Protection Method for Vehicle Communication Security and Related Devices
By authenticating the external communication module to which the vehicle belongs when receiving external command information, the problem of lack of security protection when the vehicle interacts with the external network is solved, ensuring the reliability of external commands and improving vehicle communication security.
Patent Information
- Application Number
- CN202210852767.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-19
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-07-19
AI Technical Summary
The prior art lacks effective security protection methods when interacting with external networks, and cannot effectively judge the reliability of external manipulation information.
When receiving external command information, the external communication module to which it belongs is authenticated and the authentication result is sent to the target control module to determine the unlocking action.
Authentication ensures the reliability of external instruction information, prevents external communication modules from being replaced or intruded, thereby preventing the vehicle from receiving and executing erroneous or malicious instructions, and improving the protection capability of vehicle communication security.
Smart Images

Figure CN115412291B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle communication security, and particularly to a protection method for vehicle communication security and related devices. Background Art
[0002] The traditional vehicle electronic and electrical architecture is based on a distributed architecture, with relatively few interactions between the vehicle and the outside. Therefore, fewer measures are taken for vehicle safety protection. With the development of the new four modernizations and the vehicle's electronic and electrical architecture, the functions of vehicle intelligent networking have gradually become more powerful, and the interactions between the vehicle and the outside have become more frequent. Messages from external networks have become more complex, and the vehicle's architecture has changed significantly. The application of a central integrated large computing power platform has also posed more challenges to the vehicle's safety protection system. However, in the prior art, when external control information is sent to the vehicle, there is no better method to judge the reliability of the information. Summary of the Invention
[0003] In view of the above problems, the present invention provides a protection method for vehicle communication security and related devices, mainly aiming to solve the problem of lacking a better safety protection method when the vehicle operates based on external information.
[0004] To solve the above-mentioned at least one technical problem, in a first aspect, the present invention provides a protection method for vehicle communication security, the method comprising:
[0005] When receiving external instruction information, authenticate the external communication module to which the external instruction information belongs;
[0006] Send the authentication result to the target control module corresponding to the external instruction information so that the target control module determines an unlocking action based on the authentication result.
[0007] Optionally, the external instruction information includes: remote control information and Bluetooth key authentication information, wherein the external communication module to which the remote control information belongs is a remote control module, and the external communication module to which the Bluetooth key authentication information belongs is a Bluetooth key authentication module.
[0008] Optionally, the method further comprises:
[0009] When the vehicle is powered on, the vehicle central computing unit performs identity authentication through a server to determine the correspondence between the vehicle central computing unit and the vehicle.
[0010] Optionally, when receiving external instruction information, authenticating the external communication module to which the external instruction information belongs includes:
[0011] Based on the message count and check value of the above external communication module, authenticate the external communication module to which the above external instruction information belongs through key calculation.
[0012] Optionally, the above sending the authentication result to the target control module corresponding to the above external instruction information so that the target control module determines an unlocking action based on the above authentication result includes:
[0013] In the case where the above authentication result is authentication success, broadcast the result of successful authentication to the target control module corresponding to the above external instruction information so that the target control module unlocks and executes the above external instruction information.
[0014] In the case where the above authentication result is authentication failure, broadcast the result of failed authentication to the target control module corresponding to the above external instruction information so that the target control module remains locked.
[0015] Optionally, the above method further includes:
[0016] Return the authentication result to the external communication module to which the above external instruction information belongs;
[0017] In the case where the external communication module to which the above external instruction information belongs does not receive the above authentication result within a preset time, resend the above external instruction information;
[0018] In the case where the number of times of resending the above external instruction information is greater than a preset number of times, re-obtain network authentication.
[0019] Optionally, the above method further includes:
[0020] In the case of vehicle power-off reconnection or restart, re-authenticate the external communication module to which the above external instruction information belongs.
[0021] In a second aspect, an embodiment of the present invention further provides a vehicle communication security protection device, including:
[0022] An authentication unit, configured to authenticate the external communication module to which the above external instruction information belongs when receiving the external instruction information;
[0023] A determination unit, configured to send the authentication result to the target control module corresponding to the above external instruction information so that the target control module determines an unlocking action based on the above authentication result.
