A bus message security protection method, system and electronic device
By combining vehicle dynamics and data change-level safety detection methods during the design and operation phases, the contradiction between in-vehicle bus network security and real-time performance was resolved. This enabled real-time transmission and security detection of critical messages, improving the security capabilities of the bus network and the reliability of vehicle driving functions.
Patent Information
- Application Number
- CN202411535781.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-31
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-10-31
AI Technical Summary
Existing technologies cannot improve the network security capabilities of in-vehicle bus networks while meeting the real-time requirements of in-vehicle bus messages, thus threatening the safety of vehicle driving functions.
By defining network security requirements during the design phase, adding jitter attributes, performing schedulability analysis on CAN messages, and combining lateral vehicle dynamics-based safety detection with longitudinal data change-based safety detection, the real-time transmission and security of critical messages are ensured.
While ensuring the real-time transmission of messages, the security capabilities of the in-vehicle bus network have been enhanced, effectively curbing malicious tampering attacks and ensuring the safety and stability of vehicle driving functions.
Smart Images

Figure CN119496636B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of intelligent networked vehicle network security and functional safety technology, in particular to a bus message security protection method and system and electronic equipment. BACKGROUND
[0002] With the development of the integration of automobile and information communication technology, more and more automobile electronic functions are installed on the automobile. Due to the increasing number of in-vehicle computers, the design of in-vehicle bus in terms of bandwidth optimization, functional safety guarantee and the like poses a severe challenge. On the one hand, CAN bus, i.e. controller area network bus, is the most widely used network technology in vehicles and is also applied to robots, factory automation, aircraft and medical devices and many other industrial fields. However, the CAN bus protocol does not take verification or encryption to protect network security, and most of the current security protection measures for CAN bus such as message encryption, adding MAC code in message load and network intrusion detection do not take into account the lack of constraints in terms of resource limitations and time delay requirements of in-vehicle computers. Therefore, it is extremely vulnerable to network attacks. Especially with the development of network connection, the attack surface of the automobile is continuously expanded by malicious attacks, and now attackers attack messages from in-vehicle physical interfaces and in-vehicle wireless interfaces to in-vehicle networks, which brings great security risks to vehicle driving. On the other hand, automobile electronic functions have strict real-time requirements, and if the message instructions cannot be responded in time, it may cause disastrous consequences and even threaten the safety of passengers.
[0003] Therefore, it is currently impossible to improve the network security capability of in-vehicle bus while meeting the real-time requirements of messages in in-vehicle bus and ensuring the functional safety of automobile driving. SUMMARY
[0004] The present application aims to provide a bus message security protection method, system and electronic equipment to solve or improve the problem that it is impossible to improve the network security capability of in-vehicle bus while ensuring the functional safety of automobile driving.
[0005] Therefore, the first aspect of the present application provides a bus message security protection method, comprising:
[0006] In any of the above technical solutions, S1. In the design stage, the network security requirements of in-vehicle bus are determined through security analysis, and a jitter attribute is added to the safety critical message in the in-vehicle environment to obtain a safety critical message, wherein the safety critical message is a message that may cause safety hazards if tampered with or lost, including worst execution time, message period, message deadline, queuing jitter time and priority.
[0007] Scheduling analysis is performed on CAN messages. By evaluating the worst-case execution time, message period, message deadline, queuing jitter time and priority of each message, the response time of each message is calculated. CAN is the abbreviation for Controller Area Network Bus, which is a serial communication protocol bus used for real-time applications.
[0008] S2. During the operation phase, based on the attribute parameters of the safety-critical messages, within the response time of each message, the safety-critical messages are judged for anomalies by lateral safety detection based on vehicle dynamics analysis and longitudinal safety detection based on data change degree analysis, and messages exceeding the limit threshold are discarded.
[0009] S3. Add messages that are less than or equal to the limit threshold to the message queue and wait for bus arbitration and transmission.
[0010] In any of the above technical solutions, the magnitude of the queuing jitter time is equal to the time delay of the lateral analysis based on vehicle dynamics and the longitudinal analysis based on the degree of data change for safety analysis.
