An intelligent automobile anti-theft alarm device

Through intelligent car anti-theft alarm devices, using comprehensive analysis of cameras, vibration sensors and millimeter-wave radars, dynamically adjusting verification difficulty and data encryption, and combining neural network and blockchain technology, the problem that existing systems are unable to defend against remote intrusion and covert camouflage is solved, and efficient anti-theft and low false alarms are achieved in complex environments.

CN120552791BActive Publication Date: 2025-09-30BEIJING CHEXIAO TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511079656.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-09-30
Estimated Expiration
2045-08-04

AI Technical Summary

Technical Problem

Existing anti-theft alarm systems cannot effectively defend against remote intrusion methods and covert camouflage behaviors, and have a high false alarm rate in complex environments.

Method used

It uses an intelligent car anti-theft alarm device, combined with cameras, vibration sensors and millimeter-wave radar for comprehensive analysis, dynamically adjusts the verification difficulty and data encryption strength, identifies and repairs tampering logic through the patrol and inspection module, uses neural networks to analyze multi-person collaborative attacks, and records the logic history on the blockchain to ensure security.

Benefits of technology

Reduce false alarm rates in complex environments, effectively identify and prevent various attack methods, form a comprehensive protection system, and ensure security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120552791B_ABST
    Figure CN120552791B_ABST
Patent Text Reader

Abstract

The present invention relates to an intelligent automobile anti-theft alarm device applied to the field of automobile anti-theft, including an anti-theft system installed in a vehicle and a car owner App connected to the anti-theft system through cloud technology, including a signal acquisition module for collecting data on the environment in which the vehicle is located to assist in determining whether the vehicle is in a stolen state; a privacy recording module for recording the security and privacy information of the vehicle; an anti-theft protection module; an alarm output module for providing alarm prompts and assisting in verifying the anti-theft state; and a patrol and inspection module. In the above-mentioned intelligent automobile anti-theft alarm device, this anti-theft system reduces the false alarm rate in complex environments such as downtown areas, and can cope with various attack methods at the same time. The modules are intelligently linked to form a comprehensive protection system, which ensures both safety and ease of use.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an automobile anti-theft alarm device, in particular to an intelligent automobile anti-theft alarm device applied in the field of automobile anti-theft. Background Art

[0002] Currently, most vehicles are equipped with advanced sensors, controllers, actuators and other devices, and use new technologies such as information communication, the Internet, big data, cloud computing, and artificial intelligence to improve vehicle control and driving capabilities and ensure safe, smooth, and efficient vehicle travel.

[0003] Chinese invention patent CN112896096B discloses a car anti-theft alarm method, device and terminal, which utilizes the strong anti-interference ability of radar signals to avoid false triggering caused by environmental changes, and the anti-theft effect is accurate and reliable. In addition, Chinese patent CN116872885B discloses an intelligent car anti-theft method, system and storage medium, which can analyze and judge the anti-theft status and theft status. After entering the anti-theft status, if there is a theft behavior, active theft alarm and collaborative auxiliary alarm will be issued. When entering the theft status, safe parking and alarm will be performed, thereby providing a more rigorous and effective intelligent anti-theft technology for the car.

[0004] Existing anti-theft alarm systems primarily target physical theft attempts (such as breaking windows and picking locks), but are unable to effectively protect against thefts carried out through remote intrusion (such as cracking the vehicle's system). This weakens the anti-theft performance of the anti-theft system. Furthermore, during routine patrol operations, the vehicle's anti-theft system often cannot effectively detect concealed camouflage. Summary of the Invention

[0005] In view of the above-mentioned existing technologies, the technical problem to be solved by the present invention is how to effectively identify and prevent covert intrusions into automobile anti-theft systems through dynamic intelligent patrols and multi-dimensional protection mechanisms, while reducing the false alarm rate in complex environments.

