A fusion safety analysis method of a laser radar and a storage medium

By integrating safety analysis methods and combining functional safety, expected functional safety, and information security, fault tree analysis is used to identify dangerous triggering events for lidar and generate safety mechanisms. This solves the problem of incomplete lidar safety analysis and achieves a more complete and efficient safety design.

CN122632220APending Publication Date: 2026-08-25SUTENG INNOVATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510205798.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

The existing security analysis of lidar lacks integrated security research, resulting in incomplete security analysis and high security risks.

Method used

An integrated security analysis approach is adopted, combining functional safety, expected functional safety, and information security analysis. Fault tree analysis is used to identify hazard-triggered events and generate corresponding security mechanisms, and integrated security testing and user response strategies are conducted.

Benefits of technology

It achieves comprehensive and complete LiDAR safety analysis, reduces safety risks, improves the pertinence of product design and development efficiency, reduces duplicate alarms, and enhances user convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122632220A_ABST
    Figure CN122632220A_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a kind of fusion safety analysis method and storage medium of laser radar.The method comprises: determining the top-level safety target of laser radar according to the product definition of laser radar;Based on top-level safety target and fault tree analysis method, fusion safety analysis is carried out on laser radar, to obtain dangerous trigger event, wherein, fusion safety analysis includes functional safety analysis, expected functional safety analysis and information security analysis;Determine fusion safety mechanism based on dangerous trigger event;Based on fusion safety mechanism, fusion safety test is carried out on laser radar, and output user response strategy.The method makes the safety analysis of laser radar more complete and comprehensive, effectively reduces the safety risk of laser radar product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of lidar technology, and in particular to a lidar fusion security analysis method and storage medium. Background Technology

[0002] LiDAR, as a high-precision optoelectronic instrument, has been widely used in fields such as autonomous driving, surveying and mapping, and industrial control. However, with the continuous expansion of its applications, the working environment of LiDAR is becoming increasingly complex. To ensure that LiDAR can effectively cope with various hardware failures or the impact of external environments, a safety analysis of the LiDAR product design is necessary during the product development phase.

[0003] Currently, the safety analysis of lidar is only conducted from a single aspect, such as analyzing only functional safety or only expected functional safety. There is a lack of research on fusion safety analysis of lidar, which leads to incomplete safety analysis of lidar and high safety risks. Summary of the Invention

[0004] In view of this, some embodiments of the present invention provide a fusion security analysis method and storage medium for lidar, which can perform comprehensive fusion security analysis on lidar and reduce security risks.

[0005] In a first aspect, embodiments of this application provide a fusion security analysis method for lidar, the method comprising:

[0006] The top-level security target of the lidar is determined according to the product definition of the lidar;

[0007] Based on the aforementioned top-level security objectives and fault tree analysis method, a fusion security analysis is performed on the lidar to obtain hazard triggering events. The fusion security analysis includes functional safety analysis, expected functional safety analysis, and information security analysis.

[0008] A fusion security mechanism is determined based on the aforementioned dangerous triggering events;

[0009] Based on the aforementioned fusion security mechanism, a fusion security test is performed on the lidar, and a user response strategy is output.

[0010] In some embodiments, the hazard triggering event includes a first hazard triggering event, a second hazard triggering event, and a third hazard triggering event. The step of performing a fusion security analysis on the lidar based on the top-level security objective and the fault tree analysis method to obtain the hazard triggering event includes: determining the constraints of the fusion security analysis, wherein the constraints require performing the functional safety analysis on the lidar before performing the expected functional safety analysis and the information security analysis; based on the constraints, using the fault tree analysis method to perform the functional safety analysis, the expected functional safety analysis, and the information security analysis on the lidar respectively, to obtain the top event, intermediate events, and basic events of the fault tree; wherein the top event is the failure event of the top-level security objective, the intermediate events include failure types and anomaly types corresponding to each failure type, the failure types being divided into functional safety failure, expected functional safety failure, and information security failure; the first hazard triggering event is the basic event under the anomaly type corresponding to the functional safety failure, the second hazard triggering event is the basic event under the anomaly type corresponding to the expected functional safety failure, and the third hazard triggering event is the basic event under the anomaly type corresponding to the information security failure.

[0011] In some embodiments, determining the fusion security mechanism based on the danger triggering event includes: generating a first security mechanism based on the first danger triggering event; generating a second security mechanism based on the second danger triggering event; generating a third security mechanism based on the third danger triggering event; and determining the fusion security mechanism based on the first security mechanism, the second security mechanism, and the third security mechanism.

[0012] In some embodiments, determining the integrated security mechanism based on the first security mechanism, the second security mechanism, and the third security mechanism includes: determining a first security measure and a first execution object corresponding to the first security measure according to the first security mechanism; determining a second security measure and a second execution object corresponding to the second security measure according to the second security mechanism; determining a third security measure and a third execution object corresponding to the third security measure according to the third security mechanism; determining whether there is a common execution object among the first execution object, the second execution object, and the third execution object; if there is no common execution object, determining that the integrated security mechanism includes the first security mechanism, the second security mechanism, and the third security mechanism.

