A Dynamically Immune End-to-End Trusted Sharing Method for Multimodal Data in Vehicle-Road-Cloud Systems

By performing secure encapsulation and dynamic trust assessment on multimodal data in the vehicle-road-cloud system, the problem of ensuring the trustworthiness of shared data in existing technologies is solved, achieving adaptive internal threat protection and trusted data sharing, thereby improving the security and efficiency of the system.

CN121750377BActive Publication Date: 2026-05-26HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)
Filing Date
2026-02-27
Publication Date
2026-05-26

Smart Images

  • Figure CN121750377B_ABST
    Figure CN121750377B_ABST
Patent Text Reader

Abstract

The present invention provides a dynamic immune end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system, belonging to the field of information security technology. The method includes: using a vehicle-side or roadside unit with a digital certificate as the sending end, securely encapsulating the original multimodal data to generate a secure encapsulation result, and transmitting the secure encapsulation result to a cloud platform; using the cloud platform as the receiving end, recovering the original multimodal data; using the cloud platform to perform a trustworthiness assessment of the sending end based on the recovered original multimodal data (both current and historical), obtaining multi-dimensional assessment indicators; using a preset trust fusion model combined with the multi-dimensional assessment indicators to calculate and generate a dynamic trust value for the sending end; and triggering corresponding security handling strategies based on the dynamic trust value. This invention, through the synergistic linkage of dynamic trust value and security strategies, enables the system to possess adaptive perception and proactive immunity against internal threats, effectively ensuring the trustworthiness of shared data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a dynamic immune end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system. Background Technology

[0002] As the core support architecture for intelligent transportation, the vehicle-road-cloud system achieves the collection, transmission and sharing of massive multimodal data (including vehicle trajectories, sensor streams, video images and traffic event information) through deep collaboration between vehicles, roadside infrastructure and cloud platforms, providing a data foundation for applications such as high-level autonomous driving, proactive traffic command and control, and traffic efficiency optimization.

[0003] However, when achieving trusted cross-domain data sharing, existing security systems primarily rely on static identity authentication provided by Public Key Infrastructure (PKI). The static nature of this model makes it difficult to adaptively and continuously measure and evaluate the behavioral trustworthiness of authenticated entities (such as vehicles and roadside units). Therefore, when the keys of legitimate nodes are stolen, the system struggles to effectively identify and block internal threats launched by attackers using their legitimate identities, making it difficult to guarantee the trustworthiness of shared data.

[0004] Therefore, existing technologies have shortcomings and need to be improved and developed. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a dynamic immune end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system, which addresses the above-mentioned deficiencies of the prior art and aims to solve the problem that the prior art cannot guarantee the trustworthiness of shared data.

[0006] The technical solution adopted by this invention to solve the technical problem is as follows:

[0007] This invention provides a dynamically immune end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system. The method is applied to a vehicle-road-cloud system comprising vehicle-end devices, roadside units, and a cloud platform. The method includes:

[0008] The vehicle-side or roadside unit that has obtained a digital certificate acts as the sending end, securely encapsulates the original multimodal data, generates a secure encapsulation result, and transmits the secure encapsulation result to the cloud platform through a preset communication link;

[0009] Using the cloud platform as the receiving end, the received secure encapsulation result is decrypted and verified. If the verification is successful, it is considered that the original multimodal data has been recovered.

[0010] The cloud platform is used to assess the credibility of the sending end based on the original multimodal data recovered from the current and historical data. This results in a multi-dimensional assessment index, including data rationality index, behavior consistency index, historical reputation score index, and communication behavior index. A preset trust fusion model is used to calculate the dynamic trust value of the sending end in combination with the multi-dimensional assessment index. Based on the dynamic trust value, a corresponding security handling strategy is triggered.

[0011] In one implementation, the original multimodal data is securely encapsulated to generate a secure encapsulation result, including:

[0012] Obtain the preset data volume classification threshold;

[0013] If the amount of the original multimodal data is less than or equal to the data amount classification threshold, then the original multimodal data is securely encapsulated using the first encryption mode to generate a first secure encapsulation result.

[0014] If the amount of the original multimodal data is greater than the data volume classification threshold, then the original multimodal data is securely encapsulated using a second encryption mode to generate a second secure encapsulation result.

[0015] In one implementation, the original multimodal data is securely encapsulated using a first encryption mode to generate a first secure encapsulation result, including:

[0016] Calculate the SM3 hash value of the original multimodal data;

[0017] The SM3 hash value is digitally signed using the SM2 signature private key of the sending end to obtain a signature;

[0018] The original multimodal data is concatenated with the signature to obtain the first data packet;

[0019] The first data packet is encrypted using the SM2 encryption public key of the cloud platform to obtain the first encrypted ciphertext as the first secure encapsulation result.

[0020] In one implementation, a second encryption mode is used to securely encapsulate the original multimodal data to generate a second secure encapsulation result, including:

[0021] The SM4 session key is randomly generated using the vehicle-mounted or roadside unit;

[0022] The original multimodal data is encrypted using the SM4 session key and the SM4 algorithm to obtain ciphertext.

[0023] Calculate the SM3 hash value of the SM4 session key, and sign the SM3 hash value of the SM4 session key using the SM2 signing private key of the sending end to obtain the key signature;

[0024] The SM4 session key and the key signature are combined into a key package, and the key package is encrypted using the SM2 encryption public key of the cloud platform to obtain the key ciphertext;

[0025] The data packet composed of the data ciphertext and the key ciphertext serves as the second secure encapsulation result.

