Communication method, communication service device and communication system based on OTA
By determining and processing the effectiveness of OTA upgrade packets on the server, and sending invalid packets to the client for processing when the resource load is high, the problem of high data processing pressure on the server and malicious data attacks is solved, and the efficiency and success rate of OTA upgrade and write are improved.
Patent Information
- Application Number
- CN202510161298.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-30
AI Technical Summary
When writing ECU pieces in parallel based on OTA, the server side has a high pressure to process data, resulting in low upgrade brushing efficiency and malicious data attacks that lead to the risk of upgrade failure.
By obtaining the upgrade message to be forwarded by the communication client, first determine that it is a valid or invalid upgrade message. If it is valid, it will forward to the target ECU. If it is invalid, it will be illegally processed. When the resource load is greater than the first load threshold, an invalid upgrade message is sent to the communication client for processing.
It effectively alleviates the data processing pressure on the server, improves the efficiency and success rate of upgraded flashing, and prevents the exhaustion of network bandwidth and cache area caused by malicious data attacks.
Smart Images

Figure CN120075213A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to an OTA-based communication method, a communication service device, and a communication system. Background Art
[0002] Automobile OTA (Over the Air Technology) upgrade refers to using over-the-air technology to achieve automobile firmware upgrade and software upgrade.
[0003] Currently, when performing parallel flashing of ECU (Electronic Control Unit) components based on OTA, multiple clients need to be established on the OTA upgrade master to transmit upgrade data packets corresponding to multiple ECU components. The amount of data transmitted is relatively large, and the data processing pressure on the server side is also relatively large, resulting in low upgrade flashing efficiency. In addition, if an attacker sends a large amount of malicious data to the client or the server to exhaust the network bandwidth and buffer, valid data cannot be processed, resulting in upgrade flashing failure.
[0004] Therefore, it is necessary to propose a communication mechanism to relieve the data processing pressure on the server side and improve the efficiency and success rate of upgrade flashing. Summary of the Invention
[0005] In view of this, embodiments of the present application provide an OTA-based communication method, a communication service device, and a communication system to solve the problem of how to relieve the data processing pressure on the server side and improve the efficiency and success rate of upgrade flashing.
[0006] In the first aspect of the embodiments of the present application, an OTA-based communication method applicable to a communication server is provided, including:
[0007] Obtain a to-be-forwarded upgrade packet sent by a communication client;
[0008] If it is determined that the to-be-forwarded upgrade packet is a valid upgrade packet, forward the to-be-forwarded upgrade packet to the target ECU and feedback a first response packet for the to-be-forwarded upgrade packet to the communication client;
[0009] If it is determined that the to-be-forwarded upgrade packet is an invalid upgrade packet, perform illegal data processing on the to-be-forwarded upgrade packet;
[0010] When the current resource load is greater than the first load threshold, send some or all of the invalid upgrade packets to be illegally processed to the communication client so that the communication client performs illegal data processing on the received invalid upgrade packets.
[0011] In the second aspect of the embodiments of the present application, a communication service device is provided, including:
[0012] The first process is configured to obtain the upgrade message to be forwarded sent by the communication client;
[0013] The second process is configured to, if it is determined that the upgrade message to be forwarded is a valid upgrade message, forward the upgrade message to be forwarded to the target ECU and feedback a first response message for the upgrade message to be forwarded to the communication client;
[0014] The illegal processing module is configured to, if it is determined that the upgrade message to be forwarded is an invalid upgrade message, perform illegal data processing on the upgrade message to be forwarded;
[0015] The sending module is configured to, when the current resource load is greater than the first load threshold, send some or all of the invalid upgrade messages to be subjected to illegal data processing to the communication client, so that the communication client performs illegal data processing on the received invalid upgrade messages.
[0016] In the third aspect of the embodiments of the present application, a communication system is provided, including: a communication client, a communication server communicatively connected to the communication client, and an ECU communicatively connected to the communication server or the communication client;
[0017] The communication client is configured to determine the target ECU and send an upgrade message to be forwarded corresponding to the target ECU to the communication server;
[0018] The communication server is configured to obtain the upgrade message to be forwarded sent by the communication client; if it is determined that the upgrade message to be forwarded is a valid upgrade message, forward the upgrade message to be forwarded to the target ECU and feedback a first response message for the upgrade message to be forwarded to the communication client; if it is determined that the upgrade message to be forwarded is an invalid upgrade message, perform illegal data processing on the upgrade message to be forwarded; when the current resource load is greater than the first load threshold, send some or all of the invalid upgrade messages to be subjected to illegal data processing to the communication client;
[0019] The communication client is configured to perform illegal data processing on the received invalid upgrade messages.
[0020] In the fourth aspect of the embodiments of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.
[0021] In the fifth aspect of the embodiments of the present application, a readable storage medium is provided. The readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the above method are implemented.
[0022] Compared with the prior art, the beneficial effects of the embodiments of the present application at least include: when receiving an upgrade message to be forwarded sent by a communication client, first determine whether it is a valid upgrade message or an invalid upgrade message. If it is a valid upgrade message, forward it to the target ECU; if it is an invalid upgrade message, perform illegal data processing. When the current resource load is greater than the first load threshold, send some or all of the invalid upgrade messages to be processed for illegal data to the communication client, and the communication client cooperates to perform illegal data processing on these invalid upgrade messages. This can effectively relieve the data processing pressure on the server, ensure that valid data can be processed, and effectively prevent malicious data sent by attackers from exhausting network bandwidth and buffer areas, thereby improving the success rate of upgrade flashing. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0024] Figure 1 is a schematic diagram of the application scenario of the embodiments of the present application;
[0025] Figure 2 is a schematic flowchart of a communication method based on OTA provided by the embodiments of the present application;
[0026] Figure 3 is a schematic diagram of the communication method between a CDC, a VGW, and an ECU provided by the embodiments of the present application;
[0027] Figure 4 is a schematic diagram of the message structure of an upgrade message to be forwarded provided by the embodiments of the present application;
[0028] Figure 5 is a communication interaction timing diagram between a CDC, a VGW, and a target ECU provided by the embodiments of the present application;
[0029] Figure 6 is another schematic diagram of the communication method between a CDC, a VGW, and an ECU provided by the embodiments of the present application;
[0030] Figure 7 is a schematic diagram of the internal and external modules of a CDC and a VGW provided by the embodiments of the present application;
[0031] Figure 8 is a schematic diagram of the structure of a communication service device provided by the embodiments of the present application;
[0032] Figure 9 This is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0033] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0034] Next, a communication method and device based on OTA according to an embodiment of the present application will be described in detail with reference to the accompanying drawings.
