A vehicle safety control method, device, equipment and medium

By identifying the target functional scenarios and state topology of the vehicle and comparing presets and actual state switching conditions, the problem that the existing technology cannot effectively defend against attack events is solved, efficient safety control of the vehicle is achieved, and user safety is improved.

CN115396141BActive Publication Date: 2025-05-27VOYAH AUTOMOBILE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210855155.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-19
Publication Date
2025-05-27
Estimated Expiration
2042-07-19

AI Technical Summary

Technical Problem

The existing technology can only detect and report attack events, and cannot effectively defend against attack events.

Method used

By identifying the target functional scenario where the vehicle is currently in, obtaining the state topology of the target functional scenario, and comparing the preset state switching conditions with the actual state switching conditions, if it does not match, control the vehicle to exit the target functional scenario.

Benefits of technology

It realizes effective defense against attack events, reduces the chances of vehicles responding to illegal instructions, improves the safety of vehicles, and thus improves the safety of users' property and lives.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396141B_ABST
    Figure CN115396141B_ABST
Patent Text Reader

Abstract

The present invention discloses a vehicle safety control method, device, equipment and medium, including: identifying a target function scenario in which the vehicle is currently located, and obtaining a state topology corresponding to the target function scenario; if the vehicle is in any one of the state nodes of the state topology corresponding to the target function scenario, obtaining a preset state switching condition corresponding to the state node and an actual state switching condition received by the vehicle's electronic devices corresponding to the state node at the current moment; determining whether the preset state switching condition matches the actual state switching condition; if the preset state switching condition does not match the actual state switching condition, controlling the vehicle to exit the target function scenario. When the present invention discovers that the preset state switching condition does not match the actual state switching condition, it controls the vehicle to exit the target function scenario, timely defends against the intrusion of illegal instructions, reduces the probability of the vehicle responding to illegal instructions, and thus improves the safety of the vehicle, and also improves the safety of the user's property and life.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of automotive safety technologies, and particularly to a vehicle safety control method, device, equipment, and medium. Background Art

[0002] With the development of vehicle networking technologies, automobiles have evolved from simple mechanical products into mobile intelligent cockpit products with complex networks. The networking functions of vehicles have become increasingly powerful, and the resulting vehicle information security issues have become more prominent.

[0003] In related technologies, vehicle safety is mainly maintained by detecting and reporting attack events, and effective defense against attack events cannot be achieved. Summary of the Invention

[0004] By providing a vehicle safety control method, device, equipment, and medium, embodiments of the present application solve the technical problem in the prior art that only attack events can be detected and reported, and effective defense against attack events cannot be achieved, and achieve the technical effect of effectively defending against attack events.

[0005] In a first aspect, the present application provides a vehicle safety control method, the method including:

[0006] Identifying a target function scenario in which the vehicle is currently located, and obtaining a state topology corresponding to the target function scenario;

[0007] If the vehicle is in any state node in the state topology corresponding to the target function scenario, obtaining a preset state transition condition corresponding to the state node, and an actual state transition condition received by the vehicle's entire vehicle electronic device corresponding to the state node at the current moment;

[0008] Judging whether the preset state transition condition matches the actual state transition condition;

[0009] If the preset state transition condition does not match the actual state transition condition, controlling the vehicle to exit the target function scenario.

[0010] Further, the obtaining the preset state transition condition corresponding to the state node includes:

[0011] Obtaining the preset state transition condition corresponding to the state node from a pre-constructed detection condition database.

[0012] Further, constructing the detection condition database includes:

[0013] Screening out all target functions related to vehicle safety from the vehicle's entire vehicle function cluster;

[0014] For each function usage scenario corresponding to each target function among all target functions, determine the interaction logic of the electronic and electrical architecture in the vehicle corresponding to each function usage scenario;

[0015] According to the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario, determine the preset conditions for state switching in each function usage scenario;

[0016] According to the preset conditions for state switching corresponding to each function usage scenario among all target functions, construct the detection condition database.

[0017] Further, if the preset state switching condition does not match the actual state switching condition, the method further includes:

[0018] Generate an exception log record according to the actual state switching condition and upload it to the management platform.

