Data transmission method, device, electronic device and storage medium between domain controllers

By introducing encryption processing of fresh values ​​and check codes between domain controllers, the problem of tampering in domain controller data transmission is solved, the security and reliability of data transmission are ensured, and vehicle control failures are avoided.

CN116582248BActive Publication Date: 2025-09-09GUOKE FOUNDATION STONE (CHONGQING) SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310334948.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-30
Publication Date
2025-09-09
Estimated Expiration
2043-03-30

AI Technical Summary

Technical Problem

There is a possibility that data may be tampered during data transmission between domain controllers, resulting in vehicle control failure.

Method used

By introducing encryption processing of fresh values ​​and check codes between domain controllers, communication protocol data segments are generated to ensure the integrity of data transmission.

Benefits of technology

It effectively avoids vehicle control failures caused by data tampering and improves the security and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116582248B_ABST
    Figure CN116582248B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method, device, electronic device, and storage medium for data transmission between domain controllers. The method includes: a first domain controller obtains a first freshness value associated with target transmission data; the first domain controller encrypts the target transmission data and the first freshness value to generate a first check code associated with the first freshness value; the first domain controller generates a first communication protocol data segment and a second communication protocol data segment, the second communication protocol data segment including the first freshness value and the first check code; the first domain controller transmits the first communication protocol data segment and the second communication protocol data segment to a second domain controller; the second domain controller decrypts the first communication protocol data segment to obtain the second freshness value; the second domain controller verifies the second freshness value and the first freshness value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of vehicle-mounted communication technology, and in particular to a method, device, electronic device, and storage medium for data transmission between domain controllers. Background Art

[0002] With the rapid development of vehicle technology, both gasoline-powered and electric vehicles are becoming increasingly popular and an integral part of people's daily lives. To achieve electronic and intelligent vehicle operation, the vehicle's internal electronic systems are typically divided into multiple functional blocks based on their functions. Domain controllers (DCs) are the leaders of these functional blocks. DCs not only control data transmission between systems within their respective blocks but also enable data transmission between DCs over the network, enabling data transmission between systems within different functional blocks within the vehicle.

[0003] Currently, data transmission between domain controllers—that is, data from one domain controller to another—is typically not processed; only quality assurance is required. However, data can be tampered with during transmission. If the receiving domain controller performs operations based on the tampered data, vehicle control failures may occur. Summary of the Invention

[0004] To overcome the problems existing in the related art, the present disclosure provides a method, device, electronic device and storage medium for data transmission between domain controllers.

[0005] According to a first aspect of an embodiment of the present disclosure, a method for data transmission between domain controllers is provided, the method comprising:

[0006] The first domain controller obtains a first freshness value associated with the target transmission data, the first freshness value being determined by at least one target counter associated with the first domain controller;

[0007] The first domain controller encrypts the target transmission data and the first freshness value to generate a first check code associated with the first freshness value;

[0008] The first domain controller generates a first communication protocol data segment and a second communication protocol data segment, the first communication protocol data segment includes target transmission data and a first check code, and the second communication protocol data segment includes a first freshness value and a first check code;

[0009] The first domain controller transmits the first communication protocol data segment and the second communication protocol data segment to the second domain controller;

[0010] The second domain controller decrypts the first communication protocol data segment to obtain a second freshness value;

[0011] The second domain controller verifies the second freshness value and the first freshness value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment.

[0012] In some implementations, the first domain controller obtains a first freshness value associated with target transmission data, including:

[0013] The first domain controller sends a synchronization notification message of a target synchronization period to the second domain controller according to the acquired target transmission data, where the target synchronization period is any synchronization period;

[0014] If a reception confirmation message based on the synchronization notification message feedback of the target synchronization period is received from the second domain controller, the first domain controller determines a first freshness value associated with the target transmission data according to a count value of at least one target counter in the target synchronization period.

[0015] According to a second aspect of an embodiment of the present disclosure, a device for data transmission between domain controllers is further provided, the device comprising:

[0016] a freshness value acquisition module, configured for the first domain controller to acquire a first freshness value associated with target transmission data, where the first freshness value is determined by at least one target counter associated with the first domain controller;

[0017] An encryption module, configured for the first domain controller to encrypt the first freshness value and generate a first check code associated with the first freshness value;

[0018] A first data segment generating module, configured for the first domain controller to generate a first communication protocol data segment and a second communication protocol data segment, wherein the first communication protocol data segment includes target transmission data and a first check code, and the second communication protocol data segment includes a first freshness value and a first check code;

[0019] A first transmission module is used for the first domain controller to transmit the first communication protocol data segment and the second communication protocol data segment to the second domain controller;

[0020] A first decryption module, configured for the second domain controller to decrypt the first communication protocol data segment to obtain a second freshness value;

[0021] The first verification module is used for the second domain controller to verify the second freshness value and the first freshness value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment.

[0022] According to a third aspect of an embodiment of the present disclosure, a vehicle is provided, storing a set of instruction sets, which are executed by the vehicle to implement the data transmission method between domain controllers provided by the first aspect of the present disclosure; including the data transmission device between domain controllers as described in the second aspect.

[0023] According to a fourth aspect of an embodiment of the present disclosure, an electronic device is provided, comprising: a processor; a memory for storing instructions executable by the processor; the processor for reading the executable instructions from the memory and executing the instructions to implement the data transmission method between domain controllers provided in the first aspect of the present disclosure.

[0024] According to a fifth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored. When the program instructions are executed by a processor, the steps of the data transmission method between domain controllers provided in the first aspect of the present disclosure are implemented.

[0025] The technical solution provided by the embodiments of the present disclosure may include the following beneficial effects: in the event that the target transmission data carried in the first communication protocol data segment is tampered with, the second fresh value obtained based on the decryption of the first communication protocol data segment must change from the original first fresh value (i.e., the first fresh value carried in the second communication protocol data segment), that is, the second fresh value parsed from the first communication protocol data segment and the first fresh value in the second communication protocol data segment will not match. At this time, by verifying the second fresh value with the first fresh value carried in the second communication protocol data segment, the second domain controller can determine that the target transmission data in the first communication data segment has been tampered with based on the verification result, and discard the target transmission data, thereby avoiding the second domain controller from performing operations based on the tampered target transmission data and reducing the possibility of failure in the control of the electronic device.

[0026] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0028] Figure 1 It is a structural diagram of the electronic and electrical architecture of a vehicle in the related art.

[0029] Figure 2 is a block diagram illustrating a method for transmitting data between domain controllers according to an exemplary embodiment;

[0030] Figure 3 is a flow chart illustrating a periodic synchronization fresh value synchronization mechanism according to an exemplary embodiment;

[0031] Figure 4 is a flow chart illustrating a mechanism for requesting fresh value synchronization according to an exemplary embodiment;

[0032] Figure 5 The present invention is a block diagram showing a data transmission device between domain controllers according to an exemplary embodiment.

