Traffic scheduling method and device based on trusted execution environment and multi-agent system
By introducing a trusted execution environment and a multi-agent system into the intelligent transportation system, collaborative work among vehicles, roadside and cloud agents was achieved, solving the security and real-time issues of centralized cloud computing models and constructing a safe and reliable intelligent transportation system.
Patent Information
- Application Number
- CN202510962088.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-11-07
AI Technical Summary
Existing intelligent transportation systems are unable to effectively resist kernel-level malicious behavior or external attacks when faced with centralized cloud computing models. Furthermore, they are prone to communication delays and computing congestion when processing large-scale vehicle information, failing to meet the real-time and stability requirements of intelligent transportation.
A distributed traffic scheduling method based on a trusted execution environment and a multi-agent system is adopted. Through the collaborative work of vehicle agents, roadside agents, cloud agents, emergency agents, and safety agents, data collection, edge decision-making, global optimization, and emergency response are achieved, ensuring the security and trustworthiness of data communication.
A multi-layered, modular, secure, and reliable traffic management system was constructed, which improved traffic communication efficiency, ensured the security and real-time performance of data communication, and realized the efficient, safe, and reliable operation of intelligent transportation.
Smart Images

Figure CN120913388A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of intelligent transportation, and in particular to a traffic scheduling method and device based on a trusted execution environment and a multi-agent system. BACKGROUND
[0002] With the continuous development of intelligent transportation systems (ITS), especially the accelerated deployment of intelligent connected vehicles (ICV) and vehicle-to-everything (V2X) systems, real-time communication, data sharing and collaborative control between vehicles, road side units (RSU) and cloud scheduling centers have become key factors in improving traffic efficiency and safety.
[0003] However, the current intelligent transportation system still faces many technical challenges in actual deployment and operation. Many current intelligent transportation system solutions still rely on centralized cloud computing models and operate at the operating system level, making it difficult to effectively resist kernel-level malicious behavior or external attacks. For example, in critical scenarios such as accident emergency, signal light scheduling and path optimization, the system may make decisions based on untrusted or tampered data, making key data and control logic vulnerable to attack. In addition, the centralized cloud computing model is prone to communication delays and computing congestion when processing large amounts of vehicle information, which cannot meet the real-time and stability requirements of dynamic traffic scheduling. Therefore, the existing traffic system cannot meet the needs of future urban intelligent transportation. SUMMARY
[0004] The present application provides a traffic scheduling method and device based on a trusted execution environment and a multi-agent system to solve the problem that the existing traffic system cannot meet the needs of intelligent transportation.
[0005] In a first aspect, the present application provides a traffic scheduling method based on a trusted execution environment and a multi-agent system, the method comprising:
[0006] collecting vehicle data by a vehicle Agent and sending it to the nearest road side Agent;
[0007] making a local decision on the vehicle data by the road side Agent in combination with its own perception of local traffic data to schedule road side resources and broadcast the generated obstacle information to surrounding vehicle Agents;
[0008] obtaining and analyzing the vehicle data and the obstacle information sent by the road side Agent through a cloud Agent to generate a global traffic decision;
[0009] controlling vehicle driving based on the obstacle information and the global traffic decision by the vehicle Agent;
[0010] responding quickly in emergency by the emergency Agent, and supervising authenticity and security in data communication process by the security Agent;
[0011] wherein the vehicle Agent, the roadside Agent, the cloud Agent, the emergency Agent and the security Agent all run in the trusted execution environment.
[0012] Optionally, the local decision on the vehicle data by the roadside Agent in combination with local traffic data perceived by itself for roadside resource scheduling and broadcasting the generated obstacle information to surrounding vehicle Agents comprises:
[0013] acquiring and storing the vehicle data by the roadside Agent, wherein each roadside Agent is a blockchain node;
[0014] optimizing timing control of traffic signal lights and dynamically adjusting lane functions in response to the received vehicle data and local traffic data, wherein the local traffic data includes queue length of each lane, average waiting time of vehicles and priority of emergency vehicles;
[0015] generating obstacle information in combination with the local traffic data, and broadcasting the obstacle information to surrounding vehicle Agents after digitally signing the obstacle information.
[0016] Optionally, acquiring and analyzing the vehicle data and the obstacle information sent by the roadside Agent by the cloud Agent for generating global traffic decision comprises:
[0017] acquiring the vehicle data and the obstacle information sent by the roadside Agent by the cloud Agent;
[0018] predicting influence of different scheduling strategies on traffic by simulating the vehicle data and the obstacle information, and adopting a scheduling strategy that minimizes average delay;
[0019] generating congestion probability heat map according to preset data, the vehicle data and the obstacle information, and allocating dynamic road right to key road sections according to the congestion probability heat map;
[0020] conducting personalized path recommendation in combination with vehicle type and user preference, and generating coordination strategy in road congestion, wherein the coordination strategy is used for coordinating vehicle alternate passage.
[0021] Optionally, controlling vehicle driving by the vehicle Agent in combination with the obstacle information and the global traffic decision comprises:
[0022] generating a vehicle driving strategy by the vehicle Agent according to the acquired obstacle information and the global traffic decision;
[0023] generating a driving control instruction according to the vehicle driving strategy, and requesting the security Agent to digitally sign the driving control instruction;
[0024] after the actuator receives the signed driving control instruction, requesting the security Agent to perform signature verification;
[0025] after the signature verification passes, executing the driving control instruction by the actuator to control vehicle driving.
[0026] Optionally, generating a vehicle driving strategy by the vehicle Agent according to the acquired obstacle information and the global traffic decision comprises:
[0027] analyzing the obstacle information based on a preset collision avoidance model to determine an optimal avoidance strategy;
[0028] based on the obstacle information and the global traffic decision, adjusting congestion weight and safety weight using a heuristic search algorithm to select a low-delay path and avoid accident-prone areas;
[0029] using a reinforcement learning model to optimize vehicle acceleration and deceleration strategies according to the dispatched roadside resources.
[0030] Optionally, the emergency Agent quickly responds in an emergency situation comprises:
[0031] the emergency Agent acquires and analyzes multi-modal data to determine the severity of the accident, wherein the multi-modal data comes from the vehicle Agent, the roadside Agent, and the cloud Agent;
[0032] starting a hierarchical response according to the severity of the accident;
[0033] determining the corresponding processing operation in the smart contract according to the response level, and sending the processing operation to the roadside Agent and the vehicle Agent.
[0034] Optionally, the security Agent supervises the authenticity and security of the data communication process comprises:
[0035] the security Agent digitally signs the data to be sent and performs signature verification on the received data;
[0036] Verify the authenticity of the vehicle identity through lightweight zero-knowledge proof;
[0037] Verify the identity of each Agent through a certificate chain, and confirm the authenticity of trust through a certificate revocation list in a synchronous blockchain;
[0038] Multi-dimensional trust scoring of data, and adding the corresponding Agent to a gray list when the trust score is lower than a preset threshold, wherein the multi-dimensions include data consistency, communication activity, and historical violation records of each Agent, and the Agent in the gray list is limited in communication bandwidth.
