Service access control method and device, electronic equipment and storage medium
By detecting whether the service traffic data between the controller and the access device in the car is abnormal, and revoking the authorization when an abnormality is found, the problem of abnormal vehicle communication function caused by malicious control is solved, and the security of vehicle communication is improved.
Patent Information
- Application Number
- CN202510019451.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-05-06
AI Technical Summary
In a car, if the behavior changes after accessing the device (such as malicious control), it may not be discovered in time, resulting in abnormal communication functions of the entire vehicle.
By obtaining the service traffic data between the controller and the authorized access device, detect whether the data is abnormal and revoke the authorization of the access device when an exception is discovered.
Ensure the safety and reliability of in-car service access and improve the security of vehicle communication.
Smart Images

Figure CN119945752A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and more specifically, to a service access control method, device, electronic device and storage medium. Background Art
[0002] At present, with the popularization of vehicles and the development of software-defined cars, the service-oriented architecture (SOA) design concept has gradually been introduced into the design of automotive software architecture. SOA realizes the modularization and flexible combination of vehicle functions by servitizing the functions of the entire vehicle, meets new functional requirements, and provides users with a more intelligent and personalized experience. Under this architecture, the various functional modules of the vehicle can be called and combined like services, thereby improving the flexibility and scalability of the system.
[0003] In the existing technology, in order to realize the vehicle function service, the access device is usually authenticated, and the access device is authorized after the authentication is passed, so that the access device can be used to realize the vehicle function service. However, the inventor has found through research that in the related technology, due to the increase in the interaction between the car and the outside world, such as OBD, Bluetooth, 4G / 5G, etc., after the access device is authorized, if the behavior of the access device changes (such as being maliciously controlled), it may not be discovered in time, which may cause abnormal communication function of the whole vehicle. Summary of the invention
[0004] In view of this, the embodiments of the present application propose a service access control method, device, electronic device and storage medium, which can detect whether the service traffic data of the interaction between the access device and the controller is abnormal when the access device has access authorization to the controller, and revoke the access authorization of the access device corresponding to the service traffic data to the controller when an abnormality is determined. This ensures that the in-vehicle service access is safe and reliable and improves the communication security of the entire vehicle.
[0005] In a first aspect, an embodiment of the present application provides a service access control method, the method comprising: obtaining service traffic data transmitted between a controller of a vehicle and at least one access device having access authorization to the controller; determining, based on the traffic category in the service traffic data, a traffic detection strategy corresponding to the service traffic data and an access device corresponding to the service traffic data; determining whether the service traffic data is abnormal based on the traffic detection strategy corresponding to the service traffic data; if it is determined that the service traffic data is abnormal, revoking the access authorization of the access device corresponding to the service traffic data to the controller.
[0006] In a second aspect, an embodiment of the present application provides a service access control device, which includes: a data acquisition module for acquiring service flow data transmitted between a controller of a vehicle and at least one access device having access authorization to the controller; an information determination module for determining, based on the flow category in the service flow data, a flow detection strategy corresponding to the service flow data and an access device corresponding to the service flow data; an abnormality determination module for determining whether the service flow data is abnormal based on the flow detection strategy corresponding to the service flow data; and an authorization revocation module for revokeing the access authorization of the access device corresponding to the service flow data to the controller when it is determined that the service flow data is abnormal.
[0007] In one possible implementation, a network switch is integrated in the controller; the data acquisition module includes a calling submodule and an acquisition submodule: the calling submodule is used to call the network switch to monitor the service flow data between the controller and at least one access device with access authorization to the controller; the acquisition submodule is used to acquire the service flow data monitored by the network switch.
[0008] In one possible implementation, the information determination module includes an access device determination submodule and a detection strategy determination submodule; the access device determination submodule is used to determine the access device corresponding to the service traffic data based on a first preset correspondence relationship and the traffic category in the service traffic data, wherein the first preset correspondence relationship stores multiple access devices and the traffic category corresponding to each access device; the detection strategy determination submodule is used to determine the traffic detection strategy corresponding to the service traffic data based on a second preset correspondence relationship and the traffic category in the service traffic data, wherein the second preset correspondence relationship stores multiple traffic categories and the detection strategy corresponding to each traffic category.
[0009] In one possible implementation, there is at least one detection strategy corresponding to each traffic category; the abnormality determination module is also used to determine whether there is a traffic detection strategy matching the service traffic data among the at least one traffic detection strategy corresponding to the service traffic data; if so, determine that the service traffic data is abnormal; if not, determine that the service traffic data is normal.
[0010] In one possible implementation, the data acquisition module is also used to acquire the service flow data between the controller of the vehicle and at least one access device with access authorization to the controller at each preset time interval; the abnormality determination module includes a statistical submodule and a matching submodule; the statistical submodule is used to count the number of service flow data belonging to the target type in the service flow data acquired within the preset time period when at least one of the flow detection strategies includes a target flow detection strategy that indicates whether the number of service flow data of the target type is greater than a preset threshold; the matching submodule is used to determine whether the service flow data of the target type matches the target flow detection strategy based on the statistical number and the preset threshold; if the statistical number is less than the preset threshold, the service flow data of the target type matches the flow detection strategy; if the statistical number is not less than the preset threshold, the service flow data of the target type matches the target flow detection strategy.
