Method and device for identifying vehicle CAN network attacks

By adding security authentication information to the vehicle CAN network management message for multiple legality verification, the problem of unrecognized attacks in the prior art is solved, and communication security and reliability of normal operation of the vehicle are improved.

CN114257986BActive Publication Date: 2025-08-01BEIJING JINGWEI HIRAIN TECH CO INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210105796.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-28
Publication Date
2025-08-01
Estimated Expiration
2042-01-28

AI Technical Summary

Technical Problem

The existing vehicle CAN network communication methods cannot accurately identify attack behavior, especially when OSEKNM is attacked, resulting in network abnormalities and affecting the normal use of the vehicle.

Method used

Add security authentication information to the reserved bytes of network management messages, and multiple legitimacy verification is performed to identify attacks by generating and populating count values and security authentication information.

Benefits of technology

It improves the communication security of the CAN network, can identify and discard network attack messages, prevent network abnormalities, and ensure normal communication and use of vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114257986B_ABST
    Figure CN114257986B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for identifying vehicle CAN network attacks. The method includes: in response to a node in the CAN network being awakened, receiving a network management message sent by a network management system, generating security authentication information for verifying the network management message by using a count value stored before the node goes to sleep, and filling the security authentication information into a reserved byte of the network management message; transmitting the network management message filled with the security authentication information during the communication process of the node in the CAN network, and performing multiple legitimacy verifications on the network management message sent on the bus by using the security authentication information; in the case where all the multiple legitimacy verifications pass, transmitting the network management message as a legitimate message to the network management system. Through the above method, the identification of vehicle CAN network attacks can be realized, and the problem that the existing communication method of the vehicle CAN network cannot accurately identify vehicle CAN network attacks is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and more particularly, to a method and device for identifying vehicle CAN network attacks. Background Art

[0002] With the development of automotive network communication technology, the Internet of Vehicles technology has been introduced into vehicles and widely used in automotive network communication to serve the needs of vehicle networking and interconnection. The network management system OSEKNM, as one of the earliest network management specifications used in vehicle CAN networks, is still widely used in vehicle CAN networks to implement the function of synchronously sleeping and waking up each node in the vehicle CAN network.

[0003] In the related art, the CAN network based on OSEKNM specifically includes the following steps during communication: First, nodes in the network communicate through the CAN bus; nodes in the network send and receive OSEKNM network management messages through the CAN bus; nodes in the network judge the current network state of the CAN bus according to the received network management messages; nodes in the network decide to send OSEKNM network management messages of a certain state according to their own communication requirements and the current network state, and set the current network state of this node according to the sending result; nodes in the network send and receive other messages according to the current network state of this node.

[0004] However, while the above vehicle CAN network provides users with a good vehicle use experience and high - value - added services, it also introduces the risk of network attacks. For the CAN network using OSEKNM, since it was produced in the closed vehicle network stage, it lacks the ability to defend against attacks. And with the increasing demand of customers for the Internet of Vehicles, the vehicle network faces an increasing challenge of being attacked. Especially for the CAN bus with relatively weak attack resistance itself, OSEKNM is a very easy entry point for being attacked. When an attack is implemented on OSEKNM, the existing network communication methods are difficult to accurately identify the attack behavior of the vehicle network, resulting in abnormal vehicle network communication and affecting the normal use of the vehicle. Therefore, the vehicle's demand for the CAN bus of OSEKNM to resist network attacks has become increasingly prominent. Summary of the Invention

[0005] The present invention provides a method and device for identifying vehicle CAN network attacks, which can add security authentication information in the reserved definition bytes of network management messages to identify vehicle CAN network attacks, thus solving the problem that the existing communication methods of vehicle CAN networks cannot accurately identify vehicle CAN network attacks. The specific technical solutions are as follows:

[0006] In a first aspect, an embodiment of the present invention provides a method for identifying vehicle CAN network attacks, the method including:

[0007] In response to a node in the CAN network being awakened, receive a network management message sent by a network management system, generate security authentication information for verifying the network management message by using a count value stored before the node goes to sleep, and fill the security authentication information into reserved bytes of the network management message, where an initial value of the count value is randomly generated by the node;

[0008] During the communication process of nodes in the CAN network, transmit the network management message filled with security authentication information, and perform multiple legitimacy verifications on the network management message sent on the bus by using the security authentication information;

[0009] In the case where all multiple legitimacy verifications pass, identify the network management message sent on the bus as a legitimate message and transmit it to the network management system;

[0010] In the case where any one of the legitimacy verifications fails, identify the network management message sent on the bus as a network attack message and discard it.

[0011] In one implementation, before the step of, in response to a node in the CAN network being awakened, receiving a network management message sent by a network management system and filling security authentication information for verifying the network management message into reserved bytes of the network management message, the method further includes:

[0012] Receive an active wake-up request initiated by a wake-up source recognized by the receiving node, and use an active wake-up message carried by the active wake-up request to trigger a node in the CAN network to be awakened; or

[0013] Receive a passive wake-up message sent by another node and filtered by the bus, and identify whether the CAN network is under a sleep attack according to a sleep attack monitoring logic. In the case where there is no sleep attack, use the passive wake-up message to trigger a node in the CAN network to be awakened;

[0014] Wherein, the bus-filtered passive wake-up message is obtained by a hardware filtering function set on the bus comparing configured security authentication information with security authentication information in a received network management message, and the hardware filtering function is implemented by adding a CAN transceiver with a hardware filtering function on the bus;

[0015] In the case where the configured security authentication information is consistent with the security authentication information in the received network management message, regard the received network management message as a passive wake-up message;

[0016] In the case where the configured security authentication information is inconsistent with the security authentication information in the received network management message, discard the received network management message.

[0017] In one embodiment, the method for identifying whether the CAN network is under a sleep attack according to the sleep attack monitoring logic, and triggering the wake-up of nodes in the CAN network by using the passive wake-up message when the CAN network is not under a sleep attack, includes:

[0018] Checking whether other nodes meet the sleep conditions according to the sleep attack monitoring logic;

[0019] When the other nodes meet the sleep conditions and the value of the hold wake-up timer exceeds a first preset threshold, identifying that the CAN network is under a sleep attack and discarding the passive wake-up message;

[0020] When the other nodes do not meet the sleep conditions or the value of the hold wake-up timer does not exceed the first preset threshold, identifying that the CAN network is not under a sleep attack and triggering the wake-up of nodes in the CAN network by using the passive wake-up message;

[0021] Wherein, the hold wake-up timer is used to record the time length from when the node does not have a local network wake-up source to when the CAN network is still in the wake-up state.

[0022] In one embodiment, the method for checking whether other nodes meet the sleep conditions according to the sleep attack monitoring logic includes:

[0023] Extracting the sleep indication bit of the passive wake-up message sent by other nodes and filtered by the bus;

[0024] When the sleep indication bit is a preset value, determining that other nodes do not have a local network wake-up source and meet the sleep conditions;

[0025] When the sleep indication bit is not the preset value, determining that other nodes have a local network wake-up source and do not meet the sleep conditions.

[0026] In one embodiment, the method further includes:

[0027] When the nodes in the CAN network meet the sleep conditions, receiving a network management message with a sleep indication bit being a preset value;

[0028] When the network management message with the sleep indication bit being the preset value passes multiple legitimacy validations, extracting the count value in the network management message with the sleep indication bit being the preset value, calculating the security authentication information by using the count value, and after configuring the hardware filtering on the bus with the security authentication information, performing CAN network sleep.