[0013] In some embodiments, determining the integrated security mechanism based on the first security mechanism, the second security mechanism, and the third security mechanism includes: determining a first security measure and a first execution object corresponding to the first security measure according to the first security mechanism; determining a second security measure and a second execution object corresponding to the second security measure according to the second security mechanism; determining a third security measure and a third execution object corresponding to the third security measure according to the third security mechanism; determining whether there is a common execution object among the first execution object, the second execution object, and the third execution object; if there is a common execution object, obtaining a target security measure corresponding to the common execution object based on the common execution object; determining that the integrated security mechanism includes the common execution object, the target security measure, other execution objects, and security measures corresponding to the other execution objects, wherein the other execution objects are execution objects other than the common execution object among the first execution object, the second execution object, and the third execution object.

[0014] In some embodiments, when the first executed object and the third executed object are the same, and the first executed object is different from the second executed object; obtaining the target security measure corresponding to the same executed object based on the same executed object includes: determining the first security measure or the third security measure as the target security measure, wherein the first security measure and the third security measure are the same.

[0015] In some embodiments, when the first executed object and the third executed object are the same, and the first executed object is different from the second executed object; obtaining the target security measure corresponding to the same executed object based on the same executed object further includes: determining whether the first security measure and the third security measure are mutually restrictive, wherein the first security measure and the third security measure are different; if not, the target security measure includes the first security measure and the third security measure; if so, adjusting the first security measure and the third security measure respectively to obtain the target security measure. By determining whether different security measures are mutually restrictive, conflicts in the actual implementation process can be reduced, and the accuracy and efficiency of fusion security analysis can be improved. When there are mutual restrictions, the effectiveness of fusion security analysis can be ensured by resolving the restrictions, while simultaneously meeting the security requirements of functional safety, expected functional safety, and information security.

[0016] In some embodiments, the step of performing fusion security testing on the LiDAR based on the fusion security mechanism and outputting a user response strategy includes: performing fusion security testing on the same execution object and the other execution objects to obtain fusion security test results; and outputting a user security response strategy based on the fusion security test results. By performing fusion security testing, the testing efficiency of multiple security mechanisms can be improved. Outputting the results of the fusion security test confirms the effectiveness of the fusion security mechanism, completing the entire closed-loop design and testing of the security mechanism.

[0017] In some embodiments, outputting a user security response strategy based on the fusion security test results includes: generating a first alarm signal or a second alarm signal based on the fusion security test results, wherein the first alarm signal indicates a security risk in the same executed object, and the second alarm signal indicates a security risk in other executed objects. For the same executed object, if the test results indicate a risk, only one alarm signal is output to the user, thereby reducing duplicate alarms, simplifying the user response strategy, and facilitating the user's implementation of corresponding security measures based on the alarm signal.

[0018] Secondly, this application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, is used to implement the fusion security analysis method described above.

[0019] The beneficial effects of this invention are as follows: This fusion security analysis method performs fusion security analysis on LiDAR based on fault tree analysis, making the LiDAR security analysis more complete and comprehensive, and resulting in a more complete and comprehensive fusion security mechanism. Optimizing the product design of LiDAR based on the fusion security mechanism can effectively reduce the security risks of LiDAR products. Furthermore, this fusion security analysis method analyzes the top-level security objectives of LiDAR according to the product definition, clearly defining the relationships and differences between various security analyses, making the security design and application of LiDAR more detailed and complete, and making the layers of security analysis and application more complete and clear. At the same time, the fusion security mechanism reduces similar duplicate alarms, makes alarm information more accurate, improves user convenience, and reduces the application complexity of LiDAR. The implementation of fusion functional safety and related adjustments / tests of mutual constraints ensure that the LiDAR simultaneously meets the requirements of functional safety, expected functional safety, and information security, improves the testing efficiency of multiple security mechanisms, and completes the closed-loop of the entire security mechanism design and testing chain. Attached Figure Description

[0020] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Devices with the same reference numerals in the drawings are denoted as similar devices. Unless otherwise stated, the figures in the drawings are not to be limited by scale.

[0021] Figure 1 This is a flowchart illustrating a fusion security analysis method for lidar provided in an embodiment of the present invention;

[0022] Figure 2 yes Figure 1 A flowchart illustrating step S13;

[0023] Figure 3 yes Figure 2 A flowchart illustrating step S134;

[0024] Figure 4 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0025] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention. These all fall within the scope of protection of the present invention.

[0026] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0027] LiDAR, as a high-precision sensing instrument, has been widely used in fields such as intelligent driving, surveying, and industrial control. LiDAR is installed on various devices requiring environmental scanning or target detection, such as robots and vehicles. Robots include cleaning robots, pet robots, handling robots, care robots, remote monitoring robots, and sweeping robots. Vehicles include vehicles, ships, and aircraft. When the vehicle is a vehicle, LiDAR can be installed on the front, rear, roof, side, or other parts of the vehicle. It is also understood that LiDAR can be fixed to other external devices connected to the vehicle.