[0035] Figure 1 This is a schematic diagram of an application scenario of an embodiment of the present application.
[0036] Please refer to Figure 1 , this application scenario may include a communication client 101 (also referred to as a data sending end) and a communication server 102 (also referred to as a data receiving end).
[0037] The communication client 101 may be an in-vehicle intelligent cockpit (Cockpit Domain Controller, abbreviated as "CDC"), or a vehicle dynamics control system (Vehicle Dynamics Control, abbreviated as "VDC"), or a mobile data center (Mobile Data Center, abbreviated as "MDC"). An OTA upgrade master control (Upgrade master control, abbreviated as "UMC") is carried in the CDC or MDC or VDC. The communication client 101 can communicate with the OTA cloud platform through a 4G / 5G network to download upgrade files.
[0038] The communication server 102 can be a Vehicle Gateway (abbreviated as "VGW") or a Vehicle Integration Unit (abbreviated as "VIU"). The OTA upgrade agent (UA) is carried in the VGW or VIU. Communication can be carried out between the CDC and the VGW through 100M / 1000M Ethernet (ETH). One or more ECU components can be connected under the communication server 102. Communication can be carried out between the communication server 102 and each of the ECU components connected under it through a CAN (Controller Area Network) bus or an ETH (Ethernet) bus. The OTA upgrade slave (abbreviated as "US") is carried in the ECU component.
[0039] The target ECU (also known as the ECU to be flashed) can be one or more ECU components connected under the VGW. Exemplarily, the target ECU can be ECU1-2, ECU2-1, and ECU2-n connected under the VGW.
[0040] Among them, the specific types, quantities, and combinations of the communication client 101, the communication server 102, and the target ECU can be adjusted according to the actual requirements of the application scenario, and the embodiments of the present application do not limit this.
[0041] Figure 2 It is a schematic flow diagram of a communication method based on OTA provided by the embodiments of the present application. Figure 2 The communication method based on OTA can be performed by Figure 1 the communication server 102.
[0042] Please refer to Figure 2 , the communication method based on OTA in the embodiments of the present application can include the following steps:
[0043] Step S201, obtain the upgrade message to be forwarded sent by the communication client.
[0044] Figure 3 It is a schematic diagram of the communication method between the CDC, VGW, and ECU provided by the embodiments of the present application.
[0045] Please refer to Figure 1 and Figure 3, in some embodiments, in the scenario of OTA parallel flashing of multiple ECU components, for example, the ECU to be flashed (target ECU) includes ECU1-2, ECU2-1, and ECU2-n under the VGW. For the ECU component that supports Ethernet (for example, ECU1-2), the link layer (i.e., layer 2) pass-through can be performed between the OTA upgrade master and ECU1-2 through the VGW to establish a TCP communication connection between the OTA master and ECU1-2, and the DOIP protocol is used for data communication transmission and upgrade flashing. For the ECU component that does not support Ethernet (for example, ECU2-1, ECU2-n), the OTA upgrade master establishes a TCP communication connection with the VGW. The VGW receives and parses the ECU target address in the ETH packet sent by the OTA upgrade master, converts the ETH packet into a UDS (Unified diagnostic services) packet, and then forwards the UDS packet to the target ECU for upgrade flashing.
[0046] In some embodiments, refer to Figure 3 , the communication client 101 (such as CDC) can create a socket client (SOCKER CLIENT) in the OTA upgrade master (UMC). Among them, the socket client (SOCKER CLIENT) includes multiple internal socket clients (such as IN SOCKER CLIENT1, IN SOCKER CLIENT2, and IN SOCKER CLIENTn), an internal socket server (IN SOCKER SERVER), and an external socket client (OUT SOCKER CLIENT); each internal socket client communicates with the internal socket client; the internal socket server communicates with the external socket client; the external socket client communicates with the socket server (SOCKER SERVER) created by the OTA upgrade agent (UA) of the communication server 102 (such as VGW).
[0047] The communication client 101 (such as CDC) can download the upgrade file 1 corresponding to ECU1-2, the upgrade file 2 corresponding to ECU2-1, and the upgrade file n corresponding to ECU2-n from the OTA cloud platform through the OTA upgrade master control (UMC). Then, the upgrade file 1 is transmitted to the internal socket server (IN SOCKER SERVER) through the created IN SOCKER CLIENT1, the upgrade file 2 is transmitted to the internal socket server (IN SOCKER SERVER) through IN SOCKER CLIENT2, and the upgrade file n is transmitted to the internal socket server (IN SOCKER SERVER) through IN SOCKER CLIENTn. After that, the external socket client (OUT SOCKER CLIENT) transmits the upgrade files 1, 2, and n to the socket server (SOCKER SERVER) of the communication server 102 (such as VGW).
[0048] The communication server 102 (such as VGW) can run the first process to obtain the upgrade files to be forwarded (including upgrade files 1, 2, and n) sent by the communication client 101 (such as CDC) through the external socket client (OUT SOCKER CLIENT).
[0049] Through the above method, parallel OTA flashing of ECU files can be achieved, thereby improving the ECU upgrade flashing efficiency.
[0050] Step S202, if it is determined that the upgrade message to be forwarded is a valid upgrade message, then forward the upgrade message to be forwarded to the target ECU and feedback the first response message for the upgrade message to be forwarded to the communication client.
[0051] Please refer to Figure 3 , in some embodiments, if the communication server 102 (such as VGW) confirms that the upgrade files 1, 2, and n are all valid upgrade messages, then the upgrade file 1 can be forwarded to ECU1-2 through the socket server (SOCKER SERVER) created by the OTA upgrade agent (UA) so that ECU1-2 uses the upgrade file 1 for upgrade flashing, the upgrade file 2 is forwarded to ECU2-1 so that ECU2-1 uses the upgrade file 2 for upgrade flashing, and the upgrade file n is forwarded to ECU2-n so that ECU2-n uses the upgrade file n for upgrade flashing.
[0052] Step S203, if it is determined that the upgrade message to be forwarded is an invalid upgrade message, then perform illegal data processing on the upgrade message to be forwarded.
[0053] As an example, the illegal data processing for the upgrade message to be forwarded may be as follows: when the communication server 102 determines that the upgrade message to be forwarded is an invalid upgrade message, it temporarily stores the invalid upgrade message in a preset "illegal data cache space", and at the same time does not feedback the first response message for the upgrade message to be forwarded to the communication client. The preset "illegal data cache space" may be a data storage space set in devices such as the communication server 102 or the cloud.
