Abnormal control instruction detection method and device, electronic equipment and storage medium

CN116760575BActive Publication Date: 2026-08-21CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310600237.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-25
Publication Date
2026-08-21
Estimated Expiration
2043-05-25

AI Technical Summary

Technical Problem

[0005]有鉴于此,本申请实施例提供了一种异常控制指令的检测方法、装置、电子设备及存储介质,以解决相关技术存在不能准确识别异常的控制指令,导致车辆产生安全风险的问题

Benefits of technology

[0017]This embodiment receives a remote control request sent by a client. The remote control request includes a first remote control command for the target vehicle and a first signature information corresponding to the first remote control command. It also receives encrypted data sent by the client. The encrypted data is obtained by encrypting a second remote control command and the second signature information corresponding to the second remote control command. The second remote control command is the command carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent. Based on the first signature information and the second remote control command and second signature information in the encrypted data, it detects whether the first remote control command is an abnormal control command. Since the second remote control command in the encrypted data is a remote control command... The instruction carried when the request is sent, and the second signature information, which is the signature information carried when the remote control request is sent, ensure the correctness of the instruction and signature information in the encrypted data. Therefore, it is possible to verify whether the first remote control instruction is an abnormal control instruction by using the second remote control instruction, the second signature information, and the first signature information. This enables the rapid and accurate identification of abnormal control instructions by performing data correlation analysis between the data in the remote control request and the collected encrypted data, thereby identifying remote control threats. In addition, this method does not rely on massive sample data, has higher applicability, and avoids the problems of inaccurate instruction identification such as missed detections and false alarms in related technologies' machine learning methods, thus improving vehicle safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116760575B_ABST
    Figure CN116760575B_ABST
Patent Text Reader

Abstract

The application relates to the field of connected cars, and provides an abnormal control instruction detection method and device, electronic equipment and a storage medium. The abnormal control instruction detection method comprises the following steps: receiving a remote control request sent by a client, wherein the remote control request comprises a first remote control instruction for a target vehicle and first signature information corresponding to the first remote control instruction; receiving encrypted data sent by the client, wherein the encrypted data is obtained by encrypting a second remote control instruction and second signature information corresponding to the second remote control instruction, and the second remote control instruction is an instruction carried by the remote control request when the remote control request is sent; and detecting whether the first remote control instruction is an abnormal control instruction based on the first signature information, the second remote control instruction and the second signature information. The embodiment of the application solves the problem that in the related art, an abnormal control instruction cannot be accurately identified, thereby causing a safety risk of a vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of connected vehicles, and in particular to a method, apparatus, electronic device, and storage medium for detecting abnormal control commands. Background Technology

[0002] With the continuous expansion of internet and intelligent technologies in the automotive field, connected cars have become widespread, and more and more cars are equipped with remote control functions. Users can send control commands from their mobile devices to operate the car, such as remotely starting the car or opening the windows. While remote control functions bring great convenience to users, they also bring potential security risks. For example, if a vehicle is remotely attacked and maliciously controlled, it will endanger the vehicle, roads, the environment, and even personal safety.

[0003] Currently, machine learning is commonly used to identify remote control threats. This method requires modeling and analyzing a large number of attack behavior samples to determine whether remote commands are threatening. However, the model performance is poor in this method, and there are often problems such as false negatives and missed detections.

[0004] Therefore, the relevant technologies have the problem of failing to accurately identify abnormal control commands, leading to safety risks to vehicles. Summary of the Invention

[0005] In view of this, embodiments of this application provide a method, apparatus, electronic device, and storage medium for detecting abnormal control commands, in order to solve the problem that related technologies cannot accurately identify abnormal control commands, leading to safety risks to vehicles.

[0006] A first aspect of this application provides a method for detecting abnormal control commands, comprising:

[0007] Receive a remote control request sent by a client, wherein the remote control request includes a first remote control command for the target vehicle and a first signature information corresponding to the first remote control command;

[0008] The system receives encrypted data sent by the client, wherein the encrypted data is obtained by encrypting a second remote control instruction and a second signature information corresponding to the second remote control instruction, the second remote control instruction being the instruction carried when the remote control request is sent, and the second signature information being the signature information carried when the remote control request is sent.