[0039] In a second aspect, the application provides a traffic scheduling device based on a trusted execution environment and a multi-agent system, the device comprising:
[0040] A collection module for collecting vehicle data through a vehicle Agent and sending the data to a nearest roadside Agent;
[0041] A decision module for making a local decision on the vehicle data through the roadside Agent in combination with local traffic data perceived by the roadside Agent, to make a roadside resource scheduling and broadcast generated obstacle information to surrounding vehicle Agents;
[0042] A generation module for obtaining and analyzing the vehicle data and the obstacle information sent by the roadside Agent through a cloud Agent, to generate a global traffic decision;
[0043] A control module for controlling vehicle driving based on the obstacle information and the global traffic decision through the vehicle Agent;
[0044] A response and supervision module for responding quickly in an emergency through an emergency Agent, and supervising authenticity and security in a data communication process through a security Agent;
[0045] The vehicle Agent, the roadside Agent, the cloud Agent, the emergency Agent, and the security Agent all run in the trusted execution environment.
[0046] In a third aspect, the application provides an electronic device, comprising: at least one communication interface; at least one bus connected with the at least one communication interface; at least one processor connected with the at least one bus; and at least one memory connected with the at least one bus.
[0047] In a fourth aspect, the present application also provides a computer storage medium storing computer executable instructions for executing the traffic scheduling method based on the trusted execution environment and the multi-agent system according to any one of the preceding aspects.
[0048] The above technical solution provided by the embodiments of the present application has the following advantages compared with the prior art: through the collaborative work of the vehicle Agent, the roadside Agent, the cloud Agent, the emergency Agent and the security Agent. The vehicle Agent is responsible for terminal data acquisition and execution, the roadside Agent realizes edge decision and local scheduling, the cloud Agent completes global optimization, the emergency Agent focuses on emergency response, and the security Agent guarantees communication security, and each module has clear division of labor and close cooperation. At the same time, all the Agents run in the trusted execution environment, ensuring the security and trustworthiness of data in the process of acquisition, transmission and processing. The present application constructs a multi-level, modular and secure and trusted traffic management system, which can improve the efficiency of traffic communication and guarantee the security of data communication, and realizes efficient, safe and reliable operation of intelligent transportation. BRIEF DESCRIPTION OF DRAWINGS
[0049] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and serve to explain the principles of the present application together with the specification.
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, those skilled in the art can obtain other drawings from these drawings without any creative effort.
[0051] One or more embodiments are exemplarily illustrated by pictures in the drawings corresponding to the embodiments, and these exemplary illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, unless otherwise specified. The drawings in the drawings do not constitute a proportional limitation.
[0052] Figure 1 A traffic scheduling system block diagram based on a trusted execution environment and a multi-agent system is provided for the embodiments of the present application;
[0053] Figure 2 A traffic scheduling method flowchart based on a trusted execution environment and a multi-agent system is provided for the embodiments of the present application;
[0054] Figure 3 A traffic scheduling device structure schematic diagram based on a trusted execution environment and a multi-agent system is provided for the embodiments of the present application;
[0055] Figure 4 FIG. 1 is a schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0056] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described below in connection with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0057] The following disclosure provides many different embodiments, or examples, for implementing different structures of the present application. For the purpose of simplicity, the elements and settings of particular examples in the following are described. Of course, they are merely examples and are not intended to limit the present application. Furthermore, the present application can repeat reference numerals and / or letters in various examples. Such repetition is for the purpose of simplicity and clarity and does not in itself dictate a relationship between the various embodiments and / or settings discussed.
[0058] In order to solve the problem that the existing traffic system mentioned in the background art is difficult to meet the demand of intelligent traffic, the embodiments of the present application avoid the occurrence of computing congestion by distributed Agent, and all the communication and calculation of the Agent are in a trusted execution environment, thereby constructing an intelligent traffic system which is safe and trusted, autonomous and collaborative, and fast in response.
[0059] Optionally, in the embodiments of the present application, the traffic scheduling method based on the trusted execution environment and the multi-agent system can be applied to the hardware environment composed of vehicle Agent, roadside Agent, cloud Agent, emergency Agent and safety Agent as shown in Figure 1 As shown in Figure 1 The vehicle Agent manages the operation of a single vehicle, including sensor data collection, decision making and control; the roadside Agent is responsible for local traffic data aggregation and optimization (such as signal light control), and communicates with the cloud; the cloud Agent runs a global scheduling algorithm, predicts congestion and generates dynamic path planning; the safety Agent monitors communication security, maintains node trust score and issues alerts; the emergency Agent detects accidents or emergencies, initiates emergency protocols and coordinates resources; all Agents work collaboratively through the communication link protected by the trusted execution environment, forming a distributed, intelligent and highly secure traffic management platform.
[0060] Next, the traffic scheduling method based on the trusted execution environment and the multi-agent system provided by the embodiments of the present application will be described in detail in connection with the specific embodiments, taking aa as an example.Figure 2 The specific steps are as follows:
[0061] Step 201: Collect vehicle data by the vehicle Agent and send it to the nearest roadside Agent;
[0062] Step 202: Make local decisions on vehicle data by the roadside Agent in combination with local traffic data perceived by itself, to schedule roadside resources and broadcast generated obstacle information to surrounding vehicle Agents;
[0063] Step 203: Obtain and analyze vehicle data and obstacle information sent by the roadside Agent through the cloud Agent, to generate global traffic decisions;
[0064] Step 204: Control vehicle driving based on obstacle information and global traffic decisions by the vehicle Agent;
[0065] Step 205: Respond quickly in emergency situations through the emergency Agent, and supervise the authenticity and security of the data communication process through the security Agent;
[0066] Among them, the vehicle Agent, roadside Agent, cloud Agent, emergency Agent and security Agent all run in a trusted execution environment.
[0067] First, some terms used in the embodiments of the present application are explained, including the following contents.
[0068] Vehicle Agent: an intelligent agent deployed on a vehicle terminal, integrating sensor data collection, decision generation and vehicle control functions, responsible for real-time perception of vehicle operating state and surrounding environment information.
[0069] Roadside Agent: an intelligent agent installed on roadside infrastructure, with local traffic data perception, edge computing and communication capabilities, capable of real-time scheduling of local traffic.
[0070] Cloud Agent: an intelligent agent based on a cloud computing platform, integrating global traffic data, and achieving global traffic situation analysis and decision optimization through complex algorithms.
[0071] Emergency Agent: an intelligent agent focusing on emergency response, capable of quickly identifying emergency events and starting a hierarchical emergency handling mechanism.
[0072] Security Agent: an intelligent agent responsible for ensuring data communication security, ensuring the authenticity and integrity of data transmission through digital signature, identity verification and other technologies.
[0073] Trusted Execution Environment (TEE): A hardware isolated secure area that provides a secure execution environment for each agent, preventing code and data from being illegally accessed and tampered with.