[0028] In practical applications, functional safety analysis is fundamental to the product safety of LiDAR and autonomous driving. According to the Hazard Analysis and Risk Assessment (HARA) conducted by Original Equipment Manufacturers (OEMs) in the automotive industry, the Automotive Safety Integrity Level (ASIL) for LiDAR is defined as ASIL-B. However, in various complex autonomous driving scenarios, the system functionality of LiDAR can be limited by different factors, leading to increased safety risks. These factors include insufficient sensor specifications, performance limitations, adverse weather conditions, human error, and unexpected operating scenarios. Therefore, in the field of autonomous driving, as a supplement to functional safety, a Safety of the Intended Functionality (SOTIF) analysis is usually also required to reduce safety risks and ensure the safety and stability of autonomous driving.

[0029] In addition to functional safety analysis and anticipated functional safety analysis, information security analysis is also a crucial component of lidar security analysis. Information security analysis primarily aims to mitigate the impact of network fluctuations or cyberattacks on lidar, ensure the secure output of lidar point cloud data, and guarantee the integrity and security of this data. Currently, lidar security analysis typically only performs functional safety or anticipated functional safety analysis. The lack of research on integrated security analysis for lidar results in incomplete security analysis and the continued presence of significant security risks.

[0030] To address the aforementioned issues, this invention proposes a fusion security analysis method. This method first determines the top-level security objectives of the lidar based on its product definition. Then, it performs fusion security analysis on the lidar based on the top-level security objectives and fault tree analysis to obtain hazard-triggered events. The fusion security analysis includes functional safety analysis, expected functional safety analysis, and information security analysis. Next, a fusion security mechanism is determined based on the hazard-triggered events. Finally, the lidar product design is adjusted based on the fusion security mechanism to obtain the adjusted lidar product design.

[0031] This fusion security analysis method, based on fault tree analysis, performs fusion security analysis on LiDAR, resulting in a more complete and comprehensive security analysis and a more complete and comprehensive fusion security mechanism. Adjusting the LiDAR product design based on this fusion security mechanism can effectively reduce the security risks of LiDAR products. Furthermore, this fusion security analysis method closely adheres to the product definition of LiDAR, making the security analysis more targeted and thus improving the development efficiency of LiDAR product security.

[0032] In one embodiment, see Figure 1 , Figure 1 This is a flowchart illustrating the fusion security analysis method for lidar provided in an embodiment of the present invention. Figure 1 As shown, method S100 may specifically include steps S11 to S14:

[0033] S11: Determine the top-level security target of the lidar based on the product definition of the lidar.

[0034] S12: Based on the top-level security target and fault tree analysis method, a fusion security analysis is performed on the lidar to obtain the dangerous triggering events. The fusion security analysis includes functional safety analysis, expected functional safety analysis and information security analysis.

[0035] S13: Determine the fusion security mechanism based on dangerous triggering events.

[0036] S14: Perform fusion security testing on the LiDAR based on the fusion security mechanism and output the user response strategy.

[0037] In autonomous driving scenarios, LiDAR is typically defined as a high-precision scanning instrument. The point cloud data it collects forms the data foundation for autonomous driving algorithms such as path planning, target recognition, and obstacle avoidance. By collecting and processing point cloud data, various parameters of the target object can be obtained, thereby enabling functions such as ranging, localization, obstacle avoidance, and the creation of 3D point cloud maps. These target object parameters typically include distance, spatial coordinates, velocity, shape, surface reflectivity, and size.

[0038] The correctness of point cloud data refers to the normal state of the LiDAR's measurements of various parameters of the target object, or the accuracy and precision of the measured values ​​of the target object's parameters meeting the preset product requirements, or the transmission rate, bit error rate, and packet loss rate of the point cloud data meeting the preset product requirements. Therefore, the correctness of point cloud data is the foundation for LiDAR to achieve high-precision scanning capabilities. Ensuring the correctness of LiDAR point cloud data is also a top-level security objective in the LiDAR product design process.

[0039] In one embodiment, step S11 includes: taking the correctness of point cloud data as the top-level security objective of the lidar.

[0040] In one embodiment, step S12 includes steps S121 to S122.

[0041] Fault Tree Analysis (FTA) is a top-down deductive failure analysis method that uses Boolean logic to combine low-order events to analyze undesirable states in a system. It is used to understand the causes of system failures or functional malfunctions to reduce risk, or to determine the incidence of a safety incident or specific system failure. In this embodiment, FTA is used to perform a fusion security analysis on the factors causing the failure of the top-level security target of the lidar, thereby improving the safety and reliability of the lidar.

