Movatterモバイル変換


[0]ホーム

URL:


CN115412571B - Vehicle safety protection control method and related equipment - Google Patents

Vehicle safety protection control method and related equipment
Download PDF

Info

Publication number
CN115412571B
CN115412571BCN202210849977.5ACN202210849977ACN115412571BCN 115412571 BCN115412571 BCN 115412571BCN 202210849977 ACN202210849977 ACN 202210849977ACN 115412571 BCN115412571 BCN 115412571B
Authority
CN
China
Prior art keywords
target
change rate
vehicle
rate threshold
controller
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202210849977.5A
Other languages
Chinese (zh)
Other versions
CN115412571A (en
Inventor
李家平
汪涛
张贵海
司华超
武亭
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Voyah Automobile Technology Co Ltd
Original Assignee
Voyah Automobile Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Voyah Automobile Technology Co LtdfiledCriticalVoyah Automobile Technology Co Ltd
Priority to CN202210849977.5ApriorityCriticalpatent/CN115412571B/en
Publication of CN115412571ApublicationCriticalpatent/CN115412571A/en
Application grantedgrantedCritical
Publication of CN115412571BpublicationCriticalpatent/CN115412571B/en
Activelegal-statusCriticalCurrent
Anticipated expirationlegal-statusCritical

Links

Classifications

Landscapes

Abstract

Translated fromChinese

本发明公开了一种车辆安全防护控制方法及相关设备。该方法包括:获取当前请求报文对应的目标变化率请求值;基于目标车辆的目标控制器的功能状态确定目标变化率阈值;基于上述目标变化率请求值和上述目标变化率阈值对上述当前请求报文进行安全分析;基于上述安全分析结果和上述目标变化率请求值控制上述目标车辆。本申请实施例提供的车辆安全防护方法,在第三方应用的请求报文达到车辆端的网络的情况下,根据目标车辆的目标控制器的功能状态,确定其对应的目标变化率阈值,基于目标变化率阈值对当前请求报文对应的请求值的合法性做出判断,及时抛弃超出目标变化率阈值的请求报文,避免车辆执行不符合当前功能的操作,提升车辆的安全性与稳定性。

The present invention discloses a vehicle safety protection control method and related equipment. The method includes: obtaining a target change rate request value corresponding to a current request message; determining a target change rate threshold value based on the functional state of a target controller of a target vehicle; performing a safety analysis on the current request message based on the target change rate request value and the target change rate threshold value; and controlling the target vehicle based on the safety analysis result and the target change rate request value. The vehicle safety protection method provided in the embodiment of the present application, when a request message of a third-party application reaches the network at the vehicle end, determines the corresponding target change rate threshold value according to the functional state of the target controller of the target vehicle, makes a judgment on the legitimacy of the request value corresponding to the current request message based on the target change rate threshold value, and promptly discards request messages that exceed the target change rate threshold value, thereby preventing the vehicle from performing operations that do not conform to the current function, and improving the safety and stability of the vehicle.

