Gateway data security guarantee method based on star flash technology

By collecting image and radio frequency feature data from the server side and combining it with spatial symmetry verification, attacks disguised as access points can be identified and rejected, thus solving the data security problem within the coverage boundary of relay devices in StarFlash technology and improving gateway security.

CN121842679APending Publication Date: 2026-04-10SHENZHEN XINGHANG INFORMATION TECHNOLOGY DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN XINGHANG INFORMATION TECHNOLOGY DEVELOPMENT CO LTD
Filing Date
2026-02-28
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In existing StarFlash technology, when the relay device is located within the coverage boundary or range of the mapping node, it cannot identify the source direction of the access signal, resulting in the compromise of gateway data security.

Method used

By collecting scene images from the server direction, the server's location is determined. Combined with the spatial coordinates and radio frequency characteristic data of the mapping nodes, the spatial symmetry of the access signals is verified in groups, and the asymmetric distribution pattern of the relay devices is identified.

Benefits of technology

It effectively identifies and rejects attacks from spoofed access points, improving the reliability of gateway security decisions and preventing RF spoofing and relay attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121842679A_ABST
    Figure CN121842679A_ABST
Patent Text Reader

Abstract

The invention provides a gateway data security guarantee method based on a satellite flash technology, and relates to the technical field of data processing, and the method comprises the steps: responding to the access of a server state signal of target equipment, collecting a scene image in a server direction, and determining the direction of the server, acquiring node space coordinates of each mapping node in a communication link corresponding to the satellite flash gateway under the first coordinate system; determining an access signal orientation of the access end under the first coordinate system in combination with the first feature data of the access end; when the position of the access signal falls into a space sector with the position of the server as the center, the access signal is marked as a suspicious access end; and grouping each mapping node, and verifying the suspicious access end based on the spatial symmetry of the first feature data to obtain a security judgment result. According to the invention, by identifying the orientation of the server and verifying the spatial symmetry between the radio frequency characteristic data observed by each mapping node, the camouflage access attack that the identity credential is legal but the physical position crosses the boundary is identified and prevented, and the data security guarantee of the gateway is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a gateway data security protection method based on StarFlash technology. Background Technology

[0002] StarFlash technology is a low-latency and highly reliable near-field wireless communication technology. It is typically used in smart cockpits to connect in-vehicle devices with external access points. In the in-vehicle communication network, multiple nodes are fixedly installed in the doors, seats, and dashboard. The StarFlash gateway connecting each node is located in the center console, and the StarFlash gateway performs communication scheduling for each node.

[0003] Currently, gateway security technology is mainly based on identity authentication, verifying digital certificates and key negotiation. Some solutions also add location verification, which calculates the location by measuring the time difference of arrival or the strength of received signals from multiple nodes to determine whether the location is within the gateway's signal coverage area. If it is within the coverage area, it is considered legitimate and access is allowed.

[0004] However, when a vehicle is charging at a public charging station, if an attacker has pre-installed a parasitic relay device on the charging station, the relay device may be located at the coverage boundary or even within the coverage area of ​​some mapping nodes on the in-vehicle gateway communication link, since the charging interface is located on the side of the vehicle or at one end of the edge. Therefore, even though the relay device is located outside the vehicle, the signal may still enter the coverage boundary or even the coverage area of ​​the mapping nodes. Furthermore, because the relay device is located towards the charging station, the signal strength observed by mapping nodes closer to the charging station will be significantly higher than that of mapping nodes farther away from the charging station. The radio frequency characteristic data observed by each mapping node will exhibit an asymmetrical distribution pointing towards the charging station. Therefore, if the location of the charging station is not identified, mapping nodes are not grouped according to the location of the charging station, and the spatial symmetry between the radio frequency characteristic data observed by each mapping node is not verified, it will be mistakenly identified as a legitimate access point, thereby compromising the gateway's data security. Summary of the Invention

[0005] This application provides a gateway data security assurance method based on StarFlash technology to solve the problem that in the prior art, when the relay device is located at the coverage boundary or even within the coverage area of ​​the mapping node, the source direction of the access signal is not distinguished, and the symmetry of the radio frequency characteristic data observed by each mapping node in the spatial distribution is not verified for the location of the server. This leads to the inability to identify the relay device located in the direction of the server and thus misjudging it as a legitimate access point.

[0006] The first aspect of this application provides a gateway data security assurance method based on StarFlash technology, including: responding to the access of the server status signal of the target device, acquiring scene images in the direction of the server and determining the server's orientation, and obtaining the node spatial coordinates of each mapped node in the communication link corresponding to the StarFlash gateway in the first coordinate system;

[0007] Based on the node spatial coordinates and the first feature data of the access terminal observed by each mapping node, the access signal orientation of the access terminal in the first coordinate system is determined.

[0008] When it is determined that the location of the access signal falls within a spatial sector centered on the location of the server, the access terminal is marked as a suspicious access terminal.

[0009] Based on the server's location, each mapping node is grouped, and the suspicious access point is verified based on the spatial symmetry between the first feature data of each mapping node group to obtain a security decision result.

[0010] Optionally, in one possible implementation, acquiring scene images in the direction of the server and determining the server's location includes:

[0011] The target device acquires scene images from the server direction using its image acquisition device, performs edge detection on the scene images, and extracts candidate contours from the scene images.

[0012] Based on the server standard contour features stored in the target device, determine the contour matching degree between each candidate contour and the server standard contour features, and take the candidate contour with the highest contour matching degree as the server contour.

[0013] Based on the center pixel coordinates of the server's outline in the scene image and the installation parameters of the image acquisition device, the server's orientation in the first coordinate system is determined.

[0014] Optionally, in one possible implementation, the first feature data includes a signal arrival time component and a received signal strength component;

[0015] The step of determining the access signal orientation of the access terminal in the first coordinate system based on the node spatial coordinates and the first feature data of the access terminal observed by each mapping node includes:

[0016] Determine the arrival time difference between any two mapping nodes based on the signal arrival time components observed by any two mapping nodes;

[0017] Based on the arrival time difference and signal propagation speed, determine the distance difference between any two mapping nodes and the access terminal;

[0018] Based on the node spatial coordinates of each mapping node and the corresponding distance difference, the spatial position coordinates of the access terminal in the first coordinate system are determined;

[0019] Based on the spatial location coordinates and the gateway spatial coordinates of the StarSpark gateway, the orientation of the access signal of the access terminal relative to the StarSpark gateway is determined.

[0020] Optionally, in one possible implementation, determining the access signal orientation of the access terminal relative to the StarSpark gateway based on the spatial location coordinates and the gateway spatial coordinates of the StarSpark gateway includes:

[0021] Construct a pointing vector based on the spatial location coordinates and the gateway spatial coordinates;

[0022] Projecting the pointing vector onto the horizontal reference plane of the first coordinate system yields the projected pointing vector;

[0023] The orientation of the access signal is determined based on the angle between the projection pointing vector and the reference axis of the first coordinate system.

[0024] Optionally, in one possible implementation, determining that the location of the access signal falls within a spatial sector centered on the server's location includes:

[0025] Extract the first boundary pixel coordinates and the second boundary pixel coordinates of the server-side contour;

[0026] Based on the first boundary pixel coordinates and the installation parameters of the image acquisition device, the first boundary azimuth angle of the server contour relative to the image acquisition device is determined;

[0027] Based on the second boundary pixel coordinates and the installation parameters of the image acquisition device, the second boundary azimuth angle of the server contour relative to the image acquisition device is determined;

[0028] The sector boundary of the spatial sector is determined based on the first boundary azimuth angle and the second boundary azimuth angle. When the azimuth angle of the access signal is determined to be within the angle range defined by the first boundary azimuth angle and the second boundary azimuth angle, it is determined that the azimuth angle of the access signal falls into the spatial sector.

[0029] Optionally, in one possible implementation, grouping the mapping nodes according to the server's location includes:

[0030] Based on the node spatial coordinates of each mapping node and the gateway spatial coordinates of the StarSpark gateway, determine the node azimuth angle of each mapping node relative to the StarSpark gateway.

[0031] Based on the angle difference between the azimuth of each node and the azimuth of the server, the azimuth deviation angle corresponding to each mapping node is determined, and the grouping boundary angle is determined based on the number and spatial distribution of the mapping nodes.

[0032] Mapping nodes with azimuth deviation angles less than the grouping boundary angle are classified into near-end node groups, and mapping nodes with azimuth deviation angles not less than the grouping boundary angle are classified into far-end node groups.

[0033] Optionally, in one possible implementation, verifying the suspicious access point based on the spatial symmetry between the first feature data of each mapping node group to obtain a security decision includes:

[0034] The near-end observation intensity is determined based on the received signal strength component in the first feature data observed by the near-end node group, and the far-end observation intensity is determined based on the received signal strength component observed by the far-end node group.

