A network security protection method and device based on a controller area network bus

By generating device fingerprints from CAN bus message signals and comparing their similarity with preset fingerprints, the security risks caused by the lack of encryption on the CAN bus are resolved, enabling effective identification and protection against unauthorized devices and improving network security.

CN116346443BActive Publication Date: 2026-01-06PURPLE MOUNTAIN LAB +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310234436.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-09
Publication Date
2026-01-06
Estimated Expiration
2043-03-09

AI Technical Summary

Technical Problem

In existing technologies, the Controller Area Network (CAN) bus has the problem of unauthenticated and unencrypted broadcast bus, which allows attackers to easily listen to and send messages, causing in-vehicle security risks. Existing protection solutions cannot effectively detect and prevent attacks.

Method used

By extracting the control segment signal from the message signal on the CAN bus, a device fingerprint is generated and its similarity is calculated with a preset device fingerprint. If the similarity exceeds a threshold, the message signal is invalid, thereby realizing the identification and protection of illegal devices.

Benefits of technology

Without altering the vehicle message frame structure, reliable protection of the CAN bus network is achieved, enabling the identification of unauthorized devices and the prevention of attacks, thus meeting real-time processing and communication requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346443B_ABST
    Figure CN116346443B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of identity authentication of device fingerprints, in particular to a network security protection method and device based on a controller area network bus. Through processing of a control section signal in a message signal on a CAN bus, a device fingerprint of a device sending the message signal is obtained, the control section signal comprises a reserved bit signal, a rate switching bit signal, an error state indication bit signal and a data length bit signal, similarity calculation is performed on the device fingerprint and a preset device fingerprint corresponding to the device stored in a memory, a similarity value is compared with a preset threshold value, whether the device sending the message signal is an illegal device is judged, if the device is an illegal device, the message signal is invalidated, and thus effective identification of illegal devices on the CAN bus is realized, and reliable protection of the network on the CAN bus is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of device fingerprint authentication technology, and in particular to a network security protection method and device based on a controller area network bus. Background Technology

[0002] In the field of standard in-vehicle communication networks, the Controller Area Network (CLAN)

[0003] CAN (Content-Oriented Communication) has been used in automotive and other industrial environments for over 30 years, typically for system connections critical to functional safety. As a well-designed in-vehicle communication bus, the CAN bus connects various Electronic Control Units (ECUs) within the vehicle. However, the CAN bus is an unauthenticated and unencrypted broadcast bus, meaning anyone can read and send any message. Therefore, once access is gained, attackers can listen to all traffic on the bus and send frames with their chosen CAN ID and payload. A successful attack on the CAN network poses significant security risks and could even endanger the lives of occupants. Currently, attackers have been able to inject data packets into the in-vehicle network through compromised ECUs to control vehicles and remotely stop a car traveling on a highway. This reality of vehicle attacks makes automotive security a critical issue.

[0004] Existing solutions for attacks on such in-vehicle networks still suffer from drawbacks such as poor real-time communication or the inability to detect or prevent serious attacks. Therefore, there is an urgent need to find a reliable solution for protecting the security of control networks on the controller area network bus. Summary of the Invention

[0005] To address the problems of existing technologies, this application provides a network security protection method, apparatus, electronic device, and storage medium based on a controller area network (CLAN) bus. The technical solution is as follows:

[0006] On the one hand, a network security protection method based on a controller area network bus is provided, the method comprising:

[0007] Acquire message signals on the controller area network bus;

[0008] Extract the control segment signals from the message signals; the control segment signals include reserved bit signals, rate switching bit signals, error status indication bit signals, and data length bit signals.

[0009] The differential voltage values ​​corresponding to the control segment signals are segmented to generate the device fingerprint of the device sending the message signal;

[0010] The first fingerprint similarity is determined based on the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint; the first fingerprint similarity characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint.

[0011] If the similarity of the first fingerprint is greater than the first preset threshold, a protection signal for sending an invalid message signal will be sent.

[0012] In one exemplary embodiment, the differential voltage value corresponding to the control segment signal is segmented to generate a device fingerprint of the device sending the message signal, including:

[0013] Acquire the sampling rate of the message signal, the transmission rate of the arbitration segment data symbols in the message signal, and the transmission rate of the data segment symbols in the message signal;

[0014] The target interval sampling points are determined based on the sampling rate of the message signal, the transmission rate of the arbitration segment data symbols in the message signal, and the transmission rate of the data segment symbols in the message signal.

[0015] Based on the target interval sampling point number, the message signal is segmented to obtain multiple sampling point datasets; each sampling point dataset includes the differential voltage values ​​of multiple sampling points; the number of sampling points in each sampling point dataset is equal to the target interval sampling point number;

[0016] For each sampling point dataset, the fingerprint of the sampling point dataset is determined based on the differential voltage values ​​of each sampling point in the sampling point dataset;

[0017] The device fingerprint of the device that sent the message signal is determined based on the fingerprint of the dataset of each sampling point.

[0018] In one exemplary implementation, determining the target interval sampling point number based on the sampling rate of the message signal, the transmission rate of the arbitration segment data symbols in the message signal, and the transmission rate of the data segment symbols in the message signal includes:

[0019] The number of sampling points in the first interval is determined based on the sampling rate of the message signal and the transmission rate of the data symbols in the arbitration segment of the message signal.

[0020] The number of sampling points for the second interval is determined based on the sampling rate of the message signal and the transmission rate of the data segment symbols in the message signal.

[0021] The minimum number of sampling points between the first and second intervals is taken as the target interval number of sampling points.

[0022] In one exemplary implementation, determining the fingerprint of the sampling point dataset based on the differential voltage values ​​of each sampling point in the sampling point dataset includes:

[0023] The differential voltage values ​​of each sampling point in the sampling point dataset are accumulated to generate a fingerprint of the sampling point dataset.

[0024] In one exemplary implementation, determining a first fingerprint similarity based on the device fingerprint of the device sending the message signal and a corresponding preset device fingerprint includes:

[0025] The Mahalanobis distance between the device fingerprint of the device sending the message signal and the preset device fingerprint is determined based on the device fingerprint of the device sending the message signal, the preset device fingerprint mean, and the preset device fingerprint covariance.

[0026] The Mahalanobis distance between the device fingerprint and the preset device fingerprint is determined as the first fingerprint similarity.

[0027] In one exemplary embodiment, before determining the Mahalanobis distance between the device fingerprint of the device transmitting the message signal and the preset device fingerprint based on the device fingerprint of the device transmitting the message signal, the preset device fingerprint mean, and the preset device fingerprint covariance, the method further includes:

[0028] The message signal is parsed and the identifier segment is extracted sequentially to obtain the bit array of the identifier segment;

[0029] The bit array of the identifier segment is decoded to generate the identifier of the message signal;

[0030] Based on the identifier of the message signal, the device number that sent the message signal is determined from the device information storage list; the device information storage list represents the correspondence between the identifier of the message signal and the device number.

[0031] Based on the device ID of the transmitted message signal, the preset device fingerprint mean and preset device fingerprint covariance of the transmitted message signal are determined from the device fingerprint storage list; the device fingerprint storage list represents the correspondence between the device ID and the preset device fingerprint mean and preset device fingerprint covariance.

[0032] In one exemplary implementation, before acquiring message signals on the controller area network bus, the method further includes:

[0033] Acquire the first number of historical message signals from the target device collected at a historical moment; the target device is the device that sent the message signal.

