Fraud Indicator Aggregator for Identifying Fraudulent States in a Vehicle-to-Everything (V2X) Communication System
Patent Information
- Application Number
- JP2024561894
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-04-25
- Filing Date
- 2023-02-21
- Publication Date
- 2026-02-12
AI Technical Summary
V2X systems face issues with redundant reports of inaccurate or intentional false information, leading to overloading of communication network resources and Misbehavior Authority computing devices, due to multiple vehicles detecting and reporting misconduct.
A method for aggregating indications of misbehavior from multiple detection mechanisms within a V2X system, determining a reportable or actionable misbehavior state based on thresholds, weights, or subset outputs, to reduce redundant reports and optimize resource usage.
The method effectively identifies actionable misbehavior states while minimizing redundant reports, optimizing communication bandwidth and processing capabilities in V2X systems.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] Related Applications This application claims the benefit of priority from U.S. Non-Provisional Patent Application No. 17 / 660,513, filed on April 25, 2022, the entire content of which is incorporated herein by reference.
Background Art
[0002] A Vehicle-to-Everything (V2X) system can adopt protocols and messaging defined under related standards such as Cellular Vehicle-to-Everything (C-V2X), Dedicated Short Range Communication (DSRC), and ITS-G5. These standards serve as the basis for vehicle-based wireless communication and can be used to support intelligent highways, autonomous vehicles, and semi-autonomous vehicles, and to improve the overall efficiency and safety of the arterial road transportation system. An element of the V2X system is the ability of a vehicle to broadcast V2X messages, such as Basic Safety Messages (BSM) or Cooperative Awareness Messages (CAM), that can be received and processed by other vehicles to improve traffic safety.
[0003] A V2X system can be configured to detect inaccurate or intentional false information in V2X messages received from another vehicle or from an Intelligent Transportation System (ITS) infrastructure device such as Roadside Units (RSUs). Further, the V2X system can be configured to send a report of the detected inaccurate or intentional false information to a Misbehavior Authority computing device. However, when multiple V2X systems detect such inaccurate or intentional false information and send reports thereon, the Misbehavior Authority computing device may receive multiple redundant reports, potentially overloading the Misbehavior Authority computing device. Further, the transmission of redundant reports consumes the limited communication network resources and processing capabilities of the V2X system and the Misbehavior Authority computing device.
SUMMARY OF THE INVENTION
[0004] Various aspects include a method executed by a processor of a vehicle's Vehicle-to-Everything (V2X) communication system for aggregating indications of misbehavior before determining that a misbehavior condition exists. Various aspects can include detecting, via one or more misbehavior detection mechanisms, a plurality of indications of V2X misbehavior, aggregating the indications of misbehavior output from the one or more misbehavior detection mechanisms, determining, based on the aggregated indications of misbehavior, whether a reportable or actionable misbehavior condition exists, and transmitting a misbehavior report or taking a response action in response to determining that a misbehavior condition exists.
[0005] In some aspects, aggregating the improper conduct indications output from one or more improper conduct detection mechanisms can include determining whether any of the one or more improper conduct detection mechanisms outputs an improper conduct indication, and determining whether there is a reportable or actionable improper conduct state based on the aggregated improper conduct indications can include determining that there is a reportable or actionable improper conduct state in response to determining that at least one of the improper conduct detection mechanisms outputs an improper conduct indication.
[0006] In some aspects, aggregating the improper conduct indications output from one or more improper conduct detection mechanisms can include determining whether any one of a selected subset of the one or more improper conduct detection mechanisms outputs an improper conduct indication, and determining whether there is a reportable or actionable improper conduct state based on the aggregated improper conduct indications can include determining that there is a reportable or actionable improper conduct state in response to determining that at least one of the selected subset of the improper conduct detection mechanisms outputs an improper conduct indication.
[0007] In some aspects, aggregating the improper conduct indications output from one or more improper conduct detection mechanisms can include aggregating the improper conduct indications output from a plurality of improper conduct detection mechanisms, and determining whether there is a reportable or actionable improper conduct state based on the aggregated improper conduct indications can include determining that there is a reportable or actionable improper conduct state in response to a threshold number of the improper conduct detection mechanisms outputting an improper conduct indication.
[0008] In some aspects, determining that there is a reportable or actionable improper conduct state in response to a threshold number of the improper conduct detection mechanisms outputting an improper conduct indication can include determining that there is a reportable or actionable improper conduct state in response to a majority of the improper conduct detection mechanisms outputting an improper conduct indication.
[0009] In some aspects, aggregating fraud detection indications output from one or more fraud detection mechanisms can include applying respective weights to the outputs of each of the one or more fraud detection mechanisms and aggregating the weighted outputs of the one or more fraud detection mechanisms, and determining whether there is a reportable or actionable fraud state based on the aggregated fraud detection indication can include determining that there is a reportable or actionable fraud state in response to the weighted output of the fraud detection mechanism exceeding a threshold value.
[0010] In some aspects, detecting multiple indications of V2X fraud via one or more fraud detection mechanisms can include processing V2X information received via a plurality of validity and consistency detectors configured to detect a fraud state and output a fraud detection indication to a detector selector, aggregating fraud detection indications output from one or more fraud detection mechanisms can include passing the output of fraud detection indications from a selected subset of the plurality of validity and consistency detectors from the detector selector to a fraud detector, and determining whether there is a reportable or actionable fraud state based on the aggregated fraud detection indication can include the fraud detector determining that there is a reportable or actionable fraud state in response to the output of fraud detection indications by the selected subset of the plurality of validity and consistency detectors, and the method can further include determining a rate of fraud determination, determining whether the rate of fraud determination exceeds a maximum threshold or is less than a minimum threshold, deactivating one or more high-sensitivity validity and consistency detectors in response to determining that the rate of fraud determination exceeds the maximum threshold, and activating one or more high-sensitivity validity and consistency detectors in response to determining that the rate of fraud determination is less than the minimum threshold.
[0011] In some aspects, aggregating the fraud indications output from one or more fraud detection mechanisms can include determining the number of events classified as attacks or fraud indications output by each of the multiple fraud detection mechanisms within a time window or set of events, and determining whether there is a reportable or actionable fraud state based on the aggregated fraud indications can include determining that there is a reportable or actionable fraud state in response to determining that the number of events classified as attacks or fraud indications output by any one of the multiple fraud detection mechanisms within the time window or set of events exceeds a threshold.
[0012] A further aspect includes a V2X communication processing and management system including a memory and a processor configured to perform any of the operations of the methods summarized above. A further aspect can include a V2X communication processing and management system having various means for implementing the functions corresponding to any of the methods summarized above. A further aspect can include a non-transitory processor-readable storage medium storing processor-executable instructions configured to cause a processor of a V2X communication processing and management system to perform various operations corresponding to any of the methods summarized above.
[0013] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate exemplary embodiments of the claims and, together with the provided general description and "Detailed Description of the Invention," serve to explain the features herein.
Brief Description of the Drawings
[0014]
Figure 1A
Figure 1B
Figure 2A
Figure 2B
Figure 3
Figure 4A
Figure 4B
Figure 4C
Figure 4D
Figure 4E
Figure 4F
Figure 4G
Figure 5A
Figure 5B
Figure 5C
Figure 5D
Figure 5E
Figure 5F
Figure 5G
[0015] Various embodiments will be described in detail with reference to the accompanying drawings. Wherever possible, the same or similar parts are referred to by the same reference numerals throughout the drawings. References made to particular examples and implementations are for illustrative purposes only and do not limit the scope of the claims.
[0016] Various embodiments include a method and a processor of a vehicle V2X communication processing and management system that implement one or more aggregators of fraud indications identified by any of several plural non-valid detection mechanisms and inconsistent detection mechanisms, algorithms, modules, and / or detectors configured to recognize evidence of events including inconsistent or invalid information in, or received from, V2X messages, vehicle sensors, network information, and the like. Various embodiments include an OR gate aggregator, a quorum-based aggregator, a majority-based aggregator, a majority fraud V2X information aggregator, an adaptive aggregator, and combinations of two or more of such aggregators. By aggregating fraud indications generated by multiple non-valid detection mechanisms and inconsistent detection mechanisms, the identification of the actual fraud state can be improved, false alarms can be avoided or reduced, and / or the generation of redundant fraud reports and / or responses to fraud reports can be reduced. Various embodiments include different methods of aggregating fraud states and determining when a reportable or actionable fraud state exists.
[0017] As used herein, the term "vehicle" generally refers to any of an automobile, a truck, a bus, a train, a boat, and any other type of mobile ADS-capable system that can access map data to perform autonomous or semi-autonomous functions.
[0018] The term "system on chip" (SOC) is used herein to refer to a single integrated circuit (IC) chip that includes multiple resources and / or processors integrated on a single substrate. A single SOC may include circuitry for digital, analog, mixed-signal, and radio frequency functions. A single SOC may also include any number of general-purpose and / or dedicated processors (such as digital signal processors, modem processors, video processors, etc.), memory blocks (such as ROM, RAM, flash, etc.), and resources (such as timers, voltage regulators, oscillators, etc.). An SOC may also include software for controlling not only the integrated resources and processors but also peripheral devices.
[0019] The term "system in a package" (SIP) may be used herein to refer to a single module or package that includes multiple resources, computing units, cores, and / or processors on two or more IC chips, substrates, or SOCs. For example, a SIP may include a single substrate on which multiple IC chips or semiconductor dies are stacked in a vertical configuration. Similarly, a SIP may include one or more multi-chip modules (MCMs) on which multiple ICs or semiconductor dies are packaged on a unified substrate. A SIP may also include multiple independent SOCs that are coupled to each other via high-speed communication circuitry and packaged in close proximity, such as on a single motherboard or within a single wireless device. The proximity of the SOCs facilitates high-speed communication as well as the sharing of memory and resources.
[0020] For vehicle-based communication systems and functions, standards are being developed in multiple regions of the world. Examples include standards developed by the Institute of Electrical and Electronics Engineers (IEEE) and the Society of Automotive Engineers (SAE) for use in North America, or by the European Telecommunications Standards Institute (ETSI) and the European Committee for Standardization (CEN) for use in Europe. For example, the IEEE 802.11p standard is the basis for dedicated short-range communication (DSRC) and ITS-G5 communication standards. IEEE 1609 is a higher-layer standard based on IEEE 802.11p. The Cellular Vehicle-to-Everything (C-V2X) standard is a competing standard developed under the auspices of the 3rd Generation Partnership Project. These standards serve as a basis for vehicle-based wireless communication and can be used to support intelligent highways, autonomous and semi-autonomous vehicles, and improve the overall efficiency and safety of the arterial road transport system. ITS communication can be supported by the next-generation 5G NR communication system. These and other V2X wireless technologies can be used in various embodiments.
[0021] The C-V2X protocol defines two transmission modes that together provide 360° line-of-sight-out recognition for enhanced road safety and autonomous driving and a higher level of predictability. The first transmission mode includes direct C-V2X, which includes vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-pedestrian (V2P), and provides an extended communication range and reliability within the dedicated 5.9 gigahertz (GHz) spectrum of the intelligent transportation system (ITS) that is independent of the cellular network. The second transmission mode includes vehicle-to-network communications (V2N) in mobile broadband systems and technologies such as third generation wireless mobile communication technologies (3G) (e.g., global system for mobile communications (GSM) evolution (EDGE) system, code division multiple access (CDMA) 2000 system, etc.), fourth generation wireless mobile communication technologies (4G) (e.g., long term evolution (LTE) system, LTE advanced system, mobile Worldwide Interoperability for Microwave Access (mobile WiMAX) system, etc.), fifth generation new radio wireless mobile communication technologies (5G NR system, etc.).
[0022] The processing of such messages in the transmitting vehicle and the receiving vehicle can be performed by a processor or a processing system of an on-board device that provides a vehicle-to-everything (V2X) function, which is generally referred to herein as a "V2X communication processing and management system" or simply a "V2X processing system".
