CAN network detection method, device, equipment, medium and program product

By using encrypted packets and error frame analog signals in the CAN network, the high storage space and hardware computing power required for real-time analysis of the CAN network in the prior art is solved, and more efficient detection efficiency and convenience are achieved.

CN120075035APending Publication Date: 2025-05-30ECARX (HUBEI) TECHCO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510231088.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When the prior art analyzes the characteristic data of the CAN network in real time, a large amount of storage space and hardware computing power is required, which increases the burden on the vehicle system and reduces the detection efficiency of illegal devices in the CAN network.

Method used

By acquiring the real-time driving status of the vehicle, an encrypted message is generated and sent to each detected device through the CAN bus. After the encrypted message is sent, an error frame analog signal is sent to determine whether there is an abnormal detected device.

Benefits of technology

The computing power of detecting CAN network is reduced, the detection efficiency of illegal equipment and legal faulty equipment in the CAN network is improved, and the detection convenience is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075035A_ABST
    Figure CN120075035A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a CAN network detection method and device, equipment, a medium and a program product. The method comprises the steps of obtaining a real-time driving state of a vehicle, generating an encrypted message based on the real-time driving state, sending the encrypted message to each detected device in a CAN network through a CAN bus of the vehicle, sending an error frame analog signal to the CAN bus after the encrypted message is sent for a first preset time period, and sending the error frame analog signal to the detected device in the CAN network. The method comprises the following steps: receiving an error frame analog signal from a CAN bus, enabling an abnormal detected device to receive the error frame analog signal, making an active error frame response to the error frame analog signal, and generating an anomaly detection result to indicate that the abnormal detected device exists in the CAN network when determining that the active error frame exists on the CAN bus. The method is used for achieving the effects of reducing the computing power for detecting the CAN network, improving the detection efficiency of illegal equipment and legal fault equipment in the CAN network and improving the detection convenience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a method, device, equipment, medium and program product for detecting a CAN network. Background Art

[0002] The CAN (Controller Area Network) bus is widely used in the automotive industry. By connecting various devices and / or equipment in the vehicle to the CAN bus, the CAN network of the vehicle is obtained.

[0003] In order to avoid the illegal devices connected to the vehicle system from miscontrolling the vehicle system, the prior art deploys a logic algorithm in the devices connected to the CAN network in the vehicle, so that the above devices can perform real-time analysis on the characteristic data such as the message traffic of the CAN network, determine whether there are abnormal messages, and determine that there are illegal devices in the current CAN network when there are abnormal messages.

[0004] However, the prior art needs to use a large amount of storage space and hardware computing power for real-time analysis of the characteristic data of the CAN network, which increases the burden on the vehicle system, and thus easily reduces the detection efficiency of illegal devices in the CAN network. Summary of the Invention

[0005] The embodiments of the present application provide a method, device, equipment, medium and program product for detecting a CAN network, so as to reduce the computing power for detecting the CAN network, improve the detection efficiency of illegal devices and legitimate faulty devices in the CAN network, and improve the detection convenience.

[0006] In a first aspect, the embodiments of the present application provide a method for detecting a CAN network, including:

[0007] Obtain the real-time driving state of the vehicle; generate an encrypted message based on the real-time driving state, and send it to each device to be detected through the CAN bus of the vehicle;

[0008] After a first preset time period after sending the encrypted message, send an error frame simulation signal to the CAN bus to determine whether there is at least one device to be detected sending an active error frame to the CAN bus; when it is determined that there is, generate an abnormal detection result, and the abnormal detection result is used to indicate that there are abnormal devices to be detected in the CAN network, and the abnormal devices to be detected include illegal devices and legitimate faulty devices.

[0009] Optionally, generating an encrypted message based on the real-time driving state and sending it to each device to be detected through the CAN bus of the vehicle specifically includes:

[0010] Determine whether the real-time driving state is any one of the states in the trigger table;

[0011] When in any one of the states in the trigger table, the instruction message is processed by a preset private key to generate an encrypted message;

[0012] The encrypted message is sent to the CAN bus of the vehicle so that each detected device receives the encrypted message through the CAN bus.

[0013] Optionally, when the encrypted message is sent to a legal detected device, the encrypted message is used to enable the legal detected device to parse and process the encrypted message based on a preset public key to obtain a verified instruction message;

[0014] The instruction message is used to instruct the legal detected device to close the corresponding transceiver and reopen the corresponding transceiver after a second preset time period. After the transceiver is closed, the error frame simulation signal on the CAN bus is not received.