[0006] To solve the above problems, the present invention provides an intelligent car anti-theft alarm device, comprising an anti-theft system installed in the vehicle and a car owner app connected to the anti-theft system via cloud technology, including a signal acquisition module for collecting data on the vehicle's environment to assist in determining whether the vehicle is in a stolen state;

[0007] Privacy recording module, used to record the vehicle's security and privacy information;

[0008] The anti-theft protection module includes a security verification unit, a dynamic switching unit, and an anti-theft processing unit. The security verification unit is used to perform security verification operations. The dynamic switching unit works in conjunction with the signal acquisition module to switch the verification difficulty of the vehicle's security verification unit. The anti-theft processing unit cooperates with the dynamic switching unit to adjust the encryption level of the privacy recording module for privacy data and adjust the operating frequency of the patrol module.

[0009] Alarm output module, used for alarm prompts and auxiliary verification of anti-theft status;

[0010] The patrol and inspection module is executed in a trusted execution environment and includes a patrol unit for regularly checking whether the operating logic of each module in the vehicle anti-theft system is normal, a behavior analysis unit that monitors the call chain of legal instructions in the anti-theft system and detects abnormal instructions, a data verification unit that adds protective noise to the data of the privacy recording module, a security protection unit that masks the content of instructions inside the anti-theft system through randomization operations, a correction unit that corrects tampered operating logic, and a mark-clearing unit that marks and clears identified illegal operations and attackers.

[0011] In the above-mentioned intelligent car anti-theft alarm device, this anti-theft system reduces the false alarm rate in complex environments such as downtown areas, and can also cope with various attack methods. The modules are intelligently linked to form a comprehensive protection system, which ensures both safety and ease of use.

[0012] As a further supplement to this application, the signal acquisition module includes a camera, a vibration sensor and a millimeter-wave radar installed in the vehicle, wherein the camera is used to collect environmental data inside and outside the vehicle, the vibration sensor is used to record the vibration condition of the vehicle body while the vehicle is parked, and the millimeter-wave radar is used to stably obtain the situation of objects around the vehicle. The data from the camera, vibration sensor and millimeter-wave radar are combined for comprehensive analysis to determine whether the vehicle is in a stolen state. If so, an alarm is issued through the alarm output module.

[0013] As a further supplement to the present application, the alarm output module includes an alarm prompt unit, a verification unit and an auxiliary unit, wherein the alarm prompt unit is used to perform an alarm prompt operation when the security verification unit fails, the verification unit is used to determine whether the alarm prompt unit can work normally, and when the alarm prompt unit is attacked, the auxiliary unit sends a signal to the dynamic switching unit to cooperate in dynamic switching, wherein the types of attacks encountered by the alarm prompt unit include physical attacks and operational logic attacks.

[0014] As a further supplement to this application, the patrol and inspection module also includes an experimental unit for sending experimental instructions. The working steps of the patrol and inspection module are as follows:

[0015] S1, the inspection unit checks whether the operating logic of each module has been changed at the set frequency. If there is a change, it enters S5. If there is no change, it enters S2;

[0016] S2. Check whether there is any other backup logic that can be switched in the unit where the current logic is located. If there is no other backup logic, check whether the current running logic has been modified. If there is no modification, the process ends. If there is, the process goes to S5. If there is other backup logic, the process goes to S3.

[0017] S3: Use the experimental unit to test the switching paths of other backup logic. If it is found that other backup logic is maliciously exploited, proceed to S6. If the switching is normal, end this inspection;

[0018] S4: The behavior analysis unit monitors the matching of the vehicle status and the command, and whether the command call frequency is abnormal. At the same time, the data verification unit checks whether the sensor data is abnormal. If any of the matching of the vehicle status and the command, the command call frequency, or the sensor data is abnormal, it is determined that a covert attack has occurred in the anti-theft system, and the process proceeds to S5. If the detection results of both the behavior analysis unit and the data verification unit are normal, the process ends.

[0019] S5. The correction unit repairs the tampered operation logic, and the security protection unit initiates a randomization operation on the access objects affected by the tampering.