[0011] In any of the above technical solutions, the lateral safety detection includes: obtaining the physical meaning of the signal actually contained in the message, substituting the sensor values in the message into the vehicle dynamics model, determining whether the input sensor values are abnormal, and if so, discarding the message; otherwise, performing longitudinal safety detection on the message.
[0012] In any of the above technical solutions, the longitudinal security detection includes: comparing the value of the physical quantity contained in the message with the normal value of the physical quantity; if the difference exceeds the difference threshold, it is counted as an anomaly.
[0013] In any of the above technical solutions, the longitudinal security detection further includes: setting an acceptable threshold for the number of anomalies, defining messages exceeding the threshold as abnormal messages and discarding them.
[0014] In any of the above technical solutions, the response time for each message is calculated using a formula for the response time of each message.
[0015] In any of the above technical solutions, the formula for each message response time is as follows:
[0016] R i =J i +w i +C i
[0017] Among them, R i J represents the response time for each message. i w represents the queue jitter time. i Indicates queuing delay, C iworst-case execution time of a message.
[0018] In any of the technical solutions above, the lateral safety detection is based on analysis of vehicle dynamics, and the correlation between multiple data is considered, and the longitudinal safety detection is based on analysis of the degree of data change, and the actual physical quantity change embodied by the incoming message is detected.
[0019] The second aspect of the application provides a bus message security protection system, comprising
[0020] The design module (201) is used for determining network security requirements of the in-vehicle bus through security analysis in a design phase, and adding a jitter attribute to a safety-critical message in a vehicle-mounted environment to obtain the safety-critical message, wherein the safety-critical message is a message that may cause a security risk if tampered with or lost, and includes a worst-case execution time, a message period, a message deadline, a queuing jitter time and a priority level.
[0021] The schedulability of the CAN message is analyzed, and the response time of each message is calculated by evaluating the worst-case execution time, the message period, the message deadline, the queuing jitter time and the priority level of each message, wherein CAN is the abbreviation of Controller Area Network bus, and is a serial communication protocol bus for real-time applications.
[0022] The running module (202) is used for, in a running phase, based on the attribute parameters of the safety-critical message, within the response time of each message, performing abnormality judgment on the safety-critical message through lateral safety detection based on analysis of vehicle dynamics and longitudinal safety detection based on analysis of the degree of data change, and discarding a message greater than a limit number threshold.
[0023] The transmission module (203) is used for adding a message less than or equal to the limit number threshold to a message queue, waiting for bus arbitration and transmission.
[0024] The third aspect of the application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the bus message security protection method when executing the computer program.
[0025] Compared with the prior art, the application has the following beneficial effects:
[0026] 1、The application considers the time delay overhead caused by network security protection in the design phase and adopts the method of combining lateral analysis based on vehicle dynamics and longitudinal analysis based on the degree of data change in the running phase to improve the network security capability of the in-vehicle bus and effectively curb malicious tampering attacks on CAN bus messages under the premise of ensuring the real-time performance of message transmission through scheduling analysis.
[0027] 2、The present application increases the jitter attribute by explicitly network security protection brings the time delay overhead, ensures that the message in the in-vehicle bus meets the real-time requirement;
[0028] 3、The present application adopts the way of design-time analysis and runtime detection cooperation, improves the network security capability of the in-vehicle bus, and guarantees the automobile driving function safety. BRIEF DESCRIPTION OF DRAWINGS
[0029] The above and / or additional aspects and advantages of the present application will become apparent and be readily understood from the following description, taken in conjunction with the accompanying drawings, in which:
[0030] Figure 1 A flow chart of a bus message security protection method according to the present application;
[0031] Figure 2 A block diagram of a bus message security protection system according to the present application;
[0032] Figure 3 A schematic diagram of an electronic device according to the present application. DETAILED DESCRIPTION
[0033] In order to more clearly understand the above objectives, features and advantages of the present application, the present application will be further described below in conjunction with the accompanying drawings and specific embodiments. It should be noted that the embodiments of the present application and the features in the embodiments can be combined with each other without conflict.
