Configuration content updating method and device, electronic equipment and readable storage medium
By obtaining and updating the detection rule configuration files of the target vehicle's vehicle-side intrusion detection and defense system from the cloud server, the problem of inefficient updates in the existing technology is solved and more efficient configuration file updates are achieved.
Patent Information
- Application Number
- CN202510025577.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, updating the detection rule configuration file deployed on the vehicle end intrusion detection defense system is less efficient.
When the detection rule configuration file of the vehicle-end intrusion detection defense system of the target vehicle needs to be updated, the target configuration content used to configure the detection rule configuration file is obtained from the cloud server, and the detection rule configuration file is updated based on the content.
It improves the efficiency of updating detection rule configuration files, simplifies the update process, reduces user operation burden, and ensures timely updates of detection rule configuration files.
Smart Images

Figure CN119946124A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of vehicle networking, and more specifically, to a configuration content updating method, device, electronic device and readable storage medium. Background Art
[0002] At present, with the continuous development of intelligent connected vehicles, vehicles can be deployed with vehicle-side intrusion detection and prevention systems (IDPS). The vehicle-side intrusion detection and prevention system can perceive the various security risks that the vehicle is suffering in real time according to the configured detection rule configuration file, and conduct targeted dynamic security detection and event reporting based on actual attack events, restore the attack path and use this to predict future attack trends, and realize the closed loop of automated security operations for threat detection, response, and tracing. However, the efficiency of updating the detection rule configuration file of the vehicle-side intrusion detection and prevention system deployed on the vehicle is currently low. Summary of the invention
[0003] The present application proposes a configuration content updating method, device, electronic device and readable storage medium.
[0004] In a first aspect, an embodiment of the present application provides a configuration content update method, which is applied to a target vehicle, comprising:
[0005] When it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target configuration content used to configure the detection rule configuration file is obtained from the cloud server; and the detection rule configuration file is updated based on the target configuration content.
[0006] Optionally, when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, target configuration content for configuring the detection rule configuration file is obtained from the cloud server, including: when it is detected that the target vehicle switches from a power-off state to a power-on state, detecting whether the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated; when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, obtaining target configuration content for configuring the detection rule configuration file from the cloud server.
[0007] Optionally, when it is detected that the target vehicle switches from a power-off state to a power-on state, detecting whether a detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated comprises: when it is detected that the target vehicle switches from a power-off state to a power-on state, sending a configuration content query request to the cloud server; receiving feedback content sent by the cloud server based on the configuration content query request, wherein the feedback content includes the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system; obtaining the current version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle; and, when the current version information is different from the latest version information, determining that it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated.
[0008] Optionally, the feedback content also includes download address information, and when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target configuration content for configuring the detection rule configuration file is obtained from the cloud server, including: when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, determining the target address based on the download address information; and obtaining the target configuration content for configuring the detection rule configuration file from the cloud server based on the target address.
[0009] Optionally, the feedback content also includes a decryption key, and obtaining the target configuration content for configuring the detection rule configuration file from the cloud server based on the target address includes: obtaining encrypted data from the cloud server based on the target address; decrypting the encrypted data based on the decryption key to obtain the target configuration content for configuring the detection rule configuration file.
[0010] Optionally, the feedback content also includes signature content and a public key certificate, and the encrypted data is decrypted based on the decryption key to obtain target configuration content for configuring the detection rule configuration file, including: decrypting the encrypted data based on the decryption key to obtain first decrypted data; verifying the signature content based on the public key certificate to obtain second decrypted data; and when it is detected that the first decrypted data matches the second decrypted data, using the first decrypted data as the target configuration content for configuring the detection rule configuration file.
[0011] Optionally, when it is detected that the first decrypted data matches the second decrypted data, the first decrypted data is used as the target configuration content for configuring the detection rule configuration file, including: obtaining verification information corresponding to the first decrypted data based on a hash algorithm; when it is detected that the verification information is the same as the second decrypted data, the first decrypted data is used as the target configuration content for configuring the detection rule configuration file.