[0019] In a second aspect, the present application provides a vehicle safety control device, and the device includes:

[0020] A state topology acquisition module, configured to identify the target function scenario in which the vehicle is currently located and acquire the state topology corresponding to the target function scenario;

[0021] A switching condition acquisition module, configured to, if the vehicle is in any state node in the state topology corresponding to the target function scenario, acquire the preset state switching condition corresponding to the state node and the actual state switching condition received by the vehicle's entire vehicle electronic device corresponding to the state node at the current moment;

[0022] A matching module, configured to determine whether the preset state switching condition matches the actual state switching condition;

[0023] A function exit execution module, configured to, if the preset state switching condition does not match the actual state switching condition, control the vehicle to exit the target function scenario.

[0024] Further, the switching condition acquisition module includes:

[0025] A switching condition acquisition sub-module, configured to acquire the preset state switching condition corresponding to the state node from a pre-constructed detection condition database.

[0026] Further, the device further includes a database construction module, and the database construction module is configured to:

[0027] Screen out all target functions related to vehicle safety from the vehicle's entire vehicle function cluster;

[0028] For each function usage scenario corresponding to each target function among all target functions, determine the interaction logic of the electronic and electrical architecture in the vehicle corresponding to each function usage scenario;

[0029] According to the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario, determine the preset conditions for state switching in each function usage scenario;

[0030] According to the preset conditions for state switching corresponding to each function usage scenario among all target functions, construct the detection condition database.

[0031] Furthermore, the device further includes:

[0032] A log generation module, configured to generate an abnormal log record according to the actual state switching condition and upload it to the management platform if the preset state switching condition does not match the actual state switching condition.

[0033] In a third aspect, the present application provides an electronic device, including:

[0034] A processor;

[0035] A memory for storing executable instructions of the processor;

[0036] Wherein, the processor is configured to execute to implement a vehicle safety control method as provided in the first aspect.

[0037] In a fourth aspect, the present application provides a non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, enabling the electronic device to execute and implement a vehicle safety control method as provided in the first aspect.

[0038] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:

[0039] In the embodiments of the present application, by identifying the target function scenario in which the vehicle is currently located and obtaining the state topology corresponding to the target function scenario; when the vehicle is at any state node in the state topology corresponding to the target function scenario, obtaining the preset state switching condition corresponding to the state node and the actual state switching condition received by the vehicle's electronic devices corresponding to the state node at the current moment; if the preset state switching condition does not match the actual state switching condition, controlling the vehicle to exit the target function scenario, thereby being able to timely defend against the intrusion of illegal instructions, reducing the probability of the vehicle responding to illegal instructions, and thus improving the safety of the vehicle, and also improving the safety of the user's property and life. Description of the Drawings

[0040] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0041] Figure 1 It is a schematic flowchart of a vehicle safety control method provided by this application;

[0042] Figure 2 It is a state topology diagram of a ramp assist provided by this application;

[0043] Figure 3 It is a schematic structural diagram of a vehicle safety control device provided by this application;

[0044] Figure 4 It is a schematic structural diagram of an electronic device provided by this application. Specific embodiments

[0045] By providing a vehicle safety control method in the embodiments of this application, the technical problem in the prior art that only attack events can be detected and reported, but the attack events cannot be effectively defended is solved.

[0046] The technical solution of the embodiments of this application to solve the above technical problem is generally as follows:

[0047] A vehicle safety control method, the method includes: identifying a target function scenario in which the vehicle is currently located, and obtaining a state topology corresponding to the target function scenario; if the vehicle is in any state node in the state topology corresponding to the target function scenario, obtaining a preset state transition condition corresponding to the state node, and an actual state transition condition received by the vehicle's electronic devices corresponding to the state node at the current moment; determining whether the preset state transition condition matches the actual state transition condition; if the preset state transition condition does not match the actual state transition condition, controlling the vehicle to exit the target function scenario.

[0048] In an embodiment of the present application, the target function scenario in which the vehicle is currently located is identified, and the state topology corresponding to the target function scenario is obtained; when the vehicle is at any state node in the state topology corresponding to the target function scenario, the preset state transition condition corresponding to the state node and the actual state transition condition received by the vehicle electronic devices corresponding to the state node at the current moment are obtained; if the preset state transition condition does not match the actual state transition condition, the vehicle is controlled to exit the target function scenario, thereby being able to timely defend against the intrusion of illegal instructions, reduce the probability of the vehicle responding to illegal instructions, and thus improve the safety of the vehicle, and also improve the safety of the user's property and life.

