A method for screening in-vehicle safety signals based on functional threat analysis

Through the in-vehicle safety signal screening method based on functional threat analysis, high-risk signals are screened out and reinforced according to the security level of the business and signal, which solves the problems of large screening workload and high resource consumption in the existing technology and improves the safety of intelligent connected vehicles.

CN116405311BActive Publication Date: 2025-09-30GUANGDONG WEICHEN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310507815.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-06
Publication Date
2025-09-30
Estimated Expiration
2043-05-06

AI Technical Summary

Technical Problem

Existing technologies impose a huge workload on in-vehicle safety signal screening in smart cars, making it difficult to efficiently screen out signals that require reinforcement, leading to ECU system resource consumption and communication delay problems.

Method used

Based on functional threat analysis, by determining the business information security level and functional safety level of in-vehicle signals, a business screening identifier and signal comprehensive security level mapping table are used to screen out high-risk in-vehicle signals for reinforcement.

Benefits of technology

It achieves more efficient in-vehicle safety signal screening, reduces ECU system resource consumption and communication delay, and improves the safety of intelligent connected vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405311B_ABST
    Figure CN116405311B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for screening in-vehicle safety signals based on functional threat analysis. First, based on the actual situation of an intelligent connected vehicle, the service set involved in its in-vehicle signals is determined, the service information security level of each service is determined, and then the service functional security level is determined. Based on the information security level and functional security level of the service, a service screening identifier mapping table is used to determine the service screening identifier, thereby obtaining a set of candidate in-vehicle signals. The in-vehicle signals in the candidate in-vehicle signal set are evaluated for a comprehensive signal security level. Finally, a safe signal set is screened from the candidate in-vehicle signal set based on the comprehensive signal security level. Based on threat analysis and risk assessment, the present invention screens in-vehicle signals to more efficiently reinforce the security of in-vehicle signals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of intelligent connected vehicle safety technology, and more specifically, relates to a method for screening in-vehicle safety signals based on functional threat analysis. Background Art

[0002] The development of connected smart cars is driving a surge in vehicle network communication data and signals, making network security protection crucial. While communication security measures are constantly being updated and upgraded, the resulting surge in data and signal security reinforcements inevitably leads to significant resource consumption in the vehicle's Electronic Control Unit (ECU), increased communication bus load, and signal latency. Therefore, a scientific and effective analysis and assessment method is urgently needed to determine the scope and targets of security reinforcement, thereby effectively mitigating the negative impact of security measures on ECUs.

[0003] Threat Analysis and Risk Assessment (TARA) is an analytical technology that identifies threats and assesses the corresponding risks. It allows developers to focus resources and efforts on cybersecurity activities corresponding to high-priority threats, analyzes and evaluates, and screens out signals with higher threat risk levels, effectively reducing the impact of security hardening measures on automotive ECU system resource consumption, network communication load, and communication latency. Figure 1 This is a flowchart of threat analysis and risk assessment for smart cars. Figure 1 The process shown analyzes safety signals to determine whether the target safety signal is suitable for implementing safety reinforcement measures. While TARA technology for both complete vehicles and components is relatively mature, the existing TARA process is inherently labor-intensive and difficult to implement when assessing the risk level of in-vehicle safety signals, making it incapable of effectively implementing reinforcement signal screening capabilities. Summary of the Invention

[0004] The purpose of the present invention is to overcome the shortcomings of the existing technology and provide an in-vehicle safety signal screening method based on functional threat analysis. Based on threat analysis and risk assessment, the in-vehicle signals are screened so as to more efficiently strengthen the security of the in-vehicle signals.

[0005] In order to achieve the above-mentioned object of the invention, the in-vehicle safety signal screening method based on functional threat analysis of the present invention comprises the following steps:

[0006] S1: First, based on the actual situation of the intelligent connected vehicle, determine the business set involved in its in-vehicle signal and determine the business information security level of each business. The specific method is as follows:

[0007] If a service is controlled by a computer and affects vehicle control and safety protection, the security threat level of the service is set to "dangerous";

[0008] If a service is connected to the outside world, or if it causes changes to the execution of services with a security threat level of "dangerous," or if it involves property, the security threat level of the service is set to "high."