[0026] In one implementation, the cloud platform is used as the receiving end to decrypt and verify the received secure encapsulation result. If the verification is successful, it is considered that the original multimodal data has been recovered, including:

[0027] Using the cloud platform as the receiving end, the corresponding decryption and verification path is selected for processing based on the structural characteristics of the received secure encapsulation result;

[0028] If the security encapsulation result is the first security encapsulation result, then the first decryption mode is used for decryption and verification. If the verification is successful, it is considered that the original multimodal data has been recovered.

[0029] If the security encapsulation result is the second security encapsulation result, then the second decryption mode is used for decryption and verification. If the verification is successful, it is considered that the original multimodal data has been recovered.

[0030] In one implementation, a dynamic trust value for the sending end is generated by calculating using a preset trust fusion model combined with the multi-dimensional evaluation indicators, including:

[0031] The multi-dimensional evaluation indicators are substituted into the preset trust fusion model for calculation to obtain the dynamic trust value of the sending end.

[0032] The trust fusion model is expressed as follows: , It is a dynamic trust value. , , , To preset weights, , It is a data rationality indicator. As an indicator of behavioral consistency, It is a historical credit indicator. It is a communication behavior indicator.

[0033] In one implementation, the data rationality index is used to quantitatively evaluate the credibility of the recovered original multimodal data in terms of physical laws, logical relationships, and spatiotemporal consistency. The behavior consistency index is used to quantitatively evaluate the degree of collaborative verification between the original multimodal data reported by the sending end and the external environment and other independent information source data. The historical reputation score index is used to quantify the accuracy and reliability of the sending source's behavior in history. The communication behavior index is used to quantify the normality and security of the sending source's data reporting behavior at the communication mode level.

[0034] In one implementation, before triggering the corresponding security handling strategy based on the dynamic trust value, the method further includes:

[0035] Preset a first trust threshold, a second trust threshold, and a revocation threshold;

[0036] Wherein, the first trust threshold is greater than the second trust threshold, and the second trust threshold is greater than the revocation threshold.

[0037] In one implementation, triggering a corresponding security handling strategy based on the dynamic trust value includes:

[0038] When the dynamic trust value is greater than the preset first trust threshold, it is determined to be in a healthy state, and the normal data sharing permission of the sending end is maintained.

[0039] When the dynamic trust value is greater than the preset second trust threshold and less than or equal to the preset first trust threshold, it is determined to be a warning state, and the upload rate limit or access permission downgrade is implemented on the sending end.

[0040] When the dynamic trust value is less than or equal to the preset second trust threshold, it is determined to be in a processing state, and an instruction is sent to the sending end to control the sending end to use the first encryption mode for secure encapsulation.

[0041] In one implementation, triggering a corresponding security action strategy based on the dynamic trust value further includes:

[0042] When the number of consecutive preset number of times the dynamic trust value is lower than the preset revocation threshold, the digital certificate of the sending end is revoked.

[0043] The beneficial effects of this invention are as follows: This invention uses a vehicle-side or roadside unit with an acquired digital certificate as the transmitting end to securely encapsulate the original multimodal data, generate a secure encapsulation result, and transmit the secure encapsulation result to a cloud platform. The cloud platform acts as the receiving end, recovering the original multimodal data. Based on the recovered original multimodal data from the current and historical sources, the cloud platform performs a credibility assessment of the transmitting end, obtaining multi-dimensional evaluation indicators. A preset trust fusion model is used in conjunction with these multi-dimensional evaluation indicators to calculate and generate a dynamic trust value for the transmitting end. Based on this dynamic trust value, corresponding security measures are triggered. This invention, through the synergistic linkage of dynamic trust value and security policies, enables the system to possess adaptive perception and proactive immunity against internal threats, effectively ensuring the trustworthiness of shared data. Attached Figure Description

[0044] Figure 1 This is a flowchart of a preferred embodiment of the dynamic immune vehicle-road-cloud system multimodal data end-to-end trusted sharing method in this invention.

[0045] Figure 2 This is a schematic diagram of an adaptive encryption and transmission process at the sending end according to the present invention.

[0046] Figure 3 This is a schematic diagram of a process for generating dynamic trust values ​​according to the present invention.

[0047] Figure 4 This is a schematic diagram of the data processing flow of the present invention.

[0048] Figure 5 This is a schematic diagram of a preferred embodiment of the dynamic immune vehicle-road-cloud system multimodal data end-to-end trusted sharing system in this invention.

[0049] Figure 6 This is a block diagram of the terminal principle of the present invention. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of this invention clearer and more explicit, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0051] As the core support architecture for intelligent transportation, the vehicle-road-cloud system achieves the collection, transmission and sharing of massive multimodal data (including vehicle trajectories, sensor streams, video images and traffic event information) through deep collaboration between vehicles, roadside infrastructure and cloud platforms, providing a data foundation for applications such as high-level autonomous driving, proactive traffic command and control, and traffic efficiency optimization.

[0052] However, when achieving trusted cross-domain data sharing, existing security systems primarily rely on static identity authentication provided by Public Key Infrastructure (PKI). The static nature of this model makes it difficult to continuously measure and evaluate the behavioral trustworthiness of authenticated entities (such as vehicles and roadside units). Therefore, when the keys of legitimate nodes are stolen, the system struggles to effectively identify and block internal threats launched by attackers using their legitimate identities, making it difficult to guarantee the trustworthiness of shared data.

[0053] To address the aforementioned deficiencies in existing technologies, this invention provides a dynamically immune end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system. The method includes: using a vehicle-side or roadside unit with a digital certificate as the sender, securely encapsulating the original multimodal data to generate a secure encapsulation result, and transmitting the secure encapsulation result to a cloud platform; using the cloud platform as the receiver, recovering the original multimodal data; using the cloud platform to perform a trustworthiness assessment of the sender based on the recovered original multimodal data (both current and historical), obtaining multi-dimensional assessment indicators; using a preset trust fusion model combined with the multi-dimensional assessment indicators to calculate and generate a dynamic trust value for the sender; and triggering corresponding security measures based on the dynamic trust value. This invention, through the synergistic linkage of dynamic trust values ​​and security policies, enables the system to possess adaptive perception and proactive immunity against internal threats, effectively ensuring the trustworthiness of shared data.