[0023] V2X systems and technologies are quite promising for improving traffic flow and vehicle safety by enabling vehicles to share information about their location, speed, direction of travel, braking, and other factors that may be useful to other vehicles for collision avoidance and other safety functions. Elements of a V2X system include a vehicle's ability to broadcast V2X information, such as basic safety messages (BSMs) or cooperative awareness messages (CAMs) in Europe, in V2X messages, and other vehicles can receive and process the V2X information to improve traffic safety. Vehicles can transmit V2X messages frequently, up to 20 times per second in some implementations. With most or all vehicles transmitting V2X information, a receiving vehicle can receive information from other vehicles and control its own speed, direction, steering, route planning, etc. to avoid collisions and position vehicles efficiently and safely relative to each other. Additionally, V2X-equipped vehicles may be able to improve traffic flow by safely reducing the distance between vehicles, driving several vehicles in a platoon, and avoiding vehicles experiencing a breakdown.
[0024] In V2X communication, it is important that inaccurate, corrupted, or deliberately forged data be detected and mitigated. However, as more and more ITS participants are equipped to participate in such networks, the amount of potentially inaccurate, corrupted, or deliberately forged information (which may also be referred to herein as "misconduct") is large and increasing exponentially. For example, an ITS participant engaging in misconduct as a vehicle may send a V2X message inaccurately declaring that the vehicle has the dimensions of a bus in order to deceive other nearby ITS participants into staying further away from the vehicle. As another example, an ITS participant engaging in misconduct may inaccurately indicate that the width of that ITS participant occupies most of the road width, such that other vehicles will not attempt to overtake that ITS participant. As another example, an ITS participant engaging in misconduct (e.g., a scooter) may indicate that it is a pedestrian type of ITS participant in order to drive on a sidewalk without triggering a system alert or warning, e.g., an alert sent to the police. Further, a malfunctioning vehicle sensor or processing error may provide inaccurate V2X information. Such misconduct by ITS participants, whether as a result of equipment malfunction or an intentional attack, can reduce the efficiency of the ITS and, in some cases, endanger human health and safety.
[0025] There are several known methods for detecting V2X messages that contain (or may contain) incorrect or false information, and for detecting sensors and other vehicle data indicating an improper state that can result in the generation of an improper conduct report and / or a request for a safety response by the vehicle. Such methods can be implemented in a V2X processing system as an improper conduct detection mechanism, which can be implemented in software as an algorithm, in a software module of the V2X processing system, and / or in a circuit or dedicated processor (generally referred to herein as a "device"). Some improper conduct detection mechanisms can be configured to detect the lack of consistency of the information contained in the V2X message. Some improper conduct detection mechanisms can be configured to detect when the information in the V2X message conflicts with information known to the receiving V2X processor and / or V2X communication system, such as position information that is substantially different from the position information determined by the vehicle sensors and / or reliable data (e.g., map information contained in the on-board database). Some improper conduct detection mechanisms can be configured to detect reported vehicle dimension data that changes over time or is different from known values (e.g., within the on-board database). Some improper conduct detection mechanisms can be configured to detect a substantial or incorrect drift of position information over time. Some improper conduct detection mechanisms can be configured to detect when the reported position (and potentially size) of the reporting vehicle indicates that two vehicles spatially overlap or another vehicle overlaps with its own vehicle. Some methods can be configured to monitor the speed and acceleration information received in V2X messages from other vehicles to identify speeds that do not match the current state, accelerations reported using the equations of motion that do not match the speeds from moment to moment, etc. Some methods include verifying whether sensor data, whether received from sensors inside the vehicle or other vehicle sensor data included in an improper conduct report, is not reasonable or does not match normal or expected sensor data (e.g., outside the operating range of the sensor or not consistent with the limitations imposed by the surroundings).
[0026] Each of the various methods for detecting an improper state in vehicle-generated information or received improper behavior reports can be implemented in a separate algorithm, software module, processing layer, and / or processor or dedicated circuit that can independently recognize or detect a particular type or source of the improper state. Some non-limiting examples of improper behavior detection mechanisms include errors, inconsistencies, or inappropriate information related to the position of the vehicle, other vehicles, road objects, and terrain features, and other position information that may be important for navigating the vehicle, a mechanism for identifying such errors, inconsistencies, or inappropriate information, a mechanism for identifying errors, inconsistencies, or inappropriate information related to the speed of the vehicle or other vehicles, a mechanism for identifying when the position information of other vehicles overlaps, or overlaps with each other or the host vehicle, a mechanism for identifying when there is an unacceptable drift in the position information of the vehicle or other vehicles, and a mechanism for identifying errors or inconsistencies in the vehicle sensor data within parentheses (e.g., conflicts with information received from other vehicles via V2X messages). For ease of reference, the various different methods, software modules, and / or processors / circuits are referred to herein as "validity and consistency detectors", "improper behavior detection mechanisms", or simply "detectors". In various embodiments, a vehicle V2X system may include any number or plurality of such detectors, and thus such detectors may be referred to as detector 1 through n, and any one detector may be referred to as "detector i". Referring to methods, software, and / or components for identifying an improper state as "detectors", and referring to detectors by number or letter, is not intended to limit the claims to a particular type or configuration for identifying an improper state, or a particular number of such detectors.
[0027] Reporting the status in an illegal act report that can identify the illegal act status in a vehicle and / or ITS and can be processed by other vehicles and illegal act authorities is important to minimize the chaos and safety issues that such a status can bring to all vehicles. However, sending too many illegal act reports, especially redundant reports, by V2X-equipped vehicles may overwhelm the bandwidth available for sending and receiving illegal act reports on the V2X communication channel. Similarly, sending a large number of illegal act reports for minor problems that do not require action by other vehicles or illegal act authorities does not make good use of the limited bandwidth for V2X communication and makes it more difficult for other vehicles to recognize significant illegal act reports from among many minor illegal act reports. For these reasons, V2X-equipped vehicles need to aggregate illegal act status detections before generating one or several illegal act reports, rather than simply confirming that a reportable and / or actionable illegal act status has been detected and sending a report based on all detected illegal act statuses.
[0028] Various embodiments include aggregating unauthorized act indications from one or more unauthorized act detection methods, modules, and / or devices of a vehicle, a method of identifying or determining that a reportable or actionable unauthorized act state exists based on the aggregation, and a V2X communication processing and management system implementing the method. The methods of various embodiments can enable a vehicle V2X system to identify unauthorized act states in a reliable manner while minimizing unnecessary and / or redundant unauthorized act reports and taking action based on the unauthorized act states. In various embodiments, a vehicle V2X processing system can perform operations including receiving and / or detecting multiple indications of V2X unauthorized acts via one or more unauthorized act detection mechanisms (i.e., methods, modules, and / or detector devices or circuits), and aggregating the unauthorized act indications output from the one or more unauthorized act detection mechanisms to provide an aggregated output. The vehicle V2X processing system can use or process the aggregated output to determine whether a reportable or actionable unauthorized act state exists based on the aggregated unauthorized act indications. When a reportable or actionable unauthorized act state is identified, the V2X processing system can transmit an unauthorized act report and / or take a response action in response to determining that the unauthorized act state exists.
[0029] Various types of aggregation methods can be implemented in various embodiments. In some embodiments, the V2X processing system can aggregate the fraud indication output from the fraud detection mechanism by determining whether any of one or more fraud detection mechanisms outputs a fraud indication. For example, the conclusions or outputs from multiple fraud detection mechanisms (i.e., algorithms, modules, and / or devices) can be coupled to an OR gate that functions as an aggregator, such that when any one of the multiple fraud detection mechanisms generates or outputs a fraud indication, the aggregator module outputs the fraud indication or detection to the fraud status determination module or function within the V2X processing system. In such embodiments, the V2X processing system can determine that a reportable or actionable fraud status exists in response to determining that at least one of the fraud detection mechanisms outputs a fraud indication. Thus, any one fraud indication by one or more of the multiple fraud detection mechanisms can result in a determination by the V2X processing system that a fraud status exists for which a report (i.e., a fraud report) should be sent and / or a response action should be taken.
[0030] In some embodiments, the V2X processing system can aggregate the misbehavior indications generated or output from one or more misbehavior detection mechanisms by determining whether any one of a selected subset of the misbehavior detection mechanisms outputs a misbehavior indication. For example, the conclusions or outputs from a selected subset of misbehavior detection mechanisms (i.e., algorithms, modules, and / or devices) can be coupled to an OR gate that functions as an aggregator, such that when any one of the selected misbehavior detection mechanisms generates or outputs a misbehavior indication, the aggregator module outputs a misbehavior indication or detection to a misbehavior status determination module or function within the V2X processing system. Other misbehavior detection mechanisms may be aggregated according to some of the other embodiments disclosed herein, such as being counted and compared to a threshold (e.g., a majority), or weighted indications provided to the misbehavior status determination module or function may be used to assign weights according to the type of detection mechanism. In such embodiments, the V2X processing system can determine that a reportable or actionable misbehavior state exists in response to determining that at least one of a selected subset of the misbehavior detection mechanisms outputs a misbehavior indication.
[0031] In some embodiments, the V2X processing system can aggregate the misbehavior indications output from one or more misbehavior detection mechanisms and output the number of indications received from the misbehavior detection mechanisms corresponding to a particular misbehavior state (e.g., to a misbehavior status determination module or function). In such embodiments, the V2X processing system can determine that a reportable or actionable misbehavior state exists in response to the number of misbehavior indications meeting a threshold number. In some embodiments, comparing the number of misbehavior states to a threshold number can include determining whether a majority of the misbehavior detection mechanisms output misbehavior indications.
[0032] In some embodiments, aggregating fraud indications by a V2X processing system can include applying respective weights to the outputs of each of one or more fraud detection mechanisms and aggregating the weighted outputs of the one or more fraud detection mechanisms. For example, the V2X processing system can assign a weight to a fraud indication from a particular detection mechanism according to the source or sensor used in detecting fraud. In such embodiments, the V2X processing system can determine that a reportable and / or actionable fraud state exists in response to the weighted output of the fraud detection mechanism exceeding a threshold, which may be predefined or may depend on the operating situation or context. In some embodiments, the weight assigned to any given fraud detection mechanism or fraud indication can be preset or pre-determined. In some embodiments, the weight assigned to any given fraud detection mechanism or fraud indication may be changed or updated by the V2X processing system according to various conditions and may be changed or updated by authority (e.g., fraud authority) via over-the-air update.
[0033] In some embodiments, the V2X processing system may be configured to adjust the sensitivity or detection threshold or various fraud detection mechanisms to achieve a certain level of sensitivity without generating an excessive number of fraud reports. In such embodiments, the V2X processing system uses a detector selector configured to select a particular detector whose output is evaluated as part of recognizing a fraud state, and processes fraud indications received from a plurality of validity and consistency detectors configured to detect fraud states. In such embodiments, aggregating fraud indications may include the detector selector passing the output of fraud indications from a selected subset of the plurality of fraud detection mechanisms to a fraud detector configured to determine whether a reportable or actionable fraud state exists based on indications from a selected subset of the plurality of validity and consistency detectors. In such embodiments, the V2X processing system can also determine whether the rate of fraud determination by the system (e.g., the number of fraud determinations made per unit time) exceeds a maximum threshold rate or is less than a minimum threshold rate. The V2X processing system can then deactivate one or more high-sensitivity validity and consistency detectors in response to determining that the rate of fraud determination exceeds the maximum threshold, or activate one or more high-sensitivity validity and consistency detectors in response to determining that the rate of fraud determination is less than the minimum threshold. In this way, the V2X processing system can dynamically adjust the sensitivity of fraud detection so that the rate at which the system reports or takes action based on fraud determinations remains within a predefined range between the maximum rate and the minimum rate.
[0034] In some embodiments, as part of aggregating the outputs from multiple fraud detection mechanisms, the V2X processing system can determine the number of events classified as attack or fraud indications in the output of each of the fraud detection mechanisms within a time window or a set number of events. For example, the fraud detection mechanism can be configured to indicate whether fraud has been detected periodically (e.g., once per second), such as whether fraud has been detected during an intervening period or within an output cycle. In such a configuration, the V2X processing system can monitor the outputs from each of those multiple fraud detection mechanisms over a predetermined time window (e.g., 10 seconds, 30 seconds, 1 minute, etc.) or a set number of output cycles, and aggregate or otherwise track the number of outputs indicating fraud detection. In such embodiments, the V2X processing system can determine when a reportable or actionable fraud state exists based on the count of positive fraud indications (i.e., indications of attack or fraud) by any one of the fraud detection mechanisms within the time window. For example, the V2X processing system can determine that a reportable or actionable fraud state exists when the number of events classified as attack or fraud indications output by any one of the multiple fraud detection mechanisms within the time window or a set number of output cycles exceeds a threshold, such as more than half of the outputs during the time window or a set number of output cycles.
