An intelligent roadside terminal security processing method and system based on multi-mode communication cooperation and dynamic key chain
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XIAMEN JINLONG CAR ACCESSORIES CO LTD
- Filing Date
- 2025-12-25
- Publication Date
- 2026-08-07
AI Technical Summary
[0003]某绕城高速车路协同试点中,120台双模RSU因采用硬编码静态密钥且未建立动态更新机制,密钥被攻击者逆向破解,同时多模切换仅依据信道信噪比触发,未执行时间同步与预连接流程,导致切换时旧接口残留引发资源冲突,攻击者趁机注入伪造施工区域数据,造成3起自动驾驶车辆追尾事故、直接经济损失超200万元;事故暴露的核心技术缺陷,静态密钥体系缺乏动态更新与预分发机制,跨RSU认证延迟引发安全防护真空,多模通信切换未结合空间关联优先级与安全认证流程,且数据无防篡改溯源标签,既无法抵御身份伪造、数据注入攻击,也不符合等保2.0三级与车联网安全合规要求,制约车路协同规模化应用
[0053] This system employs a trusted institution's master key-based hash algorithm to assign unique identifiers and initial keys to roadside terminals; a 3D spatial nearest point search algorithm to determine the spatial association priority between vehicles and roadside terminals; a fuzzy comprehensive evaluation method to assess the channel quality of 5G, C-V2X, and DSRC; seamless switching between multimodal pre-connection and data synchronization via the PTP protocol; pre-distribution of temporary keys to relevant roadside terminals during vehicle registration and real-time generation of session keys across roadside terminals; execution of corresponding encryption algorithms based on data type to generate tamper-proof traceability tags containing roadside terminal identifiers and timestamps; and real-time data analysis at the roadside terminal edge using quantum keys. The technical means of negotiating and dynamically generating and issuing new group keys overcomes the technical problems of existing intelligent roadside terminals, such as easy mass leakage of static keys, high latency and poor adaptability of multi-mode communication switching, large cross-roadside terminal authentication overhead leading to security vacuum, lack of closed-loop management of data security throughout the entire life cycle, and inability to dynamically update key materials. As a result, it achieves the technical effects of end-to-end latency of key messages ≤30ms, cross-roadside terminal authentication time ≤10ms, reduced risk of key leakage, real-time edge data processing to meet the needs of vehicle-road cooperation, and continuous security enhancement of key materials across the entire network, supporting efficient communication and security protection in vehicle-road cooperation scenarios.
Smart Images

Figure CN121692149B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent transportation and cyberspace security, and in particular to a method and system for secure processing of intelligent roadside terminals based on multi-mode communication collaboration and dynamic key chains. Background Technology
[0002] With the accelerated implementation of the intelligent connected vehicle industry, vehicle-to-everything (V2X) systems have become the core support for intelligent transportation. As a key hub for vehicle-road-cloud collaboration, intelligent roadside units (RSUs) need to be compatible with 5G, C-V2X, and DSRC multi-mode communication and ensure real-time secure data transmission. However, the industry is currently facing severe security challenges. The automotive information security technical requirements standard clearly requires RSUs to have identity authentication, data encryption, and operation auditing capabilities. However, existing systems generally suffer from problems such as static key management, lack of security guarantees for multi-mode switching, and lack of data traceability.
[0003] In a pilot project of vehicle-road cooperative systems on a ring expressway, 120 dual-mode RSUs used hard-coded static keys without a dynamic update mechanism. These keys were reverse-engineered and cracked by attackers. Furthermore, multi-mode switching was triggered solely by the channel signal-to-noise ratio, without time synchronization or pre-connection procedures. This resulted in resource conflicts caused by residual old interfaces during switching, allowing attackers to inject forged construction area data. This led to three rear-end collisions involving autonomous vehicles and direct economic losses exceeding 2 million yuan. The core technical flaws exposed by the incident were: the static key system lacked dynamic updates and pre-distribution mechanisms; cross-RSU authentication delays created a security vacuum; multi-mode communication switching did not incorporate spatial priority and security authentication processes; and data lacked tamper-proof traceability tags. These deficiencies made the system vulnerable to identity forgery and data injection attacks, and also failed to meet the Level 3 requirements of the Cybersecurity Law 2.0 and the requirements for vehicle-to-everything (V2X) security compliance, hindering the large-scale application of vehicle-road cooperative systems. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a method and system for secure processing of intelligent roadside terminals based on multi-mode communication collaboration and dynamic key chain, so as to achieve key message delay ≤30ms, cross-terminal authentication time ≤10ms, reduce the risk of key leakage, and meet the real-time and security enhancement requirements of vehicle-road collaboration.
[0005] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows:
[0006] In a first aspect, a security processing method for intelligent roadside terminals based on multi-mode communication collaboration and dynamic key chains is provided, the method comprising:
[0007] Based on the master key obtained from a trusted institution, the roadside terminals are registered using the master key, and each roadside terminal is assigned a unique identifier (roadside terminal ID) and an initial key.
[0008] A secure link is established using an initial key. The roadside terminal collects its own 3D spatial location information and that of the accessing vehicle to form a 3D point set to determine the spatial association priority between the vehicle and each roadside terminal. At the same time, the channel quality of the communication mode is evaluated in real time to obtain the evaluation results.
[0009] Priority scheduling of transmitted messages is performed based on spatial association priority and evaluation results, and seamless switching between multiple modes is performed based on the PTP protocol to obtain a secure transmission environment that enables collaborative communication.
[0010] Based on a secure transmission environment, when a vehicle registers and accesses a trusted institution, it obtains a temporary key and distributes it to the relevant roadside terminals through a secure link; as the vehicle moves across roadside terminals, a session key for authentication is generated in real time based on the temporary key.
[0011] Based on the session key, the data is encrypted and protected throughout the process, and a tamper-proof traceability tag is generated for each piece of data to obtain encrypted and tagged data.
[0012] Based on encrypted and tagged data, the roadside terminal performs real-time edge analysis tasks. According to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminal through a quantum key negotiation mechanism. The new group key is stored in the hardware security module to achieve dynamic synchronization and security enhancement of all key materials.
[0013] Furthermore, based on the master key obtained from a trusted institution, and using the master key to register the roadside terminals, a unique identifier (roadside terminal ID) and an initial key are assigned to each roadside terminal, including:
[0014] Based on a trusted institution, the master key is obtained, and registration requests sent by each roadside terminal are received;
[0015] Each roadside terminal requesting registration is assigned a globally unique identifier. Based on the master key and the assigned identifier, the initial key of the corresponding roadside terminal is obtained through hash operation.
[0016] The initial key is securely distributed to the corresponding roadside terminal to complete the registration and initialization process.
[0017] Furthermore, a secure link is established using an initial key. Roadside terminals collect their own 3D spatial location information and that of accessing vehicles to construct a 3D point set, determining the spatial association priority between vehicles and each roadside terminal. Simultaneously, the channel quality of the communication modes is evaluated in real time to obtain evaluation results, including:
[0018] Control each registered roadside terminal to establish a secure communication link with the initial key and adjacent roadside terminals and access vehicles through two-way authentication;
[0019] Based on the secure link, it receives the three-dimensional coordinates of itself and the 3D position information of vehicles within the communication range periodically reported by each roadside terminal, and aggregates them to form a global 3D point set.
[0020] Based on a global 3D point set, the Euclidean distance between each vehicle and each roadside terminal is calculated using a 3D spatial nearest point pair search algorithm. The spatial association priority list between vehicles and roadside terminals is dynamically determined and updated based on the Euclidean distance.
[0021] While constructing a global 3D point set, the system receives channel quality parameters of 5G, C-V2X and DSRC communication modes monitored in real time by each roadside terminal. The system then uses a fuzzy comprehensive evaluation method to score the quality of each mode, resulting in an evaluation result that includes the quality scores of each mode.
[0022] Furthermore, while constructing a global 3D point set, channel quality parameters of 5G, C-V2X, and DSRC communication modes monitored in real time by each roadside terminal are received. A fuzzy comprehensive evaluation method is used to score the quality of each mode, yielding an evaluation result containing the quality scores for each mode, including:
[0023] Through a secure communication link, the system receives real-time channel quality parameters of 5G, C-V2X, and DSRC communication modes from each roadside terminal.
[0024] Based on the collected channel quality parameters, the quality score of each communication mode is calculated by fuzzy comprehensive evaluation method to obtain the initial score of each communication mode;
[0025] Based on the initial score, communication modes that reach the preset quality threshold are selected to form a candidate communication mode set;
[0026] Based on the candidate communication modal set, a complete evaluation result including the available communication modalities and quality scores for each region is obtained.
[0027] Furthermore, based on spatial association priority and evaluation results, priority scheduling of transmitted messages is performed, and seamless switching between multimodal modes is executed based on the PTP protocol, resulting in a secure transmission environment capable of collaborative communication, including:
[0028] Based on the spatial association priority list and evaluation results, a global scheduling strategy is obtained;
[0029] Based on the global scheduling strategy, scheduling instructions containing channel allocation and resource preemption rules are issued to each roadside terminal. In the scheduling instructions, the transmission messages are divided into three levels: P0, P1, and P2. Among them, the P0 level messages exclusively occupy the channel 1 resource of the 5.9GHz spectrum.
