A Secure Cross-Domain Intelligent Vehicle Phasing Authentication Method Based on Cloud-Edge-Device Architecture

CN122575107APending Publication Date: 2026-08-14NORTHEASTERN UNIV CHINA +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-26
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0005]针对现有技术在跨域车辆编队认证中的不足,本发明提供一种基于云-边-端架构的安全跨域智能车辆编队认证方法,旨在解决开放环境下域注册可靠性不足、认证密钥协商延迟较高以及轨迹匹配过程中隐私难以保护以及组队成功率较低的问题,从而在保证车辆编队行驶安全性的同时,提高跨域车辆编队认证的实时性和实用性

Benefits of technology

[0055]The beneficial effects of adopting the above technical solution are as follows: The cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture provided by this invention can achieve reliable registration and public verification of the freight domain in an open freight alliance environment, effectively preventing untrusted domains from mixing into the vehicle platoon from a mechanism level; at the same time, through two types of low-latency authentication processes—intra-domain authentication key negotiation and cross-domain authentication key negotiation—the waiting time for vehicles to join the platoon in high-speed driving scenarios is reduced, improving platooning collaboration efficiency and driving safety; and through a cloud-edge-device collaborative trajectory matching mechanism, local matching is performed at edge nodes to achieve rapid screening, and global matching is performed in the cloud to improve matching accuracy. Thus, platooning access decisions are completed without disclosing commercially sensitive data such as vehicle transportation routes and operational information, achieving comprehensive optimization of security, real-time performance, and privacy protection, and providing technical support for the large-scale deployment of cross-domain vehicle platooning systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122575107A_ABST
    Figure CN122575107A_ABST
Patent Text Reader

Abstract

This invention provides a secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture, relating to the field of information security technology. When an intelligent vehicle applies to join a vehicle platoon in a freight alliance, the freight domain to which the intelligent vehicle belongs initiates a registration request to the freight alliance. Freight domains already joined in the freight alliance jointly negotiate to determine whether to approve the registration request, and the freight domain to which the intelligent vehicle belongs completes registration. When an intelligent vehicle applies to join a vehicle platoon, the intelligent vehicle and the vehicle platoon perform identity authentication and session key negotiation. The trajectories of the intelligent vehicle and the vehicle platoon are matched, and the matching result determines whether to allow the intelligent vehicle to join the vehicle platoon. This invention can effectively prevent untrusted domains from entering the vehicle platoon, reduce the waiting time for vehicles to join the platoon in high-speed driving scenarios, improve platooning collaboration efficiency and driving safety, and achieve optimization of security, real-time performance, and privacy protection, providing technical support for the large-scale deployment of vehicle platooning systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, and in particular relates to a secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture. Background Technology

[0002] Intelligent vehicle platooning technology integrates multiple intelligent vehicles into a longitudinal platoon and achieves cooperative autonomous driving by sharing control parameters in real time. This technology helps freight transport effectively reduce fuel consumption and traffic accidents. Its advantages are further amplified when a freight transport domain allows intelligent vehicles from other freight transport domains to join its platoon. However, if a freight transport domain allows unidentified intelligent vehicles or those with inconsistent driving trajectories to join the platoon at will, malicious freight transport domains might instruct their intelligent vehicles to infiltrate other platoons, deliberately causing traffic accidents or stealing trade secrets such as transport routes. Therefore, it is necessary to design a cross-domain intelligent vehicle platooning authentication mechanism.

[0003] In order to achieve cross-domain intelligent vehicle platooning, intelligent vehicle platooning authentication must simultaneously meet the following three key requirements: (1) a domain registration protocol is required to ensure that only intelligent vehicles belonging to a trusted domain can join the platoon; (2) authentication key negotiation must achieve low latency; and (3) trajectory matching must not reveal the specific driving trajectory of the intelligent vehicles.

[0004] Existing blockchain-based cross-domain decentralized authentication schemes still suffer from the following significant drawbacks in cross-domain vehicle platooning scenarios: Domain registration reliability is poor; centralized registration is susceptible to malicious domain infiltration. Decentralized threshold signature schemes have vulnerabilities to key and commitment information leakage, making it difficult to balance decentralization with high registration reliability. Authentication key negotiation latency is high; vehicle computing power and communication resources are limited, and existing solutions either only support one-way authentication or involve cumbersome and costly two-way authentication operations. As vehicle scale increases, data query synchronization further prolongs authentication latency. Trajectory matching privacy protection is weak; plaintext transmission of trajectories can leak sensitive commercial route data. Using fully homomorphic encryption presents challenges in adapting to multi-public-key operations, and the computational load exceeds the vehicle's computing power capacity, failing to balance trajectory matching and privacy protection. Placing platooning success rates is low; matching relies heavily on local data from single nodes, lacking comprehensive global analysis, leading to misjudgments and missed judgments. As vehicle scale increases, single-node computing power and data coverage become insufficient, making it impossible to balance real-time performance, local matching, and global matching, resulting in low platooning efficiency. Summary of the Invention

[0005] To address the shortcomings of existing technologies in cross-domain vehicle platooning authentication, this invention provides a secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture. This method aims to solve problems such as insufficient reliability of domain registration in open environments, high latency in authentication key negotiation, difficulty in protecting privacy during trajectory matching, and low platooning success rates. Thus, it improves the real-time performance and practicality of cross-domain vehicle platooning authentication while ensuring the safety of vehicle platooning.

[0006] The present invention provides a secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture, comprising the following steps:

[0007] A freight alliance is established based on multiple freight domains. The freight alliance includes one or more vehicle fleets, each vehicle fleet includes one or more intelligent vehicles, and the intelligent vehicles in each vehicle fleet come from one or more freight domains.

[0008] Initialize public parameters; when an intelligent vehicle applies to join any vehicle platoon in the freight alliance, the intelligent vehicle registers with its freight domain based on the public parameters and obtains a set of temporary identity credentials; the freight domain to which the intelligent vehicle belongs initiates a registration request to the freight alliance, and the freight domains that have joined the freight alliance jointly negotiate based on the public parameters to determine whether to approve the registration request. If the registration request is approved, the freight domain to which the intelligent vehicle belongs completes the registration and uploads the intelligent vehicle's trajectory to the cloud; otherwise, the intelligent vehicle cannot join the freight alliance.

[0009] When an intelligent vehicle applies to join a vehicle platoon, the intelligent vehicle uses a set of temporary identity credentials to authenticate its identity and negotiate a session key with the vehicle platoon, thus establishing a secure communication channel between the intelligent vehicle and the vehicle platoon.

[0010] The trajectory of intelligent vehicles and vehicle formations is matched, and the matching result is used to determine whether intelligent vehicles are allowed to join the vehicle formation.