[0035] In some embodiments, the specific type(s) of aggregator(s) implemented in the V2X processing system can be changed or implemented based on various conditions such as traffic volume, driving location, time of day, day of the week, and other factors.
[0036] Various embodiments can improve V2X communication processing and management systems and the functions of V2X communication by aggregating unauthorized act instructions and determining whether to report an unauthorized act state based on the aggregation or take countermeasures based thereon, thereby reducing the transmission of redundant unauthorized act reports, false unauthorized act reports, or low-priority unauthorized act reports, and thereby ensuring that important or critical unauthorized act reports are transmitted and / or countermeasures are taken based thereon while improving the use of limited V2X communication bandwidth.
[0037] FIG. 1A is a system block diagram showing an exemplary communication system 100 suitable for implementing various embodiments. The illustrated exemplary communication system 100 can include any other suitable network such as a 5G New Radio (NR) network, an ITS V2X wireless network, and / or a Long-Term Evolution (LTE) network. References to 5G networks and 5G network elements in the following description are for illustrative purposes and are not intended to be limiting.
[0038] The communication system 100 can include a heterogeneous network architecture including a core network 140, several base stations 110, and various mobile devices including vehicles 102 equipped with an ADS 104 including wireless communication capabilities. The base stations 110 can communicate with the core network 140 via a wired network 126. The communication system 100 can also include a roadside unit 112 that supports V2X communication with the vehicle 102 via a V2X wireless communication link 124.
[0039] The base station 110 is a network element that communicates with wireless devices (e.g., vehicle 102) via the air interface, and may also be referred to as a Node B, an Evolved Node B (eNodeB or eNB), an access point (AP), a radio head, a transmit receive point (TRP), a New Radio base station (NR BS), a 5G Node B (NodeB, NB), a Next Generation NodeB (gNodeB or gNB), etc. Each base station 110 can provide communication coverage for a specific geographic area or "cell". In 3GPP (registered trademark), the term "cell" may refer to the coverage area of a base station, the base station subsystem serving this coverage area, or a combination thereof, depending on the context in which the term is used. The core network 140 may be any type of core network, such as an LTE core network (e.g., an evolved packet core (EPC) network), a 5G core network, a split network as described with reference to Figure 1B.
[0040] The roadside unit can be coupled via the wired network 128 to a remote computing device 132 that hosts a Misbehavior Authority. The roadside unit 112 can communicate via the V2X wireless communication link 124 with the ITS and V2X-equipped vehicles 102 to download information useful for safe operation, including receiving information regarding the V2X misbehavior status recorded and reported by the Misbehavior Authority and reported by other vehicles.
[0041] A cellular wireless communication network, such as a 5G wireless communication network supported by a base station 110, can also be used for V2X communication in some implementation forms and situations. For example, in some locations and implementation forms, the 5G wireless communication network can be used by a V2X communication processing and management system to send an illegal act report to an illegal act authority and receive information regarding the illegal act status from the illegal act authority. To support such communication, the illegal act authority may be coupled to a core network via a communication link 127 such as the Internet, and map data and reliability information may be communicated to the base station 110 via a wired communication link 126 (e.g., Ethernet, optical fiber, etc.) for downloading to the vehicle 102 via a cellular wireless communication link 122 such as a 5G wireless communication link.
[0042] The cellular wireless communication link 122 may include a plurality of carrier signals, frequencies, or frequency bands, each of which may include a plurality of logical channels. The wireless communication links 122 and 124 may use one or more radio access technologies (RATs). Examples of RATs that may be used in a wireless communication link include 3GPP (registered trademark) LTE, 3G, 4G, 5G (such as NR), GSM, code division multiple access (CDMA), wideband code division multiple access (WCDMA (registered trademark)), worldwide interoperability for microwave access (WiMAX), time division multiple access (TDMA), and other cellular RATs for mobile telephony communication technologies. Further examples of RATs that may be used in one or more of the various wireless communication links within the communication system 100 include Wi-Fi, LTE-U, LTE-Direct, LAA, mid-range protocols such as MuLTEfire, and relatively short-range RATs such as ZigBee, Bluetooth, and Bluetooth low energy (LE).
[0043] Figure 1B is a system block diagram showing an exemplary split base station 160 architecture that may be part of a V2X and / or 5G network suitable for communicating V2X messages and misbehavior status information. Referring to FIGS. 1A and 1B, the split base station 160 architecture may include one or more central units (CUs) 162 that can communicate directly with the core network 180 via a backhaul link or, alternatively, communicate indirectly with the core network 180 through one or more split base station units (such as a near real-time (near RT) RAN intelligent controller (RIC) 164 via an E2 link, or a non-real-time (non RT) RIC 1515 associated with a service management and orchestration (SMO) framework 166, or both). The CU 162 can communicate with one or more distributed units (DUs) 170 via respective midhaul links such as an F1 interface. The DU 170 can communicate with one or more radio units (RUs) 172 via respective fronthaul links. The RU 172 can communicate with respective UEs 120 via one or more radio frequency (RF) access links. In some implementations, a user equipment (UE), such as a vehicle ADS system 104, may be served simultaneously by multiple RUs 172.
[0044] Each of the units (i.e., CU162, DU170, RU172), as well as the near RT RIC164, non-RT RIC168, and SMO framework 166, includes one or more interfaces configured to receive or transmit signals, data, or information (collectively signals) via a wired or wireless transmission medium, or can be coupled to one or more interfaces. Each of the units, or an associated processor or controller that provides instructions to the communication interface of the unit, can be configured to communicate with one or more of the other units via the transmission medium. For example, a unit can include a wired interface configured to receive or transmit signals to one or more of the other units via a wired transmission medium. Additionally, the units can include a wireless interface that includes a receiver, transmitter, or transceiver (such as a radio frequency (RF) transceiver) configured to receive, transmit, or receive and transmit signals to one or more of the other units via a wireless transmission medium.
[0045] In some embodiments, CU162 can host the control functions of one or more upper layers. Such control functions can include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Service Data Adaptation Protocol (SDAP), etc. Each control function can be implemented using an interface configured to communicate signals with other control functions hosted by CU162. CU162 can be configured to handle user plane functions (i.e., Central Unit - User Plane (CU-UP)), control plane functions (i.e., Central Unit - Control Plane (CU-CP)), or a combination thereof. In some implementations, CU162 can be logically divided into one or more CU-UP units and one or more CU-CP units. When implemented in an O-RAN configuration, the CU-UP units can communicate bidirectionally with the CU-CP units via an interface such as the E1 interface. CU162 can be implemented to communicate with DU170 as needed for network control and signaling.
[0046] DU170 can correspond to a logical unit that includes one or more base station functions for controlling the operation of one or more RUs172. In some embodiments, DU170 can host one or more of the Radio Link Control (RLC) layer, Media Access Control (MAC) layer, and one or more upper Physical (PHY) layers (such as modules related to Forward Error Correction (FEC) encoding and decoding, scrambling, modulation and demodulation, etc.), at least partially in accordance with a function split defined by the Third Generation Partnership Project (3GPP (registered trademark)). In some embodiments, DU170 can further host one or more lower PHY layers. Each layer (or module) can be implemented using an interface configured to communicate signals with other layers (and modules) hosted by DU170 or with the control functions hosted by CU162.
[0047] The lower layer functions can be implemented by one or more RUs 172. In some deployments, the RUs 172 controlled by the DU 170 may correspond to logical nodes that host an RF processing function, or a low PHY layer function (such as performing fast Fourier transform (FFT), inverse FFT (iFFT), digital beamforming, physical random access channel (PRACH) extraction and filtering, etc.), or both, at least partially based on function splitting such as lower layer function splitting. In such an architecture, the RU(s) 172 can be implemented to handle over-the-air (OTA) communication with one or more UEs 120. In some implementations, the real-time and non-real-time modes of control and user plane communication with the RU(s) 172 can be controlled by the corresponding DU 170. In some scenarios, this configuration can enable the DU(s) 170 and the CU 162 to be implemented in a cloud-based radio access network (RAN) architecture such as a vRAN architecture.
[0048] The SMO framework 166 can be configured to support the RAN deployment and provisioning of non-virtualized network elements and virtualized network elements. In the case of non-virtualized network elements, the SMO framework 166 can be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via operation and maintenance interfaces (such as the O1 interface). In the case of virtualized network elements, the SMO framework 166 can be configured to interact with a cloud computing platform (such as open cloud (O-cloud) 176) to perform network element lifecycle management (such as instantiating virtualized network elements) via a cloud computing platform interface (such as the O2 interface). Such virtualized network elements can include, but are not limited to, CU162, DU170, RU172, and near RT RIC164. In some implementations, the SMO framework 166 can communicate with the hardware aspects of 4G RAN, such as open eNB (O-eNB) 174, via the O1 interface. Additionally, in some implementations, the SMO framework 166 can communicate directly with one or more RU172 via the O1 interface. The SMO framework 166 may also include a non-RT RIC168 configured to support the functions of the SMO framework 166.
[0049] The non-RT RIC 168 may be configured to include a logical function that enables non-real-time control and optimization of RAN elements and resources, an artificial intelligence / machine learning (AI / ML) workflow including model training and updating, or policy-based guidance of applications / features in the near-RT RIC 164. The non-RT RIC 168 may be coupled to the near-RT RIC 125 or communicate with the near-RT RIC 164 (e.g., via the A1 interface). The near-RT RIC 164 may be configured to include a logical function that enables near-real-time control and optimization of RAN elements and resources via data collection and actions through one or more CU 162, one or more DU 170, or both, and an interface connecting the O-eNB to the near-RT RIC 164 (e.g., via the E2 interface).
[0050] In some implementations, the non-RT RIC 168 may receive parameters or external enrichment information from an external server to generate an AI / ML model deployed in the near-RT RIC 164. Such information may be utilized by the near-RT RIC 164 and may be received from a non-network data source or from a network function in the SMO framework 166 or the non-RT RIC 168. In some examples, the non-RT RIC 168 or the near-RT RIC 164 may be configured to adjust RAN behavior or performance. For example, the non-RT RIC 168 may monitor long-term trends and patterns in performance and employ an AI / ML model to implement corrective measures through the SMO framework 166 (e.g., reconfiguration via O1) or via the creation of RAN management policies (e.g., A1 policies).
[0051] FIG. 2A is a component diagram of an exemplary vehicle V2X communication system 200 suitable for implementing various embodiments. Referring to FIGS. 1A-2A, system 200 can include a vehicle 102 that includes a vehicle V2X communication processing and management system 104. The V2X communication processing and management system 104 can communicate with various systems and devices such as an in-vehicle network 210, an infotainment system 212, various sensors 214, various actuators 216, and a wireless module 218 coupled to an antenna 219. The V2X communication processing and management system 104 can also communicate with a roadside unit 112, a cellular communication network base station 110, and other external devices.
[0052] The vehicle V2X communication processing and management system 204 can include a processor 205, a memory 206, an input module 207, an output module 208, and a wireless module 218. The processor 205 can be coupled to the memory 206 (i.e., a non-transitory storage medium) and can be configured by processor-executable instructions stored in the memory 206 to perform the operations of the methods according to various embodiments described herein. Also, the processor 205 can be coupled to an output module 208 that controls an in-vehicle display and an input module 207 that receives information from vehicle sensors and driver inputs.
[0053] The vehicle V2X communication processing and management system 204 can include a V2X antenna 219 coupled to a wireless module 218 configured to communicate with one or more ITS participants such as another V2X-equipped vehicle 106, a roadside unit 112, and a base station 110 or another suitable network access point. The V2X antenna 219 and the wireless module 218 can be configured to support a V2X communication network. In various embodiments, the vehicle V2X communication processing and management system 204 can receive information from a plurality of information sources such as an in-vehicle network 210, an infotainment system 212, various sensors 214, various actuators 216, and the wireless module 218. A processor 205 of the vehicle V2X communication processing and management system can be configured to perform operations including receiving and detecting an indication of an improper act and applying an aggregator to such detection before reporting or taking action based on the determined improper act condition.