[0024] To achieve the above object, according to a third aspect of the present invention, there is provided a computer-readable storage medium, where the computer-readable storage medium includes a stored program, and when the program is executed by a processor, the steps of the above vehicle communication security protection method are implemented.
[0025] To achieve the above object, according to the fourth aspect of the present invention, there is provided an electronic device, including at least one processor and at least one memory connected to the above-mentioned processor; wherein, the above-mentioned processor is used to call program instructions in the above-mentioned memory and execute the steps of the above-mentioned vehicle communication security protection method.
[0026] By means of the above technical solution, for the problem that there is a lack of a better security protection method when a vehicle operates based on external information, the present invention authenticates the external communication module to which the above external instruction information belongs when receiving the external instruction information; and sends the authentication result to the target control module corresponding to the above external instruction information so that the above target control module determines an unlocking action based on the above authentication result. In the above solution, when the vehicle needs to operate on itself upon receiving external information, the external communication module to which the external instruction information belongs is authenticated. In the case of successful authentication, the corresponding external instruction information is executed, ensuring the reliability of the external communication module that processes and transmits the external instruction information, thereby preventing the external communication module from being replaced or invaded, and further preventing the vehicle from receiving and executing incorrect or malicious external instruction information. Moreover, since this solution is implemented based on a service-oriented architecture, it ensures the convenience, real-time nature, and traceability of the authentication process.
[0027] Correspondingly, the vehicle communication security protection device, equipment, and computer-readable storage medium provided by the embodiments of the present invention also have the above technical effects.
[0028] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the description. And in order to make the above and other objects, features, and advantages of the present invention more obvious and understandable, the following specifically describes the embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0030] Figure 1 It shows a schematic flow chart of a vehicle communication security protection method provided by an embodiment of the present invention;
[0031] Figure 2 It shows a schematic block diagram of the composition of a vehicle communication security protection device provided by an embodiment of the present invention;
[0032] Figure 3 The schematic block diagram of the composition of a protective electronic device for vehicle communication security provided by an embodiment of the present invention is shown. Specific embodiments
[0033] Exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present invention can be more thoroughly understood and the scope of the present invention can be fully conveyed to those skilled in the art.
[0034] To solve the problem that there is a lack of a better security protection method when a vehicle operates based on external information, an embodiment of the present invention provides a protection method for vehicle communication security, as Figure 1 shown, the method includes:
[0035] S101. When receiving external instruction information, authenticate the external communication module to which the external instruction information belongs;
[0036] Exemplarily, the CCU (Center Computing Unit, vehicle central computing unit) mainly integrates modules such as an external communication module, a vehicle control module, an autonomous driving module, and an intelligent cockpit module.
[0037] The VIU (Vehicle Intranet Unit, vehicle intranet unit) mainly integrates sensors, actuators, etc. The vehicle intranet units at different positions are responsible for performing different functions, mainly including:
[0038] VIU-F (Vehicle Intranet Unit Front, vehicle front control unit): motor module, transmission module, etc.
[0039] VIU-R (Vehicle Intranet Unit Rear, vehicle rear control unit): audio module, charger module
[0040] VIU-ML (Vehicle Intranet Unit Middle Left, vehicle middle left control unit), Bluetooth key module, steering wheel switch module
[0041] VIU-MR (Vehicle Intranet Unit Middle Right, vehicle middle right control unit): atmosphere lamp module, air conditioning module, etc.
