A method and system for intelligent collaborative defense against identity spoofing attacks
By using an intelligent collaboration platform and dynamic scheduling of AI models, the bottleneck problem of RSU computing resources was solved, the defense capability against identity forgery attacks was improved, and efficient and reliable cross-domain authentication and low-latency communication were achieved.
Patent Information
- Application Number
- CN202510964434.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2045-07-14
AI Technical Summary
Existing technologies have not fully resolved the computational resource bottleneck problem of RSU in demanding user-intensive scenarios, and the predictive and decision-making role of large AI models has not been fully realized.
By dynamically designating edge computing units and base stations through an intelligent collaboration platform, using AI models to predict resource status in real time, dynamically scheduling computing tasks, and combining a master-slave chain collaboration architecture for identity verification, cross-domain authentication and digital signatures are achieved.
It improves attack response speed, reduces RSU computation pressure, ensures the verifiability and non-repudiation of identity authentication, and meets the low latency requirements of high-density vehicle scenarios.
Smart Images

Figure CN120835296B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of network security, in particular to a method and system for intelligent collaborative defense against identity forgery attacks. BACKGROUND
[0002] The prior art designs a computer mechanism based on preloaded factors and pseudonym generation parameters, which requires users to use the legal parameters generated by the system to construct pseudonyms and keys. This process can effectively identify pseudonyms and keys generated without using legal parameters (i.e., forgery), but also requires the system to have strong computing power and the ability to schedule computing resources in real time.
[0003] Therefore, the prior art significantly optimizes the RSU computing resource burden, dynamically allocates high-computing tasks such as pseudonym generation parameter calculation and pseudonym legality verification, which were originally borne by the RSU, to base stations with stronger computing power, greatly alleviating the resource bottleneck problem of a single RSU in a user-intensive scenario.
[0004] However, these optimization measures still have deficiencies when faced with harsh scenarios. Therefore, it is necessary to further optimize the layout of AI large models to better play their role in prediction and decision-making.
[0005] Therefore, there is an urgent need for a targeted method and system for intelligent collaborative defense against identity forgery attacks. SUMMARY
[0006] The purpose of the present application is to provide a method and system for intelligent collaborative defense against identity forgery attacks, further optimizing the layout of AI large models to better play their role in prediction and decision-making.
[0007] In a first aspect, the application provides a method for intelligent collaborative defense against identity forgery attacks, the method comprising:
[0008] A user registers an identity in a domain, and an authentication center generates a corresponding key pair, encryption parameters, and an identity certificate for the user and uploads them to a blockchain for storage;
[0009] Returning address information from the chain;
[0010] Generating preloaded factors containing private keys in a key generation center (KGC), and batch factors are preloaded onto a roadside unit (RSU) for subsequent calculation of pseudonym generation parameters;
[0011] When a user starts a pseudonym generation request to a nearby RSU, the RSU forwards it to a nearby edge computing unit, which is dynamically designated by an intelligent collaborative platform from multiple distributed edge computing units;
[0012] The RSU forwards the pseudonym generation request to nearby base stations in parallel, and the computing power processing units carried by the base stations intelligently cooperate with the platform through multiple core networks;
[0013] The intelligent cooperation platform predicts the service capabilities of the base stations and the computing capabilities of the distributed edge computing units through AI models, formulates strategies and issues them to the base station group and the edge computing unit group respectively, and real-time schedules remote data transmission and cloud data sharing, and real-time assigns edge computing units to calculate pseudonym generation parameters;
[0014] After the user receives the pseudonym generation parameters, the user generates his own pseudonym, verification parameters and corresponding key pair;
[0015] The user uses the pseudonym and the key pair to calculate a unique signature, and encrypts the message using the signature;
[0016] When the user requests communication, the message package is sent to the receiver, and the address information is carried in the message package;
[0017] The receiver receives the message package and sends it to the nearby RSU, which forwards it to the nearby edge computing unit, which verifies the legality of the user's pseudonym;
[0018] The receiver submits a pseudonym request to the nearby RSU, which carries the address information and queries whether the address information is contained in the chain;
[0019] If the address information is contained in the chain, the identity certificate is returned, otherwise the address information is sent to the main chain to assist in completing the query;
[0020] The chain returns the identity certificate to the receiver;
[0021] The receiver verifies the signature of the user's identity, and if the user does not use the pseudonym generation parameters, the verification fails.