[0034] Extract the control segment signal from each historical message signal in the first number of historical message signals; and perform segmentation processing on the differential voltage value corresponding to the control segment signal in each historical message signal in the first number of historical message signals to generate a preset device fingerprint for each historical message signal;

[0035] A second number of historical message signals are determined from a first number of historical message signals; the second number is determined based on the number of vectors contained in the device fingerprint, and the difference between the first number and the second number is greater than or equal to 1.

[0036] The mean of the preset device fingerprint of the sent message signal is determined based on the preset device fingerprint of each historical message signal in the second quantity of historical message signals; and the preset device fingerprint covariance of the sent message signal is determined based on the preset device fingerprint and the mean of the preset device fingerprint of each historical message signal in the second quantity of historical message signals.

[0037] For each remaining historical message signal in the remaining number of historical message signals, the Mahalanobis distance between the remaining historical message signal and the second number of historical message signals is determined based on the preset device fingerprint of the remaining historical message signal, the mean of the preset device fingerprint of the sent message signal, and the covariance of the preset device fingerprint of the sent message signal; the remaining number is the difference between the first number and the second number.

[0038] The first preset threshold is determined based on the Mahalanobis distance between each remaining historical message signal and the second number of historical message signals in the remaining number of historical message signals.

[0039] In one exemplary embodiment, after determining the first fingerprint similarity based on the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint, the method further includes:

[0040] If the similarity of the first fingerprint is less than or equal to the first preset threshold, then the preset device fingerprints of the remaining legitimate devices in the controller area network bus are obtained; the remaining legitimate devices are the legitimate devices in the controller area network bus excluding the devices that send message signals.

[0041] The second fingerprint similarity is determined based on the device fingerprint of the device sending the message signal and the preset device fingerprint of the remaining legitimate devices; the second fingerprint similarity characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the preset device fingerprint of the remaining legitimate devices.

[0042] If the similarity of the second fingerprint is less than the second preset threshold, a protection signal for sending an invalid message signal is sent; if the similarity of the second fingerprint is greater than or equal to the second preset threshold, no protection signal is sent.

[0043] In an exemplary implementation, when the remaining legitimate devices include at least two legitimate devices; a second fingerprint similarity is determined based on the device fingerprint of the device sending the message signal and the preset device fingerprints of the remaining devices; if the second fingerprint similarity is less than a second preset threshold, a protection signal for sending invalid message signals is provided, including:

[0044] The remaining legitimate devices are identified as legitimate devices that have not undergone similarity processing with the device fingerprint of the device that sent the message signal.

[0045] The similarity of the second fingerprint of the legitimate device to be processed is determined based on the device fingerprint of the device sending the message signal and the preset device fingerprint of the legitimate device to be processed; the similarity of the second fingerprint of the legitimate device to be processed characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the preset device fingerprint of the legitimate device to be processed;

[0046] If the second fingerprint similarity of the legitimate device to be processed is greater than or equal to the second preset threshold, the legitimate device to be processed is determined from the remaining legitimate devices again; the remaining legitimate devices are legitimate devices that have not undergone similarity processing with the device fingerprint of the device that sent the message signal; the step of determining the second fingerprint similarity of the legitimate device to be processed based on the device fingerprint of the device that sent the message signal and the preset device fingerprint of the legitimate device to be processed continues until the second fingerprint similarity of the legitimate device to be processed is less than the second preset threshold, or there are no legitimate devices among the remaining legitimate devices that have not undergone similarity processing with the device fingerprint of the device that sent the message signal;

[0047] A protection signal is sent when the similarity of the second fingerprint of the legitimate device to be processed is less than the second preset threshold.

[0048] If none of the remaining legitimate devices have undergone similarity processing with the device fingerprint of the device that sent the message signal, then no protection signal will be sent.

[0049] On the other hand, a network security protection device is provided, the device comprising:

[0050] The acquisition module is used to acquire message signals on the controller area network bus;

[0051] The extraction module is used to extract control segment signals from the message signals; the control segment signals include reserved bit signals, rate switching bit signals, error status indication bit signals, and data length bit signals;

[0052] The segmentation processing module is used to segment the differential voltage values ​​corresponding to the control segment signals and generate the device fingerprint of the device sending the message signal.

[0053] The determination module is used to determine a first fingerprint similarity based on the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint; the first fingerprint similarity characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint;

[0054] The judgment module is a protection signal used to send an invalid message signal if the similarity of the first fingerprint is greater than a first preset threshold.

[0055] On the other hand, an electronic device is provided, including a processor and a memory, wherein the memory stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the network security protection method of any of the above aspects.

[0056] On the other hand, a computer-readable storage medium is provided, wherein at least one instruction or at least one program is stored therein, the at least one instruction or the at least one program being loaded and executed by a processor to implement the network security protection method as described above.

[0057] On the other hand, a computer program product or computer program is provided, which includes computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform any of the network security protection methods described above.

[0058] This application embodiment obtains the device fingerprint of the device sending the message signal by processing the control segment signal in the message signal on the CAN bus. The control segment signal includes reserved bit signals, rate switching bit signals, error status indication bit signals, and data length bit signals. Since the control segment signal in the message signal is parsed into a fixed sequence of bits, it is not affected by changes in the message signal's identification information (ID) or bit stuffing. Therefore, the device fingerprint obtained based on it has strong stability and robustness. In contrast, traditional methods use the message ID segment as the target signal to extract fingerprints, which is easily affected by arbitration of different device IDs. Moreover, the same device can send multiple IDs, resulting in the ID segment transmitted on the CAN bus being a superimposed signal of message signals sent by multiple devices. Using this as a device fingerprint leads to poor fingerprint stability and low robustness.

[0059] This application uses a stable device fingerprint to calculate its similarity with a stored preset device fingerprint corresponding to the same device. The similarity value is then compared with a preset threshold to determine whether the device sending the message signal is an illegitimate device. If the device is illegitimate, the message signal is invalidated, thus effectively identifying illegitimate devices on the CAN bus and improving the reliability of network protection on the CAN bus. Attached Figure Description

[0060] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0061] Figure 1 This is a schematic diagram of an implementation environment provided in an embodiment of this application;

[0062] Figure 2 This is a flowchart illustrating a network security protection method based on a controller area network bus provided in an embodiment of this application;

[0063] Figure 3 This is a schematic diagram of a process for obtaining a message signal provided in an embodiment of this application;

[0064] Figure 4 This is a schematic diagram of the structure of a message signal provided in an embodiment of this application;

[0065] Figure 5 This is a flowchart illustrating a method for determining a preset device fingerprint and a first preset threshold provided in an embodiment of this application;

[0066] Figure 6 This is a graph of the control segment signals of different devices provided in the embodiments of this application;

[0067] Figure 7 This is a graph showing the segmented processing of control segment signals from different devices, as provided in an embodiment of this application.

[0068] Figure 8 This is a schematic diagram of a process for generating a device fingerprint of a device for sending message signals, provided in an embodiment of this application.

[0069] Figure 9 This is a schematic diagram of a process for determining the similarity of a first fingerprint according to an embodiment of this application;

[0070] Figure 10 A flowchart illustrating another network security protection method based on a controller area network bus provided in this application embodiment;

[0071] Figure 11 This is a structural block diagram of a network security protection device provided in an embodiment of this application. Detailed Implementation

[0072] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0073] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0074] It is understood that in the specific embodiments of this application, data such as user information are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0075] Currently, the main countermeasures against attacks on vehicular networks are the following two protection strategies: one is message authentication. Although message authentication provides a certain level of security and has proven effective for network security, its adoption in vehicular networks is hindered by the following factors: (i) limited space available for attaching Media Access Control (MAC) codes to vehicular messages; and (ii) requirements for real-time processing and communication. The other is intrusion detection. The essence of state-of-the-art intrusion detection systems (IDS) is to monitor the content and cycle of vehicular messages and verify whether they have any significant changes. Since these messages are constant or predictable in vehicular networks, this approach is feasible in most cases. However, existing IDS still have the drawback of being unable to detect or prevent serious attacks, mainly for two reasons: 1) vehicular messages do not carry information on their transmitters, so it is impossible to determine whether they come from the real transmitter; 2) the lack of transmitter information makes it difficult or impossible for state-of-the-art IDS to identify which ECU initiated the attack.