[0009] Based on the first signature information, the second remote control instruction, and the second signature information, detect whether the first remote control instruction is an abnormal control instruction.

[0010] A second aspect of this application provides an apparatus for detecting abnormal control commands, comprising:

[0011] The first receiving module is used to receive a remote control request sent by the client, wherein the remote control request includes a first remote control command for the target vehicle and a first signature information corresponding to the first remote control command;

[0012] The second receiving module is used to receive encrypted data sent by the client, wherein the encrypted data is obtained by encrypting the second remote control instruction and the second signature information corresponding to the second remote control instruction, the second remote control instruction is the instruction carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent.

[0013] The detection module is used to detect whether the first remote control instruction is an abnormal control instruction based on the first signature information, the second remote control instruction and the second signature information.

[0014] A third aspect of this application provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described in the first aspect.

[0015] A fourth aspect of this application provides a readable storage medium storing a computer program that, when executed by a processor, implements the steps of the method described in the first aspect.

[0016] The beneficial effects of the embodiments of this application are:

[0017] This embodiment receives a remote control request sent by a client. The remote control request includes a first remote control command for the target vehicle and a first signature information corresponding to the first remote control command. It also receives encrypted data sent by the client. The encrypted data is obtained by encrypting a second remote control command and the second signature information corresponding to the second remote control command. The second remote control command is the command carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent. Based on the first signature information and the second remote control command and second signature information in the encrypted data, it detects whether the first remote control command is an abnormal control command. Since the second remote control command in the encrypted data is a remote control command... The instruction carried when the request is sent, and the second signature information, which is the signature information carried when the remote control request is sent, ensure the correctness of the instruction and signature information in the encrypted data. Therefore, it is possible to verify whether the first remote control instruction is an abnormal control instruction by using the second remote control instruction, the second signature information, and the first signature information. This enables the rapid and accurate identification of abnormal control instructions by performing data correlation analysis between the data in the remote control request and the collected encrypted data, thereby identifying remote control threats. In addition, this method does not rely on massive sample data, has higher applicability, and avoids the problems of inaccurate instruction identification such as missed detections and false alarms in related technologies' machine learning methods, thus improving vehicle safety. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a flowchart illustrating an abnormal control command detection method provided in an embodiment of this application;

[0020] Figure 2 This is an example diagram of an abnormal control command detection method provided in an embodiment of this application;

[0021] Figure 3 This is a schematic diagram of the structure of an abnormal control command detection device provided in an embodiment of this application;

[0022] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0023] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application can also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0024] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0025] Furthermore, it should be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0026] The following will describe in detail, with reference to the accompanying drawings, a method and apparatus for detecting an abnormal control command according to an embodiment of this application.

[0027] Figure 1 This is a flowchart illustrating a method for detecting abnormal control instructions provided in an embodiment of this application. The execution entity of this detection method can be a processor or a server, and the server can be in the cloud. This embodiment uses a server as the execution entity for illustration. See also Figure 1 The method includes:

[0028] Step 101: Receive a remote control request sent by the client, wherein the remote control request includes a first remote control command for the target vehicle and a first signature information corresponding to the first remote control command.

[0029] Specifically, when a client needs to remotely control a target vehicle, such as to start the vehicle or turn on the air conditioning, the client can send a remote control request. The server then receives the remote control request, which includes a first remote control instruction for the target vehicle and a first signature information corresponding to the first remote control instruction.

[0030] The target vehicle is the vehicle that the client needs to control remotely.

[0031] The first remote control command may include information such as the client's identification information, the target vehicle's vehicle identification information, remote control instruction information, and timestamps.

[0032] The client's identification information can be information that uniquely identifies the client, such as username, pre-set unique feature code, etc.

[0033] Vehicle identification information can be information that uniquely identifies a target vehicle, such as license plate number, vehicle identification number, engine number, etc.