[0074] In step 201, the vehicle Agent, as the core carrier of vehicle intelligence operation, is embedded in the computing unit of the vehicle and runs in the trusted execution environment. The vehicle Agent collects real-time vehicle operating state (such as position, speed, acceleration) and surrounding environment data (such as pedestrian, obstacle distribution) through on-board sensors, and then uses Kalman filtering and LSTM (Long Short-Term Memory Network) deep learning model to fuse GPS, LiDAR (Light Detection and Ranging), camera and IMU (Inertial Measurement Unit) and other multi-source data, eliminating noise and generating high-precision environment perception results. For example, after recognizing the state of the traffic signal lamp through the camera, it is combined with the GPS positioning data to calculate the relative distance between the vehicle and the signal lamp in real time.
[0075] Among them, the original sensor data is encrypted by AES-256 before entering the trusted execution environment, and the key is managed by the secure storage module of the trusted execution environment, ensuring that only the authorized decision module can access the decrypted data; at the same time, anomaly detection algorithms such as isolated forest are run in the trusted execution environment to identify sensor data anomalies (such as GPS signal loss or camera obstruction) in real time and trigger security protocols, and finally transmit the encrypted information to the roadside Agent through the Internet of Vehicles communication technology, realizing the whole process of data collection, fusion, and secure transmission.
[0076] In step 202, the roadside Agent is deployed in the roadside unit, and after receiving the vehicle data, on the one hand, it combines its own perception of the local traffic environment to perform local decision tasks. Based on the analysis of road traffic flow, vehicle queuing situation, special vehicle demand and other information, it reasonably schedules roadside resources. For example, dynamically adjust the length and phase of traffic signal lights, optimize lane functions to adapt to traffic demand at different times.
[0077] On the other hand, the roadside Agent will comprehensively process vehicle data and local traffic data to identify obstacles, accidents or construction and other abnormal situations on the road, and generate corresponding obstacle information. After security verification by the trusted execution environment, the roadside Agent broadcasts this information to surrounding vehicle Agents, enabling vehicles to grasp the road conditions in advance and take timely measures.
[0078] In step 203, the cloud agent manages traffic from a city-level perspective, responsible for integrating vehicle data and obstacle information uploaded from multiple roadside agents. Through powerful data analysis and processing capabilities, the cloud agent macroscopically controls the global traffic situation, and uses algorithm models to comprehensively consider traffic flow optimization, energy consumption reduction, safety protection, and other dimensions to make global traffic decisions. For example, by analyzing historical traffic data and real-time information, it predicts future traffic congestion and allocates dynamic road rights for key road sections; according to vehicle types and user preferences, it provides personalized route planning suggestions; in the case of road congestion, it coordinates the passing order of multiple vehicles to prevent further traffic deterioration. These decisions aim to achieve overall efficient operation of urban traffic and improve the service quality of the transportation system.
[0079] In step 204, after obtaining the obstacle information broadcast by the roadside agent and the global traffic decisions generated by the cloud agent, the vehicle agent formulates specific driving strategies based on the vehicle's own driving goals and safety requirements. It considers factors such as avoiding obstacles, following global route planning, and adapting to traffic flow changes to adjust the vehicle's driving direction, speed, and other factors. The vehicle agent converts the driving strategy into executable control instructions, which are executed to achieve intelligent and safe driving of the vehicle. By combining local optimization and global optimization, the vehicle agent predicts and mitigates congestion and quickly responds to dynamic traffic changes.
[0080] In step 205, the emergency agent constantly monitors various data in the transportation system and immediately activates the rapid response mechanism upon detecting an emergency situation such as a traffic accident or natural disaster. It first assesses the severity of the emergency situation and initiates appropriate response measures based on the assessment results. For different levels of response, the emergency agent determines specific handling operations through smart contracts, such as dispatching rescue vehicles, adjusting traffic signal lights to create a green channel for rescue vehicles, and guiding surrounding vehicles to avoid, etc. During the entire emergency response process, the security agent supervises all aspects of data communication, ensuring data authenticity and communication security through digital signatures, identity verification, trust scoring, and other means, preventing malicious attacks and data tampering, and ensuring the security and authenticity of data communication.
[0081] Each of the above agents runs in a trusted execution environment, which separates the execution environment of each agent from the external untrusted environment through hardware-level security isolation mechanisms, ensuring that code and data are processed in a closed and encrypted space, preventing sensitive information leakage and malicious tampering, and providing strong trusted computing protection for the entire intelligent transportation system.
[0082] Exemplarily, during the morning peak period, a traffic accident occurs due to a rear-end collision on a certain road section. The vehicle Agent of the accident vehicle immediately collects accident-related data (such as emergency braking signals, vehicle position, collision state), and sends it to the nearest roadside Agent. The roadside Agent combines the picture captured by its own camera and the data reported by other vehicles to confirm the severity of the accident, and initiates signal light adjustment through local decision-making to switch the upstream and downstream signal lights on the accident road section to red, and generates obstacle information including accident coordinates and impact range, and broadcasts it to surrounding vehicle Agents. After receiving the accident information uploaded by multiple roadside Agents, the cloud Agent analyzes the traffic flow changes in the region, predicts the congestion diffusion trend by using the digital twin model, generates global traffic decisions, including recommending detour routes for affected vehicles and adjusting signal timing in the surrounding area. The vehicle Agent of the surrounding vehicle plans a new driving path according to the received obstacle information and global traffic decisions to avoid the accident area. After detecting the accident, the emergency Agent determines that it is a high-level response, triggers the smart contract, dispatches the nearest ambulance to the accident site, and links the roadside Agent to generate a green wave band for the ambulance. The security Agent verifies the signature of each piece of data during the entire data communication process to ensure that the information is not tampered with and to ensure the smooth progress of the rescue process.
[0083] In the present application, the vehicle Agent, the roadside Agent, the cloud Agent, the emergency Agent and the security Agent work cooperatively. The vehicle Agent is responsible for terminal data collection and execution, the roadside Agent realizes edge decision and local scheduling, the cloud Agent completes global optimization, the emergency Agent focuses on emergency response, and the security Agent guarantees communication security. Each module has clear division of labor and close cooperation. At the same time, all Agents run in a trusted execution environment to ensure the security and credibility of data in the process of collection, transmission and processing. The present application constructs a multi-level, modular and secure and reliable traffic management system, which can improve the efficiency of traffic communication and ensure the safety of data communication, and realize efficient, safe and reliable operation of intelligent transportation.
[0084] In addition, the present application provides a distributed intelligent agent architecture, which reduces the centralized bottleneck and improves the response speed and scalability.
[0085] As an optional implementation, in step 202, the local decision-making on the vehicle data by the roadside Agent in combination with the local traffic data perceived by itself to perform roadside resource scheduling and broadcast the generated obstacle information to surrounding vehicle Agents includes:
[0086] Step S11: acquiring and storing vehicle data by the roadside Agent, wherein each roadside Agent is a blockchain node;
[0087] Step S12: In response to the received vehicle data and its own local traffic data, optimize the timing control of the traffic signal and dynamically adjust the lane function, wherein the local traffic data includes the queue length of each lane, the average waiting time of vehicles, and the priority of emergency vehicles;
[0088] Step S13: Generate obstacle information combined with local traffic data, and broadcast the digitally signed obstacle information to surrounding vehicle agents.
