An iot security protection method and system for vehicle networking intrusion detection

By introducing a spatiotemporal consistency verification model and a dynamic threshold behavior profiling method into the vehicle-to-everything (V2X) system, and combining them with a fine-grained spatial query mechanism based on image-perceptual hashing, the problem of detecting false information injection and man-in-the-middle attacks in V2X was solved, enabling efficient identification and rapid response to complex threats.

CN121463044BActive Publication Date: 2026-03-24CHANGCHUN INST OF ELECTRONIC TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-07
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing vehicle-to-everything (V2X) security solutions lack the ability to detect and coordinate the handling of false information injection and man-in-the-middle attacks in real time. Traditional centralized intrusion detection systems suffer from single points of failure and response delays, making it difficult to cope with attacks that spread rapidly in local areas. Furthermore, they lack a cross-verification mechanism that allows vehicles to perceive their physical environment and network behavior.

Method used

By acquiring real-time data from the vehicle's internal network and external information exchange, a spatiotemporal consistency verification model and a dynamic threshold behavior profiling method are used for preliminary detection. This generates local anomaly events with confidence levels. Furthermore, an image-centric fine-grained spatial query mechanism for vehicle-to-everything (V2X) is introduced to collaborate with other vehicle nodes to verify and confirm intrusion events.

Benefits of technology

It achieves efficient identification and mitigation of false information injection and man-in-the-middle attacks, improves the detection rate of complex threats, and ensures the security and response speed of the vehicle networking system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121463044B_ABST
    Figure CN121463044B_ABST
Patent Text Reader

Abstract

The application provides an Internet of Things security protection method and system for vehicle networking intrusion detection, which preliminarily distinguishes vehicle internal network data and vehicle external information exchange data through a built-in detection system of a vehicle, generates a local abnormal event with a confidence degree, confirms the preliminary detection result through a vehicle networking area cooperation mechanism, and introduces a fine-grained space query and verification mechanism based on a vehicle captured image, so that accurate discovery and correlation of abnormal network events and physical world perception inconsistency are realized, and complex threats such as false information injection and man-in-the-middle attacks are efficiently identified and relieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Vehicles, and more particularly, to an Internet of Things security protection method and system for Internet of Vehicles intrusion detection. BACKGROUND

[0002] As the core application of Internet of Things in the field of intelligent transportation, the security of Internet of Vehicles is of vital importance. Traditional centralized intrusion detection systems have defects such as single point of failure, high response delay, and difficulty in responding to attacks rapidly spreading in local areas. Existing Internet of Vehicles security solutions focus on communication encryption and identity authentication, but lack effective real-time detection and collaborative handling capabilities for attacks that have penetrated into the network (such as "false information injection attacks" initiated by falsifying sensor data or tampering with V2X messages, and "man-in-the-middle attacks" that eavesdrop and tamper with communication links). In addition, existing technologies lack a mechanism to associate and cross-verify the physical environment perceived by vehicles (especially visual information) with network behavior, resulting in low detection rates for advanced attacks with context spoofing. SUMMARY

[0003] In view of the above problems, the purpose of the present application is to provide an Internet of Things security protection method and system for Internet of Vehicles intrusion detection, which can efficiently identify and mitigate complex threats such as false information injection and man-in-the-middle attacks.

[0004] The first aspect of the present application provides an Internet of Things security protection method for Internet of Vehicles intrusion detection, comprising:

[0005] Real-time acquisition of vehicle internal network data and vehicle-external information exchange data, preliminary detection of false information injection attacks and man-in-the-middle attacks through a spatio-temporal consistency verification model and a dynamic threshold behavior profiling method, and generation of local abnormal events with confidence;

[0006] When the confidence of the local abnormal event exceeds a first preset threshold, a vehicle-centric fine-grained spatial query mechanism is triggered: a query request containing abnormal event description and vehicle key frame image perception hash is generated, and broadcasted to other vehicle nodes in the geographic area where the abnormal event is suspected to have occurred;

[0007] Upon receiving the query request, other vehicle nodes compare and verify the information in the query request based on their own sensor data and image perception hash within the same spatio-temporal range, and return verification feedback information containing supporting, opposing, or uncertain conclusions;

[0008] The local abnormal event information and verification feedback information from other vehicle nodes are aggregated, and the comprehensive intrusion confidence of the abnormal event is determined based on the verification feedback information of the vehicle nodes;

[0009] If the comprehensive intrusion confidence exceeds a second preset threshold, an intrusion event is determined to be confirmed, a distributed security response strategy is started, and the confirmed intrusion event is uploaded to a regional cloud security center.