[0034] In the following description, a lot of specific details are set forth in order to facilitate a thorough understanding of the present application, however, the present application can also be implemented in other ways different from those described herein, therefore, the protection scope of the present application is not limited by the specific embodiments disclosed below.
[0035] Please refer to Figures 1-3 , the following describes a bus message security protection method, system and electronic device according to the present application.
[0036] Figure 1 A flow chart of a bus message security protection method according to the present application.
[0037] In some embodiments of the present application, as shown in Figure 1 , the bus message security protection method comprises:
[0038] S1. In the design phase, determine the network security requirements of the in-vehicle bus through security analysis, and add jitter attributes to the safety-critical messages in the vehicle environment to obtain safety-critical messages, wherein the safety-critical messages are messages that may cause safety hazards if tampered with or lost, including worst-case execution time, message period, message deadline, queuing jitter time, and priority;
[0039] In one embodiment, the present application relates to a vehicle network communication process to ensure the transmission safety of safety-critical messages. The scheme of the present application is applied to a vehicle controller area network. The messages transmitted in the communication process include safety-critical messages and non-safety-critical messages, wherein the safety-critical messages have a high possibility of causing safety hazards, and the non-safety-critical messages have a low possibility of causing safety hazards; at the same time, considering the real-time requirement, not all messages are detected, only safety-critical messages are detected to reduce the overhead, and non-safety-critical messages directly enter the ready queue after the message is ready. The above parameters contained in the safety-critical messages are crucial to ensure the reliability of the vehicle system when subjected to potential attacks or failures. Specifically, the worst-case execution time refers to the longest time of message processing under the most unfavorable conditions, the message period is the frequency of message transmission, the message deadline is the last time point at which the message needs to be processed, and the queuing jitter time is the message processing delay caused by system load changes.
[0040] Among them, the security analysis refers to the evaluation of the security of the system under potential threats and attacks during the system design process; the network security requirement refers to a series of technical requirements set to ensure system security; the bus is a more general term, which refers to the data transmission network in the vehicle, including various vehicle communication networks such as CAN. The bus is a bridge for communication between vehicle computers. In a complex vehicle electronic architecture, multiple vehicle computers communicate with each other through the bus to achieve coordinated control of various functional modules of the vehicle. Vehicle computers are electronic controllers that control various subsystems of the vehicle. Modern vehicles usually contain multiple vehicle computers responsible for different functional modules. The parameter representing the jitter attribute is the queuing jitter time.
[0041] Among them, CAN (Controller Area Network) is the Chinese translation of the bus. CAN is a specific bus protocol for real-time data transmission.
[0042] The schedulability of the CAN message is analyzed, and the response time of each message is calculated by evaluating the worst-case execution time, message period, message deadline, queuing jitter time, and priority of each message, wherein CAN is the English abbreviation of Controller Area Network bus, which is a serial communication protocol bus for real-time applications;
[0043] In one embodiment, each on-board computer sends and receives control instructions or sensor data through the in-vehicle bus. For example, the on-board computer of the braking system can obtain the vehicle speed information through the CAN bus and issue a braking command according to the vehicle speed information. The present application performs schedulability analysis on the CAN messages to ensure that each message can be processed on time and prevent safety hazards caused by message loss or delay.
[0044] Each message response time is calculated by the message response time formula.
[0045] In one embodiment, in the design phase, it is determined whether each message can be processed within the specified time, i.e., before the message deadline, by calculating the response time of each message to ensure real-time requirements.
[0046] In one embodiment, the specified time, usually referred to as the maximum allowed time required by the system or application, is a target or standard, the response time is the actual performance, and the latency, i.e., the queuing delay, is a factor affecting the response time. Ensuring that the latency is controlled within a reasonable range helps to meet the requirements of the specified time. Although the response time is closely related to the worst-case execution time, the latency, and the queuing jitter time, considering the message period, deadline, and priority is also a necessary measure to ensure the overall performance and safety of the system.