[0076] Therefore, this application proposes a scheme to reliably protect the network security of the control system on the CAN bus. By processing the control segment signals in the message signals on the CAN bus, a device fingerprint of the device sending the message signal is obtained. The control segment signals include reserved bits, rate switching bits, error status indication bits, and data length bits. A similarity calculation is performed between this fingerprint and a stored preset device fingerprint corresponding to the device. The similarity value is then compared with a preset threshold to determine whether the device sending the message signal is an illegal device. If the device is illegal, the message signal is invalidated, thereby effectively identifying illegal devices on the CAN bus and improving the reliability of network protection on the CAN bus.

[0077] Please see Figure 1 The diagram illustrates an implementation environment provided in this application. This environment includes a CAN bus, multiple Electronic Control Units (ECUs) connected to the CAN bus, and a fingerprint processing device. The ECUs and fingerprint processing device are located within the same local area network. The ECUs transmit message signals via the CAN bus. The fingerprint processing device acquires the message signals on the CAN bus and processes the control segment signals within the message signals to obtain the device fingerprint of the device sending the message signal. The control segment signals include reserved bits, rate switching bits, error status indication bits, and data length bits. The device fingerprint of the device sending the message signal is compared with a stored preset device fingerprint for that device, and the similarity value is compared with a preset threshold to determine whether the device sending the message signal is an illegitimate device. If the device is illegitimate, the message signal is invalidated. Thus, without changing the vehicle message frame structure and meeting real-time processing and communication requirements, it can determine whether a message originates from a genuine transmitter and identify which ECU in the network initiated the attack.

[0078] Optionally, the CAN bus can be an in-vehicle network located on the vehicle, or a bus network located in other vehicles or control networks.

[0079] Optionally, the above-mentioned multiple ECUs are not limited to Figure 1 The number of ECUs shown, namely ECU1, ECU2 and ECU3, can also be other numbers of ECUs.

[0080] Optionally, the fingerprint processing device can be an integrated circuit with only processing functions, a device located in a terminal or server, or an integrated device consisting of a terminal and a server; there are no restrictions here.

[0081] Terminals include, but are not limited to, mobile phones, computers, smart voice interaction devices, and vehicle terminals.

[0082] A server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0083] Please see Figure 2 The diagram shown is a flowchart illustrating a network security protection method based on a controller area network bus provided in this application embodiment. This method can be applied to... Figure 1 The fingerprint processing device in the document. It should be noted that this specification provides the operational steps of the methods described in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operational steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many steps and does not represent the only execution order. In actual system or product execution, the methods shown in the embodiments or drawings can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment). Specifically, as shown... Figure 2 As shown, the method may include:

[0084] S201: Acquire message signals on the controller area network bus.

[0085] In this embodiment, the message signal is a Controller Area Network with Flexible Data-rate (CAN FD) signal. CAN FD can meet higher bandwidth and data throughput requirements. It not only inherits the main characteristics of the CAN bus, but also improves the bit rate and shortens the CAN frame. The frame can hold more data and has a higher performance Cyclic Redundancy Check (CRC) algorithm to meet the bandwidth and data throughput requirements of the significantly increased number of devices and data volume on the Controller Area Network bus.

[0086] In one exemplary implementation, see [reference] Figure 3 , Figure 3This is a schematic diagram of a process for obtaining message signals provided in an embodiment of this application. Step S201 may include: acquiring an initial message signal on the controller local area network bus; performing segmented decoding on the initial message signal to obtain a bit array corresponding to the start of frame (SOF) of the initial message signal; if the bit array corresponding to the start of frame of the initial message signal satisfies a first preset bit array, then the message signal containing the start frame is determined as a quasi-target message signal; acquiring the target remaining data segment signal in the quasi-target message signal; the target remaining data segment signal is a message signal that does not contain the start frame, end frame, and interval frame; and performing segmented decoding on the target remaining data segment signal in the quasi-target message signal to obtain a bit array of the remaining data segment signal in the quasi-target message signal; if the number of consecutive identical bit values ​​in the bit array of the remaining data segment signal in the quasi-target message signal is less than a preset number, then the quasi-target message signal is determined as the target message signal, i.e., the message signal in step S201 of this application; otherwise, the quasi-target message signal is determined as an invalid message signal; that is, this application identifies a valid CAN bus through SOF detection. The FD signal is then processed further; otherwise, the CAN FD signal of that frame is discarded and a new CAN FD signal is acquired to ensure the validity of the message signal.

[0087] In this embodiment, the start-of-frame bit detection is performed on the CAN FD signal. The CAN FD frame structure is as follows: Figure 4 As shown, according to the frame structure definition, there must be at least 10 bits '0' before the SOF flag bit, namely the 7-bit End of Frame (EOF) and the 3-bit Inter-frame Space (IFS). The SOF flag bit must be '1', meaning that there must be 10 bits '0' before the first bit '1' in the signal to pass SOF detection. If the SOF detection is passed, the message signal is recognized as a valid message and further processing is performed. Otherwise, the CAN FD signal of the frame is discarded and a new CAN FD signal is acquired. The sequence of the first preset bit array can be "00000000001".

[0088] In this embodiment, based on the CAN FD protocol, it is generally stipulated that when a sequence of 5 or more consecutive bit values ​​of 0 or 1 (i.e., 00000 or 11111) appears, the message signal is judged as an erroneous CAN FD data frame; that is, the preset number mentioned above can be 5.

[0089] See Figure 3When SOF detection is performed on the current message signal and an SOF frame is found, the system will continue to receive the message signal and decode the received frame signals sequentially. Typically, if the voltage value of the frame signal is greater than 1, it is decoded as a bit value 0; if the voltage value of the frame signal is less than or equal to 1, it is decoded as a bit value 1. The system will also determine the number of consecutive decoded bit values ​​of 0 or 1, and whether it is an erroneous frame. Figure 3 In the CAN FD frame, DCC=0 indicates that the number of consecutive 0 bits is 0, RCC=0 indicates that the number of consecutive 1 bits is 0, and Errorflag=0 indicates that the current frame is a correct frame. Correspondingly, Errorflag=1 indicates that the current frame is an error frame. When DCC=5 (i.e., the bit sequence is 00000) or RCC=5 (i.e., the bit sequence is 11111), the current frame is determined to be an error frame, i.e., Errorflag=1. In actual networks, error frames will not be received by the ECU. Therefore, the fingerprint processing device will first determine whether it is an error CAN FD frame. If it is correct, it will continue to execute the following steps, that is, extract the control segment signal from the message signal, including the Reserved (res), Bit Rate Switch (BRS), Error State Indicator (ESI), and Data Length Code (DLC) bits, and generate the corresponding fingerprint by segmenting the control segment signal. Otherwise, the frame is discarded.

[0090] In this embodiment, message signals on the CAN bus can be acquired based on a preset sampling rate fs, for example, fs = 50 Msps.

