A vehicle safety situation awareness and emergency response method and system
By combining cybersecurity and functional safety analysis into a vehicle safety situational awareness and emergency response method, the problem of incomplete mining of safety analysis results during the operation phase of intelligent connected vehicles has been solved, achieving efficient cybersecurity attack detection and response, and improving the system's flexibility and efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-14
- Publication Date
- 2026-03-27
AI Technical Summary
In existing technologies, the cybersecurity and functional safety analysis of intelligent connected vehicles lacks an inherent connection during the vehicle operation phase, resulting in the incomplete mining of safety analysis results. Furthermore, the analysis of cybersecurity incidents tends to focus on cybersecurity while neglecting functional safety.
By combining cybersecurity and functional safety analysis during the vehicle operation phase, a vehicle safety situation awareness and emergency response method is designed. It uses a cloud platform to receive attack events reported by IDPS, matches them with a scenario library in the database, outputs the scenario with the highest matching degree, and performs emergency response according to preset conditions, displaying complete attack events and emergency measures.
It improves the accuracy and response efficiency of cybersecurity attack detection for intelligent connected vehicles, enhances the system's flexibility and efficiency, and enables batch processing of a large number of threat and dangerous scenarios, reducing configuration time.
Smart Images

Figure CN116318862B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of automotive cybersecurity, specifically to a method and system for automotive security situation awareness and emergency response. Background Technology
[0002] With the development of the "new four modernizations" of intelligent connected vehicles, software-defined vehicles have become a global trend in the development of new electronic and electrical architectures for future intelligent connected vehicles. The cybersecurity issues of intelligent connected vehicles are becoming increasingly prominent. How to establish coordinated security mechanisms and strategies between the vehicle and the cloud has become a challenging problem for the cybersecurity of the next generation of intelligent connected vehicles.
[0003] On the one hand, traditional security analyses for automobiles are typically conducted during the vehicle concept design phase. These analyses and risk assessments, conducted from different perspectives such as the vehicle-wide, component-level, and functional-level, identify potential cybersecurity and functional safety risks and clarify security objectives. However, current analyses of cybersecurity and functional safety are usually independent, lacking an intrinsic connection. Furthermore, the potential value of these security analysis results during the operational phase remains largely untapped. On the other hand, during the operational phase, the industry has begun using in-vehicle intrusion detection and prevention systems (IDPS) combined with cloud-based security operations centers (VSOCs) to collect security events and information related to intelligent connected vehicle assets. Through in-depth analysis, statistics, and correlation of these collected security events, the industry can promptly reflect the security status of managed vehicle assets, identify security risks, and provide timely detection and location of various security events, offering processing methods and suggestions to assist administrators in event analysis, risk analysis, early warning management, and emergency response. However, these security event analyses are primarily focused on cybersecurity, with less consideration given to functional safety. Summary of the Invention
[0004] To address the shortcomings of existing technologies, the present invention aims to provide a method and system for automotive safety situational awareness and emergency response. It aims to guide and optimize the detection and response process for cybersecurity attacks against intelligent connected vehicles during the vehicle operation phase by combining automotive cybersecurity analysis and functional safety analysis in a coordinated manner of cybersecurity and functional safety.
[0005] The above-mentioned objective of the present invention is achieved through the following technical solution:
[0006] A method for vehicle safety situational awareness and emergency response includes the following steps:
[0007] a. After receiving attack events reported by IDPS in the cloud, the cloud matches them with the scenario library in the database and outputs the scenario with the highest matching degree.
[0008] b. Issue emergency response measures based on the various attributes of the currently matched scenario;
[0009] c. Display complete attack incident information, emergency response measures, and other information on the VSOC platform.
[0010] In a preferred embodiment, the present invention can be further configured such that: after receiving an IDPS attack event, the cloud matches it with a scenario library in the database and outputs the scenario with the highest matching degree, including:
[0011] a. Match based on preset conditions and rules to determine whether the current attack event may lead to certain threat scenarios;
[0012] b. If no threat scenario is matched, the current step stops; if a threat scenario is matched, the matching is performed according to preset conditions and rules to determine whether the current threat scenario may lead to certain dangerous scenarios.