[0042] The above architecture constitutes the central computing platform architecture, and this solution is implemented based on the above architecture of the central computing platform. Among them, the external communication module is a relatively independent hardware component, including a communication module, a 4G / 5G network card, and a clock, etc. Among them, the communication module is provided with a dedicated operator communication channel to ensure the security of the dedicated line connection to the server. The external communication module is provided with a SOME / IP client, and a SOME / IP server is set in the vehicle central computing unit. Both the external communication module and the vehicle central computing unit subscribe to the security protection authentication service VI_Auth_Sec. Among them, the above security protection authentication service VI_Auth_Sec refers to setting a software component (SWC) at the application layer, named the security protection authentication service VI_Auth_Sec, which involves services such as interface design. The main functions include the use and distribution of keys. This SWC is used in all scenarios in the vehicle related to security authentication. The OEM key management system KMS is responsible for issuing keys. If the key in the vehicle is leaked, KMS will trigger the generation of a new key and send it to the vehicle central computing unit. The vehicle central computing unit will write the key into the hardware security module, and at the same time, distribute the new key to the external communication module and VIU-ML. Because in the vehicle, generally only the external communication module and the VIU-ML in the intranet unit are responsible for interacting with the outside and performing operations based on the external instruction information.
[0043] The whole vehicle is initially in a sleep-locked state. When the vehicle central computing unit receives the above external instruction information sent by the external communication module, the vehicle is woken up from sleep. The vehicle central computing unit will broadcast a SOME / IP message named Notify_Auth_result with an unauthenticated status, that is, the whole vehicle is still in a locked state. The external communication module sends a message for security authentication with the vehicle central computing unit. After receiving the authentication message sent by the external communication module, the vehicle central computing unit authenticates the external communication module to determine whether the above external communication module is trustworthy, and further ensures whether the above external instruction information received and processed by the external communication module is trustworthy.
[0044] S102. Send the authentication result to the target control module corresponding to the above external instruction information so that the target control module determines the unlocking action based on the above authentication result.
[0045] Exemplarily, the vehicle central computing unit sends the authentication result of the above external communication module to the target control module corresponding to the above external instruction information through a message with the SOME / IP message name Notify_Auth_result.
[0046] If the above external communication module is trustworthy, it proves that the external instruction information sent to the central computing unit is trustworthy. Therefore, the target control module corresponding to the above external instruction information can be unlocked, enabling the above target control module to perform corresponding operations according to the above external instruction information. For example, when the vehicle receives external instruction information for turning on the air conditioner, authenticate the external communication module corresponding to the above instruction information for turning on the air conditioner, and send the result of whether the above external communication module is authenticated to the air conditioner control module. The air conditioner control module determines whether to unlock based on the result of whether the above external communication module is authenticated.
[0047] With the above technical solution, for the problem that there is a lack of a better security protection method when the vehicle operates based on external information, the vehicle communication security protection method provided by the present invention authenticates the external communication module to which the above external instruction information belongs when receiving the external instruction information; sends the authentication result to the target control module corresponding to the above external instruction information so that the above target control module determines the unlocking action based on the above authentication result. In the above solution, when the vehicle needs to operate on itself upon receiving external information, it authenticates the external communication module to which the external instruction information belongs. In the case of successful authentication, it executes the corresponding external instruction information to ensure the reliability of the external communication module that processes and transmits the external instruction information, thereby preventing the external communication module from being replaced or invaded, which may lead to the vehicle receiving and executing incorrect or malicious external instruction information. Moreover, since this solution is implemented based on the service-oriented architecture, it ensures the convenience, real-time nature, and traceability of the authentication process.
[0048] In one embodiment, the above external instruction information includes: remote control information and Bluetooth key authentication information. Among them, the external communication module to which the above remote control information belongs is the remote control module, and the external communication module to which the above Bluetooth key authentication information belongs is the Bluetooth key authentication module.
[0049] Exemplarily, the above external instruction information can be remote control information or Bluetooth key authentication information. Among them, the remote control information can be control information such as turning on the air conditioner, heating the battery pack, heating the seat, etc., and the above Bluetooth key authentication information can be information sent via the Bluetooth key such as opening the door, opening the trunk, closing the door, closing the trunk, etc.