[0047] Each message m i is composed of the following attributes:
[0048] (C i ,T i ,D i ,J i ,P i )
[0049] where C i represents the message worst-case execution time, i represents a positive integer, T i represents the message period, D i represents the message deadline, J i represents the message jitter time, P i represents the priority, and P i The smaller the priority, the higher the message priority; the queuing jitter time corresponds to the longest time from the initial event to the message arrival ready queue, and the size of this jitter time is equal to the latency of the lateral safety analysis based on vehicle dynamics and the longitudinal safety analysis based on the degree of data change.
[0050] where the message worst-case execution time, message period, message deadline, queuing jitter time, and priority are known, and the message response time is unknown. Through message schedulability analysis, the response time of the message is calculated.
[0051] The formula for each message response time is as follows:
[0052] R i = J i + w i + C i
[0053] wherein R i represents the response time of each message, w i represents the queuing delay, the longest time that the corresponding message can stay in the ready queue before being transmitted on the bus.
[0054] The above formula will help the designer better understand the calculation process, so that he can adjust the scheduling strategy of the message according to the actual demand and optimize the system performance.
[0055] The lateral safety detection is based on the analysis of vehicle dynamics, considering the correlation between multiple data, and the longitudinal safety detection is based on the analysis of data variation degree, detecting the actual physical quantity change embodied by the incoming message.
[0056] The present application analyzes the real-time performance of the message through the CAN message scheduling algorithm. If the response time of all messages is less than the deadline of the message, it is determined that the message set is schedulable, that is, it can be added to the message queue, waiting for bus arbitration and transmission.
[0057] The above method combines vehicle dynamics and data analysis in two dimensions, providing a comprehensive safety detection scheme, so that the system can monitor and respond to potential safety threats in real time, thereby ensuring the safe operation of the vehicle.
[0058] S2. In the running phase, based on the safety critical message attribute parameters, within the response time of each message, through the lateral safety detection based on vehicle dynamics analysis and the longitudinal safety detection based on data variation degree analysis, the safety critical message is abnormally judged, and the message greater than the limit number threshold is discarded;
[0059] In one embodiment, in the running phase, the system utilizes the safety-critical messages obtained in the design phase to implement both horizontal and vertical safety detection. The main goal of this phase is to monitor the messages transmitted on the vehicle bus in real-time to identify potential abnormal behaviors. In horizontal safety detection, the system parses the actual signals contained in the messages and combines them with the vehicle dynamics model to analyze whether there are unreasonable changes in sensor values. If it is found that the incoming sensor data deviates from the expected value, the system will mark it as a suspicious message. At the same time, in vertical safety detection, the system compares the numerical value of the physical quantity in the message with the preset normal range. If the difference is found to exceed the set threshold, the message will be recorded as abnormal. Finally, the system will determine whether the message has occurred abnormally according to the set threshold of the acceptable number of abnormalities, and if so, it will be discarded. All messages that exceed this threshold will be discarded immediately to ensure the overall safety and reliability of the system. This process ensures that all critical messages are under monitoring during operation, and potential safety threats are identified and handled in a timely manner.
[0060] S3. Add messages less than or equal to the limit number threshold to the message queue, waiting for bus arbitration and transmission.
[0061] In one embodiment, after completing the abnormality judgment, the system will include all messages less than or equal to the acceptable limit number threshold in the message queue. This step is crucial because it ensures that the safety-detected messages can continue to participate in subsequent bus arbitration and transmission processes. The construction of the message queue not only depends on the safety analysis results, but also involves reasonable management of message priorities. The system will adjust the position of each message in the queue according to its priority and real-time requirements to ensure that the most critical messages are processed first. This dynamic management mechanism helps the system maintain high efficiency under high load conditions and effectively prevents important messages from causing safety hazards due to delays. In this way, the system can ensure smooth transmission of safety-critical messages, thereby ensuring the safety and stability of the vehicle under various operating conditions.