[0054] As another example, the illegal data processing for the upgrade message to be forwarded may also be: when the communication server 102 determines that the upgrade message to be forwarded is an invalid upgrade message, it clears the invalid upgrade message in real time or periodically.
[0055] In the case of determining that the upgrade message to be forwarded is an invalid upgrade message, temporarily storing the invalid upgrade message in the "illegal data cache space" and not feedbacking the first response message for the upgrade message to be forwarded to the communication client can prevent attackers from obtaining more vulnerability messages, thereby increasing the difficulty of attack for attackers, and further ensuring the security and reliability of data transmission. At the same time, it can ensure that valid upgrade messages can be correctly processed and keep the communication channel unblocked.
[0056] Step S204, when the current resource load is greater than the first load threshold, send some or all of the invalid upgrade messages to be processed for illegal data to the communication client, so that the communication client performs illegal data processing on the received invalid upgrade messages.
[0057] The current resource load indicates the current bus bandwidth and CPU resource occupancy rate of the communication server (such as VGW).
[0058] Generally, when the communication server (such as VGW) needs to process more data messages, its bus bandwidth and CPU resource occupancy rate are relatively high, and the efficiency of processing data messages is also relatively low. For example, when the current bus bandwidth and CPU resource occupancy rate of the communication server (such as VGW) reach more than 80%, its data processing ability is weak and the efficiency is low. Therefore, the first load threshold can be set to 80%.
[0059] As an example, when the current resource load is greater than the first load threshold, the communication server 102 can send some or all of the invalid upgrade messages to be processed for illegal data to the communication client 101, and the communication client 101 performs illegal data processing on these invalid upgrade messages. In this way, the pressure on the communication server 102 to process invalid upgrade messages can be effectively relieved.
[0060] When the technical solution provided by the embodiment of the present application obtains the upgrade message to be forwarded sent by the communication client, it first determines whether it is a valid upgrade message or an invalid upgrade message. If it is a valid upgrade message, it is forwarded to the target ECU. If it is an invalid upgrade message, illegal data processing is performed. When the current resource load is greater than the first load threshold, some or all of the invalid upgrade messages to be subjected to illegal data processing are sent to the communication client, and the communication client performs illegal data processing on these invalid upgrade messages. This can relieve the data processing pressure on the server side, ensure that valid data can be processed, and effectively prevent malicious data sent by attackers from exhausting the network bandwidth and buffer, thereby improving the success rate of upgrade flashing.
[0061] In some embodiments, the upgrade message to be forwarded includes a false address and an encrypted address of the target ECU; the encrypted address is obtained by encrypting the real address of the target ECU;
[0062] Determining that the upgrade message to be forwarded is a valid upgrade message includes:
[0063] When it is recognized that the parsing result of the encrypted address matches the real address of the target ECU, it is determined that the upgrade message to be forwarded is a valid upgrade message; wherein, the parsing result of the encrypted address is obtained by the communication server parsing the encrypted address of the upgrade message to be forwarded;
[0064] Determining that the upgrade message to be forwarded is an invalid upgrade message includes:
[0065] When it is recognized that the parsing result of the encrypted address in the upgrade message to be forwarded does not match the real address of the target ECU, it is determined that the upgrade message to be forwarded is an invalid upgrade message.
[0066] Figure 4 It is a schematic diagram of the message structure of an upgrade message to be forwarded provided by the embodiment of the present application.
[0067] Please refer to Figure 4 , the upgrade message to be forwarded in the embodiment of the present application includes an Ethernet header (EthHead), an IP header (IP Head), a TCP / UDP header (TCP / UDP Head), a data message, and a frame check sequence (FCS). Among them, the IP header includes information such as the source IP address, destination IP address, and protocol type. The TCP / UDP header includes information such as the source port number and destination port number. The communication client and the communication server can establish a TCP communication connection according to the source IP address, destination IP address, protocol type, source port, and destination port.
[0068] The OTA upgrade master control (UMC) of the communication client 101 transmits data and performs upgrade flashing with the communication server 102 and the ECUs connected thereto via the DoIP protocol, and the data packet is a DoIP packet.
[0069] In some embodiments, interference fields (i.e., fake addresses of target ECUs) and identification fields (i.e., encrypted addresses of target ECUs) can be custom-set in the data field of the DoIP packet (i.e., DoIP data). Among them, the interference field can include at least one of the interference ECU source address or the interference ECU destination address. The identification field at least includes an encrypted source address field (i.e., encrypted ECU source address) and an encrypted destination address field (i.e., encrypted ECU destination address). The encrypted source address field can be a value obtained by encrypting the real source address of the ECU (the encryption algorithm can adopt a hash algorithm, etc.). The encrypted destination address field can be a value obtained by encrypting the real destination address of the ECU (the encryption algorithm can adopt a hash algorithm, etc.).
[0070] In some embodiments, the identification field can also include an encrypted ECU component identifier. Among them, the encrypted ECU component identifier can be a value obtained by encrypting and calculating according to the ECU product code, the component code, and the SOC (System on a Chip) identifier (the encryption algorithm can adopt a hash algorithm, etc.).
[0071] As an example, when the communication server 102 (such as VGW) obtains the upgrade packet to be forwarded, it can locate to the starting position of the identifier of the upgrade packet to be forwarded, that is, locate to the starting position of the identification field, and then intercept the identification field with a custom length starting from the starting position of the identification field. Exemplarily, please refer to Figure 4 , if the identification field includes an encrypted ECU component identifier, an encrypted ECU source address, and an encrypted ECU destination address, then the total length (custom length) of the identification field is 8 bytes, and the starting position of the identification field is the 129th bit (bit) of the DoIP data. If the identification field includes an encrypted ECU source address and an encrypted ECU destination address, then the total length (custom length) of the identification field is 4 bytes, and the starting position of the identification field is the 257th bit (bit) of the DoIP data.
[0072] Among them, the positions of the interference field and the identification field in the DoIP data can be flexibly adjusted according to the actual situation. For example, the identification field can be placed in front of the interference field. The positions of the ECU source address and the ECU destination address in the interference field can also be flexibly adjusted. The positions of the encrypted source address field, the encrypted destination address field, and the encrypted ECU component identifier in the identification field can also be flexibly adjusted, and no specific limitation is made in the embodiments of the present application.
[0073] Taking the identification field including the encrypted source address field and the encrypted destination address field as an example, after the communication server 102 (such as VGW) extracts the identification field in the upgrade packet to be forwarded, according to the decryption algorithm corresponding to the encryption algorithm of the encrypted source address field, it decrypts the encrypted source address field to obtain the decrypted source address.
