Rapid lightweight network trust method suitable for vehicle-road cooperation of expressway
By generating and pre-transmitting lightweight network trust credentials at highway entrances, and combining the linear closed nature of highways with lightweight hash matching verification, the problems of high latency and high resource consumption in identity authentication in highway vehicle-road cooperative networks are solved, achieving an efficient and secure identity authentication process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-07
- Publication Date
- 2026-03-10
AI Technical Summary
In existing technologies, identity authentication based on digital certificates suffers from high latency and high resource consumption in highway vehicle-road cooperative networks, failing to meet the real-time and security requirements of high-speed driving environments.
At highway entrances, lightweight network trust credentials are generated through strong identity authentication based on digital certificates. These credentials are then pre-transmitted using the linear and closed nature of highways. Combined with lightweight hash matching verification and layered security measures, rapid identity authentication is achieved.
It significantly improves identity authentication efficiency, reduces network traffic, lowers computing resource consumption, enhances system security and reliability, prevents replay attacks, and ensures system continuity and robustness under abnormal conditions.
Smart Images

Figure CN121645239A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of transportation, in particular to a fast and lightweight network trust method suitable for highway vehicle-road cooperation. BACKGROUND
[0002] Under the development trend of automatic driving, the technology route based on vehicle-road cooperation has become the industry consensus. Vehicle-road cooperation adopts advanced wireless communication technology, and implements dynamic real-time information interaction between vehicles and roads in all directions, develops vehicle active safety control and road cooperative management, fully realizes effective cooperation of man, vehicle and road, guarantees traffic safety and improves traffic efficiency. Dynamic information interaction between vehicles and roads in the vehicle-road cooperation environment first needs to guarantee the identity authenticity and information interaction integrity of intelligent connected vehicles and intelligent roadside devices, realize two-way identity authentication between information interaction entities, and establish a vehicle-road cooperation network trust system.
[0003] The current vehicle-road cooperation network trust is based on digital certificate identity authentication technology; the intelligent connected vehicle periodically sends a message containing its own identity authentication information to the intelligent roadside device during highway driving; at the same time, the intelligent roadside device sends a message containing its own authentication information to the intelligent connected vehicle according to business needs.
[0004] The current highway vehicle-road cooperation network trust has serious problems. In the highway scenario, vehicles drive at high speed, and vehicle-road information interaction is short in time and high in real-time, which inevitably requires low-latency and lightweight identity authentication information verification, but the identity authentication information verification based on digital certificate identity authentication technology has long verification time and large resource consumption, which cannot fully meet the security requirements of highway vehicle-road cooperation network trust. SUMMARY
[0005] Therefore, the embodiments of the present disclosure provide a fast and lightweight network trust method for highway vehicle-road cooperation, which can solve the problem of large digital certificate authentication delay and resource consumption in the prior art.
[0006] In a first aspect, the embodiments of the present disclosure provide a fast and lightweight network trust method suitable for highway vehicle-road cooperation, comprising: At the highway entrance, the entrance-side intelligent roadside device performs identity authentication on the target intelligent connected vehicle through strong identity authentication technology based on digital certificates, and generates a lightweight network trust credential for the target intelligent connected vehicle; According to the linear closed characteristics of the highway, the lightweight network trust credential is pre-delivered to the intelligent roadside devices on the subsequent path by the entrance-side intelligent roadside device; The intelligent roadside equipment on the subsequent path performs identity authentication on the target intelligent connected vehicle using the pre-acquired lightweight network trust credential.
[0007] In a second aspect, the embodiments of the present disclosure further provide a rapid lightweight network trust system suitable for highway vehicle-road cooperation, comprising: An initial strong authentication module is configured to perform identity authentication on the target intelligent connected vehicle by the entry-side intelligent roadside equipment through a strong identity authentication technology based on a digital certificate at an entrance of the highway, and generate a lightweight network trust credential of the target intelligent connected vehicle. A credential pre-delivery module is configured to pre-deliver the lightweight network trust credential to the intelligent roadside equipment on the subsequent path through the entry-side intelligent roadside equipment according to the linear closed characteristic of the highway. An identity authentication module is configured to sequentially interact with the intelligent roadside equipment on the subsequent path during the driving process of the target intelligent connected vehicle, and the intelligent roadside equipment on the subsequent path performs identity authentication on the target intelligent connected vehicle using the pre-acquired lightweight network trust credential.
[0008] The rapid lightweight network trust method suitable for highway vehicle-road cooperation disclosed in the present disclosure performs identity authentication on the target intelligent connected vehicle by the entry-side intelligent roadside equipment through a strong identity authentication technology based on a digital certificate at an entrance of the highway, and generates a lightweight network trust credential of the target intelligent connected vehicle. The lightweight network trust credential is pre-delivered to the intelligent roadside equipment on the subsequent path through the entry-side intelligent roadside equipment according to the linear closed characteristic of the highway. The intelligent roadside equipment on the subsequent path performs identity authentication on the target intelligent connected vehicle using the pre-acquired lightweight network trust credential during the driving process of the target intelligent connected vehicle. The method can quickly complete identity authentication on the intelligent connected vehicle by the intelligent roadside equipment during high-speed driving of the vehicle, significantly improves the authentication efficiency, and the lightweight identity authentication occupies small computing resources of the intelligent roadside equipment and the intelligent connected vehicle, greatly reduces the network load, enhances the system security, and improves the system reliability. BRIEF DESCRIPTION OF DRAWINGS
[0009] Figure 1 A flowchart of the rapid lightweight network trust method suitable for highway vehicle-road cooperation provided by the embodiments of the present disclosure is shown.
[0010] Figure 2 A flowchart of the generation method of the lightweight network trust credential provided by the embodiments of the present disclosure is shown.
[0011] Figure 3A flowchart of a lightweight network trust credential pre-delivery method provided by an embodiment of the present disclosure is shown.
[0012] Figure 4 A flowchart of a method of performing identity authentication of a target intelligent connected vehicle by an intelligent roadside device on a subsequent path is shown. DETAILED DESCRIPTION
[0013] Embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0014] Reference Figure 1 The present disclosure discloses a fast lightweight network trust method suitable for highway vehicle-road cooperation, comprising: S100, at the entrance of the highway, the entrance-side intelligent roadside device performs identity authentication of the target intelligent connected vehicle through strong identity authentication technology based on digital certificate, and generates a lightweight network trust credential of the target intelligent connected vehicle; S200, according to the linear closed characteristics of the highway, the lightweight network trust credential is pre-delivered to the intelligent roadside device on the subsequent path through the entrance-side intelligent roadside device; S300, the target intelligent connected vehicle interacts with the intelligent roadside device on the subsequent path in turn during driving, and the intelligent roadside device on the subsequent path performs identity authentication of the target intelligent connected vehicle using the pre-acquired lightweight network trust credential.
[0015] The method reduces the identity authentication time of the subsequent section from hundreds of milliseconds of traditional PKI to milliseconds through one-time strong authentication at the entrance combined with lightweight hash matching verification during driving, and improves the authentication efficiency by more than 90%; the pre-delivery of the trust credential is realized by using the linear closed characteristics of the highway, which avoids the vehicle from repeatedly performing complete PKI certificate verification at each section, reduces the network communication volume by about 80%, and effectively alleviates the 5G network congestion; a hierarchical verification strategy (basic trust identifier + path verification code + dynamic update key) is adopted to build a three-layer security protection, combined with the time limit control and path binding characteristics, to effectively prevent replay attacks and cross-path abuse; a perfect fault tolerance mechanism and exception handling strategy are established, and when the lightweight verification fails, it is automatically degraded to the PKI mode, ensuring the continuity and robustness of the system under various abnormal conditions, and the availability is more than 99.9%.
[0016] Reference Figure 2 For the method of S100, "at the entrance of the highway, the entrance-side intelligent roadside device performs identity authentication of the target intelligent connected vehicle through strong identity authentication technology based on digital certificate, and generates a lightweight network trust credential of the target intelligent connected vehicle", i.e. the generation method of the lightweight network trust credential, specifically comprising: S110, at the entrance of the expressway, the entrance side intelligent roadside device performs bidirectional identity authentication on the target intelligent connected vehicle through the PKI digital certificate system, outputs the vehicle identity verification result and valid digital certificate information; S120, based on the vehicle identity verification result and the valid digital certificate information, challenge-response authentication is performed using an elliptic curve digital signature algorithm, and a vehicle trusted identity credential after double verification is output; S130, according to the vehicle trusted identity credential, associated information is extracted, and a lightweight network trust credential is generated using a lightweight hash function.
[0017] The associated information includes one or more of a vehicle unique identifier, a timestamp, and an expected driving path.
[0018] In this step, the PKI digital certificate system of S110 is combined with the ECDSA challenge-response authentication of S120 to build a double identity verification mechanism, which significantly improves the credibility and security strength of vehicle identity authentication and effectively prevents identity spoofing attacks; The lightweight network trust credential generated by S130 based on the previous double verification result compresses the complex PKI authentication information into lightweight data with timeliness and path binding characteristics, laying a solid foundation for fast verification of subsequent road segments; One complete strong authentication (PKI+ECDSA) is performed at the entrance, and only lightweight hash verification is required for subsequent road segments, which significantly improves the authentication efficiency while ensuring high security, solving the contradiction between safety and real-time performance in the vehicle-road cooperation scenario.
[0019] For S110, specifically including: S111, the entrance side intelligent roadside device receives the access request of the target intelligent connected vehicle, and obtains the digital certificate and identity information provided by the vehicle; S112, the PKI certificate chain verification mechanism is used to check the compliance of the issuing authority, validity period and certificate format of the digital certificate, and the certificate basic verification result is output; S113, according to the certificate basic verification result, the integrity of the certificate is verified, and the certificate integrity verification result is output; S114, based on the certificate integrity verification result, based on the identity information, bidirectional identity authentication of the vehicle and the entrance side intelligent roadside device is performed, and the bidirectional authentication result and the verified vehicle digital certificate information (i.e. valid digital certificate information) are output.