[0062] In one embodiment, since CAN messages usually include an identifier ID, data length, data content, etc., when multiple vehicle computer nodes on the bus send messages simultaneously, in order to effectively manage and prioritize transmission, arbitration is performed by comparing the message identifier ID, with the smaller ID having higher priority. The message that wins the arbitration can be transmitted to all nodes on the bus, and each node decides whether to process the received message based on the message ID.
[0063] The size of the queuing jitter time is equal to the time delay of horizontal vehicle dynamics-based analysis and vertical data change-based analysis safety analysis.
[0064] In one embodiment, the queuing jitter time is not only related to the priority of the message, but also closely related to the dynamic behavior of the vehicle. By analyzing the dynamic response of the vehicle in different operating states, the actual delay in message processing can be accurately calculated, providing a reliable basis for subsequent safety detection.
[0065] The lateral safety detection includes: obtaining the physical meaning of the signal actually contained in the message, substituting the sensor value in the message into the vehicle dynamics model, judging whether the incoming sensor value is abnormal, if yes, discarding the message, if not, performing longitudinal safety detection on the message.
[0066] In one embodiment, in the lateral safety detection process, the sensor data carried in the message is first parsed to understand its physical meaning, and then the data is substituted into the vehicle dynamics model for verification to determine whether the actual situation is consistent with the model prediction. This comparison can reveal potential sensor failures or attack behaviors, so that appropriate safety measures can be taken.
[0067] The longitudinal safety detection includes: comparing the numerical value of the physical quantity contained in the message with the normal value of the physical quantity, and if the difference exceeds the difference threshold, it is counted as an abnormality.
[0068] In one embodiment, in the longitudinal safety detection, the system compares the sensor reported value with the preset normal range, and any abnormal data exceeding the threshold value will be marked as a potential threat, triggering further safety processing procedures. Ensuring the timely response of the system to abnormal behavior helps to protect the overall safety of the vehicle.
[0069] The longitudinal safety detection also includes: setting an acceptable abnormality times threshold, and defining messages exceeding the abnormality times threshold as abnormal messages and discarding them.
[0070] In one embodiment, by setting an abnormality times threshold, occasional abnormal fluctuations can be tolerated within a certain range, and once the abnormality times threshold is exceeded, the system will immediately discard the message to prevent it from affecting the stability of the system. This measure helps to maintain the long-term reliability of the system and avoids unnecessary safety alarms caused by a single abnormal data.
[0071] The present application effectively deals with malicious tampering attacks by explicitly considering the time delay overhead caused by network security protection, and timely suppresses malicious messages entering the CAN bus network; by ensuring the real-time transmission of messages through scheduling analysis, the lateral vehicle dynamics-based analysis and the longitudinal data change degree-based analysis detection are combined during runtime to improve the network security capability of the in-vehicle bus; by using the design-time analysis and runtime detection collaborative method, the network security of the in-vehicle bus is improved while the automotive driving function safety is guaranteed.
[0072] Figure 2 A block diagram of a bus message security protection system according to the present application.
[0073] The embodiment of the second aspect of the present application also provides a bus message security protection system, comprising:
[0074] The design module 201 is configured to determine network security requirements of the in-vehicle bus through security analysis in a design phase, and add jitter attributes to safety-critical messages in a vehicle-mounted environment to obtain safety-critical messages, wherein the safety-critical messages are messages that may cause safety hazards if tampered with or lost, including worst-case execution time, message period, message deadline, queuing jitter time and priority.
[0075] The schedulability of the CAN message is analyzed, and the response time of each message is calculated by evaluating the worst-case execution time, message period, message deadline, queuing jitter time and priority of each message, wherein CAN is the abbreviation of Controller Area Network bus, which is a serial communication protocol bus for real-time applications.
[0076] The running module 202 is configured to, in a running phase, based on the attribute parameters of the safety-critical messages, within the response time of each message, perform abnormality judgment on the safety-critical messages through horizontal safety detection based on vehicle dynamics analysis and longitudinal safety detection based on data change degree analysis, and discard messages greater than a limit number threshold.