[0050] Exemplarily, in the case where the above external instruction information is remote control information, the remote control module sends a SOME / IP message named RR_Auth_TSignalcall for security authentication with the vehicle central computing unit; after receiving the authentication message sent by the remote control module, the vehicle central computing unit performs authentication, and the vehicle central computing unit returns the authentication result to the remote control module through a SOME / IP message named RR_Auth_TSignalreturn.
[0051] Exemplarily, in the case where the above external instruction information is Bluetooth key authentication information, the Bluetooth key authentication module sends a SOME / IP message named RR_Auth_KSignalcall for security authentication with the vehicle central computing unit. After receiving the authentication message sent by the Bluetooth key authentication module, the vehicle central computing unit performs authentication, and the vehicle central computing unit returns the authentication result to the Bluetooth key authentication module through a SOME / IP message named RR_Auth_KSignalreturn.
[0052] In one embodiment, the above method further includes:
[0053] When the vehicle is powered on, the above vehicle central computing unit performs identity authentication through a server to determine the corresponding relationship between the above vehicle central computing unit and the above vehicle.
[0054] Exemplarily, after the vehicle is powered on, the central computing unit will automatically establish a secure identity authentication with the cloud server to ensure that the central computing unit and the vehicle have a unique corresponding relationship. The above authentication can be through methods such as verifying certificates, thus ensuring that the central computing unit has not been illegally replaced or invaded.
[0055] In one embodiment, in the case of receiving external instruction information, authenticating the external communication module to which the above external instruction information belongs includes:
[0056] Authenticating the external communication module to which the above external instruction information belongs through key calculation based on the message count and check value of the above external communication module.
[0057] Exemplarily, when the above vehicle central computing unit receives the above external instruction information sent by the external communication module, it will also receive an authentication request sent by the above external communication module, including: message count and check value. The vehicle central computing unit performs comparison through key calculation based on the above message count and check value to determine whether the external communication module that sent the above external instruction information is trustworthy.
[0058] Exemplarily, the external communication module based on the above-mentioned message count and verification value is authenticated through key calculation for the external communication module to which the above-mentioned external instruction information belongs. Specifically, it can be: the message count and the transmitted replay verification value sent by the external communication module are used to calculate the transmitted MAC value through key calculation, and the received MAC value is calculated through the message count and the received replay verification value through key calculation. It is judged whether the received replay verification value and the transmitted replay verification value meet the preset rules, and it is judged whether the transmitted MAC value and the received MAC value are consistent. Only when both conditions are met can it be determined that the external communication module passes. Thereby improving the security of message transmission, preventing the vehicle from being illegally controlled, and improving the security of the vehicle.
[0059] In one embodiment, the above-mentioned sending the authentication result to the target control module corresponding to the above-mentioned external instruction information so that the target control module determines the unlocking action based on the above-mentioned authentication result includes:
[0060] In the case where the above-mentioned authentication result is authentication success, the result of the above-mentioned authentication success is broadcast to the target control module corresponding to the above-mentioned external instruction information so that the target control module unlocks and executes the above-mentioned external instruction information.
[0061] In the case where the above-mentioned authentication result is authentication failure, the result of the above-mentioned authentication failure is broadcast to the target control module corresponding to the above-mentioned external instruction information so that the target control module remains in the locked state.
[0062] Exemplarily, the vehicle central computing unit performs comparison through key calculation based on the message count and verification value sent by the above-mentioned external communication module. If the comparison is successful, it proves that the external communication module to which the above-mentioned external instruction information belongs is trustworthy, and the result of the above-mentioned authentication success is broadcast to the target control module corresponding to the above-mentioned external instruction information so that the target control module unlocks and executes the above-mentioned external instruction information. If the comparison is unsuccessful, it proves that the external communication module to which the above-mentioned external instruction information belongs is untrustworthy, and the result of the above-mentioned authentication failure is broadcast to the target control module corresponding to the above-mentioned external instruction information so that the target control module remains in the locked state.