[0089] In step S11, the roadside agent acts as a lightweight blockchain node (such as accessing the IOTA Tangle network) to receive and store encrypted vehicle data uploaded by vehicle agents through a distributed storage mechanism. Each roadside agent only stores data shards of the local road segment, ensures data integrity through a lightweight blockchain consensus algorithm, and reduces the storage pressure of a single point. After receiving the vehicle data, the Apache Kafka streaming processing framework is used to clean the heterogeneous data (such as CAN bus data from different manufacturers' sensors and JSON format V2X messages) in real time, and the standardized components are converted into a unified traffic information model (such as JSON Schema containing timestamp, vehicle ID, and lane number), providing a high-quality data foundation for subsequent optimization.
[0090] In step S12, the roadside agent combines the standardized vehicle data with the local collected traffic data (such as lane queue length detected by millimeter wave radar, vehicle waiting time identified by camera, and emergency vehicle priority signal received by V2X), and executes double optimization logic as follows.
[0091] 1. Dynamic control of signal lights: A decision model is constructed through the Q-learning algorithm to minimize the overall delay at the intersection as the reward function, and the timing of the signal lights is dynamically adjusted. For example, when the eastbound lane queue length exceeds 15 vehicles and the average waiting time is > 60 seconds, the green light duration is automatically extended by 10 seconds, and the emergency passage request of an ambulance is preferentially responded (triggering the red light jump logic).
[0092] 2. Intelligent scheduling of lane functions: Run an integer linear programming (ILP) model in a trusted execution environment to dynamically allocate lane resources based on real-time traffic. For example, during the morning rush hour, calculate the traffic efficiency of each lane through ILP, temporarily switch the rightmost lane to a tidal lane (from a right-turn lane to a straight lane), and publicly announce it through a variable message board in real time to optimize the commuter traffic on this road segment.
[0093] 3. Event response and model evolution: When a vehicle sudden stop or collision signal is detected, the roadside Agent immediately broadcasts the accident coordinates and starts the federated learning mechanism to upload the accident features (such as time, weather, vehicle speed) to the regional RSU cluster, and cooperatively updates the state space parameters of the local Q-learning model to reduce the probability of repeated occurrence of similar scenarios. The state space includes but is not limited to lane queue length, vehicle average waiting time, and emergency vehicle priority.
[0094] In step S13, the roadside Agent integrates local traffic data (including accident coordinates, construction area, and temporary obstacle location), generates structured obstacle information, and digitally signs the obstacle information through the secure Agent in the trusted execution environment. The signed information is broadcast to vehicles within 500 meters through LTE-V2X. The vehicle verifies the validity of the signature through the trusted execution environment to ensure that the information has not been tampered with. The obstacle information is written into the blockchain synchronously to form an unalterable event record for subsequent accident tracing and global traffic model training. In addition, the application also manages edge server resources through Kubernetes to allocate dedicated computing nodes for high-priority tasks (such as emergency response).
[0095] Through the cooperation of distributed storage by blockchain, reinforcement learning optimization, trusted computing, and edge resource scheduling, the roadside Agent realizes the full-process capability improvement of data trusted storage-real-time intelligent regulation-safe event response, providing efficient, safe, and evolving edge decision support for the vehicle-road cooperation system.
[0096] As an optional implementation, in step 203, the cloud Agent obtains and analyzes the vehicle data and obstacle information sent by the roadside Agent, and generates global traffic decisions including the following contents:
[0097] Step S21: Obtain the vehicle data and obstacle information sent by the roadside Agent through the cloud Agent;
[0098] Step S22: Simulate the vehicle data and obstacle information, predict the impact of different scheduling strategies on traffic, and adopt the scheduling strategy that minimizes the average delay;
[0099] Step S23: Generate a congestion probability heat map based on the preset data, vehicle data, and obstacle information, and allocate dynamic road rights to key road segments based on the congestion probability heat map;
[0100] Step S24: Combine vehicle types and user preferences to recommend personalized paths, and generate coordination strategies when road congestion occurs, where the coordination strategies are used to coordinate vehicle alternating traffic.
[0101] In step S21, the cloud agent obtains the vehicle data (location, speed, type) and obstacle information (accident, construction area) uploaded by the roadside agent in real time through a distributed message queue (such as Apache Kafka).
[0102] Among them, the data transmission adopts an end-to-end encryption mechanism (such as TLS1.3), and the roadside agent uses the session key assigned by the security agent to perform AES-256 encryption on the data. After receiving the ciphertext, the cloud agent requests the security agent to perform decryption verification (zero-knowledge proof to verify the legitimacy of the data + decryption).
[0103] In step S22, the cloud agent optimizes traffic flow, energy consumption, and safety based on the received data using the NSGA-II multi-objective genetic algorithm. The objective function of the NSGA-II multi-objective genetic algorithm includes: maximizing the average vehicle speed in the city, minimizing the total delay of vehicles at intersections, ensuring the priority of emergency vehicles (such as ambulances), and integrating digital Luo.
[0104] The algorithm generates a set of non-dominated solutions, each representing a traffic scheduling strategy (such as a signal timing scheme or lane function adjustment). The cloud agent inputs the candidate strategy into the city traffic digital twin model to simulate the evolution of traffic state in the next 30 minutes. By comparing key indicators (average speed, queue length, emergency vehicle response time) under different strategies, the strategy that minimizes average delay and optimizes energy consumption is selected. Finally, the simulation results are fed back to the NSGA-II algorithm to update the population parameters, forming a closed-loop control of data collection → strategy optimization → simulation verification → parameter update. For example, during the morning rush hour, the system automatically identifies the commuter hotspots and extends the green light duration of the main road by 15%, which increases the average speed in the area by 12%.
[0105] In step S23, the cloud agent trains a spatio-temporal graph neural network (STGNN, Spatio-Temporal Graph Neural Network) in a trusted execution environment, inputs historical traffic flow, weather data, and event records, and outputs a congestion probability heat map for the next 30 minutes. Based on the heat map, the system allocates dynamic road rights to key road segments. For example, when the stadium disperses during the period (triggered by ticket data and people flow sensors), the system automatically adjusts the surrounding main roads to one-way traffic and synchronously pushes adjustment information through roadside display screens and vehicle navigation systems, which improves the dispersal efficiency by 30%.
[0106] In step S24, the cloud agent generates a differentiated path based on the vehicle type (electric vehicle or fuel vehicle) and user preference (shortest time or lowest energy consumption): for electric vehicles, the route with charging station coverage ≥80% is preferentially recommended, and the charging pile idle state is updated in real time; when multiple vehicles request the same congested road section, the cloud agent coordinates vehicle alternating traffic through a game theory model to avoid local congestion deterioration.
[0107] As an optional implementation, in step 204, the vehicle agent controls the vehicle driving by combining the obstacle information and the global traffic decision, including the following contents:
[0108] Step S31: generating a vehicle driving strategy according to the acquired obstacle information and global traffic decision by the vehicle agent;
[0109] Step S32: generating a driving control instruction according to the vehicle driving strategy, and requesting the security agent to digitally sign the driving control instruction;
[0110] Step S33: after the actuator receives the signed driving control instruction, requesting the security agent to perform signature verification;
[0111] Step S34: after the signature verification is passed, executing the driving control instruction by the actuator to control the vehicle driving.