[0054] Examples of in-vehicle networks 210 include a Controller Area Network (CAN), a Local Interconnect Network (LIN), a network using the FlexRay protocol, a Media Oriented Systems Transport (MOST) network, and an in-vehicle Ethernet network. Examples of vehicle sensors 214 include a position determination system (such as a Global Navigation Satellite Systems (GNSS) system), a camera, a radar, a lidar, an ultrasonic sensor, an infrared sensor, and other suitable sensor devices and systems. Examples of vehicle actuators 216 include various physical control systems such as steering, brakes, engine operation, lighting, and direction indicators.
[0055] FIG. 2B is a component block diagram showing elements of a vehicle ADS230 configured according to various embodiments. Referring to FIGS. 1A-2B, vehicle ADS230 can include a vehicle V2X communication processing and management system 204 of a vehicle (e.g., 102) configured to communicate with a roadside unit 112 and / or a cellular network base station 110.
[0056] The vehicle V2X communication processing and management system 204 can include one or more processors 205, a memory 206, a wireless module 218), and other components. The vehicle V2X communication processing and management system 204 may include multiple hardware, software, and / or firmware components that operate together to provide the functionality attributed to the processor 205 herein.
[0057] Memory 206 may include a non-transitory storage medium that electronically stores information. The electronic storage medium of memory 206 may include system storage provided integrally (i.e., substantially non-removable) with the vehicle V2X communication processing and management system 204, and / or removable storage removably connectable to the vehicle V2X communication processing and management system 204 via, for example, a port (e.g., a universal serial bus (USB) port, a FireWire port, etc.) or a drive (e.g., a disk drive, etc.). In various embodiments, memory 206 may include one or more of a charge-based storage medium (e.g., EEPROM, RAM, etc.), a solid-state storage medium (e.g., a flash drive, etc.), an optically readable storage medium (e.g., an optical disk, etc.), a magnetically readable storage medium (e.g., magnetic tape, a magnetic hard drive, a floppy drive, etc.), and / or other electronically readable storage media. Memory 206 may include one or more virtual storage resources (e.g., cloud storage, a virtual private network, and / or other virtual storage resources). Memory 206 can store software algorithms, information determined by processor(s) 205, information received from one or more other vehicles 220, information received from roadside unit 112, information received from base station 110, and / or other information that enables the vehicle V2X communication processing and management system 204 to function as described herein.
[0058] The processor(s) 205 can include one or more local processors configured to provide information processing capabilities in the vehicle V2X communication processing and management system 204. Thus, the processor(s) 205 can include one or more of a digital processor, an analog processor, a digital circuit designed to process information, an analog circuit designed to process information, a state machine, and / or other mechanisms for electronically processing information. Although the processor(s) 205 is shown as a single entity in FIG. 2A, this is for illustrative purposes only. In some embodiments, the processor(s) 205 may include multiple processing units. These processing units may be physically located within the same device, or the processor(s) 205 may represent the processing functions of multiple devices distributed within the vehicle and operating in cooperation.
[0059] The vehicle V2X communication processing and management system 204 can be configured by machine-readable instructions 232, which may include one or more instruction modules. The instruction modules may include computer program modules. In various embodiments, the instruction modules can include one or more of a misbehavior detection mechanism module 234, a misbehavior detection instruction aggregator module 236, a misbehavior status determination module 238, and a misbehavior reporting module 240. In some embodiments, the instruction modules can further include one or more of a V2X validity and consistency detector module 242, a detector selector module 244, a misbehavior detection module 246, a misbehavior rate determination module 248, a V2X validity and consistency detector deactivation module 250, a V2X validity and consistency detector activation module 252, and an attack or misbehavior instruction count module 254.
[0060] In various embodiments, a processor 205 executing an improper behavior detection mechanism module 234 can detect a plurality of indications of V2X improper behavior via one or more improper behavior detection mechanisms. For example, in various embodiments, a processor 205 executing an improper behavior detection indication aggregator 236 can aggregate improper behavior indications output from one or more improper behavior detection mechanisms. In some embodiments, a processor 205 executing an improper behavior detection indication aggregator 236 can determine whether any one of one or more improper behavior detection mechanisms outputs an improper behavior indication. In some embodiments, a processor 205 executing an improper behavior detection indication aggregator 236 can determine whether any one of a selected subset of one or more improper behavior detection mechanisms outputs an improper behavior indication. In some embodiments, a processor 205 executing an improper behavior detection indication aggregator 236 can aggregate improper behavior indications output from a plurality of improper behavior detection mechanisms. In some embodiments, a processor 205 executing an improper behavior detection indication aggregator 236 can apply respective weights to the outputs of each of one or more improper behavior detection mechanisms and aggregate the weighted outputs of the one or more improper behavior detection mechanisms. In some embodiments, the weight assigned to any given improper behavior detection mechanism or improper behavior indication can be preset or predetermined. In some embodiments, the weight assigned to any given improper behavior detection mechanism or improper behavior indication may be changed or updated by the V2X processing system according to various conditions, or may be changed or updated by authority (e.g., improper behavior authority) via over-the-air update.
[0061] In some embodiments, the processor 205 executing the fraud detection instruction aggregator 236 can pass the output of fraud detection instructions from a selected subset of the plurality of detectors from the detector selector 244 to the fraud detector module 246. In some embodiments, the processor 205 executing the fraud detection instruction aggregator 236 can determine the number of events classified as attacks or fraud detection instructions output by each of the plurality of fraud detection mechanisms within a time window or set number of events.
[0062] In various embodiments, a processor 205 executing the misconduct status determination module 238 can determine whether there is a reportable or actionable misconduct status based on the aggregated misconduct indications. In some embodiments, the processor 205 executing the misconduct status determination module 238 can determine that there is a reportable or actionable misconduct status in response to determining that at least one of the misconduct detection mechanisms outputs a misconduct indication. In some embodiments, the processor 205 executing the misconduct status determination module 238 can determine that there is a reportable or actionable misconduct status in response to determining that at least one of a selected subset of the misconduct detection mechanisms outputs a misconduct indication. In some embodiments, the processor 205 executing the misconduct status determination module 238 can determine that there is a reportable or actionable misconduct status in response to a threshold number of the misconduct detection mechanisms outputting a misconduct indication. In some embodiments, the processor 205 executing the misconduct status determination module 238 can determine that there is a reportable or actionable misconduct status in response to a majority of the misconduct detection mechanisms outputting a misconduct indication. In some embodiments, the processor 205 executing the misconduct status determination module 238 can determine that there is a reportable or actionable misconduct status in response to the weighted output of the misconduct detection mechanisms exceeding a threshold. In some embodiments, the processor 205 executing the misconduct status determination module 238 can determine that there is a reportable or actionable misconduct status in response to a misconduct indication output by a selected subset of the plurality of validity and consistency detectors 242. In some embodiments, the processor 205 executing the misconduct status determination module 238 can determine that there is a reportable or actionable misconduct status in response to determining that the number of events classified as an attack or misconduct indication output by any one of a plurality of misconduct detection mechanisms within a time window or a set number of events exceeds a threshold.
[0063] In various embodiments, the processor 205 that executes the misbehavior reporting module 240 can send a misbehavior report or take a response action in response to determining that a misbehavior state exists. For example, in some embodiments, the processor 205 that executes the V2X validity and consistency detector module 242 can detect a misbehavior state and output a misbehavior indication to the detector selector. For example, in some embodiments, the processor 205 that executes the detector selector module 244 can select all of a subset of the V2X validity and consistency detectors or detector modules 242 to pass the misbehavior detection output to the misbehavior detector 246.
[0064] In some embodiments, the processor 205 that executes the misbehavior detector 246 can determine that a reportable or actionable misbehavior state exists in response to a misbehavior indication output by a selected subset of a plurality of validity and consistency detectors.
[0065] In some embodiments, the processor 205 that executes the misbehavior rate determination module 248 can determine the rate of misbehavior determination output by the misbehavior state determination module 238.
[0066] In some embodiments, the processor 205 that executes the V2X validity and consistency detector deactivation module 250 can deactivate one or more of the high-sensitivity validity and consistency detectors 242 in response to determining that the rate of misbehavior determination by the misbehavior state determination module 238 exceeds a maximum threshold (X). For example, in some embodiments, the processor 205 that executes the V2X validity and consistency detector activation module 252 can activate one or more of the high-sensitivity validity and consistency detectors 242 in response to determining that the rate of misbehavior determination by the misbehavior state determination module 238 is less than a minimum threshold (Y).
[0067] In some embodiments, the processor 205 that executes the attack or malicious act instruction counting module 254 can determine the number of events classified as attack or malicious act instructions output by each of a plurality of malicious act detection mechanisms within a time window or a set number of events. For example, the processor(s) 205 can execute modules 232-254 and / or other modules by some combination of software, hardware, firmware, software, hardware, and / or firmware, and / or by other mechanisms for configuring processing capabilities on the processor(s) 205.
[0068] The descriptions of the functions provided by the various modules 232-244 are for illustrative purposes and are not intended to be limiting since any of the modules 232-244 may provide more or fewer functions than described. For example, one or more of the modules 232-244 may be excluded and some or all of their functions may be provided by other ones of the modules 232-244. As another example, the processor(s) 205 can execute one or more additional modules that can execute some or all of the functions resulting from one of the following modules 232-244.
[0069] FIG. 3 shows an exemplary SOC architecture of a processing device system-on-chip (SOC) 300 suitable for implementing various embodiments in a vehicle. Referring to FIGS. 1A-3, the processing device SOC 300 may be included in a vehicle V2X processing system for use in vehicle 102.
[0070] The processing device SOC300 may include several heterogeneous processors such as a digital signal processor (DSP) 303, a modem processor 304, an image and object recognition processor 306, a mobile display processor 307, an application processor 308, and a resource and power management (RPM) processor 317. The processing device SOC300 may also include one or more coprocessors 310 (e.g., vector coprocessors) connected to one or more of the heterogeneous processors 303, 304, 306, 307, 308, 317.
[0071] Each of the processors may include one or more cores and an independent / internal clock. Each processor / core may perform operations independently of other processors / cores. For example, the processing device SOC300 may include a processor that executes a first type of operating system (e.g., FreeBSD, LINUX, OS X, etc.) and a processor that executes a second type of operating system (e.g., Microsoft Windows). In some embodiments, the application processor 308 may be the main processor, central processing unit (CPU), microprocessor unit (MPU), arithmetic logic unit (ALU), etc. of the SOC300. The graphics processor 306 may be a graphics processing unit (GPU).
[0072] The processing device SOC300 may include analog circuits and custom circuits 314 for managing sensor data, analog-to-digital conversion, wireless data transmission, and performing other special operations for executing V2X communication. For example, such special operations may include identifying invalid and / or inconsistent information in V2X messages (e.g., sensor data conflicting with the information in the received V2X message) that may indicate improper behavior by another vehicle or in another vehicle sensor or internal system, as well as invalid and / or inconsistent vehicle sensor data that may indicate improper behavior in the vehicle sensors or internal systems.
[0073] The processing device SOC300 may further include system components and resources 316 such as a processor and voltage regulators, oscillators, phase-locked loops, peripheral bridges, data controllers, memory controllers, system controllers, access ports, timers, and other similar components used to support a software client (e.g., a web browser) running on a vehicle V2X processing system (e.g., 104, 204).
[0074] The processing device SOC300 also includes dedicated circuits for camera actuation and management (CAM) 305 that include, provide, control, and / or manage operations such as those of one or more cameras (e.g., primary camera, webcam, 3D camera, etc.), video display data from camera firmware, image processing, video pre-processing, video front-end (VFE), in-line JPEG, high-definition video codec, etc. CAM 305 may be an independent processing unit and / or may include an independent or internal clock.
[0075] In some embodiments, the image and object recognition processor 306 may be configured using processor-executable instructions and / or dedicated hardware configured to perform image processing and object recognition analysis involved in various embodiments. For example, the image and object recognition processor 306 may be configured to process images received from cameras (e.g., 158, 160) via CAM 305 in order to recognize and / or identify other vehicles as described and to perform the functions of the camera perception layer 224 in a different manner. In some embodiments, the processor 306 may be configured to process radar data or lidar data as described and to perform the functions of the radar and / or lidar perception layer 222.
[0076] System components and resources 316, analog and custom circuits 314, and / or CAM 305 may include circuitry for interfacing with peripheral devices such as cameras, radars, lidars, electronic displays, wireless communication devices, external memory chips, etc. Processors 303, 304, 306, 307, 308 may be interconnected via an interconnect / bus module 324, which may include an array of reconfigurable logic gates and / or implement a bus architecture (e.g., CoreConnect, AMBA, etc.), to one or more memory elements 312, system components and resources 316, analog and custom circuits 314, CAM 305, and RPM 317. Communication may be performed by an advanced interconnect such as a high-performance network-on-chip (NoC).