[0063] Exemplarily, in the case where the above-mentioned external instruction information is remote control information, if the authentication is successful, the vehicle central computing unit broadcasts a SOME / IP message named Notify_Auth_result = pass, considering the external communication module as a legal and trustworthy terminal component. If the authentication is unsuccessful, the vehicle central computing unit broadcasts a SOME / IP message named Notify_Auth_result = failed, considering the external communication module as an illegal and untrustworthy terminal component.
[0064] For example, when the vehicle central computing unit receives the air conditioner activation instruction information (remote control information) sent by the remote control module (external communication module), it authenticates the above-mentioned remote control module. After the above-mentioned remote control module passes the authentication, it sends the result of successful authentication to the air conditioner control module (target control module), and the air conditioner control module unlocks and activates the air conditioner.
[0065] Exemplarily, when the above external instruction information is Bluetooth key authentication information, if the authentication is successful, the vehicle central computing unit broadcasts a SOME / IP message named Notify_Auth_result=pass, considering that the Bluetooth key authentication module, namely VIU-ML, is a legal and trustworthy terminal component. The user's instruction to start the vehicle can be normally executed in the vehicle, the vehicle can be powered on high voltage, the gear can be normally shifted, and the driving function is normal, etc. If the authentication fails, the vehicle central computing unit broadcasts a SOME / IP message named Notify_Auth_result=failed, considering that the Bluetooth key authentication module, namely VIU-ML, is an illegal and untrustworthy terminal component.
[0066] For example, when the vehicle central computing unit receives the door opening instruction information (Bluetooth key authentication information) sent by the Bluetooth key authentication module (external communication module), it authenticates the above-mentioned Bluetooth key authentication module. After the above-mentioned Bluetooth key authentication module fails the authentication, it sends the result of failed authentication to the door control module (target control module), and the door control module remains locked.
[0067] In one embodiment, the above method further includes:
[0068] Returning the authentication result to the external communication module to which the above external instruction information belongs;
[0069] In the case where the external communication module to which the above external instruction information belongs does not receive the above authentication result within a preset time, resending the above external instruction information;
[0070] In the case where the number of times of resending the above external instruction information is greater than the preset number of times, re-obtaining network authentication.
[0071] Exemplarily, the vehicle central computing unit determines whether the external communication module to which the above external instruction information belongs is trustworthy by comparing through key calculation based on the message count and check value of the above external communication module, and sends the authentication result of the above external communication module to the external communication module by replying a SOME / IP message named RR_Auth_Tsignalreturn or RR_Auth_KSignalreturn, and displays the result of "authentication passed" or "authentication failed" on the vehicle display or other devices.
[0072] Exemplarily, a timeout retransmission mechanism is set. After the external communication module sends the external instruction information, if the authentication result is not received within a preset time, the external instruction information is resent. The preset time can be 200 ms. If the number of retransmissions is greater than a preset number, the vehicle is controlled to sleep and then woken up again. When the in-vehicle network is reconnected, the external instruction information and the message are resent again. The preset number can be 4 times, which is not specifically limited here and can be determined according to the actual business situation.
[0073] In one embodiment, the above method further includes:
[0074] When the vehicle is powered off and reconnected or restarted, the external communication module to which the external instruction information belongs is authenticated again.
[0075] Exemplarily, if the vehicle is powered off and reconnected or restarted due to an abnormal situation, the vehicle central computing unit will not save the previous authentication result, and the external communication module needs to authenticate with the vehicle central computing unit again. The authentication process is as follows: After the vehicle central computing unit restarts, it sends an unauthenticated authentication status through a Notify message. The external communication module receives the unauthenticated authentication status and then sends the above external instruction information and message.
[0076] Exemplarily, in the above solution, since the above keys are all uniformly generated and issued by the key management system, the security of the keys can be guaranteed. At the same time, both the vehicle central computing unit and the VIU have hardware security modules to protect the security of the keys. If the result of the above authentication is failure, both the vehicle central computing unit and the VIU will record detailed fault codes for easy maintenance and problem troubleshooting. This solution effectively solves the vehicle security problems caused by the legitimacy issues of remote control and keys through the vehicle security protection system based on the service-oriented architecture using the SOME / IP protocol. At the same time, the service-oriented architecture ensures the convenience, real-time performance, and traceability of the authentication process.