[0034] Remote control instruction information can be used to instruct the target vehicle on the functions it needs to perform. For example, the remote control instruction information may include instructions for controlling the start of the car or instructions for controlling the turn on of the car's air conditioning.

[0035] A timestamp is used to authenticate the time when a remote control instruction is generated. It indicates that a piece of data was existing, complete, and verifiable before a specific time. It is usually a sequence of characters that uniquely identifies a moment in time.

[0036] The first signature information is the digital signature corresponding to the first remote control information, and it is used to verify the authenticity and integrity of the first remote control information. The digital signature can be generated based on a hash algorithm. The generation process includes: applying a hash algorithm to the first remote control information to obtain a fixed-length message digest; then signing the message digest using the client's private key to form a digital signature, thereby obtaining the first signature information corresponding to the first remote control instruction.

[0037] The server receives a remote control request sent by the client. Since the remote control request may be subject to remote attacks during transmission between the client and the server, causing changes to the content of the remote control request, this embodiment needs to detect and verify the first remote control instruction and the first signature information in the remote control request to ensure that the first remote control instruction in the remote control request is indeed the remote control instruction issued by the client, thereby ensuring the safety of the target vehicle and reducing the security risks caused by abnormal remote control instructions.

[0038] Step 102: Receive encrypted data sent by the client, wherein the encrypted data is obtained by encrypting the second remote control instruction and the second signature information corresponding to the second remote control instruction, the second remote control instruction is the instruction carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent.

[0039] The second remote control instruction is the instruction carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent. In other words, the second remote control instruction is the remote control instruction entered by the user in the client, and the second signature information is the signature information generated by the client corresponding to this remote control instruction. The client encrypts the second remote control instruction and the second signature information to obtain encrypted data. This encrypted data allows the user-input remote control instruction and the client-generated signature information to be obtained, thus enabling the detection of any anomalies in the first remote control instruction within the remote control request using this encrypted data as a reference.

[0040] Furthermore, encryption refers to using cryptographic techniques to encrypt information, thereby achieving information concealment and protecting information security. In this embodiment, the client encrypts the second remote control command and the second signature information corresponding to the second remote control command to obtain encrypted data, ensuring the security of the encrypted data, and thus ensuring the security of the encrypted second remote control command and the second signature information.

[0041] After receiving the encrypted data, the client can send it to the server, which then receives the encrypted data. Due to the inherent high security of the encrypted data, it is not easily tampered with during transmission, ensuring its accuracy. This allows the encrypted data to serve as reference data for detecting any anomalies in the first control command.

[0042] Step 103: Based on the first signature information, the second remote control instruction, and the second signature information, detect whether the first remote control instruction is an abnormal control instruction.

[0043] After receiving the encrypted data sent by the client, the server can decrypt the encrypted data to obtain the second remote control command and the second signature information. Based on the first signature information and the decrypted second remote control command and the second signature information, the server can detect whether the first remote control command is an abnormal control command.

[0044] An abnormal control command refers to a command that poses a security threat; in this embodiment, it refers to a control command that is different from the second remote control command.

[0045] Since the encrypted data ensures the correctness of the second remote control command and the second signature information, and the second remote control command is the command carried when the remote control request is sent, the second remote control command and the second signature information can be used as a reference, combined with the first signature information, to detect whether the first remote control command is abnormal. This achieves data correlation analysis between the data in the remote control request and the collected encrypted data, enabling rapid and accurate identification of abnormal control commands, thereby identifying remote control threats. In addition, this embodiment does not rely on massive sample data, has higher applicability, avoids the problem of inaccurate command identification such as missed detections and false alarms in related technologies' machine learning methods, and improves vehicle safety.

[0046] Furthermore, specifically, since the first signature information can be used to verify the integrity of the signed information, this application can perform initial verification of the first remote control command through the first signature information, as detailed in the following embodiments.

[0047] Specifically, in some embodiments, after receiving the remote control request sent by the client, the method further includes:

[0048] If the verification of the first signature information fails, the first remote control instruction is determined to be an abnormal control instruction; if the verification of the first signature information is successful, the first remote control instruction and the first signature information are stored in the first storage space of the server.