[0011] Furthermore, the common parameters are: , For the first common parameter set, For the second set of common parameters;

[0012] First common parameter set ,in, , , and All are of order. cyclic group , and yes Three uniformly random generators, For generators in the common parameters, yes Uniformly random generator, For large prime numbers, It is a bilinear mapping. , , , , and Both are hash functions. For model The integer addition group, Hash function The length parameter of the output binary string. Hash function The length parameter of the output binary string;

[0013] Second common parameter set ,in, Let the dimension be the error-laden learning problem RLWE on the ring. Represents the ciphertext modulus. The expression is defined on the polynomial ring. Key distribution on The expression is defined on the polynomial ring. Error distribution on Indicates from the model A vector randomly selected from a polynomial ring vector space. This represents the dimension of a vector. Indicates by Each belongs to A vector space composed of the elements of a polynomial ring. , Represents a set of integers. Represents a polynomial variable. Represents a ring of polynomials with integer coefficients. This represents a modular polynomial, therefore a polynomial ring. In the modulo polynomial The quotient ring obtained by the following construction; Represents the polynomial ring The coefficients of each polynomial in the model are arranged according to their modulus. The polynomial ring obtained after taking values.

[0014] Furthermore, the specific method for intelligent vehicles to register with their respective freight domains is as follows:

[0015] For any intelligent vehicle and intelligent vehicles Belongs to Freight Domain A, Intelligent Vehicles Randomly generated A temporary private key factor, calculated based on public parameters. A temporary public key and A temporary identity; based on the first Temporary private key factor The calculated temporary public key is Temporary identity is ,in, , Modulus The multiplication group;

[0016] Freight Domain A is based on intelligent vehicles of A temporary public key and A temporary identity is generated for intelligent vehicles. of Temporary identity binding information and A temporary private key, based on A temporary identity binding information is used to generate intelligent vehicles. A collection of temporary identity binding information; based on the first A temporary public key and temporary identity The generated first The temporary identity binding information is , No. The temporary private key is ,in, Indicates temporary identity The validity period, This is the private key for freight domain A;

[0017] Set up temporary identity binding information for all intelligent vehicles within freight domain A. Temporary identity binding information As leaf nodes, generate the Merkle tree and the existence proof for each leaf node. The existence proofs of the root node and all leaf nodes of the Merkle tree are uploaded to the blockchain.

[0018] Freight Domain A is based on A temporary public key, temporary identity, temporary identity binding information, temporary private key, and proof of existence of the temporary identity binding information are used to generate an intelligent vehicle. Collection of temporary identity credentials ,include A temporary identity credential.

[0019] Furthermore, the specific method for the freight domain to which the intelligent vehicle belongs to initiate a registration request to the freight alliance is as follows:

[0020] For freight domain A applying to join the freight alliance, the identity identifier of freight domain A is used. Master key and share public key Generate registration request And send it to all freight domains in the freight alliance.

[0021] Furthermore, the specific method by which freight domains that have joined the freight alliance jointly negotiate whether to approve a registration request based on common parameters is as follows:

[0022] For each freight domain in the freight alliance, receive the registration request from freight domain A. Randomly select multiple Polynomial computation of commitment values, ciphertext, and zero-knowledge proofs;

[0023] Each freight domain in the freight consortium uploads its commitment value, ciphertext, and zero-knowledge proof to the blockchain for verification. Verified freight domains within the consortium are then designated as member domains, and a member domain index set is generated based on the indexes of all member domains. ;

[0024] Each member domain downloads the ciphertext and threshold public key uploaded by other member domains from the blockchain, decrypts the ciphertext, and calculates its private key share. The private key share for each member domain is , For member field index set Index of member fields, , and All are the first A polynomial with randomly selected member domains;

[0025] If the member domain's registration request to freight domain A is verified, a partial signature and a zero-knowledge proof are calculated based on the member domain's private key share and the freight domain A's registration request, and the member domain's partial signature and zero-knowledge proof are sent to freight domain A.

[0026] Freight domain A verifies the validity of the partial signature and zero-knowledge proof for each member domain when at least When the partial signature and zero-knowledge proof of each member domain are valid, the freight domain that has already joined the freight consortium approves the registration request of freight domain A, which is applying to join the freight consortium. The threshold is used as the threshold value;

[0027] Generate a complete signature for freight domain A based on the threshold signature algorithm. Complete registration.

[0028] Furthermore, the vehicle platoon includes a lead intelligent vehicle;

[0029] When an intelligent vehicle requests to join a vehicle platoon, the intelligent vehicle performs identity authentication and session key negotiation based on a set of temporary identity credentials and the vehicle platoon. The specific method is as follows:

[0030] If the intelligent vehicle and the convoy's leader intelligent vehicle belong to the same freight domain, the intelligent vehicle and the leader intelligent vehicle will negotiate the domain-specific authentication key.

[0031] If the intelligent vehicle and the convoy's leader intelligent vehicle belong to different freight domains, the intelligent vehicle and the leader intelligent vehicle shall negotiate a cross-domain authentication key.

[0032] Furthermore, the specific method for negotiating the intra-domain authentication key is as follows:

[0033] intelligent vehicles Randomly select authentication random number Computational intelligent vehicles Authentication random public key and certification value Based on temporary identity credentials Generating intelligent vehicles intradomain connection requests Send to the team leader's smart vehicle , For the timestamps generated by the intra-domain connection requests;

[0034] Intelligent vehicle for team leader Receiving intelligent vehicles intradomain connection request ,verify Whether it is valid, among which and These represent the current time and the maximum valid time interval, respectively.

[0035] if Not valid, the team leader intelligent vehicle Reject intelligent vehicles Joining the vehicle platoon, among which... The current time;

[0036] if Established, current time In intelligent vehicles The validity period of temporary identity certificates Inside, and satisfy Intelligent vehicle leading the team Randomly select authentication random number Computational intelligent vehicles Authentication random public key , certification value and symmetric encryption key Generate a leader intelligent vehicle response And send to smart vehicles ,in, Indicates the timestamp of the response generated by the leader intelligent vehicle;

[0037] intelligent vehicles Receiving the intelligent vehicle of the team leader response ,verify Is it valid?

[0038] if This is not true; intelligent vehicles Rejecting the leader's intelligent vehicle response ;

[0039] if Established, current time Temporary identity certificate Validity period Within, and meets the verification conditions. Intelligent vehicles Accepting intelligent vehicles for tour leaders response Calculate the symmetric encryption key Establish intelligent vehicles and the team leader intelligent vehicle A secure communication channel.

[0040] Furthermore, the specific method for cross-domain authentication key negotiation is as follows:

[0041] intelligent vehicles Randomly select authentication random number Computational intelligent vehicles Authentication random public key and certification value Generate intelligent vehicles Cross-domain connection request Send to the team leader's smart vehicle , This serves as the identity identifier for freight domain A. Indicates the timestamp of the cross-domain connection request being generated;

[0042] Intelligent lead vehicles belonging to freight domain B Receive cross-domain connection requests ,verify Whether it is true or not, among which, Indicates the maximum valid time interval;

[0043] if Not valid, the team leader intelligent vehicle Reject intelligent vehicles Cross-domain connection requests;

[0044] if Validity and existence proof Verification successful, temporary identity credential. Valid until Within, and meets the verification conditions. Intelligent vehicle leading the team Randomly select authentication random number Computational intelligent vehicle Authentication random public key , certification value and symmetric encryption key Generate a leader intelligent vehicle response Send to smart vehicles ,in, Intelligent vehicles for the team leader The identifier of the freight domain B, This represents the response timestamp for generating the leader intelligent vehicle;

[0045] intelligent vehicles Receiving the intelligent vehicle of the team leader response ,verify Is it valid?

