Method and device for detecting tampering of ecu data, electronic equipment and storage medium

By calculating and comparing state characteristic parameters in the ECU, the problems of immediacy and high cost in ECU data tampering detection are solved, realizing an instant and low-cost self-detection method.

CN115981953BActive Publication Date: 2026-07-21WEICHAI POWER CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WEICHAI POWER CO LTD
Filing Date
2022-12-13
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing ECU data tampering detection methods are not timely and costly, and cannot detect ECU data tampering behavior in a timely manner.

Method used

By acquiring the state characteristic parameters of the current driving cycle from the ECU, calculating the state characteristic value of the current driving cycle, and comparing it with the pre-stored initial state characteristic value, it is determined whether data tampering has occurred, generates alarm information, and triggers vehicle torque limiting operation.

Benefits of technology

It enables real-time detection of ECU data tampering, reduces detection costs, improves the timeliness of detection, and can achieve self-detection without the need for external devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115981953B_ABST
    Figure CN115981953B_ABST
Patent Text Reader

Abstract

The application provides an ECU data tampering detection method and device, electronic equipment and a storage medium. The method comprises: obtaining a state characteristic parameter of a current driving cycle in the ECU; determining an initial state characteristic value of the ECU according to a pre-stored state structure array in the ECU; calculating a state characteristic value of the ECU in the current driving cycle according to the state characteristic parameter of the current driving cycle in the ECU; and determining that data tampering occurs in the current driving cycle of the ECU when it is judged that the state characteristic value of the ECU in the current driving cycle is not identical to the initial state characteristic value. The application calculates a state characteristic value representing the current driving cycle of the ECU by using the state characteristic parameter of the current driving cycle in the ECU, and determines that data tampering occurs in the current driving cycle of the ECU when the state characteristic value of the current driving cycle changes compared with the initial state characteristic value of the vehicle, thereby achieving detection of whether ECU data is tampered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of engine data security technology, and in particular to a method, device, electronic device and storage medium for detecting ECU data tampering. Background Technology

[0002] The Engine Control Unit (ECU), as a key component of the engine, directly affects engine performance and emissions. Currently, there are instances of illegally tampering with engine controller data, such as modifying ECU data to increase engine power output, enable or disable certain vehicle functions, or alter emissions. This illegal activity not only alters engine performance and fails to meet emission standards but also adversely affects vehicle safety.

[0003] In existing technologies, authorized technical parties need to access the vehicle's ECU through specialized external devices to read and analyze a large amount of relevant data to determine whether the ECU data has been tampered with. Therefore, existing ECU data tampering detection methods have poor immediacy, cannot detect ECU data tampering behavior in a timely manner, and have high detection costs. Summary of the Invention

[0004] In view of this, this application provides a method, apparatus, electronic device and storage medium for detecting ECU data tampering, so as to detect whether engine controller data has been tampered with, ensure the timeliness of detection and reduce detection costs.

[0005] The technical solution is as follows:

[0006] In a first aspect, embodiments of this application provide a method for detecting ECU data tampering, the method comprising:

[0007] Obtain the state characteristic parameters of the current driving cycle in the ECU;

[0008] The initial state characteristic values ​​of the ECU are determined based on the pre-stored state structure array in the ECU.

[0009] Calculate the state characteristic value of the ECU in the current driving cycle based on the state characteristic parameters of the ECU in the current driving cycle;

[0010] If the state characteristic value of the ECU in the current driving cycle is not equal to the initial state characteristic value, it is determined that the ECU has tampered with data in the current driving cycle.

[0011] Optionally, the status characteristic parameters include: function switch values, engine configuration parameters, vehicle configuration parameter values, and after-processing configuration parameter values.

[0012] Optionally, after determining that the ECU has undergone data tampering within the current driving cycle, the method further includes:

[0013] The state characteristic value of the ECU in the current driving cycle and the operation information of the ECU in the current driving cycle are stored in the state structure array, wherein the operation information includes at least one of the total mileage and the total time of operation.

[0014] Optionally, after determining that the ECU has undergone data tampering within the current driving cycle, the method further includes:

[0015] An alarm message is generated, and the vehicle torque limiting operation is triggered.