[0091] In one exemplary implementation, see [reference] Figure 5 , Figure 5 This is a flowchart illustrating a method for determining a preset device fingerprint and a first preset threshold provided in an embodiment of this application. Before acquiring the message signal on the controller local area network bus, the method further includes:

[0092] S501: Acquire the first number of historical message signals from the target device collected at a historical moment; the target device is the device that sent the message signal.

[0093] Steps S501-S511 are the training phase, which is to generate the preset device fingerprint and the first preset threshold of the target device. In order to facilitate subsequent similarity comparison, the preset device fingerprint and the corresponding second preset threshold of each legitimate device can be determined by collecting the historical message signals corresponding to all legitimate devices on the CAN bus, just as the preset device fingerprint and the first preset threshold of the target device are determined.

[0094] In this embodiment, CAN FD messages of the target legitimate device are collected on the CAN bus at a sampling rate of 50 Msps. The first quantity M can be 200, but it can also be set to other values, such as 14, 15, etc.; see reference. Figure 4 The data symbols in the message signal have different transmission rates and are mainly divided into arbitration segment and data segment. For example, the data symbol transmission rate of the arbitration segment is 500kbps, so the number of sampling points for each symbol in the arbitration segment is 50M / 500K = 100; the symbol transmission rate of the data segment is 2Mbps, so the number of sampling points for each symbol in the data segment is 50M / 2M = 25. The voltage threshold for bit decoding is set to 1V. If the voltage threshold is greater than 1V, it is decoded as bit '1', and otherwise as bit '0'.

[0095] S503: Extract the control segment signal from each historical message signal in the first number of historical message signals; and perform segmentation processing on the differential voltage value corresponding to the control segment signal in each historical message signal in the first number of historical message signals to generate a preset device fingerprint for each historical message signal.

[0096] like Figure 4 The control segment signal includes a reserved bit signal, a rate switching bit signal, an error status indicator bit signal, and a data length bit signal. The reserved bit signal corresponds to 1 bit value, the rate switching bit signal corresponds to 1 bit value, the error status indicator bit signal and the data length bit signal correspond to 1 bit value and 4 bit values ​​respectively. That is, the control segment signal is a 7-bit bit sequence, and it is unaffected by ID changes and bit stuffing; it is a fixed bit sequence, unlike the existing technology that uses a message ID segment (i.e.,...). Figure 4 Compared to using Identification as the target signal to extract fingerprints, the ID segment is easily affected by the arbitration of IDs from different devices, and the same device can send multiple IDs. As a result, the ID segment transmitted on the CAN bus is a superposition of message signals sent by multiple devices. Using it as a device fingerprint will lead to poor fingerprint stability and low robustness. However, since the control segment signal in this application corresponds to a fixed bit sequence, the fingerprint generated based on it has strong stability and robustness.

[0097] In reality, although the bit array obtained by decoding the control segment signal is a fixed sequence of bits, slight differences in the physical structure of different devices result in different differential voltage values ​​for the control segment signals sent by different devices (e.g., Figure 6 As shown in the figure, the control segment signal (i.e., differential voltage value) in the message signal can be processed to reliably characterize the corresponding device features.

[0098] In this embodiment, the sampling point corresponding to the control segment signal Cdata is 325, such as Figure 6 As shown, there is a significant difference in the differential voltage values ​​of the control segment signals of the two devices in the CAN bus network. After extracting the control segment signal data, the corresponding device fingerprint x is further extracted using a segmented calculation method. Setting the interval of the segmented calculation to 25 sampling points, the sampling points can be divided into 13 groups. The device fingerprint can be determined based on the following formula (1):

[0099]

[0100] Where cdata(k) represents the differential voltage value corresponding to sampling point k, k = 1, 2, 3, ... 325; the 13-dimensional fingerprints of two devices sending CAN FD signals in the network are as follows: Figure 7 As shown, there are obvious differences in device fingerprints between different devices.

[0101] For example, x(1) = sum(cdata(0),...,cdata(24)), x(2) = sum(cdata(25),...,cdata(49)), which represent the fingerprint vector of the first group of sampling points. By analogy, the fingerprint calculation of 13 groups of sampling points is completed. The device fingerprint x is a 13x1 one-dimensional column vector.

[0102] It should be noted that the number of sampling points in the control segment is determined based on the type of control segment signal, the data symbol transmission rate of the arbitration segment, the data symbol transmission rate of the data segment, and the sampling rate. Continuing the example above, if fs = 50 Msps and the data symbol transmission rate of the arbitration segment is 500 kbps, then the number of sampling points per symbol in the arbitration segment is 50M / 500K = 100; if the data symbol transmission rate is 2 Mbps, then the number of sampling points per symbol in the data segment is 50M / 2M = 25. Since the control segment is a 7-bit fixed bit sequence, refer to... Figure 4 The DLC and ESI bits are located in the data segment, and the res and BRS bits are located in the arbitration segment. Given the known symbol transmission rates of the data and arbitration segments, the number of sampling points corresponding to the control segment can be determined. Similarly, the number of sampling points in each group is determined based on the data symbol transmission rate of the arbitration segment, the data symbol transmission rate of the data segment, and the sampling rate. The minimum number of sampling points between the number of sampling points for each symbol in the arbitration segment and the number of sampling points for each symbol in the data segment can be used as the number of sampling points in each group. Therefore, in this embodiment, the number of sampling points in each group is 25.

[0103] S505: Determine a second number of historical message signals from a first number of historical message signals; the second number is determined based on the number of vectors contained in the device fingerprint, and the difference between the first number and the second number is greater than or equal to 1.

[0104] Optionally, the second quantity is denoted as K, where K is less than M. Based on the above example, the device fingerprint is a 13-dimensional vector, so K can be set to a value greater than or equal to 13 to ensure the accuracy of the subsequently determined preset device fingerprint and the first preset threshold.

[0105] S507: Determine the mean of the preset device fingerprint of the transmitted message signal based on the preset device fingerprint of each historical message signal in the second quantity of historical message signals; and determine the preset device fingerprint covariance of the transmitted message signal based on the preset device fingerprint and the mean of the preset device fingerprint of each historical message signal in the second quantity of historical message signals.

[0106] In this embodiment, K is set to 50, and the average fingerprint value μ of the target device is calculated by selecting the first 50 fingerprints from the target device.

[0107]

[0108] Where, x k Let k be the k-th preset device fingerprint of the target device, and let ∑ be the preset device fingerprint covariance of the target device.

[0109]

[0110] S509: For each remaining historical message signal in the remaining number of historical message signals, determine the Mahalanobis distance between the remaining historical message signal and the second number of historical message signals based on the preset device fingerprint of the remaining historical message signal, the preset device fingerprint mean of the sent message signal, and the preset device fingerprint covariance of the sent message signal; the remaining number is the difference between the first number and the second number. That is, calculate the similarity D between the preset device fingerprint of the remaining (MK) groups and the preset device fingerprint mean μ. j , and the first preset threshold T1.

[0111] In this embodiment, Mahalanobis distance is used to measure similarity. The smaller the Mahalanobis distance value, the more similar the two are. The Mahalanobis distance between the remaining 150 sets of preset device fingerprints of the target device and the mean μ of the preset device fingerprints is calculated using the following formula (4):

[0112]

[0113] The first preset threshold T1 for the target device is represented as:

[0114] T1=mean(D)+3*std(D) Formula (5)

[0115] in,

[0116]

[0117]

[0118] The first preset threshold T1 determined by the above formula (5) refers to the mean of multiple preset device fingerprints plus 3 times the standard deviation, which includes nearly 99% of the sample values, ensuring that all legitimate device samples are within the threshold.

