vehicle terminals, user mobile terminals, and field-side edge cloud sub-platforms; S3: Generate intrusion-resistant network defense mechanisms; S4: Establish a security framework model.

2. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 1, characterized in that: In S1, a multi-source dynamic protection model is deployed on the vehicle terminal, user mobile terminal, and field-side edge cloud sub-platform, including: A multi-source dynamic protection model (PDPN) is deployed in the system. The dynamic changes in the positions of markers in the PDPN model represent different states of the system. The implementation rules of the system's dynamic behavior are defined as follows: S, T, and W are the dynamic protection nets in the PDPN model, where S is the position / state, T is the migration, and W is the weight; K: S→N+∪{∞} is the state / position accommodation function; F: W→N+ is the weight function; I o : S→N is the initial state; Define the multi-source dynamic protection model PDPN = (S, T, W, K, F, I0, A), where (S, T, W, K, F, I0, A) are in a network system and A is the average filtering rate; The T transfer learning in the multi-source dynamic protection model PDPN includes two subsets, namely the time transfer set and the instantaneous transfer set. The delay reference of the time transfer is a random variable with exponential distribution. The time transfer set T t ={t1, t2, ..., t k }, the time delay of transient migration is zero, the transient migration set T i ={t k+1 , t k+2 ,…,t k+n }; The dynamic protection model based on the vehicle terminal is deployed in the vehicle terminal: The dynamic protection model based on the user's mobile terminal is deployed in the user's mobile terminal device: The dynamic protection model based on the field-side edge cloud deployed in the field-side edge cloud sub-platform is: Apply the multi-source dynamic protection model PDPN to solve the probability that the system is in a stable state, define the executable set of PDPN as G, and divide it into two subsets G D and G H , where G D is the transient migration in the dominant state, G H For the transient migration in the hidden state, the probability matrix of the stable state of the multi-source dynamic protection system is constructed: in, P HH is the recessive state G H the probability of transient migration to the latent state; P HD is the recessive state G H the probability of transient migration to the dominant state; P DH G is the dominant state D The probability of transition to the latent state; P DD G is the dominant state D Internal migration probability, In the process of system state migration, the implicit state does not consume time, so the implicit state is eliminated from the executable set G, and its influence on the system is migrated to the explicit state for consideration. All states are rearranged, with all implicit states in front and explicit states in the back, and their influence is merged into the explicit state. It consists of direct migration within the explicit state and indirect migration through the implicit state. The effective migration probability matrix of the explicit state can be obtained: M=P DD +P DH (1-P HH )P HD Where, P DH (1-P HH )P HD is the probability that a dominant state migrates to another dominant state through a recessive path.

3. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 1, characterized in that: In S2, an intrusion detection mechanism is built on the vehicle terminal, user mobile terminal, and field edge cloud sub-platform based on the multi-source dynamic protection model, including: data preprocessing module, sampling module, self-encoding module, and intrusion training module. The data preprocessing module includes: data acquisition, data cleaning and normalization processing. The data acquisition receives data packets from the vehicle terminal, user mobile terminal, and field edge cloud sub-platform, and obtains data by continuously removing the header and tail of the data packet; The data cleaning is used to check the error values, duplicate values, missing values and abnormal values in the acquired data, remove or correct the error values in the checked data, delete the duplicate values, interpolate and fill the missing values, check the abnormal values using statistics and standard deviation strategies and perform corresponding cleaning processing; The normalization process is based on the data scale and dimension between different features of the data after data cleaning, and the original data is divided and aggregated into a unified data interval and range. The minimum value is mapped to the minimum value of the target range, and the maximum value is mapped to the maximum value of the target range, and the relative position relationship of other values within this range is maintained. The aggregate calculation is as follows: Calculate multi-source data X <x i ,sum i ,q_sum i >, process the sliced data, the specific processing algorithm is: Among them, p j Indicates the characteristic value of the jth data in the data source X shard, x i Indicates the number of data entries in the data source X shard, sum i Represents the sum of all features of data source X, q_sum i Represents the sum of squares of all eigenvalues of data source X; The data source X includes the vehicle terminal data source V, the user mobile terminal data source U and the field edge cloud sub-platform data source PL; Then the data processed by the above slicing data is globally aggregated to calculate the global expectation and global variance of the features; The global feature expectation is: The global feature variance is: After obtaining the global feature expectation and global feature variance after the above aggregation, the features are normalized based on the Z-Score, which is expressed as: Among them, z i represents the features before normalization, Represents the normalized features; The sampling module is used to control the amount of training data and reduce the training complexity of the model, thereby improving the intrusion detection efficiency of the model. The sampling module is used to obtain a data set with high representative features in the data with a large number of multi-source data, approximate the optimal feature clustering center, and minimize the sum of the distances between the data points and the feature clustering center, which can be expressed as: Among them, C is the feature cluster center set, y i The data points of the data sample of the data source X shards; The autoencoding module converts the feature clustering structured data samples processed by the sampling module after normalizing the data source X slices into a sequence form; The autoencoder module first maps the numerical features of the feature clustering samples to the classification embedding vector through the multi-head self-attention mechanism sublayer, and then normalizes the obtained classification embedding vector and dynamic position encoding. After processing through the feedforward neural network, the global feature weighted cross entropy is obtained, which can be: Among them, W c is the feature clustering weight, y c is the distance from the data point to the special cluster center, p c is the clustering eigenvalue of the data, and γ is the characteristic clustering parameter (set to 2); The intrusion training module adopts an unsupervised anomaly detection method to perform intrusion detection on multi-source data based on feature clustering and global feature weights; Multi-source intrusion dynamic global feature clustering weight fusion algorithm: Among them, y i,c is the distance from the data point of the data source X shard to the feature cluster center, p i,c The clustering feature value of the data in the data source X shard.

4. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 1, characterized in that: In S3, based on the multi-source dynamic protection model and intrusion detection mechanism, an adversarial network defense mechanism is generated: in, The dynamic global feature clustering parameter vector at time t after data training of the data of data source X shards. To prevent attackers from reverse engineering and obtaining the feature weight mechanism, small random perturbations D are regularly introduced to the non-critical features of data source X. X , defined as: Where ε is the random disturbance amplitude coefficient, and r is the normal distribution random variable coefficient.

5. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 1, characterized in that: The field-side base station serves as a field-side data wireless interaction device, used for data interaction between the vehicle terminal and the field-side edge cloud sub-platform, and for data interaction between the user mobile terminal device and the field-side edge cloud sub-platform.

6. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 1, characterized in that: The field-side edge cloud sub-platform includes multiple field-side edge cloud sub-platforms established in different geographical locations; The field-side edge cloud sub-platform has a built-in information transceiver processing module, in which a field-side edge cloud sub-platform dynamic protection model is deployed. The field-side edge cloud sub-platform dynamic protection model filters all received information of the information transceiver module; The information transceiver module establishes data interaction with the vehicle-mounted terminal and the user mobile terminal, and needs to perform identity authentication, authorization and access control before information interaction; The information transceiver processing module receives the vehicle positioning information and environmental information transmitted by the vehicle terminal, and sends the data to the field information processing module after data analysis; The information transceiver processing module receives the user location information of the user terminal device and sends it to the field information processing module after data decryption processing; The information transceiver processing module securely processes the reception and transmission of field-cloud information interaction data with the server-side information security platform, wherein the field-cloud interaction data includes the interaction between field-side map information and cloud-side map information and POI point information; The information transceiver processing module receives and processes the device information data of the field-side positioning device sent by the field-side positioning device manager, obtains the firmware information and real-time working status information of the corresponding field-side positioning device, and sends them to the field-side information processing module.

7. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 6, characterized in that: The terminal information processing module processes the vehicle status information, vehicle positioning information, and environmental information obtained from the vehicle-mounted terminal, the user positioning information obtained from the user mobile terminal, and the terminal map information to generate a visualization scene and interactive instructions; The visualization scene is to combine vehicle status information, vehicle positioning information, environmental information, and user positioning information; the interactive command vehicle is the interactive operation command information for the vehicle terminal and the user terminal to control the vehicle.

8. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 1, characterized in that: The server-side information security platform includes a platform service unit, a third-party service unit, and a data storage unit; The server-side information security platform securely processes information transmitted from different field-side edge cloud sub-platforms.

9. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 8, characterized in that: The server-side information security platform deploys a steady-state security model in the platform service unit, and synchronizes the multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to the platform service unit. The platform service unit then synchronizes the synchronized multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to multiple other field-side edge cloud sub-platforms and third-party server units established in different geographical locations. The third-party service unit then synchronizes the synchronized multi-source intrusion dynamic global feature clustering and generative adversarial network defense information of the intrusion detection mechanism to the vehicle-mounted terminal and user mobile terminal that do not detect the intrusion source data.

10. The method for multi-source dynamic intrusion protection of intelligent connected vehicle information security according to claim 9, characterized in that: The platform service unit deploys and establishes a security framework model, which combines the PDPN model with multi-source and steady-state probability features to cluster the dynamic global features of the multi-source dynamic protection model intrusion and generate adversarial network defense information sent by different field-side edge cloud sub-platforms and third-party service units; The security matrix has quantifiable, measurable, and filterable dynamic global intrusion signatures, and can define different security protection levels, including: Complete the given task based on relatively correct axioms and independent multi-source data, satisfying the following equation: and Among them, α is the probability limit value (range is (0,0.05]), I j Input vector for data source X, assuming the executable set is E1, E2, ..., E n The vector input set G of the generated intrusion features 1j , G 2j ,…,G nj , there is a vector set g with common invasion characteristics j , j = 1, 2, ..., m, that is, there exists: Vector input set of intrusion signatures from data source X The number of output vectors in is recorded as and Collection g j The number of output vectors in is recorded as Define τ j For the set g j Elements in, assuming that for any execution body E i ∈E, in response to the data source X input vector I j When the data source X intrusion feature vector set From the above, we can conclude that the probability of events with the same data source, at the same time, and with common intrusion characteristics is: Among them, the types of intrusion feature outputs from the same data source that may be generated by the execution body are unpredictable, and there is heterogeneity between the execution bodies. When the output vector set of the intrusion feature The larger the value, the probability P that all execution bodies generate intrusion feature output vectors and all are consistent. j The smaller it is; According to the real detection scenario, the input sequence H of the same data source in the state S at different time t is composed of a finite number of input vectors in the input vector set I, which is recorded as The probability of an event based on the execution bodies at each moment having common intrusion characteristics is: Based on the event probability algorithm of the above-mentioned intrusion characteristics, the security framework model is constructed, which has the characteristics of quantification, measurability and screening based on different dimensions of intrusion characteristics, thereby improving the security level of the platform service unit.