[0022] In a second aspect, the application provides a system for intelligently cooperating to prevent identity forgery attacks, comprising:
[0023] An authentication center for users to register identities in the domain, generate corresponding key pairs, encryption parameters and identity certificates for users, and upload them to the storage of the chain; receive the address information returned by the chain;
[0024] A key generation center KGC for generating preloaded factors containing private keys, and the batch of factors are preloaded onto the roadside unit RSU;
[0025] The roadside unit RSU receives the pseudonym generation request sent by the user, forwards it to the nearby edge computing unit, which is dynamically designated by the intelligent cooperation platform from multiple distributed edge computing units; and forwards the pseudonym generation request to the nearby base station in parallel;
[0026] An edge computing unit for calculating a generation parameter of a pseudonym;
[0027] A base station for carrying a computing power processing unit, connecting an intelligent collaborative platform through multiple core networks;
[0028] An intelligent collaborative platform for predicting the service capacity of a base station and the computing capacity of a distributed edge computing unit through an AI model, formulating a strategy and issuing it to a base station group and an edge computing unit group respectively, scheduling remote data transmission and cloud data sharing in real time, and assigning an edge computing unit to calculate a pseudonym generation parameter in real time;
[0029] A user for sending a pseudonym generation request to a nearby RSU; after receiving a pseudonym generation parameter, generating a pseudonym, a verification parameter and a corresponding key pair of the user; calculating a unique signature using the pseudonym and the key pair, and encrypting a message using the signature; when the user requests communication, sending a message package to a receiver, the message package carrying address information;
[0030] A receiver for receiving a message package, sending it to a nearby RSU, forwarding it to a nearby edge computing unit by the RSU, verifying the legality of a user pseudonym; submitting a pseudonym request to a nearby RSU, the request carrying address information, querying whether a chain contains the address information; verifying the signature of a user identity, and if the user does not use a pseudonym generation parameter, the verification fails;
[0031] A chain for judging whether it contains address information, if yes, returning an identity certificate, otherwise sending the address information to a main chain to assist in completing the query; returning the identity certificate to the receiver.
[0032] In a third aspect, the present application provides an intelligent collaborative system for preventing identity forgery attacks, comprising a processor and a memory:
[0033] The memory is used for storing program code and transmitting the program code to the processor;
[0034] The processor is used for executing the method according to the instructions in the program code.
[0035] In a fourth aspect, the present application provides a computer readable storage medium for storing program code, the program code being used for being executed by a processor to realize the method according to any one of the first aspect.
[0036] Advantages
[0037] The application provides a method and system for intelligent collaborative defense against identity spoofing attacks, including: when a user registers, an authentication center generates a key pair, encryption parameters and an identity certificate and stores them in a master chain; a key generation center (KGC) preloads factors containing private keys to a roadside unit (RSU); when a user initiates a pseudonym generation request, the RSU forwards it to a dynamically designated edge computing unit, and simultaneously sends a parallel request to a base station; an intelligent collaborative platform uses an AI model to predict the computing power of the base station group and the resource status of the edge unit in real time, dynamically schedules remote data transmission and cloud sharing, and assigns the edge unit to calculate the pseudonym generation parameters; the user generates a pseudonym and a key pair based on the parameters, and signs and encrypts a message; when the recipient verifies the message, the edge unit verifies the legality of the pseudonym, and cooperatively queries the identity certificate through the master-slave chain, and finally verifies the validity of the signature.
[0038] The method and system of the application have the following advantages and effects:
[0039] 1. Dynamic edge computing scheduling: the intelligent collaborative platform dynamically assigns computing tasks from distributed edge units, combines the real-time resource prediction (such as computing power load, network bandwidth) of the base station group and the edge unit using an AI model, optimally allocates computing tasks, and avoids overloading a single RSU or edge node. Compared with existing static scheduling strategies, the attack response speed is improved by more than 40%, effectively defending against large-scale concurrent attacks on fake pseudonyms.
[0040] 2. Efficient and reliable cross-domain authentication: the master-slave chain collaborative architecture is used to store and query user identity certificates (stored in the slave chain, cross-domain query assisted by the master chain), combined with digital signature verification, to ensure the verifiability and non-repudiation of identity authentication data in cross-domain communication.
[0041] 3. AI prediction driven global decision: the intelligent collaborative platform uses a time difference attention mechanism to analyze the base station service capability and edge unit load, generates a multi-scale saliency mapping matrix, dynamically adjusts the task distribution strategy (such as migrating tasks in high-load areas to low-load clouds), reduces the RSU computing pressure by more than 70%, and meets the low-latency demand (<100ms) of high-density vehicle scenarios.