[0042] Functional safety analysis primarily focuses on the safety of LiDAR in the event of unexpected hardware or component failures. It ensures that the LiDAR can still respond with predictable safety measures in the event of such failures, guaranteeing its safe operation and meeting the safety requirements when applied to different sensing systems. To improve the reliability of fusion safety analysis, it is necessary to clarify the relationship between functional safety analysis, anticipated functional safety analysis, and information security analysis. Functional safety analysis is the foundation for anticipated functional safety analysis and information security analysis, which in turn supplement and extend functional safety analysis. Only by meeting functional safety requirements can the achievement of top-level safety objectives be ensured. Therefore, functional safety analysis is the most fundamental safety guarantee for LiDAR and a prerequisite for conducting other types of safety analyses.

[0043] In one embodiment, step S121 includes: determining the constraints of the fusion security analysis, wherein the constraints refer to: performing functional safety analysis on the lidar before performing expected functional safety analysis and information security analysis on the lidar.

[0044] Step S122 includes: based on constraints, using fault tree analysis to perform functional safety analysis, expected functional safety analysis, and information security analysis on the LiDAR, respectively, to obtain the top event, intermediate events, and basic events of the fault tree; wherein, the top event is the top-level security target failure event, and the intermediate events include failure types and the corresponding anomaly types for each failure type. Failure types are divided into functional safety failure, expected functional safety failure, and information security failure. Danger triggering events include a first danger triggering event, a second danger triggering event, and a third danger triggering event. The first danger triggering event is the basic event under the anomaly type corresponding to the functional safety failure, the second danger triggering event is the basic event under the anomaly type corresponding to the expected functional safety failure, and the third danger triggering event is the basic event under the anomaly type corresponding to the information security failure.

[0045] In one embodiment, the top-level safety objective of the lidar is to ensure the correctness of the lidar's point cloud data. The top event is incorrect lidar point cloud data. After determining the top event, functional safety analysis is performed first. The failure type corresponding to functional safety analysis is the lidar's electrical and electronic systems (E / E) failure. E / E failure anomaly types include systemic failures and hardware failures. Based on the anomaly type corresponding to each E / E failure, the event causing incorrect lidar point cloud data is determined as the first hazard trigger event. For example, for the systemic failure anomaly type, the first hazard trigger event is a hardware design defect or software design defect. For the hardware failure anomaly type, the first hazard trigger event is software image file corruption, damage to the transmitting device, or damage to the receiving device caused by hardware failure. A software image file refers to the software package, firmware, or system image file used to run the lidar. These software image files may include: embedded operating systems, drivers, configuration tools, or data processing algorithms. Drivers are low-level programs used to drive the lidar hardware, communication network, or manage data acquisition. The configuration tool is a user interface or application programming interface (API) tool used to set the operating parameters of the LiDAR. Data processing algorithms include instruction sets for filtering, feature extraction, target detection, and other processing algorithms. Software image file corruption refers to problems such as missing data packets or garbled data in the software image file. Damage to the transmitting or receiving device refers to short circuits or open circuits in the driving circuit of the transmitting or receiving device, as well as insufficient power supply to the transmitting or receiving device.

[0046] After performing the functional safety analysis described above, a planned functional safety analysis is then conducted. The failure type under planned functional safety is: functional failure due to external factors in non-E / E failure scenarios. The corresponding anomaly types include insufficient functionality, external factor limitations, or human error. Based on each anomaly type corresponding to the planned functional safety analysis, the event causing incorrect LiDAR point cloud data is identified as the second hazard trigger event. For example: for the insufficient functionality anomaly type, the second hazard trigger event is ghosting caused by high-reflectivity objects within the LiDAR's field of view. For the external factor limitations anomaly type, the second hazard trigger event is a limited LiDAR field of view due to incorrect installation location or object obstruction. For the human error anomaly type, the second hazard trigger event is user error in using the LiDAR, such as accidentally turning it off on the vehicle's infotainment system.

[0047] While performing the aforementioned functional safety analysis on the LiDAR, information security analysis can also be conducted. The failure type corresponding to information security analysis is: functional failure caused by external interference or network attacks in non-E / E failure scenarios. The anomaly types corresponding to this failure type include external attacks on the LiDAR's file integrity. Based on each anomaly type corresponding to the information security analysis, the event causing incorrect LiDAR point cloud data is identified as the third hazard trigger event. For example, for the anomaly type of external attacks on the LiDAR's file integrity, the third hazard trigger event is the tampering of the software image file. Tampering of the software image file refers to partial deletion, virus intrusion, or garbled characters appearing in the software image file.

[0048] In the above embodiments, based on the top-level security target of the LiDAR, security analysis, expected functional safety analysis, and information security analysis can be performed on the LiDAR using fault tree analysis. The failure events of the top-level security target of the LiDAR are taken as the first level. The causes leading to the failure of the top-level security target of the LiDAR are decomposed level by level to obtain the failure types leading to the failure of the top-level security target. The failure types include functional safety failure, expected functional safety failure, and information security failure, and various anomaly types corresponding to each failure type are obtained, forming the second level. Then, for each anomaly type, the first danger triggering event, the second danger triggering event, and the third danger triggering event corresponding to that anomaly type are analyzed to obtain the first danger triggering event, the second danger triggering event, and the third danger triggering event, which are the basic events under the anomaly type corresponding to the functional safety failure, the expected functional safety failure, and the information security failure. These basic events form the third level.