[0046] if This is not true; intelligent vehicles Rejecting the leader's intelligent vehicle response ;

[0047] if Establishment of existence proof Verification successful, temporary identity credential. Valid until Within, and meets the verification conditions. Intelligent vehicles Accepting intelligent vehicles for tour leaders response Calculate the symmetric encryption key Establish intelligent vehicles and the team leader intelligent vehicle A secure communication channel.

[0048] Furthermore, the specific method for matching the trajectories of intelligent vehicles and vehicle platoons is as follows:

[0049] For any vehicle platoon's leader intelligent vehicle Generate intelligent vehicles public and private key pairs and evaluation key ,in, Indicating intelligent vehicles private key, Indicating intelligent vehicles Public key; Use of smart vehicles public key For intelligent vehicles The horizontal and vertical trajectory sequences are encrypted to obtain the intelligent vehicle. The set of encrypted tracks of the horizontal coordinates and the ciphertext set of the vertical axis trajectory Intelligent vehicles The secret track authentication request data packet Send to the team leader's intelligent vehicle ;

[0050] Intelligent vehicle for team leader Receive Secret Track Authentication Request Data Packet Generate public-private key pairs and evaluation key , Intelligent vehicles for the team leader private key, Intelligent vehicles for the team leader Public key; Leading intelligent vehicle Based on public key Intelligent vehicles for team leaders The horizontal and vertical trajectory sequences are encrypted to obtain the leader intelligent vehicle. The set of encrypted tracks of the horizontal coordinates and the ciphertext set of the vertical axis trajectory ;

[0051] Based on intelligent vehicles and the team leader intelligent vehicle Public key and evaluation key generate key information set Based on intelligent vehicles and the team leader intelligent vehicle The ciphertext set of the trajectory generates the ciphertext set of trajectory data for both parties. Send to freight domain B, to which the leader's intelligent vehicle belongs;

[0052] Freight domain B is based on a set of key information. and encrypted collection of trajectory data from both parties Local trajectory matching is performed according to time windows, and the comprehensive trajectory distance value within each time window is calculated. Based on the comprehensive trajectory distance values ​​of all time windows, a trajectory distance ciphertext set is generated. And sent to smart vehicles and the team leader intelligent vehicle ;

[0053] If the local trajectory matching result does not meet the matching conditions, then global trajectory matching is performed to obtain the intelligent vehicle. and the team leader intelligent vehicle In the preset historical time window Historical trajectories of vehicles already driven within the freight domain B, based on intelligent vehicles. and the team leader intelligent vehicle The historical trajectory is calculated using a ciphertext set of trajectory distances. The proportion of trajectory points in the ciphertext set that meet a preset matching threshold is then counted out to obtain the global trajectory matching result, which is then sent to the leader intelligent vehicle. Intelligent vehicle for team leader Determine the intelligent vehicle based on the global trajectory matching results. Does the formation condition meet? If the global trajectory matching result meets the preset matching condition, then the leader intelligent vehicle... Allow intelligent vehicles Join the vehicle platoon; otherwise, reject the intelligent vehicle. Join vehicle platoon;

[0054] If the local trajectory matching result meets the matching condition, then the intelligent vehicle and the team leader intelligent vehicle For the trajectory distance ciphertext set respectively Perform partial decryption to obtain the corresponding partially decrypted set. and And based on Algorithm calculates plaintext set If it exists This makes for All satisfy The leading intelligent vehicle Allow intelligent vehicles Join the vehicle platoon; among them, This represents the number of consecutive trajectory points that satisfy the trajectory matching condition. For matching threshold, This indicates the number of trajectory points in the partially decrypted set.

[0055] The beneficial effects of adopting the above technical solution are as follows: The cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture provided by this invention can achieve reliable registration and public verification of the freight domain in an open freight alliance environment, effectively preventing untrusted domains from mixing into the vehicle platoon from a mechanism level; at the same time, through two types of low-latency authentication processes—intra-domain authentication key negotiation and cross-domain authentication key negotiation—the waiting time for vehicles to join the platoon in high-speed driving scenarios is reduced, improving platooning collaboration efficiency and driving safety; and through a cloud-edge-device collaborative trajectory matching mechanism, local matching is performed at edge nodes to achieve rapid screening, and global matching is performed in the cloud to improve matching accuracy. Thus, platooning access decisions are completed without disclosing commercially sensitive data such as vehicle transportation routes and operational information, achieving comprehensive optimization of security, real-time performance, and privacy protection, and providing technical support for the large-scale deployment of cross-domain vehicle platooning systems. Attached Figure Description

[0056] Figure 1 A schematic diagram of the secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture provided in Embodiment 1 of the present invention. Detailed Implementation

[0057] The specific implementation methods of this application will be further described in detail below with reference to the accompanying drawings and embodiments.

[0058] Example 1:

[0059] Cross-domain intelligent vehicle fleet authentication is a method that enables fleet leaders from different freight domains to verify each other's identities and confirm whether their driving trajectories overlap. Intelligent vehicles in each freight domain travel on the road in fleets. When a fleet from freight domain A requests to join a fleet from freight domain B, the two fleet leaders first perform authentication key negotiation, which verifies each other's identities and establishes a secure communication channel. Subsequently, the fleet leader of freight domain B matches the other fleet leader's driving trajectory with its own. If the trajectories overlap, the request from the freight domain A fleet to join the freight domain B fleet is approved.

[0060] Existing cross-domain vehicle-to-vehicle authentication schemes can be divided into centralized and decentralized types. In centralized schemes, vehicles require real-time assistance from a third party to complete authentication, which introduces the risk of a single point of failure. In contrast, decentralized schemes use blockchain as a cross-domain information sharing platform, and their authentication process does not require real-time third-party participation, significantly improving system reliability. Therefore, this embodiment focuses on blockchain-based cross-domain decentralized authentication and proposes a secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture.

[0061] In cross-domain vehicle platooning scenarios, ensuring the reliability of the domain registration process is crucial to prevent smart vehicles from untrusted freight domains from joining the platoon. However, existing blockchain-based vehicle authentication schemes typically employ centralized domain registration mechanisms, with registration approval completed by a single trusted authority. Furthermore, registration requests do not require joint confirmation from other domains, making it easy for untrusted domains with malicious competition to successfully join the alliance, thus increasing the security risks of platooning operations. Schemes that improve registration reliability by introducing decentralized threshold signature mechanisms usually require publicly broadcasting commitment information and related private key shares on the blockchain. Due to the open nature of blockchain, this information is at risk of being inferred or leaked, potentially allowing malicious domains to bypass the approval mechanism and complete registration. Therefore, achieving both decentralization and high reliability in domain registration within an open environment is difficult.