[0015] Optionally, determining whether there is at least one detected device sending an active error frame to the CAN bus specifically includes:

[0016] Real-time monitoring of the level status of the CAN bus;

[0017] When the level status is the dominant level status, it is determined that there is at least one detected device sending an active error frame to the CAN bus.

[0018] Optionally, the dominant level status is sent to the CAN bus when an abnormal detected device reads an error frame simulation signal on the CAN bus.

[0019] In a second aspect, an embodiment of the present application provides a detection device for a CAN network, including:

[0020] An acquisition module, configured to acquire the real-time driving state of the vehicle; generate an encrypted message based on the real-time driving state, and send it to each detected device through the CAN bus of the vehicle;

[0021] A processing module, configured to send an error frame simulation signal to the CAN bus after a first preset time period when the encrypted message is sent, to determine whether there is at least one detected device sending an active error frame to the CAN bus;

[0022] The processing module is further configured to generate an abnormal detection result when it is determined that there is one, and the abnormal detection result is used to indicate that there is an abnormal detected device in the CAN network. The abnormal detected devices include illegal devices and legal faulty devices.

[0023] Optionally, the acquisition module is further configured to determine whether the real-time driving state is any one of the states in the trigger table;

[0024] When in any state in the touch table, the instruction message is processed by a preset private key to generate an encrypted message.

[0025] The encrypted message is sent to the CAN bus of the vehicle so that each detected device receives the encrypted message through the CAN bus.

[0026] Optionally, the processing module is further configured to, when sending the encrypted message to a legitimate detected device, the encrypted message is used to enable the legitimate detected device to perform parsing processing on the encrypted message based on a preset public key to obtain a verified instruction message.

[0027] The instruction message is used to instruct the legitimate detected device to close the corresponding transceiver and reopen the corresponding transceiver after a second preset time period. Among them, after the transceiver is closed, the error frame simulation signal on the CAN bus is not received.

[0028] Optionally, the processing module is further configured to monitor the level state of the CAN bus in real time.

[0029] When the level state is a dominant level state, it is determined that at least one detected device sends an active error frame to the CAN bus.

[0030] Optionally, the processing module is further configured to monitor the dominant level state sent to the CAN bus when an abnormal detected device reads an error frame simulation signal on the CAN bus.

[0031] In a third aspect, an embodiment of the present application provides a vehicle system, which includes a detection device and multiple detected devices.

[0032] The detection device and the multiple detected devices communicate through accessing the CAN bus; the detection device is configured to execute the above first aspect and / or various possible implementation manners of the first aspect.

[0033] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor.

[0034] The memory stores computer execution instructions.

[0035] The processor executes the computer execution instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementation manners of the first aspect.

[0036] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer execution instructions are stored, and when the computer execution instructions are executed by a processor, they are used to implement the above first aspect and / or various possible implementation manners of the first aspect.

[0037] Sixth aspect, an embodiment of the present application provides a computer program product, including a computer program which, when executed by a processor, implements the above first aspect and / or various possible implementation manners of the first aspect.

[0038] The CAN network detection method, device, equipment, medium and program product provided by the embodiments of the present application obtain the real-time driving state of a vehicle, generate an encrypted message based on the real-time driving state, send the encrypted message to each detected device in the CAN network through the CAN bus of the vehicle, and send an error frame simulation signal to the CAN bus after a first preset time period after sending the encrypted message, so that an abnormal detected device receives the error frame simulation signal and makes an active error frame response to the error frame simulation signal. When it is determined that there is an active error frame on the CAN bus, an abnormal detection result is generated to indicate that there is an abnormal detected device in the CAN network. The present application reduces the computing power used to detect the CAN network, improves the detection efficiency of illegal devices and legal faulty devices in the CAN network, and improves the detection convenience. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0040] Figure 1 It is a schematic diagram of an application scenario of the CAN network detection method provided by the present application;

[0041] Figure 2 It is a flowchart of the CAN network detection method provided by the present application Figure 1 ;

[0042] Figure 3 It is a flowchart of the CAN network detection method provided by the present application Figure 2 ;

[0043] Figure 4 It is a schematic structural diagram of the CAN network detection device provided by the present application;

[0044] Figure 5 It is a schematic structural diagram of the electronic device provided by the present application.