[0035] When the intensity difference between the near-end observation intensity and the far-end observation intensity is determined to be less than the symmetry tolerance threshold, the suspicious access terminal is determined to have passed the spatial symmetry verification, and the security decision result is an access permission.

[0036] When it is determined that the near-end observation intensity is higher than the far-end observation intensity, and the direction of intensity increase corresponding to the intensity difference between the near-end and far-end observation indices points towards the server, the suspected access terminal is deemed to have failed the spatial symmetry verification, and the security decision result is access denied.

[0037] Optionally, in one possible implementation, determining that the near-end observation intensity is higher than the far-end observation intensity, and that the direction of intensity increase corresponding to the intensity difference between the near-end and far-end observation intensities points towards the server's azimuth, includes:

[0038] Based on the node spatial coordinates of each mapped node in the near-end node group and the corresponding observed received signal strength components, the centroid coordinates of the intensity distribution of the near-end node group are determined.

[0039] The geometric center coordinates of the remote node group are determined based on the node space coordinates of each mapped node in the remote node group.

[0040] The direction of intensity increase is determined based on the direction from the geometric center coordinates to the centroid coordinates of the intensity distribution;

[0041] The allowable directional angle is determined based on the field of view of the image acquisition device and the angular span of the server's outline in the scene image. When the directional deviation angle between the intensity increasing direction and the server's orientation is less than the allowable directional angle, the intensity increasing direction is determined to point to the server's orientation.

[0042] Optionally, in one possible implementation, determining the centroid coordinates of the intensity distribution of the near-end node group based on the node spatial coordinates of each mapped node in the near-end node group and the corresponding observed received signal intensity components includes:

[0043] The received signal strength components observed by each mapping node in the near-end node group are normalized to obtain the intensity normalization value corresponding to each mapping node.

[0044] The centroid coordinates of the intensity distribution of the near-end node group are determined based on the node spatial coordinates of each mapping node and the corresponding intensity normalization value.

[0045] Optionally, in one possible implementation, determining the centroid coordinates of the intensity distribution of the near-end node group based on the node spatial coordinates of each mapped node in the near-end node group and the corresponding observed received signal intensity components includes:

[0046] The received signal strength components observed by each mapping node in the near-end node group are normalized to obtain the intensity normalization value corresponding to each mapping node.

[0047] The centroid coordinates of the intensity distribution of the near-end node group are determined based on the node spatial coordinates of each mapping node and the corresponding intensity normalization value.

[0048] The gateway data security protection method based on StarFlash technology provided in this application has the following beneficial effects:

[0049] 1. This application identifies the server's location through image acquisition, using the server's location as a spatial reference to determine whether the access signal originates from the server's direction. By grouping the mapped nodes according to the server's location, it verifies the spatial symmetry between the radio frequency characteristic data observed by the near-end node group and the far-end node group, identifying the asymmetrical distribution pattern caused by the relay device being located in the server's direction. Although the relay device installed by the attacker on the server can allow the signal to enter the coverage boundary or even the coverage area of ​​some mapped nodes, because the relay device is located in the server's direction rather than inside the target device, the radio frequency characteristic data observed by each mapped node will inevitably show an asymmetrical distribution pointing in the server's direction. Through spatial symmetry verification, this can be identified and access denied, thereby preventing spoofing attacks where the identity credentials are legitimate but the physical location is outside the designated area.

[0050] 2. This application combines image recognition and radio frequency (RF) feature verification, two distinct information modalities. Specifically, it uses an image acquisition device to capture scene images and identify the server's outline to determine its location, and uses RF feature data observed by each mapping node to determine the location of the access signal. If an attacker forges RF feature data to make the access signal appear to be outside the server's direction, a contradiction will arise when performing spatial correlation analysis between the forged access signal location and the server's location obtained from image recognition, since the image acquisition device can directly observe the server's true location. Furthermore, if an attacker launches an attack from the server's direction, although the access signal location may match the server's location, an asymmetric distribution pattern will be exposed when verifying spatial symmetry after grouping the mapping nodes based on the server's location. Therefore, the gateway security adjudication method of this application can simultaneously address both RF forgery and relay forwarding attacks, improving the reliability of gateway security adjudication. Attached Figure Description

[0051] Figure 1 This is a flowchart illustrating the gateway data security protection method based on StarFlash technology provided in an embodiment of this application;

[0052] Figure 2 This is a schematic diagram illustrating an application scenario of the gateway data security assurance method based on StarFlash technology provided in this application embodiment;

[0053] Figure 3 This is a schematic diagram of joint voting based on cooperative spatial envelope for the gateway data security assurance method based on star flash technology provided in the embodiments of this application;

[0054] Figure 4 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0055] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0056] The technical solutions of this application will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0057] See Figure 1 This is a flowchart illustrating the gateway data security protection method based on StarFlash technology provided in this application embodiment. Figure 1The execution entity of the method shown can be a software and / or hardware device. The execution entity of this application can include, but is not limited to, at least one of the following: user equipment, network equipment, etc. User equipment can include, but is not limited to, computers, smartphones, personal digital assistants (PDAs), and the aforementioned electronic devices. Network equipment can include, but is not limited to, a single network server, a server group consisting of multiple network servers, or a cloud based on cloud computing consisting of a large number of computers or network servers. Cloud computing is a type of distributed computing, consisting of a super virtual computer composed of a group of loosely coupled computers. This embodiment does not impose any limitations on this.

[0058] Figure 2 Taking the application of this application in a smart vehicle charging scenario as an example. When an electric vehicle selects a charging station in a public parking lot, the vehicle needs to park in the parking space corresponding to the charging station, with the vehicle's charging port facing the charging station. The StarFlash gateway is located at the vehicle's central control console, and five mapping nodes are deployed at the left front door N1, right front door N2, instrument panel N3, left rear seat N4, and right rear seat N5, respectively, with the five mapping nodes spatially distributed. The vehicle's onboard image acquisition device can acquire scene images in the direction of the charging port. When the access terminal initiates an access request to the StarSpark Gateway, the StarSpark Gateway acquires scene images of the charging pile's direction using an image acquisition device and determines the charging pile's location. Simultaneously, each mapping node acquires the access terminal's radio frequency (RF) signal. The StarSpark Gateway determines the access signal's location based on the RF characteristic data observed by each mapping node. The StarSpark Gateway determines whether the access signal's location falls within a spatial sector centered on the charging pile's location. Based on the charging pile's location, the StarSpark Gateway divides each mapping node into a near-end node group and a far-end node group. The StarSpark Gateway verifies the spatial symmetry between the RF characteristic data observed by the near-end node group and the far-end node group. Based on the spatial symmetry verification result, the StarSpark Gateway determines the security decision.

[0059] This application includes steps S1 to S4, as detailed below:

[0060] Step S1: In response to the server status signal access of the target device, acquire scene images in the direction of the server and determine the server's orientation, and obtain the node spatial coordinates of each mapped node in the communication link corresponding to the StarSpark Gateway in the first coordinate system.

[0061] It should be noted that in the charging pile scenario, the target device refers to the electric vehicle, and the server refers to the charging pile. The server status signal can be a broadcast signal emitted by the charging pile or a handshake signal triggered after the charging gun is inserted into the charging port. Traditional gateway security verification schemes use a passive waiting approach, initiating the verification process only after the access end initiates a request. An attacker's relay device may launch an attack as soon as the vehicle comes to a complete stop. This application uses the access of the server status signal as the trigger condition. The StarFlash gateway initiates the security verification process when it detects a vehicle entering the charging scenario, intervening in the verification before the relay device launches an attack.

[0062] In some embodiments, step S1 includes steps S11 and S12, as follows:

[0063] Step S11: In response to the server status signal of the target device, acquire scene images in the direction of the server and determine the server's location.

[0064] It should be noted that traditional gateway security solutions rely entirely on radio frequency (RF) signals for verification, which are susceptible to multipath effects and obstruction. This application introduces image acquisition to determine the location of charging piles by identifying their outlines. The location information of the charging piles is independent of the RF signals, preventing attackers from tampering with the observed location of the charging piles in the image by forging RF signals.

[0065] Step S12: Obtain the node space coordinates of each mapped node in the communication link corresponding to the StarSpark Gateway in the first coordinate system.

[0066] It should be noted that the first coordinate system is a spatial coordinate system established with the target device as the reference. In the charging pile scenario, the first coordinate system can be the vehicle body coordinate system. The mapping nodes are fixedly installed in positions such as the car doors, seats, and dashboard. The node spatial coordinates of each mapping node are pre-measured and stored in the StarScan gateway. The StarScan gateway reads the node spatial coordinates of each mapping node in the first coordinate system from the memory.

