A CAN bus safety task processing delay optimization method based on HSM module

By introducing a multi-core processing solution based on HSM module in the CAN bus system, dynamically adjusting task priorities and using the HSM core for encryption and decryption processing, the problem of CAN bus security task processing delay is solved, and the real-time performance and security of the system are improved.

CN119676025BActive Publication Date: 2025-05-06HEFEI UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510173575.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-06
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

In the prior art, there is a problem with the delay in the security task processing of the CAN bus, especially when large amounts of data are processed, the encryption and decryption operation may cause a delay of several milliseconds or even longer, affecting real-time performance.

Method used

The multi-core processing solution based on HSM module is adopted, and task priority is dynamically adjusted through Core1, and the HSM core is used for encryption, decryption and identity authentication processing, reducing the core burden of the ECU.

Benefits of technology

It effectively reduces the overall delay in handling safety tasks, improves processing efficiency, and avoids safety hazards caused by untimely processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119676025B_ABST
    Figure CN119676025B_ABST
Patent Text Reader

Abstract

The invention discloses a CAN bus security task processing delay optimization method based on an HSM module, and the CAN bus receiving data security processing process includes: Core0 merges MSG counts, bus receiving messages, etc. into a data packet and stores them in an input data storage area; Core1 reads the data packet through a shared memory, dynamically adjusts and updates the task priority according to the real-time parameters of the data packet; when a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core to process; the HSM core responds after receiving an interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing; the plain text and identity authentication code obtained through the shared memory are filled into the data packet, and the filled data packet is stored in the output data storage area; Core0 reads the data packet through the shared memory, uses the identity authentication code in the data packet for identity authentication, and stores and parses the message in the data packet after the authentication is completed. The invention improves the efficiency of security task processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle-mounted communication information security, and in particular to a CAN bus security task processing delay optimization method based on an HSM module. Background Art

[0002] CAN bus communication has the following defects because it did not consider information security issues at the beginning of its design: defects in arbitration mechanism, defects in broadcast transmission characteristics, lack of message inspection and authentication mechanism, lack of information security and encryption mechanism. It may be subject to malicious attacks such as theft, tampering, and replay.

[0003] A relatively effective method for CAN bus security protection is: identity authentication and encrypted communication.

[0004] Authentication: By authenticating the devices on the CAN bus, only authorized devices can participate in the communication. The advantage is that it can effectively prevent the intervention of unauthorized devices and improve the security of the system. The disadvantage is that the authentication process will increase communication delay and complexity.

[0005] Encrypted communication: Use encryption algorithms to encrypt communications on the CAN bus to ensure data confidentiality. The advantage is that it can effectively protect data security and prevent data from being tampered with or stolen. The disadvantage is that the encryption algorithm will increase the complexity and delay of communication, which may affect real-time performance.

[0006] Although simple information encryption and decryption and identity authentication mechanisms based on the software level can be implemented relatively easily without adding additional components, the ECU's core processing power is limited. When a large amount of data needs to be processed simultaneously, it will increase the delay and complexity of communication. Because the CAN bus is usually used for real-time control and communication, if a more complex encryption algorithm is used or the encryption key length is longer, the encryption and decryption time limit will increase accordingly, which may reach several milliseconds or even longer. In this case, the performance overhead of encryption and the impact on real-time communication need to be carefully evaluated to ensure that the encryption and decryption operations will not affect the real-time performance requirements.

[0007] Based on the above background, some manufacturers have proposed the HSM (Hardware Security Module) solution. HSM has an independent CPU dedicated to security task processing, protected memory, program code, data flash area, and hardware accelerators for AES and ECC, which can greatly improve the speed of identity authentication and data encryption and decryption. HSM and ECU are relatively independent and do not interfere with each other. HSM will only be enabled when ECU issues a security task processing request. ECU's data access to HSM is also limited. Important data is stored independently in the protected storage area of ​​HSM to ensure absolute data security. The functions of HSM usually include the following: key storage and management, generation of true random numbers, symmetric and asymmetric keys, etc., cryptographic calculation acceleration, signature generation and signature authentication, complete authentication and log tracking for multi-user permissions.

[0008] Secure processing of CAN bus data through the HSM module can protect the integrity, security authentication and timeliness of the signal in the body network with very little data overhead.

