CAN bus anomaly detection method and device, vehicle controller and medium

By implementing the abnormal detection method of the CAN bus in a car, using messages and signal rules in the detection rule database to detect abnormalities of CAN packets, the problem of lack of information security mechanism of the CAN bus is solved, and the security of the bus and the stability of the vehicle electronic system are improved.

CN119945930AActive Publication Date: 2025-05-06CHERY NEW ENERGY AUTOMOBILE TECH CO LTD

Patent Information

Application Number
CN202510014237.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-05-06
Estimated Expiration
2045-01-06

AI Technical Summary

Technical Problem

The CAN bus lacks basic information security mechanisms in modern cars, resulting in malicious attacks directly penetrate into the on-board CAN bus network through external interfaces, threatening the performance, security and privacy of the vehicle.

Method used

A method for detecting an abnormality of the CAN bus is provided. By obtaining the CAN message to be detected, the corresponding message rules and signal rules are determined from the detection rule base based on the message type, the message identifier, length, transmission period and CAN signal of the message comply with the definition in the DBC file, and then determining whether there are abnormalities in the detection result and bus operation status of the CAN message.

Benefits of technology

This method can accurately determine the detection results of CAN messages, improve the security of the CAN bus, and ensure the stable operation of the vehicle electronic system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945930A_ABST
    Figure CN119945930A_ABST
Patent Text Reader

Abstract

The invention provides a CAN bus anomaly detection method and device, a vehicle controller and a medium, and belongs to the technical field of automobiles. The method comprises the following steps: acquiring a CAN message to be detected; based on the message type of the CAN message, determining a message rule and a signal rule corresponding to the CAN message from a detection rule base of the vehicle; detecting the CAN message based on the message rule and the signal rule to obtain a detection result of the CAN message; and when the detection result shows that the CAN message is the abnormal message, determining that the running state of the CAN bus is abnormal. According to the method, the detection result of the CAN message can be accurately determined, and whether the running state of the CAN bus of the vehicle is abnormal or not is judged based on the detection result, so that the safety of the CAN bus can be effectively improved, and stable running of a vehicle electronic system is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of automobile technology, and in particular to a CAN bus abnormality detection method, device, vehicle controller and medium. Background Art

[0002] CAN (Controller Area Network) bus is a communication network used to connect various electronic control units in modern automobiles. It has the advantages of strong anti-interference ability, reliable data transmission, fast data transmission, good flexibility, low cost, etc., and is widely used in the automotive field. However, with the emergence of automobile information security issues, malicious attacks directly penetrate into the on-board CAN bus network through external interfaces, posing a serious threat to the performance, safety and privacy of the vehicle. However, the current CAN bus lacks a basic information security mechanism. In order to improve the security of the CAN bus, it is very important to realize anomaly detection of the CAN bus. Therefore, a CAN bus anomaly detection method is urgently needed. Summary of the invention

[0003] The embodiment of the present application provides a CAN bus abnormality detection method, device, vehicle controller and medium, which can accurately determine the detection result of the CAN message, and based on the detection result, whether the operation state of the vehicle's CAN bus is abnormal, thereby effectively improving the safety of the CAN bus and ensuring the stable operation of the vehicle's electronic system. The technical solution is as follows:

[0004] On the one hand, a method for detecting anomalies of a CAN bus is provided, the method comprising:

[0005] Acquire a CAN message to be detected, wherein the CAN message refers to a message transmitted on a CAN bus of a vehicle;

[0006] Based on the message type of the CAN message, determining a message rule and a signal rule corresponding to the CAN message from a detection rule library of the vehicle, wherein the message rule is used to detect whether a message identifier, a length, and a sending period of the CAN message conform to a definition in a DBC file of the vehicle, and the signal rule is used to indicate whether a CAN signal in the CAN message conforms to a definition in the DBC file, wherein the DBC file contains definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus;

[0007] Based on the message rule and the signal rule, the CAN message is detected to obtain a detection result of the CAN message;

[0008] When the detection result indicates that the CAN message is an abnormal message, it is determined that there is an abnormality in the operation state of the CAN bus, and the abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0009] On the other hand, a CAN bus abnormality detection device is provided, the device comprising:

[0010] An acquisition module, used for acquiring a CAN message to be detected, wherein the CAN message refers to a message transmitted on a CAN bus of a vehicle;

[0011] A first determination module, configured to determine, based on a message type of the CAN message, a message rule and a signal rule corresponding to the CAN message from a detection rule library of the vehicle, wherein the message rule is used to indicate a definition of a message identifier, a length, and a sending period of the CAN message in a DBC file of the vehicle, and the signal rule is used to indicate a definition of a CAN signal in the CAN message in the DBC file, wherein the DBC file contains definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate via the CAN bus;

[0012] A detection module, used to detect the CAN message based on the message rule and the signal rule to obtain a detection result of the CAN message;

[0013] The second determination module is used to determine that there is an abnormality in the operation state of the CAN bus when the detection result indicates that the CAN message is an abnormal message, and the abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0014] In some embodiments, the detection module is used to detect the CAN message based on the message rule and the signal rule; when it is detected that at least one of the message identifier, length, sending period of the CAN message and the CAN signal in the CAN message is inconsistent with the definition in the DBC file, the CAN message is determined as an abnormal message; when it is detected that the message identifier, length, sending period of the CAN message and the CAN signal in the CAN message are all consistent with the definition in the DBC file, the CAN message is determined as a normal message.

