A roadside unit resource isolation method, device and electronic equipment

By creating security VFs and service VFs in the RSU, real-time monitoring of network interface data and dynamic adjustment of resource allocation solve the problems of resource rigidity and resource contention in existing RSU security protection schemes, realize intelligent isolation of security and service resources of the RSU, and improve the security and flexibility of the RSU.

CN121151900BActive Publication Date: 2026-02-24BEIJING INFORMATION TECH COLLEGE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511398300.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2026-02-24
Estimated Expiration
2045-09-28

AI Technical Summary

Technical Problem

Existing RSU security solutions cannot dynamically adjust resources based on real-time risks, making it difficult to distinguish between emergency events and malicious attacks. They also lack sufficient privacy protection, and NFV solutions may cause critical security functions to fail during attacks due to resource contention.

Method used

By leveraging Network Functions Virtualization (NFV) and network slicing technologies, security VFs and service VFs are created. Network interface data is monitored in real time to identify attack risk levels, and resource allocation ratios are dynamically adjusted. Unidirectional data sharing channels and physical/logical isolation policies are configured to achieve intelligent isolation between security and service resources.

Benefits of technology

It enables multi-dimensional real-time risk assessment of RSUs, dynamic resource isolation, blocking lateral penetration attacks, ensuring the failure of critical security functions, supporting elastic resource allocation, and improving the security and flexibility of RSUs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121151900B_ABST
    Figure CN121151900B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a roadside unit resource isolation method, device and electronic equipment, the method comprises the following steps: creating a security virtual function VF and a business virtual function VF in a roadside unit RSU hardware layer, dividing the infrastructure of the NFV of the RSU hardware layer into a security slice and a business slice, and reserving a minimum resource quota for the security slice; real-time monitoring of monitoring data of a RSU network interface is used to identify an attack risk level, and the resource allocation ratio of the security VF and the business VF is dynamically adjusted, metadata of the business VF is transmitted to the security VF through a unidirectional data sharing channel configured between the security VF and the business VF; and / or direct communication between the security slice and the business slice is blocked through a physical or logical isolation strategy. The attack risk level is identified by real-time monitoring of the monitoring data of the RSU network interface, and the resource allocation ratio of the security VF and the business VF is dynamically adjusted, thereby realizing roadside unit resource isolation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and particularly relates to a road side unit resource isolation method and device and electronic equipment. BACKGROUND

[0002] With the rapid development of Vehicle to Everything (V2X) and Intelligent Transportation Systems (ITS), Road Side Unit (RSU) as a key infrastructure, undertakes the core function of vehicle and road cooperative communication. However, RSU faces diversified security threats in an open network environment, such as Distributed Denial of Service (DDoS) attacks, false message injection, sensitive data leakage, and protocol vulnerability exploitation, etc. These attacks may cause traffic signal confusion, vehicle decision errors, and even safety accidents.

[0003] Traditional RSU security protection schemes mainly rely on hardware firewalls, static access control and fixed resource allocation, which have the following limitations:

[0004] Resource rigidity: Intrusion detection, data encryption and other security functions are usually deployed on dedicated hardware, which cannot dynamically adjust resources according to real-time risks, resulting in performance degradation in high load or attack scenarios;

[0005] Single detection dimension: Existing schemes are mostly based on traffic threshold or simple rule matching, which are difficult to distinguish between sudden legitimate traffic such as emergency event triggering a large number of messages in vehicle networking, or malicious attacks such as fake traffic light instructions;

[0006] Insufficient privacy protection: Vehicle networking involves a large amount of sensitive data such as vehicle location and identity information, and traditional Data Leakage Prevention (DLP) technology is difficult to adapt to the dynamic access mode changes brought by high mobility of vehicles.

[0007] Protocol security relies on manual configuration: The compliance detection of V2X communication protocols (such as DSRC, C-V2X) usually relies on pre-defined rules, which cannot identify new protocol vulnerability exploitation attacks in real time.

[0008] In recent years, Network Function Virtualization (NFV) and network slicing technology have been introduced into vehicle networking to improve the flexibility and scalability of RSU. However, existing NFV schemes still have the following problems:

[0009] Security and business resource competition: security virtual functions (VF) and business VFs share physical resources, and when an attack occurs, critical security functions may fail due to resource contention.

[0010] Risk response lag: lack of fine-grained risk assessment indicators, unable to accurately trigger dynamic resource adjustment.

[0011] Therefore, there is an urgent need for a RSU-oriented security-business resource intelligent isolation method that can:

[0012] Multi-dimensional real-time risk assessment: combining network traffic anomaly (ATRI), sensitive data access behavior (SDAD) and protocol compliance (PRE), accurately identifying attack risk levels.

[0013] Dynamic resource isolation: based on NFV and network slicing technology, providing minimum resource guarantee for security functions, while supporting elastic resource allocation.

[0014] Defense in depth architecture: through physical / logical isolation of security slices and business slices, and unidirectional data channels between VFs, blocking attack lateral penetration. SUMMARY

[0015] The embodiment of the application provides a roadside unit resource isolation method, device, electronic equipment and storage medium, which realizes RSU-oriented security-business resource intelligent isolation by monitoring the monitoring data of the RSU network interface to identify the attack risk level, and dynamically adjusting the resource allocation ratio of security VFs and business VFs.

[0016] In a first aspect, the embodiment of the application provides a roadside unit resource isolation method, which comprises:

[0017] Creating security virtual functions (VFs) and business virtual functions (VFs) on the roadside unit (RSU) hardware layer through network function virtualization (NFV) technology;

[0018] Dividing the infrastructure of the NFV of the RSU hardware layer into security slices and business slices through network slicing technology, and reserving a minimum resource quota for the security slices;

[0019] Monitoring the monitoring data of the RSU network interface in real time to identify the attack risk level R, and dynamically adjusting the resource allocation ratio of security VFs and business VFs according to the R on the basis of meeting the resource quota of the security slices and the business slices;

[0020] The monitoring data includes a network layer abnormal traffic relative intensity ratio ATRI, a sensitive data access deviation SDAD and a protocol risk exposure PRE, the ATRI is obtained by counting an abnormal data packet rate received by the RSU, the SDAD is obtained by analyzing a vehicle data access log forwarded by a data transmission layer of the RSU, and the PRE is obtained by analyzing a communication protocol header processed by the RSU through deep packet inspection (DPI); the attack risk level R is equal to α*ATRI+β*SDAD+γ*PRE, α, β and γ are weight coefficients of the ATRI, the SDAD and the PRE respectively, and α+β+γ=1;

[0021] A unidirectional data sharing channel is configured between the security VF and the service VF, and in the process of dynamically adjusting the resource allocation ratio of the security VF and the service VF, metadata of the service VF is transmitted to the security VF through the unidirectional data sharing channel; and / or direct communication is blocked between the security slice and the service slice through a physical or logical isolation strategy.