[0042] 4. Parallel request processing: the RSU forwards the request to the edge unit and the base station simultaneously, uses the wide-area connection capability of the base station core network to realize remote data sharing, reduces the data transmission delay between the edge unit and the cloud, and improves the parameter generation efficiency. BRIEF DESCRIPTION OF DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, for those skilled in the art, other drawings can also be obtained based on these drawings without creative labor.
[0044] Figure 1 A flowchart of the present application;
[0045] Figure 2 A system architecture diagram of the present application. DETAILED DESCRIPTION
[0046] The preferred embodiments of the present application will be described in detail below with reference to the accompanying drawings, so that the advantages and features of the present application can be more easily understood by those skilled in the art, and the scope of protection of the present application can be more clearly defined.
[0047] The prior art designs a computer mechanism based on preloaded factors and pseudonym generation parameters, which requires users to construct pseudonyms and keys using legal parameters generated by the system. Although this process can effectively identify pseudonyms and keys generated without using legal parameters (i.e., counterfeit), it also requires strong computing power and the ability to schedule computing resources in real time.
[0048] Therefore, the prior art significantly optimizes the RSU computing resource burden, dynamically allocates high-computing tasks such as pseudonym generation parameter calculation and pseudonym legality verification, which were originally borne by the RSU, to base stations with stronger computing power, greatly alleviating the resource bottleneck problem of a single RSU in a user-intensive scenario.
[0049] However, these optimization measures described above still have deficiencies when faced with harsh scenarios. Therefore, it is necessary to further optimize the layout of AI large models to better play their role in prediction and decision-making.
[0050] That is, the AI model is not limited to resource prediction and strategy scheduling, but serves as an intelligent collaborative platform to coordinate the operation of the entire system.
[0051] The method for intelligently and collaboratively defending identity spoofing attacks provided by the present application comprises:
[0052] The user registers an identity in the domain, and the authentication center generates a corresponding key pair, encryption parameters, and an identity certificate for the user and uploads them to the blockchain for storage;
[0053] The address information is returned from the chain;
[0054] A preloaded factor containing a private key is generated in the key generation center KGC, and a batch of factors are preloaded onto the roadside unit RSU for subsequent calculation of pseudonym generation parameters;
[0055] When the user initiates a pseudonym generation request to the nearby RSU, the RSU forwards it to the nearby edge computing unit, which is dynamically specified by the intelligent collaborative platform from multiple distributed edge computing units;
[0056] The RSU forwards the pseudonym generation request to nearby base stations in parallel, and the computing power processing units carried by the base stations intelligently cooperate with the platform through multiple core networks;
[0057] The intelligent cooperation platform predicts the service capabilities of the base stations and the computing capabilities of the distributed edge computing units through AI models, formulates strategies and issues them to the base station group and the edge computing unit group respectively, and real-time schedules remote data transmission and cloud data sharing, and real-time assigns edge computing units to calculate pseudonym generation parameters;
[0058] After the user receives the pseudonym generation parameters, the user generates his own pseudonym, verification parameters and corresponding key pair;
[0059] The user uses the pseudonym and the key pair to calculate a unique signature, and encrypts the message using the signature;
[0060] When the user requests communication, the message package is sent to the recipient, and the address information is carried in the message package;
[0061] The recipient receives the message package and sends it to the nearby RSU, which forwards it to the nearby edge computing unit, which verifies the legality of the user's pseudonym;
[0062] The recipient submits a pseudonym request to the nearby RSU, which carries address information and queries whether the address information is contained in the chain;
[0063] If the address information is contained in the chain, the identity certificate is returned, otherwise the address information is sent to the main chain for assistance to complete the query;
[0064] The chain returns the identity certificate to the recipient;
[0065] The recipient verifies the signature of the user's identity, and if the user does not use the pseudonym generation parameters, the verification fails.
[0066] In the above process, malicious users cannot pass the signature verification because they do not use legal pseudonym generation parameters. The related calculation of the pseudonym generation parameters increases the workload of the RSU, and by using distributed edge computing units, the computing burden of the RSU can be reduced, the cost can be reduced, and according to the AI model of the intelligent cooperation platform, the strategy can be formulated in real time, and the resources can be used more scientifically.
[0067] In some preferred embodiments, the user includes a first user and a second user, and the first user and the second user are registered in different domains, and their respective identity certificates are stored in two independent subchains, namely a first subchain and a second subchain, to obtain two different certificate storage account addresses.
