LoRa Communication-Based Security Monitoring System for Tanker Truck Mother Locks

By collecting multimodal radio frequency signals on the tanker truck in real time and comparing them with a pre-stored database, combined with a dynamic challenge mechanism and hierarchical authorization, the problem of the tanker truck monitoring system being susceptible to GPS spoofing is solved, achieving higher security and reliability.

CN120857116BActive Publication Date: 2025-12-02FUZHOU ZHENGCHENG SECURITY SEALS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511326335.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-17
Publication Date
2025-12-02
Estimated Expiration
2045-09-17

AI Technical Summary

Technical Problem

Existing oil tanker monitoring systems are vulnerable to GPS spoofing attacks and cannot effectively defend against illegal oil unloading caused by spoofed GPS signals.

Method used

A safety monitoring system for tanker truck locks based on LoRa communication is adopted. The system collects multimodal environmental radio frequency signals in real time through the vehicle terminal and compares and verifies them with the pre-stored radio frequency signal database of the monitoring center server to ensure the authenticity of the vehicle location. A dynamic challenge-response mechanism and hierarchical authorization mode are introduced to enhance the system security.

Benefits of technology

It effectively resists GPS spoofing attacks, ensures the safety and legality of oil tanker unloading operations, improves the robustness and reliability of the system, and prevents illegal oil unloading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120857116B_ABST
    Figure CN120857116B_ABST
Patent Text Reader

Abstract

This application relates to the field of oil tanker safety monitoring technology, and in particular to a LoRa-based oil tanker lock security monitoring system, including a monitoring center server, a vehicle-mounted terminal, and a lock device. The surrounding radio environment of each physical location is complex and difficult to replicate. When an attacker performs GPS spoofing, although the GPS coordinates reported by the vehicle are forged, the set of radio frequency signals collected in real time by the vehicle-mounted terminal is a true reflection of its illegal location. This set of radio frequency signals will differ significantly from the pre-stored set of radio frequency signals for legitimate locations in the monitoring center database. By comparing the two, the system can immediately identify the spoofing behavior due to location mismatch and reject the unlocking request. This on-site inspection mechanism based on the physical environment fundamentally solves the vulnerability problem of existing technologies that rely solely on digital coordinates.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of oil tanker safety monitoring technology, and in particular to an oil tanker master lock safety monitoring system based on LoRa communication. Background Technology

[0002] Tanker trucks are crucial transportation vehicles for carrying high-value or hazardous liquid goods such as gasoline, diesel, and chemical raw materials, making safety supervision during transport paramount. Therefore, rigorous and reliable monitoring of the opening and closing operations of tanker truck valves is a core requirement within the industry.

[0003] Traditional management methods rely primarily on mechanical locks combined with manual signing and the driver's professional ethics. This approach is weak in supervision and prone to problems such as theft by those in charge and collusion between insiders and outsiders. With the development of IoT technology, electronic locks integrating GPS (Global Positioning System) and mobile communication modules such as GPRS / 3G / 4G have emerged, enabling remote monitoring of tanker truck locations and remote authorization of locks.

[0004] While existing technologies have made significant progress in security, enabling dual or multiple authentication based on location and identity, they rely entirely on coordinates reported by GPS systems to determine vehicle location, thus failing to effectively defend against GPS spoofing attacks.

[0005] GPS spoofing is an attack method that misleads GPS receivers by transmitting fake GPS signals. Attackers can deploy a low-power GPS signal transmitter near an illegal oil unloading point. The transmitter broadcasts signals that can simulate the GPS coordinates of a vehicle located at a pre-authorized, legitimate oil unloading point. At this time, the GPS module installed on the tanker truck will receive this stronger fake signal and mistakenly report this fake coordinates to the monitoring center. Since the received GPS coordinates match the preset legitimate coordinates perfectly, existing technology will misjudge that the vehicle has arrived at the designated location and thus approve the unlocking request. Attackers can then easily carry out illegal activities such as stealing oil at unauthorized locations by taking advantage of the system's legitimate authorization. Summary of the Invention