[0033] Figure 6 is a block diagram of a vehicle according to an exemplary embodiment.

[0034] Figure 7 It is a block diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION

[0035] Exemplary embodiments will be described in detail below with reference to the accompanying drawings.

[0036] It should be pointed out that the relevant embodiments and drawings are only for describing exemplary embodiments provided by the present disclosure, rather than all embodiments of the present disclosure, and it should not be understood that the present disclosure is limited to the relevant exemplary embodiments.

[0037] It should be noted that the terms "first", "second", etc. used in this disclosure are only used to distinguish different steps, devices or modules, etc. The relevant terms neither represent any specific technical meanings nor indicate the order or interdependence between them.

[0038] It should be noted that the modifications of the terms "one", "a plurality of", and "at least one" used in the present disclosure are illustrative rather than restrictive. Unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0039] It should be noted that the term "and / or" used in this disclosure to describe an association relationship between associated objects generally indicates the existence of at least three types of association relationships. For example, "A and / or B" can represent at least three types of association relationships: the existence of A alone, the existence of both A and B, and the existence of B alone.

[0040] It should be noted that the steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. Unless otherwise specified, the scope of the present disclosure is not limited by the order in which the steps are described in the relevant embodiments.

[0041] It should be noted that all actions of acquiring signals, information or data in the present disclosure are carried out in compliance with the corresponding data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.

[0042] Exemplary Methods

[0043] In traditional distributed automotive electrical and electronic architectures, data transmission and control of sensors and various electrical and electronic systems within the vehicle are handled by distributed electronic control units (ECUs). With the increasing electrification and diversification of automotive functionality, the limitations of distributed architectures and ECUs have posed challenges to vehicle production costs, functional implementation, and future development. This has led to the emergence of more integrated and intelligent solutions—domain controllers and a centralized architecture within domains.

[0044] A "domain" is a collection of electronic and electrical architectures that control a major functional module in a vehicle. Each domain is centrally controlled by a domain controller. Typically, the vehicle's electronic and electrical architecture is divided into multiple domains, each managed by its own domain controller. This means that a vehicle is equipped with multiple domain controllers, each controlling a specific domain.

[0045] In related technologies, there are various ways to divide domains in a vehicle's electrical and electronic architecture, typically into a central gateway domain and multiple functional domains. The central gateway domain is primarily responsible for forwarding messages between the functional domains, including broadcast and unicast messages.

[0046] For example, the most typical division method is to divide the electronic and electrical architecture of the entire vehicle into five domains: power chassis domain, body domain, cockpit domain, intelligent driving domain and central gateway domain, and the five domains are respectively composed of Figure 1 The five domain controllers shown (i.e., power chassis domain controller, body domain controller, cockpit domain controller, intelligent driving domain controller, and central gateway domain controller) are controlled. The specific division of labor of each domain controller is as follows:

[0047] Power chassis domain controller

[0048] Control the vehicle's powertrain, optimize the vehicle's power performance, and ensure the vehicle's power safety. Functions include but are not limited to engine management, transmission management, battery management, power distribution management, emission management, speed limit management, and fuel and power saving management; and,

[0049] Control the vehicle's driving behavior and posture, including but not limited to brake system management, transmission system management, driving system management, steering system management, vehicle speed sensor management, body posture sensor management, air suspension system management, and airbag system management;

[0050] Body domain controller

[0051] Control various vehicle body functions, including but not limited to control of headlights, taillights, interior lights, door locks, windows, sunroof, wipers, electric trunk, smart keys, air conditioning, antenna and gateway communications, etc.

[0052] Cockpit domain controller

[0053] Control various electronic information system functions in the vehicle's intelligent cockpit, including the central control system, in-vehicle infotainment system, head-up display, seat system, instrument system, rearview mirror system, driving behavior monitoring system, and navigation system;

[0054] Intelligent Driving Domain Controller

[0055] Responsible for realizing and controlling the car's autonomous driving function, it needs to have the ability to receive image information, process and judge image information, process and calculate data, navigate and plan routes, and make quick judgments and decisions about real-time situations. It needs to process algorithms at the three levels of perception, decision-making, and control, and has the highest requirements for the domain controller's hardware and software.

[0056] Central Gateway Domain Controller

[0057] It is primarily responsible for forwarding messages between domains, including broadcast and unicast messages. The intelligent driving domain controller, cockpit domain controller, power chassis domain controller, and body domain controller can communicate with each other through the central gateway domain controller.

[0058] When the vehicle's electrical and electronic architecture is divided into a central gateway domain and multiple functional domains, data transmission between functional domains can be achieved through the following communication methods:

[0059] First communication method

[0060] The intelligent driving domain controller, cockpit domain controller, power chassis domain controller and body domain controller transmit data to each other through the central gateway domain controller;

[0061] Second communication method

[0062] In the scenario where the central gateway domain controller fails, the intelligent driving domain controller, cockpit domain controller, power chassis domain controller and body domain controller directly transmit data to each other. For example, Figure 1 As shown, the power chassis domain controller can directly transmit data with the body domain controller, the intelligent driving domain controller, and so on.

[0063] However, regardless of whether the first or second communication method is used to transmit data between functional domain controllers, data transmission between domain controllers is currently implemented using transparent transmission (also known as "transparent transmission"). That is, the transmission network is only responsible for transmitting the required data from one domain controller to another domain controller, regardless of the transmitted data, while ensuring the transmission quality, without processing the transmitted data. This makes it possible for data to be tampered with during transmission within the network. If the receiving domain controller performs operations based on the tampered data, it will cause vehicle control failure.

[0064] To solve the current problem of vehicle control failure caused by tampering of transmitted data between domain controllers, an exemplary embodiment shows the following method for data transmission between domain controllers.

[0065] See Figure 2 , is a block diagram of a data transmission method between domain controllers according to an exemplary embodiment, the method is applied to the above-mentioned electronic device, which may be a vehicle. Figure 2 As shown, the above method includes the following steps S201 to S206.

[0066] Step S201: A first domain controller obtains a first freshness value associated with target transmission data, where the first freshness value is determined by at least one target counter associated with the first domain controller.

[0067] In the embodiment of the present disclosure, the first domain controller may be any domain controller in the electronic device. For example, the electronic and electrical architecture of the electronic device is divided into Figure 1 In the case of the five domain controllers shown, the above-mentioned first domain controller can be any one of the intelligent driving domain controller, the cockpit domain controller, the power chassis domain controller, the body domain controller and the central gateway domain controller.

[0068] The first freshness value is determined by at least one target counter associated with the first domain controller, and can be determined based on the count value of the at least one target counter at the moment the target transmission data is obtained when the first domain controller obtains the target transmission data.