[0029] In one embodiment, generating the security authentication information for verifying the network management message by using the count value stored before the node goes to sleep includes:

[0030] Calculate a cyclic redundancy check code by combining the source node address, destination node address, control information in the network management message with the count value stored before the node goes to sleep.

[0031] Combine the source node address, destination node address, control information, count value stored before the node goes to sleep, and the cyclic redundancy check code in the network management message, and use the secret key as the input of the encryption algorithm to calculate the original security byte.

[0032] Extract the lowest significant preset number of bytes in the original security byte as the security byte, and combine it with the count value stored before the node goes to sleep to generate security authentication information for verifying the network management message.

[0033] In one implementation, the multiple legality verification of the network management message sent on the bus using the security authentication information includes:

[0034] Perform legality verification on the security byte in the network management message sent on the bus;

[0035] When the security byte passes the legality verification, perform legality verification on the count value stored in the network management message sent on the bus;

[0036] When the security byte does not pass the legality verification, record the network management message sent on the bus as a network attack message and generate an alarm message;

[0037] When the count value passes the legality verification, perform legality verification on the message type of the network management message sent on the bus;

[0038] When the count value does not pass the legality verification, record the network management message sent on the bus as a network attack message and generate an alarm message;

[0039] When the message type passes the legality verification, transmit the network management message sent on the bus as a legal message to the network management system;

[0040] When the message type does not pass the legality verification, record the network management message sent on the bus as a network attack message and generate an alarm message.

[0041] In one implementation, the legality verification of the security byte in the network management message sent on the bus includes:

[0042] Extract the security byte in the network management message sent on the bus as the reference security byte;

[0043] Calculate a target security byte using the source node address, destination node address, control information in the network management message sent using the bus, and the count value stored before the node goes to sleep.

[0044] When the reference security byte is the same as the target security byte after comparison, determine that the security byte passes the legality verification.

[0045] The legality verification for the count value stored in the network management message sent using the bus includes:

[0046] Obtain the count value stored in the network management message with the most recent received legality as the reference count value.

[0047] Extract the count value stored in the network management message sent using the bus as the target count value.

[0048] When the target count value is greater than the reference count value and does not exceed the second preset threshold, determine that the count value passes the legality verification.

[0049] The legality verification for the message type of the network management message sent using the bus includes:

[0050] When the message type of the network management message sent using the bus is a preset type, read the time when the network management system sends the network management message, and form a time difference with the time when the network management system sent / received the network management message last time.

[0051] When the time difference meets the preset conditions, determine that the message type passes the legality verification.

[0052] In one implementation, the preset conditions are that the time difference is greater than the first time and less than the second time. The first time is the sending period set by the network management system for the network management message of the preset type, and the second time is the receiving timeout time set by the network management system for the network management message of the preset type.

[0053] In a second aspect, an embodiment of the present invention provides a device for identifying vehicle CAN network attacks, and the device includes:

[0054] A generation unit, configured to, in response to a node in the CAN network being awakened, receive a network management message sent by the network management system, generate security authentication information for verifying the network management message using the count value stored before the node goes to sleep, and fill the security authentication information into the reserved bytes of the network management message. The initial value of the count value is randomly generated by the node.

[0055] A verification unit, configured to transmit a network management message filled with security authentication information during the communication of nodes in a CAN network, and perform multiple legitimacy verifications on the network management message sent on the bus by using the security authentication information;

[0056] A transmission unit, configured to, when all the multiple legitimacy verifications are passed, identify the network management message sent on the bus as a legitimate message and transmit it to a network management system, and when any one of the legitimacy verifications fails, identify the network management message sent on the bus as a network attack message and discard it.

[0057] In an implementation manner, the device further includes:

[0058] A wake-up unit, configured to, in response to a node in the CAN network being woken up, before receiving a network management message sent by the network management system and filling security authentication information for verifying the network management message into reserved bytes of the network management message, receive an active wake-up request initiated by a wake-up source recognized by the receiving node, and trigger the node in the CAN network to be woken up by using an active wake-up message carried in the active wake-up request; or

[0059] Receive a passive wake-up message sent by another node and filtered by the bus, and identify whether the CAN network is under a sleep attack according to a sleep attack monitoring logic. When the CAN network is not under a sleep attack, trigger the node in the CAN network to be woken up by using the passive wake-up message;

[0060] Wherein, the bus-filtered passive wake-up message is obtained by a hardware filtering function set on the bus through comparing configured security authentication information with security authentication information in a received network management message, and the hardware filtering function is implemented by adding a CAN transceiver with a hardware filtering function on the bus;

[0061] When the configured security authentication information is consistent with the security authentication information in the received network management message, regard the received network management message as a passive wake-up message,

[0062] When the configured security authentication information is inconsistent with the security authentication information in the received network management message, discard the received network management message.

[0063] In an implementation manner, the wake-up unit is specifically configured to check whether other nodes meet sleep conditions according to a sleep attack monitoring logic;

[0064] When the other nodes meet sleep conditions and the value of a wake-up timer remains above a first preset threshold, identify that the CAN network is under a sleep attack and discard the passive wake-up message;

[0065] When the other nodes do not meet the sleep condition or the value of the hold wake-up timer does not exceed the first preset threshold, it is recognized that the CAN network is not under a sleep attack, and the passive wake-up message is used to trigger the wake-up of nodes in the CAN network;

[0066] Wherein, the hold wake-up timer is used to record the time length from when there is no local network wake-up source for the slave node to when the CAN network is still in the wake-up state.

[0067] In one implementation, the wake-up unit is specifically further configured to extract the sleep indication bit of the passive wake-up message sent by other nodes and filtered by the bus;

[0068] When the sleep indication bit is a preset value, it is determined that there is no local network wake-up source for other nodes and the sleep condition is met;

[0069] When the sleep indication bit is not a preset value, it is determined that there is a local network wake-up source for other nodes and the sleep condition is not met.

[0070] In one implementation, the device further includes:

[0071] A receiving unit, configured to receive a network management message with a sleep indication bit being a preset value when each node in the CAN network meets the sleep condition;

[0072] A sleep unit, configured to, when the network management message with the sleep indication bit being a preset value passes multiple legitimacy validations, extract the count value in the network management message with the sleep indication bit being a preset value, calculate security authentication information using the count value, and after configuring the security authentication information as the hardware filtering on the bus, perform CAN network sleep.

[0073] In one implementation, the generating unit includes:

[0074] A first calculation module, configured to calculate a cyclic redundancy check code by combining the source node address, target node address, control information in the network management message with the count value stored before node sleep;

[0075] A second calculation module, configured to combine the source node address, target node address, control information, count value stored before node sleep in the network management message with the cyclic redundancy check code, and use the secret key as the input of the encryption algorithm to calculate the original security byte;

[0076] A generating module, configured to extract the lowest effective preset number of bytes in the original security byte as the security byte, and combine it with the count value stored before node sleep to generate security authentication information for verifying the network management message.

[0077] In one embodiment, the verification unit is specifically configured to verify the legality of the security bytes in the network management message sent by the bus; when the security bytes pass the legality verification, verify the legality of the count value stored in the network management message sent by the bus; when the security bytes do not pass the legality verification, record the network management message sent by the bus as a network attack message and generate an alarm message; when the count value passes the legality verification, verify the legality of the message type of the network management message sent by the bus; when the count value does not pass the legality verification, record the network management message sent by the bus as a network attack message and generate an alarm message; when the message type passes the legality verification, transmit the network management message sent by the bus as a legal message to the network management system; when the message type does not pass the legality verification, record the network management message sent by the bus as a network attack message and generate an alarm message.