[0010] In the scheme, the dynamic threshold behavior portrait method specifically comprises:

[0011] Features and feature values in the vehicle internal network data are extracted, at least including current vehicle position, vehicle speed and time;

[0012] Based on the current vehicle time, historical data of a neighboring vehicle within a set first time range and set distance are obtained, and the historical data of the neighboring vehicle at least include historical position, historical speed and historical time of the neighboring vehicle;

[0013] The current vehicle position, vehicle speed and time are compared and analyzed with the historical position, historical speed and historical event of the neighboring vehicle in sequence, to obtain a consistency score value of the current vehicle and the corresponding neighboring vehicle;

[0014] After traversing all the neighboring vehicles within the set distance, a consistency score value set of the current vehicle and the neighboring vehicles is obtained;

[0015] The consistency score value in the consistency score value set of the current vehicle and the neighboring vehicles is mean calculated to obtain a consistency score average value;

[0016] If the consistency score average value is less than or equal to a preset consistency score threshold, the current vehicle is marked as a potential false information injection source.

[0017] In the scheme, the steps of the space-time consistency verification model for data processing are specifically:

[0018] According to the vehicle-to-external information exchange data, the signal strength between the vehicle node and its communication opposite end and the end-to-end communication delay are determined;

[0019] Based on a preset historical sliding time window, a historical signal strength set and an end-to-end historical communication delay set between the corresponding vehicle node and its communication opposite end are extracted;

[0020] According to the historical signal strength set and the historical communication delay set, corresponding dynamic abnormal threshold ranges are calculated respectively;

[0021] When the signal strength between the vehicle node and its communication opposite end exceeds the signal strength abnormal threshold range or the end-to-end communication delay exceeds the communication delay abnormal threshold range, it is marked that a man-in-the-middle attack exists currently.

[0022] In the scheme, the step of generating a local abnormal event with confidence specifically comprises:

[0023] If the current vehicle has a potential source of false information injection or a man-in-the-middle attack, mark the current vehicle as having a local abnormal event.

[0024] Extract the average consistency score or signal strength / communication delay;

[0025] If the current vehicle has a potential source of false information injection, the confidence level of the corresponding local abnormal event is determined based on the average consistency score, the preset consistency score threshold, and the corresponding preset mapping benchmark value.

[0026] If the current vehicle is subject to a potential man-in-the-middle attack, the confidence level of the corresponding local abnormal event is determined based on the signal strength / communication delay, the abnormal threshold range of signal strength / communication delay, and the corresponding preset mapping benchmark value.

[0027] In this solution, the image-centric vehicle-to-everything (V2X) fine-grained spatial query mechanism specifically includes the generation and broadcasting of query requests as follows:

[0028] Based on the time of the query, extract the key frame images captured by the current vehicle camera within the set second time window;

[0029] The keyframe image is converted into a fixed-length perceptual hash value H; the query request includes at least: the type of abnormal event, the suspected geographical coordinates and time range of the occurrence, and the perceptual hash value;

[0030] Based on the vehicle network to which the current vehicle has joined, the query request is broadcast to all vehicle nodes within a preset query radius centered on the suspected geographical coordinates.

[0031] In this scheme, the preset query radius is dynamically adjusted based on the vehicle's speed: when the vehicle's speed is greater than 60 km / h, the query radius is 300 to 500 meters; when the speed is less than or equal to 60 km / h, the query radius is 100 to 300 meters, to ensure that vehicle nodes within the broadcast range intersect with abnormal events in time and space.

[0032] In this solution, the step of obtaining the verification feedback information specifically includes:

[0033] The vehicle node k that receives the query request retrieves the perception hash value recorded by the corresponding vehicle node within the time range and geographical coordinates specified in the query request. and sensor data;

[0034] Perceive hash value Comparative analysis with H yields perceptual similarity values;

[0035] Based on the degree of consistency between the perceived similarity value and the description of the abnormal event using its own sensor data, a verification conclusion is generated.

[0036] The verification conclusion, together with the calculated perceptual similarity value and the sensor data itself, constitutes the verification feedback information.