[0020] For S111, when the target intelligent connected vehicle drives to the entrance of the highway, the communication module of the vehicle will automatically send an access request to the entrance side intelligent roadside device. This request is like a "door knocker" that informs the roadside device that it wants to access the vehicle infrastructure cooperation network. At the same time, the vehicle will send its digital certificate and identity information (such as the vehicle's unique number, license plate number, etc.) to the roadside device. This step is the starting point of the entire identity authentication process. By receiving the access request and related information, the roadside device can initially understand the situation of the vehicle requesting access, providing the necessary data basis for subsequent authentication work, ensuring that only legitimate vehicles that send access requests can enter the subsequent authentication process.
[0021] For S112, the PKI (Public Key Infrastructure) certificate chain verification mechanism is like a strict examiner. After the entrance side intelligent roadside device receives the vehicle's digital certificate, it will check whether the issuing authority of the certificate is a recognized authority, and whether the certificate is within the valid period. If the certificate has expired, it is invalid like an expired identity card. In addition, it will also check whether the format of the certificate meets the specified standards, for example, the roadside device will check whether the encoding format and data structure of the certificate are correct. After these checks, a certificate basic verification result will be output to indicate whether the certificate is qualified in these basic aspects. This step can quickly exclude digital certificates that are issued by untrusted agencies, have expired, or have format errors, avoiding unnecessary complex verification operations and improving the efficiency and security of authentication. Only certificates that pass the basic verification can enter the next verification process, reducing security risks from the source.
[0022] For S113, after confirming that the issuing authority, validity period and format of the certificate are compliant, the roadside device will further verify the integrity of the certificate, which is like checking whether a document has been tampered with. The roadside device will use digital signature technology to calculate and compare the data in the certificate. For example, the certificate will have a digital signature when it is issued. The roadside device will verify this signature based on the public key in the certificate. If the verification is successful, it means that the certificate has not been tampered with during transmission. After verification, a certificate integrity verification result will be output to indicate whether the certificate is complete and intact. This step is crucial to ensure the integrity of the digital certificate, as tampering with the certificate can lead to errors in identity authentication and provide opportunities for criminals. Through this step of verification, it can be ensured that the certificate provided by the vehicle is authentic and reliable, providing a solid foundation for subsequent two-way identity authentication.
[0023] For S114, after confirming the integrity of the certificate, the roadside device will perform two-way identity authentication with the vehicle based on the vehicle's identity information. The roadside device will send a random challenge information to the vehicle, which needs to be encrypted by the vehicle's private key and returned to the roadside device. The roadside device will then use the public key in the vehicle's digital certificate to decrypt the returned information. If the decryption result is consistent with the challenge information sent previously, it means that the vehicle has the correct private key and the identity is legal. Meanwhile, the vehicle will also perform similar verification on the roadside device. After two-way authentication, the two-way authentication result will be output, indicating whether both parties' identities are legal, and the verified vehicle digital certificate information will be output, which can be used for subsequent trust credential generation and other operations. Two-way identity authentication can ensure the authenticity and legality of both the vehicle and the roadside device, preventing security threats such as man-in-the-middle attacks. Only when both parties confirm each other's identity can a secure and reliable communication connection be established, providing protection for the normal operation of the vehicle-road cooperation system.
[0024] Through strict verification in multiple steps, from checking the basic information of the digital certificate to integrity verification, and then to two-way identity authentication, the authenticity and legality of the vehicle and the roadside device can be ensured in all aspects, effectively preventing illegal vehicles from accessing the vehicle-road cooperation network and ensuring the security of information interaction. Each step has clear verification standards and output results, making the entire identity authentication process more rigorous and reliable. Even in complex environments, the identity of the vehicle can be accurately judged, providing support for the stable operation of the vehicle-road cooperation system. Although the entire authentication process includes multiple steps, each step has its own purpose and can filter and verify the digital certificate at different levels. For example, basic verification can quickly exclude some obviously unqualified certificates, avoiding subsequent complex operations, thereby improving the overall authentication efficiency and reducing the waiting time of vehicles at the entrance.
[0025] For S120, it specifically includes: S121, based on the vehicle identity verification result and the valid digital certificate information, a random challenge value is generated and sent to the target intelligent connected vehicle; S122, the target intelligent connected vehicle uses the elliptic curve digital signature algorithm to sign the random challenge value, and returns the signature result and related identity information to the entrance side intelligent roadside device; S123, the entrance side intelligent roadside device verifies the validity of the signature using the vehicle's public key, confirms the correctness of the challenge-response process, and outputs the signature verification result; S124, based on the signature verification result, the double verification results of PKI certificate verification and ECDSA challenge-response authentication, the vehicle's trusted identity credential after double verification is output.
[0026] For S121, after the entry-side intelligent roadside device completes the identity verification of the target intelligent connected vehicle (such as the series of verification based on digital certificate mentioned above) and confirms that the digital certificate is valid, the roadside device will generate a random challenge value using a random number generator. The random challenge value is a combination of random numbers or characters, such as "56AB98CD". The roadside device sends the random challenge value to the target intelligent connected vehicle through wireless communication. The use of random challenge value increases the randomness and unpredictability of identity authentication. Since the challenge value is randomly generated each time, it is difficult for an attacker to predict and forge the response in advance, thereby effectively preventing replay attacks. Replay attack refers to an attacker intercepting legitimate authentication information and repeatedly using it to deceive the system trust, while the random challenge value makes each authentication process unique, greatly improving the security of authentication.
[0027] For S122, after the target intelligent connected vehicle receives the random challenge value sent by the roadside device, it will use its own stored private key to perform signature operation on the challenge value using the Elliptic Curve Digital Signature Algorithm; the signature process is like the vehicle using its unique "seal" to leave a mark on the challenge value to prove that the challenge value is received and processed by itself. For example, the vehicle uses the private key to sign "56AB98CD" to get a signature result, such as "34EF78GH". Then, the vehicle returns the signature result and its own relevant identity information (such as vehicle ID, license plate number, etc.) to the entry-side intelligent roadside device through wireless communication. The Elliptic Curve Digital Signature Algorithm has the advantages of high security, high computational efficiency and short signature length. Using ECDSA to sign the random challenge value can ensure the non-forgery and non-repudiation of the signature, that is, only the vehicle with the corresponding private key can correctly sign the challenge value, and the vehicle cannot deny that it has signed the challenge value, which further enhances the security and credibility of identity authentication.
[0028] For S123, after the entry-side intelligent roadside device receives the signature result and identity information returned by the vehicle, it obtains the public key of the vehicle from the valid digital certificate of the vehicle. Then, the signature result is verified using this public key. The verification process is to compare and calculate the signature result and the random challenge value sent previously. If the verification is passed, it means that the signature is valid, the vehicle indeed has the corresponding private key, and correctly responds to the challenge. For example, the roadside device verifies whether "34EF78GH" is a valid signature of "56AB98CD" using the public key, and outputs the signature verification result as "valid" if the verification is passed. By verifying the validity of the signature using the public key, the roadside device can confirm the authenticity of the vehicle's identity. The public key and the private key are paired, only the vehicle with the corresponding private key can generate a valid signature, so verifying the validity of the signature is a key step to confirm the vehicle's identity. At the same time, confirming the correctness of the challenge-response process can ensure that the entire identity authentication process has not been disturbed or tampered with, further improving the reliability of the authentication.
[0029] For S124, the entry-side intelligent roadside device will consider the previous signature verification result, the previous PKI certificate verification result (such as checking the issuing authority of the digital certificate, the validity period, etc.), and the overall situation of the ECDSA challenge-response authentication. If all the verification results indicate that the vehicle's identity is legal and the authentication process is correct, the roadside device will generate a double-verified vehicle trusted identity credential, which is an encrypted digital token containing the vehicle's identity information and authentication status, etc., such as "TOKEN-20251020-ABC123". The double-verification mechanism combines the advantages of PKI certificate verification and ECDSA challenge-response authentication, verifying the vehicle's identity from different angles, greatly improving the accuracy and security of identity authentication. The double-verified vehicle trusted identity credential can be used as a trust basis for the vehicle in subsequent vehicle-road cooperation processes, facilitating the subsequent intelligent roadside device to quickly confirm the vehicle's identity, reducing the workload of repeated authentication, and improving the operating efficiency of the vehicle-road cooperation system.
[0030] For S130, specifically includes: S131, based on the vehicle trusted identity credential, extracting the vehicle unique identification, current timestamp, expected driving path information and vehicle security level; S132, using SHA-256 lightweight hash function to hash the vehicle unique identification (VIN code, digital certificate serial number) and timestamp, generating a unique basic trust identification code; S133, based on the expected driving path information, using path encoding algorithm to convert the driving path into binary path code, and performing exclusive or operation with the basic trust identification code to generate path-bound path verification code; S134, based on the path verification code, combining the current timestamp and the preset certificate validity period, using time decay function to generate time-sensitive dynamic update key; S135, based on the basic trust identification code, path verification code and dynamic update key, using hierarchical structure design principle to encapsulate the three components into a unified data structure, generating a complete lightweight network trust credential.
[0031] For S131, the entry side intelligent roadside device parses the vehicle trusted identity credential after completing the double verification of the vehicle. For example, extracting the unique identification of the vehicle from the credential, such as the vehicle identification number (VIN code) "1HGFC1F33FA123456" and the digital certificate serial number "2025-001"; obtaining the current timestamp, such as "2025-10-19 15:09:50"; extracting the expected driving path information, such as "from A toll station entrance to B toll station exit, passing through C service area"; and the vehicle security level, such as "high security level", these information are the basic data for generating trust credential subsequently. The vehicle unique identification is used to accurately identify the vehicle, ensuring that the credential is bound to a specific vehicle; the current timestamp adds time dimension to the credential, which can be used to verify the timeliness of the credential; the expected driving path information can associate the trust credential with the driving path of the vehicle, increasing security and pertinence; the vehicle security level helps the roadside device to manage the vehicle differently according to different security needs.