[0112] In step S31, the vehicle agent generates a driving strategy in a trusted execution environment based on the global traffic decision issued by the cloud and the obstacle information broadcast by the roadside agent. The driving strategy includes the following contents:
[0113] 1. Dynamically adjust the congestion weight and the safety weight. Combine the global traffic decision and the obstacle information, and run a heuristic search algorithm (such as an improved A* algorithm) to dynamically adjust the weights. Among them, the congestion weight is dynamically adjusted according to the real-time flow data (such as the lane queue length provided by the RSU) to dynamically adjust the path selection tendency and preferentially select a low delay path; 2. The safety weight is combined with the historical accident database (such as the accident occurrence rate of a certain intersection in the past 30 days) to increase the penalty factor for high-risk areas, so that the path avoids accident-prone points.
[0114] 2. Optimal avoidance strategy. Based on Bayesian network and Monte Carlo tree search, the behavior of surrounding vehicles is predicted to generate a safe trajectory. For example, in the vehicle cut-in scenario, the acceleration and steering intention of adjacent vehicles are obtained through V2V communication to calculate the optimal avoidance strategy.
[0115] 3. Energy consumption optimization. A reinforcement learning model is used to optimize the vehicle acceleration and deceleration strategy according to the road slope, signal timing and traffic flow to reduce energy consumption.
[0116] The training data of each model is stored in the trusted execution environment in an encrypted manner to prevent algorithm leakage.
[0117] In step S32, the decision module of the vehicle Agent generates specific control instructions (steering angle, braking force) according to the driving strategy, and requests the security Agent in the trusted execution environment to generate a digital signature. The specific process is as follows: using an elliptic curve encryption algorithm to generate a digital signature, the private key is managed by the trusted execution environment security storage module to ensure that it is not leaked. The signature content includes the instruction content, the timestamp, and the unique identifier of the vehicle to prevent the instruction from being tampered with or replayed.
[0118] In the instruction generation process, the trusted execution environment needs to verify the consistency of the current vehicle state (such as speed, position) and the instruction, if a contradiction is found (such as the instruction requires emergency braking but the sensor shows that there is no obstacle in front), the signature is refused to be generated, and a backup control strategy is started, and the security Agent is reported of the abnormality.
[0119] In step S33, the vehicle executor (such as the steering system, the braking system) receives the signed control instruction, verifies the sender's identity through the security Agent, confirms that the instruction comes from the trusted vehicle decision module, and compares the digital signature with the public key to verify the integrity of the instruction and ensure that it has not been tampered with by an intermediate person.
[0120] In step S34, the executor executes the control instruction after verification, and the trusted execution environment continuously compares the expected state with the sensor feedback during the execution process. If the deviation is too large, a backup control strategy is started. When an abnormal situation occurs, the vehicle Agent immediately reports the event details to the security Agent and generates a tamper-proof security log.
[0121] The vehicle Agent uses the QUIC protocol to transmit control instructions, which reduces the handshake delay compared to traditional TCP, and key instructions (such as emergency braking) are transmitted through a priority queue to ensure real-time end-to-end performance.
[0122] The vehicle Agent supports DSRC and C-V2X dual-mode communication, and dynamically selects the optimal channel through the trusted execution environment. The data packet format follows the SAE J2735 standard, and the payload part is encrypted using the session key managed by the trusted execution environment.
[0123] Optionally, in step 205, the rapid response in an emergency situation by the emergency Agent includes the following contents:
[0124] Step S41: acquiring and analyzing multi-modal data by the emergency Agent to determine the severity of the accident, wherein the multi-modal data comes from the vehicle Agent, the roadside Agent, and the cloud Agent;
[0125] Step S42: Start a hierarchical response according to the severity of the accident;
[0126] Step S43: Determine the corresponding processing operation in the smart contract according to the response level, and send the processing operation to the roadside Agent and the vehicle Agent.
[0127] In step S41, the emergency Agent, as the safety center of the traffic system, real-time gathers multi-modal data from vehicle Agents, roadside Agents and cloud Agents. Through multi-modal fusion detection technology, the emergency Agent simultaneously analyzes video streams (from RSU cameras), acoustic sensors (detecting collision sound waves) and V2V emergency messages to improve detection accuracy. The emergency Agent combines a Bayesian network to build an accident severity model, and according to factors such as accident scale (number of vehicles), casualty estimation, and road blockage degree, the accident is divided into three levels.
[0128] In step S42, the emergency Agent triggers the corresponding level of response strategy according to the accident severity evaluation result.
[0129] Level I response: For single vehicle failure, only push warning information to surrounding vehicle Agents, and adjust the signal timing of adjacent intersections through roadside Agents to guide traffic.
[0130] Level II response: When multiple vehicle accidents occur, local traffic control is started, police and tow truck resources are dispatched, and variable message boards are used to issue detour recommendations.
[0131] Level III response: When a major accident occurs, the highest priority response is activated, and resources from multiple departments such as medical and fire departments are linked, and traffic control is implemented on the accident road section.
[0132] In step S43, the emergency Agent detects that when the preset conditions are met (such as 5 vehicles reporting emergency stop at the same location and video stream confirming collision), the smart contract automatically executes: 1. Traffic control: freeze the upstream and downstream signal lights on the accident road section as red lights to prevent subsequent vehicles from entering; 2. Rescue dispatch: locate the nearest ambulance through the geographic information system and generate a special green wave; 3. Information broadcast: push the optimal detour path to vehicle Agents within 1 km.
[0133] In this application, multi-modal data fusion improves the accuracy of accident detection and shortens the detection delay; acoustic and visual data complement each other, which can effectively identify hidden accidents (such as night collision without light), and reduce the risk of false negatives. The execution of the smart contract in the trusted execution environment ensures that the instructions are not tampered with, preventing malicious attacks from interfering with emergency response.
[0134] Optionally, in step 205, supervising the authenticity and security of the data communication process by the security Agent includes the following:
[0135] Step S51: digitally signing the data to be sent and verifying the signature of the received data by the security Agent;
[0136] Step S52: verifying the authenticity of the vehicle identity by lightweight zero-knowledge proof;
[0137] Step S53: verifying the identity of each Agent by certificate chain and confirming trust authenticity by certificate revocation list in the synchronous blockchain;
[0138] Step S54: multi-dimensional trust scoring of data, and adding the corresponding Agent to the gray list when the trust score is lower than the preset threshold, wherein the multi-dimension includes data consistency, communication activity and historical violation record of each Agent, and the Agent in the gray list is limited in communication bandwidth.
[0139] In step S51, the security Agent acts as a digital guardian of the transportation system, building a two-way security barrier for data communication. At the data sending end, the security Agent uses the elliptic curve digital signature algorithm to sign the data to be transmitted in each Agent, combines the data hash value with the private key encryption, and generates a unique digital fingerprint. When receiving data, the security Agent verifies the signature by the corresponding public key, compares whether the data hash value matches the signature content, and if the verification fails, the data is directly discarded to prevent tampered data from entering the system. For example, the driving control instruction sent by the vehicle Agent is signed by the security Agent before transmission, and the actuator needs to verify the validity of the signature when receiving, to ensure that the instruction has not been tampered by man-in-the-middle attack.