[0006] The purpose of this application is to provide a security monitoring system for a tanker truck's interlock lock based on LoRa communication, comprising: a monitoring center server configured to build and maintain a pre-stored radio frequency signal set database, wherein the pre-stored radio frequency signal set database stores one or more preset authorized geographical locations and their corresponding multimodal environmental radio frequency signal sets, wherein the multimodal environmental radio frequency signal set is a unique set of radio signal features characterizing a specific spatial physical environment; and a vehicle-mounted terminal installed on the tanker truck and electrically connected to the interlock lock device, wherein the vehicle-mounted terminal includes a positioning module for acquiring the vehicle's real-time geographical coordinates, a multimodal radio frequency signal acquisition module for synchronously acquiring various types of radio signals in the surrounding environment, and a communication module for remote data interaction with the monitoring center server; wherein the vehicle-mounted terminal is configured to respond to the driver's unlocking operation, trigger the positioning module to acquire the current geographical location, and initiate an unlocking authorization request containing the current geographical location to the monitoring center server via the communication module; the monitoring center server... The device is further configured to, upon receiving the unlocking authorization request, generate a dynamic challenge command with timeliness and uniqueness, and send it to the vehicle terminal to initiate the environment authenticity verification process; the vehicle terminal is further configured to receive and parse the dynamic challenge command, drive the multimodal radio frequency signal acquisition module to capture the radio signals of the current environment in real time, generate a current radio frequency signal set, and send the current radio frequency signal set back to the monitoring center server as a response to the dynamic challenge command; the monitoring center server is finally configured to perform a similarity comparison verification between the received current radio frequency signal set and the multimodal environment radio frequency signal set retrieved from the pre-stored radio frequency signal set database according to the current geographical location. If the matching degree of the two meets a preset security threshold, the vehicle is determined to be in actual position, and an unlocking authorization command is generated. The unlocking authorization command is securely sent to the vehicle terminal through the LoRa communication unit in the communication module to authorize it to open the master lock in the master lock device.

[0007] Understandably, the surrounding radio environment (such as the distribution of Wi-Fi, cellular base station signals, etc.) of each physical location is complex and difficult to replicate. When an attacker performs GPS spoofing, although the GPS coordinates reported by the vehicle are fake, the set of radio frequency signals collected in real time by the vehicle terminal is a true reflection of its illegal location. This set of radio frequency signals will be significantly different from the pre-stored set of radio frequency signals for legitimate locations stored in the monitoring center's database. By comparing the two, the system can immediately identify the spoofing behavior of location mismatch and refuse the unlocking request. This on-site inspection mechanism based on the physical environment fundamentally solves the vulnerability problem of existing technologies that rely solely on digital coordinates.

[0008] Optionally, the multimodal environment radio frequency signal set is composed of physical layer or network layer characteristic parameters of radio signals originating from at least two different communication protocols, and the type of radio signal is selected from a group consisting of Wi-Fi signals, cellular network signals, Bluetooth signals, and LoRa network signals.

[0009] By adopting the above technical solution, compared with a single signal source, such as Wi-Fi alone, the integration of features from multiple signal sources such as Wi-Fi, cellular networks, Bluetooth, and LoRa greatly increases the dimensionality and information entropy of the radio frequency signal set, significantly improving the uniqueness and recognizability of the radio frequency signal set, making it more difficult to be imitated accidentally or maliciously. At the same time, the multimodal characteristics also enhance the stability of the radio frequency signal set. Even if a certain signal source changes, such as a Wi-Fi hotspot being turned off, the features of other signal sources can still provide sufficient information for location matching, ensuring the robustness of the verification.

[0010] Optionally, the process of constructing the pre-stored radio frequency signal set database includes: performing multiple radio frequency environment scans at a preset authorized geographical location through a data acquisition device or vehicle terminal, then filtering, denoising, and extracting features from the acquired data to form a reference radio frequency signal set template that characterizes the unique radio frequency environment of the location, and storing it in conjunction with geographical coordinates.

[0011] By adopting the above technical solution, and by performing multiple scans at authorized locations over multiple time periods, and by filtering, denoising, and extracting features from the data, the influence of instantaneous fluctuations and environmental noise can be effectively eliminated, forming a statistically stable set of reference radio frequency signals that can represent the typical radio frequency environment of that location. This process ensures that the basic data for subsequent comparison and verification is of high quality and high reliability, which is a prerequisite for the effective operation of the entire verification mechanism.

[0012] Optionally, the dynamic challenge instruction includes a random number or timestamp as a one-time token. The vehicle terminal needs to incorporate the token into the current radio frequency signal set and send it back. The server verifies the token to ensure the real-time nature of the response information in order to resist replay attacks.

[0013] By adopting the above technical solution, a "dynamic challenge-response" mechanism is introduced, and a one-time random number or timestamp is embedded in the challenge command. An attacker may pre-record a set of radio frequency signal data at a legitimate location, and then, while performing GPS spoofing at an illegitimate location, replay the recorded set of radio frequency signal data to the server. The dynamic challenge mechanism of this application requires the vehicle terminal to include the one-time token issued by the server in the response. The server will verify the validity of the token before verifying the set of radio frequency signals. Since the token is generated in real time and is one-time use, any pre-recorded response that does not contain the currently valid token will be rejected by the server, thereby effectively blocking the vulnerability of replay attacks and ensuring that all verifications are based on real-time collected data.

[0014] Optionally, the comparison and verification process employs machine learning or pattern recognition algorithms. The pattern recognition algorithm calculates the similarity between the current set of radio frequency signals and the pre-stored set of radio frequency signals based on their feature vectors, and compares it with a preset security threshold to make a decision.

