A method, system, electronic device, and storage medium for vehicle data security management.

By classifying, tagging, and conducting compliance analysis of vehicle data, the transparency and security issues of connected vehicle data security management are resolved, ensuring the legitimate rights and interests of users' data, outputting only violations, and improving data security.

CN119598522BActive Publication Date: 2025-10-31CHERY AUTOMOBILE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411453627.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-17
Publication Date
2025-10-31
Estimated Expiration
2044-10-17

AI Technical Summary

Technical Problem

In existing technologies, the data security management methods for connected vehicles are limited, which leads to the impact on user privacy and national security, and users lack transparency in their perception of data.

Method used

By acquiring data from different locations on the vehicle, classifying and adding location information, and using a pre-trained labeling model to identify the type, frequency, and address of accessed data, compliance analysis is performed to determine whether any violations have occurred. The vehicle data is then stored in the storage space, and only violations are output.

Benefits of technology

It has improved the security of vehicle data, protected the legitimate rights and interests of users, made the current status of data use transparent, and supervised the illegal behavior of third parties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119598522B_ABST
    Figure CN119598522B_ABST
Patent Text Reader

Abstract

This disclosure relates to a vehicle data security management method, system, electronic device, and storage medium. The management method includes: classifying the vehicle data and adding location information; marking accessed data upon receipt; determining the data flow status of the vehicle data based on the data flow direction of the accessed data and the location information of the vehicle data; allowing users to transparently view the current status of in-vehicle data usage; then performing compliance analysis by combining the accessed data and different categories of vehicle data to determine whether any violations have occurred; and monitoring the purpose and flow of the accessed data and vehicle data to supervise the illegal collection activities of other third parties. This effectively protects the legitimate rights and interests of user data, ultimately storing vehicle data within the vehicle's storage space and only outputting violation events externally, thereby improving data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure belongs to the field of data security technology, and in particular relates to a vehicle data security management method, system, electronic device and storage medium. Background Technology

[0002] Currently, users' perception of data is based on what companies disclose to them through privacy policies, lacking a tangible concept. Furthermore, the management methods for data security in connected vehicles are relatively limited. For example, if vehicle data is completely open, it can be used infinitely by users or criminals, which could severely impact user privacy and even national security. Summary of the Invention

[0003] To address the aforementioned issues, this disclosure provides a vehicle data security management method, system, electronic device, and storage medium. By analyzing the data flow direction of accessed data and the location information of vehicle data, the flow of vehicle data is determined, allowing users to transparently view the current status of in-vehicle data usage. Through monitoring the purpose and flow of accessed and vehicle data, vehicle data is ultimately stored within the vehicle's storage space, with only violations being output externally, thus improving data security.

[0004] To address the aforementioned technical problems, the first aspect of this invention provides a vehicle data security management method, the method comprising:

[0005] Vehicle data from different locations on the vehicle is acquired, and the vehicle data is categorized according to its purpose and location information is added.

[0006] Upon receiving access data, the access data is identified based on a pre-trained labeling model, and the access type, access frequency, and access address of the access data are labeled according to the identification results.

[0007] The access type, access frequency, and access address of each access data are classified and analyzed, and the data flow of key data in the vehicle data is determined based on the location information.

[0008] The vehicle data is subjected to compliance analysis based on the classification results of the access data and the vehicle data to determine whether any violations have occurred.

[0009] The vehicle data is stored in the vehicle's storage space, and the violation event is output to the outside world.

[0010] According to a preferred embodiment of the present invention, the step of acquiring vehicle data at different locations on the vehicle includes:

[0011] The vehicle is equipped with a main control node and branch nodes located at different positions.

[0012] Both the master control node and the branch node are used to acquire the vehicle data;

[0013] According to a preferred embodiment of the present invention, storing the vehicle data in the vehicle's storage space includes:

[0014] The master control node receives the vehicle data from each of the branch nodes and stores the vehicle data in a structured manner.

[0015] According to a preferred embodiment of the present invention, before classifying the vehicle data according to its purpose and adding location information, the management method further includes:

[0016] Determine whether the vehicle data is encrypted data. If the vehicle data is encrypted data, decrypt the vehicle data, classify it, and add location information.

[0017] According to a preferred embodiment of the present invention, the management method further includes: generating a data compliance model based on preset data compliance requirements and preset normal data range;

[0018] The step of performing compliance analysis on the vehicle data by combining the classification results of the access data and the vehicle data to determine whether a violation event has occurred includes: detecting the access data and the vehicle data corresponding to different classification results according to the data compliance model, determining whether the vehicle data or access data violates compliance rules, and when the vehicle data or access data violates compliance rules, determining that a violation event has occurred and issuing an early warning.