[0030] Based on the execution status of the scheduling instructions and the real-time updated evaluation results, when it is determined that the quality of the current communication mode does not meet the transmission requirements of the current priority message, the optimal alternative mode is selected from the candidate mode set, and a switching instruction is generated.
[0031] Based on the switching command, the source roadside terminal and the target roadside terminal are coordinated to complete time synchronization through the PTP protocol, and pre-connection establishment and data caching are executed in sequence to achieve seamless switching of communication modes, thereby building a unified and secure transmission environment.
[0032] Furthermore, based on a secure transmission environment, when a vehicle registers and accesses a trusted institution, it obtains a temporary key and distributes it to relevant roadside terminals via a secure link; as the vehicle moves across roadside terminals, a session key for authentication is derived in real time based on the temporary key, including:
[0033] Based on a secure transmission environment, the system receives and verifies vehicle registration requests and encrypted authentication parameters forwarded by the current service roadside terminal in order to obtain verified vehicle registration information.
[0034] Based on the verified vehicle registration information, a temporary key is generated for the vehicle, and according to the relevant roadside terminal set determined by the spatial association priority list, the temporary key is pre-distributed to the current serving roadside terminal and potential serving roadside terminal through a secure link.
[0035] Based on the pre-distributed temporary key and the real-time updated spatial association priority list, when a vehicle is detected to have moved into the communication range of a new roadside terminal, the session key derivation process between the vehicle and the new roadside terminal is triggered.
[0036] Furthermore, based on the session key, the data is encrypted and protected throughout the process, and a tamper-proof traceability tag is generated for each piece of data to obtain encrypted and tagged data, including:
[0037] Based on the session key, the system receives data to be protected submitted by each roadside terminal and executes the corresponding encryption algorithm according to the data type to obtain encrypted data.
[0038] Based on encrypted data, key metadata is extracted and combined with the roadside terminal identifier and precise timestamp of the data source to obtain a tamper-proof traceability label;
[0039] Based on encrypted data and traceability tags, the encrypted data and traceability tags are securely bound together to obtain a complete encrypted and tagged data package.
[0040] Furthermore, based on the encrypted and tagged data, the roadside terminal performs real-time edge analysis tasks; according to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminal through a quantum key negotiation mechanism. The new group key is stored in a hardware security module, realizing dynamic synchronization and security enhancement of all key materials, including:
[0041] Based on encrypted and tagged data, coordinate the execution of real-time edge analysis tasks by each roadside terminal and receive the returned analysis results;
[0042] Based on the aggregated analysis results of various side terminals, the current network security status is assessed, and a quantum key negotiation mechanism is triggered to dynamically generate a new group key;
[0043] Based on the newly generated group key, the newly generated group key is distributed to all network-side terminals through a secure link to complete the synchronous update of the group key material;
[0044] Based on the updated group key material, a new round of secure communication cycle is established to achieve continuous security enhancement and dynamic maintenance of the full key material.
[0045] Secondly, a smart roadside terminal security processing system based on multi-mode communication collaboration and dynamic key chain includes:
[0046] The registration module is used to register roadside terminals based on the master key obtained from a trusted institution, and to assign a unique identifier (roadside terminal ID) and an initial key to each roadside terminal.
[0047] The evaluation module is used to establish a secure link through an initial key. The roadside terminal collects its own 3D spatial location information and the access vehicles to form a 3D point set to determine the spatial association priority between the vehicle and each roadside terminal. At the same time, it evaluates the channel quality of the communication mode in real time to obtain the evaluation result.
[0048] The transmission module is used to prioritize and schedule transmission messages based on spatial association priority and evaluation results, and to perform seamless switching between multiple modes based on the PTP protocol to obtain a secure transmission environment that enables collaborative communication.
[0049] The authentication module is used to obtain a temporary key and distribute it to the relevant roadside terminals through a secure link when a vehicle registers and accesses a trusted institution, based on a secure transmission environment; when the vehicle moves across roadside terminals, a session key for authentication is generated in real time based on the temporary key.
[0050] The encryption module is used to encrypt and protect the data throughout the process based on the session key, and generate a tamper-proof traceability tag for each piece of data to obtain encrypted and tagged data.
[0051] The update module is used for real-time edge analysis tasks performed by the roadside terminal based on encrypted and tagged data. According to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminal through a quantum key negotiation mechanism. The new group key is stored in the hardware security module to achieve dynamic synchronization and security enhancement of all key materials.
[0052] The above-described solution of the present invention has at least the following beneficial effects:
[0053] This system employs a trusted institution's master key-based hash algorithm to assign unique identifiers and initial keys to roadside terminals; a 3D spatial nearest point search algorithm to determine the spatial association priority between vehicles and roadside terminals; a fuzzy comprehensive evaluation method to assess the channel quality of 5G, C-V2X, and DSRC; seamless switching between multimodal pre-connection and data synchronization via the PTP protocol; pre-distribution of temporary keys to relevant roadside terminals during vehicle registration and real-time generation of session keys across roadside terminals; execution of corresponding encryption algorithms based on data type to generate tamper-proof traceability tags containing roadside terminal identifiers and timestamps; and real-time data analysis at the roadside terminal edge using quantum keys. The technical means of negotiating and dynamically generating and issuing new group keys overcomes the technical problems of existing intelligent roadside terminals, such as easy mass leakage of static keys, high latency and poor adaptability of multi-mode communication switching, large cross-roadside terminal authentication overhead leading to security vacuum, lack of closed-loop management of data security throughout the entire life cycle, and inability to dynamically update key materials. As a result, it achieves the technical effects of end-to-end latency of key messages ≤30ms, cross-roadside terminal authentication time ≤10ms, reduced risk of key leakage, real-time edge data processing to meet the needs of vehicle-road cooperation, and continuous security enhancement of key materials across the entire network, supporting efficient communication and security protection in vehicle-road cooperation scenarios. Attached Figure Description
[0054] Figure 1 This is a flowchart illustrating a smart roadside terminal security processing method based on multi-mode communication collaboration and dynamic key chain, provided by an embodiment of the present invention.
[0055] Figure 2 This is a schematic diagram of an intelligent roadside terminal security processing system based on multi-mode communication collaboration and dynamic key chain, provided by an embodiment of the present invention. Detailed Implementation
[0056] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0057] like Figure 1As shown, embodiments of the present invention propose a security processing method for intelligent roadside terminals based on multi-mode communication collaboration and dynamic key chains. The method includes the following steps:
[0058] Step 1: Based on the master key obtained from the trusted institution, register the roadside terminal using the master key, and assign a unique identifier (roadside terminal ID) and an initial key to each roadside terminal.
[0059] Step 2: Establish a secure link using the initial key. The roadside terminal collects its own 3D spatial location information and that of the accessing vehicle to form a 3D point set to determine the spatial association priority between the vehicle and each roadside terminal. At the same time, it evaluates the channel quality of the communication mode in real time to obtain the evaluation results.
[0060] Step 3: Prioritize the transmission messages based on spatial association priority and evaluation results, and perform seamless switching between multiple modes based on the PTP protocol to obtain a secure transmission environment that can coordinate communication.
[0061] Step 4: In a secure transmission environment, when a vehicle registers and accesses a trusted institution, it obtains a temporary key and distributes it to the relevant roadside terminals through a secure link; as the vehicle moves across roadside terminals, a session key for authentication is generated in real time based on the temporary key.
[0062] Step 5: Based on the session key, the data is encrypted and protected throughout the process, and a tamper-proof traceability tag is generated for each piece of data to obtain encrypted and tagged data.
[0063] Step 6: Based on the encrypted and tagged data, the roadside terminal performs real-time edge analysis tasks; according to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminal through a quantum key negotiation mechanism. The new group key is stored in the hardware security module to achieve dynamic synchronization and security enhancement of all key materials.
[0064] In this embodiment of the invention, a unique identifier and initial key are assigned to the roadside terminal using a hash operation based on a trusted institution's master key; a two-way authentication secure link is established using the initial key; a 3D spatial nearest point pair search algorithm is used to determine the spatial association priority between the vehicle and the roadside terminal; fuzzy comprehensive evaluation method is used to evaluate the channel quality of 5G, C-V2X, and DSRC; messages are scheduled based on spatial priority and channel quality evaluation results; and seamless switching between multimodal pre-connection and data caching is achieved using the PTP protocol; temporary keys are pre-distributed to relevant roadside terminals during vehicle registration, and session keys are generated in real time when crossing roadside terminals; the session keys are encrypted according to data type and a tamper-proof traceability tag containing the roadside terminal identifier and timestamp is generated; and the roadside terminal performs edge processing. By employing real-time analysis and dynamic generation and distribution of new key groups through quantum key negotiation, this technology overcomes the technical challenges of existing intelligent roadside terminals, such as easy mass leakage of static keys, high latency in multi-mode communication switching and poor scenario adaptability, large cross-roadside terminal authentication overhead leading to security vacuum, lack of full lifecycle encryption and traceability loop for data, and inability to dynamically update key materials. This achieves the following technical effects: critical message transmission latency meets the real-time requirements of vehicle-road cooperation; cross-roadside terminal authentication efficiency is improved; data encryption security complies with V2X protocol standards; key leakage risk is significantly reduced; edge data processing response is timely; and the security of key materials across the entire network is continuously enhanced. This ensures efficient communication and secure operation of intelligent roadside terminals in vehicle-road cooperative scenarios.