[0009] If a service involves vehicle body control or sensitive information preset by the user, the security threat level of the service is set to "medium";

[0010] If a service does not meet the security threat level requirements of "critical", "high", or "medium", the security threat level of the service will be set to "low";

[0011] S2: For each service in the service set, set its service function security level according to its service function, from low to high: "no impact", "A", "B", "C", and "D";

[0012] S3: Determine the business screening identifier based on the business's information security level and functional security level. The specific method is as follows:

[0013] When the business function security level of a business is "no impact", "A" or "B", and the business information security level is "no impact" or "low", the business screening indicator is "not selected"; if the business information security level is "medium", the business screening indicator is "optional"; if the business information security level is "high" or "critical", the business screening indicator is "required";

[0014] When the business function security level of a business is "C" or "D", if the business information security level is "no impact", "low" or "medium", the business screening indicator is "optional"; if the business information security level is "high" or "critical", the business screening indicator is "required";

[0015] Divide the services into a mandatory service set B1, an optional service set B2, and an unselected service set B3 according to the service screening identifier; then obtain an in-vehicle signal set S1 involved in the services in the mandatory service set B1 and an in-vehicle signal set S2 involved in the optional service set B2, and use these two in-vehicle signal sets as candidate in-vehicle signal sets;

[0016] S4: For each in-vehicle signal in the in-vehicle signal set S1 and the in-vehicle signal set S2, determine its signal information security level based on the criticality of the information involved, from low to high: "no impact", "low", "medium", "high", and "severe". Then, based on the information security level of the in-vehicle signal and the information security level of the service corresponding to the in-vehicle signal, determine the comprehensive signal security level of the in-vehicle signal. The specific method is as follows:

[0017] When the signal's information security level is "no impact", the signal's comprehensive security level is also "no impact";

[0018] When the signal information security level is "low", if the service information security level of the signal corresponding service is "no impact", then the signal comprehensive security level is "no impact", otherwise the signal comprehensive security level is "low";

[0019] When the signal information security level is "medium", if the service information security level of the signal's corresponding service is "no impact", the signal's comprehensive security level is "no impact"; if the service information security level of the signal's corresponding service is "low", the signal's comprehensive security level is "low"; if the service information security level of the signal's corresponding service is "medium", "high" or "critical", the signal's comprehensive security level is "medium";

[0020] When the signal information security level is "high", if the service information security level of the signal's corresponding service is "no impact", the signal's comprehensive security level is "no impact"; if the service information security level of the signal's corresponding service is "low" or "medium", the signal's comprehensive security level is "medium"; if the service information security level of the signal's corresponding service is "high" or "critical", the signal's comprehensive security level is "high";

[0021] When the signal's information security level is "serious", if the service information security level of the signal's corresponding service is "no impact", the signal's comprehensive security level is "no impact"; if the service information security level of the signal's corresponding service is "low", "medium" or "high", the signal's comprehensive security level is "high"; if the service information security level of the signal's corresponding service is "dangerous", the signal's comprehensive security level is "critical";

[0022] S5: For the in-vehicle signal set S1, the in-vehicle signals with a comprehensive signal safety level of "high" and "critical" are used as safety signals. For the in-vehicle signal set S2, the in-vehicle signals with a comprehensive signal safety level of "critical" are used as safety signals, thus forming a safety signal set.

[0023] The present invention discloses an in-vehicle safety signal screening method based on functional threat analysis. First, according to the actual situation of the intelligent connected vehicle, the service set involved in its in-vehicle signals is determined, the service information security level of each service is determined, and then the service function security level is determined. According to the information security level and functional safety level of the service, a service screening identifier mapping table is used to determine the screening identifier of the service, thereby obtaining an alternative in-vehicle signal set, performing a signal comprehensive security level on the in-vehicle signals in the alternative in-vehicle signal set, and finally screening the alternative in-vehicle signal set to obtain a safety signal set according to the signal comprehensive security level.

[0024] The present invention screens in-vehicle signals based on threat analysis and risk assessment so as to more efficiently reinforce the security of in-vehicle signals. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is a flowchart of threat analysis and risk assessment for smart cars;

[0026] Figure 2 This is a flowchart of a specific implementation of the in-vehicle safety signal screening method based on functional threat analysis of the present invention. DETAILED DESCRIPTION

[0027] The following describes the specific embodiments of the present invention in conjunction with the accompanying drawings so that those skilled in the art can better understand the present invention. It should be noted that in the following description, when detailed descriptions of known functions and designs may dilute the main content of the present invention, such descriptions will be omitted here.