[0019] According to a preferred embodiment of the present invention, the management method further includes:

[0020] According to the interface requirements of the preset monitoring platform, an early warning message is generated based on the violation event and the corresponding vehicle data and reported to the preset monitoring platform.

[0021] According to a preferred embodiment of the present invention, the training method of the labeling model includes:

[0022] Multiple sets of historical access data are obtained, and the historical access data are classified according to the data purpose to obtain the access category, access frequency and access address of each set of historical access data;

[0023] The labeling model is constructed and trained based on historical access data and the access categories, access frequencies, and access addresses of the historical access data.

[0024] To address the aforementioned technical problems, a second aspect of the present invention provides a vehicle data security management system, the management system comprising:

[0025] The data acquisition module is used to acquire vehicle data from different locations on the vehicle.

[0026] The data classification module is used to classify the vehicle data according to its purpose and add location information;

[0027] The data tagging module is used to identify the access data based on a pre-trained tagging model when the access data is received, and to tag the access type, access frequency and access address of the access data according to the identification result;

[0028] The data flow analysis module is used to classify and analyze the access type, access frequency and access address of each accessed data, and determine the data flow of key data in the vehicle data based on the location information.

[0029] The data compliance analysis module is used to perform compliance analysis on the vehicle data by combining the classification results of the access data and the vehicle data, and to determine whether a violation event has occurred.

[0030] The data processing module is used to store the vehicle data in the vehicle's storage space and output the violation event to the outside world.

[0031] To address the aforementioned technical problems, a third aspect of the present invention provides an electronic device, comprising:

[0032] Processor; and

[0033] A memory storing computer-executable instructions that, when executed, cause the processor to perform the method described in any of the above embodiments.

[0034] To address the aforementioned technical problems, a fourth aspect of the present invention provides a computer storage medium, wherein the computer storage medium stores one or more programs, which, when executed by a processor, implement the method described in any of the above embodiments.

[0035] Compared with existing technologies, this disclosure has the following advantages: After acquiring vehicle data, this disclosure classifies the vehicle data and adds location information. Upon receiving access data, it identifies the access data using a tagging model, marking the access type, access frequency, and access address. Based on the data flow direction of the access data and the location information of the vehicle data, it obtains the data flow status of the vehicle data, allowing users to transparently view the current status of in-vehicle data usage. Then, it combines the access data and different categories of vehicle data for compliance analysis to determine whether any violations have occurred. By monitoring the purpose and flow of access data and vehicle data, it supervises the illegal collection behavior of other third parties. This effectively protects the legitimate rights and interests of user data, ultimately storing vehicle data in the vehicle's storage space and only outputting violation events externally, thus improving data security.

[0036] Other features and advantages of this disclosure will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the disclosure. The objects and other advantages of this disclosure may be realized and obtained by means of the structures pointed out in the description, claims and drawings. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1 A schematic flowchart of a vehicle data security management method according to an embodiment of the present disclosure is shown;

[0039] Figure 2 A block diagram of a vehicle data security management system according to an embodiment of the present disclosure is shown;

[0040] Figure 3 A schematic diagram of an electronic device structure according to an embodiment of the present disclosure is shown. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0042] The same reference numerals in the accompanying drawings denote the same or similar elements, components, or parts, and therefore, repeated descriptions of the same or similar elements, components, or parts may be omitted below. It should also be understood that although terms such as first, second, third, etc., indicating numbers may be used herein to describe various devices, elements, components, or parts, these devices, elements, components, or parts should not be limited by these terms. That is, these terms are only used to distinguish one from another. For example, a first device may also be referred to as a second device, without departing from the essential technical solution of the invention. Furthermore, the terms "and / or" and "and / or" refer to all combinations including any one or more of the listed items.

[0043] Please see Figure 1 , Figure 1 This is a schematic diagram of a vehicle data security management method provided by the present invention, such as... Figure 1 As shown, the method includes:

[0044] S11. Obtain vehicle data from different locations on the vehicle, classify the vehicle data according to its purpose, and add location information.

[0045] In this embodiment, the solution acquires vehicle data at different locations on the vehicle, classifies the vehicle data based on its intended use, and adds corresponding location information to each vehicle data set to help the system understand the status of the data.