[0022] As a preferred scheme of the embodiment of the application, the resource allocation ratio of the security VF and the service VF is dynamically adjusted according to the R on the basis of meeting the resource quota of the security slice and the service slice, and specifically includes:

[0023] The resource quota of the security VF is equal to B+f(R); wherein B is an initial resource quota of the security slice and the service slice, and f(R) is a risk response function, which is used to calculate a dynamic resource increment of the security VF based on the R.

[0024] As a preferred scheme of the embodiment of the application, the method further includes: monitoring a risk mean μ, a variance σ 2 , an entropy value H(R), a CPU load and a complex attack type of the R in real time, and the method further includes calculating the entropy value of the R.

[0025] In a sliding time window T period, the R is calculated once for each received data packet or every Δt, to obtain R_t=[R1, R2,..., R N ], the risk mean μ in the time window T period and the variance

[0026]

[0027] For the R_t=[R1, R2,..., R N ], a range [0, 1] of risk values is divided into K intervals according to a fixed interval m; wherein each interval is Bink=[m×(k-1), m×k), k=1, 2,..., K, and the number of data points n in each interval is counted respectivelyi ;

[0028] Calculate the probability of data points in each interval:

[0029] Where,

[0030] Calculate the entropy value of the R

[0031] As a preferred scheme of the embodiment of the application, the method further comprises monitoring the variance σ of the R in real time 2 , calculating the R every time a data packet is received or every Δt within the sliding time window T, and adjusting the sliding time window T for obtaining the R in real time according to the variance σ of the R 2 .

[0032] As a preferred scheme of the embodiment of the application, the method comprises monitoring the variance σ of the R in real time 2 <0.1, and the CPU load is in the low load interval, a linear function f (R) = x·R is used as the risk response function, where x is a slope coefficient. linear

[0033] As a preferred scheme of the embodiment of the application, the method comprises monitoring the variance σ of the R 2 ≥0.1, and the entropy value H(R) of the R is greater than 1.5, a nonlinear function f (R) = M·(1-e nonlinear ) is used as the risk response function, where v is a growth rate coefficient, which is optimized by training based on historical data, and M is an upper limit value of the VF dynamic adjustment. -vR

[0034] As a preferred scheme of the embodiment of the application, the method comprises monitoring the CPU load of the R in real time, and if the CPU load is in the high load interval, a discretized response function f (R) = LUT[round(R·(N-1))] is used as the risk response function, where LUT is a preset resource mapping table, N is the total number of discrete levels, N-1 indicates that the levels are numbered from 0, and round() indicates rounding to the nearest integer, ensuring that the index is an integer.

[0035] f discrete (R) = LUT[round(R·(N-1))] as the risk response function, where LUT is a preset resource mapping table, N is the total number of discrete levels, N-1 indicates that the levels are numbered from 0, and round() indicates rounding to the nearest integer, ensuring that the index is an integer.

[0036] As a preferred scheme of the embodiment of the application, on the basis of meeting the resource quotas of the security slice and the service slice, the resource allocation ratio of the security VF and the service VF is dynamically adjusted according to the attack risk level R, which specifically comprises:

[0037] ​​The minimum reserved resource quota of the security slice remains unchanged; the proportion of non-reserved elastic resources occupied by the security VF and the service VF is dynamically adjusted according to the risk level; when the demand of the security VF exceeds the elastic resources of the security slice, priority is given to allocating resources from the elastic resources of the service slice.

[0038] Secondly, embodiments of the present invention provide a roadside unit resource isolation device, the device comprising a creation unit, a slicing unit, a monitoring unit, and a processing unit;

[0039] The creation unit is used to create security VF and service VF at the roadside unit (RSU) hardware layer through network function virtualization (NFV) technology.

[0040] The slicing unit is used to divide the NFV infrastructure of the RSU hardware layer into security slices and service slices through network slicing technology, and to reserve a minimum resource quota for the security slices.

[0041] The monitoring unit is used to monitor the monitoring data of the RSU network interface in real time to identify the attack risk level R. Based on the resource quota of the security slice and the service slice, it dynamically adjusts the resource allocation ratio of the security VF and the service VF according to the R.

[0042] The monitoring data includes Network Layer Abnormal Traffic Relative Strength Ratio (ATRI), Sensitive Data Access Deviation (SDAD), and Protocol Risk Exposure (PRE). ATRI is obtained by statistically analyzing the rate of abnormal data packets received by the RSU; SDAD is obtained by analyzing vehicle data access logs forwarded by the RSU data transmission layer; and PRE is obtained by parsing the communication protocol headers processed by the RSU using Deep Packet Inspection (DPI). The attack risk level R = α*ATRI + β*SDAD + γ*PRE, where α, β, and γ are the weighting coefficients of ATRI, SDAD, and PRE, respectively, and α + β + γ = 1.

[0043] The processing unit is configured to configure a one-way data sharing channel between the security VF and the service VF, and during the process of dynamically adjusting the resource allocation ratio between the security VF and the service VF, the metadata of the service VF is transmitted to the security VF through the one-way data sharing channel, and / or the security slice and the service slice block direct communication through physical or logical isolation strategies.

[0044] Thirdly, embodiments of the present invention provide an electronic device, including: a memory, a processor, and a communication interface; wherein, the memory stores executable code, and when the executable code is executed by the processor, the processor can at least implement the roadside unit resource isolation method as described in the first aspect.

[0045] Fourthly, embodiments of the present invention provide a non-transitory machine-readable storage medium storing executable code, which, when executed by a processor of an electronic device, enables the processor to at least implement the roadside unit resource isolation method as described in the first aspect.

[0046] In the solution provided by this invention, the attack risk level is identified by real-time monitoring of the Network Layer Abnormal Traffic Relative Strength Ratio (ATRI), Sensitive Data Access Deviation (SDAD), and Protocol Risk Exposure (PRE) of the RSU network interface. The resource allocation ratio between the security VF and the service VF is dynamically adjusted according to the attack risk level. Based on the unidirectional data sharing channel configured between the security VF and the service VF, the metadata of the service VF is transmitted to the security VF through the unidirectional data sharing channel. And / or direct communication between the security slice and the service slice is blocked through physical or logical isolation strategies, thereby realizing intelligent isolation of security and service resources for RSU. Attached Figure Description

[0047] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 This is a schematic diagram of a vehicle-to-everything (V2X) architecture for roadside unit resource isolation applications provided in an embodiment of the present invention.

[0049] Figure 2 This is a schematic diagram illustrating the execution of the roadside unit resource isolation method provided in an embodiment of the present invention;

[0050] Figure 3 This is a schematic diagram illustrating another execution process of the roadside unit resource isolation method provided in an embodiment of the present invention;

[0051] Figure 4 This is a schematic diagram of the roadside unit resource isolation device provided in an embodiment of the present invention;

[0052] Figure 5 To and Figure 4 The illustrated embodiment provides a schematic diagram of the electronic equipment corresponding to the roadside unit resource isolation device. Detailed Implementation

[0053] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0054] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “a,” “the,” and “the” used in the embodiments of this invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. “Multiple” generally includes at least two, but does not exclude the inclusion of at least one.