[0069] The above-mentioned first domain controller obtains the above-mentioned target transmission data, which may be when the first domain controller is the above-mentioned functional domain controller, and the above-mentioned target transmission data is collected by sensors in the domain corresponding to the domain controller; or, it may be when the first domain controller is the above-mentioned central gateway domain controller, and the data transmitted by the functional domain controller is received.

[0070] The at least one target counter associated with the first domain controller may be a counter pre-configured in the electronic device for the first domain controller; or, the electronic device may be configured with multiple counters, and the at least one target counter is at least one counter among the multiple counters that is associated with the configuration information of the first domain controller, and the configuration information may include at least one of a type and an attribute.

[0071] The multiple counters may be counters with different counting ranges. Specifically, the multiple counters may include a trip counter, a time counter, a watchdog counter, a message counter, and a reset counter, and the range of the reset counter is 1 to 2. 8 -1; the message counter range is 2 8 ~2 16 -1; the range of the watchdog counter is 2 16 ~2 32 -1; the range of the trip counter is 2 32 ~2 64 -1; the time counter has a range of 2 64 ~2 128 -1.

[0072] It should be noted that each of the above domain controllers can be associated with only one counter or multiple counters. For example, the above intelligent driving domain controller can be pre-configured to be associated with the reset counter, message counter, trip counter, and time counter; the above power chassis domain controller can be associated with the reset counter, message counter, and watchdog counter; the body domain controller can be associated with the reset counter, message counter, watchdog counter, trip counter, and time counter; the cockpit domain controller can be associated with the reset counter, message counter, and trip counter; and the central gateway domain controller can be associated only with the message counter.

[0073] The determination based on the count value of the at least one target counter at the moment when the target transmission data is acquired may be to determine the first fresh value as the product or difference between the at least one target counter.

[0074] Step S202: The first domain controller encrypts the first freshness value to generate a first verification code associated with the first freshness value.

[0075] In the embodiment of the present disclosure, the first domain controller encrypts the first freshness value, and may encrypt the first freshness value using a preset encryption algorithm.

[0076] The preset encryption algorithm can be any data that can be used to obtain a check code (also called a "key") from the transmitted data and the fresh value. Specifically, the encryption algorithm can be Advanced Encryption Standard (AES) 128, 192, or 256, a national encryption algorithm, etc. Since the processing of the encryption algorithm is well known in the art, it will not be described in detail here.

[0077] It should be noted that the above-mentioned first verification code can be obtained only by encrypting the above-mentioned target transmission data and the above-mentioned first fresh value; or, before the above-mentioned step S202, it can also include: obtaining the identity data of the first domain controller, which is used to identify the first domain controller; the above-mentioned step S202 can include: the first domain controller encrypts the target transmission data, the identity data and the first fresh value to generate a first verification code associated with the first fresh value.

[0078] The identification data of the first domain controller may be information pre-configured by the electronic device for the first domain controller, and the identification data may be different between different domain controllers in the electronic device. Specifically, the identification data may be a Secure Onboard Communication (SecOC) data identification number (Data-Identity Document, DataID), etc.

[0079] Step S203: The first domain controller generates a first communication protocol data segment and a second communication protocol data segment, where the first communication protocol data segment includes target transmission data and a first check code, and the second communication protocol data segment includes a first freshness value and a first check code.

[0080] In an embodiment of the present disclosure, when the first domain controller encrypts and obtains the first verification code, the first domain controller may combine the target transmission data and the first verification code to form the first communication protocol data segment; and combine the first freshness value and the first verification code to form the second communication protocol data segment. Each of the communication protocol data segments may include a Secured Protocol Data Unit (SPDU).

[0081] In the case where the above-mentioned first verification code is a verification code generated based on the above-mentioned target transmission data, the above-mentioned identity identification data and the above-mentioned first freshness value, the above-mentioned first communication protocol data segment may include the above-mentioned target transmission data, the above-mentioned identity identification data and the above-mentioned first verification code; and the above-mentioned second communication protocol data segment may include the above-mentioned first freshness value and the above-mentioned first verification code.

[0082] Step S204: The first domain controller transmits the first communication protocol data segment and the second communication protocol data segment to the second domain controller.

[0083] In the embodiment of the present disclosure, the second domain controller may be any domain controller in the electronic device other than the first domain controller, and may be capable of receiving data transmitted by the first domain controller.

[0084] Specifically, in the case where the first domain controller is the functional domain controller, the second domain controller may be a central gateway domain controller or any other functional domain controller that is directly connected to the first domain controller. Figure 1 In the case of the intelligent driving domain controller shown, the above-mentioned second domain controller can be a central gateway domain controller, a power chassis domain controller, or a cockpit domain controller.

[0085] Alternatively, in the case where the first domain controller is a central domain controller, the second domain controller may be a functional domain controller that receives the target transmission data. Figure 1 In the case of the central gateway domain controller shown, if the above-mentioned target transmission data is data transmitted from the intelligent driving domain controller to the body domain controller, then the above-mentioned second domain controller is the body domain controller.

[0086] The first domain controller transmits the first communication protocol data segment and the second communication protocol data segment to the second domain controller, and may continuously transmit the first communication protocol data segment and the second communication protocol data segment to the second domain controller within a preset time period, so that the second domain controller can determine whether to discard the target transmission data more promptly.

[0087] Step S205: The second domain controller decrypts the first communication protocol data to obtain a second freshness value.

[0088] In the embodiment of the present disclosure, the above-mentioned second domain controller decrypts the first communication protocol data segment to obtain the second fresh value. The second domain controller may input the target transmission data and the first verification code in the first communication protocol data segment into the decryption algorithm corresponding to the above-mentioned encryption algorithm to obtain the second fresh value.

[0089] For example, when the above encryption algorithm adopts the AES 128 encryption algorithm, the second domain controller can input the target transmission data and the first check code in the received first communication protocol data segment into the AES 128 decryption algorithm, and decrypt it to obtain the above second fresh value.

[0090] According to the principles of encryption and decryption, if the target transmission data of the first communication protocol data segment is tampered with during the data transmission process, and the first check code obtained by encryption has high security and cannot be tampered with, the second fresh value obtained by decrypting the tampered target transmission data and the first check code must be different from the first fresh value used during encryption.

[0091] If the first verification code is a verification code generated based on the target transmission data, the identity data, and the first freshness value, the first communication protocol data segment includes the target transmission data, the identity data, and the first verification code. In this case, the second domain controller decrypts the first communication protocol data segment to obtain the second freshness value. This can be done by inputting the target transmission data, the identity data, and the first verification code in the first communication protocol data segment into a decryption algorithm to decrypt the second freshness value.