[0015] In some embodiments, the second determining module includes:

[0016] A first determining unit, configured to analyze inconsistent definitions between the CAN message and the DBC file to determine an abnormal event corresponding to the CAN message when the detection result indicates that the CAN message is an abnormal message;

[0017] The second determining unit is used to determine that there is an abnormality in the operating state of the CAN bus when the risk level of the abnormal event is higher than a preset value, and the risk level is used to indicate the risk level of the CAN message.

[0018] In some embodiments, the first determination unit is used to analyze the inconsistent definitions between the CAN message and the DBC file to determine the abnormal type of the CAN message when the detection result indicates that the CAN message is an abnormal message; based on the abnormal type of the CAN message, query the abnormal event corresponding to the CAN message from the abnormal event mapping information, and the abnormal event mapping information is used to indicate the mapping relationship between the abnormal type and the abnormal event.

[0019] In some embodiments, the second determination unit is also used to analyze the inconsistent definitions between the CAN message and the DBC file when the risk level of the abnormal event corresponding to the CAN message is higher than the preset value, determine the attack type of the CAN message, and the attack type includes at least one of an injection attack, a replay attack, and a fuzzy attack; issue an alarm and execute defense measures corresponding to the attack type.

[0020] In some embodiments, the apparatus further comprises:

[0021] A rule updating module, configured to adjust the detection rules in the detection rule base based on the updated DBC file when a definition update contained in the DBC file is detected;

[0022] The first determination module is used to determine the message rule and the signal rule corresponding to the CAN message from the adjusted detection rule library based on the message type of the CAN message.

[0023] In some embodiments, the apparatus further comprises:

[0024] A parameter calculation module, used to calculate the CAN bus load rate and CAN bus information entropy of the vehicle during operation, wherein the CAN bus load rate is used to describe the current workload of the CAN bus, and the CAN bus information entropy is used to describe the complexity and uncertainty of messages transmitted on the CAN bus;

[0025] The second determination module is further configured to determine that an abnormality exists in the operating state of the CAN bus when the load rate of the CAN bus or the information entropy of the CAN bus exceeds a threshold value defined in the detection rule base.

[0026] In another aspect, a vehicle controller is provided, which includes a main control module, the main control module includes a processor and a memory, the memory is used to store at least one computer program, and the at least one computer program is loaded and executed by the processor to implement the CAN bus abnormality detection method in the embodiment of the present application.

[0027] On the other hand, a computer-readable storage medium is provided, which is used to store at least one computer program, and the at least one computer program is loaded and executed by a processor to implement the CAN bus abnormality detection method in the embodiment of the present application.

[0028] An embodiment of the present application provides a method for detecting anomalies of a CAN bus. By determining the message rule and signal rule corresponding to the CAN message from a detection rule library based on the message type of the CAN message to be detected, the method can detect the message identifier, length, sending period of the CAN message and whether the CAN signal contained in the CAN message complies with the definition of the CAN message in the DBC file of the vehicle based on the message rule and signal rule. The method can then accurately determine the detection result of the CAN message and determine whether the operating status of the vehicle's CAN bus is abnormal based on the detection result, thereby effectively improving the security of the CAN bus and ensuring the stable operation of the vehicle's electronic system. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0030] Figure 1 It is a schematic diagram of an implementation environment of a CAN bus abnormality detection method provided in an embodiment of the present application;

[0031] Figure 2 It is a flow chart of a CAN bus abnormality detection method provided according to an embodiment of the present application;

[0032] Figure 3 It is a flow chart of abnormality detection of a CAN bus provided according to an embodiment of the present application;

[0033] Figure 4 is a flow chart of another CAN bus abnormality detection method provided according to an embodiment of the present application;

[0034] Figure 5 It is a block diagram of a CAN bus abnormality detection device provided according to an embodiment of the present application;

[0035] Figure 6 is a block diagram of another CAN bus abnormality detection device provided according to an embodiment of the present application;

[0036] Figure 7 It is a structural schematic diagram of a vehicle controller provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0037] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.

[0038] In this application, the terms "first", "second", etc. are used to distinguish identical or similar items with basically the same effects and functions. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor is there any limitation on quantity and execution order.

[0039] In the present application, the term "at least one" means one or more, and the term "plurality" means two or more.

[0040] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0041] Figure 1 Schematic diagram of an implementation environment of a CAN bus abnormality detection method provided in accordance with an embodiment of the present application. Figure 1 The implementation environment includes a vehicle 101 and a server 102, and the vehicle 101 and the server 102 are connected via a wireless network.

[0042] In some embodiments, the vehicle 101 is equipped with multiple electronic control units (ECUs), such as an engine control unit, a wheel speed control unit, a body stability control unit, an airbag control unit, an anti-lock control unit, etc. The multiple electronic control units communicate via a CAN bus in the vehicle 101.

[0043] In some embodiments, the CAN bus includes a powertrain CAN bus, a chassis control CAN bus, a body control CAN bus, and an entertainment system CAN bus, etc. The electronic control units connected to different CAN buses are also different. Accordingly, a gateway is also installed in the vehicle 101, and the gateway is used to receive data from different CAN buses, and can forward data from one CAN bus to another CAN bus to achieve communication between two electronic control units that are not connected to the same CAN bus. Exemplarily, when the engine of the vehicle 101 fails, the engine control unit will send a fault signal to the powertrain CAN bus. After the gateway receives the fault signal from the powertrain CAN bus, it can forward it to the body control CAN bus, so that the body control unit can obtain the fault signal from the body control CAN bus, and then based on the fault signal, control the dashboard warning light in the car to light up to remind the driver that the vehicle has a power system failure.