[0011] In one possible implementation, the service access control device further includes: an access request receiving module, a request response module, a first response generating module, a key receiving module, a key verification module, and a second response generating module. The request receiving module is used to receive an access request sent by an access device, wherein the access request carries a device identification of the access device; the request response module is used to determine, in response to the access request, whether a device identification corresponding to the access device is stored in a preset device list; the first response generating module is used to generate an access response and send it to the access device when it is determined that the device identification corresponding to the access device is stored; the key receiving module is used to receive a security key fed back by the access device in response to the access response; the key verification module is used to verify the security key based on a reference key corresponding to the device identification of the access device stored in the preset device list; the second response generating module is used to authorize the access device to access the controller when the verification is passed, and send a verification pass response to the access device, so that the access device confirms that it has accessed the controller when receiving the verification pass response.
[0012] In one possible implementation, the service access control device further includes: a service request receiving module, a control unit determining module, and a service request sending module. The service request receiving module is used to receive the service request sent by the access device, the service request carries service flow data, and the service flow data includes a target service ID; the control unit determining module is used to determine the target electronic control unit that executes the service request from multiple electronic control units associated with the controller according to the target service ID and a third preset correspondence, the third preset correspondence stores multiple preset service IDs and electronic control units that process service requests corresponding to each preset service ID; the service request sending module is used to send the service request to the target electronic control unit so that the target electronic control unit processes the service request.
[0013] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory; one or more programs are stored in the memory and configured to be executed by the processor to implement the above method.
[0014] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a program code is stored, wherein the above method is executed when the program code is executed by a processor.
[0015] In a fifth aspect, an embodiment of the present application provides a computer program product or a computer program, the computer program product or the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of a computer device obtains the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device performs the above method.
[0016] The embodiments of the present application provide a service access control method, device, electronic device and storage medium. The method includes: obtaining service flow data transmitted between a vehicle controller and at least one access device with access authorization to the controller; determining the flow detection strategy corresponding to the service flow data and the access device corresponding to the service flow data according to the flow category in the service flow data; determining whether the service flow data is abnormal according to the flow detection strategy corresponding to the service flow data; if it is determined that the service flow data is abnormal, revoking the access authorization of the access device corresponding to the service flow data to the controller. By adopting the above method, after the access device is authorized to access the controller, the service flow data between the access device and the controller can be continuously monitored, and the service flow data can be judged based on the predefined flow detection strategy to determine whether the service flow data is abnormal, and the access authorization of the corresponding access device to the controller can be revoked when the service flow data is determined to be abnormal, thereby making the vehicle's service access more secure and reliable, thereby improving the security of the entire vehicle communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0018] Figure 1 A schematic diagram of a process flow of a service access control method provided by an embodiment of the present application is shown;
[0019] Figure 2 Another flowchart of a service access control method provided by an embodiment of the present application is shown;
[0020] Figure 3 Another flowchart of a service access control method provided by an embodiment of the present application is shown;
[0021] Figure 4 A schematic diagram of a timing flow of a service access control method provided in an embodiment of the present application is shown;
[0022] Figure 5 Another flowchart of a service access control method provided by an embodiment of the present application is shown;
[0023] Figure 6 A connection block diagram of a vehicle provided by an embodiment of the present application is shown;
[0024] Figure 7 A connection block diagram of a service access control device proposed in an embodiment of the present application is shown;
[0025] Figure 8 A structural block diagram of an electronic device for executing the method of an embodiment of the present application is shown. DETAILED DESCRIPTION
[0026] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more comprehensive and complete and fully convey the concept of the example embodiments to those skilled in the art.
[0027] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present application. However, those skilled in the art will appreciate that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, known methods, devices, realizations or operations are not shown or described in detail to avoid blurring the various aspects of the application.
[0028] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microprocessor devices.
[0029] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.
[0030] It should be noted that the "multiple" mentioned in this article refers to two or more. "And / or" describes the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.
[0031] It should also be noted that in the embodiments of the present application, the collection, use, processing and storage of application information are all subject to the user's permission and must comply with the regulations of the region.
[0032] The present application provides a service access control method, which can be applied to an electronic device, which may be a server, a terminal device, a vehicle, or a combination of one or more of the above.
[0033] In some embodiments, the server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0034] The terminal device may be a smart phone, tablet computer, laptop computer, desktop computer, intelligent voice interaction device, smart home appliance, vehicle-mounted terminal, etc., but is not limited thereto.
[0035] In one possible implementation of the present application, the service control method may be executed by a controller of the vehicle.
[0036] Figure 1 The service access control method of the present application is specifically shown, and is described as being applicable to a controller of a vehicle. The method includes:
[0037] Step S110: Acquire service traffic data transmitted between a controller of a vehicle and at least one access device having access authorization of the controller.
[0038] Among them, the vehicle controller can specifically be the vehicle's central controller, which has high reliability and is the communication hub between the various subsystems inside the vehicle (such as the power system, body system, entertainment system, and assisted driving system, etc.) or various components (such as cameras, radars, air conditioning, and audio, etc.). It is used to manage and coordinate the operation of each subsystem, and is responsible for the routing and forwarding of data packets to ensure that data is transmitted correctly between various subsystems or components.
[0039] Access devices may include external devices (such as external purification equipment, vehicle performance monitoring equipment, and mobile terminals, etc.) and background servers (such as remote monitoring servers, data analysis servers, and software update servers, etc.) or vehicle-mounted devices (such as window control devices, sensors, etc.) and other physical devices that need to call the whole vehicle service. They may also be virtual devices that need to call the whole vehicle service, such as applications (such as navigation applications, music playback applications, or video playback applications, etc.).
[0040] Among them, an access device with access authorization to the controller can send a service request (such as a diagnostic request, a control command, a data query, etc.) to the controller, so that when the controller determines the corresponding electronic control unit according to the service request, the electronic control unit corresponding to the service request or the device connected to the electronic control unit or the installed program responds to the service request initiated by the service device.