[0009] Currently, HSM performs security processing of CAN bus data in the order of message reception or transmission, and the next security task can only be processed after the current security task is completed.

[0010] Priority ceiling means raising the priority of a task that applies for (occupies) a resource to the highest priority of all tasks that may access the resource. This priority is called the priority ceiling of the resource.

[0011] The main purpose of the priority ceiling mechanism is to avoid conflicts when different tasks access the same resource at the same time, and to ensure that high-priority tasks can access resources first. When a task applies for a resource, if the priority of the task is lower than the priority ceiling of the resource, its priority will be temporarily raised to the priority ceiling of the resource to ensure that the high-priority task can access the resource in a timely manner.

[0012] When implementing a priority ceiling mechanism, a priority ceiling is usually set for the resource during the static resource allocation phase. When a task accesses the resource, the system checks the priority of the task. If the task's priority is lower than the resource's priority ceiling, its priority is temporarily raised to the resource's priority ceiling; if the task's priority is already higher than or equal to the resource's priority ceiling, it remains unchanged.

[0013] Advantages of priority ceiling: Ensuring timely execution of high-priority tasks: By increasing the priority of tasks, it can ensure that high-priority tasks can access resources in a timely manner, improving the response speed and efficiency of the system. The implementation of priority ceiling is relatively simple and does not require complex priority dynamic adjustment logic.

[0014] However, the task scheduling in the prior art basically adopts a static scheduling table for scheduling, and the parameters are fixed and cannot be updated in real time. Tasks with low priority but no response for a long time cannot be processed in time. Summary of the invention

[0015] The purpose of the present invention is to provide a CAN bus safety task processing delay optimization method based on an HSM module, which can solve the technical problems mentioned in the background technology.

[0016] Explanation of terms involved in the present invention:

[0017] HSM (Hardware Security Module): Used to generate, store and process vehicle security information (such as keys) and isolate attacks from external malware.

[0018] ECU (Electronic Control Unit): Electronic controller unit, also known as the car's "on-board computer", is used to control the car's driving status and realize its various functions.

[0019] Priority ceiling: refers to raising the priority of a task that applies for (occupies) a resource to the highest priority task among all tasks that may access the resource. This priority is called the priority ceiling of the resource.

[0020] CAN bus: CAN bus protocol (Controller Area Network), controller area network bus, is a serial communication protocol bus developed by BOSCH of Germany. It can use twisted pair cables to transmit signals and is one of the most widely used field buses in the world.

[0021] MSG count: The number of times the same message is repeatedly received or sent.

[0022] Main core: An ECU with an HSM module generally includes a main CPU and a CPU that comes with the HSM, which are called the main core and the HSM core. The HSM core is only used to process safety tasks, and the main core is responsible for other tasks.

[0023] Shared memory: refers to a large amount of memory that can be accessed by different central processing units (CPUs) in a multi-processor computer system.

[0024] Dflash: Data flash, usually FlexNVM, can be divided into EEPROM backup and Dataflash. If it is data flash, it can coexist with the main flash and can be erased and written when the main program memory is running. It can be used to store bootloader code or large data blocks.

[0025] Interrupt: An interrupt occurs when the CPU is processing an event and another external event (such as a change in voltage level, a pulse edge, a timer counter overflow, etc.) occurs, requesting the CPU to process it quickly. The CPU pauses the current program and processes what happened. After processing what happened, it returns to the originally paused program and continues the original work.

[0026] AES: AES (Advanced Encryption Standard) is a symmetric encryption algorithm that supports 128-bit, 192-bit, and 256-bit key lengths. For AES-128, the encryption process is divided into 10 rounds.

[0027] CMAC: CMAC (Cipher-based Message Authentication Code) is a message authentication code based on an encryption algorithm, usually used to ensure data integrity and authenticity. It uses a symmetric encryption algorithm (such as AES) to generate an authentication code for a message. Only two parties holding the same key can verify the authenticity of the message.