[0067] Preferably, step S1 determines the server's orientation through image acquisition, step S1 establishes a spatial reference independent of the radio frequency signal for spatial verification, and step S1 obtains the node spatial coordinates of each mapping node to provide spatial geometric information for grouping the mapping nodes according to the server's orientation.

[0068] In some embodiments, step S11 is specifically implemented by steps S111 to S113:

[0069] Step S111: Acquire scene images from the server direction using the image acquisition device of the target device, perform edge detection on the scene images, and extract candidate contours from the scene images.

[0070] The image acquisition device is installed in a position that can cover the direction of the charging port. The installation parameters of the image acquisition device include parameters such as the installation position coordinates, orientation angle, and field of view. The installation parameters of the image acquisition device are pre-stored in the target device.

[0071] Understandably, when the StarScan gateway detects a server status signal, it controls the image acquisition device to acquire scene images in the direction of the server. An edge detection algorithm is then performed on the scene image; this algorithm can be either the Canny edge detection algorithm or the Sobel edge detection algorithm. Based on the edge detection results, candidate contours are extracted from the scene image; these candidate contours are closed or nearly closed edge curves identified by the edge detection algorithm.

[0072] For example, in a smart vehicle charging scenario, after detecting the handshake signal from the charging pile, the onboard image acquisition device acquires a scene image in the direction of the charging port. The resolution of the scene image is 1920×1080 pixels. The Canny edge detection algorithm is then applied to the scene image: Gaussian filtering is applied to reduce noise interference; the convolution kernel size for the Gaussian filter can be 5×5, and the standard deviation is set to 1.4. The Sobel operator is used to calculate the gradient values ​​of each pixel in the scene image in the horizontal and vertical directions. The gradient magnitude and gradient direction are calculated based on the horizontal and vertical gradient values. Non-maximum suppression is applied to the gradient magnitude, retaining pixels where the gradient magnitude along the gradient direction is a local maximum. Dual threshold detection and edge connection are used, with a high threshold set to 100 and a low threshold set to 50. Pixels with gradient magnitudes higher than the high threshold are marked as strong edge pixels, and pixels with gradient magnitudes between the high and low thresholds are marked as weak edge pixels. Weak edge pixels adjacent to strong edge pixels are retained as edge pixels, while other weak edge pixels are suppressed. Candidate contours are extracted from the scene image based on the results of Canny edge detection. Candidate contours are closed or nearly closed edge curves identified by the edge detection algorithm. Multiple candidate contours are identified in the scene image, such as the rectangular candidate contour of the charging pile shell, the circular candidate contour of the charging gun socket, and the strip-shaped candidate contour of the street lamp pole in the background.

[0073] Step S112: Based on the server standard contour features stored in the target device, determine the contour matching degree between each candidate contour and the server standard contour features, and take the candidate contour with the highest contour matching degree as the server contour.

[0074] Among them, the server-side standard contour features are typical appearance features of the charging pile. The server-side standard contour features include the shape features and size ratio features of the charging pile. The server-side standard contour features are pre-stored in the target device.

[0075] Understandably, each candidate contour is matched against the server-side standard contour features, and the contour matching degree between each candidate contour and the server-side standard contour features is calculated. The contour matching degree reflects the degree of similarity between the candidate contour and the server-side standard contour features. The contour matching degree can be calculated using template matching algorithms, shape context matching algorithms, or Hu moment matching algorithms. The candidate contour with the highest contour matching degree is determined as the server contour.

[0076] For example, the server-side standard contour features stored in the target device include typical appearance features of a DC charging pile. These features describe the rectangular main contour of the charging pile, the arcuate contour of the top indicator light area, and the specific shape features of the charging gun mounting area. Then, the Hu moment matching algorithm is used to calculate the contour matching degree between each candidate contour and the server-side standard contour features. For each candidate contour, seven Hu invariant moments are calculated, with values ​​η1 to η7. These Hu invariant moments are characterized by translation invariance, scaling invariance, and rotation invariance. Positional offsets, size changes, and angular tilts of the candidate contour in the scene image do not affect the values ​​of the Hu invariant moments. Seven Hu invariant moments are also calculated for the server-side standard contour features as reference values. The seven Hu invariant moments of the candidate contours are compared with the seven Hu invariant moments of the server-side standard contour features, and the Euclidean distance between the two sets of Hu invariant moments is calculated as a measure of the contour matching degree. A smaller Euclidean distance indicates a higher contour matching degree. Assuming the Euclidean distance between the Hu invariant moments of the candidate contour of the charging pile body identified in the scene image and the Hu invariant moments of the server standard contour features is 0.012, the Euclidean distance between the Hu invariant moments of the candidate contour of the street lamp pole and the Hu invariant moments of the server standard contour features is 0.285, and the Euclidean distance between the Hu invariant moments of the candidate contour of the billboard and the Hu invariant moments of the server standard contour features is 0.193, since the Euclidean distance of the candidate contour of the charging pile body is the smallest, i.e. the contour matching degree is the highest, the candidate contour of the charging pile body is determined as the server contour.

[0077] Step S113: Determine the server's orientation in the first coordinate system based on the center pixel coordinates of the server's outline in the scene image and the installation parameters of the image acquisition device.

[0078] Understandably, the process involves calculating the center pixel coordinates of the server-side contour, which represents the geometric center of the server-side contour within the scene image. Based on the horizontal position of the center pixel coordinates within the scene image, the horizontal deflection angle of the charging pile relative to the optical axis of the image acquisition device is determined. The angular resolution for each pixel is calculated based on the field of view of the image acquisition device and the number of horizontal pixels in the scene image. The horizontal deflection angle of the charging pile relative to the optical axis of the image acquisition device is then calculated based on the pixel difference between the horizontal pixel position of the center pixel coordinates and the pixel position of the image center, along with the angular resolution for each pixel. Finally, the azimuth angle of the charging pile in the first coordinate system is calculated based on the orientation angle of the image acquisition device and the horizontal deflection angle of the charging pile relative to the optical axis of the image acquisition device. This azimuth angle of the charging pile in the first coordinate system is then used as the server's azimuth.

[0079] Preferably, step S11 identifies the outline of the charging pile in the scene image through edge detection and contour matching. Step S11 determines the orientation of the charging pile relative to the vehicle based on the position of the charging pile outline in the scene image. Step S11 converts the image information into spatial orientation information. Step S11 provides a spatial reference independent of the radio frequency signal for determining whether the access signal comes from the direction of the charging pile.

[0080] In some embodiments, after determining the server's orientation in the first coordinate system, this application further includes:

[0081] By comparing the image region containing the server contour with the standard contour features of the server, and determining the presence of an abnormal attachment region in the image region, the abnormal attachment orientation corresponding to the abnormal attachment region is determined based on the center pixel coordinates of the abnormal attachment region and the installation parameters of the image acquisition device.

[0082] When the azimuth difference between the access signal location and the abnormal attachment location is less than the attachment association angle, and the increasing intensity direction points towards the server location, the security decision result is access rejection.

[0083] It should be noted that the relay equipment installed by attackers on the charging pile may be disguised as an original component of the charging pile and attached to its outer shell. This relay equipment will leave abnormal features on the charging pile's appearance. After determining the server's location, anomaly detection is performed on the image region containing the server's outline. The image region containing the server's outline is compared with the standard outline features of the server. When an abnormal attachment region is determined to exist in the image region, the set of boundary pixels of the abnormal attachment region is extracted. The average of the horizontal pixel positions of all pixels in the boundary pixel set of the abnormal attachment region is used to obtain the horizontal center pixel position of the abnormal attachment region. The average of the vertical pixel positions of all pixels in the boundary pixel set of the abnormal attachment region is used to obtain the vertical center pixel position of the abnormal attachment region. The horizontal and vertical center pixel positions of the abnormal attachment region are combined to form the region center pixel coordinates of the abnormal attachment region. Calculate the pixel offset between the horizontal center pixel position of the abnormal attachment region and the image center pixel position of the scene image. Determine the angle value corresponding to each pixel based on the field of view of the image acquisition device and the total number of horizontal pixels in the scene image. Combine the pixel offset with the angle value corresponding to each pixel to obtain the horizontal deflection angle of the abnormal attachment region relative to the optical axis of the image acquisition device. Combine the orientation angle of the image acquisition device with the horizontal deflection angle of the abnormal attachment region relative to the optical axis of the image acquisition device to obtain the azimuth angle of the abnormal attachment region in the first coordinate system. Use the azimuth angle of the abnormal attachment region in the first coordinate system as the abnormal attachment azimuth.