[0065] In a preferred embodiment of the present invention, step 1 above may include:
[0066] Step 1.1: Based on the trusted institution, obtain the master key and receive registration requests from each roadside terminal. Specifically, this includes: First, constructing a dedicated trusted institution for vehicle-road cooperation. This institution, as the security core, is responsible for coordinating key generation and device identity management, avoiding the key confusion problem caused by the lack of a unified security management entity in traditional systems. The trusted institution generates the master key through a standard security mechanism and immediately isolates and protects the master key to prevent it from being illegally read or tampered with. Then, after completing hardware deployment and access, each roadside terminal initiates a registration request to the trusted institution through a pre-built dedicated secure communication channel. The request includes the hardware model, production batch number, actual deployment location coordinates, and basic verification information of the device at the time of manufacture, ensuring that the trusted institution accurately identifies each roadside terminal applying for registration.
[0067] Step 1.2 assigns a globally unique identifier to each roadside terminal requesting registration. Based on the master key and the assigned identifier, an initial key for the corresponding roadside terminal is obtained through hash calculation. Specifically, after receiving the registration request from a roadside terminal, the trusted organization first performs multi-dimensional verification of the basic information of the roadside terminal contained in the request, including verifying the matching of hardware model and production batch, the consistency of deployment location and planned area, and the validity of factory verification information. Only roadside terminals that pass all verifications can enter the subsequent process to prevent unauthorized devices from accessing the network. After verification, the trusted organization assigns a globally unique identifier to the roadside terminal. The identifier is composed of the administrative division code of the roadside terminal's deployment area, the device type code, and a randomly generated 16-bit numerical sequence, ensuring that there will be no duplicate identifiers in the entire vehicle-road cooperative system, solving the problem of confusing and difficult-to-trace device identifications. Subsequently, the trusted organization initiates a preset secure hash calculation process. ,in, This refers to the SM3 cryptographic hash algorithm. This represents the master key of a trusted organization. A unique identifier representing a roadside terminal. This indicates a data concatenation operation. The master key previously generated and stored in the hardware, along with the unique identifier just assigned to the roadside terminal, are used as inputs for the operation. A hash operation is then used to generate an initial key specific to each roadside terminal, ensuring that the initial key of each roadside terminal is strongly bound to its own unique identifier.
[0068] Step 1.3 securely distributes the initial key to the corresponding roadside terminal to complete the registration initialization process. This includes: after the trusted organization generates the initial key for the roadside terminal, it distributes the initial key to the corresponding roadside terminal via an encrypted communication link. During transmission, the initial key is encrypted in real-time using an encryption algorithm conforming to cryptographic standards to prevent interception or theft during transmission. Upon receiving the encrypted initial key, the roadside terminal immediately activates the decryption function of its own hardware security module, completing the decryption operation of the initial key internally. The decrypted initial key is directly stored without passing through the ordinary storage area operated by the terminal, preventing the initial key from being stolen or tampered with by malicious programs in the terminal system. Afterwards, the roadside terminal sends a confirmation message of successful initial key reception to the trusted organization through the previously established secure communication channel. The confirmation message contains the roadside terminal's unique identifier and a checksum of the initial key. Upon receiving the confirmation message, the trusted organization verifies the checksum. If the verification is successful, the roadside terminal's registration process is marked as complete. The roadside terminal has thus completed registration initialization and possesses the basic conditions for establishing secure communication links with adjacent roadside terminals and access vehicles.
[0069] In this embodiment of the invention, because a trusted institution generates a master key and receives roadside terminal registration requests, assigns a globally unique identifier to each roadside terminal requesting registration, generates an initial key for the corresponding roadside terminal through hash calculation based on the master key and the identifier, and finally securely distributes the initial key to the corresponding roadside terminal to complete the registration initialization, the technical means overcome the technical problems of traditional roadside terminal registration, such as the lack of a globally unique identifier, which easily leads to chaotic device management; the use of static hard encoding for initial keys, which easily leads to the risk of mass leakage; and the lack of security protection in the key distribution process, which makes it easy to be intercepted and stolen. Thus, the technical effects of achieving a globally unique and accurately traceable roadside terminal identity, a more secure initial key based on the master key, and a secure and controllable registration initialization process are achieved.
[0070] In a preferred embodiment of the present invention, step 2 above may include:
[0071] Step 2.1 involves controlling each registered roadside terminal to establish a secure communication link with its initial key, adjacent roadside terminals, and accessing vehicles. Specifically, this includes: First, controlling each registered roadside terminal to call its own hardware-stored initial key to initiate the two-way authentication process; for link establishment between adjacent roadside terminals, one of the roadside terminals first sends an authentication request to the target adjacent roadside terminal. This request includes its own globally unique identifier and identity verification information encrypted with the initial key; upon receiving the request, the target adjacent roadside terminal extracts the identifier, calls its own initial key to decrypt and verify the verification information, and returns a secure communication link containing the initial key to the initiator. The response includes the vehicle's own identifier and encrypted verification information. The initiator also decrypts and verifies the response information. Once both parties pass the verification, a secure communication link between adjacent roadside terminals is established. For the link establishment between a roadside terminal and an access vehicle, after the vehicle enters the communication range of the roadside terminal, it actively sends an access request to the roadside terminal, which includes the vehicle's identity information. After receiving the request, the roadside terminal generates random verification information based on the initial key and sends it to the vehicle. The vehicle processes the verification information using pre-obtained security credentials and returns it. The roadside terminal verifies the validity of the returned result using the initial key. Once the verification is successful, a two-way authenticated secure communication link between the roadside terminal and the vehicle is established.
[0072] Step 2.2, based on the secure communication link, receives the 3D coordinates of each roadside terminal periodically reported by the roadside terminal and the 3D position information of vehicles within the communication range, and aggregates them to form a global 3D point set. Specifically, this includes: setting a fixed reporting period, such as once every 500 milliseconds, based on the established secure communication link, controlling each roadside terminal to periodically collect its own 3D coordinate information; the roadside terminal obtains its own real-time 3D coordinates through its onboard high-precision positioning equipment, and simultaneously uses its own equipped LiDAR, millimeter-wave radar, and camera sensors to perform real-time position detection on each vehicle within the communication range, obtaining the 3D position information of the vehicles. Each roadside terminal, according to the set period, reports its own 3D coordinates and the detected vehicle 3D position information to the global data aggregation node through the secure communication link; after receiving the information reported by each roadside terminal, the global data aggregation node performs integrity verification to ensure that no data is lost or damaged, and then integrates the 3D coordinates of all roadside terminals and the 3D position information of all vehicles to construct a global 3D point set covering the entire vehicle-road cooperative area.
[0073] Step 2.3: Based on the global 3D point set, calculate the Euclidean distance between each vehicle and each roadside terminal using a 3D spatial nearest point pair search algorithm. Dynamically determine and update the spatial association priority list between vehicles and roadside terminals based on the Euclidean distance. Specifically, this includes: calling the 3D spatial nearest point pair search algorithm to process the constructed global 3D point set; firstly, extracting the 3D coordinates of each vehicle and each roadside terminal from the global 3D point set; then, for each vehicle, calculating the Euclidean distance between the vehicle and each roadside terminal one by one, strictly following the calculation logic of the distance between two points in 3D space, combined with the x-axis and y-axis of the vehicle and the roadside terminal. The z-axis coordinates are precisely calculated. After calculating the Euclidean distance between each vehicle and all roadside terminals, these roadside terminals are sorted in order of distance from nearest to farthest. The roadside terminal closest to the vehicle is set to the highest priority, the second closest to the vehicle is set to the second highest priority, and so on, forming a spatial association priority sequence between vehicles and roadside terminals. At the same time, a dynamic update mechanism is set, for example, recalculating the Euclidean distance between vehicles and roadside terminals every 200 milliseconds and adjusting the priority sequence according to the new distance results. This ensures that the vehicle can always maintain a high association priority with the nearest roadside terminal with the best communication conditions while moving, and avoids the association priority from lagging due to vehicle movement.