[0041] The above step S110 may be to obtain the service flow data between the controller and the access device captured by a network sniffer, data recorder, network analyzer, etc. set on the network interface of the vehicle. It may also be to obtain the service flow data between the controller and the access device recorded in the log of each external device. It may also be to record the service flow data using the monitoring tool provided by the cloud platform when the central controller and the access device of the vehicle are connected to the cloud platform.
[0042] When obtaining the service flow data between the controller and the access device, it can be obtained in real time or at intervals of a preset duration (eg, every 5 seconds, 10 seconds, 30 seconds, etc.).
[0043] In one possible implementation, a network switch is integrated in the controller; the above step S110 may specifically include step a and step b.
[0044] Step a: Invoking the network switch to monitor service traffic data between the controller and at least one access device having access authorization to the controller.
[0045] The network switch may specifically be a TSN switch (Time-Sensitive Networking (TSN) Switch).
[0046] A mirror port can be configured on a network switch, and the service flow data on the interface on the controller or the specified VLAN can be copied to the mirror port to monitor the service flow data between the controller and the access device in real time, and record all monitored service flow data. The service flow data may include timestamp, source address, destination address, protocol type, packet size, data length, and service ID, etc. It may also include a virtual LAN identifier (i.e., VLAN identifier), priority identifier, etc., which are used to distinguish the flow category of the service flow data.
[0047] Among them, service ID refers to a unique identifier assigned in the vehicle network to distinguish and manage different services. Each service ID corresponds to a specific function or service. The controller can identify and manage different service requests through the service ID. In order to distinguish the service traffic data corresponding to different access devices, the service ID intervals corresponding to different access devices are usually different, and different access devices correspond to traffic categories. For example, Table 1 shows the service ID intervals and corresponding traffic categories of the open services corresponding to different access devices. Table 1 is as follows:
[0048]
[0049] Exemplarily, external device 1 can be a terminal used to control basic control functions of the vehicle. The service ID corresponding to external device 1 ranges from 0x1001 to 0x1030. The basic control functions include window control, door lock control, light control, etc. Specifically, the function corresponding to service ID 0x1001 is window lift control; the function corresponding to service ID 0x1002 is door lock control; the function corresponding to service ID 0x1003 is headlight switch; and the function corresponding to service ID 0x1004 is taillight switch. APP1 is a navigation APP, and the corresponding service ID range is 0x2001 and 0x3001-0x3003. The service corresponding to service ID 0x2001 is navigation service; the service corresponding to service ID 0x3001-0x3003 is entertainment system service. Specifically, the function corresponding to service ID 0x3001 is audio playback control; the function corresponding to service ID 0x3002 is navigation content playback control on the vehicle display screen; the function corresponding to service ID 0x3003 is to control the channel selection of the vehicle radio, such as FM / AM broadcast control. External device 2 can be an air purifier for purifying the air in the vehicle. The corresponding service ID is 0x1040-0x1041. The service corresponding to service ID 0x1040 is the air purifier switch, and the service corresponding to service ID 0x1041 is the air purifier power control.
[0050] Step b: Acquire the service flow data monitored by the network switch.
[0051] Specifically, the controller may acquire the service flow data monitored by the network switch in real time, or the controller may acquire the service flow data monitored by the network switch at preset time intervals.
[0052] The above preset duration can be 5 seconds, 10 seconds, 30 seconds, etc., and can be set according to actual needs.
[0053] Step S120: Determine the traffic detection strategy corresponding to the service traffic data and the access device corresponding to the service traffic data according to the traffic category in the service traffic data.
[0054] Different traffic categories may correspond to different access devices, and the access device corresponding to the service traffic data may be determined based on the traffic category. Exemplarily, the traffic category may specifically include one or more of the destination MAC address, source MAC address, VLAN ID, priority ID, destination IP address, and source IP address. Different traffic categories may also correspond to different traffic detection strategies, and the traffic detection strategy corresponding to the service traffic data may be determined based on the traffic category in the service traffic data, wherein the traffic detection strategy is used to detect whether the corresponding service traffic data is normal.
[0055] It is worth mentioning that when the access device is an APP or an in-vehicle device, its traffic category can be any one of the destination MAC address, source MAC address and priority identifier; when the access device is an external device, its traffic category can be any one of the VLAN identifier, destination IP address, source IP address and priority identifier. Among them, the destination MAC address and source MAC address can be used to accurately identify the service traffic data of the access device as a built-in device of the vehicle; the destination IP address and source IP address can be used to identify the source and destination of the service traffic data of the access device as an external device of the vehicle; the priority identifier can be used to identify the priority of the service traffic data of the access device. The VLAN identifier can be used to identify the corresponding specific VLAN of the service traffic data of the access device as an external device of the vehicle.
[0056] The traffic detection strategy may include: traffic data length judgment strategy, traffic rate judgment strategy, and message quantity judgment strategy for matching flow filters. Among them, the traffic data length judgment strategy can be used to judge whether the length of the traffic data packet corresponding to the service traffic data is greater than the preset bytes. If it is greater, it is abnormal, and if it is less, it is normal; the traffic rate judgment strategy can be used to judge whether the traffic rate corresponding to the service traffic data is greater than the preset bits per second. If it is greater, it is abnormal, and if it is less, it is normal; the message quantity judgment strategy for matching flow filters is used to judge whether the number of service traffic data of the same type (such as the same source MAC address, the same destination MAC address, the same source IP address or the same destination IP address, etc.) in a unit time is greater than the preset number threshold. If it is greater, it is abnormal, and if it is less, it is normal,
[0057] Specifically, in one possible implementation, the above step S120 includes step c and step d.