[0140] In step S52, to resist Sybil attack (malicious node faking identity), the security Agent uses lightweight zero-knowledge proof technology to verify the authenticity of the vehicle identity. The proof process is completed in a trusted execution environment, and the vehicle does not need to expose sensitive information, but only proves to the security Agent that it is a legal vehicle through encrypted interaction. The whole verification process is time-consuming, which not only guarantees efficiency but also avoids identity information leakage. For example, a vehicle newly accessing the road network needs to complete identity verification through the zk-SNARKs protocol before communication, and the security Agent allows it to access the network only after confirming, preventing illegal vehicles from injecting false traffic data.
[0141] In step S53, the security Agent realizes cross-manufacturer and cross-regional Agent identity mutual recognition based on the X.509 certificate chain. Each Agent (vehicle, roadside, cloud, etc.) holds a digital certificate issued by an authoritative certificate authority, and the certificate chain extends from the root CA to the terminal Agent. Before communication, the security Agent verifies the certificate signature level by level to ensure that the identity of the other party is trustworthy. At the same time, by means of the block chain synchronization certificate revocation list (CRL, Certificate Revocation List), real-time invalid certificate information is obtained. For example, when the certificate of a roadside Agent is revoked due to equipment failure, the block chain immediately broadcasts this information, and other Agents synchronize the CRL through the security Agent, and subsequently refuse to communicate with the roadside Agent, avoiding the security risk caused by trusting expired nodes.
[0142] In step S54, the security Agent constructs a multi-dimensional trust score model to evaluate the trustworthiness of the Agent from three aspects, which are as follows.
[0143] Data consistency: Compare the matching degree of the vehicle Agent data and the data uploaded to the roadside Agent to determine whether the data has been tampered with during transmission.
[0144] Communication activity: Analyze the number of effective messages in a unit of time, and abnormal frequent or too little communication will reduce the score.
[0145] Historical violation records: Record behaviors such as false alarms and malicious attacks, and the more violations, the lower the score.
[0146] When the trust score of the Agent is lower than the preset threshold, the security Agent adds it to the gray list, limits the communication bandwidth, and reduces the potential threat; if the score continues to deteriorate, it is upgraded to the black list, completely isolates the Agent and triggers the hardware self-checking process, preventing malicious Agents from continuously endangering system security.
[0147] In this application, each Agent has a clear division of labor in the intelligent transportation system, cooperates with each other, and jointly guarantees the efficient and safe operation of the transportation system. The following is a description of the functions of each Agent and the trusted execution environment.
[0148] 1. Vehicle Agent: As the core of vehicle intelligent operation, it is embedded in the vehicle computing unit and runs in the trusted execution environment (TEE). In data collection, it fuses multi-source data such as GPS and lidar through Kalman filtering and deep learning model, generates high-precision environment perception results, and encrypts and detects anomalies in raw data. The decision module combines data from cloud and roadside agents, respectively uses improved A* algorithm, Bayesian network and Monte Carlo tree search, and reinforcement learning model to realize dynamic path planning, collision avoidance and energy optimization. In vehicle control, the decision instruction is verified by signature, with redundant control mechanism, and low-latency data transmission is realized through communication modules supporting DSRC and C-V2X.
[0149] 2. Roadside Agent: Deployed in road units, responsible for local traffic management. The data aggregation module uses lightweight blockchain technology to store vehicle state data, and uses Apache Kafka to standardize heterogeneous data cleaning. The local optimization module optimizes signal timing through Q-learning algorithm, dynamically adjusts lane functions using integer linear programming model, and has accident detection and response capabilities. The hardware interaction module controls the signal light through ModbusTCP protocol, uses Kubernetes to schedule edge computing resources, and ensures high-priority task execution.
[0150] 3. Cloud Agent: Manages traffic from a city-level perspective. The global scheduling module uses NSGA-II algorithm to realize multi-objective optimization, and verifies the scheduling strategy through digital twin model simulation. The congestion prediction module predicts future congestion conditions through spatio-temporal graph neural network, and then performs dynamic road right allocation. The path planning module provides personalized path recommendations based on vehicle type and user preferences, and coordinates vehicle alternating traffic based on game theory model to improve overall traffic efficiency when road congestion occurs.
[0151] 4. Security Agent: Focuses on ensuring system communication security and node trustworthiness. The communication verification module uses lightweight zero-knowledge proof technology to verify vehicle identity, uses X.509 certificate chain to realize cross-domain identity mutual recognition, and synchronizes certificate revocation list through blockchain. The trust scoring module scores nodes from data consistency, communication activity, historical violation records and other dimensions, implements dynamic isolation strategy for low-score nodes, limits their communication bandwidth or completely isolates them, and ensures safe operation of the system.
[0152] 5. Emergency Agent: mainly responsible for emergency handling in the traffic system. The accident detection module accurately judges the severity of the accident by fusing video streams, acoustic signals and V2V emergency messages, and starts a hierarchical response mechanism. The emergency protocol module realizes automatic response in the trusted execution environment through smart contracts, such as freezing the signal lights of the accident road section, dispatching rescue vehicles, pushing the detour path, etc.; at the same time, it provides a manual intervention interface to ensure that the traffic control center can intervene in the decision-making in extreme cases, guaranteeing the flexibility and reliability of emergency handling.
[0153] 6. Trusted execution environment.
[0154] (1) Hardware selection and configuration.
[0155] Vehicle side: using ARM TrustZone + SecureElement dual-chip architecture, the decision module runs in the TrustZone safe world, and the key is stored in the tamper-proof area of SecureElement.
[0156] RSU side: deploy Intel SGX Enclave, optimize the performance of the memory encryption engine (MEE), support processing 100,000 encrypted messages per second.
[0157] Cloud side: use AMD SEV encrypted virtual machines to ensure that the global scheduling model is encrypted in memory throughout.
[0158] (2) Remote authentication mechanism.
[0159] Each node sends a trusted execution environment proof (Attestation Report) to the security agent when starting, and the report includes: trusted execution environment firmware version hash value, running software measurement value, security agent verifies the authenticity of the report through the pre-set certificate chain, and refuses access to the system for nodes that do not pass authentication.
[0160] In order to realize the wide application and stable operation of intelligent transportation system, the application designs and integrates deployment strategies from three levels of vehicle adaptation, communication compatibility and function release, including the following contents.
[0161] 1. Vehicle side adaptation scheme. According to the difference between new and old car models, a hierarchical deployment strategy is provided.
[0162] Front integration: new cars are directly built-in with trusted execution environment hardware when leaving the factory, seamlessly integrating vehicle Agent function modules, and supporting OTA remote software update to ensure continuous iteration and optimization of the system.
[0163] After modification: design a lightweight external solution for stock old car models, quickly access the trusted execution environment function through a USB-shaped hardware security module, and realize multi-Agent collaboration.
[0164] 2. Hybrid communication protocol fusion mechanism.