[0054] Please see Figure 1 The dynamic immune vehicle-road-cloud system multimodal data end-to-end trusted sharing method described in this embodiment of the invention is applied to a vehicle-road-cloud system including vehicle terminals, roadside units, and a cloud platform, and includes the following steps:

[0055] Step S100: The vehicle-side or roadside unit that has obtained a digital certificate acts as the sending end, performs secure encapsulation on the original multimodal data, generates a secure encapsulation result, and transmits the secure encapsulation result to the cloud platform through a preset communication link.

[0056] Specifically, in the vehicle-road-cloud system, the vehicle-side is a multimodal data intelligent perception and transmission system with communication and interaction capabilities, capable of uploading collected data to the cloud. Roadside units (RSUs) are multimodal data intelligent perception and communication devices installed on both sides of roads (such as traffic light poles, streetlights, and highways). The vehicle-side and RSUs, as core edge-side perception nodes, continuously collect multimodal raw data, including vehicle trajectory, vehicle sensor data (such as vehicle speed, acceleration, tire pressure, etc.), video images (road conditions, driver's cab conditions, surrounding environment, etc.), and traffic event information (such as accidents, congestion, construction). After being uploaded to the cloud platform and fused, this data supports applications such as global traffic situation generation, intelligent congestion point diagnosis, traffic light timing optimization, and autonomous driving model training, which are crucial for realizing intelligent transportation. However, the high dependence of these applications also makes the data itself a potential target for attacks. If the data is tampered with, forged, or leaked during transmission or use, it will directly lead to data-driven decision-making errors and cause serious security consequences. Therefore, data must be strictly encapsulated for security before it leaves the sending end.

[0057] In one implementation, the original multimodal data is securely encapsulated to generate a secure encapsulation result, including:

[0058] Obtain the preset data volume classification threshold;

[0059] If the amount of the original multimodal data is less than or equal to the data amount classification threshold, then the original multimodal data is securely encapsulated using the first encryption mode to generate a first secure encapsulation result.

[0060] If the amount of the original multimodal data is greater than the data volume classification threshold, then the original multimodal data is securely encapsulated using a second encryption mode to generate a second secure encapsulation result.

[0061] Specifically, data volume classification threshold Instead of fixed values, the cloud platform can dynamically issue adjustment commands to vehicle / roadside units based on real-time network load, its own computing resources, and data type to achieve an optimal balance between safety and efficiency. This involves acquiring raw multimodal data. Then, the multimodal raw data can be determined at the sending end. and data volume classification threshold The relationships between the data are defined, and different encryption methods are used for encapsulation based on these relationships. The first encryption mode is designed for lightweight data, with its core advantage being a simple process. It simultaneously achieves encrypted data transmission, integrity verification, and authentication through a single asymmetric encryption process, resulting in a compact structure and comprehensive functionality. Due to the small data volume, the performance overhead of asymmetric encryption is within acceptable limits, avoiding the complex management of symmetric keys and providing high-strength security protection for critical data in the most direct way. The second encryption mode employs hybrid encryption to address the performance bottleneck of heavyweight data. It fully leverages the dual advantages of fast symmetric encryption processing and convenient asymmetric encryption key exchange, ensuring not only high efficiency in large-scale data encryption but also enhancing system security and flexibility through its one-time session key mechanism.

[0062] In one implementation, the data volume classification threshold Set to 1KB.

[0063] Raw multimodal data with a data volume classification threshold less than or equal to the data volume can be considered lightweight data. In this case, a first encryption mode based on asymmetric encryption can be used. The first encryption mode may include the following steps: calculating the SM3 hash value of the raw multimodal data. Use the sender's SM2 signing private key to hash the SM3 value. Perform digital signature to obtain signature ; the original multimodal data and signature By splicing, the first data packet is obtained. , Use the cloud platform's SM2 public key to access the first data packet. Encryption is performed to generate the first encrypted ciphertext. As the first security encapsulation result.

[0064] In addition, the first encryption mode may also include the following steps: using the SM2 encryption public key of the cloud platform to encrypt the original multimodal data. Encryption is performed to obtain the second encrypted ciphertext. ; Calculate the SM3 hash value of the original multimodal data The SM3 hash value of the original multimodal data is digitally signed using the SM2 signing private key of the sending end to obtain the signature. ; the second encrypted ciphertext and signature The data packets are then concatenated to obtain the second data packet. , The second data packet is used as the result of the first secure encapsulation.

[0065] Raw multimodal data exceeding the data volume classification threshold can be considered as heavy data. In this case, a second encryption mode is used to securely encapsulate the raw multimodal data. The secure encapsulation of the raw multimodal data using the second encryption mode, generating a second secure encapsulation result, includes: randomly generating an SM4 session key using the vehicle-mounted or roadside unit. The original multimodal data is processed using the SM4 session key and the SM4 algorithm. Encryption is performed to obtain ciphertext data. ; Calculate the SM4 session key SM3 hash value And use the SM2 signing private key of the sending end to hash the SM3 value of the SM4 session key. Perform the signing to obtain the key signature. ; the SM4 session key Signing with the key Combined into a key packet , and use the SM2 encryption public key of the cloud platform to encrypt the key packet. Encryption is performed to obtain the key ciphertext. ; from the encrypted data and the key ciphertext The resulting data packet serves as the second secure encapsulation result.