[0028] The present invention provides a method for optimizing the delay of CAN bus security task processing based on an HSM module, the method comprising a CAN bus receiving data security processing process and a CAN bus sending data security processing process, wherein the CAN bus receiving data security processing process comprises the following steps:

[0029] Step 101, open two 10KB fixed address memories in Dflash, one for secure processing input data storage, and the other for secure processing output data storage;

[0030] Step 102, Core0 combines the MSG count, bus received message, message receiving time, message cycle, encryption and decryption method, and task deadline into a data packet and stores it in the 10KB input data storage area at the fixed address in step 101. The data packet size is 512 bits.

[0031] Step 103, Core 1 reads the data packet in step 102 through the shared memory, dynamically adjusts and updates the task priority according to the real-time parameters of the data packet, and after the update, the task with the highest priority enters the ready queue;

[0032] Step 104: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core to process;

[0033] Step 105, the HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing, the processing process includes calculating the identity authentication code and decrypting the data according to the set encryption and decryption method;

[0034] Step 106, after the HSM completes the identity authentication and decryption of the data, it stores the plain text and the verified identity authentication code in the HSM core-specific shared storage area and generates an interrupt notification Core1 for processing;

[0035] Step 107, Core1 responds after receiving the interrupt from HSM, obtains the plain text and identity authentication code in step 106 through shared memory and fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 101, releases the memory of the input data storage area, clears the processed input data, and releases the memory from the low address after the memory of the output data storage area is fully occupied and overwrites it with new data;

[0036] Step 108, Core0 reads the data packet in the Dflash output data storage area in step 107 through the shared memory, uses the identity authentication code in the data packet to perform identity authentication, and after the authentication is completed, stores and parses the message in the data packet.

[0037] As a further technical solution of the present invention, the CAN bus sends data security processing process including:

[0038] Step 201, open two 10KB fixed address memories in Dflash, one for secure processing input data storage, and the other for secure processing output data storage;

[0039] Step 202, Core0 combines the MSG count, message cycle, encryption and decryption method, and task deadline into a data packet and stores it in the 10KB input data storage area at the fixed address in step 201. The data packet size is 512 bits.

[0040] Step 203, Core1 reads the data packet in step 202 through the shared memory, dynamically adjusts and updates the task priority according to the real-time parameters of the data packet, and after the update, the task with the highest priority enters the ready queue;

[0041] Step 204: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core to process;

[0042] Step 205, the HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing, the processing process includes generating an identity authentication code and encrypting the data according to the set encryption and decryption method;

[0043] Step 206, after the HSM completes the identity authentication and encryption of the data, it stores the ciphertext and the identity authentication code in the HSM core-specific shared storage area and generates an interrupt notification to Core1 for processing;

[0044] Step 207, Core1 responds after receiving the interrupt from HSM, obtains the ciphertext and identity authentication code in step 206 through shared memory and fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 201, releases the memory in the input data storage area, clears the processed input data, and releases the memory from the low address after all the memory in the output data storage area is occupied and overwrites it with new data;

[0045] Step 208, Core0 reads the data packet from the Dflash output data storage area in step 207 through the shared memory, and sends the ciphertext and identity authentication code in the data packet through the CAN bus.

[0046] As a further technical solution of the present invention, the task priority dynamic adjustment method includes:

[0047] Step 1: Initialization: Set the initial priority according to the message ID, encryption and decryption method, task deadline and sending cycle. Set the highest priority and the maximum tolerance value of the message, the polling number is 0, and the MSG count is 0.

[0048] Step 2: Perform fixed period query, i.e. polling, on the above data (priority, MSG count, and polling times in step 1), with a fixed 100μs period for polling, and set a counter to count the polling times;

[0049] Step 3: Check whether the MSG count increases. If it does, increase the initial priority to the highest priority set. If it does not, proceed to the next step.

[0050] Step 4: Check whether the MSG count reaches the maximum tolerance value for message sending. If it reaches the maximum tolerance value, send an abnormal warning. If not, proceed to the next step.

[0051] Step 5: Check whether the waiting time increase is greater than 50% of the task deadline. The waiting time is obtained by multiplying the polling cycle and the number of polling times. If it exceeds, the initial priority is increased to the set highest priority. If it does not exceed, proceed to the next step.

[0052] Step 6: Check whether the waiting time is greater than 90% of the deadline. If so, send an exception warning. If not, the priority remains unchanged.

[0053] Step 7: After completing the above check, the priority is updated, a polling cycle ends, and waits for 100 μs for the next polling.