[0028] Example

[0029] Figure 2 This is a flow chart of a specific implementation of the in-vehicle safety signal screening method based on functional threat analysis of the present invention. Figure 2 As shown, the specific steps of the in-vehicle safety signal screening method based on functional threat analysis of the present invention include:

[0030] S201: Determine the business information security level:

[0031] Based on the above analysis, the present invention first determines the service set involved in the in-vehicle signal according to the actual situation of the intelligent connected vehicle, and determines the service information security level of each service. The specific method is as follows:

[0032] If a business is controlled by a computer and affects vehicle control and safety protection, the business information security level of the business is set to "dangerous";

[0033] If a business is connected to the outside world, or if the business will cause changes to the execution of a business with a business information security level of "dangerous", or if the business involves property, the business information security level of the business will be set to "high";

[0034] If a service does not affect driving safety or property, but involves vehicle body control or user-preset sensitive information, the service information security level of the service is set to "Medium";

[0035] If a service involves auxiliary functions such as information display, the security threat level for that service is set to "Low." This service generally does not affect driving safety and does not involve vehicle control or property, so the service information security level is set to "Low."

[0036] If a business does not meet the requirements of the business information security level of "dangerous", "high", "medium" or "low", the business information security level of the business will be set to "no impact".

[0037] According to the business structure of existing smart cars, the businesses with a security threat level of "dangerous" in this embodiment include: businesses involving longitudinal control of vehicle movement; businesses involving lateral control of vehicle movement; businesses involving stopping control of vehicle movement; businesses related to anti-collision radar; businesses related to Doppler radar; businesses related to infrared radar; active braking system business; lane keeping system business; lane change warning system business; traction control system business; electronic stability control system business; brake anti-lock system business; and electronic brake control system business.

[0038] In this embodiment, services with a security threat level of "high" include: services connected to Bluetooth; services connected to 4G and 5G; infrared data services; radar data services; window control services; door control services; services involving financial payments; power control battery services; and power battery temperature control services.

[0039] In this embodiment, services with a security threat level of "medium" include: services related to parking information; services related to driving tracks; wiper control services; headlight control services; and rearview mirror automatic control services.

[0040] In this embodiment, the services with a security threat level of "low" include: tire pressure feedback service; temperature feedback service; fuel feedback service; and water volume feedback service.

[0041] Based on the above services, the message IDs and ECU (sending / receiving) lists that need to be reinforced by SecOC are screened out.

[0042] S202: Determine the business function safety level:

[0043] In terms of the impact level of business functions, among safety, finance, operation, and privacy, the impact weight of operation and privacy is relatively small, and the impact level is mainly determined by safety and finance. For business functions, the financial level is mainly determined by the safety level. Therefore, when considering the impact level of business, the present invention simplifies it to mainly consider the safety factors of business functions. The functional safety level (ASIL) is the result of hazard analysis and risk assessment of automotive electronic systems. There are four levels of functional safety: A, B, C, and D, where A is the lowest level and D is the highest level. The classification of functional levels is mainly based on three indicators: severity, exposure, and controllability. The higher the functional level, the higher the safety requirements and the higher the cost of achieving safety.2 Functional safety levels can be broken down and allocated according to different uses and safety goals, and can be pre-evaluated and determined by professionals.

[0044] In the present invention, for each service in the service set, its service function security level is set according to its service function, which are "no impact", "A", "B", "C" and "D" from low to high.

[0045] S203: Filtering candidate in-vehicle signal sets:

[0046] According to the information security level and functional security level of the service, the service screening identifier mapping table is used to determine the service screening identifier of the service. Table 1 is the service screening identifier mapping table in the present invention.

[0047]

[0048] Table 1

[0049] According to Table 1, the method for determining the service screening identifier in the present invention is as follows:

[0050] When the business function security level of a business is "no impact", "A" or "B", and the business information security level is "no impact" or "low", the business screening indicator is "not selected"; if the business information security level is "medium", the business screening indicator is "optional"; if the business information security level is "high" or "critical", the business screening indicator is "required";

[0051] When the business function security level of a business is "C" or "D", if the business information security level is "no impact", "low" or "medium", the business screening indicator is "optional"; if the business information security level is "high" or "critical", the business screening indicator is "required".