[0020] S6. The mark clearing unit locates the access object of the covert attack, performs clearing processing, and checks whether the access channel of the access object is allowed to exist. If it is not allowed to exist, the channel is closed.

[0021] As a further supplement to the present application, the patrol module also includes a stripping unit, which removes the camouflage layer of the access object in the anti-theft system, so that the operating logic in the anti-theft protection module and the alarm output module are exposed. In addition, the stripping unit is also used to expose the characteristic data of the illegally accessed object, record it to the privacy recording module, generate a characteristic database, and cooperate with the security verification unit to prevent subsequent security verification.

[0022] As a further supplement to this application, the working steps when the dynamic switching unit is combined with the signal acquisition module are as follows:

[0023] A1. Build a diagram of the interaction between people, equipment, and vehicles using onboard cameras and millimeter-wave radar.

[0024] A2. Use a neural network to analyze the interaction relationship. If it is detected that the behavior of multiple people meets the predefined attack collaboration purpose, the dynamic switching unit and the anti-theft processing unit are activated.

[0025] As a further supplement to this application, the data recorded by the privacy recording module includes the vehicle's driving records, door opening and closing records, data from the signal acquisition module, and the vehicle's operation log, among which the sensor data includes monitoring data of other sensors including vibration sensors installed on the vehicle, and other sensors include ultrasonic sensors, tilt sensors, door and trunk sensors, tire pressure sensors, glass breakage sensors, and acoustic sensors.

[0026] As a further supplement to this application, the patrol and inspection module also includes a logic history tracing unit, which is used to record the modification history of the operating logic and store it in the blockchain. The patrol unit synchronously compares the historical version consistency when checking the logic. The behavior analysis unit monitors the behavior change trend after the logic is modified through a time series model. If it is detected that the modified operating logic has an abnormality after delayed operation, the correction unit is triggered.

[0027] In summary, the signal acquisition module integrates data from cameras, vibration sensors, and millimeter-wave radar to accurately identify vehicle theft. The anti-theft protection module dynamically adjusts verification difficulty, data encryption strength, and patrol frequency to adapt to different environments. The patrol and inspection module operates within a protected environment, effectively identifying and repairing tampered operating logic and eliminating malicious attacks. The dynamic switching unit can identify multi-person collaborative attack patterns and automatically enhance protection levels. The privacy recording module fully preserves vehicle operation logs, providing a basis for security analysis. Furthermore, the logic history traceability function records all modifications and stores them in a tamper-proof blockchain. Even if an attacker makes non-compliant modifications, they can be detected through behavioral trend analysis. Compared to traditional solutions, this anti-theft system reduces false alarm rates in complex environments such as downtown areas and can defend against various attack methods, including covert intrusions that do not modify the operating logic. The intelligent linkage between the modules forms a comprehensive protection system that ensures both security and user-friendliness. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 This is a schematic diagram of the system composition of this application;

[0029] Figure 2 This is the workflow diagram of the patrol and inspection module of this application. DETAILED DESCRIPTION

[0030] Two implementation modes of the present application are described in detail below with reference to the accompanying drawings.

[0031] The first implementation method:

[0032] Figure 1An intelligent car anti-theft alarm device is shown, comprising an anti-theft system installed in the vehicle and a car owner app connected to the anti-theft system via cloud technology. The device also includes a signal acquisition module for collecting data about the vehicle's environment to assist in determining whether the vehicle is stolen.

[0033] Privacy recording module, used to record the security and privacy information of the vehicle;

[0034] The anti-theft protection module includes a security verification unit, a dynamic switching unit, and an anti-theft processing unit. The security verification unit is used to perform security verification operations. The dynamic switching unit works in conjunction with the signal acquisition module to switch the verification difficulty of the vehicle's security verification unit. The anti-theft processing unit cooperates with the dynamic switching unit to adjust the encryption level of the privacy recording module for privacy data and adjust the operating frequency of the patrol module.