[0013] c. If no dangerous scenario is matched, only the threat scenario is retained; if multiple threat scenarios are matched, the security risks of different threat scenarios are compared, and the threat scenario with the highest risk value is selected as the benchmark; the matched threat scenario and dangerous scenario are used as the output of the current step of attack event matching.
[0014] In a preferred embodiment, the present invention can be further configured as follows: after determining the corresponding scenario, an emergency response is issued based on various attributes of the current scenario, the steps of which include:
[0015] a. Match based on preset conditions and rules to determine whether there are corresponding response measures for the current threat scenario and dangerous scenario;
[0016] b. If a response measure is matched, execute it; otherwise, stop the current step.
[0017] In a preferred embodiment, the present invention can be further configured to: display complete attack event information, emergency response measures, and other information on the VSOC platform, the steps of which include:
[0018] a. Record the entire process information of the uploaded attack events, matching scenarios, and corresponding response measures, and store it in the database;
[0019] b. Database information is summarized, filtered, and statistically analyzed to create various formats such as lists, pie charts, bar charts, line charts, and map markers for display on the VSOC platform.
[0020] In a preferred embodiment, the present invention may further be configured to include:
[0021] a. Based on prior knowledge, design multiple threat scenarios, multiple hazardous scenario libraries, and multiple emergency response measures, and store them in the corresponding databases;
[0022] b. Based on prior knowledge, design the correspondence between threat scenarios and dangerous scenarios, indicate the dangerous scenarios that a certain threat scenario may lead to, and store them in the corresponding database.
[0023] In a preferred embodiment, the present invention may further be configured to include: designing emergency response measures to be performed when different threat scenarios and dangerous scenarios may occur based on prior knowledge, and storing the corresponding relationships in a database.
[0024] In a preferred embodiment, the present invention can be further configured to include: the association between emergency response measures and scenarios must be implemented through graphical programming; and the association configuration is performed based on various different attributes of threat scenarios and dangerous scenarios.
[0025] A vehicle safety situation awareness and emergency response system is characterized in that the vehicle safety situation awareness and emergency response system includes a VSOC platform, a threat scenario database, a hazardous scenario database, an emergency response database, a policy configuration database, and an attack event database.
[0026] In summary, the present invention has at least one of the following beneficial technical effects:
[0027] 1. By combining automotive cybersecurity analysis with functional safety analysis, we can guide and optimize the detection and response process for cybersecurity attacks against intelligent connected vehicles from both cybersecurity and functional safety perspectives during the vehicle operation phase, explore the potential value of the analysis results, and improve the detection accuracy and response efficiency of IDPS.
[0028] 2. A graphical editing solution is provided for editing emergency response procedures, which can batch process responses to a large number of threat scenarios and dangerous scenarios, reducing the time consumed when there are a large number of scenarios that need to be configured, improving efficiency and enhancing system flexibility. Attached Figure Description
[0029] Figure 1 This is a flowchart illustrating an embodiment of a vehicle safety situational awareness and emergency response method according to this application.
[0030] Figure 2 A flowchart illustrating how attack events received in the cloud are matched against a scenario database.
[0031] Figure 3 This is a schematic diagram of an embodiment of an automotive safety situational awareness and emergency response system according to this application. Detailed Implementation
[0032] The present invention will be further described in detail below with reference to the accompanying drawings.
[0033] Reference Figure 1 and Figure 2 The present invention discloses a method for vehicle safety situational awareness and emergency response, comprising the following steps:
[0034] a. After receiving attack events reported by IDPS in the cloud, the cloud matches them with the scenario library in the database and outputs the scenario with the highest matching degree.