[0058] Step c: Determine the access device corresponding to the service traffic data according to a first preset correspondence relationship and the traffic category in the service traffic data, wherein the first preset correspondence relationship stores a plurality of access devices and the traffic category corresponding to each access device.
[0059] Exemplarily, if a service traffic data contains the following information: the destination MAC address is 00:11:22:33:44:55; the source MAC address is 66:77:88:99:AA:BB; the VLAN identifier is 2; the priority identifier (PCP) is 0; the destination IP address is 192.168.1.1; the source IP address is 192.168.1.2; the first preset correspondence includes: the traffic category corresponding to external device 1 is VLAN identifier = 2; the traffic category corresponding to APP1 is priority identifier (PCP) = 2; the traffic category corresponding to external device 2 is VLAN identifier = 3; then according to the first preset correspondence and the traffic category in the service traffic data (i.e., VLAN identifier is 2), the matching access device is found to be external device 1.
[0060] Step d: Determine the traffic detection strategy corresponding to the service traffic data according to the second preset correspondence relationship and the traffic category in the service traffic data, wherein the second preset correspondence relationship stores a plurality of traffic categories and a detection strategy corresponding to each traffic category.
[0061] Among them, different traffic categories correspond to different traffic detection strategies, and each traffic category corresponds to one or more traffic detection strategies.
[0062] Exemplarily, if a service flow data contains the following information: the destination MAC address is 00:11:22:33:44:55; the source MAC address is 66:77:88:99:AA:BB; the VLAN ID is 2; the priority ID (PCP) is 0; the destination IP address is 192.168.1.1; the source IP address is 192.168.1.2; the second preset correspondence includes: the flow category ID is VLAN ID = 2, which corresponds to flow detection strategy 1 (such as flow rate does not exceed 2Mbps); the flow category ID is priority ID (PCP) = 2, which corresponds to flow detection strategy 2 (such as high priority, flow priority processing); the flow category ID is VLAN ID = 3, which corresponds to flow detection strategy 3 (such as flow rate does not exceed 1Mbps). Then according to the second preset correspondence and the flow category in the service flow data (that is, VLAN ID is 2), the matching flow detection strategy is found to be flow detection strategy 1.
[0063] Exemplarily, as shown in Table 3, the corresponding relationship between the traffic category of service traffic data and the traffic detection strategy is shown. Table 3 is as follows:
[0064]
[0065] It is worth mentioning that when there are multiple service flow data obtained in step S110, the access device corresponding to each service flow data and the flow detection strategy corresponding to each service flow data can be obtained by adopting the above steps.
[0066] Step S130: Determine whether the service traffic data is abnormal according to the traffic detection strategy corresponding to the service traffic data.
[0067] In one possible implementation, each traffic category corresponds to at least one detection strategy, and the above step S130 may specifically be:
[0068] Determine whether there is a traffic detection strategy matching the service traffic data among at least one traffic detection strategy corresponding to the service traffic data; if so, determine that the service traffic data is abnormal; if not, determine that the service traffic data is normal.
[0069] In one possible implementation, see Figure 2 , the above step S110 is specifically: obtaining service flow data transmitted between the controller and at least one access device having access authorization of the controller at every preset time interval. In this case, if at least one of the flow detection strategies includes a target flow detection strategy indicating whether the amount of service flow data of a target type is greater than a preset threshold, the above step S130 includes:
[0070] Step S132: Counting the number of service flow data belonging to the target type in the service flow data acquired within the preset time period.
[0071] Step S134: Determine whether the service traffic data of the target type matches the target traffic detection strategy according to the statistical quantity and the preset threshold.
[0072] Among them, if the statistical quantity is less than the preset threshold, the service traffic data of the target type matches the traffic detection strategy; if the statistical quantity is not less than the preset threshold, the service traffic data of the target type matches the target traffic detection strategy.
[0073] It is worth mentioning that, in the above case, if at least one traffic detection strategy only includes the target traffic detection strategy, then when the service traffic data of the target type matches the target traffic detection strategy, the service traffic data is determined to be abnormal; and when the service traffic data of the target type does not match the traffic detection strategy, the service traffic data is determined to be normal. If at least one traffic detection strategy also includes other traffic detection strategies, then when the service traffic data of the target type matches any one of the traffic detection strategy or other traffic detection strategies, the service traffic data of the target type is determined to be abnormal; and when the service traffic data of the target type does not match the target traffic detection strategy or other traffic detection strategies, the service traffic data of the target type is determined to be normal.
[0074] Exemplarily, if the service traffic data of the target type is a message detected to be sent to the controller from the MAC address corresponding to the in-vehicle navigation APP, and the number of such messages exceeds 20 within 5 seconds, it is determined that the service traffic data of the target type is abnormal.
[0075] Step S140: If it is determined that the service flow data is abnormal, revoke the access authorization of the access device corresponding to the service flow data to the controller.
[0076] Specifically, the controller may maintain a list of access rights of various access devices to the controller, and the controller may update the access right information of the access device corresponding to the service traffic data in the access right list to revoke the access right of the access device to the controller. In some implementations, after revoking the access authorization of the access device corresponding to the abnormal service traffic data to the controller, the controller may also send a permission revocation notification to the access device.
[0077] For example, when the traffic category is VLAN ID = 8 and the corresponding traffic detection policy indicates that the maximum traffic rate is 2Mbps, if the traffic rate of the detected service traffic data is greater than 2, the service traffic data is considered to be abnormal. At this time, it is necessary to revoke the authorization of the access device corresponding to the service traffic data so that the access device does not have access to the controller.