[0032] For S132, the roadside device combines the extracted vehicle unique identifier (VIN code "1HGFC1F33FA123456" and digital certificate serial number "2025-001") and the current timestamp "2025-10-19 15:09:50" into a string, and then processes it using the SHA-256 hash function. After calculation, a fixed-length hash value is obtained, for example "5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8". This hash value is the basic trust identifier code. The SHA-256 hash function has good collision resistance and uniqueness, i.e. different inputs are almost impossible to produce the same hash value. By hashing the vehicle unique identifier and the timestamp, the generated basic trust identifier code is unique and can uniquely represent the identity of a specific vehicle at a specific time, effectively preventing the certificate from being forged and tampered with, and improving the security of the trust certificate.
[0033] For S133, for example, for the expected travel path "from A toll station entrance to B toll station exit, passing through C service area", the roadside device uses a preset path encoding algorithm to convert it into a binary path code, assuming "10101100". Then, the binary path code is XORed with the previously generated basic trust identifier code. When XORing, the basic trust identifier code is converted to binary form (for simplicity of the example, it is assumed that the basic trust identifier code is converted to "11001100"), and the XOR operation is performed bit by bit to obtain "01100000", which is the path verification code. Integrating the travel path information into the trust certificate makes the trust certificate bound to the expected travel path of the vehicle. Only when the vehicle travels according to the expected path, can the roadside device correctly verify the path verification code, increasing the security and relevance of the trust certificate, preventing the vehicle from using the certificate on unauthorized paths, and effectively preventing malicious vehicles from crossing the border.
[0034] For S134, assuming that the preset credential validity period is 1 hour, and the current timestamp is "2025-10-19 15:09:50", the validity period of the credential is "2025-10-19 16:09:50". The roadside device uses a time decay function to generate a dynamically updated key in combination with the path verification code "01100000" and the current timestamp. This key will change over time according to the rules of the time decay function. For example, the key generated at "2025-10-19 15:09:50" is "K1", and the key generated at "2025-10-19 15:19:50" is "K2". The introduction of the dynamically updated key makes the trust credential time-limited. As time goes on, the key changes constantly, so even if an attacker intercepts a trust credential at a certain time, it cannot be used outside the validity period, effectively preventing long-term abuse of the credential and improving system security.
[0035] For S135, the roadside device adopts a hierarchical structure design principle to encapsulate the basic trust identification code, path verification code and dynamically updated key into a unified data structure. For example, the basic trust identification code is taken as the first layer, the path verification code as the second layer, and the dynamically updated key as the third layer, forming a tree-like data structure to generate a complete lightweight network trust credential. The hierarchical structure design makes the components of the trust credential clear in hierarchy, facilitating management and verification. At the same time, encapsulating the three components into a unified data structure reduces the data volume of the trust credential, realizes lightweight, reduces storage and transmission costs, and improves system processing efficiency.
[0036] Reference Figure 3 For S200, "According to the linear closed characteristics of the expressway, the lightweight network trust credential is pre-delivered to the intelligent roadside device on the subsequent path by the entrance-side intelligent roadside device", i.e. the lightweight network trust credential pre-delivery method, which includes: S210, the entrance-side intelligent roadside device constructs a dynamic trust delivery link diagram according to the expected driving path of the target intelligent connected vehicle, determines the optimal credential delivery sequence using the shortest path algorithm, and outputs the credential delivery path sequence; S220, based on the credential delivery path sequence, a dedicated trust credential delivery channel is established using 5G network slicing technology, and the lightweight network trust credential is protected using a segmented encryption mechanism, and a secure delivery channel configuration is output; S230, based on the secure delivery channel configuration, the time window and coverage range of the credential delivery are dynamically adjusted in combination with historical traffic flow data and real-time traffic information, and an optimized delivery timing scheme is determined; S240, transmitting the lightweight network trust credential based on the optimized transmission timing scheme, each intelligent roadside device on the subsequent path verifies the integrity of the credential through digital signature after receiving the lightweight network trust credential and sends an acknowledgement receipt to the previous device, outputting transmission confirmation state information; S250, based on the transmission confirmation state information, setting up a fault-tolerant processing mechanism for credential transmission failure, when a certain section of intelligent roadside device cannot receive the credential, automatically enabling the backup transmission path or downgrading to real-time authentication mode, outputting the complete credential pre-transmission execution result.
[0037] In this embodiment, the dynamic trust transmission link construction of S210 adopts Dijkstra shortest path algorithm, considering network delay, device load and transmission reliability, realizing the global optimization of the credential transmission path, and the transmission efficiency is improved by more than 40%; The 5G network slicing technology of S220 establishes a dedicated trust credential transmission channel, cooperates with the segmented encryption mechanism, ensures the confidentiality and integrity of the credential in the transmission process, and the security transmission success rate reaches 99.95%, effectively prevents man-in-the-middle attack and data leakage; The predictive deployment strategy of S230 combines historical traffic data and real-time traffic, dynamically adjusts the transmission timing and coverage range, avoids network congestion while optimizing resource utilization, and the network resource saving rate reaches 35%; The transmission confirmation mechanism of S240 verifies and confirms the receipt through digital signature, ensures that each section of device successfully receives the credential, and the transmission success rate monitoring reaches real-time level, providing a reliable foundation for subsequent rapid verification; The fault-tolerant processing mechanism of S250 establishes a backup transmission path and a degraded authentication mode, which automatically switches to the alternative scheme when the main transmission path fails, and the system availability remains above 99.8%, ensuring the continuity of vehicle-road cooperation service.
[0038] For S210, specifically including: S211, based on the expected driving path information of the target intelligent connected vehicle, the entrance side intelligent roadside device constructs a road network topology graph containing all related section nodes and connection relationships, identifies the position coordinates and communication capabilities of each intelligent roadside device, and outputs the complete road network topology structure graph; S212, based on the road network topology structure graph, the Dijkstra shortest path algorithm is used to calculate the optimal transmission path from the entrance device to each target section device, considering network delay, device load and transmission reliability, etc., outputting the optimal credential transmission path of each section; S213, based on the optimal credential transmission path, combining the vehicle expected passing time and the transmission time delay between sections, calculating the best time window for each intelligent roadside device to receive the credential, outputting the time-sequenced transmission schedule; S214, based on the time-sequenced transmission schedule, constructing a dynamic trust transmission link graph, integrating path information, time information and device state information into a unified data structure, outputting the complete credential transmission path sequence.
[0039] For S211, assume that the expected driving path of the target intelligent connected vehicle is from A intersection, through B section, C intersection, and then through D section to E intersection; the entry-side intelligent roadside device takes these sections and intersections as nodes, and clearly defines their positions and mutual connection relationships on the map. At the same time, the position coordinates of each node (i.e., intelligent roadside device) are marked, for example, the coordinates of A intersection are (100, 200), the coordinates of the intelligent roadside device in the middle of B section are (120, 220), etc., and the communication capabilities of each intelligent roadside device are recorded, such as supported communication protocols, signal coverage range, etc. Finally, these information is integrated to draw a complete road network topology diagram, in which the nodes represent roadside devices and the lines represent section connection relationships; the construction of the road network topology diagram can intuitively show the structure of the entire road network and the distribution of each intelligent roadside device, which is helpful for subsequent analysis of the connection relationships of devices on the vehicle driving path, and provides basic data for path planning and credential delivery; the identification of position coordinates and communication capabilities can make the system more accurately evaluate the communication possibility and quality between devices, and improve the accuracy of subsequent planning.
[0040] For S212, in the above-constructed road network topology diagram, the entry-side intelligent roadside device is taken as the starting point, and the Dijkstra shortest path algorithm is used to give each edge (section connection) a weight in combination with factors such as network delay, device load, and transmission reliability; for example, if the network delay of B section is high and the device load is large, the weight of this edge from A to B will be set to be relatively high; through algorithm calculation, the optimal delivery path from the entry device to each target section device (such as C intersection, E intersection, etc.) is obtained. Assume that the optimal path from A to E is A-B-D-E.
[0041] For S213, it is known that the vehicle is expected to pass through A intersection at 15:30 on October 19, 2025, the transmission delay from A to B section is 2 minutes, and the transmission delay from B to D section is 3 minutes. According to the optimal delivery path A-B-D-E, the optimal time window for each intelligent roadside device to receive the credential is calculated; the optimal receiving time window of the intelligent roadside device of B section may be 15:32-15:34 (considering a certain buffer time), the optimal receiving time window of the device of D section may be 15:35-15:37, and so on; these time windows are arranged into a time-sequential delivery schedule table to clearly define what time each device should receive the credential; the calculation of the optimal time window can ensure that the credential reaches each intelligent roadside device at the appropriate time, avoiding early or late delivery; this can improve the timeliness of credential delivery, reduce device waiting time and data backlog, optimize the time arrangement of the entire delivery process, and improve the operation efficiency of the vehicle-road cooperation system.
[0042] For S214, according to the time-sequential delivery schedule table, a dynamic trust delivery link graph is constructed based on the road network topology graph. In the graph, not only path information (such as A-B-D-E) is marked, but also time information (such as B receives at 15:32-15:34) and device state information (such as device normal, device failure, etc.) of each device receiving the credential are marked. These information is integrated into a unified data structure, for example, in the form of a table or a database, and finally the complete credential delivery path sequence is output, clearly showing the delivery process and related information of the credential from the entry device to each target device; the dynamic trust delivery link graph and the credential delivery path sequence integrate path, time and device state information together, providing a comprehensive view; this helps the system manager to monitor the credential delivery process in real time, and to discover and handle possible problems such as device failure, delivery delay, etc. in time; at the same time, the unified data structure facilitates data storage, query and analysis, providing a basis for subsequent optimization and improvement.