[0037] In this solution, the step of generating a verification conclusion based on the degree of conformity between the perceived similarity value and the description of the abnormal event using its own sensor data specifically includes:

[0038] Extract vehicle position, speed, and time from its own sensor data;

[0039] Extract vehicle location, speed, and time from the description of the abnormal event;

[0040] The vehicle position in its own sensor data is compared and analyzed with the vehicle position in the abnormal event description, the vehicle speed in its own sensor data is compared with the vehicle speed in the abnormal event description, and the time in its own sensor data is compared with the time in the abnormal event description. The results are then calculated to obtain the degree of conformity.

[0041] Based on perceived similarity and degree of conformity, the state of the verification conclusion is determined, and the state of the verification conclusion includes support, opposition, and uncertainty.

[0042] In this solution, after broadcasting to other vehicle nodes within the geographical area where the abnormal event is suspected to have occurred, the solution further includes:

[0043] If no verifiable messages from nearby vehicles are received within a preset time period, the vehicle will automatically enter "island mode".

[0044] Based on the "island mode", obtain the traffic environment model of the current geographical location and the current vehicle driving direction;

[0045] Based on the traffic environment model of the current geographical location and the current vehicle driving direction, a set of visualized scene images is estimated;

[0046] The visualized scene images in the estimated set of visualized scene images are compared and analyzed with the key frame images captured by the current vehicle camera to determine the scene deviation index.

[0047] Assess the level of security threat currently faced by the vehicle based on the scenario deviation index;

[0048] If the current security threat level faced by the vehicle exceeds the preset security threat level threshold, a security warning message will be triggered and the high-risk time will be reported through vehicle-to-infrastructure communication.

[0049] A second aspect of the present invention provides an Internet of Things (IoT) security protection system for vehicle network intrusion detection, including a memory and a processor, wherein the memory stores a program for an IoT security protection method for vehicle network intrusion detection as described in any of the preceding claims.

[0050] This invention provides an IoT security protection method and system for vehicle-to-everything (V2X) intrusion detection. Through the vehicle's built-in detection system, it initially identifies internal network data and external information exchange data, generating local anomaly events with confidence levels. Then, it confirms the initial detection results through a V2X regional collaborative mechanism and introduces a fine-grained spatial query and verification mechanism based on vehicle-captured images. This enables accurate discovery and correlation of inconsistencies between abnormal network events and physical world perception, thereby efficiently identifying and mitigating complex threats such as false information injection and man-in-the-middle attacks. Attached Figure Description

[0051] Figure 1 A flowchart of an IoT security protection method for vehicle network intrusion detection according to the present invention is shown;

[0052] Figure 2 The flowchart of the data processing steps of the spatiotemporal consistency verification model of the present invention is shown;

[0053] Figure 3 A block diagram of an Internet of Things (IoT) security protection system for vehicle network intrusion detection according to the present invention is shown. Detailed Implementation

[0054] To better understand the above-mentioned objectives, features, and advantages of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be combined with each other.

[0055] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and therefore the scope of protection of the invention is not limited to the specific embodiments disclosed below.

[0056] Figure 1 A flowchart of an IoT security protection method for vehicle network intrusion detection according to the present invention is shown.

[0057] like Figure 1 As shown, this invention discloses an IoT security protection method for vehicle network intrusion detection, comprising:

[0058] S101 acquires real-time data from the vehicle's internal network and the vehicle's external information exchange data. Through a spatiotemporal consistency verification model and a dynamic threshold behavior profiling method, it performs preliminary detection of false information injection attacks and man-in-the-middle attacks, and generates local abnormal events with confidence levels.

[0059] S102, when the confidence level of the local abnormal event exceeds the first preset threshold, a fine-grained spatial query mechanism for the vehicle network centered on the image is triggered: a query request containing a description of the abnormal event and the perception hash of the key frame image of the vehicle is generated and broadcast to other vehicle nodes in the geographical area where the abnormal event is suspected to have occurred.

[0060] S103, other vehicle nodes that receive the query request compare and verify the information in the query request based on their own sensor data and image perception hash within the same spatiotemporal range, and return verification feedback information containing supporting, opposing, or uncertain conclusions.

[0061] S104, Gather the local abnormal event information and the verification feedback information from other vehicle nodes, and determine the comprehensive intrusion confidence of the abnormal event based on the verification feedback information of the vehicle nodes;

[0062] S105, if the overall intrusion confidence level exceeds the second preset threshold, it is determined to be an intrusion event, the distributed security response strategy is activated, and the confirmed intrusion event is uploaded to the regional cloud security center.