[0046] In this embodiment, vehicle data from different locations on the vehicle can be collected through TBOX devices, gateways, intelligent driving domain controllers, and other devices installed on the vehicle. The TBOX device refers to an intelligent in-vehicle terminal, also known as a Telematics BOX. It is an embedded system installed in the vehicle, connecting to a backend server via wireless communication technology to achieve real-time transmission and remote control of vehicle data. The Automated Driving Control Unit (ADCU) is a core component specifically designed for intelligent driving systems. The ADCU receives data from multiple sensors (such as cameras, millimeter-wave radar, lidar, and V2X cloud data transmission) and vehicle dynamic data (such as vehicle speed and pedal signals) acquired through the ADCU. It supports customized control strategies and execution decisions for all inputs and outputs feedback on driving status, thereby executing various intelligent driving functions on the vehicle. Specifically, the vehicle has a master control node and branch nodes located at different locations; both the master control node and branch nodes are used to acquire vehicle data. The branch nodes are the aforementioned TBOX devices, gateways, intelligent driving domain controllers, and other devices.

[0047] In this embodiment, the uses of vehicle data include: vehicle monitoring data, data provided by vehicle manufacturers, and sensitive personal data. Different types of data serve different purposes and have different impacts on users. For example, vehicle monitoring data is used to monitor various real-time data of the vehicle, such as vehicle exhaust emissions, including the types, concentrations, and amounts of emissions. Emission data helps assess the environmental performance of vehicles and provides a basis for setting emission standards. Road test data, mileage, and accident rates of autonomous vehicles help understand the safety and reliability of autonomous driving technology and provide a basis for its promotion. Data provided by vehicle manufacturers can be data displayed on the vehicle's dashboard, various vehicle status data displayed on the vehicle's central control screen, and data related to vehicle driving status control. Sensitive personal data includes vehicle usernames, monitoring data, and cabin data.

[0048] In this embodiment, it is determined whether the vehicle data is encrypted. If the vehicle data is encrypted, it is decrypted and then processed. When the branch node probe runs in the controller, it monitors the data at the entrance and exit. When the currently accessed data is plaintext, it is automatically recorded and categorized according to a preset data classification library, such as regulatory data, vehicle-to-cloud communication service data, and personal sensitive data. When the data is encrypted, the encryption / decryption interface in the controller needs to be called to parse it into plaintext before data collection and classification.

[0049] In this embodiment, adding location information to vehicle data allows for data tracing, determining the flow of vehicle data, and enabling users to transparently view the current status of in-vehicle data usage and flow.

[0050] S12. Upon receiving access data, the access data is identified based on a pre-trained labeling model, and the access type, access frequency, and access address of the access data are labeled according to the identification results.

[0051] In this embodiment, the pre-trained labeling model can be obtained by acquiring multiple sets of historical access data, classifying the historical access data according to its purpose, and obtaining the access category, access frequency, and access address for each set of historical access data. Based on the historical access data and its access category, access frequency, and access address, a labeling model is constructed and trained. Specifically, for example, multiple sets of historical communication data are acquired; each set of historical communication data undergoes data structure processing to obtain the communication address, access frequency, and service level for each set of historical communication data; and based on a preset classification strategy, the communication addresses are divided into frequency levels according to the access frequency to obtain the corresponding frequency levels for the communication addresses; a preset labeling model is established based on the communication address, frequency level, and access destination IP address or domain name. In this scheme, historical communication data is access data, and access types include: data acquisition requests, data transmission, etc.

[0052] In this embodiment, the development of each node mainly realizes the collection of communication traffic, linkage with firewall functions, and classification of destination addresses, similar to the firewall function in the network. The software module adopts a bypass deployment method to collect mirrored traffic data of the communication port, so as not to occupy the network bandwidth of the communication port and ensure that the communication service is not affected.

[0053] S13. Classify and analyze the access type, access frequency and access address of each access data, and determine the data flow of key data in vehicle data based on location information.

[0054] In this embodiment, by classifying and analyzing the access type, frequency, and address of the accessed data, the data acquisition and transmission status of each vehicle's data is summarized. Specifically, the destination address of the access can be classified and analyzed, and filtered into regulatory addresses, OEM cloud service addresses, and other types of addresses. This provides business support for subsequent data applications. At this time, addresses that are not within the preset range can be classified as suspicious addresses and uploaded to the enterprise's cloud platform for monitoring and analysis, and the vehicle-side analysis model can be continuously improved.