[0078] In one embodiment, the verification unit is further specifically configured to extract the security bytes in the network management message sent by the bus as reference security bytes; calculate the target security bytes by using the source node address, target node address, control information in the network management message sent by the bus, and the count value stored before the node goes to sleep; when the reference security bytes are the same as the target security bytes after comparison, determine that the security bytes pass the legality verification;

[0079] The verification unit is further specifically configured to obtain the count value stored in the most recently received legal network management message as a reference count value; extract the count value stored in the network management message sent by the bus as a target count value; when the target count value is greater than the reference count value and does not exceed the second preset threshold, determine that the count value passes the legality verification;

[0080] The verification unit is further specifically configured to when the message type of the network management message sent by the bus is a preset type, read the time when the network management system sends the network management message and form a time difference with the time when the network management system sent / received the network management message last time; when the time difference meets the preset conditions, determine that the message type passes the legality verification.

[0081] In one embodiment, the preset condition is that the time difference is greater than the first time and less than the second time, the first time is the sending period set by the network management system for the network management message of the preset type, and the second time is the receiving timeout time set by the network management system for the network management message of the preset type.

[0082] In a third aspect, an embodiment of the present invention provides a storage medium, on which executable instructions are stored. When the instructions are executed by a processor, the processor implements the method described in the first aspect.

[0083] In a fourth aspect, an embodiment of the present invention provides a vehicle, including:

[0084] One or more processors;

[0085] A storage device for storing one or more programs,

[0086] wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in the first aspect.

[0087] As can be seen from the above, the method and device for identifying vehicle CAN network attacks provided by the embodiments of the present invention can, in response to a node in the CAN network being awakened, receive a network management message sent by a network management system, generate security authentication information for verifying the network management message by using a count value stored before the node goes to sleep, and fill the reserved bytes of the network management message with the security authentication information for verifying the network management message. Here, the initial value of the count value is randomly generated by the node. Further, during the communication process of nodes in the CAN network, the network management message filled with security authentication information is transmitted, and the network management message sent on the bus is subjected to multiple legitimacy verifications by using the security authentication information. In the case where all multiple legitimacy verifications pass, the network management message sent on the bus is transmitted to the network management system. It can be seen that, compared with the existing communication method of the vehicle CAN network that cannot accurately identify vehicle CAN network attacks, the embodiments of the present invention can add security authentication information to the reserved bytes of the network management message to achieve the identification of vehicle CAN network attacks, thereby solving the problem that the existing communication method of the vehicle CAN network cannot accurately identify vehicle CAN network attacks.

[0088] In addition, the technical effects that can be achieved by this embodiment further include:

[0089] By using the reserved bytes of the network management message to store the security authentication information for verifying the network management message, and using the security verification information to perform multiple legitimacy verifications on the network management message during the CAN network communication process, the ongoing CAN network attacks can be identified, so as to minimize the impact of CAN network attacks on the vehicle communication as much as possible and improve the communication security during the vehicle operation.

[0090] Of course, it is not necessary for any product or method implementing the present invention to achieve all the above-mentioned advantages at the same time. Description of the Drawings

[0091] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0092] Figure 1 It is a schematic flowchart of a method for identifying vehicle CAN network attacks provided by an embodiment of the present invention;

[0093] Figure 2a It is a structural block diagram of a vehicle's entire vehicle CAN network provided by an embodiment of the present invention;

[0094] Figure 2b It is another structural block diagram of a vehicle's entire vehicle CAN network provided by an embodiment of the present invention;

[0095] Figure 3a It is a schematic diagram of the network management message format and node skipping algorithm in the related art provided by an embodiment of the present invention;

[0096] Figure 3b It is a schematic diagram of the network management message format provided by an embodiment of the present invention;

[0097] Figure 4a It is a structural block diagram of the software of nodes in the CAN network in the related art provided by an embodiment of the present invention;

[0098] Figure 4b It is a structural block diagram of the software of nodes in the CAN network provided by an embodiment of the present invention;

[0099] Figure 5a-5b It is a schematic diagram of the state transition of nodes in the CAN network in the related art provided by an embodiment of the present invention;

[0100] Figure 5c-5d It is a schematic diagram of the state conversion and data flow of nodes in the security management module provided by an embodiment of the present invention;

[0101] Figure 6a-6b It is a schematic flowchart of CAN network wake-up provided by an embodiment of the present invention;

[0102] Figure 7 It is a schematic flowchart of CAN network sleep provided by an embodiment of the present invention;

[0103] Figure 8a-8b It is a schematic flowchart of CAN network management message sending and receiving provided by an embodiment of the present invention;

[0104] Figure 9It is a block diagram of a recognition device for vehicle CAN network attacks provided by an embodiment of the present invention. Specific embodiments

[0105] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0106] It should be noted that the terms "including" and "having" and any variations thereof in the embodiments of the present invention and the accompanying drawings are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices.

[0107] The present invention provides a method and device for recognizing vehicle CAN network attacks, which can add security authentication information in the reserved definition bytes of network management messages to realize the recognition of vehicle CAN network attacks, thereby solving the problem that the existing communication method of vehicle CAN network cannot accurately recognize vehicle CAN network attacks. The CAN network in the embodiment of the present invention can realize the communication between the electronic controllers of various components in the vehicle, such as the engine, transmission controller, instrument equipment, door controller, etc.

[0108] In the related art, when OSEKNM is under attack, it is difficult for the existing network communication methods to accurately identify the attack behaviors of the vehicle network, mainly involving the following situations: 1. When continuously attacking OSEKNM (for example, sending unexpected RING messages, causing each node in the CAN network to enter the skipped state), multiple nodes send network management messages simultaneously, resulting in the CAN network being continuously in a high-load state, affecting the normal communication and use of the vehicle; 2. When continuously attacking OSEKNM (for example, interfering with the sending and receiving of network management messages), the network state of the node is in a limp state, and the normal application of network management messages is prohibited from being sent and received, causing the vehicle communication to be paralyzed and affecting the normal use of the vehicle; 3. When attacking OSEKNM (for example, continuously sending messages with a sleep indicator of 0), in the long-term parking scenario, the network works continuously and cannot enter the sleep state, quickly exhausting the vehicle battery and making the vehicle unable to start normally. The existing communication methods of the CAN network cannot accurately identify the above several ways of attacking OSEKNM, nor can they provide alarm information to customers in a timely manner.

[0109] The embodiments of the present invention will be described in detail below.

[0110] Figure 1 It is a schematic flowchart of a method for identifying vehicle CAN network attacks provided by an embodiment of the present invention. The method may include the following steps:

[0111] 101. In response to a node in the CAN network being awakened, receive a network management message sent by the network management system, generate security authentication information for verifying the network management message using the count value stored before the node goes to sleep, and fill the security authentication information into the reserved bytes of the network management message.

[0112] Among them, the CAN network is a local area network for communication between electronic controllers of various components in a vehicle. The nodes in the CAN network are the electronic controllers of various components in the vehicle. For each node in the CAN network, data interaction with other nodes can be achieved by sending / receiving network management messages through the CAN bus, so as to realize control such as node sleep and wake-up. Here, the network management system, as the node management specification in the CAN network, can send / receive network management messages after startup and define the format of the network management message.

