Internet of vehicles data security protection method, apparatus and device, and readable storage medium

Through cloud analysis and identification of threat risk data of vehicle network system, and formulating and sending data full life cycle rule tables, it solves the problem of insufficient dynamic security requirements for the Internet of Vehicles system during the entire life cycle of data, and improves data security protection efficiency and system security.

CN120075811APending Publication Date: 2025-05-30智行盒子(河南)科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411906309.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When processing data security, existing Internet of Vehicles systems fail to fully consider the dynamic security needs of data throughout the entire life cycle, resulting in low data protection efficiency and manual configuration of rules is required, which wastes time.

Method used

Through cloud analysis, identify potential threat and risk data of the vehicle network system, obtain risk level and classification basis, formulate a rule table for the entire life cycle of data, and send the rule table to the vehicle terminal to achieve automated data security protection.

Benefits of technology

The efficiency of data security protection in the Internet of Vehicles has been improved. By dynamically adjusting data security management, the flexibility and comprehensiveness of data protection have been enhanced, manual operations have been reduced, and the security of the Internet of Vehicles has been improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075811A_ABST
    Figure CN120075811A_ABST
Patent Text Reader

Abstract

The invention provides an Internet of Vehicles data security protection method, device and equipment and a readable storage medium, the method is applied to an Internet of Vehicles system comprising a vehicle end and a cloud end, the method is executed by the cloud end, and the method comprises the following steps: analyzing and identifying potential threat risk data of the Internet of Vehicles system to obtain a risk level and a classification and grading basis, the threat risk data comprises at least one of data leakage, data tampering and data loss, and the classification and grading basis comprises data leakage, data tampering and data loss; the data are at least one of periodically generated data, user behavior data and emergency data; formulating a data full life cycle rule table according to the risk level and the classification and grading basis; and the data full-life-cycle rule table is sent to the vehicle end, and the data full-life-cycle rule table is used for safety protection of data in the vehicle end. Through the method, the effect of improving the efficiency of data security protection of the Internet of Vehicles can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data protection. Specifically, it relates to a method, device, equipment, and readable storage medium for vehicle networking data security protection. Background Art

[0002] Vehicle networking technology has been widely applied in modern vehicles, and various types of data (such as vehicle operation data, user behavior data, and emergency data) are transmitted inside the vehicle through communication methods such as CAN bus. Since these data involve vehicle safety and user privacy, ensuring the security and integrity of the data has become particularly important. Existing technical solutions mainly focus on the following aspects: Data encryption: Using encryption algorithms to protect data security during data storage and transmission. Access control: Restricting access to data through access control lists and permission management. Data isolation: Using hardware security modules (HSM) and trusted execution environments (TEE) for isolated storage of data.

[0003] However, when existing vehicle networking systems handle data security, they often fail to fully consider the dynamic security requirements of data throughout its entire life cycle. Although these methods can provide certain data protection, they often require manual configuration of rules and need to be reconfigured in actual usage scenarios, wasting time.

[0004] Therefore, how to improve the efficiency of vehicle networking data security protection is a technical problem that needs to be solved. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a method for vehicle networking data security protection, and through the technical solutions of the embodiments of this application, the effect of improving the efficiency of vehicle networking data security protection can be achieved.

[0006] In a first aspect, the embodiments of this application provide a method for vehicle networking data security protection, which is applied to a vehicle networking system including a vehicle end and a cloud end. This method is executed by the cloud end and includes: analyzing and identifying potential threat risk data of the vehicle networking system to obtain a risk level and a basis for classification and grading, where the threat risk data includes at least one of data leakage, data tampering, and data loss, and the basis for classification and grading includes at least one of periodically generated data, user behavior data, and emergency data; formulating a data full life cycle rule table according to the risk level and the basis for classification and grading; sending the data full life cycle rule table to the vehicle end, where the data full life cycle rule table is used for the security protection of data inside the vehicle end.

[0007] In the above embodiments of the present application, the vehicle networking data security protection method based on data classification and grading and the application of data full life cycle rules enables data security management to be dynamically adjusted according to data types and actual scenarios. Through automated rule querying and execution, the flexibility and comprehensiveness of data protection can be effectively improved, manual operations can be reduced, and the security of the vehicle networking system can be enhanced.

[0008] In some embodiments, potential threat risk data of the vehicle networking system is analyzed and identified to obtain a risk level and classification and grading basis, including: obtaining the risk level corresponding to the threat risk data from a preset risk assessment rule; obtaining the classification and grading basis corresponding to the generated threat risk data.