[0012] In a second aspect, the embodiment of the present application further provides a configuration content updating device, which is applied to a target vehicle, and includes: an acquisition unit and an update unit. The acquisition unit is used to acquire target configuration content used to configure the detection rule configuration file from a cloud server when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated; the update unit is used to update the detection rule configuration file based on the target configuration content.
[0013] In a third aspect, an embodiment of the present application further provides an electronic device, comprising: one or more processors; a memory; and one or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method described in the first aspect.
[0014] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, in which a program code is stored. The program code can be called by a processor to execute the method described in the first aspect above.
[0015] The configuration content updating method, device, electronic device and readable storage medium provided in the embodiment of the present application first obtain the target configuration content for configuring the detection rule configuration file from the cloud server when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated; and then update the detection rule configuration file based on the target configuration content. In the scheme of the present application, the target configuration content for configuring the detection rule configuration file is directly sent to the target vehicle through the cloud server, and then the detection rule configuration file in the target vehicle is updated, thereby improving the efficiency of updating the detection rule configuration file.
[0016] Other features and advantages of the embodiments of the present application will be described in the subsequent description, and partly become apparent from the description, or can be understood by practicing the embodiments of the present application. The purposes and other advantages of the embodiments of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0018] Figure 1 An application scenario diagram of the configuration content updating method provided in an embodiment of the present application is shown;
[0019] Figure 2 A method flow chart of a configuration content updating method provided in an embodiment of the present application is shown;
[0020] Figure 3 A method flow chart of a configuration content updating method provided by another embodiment of the present application is shown;
[0021] Figure 4 A method flow chart of a configuration content updating method provided by another embodiment of the present application is shown;
[0022] Figure 5 A structural block diagram of a configuration content updating device provided in an embodiment of the present application is shown;
[0023] Figure 6 A structural block diagram of an electronic device provided in an embodiment of the present application is shown;
[0024] Figure 7 A structural block diagram of a computer-readable storage medium provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0025] In order to make those skilled in the art better understand the present application scheme, the technical scheme in the present application embodiment will be clearly and completely described below in conjunction with the drawings in the present application embodiment. Obviously, the described embodiment is only a part of the present application embodiment, rather than all the embodiments. The components of the present application embodiment usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application for protection, but merely represents the selected embodiment of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.
[0026] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0027] At present, with the continuous development of intelligent connected vehicles, vehicles can be deployed with vehicle-side intrusion detection and prevention systems (IDPS). The vehicle-side intrusion detection and prevention system can perceive the various security risks that the vehicle is suffering in real time according to the configured detection rule configuration files, and conduct targeted dynamic security detection and event reporting based on actual attack events, restore the attack path and use this to predict future attack trends, and realize the closed loop of automated security operations such as threat detection, response, and tracing. However, the efficiency of updating the detection rule configuration files of the vehicle-side intrusion detection and prevention system deployed in the vehicle is currently low. How to improve the efficiency of updating the detection rule configuration files of the vehicle-side intrusion detection and prevention system deployed in the vehicle is an urgent problem to be solved.
[0028] At present, the new detection rule configuration file can be transmitted to the target vehicle through the vehicle over-the-air technology (OTA) upgrade, and then the target vehicle updates the detection rule configuration file. In addition, the local data of the target vehicle can also be manually flashed to achieve the update of the detection rule configuration file.
[0029] However, the inventors found in their research that the method of transmitting the new detection rule configuration file to the target vehicle through the over-the-air download technology upgrade of the whole vehicle needs to go through a series of approval processes such as the enterprise announcement change process and the national filing and approval process. Therefore, the update process is cumbersome, the update link is long, and the update efficiency is low. As for the method of manually flashing the local data of the target vehicle, it is difficult to cope with the update needs of the target vehicle for the detection rule configuration file in a mass production environment, and there is also the problem of low efficiency.
[0030] Therefore, in order to solve or partially solve the above problems, the present application provides a configuration content update method, device, electronic device and readable storage medium.