[0113] In a specific actual application scenario, as a representation of the structure of the vehicle's entire vehicle CAN network, in Figure 2a In a provided structure block diagram of the vehicle's entire vehicle CAN network, the various component nodes in the vehicle can perform data transmission through the CAN bus and access the vehicle networking communication terminal T-Box through the CAN bus to achieve overall vehicle control. Here, the T-Box can be connected to the Internet. At this time, a network attacker may invade the T-Box through Internet tools and attack the network management system of the CAN network through the T-Box. Further, as another representation of the structure of the vehicle's entire vehicle CAN network, in Figure 2b In another provided structure block diagram of the vehicle's entire vehicle CAN network, the various component nodes in the vehicle can access the networked node through the CAN bus. At this time, the attacker can attack the network management system of the CAN network by manipulating the networked node.

[0114] In an embodiment of the present invention, nodes in the CAN network are in a dormant state before being awakened. There are mainly two ways to trigger node awakening. One is the active awakening method. Specifically, before receiving the network management message sent by the network management system in response to a node in the CAN network being awakened and filling the security authentication information for verifying the network management message into the reserved bytes of the network management message, the receiving node recognizes the active awakening request initiated by the awakening source and uses the active awakening message carried by the active awakening request to trigger the awakening of nodes in the CAN network. Here, different awakening sources are applicable to different nodes. For example, for a door controller node, the awakening source can be the opening of the door, a remote control signal, etc. For an engine controller, the awakening source can be the ignition key, steering wheel startup, etc. The other is the passive awakening method. Specifically, before receiving the network management message sent by the network management system in response to a node in the CAN network being awakened and filling the security authentication information for verifying the network management message into the reserved bytes of the network management message, the receiving node receives the passive awakening message sent by other nodes and filtered by the bus, and determines whether the CAN network is under a sleep attack according to the sleep attack monitoring logic. In the case of no sleep attack, the passive awakening message is used to trigger the awakening of nodes in the CAN network. Among them, the passive awakening message filtered by the bus is obtained by comparing the configured security authentication information with the security authentication information in the received network management message by the hardware filtering function set on the bus. The hardware filtering function is implemented by adding a CAN transceiver with a hardware filtering function to the bus. When the configured security authentication information is consistent with the security authentication information in the received network management message, the received network management message is used as the passive awakening message. When the configured security authentication information is inconsistent with the security authentication information in the received network management message, the received network management message is discarded.

[0115] The security authentication information in the above network management message is equivalent to the security bytes and count values added on the basis of the original format of the network management message. Here, the count value is continuously updated during the transmission of the network management message. Only when the count value and the security bytes are the same, it is determined that the configured security authentication information is consistent with the security authentication information in the received network management message.

[0116] It can be understood that the active wake-up method is equivalent to the situation where the node is in the sleep state. After the wake-up source is recognized, the transmission of the active wake-up message is automatically triggered, triggering the wake-up of the node in the CAN network, and at the same time starting the network management system to send / receive network management messages. The passive wake-up is equivalent to the situation where the node is in the sleep state. After recognizing the passive wake-up message sent by other nodes and filtered by the bus, it does not directly trigger the transmission of the passive wake-up message, but judges whether the CAN network is under a sleep attack. In the case of no sleep attack, it triggers the transmission of the passive wake-up message, triggering the wake-up of the node in the CAN network, and at the same time starting the network management system to send / receive network management messages.

[0117] Specifically, in the process of judging whether the CAN network is under a sleep attack, it is possible to check whether other nodes meet the sleep conditions according to the sleep attack monitoring logic. When other nodes meet the sleep conditions and the value of the hold wake-up timer exceeds the first preset threshold, it is recognized that the CAN network is under a sleep attack, and the passive wake-up message is discarded; when other nodes do not meet the sleep conditions, or the value of the hold wake-up timer does not exceed the first preset threshold, it is recognized that the CAN network is not under a sleep attack, and the passive wake-up message is used to trigger the wake-up of the node in the CAN network; among them, the hold wake-up timer is used to record the time length from when there is no local network wake-up source for the node to when the CAN network is still in the wake-up state.

[0118] Furthermore, in order to improve the flexibility of the sleep conditions, the setting of the first preset threshold here can be defined according to the vehicle functions. For example, if the sensitivity requirement of the vehicle function is relatively high, the corresponding first preset threshold will be relatively small.

[0119] The above sleep conditions refer to the situation where the node has no local network wake-up source. When there is a local network wake-up source, the Sleep.Ind and Sleep.Ack of the network management message sent by the node must be 0. When the node has no local network wake-up source, the Sleep.Ind of the network management message sent by the node is set to 1. For example, a certain node uses the ignition switch as the local network wake-up source. When it detects that the state of the ignition switch is not OFF, it actively wakes up the CAN network and sends a wake-up message to the CAN network. At the same time, the network management system sends network management messages of Sleep.Ind and Sleep.Ack. Specifically, in the process of checking whether other nodes meet the sleep conditions according to the sleep attack monitoring logic, the sleep indication bit of the passive wake-up message sent by other nodes and filtered by the bus can be extracted; when the sleep indication bit is the preset value, it is determined that other nodes have no local network wake-up source and meet the sleep conditions. When the sleep indication bit is not the preset value, it is determined that other nodes have a local network wake-up source and do not meet the sleep conditions.

[0120] Furthermore, during the communication process of nodes in the CAN network, in order to prevent the CAN network from being attacked and unable to enter the sleep state normally, in the embodiments of the present invention, when each node in the CAN network meets the sleep condition, a network management message with a sleep indication bit being a preset value may be received; when the network management message with the sleep indication bit being the preset value passes multiple legality validations, the count value in the network management message with the sleep indication bit being the preset value is extracted, the security authentication information is calculated using the count value, and after the security authentication information is used as the hardware filtering configuration on the bus, the CAN network sleep is executed. On the one hand, the nodes that meet the sleep condition can be prevented from being interfered by CAN network attacks, and on the other hand, the messages received on the bus can be efficiently filtered, thereby ensuring the security of the nodes in the sleep state in the CAN network.

[0121] Specifically, in the process of generating the security authentication information for verifying the network management message using the count value stored before node sleep, the cyclic redundancy check code can be calculated by combining the source node address, destination node address, control information in the network management message with the count value stored before node sleep; and the source node address, destination node address, control information, count value stored before node sleep in the network management message and the cyclic redundancy check code are combined, and together with the secret key as the input of the encryption algorithm, the original security byte is calculated; further, the lowest effective preset number of bytes in the original security byte is extracted as the security byte, and combined with the count value stored before node sleep, the security authentication information for verifying the network management message is generated.

[0122] It should be noted that a network management message will be transmitted before node sleep, and at this time, the count value will be stored in the network management message. The initial value of this count value is randomly generated by the node. Generally, after the CAN network is awakened, the counter randomly generated by the node is used as the initial count value, and the count value of the first network management message transmitted is used as the starting count value of the subsequent network management messages. Each time a subsequent network management message is transmitted, the count value is updated.

[0123] In the actual application scenario, the format of the network management message in the related technology is as Figure 3a shown, including an 11-byte CAN identifier and an 8-byte CAN data. The CAN identifier includes the network address and the source node address. The CAN data includes the destination node address, control information, and data (reserved and unused). This data (reserved and unused) is used as a reserved byte and is not occupied. Figure 3aIn the network management message, the source node is represented as SA, the nursery stock table node address in the network management message is represented as DA, and the node address for receiving the network management message is represented as RA. Specifically, after the receiving node, it can be determined whether the receiving node is skipped according to the address relationship in the network management message. If DA < SA < RA, it is determined that the receiving node is skipped; if RA < DA < SA, it is determined that the receiving node is skipped; if SA < RA < DA, it is determined that the receiving node is skipped; in other cases, it is determined that the receiving node is not skipped. And the network management message format in the embodiment of the present invention is as Figure 3b shown. Compared with the network management message format in the related art, the reserved bytes in the network management message are filled with the count value CNT stored before the node goes to sleep and the security character MAC_S. MAC_S is the lowest 3 significant bytes of the initial security character MAC. In the specific calculation process of the security character, it can be calculated according to 'Source node address + Destination node address + Control information + CNT' to obtain a byte of CRC8, and use 'Source node address + Destination node address + Control information + CNT + CRC8' as the input, combined with the secret key Key, to calculate 16 bytes of the original MAC, and use the lowest 3 characters of the original MAC as MAC_S. Among them, after the network wakes up, the 16-bit counter randomly generated by the node is used as the initial CNT, and the CNT of the first sent RING message is used as the starting CNT of the subsequent RING messages. Each time a RING message is sent, CNT is incremented by 1. The byte order of CNT and MAC_S is the Motorola format.

