Space-time fence-based cyber physical attack and defense drill method and system for geographic information security of internet of vehicles
By employing a spatiotemporal fence-based approach to attack and defend geographic information security in connected vehicles, a hybrid simulation environment was constructed. By combining dynamic spatiotemporal fences and Bi-LSTM models, the problems of data transmission security and uneven resource allocation of geographic information in intelligent connected vehicles were solved, achieving efficient and flexible security protection and resource optimization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINESE ACAD OF SURVEYING & MAPPING
- Filing Date
- 2026-05-13
- Publication Date
- 2026-07-21
AI Technical Summary
In existing technologies, the geographic information data of intelligent connected vehicles is vulnerable to attacks during transmission, leading to navigation errors and security risks. Traditional geofencing cannot adapt to dynamic threats, scheduling strategies lack flexibility and accuracy, resource allocation is uneven, and attack and defense drills are costly and limited to a single scenario.
A spatiotemporal fence-based geographic information security attack and defense exercise method for vehicle networks was adopted. By constructing a hybrid simulation environment, using a dynamic spatiotemporal fence rule base and encryption algorithm, and combining a Bi-LSTM model for data feature extraction and node allocation, dynamic defense and resource optimization were achieved.
It ensures the confidentiality and integrity of geographic information data, improves the real-time response capability and resource utilization of defense strategies, reduces testing costs, and expands the scope of scenarios and verification efficiency.
Smart Images

Figure CN122179246B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method and system for attack and defense drills of geographic information security in vehicle-to-everything (V2X) networks based on spatiotemporal fences. It is applicable to the dynamic security protection and distributed resource intelligent scheduling of high-precision geographic information data in V2X communication scenarios, and belongs to the field of intelligent connected vehicles and geographic information security technology. Background Technology
[0002] The current vehicle-to-infrastructure (V2I) interaction in intelligent connected vehicle scenarios requires high-precision geographic information data. If these high-precision coordinates are obtained or tampered with by attackers during transmission, it could potentially lead to navigation errors, malicious guidance, and malfunctions in intelligent driving systems. A comprehensive, systematic, and intuitive deep visualization of potential geographic information security risks in these scenarios, along with corresponding efficient and feasible risk triggering mechanisms and security defense strategies, is crucial for improving awareness of geographic information security risks and enhancing technical defense capabilities in intelligent connected vehicle scenarios.
[0003] Currently, intelligent connected vehicle attack and defense drills mainly rely on physical vehicles and roadside equipment to build closed test fields. However, this model is difficult to meet complex attack and defense verification needs, and the testing cost is high and the scenarios are limited. Typically, a single attack and defense drill requires the deployment of dozens of real vehicles and supporting equipment such as RSUs. In addition, the deployment cycle is long, and it can only reproduce simple, inherent road environments such as intersections and straight road sections, and cannot construct extreme traffic conditions such as large-scale vehicle collaborative attacks or chain-reaction rear-end collisions. At the same time, if real high-precision coordinates are used directly in attack tests, important data may be leaked due to backdoors in equipment or protocol vulnerabilities, posing significant geographic information security risks.
[0004] Meanwhile, traditional geofencing technology has limitations in dealing with dynamic security threats. Preset, static, fixed fence boundaries cannot adapt to the real-time spread of attack risks, making it difficult to support efficient coordination of defense strategies. When the risk source dynamically changes in a road scenario, the fixed coverage area of the geofence is easily misaligned with the constantly changing risk area, resulting in defense commands failing to accurately match the real threat target. Furthermore, the strategy triggering mechanism based on geofencing is also lagging. Its defense rules need to be manually pre-configured and then linked to a specific fence ID. When facing rapidly changing attack characteristics, the time required from risk identification to manual parameter tuning and strategy issuance is long, exposing vehicles to the threat window. Therefore, the inaccurate fixed defense range and delayed response time of traditional static geofencing methods cannot cope with the spatiotemporal dynamic defense needs in highly variable attack scenarios. As an important means in the defense system, it fails to fully utilize its spatial advantages and has become a serious bottleneck restricting the overall defense effectiveness.
[0005] Existing scheduling methods often focus only on single-dimensional features such as node performance or data itself, neglecting the impact of key characteristics like energy consumption and computational complexity of corresponding encryption algorithms on scheduling decisions in massive data scenarios. This results in a one-sided feature collection dimension, failing to provide complete data support for scheduling analysis, easily leading to scheduling biases, and affecting task processing efficiency and security. Traditional scheduling strategies often rely on fixed rules or simple algorithms to allocate nodes, lacking the ability to deeply mine the inherent correlations between multi-dimensional features. This makes it difficult to accurately match data processing needs with node performance capacity, resulting in uneven utilization of distributed node resources, with some nodes running overloaded while others are idle, leading to low overall scheduling efficiency.
[0006] Traditional solutions lack effective dynamic iteration mechanisms. Once the scheduling strategy is determined, it is difficult to adaptively adjust it based on actual operational results (such as task processing delays and node reliability fluctuations). When faced with dynamic changes in data volume, algorithm type, and node status, the adaptability and flexibility are insufficient, failing to continuously guarantee the scientific rigor and reliability of scheduling decisions. During data flow across various scheduling stages, issues such as inconsistent formats, transmission delays, and insufficient security control exist. Overcoming data silos, ensuring real-time and secure data transmission, and adapting to subsequent modeling requirements have become key technical bottlenecks restricting the efficient integration of the entire scheduling process. Summary of the Invention
[0007] This invention provides a method and system for attack and defense drills of geographic information security in the Internet of Vehicles based on spatiotemporal fences, in order to solve the problems in the existing technology such as fixed attack and defense scenarios, static and inflexible geofences, unreasonable allocation of encrypted resources, and the inability of security protection strategies to dynamically adapt to spatiotemporal risks.
[0008] The technical solution adopted by this invention to solve its technical problem is as follows: On the one hand, a method for security attack and defense drills of vehicle-to-everything (V2X) geographic information based on spatiotemporal fences is provided, including the following steps: Step S1: Construct a hybrid simulation environment containing real hardware devices and virtualization simulation components. The hybrid simulation environment deploys a distributed system and a dynamic spatiotemporal fence rule base; Step S2: Acquire multiple spatiotemporal fence data in the hybrid simulation environment, and mark the security level of each spatiotemporal fence data according to a preset importance level. The spatiotemporal fence data has time and space dimension labels; Step S3: Encrypt the spatiotemporal fence data using a preset encryption algorithm to obtain encrypted spatiotemporal fence data and corresponding encryption algorithm features; Step S4: Extract the data features of each encrypted spatiotemporal fence data and extract the algorithm features of the corresponding encryption algorithm. At the same time, collect the real-time performance features of each computing node in the distributed system, and combine the data features and the algorithm features of the encrypted spatiotemporal fence data with the algorithm features of the corresponding encryption algorithm. The algorithm features and the real-time performance features are concatenated to form a joint feature vector. The real-time performance features include at least CPU utilization, memory usage, and the current task queue length. Step S5: The joint feature vector is input into a pre-trained energy consumption prediction and scheduling model. The model outputs the allocation probability of each spatiotemporal fence data point to each node in the distributed system. Step S6: The allocation probability is constrained based on the security level of the spatiotemporal fence data: if the security level is core level or important level (higher than the warning level), it is forcibly allocated to a high-performance node with a performance score higher than 0.8; if it is the warning level, it is allocated according to the maximum probability. If there is no high-performance node, the node with the highest performance score is selected and an alarm is triggered. Step S7: The allocation is performed and the binding relationship between the spatiotemporal fence data and the distributed nodes is generated. An analysis report is output for resource allocation and security protection strategy updates in the real environment.
[0009] On the other hand, a vehicle-to-everything (V2X) geographic information security attack and defense exercise device based on spatiotemporal fences is provided, including a simulation environment construction module, a data acquisition and labeling module, an encryption processing module, a feature extraction and splicing module, an energy consumption prediction and scheduling model module, a constraint decision and allocation module, and a report output and feedback module, which are used to implement the above methods.
[0010] On another front, a vehicle-to-everything (V2X) geographic information security attack and defense exercise system based on spatiotemporal fences is provided, including: The vehicle-road cooperative hybrid simulation environment integrates real physical hardware devices and a virtual simulation component pool; The layered security protection system includes a data layer protection unit, a protocol adaptation layer unit, and a dynamic defense layer unit. The data layer protection unit encrypts the high-precision spatial coordinate data units involved in the Basic Security Message (BSM) of intelligent connected vehicles. The protocol adaptation layer unit is deployed on roadside edge computing nodes to handle the underlying protocol differences between C-V2X cellular vehicle-to-everything (CV2X) communication and DSRC dedicated short-range communication. The dynamic defense layer unit is implemented through a unified security communication and attack perception center deployed on the V2X communication interface, and determines subsequent actions based on the spatiotemporal fence dynamic attack and defense engine and the attack perception engine. The output of the data layer protection unit is connected to the protocol adaptation layer unit, which is communicatively connected to the dynamic defense layer unit. The security communication and attack perception center in the dynamic defense layer unit interacts with both the data layer protection unit and the protocol adaptation layer unit. The closed-loop attack and defense verification mechanism operates in a hybrid simulation environment with the aforementioned secure communication and attack perception center deployed. It includes an attack simulation module, a defense response module, and an effect quantification evaluation module: The attack simulation module generates targeted attack test cases and pushes them to the attack perception center; the defense response module generates corresponding defense command sequences based on the currently activated security protection strategy, drives the loading of the spatiotemporal fence dynamic trigger strategy, and transmits the defense commands to the target vehicle's OBU to drive the vehicle to perform defensive operations; the effect quantification evaluation module generates evaluation reports to assist in improving the security protection strategy in real-world scenarios.