[0066] The first or second secure encapsulation result is transmitted to the cloud platform via a pre-defined Transport Layer Security (TLS) tunnel. In this invention, SM2 is the SM2 public-key cryptographic algorithm, SM3 is the SM3 cryptographic hash algorithm, and SM4 is the SM4 block cipher algorithm.

[0067] A schematic diagram of the adaptive encryption and transmission process of the sending end according to the present invention is shown below. Figure 2 As shown.

[0068] In one implementation, the original multimodal data is securely encapsulated to generate a secure encapsulation result, including:

[0069] Determine the data type of the raw multimodal data;

[0070] When the data type of the original multimodal data is an image or video, a preset first data volume classification threshold is obtained. If the data volume of the original multimodal data is less than or equal to the first data volume classification threshold, the original multimodal data is securely encapsulated using a first encryption mode to generate a first secure encapsulation result. If the data volume of the original multimodal data is greater than the first data volume classification threshold, the original multimodal data is securely encapsulated using a second encryption mode to generate a second secure encapsulation result.

[0071] When the data type of the original multimodal data is text, a preset second quantity classification threshold is obtained. If the data volume of the original multimodal data is less than or equal to the second data volume classification threshold, the original multimodal data is securely encapsulated using a first encryption mode to generate a first secure encapsulation result. If the data volume of the original multimodal data is greater than the second data volume classification threshold, the original multimodal data is securely encapsulated using a second encryption mode to generate a second secure encapsulation result.

[0072] Specifically, this embodiment ensures that security resources are accurately deployed through a dual judgment mechanism based on data type and data volume.

[0073] Please see Figure 1 The end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system with dynamic immunity, as described in this embodiment of the invention, further includes the following steps:

[0074] Step S200: Using the cloud platform as the receiving end, decrypt and verify the received secure encapsulation result. If the verification is successful, it is considered that the original multimodal data has been recovered.

[0075] Specifically, using the cloud platform as the receiving end, the corresponding decryption and verification path is selected for processing based on the structural characteristics of the received secure encapsulation result; if the secure encapsulation result is a first secure encapsulation result, the first decryption mode is used for decryption and verification, and if the verification is successful, it is considered that the original multimodal data has been recovered; if the secure encapsulation result is a second secure encapsulation result, the second decryption mode is used for decryption and verification, and if the verification is successful, it is considered that the original multimodal data has been recovered.

[0076] It should be noted that the cloud platform of this invention is a trusted cloud platform, and its operation is subject to strict constraints and auditing by the system security policy.

[0077] The first decryption mode may include the following steps: using the cloud platform's own SM2 decryption private key to decrypt the received first encrypted ciphertext. Decrypt and recover the first data packet. From the recovered first data packet Separate the original multimodal data and signature Use the sender's SM2 signing public key to sign. Perform a signature verification operation. If the signature verification passes, retrieve the SM3 hash value of the original multimodal data. ; the original multimodal data obtained from decryption Calculate the SM3 hash value to obtain the second hash value. Compare the SM3 hash values ​​of the retrieved original multimodal data. Second hash value ,like = This proves that the data has not been tampered with during transmission, and the verification is successful. At this point, it can be considered that the original multimodal data has been recovered. ;like ≠ If the verification fails, the data integrity is deemed compromised, the security event is recorded, and the data is discarded.

[0078] The first decryption mode may also include the following steps: extracting the second encrypted ciphertext from the received second data packet. and signature The second encrypted ciphertext was decrypted using the SM2 decryption private key from the cloud platform. Recover the original multimodal data Use the sender's SM2 signing public key to sign. Perform signature verification. If the signature verification passes, retrieve the SM3 hash value of the original multimodal data. Calculate the SM3 hash value of the recovered original multimodal data to obtain the second hash value. Compare the SM3 hash values ​​of the retrieved original multimodal data. Second hash value ,like = This proves that the data has not been tampered with during transmission, and the verification is successful. At this point, it can be considered that the original multimodal data has been recovered. ;like ≠ If the verification fails, the data integrity is deemed compromised, the security event is recorded, and the data is discarded.

[0079] The second decryption mode may include the following steps: decrypting the received key ciphertext using the cloud platform's own SM2 decryption private key. Obtain the key packet From the key packet Extract the SM4 session key from and key signing Sign the key using the sender's SM2 signing public key. Perform signature verification; if the verification is successful, retrieve the SM3 hash value of the original multimodal data. ; Calculate the SM4 session key The SM3 hash value is used to obtain the fourth hash value. Compare the SM3 hash values ​​of the extracted original multimodal data. If the hash value matches the fourth hash value, it proves that the SM4 session key was intact and of genuine origin during transmission, and the verification is successful. The verified SM4 session key can then be used. And decrypting the SM4 algorithm to ciphertext the data in the second secure encapsulation result Decrypt the data to recover the original multimodal data; if there is no consistency, the verification is considered to have failed, at which point the process is terminated and a security event is recorded.

[0080] To facilitate understanding of the application scenarios of this solution, the following example illustrates the process. When a vehicle with a digital certificate needs to report approximately 300 bytes of CAN bus data (lightweight data), such as engine speed and vehicle speed, the system automatically triggers the first encryption mode because the data volume is less than the preset data volume classification threshold. The sending vehicle transmits the data using SM3 hashing, SM2 signing, and encryption with the cloud platform's public key, then transmits it to the cloud platform via a preset Transport Layer Security (TLS) tunnel. The cloud platform successfully decrypts and verifies the data upon receipt. If a roadside unit needs to upload multiple high-definition surveillance video streams from an intersection, the second encryption mode is automatically triggered because the data volume exceeds the preset data volume classification threshold. The roadside unit randomly generates an SM4 session key to encrypt the video data, signs and encrypts the key, and then transmits the encrypted data and key to the cloud platform via a preset Transport Layer Security (TLS) tunnel. The cloud platform successfully decrypts and verifies the signature upon receipt.