[0165] To be compatible with multiple communication protocols such as DSRC, C-V2X, and 5G NR-V2X, a security protocol conversion middleware is designed. The middleware runs in the trusted execution environment, and through hardware-level isolation, it ensures the encryption of the entire protocol conversion process, prevents data leakage and protocol vulnerability attacks, and realizes seamless switching and secure interaction between heterogeneous communication networks.
[0166] 3. Gray release strategy.
[0167] Adopting a gray release mode to ensure system stability: new functions or algorithm optimization are first tested on a small scale in a single road unit jurisdiction, and A / B testing is used to compare the traffic optimization effects (such as traffic efficiency and accident response speed) of the new and old versions. After data verification, the coverage is gradually expanded, and finally the smooth upgrade of the city's traffic network is realized, reducing the risk of large-scale deployment.
[0168] Through the cooperation of trusted execution environment and multi-agent, the present application solves the core pain points of existing ITS systems and achieves the following technical effects:
[0169] 1. Hardware-level security protection, building a trusted computing system. The vehicle Agent, roadside Agent, and other core components are deployed in the trusted execution environment, and through hardware isolation, the code and data are protected, resisting kernel-level attacks and malicious tampering.
[0170] 2. Standardized encrypted communication, strengthening data transmission security. A unified V2X communication encryption standard is designed, combined with AES-256 data encryption, ECC digital signature, and blockchain certificate revocation mechanism, to realize end-to-end data theft prevention and tamper prevention. At the same time, the protocol conversion middleware runs in the trusted execution environment, ensuring the communication security during the switching of heterogeneous networks such as DSRC and C-V2X, effectively resisting Sybil attacks and man-in-the-middle attacks, and compared with traditional systems, the data transmission reliability is improved.
[0171] 3. Transparent decision-making model, improving system credibility. White-box models such as NSGA-II multi-objective genetic algorithm and spatiotemporal graph neural network are used, combined with digital twin simulation verification mechanism, making the global scheduling and path planning results verifiable and the process traceable, solving the trust crisis caused by traditional black-box models.
[0172] 4. Automated emergency response, shortening the event handling time. The emergency Agent is based on multi-modal data fusion detection and intelligent contract automatic execution, realizing second-level response to accidents. When an emergency is detected, the hierarchical response mechanism is automatically triggered, and compared with the traditional manual intervention mode, the emergency handling efficiency is improved.
[0173] 5. Distributed architecture optimization breaks through the performance bottleneck of computing. A distributed architecture of vehicle Agent edge perception-roadside Agent local decision-making-cloud Agent global collaboration is adopted to reduce the dependence on centralized cloud. Roadside Agent processes local data as a blockchain node, combined with Kubernetes edge resource scheduling, so that the system can support million-level vehicle concurrent access, reduce communication delay, and effectively solve the congestion problem of large-scale data processing.
[0174] 6. Heterogeneous system compatibility enhances platform scalability. Distributed data storage is achieved through lightweight blockchain technology, and Apache Kafka is used for heterogeneous data standardization processing to support seamless access of different manufacturer devices and protocols. At the same time, X.509 certificate chain and federated learning mechanism guarantee cross-domain identity mutual recognition and model collaboration, so that the system scalability is improved by more than 3 times, adapting to the evolution needs of future complex traffic networks.
[0175] Based on the same technical concept, the application provides a traffic scheduling device based on a trusted execution environment and a multi-agent system, as shown in Figure 3 The device includes:
[0176] The acquisition module 301 is configured to collect vehicle data through the vehicle Agent and send the vehicle data to the nearest roadside Agent;
[0177] The decision module 302 is configured to make local decisions on the vehicle data through the roadside Agent combined with the local traffic data perceived by the roadside Agent, to perform roadside resource scheduling and broadcast the generated obstacle information to surrounding vehicle Agents;
[0178] The generation module 303 is configured to obtain and analyze the vehicle data and obstacle information sent by the roadside Agent through the cloud Agent, and generate global traffic decisions;
[0179] The control module 304 is configured to control vehicle driving based on the obstacle information and global traffic decisions through the vehicle Agent;
[0180] The response and supervision module 305 is configured to respond quickly in an emergency through the emergency Agent, and supervise the authenticity and security of the data communication process through the security Agent;
[0181] The vehicle Agent, the roadside Agent, the cloud Agent, the emergency Agent, and the security Agent all run in a trusted execution environment.
[0182] Optionally, the decision module 302 is configured to:
[0183] obtain and store vehicle data through the roadside Agent, wherein each roadside Agent is a blockchain node;
[0184] in response to the received vehicle data and local traffic data of itself, optimizing timing control of traffic signal lights and dynamically adjusting lane functions, wherein the local traffic data comprises queue length of each lane, average waiting time of vehicles and priority of emergency vehicles;
[0185] obstacle information is generated in combination with the local traffic data, and the obstacle information is digitally signed and broadcast to surrounding vehicle agents.
[0186] Optionally, the generation module 303 is configured to:
[0187] obtain vehicle data and obstacle information sent by a roadside agent through a cloud agent;
[0188] By simulating the vehicle data and the obstacle information, the influence of different scheduling strategies on traffic is predicted, and the scheduling strategy that minimizes the average delay is adopted;
[0189] According to the preset data, the vehicle data and the obstacle information, a congestion probability heat map is generated, and dynamic road rights are allocated to key road sections according to the congestion probability heat map;
[0190] Personalized path recommendation is made in combination with vehicle types and user preferences, and a coordination strategy is generated when a road section is congested, wherein the coordination strategy is used to coordinate alternating vehicle traffic.
[0191] Optionally, the control module 304 is configured to:
[0192] A vehicle driving strategy is generated by a vehicle agent according to the obtained obstacle information and global traffic decision;
[0193] A driving control instruction is generated according to the vehicle driving strategy, and a security agent is requested to digitally sign the driving control instruction;
[0194] After the actuator receives the signed driving control instruction, the security agent is requested to perform signature verification;
[0195] After the signature verification is passed, the driving control instruction is executed by the actuator to control the vehicle driving.
[0196] Optionally, the control module 304 is specifically configured to:
[0197] Based on a preset collision avoidance model, the obstacle information is analyzed to determine an optimal avoidance strategy;
[0198] Based on the obstacle information and the global traffic decision, a heuristic search algorithm is used to adjust congestion weight and safety weight to select a low-delay path and avoid accident-prone areas;
[0199] The reinforcement learning model is used to optimize the vehicle acceleration and deceleration strategy according to the scheduled roadside resources.
[0200] Optionally, the response and supervision module 305 is configured to:
[0201] The multi-modal data from the vehicle agent, the roadside agent and the cloud agent are acquired and analyzed by the emergency agent to determine the accident severity;
[0202] The hierarchical response is started according to the accident severity;
[0203] The corresponding processing operation in the smart contract is determined according to the response level, and the processing operation is sent to the roadside agent and the vehicle agent.
[0204] Optionally, the response and supervision module 305 is configured to:
[0205] The data to be sent is digitally signed by the security agent, and the received data is signed and verified;
[0206] The authenticity of the vehicle identity is verified by the lightweight zero-knowledge proof;
[0207] The identity of each agent is verified by the certificate chain, and the trust authenticity is confirmed by the certificate revocation list in the synchronous blockchain;
[0208] The data is given a multi-dimensional trust score, and when the trust score is lower than a preset threshold, the corresponding agent is added to a gray list, wherein the multi-dimensions include the data consistency, the communication activity and the historical violation record of each agent, and the agent in the gray list is limited in communication bandwidth.
