A connected vehicle platoon safety control method and system
By constructing a communication attack model and cryptographic commitment verification, combined with predictive control algorithms, the security and robustness issues of connected vehicle platooning under fake data attacks were solved, achieving the effect of quickly tracking target speed and maintaining the desired vehicle distance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- WUHAN TEXTILE UNIV
- Filing Date
- 2026-03-05
- Publication Date
- 2026-06-02
Smart Images

Figure CN121785372B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of vehicle control and wireless communication technology, specifically relating to a method and system for safe control of connected vehicle platooning. Background Technology
[0002] With the development of vehicle-to-everything (V2X) and autonomous driving technologies, network communication plays a crucial role in autonomous vehicle systems. Vehicle dynamics and data communication processes are interdependent. While this characteristic endows the system with powerful functionality, it necessitates the use of wireless networks to transmit vehicle status data. This reliance on communication systems makes them highly vulnerable to malicious network interference. Therefore, reliable connected vehicle secure communication protocols and controller design have attracted widespread attention and are of paramount importance. Summary of the Invention
[0003] To improve the communication security and control robustness of connected vehicle platooning under spoofing attacks, in a first aspect of the present invention, a connected vehicle platooning security control method is provided, comprising: acquiring the longitudinal dynamic parameters of the vehicle and platooning configuration information based on a leader-follower architecture; constructing a communication attack model based on sensors and vehicle-to-everything (V2X) networks; executing a data security transmission protocol: receiving state data shares and corresponding encryption commitments from the preceding vehicle through multiple communication channels, and using the encryption commitments to verify the consistency of the received state data shares; reconstructing the trusted state information of the preceding vehicle based on the verified state data shares; performing attack detection using the trusted state information and the communication attack model: identifying the attacked state data shares based on the consistency verification results to detect communication network attacks, and detecting sensor attacks by comparing the trusted state information with the vehicle's local sensor measurement data; and calculating the optimal control input of the vehicle based on the trusted state information using a predictive control algorithm to drive the vehicle to track the target speed and maintain a desired distance.
[0004] In some embodiments of the present invention, the state data share and cryptographic commitment are generated by the following steps: constructing a polynomial function based on the current state value of the preceding vehicle and a random number; calculating the state data share corresponding to different communication channels according to the polynomial function; and calculating the cryptographic commitment corresponding to each state data share based on the generator and the polynomial function.
[0005] In some embodiments of the present invention, the consistency verification includes: calculating a preset power mapping value of the received state data share; determining whether the preset power mapping value and the received encryption commitment satisfy a preset congruence relationship; if satisfied, determining that the state data share under the communication channel is a trusted share; if not satisfied, determining that it is an attacked share.
[0006] In some embodiments of the present invention, the reconstructing of the trusted state information of the preceding vehicle includes: filtering out a set of trusted shares that have passed consistency verification from the data received from all communication channels; and using the Lagrange interpolation method or the polynomial reconstruction algorithm to inversely solve the true state value of the preceding vehicle based on the data in the set of trusted shares.
[0007] In some embodiments of the present invention, the attack detection using the trusted state information includes: communication network attack detection: identifying the communication channel where the failed verification state data share is located, and determining that the channel has been subjected to a data injection attack; sensor attack detection: calculating the residual between the local sensor measurement value of the vehicle and the trusted state information, and determining that the vehicle sensor has been subjected to a data injection attack when the residual exceeds a preset threshold.
[0008] In some embodiments of the present invention, the step of using predictive control algorithms to calculate the optimal control input for the vehicle includes: constructing an optimization problem that includes the vehicle's state tracking error, control input cost, and vehicle physical constraints; solving the optimization problem in the prediction time domain, using the reliable state information as a reference, to obtain a control input sequence; and using the first element of the control input sequence as the vehicle acceleration control command at the current moment.
[0009] A second aspect of the present invention provides a connected vehicle platooning safety control system, comprising: an acquisition module for acquiring longitudinal dynamic parameters of the vehicle and platooning configuration information based on a lead-follow architecture; constructing a communication attack model based on sensors and vehicle-to-everything (V2X) networks; an execution module for executing a data security transmission protocol: receiving state data shares and corresponding encryption commitments from a preceding vehicle through multiple communication channels, and using the encryption commitments to verify the consistency of the received state data shares; a detection module for reconstructing trusted state information of the preceding vehicle based on the verified state data shares; performing attack detection using the trusted state information and the communication attack model: identifying attacked state data shares based on the consistency verification results to detect communication network attacks, and detecting sensor attacks by comparing the trusted state information with local sensor measurement data of the vehicle; and a drive module for calculating the optimal control input of the vehicle based on the trusted state information using a predictive control algorithm to drive the vehicle to track a target speed and maintain a desired distance.