[0031] See also Figure 1 , Figure 1 The application scenario diagram of the configuration content update method provided by the present application is shown, namely, a configuration content update scenario 100. The configuration content update scenario 100 includes a target vehicle 110 and a cloud server 120.
[0032] Among them, a vehicle-side intrusion detection and defense system can be deployed in the target vehicle 110. The vehicle-side intrusion detection and defense system can be configured with a detection rule configuration file, so that it can perform response operations for security risks, attack events, etc. according to the detection rule configuration file. For a detailed introduction, please refer to the aforementioned introduction to the vehicle-side intrusion detection and defense system, which will not be repeated here.
[0033] The target vehicle 110 can also establish a communication connection with the cloud server 120, so that it can communicate with the cloud server 120 to obtain the target configuration content sent by the cloud server, and then update the detection rule configuration file through the obtained target configuration content. For a detailed introduction, please refer to the subsequent embodiments.
[0034] See also Figure 2 , Figure 2 A method flow chart of a configuration content update method provided by an embodiment of the present application is shown. The configuration content update method can be applied to Figure 1 In the configuration content update scenario shown in , it can be specifically applied to the target vehicle. The configuration content update method specifically includes step S110 and step S120.
[0035] Step S110: when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target configuration content for configuring the detection rule configuration file is obtained from the cloud server.
[0036] In some implementations, the rule configuration file may include multiple types of files, such as detection algorithms, detection rules, extended security monitoring directories or files, and the latest virus signature library, etc. Thus, the vehicle-side intrusion detection and defense system of the target vehicle can perceive the various security risks that the vehicle is suffering in real time based on the rule configuration file, and conduct targeted dynamic security detection and event reporting based on actual attack events, restore the attack path, and thereby predict future attack situations, thus realizing an automated security operation closed loop of threat detection, response, and tracing.
[0037] It is understandable that before updating the detection rule configuration file, it is possible to detect whether the detection rule configuration file needs to be updated, so that when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, subsequent updates can be performed, avoiding obtaining the target configuration content to update the detection rule configuration file when there is no need to update the detection rule configuration file, thereby wasting bandwidth and user time.
[0038] For some implementations, the current version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle and the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system in the cloud server can be compared to determine whether the detection rule configuration file in the target vehicle needs to be updated. For detailed introduction, please refer to the subsequent embodiments.
[0039] Furthermore, when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target configuration content for configuring the detection rule configuration file can be obtained from the cloud server. The cloud server can establish a communication connection with the target vehicle in advance. For example, the target vehicle can be provided with a vehicle-mounted system, so that a communication connection can be established with the cloud server through the vehicle-mounted system of the target vehicle, thereby realizing direct data communication between the target vehicle and the cloud server.
[0040] Optionally, the cloud server may be a distributed object storage server, for example, a Tencent Cloud COS server.
[0041] The cloud server may send target configuration content to the target vehicle, and the target configuration content includes content used to configure the detection rule configuration file.
[0042] Step S120: updating the detection rule configuration file based on the target configuration content.
[0043] Therefore, after obtaining the target configuration content, the target vehicle can update the detection rule configuration file of the vehicle-side intrusion detection and defense system deployed on the target vehicle according to the target configuration content. For example, the detection algorithm can be optimized based on the target configuration content; new detection rules can be added; the directories or files that need to be tested can be expanded; and the latest virus feature library can be updated and synchronized.
[0044] It should be noted that the above examples are only for illustrating specific contents that can be updated, and do not constitute a limitation on the embodiments of the present application.
[0045] It is understandable that in order to increase the security of the target vehicle and the cloud server during the communication process, the data sent by the cloud server to the target vehicle can be encrypted data after encryption processing, so that the target vehicle receives the encrypted data after encryption processing. The target vehicle also needs to decrypt the encrypted data to obtain the target configuration content that can be used to configure the detection rule configuration file. Optionally, the target vehicle can also perform a signature verification operation after decrypting the encrypted data. Only when the signature verification passes, the obtained content is used as the target configuration content. For a detailed introduction, please refer to the subsequent embodiments.