[0077] The processing device SOC 300 may further include an input / output module (not shown) for communicating with resources external to the SOC, such as a clock 318 and a voltage regulator 320. Resources external to the SOC (e.g., clock 318, voltage regulator 320) may be shared by two or more of the internal SOC processors / cores (e.g., DSP 303, modem processor 304, graphics processor 306, application processor 308, etc.).
[0078] The processing device SOC300 may also include additional hardware and / or software components suitable for collecting sensor data from sensors including motion sensors (e.g., the accelerometer and gyroscope of an IMU), user interface elements (e.g., input buttons, touch screen displays, etc.), microphone arrays, sensors for monitoring physical states (e.g., position, orientation, movement, direction, vibration, pressure, etc.), cameras, compasses, Global Positioning System (GPS) receivers, communication circuits (e.g., Bluetooth®, WLAN, WiFi, etc.), and other well-known components of modern electronic devices.
[0079] Figures 4A through 4G are processing module and process flow diagrams showing different systems and processes for aggregating fraud indicators, determining whether there are reportable or actionable fraud states prior to sending a fraud report using the aggregated fraud indicators, and / or determining that action should be taken based on one or more fraud indicators.
[0080] FIG. 4A is a functional block diagram of a V2X aggregator system 400 according to various embodiments for detecting V2X misbehavior events, aggregating V2X misbehavior indications, and transmitting / coping based on the determined misbehavior status. Referring to FIGS. 1A-4A, in various embodiments, the V2X processing system can receive V2X information 402 such as the position, speed, and direction of other vehicles, lane states (e.g., traffic conditions, accident notifications, etc.) of other vehicles and roadside units via BSMs and other V2X messages. Such information is useful and used by the V2X safety application 426, but the information may also be processed by a plurality of validity and consistency detectors 404 that can be composed of several detector mechanisms shown as "Detector 1" 406, "Detector 2" 408, "Detector i" 410, and "Detector n" 412. Each of the plurality of detector mechanisms 406-412 can be configured to evaluate a specific type of information from a specific source, such as by comparing the received information with data stored in memory and data obtained from a specific vehicle information source including sensor data, to recognize or detect misbehavior, errors, or lack of consistency.
[0081] The misbehavior status determination module 414 can use a plurality of aggregators 416, 418, 420, 422 that implement different aggregation methods including the aggregation methods described herein to determine whether one or more misbehavior statuses exist. In addition, the misbehavior status determination module 414 can use the outputs from the plurality of aggregators 416, 418, 420, 422 to align different types of misbehavior determinations 424 with a specific misbehavior detection mechanism (e.g., one or more of the detector mechanisms 406-412) and the specific aggregator output used in making the misbehavior determination 424.
[0082] In some embodiments, the plurality of aggregators 416-422 can receive and aggregate fraud indications from each one of the detector mechanisms 406-412 to perform a fraud determination 424. In such embodiments, a one-to-one correlation can exist between a given aggregator and the corresponding detector mechanism. In this way, the aggregation method used by a given aggregator can be appropriate for the type of fraud detected, the information sources used, or the accuracy or reliability of the corresponding detector mechanism.
[0083] In some embodiments, the outputs from the various detector mechanisms 406-412 may be processed by one or more aggregators 416, 418, 420, 422, and the fraud status determination module 414 can perform a fraud determination 424 using the outputs from the plurality of aggregators 416, 418, 420, 422 coupled to the detector mechanisms 406-412. For example, as shown in FIG. 4A, "Aggregator 1" 416 can receive and process fraud indications output by all of the detector mechanisms 406-412, and "Aggregator 2" 418 can receive and process fraud indications output by "Detector 1" 406 and "Detector n" 412. The different aggregators 416-422 can process the inputs from the plurality of detector mechanisms 406-412 using different aggregation methods suitable for the type of fraud indication received and processed.
[0084] The improper behavior state determination module 414 can output different types of improper behavior determinations 424 according to the processed outputs from various detectors 406-412 and various aggregators 416-422, and the corresponding determination criteria used to identify or confirm the improper behavior state. As an example, consider the case of processing information output from an Emergency Electronic Brake Light (EEBL) application, which is one of the V2X safety applications. The EEBL application enables a vehicle to broadcast its self-generated emergency braking event to surrounding vehicles via V2X messages. A detector (e.g., one of 406-412) can compare the information received in the EEBL V2X message with other vehicle sensor information from, for example, radar, lidar, and cameras, to check whether the remote vehicle transmitting such a V2X message shows a high deceleration consistent with emergency braking. Additionally, the detector may determine whether the braking state of the remote vehicle is relevant to that vehicle (i.e., the "own vehicle"), such as by determining whether the remote vehicle is in the same lane as the own vehicle and within a certain safety distance, such as 100 meters. Thus, in this example, the improper behavior state determination module 414, which makes an improper behavior determination based on information related to the EEBL event, can determine whether to issue a warning by issuing an improper behavior determination 424 relying on acceleration and position information. Therefore, in the case of the EEBL event, the improper behavior state determination module 414 can use the outputs from acceleration-related aggregators and position-related aggregators such as those shown in FIG. 4C.
[0085] The misbehavior determination 424 can be provided to the V2X safety application 426 for an action. In some cases, the V2X safety application 426 can issue a safety warning 428, such as by sending a misbehavior report or generating an internal warning for the driver. In some cases, the V2X safety application 426 can take actions to ensure the safe operation of the vehicle, such as ignoring V2X information determined to be incorrect or taking an action to avoid a dangerous situation in response to determining that the determined misbehavior requires a safety action.
[0086] FIG. 4B shows an exemplary embodiment of a V2X aggregator system 430a for aggregating V2X misbehavior indications and determining whether there is a reportable or actionable misbehavior condition based on the aggregated misbehavior indications. Referring to FIGS. 1A-4B, in some embodiments, one or more of the misbehavior detection mechanisms 406-412 can function as, or similarly to, an OR gate 432. In such embodiments, one or more of the misbehavior detection mechanisms 406-412 can be configured to provide a misbehavior indication (e.g., an indication that a misbehavior has been detected) to the OR gate 432, and the OR gate 432 can be configured to determine that a misbehavior condition exists and issue a misbehavior determination 424 in response to any of the connected misbehavior detection mechanisms 406-412 providing a misbehavior indication.
[0087] As shown in FIG. 4B, the use of an OR function as an integrator can be applied to some but not all of the various fraud detection mechanisms 406-412. Referring to FIGS. 1A-4C, FIG. 4C shows one embodiment of a V2X aggregator system 430b for aggregating V2X fraud indications, where some of the fraud detection mechanisms (e.g., detectors 406, 408) are aggregated at an OR gate 432 and other fraud detection mechanisms (e.g., detectors 410, 412) are aggregated using other types of aggregation 436 that include the aggregator described herein. For example, the OR gate 432 aggregator aggregates fraud indications from location-related detectors 434 (e.g., detectors 406, 408) that identify location-related errors or fraud (e.g., improper and / or inconsistent V2X information), and can output a fraud determination 424 if any one of such detectors identifies a fraud condition.
[0088] Figure 4D shows another embodiment of a V2X aggregator system 440 for aggregating V2X misbehavior indications and determining whether a reportable or actionable misbehavior state exists based on the aggregation of misbehavior indications across several misbehavior detection mechanisms (shown as detectors 406-412). Referring to FIGS. 1A-4D, in some embodiments, the aggregation of V2X misbehavior indications receives misbehavior indication outputs from a plurality of misbehavior detection mechanisms 406-412 and, in decision block 444, determines whether a detector of a predefined threshold number or quorum threshold has provided or is providing the same misbehavior indication or misbehavior indication being evidenced, and generates an output 446 to the V2X processing device of the determination that the detected event constitutes a misbehavior, which can be achieved by an aggregator 442 (shown as a "quorum aggregator"). In some embodiments, the quorum aggregator 442 receives misbehavior indications from various misbehavior detection mechanisms or detectors 406-412, tracks the received misbehavior indications to identify the events reported by the indications, and can effectively count the number of indications within a predefined time interval (e.g., 1 second, 10 seconds, etc.) associated with the same event before comparing its count to the quorum threshold in decision block 444.
[0089] The quorum threshold against which the number of misbehavior indications is compared may be any preset value greater than 1 and can be adjusted dynamically based on operating conditions such as the rate of this behavior event detection. Further, the quorum aggregator 442 may be coupled to some but not all of the misbehavior detection mechanisms or detectors 406-412 within the vehicle V2X system, in which case the aggregated number of misbehavior indications compared to the quorum threshold may be a subset of the mechanisms or detectors. For example, the quorum aggregator 442 may be coupled to misbehavior detection mechanisms or detectors 406-412 that are not coupled to the OR aggregator 432 as shown in FIG. 4C.
[0090] Figure 4E shows another embodiment of the V2X aggregator system 450 for aggregating V2X misbehavior indications and determining whether there is a reportable or actionable misbehavior state based on the aggregated misbehavior indications. Referring to FIGS. 1A-4E, in some embodiments, the weighted aggregation of misbehavior indications from multiple misbehavior detection mechanisms or detectors 406-412 can be performed by the majority aggregator 458. In such embodiments, the misbehavior indication outputs by each of the misbehavior detection mechanisms or detectors 406-412 may be assigned respective weights 451, 452, 453, 454, and the weighted indications can be aggregated by the majority aggregator 458. The majority aggregator 458 can compare the result of aggregating the weighted indications with a threshold in the decision block 458. In response to determining that the weighted indication meets or exceeds the threshold, the majority aggregator 458 can output a misbehavior determination 446 to the V2X processing device, output nothing, or output a determination 448 that the event is not a misbehavior. In some embodiments, the weights 451-454 applied to the misbehavior indications output by the multiple misbehavior detection mechanisms or detectors 406-412 can be pre-determined by misbehavior authority or the like during wireless update or provisioning. In some embodiments, the weights 451-454 applied to the misbehavior indications output by the multiple misbehavior detection mechanisms or detectors 406-412 can be dynamically determined or adjusted by the vehicle V2X processing device based on the rate of the determined misbehavior state by misbehavior authority during wireless update or provisioning, and by other considerations, etc.
[0091] Figure 4F shows another embodiment 470 for aggregating V2X misconduct indications and determining whether there is a reportable or actionable misconduct state based on the aggregated misconduct indications. Referring to FIGS. 1A-4F, in some embodiments, a plurality of validity and consistency detectors 404 can provide a plurality of outputs to an aggregator system 471, which can include a detector selector 472, a misconduct detector 473, a misconduct rate counter 474, comparators 475, 476, 477 for comparing the misconduct rate to a maximum threshold and a minimum threshold, a circuit or algorithm 478 configured to deactivate a high-sensitivity detector within the detector selector 472 when the misconduct rate exceeds the maximum threshold, and a circuit or algorithm 479 configured to activate a high-sensitivity detector within the detector selector 472 when the misconduct rate is below the maximum threshold. Such elements of the aggregator system 471 can be implemented as software as an algorithm, software modules, dedicated circuits, and / or a combination of circuits (e.g., dedicated processors) and software. Such an aggregator system 471 can be used to detect a misconduct state such that the vehicle V2X processing device can vary the validity and consistency detectors 404 used to detect the misconduct state to maintain a rate of misconduct event detection between a maximum threshold rate and a minimum threshold rate.
[0092] In such embodiments, the vehicle V2X processing device can include a plurality of validity and consistency detectors 404 (e.g., detection mechanisms, software modules, and / or devices) that process information received from V2X communications from other vehicles, roadside units, etc., information obtained from vehicle sensors, in-vehicle memory (e.g., in a database containing map information, information about other types of vehicles, etc.), and other sources for identifying inconsistent reports, invalid results (e.g., information known or conflicting with physics), and other indications of possible misconduct within the vehicle, other vehicles, or an intelligent highway system.
[0093] The outputs from the multiple validity and consistency detectors 404 can be selected or filtered by a detector selector 472 that can be configured to pass the fraud indication from the selected one of the multiple validity and consistency detectors 404 to the fraud detector 473. The validity and consistency detectors 404 passed to the fraud detector 473 can be adjusted by inputs from a module or device 478 for deactivating the high-sensitivity detector and a module or device 479 for activating the high-sensitivity detector.