[0016] Secondly, embodiments of this application provide an ECU data tampering detection device, the device comprising:

[0017] The acquisition module is used to acquire the state characteristic parameters of the current driving cycle in the ECU;

[0018] The determination module is used to determine the initial state characteristic values ​​of the ECU based on the pre-stored state structure array in the ECU;

[0019] The calculation module is used to calculate the state characteristic value of the ECU in the current driving cycle based on the state characteristic parameters of the ECU in the current driving cycle;

[0020] The judgment module is used to determine that the ECU has committed data tampering in the current driving cycle when the state characteristic value of the ECU in the current driving cycle is not the same as the initial state characteristic value.

[0021] Optionally, the status characteristic parameters include: function switch values, engine configuration parameters, vehicle configuration parameter values, and after-processing configuration parameter values.

[0022] Optionally, the device further includes:

[0023] The storage module is used to store the state characteristic value of the ECU in the current driving cycle and the operating information of the ECU in the current driving cycle into the state structure array after determining that the ECU has undergone data tampering in the current driving cycle. The operating information includes at least one of the total mileage and the total time of operation.

[0024] Optionally, the device further includes:

[0025] The alarm module is used to generate alarm information after determining that the ECU has committed data tampering in the current driving cycle;

[0026] The torque limiting module is used to trigger vehicle torque limiting operation after determining that the ECU has tampered with data during the current driving cycle.

[0027] Thirdly, embodiments of this application provide an electronic device, the electronic device comprising:

[0028] Memory, used to store one or more programs;

[0029] A processor; when the one or more programs are executed by the processor, to implement the method described in any of the first aspects above.

[0030] Fourthly, embodiments of this application provide a computer storage medium storing a program that, when executed by a processor, implements the method described in any of the first aspects above.

[0031] The above technical solution has the following beneficial effects:

[0032] This application provides a method for detecting ECU data tampering. When executing the method, the following steps are taken: First, the state characteristic parameters of the current driving cycle in the ECU are obtained. Then, the initial state characteristic value of the ECU is determined based on a pre-stored state structure array in the ECU. Next, the state characteristic value of the ECU in the current driving cycle is calculated based on the state characteristic parameters. If the state characteristic value of the ECU in the current driving cycle is not equal to the initial state characteristic value, it is determined that data tampering has occurred in the current driving cycle. This application calculates the state characteristic value representing the current driving cycle of the ECU using the state characteristic parameters and compares it with the initial state characteristic value of the vehicle. If the state characteristic value of the current driving cycle changes compared to the initial state characteristic value, it is determined that data tampering has occurred in the current driving cycle. This achieves the detection of whether ECU data has been tampered with. Therefore, this application does not require external devices and can achieve self-detection of data tampering based solely on the vehicle ECU, improving the immediacy of ECU data tampering detection and reducing detection costs.

[0033] This application also provides apparatus, electronic devices, and storage media corresponding to the above methods, which have the same beneficial effects as the above methods. Attached Figure Description

[0034] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0035] Figure 1 A schematic flowchart of an ECU data tampering detection method provided in an embodiment of this application;

[0036] Figure 2 This is a schematic diagram of the structure of an ECU data tampering detection device provided in an embodiment of this application. Detailed Implementation

[0037] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0038] Engine Control Unit (ECU) data is typically hardened and rewritten at the time of engine and vehicle assembly. However, illegal methods of tampering with ECU data have emerged, such as modifying ECU data to increase engine power output, enable or disable certain vehicle functions, or alter emissions. This illegal activity not only alters engine performance and fails to meet emission standards but also adversely affects vehicle safety. This application provides a method for detecting ECU data tampering, applicable to ECUs. Please refer to [link to relevant documentation]. Figure 1 The diagram illustrates a method for detecting ECU data tampering, which may include:

[0039] Step S100: Obtain the state characteristic parameters of the current driving cycle in the ECU.

[0040] Specifically, status characteristic parameters may include function switch values, engine configuration parameters, vehicle configuration parameter values, and after-treatment configuration parameter values.

[0041] Understandably, the function switch value is used to indicate whether the feature value calculation function is enabled. When the feature value calculation function is enabled, the function switch is turned on and the function switch value is 1 when the system starts to perform ECU data tampering detection. When the system turns off ECU data tampering detection, the function switch is turned off and the function switch value is 0.