[0062] In this embodiment, during the domain registration phase, when a smart vehicle applies to join any vehicle platoon of the freight alliance, the freight domain to which the smart vehicle belongs initiates a registration request to the freight alliance. The registration request can only be completed after it has been jointly approved by more than a preset number of freight domains that have joined the freight alliance, in order to prevent untrusted freight domains from joining the freight alliance. During the registration process, the registration request is verified through blockchain, thereby improving the reliability of freight domain registration in an open environment and preventing smart vehicles from untrusted freight domains from sending malicious instructions to the vehicle platoon, which would affect the driving safety of the vehicle platoon.

[0063] In high-speed driving scenarios, intelligent vehicles require high real-time authentication and key negotiation when requesting to join a platoon. However, onboard devices have limited computing power and communication resources, making it difficult to support complex cryptographic operations or large-scale data transmission. While elliptic curve cryptography-based schemes reduce computational overhead, they typically only support one-way authentication and cannot complete full authentication key negotiation. Two-way authentication schemes rely on highly complex computations and require multiple rounds of interaction, resulting in significant computational and communication overhead. Furthermore, as the number of vehicles increases, the scale of information that needs to be synchronized and queried for cross-domain authentication expands, further increasing authentication latency.

[0064] In this embodiment, during the vehicle authentication key negotiation phase, after the freight domain to which the intelligent vehicle belongs completes registration with the freight alliance, the intelligent vehicle and the leader of the vehicle convoy perform identity authentication and session key negotiation. The identity authentication and session key negotiation are implemented based on lightweight cryptographic operations, and are completed through a limited number of rounds of interaction to reduce computation and communication overhead and meet the requirements for low-latency authentication in high-speed driving scenarios. At the same time, by compressing the information required for cross-freight domain authentication, the scale of cross-domain authentication data is prevented from increasing linearly with the number of intelligent vehicles, thereby reducing the latency of cross-domain information upload and query.

[0065] Trajectory matching is a crucial step in vehicle platooning authentication. The platoon leader typically decides whether to allow a smart vehicle to join the platoon based on the trajectory matching results. However, if a smart vehicle directly sends plaintext trajectory data during the authentication process, it will leak commercially sensitive information such as transportation routes. Although some solutions attempt to use fully homomorphic encryption for privacy protection, single-key homomorphic encryption cannot effectively compute data encrypted with different public keys, making it difficult to obtain correct matching results. Furthermore, fully homomorphic encryption involves a large amount of complex computation, which is difficult for onboard devices with limited computing resources. Therefore, existing technologies struggle to simultaneously achieve trajectory matching and trajectory privacy protection under conditions of limited vehicle resources. In cross-domain vehicle platooning scenarios, the successful joining of a smart vehicle often depends on the trajectory matching results. However, most existing solutions rely on matching from a single node or local information, lacking a comprehensive analysis from a global perspective, which can easily lead to misjudgments or omissions, resulting in vehicles meeting platooning requirements not being identified. As the number of vehicles increases, single-node matching mechanisms have limitations in both computing power and data acquisition range, making it difficult to obtain vehicle trajectory information from a wider range in a timely manner, thus reducing the success rate of platooning. Therefore, existing technologies struggle to balance real-time performance with both local and global matching, impacting vehicle platooning efficiency.

[0066] In this embodiment, after identity authentication and session key negotiation are completed during the trajectory matching phase, the intelligent vehicle and the lead vehicle of the vehicle platoon enter the trajectory matching process. The intelligent vehicle encrypts its own trajectory data and sends it to the lead vehicle of the vehicle platoon. The lead vehicle of the vehicle platoon completes the matching calculation based on the encrypted trajectory data and determines whether to allow the intelligent vehicle to join the vehicle platoon based on the matching result. During the trajectory matching process, the trajectory data is not transmitted or leaked in plaintext, thereby preventing the leakage of commercially sensitive information such as the intelligent vehicle's transportation route and operating efficiency, while ensuring that the trajectory matching process can be realized under the limited computing resources of the intelligent vehicle.

[0067] An embodiment of a secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture, such as Figure 1 As shown, it includes the following steps;

[0068] Step 1: Initialize the common parameters, including the first set of common parameters and the second set of common parameters;

[0069] Initialize common parameters ,in, For the first common parameter set, For the second set of common parameters;

[0070] First common parameter set This includes common parameters required for threshold signing, ElGamal encryption, and authentication key negotiation, among which... , , and All are of order. cyclic group , and yes Three uniformly random generators, For generators in the common parameters, yes Uniformly random generator, For large prime numbers, It is a bilinear mapping. , , , , and Both are hash functions. For model The integer addition group, Hash function The length parameter of the output binary string. Hash function The length parameter of the output binary string;

[0071] Second common parameter set ,in, For the dimensions of RLWE, Represents the ciphertext modulus. The expression is defined on the polynomial ring. Key distribution on The expression is defined on the polynomial ring. Error distribution on Indicates from the model A vector randomly selected from the polynomial ring vector space, i.e. for random vectors on, This represents the dimension of a vector. Indicates by Each belongs to A vector space composed of the elements of a polynomial ring. , Represents a set of integers. Represents a polynomial variable. Represents a ring of polynomials with integer coefficients. This represents a modular polynomial, therefore a polynomial ring. In the modulo polynomial The quotient ring obtained by the following construction; Represents the polynomial ring The coefficients of each polynomial in the model are arranged according to their modulus. The polynomial ring obtained after taking values;

[0072] RLWE is an abbreviation for Ring Learning With Errors, which represents the error-based learning problem on rings and is a fundamental and difficult problem for the security of multi-key homomorphic encryption schemes.

[0073] Freight companies that initiated the freight alliance deployed smart contracts to the blockchain. and obtain the smart contract identifier. ;in, Indicates the registered public key authentication algorithm. This indicates the registration verification function. This represents a unique identifier generated after a smart contract is deployed on the blockchain, used for subsequent calls to the smart contract.

[0074] Step 2: When an intelligent vehicle applies to join any vehicle platoon in the freight alliance, the intelligent vehicle registers with its freight domain based on public parameters and obtains a set of temporary identity credentials; the freight domain to which the intelligent vehicle belongs initiates a registration request to the freight alliance based on public parameters, and the freight domains that have joined the freight alliance jointly negotiate to determine whether to approve the registration request based on public parameters; after the freight domain to which the intelligent vehicle belongs completes the registration, the freight domain uploads the intelligent vehicle's trajectory to the cloud.

[0075] Step 2.1: The intelligent vehicle registers with its freight domain based on public parameters, obtaining a set of temporary identity credentials for the intelligent vehicle, including... A temporary identity credential;

[0076] intelligent vehicles Send the real identity identifier to its freight domain A Randomly generated The temporary private key factor is used to calculate the temporary public key and temporary identity; based on the first temporary private key factor... Temporary private key factor The calculated temporary public key is Temporary identity is ,in, , Modulus The multiplication group;

[0077] Freight Domain A is based on intelligent vehicles of A temporary public key and A temporary identity is generated for intelligent vehicles. of Temporary identity binding information and A temporary private key, based on A temporary identity binding information is used to generate intelligent vehicles. A collection of temporary identity binding information; based on the first A temporary public key and temporary identity The generated first The temporary identity binding information is , No. The temporary private key is ,in, Indicates temporary identity The validity period, This is the private key for freight domain A;

[0078] Set up temporary identity binding information for all intelligent vehicles within freight domain A. Temporary identity binding information As leaf nodes, generate the Merkle tree and the existence proof for each leaf node. The root node of the Merkle tree and all leaf nodes The proof of existence is uploaded to the blockchain, whereby... The number of intelligent vehicles in freight domain A.