[0055] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0056] Depending on the context, the words “if” or “suppose” as used here can be interpreted as “when” or “in response to determination” or “in response to detection.” Similarly, depending on the context, the phrases “if determination” or “if detection (of the stated condition or event)” can be interpreted as “when determination” or “in response to determination” or “when detection (of the stated condition or event)” or “in response to detection (of the stated condition or event).”

[0057] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a product or system comprising a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a product or system. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the product or system that includes said element.

[0058] Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0059] The roadside unit resource isolation method provided in this embodiment of the invention can be executed by an electronic device, which can be a terminal device such as a PC, laptop, or smartphone, or a server. The server can be a physical server containing an independent host, a virtual server, a cloud server, or a server cluster.

[0060] Combination Figure 1 The aforementioned vehicle-to-everything (V2X) architecture, and Figure 2 This is a flowchart of a roadside unit resource isolation method provided by an embodiment of the present invention. The method of this proposal performs the following steps:

[0061] 101. Create security virtual function (VF) and service virtual function (VF) at the roadside unit (RSU) hardware layer using Network Function Virtualization (NFV) technology;

[0062] In this embodiment of the invention, the Security Virtual Function (VF) is referred to as Security VF, and the Service Virtual Function (VF) is referred to as Service VF. Security VF is responsible for intrusion detection and data encryption, while Service VF is responsible for vehicle communication and signal processing.

[0063] 102. Divide the NFV infrastructure of the RSU hardware layer into security slices and service slices using network slicing technology, and reserve minimum resource quotas for security slices.

[0064] 103. Monitor the RSU network interface data in real time to identify the attack risk level R. While meeting the resource quotas of security slices and service slices, dynamically adjust the resource allocation ratio of security VF and service VF according to the attack risk level.

[0065] The monitoring data includes Network Layer Abnormal Traffic Relative Strength Ratio (ATRI), Sensitive Data Access Deviation (SDAD), and Protocol Risk Exposure (PRE). ATRI is obtained by statistically analyzing the rate of abnormal data packets received by the RSU, SDAD is obtained by analyzing the vehicle data access logs forwarded by the RSU data transmission layer, and PRE is obtained by parsing the communication protocol header processed by the RSU through Deep Packet Inspection (DPI). The attack risk level R = α*ATRI + β*SDAD + γ*PRE, where α, β, and γ are the weighting coefficients of ATRI, SDAD, and PRE, respectively, and α + β + γ = 1.

[0066] Furthermore, in this embodiment of the invention, based on meeting the resource quotas for security slices and service slices, the resource allocation ratio between security VF and service VF is dynamically adjusted according to the attack risk level R, specifically including:

[0067] The minimum reserved resource quota for security slices remains unchanged; the ratio of non-reserved elastic resources used by security VF and business VF is dynamically adjusted according to the risk level; when the demand of security VF exceeds the elastic resources of security slices, priority is given to allocating resources from the elastic resources of business slices.

[0068] 104. Configure a one-way data sharing channel between the security VF and the service VF. During the process of dynamically adjusting the resource allocation ratio between the security VF and the service VF, the metadata of the service VF is transmitted to the security VF through the one-way data sharing channel; and / or the security slice and the service slice block direct communication through physical or logical isolation strategies.

[0069] This invention identifies attack risk levels by real-time monitoring of the Network Layer Abnormal Traffic Relative Strength Ratio (ATRI), Sensitive Data Access Deviation (SDAD), and Protocol Risk Exposure (PRE) of the RSU network interface. Based on these attack risk levels, the resource allocation ratio between the security VF and the service VF is dynamically adjusted. A one-way data sharing channel is configured between the security VF and the service VF, through which the metadata of the service VF is transmitted to the security VF. And / or direct communication between the security slice and the service slice is blocked through physical or logical isolation strategies, thus achieving intelligent isolation of security and service resources for RSU.

[0070] The roadside unit resource isolation method of one or more embodiments of the present invention will be described in detail below.

[0071] In intelligent transportation systems, roadside units (RSUs) are deployed, and NFV technology is used to create two virtual functions at the RSU hardware layer: a safety virtual function (VF) and a service virtual function (VF). Network slicing technology is used to divide the RSU infrastructure into safety slices and service slices. In this embodiment, 20% of CPU and memory resources are reserved for the safety slice, and the remaining 80% of resources are used for the service slice.

[0072] 201. Using Network Function Virtualization (NFV) technology, a security VF and a service VF are created at the roadside unit (RSU) hardware layer. The security VF is responsible for intrusion detection and data encryption, while the service VF is responsible for vehicle communication and signal processing.

[0073] 202. Divide the NFV infrastructure of the RSU hardware layer into security slices and service slices using network slicing technology, and reserve minimum resource quotas for security slices.

[0074] 203. Monitor the RSU network interface data in real time to identify the attack risk level R. Based on the resource quota of security slice and service slice, dynamically adjust the resource allocation ratio of security VF and service VF according to R. The monitoring data includes the relative strength ratio of abnormal network layer traffic (ATRI), sensitive data access deviation (SDAD), and protocol risk exposure (PRE).

[0075] Specifically, the attack risk level R = α*ATRI + β*SDAD + γ*PRE, where α, β, and γ are the weighting coefficients of ATRI, SDAD, and PRE, respectively, and α + β + γ = 1.

[0076] The process of acquiring this monitoring data is described in detail below:

[0077] 1. Relative strength ratio of abnormal network layer traffic to ATRI

[0078] ATRI is calculated by statistically analyzing the abnormal data packet rate received by the RSU. Specifically, the traffic monitoring module of the RSU network interface, such as NetFlow / sFlow data acquisition, obtains the data packet rate. The average data packet reception rate over the past 24 hours is 1000pps (packets / second), with a standard deviation of 50pps. In the current detection window, such as within 5 minutes, if a burst of traffic lasting 30 seconds occurs with an average rate of 1300pps, exceeding the mean by 6 standard deviations, it indicates an anomaly.

[0079] Calculate abnormal traffic: Number of abnormal packets = (1300 - 1000) × 30 seconds = 9000 packets; Total number of packets = 1300 × 30 = 39000 packets; ATRI = Number of abnormal packets / Total number of packets = 9000 / 39000 ≈ 0.23

[0080] In this embodiment of the invention, considering the characteristics of SYN flooding, such as an attack probability weight of 1.3, the final ATRI = 0.23 × 1.3 ≈ 0.3.

[0081] SYN flooding is a typical DDoS attack method. Attackers send a large number of TCP SYN packets with spoofed source IPs but do not complete the three-way handshake, causing the server to maintain a large number of half-open connections, exhausting resources and unable to respond to normal requests. It is characterized by an abnormally high SYN packet rate (e.g., 100 packets / second normally → 10,000 packets / second during an attack), a significantly decreased SYN / ACK packet response ratio (normally close to 1:1, but may be lower than 1:10 during an attack), and abnormal source IP distribution (spoofed IPs cause no real host to respond with an ACK).