[0094] Thus, some but not necessarily all of the fraud indications output from the validity and consistency detectors 404 can be received by the fraud detector 473. Next, the fraud detector 473 can use the received fraud indication to make a fraud determination 424 (e.g., whether a fraud state exists within the event that triggers the fraud indication). The fraud determination 424 can be passed to the V2X processing device and processed by the V2X processing device. Additionally, a fraud rate counter 474 can record or count the fraud determination 424 and, based thereon, determine the rate of fraud determinations made by the aggregator system 471 per unit of time (e.g., per minute, per hour, etc.).
[0095] As part of determining the rate of misbehavior determination, the misbehavior rate counter 474 or separate comparison modules 475, 476, 477 can determine whether the rate of misbehavior determination exceeds a maximum threshold (determination block 475) or is less than a minimum threshold (determination block 476). Based on such a comparison, the aggregator system 471 can deactivate one or more high-sensitivity detectors (478) if the rate of misbehavior determination exceeds the maximum threshold, or activate one or more high-sensitivity detectors (479) if the rate of misbehavior determination is less than the minimum threshold. In some embodiments, the validity and consistency detectors 404 that are activated or deactivated may be predetermined in an order or ranking based on the accuracy and / or precision of the associated sensor or information source and / or the importance or criticality to vehicle safety of the type of information being addressed by the detector. In this way, the aggregator system 471 can dynamically adjust the validity and consistency detectors 404 that are monitored to detect misbehavior states in response to environmental and vehicle sensors.
[0096] Figure 4G shows another embodiment 460 for aggregating V2X misbehavior indications and determining whether there is a reportable or actionable misbehavior state based on the aggregated misbehavior indications. Referring to FIGS. 1A-4G, in some embodiments, misbehavior indications output by a plurality of misbehavior state detectors 406-412 are received and monitored by a majority misbehavior V2X information aggregator 462 configured to count or otherwise determine the number of event outputs per unit time (e.g., per five event outputs as shown) by each (or a selected subset) of the detectors that classify or indicate an attack (or other misbehavior).
[0097] In some embodiments, the majority misbehavior V2X information aggregator 462 determines, for any one of the detectors 406-412 (e.g., in decision block 468), whether the majority of the events output by a given detector are classified as an attack (or other misbehavior) per unit time, and accordingly can output to the V2X processing system a determination 446 that the event is in a misbehavior state or a determination 448 that the event is not in a misbehavior state.
[0098] In some embodiments, the majority misbehavior V2X information aggregator 462 determines (e.g., in decision block 468) whether the majority of the events output by the misbehavior state detectors 406-412 are classified as an attack (or other misbehavior) per unit time, and accordingly can output to the V2X processing system a determination 446 that the event is in a misbehavior state or a determination 448 that the event is not in a misbehavior state. In some embodiments, the decision module or device 468 that determines whether the majority of the events from a given detector are classified as an attack is separate from the majority misbehavior V2X information aggregator 462 and can make a determination based on the output from the majority misbehavior V2X information aggregator 462.
[0099] FIG. 5A is a process flow diagram of an exemplary method 500a that can be executed by a processor of a vehicle's V2X communication processing and management system (e.g., 104) to aggregate fraud indications received from multiple fraud detection mechanisms (i.e., fraud detection methods, modules, and / or devices) and determine fraud states that are reportable and / or actionable based on the aggregated fraud indications. FIGS. 5B-5H are process flow diagrams of exemplary operations 500b-500h that can be executed as part of what has been described to aggregate fraud indications received from multiple fraud detection mechanisms. Referring to FIGS. 1A-5G, method 500a and operations 500b-500h can be implemented in a vehicle V2X communication processing and management system or other vehicle processor (e.g., 104, 204, 205, 220, 300) (collectively referred to as the "V2X processor") (e.g., 205, 300) that can be implemented in a hardware element, a software element, or a combination of a hardware element and a software element.
[0100] In block 502, the V2X processor can perform operations including detecting multiple indications of V2X misbehavior via one or more misbehavior detection mechanisms. The V2X processing system can be coupled to a plurality of vehicle sensors (e.g., cameras, radars, LIDAR, GPS receivers, etc.) and configured to process information received within V2X messages (e.g., BSMs), and can include software-implemented algorithms or modules and / or devices configured to analyze information obtained from the sensors and V2X messages to recognize inconsistent and / or inappropriate information indicating a misbehavior state. Such software-implemented algorithms or modules and / or devices can be configured as misbehavior detection mechanisms that output misbehavior indications when an inconsistent or inappropriate state that may be caused by a V2X misbehavior state (e.g., an intentional attack or sensor failure) is detected. The means for performing the operations of block 502 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a misbehavior detection mechanism module 234.
[0101] In block 504, the V2X processor can perform operations including aggregating misbehavior indications output from one or more misbehavior detection mechanisms. Aggregating misbehavior indications from a plurality of detectors (e.g., 406 - 412) can include selecting or identifying misbehavior indications from one or selected misbehavior detection mechanisms for use in determining whether a misbehavior state exists or is detected. In some embodiments, as part of the operations in block 504, a plurality of aggregators can receive misbehavior inputs from one or more of the detector mechanisms and apply an aggregation method suitable for the type of detector mechanism coupled to each aggregator or the misbehavior indications processed by each aggregator. In some embodiments, each of the plurality of aggregators can be coupled to a corresponding one of the plurality of detector mechanisms and configured to aggregate the output therefrom.
[0102] By aggregating improper behavior indications and determining whether an improper behavior state exists using the results of such aggregation, false detection and / or the generation of redundant reports of improper behavior states can be avoided. Based on different types of aggregation used in the various embodiments described herein, the output of the improper behavior detection mechanism can be selected, weighted, analyzed over time, or otherwise considered to support determining whether a reportable and / or actionable improper behavior state exists. The means for performing the operation of block 504 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes an improper behavior detection indicator aggregator module 236.
[0103] In block 506, the V2X processor can perform an operation including determining whether a reportable or actionable improper behavior state exists based on the aggregated improper behavior indications. In some embodiments, the V2X processor can determine that an improper behavior state exists in response to any one of all or a selected number of aggregations of the improper behavior detection mechanism outputting an improper behavior indication. In some embodiments, the V2X processor can determine that an improper behavior state exists in response to one or more aggregators determining that the number of improper behavior detection mechanisms outputting an improper behavior indication meets or exceeds a threshold such as a majority or a quorum of the plurality of improper behavior detection mechanisms. In some embodiments, the V2X processor can determine that an improper behavior state exists in response to one or more aggregators indicating that one or more of the improper behavior indicators have concluded that an event is classified as an attack (or other improper behavior) within a unit of time. The means for performing the operation of block 506 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes an improper behavior state determination module 238.
[0104] In block 508, in response to determining that an improper behavior state exists, the V2X processor can perform operations including transmitting an improper behavior report or taking a response action. For example, the V2X processor can generate an improper behavior report including information about the detected improper behavior and initiate transmission of the generated improper behavior report. As another example, the V2X processor can, in response to the detected improper behavior state, ignore incorrect or malicious information, take actions to protect against incorrect or malicious information, or take actions such as initiating a driving response to ensure the safe operation of the vehicle in consideration of incorrect or malicious information from the improper behavior state. The means for performing the operations of block 508 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes an improper behavior reporting module 240.
[0105] Figures 5B - 5G are process flow diagrams of exemplary operations 500b - 500h that can be performed as part of aggregating improper behavior indications received from multiple improper behavior detection mechanisms and determining reportable and / or actionable improper behavior states based on the aggregated improper behavior indications. Operations 500b - 500h can be performed by a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system or other vehicle processors (e.g., 104, 204, 205, 220, 300) (collectively referred to as the "V2X processor") that can be implemented in a hardware element, a software element, or a combination of a hardware element and a software element.
[0106] Figure 5B shows operation 500b that can be performed by a V2X processor to aggregate tampering indications, according to some embodiments. Referring to FIGS. 1A-5B, following the operation at block 502, the V2X processor, as part of aggregating tampering indications output from one or more tampering detection mechanisms, can perform an operation that includes determining, at block 510, whether any of the one or more tampering detection mechanisms outputs a tampering indication. For example, as part of aggregating tampering indications output from one or more tampering detection mechanisms, the V2X processor can receive inputs from all the tampering detection mechanisms and, in response to any tampering indication, determine that the tampering indication should be processed by a tampering detector. In this regard, the aggregator can function as an OR gate and provide an output to the tampering detector in response to any positive indication of tampering detection. The means for performing the operation of block 510 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a tampering detection indication aggregator module 236.
[0107] At block 512, the V2X processor, as part of determining whether there is a reportable or actionable tampering state based on the aggregated tampering indication, can perform an operation that includes determining that there is a reportable or actionable tampering state in response to determining that at least one of the tampering detection mechanisms outputs a tampering indication. For example, the tampering detector can output to the remainder of the V2X processing system a determination that there is a reportable or actionable tampering state, based on the output from the aggregator at block 510. The means for performing the operation of block 512 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a tampering state determination module 238.
[0108] After the operation in block 512, the V2X processor can perform the operation in block 508 as described.
[0109] FIG. 5C shows operation 500c that can be performed by a V2X processor to aggregate tampering indications, according to some embodiments. Referring to FIGS. 1A - 5C, following the operation in block 502, the V2X processor, as part of aggregating tampering indications output from one or more tampering detection mechanisms, can perform an operation in block 514 that includes determining whether any one of a selected subset of one or more tampering detection mechanisms outputs a tampering indication. For example, as part of aggregating tampering indications output from one or more tampering detection mechanisms, the V2X processor can receive an input from a selected subset of tampering detection mechanisms and, in response to any tampering indication from the selected subset of tampering detection mechanisms, can determine that the tampering indication should be processed by a tampering detector, and other tampering indications from other tampering detection mechanisms are aggregated using other aggregation methods. In this regard, one or more aggregators can function as an OR gate for processing the output from a selected subset of tampering detection mechanisms and can provide an output to a tampering detector in response to any positive indication of tampering detection from the selected subset of tampering detection mechanisms. Such embodiments can be useful for aggregating several tampering detection mechanisms that detect tampering having a significant safety impact, such as tampering related to determining or tracking the position of a vehicle and navigation. The means for performing the operation in block 514 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a tampering detection indication aggregator module 236.
[0110] In block 516, as part of determining whether there is a reportable or actionable misconduct state based on the aggregated misconduct instructions, the V2X processor can perform operations including determining that there is a reportable or actionable misconduct state in response to determining that at least one of a selected subset of the misconduct detection mechanisms outputs a misconduct instruction. In such an embodiment, the misconduct detector can output to the rest of the V2X processing system a determination that there is a reportable or actionable misconduct state based on the output from the OR aggregator in block 514 or from other aggregators. The means for performing the operations of block 512 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a misconduct state determination module 238.
[0111] After the operations in block 516, the V2X processor can perform the operations in block 508 as described.
[0112] FIG. 5D shows operation 500d that can be performed by the V2X processor to aggregate misconduct instructions according to some embodiments. Referring to FIGS. 1A - 5D, subsequent to the operations in block 502, the V2X processor can perform operations including aggregating, in block 518, the misconduct instructions output from one or more misconduct detection mechanisms as part of aggregating the misconduct instructions output from the plurality of misconduct detection mechanisms. As part of this aggregation, the V2X processor can total the number of misconduct detection mechanisms that output a positive misconduct instruction. Such a total can be calculated within a period such as within 1 second, 10 seconds, or a minute, as would be the case when a single event is detected by multiple misconduct detection mechanisms. The means for performing the operations of block 5xx can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a misconduct detection instruction aggregator module 236.