[0054] Beneficial effects achieved by the present invention:

[0055] 1. Use the CPU with lower load rate in the multi-core chip to update the parameters related to the security task priority in real time, dynamically adjust the priority, and improve the efficiency of security task processing.

[0056] 2. Reduce the overall processing time of security tasks, avoid the impact of untimely processing of some security tasks on other security tasks, and thus avoid safety hazards caused by failure to complete security tasks within the specified time. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 This is a diagram of the secure processing process of received data according to an embodiment of the present invention.

[0058] Figure 2 This is a diagram of the secure processing process of sending data according to an embodiment of the present invention.

[0059] Figure 3 The following is a flowchart of the dynamic adjustment of priority according to an embodiment of the present invention. DETAILED DESCRIPTION

[0060] The technical solution of the present invention is described in detail below in conjunction with the specific drawings.

[0061] This embodiment provides a CAN bus security task processing delay optimization method based on the HSM module, the method includes a CAN bus receiving data security processing process and a CAN bus sending data security processing process, wherein, Figure 1 As shown, the CAN bus receiving data security processing process includes the following steps:

[0062] Step 101, open two 10KB fixed address memories in Dflash, one for secure processing input data storage (input data storage area), and the other for secure processing output data storage (output data storage area);

[0063] Step 102, Core0 combines the MSG count, bus received message, message receiving time, message cycle, encryption and decryption method, and task deadline into a data packet and stores it in the 10KB input data storage area at the fixed address in step 101. The data packet size is 512 bits.

[0064] Step 103, Core 1 reads the data packet in step 102 through the shared memory, and dynamically adjusts and updates the task priority according to the real-time parameters of the data packet. The priority dynamic adjustment method is as follows, see Figure 3 , after updating, the task with the highest priority is put into the ready queue;

[0065] Step 104: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core to process;

[0066] Step 105, the HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing, the processing process includes calculating the identity authentication code and decrypting the data according to the set encryption and decryption method;

[0067] Step 106, after the HSM completes the identity authentication and decryption of the data, it stores the plain text and the verified identity authentication code in the HSM core-specific shared storage area and generates an interrupt notification Core1 for processing;

[0068] Step 107, Core1 responds after receiving the interrupt from HSM, obtains the plain text and identity authentication code in step 106 through shared memory and fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 101, releases the memory of the input data storage area, clears the processed input data, and releases the memory from the low address after the memory of the output data storage area is fully occupied and overwrites it with new data;

[0069] Step 108, Core0 reads the data packet in the Dflash output data storage area in step 107 through the shared memory, uses the identity authentication code in the data packet to perform identity authentication, and after the authentication is completed, stores and parses the message in the data packet.

[0070] In this embodiment, Figure 2 As shown, the CAN bus data transmission security processing process includes:

[0071] Step 201, open two 10KB fixed address memories in Dflash, one for secure processing input data storage, and the other for secure processing output data storage;

[0072] Step 202, Core0 combines the MSG count, message cycle, encryption and decryption method, and task deadline into a data packet and stores it in the 10KB input data storage area at the fixed address in step 201. The data packet size is 512 bits.

[0073] Step 203: Core 1 reads the data packet in step 202 through the shared memory, and dynamically adjusts and updates the task priority according to the real-time parameters of the data packet. The priority dynamic adjustment method is shown in Figure 3 , after updating, the task with the highest priority is put into the ready queue;

[0074] Step 204: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core to process;

[0075] Step 205, the HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing, the processing process includes generating an identity authentication code and encrypting the data according to the set encryption and decryption method;

[0076] Step 206, after the HSM completes the identity authentication and encryption of the data, it stores the ciphertext and the identity authentication code in the HSM core-specific shared storage area and generates an interrupt notification to Core1 for processing;

[0077] Step 207, Core1 responds after receiving the interrupt from HSM, obtains the ciphertext and identity authentication code in step 206 through shared memory and fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 201, releases the memory in the input data storage area, clears the processed input data, and releases the memory from the low address after all the memory in the output data storage area is occupied and overwrites it with new data;

[0078] Step 208, Core0 reads the data packet from the Dflash output data storage area in step 207 through the shared memory, and sends the ciphertext and identity authentication code in the data packet through the CAN bus.