[0009] In the above embodiments of the present application, the generated threat risk data can be accurately matched with the classification and grading basis according to the preset risk assessment rule.

[0010] In some embodiments, according to the risk level and classification and grading basis, a data full life cycle rule table is formulated, including: establishing a classification and grading table corresponding to the classification and grading basis according to a preset classification and grading template; formulating security protection configurations corresponding to the risk level and the classification and grading table, where the security protection configurations include: measure configurations and policy configurations; formulating a data full life cycle rule table according to the security protection configurations, where the data full life cycle rule table includes: at least one rule among data collection, transmission, use, storage, upload, and destruction.

[0011] In the above embodiments of the present application, a data full life cycle rule table can be automatically obtained through the risk level and classification and grading basis for automatically protecting vehicle - end data.

[0012] In some embodiments, before analyzing and identifying potential threat risk data of the vehicle networking system, it further includes: when an in - vehicle electrical component performs in - vehicle data transmission, receiving an analysis instruction for potential threat risk data of the vehicle networking system sent by the vehicle end.

[0013] In the above embodiments of the present application, when receiving the analysis instruction for potential threat risk data of the vehicle networking system sent by the vehicle end, security protection rules can be automatically generated according to data classification and grading and data full life cycle rules.

[0014] Second aspect, an embodiment of the present application provides a method for vehicle networking data security protection, which is applied to a vehicle networking system including a vehicle terminal and a cloud terminal. The method is executed by the vehicle terminal and includes: when an in-vehicle electrical component performs in-vehicle data transmission, sending a data analysis instruction on potential threat risks of the vehicle networking system to the cloud terminal, where the analysis instruction is used for the cloud terminal to analyze and identify potential threat risk data of the vehicle networking system and formulate a data full life cycle rule table; receiving the data full life cycle rule table sent by the cloud terminal; and performing security protection on the in-vehicle data according to the data full life cycle rule table.

[0015] In the above embodiment of the present application, the vehicle networking data security protection method based on data classification and grading and data full life cycle rule application enables data security management to be dynamically adjusted according to data types and actual scenarios. Through automated rule querying and execution, the flexibility and comprehensiveness of data protection can be effectively improved, manual operations can be reduced, and the security of the vehicle networking system can be enhanced.

[0016] In some embodiments, performing security protection on the in-vehicle data according to the data full life cycle rule table includes: storing the data full life cycle rule table locally; and performing data processing on the in-vehicle data according to the data full life cycle rule table stored locally, where the data processing includes at least one of encryption processing and isolated storage processing.

[0017] In the above embodiment of the present application, data security protection can be achieved by performing data processing on the in-vehicle data according to the data full life cycle rule table.

[0018] Third aspect, an embodiment of the present application provides a device for vehicle networking data security protection, including:

[0019] An identification module, configured to analyze and identify potential threat risk data of the vehicle networking system to obtain a risk level and a classification and grading basis, where the threat risk data includes at least one of data leakage, data tampering, and data loss, and the classification and grading basis includes at least one of periodically generated data, user behavior data, and emergency data;

[0020] A formulation module, configured to formulate a data full life cycle rule table according to the risk level and the classification and grading basis;

[0021] A sending module, configured to send the data full life cycle rule table to the vehicle terminal, where the data full life cycle rule table is used for security protection of data in the vehicle terminal.

[0022] Optionally, the identification module is specifically configured to:

[0023] Obtain the risk level corresponding to the threat risk data from the preset risk assessment rules;

[0024] Obtain the classification and grading basis corresponding to the generated threat risk data.

[0025] Optionally, the formulating module is specifically configured to:

[0026] Establish a classification and grading table corresponding to the classification and grading basis according to the preset classification and grading template;

[0027] Formulate a security protection configuration corresponding to the risk level and the classification and grading table, wherein the security protection configuration includes: measure configuration and policy configuration;

[0028] According to the security protection configuration, formulate a data full life cycle rule table, wherein the data full life cycle rule table includes: at least one rule among data collection, transmission, use, storage, upload, and destruction.

[0029] Optionally, the device further includes:

[0030] The receiving module is used to receive a threat risk data analysis instruction of the vehicle networking system sent by the vehicle terminal when the in-vehicle electrical component performs in-vehicle data transmission before the identification module analyzes and identifies the potential threat risk data of the vehicle networking system.