[0046] The configuration content updating method, device, electronic device and readable storage medium provided in the embodiment of the present application first obtain the target configuration content for configuring the detection rule configuration file from the cloud server when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated; and then update the detection rule configuration file based on the target configuration content. In the scheme of the present application, the target configuration content for configuring the detection rule configuration file is directly sent to the target vehicle through the cloud server, and then the detection rule configuration file in the target vehicle is updated, thereby improving the efficiency of updating the detection rule configuration file.
[0047] See also Figure 3 , Figure 3 A method flow chart of a configuration content update method provided by an embodiment of the present application is shown. The configuration content update method can be applied to Figure 1 In the configuration content update scenario shown in , it can be specifically applied to the target vehicle. The configuration content update method specifically includes steps S210 to S230.
[0048] Step S210: When it is detected that the target vehicle switches from a power-off state to a power-on state, it is detected whether a detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated.
[0049] The user can actively trigger the update operation, and the target vehicle can then execute the detection rule configuration file of the vehicle-side intrusion detection and defense system to determine whether it needs to be updated. For example, the user can operate the operation control corresponding to the update detection rule configuration file in the vehicle-side intrusion detection and defense system of the target vehicle to control whether the target vehicle needs to update the detection rule configuration file of the vehicle-side intrusion detection and defense system. However, the user actively triggering the update operation will cause additional operational burden to the user, and the user may forget that the update operation is required, resulting in the failure to update the detection rule configuration file in a timely manner.
[0050] Therefore, in the embodiment provided by the present application, when it is detected that the target vehicle switches from a power-off state to a power-on state, it is detected whether the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated. Among them, the switching of the target vehicle from a power-off state to a power-on state can be used to characterize each ignition of the target vehicle. That is to say, in the embodiment provided by the present application, it is possible to detect whether the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated when a vehicle ignition event is detected, thereby eliminating the need for the user to actively trigger the update operation and ensuring that the detection rule configuration file can be updated in a timely manner as much as possible.
[0051] In some implementations, it may be determined whether the detection rule configuration file needs to be updated based on the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and prevention system. Specifically, step S210 may include steps S211 to S214.
[0052] Step S211: When it is detected that the target vehicle switches from a power-off state to a power-on state, a configuration content query request is sent to the cloud server.
[0053] Step S212: receiving feedback content sent by the cloud server based on the configuration content query request, wherein the feedback content includes the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system.
[0054] Step S213: Obtain the current version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle.
[0055] Step S214: When the current version information is different from the latest version information, it is determined that the detection rule configuration file of the vehicle-side intrusion detection and defense system that detects the target vehicle needs to be updated.
[0056] Specifically, when it is detected that the target vehicle switches from a power-off state to a power-on state, a configuration content query request may be sent to the cloud server. Thus, after receiving the configuration content query request, the cloud server may respond to the configuration content query request and send feedback content to the target vehicle. The feedback content may include the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system.
[0057] The target vehicle can receive the feedback content sent by the cloud server based on the configuration content query request. In addition, the target vehicle can also obtain the current version information of the detection rule configuration file of the vehicle-side intrusion detection and prevention system. Exemplarily, the target vehicle can capture the version information of the currently deployed vehicle-side intrusion detection and prevention system through the vehicle-mounted system as the current version information.
[0058] Furthermore, the current version information may be compared with the latest version information to see whether they are the same. If the current version information is different from the latest version information, it may be determined that the detection rule configuration file of the vehicle-side intrusion detection and defense system that detects the target vehicle needs to be updated.
[0059] When the current version information is the same as the latest version information, the configuration content updating method may be terminated.
[0060] Step S220: When it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target configuration content for configuring the detection rule configuration file is obtained from the cloud server.
[0061] Thus, when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target vehicle can obtain the target configuration content used to configure the detection rule configuration file from the cloud server.