[0035] Alarm output module, used for alarm prompts and auxiliary verification of anti-theft status;

[0036] The patrol and inspection module is executed in a trusted execution environment and includes a patrol unit for regularly checking whether the operating logic of each module in the vehicle anti-theft system is normal, a behavior analysis unit that monitors the call chain of legal instructions in the anti-theft system and detects abnormal instructions, a data verification unit that adds protective noise to the data of the privacy recording module, a security protection unit that masks the content of instructions inside the anti-theft system through randomization operations, a correction unit that corrects tampered operating logic, and a mark-clearing unit that marks and clears identified illegal operations and attackers.

[0037] The signal acquisition module includes a camera, a vibration sensor, and a millimeter-wave radar installed in the vehicle. The camera is used to collect environmental data inside and outside the vehicle, the vibration sensor is used to record the vibration condition of the vehicle body when the vehicle is parked, and the millimeter-wave radar is used to stably obtain the situation of objects around the vehicle. Combining the data from the camera, vibration sensor, and millimeter-wave radar, a comprehensive analysis is performed to determine whether the vehicle is in a stolen state. If so, an alarm is issued through the alarm output module.

[0038] The alarm output module includes an alarm prompt unit, a verification unit and an auxiliary unit. The alarm prompt unit is used to perform an alarm prompt operation when the security verification unit fails. The verification unit is used to determine whether the alarm prompt unit can work normally. When the alarm prompt unit is attacked, the auxiliary unit sends a signal to the dynamic switching unit to cooperate in dynamic switching. The types of attacks encountered by the alarm prompt unit include physical attacks and operational logic attacks.

[0039] Figure 2 As shown, the patrol and inspection module also includes an experimental unit for sending experimental instructions. The working steps of the patrol and inspection module are as follows:

[0040] S1, the inspection unit checks whether the operating logic of each module has been changed at the set frequency. If there is a change, it enters S5. If there is no change, it enters S2;

[0041] S2. Check whether there is any other backup logic that can be switched in the unit where the current logic is located. If there is no other backup logic, check whether the current running logic has been modified. If there is no modification, the process ends. If there is, the process goes to S5. If there is other backup logic, the process goes to S3.

[0042] S3: Use the experimental unit to test the switching paths of other backup logic. If it is found that other backup logic is maliciously exploited, proceed to S6. If the switching is normal, end this inspection;

[0043] S4: The behavior analysis unit monitors the matching of the vehicle status and the command, and whether the command call frequency is abnormal. At the same time, the data verification unit checks whether the sensor data is abnormal. If any of the matching of the vehicle status and the command, the command call frequency, or the sensor data is abnormal, it is determined that a covert attack has occurred in the anti-theft system, and the process proceeds to S5. If the detection results of both the behavior analysis unit and the data verification unit are normal, the process ends.

[0044] S5. The correction unit repairs the tampered operation logic, and the security protection unit initiates a randomization operation on the access objects affected by the tampering.

[0045] S6. The mark clearing unit locates the access object of the covert attack, performs clearing processing, and checks whether the access channel of the access object is allowed to exist. If it is not allowed to exist, the channel is closed.

[0046] Specifically, during the inspection, the inspection module is in a trusted execution environment, and its own logic maintains a high degree of stability. It checks whether there are any changes to the current operating logic. If there are any changes, the correction unit will modify the changed operating logic and mark and destroy the access object that tampers with the operating logic (when tampering with the key parameters of the operating logic, the access object that implements the tampering behavior will carry the marking characteristics carried by the operating logic itself, thereby facilitating the subsequent mark clearing unit to locate and destroy it). For example:

[0047] If the operating logic of the security verification unit is modified, the access object will modify the current operating logic to facilitate the access object to evade verification and pretend to pass verification;

[0048] If the operating logic of the alarm prompt unit is modified, the alarm signal issued without passing the verification will not be triggered;

[0049] If the operating logic of the verification unit is modified, the alarm prompt unit is damaged but the verification unit tests whether it can work normally, the answer is yes.