[0011] The system consists of a four-layer architecture: a physical device layer, a virtualization control layer, an attack and defense engine layer, and a visualization verification layer. The attack and defense engine layer is used to execute the spatiotemporal fence-based vehicle network geographic information security attack and defense exercise method described above, so as to realize the dynamic scheduling and security protection of spatiotemporal fence data.
[0012] One of the above technical solutions has the following advantages or beneficial effects: 1. Substantial Enhancement of Geographic Information Security Protection Capabilities: This invention performs FPE (Format Preservation Encryption) on high-precision geographic information coordinate units in BSM messages through the hardware security module HSM. This ensures that the encrypted ciphertext has the exact same field length and structure as the original plaintext, seamlessly compatible with existing V2X communication protocol stacks, and eliminating the risk of attackers directly obtaining plaintext coordinate data through PC5 over-the-air eavesdropping. Even if an attacker intrudes into the OBU and establishes a backdoor connection, the intercepted coordinate data will all be ciphertext encrypted with the SM4 algorithm, making it impossible to reconstruct the true geographical location. In contrast, the same attack using a traditional unencrypted scheme could completely expose the vehicle's trajectory. Simultaneously, the signature verification mechanism based on digital certificates effectively blocks the replay and tampering of BSM messages. Timestamp verification can identify and discard messages exceeding the time limit, avoiding misleading traffic decisions due to malicious messages, and ensuring the confidentiality and integrity of geographic information data from the source.
[0013] 2. Innovative Integration of Offensive and Defensive Strategies Driven by Spatiotemporal Fences: The spatiotemporal fence proposed in this invention breaks through the static and fixed boundaries of traditional geofences. Based on spatially defined seed areas, it couples with multiple factors such as key attributes, time dimensions, and external traffic flow to form a dynamic defense boundary. The spatiotemporal fence directly transforms the dynamic boundary jointly defined by spatial range, time window, and behavioral rules into the basis for security strategy execution, achieving real-time and accurate matching between defensive actions and traffic risk situations. This spatiotemporal fence can automatically scale its range or change its shape and structure according to external drivers (such as attack source location, traffic density, and time period changes), avoiding the coverage blind spots of fixed geofences and achieving adaptive matching between the defense range and risk diffusion paths. At the same time, through the dynamic association mechanism between strategy templates and spatiotemporal fence attributes, the manual configuration step is eliminated, realizing automated triggering from risk perception to command execution, improving the strategy response speed from minutes to seconds, and significantly enhancing the emergency response capability to sudden attacks.
[0014] 3. Dynamic Security Protection Adjustment Combining Artificial Intelligence and Big Data: This invention uses tagging to perform fine-grained control of data within a spatiotemporal fence, creatively combining spatiotemporal fence data with artificial intelligence and big data processing methods. In a simulation environment, the encryption energy consumption and computational complexity of the data to be processed within the spatiotemporal fence are accurately assessed. Based on the assessment results, the security protection background in the real environment is dynamically predicted, and the security protection strategy is dynamically adjusted accordingly. Compared to traditional fixed rules or single-dimensional scheduling, this invention can more effectively differentiate the processing of different types of spatiotemporal data within massive datasets: high-performance nodes are prioritized and encryption is strengthened for core-level data, while lightweight processing is used for early warning-level data. This improves both the efficiency and accuracy of security protection operations (high-security-level data is forcibly allocated for protection). Simultaneously, during simulation system exercises, the security protection system in the real environment is dynamically adjusted in a closed-loop manner based on continuously updated log data, reducing manual intervention and ensuring that the protection strategy remains synchronized with the real-time threat situation.
[0015] 4. Pre-deployment of resources based on prediction to avoid uneven distribution: This invention utilizes Bi The LSTM model predicts the energy consumption and node matching probability of encrypted spatiotemporal fence data with high importance and large data volume, and deploys more computing resources in advance for processing. This effectively avoids uneven distribution of computing resources caused by dynamic changes in data in the real environment, and prevents node overload or processing timeout caused by a sudden influx of high-security data, thereby ensuring a timely and comprehensive response to emergencies.
[0016] 5. Significant Optimization of Attack and Defense Verification Efficiency and Expansion Space: The collaborative design of the virtualization component layer and real devices in this invention addresses the current limitation of limited physical testing resources. By loading multi-vendor OBU firmware using QEMU virtualization technology and combining it with the dynamic reconfiguration capabilities of SDN networks, complex scenario switching that traditionally requires weeks of deployment can be completed quickly. The attack and defense scenario generation engine can generate large-scale vehicle behavior models, reproducing attack scenarios requiring multi-vehicle collaboration for verification, such as replay attacks and area denial-of-service attacks, without needing to schedule dozens of real vehicles. Furthermore, the attack signature library's pre-defined rules, such as replay sequence number patterns and malicious broadcast frequency thresholds, support rapid response and iteration to new attack vectors. The visualization feedback interface outputs metrics such as encryption coverage and attack blocking rate, providing quantitative basis for subsequent security strategy expansion, supporting the rapid implementation of exercise results into real vehicle systems, reducing overall testing costs, and increasing the breadth of scenario coverage.
[0017] 6. The synergy of multiple technical approaches yielded unexpected technical effects: This invention is not a simple superposition of "dynamic spatiotemporal fencing + encryption + Bi-LSTM prediction + security-level hard constraints + virtual-real simulation". Dynamic spatiotemporal fencing adjusts labels in real time according to security levels, providing more accurate input features for the Bi-LSTM model. Simultaneously, hard constraint decisions compensate for the allocation risks of purely probabilistic models in extreme scenarios. Furthermore, the algorithmic features (energy consumption, complexity) extracted during the encryption step directly participate in model training, creating a double insurance effect between high-security data and forced allocation. The virtual-real simulation environment provides the model with massive amounts of positive and negative samples (especially the constructed "high complexity + large data volume → low-performance node" negative samples), significantly enhancing the model's generalization ability. These technical features are interdependent and mutually supportive, jointly achieving a comprehensive leap in geographic information security protection, resource allocation efficiency, and attack / defense drill capabilities. This results in breakthrough comprehensive performance far exceeding the sum of individual feature improvements, yielding unexpected technical effects. Attached Figure Description
[0018] Figure 1 This is a flowchart illustrating a method for attacking and defending geographic information in the Internet of Vehicles based on a spatiotemporal fence, according to an exemplary embodiment. Figure 2 This is a schematic diagram of a vehicle-to-everything (V2X) geographic information security attack and defense exercise device based on a spatiotemporal fence, according to an exemplary embodiment. Detailed Implementation
[0019] To more clearly illustrate the technical features of the present invention, the invention will be described in detail below through specific embodiments and in conjunction with the accompanying drawings. The following disclosure provides many different embodiments or examples for implementing different structures of the present invention. To simplify the disclosure of the present invention, the components and arrangements of specific examples are described below. Of course, these are merely examples and are not intended to limit the invention.
[0020] In this invention, a spatiotemporal fence is a digital dynamic boundary constructed to achieve proactive geographic information security defense for intelligent connected vehicles. This boundary is jointly defined by spatial range (geographic coordinates or road segment), time window (start and end time), and security level (core level, important level, early warning level). It can dynamically adjust the shape, size, or security level of the boundary based on factors such as real-time attack and defense situation, vehicle density, and risk source location, and automatically adapt to execute defense commands such as detection, isolation, and policy enhancement for abnormal nodes within the boundary. The spatiotemporal fence data refers to V2X communication messages, location data, and related log information generated within the boundary. The dynamic spatiotemporal fence rule base stores the defense command sequences corresponding to different security levels, used to drive defense actions such as encrypted channel switching and intrusion detection adjustment. As a defense entity that integrates real-world scenarios and digital feedback, the spatiotemporal fence ultimately constitutes a closed-loop mechanism for geographic information security of intelligent connected vehicles that integrates perception, decision-making, and response.
[0021] Example 1 like Figure 1 As shown in the figure, an embodiment of the present invention provides a method for security attack and defense drills of vehicle-to-everything (V2X) geographic information based on spatiotemporal fences, which includes the following steps: Step S1: Construct a hybrid simulation environment that includes real hardware devices and virtualization simulation components.
[0022] The hybrid simulation environment deploys a distributed system and a dynamic spatiotemporal fence rule base. Step S1 specifically includes: dynamically networking real OBU and RSU hardware devices with a virtualized simulation component pool based on a software-defined networking (SDN) controller to achieve hybrid communication of real physical layer signals and virtualized message traffic; the distributed system consists of multiple heterogeneous computing nodes, each configured with a performance score. The initial value of the performance score is obtained by weighting the CPU baseline computing power, memory bandwidth, and historical task response latency, and is dynamically updated based on the node's real-time CPU utilization, memory usage, processing speed, and historical reliability; the dynamic spatiotemporal fence rule base includes at least spatial boundaries, time windows, security levels, and corresponding defense instruction sequences. The defense instruction sequences include encrypted channel switching, intrusion detection frequency adjustment, message broadcast permission restrictions, and network isolation. The virtualized simulation component pool loads OBU firmware images from different vendors through QEMU virtualization technology and simulates large-scale vehicle node behavior and abnormal traffic injection. The SDN controller dynamically adjusts the network topology and communication link priorities according to the attack and defense scenario requirements.