[0063] According to embodiments of the present invention, both the spatiotemporal consistency verification model and the dynamic threshold behavior profiling method are set within the vehicle system. That is, after acquiring internal vehicle network data and vehicle-to-external information exchange data, a preliminary judgment is immediately made, solving the problems of low latency and limited bandwidth in vehicle-to-everything (V2X) networks. The spatiotemporal consistency verification model utilizes the strong inertia of vehicle physical movement; for example, if the vehicle in front brakes suddenly, the vehicle behind will inevitably slow down or maintain a safe distance. False information is detected by comparing logical contradictions. The dynamic threshold behavior profiling focuses on microscopic anomalies in the communication channel itself. These anomalies are often difficult to completely conceal when a man-in-the-middle attack inserts a proxy node. The distributed security response strategy includes rapidly disseminating alerts within the corresponding V2X network via a lightweight protocol, enabling vehicles in the affected area to immediately take evasive actions, such as rerouting or ignoring malicious information. Simultaneously, isolation software is configured to softly isolate malicious sources.

[0064] It should be noted that, assuming an intruder injects false "accident ahead" information into an intersection area, vehicle A receives the message, but its own camera does not capture the accident, and the radar monitoring of the traffic ahead does not show any signs of slowing down. Vehicle A's built-in preliminary detection system, based on construction consistency checks, determines that the message is highly suspicious and constitutes false information injection. Vehicle A generates a query request, including the accident location, timestamp, and the hash value of an image of a "no accident" scene at that location captured by its camera, and broadcasts it to vehicles around the intersection. Vehicles B, C, and D within a defined area of ​​the intersection receive the request. B and C retrieve images from similar times, calculate their hash values, find them highly similar to the hash value provided by A, and confirm that their own sensors show no abnormalities. Therefore, they provide feedback indicating that the corresponding information is false information injection. Vehicle D, whose view was obstructed by a large vehicle, provides feedback indicating uncertainty. The overall intrusion confidence is then calculated based on the feedback from vehicles B, C, and D. If the overall intrusion confidence exceeds a second preset threshold, the intrusion event is determined to be a false "accident ahead" information injection.

[0065] According to an embodiment of the present invention, the dynamic threshold behavior profiling method specifically includes:

[0066] Extract features and feature values ​​from the vehicle's internal network data, including at least the current vehicle position, speed, and time.

[0067] Based on the current vehicle time, acquire historical data of neighboring vehicles within a set distance and a first time range. The historical data of the neighboring vehicles includes at least the historical location, historical speed and historical time of the neighboring vehicles.

[0068] The current vehicle's location, speed, and time are compared with the historical locations, speeds, and events of neighboring vehicles to obtain a consistency score between the current vehicle and its corresponding neighboring vehicles.

[0069] After traversing all neighboring vehicles within a set distance, a set of consistency scores between the current vehicle and its neighboring vehicles is obtained.

[0070] The average consistency score is calculated by averaging the consistency scores of the current vehicle and its neighboring vehicles.

[0071] If the average consistency score is less than or equal to the preset consistency score threshold, the current vehicle is marked as a potential source of false information injection.

[0072] It should be noted that the internal network data of the current vehicle i is set to... ,in Indicates the current position of vehicle i. This represents the current speed of vehicle i. This indicates the time when the internal network data of vehicle i is acquired; the historical data of neighboring vehicle j is set as... Set the consistency score between the current vehicle i and its neighboring vehicle j to 1. Its formula is ;in This represents the velocity projection function based on maximum acceleration. , This represents the maximum acceleration of vehicle j; , This represents the corresponding weight coefficient; when the average consistency score is less than or equal to the preset consistency score threshold, it indicates that the behavior of the corresponding vehicle is inconsistent with the behavior of most vehicles around it, and the corresponding vehicle is set as a potential source of false information injection.

[0073] Figure 2 The flowchart of the data processing steps of the spatiotemporal consistency verification model of the present invention is shown.

[0074] According to embodiments of the present invention, such as Figure 2 As shown, the spatiotemporal consistency verification model performs the following data processing steps:

[0075] S201, Based on the information exchange data between the vehicle and the outside world, determine the signal strength and end-to-end communication delay between the vehicle node and its communication peer;

[0076] S202, Based on a preset historical sliding time window, extract the historical signal strength set and the end-to-end historical communication delay set between the corresponding vehicle node and its communication peer;

[0077] S203, Calculate the corresponding dynamic anomaly threshold range based on the historical signal strength set and the historical communication delay set respectively;

[0078] S204. When the signal strength between a vehicle node and its communication peer exceeds the abnormal signal strength threshold or the end-to-end communication delay exceeds the abnormal communication delay threshold, a man-in-the-middle attack is detected.

