Data communication protection method and device
By using hardware information to bind to IP addresses and port numbers in automotive networks to verify the legality and monitoring encrypted data transmission in real time, the problem of SOME/IP protocol being vulnerable to man-in-the-middle attacks is solved, and the reliability and security of data communication are improved.
Patent Information
- Application Number
- CN202410751258.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-12
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-06-12
AI Technical Summary
The SOME/IP protocol is vulnerable to man-in-the-middle attacks in automotive networks, affecting the security of the entire vehicle network and data transmission security.
By establishing an encrypted data communication channel between the server and the client, verifying the legitimacy using the binding relationship between hardware information and IP address and port number, monitoring the running process in real time, and encrypting data transmission is carried out after confirming that there are no exceptions.
It improves the reliability of data communication and attack prevention capabilities, and ensures the security of the entire vehicle's network security and data transmission security.
Smart Images

Figure CN118631525B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of new energy vehicles, and particularly to a data communication protection method and device. Background Art
[0002] With the continuous increase in the demand for data communication in the automotive industry, SOME / IP (Scalable service-Oriented MiddlewarE over IP), as a communication protocol supporting automotive Ethernet processes and inter-device communication, has emerged. SOME / IP features lightweight, high efficiency, and being dominated by the needs of the receiving party, and can provide procedure calls and event notifications, and is gradually used by various automotive devices. However, precisely due to its wide use and importance, the SOME / IP protocol has also become a potential target for attacks.
[0003] The most common type of attack on the SOME / IP protocol is the man-in-the-middle attack. A man-in-the-middle attack refers to an attack type where the attacker performs data eavesdropping and tampering without the victim parties (such as the server and the client) discovering the attacker's identity. In an Ethernet environment, the attacker can achieve the effect of a man-in-the-middle attack by connecting to the same switch as the victim parties simultaneously.
[0004] During the SOME / IP communication process inside the vehicle or between the vehicle and the cloud, if the attacker maliciously attacks SOME / IP, it will seriously affect the overall vehicle network security, thereby affecting the data transmission security and even the vehicle safety. Therefore, there is an urgent need to provide a data communication protection method with high reliability and strong anti-attack ability to ensure the overall vehicle network security, improve the data transmission security, and guarantee the vehicle safety. Summary of the Invention
[0005] In view of this, the embodiments of this application provide a data communication protection method and device with high reliability and strong anti-attack ability to ensure the overall vehicle network security, improve the data transmission security, and guarantee the vehicle safety.
[0006] In the first aspect of the embodiments of this application, a data communication protection method is provided, including:
[0007] The first server:
[0008] Send a service publication message to the target client, where the service publication message includes service identification information, the first encrypted sending IP address and the first encrypted sending port number of the first server, and there is a binding relationship between the hardware information of the first server and the first encrypted sending IP address and the first encrypted sending port number;
[0009] After receiving a service subscription message corresponding to the service identification information sent by the target client and confirming that the service subscription message is legal information, establish a first data communication channel with the target client and create a first service process; wherein, the service subscription message includes the encrypted receiving IP address and encrypted receiving port number of the target client, and there is a binding relationship between the hardware information of the target client and the encrypted receiving IP address and encrypted receiving port number;
[0010] Start the pre-set first security monitoring process to perform real-time monitoring on the currently running processes, obtain the first monitoring result, and send the first monitoring result to the second security monitoring process of the second server; wherein, the currently running processes include the first service process;
[0011] Receive the second monitoring result obtained by the second server through the second security monitoring process for real-time monitoring of the currently running processes;
[0012] If it is determined that there is no abnormality in the currently running processes based on the first monitoring result and the second monitoring result, then transmit an encrypted data packet to the target client through the first data communication channel.
[0013] In the second aspect of the embodiments of the present application, a data communication protection device is provided, including:
[0014] A message sending module, configured to send a service publishing message to the target client, the service publishing message includes service identification information, the first encrypted sending IP address and the first encrypted sending port number of the first server, wherein, there is a binding relationship between the hardware information of the first server and the first encrypted sending IP address and the first encrypted sending port number;
[0015] A channel establishing module, configured to establish a first data communication channel with the target client and create a first service process after receiving a service subscription message corresponding to the service identification information sent by the target client and confirming that the service subscription message is legal information; wherein, the service subscription message includes the encrypted receiving IP address and encrypted receiving port number of the target client, and there is a binding relationship between the hardware information of the target client and the encrypted receiving IP address and encrypted receiving port number;
[0016] A process monitoring module, configured to start the pre-set first security monitoring process to perform real-time monitoring on the currently running processes, obtain the first monitoring result, and send the first monitoring result to the second security monitoring process of the second server; wherein, the currently running processes include the first service process;
[0017] A result receiving module, configured to receive the second monitoring result obtained by the second server through the second security monitoring process for real-time monitoring of the currently running processes;
[0018] A data transmission module, configured to transmit an encrypted data packet to a target client through a first data communication channel if it is determined based on a first monitoring result and a second monitoring result that the currently running process is normal.
[0019] In a third aspect of the embodiments of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.
[0020] In a fourth aspect of the embodiments of the present application, a readable storage medium is provided. The readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0021] Compared with the prior art, the beneficial effects of the embodiments of the present application at least include:
[0022] In the first aspect, during the process of establishing a first data communication channel between the first server and the target client, the first encrypted sending IP address and the first encrypted sending port number in the service publication message sent by the first server to the target client have a binding relationship with the hardware information of the first server; thus, after receiving the service publication message, the target client can verify whether the first server is a legal communication node based on this binding relationship. If it is determined that the first server is a legal communication node and it needs to subscribe to the service corresponding to the service identification information, then it can send a service subscription message corresponding to the service identification information to the first server; the first server establishes a first data communication channel with the target client only after receiving the service subscription message corresponding to the service identification information sent by the target client and confirming that the service subscription message is a legal message. In this way, it can be ensured that a data communication connection is established between the first server and the target client only when both the first server and the target client are legal communication nodes, thereby effectively preventing the first server and the target client from being exploited by attackers and impersonating the first server or the target client for service publication or subscription due to the leakage of the IP address and / or port number during the process of establishing the first data communication channel, thus improving the reliability and security of data communication between the first server and the target client, and at the same time improving the anti-attack ability of the data communication process.
[0023] In a second aspect, after establishing a first data communication channel between the first server and the target client and before data transmission, the first server starts a first security monitoring process preset in the first server to perform real-time monitoring on the currently running processes, obtaining a first monitoring result. At the same time, the second server also performs real-time monitoring on the currently running processes and feeds back a second monitoring result to the first server. After the first server confirms that the currently running processes are normal based on the first monitoring result and the second monitoring result, it then transmits an encrypted data packet to the target client through the first data communication channel. In this way, the reliability and anti-attack ability of the data communication process can be improved, the vehicle network security can be guaranteed, the data transmission security can be enhanced, and the vehicle safety can be ensured.