[0015] By adopting the above technical solutions, compared with simple numerical matching, advanced algorithms such as support vector machines, K-nearest neighbors, and deep neural networks can better handle the inherent fluctuations and complexities of radio frequency signals. Through learning from a large number of samples, the model can capture the deep nonlinear characteristics of the location radio frequency environment, so that even under certain environmental changes, it can still make high-precision matching decisions, effectively reducing the probability of rejecting legal unlocking and approving illegal unlocking due to minor environmental changes.

[0016] Optionally, the communication module of the vehicle terminal is configured in a dual-channel mode, with the cellular communication unit serving as the main channel for regular data interaction and the LoRa communication unit serving as a dedicated redundant channel for receiving unlocking authorization commands, so as to ensure that core commands can still be reliably delivered when the cellular network is interfered with.

[0017] By adopting the above technical solution, the advantages of different communication technologies are cleverly utilized. Cellular networks (4G / 5G) have high bandwidth and are suitable for transmitting large amounts of radio frequency signal collection information, while LoRa remote radio technology, with its low power consumption, strong penetration, good anti-interference ability, and low networking cost, is very suitable as a dedicated channel for issuing critical control commands (such as unlocking authorization). In areas with poor cellular signal coverage or when encountering cellular network interference, the LoRa channel can ensure that unlocking commands can still be reliably delivered to the vehicle terminal, greatly improving the availability and robustness of the system.

[0018] Optionally, the control logic of the master lock device is a hierarchical authorization mode, where the opening permission of the master lock is remotely controlled by the monitoring center server; the opening permission of the child lock is managed locally by the vehicle terminal, and the prerequisite for its unlocking operation is that the master lock has been successfully opened.

[0019] By adopting the above technical solution, the main lock is remotely controlled by the monitoring center with the highest authority, ensuring that operation can only be initiated after passing the most stringent location authenticity verification; the sub-lock's authority is delegated to the vehicle terminal for local management, but its unlocking must be based on the main lock being opened. This design not only ensures the highest level of security control, but also provides a certain degree of flexibility for on-site operation, achieving an organic combination of centralized authorization and distributed execution, balancing security and efficiency.

[0020] Optionally, after the preconditions for unlocking the sublock are met, the vehicle terminal must also verify the local identity authentication credentials of the on-site operator through the human-machine interface before it can open the sublock; the identity authentication credentials include at least one of a password, an RFID card, or biometric information.

[0021] By adopting the above technical solution, even if the vehicle location verification is successful and the main lock is opened, a secondary confirmation must be made on-site by an authorized operator with valid credentials before the specific sub-lock can be opened for oil unloading. This not only prevents misoperation or malicious operation by unauthorized personnel, but also ensures that all operation records are linked to specific personnel, providing a clear and reliable basis for post-event auditing and accountability.

[0022] Optionally, the communication link between the vehicle terminal and the monitoring center server is protected by a transport layer security protocol; in addition, the response information containing the current radio frequency signal set is encrypted by the vehicle terminal at the application layer before being sent, so as to achieve end-to-end security.

[0023] By adopting the above technical solutions, the TLS protocol protects the data transmission channel between the vehicle terminal and the server, preventing eavesdropping and man-in-the-middle attacks; while application-layer encryption of core sensitive information achieves end-to-end protection; even if the transmission channel is compromised, the attacker can only obtain the encrypted ciphertext and cannot decipher the content of the radio frequency signal set; this layered encryption strategy ensures the confidentiality and integrity of core data throughout its entire lifecycle of generation, transmission, and storage.

[0024] Optionally, the vehicle-mounted terminal includes: a central processing unit; a secure storage unit for storing keys; a positioning module; a multi-mode radio frequency signal acquisition module integrating multiple radio frequency front-ends to support synchronous acquisition; and a dual-mode communication module including cellular and LoRa communication chips. Attached Figure Description

[0025] Figure 1 This is a block diagram of the LoRa communication-based safety monitoring system for the master lock of an oil tanker truck. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be described in detail below. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0027] This application proposes a security monitoring system for a tanker truck's master lock based on LoRa communication. By introducing a mechanism for comparison and verification of multimodal environmental radio frequency signals, the system determines the physical space where the vehicle is located, thereby building a security defense line that can resist advanced attacks such as GPS spoofing.

[0028] The following section will elaborate on the specific implementation methods of this application, focusing on the various components of the system and their interaction processes.

[0029] like Figure 1 As shown in the figure, the LoRa-based oil tanker lock safety monitoring system according to this application includes a monitoring center server, a vehicle terminal, and a lock device. These three components work together organically through a wireless communication network to achieve closed-loop safety monitoring of the entire oil tanker unloading operation.