[0049] To better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings of the specification and specific embodiments.

[0050] First, it should be noted that the term "and / or" appearing in this article is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the preceding and following associated objects.

[0051] This embodiment provides a Figure 1 vehicle safety control method as shown, and the method includes steps S11 - step S14.

[0052] Step S11, identify the target function scenario in which the vehicle is currently located, and obtain the state topology corresponding to the target function scenario;

[0053] Step S12, if the vehicle is at any state node in the state topology corresponding to the target function scenario, obtain the preset state transition condition corresponding to the state node and the actual state transition condition received by the vehicle electronic devices corresponding to the state node at the current moment;

[0054] Step S13, determine whether the preset state transition condition matches the actual state transition condition;

[0055] Step S14, if the preset state transition condition does not match the actual state transition condition, control the vehicle to exit the target function scenario.

[0056] A vehicle safety control method provided by this embodiment can be applied to a safety control system, and specifically can include a database component, a message analysis component, a condition configuration component, and an update engine component.

[0057] Functions of the database component: store basic system configuration data, conditional configuration data, update engine configuration data, and log record data of the intrusion detection and defense module.

[0058] Functions of the message analysis component: Filter and screen the signals inside the car and match the generated detection condition database to analyze threat events inside the car, and record log files at the same time.

[0059] Functions of the conditional configuration component: configure conditional files that can be recognized by in-vehicle components, and update the conditional library of in-vehicle components to repair in-vehicle vulnerabilities.

[0060] Function of the update engine component: In order to meet the update of the in-vehicle defense strategy, this component has networking capabilities. The update engine component in the vehicle will establish a connection with the cloud-based operation and maintenance management platform. If the cloud-based operation and maintenance management platform has new conditional configuration data, it will obtain the new conditional configuration data from the cloud.

[0061] Regarding step S11, the target functional scenario in which the vehicle is currently located is identified, and the state topology corresponding to the target functional scenario is obtained.

[0062] When the vehicle is in operation, multiple functions can be run at the same time. For example, when the vehicle is in operation, the vehicle player can play music and videos. Each function corresponds to a functional scene. For each functional scene that the vehicle is currently in, it can be used as a target functional scene, and steps S11 to S14 are executed respectively and in a targeted manner.

[0063] Based on the message analysis component, the vehicle's driving status can be obtained from the vehicle's electronic control unit. Then, according to the functional scenario of the vehicle in the driving status, each functional scenario is used as the target functional scenario. For each target functional scenario, the state topology corresponding to the target functional scenario is obtained. The state topology represents the different states involved in the target functional scenario in the whole process and the conditions for switching between different states.

[0064] For example, when the target functional scenario is hill assist, the corresponding state topology can be as follows: Figure 2As shown. If the C0 condition (hardware ignition) is met, the EPB (Electrical-Park-Brake) is in the initial state. If the C1 condition (wheel speed is valid and less than the minimum dynamic vehicle speed) is met, the EPB is in the static mode. If the C3 condition (no action on the EPB switch) is met, the EPB will remain in the static mode. If the C2 condition (the AUTO key is lit, and the AUTO key is the button for one-touch start) is met, the EPB is in the AUTO mode (i.e., the start mode). If the C4 condition (the driver's seat belt is fastened and the door is closed) is met, the EPB is in the working state. If the C5 condition is met, the EPB is automatically released, and thus the ramp assist scenario is exited. Among them, the C5 condition includes two parallel sub-conditions. One sub-condition is that the vehicle is in the D gear (drive gear), the throttle depth meets the preset condition, the engine torque meets the preset condition, and it is on an uphill slope. The other sub-condition is that the vehicle is in the R gear (reverse gear), the throttle depth meets the preset condition, the engine torque meets the preset condition, and it is on a downhill slope. If one of the sub-conditions in C5 is met, the EPB is automatically released, and thus the ramp assist scenario is exited.

[0065] Regarding step S12, if the vehicle is in any one of the state nodes in the state topology corresponding to the target function scenario, obtain the preset state transition condition corresponding to the state node, and the actual state transition condition received by the vehicle electronic devices corresponding to the state node at the current moment.