[0082] In ATRI calculations, this embodiment of the invention uses historical attack data to train and derive a risk amplification coefficient, which is used to quantify the specific threat level of SYN flooding. The logic is as follows:

[0083] Baseline weight: The baseline weight for normal traffic anomalies (such as sudden bursts of legitimate traffic) is 1.0.

[0084] The weight adjustment and threat escalation are triggered when any of the following characteristics are detected: SYN packet percentage > 70% of total traffic (this example uses <30% as a normal example), number of half-open connections exceeds the threshold (e.g., > 5000), or source IP entropy value is higher than the preset value (randomness caused by spoofed IPs).

[0085] The logistic regression model shows that the risk probability of the SYN flooding scenario is 1.3 times that of the ordinary anomaly, and thus the final weight is obtained as: base weight × (1 + 0.3 × sigmoid (attack feature confidence)).

[0086] 2. Sensitive Data Access Deviation (SDAD)

[0087] The SDAD is obtained by analyzing the vehicle data access logs forwarded by the RSU data transmission layer. Specifically, the vehicle data access logs forwarded by the RSU data transmission layer can be Apache Kafka or MQTT broker logs.

[0088] The normal access mode is as follows: the vehicle OBU requests the traffic light status and the vehicle location update interval within the geofence once every 5 seconds on average.

[0089] Abnormal behavior detection includes: a fake OBU (ID=XYZ) making 50 requests for traffic light status within 10 seconds (e.g., 5 times / second, a deviation of 25 times), or the same OBU attempting to access camera data in an unrelated area.

[0090] In basic statistics, statistics for a single anomaly type are usually used, such as only calculating the number of abnormal accesses, obtaining the sensitive data access frequency Nsens and the baseline access frequency Nnorm from real-time audit log analysis; SDAD = Nsens / Nnorm. However, in actual engineering applications, this single-dimensional statistical method cannot integrate multi-dimensional features. Therefore, this embodiment of the invention adopts a method that considers both frequency and permissions to calculate the sensitive data access deviation SDAD.

[0091] First, calculate the frequency deviation.

[0092] Frequency deviation = (current frequency - baseline frequency) / baseline frequency, which represents the degree of abnormality in the quantitative access frequency. The baseline frequency is obtained from historical data statistics, and the current frequency is obtained from the number of requests made by the attacker's OBU within a certain period of time. The larger the frequency deviation value, the more the behavior deviates from the normal pattern.

[0093] For example, baseline frequency: a normal vehicle's OBU requests traffic light status an average of once every 5 seconds → 0.2 times / second; current frequency: an attacker's OBU requests 50 times in 10 seconds → 5 times / second.

[0094] Therefore, the frequency deviation = (5-0.2) / 0.2 = 24, which means that the current request frequency is 25 times (24+1) times the normal value, which is very likely to be malicious data scraping.

[0095] Then, mark the permission deviation.

[0096] Permission deviation is represented by a Boolean value of 0 or 1, where 1 indicates unauthorized access and 0 indicates no unauthorized access, marking whether unauthorized data / services have been accessed.

[0097] The vehicle's OBU can only access the traffic light status of its own lane, which indicates normal permissions; if the OBU is detected attempting to access camera data in an adjacent area → unauthorized access, it is considered abnormal behavior; at this point, the permission deviation = 1, indicating unauthorized access.

[0098] Finally, weighted standardization is performed.

[0099] In this embodiment of the invention, machine learning training is used to obtain the weight coefficients of frequency deviation and permission deviation. These weight coefficients represent the proportion of contribution of frequency and permission to the overall risk.

[0100] For example, if the frequency deviation = 24, the permission deviation = 1, the frequency weight value = 0.6, and the permission weight value = 0.4, then the weighted value = 24 × 0.6 + 1 × 0.4 = 14.8;

[0101] This invention provides a method for standardizing weighted values ​​to the range of [0,1]. Assuming the historical maximum deviation is 37, the weighted values ​​are scaled using the Sigmoid function or the maximum and minimum values ​​to obtain the standardized value, i.e., SDAD = 14.8 / 37 ≈ 0.4.

[0102] Specifically, the weighted value is calculated as follows: Weighted Value = (Frequency Deviation × W1 + Permission Deviation × W2), where frequency deviation quantifies the degree of deviation between the current access frequency and the historical normal baseline, reflecting the suddenness of the behavior. Permission deviation indicates whether unauthorized access has occurred, reflecting a permission violation (Boolean value: 0 or 1). The judgment logic is: 0: No access to unauthorized resources; 1: Access to unauthorized data / services. The weighting coefficients (W1, W2) are used to balance the contribution ratio of frequency and permission to the overall risk, satisfying W1 + W2 = 1. The standardized value is calculated as: Weighted Value / Historical Maximum Deviation Value. The purpose of standardization is to map the weighted sum to the [0,1] interval, facilitating unified risk assessment.

[0103] This invention captures brute-force scanning or data theft behavior by frequency deviation, such as frequently requesting traffic light status to infer traffic control patterns. High multiple deviation directly reflects the attack intensity. Lateral penetration behavior is identified by permission deviation, such as jumping from traffic light access to camera control. Boolean value design simplifies the judgment logic of permission violation.

[0104] 3. Agreement Risk Exposure PRE

[0105] The PRE is obtained by parsing the communication protocol header of RSU processing through Deep Packet Inspection (DPI). Specifically, it uses a Deep Packet Inspection (DPI) engine, such as Suricata / Snort, to check protocol compliance: using the normal V2X message format: the DSRC protocol header should contain a valid MessageID (0x01-0xFF) and TTL=3.

[0106] In practice, a MessageID of 0x00 indicates that an abnormal protocol header has been detected. 0x00 is a reserved field that attackers may use to probe for vulnerabilities. A TTL of 0 indicates that the packet has medium risk and may be a route spoofing attack.

[0107] The risk value calculation process is as follows:

[0108] Input total data packets: 60,000 (within the detection time window). 150 abnormal protocol packets with MessageID=0x00 were found, and 40 packets had TTL=0. The weight of MessageID=0x00 was set to 80, and the weight of TTL=0 was set to 20. Therefore, PRE = (150×80 + 40×20) / 60,000 = 0.2

[0109] In practice, MessageID and TTL pose different threats and have different attack costs. For example, an abnormal MessageID can cause RSU to crash, while an abnormal TTL only manifests as routing anomalies. It is clear that an abnormal MessageID is more harmful than an abnormal TTL. Forging MessageID=0x00 requires protocol reverse engineering capabilities, which is the work of highly skilled attackers, while modifying TTL=0 only requires simple tools, which is the work of low-skilled attackers. Therefore, simply looking at the percentage of abnormal packets will underestimate the risk. This embodiment of the invention amplifies the impact of high-risk behaviors through weighting. For example, a high-risk weight of 80 amplifies the impact by 50 times, and a medium-risk weight of 20 amplifies the impact by 20 times.