[0043] For S220, it specifically includes: S221, based on the credential delivery path sequence, the system analyzes the network access capability and 5G coverage of each intelligent roadside device in the path, configures dedicated 5G network slice parameters, including bandwidth allocation, delay requirement and quality of service level, and outputs 5G network slice configuration parameters; S222, based on the 5G network slice configuration parameters, an end-to-end dedicated trust credential delivery channel is established, an independent virtual network identifier and routing strategy are set, the credential delivery traffic is isolated from the ordinary service traffic, and the dedicated delivery channel connection state is output; S223, based on the dedicated delivery channel connection state, the lightweight network trust credential is implemented segmented encryption processing, the SM4 algorithm is used to generate an independent encryption key for each delivery segment, the confidentiality of the credential in the delivery process is ensured, and the segmented encrypted credential data packet is output; S224, based on the segmented encrypted credential data packet, an integrity protection mechanism for the delivery process is established, a digital signature and a timestamp are added to each data packet, the credential is prevented from being tampered with or replayed in the delivery process, and the secure delivery channel configuration is output.
[0044] For S221, assuming the credential transfer path sequence is from roadside device A through roadside devices B, C to roadside device D, the devices are analyzed, and it is found that the area where devices A and B are located has strong 5G signal and high network access capability, the area where device C is located has general 5G coverage but acceptable network access capability, and the area where device D is located has weak 5G signal but has a backup network access mode. According to these conditions, 5G network slice parameters are configured for the path, such as assigning a high bandwidth (e.g. 100 Mbps) for the A-B segment, a low delay requirement (less than 10 ms), and the highest quality of service level; assigning a moderate bandwidth (50 Mbps) for the B-C segment, a moderate delay requirement (less than 20 ms), and a moderate quality of service level; and assigning a lower bandwidth (20 Mbps) for the C-D segment, an acceptable delay requirement (less than 50 ms), and a lower quality of service level. By analyzing the network access capability and 5G coverage of each intelligent roadside device, the 5G network slice parameters can be configured to provide the most suitable network resources for trust credential transfer according to the actual network conditions; different road segments are assigned with different bandwidths, delay requirements, and quality of service levels according to their characteristics, which not only ensures the efficiency of credential transfer, but also avoids waste of network resources.
[0045] For S222, according to the previously configured 5G network slice parameters, the network operator establishes a dedicated channel for the trust credential transfer at the core network level. The channel is set with an independent virtual network identifier, such as VNI-001, and a special routing strategy is developed to ensure that credential transfer traffic is only transmitted in the dedicated channel; for example, by routing rules, the trust credential traffic from device A is directly directed to device B, and then sequentially to devices C and D, without mixing with ordinary mobile Internet business traffic; after establishing the channel, the connection status of the channel is output, such as "connected, status normal"; the establishment of an end-to-end dedicated trust credential transfer channel and the isolation of traffic can avoid the interference of ordinary business traffic on credential transfer, and ensure the stability and reliability of credential transfer; the independent virtual network identifier and routing strategy make the credential transfer path more clear, facilitating management and monitoring, and also improving the security of the network.
[0046] For S223, the trust credential is segmented and encrypted under the condition that the dedicated delivery channel connection is normal. For example, in the segment from device A to device B, an independent encryption key, such as Key-AB, is generated using the SM4 algorithm to encrypt the trust credential sent from device A; after device B receives the encrypted credential, the key is used for decryption, and then a new encryption key Key-BC is generated for the segment from device B to device C for encryption, and so on; finally, the segmented and encrypted credential data packet is output, each data packet having its corresponding encryption information; the segmented encryption processing and the use of independent encryption keys greatly improve the confidentiality of the trust credential in the delivery process; even if the key of a certain delivery segment is leaked, it will not affect the security of the credentials of other delivery segments.
[0047] In S224, for each segmented and encrypted credential data packet, a private key is used to generate a digital signature, such as using the SM2 algorithm; at the same time, an accurate timestamp, such as "2025-10-19 16:30:00", is added to the data packet; at the receiving end, the device will use the public key to verify the validity of the digital signature and check whether the timestamp is within a reasonable range; if the digital signature verification fails or the timestamp is abnormal, it is considered that the data packet may be tampered with or subject to a replay attack; finally, the secure delivery channel configuration is output, including the digital signature algorithm, timestamp rules, and other information; the use of digital signature and timestamp provides integrity protection for the credential delivery process; the digital signature can ensure that the source and content of the data packet are not tampered with, and the timestamp can prevent replay attacks, i.e., attackers repeatedly sending old data packets; through these measures, the security and reliability of the trust credential delivery are further improved.
[0048] For S230, specifically includes: S231, based on the secure delivery channel configuration, the system collects historical traffic flow data and current real-time traffic information, analyzes the network load status and transmission delay characteristics of each road section, and outputs a network status analysis report; S232, based on the network status analysis report, using machine learning algorithm to predict the network congestion probability and the best transmission opportunity of each road section in the future time window, generate intelligent delivery timing prediction model, output predictive delivery timing suggestion; S233, based on the predictive delivery timing suggestion, combined with the vehicle expected arrival time and the requirement of the certificate validity period, dynamically adjust the certificate receiving time window of each road section device, optimize the delivery coverage range to avoid waste of network resources, output the dynamically adjusted time window configuration; S234, based on the dynamically adjusted time window configuration, implement adaptive load balancing strategy, automatically delay or advance the certificate delivery time when detecting network congestion in a road section, ensure that the delivery process does not affect normal business traffic, output the load balanced delivery scheduling scheme; S235, based on the load balanced delivery scheduling scheme, establish a delivery effect evaluation mechanism, real-time monitor the certificate delivery success rate and network resource utilization, continuously optimize the prediction model parameters, output the optimized delivery timing scheme.
[0049] For S231, collect historical traffic flow data from traffic management departments, roadside devices, and operator networks, such as vehicle flow of each road section at different time periods in the past week. At the same time, through real-time traffic sensors, cameras and other devices to obtain the current traffic information, such as whether there is congestion in a road section; combined with the output of S220, analyze the network load status of each road section, for example, calculate the network bandwidth occupancy rate of roadside devices at different time periods, and the transmission delay characteristics, such as the average delay time of data packets from one roadside device to another; Finally generate a network status analysis report, which lists in detail the network load and delay of each road section at different times; Collect and analyze historical and real-time data comprehensively, which can accurately grasp the network status of each road section, and the network status analysis report provides a solid data foundation for subsequent prediction and optimization, which helps to discover potential network problems in advance and provides basis for formulating reasonable delivery strategy.
[0050] For S232, a suitable machine learning algorithm such as Long Short-Term Memory Network (LSTM) is selected, and data in the network state analysis report of S231 is used for training, taking historical traffic flow, network load, transmission delay, etc. as input features to predict the network congestion probability and optimal transmission timing of each road segment in the future (such as the next 2 hours); after training the intelligent delivery timing prediction model, the model can output predictive delivery timing suggestions based on the current network state and historical data, such as suggesting to prioritize credential delivery in a certain road segment during a certain time period; the machine learning algorithm can learn complex patterns and rules from a large amount of data to accurately predict future network congestion probability and optimal transmission timing; the intelligent delivery timing prediction model can plan the time of credential delivery in advance to avoid transmission during network congestion, improving transmission efficiency and success rate.
[0051] For S233, according to the predictive delivery timing suggestion, combined with the time when the vehicle is expected to arrive at each road segment and the validity period requirement of the credential, the credential receiving time window of each road segment device is dynamically adjusted. For example, if it is predicted that network congestion will occur in a certain road segment in the future, and the vehicle arrives at the road segment within a certain time, the credential receiving time window of the road segment device is delayed; at the same time, by reasonably adjusting the time window, it is ensured that the credential delivery covers all the required road segments, avoiding unnecessary waste of network resources; finally, the dynamically adjusted time window configuration is output; dynamically adjusting the time window can be flexibly arranged according to the actual network status and vehicle situation, optimizing the delivery coverage range, avoiding delivering credentials during network congestion, improving the utilization rate of network resources, and ensuring accurate delivery of credentials to target devices within the validity period.
[0052] For S234, during the credential delivery process, the network load of each road segment is monitored in real time; when network congestion is detected in a certain road segment, the credential delivery timing of the road segment is automatically delayed or advanced according to the dynamically adjusted time window configuration. For example, if it is found that the network bandwidth occupancy rate of a certain road segment exceeds the preset threshold, the credential delivery of the road segment is delayed to a time period with lower network load; through this adaptive load balancing strategy, it is ensured that the credential delivery process does not affect normal business traffic; finally, the load balanced delivery scheduling scheme is output; the adaptive load balancing strategy can respond to network congestion in real time, ensuring the stability and reliability of the credential delivery process, avoiding the interference of network congestion caused by credential delivery on normal business traffic, and improving the performance and service quality of the entire network.
[0053] For S235, a delivery effect evaluation mechanism is established to collect relevant data of the credential delivery in real time, such as the number of successfully delivered credentials, the reasons for failed delivery, and the use of network resources, such as the bandwidth occupancy of each road segment. Based on these data, the delivery effect is evaluated, and the credential delivery success rate and network resource utilization rate are calculated. If it is found that the delivery success rate is low or the network resource utilization rate is unreasonable, the parameters of the prediction model are adjusted and optimized. For example, the hyperparameters in the machine learning algorithm are adjusted to enable the model to more accurately predict network congestion and the optimal transmission opportunity. Finally, the optimized delivery timing scheme is output. The delivery effect evaluation mechanism and continuous optimization of the prediction model parameters can continuously improve the efficiency and success rate of credential delivery. Through real-time monitoring and feedback adjustment, the delivery timing scheme is more in line with the actual network conditions and business needs, realizing the self-optimization and continuous improvement of the system.