[0078] By adopting the applied service access control method, it is possible to continuously monitor the service traffic data between the access device and the controller after the access device is authorized to access the controller, and determine whether the service traffic data is abnormal based on a predefined traffic detection strategy. When it is determined that the service traffic data is abnormal, the access authorization of the corresponding access device to the controller can be revoked, thereby making the vehicle's service access safer and more reliable, thereby improving the security of the entire vehicle communication.
[0079] In one possible implementation, please refer to Figure 3 and Figure 4 , the method further comprises:
[0080] Step S150: receiving an access request sent by an access device, wherein the access request carries a device identification of the access device.
[0081] Specifically, the controller may receive the access request sent by the access device through a network interface (such as Ethernet, Wi-Fi, Bluetooth, etc.) The above-mentioned device identification may be a MAC address of the device or any information that can uniquely identify the device.
[0082] Step S160: In response to the access request, determine whether a device identifier corresponding to the access device is stored in a preset device list.
[0083] The controller maintains a preset device list, which stores the device identifiers of all access devices allowed to access. When receiving an access request, the controller can search the preset device list for the device identifier carried in the access request. Exemplarily, the above-mentioned device identifier can be the MAC address of the device, and the preset device list stores the MAC addresses of all access devices allowed to access.
[0084] Step S170: If it is determined that the device identification corresponding to the access device is stored, an access response is generated and sent to the access device.
[0085] The access response is information indicating that the access request has been accepted. It is worth mentioning that if it is determined that the device identifier corresponding to the access device is not stored, an access exception feedback will be generated to indicate that the access request has not been accepted. The access response or access exception feedback can be sent to the access device through the network interface of the controller.
[0086] Step S180: receiving the security key fed back by the access device in response to the access response.
[0087] The security key may be pre-generated by the access device, or may be generated by the access device by encrypting the device identification of the access device using a preset encryption algorithm, which is not specifically limited here.
[0088] Step S190: verifying the security key based on a reference key corresponding to the device identification of the access device and stored in the preset device list.
[0089] In one possible implementation, the reference key may be compared with the security key. If the comparison is consistent, the security key is verified successfully, otherwise the verification fails.
[0090] In another possible implementation, the reference key stored in the preset device list is a public key, and the security key generated by the access device is a digital signature, which is obtained by signing a message (such as a device identification) using a private key. The digital signature can then be verified using the public key. If the verification passes, the verification passes, otherwise the verification fails.
[0091] Step S210: If the verification is successful, the access device is authorized, and a verification success response is sent to the access device, so that the access device confirms that it has accessed the controller when receiving the verification success response.
[0092] The access device is authorized to provide services to the vehicle or control components in the vehicle. The above verification response may carry the authorization information so that the access device can confirm that it has access to the controller when receiving the verification response.
[0093] By adopting the above steps S150-S210, it is possible to implement the preset device list and security key verification to ensure that only legitimate access devices can access the controller, thereby improving the security of access devices accessing the controller. Further, after the access device is authorized to access the controller, by executing the above steps S110-S140, it is achieved that
[0094] In one possible implementation, see Figure 5 , the method further comprises:
[0095] Step S220: receiving a service request sent by the access device.
[0096] The service request carries service traffic data, and the service traffic data includes a target service ID.
[0097] Specifically, the controller receives a service request sent by an access device through a network interface (such as Ethernet, Wi-Fi, Bluetooth, etc.), and extracts the service traffic data carried therein by parsing the service request.
[0098] Step S230: determining a target electronic control unit that executes the service request from a plurality of electronic control units associated with the controller according to the target service ID and a third preset correspondence.
[0099] The third preset correspondence relationship stores a plurality of preset service IDs and an electronic control unit for processing a service request corresponding to each preset service ID.
[0100] The above-mentioned electronic control unit can be specifically an ECU (Electronic Control Unit), which is a microcomputer responsible for executing specific functions, and the ECU can receive service requests from the central controller and perform corresponding processing according to the request content. Each preset service ID can correspond to an electronic control unit, and multiple preset service IDs can correspond to the same electronic control unit.
[0101] For example, Figure 6 As shown, the multiple electronic control units can be N in number, and different electronic control units can control different in-vehicle devices, and each electronic control unit is connected to the controller via the vehicle Ethernet. Among them, ECU1 can control the engine, such as adjusting the working state of the engine (such as adjusting the speed, injection amount, etc.), and the third preset correspondence stores multiple preset service IDs of ECU1 controlling the engine. ECU2 can control the braking system, such as adjusting the pressure of the braking system to achieve vehicle deceleration or parking, and the third preset correspondence stores multiple preset service IDs of ECU2 controlling the braking system. ECU3 can control the sensor, such as reading sensor data (such as temperature, pressure, speed, etc.), and the third preset correspondence stores multiple preset service IDs of ECU3 controlling the sensor. ECU4 can control the entertainment system, such as adjusting entertainment functions such as audio and navigation, and the third preset correspondence stores multiple preset service IDs of ECU4 controlling the entertainment system; ECU5 can collect data, that is, collect various data of the vehicle, such as mileage, fuel consumption, etc., and the third preset correspondence stores multiple preset service IDs of ECU5 collecting data.
[0102] Step S240: sending the service request to the target electronic control unit so that the target electronic control unit processes the service request.
[0103] For example, if the service request is to read the temperature inside the vehicle, the service request may be sent to ECU 3 so that ECU 3 reads the temperature inside the vehicle. If the service request is to adjust the volume of the audio, the service request may be sent to ECU 4 so that ECU 4 adjusts the volume of the audio.