[0049] Specifically, when the server verifies the first signature information, it can first use the client's public key to decrypt the first signature information to obtain the message digest of the first remote control instruction; then, it can use the hash function used during signing to perform hash calculation on the first remote control instruction to obtain a new message digest; finally, it can determine whether the new message digest obtained is the same as the decrypted message digest. If they are the same, the verification is successful; if they are different, the verification fails.

[0050] The first storage space is the storage space in the server, which is a database used to store the first remote control command and the first signature information. The first remote control command and the first signature information stored in this database can be retrieved when needed, as one of the basic information for detecting abnormal control commands.

[0051] After receiving a remote control request from a client, the server can parse the request to obtain a first remote control instruction and a first signature. Then, it performs digital signature verification on the first signature. The result of this verification serves as the basis for determining whether the remote control instruction is abnormal. If the verification fails, the first remote control instruction is considered abnormal. If the verification succeeds, it can be preliminarily assumed that the first remote control instruction has not been tampered with. However, to ensure the security of the first remote control instruction, both the first remote control instruction and the first signature can be stored in the server's primary storage space for further verification to determine if the instruction is abnormal.

[0052] Furthermore, in some embodiments, when the server receives a remote control request sent by the client, it may receive the remote control request sent by the client through a first encrypted network.

[0053] Specifically, the first encrypted network transmission can be a Hypertext Transfer Protocol Secure (HTTPS) two-way authentication encrypted network or an HTTPS one-way authentication encrypted network. HTTPS is a transmission protocol for secure communication over computer networks. It communicates via Hypertext Transfer Protocol (HTTP) and uses Secure Sockets Layer (SSL) / Transport Layer Security (TLS) to establish a secure channel and encrypt data packets. HTTPS can protect the security and integrity of exchanged data.

[0054] In this embodiment, the server receives a remote control request sent by the client using the first encrypted network, which enhances the security of the remote control request transmission process, increases the cost of malicious attacks and spoofed data, and thus enhances the security of the remote control request.

[0055] In some embodiments, the encrypted data is obtained by encrypting intermediate data using a first encryption method, and the intermediate data is obtained by encrypting the second remote control command and the second signature information using a second encryption method.

[0056] Specifically, the second encryption method can include symmetric encryption and asymmetric encryption. Symmetric encryption methods can include Advanced Encryption Standard (AES) encryption algorithms, Triple Data Encryption Algorithm (3DES), etc. AES supports three key lengths: 128 bits, 192 bits, and 256 bits. For example, AES256 has a key length of 256 bits, supporting the maximum bit size. Asymmetric encryption methods include Digital Signature Algorithm (DSA), Elliptic Curve Cryptography (ECC), etc. For example, in this embodiment, the second encryption method can be AES256, that is, using AES256 to encrypt the second remote control command and the second signature information to generate non-plaintext intermediate data.

[0057] The first encryption method may include multi-layer encryption, asymmetric encryption, symmetric encryption, Message-Digest Algorithm 5 (MD5), etc. This embodiment does not specifically limit the specific encryption method of the first encryption method.

[0058] In this embodiment, intermediate data is obtained by encrypting the second remote control command and the second signature information using a second encryption method, and then the intermediate data is encrypted using a first encryption method to obtain double-protected encrypted data. This ensures that even if one encryption method is compromised, the other encryption method can still protect the second remote control command and the second signature information, reducing the possibility of the encrypted data being threatened and ensuring the security of the encrypted data.

[0059] In some embodiments, receiving encrypted data sent by a client may include:

[0060] Receive encrypted data sent by the client through a second encrypted network according to a preset private protocol;

[0061] Correspondingly, after the server receives the encrypted data sent by the client, it may also include:

[0062] The private protocol is parsed to obtain encrypted data; the encrypted data is decrypted using the first decryption method corresponding to the first encryption method to obtain intermediate data; the intermediate data is decrypted using the second decryption method corresponding to the second encryption method to obtain the second remote control command and the second signature information, and the second remote control command and the second signature information are stored in the second storage space of the server.