[0044] In some embodiments, server 102 is an independent physical server, or it can be a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network) and big data and artificial intelligence platforms.

[0045] In the embodiment of the present application, the gateway is a vehicle controller with the largest network traffic in the vehicle 101, and is deployed with a CAN bus abnormality detection system. During the operation of the vehicle 101, the gateway can obtain CAN messages from different CAN buses and the detection rule base sent to the vehicle 101 by the server 102 through a wireless network connection, and then can detect the CAN messages based on the detection rule base, so as to determine whether the operation status of the vehicle CAN bus is abnormal based on the detection results of the CAN messages.

[0046] Figure 2 is a flow chart of a CAN bus abnormality detection method provided according to an embodiment of the present application, the method is executed by a vehicle gateway, such as Figure 2 As shown, the CAN bus abnormality detection method includes the following steps:

[0047] 201. The gateway obtains a CAN message to be detected. The CAN message refers to a message transmitted on a CAN bus of a vehicle.

[0048] In an embodiment of the present application, a CAN bus anomaly detection system is deployed in the gateway of the vehicle. The anomaly detection system is used to detect messages transmitted on the vehicle's CAN bus to determine whether there is an abnormality in the operation state of the vehicle's CAN bus. Accordingly, when the vehicle's anomaly detection system is started, the gateway can obtain the CAN message to be detected. Among them, the CAN message can be a message sent by any electronic control unit in the vehicle.

[0049] 202. The gateway determines the message rule and signal rule corresponding to the CAN message from the detection rule library of the vehicle based on the message type of the CAN message.

[0050] In an embodiment of the present application, when the abnormality detection system of the vehicle is started, the gateway can also pull the detection rule base generated based on the DBC (Database CAN) file of the vehicle from the server. Among them, the DBC file contains the definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus. The definition of the CAN message includes the message definition (message identifier, length, period, etc. of the message) and the signal definition (value range, start bit, length, maximum value, reserved bit, etc. of the signal in the message). The detection rule base includes multiple detection rules, and the detection rule refers to the standard used to determine whether the data meets specific conditions, that is, based on the detection rule, the gateway can detect whether the CAN message is an abnormal message.

[0051] The message types of CAN messages include data frames, remote frames, and overload frames. Among them, data frames are the most common message type on the CAN bus, which are used to transmit actual data information between electronic control units. Remote frames are used to request other electronic control units to send data. For example, if an electronic control unit needs to obtain engine speed data, the electronic control unit will send a remote frame requesting to obtain engine speed data. Overload frames are used to request to temporarily stop sending messages when the receiver or sender is too late to process the current message traffic to avoid data loss or errors.

[0052] Since the contents of CAN messages of different message types are different, the detection rules corresponding to CAN messages of different message types are also different. Accordingly, the gateway can determine the message rules and signal rules corresponding to the CAN message from the vehicle's detection rule library based on the message type of the CAN message. Among them, the message rules are used to detect whether the message identifier, length and sending period of the CAN message conform to the definition in the DBC file, that is, the message rules clarify the definition of the message identifier, length and sending period of the CAN message in the vehicle's DBC file. The signal rule is used to detect whether the CAN signal in the CAN message conforms to the definition in the DBC file, that is, the signal rule clarifies the definition of the CAN signal in the CAN message in the DBC file.

[0053] 203. The gateway detects the CAN message based on the message rule and the signal rule to obtain a detection result of the CAN message.

[0054] In an embodiment of the present application, the gateway can detect whether the real message identifier, real length and real sending period of the CAN message meet the definition of the message identifier, length and sending period of the CAN message indicated in the message rule in the DBC file of the vehicle. Similarly, the gateway can also detect whether the value range, start bit, length, maximum value, reserved bit, etc. of the CAN signal in the CAN message meet the definition based on the definition of the CAN signal in the CAN message indicated in the signal rule in the DBC file. In the case where any item is detected to be inconsistent with the definition, the gateway determines that the detection result is that the CAN message is an abnormal message. In the case where all items are detected to be consistent with the definition, the gateway determines that the detection result is that the CAN message is a normal message.

[0055] For example, Figure 3 1 is a flow chart of abnormality detection of a CAN bus according to an embodiment of the present application. Figure 3 As shown, the abnormal detection system can first load the detection rule base of the vehicle, then collect the CAN messages transmitted on the CAN bus through the gateway, and pre-process the CAN messages to obtain the CAN message ID (message identifier), length, transmission cycle, value range of CAN signals in the CAN message, start bit, length, maximum value, reserved bit, etc. Finally, according to the detection rules in the detection rule base, the CAN message is detected to obtain the detection result.

[0056] 204. When the detection result indicates that the CAN message is an abnormal message, the gateway determines that there is an abnormality in the operation state of the CAN bus, and the abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0057] In an embodiment of the present application, when the detection result indicates that the CAN message is an abnormal message, it means that the CAN message obtained by the gateway does not conform to the definition of the CAN message in the DBC file. Therefore, the gateway can determine that there is an abnormality in the operating status of the CAN bus, that is, the CAN bus is attacked.

[0058] An embodiment of the present application provides a method for detecting anomalies of a CAN bus. By determining the message rule and signal rule corresponding to the CAN message from a detection rule library based on the message type of the CAN message to be detected, the method can detect the message identifier, length, sending period of the CAN message and whether the CAN signal contained in the CAN message complies with the definition of the CAN message in the DBC file of the vehicle based on the message rule and signal rule. The method can then accurately determine the detection result of the CAN message and determine whether the operating status of the vehicle's CAN bus is abnormal based on the detection result, thereby effectively improving the security of the CAN bus and ensuring the stable operation of the vehicle's electronic system.