[0074] Step 2.4: While constructing the global 3D point set, receive the channel quality parameters of 5G, C-V2X, and DSRC communication modes monitored in real time by each roadside terminal. Use the fuzzy comprehensive evaluation method to score the quality of each mode, obtaining an evaluation result that includes the quality scores for each mode. Specifically, while constructing the global 3D point set, control each roadside terminal to monitor the channel quality parameters of the 5G, C-V2X, and DSRC communication modes it supports in real time. The monitored parameters include, but are not limited to, signal strength, receiver sensitivity, end-to-end transmission delay, communication bandwidth, and data packet loss rate for each communication mode, ensuring a comprehensive reflection of the actual communication capabilities of the channel. Each roadside terminal will display the real-time monitored parameters. All channel quality parameters are transmitted to the system's channel quality assessment node via a secure communication link. Upon receiving the parameters, the assessment node uses a fuzzy comprehensive evaluation method to score the quality of each communication mode. First, based on the requirements of the vehicle-road cooperative scenario, the weights of each channel quality parameter are determined. Then, according to preset scoring criteria, the monitoring results of each parameter are scored. Finally, the comprehensive quality score for each communication mode is calculated by combining the weights of each parameter. The assessment node organizes the comprehensive quality scores of all communication modes, filters out communication modes whose comprehensive quality scores reach a preset qualified threshold, and forms a complete assessment result containing the names of available communication modes in each area and their corresponding comprehensive quality scores. The weight matrix... The scoring formula is: 0.4 is the weight for received signal strength, 0.3 is the weight for transmission delay, 0.2 is the weight for available bandwidth, and 0.1 is the weight for packet loss rate. For normalized received signal strength indication, For normalized transmission delay, Normalized available bandwidth, The normalized packet loss rate, This is the transpose operation for a vector.
[0075] In this embodiment of the invention, because it employs a secure communication link with adjacent roadside terminals and access vehicles using an initial key, and periodically reports the three-dimensional coordinates of each roadside terminal and the 3D position information of vehicles within the communication range, and aggregates these to form a global 3D point set, and calculates the Euclidean distance between each vehicle and each roadside terminal using a 3D spatial nearest point search algorithm based on the global 3D point set, dynamically determines and updates the spatial association priority list, and simultaneously receives the channel quality parameters of 5G, C-V2X, and DSRC communication modes monitored in real time by each roadside terminal, and scores the quality of each mode using a fuzzy comprehensive evaluation method, the invention overcomes the limitations of traditional methods. This technology overcomes the technical problems of existing multi-mode communication switching, such as the lack of a secure authentication mechanism that makes it vulnerable to malicious data injection, the failure to consider the spatial association between vehicles and roadside terminals leading to poor switching adaptability, the single channel quality assessment that makes it impossible to accurately select the optimal communication mode, and the lack of two-way authentication in cross-device communication, which poses security vulnerabilities. It achieves the following technical effects: roadside terminals have two-way security protection capabilities for communication with adjacent devices and access vehicles; the spatial association priority between vehicles and roadside terminals can be dynamically adjusted as vehicles move; the quality of multi-mode communication can be accurately quantified and evaluated to support scenario-based selection; and it lays a secure and efficient foundation for message priority scheduling and seamless multi-mode switching. This technology meets the core requirements of vehicle-road cooperation for communication security, real-time performance, and scenario adaptability.
[0076] In a preferred embodiment of the present invention, step 2.4 above may include:
[0077] Step 2.41: Through a secure communication link, receive real-time channel quality parameters for 5G, C-V2X, and DSRC communication modes collected by each roadside terminal. Specifically, this includes: first, controlling each roadside terminal to start the channel quality parameter collection function; collecting four types of core channel quality parameters for 5G, C-V2X, and DSRC communication modes respectively, including signal strength, end-to-end transmission delay, actual communication bandwidth, and data packet loss rate for each mode, ensuring comprehensive coverage of key indicators reflecting channel communication capabilities, and avoiding evaluation bias caused by relying on only a single parameter; during the collection process, the roadside terminal monitors each type of parameter in real time through its own onboard communication module. The changes in parameters are recorded every 100 milliseconds to ensure real-time data accuracy. Subsequently, the roadside terminal transmits the collected parameter data through the established two-way certified secure communication link. Before transmission, the parameter data is encrypted using its own stored initial key to prevent illegal interception, tampering, or forgery during transmission. After receiving the encrypted parameter data sent by each roadside terminal, the channel data receiving node calls the initial key of the corresponding roadside terminal to decrypt the data. At the same time, it performs integrity verification on the decrypted parameter data, checking for missing data and correct format. After confirming that there are no errors, the parameter data is temporarily stored in a temporary database.
[0078] Step 2.42: Based on the collected channel quality parameters, a quality score is calculated for each communication mode using the fuzzy comprehensive evaluation method to obtain an initial score for each communication mode. Specifically, this includes: determining the weights of various channel quality parameters according to the actual communication requirements of the vehicle-road cooperative scenario; considering the extremely high latency requirements for emergency messages such as collision warnings in vehicle-road cooperative systems, the weight of end-to-end transmission delay is set to the highest, followed by data packet loss rate; communication bandwidth and signal strength are then assigned corresponding weights to ensure that the weight allocation meets the security requirements for critical message transmission; next, detailed scoring standards are formulated for each type of parameter, such as signal strength in the range of -70 dB to -50 dB. Within a certain range, a score of 90 to 100 is awarded; below -90 dB, a score of 0 to 30 is awarded. End-to-end transmission delay below 10 milliseconds earns 100 points; 10 to 30 milliseconds earns 80 to 90 points; and exceeding 50 milliseconds earns 0 to 40 points. Other parameters are assigned corresponding scoring ranges based on similar logic. Then, parameter data for each communication mode of each channel-side terminal is extracted from a temporary database, and each parameter is scored according to the scoring criteria to obtain a single score for each parameter. Finally, the single score for each parameter of each communication mode is multiplied by its corresponding weight, and all products are summed to calculate the initial score for the communication mode, achieving a multi-dimensional comprehensive evaluation of channel quality.
[0079] Step 2.43: Based on the initial score, select communication modes that have reached the preset quality threshold to form a candidate communication mode set. Specifically, this includes setting the preset quality threshold by referring to the automotive information security technical requirements standard and the performance requirements for vehicle-road cooperative communication, and combining the transmission requirements of key messages such as traffic light phase data and collision warning messages in actual applications. For example, based on the requirements that the end-to-end latency of critical messages must be ≤50 milliseconds and the data packet loss rate must be ≤1%, the corresponding initial scoring threshold is derived in reverse to ensure that the communication modes that reach the threshold can meet the basic security transmission requirements. Subsequently, the initial scores of each communication mode reported by each roadside terminal are compared one by one, and the communication modes with initial scores greater than or equal to the preset quality threshold are selected. The preset quality threshold is S≥0.8. At the same time, the specific initial scores, communication types, and corresponding roadside terminal identification information of these communication modes are recorded. The selected communication mode information is deduplicated and classified. For example, the 5G qualified modes and C-V2X qualified modes under the same roadside terminal are classified separately, and finally a candidate communication mode set containing the available qualified communication modes of each roadside terminal and their corresponding scores is formed.
[0080] Step 2.44: Based on the candidate communication modality set, obtain a complete evaluation result including the available communication modalities and quality scores for each region. Specifically, this includes: dividing the area according to the actual deployment area of roadside terminals. For example, the entire vehicle-road cooperative area is divided into multiple continuous sub-regions according to the sections of the ring expressway. Each sub-region corresponds to all roadside terminals deployed within it. For each sub-region, extract the qualified communication modality information of all roadside terminals within the region from the candidate communication modality set, count the frequency of occurrence of each type of communication modality within the region, and calculate the average initial score of each type of communication modality within the region. For example, if there are 10 roadside terminals in a sub-region, of which 8 are qualified in C-V2X mode with an average score of 85, and 6 are qualified in 5G mode with an average score of 80, then C-V2X mode is the dominant mode in the region. The system organizes the communication modality types, their respective average scores, frequency of occurrence, and the covered roadside terminal range within each sub-region into structured data, forming a complete evaluation result including the available communication modalities and quality scores for each region.
[0081] In this embodiment of the invention, because the channel quality parameters of 5G, C-V2X, and DSRC communication modes are received in real time from each roadside terminal via a secure communication link, and the initial score of each communication mode is calculated based on the collected multi-dimensional channel quality parameters using a fuzzy comprehensive evaluation method, and the communication modes that reach a preset quality threshold are selected based on the initial scores to form a candidate communication mode set, and then a complete evaluation result containing the available communication modes in each region and their corresponding quality scores is obtained based on the candidate communication mode set, this overcomes the technical means of existing multi-mode communication mode quality evaluation that only relies on the signal-to-noise ratio of a single channel and cannot comprehensively reflect the actual communication mode. The system addresses several technical issues, including the ease with which substandard modes can lead to communication delays or interruptions, the lack of regionalized modal evaluation results, difficulty in adapting to different regional communication scenarios, and even the risk of data injection vulnerabilities due to modal quality defects. This system aims to achieve a multi-dimensional and accurate assessment of the channel quality of each communication mode, ensuring that all candidate communication modes meet the quality requirements of vehicle-road cooperative communication. Furthermore, the comprehensive regionalized evaluation results can accurately match different regional communication scenarios, guaranteeing communication stability and reliability, reducing security risks caused by modal quality issues, and fulfilling the core technical requirements of vehicle-road cooperative systems for communication quality and security.