Description

Vehicle safety protection control method and related equipment
Technical Field
The present disclosure relates to the field of vehicle safety, and more particularly, to a vehicle safety protection control method and related devices.
Background
With the development of internet of vehicles technology, automobiles have changed from simple mechanical products to mobile intelligent cabin products with complex networks, and the internet of vehicles has become more and more powerful. Intrusion detection and prevention of internet technology is becoming more and more widely used in the automotive field. The intrusion detection and defense module of the vehicle meets the information security requirement of the modern intelligent automobile. Meanwhile, the Ethernet is widely applied in automobiles, and buses commonly used in automobiles are CAN/CAN FD and Ethernet at present. Whether it is CAN/CAN FD bus based in IDS (Intrusion Detection System, intrusion detection module) or ethernet based IDPS (Intrusion Detection and Prevention System, intrusion detection and prevention module), they achieve detection by configuring various rule files. The rule of detection mostly uses common rules of internet technology, such as port scan class, SSH/HTTP protocol attack, doS attack, ARP spoofing, etc. In the automotive field, the IDS based on CAN/CAN FD only adapts the corresponding functions of signal detection, load rate detection and the like based on a communication matrix.
With the wide application of ethernet in the automotive field, the content of traditional IDS detection is only to detect reporting attack events as analysis of cloud data operation and maintenance data, and this way cannot meet the use scenario of the existing intelligent internet-connected automobile. The IDPS development of the current automobile is still adapted based on the detection rules of the traditional internet. The threat event in the vehicle is still the main processing mode for detection and reporting. The accurate blocking function cannot be achieved at the present stage so as to ensure that the vehicle is effectively defended when the vehicle is subjected to a threat attack event.
Disclosure of Invention
In the summary, a series of concepts in a simplified form are introduced, which will be further described in detail in the detailed description. The summary of the invention is not intended to define the key features and essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.
In a first aspect, the present invention provides a vehicle safety protection control method, including:
Acquiring a target change rate request value corresponding to a current request message;
determining a target rate of change threshold based on a functional state of a target controller of the target vehicle;
Performing security analysis on the current request message based on the target change rate request value and the target change rate threshold value;
and controlling the target vehicle based on the safety analysis result and the target change rate request value.
Optionally, the method further comprises:
determining a corresponding target controller based on the current request message;
acquiring a history request message of the target controller;
and acquiring the functional state of the target controller based on the history request message.
Optionally, the method further comprises:
And detecting the validity of the third party application corresponding to the current request message.
Optionally, the determining the target change rate threshold based on the functional state of the target controller of the target vehicle includes:
And determining the target change rate threshold based on the dependency relationship between each function under the condition that the target controller simultaneously corresponds to a plurality of different functions.
Optionally, in the case that the target controller corresponds to a plurality of different functions at the same time, determining the target change rate threshold based on a dependency relationship between each function includes:
Under the condition that the target controller is a vehicle speed controller and the target vehicle simultaneously starts the self-adaptive cruise function and the road borrowing overtaking function, a first steering rate threshold value corresponding to the self-adaptive cruise function is obtained;
acquiring a second steering rate threshold corresponding to the road-borrowing overtaking function;
acquiring road condition information of the current position of a target vehicle;
and determining a target change rate threshold corresponding to the vehicle speed controller based on the first steering rate threshold, the second steering rate threshold and the road condition information.
Optionally, the determining the target change rate threshold based on the functional state of the target controller of the target vehicle includes:
And determining a corresponding target change rate threshold value of the target controller under the current functional state based on the detection rule policy database of the target vehicle.
Optionally, the controlling the target vehicle based on the security analysis result and the target change rate request value includes:
controlling the target controller to exit the current function under the condition that the safety analysis result is a dangerous result;
The current request message is sent to a server side, so that the server side executes security check and upgrades the detection rule policy database;
Or alternatively, the first and second heat exchangers may be,
And controlling the target controller to execute corresponding operation based on the target change rate request value under the condition that the safety analysis result is a safety result.
In a second aspect, the present invention also proposes a vehicle safety protection control device, including:
The acquisition unit is used for acquiring a target change rate request value corresponding to the current request message;
A determining unit configured to determine a target change rate threshold value based on a functional state of a target controller of a target vehicle;
The analysis unit is used for carrying out safety analysis on the current request message based on the target change rate request value and the target change rate threshold value;
And a control unit configured to control the target vehicle based on the safety analysis result and the target change rate request value.
In a third aspect, an electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, the processor being configured to implement the steps of the vehicle safety protection control method according to any one of the first aspects when executing the computer program stored in the memory.