[0066] When the vehicle is in the target function scenario, it may receive illegal instructions from hackers. Currently, it is not possible to effectively distinguish between illegal instructions from hackers and normal instructions of the vehicle from the instructions themselves. Therefore, when the vehicle receives illegal instructions from hackers and normal instructions of the vehicle, it may respond to the illegal instructions from hackers or may also respond to the normal instructions of the vehicle. If the vehicle responds to the illegal instructions from hackers, it may lead to safety accidents. To solve this problem, the present embodiment provides the following technical concept to distinguish between illegal instructions and normal instructions.

[0067] Whether it is an illegal instruction or a normal instruction, there will be a corresponding instruction execution object, that is, the vehicle electronic devices corresponding to the state node. When the vehicle electronic devices receive an illegal instruction or a normal instruction, they will perform corresponding operations to cause the vehicle to switch from the current state to the next state.

[0068] This embodiment makes a judgment based on the message analysis component from the instruction content, that is, to determine whether the switching conditions contained in the instruction content corresponding to each state node switch are legal. When the target function scenario executes to any state node in the corresponding state topology, obtain the preset state switching condition corresponding to the state node, and the actual state switching condition received by the vehicle electronic device corresponding to the state node at the current moment, and continue to execute step S13.

[0069] Among them, the preset state switching condition is the condition for the vehicle to be able to normally switch from the current state node to the next state in the target function scenario, while the actual state switching condition is the state switching condition actually received by the vehicle electronic device.

[0070] The preset state switching condition can obtain the preset state switching condition corresponding to the state node from the pre-constructed detection condition database.

[0071] Among them, based on the database component and the condition configuration component, building the detection condition database includes steps S121 - S124.

[0072] Step S121, screen out all target functions related to vehicle safety from the vehicle's vehicle function cluster.

[0073] During the vehicle production and R & D process, a function cluster will be defined for the whole vehicle. The function cluster contains most of the functions that the vehicle can execute, and may even contain all the functions that the vehicle can execute. The vehicle function cluster can include functions related to remote control, functions related to cloud communication, functions related to short-range communication, functions related to local interfaces, and functions related to key services.

[0074] Screen out all target functions related to vehicle safety from the vehicle function cluster. Among them, the functions related to vehicle safety can be determined according to the actual situation of the vehicle.

[0075] For example, it can be determined whether a function has the possibility of being hacked by whether the corresponding function is directly connected to the in-vehicle network, or it can be determined whether a function has the possibility of being hacked by whether the corresponding function of the vehicle is directly connected to the out-of-vehicle network, or it can be determined whether a function has the possibility of being hacked by whether the corresponding function is indirectly linked to the vehicle network. Of course, it can also be determined whether a function has the possibility of being hacked by whether the corresponding function includes only software systems or hardware or advanced sensors.

[0076] Step S122, for the function usage scenario corresponding to each target function among all target functions, determine the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario in the vehicle.

[0077] Each target function corresponds to a function usage scenario, and each function usage scenario is executed and implemented by the corresponding electronic and electrical architecture. During the execution and implementation process, there will be information interaction in the electronic and electrical architecture, that is, there is an interaction logic. That is to say, according to each function usage scenario, the interaction logic of the corresponding electronic and electrical architecture is determined.

[0078] For example, for remote parking, the involved electronic and electrical architecture includes: remote parking application software (APP, application), telematics service provider (TSP), telematics box (TBOX), central computing unit (including vehicle control, gateway, ADAS control), chassis domain control (EPB, IPB (intelligent integrated braking system), EPS (Electronic Power Steering, power steering)), body domain control (BCM, Body Control Module, body control module), power domain control (motor, battery), etc.

[0079] The user can operate the remote parking instruction through the mobile phone APP; the instruction is forwarded to the telematics platform through the TSP platform, and the telematics platform establishes a two-way authentication and secure connection with the vehicle end; the TBOX receives the remote control parking instruction issued by the telematics platform, and the TBOX verifies the signature of the received remote control parking instruction to ensure security; the central computing unit performs vehicle power mode control, signal routing and forwarding, and ADAS-related function implementation.

[0080] In addition, the chassis domain is responsible for the implementation of braking, driving, steering, suspension adjustment, etc.; the body domain judges the body state, including whether the ambient perception light is on, and whether the doors and tailgate are closed; the power domain is responsible for receiving the torque request from the central computing unit to the motor, and judging the battery health status, etc.