[0113] In block 520, the V2X processor can perform operations including determining that a reportable or actionable misconduct state exists in response to the threshold number of misconduct detection mechanisms outputting a misconduct instruction. In some embodiments, the threshold number can be any predetermined number greater than 1, and thus, some evidence or verification among multiple misconduct detection mechanisms is required before the V2X processor determines that a reportable or actionable misconduct state exists. In some embodiments, the threshold number can be set to a number one more than half the number of active misconduct detection mechanisms in the V2X processing system, and thus, it is required that more than half of the misconduct detection states have detected an output action instruction before the system determines that a reportable or actionable misconduct state exists. In some embodiments, the threshold number can be set to a number predefined as a quorum, such as more than half the number of active misconduct detection mechanisms in the V2X processing system, and thus, it is required that a quorum of the misconduct detection states have detected an output action instruction before the system determines that a reportable or actionable misconduct state exists. In some embodiments, the threshold number can be set to a number substantially greater than half the number of active misconduct detection mechanisms in the V2X processing system, and thus, it is required that a overwhelming majority of the misconduct detection states have detected an output action instruction before the system determines that a reportable or actionable misconduct state exists. Such embodiments can protect against an incorrect determination of a reportable or actionable misconduct state based on one or some of the misconduct detection mechanisms that may be subject to errors or their own misconduct. The means for performing the operations of block 520 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a misconduct state determination module 238.
[0114] After the operations in block 520, the V2X processor can perform the operations in block 508 as described.
[0115] Figure 5E shows operation 500e that can be performed by a V2X processor to determine that an unauthorized act state exists based on a weighted aggregation of unauthorized act indications, according to some embodiments. Referring to FIGS. 1A-5E, following the operation at block 502, the V2X processor can perform an operation at block 522 that includes applying respective weights to the outputs of each of one or more unauthorized act detection mechanisms. The weight applied to each of the unauthorized act detection mechanism outputs can depend on several factors, including the severity of the unauthorized act detected by a particular mechanism, the accuracy or sensitivity of a particular detector mechanism, and / or the reliability of the information used by a particular detection mechanism. For example, an unauthorized act indication output from an unauthorized act detection mechanism configured to identify an error, inconsistency, or other unauthorized act related to safety-critical information (e.g., vehicle position or autonomous driving control) may be given a greater weight than an unauthorized act indication output from an unauthorized act detection mechanism configured to identify an error or inconsistency in less important information. By weighting the unauthorized act indications in this manner, the V2X processing system can be made more likely to recognize a reportable or actionable unauthorized act state among many simultaneous unauthorized act indications that may be of lower importance or severity to vehicle safety. The means for performing the operation of block 522 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes an unauthorized act detection indication aggregator module 236.
[0116] In block 524, the V2X processor can perform operations including aggregating the weighted outputs of one or more tamper detection mechanisms as part of aggregating tamper indications output from one or more tamper detection mechanisms. For example, the V2X processor can add the weighted tamper indications to obtain an overall weighted indication value. As another example, the V2X processor can determine an average weighted tamper indication by taking the average of all weighted tamper indications within a unit of time. In block 524, other processing of the weighted tamper indications can be used. The means for performing the operations of block 524 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a tamper detection indication aggregator module 236.
[0117] In block 526, the V2X processor can perform operations including determining that a reportable or actionable tamper state exists in response to the weighted output of a tamper detection mechanism exceeding a threshold. In some embodiments, the threshold can be any preset value that can be set by a V2X system provider, a vehicle manufacturer, an intelligent highway system administrator, a tamper authority, or other entity. In some embodiments, the threshold can be set dynamically by the V2X system processor in response to a tamper determination, and / or by a rate of tamper determination, or by an external entity (e.g., a tamper authority) via a wireless system update. The means for performing the operations of block 526 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a tamper state determination module 238.
[0118] After the operations in block 526, the V2X processor can perform the operations in block 508 as described.
[0119] Figure 5F shows an operation 500f that can be performed by a V2X processor to dynamically adjust the sensitivity of V2X misbehavior detection capabilities, according to some embodiments. Referring to FIGS. 1A-5F, the V2X processor can perform operations including processing received V2X information including sensor data via a plurality of validity and consistency detectors configured to detect a misbehavior state and output a misbehavior indication to a detector selector (e.g., 472) at block 528. In some embodiments, such operations can be performed as part of detecting a plurality of indications of V2X misbehavior via one or more misbehavior detection mechanisms at block 502, as described. The means for performing the operations of block 528 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a V2X validity and consistency detector module 242.
[0120] In block 530, as part of aggregating the fraud indication output from one or more fraud detection mechanisms, the V2X processor can perform operations including passing the fraud indication output from a selected subset of the plurality of fraud detection mechanisms from a detector selector (e.g., 472) to a fraud detector (e.g., 473). In such an operation, the detector selector functions as a filter, accepting the fraud indication output from a particular one of the plurality of validity and consistency detectors (e.g., 404) for processing while not passing the fraud indication from unselected detectors. In such an embodiment, the particular validity and consistency detectors accepted for processing can be adjusted according to various conditions, including, as described, according to the rate when the fraud determination is being made. For example, at initial startup, the fraud indication output from all or a predetermined subset of the validity and consistency detectors can be passed to the fraud detector (e.g., 473), but the filter settings of the detector selector over time can be adjusted so that the output from one or some of the selected validity and consistency detectors is not passed to the fraud detector. The means for performing the operations of block 530 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a detector selector module 244.
[0121] In block 532, the V2X processor can perform operations including determining by the fraud detector that there is a reportable or actionable fraud state in response to an output of fraud indication by a selected subset of a plurality of validity and consistency detectors. In some embodiments, such operations can be performed as part of determining whether there is a reportable or actionable fraud state based on an aggregated fraud indication. Various methods described herein, such as based on a threshold number of detectors to report (e.g., a majority of a quorum), or a weighted aggregation of this action indication output by a detector selector (e.g., 472), can be used by the fraud detector 473 to identify a reportable or actionable fraud state. The means for performing the operations of block 532 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes the fraud detector module 246.
[0122] In block 508, the V2X processor can perform the described operations including reporting fraud by transmitting a fraud report and / or taking a safety action(s) in response to determining that there is a reportable or actionable fraud state. The means for performing the operations of block 508 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes the fraud report module 240.
[0123] In block 536, the V2X processor can perform operations including determining the rate (η) of the fraud determination performed in block 532. For example, in some embodiments, the V2X processor performs several fraud determinations made within a given period such as one minute, one hour, or one day, and divides by the length of that period to obtain the rate. As another example, in some embodiments, the V2X processor can count the number of fraud determinations within a given period and use that number as the current rate of fraud determination. As a further example, in some embodiments, the V2X processor can average the time intervals between fraud determinations and use that average interval to determine the rate of fraud determination over the period for which the average was taken. In block 536, other means of determining the rate of fraud determination can also be used by the V2X processor. The means for performing the operations of block 536 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a fraud rate determination module 248.
[0124] In the determination block 538, the V2X processor can perform an operation including comparing the rate (η) of the illegal act determination with the maximum threshold value (X) and / or the minimum threshold value (Y). In some embodiments, the V2X processor can determine whether the rate of the illegal act determination exceeds the maximum threshold value or is less than the minimum threshold value. By performing this comparison, the V2X processor determines whether the average rate at which the illegal act determination is being made under the current situation is within the target range of the determination rate. The maximum threshold value and / or the minimum threshold value may be any preset value and may be set by a V2X system provider, a vehicle manufacturer, an intelligent highway system administrator, an illegal act authority, or other institutions. As a non-limiting example, the maximum threshold value X may be 100 illegal act determinations per second. Thus, when the V2X system reports or takes action based on more illegal act states per unit time than those set by the appropriate institution, the V2X processor can, in block 540, reduce the sensitivity of the illegal act detection system and take an action to maintain the illegal act determination rate within the set range of detection and reporting / action rates. As a non-limiting example, the minimum threshold value Y may be 1 illegal act determination every 10 seconds. Thus, when the V2X system reports or takes action based on fewer illegal act states per unit time than those set by the appropriate institution, the V2X processor can, in block 542, increase the sensitivity of the illegal act detection system and take an action to maintain the illegal act determination rate within the set range of detection and reporting / action rates. The means for performing the operation of block 538 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes an illegal act rate determination module 248.
[0125] In block 540, in response to determining that the fraud detection rate (η) exceeds the maximum threshold (X), the V2X processor can perform operations including deactivating one or more high-sensitivity validity and consistency detectors. For example, in block 540, the V2X processor can reconfigure the detector selector (e.g., 472) to begin filtering one or more validity and consistency detectors whose detection instructions were previously passed to a fraud detector (e.g., 473). In some embodiments, the V2X processor can identify the validity and consistency detectors to be deactivated (i.e., whose fraud detection instructions are to be filtered) based on a prioritization or ranking that may depend on the importance or significance of the nature of the fraud identified by each detector. In this way, the V2X processor can selectively increase the filtering of fraud detection and thus reduce the rate at which it can report and / or act on a fraud condition. The means for performing the operations of block 540 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a V2X validity and consistency detector deactivation module 250.
[0126] In block 542, in response to determining that the rate of misbehavior determination (η) is less than the minimum threshold Y, the V2X processor can perform operations including activating one or more high-sensitivity validity and consistency detectors. For example, in block 542, the V2X processor can reconfigure a detector selector (e.g., 472) to stop filtering one or more previously filtered validity and consistency detectors so that subsequent misbehavior indications can be passed to a misbehavior detector (e.g., 473). In some embodiments, the V2X processor can identify validity and consistency detectors for activation (i.e., that should no longer be filtered) based on a prioritization or ranking that may depend on the importance or significance of the nature of the misbehavior that each detector is configured to identify. In this way, the V2X processor can selectively reduce the filtering of misbehavior detection and thus increase the rate at which misbehavior conditions can be reported and / or acted upon. The means for performing the operations of block 542 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a V2X validity and consistency detector activation module 252.
[0127] In response to determining that the rate of misbehavior determination (η) is between the maximum threshold X and the minimum threshold Y, no change to the active validity and consistency detectors may be made, and the V2X processor can continue to perform operation 500f by processing the V2X information received via the plurality of validity and consistency detectors in block 528, as described.
[0128] Figure 5G shows operation 500g that can be performed by a V2X processor to aggregate fraud indications and determine whether a fraud state exists, according to some embodiments. Referring to FIGS. 1A - 5G, following the operation in block 502, the V2X processor can perform an operation including determining, in block 544, the number of events classified as attack or fraud indications output by each of a plurality of fraud detection mechanisms within a set number of time windows or events. For example, an aggregator can count the events classified as attacks or other frauds within a series of outputs from each fraud detection mechanism and from that count, determine the percentage of outputs indicating an attack or other fraud. This calculation can be achieved for some or all of the fraud detection mechanisms within the V2X system. In some embodiments, this calculation is performed continuously, such as by maintaining a count of the number or percentage of a given number of outputs or a given number of outputs from fraud detection mechanisms classified as attacks or other frauds within a given time window, and providing the running count or percentage as an output. The means for performing the operation of block 544 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes an attack or fraud indication count module 254.
[0129] In determination block 546, the V2X processor can perform operations including determining whether the number of attacks or malicious events indicated in any one of the misbehavior detection mechanisms exceeds a threshold within a time window or the detector output or the set number of events. The threshold can be any number greater than 1. In some embodiments, the threshold can be set to determine whether most of the misbehavior indications from one or more of the misbehavior detection mechanisms indicate attacks or other misbehaviors within a time window or the detector output or the set number of events. The means for performing the operations of block 546 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes an attack or misbehavior indication counting module 254.
[0130] In response to determining that the number of attacks or malicious events indicated in any one of the misbehavior detection mechanisms does not exceed the threshold within the time window or the set number of events (i.e., determination block 546 = "no"), the V2X processor can continue to detect multiple indications of V2X misbehavior via one or more misbehavior detection mechanisms in block 502, as described.
[0131] In response to determining that the number of attacks or malicious events indicated in any one of the misbehavior detection mechanisms exceeds a threshold within a time window or a set number of events (i.e., decision block 546 = "yes"), the V2X processor can determine in block 548 that a misbehavior state exists. As part of the operation in block 548, the V2X processor can execute the operations in the described block 508 and / or output a misbehavior determination to other parts of the V2X system, such as a reporting function and / or a response function for determining the rate of misbehavior determination in block 536. The means for executing the operation in block 548 can include a processor (e.g., 205, 300) of a vehicle V2X communication processing and management system (e.g., 104, 204) that executes a misbehavior state determination module 238.
[0132] After the operation in block 548, the V2X processor can execute the operations in block 508 and / or block 548 as described.