[0119] Formula (7) is the standard deviation std(D) calculated using an unbiased estimation method. In fact, a biased estimation method can also be used. There is no restriction here. Furthermore, the method for calculating the similarity between the preset device fingerprint and the preset device fingerprint mean μ is not limited to the Mahalanobis distance mentioned above, but can also be the Euclidean distance.

[0120] S511: The first preset threshold is determined based on the Mahalanobis distance between each remaining historical message signal and the second number of historical message signals in the remaining number of historical message signals. The first preset threshold T1 can be calculated using the above formulas (5)-(7).

[0121] The above describes the process of determining the preset device fingerprint mean, preset device fingerprint covariance, and first preset threshold during training. The following will continue with... Figure 2 The steps of the actual use phase shown in step S203 will be explained.

[0122] S203: Extract the control segment signals from the message signals; the control segment signals include reserved bit signals, rate switching bit signals, error status indication bit signals, and data length bit signals.

[0123] In this embodiment, the message signal can be decoded first to obtain the bit sequence corresponding to the message signal, thereby determining the control segment signal, and then the control segment signal can be determined from the message signal. As mentioned above, since the control segment signal is a fixed bit sequence, it has the characteristics of strong stability and robustness, and the device fingerprint generated based on it also has strong stability and robustness.

[0124] S205: Perform segmentation processing on the differential voltage values ​​corresponding to the control segment signals to generate the device fingerprint of the device sending the message signal.

[0125] In one exemplary implementation, see [reference] Figure 8 , Figure 8 This is a schematic diagram illustrating the process of generating a device fingerprint for a device transmitting a message signal, as provided in an embodiment of this application. Step 205 may include:

[0126] S2051: Obtain the sampling rate of the message signal, the transmission rate of the arbitration segment data symbols in the message signal, and the transmission rate of the data segment symbols in the message signal.

[0127] In this embodiment, the sampling rate fs of the message signal collected during the usage phase is the same as that of the historical message signal collected during the training phase. Similarly, the transmission rate of the arbitration segment data symbols and the transmission rate of the data segment symbols in the message signal are also consistent between the usage phase and the training phase. For example, fs = 50Msps, the transmission rate of the arbitration segment data symbols is 500kbps, and the transmission rate of the data segment symbols is 2Mbps.

[0128] S2053: Determine the target interval sampling points based on the sampling rate of the message signal, the transmission rate of the arbitration segment data symbols in the message signal, and the transmission rate of the data segment symbols in the message signal.

[0129] In one feasible embodiment, step S2053 may include: determining the number of first interval sampling points based on the sampling rate of the message signal and the transmission rate of the arbitration segment data symbols in the message signal; determining the number of second interval sampling points based on the sampling rate of the message signal and the transmission rate of the data segment symbols in the message signal; and taking the interval sampling point number with the smallest value between the first interval sampling point number and the second interval sampling point number as the target interval sampling point number.

[0130] Continuing with the example above, the number of sampling points in the first interval is 50M / 500K = 100, and the number of sampling points in the second interval is 50M / 2M = 25. Therefore, the number of sampling points in the second interval, 25, is taken as the target number of sampling points in the interval.

[0131] S2055: Based on the target interval sampling point number, the message signal is segmented to obtain multiple sampling point datasets; each sampling point dataset includes the differential voltage values ​​of multiple sampling points; the number of sampling points in each sampling point dataset is equal to the target interval sampling point number.

[0132] Since the control segment is a 7-bit fixed bit sequence, see [link / reference] Figure 4 The DLC bit and ESI bit are in the data segment, and the res bit and BRS bit are in the arbitration segment. The symbol transmission rate of the data segment and the arbitration segment is known, so the number of sampling points corresponding to the control segment can be determined. The number of sampling points is 325. The message signal can be divided into 325 / 25 = 13 groups. The first group includes cdata(0),...,cdata(24), the second group includes cdata(25),...,cdata(49), and so on, to complete the segmentation of the 13 groups of sampling points. Here, cdata(0) represents the differential voltage value of the first sampling point.

[0133] S2057: For each sampling point dataset, determine the fingerprint of the sampling point dataset based on the differential voltage value of each sampling point in the sampling point dataset.

[0134] In an exemplary implementation, step S2057 may include: accumulating the differential voltage values ​​of each sampling point in the sampling point dataset to generate a fingerprint of the sampling point dataset.

[0135] For example, the first group corresponds to fingerprint x(1) = sum(cdata(0), ..., cdata(24)).

[0136] S2059: Determine the device fingerprint of the device that sent the message signal based on the fingerprint of the dataset of each sampling point.

[0137] In this embodiment, the device fingerprint can be calculated based on the above formula (1).

[0138] S207: Determine a first fingerprint similarity based on the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint; the first fingerprint similarity characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint.

[0139] In one exemplary implementation, see [reference] Figure 9 , Figure 9 This is a schematic diagram of a process for determining the similarity of a first fingerprint according to an embodiment of this application. Step S207 includes:

[0140] S2071: Determine the Mahalanobis distance between the device fingerprint of the device sending the message signal and the preset device fingerprint based on the device fingerprint of the device sending the message signal, the preset device fingerprint mean, and the preset device fingerprint covariance.

[0141] In one exemplary embodiment, prior to step 2071, the method may further include:

[0142] 1) Perform parsing and identifier segment extraction operations on the message signal in sequence to obtain the bit array of the identifier segment.

[0143] In this embodiment, see Figure 4 The identifier segment, also known as the ID segment, typically consists of an 11-bit bit array denoted as ID. Array For example, ID Array It is 10000000001.

[0144] 2) Decode the bit array of the identifier segment to generate the identifier of the message signal.

[0145] The identifier of the message signal can be calculated using the following formula (8):

[0146]

[0147] Continuing with the example above, the formula expands to 1*2 10 +0……+1*20 =1024+1=1025, that is, the 11-bit ID is 00000001025.

[0148] 3) Based on the identifier of the message signal, determine the device number that sent the message signal from the device information storage list; the device information storage list represents the correspondence between the identifier of the message signal and the device number.

[0149] Optionally, the above-mentioned device information storage list can be represented as a hash table, that is, the identifier of the message signal and the device number are stored in a hash table. The device number corresponding to the message can be found from the hash table according to the identifier of the message signal. In this embodiment, each message signal identifier can only correspond to one device number, but a device can send message signals with multiple message signal identifiers.

[0150] 4) Based on the device ID of the transmitted message signal, determine the preset device fingerprint mean and preset device fingerprint covariance from the device fingerprint storage list. The device fingerprint storage list represents the correspondence between the device ID and the preset device fingerprint mean and preset device fingerprint covariance. In other words, the preset device fingerprint mean and preset device fingerprint covariance determined during the training phase are stored in the device fingerprint storage list. This device fingerprint storage list and the device information storage list can be integrated into one table or two separate tables, and can be stored on the corresponding physical device as needed, for example, in a fingerprint processing device.

[0151] S2073: The Mahalanobis distance between the device fingerprint and the preset device fingerprint is determined as the first fingerprint similarity.

[0152] The Mahalanobis distance between the device fingerprint of the target device and the corresponding preset device fingerprint can be calculated using the above formula (4) to obtain the first fingerprint similarity. Alternatively, the Euclidean distance between the device fingerprint of the target device and the corresponding preset device fingerprint can be determined as the first fingerprint similarity. Of course, other similarity calculation methods can also be used according to actual needs. All similarity calculation methods involved in this application embodiment should be consistent, that is, they should all use Euclidean distance or Mahalanobis distance.