[0081] Please see Figure 1 The end-to-end trusted sharing method for multimodal data in a dynamically immune vehicle-road-cloud system according to an embodiment of the present invention further includes the following steps:

[0082] Step S300: The cloud platform is used to recover the original multimodal data based on the current and historical data to evaluate the credibility of the sending end, and obtain multi-dimensional evaluation indicators including data rationality indicators, behavior consistency indicators, historical reputation score indicators and communication behavior indicators. The preset trust fusion model is used to calculate the dynamic trust value of the sending end in combination with the multi-dimensional evaluation indicators, and the corresponding security handling strategy is triggered according to the dynamic trust value.

[0083] Specifically, the multi-dimensional evaluation indicators include data rationality indicators, behavioral consistency indicators, historical reputation score indicators, and communication behavior indicators. A flowchart illustrating the process of generating dynamic trust values ​​according to this invention is shown below. Figure 3 As shown.

[0084] The data rationality index is used to quantitatively evaluate the credibility of the recovered original multimodal data in terms of physical laws, logical relationships, and spatiotemporal consistency. Its calculation process is as follows: First, the system presets a rationality rule base containing multi-dimensional judgment rules, such as the physical limit range of vehicle speed or acceleration, the continuity and rationality of position trajectories, the effective range of various sensor measurement data, and the spatiotemporal alignment logic between different modal data. During evaluation, the system calls all rules related to the data from the rule base. If the recovered original multimodal data is only of a single type (e.g., only vehicle speed), the data rationality index is a binary value: 1 if it fully conforms to the rules, and 0 otherwise. If the original multimodal data contains multiple types (e.g., simultaneously containing vehicle speed, position, and image data), the data rationality index is the percentage ratio of the number of rules passed to the total number of applicable rules, calculated using the following formula: .in, It is a data rationality indicator. This refers to the number of rules in the rationality rule base used to process the original multi-dimensional data. This represents the total number of rules in the applicable rationality rule base. This method, through rule-based and quantitative calculations, systematically achieves automated assessment of the inherent credibility of data.

[0085] The Behavioral Consistency Index is used to quantify the degree of co-verification between the raw multimodal data reported by the transmitter and the external environment and other independent information sources, aiming to detect data fraud or equipment anomalies. Its calculation process is as follows: First, based on the time and spatial location of the raw multimodal data reporting, an association window is set, and other independent information sources within this spatiotemporal range are retrieved, such as surrounding vehicles and roadside units, forming a set of associated information sources. Then, each information source in the associated information source set is judged: if its reported data corroborates the raw multimodal data in terms of event description or state characteristics, it is marked as a corroborating source; otherwise, it is marked as a non-corroborating source. Simultaneously, the system assigns a confidence weight to each information source, which comprehensively considers factors such as its equipment type, spatial proximity, and its own historical reliability. For example, the weight of roadside units is usually higher than that of ordinary vehicles, and the weight of nearby information sources is greater than that of distant information sources. The formula for calculating the Behavioral Consistency Index is: .in, As an indicator of behavioral consistency, It is an index of information sources related to the sender, retrieved within the associated spatiotemporal window. It is aimed at the first The verification function for the nth source. When the nth source... When the data from one information source corroborates the original multimodal data from the sender in terms of events or states, The value is 1. When the first When the data from one information source does not corroborate the original multimodal data from the sender in terms of events or states, The value is 0. To be assigned to the The confidence weights of each source are real numbers greater than 0 and less than 1, and can be configured according to the actual network deployment density and application scenario. This method transforms abstract behavioral consistency into quantifiable values ​​through multi-source cross-validation and weighted aggregation, providing an objective basis for dynamic trust assessment.

[0086] Historical reputation metrics are used to quantify the accuracy and reliability of a source's behavior in recent history. The calculation process is as follows: First, a sliding statistical time window (e.g., the past 24 hours) is set, and all reporting records from the source within this window are maintained. During evaluation, the total number of reports from the source within this time window is counted, and the number of reports deemed accurate is selected. The criteria for accurate reporting are: data successfully passes decryption verification, data reasonableness checks, and behavior consistency checks, and is not marked as any anomaly. Finally, the historical reputation metric is the percentage of accurate reports to total reports, calculated using the following formula: .in, It is a historical credit indicator. It refers to the number of times accurately reported within the statistical period. This represents the total number of reports within the statistical period. This method, through a sliding time window and accuracy statistics, achieves an objective quantification of the reliability of the historical behavior of the sending source.

[0087] Communication behavior metrics are used to quantify the normality and security of data reporting behavior at the communication mode level, aiming to identify network layer threats such as frequency anomalies and replay attacks. The calculation process is as follows: Communication behavior metrics are used to evaluate the standardization of data reporting behavior at the sending end and detect risks such as frequency anomalies. The calculation is based on a preset communication rule base, including rules such as whether the reporting frequency is within the normal range, whether the amount of data per instance is reasonable, and whether the message sequence conforms to specifications. During evaluation, the system calls relevant rules to verify the reporting behavior. The communication behavior metric is the ratio of the number of passed rules to the total number of rules, and its calculation formula is: .in, It is a communication behavior indicator. This is the number of rules in the communication rule base that this action conforms to. This represents the total number of rules in the applicable communication rule base. This method measures the normality of communication behavior through rule conformity.

[0088] The dynamic trust value of the sending end is generated by calculating using a preset trust fusion model combined with the multi-dimensional evaluation indicators, including:

[0089] The multi-dimensional evaluation indicators are substituted into the preset trust fusion model for calculation to obtain the dynamic trust value of the sending end.