[0045] Through the above accompanying drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These accompanying drawings and text descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0047] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, complies with the relevant laws, regulations, and standards of the relevant regions, adopts necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for users to choose to authorize or refuse.

[0048] The CAN bus is a serial communication protocol bus for real-time applications. It transmits signals to each device connected to the CAN bus through twisted pairs, thus forming a CAN network. Figure 1 It is a schematic diagram of the application scenario of the CAN network detection method provided by the present application. As Figure 1 shown, the specific application scenario of the present application includes a CAN bus, Device 1, Device 2,..., Device n, where n is a positive integer. Each device includes a transceiver, a CAN controller, and a processor. The CAN controller and / or the processor are used to control the transceiver to send and / or read data to / from the CAN bus. The CAN bus includes a CAN_H line and a CAN_L line. Each device communicates by connecting the CAN_H line and the CAN_L line. When multiple devices output different electrical levels to the CAN bus simultaneously, the CAN bus is in a dominant level state. Based on the vehicle's CAN network, since the CAN bus has no identity authentication mechanism for the connected devices, each device can access the CAN network by connecting the CAN_H line and the CAN_L line. Therefore, an illegally connected device can transmit any data to other devices through the CAN bus, which may easily cause other devices to output instructions that are not expected by the user, reducing the stability of the vehicle's internal system and the driving safety.

[0049] To detect a CAN network, the prior art deploys a logic algorithm to each device connected to the CAN network, enabling each device to perform real-time analysis on characteristic data such as the message traffic transmitted in the CAN network, thereby determining whether there are abnormal messages on the CAN bus and determining the existence of illegal devices when there are abnormal messages. However, real-time detection and analysis of the characteristic data of the CAN network consume a large amount of storage space and hardware computing power, increasing the system burden. In addition, the prior art realizes the detection of the CAN bus by connecting a dedicated hardware device to the CAN network. However, the R & D cost of the dedicated hardware device is relatively high, and the system architecture of the whole vehicle needs to be adjusted when connecting to the CAN network, further increasing the detection cost.

[0050] The detection method of the CAN network provided by this application obtains the real-time driving state of the vehicle through a detection device. When the real-time driving state meets the state in the trigger table, an encrypted message is generated through a preset private key and sent to each detected device through the CAN bus, so that the detected device with the preset public key can parse and identify the encrypted message, and close the corresponding transceiver according to the parsing result. After the first preset time period when the detection device sends the encrypted message, an error frame simulation signal is sent to the CAN bus, so that the detected device without the preset public key can receive the error frame simulation signal through the CAN bus and feedback an active error frame to the CAN bus for the error frame simulation signal. When the detection device monitors the dominant level state on the CAN bus, it is determined that at least one detected device in the current CAN network is an abnormal detected device, and an abnormal detection result is generated. This application triggers the detection process when the state in the trigger table is met, reducing the system occupancy of the normal function response of the vehicle, not relying on dedicated hardware devices, expanding the usage scenario, reducing the detection cost, and detecting legal faulty devices that cannot communicate effectively while detecting illegal devices, improving the reliability and convenience of CAN network detection and further improving the detection efficiency.

[0051] The following uses specific embodiments to elaborate in detail on the technical solution of this application and how the technical solution of this application solves the above technical problems. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0052] Figure 2 Flow schematic of the detection method of the CAN network provided by this application Figure 1 as Figure 2 shown, this method includes:

[0053] S201. Obtain the real-time driving state of the vehicle, and generate an encrypted message based on the real-time driving state and send it to each detected device.

[0054] More specifically, obtain the real-time driving state of the vehicle; generate an encrypted message based on the real-time driving state and send it to each detected device through the vehicle's CAN bus.

[0055] Optionally, the vehicle system of the vehicle includes a detection device and multiple detected devices, and the detection device and the multiple detected devices communicate through accessing the CAN bus. Among them, each device of the vehicle system accesses the CAN bus for communication, and the detection device is any legal device that has the function of obtaining the real-time driving state of the vehicle and accesses the CAN bus in the vehicle system. In this embodiment, the legal device inside the vehicle system is used to detect the CAN network, which reduces the detection cost of reconnecting dedicated hardware devices, eliminates the need to deploy complex logic algorithms to each connected device, reduces the burden on the vehicle system, and improves the detection convenience.