[0042] Engine configuration parameters refer to parameters related to the engine. As an example, engine configuration parameters may include vehicle speed limit parameters, torque limit parameters, fuel quantity limit parameters, etc.

[0043] Vehicle configuration parameter values ​​refer to the functional parameters configured at the factory. As an example, vehicle configuration parameter values ​​can be parameter values ​​related to vehicle locking function, cruise control function, and power output assist (PTO) function. For example, when the vehicle has cruise control function, the locking function value is 1, and when the vehicle does not have cruise control function, the locking function value is 0.

[0044] Aftertreatment configuration parameter values ​​refer to parameters related to the vehicle's aftertreatment system. As an example, aftertreatment configuration parameter values ​​can be the DOC function switch value of the oxidation catalyst, the DPF function switch value of the wall-flow particulate filter, the SCR function switch value, etc.

[0045] Step S200: Determine the initial state characteristic value of the ECU based on the pre-stored state structure array in the ECU.

[0046] Specifically, in this embodiment of the application, the ECU memory pre-stores a state structure array M. The state structure array should at least store the initial state characteristic value of the ECU. The initial state characteristic value is calculated based on the state characteristic parameters corresponding to the vehicle when it leaves the factory, and can characterize the parameter state when the vehicle ECU data has not been tampered with.

[0047] Optionally, the state structure array may include pre-stored state characteristic values ​​Z of the ECU. n eigenvalues ​​Z n The corresponding operating information can include total engine mileage data (D). n And the total engine running time data T n At least one of the following, where n is the number of driving cycles, n≥0, and n is an integer.

[0048] As an example, when the state structure array M includes state feature values, total engine mileage data, and total engine operating time data, the structure of the state structure array M provided in this embodiment can be as follows:

[0049]

[0050] It should be noted that the structure of the state structure array provided here is only an illustration, and technicians can adjust the data structure as needed.

[0051] Step S300: Calculate the state characteristic value of the ECU in the current driving cycle based on the state characteristic parameters of the current driving cycle in the ECU.

[0052] Specifically, the state characteristic value of the ECU in the current driving cycle is calculated based on the state characteristic parameters of the current driving cycle obtained in step S100.

[0053] As an example, the calculation of state eigenvalues ​​may include:

[0054]

[0055] Among them, Z n The state characteristic values ​​corresponding to the nth driving cycle; α, β, γ, δ, ε, ∈, θ, μ is the preset weighting coefficient; A is the function switch value in the nth driving cycle. When the ECU data tampering detection function is enabled, A is 1, and when the ECU data tampering detection function is disabled, A is 0; B, C, D, and E are the engine configuration parameters in the nth driving cycle. Specifically, B is the speed limit, C is the vehicle speed limit, D is the torque limit, and E is the fuel limit; F, G, and H are the vehicle configuration parameter values ​​in the nth driving cycle. Specifically, F is the vehicle locking function value, G is the cruise control function value, and H is the power output to power (PTO) function value; I, J, and K are the after-processing configuration parameter values ​​in the nth driving cycle. Specifically, I is the DOC function switch value, J is the DPF function switch value, and K is the SCR function switch value.

[0056] It should be noted that the above formula for calculating state characteristic values ​​is merely an example. Technicians can adjust and design the parameters and corresponding weights in the formula for calculating state characteristic values ​​according to requirements and the actual functions of the vehicle.

[0057] It should be noted that the initial state characteristic value Z0 of the ECU can be obtained by reading the state characteristic parameters in the controller after the engine test is completed before the car leaves the factory, and then calculating the corresponding factory characteristic value Z0 for the engine ECU using the characteristic value calculation formula built into the flashing tool. After the calculation is completed, the flashing tool writes Z0, as well as the corresponding engine running mileage D0 and engine running time T0, into a preset structure array M. Finally, the flashing tool enables the characteristic value calculation module in the controller.

[0058] Step S400: When it is determined that the state characteristic value of the ECU in the current driving cycle is not the same as the initial state characteristic value, it is determined that the ECU has tampered with data in the current driving cycle.

