Vehicle exposed data interface protection method and system, electronic equipment and vehicle
By setting up a verification module in the vehicle and comparing verification information when the vehicle is powered on, the problem of lack of information security protection for the external interface of the vehicle is solved, and effective protection of the exposed data interface of the vehicle is achieved, ensuring the security and integrity of the data.
Patent Information
- Application Number
- CN202510507947.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-06-03
AI Technical Summary
The external interface of the vehicle lacks an information security protection mechanism, which poses the risk of unauthorized access, affecting the security and integrity of vehicle data.
By setting up a verification module in the vehicle, receiving the verification information input by the user in response to the vehicle when powered on, and comparing it with the standard information, it determines whether the verification has passed. If the verification is passed, the vehicle's exposed data interface is allowed to be connected to the on-board data source; otherwise, it remains disconnected to prevent unauthorized access.
Effectively prevent unauthorized personnel from illegally accessing and obtaining data when the vehicle stops running, reducing the risk of data leakage, ensuring the security and integrity of vehicle data, and complying with the provisions of GB44495-2024 "Technical Requirements for Information Security of Automobile Complete Vehicles".
Smart Images

Figure CN120080809A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission security, and specifically relates to a protection method, system, electronic device and vehicle for vehicle exposed data interfaces. Background Art
[0002] Against the backdrop of the booming development of intelligent connected vehicles, the networking technology drives the continuous outward expansion and extension of the vehicle communication network, while the intelligent technology promotes the internal upgrade and optimization of the vehicle communication network. This continuous extension and upgrade enable the vehicle communication to carry richer vehicle function interactions, bringing many new value experiences to users. However, when a vehicle breaks down, finding the root cause of the problem and locating the fault location must rely on the relevant data presented in the vehicle communication. It can be said that the accuracy and completeness of vehicle data are directly related to the accuracy and timeliness of problem location.
[0003] In addition, according to the clear stipulation of GB44495-2024 "Technical Requirements for Vehicle Information Security", "Access control protection measures shall be implemented for vehicle external interfaces, and unauthorized access is strictly prohibited", which means that the external interfaces of vehicles must have information security protection mechanisms, and there must be no external interfaces lacking security protection. Summary of the Invention
[0004] The purpose of the present invention is to provide a protection method, system, electronic device and vehicle for vehicle exposed data interfaces, which can collect all vehicle original data, while ensuring the security of the data interface and preventing unauthorized access.
[0005] To achieve the above purpose, the technical solution adopted by the present invention is as follows: In the first aspect, the present invention discloses a protection method for vehicle exposed data interfaces, which is applied to the vehicle end and includes: In response to vehicle power-off, the vehicle exposed data interface is in a disconnected state from the vehicle data source; In response to vehicle power-on, receive the verification information input by the user, compare the verification information with the standard information, and determine whether the verification passes; If the verification fails, the vehicle exposed data interface is in a disconnected state from the vehicle data source; If the verification passes, adjust the vehicle exposed data interface to a connected state with the vehicle data source.
[0006] Further, in response to vehicle power-on, receiving the verification information input by the user, comparing the verification information with the standard information, and determining whether the verification passes specifically includes: The verification module receives the request identity verification instruction sent by the user, and sends an identity verification request instruction including the user's personal information to the verification module; The verification module receives the identity verification result of the verification module. If the identity verification fails, the process ends; if the identity verification passes, it receives the verification information input by the user and the standard information generated by the verification module, and conducts a comparison. If the verification information is consistent with the standard information, it is determined that the verification passes; otherwise, it is determined that the verification fails.
[0007] Furthermore, the verification module is arranged in the cloud server.
[0008] Furthermore, when the vehicle external data interface and the in-vehicle data source are in a connected state, in response to receiving a disconnection instruction sent by the user, or when the connection time between the vehicle external data interface and the in-vehicle data source exceeds a preset time threshold, or when the vehicle switches from the powered-on state to the powered-off state, control the disconnection between the vehicle external data interface and the in-vehicle data source.