[0056] Exemplarily, the detection device is determined according to the user instruction, where the user instruction includes but is not limited to the device identifier. Determine the device corresponding to the device identifier as the detection device.

[0057] Optionally, generating an encrypted message based on the real-time driving state and sending it to each detected device through the vehicle's CAN bus specifically includes: determining whether the real-time driving state is any one of the states in the trigger table; when it is any one of the states in the trigger table, process the instruction message with a preset private key to generate an encrypted message; send the encrypted message to the vehicle's CAN bus so that each detected device receives the encrypted message through the CAN bus.

[0058] Optionally, the trigger table includes multiple preset states. For example, any one of the preset states is the state where the vehicle is not driving and the handbrake is pulled up.

[0059] In a possible embodiment, the detection device specified by the user obtains the real-time driving state of the vehicle, and when it is determined that the current driving state is the state where the vehicle is not driving and the handbrake is pulled up, generates a detection instruction message, encrypts the instruction message with a preset private key to generate an encrypted message, and sends the encrypted message to the CAN bus through the transceiver that controls the detection device, so that each device accessing the CAN bus receives the encrypted message sent by the detection device to the CAN bus. In this embodiment, when it is determined that the driving state of the current vehicle meets any one of the preset states in the trigger table, the instruction message is generated into an encrypted message with a preset private key to trigger the detection process through the encrypted message, so that it is not necessary to monitor and analyze the characteristic data of the CAN bus in real time, reducing the computing power occupied by the CAN network detection process, reducing the occupation of the vehicle system storage space, improving the security of the instruction message, preventing illegal devices from obtaining the instruction message and miscontrolling the vehicle, and enhancing the stability of the vehicle system.

[0060] More specifically, when sending an encrypted message to a legitimate device under test, the encrypted message is used to enable the legitimate device under test to parse and process the encrypted message based on a preset public key to obtain an instruction message that passes verification; the instruction message is used to instruct the legitimate device under test to close the corresponding transceiver and reopen the corresponding transceiver after a second preset time period. After the transceiver is closed, error frame simulation signals on the CAN bus are not received.

[0061] In a possible embodiment, when the legitimate device under test receives the encrypted message, it decrypts the encrypted message using the preset public key. After successful decryption, it obtains the instruction message, closes the corresponding transceiver according to the instruction of the instruction message, and reopens the corresponding transceiver after a second preset time period (e.g., 1 second). During the second preset time period when the transceiver of the legitimate device under test is closed, the detection device detects the CAN network. After the second preset time period, the legitimate device under test accesses the CAN bus in time to participate in normal communication. In this embodiment, encrypted communication is performed between the detection device and the legitimate device under test to transmit recognizable and valid signals to the legitimate device under test, so that the legitimate device under test closes the transceiver after successful recognition, thereby providing a detection environment for the detection device and realizing effective detection of the CAN network and improving the reliability of the detection result.

[0062] S202. After a first preset time period from sending the encrypted message, send an error frame simulation signal to the CAN bus to determine whether there is at least one device under test sending an active error frame to the CAN bus.

[0063] More specifically, the detection device waits for the first preset time period after sending the encrypted message to enable the legitimate device under test to close the corresponding transceiver within the first preset time period. After the first preset time period, an error frame simulation signal is sent to the CAN bus. The error frame simulation signal is an analog signal based on the bit stuffing rule. The bit stuffing rule is that during the CAN network communication process, to avoid the level on the CAN bus remaining unchanged for a long time (i.e., continuously presenting as a continuous dominant level or a continuous recessive level), when the sending end sends data, if it detects that 5 identical bits (0 or 1) have been sent, a reverse bit (i.e., a stuffed bit) is inserted. When the receiving end receives the data, the stuffed bit inserted by the sending end is removed and the original data is restored. An active error frame is sent to the CAN bus when the receiving end receives more than 5 identical bits, that is, it is confirmed that there is a bit stuffing error on the CAN bus. At this time, an active error frame (i.e., 6 consecutive dominant levels) is sent to the CAN bus to increase the probability that other receiving ends accessing the CAN bus recognize that there is a bit stuffing error on the CAN bus.

[0064] Optionally, it is determined whether there is at least one detected device sending an active error frame to the CAN bus, specifically including: real-time monitoring of the level state of the CAN bus; when the level state is a dominant level state, it is determined that there is at least one detected device sending an active error frame to the CAN bus.