[0092] Step S206: The second domain controller verifies the second freshness value and the first freshness value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment.

[0093] In the embodiment of the present disclosure, the above-mentioned second domain controller verifies the second fresh value and the first fresh value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment. The first domain controller can extract the first fresh value from the second communication data segment and verify the extracted first fresh value and the second fresh value, and determine whether to discard the target transmission data in the first communication protocol data segment based on the verification result. The verification result is used to indicate whether the first fresh value and the second fresh value match.

[0094] The above-mentioned determination of whether to discard the target transmission data in the first communication protocol data segment based on the verification result can be that when the verification result indicates that the first fresh value and the second fresh value do not match, it is determined that the target transmission data in the first communication protocol data segment has been tampered with, and the target transmission data in the first communication protocol data segment is discarded at this time; otherwise, it is not discarded.

[0095] Based on this, in the case where the target transmission data carried in the first communication protocol data segment is tampered with, the second fresh value obtained based on the decryption of the first communication protocol data segment must change from the original first fresh value (i.e., the first fresh value carried in the second communication protocol data segment), that is, the second fresh value obtained by parsing the first communication protocol data segment and the first fresh value in the second communication protocol data segment will not match. At this time, by verifying the second fresh value with the first fresh value carried in the second communication protocol data segment, the second domain controller can determine that the target transmission data in the first communication data segment has been tampered with based on the verification result, and discard the target transmission data, thereby avoiding the second domain controller from performing operations based on the tampered target transmission data and reducing the possibility of failure in the electronic device control.

[0096] In some implementations, the first domain controller obtains a first freshness value associated with target transmission data, including:

[0097] The first domain controller sends a synchronization notification message of a target synchronization period to the second domain controller according to the acquired target transmission data, where the target synchronization period is any synchronization period;

[0098] If a reception confirmation message based on the synchronization notification message feedback of the target synchronization period is received from the second domain controller, the first domain controller determines a first freshness value associated with the target transmission data according to a count value of at least one target counter in the target synchronization period.

[0099] In this embodiment, the first domain controller can send a synchronization notification message to the second domain controller in each synchronization cycle, and upon receiving a reception confirmation message from the second domain controller based on the feedback of the synchronization notification message, determine the first fresh value based on the count value of at least one target counter in the synchronization cycle in which the synchronization notification message is sent, thereby enabling the first domain controller to actively initiate the acquisition of the first fresh value to transmit the target transmission data.

[0100] The above-mentioned sending of the synchronization notification message of the target synchronization period to the second domain controller based on the acquired target transmission data may be that when the target transmission data is acquired, if the first domain controller detects that the current synchronization period has arrived, the synchronization notification message is sent to the second domain controller.

[0101] When the second domain controller receives the synchronization notification message sent by the first domain controller, the second domain controller will determine whether it needs to receive the target transmission data. If the second domain controller determines that it needs to receive the target transmission data, the second domain controller will send the above-mentioned reception confirmation message to the first domain controller.

[0102] The above-mentioned determination of the first fresh value associated with the target transmission data based on the count value of at least one target counter in the target synchronization period may be that the first domain controller uses the difference or product of the count values ​​of each counter in the at least one target counter in the target synchronization period as the first fresh value.

[0103] For example, Figure 3 As shown, a periodic synchronization fresh value synchronization mechanism may be configured, and the periodic synchronization fresh value synchronization mechanism may include the following steps:

[0104] Step S301: The sending node fresh value manager sends a fresh value synchronization notification message to the receiving node fresh value manager, wherein the sending node fresh value manager is the first domain controller, that is, the first domain controller sends a synchronization notification message of a target synchronization period to the second domain controller;

[0105] Step S302: The fresh value manager of the receiving node sends a fresh value synchronization reception confirmation message to the fresh value manager of the sending node in response to the received fresh value synchronization notification message. The fresh value synchronization reception confirmation message is used to indicate that the fresh value manager of the receiving node allows receiving the fresh value, that is, the second domain controller feeds back a reception confirmation message based on the synchronization notification message of the target synchronization period.

[0106] Step S303: The sending node fresh value manager sends the fresh value in the current period to the receiving node fresh value manager in response to the received fresh value synchronization reception confirmation message, that is, the first domain controller sends the first fresh value through the communication protocol data segment;

[0107] Step S304: The fresh value manager of the receiving node sends a fresh value reception confirmation message to the fresh value manager of the sending node in response to the received fresh value.

[0108] In some embodiments, before the first domain controller obtains the first freshness value associated with the target transmission data, the method further includes:

[0109] The first domain controller receives the synchronization request sent by the second domain controller.

[0110] The first domain controller obtaining a first freshness value associated with the target transmission data may include:

[0111] In response to the synchronization request, the first domain controller determines a first freshness value associated with the target transmission data according to the acquired target transmission data and a count value of at least one target counter.

[0112] In this embodiment, when the first domain controller receives a synchronization request sent by the second domain controller, it can respond to the synchronization request and determine the first freshness value based on the count value of at least one target counter. This can enable the first domain controller to passively obtain the first freshness value to transmit target data based on the data acquisition needs of the second domain controller.

[0113] The synchronization request may be a request initiated by the second domain controller to the first domain controller when the second domain controller requires the first domain controller to transmit the target transmission data to the second domain controller.

[0114] The above-mentioned determination of the first fresh value associated with the target transmission data based on the acquired target transmission data and the count value of at least one target counter can be understood as that when the first domain controller acquires the target transmission data, the first domain controller uses the difference or product of the count values ​​of each counter in at least one target counter when receiving the synchronization request as the first fresh value.

[0115] For example, Figure 4 As shown, a request fresh value synchronization mechanism may be configured. The periodic synchronization fresh value synchronization mechanism may include the following steps:

[0116] Step S401: The fresh value manager of the receiving node sends a fresh value synchronization request message to the fresh value manager of the sending node, that is, the second domain controller sends a synchronization request to the first domain controller;

[0117] Step S402: The sending node fresh value manager synchronizes the fresh value with the receiving node fresh value manager in response to the received fresh value synchronization request message. That is, the first domain controller determines the first fresh value associated with the target transmission data based on the acquired target transmission data and the count value of at least one target counter in response to the synchronization request, and sends the first fresh value to the second domain controller through the communication data segment.

[0118] Step S403: In the case of synchronizing fresh values, the sending node fresh value manager also sends a fresh value synchronization request confirmation message to the receiving node fresh value manager;

[0119] Step S404: The fresh value manager of the receiving node sends a fresh value reception confirmation message to the fresh value manager of the sending node in response to the received fresh value.

[0120] In some embodiments, the communication mode between the first domain controller and the second domain controller includes a first communication mode and a second communication mode, wherein the first communication mode is that the first domain controller and the second domain controller transmit data through a third domain controller; and the second communication mode is that the first domain controller and the second domain controller transmit data directly.