[0124] Exemplarily, the source node in the above network management message is represented as SA, and the nursery stock table node address in the network management message is represented as DA. The specific calculation example is as follows: Assume that the address SA of the sending node is 0x45; the destination node address DA is 0x43; the control information is 0x80; the current CNT is -0x1021; the key of AES-128 is {0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77, 0x88, 0x99, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF}, and the AES-128 encryption and decryption mode is ECB; input 0x45, 0x43, 0x80, 0x10, 0x21 into CRC-8 calculation in sequence to obtain the CRC value 0x3F; input 0x45, 0x43, 0x80, 0x10, 0x21, 0x3F and the key into AES-128, and calculate in the ECB algorithm to obtain 0xac, 0xe7, 0x63, 0x71, 0xf7, 0x55, 0x35, 0xee, 0x2b, 0x32, 0x5c, 0xa8, 0xa4, 0xe2, 0x85, 0xe6 as the initial MAC, and further select the lowest 3 characters 0xe2, 0x85, 0xe6 of the MAC as MAC_S; the message content is: 0x43, 0x80, 0x10, 0x21, 0x3F, 0xe2, 0x85, 0xe6.

[0125] 102. During the communication process of nodes in the CAN network, a network management message filled with security authentication information is transmitted, and multiple legality verifications are performed on the network management message sent on the bus by using the security authentication information.

[0126] In an embodiment of the present invention, the process of performing multiple legality verifications on the network management message sent by the bus using security authentication information requires performing multiple legality verifications on the network management message. Each legality verification is performed for different features in the network management message. Here, the different features at least include the security byte, count value, and message type stored in the network management message. Specifically, the legality verification can be performed on the security byte in the network management message sent by the bus. When the security byte passes the legality verification, the legality verification is performed on the count value stored in the network management message sent by the bus. When the security byte fails to pass the legality verification, the network management message sent by the bus is recorded as a network attack message and an alarm message is generated. When the count value passes the legality verification, the legality verification is performed on the message type of the network management message sent by the bus. When the count value fails to pass the legality verification, the network management message sent by the bus is recorded as a network attack message and an alarm message is generated. When the message type passes the legality verification, the network management message sent by the bus is transmitted as a legal message to the network management system. When the message type fails to pass the legality verification, the network management message sent by the bus is recorded as a network attack message and an alarm message is generated.

[0127] Further, in the process of performing the legality verification on the security byte in the network management message sent by the bus, specifically, the security byte in the network management message sent by the bus can be extracted as the reference security byte; the target security byte is calculated using the source node address, target node address, control information in the network management message sent by the bus, and the count value stored before the node goes to sleep. When the reference security byte is the same as the target security byte after comparison, it is determined that the security byte passes the legality verification.

[0128] Further, in the process of performing the legality verification on the count value stored in the network management message sent by the bus, specifically, the count value stored in the network management message with the most recent received legality can be obtained as the reference count value; the count value stored in the network management message sent by the bus is extracted as the target count value. When the target count value is greater than the reference count value and does not exceed the second preset threshold, it is determined that the count value passes the legality verification.

[0129] Further, in the process of verifying the legality of the message type of the network management message sent on the bus, when the message type of the network management message sent on the bus is a preset type, the time when the network management system sends the network management message is read, and a time difference is formed with the time when the network management system sent / received the network management message last time; when the time difference meets the preset conditions, it is determined that the message type passes the legality verification. Here, the preset conditions are that the time difference is greater than the first time and less than the second time. The first time is the sending period set by the network management system for the network management message of the preset type, and the second time is the receiving timeout time set by the network management system for the network management message of the preset type.

[0130] 103. When multiple legality verifications all pass, the network management message sent on the bus is identified as a legal message and transmitted to the network management system. When any legality verification fails, the network management message sent on the bus is identified as a network attack message and discarded.

[0131] It can be understood that when multiple legality verifications all pass, it indicates that the network management message sent on the bus is a legal message. For legal messages, normal communication can be carried out in the CAN network without interfering with the normal operation of the vehicle. When any legality verification fails, it indicates that the network management message sent on the bus is a network attack message. For network attack messages, they may interfere with the normal operation of CAN network communication. For example, as long as the bus continuously sends messages, it can interfere with the CAN network and prevent it from normal sleep. Another example is that when interfering with the sending and receiving of network management messages on the bus, the network management system can be put into a limp home state, causing the node to stop sending and receiving messages, affecting vehicle communication and operation. In addition, as long as illegal RING messages are continuously sent on the bus, with the source node address SA of the target node being the smallest and the destination node address DA being the largest, the node identification can be skipped, causing all nodes to simultaneously request to send a declaration message, keeping the network in a high-load state and affecting vehicle communication and operation. Refer to Figure 3a the node skipping algorithm in . As long as one node sets its SA to 0 and DA to 255, other nodes will identify it as skipped when receiving. Further record and alarm the network attack message, and discard the network attack message.

[0132] In the actual application scenario, the software architecture of nodes in the relevant technology such as Figure 4aAs shown in the figure, it mainly includes an application layer 21, an interaction layer 22, a network layer 23, a security management system OSEKNM 24, a data link layer 25, and a bus communication hardware (CAN transceiver) 26. The specific connection relationships are as follows: The application layer 21 is connected to the interaction layer 22 for signal message sending / receiving. The application layer 21 is connected to the security management system OSEKNM 24 for network status request / reporting. The interaction layer 22 is connected to the security management system OSEKNM 24 for prohibiting / enabling message sending / receiving. The interaction layer 22 is connected to the network layer 23. The network layer 23 is connected to the data link layer 25 for application message sending / receiving. The interaction layer 22 is connected to the data link layer 25. The security management system OSEKNM 24 is connected to the data link layer 25 for network management message sending / receiving. The data link layer 25 is connected to the bus communication hardware (CAN transceiver) 26 for CAN message sending / receiving. And in the embodiment of the present invention, the software architecture of the nodes in the CAN network is as Figure 4b shown. On the basis of the software architecture of the nodes in the CAN network in the related art, a security management module 27 is added. The communication control requirements between the internal software of the nodes can be uniformly managed by the security management module 27. That is, in the embodiment of the present invention, the process of identifying attacks on the CAN network can be implemented by the security management module 27. Here, the internal logic of each module in the nodes of the CAN network remains unchanged, and the interaction between each module is carried out through the security management module 27.