[0009] Furthermore, a controllable switch is arranged between the vehicle external data interface and the in-vehicle data source. In response to the vehicle powering off, or in response to the vehicle powering on and the verification failing, the controllable switch is in the cut-off state; in response to the vehicle powering on and the verification passing, the controllable switch is in the conducting state.
[0010] Furthermore, in response to the vehicle external data interface and the in-vehicle data source being in a connected state, data collection, data diagnosis, data calibration, or data configuration is performed on the vehicle's full amount of original data through the vehicle external data interface.
[0011] In a second aspect, the present invention discloses a vehicle external data interface protection system, which is characterized by including: A first response module, used to control the vehicle external data interface and the in-vehicle data source to be in a disconnected state in response to the vehicle powering off; A verification module, used to receive the verification information input by the user in response to the vehicle powering on, compare the verification information with the standard information, and determine whether the verification passes; A second response module, used to control the vehicle external data interface and the in-vehicle data source to be in a disconnected state when the verification by the verification module fails; A third response module, used to control the vehicle external data interface and the in-vehicle data source to be in a connected state when the verification by the verification module passes.
[0012] Furthermore, it further includes a fourth response module, used to control the disconnection between the vehicle external data interface and the in-vehicle data source when the vehicle external data interface and the in-vehicle data source are in a connected state, in response to receiving a disconnection instruction sent by the user, or when the connection time between the vehicle external data interface and the in-vehicle data source exceeds a preset time threshold, or when the vehicle switches from the powered-on state to the powered-off state.
[0013] In a third aspect, the present invention discloses an electronic device, comprising a processor and a memory; the memory stores one or more programs, and when the one or more programs are executed by the processor, the vehicle is caused to execute the above-mentioned vehicle external data interface protection method.
[0014] In a fourth aspect, the present invention discloses a vehicle, comprising the above-mentioned electronic device.
[0015] The present invention has the following unexpected beneficial effects: 1. When the vehicle is powered off, the method of the present invention ensures that the vehicle external data interface is disconnected from the vehicle data source, effectively preventing unauthorized personnel from illegally accessing and obtaining data when the vehicle stops running. When the vehicle is powered on, the connection state of the vehicle external data interface and the vehicle data source is controlled by comparing verification information. Only when the verification passes is the connection allowed, avoiding the random access and tampering of the vehicle data source data by unauthorized personnel, reducing the risk of data leakage, and ensuring the security of vehicle data. Moreover, the operation process of this method is relatively simple. When the vehicle is powered off, the connection is automatically disconnected. When the vehicle is powered on, verification is performed. If the verification passes, the connection is established. If the verification fails, the disconnection is maintained. This simple logic is easy to implement and execute, and can effectively protect the vehicle external data interface without adding too many complex operations and system burdens, helping to improve the system operation efficiency and reduce the failure probability caused by complex protection mechanisms.
[0016] 2. The present invention provides a full-volume raw data acquisition interface, namely the vehicle data source, without the need for additional mapping, secondary acquisition processing or forwarding of the communication network. It can directly diagnose, calibrate and configure the vehicle, improving the efficiency and accuracy of data acquisition, ensuring the integrity of data, and better meeting the interface requirements of the vehicle for data acquisition, data diagnosis, data calibration and data configuration functions.
[0017] 3. The present invention uses a verification module in the cloud for permission management. The cloud performs authorization management according to methods such as white lists or multi-dimensional identity authentication. If the operator belongs to a legitimate identity within the authorized scope, the cloud will distribute verification information for the verification module to compare. The comparison through the two-level security policies of the list and verification information is more secure. At the same time, since the storage and maintenance of the authorized list are carried out in the cloud, it is more difficult for hackers to bypass authorization to obtain data, and the authorization management is more secure. Description of the Drawings
[0018] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention.
[0019] Figure 1The flowchart of the vehicle exposed data interface protection method provided by the embodiments of the present invention is shown.
[0020] Figure 2 The structural schematic diagram of the vehicle exposed data interface protection system provided by the embodiments of the present invention is shown.