[0063] Specifically, a proprietary protocol refers to a protocol whose format is not publicly disclosed, such as a protocol standard developed internally by a company and used only within the company.

[0064] The second encrypted network can be an HTTPS two-way authentication encrypted network or an HTTPS one-way authentication encrypted network.

[0065] The client can send encrypted data to the server via a second encrypted network according to a preset private protocol. The server then receives the encrypted data and parses the private protocol to obtain the transmitted encrypted data.

[0066] Since the encrypted data is obtained by encrypting it using the first encryption method and the second encryption method, the server can decrypt the encrypted data using the first decryption method corresponding to the first encryption method to obtain intermediate data, and then decrypt the intermediate data using the second decryption method corresponding to the second encryption method to obtain the second remote control command and the second signature information.

[0067] The second storage space is the storage space within the server. It can be a database used to store the decrypted second remote control commands and the second signature information. The second remote control commands and the second signature information stored in this database can be retrieved when needed and used as one of the reference information for detecting abnormal control commands.

[0068] In this embodiment, the server receives encrypted data sent by the client through a second encrypted network according to a preset private protocol. The server uses the private protocol to transmit the encrypted data, which means that the encrypted data can only be parsed through the private protocol, thus improving the security of the data encryption. In addition, the use of the second encrypted network for transmission further ensures the security of the encrypted data.

[0069] Furthermore, in some embodiments, when detecting whether the first remote control instruction is an abnormal control instruction based on the first signature information, the second remote control instruction, and the second signature information, the following steps may be included:

[0070] Construct a first data table, which includes a first remote control instruction and a first signature information, wherein the first remote control instruction and the first signature information belong to different columns;

[0071] Construct a second data table, which includes a second remote control command and a second signature information, with the second remote control command and the second signature information belonging to different columns;

[0072] The first data table and the second data table are left-joined. If the first signature information does not match the second signature information, the first remote control instruction is determined to be an abnormal control instruction.

[0073] Specifically, the first data table and the second data table can be temporary tables, used to temporarily store remote control commands and signature information, respectively.

[0074] A left join is based on the left table and connects the two tables according to the related fields. The result will retain all records in the left table and the records in the right table that meet the join conditions. Records in the right table that do not meet the join conditions will be set to null.

[0075] In this embodiment, the first data table can be used as the left table, and the first signature information and the second signature information can be used as the association field to connect the first data table and the second data table. If the first signature information and the second signature information do not match, the row containing the second signature information in the second data table will be set to empty. At this time, it can be determined that the first remote control instruction is an abnormal control instruction.

[0076] It should be noted that in this embodiment, the first data table and the second data table can also be right-joined, that is, the second data table is used as the right table, the first signature information and the second signature information are used as the association fields, and the first data table and the second data table are joined according to the association fields. At this time, if the first signature information and the second signature information do not match, the first signature information will no longer be displayed in the first data table. At this time, it can be determined that the first remote control command is an abnormal control command.

[0077] According to the technical solution provided in the embodiments of this application, a first data table and a second data table are left-joined, that is, the first remote control command, the first signature information, the second remote control command, and the second signature information in the data tables are compared and analyzed. If the content of the first data table in the third data table generated by the left join of the first and second data tables matches the content of the second data table, it indicates that the first remote control command is a normal control command. If the content of the first data table in the third data table generated by the left join of the first and second data tables does not match the content of the second data table, it indicates that the first remote control command is an abnormal control command. This detection method does not rely on massive external samples for model analysis and can quickly and accurately detect abnormal remote control commands, reducing the possibility of missed or false alarms for abnormal control commands, thereby improving the safety of connected vehicles.

[0078] In some embodiments, after determining that the first remote control command is an abnormal control command, the method further includes:

[0079] Send alert messages to the client; these alert messages are used to warn of the safety of the target vehicle.

[0080] Specifically, the warning message can be a text message, an audio message, etc. For example, the warning message can be "The target vehicle is currently under abnormal control" or "The target vehicle has received an abnormal control command". Of course, this embodiment does not limit the type and number of warning messages.