[0049] Based on the hazardous triggering events, corresponding security mechanisms are determined. These mechanisms include security measures and their corresponding execution objects. Security measures are used to prevent the occurrence of hazardous triggering events from affecting the achievement of top-level security objectives. Each execution object may have one or more security measures. The execution objects in the security mechanisms corresponding to different hazardous triggering events may be the same or different.

[0050] In one embodiment, such as Figure 3 As shown, step S13 includes steps S131 to S134:

[0051] S131: Generate the first safety mechanism based on the first danger triggering event.

[0052] Based on the first hazard triggering event, corresponding functional safety requirements are generated, and then based on these functional safety requirements, corresponding first safety mechanisms are generated, including:

[0053] If the first hazard triggering event is a hardware or software design defect caused by a systemic failure, the corresponding functional safety requirement is: development should be carried out according to the design and verification process defined in the functional safety standard ISO 26262. The first safety mechanism generated based on this functional safety requirement is: development should be carried out according to the design and verification process defined in the functional safety standard ISO 26262.

[0054] If the first hazard triggering event is a corrupted software image file caused by hardware failure, the corresponding functional safety requirement is to check the integrity of the software image file. Based on this functional safety requirement, the first safety mechanism is to check the integrity of the software image file during the initialization and startup phase.

[0055] If the first hazardous triggering event is damage to the transmitting or receiving device caused by random hardware failure, the corresponding functional safety requirement is: to check whether the transmitting or receiving device is functioning normally. Based on this functional safety requirement, the first safety mechanism is: during the initialization and startup phases and the normal operation phases, to check whether the driving circuit of the transmitting / receiving device has a short circuit or open circuit, and whether the supply voltage / current of the transmitting / receiving device meets the rated requirements.

[0056] S132: Generate a second safety mechanism based on the second danger triggering event.

[0057] Based on the second dangerous triggering event, the corresponding expected functional safety requirements are generated, and then the corresponding second safety mechanism is generated based on the expected functional safety requirements.

[0058] If the second hazard triggering event is a limitation of the lidar's field of view, the corresponding expected functional safety requirement is that the lidar should be installed correctly. Based on this expected functional safety requirement, the second safety mechanism is to monitor the lidar installation process and correct the lidar's pose.

[0059] S133: Generate a third security mechanism based on a third danger-triggered event.

[0060] Based on the third dangerous triggering event, a corresponding information security requirement is generated, and then a corresponding third security mechanism is generated based on the information security requirement.

[0061] The third risk trigger event is the tampering of the software image file due to an external attack. The corresponding information security requirement is to check the integrity of the software image file. Based on this information security requirement, the third security mechanism is to check the integrity of the software image file during the initialization and startup phase.

[0062] S134: Determine the fusion security mechanism based on the first security mechanism, the second security mechanism, and the third security mechanism.

[0063] The objects to be executed in each security mechanism may be the same or different. By merging the security measures corresponding to the same objects to be executed, a merged security measure is obtained.

[0064] In one embodiment, such as Figure 3 As shown, step S134 includes steps S1341 to S1345:

[0065] S1341: Based on the first security mechanism, determine the first security measure and the first object to be executed corresponding to the first security measure. The first security mechanism includes the first security measure and the first object to be executed.

[0066] The primary safety mechanism is to develop the product according to the design and verification procedures defined in the functional safety standard ISO 26262. Therefore, the primary target is the product design of the lidar, and the primary safety measure is to consult the functional safety standard ISO 26262 and develop the lidar according to the design and verification procedures defined in ISO 26262.

[0067] The primary security mechanism is to check the integrity of the software image file during the initialization and startup phase. Therefore, the first object executed is the software image file, and the primary security measure is to monitor the integrity of the software image file using a Secure Hash Algorithm (SHA) or Cyclic Redundancy Check (CRC).

[0068] The first safety mechanism is as follows: During the initialization and startup phases and the normal operation phase, check whether the drive circuit of the transmitting / receiving device has a short circuit or open circuit, and whether the supply voltage / current of the transmitting / receiving device meets the rated requirements. Therefore, the first object of execution is the drive circuit of the transmitting / receiving device, and the first safety measure is to check whether the drive circuit has a short circuit or open circuit, and whether the supply voltage / current supplied by the drive circuit to the transmitting / receiving device meets the rated requirements.

[0069] S1342: Based on the second security mechanism, determine the second security measure and the second object to be executed corresponding to the execution of the second security measure. The second security mechanism includes the second security measure and the second object to be executed.

[0070] The second safety mechanism is to monitor the installation process of the lidar and correct its pose during installation. Therefore, the second object of execution is the lidar's pose, and the second safety measure is to monitor the lidar's installation process and correct its pose.

[0071] S1343: Based on the third security mechanism, determine the third security measure and the third object to be executed corresponding to the execution of the third security measure. The third security mechanism includes the third security measure and the third object to be executed.