[0104] By adopting the above steps S220-S240, the controller can accurately route the service request to the correct electronic control unit, avoiding unnecessary forwarding and processing, and improving the efficiency of the system. By setting up multiple electronic control units and centrally managing them by the controller, that is, the controller serves as a single entry point to receive all service requests from access devices, thereby simplifying the system architecture, reducing network complexity, and achieving the effect of a central deployment of multiple nodes (multiple electronic control units) in the whole vehicle. Furthermore, since each service request is processed by a specific electronic control unit, even if an electronic control unit fails, it will not affect the normal operation of other services, thereby improving the security of vehicle service access.
[0105] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0106] See also Figure 7 Another embodiment of the present application provides a service access control device 300, which includes: a data acquisition module 310, an information determination module 320, an abnormality determination module 330 and an authorization revocation module 340.
[0107] A data acquisition module 310 is used to acquire service flow data transmitted between a vehicle controller and at least one access device having access authorization to the controller; an information determination module 320 is used to determine, based on the flow category in the service flow data, a flow detection strategy corresponding to the service flow data and an access device corresponding to the service flow data; an abnormality determination module 330 is used to determine whether the service flow data is abnormal based on the flow detection strategy corresponding to the service flow data; an authorization revocation module 340 is used to revoke the access authorization of the access device corresponding to the service flow data to the controller when it is determined that the service flow data is abnormal.
[0108] In one possible implementation, a network switch is integrated in the controller; the data acquisition module 310 includes a calling submodule and an acquisition submodule: the calling submodule is used to call the network switch to monitor the service flow data between the controller and at least one access device with access authorization to the controller; the acquisition submodule is used to obtain the service flow data monitored by the network switch.
[0109] In one possible implementation, the information determination module 320 includes an access device determination submodule and a detection strategy determination submodule; the access device determination submodule is used to determine the access device corresponding to the service traffic data based on a first preset correspondence and the traffic category in the service traffic data, wherein the first preset correspondence stores multiple access devices and the traffic category corresponding to each access device; the detection strategy determination submodule is used to determine the traffic detection strategy corresponding to the service traffic data based on a second preset correspondence and the traffic category in the service traffic data, wherein the second preset correspondence stores multiple traffic categories and the detection strategy corresponding to each traffic category.
[0110] In one possible implementation, there is at least one detection strategy corresponding to each traffic category; the abnormality determination module 330 is also used to determine whether there is a traffic detection strategy matching the service traffic data among the at least one traffic detection strategy corresponding to the service traffic data; if so, it is determined that the service traffic data is abnormal; if not, it is determined that the service traffic data is normal.
[0111] In one possible implementation, the data acquisition module 310 is also used to acquire the service flow data between the controller of the vehicle and at least one access device with access authorization to the controller at each preset time interval; the abnormality determination module includes a statistical submodule and a matching submodule; the statistical submodule is used to count the number of service flow data belonging to the target type in the service flow data acquired within the preset time period when at least one of the flow detection strategies includes a target flow detection strategy that indicates whether the number of service flow data of the target type is greater than a preset threshold; the matching submodule is used to determine whether the service flow data of the target type matches the target flow detection strategy based on the statistical number and the preset threshold; if the statistical number is less than the preset threshold, the service flow data of the target type matches the flow detection strategy; if the statistical number is not less than the preset threshold, the service flow data of the target type matches the target flow detection strategy.
[0112] In one possible implementation, the service access control device 300 further includes: an access request receiving module, a request response module, a first response generating module, a key receiving module, a key verification module, and a second response generating module. The request receiving module is used to receive an access request sent by an access device, wherein the access request carries a device identification of the access device; the request response module is used to determine, in response to the access request, whether a device identification corresponding to the access device is stored in a preset device list; the first response generating module is used to generate an access response and send it to the access device when it is determined that a device identification corresponding to the access device is stored; the key receiving module is used to receive a security key fed back by the access device in response to the access response; the key verification module is used to verify the security key based on a reference key corresponding to the device identification of the access device stored in the preset device list; the second response generating module is used to authorize the access device to access the controller when the verification is passed, and send a verification pass response to the access device, so that the access device confirms that it has accessed the controller when receiving the verification pass response.
[0113] In one possible implementation, the service access control device 300 further includes: a service request receiving module, a control unit determining module, and a service request sending module. The service request receiving module is used to receive the service request sent by the access device, the service request carries service flow data, and the service flow data includes a target service ID; the control unit determining module is used to determine the target electronic control unit that executes the service request from multiple electronic control units associated with the controller according to the target service ID and a third preset correspondence, the third preset correspondence stores multiple preset service IDs and electronic control units that process service requests corresponding to each preset service ID; the service request sending module is used to send the service request to the target electronic control unit so that the target electronic control unit processes the service request.
[0114] Each module in the above-mentioned device can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each of the above modules. It should be noted that the device embodiment in this application corresponds to the aforementioned method embodiment. The specific principles in the device embodiment can be found in the contents of the aforementioned method embodiment, which will not be repeated here.
[0115] The following will be combined Figure 8 An electronic device provided by the present application is described.
[0116] See also Figure 8Based on the service access control method provided in the above embodiment, the embodiment of the present application also provides another electronic device 100 including a processor 102 that can execute the above method. The electronic device 100 can be a server, a terminal device or a vehicle. The terminal device can be a smart phone, a tablet computer, a computer or a portable computer and other devices.
[0117] The electronic device 100 further includes a memory 104 . The memory 104 stores a program that can execute the contents of the aforementioned embodiments, and the processor 102 can execute the program stored in the memory 104 .