[0021] Figure 3 The structural schematic diagram of a specific example of the vehicle exposed data interface protection system of the present invention is shown.
[0022] Figure 4 The structural schematic diagram of the vehicle provided by the embodiments of the present invention is shown.
[0023] Figure 5 The flowchart of a specific example of the vehicle exposed data interface protection method of the present invention is shown. Detailed implementation manners
[0024] The following will illustrate the implementation manners of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention rather than for limiting the protection scope of the present invention.
[0025] In one embodiment, the present invention provides a vehicle exposed data interface protection method, which is applied to the vehicle end. Refer to Figure 1 and Figure 3 as shown, the protection method includes: In response to the vehicle powering off, the vehicle exposed data interface 15 and the vehicle-mounted data source 16 are in a disconnected state. With such a setting, it is ensured that the vehicle exposed data interface 15 and the vehicle-mounted data source 16 are disconnected, which can effectively prevent unauthorized personnel from illegally accessing and obtaining data when the vehicle stops running.
[0026] In response to the vehicle powering on, receive the verification information input by the user, compare the verification information with the standard information, and determine whether the verification passes; if the verification fails, the vehicle exposed data interface 15 and the vehicle-mounted data source 16 are in a disconnected state; if the verification passes, adjust the vehicle exposed data interface 15 and the vehicle-mounted data source 16 to a connected state.
[0027] When the vehicle is powered on, the connection status between the vehicle's exposed data interface 15 and the in-vehicle data source 16 is controlled by comparing verification information. Only when the verification is passed is the connection allowed, which avoids unauthorized access to and tampering with the data of the in-vehicle data source 16, reduces the risk of data leakage, ensures the security of vehicle data, and complies with the regulations on access control protection of vehicle external interfaces in GB44495-2024 "Technical Requirements for Vehicle Information Security".
[0028] The operation process of the method of the present invention is relatively simple. When the vehicle is powered off, the connection is automatically disconnected. When powered on, verification is performed. If the verification is passed, the connection is established; if the verification fails, the disconnection is maintained. This simple logic is easy to implement and execute, and can effectively protect the vehicle's exposed data interface 15 without adding too many complex operations and system burdens, which helps to improve the system operation efficiency and reduce the failure probability caused by complex protection mechanisms. Moreover, by comparing the verification information with the standard information, it can be ensured that only authorized personnel who meet the standards can access the in-vehicle data source 16, guaranteeing the legality of the data operation subject. This enables operations such as data collection, diagnosis, calibration, and configuration of vehicle data to be carried out within the authorized scope, avoiding vehicle failures or safety problems caused by illegal operations, and ensuring the normal operation of the vehicle and the use safety of users.
[0029] In the vehicle after-sales maintenance scenario, authorized maintenance personnel can connect the vehicle's exposed data interface 15 and the in-vehicle data source 16 through the verification process to perform operations such as data collection and fault diagnosis, obtain the original data of the vehicle, help accurately and quickly locate and solve vehicle problems, improve the efficiency and quality of after-sales maintenance, and provide convenience for after-sales maintenance throughout the vehicle's life cycle.
[0030] As a preferred implementation manner of the present invention, in response to the vehicle being powered on, receiving the verification information input by the user and comparing the verification information with the standard information, determining whether the verification is passed specifically includes: the verification module 12 receives the request identity verification instruction sent by the user and sends an identity verification request instruction including the user's personal information to the verification module 17; the verification module 12 receives the identity verification result of the verification module 17. If the identity verification fails, the process ends; if the identity verification passes, it receives the verification information input by the user and the standard information generated by the verification module 17 and performs a comparison; if the verification information is consistent with the standard information, it is determined that the verification is passed; otherwise, it is determined that the verification fails.
[0031] By adding a request identity verification instruction and sending the user's personal information to the verification module 17, the user's identity can be preliminarily screened in advance. The verification module 17 conducts verification based on the user's personal information, which can more comprehensively confirm whether the user has access qualifications and avoid security vulnerabilities that may occur when relying solely on a single verification message. Only after the verification module 17 confirms that the user's identity is initially compliant will the subsequent comparison of the verification information with the standard information be entered, which greatly improves the rigor of the overall verification process and effectively reduces the risk of illegal users bypassing the verification.
