Vehicle communication method, vehicle communication device, and vehicle
By introducing target components into the vehicle to perform security verification on the brake system messages, the problem of the vehicle's host being unable to effectively verify the electronic stability system and integrated brake control system messages is solved, the safety and verification efficiency of the brake system signals are improved, and the safe operation of the vehicle is ensured.
Patent Information
- Application Number
- CN202411911734.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-12-24
AI Technical Summary
In the prior art, the vehicle-mounted host cannot perform effective security verification on the messages of the electronic stability system and the integrated brake control system, resulting in abnormal braking function.
The target component is introduced into the vehicle, which receives the message sent by the braking system and performs a security check based on the target function signal and the candidate check field. After the verification is successful, the target function signal is sent to the vehicle host.
The safety and verification efficiency of the brake system signal are improved, the abnormal braking function caused by the incorrect verification of the vehicle host is avoided, and the safe operation of the vehicle is ensured.
Smart Images

Figure CN119814417B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of vehicles, and more particularly, to a vehicle communication method, a vehicle communication device and a vehicle. BACKGROUND
[0002] With the gradual popularity of automobile networking, the safety of vehicle communication is also paid more and more attention. However, in the current vehicle network, most of the data transmission is carried out without any security measures, and the trustworthiness of the sending node cannot be checked. Therefore, as a safe and reliable encryption communication scheme, secure on board communication (SecOC) has been included in the vehicle safety communication standard to ensure the safety of vehicle communication.
[0003] Electronic stability system and integrated brake control system are different types of vehicle braking systems. In the signal security verification process, the electronic stability system cannot be adapted to the SecOC verification mode due to the lower configuration, which may cause unexpected verification failure, and further may cause abnormal braking function of the vehicle.
[0004] Therefore, how to avoid the abnormal function of the braking system caused by the error verification of the vehicle host to the message is a problem to be solved. SUMMARY
[0005] The present application provides a vehicle communication method, a vehicle communication device and a vehicle, which can avoid the abnormal function of the braking system caused by the error verification of the vehicle host to the message.
[0006] In a first aspect, a vehicle communication method is provided, the method being applied to a target component, and the method comprises:
[0007] receiving a target message sent by a braking system in a vehicle, wherein the target message comprises a target function signal and a candidate verification field;
[0008] verifying the target message based on the target function signal and the candidate verification field;
[0009] if the target message is verified successfully, sending the target function signal to a vehicle host, so that the vehicle host verifies the target function signal.
[0010] In the technical solution, the target component receives a target message sent by the braking system, performs security verification on the target message according to a target function signal in the target message and a candidate verification field, and sends the target function signal in the target message to the vehicle-mounted host computer when the target message is verified successfully, so that the vehicle-mounted host computer verifies the target function signal. Through twice verification of the target component and the vehicle-mounted host computer, the security of the signal sent by the braking system can be ensured. In addition, compared with the prior art in which all messages are verified by the vehicle-mounted host computer, in the present solution, the target function signal in the target message that is verified successfully is forwarded to the vehicle-mounted host computer, so that the normal function signal is screened, the workload of the vehicle-mounted host computer is reduced, and the security verification efficiency is improved.
[0011] With reference to the first aspect, in some possible implementation manners, when the braking system is an electronic stability system, the candidate verification field is a first hash field.
[0012] The verification on the target message based on the target function signal and the candidate verification field includes:
[0013] The second hash field is obtained based on the target function signal and a hash algorithm.
[0014] The target message is verified based on the first hash field and the second hash field.
[0015] In the technical solution, when the braking system is an electronic stability system, the target component obtains a second hash field based on a function signal and a hash algorithm, and compares the second hash field with a first hash field in the target message, to implement security verification on the target message. The determinacy and collision resistance of the hash algorithm make the generated hash value different as long as the function signal changes slightly. The target component can determine whether the function signal maintains the original integrity by comparing the two hash fields, so as to ensure that the function signal sent by the braking system is a real and reliable signal, and to ensure the safe execution of the vehicle braking function.
[0016] With reference to the first aspect and the implementation manners, in some possible implementation manners, the verification on the target message based on the first hash field and the second hash field includes:
[0017] If the first hash field and the second hash field are consistent, it is determined that the target message is verified successfully.
[0018] If the first hash field and the second hash field are inconsistent, it is determined that the target message is verified unsuccessfully.
[0019] In the technical solution, when the first hash field in the target message is consistent with the second hash field calculated by the target component, it is determined that the target message is verified successfully; when the first hash field is not consistent with the second hash field, it is determined that the target message is verified unsuccessfully. By comparing the first hash field in the target message with the second hash field calculated by the target component, it is determined whether the target message is verified successfully, thereby improving the accuracy of safety verification of the related data of the vehicle braking system and providing reliable data basis for safe operation of the vehicle.
[0020] With reference to the first aspect and the above implementation manners, in some possible implementation manners, when the braking system is an integrated brake control system, the candidate verification field is a first communication verification field.
[0021] Based on the target function signal and the candidate verification field, the target message is verified, including:
[0022] Based on the target function signal and the target algorithm, a second communication verification field is obtained, wherein the target algorithm is an algorithm corresponding to safety vehicle-mounted communication verification.
[0023] Based on the first communication verification field and the second communication verification field, the target message is verified.
[0024] In the technical solution, when the braking system of the vehicle is an integrated brake control system, the target component calculates a second communication verification field according to the target function signal in the target message by using a target algorithm. The target message is verified by comparing the first communication verification field with the second communication verification field. The accuracy of verification of whether the message is tampered during transmission can be ensured, the integrity and authenticity of the related instructions and data of the integrated brake control system can be ensured, and the safety verification efficiency and accuracy of the message can be improved.
[0025] With reference to the first aspect and the above implementation manners, in some possible implementation manners, based on the first communication verification field and the second communication verification field, the target message is verified, including:
[0026] If the first communication verification field is consistent with the second communication verification field, it is determined that the target message is verified successfully.
[0027] If the first communication verification field is not consistent with the second communication verification field, it is determined that the target message is verified unsuccessfully.
[0028] In the technical solution, when the first communication check field in the target message is consistent with the second communication check field calculated by the target component, it is determined that the target message check is successful; when the first communication check field is inconsistent with the second communication check field, it is determined that the target message check fails. By comparing whether the first communication check field in the target message is consistent with the second communication check field calculated by the target component, it is determined whether the target message check is successful, the accuracy of safety check of vehicle braking system related data is improved, a reliable data basis for safe operation of the vehicle is provided, and vehicle braking control failure caused by abnormal message signal transmission is avoided, and driving safety is affected.