[0024] In summary, in the embodiments of the present application, corresponding data communication security protection measures are taken in each link of data communication transmission between the first server and the target client. For example, in the stage of establishing a data communication connection, the data communication connection between each other is established only when it is confirmed that both the first server and the target client are legitimate communication nodes; before transmitting data to the target client, the first security monitoring process of the first server and the second security monitoring process of the second server are started to perform security monitoring on the currently running processes, and data transmission is carried out only after it is confirmed that the currently running processes are normal; in the data transmission stage, encrypted transmission is performed, so as to comprehensively improve the reliability and anti-attack ability of the data communication process in all aspects, ensure the vehicle network security, enhance the data transmission security, and ensure the vehicle safety. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0026] Figure 1 is a schematic diagram of an application scenario of an embodiment of the present application;
[0027] Figure 2 is a schematic diagram of the interaction process between a server and a client based on the SOA architecture provided by an embodiment of the present application;
[0028] Figure 3 is a network topology relationship diagram of in-vehicle components designed based on the SOA architecture provided by an embodiment of the present application;
[0029] Figure 4 is a schematic diagram of the service publishing and subscribing process between a first server, an attacker, and a target client in the prior art;
[0030] Figure 5 It is a schematic diagram of another service publishing and subscribing process between the first server, the attacker, and the target client in the prior art;
[0031] Figure 6 It is a schematic flowchart of a data communication protection method provided by an embodiment of the present application;
[0032] Figure 7 It is a schematic diagram of an Ethernet packet structure provided by an embodiment of the present application;
[0033] Figure 8 It is a schematic flowchart of a process for the second server to transparently transmit data to the target client provided by an embodiment of the present application;
[0034] Figure 9 It is a schematic diagram of a data communication protection device provided by an embodiment of the present application;
[0035] Figure 10 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0036] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0037] A data communication protection method and device according to an embodiment of the present application will be described in detail below with reference to the accompanying drawings.
[0038] Figure 1It is a schematic diagram of an application scenario of an embodiment of the present application. This application scenario may include a server 10 and a vehicle terminal 20; among them, the server 10 may be a cloud server or a background server, etc. The server 10 may include a first cloud platform 101 and a second cloud platform 102; the vehicle terminal 20 includes, but is not limited to, the following in-vehicle components: a first server 201, a second server 202, a vehicle controller 203 (Vehicle Domain Controller, abbreviated as "VDC"), and N vehicle gateways 204 (or called vehicle integration gateways, Vehicle Integration Unit, abbreviated as "VIU"), where N is an integer greater than or equal to 2. Each of the first server 201, the vehicle controller 203, and each vehicle gateway 204 is connected to at least one electronic control unit (ECU). The vehicle network topology structure formed by the above-mentioned in-vehicle components is a ring network architecture designed based on the SOA concept. SOA is an idea and a design method that abstracts the capabilities of a system into callable services with standard interfaces, so that the business requirements of the system can be met by calling services or combinations of multiple services. The carrier of SOA is a design of a communication mechanism, often implemented using SOME / IP. The SOME / IP protocol is a service-oriented communication middleware that provides a standard service interface for the client / server communication mechanism of in-vehicle Ethernet.
[0039] Please refer to Figure 2 , SOME / IP (Scalable service-Oriented MiddlewarE over IP) refers to an IP-based scalable service-oriented middleware, which is a service-oriented in-vehicle Ethernet communication protocol. It is located above the transport layer TCP / UDP and is compatible with the basic software development platform jointly discussed internationally. The SOME / IP protocol adopts a C / S (Client / Server) communication architecture, where the Server is the service provider and the Client is the service consumer. According to the service interface type, a remote service call (Remote Procedure Call) mechanism is used, and data is transmitted over the network through data serialization and deserialization (Serialization / Deserialization). The dynamic configuration of services is achieved through an available service discovery SD (Service Discovery) mechanism.
[0040] In the SOA architecture, nodes on the network open their resources to other participants on the network in the form of independent services, and other participants use the resources in a standard way. Different from the traditional point-to-point architecture, the SOA architecture consists of loosely coupled and highly interoperable application services (or called atomic services).
[0041] Figure 3 This is a network topology relationship diagram of in-vehicle components designed based on the SOA architecture provided by an embodiment of the present application. As Figure 3 shown, in this network topology relationship of in-vehicle components, for each in-vehicle component involved in OTA upgrade, the OTA upgrade master controller (UMC), the OTA upgrade agent (UA), and the OTA upgrade slave controller (US) can all include an atomic service layer, a device abstraction layer, middleware, an operating system, and a hardware layer. Among them, the hardware layers between the UMC, UA, and US are connected through Ethernet.
[0042] The first cloud platform 101 can be connected to the second server 202 through a 4G / 5G network or WiFi; the second cloud platform 102 can be connected to the first server 201 through a 4G / 5G network or WiFi; the first server 201 and the second server 202 can be connected through a 100M / 1000M Ethernet. The first server 201 can be connected to the vehicle controller 203 and N vehicle gateways 204 through a 100M / 1000M Ethernet; the second server 202 can be connected to the vehicle controller 203 through a 100M / 1000M Ethernet; the N vehicle gateways 204 can be connected to each other through a 100M / 1000M Ethernet; the first server 201, the vehicle controller 203, and each vehicle gateway 204 can be connected to their subordinate electronic control units (ECUs) through Ethernet or a CAN bus.
[0043] The first server 201 can be the intelligent cockpit of the vehicle end 20 (or called the cockpit domain controller, abbreviated as "CDC"); the second server 202 can be the vehicle remote communication module of the vehicle end 20 (abbreviated as "VBOX").
[0044] As an example, please refer to Figure 1 , in the OTA upgrade, the OTA upgrade master controller (hereinafter referred to as "UMC") is deployed in the first server 201, the vehicle controller 203, and the N vehicle gateways 204. For example, assume N = 4, including vehicle gateway 1 (VIU1), vehicle gateway 2 (VIU2), vehicle gateway 3 (VIU3), and vehicle gateway 4 (VIU4). UMC0 is deployed in the first server 201; UMC1, UMC2, UMC3, and UMC4 are respectively deployed in vehicle gateway 1, vehicle gateway 2, vehicle gateway 3, and vehicle gateway 4; UMC5 is deployed in the vehicle controller 203. The OTA upgrade slave controller (hereinafter referred to as "US") is deployed in the electronic control units under the first server 201, the vehicle controller 203, and each vehicle gateway 204.
[0045] The vehicle network topology structure formed among the above-mentioned first server 201, second server 202, vehicle controller 203, and N vehicle gateways 204 is a ring network architecture designed based on the SOA concept. Please refer to Figure 1 In this vehicle network topology structure, the first server 201 and the second server 202 are connected to form an open-loop network structure. The first server 201 is connected to at least two vehicle gateways 204 to form a first ring network structure. For example, the first server 201 is connected to vehicle gateway 3 and vehicle gateway 4 to form a first ring network structure: The N vehicle gateways 204 are connected to form a second ring network structure. Exemplarily, assuming N = 4, vehicle gateway 1, vehicle gateway 2, vehicle gateway 3, and vehicle gateway 4 are connected to form a second ring network structure, such as:
[0046] The target client in the embodiments of the present application can be at least one of the vehicle controller 203, vehicle gateway 204, or electronic control unit. Exemplarily, the target client can be the vehicle controller (VDC) 203, or at least one ECU connected under the vehicle controller (VDC) 203.
[0047] It should be noted that the specific types, quantities, and combinations of the cloud platform in the server 10 and each in-vehicle component (including the first server, second server, vehicle controller, vehicle gateway, and electronic control unit) of the vehicle end 20 can be adjusted according to the actual requirements of the application scenario, and the embodiments of the present application do not limit this.