[0079] In this embodiment, Figure 3 As shown, the task priority dynamic adjustment method includes:

[0080] Step 1: Initialization: Set the initial priority according to the message ID, encryption and decryption method, task deadline and sending cycle. Set the highest priority and the maximum tolerance value of the message (the maximum number of repeated sending or receiving times of the message), the polling number is 0, and the MSG count is 0.

[0081] Step 2: Perform fixed period query, i.e. polling, on the above data (priority, MSG count, and polling times in step 1), with a fixed 100μs period for polling, and set a counter to count the polling times;

[0082] Step 3: Check whether the MSG count increases. If it does, increase the initial priority to the highest priority set. If it does not, proceed to the next step.

[0083] Step 4: Check whether the MSG count reaches the maximum tolerance value for message sending. If it reaches the maximum tolerance value, send an abnormal warning. If not, proceed to the next step.

[0084] Step 5: Check whether the waiting time increase is greater than 50% of the task deadline. The waiting time is obtained by multiplying the polling cycle and the number of polling times. If it exceeds, the initial priority is increased to the set highest priority. If it does not exceed, proceed to the next step.

[0085] Step 6: Check whether the waiting time is greater than 90% of the deadline. If so, send an exception warning. If not, the priority remains unchanged.

[0086] Step 7: After completing the above check, the priority is updated, a polling cycle ends, and waits for 100 μs for the next polling.

[0087] In order to facilitate those skilled in the art to better understand the technical solution of the present invention, specific embodiments of the present invention are given as follows:

[0088] CAN bus receiving data security processing example:

[0089] Step 1: Open two 10KB fixed address memories in Dflash, one for safe processing input data storage, the address starts from 0XAF010000, and the other for safe processing output data storage, the address starts from 0XAF0A0000.

[0090] Step 2, Core0 combines the MSG count (0), bus received message (0XABCD0101ABCD0101), message receiving time (10:10:10), message cycle (10ms), encryption and decryption method (AES), and task deadline (1ms) into a data packet and stores it in the 10KB input data storage area at the fixed address in step 1. The data packet size is 512 bits, and the storage address is 0XAF010000 followed by 512 bits.

[0091] Step 3: Core 1 reads the data packet in step 2 through the shared memory, and dynamically adjusts and updates the task priority according to the real-time parameters of the data packet. The method for dynamically adjusting the priority is as follows: Figure 3 , after updating, the task with the highest priority enters the ready queue.

[0092] Step 4: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core for processing.

[0093] Step 5. The HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing. The processing process includes calculating the identity authentication code and decrypting the data according to the set encryption and decryption method. The encryption and decryption method is AES. The decrypted data is 0X10203040 50607080. The identity authentication adopts CMAC. The calculated identity authentication code is 0X12345678 123456781 2345678 12345678.

[0094] Step 6: After the HSM completes the authentication and decryption of the data, it stores the plain text and the verified authentication code in a specific shared storage area of ​​the HSM core and generates an interrupt notification Core1 for processing. The storage address starts at 0XAFC10000.

[0095] Step 7, Core1 responds after receiving the interrupt from HSM, obtains the plain text and identity authentication code starting from address 0XAFC10000 in step 6 through shared memory, fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 1, the address is 0XAF0F0000, and releases the memory of the input data storage area, that is, clears the 512 bits of input data after address 0XAF010000, and after the memory of the output data storage area is fully occupied, releases the memory from the lower address and overwrites it with new data.

[0096] Step 8. Core0 reads the data packet in the Dflash output data storage area in step 7 through the shared memory, and uses the identity authentication code 0X12345678 12345678 12345678 12345678 in the data packet for identity authentication. After the authentication is completed, the message 0X10203040 50607080 in the data packet is stored and the data is parsed.

[0097] CAN bus sends data security processing process example:

[0098] Step 1: Open two 10KB fixed address memories in Dflash, one for safe processing input data storage, the address starts from 0XAF030000, and the other for safe processing output data storage, the address starts from 0XAF0C0000.

[0099] Step 2: Core0 combines the MSG count (0), message period (10ms), encryption and decryption method (AES), and task deadline (1ms) into a data packet and stores it in the 10KB input data storage area at the fixed address in step 1. The storage address is 0XAF030000, and the data packet size is 512 bits.