[0023] Step S2: Acquire multiple spatiotemporal fence data in the hybrid simulation environment, and mark the security level of each spatiotemporal fence data according to a preset importance.
[0024] The spatiotemporal fence data has time and spatial dimension labels. Step S2 specifically includes: extracting data within a preset time and spatial range from real-time V2X communication logs or historical logs, forming seed spatiotemporal fence data after clustering, deduplication, and filtering; using a Support Vector Machine (SVM) classifier to classify each seed spatiotemporal fence data into three-dimensional labels, including time labels, spatial labels, and security level labels; the security level is dynamically divided into core level, important level, and warning level according to the importance of the geographical area and time, where the core level corresponds to government agencies and military zones, the important level corresponds to schools and large venue activity areas, and the warning level corresponds to general urban road congestion sections. The SVM classifier adopts a one-to-one OVO multi-classification strategy, constructing binary sub-models for the three dimensions of time, space, and security level, and mapping nonlinear features to a high-dimensional space through the RBF kernel function, finally outputting the three-dimensional label vector of each spatiotemporal fence data through a voting mechanism.
[0025] Specifically, in step S2, when using the SVM classifier to perform three-dimensional label classification on the spatiotemporal fence data, a security level-defense instruction sequence mapping table is pre-established: the core level is mapped to {encrypted channel switching, network isolation}, the important level is mapped to {intrusion detection frequency adjustment, message broadcast permission restriction}, and the early warning level is mapped to {log auditing, basic monitoring}.
[0026] Step S3: Encrypt the spatiotemporal fence data using a preset encryption algorithm to obtain the encrypted spatiotemporal fence data and the corresponding encryption algorithm features.
[0027] The encryption algorithm is the GCM encryption mode of the national cryptographic SM4 algorithm. The algorithm features also include the power consumption per KB of data encryption and the number of algorithm rounds. The computational complexity is obtained by normalizing the product of the number of SM4 algorithm rounds and the number of data blocks.
[0028] Step S4: Extract the data features of each encrypted spatiotemporal fence data and extract the algorithm features of the corresponding encryption algorithm. At the same time, collect the real-time performance features of each computing node in the distributed system. Concatenate the data features, the algorithm features, and the real-time performance features to form a joint feature vector. The real-time performance features include at least CPU utilization, memory usage, and current task queue length. The data features include at least a normalized value for data volume, a data type encoding, and a normalized value for data importance; the data type encoding uses 1 for structured data and 0 for unstructured data. The algorithm features include at least a normalized value for encryption algorithm energy consumption, a normalized value for computational complexity, and an algorithm type encoding. The real-time performance features are obtained by real-time collection and normalization of data from a monitoring agent deployed on distributed nodes. The monitoring agent acquires CPU utilization, memory usage, and the current task queue length at fixed intervals. The data feature vector of a single spatiotemporal fence, the corresponding encryption algorithm feature vector, and the real-time performance feature vector are concatenated end-to-end to form a one-dimensional joint feature vector, which is then processed by Min-Max normalization to eliminate the influence of dimensions.
[0029] Step S5: Input the joint feature vector into the pre-trained energy consumption prediction and scheduling model, which outputs the allocation probability of each spatiotemporal fence data being assigned to each node in the distributed system.
[0030] The pre-trained energy consumption prediction and scheduling model is a deep learning model built on a bidirectional long short-term memory network (Bi-LSTM). Its training steps include: collecting historical spatiotemporal fence data, encrypted algorithm logs, and real-time performance feature sequences of distributed nodes from the real environment, and combining them with positive and negative samples constructed by the simulation system to form a training dataset; the positive samples are samples with "high computational complexity + large data volume" that label high-performance nodes, and the negative samples are samples with "high computational complexity + large data volume" that intentionally label low-performance nodes or nodes that are overloaded but still label them; a sample weighting strategy is adopted, with weight = importance normalized value × 1.2 + data volume normalized value × 0.8, to perform weighted training on the model, and the loss function is sparse cross-entropy loss. The Bi-LSTM model structure includes: an input layer that receives a joint feature vector of shape (None, sequence length, single-step feature dimension). If static input (no time sequence) is used, the sequence length can be set to 1; if time sequence input is used, the sequence length represents the size of the historical time window; a hidden layer is a 64-dimensional bidirectional LSTM layer that outputs 128-dimensional features; followed by a 32-dimensional fully connected layer and a ReLU activation function; and an output layer that is a fully connected layer with the number of nodes, using the Softmax function to output the probability assigned to each node.
[0031] For the time series input of the Bi-LSTM model, this embodiment preferably takes the performance feature sequence of 5 historical sampling periods (100ms each) as input to capture the node load change trend and improve prediction accuracy.
[0032] Step S6: Make a constraint decision on the allocation probability based on the security level of the spatiotemporal fence data: If the security level is core level or important level (higher than the warning level), it will be forcibly allocated to a high-performance node with a performance score higher than 0.8; if it is the warning level, it will be allocated according to the maximum probability; if there is no high-performance node, the node with the highest performance score will be selected and an alarm will be triggered.
[0033] Step S6 specifically includes: when the security level is core level or important level, select high-performance nodes with a performance score ≥ 0.8 from the distributed system. If such nodes exist, allocate the data to the node with the lowest load. If no high-performance nodes are available, select the node with the highest performance score and trigger an alarm, and record the alarm reason in the analysis report. When the security level is warning level, directly select the node with the highest output probability from the model for allocation.
[0034] This invention provides a dynamic adjustment rule: if the real-time vehicle density in the core-level area exceeds 80 vehicles / km / lane, the spatiotemporal fence is extended outward by 200 meters; if the attack perception engine detects a replay attack with a confidence level higher than 0.7, the security level of the corresponding fence is automatically and temporarily upgraded to the core level, and encrypted channel switching and network isolation are performed. These rules are pre-set in the rule base as templates and can be adaptively updated with weights based on the attack blocking rate in the exercise logs.
[0035] Step S7: Execute the allocation and generation of spatiotemporal fence data and the binding relationship between distributed nodes, and output an analysis report for resource allocation and security protection strategy updates in the real environment.
[0036] Step S7 specifically includes: associating and storing the unique identifier of each spatiotemporal fence data with the assigned target node ID to form a data-node mapping table; matching the corresponding defense instruction sequence from the spatiotemporal rule base according to the security level of the spatiotemporal fence data, and encapsulating the instruction sequence and the mapping table together into an analysis report; the analysis report includes at least: the task load distribution of each node, the record of forced allocation of high-security data, the alarm event log, and the execution status of the defense instruction.
[0037] To clarify the matching rules between security levels and defense command sequences, this embodiment provides a specific implementation method: A security level-defense command sequence mapping table is pre-established, where the core level (Level 1) maps to {encrypted channel switching, network isolation}, the important level (Level 2) maps to {intrusion detection frequency adjustment, message broadcast permission restriction}, and the early warning level (Level 3) maps to {log auditing, basic monitoring}. During matching, the system directly queries this mapping table based on the security level of the spatiotemporal fence data to obtain the corresponding defense command sequence and execute it. Alternatively, a rule engine can be used, taking the security level as input and dynamically generating command sequences through predefined rules (such as "if security level == core level then execute encrypted channel switching and network isolation").
[0038] After the analysis report is output, the resource allocation module in the real environment dynamically adjusts the task queue priority of the distributed nodes according to the load distribution in the report, and the security policy update module corrects the security level threshold and defense instruction parameters in the spatiotemporal fence rule base according to the alarm event log and the execution status of the defense instruction, forming a closed-loop optimization from simulation exercise to real deployment.
[0039] This invention integrates real-time performance characteristics of nodes into the model input, enabling scheduling decisions to dynamically adapt to load changes, effectively avoiding uneven resource allocation, and improving overall processing efficiency and security. By combining dynamic spatiotemporal fencing with SM4-FPE encryption, it enhances the protection capabilities of geographic information data. The hybrid virtual-real simulation environment reduces testing costs and improves the flexibility and scalability of attack and defense exercises.
[0040] Example 2 like Figure 2 As shown in the figure, an embodiment of the present invention provides a vehicle-to-everything (V2X) geographic information security attack and defense exercise device based on spatiotemporal fences, comprising: The simulation environment construction module is used to build a hybrid simulation environment that includes real hardware devices and virtualized simulation components. The hybrid simulation environment deploys a distributed system and a dynamic spatiotemporal fence rule base. The data acquisition and labeling module is used to acquire multiple spatiotemporal fence data in the hybrid simulation environment, and to label each spatiotemporal fence data with a security level according to a preset importance. The spatiotemporal fence data has time and space dimension labels. The encryption processing module is used to encrypt the spatiotemporal fence data using a preset encryption algorithm to obtain the encrypted spatiotemporal fence data and the corresponding encryption algorithm features. The feature extraction and splicing module is used to extract the data features of each encrypted spatiotemporal fence data and extract the algorithm features of the corresponding encryption algorithm. At the same time, it collects the real-time performance features of each computing node in the distributed system and splices the data features, the algorithm features and the real-time performance features to form a joint feature vector. The real-time performance features include at least CPU utilization, memory usage and current task queue length. The energy consumption prediction and scheduling model module is used to input the joint feature vector into the pre-trained energy consumption prediction and scheduling model, and the model outputs the allocation probability of each spatiotemporal fence data being allocated to each node in the distributed system. The constraint decision and allocation module is used to make constraint decisions on the allocation probability based on the security level of the spatiotemporal fence data: if the security level is core level or important level (higher than the warning level), it will force the allocation to a high-performance node with a performance score higher than 0.8; if it is the warning level, it will allocate according to the maximum probability; if there is no high-performance node, it will select the node with the highest performance score and trigger an alarm. The report output and feedback module is used to perform allocation and generate the binding relationship between spatiotemporal fence data and distributed nodes, and output analysis reports for resource allocation and security protection strategy updates in real-world environments.