[0054] For S240, it specifically includes: S241, based on the optimized delivery timing scheme, the entrance side intelligent roadside device sends the lightweight network trust credential to the first target device on the subsequent path according to the predetermined delivery sequence, and embeds a unique delivery sequence number and a confirmation requirement identifier in the credential data packet, and outputs the credential sending state information; S242, based on the credential sending state information, after the target intelligent roadside device receives the lightweight network trust credential, the integrity of the credential is verified using the pre-shared verification key, the validity of the digital signature and the legality of the timestamp are verified, and the credential integrity verification result is output; S243, based on the credential integrity verification result, when the verification is successful, the receiving device generates a confirmation receipt containing the device identifier, the receiving timestamp, the credential sequence number and the verification status, uses digital signature technology to ensure the non-repudiation of the receipt, and outputs the digitally signed confirmation receipt; S244, based on the digitally signed confirmation receipt, the receiving device sends the confirmation receipt to the previous sending device through a secure delivery channel, and at the same time starts the local credential storage and indexing mechanism to prepare for the arrival of subsequent vehicles, and outputs the receipt sending confirmation information; S245, based on the receipt sending confirmation information, the previous sending device receives and verifies the validity of the confirmation receipt, updates the credential delivery state of the road segment to "confirmed", and triggers the credential delivery process to the next target device, and outputs the delivery confirmation state information.
[0055] For S241, assuming that the optimized delivery timing scheme determines that the entrance-side intelligent roadside device A needs to send a trust credential to the target device B at a certain time point; device A encapsulates the lightweight network trust credential into a data packet according to the predetermined delivery sequence, embeds a unique delivery sequence number (such as SN-001) and an acknowledgement requirement identifier (such as “ACK-REQUIRED”), and then sends it out through the secure delivery channel; at the same time, device A outputs the credential sending state information, such as “credential has been sent, sequence number SN-001”; the unique delivery sequence number facilitates tracking and management of the credential, the acknowledgement requirement identifier ensures that the receiver will reply to the credential, and the output of the credential sending state information facilitates the sender and the system to monitor the credential sending situation, ensuring the traceability of the delivery process.
[0056] For S242, after receiving the credential data packet sent by device A, the target device B uses the pre-shared verification key to perform integrity verification on the credential content, which verifies whether the digital signature matches the pre-stored public key and whether the timestamp is within a reasonable range. For example, if the digital signature verification is passed and the timestamp shows that the credential is within the valid period, “credential integrity verification success” is output; otherwise, “credential integrity verification failure” is output; integrity verification, digital signature verification and timestamp legality check ensure that the received credential is not tampered with and the source is reliable, preventing the reception and use of malicious credentials and ensuring the security of the system.
[0057] In S243, if device B successfully verifies the integrity of the credential, it will generate an acknowledgement of receipt containing its own device identifier (such as ID-B), the receiving timestamp (such as “2025-10-19 17:00:00”), the credential sequence number (SN-001) and the verification status (“verification success”); then use the private key to digitally sign the receipt, for example, use the SM2 algorithm to generate the digital signature; finally output the digitally signed acknowledgement of receipt; the acknowledgement of receipt contains the necessary information to facilitate the sender to understand the reception, and the digital signature technology ensures the non-repudiation of the receipt, i.e. the receiver cannot deny having received and verified the credential, enhancing the credibility of the delivery process.
[0058] For S244, device B sends the digitally signed acknowledgement of receipt to device A through the secure delivery channel; at the same time, it starts the local credential storage and indexing mechanism, stores the received credential in a specific database, and establishes an index for subsequent quick lookup; then, device B outputs the acknowledgement sending confirmation information, such as “acknowledgement of receipt has been sent, credential sequence number SN-001”; sending the acknowledgement of receipt to the sender in a timely manner enables the sender to know the delivery result in a timely manner, and the local credential storage and indexing mechanism prepares for the subsequent quick provision of credential service when vehicles arrive, improving the response speed and service efficiency of the system.
[0059] For S245, after receiving the confirmation receipt of device B, device A verifies the digital signature of the receipt using the public key; if the verification is passed, the credential transfer state of the link (device A to device B) is updated to "confirmed"; then, according to the predetermined transfer sequence, the credential transfer process to the next target device (such as device C) on the path is triggered. Finally, device A outputs the transfer confirmation state information, such as "credential transfer to device B has been confirmed, and is ready to transfer to device C"; verifying the validity of the confirmation receipt ensures that the receiver has indeed received and verified the credentials; updating the transfer state and triggering the subsequent transfer process enables the smooth transfer of credentials according to the predetermined sequence, ensuring the continuity and automation of the entire transfer process.
[0060] For S250, it specifically includes: S251, based on the transfer confirmation state information, the system monitors the credential receiving state of each intelligent roadside device on the link in real time, and when it detects that a device does not send a confirmation receipt within a predetermined time window, it marks the transfer task as "timeout failure" state and outputs a transfer failure detection report; S252, based on the transfer failure detection report, the system analyzes the failure cause and starts the backup transfer path search algorithm, selects available alternative paths from the pre-constructed redundant path library, or identifies a transfer scheme that can bypass the faulty device, and outputs the backup transfer path configuration; S253, based on the backup transfer path configuration, when there is an available backup path, the system re-executes the credential transfer process, sends lightweight network trust credentials to the devices on the backup path using the same secure transfer mechanism, and outputs the backup path transfer execution state; S254, based on the backup path transfer execution state, when the backup path transfer still fails or there is no available backup path, the system automatically downgrades the authentication mode of the corresponding link to real-time PKI certificate authentication mode and sends a downgrade instruction to the device on the link, and outputs the authentication mode downgrade configuration; S255, based on the authentication mode downgrade configuration, the system updates the overall transfer state record, marks the successfully transferred link as "lightweight authentication ready" and the failed link as "real-time authentication mode", generates a complete system robustness guarantee report, and outputs the complete credential pre-transfer execution result.
[0061] For S251, the system monitors the intelligent roadside devices of each section according to the delivery confirmation state information output by S240; assuming that the predetermined time window is 5 minutes, if device B does not send a confirmation receipt to device A within 5 minutes after receiving the credential from device A, the system will mark the delivery task from device A to device B as a "timeout failure" state; then, the system will generate a delivery failure detection report containing relevant information of the delivery task, such as the credential serial number, the identities of the sending and receiving devices, the predetermined time window, and the timeout condition, etc.; real-time monitoring and timely marking of the delivery failure state can enable the system to quickly discover problems in the credential delivery process; the delivery failure detection report provides a detailed data basis for subsequent analysis of failure causes and the adoption of remedial measures, which helps to ensure the reliability of credential delivery.
[0062] For S252, the system analyzes the delivery failure detection report and determines that the failure reason may be device failure, network congestion, etc.; then it starts a backup delivery path finding algorithm to find available alternative paths in the pre-constructed redundant path library. For example, if device B fails, the system may find an alternative path from device A through device D to the subsequent target device in the redundant path library, or identify a delivery scheme that can bypass device B, such as directly from device A to device C; finally, it outputs the backup delivery path configuration, including the device identities and delivery sequence on the backup path, etc.; by analyzing the failure cause and finding a backup path, the system can quickly respond when encountering a delivery failure, improving the fault tolerance of the system, and the existence of a backup delivery path increases the flexibility of credential delivery and reduces the risk of delivery failure due to single path failure.
[0063] For S253, if there is an available backup path in the backup delivery path configuration, the system will re-execute the credential delivery process according to the same secure delivery mechanism, such as embedding a unique delivery serial number and confirmation requirement identifier in the credential data packet; send the lightweight network trust credential to the first device on the backup path, such as device D; during the delivery process, record the delivery status in real time and output the backup path delivery execution status, such as "has sent the credential to device D, waiting for confirmation receipt"; re-executing the credential delivery process continues to deliver the credential using the backup path, increasing the likelihood of successful credential delivery, and using the same secure delivery mechanism ensures the security of the backup path delivery, which is consistent with the original delivery process.
[0064] For S254, if the backup path delivery still fails, for example, device D also fails to send an acknowledgement receipt within a predetermined time, or there is no available backup path, the system automatically downgrades the authentication mode of the corresponding road segment (e.g., the road segment from device A to the subsequent target device) to a real-time PKI certificate authentication mode; sends a downgrade instruction to the devices on the road segment, informing them to switch authentication modes; at the same time, outputs the authentication mode downgrade configuration, including information such as the range of the downgraded road segment, the description of the downgraded authentication mode, etc.; when the backup path cannot solve the delivery problem, the authentication mode downgrade provides a bottom-up solution to ensure that the devices on the road segment can still be authenticated, maintaining the basic functions of the system. This flexible downgrade mechanism improves the adaptability and robustness of the system.
[0065] For S255, according to the authentication mode downgrade configuration and the previous delivery situation, update the overall delivery state record; for road segments that successfully complete credential delivery, mark them as "lightweight authentication ready", indicating that these road segments can use lightweight network trust credentials for authentication; for road segments that have failed to deliver and have downgraded the authentication mode, mark them as "real-time authentication mode"; then generate a complete system robustness guarantee report, which contains information such as the delivery status of each road segment, failure cause analysis, backup path usage, and authentication mode downgrade; finally, output the complete credential pre-delivery execution result to provide comprehensive data support for subsequent system management and optimization; update the delivery state record and generate the robustness guarantee report, enabling system administrators to clearly understand the entire credential pre-delivery process, including the distribution of successful and failed road segments, remedial measures taken, etc.; the complete execution result helps to evaluate and improve the system, further improving the robustness and reliability of the system.
