Vehicle communication methods, vehicle communication devices and vehicles
By performing initial verification of the braking system's functional signals through the vehicle gateway and subsequent verification at the vehicle host, the problem of verification failure caused by the low configuration of the electronic stability system is resolved, thereby improving the security and efficiency of vehicle communication.
Patent Information
- Application Number
- CN202411912267.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-24
AI Technical Summary
In the existing technology, electronic stability systems, due to their low configuration, cannot be adapted to the SecOC verification method, resulting in unexpected verification failures, which may lead to abnormal vehicle braking function.
The vehicle gateway receives the functional signals and verification fields of the braking system for initial verification, and then sends them to the vehicle host for re-verification after successful verification, ensuring the security of the signal transmission process.
It improves the accuracy of safety verification, avoids abnormal braking function due to verification failure, ensures vehicle driving safety, reduces the computing load of the on-board host, and improves the efficiency of safety verification of functional signals.
Smart Images

Figure CN119814418B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicles, and more specifically, to a vehicle communication method, a vehicle communication device, and a vehicle in the field of vehicles. Background Technology
[0002] With the increasing prevalence of connected vehicles, the security of in-vehicle communication is receiving more and more attention. However, in current in-vehicle networks, most data transmission occurs without any security measures, making it impossible to verify the trustworthiness of the sending node. Therefore, Secure On Board Communication (SecOC), as a secure and reliable encrypted communication solution, has been included in the in-vehicle secure communication standard to ensure the security of in-vehicle communication.
[0003] Electronic stability systems (ESS) and integrated braking control systems are different types of vehicle braking systems. During signal safety verification, EES, due to its lower configuration, cannot adapt to the SecOC verification method, which may lead to unexpected verification failures and consequently, abnormal vehicle braking function.
[0004] Therefore, how to avoid abnormal braking system function caused by incorrect message verification is an urgent problem to be solved. Summary of the Invention
[0005] This application provides a vehicle communication method, a vehicle communication device, and a vehicle, which can avoid abnormal braking system function caused by incorrect verification of messages.
[0006] Firstly, a vehicle communication method is provided, which is applied to an in-vehicle gateway, and the method includes:
[0007] Receive the target function signal and the first verification field corresponding to the target function signal sent by the braking system in the vehicle;
[0008] The target function signal is verified based on the first verification field;
[0009] If the target function signal verification is successful, the target function signal is sent to the vehicle host so that the vehicle host can verify the target function signal.
[0010] In the above technical solution, the vehicle gateway receives the functional signals and verification fields sent by the braking system; it performs security verification on the functional signals based on the verification fields to determine whether there are any transmission abnormalities during the signal transmission process from the braking system to the vehicle gateway, thus ensuring the communication security between the braking system and the vehicle gateway; by having the vehicle gateway perform the initial verification of the functional signals and the vehicle host perform the second verification of the functional signals, the accuracy of the security verification can be improved, avoiding abnormal vehicle braking function due to verification failure, which would affect vehicle driving safety.
[0011] Furthermore, compared to existing technologies where the vehicle host performs security verification on functional signals, in this solution, the vehicle gateway only sends functional signals to the vehicle host if the verification is successful, and will not send functional signals that fail verification. This reduces the computational load on the vehicle host and improves the efficiency of functional signal security verification.
[0012] In conjunction with the first aspect, in some possible implementations, the method also includes:
[0013] Upon receiving the target function signal sent by the braking system, a response signal corresponding to the target function signal is sent to the braking system, wherein the response signal is used to indicate that the vehicle gateway has received the target function signal.
[0014] In the above technical solution, when the vehicle gateway receives the target function signal sent by the braking system, it sends a response signal corresponding to the target function signal to the braking system. Through this response signal, the braking system can confirm that the signal was successfully transmitted. This avoids the braking system generating fault codes or taking other remedial measures, such as repeatedly sending signals, due to uncertainty about signal reception, thus preventing waste of system resources or signal confusion and improving the transmission efficiency of vehicle signal communication.
[0015] Combining the first aspect and the above implementation methods, in some possible implementation methods, the target function signal is verified based on the first verification field, including:
[0016] Based on the target function signal and the target algorithm, a second verification field is generated, where the target algorithm is the algorithm corresponding to the verification of secure vehicle communication.
[0017] The target function signal is verified based on the first and second verification fields.
[0018] In the above technical solution, the vehicle gateway calculates the corresponding second verification field based on the target function signal sent by the braking system; by comparing the first and second verification fields, the target function signal is verified. Since the verification fields are all calculated based on the function signal, by comparing the verification fields calculated by the braking system and the vehicle gateway, it is possible to accurately verify whether the message has been tampered with during transmission, ensuring the integrity and authenticity of the instructions and data related to the integrated braking control system, and improving the efficiency and accuracy of message security verification.
[0019] Combining the first aspect and the above implementation methods, in some possible implementation methods, the target function signal is verified based on the first verification field and the second verification field, including:
[0020] If the first verification field and the second verification field are consistent, the target function signal verification is successful.
[0021] If the first verification field and the second verification field are inconsistent, the target function signal verification is determined to have failed.
[0022] In the above technical solution, when the first verification field sent by the braking system matches the second verification field calculated by the vehicle gateway, the target function signal verification is considered successful; when the first and second verification fields do not match, the target function signal verification is considered unsuccessful. By comparing whether the first verification field sent by the braking system and the second verification field calculated by the vehicle gateway match, the accuracy of safety verification of vehicle braking system-related data is improved, providing a reliable data foundation for safe vehicle operation and preventing vehicle braking control errors due to abnormal function signal transmission, which could affect driving safety.
[0023] Secondly, a vehicle communication method is provided, which is applied to a braking system, and the method includes:
[0024] Send the target function signal to the vehicle's onboard gateway;
[0025] Receive the response signal corresponding to the target function signal sent by the vehicle gateway;
[0026] In response to the response signal, the first verification field corresponding to the target function signal is sent to the vehicle gateway.