[0079] Freight Domain A is based on A temporary public key, temporary identity, temporary identity binding information, temporary private key, and proof of existence of the temporary identity binding information are used to generate an intelligent vehicle. Collection of temporary identity credentials ,include A temporary identity credential;

[0080] Step 2.2: The freight domain to which the intelligent vehicle belongs initiates a registration request to the freight alliance;

[0081] Freight domain A applying to join the freight alliance is based on identity verification. Master key and share public key Generate a registration request for freight domain A. And send it to all freight domains in the freight alliance;

[0082] Step 2.3: Freight domains that have joined the freight alliance jointly determine whether to approve the registration request based on common parameters;

[0083] All freight domains that have joined the freight alliance receive registration requests from freight domain A. Randomly select multiple The polynomial computation of the commitment value, ciphertext, and zero-knowledge proof; the... The selected freight domains that have joined the freight alliance Polynomials of degree include , and ,in, For polynomial variables, For polynomials coefficient, For polynomials coefficient, For polynomials The coefficient;

[0084] No. The commitment value calculated by a freight domain that has joined a freight alliance. As shown in the formula below:

[0085] ;

[0086] No. A freight domain that has joined a freight alliance is based on other freight domains that have joined freight alliances. Calculated ciphertext As shown in the formula below:

[0087] ;

[0088] in, , and They respectively represent polynomials , and The generated share-related encrypted ciphertext; and Representing polynomials respectively and In polynomial variables The value at; and A randomly selected encrypted random number. And satisfy ; For the first The share public key of a freight domain that has joined the freight alliance; This is a set of indexes for all freight domains that have joined the freight alliance. Indicates except the first A set of indexes for other freight domains that have joined a freight alliance, excluding the freight domains that have joined the freight alliance.

[0089] No. Zero-knowledge proofs obtained from freight domains that have joined freight alliances. As shown in the formula below:

[0090] ;

[0091] in, To prove the value of the commitment Zero-knowledge proof of correctness For the purpose of proving sent to the first Ciphertext of each member field , , Zero-knowledge proof of correctness; For the first The share public key of a freight domain that has joined the freight alliance; , , , , and These correspond to the first and second components in the ciphertext, respectively. Represents non-interactive zero-knowledge proofs, symbol Represents logical AND relation.

[0092] Each freight domain that has joined the freight consortium uploads its commitment value, encrypted data, and zero-knowledge proof to the blockchain, based on smart contracts. Verify the commitment value, ciphertext, and zero-knowledge proof of each freight domain that has joined the freight consortium. ,in, Indicates the registered public key authentication algorithm. This indicates the registration verification function. This indicates the number of freight domains that have joined the freight alliance;

[0093] Define the freight domains within the verified freight alliance as member domains, and generate a member domain index set based on the indexes of all member domains. Generate the threshold public key for each member field;

[0094] Setting the first If a freight domain that has joined the freight alliance passes verification, then the first one... A freight domain that has joined the freight consortium downloads ciphertext uploaded by other member domains from the blockchain as a member domain. and threshold public key Subsequently, the first A freight domain that has joined a freight alliance downloads encrypted text. Decrypt and calculate the private key share. ;

[0095] If the If a freight domain that has joined the freight alliance verifies the registration request of freight domain A, then a partial signature for that registration request is generated. A freight domain that has joined the freight alliance is based on private key shares. Calculate the partial signature and zero-knowledge proof ,in, Registration request for freight domain A to join the freight alliance;

[0096] The first A freight domain signature that has joined the freight alliance and zero-knowledge proof Send to Freight Domain A, which is applying to join the Freight Consortium.

[0097] Freight domain A, applying to join the freight alliance, receives the first... Partial signatures and zero-knowledge proofs of freight domains that have joined the freight consortium are used to verify the first... Zero-knowledge proofs for freight domains that have joined freight alliances Is it valid? If the first Zero-knowledge proofs for freight domains that have joined freight alliances If valid, then determine the first... A freight domain signature that has joined the freight alliance efficient;

[0098] When Freight Domain A, which applied to join the Freight Alliance, received at least If a valid partial signature is obtained, the freight domain that has joined the freight alliance is deemed to have approved the registration request of freight domain A to join the freight alliance.

[0099] Generate a complete signature for freight domain A based on the threshold signature algorithm. , call Registration-based verification function Complete registration, among which, This is the threshold.

[0100] Step 3: When an intelligent vehicle requests to join a vehicle platoon, the intelligent vehicle and the vehicle platoon perform identity authentication and session key negotiation based on common parameters;

[0101] Step 3.1: If intelligent vehicles Intelligent vehicles and vehicle platoon leader If they belong to the same freight domain A, then intelligent vehicles Captain's intelligent vehicle Perform intra-domain authentication key negotiation;

[0102] intelligent vehicles Randomly select authentication random number Computational intelligent vehicles Authentication random public key and certification value Based on temporary identity credentials Generate intradomain connection request Send to the intelligent vehicle of the team leader within the domain , For the timestamps generated by the intra-domain connection requests;

[0103] Intelligent vehicle for team leader Receive intra-domain connection requests , through verification The validity of the request is used to check the message freshness of the intra-domain connection request. and These represent the current time and the maximum valid time interval, respectively.

[0104] if Not valid, the team leader intelligent vehicle Reject intelligent vehicles Join the team;

[0105] if Established, current time Located in temporary identity certificate Validity period Inside, and satisfy Intelligent vehicle leading the team Randomly select authentication random number Computational intelligent vehicles Authentication random public key , certification value and symmetric encryption key Generate a leader intelligent vehicle response And send to smart vehicles ,in, Indicates the timestamp of the response generated by the leader intelligent vehicle;

[0106] intelligent vehicles Receiving the intelligent vehicle of the team leader response , through verification The validity of the response message is checked to determine its freshness.

[0107] if This is not true; intelligent vehicles Rejecting the leader's intelligent vehicle response ;

[0108] if Established, current time Located in temporary identity certificate Validity period Inside, and satisfy Intelligent vehicles Accepting intelligent vehicles for tour leaders response Calculate the symmetric encryption key This is used for encrypted transmission of subsequent inter-vehicle communication data.

[0109] Step 3.2: If intelligent vehicles Intelligent vehicles leading the convoy If they belong to different freight domains, then intelligent vehicles and the team leader intelligent vehicle Perform cross-domain authentication key negotiation;

[0110] intelligent vehicles Randomly select authentication random number Computational intelligent vehicles Authentication random public key and certification value Generate intelligent vehicles Cross-domain connection request Send to the team leader's smart vehicle , This serves as the identity identifier for freight domain A. Indicates the timestamp of the cross-domain connection request being generated;

[0111] Intelligent vehicle for team leader Receiving intelligent vehicles Cross-domain connection request Intelligent vehicle leading the team verify The validity of the cross-domain connection request message freshness is checked by verifying whether the condition is met. and These represent the current timestamp and the maximum valid time interval, respectively.