[0062] In some embodiments, the cloud server may provide download address information to the target vehicle, so that the target vehicle may obtain the target configuration content based on the download address information. Specifically, step S220 may include step S221 and step S222.
[0063] Step S221: when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, determining the target address based on the download address information.
[0064] Step S222: Obtain target configuration content for configuring the detection rule configuration file from the cloud server based on the target address.
[0065] For some implementation modes, the feedback content may further include download address information, wherein the download address information may include a connection address provided by the cloud server for downloading the target configuration content.
[0066] Thus, when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target vehicle can extract the detection rule configuration file based on the feedback information obtained, and then determine the target address based on the download address information. It can be understood that the target address is the connection address provided by the cloud server for downloading the target configuration content.
[0067] Further, the target vehicle may obtain target configuration content for configuring the detection rule configuration file from the cloud server based on the target address. In some embodiments, the target address may be represented by a Uniform Resource Locator (URL).
[0068] For some implementations, the target vehicle may obtain encrypted data from the target address after being encrypted by the cloud server, so that the target vehicle may also decrypt the encrypted data. Specifically, step S222 may include step S223 and step S224.
[0069] Step S223: Obtaining encrypted data from the cloud server based on the target address.
[0070] Step S224: decrypting the encrypted data based on the decryption key to obtain target configuration content for configuring the detection rule configuration file.
[0071] The feedback content may also include a decryption key, so that after the target vehicle obtains the encrypted data from the cloud server based on the target address, it may also decrypt the encrypted data based on the decryption key to obtain the target configuration content for configuring the detection rule configuration file.
[0072] It should be noted that the decryption key may be a public key, and the cloud server encrypts the target configuration content using a private key, wherein the public key and the private key are matched in pairs. Therefore, the target vehicle can decrypt the encrypted data encrypted by the private key matching the public key based on the public key, and obtain the target configuration content used to configure the detection rule configuration file.
[0073] Optionally, the decryption key may be an SM4 decryption key.
[0074] Optionally, after the cloud server encrypts the target configuration content with the private key to obtain the encrypted data, it can also encode the encrypted data, so that the encoded encrypted data is more convenient to transmit. Exemplarily, the encrypted data can be encoded by Base64 encoding. Thus, the target vehicle obtains the encoded encrypted data from the target address, so the target vehicle can also decode the encoded encrypted data to obtain the encrypted data. Exemplarily, the encoded encrypted data can be decoded by Base64 decoding.
[0075] It should be noted that the above-mentioned specific encoding and decoding methods are only examples and do not constitute a limitation on the embodiments of the present application. It is only necessary to ensure that the decoding and encoding methods correspond to each other, and appropriate encoding and decoding methods can be flexibly selected in practical applications.
[0076] In addition, after the encrypted data is decrypted by the decryption key, a signature verification operation may be performed on the obtained decrypted data, so that the decrypted data obtained by decryption is used as the target configuration content only when the signature verification operation passes. Specifically, step S224 may also include steps S225 to S227.
[0077] Step S225: Decrypt the encrypted data based on the decryption key to obtain first decrypted data.
[0078] Step S226: Verify the signature content based on the public key certificate to obtain second decrypted data.
[0079] Step S227: When it is detected that the first decrypted data matches the second decrypted data, the first decrypted data is used as target configuration content for configuring the detection rule configuration file.
[0080] For some implementations, the feedback content may also include signature content and a public key certificate. The signature content is the content generated by the cloud server based on the private key certificate and the target configuration content. For example, a hash operation may be performed on the target configuration content to obtain an information summary, and then the obtained information summary may be encrypted by a private key certificate to obtain the signature content. The public key certificate matches the private key certificate used to encrypt the information summary. Thus, the signature content may be verified by the public key certificate to obtain the second decrypted data. Exemplarily, when the obtained summary is encrypted by a private key certificate, the second decrypted data is the information summary.
[0081] Therefore, after obtaining the encrypted data, the encrypted data can be decrypted based on the decryption key to obtain the first decrypted data. Then, the signature content can be verified based on the public key certificate to obtain the second decrypted data.