[0065] Optionally, the dominant level state is sent to the CAN bus when an abnormal detected device reads an error frame analog signal on the CAN bus.

[0066] In a possible embodiment, after the detection device sends an encrypted message for the first preset time period (e.g., 1.5 seconds), it sends an error frame analog signal to the CAN bus, so that a legitimate detected device that has turned off its transceiver within the first preset time period cannot receive the error frame analog signal on the CAN bus, and an abnormal detected device that has not turned off its corresponding transceiver within the first preset time period can receive the error frame analog signal on the CAN bus, and when it recognizes a bit stuffing error in the error frame analog signal, it sends an active error frame (i.e., 6 consecutive dominant levels) to the CAN bus. After the detection device sends the error frame analog signal, it real-time monitors the level state of the CAN bus, and when it detects a dominant level state, it determines that there is at least one detected device in the current CAN network sending an active error frame to the CAN bus. This embodiment enables the abnormal detected device to automatically trigger the transmission of the dominant level according to the error frame analog signal, so that the detection device can determine that there is at least one detected device sending an active error frame to the CAN bus when it detects the dominant level on the CAN bus, improving the detection efficiency and convenience of the CAN network, enhancing the reliability of the detection result, and without relying on a large amount of storage space and hardware computing power, reducing the cost of detecting the CAN network.

[0067] S203. When it is determined that there is such a situation, generate an abnormal detection result.

[0068] More specifically, when it is determined that there is such a situation, generate an abnormal detection result, and the abnormal detection result is used to indicate that there is an abnormal detected device in the CAN network, and the abnormal detected devices include illegal devices and legitimate faulty devices.

[0069] In a possible embodiment, when a legitimate detected device has a fault (i.e., a legitimate faulty device), it is difficult to effectively identify the command message, so it is difficult to effectively disconnect from the CAN network within the second preset time period, and after the detection device sends an error frame analog signal, in response to the error frame analog signal, it sends an active error frame to the CAN bus. The detection device generates an abnormal detection result based on the active error frame sent by the legitimate faulty device to indicate that there is a fault in the legitimate detected device in the current CAN network.

[0070] Exemplarily, an illegal device is a device that invades the vehicle system, and a legal faulty device is a non-invasive device with a fault in the vehicle system.

[0071] In a possible embodiment, when it is determined that at least one detected device in the current CAN network has sent an active error frame to the CAN bus, an abnormal detected device is determined, and an abnormal detection result is generated to indicate that there is an abnormal detected device in the CAN network.

[0072] Exemplarily, after the detection device is determined, the preset private key of the detection device and the preset public key of the detected device are pre-configured by the user.

[0073] Exemplarily, the above-mentioned preset private key and preset public key are updated every preset period.

[0074] Exemplarily, when it is determined that there is an abnormal detected device in the CAN network, the above-mentioned preset private key and preset public key are updated to prevent the preset private key and / or preset public key from being stolen.

[0075] The detection method of the CAN network provided by the embodiments of the present application generates an encrypted message according to the real-time driving state and sends it to each detected device through the CAN bus, and sends error frame simulation information after the first preset time period to determine whether there are illegal devices or legal faulty devices in the CAN network through the error frame simulation information, reducing the occupation of the vehicle system's storage space and computing power, improving the detection efficiency and detection reliability, reducing the impact on the normal operation of the vehicle system, and improving the stability of the vehicle system.

[0076] Figure 3 Schematic flow of the detection method of the CAN network provided by the present application Figure 2 , as Figure 3 shown, based on the Figure 2 embodiment, the detection method of the CAN network is described in detail. The method includes the following steps: The detection device, detected device 1, detected device 2, and detected device 3 in the vehicle system communicate with each other through connection to the CAN bus. Among them, the CAN bus includes CAN_H and CAN_L, as Figure 3 shown in state 1. The detection device obtains the real-time driving state of the vehicle. When the real-time driving state meets any one of the states in the trigger table, an instruction message is generated, and the instruction message is encrypted using the preset private key to obtain an encrypted message and sent to detected device 1, detected device 2, and detected device 3 through the CAN bus, as Figure 3 shown in state 2.