In a fourth aspect, the present invention also proposes a computer-readable storage medium, on which a computer program is stored, which computer program, when executed by a processor, implements the vehicle safety protection control method of any one of the first aspects.
In summary, the vehicle safety protection control method of the embodiment of the application comprises the steps of obtaining a target change rate request value corresponding to a current request message, determining a target change rate threshold value based on the functional state of a target controller of a target vehicle, carrying out safety analysis on the current request message based on the target change rate request value and the target change rate threshold value, and controlling the target vehicle based on the safety analysis result and the target change rate request value. According to the vehicle safety protection method provided by the embodiment of the application, under the condition that the request message applied by the third party reaches the network of the vehicle end, the corresponding target change rate threshold value is determined according to the functional state of the target controller of the target vehicle, the validity of the target change rate request value corresponding to the current request message is judged based on the target change rate threshold value, the request message exceeding the target change rate threshold value is abandoned in time, the vehicle is prevented from executing the operation which does not accord with the current function, and the safety and stability of the vehicle are improved.
Additional advantages, objects, and features of the invention will be set forth in part in the description which follows and in part will become apparent to those having ordinary skill in the art upon examination of the following or may be learned from practice of the invention.
Drawings
Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The drawings are only for purposes of illustrating the preferred embodiments and are not to be construed as limiting the specification. Also, like reference numerals are used to designate like parts throughout the figures. In the drawings:
FIG. 1 is a schematic flow chart of a vehicle safety protection control method according to an embodiment of the present application;
fig. 2 is a schematic structural diagram of a vehicle safety protection control device according to an embodiment of the present application;
fig. 3 is a schematic structural diagram of a vehicle safety protection control electronic device according to an embodiment of the present application.
Detailed Description
According to the vehicle safety protection method provided by the embodiment of the application, under the condition that the request message applied by the third party reaches the network of the vehicle end, the corresponding target change rate threshold value is determined according to the functional state of the target controller of the target vehicle, the validity of the request value corresponding to the current request message is judged based on the target change rate threshold value, the request message exceeding the target change rate threshold value is abandoned in time, the vehicle is prevented from executing the operation which does not accord with the current function, and the safety and stability of the vehicle are improved.
The terms "first," "second," "third," "fourth" and the like in the description and in the claims and in the above drawings, if any, are used for distinguishing between similar objects and not necessarily for describing a particular sequential or chronological order. It is to be understood that the data so used may be interchanged where appropriate such that the embodiments described herein may be implemented in other sequences than those illustrated or otherwise described herein. Furthermore, the terms "comprises," "comprising," and "having," and any variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, system, article, or apparatus that comprises a list of steps or elements is not necessarily limited to those steps or elements expressly listed but may include other steps or elements not expressly listed or inherent to such process, method, article, or apparatus. The following description of the embodiments of the present application will be made clearly and completely with reference to the accompanying drawings, in which it is apparent that the embodiments described are only some embodiments of the present application, but not all embodiments.
Referring to fig. 1, a schematic flow chart of a vehicle safety protection control method provided in an embodiment of the application may specifically include:
S110, acquiring a target change rate request value corresponding to a current request message;
For example, in some vehicles, the IDPS systems of the vehicle may be comprised of database components, message analysis components, rule configuration components, update engine components, and the like. The database component is used to store IDPS basic system configuration data, rule configuration data, configuration data of the update engine, log record data, and the like. The message analysis component is used for filtering signals in the screening vehicle and matching the generated rule database, and is used for analyzing threat events in the vehicle and recording log files. The rule configuration component is used for configuring a rule file which can be identified by the in-vehicle component, and a rule base of the in-vehicle component can be updated for repairing the in-vehicle loopholes. In order to meet the updating of the in-vehicle defense strategy, the updating engine component has networking capability, the in-vehicle updating engine component can be connected with the cloud operation and maintenance management platform, and if the cloud operation and maintenance management platform has new rule configuration data, the new rule configuration data can be acquired from the cloud.
The current request message is a message which has entered the vehicle-end network, and the target change rate request value is a specific value of an operation to be executed by the request message control target controller, for example, may be a specific value of vehicle speed acceleration, a vehicle yaw angle change rate and the like.
S120, determining a target change rate threshold value based on the functional state of a target controller of the target vehicle;
For example, each target controller may correspond to a different working value interval based on different functional states, where the value interval, i.e., the upper limit and the lower limit, are the target change rate thresholds. For example, the vehicle is executing an autopilot function, and the set target speed is 100km/h, in this functional state, the change rate threshold of the allowed running yaw angle of the vehicle is 10% -15% in consideration of the fast vehicle speed, otherwise, steering may be too severely affected to the driving feeling or the safety of the vehicle.