[0084] The attachment association angle is a preset angle threshold. In this application, the attachment association angle is mainly determined based on the angular resolution of the image acquisition device and the size range of the abnormal attachment region. The angular resolution of the image acquisition device is determined by the field of view of the image acquisition device and the total number of horizontal pixels in the scene image. The size range of the abnormal attachment region corresponds to the pixel width occupied by the abnormal attachment region in the scene image. The pixel width occupied by the abnormal attachment region in the scene image is combined with the angular resolution of the image acquisition device to obtain the angular span corresponding to the abnormal attachment region. The attachment association angle can be set as a certain multiple of the angular span corresponding to the abnormal attachment region. It is determined based on the actual situation that the access signal originates from the direction of the abnormal attachment region when the azimuth of the access signal falls within the angular range corresponding to the abnormal attachment region and its adjacent range.

[0085] Understandably, the azimuth difference between the access signal azimuth and the anomalous attachment azimuth is calculated. If the azimuth difference is less than the attachment-related angle, the access signal is determined to originate from the direction of the anomalous attachment area. If the increasing intensity direction points towards the server azimuth, the access signal is determined to originate from an anomalous attachment on the charging pile, and the radio frequency characteristic data observed by each mapping node shows an asymmetrical distribution pointing towards the charging pile, resulting in a security decision of access rejection. If the azimuth difference is not less than the attachment-related angle, or if the increasing intensity direction does not point towards the server azimuth, the security decision is not based on the anomalous attachment area, and the spatial symmetry verification process continues.

[0086] Step S2: Determine the location of the access signal of the access terminal in the first coordinate system based on the spatial coordinates of the nodes and the first feature data of the access terminal observed by each mapping node.

[0087] The first feature data includes a signal arrival time component and a received signal strength component. The signal arrival time component is the time when the radio frequency signal emitted by the access end arrives at each mapping node, and the received signal strength component is the power value of the radio frequency signal received by each mapping node.

[0088] It should be noted that when the access terminal initiates an access request to the StarSpark gateway, the radio frequency (RF) signal emitted by the access terminal is received by each mapping node. Due to differences in their distance from the access terminal, different mapping nodes receive the RF signal at different times; mapping nodes closer to the access terminal receive the RF signal first, and those farther away receive it later. This application uses the difference in signal arrival time components observed by each mapping node to estimate the spatial location of the access terminal, and determines the access signal orientation of the access terminal relative to the StarSpark gateway based on the spatial location of the access terminal. Existing technologies also use time difference of arrival to calculate the location of the access terminal, but the purpose of existing location calculations is to determine whether the access terminal is within the coverage area of ​​the gateway. The purpose of this application in calculating the access signal orientation is to compare the access signal orientation with the server orientation.

[0089] In some embodiments, step S2 includes steps S21 to S24, as follows:

[0090] Step S21: Determine the arrival time difference between any two mapping nodes based on the signal arrival time components observed by any two mapping nodes.

[0091] Here, the arrival time difference is the difference between the signal arrival time components observed by the two mapping nodes.

[0092] Understandably, each mapping node records the signal arrival time component upon receiving the RF signal from the access terminal, and reports this signal arrival time component to the StarScan gateway. The StarScan gateway selects any two mapping nodes, obtains the signal arrival time components observed by each of the two mapping nodes, and calculates the difference between the two signal arrival time components to obtain the arrival time difference between the two mapping nodes. Taking the left front door mapping node and the right rear seat mapping node as an example, the signal arrival time component observed by the left front door mapping node is the first moment, and the signal arrival time component observed by the right rear seat mapping node is the second moment. The difference between the first moment and the second moment is the arrival time difference between the left front door mapping node and the right rear seat mapping node. All mapping nodes are paired, and the arrival time difference between each pair of mapping nodes is calculated.

[0093] Step S22: Determine the distance difference between any two mapping nodes and the access end based on the time difference of arrival and the signal propagation speed.

[0094] It should be noted that radio frequency signals propagate in the form of electromagnetic waves, and the speed of electromagnetic waves in air is approximately the speed of light. The time difference of arrival reflects the difference in propagation time from the access point to the two mapping nodes. The difference in propagation time, combined with the propagation speed, can yield the difference in propagation distance.

[0095] Understandably, the signal propagation speed is obtained, which is the speed of electromagnetic waves in air. Combining the arrival time difference between any two mapping nodes with the signal propagation speed yields the distance difference between any two mapping nodes and the access point. This distance difference represents the difference between the distance from the access point to the first mapping node and the distance from the access point to the second mapping node. A positive arrival time difference indicates that the access point is closer to the first mapping node than to the second mapping node, while a negative arrival time difference indicates that the access point is farther from the first mapping node than to the second mapping node.

[0096] Step S23: Determine the spatial position coordinates of the access terminal in the first coordinate system based on the node spatial coordinates of each mapping node and the corresponding distance difference.

[0097] It is understandable that for any two mapping nodes, the access point positions satisfying the distance difference constraints form a hyperboloid in space with these two mapping nodes as foci. Multiple pairs of mapping nodes generate multiple distance difference constraints, which correspond to multiple hyperboloids. The intersection region of these hyperboloids in space represents the possible location range of the access point. A spatial geometric model is established based on the spatial coordinates of each mapping node. The distance difference between each pair of mapping nodes is used as a constraint condition to solve for the spatial position satisfying all distance difference constraints. The solved spatial position is then used as the spatial position coordinates of the access point in the first coordinate system. The solution method can employ the least squares method or an iterative approximation method. When measurement errors exist in multiple distance difference constraints, the solution method seeks the optimal spatial position coordinates that minimize the sum of the residuals of each distance difference constraint.

[0098] As mentioned in the previous example, the five mapping nodes of the StarSignal gateway communication link are deployed at the left front door N1, right front door N2, dashboard N3, left rear seat N4, and right rear seat N5, respectively. Based on the node spatial coordinates of the five mapping nodes in the vehicle body coordinate system, each mapping node calculates the distance difference constraints between ten pairs of mapping nodes after observing the signal arrival time component of the access terminal. Then, the least squares method is used to solve for the spatial coordinates that satisfy all distance difference constraints. The spatial coordinates of the access terminal are set as the three-dimensional unknowns (x, y, z) to be solved. A system of equations is constructed based on the node spatial coordinates of each pair of mapping nodes and the corresponding distance difference. Each equation in the system of equations indicates that the difference between the distance from the access terminal to the first mapping node and the distance from the access terminal to the second mapping node is equal to the distance difference constraint value. Due to the error in actual measurement, the ten equations generated by the ten pairs of mapping nodes cannot be simultaneously satisfied precisely. The least squares method is used to find the optimal spatial coordinates that minimize the sum of squared residuals of each distance difference constraint. The residual is defined as the deviation between the actual calculated distance difference and the measured distance difference constraint value. The objective function is constructed as the sum of squares of all residuals. The partial derivatives of the objective function are calculated and set to zero. The spatial coordinates that minimize the objective function are obtained, which are the spatial coordinates of the access end in the vehicle coordinate system.

[0099] Step S24: Determine the access signal orientation of the access terminal relative to the StarSpark gateway based on the spatial location coordinates and the gateway spatial coordinates of the StarSpark gateway.

[0100] The gateway spatial coordinates refer to the three-dimensional position of the StarSpark gateway in the first coordinate system, and these coordinates are pre-stored within the StarSpark gateway. When the origin of the vehicle body coordinate system is set at the StarSpark gateway's installation location, the gateway spatial coordinates are taken as the origin.

[0101] Understandably, based on the spatial coordinates of the access terminal obtained in step S23 and the gateway spatial coordinates of the StarScan gateway, the direction of the access terminal relative to the StarScan gateway is determined, and this direction is taken as the access signal azimuth. The access signal azimuth indicates the direction from which the radio frequency signal from the access terminal originates, and is expressed in angle values.

[0102] Preferably, step S2 calculates the spatial location of the access terminal by the difference between the signal arrival time components observed by multiple mapping nodes, determines the access signal orientation of the access terminal relative to the StarSpark gateway based on the spatial location of the access terminal, converts the radio frequency characteristic data into spatial orientation information, and provides orientation data based on radio frequency signals for determining whether the access signal comes from the direction of the server. Finally, the obtained access signal orientation and the server orientation obtained in step S1 belong to different information modes.

[0103] In some embodiments, step S24 is specifically implemented by steps S241 to S243:

[0104] Step S241: Construct a pointing vector based on the spatial location coordinates and the gateway spatial coordinates.

[0105] It should be noted that the pointing vector is the directional vector from the StarSpark gateway to the access point. The starting point of the pointing vector is the spatial coordinates of the gateway, and the ending point of the pointing vector is the spatial position coordinates.