[0031] Fourthly, an embodiment of the present application provides a device for vehicle networking data security protection, including:

[0032] A sending module, configured to send the threat risk data analysis instruction of the vehicle networking system to the cloud when the in-vehicle electrical component is started, wherein the analysis instruction is used for the cloud to analyze and identify the potential threat risk data of the vehicle networking system and formulate a data full life cycle rule table;

[0033] A receiving module, configured to receive the data full life cycle rule table sent by the cloud;

[0034] A protection module, configured to perform security protection on the in-vehicle data according to the data full life cycle rule table.

[0035] Optionally, the protection module is specifically configured to:

[0036] Store the data full life cycle rule table locally;

[0037] Perform data processing on the in-vehicle data according to the data full life cycle rule table stored locally, wherein the data processing includes: at least one of encryption processing and isolated storage processing.

[0038] Fifth aspect, an embodiment of the present application provides an electronic device, including a processor and a memory. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the steps in the method provided in the first aspect as described above are run.

[0039] Sixth aspect, an embodiment of the present application provides a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the method provided in the first aspect as described above are run.

[0040] Other features and advantages of the present application will be described in the subsequent specification, and part of them will become obvious from the specification, or can be understood by implementing the embodiments of the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation of the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0042] Figure 1 It is a schematic diagram of the result of a vehicle networking system provided by an embodiment of the present application;

[0043] Figure 2 It is a flowchart of a method for vehicle networking data security protection provided by an embodiment of the present application;

[0044] Figure 3 It is a flowchart of another method for vehicle networking data security protection provided by an embodiment of the present application;

[0045] Figure 4 It is a schematic block diagram of a device for vehicle networking data security protection provided by an embodiment of the present application;

[0046] Figure 5 It is a schematic block diagram of another device for vehicle networking data security protection provided by an embodiment of the present application;

[0047] Figure 6 It is a schematic structural diagram of a device for vehicle networking data security protection provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.

[0049] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0050] First, some terms involved in the embodiments of the present application will be described to facilitate the understanding of those skilled in the art.

[0051] Threat Analysis and Risk Assessment (TARA) analysis, the full name of which is Threat Analysis and Risk Assessment, is a key activity defined in the ISO / SAE 21434 standard and is used to identify and evaluate potential factors that may pose threats and risks to automotive cybersecurity systems or individuals.

[0052] The data full-life cycle rule table refers to a tabular summary of a series of management activities around the generation, collection, processing, use, and destruction of data. This table details the management activities that should be carried out at each life cycle stage of the data, including data quality, data modeling, data analysis, etc. The TBox (Telematics Box) vehicle-mounted electrical component is an important part of the vehicle networking system and is mainly responsible for data collection and remote communication. It realizes functions such as vehicle remote monitoring, safety monitoring and alarm, and real-time collection of vehicle information through 4G / 5G remote wireless communication, GPS satellite positioning, acceleration sensing, and CAN communication functions.

[0053] IVI (In-Vehicle Infotainment) is an in-vehicle infotainment system. This system uses a dedicated in-vehicle central processor and, based on the vehicle body bus system and Internet services, forms a comprehensive information processing platform. Through this system, the vehicle can achieve a high degree of electronization, networking, and intelligence, greatly enhancing the driving and riding experience.

[0054] The ECU is an electronic control unit, also known as the vehicle computer, in-vehicle computer, etc. The ECU consists of a microprocessor, a memory, an input / output interface, an analog-to-digital converter, and large-scale integrated circuits such as shaping and driving circuits. It is a comprehensive control device used for engine control.

[0055] An external Flash is a storage device mainly used to store firmware programs, configuration information, data, etc. in an embedded system. It is usually divided into two types: Nor Flash and Nand Flash.

[0056] HSM is the abbreviation of Hardware Security Module. It is a computer hardware device used to protect and manage the keys used in a strong authentication system and provide related cryptographic operations.

[0057] TEE is a secure storage technology designed to save sensitive data for users, such as keys. It utilizes the TEE (Trusted Execution Environment) to provide security and integrity protection. TEE storage ensures that all computations of sensitive data are performed in an isolated memory area allocated for sensitive data in the hardware, and the information in this isolated memory cannot be accessed by other parts of the hardware except through authorized interfaces.

[0058] A CAN message refers to a frame for transmitting data from a sending unit to a receiving unit.