[0030] The monitoring center server is configured to build and maintain a pre-stored radio frequency signal set database. This database stores one or more preset authorized geographical locations and their corresponding multimodal environmental radio frequency signal sets. Each multimodal environmental radio frequency signal set is a unique set of radio signal characteristics representing a specific spatial physical environment. The vehicle-mounted terminal is installed on the tanker truck and electrically connected to a lock / lock system. The vehicle-mounted terminal includes a positioning module for acquiring the vehicle's real-time geographical coordinates, a multimodal radio frequency signal acquisition module for synchronously acquiring various types of radio signals from the surrounding environment, and a communication module for remote data interaction with the monitoring center server. The vehicle-mounted terminal is configured to respond to the driver's unlocking operation, triggering the positioning module to acquire the current geographical location and initiating an unlocking authorization request containing the current geographical location to the monitoring center server via the communication module. The monitoring center server is further configured to receive... Upon receiving the unlock authorization request, a time-sensitive and unique dynamic challenge command is generated and sent to the vehicle terminal to initiate the environmental authenticity verification process. The vehicle terminal is further configured to receive and parse the dynamic challenge command, drive the multimodal radio frequency signal acquisition module to capture the radio signals of the current environment in real time, generate the current radio frequency signal set, and send the current radio frequency signal set back to the monitoring center server as a response to the dynamic challenge command. Finally, the monitoring center server is configured to perform a similarity comparison verification between the received current radio frequency signal set and the multimodal environmental radio frequency signal set retrieved from the pre-stored radio frequency signal set database according to the current geographical location. If the matching degree between the two meets the preset security threshold, the vehicle is determined to be in place, and an unlock authorization command is generated. The unlock authorization command is securely sent to the vehicle terminal through the LoRa communication unit in the communication module to authorize it to open the master lock in the master lock device.

[0031] For example, in this embodiment of the application, after the tanker truck driver arrives at the designated unloading point, such as a gas station or a factory tank area, he initiates an unlocking request through the human-machine interface on the vehicle terminal. The human-machine interface can be a physical button or a virtual button on a touch screen.

[0032] After receiving the request, the vehicle terminal calls its internal positioning module to obtain the current GPS / BeiDou coordinates, and sends the unlock authorization request containing the vehicle ID, current coordinates and request timestamp to the monitoring center server through the main communication channels such as 4G / 5G.

[0033] After receiving the request, the monitoring center server first checks whether the coordinates are a registered authorized location in the pre-stored radio frequency signal set database. If so, it does not authorize directly, but generates a dynamic challenge command containing a one-time random number and a timestamp, and sends it to the vehicle terminal via cellular network or 4G / 5G, etc., to command it to perform environmental radio frequency scanning.

[0034] After receiving the challenge command, the vehicle terminal drives the multi-mode radio frequency signal acquisition module to perform a snapshot scan of the surrounding radio environment and generate a current radio frequency signal set. The data packet of the current radio frequency signal set will contain a Nonce (Number once, in cryptography, a Nonce is an arbitrary or non-repeating random value that is used only once) issued by the monitoring center server. Subsequently, the vehicle terminal responds by sending this radio frequency signal set containing the Nonce back to the monitoring center server through the cellular network.

[0035] After receiving the response, the monitoring center server first verifies the validity of the Nonce to prevent replay attacks. After the verification is successful, it retrieves the pre-stored set of radio frequency signals corresponding to the requested coordinates from the database and calls a machine learning algorithm to perform a deep comparison between the received current set of radio frequency signals and the pre-stored set of radio frequency signals.

[0036] If the similarity of the comparison results is higher than the preset security threshold, such as 90%, the monitoring center server determines that the vehicle is actually in place and generates an unlocking authorization command that is digitally signed and encrypted. In order to ensure the reliable delivery of the unlocking authorization command, the unlocking authorization command will be sent to the vehicle terminal through a dedicated LoRa communication channel with strong anti-interference capabilities. If the comparison fails, the monitoring center server determines it to be an abnormal situation, such as GPS spoofing, rejects the request, and triggers an alarm.

[0037] After receiving the unlocking command via the LoRa module, the vehicle terminal decrypts and verifies the signature. If the verification is successful, it drives the actuator connected to the main lock, such as an electromagnet or motor, to unlock the main lock. The main lock is usually the key lock that controls the main outlet of all valves on the tanker truck.

[0038] After the main lock is successfully opened, the system status of the vehicle terminal changes to "sublocks to be opened". At this time, the driver or oil depot manager and other on-site operators can perform local identity authentication on the human-machine interface of the vehicle terminal by entering a password or swiping an RFID work card. After successful authentication, the operator can select one or more sublocks to be opened (corresponding to different oil tank valves), and the vehicle terminal will then send opening signals to the actuators of these sublocks respectively.

[0039] The components and technical details are described in detail below.

[0040] Specifically, the monitoring center server is responsible for data storage, intelligent analysis, and decision authorization. In a specific embodiment, the monitoring center server can be deployed in the cloud, such as Alibaba Cloud or Tencent Cloud, to provide services in the form of Platform as a Service or Software as a Service, thereby ensuring high availability, scalability, and data disaster recovery capabilities.

[0041] The hardware configuration can use a load balancer connected to a cluster of multiple application servers, with a high-availability database cluster and a cache server connected to the backend to handle a large number of concurrent requests from vehicle terminals. The database cluster can be a MySQL master-slave replication, a MongoDB sharded cluster, etc., and the cache server can be Redis.