[0032] In this preferred embodiment, the verification process is divided into multiple clear steps. From sending the request identity verification instruction, to receiving the identity verification result, and then to comparing the verification information with the standard information, each link has a clear definition and sequence. This logically clear process not only facilitates system design and code writing for developers but also benefits subsequent system maintenance and upgrades. At the same time, when verification anomalies or security issues occur, it is easier to troubleshoot and locate the problem, improving the maintainability of the system.
[0033] Meanwhile, in this embodiment, the verification module 17 can be designed and optimized independently of the verification module 12. If it is necessary to adjust the identity verification criteria or methods, only the verification module 17 needs to be modified without affecting other parts of the verification module 12. For example, in the future, it can be conveniently connected to more complex identity verification algorithms or databases, or docked with other security systems to achieve more advanced identity verification functions such as multi-factor authentication, thereby enhancing the security and adaptability of the entire verification system.
[0034] Furthermore, as shown in Figure 3 The verification module 17 is arranged in the cloud server. On the one hand, the cloud server can centrally store and manage a large amount of standard information and authorized personnel data, which can be directly called by the verification module 17. When there are changes in personnel permissions or updates to verification rules, only unified modifications need to be made in the cloud, and all vehicles using this verification module 17 can obtain the latest data in real time without separately upgrading the local systems of each vehicle, greatly improving management efficiency and update timeliness. For example, when a batch of new maintenance personnel are authorized, after updating the authorized personnel white list in the cloud verification module 17, the relevant personnel can immediately perform identity verification operations on each vehicle. Moreover, the cloud verification module 17 can share data and work collaboratively with other relevant systems. For example, it can be docked with the after-sales service system of the vehicle manufacturer, the vehicle insurance system, etc. to achieve multi-dimensional identity verification and data association. When conducting identity verification, it can not only compare the authorized personnel white list but also comprehensively judge in combination with user information in other systems, further enhancing the accuracy and security of verification.
[0035] On the other hand, by placing the verification module 17 in the cloud, the vehicle does not need to be equipped with complex local verification hardware and software, which reduces the hardware burden of the vehicle, as well as the production cost and system complexity. The vehicle only needs to be responsible for receiving user input information and interacting with the cloud, reducing the probability of local hardware failures and improving the overall stability and reliability of the vehicle.
[0036] As a preferred embodiment of the present invention, when the vehicle external data interface 15 and the in-vehicle data source 16 are in a connected state, in response to receiving a disconnection instruction sent by the user, or when the vehicle external data interface 15 fails to perform a data transmission action for more than a preset time threshold, or when the vehicle switches from the powered-on state to the powered-off state, control is performed to disconnect the connection between the vehicle external data interface 15 and the in-vehicle data source 16.
[0037] When receiving a disconnection instruction sent by the user, immediately controlling the disconnection between the vehicle external data interface 15 and the in-vehicle data source 16 can ensure that the user timely cuts off the data transmission channel after completing the operation, avoiding potential data security risks caused by forgetting to disconnect, and effectively preventing unauthorized personnel from using the connection for illegal data access after the user leaves. Disconnecting when the vehicle external data interface 15 fails to perform a data transmission action for more than a preset time threshold can prevent the interface from being in a connected state for a long time without actual data transmission, reducing the risk of being attacked by hackers or invaded by malicious software, and decreasing the possibility of data leakage. And disconnecting when the vehicle switches from the powered-on state to the powered-off state conforms to the vehicle operation logic, ensuring that when the vehicle stops running, the in-vehicle data source is completely isolated from the outside world, further guaranteeing data security.