[0079] It should be noted that, based on the historical signal strength set and the historical communication delay set, the moving average of the corresponding historical signal strength set and historical communication delay set is calculated. and moving standard deviation The corresponding dynamic anomaly threshold range is set to... , ,in and This is an adjustable coefficient; when the signal strength between the vehicle node and its communication peer exceeds... The range, or the vehicle-to-end communication delay, exceeds... If the scope is unclear, a man-in-the-middle attack is suspected, and the characteristics of this abnormal behavior are recorded to build an attacker profile.

[0080] According to an embodiment of the present invention, the step of generating a local anomaly event with confidence level specifically includes:

[0081] If the current vehicle has a potential source of false information injection or a man-in-the-middle attack, mark the current vehicle as having a local abnormal event.

[0082] Extract the average consistency score or signal strength / communication delay;

[0083] If the current vehicle has a potential source of false information injection, the confidence level of the corresponding local abnormal event is determined based on the average consistency score, the preset consistency score threshold, and the corresponding preset mapping benchmark value.

[0084] If the current vehicle is subject to a potential man-in-the-middle attack, the confidence level of the corresponding local abnormal event is determined based on the signal strength / communication delay, the abnormal threshold range of signal strength / communication delay, and the corresponding preset mapping benchmark value.

[0085] It should be noted that the consistency score difference is obtained by subtracting the average consistency score from the preset consistency score threshold. When the consistency score difference exceeds the corresponding preset mapping benchmark value, the confidence level of the corresponding local anomaly event is 1. When the consistency score difference is less than the corresponding preset mapping benchmark value, the consistency score difference is divided by the corresponding preset mapping benchmark value to obtain the confidence level of the corresponding local anomaly event. If the current vehicle is under potential man-in-the-middle attack, when the signal strength exceeds the signal strength anomaly threshold range, the signal strength difference is calculated. If the signal strength difference is greater than or equal to the corresponding preset mapping benchmark value, the confidence level of the corresponding signal strength is set to 1. If the difference is less than the corresponding preset mapping benchmark value, the confidence level of the corresponding signal strength is equal to the signal strength difference divided by the corresponding preset mapping benchmark value. When the communication delay exceeds the communication delay anomaly threshold, the communication delay difference is calculated. If the communication delay difference is greater than or equal to the corresponding preset mapping benchmark value, the confidence level of the corresponding communication delay is set to 1. If the communication delay difference is less than the corresponding preset mapping benchmark value, the confidence level of the corresponding communication delay is equal to the communication delay difference divided by the corresponding preset mapping benchmark value. Then, the confidence level of the communication delay is multiplied by the corresponding weight coefficient, and the confidence level of the signal strength is multiplied by the corresponding weight coefficient. The results are accumulated to obtain the confidence level of the local anomaly event.

[0086] It should be noted that when the communication delay is less than the minimum value in the communication delay abnormal threshold range, the minimum value in the communication delay abnormal threshold range is subtracted from the communication delay, and then the corresponding value is obtained. When the communication delay is greater than the maximum value in the communication delay abnormal threshold range, the communication delay is subtracted from the maximum value in the communication delay abnormal threshold range, and the corresponding communication delay difference is obtained. Similarly, the signal strength difference can be obtained.

[0087] According to an embodiment of the present invention, the image-centric vehicle-to-everything (V2X) fine-grained spatial query mechanism specifically includes the generation and broadcasting of query requests as follows:

[0088] Based on the time of the query, extract the key frame images captured by the current vehicle camera within the set second time window;

[0089] The keyframe image is converted into a fixed-length perceptual hash value H; the query request includes at least: the type of abnormal event, the suspected geographical coordinates and time range of the occurrence, and the perceptual hash value;

[0090] Based on the vehicle network to which the current vehicle has joined, the query request is broadcast to all vehicle nodes within a preset query radius centered on the suspected geographical coordinates.

[0091] It should be noted that the abnormal event types include at least the injection of false information and man-in-the-middle attacks; for example, if the preset query radius is 100 meters, the suspected geographical coordinates are the geographical coordinates of the vehicle's location when the local abnormal event is triggered, which are used to obtain data from the vehicle's internal network or the vehicle's exchange of information with the outside world.