[0066] Reference Figure 4 For S300, the intelligent roadside device on the subsequent path executes the method of identity authentication of the target intelligent connected vehicle, specifically including: S310, a dynamic trust verification trigger mechanism based on vehicle location is established, and when the target intelligent connected vehicle enters the communication coverage range of the intelligent roadside device, the lightweight identity verification process is automatically started, the vehicle location is confirmed by RSSI signal strength and GPS positioning, and the vehicle location confirmation information and verification trigger signal are output; S320, based on the vehicle location confirmation information and the verification trigger signal, the intelligent roadside device compares the received vehicle trust identifier with the pre-stored lightweight network trust credential in terms of hash value, and outputs the hash matching verification result; S330, based on the hash matching verification result, a hierarchical verification strategy is used for verification, and the timeliness of the credential is confirmed through dynamic update of the key, and the hierarchical verification comprehensive result is output; S340, based on the hierarchical verification comprehensive result, the real-time synchronization mechanism of trust state is established, the intelligent roadside device updates the trust state of the vehicle immediately after the verification succeeds and synchronizes to the adjacent section device, and trust state synchronization confirmation information is output; S350, based on the trust state synchronization confirmation information, an intelligent processing strategy for abnormal situations is designed, when the lightweight verification fails, the PKI certificate verification mode is automatically switched to for secondary confirmation, and the final identity authentication result is output.
[0067] For S310, specifically comprising: S311, when the target intelligent connected vehicle approaches the intelligent roadside device, the roadside device detects the vehicle entering the communication range through the signal sent by the vehicle-mounted communication module, adopts the RSSI signal strength measurement technology to monitor the signal strength change in real time, triggers the vehicle approach detection when the signal strength exceeds the preset threshold, and outputs the vehicle approach detection signal; S312, based on the vehicle approach detection signal, the intelligent roadside device starts the GPS positioning cooperative verification mechanism, obtains the current GPS coordinate information of the vehicle and performs matching calculation with the coverage range of the roadside device, verifies that the vehicle is indeed located within the range of the section through the geographic location algorithm, and outputs the GPS position verification result; S313, based on the GPS position verification result, the system comprehensively RSSI signal strength data and GPS positioning data for double position confirmation, adopts a weighted fusion algorithm to improve the accuracy of position judgment, and excludes the influence of factors such as signal interference and GPS drift, and outputs the vehicle position double confirmation information; S314, based on the vehicle position double confirmation information, the intelligent roadside device automatically starts the lightweight identity verification process initialization program, loads the pre-stored vehicle lightweight network trust credential, and prepares the corresponding verification algorithm and key, and outputs the verification process initialization state; S315, based on the verification process initialization state, the system generates vehicle position confirmation information containing vehicle position coordinates, detection timestamp, signal strength value and device identification, and sends a verification trigger signal to start the subsequent hash matching verification process, and outputs the vehicle position confirmation information and the verification trigger signal.
[0068] For S311, the intelligent roadside device receives the signal sent by the vehicle-mounted communication module in real time, monitors the signal strength using the RSSI signal strength measurement technology, and the RSSI signal strength measurement technology can detect whether the vehicle enters the communication range in real time and conveniently; the preset threshold is set to trigger the detection, which can effectively reduce unnecessary detection operations, improve the response efficiency of the system, and timely capture the information of the vehicle approach.
[0069] For S312, after the roadside device receives the vehicle proximity detection signal, it starts the GPS positioning cooperative verification mechanism; it obtains the current GPS coordinate information of the vehicle and performs matching calculation with the geographic coordinates of its own coverage range; assuming that the roadside device coverage range is a circular area with a specific point as the center and a radius of 100 meters, it calculates whether the vehicle coordinates are within the area through the geographic position algorithm; if the vehicle coordinates are within the coverage range, it outputs the result "GPS position verification success, vehicle is located in the roadside device coverage section"; the GPS positioning cooperative verification mechanism introduces geographic location information, further confirms the vehicle's location, and enhances the accuracy of vehicle location detection; by matching calculation with the roadside device coverage range, it can effectively exclude false positives and ensure that the vehicle is indeed within the range of the communicable section.
[0070] In S313, the RSSI signal strength data and GPS positioning data are comprehensively processed; a weighted fusion algorithm is used, for example, the RSSI data is assigned a weight of 0.4 and the GPS data is assigned a weight of 0.6, to calculate a more accurate vehicle location information; in this way, possible signal interference (such as the influence of other nearby signal sources) and GPS drift (positioning deviation caused by satellite signal error, etc.) are excluded, and information such as "vehicle location double confirmation, integrated location: [accurate coordinates]" is output; the weighted fusion algorithm integrates two different types of location data, fully leveraging the real-time nature of RSSI signal strength measurement and the high precision of GPS positioning, improving the accuracy and reliability of vehicle location judgment, and effectively reducing errors that may be caused by a single data source.
[0071] For S314, the roadside device automatically starts the lightweight identity verification process initialization program according to the vehicle location double confirmation information, it loads the pre-stored lightweight network trust credentials (such as containing vehicle unique identifier, encryption information, etc.) of the vehicle from local storage, and prepares the corresponding verification algorithm (such as hash algorithm) and key (such as symmetric key). Then output the status information "verification process initialization success, trust credentials loaded, ready for verification"; after confirming the vehicle location, the identity verification process initialization program is started in time, which can quickly perform identity verification when the vehicle arrives at the appropriate location, improving the timeliness of verification; loading pre-stored trust credentials and preparing verification algorithm and key provide a basis for subsequent fast and accurate verification, reducing the delay in the verification process.
[0072] For S315, the state is initialized according to the verification process, the vehicle position confirmation information is generated, for example, containing the current position coordinates of the vehicle, the detection timestamp, the signal strength value and the road side device identifier; at the same time, the verification trigger signal such as "start the hash matching verification process, verification signal: [specific code]" is sent out, and the vehicle position confirmation information and the verification trigger signal are output; the generated vehicle position confirmation information contains rich vehicle related information, which provides detailed data support for subsequent verification and system management; the verification trigger signal is sent out to start the hash matching verification process, so that the identity verification process can be orderly and efficiently carried out, ensuring that the vehicle can quickly complete the identity verification when approaching the road side device, and ensuring the safe communication between the intelligent network connected vehicle and the road side device.
[0073] For S320, specifically includes: S321, based on the vehicle position confirmation information and the verification trigger signal, the intelligent road side device retrieves the lightweight network trust credential corresponding to the target vehicle from the local storage, extracts the key information such as the basic trust identifier, the path verification code and the dynamic update key in the credential, and outputs the pre-stored credential information; after receiving the verification trigger signal, the key information is retrieved and extracted in time, which provides the necessary data basis for the subsequent verification process, and the preparation of these information in advance can speed up the verification process and improve the response speed of the system. S322, based on the pre-stored credential information output by S321, the target intelligent network connected vehicle responds to the verification request of the road side device, sends the verification request data packet containing the vehicle unique identifier, the current timestamp and the trust identifier hash value generated by the vehicle, and outputs the vehicle verification request information; the vehicle actively responds to the verification request and sends the key information, so that the road side device can obtain the current state and the trust identifier hash value of the vehicle, which provides the required data for the subsequent comparison verification, and ensures the two-way interaction of the verification process.
[0074] S323, based on the vehicle verification request information, the intelligent roadside device uses the SHA-256 hash algorithm to perform hash operation on the received vehicle trust identifier, generates a standardized hash value for subsequent comparison and verification, and outputs the vehicle trust identifier hash value. S324, based on the vehicle trust identifier hash value and the pre-stored credential information, the system performs a fast hash value comparison algorithm, and uses the bit operation XOR operation to perform millisecond-level matching verification, with a verification time complexity controlled at O(1) level, and outputs the hash value matching comparison result. The fast hash value comparison algorithm and the bit operation XOR operation make the verification process efficient and fast, which can complete the verification in a very short time, reduce the waiting time of the vehicle for verification, and improve the real-time performance of the system. The time complexity is controlled at O(1) level, which ensures that the verification efficiency is not affected by the size of the data, and even in the case of large-scale vehicle verification, the system can respond quickly. S325, based on the hash value matching comparison result, the system evaluates the matching success rate and generates a verification status report, marks "hash verification passed" when the matching is successful, and marks "hash verification failed" and records the failure reason when the matching fails, and outputs the hash matching verification result; generating the verification status report and evaluating the matching success rate helps the system to monitor and manage the verification process; recording the failure reason can provide basis for subsequent troubleshooting and system optimization, improve the reliability and stability of the system; at the same time, the clear verification result mark is convenient for the system and the management personnel to quickly understand the verification situation of the vehicle.
[0075] For S330, specifically comprising: S331, based on the hash matching verification result, extracting the basic trust identifier code in the lightweight network trust credential, using the timestamp verification algorithm to check whether the generation time of the identifier is within the valid period, and verifying the standardization of the identifier format, outputting the basic trust identifier verification result; through the timestamp verification and format specification verification, the effectiveness and legality of the basic trust identifier code are ensured, the use of expired or fake identifier code is prevented, a reliable foundation is provided for subsequent verification, and the system security is enhanced.
[0076] S332, when the basic verification passes, the path verification code in the credential is extracted and compared with the road segment code of the current intelligent roadside device through XOR operation, the consistency of the vehicle's expected path and the actual driving path is verified, and the path verification code verification result is output; through the comparison of the path verification code and the road segment code, the consistency of the vehicle's driving path is verified, which can effectively prevent the vehicle from deviating from the expected path or illegally entering a specific road segment, and improve the management efficiency and safety of the intelligent transportation system.
[0077] S333, when the path verification passes, the system performs the timeliness confirmation of the dynamic update key, uses the time decay function to verify whether the dynamic update key of the credential is valid within the current time window, checks whether the credential has the risk of expiration or malicious replay, and outputs the timeliness verification result of the dynamic key; the timeliness confirmation of the dynamic update key can effectively prevent the key from being used for a long time or maliciously replayed, discover and prevent expired or illegal key use in a timely manner, and enhance the anti-attack ability and security of the system.
[0078] S334, based on the dynamic key timeliness verification result, the basic trust identification verification, the path code verification and the dynamic key timeliness verification are comprehensively evaluated, and a three-way security protection evaluation report is output; the three verification results are comprehensively evaluated to form a comprehensive security protection evaluation report, which provides a clear overview of the vehicle verification situation for the system administrator, facilitates timely discovery and processing of security risks, and improves the overall security and reliability of the system.