[0133] It can be understood that since there is a lack of an identification mechanism for attacks on the network management system in the CAN network in the related art, in this embodiment, security authentication information is added to the network management message, so as to use the security authentication information to perform multiple legality verifications on the transmitted network management message to ensure the security of the network management message, so as to locate the network attack message at the first time when the network management system is attacked and perform discard processing. In the specific implementation process, on the basis of the existing network management message format, 5 bytes reserved in the network management message can be used to add counter (subsequently replaced by CNT) and MAC information to prevent replay attacks and illegal node attacks; by adding message type checking and frequency monitoring in the security management module to prevent flood attacks; by adding a sleep anomaly monitoring function in the security management module to prevent the network from not being able to enter the sleep state when the node is attacked; by adding a wake-up filtering setting after sleep to avoid being illegally woken up; by adding a CAN transceiver with a hardware filtering function, such as TJA1145T, on the hardware to cooperate with the wake-up filtering process to implement wake-up hardware filtering to enhance the protection ability against illegal wake-up attacks; by adding an attack identification record and alarm function in the security management module to provide alarm information to the user in a timely manner.

[0134] The state transition of the nodes in the CAN network in the related art is as Figure 5a-5b shown.Figure 5a It involves the transitions of various states of the node, including the transition from the normal communication state to the limp home state and the transition to the pre-sleep state, the transition from the pre-sleep state to the waiting-to-sleep state, and the transition from the waiting-to-sleep state to the sleep state, and provides the conditions that need to be met for the corresponding state transitions. Figure 5b It involves the transitions of various states of the node, including the transition from the normal communication state to the initialization state and the limp home state, and the transition from the initialization state to the limp home state, and provides the conditions that need to be met for the corresponding state transitions.

[0135] Correspondingly, in the embodiment of the present invention, the node state conversion and data flow in the security management module are as Figure 5c-5d shown. Figure 5c It shows the process of node state transition and data flow under the control of the security management module, specifically involving the CAN network wake-up process, the CAN network sleep process, and the network management message sending and receiving process.

[0136] The above-mentioned CAN network wake-up process is as Figure 6a-Figure 6b shown, including the active wake-up method and the passive wake-up method. For the active wake-up method, as Figure 6a shown, it includes the following steps: 301. The active wake-up node initiates a network wake-up; 302. Obtain the stored CNT; 303. Calculate CTC and MAC_S; 304. Add CTC and MAC_S to the message; 305. Send the message. For the passive wake-up method, as Figure 6bAs shown in the figure, the method includes the following steps: 301'. The passive wake-up node receives a wake-up message; 302'. The hardware filter verifies the wake-up message; 303'. The wake-up message is passed to the security management module; 304'. The sleep attack is identified; 305'. The network wake-up is executed. Specifically, for the active wake-up process, after the node identifies the wake-up source, it initiates an active wake-up network request to the security management module. The security management module starts the security management system OSEKNM, and then the security management system OSEKNM requests the security management module to send a wake-up message; the security management module obtains the stored CNT; calculates the CRC (CRC is a verification algorithm) using the CNT, and uses the CNT and CRC, together with the secret key, as the input of the AES128 algorithm (AES-128 is an international standard symmetric encryption and decryption algorithm, and the secret key is allocated before the product leaves the factory. The specific setting needs to be based on the requirements of the vehicle factory), calculates the original MAC, and uses the lowest 3 bytes of the MAC as MAC_S; fills the CNT and MAC_S into the corresponding positions of the network management message; and sends the network management message. For the passive wake-up process, when the transceiver is in the sleep state, the message that appears on the bus first enters the hardware filter of the transceiver; the hardware filter compares the CNT and MAC_S of the received message with the configured values according to the configuration. If the configuration is inconsistent, the received wake-up message is directly discarded and the wake-up process is stopped; if they are consistent, the message is passed to the security management module; the sleep attack monitoring logic in the security management module checks the sleep condition and the keep-awake timer. If the sleep condition is met and the value of the keep-awake timer has exceeded the threshold Thmax, it is identified as a sleep attack and the wake-up message is discarded; if the sleep condition is not met, or the value of the keep-awake timer has not exceeded the threshold Thmax, the wake-up process is executed and the wake-up message is passed to the security management system OSEKNM.

[0137] The above CAN network sleep process is as Figure 7 shown in the figure, and includes the following steps: 401. Send or receive a message with Sleep.Ack = 1; 402. Verify the legality of the network management message; 403. Store the CNT stored in the network management message; 404. Calculate the CRC and MAC_S; 305. Configure the hardware filter of the transceiver. Specifically, for the network sleep process, each node meets the sleep condition and finally sends a network management message with Sleep.Ack being 1; receives and verifies the legality of the message; extracts the CNT in the message when the message is legal; calculates the CNT and CRC8 value, and uses the CNT and CRC8, together with the secret key, as the input of the AES128 algorithm to calculate the original MAC, and uses the lowest 3 bytes of the MAC as MAC_S; configures the CNT and MAC_S as the hardware filter for the wake-up message of the transceiver, and executes the network sleep.

[0138] The above CAN network management message sending and receiving processes are as follows Figure 8a-8b shown. For the network management message sending process, as shown in Figure 8, it includes the following steps: 501. Send a message request; 502. Obtain the stored CNT; 503. Calculate CRC8; 504. Calculate MAC_S; 505. After filling the CNT and MAC_S into the message, transmit the message; For the network management message receiving process, as Figure 8bAs shown, it includes the following steps: 501': Receive a message; 502': Verify MAC_S in the message; 503': Verify CNT; 504': Verify the message type; 505': After verifying that the message is legal, transmit the received message to the network management system. Specifically, for the message sending process, the security management system OSEKNM requests the security module to send a message; the security module obtains the stored CNT value; uses SA + DA + control information + CNT in the message provided by the OSEKNM module as input to calculate CRC8; uses SA + DA + control information + CNT + CRC8, combined with the secret key, as the input of the AES-128 algorithm to calculate the original MAC with a length of 16 bytes, and extracts the lowest 3 significant bytes of the original MAC as MAC_S; fills CNT and MAC_S into the message and sends it to the bus. For the message receiving process, a network management message is received on the bus and sent to the security management module for message legality verification. First, extract SA + DA + control information + CNT in the message as input to calculate CRC8; use SA + DA + control information + CNT + CRC8, combined with the secret key, as the input of the AES-128 algorithm to calculate the original MAC with a length of 16 bytes, and extract the lowest 3 significant bytes of the original MAC in the message as MAC_S'; compare the calculated MAC_S' with the MAC_S recorded in the message. If they are equal, perform the next verification; otherwise, record the attack message information and alarm and discard the received message; then obtain the stored CNT value. If the received CNT value is larger than the stored CNT value and does not exceed 3, it is identified as CNT legal (CNT is a cyclic count. If the stored CNT value is 0xFFFF, the received CNT values of 0x0000, 0x0001, and 0x0002 are all legal), store the received CNT value, and perform the subsequent steps; otherwise, record the attack message information and alarm and discard the received message; further, if it is a RING message, read the time TL of the previous network management message sending / receiving, read the time TC of the currently received message, compare TC and TL. If the time difference dT between the two satisfies T ≤ dT ≤ Tmax (T is the RING message sending period of the security management system OSEKNM, and Tmax is the RING message receiving timeout time of OSEKNM), it is identified as a legal message, record and update the TL value to the TC value, and perform the subsequent steps; otherwise, record the attack message information and alarm and discard the received message. If it is other types of messages, directly discard them; pass the received message to the security management system OSEKNM.