[0077] In a possible embodiment, as Figure 3As shown in State 3, the legitimate DUT 1 uses the preset public key to parse the encrypted message, obtains the instruction message, and closes the corresponding transceiver based on the instruction message, so that the legitimate DUT 1 disconnects from the CAN bus. The legitimate DUT 2 uses the preset public key to parse the encrypted message, obtains the instruction message, and closes the corresponding transceiver based on the instruction message, so that the legitimate DUT 2 disconnects from the CAN bus. After receiving the encrypted message, the abnormal DUT 3 continues to remain connected to the CAN bus and communicates with the detection device through the CAN bus. After sending the encrypted message, the processor of the detection device closes the corresponding CAN controller.

[0078] In a possible embodiment, as Figure 3 shown in State 4, 2 seconds after sending the encrypted message, the processor of the detection device sends an error frame simulation signal to the abnormal DUT 3 through the CAN bus. At this time, the legitimate DUT 1 and the legitimate DUT 2 do not receive the error frame simulation signal.

[0079] In a possible embodiment, as Figure 3 shown in State 5, the abnormal DUT 3 generates an active error frame based on the error frame simulation signal and sends it to the CAN bus. The detection device monitors the level state of the CAN bus in real time, so that when the abnormal DUT 3 sends an active error frame to the CAN bus, it monitors the dominant level state of the CAN bus, determines that there is a DUT in the current CAN network that has transmitted an active error frame to the CAN bus based on the dominant level state, and generates an abnormal detection result.

[0080] In a possible embodiment, after closing the corresponding transceivers for 1 second, the legitimate DUT 1 and the legitimate DUT 2 reopen the transceivers to reconnect to the CAN bus for communication after the detection device completes this detection. At the same time, the detection device reopens the corresponding CAN controller and stops the processor from controlling the transceiver of the detection device, so as to release the processor performance of the detection device in time, reduce the burden on the vehicle system, and improve the performance of the vehicle system.

[0081] The CAN network detection method provided by the embodiments of this application enables the detection device in the vehicle system to send encrypted messages to each DUT through the CAN bus when the real-time driving state of the vehicle reaches the state where detection is triggered, so that the DUT with the preset public key parses the encrypted message and disconnects from the CAN bus for a second preset time period, for the detection device to monitor the level state of the CAN bus in real time during this second preset time period, thereby completing the detection of the CAN network, reducing the computing power used to detect the CAN network, improving the detection efficiency and reliability for illegal devices and faulty devices in the CAN network, and improving the detection convenience of the CAN network.

[0082] Figure 4 The structural schematic diagram of the CAN network detection device provided for this application is as follows Figure 4 As shown, the CAN network detection device 40 provided in this embodiment includes:

[0083] An acquisition module 401, configured to acquire the real-time driving state of the vehicle; generate an encrypted message based on the real-time driving state, and send it to each device to be detected through the CAN bus of the vehicle;

[0084] A processing module 402, configured to send an error frame simulation signal to the CAN bus after a first preset time period after sending the encrypted message, so as to determine whether there is at least one device to be detected sending an active error frame to the CAN bus;

[0085] The processing module 402 is further configured to generate an abnormal detection result when it is determined that there is an abnormal detection result, which is used to indicate that there is an abnormal device to be detected in the CAN network. The abnormal device to be detected includes an illegal device and a legal faulty device.

[0086] Optionally, the acquisition module 401 is further configured to determine whether the real-time driving state is any one of the states in the trigger table;

[0087] When it is any one of the states in the trigger table, process the instruction message through a preset private key to generate an encrypted message;

[0088] Send the encrypted message to the CAN bus of the vehicle, so that each device to be detected receives the encrypted message through the CAN bus.

[0089] Optionally, the processing module 402 is further configured to, when sending the encrypted message to a legal device to be detected, the encrypted message is used to enable the legal device to be detected to parse and process the encrypted message based on a preset public key to obtain a verified instruction message;

[0090] The instruction message is used to instruct the legal device to be detected to close the corresponding transceiver and reopen the corresponding transceiver after a second preset time period. After the transceiver is closed, the error frame simulation signal on the CAN bus is not received.

[0091] Optionally, the processing module 402 is further configured to monitor the level state of the CAN bus in real time;

[0092] When the level state is a dominant level state, it is determined that there is at least one device to be detected sending an active error frame to the CAN bus.

[0093] Optionally, the processing module 402 is further configured to monitor the dominant level state sent to the CAN bus when an abnormal device to be detected reads an error frame simulation signal on the CAN bus.