S130, carrying out security analysis on the current request message based on the target change rate request value and the target change rate threshold value;
For example, if the target rate of change request value falls within the target rate of change threshold, the request value is considered legal, the security of the request message is satisfactory, if the target rate of change request value exceeds the upper limit of the target rate of change threshold or is lower than the lower limit of the target rate of change threshold, the request value is considered illegal, the security of the request message is not satisfactory, and the request message is discarded.
And S140, controlling the target vehicle based on the safety analysis result and the target change rate request value.
In an exemplary case that the current request message is a legal message, a request instruction is sent to a corresponding controller based on the request value, and corresponding equipment is controlled by the controller to complete the request operation corresponding to the request message. If the current request message is an illegal message, the illegal message is directly discarded,
In summary, in the vehicle safety protection method provided by the embodiment of the application, under the condition that the request message applied by the third party reaches the network of the vehicle end, the corresponding target change rate threshold value is determined according to the functional state of the target controller of the target vehicle, the validity of the request value corresponding to the current request message is judged based on the target change rate threshold value, the request message exceeding the target change rate threshold value is abandoned in time, the vehicle is prevented from executing the operation which does not accord with the current function, and the safety and stability of the vehicle are improved.
In some examples, the above method further comprises:
determining a corresponding target controller based on the current request message;
acquiring a history request message of the target controller;
and acquiring the functional state of the target controller based on the history request message.
The method includes determining a corresponding target controller according to address information, target port information and the like corresponding to a request message, retrieving a history request message of the target controller, screening a current functional state of the target controller in the history request message, and acquiring a target change rate threshold according to the current functional state.
In summary, the vehicle safety protection control method provided by the embodiment of the application acquires the functional state of the controller based on the history message of the target controller, does not need to acquire the state of the controller based on the instruction again, is convenient and quick, and reduces the operation burden of the target controller.
In some examples, the above method further comprises:
And detecting the validity of the third party application corresponding to the current request message.
For example, before the current request message enters the network of the vehicle end, the validity of the third party application may be checked preferentially, including whether the identity of the third party application is in the white list of the vehicle corresponding to the third party application, and further including whether the request instruction sent by the third party application accords with the corresponding authority. If the third party application is illegal or the request instruction authority sent by the third party application exceeds the due authority, the current application message is directly discarded, and if the third party application is legal and the authority meets the requirements, the message is transferred to the network of the vehicle end.
In summary, the vehicle safety protection method provided by the embodiment of the application firstly screens the legitimacy and authority of the third party application sending the current request message before the current request message enters the vehicle-connected end, blocks the invasion of the illegal third party application, realizes two-stage safety protection before and in the network of the vehicle end, and improves the safety of the vehicle.
In some examples, determining the target rate of change threshold based on the functional state of the target controller of the target vehicle includes:
And determining the target change rate threshold based on the dependency relationship between each function under the condition that the target controller simultaneously corresponds to a plurality of different functions.
The method comprises the steps of enabling IDPS to be capable of effectively functioning in an automobile, enabling a detection reporting function of a threat event to be achieved, and also capable of timely and effectively preventing the threat event in the automobile from being automatically started based on function definitions of the whole automobile, combing and identifying function usage lists related to safety of the automobile, such as a steering system of a chassis domain, a wiper system of a car body domain, an automatic driving system of an intelligent driving domain, a motor system of a power domain and the like, analyzing function usage scenes, combing dependency relations among functions under actual working conditions of the whole automobile, such as functions of automatically cruising the automobile in a rainy day, combining an electronic appliance framework defined by the whole automobile and finishing interaction logic of related parties, such as that when the automobile is kept in an automatic cruising state, a rain sensor detects the rain amount, decomposing state machines among the related parties, outputting interaction signals, linking the dependency relations of the interaction signals of the related parties in the automobile, extracting context information in the dependency relations, defining a target change rate threshold under various functional states, and matching control strategies according to the target change rate threshold.
In summary, according to the vehicle protection control method provided by the embodiment of the application, the target change rate threshold values which can meet the functions are determined by combing the logic relations and the dependency relations among the functions, so that the requirements of the functions can be met when the current message request value is executed, and the safety of the vehicle is ensured.