[0081] In this embodiment, after confirming that the first remote control command is an abnormal control command, it indicates that there is a safety hazard to the target vehicle. At this time, a warning message is sent to the client associated with the target vehicle to alert the client that the target vehicle has received an abnormal control command, so that corresponding protective measures can be taken to prevent the target vehicle from being controlled by the abnormal control command, thereby improving the safety of the target vehicle.

[0082] The following reference Figure 2 Here, we will specifically describe one embodiment of this application.

[0083] First, when the client receives a remote control command input by the user, it can generate signature information corresponding to that command and then generate a remote control request. The remote control request carries the user-input remote control command and its corresponding signature information. The remote control command may include the client's identification information, the target vehicle's vehicle identification information, remote control instructions, a timestamp, and other information.

[0084] The client can then send the remote control request to the server via the first encrypted network. The server receives the remote control request transmitted by the client through the first encrypted network, and the received request includes a first remote control instruction and first signature information. Because the remote control request may be vulnerable to remote attacks during transmission, the first remote control instruction and first signature information carried in the request may not necessarily be the user-input remote control instruction and the client-generated signature information. It should be noted that a session module can be set up in the client to generate and send the remote control request to the server.

[0085] Next, the server verifies the first signature information. If the verification fails, it indicates that the first remote control instruction is an abnormal control instruction. If the verification succeeds, the first remote control instruction and the first signature information are saved in the server's first storage space.

[0086] Furthermore, after sending a remote control request, the client can use a second encryption method to encrypt the second remote control command and the second signature information corresponding to the second remote control command to obtain intermediate data. The second remote control command is the remote control command input by the user. As an example, the second encryption method can be AES256. The client can then further encrypt the intermediate data using the first encryption method to obtain encrypted data, and transmit the encrypted data to the server according to a private protocol via a second encrypted network. It should also be noted that the client can be equipped with an encryption module and a data acquisition module. The encryption module encrypts the intermediate data, and the acquisition module further encrypts the intermediate data to obtain encrypted data before transmitting it to the server.

[0087] Then, after receiving the encrypted data transmitted by the client using a preset private protocol and a second encrypted network, the server parses the private protocol to obtain the encrypted data, and decrypts the encrypted data using a first decryption method corresponding to the first encryption method to obtain intermediate data. The intermediate data is then decrypted using a second decryption method corresponding to the second encryption method to obtain the second remote control command and the second signature information. The second remote control command and the second signature information are then stored in the server's second storage space.

[0088] Next, the server retrieves the first remote control instruction and the first signature information from the first storage space and constructs a first data table; the server retrieves the second remote control instruction and the second signature information from the second storage space and constructs a second data table; the server performs a left join between the first data table and the second data table to generate a third data table, and filters the columns in the third data table that fail to associate, that is, filters the first signature information that does not match the second signature information. At this time, the first remote control instruction corresponding to the column that fails to associate can be identified as an abnormal control instruction.

[0089] Finally, in response to this abnormal control command, an alert message can be sent to the client. The alert message is used to warn the target vehicle about its safety, so that both the client and the target vehicle can activate the corresponding protection measures.

[0090] All the above-mentioned optional technical solutions can be combined in any way to form the optional embodiments of this application, and will not be described in detail again.

[0091] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the process of the embodiments of this application.

[0092] The following are embodiments of the apparatus described in this application, which can be used to execute the embodiments of the method described in this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the method described in this application.

[0093] Figure 3 This application provides an embodiment of an abnormal control command detection device, which includes:

[0094] The first receiving module 301 is used to receive a remote control request sent by a client, wherein the remote control request includes a first remote control instruction for the target vehicle and a first signature information corresponding to the first remote control instruction.

[0095] The second receiving module 302 is used to receive encrypted data sent by the client, wherein the encrypted data is obtained by encrypting the second remote control instruction and the second signature information corresponding to the second remote control instruction, the second remote control instruction is the instruction carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent.

[0096] The detection module 303 is used to detect whether the first remote control instruction is an abnormal control instruction based on the first signature information, the second remote control instruction and the second signature information.