[0052] Based on the service screening identifiers, the services are divided into a mandatory service set B1, an optional service set B2, and an unselected service set B3. Then, the in-vehicle signal set S1 involved in the services in the mandatory service set B1 and the in-vehicle signal set S2 involved in the optional service set B2 are obtained, and these two in-vehicle signal sets are used as the alternative in-vehicle signal sets.

[0053] S204: Determine the comprehensive signal safety level:

[0054] In existing intelligent connected vehicles, in-vehicle signals are transmitted via the CAN bus. In terms of threat level, regardless of the attack method used to compromise in-vehicle bus signals, physical contact is ultimately required to compromise the signals. Therefore, all communication channels within the vehicle have essentially the same threat level, and thus, security signals can be simply assumed to have essentially the same threat level. Therefore, in this disclosure, only the signal information security level of in-vehicle signals is considered.

[0055] For each in-vehicle signal in in-vehicle signal set S1 and in-vehicle signal set S2, its signal information security level is determined based on the criticality of the information involved, from low to high: "no impact," "low," "medium," "high," and "severe." The criticality of the information can be pre-assessed by professionals. Then, based on the information security level of the in-vehicle signal and the information security level of the service corresponding to the in-vehicle signal, a signal comprehensive security mapping table is used to determine the comprehensive signal security level of the in-vehicle signal. Table 2 shows the signal comprehensive security mapping table used in the present invention.

[0056]

[0057] Table 2

[0058] According to Table 2, the method for determining the comprehensive signal security level in the present invention is as follows:

[0059] When the signal's information security level is "no impact", the signal's comprehensive security level is also "no impact";

[0060] When the signal information security level is "low", if the service information security level of the signal corresponding service is "no impact", then the signal comprehensive security level is "no impact", otherwise the signal comprehensive security level is "low";

[0061] When the signal information security level is "medium", if the service information security level of the signal's corresponding service is "no impact", the signal's comprehensive security level is "no impact"; if the service information security level of the signal's corresponding service is "low", the signal's comprehensive security level is "low"; if the service information security level of the signal's corresponding service is "medium", "high" or "critical", the signal's comprehensive security level is "medium";

[0062] When the signal information security level is "high", if the service information security level of the signal's corresponding service is "no impact", the signal's comprehensive security level is "no impact"; if the service information security level of the signal's corresponding service is "low" or "medium", the signal's comprehensive security level is "medium"; if the service information security level of the signal's corresponding service is "high" or "critical", the signal's comprehensive security level is "high";

[0063] When the information security level of the signal is "serious", if the business information security level of the business corresponding to the signal is "no impact", the comprehensive security level of the signal is "no impact"; if the business information security level of the business corresponding to the signal is "low" or "medium" or "high", the comprehensive security level of the signal is "high"; if the business information security level of the business corresponding to the signal is "dangerous", the comprehensive security level of the signal is "critical".

[0064] S205: Filter and obtain a set of safety signals:

[0065] For the in-vehicle signal set S1, the in-vehicle signals with a comprehensive signal safety level of "high" and "critical" are used as safety signals. For the in-vehicle signal set S2, the in-vehicle signals with a comprehensive signal safety level of "critical" are used as safety signals, thus forming a safety signal set.

[0066] For in-vehicle signals in the security signal set, obtaining their message IDs and sending / receiving ECU lists for SecOC reinforcement can effectively improve the safety of intelligent connected vehicles.

[0067] Although the above describes the illustrative specific embodiments of the present invention to facilitate understanding of the present invention by those skilled in the art, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the appended claims, these changes are obvious, and all inventions and creations using the concepts of the present invention are protected.