[0082] In a preferred embodiment of the present invention, step 3 above may include:
[0083] Step 3.1: Based on the spatial association priority list and evaluation results, a global scheduling strategy is obtained. This includes: first, retrieving the generated spatial association priority list and the generated communication modality quality evaluation results from the global data nodes; integrating and dividing these two types of data according to the roadside terminal deployment area to ensure a one-to-one correspondence between the spatial association relationship between vehicles and roadside terminals, the available communication modalities of roadside terminals, and quality scores in each area; for each area, first extracting the spatial association priority information of all vehicles in the area, determining the highest priority roadside terminal currently associated with each vehicle (i.e., the nearest roadside terminal); then retrieving the candidate communication modality set and quality scores of each modality for these high-priority roadside terminals from the evaluation results; then… Based on the message transmission requirements in the vehicle-road cooperative scenario, messages are divided into different priorities according to their urgency. For example, collision warning and fault alarms are the highest priority messages, traffic light phase map data are medium priority messages, and traffic flow statistics are low priority messages. On this basis, communication scheduling rules within the region are formulated. For example, the highest priority messages must be assigned to the communication mode with the highest quality score among the high-priority roadside terminals, and the mode must exclusively occupy the designated channel to ensure transmission speed. Medium and low priority messages can be assigned channels in order of their scores among the remaining qualified modes. At the same time, conflicts between messages of different priorities in the same channel are avoided. The scheduling rules of all regions are integrated to form a global scheduling strategy covering the entire vehicle-road cooperative system.
[0084] Step 3.2: Based on the global scheduling strategy, a scheduling instruction containing channel allocation and resource preemption rules is issued to each roadside terminal. The scheduling instruction categorizes transmitted messages into three levels: P0, P1, and P2. P0 level messages exclusively occupy channel 1 resource in the 5.9GHz spectrum. Specifically, based on the generated global scheduling strategy, a dedicated scheduling instruction is generated for each roadside terminal. This instruction includes two parts: channel allocation rules and resource preemption rules. The channel allocation rules clearly specify the specific frequency bands and channel numbers that each communication mode of the roadside terminal can use. For example, the first channel in the 5.9GHz band is designated as the dedicated channel for the highest priority messages, while the second and third channels are used for medium and low priority message transmission, respectively. The usage time and multiplexing rules for each channel are also indicated to avoid conflicts caused by different roadside terminals transmitting data simultaneously on the same channel. The resource preemption rules specify that when a roadside terminal receives the highest priority message, it must first use the channel with the highest priority message. When a high-priority message is received, the currently ongoing transmission of medium- and low-priority messages can be forcibly paused. CPU computing power and communication channel resources are prioritized for the processing and transmission of the highest-priority message. Transmission of medium- and low-priority messages is resumed only after the transmission of the highest-priority message is completed. After the scheduling instruction is generated, it is sent to the corresponding roadside terminal through the established two-way authenticated secure communication link. Before sending, the instruction is encrypted using the initial key of the roadside terminal to prevent it from being illegally tampered with or forged during transmission. After receiving the encrypted scheduling instruction, each roadside terminal calls its own initial key to decrypt the instruction, performs integrity verification on the instruction content, and confirms that the instruction has not been tampered with and meets the scheduling requirements of its own deployment area. Then, it sends a confirmation message to the feedback instruction receiving center. After receiving confirmation messages from all roadside terminals, the system records the instruction delivery completion status to ensure that the global scheduling strategy is accurately implemented.
[0085] Step 3.3: Based on the execution status of the scheduling instructions and the real-time updated evaluation results, when it is determined that the quality of the current communication mode does not meet the transmission requirements of the current priority message, the optimal alternative mode is selected from the candidate mode set, and a switching instruction is generated. Specifically, this includes: real-time monitoring of the execution status of each roadside terminal in response to the scheduling instructions, including the currently used communication mode, the transmission progress of each priority message, channel occupancy, and other data; simultaneously, receiving real-time communication mode quality evaluation data reported by the roadside terminals through a secure communication link, including the real-time end-to-end transmission delay, data packet loss rate, signal strength changes, etc. of the current mode; and comparing the real-time evaluation data with the preset quality threshold corresponding to the communication mode. The system compares the current transmission message with the priority requirements. For example, if the current transmission is the highest priority message with a preset delay threshold of 10 milliseconds, when the real-time monitoring shows that the transmission delay of the mode exceeds 10 milliseconds or the data packet loss rate exceeds 1%, it is determined that the quality of the current communication mode no longer meets the transmission requirements of the current priority message. At this time, the system selects the optimal alternative mode from the candidate communication modes set of the roadside terminal. The selection criteria are to first select the mode with the highest quality score. If there are multiple modes with the same score, the mode with higher adaptability to the current message type is selected first. For example, the highest priority message will preferentially select the C-V2X mode with lower transmission delay. After determining the optimal alternative mode, a handover instruction is generated.
[0086] Step 3.4: Based on the handover command, coordinate the source roadside terminal and the target roadside terminal to complete time synchronization via the PTP protocol, and sequentially execute pre-connection establishment and data caching to ultimately achieve seamless switching of communication modes, thereby building a unified secure transmission environment. Specifically, this includes: First, coordinating the source roadside terminal currently providing services to the vehicle and the target roadside terminal about to connect, initiating PTP protocol time synchronization. Both the source and target roadside terminals receive PTP protocol signals through their respective time synchronization modules, adjusting their times to ensure the time error is controlled within 5 milliseconds, avoiding timing chaos or data loss during data transmission due to time asynchrony. After time synchronization is complete, control the target roadside terminal to establish a pre-connection with the vehicle in advance according to the target communication mode type in the handover command. The target roadside terminal sends a pre-connection request to the vehicle. After the vehicle verifies the validity of the request through security credentials, it completes the connection with the target roadside terminal. The process involves route negotiation and quality verification to confirm that parameters such as transmission delay and packet loss rate of the pre-connected link meet the requirements. Simultaneously, the source road-side terminal initiates a data caching mechanism, using a sliding window technique to cache data currently being transmitted but for which acknowledgment has not yet been received, ensuring that this data is not lost during the handover process. After the pre-connection is established and data caching is complete, a command to disconnect the old link is sent to the source road-side terminal, causing the source road-side terminal to stop using the original communication mode to transmit data and release the occupied channel resources. At the same time, a command to activate the new link is sent to the target road-side terminal, which continues to transmit the cached data to the vehicle and begins processing new message transmission tasks. After the handover is complete, the transmission quality of the new communication mode of the target road-side terminal is monitored. Once no abnormalities are confirmed, detailed information about the handover is recorded, including the mode type before and after the handover, handover time, and data transmission status. This ultimately constructs a unified and secure transmission environment covering all aspects of the network. The handover trigger condition is that the current mode score S < 0.6 or the signal is interrupted.
[0087] In this embodiment of the invention, because a global scheduling strategy is formulated based on a spatial correlation priority list and communication mode quality assessment results, scheduling instructions containing channel allocation and resource preemption rules are issued to each roadside terminal according to the global scheduling strategy, and the execution status of the scheduling instructions is combined with the real-time updated assessment results, the optimal alternative mode is selected from the candidate mode set and a handover instruction is generated when the current communication mode quality does not meet the message transmission requirements, and the source roadside terminal and the target roadside terminal are coordinated to complete time synchronization through the PTP protocol based on the handover instruction, and pre-connection establishment and data caching are executed sequentially to achieve seamless switching of communication modes, the technical means of overcoming the challenges of communication mode switching are as follows: This invention addresses the technical problems of existing multi-mode communication systems, such as the lack of global scheduling leading to chaotic channel resource allocation, the absence of priority rules for message transmission causing delays in critical messages, mode switching based on a single parameter without time synchronization and pre-connection processes resulting in resource conflicts caused by old interface remnants, and the lack of optimal alternatives for communication interruptions when mode quality is substandard. The invention achieves the following technical effects: globally ordered allocation of channel resources, priority transmission of critical messages such as P0-level emergency messages while meeting latency requirements, avoidance of resource conflicts and data loss during switching, construction of a unified and stable secure transmission environment, and alignment with the low-latency, high-reliability communication requirements of vehicle-road cooperative scenarios.