[0059] Figure 4 is a flowchart of another CAN bus abnormality detection method provided in an embodiment of the present application, the method is executed by the gateway of the vehicle, such as Figure 4 As shown, the CAN bus abnormality detection method includes the following steps:

[0060] 401. The gateway obtains a CAN message to be detected. The CAN message refers to a message transmitted on a CAN bus of a vehicle.

[0061] In the embodiment of the present application, step 401 is the same as the above-mentioned step 201 and will not be described again here.

[0062] 402. The gateway determines a message rule and a signal rule corresponding to the CAN message from a detection rule library of the vehicle based on the message type of the CAN message.

[0063] In the embodiment of the present application, since there are many different types of messages on the CAN bus, they come from different electronic control units and carry a variety of information, including vehicle status information (such as vehicle speed, engine speed, etc.) and control instructions (such as braking instructions, throttle control instructions, etc.). Different messages need to follow different communication rules under normal circumstances. Therefore, in order to accurately detect whether the message is abnormal, the gateway can determine the message type of the CAN message and the message rules and signal rules corresponding to the CAN message from the vehicle's detection rule library. Among them, the message rule is used to detect whether the message identifier, length and sending period of the CAN message conform to the definition in the DBC file, that is, the message rule clarifies the definition of the message identifier, length and sending period of the CAN message in the vehicle's DBC file. The signal rule is used to detect whether the CAN signal in the CAN message conforms to the definition in the DBC file, that is, the signal rule clarifies the definition of the CAN signal in the CAN message in the DBC file.

[0064] It should be noted that the detection rule base includes detection rules corresponding to CAN messages sent by multiple electronic control units of the vehicle. For CAN messages of the same message type but from different electronic control units, the corresponding message rules and signal rules are also different.

[0065] For example, for the definition of message identifiers in the message rules, the message identifier range defined in the corresponding message rules for CAN messages sent by the engine control unit can be 0x100-0x1FF, and the message identifier range defined in the corresponding message rules for CAN messages sent by the body control unit can be 0x200-0x2FF.

[0066] In some embodiments, when it is detected that the definition contained in the DBC file is updated, the detection rules in the detection rule base are adjusted based on the updated DBC file. Accordingly, the above step 402 can be replaced by: based on the message type of the CAN message, determining the message rule and signal rule corresponding to the CAN message from the adjusted detection rule base. Among them, the DBC file is a database file format for describing CAN bus network communication. It contains detailed definitions of messages on the CAN bus, such as message identifiers, message lengths, and data meanings of each byte in the message. With the upgrade of vehicle functions, electronic control units may be added or upgraded. Accordingly, the definition of the CAN message in the DBC file will also change accordingly. The gateway can read the updated DBC file from the server and parse the updated DBC file to obtain the network node definition, message definition, and signal definition therein. Then, the key parameters of the definition can be extracted, such as the updated message identifier, the various attributes of the updated signal, etc., and then the detection rules corresponding to the definition can be adjusted based on the updated parameters in the definition. By adjusting the detection rules in the detection rule base, it is possible to perform message detection based on the new detection rules, thereby ensuring that intrusion behavior can be accurately detected.

[0067] 403. The gateway detects the CAN message based on the message rule and the signal rule.

[0068] In the embodiment of the present application, the CAN message consists of a frame start, an arbitration field, a control field, a data field, a CRC (Cyclic Redundancy Check) field, a response field, and a frame end. Among them, the frame start marks the beginning of a CAN message, which is used to notify all nodes on the CAN bus that a new message is being sent. The arbitration field is used to define the message identifier of the CAN message, and the message identifier is used to determine the priority of the CAN message. When multiple electronic control units send CAN messages at the same time, the gateway can arbitrate according to the size of the message identifier of the message. The smaller the value of the message identifier, the higher the priority. The control field is used to define information such as the length of the data field. The data field is the core part of the CAN message and is used to exist CAN signals. Different electronic control units will send CAN signals of different lengths according to their own functions and the communication requirements at the time. For example, the length of the CAN signal in a simple door status message may be 1 byte to indicate whether the door is open or closed. The length of the CAN signal of a complex engine operating condition message may be 8 bytes to include multiple parameters such as engine speed, coolant temperature, and intake pressure. When the sender sends a CAN message, it will calculate a CRC value based on the previous part such as the data field and put it in the CRC field. After receiving the message, the receiver will calculate the CRC value according to the same algorithm and compare it with the received CRC value. If the two are consistent, it means that there is no error in the message transmission process; if they are inconsistent, it means that there may be an error in the data, and the receiver will ask the sender to resend the message, thereby ensuring the accuracy of data transmission. After successfully receiving and verifying the message, the receiver will send a response signal in the response field to inform the sender that the message has been received correctly. The end of the frame marks the end of a CAN message.

[0069] In the process of detecting CAN messages based on message rules, the gateway can parse the CAN messages to obtain the real message identifier, real length and real sending period of the CAN messages. Then they are matched one by one with the message identifier, length and sending period defined in the message rules to obtain the matching results. Similarly, in the process of detecting CAN messages based on signal rules, the gateway can parse the CAN messages to obtain the real value range, real start bit, real length, real maximum value, real reserved bit and other contents of the CAN signal in the CAN messages, and then they are matched one by one with these parameters defined in the signal rules to obtain the matching results.

[0070] 404. When it is detected that at least one of the message identifier, length, transmission period of the CAN message and the CAN signal in the CAN message is inconsistent with the definition in the DBC file, the gateway determines the CAN message as an abnormal message.