[0042] The software architecture can adopt a microservice architecture, which breaks down the entire backend system into multiple independent services, including device access service, identity authentication and authorization service, geographic and radio frequency signal aggregate data service, dynamic query service, radio frequency signal aggregate comparison engine, command issuance service, and alarm and log service.

[0043] Specifically, the device access service is responsible for handling connections and data reporting initiated by vehicle terminals via protocols such as MQTT and HTTP, and managing long-lived device connections; the identity authentication and authorization service is used to manage information such as vehicles, users, and permissions; the geographic and radio frequency signal set data service is responsible for maintaining the pre-stored radio frequency signal set database and providing interfaces for adding, deleting, modifying, and querying radio frequency signal sets; the dynamic challenge service is responsible for generating and managing time-sensitive dynamic challenge commands and their nonces; the radio frequency signal set comparison engine embeds a machine learning model to perform comparison calculations between the current radio frequency signal set and the pre-stored radio frequency signal set; the command issuance service is responsible for generating, signing, and encrypting commands, and pushing the commands to the specified vehicle terminals through the API of the LoRaWAN Network Server; and the alarm and log service records all operation logs, system status, and abnormal alarms for subsequent audit analysis.

[0044] The pre-stored radio frequency signal set database is the foundation for realizing location authenticity verification. Its construction process includes: performing multiple radio frequency environment scans at a preset authorized geographical location through a data acquisition device or vehicle terminal, then filtering, denoising and extracting features from the acquired data to form a benchmark radio frequency signal set template that characterizes the unique radio frequency environment of the location, and storing it in conjunction with the geographic coordinates.

[0045] Specifically, after a new authorized unloading point is determined, such as a newly built gas station, on-site radio frequency signal collection is required. The collection work can be completed by a dedicated portable collection device or by a registered and trusted vehicle terminal that has entered collection mode. In order to ensure the stability of the radio frequency signal collection, the collection needs to be carried out multiple times at different time points. For example, at an authorized point, collection can be carried out continuously for 24 hours at 10-minute intervals, or more than 100 collections can be carried out cumulatively on different dates.

[0046] It is understandable that the collection of multimodal environmental radio frequency signals is composed of physical layer or network layer feature parameters of radio signals originating from at least two different communication protocols. The types of radio signals are selected from a group consisting of Wi-Fi signals, cellular network signals, Bluetooth signals, and LoRa network signals. It is necessary to extract representative features from them to form feature vectors.

[0047] Specifically, the extracted features include, but are not limited to, the MAC addresses (i.e., BSSIDs), Received Signal Strength Indicator (RSSI), channels, and Service Set Identifiers of all nearby scannable Wi-Fi access points; the extracted features include the Global Cell Identifier, Physical Cell ID, Received Signal Power, Received Signal Quality, and Timing Advance of the current serving cell and neighboring cells; the extracted features include the MAC addresses and RSSI values ​​of surrounding Bluetooth devices, especially Bluetooth Low Energy beacons; if the licensed point is located in the LoRaWAN network coverage area, the beacon signals emitted by nearby LoRa gateways can also be collected, and their gateway IDs, RSSIs, and signal-to-noise ratios can be extracted.

[0048] The feature vectors collected multiple times are processed to generate a robust RF signal set template. A simple approach is to calculate the average, median, and standard deviation of the RSSI values ​​measured multiple times for each detected signal source, such as a specific Wi-Fi BSSID, and use these as features of that signal source. Occasional signal sources with low occurrence frequency can be filtered out. Ultimately, the RF signal set template for a location can be a complex data structure composed of features from multiple signal sources, such as a JSON object or a fixed-length vector.

[0049] The generated radio frequency signal set template is bound to the geographical coordinates (latitude and longitude), location name, ID and other information of the authorized point and stored in the database.

[0050] It is understood that the vehicle-mounted terminal in this application embodiment is installed on a tanker truck and includes: a central processing unit; a secure storage unit for storing keys; a positioning module; a multi-mode radio frequency signal acquisition module that integrates multiple radio frequency front-ends to support synchronous acquisition; and a dual-mode communication module that includes cellular and LoRa communication chips.

[0051] Specifically, the central processing unit can be an industrial-grade 32-bit ARM Cortex-M4 / M7 series microcontroller or a more powerful Cortex-A series application processor; the former has lower power consumption and is suitable for a pure RTOS environment; the latter has higher performance and can run the Linux operating system, making it easier to implement more complex application logic and algorithms.

[0052] To protect core sensitive data such as keys and device certificates, a dedicated secure storage solution can be adopted. For example, a secure area integrated inside the main control MCU, such as TrustZone, can be selected, or an external secure element chip can be added. All encryption operations, signature verification, and other operations are completed in this secure environment, and the private key will never leave the security boundary.

[0053] The positioning module can be a module that supports multi-mode satellite navigation systems to improve positioning accuracy and reliability. For example, U-Blox's ZED-F9P series modules support GPS, BeiDou, GLONASS, Galileo and other modes.