[0059] Specifically, the calculated state characteristic value of the current driving cycle is compared with the initial state characteristic value. If the state characteristic value of the current driving cycle is not the same as the initial state characteristic value, it is determined that the ECU has tampered with data within the current driving cycle. This application embodiment calculates the state characteristic value of the ECU in different driving cycles and uses these state characteristic values ​​to determine whether the ECU data has been tampered with, thereby achieving the detection of whether the engine controller data has been tampered with.

[0060] As an example, if the current driving cycle's state characteristic value is Z1 and the initial state characteristic value is Z0, then when it is determined that Z1 ≠ Z0, it is confirmed that ECU data tampering has occurred within the driving cycle corresponding to the state characteristic value Z1. It can be understood that a driving cycle refers to the complete process of a car completing ignition, operation, and shutdown.

[0061] As an optional implementation, the detection method provided in this application embodiment may further include:

[0062] After determining that the ECU has committed data tampering in the current driving cycle, the state characteristic value of the ECU in the current driving cycle and the operating information of the ECU in the current driving cycle are stored in the state structure array. The operating information includes at least one of the total mileage and the total time of operation.

[0063] Specifically, after ECU data is tampered with, the state characteristic value, total mileage, and total running time of the driving cycle corresponding to the data tampering are stored in a preset state structure array. It should be noted that the total mileage and total running time can be directly read and obtained by the ECU. This embodiment of the application records the operation of engine data throughout its life cycle by using a structure array containing state characteristic values, total engine mileage, and total engine running time, and promptly records tampered information.

[0064] As an example, if it is determined that ECU data tampering has occurred within the current driving cycle, the state characteristic value calculated for the current driving cycle is Z. n and the corresponding total mileage D n With total running time T n Stored in the preset state structure array M in the ECU memory.

[0065] It should be noted that after the ECU data has been confirmed to have not been tampered with, that is, the state characteristic values ​​corresponding to the previous and next driving cycles have not changed, the state characteristic values ​​of the current driving cycle and the corresponding total mileage and total time can be left unstored in the state structure array, thus saving storage data and improving detection efficiency.

[0066] It should be noted that 0 is the factory state characteristic value of the engine ECU, which is acquired and written into the state structure array when the engine is off the production line. Subsequent detection can be performed after the vehicle is started and the engine ECU is powered on by T15. The characteristic value calculation module in the ECU controller acquires the state characteristic parameters and calculates the state characteristic value. The state characteristic value is compared in each driving cycle, realizing data monitoring throughout the engine's life cycle. The mileage and running time information associated with the engine data are recorded through a preset structure array, providing data support for resolving customer disputes.

[0067] As an optional implementation, the detection method provided in this application embodiment may further include:

[0068] After determining that the ECU has tampered with data during the current driving cycle, an alarm message is generated and the vehicle torque limiting operation is triggered.

[0069] Specifically, after ECU data is tampered with, the ECU can activate the associated Diagnostic Fault Check (DFC) based on the data tampering determination result, triggering engine torque limiting operation and generating corresponding alarm information. This alarm is then sent to the driver via the vehicle's central control notification system, alerting them to the ECU data tampering and allowing the driver to take timely corrective action. It is understandable that linking the controller data status with engine torque limiting operation provides protection for engine performance and lifespan, while simultaneously ensuring vehicle driving safety.

[0070] In summary, this application provides a method for detecting ECU data tampering. When executing the method, the following steps are taken: First, the state characteristic parameters of the current driving cycle in the ECU are obtained. Second, the initial state characteristic value of the ECU is determined based on a pre-stored state structure array in the ECU. Third, the state characteristic value of the ECU in the current driving cycle is calculated based on the state characteristic parameters of the current driving cycle. If the state characteristic value of the ECU in the current driving cycle is not equal to the initial state characteristic value, it is determined that data tampering has occurred in the current driving cycle. This application calculates the state characteristic value representing the current driving cycle of the ECU using the state characteristic parameters of the current driving cycle in the ECU and compares it with the initial state characteristic value of the vehicle. If the state characteristic value of the current driving cycle changes compared to the initial state characteristic value, it is determined that data tampering has occurred in the current driving cycle. This achieves the detection of whether ECU data has been tampered with. Furthermore, this application can achieve self-detection of data tampering based on the vehicle ECU, without the need for external devices, improving the immediacy of ECU data tampering detection and reducing detection costs.