[0029] In a second aspect, a vehicle communication method is provided, which is applied to a vehicle gateway, and the method comprises the following steps:
[0030] Receiving a target function signal sent by a target component in a vehicle, wherein the target component is configured to check a target message sent by a braking system;
[0031] Generating a target check field based on the target function signal;
[0032] Sending the target function signal and the target check field corresponding to the target function signal to a vehicle host, so that the vehicle host checks the target function signal based on the target check field.
[0033] In the technical solution, after receiving the target function signal sent by the target component, the vehicle gateway calculates the corresponding target check field according to the target function signal, and synchronously sends the target function signal and the target check field to the vehicle host for safety check. The target check field is added to the target function signal by the vehicle gateway, which avoids the situation that the safety check required field does not exist in the signal sent to the vehicle host, causing the signal sent by the braking system to the vehicle host to fail, and further causing the braking system to be abnormal. The safety of signal transmission between the braking system and the vehicle host is further ensured. In addition, the first safety check is performed by the target component, and the vehicle gateway only needs to complete the calculation and transmission of the check field, which can reduce the software modification of the vehicle gateway, avoid unnecessary software vulnerabilities, and further improve the processing efficiency of safety check.
[0034] In combination with the second aspect, in some possible implementation manners, the target check field is generated based on the target function signal, and the method comprises the following steps:
[0035] The target check field is generated based on the target function signal and a target algorithm, wherein the target algorithm is an algorithm corresponding to a safe vehicle communication check.
[0036] In the technical solution, the corresponding algorithm of the secure vehicle-mounted communication verification is used to calculate the corresponding target verification field according to the target function signal sent by the target component, so as to ensure that the target verification field can reflect the relevant transmission information of the target function signal. Since the vehicle-mounted host computer performs secure vehicle-mounted communication verification on the signal, the signal sent by the vehicle-mounted communication device includes the field required for verification, so that the failure of the verification due to the absence of the corresponding field in the signal is avoided, and the normal use of the braking function is affected.
[0037] In a third aspect, a vehicle communication device is provided, and the device comprises:
[0038] A first receiving module is configured to receive a target message sent by a braking system in a vehicle, wherein the target message comprises a target function signal and a candidate verification field.
[0039] A verification module is configured to verify the target message based on the target function signal and the candidate verification field.
[0040] A first sending module is configured to send the target function signal to a vehicle-mounted host computer if the target message is verified successfully, so that the vehicle-mounted host computer verifies the target function signal.
[0041] In combination with the third aspect, in some possible implementation manners, when the braking system is an electronic stability system, the candidate verification field is a first hash field; the verification module is further configured to obtain a second hash field based on the target function signal and a hash algorithm; and the target message is verified based on the first hash field and the second hash field.
[0042] In combination with the third aspect and the above implementation manners, in some possible implementation manners, the verification module is further configured to determine that the target message is verified successfully if the first hash field and the second hash field are consistent; and determine that the target message is verified unsuccessfully if the first hash field and the second hash field are inconsistent.
[0043] In combination with the third aspect and the above implementation manners, in some possible implementation manners, when the braking system is an integrated brake control system, the candidate verification field is a first communication verification field; the verification module is further configured to obtain a second communication verification field based on the target function signal and a target algorithm, wherein the target algorithm is a corresponding algorithm of secure vehicle-mounted communication verification; and the target message is verified based on the first communication verification field and the second communication verification field.
[0044] In combination with the third aspect and the above implementation manners, in some possible implementation manners, the verification module is further configured to determine that the target message is verified successfully if the first communication verification field and the second communication verification field are consistent; and determine that the target message is verified unsuccessfully if the first communication verification field and the second communication verification field are inconsistent.
[0045] In a fourth aspect, a vehicle communication device is provided, and the device comprises:
[0046] A second receiving module is configured to receive a target function signal sent by a target component in the vehicle, wherein the target component is configured to check a target message sent by the brake system;
[0047] A generating module is configured to generate a target check field based on the target function signal;
[0048] A second sending module is configured to send the target function signal and the target check field corresponding to the target function signal to a vehicle host, so that the vehicle host checks the target function signal based on the target check field.
[0049] In combination with the fourth aspect and the above implementation manners, in some possible implementation manners, the generating module is specifically configured to generate the target check field based on the target function signal and a target algorithm, wherein the target algorithm is an algorithm corresponding to the safety vehicle communication check.
[0050] In a fifth aspect, a vehicle is provided, comprising a memory and a processor. The memory is configured to store executable program code, and the processor is configured to call and run the executable program code from the memory, so that the vehicle executes the method in the first aspect or any one of the possible implementation manners of the first aspect.
[0051] In a sixth aspect, a computer program product is provided, and the computer program product comprises computer program code. When the computer program code is run on a computer, the computer program code causes the computer to execute the method in the first aspect or any one of the possible implementation manners of the first aspect.
[0052] In a seventh aspect, a computer readable storage medium is provided, and the computer readable storage medium stores computer program code. When the computer program code is run on a computer, the computer program code causes the computer to execute the method in the first aspect or any one of the possible implementation manners of the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0053] Figure 1 is a schematic diagram of a vehicle system architecture provided by an embodiment of the present application;
[0054] Figure 2 is a schematic diagram of another vehicle system architecture provided by an embodiment of the present application;
[0055] Figure 3 is a schematic flowchart of a vehicle communication method provided by an embodiment of the present application;
[0056] Figure 4 is a schematic flowchart of another vehicle communication method provided by an embodiment of the present application;
[0057] Figure 5 is a schematic flowchart of another vehicle communication method provided by an embodiment of the present application;
[0058] Figure 6 is a structural schematic diagram of a vehicle communication device provided by an embodiment of the present application;
[0059] Figure 7 is a structural schematic diagram of another vehicle communication device provided by an embodiment of the present application;
[0060] Figure 8 is a structural schematic diagram of a vehicle provided by an embodiment of the present application. DETAILED DESCRIPTION
[0061] The technical solutions in the present application will be described in detail below with reference to the drawings. In the description of the embodiments of the present application, unless otherwise specified, “ / ” represents or, for example, A / B can represent A or B: “and / or” in the text only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist together, and B exists alone, and in addition, in the description of the embodiments of the present application, “multiple” means two or more than two.
[0062] Hereinafter, the terms “first” and “second” are only used for descriptive purposes, and cannot be understood as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with “first” and “second” can explicitly or implicitly include one or more of the features.
[0063] With the rapid development of science and technology, the automobile industry is undergoing a huge transformation from traditional mechanical transportation tools to intelligent mobile terminals. Modern cars are equipped with a large number of electronic control units (ECU), which control various functions of the vehicle, such as engine management, braking system, vehicle body stability system, etc. At the same time, the connection between the vehicle and the external network is becoming closer and closer, for example, the Internet of Vehicles technology enables vehicles to realize remote information processing, real-time traffic information acquisition, online software upgrade, etc.