[0054] There are several ways to implement a multi-mode radio frequency signal acquisition module. One approach is to use an integrated solution with one or more SoC chips that integrate multiple wireless communication functions. For example, one chip can support both Wi-Fi and Bluetooth scanning, while another chip can handle cellular network communication and report neighboring cell information. Alternatively, separate modules can be used to implement discrete solutions for different signal acquisition functions. For instance, an ESP32 module can be used for Wi-Fi and Bluetooth scanning, a Quectel 4G / 5G module can be used to acquire cellular network information, and a Semtech LoRa chip can be added for LoRa communication. The CPU controls these modules uniformly through interfaces such as UART and SPI, and scans synchronously.

[0055] Understandably, the vehicle terminal's communication module is configured in a dual-channel mode, with the cellular communication unit serving as the main channel for regular data interaction and the LoRa communication unit serving as a dedicated redundant channel for receiving unlocking authorization commands, ensuring that core commands can still be reliably delivered when the cellular network is interfered with.

[0056] Specifically, the cellular communication unit can be a cellular module that supports 4G LTE Cat 1 / Cat 4 or 5G, responsible for routine communication with large data volumes or low latency, such as reporting of radio frequency signal sets.

[0057] The LoRa communication unit is a LoRa or LoRaWAN transceiver. Due to the excellent penetration and anti-interference capabilities of LoRa technology, even if the vehicle is parked in a basement or a large steel structure factory, resulting in weak or even interrupted cellular signals, the LoRa signal still has a high probability of penetrating the obstacle to ensure that the most critical unlocking command can be received. This redundancy design is the key to ensuring system availability.

[0058] The peripheral interfaces include relays or drive circuits that drive the electromagnetic mechanism of the master lock; GPIO, I2C, and SPI interfaces for connecting the human-machine interface; and RFID reader interfaces for local identity authentication.

[0059] Alternatively, it can draw power from the tanker truck's battery, with a built-in wide voltage input DC-DC converter (e.g., 9-36V) and a backup lithium battery to ensure that the terminal can still operate for a period of time and report a power outage alarm when the vehicle loses power or the battery is illegally removed.

[0060] Understandably, dynamic challenge commands include random numbers or timestamps as one-time tokens. The vehicle terminal needs to incorporate the token into the current radio frequency signal set and send it back. The server verifies the token to ensure the real-time nature of the response information in order to resist replay attacks.

[0061] Specifically, when generating a challenge, the server-side dynamic challenge service generates a high-strength random number as a Nonce, such as a 128-bit UUID, and records the generation time of the Nonce and the vehicle ID associated with it; the validity period of the Nonce is very short, such as 30 seconds.

[0062] Once the vehicle terminal receives a challenge command, it will execute the radio frequency scanning task with the highest priority to minimize the time difference between the challenge and the response and reduce the window for attackers to perform intermediate operations. After the terminal has collected the radio frequency signal set data, it will put the Nonce sent by the server into the response data packet without modification.

[0063] After receiving the response, the server's first step is to extract the Nonce and compare it with its own Nonce, which is still valid. If they match, it proves that the response is a real-time feedback to the challenge. If they do not match or the timeout has occurred, the server immediately discards the packet and records a potential replay attack event.

[0064] Understandably, the comparison and verification process uses machine learning or pattern recognition algorithms. The pattern recognition algorithm calculates the similarity between the current set of radio frequency signals and the pre-stored set of radio frequency signals based on their feature vectors, and compares it with a preset security threshold to make a decision.

[0065] Specifically, before comparison, both the pre-stored RF signal set template and the current RF signal set can be converted into feature vectors of a unified format. For example, a global dictionary containing all Wi-Fi BSSIDs and cell IDs that may appear near the license point can be constructed. An RF signal set can be represented as a long vector, where each dimension of the vector corresponds to a signal source in the dictionary, and its value is the RSSI of that signal source. If it is not detected, it is a special minimum value, such as -120dBm.

[0066] Pattern recognition algorithms can be either the K-Nearest Neighbors algorithm or a Support Vector Machine (SVM). The K-Nearest Neighbors algorithm compares the feature vector of the current radio frequency signal set with all historical samples collected at that location in the database to see if the K nearest neighbors in the feature space mostly belong to that location. This method is simple and intuitive, but computationally intensive. The SVM can train a binary classification SVM model. Positive samples are a large set of radio frequency signal data collected at authorized locations, while negative samples are a set of radio frequency signal data collected at various unauthorized locations, including roads, other cities, and the vicinity of known black market oil depots. The trained model can directly determine whether the input current radio frequency signal set belongs to a match (i.e., at an authorized location) or a mismatch (i.e., not at an authorized location).

[0067] Understandably, a convolutional neural network or recurrent neural network could also be designed to process RF signal datasets; for example, Wi-Fi BSSID and RSSI sequences could be treated as an image or time series, and a neural network could be used to automatically learn their deep spatial or temporal features. This approach may be more robust to environmental changes, but it requires more training data and stronger server computing power.