[0041] Example 3 This invention provides a vehicle-to-everything (V2X) geographic information security attack and defense exercise system based on spatiotemporal fences, comprising: A vehicle-road cooperative hybrid simulation environment integrates real physical hardware devices and a virtualized simulation component pool. The real physical hardware devices include at least one on-board unit (OBU) and at least one roadside unit (RSU). The OBU integrates a Global Navigation Satellite System (GNSS) positioning module and a Hardware Security Module (HSM), with the HSM containing an SM4 encryption engine. The real OBU and RSU communicate with each other via a V2X communication interface using the PC5 protocol. The virtualized simulation component pool includes a virtual on-board gateway node, a vehicle infotainment system simulation node, and a software-simulated roadside infrastructure logical function module. The real physical hardware devices and the virtualized simulation component pool are interconnected through a Software Defined Networking (SDN) architecture, with an SDN controller dynamically configuring and managing the network topology. The virtualized simulation component pool uses QEMU virtualization technology to load and run firmware from multiple OBU devices provided by different manufacturers. The vehicle-road cooperative hybrid simulation environment has a spatiotemporal synchronization mechanism to ensure that the high-precision spatial positioning data received by the GNSS positioning module integrated in the real OBU is consistent with the vehicle motion model data generated by the virtualized simulation components in terms of time and spatial location. A layered security protection system, comprising: The data layer protection unit is used to encrypt the high-precision spatial coordinate data units involved in the Basic Safety Message (BSM) of intelligent connected vehicles. The encryption process adopts the domestic commercial cryptographic SM4 block encryption algorithm and runs in the format preservation encryption (FPE) mode to ensure that the encrypted ciphertext is consistent with the format, length and structural characteristics of the original plaintext, so as to seamlessly embed it into the standard V2X communication protocol stack. The protocol adaptation layer unit is deployed on the roadside edge computing node and includes a lightweight protocol conversion middleware. It is used to handle the underlying protocol differences between C-V2X cellular vehicle-to-everything communication and DSRC dedicated short-range communication, and to ensure that the encrypted BSM message is correctly identified, transmitted and parsed in the heterogeneous network environment. The dynamic defense layer unit is implemented through a unified security communication and attack perception center deployed on the V2X communication interface. This center monitors network traffic in real time and, based on the spatiotemporal fence dynamic attack and defense engine and the attack perception engine, determines subsequent actions. The spatiotemporal fence dynamic attack and defense engine includes a dynamic spatiotemporal fence rule base and a spatiotemporal fence dynamic policy trigger. It generates a spatiotemporally flexible dynamic defense boundary based on vehicle trajectories, road network status, threat intelligence, and historical logs. It defines three security levels—core, important, and early warning—based on importance, establishes a dynamically adjustable spatiotemporal fence rule base, and dynamically adapts the spatiotemporal fence range and shape by combining real-time traffic data reported by the entity RSU. The spatiotemporal fence dynamic policy trigger converts spatial location into the basis for security policy execution, perceiving attack risks, driving defense policy execution, and displaying spatiotemporal attack and defense effects within spatiotemporal fences of different security levels. The attack perception engine uniformly detects attack characteristics and compares them with the attack rule base, working in conjunction with the spatiotemporal fence dynamic attack and defense engine to collaboratively provide defense policy feedback. A closed-loop attack and defense verification mechanism, which operates in a hybrid simulation environment where the secure communication and attack awareness center is deployed, includes: The attack simulation module connects to a pre-built database of known security vulnerabilities. It is used to automatically generate targeted attack test cases and push them to the attack awareness center by selecting a specific model and firmware version of OBU or RSU as the target device and performing similarity matching analysis. The defense response module is used to respond to attack events triggered by the attack simulation module, calculate and evaluate the potential impact range of the attack in real time, generate corresponding defense instruction sequences based on the currently activated security protection strategy, drive the loading of the spatiotemporal fence dynamic triggering strategy, and transmit the defense instructions to the target vehicle OBU through a low-latency dedicated communication thread or an optimized message queue to drive the vehicle to perform defensive operations. The effectiveness quantification and evaluation module is integrated into the visualization verification platform. It is used to synchronously compare and display the attack propagation range and the dynamic response driving trajectory of affected vehicles before and after the security protection measures are enabled. Based on the system operation log data, it calculates and outputs encryption coverage, attack blocking rate and protocol compatibility indicators, and generates evaluation reports to assist in the improvement of security protection strategies in real scenarios. Furthermore, the system comprises a four-layer architecture: a physical device layer, a virtualization control layer, an attack and defense engine layer, and a visualization verification layer. The attack and defense engine layer, in collaboration with the layered security protection system, achieves a dynamic defense closed loop. Specifically, it includes: a secure communication and attack perception center, a spatiotemporal fence dynamic attack and defense engine, an attack and defense scenario generation engine, a V2X message encryption / decryption bus, and a cryptographic service engine. The physical device layer deploys OBU and RSU physical devices. The OBU acquires high-precision geographic spatial coordinates through an integrated GNSS positioning module and assembles BSM messages. The SM4 encryption engine embedded in the HSM security chip performs FPE format preservation encryption operations to encrypt the BSM messages. The virtualization control layer utilizes SDN to divide dedicated communication channels to ensure the transmission priority and bandwidth isolation of defense commands. It also constructs an isolated sandbox environment using QEMU virtualization technology to simulate attack behavior and test defense strategies. The visualization verification layer provides a three-dimensional intelligent connected vehicle traffic twin scenario, displaying vehicle trajectories, dynamic spatiotemporal fence changes, and attack defense response links. Based on log data, it generates a quantitative report on the defense effectiveness.
[0042] The core technologies of this system are as follows.
[0043] 1. Vehicle-Road Cooperative Hybrid Simulation Environment: This environment integrates real physical hardware devices, a virtualization simulation component pool, and engines for generating attack and defense scenarios. The real hardware devices include one real OBU and one RSU device capable of collecting and transmitting high-precision geographic information spatial coordinates. The real OBU and RSU devices communicate with each other via an actual V2X communication interface using the PC5 protocol.
[0044] The virtualization simulation component pool includes virtual vehicle gateway nodes, vehicle infotainment system simulation nodes, and roadside infrastructure logical function modules based on software simulation. It works in conjunction with the scenario configuration of the attack and defense scenario generation engine and the generation of large-scale traffic flow data to drive the behavior simulation of the virtual nodes.
[0045] The real hardware devices and virtualization simulation components are interconnected through an SDN architecture. The SDN controller is responsible for dynamically configuring and managing the network topology of this hybrid environment.
[0046] The virtualization simulation control component can load and run OBU device firmware from multiple different manufacturers through simulator and virtual machine supervisor (QEMU, QuickEMUlator) virtualization technology, thereby simulating the behavior of real firmware.
[0047] The environment has a spatiotemporal synchronization mechanism to ensure that the high-precision spatial positioning data received by the Global Navigation Satellite System (GNSS) positioning module integrated in the real OBU device is consistent with the vehicle motion model data generated by the virtualization simulation component in terms of time and spatial location.
[0048] 2. Layered security protection system: Data Layer Protection: This layer is responsible for encrypting high-precision spatial coordinate data units in the BSM messages of intelligent connected vehicles. The encryption process uses the domestically developed SM4 block cipher algorithm and operates in Format Preserving Encryption (FPE) mode. This ensures that the encrypted data maintains the same format, length, and structural characteristics as the original plaintext, allowing for seamless integration into existing standardized V2X communication protocol stacks for transmission and avoiding protocol parsing errors or compatibility issues caused by changes in data format.
[0049] Protocol Adaptation Layer: This layer contains lightweight protocol conversion middleware deployed on roadside edge computing nodes. This middleware handles the underlying protocol differences between different communication frameworks, such as C-V2X cellular vehicle-to-everything (V2X) communication and DSRC dedicated short-range communication, ensuring that the encrypted BSM messages can be correctly identified, transmitted, and parsed in heterogeneous network environments, thus guaranteeing interoperability across technology systems.
[0050] Dynamic Defense Layer: This layer is implemented through a unified security communication and attack detection hub deployed on the V2X communication interface. This hub monitors network communication traffic in real time and, based on the spatiotemporal fence dynamic attack and defense engine and the attack detection engine, jointly determines subsequent actions to be taken.
[0051] The spatiotemporal fence dynamic attack and defense engine includes a dynamic spatiotemporal fence rule base and dynamic spatiotemporal fence policy triggers. Based on vehicle trajectories, road network status, threat intelligence, and historical logs, it generates a spatiotemporally flexible dynamic defense boundary. This engine pre-defines fixed locations such as government agencies, schools, and large venues within the scenario, as well as congested road sections, intersections, and frequently or temporarily occurring accident points, as seed spatiotemporal fences. It dynamically associates key attribute information of each seed spatiotemporal fence, such as the nature of government agencies, school start and end times, the date and scale of events held at large venues, and experience values for congestion periods. Based on importance, it defines three security levels: core, important, and warning, establishing a dynamically adjustable spatiotemporal fence rule base for the seed spatiotemporal fences.