[0071] In an embodiment of the present application, when the matching result indicates that at least one of the message identifier, length, sending period of the CAN message and the CAN signal in the CAN message is inconsistent with the definition in the DBC file, it indicates that there is an abnormality in the current CAN message, and therefore the CAN message is determined to be an abnormal message.

[0072] For example, when it is detected that the message identifier of a CAN message is not in the message identifier range that its corresponding electronic control unit should use, it may mean that an illegal device has been connected or the message has been tampered with, so the CAN message can be determined to be an abnormal message. Alternatively, for those CAN messages that are known to be sent periodically, by comparing the timestamp difference between the current CAN message and the last CAN message of the same type, determine whether it is within the normal cycle range specified by the rule base. When it deviates from the normal range, the CAN message can be determined to be an abnormal message. Alternatively, for the value of the CAN signal in the CAN message, determine whether it is within the value range set in the rule base. For example, the normal value range of the engine speed is 0 to 8000 revolutions per minute. If the value of the engine speed field in the CAN signal is detected to be 10000 per minute, it can be determined that it is obviously beyond the normal range, so the engine speed message is considered abnormal.

[0073] 405. When it is detected that the message identifier, length, transmission cycle of the CAN message and the CAN signal in the CAN message are consistent with the definition in the DBC file, the gateway determines the CAN message as a normal message.

[0074] In an embodiment of the present application, when the matching result indicates that the message identifier, length, sending period of the CAN message and the CAN signal in the CAN message are consistent with the definition in the DBC file, it indicates that there is no abnormality in the current CAN message, and therefore the CAN message is determined to be a normal message.

[0075] 406. When the detection result indicates that the CAN message is an abnormal message, the gateway analyzes the inconsistent definitions between the CAN message and the DBC file to determine the abnormal event corresponding to the CAN message.

[0076] In an embodiment of the present application, since some abnormal events with lower danger levels will not affect vehicle safety, when the CAN message is an abnormal message, the gateway can also determine the abnormal event corresponding to the abnormal situation of the CAN message by analyzing the inconsistent definitions in the CAN message and the DBC file.

[0077] In some embodiments, when the detection result indicates that the CAN message is an abnormal message, the inconsistent definitions in the CAN message and the DBC file are analyzed to determine the abnormal type of the CAN message; based on the abnormal type of the CAN message, the abnormal event corresponding to the CAN message is queried from the abnormal event mapping information, and the abnormal event mapping information is used to indicate the mapping relationship between the abnormal type and the abnormal event. Among them, the abnormal type may include length abnormality, signal value abnormality, message cycle abnormality, etc. Optionally, the mapping relationship between the abnormal type and the abnormal event is shown in Table 1. Among them, the abnormal events corresponding to the length abnormality and the signal value abnormality are message health abnormalities.

[0078] Table 1

[0079]

[0080]

[0081] 407. When the risk level of the abnormal event is higher than a preset value, the gateway determines that the operation status of the CAN bus is abnormal, and the risk level is used to indicate the risk level of the CAN message.

[0082] In the embodiment of the present application, since different abnormal events correspond to different danger levels, when the danger level of the abnormal event corresponding to the CAN message is higher than the preset value, that is, when the danger level of the CAN message is high, the gateway cannot ignore the abnormality. Therefore, the gateway can determine that the CAN message is an attack message, that is, the CAN message will cause abnormality to the operating status of the CAN bus.

[0083] In some embodiments, when the risk level of an abnormal event corresponding to a CAN message is higher than a preset value, the inconsistent definitions in the CAN message and the DBC file are analyzed to determine the attack type of the CAN message, which includes at least one of an injection attack, a replay attack, and a fuzzy attack; an alarm is issued and defense measures corresponding to the attack type are executed.

[0084] Among them, injection attack refers to the attacker inserting malicious data into normal CAN bus communication. In this way, the attacker attempts to tamper with the vehicle's control system instructions or interfere with normal communication data in order to affect the vehicle's behavior. For example, by sending a forged engine speed control message on the CAN bus, the engine speed is set to an abnormally high value, causing the engine to overspeed. This attack may cause serious damage to the vehicle's power system and even endanger driving safety. Accordingly, when it is detected that the value of the CAN signal in the CAN message does not conform to the normal value range, it can be determined that the attack type of the CAN message is an injection attack. The corresponding defense measure for injection attacks can be to encrypt the key messages transmitted on the CAN bus, so that even if the attacker intercepts the message, he cannot tamper with the content without the decryption key.

[0085] A replay attack is when an attacker intercepts and records legitimate CAN messages, and then resends them at an appropriate time to deceive the vehicle's electronic control unit into performing the same operation or interfering with normal communication processes. For example, suppose an attacker intercepts a legitimate door unlock message. After the owner has locked the door and left the vehicle, the attacker resends the door unlock message to unlock the door again. This not only infringes on the safety of the vehicle, but may also lead to theft of items in the vehicle. Accordingly, when it is detected that the sending time interval of the CAN message, that is, the sending cycle, does not meet the normal range, the attack type of the CAN message can be determined to be a replay attack. The corresponding defense measures for replay attacks can be to add a timestamp to each CAN message and record the sending time of the CAN message. After receiving the CAN message, the timestamp is compared with the current time to determine whether the CAN message is fresh. For example, if the timestamp of the received message differs from the current time by more than a reasonable range (such as a few seconds), it is considered to be a replay attack and the message is refused to be received. It can also be to assign a unique serial number to each message. The receiver records the serial numbers that have been received. When a CAN message with a serial number that has already appeared is received, it is determined to be a possible replay attack.