[0097] According to the technical solution provided in the embodiments of this application, a first receiving module 301 receives a remote control request sent by a client. The remote control request includes a first remote control command for the target vehicle and first signature information corresponding to the first remote control command. A second receiving module 302 receives encrypted data sent by the client. The encrypted data is obtained by encrypting the second remote control command and the second signature information corresponding to the second remote control command. The second remote control command is the command carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent. A detection module 303 detects whether the first remote control command is an abnormal control based on the first signature information and the second remote control command and the second signature information in the encrypted data. The method employs a unique approach. Since the second remote control command in the encrypted data is the command carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent, the correctness of the encrypted data is guaranteed. Therefore, the first remote control command can be verified as an abnormal control command by using the second remote control command, the second signature information, and the first signature information. This enables rapid and accurate identification of abnormal control commands and thus the detection of remote control threats through data correlation analysis between the data in the remote control request and the collected encrypted data. Furthermore, this method does not rely on massive sample data, making it more practical and avoiding the problems of inaccurate command identification, such as false positives and false negatives, that exist in machine learning methods in related technologies, thereby improving vehicle safety.

[0098] In some embodiments, the first receiving module 301 is further configured to: determine the first remote control instruction as an abnormal control instruction if the verification of the first signature information fails; and save the first remote control instruction and the first signature information in the first storage space of the server if the verification of the first signature information is successful.

[0099] In some embodiments, the first receiving module 301 is specifically used to receive a remote control request sent by the client through the first encrypted network.

[0100] In some embodiments, the encrypted data is obtained by encrypting intermediate data using a first encryption method, and the intermediate data is obtained by encrypting the second remote control command and the second signature information using a second encryption method.

[0101] In some embodiments, the second receiving module 302 is specifically used to: receive encrypted data sent by the client through the second encrypted network according to a preset private protocol; parse the private protocol to obtain encrypted data; decrypt the encrypted data using a first decryption method corresponding to the first encryption method to obtain intermediate data; decrypt the intermediate data using a second decryption method corresponding to the second encryption method to obtain a second remote control instruction and a second signature information, and store the second remote control instruction and the second signature information in the second storage space of the server.

[0102] In some embodiments, the detection module 303 is specifically configured to: construct a first data table, the first data table including a first remote control instruction and a first signature information, wherein the first remote control instruction and the first signature information belong to different columns; construct a second data table, the second data table including a second remote control instruction and a second signature information, wherein the second remote control instruction and the second signature information belong to different columns; perform a left join between the first data table and the second data table; if the first signature information does not match the second signature information, then determine that the first remote control instruction is an abnormal control instruction.

[0103] In some embodiments, the detection module 303 is further configured to send a warning message to the client, the warning message being used to provide an early warning regarding the safety of the target vehicle.

[0104] The abnormal control command detection device provided in this application embodiment can realize all the processes and beneficial effects implemented in the above method embodiments, and will not be repeated here to avoid repetition.

[0105] Figure 4 This is a schematic diagram of the electronic device 4 provided in an embodiment of this application. Figure 4As shown, the electronic device 4 of this embodiment includes: a processor 401, a memory 402, and a computer program 403 stored in the memory 402 and executable on the processor 401. When the processor 401 executes the computer program 403, it implements the steps in the various method embodiments described above. Alternatively, when the processor 401 executes the computer program 403, it implements the functions of each module / unit in the various device embodiments described above.

[0106] Electronic device 4 can be a desktop computer, laptop, handheld computer, cloud server, or other electronic device. Electronic device 4 may include, but is not limited to, processor 401 and memory 402. Those skilled in the art will understand that... Figure 4 This is merely an example of electronic device 4 and does not constitute a limitation on electronic device 4. It may include more or fewer components than shown, or different components.

[0107] The processor 401 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0108] The memory 402 can be an internal storage unit of the electronic device 4, such as a hard disk or RAM of the electronic device 4. The memory 402 can also be an external storage device of the electronic device 4, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc., equipped on the electronic device 4. The memory 402 can also include both internal and external storage units of the electronic device 4. The memory 402 is used to store computer programs and other programs and data required by the electronic device.