[0072] The third security mechanism is to check the integrity of the software image file during the initialization and startup phase. Therefore, the third object executed is the software image file, and the third security measure is to monitor the integrity of the software image file through SHA or a cryptographic hash function (BLAKE2).

[0073] S1344: Determine whether there is a common executable object among the first executable object, the second executable object, and the third executable object.

[0074] S1345: If there is no identical object to be executed, determine that the fusion security mechanism includes the first security mechanism, the second security mechanism, and the third security mechanism.

[0075] In one embodiment, step S1345 is as follows: If the first executed object, the second executed object, and the third executed object are all different, then it is determined that the first executed object, the second executed object, and the third executed object do not have the same executed object. It is then determined whether the first security measure, the second security measure, and the third security measure mutually restrict each other.

[0076] If the first security measure, the second security measure, and the third security measure do not restrict each other, the integrated security mechanism is determined to include the first security mechanism, the second security mechanism, and the third security mechanism. That is, the integrated security mechanism includes the first subject to be executed and its corresponding first security measure, the second subject to be executed and its corresponding second security measure, and the third subject to be executed and its corresponding third security measure. Each security measure is executed independently and does not affect each other.

[0077] If at least two of the first, second, and third security measures are mutually restrictive, then each security measure is adjusted until there are no more mutual restrictions among the individual security measures. The integrated security mechanism is defined as the adjusted first, second, and third security mechanisms.

[0078] In another embodiment, step S1345 is as follows: if there are identical executed objects, obtain the target security measures corresponding to the identical executed objects based on the identical executed objects; determine that the fusion security mechanism includes identical executed objects, target security measures, other executed objects and security measures corresponding to other executed objects, wherein the other executed objects are the executed objects other than the identical executed objects among the first executed object, the second executed object and the third executed object.

[0079] In one example, when the first executed object and the third executed object are the same, and the first executed object is different from the second executed object; based on the same executed object, the target security measure corresponding to the same executed object is obtained, including: determining the first security measure or the third security measure as the target security measure, wherein the first security measure and the third security measure are the same.

[0080] For example, after performing functional safety analysis, expected functional safety analysis, and information security analysis, the first executable object is identified as the software image file, the second executable object as the LiDAR pose, and the third executable object as the software image file. The second security measure is to monitor the LiDAR installation process and correct the LiDAR pose. Since the first and third security measures are the same, both involving monitoring the integrity of the software image file via SHA (Safety Assurance). Therefore, the first and third executable objects are the same executable object, and monitoring the integrity of the software image file via SHA is determined as the target security measure.

[0081] In one example, when the first and third executed objects are the same, and the first executed object is different from the second executed object; based on the same executed object, the target security measure corresponding to the same executed object is obtained, which further includes: determining whether the first security measure and the third security measure are mutually restrictive, wherein the first security measure and the third security measure are different; if not, the target security measure includes the first security measure and the third security measure. If yes, the first security measure and the third security measure are adjusted to obtain the target security measure.

[0082] For example, after performing functional safety analysis, expected functional safety analysis, and information security analysis, the first executable object is identified as the software image file, the second executable object as the LiDAR pose, and the third executable object as the software image file. The second security measure is to monitor the LiDAR installation process and correct the LiDAR pose. The first security measure is to verify the integrity of the software image file using CRC or SHA, and the third security measure is to verify the integrity of the software image file using SHA or a cryptographic hash function. To avoid conflicts and constraints caused by different verification methods, the first security measure is adjusted to verify the integrity of the software image file using SHA, and the third security measure is also adjusted to verify the integrity of the software image file using SHA. That is, the target security measure is to verify the integrity of the software image file using SHA.

[0083] In one embodiment, step S13 further includes: determining whether the target security measure and the security measures corresponding to other objects being executed restrict each other; if so, adjusting the first security mechanism, the second security mechanism and the third security mechanism until the target security measure and the security measures corresponding to other objects being executed do not restrict each other.

[0084] In one embodiment, if the first, second, and third executed objects contain the same executed object, step S14 includes: performing a fusion security test on the same executed object and other executed objects to obtain a fusion security test result; and outputting a user security response strategy based on the fusion security test result.

[0085] For example, based on the fusion security mechanism, the first and third executed objects are determined to be software image files, while the second executed object is the pose of the LiDAR. The target security measure is to check the integrity of the software image file during the initialization and startup phase. The second security measure corresponding to the second executed object is to monitor the installation process of the LiDAR and correct its pose.

[0086] A fusion security test is performed on the same executable object and the other executable objects to obtain the fusion security test results. This includes verifying the integrity of the software image file during the initialization and startup phase, and conducting flatness, angular accuracy, and field-of-view experiments on the installation pose of the lidar.

[0087] Based on the fusion security test results, a user security response strategy is output, including: if the test results indicate that the integrity verification of the software image file fails, a first alarm signal is output to the user to inform them that the software image file has a security risk, and to allow them to repair or replace the software image file. If the installation position of the LiDAR is deviated, a second alarm signal is output to the user to inform them that the installation of the LiDAR has a security risk, and to prompt them to correct the pose of the LiDAR.