[0139] The vehicle CAN network attack recognition method provided by the embodiment of the present invention can, in response to a node in the CAN network being awakened, receive a network management message sent by a network management system, generate security authentication information for verifying the network management message by using a count value stored before the node goes to sleep, and fill the security authentication information for verifying the network management message into a reserved byte of the network management message. Here, the initial value of the count value is randomly generated by the node. Further, during the communication process of nodes in the CAN network, the network management message filled with the security authentication information is transmitted, and the security authentication information is used to perform multiple legitimacy verifications on the network management message sent on the bus. When all the multiple legitimacy verifications pass, the network management message sent on the bus is transmitted to the network management system. It can be seen that, compared with the existing communication method of the vehicle CAN network that cannot accurately identify vehicle CAN network attacks, the embodiment of the present invention can add security authentication information to the reserved byte of the network management message to achieve the recognition of vehicle CAN network attacks, thus solving the problem that the existing communication method of the vehicle CAN network cannot accurately identify vehicle CAN network attacks.

[0140] Based on the above embodiment, another embodiment of the present invention provides a vehicle CAN network attack recognition device, as Figure 9 shown, the device includes:

[0141] A generation unit 61, configured to, in response to a node in the CAN network being awakened, receive a network management message sent by a network management system, generate security authentication information for verifying the network management message by using a count value stored before the node goes to sleep, and fill the security authentication information into a reserved byte of the network management message, where the initial value of the count value is randomly generated by the node;

[0142] A verification unit 62, configured to transmit the network management message filled with the security authentication information during the communication process of nodes in the CAN network, and perform multiple legitimacy verifications on the network management message sent on the bus by using the security authentication information;

[0143] A transmission unit 63, configured to, when all the multiple legitimacy verifications pass, identify the network management message sent on the bus as a legitimate message and transmit it to the network management system, and when any one of the legitimacy verifications fails, identify the network management message sent on the bus as a network attack message and discard it.

[0144] Optionally, the device further includes:

[0145] The wake-up unit is used to receive the active wake-up request initiated by the wake-up source recognized by the node before receiving the network management message sent by the network management system in response to the wake-up of the node in the CAN network and filling the security authentication information for verifying the network management message into the reserved bytes of the network management message, and triggering the wake-up of the node in the CAN network by using the active wake-up message carried in the active wake-up request; or

[0146] Receiving the passive wake-up message sent by other nodes and filtered by the bus, and identifying whether the CAN network is under a sleep attack according to the sleep attack monitoring logic. If there is no sleep attack, triggering the wake-up of the node in the CAN network by using the passive wake-up message;

[0147] Wherein, the bus-filtered passive wake-up message is obtained by comparing the configured security authentication information with the security authentication information in the received network management message by the hardware filtering function set on the bus, and the hardware filtering function is implemented by adding a CAN transceiver with hardware filtering function on the bus;

[0148] When the configured security authentication information is consistent with the security authentication information in the received network management message, taking the received network management message as the passive wake-up message,

[0149] When the configured security authentication information is inconsistent with the security authentication information in the received network management message, discarding the received network management message.

[0150] Optionally, the wake-up unit is specifically used to check whether other nodes meet the sleep conditions according to the sleep attack monitoring logic;

[0151] When the other nodes meet the sleep conditions and the value of the hold wake-up timer exceeds the first preset threshold, identifying that the CAN network is under a sleep attack and discarding the passive wake-up message; when the other nodes do not meet the sleep conditions or the value of the hold wake-up timer does not exceed the first preset threshold, identifying that the CAN network is not under a sleep attack and triggering the wake-up of the node in the CAN network by using the passive wake-up message;

[0152] Wherein, the hold wake-up timer is used to record the time length from when there is no local network wake-up source for the node to when the CAN network is still in the wake-up state.

[0153] Optionally, the wake-up unit is specifically further used to extract the sleep indication bit of the passive wake-up message sent by other nodes and filtered by the bus;

[0154] When the sleep indication bit is a preset value, determining that there is no local network wake-up source for other nodes and meeting the sleep conditions;

[0155] When the sleep indication bit is not the preset value, it is determined that there is a local network wake-up source in other nodes, and the sleep condition is not satisfied.

[0156] Optionally, the device further includes:

[0157] A receiving unit, configured to receive a network management message with a sleep indication bit being a preset value when each node in the CAN network meets the sleep condition;

[0158] A sleep unit, configured to, when the network management message with the sleep indication bit being the preset value passes multiple legitimacy validations, extract a count value in the network management message with the sleep indication bit being the preset value, calculate security authentication information by using the count value, and use the security authentication information as the hardware filtering configuration on the bus, and then execute CAN network sleep.

[0159] Optionally, the generating unit 61 includes:

[0160] A first calculation module, configured to calculate a cyclic redundancy check code by combining a source node address, a destination node address, control information in the network management message with a count value stored before the node sleeps;

[0161] A second calculation module, configured to combine the source node address, the destination node address, the control information, the count value stored before the node sleeps, and the cyclic redundancy check code in the network management message, and use a secret key as an input of an encryption algorithm to calculate an original security byte;

[0162] A generating module, configured to extract a preset number of lowest effective bytes in the original security byte as a security byte, and combine the security byte with the count value stored before the node sleeps to generate security authentication information for verifying the network management message.

[0163] Optionally, the verification unit 62 is specifically configured to perform a legality verification on the security bytes in the network management message sent by the bus; in the case where the security bytes pass the legality verification, perform a legality verification on the count value stored in the network management message sent by the bus, and in the case where the security bytes do not pass the legality verification, record the network management message sent by the bus as a network attack message and generate an alarm message; in the case where the count value passes the legality verification, perform a legality verification on the message type of the network management message sent by the bus, and in the case where the count value does not pass the legality verification, record the network management message sent by the bus as a network attack message and generate an alarm message; in the case where the message type passes the legality verification, transmit the network management message sent by the bus as a legal message to the network management system, and in the case where the message type does not pass the legality verification, record the network management message sent by the bus as a network attack message and generate an alarm message.

[0164] Optionally, the verification unit 62 is specifically further configured to extract the security bytes in the network management message sent by the bus as reference security bytes; use the source node address, target node address, control information, and the count value stored before the node goes to sleep in the network management message sent by the bus to calculate the target security bytes; in the case where the reference security bytes are compared with the target security bytes and are the same, determine that the security bytes pass the legality verification;

[0165] The verification unit 62 is specifically further configured to obtain the count value stored in the most recently received legal network management message as a reference count value; extract the count value stored in the network management message sent by the bus as a target count value; in the case where the target count value is greater than the reference count value and does not exceed a second preset threshold, determine that the count value passes the legality verification;

[0166] The verification unit 62 is specifically further configured to when the message type of the network management message sent by the bus is a preset type, read the time when the network management system sends the network management message, and form a time difference with the time when the network management system sent / received the network management message last time; in the case where the time difference meets the preset conditions, determine that the message type passes the legality verification.

[0167] Optionally, the preset condition is that the time difference is greater than a first time and less than a second time, the first time is the sending period set by the network management system for the network management message of the preset type, and the second time is the receiving timeout time set by the network management system for the network management message of the preset type.

[0168] Based on the above method embodiments, another embodiment of the present invention provides a storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor implements the above method.

[0169] Based on the above embodiments, another embodiment of the present invention provides a vehicle, comprising:

[0170] One or more processors;

[0171] A storage device for storing one or more programs,

[0172] wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement the above method. The vehicle may be a non-autonomous vehicle or an autonomous vehicle.

[0173] The above system and device embodiments correspond to the method embodiments and have the same technical effects as the method embodiments. For specific descriptions, refer to the method embodiments. The device embodiments are obtained based on the method embodiments. For specific descriptions, refer to the method embodiment part and will not be elaborated here. Those of ordinary skill in the art can understand that the drawings are only schematic diagrams of one embodiment, and the modules or processes in the drawings are not necessarily essential for implementing the present invention.