[0035] The system matches data against preset conditions and rules to determine whether a current attack event could lead to certain threat scenarios. These preset conditions and rules are derived from prior knowledge and analysis and stored in a database. Upon receiving reported attack event data in the cloud, the database information is retrieved for matching. Typically, one attack event may lead to one or more threat scenarios.
[0036] If no threat scenario is matched, it generally means that the current attack is relatively minor and does not constitute a cybersecurity threat, so the current step should be stopped.
[0037] If a threat scenario is matched, it will be matched according to preset conditions and rules to determine whether the current threat scenario may lead to certain dangerous scenarios. Usually, the relationship between threat scenarios and dangerous scenarios is derived from prior knowledge and analysis and stored in the database.
[0038] If no dangerous scenario is matched, only the threatening scenario will be retained;
[0039] If multiple threat scenarios are matched, the security risks of different threat scenarios are compared, and the threat scenario with the highest risk value is selected as the benchmark.
[0040] In one specific embodiment, when the ADAS domain load rate in the data uploaded to the cloud is abnormal, exceeding the total load rate of all messages in the DBC, and no message containing the brake pedal status signal is detected on the ADAS_CAN domain CAN bus, the attack event will be matched with a specified threat scenario according to preset rules, and this scenario will be used as a benchmark.
[0041] In one specific embodiment, the above-mentioned threat scenario is associated with 6 dangerous scenarios, among which the risk value of a certain dangerous scenario is 3, which is higher than the other dangerous scenarios. This means that in this scenario, the driver may face a more serious threat to personal safety. Therefore, this scenario is selected as the benchmark.
[0042] The matched threat scenarios and dangerous scenarios are used as the output of the current step of attack event matching.
[0043] The matching logic here:
[0044] 1. Define the score for each of the threat scenarios and dangerous scenarios;
[0045] 2. An attack event may match zero, one, or multiple threat scenarios, and each threat scenario may be associated with zero, one, or multiple dangerous scenarios, i.e., a many-to-many relationship;
[0046] 3. If many-to-many matching exists, first select the threat scenario with the highest risk value as the benchmark, and then select the dangerous scenario with the highest risk value as the benchmark within this threat scenario, thus obtaining two scenarios: threat and dangerous.
[0047] In one specific embodiment, the numbers of the aforementioned threat scenarios and dangerous scenarios are used as the current output. It should be noted that the above two scenarios include multiple built-in attributes and corresponding scores, and are not simply output as strings.
[0048] b. Issue emergency response measures based on the various attributes of the currently matched scenario;
[0049] Based on preset conditions and rules, the system matches and determines whether there are corresponding response measures for the current threat scenario and the dangerous scenario.
[0050] If a response measure is matched, it will be executed;
[0051] If no response is found, the current step stops.
[0052] In one specific embodiment, the aforementioned threat scenario is matched with a corresponding emergency response strategy, which includes a series of response measures such as sending alarm emails to operations personnel and pushing warning information to the vehicle.
[0053] c. Display complete attack incident information, emergency response measures, and other information on the VSOC platform.
[0054] a. Record the entire process information of the uploaded attack events, matching scenarios, and corresponding response measures, and store it in the database;
[0055] b. Database information is summarized, filtered, and statistically analyzed to create various formats such as lists, pie charts, bar charts, line charts, and map markers for display on the VSOC platform.
[0056] In one specific embodiment, the information displayed on the VSOC platform includes: occurrence time, event type, attack type, domain where the attack occurred, risk level, emergency response measures, processing status, detailed description, attack path, and other content. In addition, the VSOC platform categorizes and displays information according to the event type, including CAN network anomalies, vehicle Ethernet anomalies, vehicle infotainment system anomalies, and TBOX external communication anomalies.
[0057] Vehicle safety situational awareness and emergency response methods also include:
[0058] Based on prior knowledge, we design multiple threat scenarios, multiple dangerous scenario libraries, and multiple emergency response measures, and store them in the corresponding databases.