[0077] Further, as an implementation of the above Figure 1 shown method, an embodiment of the present invention also provides a protection device for vehicle communication security for implementing the above Figure 1 shown method. This device embodiment corresponds to the foregoing method embodiment. For easy reading, the details in the foregoing method embodiment will not be repeated one by one in this device embodiment. However, it should be clear that the device in this embodiment can correspondingly implement all the content in the foregoing method embodiment. As Figure 2 shown, the device includes: an authentication unit 21 and a determination unit 22, where
[0078] An authentication unit 21, configured to authenticate an external communication module to which the external instruction information belongs when receiving the external instruction information;
[0079] A determination unit 22, configured to send the authentication result to a target control module corresponding to the external instruction information, so that the target control module determines an unlocking action based on the authentication result.
[0080] Exemplarily, the external instruction information includes: remote control information and Bluetooth key authentication information, where the external communication module to which the remote control information belongs is a remote control module, and the external communication module to which the Bluetooth key authentication information belongs is a Bluetooth key authentication module.
[0081] Exemplarily, the unit is further configured to:
[0082] When the vehicle is powered on, the vehicle central computing unit performs identity authentication through a server to determine the correspondence between the vehicle central computing unit and the vehicle.
[0083] Exemplarily, when receiving the external instruction information, authenticating the external communication module to which the external instruction information belongs includes:
[0084] Authenticating the external communication module to which the external instruction information belongs through key calculation based on the message count and check value of the external communication module.
[0085] Exemplarily, sending the authentication result to the target control module corresponding to the external instruction information so that the target control module determines an unlocking action based on the authentication result includes:
[0086] When the authentication result is authentication success, broadcasting the authentication success result to the target control module corresponding to the external instruction information so that the target control module unlocks and executes the external instruction information;
[0087] When the authentication result is authentication failure, broadcasting the authentication failure result to the target control module corresponding to the external instruction information so that the target control module remains in the locked state.
[0088] Exemplarily, the unit is further configured to:
[0089] Returning the authentication result to the external communication module to which the external instruction information belongs;
[0090] When the external communication module to which the external instruction information belongs does not receive the authentication result within a preset time, resending the external instruction information;
[0091] In the case that the number of times of resending the above external instruction information is greater than the preset number of times, re-obtain network authentication.
[0092] Exemplarily, the above unit is further configured to:
[0093] In the case of vehicle power-off and reconnection or restart, re-authenticate the external communication module to which the above external instruction information belongs.
[0094] By means of the above technical solution, for the problem that there is a lack of a better security protection method when the vehicle operates based on external information, the vehicle communication security protection device provided by the present invention authenticates the external communication module to which the above external instruction information belongs when receiving the external instruction information; sends the authentication result to the target control module corresponding to the above external instruction information so that the target control module determines the unlocking action based on the above authentication result. In the above solution, when the vehicle needs to operate on the vehicle itself upon receiving external information, the external communication module to which the external instruction information belongs is authenticated. In the case of successful authentication, the corresponding external instruction information is executed, ensuring the reliability of the external communication module for processing and transmitting the external instruction information, thereby preventing the external communication module from being replaced or invaded and then causing the vehicle to receive and execute incorrect or malicious external instruction information. And since this solution is implemented for the service-oriented architecture, it ensures the convenience, real-time nature, and traceability of the authentication process.
[0095] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, a vehicle communication security protection method can be realized, which can solve the problem that there is a lack of a better security protection method when the vehicle operates based on external information.
[0096] The embodiment of the present invention provides a computer-readable storage medium, and the above computer-readable storage medium includes a stored program, and when the program is executed by a processor, the above vehicle communication security protection method is realized.
[0097] The embodiment of the present invention provides a processor, and the above processor is used to run a program, wherein when the above program runs, the above vehicle communication security protection method is executed.