[0027] In the above technical solution, the braking system first sends the target function signal to the vehicle gateway. After receiving the response signal from the vehicle gateway, it then sends the target verification field corresponding to the target function signal to the vehicle gateway. Sending the function signal and verification field in batches not only enables secure verification of the function signal but also avoids the situation where a low-configuration braking system cannot simultaneously send the function signal and the verification field required for secure vehicle communication verification, which could lead to errors in function signal verification by the vehicle gateway and the vehicle host, resulting in abnormal braking function. This further improves the accuracy of the secure verification of the function signal.
[0028] In conjunction with the second aspect, in some possible implementations, in response to the response signal, a first verification field corresponding to the target function signal is sent to the vehicle gateway, including:
[0029] In response to the response signal, and based on the target function signal, the first verification field is generated;
[0030] Send the first verification field to the vehicle gateway.
[0031] Combining the second aspect and the above implementation methods, in some possible implementation methods, a first verification field is generated based on the target function signal, including:
[0032] Based on the target function signal and the target algorithm, a first verification field is generated, where the target algorithm is the algorithm corresponding to the verification of secure vehicle communication.
[0033] In the above technical solution, the braking system uses the target algorithm corresponding to the safe vehicle communication verification to calculate the first verification field corresponding to the target function signal, so that the vehicle gateway can perform safe communication network verification on the target function signal to ensure the safety of vehicle network communication.
[0034] Thirdly, a vehicle communication device is provided, which is applied to an in-vehicle gateway, and the device includes:
[0035] The first receiving module is used to receive the target function signal and the first verification field corresponding to the target function signal sent by the braking system in the vehicle.
[0036] The verification module is used to verify the target function signal based on the first verification field;
[0037] The first transmitting module is used to send the target function signal to the vehicle host if the target function signal verification is successful, so that the vehicle host can verify the target function signal.
[0038] In conjunction with the third aspect, in some possible implementations, the device further includes a fourth transmitting module, used to transmit a response signal corresponding to the target function signal to the braking system upon receiving the target function signal transmitted by the braking system, wherein the response signal is used to indicate that the vehicle gateway has received the target function signal.
[0039] In conjunction with the third aspect and the above implementation methods, in some possible implementation methods, the verification module is also used to generate a second verification field based on the target function signal and the target algorithm, wherein the target algorithm is the algorithm corresponding to the safe vehicle communication verification; and to verify the target function signal based on the first verification field and the second verification field.
[0040] In conjunction with the third aspect and the above implementation methods, in some possible implementation methods, the verification module is also used to determine that the target function signal verification is successful if the first verification field and the second verification field are consistent; and to determine that the target function signal verification fails if the first verification field and the second verification field are inconsistent.
[0041] Fourthly, a vehicle communication device is provided, which is applied to a braking system, the device comprising:
[0042] The second transmitting module is used to send the target function signal to the vehicle's on-board gateway.
[0043] The second receiving module is used to receive the response signal corresponding to the target function signal sent by the vehicle gateway;
[0044] The third sending module is used to send the first verification field corresponding to the target function signal to the vehicle gateway in response to the response signal.
[0045] In conjunction with the fourth aspect and the above implementation methods, in some possible implementation methods, the third sending module is also used to generate a first verification field based on the target function signal in response to the response signal; and send the first verification field to the vehicle gateway.
[0046] In conjunction with the fourth aspect and the above implementation methods, in some possible implementation methods, the third sending module is also used to generate a first verification field based on the target function signal and the target algorithm, wherein the target algorithm is the algorithm corresponding to the secure vehicle communication verification.
[0047] Fifthly, a vehicle is provided, including a memory and a processor. The memory is used to store executable program code, and the processor is used to call and run the executable program code from the memory, causing the vehicle to perform the methods described in the first aspect or any possible implementation thereof.
[0048] In a sixth aspect, a computer program product is provided, comprising: computer program code, which, when run on a computer, causes the computer to perform the method described in the first aspect or any possible implementation thereof.
[0049] In a seventh aspect, a computer-readable storage medium is provided that stores computer program code, which, when executed on a computer, causes the computer to perform the methods described in the first aspect or any possible implementation thereof. Attached Figure Description
[0050] Figure 1 This is a schematic diagram of a vehicle system architecture provided in an embodiment of this application;
[0051] Figure 2 This is a schematic flowchart illustrating a vehicle communication method provided in an embodiment of this application;
[0052] Figure 3 This is a schematic flowchart of another vehicle communication method provided in an embodiment of this application;
[0053] Figure 4 This is a schematic flowchart of another vehicle communication method provided in an embodiment of this application;
[0054] Figure 5 This is a schematic diagram of the structure of a vehicle communication device provided in an embodiment of this application;
[0055] Figure 6 This is a schematic diagram of another vehicle communication device provided in an embodiment of this application;
[0056] Figure 7 This is a schematic diagram of the structure of a vehicle provided in an embodiment of this application. Detailed Implementation
[0057] The technical solutions in this application will be clearly and thoroughly described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. "And / or" in the text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more than two.
[0058] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.
[0059] With the rapid development of technology, the automotive industry is undergoing a massive transformation from traditional mechanical transportation tools to intelligent mobile terminals. Modern cars are equipped with a large number of Electronic Control Units (ECUs), which control various vehicle functions such as engine management, braking systems, and vehicle stability systems. At the same time, the connection between vehicles and external networks is becoming increasingly close; for example, vehicle-to-everything (V2X) technology enables vehicles to achieve remote information processing, real-time traffic information acquisition, and online software upgrades.
[0060] The network architecture within vehicles is becoming increasingly complex, with multiple communication protocols such as CAN (Controller Area Network), LIN (Local Interconnect Network), and Ethernet being used simultaneously. Different ECUs communicate with each other through these protocols, and in intelligent connected vehicles, the internal network also needs to interact with external networks (such as 4G / 5G networks). Taking the CAN bus as an example, it is a widely used communication protocol within vehicles, used to connect critical ECUs such as those in the powertrain and chassis systems. In traditional vehicles, the CAN bus primarily focuses on internal communication efficiency, but in a connected environment, it can become an entry point for cyberattacks.