[0059] Message ID is a message identifier. It is a short string used to uniquely identify a message. MessageID is usually set to be unique in business and is applicable to scenarios that require ensuring the uniqueness of messages, such as sales orders, work orders, etc.

[0060] This application is applied to the scenario of vehicle networking data protection. The specific scenario is a vehicle networking data security protection method based on vehicle networking data classification and grading and dynamic rule application, enabling data security management to be dynamically adjusted according to data types and actual scenarios.

[0061] Vehicle networking technology has been widely applied in modern vehicles. All kinds of data (such as vehicle operation data, user behavior data, emergency data) are transmitted inside the vehicle through communication methods such as CAN bus. Since these data involve vehicle safety and user privacy, ensuring the security and integrity of the data becomes particularly important. Existing technical solutions mainly focus on the following aspects: Data encryption: Use encryption algorithms to protect data security during data storage and transmission. Access control: Restrict access to data through access control lists and permission management. Data isolation: Use hardware security modules (HSM) and trusted execution environments (TEE) for isolated storage of data. However, when dealing with data security, existing vehicle networking systems often fail to fully consider the dynamic security requirements of data throughout its entire life cycle. Although these methods can provide certain data protection, they often require manual configuration of rules and need to be reconfigured in actual usage scenarios, wasting time.

[0062] Therefore, in this application, the cloud analyzes and identifies potential threat risk data of the vehicle networking system to obtain the risk level and classification and grading basis. Among them, the threat risk data includes at least one of data leakage, data tampering, and data loss, and the classification and grading basis includes at least one of periodically generated data, user behavior data, and emergency data; according to the risk level and classification and grading basis, a data full life cycle rule table is formulated; the data full life cycle rule table is sent to the vehicle side, where the data full life cycle rule table is used for the security protection of data inside the vehicle side. The vehicle networking data security protection method based on data classification and grading and the application of data full life cycle rules enables data security management to be dynamically adjusted according to data types and actual scenarios. Through automated rule query and execution, it can effectively improve the flexibility and comprehensiveness of data protection, reduce manual operations, and improve the security of the vehicle networking system.

[0063] In the embodiments of this application, the execution subject can be the vehicle networking data security protection device in the vehicle networking data security protection system. In actual applications, the vehicle networking data security protection device can be electronic devices such as terminal devices and servers, which are not limited here.

[0064] The following combines Figure 1 to describe the vehicle networking system of the embodiments of this application in detail.

[0065] Please refer to Figure 1 , Figure 1 , which is a schematic diagram of the result of a vehicle networking system provided by the embodiments of this application, including:

[0066] Cloud 110 and vehicle side 120.

[0067] When in-vehicle electrical components perform in-vehicle data transmission, the vehicle end 110 sends an instruction for analyzing potential threat risk data of the vehicle networking system to the cloud end 120. The cloud end 120 analyzes and identifies the potential threat risk data of the vehicle networking system according to the instruction for analyzing potential threat risk data of the vehicle networking system, obtains the risk level and the classification and grading basis, formulates a data full life cycle rule table according to the risk level and the classification and grading basis, and sends the data full life cycle rule table to the vehicle end 110. The vehicle end 110 performs security protection on the in-vehicle data according to the data full life cycle rule table.

[0068] Optionally, the vehicle networking system further includes a vehicle networking data asset management system, a data security SDK / security chip, and a data security operation and maintenance system.

[0069] Among them, the vehicle networking data asset management system is used to create a classification and grading module after the user logs in, configure data classification and grading, and create a vehicle end policy configuration. The data security SDK / security chip is used to send the above configuration to the vehicle end. The vehicle end can save the classified and graded data and perform operations such as data collection, storage, processing, uploading, and deletion according to the data ID and the data classification and grading identifier, etc., to achieve data security maintenance. The data security operation and maintenance system realizes data security auditing through abnormal event monitoring, recording, abnormal emergency handling, statistical analysis, traceability, work order handling, log auditing, and abnormal handling tracking.

[0070] Next, in combination with Figure 2 The method for vehicle networking data security protection in the embodiments of the present application will be described in detail.

[0071] Please refer to Figure 2 , Figure 2 which is a flowchart of a method for vehicle networking data security protection provided by an embodiment of the present application, applied to a vehicle networking system including a vehicle end and a cloud end. This method is executed by the cloud end. As Figure 2 shown, the method for vehicle networking data security protection includes:

[0072] Step 210: Analyze and identify the potential threat risk data of the vehicle networking system to obtain the risk level and the classification and grading basis.