[0088] In a preferred embodiment of the present invention, step 4 above may include:
[0089] Step 4.1, based on a secure transmission environment, receives and verifies the vehicle registration request and encrypted authentication parameters forwarded by the currently serving roadside terminal to obtain the verified vehicle registration information. Specifically, this includes: First, after a vehicle enters the communication range of a roadside terminal, if it has not yet completed registration, it will actively generate a vehicle registration request. The registration request contains the vehicle's real identity information, factory compliance certificate, and encrypted authentication parameters used for security verification. The encrypted authentication parameters are generated by the vehicle using a pre-obtained temporary security certificate. The vehicle sends the registration request to the currently serving roadside terminal covering it, i.e., the nearest roadside terminal. After receiving the registration request, the currently serving roadside terminal first calls its own [connection / relationship] through the established secure communication link. The initial key performs preliminary decryption and verification of the encrypted authentication parameters in the request. After confirming that the parameter format is legal and the source is not obviously abnormal, the registration request and encrypted authentication parameters are forwarded to the trusted institution in their entirety. During the forwarding process, the data is re-encrypted through a secure link to prevent tampering during transmission. After receiving the forwarded data, the trusted institution, based on the established key system, calls the corresponding decryption mechanism to perform deep verification of the encrypted authentication parameters, compares the consistency between the vehicle identity information and the factory compliance certificate, and checks whether the authentication parameters conform to the preset security format and verification rules. If all verification items pass, the trusted institution confirms the vehicle's legal identity and compiles the vehicle's identity information, registration time, initial security permissions, and other content into verified vehicle registration information.
[0090] Step 4.2: Based on the verified vehicle registration information, a temporary key is generated for the vehicle. According to the relevant roadside terminal set determined by the spatial association priority list, the temporary key is pre-distributed to the current and potential serving roadside terminals via a secure link. Specifically, this includes: the trusted institution initiating a temporary key generation process based on the verified vehicle registration information. During the generation process, the trusted institution calls the hardware security module and, combined with the vehicle's unique identifier, registration timestamp, and master key, generates a temporary key specific to the vehicle. The temporary key generation formula is as follows: ,in, It uses the SM3 cryptographic hash algorithm. For data concatenation operations, As an intermediate variable, , The random number is either pre-set by the system or distributed by a trusted organization. For bitwise XOR operation, A unique identifier for the vehicle. The master key is held by a trusted institution. The system uses a precise timestamp when a vehicle initiates a registration request to ensure that each vehicle's temporary key is unique and strongly bound to its own identity, preventing multiple vehicles from sharing the same temporary key. Subsequently, the trusted authority retrieves the generated spatial association priority list and, based on the vehicle's current location and the deployment range of the current service roadside terminals, determines the set of roadside terminals potentially associated with the vehicle. This set includes not only the current service roadside terminal but also adjacent roadside terminals, i.e., the potential service roadside terminals the vehicle is most likely to connect to during its subsequent movement. Next, the trusted authority distributes the generated temporary key to both the current and potential service roadside terminals via an established two-way authentication secure communication link.
[0091] Step 4.3: Based on the pre-distributed temporary key and the real-time updated spatial association priority list, when a vehicle is detected moving into the communication range of a new roadside terminal, a session key derivation process between the vehicle and the new roadside terminal is triggered. Specifically, this includes: real-time monitoring of vehicle location changes within the communication range using sensors on each roadside terminal; each roadside terminal reporting the monitored vehicle location information to the global location monitoring node via a secure link in real time; and the global location monitoring node continuously tracking the roadside terminal status of each registered vehicle in conjunction with the real-time updated spatial association priority list. When a vehicle's location is detected to exceed the communication range of the currently serving roadside terminal and enter the communication range of another new roadside terminal, the global location monitoring node determines that the vehicle needs to switch serving roadside terminals and immediately sends a switching notification to both the new roadside terminal and the vehicle. After receiving the handover prompt, the vehicle sends an access request to the new roadside terminal. The request includes its unique identifier and identity verification information encrypted with a temporary key. Upon receiving the access request, the new roadside terminal retrieves the pre-stored vehicle temporary key from its own hardware and decrypts and verifies the verification information in the request. After successful verification, the new roadside terminal and the vehicle jointly initiate a session key derivation process based on the pre-stored temporary key. Both parties generate random parameters and interact through a secure link. Combining the temporary key, vehicle identifier, new roadside terminal identifier, and current timestamp, they jointly calculate the session key used for this communication. The entire derivation process does not require requesting a new key from a trusted institution, significantly shortening authentication time, eliminating the security vacuum when the vehicle switches roadside terminals, and ensuring that the vehicle can quickly establish secure communication while moving at high speed.
[0092] In this embodiment of the invention, because it employs a secure transmission environment to receive and verify vehicle registration requests and encrypted authentication parameters forwarded by the currently serving roadside terminal to obtain verified vehicle registration information, generates a temporary key for the vehicle based on the verified vehicle registration information, determines the relevant roadside terminal set according to the spatial association priority list, pre-distributes the temporary key to the currently serving roadside terminal and potential serving roadside terminals through a secure link, and then, based on the pre-distributed temporary key and the real-time updated spatial association priority list, triggers the session key derivation process between the vehicle and the new roadside terminal when the vehicle is detected to have moved into the communication range of a new roadside terminal, the invention overcomes the limitations of traditional methods. This technology addresses the technical issues of existing vehicle registration systems, such as the lack of secure verification leading to identity theft, the absence of a pre-distribution mechanism for temporary keys causing delays when authenticating across roadside terminals due to waiting for cloud responses, creating a security vacuum, and failing to meet the rapid authentication needs of high-speed vehicle movement scenarios. It aims to ensure the legitimacy and authenticity of vehicle registration identities to resist identity forgery attacks. Furthermore, it eliminates the need to reapply for keys from trusted institutions when authenticating across roadside terminals, rapidly generating session keys and significantly reducing authentication time. This also eliminates security gaps when vehicles switch communication nodes, while ensuring the security of key transmission, thus meeting the low-latency, high-security authentication requirements of vehicle-road cooperative scenarios.
[0093] In a preferred embodiment of the present invention, step 5 above may include:
[0094] Step 5.1: Based on the session key, receive the data to be protected submitted by each roadside terminal, and execute the corresponding encryption algorithm according to the data type to obtain encrypted data. Specifically, this includes: First, establishing a dedicated data receiving channel with each intelligent roadside terminal using the generated session key. After collecting the data to be protected, the intelligent roadside terminal first uses its own hardware security module to call the session key to perform preliminary encryption processing on the data, and then submits the encrypted data to be protected to the system's data processing node through a two-way authenticated secure communication link. After receiving the data, the data processing node first decrypts the data using the corresponding session key to obtain the original data to be protected, and at the same time verifies the integrity of the data to confirm that the data has not been lost or damaged during transmission. Subsequently, based on the actual purpose and importance of the data to be protected... The system categorizes data into different types. The PC5 interface uses ECC-P-256+AES-256-CCM, while the Uu interface uses the TLS 1.3 protocol. Data types include emergency data such as collision warning and fault alarms, critical data such as traffic light phase map data, and general data such as traffic flow statistics and equipment status. Corresponding encryption algorithms are applied to each data type. For emergency and critical data, high-strength encryption algorithms conforming to standards are used to ensure absolute security during data transmission and storage. For general data, lightweight encryption algorithms that balance security and efficiency are used to ensure basic security while avoiding resource waste caused by excessive encryption. After encryption, the generated encrypted data is temporarily stored in an encrypted database with hardware protection to prevent unauthorized access during storage.
[0095] Step 5.2: Based on the encrypted data, extract key metadata and combine it with the roadside terminal identifier and precise timestamp to obtain a tamper-proof traceability tag. Specifically, this includes: extracting key metadata reflecting the core characteristics of the data from the temporarily stored encrypted data. This metadata includes information such as data type identifier, data transmission priority level, original data length, and data encryption algorithm type, ensuring that the basic attributes of the data can be quickly understood during subsequent traceability; simultaneously, retrieving the globally unique identifier of the intelligent roadside terminal from which the data originated. This identifier is assigned to the intelligent roadside terminal to accurately locate the source of the data; furthermore, using PTP (Precision Time Point) for precise... The time protocol obtains the current precise timestamp, accurate to the millisecond level, ensuring that the accurate moment of data encryption generation can be recorded, meeting the high time accuracy requirements in vehicle-road cooperative scenarios. Next, the initial key stored in the intelligent roadside terminal, the data source, is called to integrate the extracted key metadata, the globally unique identifier of the intelligent roadside terminal, and the precise timestamp to generate a piece of original tag information in a fixed format. Subsequently, the hash algorithm in the standard is used to calculate the tag original information to generate a tag hash value, and then the hash value is signed with the exclusive key of the intelligent roadside terminal to form a tamper-proof traceability tag.
[0096] Step 5.3: Based on the encrypted data and traceability tags, securely bind the encrypted data and traceability tags to obtain a complete encrypted and tagged data packet. Specifically, this includes: first, constructing a unified data packet structure, divided into a data area and a tag area. The data area stores the generated encrypted data, and the tag area stores the generated tamper-proof traceability tags; after filling the encrypted data and traceability tags into their respective areas, using the current session key to encrypt the header information of the entire data packet. The header information includes the total length of the data packet, the length of the data area, the length of the tag area, and the data checksum generation rules; subsequently, based on the encrypted data and traceability tags... The content of the tag is processed using a hash algorithm to generate a unified data packet checksum. This checksum is then appended to the end of the data packet as a verification of the binding integrity. After the structure is completed, the entire data packet is encrypted a second time using a session key to ensure that the encrypted data and the traceability tag remain bound together during transmission and storage, preventing separation or individual tampering. Finally, the generated complete encrypted and tagged data packet is stored in a distributed security database, along with the storage location and access permissions of the data packet. This ensures that when subsequent calls or traceability are needed, the data packet can be quickly located and the binding validity of the encrypted data and the traceability tag can be verified.