[0077] The transmission module 203 is configured to add messages less than or equal to the limit number threshold to a message queue, and wait for bus arbitration and transmission.
[0078] Figure 3 A schematic diagram of an electronic device according to the present application.
[0079] The embodiment of the third aspect of the present application provides an electronic device. In some embodiments of the present application, as shown in Figure 3 The electronic device can be a desktop computer, a notebook, a palm computer, a cloud server, etc. The electronic device 3 can include but is not limited to a processor 301 and a memory 302. Those skilled in the art can understand that Figure 3 The electronic device 3 is only an example of the electronic device 3 and does not constitute a limitation on the electronic device 3, and can include more or fewer components than the diagram or different components.
[0080] The processor 301 can be a central processing unit (CPU), or other general purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, etc.
[0081] The memory 302 can be an internal storage unit of the electronic device 3, for example, a hard disk or a memory of the electronic device 3. The memory 302 can also be an external storage device of the electronic device 3, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 3. The memory 302 can also include both the internal storage unit and the external storage device of the electronic device 3. The memory 302 is used to store computer programs and other programs and data required by the electronic device.
[0082] Embodiments of the present application provide a computer readable storage medium. In some embodiments of the present application, a computer readable storage medium is provided, which, when executed by the processor 301, implements the steps of the above method, so that the computer readable storage medium provided by the present application has all the technical effects of the above steps, which will not be repeated here.
[0083] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific name of each functional unit and module is only for convenient distinction, and does not limit the protection scope of the present application. The specific working process of the unit and module in the above system can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0084] Those skilled in the art can appreciate that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present disclosure.
[0085] In the embodiments provided by the present disclosure, it should be understood that the disclosed apparatus / equipment and method can be implemented in other ways. For example, the apparatus / equipment embodiments described above are merely schematic. For example, the division of the modules or units is merely a logical function division, and there can be another division manner in actual implementation. Multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or in other forms.
[0086] If the integrated modules / units are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on such understanding, the present disclosure realizes all or part of the processes in the above-mentioned embodiment methods, which can also be completed by instructing related hardware through a computer program. The computer program can be stored in a computer readable storage medium, and when the program is executed by a processor, the steps of the above-mentioned various method embodiments can be realized. The computer program can include computer program code, which can be in the form of source code, object code, executable file or some intermediate form. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier wave signal, telecommunication signal and software distribution medium, etc. It should be noted that the content included in the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electric carrier wave signal and telecommunication signal.
[0087] The above examples are only used to illustrate the technical solutions of the present disclosure, rather than limit the same; although the present disclosure is described in detail with reference to the foregoing examples, those of ordinary skill in the art should understand that the technical solutions recorded in the foregoing examples can be modified, or some technical features thereof can be replaced by equivalents; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should be included in the protection scope of the present disclosure.
Claims
1. A method for securing bus messages, characterized in that The method comprises the following steps: S1. In the design stage, network security requirements of the in-vehicle bus are determined through security analysis, and a jitter attribute is added to a safety-critical message in a vehicle-mounted environment to obtain the safety-critical message, wherein the safety-critical message is a message that may cause a safety hazard if tampered with or lost, and comprises worst-case execution time, message period, message deadline, queuing jitter time and priority; S2. In the running stage, based on the attribute parameters of the safety-critical message, within the response time of each message, the safety-critical message is abnormally judged through transverse safety detection based on vehicle dynamics analysis and longitudinal safety detection based on data change degree analysis, and messages greater than a limit number threshold are discarded; The transverse safety detection comprises the following steps: obtaining the physical meaning of the actual signals contained in the message, substituting the sensor values in the message into a vehicle dynamics model, judging whether the incoming sensor values are abnormal, if yes, discarding the message, and if no, performing longitudinal safety detection on the message; The longitudinal safety detection comprises the following steps: comparing the numerical value of the physical quantity contained in the message with the normal value of the physical quantity, and if the difference exceeds a difference threshold, counting as one abnormality; The longitudinal safety detection further comprises the following steps: setting an acceptable abnormality number threshold, and defining messages exceeding the abnormality number threshold as abnormal messages and discarding the abnormal messages; S3. Messages less than or equal to the limit number threshold are added to a message queue and wait for bus arbitration and transmission. Each message response time is calculated by a message response time formula. The message response time formula is as follows:
2. The method of claim 1, wherein, The transverse safety detection is based on vehicle dynamics analysis and considers the correlation between multiple data, and the longitudinal safety detection is based on data change degree analysis and detects the actual physical quantity change embodied in the incoming message.