[0068] The algorithm's output is typically a similarity score (e.g., between 0 and 1) or a classification result. System administrators can set an adjustable security threshold based on the security level of the actual application scenario; for example, the threshold can be set to 0.95 for the transportation of highly sensitive chemicals and 0.85 for ordinary fuels.

[0069] It is understandable that the control logic of the master lock device is a hierarchical authorization mode. The opening permission of the master lock is remotely controlled by the monitoring center server; the opening permission of the slave lock is managed locally by the vehicle terminal, and the prerequisite for its unlocking operation is that the master lock has been successfully opened; after the prerequisite for unlocking the slave lock is met, the vehicle terminal must also verify the local identity authentication credentials of the on-site operator through the human-machine interface before it can execute the unlocking of the slave lock; the identity authentication credentials include at least one of password, RFID card or biometric information.

[0070] Specifically, the main lock can be a heavy-duty electronic lock installed on the outer protective door of the valve compartment of the tanker truck or on the main pipeline switch; for example, a locking pin driven by a high-torque motor or a high-strength electromagnetic attraction lock that can only be opened by a single, legitimate electronic signal.

[0071] Sublocks can be small electrically controlled valves or electrically controlled latches installed on each independent oil tank unloading valve, under the protection of the main lock. Their structure can be relatively simple because their safety is protected by the main lock.

[0072] The firmware of the vehicle terminal implements a state machine to manage the hierarchical authorization logic.

[0073] The initial state is that both the master lock and the child locks are closed.

[0074] Upon receiving a valid unlocking command from the monitoring center server: the status changes to "main lock open", the vehicle terminal drives the main lock to open, and displays "Main lock open, please verify your identity to unlock the sub-lock" on the human-machine interface.

[0075] When the main lock is open, the system activates the local identity authentication module, such as an RFID card reader. After the operator swipes the card or enters a credential, the terminal verifies whether the credential is a pre-authorized and valid credential.

[0076] After local identity authentication is successful, the status changes to "sublock authentication successful". The interface displays a list of sublocks to choose from, such as "Block 1" and "Block 2". After the operator selects a sublock, the vehicle terminal drives the corresponding sublock to open.

[0077] After the operator completes the oil unloading, they can select to lock all locks through the interface, or the system will automatically time out after a period of inactivity, and the state machine will return to the state where the main lock and sub-locks are all closed, and all opened locks will automatically close and lock.

[0078] Throughout the system of this application embodiment, the confidentiality, integrity, and authenticity of the data are of paramount importance; all TCP / IP-based communication between the vehicle terminal and the monitoring center server (mainly the cellular network channel in this application embodiment) is required to use TLS 1.2 or a higher version protocol; the root certificate of the server is pre-installed inside the vehicle terminal, and the server certificate is strictly verified when establishing a connection to prevent man-in-the-middle attacks; at the same time, two-way authentication can be adopted, that is, the monitoring center server also needs to verify the device certificate presented by the vehicle terminal to ensure that only legitimate devices can access the system.

[0079] Understandably, for sensitive data such as radio frequency signal sets, an additional application-layer encryption can be performed before transmission through a TLS-protected channel. For example, the vehicle terminal and the monitoring center server can establish a temporary symmetric encryption key, such as AES-256, for each session through a key negotiation protocol. Before sending the radio frequency signal set data, the vehicle terminal uses this session key to encrypt the radio frequency signal set data itself. In this way, even if TLS is broken by some advanced means, the attacker will only obtain the ciphertext after the second layer of encryption, achieving deep end-to-end security.

[0080] All critical commands sent from the monitoring center server to the terminal, especially unlocking commands, require digital signatures. The monitoring center server uses a private key stored in the hardware security module to generate a signature for the command content, which may include the vehicle ID, command type, nonce, etc. After receiving the command, the vehicle terminal verifies the signature using a pre-set server public key. Commands that fail to verify the signature are considered forged or tampered with and are immediately discarded, thus ensuring the non-repudiation and integrity of the commands.

[0081] In summary, this application constructs a multi-dimensional tanker truck safety monitoring system by combining multimodal environment radio frequency signal set verification, dynamic challenge-response mechanism, machine learning-based intelligent comparison, LoRa and cellular network dual-channel communication, hierarchical authorization physical structure of master lock and child lock, and end-to-end full-link encryption strategy. It can not only effectively resist advanced technical attacks, including GPS spoofing and replay attacks, but also greatly improve the overall security level of tanker truck cargo transportation and handover through refined permission management and operation traceability. It has extremely high practical application value and promotion prospects.

[0082] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

[0083] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0084] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.

[0085] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0086] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0087] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0088] The above are all preferred embodiments of this application and are not intended to limit the scope of protection of this application. Any feature disclosed in this specification (including the abstract and drawings) may be replaced by other equivalent or similar features unless specifically stated otherwise. That is, unless specifically stated otherwise, each feature is only one example of a series of equivalent or similar features.