[0064] The network architecture inside a vehicle becomes increasingly complex, and multiple communication protocols such as CAN (Controller Area Network), LIN (Local Interconnect Network), Ethernet, etc. are used simultaneously. Different ECUs communicate with each other through these protocols, and in intelligent connected vehicles, the vehicle internal network also needs to interact with external networks (such as 4G / 5G networks). Taking the CAN bus as an example, it is a widely used communication protocol inside a vehicle, used to connect key ECUs such as power systems and chassis systems. In traditional vehicles, the CAN bus mainly focuses on internal communication efficiency, but in a connected environment, it can become an entry point for network attacks.
[0065] Therefore, in the communication security verification process of the vehicle, a new verification method - Secure On-Board Communication (SecOC) is proposed. SecOC is a standard secure communication module that uses Freshness value and CMAC for verification of whether the message is correct and tampered with during transmission. Freshness value and CMAC together ensure the security of vehicle CAN communication, and are usually applied to messages containing high-risk and important function signals.
[0066] Figure 1 is a schematic diagram of a vehicle system architecture provided by an embodiment of the present application. As shown in Figure 1 In the prior art, during the operation of the vehicle, messages are transmitted between the braking system 101, the vehicle gateway (Gate Way, GW) 102 and the vehicle host (Head Unit, HUT) 103 in the vehicle. The vehicle braking system 101 can include an integrated brake control system (Integrated Brake Control, IBC) and an electronic stability system (Electronic Stability Program, ESP).
[0067] Suppose the HUT needs to send a message to the IBC; since the message is composed of many signals, in order to detect whether the message or the signals in the message sent by the HUT to the IBC has been tampered with or attacked, before the message is transmitted, the HUT will calculate an additional value based on the value of the message and send it to the IBC, this additional value is called Cipher-based Message Authentication Code (CMAC). After receiving the message, the IBC calculates the additional value using the same algorithm, and compares the calculated CMAC with the CMAC sent by the HUT. If they are consistent, it means that this frame of message has not been tampered with.
[0068] Freshness value is used to detect whether the received message is the latest message; that is, to detect whether there is a card stagnation in the message transmission process. SecOC communication is a master-slave architecture, and the vehicle gateway is usually used as the master node. The vehicle gateway will synchronize the same freshness value to all slave nodes at regular intervals. If HUT wants to send a message to IBC, it needs to check the CMAC value and the Freshness value. For example, the first frame of HUT has a freshness value of 1, and IBC will store the freshness value 1 after receiving it. The second time the freshness value is 3, and IBC will update the freshness value 1 to the freshness value 3 after receiving it. The freshness value does not necessarily increase in an arithmetic sequence, and it may be 1.3.4.6.7, etc. There may be no logical relationship between adjacent freshness values, but the freshness value of the next frame must be greater than that of the previous frame. If the local IBC stores the freshness value 3, the next time HUT sends the freshness value 2, it means that the message may have card stagnation during transmission, that is, the frame of the message is not fresh.
[0069] In the CMAC and Freshness value verification process, the signal may be stuck during transmission. To be redundant, the number of verifications can be set. For example, if the CMAC is inconsistent for five times, it is determined to be an error; if the freshness value is determined to be not fresh for five times, it is determined to be an error.
[0070] The configuration of the brake system in vehicles of different configuration levels is different. Low-configuration vehicles may be equipped with ESP, while high-configuration vehicles may be equipped with more advanced IBC. In the existing message signal verification process, the CMAC value and the freshness value generated by SecOC verification are attached to the message in the form of CAN signal. The CMAC value occupies 6 bytes, and the freshness value occupies 2 bytes. The data frame payload of the traditional CAN is usually 8 bytes, and if there is a function signal in the CAN message signal, it cannot carry the bytes occupied by the CMAC value and the freshness value, which will cause the message signal to be unable to perform SecOC verification.
[0071] For the vehicle configured with ESP, since ESP uses common CAN signal in signal transmission process, the message sent by ESP to GW does not contain the fields required for SecOC verification (such as CMAC value and freshness value); therefore, GW does not verify the message sent by ESP, and only routes the message to HUT; at this time, the message signal still does not contain the fields required for SecOC verification, which causes HUT to be unable to perform SecOC verification on the message, and thus causes HUT verification failure; then the frame message is discarded, and the result of function abnormality is output. However, the result may not be caused by function signal abnormality, so there is error verification in the verification process, which causes function abnormality.
[0072] For the vehicle configured with IBC, since IBC uses the communication protocol developed on the basis of traditional CAN bus, i.e. CANFD (Controller Area Network Flexible Data-rate) signal in signal transmission process, the data frame payload of CANFD can reach 64 bytes or more, therefore, the message sent by IBC can contain the fields required for SecOC verification; GW routes it to HUT, and HUT can perform SecOC verification on the message according to the fields in the message.
[0073] In summary, the vehicle gateway in the prior art is only used to route the message sent by the brake system to the vehicle host, and in this process, the message is not verified for security, and the security of the message cannot be guaranteed; and different message signals sent by different brake systems cannot be uniformly verified, and in the process of SecOC verification by the vehicle host, there may be a problem that the function signal is a correct signal, but the security verification is incorrect due to the absence of the required verification fields, and thus the brake function is abnormal.
[0074] In view of the problems in the prior art described above, the present application provides a vehicle communication method, a vehicle communication device and a vehicle, which are applied to a target component; after receiving the target message sent by the brake system, the target component verifies the target message according to the target function signal and the candidate verification field in the target message; if the target message verification is successful, the target function signal is forwarded to the vehicle host for security verification, so as to avoid the problem of brake function abnormality caused by error verification of the vehicle host on the message.
[0075] Figure 2 FIG. 2 is a schematic diagram of another vehicle system architecture provided by an embodiment of the present application; as shown in FIG. 2, the vehicle system architecture provided by the embodiment of the present application comprises a brake system, a vehicle gateway (GW), a target component and a vehicle host (HUT). Figure 2As shown, the scheme adds a safety middleware-target component 201 between the brake system 101 and the vehicle gateway 102; and the transmission process of the message signal includes that the brake system 101 of the vehicle sends a target message to the target component 201, the target component 201 performs safety verification on the target message; if the safety verification is successful, a target function signal is sent to the vehicle gateway 102; the vehicle gateway 102 calculates a corresponding target verification field according to the target function signal, and synchronously sends the target function signal and the target verification field to the vehicle host 103 for safety verification.
[0076] The following will be described in detail Figures 3 to 5 The vehicle communication method provided by the embodiment of the present application is described in detail.
[0077] Figure 3 The vehicle communication method provided by the embodiment of the present application is described in detail.