[0010] A third aspect of the present invention provides an electronic device comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the connected vehicle platooning safety control method provided in the first aspect of the present invention.
[0011] In a fourth aspect, the present invention provides a computer-readable medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the connected vehicle platooning safety control method provided in the first aspect of the present invention.
[0012] The beneficial effects of this invention are:
[0013] This invention addresses the network attack problem in the platooning control of connected autonomous vehicles by proposing a secure communication protocol. Through the distribution of encrypted state shares, it achieves trusted state reconstruction, distributed real-time attack detection, and inherent privacy protection of vehicle state information. Utilizing the trusted state provided by the security layer, the optimal control input is quickly calculated, ensuring that even under spoofing attacks, the following vehicle rapidly converges to the target speed and accurately maintains the desired distance. Attached Figure Description
[0014] Figure 1 This is a basic flowchart illustrating the connected vehicle platooning safety control method in some embodiments of the present invention;
[0015] Figure 2 This is a schematic diagram of a connected vehicle platooning model in some embodiments of the present invention;
[0016] Figure 3 This is a schematic diagram of the structure of the vehicle platooning safety control system in some embodiments of the present invention;
[0017] Figure 4 This is a schematic diagram of the structure of an electronic device in some embodiments of the present invention. Detailed Implementation
[0018] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0019] Example 1
[0020] refer to Figure 1 and Figure 2 In a first aspect of the present invention, a method for safe control of connected vehicle platooning is provided, comprising:
[0021] S100. Obtain the longitudinal dynamic parameters of this vehicle and the formation configuration information based on the leader-follower architecture; construct a communication attack model based on sensors and vehicle networking;
[0022] S200. Execute the data security transmission protocol: Receive status data shares and corresponding encryption commitments from the preceding vehicle through multiple communication channels, and use the encryption commitments to verify the consistency of the received status data shares;
[0023] S300. Based on the verified state data shares, reconstruct the trusted state information of the preceding vehicle; use the trusted state information and the communication attack model to perform attack detection: identify the attacked state data shares according to the consistency verification results to detect communication network attacks, and detect sensor attacks by comparing the trusted state information with the local sensor measurement data of the vehicle.
[0024] S400. Based on the reliable state information, the optimal control input of the vehicle is calculated using a predictive control algorithm to drive the vehicle to track the target speed and maintain the desired distance.
[0025] refer to Figure 2 In step S100 of some embodiments of the present invention, the longitudinal dynamic parameters of the vehicle and the formation configuration information based on the navigator-follower architecture are obtained; a communication attack model based on sensors and vehicle networking is constructed.
[0026] Specifically, Figure 2 The diagram shows a connected vehicle platoon model, a fleet of multiple vehicles including a leader and... n There are several followers, each equipped with multiple communication channels and radar sensors to obtain information from the vehicle ahead. It is assumed that some of these communication channels and sensors are under attack.
[0027] The kinematic model for each vehicle is as follows:
[0028] (1)
[0029] in, For the first i The longitudinal position of the vehicle For the first i The speed of the car For the first i The vehicle's control input (i.e., acceleration).
[0030] Assume the sampling time interval is Then equation (1) can be discretized as:
[0031] (2)
[0032] (3)
[0033] The purpose of this invention is to ensure control input This makes the following equation true:
[0034] (4)
[0035] (5)
[0036] in, Represents the vehicle's position and speed when it is stable. d and The set following distance and speed. Therefore, the first... i The distributed control law design for the vehicle is as follows:
[0037] (6)
[0038] in, Vehicle distance information Speed information can be obtained from vehicle-mounted radar. This can be obtained through workshop communication. Consider the following two types of fake data injection attacks:
[0039] Sensor attacks: Attackers could manipulate vehicles i The readings from the vehicle's onboard sensors. For the actual distance... The tampered sensor output became , This indicates a biased injection attack.
[0040] V2V network communication attack: Attackers intercept and manipulate wireless communication data by injecting deceptive signals. Launching FDI attacks. These attacks disrupt fleet controllers and compromise data integrity by hijacking wireless communications and injecting false information.
[0041] Assuming the injected fake data is bounded, that is, considering the attacker's limited energy, the following condition must be met:
[0042] (7)
[0043] in, and Indicates the upper bound of the attack.