[0038] In this preferred embodiment, by automatically disconnecting unused data connections for a long time, the invalid occupation of system resources is avoided. During the operation of the vehicle, system resources are limited. Continuously maintaining unused data connections will consume resources such as network bandwidth and power, affecting the normal operation of other functions of the vehicle. This automatic disconnection mechanism can improve the utilization rate of system resources, ensuring the efficient operation of the vehicle system in all aspects. Moreover, promptly responding to the disconnection instruction and automatically disconnecting when there is no operation can make the user feel the intelligence and convenience of the system. The user does not need to worry about the management of the connection status, and the system will handle it automatically, enhancing the user's satisfaction with the security and convenience of vehicle data operations. At the same time, this mechanism also helps to improve the overall stability of the vehicle, reducing system failures caused by abnormal connections and providing a more reliable usage environment for the user.
[0039] As a preferred embodiment of the present invention, refer to Figure 3As shown, a controllable switch 18 is arranged between the vehicle exposed data interface 15 and the on-board data source 16. In response to the vehicle powering off, or in response to the vehicle powering on and the verification fails, the controllable switch 18 is in the off state; in response to the vehicle powering on and the verification passes, the controllable switch 18 is in the on state.
[0040] The controllable switch 18 is in the off state when the vehicle is powered off or the verification fails, which physically cuts off the connection between the vehicle's exposed data interface and the on-board data source, just like setting a solid gate on the data channel. It effectively prevents unauthorized personnel from illegally accessing the on-board data source through the vehicle's exposed data interface when the vehicle is powered off, and also prevents personnel who fail the verification from obtaining data, greatly reducing the risk of data leakage and tampering, and ensuring the security and integrity of the data.
[0041] In this preferred embodiment, the verification result is directly associated with the state of the controllable switch 18, making the system control logic clearer and simpler. When the vehicle is powered on, the controllable switch 18 is turned on or off only based on whether the verification is passed, reducing the complex intermediate judgment links. This simple and direct control method is not only convenient for system development and maintenance, but also reduces the risk of security vulnerabilities caused by logical errors and improves the stability and reliability of system operation.
[0042] The controllable switch 18 can quickly respond to changes in vehicle status and verification results. When the verification is passed, the controllable switch 18 is quickly turned on, and the authorized personnel can perform data operations in time; when the vehicle is powered off or the verification fails, the controllable switch 18 is immediately turned off and the connection is quickly cut off. This fast response mechanism can effectively reduce data transmission delays and improve user experience. At the same time, it can also respond to potential security threats in a timely manner and ensure the safe operation of the vehicle data system.
[0043] As a preferred embodiment of the present invention, in response to the vehicle exposed data interface 15 being connected to the vehicle-mounted data source 16 , data collection, data diagnosis, data calibration or data configuration is performed on the vehicle through the vehicle exposed data interface 15 .
[0044] When the vehicle exposed data interface 15 is connected to the vehicle data source 16, data collection, diagnosis, calibration and configuration can be directly performed without additional complicated switching or data processing steps, thus reducing the operation process and time cost. For example, when a vehicle fails, maintenance personnel can quickly connect to the vehicle exposed data interface 15, quickly obtain fault data and perform diagnosis, thus shortening the vehicle maintenance time and reducing the downtime loss caused by vehicle failure.
[0045] See also Figure 3 As shown, the hardware device corresponding to the protection method of the present invention is described in detail with reference to a specific example, including: The verification module 12 is used to input the identity information of the operator and send it to the verification module 17. At the same time, it receives the standard information sent by the verification module 17 and the verification information sent by the operation terminal 19 for comparison and verification. According to the verification result, it controls the controllable switch 18 to be controlled to conduct or remain disconnected.
[0046] The vehicle external data interface 15 is a connection interface for the operator to collect, diagnose, calibrate, and configure data of the vehicle. It is set in a place where it is convenient for the operator to connect or can be connected by simple disassembly.
[0047] The vehicle-mounted data source 16 securely connects the communication network to the vehicle external data interface 15 through the controllable switch 18.
[0048] The verification module 17, after receiving the personal information sent by the verification module 12, compares it with the authorized personnel white list stored in the cloud server. If the received personal information is within the white list, it will send the verification information to the verification module 12 and the operator's operation terminal 19 respectively.