[0074] Similarly, according to the decryption algorithm corresponding to the encryption algorithm of the encrypted destination address field, it decrypts the encrypted destination address field to obtain the decrypted destination address.
[0075] By adopting the custom data packet structure of the present application, illegal data packets can be quickly identified, ensuring the transmission security and reliability of the data packets.
[0076] In some embodiments, the corresponding relationship between each ECU component and its real source address and real destination address can be pre-created and stored in the communication server 102 (such as VGW) or in the cloud for subsequent invocation. Generally, one ECU component corresponds to one real source address and one real destination address.
[0077] If the communication server 102 identifies that the parsing result of the encrypted address of the upgrade packet to be forwarded matches the real address of the target ECU, that is, it queries the real source address corresponding to the decrypted source address of the target ECU and the real destination address corresponding to the decrypted destination address, and the real source address and the real destination address both correspond to the same ECU, then it determines that the upgrade packet to be forwarded is a valid upgrade packet.
[0078] If the communication server 102 does not query the real source address corresponding to the decrypted source address of the target ECU, or does not query the real destination address corresponding to the decrypted destination address of the target ECU, or it queries the real source address corresponding to the decrypted source address of the target ECU and the real destination address corresponding to the decrypted destination address of the target ECU, but the real source address and the real destination address do not correspond to the same ECU, then it can be determined that the upgrade packet to be forwarded is an invalid upgrade packet.
[0079] In some embodiments, the above method may further include the following steps:
[0080] Obtain the reply packet to be forwarded returned by the target ECU for the upgrade packet to be forwarded;
[0081] If it is determined that the reply packet to be forwarded is a valid reply packet, then forward the reply packet to be forwarded to the communication client and feedback a second reply packet for the reply packet to be forwarded to the target ECU;
[0082] If it is determined that the reply packet to be forwarded is an invalid reply packet, then perform illegal data processing on the reply packet to be forwarded.
[0083] Figure 5 This is a communication interaction timing diagram between a CDC, a VGW, and a target ECU provided by an embodiment of the present application.
[0084] As an example, please refer to Figure 5 , the communication interaction process between the CDC, the VGW, and the target ECU in the embodiment of the present application includes the following steps:
[0085] Step 1: The communication client (CDC) sends the upgrade message to be forwarded to the communication server (VGW).
[0086] Step 2: The communication server (VGW) runs the first process to receive the upgrade message to be forwarded and writes it into the first-level service buffer. The first-level service buffer can be a circular buffer set in the communication server 102.
[0087] Step 3: The communication server (VGW) runs the second process to read the upgrade message to be forwarded from the first-level service buffer and parse the upgrade message to be forwarded.
[0088] Step 4: If the communication server (VGW) determines that the upgrade message to be forwarded is a valid upgrade message, it forwards the upgrade message to be forwarded to the target ECU.
[0089] Step 5: The communication server (VGW) returns a first response message to the communication client (CDC), and the first response message indicates that the upgrade message to be forwarded has been successfully received.
[0090] Step 6: The target ECU returns a response message to be forwarded to the communication server (VGW), and the response message to be forwarded indicates that the upgrade message to be forwarded has been successfully received.
[0091] Step 7: The communication server (VGW) runs the first process to obtain the response message to be forwarded returned by the target ECU and writes the response message to be forwarded into the first-level service buffer.
[0092] Step 8: The communication server (VGW) runs the second process to read the response message to be forwarded from the first-level service buffer, perform a first parsing on the response message to be forwarded, and obtain a first parsing result.
[0093] Step 9: If the communication server (VGW) determines that the response message to be forwarded is a valid response message according to the first parsing result, it forwards the response message to be forwarded to the communication client (CDC).
[0094] Step 10: If the communication server (VGW) determines that the response message to be forwarded is an invalid response message according to the first parsing result, it performs illegal data processing on the response message to be forwarded.
[0095] In some embodiments, the packet encapsulation structures of the response packet to be forwarded and the upgrade packet to be forwarded are the same. The communication server (VGW) can parse the response packet to be forwarded according to the above embodiments, and intercept the identification field of the response packet to be forwarded. Then, it is confirmed whether the response packet to be forwarded is a valid response packet through the identification field.
[0096] For example, if the identification field of the response packet to be forwarded includes the encrypted VGW identifier, the encrypted VGW source address, and the encrypted VGW destination address, then the communication server (VGW) can call the decryption algorithm to decrypt the encrypted VGW identifier, the encrypted VGW source address, and the encrypted VGW destination address to obtain a first parsing result, that is, the decrypted VGW identifier, the decrypted VGW source address, and the decrypted VGW destination address; then, compare whether the decrypted VGW identifier is consistent with the actual VGW identifier of the communication server (VGW), compare whether the decrypted VGW source address is consistent with the actual VGW source address of the communication server (VGW), and compare whether the decrypted VGW destination address is consistent with the actual VGW destination address of the communication server (VGW). If all three are consistent, it is confirmed that the response packet to be forwarded is a valid response packet, and the response packet to be forwarded is forwarded to the communication server (CDC), and a second response packet for the response packet to be forwarded is fed back to the target ECU. The second response packet indicates that the communication server (VGW) has successfully received the response packet to be forwarded.
[0097] If at least one of the decrypted VGW identifier and the actual VGW identifier, the decrypted VGW source address and the actual VGW source address, or the decrypted VGW destination address and the actual VGW destination address is inconsistent, then the forwarded response packet is an invalid response packet. The communication server (VGW) stores the response packet to be forwarded in a preset "illegal data cache space" and does not feed back a second response packet for the response packet to be forwarded to the target ECU. In this way, the attacker cannot confirm whether the response packet to be forwarded has been received by the communication server (VGW), thereby improving the communication security and reliability between the communication server (VGW) and the target ECU.
[0098] Figure 6 It is a schematic diagram of another communication method among the CDC, VGW, and ECU provided by the embodiments of the present application.