[0090] The trust fusion model is expressed as follows: , It is a dynamic trust value. , , , To preset weights, , It is a data rationality indicator. As an indicator of behavioral consistency, It is a historical credit indicator. It is a communication behavior indicator.

[0091] Optionally, the dynamic trust assessment mechanism uses a sliding window mechanism to update the trust value, that is, it only calculates based on recent behavioral data within a preset time window, so as to achieve a balance between resource consumption and assessment accuracy.

[0092] It should be noted that the end-to-end trusted sharing of this invention covers the entire process from the sending end to the final use by an authorized application on the cloud platform, ensuring its confidentiality and integrity. To achieve this, the data remains encrypted during transmission and storage. When the cloud platform needs to perform trust assessment or business analysis on the data, it is decrypted within a secure and trusted execution environment within the cloud platform. This environment is invisible to external systems and unauthorized applications, thus logically achieving end-to-end control and security of the data throughout the shared link.

[0093] In one implementation, before triggering the corresponding security handling strategy based on the dynamic trust value, the method further includes:

[0094] Preset a first trust threshold, a second trust threshold, and a revocation threshold;

[0095] Wherein, the first trust threshold is greater than the second trust threshold, and the second trust threshold is greater than the revocation threshold.

[0096] Specifically, by setting multi-level trust thresholds, the system can finely distinguish the trust status of the sender, thereby triggering differentiated gradient security handling strategies.

[0097] In one implementation, a corresponding security handling strategy is triggered based on the dynamic trust value, including:

[0098] When the dynamic trust value is greater than the preset first trust threshold, it is determined to be in a healthy state, and the normal data sharing permission of the sending end is maintained.

[0099] When the dynamic trust value is greater than the preset second trust threshold and less than or equal to the preset first trust threshold, it is determined to be a warning state, and the upload rate limit or access permission downgrade is implemented on the sending end.

[0100] When the dynamic trust value is less than or equal to the preset second trust threshold, it is determined to be in a processing state, and an instruction is sent to the sending end to control the sending end to use the first encryption mode for secure encapsulation.

[0101] Specifically, in the warning state, the upload speed is limited to half of a preset value, the sender's access permissions are reduced, and access to sensitive data is prohibited. In the handling state, forcing the sender to use the first encryption mode increases its computational overhead; furthermore, communication bandwidth can be limited to reduce potential harm. In addition, triggering corresponding security handling strategies based on the dynamic trust value includes: when the dynamic trust value falls below a preset revocation threshold for a consecutive preset number of times, a revocation state is determined, and the sender's digital certificate is revoked. The certificate revocation list is updated and synchronized across the entire system, allowing for subsequent source tracing analysis based on this timeframe.

[0102] In one implementation, if the verification fails during the decryption and verification of the received secure encapsulation result, the current original multi-source data is discarded and the dynamic trust value of the corresponding sender is lowered.

[0103] The data processing flow diagram of this invention is shown below. Figure 4 As shown. This invention, through the synergistic linkage of dynamic trust values ​​and security policies, enables the system to possess proactive immunity to detect and respond to internal threats, effectively ensuring the trustworthiness of shared data.

[0104] The current mainstream protection solution is to deploy transport layer security protocols on the communication link to build an encrypted channel. However, this solution can only guarantee the security of data during network transmission. Once data packets arrive at the cloud platform's entry gateway, load balancer, or API (Application Programming Interface), they are usually decrypted for routing, protocol conversion, or preliminary business logic processing. This results in data generally being in plaintext or simply encrypted form as it flows through the complex microservice architecture, data bus, and storage system within the cloud platform. This approach cannot defend against threats from within the cloud platform (such as abuse of privileges by operations and maintenance personnel, lateral movement after a microservice is compromised), creating a security blind spot throughout the data lifecycle, which contradicts the requirements of regulations for handling highly sensitive data. Furthermore, there is a sharp contradiction between security overhead and business real-time requirements. Data in vehicle-road-cloud systems is highly heterogeneous, including small data packets such as vehicle control commands and safety warnings requiring millisecond-level responses, as well as large data packets such as continuously generated high-definition video streams and laser point clouds. Existing technologies mostly adopt a one-size-fits-all encryption strategy, which has certain drawbacks. In existing technologies, if asymmetric encryption (such as SM2) is used for all data, strong security authentication can be achieved, but it will bring huge computational overhead and transmission delay, which cannot meet the real-time requirements of scenarios such as vehicle platooning and emergency braking. Conversely, if symmetric encryption (such as SM4) is used for all data, although the processing efficiency is high, there are shortcomings in key distribution and management, as well as identity authentication strength.

[0105] This invention, by implementing encryption algorithms at the application layer rather than the transport layer, ensures that data exists in encrypted form throughout its entire lifecycle, from the moment it leaves the vehicle or roadside unit until it is consumed by the final business application on the cloud platform. This effectively bridges the security gap within the cloud and achieves a higher level of data confidentiality. The adaptive encryption strategy selection mechanism of this invention can dynamically allocate cryptographic resources based on the essential characteristics (size) of the data, precisely matching security overhead with business needs, thereby improving the overall data processing throughput and real-time performance of the vehicle-road-cloud system.

[0106] To facilitate understanding of the data processing flow of this invention, a specific embodiment is described below. In this embodiment, the data is first obtained from the vehicle end... Raw multimodal data reported on a certain expressway section The original multimodal data Includes vehicle speed latitude and longitude timestamp Vehicle end Based on the data size, the first encryption mode was selected for secure encapsulation before transmission. After receiving the data, the cloud platform decrypted it, verified the signature, and successfully recovered the original multimodal data. Then, the cloud platform, based on the raw multimodal data from this study... The original multimodal data recovered from history is used for the sending end. Conduct a credibility assessment and calculate data reasonableness indicators separately. Behavioral consistency indicators Historical credit indicators and communication behavior indicators .