[0118] Among them, the processor 102 may include one or more cores for processing data and a message matrix unit. The processor 102 uses various interfaces and lines to connect various parts of the entire electronic device 100, and executes various functions and processes data of the electronic device 100 by running or executing instructions, programs, code sets or instruction sets stored in the memory 104, and calling data stored in the memory 104. Optionally, the processor 102 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 102 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 102, but may be implemented separately through a communication chip.
[0119] The memory 104 may include a random access memory (RAM) or a read-only memory (ROM). The memory 104 may be used to store instructions, programs, codes, code sets or instruction sets. The memory 104 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function, instructions for implementing the following various method embodiments, etc. The data storage area may also store data (e.g., application information or skin images) acquired by the electronic device 100 during use.
[0120] The electronic device 100 may also include a network module and a screen. The network module is used to receive and send electromagnetic waves, realize the mutual conversion between electromagnetic waves and electrical signals, and thus communicate with a communication network or other devices, such as communicating with an audio playback device. The network module may include various existing circuit components for performing these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, user identity modules (SIM) cards, memories, and the like. The network module may communicate with various networks such as the Internet, corporate intranets, wireless networks, or communicate with other devices via wireless networks. The above-mentioned wireless networks may include cellular telephone networks, wireless local area networks, or metropolitan area networks. The screen may display interface content and perform data interaction, such as displaying the aforementioned interface, and triggering operations via the screen.
[0121] In some embodiments, the electronic device 100 may further include: a peripheral interface 106 and at least one peripheral device. The processor 102, the memory 104 and the peripheral interface 106 may be connected via a bus or a signal line. Each peripheral device may be connected to the peripheral interface via a bus, a signal line or a circuit board. Specifically, the peripheral device includes: at least one of a radio frequency component 108, a positioning component 112, a camera 114, an audio component 116, a display screen 118 and a power supply 122.
[0122] The peripheral interface 106 may be used to connect at least one peripheral device related to I / O (Input / Output) to the processor 102 and the memory 104. In some embodiments, the processor 102, the memory 104, and the peripheral interface 106 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 102, the memory 104, and the peripheral interface 106 may be implemented on a separate chip or circuit board, which is not limited in the embodiments of the present application.
[0123] The radio frequency component 108 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency component 108 communicates with the communication network and other communication devices through electromagnetic signals. The radio frequency component 108 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals into electrical signals. Optionally, the radio frequency component 108 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, and the like. The radio frequency component 108 can communicate with other terminals through at least one wireless communication protocol. The wireless communication protocol includes, but is not limited to: the World Wide Web, a metropolitan area network, an intranet, various generations of mobile communication networks (2G, 3G, 4G and 5G), a wireless local area network and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency component 108 may also include circuits related to NFC (Near Field Communication), which is not limited in this application.
[0124] The positioning component 112 is used to locate the current geographic location of the electronic device to implement navigation or LBS (Location Based Service). The positioning component 112 can be a positioning component based on the US GPS (Global Positioning System), Beidou system or Galileo system.
[0125] The camera 114 is used to capture images or videos. Optionally, the camera 114 includes a front camera and a rear camera. Usually, the front camera is arranged on the front panel of the electronic device 100, and the rear camera is arranged on the back of the electronic device 100. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth of field camera, a wide-angle camera, and a telephoto camera, so as to realize the fusion of the main camera and the depth of field camera to realize the background blur function, the fusion of the main camera and the wide-angle camera to realize the panoramic shooting and VR (Virtual Reality) shooting function or other fusion shooting functions. In some embodiments, the camera 114 may also include a flash. The flash can be a monochrome temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cold light flash, which can be used for light compensation at different color temperatures.
[0126] The audio component 116 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, and convert the sound waves into electrical signals and input them into the processor 102 for processing, or input them into the RF component 108 to achieve voice communication. For the purpose of stereo acquisition or noise reduction, there can be multiple microphones, which are respectively arranged at different parts of the electronic device 100. The microphone can also be an array microphone or an omnidirectional acquisition microphone. The speaker is used to convert the electrical signal from the processor 102 or the RF component 108 into sound waves. The speaker can be a traditional film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into sound waves inaudible to humans for purposes such as ranging. In some embodiments, the audio component 114 may also include a headphone jack.
[0127] The display screen 118 is used to display the UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 118 is a touch display screen, the display screen 118 also has the ability to collect touch signals on the surface or above the surface of the display screen 118. The touch signal can be input to the processor 102 as a control signal for processing. At this time, the display screen 118 can also be used to provide virtual buttons and / or virtual keyboards, also known as soft buttons and / or soft keyboards. In some embodiments, the display screen 118 can be one, and the front panel of the electronic device 100 is set; in other embodiments, the display screen 118 can be at least two, which are respectively set on different surfaces of the electronic device 100 or are folded; in some other embodiments, the display screen 118 can be a flexible display screen, which is set on the curved surface or folded surface of the electronic device 100. Even, the display screen 118 can also be set as a non-rectangular irregular shape, that is, a special-shaped screen. The display screen 118 can be made of materials such as LCD (Liquid Crystal Display), OLED (Organic Light-Emitting Diode, machine light-emitting diode).
[0128] The power supply 122 is used to power various components in the electronic device 100. The power supply 122 can be an alternating current, a direct current, a disposable battery, or a rechargeable battery. When the power supply 122 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery that is charged through a wired line, and a wireless rechargeable battery is a battery that is charged through a wireless coil. The rechargeable battery can also be used to support fast charging technology.