[0052] Based on the spatial range of the spatiotemporal fence, a corresponding rule base is coupled, and multi-terminal input reference values such as real-time traffic data reported by physical entities (RSUs) at the device physical layer are combined to achieve dynamic adaptation of the spatiotemporal fence range and shape. For example, the seed area of an important government agency in the scenario can be defined as the core level, with a work schedule attached. During office hours, the seed area expands outward by 200 meters, and during holidays or non-working hours, it shrinks inward appropriately. Another example is the seed area of a school, which can be defined as the important level. When students are at school, the area expands outward by 50 meters, and especially during school hours, the range can be extended to the road area at the school gate, and its level is temporarily upgraded to the core level. However, after school or during winter and summer vacations, the level can be downgraded to the warning level or the seed area can be temporarily removed. Furthermore, the seed area of a large venue can be defined as the warning level. During major events or activities, it can be dynamically upgraded to the important or core level based on the level and scale of the event and surrounding real-time traffic indicators.
[0053] The spatiotemporal fence dynamic policy trigger, acting as the basis for converting spatial location into security policy execution, is responsible for detecting attack risks, driving defense policy execution, and displaying spatiotemporal attack and defense effects within spatiotemporal fences of different security levels. For example, in terms of risk perception, for core-level spatiotemporal fences, it triggers a forced switch to the highest level of defense, such as encrypted channels; for important-level spatiotemporal fences, it increases intrusion detection frequency and sets medium-level defense; and for early warning-level spatiotemporal fences, it marks suspicious terminals and triggers basic defense. In terms of defense-driven execution, it can establish strategies such as isolating communication channels in core areas to block external eavesdropping, forcibly controlling data flow in important areas to discard unknown data packets, and restricting or dynamically downgrading the behavior of terminal nodes in early warning areas. Regarding the display of spatiotemporal attack and defense effects, it can push the dynamic range of the spatiotemporal fence to the scene generation engine and render it in real time in the traffic flow scene of the visualization verification platform, supporting the display of attack heatmaps, etc.
[0054] The attack detection engine of the secure communication and attack perception center is responsible for uniformly detecting attack characteristics and comparing them with the attack rule base. Simultaneously, it coordinates with the spatiotemporal fence dynamic attack and defense engine to provide feedback on defense strategies. In particular, it highlights attack behavior characteristics such as messages with the same sequence number appearing repeatedly in core-level or important-level spatiotemporal fence areas, and message broadcasting frequencies exceeding normal thresholds. Once a spatiotemporal attack characteristic related to the above is detected, predefined defense action commands are automatically triggered immediately. These actions include forcibly switching communication channels within the core-level spatiotemporal fence to block external eavesdropping, marking OBU terminals that frequently enter and exit important-level spatiotemporal fences as high-risk and restricting their message broadcasting permissions, discarding communication data packets that do not conform to the security policies within the warning-level spatiotemporal fence, and implementing network isolation for devices that have not passed authentication or are identified as malicious source addresses. The detection rule base of the center can be dynamically learned and updated based on historical attack pattern data collected during system operation, improving the ability to identify new or variant attacks.
[0055] 3. Closed-loop attack and defense verification mechanism: The mechanism operates in the hybrid simulation environment where a secure communication and attack awareness hub is deployed.
[0056] Attack Simulation and Command Transmission: This module connects to a pre-configured database of known security vulnerabilities. By selecting specific models and firmware versions of OBUs or RSUs as target devices, and performing similarity matching analysis on key characteristics such as firmware version number and communication protocol type, it automatically generates targeted attack test cases and pushes them to the attack awareness center. These attack test cases simulate real-world threat behaviors, such as manipulating signal coverage to interfere with the communication of specific devices, causing them to be unable to send or receive V2X messages, or constructing and sending BSM data packets with forged location coordinate data units, leading to various collision warning anomalies.
[0057] Defense Response and Command Execution: This module responds to attack events triggered by the attack simulation module. Upon detecting an attack event, the module calculates and assesses the potential impact range of the attack in real time, generates a corresponding defense command sequence based on the currently activated security protection strategy, drives the loading of the spatiotemporal fence dynamic triggering strategy, and enhances the encryption strength of specific message types. The generated defense commands are transmitted to the target vehicle's OBU via a low-latency dedicated communication thread or an optimized message queue. After receiving the commands, the OBU directly drives the Controller Area Network (CAN) bus or relevant vehicle control interfaces, commanding the vehicle to perform predefined defensive maneuvers such as speed limiting and maintaining the current lane line.
[0058] Effectiveness Quantification Evaluation: This module is integrated into a visual verification platform, synchronously comparing and displaying the propagation range of simulated attack activities and the dynamic response trajectories of affected vehicles before and after enabling security protection measures (corresponding to plaintext message transmission) and after (corresponding to encrypted transmission and protection activation). Simultaneously, this module calculates and outputs relevant core performance indicators based on system operation log data, such as the encryption coverage rate of successfully applying the specified format to preserve encryption in transmitted BSM messages, the attack blocking rate of the sensing center successfully blocking attack attempts, and protocol compatibility indicators of underlying protocol parsing failures due to data format embedding issues during encrypted transmission. Evaluation reports can also be exported to assist in improving security protection strategies in real-world scenarios.
[0059] 4. System Architecture: The vehicle-to-everything (V2X) geographic information security attack and defense exercise system based on spatiotemporal fences consists of a four-layer architecture: physical device layer, virtualization control layer, attack and defense engine layer, and visualization verification layer.
[0060] The physical equipment layer deploys OBU and RSU physical devices. The OBU uses an integrated GNSS positioning module to acquire high-precision geographic information spatial coordinates and other relevant data (including vehicle information) to form a BSM message. The SM4 encryption engine embedded in the HSM security chip performs FPE format encryption on the high-precision geographic information spatial positioning data units (longitude, latitude, and elevation) in the BSM message, ensuring that the encrypted data maintains the original field length and structure defined by the V2X protocol. The BSM message is then digitally signed before being sent to the RSU. The RSU receives the encrypted message and uploads it to the sensing center based on real-time traffic density data monitored by the roadside sensing devices, providing information input to support dynamic adjustments to defense strategies.
[0061] The virtualization control layer utilizes SDN to allocate dedicated communication channels, ensuring the priority and bandwidth isolation of defense command transmissions and preventing command delays caused by network congestion. Simultaneously, an isolated sandbox environment is constructed using QEMU virtualization technology. This environment simulates attack behaviors such as replay attacks and tests defense strategies, preventing interference with real vehicle systems or leakage of high-precision geographic information data.
[0062] The attack and defense engine layer, as the core decision-making hub of this system, achieves a dynamic defense closed loop through the coordinated operation of five functional modules. The secure communication and attack perception hub monitors V2X message bus traffic from OBU and RSU in real time, identifies abnormal behavior patterns based on the attack perception engine and a pre-built rule base, and triggers a key update mechanism in conjunction with the cryptographic service engine to ensure the encryption system dynamically responds to threats. The spatiotemporal fence dynamic attack and defense engine receives spatiotemporal attack behaviors driven by the perception hub's defense linkage engine, passes them to the dynamic policy trigger for response judgment, and generates a dynamic spatiotemporal fence range and defense strategy that changes with the location of the risk source, pushing it back to the perception hub. Upon receiving this, the perception hub passes it to the scene generation engine to render the effects, and to the physical RSU and OBU devices to execute the corresponding strategies. The attack and defense scene generation engine constructs a digital twin traffic network scene based on the feature parameters input from the perception hub, simulating the response of vehicles to defense strategies in complex traffic flows, providing a high-fidelity data foundation for strategy pre-verification. The V2X message encryption / decryption bus, as a standardized access interface, provides a unified encryption / decryption service call channel for the physical device layer, and provides a standardized service interface for physical OBU and RSU devices to efficiently perform operations such as message signing, signature verification, and ciphertext parsing. The cryptographic service engine provides hardware acceleration support for domestically produced commercial cryptographic algorithms for the entire system, manages the key lifecycle, and ensures the efficiency and reliability of encryption signatures.
[0063] The visualization verification layer provides a 3D traffic twin scenario for intelligent connected vehicles, showcasing vehicle trajectories, dynamic spatiotemporal fence changes, and attack / defense response chains. It also generates a quantitative report on defense effectiveness based on log data. This platform creates a closed loop for testing, optimizing, and verifying defense strategies, eliminating the need for real-vehicle road testing.
[0064] Example 4 The embodiments of the present invention provide several key technologies for implementing the present invention.
[0065] (I) Construction of Hybrid Simulation Environment: Based on SDN (Software-Defined Networking) and lightweight virtualization technology, real OBU (On-Board Unit), RSU (Roadside Unit) and virtual on-board gateway, infotainment system and other devices are dynamically networked to simulate the full-link interaction between vehicle, cloud and roadside devices.
[0066] 1. Network topology management: The network topology is managed uniformly through the SDN controller, which supports dynamic loading of OBU firmware and communication protocols (such as C-V2X) from different manufacturers, and enables compatibility testing of multi-brand devices.