[0107] Data rationality indicators The calculation process is as follows:

[0108] First, call the original multimodal data from the rule base. The two relevant rules are: Rule 1 is the road segment speed limit rule, which specifies latitude and longitude. The maximum speed limit for the corresponding road section is 100 km / h. Rule 2 is a location validity rule, which limits the location to latitude and longitude. exist The current time represents a valid road segment. The original multimodal data is available at this time. This violates Rule 1 but complies with Rule 2. According to the calculation formula for the data rationality index, the data rationality index at this time is 0.5.

[0109] The calculation process for the behavioral consistency index C is as follows:

[0110] latitude and longitude and timestamp Based on this, two independent sources were retrieved: roadside units. (Confidence weight) ) and vehicles (Confidence weight) Neither of these two independent sources reported to the vehicle. The speeding incident. According to the formula for calculating the behavioral consistency index, the behavioral consistency index at this time can be calculated to be 0.

[0111] The calculation process for the historical credit index H is as follows:

[0112] Statistics from the past 24 hours show that... Total number of reports The number of times the data was accurately reported According to the formula for calculating the historical credit index, the historical credit index at this time is 0.95.

[0113] The calculation process for communication behavior indicator B is as follows:

[0114] The current reporting behavior is compared with the preset communication rule base, including whether the reporting frequency is within the normal range, whether the amount of data per message is reasonable, and whether the message sequence conforms to the specifications. If all comparisons pass, then... , According to the calculation formula for the communication behavior index, the communication behavior index at this time is 1.

[0115] The above four indicators are substituted into the trust fusion model for calculation, where the preset weights are as follows:

[0116] , , , The final dynamic trust value is calculated as follows: .

[0117] Finally, the dynamic trust value is compared with a preset trust threshold. In this embodiment, the first trust threshold is 0.85, the second trust threshold is 0.60, and the revocation threshold is 0.30. Since the dynamic trust value calculated this time is less than the second trust threshold, it is determined to be in a processing state. At this time, the cloud platform immediately sends a notification to the relevant authorities. A security instruction was issued to force all subsequent data reporting to switch to the first encryption mode (i.e., using SM2 asymmetric encryption throughout the process) in order to increase its computational overhead and implement control.

[0118] The above methods enable the system to have adaptive perception and proactive immunity to internal threats, effectively ensuring the trustworthiness of shared data.

[0119] In one embodiment, such as Figure 5 As shown, based on the above-mentioned dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing method, the present invention also provides a dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing system, the system comprising:

[0120] The sending module 100 is used by a vehicle-side or roadside unit that has obtained a digital certificate as the sending end to perform secure encapsulation on the original multimodal data, generate a secure encapsulation result, and transmit the secure encapsulation result to the cloud platform through a preset communication link.

[0121] The receiving module 200 is used to use the cloud platform as the receiving end to decrypt and verify the received secure encapsulation result. If the verification is successful, it is considered that the original multimodal data has been recovered.

[0122] The security control module 300 is used to use the cloud platform to perform a credibility assessment on the sending end based on the original multimodal data recovered from the current and historical data, and obtain a multi-dimensional evaluation index including data rationality index, behavior consistency index, historical reputation score index and communication behavior index. The module uses a preset trust fusion model to calculate the dynamic trust value of the sending end in combination with the multi-dimensional evaluation index, and triggers a corresponding security handling strategy based on the dynamic trust value.

[0123] It should be noted that the foregoing explanation of the embodiment of the dynamic immune vehicle-road-cloud system multimodal data end-to-end trusted sharing method also applies to the dynamic immune vehicle-road-cloud system multimodal data end-to-end trusted sharing system of this embodiment, and will not be repeated here.

[0124] Based on the above embodiments, the present invention also provides a terminal, the structural schematic diagram of which is as follows: Figure 6 As shown. The terminal includes a processor, memory, network interface, and display screen connected via a device bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating device and the dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing program. The internal memory provides an environment for the operation of the operating device and the dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing program stored in the non-volatile storage medium. The network interface is used for communication with external terminals via a network connection. When the dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing program is executed by the processor, it implements the steps of any of the aforementioned dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing methods. The display screen can be a liquid crystal display (LCD) or an e-ink display.

[0125] Those skilled in the art will understand that Figure 6 The structural schematic diagram shown is only a schematic diagram of a part of the structure related to the present invention solution, and does not constitute a limitation on the terminal on which the present invention solution is applied. The specific terminal may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements.

[0126] In one embodiment, a terminal is provided, the terminal including a memory, a processor, and a dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing program stored in the memory and executable on the processor. When the dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing program is executed by the processor, it implements the steps of any of the dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing methods provided in the embodiments of the present invention.

[0127] This invention also provides a computer-readable storage medium storing a dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing program. When the dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing program is executed by a processor, it implements the steps of any of the dynamically immune vehicle-road-cloud system multimodal data end-to-end trusted sharing methods provided in this invention.

[0128] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0129] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the above device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this invention. The specific working process of the units and modules in the above device can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0130] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0131] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0132] In the embodiments provided by this invention, it should be understood that the disclosed apparatus / terminal devices and methods can be implemented in other ways. For example, the apparatus / terminal device embodiments described above are merely illustrative. For instance, the division of modules or units described above is only a logical functional division, and in actual implementation, it can be divided in other ways. For example, several units or components can be combined or integrated into another device, or some features can be ignored or not executed.