[0061] Therefore, a new verification method—Secure On-Board Communication (SecOC)—was proposed for vehicle communication security verification. SecOC is a standard secure communication module that utilizes a freshness value and a checksum (CMAC) to verify the correctness and tampering of messages during transmission. The freshness value and checksum together ensure the security of vehicle CAN communication and are typically applied to messages containing high-risk, critical functional signals.
[0062] Figure 1 This is a schematic diagram of a vehicle system architecture provided in an embodiment of this application. Figure 1As shown, during vehicle operation, message transmission occurs between the vehicle's braking system 101, the on-board gateway (GW) 102, and the on-board unit (HUT) 103. The vehicle braking system 101 may include an integrated brake control system (IBC) and an electronic stability program (ESP).
[0063] Suppose the HUT needs to send a message to the IBC. Since a message consists of many signals, to detect whether the message or the signals within it have been tampered with or attacked during transmission, the HUT calculates an additional value for the message value before transmission and attaches it to the message before sending it to the IBC. This additional value is called the Cipher-based Message Authentication Code (CMAC). After receiving the message, the IBC uses the same algorithm to calculate the additional value and compares the calculated CMAC with the CMAC sent by the HUT. If they match, it means that the message frame has not been tampered with.
[0064] The freshness value is used to detect whether a received message is up-to-date; that is, to detect any delays in message transmission. SecOC communication uses a master-slave architecture, typically with the vehicle gateway acting as the master node. The vehicle gateway periodically synchronizes the same freshness value with all slave nodes. If the HUT (Host Receiver) needs to send a message frame to the IBC (Integrated Broadband Receiver), in addition to verifying the CMAC (Content Management Requirement) value, it also needs to verify the freshness value. For example, if the first frame from the HUT has a freshness value of 1, the IBC will store this value locally. If the second frame has a freshness value of 3, the IBC will update the freshness value from 1 to 3. The freshness value does not necessarily increase sequentially in an arithmetic order; it could be 1, 3, 4, 6, 7, etc. Adjacent freshness values may not have a logical relationship, but the freshness value of the next frame will always be greater than the freshness value of the previous frame. If the local IBC storage has a freshness value of 3, and the next HUT transmission has a freshness value of 2, then it means that the message may be stuck during the transmission process, that is, the message is not fresh.
[0065] During the verification process of CMAC and Freshness value, signal transmission may be interrupted. For redundancy, the number of verifications can be set. For example, if CMAC shows five inconsistencies, an error is determined; if the freshness value shows five instances of being not fresh, an error is also determined.
[0066] The braking system configurations differ across vehicle trim levels. Lower-spec vehicles may have ESP, while higher-spec vehicles may have the more advanced IBC. In existing message signal verification processes, the CMAC and freshness values generated by SecOC verification are attached to the message as CAN signals, with the CMAC value occupying 6 bytes and the freshness value occupying 2 bytes. Traditional CAN data frame payloads are typically 8 bytes. If the CAN message signal contains functional signals, it cannot carry the bytes required for the CMAC and freshness values, thus preventing SecOC verification.
[0067] For vehicles equipped with ESP, because ESP uses ordinary CAN signals during signal transmission, the messages sent by ESP to GW do not include fields required for SecOC verification (such as CMAC and freshness values). Therefore, GW does not verify the messages sent by ESP and only routes them to HUT. At this point, the message signal still lacks the fields required for SecOC verification, causing HUT to fail to perform SecOC verification, resulting in HUT verification failure. The frame is then discarded, and a functional anomaly result is output. However, this result may not be caused by a functional signal anomaly, indicating a functional anomaly due to incorrect verification during the verification process.
[0068] For vehicles equipped with IBC, since IBC uses the CAN FD (Controller Area Network Flexible Data-rate) signal, a communication protocol developed from the traditional CAN bus, during signal transmission, the effective payload of the CAN FD data frame can reach 64 bytes or more. Therefore, the message sent by IBC can contain the fields required for SecOC verification. GW routes it to HUT, and HUT can perform SecOC verification on the message based on the fields in the message.
[0069] In summary, existing technologies cannot simultaneously generate messages containing both functional signals and the fields required for SecOC verification for lower-configuration braking systems, and then send them together to system modules such as the vehicle gateway and vehicle host for verification. Existing verification methods cannot satisfy all braking systems, and there may be situations where the functional signal is correct, but a safety verification error occurs due to the absence of the required fields, leading to abnormal braking function.
[0070] In view of the problems existing in the prior art, this application provides a vehicle communication method, a vehicle communication device, and a vehicle. The method is applied to an in-vehicle gateway. The in-vehicle gateway receives a target function signal and a first verification field corresponding to the target function signal sent by the braking system in the vehicle. Based on the first verification field, the target function signal can be verified to determine whether there is a transmission anomaly. If the verification of the target function signal is successful, the target function signal is sent to the in-vehicle host for verification. Another in-vehicle communication method is also provided, applied to the braking system. The braking system sends a function signal to the in-vehicle gateway; after receiving a response signal sent by the in-vehicle gateway, it sends the verification field corresponding to the function signal to the in-vehicle gateway. The above method can improve the security of signal transmission and avoid braking function anomalies caused by incorrect verification of messages.
[0071] The following is combined Figures 2 to 4 The vehicle communication method provided in the embodiments of this application will be described in detail.
[0072] Figure 2 This is a schematic flowchart illustrating a vehicle communication method provided in an embodiment of this application. It should be understood that this method can be applied to a vehicle; or, to an in-vehicle gateway within a vehicle; or, to a chip mounted in an in-vehicle gateway within a vehicle.
[0073] For example, such as Figure 2 As shown, the method 200 includes the following steps S201 to S203.
[0074] S201, Receive the target function signal and the first verification field corresponding to the target function signal sent by the braking system in the vehicle.
[0075] The first verification field is the verification field corresponding to the Secure In-Vehicle Communication (SecOC) verification, which may include the freshness value and the CMAC value.