[0067] 2. Division of labor in data interaction: Real hardware: responsible for high-precision spatial positioning data collection and physical layer signal transmission; Virtualization simulation component: Simulates large-scale vehicle node behavior and abnormal traffic injection, reducing the complexity of physical test deployment.
[0068] 3. Basic Data and Rule Construction: A spatiotemporal fence and a spatiotemporal rule library are built according to preset rules; the spatiotemporal fence is a preset time range and location area; the spatiotemporal rule library stores the corresponding defense instruction sequence, which drives the loading of the spatiotemporal fence dynamic trigger strategy.
[0069] The V2X data within the spatiotemporal fence is acquired. V2X includes four types: V2V (vehicle-to-vehicle communication), V2I (vehicle-to-infrastructure communication), V2P (vehicle-to-person communication), and V2N (vehicle-to-cloud communication). It can realize vehicle operation information, as well as vehicle-road-person interconnection and multi-dimensional perception.
[0070] Spatiotemporal fence data is constructed in the simulation system. Based on the importance, three security levels are defined: core, important, and early warning (level 1, level 2, and level 3, respectively). Individual spatiotemporal fence data are marked and used as construction data for later use.
[0071] A distributed system corresponding to the real environment is built in the simulation system. The distributed system consists of multiple nodes, and different nodes have different processing performance.
[0072] (II) Simulation and prediction of security protection mechanisms in the simulation system: Step 1: Initial Construction of Seed Spatiotemporal Fence Data: 1. Extract real-time V2X log information, and combine it with real-time traffic data reported by physical layer devices such as RSU based on the preset time and space range to achieve dynamic adaptation of the spatiotemporal fence range and shape. Based on this, cluster and similarity calculation are performed on the data in the log to filter out duplicate and noisy data. 2. Obtain and construct seed spatiotemporal fence data from historical logs within a preset range, and simultaneously obtain the security level of each spatiotemporal fence.
[0073] Step 2: Spatiotemporal fence data classification based on SVM classifier: The seed spatiotemporal fence data is input into an SVM classifier, which outputs spatiotemporal fence cluster data with multi-dimensional labels. Each cluster data consists of vector data.
[0074] 1. Classification and labeling system: The vector data contains three dimensional labels: time, space, and security level. The security level is defined according to the importance of the data into three levels: core, important, and warning (level 1, level 2, and level 3, respectively), as shown in Table 1.
[0075] Table 1. Three-dimensional labels of the classification label system
[0076] 2. SVM classifier execution steps: 2.1 Feature Quantization and Standardization: Non-numerical features such as time and space are assigned values according to the corresponding scores in Table 1, and then the influence of dimensions is eliminated by Min-Max standardization, and integrated into a standardized feature vector; 2.2 Constructing a basic binary classification SVM model: For any two label categories, solve for the optimal separating hyperplane to achieve linear partitioning of the two classes of samples; 2.3 Introducing kernel functions to handle nonlinear features: The nonlinear spatiotemporal features of V2X are mapped to a high-dimensional space through kernel functions, achieving linear separability; 2.4 OVO Multi-Classification Strategy: For each label dimension (number of categories k), construct k(k) 1) Two binary SVMs are used to determine the final label through a voting method; 2.5 Output classification results: Complete the dimensional classification and output the three-dimensional label set vector [ytime, yspace, ysafe].
[0077] Step 3: Encryption operation of the algorithm: Commercial cryptographic encryption is applied to the classified spatiotemporal fence data from step two. Encryption is performed on each individual data point within a single spatiotemporal fence dataset, using the SM4 GCM encryption mode to achieve confidentiality and tamper-proof protection for the data.
[0078] Step 4: Distributed Node Matching Feature extraction and feature concatenation are performed on the encrypted single spatiotemporal fence data obtained in step three, as well as the encryption algorithm. The feature extraction and splicing methods are as follows: (1) Data feature extraction: For each piece of data to be processed in a single spatiotemporal fence, the core features are extracted and quantified into normalized values. The features include: data volume (normalized to the 0-1 range to represent the amount of computation), data type (structured / unstructured, encoded as 0 / 1), and data importance (normalized to the 0-1 range according to the label level 1-3, and optionally weighted to within 1.0 to strengthen the feature weight); then the features of each piece of data to be processed are spliced together to obtain the feature data of a single spatiotemporal fence.
[0079] (2) Encryption algorithm feature extraction: For the encryption algorithm corresponding to the data, extract the core features and normalize them. The features include: algorithm energy consumption (W / h, normalized to 0-1), computational complexity (quantized into numerical values and normalized), and algorithm type (SM4 algorithm, encoded as 0-N and normalized). (3) Feature concatenation and format conversion: The data feature vector, the encryption algorithm feature vector, and the real-time performance feature vectors of each node (CPU utilization, memory usage, task queue length, etc.) are concatenated end to end to form a one-dimensional joint feature vector. If a Bi-LSTM model is used and time-series information is required, the sequence length represents the number of samples within the time window and is independent of the number of nodes.
[0080] The concatenated sequence feature vector is input into the energy consumption prediction and scheduling model, which outputs the probability of a single spatiotemporal fence data being allocated to each distributed node.
[0081] Step 5: Repeat the method in Step 4 to obtain the probability of all spatiotemporal fence data being assigned to each distributed node, based on the probability of all spatiotemporal fence data being assigned to which nodes.
[0082] Step Six: Constraint Decision Generation and Binding Relationships: Basic rules: Sort nodes by probability from high to low, and assign each spatiotemporal fence data to the node with the highest probability output by the model for processing; and select the corresponding defense instruction sequence from the spatiotemporal rule base according to the security level of the spatiotemporal fence; if the data security level of the spatiotemporal fence data corresponding to the splicing vector is ≥2 (i.e., data security level is 1 and 2), a high-performance node with a performance score ≥0.8 is forcibly selected; if no high-performance node is available, the optimal node is selected and an alarm is triggered. The performance scoring of distributed nodes can adopt a feature-weighted form commonly used in existing technologies, for example: Performance Score = α·Norm (CPU baseline computing power) + β·Norm (memory bandwidth) + γ·Norm (1 / historical response latency), where α + β + γ = 1, with initial values of α = 0.5, β = 0.3, and γ = 0.2, and the weights are dynamically adjusted according to the real-time load of the nodes. The above is a common method in existing technologies and will not be elaborated further.
[0083] Step 7: Generate binding relationships from the constraint decisions obtained from the real-time collected V2X data and output them as an analysis report as a simulation system output, so as to serve as reference data for resource allocation in the real environment.
[0084] (III) Training of the Encryption Energy Consumption Model: The training steps for the encrypted energy consumption model are as follows: 1. Training data construction: The training data is constructed as follows: First, clarify the specific dimensions of the input features to ensure that the feature dimensions of the real data and the constructed data are consistent; the training data consists of real data and constructed data.
[0085] (1) Real data processing: Based on the method in step four, extract spatiotemporal fence data and encryption algorithm data from the real environment, then obtain distributed node data from the real environment, and then extract features from the spatiotemporal fence data, encryption algorithm data and distributed node data, and clean outliers (such as node performance of 0, algorithm energy consumption of negative, etc.) based on the above features. Label the optimal node according to preset rules: For example: Calculate the score of "encryption algorithm complexity × data volume", and label the top 20% of data as "high-performance nodes (such as node A)", medium-scoring nodes as "medium-performance nodes (such as node B)" and low-scoring nodes as "low-performance nodes (such as node C)". Real samples with poor performance (such as high-performance data being assigned to low-performance nodes, causing timeouts) are directly labeled as "non-optimal nodes" corresponding to negative samples.
[0086] (2) Constructing data: Samples are constructed for scenarios with insufficient real-world data coverage (such as extreme encryption algorithm complexity, node full load / no load): Based on the feature distribution of real data, randomly generate feature values that conform to business logic (such as algorithm complexity within 1.2 times the real maximum value and node performance in the range of 0-1). Labeling must be done strictly according to the preset rules: Positive samples: High energy consumption of encryption algorithms + large data volume → label high-performance nodes; Low energy consumption and small data volume in encryption algorithms → mark low-performance nodes; Negative samples: High energy consumption of encryption algorithms → Intentionally marking low-performance nodes; The node is already fully loaded → the node is still marked (simulating incorrect allocation); Recommended ratio of real data to constructed data: 7:3 or 8:2 (prioritizing real data). The constructed data is loaded into the simulation system as a supplement to the real data, and the two are used together as training data to train the model.
[0087] (3) Training set / test set / validation set partitioning: Merge real data and constructed data, and divide them by stratified sampling (ensuring that the labels of each node and the proportion of positive and negative samples are consistent in each set). The split ratio is: 70% for training set, 15% for validation set, and 15% for test set. Data format: The input is a concatenated vector of "data features + encryption algorithm features + node features" (dimensionality example: assuming data features are 5-dimensional + algorithm features are 4-dimensional + node features are 3-dimensional = 12-dimensional), and the output is "node category labels" (e.g., node A=0, node B=1, node C=2).