[0110] In summary, in this embodiment of the invention, RSU network interface data is monitored in real time, and the relative strength ratio of abnormal network layer traffic (ATRI) is calculated to be 0.3, sensitive data access deviation (SDAD) to be 0.4, and protocol risk exposure (PRE) to be 0.2. Weighting coefficients are set to α = 0.5, β = 0.3, and γ = 0.2. Considering the real-time requirements, compliance requirements, and protocol stability characteristics of the Internet of Vehicles (IoV), this embodiment assigns the highest weight α = 0.5, considering that ATRI can detect millisecond-level attacks the fastest. SDAD involves regulations such as GDPR, requiring a higher weight β = 0.3. PRE is typically a secondary risk, with γ = 0.2. The calculated attack risk level R = 0.5 × 0.3 + 0.3 × 0.4 + 0.2 × 0.2 = 0.31. Thus, the resource allocation ratio is dynamically adjusted based on the R value, increasing the security VF resource to 25%, while configuring a unidirectional data channel so that service VF metadata can only be transmitted to the security VF. A VLAN isolation strategy is used between the security slice and the service slice to block direct communication.

[0111] In step 203, in addition to satisfying the resource quotas of the security slice and the service slice, this embodiment of the invention also provides a method for dynamically adjusting the resource allocation ratio of the security VF and the service VF according to the risk level R. The security VF resource quota = B + f(R), where B is the initial resource quota of the security slice and the service slice, and f(R) is a risk response function used to calculate the dynamic resource increment of the security VF based on R, and to quantify the mapping relationship between risk and resource demand.

[0112] In this embodiment of the invention, the total computing resources of the RSU hardware layer, i.e., the total CPU resources, are 10 cores; the total memory resources of the RSU hardware layer, i.e., the total memory resources, are 20GB; the minimum resources reserved for security slices, i.e., the basic security VF quota, are 20%; and resources are increased by 5% per unit of risk level, i.e., the risk response function f(R) = 5R, and the attack risk level R = 0.5 × 0.3 + 0.3 × 0.4 + 0.2 × 0.2 = 0.31, are used as an example for explanation:

[0113] Using a linear function as the risk response function, f(R) = 5R, f(R) = 5 × R = 5 × 0.31 = 1.55%, indicating that a risk level of 0.31 triggers an additional 1.55% resource requirement. The safe VF resource quota = B + f(R) = 20% + 1.55% = 21.55%.

[0114] Based on the aforementioned security VF resource quota of 21.55%, CPU and memory are allocated accordingly.

[0115] CPU allocation:

[0116] Security VF CPU core count = total CPU × quota = 10 cores × 21.55% ≈ 2.155 cores. This can be achieved by exclusively using 2 physical cores to ensure minimum performance; the remaining 0.155 cores are shared through CPU time slices, such as by using cgroup weight adjustment.

[0117] Memory allocation:

[0118] Secure VF memory = total memory × quota = 20GB × 21.55% ≈ 4.31GB. It can be implemented by statically allocating 4GB of physical memory and dynamically allocating 0.31GB through memory balloon technology.

[0119] During system execution, CPU / memory usage and risk indicators are monitored in real time. When R ≥ 0.1, f(R) = 5R is activated to allocate resources, such as allocating 1.55% of resources from the elastic resource pool of the business slice and performing expansion through the virtualization management layer to ensure that security VF resources are not preempted by business VFs and achieve isolation protection.

[0120] Furthermore, following step 203, the method further includes real-time monitoring of the variance σ of R. 2 Within the sliding time window T, R is calculated once for each data packet received or every Δt, and the sliding time window T of R is adjusted in real time based on the variance σ2 of R.

[0121] Specifically, in a risk monitoring system, the size of the sliding time window T directly affects sensitivity and stability. Sensitivity means that a smaller T can quickly detect sudden attacks; stability means that a larger T can smooth out false alarm fluctuations. Therefore, based on the risk variance σ... 2 T is dynamically adjusted to achieve precise balance.

[0122] Example: Current window T = 60s, risk sequence R_t = [0.28, 0.29, ..., 0.33] (60 points), risk variance σ 2 =[(0.28-0.31) 2 +(0.29-0.31) 2 +……+(0.33-0.31) 2 ] / 60=0.002, σ 2 =0.002<0.05→determined as low-risk fluctuation; if the window T_new=120s is adjusted, the original 60 data points are retained, and 60 new points are added from earlier historical data, such as time t-60 to t-120. At this time, the length of the new sequence is N=120 (Δt is still 1s).

[0123] The embodiments of the present invention employ a sliding time window management mechanism to maintain time series data of a fixed length, supporting efficient updates and statistical calculations to calculate the entropy value of the risk level R.

[0124] Within a 60-second sliding window, the risk level R is collected every second to obtain a sequence R_t. The mean risk is then calculated based on this sequence. Risk Variance Calculate the probability of each data point within each interval: in, Based on this, the entropy value of risk level R

[0125] Example:

[0126] Assuming that within a 60-second sliding window, the risk level R is collected every second, the sequence R_t = [0.28, 0.29, 0.30, 0.31, 0.32, 0.33, ..., 0.33] is obtained. This R_t has a total of 60 values, with an average of 0.31.

[0127] Calculate the mean risk μ = (0.28 + 0.29 + ... + 0.33) / 60 = 0.31, and calculate the variance of risk σ. 2 =[(0.28-0.31) 2 +(0.29-0.31) 2 +……+(0.33-0.31) 2 ] / 60 = 0.002

[0128] Divide [0,1] into K = 10 intervals (m = 0.1). When the range of interval 3 is [0.2, 0.3), count 18, and the example values ​​in t are 0.28, 0.29, ..., 0.29. When the range of interval 4 is [0.3, 0.4), count 42, and the example values ​​in t are 0.30, 0.31, ..., 0.33.

[0129] The probabilities of data points within each interval are: P3 = 18 / 60 = 0.3, P4 = 42 / 60 = 0.7. The entropy value of risk level R is calculated as H(R) = -(0.3*log2(0.3) + 0.7*log2(0.7)) ≈ 0.881.

[0130] This invention monitors the variance of R in real time and performs the following operations:

[0131] 1) When the variance σ of R 2 When the value is less than 0.1 and the CPU load is in a low load range, a linear function f is used. linear (R) = x·R is the risk response function, where x is the slope coefficient. The variance σ of R is... 2<0.1 indicates that the current attack risk level is fluctuating at a low risk level;

[0132] Example: Risk level sequence R_t=[0.28,0.29,0.30,0.31,0.32] (sliding window T=60s), calculate mean μ=0.30, variance σ 2 =0.002, CPU load =35%, which is below the 40% threshold, indicating low load;

[0133] Current resource allocation: Security VF: 20% (basic quota), Business VF: 80%;

[0134] At this time, condition σ is satisfied. 2 For values ​​<0.1 and CPU load <40%, enable the linear function: flinear(R)=x·R. Assume the slope coefficient x=8 obtained by regression from historical data, and take the window mean μ to obtain the current risk level R=0.30; the resource adjustment execution strategy is: safe VF resource = basic quota B + dynamic increment = 20% + 2.4% = 22.4%.