[0049] The controllable switch 18 is used to control the disconnection or connection between the vehicle external data interface 15 and the vehicle-mounted data source 16. It is in the disconnected state when "not powered on" or "remaining disconnected", and in the connected state when controlled to be "connected".
[0050] The operation terminal 19 is responsible for receiving the verification information from the verification module 17.
[0051] See Figure 5 As shown, the working process of the protection method described in the present invention will be described in detail with specific examples.
[0052] Normally disconnected state: In the normally disconnected state, no operator operates the vehicle, the vehicle is not powered on, the controllable switch 18 is in the normally disconnected state, and the vehicle external data interface 15 is not connected to the vehicle-mounted data source 16.
[0053] Identity verification process: When an operator needs to perform data operations on a vehicle, after obtaining the vehicle key, the vehicle is powered on. At this time, the controllable switch 18 is powered on and in a controlled state, and the verification module 12 arranged at the vehicle end is powered on and in a standby state. The operator inputs personal information into the verification module 12 for verification. After the verification module 12 enters the operator's information, it sends it to the verification module 17 arranged in the cloud server. After receiving the personal information, the verification module 17 compares it with the whitelist of authorized personnel stored in the cloud server. If it is not within the scope of authorized personnel, no processing is done and the process ends. If the received personal information is within the scope of authorized personnel, verification information is generated and the generated verification information is sent to the verification module 12 and the operator's operation terminal 19 respectively. The operator inputs the verification information into the verification module 12 again for verification information verification. The verification module 12 compares the verification information from the verification module 17 of the cloud server with the verification information input by the operator. If they are consistent, the controllable switch 18 is controlled to conduct. If they are inconsistent, the controllable switch 18 remains in a normally open state. When the controllable switch 18 is in a conducting state, the vehicle external data interface 15 is connected to the vehicle-mounted data source 16 in a controlled state. At this time, the operator passes the identity verification and is an authorized person, and can perform relevant data operations, that is, data collection, diagnosis, calibration, or configuration can be carried out. It should be noted that the verification information should meet the randomness requirement to ensure higher security.
[0054] Return to the normally open state: When a disconnection instruction sent by the user is received, or the vehicle external data interface 15 exceeds the preset time threshold, or the vehicle switches from the powered-on state to the powered-off state, the verification module 12 at the vehicle end controls the controllable switch 18 to disconnect, and the vehicle external data interface 15 is no longer connected to the vehicle-mounted data source 16, and the entire system returns to the normally open state.
[0055] After the vehicle-end verification module 12 exits this authentication, the operator needs to re-perform identity verification according to the above process to perform data operations again.
[0056] In another embodiment, the present invention also discloses a protection system for a vehicle external data interface. Refer to Figure 2As shown, the protection system 10 includes a first response module 11, a verification module 12, a second response module 13, and a fourth response module 14. The first response module 11 is configured to control the vehicle's external data interface and the in-vehicle data source to be in a disconnected state in response to the vehicle powering off. The verification module 12 is configured to receive the verification information input by the user in response to the vehicle powering on, compare the verification information with the standard information, and determine whether the verification passes. The second response module 13 is configured to control the vehicle's external data interface and the in-vehicle data source to be in a disconnected state when the verification by the verification module fails. The third response module 14 is configured to control the vehicle's external data interface and the in-vehicle data source to be in a connected state when the verification by the verification module passes.
[0057] As a preferred embodiment of the present invention, the vehicle external data interface protection system further includes a fourth response module, which is configured to, when the vehicle external data interface 15 and the in-vehicle data source 16 are in a connected state, in response to receiving a disconnection instruction sent by the user, or when the vehicle external data interface 15 fails to perform a data transmission action for a preset time threshold, or when the vehicle switches from the powered-on state to the powered-off state, control the vehicle external data interface 15 and the in-vehicle data source 16 to be disconnected.
[0058] In another embodiment, the present invention also discloses an electronic device, including a processor and a memory; the memory stores one or more programs, and when the one or more programs are executed by the processor, the vehicle is caused to execute the vehicle external data interface protection method described in any of the above embodiments.