[0078] Exemplarily, as Figure 3 As shown, the method 300 includes the following steps S301 to S303.
[0079] S301, receiving a target message sent by a brake system in a vehicle, wherein the target message includes a target function signal and a candidate verification field.
[0080] Exemplarily, the message sent by the brake system needs to be verified by the target component for safety, and then it is determined whether the message is continuously sent to the vehicle gateway, the vehicle host and other modules; the target component receives the target message sent by the brake system in real time, which includes the target function signal and the candidate verification field.
[0081] The composition of the target message can include an identifier (Identifier, ID) and a data part of the message; the ID can be used to distinguish different types of messages, so that the target component and other system modules can quickly identify the source of the message; the data part can include the target function signal and the candidate verification field, and the target component and other system modules can identify the purpose of the message according to the function signal.
[0082] Exemplarily, the ID of the target message is 0x137 ESP, and the target component can determine that the target message is the message sent by ESP according to the ID.
[0083] Optionally, the target component can also be called a safety gateway (Safe Gate Way, SGW) and a safety middleware, etc.; the naming of the target component is not limited in the embodiment of the present application.
[0084] For example, the target function signal can include a brake pressure value signal, a brake mode signal, a brake component state signal, etc. The brake system can convert the pressure value in the brake pipeline into a digital code, which can be reflected in the message.
[0085] The brake system also includes various modes, such as a normal mode, an emergency brake, an anti-lock braking system (ABS) mode, and an electric parking brake (EPB) mode. Corresponding codes can be used in the message data field to reflect these modes. For example, a byte can be used to represent the normal brake (00), the emergency brake (01), the ABS mode (10), and the EPB mode (11). When the brake system enters a specific mode, the corresponding byte in the message data field can be updated to send the corresponding mode code to the target component or other system module.
[0086] The brake system also includes various components, such as brake pads, brake discs, brake pumps, etc. The state of these components can also be reflected in the message. For example, for the brake pad wear state, a byte can be used to represent it. If the value of the byte is 0-3, it indicates that the brake pad thickness is normal, 4-6 indicates that the brake pad is about to wear to the limit, and 7 indicates that the brake pad has worn to the limit and needs to be replaced. Through this coding method, the brake system can timely transmit component state information to other systems (such as a vehicle gateway).
[0087] Optionally, the brake system can include an electronic stability system (ESP) or an integrated brake control system (IBC).
[0088] It should be understood that when the brake system configured in the vehicle is different, the target message received by the target component will also be different; for example, the target message also includes a configuration field, which can be used to indicate the type of brake system, and the target component can determine the type of corresponding brake system according to the configuration field in the target message.
[0089] For example, the configuration field corresponding to the ESP is defined as EAA01, and the configuration field of the IBC is EAA02. The configuration field is stored in the target message. When the target component obtains the configuration field EAA01 in the target message, it can be determined that the vehicle is configured with the ESP, and the target message is sent by the ESP; when the target component obtains the configuration field EAA02 in the target message, it can be determined that the vehicle is configured with the IBC, and the target message is sent by the IBC.
[0090] S302, verifying the target message based on the target function signal and the candidate check field.
[0091] Exemplarily, after receiving the target message sent by the brake system, the target component can perform security check on the target message according to the target function signal and the candidate check field in the target message, to determine whether there is transmission anomaly in the transmission procedure of the target message, such as data tampering or transmission lag.
[0092] Since different brake systems have different configurations, the types of the candidate check fields contained in the target messages sent by different brake systems are different, and in the security check process, a check algorithm matched with the brake system also needs to be used for security check.
[0093] Optionally, the check algorithm corresponding to the configuration field can be determined according to the configuration field in the target message.
[0094] Exemplarily, it is defined in advance that the configuration field corresponding to ESP is EAA01, and the configuration field corresponding to IBC is EAA02. When the configuration field is EAA01, the corresponding brake system is ESP, and it is determined that the check algorithm corresponding to the configuration field is the hash algorithm; when the configuration field is EAA02, the corresponding brake system is IBC, and it is determined that the check algorithm corresponding to the configuration field is the target algorithm, that is, the algorithm corresponding to the security vehicle-mounted communication check.
[0095] The hash algorithm (Hash Algorithm) is also called a hash algorithm, which is a function that can map data of an arbitrary length to a fixed length of shorter data (hash value). The fixed length of the hash value is usually a number or a string, for example, the output of the common hash algorithm may be binary data of 128 bits, 256 bits, etc., which is converted into hexadecimal representation.
[0096] The security vehicle-mounted communication (SecOC) check is a check method for determining whether the message signal is abnormal by comparing the freshness value and the CMAC value.
[0097] In an implementation manner, when the brake system is an electronic stability system, the candidate check field is a first hash field; the process of performing check on the target message based on the target function signal and the candidate check field can include: obtaining a second hash field based on the target function signal and the hash algorithm; and performing check on the target message based on the first hash field and the second hash field.
[0098] Exemplarily, since the electronic stability system is configured to be low, it cannot adapt to the SecOC verification mode, but in order to ensure the safety of signal transmission between the electronic stability system and the target component and the subsequent module, a hash algorithm can be used for security verification. Correspondingly, the electronic stability system in the vehicle needs to calculate a first hash field according to the target function signal by using a hash algorithm; and generate a target message based on the first hash field and the target function signal and send it to the target component. After the target component obtains the target message containing the target function signal and the first hash field, it first calculates a second hash field according to the target function signal by using a hash algorithm; and then compares the first hash field and the second hash field to determine whether the target message is verified successfully, that is, whether the data in the target message is abnormal.
[0099] In the embodiment of the application, when the braking system is an electronic stability system, the target component compares the second hash field calculated according to the function signal and the hash algorithm with the first hash field in the target message to realize security verification of the target message. The determinacy and collision resistance of the hash algorithm make the generated hash value different as long as the function signal changes slightly. By comparing the two hash fields, the target component can determine whether the function signal maintains the original integrity, thereby ensuring that the function signal sent by the braking system is a real and reliable signal to ensure the safe execution of the vehicle braking function.
[0100] In an implementation manner, the process of verifying the target message based on the first hash field and the second hash field can specifically include: if the first hash field and the second hash field are consistent, it is determined that the target message is verified successfully; and if the first hash field and the second hash field are inconsistent, it is determined that the target message is verified unsuccessfully.
[0101] Exemplarily, assuming that the first hash field in the target message obtained by the target component is 3, if the second hash field calculated according to the function signal in the target message is also 3 and consistent with the first hash field, it can be determined that the target message is verified successfully, and the data information contained therein does not have abnormal conditions such as tampering; if the second hash field calculated by the target component according to the function signal in the target message is 7 and different from the first hash field 3, it can be determined that the target message is verified unsuccessfully, indicating that the target message may have transmission abnormalities in the transmission process.