[0135] The embodiments of the present invention provide factors affecting the slope coefficient x. For example, when x = 5 and R = 0.3, the increment is 1.5%, which is suitable for a conservative strategy (resource conservation first); when x = 5 and R = 0.3, the increment is 2.4%, which is suitable for a balanced strategy (default value); when x = 10 and R = 0.3, the increment is 3.0%, which is suitable for an aggressive strategy (safety first).

[0136] When the slope x = 5, the resource adjustment range is: 5% increase in resources per unit of risk level; the response speed is relatively smooth; applicable scenarios: normal low-risk environments; the security-business balance is: biased towards business VF resource protection; the CPU load threshold is not explicitly limited.

[0137] When the slope x = 8, the resource adjustment range is: 8% increase in resources per unit of risk level; the response speed is more sensitive; applicable scenarios: low-fluctuation scenarios requiring rapid response; the security-business balance is: biased towards security VF resource preemption; the CPU load threshold must meet the requirement of CPU load < 40%.

[0138] The resource type is CPU cores, with a total of 10 cores, 2.24 cores allocated for security VF, and 7.76 cores remaining for service VF. The resource type is memory, with a total of 20GB, 4.48GB allocated for security VF, and 15.52GB remaining for service VF. At this point, the CPU allocation is: 2 dedicated physical cores + 0.24 cores dynamically shared via CPU share (cgroups). The memory allocation is: 4GB fixed memory + 0.48GB elastically allocated via memory ballooning technology.

[0139] The control flow timing provided in this embodiment of the invention includes:

[0140] During the monitoring phase (lasting 60 seconds), risk level R and CPU load are collected every second, and sliding window statistics are maintained. During the decision-making phase (at the 61st second), σ is calculated. 2 =0.002<0.1, CPU load detected = 35%<40%, activate f_linear(R)

[0141] During the execution phase, the resource manager reclaims CPU from the business VF, 0.24 cores (by adjusting the CFS scheduler weight), 0.48GB of memory (triggered Balloon Driver compression), and the security VF is expanded to 22.4%.

[0142] 2) When the variance σ of R 2 When the entropy value H(R) of R is greater than or equal to 0.1, and the complex attack type is A, a nonlinear function f is used: nonlinear (R)=M·(1-e -vR ) is the risk response function, where v is the growth rate coefficient, optimized through training with historical data, and M is the upper limit of the dynamic adjustment of the safety VF.

[0143] For example, the attack scenario trigger condition is: risk sequence R_t = [0.15, 0.38, 0.72, 0.65, 0.41] (sliding window T = 60s), statistically calculated mean μ = 0.46, variance σ 2 =0.12(σ 2 ≥0.1 indicates high-risk volatility, and the entropy value H(R) = 1.8 (H(R) > 1.5 indicates complex attack).

[0144] Attack characteristics: Slow HTTP Attack detected (such as complex attack type A); CPU load = 78% (78% > preset 40%, indicating a high load range); Current resource allocation: Security VF: 20% (basic quota), Business VF: 80%;

[0145] It can be seen that the above condition σ 2 If ≥0.1∧H(R)>1.5 and attack type A exists, enable the nonlinear function: fnonlinear(R)=M·(1-

[0146] With an upper limit of M = 30% (the system's maximum elastic resource), a growth rate of v = 3.5, and a current risk level of R = 0.46 (taking the maximum value of the window), then the dynamic increment = 30% * (1 - e^(-3.5 * 0.46)) ≈ 30% * 0.81 = 24.3%;

[0147] At this point, the new resource quota: Security VF Resources = Basic Quota + Dynamic Increment = 20% + 24.3% = 44.3%;

[0148] The new physical resource allocation method is as follows: the resource type is CPU cores, with a total of 10 cores, a security VF allocation of 4.43 cores, and a remaining service VF of 5.57 cores; the resource type is memory, with a total of 20GB, a security VF allocation of 8.86GB, and a remaining service VF of 11.14GB.

[0149] Emergency measures may include any one or more of the following: business VF degradation, shutdown of non-critical services such as log collection, limiting message rates for low-priority vehicles, security VF enhancement, enabling all DPI detection rules and / or initiating collaborative defenses, such as requesting resources from neighboring RSUs.

[0150] This invention provides a training process for the aforementioned growth rate, including: constructing a dataset and recording historical attack events: [(R=0.3, Δ=12%), (R=0.5, Δ=22%), (R=0.7, Δ=28%)], finding the optimal parameter v such that the mean square error between the predicted value f(Ri) and the actual value Δi is minimized; given a historical data pair (Ri, Δi), solving for the growth rate coefficient v such that the nonlinear function:

[0151] The best fit between f(R)=M·(1-)(M=30%) and the observed value Δi is obtained by solving the steps of the Gauss-Newton method, and the optimal parameter growth rate v=3.5 is obtained.

[0152] This embodiment of the invention monitors the CPU load of R in real time and performs the following operations:

[0153] When the CPU load is in the high load range, a discretized response function is used: f discrete (R) = LUT[round(R·(N-1))] is used as the risk response function. LUT is a preset resource mapping table, N is the total number of discrete levels, N-1 indicates that the levels are numbered starting from 0, and round() means rounding to the nearest integer to ensure that the index is an integer.

[0154] For example, the current risk level R = 0.62, the CPU load has exceeded 85% for 3 minutes (greater than the preset 40%, which is considered a high load threshold), the preset number of discrete levels N = 5, and the resource mapping table LUT = [0%, 5%, 12%, 20%, 30%];

[0155] The process of calculating the discretized response includes: mapping the continuous risk level R∈[0,1] to the discrete level k∈{0,1,...,N-1}; k=round(R·(N-1))=round(0.62×4)=2;

[0156] Based on index k=2, read the resource increment from the LUT: fdiscrete(R) = LUT[2] = 12%

[0157] Based on the basic quota of 20% fixed occupation of security VF, the following dynamic resource adjustments are made: Security VF resources = 20% + 12% = 32%; Business VF resources = 100% - 32% = 68%.

[0158] Specifically, the resource type is CPU cores, with a total of 16 cores, 5.12 cores (32%) allocated to security VF, and 10.88 cores remaining in service VF; the resource type is memory, with a total of 32GB, 10.24GB allocated to security VF, and 21.76GB remaining in service VF; the resource type is network bandwidth, with a total of 10Gbps, 3.2Gbps (hard isolation) allocated to security VF, and 6.8Gbps remaining in service VF.

[0159] In practice, CPU allocation can be achieved by directly limiting the CPU time slice of the service VF through cpu.cfs_quota_us in Linux cgroups; memory isolation can be achieved by using mlock to lock the 10.24GB physical memory of the secure VF to prevent swapping out; and network QoS can be achieved by implementing a hard bandwidth cap through TC (Traffic Control).