[0099] As an example, please refer to Figure 1 and Figure 6, assume that the target ECU includes ECU1-2, ECU2-1, and ECU2-n connected under the VGW. ECU1-2, ECU2-1, and ECU2-n respectively return the to-be-forwarded response message 1-2 (corresponding to ECU1-2), the to-be-forwarded response message 2-1 (corresponding to ECU2-1), and the to-be-forwarded response message 2-n (corresponding to ECU2-n) to the VGW. The VGW runs the first process to obtain the to-be-forwarded response messages 1-2, 2-1, and 2-n and writes them into the primary service buffer; then, the socket server (SOCKER SERVER) created by the OTA upgrade agent (UA) runs the second process to read the to-be-forwarded response messages 1-2, 2-1, and 2-n from the primary service buffer and parse the to-be-forwarded response messages 1-2, 2-1, and 2-n. If it is confirmed that the to-be-forwarded response messages 1-2, 2-1, and 2-n are all valid response messages, the to-be-forwarded response messages 1-2, 2-1, and 2-n are forwarded to the socket client (SOCKER CLIENT) created by the OTA master control (UMC) of the communication client (CDC), and then distributed by the socket client (SOCKER CLIENT) to the client buffers 1, 2, and 3. Then, the C1 receiving and parsing unit (corresponding to CLIENT1), the C2 receiving and parsing unit (corresponding to CLIENT2), and the C3 receiving and parsing unit (corresponding to CLIENT3) of the OTA master control (UMC) respectively read the to-be-forwarded response messages 1-2, 2-1, and 2-n from the client buffers 1, 2, and 3 (circular buffers arranged from top to bottom) and parse them. If it is confirmed by parsing that the to-be-forwarded response messages 1-2, 2-1, and 2-n are all valid response messages, a response message for the to-be-forwarded response messages 1-2, 2-1, and 2-n is returned to the socket server (SOCKER SERVER) of the VGW through the socket client (SOCKER CLIENT) to inform the VGW that the to-be-forwarded response messages 1-2, 2-1, and 2-n have been successfully received.
[0100] In some embodiments, performing illegal data processing on the to-be-forwarded response message includes:
[0101] When the current resource load is greater than the first load threshold, some or all of the ineffective response messages to be subjected to illegal data processing are sent down to the communication client so that the communication client performs illegal data processing on the received ineffective response messages.
[0102] As an example, when the current resource load of the communication server 102 is less than or equal to the first load threshold (such as 80%), the communication server 102 processes the illegal data in the to-be-forwarded response message. For example, the communication server 102 can temporarily store the null response message in a preset "illegal data cache space", and at the same time, does not feedback the second response message for the to-be-forwarded response message to the target ECU. In this way, it is possible to prevent attackers from obtaining more vulnerability messages, thereby increasing the difficulty of attack by the attackers, and further ensuring the security and reliability of data transmission. At the same time, it is possible to ensure that the valid response message can be correctly processed and keep the communication channel unblocked.
[0103] As another example, when the current resource load of the communication server 102 is greater than the first load threshold (such as 80%), some or all of the valid response messages can be sent to the communication client, and the communication client is coordinated to process the illegal data in the received null response message. In this way, the data processing pressure on the communication server can be effectively alleviated.
[0104] In some embodiments, when the to-be-forwarded upgrade message or the to-be-forwarded response message is obtained, the to-be-forwarded upgrade message or the to-be-forwarded response message is stored in the first-level service buffer;
[0105] When the to-be-forwarded upgrade message or the to-be-forwarded response message is read from the first-level service buffer, the storage space corresponding to the to-be-forwarded upgrade message or the to-be-forwarded response message in the first-level service buffer is released.
[0106] In some embodiments, the communication server 102 can run the first process to obtain the to-be-forwarded response message or the to-be-forwarded response message, and store the to-be-forwarded response message or the to-be-forwarded response message in the first-level service buffer; then, after running the second process to read the to-be-forwarded response message or the to-be-forwarded response message from the first-level service buffer, the storage space occupied by the to-be-forwarded response message or the to-be-forwarded response message in the first-level service buffer is released. In this way, the utilization rate of the first-level service buffer can be improved, which is beneficial to maintaining the first-level service buffer in a "non-zero window" state, thereby enhancing the data throughput capacity of the first-level service buffer. When the first-level service buffer is in the "zero window" state, the first-level service buffer cannot write data anymore, and it is necessary to wait for the communication server (VGW) to read the data from the first-level service buffer and release the space occupied by the data before continuing to write data packets into it.
[0107] In some embodiments, the above method further includes:
[0108] When the current resource load is greater than or equal to the second load threshold, send a first traffic control instruction to the target ECU and a second traffic control instruction to the communication client; wherein, the first traffic control instruction instructs the target ECU to extend the first time interval for returning the reply message to be forwarded; the second traffic control instruction instructs the communication client to extend the second time interval for sending the upgrade message to be forwarded; the second load threshold is greater than the first load threshold.
[0109] The second load threshold indicates the load critical value at which the communication server can normally process data messages. Usually, when the current bus bandwidth and CPU resource occupancy rate of the communication server reach 90% or more, its data processing ability is very weak, and phenomena such as system lag and abnormal data transmission (such as data transmission interruption, etc.) are likely to occur, thus unable to ensure normal data transmission. Based on this, the second load threshold can be set to 90%.
[0110] The user can customize the first time interval for the target ECU to return the reply message to be forwarded and the second time interval for the communication client (CDC) to send the upgrade to be forwarded according to the actual situation. Among them, the first time interval and the second time interval can be the same or different. For example, both the first time interval and the second time interval are set to 110 milliseconds. Another example is that the first time interval is set to 100 milliseconds and the second time interval is set to 120 milliseconds.
[0111] As an example, assume that the second load threshold is 90%, and both the first time interval and the second time interval are set to 110 milliseconds. When the current bus bandwidth and CPU resource occupancy rate of the communication server (VGW) are greater than or equal to the second load threshold (such as 90%), the data processing ability of the communication server (VGW) is weak, and situations such as system lag and data transmission interruption are likely to occur. To ensure normal data transmission, the communication server (VGW) can send a first traffic control instruction to the target ECU and a second traffic control instruction to the communication client. When the target ECU receives the first traffic control instruction, it extends the first time interval for returning the reply message to be forwarded. For example, it extends from the original 100 milliseconds to 120 milliseconds. When the communication client (CDC) receives the second traffic control instruction, it extends the second time interval for sending the upgrade message to be forwarded. For example, it extends from the original 100 milliseconds to 110 milliseconds.
[0112] In the above embodiments, when the current resource load of the communication server is too heavy (exceeding the second load threshold), the communication server sends a first traffic control instruction and a second traffic control instruction to the target ECU and the communication client respectively, so as to adjust the time interval for receiving the upgrade message to be forwarded and the response message to be forwarded, which can ensure the normal data communication between the communication server and the target ECU and the communication client, and is beneficial to improving the efficiency and success rate of the upgrade and flashing. At the same time, the system stability of the communication client and the communication server can be ensured.