[0106] Understandably, the process involves obtaining the spatial coordinates of the access point and the gateway spatial coordinates of the StarSpark gateway. The spatial coordinates include X, Y, and Z coordinate components, and the gateway spatial coordinates also include X, Y, and Z coordinate components. The difference between the X coordinate component of the spatial coordinates and the X coordinate component of the gateway spatial coordinates is used as the X component of the pointing vector; the difference between the Y coordinate component of the spatial coordinates and the Y coordinate component of the gateway spatial coordinates is used as the Y component of the pointing vector; and the difference between the Z coordinate component of the spatial coordinates and the Z coordinate component of the gateway spatial coordinates is used as the Z component of the pointing vector. The X, Y, and Z components of the pointing vector are then combined to form the pointing vector.

[0107] Step S242: Project the pointing vector onto the horizontal reference plane of the first coordinate system to obtain the projected pointing vector.

[0108] The horizontal reference plane is a plane parallel to the ground in the first coordinate system. In the vehicle body coordinate system, the horizontal reference plane is a plane composed of the X-axis and the Y-axis.

[0109] It is understood that a pointing vector is a vector in three-dimensional space, containing horizontal and vertical components. This application focuses on the orientation of the access point relative to the StarSpark gateway on the horizontal plane; therefore, this application needs to project the pointing vector onto a horizontal reference plane. The X and Y components of the pointing vector are retained, while the Z component is set to zero, resulting in the projected pointing vector. The projected pointing vector is the projection of the pointing vector onto the horizontal reference plane, and it represents the orientation of the access point relative to the StarSpark gateway on the horizontal plane.

[0110] Step S243: Determine the orientation of the access signal based on the angle between the projection pointing vector and the reference axis of the first coordinate system.

[0111] The reference axis is the reference axis used to measure the azimuth angle in the first coordinate system. In the vehicle coordinate system, the reference axis can be the X-axis, which is the direction directly in front of the vehicle.

[0112] Understandably, the calculation involves determining the angle between the projected pointing vector and the reference axis. The projected pointing vector contains X and Y components, and the reference axis is along the positive X-axis. The angle by which the projected pointing vector deviates from the reference axis is determined based on the ratio of the Y component to the X component of the projected pointing vector. When both the X and Y components of the projected pointing vector are positive, the angle is in the first quadrant; when both are negative, it is in the second quadrant; when both are negative, it is in the third quadrant; and when both are positive, it is in the fourth quadrant. The angle between the projected pointing vector and the reference axis is determined based on the values ​​of the X and Y components and their respective quadrants. This angle is then used as the azimuth of the incoming signal. The range of the access signal azimuth is 0 degrees to 360 degrees or -180 degrees to +180 degrees.

[0113] It should be noted that step S24 transforms the three-dimensional spatial position of the access point into an azimuth angle on a two-dimensional plane by constructing a pointing vector and projecting it onto a horizontal reference plane. The access signal azimuth obtained in step S24 uses the same angle representation as the server azimuth obtained in step S1. The fact that the access signal azimuth can be directly compared with the server azimuth is crucial. Step S24 provides comparable azimuth data for determining whether the access signal azimuth falls within a spatial sector centered on the server azimuth.

[0114] Step S3: When the location of the access signal falls within the spatial sector centered on the location of the server, mark the access terminal as a suspicious access terminal.

[0115] It should be noted that a spatial sector is a fan-shaped area centered on the server's location, covering the area in the direction the server is located. In a charging pile scenario, the spatial sector covers the direction of the charging pile, making access requests from that direction high-risk. Legitimate user equipment (UU) inside the vehicle is located within the vehicle, and its radio frequency (RF) signals will not originate from the charging pile direction. Relay equipment installed on the charging pile will inevitably transmit its RF signals from the charging pile direction. This application filters access requests from the server direction by determining whether the access signal's location falls within a spatial sector.

[0116] In some embodiments, determining that the location of the access signal falls within a spatial sector centered on the location of the server in step S3 includes steps S31 to S34:

[0117] Step S31: Extract the first boundary pixel coordinates and the second boundary pixel coordinates of the server contour.

[0118] Wherein, the first boundary pixel coordinates are the pixel positions of the left boundary point of the server contour in the scene image, and the second boundary pixel coordinates are the pixel positions of the right boundary point of the server contour in the scene image.

[0119] Understandably, step S112 has already determined the server-side contour, which is the outer contour of the charging pile in the scene image. All boundary pixels of the server-side contour are traversed, and the boundary pixel with the smallest horizontal pixel position is found as the left boundary point of the server-side contour. The pixel position of the left boundary point is used as the first boundary pixel coordinate. The boundary pixel with the largest horizontal pixel position is found as the right boundary point of the server-side contour, and the pixel position of the right boundary point is used as the second boundary pixel coordinate. The first and second boundary pixel coordinates correspond to the left and right edge positions of the charging pile in the scene image, respectively.

[0120] Step S32: Determine the azimuth angle of the server contour relative to the first boundary of the image acquisition device based on the first boundary pixel coordinates and the installation parameters of the image acquisition device.

[0121] Understandably, the process involves obtaining the horizontal pixel position of the first boundary pixel coordinates and the image center pixel position of the scene image. The pixel offset between the horizontal pixel position of the first boundary pixel coordinates and the image center pixel position of the scene image is calculated. The angle value corresponding to each pixel is determined based on the field of view of the image acquisition device and the total number of horizontal pixels in the scene image; specifically, it is the ratio of the field of view of the image acquisition device to the total number of horizontal pixels in the scene image. The pixel offset is combined with the angle value corresponding to each pixel to obtain the horizontal deflection angle of the left boundary of the server contour relative to the optical axis of the image acquisition device. The orientation angle of the image acquisition device is combined with the horizontal deflection angle of the left boundary of the server contour relative to the optical axis of the image acquisition device to obtain the first boundary azimuth angle. The first boundary azimuth angle represents the orientation of the left edge of the charging pile in the first coordinate system.

[0122] Step S33: Determine the azimuth angle of the server contour relative to the second boundary of the image acquisition device based on the second boundary pixel coordinates and the installation parameters of the image acquisition device.

[0123] Understandably, the second boundary pixel coordinates are processed using the same method as in step S32. The pixel offset between the horizontal pixel position of the second boundary pixel coordinates and the image center pixel position of the scene image is calculated. This pixel offset is combined with the angle value corresponding to each pixel to obtain the horizontal deflection angle of the right boundary of the server contour relative to the optical axis of the image acquisition device. The orientation angle of the image acquisition device is then combined with the horizontal deflection angle of the right boundary of the server contour relative to the optical axis of the image acquisition device to obtain the second boundary azimuth angle. The second boundary azimuth angle represents the orientation of the right edge of the charging pile in the first coordinate system.

[0124] Step S34: Determine the sector boundary of the spatial sector based on the first boundary azimuth angle and the second boundary azimuth angle. When the azimuth of the access signal is within the angle range defined by the first boundary azimuth angle and the second boundary azimuth angle, determine that the azimuth of the access signal falls into the spatial sector.

[0125] It is understandable that the first boundary azimuth and the second boundary azimuth define the left and right boundaries of the spatial sector, and the spatial sector is the angular range between the first boundary azimuth and the second boundary azimuth. The first boundary azimuth is taken as the left boundary of the spatial sector, and the second boundary azimuth is taken as the right boundary of the spatial sector.

[0126] Obtain the access signal azimuth obtained in step S2, and determine whether the access signal azimuth is within the angle range defined by the first boundary azimuth angle and the second boundary azimuth angle. If the access signal azimuth is greater than or equal to the first boundary azimuth angle and less than or equal to the second boundary azimuth angle, the access signal azimuth is determined to fall within a spatial sector, and the access terminal is marked as a suspicious access terminal. If the access signal azimuth is less than the first boundary azimuth angle or greater than the second boundary azimuth angle, the access signal azimuth is determined not to fall within a spatial sector, and the access terminal is not marked as a suspicious access terminal, indicating that the access signal comes from a direction other than the server.

[0127] It should be noted that steps S31 to S34 determine the boundaries of the spatial sector by extracting the left and right boundary pixel coordinates of the server contour and converting them into azimuth angles. The boundaries of the spatial sector correspond to the actual range of the server contour in the scene image, and the spatial sector accurately covers the directional range where the server is located. Steps S31 to S34 convert the pixel positions in the image space into azimuth angles in the first coordinate system, enabling a direct comparison between the image-based server azimuth information and the access signal azimuth based on the radio frequency signal.

[0128] Preferably, step S3 filters suspicious access points by determining whether the location of the access signal falls within a spatial sector centered on the server's location. Access requests originating from a spatial sector are marked as suspicious access points, while access requests from other directions are not. This filtering focuses security verification on access requests originating from the server, improving the targeting of security verification and reducing the probability of false positives for legitimate access requests from other directions.

[0129] Step S4: Group each mapping node according to the server's location, verify the suspicious access terminal based on the spatial symmetry between the first feature data of each mapping node group, and obtain the security decision result.