[0153] S209: If the similarity of the first fingerprint is greater than the first preset threshold, a protection signal for sending an invalid message signal is sent.

[0154] Specifically, the protection signal for invalid message signals can be a preset number of explicit or implicit voltage signals sent by the fingerprint processing device. This preset number is usually greater than or equal to 5, in order to destroy illegal message information and achieve the purpose of discarding the illegal message due to bit stuffing errors.

[0155] In one exemplary implementation, see [reference] Figure 10 , Figure 10 This is a flowchart illustrating another network security protection method based on a controller local area network (Controller Area Network) bus provided in this application embodiment. After step S207, the method further includes: if the first fingerprint similarity is less than or equal to a first preset threshold, then obtaining preset device fingerprints of the remaining legitimate devices in the Controller Area Network bus; the remaining legitimate devices are legitimate devices in the Controller Area Network bus excluding the device sending the message signal; determining a second fingerprint similarity based on the device fingerprint of the device sending the message signal and the preset device fingerprints of the remaining legitimate devices; the second fingerprint similarity characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the preset device fingerprints of the remaining legitimate devices; if the second fingerprint similarity is less than a second preset threshold, then sending a protection signal for invalid message signals; if the second fingerprint similarity is greater than or equal to the second preset threshold, not sending a protection signal.

[0156] In this embodiment, the method for determining the preset device fingerprint and the second preset threshold of the remaining legitimate devices on the bus can be as shown in steps S501-S511, which calculates the preset device fingerprint and the first preset threshold of the target device, and will not be repeated here.

[0157] In an exemplary embodiment, when the remaining legitimate devices include at least two legitimate devices; determining a second fingerprint similarity based on the device fingerprint of the device sending the message signal and the preset device fingerprint of the remaining devices; if the second fingerprint similarity is less than a second preset threshold, then sending a protection signal for invalid message signals includes: determining a legitimate device to be processed from the remaining legitimate devices; the remaining legitimate devices are legitimate devices that have not undergone similarity processing with the device fingerprint of the device sending the message signal; determining a second fingerprint similarity of the legitimate device to be processed based on the device fingerprint of the device sending the message signal and the preset device fingerprint of the legitimate device to be processed; the second fingerprint similarity of the legitimate device to be processed characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the preset device fingerprint of the legitimate device to be processed; if the second fingerprint similarity of the legitimate device to be processed is greater than a second preset threshold, then... If the value is equal to the second preset threshold, then the process repeats to determine the legitimate device to be processed from the remaining legitimate devices. The remaining legitimate devices are legitimate devices that have not undergone similarity processing with the device fingerprint of the device that sent the message signal. The process continues to determine the second fingerprint similarity of the legitimate device to be processed based on the device fingerprint of the device that sent the message signal and the preset device fingerprint of the legitimate device to be processed, until the second fingerprint similarity of the legitimate device to be processed is less than the second preset threshold, or there is no legitimate device among the remaining legitimate devices that has not undergone similarity processing with the device fingerprint of the device that sent the message signal. If the second fingerprint similarity of the legitimate device to be processed is less than the second preset threshold, then a protection signal for invalid message signals is sent. If there is no legitimate device among the remaining legitimate devices that has not undergone similarity processing with the device fingerprint of the device that sent the message signal, then no protection signal is sent.

[0158] As can be seen from the above technical solutions of the embodiments of this application, the embodiments of this application first extract the control segment signal from the historical message signal of each legitimate device in the CAN network during the training phase, further perform segmented integration on the control segment signal to obtain the preset device fingerprint of each legitimate device, and calculate the first preset threshold or the second preset threshold of each legitimate device, and store these data; in the actual use phase, the message signal collected on the CAN bus is parsed and extracted to obtain the identifier of the message signal, and the control segment signal in the message signal is extracted and segmented to generate the corresponding device fingerprint. Then, the preset device fingerprint of the corresponding legitimate device is searched in the corresponding storage list according to the identifier of the message signal, and the similarity between the two fingerprints is calculated. If the similarity is greater than the first preset threshold, the identity authentication fails and the device is judged as an illegal device. Otherwise, the similarity between the device fingerprint of the message signal and the fingerprints of other legitimate devices is further calculated. If there is a case where the similarity is less than the second preset threshold of a certain legitimate device, the identity authentication fails. Otherwise, the identity authentication succeeds and the device is judged as a legitimate device. This invention can extract device fingerprints from CANFD physical layer signals and effectively resist impersonation attacks both within and outside the domain by using a similarity comparison method. It can be widely used for identity authentication and system protection of CAN FD devices.

[0159] Corresponding to the network security protection methods based on the controller local area network bus provided in the above embodiments, this application also provides a network security protection device. Since the network security protection device provided in this application corresponds to the network security protection methods provided in the above embodiments, the implementation methods of the aforementioned network security protection methods are also applicable to the network security protection device provided in this embodiment, and will not be described in detail in this embodiment.

[0160] Please see Figure 11 The diagram shown is a structural schematic of a network security protection device provided in an embodiment of this application. This device has the function of implementing the network security protection method described in the above method embodiments. This function can be implemented by hardware or by hardware executing corresponding software. Figure 11 As shown, the device may include:

[0161] The acquisition module 1101 is used to acquire message signals on the controller local area network bus;

[0162] Extraction module 1103 is used to extract control segment signals from message signals; control segment signals include reserved bit signals, rate switching bit signals, error status indication bit signals, and data length bit signals;

[0163] The segmentation processing module 1105 is used to segment the differential voltage value corresponding to the control segment signal and generate the device fingerprint of the device that sends the message signal.

[0164] The determining module 1107 is used to determine a first fingerprint similarity based on the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint; the first fingerprint similarity characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint;

[0165] The judgment module 1109 is a protection signal used to send an invalid message signal if the similarity of the first fingerprint is greater than the first preset threshold.

[0166] In one exemplary embodiment, the segmentation processing module is used to acquire the sampling rate of the message signal, the transmission rate of the arbitration segment data symbols in the message signal, and the transmission rate of the data segment symbols in the message signal.

[0167] The target interval sampling points are determined based on the sampling rate of the message signal, the transmission rate of the arbitration segment data symbols in the message signal, and the transmission rate of the data segment symbols in the message signal.

[0168] Based on the target interval sampling point number, the message signal is segmented to obtain multiple sampling point datasets; each sampling point dataset includes the differential voltage values ​​of multiple sampling points; the number of sampling points in each sampling point dataset is equal to the target interval sampling point number;

[0169] For each sampling point dataset, the fingerprint of the sampling point dataset is determined based on the differential voltage values ​​of each sampling point in the sampling point dataset;

[0170] The device fingerprint of the device that sent the message signal is determined based on the fingerprint of the dataset of each sampling point.

[0171] In one exemplary embodiment, the segmentation processing module is configured to determine the number of sampling points in a first interval based on the sampling rate of the message signal and the transmission rate of the arbitration segment data symbols in the message signal; and to determine the number of sampling points in a second interval based on the sampling rate of the message signal and the transmission rate of the data segment symbols in the message signal.

[0172] The minimum number of sampling points between the first and second intervals is taken as the target interval number of sampling points.

[0173] In one exemplary implementation, the segmentation processing module is used to accumulate the differential voltage values ​​of each sampling point in the sampling point dataset to generate a fingerprint of the sampling point dataset.