[0113] In some embodiments, if it is determined that the upgrade message to be forwarded is an invalid upgrade message, illegal data processing is performed on the upgrade message to be forwarded, including:
[0114] If it is determined that the upgrade message to be forwarded is an invalid upgrade message, the upgrade message to be forwarded is transferred to the secondary service buffer;
[0115] Read the upgrade message to be forwarded from the secondary service buffer. If it is determined that the upgrade message to be forwarded is an invalid upgrade message, illegal data processing is performed on the upgrade message to be forwarded.
[0116] The secondary service buffer and the primary service buffer are two independent data cache windows.
[0117] As an example, assume that the target ECU is ECU1-2 connected to the communication server (VGW), the upgrade message to be forwarded is upgrade file 1, and the identification field of upgrade file 1 includes the encrypted ECU file identification, the encrypted ECU source address, and the encrypted ECU destination address. The communication server (VGW) runs the second process to parse upgrade file 1 once. The parsing result is that the decrypted ECU file identification corresponding to the encrypted ECU file identification is consistent with the real ECU file identification of ECU1-2, the decrypted ECU source address corresponding to the encrypted ECU source address is inconsistent with the real ECU source address of ECU1-2, and the decrypted ECU destination address corresponding to the encrypted ECU destination address is inconsistent with the real ECU destination address of ECU1-2. Then it can be determined that upgrade file 1 is an invalid upgrade file, and this upgrade file 1 is transferred to the secondary service buffer.
[0118] Next, the communication server (VGW) runs the third process to read this upgrade file 1 from the secondary service buffer and perform a secondary parsing on this upgrade file 1 to obtain the secondary parsing result. Among them, the secondary parsing is similar to the above-mentioned primary parsing operation and will not be elaborated here. If it is determined according to this secondary parsing result that upgrade file 1 is still an invalid upgrade message, illegal data processing is performed on upgrade file 1. Specifically, upgrade file 1 can be temporarily stored in the preset "illegal data cache space", and at the same time, no response is made to upgrade file 1.
[0119] In some embodiments, when reading the upgrade message to be forwarded from the secondary service buffer, if it is determined that the upgrade message to be forwarded is an invalid upgrade message, after performing illegal data processing on the upgrade message to be forwarded, it further includes:
[0120] If it is determined that the upgrade message to be forwarded is a valid upgrade message, the upgrade message to be forwarded is put back into the primary service buffer;
[0121] Read the upgrade message to be forwarded from the primary service buffer, and when it is confirmed that the upgrade message to be forwarded is a valid upgrade message, forward the upgrade message to be forwarded to the target ECU.
[0122] For the sake of easy understanding, continue to use the above example. If it is determined according to the secondary parsing result that the upgrade file 1 is a valid upgrade message, the upgrade message 1 is put back into the primary service buffer. The communication server 102 runs the second process, reads the upgrade message 1 from the primary service buffer, and parses the upgrade message 1. If it is determined that the upgrade message 1 is a valid upgrade message, the upgrade message 1 is forwarded to the target ECU. If it is confirmed that the upgrade message 1 is an invalid upgrade message, it is directly discarded into the preset "illegal data cache space", and no response is made to the upgrade message 1.
[0123] In the above embodiment, by setting the secondary service buffer to cache the upgrade message to be forwarded that is initially parsed by the second process as an invalid upgrade message, and then the third process performs secondary parsing on the upgrade message to be forwarded to confirm again whether the upgrade message to be forwarded is a valid upgrade message. In this way, it is possible to reduce the situation where the second process misjudges the upgrade message to be forwarded as an invalid upgrade message due to missing or misreading the identification field of the upgrade message to be forwarded during the initial parsing.
[0124] In summary, in this application, data packet transmission is based on the DOIP communication protocol carried on TCP between the CDC and the VGW. ECU identification of data packets is performed based on the encrypted ECU identification in the data packets. Authenticity identification of data packets is performed based on the "yin-yang" ECU addresses in the data packets (the yin ECU address refers to the encrypted ECU source address and the encrypted ECU destination address; the yang ECU address refers to the interfering ECU source address and the interfering ECU destination address), and valid packets and invalid packets can be quickly distinguished. By performing illegal data processing on illegal data packets (invalid packets), the data processing pressure on the communication server can be alleviated, and the data transmission channel can be kept unobstructed, thereby improving the upgrade and flashing efficiency. By monitoring and processing illegal processes or threads on the communication client and the communication server, illegal processes or threads can be deleted in a timely manner to prevent attackers from using illegal processes or threads to damage the security and reliability of data transmission. By scheduling the network load of the communication client and the communication server, the transmission reliability of data packets can be ensured, which is conducive to improving the efficiency and success rate of upgrade and flashing.
[0125] All of the above optional technical solutions can be combined arbitrarily to form optional embodiments of this application, which will not be elaborated one by one here.
[0126] Figure 7 It is a schematic diagram of internal and external modules of a CDC and a VGW provided by an embodiment of this application.
[0127] Please refer to Figure 7 , the CDC of the embodiment of this application includes a client management module, a data sending module, a data receiving module, a transport layer, a network layer, a link layer, a PHY (physical) layer, a traffic monitoring module, a process monitoring module, an encryption and decryption module, and a black hole entry processing module. The VGW includes a server management module, a data sending module, a data receiving module, a transport layer, a network layer, a link layer, a PHY (physical) layer, a traffic monitoring module, a process monitoring module, an encryption and decryption module, and a black hole entry processing module.
[0128] In the scenario of OTA parallel flashing of ECU parts, the CDC can establish a TCP communication connection with the transport layer of the VGW through its transport layer. After successfully establishing a TCP communication connection with the VGW, the client management module of the CDC controls the CDC to enter the OTA mode. In the OTA mode, the data sending module of the CDC transmits the upgrade file to be forwarded downloaded from the OTA cloud platform to the PHY (physical) layer of the VGW through the transport layer, the network layer, the link layer, and the PHY (physical) layer in sequence.
[0129] The traffic monitoring module of the CDC is used to monitor the current resource load of the CDC (including bus bandwidth and CPU resource occupancy rate) in real time during the data packet transmission process.
[0130] The process monitoring module of the CDC is used to monitor all processes currently running on the CDC in real time, and immediately delete the illegal thread or process when it is detected that an attacker creates an illegal thread or process during the OTA upgrade of the main control.
[0131] The encryption and decryption module of the CDC is used to obtain the ECU product code, component code, and SOC identifier for encryption when sending the upgrade message to be forwarded, to obtain the encrypted ECU component identifier; encrypt the real ECU source address to obtain the encrypted ECU source address; encrypt the real ECU destination address to obtain the encrypted ECU destination address, and fill the encrypted ECU component identifier, encrypted ECU source address, and encrypted ECU destination address into the identifier field of the upgrade message to be forwarded.