[0160] This invention provides a mapping table design method:

[0161] The LUT generation rules are based on historical data analysis. Specifically, they statistically analyze the (R,Δ) distribution of the past 1000 attack events and categorize them according to the quintiles of risk level.

[0162] math

[0163] \begin{cases}

[0164] \text{LUT}[0]=0\%&R\in[0.0,0.2)\\

[0165] \text{LUT}[1]=5\%&R\in[0.2,0.4)\\

[0166] \text{LUT}[2]=12\%&R\in[0.4,0.6)\\

[0167] \text{LUT}[3]=20\%&R\in[0.6,0.8)\\

[0168] \text{LUT}[4]=30\%&R\in[0.8,1.0]

[0169] \end{cases}

[0170] During security verification: Ensure that the highest-level resources do not exceed the system's elastic capacity limit.

[0171] The embodiments of the present invention also provide anomaly handling measures. When R>1.0: force k=N-1 (take the highest protection level). When the CPU load suddenly drops (e.g. from 90% to 60%), a gradual rollback mechanism is started: safe VF resources = current value × 0.9 every 5 seconds, until the base quota of 20% is returned.

[0172] Furthermore, in this embodiment of the invention, based on meeting the resource quotas for security slices and service slices, the resource allocation ratio between security VF and service VF is dynamically adjusted according to the attack risk level R, specifically including:

[0173] The minimum reserved resource quota for security slices remains unchanged; the ratio of non-reserved elastic resources used by security VF and business VF is dynamically adjusted according to the risk level; when the demand of security VF exceeds the elastic resources of security slices, priority is given to allocating resources from the elastic resources of business slices.

[0174] Example,

[0175] 1. The resource pool initialization configuration is as follows:

[0176] The resource type is CPU cores, the total resource is 16 cores, the security slice is a fixed quota of 4 cores (25%), and the business slice is a fixed quota of 8 cores (50%).

[0177] The resource type is memory, the total resource is 32GB, the security slice is a fixed quota of 8GB (25%), and the service slice is a fixed quota of 16GB (50%).

[0178] The resource type is elastic resource, the security slice is an elastic pool: 4 cores + 8GB (25%), and the business slice is an elastic pool: 4 cores + 8GB (25%).

[0179] 2. Dynamically adjust trigger scenarios

[0180] Input parameters: Current risk level R = 0.65; Security VF resource requirements: Requirements = Fixed quota + f(R) = 25% + 18% = 43%, (f(R) = 18%), Security slice elastic resource remaining: 10% (15% used);

[0181] 3. Flexible resource allocation process

[0182] Prioritize the use of security slices for elastic resource allocation: Allocated = min(18%, 25%) = 18%

[0183] CPU: 4 cores + 2.88 cores = 6.88 cores; Memory: 8GB + 5.76GB = 13.76GB

[0184] When the security slice elastic pool is exhausted (assuming the demand is 50%), business slice resources are borrowed. The borrowing ratio = 50% - 25% (fixed) - 25% (security elastic) = 0%. It should be noted that the borrowing is not triggered in this example. If the demand is 55%, then 5% needs to be borrowed.

[0185] 4. Resource Preemption Protocol

[0186] This invention provides different priority strategies in its embodiments:

[0187] Level 1: Fixed quota for security slices (25%, non-preemptible); Level 2: Elastic pool for security slices (25%, can be exclusively used by Security VF); Level 3: Elastic pool for service slices (25%, borrowable on demand).

[0188] Borrowing rules: Minimum borrowing unit: 0.5% of total resources; Maximum borrowing ratio: 50% of the business slice elastic pool (i.e., 12.5% ​​of total resources); Resource transfer must be completed within 100ms.

[0189] 204. Configure a one-way data sharing channel between the security VF and the service VF. During the process of dynamically adjusting the resource allocation ratio between the security VF and the service VF, the metadata of the service VF is transmitted to the security VF through the one-way data sharing channel; and / or the security slice and the service slice block direct communication through physical or logical isolation strategies.

[0190] The above-described solution provided in this invention identifies attack risk levels by real-time monitoring of the Network Layer Abnormal Traffic Relative Strength Ratio (ATRI), Sensitive Data Access Deviation (SDAD), and Protocol Risk Exposure (PRE) of the RSU network interface. Based on these attack risk levels, the solution dynamically adjusts the resource allocation ratio between the security VF and the service VF. Metadata from the service VF is transmitted to the security VF through a unidirectional data sharing channel configured between the security VF and the service VF. Furthermore, direct communication between the security slice and the service slice is blocked through physical or logical isolation strategies, thus achieving intelligent isolation of security and service resources for RSU.

[0191] The following describes in detail one or more embodiments of the roadside unit resource isolation device of the present invention. Those skilled in the art will understand that these devices can be configured using commercially available hardware components through the steps taught in this solution.

[0192] Figure 4 This is a schematic diagram of the structure of a roadside unit resource isolation device provided in an embodiment of the present invention, as shown below.Figure 4 As shown, the device includes: a creation unit 11, a slicing unit 12, a monitoring unit 13, and a processing unit 14;

[0193] Create Unit 11, which is used to create security VF and service VF at the roadside unit (RSU) hardware layer through Network Function Virtualization (NFV) technology;

[0194] Slicing unit 12 is used to divide the NFV infrastructure of the RSU hardware layer into security slices and service slices through network slicing technology, and to reserve minimum resource quotas for security slices.

[0195] Monitoring unit 13 is used to monitor the monitoring data of the RSU network interface in real time to identify the attack risk level R. The monitoring data includes the relative strength ratio of abnormal network layer traffic (ATRI), the sensitive data access deviation (SDAD), and the protocol risk exposure (PRE). The ATRI is obtained by statistically analyzing the rate of abnormal data packets received by the RSU, the SDAD is obtained by analyzing the vehicle data access logs forwarded by the RSU data transmission layer, and the PRE is obtained by parsing the communication protocol header processed by the RSU through deep packet inspection (DPI). The attack risk level R is defined as α*ATRI + β*SDAD + γ*PRE, where α, β, and γ are the weighting coefficients of ATRI, SDAD, and PRE, respectively, and α + β + γ = 1. Based on the resource quotas of security slices and service slices, the resource allocation ratio of security VF and service VF is dynamically adjusted according to R.

[0196] Processing unit 14 is used to configure a one-way data sharing channel between security VF and service VF, and during the process of dynamically adjusting the resource allocation ratio between security VF and service VF, the metadata of service VF is transmitted to security VF through the one-way data sharing channel, and / or direct communication between security slice and service slice is blocked through physical or logical isolation strategies.

[0197] Figure 4 The device shown can perform the steps described in the foregoing embodiments. For detailed execution process and technical effects, please refer to the description in the foregoing embodiments, which will not be repeated here.

[0198] In one possible design, the above Figure 4 The structure of the roadside unit resource isolation device shown can be implemented as an electronic device, such as... Figure 5 As shown, the electronic device may include: a memory 21, a processor 22, and a communication interface 23. The memory 21 stores executable code, which, when executed by the processor 22, enables the processor 22 to at least implement the roadside unit resource isolation method provided in the foregoing embodiments.