Claims

1. A security monitoring system for a tanker truck's master lock based on LoRa communication, characterized in that, include: The monitoring center server is configured to build and maintain a pre-stored radio frequency signal set database. The pre-stored radio frequency signal set database stores one or more preset authorized geographical locations and their corresponding multimodal environmental radio frequency signal sets. The multimodal environmental radio frequency signal set is a unique set of radio signal features characterizing a specific spatial physical environment. The vehicle-mounted terminal is installed on the tanker truck and electrically connected to the lock device. The vehicle-mounted terminal includes a positioning module for acquiring the real-time geographic coordinates of the vehicle, a multi-mode radio frequency signal acquisition module for synchronously acquiring various types of radio signals in the surrounding environment, and a communication module for remote data interaction with the monitoring center server. The vehicle terminal is configured to respond to the driver's unlocking operation, trigger the positioning module to obtain the current geographical location, and send an unlocking authorization request containing the current geographical location to the monitoring center server via the communication module. The monitoring center server is further configured to generate a time-sensitive and unique dynamic query command after receiving the unlock authorization request, and send it to the vehicle terminal to initiate the environment authenticity verification process. The vehicle-mounted terminal is further configured to receive and parse the dynamic challenge command, drive the multimodal radio frequency signal acquisition module to capture the radio signals of the current environment in real time, generate the current radio frequency signal set, and send the current radio frequency signal set back to the monitoring center server as a response to the dynamic challenge command. The monitoring center server is ultimately configured to perform a similarity comparison between the received current radio frequency signal set and the multimodal environmental radio frequency signal set retrieved from the pre-stored radio frequency signal set database based on the current geographical location. If the matching degree between the two meets the preset security threshold, the vehicle is determined to be in actual location, and an unlocking authorization command is generated. The unlocking authorization command is then securely sent to the vehicle terminal through the LoRa communication unit in the communication module to authorize it to open the master lock in the master lock device.

2. The system according to claim 1, characterized in that, The multimodal environment radio frequency signal set is composed of physical layer or network layer characteristic parameters of radio signals originating from at least two different communication protocols, and the type of radio signal is selected from a group consisting of Wi-Fi signals, cellular network signals, Bluetooth signals, and LoRa network signals.

3. The system according to claim 1, characterized in that, The process of constructing the pre-stored radio frequency signal set database includes: performing multiple radio frequency environment scans at a preset authorized geographical location through a data acquisition device or vehicle terminal, then filtering, denoising, and extracting features from the acquired data to form a reference radio frequency signal set template that characterizes the unique radio frequency environment of the location, and storing it in conjunction with geographical coordinates.

4. The system according to claim 1, characterized in that, The dynamic challenge command includes a random number or timestamp as a one-time token. The vehicle terminal needs to incorporate the token into the current radio frequency signal set and send it back. The server verifies the token to ensure the real-time nature of the response information in order to resist replay attacks.

5. The system according to claim 1, characterized in that, The comparison and verification process employs machine learning or pattern recognition algorithms. The pattern recognition algorithm calculates the similarity between the current set of radio frequency signals and the pre-stored set of radio frequency signals based on their feature vectors, and compares it with a preset security threshold to make a decision.

6. The system according to claim 1, characterized in that, The communication module of the vehicle terminal is configured in a dual-channel mode. The cellular communication unit serves as the main channel for regular data interaction, while the LoRa communication unit serves as a dedicated redundant channel for receiving unlocking authorization commands, ensuring that core commands can still be reliably delivered when the cellular network is interfered with.

7. The system according to claim 1, characterized in that, The control logic of the master lock device is a hierarchical authorization mode. The opening permission of the master lock is remotely controlled by the monitoring center server; the opening permission of the slave lock is managed locally by the vehicle terminal, and the prerequisite for its unlocking operation is that the master lock has been successfully opened.

8. The system according to claim 7, characterized in that, After the preconditions for unlocking the sublock are met, the vehicle terminal must also verify the local identity authentication credentials of the on-site operator through the human-machine interface before it can open the sublock; the identity authentication credentials include at least one of password, radio frequency identification card or biometric information.

9. The system according to claim 1, characterized in that, The communication link between the vehicle terminal and the monitoring center server is protected by a transport layer security protocol. In addition, the response information containing the current radio frequency signal set is encrypted by the vehicle terminal at the application layer before being sent, so as to achieve end-to-end security.

10. The system according to claim 1, characterized in that, The vehicle-mounted terminal includes: Central processing unit; A secure storage unit is used to store the key; Positioning module; A multi-mode radio frequency signal acquisition module integrates multiple radio frequency front-ends to support synchronous acquisition; and Dual-mode communication module, including cellular and LoRa communication chips.

Citation Information

Patent Citations

  • Information access security control method and system

    CN120263523A

  • Haulage vehicle supervises service system

    CN204870841U