[0098] The embodiment of the present invention provides an electronic device, and the above electronic device includes at least one processor and at least one memory connected to the above processor; wherein, the above processor is used to call the program instructions in the above memory and execute the vehicle communication security protection method as described above
[0099] The embodiment of the present invention provides an electronic device 30, as Figure 3As shown, the electronic device includes at least one processor 301, at least one memory 302 connected to the processor, and a bus 303; wherein, the processor 301 and the memory 302 communicate with each other through the bus 303; the processor 301 is used to call program instructions in the memory to execute the above-mentioned vehicle communication security protection method.
[0100] The intelligent electronic device in this article can be a PC, PAD, mobile phone, etc.
[0101] This application also provides a computer program product, which, when executed on a process management electronic device, is suitable for executing a program initialized with the following method steps:
[0102] When receiving external instruction information, authenticate the external communication module to which the external instruction information belongs;
[0103] Send the authentication result to the target control module corresponding to the above external instruction information so that the target control module determines an unlocking action based on the authentication result.
[0104] Furthermore, the above external instruction information includes: remote control information and Bluetooth key authentication information, wherein, the external communication module to which the remote control information belongs is a remote control module, and the external communication module to which the Bluetooth key authentication information belongs is a Bluetooth key authentication module.
[0105] Furthermore, the above method further includes:
[0106] When the vehicle is powered on, the vehicle central computing unit performs identity authentication through the server to determine the correspondence between the vehicle central computing unit and the vehicle.
[0107] Furthermore, when receiving external instruction information, authenticating the external communication module to which the external instruction information belongs includes:
[0108] Authenticate the external communication module to which the external instruction information belongs through key calculation based on the message count and check value of the external communication module.
[0109] Furthermore, sending the authentication result to the target control module corresponding to the above external instruction information so that the target control module determines an unlocking action based on the authentication result includes:
[0110] When the authentication result is authentication success, broadcast the authentication success result to the target control module corresponding to the above external instruction information so that the target control module unlocks and executes the above external instruction information.
[0111] In the case where the above authentication result is authentication failure, broadcast the above authentication failure result to the target control module corresponding to the above external instruction information so that the above target control module remains in a locked state.
[0112] Further, the above method further includes:
[0113] Return the authentication result to the external communication module to which the above external instruction information belongs;
[0114] In the case where the external communication module to which the above external instruction information belongs does not receive the above authentication result within a preset time, resend the above external instruction information;
[0115] In the case where the number of times of resending the above external instruction information is greater than a preset number of times, re-obtain network authentication.
[0116] Further, the above method further includes:
[0117] In the case of vehicle power-off reconnect or restart, re-authenticate the external communication module to which the above external instruction information belongs.
[0118] This application is described with reference to the flowcharts and / or block diagrams of methods, electronic devices (systems), and computer program products according to embodiments of this application. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable process management electronic devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable process management electronic devices generate means for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks
[0119] In a typical configuration, an electronic device includes one or more processors (CPUs), a memory, and a bus. The electronic device may also include an input / output interface, a network interface, etc.
[0120] The memory may include non-permanent memory in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip. The memory is an example of a computer-readable medium.
[0121] A computer-readable medium includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer-readable storage media for a computer include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage electronic devices, or any other non-transmission medium that can be used to store information that can be accessed by a computing electronic device. As defined herein, a computer-readable medium does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0122] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or electronic device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or electronic device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or electronic device comprising the element.