[0102] Optionally, a preset number of times, for example, 5 times, is set. The target message is verified 5 times, and if the 5 times of verification all indicate that the first hash field and the second hash field are inconsistent, it is determined that the target message is verified unsuccessfully.
[0103] In the embodiment of the present application, when the first hash field in the target message and the second hash field calculated by the target component are consistent, it is determined that the target message is verified successfully; when the first hash field and the second hash field are inconsistent, it is determined that the target message is verified unsuccessfully. By comparing whether the first hash field in the target message and the second hash field calculated by the target component are consistent, it is determined whether the target message is verified successfully, the accuracy of safety verification of the related data of the vehicle braking system is improved, and reliable data basis is provided for safe operation of the vehicle.
[0104] In an implementation manner, when the braking system is an integrated brake control system, the candidate verification field is a first communication verification field; and the process of verifying the target message based on the target function signal and the candidate verification field can include: obtaining a second communication verification field based on the target function signal and a target algorithm, wherein the target algorithm is an algorithm corresponding to safety vehicle-mounted communication verification; and verifying the target message based on the first communication verification field and the second communication verification field.
[0105] For example, when the braking system is an IBC, the target algorithm (an algorithm corresponding to SecOC verification) is used for safety verification; accordingly, in the process of signal processing, the IBC calculates a first communication verification field according to the function signal, and the first communication verification field and the function signal are sent to the target component at the same time; after receiving the target message, the target component calculates a second communication verification field according to the function signal in the target message by using the target algorithm; and then the target message can be verified by comparing the first communication verification field and the second communication verification field, to determine whether the target message is tampered with or has other abnormal conditions in the transmission process.
[0106] In the embodiment of the present application, when the braking system of the vehicle is an integrated brake control system, the target component calculates a second communication verification field according to the target function signal in the target message by using the target algorithm; and the target message is verified by comparing the first communication verification field and the second communication verification field. The message can be accurately verified whether it is tampered with in the transmission process, the integrity and authenticity of the instructions and data related to the integrated brake control system are ensured, and the safety verification efficiency and verification accuracy of the message are improved.
[0107] In an implementation manner, the process of verifying the target message based on the first communication verification field and the second communication verification field can specifically include: if the first communication verification field and the second communication verification field are consistent, it is determined that the target message is verified successfully; and if the first communication verification field and the second communication verification field are inconsistent, it is determined that the target message is verified unsuccessfully.
[0108] The communication verification field is a field required in the SecOC verification process, and can include a CMAC value and a freshness value.
[0109] For example, assuming that the first communication check field in the target message obtained by the target component includes a first CMAC value CMAC1 and a first freshness value 2, if the second CMAC value calculated according to the target function signal in the target message is consistent with CMAC1, and the first freshness value is greater than the second freshness value (for example, 0 or 1) stored when the previous message is sent, it can be determined that the target message is successfully checked, and the data information contained in the target message does not exist tampering or other abnormal conditions; if the second CMAC value calculated according to the target function signal in the target message is inconsistent with CMAC1, and / or the first freshness value is less than or equal to the second freshness value stored when the previous message is sent, it can be determined that the target message is not checked, indicating that the target message may exist transmission abnormality in the transmission process.
[0110] Optionally, a preset number of times, for example, 5 times, is set. The target message is checked 5 times, and if the first CMAC value and the second CMAC value are inconsistent in the 5 times of checking, and / or the first freshness value is less than or equal to the second freshness value stored when the previous message is sent, it is determined that the target message is not checked.
[0111] In the embodiment of the application, when the first communication check field in the target message and the second communication check field calculated by the target component are consistent, it is determined that the target message is successfully checked; when the first communication check field and the second communication check field are inconsistent, it is determined that the target message is not checked. By comparing whether the first communication check field in the target message and the second communication check field calculated by the target component are consistent, it is determined whether the target message is successfully checked, the accuracy of the safety check of the related data of the vehicle braking system is improved, a reliable data basis for safe operation of the vehicle is provided, and the vehicle braking control failure caused by abnormal message signal transmission is avoided, thereby affecting the driving safety.
[0112] S303, if the target message is successfully checked, the target function signal is sent to the vehicle host to enable the vehicle host to check the target function signal.
[0113] For example, the target component checks the target message, and when the target message is successfully checked, it is indicated that the target message does not exist abnormal condition in the transmission process, and is a correct and complete message, and then the target function signal in the target message is sent to the vehicle gateway; so that the vehicle gateway can route the target function signal and other information to the vehicle host, and further enable the vehicle host to check the target function signal for safety, so as to be used by other systems or modules, for example, to control the vehicle braking according to the target function signal.
[0114] For example, the target message sent by the braking system contains the target function signal and the candidate check field. If the target component successfully checks the target message, the candidate check field in the target message is discarded, and only the target function signal is sent to the vehicle gateway for processing.
[0115] It should be noted that, in the process of sending the target function signal to the vehicle gateway, the content sent does not contain the check field, so the vehicle gateway cannot perform security check on the target function signal to ensure the correctness of the target function signal. Therefore, in order to ensure the safety of signal transmission between the target component and the vehicle gateway, the target component and the vehicle gateway can be deployed in a relatively close physical distance; or a transmission mode with high transmission rate and safety is used to establish a communication connection between the target component and the vehicle gateway, so as to ensure that the signal sent by the target component can be sent to the vehicle gateway for processing in a short transmission time.
[0116] Optionally, if the target message fails to pass the check, the abnormal message does not need to be sent to other modules, and the current target message can be discarded to reduce the workload of subsequent processing.
[0117] In summary, in the embodiment of the present application, the target component receives the target message sent by the braking system; the target message is checked for security according to the target function signal and the candidate check field in the target message; when the target message passes the check, the target function signal in the message is sent to the vehicle host to enable the vehicle host to check the target function signal. Through the twice check of the target component and the vehicle host, the safety of the signal sent by the braking system can be ensured; in addition, compared with the prior art in which all messages are checked by the vehicle host, in the present scheme, the target function signal in the target message that passes the check is forwarded to the vehicle host, so that the normal function signal is screened, and the workload of the vehicle host can be reduced to improve the security check efficiency.
[0118] Figure 4 is a schematic flowchart of another vehicle communication method provided by the embodiment of the present application. It should be understood that the method can be applied to a vehicle; or applied to a vehicle gateway in a vehicle; or applied to a chip mounted in a vehicle gateway in a vehicle.
[0119] For example, as shown in Figure 4 The method 400 includes the following steps S401 to S403.
[0120] S401, receiving a target function signal sent by a target component in a vehicle, wherein the target component is configured to check a target message sent by a braking system.