[0050] Since the number of operating logics in each unit is uncertain, if an illegal access object enters the system, it does not directly modify the current operating logic (for modification of key parameters, for example, the threshold is 60 to pass verification, but it can pass verification by changing it to 40), but instead uses multi-level jumps to switch the operating logic that is finally executed (in S3, if it is found that the backup logic is maliciously used, such as hiding the attack through multi-level jumps), thereby avoiding the offensive access object from being directly discovered. At this time, the mark clearing unit cannot find the offensive access object. Therefore, during the inspection, it is necessary to use the experimental unit to issue experimental instructions to find the operating logic that is finally executed and destroy it (because the current operating logic is executed under normal conditions, and jump execution is an unnecessary and cumbersome abnormal behavior), preventing external operating logic from tampering with the operating logic of each unit in this anti-theft system, and thus playing a corresponding patrol and inspection role.

[0051] In addition, after some aggressive access objects enter the system, they do not change the operating logic or execute through jumps, but use other hidden means to implement corresponding intrusion processing, causing the patrol and inspection module to fail. This includes malicious code that only exists in memory and does not modify the storage logic, or injects forged feature data into the privacy recording module to mislead security verification.

[0052] In response to the above phenomenon, through the cooperation of the behavior analysis unit, data verification unit and security protection unit, protection against corresponding covert attack methods can be achieved.

[0053] In S4, the behavior analysis unit monitors the matching between the vehicle state and the command, and whether the command calling frequency is abnormal, and then detects abnormal behavior, such as starting the engine immediately after the door unlock command, thus detecting abnormal behavior and starting the engine directly without unlocking the door;

[0054] The data verification unit adds protective noise (Laplace noise, with the noise level dynamically adjusted based on the scenario, increasing by 20% in downtown areas) to key data recorded by the system, such as sensor data and user operation logs. This prevents hackers from forging data to deceive the anti-theft system and further verifies the authenticity of sensor data, such as vibration data, which has been tampered with.

[0055] The security protection unit masks internal system activities through randomized operations (such as changing the inspection frequency at irregular intervals), preventing hackers from stealing information through physical signals such as power consumption, and thus reversing information such as security keys.

[0056] In summary, the patrol and inspection module can cover multi-dimensional attacks such as logical tampering, abnormal behavior, data forgery, physical eavesdropping, etc. to provide patrol protection and enhance anti-theft security.

[0057] The patrol and inspection module also includes a stripping unit, which removes the camouflage layer of the access object in the anti-theft system, so that the operating logic in the anti-theft system is exposed. In addition, the stripping unit is also used to expose the characteristic data of the illegally accessed object, record it to the privacy recording module, generate a characteristic database, and cooperate with the security verification unit to prevent subsequent security verification.

[0058] Specifically, through the stripping unit, all access objects in the anti-theft system can be put in a non-concealed state (the camouflage layer is used to cover and hide, and after being stripped off by the stripping unit, all access objects can be exposed), ensuring that the patrol unit can fully detect all access objects to avoid omissions (if the access object that enters illegally enters the system and carries a new hidden state and the operating logic used to replace it, the patrol unit can discover it and will not miss it).

[0059] The camouflage layer exposed after stripping is marked with features, and while generating a feature database, subsequent access objects carrying the same feature mark are prevented from passing security verification.

[0060] The working steps when the dynamic switching unit is combined with the signal acquisition module are as follows:

[0061] A1. Build a diagram of the interaction between people, equipment, and vehicles using onboard cameras and millimeter-wave radar.

[0062] A2. Use a neural network to analyze the interaction relationship. If it is detected that the behavior of multiple people meets the predefined attack collaboration purpose, the dynamic switching unit and the anti-theft processing unit are activated.