[0199] In addition, embodiments of the present invention provide a non-transitory machine-readable storage medium storing executable code, which, when executed by a processor of an electronic device, enables the processor to at least implement the roadside unit resource isolation method provided in the foregoing embodiments.

[0200] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separate. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0201] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of a necessary general-purpose hardware platform, or by a combination of hardware and software. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a computer product. The present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0202] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for isolating roadside unit resources, characterized in that, include: Security Virtual Functions (VFs) and Service Virtual Functions (VFs) are created at the Roadside Unit (RSU) hardware layer using Network Function Virtualization (NFV) technology. The NFV infrastructure of the RSU hardware layer is divided into security slices and service slices using network slicing technology, and a minimum resource quota is reserved for the security slices. The monitoring data of the RSU network interface is monitored in real time to identify the attack risk level R. Based on the resource quota of the security slice and the service slice, the resource allocation ratio of the security VF and the service VF is dynamically adjusted according to the R. The monitoring data includes Network Layer Abnormal Traffic Relative Strength Ratio (ATRI), Sensitive Data Access Deviation (SDAD), and Protocol Risk Exposure (PRE). ATRI is obtained by statistically analyzing the rate of abnormal data packets received by the RSU; SDAD is obtained by analyzing vehicle data access logs forwarded by the RSU data transmission layer; and PRE is obtained by parsing the communication protocol headers processed by the RSU using Deep Packet Inspection (DPI). The attack risk level R = α*ATRI + β*SDAD + γ*PRE, where α, β, and γ are the weighting coefficients of ATRI, SDAD, and PRE, respectively, and α + β + γ = 1. In the process of configuring a one-way data sharing channel between the security VF and the service VF and dynamically adjusting the resource allocation ratio between the security VF and the service VF, the metadata of the service VF is transmitted to the security VF through the one-way data sharing channel; and / or the security slice and the service slice block direct communication through physical or logical isolation strategies.

2. The method according to claim 1, characterized in that, The step of dynamically adjusting the resource allocation ratio of the security VF and the service VF according to R, based on the resource quotas of the security slice and the service slice, specifically includes: The resource quota of the security VF is B + f(R); where B is the initial resource quota of the security slice and the service slice, and f(R) is a risk response function used to calculate the dynamic resource increment of the security VF based on R.

3. The method according to claim 2, characterized in that, The method further includes: real-time monitoring of the risk mean μ and variance σ of R. 2 The method further includes calculating the entropy value of R, including entropy value H(R), CPU load, and complex attack type; Within the sliding time window T, R is calculated once for each received data packet or every Δt, resulting in R_t = [R1, R2, ..., R]. N [Obtain the mean risk μ and the variance of R within the time window T.] For the given R_t=[R1,R2,...,R N The risk value range [0,1] is divided into K intervals at fixed intervals of m; each interval is: Bink = [m×(k-1),m×k), k = 1,2,...,K. The number of data points n in each interval is counted. i ; Calculate the probability of each data point within each interval: in, Calculate the entropy value of R.

4. The method according to claim 1 or 2, characterized in that, The method also includes real-time monitoring of the variance σ of R. 2 Within the sliding time window T, R is calculated once for each received data packet or every Δt, based on the variance σ of R. 2 The sliding time window T for obtaining R is adjusted in real time.

5. The method according to claim 2, characterized in that, The method includes: Real-time monitoring of the variance σ of R 2 When the value is less than 0.1 and the CPU load is in a low load range, a linear function f is used. linear (R) = x·R is the risk response function, where x is the slope coefficient.

6. The method according to claim 3, characterized in that, The method includes: The variance σ of R 2 ≥0.1, and the entropy value H(R) of R >1.5, using a nonlinear function: f nonlinear (R)=M·(1-e -vR As the risk response function, v is the growth rate coefficient, which is optimized through training with historical data, and M is the upper limit of the dynamic adjustment of the safety VF.

7. The method according to claim 2, characterized in that, The method includes: Real-time monitoring of the CPU load of R; if the CPU load is in a high-load range, then a discretized response function is used: f discrete (R) = LUT[round(R·(N-1))] is the risk response function, where LUT is a preset resource mapping table, N is the total number of discrete levels, N-1 indicates that the levels are numbered starting from 0, and round() indicates rounding to the nearest integer to ensure that the index is an integer.

8. The method according to claim 1, characterized in that, The method of dynamically adjusting the resource allocation ratio between security VF and service VF based on the attack risk level R, while satisfying the resource quotas for security slices and service slices, specifically includes: The minimum reserved resource quota of the security slice remains unchanged; the proportion of non-reserved elastic resources occupied by the security VF and the service VF is dynamically adjusted according to the risk level; when the demand of the security VF exceeds the elastic resources of the security slice, priority is given to allocating resources from the elastic resources of the service slice.

9. A roadside unit resource isolation device, characterized in that, The device includes a creation unit, a slicing unit, a monitoring unit, and a processing unit; The creation unit is used to create security VF and service VF at the roadside unit (RSU) hardware layer through network function virtualization (NFV) technology. The slicing unit is used to divide the NFV infrastructure of the RSU hardware layer into security slices and service slices through network slicing technology, and to reserve a minimum resource quota for the security slices. The monitoring unit is used to monitor the monitoring data of the RSU network interface in real time to identify the attack risk level R. Based on the resource quota of the security slice and the service slice, it dynamically adjusts the resource allocation ratio of the security VF and the service VF according to the R. The monitoring data includes Network Layer Abnormal Traffic Relative Strength Ratio (ATRI), Sensitive Data Access Deviation (SDAD), and Protocol Risk Exposure (PRE). ATRI is obtained by statistically analyzing the rate of abnormal data packets received by the RSU; SDAD is obtained by analyzing vehicle data access logs forwarded by the RSU data transmission layer; and PRE is obtained by parsing the communication protocol headers processed by the RSU using Deep Packet Inspection (DPI). The attack risk level R = α*ATRI + β*SDAD + γ*PRE, where α, β, and γ are the weighting coefficients of ATRI, SDAD, and PRE, respectively, and α + β + γ = 1. The processing unit is configured to configure a one-way data sharing channel between the security VF and the service VF, and during the process of dynamically adjusting the resource allocation ratio between the security VF and the service VF, the metadata of the service VF is transmitted to the security VF through the one-way data sharing channel, and / or the security slice and the service slice block direct communication through physical or logical isolation strategies.

10. An electronic device, the electronic device comprising: Processor, communication interface, memory, and communication bus; The processor, the communication interface, and the memory communicate with each other through the communication bus; characterized in that the processor calls logical instructions in the memory to implement the roadside unit resource isolation method as described in any one of claims 1-8 when executing a computer program.

Citation Information

Patent Citations

  • Road traffic accident detection method and system based on roadside radar perception

    CN119091616A

  • Systems and methods for automated quantitative risk and threat calculation and remediation

    US20210266340A1