3. The method of claim 2, wherein, The method comprises the following steps: R i =J i +w i +C i where R i represents the response time of each message, J i represents the queuing jitter time, w i represents the queuing delay, C i represents the worst-case execution time of a message.
4. The method of claim 1, wherein, A design module (201) is configured to, in the design stage, determine network security requirements of the in-vehicle bus through security analysis, and add a jitter attribute to a safety-critical message in a vehicle-mounted environment to obtain the safety-critical message, wherein the safety-critical message is a message that may cause a safety hazard if tampered with or lost, and comprises worst-case execution time, message period, message deadline, queuing jitter time and priority; 5. A system for implementing the bus message security method of any one of claims 1-4, characterized by S2. In the running stage, based on the attribute parameters of the safety-critical message, within the response time of each message, the safety-critical message is abnormally judged through transverse safety detection based on vehicle dynamics analysis and longitudinal safety detection based on data change degree analysis, and messages greater than a limit number threshold are discarded; The transverse safety detection comprises the following steps: obtaining the physical meaning of the actual signals contained in the message, substituting the sensor values in the message into a vehicle dynamics model, judging whether the incoming sensor values are abnormal, if yes, discarding the message, and if no, performing longitudinal safety detection on the message; The longitudinal safety detection comprises the following steps: comparing the numerical value of the physical quantity contained in the message with the normal value of the physical quantity, and if the difference exceeds a difference threshold, counting as one abnormality; The longitudinal safety detection further comprises the following steps: setting an acceptable abnormality number threshold, and defining messages exceeding the abnormality number threshold as abnormal messages and discarding the abnormal messages; S3. Messages less than or equal to the limit number threshold are added to a message queue and wait for bus arbitration and transmission. Each message response time is calculated by a message response time formula. The message response time formula is as follows: The transverse safety detection is based on vehicle dynamics analysis and considers the correlation between multiple data, and the longitudinal safety detection is based on data change degree analysis and detects the actual physical quantity change embodied in the incoming message. The queuing jitter time is equal to the time delay of the transverse vehicle dynamics-based analysis and the longitudinal data variation degree-based analysis safety analysis; The running module (202) is configured to, in the running phase, based on the safety critical message attribute parameter, perform abnormality judgment on the safety critical message within the response time of each message through the transverse safety detection based on the vehicle dynamics analysis and the longitudinal safety detection based on the data variation degree analysis, and discard the message greater than a limit number threshold value; The transverse safety detection comprises: obtaining a physical meaning of a signal actually contained in the message, substituting a sensor value in the message into a vehicle dynamics model, judging whether the incoming sensor value is abnormal, if yes, discarding the message, and if no, performing longitudinal safety detection on the message; The longitudinal safety detection comprises: comparing a numerical value of a physical quantity contained in the message with a normal value of the physical quantity, and if a difference value exceeds a difference threshold value, counting as one abnormality; The longitudinal safety detection further comprises: setting an acceptable abnormality number threshold value, defining the message exceeding the abnormality number threshold value as an abnormal message and discarding the abnormal message; and the transmission module (203) is configured to add the message less than or equal to the limit number threshold value to a message queue, and wait for bus arbitration and transmission.
6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that, The processor implements the steps of the bus message safety protection method according to any one of claims 1 to 4 when executing the computer program.
Citation Information
Patent Citations
Offset-based CAN FD (Controller Area Network with Flexible Data rate) bus message scheduling method
CN109327367A
Abnormity detection method and device of vehicle-mounted CAN bus, storage medium and electronic equipment
CN116155767A