[0123] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, system, or computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0124] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A method for protecting vehicle communication security, the vehicle comprising: An external communication module for receiving external instruction information, a target control module for performing a target function according to the instruction information, and a vehicle central computing unit, wherein the vehicle central computing unit is communicatively connected to the external communication module and the target control module. It is characterized in that the method is used for the vehicle central computing unit, and the method includes: Authenticating the external communication module to which the external instruction information belongs when the external instruction information is received; Sending the authentication result to the target control module corresponding to the external instruction information so that the target control module determines an unlocking action based on the authentication result; The authenticating the external communication module to which the external instruction information belongs when the external instruction information is received includes: Authenticating the external communication module to which the external instruction information belongs through key calculation based on the message count and check value of the external communication module; The authenticating the external communication module to which the external instruction information belongs through key calculation based on the message count and check value of the external communication module includes: Calculating a sending MAC value through key calculation using the message count and sending replay check value sent by the external communication module, calculating a receiving MAC value through key calculation using the message count and receiving replay check value, determining whether the receiving replay check value and the sending replay check value meet a preset rule, and determining whether the sending MAC value and the receiving MAC value are consistent. If both conditions are met, it is determined that the external communication module passes; The sending the authentication result to the target control module corresponding to the external instruction information so that the target control module determines an unlocking action based on the authentication result includes: When the authentication result is authentication success, broadcasting the authentication success result to the target control module corresponding to the external instruction information so that the target control module unlocks and executes the external instruction information; When the authentication result is authentication failure, broadcasting the authentication failure result to the target control module corresponding to the external instruction information so that the target control module remains in the locked state; Returning the authentication result to the external communication module to which the external instruction information belongs; When the external communication module to which the external instruction information belongs does not receive the authentication result within a preset time, resending the external instruction information; When the number of times of resending the external instruction information is greater than a preset number of times, re-obtaining network authentication.
2. The method according to claim 1, wherein, The external instruction information includes: remote control information and Bluetooth key authentication information, wherein the external communication module to which the remote control information belongs is a remote control module, and the external communication module to which the Bluetooth key authentication information belongs is a Bluetooth key authentication module.
3. The method according to claim 1, wherein, It further includes: When the vehicle is powered on, the vehicle central computing unit performs identity authentication through a server to determine the correspondence between the vehicle central computing unit and the vehicle.
4. The method according to claim 1, wherein, It further includes: When the vehicle is powered off and reconnected or restarted, re-authenticating the external communication module to which the external instruction information belongs.
5. A device for protecting vehicle communication security, wherein, It includes: An authentication unit, configured to authenticate an external communication module to which the external instruction information belongs when receiving the external instruction information; A determination unit, configured to send the authentication result to a target control module corresponding to the external instruction information so that the target control module determines an unlocking action based on the authentication result; The authenticating, when receiving the external instruction information, the external communication module to which the external instruction information belongs, includes: Authenticating the external communication module to which the external instruction information belongs through key calculation based on the message count and check value of the external communication module; The authenticating the external communication module to which the external instruction information belongs through key calculation based on the message count and check value of the external communication module includes: Calculating a transmission MAC value through key calculation using the message count and transmission replay check value sent by the external communication module, calculating a reception MAC value through key calculation using the message count and reception replay check value, determining whether the reception replay check value and the transmission replay check value meet a preset rule, and determining whether the transmission MAC value and the reception MAC value are consistent. When both conditions are met, it is determined that the external communication module passes; The sending the authentication result to the target control module corresponding to the external instruction information so that the target control module determines an unlocking action based on the authentication result includes: When the authentication result is authentication success, broadcasting the authentication success result to the target control module corresponding to the external instruction information so that the target control module unlocks and executes the external instruction information; When the authentication result is authentication failure, broadcasting the authentication failure result to the target control module corresponding to the external instruction information so that the target control module remains in a locked state; Returning the authentication result to the external communication module to which the external instruction information belongs; When the external communication module to which the external instruction information belongs does not receive the authentication result within a preset time, resending the external instruction information; When the number of times of resending the external instruction information is greater than a preset number of times, re-obtaining network authentication.
6. A computer-readable storage medium, wherein, The computer-readable storage medium includes a stored program, wherein when the program is executed by a processor, the steps of the vehicle communication security protection method according to any one of claims 1 to 4 are implemented.
7. An electronic device, characterized in that, The electronic device includes at least one processor and at least one memory connected to the processor; wherein, the processor is configured to call program instructions in the memory and execute the steps of the vehicle communication security protection method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Method for remotely controlling vehicle
CN103770742A
Key unit and vehicle having key unit
CN109695379A
Message encryption method and related equipment
CN114301623A