[0048] The vehicle network topology structure (which is an electronic and electrical architecture) in the embodiments of the present application is a network topology structure designed based on the SOA concept. This vehicle network topology structure is a ring network architecture that supports SOA serviceization and communication channel protection. Among them, VBOX and CDC are nodes that directly interact with the outside world for information and data, and their security is directly related to the safety of the entire vehicle system.
[0049] The most common attack type of the SOME / IP protocol is the man-in-the-middle attack. The man-in-the-middle attack is an attack type in which the attacker eavesdrops on and tampers with data without the victim parties discovering the attacker's identity. In an Ethernet environment, the effect of a man-in-the-middle attack can be achieved by connecting to the same switch as the victim parties at the same time. For SOME / IP communication, there are the following 3 different man-in-the-middle attack methods: (1) data tampering attack in service communication; (2) disconnection attack on the service provider; (3) attack on service subscription and service publication.
[0050] Figure 4 It is a schematic diagram of the service publication and subscription process between the first server, the attacker, and the target client in the prior art.
[0051] Please refer to Figure 1 and Figure 4 If the server 10 has a software version update for the VDC (target client), the software version update is stored in the first cloud platform 101 and / or the second cloud platform 102 of the server 10. The server 10 can send a software version update notification to the first server 201 (such as CDC) of the vehicle terminal 20. The software version update notification includes information such as the identification information (such as ID) and software version number of the VDC. After receiving the software version update notification, the CDC broadcasts a message that the VDC has a software version update to the vehicle network topology of the vehicle terminal 20. At this time, the VDC (target client) receives the software version update message sent by the CDC (first server), such as: providing a software upgrade version upgrade service for the VDC: 0x0201, the first sending IP address of the first server: 192.168.0.100, and the first sending port number: 30501. If the VDC determines that it needs to be upgraded after receiving the software version update message, it can send a subscription event group (service) 0x0201 to the first server (CDC) and send its own receiving IP address 192.168.0.1 and receiving port number 30510 to the first server (CDC). After receiving the subscription event group (service), the first server (CDC) replies with a message response, that is, a subscription event group (service) confirmation response. Subsequently, the VDC and the CDC establish a TCP or UDP connection for data communication based on the carried first sending IP address, first sending port number, receiving IP address, and receiving port number. After establishing the data communication, the CDC transfers the VDC upgrade package obtained from the second cloud platform 102 of the server 10 to the VDC for upgrading. If an attacker (such as a hacker) takes advantage of a vulnerability in the CDC at this time, implants a malicious program in the CDC, and impersonates an illegal client, it will also receive the software version update message broadcast by the first server CDC and establish a connection with the first server CDC; after establishing a connection with the first server, the attacker impersonates the target client VDC and initiates an unsubscribe event group (service) to the first server CDC. At this time, the data communication transmission between the VDC and the CDC is interrupted. At the same time, the attacker impersonates the first server CDC and initiates an upgrade service push to the VDC, such as: providing a software upgrade version upgrade service for the VDC: 0x0201, the attacker's IP address: 192.168.0.10, and the port number: 30555, and establishes a connection with the target client VDC for data communication. At this time, the VDC is illegally held by the attacker and illegally controlled, seriously affecting the vehicle network security.
[0052] Figure 5 It is a schematic diagram of another service publishing and subscribing process among the first server, the attacker, and the target client in the prior art.
[0053] Please refer to Figure 1 and Figure 5 , the service publishing and subscribing service steps of the first server CDC and the target client VDC are substantially the same as those of the first server and the target client shown in Figure 4 . The main difference between the two lies in the different attack methods adopted by the attacker. As shown in Figure 5 , after the attacker establishes a connection with the first server CDC, the attacker obtains the first sending IP address 192.168.0.100 and the first sending port number 30501 of the CDC. At this time, if the attacker kills or suspends the legitimate current service process between the first server CDC and the target client VDC, and starts the illegal process of the attacker, and impersonates the first sending IP address and the first sending port number of the first server CDC to communicate with the VDC, the VDC is illegally hijacked by the attacker for illegal control. This method is more concealed and has greater destructive power.
[0054] It can be seen that during the in-vehicle or vehicle-cloud SOME / IP communication process, if the attacker launches a malicious attack on SOME / IP, it will seriously affect the vehicle network security, thereby affecting the data transmission security and even the vehicle security. Therefore, there is an urgent need to provide a data communication protection method with high reliability and strong anti-attack ability to ensure the vehicle network security, improve the data transmission security and guarantee the vehicle security.
[0055] Figure 6 is a schematic flowchart of a data communication protection method provided by an embodiment of the present application. Figure 6 The data communication protection method can be executed by the first server 201 of Figure 1 . As shown in Figure 6 , the data communication protection method may specifically include the following steps:
[0056] Step S601, send a service publishing message to the target client, where the service publishing message includes service identification information, the first encrypted sending IP address and the first encrypted sending port number of the first server, and there is a binding relationship between the hardware information of the first server and the first encrypted sending IP address and the first encrypted sending port number.
[0057] The target client, also known as the data receiving end, may be at least one of the vehicle controller 203, the vehicle gateway 204 or the electronic control unit in Figure 1 .
[0058] The service identification information usually refers to the service ID, and different service IDs represent different services. For example, the service ID for the software upgrade version upgrade of the VDC is 0x0201.
[0059] The hardware information of the first server may be its ID information.
[0060] Step S602, after receiving a service subscription message corresponding to the service identification information sent by the target client and confirming that the service subscription message is legal information, establish a first data communication channel with the target client and create a first service process; wherein, the service subscription message includes the encrypted receiving IP address and encrypted receiving port number of the target client, and there is a binding relationship between the hardware information of the target client and the encrypted receiving IP address and encrypted receiving port number.
[0061] The hardware information of the target client can be its ID information.
[0062] When the first server (such as CDC) receives a service subscription message corresponding to the service identification information (such as 0x0201) sent by the target client (such as VDC), parse the service subscription message, decrypt the encrypted receiving IP address and encrypted receiving port number to obtain the decrypted receiving IP address and decrypted receiving port number, and then query the preset "hardware information - IP address - port number" corresponding relationship table to confirm whether there are corresponding receiving IP address, receiving port number and hardware information in the corresponding relationship table for the decrypted receiving IP address and decrypted receiving port number. If it exists, determine that the service subscription message is legal information. If it does not exist, determine that the service subscription message is illegal information.
[0063] As an example, the preset "hardware information - IP address - port number" corresponding relationship table is shown in Table 1. This corresponding relationship table can be stored in the secure storage area of the first server.
[0064] Table 1 Corresponding relationship table of "hardware information - IP address - port number"
[0065]
[0066]
[0067] Among them, ECU0-1 to ECU0-m in Table 1 represent the ECU components connected to the first server CDC; ECU1-1 to ECUm-m represent the ECU components connected to the vehicle gateway and vehicle controller.
[0068] After the first server confirms that the service subscription message sent by the target client is legal information, based on its own first sending IP address and first sending port number, establish a first data communication channel with the target client using the decrypted receiving IP address and decrypted receiving port number, and at the same time create (start) the first service process.