[0132] The encryption and decryption module of the CDC is also used to decrypt the encrypted ECU component identifier, encrypted ECU source address, and encrypted ECU destination address when receiving the reply message to be forwarded.
[0133] The black hole entry processing module of the CDC is used to discard the ineffective reply message into the black hole area and not reply to any messages. It can also be used to manage and maintain the ECU product code, component code, and SOC identifier.
[0134] It can be understood that the functions of the traffic monitoring module, process monitoring module, encryption and decryption module, and black hole entry processing module of the VGW are similar to those of the traffic monitoring module, process monitoring module, encryption and decryption module, and black hole entry processing module of the CDC, and will not be elaborated here.
[0135] The following is an embodiment of the device of the present application, which can be used to execute the embodiment of the method of the present application. For the details not disclosed in the embodiment of the device of the present application, please refer to the embodiment of the method of the present application.
[0136] Figure 8 It is a schematic structural diagram of a communication service device provided by an embodiment of the present application. As Figure 8 shown, the communication service device includes:
[0137] The first process 801 is configured to obtain the upgrade message to be forwarded sent by the communication client;
[0138] The second process 802 is configured to forward the upgrade message to be forwarded to the target ECU and feedback the first reply message for the upgrade message to be forwarded to the communication client if it is determined that the upgrade message to be forwarded is a valid upgrade message;
[0139] The illegal processing module 803 is configured to perform illegal data processing on the upgrade message to be forwarded if it is determined that the upgrade message to be forwarded is an invalid upgrade message;
[0140] The sending module 804 is configured to, when the current resource load is greater than the first load threshold, send some or all of the invalid upgrade messages to be processed for illegal data to the communication client, so that the communication client processes the received invalid upgrade messages for illegal data.
[0141] In some embodiments, the above device further includes:
[0142] An obtaining module, configured to obtain a to-be-forwarded response message returned by the target ECU for the to-be-forwarded upgrade message;
[0143] A forwarding module, configured to, if it is determined that the to-be-forwarded response message is a valid response message, forward the to-be-forwarded response message to the communication client, and feedback a second response message for the to-be-forwarded response message to the target ECU;
[0144] A processing module, configured to, if it is determined that the to-be-forwarded response message is an invalid response message, perform illegal data processing on the to-be-forwarded response message.
[0145] In some embodiments, the above processing module includes:
[0146] A sending unit, configured to, when the current resource load is greater than the first load threshold, send some or all of the invalid response messages to be processed for illegal data to the communication client, so that the communication client processes the received invalid response messages for illegal data.
[0147] In some embodiments, the to-be-forwarded upgrade message includes a fake address and an encrypted address of the target ECU; the encrypted address is obtained by encrypting the real address of the target ECU.
[0148] The above first process includes:
[0149] A first recognition unit, configured to, when recognizing that the parsing result of the encrypted address matches the real address of the target ECU, determine that the to-be-forwarded upgrade message is a valid upgrade message; wherein, the parsing result of the encrypted address is obtained by the communication server parsing the encrypted address of the to-be-forwarded upgrade message;
[0150] The above second process includes:
[0151] A second recognition unit, configured to, when recognizing that the parsing result of the encrypted address in the to-be-forwarded upgrade message does not match the real address of the target ECU, determine that the to-be-forwarded upgrade message is an invalid upgrade message.
[0152] In some embodiments, the above device includes:
[0153] A data storage module, configured to store a to-be-forwarded upgrade message or a to-be-forwarded response message into a first-level service buffer when obtaining the to-be-forwarded upgrade message or the to-be-forwarded response message;
[0154] A data reading module, configured to release the storage space corresponding to the to-be-forwarded upgrade message or the to-be-forwarded response message in the first-level service buffer when reading the to-be-forwarded upgrade message or the to-be-forwarded response message from the first-level service buffer.
[0155] In some embodiments, the above-mentioned device further includes:
[0156] A traffic control module, configured to send a first traffic control instruction to a target ECU and send a second traffic control instruction to a communication client when the current resource load is greater than or equal to a second load threshold; wherein, the first traffic control instruction instructs the target ECU to extend a first time interval for returning a to-be-forwarded response message; the second traffic control instruction instructs the communication client to extend a second time interval for sending a to-be-forwarded upgrade message; the second load threshold is greater than the first load threshold.
[0157] In some embodiments, the above-mentioned illegal processing module 803 includes:
[0158] A transfer unit, configured to transfer the to-be-forwarded upgrade message to a second-level service buffer;
[0159] An illegal processing unit, configured to read the to-be-forwarded upgrade message from the second-level service buffer, and if it is determined that the to-be-forwarded upgrade message is an invalid upgrade message, perform illegal data processing on the to-be-forwarded upgrade message.
[0160] In some embodiments, the above-mentioned illegal processing module 803 further includes:
[0161] A playback unit, configured to put the to-be-forwarded upgrade message back into the first-level service buffer if it is determined that the to-be-forwarded upgrade message is a valid upgrade message;
[0162] A forwarding unit, configured to read the to-be-forwarded upgrade message from the first-level service buffer, and when it is confirmed that the to-be-forwarded upgrade message is a valid upgrade message, forward the to-be-forwarded upgrade message to the target ECU.
[0163] An embodiment of the present application further provides a communication system, including: a communication client, a communication server communicatively connected to the communication client, and an ECU communicatively connected to the communication server or the communication client;
[0164] A communication client, configured to determine a target ECU and send a to-be-forwarded upgrade message corresponding to the target ECU to the communication server;
[0165] A communication server, configured to obtain an upgrade message to be forwarded sent by a communication client; if it is determined that the upgrade message to be forwarded is a valid upgrade message, forward the upgrade message to be forwarded to a target ECU, and feedback a first response message for the upgrade message to be forwarded to the communication client; if it is determined that the upgrade message to be forwarded is an invalid upgrade message, perform illegal data processing on the upgrade message to be forwarded; when the current resource load is greater than a first load threshold, send some or all of the invalid upgrade messages to be subjected to illegal data processing to the communication client;
[0166] A communication client, configured to perform illegal data processing on the received invalid upgrade message.
[0167] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0168] Figure 9 is a schematic diagram of an electronic device 9 provided by an embodiment of the present application. As Figure 9 shown, the electronic device 9 in this embodiment includes: a processor 901, a memory 902, and a computer program 903 stored in the memory 902 and executable on the processor 901. When the processor 901 executes the computer program 903, the steps in the above various method embodiments are implemented. Alternatively, when the processor 901 executes the computer program 903, the functions of each module / unit in the above various device embodiments are implemented.