[0055] For example, it can generate access frequency and destination data for sensitive information such as microphone and camera permissions. This allows users to understand the flow of data they care about. It can also generate a comprehensive data flow map, dynamically displaying the real-time data flow between various controllers. This allows users to transparently view the current status of in-vehicle data usage. Depending on design requirements, it can provide refined query functions to show users the data usage status of each vehicle.

[0056] After classifying and analyzing the data, it can be cleaned and filtered to generate data specific to the reporting function. It supports generating various report types, such as list reports, summary reports, and matrix reports, to meet the needs of different users and scenarios. These reports can display data in the form of tables, charts (such as bar charts, line charts, pie charts, etc.), and dashboards. Through charts, graphs, and dashboards, the reporting tool presents complex data in an intuitive and easy-to-understand format, helping users better understand and analyze the data.

[0057] In this embodiment, based on the processed data, more refined data services can be provided, such as data drill-down: the reporting tool supports data drill-down, allowing users to delve deeper from summary data to detailed data to gain a more in-depth understanding of the reasons and patterns behind the data. Report linkage: through the report linkage function, users can establish relationships between multiple reports to achieve cross-report analysis and display of data. Decision suggestions: based on the results of data analysis, the reporting tool can provide users with decision suggestions or reference opinions to help them make more informed decisions.

[0058] S14. Combine the classification results of access data and vehicle data to conduct compliance analysis on vehicle data and determine whether any violations have occurred.

[0059] In this embodiment, data early warning capability refers to the ability to predict and warn of potential data anomalies, risks, or crises in advance. Especially in a big data environment, various data anomalies may indicate potential problems or risks. Timely early warning and corresponding measures can effectively reduce losses and ensure the smooth operation of business.

[0060] In this embodiment, a data compliance model can be pre-built, generated based on preset data compliance requirements and preset normal data ranges. Specifically, data compliance requirements can be incorporated into the model, such as requirements for anonymizing external vehicle information, default non-collection of cabin data, default in-vehicle processing requirements, and prominent notification requirements. This is combined with the collected data, the IP address of the transmission destination, and the data compliance functions developed and designed by the OEM to generate the data compliance model. The data compliance model is then used to perform compliance analysis on vehicle data to determine if any violations have occurred. Based on the data compliance model, access data and vehicle data corresponding to different classification results are detected to determine whether the vehicle data or access data violates compliance rules. When vehicle data or access data violates compliance rules, a violation event is identified, and an early warning is issued.

[0061] In this embodiment, early warning rules can also be set. When vehicle data or access data violates these rules, a violation event is determined. For example, the system defines the conditions under which an early warning will be triggered. These early warning rules are formulated based on business experience and include the normal range of data, abnormal thresholds, and early warning cycles. When data triggers an early warning rule, the system needs to promptly send an early warning notification to the vehicle owner. Early warning notifications can be sent in various ways, including through the vehicle owner's app and push notifications via the system's pop-up window.

[0062] S15. Store vehicle data in the vehicle's storage space and output violation events externally.

[0063] In this embodiment, vehicle data is stored in the vehicle's storage space, while only the occurrence of violation events is output externally. In order to fully protect the user's data security rights, it is required that only the occurrence of violation events be uploaded, and not the specific violation event data.

[0064] In this embodiment, data storage requires allocating independent storage areas on the host machine. The master node receives vehicle data from various branch nodes and stores this data in a structured manner. This on-vehicle structured storage effectively manages data access, improves performance scalability, and enhances security. It effectively determines data fields, their arrangement, and the relationships between data tables. It minimizes data duplication, thereby reducing storage pressure and improving data access efficiency. During structured storage, duplicate data is stored only once, and its address is mapped to a different data table.

[0065] In this embodiment, considering the issue of storage space, the data storage time can be set, for example, expired data can be cleared on a rolling basis every 30 days.

[0066] In this embodiment, when outputting violation events to external parties, a warning message can be generated based on the violation event and the corresponding vehicle data according to the interface requirements of the preset monitoring platform, and then reported to the preset monitoring platform.

[0067] Specifically, during the development of the master control node module, the reporting interface protocol can be standardized, and the regulatory interface can be unified, thus laying the foundation for a national data security platform. When a violation is detected, the reporting function is activated, and the status is synchronized to the regulatory department's data center.