[0076] For example, during vehicle signal communication, a communication connection is established between the braking system, the vehicle gateway (GW), and the vehicle head unit (HUT). The vehicle gateway receives the target function signal sent by the braking system and the first verification field corresponding to the target function signal.
[0077] Optionally, the braking system may include Electronic Stability System (ESP) and Integrated Brake Control System (IBC), etc. In the controller of ESP or IBC, a corresponding first verification field is generated based on the target function signal to be sent.
[0078] For example, in the controller of the braking system, a corresponding algorithm for Safe On-board Communication (SecOC) verification is used to calculate a first verification field corresponding to the target function signal based on the target function signal, and the target function signal and the first verification field are sent to the vehicle gateway for Safe On-board Communication (SecOC) verification.
[0079] The target function signals may include brake pressure value signals, brake mode signals, and brake component status signals. The braking system converts the pressure values in the brake lines into digital codes, which are then reflected in the message.
[0080] The braking system also includes multiple modes, such as normal mode, emergency braking, anti-lock braking system (ABS) mode, and electronic parking brake (EPB) mode. These modes are represented by corresponding codes in the message data field. For example, a single byte might use 00 to represent normal braking, 01 to represent emergency braking, 10 to indicate ABS mode is active, and 11 to indicate EPB mode is activated. When the braking system enters a specific mode, it updates the corresponding byte in the message data field, sending the corresponding mode code to the vehicle gateway.
[0081] The braking system also includes various components such as brake pads, brake discs, and brake pumps. The status of these components is also reflected in the message. For example, the wear status of brake pads can be represented using a single byte. A value of 0-3 indicates normal brake pad thickness, 4-6 indicates the brake pad is about to wear to its limit, and 7 indicates the brake pad has worn to its limit and needs replacement. Through this encoding method, the braking system can promptly transmit component status information to other systems (such as the vehicle gateway).
[0082] In one implementation, upon receiving a target function signal from the braking system, a response signal corresponding to the target function signal is sent to the braking system, wherein the response signal is used to indicate that the vehicle gateway has received the target function signal.
[0083] The response signal can also be called the positive response signal.
[0084] For example, after the braking system sends the target function signal to the vehicle gateway, it also needs to send the first verification field corresponding to the target function signal to the vehicle gateway. To avoid the braking system sending the first verification field prematurely or delayed, causing the vehicle gateway to fail to verify the target function signal, a response signal can be returned to the braking system after receiving the target function signal to indicate that the vehicle gateway has successfully received the target function signal, allowing the braking system to send the first verification field corresponding to the target function signal to the vehicle gateway.
[0085] Optionally, after receiving the target function signal, the vehicle gateway extracts the identifier (ID, Identify) of the target function signal; generates a response signal corresponding to the target function signal based on the ID, and sends the response signal to the braking system, so that the braking system can clearly identify the first verification field that needs to be sent as the field corresponding to the target function signal.
[0086] In this embodiment, when the vehicle gateway receives the target function signal sent by the braking system, it sends a response signal corresponding to the target function signal to the braking system. Through this response signal, the braking system can confirm that the signal was successfully transmitted. This avoids the braking system generating fault codes or taking other remedial measures, such as repeatedly sending signals, due to uncertainty about signal reception, thus preventing waste of system resources or signal confusion and improving the transmission efficiency of vehicle signal communication.
[0087] S202, Verify the target function signal based on the first verification field.
[0088] For example, the first verification field is calculated based on the target function signal and is used for SecOC verification. After receiving the target function signal and the corresponding first verification field sent by the braking system, the vehicle gateway can perform security verification on the target function signal based on the first verification field to determine whether there are any transmission anomalies such as data tampering in the target function signal.
[0089] In one implementation, the process of verifying the target function signal based on the first verification field may specifically include:
[0090] Based on the target function signal and the target algorithm, a second verification field is generated, where the target algorithm is the algorithm corresponding to the verification of secure vehicle communication.
[0091] The target function signal is verified based on the first and second verification fields.
[0092] For example, after receiving the target function signal, the vehicle gateway can use the target algorithm to calculate the second verification field, which may include a second freshness value and a second CMAC value; then it can compare the first verification field and the second verification field to determine whether there is an anomaly in the target function signal.
[0093] In this embodiment, the vehicle gateway calculates the corresponding second verification field based on the target function signal sent by the braking system; the target function signal is verified by comparing the first verification field and the second verification field. Since the verification fields are all calculated based on the function signal, by comparing the verification fields calculated by the braking system and the vehicle gateway, it is possible to accurately verify whether the message has been tampered with during transmission, ensuring the integrity and authenticity of the instructions and data related to the integrated braking control system, and improving the efficiency and accuracy of message security verification.
[0094] In one implementation, the process of verifying the target functional signal based on the first and second verification fields may include:
[0095] If the first verification field and the second verification field are consistent, the target function signal verification is successful.
[0096] If the first verification field and the second verification field are inconsistent, the target function signal verification is determined to have failed.
[0097] For example, assuming the first verification field obtained by the vehicle gateway includes a first CMAC value of CMAC1 and a first freshness value of 2, if the second CMAC value calculated based on the target function signal is consistent with CMAC1, and the first freshness value is greater than the second freshness value stored when the function signal was sent previously (e.g., 0, 1), then it can be determined that the target function signal verification is successful and the target function signal has not been tampered with or is otherwise abnormal. If the second CMAC value calculated based on the target function signal is inconsistent with CMAC1, and / or the first freshness value is less than or equal to the second freshness value stored when the function signal was sent previously, then it can be determined that the target function signal verification fails, indicating that there may be a transmission anomaly in the target function signal during transmission.
[0098] Optionally, a preset number of times can be set, for example, 5 times. The target function signal is subjected to 5 security checks. If all 5 checks indicate that the first CMAC value and the second CMAC value are inconsistent, and / or the first freshness value is less than or equal to the second freshness value stored when the previous message was sent, then the target function signal check is determined to have failed.