[0081] Step S123, according to the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario, determine the preset conditions for state switching in each function usage scenario.

[0082] According to the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario, the switching sequence between each state and the switching conditions between adjacent two states in each function usage scenario can be determined. Usually, the switching conditions are preset according to the function usage scenario during vehicle R & D.

[0083] Step S124, according to the preset conditions for state switching corresponding to each function usage scenario in all target functions, construct the detection condition database.

[0084] According to the preset conditions for state switching corresponding to all function usage scenarios of all target functions, a corresponding detection condition database is constructed. When the vehicle is in a certain function usage scenario, the preset conditions for state switching in this scenario can be determined by querying the detection condition database.

[0085] Regarding step S13, it is determined whether the preset state switching condition matches the actual state switching condition.

[0086] Regarding step S14, if the preset state switching condition does not match the actual state switching condition, the vehicle is controlled to exit the target function scenario.

[0087] Determine whether the preset state switching condition matches the actual state switching condition. When the two match, it means that the current state switching is normal, and the state switching can be performed, and the target function scenario can be continued.

[0088] When the two do not match, it means that the actual state switching condition may be provided by a hacker or other illegal instructions. If the actual state switching condition is continuously responded to, it may cause a safety accident for the vehicle. At this time, the vehicle can be controlled to immediately exit the current target function scenario to prevent the vehicle from being continuously controlled by illegal instructions, thereby reducing the probability of a safety accident.

[0089] For example, when remotely parking, the corresponding preset state switching condition is that the vehicle speed is less than or equal to 5 km / h. If the actual state switching condition is that the vehicle speed is greater than 10 km / h, it means that the preset state switching condition does not match the actual state switching condition. At this time, the vehicle needs to immediately exit the remote parking to avoid a safety accident for the vehicle. If the actual state switching condition is that the vehicle speed is 4 km / h, it means that the preset state switching condition matches the actual state switching condition. At this time, the vehicle can continue to perform remote parking.

[0090] For another example, when remotely parking, the corresponding preset state switching condition is that the moving distance is less than or equal to 120 m. If the actual state switching condition is that the moving distance exceeds 120 m, it means that the preset state switching condition does not match the actual state switching condition. At this time, the vehicle needs to immediately exit the remote parking to avoid a safety accident for the vehicle.

[0091] If the actual state switching condition is that the moving distance is 100 m, it means that the preset state switching condition matches the actual state switching condition. At this time, the vehicle can continue to perform remote parking.

[0092] If the preset state transition condition does not match the actual state transition condition, it means that the actual state transition condition may be generated by an illegal instruction. Furthermore, based on the update engine component, an exception log record can be generated according to the actual state transition condition and uploaded to the management platform.

[0093] Based on the abnormal situation generated by the management platform according to the actual state transition condition, relevant personnel can be notified in a timely manner to conduct an investigation on the vehicle for abnormal events. In addition, the detection condition database can be updated according to the exception log record. When the same actual state transition condition as this time is received next time, the instruction corresponding to this condition can be directly ignored, thereby improving the safety of the vehicle.

[0094] In summary, in this embodiment, by identifying the target functional scenario where the vehicle is currently located and obtaining the state topology corresponding to the target functional scenario; when the vehicle is at any state node in the state topology corresponding to the target functional scenario, obtaining the preset state transition condition corresponding to the state node and the actual state transition condition received by the vehicle electronic device corresponding to the state node at the current moment; if the preset state transition condition does not match the actual state transition condition, controlling the vehicle to exit the target functional scenario, thereby being able to timely defend against the intrusion of illegal instructions, reducing the probability of the vehicle responding to illegal instructions, and thus improving the safety of the vehicle, and also improving the safety of the user's property and life.

[0095] Based on the same inventive concept, this embodiment provides a vehicle safety control device as shown in Figure 3 The device includes:

[0096] A state topology acquisition module 31, configured to identify the target functional scenario where the vehicle is currently located and obtain the state topology corresponding to the target functional scenario;

[0097] A switching condition acquisition module 32, configured to, if the vehicle is at any state node in the state topology corresponding to the target functional scenario, obtain the preset state transition condition corresponding to the state node and the actual state transition condition received by the vehicle electronic device corresponding to the state node at the current moment;

[0098] A matching module 33, configured to determine whether the preset state transition condition matches the actual state transition condition;

[0099] A function exit execution module 34, configured to, if the preset state transition condition does not match the actual state transition condition, control the vehicle to exit the target functional scenario.