[0082] Further, it is possible to determine whether the first decrypted data matches the second decrypted data, so that when it is detected that the first decrypted data matches the second decrypted data, the first decrypted data is used as the target configuration content for configuring the detection rule configuration file. It is understandable that when it is detected that the first decrypted data matches the second decrypted data, it can be considered that the signature verification operation has passed.
[0083] For some implementations, verification information corresponding to the first decrypted data may be obtained, and then the verification information and the second decrypted data may be used to determine whether the first decrypted data matches the second decrypted data. Specifically, step S227 may further include step S228 and step S229.
[0084] Step S228: Obtain verification information corresponding to the first decrypted data based on a hash algorithm.
[0085] Step S229: When it is detected that the verification information is the same as the second decrypted data, the first decrypted data is used as target configuration content for configuring the detection rule configuration file.
[0086] In some implementations, the verification information corresponding to the first decrypted data may be obtained based on a hash algorithm. Specifically, a hash calculation may be performed on the first decrypted data to obtain the verification information corresponding to the first decrypted data.
[0087] Here, a hash calculation is performed on the first decrypted data to obtain an output value of a fixed length, and the output value is the hash value.
[0088] When the cloud server performs hashing technology on the target configuration content and encrypts the target configuration content after hashing through the private key certificate, the second decrypted data is the target configuration content after hashing. Therefore, when it is detected that the verification information is the same as the second decrypted data, the first decrypted data is used as the target configuration content for configuring the detection rule configuration file.
[0089] When it is detected that the verification information is different from the second decrypted data, it can be indicated that the acquired target configuration content has been maliciously tampered with by a third party. In this case, the target configuration content can be reacquired.
[0090] Optionally, the above hash calculation may be a hash calculation based on a SHA-256 function.
[0091] Optionally, for some implementations, the target vehicle may also encode the first decrypted data after hash calculation, such as performing Base64 encoding, so as to use the encoded data as verification information corresponding to the first decrypted data.
[0092] Step S230: Update the detection rule configuration file based on the target configuration content.
[0093] Among them, step S230 has been introduced in detail in the above embodiment and will not be repeated here.
[0094] The configuration content update method provided in the embodiment of the present application improves the security of the data transmission process by encrypting the data in the cloud server and decrypting the encrypted data in the target vehicle. Moreover, it does not have a negative impact on the update efficiency of the detection rule configuration file, and still has a high update efficiency of the detection rule configuration file.
[0095] See also Figure 4 , Figure 4 A method flow chart of a configuration content update method provided by an embodiment of the present application is shown. The configuration content update method can be applied to Figure 1 In the configuration content update scenario shown in , it can be specifically applied to the target vehicle. The configuration content update method specifically includes steps S310 to S380.
[0096] Step S310: receiving feedback content sent by the cloud server based on the configuration content query request.
[0097] Step S320: Obtaining encrypted data from a cloud server based on the target address.
[0098] Step S330: Base64 decoding.
[0099] Step S340: SM4 decryption.
[0100] Step S350: Hash256 verification.
[0101] Step S360: Base64 encoding.
[0102] Step S370: Signature verification.
[0103] Step S380: Obtain target configuration content.
[0104] For some implementations, feedback content can be obtained from the cloud server, wherein the feedback content may include the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and prevention system, download address information, decryption key, signature content and public key certificate. Thus, the target address can be determined based on the download address information, and then the encrypted data can be obtained from the cloud server based on the target address.
[0105] Furthermore, after performing Base64 decoding, SM4 decryption, Hash256 verification and Base64 encoding on the encrypted data, verification information corresponding to the first decrypted data can be obtained.
[0106] In addition, the second decrypted data can be obtained by combining the signature content and the public key certificate, and the verification information can be verified by the second decrypted data. Therefore, when it is detected that the verification information is the same as the second decrypted data, the first decrypted data is used as the target configuration content for configuring the detection rule configuration file.