In some examples, where the target controller corresponds to a plurality of different functions simultaneously, determining the target rate of change threshold based on a dependency relationship between each function includes:
Under the condition that the target controller is a vehicle speed controller and the target vehicle simultaneously starts the self-adaptive cruise function and the road borrowing overtaking function, a first steering rate threshold value corresponding to the self-adaptive cruise function is obtained;
acquiring a second steering rate threshold corresponding to the road-borrowing overtaking function;
acquiring road condition information of the current position of a target vehicle;
and determining a target change rate threshold corresponding to the vehicle speed controller based on the first steering rate threshold, the second steering rate threshold and the road condition information.
The target controller may be a vehicle steering controller, and the vehicle steering controller may participate in the adaptive cruise and road-borrowing overtaking functions at the same time, where the determined target change rate threshold needs to consider the maximum steering rate of the adaptive cruise, the maximum steering rate of the road-borrowing overtaking function, and road condition information, where the road condition information may be whether the current road section allows overtaking, or whether other vehicles are nearby the vehicle, for example, the maximum steering rate set by the adaptive cruise is 10% -15%, the maximum steering rate of the road-borrowing overtaking function is 12% -20, the current road section allows overtaking, and no other vehicles are in the front-rear safety range, the target change rate threshold of the steering controller is 12% -15%, and the target change rate threshold of the vehicle speed controller is kept at the maximum steering rate set by the adaptive cruise is 10% -15% when the current road section does not allow overtaking or there is vehicle interference in the front-rear. The target change rate threshold value obtained based on the method can meet the requirements of self-adaptive cruising, overtaking by road and current road conditions at the same time, and after the safety of the change rate request value of the current request message is analyzed through the target change rate threshold value, the requirements in the current functional state can be met, and the running safety of the vehicle can be effectively ensured.
In summary, according to the vehicle safety protection method provided by the embodiment of the application, the first steering rate threshold value of the self-adaptive cruise function, the second steering rate threshold value of the road-borrowing overtaking and the target change rate threshold value determined by the current road condition information can be more in line with the safety requirement of the vehicle in the current running state, and the safety analysis result of the current request message obtained based on the safety requirement is more reliable and accurate.
In some examples, determining the target rate of change threshold based on the functional state of the target controller of the target vehicle includes:
And determining a corresponding target change rate threshold value of the target controller under the current functional state based on the detection rule policy database of the target vehicle.
The cloud operation and maintenance management platform can update the detection strategy database of the vehicle high end, update the rule configuration component of the vehicle end, the message analysis component of IDPS can track the target change rate threshold value in the historical message of the target controller in real time when the vehicle uses the function under a certain working condition, call the database component to detect based on the generated target change rate threshold detection strategy, and execute the function exit from the functional scene to ensure the safety of the vehicle if the request value corresponding to the current request message is found to exceed the target change rate threshold value under a certain vehicle working condition.
In summary, according to the vehicle safety protection control method provided by the embodiment of the application, the target change rate threshold values of different controllers in different functional states are determined by setting the detection rule policy database at the vehicle end, and the database can be updated based on the cloud.
In some examples, the controlling the target vehicle based on the security analysis result and the target change rate request value includes:
controlling the target controller to exit the current function under the condition that the safety analysis result is a dangerous result;
The current request message is sent to a server side, so that the server side executes security check and upgrades the detection rule policy database;
Or alternatively, the first and second heat exchangers may be,
And controlling the target controller to execute corresponding operation based on the target change rate request value under the condition that the safety analysis result is a safety result.
After the security of the current request message is analyzed according to the target change rate threshold, if the security of the current request message meets the requirement, the target controller is controlled to control the corresponding device to execute the corresponding operation according to the request value corresponding to the request message.
If the security analysis result of the current request message is dangerous, the log of the abnormal situation is recorded in the updating engine component, the log of the abnormal situation can be automatically uploaded to the cloud operation and maintenance management platform under the condition that the network link is normal, the cloud operation and maintenance management platform can immediately inform emergency response management personnel to process after receiving the reported context abnormal log, the emergency response management personnel can immediately contact a user to inquire the relevant state of the vehicle and check the problem of the vehicle, and if the abnormal event occurs when the vehicle is attacked by an external hacker, the information security department needs to immediately check the loopholes and update IDPS relevant components of all affected vehicles in time so as to ensure the safety of the vehicle.