[0094] The detection device of the CAN network provided in this embodiment can execute the method provided in the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0095] Figure 5 It is a schematic structural diagram of the electronic device provided in this application. As Figure 5 shown, the electronic device 50 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. Among them, the processor 501, the memory 502, and the communication component 503 are connected through a bus 504.

[0096] In the specific implementation process, at least one processor 501 executes the computer-executable instructions stored in the memory 502, so that at least one processor 501 executes the above method.

[0097] For the specific implementation process of the processor 501, reference can be made to the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0098] In the above embodiment, it should be understood that the processor may be a central processing unit (English: Central Processing Unit, abbreviated as: CPU), or other general-purpose processors, digital signal processors (English: Digital Signal Processor, abbreviated as: DSP), application specific integrated circuits (English: Application Specific Integrated Circuit, abbreviated as: ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0099] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.

[0100] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience in representation, the buses in the drawings of the present application are not limited to only one bus or one type of bus.

[0101] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0102] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the processor executes the computer-executable instructions, the above method is implemented.

[0103] The above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0104] An exemplary readable storage medium is coupled to the processor, so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.

[0105] The division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in an electrical, mechanical or other form.

[0106] The unit described as a separate component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed across multiple network units. Some or all of these units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0107] In addition, in each embodiment of the present invention, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0108] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs and other various media that can store program codes.

[0109] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When this program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disks, or optical discs and other various media that can store program codes.

[0110] Finally, it should be noted that: After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily think of other implementation schemes of the present invention. The present invention aims to cover any variations, uses, or adaptive changes of the present invention. These variations, uses, or adaptive changes follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field of the present invention that are not disclosed in the present invention. It is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.

Claims

1. A CAN network detection method, characterized in that: include: Get the real-time driving status of the vehicle; Generate an encrypted message based on the real-time driving status, and send it to each detected device via the CAN bus of the vehicle; After the encrypted message is sent for a first preset time period, an error frame simulation signal is sent to the CAN bus to determine whether there is at least one detected device sending an active error frame to the CAN bus; When it is determined that there is an abnormality, an abnormality detection result is generated, and the abnormality detection result is used to indicate that there is an abnormal detected device in the CAN network, and the abnormal detected device includes an illegal device and a legal faulty device.

2. The method according to claim 1, characterized in that Generate an encrypted message based on the real-time driving status, and send it to each detected device through the CAN bus of the vehicle, specifically including: Determine whether the real-time driving state is any state in the trigger table; When it is any state in the trigger table, the command message is processed by a preset private key to generate an encrypted message; The encrypted message is sent to the CAN bus of the vehicle, so that each detected device receives the encrypted message through the CAN bus.

3. The method according to claim 2, characterized in that Also includes: When the encrypted message is sent to a legitimate detected device, the encrypted message is used to enable the legitimate detected device to parse the encrypted message based on a preset public key to obtain a verified instruction message; The instruction message is used to instruct the legal detected device to turn off the corresponding transceiver and reopen the corresponding transceiver after a second preset time period, wherein after the transceiver is turned off, the error frame simulation signal on the CAN bus is not received.

4. The method according to any one of claims 1 to 3, characterized in that: Determining whether there is at least one detected device sending an active error frame to the CAN bus specifically includes: Real-time monitoring of the level status of the CAN bus; When the level state is a dominant level state, it is determined that there is at least one detected device sending an active error frame to the CAN bus.

5. The method according to claim 4, characterized in that The dominant level state is sent to the CAN bus by the abnormal detected device when it reads an error frame simulation signal on the CAN bus.

6. A CAN network detection device, characterized in that: include: An acquisition module is used to acquire the real-time driving status of the vehicle; Generate an encrypted message based on the real-time driving status, and send it to each detected device via the CAN bus of the vehicle; A processing module, configured to send an error frame simulation signal to the CAN bus after sending the encrypted message for a first preset time period; and determine whether there is at least one detected device sending an active error frame to the CAN bus; The processing module is further used to generate an abnormality detection result when it is determined that there is an abnormal detected device in the CAN network, and the abnormal detected device includes an illegal device and a legal faulty device.

7. A vehicle system, characterized in that: The vehicle system includes a detection device and a plurality of detected devices; The detection device and the multiple detected devices communicate by accessing a CAN bus; the detection device is used to execute the method according to any one of claims 1-5.

8. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 5.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 5 when executed by a processor.

10. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 5 when being executed by a processor.