Claims

1. A method for screening in-vehicle safety signals based on functional threat analysis, characterized in that: The following steps are involved: S1: First, based on the actual situation of the intelligent connected vehicle, determine the business set involved in its in-vehicle signal and determine the business information security level of each business. The specific method is as follows: If a service is controlled by a computer and affects vehicle control and safety protection, the security threat level of the service is set to "dangerous"; If a service is connected to the outside world, or if it causes changes to the execution of services with a security threat level of "Critical," or if it involves property, the security threat level of that service is set to "High." If a service involves vehicle body control or sensitive information preset by the user, the security threat level of the service is set to "medium"; If a service does not meet the security threat level requirements of "critical", "high", or "medium", the security threat level of the service will be set to "low"; S2: For each service in the service set, set its service function security level according to its service function, from low to high: "no impact", "A", "B", "C", and "D"; S3: Determine the business screening identifier based on the business's information security level and functional security level. The specific method is as follows: When the business function security level of a business is "No Impact", "A", or "B", and the business information security level is "No Impact" or "Low", the business screening indicator is "Not Selected". If the business information security level is "Medium", the business screening indicator is "Optional". If the business information security level is "High" or "Critical", the business screening indicator is "Required"; When the business function security level of a service is "C" or "D", and the business information security level is "No Impact", "Low", or "Medium", the business screening indicator is "Optional". If the business information security level is "High" or "Critical", the business screening indicator is "Required". Divide the services into a mandatory service set B1, an optional service set B2, and an unselected service set B3 according to the service screening identifier; then obtain an in-vehicle signal set S1 involved in the services in the mandatory service set B1 and an in-vehicle signal set S2 involved in the optional service set B2, and use these two in-vehicle signal sets as candidate in-vehicle signal sets; S4: For each in-vehicle signal in in-vehicle signal set S1 and in-vehicle signal set S2, determine its signal information security level based on the criticality of the information involved, from low to high: "no impact", "low", "medium", "high", and "severe". Then, based on the information security level of the in-vehicle signal and the information security level of the service corresponding to the in-vehicle signal, determine the comprehensive signal security level of the in-vehicle signal. The specific method is as follows: When the signal's information security level is "no impact", the signal's comprehensive security level is also "no impact"; When the signal information security level is "low", if the service information security level of the signal corresponding service is "no impact", the signal comprehensive security level is "no impact", otherwise the signal comprehensive security level is "low"; When the signal's information security level is "Medium", if the service information security level of the signal's corresponding service is "No Impact", the signal's comprehensive security level is "No Impact"; if the service information security level of the signal's corresponding service is "Low", the signal's comprehensive security level is "Low"; if the service information security level of the signal's corresponding service is "Medium", "High", or "Critical", the signal's comprehensive security level is "Medium"; When the signal's information security level is "High", if the service information security level of the signal's corresponding service is "No Impact", the signal's comprehensive security level is "No Impact"; if the service information security level of the signal's corresponding service is "Low" or "Medium", the signal's comprehensive security level is "Medium"; if the service information security level of the signal's corresponding service is "High" or "Critical", the signal's comprehensive security level is "High"; When the signal's information security level is "Severe", if the service information security level of the signal's corresponding service is "No Impact", the signal's comprehensive security level is "No Impact"; if the service information security level of the signal's corresponding service is "Low", "Medium", or "High", the signal's comprehensive security level is "High"; if the service information security level of the signal's corresponding service is "Critical", the signal's comprehensive security level is "Critical"; S5: For the in-vehicle signal set S1, the in-vehicle signals with a comprehensive signal safety level of "high" and "critical" are used as safety signals. For the in-vehicle signal set S2, the in-vehicle signals with a comprehensive signal safety level of "critical" are used as safety signals, thus forming a safety signal set.

2. The in-vehicle safety signal screening method according to claim 1, characterized in that: The services with a security threat level of "dangerous" in step S1 include: services involving longitudinal control of vehicle movement; services involving lateral control of vehicle movement; services involving stopping control of vehicle movement; services related to anti-collision radar; services related to Doppler radar; services related to infrared radar; services related to active braking systems; services related to lane keeping systems; services related to lane change warning systems; services related to traction control systems; services related to electronic stability control systems; services related to anti-lock braking systems; and services related to electronic brake control systems. Services with a security threat level of "high" include: services connected to Bluetooth; services connected to 4G and 5G; infrared data services; radar data services; window control services; door control services; Business involving financial payments; power control battery business; power battery temperature control business; Services with a security threat level of "medium" include: services involving parking information; services involving driving trajectories; windshield wiper control services; vehicle light control services; and automatic rearview mirror control services. Services with a security threat level of "low" include: tire pressure feedback service; temperature feedback service; fuel feedback service; and water volume feedback service.