In summary, according to the vehicle safety protection method provided by the embodiment of the application, the safety of the current request message can be obtained by comparing the target change rate threshold value with the request value of the request message, and when the current request message is a dangerous message, the abnormal condition is reported to the server side, so that the server side can check the loophole, upgrade the detection rule policy database and improve the safety of the vehicle.
Referring to fig. 2, an embodiment of a vehicle safety protection control device according to an embodiment of the present application may include:
an obtaining unit 21, configured to obtain a target change rate request value corresponding to a current request packet;
A determining unit 22 for determining a target rate of change threshold based on a functional state of a target controller of the target vehicle;
An analysis unit 23, configured to perform security analysis on the current request packet based on the target rate of change request value and the target rate of change threshold;
and a control unit 24 for controlling the target vehicle based on the safety analysis result and the target change rate request value.
As shown in fig. 3, an embodiment of the present application further provides an electronic device 300, including a memory 310, a processor 320, and a computer program 311 stored in the memory 320 and capable of running on the processor, where the processor 320 executes the steps of any one of the methods for controlling the safety protection of a vehicle.
Since the electronic device described in this embodiment is a device for implementing the vehicle safety protection control device in this embodiment of the present application, based on the method described in this embodiment of the present application, those skilled in the art can understand the specific implementation of the electronic device in this embodiment and various modifications thereof, so how the electronic device implements the method in this embodiment of the present application will not be described in detail herein, and as long as those skilled in the art implement the device for implementing the method in this embodiment of the present application, all fall within the scope of protection of the present application.
In an implementation, the computer program 311 is executed by a processor to perform the steps of any of the methods of the first aspect.
In the foregoing embodiments, the descriptions of the embodiments are focused on, and for those portions of one embodiment that are not described in detail, reference may be made to the related descriptions of other embodiments.
It will be appreciated by those skilled in the art that embodiments of the present application may be provided as a method, system, or computer program product. Accordingly, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, and the like) having computer-usable program code embodied therein.
The present application is described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each flow and/or block of the flowchart illustrations and/or block diagrams, and combinations of flows and/or blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means which implement the function specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
Embodiments of the present application also provide a computer program product comprising computer software instructions that, when run on a processing device, cause the processing device to perform a flow of vehicle safety protection control as in the corresponding embodiment of fig. 1.
The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions in accordance with embodiments of the present application are produced in whole or in part. The computer may be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by a wired (e.g., coaxial cable, fiber optic, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). Computer readable storage media can be any available media that can be stored by a computer or data storage devices such as servers, data centers, etc. that contain an integration of one or more available media. Usable media may be magnetic media (e.g., floppy disks, hard disks, magnetic tape), optical media (e.g., DVD), or semiconductor media (e.g., solid State Disk (SSD)) or the like.
It will be clear to those skilled in the art that, for convenience and brevity of description, specific working procedures of the above-described systems, apparatuses and units may refer to corresponding procedures in the foregoing method embodiments, which are not repeated herein.
In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods may be implemented in other manners. For example, the apparatus embodiments described above are merely illustrative, e.g., the division of elements is merely a logical functional division, and there may be additional divisions of actual implementation, e.g., multiple elements or components may be combined or integrated into another system, or some features may be omitted, or not performed. Alternatively, the coupling or direct coupling or communication connection shown or discussed with each other may be an indirect coupling or communication connection via some interfaces, devices or units, which may be in electrical, mechanical or other form.
The units described as separate units may or may not be physically separate, and units shown as units may or may not be physical units, may be located in one place, or may be distributed over a plurality of network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
In addition, each functional unit in the embodiments of the present application may be integrated in one processing unit, or each unit may exist alone physically, or two or more units may be integrated in one unit. The integrated units may be implemented in hardware or in software functional units.
The integrated units, if implemented in the form of software functional units and sold or used as stand-alone products, may be stored in a computer readable storage medium. Based on such understanding, the technical solution of the present application may be embodied in essence or a part contributing to the prior art or all or part of the technical solution in the form of a software product stored in a storage medium, including several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods of the embodiments of the present application. The storage medium includes a U disk, a removable hard disk, a Read-Only Memory (ROM), a random access Memory (Random Access Memory, RAM), a magnetic disk, an optical disk, or other various media capable of storing program codes.
Although the present application has been described in detail with reference to the foregoing embodiments, it will be understood by those skilled in the art that the foregoing embodiments may be modified or equivalents may be substituted for some of the features thereof, and that the modifications or substitutions do not depart from the spirit and scope of the embodiments of the present application.