[0092] According to an embodiment of the present invention, the preset query radius is dynamically adjusted based on the vehicle speed: when the vehicle speed is greater than 60 km / h, the query radius is 300 to 500 meters; when the speed is less than or equal to 60 km / h, the query radius is 100 to 300 meters, so as to ensure that the vehicle nodes within the broadcast range have an intersection with the abnormal event in time and space.

[0093] According to an embodiment of the present invention, the step of obtaining the verification feedback information specifically includes:

[0094] The vehicle node k that receives the query request retrieves the perception hash value recorded by the corresponding vehicle node within the time range and geographical coordinates specified in the query request. and sensor data;

[0095] Perceive hash value Comparative analysis with H yields perceptual similarity values;

[0096] Based on the degree of consistency between the perceived similarity value and the description of the abnormal event using its own sensor data, a verification conclusion is generated.

[0097] The verification conclusion, together with the calculated perceptual similarity value and the sensor data itself, constitutes the verification feedback information.

[0098] It should be noted that the perceptual similarity value between the vehicle node k receiving the query request and the current vehicle is set to... Its formula is ,in The Hamming distance between two corresponding perceptual hash values ​​is represented. The larger the Hamming distance, the more significantly different the contents of the two images are, and they may correspond to completely different road scenes; L represents the length of the hash value.

[0099] According to an embodiment of the present invention, the step of generating a verification conclusion based on the degree of conformity between the perceived similarity value and the description of the abnormal event using its own sensor data specifically includes:

[0100] Extract vehicle position, speed, and time from its own sensor data;

[0101] Extract vehicle location, speed, and time from the description of the abnormal event;

[0102] The vehicle position in its own sensor data is compared and analyzed with the vehicle position in the abnormal event description, the vehicle speed in its own sensor data is compared with the vehicle speed in the abnormal event description, and the time in its own sensor data is compared with the time in the abnormal event description. The results are then calculated to obtain the degree of conformity.

[0103] Based on perceived similarity and degree of conformity, the state of the verification conclusion is determined, and the state of the verification conclusion includes support, opposition, and uncertainty.

[0104] It should be noted that, based on the vehicle position in its own sensor data and the vehicle position in the abnormal event description, the position distance difference is determined; based on the vehicle speed in its own sensor data and the vehicle speed in the abnormal event description, the speed difference is determined; based on the time in its own sensor data and the time in the abnormal event description, the time difference is determined; these position distance differences, speed differences, and time differences are each mapped to the 0-1 interval, where the larger the difference, the closer to 1; then, different mapped values ​​are multiplied by their corresponding weighting coefficients to obtain a cumulative sum, determining the degree of agreement; the state of the verification conclusion is set to V. ;in , These represent the high threshold for perceived similarity and the high threshold for conformity, respectively, for example, set to 0.8 and 0.75. , These represent the low threshold for perceived similarity and the low threshold for conformity, for example, set to 0.4 and 0.3 respectively; C represents the degree of conformity.

[0105] According to an embodiment of the present invention, after broadcasting to other vehicle nodes within the geographical area where the abnormal event is suspected to have occurred, the method further includes:

[0106] If no verifiable messages from nearby vehicles are received within a preset time period, the vehicle will automatically enter "island mode".

[0107] Based on the "island mode", obtain the traffic environment model of the current geographical location and the current vehicle driving direction;

[0108] Based on the traffic environment model of the current geographical location and the current vehicle driving direction, a set of visualized scene images is estimated;

[0109] The visualized scene images in the estimated set of visualized scene images are compared and analyzed with the key frame images captured by the current vehicle camera to determine the scene deviation index.

[0110] Assess the level of security threat currently faced by the vehicle based on the scenario deviation index;

[0111] If the current security threat level faced by the vehicle exceeds the preset security threat level threshold, a security warning message will be triggered and the high-risk time will be reported through vehicle-to-infrastructure communication.

[0112] It should be noted that the traffic environment model of the current geographical location includes all scene images seen by the vehicle on the road surface at the corresponding geographical location. These scene images are then filtered according to the current vehicle's driving direction to estimate a set of visualized scene images. The step of comparing and analyzing the visualized scene images in the estimated set with keyframe images captured by the vehicle's camera to determine the scene deviation index specifically includes: comparing and analyzing the visualized scene images in the estimated set with the keyframe images captured by the vehicle's camera to obtain scene image similarity values; after traversing all visualized scene images, extracting the scene image with the highest similarity value and setting the scene deviation index as... Its formula is ,in This represents the corresponding conversion factor. This represents the maximum scene image similarity value. The scene deviation index is divided into multiple regions, and each region corresponds to a security threat level. The higher the value in a region, the greater the corresponding security threat level. For example, if the preset security threat level threshold is 2, a security warning will be issued if the current vehicle faces a security threat level greater than 2. For example, if the current vehicle exceeds the original lane range during driving, the scene deviation index of the key frame image captured by the vehicle's camera and the visualized scene image will increase, and the corresponding security threat level will increase.