[0099] In this embodiment, when the first verification field sent by the braking system matches the second verification field calculated by the vehicle gateway, the target function signal verification is determined to be successful; when the first verification field and the second verification field do not match, the target function signal verification is determined to be unsuccessful. By comparing whether the first verification field sent by the braking system and the second verification field calculated by the vehicle gateway match, the accuracy of safety verification of vehicle braking system-related data is improved, providing a reliable data foundation for safe vehicle operation and avoiding vehicle braking control errors due to abnormal function signal transmission, which could affect driving safety.
[0100] S203, if the target function signal verification is successful, the target function signal is sent to the vehicle host so that the vehicle host can verify the target function signal.
[0101] For example, when the vehicle gateway successfully verifies the target function signal, it indicates that there is no transmission abnormality in the transmission of the target function signal from the braking system to the vehicle gateway. Then, the target function signal can be routed and forwarded to the vehicle host through the vehicle gateway, so that the vehicle host can perform a second security verification of the target function signal. The vehicle host can also send the target function signal to other system modules to achieve vehicle control.
[0102] Optionally, if the target function signal verification fails, the vehicle gateway can send a negative response signal to the vehicle host to indicate that the target function signal verification has failed.
[0103] Optionally, when the target sensing fails the verification, a target signal can be sent to the braking system, instructing the braking system to resend the failed target function signal and perform a safety verification on the resent target function signal again, so as to avoid verification failure due to other abnormal factors and further improve the accuracy of safety verification.
[0104] When the vehicle gateway successfully verifies the target function signal, it can only ensure the security of transmission between the braking system and the vehicle gateway. If the target function signal is sent directly to the vehicle host, the security of the path between the vehicle gateway and the vehicle host cannot be guaranteed. In addition, the vehicle host needs to use SecOC verification to perform security verification on the signal. If the signal sent to the vehicle host does not contain the fields required for SecOC verification, it may cause verification failure, resulting in abnormal braking function.
[0105] To prevent the vehicle-mounted host from failing to verify normal function signals, in one implementation, the process of sending the target function signal to the vehicle-mounted host so that the vehicle-mounted host can verify the target function signal may include: generating a third verification field based on the target function signal and the target algorithm; and sending the target function signal and the third verification field to the vehicle-mounted host so that the vehicle-mounted host can verify the target function signal based on the third verification field.
[0106] For example, the target algorithm is the algorithm corresponding to Secure In-Vehicle Communication (SecOC) verification. Using the target algorithm, the third verification field corresponding to the target function signal can be calculated, which may include the third freshness value and the third CMAC value, etc. The target function signal and the third verification field are sent to the vehicle host at the same time. The vehicle host can perform SecOC verification on the target function signal according to the third verification field to determine whether there is a transmission anomaly between the vehicle gateway and the vehicle host.
[0107] Furthermore, the vehicle host can calculate the fourth verification field based on the target function signal. By comparing the fourth verification field with the third verification field sent by the vehicle gateway, it can determine whether the verification was successful and whether there is any transmission abnormality.
[0108] In this embodiment, the vehicle gateway calculates the third verification field based on the target function signal and sends both the target function signal and the third verification field to the vehicle host simultaneously. This enables the vehicle host to perform security verification on the processed message based on the target verification field, preventing the vehicle host from failing to verify the message sent to the braking system due to the absence of the required field for security verification in the target message, which could lead to abnormal braking system function. Furthermore, the above solution performs dual verification of the target message by the vehicle gateway and the vehicle host, improving the accuracy of security verification and thus ensuring the security of vehicle network communication.
[0109] In summary, in this embodiment, the vehicle gateway receives the functional signal and verification field sent by the braking system; it performs security verification on the functional signal based on the verification field to determine whether there are any transmission anomalies during the signal transmission process from the braking system to the vehicle gateway, thus ensuring the communication security between the braking system and the vehicle gateway. By having the vehicle gateway perform the initial verification of the functional signal, and the vehicle host performs a second verification, the accuracy of the security verification can be improved, avoiding abnormal vehicle braking function due to verification failure, which could affect vehicle driving safety. Furthermore, compared to existing technologies where the vehicle host performs security verification on the functional signal, in this solution, the vehicle gateway only sends the functional signal to the vehicle host if the verification is successful, and does not send functional signals indicating verification failure. This reduces the computational load on the vehicle host and improves the efficiency of functional signal security verification.
[0110] Figure 3 This is a schematic flowchart illustrating another vehicle communication method provided in an embodiment of this application. It should be understood that this method can be applied to a vehicle; or, to the braking system in a vehicle; or, to a chip related to the braking system mounted in a vehicle.
[0111] It should be noted that the braking system may include electronic stability system (ESP) and integrated brake control system (IBC), etc. This method can be applied to any braking system, and the embodiments of this application do not limit it.
[0112] For example, such as Figure 3 As shown, the method 300 includes the following steps S301 to S303.
[0113] S301 sends the target function signal to the vehicle's onboard gateway.
[0114] For example, during vehicle network communication, the braking system continuously transmits functional signals to system modules such as the onboard host for processing and application. During this process, preprocessing, including safety verification, is required via the onboard gateway. For Electronic Stability Program (ESP), due to its lower configuration, CAN transmission is used during signal transmission. However, the CAN signal can only carry a limited number of characters, making it impossible to send functional signals and verification fields simultaneously. Therefore, for any type of braking system, the target functional signal can be sent to the onboard gateway in the vehicle first.
[0115] Optionally, the meaning of the content indicated by the function signals can be found in [reference needed]. Figure 2 The relevant descriptions in S201 are not repeated here in the embodiments of this application.
[0116] S302 receives the response signal corresponding to the target function signal sent by the vehicle gateway.
[0117] The response signal, also known as the positive response signal, is used to indicate that the vehicle gateway has successfully received the target function signal sent by the braking system.
[0118] For example, after the braking system sends a target function signal to the vehicle gateway, it will be in a waiting state for a response. At this time, if the vehicle gateway sends a response signal to the braking system, the braking system will receive the response signal corresponding to the target function signal sent by the vehicle gateway.