[0100] Step 3: Core1 reads the data packet in step 2 through shared memory, and dynamically adjusts and updates the task priority according to the real-time parameters of the data packet. The priority dynamic adjustment method is shown in Figure 3 , after updating, the task with the highest priority enters the ready queue.

[0101] Step 4: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core for processing.

[0102] Step 5. The HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing. The processing process includes generating an identity authentication code and encrypting the data according to the set encryption and decryption method. The identity authentication code is generated by CMAC method with a total of 128 bits, which is 0X12345678 12345678 1234567812345678. The encryption and decryption method is AES. The encrypted ciphertext is 0XABCD0101 ABCD0101.

[0103] Step 6: After the HSM completes the authentication and encryption of the data, it stores the ciphertext and the authentication code in a shared storage area specific to the HSM core and generates an interrupt notification Core1 for processing, the storage address is 0XAFC1A000.

[0104] Step 7, Core1 responds after receiving the interrupt from HSM, obtains the ciphertext and identity authentication code starting from address 0XAFC1A000 in step 6 through shared memory, fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 1, the address is 0XAF0C0000, and releases the memory of the input data storage area, clears the processed input data, that is, clears the 512 bits of input data after address 0XAF030000, and after the memory of the output data storage area is fully occupied, releases the memory from the lower address and overwrites it with new data.

[0105] Step 8. Core0 reads the data packet from the Dflash output data storage area in step 7 through the shared memory, and sends the ciphertext 0XABCD0101 ABCD0101 and the identity authentication code 0X12345678 12345678 1234567812345678 in the data packet through the CAN bus.

[0106] Priority dynamic adjustment method embodiment:

[0107] Step 1: Initialization. Set the initial priority according to the message ID, encryption and decryption method, task deadline and sending cycle. Set the highest priority and the maximum tolerance value of the message (the maximum number of repeated sending or receiving of the message), the polling number is 0, and the MSG count is 0. The message ID is 0X28, the encryption and decryption method is AES, the task deadline is 1ms, the sending cycle is 10ms, the initial priority is 3, the highest priority is 5, and the maximum tolerance value of message sending is 3.

[0108] Step 2: perform fixed period query, i.e., polling, on the above data, with a fixed 100 μs period for polling, and set a counter to count the number of polling times.

[0109] Step 3: Check whether the MSG count increases. If it increases, increase the initial priority to the highest priority set. If it does not increase, proceed to the next step. The MSG count is 1. The last polling MSG count was 1 and did not increase. Go to the next step.

[0110] Step 4: Check whether the MSG count has reached the maximum tolerance value for message sending. If it has, send an abnormal warning. If it has not, proceed to the next step. The MSG count is 1, and the maximum tolerance value for message sending is 3, so proceed to the next step.

[0111] Step 5. Check whether the increase in waiting time is greater than 50% of the task deadline. The waiting time is obtained by multiplying the polling cycle and the number of polls. If it exceeds, the initial priority is increased to the set highest priority. If it does not exceed, proceed to the next step. The number of polls is 6, and the waiting time is 6 x 100=600μs=0.6ms, which is greater than 50% of the task deadline, i.e. 0.5ms, and the priority is adjusted to 5.

[0112] Step 6: Check whether the waiting time is greater than 90% of the deadline. If so, send an exception warning. If not, the priority remains unchanged.

[0113] Step 7: After completing the above check, the priority is updated to 5. The task enters the ready queue and waits for HSM to perform security processing. After a polling cycle ends, wait for 100 μs for the next polling.