Claims (7)

Translated fromChinese
1.一种车辆安全防护控制方法,其特征在于,包括:1. A vehicle safety protection control method, characterized by comprising:获取当前请求报文对应的目标变化率请求值;Get the target change rate request value corresponding to the current request message;基于目标车辆的目标控制器的功能状态确定目标变化率阈值,包括:The target change rate threshold is determined based on the functional state of the target controller of the target vehicle, including:在所述目标控制器同时对应多种不同功能的情况下,基于每种功能之间的依赖关系确定所述目标变化率阈值,包括:In the case where the target controller corresponds to multiple different functions at the same time, determining the target change rate threshold based on the dependency relationship between each function includes:在所述目标控制器为车速控制器且所述目标车辆同时开启自适应巡航与借道超车功能的情况下,获取所述自适应巡航功能对应的第一转向率阈值;When the target controller is a vehicle speed controller and the target vehicle turns on both the adaptive cruise control and lane-crossing overtaking functions, obtaining a first turning rate threshold corresponding to the adaptive cruise control function;获取所述借道超车功能对应的第二转向率阈值;Obtaining a second turning rate threshold corresponding to the lane-crossing overtaking function;获取目标车辆当前位置的路况信息;Obtain the road condition information of the target vehicle's current location;基于所述第一转向率阈值、所述第二转向率阈值和所述路况信息确定所述车速控制器对应的目标变化率阈值;determining a target change rate threshold corresponding to the vehicle speed controller based on the first turning rate threshold, the second turning rate threshold and the road condition information;基于所述目标变化率请求值和所述目标变化率阈值对所述当前请求报文进行安全分析,得到安全分析结果;Performing a security analysis on the current request message based on the target change rate request value and the target change rate threshold to obtain a security analysis result;基于所述安全分析结果和所述目标变化率请求值控制所述目标车辆;controlling the target vehicle based on the safety analysis result and the target change rate request value;还包括:Also includes:基于所述当前请求报文确定对应的目标控制器;Determine a corresponding target controller based on the current request message;获取所述目标控制器的历史请求报文;Obtaining historical request messages of the target controller;基于所述历史请求报文获取所述目标控制器的功能状态。The functional status of the target controller is obtained based on the historical request message.2.如权利要求1所述的方法,其特征在于,还包括:2. The method according to claim 1, further comprising:检测所述当前请求报文对应的第三方应用的合法性。Detect the legitimacy of the third-party application corresponding to the current request message.3.如权利要求1所述的方法,其特征在于,所述基于目标车辆的目标控制器的功能状态确定目标变化率阈值,包括:3. The method according to claim 1, characterized in that the determining the target change rate threshold value based on the functional state of the target controller of the target vehicle comprises:基于所述目标车辆的检测规则策略数据库确定目标控制器在当前功能状态下对应的目标变化率阈值。A target change rate threshold corresponding to the target controller in the current functional state is determined based on the detection rule strategy database of the target vehicle.4.如权利要求3所述的方法,其特征在于,所述基于所述安全分析结果和所述目标变化率请求值控制所述目标车辆,包括:4. The method according to claim 3, wherein the controlling the target vehicle based on the safety analysis result and the target change rate request value comprises:在所述安全分析结果为危险结果的情况下,控制所述目标控制器退出当前功能;When the safety analysis result is a dangerous result, controlling the target controller to exit the current function;向服务器端发送所述当前请求报文,以使所述服务器端执行安全排查并升级所述检测规则策略数据库;Sending the current request message to the server side so that the server side performs a security check and updates the detection rule policy database;或,or,在所述安全分析结果为安全结果的情况下,基于所述目标变化率请求值控制目标控制器执行对应操作。In a case where the safety analysis result is a safety result, the target controller is controlled to perform a corresponding operation based on the target change rate request value.5.一种车辆安全防护控制装置,其特征在于,包括:5. A vehicle safety protection control device, characterized in that it comprises:获取单元,用于获取当前请求报文对应的目标变化率请求值;An acquisition unit, used to acquire a target change rate request value corresponding to a current request message;确定单元,用于基于目标车辆的目标控制器的功能状态确定目标变化率阈值,包括:A determination unit, configured to determine a target change rate threshold value based on a functional state of a target controller of a target vehicle, comprising:在所述目标控制器同时对应多种不同功能的情况下,基于每种功能之间的依赖关系确定所述目标变化率阈值,包括:In the case where the target controller corresponds to multiple different functions at the same time, determining the target change rate threshold based on the dependency relationship between each function includes:在所述目标控制器为车速控制器且所述目标车辆同时开启自适应巡航与借道超车功能的情况下,获取所述自适应巡航功能对应的第一转向率阈值;When the target controller is a vehicle speed controller and the target vehicle turns on both the adaptive cruise control and lane-crossing overtaking functions, obtaining a first turning rate threshold corresponding to the adaptive cruise control function;获取所述借道超车功能对应的第二转向率阈值;Obtaining a second turning rate threshold corresponding to the lane-crossing overtaking function;获取目标车辆当前位置的路况信息;Obtain the road condition information of the current location of the target vehicle;基于所述第一转向率阈值、所述第二转向率阈值和所述路况信息确定所述车速控制器对应的目标变化率阈值;determining a target change rate threshold corresponding to the vehicle speed controller based on the first turning rate threshold, the second turning rate threshold and the road condition information;分析单元,用于基于所述目标变化率请求值和所述目标变化率阈值对所述当前请求报文进行安全分析,得到安全分析结果;an analyzing unit, configured to perform a security analysis on the current request message based on the target change rate request value and the target change rate threshold, to obtain a security analysis result;控制单元,用于基于所述安全分析结果和所述目标变化率请求值控制所述目标车辆;a control unit, configured to control the target vehicle based on the safety analysis result and the target change rate request value;还包括:Also includes:基于所述当前请求报文确定对应的目标控制器;Determine a corresponding target controller based on the current request message;获取所述目标控制器的历史请求报文;Obtaining historical request messages of the target controller;基于所述历史请求报文获取所述目标控制器的功能状态。The functional status of the target controller is obtained based on the historical request message.6.一种电子设备,包括:存储器和处理器,其特征在于,所述处理器用于执行存储器中存储的计算机程序时实现如权利要求1-4中任一项所述的车辆安全防护控制方法的步骤。6. An electronic device, comprising: a memory and a processor, wherein the processor is used to implement the steps of the vehicle safety protection control method according to any one of claims 1 to 4 when executing a computer program stored in the memory.7.一种计算机可读存储介质,其上存储有计算机程序,其特征在于:所述计算机程序被处理器执行时实现如权利要求1-4中任一项所述的车辆安全防护控制方法。7. A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the vehicle safety protection control method according to any one of claims 1 to 4.
CN202210849977.5A2022-07-192022-07-19 Vehicle safety protection control method and related equipmentActiveCN115412571B (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN202210849977.5ACN115412571B (en)2022-07-192022-07-19 Vehicle safety protection control method and related equipment