[0112] like Not valid, the team leader intelligent vehicle Reject intelligent vehicles Cross-domain connection requests;

[0113] if Validity and existence proof Verification successful, temporary identity credential. Valid until Within, and satisfying the verification conditions: Intelligent vehicle leading the team Randomly select authentication random number Computational intelligent vehicle Authentication random public key , certification value and symmetric encryption key Generate a leader intelligent vehicle response Send to smart vehicles ,in Indicates the timestamp of the response generated by the leader intelligent vehicle;

[0114] intelligent vehicles Receiving the intelligent vehicle of the team leader response ,verify The validity of the response message is checked to determine its freshness.

[0115] if This is not true; intelligent vehicles Rejecting the leader's intelligent vehicle response ;

[0116] if Validity and existence proof Verification successful, temporary identity credential. Valid until Within, and meets the verification conditions: Intelligent vehicles Accepting intelligent vehicles for tour leaders response Calculate the symmetric encryption key .

[0117] Step 4: Match the trajectories of intelligent vehicles and vehicle platoons, and determine whether to allow intelligent vehicles to join vehicle platoons based on the matching results;

[0118] With intelligent vehicles Intelligent vehicles leading the convoy Taking different freight domains as an example, the team leader intelligent vehicle Whether to approve following the vehicle is determined based on the trajectory matching results. The request to join. For example, intelligent vehicles. and cross-domain leading intelligent vehicles The trajectory information is as follows and ,in, This indicates the length of the intelligent vehicle's trajectory, which is the number of trajectory points contained in the trajectory. This represents the trajectory point index. This embodiment employs a combination of local and global matching for trajectory matching to improve team formation success rates while ensuring privacy protection. The trajectory matching process is as follows:

[0119] Step 4.1: Generate Follow-up Vehicle Key and encrypt the track;

[0120] MKHE is a multi-key homomorphic encryption mechanism that supports homomorphic operations between data encrypted with different public keys.

[0121] based on Algorithm-generated intelligent vehicles public and private key pairs and evaluation key ,in, Indicating intelligent vehicles private key, Indicating intelligent vehicles The public key. Then, smart vehicles were used respectively. public key The abscissa trajectory sequence of intelligent vehicles and the ordinate trajectory sequence Encryption is performed to obtain the ciphertext set of the horizontal coordinate trajectory. and the ciphertext set of the vertical axis trajectory .in, and They represent intelligent vehicles. No. The x and y coordinates of each trajectory point Indicates the number of trajectory points. and These represent the ciphertext obtained after encrypting the corresponding x and y coordinates, respectively. (Intelligent Vehicles) The secret track authentication request data packet Send to cross-domain leader intelligent vehicle .

[0122] Step 4.2: Leader Generation After using the key and encrypting the trajectory, it is sent to domain B;

[0123] Cross-domain leading intelligent vehicles Receive Secret Track Authentication Request Data Packet ,use Algorithm generates public-private key pairs and evaluation key Cross-domain leading intelligent vehicles Encrypt using its public key respectively and Obtain the ciphertext and , Indicating cross-domain leading intelligent vehicles No. The ciphertext obtained by encrypting the x-coordinates of each trajectory point Indicating cross-domain leading intelligent vehicles No. The ciphertext obtained by encrypting the ordinates of the trajectory points;

[0124] Based on intelligent vehicles and cross-domain leading intelligent vehicles Public key and evaluation key generate key information set Based on intelligent vehicles and cross-domain leading intelligent vehicles The ciphertext set of the trajectory generates the ciphertext set of trajectory data for both parties. Send to freight domain B, to which the leader's intelligent vehicle belongs;

[0125] Step 4.3: The freight domain B to which the leader intelligent vehicle belongs performs local trajectory matching:

[0126] The freight domain B, to which the leader intelligent vehicle belongs, receives the set of key information required for trajectory matching between the two parties. The ciphertext set corresponding to the trajectory data of both parties And perform local trajectory matching based on the trajectory information within the current time window;

[0127] Calculate the first The combined distance value of the trajectory within each time window A trajectory distance ciphertext set is generated based on the comprehensive trajectory distance values ​​across all time windows. As shown in the formula below:

[0128] ;

[0129] ;

[0130] ;

[0131] in, This represents the trajectory distance value along the horizontal axis. This represents the trajectory distance along the vertical axis. Represents the tensor product;

[0132] Freight Domain B to Cross-Domain Leading Intelligent Vehicles Sending trajectory distance ciphertext set Subsequently, cross-domain leading intelligent vehicles Forward To intelligent vehicles If the local matching result meets the preset matching conditions, proceed to the decryption judgment step; if the local matching result does not meet the matching conditions, proceed to the global trajectory matching step.

[0133] Step 4.4: Intelligent Vehicles Received trajectory distance ciphertext set ,use The algorithm partially decrypts the ciphertext set of trajectory distances, obtaining a partial decryption result set. Send to cross-domain leader intelligent vehicle ,in, Indicates the first The partial decryption result corresponding to the distance of each trajectory from the ciphertext Indicates the number of trajectory points;

[0134] Step 4.5: Decrypt and merge the plaintext parts to obtain the plaintext distance and make a judgment;

[0135] Cross-domain leading intelligent vehicles Received decryption result set ,use Algorithm calculation part decryption result set and use Algorithm calculates plaintext set ;

[0136] If it exists This makes for All satisfy Then cross-domain leading intelligent vehicles Agree on intelligent vehicles The request to join allows intelligent vehicles Join the team; among them, This represents the number of consecutive trajectory points that satisfy the trajectory matching condition. The matching threshold;

[0137] Step 4.6: When local matching fails, further perform global trajectory matching;

[0138] Acquiring intelligent vehicles With cross-domain leading intelligent vehicles In the preset historical time window The historical trajectories already traveled within the region are analyzed, and a global similarity analysis is performed. Among these, This represents the global matching time window, which is larger than the time window used for local matching.

[0139] Based on the historical trajectory data of both parties, freight domain B recalculates the trajectory distance ciphertext set and counts the proportion of trajectory points in the trajectory distance ciphertext set that meet the preset matching threshold to the total number of trajectory points, thus obtaining the global trajectory matching result.

[0140] Freight domain B will return the global matching results to the cross-domain leader intelligent vehicle. Intelligent vehicles led by cross-domain teams Determine intelligent vehicles based on global matching results. Does the formation condition meet? If the global matching result meets the preset matching condition, then the cross-domain leader intelligent vehicle... Allow intelligent vehicles Join the formation; otherwise, reject the intelligent vehicle's request to join.