[0088] 2. Model Building: (1) Construct a scheduling model with Bi-LSTM (Bi-Long Short-Term Memory) network as its core. The model structure includes: (a) Input layer: Receives raw training data, with an input shape of (None, sequence length, single-step feature dimension), where None represents the number of samples; the features include feature data extracted from historical data of distributed nodes, spatiotemporal fence data features, and algorithm features; (b) Bidirectional LSTM layer: The hidden layer dimension is set to 64, and the output dimension is 128 (2×64), which is used to capture the relationship between data, algorithms, and node features; (c) Fully connected layer: The first fully connected layer has a dimension of 32, and uses the ReLU activation function to reduce the dimension and extract the core features; the second fully connected layer has a dimension of the number of nodes, and uses the Softmax activation function to output the allocation probability of each node (the sum of the probabilities is 1). (d) Model compilation: The Adam optimizer (learning rate 0.001) is used, the loss function is sparse cross-entropy loss (adapted to discrete node ID labels), and the evaluation metric is accuracy.
[0089] (2) Weighted training of the model: (a) Sample weight generation: Each training sample is assigned a weight based on the importance of the data and the amount of computation. The weight calculation formula is: weight = importance normalized value × 1.2 + data volume normalized value × 0.8, and the minimum weight is 1.0 to ensure that samples with high importance / high computational cost receive higher training weights. (b) Model training: Input the preprocessed training set features, optimal node labels, and sample weights into the model, set the batch size to 32 and the number of training rounds to 50, and add an early stop callback to allow the model to learn the allocation rules of high-priority samples first. (c) Model evaluation and storage: Evaluate the model using the test set, focusing on verifying the allocation accuracy of high-importance / high-computation samples (target ≥95%), and store the trained model and normalizer for online inference.
[0090] 3. Iterative updates of the model: After deployment in a real environment, collect the actual performance of the allocation results (such as task processing latency and node load). If the allocation result of a certain data causes node overload / processing timeout, mark it as an "error sample" and add it to the training set; Regularly (e.g., weekly), use "old training set + new error samples + newly constructed data" to reacquire distributed system performance metrics, spatiotemporal fence data, and encryption algorithm data, and train the model accordingly to update the online model; Continuously monitor the model's accuracy; if it drops by more than 5%, immediately trigger the iteration process.
[0091] (iv) SVM classifier: The specific content of the SVM classifier in step two above is as follows: Step 1: Feature Quantization and Standardization Non-numerical features such as time, space, and vehicle type are converted into standardized numerical values to eliminate the influence of dimensions and ensure SVM convergence. Features such as time, space, vehicle type, communication type, and traffic density are integrated into a standardized feature vector.
[0092] Step 2: Construct the basic binary classification SVM model: For any two label categories, find the optimal separating hyperplane to achieve a linear partition between the two classes of samples.
[0093] Step 3: Introduce kernel functions to handle nonlinear characteristics: For the nonlinear distribution of V2X spatiotemporal data, a kernel function is used to map features to a high-dimensional space to achieve linear separability.
[0094] Step 4: OVO multi-classification strategy (adapting to three tags).
[0095] Step 5: Output the classification results and quantify the importance.
[0096] Label output: After completing the classification in 3 dimensions, output a vector of three labels.
[0097] (v) Real-time resource indicators for each node: Step four describes the "real-time resource metrics parameters for each node" in the distributed system, which includes, but is not limited to, the following metrics: 1. Computational / Actional workload category: Floating-point operations (FLOPS / Total FLOP): Floating-point operations per second / Total number of operations per encryption cycle; Total CPU instructions executed: The total number of arithmetic / logical instructions executed by the CPU during the encryption process; Algorithm rounds × number of data blocks: For example, SM4 has 32 rounds of transformation × number of data blocks to be encrypted (theoretical computational load).
[0098] 2. Hardware resource usage category: CPU utilization (%) / number of cores used; Memory usage (MB / GB) / Memory read / write speed (MB / s); GPU memory usage (GB) / GPU computing power utilization (%) (GPU encryption scenario).
[0099] 3. Energy-consuming scenarios (embedded / low-power scenarios): Total power consumption for encryption (W); Energy consumption per KB of data encryption (Wh / KB).
[0100] Example 5 The embodiments of the present invention provide two specific calculation examples.
[0101] Example 1: Conventional V2X data attack and defense exercise on urban roads: I. Drill Scenario: For roads surrounding urban residential areas (spatial-temporal fence: 116.26°-116.27°E, 39.90°-39.91°N, time window: weekday evening rush hour 18:00-19:00), routine V2X data attack and defense drills were conducted to verify the classification, encryption, and distributed node allocation effects of Level 3 early warning data such as vehicle-to-vehicle distance and roadside traffic light signals, adapting to the geographic information security attack and defense verification needs of ordinary urban roads.
[0102] II. Drill Procedure: Simulation environment setup: Using SDN technology, two real OBUs and one RSU are dynamically networked to virtualize and simulate 30 virtual vehicle nodes, realizing full-link interaction between vehicles and roads; a distributed system with three performance-level nodes is built (Node A: high performance, performance score 0.83; Node B: medium performance, performance score 0.62; Node C: low performance, performance score 0.41), with preset spatiotemporal fences and rule bases, and three levels of data triggering conventional audit defense commands.
[0103] Data preprocessing and classification: 500 V2X log data from this scenario were extracted, clustered, deduplicated, filtered and denoised as seed data, and labeled as security level 3. The seed data were input into an SVM classifier, and after feature quantization, standardization and nonlinear mapping, a three-dimensional label vector of time-space-security level was output, with a classification accuracy of 95%.
[0104] Encryption and Node Allocation: The SM4 GCM encryption mode is used to encrypt the classified data at the single-item level. Data features, encryption algorithm features, and real-time resource features of nodes are extracted and concatenated into a sequence feature vector, which is input into the trained Bi-LSTM energy consumption prediction and scheduling model. The model outputs the node allocation probabilities (A: 0.18, B: 0.32, C: 0.50). Since the data is at level 3 security, there is no mandatory allocation requirement for high-performance nodes. The data is allocated to node C according to the probability.
[0105] Output results: Node C completed all data processing without overload or processing timeout. The simulation system generated an analysis report containing node allocation results and defense command execution status, verifying the rationality of scheduling and protection of conventional Level 3 data in urban road scenarios.
[0106] Example 2: High-security data attack and defense exercise on a closed road in the test area: I. Drill Scenario: For the core area of the intelligent connected vehicle test zone (spatial fence: 116.48°-116.50° E, 39.78°-39.80° N, time window: all day), a high-security data attack and defense exercise was conducted to verify the encryption protection, forced node allocation, and anomaly alarm mechanism for Level 2 important data such as confidential vehicle test parameters, adapting to the security attack and defense verification requirements of high-value geographic information in the closed test zone.
[0107] II. Drill Procedure: Simulation environment setup: Deploy 1 real OBU, 1 RSU and virtual cloud platform to build an integrated vehicle-road-cloud simulation network; build a distributed system with 2 nodes (Node A: high performance, performance score 0.81; Node B: medium performance, performance score 0.65), preset spatiotemporal rule base, level 2 data trigger traffic monitoring and defense command, and automatically trigger alarm when no available high performance node.
[0108] Data preprocessing and classification: 300 confidential vehicle test parameter data from the park were extracted, cleaned and used as seed data and marked as level 2 security; after processing by SVM classifier, a three-dimensional label vector was output, with a classification accuracy of 96.3%.
[0109] Encryption and Node Allocation: The GCM encryption mode of SM4 is used to encrypt the Level 2 data at the single-line granularity. The relevant features are extracted and concatenated into a sequence feature vector, which is then input into the Bi-LSTM model. Since the data security level is ≥ Level 2, all data is forcibly allocated to high-performance node A. Extreme scenarios are simulated synchronously. If node A is fully loaded and has no processing capacity, the data is allocated to node B and a system alarm is triggered.
[0110] Output results: Node A efficiently completed all Level 2 data processing, traffic monitoring and defense commands were executed normally, and the alarm mechanism responded promptly in extreme scenarios; the simulation system generated an analysis report, verifying the encryption protection effect of high-security data, the feasibility of the forced allocation rules, and the effectiveness of the abnormal alarm mechanism.
[0111] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.
Claims
1. A method for conducting a geographic information security attack and defense exercise for the Internet of Vehicles based on spatiotemporal fences, characterized in that, Includes the following steps: Step S1: Construct a hybrid simulation environment that includes real hardware devices and virtualization simulation components. The hybrid simulation environment deploys a distributed system and a dynamic spatiotemporal fence rule base. Step S2: Acquire multiple spatiotemporal fence data in the hybrid simulation environment, and mark the security level of each spatiotemporal fence data according to a preset importance. The spatiotemporal fence data has time and space dimension labels. Step S3: Encrypt the spatiotemporal fence data using a preset encryption algorithm to obtain the encrypted spatiotemporal fence data and the corresponding encryption algorithm features; Step S4: Extract the data features of each encrypted spatiotemporal fence data and extract the algorithm features of the corresponding encryption algorithm. At the same time, collect the real-time performance features of each computing node in the distributed system. Concatenate the data features, the algorithm features, and the real-time performance features to form a joint feature vector. The real-time performance features include at least CPU utilization, memory usage, and current task queue length. Step S5: Input the joint feature vector into the pre-trained energy consumption prediction and scheduling model, and the model outputs the allocation probability of each spatiotemporal fence data being allocated to each node in the distributed system; Step S6: Make a constraint decision on the allocation probability based on the security level of the spatiotemporal fence data: if the security level is core level or important level, force allocation to high-performance nodes with a performance score higher than 0.8; if it is warning level, allocate according to the maximum probability; if there are no high-performance nodes, select the node with the highest performance score and trigger an alarm. Step S7: Execute the allocation and generation of spatiotemporal fence data and the binding relationship between distributed nodes, and output an analysis report for resource allocation and security protection strategy updates in the real environment.