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN202210849977.5ACN115412571B (en)2022-07-192022-07-19 Vehicle safety protection control method and related equipment

Publications (2)

Publication NumberPublication Date
CN115412571A CN115412571A (en)2022-11-29
CN115412571Btrue CN115412571B (en)2025-06-10

Family

ID=84156729

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN202210849977.5AActiveCN115412571B (en)2022-07-192022-07-19 Vehicle safety protection control method and related equipment

Country Status (1)

CountryLink
CN (1)CN115412571B (en)

Citations (2)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN106094830A (en)*2016-07-112016-11-09百度在线网络技术(北京)有限公司For the method and apparatus controlling automatic driving vehicle
CN113562065A (en)*2021-07-152021-10-29东风汽车集团股份有限公司Control method and device for preventing data abnormality of electric power steering controller

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2018008452A1 (en)*2016-07-052018-01-11パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカMethod for inhibiting unauthorized control, device for inhibiting unauthorized control, and vehicle-mounted network system
US10332320B2 (en)*2017-04-172019-06-25Intel CorporationAutonomous vehicle advanced sensing and response
JP7033499B2 (en)*2017-07-262022-03-10パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ Anomaly detection device and anomaly detection method
DE102019004265B4 (en)*2018-11-092025-10-09obsurver UG (haftungsbeschränkt) Method for a driver assistance function for situation-appropriate warning of a vehicle driver and/or for situation-appropriate automatic intervention in the vehicle longitudinal guidance
CN111726774B (en)*2020-06-282023-09-05阿波罗智联(北京)科技有限公司Method, device, equipment and storage medium for defending attack
CN114338073A (en)*2021-11-092022-04-12江铃汽车股份有限公司Protection method, system, storage medium and equipment for vehicle-mounted network

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN106094830A (en)*2016-07-112016-11-09百度在线网络技术(北京)有限公司For the method and apparatus controlling automatic driving vehicle
CN113562065A (en)*2021-07-152021-10-29东风汽车集团股份有限公司Control method and device for preventing data abnormality of electric power steering controller

Also Published As

Publication numberPublication date
CN115412571A (en)2022-11-29

Similar Documents

PublicationPublication DateTitle
US11748474B2 (en)Security system and methods for identification of in-vehicle attack originator
JP6574535B2 (en) Global car safety system
CN110226310B (en) Electronic control device, fraud detection server, in-vehicle network system, in-vehicle network monitoring system and method
US10986093B2 (en)Monitoring device, monitoring method, and computer program
US20190182267A1 (en)Vehicle security manager
JP6846706B2 (en) Monitoring equipment, monitoring methods and computer programs
JP6807906B2 (en) Systems and methods to generate rules to prevent computer attacks on vehicles
JP7665640B2 (en) System for detecting intrusions into in-vehicle networks and method of implementing same - Patents.com
CN111225834B (en)Vehicle control device
US11368471B2 (en)Security gateway for autonomous or connected vehicles
KR102524204B1 (en)Apparatus and method for intrusion response in vehicle network
CN111466107A (en)Ethernet profiling intrusion detection control logic and architecture for in-vehicle controllers
CN110505134B (en)Internet of vehicles CAN bus data detection method and device
JPWO2019216306A1 (en) Anomaly detection electronic control unit, in-vehicle network system and anomaly detection method
JP6782444B2 (en) Monitoring equipment, monitoring methods and computer programs
WO2021145144A1 (en)Intrusion-path analyzing device and intrusion-path analyzing method
WO2017024078A1 (en)A method for detecting, blocking and reporting cyber-attacks against automotive electronic control units
US20220247772A1 (en)Attack monitoring center apparatus and attack monitoring terminal apparatus
JP7241281B2 (en) Information processing device, control method and program
Ring et al.Survey on vehicular attacks-building a vulnerability database
CN115396141B (en) Vehicle safety control method, device, equipment and medium
JP2021140460A (en)Security management apparatus
CN118355383A (en) Threat information expansion system, threat information expansion method and program
CN115412571B (en) Vehicle safety protection control method and related equipment
US20150113125A1 (en)System and Method for Providing the Status of Safety Critical Systems to Untrusted Devices

Legal Events

DateCodeTitleDescription
PB01Publication
PB01Publication
SE01Entry into force of request for substantive examination
SE01Entry into force of request for substantive examination
GR01Patent grant
GR01Patent grant

[8]ページ先頭

©2009-2025 Movatter.jp