[0088] In one embodiment, if there are no identical executable objects among the first executable object, the second executable object, and the third executable object, step S14 includes: performing a fusion security test on the first executable object, the second executable object, and the third executable object to obtain a fusion security test result; and outputting a user security response strategy based on the fusion security test result.

[0089] Based on the fusion security mechanism, the first execution object is determined to be the driving circuit of the transmitting device, the second execution object is the pose of the lidar, and the third execution object is the software image file. Fusion security tests are performed on the first, second, and third execution objects to obtain the fusion security test results, including: checking whether the driving circuit has a short circuit or not; checking whether the power supply voltage / current supplied by the driving circuit to the transmitting device meets the rated requirements; checking the integrity of the software image file; and conducting flatness, angular accuracy, and field-of-view experiments on the lidar's installation pose.

[0090] Based on the fusion security test results, the following user safety response strategies are output: If the test results indicate a decrease in the power supply voltage of the transmitting device, a first alarm signal is output to the user to inform them of insufficient power supply to the LiDAR and the need to check the power supply line. If the integrity verification of the software image file fails, a second alarm signal is output to the user to inform them of a security risk in the software image file and the need to repair or replace it. If the installation position of the LiDAR is deviated, a third alarm signal is output to the user to inform them of a security risk in the installation of the LiDAR and to prompt them to correct the LiDAR's pose.

[0091] In summary, this fusion security analysis method, based on fault tree analysis, performs fusion security analysis on LiDAR, resulting in a more complete and comprehensive security analysis and a more complete and comprehensive fusion security mechanism. Adjusting the LiDAR product design based on this fusion security mechanism can effectively reduce the security risks of LiDAR products. Furthermore, this fusion security analysis method closely adheres to the product definition of LiDAR, making the security analysis more targeted and improving the development efficiency of LiDAR product security. Outputting user security response strategies based on the fusion security mechanism reduces duplicate alarms, provides more accurate alarm information, and simplifies the use of alarm information for users, reducing the complexity of LiDAR product applications.

[0092] This invention also provides an electronic device, please refer to [link / reference]. Figure 4 , Figure 4 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention.

[0093] like Figure 4 As shown, the electronic device 200 includes at least one processor 201 and a memory 202 connected in communication. Figure 4 (Taking a bus connection and a processor as an example). The processor 201 is used to provide computing and control capabilities to control the electronic device 200 to perform corresponding tasks, such as controlling the electronic device 200 to perform the fusion security analysis method of lidar in any of the above method embodiments.

[0094] In this embodiment, the electronic device performs fusion security analysis on the lidar based on the fault tree analysis method, making the lidar security analysis more complete and comprehensive. The resulting fusion security measures are also more complete and comprehensive. Based on the fusion security measures, the product design of the lidar is adjusted, effectively reducing the safety risks of the lidar product. Moreover, this fusion security analysis method is closely related to the product definition of lidar, making the fusion security analysis more targeted, thereby improving the efficiency of lidar product safety development.

[0095] Processor 201 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), a hardware chip, or any combination thereof; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The aforementioned PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0096] The memory 202, as a non-volatile computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the fusion security analysis method for electronic devices in the embodiments of the present invention. The processor 201 can implement the fusion security analysis method for electronic devices in any of the above method embodiments by running the software programs, instructions, and modules stored in the memory 202; to avoid repetition, further details are omitted here.

[0097] Specifically, memory 202 may include volatile memory (VM), such as random access memory (RAM); memory 202 may also include non-volatile memory (NVM), such as read-only memory (ROM), flash memory, hard disk drive (HDD), solid-state drive (SSD), or other non-transitory solid-state storage devices; memory 202 may also include combinations of the above types of memory.

[0098] In this embodiment of the invention, the memory 202 may further include memory remotely configured relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0099] In this embodiment of the invention, the electronic device 200 may also include other components for implementing the device functions, which will not be described in detail here.

[0100] This invention also provides a computer-readable storage medium, such as a memory including program code, which can be executed by a processor to complete the fusion security analysis method for the electronic device described in the above embodiments. For example, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CDROM), magnetic tape, floppy disk, or optical data storage device, etc.

[0101] This invention also provides a computer program product comprising one or more lines of program code stored in a computer-readable storage medium. A processor of an electronic device reads the program code from the computer-readable storage medium and executes the program code to complete the method steps of the fused security analysis method for the electronic device provided in the above embodiments.

[0102] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0103] It should be noted that, unless otherwise specified, the various features in the embodiments of this invention can be combined with each other, all of which are within the protection scope of this invention. Furthermore, although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than the module division in the device or the order in the flowchart. In addition, the terms "first," "second," and "third" used herein do not limit the data or execution order, but only distinguish identical or similar items with substantially the same function and effect.

[0104] Unless otherwise defined, all technical and scientific terms used in this specification have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. The term "and / or" as used in this specification includes any and all combinations of one or more of the associated listed items.