[0086] A fuzzy attack is when an attacker sends a message with an incorrect format, non-compliant with the protocol specification, or with abnormal data to the CAN bus, with the purpose of causing the vehicle's electronic control unit to make errors when processing these messages, such as causing the system to crash, enter an abnormal state, or leak sensitive information. For example, an attacker may send a CAN message with a data field length that does not comply with the regulations. When the electronic control unit receives such a message that does not comply with the specifications, it may fail due to the inability to process it correctly, such as the program falling into an infinite loop, memory overflow, etc., thereby affecting the normal operation of the vehicle. Accordingly, when it is detected that the format of the CAN message does not comply with the protocol standard, whether the frame start and frame end of the CAN message are correct, whether the data field length is within the specified range, etc., can determine that the attack type is a fuzzy attack. The corresponding defense measure for fuzzy attacks is to strictly check whether the format of the received CAN message complies with the CAN bus protocol. This includes verifying whether the format of each part such as the frame start, arbitration field, control field, data field, CRC field, response field, and frame end is correct.

[0087] Optionally, if a CAN message that does not conform to the normal message identifier range of the electronic control unit is detected on the CAN bus, it is likely a spoofing attack. For example, under normal circumstances, the message identifier range of the message sent by the engine control unit is 0x100-0x1FF. If a CAN message with a message identifier of 0x300 appears but claims to be from the engine control unit, it may be a message sent by an external device disguised as the engine control unit. If the cycle of a critical message (such as a vehicle speed message) that is sent periodically becomes extremely short or extremely long, exceeding the normal range, it may also be a denial of service attack. For example, a normal vehicle speed message is sent every 100ms, and suddenly it becomes sent every 10ms, which will occupy a large amount of bus resources and prevent other electronic control units from communicating normally.

[0088] In some embodiments, since flood attacks, injection attacks, etc. are carried out on the vehicle network, the load rate and information entropy of the CAN bus will exceed the normal value. Therefore, in addition to detecting the message, the gateway can also calculate the load rate and information entropy on the CAN bus, and then determine whether there is an abnormality based on the calculation results. Accordingly, the CAN bus load rate and CAN bus information entropy of the vehicle during operation are calculated. The CAN bus load rate is used to describe the current workload of the CAN bus, and the CAN bus information entropy is used to describe the complexity and uncertainty of the message transmitted on the CAN bus; when the CAN bus load rate or the CAN bus information entropy exceeds the threshold defined in the detection rule base, it is determined that the operation state of the CAN bus is abnormal. Among them, the CAN bus load rate refers to the ratio of the number of bits actually transmitted per unit time on the CAN bus to the number of bits that can be transmitted. Load rate detection can monitor the traffic of the network. Information entropy is used to measure the complexity and uncertainty of the message transmitted on the CAN bus. Since the load rate and information entropy of the CAN bus are relatively stable under normal circumstances, when the load rate of the CAN bus exceeds the threshold defined in the detection rule base (suddenly increased significantly), it may be subjected to a flood attack. The attacker attempts to flood the normal communication messages by sending a large number of messages, so that the vehicle's electronic control unit cannot process information normally. Since the vehicle is running stably, the information entropy of the CAN bus will remain in a relatively stable range. If the information entropy of the CAN bus exceeds the threshold defined in the detection rule base (suddenly increases significantly), it may indicate that the CAN bus is abnormal. For example, when attacked, if a large number of new messages that do not conform to normal rules are injected, the information entropy will increase.

[0089] An embodiment of the present application provides a method for detecting anomalies of a CAN bus. By determining the message rule and signal rule corresponding to the CAN message from a detection rule library based on the message type of the CAN message to be detected, the method can detect the message identifier, length, sending period of the CAN message and whether the CAN signal contained in the CAN message complies with the definition of the CAN message in the DBC file of the vehicle based on the message rule and signal rule. The method can then accurately determine the detection result of the CAN message and determine whether the operating status of the vehicle's CAN bus is abnormal based on the detection result, thereby effectively improving the security of the CAN bus and ensuring the stable operation of the vehicle's electronic system.

[0090] Figure 5 : is a block diagram of a CAN bus anomaly detection device provided according to an embodiment of the present application. The device is used to execute the steps of the above-mentioned CAN bus anomaly detection method. Figure 5 , the device comprises:

[0091] The acquisition module 501 is used to acquire the CAN message to be detected, where the CAN message refers to the message transmitted on the CAN bus of the vehicle;

[0092] A first determination module 502 is used to determine a message rule and a signal rule corresponding to a CAN message from a detection rule library of the vehicle based on a message type of the CAN message, wherein the message rule is used to detect whether a message identifier, a length, and a sending period of the CAN message conform to a definition in a DBC file of the vehicle, and the signal rule is used to detect whether a CAN signal in the CAN message conforms to a definition in a DBC file, wherein the DBC file contains definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through a CAN bus;

[0093] The detection module 503 is used to detect the CAN message based on the message rule and the signal rule to obtain the detection result of the CAN message;

[0094] The second determination module 504 is used to determine that the operation state of the CAN bus is abnormal when the detection result indicates that the CAN message is an abnormal message, and the abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0095] In some embodiments, the detection module 503 is used to detect the CAN message based on the message rules and the signal rules; when it is detected that at least one of the message identifier, length, sending period and CAN signal in the CAN message is inconsistent with the definition in the DBC file, the CAN message is determined as an abnormal message; when it is detected that the message identifier, length, sending period and CAN signal in the CAN message are all consistent with the definition in the DBC file, the CAN message is determined as a normal message.