[0068] Specifically, the pre-set monitoring platform can be a national data security regulatory platform or an enterprise data security regulatory platform. The national monitoring platform requires monitoring fields to include the enterprise name, vehicle model name, event type, and violation records. Each enterprise develops a template according to regulatory requirements, releases it to automakers for implementation, specifies the implementation standards, and establishes a monitoring dashboard. OEMs also have requirements for the monitored fields, requiring the reporting of vehicle internal and external codes and names, vehicle VIN, data security event type, and violation records. This two-way monitoring through the national monitoring platform and the enterprise regulatory platform ensures vehicle-side data security.

[0069] In this embodiment, after acquiring vehicle data, the solution categorizes the data and adds location information. Upon receiving access data, a tagging model identifies the access type, frequency, and address. Based on the data flow direction and location information of the vehicle data, the solution obtains the data flow status of the vehicle data, allowing users to transparently view the current status of in-vehicle data usage. Then, compliance analysis is performed by combining the access data and different categories of vehicle data to determine if any violations have occurred. By monitoring the purpose and flow of access and vehicle data, the solution supervises unauthorized data collection by other third parties. This effectively protects the legitimate rights and interests of user data. Ultimately, vehicle data is stored in the vehicle's storage space, and only violations are output externally, thus improving data security.

[0070] Please see Figure 2 , Figure 2 This is a block diagram of a vehicle data security management system provided by the present invention, such as... Figure 2 As shown, the management system includes branch nodes and a master node. The branch nodes include a data acquisition module, a data classification module, and a data tagging module. The master node includes a data acquisition module, a data classification module, a data tagging module, a data flow analysis module, a data compliance analysis module, and a data processing module.

[0071] In this embodiment, the data acquisition module is used to acquire vehicle data at different locations on the vehicle.

[0072] In this embodiment, the data classification module is used to classify vehicle data according to its purpose and add location information.

[0073] In this embodiment, the data tagging module is used to identify the access data based on a pre-trained tagging model when the access data is received, and to tag the access type, access frequency and access address of the access data according to the identification result.

[0074] In this embodiment, the data flow analysis module is used to classify and analyze the access type, access frequency and access address of each access data, and determine the data flow of key data in vehicle data based on location information.

[0075] In this embodiment, the data compliance analysis module is used to perform compliance analysis on vehicle data by combining the classification results of access data and vehicle data to determine whether a violation has occurred.

[0076] In this embodiment, the data processing module is used to store vehicle data in the vehicle's storage space and output violation events to the outside world.

[0077] In this embodiment, the data processing module includes a data storage unit, which is used to receive vehicle data from each branch node and store the vehicle data in a structured manner.

[0078] In this embodiment, both the branch node and the master node include a data decryption module, which is used to determine whether the vehicle data is encrypted data, and decrypt the vehicle data when the vehicle data is encrypted data.

[0079] In this embodiment, the master control node further includes: a first model training module, used to generate a data compliance model based on preset data compliance requirements and preset normal data range.

[0080] In this embodiment, the data compliance analysis module is specifically used to detect access data and vehicle data corresponding to different classification results based on the data compliance model, determine whether the vehicle data or access data violates compliance rules, and determine that a violation event has occurred when the vehicle data or access data violates compliance rules.

[0081] In this embodiment, the data processing module includes a data early warning unit, which is used to provide early warning reminders for violations. Based on the interface requirements of the preset monitoring platform, the module generates early warning information based on the violation and the corresponding vehicle data, and reports it to the preset monitoring platform.

[0082] In this embodiment, both the branch node and the master node include: a second model training module, used to acquire multiple sets of historical access data, classify the historical access data according to the data purpose, and obtain the access category, access frequency and access address of each set of historical access data; and construct and train a labeling model based on the historical access data and the access category, access frequency and access address of the historical access data.

[0083] like Figure 3As shown, this embodiment of the invention provides an electronic device, including a processor 1110, a communication interface 1120, a memory 1130, and a communication bus 1140, wherein the processor 1110, the communication interface 1120, and the memory 1130 communicate with each other through the communication bus 1140.

[0084] Memory 1130 is used to store computer programs;

[0085] When the processor 1110 executes the program stored in the memory 1130, it implements any of the above-described determination methods.

[0086] The electronic device provided in this embodiment of the invention includes a processor 1110 that executes a program stored in a memory 1130 to acquire vehicle data from different locations on the vehicle, classifies the vehicle data according to its purpose and adds location information; upon receiving access data, it identifies the access data based on a pre-trained labeling model, and labels the access type, access frequency, and access address of the access data according to the identification results; it performs classification analysis on the access type, access frequency, and access address of each access data, and determines the data flow of key data in the vehicle data based on the location information; it performs compliance analysis on the vehicle data by combining the classification results of the access data and the vehicle data to determine whether any violations have occurred; it stores the vehicle data in the vehicle's storage space and outputs the violation event to the outside world.