[0209] As shown in Figure 4 The embodiments of the present application provide an electronic device, which comprises a processor 401, a communication interface 402, a memory 403 and a communication bus 404, wherein the processor 401, the communication interface 402 and the memory 403 complete mutual communication through the communication bus 404.
[0210] The memory 403 is used to store a computer program.
[0211] In an embodiment of the present application, the processor 401 is used to execute the program stored in the memory 403, and realizes the traffic scheduling method based on the trusted execution environment and the multi-agent system provided by any one of the preceding method embodiments.
[0212] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement steps of the traffic scheduling method based on the trusted execution environment and the multi-agent system according to any one of the preceding method embodiments.
[0213] The apparatus embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment.
[0214] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course can also be implemented by hardware. Based on such understanding, the above technical solutions or the part that contributes to the related art can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0215] It should be understood that the terms used herein are for the purpose of describing particular example embodiments only and are not intended to be limiting. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. The terms "comprises", "comprising", "includes", "including" and "has" are inclusive and therefore specify the presence of stated features, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof. The method steps, processes, and operations described herein are not to be construed as necessarily requiring their performance in the particular order in which they are described, unless specifically identified as an order dependent step. It is also to be understood that additional or alternative steps can be employed.
[0216] The above description merely illustrates the embodiments of the present application, enabling a person skilled in the art to understand or implement the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A traffic scheduling method based on a trusted execution environment and a multi-agent system, characterized in that, The method comprises: collecting vehicle data by a vehicle agent and sending to a nearest roadside agent; making local decisions on the vehicle data by the roadside agent in combination with local traffic data perceived by itself to make roadside resource scheduling and broadcast generated obstacle information to surrounding vehicle agents; obtaining and analyzing the vehicle data and the obstacle information sent by the roadside agent by a cloud agent to generate global traffic decisions; controlling vehicle driving by the vehicle agent based on the obstacle information and the global traffic decisions; quickly responding by an emergency agent when an emergency occurs and supervising authenticity and security in the data communication process by a security agent; wherein the vehicle agent, the roadside agent, the cloud agent, the emergency agent and the security agent all run in the trusted execution environment.
2. The method of claim 1, wherein, Making local decisions on the vehicle data by the roadside agent in combination with local traffic data perceived by itself to make roadside resource scheduling and broadcast generated obstacle information to surrounding vehicle agents comprises: obtaining and storing the vehicle data by the roadside agent, wherein each roadside agent is a blockchain node; optimizing timing control of traffic signals and dynamically adjusting lane functions in response to the received vehicle data and local traffic data, wherein the local traffic data includes queue length, average waiting time and emergency vehicle priority of each lane; generating obstacle information in combination with the local traffic data, digitally signing the obstacle information and broadcasting to surrounding vehicle agents.
3. The method of claim 1, wherein, Obtaining and analyzing the vehicle data and the obstacle information sent by the roadside agent by a cloud agent to generate global traffic decisions comprises: obtaining the vehicle data and the obstacle information sent by the roadside agent by the cloud agent; predicting the impact of different scheduling strategies on traffic by simulating the vehicle data and the obstacle information, and adopting the scheduling strategy that minimizes the average delay; generating a congestion probability heat map according to preset data, the vehicle data and the obstacle information, and assigning dynamic road rights to key road sections according to the congestion probability heat map; conducting personalized path recommendation in combination with vehicle types and user preferences, and generating coordination strategies when road congestion occurs, wherein the coordination strategies are used to coordinate vehicle alternating traffic.
4. The method of claim 1, wherein, Controlling vehicle driving by the vehicle agent in combination with the obstacle information and the global traffic decisions comprises: generating a vehicle driving strategy by the vehicle agent according to the obtained obstacle information and global traffic decisions; generating driving control instructions according to the vehicle driving strategy and requesting the security agent to digitally sign the driving control instructions; after the actuator receives the signed driving control instructions, requesting the security agent to perform signature verification; After the signature verification passes, the driving control instruction is executed by the executor to control the vehicle to drive.
5. The method of claim 3, wherein, The vehicle driving strategy is generated by the vehicle Agent based on the obtained obstacle information and the global traffic decision, which includes: An optimal avoidance strategy is determined by analyzing the obstacle information based on a preset collision avoidance model; Based on the obstacle information and the global traffic decision, a heuristic search algorithm is used to adjust congestion weight and safety weight to select a low-delay path and avoid accident-prone areas; A reinforcement learning model is used to optimize vehicle acceleration and deceleration strategies based on the scheduled roadside resources.
6. The method of claim 1, wherein, The emergency Agent quickly responds to emergencies, which includes: The emergency Agent obtains and analyzes multi-modal data to determine the severity of the accident, where the multi-modal data comes from the vehicle Agent, the roadside Agent, and the cloud Agent; According to the severity of the accident, a hierarchical response is started; According to the response level, the corresponding processing operation in the smart contract is determined, and the processing operation is sent to the roadside Agent and the vehicle Agent.
7. The method of claim 1, wherein, The security Agent supervises the authenticity and security of the data communication process, which includes: The security Agent digitally signs the data to be sent and verifies the signature of the received data; The authenticity of the vehicle identity is verified by lightweight zero-knowledge proof; The identity of each Agent is verified by certificate chain, and the trust authenticity is confirmed by the certificate revocation list in the synchronous blockchain; Multi-dimensional trust scoring is performed on the data, and when the trust score is lower than the preset threshold, the corresponding Agent is added to the gray list, where the multi-dimensions include data consistency, communication activity, and historical violation records of each Agent, and the Agent in the gray list is limited in communication bandwidth.
8. A traffic scheduling apparatus based on a trusted execution environment and a multi-agent system, characterized by, The device includes: The acquisition module is used to collect vehicle data by the vehicle Agent and send it to the nearest roadside Agent; The decision module is used to make local decisions on the vehicle data by the roadside Agent combined with its own perception of local traffic data, to schedule roadside resources and broadcast the generated obstacle information to surrounding vehicle Agents; The generation module is used to obtain and analyze the vehicle data and obstacle information sent by the roadside Agent through the cloud Agent to generate a global traffic decision; The control module is used to control the vehicle driving based on the obstacle information and the global traffic decision by the vehicle Agent; The response and supervision module is used to quickly respond to emergencies by the emergency Agent, and to supervise the authenticity and security of the data communication process by the security Agent; The vehicle Agent, the roadside Agent, the cloud Agent, the emergency Agent, and the security Agent all run in the trusted execution environment.
9. An electronic device, comprising: It includes a processor, a communication interface, a memory, and a communication bus, where the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; A processor is configured to implement the method of any one of claims 1-7 when executing a program stored in a memory.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer readable storage medium and configured to implement the method of any one of claims 1-7 when executed by a processor.
Citation Information
Cited By
Vehicle driving control method and system and vehicle
CN121697654A