[0121] Before the first domain controller generates the first communication protocol data segment and the second communication protocol data segment, the method further includes:

[0122] When the first domain controller communicates with the second domain controller through the first communication mode, obtaining fault information of the first communication mode, where the fault information is used to indicate whether there is a fault in the first communication mode;

[0123] If the fault information indicates that the first communication mode has a fault, the first domain controller communicates with the second domain controller via the second communication mode;

[0124] The first communication protocol data segment and the second communication protocol data segment are communication protocol data segments generated under the second communication mode.

[0125] In this embodiment, when the first communication mode between the first domain controller and the second domain controller fails, the first domain controller can switch to the second communication mode in a timely manner, and under the second communication mode, the first domain controller transmits data to the second domain controller through the first communication protocol data segment and the second communication protocol data segment, so that when the central gateway domain controller fails, not only can normal data transmission between the first domain controller and the second domain controller be achieved, but also failure of electronic device control caused by tampering of the transmitted data can be avoided.

[0126] In this embodiment, the first domain controller and the second domain controller are two domain controllers that can communicate directly with each other. Figure 1 As shown, the first domain controller can be one of the intelligent driving domain controller and the power chassis domain controller, and the second domain controller is the other of the intelligent driving domain controller and the power chassis domain controller; or, the first domain controller can be one of the intelligent driving domain controller and the cockpit domain controller, and the second domain controller is the other of the intelligent driving domain controller and the cockpit domain controller, and so on.

[0127] The above-mentioned acquisition of the fault information of the first communication mode may be that the first domain controller detects whether it has received a message fed back by the central gateway domain controller when transmitting data to the central gateway domain controller. If the message is received, it is determined that the first communication mode is faulty; otherwise, it is normal.

[0128] The above-mentioned first communication protocol data segment and second communication protocol data segment are communication protocol data segments generated under the second communication mode. It can be understood that when the first domain controller transmits data to the second domain controller through the second communication mode, the first domain controller generates a first check code based on the target transmission data and the associated first freshness value, and further generates a first communication protocol data segment and a second communication protocol data segment and sends them to the second domain controller.

[0129] It should be noted that, when the above-mentioned first domain controller communicates with the first domain controller through the first communication method, the first domain controller can also generate the above-mentioned first communication protocol data segment and the above-mentioned second communication protocol data segment based on the first freshness value, target transmission data generation and the first verification code, which is not limited here.

[0130] In some embodiments, after the first domain controller encrypts the first freshness value and generates a first verification code associated with the first freshness value, the method further includes:

[0131] When the communication mode between the first domain controller and the second domain controller is the second communication mode, the first domain controller generates a third communication protocol data segment including target transmission data, a first freshness value, and a first check code;

[0132] The first domain controller transmits a third communication protocol data segment to the second domain controller in the electronic device;

[0133] The second domain controller decrypts the third communication protocol data segment to obtain a third freshness value;

[0134] The second domain controller verifies the third freshness value and the third freshness value in the third communication protocol data segment to determine whether to discard the target transmission data in the third communication protocol data segment.

[0135] In this embodiment, under the first communication mode, the first domain controller can send the above-mentioned target transmission data, the first freshness value and the first verification code through a communication protocol data segment (i.e., the third communication protocol data segment), so that the second domain controller can verify the freshness value based on the one communication protocol data segment, and then determine whether to discard the target transmission data, thereby making the method of determining whether to discard the target transmission data under the first communication mode more flexible.

[0136] For example, when the above-mentioned intelligent driving domain controller and the power chassis domain controller communicate through the central gateway domain controller, the intelligent driving domain controller can generate the above-mentioned third communication protocol data segment and send it to the chassis domain controller through the central gateway domain controller. The chassis domain controller determines whether to discard the target transmission data in the third communication protocol data segment based on the verification results of the third fresh value decrypted in the third communication protocol data segment and the first fresh value in the third communication protocol data segment.

[0137] It should be noted that the process of obtaining the third fresh value based on the decryption of the third communication protocol data segment is similar to the process of obtaining the second fresh value based on the decryption of the first communication protocol data segment, and will not be repeated here.

[0138] In addition, in the case where the first domain controller also obtains its identity identification data, the third communication protocol data may further include the identity identification data.

[0139] In some implementations, the first domain controller obtains a first freshness value associated with target transmission data, including:

[0140] The first domain controller obtains a count value of each target counter in at least one target counter;

[0141] The first domain controller determines a sum of count values ​​of at least one target counter as a first fresh value.

[0142] In this embodiment, by determining the sum of the count values ​​of at least one target counter as the first fresh value, the method for determining the first fresh value is made simpler and more flexible.

[0143] The above-mentioned determination of the sum of the count values ​​of at least one target counter as the first fresh value can be expressed by the following formula (1).

[0144]

[0145] In the above formula (1), FV(i) represents the first fresh value of the i-th domain controller. Where i is the serial number of the domain controller, for example, Figure 1 As shown, the values ​​of i are 1, 2, 3, 4, and 5, corresponding to the intelligent driving domain controller, power chassis domain controller, body domain controller, cockpit domain controller, and central gateway domain controller, respectively;

[0146] n represents the number of multiple counters configured in the electronic device;

[0147] C ij represents the count value of the jth counter;

[0148] m ij Pre-configured 0 or 1,m ij When it is zero, it means that the jth counter is not associated with the i-th domain controller; m ij When it is 1, it indicates that the jth counter is associated with the i-th domain controller.

[0149] For example, Figure 1As shown, assuming that the above-mentioned intelligent driving domain controller is pre-configured to be associated with the reset counter, message counter, trip counter and time counter; the above-mentioned power chassis domain controller is associated with the reset counter, message counter and watchdog counter; the body domain controller is associated with the reset counter, message counter, watchdog counter, trip counter and time counter; the cockpit domain controller is associated with the reset counter, message counter and trip counter; the central gateway domain controller is only associated with the message counter, then the first fresh value of each domain controller and the corresponding m can be represented by the following Table 1 ij .

[0150] Table 1 The first fresh value of each domain controller and the corresponding m ij

[0151] domain controller First fresh value <![CDATA[m ij ]]> Intelligent driving domain controller (j=1) <![CDATA[C 11 +C 12 +C 14 +C 15 ]]> <h2 style=";text-align:left;direction:ltr"><![CDATA[m <h2 style=";text-align:left;direction:ltr"> 1,2,4,5 <h2 style=";text-align:left;direction:ltr"> <1,m3=0]]><h2 style=";text-align:left;direction:ltr"> Power chassis domain controller (j=2) <![CDATA[C 21 +C 22 +C 23 ]]> <![CDATA[m 1,2,3 =1,m 4,5 =0]]> Body domain controller (j=3) <![CDATA[C 31 +C 32 +C 33 +C 34 +C 35 ]]> <![CDATA[m 1,2,3,4,5 =1]]> Cockpit domain controller (j=4) <![CDATA[C 41 +C 42 +C 44 ]]> <![CDATA[m 1,2,4 =1,m 3,5 =0]]> Central gateway domain controller (j=5) <![CDATA[C 52 ]]> <![CDATA[m2=1,m 1,3,4,5 =0]]>

[0152] It should be noted that the at least one target counter associated with each domain controller may be pre-configured and fixed.