[0063] Specifically, the dynamic switching unit utilizes a three-layer graph convolutional network (GCN) neural network. The input layer receives an interaction graph generated by the camera and millimeter-wave radar. Nodes in the graph contain person coordinates, device IDs, and vehicle locations, and edge weights are calculated based on signal interaction strength. Training data comes from 1,000 sets of annotated scenes provided by partner automakers. Feature extraction encompasses spatial distance, motion synchronization, and node centrality. If the model outputs an attack probability of at least 0.8, the protection mechanism is activated.

[0064] If an intruder damages the alarm prompt unit by destroying the alarm output terminal, the alarm will not be triggered even if the verification fails. Therefore, it is necessary to verify whether the alarm prompt unit can work normally, and use the auxiliary unit to perform corresponding prompt operations on the dynamic switching unit.

[0065] The dynamic switching unit is mainly used to perform targeted anti-theft operations according to the different environments in which the vehicle is located. In downtown areas, there may be a collaborative approach of multiple people to interfere with the vehicle in different ways, thereby cooperating with remote-controlled intruders to invade the vehicle's anti-theft system. For example, in a short period of time, blocking the on-board camera, causing vibration to the vehicle itself, and interfering with the signals around the vehicle occur in sequence (the predefined attack collaboration purpose is set to this, and targeted design can also be made according to actual conditions). At this time, there is the possibility of multi-person collaboration, which can increase the verification difficulty of the security verification unit, increase the encryption level of the privacy recording module, and increase the patrol frequency of the patrol and inspection module to do a good job of prevention.

[0066] Compared with traditional technologies, which use rules such as the remoteness of the vehicle environment (the possibility of theft is low in downtown areas, and the possibility of theft is high in remote areas) and time periods (the possibility of theft is high at night, and the possibility of theft is low during the day), in real life, it is easier to play a masking role during the day or in downtown areas where there are dense human activities. Therefore, this system comprehensively considers human behavior and performs dynamic switching to be more in line with real life.

[0067] High false alarm rates in downtown areas, such as when pedestrians accidentally pass by, can be avoided by adjusting the predefined attack collaboration purpose. Therefore, a single accidental occlusion or vibration in the construction environment will not trigger the corresponding dynamic switching operation. Multiple types of operations must all occur within the specified time, so the false alarm rate can be controlled.

[0068] The data recorded by the privacy recording module includes the vehicle's driving records, door opening and closing records, data from the signal acquisition module, and the vehicle's operation log. The sensor data includes monitoring data from other sensors including vibration sensors installed on the vehicle, and other sensors include ultrasonic sensors, tilt sensors, door and trunk sensors, tire pressure sensors, glass breakage sensors, and acoustic sensors.

[0069] Second implementation method:

[0070] The inspection and supervision module also includes a logic history tracing unit, which is used to record the modification history of the operating logic and store it in the blockchain. The inspection unit synchronously compares the consistency of historical versions when checking the logic. The behavior analysis unit monitors the behavior change trend after the logic is modified through a time series model. If it is detected that the modified operating logic has an abnormality after delayed operation, the correction unit will be triggered.

[0071] Unlike the first embodiment, in the first embodiment, the patrol and inspection module can be used to patrol and protect against multi-dimensional attacks such as logic tampering, behavioral anomalies, data forgery, physical eavesdropping, etc. However, if the aggressive access object enters the anti-theft system through the alarm terminal and does not perform the above-mentioned behaviors, the compliance modifications (such as modifications of non-critical parameters) will not be marked. Therefore, the patrol unit cannot detect this aggressive access object, but in the subsequent delayed execution or conditional triggering, the originally normal logic will be mistakenly judged as an abnormality and destroyed.

[0072] For example, an aggressive access target modifies the door lock control logic from the original "automatic locking when the vehicle speed exceeds 30km / h" to "automatic locking when the vehicle speed exceeds 30km / h and the system time is later than x year x month x day". In this case, before x year x month x day, the door lock will not be locked normally when the vehicle speed exceeds 30km / h, but after x year x month x day, the door lock will be locked when the speed exceeds 30km / h. In this way, before the time node, it is difficult for maintenance personnel to find the abnormality during inspection. The attacker can accurately control the time range of the dangerous period, and the inspection unit can destroy the normal logic of automatic locking when the vehicle speed exceeds 30km / h before the time node, resulting in accidental killing.