[0069] As an example, the range of port numbers of all in-vehicle components (including the first server, the second server, the vehicle controller, N vehicle gateways (N is an integer greater than or equal to 2), and each electronic control unit connected under the first server, the vehicle controller, and each vehicle gateway) in the vehicle network topology of the vehicle end 20 can be configured as [30501 to 305FF], and a port number is assigned to each in-vehicle component. For each in-vehicle component, its IP address is bound to the assigned port number, that is, a mapping relationship (corresponding relationship) between the two is established to form a service connection information table (the corresponding relationship table of "hardware information - IP address - port number" as shown in Table 1), and then the service connection information table is distributed to each in-vehicle component, and each in-vehicle component receives the service connection information table and stores it in its respective secure storage area.
[0070] After receiving the service publication message sent by the first server, the target client first decrypts the first encrypted sending IP address and the first encrypted sending port number to obtain the first decrypted sending IP address and the first decrypted sending port number. Then, it queries the service connection information table to confirm whether the first decrypted sending IP address and the first decrypted sending port number are legal IP addresses or legal port numbers. If they are illegal IP addresses or illegal port numbers, the service publication message is not responded to.
[0071] Similarly, after receiving the service subscription message sent by the target client, the first server can use the above implementation method to determine whether the service subscription message is legal information. If it is illegal information, the service subscription message is not responded to.
[0072] In this way, it can be ensured that when there is an illegal IP address or illegal port number on either the first server or the target client, a data communication connection cannot be established between them, thereby effectively preventing an attacker from implementing a man-in-the-middle attack, and further improving the reliability and anti-attack ability of the data communication process, ensuring the vehicle network security, improving the data transmission security, and ensuring the vehicle safety.
[0073] Step S603, start the preset first security monitoring process to monitor the currently running processes in real time, obtain the first monitoring result, and send the first monitoring result to the second security monitoring process of the second server; where the currently running processes include the first service process.
[0074] The first service process refers to the data communication transmission process between the first server and the target client.
[0075] The first security monitoring process can be pre-stored in the secure storage area of the first server. When the first server creates the first service process between it and the target client, the first security monitoring process is started to perform real-time monitoring and scanning on all currently running processes of the vehicle terminal 20, obtain the running status of the currently running processes, that is, obtain the first monitoring result, and send the first monitoring result to the second security monitoring process of the second server.
[0076] Step S604, receive the second monitoring result obtained by the second security monitoring process of the second server through real-time monitoring of the currently running processes.
[0077] The second security monitoring process can be pre-stored in the secure storage area of the second server (such as VBOX). When the second server detects that the first server starts the first security monitoring process, the second security monitoring process is started to perform real-time monitoring and scanning on all currently running processes of the vehicle terminal 20, obtain the running status of the currently running processes, that is, obtain the second monitoring result, and send the second monitoring result to the first security monitoring process of the first server.
[0078] Step S605, if it is determined that the currently running processes are normal based on the first monitoring result and the second monitoring result, transmit the encrypted data packet to the target client through the first data communication channel.
[0079] Figure 7 It is a schematic diagram of an Ethernet packet structure provided by an embodiment of the present application. Please refer to Figure 7 , the Ethernet packet includes an Ethernet header (EthHead), an IP header (IpHead), a TCP / UDP header (TCP / UDP Head), and a data field. The data field includes a SOMEIP header and a SOMEIP data field.
[0080] The SOMEIP header includes a server ID field, a data length field, a client ID field, a version number, an interface version, a message type, and a response code. The server ID field is used to represent different services, and different services correspond to different service IDs. The client ID field is used to represent the identification ID of the target upgrade component. Exemplarily, the identification ID of VBOX can be configured as 0; the identification ID of VDC can be configured as 1; the identification ID of ADC can be configured as 2; the identification ID of CDC can be configured as 3; the identification ID of VIU1 can be configured as 4; the identification ID of VIU2 can be configured as 5; the identification ID of VIU3 can be configured as 6; the identification ID of VIU4 can be configured as 7; the identification IDs of other ECUs supporting ETH can be configured as 8 to ffff. The message type is used to represent the message response situation. For example, 0 indicates that a response is required, and 1 indicates no response.
[0081] The SOMEIP data field includes a configuration information field and a message data area. The configuration information field includes a communication protocol flag field, a partition flag field, a cloud backup channel configuration field, a vehicle-side channel configuration field, a vehicle-side primary channel line field, and a vehicle-side protection channel line field. The communication protocol flag field is used to represent the communication protocol flag supported by the target client. The partition flag field is used to represent the A / B partition flag supported by the target client, where the A partition can represent the running partition and the B partition can represent the backup partition. The cloud backup channel configuration field is used to represent whether a cloud backup channel is configured. For example, 0 indicates that the cloud backup channel is not configured, and 1 indicates that the cloud backup channel is configured. The vehicle-side protection channel configuration field is used to represent whether a vehicle-side protection channel is configured. For example, 0 indicates that the vehicle-side protection channel is not configured, 1 indicates that the vehicle-side protection channel is manually configured, and 2 indicates that the vehicle-side protection channel is automatically configured. The vehicle-side primary channel line field is used to represent the vehicle-side primary channel line. The vehicle-side protection channel line field is used to represent the vehicle-side protection channel line.
[0082] The first server can encapsulate and encrypt the data (such as an upgrade data packet) to be sent to the target client according to the above Ethernet message structure to obtain an encrypted data packet, and then transmit the encrypted data packet to the target client through the first data communication channel.
[0083] In some embodiments, since all the ECUs supporting the Ethernet communication protocol in the vehicle are in the same network segment, the SOME / IP message can be directly carried on the Ethernet layer 2 (i.e., the Ethernet link layer) for communication transmission. In this way, the encapsulation and decapsulation of TCP and IP can be bypassed, thereby reducing the time-consuming of frequent message encapsulation and decapsulation, reducing the overhead of message assembly and decapsulation, and at the same time increasing the data payload and the data transmission volume, thus improving the data transmission efficiency.
[0084] The technical solution provided by the embodiments of the present application adopts corresponding data communication security protection measures in each link of data communication transmission between the first server and the target client. For example, in the stage of establishing a data communication connection, a data communication connection is established between the first server and the target client only when it is confirmed that both the first server and the target client are legal communication nodes; before transmitting data to the target client, start the first security monitoring process of the first server and the second security monitoring process of the second server to perform security monitoring on the currently running processes, and then perform data transmission after confirming that the currently running processes are normal; perform encrypted transmission in the data transmission stage, so as to comprehensively and comprehensively improve the reliability and anti-attack ability of the data communication process, ensure the vehicle network security, improve the data transmission security and ensure the vehicle safety.
[0085] In some embodiments, after the first server creates the first service process, it further includes:
[0086] Obtain the first process identifier of the first service process and the server identifier corresponding to the first server;
[0087] Based on the first process identifier and the server identifier, calculate the second process identifier corresponding to the first service process;
[0088] Expose the second process identifier and hide the first process identifier.
[0089] The first process identifier is the real service ID of the first service process.
[0090] As an example, the first server (such as CDC) can obtain the first process identifier (process ID) of the first service process, the server identifier (CDC ID) corresponding to the first server, and the chip identifier (CHIPID), then use the CRC32 algorithm to calculate the process ID + CDC ID + CHIPID to obtain the calculation result, and then use a preset encryption algorithm (such as the AES-256 encryption algorithm, etc.) to perform an encryption calculation on the calculation result to obtain the second process identifier. The second process identifier is the virtual service ID of the first service process. The first server exposes the second process ID of the first service process at the vehicle end 20 and hides its first process ID.