[0133] Implementation examples are described in the following paragraphs. Some of the following implementation examples are described with respect to exemplary methods, but further exemplary implementation forms include the exemplary methods described in the following paragraphs implemented by a V2X communication processing and management system including a processor configured with processor-executable instructions for performing the operations of the methods of the following implementation examples, and the exemplary methods described in the following paragraphs implemented by a V2X communication processing and management system including means for performing the functions of the methods of the following implementation examples. The exemplary methods described in the following paragraphs can be implemented as a non-transitory processor-readable storage medium storing processor-executable instructions configured to cause a processor of a V2X communication processing and management system to execute the operations of the methods of the following implementation examples.
[0134] Example 1. A method executed by a processor of a V2X communication system of a vehicle, the method comprising: detecting a plurality of indications of V2X fraud via one or more fraud detection mechanisms; aggregating fraud indications output from the one or more fraud detection mechanisms; determining, based on the aggregated fraud indications, whether there is a reportable or actionable fraud state; and transmitting a fraud report or taking a response action in response to determining that there is a fraud state.
[0135] Example 2. Aggregating fraud indications output from the one or more fraud detection mechanisms includes determining whether any of the one or more fraud detection mechanisms outputs a fraud indication, and determining whether there is a reportable or actionable fraud state based on the aggregated fraud indications includes determining that there is a reportable or actionable fraud state in response to determining that at least one of the fraud detection mechanisms outputs a fraud indication, the method according to Example 1.
[0136] Example 3. Aggregating fraud indications output from the one or more fraud detection mechanisms includes determining whether any one of a selected subset of the one or more fraud detection mechanisms outputs a fraud indication, and determining whether there is a reportable or actionable fraud state based on the aggregated fraud indications includes determining that there is a reportable or actionable fraud state in response to determining that at least one of the selected subset of the fraud detection mechanisms outputs a fraud indication, the method according to Example 1 or 2.
[0137] Example 4. Aggregating the fraud indication output from one or more fraud detection mechanisms includes aggregating the fraud indications output from multiple fraud detection mechanisms, and determining whether there is a reportable or actionable fraud state based on the aggregated fraud indication. When a threshold number of fraud detection mechanisms output fraud indications, it includes determining that there is a reportable or actionable fraud state. The method according to any one of Examples 1 to 3.
[0138] Example 5. Determining that there is a reportable or actionable fraud state in response to a threshold number of fraud detection mechanisms outputting fraud indications includes determining that there is a reportable or actionable fraud state in response to most of the fraud detection mechanisms outputting fraud indications. The method according to Example 4.
[0139] Example 6. Aggregating the fraud indication output from one or more fraud detection mechanisms includes applying respective weights to the output of each of the one or more fraud detection mechanisms and aggregating the weighted outputs of the one or more fraud detection mechanisms. Determining whether there is a reportable or actionable fraud state based on the aggregated fraud indication includes determining that there is a reportable or actionable fraud state in response to the weighted output of the fraud detection mechanism exceeding a threshold. The method according to any one of Examples 1 to 5.
[0140] Example 7. Detecting multiple indications of V2X misbehavior via one or more misbehavior detection mechanisms includes processing the received V2X information via a plurality of validity and consistency detectors configured to detect a misbehavior state and output a misbehavior indication to a detector selector. Aggregating the misbehavior indications output from the one or more misbehavior detection mechanisms includes passing the output of the misbehavior indications from a selected subset of the plurality of validity and consistency detectors from the detector selector to the misbehavior detector. Determining whether there is a reportable or actionable misbehavior state based on the aggregated misbehavior indication includes determining by the misbehavior detector that there is a reportable or actionable misbehavior state in response to the output of the misbehavior indication by the selected subset of the plurality of validity and consistency detectors. The method further includes determining the rate of misbehavior determination, determining whether the rate of misbehavior determination exceeds a maximum threshold or is less than a minimum threshold, deactivating one or more high-sensitivity validity and consistency detectors in response to determining that the rate of misbehavior determination exceeds the maximum threshold, and activating one or more high-sensitivity validity and consistency detectors in response to determining that the rate of misbehavior determination is less than the minimum threshold. The method according to any one of Examples 1 to 6.
[0141] Example 8. Aggregating the misbehavior indications output from one or more misbehavior detection mechanisms includes determining the number of events classified as attacks or misbehavior indications output by each of the plurality of misbehavior detection mechanisms within a time window or a set number of events. Determining whether there is a reportable or actionable misbehavior state based on the aggregated misbehavior indication includes determining that there is a reportable or actionable misbehavior state in response to determining that the number of events classified as attacks or misbehavior indications output by any one of the plurality of misbehavior detection mechanisms within the time window or the set number of events exceeds a threshold. The method according to any one of Examples 1 to 7.
[0142] The various embodiments illustrated and described are provided only as examples to illustrate various features of the claims. However, the features illustrated and described with respect to any given embodiment are not necessarily limited to the related embodiment and may be used with or combined with other illustrated and described embodiments. Further, the claims are not limited by any exemplary single embodiment. For example, one or more of the operations of a method may be replaced or combined with one or more of the operations of the method.
[0143] The above description of the method and the process flow diagrams are provided only as illustrative examples and do not require or imply that the operations of the various embodiments must be performed in the presented order. As will be understood by those skilled in the art, the order of operations in the above embodiments may be performed in any order. Words such as "thereafter", "then", "next", etc. do not limit the order of operations. These words are used only to guide the reader through the description of the method. Further, for example, any reference to a claim element in the singular using the articles "a", "an", or "the" should not be construed as limiting that element to the singular.
[0144] The various exemplary logical blocks, modules, circuits, and algorithm operations described with respect to the embodiments disclosed herein may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, various exemplary components, blocks, modules, circuits, and operations have generally been described in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in various ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the claims.
[0145] The hardware used to implement the various exemplary logics, logical blocks, modules, and circuits described with respect to the embodiments disclosed in this specification can be implemented or executed using a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gates or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. The general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Alternatively, some operations or methods may be performed by circuitry specific to a given function.
[0146] In one or more embodiments, the described functions may be implemented in hardware, software, firmware, or any combination thereof. When implemented in software, the functions may be stored as one or more instructions or code on a non-transitory computer-readable medium or a non-transitory processor-readable medium. The operations of the methods or algorithms disclosed herein may be embodied in a processor-executable software module that may exist on a non-transitory computer-readable storage medium or a non-transitory processor-readable storage medium. A non-transitory computer-readable storage medium or a non-transitory processor-readable storage medium may be any storage medium that can be accessed by a computer or a processor. By way of example and not limitation, such a non-transitory computer-readable medium or non-transitory processor-readable medium may include RAM, ROM, EEPROM, FLASH memory, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code in the form of instructions or data structures and that can be accessed by a computer. As used herein, Disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray (registered trademark) disc, where disk typically magnetically reproduces data, while disc optically reproduces data using a laser. Combinations of the above are also included within the scope of non-transitory computer-readable and processor-readable media. Additionally, the operations of a method or algorithm may exist as one or any combination or set of code and / or instructions on a non-transitory processor-readable medium and / or a non-transitory computer-readable medium that may be incorporated in a computer program product.
[0147] The foregoing description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the claimed invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the claimed invention. Accordingly, the disclosure is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the following claims and the principles and novel features disclosed herein.
Claims
1. 1. A method executed by a processor of a vehicle-to-everything (V2X) communication system of a vehicle, comprising: processing the received V2X information through a plurality of validity and consistency detectors configured to detect V2X fraud; outputting a fraud indication from the plurality of validity and consistency detectors to a detector selector; the detector selector selecting a subset of the plurality of validity and consistency detectors; passing misconduct indications output from the plurality of validity and consistency detectors to a misconduct detector for a selected subset of the plurality of validity and consistency detectors; the fraud detector determining whether a reportable or actionable fraud condition exists based on the fraud indications output from the selected subset of the plurality of validity and consistency detectors; In response to determining that a fraud condition exists, sending a fraud report or taking a responsive action; A method comprising:
2. The method described in claim 1, wherein the detector selector selects a subset of the plurality of validity and consistency detectors based on a predefined level of sensitivity.
3. Determining whether a reportable or actionable misconduct condition exists includes determining that a reportable or actionable misconduct condition exists in response to determining that at least one of the selected subset of the plurality of validity and consistency detectors outputs a misconduct indication. The method of claim 1.
4. Determining whether a reportable or actionable fraud condition exists includes determining that a reportable or actionable fraud condition exists in response to a threshold number of the selected subset of the plurality of validity and consistency detectors outputting a fraud indication. The method of claim 1.
5. 5. The method of claim 4, wherein determining that a reportable or actionable fraud condition exists in response to a threshold number of the selected subset of the plurality of validity and consistency detectors outputting a fraud indication comprises determining that a reportable or actionable fraud condition exists in response to a majority of the selected subset of the plurality of validity and consistency detectors outputting a fraud indication. applying a respective weight to the output of each of the selected subset of the plurality of validity and consistency detectors; aggregating the weighted outputs of the selected subset of the plurality of validity and consistency detectors; Further comprising: determining whether a reportable or actionable fraud condition exists comprises determining that a reportable or actionable fraud condition exists in response to the weighted output of the fraud detection mechanism exceeding a threshold; The method of claim 1.
7. determining a rate of fraud determination; determining whether the rate of fraudulent activity determinations is above a maximum threshold or below a minimum threshold; deactivating one or more high sensitivity validity and consistency detectors in response to determining that the rate of fraudulent activity determinations exceeds the maximum threshold; activating one or more high sensitivity validity and consistency detectors in response to determining that the rate of fraudulent activity determinations is less than the minimum threshold; Further comprising: The method of claim 1.
8. determining a number of events classified as attack or fraud indications output by each of the selected subset of the plurality of validity and consistency detectors within a time window or a set number of events; determining whether a reportable or actionable fraud condition exists comprises determining that a reportable or actionable fraud condition exists in response to determining that the number of events classified as an attack or fraud indication output by any one of the selected subset of the plurality of validity and consistency detectors within the time window or set number of events exceeds a threshold. The method of claim 1.
9. 1. A vehicle-to-everything (V2X) communication system, comprising: a processor, the processor comprising: processing the received V2X information through a plurality of validity and consistency detectors configured to detect V2X fraud; outputting a cheating instruction to the detector selector; selecting a subset of the plurality of validity and consistency detectors by the detector selector; passing the misconduct indications output from the plurality of validity and consistency detectors to a misconduct detector for a selected subset of the plurality of validity and consistency detectors; determining, by the fraud detector, whether a reportable or actionable fraud condition exists based on the fraud indications output from the selected subset of the plurality of validity and consistency detectors; Sending a fraud report or taking responsive action in response to determining that a fraud condition exists; consists of processor-executable instructions, V2X communication system.
10. The V2X communication system of claim 9, wherein the detector selector is configured to select a subset of the plurality of validity and consistency detectors based on a predefined level of sensitivity.
11. the processor: determining whether a reportable or actionable fraud condition exists in response to determining that at least one of the selected subset of the plurality of validity and consistency detectors outputs a fraud indication; further comprising processor-executable instructions, 10. The V2X communication system of claim 9.
12. the processor: determining whether a reportable or actionable fraud condition exists in response to a threshold number of the selected subset of the plurality of validity and consistency detectors outputting a fraud indication; further comprising processor-executable instructions; the processor further comprising processor-executable instructions for determining that a reportable or actionable fraud condition exists in response to a majority of the selected subset of the plurality of validity and consistency detectors outputting a fraud indication.
10. The V2X communication system of claim 9.
13. the processor: applying a respective weight to the output of each of the selected subset of the plurality of validity and consistency detectors; aggregating the weighted outputs of the selected subset of the plurality of validity and consistency detectors; determining whether a reportable or actionable fraud condition exists in response to the weighted output of the selected subset of the plurality of validity and consistency detectors exceeding a threshold; further comprising processor-executable instructions, 10. The V2X communication system of claim 9.
14. the processor: Determine the rate of fraud detection, determining whether the rate of fraudulent activity determinations is above a maximum threshold or below a minimum threshold; deactivating one or more high sensitivity validity and consistency detectors in response to determining that the rate of fraudulent activity determinations exceeds the maximum threshold; activating one or more high sensitivity validity and consistency detectors in response to determining that the rate of fraudulent activity determinations is less than the minimum threshold; further comprising processor-executable instructions, 10. The V2X communication system of claim 9.
15. A non-transitory processor-readable medium having stored thereon processor-executable instructions configured to cause a processor of a vehicle-to-everything (V2X) communication system to perform operations corresponding to the method of any one of claims 1 to 8.