[0133] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not mean that the essence of the corresponding technical solutions deviates from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A method for end-to-end trusted sharing of multimodal data in a dynamically immune vehicle-road-cloud system, characterized in that, The method is applied to a vehicle-road-cloud system comprising a vehicle terminal, a roadside unit, and a cloud platform, and the method includes: The vehicle-side or roadside unit that has obtained a digital certificate serves as the sending end, which securely encapsulates the original multimodal data, generates a secure encapsulation result, and transmits the secure encapsulation result to the cloud platform through a preset communication link. Using the cloud platform as the receiving end, the received secure encapsulation result is decrypted and verified. If the verification is successful, it is considered that the original multimodal data has been recovered. The cloud platform is used to assess the credibility of the sending end based on the original multimodal data recovered from the current and historical data, resulting in a multi-dimensional assessment index including data rationality index, behavior consistency index, historical reputation score index and communication behavior index. A preset trust fusion model is used to calculate the dynamic trust value of the sending end based on the multi-dimensional assessment index, and corresponding security handling strategies are triggered according to the dynamic trust value. The data rationality index is used to quantitatively evaluate the credibility of the recovered original multimodal data in terms of physical laws, logical relationships, and spatiotemporal consistency. The behavior consistency index is used to quantify the degree of collaborative verification between the original multimodal data reported by the sending end and the external environment and other independent information source data. The historical reputation score index is used to quantify the accuracy and reliability of the sending source's behavior in history. The communication behavior index is used to quantify the normality and security of the sending source's data reporting behavior at the communication mode level. The dynamic trust value of the sending end is generated by calculating using a preset trust fusion model combined with the multi-dimensional evaluation indicators, including: substituting the multi-dimensional evaluation indicators into the preset trust fusion model for calculation to obtain the dynamic trust value of the sending end; wherein, the trust fusion model is expressed as: , It is a dynamic trust value. , , , To preset weights, , It is a data rationality indicator. As an indicator of behavioral consistency, It is a historical credit indicator. It is a communication behavior indicator; Before triggering the corresponding security action strategy based on the dynamic trust value, the method further includes: setting a first trust threshold, a second trust threshold, and a revocation threshold; wherein, the first trust threshold is greater than the second trust threshold, and the second trust threshold is greater than the revocation threshold; The dynamic trust value triggers a corresponding security handling strategy, including: when the dynamic trust value is greater than a preset first trust threshold, it is determined to be in a healthy state, and the normal data sharing permissions of the sending end are maintained; when the dynamic trust value is greater than a preset second trust threshold and less than or equal to the preset first trust threshold, it is determined to be in a warning state, and the upload rate of the sending end is limited or the access permission is downgraded; when the dynamic trust value is less than or equal to the preset second trust threshold, it is determined to be in a handling state, and an instruction is issued to the sending end to control the sending end to use the first encryption mode for secure encapsulation.

2. The method for end-to-end trusted sharing of multimodal data in a vehicle-road-cloud system with dynamic immunity according to claim 1, characterized in that, The original multimodal data is securely encapsulated to generate a secure encapsulation result, including: Obtain the preset data volume classification threshold; If the amount of the original multimodal data is less than or equal to the data amount classification threshold, then the original multimodal data is securely encapsulated using the first encryption mode to generate a first secure encapsulation result. If the amount of the original multimodal data is greater than the data volume classification threshold, then the original multimodal data is securely encapsulated using a second encryption mode to generate a second secure encapsulation result.

3. The method for end-to-end trusted sharing of multimodal data in a vehicle-road-cloud system with dynamic immunity according to claim 2, characterized in that, The original multimodal data is securely encapsulated using a first encryption mode to generate a first secure encapsulation result, including: Calculate the SM3 hash value of the original multimodal data; The SM3 hash value is digitally signed using the SM2 signature private key of the sending end to obtain a signature; The original multimodal data is concatenated with the signature to obtain the first data packet; The first data packet is encrypted using the SM2 encryption public key of the cloud platform to obtain the first encrypted ciphertext as the first secure encapsulation result.

4. The method for end-to-end trusted sharing of multimodal data in a vehicle-road-cloud system with dynamic immunity according to claim 2, characterized in that, The original multimodal data is securely encapsulated using a second encryption mode to generate a second secure encapsulation result, including: The SM4 session key is randomly generated using the vehicle-mounted or roadside unit; The original multimodal data is encrypted using the SM4 session key and the SM4 algorithm to obtain ciphertext. Calculate the SM3 hash value of the SM4 session key, and sign the SM3 hash value of the SM4 session key using the SM2 signing private key of the sending end to obtain the key signature; The SM4 session key and the key signature are combined into a key package, and the key package is encrypted using the SM2 encryption public key of the cloud platform to obtain the key ciphertext; The data packet composed of the data ciphertext and the key ciphertext serves as the second secure encapsulation result.

5. The end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system with dynamic immunity according to claim 2, characterized in that, Using the cloud platform as the receiving end, the received secure encapsulation result is decrypted and verified. If the verification is successful, it is considered that the original multimodal data has been recovered, including: Using the cloud platform as the receiving end, the corresponding decryption and verification path is selected for processing based on the structural characteristics of the received secure encapsulation result; If the security encapsulation result is the first security encapsulation result, then the first decryption mode is used for decryption and verification. If the verification is successful, it is considered that the original multimodal data has been recovered. If the security encapsulation result is the second security encapsulation result, then the second decryption mode is used for decryption and verification. If the verification is successful, it is considered that the original multimodal data has been recovered.

6. The end-to-end trusted sharing method for multimodal data in a vehicle-road-cloud system with dynamic immunity according to claim 1, characterized in that, Triggering corresponding security measures based on the dynamic trust value also includes: When the number of consecutive preset number of times the dynamic trust value is lower than the preset revocation threshold, it is determined to be in a revocation state, and the digital certificate of the sending end is revoked.