[0091] In this way, the real service ID of the first service process can be hidden, effectively preventing attackers from performing malicious operations on the first service process (such as forcibly exiting or forcibly suspending the first service process, etc.), thereby improving the data transmission reliability and anti-attack ability between the first server and the target client, ensuring the vehicle network security, improving the data transmission security, and guaranteeing the vehicle safety.
[0092] In some embodiments, the above method may further include the following steps:
[0093] If it is determined based on the first monitoring result and the second monitoring result that there is an illegal running process in the current running processes, and the first service process is forcibly exited or forcibly suspended, then kill and clear the illegal running process, and restart the first service process;
[0094] If the restart of the first service process is successful, continue to transmit the encrypted data packet to the target client through the first data communication channel.
[0095] The current running processes include the first service process and other service processes.
[0096] An illegal running process refers to a running process corresponding to an illegal IP address or an illegal port number. For example, a running process corresponding to the IP address of a (suspicious) attacker (such as 192.168.0.10).
[0097] After receiving the second monitoring result sent by the second server, the first server can first compare whether the first monitoring result is consistent with the second monitoring result. If the first monitoring result is consistent with the second monitoring result, it is further determined whether the current running process in the first monitoring result or the second monitoring result contains an illegal running process (such as a running process with an illegal IP address or an illegal port number), and whether the first service process has been forcibly exited or forcibly suspended. If the current running process contains an illegal running process and the first service process has been forcibly exited or forcibly suspended, the first security monitoring process is used to kill and clear the illegal running process, and the first service process is restarted. If the first service process is successfully restarted and runs again, the encrypted data packet is continuously transmitted to the target client through the first data communication channel. If the first monitoring result is inconsistent with the second monitoring result, the second monitoring result is used as the standard, and it is detected whether the current running process in the second monitoring result contains an illegal running process, and whether the first service process has been forcibly exited or forcibly suspended.
[0098] By simultaneously performing security monitoring on the vehicle network of the vehicle end through the first security monitoring process of the first server and the second security monitoring process of the second server, scanning the running status of the current running process, and combining the first monitoring result and the second monitoring result, it is possible to more accurately determine whether there is an illegal running process in the current running process and whether the first service process has been forcibly exited or forcibly suspended. When it is determined that there is an illegal running process and the first service process has been forcibly exited or forcibly suspended, the first security monitoring process is used to kill and clear the illegal running process in a timely manner, which can effectively block the attack of the attacker; then the first service process is restarted through the first security monitoring process, and normal data communication transmission can be quickly restored.
[0099] In some embodiments, if the restart of the first service process fails, the transmission of the encrypted data packet to the target client through the first data communication channel is aborted, and an alarm message is broadcast across the network; a data transmission takeover request is sent to the second server, and the data transmission takeover request includes the encrypted data packet;
[0100] Second server: In response to the data transmission takeover request, the encrypted data packet is transparently transmitted to the data link layer of the target client through the data link layer of the first server.
[0101] If the first server fails to restart the first service process through the first security monitoring process, the transmission of the encrypted data packet to the target client through the first data communication channel is aborted, and an alarm message (such as relevant information about the attacker, such as the attacker's IP address and port number, etc.) is broadcast across the network. Then, the first server (such as CDC) sends a data transmission takeover request to the second server (such as VBOX), and the data transmission takeover request includes the encrypted data packet (such as the encrypted upgrade data packet of the target client VDC). Please refer toFigure 8 The second server responds to the data transmission takeover request and transparently transmits the encrypted data packet to the data link layer (MAC layer) of the target client (target ECU) through the data link layer (MAC layer) of the first server.
[0102] When the first security monitoring process of the first server fails to restart the first service process, the second server takes over the first server to execute the transmission task of the encrypted data packet, which can ensure the transmission efficiency of the encrypted data packet (such as the encrypted upgrade data packet); in addition, the second server transparently transmits the encrypted data packet to the target client through the data link layer of the first server, which can not only improve the data transmission efficiency, ensure the normal upgrade of the VDC, but also increase the difficulty for attackers to discover and attack the second server, thus ensuring the vehicle network security, improving the data transmission security and ensuring the vehicle safety.
[0103] In some embodiments, during normal communication, if the first server suddenly receives an unsubscribe event (service) sent by the target client, but it is confirmed through the first monitoring result of the first security monitoring process and the second monitoring result of the second security monitoring process that the current running process is normal, the unsubscribe event (service) is not responded to avoid being attacked by attackers.
[0104] In some embodiments, the first server transmits an encrypted data packet to the target client through the first data communication channel, including:
[0105] Based on the vehicle network topology, determine the primary transmission channel and the backup transmission channel for transmitting the encrypted data packet to the target client; wherein, the vehicle network topology includes a first server, a second server, a vehicle controller, and N vehicle gateways, N is an integer greater than or equal to 2; the first server, the vehicle controller, and each vehicle gateway are each connected to at least one electronic control unit; the target client is at least one of the vehicle controller, the vehicle gateway, or the electronic control unit; the first server and the second server are connected to form an open-loop network structure, the first server is connected to at least two vehicle gateways to form a first ring network structure, and the N vehicle gateways are connected to form a second ring network structure;
[0106] Use the primary transmission channel as the first data communication channel to transmit the encrypted data packet to the target client.
[0107] In some embodiments, based on the vehicle network topology, determining the primary transmission channel and the backup transmission channel for transmitting the encrypted data packet to the target client includes:
[0108] Search for M reachable transmission paths in the vehicle network topology with the first server as the path start point and the target client as the path end point;
[0109] When M = 1, the reachable transmission path is determined as the primary transmission channel;
[0110] When M ≥ 2, search for the shortest transmission path from the first server to the target client, and determine the shortest transmission path as the primary transmission channel, and the remaining M - 1 reachable transmission paths are all determined as backup transmission channels.
[0111] Please refer to Figure 1 , as an example, assume that the first server is CDC, the second server is VBOX, and the target client is VDC. Then the first server CDC can search for all reachable transmission paths with CDC as the path start point and VDC as the path end point based on the vehicle network topology structure as shown in Figure 1 . Among them, some search results are as follows: Reachable communication transmission path ①: CDC → VBOX → VDC; Reachable communication transmission path ②: CDC → VIU4 → VIU1 → VDC; Reachable communication transmission path ③: CDC → VIU4 → VIU1 → VIU2 → VDC; Reachable communication transmission path ④: CDC → VIU3 → VIU2 → VDC; Reachable communication transmission path ⑤: CDC → VIU3 → VIU2 → VIU1 → VDC. Among the above reachable transmission paths ① - ⑤, the shortest transmission path from CDC to VDC is reachable communication transmission path ①. Then, reachable communication transmission path ① can be determined as the primary transmission channel, and the remaining 4 reachable transmission paths ② - ⑤ are determined as backup transmission channels.