[0044] In step S200 of some embodiments of the present invention, a data security transmission protocol is executed: a state data share and a corresponding encryption commitment are received from the preceding vehicle through multiple communication channels, and the received state data share is verified for consistency using the encryption commitment; wherein, the state data share and the encryption commitment are generated through the following steps:
[0045] S201. Construct a polynomial function based on the current state value of the preceding vehicle and a random number; S202. Calculate the state data share corresponding to different communication channels according to the polynomial function;
[0046] Specifically, ,in Represents a rounded function. express k Time vehicle i state,S Indicates the scaling factor. Indicates assignment. Generates a function with a random polynomial. ,in t and p Given a value and satisfying , p For large prime numbers, It is a random number.
[0047] S203. Calculate the cryptographic commitment corresponding to each state data share based on the generator and the polynomial function.
[0048] Specifically, calculate commitment ,in g To generate the model p The generator of the multiplicative group.
[0049] vehicle i pass n Each communication channel is distributed and shared. .
[0050] In step S200 of some embodiments of the present invention, the consistency verification includes:
[0051] S204. Calculate the preset power mapping value of the received state data share;
[0052] Specifically, corroding shared values ,in express, This represents the value after an attack. Corrosion commitment. ,in This indicates fake data injected by the attacker.
[0053] S205 determines whether the preset power mapping value and the received encryption commitment satisfy a preset congruence relationship; if they satisfy, the state data share under the communication channel is determined to be a trusted share; if they do not satisfy, it is determined to be an attacked share.
[0054] Specifically, verification The system checks whether the commitment is true or false. If true, no attack exists; otherwise, an attack exists. Using this method, commitments are divided into two groups: one group consists of those that have been authenticated. One group consists of those that have not been certified. .
[0055] Calculate vehicles i Correct state .
[0056] In step S300 of some embodiments of the present invention, the trusted state information of the preceding vehicle is reconstructed based on the verified state data share; attack detection is performed using the trusted state information and the communication attack model: the attacked state data share is identified according to the result of consistency verification to detect communication network attacks, and sensor attacks are detected by comparing the trusted state information with the local sensor measurement data of the vehicle.
[0057] The reconstructed trusted state information of the preceding vehicle includes:
[0058] S301. Select a set of trusted shares that have passed the consistency verification from the data received from all communication channels; S302. Use the Lagrange interpolation method or the polynomial reconstruction algorithm to solve the true state value of the preceding vehicle based on the data in the set of trusted shares.
[0059] The attack detection using the trusted state information includes:
[0060] S303. Communication network attack detection: Identify the communication channel where the verification failed status data share is located, and determine that the channel has been subjected to a data injection attack;
[0061] Specifically, the core principle of the communication network attack detector is deeply integrated into the verification and reconstruction process of the proposed secure transmission protocol. Firstly, the vehicle... i Able to receive from the vehicle in front n Each data share is precisely divided into two distinct sets: a "credible share set". This includes all cryptographically verified shares; and a "set of untrusted shares". This includes all shares that failed to be validated. A non-empty state is the primary criterion for successfully detecting a communication attack.
[0062] definition , ,in , It can be inferred that the attack was , This represents the attack value received by the vehicle.
[0063] S304. Sensor Attack Detection: Calculate the residual between the local sensor measurement value of the vehicle and the trusted state information. When the residual exceeds a preset threshold, it is determined that the vehicle sensor has been subjected to a data injection attack.
[0064] Specifically, vehicles i The distance to the vehicle in front can be obtained in two ways: one is by directly measuring it through onboard sensors, which yields an unreliable value that could be tampered with by an attacker. Secondly, by calculating the reliable distance This value can be reconstructed from the trusted location of the preceding vehicle using the proposed security protocol. and its own trusted local location The calculation yielded the following attack model: Then the detection residual is .therefore, Directly indicates whether the attack exists, i.e. This indicates that an attack has occurred. This indicates that no attack exists.
[0065] In step S400 of some embodiments of the present invention, based on the reliable state information, the optimal control input of the vehicle is calculated using a predictive control algorithm to drive the vehicle to track the target speed and maintain the desired distance.
[0066] The calculation of the optimal control input for the vehicle using a predictive control algorithm includes:
[0067] S401. Construct an optimization problem that includes the vehicle's state tracking error, control input cost, and vehicle physical constraints;
[0068] Specifically, define vehicles i The state and tracking error are Therefore, we can obtain:
[0069] (8)
[0070] in, , Control input This can be obtained by solving the following constrained optimization problem:
[0071] (9)
[0072] in,
[0073] ;
[0074] N To predict the length of the time domain, Q , and Given the cost function weight matrix, Given a linear cost vector used to adjust the response. and For a given convex set.
[0075] Solving optimization problem (9) is equivalent to solving the following equality-constrained optimization problem.
[0076] (10)
[0077] in:
[0078]
[0079] ,
[0080] in, and As slack variables, and As dual variables, This is the penalty parameter.