[0071] Corresponding to the above method, this application also provides an ECU data tampering detection device. The various modules of this device can be installed within the ECU. (See also...) Figure 2 A schematic diagram of the device is shown, which may include:

[0072] The acquisition module 201 is used to acquire the state characteristic parameters of the current driving cycle in the ECU;

[0073] The determining module 202 is used to determine the initial state characteristic value of the ECU based on the pre-stored state structure array in the ECU;

[0074] Calculation module 203 is used to calculate the state characteristic value of the ECU in the current driving cycle based on the state characteristic parameters of the ECU in the current driving cycle;

[0075] The judgment module 204 is used to determine that the ECU has tampered with data in the current driving cycle when the state characteristic value of the ECU in the current driving cycle is not the same as the initial state characteristic value.

[0076] As an optional implementation, the state characteristic parameters include: function switch values, engine configuration parameters, vehicle configuration parameter values, and after-processing configuration parameter values.

[0077] As an optional implementation, the device further includes:

[0078] The storage module is used to store the state characteristic value of the ECU in the current driving cycle and the operating information of the ECU in the current driving cycle into the state structure array after determining that the ECU has been tampered with in the current driving cycle. The operating information includes at least one of the total mileage and the total time of operation.

[0079] As an optional implementation, the device further includes:

[0080] The alarm module is used to generate alarm information after determining that the ECU has committed data tampering in the current driving cycle;

[0081] The torque limiting module is used to trigger vehicle torque limiting operation after determining that the ECU has tampered with data during the current driving cycle.

[0082] It should be noted that the steps and related technical features of each module in the ECU data tampering detection device provided in this application correspond to the ECU data tampering detection method provided in the application embodiment. The description of the device part can be found in the embodiments of the aforementioned method part, and will not be repeated here.

[0083] In summary, this application provides an ECU data tampering detection device. The device includes: an acquisition module for acquiring state characteristic parameters of the current driving cycle in the ECU; a determination module for determining the initial state characteristic value of the ECU based on a pre-stored state structure array in the ECU; a calculation module for calculating the state characteristic value of the ECU in the current driving cycle based on the state characteristic parameters of the current driving cycle in the ECU; and a judgment module for determining that data tampering has occurred in the current driving cycle if the state characteristic value of the ECU in the current driving cycle is not equal to the initial state characteristic value. This application calculates the state characteristic value representing the current driving cycle of the ECU using the state characteristic parameters of the current driving cycle in the ECU and compares it with the initial state characteristic value of the vehicle. If the state characteristic value of the current driving cycle changes compared to the initial state characteristic value, it determines that data tampering has occurred in the current driving cycle, thereby achieving the detection of whether engine controller data has been tampered with. Furthermore, this application can achieve self-detection of data tampering based on the vehicle ECU, without the need for external devices, improving the immediacy of ECU data tampering detection and reducing detection costs.

[0084] Corresponding to the above method, embodiments of this application also provide an electronic device, including:

[0085] Memory, used to store one or more programs;

[0086] A processor; when the processor executes the one or more programs, it implements the ECU data tampering detection method as described in any of the foregoing embodiments.

[0087] Corresponding to the above methods, this application also provides a storage medium storing a program, which, when executed by a processor, implements the ECU data tampering detection method as described in any of the foregoing embodiments.

[0088] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0089] Those skilled in the art will understand that the flowchart shown is merely an example in which the embodiments of this application can be implemented, and the scope of application of the embodiments of this application is not limited by any aspect of the flowchart.

[0090] In the several embodiments provided in this application, it should be understood that the disclosed methods, apparatuses, and devices can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings or direct couplings or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.