[0100] Further, the switching condition acquisition module 32 includes:

[0101] A switching condition acquisition sub-module, configured to obtain the preset state switching condition corresponding to the state node from a pre-constructed detection condition database.

[0102] Further, the apparatus further includes a database construction module, and the database construction module is configured to:

[0103] Screen out all target functions related to vehicle safety from the vehicle's entire vehicle function cluster;

[0104] For the function usage scenarios corresponding to each target function among all target functions, determine the interaction logic of the electronic and electrical architecture in the vehicle corresponding to each function usage scenario;

[0105] According to the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario, determine the preset conditions for state switching in each function usage scenario;

[0106] According to the preset conditions for state switching corresponding to each function usage scenario among all target functions, constitute the detection condition database.

[0107] Further, the apparatus further includes:

[0108] A log generation module, configured to, if the preset state switching condition does not match the actual state switching condition, generate an abnormal log record according to the actual state switching condition and upload it to the management platform.

[0109] Based on the same inventive concept, this embodiment provides an electronic device as shown in Figure 4 and includes:

[0110] A processor;

[0111] A memory for storing executable instructions of the processor;

[0112] Wherein, the processor is configured to execute to implement a vehicle safety control method provided as described above.

[0113] Based on the same inventive concept, this embodiment provides a non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, enabling the electronic device to execute and implement a vehicle safety control method provided as described above.

[0114] Since the electronic device introduced in this embodiment is the electronic device used to implement the information processing method in the embodiments of the present application, based on the information processing method introduced in the embodiments of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiments of the present application will not be described in detail here. As long as the electronic device used by those skilled in the art to implement the information processing method in the embodiments of the present application falls within the scope protected by the present application.

[0115] The technical solutions in the above embodiments of the present application have at least the following technical effects or advantages:

[0116] In this embodiment, by identifying the target functional scenario where the vehicle is currently located and obtaining the state topology corresponding to the target functional scenario; when the vehicle is at any state node in the state topology corresponding to the target functional scenario, obtaining the preset state switching condition corresponding to the state node and the actual state switching condition received by the vehicle electronic devices corresponding to the state node at the current moment; if the preset state switching condition does not match the actual state switching condition, controlling the vehicle to exit the target functional scenario, thereby timely defending against the intrusion of illegal instructions, reducing the probability of the vehicle responding to illegal instructions, and further improving the safety of the vehicle, and thus improving the safety of the user's property and life.

[0117] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can be implemented in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can be implemented in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0118] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0119] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the function specified in one or more processes and / or blocks Figure 1 in the flowchart Figure 1 represented by one or more blocks or blocks.

[0120] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the function specified in one or more processes and / or blocks Figure 1 in the flowchart Figure 1 represented by one or more blocks or blocks.

[0121] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.

[0122] It is obvious that those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A vehicle safety control method, characterized in that, the method includes: When the vehicle is in an operating state, identify the target function scenario where the vehicle is currently located, and obtain the state topology corresponding to the target function scenario; the target function scenario includes hill-start assist. In the hill-start assist scenario, if the hardware ignition condition is met, the electronic parking brake system is in the initial state node; if the wheel speed is valid and less than the minimum dynamic vehicle speed condition is met, the electronic parking brake system is in the static mode node; if the condition that there is no operation on the electronic parking brake system switch is met, the electronic parking brake system will remain in the static mode node; if the condition that the start button is lit is met, the electronic parking brake system is in the start mode node; if the condition that the driver's seat belt is fastened and the door is closed is met, the electronic parking brake system is in the working state node; if the first sub-condition or the second sub-condition is met, the electronic parking brake system will be automatically released, and then the vehicle will exit the hill-start assist scenario; wherein, the first sub-condition is: the vehicle is in the drive gear, the throttle depth meets the preset condition, the engine torque meets the preset condition, and the vehicle is on an uphill; the second sub-condition is: the vehicle is in the reverse gear, the throttle depth meets the preset condition, the engine torque meets the preset condition, and the vehicle is on a downhill; If the vehicle is in any one of the state nodes in the state topology corresponding to the target function scenario, obtain the preset state transition condition corresponding to the state node in the state topology, and obtain the actual state transition condition received by the vehicle's entire vehicle electronic devices corresponding to the state node at the current moment; the preset state transition condition is used to indicate the condition for the vehicle to switch from the current state node to the next state in the target function scenario; Judge whether the preset state transition condition matches the actual state transition condition; If the preset state transition condition does not match the actual state transition condition, control the vehicle to exit the target function scenario.