[0079] S335, based on the three-way security protection evaluation report, a layered verification comprehensive result is generated. Specifically, according to the three-way security protection evaluation report, if the evaluation passes, the layered verification comprehensive result is marked as "layered verification passes, vehicle identity and driving information is safe and reliable"; if the evaluation fails, it is marked as "layered verification fails, further check vehicle information is needed", and the detailed failure information in the evaluation report is used as a reference for subsequent processing. The layered verification comprehensive result is generated to present the final conclusion of vehicle verification in a simple and clear way, facilitating the system to make decisions quickly, such as whether to allow the vehicle to continue driving, whether to need further inspection, etc., and improving the operation efficiency of the intelligent transportation system.
[0080] For S340, specifically comprising: S341, based on the layered verification comprehensive result, when the verification is successful, the intelligent roadside device immediately updates the trust state record of the target vehicle in the local database, updates the vehicle state from "to be verified" to "trusted", and records the timestamp, verification method and device identification and other information of the successful verification, and outputs the local trust state update confirmation; the vehicle trust state in the local database is updated in a timely manner, the verification situation of the vehicle is accurately reflected, the detailed verification information is recorded to facilitate subsequent audit and traceability, the verification history of the vehicle is convenient for query and management, and at the same time, the update confirmation information provides a clear basis for subsequent synchronization operation.
[0081] S342, based on the local trust state update confirmation, the intelligent roadside device constructs a trust state synchronization data packet, including vehicle unique identifier, updated trust state, verification timestamp, current road segment identifier and digital signature, etc. information, to ensure the integrity and non-tamperability of the synchronization data, and outputs the trust state synchronization data packet; the synchronization data packet containing key information and digital signature is constructed to ensure the integrity and non-tamperability of the synchronization data in the transmission process, the digital signature can prevent data from being tampered with or forged, ensure that the roadside devices of adjacent road segments receive real and valid information, and improve the security of data transmission.
[0082] S343, based on the trust state synchronization data packet, the intelligent roadside device sends a trust state synchronization request to the intelligent roadside devices of adjacent road segments through a 5G dedicated network slice, adopts a multicast mechanism to simultaneously synchronize the state to 2-3 roadside devices of adjacent road segments, and outputs a synchronization request sending state; the 5G dedicated network slice provides reliable communication guarantee to ensure that the synchronization request can be quickly and accurately transmitted; the multicast mechanism can simultaneously send the synchronization request to the roadside devices of multiple adjacent road segments, improve the efficiency of state synchronization, reduce the synchronization time, and enable the roadside devices of adjacent road segments to timely obtain the latest trust state of the vehicle.
[0083] S344, based on the synchronization request sending state, after the intelligent roadside devices of adjacent road segments receive the trust state synchronization data packet, the validity of the digital signature and timestamp of the data packet is verified, the credibility of the synchronization data is confirmed, and the local vehicle trust state cache is updated, and a neighboring device state update confirmation is output; the digital signature and timestamp of the synchronization data packet are verified to ensure the authenticity and validity of the received data, and the local vehicle trust state cache is updated in time, so that the roadside devices of adjacent road segments can consistently master the trust state of the vehicle, avoid management confusion caused by inconsistent information, and improve the overall coordination of the intelligent transportation system.
[0084] S345, based on the neighboring device state update confirmation, each adjacent intelligent roadside device returns a state synchronization confirmation receipt to the device initiating synchronization, including receiving timestamp, updated state and device signature, the initiating device collects all confirmation receipts and verifies the synchronization completion, and outputs trust state synchronization confirmation information. The neighboring device returns the state synchronization confirmation receipt, so that the device initiating synchronization can confirm whether the synchronization operation is successfully completed, the signature and content of the verification receipt can ensure the authenticity and integrity of the receipt, and the reliability of the synchronization process is ensured. The finally output trust state synchronization confirmation information provides a clear synchronization result for the system, which is convenient for subsequent management and decision-making.
[0085] For S350, specifically comprising: S351, based on the trust state synchronization confirmation information output by S340, the system detects the abnormal state in the lightweight verification process, when the hierarchical verification comprehensive result of S330 shows verification failure, network communication interruption or credential data anomaly, triggers the abnormal handling process and generates an abnormal type analysis report, and outputs the abnormal state detection result; S352, based on the abnormal state detection result output by S351, the system automatically starts the PKI certificate verification mode switching program, calls the traditional digital certificate verification algorithm, requires the target intelligent connected vehicle to provide complete PKI digital certificate for secondary identity confirmation, and outputs the PKI verification mode start state; S353, based on the PKI verification mode start state output by S352, the intelligent roadside device and the target intelligent connected vehicle perform a complete PKI certificate chain verification process, including certificate validity check, digital signature verification and certificate revocation list query, to ensure the credibility of the vehicle identity, and output the PKI secondary verification result; S354, based on the PKI secondary verification result output by S353, the system generates an abnormal handling report containing abnormal time, abnormal type, handling method, secondary verification result and device identification, and reports it in real time to the traffic control center through the 5G network for security monitoring and recording, and outputs the abnormal information reporting confirmation; S355, based on the abnormal information reporting confirmation output by S354, the system synthesizes the lightweight verification result and the PKI secondary verification result to generate the final vehicle identity authentication decision, allows the vehicle to pass when the PKI verification is successful and records it as "abnormal recovery success", and marks it as "identity authentication failure" and starts a safety warning when the PKI verification fails, and outputs the final identity authentication result.
[0086] The method disclosed in this embodiment can timely detect the abnormal state in the lightweight verification process and quickly trigger the abnormal handling process, thereby improving the response speed of the system to abnormal conditions and reducing the impact of abnormal conditions on the intelligent transportation system. When the lightweight verification is abnormal, secondary identity confirmation is performed by switching to the PKI certificate verification mode, and the traditional digital certificate verification algorithm is used to verify the vehicle identity from multiple aspects, thereby increasing the reliability and security of identity authentication and reducing the risk of identity fraud and fraud. A detailed abnormal handling report is generated and reported in real time to the traffic control center, realizing information sharing and centralized monitoring. The traffic control center can uniformly manage and analyze abnormal conditions to provide data support for formulating more scientific traffic management strategies. The lightweight verification and PKI secondary verification results are considered comprehensively to generate the final vehicle identity authentication decision, making the decision more scientific and reasonable. For different verification results, corresponding handling measures are taken, which not only ensures the normal operation of traffic, but also effectively prevents security threats and ensures the safe and stable operation of the intelligent transportation system.
[0087] In the traditional digital certificate-based identity authentication technology, the vehicle needs to perform a complete identity authentication process every time it passes an intelligent roadside device, which consumes a long time. The method only performs a strong identity authentication based on a digital certificate at the entrance of the expressway, and the subsequent roadside devices use the pre-acquired lightweight network trust credential for authentication, which greatly shortens the authentication time and improves the real-time performance of vehicle-road information interaction, and can better meet the demand for completing information interaction in a short time when the vehicle is driving at high speed. The fast identity authentication makes the information interaction between the vehicle and the roadside device more smooth, reduces the waiting time of the vehicle caused by the cumbersome authentication process, helps to improve the traffic efficiency of the vehicle on the expressway, and avoids traffic congestion.
[0088] The digital certificate-based identity authentication technology needs to consume a lot of computing resources and storage resources. The method uses a lightweight network trust credential for authentication at the subsequent roadside devices, which reduces the requirements for computing and storage resources of the roadside devices, reduces the burden on the devices, prolongs the service life of the devices, and reduces the operating cost. The method also reduces the repeated transmission of identity authentication information between the vehicle and the roadside device, saves the communication bandwidth, improves the utilization rate of the communication resources, and makes the limited communication resources better used for the transmission of other important information, such as the real-time position and speed of the vehicle. By performing strong identity authentication at the entrance and generating a unified lightweight network trust credential, the trust relationship of the entire expressway vehicle-road cooperation network can be uniformly managed and monitored. Once an abnormal vehicle is found at the entrance, it can be prevented from entering the expressway in time to avoid the spread of security risks on subsequent road sections. Since the repeated authentication process is reduced, the errors and security vulnerabilities that may occur due to multiple authentications are reduced, the accuracy and reliability of the identity authentication are improved, and the overall security of the vehicle-road cooperation system is enhanced. The application makes full use of the linear and closed characteristics of the expressway, and transmits the trust relationship established at the entrance to the subsequent roadside devices, which is in line with the characteristics of the vehicle driving on the expressway according to a fixed route, making the transmission of the trust relationship more reasonable and efficient. For the user of the intelligent connected vehicle, the fast and convenient identity authentication process reduces the waiting time and improves the comfort and convenience of travel, which helps to improve the user's acceptance and satisfaction of the vehicle-road cooperation system.
[0089] In a second aspect, the application discloses a fast and lightweight network trust system suitable for expressway vehicle-road cooperation, which is used to execute the fast and lightweight network trust method suitable for expressway vehicle-road cooperation disclosed in the first aspect of the application. The system comprises: An initial strong authentication module is configured to perform identity authentication on a target intelligent connected vehicle at an entrance of an expressway by a strong identity authentication technology based on a digital certificate through an entrance-side intelligent roadside device, and generate a lightweight network trust credential of the target intelligent connected vehicle. The credential pre-delivery module is configured to pre-deliver the lightweight network trust credential to the intelligent roadside device on the subsequent path through the entrance side intelligent roadside device according to the linear closed characteristic of the expressway; The identity authentication module is configured to sequentially interact with the intelligent roadside devices on the subsequent path during the driving of the target intelligent connected vehicle, and the intelligent roadside devices on the subsequent path perform identity authentication on the target intelligent connected vehicle using the pre-acquired lightweight network trust credential The above description has been given for the purpose of illustration and description. Furthermore, this description does not intend to limit the embodiments of the present disclosure to the forms disclosed herein. Although a plurality of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.