[0059] In one specific embodiment, the design of threat scenarios must, according to the concept phase (Chapter 9 of ISO / SAE 21434 standard) of the entire lifecycle of automotive systems, identify potential threat scenarios for the vehicle through Threat Analysis and Risk Assessment (TARA analysis) after the "Item" definition is completed in the conceptual phase, and determine the risk level of different scenarios based on the Threat Analysis and Risk Assessment (TARA) analysis. Furthermore, the "Item" definition phase must be based on signals corresponding to the vehicle's functions.
[0060] In one specific embodiment, the design of hazardous scenarios must, according to the concept phase (Chapter 9 of standard 21434) of the automotive system lifecycle proposed by ISO / SAE 26262, identify potential hazardous scenarios of the vehicle through Hazard Analysis and Risk Assessment (HARA analysis) after completing the definition of the "Item," and determine the comprehensive functional safety risk value of different scenarios; and in the "Item" definition phase, the analysis must be based on the vehicle's functions.
[0061] Based on prior knowledge, design the correspondence between threat scenarios and dangerous scenarios, indicate the dangerous scenarios that a certain threat scenario may lead to, and store them in the corresponding database;
[0062] In one specific embodiment, threat scenarios and dangerous scenarios are associated based on functionality.
[0063] Based on prior knowledge, design emergency response measures to be taken when different threat and danger scenarios may occur, and store the corresponding relationships in the database;
[0064] In one specific embodiment, the design of emergency response measures follows the PDCERF (Prepare, Detect, Suppress, Eradicate, Recover, Summarize) emergency response process, and is designed from multiple perspectives, including technical response and business response. Technical response mainly includes sending early warning information to the vehicle and updating IDPS via OTA; business response mainly includes early warning from operations personnel and work order early warning.
[0065] In one specific embodiment, the association between emergency response measures and scenarios must be implemented through graphical programming. Graphical programming is based on BPMN business process modeling and is configured with start node, end node, mutual exclusion gateway, technical response node, and business response node as the main elements.
[0066] In one specific embodiment, the association configuration is performed based on various attributes of threat scenarios and dangerous scenarios. The main attributes of threat scenarios include: SFOP rating (security, property, operability, privacy), impact rating, feasibility analysis, risk value, and whether it is associated with dangerous scenarios, etc.; the main attributes of dangerous scenarios include: hazard, exposure, controllability, ASIL rating, etc.
[0067] Furthermore, this application embodiment also provides a vehicle safety situation awareness and emergency response system that integrates network security and functional safety, the vehicle safety situation awareness and emergency response system integrating network security and functional safety includes:
[0068] Furthermore, to achieve the above objectives, an automotive safety situation awareness and emergency response system is also provided. This system includes: a VSOC platform, a security event database, a threat scenario database, a hazardous scenario database, an emergency response database, a policy configuration database, and an attack event database.
[0069] The VSOC platform is used to receive attack events and data reported by the vehicle-mounted IDPS;
[0070] The VSOC platform is used to display a database of attack events;
[0071] The VSOC platform is used to add, delete, edit, and display threat scenario databases;
[0072] The VSOC platform is used to add, delete, edit, and display hazardous scenario databases;
[0073] The VSOC platform is used to add, delete, edit, and display emergency response databases.
[0074] The VSOC platform is used to add, delete, edit, and display policy configuration databases;
[0075] The threat scenario database is used to store threat scenario information;
[0076] The hazardous scenario database is used to store hazardous scenario information;
[0077] The emergency response database is used to store information on emergency response measures;
[0078] The policy configuration database is used to store information about the relationship between threat scenarios and emergency response measures.
[0079] The system is essentially a vehicle-to-everything (V2X) security monitoring platform. It monitors and analyzes data uploaded from vehicles to identify potential security risks.
[0080] System operating logic:
[0081] 1. Devices deployed on connected vehicles upload data, which typically includes vehicle logs, attack events detected by the devices, etc.