[0130] It should be noted that step S3 has already screened out suspicious access points from the server direction, and step S4 needs to further verify whether the suspicious access points are relay devices. The relay devices are installed on the charging pile, located at the edge of the vehicle body towards the server direction rather than inside the vehicle. Mapping nodes closer to the server direction are closer to the relay devices, while mapping nodes farther from the server direction are farther away. Mapping nodes closer to the server direction observe higher signal strength, while mapping nodes farther from the server direction observe lower signal strength. The radio frequency characteristic data observed by each mapping node shows an asymmetrical distribution pointing towards the server direction. The legitimate user equipment inside the vehicle is located in the central area of ​​the vehicle body. The distance between each mapping node and the legitimate user equipment is not significantly different, and the radio frequency characteristic data observed by each mapping node shows a relatively symmetrical distribution. This application divides the mapping nodes into near-end node groups and far-end node groups based on the server orientation, and verifies spatial symmetry by comparing the radio frequency characteristic data observed by the near-end node groups and far-end node groups.

[0131] In some embodiments, step S4 includes steps S41 and S42:

[0132] Step S41: Group the mapping nodes according to the server's location.

[0133] In some embodiments, step S41 is specifically implemented by steps S411 to S413:

[0134] Step S411: Determine the node azimuth angle of each mapping node relative to the StarSpark gateway based on the node spatial coordinates of each mapping node and the gateway spatial coordinates of the StarSpark gateway.

[0135] The process involves obtaining the node spatial coordinates of each mapping node and the gateway spatial coordinates of the StarScan gateway. For each mapping node, the difference between its node spatial coordinates and the gateway spatial coordinates is used as the direction vector from the StarScan gateway to the mapping node. The X and Y components of the direction vector are retained, and the orientation of the mapping node relative to the StarScan gateway on the horizontal plane is determined based on these components. This orientation is then expressed as an angle value, which is taken as the node azimuth. This same operation is performed on all mapping nodes to obtain the node azimuth of each mapping node relative to the StarScan gateway.

[0136] Step S412: Determine the azimuth deviation angle corresponding to each mapping node based on the angle difference between the azimuth angle of each node and the azimuth of the server, and determine the grouping boundary angle based on the number and spatial distribution of the mapping nodes.

[0137] The azimuth deviation angle is the absolute value of the angular difference between the node's azimuth and the server's azimuth. It reflects the degree of deviation of the mapped node from the server's direction. A smaller azimuth deviation angle indicates that the mapped node is closer to the server's direction, while a larger angle indicates that the mapped node is farther away from the server's direction.

[0138] Understandably, after obtaining the server's azimuth from step S1, the angle difference between the node's azimuth and the server's azimuth is calculated for each mapping node. The absolute value of this angle difference is used as the azimuth deviation angle corresponding to the mapping node. The group boundary angle is the angle threshold that distinguishes between near-end and far-end node groups. Determining the group boundary angle requires ensuring that both near-end and far-end node groups contain a sufficient number of mapping nodes. One way to determine the group boundary angle is to arrange the azimuth deviation angles of each mapping node in ascending order and select the azimuth deviation angle in the middle position as the group boundary angle. Another way to determine the group boundary angle is to use 90 degrees as the group boundary angle; mapping nodes with azimuth deviation angles less than 90 degrees are located within the server's hemisphere, while mapping nodes with azimuth deviation angles not less than 90 degrees are located outside the server's hemisphere.

[0139] Step S413: Divide the mapping nodes whose azimuth deviation angle is less than the grouping boundary angle into the near-end node group, and divide the mapping nodes whose azimuth deviation angle is not less than the grouping boundary angle into the far-end node group.

[0140] It should be noted that the near-end node group includes mapping nodes that are closer to the server, while the far-end node group includes mapping nodes that are farther from the server. In the charging pile scenario, assuming the charging port is located on the right side of the vehicle and the charging pile is also on the right side, the right front door mapping node and the right rear seat mapping node are closer to the charging pile, and their azimuth deviation angles are small, so they are assigned to the near-end node group. The left front door mapping node, the left rear seat mapping node, and the dashboard mapping node are farther from the charging pile, and their azimuth deviation angles are large, so they are assigned to the far-end node group.

[0141] Preferably, step S41 groups the mapping nodes according to the server's orientation. Step S41 divides the mapping nodes into a near-end node group (closer to the server) and a far-end node group (farther from the server). The division between the near-end and far-end node groups is based on the orientation deviation angle of each mapping node relative to the server's orientation. Step S41 establishes a correlation between the grouping of the mapping nodes and the server's orientation, providing a grouping basis for subsequent comparison of the radio frequency characteristic data observed by the near-end node group and the far-end node group.

[0142] Step S42: Verify the suspicious access point based on the spatial symmetry between the first feature data of each mapping node group, and obtain the security decision result.

[0143] like Figure 3 As shown, in some embodiments, step S42 is specifically implemented by including steps S421 to S423:

[0144] Step S421: Determine the near-end observation intensity based on the received signal intensity component in the first feature data observed by the near-end node group, and determine the far-end observation intensity based on the received signal intensity component observed by the far-end node group.

[0145] Among them, the near-end observation intensity is the statistical value of the received signal strength component observed by the near-end node group, and the far-end observation intensity is the statistical value of the received signal strength component observed by the far-end node group.

[0146] Understandably, the process involves acquiring the first feature data observed by each mapping node in the near-end node group, and extracting the received signal strength component from this data. Statistical processing is then performed on the received signal strength components observed by each mapping node in the near-end node group. This processing can be done by calculating the average or the median, and the result is taken as the near-end observed intensity. The same statistical processing method is applied to the far-end node group, acquiring the received signal strength components observed by each mapping node in the far-end node group and performing statistical processing. The result is then taken as the far-end observed intensity.

[0147] Step S422: When the intensity difference between the near-end observation intensity and the far-end observation intensity is less than the symmetry tolerance threshold, the suspicious access end is determined to have passed the spatial symmetry verification, and the security decision result is an access permission.

[0148] The intensity difference is the absolute value of the difference between the intensity observed at the near end and the intensity observed at the far end. The symmetry tolerance threshold is a preset intensity difference threshold, which is used to determine whether the radio frequency feature data observed by the near-end node group and the far-end node group exhibit a symmetrical distribution.

[0149] Understandably, the difference between the near-end and far-end observation intensities is calculated, and the absolute value of the difference is taken as the intensity difference. The intensity difference is then compared to the symmetry tolerance threshold. If the intensity difference is determined to be less than the symmetry tolerance threshold, the radio frequency characteristic data observed by the near-end and far-end node groups are considered to exhibit a relatively symmetrical distribution. This relatively symmetrical distribution indicates that the access point is located in the central region of the vehicle body rather than the service direction at the edge of the vehicle body. The suspicious access point is thus deemed to have passed the spatial symmetry verification, and the security decision result is granted access permission.

[0150] The symmetry tolerance threshold is determined based on the signal propagation characteristics of StarScan communication and the spatial distribution of mapping nodes. Setting the symmetry tolerance threshold requires considering the range of differences in received signal strength components observed by the near-end and far-end node groups when legitimate user equipment is located at different positions within the vehicle under normal conditions. The symmetry tolerance threshold is set to the upper limit of the normal difference range; a difference in strength less than the symmetry tolerance threshold indicates that the difference in observed data is within the normal range.

[0151] Step S423: When it is determined that the intensity of the near-end observation is higher than that of the far-end observation, and the direction of the intensity increase corresponding to the intensity difference between the near-end observation intensity and the far-end observation intensity points to the direction of the server, it is determined that the suspicious access end has failed the spatial symmetry verification, and the security decision result is access rejection.

[0152] Understandably, when the intensity difference is determined to be no less than the symmetry tolerance threshold, the directionality of the intensity difference is further determined. The magnitude relationship between the near-end and far-end observed intensity is compared. If the near-end observed intensity is higher than the far-end observed intensity, the signal strength observed by the mapping node closer to the server is determined to be higher than the signal strength observed by the mapping node farther from the server. Further determination is made as to whether the intensity increase direction points to the server's location; the intensity increase direction is the direction in which the signal strength changes from low to high. If the intensity increase direction points to the server's location, it is determined that the radio frequency characteristic data observed by each mapping node exhibits an asymmetrical distribution pointing towards the server. This asymmetrical distribution pointing towards the server is consistent with the characteristics of the relay device located in the server's direction. Therefore, it is determined that the suspicious access point has failed the spatial symmetry verification, resulting in an access denial security decision.

[0153] If it is determined that the intensity of the near-end observation is not higher than that of the far-end observation, or if it is determined that the direction of the intensity increase does not point to the location of the server, it is determined that although there are differences in the radio frequency feature data observed by each mapping node, the direction of the difference does not point to the location of the server. If no security decision is obtained, it is an access rejection. Radio frequency feature data can continue to be collected for verification, or the security decision can be determined based on other verification conditions.