[0141] This embodiment implements a decentralized registration and public verification mechanism for freight domains by deploying smart contracts on the blockchain. Each freight domain participates in the registration confirmation process for applying to join the freight alliance through threshold signatures, avoiding a single freight domain controlling registration permissions. This prevents untrusted domains from joining the alliance at the source, solving the problems of strong trust dependence and susceptibility to malicious exploitation inherent in existing centralized registration models, thereby improving the overall security and reliability of the cross-domain vehicle platooning system.

[0142] This embodiment addresses the need for low-latency authentication in high-speed vehicle scenarios by designing two processes: intra-domain authentication key negotiation and cross-domain authentication key negotiation. By introducing temporary identity credentials and cross-domain credential mechanisms, anonymous vehicle authentication and rapid key negotiation are achieved. This reduces the number of interaction rounds and computational overhead while ensuring authentication security, enabling efficient and secure platooning access even under conditions of limited computing resources and complex communication environments. After vehicles complete identity authentication and establish a secure communication channel, a cloud-edge-device collaborative trajectory matching mechanism is introduced. Local trajectory matching is performed at edge nodes to quickly filter short-term vehicle trajectory information; when local matching fails, global trajectory matching is performed in the cloud to comprehensively analyze vehicle trajectory information over a wider range, thereby improving the accuracy and success rate of vehicle platooning matching. Cross-domain credentials are generated using a Merkle tree structure, and the root nodes of each company are uploaded to the blockchain, ensuring the verifiability and traceability of cross-domain identity information. In cross-domain scenarios, vehicles can complete legitimacy verification without exposing their real identities, improving the system's anti-attack capability and scalability while maintaining anonymity.

[0143] The scope of protection of this application is not limited to the embodiments described above. Obviously, those skilled in the art can make various modifications and variations to this disclosure without departing from the scope and spirit of this disclosure. If such modifications and variations fall within the scope of this disclosure and its equivalents, then the intent of this disclosure also includes these modifications and variations.

Claims

1. A secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture, characterized in that, Includes the following steps: A freight alliance is established based on multiple freight domains. The freight alliance includes one or more vehicle fleets, each vehicle fleet includes one or more intelligent vehicles, and the intelligent vehicles in each vehicle fleet come from one or more freight domains. Initialize public parameters; when an intelligent vehicle applies to join any vehicle platoon in the freight alliance, the intelligent vehicle registers with its freight domain based on the public parameters and obtains a set of temporary identity credentials; the freight domain to which the intelligent vehicle belongs initiates a registration request to the freight alliance, and the freight domains that have joined the freight alliance jointly negotiate based on the public parameters to determine whether to approve the registration request. If the registration request is approved, the freight domain to which the intelligent vehicle belongs completes the registration and uploads the intelligent vehicle's trajectory to the cloud; otherwise, the intelligent vehicle cannot join the freight alliance. When an intelligent vehicle applies to join a vehicle platoon, the intelligent vehicle uses a set of temporary identity credentials to conduct a limited number of rounds of identity authentication and session key negotiation with the vehicle platoon to establish a secure communication channel between the intelligent vehicle and the vehicle platoon. The trajectory of intelligent vehicles and vehicle formations is matched, and the matching result is used to determine whether intelligent vehicles are allowed to join the vehicle formation.

2. The secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 1, characterized in that, The common parameters are: , For the first common parameter set, For the second common parameter set; First common parameter set ,in, , , and All are of order. cyclic group , and yes Three uniformly random generators, For generators in the common parameters, yes Uniformly random generator, For large prime numbers, It is a bilinear mapping. , , , , and Both are hash functions. For model The integer addition group, Hash function The length parameter of the output binary string. Hash function The length parameter of the output binary string; Second common parameter set ,in, Let the dimension be the error-laden learning problem RLWE on the ring. Represents the ciphertext modulus. The expression is defined on the polynomial ring. Key distribution on The expression is defined on the polynomial ring. Error distribution on Indicates from the model A vector randomly selected from a polynomial ring vector space. This represents the dimension of a vector. Indicates by Each belongs to A vector space composed of the elements of a polynomial ring. , Represents a set of integers. Represents a polynomial variable. Represents a ring of polynomials with integer coefficients. This represents a modular polynomial, therefore a polynomial ring. In the modulo polynomial The quotient ring obtained by the following construction; Represents the polynomial ring The coefficients of each polynomial in the model are arranged according to their modulus. The polynomial ring obtained after taking values.

3. The secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 2, characterized in that, The specific method for intelligent vehicles to register with their respective freight domains is as follows: For any intelligent vehicle and intelligent vehicles Belongs to Freight Domain A, Intelligent Vehicles Randomly generated A temporary private key factor, calculated based on public parameters. A temporary public key and A temporary identity; based on the first Temporary private key factor The calculated temporary public key is Temporary identity is ,in, , Modulus The multiplication group; Freight Domain A is based on intelligent vehicles of A temporary public key and A temporary identity is generated for intelligent vehicles. of Temporary identity binding information and A temporary private key, based on A temporary identity binding information is used to generate intelligent vehicles. A collection of temporary identity binding information; based on the first A temporary public key and temporary identity The generated first The temporary identity binding information is , No. The temporary private key is ,in, Indicates temporary identity The validity period, This is the private key for freight domain A; Set up temporary identity binding information for all intelligent vehicles within freight domain A. Temporary identity binding information As leaf nodes, generate the Merkle tree and the existence proof for each leaf node. The existence proofs of the root node and all leaf nodes of the Merkle tree are uploaded to the blockchain. Freight Domain A is based on A temporary public key, temporary identity, temporary identity binding information, temporary private key, and proof of existence of the temporary identity binding information are used to generate an intelligent vehicle. Collection of temporary identity credentials ,include A temporary identity credential.

4. The secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 2, characterized in that, The specific method for intelligent vehicles belonging to the freight domain to initiate a registration request to the freight alliance is as follows: For freight domain A applying to join the freight alliance, the identity identifier of freight domain A is used. Master key and share public key Generate registration request And send it to all freight domains in the freight alliance.

5. The secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 4, characterized in that, The specific method by which freight domains that have joined the freight alliance jointly determine whether to approve a registration request based on common parameters is as follows: For each freight domain in the freight alliance, receive the registration request from freight domain A. Randomly select multiple Polynomial computation of commitment values, ciphertext, and zero-knowledge proofs; Each freight domain in the freight consortium uploads its commitment value, ciphertext, and zero-knowledge proof to the blockchain for verification. Verified freight domains within the consortium are then designated as member domains, and a member domain index set is generated based on the indexes of all member domains. ; Each member domain downloads the ciphertext and threshold public key uploaded by other member domains from the blockchain, decrypts the ciphertext, and calculates its private key share. The private key share for each member domain is , For member field index set Index of member fields , and All are the first A polynomial with randomly selected member fields; If the member domain's registration request to freight domain A is verified, then a partial signature and a zero-knowledge proof are calculated based on the member domain's private key share and the freight domain A's registration request, and the member domain's partial signature and zero-knowledge proof are sent to freight domain A. Freight domain A verifies the validity of the partial signature and zero-knowledge proof for each member domain when at least When the partial signature and zero-knowledge proof of each member domain are valid, the freight domain that has already joined the freight consortium approves the registration request of freight domain A, which is applying to join the freight consortium. The threshold is used as the threshold value; Generate a complete signature for freight domain A based on the threshold signature algorithm. Complete registration.