[0112] Please refer to Figure 1 , as another example, assume that the first server is CDC, the second server is VBOX, and the target client is ECU0 - 1 connected under CDC. Then the reachable transmission path with CDC as the path start point and ECU0 - 1 as the path end point is only CDC → ECU0 - 1. At this time, M = 1. This reachable transmission path CDC → ECU0 - 1 is determined as the primary transmission channel.
[0113] In some embodiments, if there are at least two shortest transmission paths (the number of path nodes is the same) in the reachable transmission paths from the first server to the target client, then the data transmission time of each shortest transmission path can be further calculated, and then the one with the shortest data transmission time is used as the primary transmission channel, and the remaining shortest transmission paths are all determined as backup transmission channels.
[0114] By determining the shortest transmission path as the primary transmission channel and using the primary transmission channel as the first data communication channel to transmit encrypted data packets to the target client, the data transmission efficiency can be improved. In addition, by configuring backup transmission channels, when problems such as failures occur in the primary transmission channel, the normal transmission of data can be guaranteed.
[0115] In some embodiments, using the primary transmission channel as the first data communication channel to transmit encrypted data packets to the target client includes:
[0116] Determine the transmission security level of the encrypted data packet;
[0117] If the transmission security level is the first security level, use the primary transmission channel as the first data communication channel to transmit the encrypted data packet to the target client;
[0118] If the transmission security level is the second security level, use the primary transmission channel and at least one backup transmission channel as the first data communication channel to transmit the encrypted data packet to the target client in parallel; wherein, the importance level of the first security level is lower than that of the second security level.
[0119] The transmission security level is related to the importance level of the encrypted data packet. Generally, the higher the importance level, the higher the transmission security level; conversely, the lower the importance level, the lower the transmission security level. Generally, the transmission security level of encrypted data packets related to the safety of the vehicle is relatively high. For example, the transmission security levels of encrypted data packets related to the vehicle power domain, chassis domain, cockpit domain, etc. are relatively high; the transmission security levels of encrypted data packets related to the vehicle body domain, in-vehicle entertainment information system, etc. are relatively low.
[0120] If the transmission security level of the encrypted data packet is the first security level, that is, the importance level is relatively low. At this time, only the primary transmission channel can be used as the first data communication channel to transmit the encrypted data packet to the target client. In this way, data transmission resources can be saved.
[0121] If the transmission security level of the encrypted data packet is the second security level, that is, the importance level is relatively high. At this time, the primary transmission channel and at least one backup transmission channel can be used as the first data communication channel to transmit the encrypted data packet to the target client in parallel. In this way, the reliability of data transmission can be improved.
[0122] In some embodiments, using the primary transmission channel and at least one backup transmission channel as the first data communication channel to transmit the encrypted data packet to the target client in parallel includes:
[0123] The first server:
[0124] Transmit the first encrypted data packet to the target client through the primary transmission channel and transmit the second encrypted data packet to the target client through the backup transmission channel; wherein, the first encrypted data packet is the same as the second encrypted data packet;
[0125] The target client:
[0126] Receive the first encrypted data packet transmitted from the primary transmission channel and the second encrypted data packet transmitted from the backup transmission channel, decrypt the first encrypted data packet and the second encrypted data packet respectively to obtain the first decrypted data packet and the second decrypted data packet, and compare whether the first decrypted data packet and the second decrypted data packet are consistent;
[0127] If they are consistent, check whether the effective data length of the first decrypted data packet or the second decrypted data packet is consistent with the preset standard data length;
[0128] If they are inconsistent, record the number of abnormal data reception times and feedback the data reception abnormal message to the first server, where the data reception abnormal message includes the number of abnormal data reception times;
[0129] The first server:
[0130] If the number of abnormal data reception times exceeds the preset number threshold, broadcast the alarm information across the network and abort transmitting the first encrypted data packet through the primary transmission channel and the second encrypted data packet through the backup transmission channel.
[0131] As an example, assume that the first server is CDC, the target client is VDC, the primary transmission channel is the reachable communication transmission path ①: CDC→VBOX→VDC, and the backup transmission channel is the reachable communication transmission path ②: CDC→VIU4→VIU1→VDC. The first server CDC can transmit the first encrypted data packet to the target client VDC through the reachable communication transmission path ①; and transmit the second encrypted data packet to the target client VDC through the reachable communication transmission path ② at the same time. After the target client VDC receives the first encrypted data packet transmitted from the reachable communication transmission path ① and the second encrypted data packet transmitted from the reachable communication transmission path ②, it can first decrypt the first encrypted data packet and the second encrypted data packet to obtain the first decrypted data packet and the second decrypted data packet; and then compare whether the first decrypted data packet and the second decrypted data packet are consistent.
[0132] If the first decrypted data packet and the second decrypted data packet are consistent, check whether the effective data length (i.e., the actual payload data length) of the first decrypted data packet or the second decrypted data packet is consistent with the preset standard data length (i.e., the configured payload data). Among them, the preset standard data length can be flexibly set according to the actual situation, and its data length range can be selected from 1 to 1484 bytes.
[0133] If the valid data length of the first decrypted data packet or the second decrypted data packet is inconsistent with the preset standard data length, record the data reception anomaly count i, and feedback a data reception anomaly message to the first server. After receiving the data reception anomaly message, if the first server determines that i < the preset count threshold (which can be flexibly set according to actual situations), it will retransmit the first encrypted data packet and the second encrypted data packet to the target client VDC.
[0134] After the target client receives the first encrypted data packet and the second encrypted data packet retransmitted by the first server, repeat the above steps. If it is determined that the valid data length of the first decrypted data packet or the second decrypted data packet is inconsistent with the preset standard data length, record the data reception anomaly count i (i = i + 1), and feedback a data reception anomaly message to the first server.
[0135] After the first server receives the data reception anomaly message, if it determines that i ≥ the preset count threshold, at this time, the first server may be under attack, then broadcast an alarm message across the network, and abort transmitting the first encrypted data packet through the primary transmission channel and the second encrypted data packet through the backup transmission channel.
[0136] In this way, the reliability and security of data transmission can be improved, and at the same time, the anti-attack performance of data communication can be enhanced.
[0137] All of the above optional technical solutions can be combined arbitrarily to form optional embodiments of the present application, which will not be elaborated one by one here.
[0138] The following is an embodiment of the device of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the device embodiment of the present application, please refer to the method embodiment of the present application.
[0139] Figure 9 is a schematic diagram of a data communication protection device provided by an embodiment of the present application. As Figure 9 shown, the data communication protection device includes:
[0140] A message sending module 901, configured to send a service publishing message to a target client. The service publishing message includes service identification information, the first encrypted sending IP address and the first encrypted sending port number of the first server. Among them, the first encrypted sending IP address and the first encrypted sending port number have a binding relationship;
[0141] The channel establishment module 902 is configured to establish a first data communication channel with the target client and create a first service process after receiving a service subscription message corresponding to the service identification information sent by the target client and confirming that the service subscription message is legal information; wherein, the service subscription message includes the encrypted receiving IP address and the encrypted receiving port number of the target client, and the encrypted receiving IP address and the encrypted receiving port number have a binding relationship;
[0142] The process monitoring module 903 is configured to start a preset first security monitoring process to monitor the currently running processes, obtain a first monitoring result, and send the first monitoring result to the second security monitoring process of the second server; wherein, the currently running processes include the first service process;
[0143] The result receiving module 904 is configured to receive a second monitoring result obtained by the second server through the second security monitoring process for monitoring the currently running processes;
[0144] The first data transmission module 905 is configured to transmit an encrypted data packet to the target client through the first data communication channel if it is determined based on the first monitoring result and the second monitoring result that the currently running processes are normal.