[0169] The electronic device 9 may be a desktop computer, a notebook, a palm computer, a cloud server, and other electronic devices. The electronic device 9 may include, but is not limited to, the processor 901 and the memory 902. Those skilled in the art can understand that Figure 9 is only an example of the electronic device 9, and does not constitute a limitation to the electronic device 9. It may include more or fewer components than those shown in the figure, or different components.
[0170] The processor 901 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0171] The memory 902 can be an internal storage unit of the electronic device 9, for example, the hard disk or memory of the electronic device 9. The memory 902 can also be an external storage device of the electronic device 9, for example, a plug-in hard disk equipped on the electronic device 9, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. The memory 902 can also include both the internal storage unit and the external storage device of the electronic device 9. The memory 902 is used to store computer programs and other programs and data required by the electronic device.
[0172] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above division of each functional unit and module is used as an example. In practical applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0173] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium (such as a computer-readable storage medium). Based on such an understanding, to implement all or part of the processes in the above embodiment methods of this application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be implemented. The computer program can include computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable storage medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a Read-Only Memory (ROM), a Random Access Memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0174] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A communication method based on OTA, characterized in that: Applicable to the communication service end, the communication method includes: Obtain the upgrade message to be forwarded sent by the communication client; If it is determined that the upgrade message to be forwarded is a valid upgrade message, forwarding the upgrade message to be forwarded to the target ECU, and feeding back a first response message for the upgrade message to be forwarded to the communication client; If it is determined that the upgrade message to be forwarded is an invalid upgrade message, performing illegal data processing on the upgrade message to be forwarded; When the current resource load is greater than the first load threshold, part or all of the invalid upgrade messages to be processed for illegal data are sent to the communication client, so that the communication client performs illegal data processing on the received invalid upgrade messages.
2. The method according to claim 1, characterized in that The method further comprises: Obtaining a response message to be forwarded returned by the target ECU in response to the upgrade message to be forwarded; If it is determined that the reply message to be forwarded is a valid reply message, the reply message to be forwarded is forwarded to the communication client, and a second reply message for the reply message to be forwarded is fed back to the target ECU; If it is determined that the response message to be forwarded is an invalid response message, illegal data processing is performed on the response message to be forwarded.
3. The method according to claim 2, characterized in that Performing illegal data processing on the response message to be forwarded includes: When the current resource load is greater than the first load threshold, part or all of the invalid response messages to be processed for illegal data are sent to the communication client, so that the communication client performs illegal data processing on the received invalid response messages.
4. The method according to claim 1, characterized in that: The upgrade message to be forwarded includes a false address and an encrypted address of the target ECU; the encrypted address is encrypted by encrypting the real address of the target ECU; Determining that the upgrade message to be forwarded is a valid upgrade message includes: When it is identified that the parsing result of the encrypted address matches the real address of the target ECU, the upgrade message to be forwarded is determined to be a valid upgrade message; wherein the parsing result of the encrypted address is obtained by the communication service end by parsing the encrypted address of the upgrade message to be forwarded; Determining that the upgrade message to be forwarded is an invalid upgrade message includes: When it is identified that the parsing result of the encrypted address in the upgrade message to be forwarded does not match the real address of the target ECU, it is determined that the upgrade message to be forwarded is an invalid upgrade message.
5. The method according to claim 2, characterized in that: The method further comprises: When the upgrade message to be forwarded or the reply message to be forwarded is obtained, the upgrade message to be forwarded or the reply message to be forwarded is stored in the first-level service buffer; When the upgrade message to be forwarded or the reply message to be forwarded is read from the primary service buffer, the storage space corresponding to the upgrade message to be forwarded or the reply message to be forwarded in the primary service buffer is released.
6. The method according to claim 2, characterized in that The method further comprises: When the current resource load is greater than or equal to a second load threshold, a first flow control instruction is sent to the target ECU, and a second flow control instruction is sent to the communication client; wherein the first flow control instruction instructs the target ECU to extend a first time interval for returning a response message to be forwarded; the second flow control instruction instructs the communication client to extend a second time interval for sending an upgrade message to be forwarded; and the second load threshold is greater than the first load threshold.
7. The method according to claim 5, characterized in that Performing illegal data processing on the upgrade message to be forwarded includes: Transferring the upgrade message to be forwarded to the secondary service buffer; The upgrade message to be forwarded is read from the secondary service buffer, and if it is determined that the upgrade message to be forwarded is an invalid upgrade message, illegal data processing is performed on the upgrade message to be forwarded.
8. The method according to claim 7, characterized in that The method further comprises: reading the upgrade message to be forwarded from the secondary service buffer, and if it is determined that the upgrade message to be forwarded is an invalid upgrade message, then performing illegal data processing on the upgrade message to be forwarded, further comprising: If it is determined that the upgrade message to be forwarded is a valid upgrade message, the upgrade message to be forwarded is placed back into the first-level service buffer; The upgrade message to be forwarded is read from the primary service buffer, and when it is confirmed that the upgrade message to be forwarded is a valid upgrade message, the upgrade message to be forwarded is forwarded to a target ECU.
9. A communication service device, characterized in that: include: The first process is configured to obtain an upgrade message to be forwarded sent by a communication client; The second process is configured to forward the upgrade message to the target ECU if it is determined that the upgrade message to be forwarded is a valid upgrade message, and feed back a first response message for the upgrade message to be forwarded to the communication client; an illegal processing module, configured to perform illegal data processing on the upgrade message to be forwarded if it is determined that the upgrade message to be forwarded is an invalid upgrade message; The sending module is configured to send part or all of the invalid upgrade messages to be processed illegally to the communication client when the current resource load is greater than the first load threshold, so that the communication client performs illegal data processing on the received invalid upgrade messages.
10. A communication system, characterized in that: include: A communication client, a communication server connected to the communication client, and an ECU connected to the communication server or the communication client; The communication client is configured to determine a target ECU and send a to-be-forwarded upgrade message corresponding to the target ECU to the communication server; The communication server is configured to obtain the upgrade message to be forwarded sent by the communication client; If it is determined that the upgrade message to be forwarded is a valid upgrade message, the upgrade message to be forwarded is forwarded to the target ECU, and a first response message for the upgrade message to be forwarded is fed back to the communication client; if it is determined that the upgrade message to be forwarded is an invalid upgrade message, illegal data processing is performed on the upgrade message to be forwarded; When the current resource load is greater than a first load threshold, sending part or all of the invalid upgrade messages to be processed with illegal data to the communication client; The communication client is configured to perform illegal data processing on the received invalid upgrade message.