[0121] Exemplarily, the safety check is completed between the brake system of the vehicle and the vehicle gateway through a target component, and after the message sent by the brake system is checked successfully by the target component, the target function signal in the message is sent to the vehicle gateway for processing. The vehicle gateway receives the target function signal sent by the target component.
[0122] Optionally, the content contained in the target function signal can refer to the related description of S301 in the Figure 3 application embodiment, which is not described herein.
[0123] S402, generating a target check field based on the target function signal.
[0124] The target check field is a field required for SecOC check, which can include a freshness value and a CMAC value.
[0125] Exemplarily, after receiving the target function signal sent by the target component, the target check field corresponding to the target function signal can be determined according to the target function signal.
[0126] In an implementation manner, the process of generating the target check field based on the target function signal can specifically include: generating the target check field based on the target function signal and a target algorithm, wherein the target algorithm is an algorithm corresponding to the safety vehicle communication check.
[0127] Exemplarily, the software on the current vehicle host side is platformized, and the signals sent by other system modules are continuously subjected to the safety vehicle communication SecOC check. In order to adapt to the check manner of the vehicle host, the check field required for the SecOC check needs to be determined according to the target function signal sent by the target component. Therefore, the target check field corresponding to the target function signal is calculated according to the target function signal in combination with the target algorithm corresponding to the safety vehicle communication check.
[0128] In the application embodiment, the target check field is calculated according to the target function signal sent by the target component by using the algorithm corresponding to the safety vehicle communication check, so as to ensure that the target check field can reflect the related transmission information of the target function signal. Since the vehicle host will perform the safety vehicle communication check on the signal, through the scheme, the signal sent can include the field required for the check, so as to avoid the check failure due to the absence of the corresponding field in the signal and affect the normal use of the brake function.
[0129] S403, sending the target function signal and the target check field corresponding to the target function signal to the vehicle host, so that the vehicle host checks the target function signal based on the target check field.
[0130] Exemplarily, after the target check field corresponding to the target function signal is calculated, the target function signal and the target check field are sent to the vehicle host computer, so that the vehicle host computer can perform security check on the target function signal according to the target check field after receiving the target function signal and the target check field, to determine whether there is transmission abnormality in the transmission process from the vehicle gateway to the vehicle host computer, and further ensure the safety of signal transmission.
[0131] In summary, in the embodiment of the present application, after the vehicle gateway receives the target function signal sent by the target component, the target check field corresponding to the target function signal is calculated, and the target function signal and the target check field are sent to the vehicle host computer for security check. The target check field is added to the target function signal by the vehicle gateway, which avoids the failure of the vehicle host computer to check the signal sent by the brake system due to the absence of the required field for security check in the signal sent to the vehicle host computer, and further ensures the safety of signal transmission between the brake system and the vehicle host computer. In addition, the first security check is performed by the target component, and the vehicle gateway only needs to complete the calculation and transmission of the check field, which can reduce the software modification of the vehicle gateway, avoid unnecessary software vulnerabilities, and further improve the processing efficiency of security check.
[0132] Figure 5 is a schematic flowchart of another vehicle communication method provided by the embodiment of the present application. It should be understood that the method can be applied to a vehicle configured with a vehicle gateway and a target component, or a chip mounted in a vehicle.
[0133] Exemplarily, as shown in Figure 5 , the method 500 includes the following steps S501 to S506.
[0134] S501, a target component is deployed in the middle of the link between the brake system of the vehicle and the vehicle gateway, wherein the brake system includes an electronic stability system and / or an integrated brake control system.
[0135] Exemplarily, in the prior art, the brake system ESP or IBC directly sends a message to the vehicle gateway, and routes the message to the vehicle host computer through the vehicle gateway. In this process, the vehicle host computer performs SecOC check on the message, but the message may not contain the required field for check, thereby causing check failure and affecting the normal use of the brake function. Therefore, the target component, also called safety gateway (SGW), is added in the middle of the link between the brake system of the vehicle and the vehicle gateway.
[0136] Alternatively, the implementation of S501 can refer to the related description of Figure 2 ; the embodiment of the present application does not repeat it here.
[0137] S502, the target component receives a first message sent by the electronic stability system, wherein a check field included in the first message is a Hash field.
[0138] For example, the target component receives a message sent by the braking system; when the braking system configured in the vehicle is an electronic stability system (ESP), the first message includes a function signal and a Hash field, and the Hash field is used for checking the function signal.
[0139] Optionally, the implementation of S502 can refer to the related description of S301 in Figure 3 This application embodiment will not be described here in detail.
[0140] S503, the target component receives a second message sent by the integrated braking control system, wherein a check field included in the second message is a communication check field.
[0141] For example, the target component receives a message sent by the braking system; when the braking system configured in the vehicle is an integrated braking control system (IBC), the second message includes a function signal and a communication check (SecOC) field, and the communication check field is used for checking the function signal.
[0142] Optionally, the implementation of S503 can refer to the related description of S301 in Figure 3 This application embodiment will not be described here in detail.
[0143] It should be noted that when only one kind of braking system is configured in the vehicle, the step S502 and the step S503 only perform the steps corresponding to the currently configured braking system in the vehicle.
[0144] For example, when the braking system of the vehicle is an electronic stability system, the step S502 is performed and the step S503 is not performed; when the braking system of the vehicle is an integrated braking control system, the step S503 is performed and the step S502 is not performed; when the electronic stability system and the integrated braking control system are both configured in the vehicle, the step S502 and the step S503 are simultaneously or sequentially performed.
[0145] S504, the target component performs a preset number of security checks on the first message and / or the second message, and determines whether the check is successful. If yes, S505 is performed; if no, the check is ended.
[0146] For example, after receiving the first message and / or the second message sent by the braking system, the target component needs to perform a preset number (for example, 5 times) of security checks on the first message and / or the second message, and determine whether the first message and / or the second message is successfully checked.
[0147] Optionally, different ways can be taken to check the messages sent to different braking systems and containing different types of check fields.
[0148] For example, the first message containing the hash field can be checked by using the hash algorithm, and the second message containing the communication check field can be checked by using the corresponding algorithm of the secure vehicle communication check.
[0149] Optionally, a number threshold is set, and when the number of check failures indicated by the check results after a preset number of times reaches the number threshold, it is determined that the check fails; and when the number of check failures indicated by the check results after a preset number of times is less than the number threshold, it is determined that the check succeeds.
[0150] Optionally, the implementation of S504 can refer to the related description of S302 in Figure 3 The embodiments of the present application will not be repeated here.
[0151] S505, the target component cancels the check field in the first message and / or the second message, and sends the target function signal to the vehicle gateway.
[0152] For example, the target component checks the first message and / or the second message, and when the check result indicates that the check succeeds, the target component cancels the hash field in the first message, and / or cancels the communication check field in the second message, and sends the remaining target function signal in the message to the vehicle gateway for processing.