[0096] In some embodiments, Figure 6 is a block diagram of another CAN bus abnormality detection device provided according to an embodiment of the present application. Figure 6 , the second determining module 504 includes:

[0097] The first determination unit 601 is used to analyze the inconsistent definitions between the CAN message and the DBC file to determine the abnormal event corresponding to the CAN message when the detection result indicates that the CAN message is an abnormal message;

[0098] The second determining unit 602 is used to determine that there is an abnormality in the operation state of the CAN bus when the risk level of the abnormal event is higher than a preset value, and the risk level is used to indicate the risk level of the CAN message.

[0099] In some embodiments, the first determination unit 601 is used to analyze the inconsistent definitions between the CAN message and the DBC file to determine the abnormal type of the CAN message when the detection result indicates that the CAN message is an abnormal message; based on the abnormal type of the CAN message, query the abnormal event corresponding to the CAN message from the abnormal event mapping information, and the abnormal event mapping information is used to indicate the mapping relationship between the abnormal type and the abnormal event.

[0100] In some embodiments, the second determination unit 602 is also used to analyze the inconsistent definitions between the CAN message and the DBC file when the risk level of the abnormal event corresponding to the CAN message is higher than a preset value, determine the attack type of the CAN message, and the attack type includes at least one of an injection attack, a replay attack, and a fuzzy attack; issue an alarm and execute defense measures corresponding to the attack type.

[0101] In some embodiments, see Figure 6 , the device further comprises:

[0102] A rule updating module 505, configured to adjust the detection rules in the detection rule base based on the updated DBC file when a definition update contained in the DBC file is detected;

[0103] The first determination module 502 is used to determine the message rule and signal rule corresponding to the CAN message from the adjusted detection rule library based on the message type of the CAN message.

[0104] In some embodiments, see Figure 6 , the device further comprises:

[0105] The parameter calculation module 506 is used to calculate the CAN bus load rate and CAN bus information entropy of the vehicle during operation. The CAN bus load rate is used to describe the current workload of the CAN bus, and the CAN bus information entropy is used to describe the complexity and uncertainty of the message transmitted on the CAN bus.

[0106] The second determination module 504 is further configured to determine that an abnormality exists in the operation state of the CAN bus when the load rate of the CAN bus or the information entropy of the CAN bus exceeds a threshold value defined in the detection rule base.

[0107] An embodiment of the present application provides an abnormality detection device for a CAN bus, which determines the message rule and signal rule corresponding to the CAN message from a detection rule library based on the message type of the CAN message to be detected, and can detect the message identifier, length, sending period of the CAN message and whether the CAN signal contained in the CAN message complies with the definition of the CAN message in the DBC file of the vehicle based on the message rule and signal rule, and can then accurately determine the detection result of the CAN message, and based on the detection result, whether there is any abnormality in the operating status of the vehicle's CAN bus, thereby effectively improving the security of the CAN bus and ensuring the stable operation of the vehicle's electronic system.

[0108] It should be noted that: the CAN bus anomaly detection device provided in the above embodiment only uses the division of the above functional modules as an example when running an application program. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the CAN bus anomaly detection device provided in the above embodiment and the CAN bus anomaly detection method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0109] Figure 7 It is a structural schematic diagram of a vehicle controller provided according to an embodiment of the present application.

[0110] Typically, the vehicle controller 700 includes: a main control module 701, a CAN interface 702, a hard-line input interface 703, and a hard-line output interface 704. The main control module 701 is connected to the CAN interface 702, the hard-line input interface 703, and the hard-line output interface 704, respectively.

[0111] The main control module 701 generally includes a processor and a memory. Among them, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the vehicle display screen. In some embodiments, the processor may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning. The memory may include one or more computer-readable storage media, which may be non-transitory. The memory may also include a high-speed random access memory and a non-volatile memory, such as one or more disk storage devices and flash storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory is used to store at least one computer program, and the at least one computer program is used to be executed by the processor to implement the CAN bus abnormality detection method provided in the method embodiment of the present application.

[0112] The CAN interface 702 may include a power CAN interface, a body CAN interface, a brake CAN interface, a diagnostic CAN interface, etc. The power CAN interface is used to communicate with the power system of the vehicle, the body CAN interface is used to communicate with the body control system of the vehicle, the brake CAN interface is used to communicate with the brake system of the vehicle, and the diagnostic CAN interface is used to communicate with the diagnostic system.

[0113] The hard-wire input interface 703 is used to receive hard-wire control signals. The hard-wire output interface 704 is used to send control instructions to the electronic control components of the vehicle so that the electronic control components of the vehicle perform corresponding actions. The electronic control components of the vehicle include a power management system, a motor controller, an on-board charger, a body control system, etc.

[0114] The main control module 701 can communicate with the vehicle's power system, body control system, braking system and diagnostic system through the CAN interface 702, and generate control instructions based on the hard-wired control signal received by the hard-wired input interface 703, so as to send the control instructions to the vehicle's electronic control components through the hard-wired output interface 704.

[0115] Those skilled in the art will understand that Figure 7 The structure shown in the figure does not constitute a limitation on the vehicle controller 700, and the vehicle controller 700 may include more or fewer components than shown in the figure, or combine certain components, or adopt a different component arrangement.

[0116] The embodiment of the present application also provides a computer-readable storage medium, in which at least one computer program is stored, and the at least one computer program is loaded and executed by the processor of the vehicle controller to implement the operation performed by the vehicle controller in the abnormality detection method of the CAN bus in the above embodiment. For example, the computer-readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), a magnetic tape, a floppy disk, and an optical data storage device.