[0073] Among them, the threat risk data includes at least one of data leakage, data tampering, and data loss. The classification and grading basis (rule MAP) includes at least one of periodically generated data, user behavior data, and emergency data. Analyzing and identifying the potential threat risk data of the vehicle networking system to obtain the risk level and the classification and grading basis can be obtained by means of correlation analysis or manual entry in the cloud end.

[0074] In some embodiments of the present application, before analyzing and identifying the potential threat risk data of the vehicle networking system, Figure 2The method shown also includes: when in-vehicle electrical components perform in-vehicle data transmission, receiving a data analysis instruction on potential threat risks of the vehicle network system sent by the vehicle terminal.

[0075] In the above process of this application, when receiving a data analysis instruction on potential threat risks of the vehicle network system sent by the vehicle terminal, security protection rules can be automatically generated according to data classification and grading and data full life cycle rules.

[0076] Among them, the data analysis instruction on threat risks can be an instruction sent by the vehicle terminal to the cloud during processes such as data collection, transmission, use, storage, upload, and destruction.

[0077] In some embodiments of this application, analyzing and identifying potential threat risk data of the vehicle network system to obtain a risk level and classification and grading basis includes: obtaining the risk level corresponding to the threat risk data from a preset risk assessment rule; obtaining the classification and grading basis corresponding to the generated threat risk data.

[0078] In the above process of this application, the generated threat risk data can be accurately matched with the classification and grading basis according to the preset risk assessment rule.

[0079] Among them, the preset risk assessment rule includes threat risk data in historical data and the corresponding risk levels, as well as historical generated threat risk data and the corresponding classification and grading basis.

[0080] Specifically, potential threats and risks faced by the system, including data leakage, tampering, and loss, etc., can be identified through TARA analysis and cloud association analysis to obtain the risk level when relevant data is attacked, and then the classification and grading basis (periodically generated data, user behavior data, emergency data) can be obtained, and a data classification and grading table can be established.

[0081] Step 220: Formulate a data full life cycle rule table according to the risk level and classification and grading basis.

[0082] In some embodiments of this application, formulating a data full life cycle rule table according to the risk level and classification and grading basis includes: establishing a classification and grading table corresponding to the classification and grading basis according to a preset classification and grading template; formulating security protection configurations corresponding to the risk level and classification and grading table, where the security protection configurations include: measure configurations and policy configurations; formulating a data full life cycle rule table according to the security protection configurations, where the data full life cycle rule table includes: at least one rule among data collection, transmission, use, storage, upload, and destruction.

[0083] In the above process of this application, a data full life cycle rule table can be automatically obtained through the risk level and classification and grading basis for automatically protecting vehicle terminal data.

[0084] Specifically, corresponding risk measures and strategies can be formulated for relevant data according to the data risk levels and classification and grading tables obtained from TARA analysis and correlation analysis, covering data collection, transmission, use, storage, upload, and destruction, etc. In this way, a data full-life cycle rule table can be obtained.

[0085] Step 230: Send the data full-life cycle rule table to the vehicle side.

[0086] Among them, the data full-life cycle rule table is used for the security protection of data inside the vehicle side. When analyzing and identifying potential threat risk data of the vehicle networking system for the Pdu (in-vehicle data storage device) where important data (signal) is located inside the vehicle side ECU (engine comprehensive control device), obtaining the risk level and classification and grading basis, and formulating the data full-life cycle rule table

[0087] Alternatively, the method executed by the cloud side shown above Figure 2 can be executed by integrating a local rule engine through Tbox. By configuring risk measures and strategies, covering data collection, transmission, use, storage, upload, and destruction, etc., a data full-life cycle rule table is formulated.

[0088] In the process shown above Figure 2 In the method for protecting vehicle networking data security of the present application, the cloud side of the present application analyzes and identifies potential threat risk data of the vehicle networking system, obtains the risk level and classification and grading basis. Among them, the threat risk data includes at least one of data leakage, data tampering, and data loss, and the classification and grading basis includes at least one of periodically generated data, user behavior data, and emergency data; according to the risk level and classification and grading basis, a data full-life cycle rule table is formulated; the data full-life cycle rule table is sent to the vehicle side, where the data full-life cycle rule table is used for the security protection of data inside the vehicle side. The vehicle networking data security protection method based on data classification and grading and the application of the data full-life cycle rule enables data security management to be dynamically adjusted according to the data type and actual scenario. Through automated rule query and execution, the flexibility and comprehensiveness of data protection can be effectively improved, manual operations can be reduced, and the security of the vehicle networking system can be improved.