[0119] S303, in response to the response signal, sends the first verification field corresponding to the target function signal to the vehicle gateway.
[0120] For example, after receiving a response signal from the vehicle gateway, the braking system indicates that the vehicle gateway has successfully received the target function signal; in response to the response signal, the system sends the first verification field corresponding to the target function signal to the vehicle gateway, so that the vehicle gateway can verify the target function signal through the first verification field.
[0121] Optionally, the first verification field can be calculated by the braking system based on the target function signal before sending the target function signal, and pre-stored; after receiving the response signal, the pre-stored first verification field is directly sent to the vehicle gateway. Alternatively, after receiving the response signal, the corresponding target function signal is determined based on the identifier of the response signal, and then the first verification field is calculated based on the target function signal; and the first verification field is sent to the vehicle gateway.
[0122] In one implementation, the process of generating the first verification field based on the target function signal may specifically include: generating the first verification field based on the target function signal and the target algorithm, wherein the target algorithm is the algorithm corresponding to the secure vehicle communication verification.
[0123] For example, vehicle gateways and vehicle hosts need to perform Secure In-Vehicle Communication (SecOC) verification on functional signals. Correspondingly, the braking system needs to calculate the verification field required for SecOC verification based on the target functional signal. Therefore, after generating the target functional signal, the braking system can use the target algorithm corresponding to SecOC verification to calculate the corresponding first verification field based on the target functional signal. Then, the first verification field can be sent to the vehicle gateway so that the vehicle gateway can perform SecOC verification on the target functional signal based on the first verification field to determine whether there is a transmission anomaly in the target functional signal.
[0124] In this embodiment, the braking system uses the target algorithm corresponding to the secure vehicle communication verification to calculate the first verification field corresponding to the target function signal, so that the vehicle gateway can perform secure communication network verification on the target function signal to ensure the security of vehicle network communication.
[0125] In summary, in this embodiment, the braking system first sends the target function signal to the vehicle gateway. After receiving the response signal from the vehicle gateway, it then sends the target verification field corresponding to the target function signal to the vehicle gateway. Sending the function signal and verification field in batches not only enables secure verification of the function signal but also avoids the situation where a low-configuration braking system cannot simultaneously send the function signal and the verification field required for secure vehicle communication verification, which could lead to errors in function signal verification by the vehicle gateway and the vehicle host, resulting in abnormal braking function. This further improves the accuracy of the secure verification of the function signal.
[0126] Figure 4This is a schematic flowchart illustrating another vehicle communication method provided in an embodiment of this application. It should be understood that this method can be applied to vehicles equipped with an on-board gateway, braking system, and on-board host.
[0127] For example, such as Figure 4 As shown, the method 400 includes the following steps S401 to S407.
[0128] S401, the vehicle's braking system calculates the target verification field corresponding to the target function signal based on the target function signal.
[0129] The target verification field is the verification field required for Secure In-Vehicle Communication (SecOC) verification; it may include the target freshness value and the target CMAC value.
[0130] For example, there is a signal communication connection between the braking system, the vehicle gateway, and the vehicle host in the vehicle. In order to ensure the security of signal transmission between different nodes, the braking system needs to calculate the target verification field corresponding to the target function signal based on the target function signal, so that other modules can verify the target function signal based on the target verification field.
[0131] Optionally, the meaning of the content indicated by the function signals can be found in [reference needed]. Figure 2 The relevant descriptions in S201 are not repeated here in the embodiments of this application.
[0132] Alternatively, the implementation of S401 can be found in [reference needed]. Figure 3 The relevant descriptions are omitted here, as are the embodiments of this application.
[0133] S402, the braking system sends a target function signal to the vehicle gateway.
[0134] For example, when the vehicle is powered on, the braking system sends a target function signal to the vehicle gateway in real time, so that the vehicle gateway and other system modules can monitor and apply the braking system-related signals.
[0135] It should be understood that lower-spec Electronic Stability Program (ESP) systems can only transmit signals via the CAN bus. Since CAN signals can only carry 8 bytes, the system cannot synchronously send the fields required for safety verification along with the target function signal to the vehicle gateway during signal transmission. Therefore, the braking system first sends the target function signal to the vehicle gateway.
[0136] Alternatively, the implementation of S402 can be found in [reference needed]. Figure 3 The relevant descriptions are omitted here, as are the embodiments of this application.
[0137] S403: After receiving the target function signal, the vehicle gateway sends a positive response signal to the braking system.
[0138] The positive response signal indicates that the vehicle gateway has successfully received the target function signal sent by the braking system.
[0139] For example, after receiving the target function signal sent by the braking system, the vehicle gateway temporarily stores the target function signal and does not directly route the target function signal to the vehicle host; and returns a positive response signal to the braking system so that the braking system knows that the vehicle gateway has successfully received the target function signal.
[0140] Alternatively, the implementation of S403 can be found in [reference needed]. Figure 2 The relevant description of S201 is not repeated here in the embodiments of this application.
[0141] S404: After receiving a positive response signal, the braking system sends the target verification field to the vehicle gateway.
[0142] For example, after receiving a positive response signal from the vehicle gateway, the braking system, in response to the positive response signal, sends the target verification field calculated based on the target function signal to the vehicle gateway for processing.
[0143] Alternatively, the implementation of S404 can be found in [reference needed]. Figure 3 The relevant descriptions are omitted here, as are the embodiments of this application.
[0144] Optionally, S401 can be executed before step S402; or it can be executed after receiving a positive response signal from the vehicle gateway in S404. This application embodiment does not limit this.
[0145] For example, after receiving a positive response signal, the braking system generates a target verification field corresponding to the target function signal based on the target function signal, and sends the target verification field to the vehicle gateway.
[0146] S405, the vehicle gateway verifies the target function signal based on the target verification field to determine whether the target function signal has been successfully verified. If yes, proceed to step S406; otherwise, proceed to step S407.
[0147] For example, after receiving the target verification field corresponding to the target function signal sent by the braking system, the vehicle gateway verifies the target function signal according to the target verification field to determine the verification result and determine whether there is a transmission abnormality in the target function signal during transmission.