[0117] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.

[0118] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A CAN bus abnormality detection method, characterized in that: The method comprises: Acquire a CAN message to be detected, wherein the CAN message refers to a message transmitted on a CAN bus of a vehicle; Based on the message type of the CAN message, determining a message rule and a signal rule corresponding to the CAN message from a detection rule library of the vehicle, wherein the message rule is used to detect whether a message identifier, a length, and a sending period of the CAN message conform to a definition in a DBC file of the vehicle, and the signal rule is used to indicate whether a CAN signal in the CAN message conforms to a definition in the DBC file, wherein the DBC file contains definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus; Based on the message rule and the signal rule, the CAN message is detected to obtain a detection result of the CAN message; When the detection result indicates that the CAN message is an abnormal message, it is determined that there is an abnormality in the operation state of the CAN bus, and the abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

2. The method according to claim 1, characterized in that The detecting the CAN message based on the message rule and the signal rule to obtain the detection result of the CAN message includes: Based on the message rule and the signal rule, detecting the CAN message; When it is detected that at least one of the message identifier, length, transmission period of the CAN message and the CAN signal in the CAN message is inconsistent with the definition in the DBC file, the CAN message is determined as an abnormal message; When it is detected that the message identifier, length, transmission period of the CAN message and the CAN signal in the CAN message are consistent with the definition in the DBC file, the CAN message is determined to be a normal message.

3. The method according to claim 1, characterized in that: When the detection result indicates that the CAN message is an abnormal message, determining that the operation state of the CAN bus is abnormal includes: When the detection result indicates that the CAN message is an abnormal message, analyzing the inconsistent definitions between the CAN message and the DBC file to determine the abnormal event corresponding to the CAN message; When the risk level of the abnormal event is higher than a preset value, it is determined that there is an abnormality in the operation state of the CAN bus, and the risk level is used to indicate the risk level of the CAN message.

4. The method according to claim 3, characterized in that When the detection result indicates that the CAN message is an abnormal message, analyzing the inconsistent definitions between the CAN message and the DBC file to determine the abnormal event corresponding to the CAN message includes: When the detection result indicates that the CAN message is an abnormal message, analyzing inconsistent definitions between the CAN message and the DBC file to determine the abnormal type of the CAN message; Based on the abnormal type of the CAN message, the abnormal event corresponding to the CAN message is queried from abnormal event mapping information, where the abnormal event mapping information is used to indicate a mapping relationship between the abnormal type and the abnormal event.

5. The method according to claim 3, characterized in that: The method further comprises: When the risk level of the abnormal event corresponding to the CAN message is higher than the preset value, the inconsistent definitions between the CAN message and the DBC file are analyzed to determine the attack type of the CAN message, where the attack type includes at least one of an injection attack, a replay attack, and a fuzzy attack; Issue an alert and execute defense measures corresponding to the attack type.

6. The method according to claim 1, characterized in that The method further comprises: In case of detecting that a definition included in a DBC file is updated, adjusting the detection rules in the detection rule base based on the updated DBC file; The determining, based on the message type of the CAN message, a message rule and a signal rule corresponding to the CAN message from a detection rule library of the vehicle includes: Based on the message type of the CAN message, a message rule and a signal rule corresponding to the CAN message are determined from the adjusted detection rule base.

7. The method according to claim 1, characterized in that The method further comprises: Calculating a CAN bus load rate and a CAN bus information entropy of the vehicle during operation, wherein the CAN bus load rate is used to describe a current workload of the CAN bus, and the CAN bus information entropy is used to describe the complexity and uncertainty of messages transmitted on the CAN bus; When the CAN bus load rate or the CAN bus information entropy exceeds a threshold value defined in the detection rule base, it is determined that an abnormality exists in the operating state of the CAN bus.

8. A CAN bus abnormality detection device, characterized in that: The device comprises: An acquisition module, used for acquiring a CAN message to be detected, wherein the CAN message refers to a message transmitted on a CAN bus of a vehicle; A first determination module, configured to determine, based on a message type of the CAN message, a message rule and a signal rule corresponding to the CAN message from a detection rule library of the vehicle, wherein the message rule is used to indicate a definition of a message identifier, a length, and a sending period of the CAN message in a DBC file of the vehicle, and the signal rule is used to indicate a definition of a CAN signal in the CAN message in the DBC file, wherein the DBC file contains definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate via the CAN bus; A detection module, used to detect the CAN message based on the message rule and the signal rule to obtain a detection result of the CAN message; The second determination module is used to determine that there is an abnormality in the operation state of the CAN bus when the detection result indicates that the CAN message is an abnormal message, and the abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

9. A vehicle controller, characterized in that: The vehicle controller includes a main control module, which includes a processor and a memory. The memory is used to store at least one computer program. The at least one computer program is loaded by the processor and executes the CAN bus abnormality detection method described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store at least one computer program, and the at least one computer program is used to execute the CAN bus abnormality detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • CAN bus anomaly detection method based on information entropy

    CN109347823A

  • Vehicle-mounted CAN bus anomaly detection method, device and equipment, and storage medium

    CN112153070A

  • Abnormity detection method and device

    CN112514351A

  • Vehicle security monitoring device, method, and program

    CN113348111A

  • Vehicle CAN network intrusion detection method and device, electronic equipment and medium

    CN114374565A

Cited By

  • Communication method of electronic control unit, storage medium and electronic equipment

    CN121397012A