2. The method according to claim 1, characterized in that, the obtaining of the preset state transition condition corresponding to the state node includes: Obtain the preset state transition condition corresponding to the state node from a pre-constructed detection condition database.

3. The method according to claim 2, characterized in that, Constructing the detection condition database includes: From the entire vehicle function cluster of the vehicle, screen out all target functions related to vehicle safety; For each function usage scenario corresponding to each target function among all target functions, determine the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario in the vehicle; According to the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario, determine the preset conditions for state transition in each function usage scenario; According to the preset conditions for state transition corresponding to each function usage scenario among all target functions, form the detection condition database.

4. The method according to claim 1, characterized in that, If the preset state transition condition does not match the actual state transition condition, the method further includes: Generate an exception log record according to the actual state transition condition and upload it to the management platform.

5. A vehicle safety control device, characterized in that, the device includes: A state topology acquisition module, which is used to identify the target function scenario where the vehicle is currently located and acquire the state topology corresponding to the target function scenario when the vehicle is in the running state; the target function scenario includes hill start assist. In the hill start assist scenario, if the hardware ignition condition is met, the electronic parking brake system is in the initial state node; if the wheel speed is valid and less than the minimum dynamic vehicle speed condition is met, the electronic parking brake system is in the static mode node; if the condition that there is no operation of the electronic parking brake system switch is met, the electronic parking brake system will remain in the static mode node; if the condition that the one - key start button is lit is met, the electronic parking brake system is in the start mode node; if the condition that the driver's seat belt is fastened and the door is closed is met, the electronic parking brake system is in the working state node; if the first sub - condition or the second sub - condition is met, the electronic parking brake system will be automatically released and then exit the hill start assist scenario; wherein, the first sub - condition is: the vehicle is in the drive gear, the throttle depth meets the preset condition, the engine torque meets the preset condition, and it is on an uphill slope; the second sub - condition is: the vehicle is in the reverse gear, the throttle depth meets the preset condition, the engine torque meets the preset condition, and it is on a downhill slope; A switching condition acquisition module, which is used to, if the vehicle is in any one of the state nodes corresponding to the state topology of the target function scenario, acquire the preset state switching condition corresponding to the state node in the state topology, and acquire the actual state switching condition received by the vehicle's whole - vehicle electronic devices corresponding to the state node at the current moment; the preset state switching condition is used to indicate the condition for the vehicle to switch from the current state node to the next state in the target function scenario; A matching module, which is used to judge whether the preset state switching condition matches the actual state switching condition; A function exit execution module, which is used to, if the preset state switching condition does not match the actual state switching condition, control the vehicle to exit the target function scenario.

6. The device according to claim 5, characterized in that, the switching condition acquisition module includes: A switching condition acquisition sub - module, which is used to acquire the preset state switching condition corresponding to the state node from a pre - constructed detection condition database.

7. The device according to claim 6, characterized in that, the device further includes a database construction module, and the database construction module is used for: screening out all target functions related to vehicle safety from the whole - vehicle function cluster of the vehicle; determining the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario for each target function among all target functions; determining the preset condition for state switching in each function usage scenario according to the interaction logic of the electronic and electrical architecture corresponding to each function usage scenario; constituting the detection condition database according to the preset conditions for state switching corresponding to each function usage scenario among all target functions.

8. The device according to claim 5, characterized in that, the device further includes: A log generation module, configured to generate an exception log record according to the actual status switching condition and upload it to the management platform if the preset status switching condition does not match the actual status switching condition.

9. An electronic device, characterized in that, it comprises: a processor; a memory for storing executable instructions of the processor; wherein, the processor is configured to execute to implement a vehicle safety control method according to any one of claims 1 to 4.

10. A non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, enabling the electronic device to execute and implement a vehicle safety control method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Attack defense method, device and equipment and storage medium

    CN111726774A

  • Remote starting method and system of vehicle, storage medium and vehicle

    CN114312657A