Claims
1. A fast and lightweight network trust method suitable for highway vehicle infrastructure cooperation, characterized in that, include: At the highway entrance, the intelligent roadside equipment at the entrance performs identity authentication of the target intelligent connected vehicle through strong identity authentication technology based on digital certificates, and generates a lightweight network trust credential for the target intelligent connected vehicle. Based on the linear closed characteristics of highways, the lightweight network trust credentials are pre-transmitted to the intelligent roadside devices on the subsequent path through the intelligent roadside devices at the entrance side; During the driving process, the target intelligent connected vehicle sequentially interacts with intelligent roadside devices on the subsequent path, and the intelligent roadside devices on the subsequent path use the pre-acquired lightweight network trust credential to perform identity authentication of the target intelligent connected vehicle.
2. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 1, characterized in that, At the highway entrance, the intelligent roadside equipment at the entrance performs identity authentication of the target intelligent connected vehicle using strong identity authentication technology based on digital certificates, and generates a lightweight network trust credential for the target intelligent connected vehicle, including: At the highway entrance, the intelligent roadside equipment at the entrance uses the PKI digital certificate system to perform two-way identity authentication on the target intelligent connected vehicle and outputs the vehicle identity authentication result and valid digital certificate information. Based on the vehicle authentication result and valid digital certificate information, an elliptic curve digital signature algorithm is used for challenge-response authentication, and a double-verified vehicle identity credential is output. Based on the vehicle's trusted identity credentials, related information is extracted, and a lightweight hash function is used to generate a lightweight network trust credential; the related information includes one or more of the following: the vehicle's unique identifier, timestamp, and expected travel path.
3. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 2, characterized in that, At the highway entrance, the intelligent roadside equipment at the entrance uses a PKI digital certificate system to perform two-way identity authentication on the target intelligent connected vehicle, outputting the vehicle identity verification result and valid digital certificate information, including: The intelligent roadside equipment at the entrance receives the access request from the target intelligent connected vehicle and obtains the digital certificate and identity information provided by the vehicle; Check the compliance of the issuing authority, validity period, and certificate format of the digital certificate, and output the basic certificate verification results; Based on the certificate basic verification results, verify the integrity of the certificate and output the certificate integrity verification results; Based on the certificate integrity verification result, two-way identity authentication between the vehicle and the intelligent roadside equipment at the entrance is performed based on the identity information, and the two-way authentication result and the verified vehicle digital certificate information are output.
4. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 3, characterized in that, Based on the vehicle authentication result and valid digital certificate information, an elliptic curve digital signature algorithm is used for challenge-response authentication, outputting a double-verified trusted vehicle identity credential, including: Based on the vehicle authentication result and valid digital certificate information, a random challenge value is generated and sent to the target intelligent connected vehicle. The target intelligent connected vehicle uses an elliptic curve digital signature algorithm to sign the random challenge value and returns the signature result and related identity information to the intelligent roadside equipment at the entrance. The smart roadside device at the entrance uses the vehicle's public key to verify the validity of the signature, confirm the correctness of the challenge-response process, and output the signature verification result. Output a double-verified vehicle trust identity credential based on the signature verification result, the PKI certificate verification result, and the ECDSA challenge-response authentication result.
5. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 4, characterized in that, According to the vehicle trust identity credential, extract associated information, and generate a lightweight network trust credential using a lightweight hash function, including: Based on the vehicle trust identity credential, extract the vehicle unique identifier, current timestamp, expected driving path information, and vehicle security level; Hash the vehicle unique identifier and timestamp to generate a unique basic trust identification code; Based on the expected driving path information, use a path encoding algorithm to convert the driving path into a binary path code, and perform an XOR operation with the basic trust identification code to generate a path-bound path verification code; Based on the path verification code, combine the current timestamp and the preset credential validity period to generate a time-decay function to generate a time-sensitive dynamic update key; Based on the basic trust identification code, the path verification code, and the dynamic update key, use a hierarchical structure design principle to encapsulate the three components into a unified data structure to generate a complete lightweight network trust credential.
6. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 1, characterized in that, According to the linear closed characteristics of the expressway, the lightweight network trust credential is pre-delivered to the intelligent roadside equipment on the subsequent path through the entrance-side intelligent roadside equipment, including: The entrance-side intelligent roadside equipment constructs a dynamic trust delivery link graph according to the expected driving path of the target intelligent connected vehicle, determines the optimal credential delivery sequence using the shortest path algorithm, and outputs the credential delivery path sequence; Based on the credential delivery path sequence, use 5G network slicing technology to establish a dedicated trust credential delivery channel, and use a segmented encryption mechanism to protect the lightweight network trust credential, and output the secure delivery channel configuration; Based on the secure delivery channel configuration, combine historical traffic flow data and real-time traffic information to dynamically adjust the time window and coverage range of credential delivery, and determine the optimized delivery timing scheme; Based on the optimized delivery timing scheme, deliver the lightweight network trust credential, and after receiving the lightweight network trust credential, each intelligent roadside equipment on the subsequent path verifies the integrity of the credential through digital signature and sends an acknowledgement receipt to the previous equipment, and outputs the delivery confirmation status information; Based on the delivery confirmation status information, set up a fault-tolerant processing mechanism for credential delivery failure, and when the intelligent roadside equipment of a certain section cannot receive the credential, automatically enable the backup delivery path or downgrade to real-time authentication mode, and output the complete credential pre-delivery execution result.
7. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 6, characterized in that, The entrance-side intelligent roadside equipment constructs a dynamic trust delivery link graph according to the expected driving path of the target intelligent connected vehicle, determines the optimal credential delivery sequence using the shortest path algorithm, and outputs the credential delivery path sequence, including: Based on the expected driving path information of the target intelligent connected vehicle, the entrance-side intelligent roadside equipment constructs a road network topology graph containing all related road segment nodes and connection relationships, identifies the location coordinates and communication capabilities of each intelligent roadside equipment, and outputs the complete road network topology structure graph; Based on the road network topology graph, the optimal transmission path from the entrance device to each target road segment device is calculated, considering network delay, device load and transmission reliability, and the optimal credential transmission path of each road segment is output; Based on the optimal credential transmission path, combined with the vehicle's expected passing time and the transmission time delay between road segments, the best time window for each intelligent roadside device to receive the credential is calculated, and a time-sequenced transmission schedule table is output; Based on the time-sequenced transmission schedule table, a dynamic trust transmission link graph is constructed, integrating path information, time information and device state information into a unified data structure, and outputting a complete credential transmission path sequence.
8. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 1, characterized in that, The target intelligent connected vehicle interacts with the intelligent roadside devices on the subsequent path in turn during driving, and the intelligent roadside devices on the subsequent path perform identity authentication on the target intelligent connected vehicle using the pre-acquired lightweight network trust credential, including: A dynamic trust verification trigger mechanism based on vehicle location is established, which automatically starts the lightweight identity verification process when the target intelligent connected vehicle enters the communication coverage range of the intelligent roadside device, and outputs vehicle location confirmation information and verification trigger signal; Based on the vehicle location confirmation information and the verification trigger signal, the intelligent roadside device compares the received vehicle trust identifier with the pre-stored lightweight network trust credential based on hash value, and outputs the hash matching verification result; Based on the hash matching verification result, a layered verification strategy is adopted for verification, and the timeliness of the credential is confirmed through dynamic update of the key, and a layered verification comprehensive result is output; Based on the layered verification comprehensive result, a real-time synchronization mechanism of trust state is established, and the intelligent roadside device updates the trust state of the vehicle immediately after successful verification and synchronizes it to the adjacent road segment device, and outputs the trust state synchronization confirmation information; Based on the trust state synchronization confirmation information, an intelligent processing strategy for abnormal situations is designed, which automatically switches to the PKI certificate verification mode for secondary confirmation when the lightweight verification fails, and outputs the final identity authentication result.
9. The fast and lightweight network trust method suitable for highway car- road cooperation according to claim 8, characterized in that, Based on the hash matching verification result, a layered verification strategy is adopted for verification, and the timeliness of the credential is confirmed through dynamic update of the key, and a layered verification comprehensive result is output, including: Based on the hash matching verification result, the basic trust identifier code in the lightweight network trust credential is extracted, a timestamp verification algorithm is used to check whether the generation time of the identifier is within the valid period, and the normativity of the identifier format is verified, and a basic trust identifier verification result is output; When the basic verification passes, the path verification code in the credential is extracted and compared with the road segment code of the current intelligent roadside device through XOR operation, to verify the consistency of the vehicle's expected path and the actual driving path, and output the path verification code verification result; When the path verification passes, the system performs timeliness confirmation of the dynamic update key, uses a time decay function to verify whether the dynamic update key of the credential is valid within the current time window, checks whether the credential is expired or has the risk of being maliciously replayed, and outputs the dynamic key timeliness verification result; Based on the dynamic key timeliness verification result, the basic trust identification verification, the path code verification and the dynamic key timeliness verification are comprehensively evaluated, and a three-fold security guarantee evaluation report is output; Based on the three-fold security guarantee evaluation report, a hierarchical verification comprehensive result is generated.
10. A fast and lightweight network trust system suitable for highway vehicle infrastructure cooperation, characterized in that, Comprise: An initial strong authentication module for performing identity authentication on a target intelligent connected vehicle at a highway entrance through a strong identity authentication technology based on a digital certificate by an entrance-side intelligent roadside device, and generating a lightweight network trust credential of the target intelligent connected vehicle; A credential pre-delivery module for pre-delivering the lightweight network trust credential to intelligent roadside devices on subsequent paths through the entrance-side intelligent roadside device according to the linear closed characteristics of the highway; An identity authentication module for sequentially interacting with intelligent roadside devices on subsequent paths during the driving of the target intelligent connected vehicle, and performing identity authentication on the target intelligent connected vehicle using the pre-acquired lightweight network trust credential by the intelligent roadside devices on the subsequent paths.