[0153] Optionally, the implementation of S505 can refer to the related description of S303 in Figure 3 The embodiments of the present application will not be repeated here.
[0154] S506, the vehicle gateway generates a target check field according to the target function signal, and sends the target function signal and the target check field to the vehicle host for security check.
[0155] The target check field is the check field required for the vehicle host to perform secure vehicle communication check; it can include a freshness value and a CMAC value.
[0156] For example, after receiving the target function signal sent by the target component, the vehicle gateway calculates the corresponding target check field according to the target function signal by using the target algorithm; then, the vehicle gateway sends the target function signal and the target check field corresponding to the target function signal to the vehicle host, so that the vehicle host performs security check on the target function signal according to the target check field, to determine whether the target function signal has transmission abnormality in the transmission process.
[0157] Optionally, the implementation of S506 can refer toFigure 4 The related description is described in detail in the foregoing method embodiments of the present application; the embodiments of the present application do not make superfluous repetition here.
[0158] In summary, in the embodiments of the present application, a target component is added in the communication link between the brake system and the vehicle gateway; the target component receives the message sent by the brake system, and the message contains a field for security check; the target component checks the message according to the check field to ensure the safety of signal transmission between the brake system and the target component; in the case of successful check, the function signal is sent to the vehicle gateway, and if the check fails, the message is discarded, which can reduce the operation amount of the vehicle gateway and subsequent system modules and improve the efficiency of security check; then, the vehicle gateway determines the target check signal according to the function signal and sends the function signal and the target check signal to the vehicle host at the same time, since the target check signal is the field required for the vehicle host to perform security check, the vehicle host can perform security check on the function signal, avoiding security check failure due to the absence of the corresponding field in the transmission signal, which further causes the function signal to be unable to be normally transmitted and affects the brake function.
[0159] The foregoing describes the vehicle communication method provided by the embodiments of the present application in detail; the following will describe the device embodiments of the present application in detail. Figures 1 to 5 The foregoing describes the vehicle communication method provided by the embodiments of the present application in detail; the following will describe the device embodiments of the present application in detail. Figures 6 to 8 It should be understood that the device in the embodiments of the present application can perform the various methods of the foregoing embodiments of the present application, that is, the specific working processes of the following various products can refer to the corresponding processes in the foregoing method embodiments.
[0160] Figure 6 FIG. 1 is a structural schematic diagram of a vehicle communication device provided by an embodiment of the present application.
[0161] For example, as shown in FIG. 6, the vehicle communication device 600 applied to the target component includes: Figure 6
[0162] The first receiving module 601 is configured to receive the target message sent by the brake system in the vehicle, wherein the target message includes the target function signal and the candidate check field.
[0163] The check module 602 is configured to check the target message based on the target function signal and the candidate check field.
[0164] The first sending module 603 is configured to send the target function signal to the vehicle host if the target message is successfully checked, so that the vehicle host checks the target function signal.
[0165] In one possible implementation, when the braking system is an electronic stability system, the candidate check field is the first hash field; the check module 602 is also used to obtain the second hash field based on the target function signal and the hash algorithm; and to check the target message based on the first hash field and the second hash field.
[0166] In a possible implementation, the verification module 602 is further configured to determine that the target message verification succeeds if the first hash field and the second hash field are consistent; and to determine that the target message verification fails if the first hash field and the second hash field are inconsistent.
[0167] In one possible implementation, when the braking system is an integrated braking control system, the candidate check field is the first communication check field; the check module 602 is also used to obtain the second communication check field based on the target function signal and the target algorithm, where the target algorithm is the algorithm corresponding to the safe vehicle communication verification; based on the first communication check field and the second communication check field, the target message is verified.
[0168] In a possible implementation, the verification module 602 is further configured to determine that the target message verification succeeds if the first communication verification field and the second communication verification field are consistent; and to determine that the target message verification fails if the first communication verification field and the second communication verification field are inconsistent.
[0169] Figure 7 It is a structural diagram of another vehicle communication device provided in an embodiment of the present application.
[0170] For example, Figure 7 As shown, the vehicle communication device 700 is applied to a vehicle gateway, and the vehicle communication device 700 includes:
[0171] The second receiving module 701 is used to receive a target function signal sent by a target component in the vehicle, wherein the target component is used to verify the target message sent by the braking system;
[0172] A generating module 702 is configured to generate a target check field based on the target function signal;
[0173] The second sending module 703 is configured to send the target function signal and the target check field corresponding to the target function signal to the vehicle host, so that the vehicle host can check the target function signal based on the target check field.
[0174] In a possible implementation, the generation module 702 is specifically configured to generate a target verification field based on a target function signal and a target algorithm, wherein the target algorithm is an algorithm corresponding to a secure vehicle communication verification.
[0175] It should be noted that the vehicle communication device is embodied in the form of a functional unit. The term "module" herein can be realized in the form of software and / or hardware, and is not specifically limited.
[0176] For example, the "module" can be a software program, a hardware circuit, or a combination of both, which realizes the above functions. The hardware circuit can include an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor, or a group processor, etc.) and a memory for executing one or more software or firmware programs, and a combination logic circuit and / or other suitable components supporting the described functions.
[0177] Therefore, the units of each example described in the embodiments of the present application can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0178] Figure 8 is a structural schematic diagram of a vehicle provided by an embodiment of the present application.
[0179] For example, as shown in Figure 8 The vehicle 800 includes a memory 801 and a processor 802, wherein the memory 801 stores executable program code 803, and the processor 802 is configured to invoke and execute the executable program code 803 to perform a vehicle communication method.
[0180] In addition, an embodiment of the present application also protects a device, which can include a memory and a processor, wherein the memory stores executable program code, and the processor is configured to invoke and execute the executable program code to perform a vehicle communication method provided by an embodiment of the present application.
[0181] The embodiment can divide the device into functional modules according to the above method examples, for example, corresponding to each functional module, or two or more functions can be integrated into one processing module, and the integrated module can be realized in the form of hardware. It should be noted that the division of modules in the embodiment is illustrative, and is only a logical function division. When actually implemented, there can be another division manner.
[0182] In the case of adopting the respective functional modules corresponding to the respective functions, the apparatus can further include a first receiving module, a checking module, a first sending module, a second receiving module, a generating module, and a second sending module, etc. It should be noted that all related content of the respective steps involved in the above method embodiments can be cited to the functional description of the corresponding functional modules, and will not be repeated here.
[0183] It should be understood that the apparatus provided by the embodiment is used to execute the vehicle communication method described above, and thus can achieve the same effect as the implementation method described above.