[0097] In this embodiment of the invention, by employing a technique that receives data to be protected submitted by each roadside terminal based on a session key and executes the corresponding encryption algorithm according to the data type, extracts key metadata from the encrypted data and generates an anti-tampering traceability tag by combining the roadside terminal identifier and precise timestamp of the data source, and then securely binds the encrypted data with the traceability tag, the technical problems of existing data encryption not being differentiated according to type, resulting in insufficient protection of key data or redundant encryption of ordinary data, lack of dedicated anti-tampering traceability information for data leading to the inability to locate the source node after leakage, and separation of encrypted data and traceability information making it difficult to associate and trace, the invention achieves adaptive encryption protection for different types of data to balance security and transmission efficiency, and allows for precise location of the source roadside terminal and generation time through the traceability tag throughout the entire data lifecycle. The binding of encrypted data and traceability tag ensures that the traceability information is not tampered with or separated from the data subject, meeting the Level 3 requirements of the Information Security Protection System 2.0 and the Internet of Vehicles security compliance requirements, effectively resisting data tampering and forgery attacks, and achieving rapid traceability after data leakage.
[0098] In a preferred embodiment of the present invention, step 6 above may include:
[0099] Step 6.1: Based on the encrypted and tagged data, coordinate the execution of real-time edge analysis tasks by each roadside terminal and receive the returned analysis results. Specifically, this includes: first, classifying and organizing the encrypted and tagged data; then, according to the deployment area and data type of the associated roadside terminal, allocating the data to the corresponding roadside terminals. During the allocation process, considering the real-time computing load of each roadside terminal, avoid analysis delays caused by excessive workload on a single roadside terminal, ensuring the real-time performance of edge processing. After receiving the allocated encrypted and tagged data, each roadside terminal first calls the session key in its own hardware security module to decrypt the data. Simultaneously, the integrity of the traceability label is verified to confirm that the data has not been tampered with and that its source is legitimate. After verification, the roadside terminal starts the preset edge-side real-time analysis algorithm to process the decrypted raw data, such as identifying anomalies in traffic target trajectory data, detecting faults in equipment operating parameters, and monitoring abnormal behavior in communication data. After the analysis is completed, the roadside terminal sends the analysis results, including normal data statistics, abnormal event types, and the time and location of the anomalies, back to the global data aggregation node through a secure communication link. The global data aggregation node summarizes and organizes the analysis results returned by all roadside terminals and removes duplicate information.
[0100] Step 6.2: Based on the aggregated analysis results of each roadside terminal, assess the current network security status and trigger the quantum key negotiation mechanism to dynamically generate a new group key. Specifically, this includes: retrieving the aggregated analysis results of each roadside terminal from the global data aggregation node; initiating the network security status assessment process; during the assessment, the system sets multi-dimensional assessment indicators, including the frequency of abnormal data occurrences, the severity of abnormal events, key usage duration, and signs of communication link attacks. For example, if abnormal records of data tampering attempts appear continuously in a certain area, or the usage duration of a certain group key exceeds a preset security period, or an illegal access request is detected on the communication link, the current network security status is deemed to be at risk. After the assessment, if the network security status is deemed good and the key has not reached its update cycle, the current key system is maintained; if a security risk is deemed to exist or the key needs to be updated, the quantum key negotiation mechanism BB84 protocol is immediately triggered. After the quantum key negotiation mechanism is initiated, a trusted institution acts as the coordinating core, uniting all roadside terminals in the network to participate in key negotiation. During the negotiation process, highly secure random key materials are generated using quantum communication technology, combined with the unique identifier of the roadside terminal, the current timestamp, and the network security status assessment results, and through multiple rounds of interactive verification, a new group key is dynamically generated.
[0101] Step 6.3: Based on the newly generated group key, distribute the newly generated group key to all network-side terminals via a secure link to complete the synchronous update of the group key materials. Specifically, this includes: After the new group key is generated, the trusted organization first stores the group key in its own hardware security module for temporary protection, and then initiates the network-wide distribution process; before distribution, the trusted organization uses the initial key of each network-side terminal to individually encrypt the new group key, ensuring that the group key received by each network-side terminal is exclusively encrypted, preventing the key from being intercepted and cracked during distribution. The distribution process is carried out through an established two-way authenticated secure communication link. The system distributes the encrypted new group key to all network-side terminals in batches according to region. To avoid network congestion caused by centralized distribution, each roadside terminal receives the encrypted new group key, decrypts it using its own initial key, stores the new group key in the hardware, and overwrites the old group key. After storage, the roadside terminal sends a key update confirmation message to the trusted authority, which includes a checksum of the new group key. After receiving the confirmation message from each roadside terminal, the trusted authority verifies the checksum to ensure that the roadside terminal has successfully received and correctly stored the new group key. Once all roadside terminals have responded with confirmation messages, the group key is synchronously updated. If any roadside terminal fails to respond, the distribution is re-initiated until all roadside terminals in the network have completed the update.
[0102] Step 6.4: Based on the updated group key materials, establish a new secure communication cycle to achieve continuous security enhancement and dynamic maintenance of the full key materials. Specifically, this includes: after all network-side terminals complete the group key synchronization update, a new secure communication cycle is initiated. In this new cycle, the network-side terminals, based on the updated group key, regenerate various key materials such as session keys and temporary keys, replacing the original old key materials for data encryption, authentication, and other security operations. A dynamic maintenance mechanism is set up, including periodic security status assessments and adaptive adjustments to the key update cycle. For example, based on the network security status assessment results, if the security risk is high, the cycle can be shortened. Key update cycle; if the security status is stable, the update cycle can be appropriately extended, but it shall not exceed the security cycle specified in the Level 3 standard of the Information Security Protection 2.0 standard; at the same time, record the key update log for each round of secure communication cycle, including key generation time, distribution completion time, usage cycle, update reason and other information, to form a complete key operation audit record, meet the security compliance requirements of vehicle-road cooperative system, and achieve continuous security enhancement and dynamic maintenance of all key materials through the process of continuous analysis and evaluation, key generation, synchronous update and periodic maintenance, solve the problem of lack of update mechanism in traditional static key system, and continuously improve the overall security protection capability of vehicle-road cooperative system.
[0103] In this embodiment of the invention, by employing data coordination based on encryption and tagging to enable each roadside terminal to perform real-time edge analysis tasks and receive analysis results, assessing the current network security status based on the aggregated analysis results, triggering a quantum key negotiation mechanism to dynamically generate a new group key, distributing the new group key to all roadside terminals across the network through a secure link to complete synchronous updates, and establishing a new round of secure communication cycle based on the updated group key material to achieve continuous security enhancement and dynamic maintenance of all key materials, this invention overcomes the technical problems of existing systems where the key system is static and lacks a dynamic update mechanism, group keys cannot be adjusted in real time according to network security status, edge-side data processing is scattered, leading to delayed security assessment, and untimely synchronization of keys across the network easily causes security vulnerabilities. This achieves the technical effects of improved real-time edge data analysis response speed, adaptation of group key generation and updates to dynamic network security changes to reduce the risk of key leakage, consistency and synchronization of key materials across all roadside terminals to ensure cross-terminal communication security, and dynamic maintenance of the entire key lifecycle to meet the Level 3 requirements of the Information Security Protection Standard 2.0 and vehicle-to-everything (V2X) security compliance requirements, continuously strengthening the overall security protection capabilities of the vehicle-road cooperative system.
[0104] like Figure 2 As shown, embodiments of the present invention also provide a smart roadside terminal security processing system based on multi-mode communication collaboration and dynamic key chain, comprising:
[0105] The registration module is used to register roadside terminals based on the master key obtained from a trusted institution, and to assign a unique identifier (roadside terminal ID) and an initial key to each roadside terminal.
[0106] The evaluation module is used to establish a secure link through an initial key. The roadside terminal collects its own 3D spatial location information and the access vehicles to form a 3D point set to determine the spatial association priority between the vehicle and each roadside terminal. At the same time, it evaluates the channel quality of the communication mode in real time to obtain the evaluation result.
[0107] The transmission module is used to prioritize and schedule transmission messages based on spatial association priority and evaluation results, and to perform seamless switching between multiple modes based on the PTP protocol to obtain a secure transmission environment that enables collaborative communication.
[0108] The authentication module is used to obtain a temporary key and distribute it to the relevant roadside terminals through a secure link when a vehicle registers and accesses a trusted institution, based on a secure transmission environment; when the vehicle moves across roadside terminals, a session key for authentication is generated in real time based on the temporary key.
[0109] The encryption module is used to encrypt and protect the data throughout the process based on the session key, and generate a tamper-proof traceability tag for each piece of data to obtain encrypted and tagged data.