6. The secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 5, characterized in that, The vehicle platoon includes a leader intelligent vehicle; When an intelligent vehicle requests to join a vehicle platoon, the intelligent vehicle performs a limited number of rounds of identity authentication and session key negotiation based on a set of temporary identity credentials and the vehicle platoon. The specific method is as follows: If the intelligent vehicle and the convoy's leader intelligent vehicle belong to the same freight domain, the intelligent vehicle and the leader intelligent vehicle will negotiate the domain-specific authentication key. If the intelligent vehicle and the convoy's leader intelligent vehicle belong to different freight domains, the intelligent vehicle and the leader intelligent vehicle shall negotiate a cross-domain authentication key.

7. The secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 6, characterized in that, The specific method for negotiating the intra-domain authentication key is as follows: intelligent vehicles Randomly select authentication random number Computational intelligent vehicles Authentication random public key and certification value Based on temporary identity credentials Generating intelligent vehicles intradomain connection requests Send to the team leader's smart vehicle , For the timestamps generated by the intra-domain connection requests; Intelligent vehicle for team leader Receiving intelligent vehicles intradomain connection requests ,verify Whether it is valid, among which and These represent the current time and the maximum valid time interval, respectively. if Not valid, the team leader intelligent vehicle Reject intelligent vehicles Joining the vehicle platoon, among which... The current time; if Established, current time In intelligent vehicles The validity period of temporary identity certificates Inside, and satisfy Intelligent vehicle leading the team Randomly select authentication random number Computational intelligent vehicles Authentication random public key , certification value and symmetric encryption key Generate a leader intelligent vehicle response And send to smart vehicles ,in, Indicates the timestamp of the response generated by the leader intelligent vehicle; intelligent vehicles Receiving the intelligent vehicle of the team leader response ,verify Is it valid? if This is not true; intelligent vehicles Rejecting the leader's intelligent vehicle response ; if Established, current time Temporary identity certificate Validity period Within, and meets the verification conditions. Intelligent vehicles Accepting intelligent vehicles for tour leaders response Calculate the symmetric encryption key Establish intelligent vehicles and the team leader intelligent vehicle A secure communication channel.

8. The secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 6, characterized in that, The specific method for cross-domain authentication key negotiation is as follows: intelligent vehicles Randomly select authentication random number Computational intelligent vehicles Authentication random public key and certification value Generate intelligent vehicles Cross-domain connection request Send to the team leader's smart vehicle , This serves as the identity identifier for freight domain A. Indicates the timestamp of the cross-domain connection request being generated; Intelligent lead vehicles belonging to freight domain B Receive cross-domain connection requests ,verify Whether it is true or not, among which, Indicates the maximum valid time interval; if Not valid, the team leader intelligent vehicle Reject intelligent vehicles Cross-domain connection requests; if Validity and existence proof Verification successful, temporary identity credential. Valid until Within, and meets the verification conditions. Intelligent vehicle leading the team Randomly select authentication random number Computational intelligent vehicle Authentication random public key , certification value and symmetric encryption key Generate a leader intelligent vehicle response Send to smart vehicles ,in, Intelligent vehicles for the team leader The identifier of the freight domain B, This represents the response timestamp for generating the leader intelligent vehicle; intelligent vehicles Receiving the intelligent vehicle of the team leader response ,verify Is it valid? if This is not true; intelligent vehicles Rejecting the leader's intelligent vehicle response ; if Establishment of existence proof Verification successful, temporary identity credential. Valid until Within, and meets the verification conditions. Intelligent vehicles Accepting intelligent vehicles for tour leaders response Calculate the symmetric encryption key Establish intelligent vehicles and the team leader intelligent vehicle A secure communication channel.

9. A secure cross-domain intelligent vehicle platooning authentication method based on a cloud-edge-device architecture according to claim 8, characterized in that, The specific method for matching the trajectories of intelligent vehicles and vehicle platoons is as follows: For any vehicle platoon's leader intelligent vehicle Generate intelligent vehicles public and private key pairs and evaluation key ,in, Indicating intelligent vehicles private key, Indicating intelligent vehicles Public key; Use of smart vehicles public key For intelligent vehicles The horizontal and vertical trajectory sequences are encrypted to obtain the intelligent vehicle. The set of encrypted tracks of the horizontal coordinates and the ciphertext set of the vertical axis trajectory Intelligent vehicles The secret track authentication request data packet Send to the team leader's intelligent vehicle ; Intelligent vehicle for team leader Receive Secret Track Authentication Request Data Packet Generate public-private key pairs and evaluation key , Intelligent vehicles for the team leader private key, Intelligent vehicles for the team leader Public key; Leading intelligent vehicle Based on public key Intelligent vehicles for team leaders The horizontal and vertical trajectory sequences are encrypted to obtain the leader intelligent vehicle. The set of encrypted tracks of the horizontal coordinates and the ciphertext set of the vertical axis trajectory ; Based on intelligent vehicles and the team leader intelligent vehicle Public key and evaluation key generate key information set Based on intelligent vehicles and the team leader intelligent vehicle The ciphertext set of the trajectory generates the ciphertext set of trajectory data for both parties. Send to freight domain B, to which the leader's intelligent vehicle belongs; Freight domain B is based on a set of key information. and encrypted collection of trajectory data from both parties Local trajectory matching is performed according to time windows, and the comprehensive trajectory distance value within each time window is calculated. Based on the comprehensive trajectory distance values ​​of all time windows, a trajectory distance ciphertext set is generated. And sent to smart vehicles and the team leader intelligent vehicle ; If the local trajectory matching result does not meet the matching conditions, then global trajectory matching is performed to obtain the intelligent vehicle. and the team leader intelligent vehicle In the preset historical time window Historical trajectories of vehicles already driven within the freight domain B, based on intelligent vehicles. and the team leader intelligent vehicle The historical trajectory is calculated using a ciphertext set of trajectory distances. The proportion of trajectory points in the ciphertext set that meet a preset matching threshold is then counted out to obtain the global trajectory matching result, which is then sent to the leader intelligent vehicle. Intelligent vehicle leading the team Determine the intelligent vehicle based on the global trajectory matching results. Does the formation condition meet? If the global trajectory matching result meets the preset matching condition, then the leader intelligent vehicle... Allow intelligent vehicles Join the vehicle platoon; otherwise, reject the intelligent vehicle. Join vehicle platoon; If the local trajectory matching result meets the matching condition, then the intelligent vehicle and the team leader intelligent vehicle For the trajectory distance ciphertext set respectively Perform partial decryption to obtain the corresponding partially decrypted set. and And based on Algorithm calculates plaintext set If it exists This makes for All satisfy The leading intelligent vehicle Allow intelligent vehicles Join the vehicle platoon; among them, This represents the number of consecutive trajectory points that satisfy the trajectory matching condition. For matching threshold, This indicates the number of trajectory points in the partially decrypted set.