[0114] It should be noted that, in this article, the term "comprises" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of more restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0115] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A CAN bus safety task processing delay optimization method based on HSM module, characterized in that: The method includes a CAN bus receiving data security processing process and a CAN bus sending data security processing process, wherein the CAN bus receiving data security processing process includes the following steps: Step 101, open two 10KB fixed address memories in Dflash, one for secure processing input data storage, and the other for secure processing output data storage; Step 102, Core0 combines the MSG count, bus received message, message receiving time, message cycle, encryption and decryption method, and task deadline into a data packet and stores it in the 10KB input data storage area at the fixed address in step 101. The data packet size is 512 bits. Step 103, Core 1 reads the data packet in step 102 through the shared memory, dynamically adjusts and updates the task priority according to the real-time parameters of the data packet, and after the update, the task with the highest priority enters the ready queue; Step 104: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core to process; Step 105, the HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing, the processing process includes calculating the identity authentication code and decrypting the data according to the set encryption and decryption method; Step 106, after the HSM completes the identity authentication and decryption of the data, it stores the plain text and the verified identity authentication code in the HSM core-specific shared storage area and generates an interrupt notification Core1 for processing; Step 107, Core1 responds after receiving the interrupt from HSM, obtains the plain text and identity authentication code in step 106 through shared memory and fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 101, releases the memory of the input data storage area, clears the processed input data, and releases the memory from the low address after the memory of the output data storage area is fully occupied and overwrites it with new data; Step 108, Core0 reads the data packet in the Dflash output data storage area in step 107 through the shared memory, uses the identity authentication code in the data packet to perform identity authentication, and after the authentication is completed, stores and parses the message in the data packet.

2. According to a CAN bus safety task processing delay optimization method based on the HSM module according to claim 1, it is characterized in that: The CAN bus sends data security processing process includes: Step 201, open two 10KB fixed address memories in Dflash, one for secure processing input data storage, and the other for secure processing output data storage; Step 202, Core0 combines the MSG count, message cycle, encryption and decryption method, and task deadline into a data packet and stores it in the 10KB input data storage area at the fixed address in step 201. The data packet size is 512 bits. Step 203, Core1 reads the data packet in step 202 through the shared memory, dynamically adjusts and updates the task priority according to the real-time parameters of the data packet, and after the update, the task with the highest priority enters the ready queue; Step 204: When a new task appears in the Core1 ready queue, an interrupt is generated to notify the HSM core to process; Step 205, the HSM core responds after receiving the interrupt from Core1, obtains the updated data packet of Core1 through the shared memory and performs security processing, the processing process includes generating an identity authentication code and encrypting the data according to the set encryption and decryption method; Step 206, after the HSM completes the identity authentication and encryption of the data, it stores the ciphertext and the identity authentication code in the HSM core-specific shared storage area and generates an interrupt notification to Core1 for processing; Step 207, Core1 responds after receiving the interrupt from HSM, obtains the ciphertext and identity authentication code in step 206 through shared memory and fills them into the data packet, stores the filled data packet in the Dflash output data storage area in step 201, releases the memory in the input data storage area, clears the processed input data, and releases the memory from the low address after all the memory in the output data storage area is occupied and overwrites it with new data; Step 208, Core0 reads the data packet from the Dflash output data storage area in step 207 through the shared memory, and sends the ciphertext and identity authentication code in the data packet through the CAN bus.

3. A CAN bus safety task processing delay optimization method based on HSM module according to claim 2, characterized in that: The task priority dynamic adjustment method comprises: Step 1: Initialization: Set the initial priority according to the message ID, encryption and decryption method, task deadline and sending cycle. Set the highest priority and the maximum tolerance value of the message, the polling number is 0, and the MSG count is 0. Step 2: Perform fixed period query, i.e. polling, on the priority, MSG count and polling times in step 1, with a fixed 100 μs period for polling, and set a counter to count the polling times; Step 3: Check whether the MSG count increases. If it does, increase the initial priority to the highest priority set. If it does not, proceed to the next step. Step 4: Check whether the MSG count reaches the maximum tolerance value for message sending. If it reaches the maximum tolerance value, send an abnormal warning. If not, proceed to the next step. Step 5: Check whether the waiting time increase is greater than 50% of the task deadline. The waiting time is obtained by multiplying the polling cycle and the number of polling times. If it exceeds, the initial priority is increased to the set highest priority. If it does not exceed, proceed to the next step. Step 6: Check whether the waiting time is greater than 90% of the deadline. If so, send an exception warning. If not, the priority remains unchanged. Step 7: After the check is completed, the priority is updated, a polling cycle ends, and the next polling is performed after waiting for 100 μs.

Citation Information

Patent Citations

  • Vehicle CAN bus encryption method

    CN109495449A

  • CAN bus safety communication real-time monitoring method and system based on HSM module

    CN118337528A