[0129] In one possible implementation, the electronic device includes a vehicle, and the processor includes a controller of the vehicle.
[0130] The embodiment of the present application also provides a structural block diagram of a computer-readable storage medium. The computer-readable medium stores program codes, which can be called by a processor to execute the method described in the above method embodiment.
[0131] The computer-readable storage medium may be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium has storage space for program codes that execute any of the method steps in the above method. These program codes can be read from or written to one or more computer program products. The program code can be compressed, for example, in an appropriate form.
[0132] The embodiment of the present application also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. The processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device performs the method described in the above various optional implementations.
[0133] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A service access control method, characterized in that: The method comprises: acquiring service flow data transmitted between a controller of the vehicle and at least one access device having access authorization of the controller; Determine, according to the traffic category in the service traffic data, a traffic detection strategy corresponding to the service traffic data and an access device corresponding to the service traffic data; Determining whether the service flow data is abnormal according to a flow detection strategy corresponding to the service flow data; If it is determined that the service traffic data is abnormal, the access authorization of the access device corresponding to the service traffic data to the controller is revoked.
2. The method according to claim 1, characterized in that: A network switch is integrated in the controller; The acquiring of service flow data transmitted between a controller of a vehicle and at least one access device having access authorization of the controller comprises: Invoking the network switch to monitor service traffic data between the controller and at least one access device having access authorization to the controller; Obtain service flow data monitored by the network switch.
3. The method according to claim 1, characterized in that The determining, according to the traffic category in the service traffic data, a traffic detection strategy corresponding to the service traffic data and an access device corresponding to the service traffic data comprises: Determine the access device corresponding to the service traffic data according to a first preset correspondence relationship and the traffic category in the service traffic data, wherein the first preset correspondence relationship stores a plurality of access devices and the traffic category corresponding to each access device; The traffic detection strategy corresponding to the service traffic data is determined according to the second preset correspondence relationship and the traffic category in the service traffic data, wherein the second preset correspondence relationship stores a plurality of traffic categories and a detection strategy corresponding to each traffic category.
4. The method according to claim 3, characterized in that There is at least one detection strategy corresponding to each traffic category; Determining whether the service flow data is abnormal according to a flow detection strategy corresponding to the service flow data includes: Determine whether there is a traffic detection strategy matching the service traffic data among at least one traffic detection strategy corresponding to the service traffic data; if so, determine that the service traffic data is abnormal; if not, determine that the service traffic data is normal.
5. The method according to claim 4, characterized in that The acquiring of service flow data transmitted between a controller of a vehicle and at least one access device having access authorization of the controller comprises: Acquire service flow data between a controller of a vehicle and at least one access device having access authorization to the controller at intervals of a preset duration; The determining whether there is a traffic detection strategy matching the service traffic data in at least one traffic detection strategy corresponding to the service traffic data, comprises: If at least one of the traffic detection strategies includes a target traffic detection strategy for indicating whether the amount of service traffic data of a target type is greater than a preset threshold, the number of service traffic data belonging to the target type in the service traffic data acquired within the preset time period is counted; Determine whether the service traffic data of the target type matches the target traffic detection strategy based on the statistical quantity and the preset threshold; if the statistical quantity is less than the preset threshold, the service traffic data of the target type matches the traffic detection strategy; if the statistical quantity is not less than the preset threshold, the service traffic data of the target type matches the target traffic detection strategy.
6. The method according to claim 1, characterized in that Before acquiring the service flow data transmitted between the controller of the vehicle and at least one access device having access authorization of the controller, the method includes: Receiving an access request sent by an access device, wherein the access request carries a device identifier of the access device; In response to the access request, determining whether a device identifier corresponding to the access device is stored in a preset device list; If it is determined that a device identification corresponding to the access device is stored, generating an access response and sending it to the access device; Receiving a security key fed back by the access device in response to an access response; verifying the security key based on a reference key corresponding to the device identification of the access device stored in the preset device list; If the verification is successful, the access device is authorized, and a verification success response is sent to the access device, so that the access device confirms that it has accessed the controller when receiving the verification success response.
7. The method according to claim 6, characterized in that If the verification is successful, the access device is allowed to access, and a verification success response is sent to the access device, the method further includes: receiving a service request sent by the access device, wherein the service request carries service flow data, and the service flow data includes a target service ID; Determine a target electronic control unit that executes the service request from a plurality of electronic control units associated with the controller according to the target service ID and a third preset correspondence relationship, wherein the third preset correspondence relationship stores a plurality of preset service IDs and an electronic control unit that processes a service request corresponding to each preset service ID; The service request is sent to the target electronic control unit so that the target electronic control unit processes the service request.
8. A service access control device, characterized in that: The device comprises: a data acquisition module, configured to acquire service flow data transmitted between a controller of a vehicle and at least one access device having access authorization of the controller; An information determination module, used to determine, according to the traffic category in the service traffic data, a traffic detection strategy corresponding to the service traffic data and an access device corresponding to the service traffic data; An abnormality determination module, used to determine whether the service flow data is abnormal according to the flow detection strategy corresponding to the service flow data; The authorization revocation module is used to revoke the access authorization of the access device corresponding to the service flow data to the controller when it is determined that the service flow data is abnormal.
9. An electronic device, characterized in that: include: processor; Memory; One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, and the one or more programs are configured to execute the method according to any one of claims 1 to 7.
10. The electronic device according to claim 9, characterized in that: The electronic device comprises a vehicle and the processor comprises a controller of the vehicle.
11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, and the program codes can be called by a processor to execute the method according to any one of claims 1 to 7.
12. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method described in any one of claims 1 to 7 are implemented.