[0174] In one exemplary embodiment, the determining module is configured to determine the Mahalanobis distance between the device fingerprint of the device sending the message signal and the preset device fingerprint based on the device fingerprint of the device sending the message signal, the preset device fingerprint mean, and the preset device fingerprint covariance.

[0175] The Mahalanobis distance between the device fingerprint and the preset device fingerprint is determined as the first fingerprint similarity.

[0176] In one exemplary implementation, the determining module is used to sequentially parse the message signal and extract the identifier segment to obtain a bit array of the identifier segment;

[0177] The bit array of the identifier segment is decoded to generate the identifier of the message signal;

[0178] Based on the identifier of the message signal, the device number that sent the message signal is determined from the device information storage list; the device information storage list represents the correspondence between the identifier of the message signal and the device number.

[0179] Based on the device ID of the transmitted message signal, the preset device fingerprint mean and preset device fingerprint covariance of the transmitted message signal are determined from the device fingerprint storage list; the device fingerprint storage list represents the correspondence between the device ID and the preset device fingerprint mean and preset device fingerprint covariance.

[0180] In one exemplary embodiment, the device further includes:

[0181] The training module is used to acquire the first number of historical message signals from the target device collected at historical moments; the target device is the device that sends the message signal.

[0182] Extract the control segment signal from each historical message signal in the first number of historical message signals; and perform segmentation processing on the differential voltage value corresponding to the control segment signal in each historical message signal in the first number of historical message signals to generate a preset device fingerprint for each historical message signal;

[0183] A second number of historical message signals are determined from a first number of historical message signals; the second number is determined based on the number of vectors contained in the device fingerprint, and the difference between the first number and the second number is greater than or equal to 1.

[0184] The mean of the preset device fingerprint of the sent message signal is determined based on the preset device fingerprint of each historical message signal in the second quantity of historical message signals; and the preset device fingerprint covariance of the sent message signal is determined based on the preset device fingerprint and the mean of the preset device fingerprint of each historical message signal in the second quantity of historical message signals.

[0185] For each remaining historical message signal in the remaining number of historical message signals, the Mahalanobis distance between the remaining historical message signal and the second number of historical message signals is determined based on the preset device fingerprint of the remaining historical message signal, the mean of the preset device fingerprint of the sent message signal, and the covariance of the preset device fingerprint of the sent message signal; the remaining number is the difference between the first number and the second number.

[0186] The first preset threshold is determined based on the Mahalanobis distance between each remaining historical message signal and the second number of historical message signals in the remaining number of historical message signals.

[0187] In one exemplary embodiment, the determination module is configured to obtain the preset device fingerprints of the remaining legitimate devices in the controller local area network bus if the first fingerprint similarity is less than or equal to a first preset threshold; the remaining legitimate devices are legitimate devices in the controller local area network bus excluding the devices that send message signals.

[0188] The second fingerprint similarity is determined based on the device fingerprint of the device sending the message signal and the preset device fingerprint of the remaining legitimate devices; the second fingerprint similarity characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the preset device fingerprint of the remaining legitimate devices.

[0189] If the similarity of the second fingerprint is less than the second preset threshold, a protection signal for sending an invalid message signal is sent; if the similarity of the second fingerprint is greater than or equal to the second preset threshold, no protection signal is sent.

[0190] In an exemplary implementation, when the remaining legitimate devices include at least two legitimate devices; the determination module is used to determine the legitimate device to be processed from the remaining legitimate devices; the remaining legitimate devices are legitimate devices that have not undergone similarity processing with the device fingerprint of the device that sent the message signal;

[0191] The similarity of the second fingerprint of the legitimate device to be processed is determined based on the device fingerprint of the device sending the message signal and the preset device fingerprint of the legitimate device to be processed; the similarity of the second fingerprint of the legitimate device to be processed characterizes the degree of similarity between the device fingerprint of the device sending the message signal and the preset device fingerprint of the legitimate device to be processed;

[0192] If the second fingerprint similarity of the legitimate device to be processed is greater than or equal to the second preset threshold, the legitimate device to be processed is determined from the remaining legitimate devices again; the remaining legitimate devices are legitimate devices that have not undergone similarity processing with the device fingerprint of the device that sent the message signal; the step of determining the second fingerprint similarity of the legitimate device to be processed based on the device fingerprint of the device that sent the message signal and the preset device fingerprint of the legitimate device to be processed continues until the second fingerprint similarity of the legitimate device to be processed is less than the second preset threshold, or there are no legitimate devices among the remaining legitimate devices that have not undergone similarity processing with the device fingerprint of the device that sent the message signal;

[0193] A protection signal is sent when the similarity of the second fingerprint of the legitimate device to be processed is less than the second preset threshold.

[0194] If none of the remaining legitimate devices have undergone similarity processing with the device fingerprint of the device that sent the message signal, then no protection signal will be sent.

[0195] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules when implementing its functions. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0196] This application provides an electronic device including a processor and a memory. The memory stores at least one instruction or at least one program, which is loaded and executed by the processor to implement any of the network security protection methods provided in the above method embodiments.

[0197] Memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. Memory can primarily include a program storage area and a data storage area. The program storage area can store the operating system, application programs required for the functions, etc.; the data storage area can store data created based on the use of the device, etc. Furthermore, memory can include high-speed random access memory, and can also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, memory can also include a memory controller to provide the processor with access to the memory.

[0198] Embodiments of this application also provide a computer-readable storage medium, which can be disposed in an electronic device to store at least one instruction or at least one program related to implementing a network security protection method. The at least one instruction or the at least one program is loaded and executed by the processor to implement any of the network security protection methods provided in the above-described method embodiments.

[0199] Embodiments of this application also provide a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform any of the network security protection methods provided in the above-described method embodiments.

[0200] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0201] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0202] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0203] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0204] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A method for network security protection based on a controller area network bus, characterized in that, The method comprises: acquiring a message signal on a controller area network bus; extracting a control section signal in the message signal; the control section signal comprises a reserved bit signal, a rate switch bit signal, an error status indication bit signal and a data length bit signal; segmenting a differential voltage value corresponding to the control section signal to generate a device fingerprint of a device sending the message signal; determining a first fingerprint similarity based on the device fingerprint of the device sending the message signal and a corresponding preset device fingerprint; the first fingerprint similarity represents a similarity degree between the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint; if the first fingerprint similarity is greater than a first preset threshold, sending a protection signal invalidating the message signal; the segmenting of the differential voltage value corresponding to the control section signal to generate the device fingerprint of the device sending the message signal comprises: determining a target interval sampling point number based on a sampling rate of the acquired message signal, a transmission rate of arbitration section data symbols in the message signal and a transmission rate of data section symbols in the message signal; segmenting the message signal based on the target interval sampling point number to obtain a plurality of sampling point data sets; each sampling point data set in the plurality of sampling point data sets comprises differential voltage values of a plurality of sampling points; a number of sampling points in each sampling point data set is equal to the target interval sampling point number; for each sampling point data set, determining a fingerprint of the sampling point data set based on the differential voltage values of the sampling points in the sampling point data set, or performing accumulation processing on the differential voltage values of the sampling points in the sampling point data set to generate the fingerprint of the sampling point data set; determining the device fingerprint of the device sending the message signal based on the fingerprints of the sampling point data sets.

2. The network security protection method of claim 1, wherein, The determining of the target interval sampling point number based on the sampling rate of the message signal, the transmission rate of the arbitration section data symbols in the message signal and the transmission rate of the data section symbols in the message signal comprises: determining a first interval sampling point number based on the sampling rate of the message signal and the transmission rate of the arbitration section data symbols in the message signal; determining a second interval sampling point number based on the sampling rate of the message signal and the transmission rate of the data section symbols in the message signal; taking the interval sampling point number with the minimum value between the first interval sampling point number and the second interval sampling point number as the target interval sampling point number.