[0145] In some embodiments, the above-mentioned channel establishment module 902 may also be configured to:
[0146] Obtain the first process identifier of the first service process and the server identifier corresponding to the first server; calculate a second process identifier corresponding to the first service process based on the first process identifier and the server identifier; expose the second process identifier and hide the first process identifier.
[0147] In some embodiments, the above-mentioned data communication protection device further includes:
[0148] The process restart module is configured to kill and clear an illegally running process and restart the first service process if it is determined based on the first monitoring result and the second monitoring result that there is an illegally running process in the currently running processes and the first service process is forcibly exited or forcibly suspended;
[0149] The second data transmission module is configured to continue to transmit an encrypted data packet to the target client through the first data communication channel if the restart of the first service process is successful.
[0150] In some embodiments, the above-mentioned data communication protection device further includes:
[0151] The transmission abort module is configured to abort the transmission of the encrypted data packet to the target client through the first data communication channel and broadcast an alarm message across the network if the restart of the first service process fails;
[0152] A request sending module, configured to send a data transmission takeover request to a second server, where the data transmission takeover request includes an encrypted data packet;
[0153] The second server includes:
[0154] A request response module, configured to respond to the data transmission takeover request and transparently transmit the encrypted data packet to the data link layer of the target client through the data link layer of the first server.
[0155] In some embodiments, the above-mentioned first data transmission module 905 includes a data transmission unit, and the data transmission unit is configured to: transmit the encrypted data packet to the target client through a first data communication channel.
[0156] The data transmission unit may specifically be configured to: determine a primary transmission channel and a backup transmission channel for transmitting the encrypted data packet to the target client based on the vehicle network topology; where the vehicle network topology includes a first server, a second server, a vehicle controller, and N vehicle gateways, and N is an integer greater than or equal to 2; the first server, the vehicle controller, and each vehicle gateway are each connected to at least one electronic control unit; the target client is at least one of the vehicle controller, the vehicle gateway, or the electronic control unit; the first server and the second server are connected to form an open-loop network structure, the first server is connected to at least two vehicle gateways to form a first ring network structure, and the N vehicle gateways are connected to form a second ring network structure; use the primary transmission channel as the first data communication channel to transmit the encrypted data packet to the target client.
[0157] In some embodiments, determining a primary transmission channel and a backup transmission channel for transmitting the encrypted data packet to the target client based on the vehicle network topology includes:
[0158] Search for M reachable transmission paths in the vehicle network topology with the first server as the path starting point and the target client as the path ending point; when M = 1, determine the reachable transmission path as the primary transmission channel; when M ≥ 2, find the shortest transmission path from the first server to the target client and determine the shortest transmission path as the primary transmission channel, and the remaining M - 1 reachable transmission paths are all determined as backup transmission channels.
[0159] In some embodiments, using the primary transmission channel as the first data communication channel to transmit the encrypted data packet to the target client includes:
[0160] Determine the transmission security level of the encrypted data packet; if the transmission security level is the first security level, use the primary transmission channel as the first data communication channel to transmit the encrypted data packet to the target client; if the transmission security level is the second security level, use the primary transmission channel and at least one backup transmission channel as the first data communication channel to transmit the encrypted data packet to the target client in parallel; wherein, the importance level of the first security level is lower than that of the second security level.
[0161] In some embodiments, using the primary transmission channel and at least one backup transmission channel as the first data communication channel to transmit the encrypted data packet to the target client in parallel includes:
[0162] The first server: Transmit the first encrypted data packet to the target client through the primary transmission channel and transmit the second encrypted data packet to the target client through the backup transmission channel; wherein, the first encrypted data packet is the same as the second encrypted data packet.
[0163] The target client: Receive the first encrypted data packet transmitted from the primary transmission channel and the second encrypted data packet transmitted from the backup transmission channel, decrypt the first encrypted data packet and the second encrypted data packet respectively to obtain the first decrypted data packet and the second decrypted data packet, and compare whether the first decrypted data packet and the second decrypted data packet are consistent; if they are consistent, check whether the effective data length of the first decrypted data packet or the second decrypted data packet is consistent with the preset standard data length; if they are inconsistent, record the number of data reception anomalies and feedback a data reception anomaly message to the first server, and the data reception anomaly message includes the number of data reception anomalies.
[0164] The first server: If the number of data reception anomalies exceeds the preset number threshold, broadcast an alarm message across the network and abort transmitting the first encrypted data packet through the primary transmission channel and transmitting the second encrypted data packet through the backup transmission channel.
[0165] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution is prior or subsequent, and the order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0166] In summary, the data communication protection method provided by the embodiments of the present application binds the hardware information of in-vehicle components to their IP addresses and port numbers, and only legal communication nodes can perform data communication, which can effectively prevent the addition of malicious nodes (attackers) and improve network security. By encrypting and hiding the first process identifier of the first service process, when the first service process has an abnormal suspension or is killed, the first service process is restarted and an alarm is issued to ensure process security. It can prevent attackers from impersonating subscribers (target clients) and service providers (the first server), support encrypted data transmission, prevent information tampering and data theft, and ensure data security.
[0167] Figure 10 is a schematic diagram of the electronic device 100 provided by the embodiments of the present application. As Figure 10 shown, the electronic device 100 of this embodiment includes: a processor 1001, a memory 1002, and a computer program 1003 stored in the memory 1002 and executable on the processor 1001. When the processor 1001 executes the computer program 1003, the steps in the above method embodiments are implemented. Alternatively, when the processor 1001 executes the computer program 1003, the functions of the various modules / units in the above device embodiments are implemented.
[0168] The electronic device 100 may be a desktop computer, a notebook, a palm computer, a cloud server, or other electronic devices. The electronic device 100 may include, but is not limited to, the processor 1001 and the memory 1002. Those skilled in the art can understand that Figure 10 merely examples of the electronic device 100, which do not constitute a limitation on the electronic device 100, may include more or fewer components than shown in the figure, or different components.
[0169] The processor 1001 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0170] The memory 1002 may be an internal storage unit of the electronic device 100. For example, it can be the hard disk or memory of the electronic device 100. The memory 1002 can also be an external storage device of the electronic device 100. For example, it can be a plug-in hard disk equipped on the electronic device 100, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. The memory 1002 can also include both the internal storage unit and the external storage device of the electronic device 100. The memory 1002 is used to store computer programs and other programs and data required by the electronic device.
[0171] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above-mentioned division of each functional unit and module is used as an example. In practical applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0172] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium (such as a computer-readable storage medium). Based on this understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above method embodiments. The computer program can include computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable storage medium can include: any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0173] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included within the protection scope of the present application.