[0153] In some implementations, a plurality of counters are configured in the first domain controller.

[0154] Before the first domain controller obtains the first freshness value associated with the target transmission data, the method further includes:

[0155] The first domain controller obtains a data volume of at least one historical transmission data transmitted by the first domain controller, where each historical transmission data is data transmitted by the first domain controller within a preset time period before a current moment;

[0156] The first domain controller determines a data volume distribution interval associated with the first domain controller based on a data volume of at least one historical transmission data, wherein the data volume of the at least one historical transmission data is within the data volume distribution interval;

[0157] The first domain controller determines at least one target counter from among the multiple counters based on the data volume distribution interval, wherein the distribution interval of the sum of the count values ​​of the at least one target counter includes the data volume distribution interval. In this embodiment, the first domain controller can determine at least one target counter from among the multiple counters that corresponds to the data volume distribution interval based on the data volume of historically transmitted data transmitted within a preset time period. This allows for real-time adjustment of the at least one target counter associated with each domain controller, resulting in a more reasonable at least one target counter associated with each domain controller.

[0158] The above-mentioned preset time period may be a time period with a preset time distance from the current moment, for example, it may be within the latest week, or within the latest month, and so on.

[0159] The above-mentioned determination of the data volume distribution interval associated with the first domain controller based on the data volume of at least one historical transmission data may be to use the maximum value and the minimum value of the data volume of the at least one historical transmission data as the two endpoint values ​​of the above-mentioned data volume distribution interval.

[0160] The distribution interval of the sum of the count values ​​of the at least one target counter includes the data volume distribution interval, which can be understood as the data volume distribution interval being completely within the distribution interval of the sum of the count values ​​of the at least one target counter.

[0161] Exemplary devices

[0162] Figure 5 FIG. 1 is a schematic diagram showing a structure of a data transmission device between domain controllers according to an exemplary embodiment. Figure 3 The device 500 includes a freshness value acquisition module 501, an encryption module 502, a first data segment generation module 503, a first transmission module 504, a first decryption module 505 and a first verification module 506.

[0163] The freshness value acquisition module 501 is configured to enable the first domain controller to acquire a first freshness value associated with target transmission data, where the first freshness value is determined by at least one target counter associated with the first domain controller.

[0164] Among them, the at least one target counter associated with the first domain controller may be the at least one target counter pre-configured in the electronic device for the first domain controller; or, the electronic device may be configured with multiple counters, and the at least one target counter is at least one counter among the multiple counters that is associated with the configuration information of the first domain controller, and the configuration information may include at least one item of type and attribute.

[0165] The encryption module 502 is configured to enable the first domain controller to encrypt the first freshness value and generate a first check code associated with the first freshness value.

[0166] The preset encryption algorithm may be any data that can be used to obtain a check code (also referred to as a "key") for the transmitted data and the fresh value. Specifically, the encryption algorithm may be Advanced Encryption Standard (AES) 128, 192, or 256, a national encryption algorithm, or the like.

[0167] The first data segment generation module 503 is used by the first domain controller to generate a first communication protocol data segment and a second communication protocol data segment, the first communication protocol data segment includes target transmission data and a first check code, and the second communication protocol data segment includes a first freshness value and a first check code.

[0168] In which, when the first domain controller encrypts and obtains the first verification code, the first domain controller can combine the target transmission data and the first verification code to form the first communication protocol data segment (Secured Protocol Data Unit, SPDU); and, combine the first fresh value and the first verification code to form the second communication protocol data segment.

[0169] The first transmission module 504 is configured to transmit a first communication protocol data segment and a second communication protocol data segment from the first domain controller to the second domain controller.

[0170] Among them, the above-mentioned first domain controller transmits the above-mentioned first communication protocol data segment and the second communication protocol data segment to the second domain controller, and can continuously transmit the first communication protocol data segment and the second communication protocol data segment to the second domain controller within a preset time period, so that the second domain controller can determine whether to discard the target transmission data more promptly.

[0171] The first decryption module 505 is used for the second domain controller to decrypt the first communication protocol data segment to obtain a second freshness value.

[0172] Among them, the above-mentioned second domain controller decrypts the first communication protocol data segment to obtain the second fresh value. The second domain controller may input the target transmission data and the first verification code in the first communication protocol data segment into the decryption algorithm corresponding to the above-mentioned encryption algorithm to obtain the second fresh value.

[0173] The first verification module 506 is configured for the second domain controller to verify the second freshness value and the first freshness value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment.

[0174] Among them, the above-mentioned determination of whether to discard the target transmission data in the first communication protocol data segment based on the verification result can be that when the verification result indicates that the first fresh value and the second fresh value do not match, it is determined that the target transmission data in the first communication protocol data segment has been tampered with, and the target transmission data in the first communication protocol data segment is discarded at this time; otherwise, it is not discarded.

[0175] In some implementations, the fresh value acquisition module 501 includes:

[0176] A synchronization notification message sending unit is configured to cause the first domain controller to send a synchronization notification message of a target synchronization period to the second domain controller according to the acquired target transmission data, where the target synchronization period is any synchronization period;

[0177] The first freshness value determination unit is used to determine the first freshness value associated with the target transmission data based on the count value of at least one target counter in the target synchronization period if a reception confirmation message of the synchronization notification message feedback based on the target synchronization period is received from the second domain controller.

[0178] In this embodiment, the above-mentioned sending of the synchronization notification message of the target synchronization period to the second domain controller based on the acquired target transmission data may be that when the target transmission data is acquired, if the first domain controller detects that the current synchronization period has arrived, the synchronization notification message is sent to the second domain controller.

[0179] When the second domain controller receives the synchronization notification message sent by the first domain controller, the second domain controller will determine whether it needs to receive the target transmission data. If the second domain controller determines that it needs to receive the target transmission data, the second domain controller will send the above-mentioned reception confirmation message to the first domain controller.

[0180] In some embodiments, the apparatus 500 further includes:

[0181] The synchronization request receiving module is used for the first domain controller to receive the synchronization request sent by the second domain controller.