[0113] Figure 3 A block diagram of an Internet of Things (IoT) security protection system for vehicle network intrusion detection according to the present invention is shown.

[0114] like Figure 3 As shown, the second aspect of the present invention provides an Internet of Things (IoT) security protection system 3 for vehicle network intrusion detection, including a memory 31 and a processor 32, wherein the memory stores a program for an IoT security protection method for vehicle network intrusion detection as described in any of the above claims.

[0115] This invention provides an IoT security protection method and system for vehicle-to-everything (V2X) intrusion detection. Through the vehicle's built-in detection system, it initially identifies internal network data and external information exchange data, generating local anomaly events with confidence levels. Then, it confirms the initial detection results through a V2X regional collaborative mechanism and introduces a fine-grained spatial query and verification mechanism based on vehicle-captured images. This enables accurate discovery and correlation of inconsistencies between abnormal network events and physical world perception, thereby efficiently identifying and mitigating complex threats such as false information injection and man-in-the-middle attacks.

[0116] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0117] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0118] In addition, in the various embodiments of the present invention, each functional unit can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0119] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0120] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

Claims

1. A method for IoT security protection of vehicle network intrusion detection, characterized in that, include; Real-time acquisition of vehicle internal network data and vehicle-to-external information exchange data; using a spatiotemporal consistency verification model and dynamic threshold behavior profiling method to perform preliminary detection of false information injection attacks and man-in-the-middle attacks, and generate local abnormal events with confidence. When the confidence level of the local abnormal event exceeds the first preset threshold, an image-centric vehicle-to-everything (V2X) fine-grained spatial query mechanism is triggered: a query request containing a description of the abnormal event and the perception hash of the vehicle's key frame image is generated and broadcast to other vehicle nodes in the geographic area where the abnormal event is suspected to have occurred. Other vehicle nodes that receive the query request compare and verify the information in the query request with their own sensor data and image perception hashes within the same spatiotemporal range, and return verification feedback information containing supporting, opposing, or uncertain conclusions. The local abnormal event information is aggregated with the verification feedback information from other vehicle nodes, and the comprehensive intrusion confidence of the abnormal event is determined based on the verification feedback information from the vehicle nodes. If the overall intrusion confidence level exceeds the second preset threshold, it is determined to be an intrusion event, a distributed security response strategy is initiated, and the confirmed intrusion event is uploaded to the regional cloud security center.

2. The IoT security protection method for vehicle network intrusion detection according to claim 1, characterized in that, The dynamic threshold behavior profiling method specifically includes: Extract features and feature values ​​from the vehicle's internal network data, including at least the current vehicle position, speed, and time. Based on the current vehicle time, acquire historical data of neighboring vehicles within a set distance and a first time range. The historical data of the neighboring vehicles includes at least the historical location, historical speed and historical time of the neighboring vehicles. The current vehicle's location, speed, and time are compared with the historical locations, speeds, and events of neighboring vehicles to obtain a consistency score between the current vehicle and its corresponding neighboring vehicles. After traversing all neighboring vehicles within a set distance, a set of consistency scores between the current vehicle and its neighboring vehicles is obtained. The average consistency score is calculated by averaging the consistency scores of the current vehicle and its neighboring vehicles. If the average consistency score is less than or equal to the preset consistency score threshold, the current vehicle is marked as a potential source of false information injection.

3. The IoT security protection method for vehicle network intrusion detection according to claim 2, characterized in that, The spatiotemporal consistency verification model performs the following data processing steps: Based on the information exchanged between the vehicle and the outside world, determine the signal strength and end-to-end communication delay between the vehicle node and its communication peer. Based on a preset historical sliding time window, extract the historical signal strength set and end-to-end historical communication delay set between the corresponding vehicle node and its communication peer. Calculate the corresponding dynamic anomaly threshold ranges based on the historical signal strength set and the historical communication delay set; When the signal strength between a vehicle node and its communication peer exceeds the abnormal signal strength threshold or the end-to-end communication delay exceeds the abnormal communication delay threshold, a man-in-the-middle attack is detected.