[0081] S402. In the prediction time domain, based on the reliable state information, solve the optimization problem to obtain the control input sequence;
[0082] Specifically, step one: Calculation:
[0083] , , ,
[0084] Among them, matrix The steady-state value of the following equation can be obtained by iterative solution:
[0085] ,
[0086] ,
[0087] set up .
[0088] Step 2: Update feedforward terms and linear cost vector :
[0089] ,
[0090] ,
[0091] in, .
[0092] Step 3: Update the control input and error for the next time step:
[0093] , ;
[0094] Step 4: Update slack variables:
[0095] , ,
[0096] in, , , For the projection operator. Projected onto feasible set Ensure that the vehicle collision-free constraint is met. (Regarding input constraints...) The projection is a saturation function that ensures the input meets the vehicle's physical constraints.
[0097] Step 5: Update the dual variable:
[0098] , ,
[0099] The update rule proposed in this invention acts as a corrective feedback loop. Variable and Cumulative consistency error (raw residuals). Optimal input. Its equivalent variable under constraint The differences between them are stored In this context, the stored quantity modifies the weights in subsequent optimization subproblems, guiding the vehicle's trajectory towards the optimal direction. Not generally, the first element of the control input sequence is used as the vehicle acceleration control command at the current moment.
[0100] It is understandable that the optimization problem is solved using an iterative update strategy, which specifically includes: introducing slack variables to handle state constraints and introducing dual variables to handle equality constraints; at each sampling time, alternately updating the control input, slack variables, and dual variables, where the update of the control input includes feedforward terms and feedback correction for consistency errors; and using projection operators to restrict the updated variables within the feasible region to satisfy the vehicle collision-free constraint and physical constraints.
[0101] Example 2
[0102] refer to Figure 3 In a second aspect, the present invention provides a connected vehicle platooning safety control system 1, comprising:
[0103] Module 11 is used to acquire the longitudinal dynamic parameters of the vehicle and the formation configuration information based on the leader-follower architecture; and to construct a communication attack model based on sensors and vehicle networking.
[0104] Execution module 12 is used to execute a data security transmission protocol: receiving status data shares and corresponding encryption commitments from the preceding vehicle through multiple communication channels, and using the encryption commitments to verify the consistency of the received status data shares;
[0105] Detection module 13 is used to reconstruct the trusted state information of the preceding vehicle based on the verified state data share; and to perform attack detection using the trusted state information and the communication attack model: to identify the attacked state data share according to the consistency verification result to detect communication network attacks, and to detect sensor attacks by comparing the trusted state information with the local sensor measurement data of the vehicle.
[0106] The drive module 14 is used to calculate the optimal control input of the vehicle based on the reliable state information using a predictive control algorithm, so as to drive the vehicle to track the target speed and maintain the desired distance.
[0107] Furthermore, the drive module 14 includes: a construction unit, used to construct an optimization problem including the vehicle's state tracking error, control input cost, and vehicle physical constraints; a solution unit, used to solve the optimization problem in the prediction time domain, based on the reliable state information, to obtain a control input sequence; and a control unit, used to take the first element of the control input sequence as the vehicle acceleration control command at the current moment.
[0108] Example 3
[0109] refer to Figure 4 In a third aspect, the present invention provides an electronic device comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the connected vehicle platooning safety control method of the first aspect of the present invention.
[0110] Electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 502 or a program loaded from storage device 508 into random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of electronic device 500. The processing unit 501, ROM 502, and RAM 503 are interconnected via bus 504. An input / output (I / O) interface 505 is also connected to bus 504.
[0111] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, hard disks; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 4An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 4 Each box shown can represent a device or multiple devices as needed.