[0089] Next, in combination with Figure 3 the method for protecting vehicle networking data security in the embodiments of the present application will be described in detail again.

[0090] Please refer to Figure 3 , Figure 3 which is a flowchart of another method for protecting vehicle networking data security provided by the embodiments of the present application, applied to a vehicle networking system including a vehicle side and a cloud side. This method is executed by the vehicle side. As Figure 3 shown, the method for protecting vehicle networking data security includes:

[0091] Step 310: When a vehicle-mounted electrical component is started, send a data analysis instruction for potential threat risks of the vehicle networking system to the cloud.

[0092] Among them, the analysis instruction is used for the cloud to analyze and identify potential threat risk data of the vehicle networking system, formulate a data full life cycle rule table; receive the data full life cycle rule table sent by the cloud.

[0093] Step 320: Receive the data full life cycle rule table sent by the cloud.

[0094] Specifically, an ECU with networking capabilities such as a vehicle-end Tbox or IVI requests the data full life cycle rule table from the cloud according to requirements and stores the rule table locally.

[0095] Step 330: Perform security protection on vehicle-mounted data according to the data full life cycle rule table.

[0096] Specifically, in the data usage stage, the Tbox processes the data (such as encryption, isolated storage) according to the data full life cycle rule table to ensure the security of the data.

[0097] In some embodiments of the present application, performing security protection on vehicle-mounted data according to the data full life cycle rule table includes: storing the data full life cycle rule table locally; performing data processing on vehicle-mounted data according to the locally stored data full life cycle rule table, where the data processing includes at least one of encryption processing and isolated storage processing.

[0098] In the above process of the present application, by performing data processing on vehicle-mounted data according to the data full life cycle rule table, data security protection can be achieved.

[0099] Among them, after encryption, it can be stored in a rule module such as an HSM, TEE, or external FLASH for use when the vehicle-end performs data security protection next time.

[0100] For example, when the Tbox receives a CAN message with an ID of 0x123, which contains a speed signal, the Tbox will query the rule module according to the Message ID, start position, and signal length of the signal, and learn that the signal needs to be encrypted and stored in the HSM. Then perform the vehicle-end security protection operation.

[0101] Alternatively, implement the rule module as a network service to provide rule query and application functions.

[0102] Optionally, during the protection process, the vehicle end calls the data full life cycle rule table in the Tbox application software through the interface, and realizes the security protection of vehicle end data through operations such as data identification, assignment, collection, storage, encryption, transmission, selection, and deletion.

[0103] In the above Figure 3 During the process shown, when the vehicle-mounted electrical components of the vehicle end of this application perform vehicle-mounted data transmission, it sends a data analysis instruction on potential threat risks of the vehicle network system to the cloud. Among them, the analysis instruction is used for the cloud to analyze and identify potential threat risk data of the vehicle network system and formulate a data full life cycle rule table; receive the data full life cycle rule table sent by the cloud; and perform security protection on the vehicle-mounted data according to the data full life cycle rule table. The vehicle network data security protection method based on data classification and grading and the application of the data full life cycle rule enables data security management to be dynamically adjusted according to the data type and actual scenario. Through automated rule query and execution, it can effectively improve the flexibility and comprehensiveness of data protection, reduce manual operations, and improve the security of the vehicle network system.

[0104] The foregoing has described Figures 2 - 3 the method for vehicle network data security protection. Next, in combination with Figures 4 - 6 describe the device for vehicle network data security protection.

[0105] Please refer to Figure 4 , which is a schematic block diagram of a device 400 for vehicle network data security protection provided in an embodiment of this application. The device 400 can be a module, program segment, or code on an electronic device. The device 400 corresponds to the above Figure 2 method embodiment and can execute Figure 2 each step involved in the method embodiment. The specific functions of the device 400 can be seen in the following description. To avoid repetition, the detailed description is appropriately omitted here.

[0106] Optionally, the device 400 includes:

[0107] An identification module 410, configured to analyze and identify potential threat risk data of the vehicle network system, and obtain a risk level and a classification and grading basis. Among them, the threat risk data includes at least one of data leakage, data tampering, and data loss, and the classification and grading basis includes at least one of periodically generated data, user behavior data, and emergency data;

[0108] A formulation module 420, configured to formulate a data full life cycle rule table according to the risk level and the classification and grading basis;

[0109] A sending module 430, configured to send the data full - life - cycle rule table to the vehicle terminal, where the data full - life - cycle rule table is used for the security protection of data in the vehicle terminal.