[0107] The detailed description of the above steps can be found in the description of the above embodiments, which will not be repeated here.
[0108] See also Figure 5 , Figure 5 A structural block diagram of a configuration content updating device provided in an embodiment of the present application is shown, which is applied to a target vehicle. The configuration content updating device 500 includes: an acquisition unit 510 and an update unit 520 .
[0109] The acquisition unit 510 is used to acquire target configuration content used to configure the detection rule configuration file from the cloud server when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated.
[0110] Optionally, the acquisition unit 510 can also be used to detect whether the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated when it is detected that the target vehicle switches from a power-off state to a power-on state; when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, obtain the target configuration content used to configure the detection rule configuration file from the cloud server.
[0111] Optionally, the acquisition unit 510 can also be used to send a configuration content query request to the cloud server when it is detected that the target vehicle switches from a power-off state to a power-on state; receive feedback content sent by the cloud server based on the configuration content query request, wherein the feedback content includes the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system; obtain the current version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle; and when the current version information is different from the latest version information, determine that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated.
[0112] Optionally, the acquisition unit 510 can also be used to determine the target address based on the download address information when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated; and obtain the target configuration content for configuring the detection rule configuration file from the cloud server based on the target address.
[0113] Optionally, the acquisition unit 510 may also be used to acquire encrypted data from a cloud server based on the target address;
[0114] The encrypted data is decrypted based on the decryption key to obtain target configuration content for configuring the detection rule configuration file.
[0115] Optionally, the acquisition unit 510 can also be used to decrypt the encrypted data based on the decryption key to obtain first decrypted data; verify the signature content based on the public key certificate to obtain second decrypted data; and when it is detected that the first decrypted data matches the second decrypted data, use the first decrypted data as the target configuration content for configuring the detection rule configuration file.
[0116] Optionally, the acquisition unit 510 can also be used to obtain verification information corresponding to the first decrypted data based on a hash algorithm; when it is detected that the verification information is the same as the second decrypted data, the first decrypted data is used as the target configuration content for configuring the detection rule configuration file.
[0117] The updating unit 520 is configured to update the detection rule configuration file based on the target configuration content.
[0118] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices and units can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here.
[0119] In several embodiments provided in the present application, the coupling between the units may be electrical, mechanical or other forms of coupling. In addition, each functional unit in each embodiment of the present application may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0120] See also Figure 6 , Figure 6 The structural block diagram of an electronic device provided by an embodiment of the present application is shown. The electronic device 1000 may be a vehicle system, which may be arranged in a vehicle. The electronic device 1000 in the present application may include one or more of the following components: a processor 1011, a memory 1012, and one or more application programs, wherein the processor 1011 is electrically connected to the memory 1012, and the one or more program configurations are used to execute the methods described in the above-mentioned configuration content update method embodiments.
[0121] The processor 1011 may include one or more processing cores. The processor 1011 uses various interfaces and lines to connect various parts of the entire electronic device 1000, and executes various functions and processes data of the electronic device 1000 by running or executing instructions, programs, code sets or instruction sets stored in the memory 1012, and calling data stored in the memory 1012. Optionally, the processor 1011 can be implemented in at least one hardware form of digital signal processing (DSP), field programmable gate array (FPGA), and programmable logic array (PLA). The processor 1011 can integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes the operating system, user interface, and computer programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It is understandable that the above-mentioned modem may not be integrated into the processor 1011, but may be implemented by a communication chip alone. Specifically, the method described in the above-mentioned embodiment may be executed by one or more processors 1011.
[0122] For some embodiments, the memory 1012 may include a random access memory (RAM) or a read-only memory (ROM). The memory 1012 may be used to store instructions, programs, codes, code sets, or instruction sets. The memory 1012 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function, instructions for implementing the following various method embodiments, etc. The data storage area may also store data created by the electronic device 1000 during use, etc.