Claims
1. A data communication protection method, which is applied to the in-vehicle or vehicle-cloud SOME / IP communication process, and is characterized in that Including: The first server: Sends a service publication message to the target client. The service publication message includes service identification information, the first encrypted sending IP address and the first encrypted sending port number of the first server. Among them, there is a binding relationship between the hardware information of the first server and the first encrypted sending IP address and the first encrypted sending port number; After receiving the service subscription message corresponding to the service identification information sent by the target client and confirming that the service subscription message is legal information, establish a first data communication channel with the target client and create a first service process; among them, the service subscription message includes the encrypted receiving IP address and the encrypted receiving port number of the target client, and there is a binding relationship between the hardware information of the target client and the encrypted receiving IP address and the encrypted receiving port number; Start the preset first security monitoring process to perform real-time monitoring on the currently running processes, obtain the first monitoring result, and send the first monitoring result to the second security monitoring process of the second server; among them, the currently running processes include the first service process; Receive the second monitoring result obtained by the second server through the second security monitoring process for real-time monitoring of the currently running processes; If the first monitoring result and the second monitoring result are consistent, determine whether there is an abnormality in the currently running processes based on the first monitoring result or the second monitoring result. If the first monitoring result and the second monitoring result are inconsistent, determine whether there is an abnormality in the currently running processes based on the second monitoring result; If it is determined that there is no abnormality in the currently running processes, encapsulate and encrypt the data to be sent to the target client according to the Ethernet packet structure to obtain an encrypted data packet, and transmit the encrypted data packet to the target client through the first data communication channel; Among them, the first server is the intelligent cockpit of the vehicle end, and the second server is the vehicle's whole vehicle remote communication module.
2. The method according to claim 1, characterized in that, After creating the first service process, it further includes: Obtain the first process identifier of the first service process and the service server identifier corresponding to the first server; Based on the first process identifier and the service server identifier, calculate the second process identifier corresponding to the first service process; Expose the second process identifier and hide the first process identifier.
3. The method according to claim 1, characterized in that, The method further includes: If it is determined that there is an illegal running process in the currently running processes based on the first monitoring result and the second monitoring result, and the first service process is forcibly exited or forcibly suspended, then kill and clear the illegal running process and restart the first service process; If the restart of the first service process is successful, continue to transmit the encrypted data packet to the target client through the first data communication channel.
4. The method according to claim 3, wherein The method further includes: If the restart of the first service process fails, abort the transmission of the encrypted data packet to the target client through the first data communication channel and broadcast an alarm message across the network; Send a data transmission takeover request to the second server, and the data transmission takeover request includes the encrypted data packet; The second server: In response to the data transmission takeover request, the encrypted data packet is transparently transmitted to the data link layer of the target client through the data link layer of the first server.
5. The method according to claim 1, characterized in that, Transmitting the encrypted data packet to the target client through the first data communication channel includes: Based on the vehicle network topology, determining the primary transmission channel and the backup transmission channel for transmitting the encrypted data packet to the target client; wherein, the vehicle network topology includes a first server, a second server, a vehicle controller, and N vehicle gateways, N being an integer greater than or equal to 2; the first server, the vehicle controller, and each of the vehicle gateways are each connected to at least one electronic control unit; the target client is at least one of the vehicle controller, the vehicle gateway, or the electronic control unit; the first server and the second server are connected to form an open-loop network structure, the first server is connected to at least two of the vehicle gateways to form a first ring network structure, and the N vehicle gateways are connected to form a second ring network structure; Using the primary transmission channel as the first data communication channel, transmitting the encrypted data packet to the target client.
6. The method according to claim 5, wherein Based on the vehicle network topology, determining the primary transmission channel and the backup transmission channel for transmitting the encrypted data packet to the target client includes: Searching for M reachable transmission paths in the vehicle network topology with the first server as the path start point and the target client as the path end point; When M = 1, determining the reachable transmission path as the primary transmission channel; When M ≥ 2, finding the shortest transmission path from the first server to the target client, and determining the shortest transmission path as the primary transmission channel, and determining the remaining M - 1 reachable transmission paths as backup transmission channels.
7. The method according to claim 5, wherein Using the primary transmission channel as the first data communication channel, transmitting the encrypted data packet to the target client includes: Determining the transmission security level of the encrypted data packet; If the transmission security level is the first security level, using the primary transmission channel as the first data communication channel to transmit the encrypted data packet to the target client; If the transmission security level is the second security level, using the primary transmission channel and at least one backup transmission channel as the first data communication channel to transmit the encrypted data packet to the target client in parallel; wherein, the importance of the first security level is lower than the importance of the second security level.
8. The method according to claim 7, wherein Using the primary transmission channel and at least one backup transmission channel as the first data communication channel to transmit the encrypted data packet to the target client in parallel includes: First server: Transmitting the first encrypted data packet to the target client through the primary transmission channel, and transmitting the second encrypted data packet to the target client through the backup transmission channel; wherein, the first encrypted data packet is the same as the second encrypted data packet; Target client: Receive the first encrypted data packet transmitted from the primary transmission channel and the second encrypted data packet transmitted from the backup transmission channel, decrypt the first encrypted data packet and the second encrypted data packet respectively to obtain a first decrypted data packet and a second decrypted data packet, and compare whether the first decrypted data packet and the second decrypted data packet are consistent; If they are consistent, check whether the effective data length of the first decrypted data packet or the second decrypted data packet is consistent with a preset standard data length; If they are inconsistent, record the number of abnormal data receptions, and feedback a data reception abnormal message to the first server, where the data reception abnormal message includes the number of abnormal data receptions; First server: If the number of abnormal data receptions exceeds a preset number threshold, broadcast an alarm message across the network, and abort transmitting the first encrypted data packet through the primary transmission channel and transmitting the second encrypted data packet through the backup transmission channel.
9. A data communication protection device is applied to the in-vehicle or vehicle-cloud SOME / IP communication process, and is characterized in that Includes: A message sending module, configured to send a service publishing message to a target client, where the service publishing message includes service identification information, a first encrypted sending IP address and a first encrypted sending port number of the first server, and where there is a binding relationship between the hardware information of the first server and the first encrypted sending IP address and the first encrypted sending port number; A channel establishing module, configured to establish a first data communication channel with the target client and create a first service process after receiving a service subscription message corresponding to the service identification information sent by the target client and confirming that the service subscription message is legal information; where the service subscription message includes an encrypted receiving IP address and an encrypted receiving port number of the target client, and there is a binding relationship between the hardware information of the target client and the encrypted receiving IP address and the encrypted receiving port number; A process monitoring module, configured to start a preset first security monitoring process to monitor the currently running processes to obtain a first monitoring result, and send the first monitoring result to the second security monitoring process of the second server; where the currently running processes include the first service process; A result receiving module, configured to receive a second monitoring result obtained by the second server through the second security monitoring process for monitoring the currently running processes; A data transmission module, configured to determine that there is no abnormality in the currently running process based on the first monitoring result or the second monitoring result if the first monitoring result and the second monitoring result are consistent, and determine whether there is an abnormality in the currently running process based on the second monitoring result if the first monitoring result and the second monitoring result are inconsistent; if it is determined that there is no abnormality in the currently running process, encapsulate and encrypt the data to be sent to the target client according to the Ethernet packet structure to obtain an encrypted data packet, and transmit the encrypted data packet to the target client through the first data communication channel; Wherein, the first server is the intelligent cockpit of the vehicle end, and the second server is the vehicle's whole vehicle remote communication module.
10. A readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Permission checking method and system for event subscription
CN114615049A
Communication method, device and system
CN116962157A
Detection method and device of vehicle-mounted operating system, vehicle and storage medium
CN117436070A