[0105] Furthermore, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other. The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it; under the concept of the present invention, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the present invention as described above, which are not provided in detail for the sake of brevity; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A fusion security analysis method for lidar, characterized in that, The method includes: The top-level security target of the lidar is determined according to the product definition of the lidar; Based on the aforementioned top-level security objectives and fault tree analysis method, a fusion security analysis is performed on the lidar to obtain hazard triggering events. The fusion security analysis includes functional safety analysis, expected functional safety analysis, and information security analysis. A fusion security mechanism is determined based on the aforementioned dangerous triggering events; Based on the aforementioned fusion security mechanism, a fusion security test is performed on the lidar, and a user response strategy is output.

2. The method according to claim 1, characterized in that, The danger triggering events include a first danger triggering event, a second danger triggering event, and a third danger triggering event. The fusion security analysis of the lidar based on the top-level security objective and fault tree analysis method yields the danger triggering events, including: The constraints of the fusion security analysis are determined, wherein the constraints are that the functional security analysis of the lidar is performed before the expected functional security analysis and the information security analysis are performed on the lidar; Based on the constraints, the fault tree analysis method is used to perform the functional safety analysis, the expected functional safety analysis, and the information security analysis on the lidar, respectively, to obtain the top event, intermediate events, and basic events of the fault tree. The top event is the failure event of the top-level security target, and the intermediate events include failure types and anomaly types corresponding to each failure type. The failure types are divided into functional safety failure, expected functional safety failure and information security failure. The first danger triggering event is the basic event under the anomaly type corresponding to the functional safety failure; the second danger triggering event is the basic event under the anomaly type corresponding to the expected functional safety failure; and the third danger triggering event is the basic event under the anomaly type corresponding to the information security failure.

3. The method according to claim 1 or 2, characterized in that, The determination of the fusion security mechanism based on the dangerous triggering event includes: A first safety mechanism is generated based on the first danger-triggered event; A second safety mechanism is generated based on the second danger-triggered event; A third safety mechanism is generated based on the aforementioned third danger triggering event; The fusion security mechanism is determined based on the first security mechanism, the second security mechanism, and the third security mechanism.

4. The method according to claim 3, characterized in that, Determining the fusion security mechanism based on the first security mechanism, the second security mechanism, and the third security mechanism includes: Based on the first security mechanism, a first security measure and a first object to be executed corresponding to the first security measure are determined; Based on the second security mechanism, determine the second security measure and the second object to be executed corresponding to the second security measure; Based on the third security mechanism, a third security measure and a third execution object corresponding to the third security measure are determined; Determine whether there is a common executable object among the first executable object, the second executable object, and the third executable object; If no identical object exists, the fusion security mechanism is determined to include the first security mechanism, the second security mechanism, and the third security mechanism.

5. The method according to claim 3, characterized in that, Determining the fusion security mechanism based on the first security mechanism, the second security mechanism, and the third security mechanism includes: Based on the first security mechanism, a first security measure and a first object to be executed corresponding to the first security measure are determined; Based on the second security mechanism, determine the second security measure and the second object to be executed corresponding to the second security measure; Based on the third security mechanism, a third security measure and a third execution object corresponding to the third security measure are determined; Determine whether there is a common executable object among the first executable object, the second executable object, and the third executable object; If the same object exists, the target security measure corresponding to the same object is obtained based on the same object. The integrated security mechanism is defined as including the same executed object, the target security measure, other executed objects, and the security measures corresponding to the other executed objects, wherein the other executed objects are the first executed object, the second executed object, and the third executed object other than the same executed object.

6. The method according to claim 5, characterized in that, When the first executed object and the third executed object are the same, and the first executed object is different from the second executed object; The step of obtaining the target security measures corresponding to the same executed object includes: The first security measure or the third security measure is determined as the target security measure, wherein the first security measure and the third security measure are the same.

7. The method according to claim 5, characterized in that, When the first executed object and the third executed object are the same, and the first executed object is different from the second executed object; The step of obtaining the target security measures corresponding to the same executed object based on the same executed object further includes: Determine whether the first security measure and the third security measure restrict each other, wherein the first security measure and the third security measure are different; If not, the target security measures include the first security measures and the third security measures; If so, the first security measure and the third security measure are adjusted respectively to obtain the target security measure.

8. The method according to claim 5, characterized in that, The process of performing fusion security testing on the lidar based on the fusion security mechanism and outputting a user response strategy includes: Perform a fusion security test on the same executable object and the other executable objects to obtain the fusion security test results; Based on the results of the integrated security test, a user security response strategy is output.

9. The method according to claim 8, characterized in that, The step of outputting a user security response strategy based on the fusion security test results includes: Based on the results of the fusion security test, a first alarm signal or a second alarm signal is generated, wherein the first alarm signal is used to indicate that the same executed object has a security risk, and the second alarm signal is used to indicate that the other executed objects have a security risk.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, is used to implement the fusion security analysis method as described in any one of claims 1 to 9.