[0112] Specifically, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a ROM 502. When the computer program is executed by a processing device 501, it performs the functions defined in the methods of embodiments of this disclosure. It should be noted that the computer-readable medium described in embodiments of this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0113] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more computer programs, which, when executed by the electronic device, cause the electronic device to:
[0114] Computer program code for performing the operations of embodiments of this disclosure can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages—such as Java, Smalltalk, C++, and Python—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0115] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0116] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A safety control method for connected vehicle platooning, characterized in that, include: Obtain the vehicle's longitudinal dynamic parameters and formation configuration information based on the navigator-follower architecture; Construct a communication attack model based on sensors and vehicle-to-everything (V2X) networks; Execute a data security transmission protocol: Receive state data shares and corresponding encryption commitments from the preceding vehicle through multiple communication channels, and use the encryption commitments to verify the consistency of the received state data shares: Calculate a preset power mapping value for the received state data shares; determine whether the preset power mapping value and the received encryption commitments satisfy a preset congruence relationship; if satisfied, determine that the state data share under this communication channel is a trusted share; if not satisfied, determine that it is an attacked share. Based on the verified state data shares, the trusted state information of the preceding vehicle is reconstructed; attack detection is performed using the trusted state information and the communication attack model: the attacked state data shares are identified according to the consistency verification results to detect communication network attacks, and sensor attacks are detected by comparing the trusted state information with the local sensor measurement data of the vehicle. The reconstructed trusted state information of the preceding vehicle includes: selecting a set of trusted shares that have passed consistency verification from the data received from all communication channels; and using the Lagrange interpolation method or the polynomial reconstruction algorithm to inversely solve the true state value of the preceding vehicle based on the data in the set of trusted shares. Based on the trusted state information, a predictive control algorithm is used to calculate the optimal control input for the vehicle, driving it to track the target speed and maintain the desired distance. The attack detection using the trusted state information includes: communication network attack detection: identifying the communication channel where the failed verification state data share is located, and determining that the channel has been subjected to a data injection attack; sensor attack detection: calculating the residual between the vehicle's local sensor measurements and the trusted state information, and determining that the vehicle's sensors have been subjected to a data injection attack when the residual exceeds a preset threshold.
2. The connected vehicle platooning safety control method according to claim 1, characterized in that, The state data share and cryptographic commitment are generated through the following steps: A polynomial function is constructed based on the current state value of the preceding vehicle and a random number; The state data share corresponding to different communication channels is calculated based on the polynomial function. The cryptographic commitment corresponding to each state data share is calculated based on the generator and the polynomial function.
3. The connected vehicle platooning safety control method according to claim 1, characterized in that, The calculation of the optimal control input for the vehicle using a predictive control algorithm includes: Construct an optimization problem that includes the vehicle's state tracking error, control input cost, and vehicle physical constraints; In the prediction time domain, the optimization problem is solved based on the reliable state information to obtain the control input sequence; The first element of the control input sequence is used as the vehicle acceleration control command at the current moment.
4. A safety control system for connected vehicle platooning, characterized in that, include: The acquisition module is used to acquire the longitudinal dynamic parameters of this vehicle and the formation configuration information based on the navigator-follower architecture; Construct a communication attack model based on sensors and vehicle-to-everything (V2X) networks; The execution module is used to execute the data security transmission protocol: receiving state data shares and corresponding encryption commitments from the preceding vehicle through multiple communication channels, and using the encryption commitments to verify the consistency of the received state data shares: calculating a preset power mapping value of the received state data shares; determining whether the preset power mapping value and the received encryption commitments satisfy a preset congruence relationship; if they satisfy the relationship, the state data shares under this communication channel are determined to be trusted shares; if they do not satisfy the relationship, they are determined to be attacked shares. The detection module is used to reconstruct the trusted state information of the preceding vehicle based on the verified state data share; Attack detection is performed using the trusted state information and the communication attack model: the attacked state data share is identified based on the consistency verification result to detect communication network attacks, and sensor attacks are detected by comparing the trusted state information with the local sensor measurement data of the vehicle. The reconstructed trusted state information of the preceding vehicle includes: selecting a set of trusted shares that have passed consistency verification from the data received from all communication channels; and using the Lagrange interpolation method or the polynomial reconstruction algorithm to inversely solve the true state value of the preceding vehicle based on the data in the set of trusted shares. The drive module is used to calculate the optimal control input of the vehicle based on the trusted state information using a predictive control algorithm, so as to drive the vehicle to track the target speed and maintain the desired distance. The attack detection using the trusted state information includes: communication network attack detection: identifying the communication channel where the failed verification state data share is located, and determining that the channel has been subjected to a data injection attack; sensor attack detection: calculating the residual between the local sensor measurement value of the vehicle and the trusted state information, and determining that the vehicle sensor has been subjected to a data injection attack when the residual exceeds a preset threshold.
5. The connected vehicle platooning safety control system according to claim 4, characterized in that, The driving module includes: The building unit is used to construct an optimization problem that includes the vehicle's state tracking error, control input cost, and vehicle physical constraints; The solution unit is used to solve the optimization problem in the prediction time domain, based on the reliable state information, to obtain the control input sequence; The control unit is used to take the first element of the control input sequence as the vehicle acceleration control command at the current moment.
6. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the connected vehicle platooning safety control method as described in any one of claims 1 to 3.
7. A computer-readable medium having a computer program stored thereon, wherein, When the computer program is executed by the processor, it implements the connected vehicle platooning safety control method as described in any one of claims 1 to 3.