[0068] In some preferred embodiments, the first user establishes a connection with a trusted entity in the domain in which the first user is located, i.e., a first slave chain, the first user queries whether the identity certificate of the corresponding user exists through the account address of the second user, if it exists, it is directly returned to the trusted entity for identity verification, if the identity certificate of the second user does not exist in the first slave chain, the first slave chain submits a request to the corresponding node in the main chain, and the data information of the account address in the second slave chain is queried in the main chain.
[0069] In some preferred embodiments, when the account address is queried from the second slave chain, the main chain sends the data received from the second slave chain to the first slave chain, and the trusted entity of the first slave chain uses the identity certificate in the data to perform relevant authentication, if the authentication is passed, the first user and the second user in different domains are allowed to communicate.
[0070] The user can be a vehicle, and the so-called trusted entity can be a corresponding node of the slave chain, the first user or the second user can be a sender or a receiver.
[0071] Figure 2 The architecture diagram of the intelligent collaborative defense system against identity forgery attacks provided in the present application, the system comprises:
[0072] An authentication center for registering the identity of a user in a domain, generating a corresponding key pair, encryption parameters and an identity certificate for the user, and uploading to a slave chain for storage; receiving address information returned from the slave chain;
[0073] A key generation center KGC for generating preloaded factors containing private keys, and a batch of factors are preloaded onto a roadside unit RSU;
[0074] A roadside unit RSU for receiving a pseudonym generation request sent by a user, forwarding it to a nearby edge computing unit, which is dynamically designated by an intelligent collaborative platform from multiple distributed edge computing units; and forwarding the pseudonym generation request to a nearby base station in parallel;
[0075] An edge computing unit for calculating the generation parameters of a pseudonym;
[0076] A base station for carrying a computing power processing unit and connecting an intelligent collaborative platform through multiple core networks;
[0077] An intelligent collaborative platform for predicting the service capacity of a base station and the computing capacity of a distributed edge computing unit through an AI model, formulating a strategy and issuing it to a base station group and an edge computing unit group respectively, scheduling remote data transmission and cloud data sharing in real time, and assigning an edge computing unit to calculate the generation parameters of a pseudonym in real time;
[0078] User, for sending pseudonym generation request to nearby RSU; after receiving pseudonym generation parameter, generating own pseudonym, verification parameter and corresponding key pair; using pseudonym and key pair to calculate unique signature, and encrypting message by using signature; when user requests communication, sending message package to receiver, wherein the message package carries address information;
[0079] Receiver, for receiving message package, sending it to nearby RSU, forwarding it to nearby edge computing unit by RSU, verifying legality of user pseudonym; submitting pseudonym request to nearby RSU, wherein the request carries address information, inquiring whether from chain contains address information; verifying signature of user identity, if user does not use pseudonym generation parameter, verification fails;
[0080] From chain, for judging whether to contain address information, if yes, returning identity certificate, otherwise sending address information to main chain, and assisting main chain to complete inquiry; returning identity certificate to receiver.
[0081] The application provides a system for intelligent collaborative defense against identity forgery attack, the system comprising: the system comprises a processor and a memory:
[0082] The memory is configured to store program code and transmit the program code to the processor;
[0083] The processor is configured to execute the method according to the instructions in the program code.
[0084] The application provides a computer readable storage medium for storing program code, the program code being used for being executed by a processor to realize the method according to any one of all embodiments of the first aspect.
[0085] In specific implementation, the application further provides a computer storage medium, wherein the computer storage medium can store a program, and the program can include part or all steps in various embodiments of the application when executed. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM) and the like.
[0086] Those skilled in the art can clearly understand that the technical solution in the embodiments of the present application can be realized by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution in the embodiments of the present application can be embodied in a form of a software product, which can be stored in a storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a plurality of instructions to cause a computer device (which can be a personal computer, a server, or a network device, and the like) to execute the methods described in the various embodiments or some parts of the embodiments of the present application.
[0087] The above-described embodiments of the present application do not constitute a limitation on the protection scope of the present application.