[0073] To address this issue, the logic history tracing unit continuously records all operational logic modifications (including modification content, timestamps, and operator information) and encrypts and stores this historical data in the vehicle's onboard blockchain node to ensure it cannot be tampered with. During routine inspections, the inspection unit not only verifies the legitimacy of the current operational logic but also retrieves historical records from the blockchain for comparison. If unauthorized differences are found between the current logic and historical versions (such as parameter changes not signed by the manufacturer), an alert will be triggered, even if the operational logic itself is temporarily compliant.

[0074] At the same time, the behavior analysis unit uses a time series model to analyze the system's behavior after the logic modification (such as sensor data reporting frequency, instruction call interval, etc.). If it detects that the modified logic causes abnormal behavior after a delay (such as an unwarranted increase in data encryption frequency), it will work with the correction unit to immediately roll back to the most recently trusted version and notify the dynamic switching unit to temporarily increase the security level. Both units are linked through real-time data sharing and blockchain verification (using Hyperledger Fabric). The historical tracing unit provides a chain of evidence for tampering, while the behavior analysis unit captures the time sequence of potential threats. Together, they ensure that even attackers disguised by legitimate modifications can be accurately identified and intercepted.

[0075] Although the millimeter-wave radar, blockchain, and trusted execution environment (TEE) used in this system will increase costs, they will improve anti-theft security.

[0076] In view of current actual needs, the protection scope of the above-mentioned implementation mode adopted in this application is not limited to this. Various changes made within the knowledge scope of technical personnel in this field without departing from the concept of this application still fall within the protection scope of the present invention.

Claims

1. An intelligent automobile anti-theft alarm device, characterized by: It includes an anti-theft system installed in the vehicle and a car owner app connected to the anti-theft system via cloud technology, including a signal acquisition module for collecting data about the car's environment to assist in determining whether the vehicle is in a stolen state; Privacy recording module, used to record the vehicle's security and privacy information; The anti-theft protection module includes a security verification unit, a dynamic switching unit, and an anti-theft processing unit. The security verification unit is used to perform security verification operations. The dynamic switching unit works in conjunction with the signal acquisition module to switch the verification difficulty of the vehicle's security verification unit. The anti-theft processing unit cooperates with the dynamic switching unit to adjust the encryption level of the privacy recording module for privacy data and adjust the operating frequency of the patrol module. Alarm output module, used for alarm prompts and auxiliary verification of anti-theft status; The patrol and inspection module, which is executed in a trusted execution environment, includes a patrol unit for regularly checking whether the operating logic of each module in the vehicle anti-theft system is normal, a behavior analysis unit that monitors the call chain of legitimate instructions in the anti-theft system and detects abnormal instructions, a data verification unit that adds protective noise to the data of the privacy recording module, a security protection unit that masks the content of instructions within the anti-theft system through randomization operations, a correction unit that corrects tampered operating logic, and a mark-clearing unit that marks and clears identified illegal operations and attackers; The working steps of the dynamic switching unit in conjunction with the signal acquisition module are as follows: A1. Build a diagram of the interaction between people, equipment, and vehicles using onboard cameras and millimeter-wave radar. A2. Use a neural network to analyze interactions. If it detects that the behavior of multiple people matches the predefined attack collaboration purpose, the dynamic switching unit and the anti-theft processing unit are activated. The inspection and supervision module also includes a logic history tracing unit, which is used to record the modification history of the operating logic and store it in the blockchain. The inspection unit synchronously compares the consistency of historical versions when checking the logic. The behavior analysis unit monitors the behavior change trend after the logic is modified through a time series model. If it is detected that the modified operating logic has an abnormality after delayed operation, the correction unit is triggered.