[0154] It should be noted that step S42 verifies spatial symmetry by comparing the received signal strength components observed by the near-end node group and the far-end node group. Step S42 determines the security decision based on the spatial symmetry verification result. If the intensity difference is less than the symmetry tolerance threshold, it indicates that the observed data exhibits a symmetrical distribution. This symmetrical distribution indicates that the access point is located inside the vehicle rather than in the direction of the server. Step S42 then obtains a security decision of access permission. If the near-end observed intensity is higher than the far-end observed intensity and the increasing intensity direction points towards the server, it indicates that the observed data exhibits an asymmetrical distribution pointing towards the server. This asymmetrical distribution pointing towards the server indicates that the access point is located in the direction of the server. Step S42 then obtains a security decision of access denial.

[0155] Preferably, step S4 identifies the relay device by grouping the mapped nodes according to the server's location and verifying spatial symmetry. Step S4 combines the server's location information with the spatial distribution characteristics of the radio frequency feature data, enabling it to identify the asymmetric distribution pattern caused by the relay device located in the server's direction. Since the attacker's relay device is installed on the charging pile, the relay device will inevitably cause the mapped nodes near the charging pile to observe higher signal strength. Step S4 can identify the relay device based on the asymmetric distribution characteristics of the observed data.

[0156] It should be noted that step S423, which determines that the near-end observation intensity is higher than the far-end observation intensity, and that the direction of intensity increase corresponding to the intensity difference between the near-end and far-end observation intensities points towards the server's azimuth, includes steps A1 to A3:

[0157] Step A1: Determine the centroid coordinates of the intensity distribution of the near-end node group based on the node spatial coordinates of each mapped node in the near-end node group and the corresponding observed received signal intensity components.

[0158] The centroid coordinates of the intensity distribution are the weighted center positions of the near-end node group calculated with the received signal intensity components as weights. The higher the received signal intensity component, the greater the contribution of the mapping node to the centroid coordinates of the intensity distribution.

[0159] Specifically, step A1 includes steps A11 and A12:

[0160] Step A11: Normalize the received signal strength components observed by each mapping node in the near-end node group to obtain the normalized strength value corresponding to each mapping node.

[0161] Understandably, this involves obtaining the received signal strength components observed by each mapping node in the near-end node group. The numerical range of these received signal strength components may be large, so normalization is performed to facilitate subsequent calculations. The normalization process involves mapping the received signal strength components observed by each mapping node to a range of 0 to 1. The maximum and minimum values ​​of the received signal strength components in the near-end node group are then found. For each mapping node, the difference between the received signal strength component and the minimum value is divided by the difference between the maximum and minimum values ​​to obtain the normalized strength value for that mapping node. The normalized strength value ranges from 0 to 1, with the mapping node having the highest received signal strength component having a normalized strength value of 1, and the mapping node having the lowest received signal strength component having a normalized strength value of 0.

[0162] Step A12: Determine the centroid coordinates of the intensity distribution of the near-end node group based on the node spatial coordinates of each mapped node and the corresponding intensity normalization value.

[0163] It should be explained that the calculation principle of the centroid coordinates of the intensity distribution is similar to the calculation of the centroid in physics. The higher the received signal intensity component, the greater the contribution of the mapping node to the centroid coordinates of the intensity distribution.

[0164] Understandably, for each mapped node in the near-end node group, the X-coordinate component of the node's spatial coordinates is combined with the corresponding intensity normalized value, and the Y-coordinate component of the node's spatial coordinates is also combined with the corresponding intensity normalized value. The results of combining the X-coordinate components of all mapped nodes with their intensity normalized values ​​are summed, and the ratio of this sum to the sum of the intensity normalized values ​​of all mapped nodes is used as the X-coordinate component of the intensity distribution centroid coordinates. Similarly, the results of combining the Y-coordinate components of all mapped nodes with their intensity normalized values ​​are summed, and the ratio of this sum to the sum of the intensity normalized values ​​of all mapped nodes is used as the Y-coordinate component of the intensity distribution centroid coordinates. Finally, the X-coordinate and Y-coordinate components of the intensity distribution centroid coordinates are combined to form the intensity distribution centroid coordinates of the near-end node group.

[0165] It should be noted that step A1 determines the centroid coordinates of the intensity distribution of the near-end node group through normalization and weighted calculation. The centroid coordinates of the intensity distribution are biased towards the location of the mapping node with higher received signal strength components. When the access end is located in the direction of the server end, the mapping node closer to the server end observes a higher received signal strength component, and the centroid coordinates of the intensity distribution will be biased towards the server end.

[0166] Step A2: Determine the geometric center coordinates of the remote node group based on the node space coordinates of each mapped node in the remote node group.

[0167] The geometric center coordinates are the average position of the node spatial coordinates of each mapped node in the remote node group. The geometric center coordinates do not take into account the weight of the received signal strength component.

[0168] The process involves obtaining the node spatial coordinates of each mapped node in the remote node group. The X-coordinate components of all mapped node spatial coordinates are summed, and the ratio of this summation to the number of mapped nodes in the remote node group is used as the X-coordinate component of the geometric center coordinates. Similarly, the Y-coordinate components of all mapped node spatial coordinates are summed, and the ratio of this summation to the number of mapped nodes in the remote node group is used as the Y-coordinate component of the geometric center coordinates. Finally, the X-coordinate and Y-coordinate components of the geometric center coordinates are combined to form the geometric center coordinates of the remote node group.

[0169] Step A3: Determine the direction of intensity increase based on the direction from the geometric center coordinates to the centroid coordinates of the intensity distribution.

[0170] Understandably, the difference between the coordinates of the centroid of the intensity distribution and the coordinates of the geometric center is used as the direction vector pointing from the geometric center to the centroid of the intensity distribution. The X and Y components of the direction vector are retained, and the angle of the direction vector on the horizontal plane is determined based on these components. This angle is then used as the direction of increasing intensity. The direction of increasing intensity indicates the direction in which signal strength increases from the far-end node group to the near-end node group, pointing towards areas of higher signal strength.

[0171] Step A4: Determine the allowable direction angle based on the field of view of the image acquisition device and the angular span of the server contour in the scene image. If the directional deviation angle between the intensity increasing direction and the server orientation is less than the allowable direction angle, determine that the intensity increasing direction points to the server orientation.

[0172] Among them, the direction tolerance angle is the angular tolerance for determining whether the direction of intensity increase points to the location of the server, and the direction deviation angle is the absolute value of the angular difference between the direction of intensity increase and the location of the server.

[0173] Understandably, the angular span of the server contour in the scene image is determined based on the field of view of the image acquisition device and the pixel width occupied by the server contour in the scene image. The angular span of the server contour in the scene image is the corresponding angular range between the left and right boundaries of the server contour. The allowable direction angle is determined based on the angular span of the server contour in the scene image. The allowable direction angle can be set to a certain multiple of the angular span of the server contour in the scene image. The setting of the allowable direction angle ensures that when the intensity increasing direction falls within the server's azimuth and its vicinity, the intensity increasing direction is determined to point towards the server's azimuth.

[0174] Calculate the angular difference between the intensity increasing direction and the server's azimuth, and use the absolute value of this angular difference as the direction deviation angle. Compare the direction deviation angle with the allowable direction angle. If the direction deviation angle is less than the allowable direction angle, the intensity increasing direction is determined to point towards the server's azimuth. If the direction deviation angle is not less than the allowable direction angle, the intensity increasing direction is determined not to point towards the server's azimuth.

[0175] Preferably, steps A1 to A4 determine the direction of intensity increase by calculating the centroid coordinates and geometric center coordinates of the intensity distribution. Steps A1 to A4 then compare the direction of intensity increase with the server's azimuth to determine whether the asymmetric distribution of the observed data points towards the server. Steps A1 to A4 not only verify whether the near-end observed intensity is higher than the far-end observed intensity, but also verify whether the direction of intensity increase is consistent with the server's azimuth. If the direction of intensity increase points towards the server's azimuth, it indicates that the asymmetric distribution is caused by the access point being located in the server's direction. Steps A1 to A4 can rule out asymmetric distributions caused by obstructions inside the vehicle or other reasons.

[0176] In some embodiments, after obtaining the security ruling, this application further includes:

[0177] During the duration of the server status signal, scene images in the direction of the server are periodically collected, and the server's orientation is updated based on the periodically collected scene images.

[0178] Periodically collect the first feature data of the access end observed by each mapping node, redetermine the azimuth deviation angle corresponding to each mapping node according to the updated server azimuth, and re-divide the near-end node group and the far-end node group according to the redetermined azimuth deviation angle.