[0182] The fresh value acquisition module 501 can be specifically used to:

[0183] In response to the synchronization request, the first domain controller determines a first freshness value associated with the target transmission data according to the acquired target transmission data and a count value of at least one target counter.

[0184] In this implementation manner, the synchronization request may be a request initiated by the second domain controller to the first domain controller when the second domain controller requires the first domain controller to transmit the target transmission data to the second domain controller.

[0185] In some embodiments, the communication mode between the first domain controller and the second domain controller includes a first communication mode and a second communication mode, wherein the first communication mode is that the first domain controller and the second domain controller transmit data through a third domain controller; and the second communication mode is that the first domain controller and the second domain controller transmit data directly.

[0186] The apparatus 500 may further include:

[0187] a fault information acquisition module, configured to acquire fault information of the first communication mode when the first domain controller communicates with the second domain controller via the first communication mode, the fault information being used to indicate whether there is a fault in the first communication mode;

[0188] a communication mode updating module, configured to cause the first domain controller to communicate with the second domain controller via a second communication mode if the fault information indicates that the first communication mode has a fault;

[0189] The first communication protocol data segment and the second communication protocol data segment are communication protocol data segments generated under the second communication mode.

[0190] In this embodiment, the above-mentioned acquisition of the fault information of the first communication mode can be that the first domain controller detects whether it has received a message fed back by the central gateway domain controller when transmitting data to the central gateway domain controller. If the message is received, it is determined that the first communication mode is faulty; otherwise, it is normal.

[0191] In some embodiments, the apparatus 500 further comprises:

[0192] a second data segment generating module, configured to generate, by the first domain controller, a third communication protocol data segment including target transmission data, a first freshness value, and a first check code when the communication mode between the first domain controller and the second domain controller is the first communication mode;

[0193] A second transmission module is used for the first domain controller to transmit a third communication protocol data segment to a second domain controller in the electronic device;

[0194] a second decryption module, configured for the second domain controller to decrypt the third communication protocol data segment to obtain a third freshness value;

[0195] The second verification module is used for the second domain controller to verify the third freshness value and the first freshness value in the third communication protocol data segment to determine whether to discard the target transmission data in the third communication protocol data segment.

[0196] For example, when the above-mentioned intelligent driving domain controller and the power chassis domain controller communicate through the central gateway domain controller, the intelligent driving domain controller can generate the above-mentioned third communication protocol data segment and send it to the chassis domain controller through the central gateway domain controller. The chassis domain controller determines whether to discard the target transmission data in the third communication protocol data segment based on the verification results of the third fresh value decrypted in the third communication protocol data segment and the first fresh value in the third communication protocol data segment.

[0197] In some implementations, the fresh value acquisition module 501 includes:

[0198] a count value acquiring unit, configured for the first domain controller to acquire a count value of each target counter in at least one target counter;

[0199] The third freshness value determining unit is configured to enable the first domain controller to determine a sum of count values ​​of at least one target counter as a first freshness value.

[0200] In some embodiments, a plurality of counters are configured in the first domain controller;

[0201] The apparatus 500 further includes:

[0202] A data volume acquisition module is configured to be used by the first domain controller to acquire the data volume of at least one historical transmission data transmitted by the first domain controller, where each historical transmission data is data transmitted by the first domain controller within a preset period before a current moment;

[0203] a distribution interval determining module, configured for the first domain controller to determine a data volume distribution interval associated with the first domain controller based on a data volume of at least one historical transmission data, wherein the data volume of the at least one historical transmission data is within the data volume distribution interval;

[0204] The counter determination module is used for the first domain controller to determine at least one target counter from multiple counters according to the data volume distribution interval, wherein the distribution interval of the sum of the count values ​​of the at least one target counter includes the data volume distribution interval.

[0205] In this embodiment, the data volume distribution interval associated with the first domain controller is determined based on the data volume of at least one historical transmission data, and the maximum value and the minimum value of the data volume of the at least one historical transmission data can be used as the two endpoint values ​​of the above data volume distribution interval.

[0206] The distribution interval of the sum of the count values ​​of the at least one target counter includes the data volume distribution interval, which can be understood as the data volume distribution interval being completely within the distribution interval of the sum of the count values ​​of the at least one target counter.

[0207] The training device for the vehicle chassis control model provided by the embodiment of the present disclosure can achieve Figures 2 to 4 The various processes implemented in the method embodiment shown achieve the same technical effect, and to avoid repetition, they will not be described again here.

[0208] Example Vehicle

[0209] Figure 6 FIG. 1 is a block diagram of a vehicle 600 according to an exemplary embodiment. The vehicle 600 may be a fuel vehicle, a hybrid vehicle, an electric vehicle, a fuel cell vehicle, or other types of vehicles.

[0210] Reference Figure 6The vehicle 600 may include multiple subsystems, such as a drive system 610, a control system 620, a perception system 630, a communication system 640, an information display system 650, and a computing system 660. The vehicle 600 may also include more or fewer subsystems, and each subsystem may include multiple components, which are not described in detail here.

[0211] The drive system 610 includes components that provide power for the vehicle 600, such as an engine, an energy source, a transmission, and the like.

[0212] The control system 620 includes components that provide control for the vehicle 600, such as vehicle control, cabin equipment control, and driver assistance control.

[0213] The perception system 630 includes components that provide the vehicle 600 with environmental awareness, such as a vehicle positioning system, a laser sensor, a voice sensor, an ultrasonic sensor, and a camera.

[0214] The communication system 640 includes components that provide communication connections for the vehicle 600, such as mobile communication networks (e.g., 3G, 4G, 5G networks, etc.), WiFi, Bluetooth, and Internet of Vehicles.

[0215] The information display system 650 includes components that provide various information displays for the vehicle 600, such as vehicle information display, navigation information display, entertainment information display, etc.

[0216] The computing and processing system 660 includes components that provide data computing and processing capabilities for the vehicle 600. The computing and processing system 660 may include at least one processor 661 and a memory 662. The processor 661 may execute instructions stored in the memory 662.

[0217] The processor 661 can be any conventional processor, such as a commercially available CPU. The processor can also include a graphics processor (GPU), a field programmable gate array (FPGA), a system on chip (SOC), an application specific integrated circuit (ASIC), or a combination thereof.

[0218] The memory 662 may be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.

[0219] In the embodiment of the present disclosure, a set of instruction sets is stored in the memory 662, and the processor 661 can execute the instruction set to implement all or part of the steps of the data transmission method between domain controllers described in any of the above exemplary embodiments.

[0220] Exemplary electronic devices

[0221] Figure 7 FIG. 7 is a block diagram of an electronic device 700 according to an exemplary embodiment. The electronic device 700 may be a vehicle controller, a vehicle terminal, a vehicle computer, or other types of electronic devices.