[0082] 2. The cloud system receives data reported by the vehicle, matches the data with scenarios stored in the threat and danger scenario database, and analyzes the potential dangers that the vehicle may be in.
[0083] 3. Respond to the potential dangers mentioned in point 2 based on the stored response strategy;
[0084] 4. Store the entire process of attack events and event handling;
[0085] 5. In addition to the above emergency procedures, the cloud system also monitors and displays information about all vehicles in real time, including location and driving status;
[0086] 6. The database mentioned above is used to store data.
[0087] The implementation principle of this embodiment is as follows: After receiving the attack event reported by IDPS, the cloud performs matching in the database, outputs the scenario with the highest matching degree, issues emergency response based on the various attributes of the currently matched scenario, and finally displays the complete attack event information, emergency response measures and other information on the VSOC platform, while storing the event.
[0088] The embodiments described herein are preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Therefore, all equivalent changes made in accordance with the structure, shape, and principle of the present invention should be covered within the scope of protection of the present invention.
Claims
1. A method for automotive safety situation awareness and emergency response, the method comprising: The method comprises the following steps: a. After receiving the attack event reported by the IDPS, the cloud matches the scene library in the database, and outputs the scene with the highest matching degree; b. According to the properties of the current matched scene, emergency response is issued; c. The complete attack event information and emergency response measure information are displayed on the VSOC platform; The step of matching the scene library in the database after receiving the attack event reported by the cloud includes: a. According to the preset conditions and rules, it is judged whether the current attack event may lead to some threat scenes, wherein the threat scene is defined based on ISO / SAE 21434 standard through threat analysis and risk assessment; b. If no threat scene is matched, the current step stops; if a threat scene is matched, according to the preset conditions and rules, it is judged whether the current threat scene may lead to some dangerous scenes, wherein the dangerous scene is defined based on ISO / SAE 26262 standard through danger analysis and risk assessment; c. If no dangerous scene is matched, only the threat scene is retained; if multiple dangerous scenes are matched, the safety risks of different dangerous scenes are compared, and the dangerous scene with the highest risk value is selected as the reference; the matched threat scene and dangerous scene are taken as the output of the current step.
2. The method of claim 1, wherein, After determining the corresponding scene, according to the properties of the current scene, emergency response is issued, and the steps include: a. According to the preset conditions and rules, it is judged whether the current threat scene and dangerous scene have corresponding response measures; b. If the response measure is matched, it is executed; if no response measure is matched, the current step stops.
3. The method of claim 2, wherein, The steps of displaying the complete attack event information and emergency response measure information on the VSOC platform include: a. Record the uploaded attack event, matched scene, corresponding response measure and whole process information, and store them in the database; b. The database information is displayed on the VSOC platform in the form of list, pie chart, column chart, line chart and map marker through summarization, screening and statistical methods.
4. The method of claim 3, wherein, Further comprising: a. According to prior knowledge, design multiple threat scene libraries, multiple dangerous scene libraries and multiple emergency response measures, and store them in the corresponding databases; b. According to prior knowledge, design the corresponding relationship between threat scenes and dangerous scenes, indicate the dangerous scenes that may be caused by a threat scene, and store them in the corresponding database.
5. The method of claim 4, wherein, Further comprising: According to prior knowledge, design the emergency response measures to be executed when different threat scenes and dangerous scenes may occur, and store the corresponding relationship in the database.
6. The method of claim 1, wherein, The association between emergency response measures and scenes must be realized by graphical programming; the association is configured according to the multiple different properties of threat scenes and dangerous scenes.
7. An automotive safety situation awareness and emergency response system, characterized by, The system is used for executing the automobile safety situation awareness and emergency response method in any one of claims 1-6, and comprises a VSOC platform, a threat scene database, a dangerous scene database, an emergency response database, a strategy configuration database and an attack event database.
Citation Information
Patent Citations
File detection and threat level determination method, device and system
CN108009425A
Network security emergency response method and system based on knowledge graph
CN111614696A
Communication security car networking system
CN115664691A