2. The intelligent automobile anti-theft alarm device according to claim 1, characterized in that: The signal acquisition module includes a camera, a vibration sensor, and a millimeter-wave radar installed in the vehicle. The camera is used to collect environmental data inside and outside the vehicle, the vibration sensor is used to record the vibration condition of the vehicle body when the vehicle is parked, and the millimeter-wave radar is used to stably obtain the situation of objects around the vehicle. The data from the camera, vibration sensor, and millimeter-wave radar are combined for comprehensive analysis to determine whether the vehicle is in a stolen state. If so, an alarm is issued through the alarm output module.

3. The intelligent automobile anti-theft alarm device according to claim 2, characterized in that: The alarm output module includes an alarm prompt unit, a verification unit and an auxiliary unit, wherein the alarm prompt unit is used to perform an alarm prompt operation when the security verification unit fails, the verification unit is used to determine whether the alarm prompt unit can work normally, and when the alarm prompt unit encounters an attack, the auxiliary unit sends a signal to the dynamic switching unit to cooperate in dynamic switching, wherein the types of attacks encountered by the alarm prompt unit include physical attacks and operational logic attacks.

4. The intelligent automobile anti-theft alarm device according to claim 3, characterized in that: The patrol and inspection module also includes an experimental unit for sending experimental instructions. The working steps of the patrol and inspection module are as follows: S1, the inspection unit checks whether the operating logic of each module has been changed at the set frequency. If there is a change, it enters S5. If there is no change, it enters S2; S2. Check whether there is any other backup logic that can be switched in the unit where the current logic is located. If there is no other backup logic, check whether the current running logic has been modified. If there is no modification, the process ends. If there is, the process goes to S5. If there is other backup logic, the process goes to S3. S3: Use the experimental unit to test the switching paths of other backup logic. If it is found that other backup logic is maliciously exploited, proceed to S6. If the switching is normal, end this inspection; S4: The behavior analysis unit monitors the matching of the vehicle status and the command, and whether the command call frequency is abnormal. At the same time, the data verification unit checks whether the sensor data is abnormal. If any of the matching of the vehicle status and the command, the command call frequency, or the sensor data is abnormal, it is determined that a covert attack has occurred in the anti-theft system, and the process proceeds to S5. If the detection results of both the behavior analysis unit and the data verification unit are normal, the process ends. S5. The correction unit repairs the tampered operation logic, and the security protection unit initiates a randomization operation on the access objects affected by the tampering. S6. The mark clearing unit locates the access object of the covert attack, performs clearing processing, and checks whether the access channel of the access object is allowed to exist. If it is not allowed to exist, the channel is closed.

5. The intelligent automobile anti-theft alarm device according to claim 4, characterized in that: The patrol module also includes a stripping unit, which removes the camouflage layer of the access object in the anti-theft system, so that the operating logic in the anti-theft protection module and the alarm output module are exposed. In addition, the stripping unit is also used to expose the characteristic data of the illegally accessed object, record it to the privacy recording module, generate a characteristic database, and cooperate with the security verification unit to prevent subsequent security verification.

6. The intelligent automobile anti-theft alarm device according to claim 5, characterized in that: The data recorded by the privacy recording module includes the vehicle's driving records, door opening and closing records, data from the signal acquisition module and the vehicle's operation log, among which the sensor data includes monitoring data of other sensors including vibration sensors installed on the vehicle, and other sensors include ultrasonic sensors, tilt sensors, door and trunk sensors, tire pressure sensors, glass breakage sensors and acoustic sensors.

Citation Information

Patent Citations

  • Car anti-theft alarm methods, devices and terminals

    CN112896096B

  • A smart car anti-theft method, system, and storage medium

    CN116872885B

  • Vehicle anti-theft method and device based on sentry mode, electronic equipment and medium

    CN117601801A

  • Intelligent networked automobile network security assessment method

    CN118074970A

  • System and method for controlling vehicle using smart phone

    WO2018186512A1