[0222] Reference Figure 7 The electronic device 700 may include at least one processor 710 and a memory 720. The processor 710 may execute instructions stored in the memory 720. The processor 710 is communicatively connected to the memory 720 via a data bus. In addition to the memory 720, the processor 710 may also be communicatively connected to an input device 730, an output device 740, and a communication device 770 via a data bus.

[0223] The processor 710 may be any conventional processor, such as a commercially available CPU. The processor may also include a graphics processor (GPU), a field programmable gate array (FPGA), a system on chip (SOC), an application specific integrated circuit (ASIC), or a combination thereof.

[0224] The memory 720 may be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.

[0225] In an embodiment of the present disclosure, executable instructions are stored in the memory 720, and the processor 710 can read the executable instructions from the memory 720 and execute the instructions to implement all or part of the steps of the data transmission method between domain controllers described in any of the above exemplary embodiments.

[0226] Exemplary computer-readable storage media

[0227] In addition to the above methods and apparatuses, exemplary embodiments of the present disclosure may also be a computer program product or a computer-readable storage medium storing the computer program product. The computer product includes computer program instructions that can be executed by a processor to implement all or part of the steps described in any of the methods in the above exemplary embodiments.

[0228] The computer program product may be written in any combination of one or more programming languages ​​to implement the program code for performing the operations of the disclosed embodiments, including object-oriented programming languages ​​such as Java, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages ​​and scripting languages ​​(e.g., Python). The program code may be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0229] The computer-readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can include, for example, but is not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples of readable storage media include: a static random access memory (SRAM) electrically connected with one or more wires, an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk or an optical disk, or any suitable combination thereof.

[0230] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the present disclosure. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.

[0231] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A data transmission method between domain controllers, characterized in that: The method comprises: The first domain controller obtains a first freshness value associated with target transmission data, the first freshness value being determined by at least one target counter associated with the first domain controller; The first domain controller encrypts the target transmission data and the first freshness value to generate a first check code associated with the first freshness value; The first domain controller generates a first communication protocol data segment and a second communication protocol data segment, the first communication protocol data segment includes the target transmission data and the first check code, and the second communication protocol data segment includes the first freshness value and the first check code; The first domain controller transmits the first communication protocol data segment and the second communication protocol data segment to the second domain controller; The second domain controller decrypts the first communication protocol data segment to obtain a second freshness value; The second domain controller verifies the second freshness value and the first freshness value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment.

2. The method according to claim 1, characterized in that The first domain controller obtains a first freshness value associated with target transmission data, including: The first domain controller sends a synchronization notification message of a target synchronization period to the second domain controller according to the acquired target transmission data, where the target synchronization period is any synchronization period; If a reception confirmation message is received from the second domain controller based on the synchronization notification message feedback of the target synchronization period, the first domain controller determines a first freshness value associated with the target transmission data according to the count value of the at least one target counter in the target synchronization period.

3. The method according to claim 1, characterized in that Before the first domain controller obtains the first freshness value associated with the target transmission data, the method further includes: The first domain controller receives a synchronization request sent by the second domain controller; The first domain controller obtains a first freshness value associated with target transmission data, including: In response to the synchronization request, the first domain controller determines a first freshness value associated with the target transmission data according to the acquired target transmission data and a count value of the at least one target counter.

4. The method according to claim 1, wherein The communication mode between the first domain controller and the second domain controller includes a first communication mode and a second communication mode, wherein the first communication mode is that the first domain controller and the second domain controller transmit data through a third domain controller; and the second communication mode is that the first domain controller and the second domain controller transmit data directly. Before the first domain controller generates the first communication protocol data segment and the second communication protocol data segment, the method further includes: When the first domain controller communicates with the second domain controller through the first communication mode, obtaining fault information of the first communication mode, where the fault information is used to indicate whether there is a fault in the first communication mode; If the fault information indicates that the first communication mode has a fault, the first domain controller communicates with the second domain controller through the second communication mode; The first communication protocol data segment and the second communication protocol data segment are communication protocol data segments generated under the second communication mode.

5. The method according to claim 4, characterized in that After the first domain controller encrypts the first freshness value and generates a first verification code associated with the first freshness value, the method further includes: When the communication mode between the first domain controller and the second domain controller is the first communication mode, the first domain controller generates a third communication protocol data segment including the target transmission data, the first freshness value and the first check code; The first domain controller transmits the third communication protocol data segment to the second domain controller; The second domain controller decrypts the third communication protocol data segment to obtain a third freshness value; The second domain controller verifies the third freshness value and the first freshness value in the third communication protocol data segment to determine whether to discard the target transmission data in the third communication protocol data segment.

6. The method according to claim 1, characterized in that The first domain controller obtains a first freshness value associated with target transmission data, including: The first domain controller obtains a count value of each target counter in the at least one target counter; The first domain controller determines a sum of count values ​​of the at least one target counter as the first fresh value.

7. The method according to claim 6, characterized in that The first domain controller is configured with multiple counters; Before the first domain controller obtains the first freshness value associated with the target transmission data, the method further includes: The first domain controller obtains a data volume of at least one historical transmission data transmitted by the first domain controller, where each historical transmission data is data transmitted by the first domain controller within a preset time period before a current moment; The first domain controller determines, based on the data volume of the at least one historical transmission data, a data volume distribution interval associated with the first domain controller, wherein the data volume of the at least one historical transmission data is within the data volume distribution interval; The first domain controller determines the at least one target counter from the multiple counters according to the data volume distribution interval, wherein the distribution interval of the sum of the count values ​​of the at least one target counter includes the data volume distribution interval.

8. A data transmission device between domain controllers, characterized in that: The device comprises: a freshness value acquisition module, configured to acquire, by a first domain controller, a first freshness value associated with target transmission data, where the first freshness value is determined by at least one target counter associated with the first domain controller; An encryption module, configured for the first domain controller to encrypt the first freshness value and generate a first check code associated with the first freshness value; a first data segment generating module, configured for the first domain controller to generate a first communication protocol data segment and a second communication protocol data segment, wherein the first communication protocol data segment includes the target transmission data and the first check code, and the second communication protocol data segment includes the first freshness value and the first check code; A first transmission module, configured for the first domain controller to transmit the first communication protocol data segment and the second communication protocol data segment to the second domain controller; a first decryption module, configured for the second domain controller to decrypt the first communication protocol data segment to obtain a second freshness value; The first verification module is used by the second domain controller to verify the second freshness value and the first freshness value in the second communication protocol data segment to determine whether to discard the target transmission data in the first communication protocol data segment.

9. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the data transmission method between domain controllers according to any one of claims 1 to 7.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the program instructions are executed by a processor, the steps of the method for data transmission between domain controllers described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Method and device for communication and secret key updating

    CN112449326A

  • Communication method and device based on in-vehicle network

    CN113132082A