[0110] Optionally, the recognition module is specifically configured to:

[0111] Obtain the risk level corresponding to the threat risk data from a preset risk assessment rule; obtain the classification and grading basis corresponding to the generated threat risk data.

[0112] Optionally, the formulation module is specifically configured to:

[0113] Establish a classification and grading table corresponding to the classification and grading basis according to a preset classification and grading template; formulate security protection configurations corresponding to the risk level and the classification and grading table, where the security protection configurations include: measure configurations and policy configurations; formulate a data full - life - cycle rule table according to the security protection configurations, where the data full - life - cycle rule table includes at least one rule among data collection, transmission, use, storage, upload, and destruction.

[0114] Optionally, the device further includes:

[0115] A receiving module is configured to, before the recognition module analyzes and recognizes potential threat risk data of the vehicle network system, when in - vehicle electrical components perform in - vehicle data transmission, receive a potential threat risk data analysis instruction of the vehicle network system sent by the vehicle terminal.

[0116] Please refer to Figure 5 , which is a schematic block diagram of another vehicle - to - everything (V2X) data security protection device 500 provided in an embodiment of the present application. The device 500 can be a module, a program segment, or code on an electronic device. The device 500 corresponds to the above - mentioned Figure 3 method embodiment, and can execute Figure 3 each step involved in the method embodiment. The specific functions of the device 500 can be seen in the following description. To avoid repetition, the detailed description is appropriately omitted here.

[0117] Optionally, the device 500 includes:

[0118] A sending module 510, configured to send the potential threat risk data analysis instruction of the vehicle network system to the cloud when in - vehicle electrical components are started, where the analysis instruction is used for the cloud to analyze and recognize potential threat risk data of the vehicle network system and formulate a data full - life - cycle rule table;

[0119] A receiving module 520, configured to receive the data full - life - cycle rule table sent by the cloud;

[0120] A protection module 530 is configured to perform security protection on the vehicle-mounted data according to the data full life cycle rule table.

[0121] Optionally, the protection module is specifically configured to:

[0122] Store the data full life cycle rule table locally; perform data processing on the vehicle-mounted data according to the locally stored data full life cycle rule table, where the data processing includes at least one of encryption processing and isolated storage processing.

[0123] Please refer to Figure 6 FIG. 0 is a schematic structural diagram of a device for vehicle networking data security protection provided in an embodiment of the present application. The device may include a memory 610 and a processor 620. Optionally, the device may further include: a communication interface 630 and a communication bus 640. The device corresponds to the above Figure 1 or Figure 2 The method embodiment corresponds and is capable of executing Figure 1 or Figure 2 Each step involved in the method embodiment. The specific functions of the device may be referred to the description below.

[0124] Specifically, the memory 610 is configured to store computer-readable instructions.

[0125] The processor 620 is configured to process the readable instructions stored in the memory and is capable of executing Figure 1 or Figure 2 Each step in the method.

[0126] The communication interface 630 is configured to communicate signaling or data with other node devices. For example: for communicating with a server or a terminal, or for communicating with other device nodes. The embodiments of the present application are not limited thereto.

[0127] The communication bus 640 is configured to implement direct connection communication between the above components.

[0128] Among them, the communication interface 630 of the device in the embodiment of the present application is configured to communicate signaling or data with other node devices. The memory 610 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. Optionally, the memory 610 may further be at least one storage device located far from the foregoing processor. The memory 610 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 620, the electronic device executes the above Figure 1 or Figure 2The method process shown. The processor 620 can be used on the device 400 or the device 500 and is used to execute the functions in this application. Exemplarily, the above-mentioned processor 620 can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The embodiments of this application are not limited thereto.

[0129] The embodiments of this application also provide a readable storage medium. When the computer program is executed by a processor, it executes the method process executed by the electronic device in the method embodiment as Figure 1 or Figure 2 shown.

[0130] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the above-described device can refer to the corresponding process in the foregoing method and will not be elaborated herein.