[0148] Optionally, the process of verifying the target function signal based on the target verification field may include: using the target algorithm corresponding to the safe vehicle communication verification, generating candidate verification fields based on the target function signal; comparing whether the candidate verification fields and the target verification fields are consistent; if the candidate verification fields and the target verification fields are consistent, it is determined that the target function signal verification is successful; if the candidate verification fields and the target verification fields are inconsistent, it is determined that the target function signal verification fails.
[0149] Alternatively, the implementation of S405 can be found in [reference needed]. Figure 2 The relevant description of S202 is not repeated here in the embodiments of this application.
[0150] S406, the vehicle gateway routes the target function signal to the vehicle host.
[0151] For example, when the target function signal is successfully verified, the vehicle gateway routes the target function signal to the vehicle host so that the vehicle host can perform subsequent processing and application of the target function signal.
[0152] Optionally, when the vehicle gateway successfully verifies the target function signal, it indicates that the path between the braking system and the vehicle gateway is relatively secure. To further ensure the security of the path between the vehicle gateway and the vehicle host, the vehicle gateway can use a target algorithm to generate a corresponding second target verification field based on the target function signal. Since the vehicle gateway supports CAN FD signals, the target function signal and the second target verification field can be combined and sent to the vehicle host. The vehicle host can then perform Secure In-Vehicle Communication (SecOC) verification on the target function signal based on the second target verification field to ensure that the target function signal used in other systems is a secure signal that has not been tampered with or illegally accessed.
[0153] Alternatively, the implementation of S406 can be found in [reference needed]. Figure 2 The relevant description of S203 is not repeated here in the embodiments of this application.
[0154] S407, the vehicle gateway sends a negative response signal to the vehicle host.
[0155] For example, when the target function signal verification fails, the vehicle gateway sends a negative response signal to the vehicle host to indicate that the target function signal verification failed and there is an anomaly in the transmission process.
[0156] Alternatively, the implementation of S407 can be found in [reference needed]. Figure 2 The relevant description of S203 is not repeated here in the embodiments of this application.
[0157] In summary, in this embodiment, the braking system first sends the target function signal to the vehicle gateway. Upon receiving a positive response signal from the vehicle gateway, it then sends the target verification field corresponding to the target function signal to the vehicle gateway. This solves the problem that low-configuration braking systems cannot simultaneously send the function signal and the verification field required for SecOC verification, improving the compatibility of SecOC verification with various braking systems. Subsequently, the vehicle gateway can perform secure vehicle communication verification on the target function signal based on the received target verification field to determine if there are any anomalies in the transmission process, ensuring the security of the function signal and avoiding braking function anomalies due to security verification failures.
[0158] The above text combined Figures 2 to 4 The vehicle communication method provided in the embodiments of this application is described in detail below; the following will be combined with Figure 5 and Figure 7 The apparatus embodiments of this application are described in detail below. It should be understood that the apparatus in the embodiments of this application can perform the various methods described in the foregoing embodiments of this application, that is, the specific working processes of the various products described below can be referred to the corresponding processes in the foregoing method embodiments.
[0159] Figure 5 This is a schematic diagram of the structure of a vehicle communication device provided in an embodiment of this application.
[0160] For example, such as Figure 5 As shown, the vehicle communication device 500 includes:
[0161] The first receiving module 501 is used to receive the target function signal and the first verification field corresponding to the target function signal sent by the braking system in the vehicle.
[0162] The verification module 502 is used to verify the target function signal based on the first verification field;
[0163] The first transmitting module 503 is used to send the target function signal to the vehicle host if the target function signal verification is successful, so that the vehicle host can verify the target function signal.
[0164] In one possible implementation, the vehicle communication device 500 further includes a fourth transmitting module, which, upon receiving a target function signal transmitted by the braking system, transmits a response signal corresponding to the target function signal to the braking system, wherein the response signal is used to indicate that the vehicle gateway has received the target function signal.
[0165] In one possible implementation, the verification module 502 is further configured to generate a second verification field based on the target function signal and the target algorithm, wherein the target algorithm is the algorithm corresponding to the secure vehicle communication verification; and to verify the target function signal based on the first verification field and the second verification field.
[0166] In one possible implementation, the verification module 502 is further configured to determine that the target function signal verification is successful if the first verification field and the second verification field are consistent; and to determine that the target function signal verification fails if the first verification field and the second verification field are inconsistent.
[0167] Figure 6 This is a schematic diagram of another vehicle communication device provided in an embodiment of this application.
[0168] For example, such as Figure 6 As shown, the vehicle communication device 600 includes:
[0169] The second transmitting module 601 is used to send a target function signal to the vehicle's on-board gateway.
[0170] The second receiving module 602 is used to receive the response signal corresponding to the target function signal sent by the vehicle gateway;
[0171] The third sending module 603 is used to send the first verification field corresponding to the target function signal to the vehicle gateway in response to the response signal.
[0172] In one possible implementation, the third sending module 603 is further configured to generate a first verification field based on the target function signal in response to the response signal; and send the first verification field to the vehicle gateway.
[0173] In one possible implementation, the third sending module 603 is further configured to generate a first verification field based on the target function signal and the target algorithm, wherein the target algorithm is the algorithm corresponding to the secure vehicle communication verification.
[0174] It should be noted that the aforementioned vehicle communication device is embodied in the form of a functional unit. The term "module" here can be implemented in software and / or hardware, without specific limitations.
[0175] For example, a "module" can be a software program, hardware circuit, or a combination of both that implements the above functions. Hardware circuits may include application-specific integrated circuits (ASICs), electronic circuits, processors (e.g., shared processors, proprietary processors, or group processors) and memory for executing one or more software or firmware programs, combined logic circuits, and / or other suitable components that support the described functions.
[0176] Therefore, the units of the various examples described in the embodiments of this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0177] Figure 7 This is a schematic diagram of the structure of a vehicle provided in an embodiment of this application.