[0174] Those of ordinary skill in the art can understand that the modules in the device in the embodiments can be distributed in the device in the embodiments according to the descriptions in the embodiments, or can be correspondingly changed and located in one or more devices different from the present embodiments. The modules in the above embodiments can be combined into one module, or can be further split into multiple sub-modules.

[0175] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for identifying vehicle CAN network attacks, characterized in that, The method includes: In response to a node in the CAN network being awakened, receiving a network management message sent by a network management system, generating security authentication information for verifying the network management message by using a count value stored before the node goes to sleep, and filling the security authentication information into a reserved byte of the network management message, wherein an initial value of the count value is randomly generated by the node; During the communication process of nodes in the CAN network, transmitting the network management message filled with security authentication information, and performing multiple legitimacy verifications on the network management message sent on the bus by using the security authentication information; In the case that all multiple legitimacy verifications pass, identifying the network management message sent on the bus as a legitimate message and transmitting it to the network management system; In the case that any one of the legitimacy verifications fails, identifying the network management message sent on the bus as a network attack message and discarding it; In the case that each node in the CAN network meets the sleep condition, receiving a network management message with a sleep indication bit being a preset value; In the case that the network management message with the sleep indication bit being the preset value passes the multiple legitimacy verifications, extracting the count value in the network management message with the sleep indication bit being the preset value, calculating security authentication information by using the count value, and after configuring the security authentication information as hardware filtering on the bus, performing CAN network sleep; 2. The method according to claim 1, wherein Before the step of, in response to a node in the CAN network being awakened, receiving a network management message sent by a network management system and filling the security authentication information for verifying the network management message into a reserved byte of the network management message, the method further includes: Receiving an active wake-up request initiated by a wake-up source recognized by the receiving node, and triggering the node in the CAN network to be awakened by using an active wake-up message carried in the active wake-up request; or Receiving a passive wake-up message sent by another node and filtered by the bus, and identifying whether the CAN network is under a sleep attack according to a sleep attack monitoring logic, and in the case that there is no sleep attack, triggering the node in the CAN network to be awakened by using the passive wake-up message; Wherein, the passive wake-up message filtered by the bus is obtained by comparing the configured security authentication information with the security authentication information in the received network management message by a hardware filtering function set on the bus, and the hardware filtering function is implemented by adding a CAN transceiver with a hardware filtering function on the bus; In the case that the configured security authentication information is consistent with the security authentication information in the received network management message, regarding the received network management message as a passive wake-up message; In the case that the configured security authentication information is inconsistent with the security authentication information in the received network management message, discarding the received network management message.

3. The method according to claim 2, characterized in that, The step of identifying whether the CAN network is under a sleep attack according to the sleep attack monitoring logic, and in the case that there is no sleep attack, triggering the node in the CAN network to be awakened by using the passive wake-up message includes: Checking whether other nodes meet the sleep condition according to the sleep attack monitoring logic; When the other nodes meet the sleep condition and the value of the wake-up timer remains above the first preset threshold, it is recognized that the CAN network is under a sleep attack, and the passive wake-up message is discarded; When the other nodes do not meet the sleep condition or the value of the wake-up timer does not exceed the first preset threshold, it is recognized that the CAN network is not under a sleep attack, and the passive wake-up message is used to trigger the wake-up of nodes in the CAN network; Among them, the wake-up timer is used to record the time length from when there is no local network wake-up source for the slave node until the CAN network remains in the wake-up state.

4. The method according to claim 3, characterized in that The checking whether the other nodes meet the sleep condition according to the sleep attack monitoring logic includes: Extracting the sleep indication bit of the passive wake-up message sent by other nodes and filtered by the bus; When the sleep indication bit is a preset value, it is determined that there is no local network wake-up source for other nodes and the sleep condition is met; When the sleep indication bit is not a preset value, it is determined that there is a local network wake-up source for other nodes and the sleep condition is not met.

5. The method according to any one of claims 1 to 4, characterized in that, The generating of the security authentication information for verifying the network management message by using the count value stored before node sleep includes: Calculating the cyclic redundancy check code according to the combination of the source node address, destination node address, control information in the network management message and the count value stored before node sleep; Combining the source node address, destination node address, control information, count value stored before node sleep and the cyclic redundancy check code in the network management message, and using the secret key as the input of the encryption algorithm to calculate the original security byte; Extracting the lowest effective preset number of bytes from the original security byte as the security byte, and combining it with the count value stored before node sleep to generate the security authentication information for verifying the network management message.

6. The method according to any one of claims 1-4, characterized in that, The performing of multiple legality verifications on the network management message sent on the bus by using the security authentication information includes: performing a legality verification on the security byte in the network management message sent on the bus; When the security byte passes the legality verification, performing a legality verification on the count value stored in the network management message sent on the bus; When the security byte does not pass the legality verification, recording the network management message sent on the bus as a network attack message and generating an alarm message; When the count value passes the legality verification, performing a legality verification on the message type of the network management message sent on the bus; When the count value does not pass the legality verification, recording the network management message sent on the bus as a network attack message and generating an alarm message; When the message type passes the legality verification, transmitting the network management message sent on the bus as a legal message to the network management system; When the message type does not pass the legality verification, recording the network management message sent on the bus as a network attack message and generating an alarm message.

7. The method according to claim 6, wherein The performing of the legality verification on the security byte in the network management message sent on the bus includes: Extracting the security byte in the network management message sent on the bus as the reference security byte; Calculate a target security byte using the source node address, destination node address, control information, and the count value stored before the node goes to sleep in the network management message sent using the bus; When the reference security byte is compared with the target security byte and they are the same, determine that the security byte passes the legality verification; The legality verification for the count value stored in the network management message sent using the bus includes: Obtain the count value stored in the network management message with the most recently received legal status as the reference count value; Extract the count value stored in the network management message sent using the bus as the target count value; When the target count value is greater than the reference count value and does not exceed the second preset threshold, determine that the count value passes the legality verification; The legality verification for the message type of the network management message sent using the bus includes: When the message type of the network management message sent using the bus is a preset type, read the time when the network management system sends the network management message, and form a time difference with the time when the network management system sent / received the network management message last time; When the time difference meets the preset conditions, determine that the message type passes the legality verification.

8. The method according to claim 7, wherein The preset conditions are that the time difference is greater than the first time and less than the second time. The first time is the sending period set by the network management system for the network management message of the preset type, and the second time is the receiving timeout time set by the network management system for the network management message of the preset type.

9. An identification device for vehicle CAN network attacks, characterized in that The device includes: A generating unit, configured to, in response to a node in the CAN network being awakened, receive a network management message sent by the network management system, generate security authentication information for verifying the network management message using the count value stored before the node goes to sleep, and fill the security authentication information into the reserved bytes of the network management message. The initial value of the count value is randomly generated by the node; A verifying unit, configured to transmit the network management message filled with security authentication information during the communication of the node in the CAN network, and perform multiple legality verifications on the network management message sent using the bus using the security authentication information; A transmitting unit, configured to, when all multiple legality verifications pass, identify the network management message sent using the bus as a legal message and transmit it to the network management system, and when any legality verification fails, identify the network management message sent using the bus as a network attack message and discard it; A receiving unit, configured to, when each node in the CAN network meets the sleep conditions, receive a network management message with a sleep indication bit being a preset value; A sleeping unit, configured to, when the network management message with the sleep indication bit being a preset value passes multiple legality verifications, extract the count value in the network management message with the sleep indication bit being a preset value, calculate security authentication information using the count value, and use the security authentication information as the hardware filtering configuration on the bus, and then perform CAN network sleep.