[0184] In the case of adopting the integrated unit, the apparatus can include a processing module and a storage module. When the apparatus is applied to a vehicle, the processing module can be used to control and manage the actions of the vehicle. The storage module can be used to support the vehicle to execute the related program code, etc.
[0185] The processing module can be a processor or a controller, which can realize or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure of the present application. The processor can also be a combination of computing functions, such as one or more microprocessor combinations, combinations of digital signal processing (DSP) and microprocessors, etc. The storage module can be a memory.
[0186] In addition, the apparatus provided by the embodiments of the present application can be a chip, a component or a module, the chip can include a connected processor and a memory; wherein the memory is used to store instructions, when the processor calls and executes the instructions, the chip can execute the vehicle communication method provided by the above-mentioned embodiments.
[0187] The embodiment also provides a computer readable storage medium, the computer readable storage medium stores computer program codes, when the computer program codes run on the computer, the computer executes the related method steps to realize the vehicle communication method provided by the above-mentioned embodiments.
[0188] The computer readable storage medium can include, but is not limited to, any type of disk including floppy disks, optical disks, Digital Video Discs (DVDs), Compact Disc Read-Only Memories (CD-ROMs), micro drives, and magneto-optical disks, Read-Only Memories (ROMs), Random Access Memories (RAMs), Erasable Programmable Read-Only Memories (EPROMs), Electrically Erasable Programmable Read-Only Memories (EEPROMs), Dynamic Random Access Memories (DRAMs), Video Random Access Memories (VRAMs), flash memory devices, magnetic or optical cards, nano-systems (including molecular memory ICs), or any type of media or device suitable for storing instructions and / or data.
[0189] The embodiment further provides a computer program product, which, when running on a computer, enables the computer to perform the above related steps to realize the vehicle communication method provided by the above embodiment.
[0190] The device, the computer readable storage medium, the computer program product or the chip provided by the embodiment are used to execute the corresponding method provided above, so the beneficial effects achieved thereby can refer to the beneficial effects of the corresponding method provided above, which will not be described herein again.
[0191] Through the above description of the embodiments, those skilled in the art can understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0192] In the embodiments of the present disclosure, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are merely schematic, and the division of the modules or units is merely a logical function division. In actual implementation, another division manner can be adopted, for example, a plurality of units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or in other forms.
[0193] The above merely describes specific embodiments of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present disclosure, which should be covered by the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A vehicle communication method, characterized in that: The method is applied to a target component, and the method comprises: receiving a target message sent by a braking system in a vehicle, wherein the target message includes a target function signal and a candidate check field; The target message is verified based on the target function signal and the candidate verification field; wherein, when the braking system is an electronic stability system, the target message is verified based on the target function signal and a hash algorithm; when the braking system is an integrated braking control system, the target message is verified based on the target function signal and a target algorithm, and the target algorithm is an algorithm corresponding to secure vehicle communication verification; If the target message verification is successful, a target verification field is added to the target function signal through the vehicle gateway, and the target function signal and the target verification field are sent to the vehicle host, so that the vehicle host verifies the target function signal.
2. The method according to claim 1, characterized in that When the braking system is an electronic stability system, the candidate check field is a first hash field; The verifying the target message based on the target function signal and the candidate verification field includes: Based on the target function signal and the hash algorithm, obtain a second hash field; The target message is verified based on the first hash field and the second hash field.
3. The method according to claim 2, characterized in that The verifying the target message based on the first hash field and the second hash field includes: If the first hash field and the second hash field are consistent, it is determined that the target message verification is successful; If the first hash field and the second hash field are inconsistent, it is determined that the target message verification fails.
4. The method according to any one of claims 1 to 3, characterized in that When the braking system is an integrated braking control system, the candidate check field is a first communication check field; The verifying the target message based on the target function signal and the candidate verification field includes: Based on the target function signal and the target algorithm, a second communication verification field is obtained, wherein the target algorithm is an algorithm corresponding to the secure vehicle communication verification; The target message is verified based on the first communication verification field and the second communication verification field.
5. The method according to claim 4, characterized in that The verifying the target message based on the first communication verification field and the second communication verification field includes: If the first communication check field and the second communication check field are consistent, determining that the target message verification is successful; If the first communication check field and the second communication check field are inconsistent, it is determined that the target message verification fails.
6. A vehicle communication method, characterized in that: The method is applied to a vehicle gateway, and the method includes: receiving a target function signal sent by a target component in the vehicle, wherein the target component is used to verify a target message sent by the braking system; when the braking system is an electronic stability system, the target message is verified based on the target function signal and a hash algorithm; when the braking system is an integrated braking control system, the target message is verified based on the target function signal and a target algorithm, wherein the target algorithm is an algorithm corresponding to secure vehicle communication verification; generating a target check field based on the target function signal; The target function signal and the target check field corresponding to the target function signal are sent to the vehicle-mounted host, so that the vehicle-mounted host checks the target function signal based on the target check field.
7. The method according to claim 6, characterized in that Generating a target check field based on the target function signal includes: The target verification field is generated based on the target function signal and the target algorithm, wherein the target algorithm is an algorithm corresponding to the safe vehicle communication verification.
8. A vehicle communication device, characterized in that: The device is applied to a target component, and the device comprises: A first receiving module is configured to receive a target message sent by a braking system in a vehicle, wherein the target message includes a target function signal and a candidate check field; a verification module, configured to verify the target message based on the target function signal and the candidate verification field; wherein, when the braking system is an electronic stability system, the target message is verified based on the target function signal and a hash algorithm; and when the braking system is an integrated braking control system, the target message is verified based on the target function signal and a target algorithm, where the target algorithm is an algorithm corresponding to secure vehicle communication verification; The first sending module is used to add a target check field to the target function signal through the vehicle gateway if the target message verification is successful, and send the target function signal and the target check field to the vehicle host, so that the vehicle host verifies the target function signal.
9. A vehicle communication device, characterized in that: The device is applied to a vehicle gateway, and includes: a second receiving module, configured to receive a target function signal sent by a target component in the vehicle, wherein the target component is configured to verify a target message sent by the braking system; when the braking system is an electronic stability system, the target message is verified based on the target function signal and a hash algorithm; when the braking system is an integrated braking control system, the target message is verified based on the target function signal and a target algorithm, wherein the target algorithm is an algorithm corresponding to secure vehicle communication verification; A generating module, configured to generate a target check field based on the target function signal; The second sending module is used to send the target function signal and the target check field corresponding to the target function signal to the vehicle-mounted host, so that the vehicle-mounted host verifies the target function signal based on the target check field.
10. A vehicle, characterized in that: The vehicle comprises: a memory for storing executable program code; A processor is configured to call and run the executable program code from the memory, so that the vehicle executes the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Vehicle communication method, vehicle communication device, vehicle and storage medium
CN119814416A