[0091] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, the functional units in the various embodiments of this application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0092] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0093] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for detecting ECU data tampering, characterized in that, Applied to the ECU, the method includes: The state characteristic parameters of the current driving cycle in the ECU are obtained. These state characteristic parameters include: function switch values, engine configuration parameters, vehicle configuration parameter values, and after-treatment configuration parameter values. The current driving cycle refers to the complete process of the vehicle completing ignition, operation, and shutdown. The engine configuration parameters include vehicle speed limit parameters, torque limit parameters, and fuel quantity limit parameters. The vehicle configuration parameter values ​​include parameters related to vehicle locking function, cruise control function, and power output to power (PTO) function. The after-treatment configuration parameter values ​​include the oxidation catalyst (DOC) function switch value, the wall-flow particulate filter (DPF) function switch value, and the selective catalytic reduction (SCR) function switch value. The initial state characteristic value of the ECU is determined based on the pre-stored state structure array in the ECU. The initial state characteristic value is obtained by reading the state characteristic parameters in the ECU and calculating them using a flashing tool before the vehicle leaves the factory, and then written into the state structure array of the ECU. The state structure array is pre-stored in the memory of the ECU and includes: the initial state characteristic value and the initial total mileage and initial total running time corresponding to the initial state characteristic value. The state characteristic value of the ECU in the current driving cycle is calculated based on the state characteristic parameters in the ECU; the state characteristic value is obtained by weighted summation of the function switch value, engine configuration parameter, vehicle configuration parameter value and after-processor configuration parameter value; If the state characteristic value of the ECU in the current driving cycle is not equal to the initial state characteristic value, it is determined that the ECU has tampered with data in the current driving cycle.

2. The method according to claim 1, characterized in that, After determining that the ECU has undergone data tampering within the current driving cycle, the method further includes: The state characteristic value of the ECU in the current driving cycle and the operation information of the ECU in the current driving cycle are stored in the state structure array, wherein the operation information includes at least one of the total mileage and the total time of operation.

3. The method according to claim 1, characterized in that, After determining that the ECU has undergone data tampering within the current driving cycle, the method further includes: An alarm message is generated, and the vehicle torque limiting operation is triggered.

4. A detection device for ECU data tampering, characterized in that, The device includes: The acquisition module is used to acquire the state characteristic parameters of the current driving cycle in the ECU. These state characteristic parameters include: function switch values, engine configuration parameters, vehicle configuration parameter values, and after-treatment configuration parameter values. The current driving cycle refers to the complete process of the vehicle completing ignition, operation, and shutdown. The engine configuration parameters include vehicle speed limit parameters, torque limit parameters, and fuel quantity limit parameters. The vehicle configuration parameter values ​​include parameters related to vehicle locking function, cruise control function, and power output to trip (PTO) function. The after-treatment configuration parameter values ​​include the oxidation catalyst (DOC) function switch value, the wall-flow particulate filter (DPF) function switch value, and the selective catalytic reduction (SCR) function switch value. The determination module is used to determine the initial state characteristic value of the ECU based on the pre-stored state structure array in the ECU. The initial state characteristic value is obtained by reading the state characteristic parameters in the ECU and calculating them using a flashing tool before the vehicle leaves the factory, and then writing them into the state structure array of the ECU. The state structure array is pre-stored in the memory of the ECU and includes: the initial state characteristic value and the initial total mileage and initial total running time corresponding to the initial state characteristic value. The calculation module is used to calculate the state characteristic value of the ECU in the current driving cycle based on the state characteristic parameters in the ECU; the state characteristic value is obtained by weighted summation of the function switch value, engine configuration parameter, vehicle configuration parameter value and after-processor configuration parameter value; The judgment module is used to determine that the ECU has committed data tampering in the current driving cycle when the state characteristic value of the ECU in the current driving cycle is not the same as the initial state characteristic value.

5. The apparatus according to claim 4, characterized in that, The device further includes: The storage module is used to store the state characteristic value of the ECU in the current driving cycle and the operating information of the ECU in the current driving cycle into the state structure array after determining that the ECU has undergone data tampering in the current driving cycle. The operating information includes at least one of the total mileage and the total time of operation.

6. The apparatus according to claim 4, characterized in that, The device further includes: The alarm module is used to generate alarm information after determining that the ECU has committed data tampering in the current driving cycle; The torque limiting module is used to trigger vehicle torque limiting operation after determining that the ECU has tampered with data during the current driving cycle.

7. An electronic device, characterized in that, include: Memory, used to store one or more programs; processor; When the one or more programs are executed by the processor, the method as described in any one of claims 1 to 3 is implemented.

8. A storage medium, characterized in that, The storage medium stores a program that, when executed by a processor, implements the method of any one of claims 1 to 3.