4. The IoT security protection method for vehicle network intrusion detection according to claim 3, characterized in that, The step of generating local anomalous events with confidence levels specifically includes: If the current vehicle has a potential source of false information injection or a man-in-the-middle attack, mark the current vehicle as having a local abnormal event. Extract the average consistency score or signal strength / communication delay; If the current vehicle has a potential source of false information injection, the confidence level of the corresponding local abnormal event is determined based on the average consistency score, the preset consistency score threshold, and the corresponding preset mapping benchmark value. If the current vehicle is subject to a potential man-in-the-middle attack, the confidence level of the corresponding local abnormal event is determined based on the signal strength / communication delay, the abnormal threshold range of signal strength / communication delay, and the corresponding preset mapping benchmark value.

5. The IoT security protection method for vehicle network intrusion detection according to claim 1, characterized in that, The image-centric vehicle-to-everything (V2X) fine-grained spatial query mechanism specifically includes the generation and broadcasting of query requests as follows: Based on the time of the query, extract the key frame images captured by the current vehicle camera within the set second time window; The keyframe image is converted into a fixed-length perceptual hash value H; the query request includes at least: the type of abnormal event, the suspected geographical coordinates and time range of the occurrence, and the perceptual hash value; Based on the vehicle network to which the current vehicle has joined, the query request is broadcast to all vehicle nodes within a preset query radius centered on the suspected geographical coordinates.

6. The IoT security protection method for vehicle network intrusion detection according to claim 5, characterized in that, The preset query radius is dynamically adjusted based on the vehicle's speed: when the vehicle's speed is greater than 60 km / h, the query radius is 300 to 500 meters; when the speed is less than or equal to 60 km / h, the query radius is 100 to 300 meters, to ensure that vehicle nodes within the broadcast range intersect with abnormal events in time and space.

7. The IoT security protection method for vehicle network intrusion detection according to claim 1, characterized in that, The steps for obtaining the verification feedback information specifically include: The vehicle node k that receives the query request retrieves the perception hash value recorded by the corresponding vehicle node within the time range and geographical coordinates specified in the query request. and sensor data; Perceive hash value Comparative analysis with H yields perceptual similarity values; Based on the degree of consistency between the perceived similarity value and the description of the abnormal event using its own sensor data, a verification conclusion is generated. The verification conclusion, together with the calculated perceptual similarity value and the sensor data itself, constitutes the verification feedback information.

8. The IoT security protection method for vehicle network intrusion detection according to claim 7, characterized in that, The step of generating a verification conclusion based on the degree of consistency between the perceived similarity value and the description of the abnormal event using its own sensor data specifically includes: Extract vehicle position, speed, and time from its own sensor data; Extract vehicle location, speed, and time from the description of the abnormal event; The vehicle position in its own sensor data is compared and analyzed with the vehicle position in the abnormal event description, the vehicle speed in its own sensor data is compared with the vehicle speed in the abnormal event description, and the time in its own sensor data is compared with the time in the abnormal event description. The results are then calculated to obtain the degree of conformity. Based on perceived similarity and degree of conformity, the state of the verification conclusion is determined, and the state of the verification conclusion includes support, opposition, and uncertainty.

9. The IoT security protection method for vehicle network intrusion detection according to claim 1, characterized in that, After broadcasting to other vehicle nodes within the suspected geographic area of ​​the anomaly, the process also includes: If no verifiable messages from nearby vehicles are received within a preset time period, the vehicle will automatically enter "island mode". Based on the "island mode", obtain the traffic environment model of the current geographical location and the current vehicle driving direction; Based on the traffic environment model of the current geographical location and the current vehicle driving direction, a set of visualized scene images is estimated; The visualized scene images in the estimated set of visualized scene images are compared and analyzed with the key frame images captured by the current vehicle camera to determine the scene deviation index. Assess the level of security threat currently faced by the vehicle based on the scenario deviation index; If the current security threat level faced by the vehicle exceeds the preset security threat level threshold, a security warning message will be triggered and the high-risk time will be reported through vehicle-to-infrastructure communication.

10. An Internet of Things (IoT) security protection system for vehicle network intrusion detection, characterized in that, It includes a memory and a processor, wherein the memory stores an IoT security protection method program for vehicle network intrusion detection as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Internet of vehicles Sybil attack detection method based on behavior characteristics

    CN115190485A

  • Hybrid intrusion detection method and system for Internet of Vehicles intersection communication security

    CN121261919A