[0178] For example, such as Figure 7 As shown, the vehicle 700 includes a memory 701 and a processor 702, wherein the memory 701 stores executable program code 703, and the processor 702 is used to call and execute the executable program code 703 to perform a vehicle communication method.
[0179] Furthermore, embodiments of this application also protect an apparatus that may include a memory and a processor, wherein the memory stores executable program code, and the processor is used to call and execute the executable program code to perform a vehicle communication method provided in embodiments of this application.
[0180] This embodiment can divide the device into functional modules based on the above method example. For example, each module can correspond to a separate function, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware. It should be noted that the module division in this embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0181] When the functional modules are divided according to their respective functions, the device may further include a first receiving module, a verification module, a first transmitting module, a second transmitting module, a second receiving module, and a third transmitting module. It should be noted that all relevant content of each step involved in the above method embodiments can be referenced to the functional description of the corresponding functional module, and will not be repeated here.
[0182] It should be understood that the device provided in this embodiment is used to execute the above-described vehicle communication method, and therefore can achieve the same effect as the above-described implementation method.
[0183] When using an integrated unit, the device may include a processing module and a storage module. When the device is applied to a vehicle, the processing module can be used to control and manage the vehicle's movements. The storage module can be used to support the vehicle in executing relevant program code.
[0184] The processing module may be a processor or a controller, which can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination of functions that implement computing capabilities, such as a combination of one or more microprocessors, a combination of digital signal processing (DSP) and a microprocessor, etc., and the storage module may be a memory.
[0185] In addition, the device provided in the embodiments of this application may specifically be a chip, component or module. The chip may include a connected processor and a memory. The memory is used to store instructions. When the processor calls and executes the instructions, the chip can execute a vehicle communication method provided in the above embodiments.
[0186] This embodiment also provides a computer-readable storage medium storing computer program code. When the computer program code is run on a computer, the computer executes the above-described related method steps to implement the vehicle communication method provided in the above embodiment.
[0187] The computer-readable storage medium may include, but is not limited to, any type of disk, including floppy disks, optical disks, Digital Video Discs (DVDs), Compact Disc Read-Only Memory (CD-ROM), microdrives, and magneto-optical disks, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), dynamic random access memory (DRAM), video random access memory (VRAM), flash memory devices, magnetic cards or optical cards, nanosystems (including molecular memory ICs), or any type of medium or device suitable for storing instructions and / or data.
[0188] This embodiment also provides a computer program product that, when run on a computer, causes the computer to perform the aforementioned related steps to implement a vehicle communication method provided in the above embodiment.
[0189] In this embodiment, the device, computer-readable storage medium, computer program product, or chip are all used to execute the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0190] Through the above description of the embodiments, those skilled in the art will understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0191] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0192] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A vehicle communication method, characterized in that, The method is applied to an in-vehicle gateway, and the method includes: Receive the target function signal sent by the braking system in the vehicle and the first verification field corresponding to the target function signal; The target function signal is verified based on the first verification field; If the target function signal is successfully verified, the target function signal is sent to the vehicle host so that the vehicle host can verify the target function signal. The step of verifying the target function signal based on the first verification field includes: Based on the target function signal and the target algorithm, a second verification field is generated, wherein the target algorithm is the algorithm corresponding to the secure vehicle communication verification. The target function signal is verified based on the first verification field and the second verification field; The verification of the target function signal based on the first verification field and the second verification field includes: If the first verification field and the second verification field are consistent, the target function signal verification is successful. If the first verification field and the second verification field are inconsistent, the target function signal verification is determined to have failed.
2. The method according to claim 1, characterized in that, The method further includes: Upon receiving the target function signal sent by the braking system, a response signal corresponding to the target function signal is sent to the braking system, wherein the response signal is used to indicate that the vehicle gateway has received the target function signal.
3. A vehicle communication method, characterized in that, The method is applied to a braking system, and the method includes: Send the target function signal to the vehicle's onboard gateway; Receive the response signal corresponding to the target function signal sent by the vehicle gateway; In response to the response signal, the first verification field corresponding to the target function signal is sent to the vehicle gateway; Wherein, the step of sending the first verification field corresponding to the target function signal to the vehicle gateway in response to the response signal includes: In response to the response signal, a first verification field is generated based on the target function signal; Send the first verification field to the vehicle gateway; The step of generating a first verification field based on the target function signal includes: Based on the target function signal and the target algorithm, the first verification field is generated, wherein the target algorithm is the algorithm corresponding to the secure vehicle communication verification.
4. A vehicle communication device, characterized in that, The device is used in a vehicle-mounted gateway, and the device includes: The first receiving module is used to receive the target function signal sent by the braking system in the vehicle and the first verification field corresponding to the target function signal; The verification module is used to verify the target function signal based on the first verification field; The first sending module is configured to send the target function signal to the vehicle host if the target function signal verification is successful, so that the vehicle host can verify the target function signal; The verification module is further configured to generate a second verification field based on the target function signal and the target algorithm, wherein the target algorithm is an algorithm corresponding to the verification of secure vehicle communication; and to verify the target function signal based on the first verification field and the second verification field. The verification module is further configured to determine that the target function signal verification is successful if the first verification field and the second verification field are consistent; and to determine that the target function signal verification fails if the first verification field and the second verification field are inconsistent.
5. A vehicle communication device, characterized in that, The device is used in a braking system, and the device includes: The second transmitting module is used to send the target function signal to the vehicle's on-board gateway. The second receiving module is used to receive the response signal corresponding to the target function signal sent by the vehicle gateway; The third sending module is used to send the first verification field corresponding to the target function signal to the vehicle gateway in response to the response signal; The third sending module is further configured to, in response to the response signal, generate a first verification field based on the target function signal; and send the first verification field to the vehicle gateway. The third sending module is further configured to generate the first verification field based on the target function signal and the target algorithm, wherein the target algorithm is the algorithm corresponding to the secure vehicle communication verification.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, implements the method as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Vehicle-mounted gateway routing table self-learning method and device, vehicle and storage medium
CN118802712A
Gateway device, on-vehicle network system and transfer method
JP2017050848A