[0109] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0110] If an integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program may include computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. A readable storage medium may include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in a readable storage medium can be appropriately added or removed according to the requirements of legislation and patent practice in a jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.

[0111] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for detecting abnormal control commands, characterized in that, include: Receive a remote control request sent by a client through a first encrypted network, wherein the remote control request includes a first remote control command for the target vehicle and a first signature information corresponding to the first remote control command; The system receives encrypted data sent by the client through a second encrypted network according to a preset private protocol. The encrypted data is obtained by encrypting intermediate data using a first encryption method. The intermediate data is obtained by encrypting a second remote control instruction and the second signature information corresponding to the second remote control instruction using a second encryption method. The second remote control instruction is the instruction carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent. The private protocol is parsed to obtain the encrypted data, and the encrypted data is decrypted using a first decryption method corresponding to the first encryption method to obtain the intermediate data. The intermediate data is then decrypted using a second decryption method corresponding to the second encryption method to obtain the second remote control command and the second signature information. Based on the first signature information, the second remote control instruction, and the second signature information, detect whether the first remote control instruction is an abnormal control instruction.

2. The method for detecting abnormal control commands according to claim 1, characterized in that, After receiving the remote control request sent by the client, the method further includes: If the verification of the first signature information fails, the first remote control instruction is determined to be the abnormal control instruction; If the first signature information is successfully verified, the first remote control command and the first signature information are saved in the first storage space of the server.

3. The method for detecting abnormal control commands according to claim 1, characterized in that, The remote control request sent by the receiving client includes: Receive the remote control request sent by the client through the first encrypted network.

4. The method for detecting abnormal control commands according to claim 1, characterized in that, After decrypting the intermediate data using the second decryption method corresponding to the second encryption method to obtain the second remote control command and the second signature information, the method further includes: The second remote control command and the second signature information are stored in the second storage space of the server.

5. The method for detecting abnormal control commands according to claim 1, characterized in that, The step of detecting whether the first remote control instruction is an abnormal control instruction based on the first signature information, the second remote control instruction, and the second signature information includes: Construct a first data table, which includes the first remote control instruction and the first signature information, and the first remote control instruction and the first signature information belong to different columns; Construct a second data table, which includes the second remote control instruction and the second signature information, and the second remote control instruction and the second signature information belong to different columns; The first data table and the second data table are left-joined. If the first signature information does not match the second signature information, the first remote control instruction is determined to be the abnormal control instruction.

6. The method for detecting abnormal control commands according to claim 2 or 5, characterized in that, After determining that the first remote control command is the abnormal control command, the method further includes: A warning message is sent to the client, which is used to provide a safety warning for the target vehicle.

7. A detection device for abnormal control commands, characterized in that, include: The first receiving module is configured to receive a remote control request sent by a client through a first encrypted network, wherein the remote control request includes a first remote control instruction for the target vehicle and a first signature information corresponding to the first remote control instruction. The second receiving module is used to receive encrypted data sent by the client through a second encrypted network according to a preset private protocol. The encrypted data is obtained by encrypting intermediate data using a first encryption method. The intermediate data is obtained by encrypting a second remote control instruction and the second signature information corresponding to the second remote control instruction using a second encryption method. The second remote control instruction is the instruction carried when the remote control request is sent, and the second signature information is the signature information carried when the remote control request is sent. The private protocol is parsed to obtain the encrypted data, and the encrypted data is decrypted using a first decryption method corresponding to the first encryption method to obtain the intermediate data. The intermediate data is then decrypted using a second decryption method corresponding to the second encryption method to obtain the second remote control command and the second signature information. The detection module is used to detect whether the first remote control instruction is an abnormal control instruction based on the first signature information, the second remote control instruction and the second signature information.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 6.

9. A readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method, system and device for remotely controlling vehicle

    CN109819049A

  • Mutual authentication security system with detection and mitigation of active man-in-the-middle browser attacks, phishing, and malware and other security improvements.

    US20170346851A1