3. The network security protection method of claim 1, wherein, The determining of the fingerprint of the sampling point data set based on the differential voltage values of the sampling points in the sampling point data set comprises: performing accumulation processing on the differential voltage values of the sampling points in the sampling point data set to generate the fingerprint of the sampling point data set.

4. The network security protection method of claim 1, wherein, The determining of the first fingerprint similarity based on the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint comprises: determining a Mahalanobis distance between the device fingerprint of the device sending the message signal and the preset device fingerprint based on the device fingerprint of the device sending the message signal, a mean value of the preset device fingerprint and a covariance of the preset device fingerprint. The Mahalanobis distance of the device fingerprint of the device sending the message signal and the preset device fingerprint is determined as the first fingerprint similarity.

5. The network security protection method of claim 4, wherein, Before the Mahalanobis distance of the device fingerprint of the device sending the message signal and the preset device fingerprint is determined based on the device fingerprint of the device sending the message signal, the preset device fingerprint mean and the preset device fingerprint covariance, the method further comprises: The message signal is sequentially subjected to parsing and identification segment extraction operations to obtain a bit array of the identification segment; The bit array of the identification segment is subjected to decoding processing to generate an identification of the message signal; Based on the identification of the message signal, a device number of the device sending the message signal is determined from a device information storage list; the device information storage list represents a corresponding relationship between the identification of the message signal and the device number; Based on the device number of the device sending the message signal, a preset device fingerprint mean and a preset device fingerprint covariance of the device sending the message signal are determined from a device fingerprint storage list; the device fingerprint storage list represents a corresponding relationship between the device number and the preset device fingerprint mean and the preset device fingerprint covariance.

6. The network security protection method of claim 1, wherein, Before the message signal on the controller area network bus is acquired, the method further comprises: A first number of historical message signals of a target device collected at a historical time are acquired; the target device is the device sending the message signal; A control segment signal in each of the first number of historical message signals is extracted, and a segmented processing is performed on a differential voltage value corresponding to the control segment signal in each of the first number of historical message signals to generate a preset device fingerprint of each of the historical message signals; A second number of historical message signals are determined from the first number of historical message signals; the second number is determined based on a number of vectors contained in the device fingerprint, and a difference between the first number and the second number is greater than or equal to 1; A preset device fingerprint mean of the device sending the message signal is determined based on the preset device fingerprint of each of the second number of historical message signals, and a preset device fingerprint covariance of the device sending the message signal is determined based on the preset device fingerprint of each of the second number of historical message signals and the preset device fingerprint mean; For each of a remaining number of historical message signals, a Mahalanobis distance of the remaining historical message signal and the second number of historical message signals is determined based on the preset device fingerprint of the remaining historical message signal, the preset device fingerprint mean of the device sending the message signal and the preset device fingerprint covariance of the device sending the message signal; the remaining number is a difference between the first number and the second number; The first preset threshold is determined based on the Mahalanobis distance of each of the remaining number of historical message signals and the second number of historical message signals.

7. The network security protection method according to any one of claims 1-4, characterized in that, After the first fingerprint similarity is determined based on the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint, the method further comprises: If the first fingerprint similarity is less than or equal to the first preset threshold, preset device fingerprints of remaining legal devices in the controller area network bus are acquired; the remaining legal devices are legal devices in the controller area network bus except the device sending the message signal; A second fingerprint similarity is determined based on the device fingerprint of the device sending the message signal and the preset device fingerprints of the remaining legal devices; the second fingerprint similarity represents a similarity degree between the device fingerprint of the device sending the message signal and the preset device fingerprints of the remaining legal devices; If the second fingerprint similarity is less than a second preset threshold, a protection signal invalidating the message signal is sent; in a case where the second fingerprint similarity is greater than or equal to the second preset threshold, the protection signal is not sent.

8. The network security protection method of claim 7, wherein, In a case where the remaining legal devices include at least two legal devices, the second fingerprint similarity is determined based on the device fingerprint of the device sending the message signal and the preset device fingerprints of the remaining legal devices; If the second fingerprint similarity is less than a second preset threshold, a protection signal invalidating the message signal is sent, including: A legal device to be processed is determined from the remaining legal devices; the remaining legal devices are legal devices that have not been subjected to similarity processing with the device fingerprint of the device sending the message signal; A second fingerprint similarity of the legal device to be processed is determined based on the device fingerprint of the device sending the message signal and a preset device fingerprint of the legal device to be processed; the second fingerprint similarity of the legal device to be processed represents a similarity degree between the device fingerprint of the device sending the message signal and the preset device fingerprint of the legal device to be processed; If the second fingerprint similarity of the legal device to be processed is greater than or equal to a second preset threshold, the step of determining the second fingerprint similarity of the legal device to be processed based on the device fingerprint of the device sending the message signal and the preset device fingerprint of the legal device to be processed is repeated until the second fingerprint similarity of the legal device to be processed is less than the second preset threshold, or there is no legal device that has not been subjected to similarity processing with the device fingerprint of the device sending the message signal in the remaining legal devices; In a case where the second fingerprint similarity of the legal device to be processed is less than the second preset threshold, the protection signal invalidating the message signal is sent; In a case where there is no legal device that has not been subjected to similarity processing with the device fingerprint of the device sending the message signal in the remaining legal devices, the protection signal is not sent.

9. A network security device comprising: The apparatus includes: An acquisition module configured to acquire a message signal on a controller area network bus; An extraction module configured to extract a control section signal in the message signal; the control section signal includes a reserved bit signal, a rate switch bit signal, an error status indication bit signal and a data length bit signal; The segmentation processing module is configured to perform segmentation processing on the differential voltage value corresponding to the control segment signal to generate a device fingerprint of a device sending the message signal. The determination module is configured to determine a first fingerprint similarity based on the device fingerprint of the device sending the message signal and a corresponding preset device fingerprint, where the first fingerprint similarity represents a similarity between the device fingerprint of the device sending the message signal and the corresponding preset device fingerprint. The judgment module is configured to send a protection signal invalidating the message signal if the first fingerprint similarity is greater than a first preset threshold. The segmentation processing on the differential voltage value corresponding to the control segment signal to generate a device fingerprint of a device sending the message signal includes: determining a target interval sampling point number based on a sampling rate of the obtained message signal, a transmission rate of arbitration segment data symbols in the message signal, and a transmission rate of data segment symbols in the message signal; performing segmentation processing on the message signal based on the target interval sampling point number to obtain a plurality of sampling point data sets, where each sampling point data set in the plurality of sampling point data sets includes differential voltage values of a plurality of sampling points, and a number of sampling points in each sampling point data set is equal to the target interval sampling point number; for each sampling point data set, determining a fingerprint of the sampling point data set based on the differential voltage values of the sampling points in the sampling point data set, or performing accumulation processing on the differential voltage values of the sampling points in the sampling point data set to generate the fingerprint of the sampling point data set; and determining a device fingerprint of the device sending the message signal based on the fingerprints of the sampling point data sets.

10. An electronic device, comprising: The computer readable storage medium stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the network security protection method according to any one of claims 1-8.

11. A computer readable storage medium, characterized in that, The computer readable storage medium stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the network security protection method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Deep SVDD-based vehicle external intrusion detection method and system

    CN113359666A

  • Production line network security protection method based on equipment fingerprint and national secret algorithm

    CN115567191A