Claims
1. A method of intelligently coordinating defense against identity spoofing attacks, characterized by, The method comprises: A user registers an identity in a domain, and a certification center generates a corresponding key pair, encryption parameter and identity certificate for the user and uploads to storage from a chain; Return address information from the chain; A preloaded factor containing a private key is generated in a key generation center KGC, and a batch of factors are preloaded on a roadside unit RSU for subsequent calculation of pseudonym generation parameters; When a user initiates a pseudonym generation request to a nearby RSU, the RSU forwards it to a nearby edge computing unit, which is dynamically specified by an intelligent collaborative platform from multiple distributed edge computing units; The RSU forwards the pseudonym generation request to a nearby base station in parallel, and the processing unit on the base station connects the intelligent collaborative platform through multiple core networks; The intelligent collaborative platform predicts the service capability of the base station and the computing capability of the distributed edge computing unit through an AI model, formulates a strategy and respectively issues it to the base station group and the edge computing unit group, schedules remote data transmission and cloud data sharing in real time, and assigns edge computing units to calculate pseudonym generation parameters in real time; After the user receives the pseudonym generation parameters, the user generates own pseudonym, verification parameter and corresponding key pair; The user calculates a unique signature using the pseudonym and the key pair, and encrypts the message using the signature; When the user requests communication, a message package is sent to the receiver, which carries address information; The receiver receives the message package and sends it to a nearby RSU, which forwards it to a nearby edge computing unit to verify the legality of the user pseudonym; The receiver submits a pseudonym request to a nearby RSU, which carries address information, and queries whether the address information is contained in the chain; If the address information is contained in the chain, the identity certificate is returned, otherwise the address information is sent to the main chain, which assists in completing the query; The chain returns the identity certificate to the receiver; The receiver verifies the signature of the user's identity, and if the user does not use the pseudonym generation parameter, the verification fails.
2. The method of claim 1, wherein: The user includes a first user and a second user, and the first user and the second user are registered in different domains, and their respective identity certificates are stored in two independent chains, namely a first chain and a second chain, to obtain two different certificate storage account addresses.
3. The method of claim 2, wherein: The first user establishes a connection with a trusted entity in the domain where it is located, i.e. a first chain, and queries whether the identity certificate of the corresponding user exists through the account address of the second user, and if it exists, it is directly returned to the trusted entity for identity verification, if the identity certificate of the second user does not exist in the first chain, the first chain submits a request to the corresponding node in the main chain, and queries the data information of the account address in the second chain in the main chain.
4. The method of claim 2, wherein: When the account address is queried from the second chain, the main chain responds to the data received from the second chain to the first chain, and the trusted entity of the first chain uses the identity certificate in the data for related authentication, if the authentication is passed, the first user and the second user in different domains are allowed to communicate.
5. A system for intelligent collaborative defense against identity spoofing attacks, characterized in that, The system comprises: An authentication center is configured to register the identity of a user in a domain, generate a corresponding key pair, encryption parameters and identity certificate for the user, and upload them to a storage from a chain; receive address information returned from the chain; A key generation center KGC is configured to generate preloaded factors containing private keys, and the batch of factors are preloaded onto a roadside unit RSU; The roadside unit RSU is configured to receive a pseudonym generation request sent by a user, forward it to a nearby edge computing unit, which is dynamically designated by an intelligent collaborative platform from multiple distributed edge computing units, and forward the pseudonym generation request to a nearby base station in parallel; The edge computing unit is configured to calculate the generation parameters of the pseudonym; The base station is configured to carry an algorithm processing unit and connect an intelligent collaborative platform through multiple core networks; The intelligent collaborative platform is configured to predict the service capability of the base station and the computing capability of the distributed edge computing unit through an AI model, formulate a strategy and respectively issue it to a base station group and an edge computing unit group, real-time schedule remote data transmission and cloud data sharing, and real-time assign the edge computing unit to calculate the pseudonym generation parameters; The user is configured to send a pseudonym generation request to a nearby RSU, generate own pseudonym, verification parameters and corresponding key pair after receiving the pseudonym generation parameters, calculate a unique signature using the pseudonym and the key pair, and encrypt a message using the signature; when the user requests communication, send a message package to a receiver, the message package carrying address information; The receiver is configured to receive the message package, send it to a nearby RSU, forward it to a nearby edge computing unit by the RSU, verify the legality of the user pseudonym, submit a pseudonym request to a nearby RSU, which carries address information, query whether the address information is contained in a chain, and verify the signature of the user identity, if the user does not use the pseudonym generation parameters, the verification is not passed; The chain is configured to determine whether the address information is contained, if yes, return the identity certificate, otherwise, send the address information to a main chain, and assist the main chain to complete the query; return the identity certificate to the receiver.
6. A system for intelligent collaborative defense against identity spoofing attacks, characterized in that, The system comprises a processor and a memory: The memory is configured to store program code and transmit the program code to the processor; The processor is configured to execute instructions in the program code to implement the method of any one of claims 1-4.
7. A computer-readable storage medium, characterized in that, The computer readable storage medium is configured to store program code, and the program code is configured to be executed by the processor to implement the method of any one of claims 1-4.
Citation Information
Patent Citations
Identity authentication method and system for resisting identity forgery attack
CN120750593A