[0179] The access point is re-verified based on the first characteristic data of the newly divided near-end node group and far-end node group. When the security decision result obtained from the re-verification changes, the security decision result is updated based on the security decision result obtained from the re-verification.

[0180] It should be noted that in charging pile scenarios, the charging process typically lasts from tens of minutes to several hours, during which the relay device has ample time to continuously attempt to connect to the StarSignal gateway. This application periodically collects scene images and radio frequency characteristic data during the duration of the server's status signal. Based on the periodically collected data, it updates the server's location and re-divides the mapping node groups, then re-verifies the access end based on the re-dividated groups. This periodic and continuous monitoring can address dynamic risk changes during the charging process and can detect relay devices launching attacks mid-charging.

[0181] In summary, this application identifies relay devices by recognizing the server's location through image recognition and grouping mapping nodes accordingly. It then verifies the spatial symmetry between the radio frequency (RF) feature data observed by the near-end and far-end node groups. Combining image recognition with RF feature verification forms a cross-modal fusion verification. The server's location is determined through image acquisition, the access signal's location is determined through RF feature calculation, and the direction of intensity increase is determined through the spatial distribution calculation of RF features. Since the attacker's relay device is installed on the charging pile, it will inevitably be located in the server's direction. This will cause each mapping node to observe an asymmetrical distribution pointing towards the server, thus enabling the relay device to be identified through joint verification of image information and RF features. This application can prevent spoofing attacks where the identity credentials are legitimate but the physical location is outside the designated area, improving the reliability of gateway security decisions.

[0182] See Figure 4 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. The electronic device 40 includes: a processor 41, a memory 42, and a computer program; wherein,

[0183] The memory 42 is used to store the computer program, and the memory may also be flash memory. The computer program is, for example, an application program or functional module that implements the above method.

[0184] The processor 41 is configured to execute the computer program stored in the memory to implement the various steps performed by the device in the above method. For details, please refer to the relevant descriptions in the preceding method embodiments.

[0185] Alternatively, the memory 42 can be either standalone or integrated with the processor 41.

[0186] When the memory 42 is a device independent of the processor 41, the device may further include:

[0187] Bus 43 is used to connect the memory 42 and the processor 41.

[0188] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A gateway data security assurance method based on StarFlash technology, characterized in that, include: In response to the server status signal access of the target device, the scene image in the direction of the server is collected and the server location is determined. The node spatial coordinates of each mapped node in the communication link corresponding to the StarSpark Gateway in the first coordinate system are obtained. Based on the node spatial coordinates and the first feature data of the access terminal observed by each mapping node, the access signal orientation of the access terminal in the first coordinate system is determined. When it is determined that the location of the access signal falls within a spatial sector centered on the location of the server, the access terminal is marked as a suspicious access terminal. Based on the server's location, each mapping node is grouped, and the suspicious access point is verified based on the spatial symmetry between the first feature data of each mapping node group to obtain a security decision result.

2. The method according to claim 1, characterized in that, The process of acquiring scene images from the server's direction and determining the server's location includes: The target device acquires scene images from the server direction using its image acquisition device, performs edge detection on the scene images, and extracts candidate contours from the scene images. Based on the server standard contour features stored in the target device, determine the contour matching degree between each candidate contour and the server standard contour features, and take the candidate contour with the highest contour matching degree as the server contour. Based on the center pixel coordinates of the server's outline in the scene image and the installation parameters of the image acquisition device, the server's orientation in the first coordinate system is determined.

3. The method according to claim 1, characterized in that, The first feature data includes the signal arrival time component and the received signal strength component; The step of determining the access signal orientation of the access terminal in the first coordinate system based on the node spatial coordinates and the first feature data of the access terminal observed by each mapping node includes: Determine the arrival time difference between any two mapping nodes based on the signal arrival time components observed by any two mapping nodes; Based on the arrival time difference and signal propagation speed, determine the distance difference between any two mapping nodes and the access terminal; Based on the node spatial coordinates of each mapping node and the corresponding distance difference, the spatial position coordinates of the access terminal in the first coordinate system are determined; Based on the spatial location coordinates and the gateway spatial coordinates of the StarSpark gateway, the orientation of the access signal of the access terminal relative to the StarSpark gateway is determined.

4. The method according to claim 3, characterized in that, Determining the access signal orientation of the access terminal relative to the StarSpark gateway based on the spatial location coordinates and the gateway spatial coordinates of the StarSpark gateway includes: Construct a pointing vector based on the spatial location coordinates and the gateway spatial coordinates; Projecting the pointing vector onto the horizontal reference plane of the first coordinate system yields the projected pointing vector; The orientation of the access signal is determined based on the angle between the projection pointing vector and the reference axis of the first coordinate system.

5. The method according to claim 2, characterized in that, Determining that the location of the access signal falls within a spatial sector centered on the location of the server includes: Extract the first boundary pixel coordinates and the second boundary pixel coordinates of the server-side contour; Based on the first boundary pixel coordinates and the installation parameters of the image acquisition device, the first boundary azimuth angle of the server contour relative to the image acquisition device is determined; Based on the second boundary pixel coordinates and the installation parameters of the image acquisition device, the second boundary azimuth angle of the server contour relative to the image acquisition device is determined; The sector boundary of the spatial sector is determined based on the first boundary azimuth angle and the second boundary azimuth angle. When the azimuth angle of the access signal is determined to be within the angle range defined by the first boundary azimuth angle and the second boundary azimuth angle, it is determined that the azimuth angle of the access signal falls into the spatial sector.

6. The method according to claim 1, characterized in that, The grouping of each mapping node according to the server's location includes: Based on the node spatial coordinates of each mapping node and the gateway spatial coordinates of the StarSpark gateway, determine the node azimuth angle of each mapping node relative to the StarSpark gateway. Based on the angle difference between the azimuth of each node and the azimuth of the server, the azimuth deviation angle corresponding to each mapping node is determined, and the grouping boundary angle is determined based on the number and spatial distribution of the mapping nodes. Mapping nodes with azimuth deviation angles less than the grouping boundary angle are classified into near-end node groups, and mapping nodes with azimuth deviation angles not less than the grouping boundary angle are classified into far-end node groups.

7. The method according to claim 6, characterized in that, The verification of the suspicious access point based on the spatial symmetry between the first feature data of each mapping node group, to obtain a security decision result, includes: The near-end observation intensity is determined based on the received signal strength component in the first feature data observed by the near-end node group, and the far-end observation intensity is determined based on the received signal strength component observed by the far-end node group. When the intensity difference between the near-end observation intensity and the far-end observation intensity is determined to be less than the symmetry tolerance threshold, the suspicious access terminal is determined to have passed the spatial symmetry verification, and the security decision result is an access permission. When it is determined that the near-end observation intensity is higher than the far-end observation intensity, and the direction of intensity increase corresponding to the intensity difference between the near-end and far-end observation indices points towards the server, the suspected access terminal is deemed to have failed the spatial symmetry verification, and the security decision result is access denied.

8. The method according to claim 7, characterized in that, The determination that the near-end observation intensity is higher than the far-end observation intensity, and that the direction of intensity increase corresponding to the intensity difference between the near-end and far-end observation intensities points towards the server location, includes: Based on the node spatial coordinates of each mapped node in the near-end node group and the corresponding observed received signal strength components, the centroid coordinates of the intensity distribution of the near-end node group are determined. The geometric center coordinates of the remote node group are determined based on the node space coordinates of each mapped node in the remote node group. The direction of intensity increase is determined based on the direction from the geometric center coordinates to the centroid coordinates of the intensity distribution; The allowable directional angle is determined based on the field of view of the image acquisition device and the angular span of the server's outline in the scene image. When the directional deviation angle between the intensity increasing direction and the server's orientation is less than the allowable directional angle, the intensity increasing direction is determined to point to the server's orientation.

9. The method according to claim 8, characterized in that, The step of determining the centroid coordinates of the intensity distribution of the near-end node group based on the node spatial coordinates of each mapped node in the near-end node group and the corresponding observed received signal intensity components includes: The received signal strength components observed by each mapping node in the near-end node group are normalized to obtain the intensity normalization value corresponding to each mapping node. The centroid coordinates of the intensity distribution of the near-end node group are determined based on the node spatial coordinates of each mapping node and the corresponding intensity normalization value.

10. The method according to claim 2, characterized in that, After determining the server's location in the first coordinate system, the method further includes: When the image region containing the server contour is compared with the standard contour features of the server, and an abnormal attachment region is determined to exist in the image region, the abnormal attachment orientation corresponding to the abnormal attachment region is determined according to the center pixel coordinates of the abnormal attachment region and the installation parameters of the image acquisition device. When the azimuth difference between the access signal azimuth and the abnormal attachment azimuth is less than the attachment association angle, and the increasing intensity direction points towards the server azimuth, the security decision result is access rejection.