[0110] The update module is used for real-time edge analysis tasks performed by the roadside terminal based on encrypted and tagged data. According to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminal through a quantum key negotiation mechanism. The new group key is stored in the hardware security module to achieve dynamic synchronization and security enhancement of all key materials.
[0111] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for secure processing of intelligent roadside terminals based on multi-mode communication collaboration and dynamic key chains, characterized in that, The method includes: Based on the master key obtained from a trusted institution, the roadside terminals are registered using the master key, and each roadside terminal is assigned a unique identifier (roadside terminal ID) and an initial key. A secure link is established using an initial key. Roadside terminals collect their own 3D spatial location information and that of accessing vehicles, forming a 3D point set to determine the spatial association priority between vehicles and each roadside terminal. Simultaneously, the channel quality of the communication modes is evaluated in real time to obtain evaluation results, including: Control each registered roadside terminal to establish a secure communication link with the initial key and adjacent roadside terminals and access vehicles through two-way authentication; Based on the secure link, it receives the three-dimensional coordinates of itself and the 3D position information of vehicles within the communication range periodically reported by each roadside terminal, and aggregates them to form a global 3D point set. Based on a global 3D point set, the Euclidean distance between each vehicle and each roadside terminal is calculated using a 3D spatial nearest point pair search algorithm. The spatial association priority list between vehicles and roadside terminals is dynamically determined and updated based on the Euclidean distance. While constructing a global 3D point set, the channel quality parameters of 5G, C-V2X and DSRC communication modes monitored in real time by each roadside terminal are received. The quality score of each mode is scored by the fuzzy comprehensive evaluation method to obtain the evaluation result containing the quality score of each mode. Priority scheduling of transmitted messages is performed based on spatial association priority and evaluation results, and seamless switching between multiple modes is performed based on the PTP protocol to obtain a secure transmission environment that enables collaborative communication. Based on a secure transmission environment, when a vehicle registers and accesses a trusted institution, it obtains a temporary key and distributes it to relevant roadside terminals via a secure link. During the vehicle's movement across roadside terminals, a session key for authentication is derived in real-time based on the temporary key, including: Based on a secure transmission environment, the system receives and verifies vehicle registration requests and encrypted authentication parameters forwarded by the current service roadside terminal in order to obtain verified vehicle registration information. Based on the verified vehicle registration information, a temporary key is generated for the vehicle, and according to the relevant roadside terminal set determined by the spatial association priority list, the temporary key is pre-distributed to the current serving roadside terminal and potential serving roadside terminal through a secure link. Based on the pre-distributed temporary key and the real-time updated spatial association priority list, when a vehicle is detected to have moved into the communication range of a new roadside terminal, the session key derivation process between the vehicle and the new roadside terminal is triggered. Based on the session key, the data is encrypted and protected throughout the process, and a tamper-proof traceability tag is generated for each piece of data to obtain encrypted and tagged data. Based on encrypted and tagged data, the roadside terminal performs real-time edge analysis tasks. According to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminal through a quantum key negotiation mechanism. The new group key is stored in the hardware security module to achieve dynamic synchronization and security enhancement of all key materials.
2. The intelligent roadside terminal security processing method based on multi-mode communication collaboration and dynamic key chain according to claim 1, characterized in that, Based on the master key obtained from a trusted institution, roadside terminals are registered using the master key. Each roadside terminal is assigned a unique identifier (Roadside Terminal ID) and an initial key, including: Based on a trusted institution, the master key is obtained, and registration requests sent by each roadside terminal are received; Each roadside terminal requesting registration is assigned a globally unique identifier. Based on the master key and the assigned identifier, the initial key of the corresponding roadside terminal is obtained through hash operation. The initial key is securely distributed to the corresponding roadside terminal to complete the registration and initialization process.
3. The intelligent roadside terminal security processing method based on multi-mode communication collaboration and dynamic key chain according to claim 2, characterized in that, While constructing a global 3D point set, channel quality parameters of 5G, C-V2X, and DSRC communication modes are received in real time from each roadside terminal. A fuzzy comprehensive evaluation method is used to score the quality of each mode, yielding an evaluation result that includes the quality scores for each mode, including: Through a secure communication link, the system receives real-time channel quality parameters of 5G, C-V2X, and DSRC communication modes from each roadside terminal. Based on the collected channel quality parameters, the quality score of each communication mode is calculated by fuzzy comprehensive evaluation method to obtain the initial score of each communication mode; Based on the initial score, communication modes that reach the preset quality threshold are selected to form a candidate communication mode set; Based on the candidate communication modal set, a complete evaluation result including the available communication modalities and quality scores for each region is obtained.
4. The intelligent roadside terminal security processing method based on multi-mode communication collaboration and dynamic key chain according to claim 3, characterized in that, Based on spatial association priority and evaluation results, priority scheduling of transmitted messages is performed, and seamless switching between multimodal modes is executed based on the PTP protocol, resulting in a secure transmission environment for cooperative communication, including: Based on the spatial association priority list and evaluation results, a global scheduling strategy is obtained; Based on the global scheduling strategy, scheduling instructions containing channel allocation and resource preemption rules are issued to each roadside terminal. In the scheduling instructions, the transmission messages are divided into three levels: P0, P1, and P2. Among them, the P0 level messages exclusively occupy the channel 1 resource of the 5.9GHz spectrum. Based on the execution status of the scheduling instructions and the real-time updated evaluation results, when it is determined that the quality of the current communication mode does not meet the transmission requirements of the current priority message, the optimal alternative mode is selected from the candidate mode set, and a switching instruction is generated. Based on the switching command, the source roadside terminal and the target roadside terminal are coordinated to complete time synchronization through the PTP protocol, and pre-connection establishment and data caching are executed in sequence to achieve seamless switching of communication modes, thereby building a unified and secure transmission environment.
5. The intelligent roadside terminal security processing method based on multi-mode communication collaboration and dynamic key chain according to claim 4, characterized in that, Based on the session key, the data is encrypted and protected throughout the process, and a tamper-proof traceability tag is generated for each piece of data, resulting in encrypted and tagged data, including: Based on the session key, the system receives data to be protected submitted by each roadside terminal and executes the corresponding encryption algorithm according to the data type to obtain encrypted data. Based on encrypted data, key metadata is extracted and combined with the roadside terminal identifier and precise timestamp of the data source to obtain a tamper-proof traceability label; Based on encrypted data and traceability tags, the encrypted data and traceability tags are securely bound together to obtain a complete encrypted and tagged data package.
6. The intelligent roadside terminal security processing method based on multi-mode communication collaboration and dynamic key chain according to claim 5, characterized in that, Based on encrypted and tagged data, roadside terminals perform real-time edge-side analysis tasks. According to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminals via a quantum key negotiation mechanism. The new group key is stored in a hardware security module, achieving dynamic synchronization and security enhancement of all key materials, including: Based on encrypted and tagged data, coordinate the execution of real-time edge analysis tasks by each roadside terminal and receive the returned analysis results; Based on the aggregated analysis results of various side terminals, the current network security status is assessed, and a quantum key negotiation mechanism is triggered to dynamically generate a new group key; Based on the newly generated group key, the newly generated group key is distributed to all network-side terminals through a secure link to complete the synchronous update of the group key material; Based on the updated group key material, a new round of secure communication cycle is established to achieve continuous security enhancement and dynamic maintenance of the full key material.
7. A smart roadside terminal security processing system based on multi-mode communication collaboration and dynamic key chain, wherein the system implements the method as described in any one of claims 1 to 6, characterized in that, include: The registration module is used to register roadside terminals based on the master key obtained from a trusted institution, and to assign a unique identifier (roadside terminal ID) and an initial key to each roadside terminal. The evaluation module is used to establish a secure link through an initial key. The roadside terminal collects its own 3D spatial location information and the access vehicles to form a 3D point set to determine the spatial association priority between the vehicle and each roadside terminal. At the same time, it evaluates the channel quality of the communication mode in real time to obtain the evaluation result. The transmission module is used to prioritize and schedule transmission messages based on spatial association priority and evaluation results, and to perform seamless switching between multiple modes based on the PTP protocol to obtain a secure transmission environment that enables collaborative communication. The authentication module is used to obtain a temporary key and distribute it to the relevant roadside terminals through a secure link when a vehicle registers and accesses the network with a trusted institution, based on a secure transmission environment. As the vehicle moves across the roadside terminal, a session key for authentication is generated in real time based on the temporary key; The encryption module is used to encrypt and protect the data throughout the process based on the session key, and generate a tamper-proof traceability tag for each piece of data to obtain encrypted and tagged data. The update module is used for real-time edge analysis tasks performed by the roadside terminal based on encrypted and tagged data. According to the aggregated data, a new group key is dynamically generated and securely distributed to the roadside terminal through a quantum key negotiation mechanism. The new group key is stored in the hardware security module to achieve dynamic synchronization and security enhancement of all key materials.
Citation Information
Patent Citations
Vehicle identity anonymous authentication method in space-air-ground fusion vehicle-mounted network
CN120825699A
Identity authentication system for distributed Internet of vehicles
US12224994B1