[0123] See also Figure 7 , which shows a structural block diagram of a computer-readable storage medium provided in an embodiment of the present application. The computer-readable medium 700 stores program codes, which can be called by a processor to execute the method described in the above method embodiment.
[0124] The computer readable storage medium 700 can be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Optionally, the computer readable storage medium 700 includes a non-transitory computer-readable storage medium. The computer readable storage medium 700 has storage space for program code 710 that executes any method step in the above method. These program codes can be read from or written into one or more computer program products. The program code 710 can be compressed, for example, in an appropriate form.
[0125] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A configuration content updating method, characterized in that: Applied to target vehicles, including: When it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, obtaining target configuration content for configuring the detection rule configuration file from the cloud server; The detection rule configuration file is updated based on the target configuration content.
2. The method according to claim 1, characterized in that When it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, obtaining target configuration content for configuring the detection rule configuration file from the cloud server includes: When it is detected that the target vehicle switches from a power-off state to a power-on state, detecting whether a detection rule configuration file of a vehicle-side intrusion detection and defense system of the target vehicle needs to be updated; When it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target configuration content for configuring the detection rule configuration file is obtained from the cloud server.
3. The method according to claim 2, characterized in that When detecting that the target vehicle switches from a power-off state to a power-on state, detecting whether a detection rule configuration file of a vehicle-side intrusion detection and defense system of the target vehicle needs to be updated includes: When detecting that the target vehicle switches from a power-off state to a power-on state, sending a configuration content query request to the cloud server; Receiving feedback content sent by the cloud server based on the configuration content query request, wherein the feedback content includes the latest version information of the detection rule configuration file of the vehicle-side intrusion detection and defense system; Obtaining current version information of a detection rule configuration file of a vehicle-side intrusion detection and prevention system of the target vehicle; In a case where the current version information is different from the latest version information, it is determined that a detection rule configuration file of the vehicle-side intrusion detection and defense system that detects the target vehicle needs to be updated.
4. The method according to claim 3, characterized in that The feedback content also includes download address information. When it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, the target configuration content for configuring the detection rule configuration file is obtained from the cloud server, including: In the case where it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated, determining the target address based on the download address information; Based on the target address, target configuration content for configuring the detection rule configuration file is obtained from the cloud server.
5. The method according to claim 4, characterized in that The feedback content also includes a decryption key, and the acquiring of target configuration content for configuring the detection rule configuration file from the cloud server based on the target address includes: Obtaining encrypted data from a cloud server based on the target address; The encrypted data is decrypted based on the decryption key to obtain target configuration content for configuring the detection rule configuration file.
6. The method according to claim 5, characterized in that The feedback content also includes signature content and a public key certificate. The encrypted data is decrypted based on the decryption key to obtain target configuration content for configuring the detection rule configuration file, including: Decrypting the encrypted data based on the decryption key to obtain first decrypted data; Verify the signature content based on the public key certificate to obtain second decrypted data; In a case where it is detected that the first decrypted data matches the second decrypted data, the first decrypted data is used as target configuration content for configuring the detection rule configuration file.
7. The method according to claim 6, characterized in that The method of using the first decrypted data as target configuration content for configuring the detection rule configuration file when it is detected that the first decrypted data matches the second decrypted data includes: Obtaining verification information corresponding to the first decrypted data based on a hash algorithm; In a case where it is detected that the verification information is identical to the second decrypted data, the first decrypted data is used as target configuration content for configuring the detection rule configuration file.
8. A configuration content updating device, characterized in that: Applied to target vehicles, including: An acquisition unit, configured to acquire target configuration content for configuring the detection rule configuration file from a cloud server when it is detected that the detection rule configuration file of the vehicle-side intrusion detection and defense system of the target vehicle needs to be updated; An updating unit is used to update the detection rule configuration file based on the target configuration content.
9. An electronic device, characterized in that: include: one or more processors; Memory; One or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, and the program code can be called by a processor to execute the method according to any one of claims 1 to 7.
Citation Information
Cited By
Equipment network access method and device, electronic equipment, storage medium and program product
CN121510009A