[0087] The communication bus 1140 mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus 1140 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, it is shown in the figure with only one thick line, but this does not indicate that there is only one bus or one type of bus.

[0088] The communication interface 1120 is used for communication between the above-mentioned electronic device and other devices.

[0089] The memory 1130 may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory 1130 may also be at least one storage device located remotely from the aforementioned processor 1110.

[0090] The processor 1110 mentioned above can be a general-purpose processor 1110, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0091] This invention provides a computer-readable storage medium storing one or more programs, which can be executed by one or more processors 1110 to implement the management method of any of the above embodiments.

[0092] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0093] Although the present disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.

Claims

1. A method for vehicle data security management, characterized in that, The management method includes: Vehicle data from different locations on the vehicle is acquired, and the vehicle data is categorized according to its purpose and location information is added. Upon receiving access data, the access data is identified based on a pre-trained labeling model, and the access type, access frequency, and access address of the access data are labeled according to the identification results. The access type, access frequency, and access address of each access data are classified and analyzed, and the data flow of key data in the vehicle data is determined based on the location information. The vehicle data is subjected to compliance analysis based on the classification results of the access data and the vehicle data to determine whether any violations have occurred. The vehicle data is stored in the vehicle's storage space, and the violation event is output to the outside world; The training method for the labeled model includes: Multiple sets of historical access data are obtained, and the historical access data are classified according to the data purpose to obtain the access category, access frequency and access address of each set of historical access data; The labeling model is constructed and trained based on historical access data and the access categories, access frequencies, and access addresses of the historical access data.

2. The management method according to claim 1, characterized in that, The acquisition of vehicle data at different locations on the vehicle includes: The vehicle is equipped with a main control node and branch nodes located at different positions. Both the master node and the branch node are used to acquire the vehicle data.

3. The management method according to claim 2, characterized in that, The step of storing the vehicle data in the vehicle's storage space includes: The master control node receives the vehicle data from each of the branch nodes and stores the vehicle data in a structured manner.

4. The management method according to claim 1, characterized in that, Before classifying the vehicle data according to its purpose and adding location information, the management method further includes: Determine whether the vehicle data is encrypted data. If the vehicle data is encrypted data, decrypt the vehicle data, classify it, and add location information.

5. The management method according to claim 1, characterized in that, The management method also includes: generating a data compliance model based on preset data compliance requirements and preset normal data ranges; The step of performing compliance analysis on the vehicle data by combining the classification results of the access data and the vehicle data to determine whether a violation event has occurred includes: detecting the access data and the vehicle data corresponding to different classification results according to the data compliance model, determining whether the vehicle data or access data violates compliance rules, and when the vehicle data or access data violates compliance rules, determining that a violation event has occurred and issuing an early warning.

6. The management method according to claim 5, characterized in that, The management method also includes: According to the interface requirements of the preset monitoring platform, an early warning message is generated based on the violation event and the corresponding vehicle data and reported to the preset monitoring platform.

7. A vehicle data security management system, characterized in that, The management system includes: The data acquisition module is used to acquire vehicle data from different locations on the vehicle. The data classification module is used to classify the vehicle data according to its purpose and add location information; The data tagging module is used to identify the access data based on a pre-trained tagging model when the access data is received, and to tag the access type, access frequency and access address of the access data according to the identification result; The data flow analysis module is used to classify and analyze the access type, access frequency and access address of each accessed data, and determine the data flow of key data in the vehicle data based on the location information. The data compliance analysis module is used to perform compliance analysis on the vehicle data by combining the classification results of the access data and the vehicle data, and to determine whether a violation event has occurred. The data processing module is used to store the vehicle data in the vehicle's storage space and output the violation event to the outside world; The second model training module is used to acquire multiple sets of historical access data, classify the historical access data according to the data purpose, and obtain the access category, access frequency and access address of each set of historical access data; based on the historical access data and the access category, access frequency and access address of the historical access data, a labeling model is constructed and trained.

8. An electronic device, characterized in that, include: processor; as well as A memory storing computer-executable instructions, which, when executed, cause the processor to perform the method according to any one of claims 1-6.

9. A computer storage medium, characterized in that, in, The computer storage medium stores one or more programs that, when executed by a processor, implement the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Network attack detection method and device

    CN111541687A

  • Automobile data processing method and device, electronic equipment and storage medium

    CN116662626A