2. The method for conducting a vehicle-to-everything (V2X) geographic information security attack and defense exercise based on spatiotemporal fences according to claim 1, characterized in that, Step S1 specifically includes: dynamically networking real OBU and RSU hardware devices with a virtualization simulation component pool based on a software-defined networking (SDN) controller to achieve hybrid communication of real physical layer signals and virtualized message traffic; the distributed system consists of multiple heterogeneous computing nodes, each node is configured with a performance score, the initial value of which is obtained by weighted calculation of CPU baseline computing power, memory bandwidth and historical task response latency, and is dynamically updated based on the node's real-time CPU utilization, memory usage, processing speed and historical reliability; the dynamic spatiotemporal fence rule base includes at least spatial boundaries, time windows, security levels and corresponding defense instruction sequences, the defense instruction sequences include encrypted channel switching, intrusion detection frequency adjustment, message broadcast permission restriction and network isolation.
3. The method for conducting a vehicle-to-everything (V2X) geographic information security attack and defense exercise based on spatiotemporal fences according to claim 1, characterized in that, Step S2 specifically includes: extracting data within a preset time and space range from real-time V2X communication logs or historical logs, forming seed spatiotemporal fence data after clustering deduplication and filtering noise reduction; using a support vector machine (SVM) classifier to perform three-dimensional label classification on each seed spatiotemporal fence data, the three-dimensional label including time label, spatial label and security level label; the security level is dynamically divided into core level, important level and early warning level according to the importance of the geographical area and time.
4. The method for conducting a vehicle-to-everything (V2X) geographic information security attack and defense exercise based on spatiotemporal fences according to claim 1, characterized in that, Step S4 specifically includes: the data features include at least a normalized value of data volume, a normalized value of data type, and a normalized value of data importance; the algorithm features include at least a normalized value of encryption algorithm energy consumption, a normalized value of computational complexity, and an algorithm type code; the real-time performance features are obtained by real-time collection and normalization of data from a monitoring agent deployed on distributed nodes, and the monitoring agent obtains CPU utilization, memory usage, and current task queue length at fixed intervals; the data feature vector of a single spatiotemporal fence, the corresponding encryption algorithm feature vector, and the real-time performance feature vector are concatenated end-to-end to form a one-dimensional joint feature vector, which is then processed by Min-Max normalization.
5. A method for conducting a geographic information security attack and defense exercise for the Internet of Vehicles based on spatiotemporal fences according to claim 1, characterized in that, The pre-trained energy consumption prediction and scheduling model is a deep learning model built on a bidirectional long short-term memory network (Bi-LSTM). Its training steps include: collecting historical spatiotemporal fence data, encrypted algorithm logs, and real-time performance feature sequences of distributed nodes from the real environment, and combining them with positive and negative samples constructed from the simulation system to form a training dataset; the positive samples are samples labeled with high computational complexity and large data volume to indicate high performance nodes, and the negative samples are samples labeled with low performance nodes or nodes that are overloaded but still labeled, to indicate high computational complexity and large data volume; a sample weighting strategy is adopted, with weight = importance normalized value × 1.2 + data volume normalized value × 0.8, to perform weighted training on the model, and the loss function is sparse cross-entropy loss.
6. A method for attack and defense drills of vehicle network geographic information security based on spatiotemporal fences according to claim 1, characterized in that, Step S6 specifically includes: when the security level is core level or important level, selecting high-performance nodes with a performance score ≥ 0.8 from the distributed system; if such nodes exist, allocating data to the node with the lowest load; if no high-performance nodes are available, selecting the node with the highest performance score and triggering an alarm, recording the alarm reason in the analysis report; when the security level is warning level, directly selecting the node with the highest output probability from the model for allocation.
7. A method for conducting a geographic information security attack and defense exercise for the Internet of Vehicles based on spatiotemporal fences according to any one of claims 1-6, characterized in that, Step S7 specifically includes: associating and storing the identifier of each spatiotemporal fence data with the assigned target node ID to form a data-node mapping table; matching the corresponding defense instruction sequence from the spatiotemporal rule base according to the security level of the spatiotemporal fence data, and encapsulating the instruction sequence and the mapping table together into an analysis report; the analysis report includes at least: the task load distribution of each node, the record of forced allocation of high-security-level data, the alarm event log, and the execution status of the defense instruction.
8. A vehicle-to-everything (V2X) geographic information security attack and defense exercise device based on spatiotemporal fences, characterized in that, include: The simulation environment construction module is used to build a hybrid simulation environment that includes real hardware devices and virtualized simulation components. The hybrid simulation environment deploys a distributed system and a dynamic spatiotemporal fence rule base. The data acquisition and labeling module is used to acquire multiple spatiotemporal fence data in the hybrid simulation environment, and to label each spatiotemporal fence data with a security level according to a preset importance. The spatiotemporal fence data has time and space dimension labels. The encryption processing module is used to encrypt the spatiotemporal fence data using a preset encryption algorithm to obtain the encrypted spatiotemporal fence data and the corresponding encryption algorithm features. The feature extraction and splicing module is used to extract the data features of each encrypted spatiotemporal fence data and extract the algorithm features of the corresponding encryption algorithm. At the same time, it collects the real-time performance features of each computing node in the distributed system and splices the data features, the algorithm features and the real-time performance features to form a joint feature vector. The real-time performance features include at least CPU utilization, memory usage and current task queue length. The energy consumption prediction and scheduling model module is used to input the joint feature vector into the pre-trained energy consumption prediction and scheduling model, and the model outputs the allocation probability of each spatiotemporal fence data being allocated to each node in the distributed system. The constraint decision and allocation module is used to make constraint decisions on the allocation probability based on the security level of the spatiotemporal fence data: if the security level is core level or important level, it will force the allocation to a high-performance node with a performance score higher than 0.8; if it is warning level, it will allocate according to the maximum probability; if there is no high-performance node, it will select the node with the highest performance score and trigger an alarm. The report output and feedback module is used to perform allocation and generate the binding relationship between spatiotemporal fence data and distributed nodes, and output analysis reports for resource allocation and security protection strategy updates in real-world environments.
9. A vehicle-to-everything (V2X) geographic information security attack and defense exercise system based on spatiotemporal fences, characterized in that, include: The vehicle-road cooperative hybrid simulation environment integrates real physical hardware devices and a virtual simulation component pool; The layered security protection system includes a data layer protection unit, a protocol adaptation layer unit, and a dynamic defense layer unit. The data layer protection unit encrypts the high-precision spatial coordinate data units involved in the Basic Security Message (BSM) of intelligent connected vehicles. The protocol adaptation layer unit is deployed on roadside edge computing nodes to handle the underlying protocol differences between C-V2X cellular vehicle-to-everything (CV2X) communication and DSRC dedicated short-range communication. The dynamic defense layer unit is implemented through a unified security communication and attack perception center deployed on the V2X communication interface, and determines subsequent actions based on the spatiotemporal fence dynamic attack and defense engine and the attack perception engine. The output of the data layer protection unit is connected to the protocol adaptation layer unit, which is communicatively connected to the dynamic defense layer unit. The security communication and attack perception center in the dynamic defense layer unit interacts with both the data layer protection unit and the protocol adaptation layer unit. The closed-loop attack and defense verification mechanism operates in a hybrid simulation environment with the aforementioned secure communication and attack perception center deployed. It includes an attack simulation module, a defense response module, and an effect quantification evaluation module: The attack simulation module generates targeted attack test cases and pushes them to the attack perception center; the defense response module generates corresponding defense command sequences based on the currently activated security protection strategy, drives the loading of the spatiotemporal fence dynamic trigger strategy, and transmits the defense commands to the target vehicle's OBU to drive the vehicle to perform defensive operations; the effect quantification evaluation module generates evaluation reports to assist in improving the security protection strategy in real-world scenarios.
10. A vehicle-to-everything (V2X) geographic information security attack and defense exercise system based on spatiotemporal fences according to claim 9, characterized in that, The system comprises a four-layer architecture: a physical device layer, a virtualization control layer, an attack and defense engine layer, and a visualization verification layer. The attack and defense engine layer, in collaboration with the layered security protection system, achieves a dynamic defense closed loop. Specifically, it includes: a secure communication and attack perception hub, a spatiotemporal fence dynamic attack and defense engine, an attack and defense scenario generation engine, a V2X message encryption / decryption bus, and a cryptographic service engine. The physical device layer deploys OBU and RSU physical devices. The OBU acquires high-precision geographic spatial coordinates through an integrated GNSS positioning module and assembles BSM messages. The SM4 encryption engine embedded in the HSM security chip performs FPE format preservation encryption operations to encrypt the BSM messages. The virtualization control layer utilizes SDN to divide dedicated communication channels to ensure the transmission priority and bandwidth isolation of defense commands. It also constructs an isolated sandbox environment using QEMU virtualization technology to simulate attack behavior and test defense strategies. The visualization verification layer provides a three-dimensional intelligent connected vehicle traffic twin scenario, displaying vehicle trajectories, dynamic spatiotemporal fence changes, and attack defense response links. Based on log data, it generates a quantitative report on the defense effectiveness.
Citation Information
Patent Citations
Novel information security attack and defense experiment platform and implementation method thereof
CN104778073A
Security fence protection method and device based on Internet of Things technology
CN121330822A