[0131] In summary, the embodiments of this application provide a method, device, equipment, and readable storage medium for vehicle networking data security protection. The method includes analyzing and identifying potential threat risk data of the vehicle networking system to obtain a risk level and a basis for classification and grading. Among them, the threat risk data includes at least one of data leakage, data tampering, and data loss, and the basis for classification and grading includes at least one of periodically generated data, user behavior data, and emergency data; formulating a data full life cycle rule table according to the risk level and the basis for classification and grading; sending the data full life cycle rule table to the vehicle end, where the data full life cycle rule table is used for the security protection of the data in the vehicle end. Through this method, the effect of improving the efficiency of vehicle networking data security protection can be achieved.

[0132] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0133] In addition, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0134] If the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.

[0135] The above are only examples of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0136] As described above, these are only the specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all of them should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described.

[0137] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A method for protecting data security in an Internet of Vehicles, characterized in that: Applied to a vehicle networking system including a vehicle terminal and a cloud, the method is executed by the cloud terminal and includes: Analyze and identify potential threat risk data of the vehicle network system to obtain risk levels and classification basis, wherein the threat risk data includes: at least one of data leakage, data tampering and data loss, and the classification basis includes: at least one of periodically generated data, user behavior data and emergency data; Formulate a data life cycle rule table based on the risk level and classification basis; The data life cycle rule table is sent to the vehicle end, wherein the data life cycle rule table is used for security protection of data in the vehicle end.

2. The method according to claim 1, characterized in that: The analysis identifies potential threat risk data of the vehicle network system and obtains risk levels and classification basis, including: Obtaining the risk level corresponding to the threat risk data from a preset risk assessment rule; Obtain the classification and grading basis corresponding to the threat risk data.

3. The method according to claim 1 or 2, characterized in that: According to the risk level and the classification basis, a data life cycle rule table is formulated, including: According to the preset classification and grading template, a classification and grading table corresponding to the classification and grading basis is established; Formulate a security protection configuration corresponding to the risk level and the classification and grading table, wherein the security protection configuration includes: measure configuration and policy configuration; According to the security protection configuration, the data life cycle rule table is formulated, wherein the data life cycle rule table includes: at least one rule of data collection, transmission, use, storage, upload and destruction.

4. The method according to claim 1 or 2, characterized in that: Before analyzing and identifying the potential threat risk data of the vehicle network system and obtaining the risk level and classification basis, the method further includes: When the vehicle-mounted electrical components are transmitting vehicle-mounted data, a data analysis instruction for potential threat risks of the vehicle network system sent by the vehicle end is received.

5. A method for protecting data security in an Internet of Vehicles, characterized in that: Applied to a vehicle networking system including a vehicle terminal and a cloud, the method is executed by the vehicle terminal and includes: When the vehicle-mounted electrical component is started, a potential threat risk data analysis instruction of the vehicle network system is sent to the cloud, wherein the analysis instruction is used by the cloud to analyze and identify the potential threat risk data of the vehicle network system and formulate a data full life cycle rule table; Receiving the data life cycle rule table sent by the cloud; According to the data life cycle rule table, the vehicle-mounted data is securely protected.

6. The method according to claim 5, characterized in that The step of performing security protection on the vehicle-mounted data according to the data life cycle rule table includes: Storing the data life cycle rule table locally; The vehicle-mounted data is processed according to the data life cycle rule table stored locally, wherein the data processing includes at least one of encryption processing and isolated storage processing.

7. A device for protecting data security in an Internet of Vehicles, characterized in that: include: An identification module, used to analyze and identify potential threat risk data of the vehicle network system, and obtain risk levels and classification basis, wherein the threat risk data includes: at least one of data leakage, data tampering and data loss, and the classification basis includes: at least one of periodically generated data, user behavior data and emergency data; A formulation module, used to formulate a data life cycle rule table according to the risk level and the classification basis; A sending module is used to send the data life cycle rule table to the vehicle end, wherein the data life cycle rule table is used for security protection of data in the vehicle end.

8. A device for protecting data security in an Internet of Vehicles, characterized in that: include: A sending module, used for sending a potential threat risk data analysis instruction of the vehicle network system to the cloud when the vehicle-mounted electrical component is started, wherein the analysis instruction is used by the cloud to analyze and identify the potential threat risk data of the vehicle network system and formulate a data full life cycle rule table; A receiving module, used for receiving the data life cycle rule table sent by the cloud; The protection module is used to perform security protection on the vehicle-mounted data according to the data full life cycle rule table.

9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method as described in any one of claims 1-4 or 5-6 are executed.

10. A computer-readable storage medium, characterized in that: include: A computer program, when the computer program is run on a computer, causes the computer to execute the method according to any one of claims 1-4 or 5-6.