[0059] In another embodiment, the present invention also discloses a vehicle, as shown in Figure 4 The vehicle 100 includes the above-mentioned electronic device.
[0060] The above embodiments are only preferred embodiments given to fully illustrate the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or transformations made by those skilled in the art on the basis of the present invention are all within the protection scope of the present invention.
Claims
1. A method for protecting an exposed data interface of a vehicle, characterized in that: Applied to the vehicle side, including: In response to the vehicle being powered off, the vehicle's exposed data interface and the vehicle's onboard data source are disconnected; In response to the vehicle being powered on, receiving verification information input by a user, comparing the verification information with standard information, and determining whether the verification is passed; If the verification fails, the vehicle's exposed data interface and the vehicle's onboard data source are disconnected; If the verification is successful, the vehicle's exposed data interface and the onboard data source are adjusted to a connection state.
2. The method for protecting the exposed data interface of a vehicle according to claim 1, characterized in that: In response to the vehicle being powered on, receiving verification information input by the user, comparing the verification information with standard information, and determining whether the verification is passed specifically includes: The verification module receives the identity verification request instruction sent by the user, and sends the identity verification request instruction including the user's personal information to the verification module; The verification module receives the identity verification result of the verification module. If the identity verification fails, the process ends; if the identity verification passes, the verification information input by the user and the standard information generated by the verification module are received and compared; if the verification information is consistent with the standard information, the verification is determined to be passed, otherwise, the verification is determined to be failed.
3. The method for protecting the exposed data interface of a vehicle according to claim 1, characterized in that: The verification module is arranged on a cloud server.
4. The method for protecting the exposed data interface of a vehicle according to claim 1, characterized in that: When the vehicle's exposed data interface is in a connected state with the on-board data source, in response to receiving a disconnection instruction sent by a user, or the connection time between the vehicle's exposed data interface and the on-board data source exceeds a preset time threshold, or the vehicle switches from a power-on state to a power-off state, the vehicle's exposed data interface and the on-board data source are controlled to be disconnected.
5. The method for protecting the exposed data interface of a vehicle according to claim 1, characterized in that: A controllable switch is arranged between the vehicle exposed data interface and the vehicle-mounted data source, and in response to the vehicle being powered off, or in response to the vehicle being powered on and the verification fails, the controllable switch is in an off state; In response to the vehicle being powered on and the verification being passed, the controllable switch is in the on state.
6. The method for protecting the exposed data interface of a vehicle according to claim 1, characterized in that: In response to the vehicle exposed data interface being connected to the vehicle-mounted data source, data collection, data diagnosis, data calibration or data configuration is performed on the entire amount of original data of the vehicle through the vehicle exposed data interface.
7. A vehicle exposed data interface protection system, characterized in that: include: A first response module, configured to control the vehicle's exposed data interface and the vehicle's onboard data source to be in a disconnected state in response to the vehicle being powered off; A verification module, for receiving verification information input by a user in response to the vehicle being powered on, comparing the verification information with standard information, and determining whether the verification is passed; The second response module is used to control the vehicle's exposed data interface and the vehicle-mounted data source to be disconnected when the verification module fails to pass the verification; The third response module is used to control the vehicle's exposed data interface and the vehicle-mounted data source to be in a connected state when the verification module passes the verification.
8. A vehicle exposed data interface protection system, characterized in that: It also includes a fourth response module, which is used to control the disconnection between the vehicle's exposed data interface and the on-board data source in response to receiving a disconnection instruction sent by a user when the vehicle's exposed data interface and the on-board data source are in a connected state, or the connection time between the vehicle's exposed data interface and the on-board data source exceeds a preset time threshold, or the vehicle switches from a power-on state to a power-off state.
9. An electronic device, characterized in that: It comprises a processor and a memory; the memory stores one or more programs, and when the one or more programs are executed by the processor, the vehicle executes the vehicle exposed data interface protection method as described in any one of claims 1 to 7.
10. A vehicle, characterized in that: Comprising the electronic device as claimed in claim 9.
Citation Information
Patent Citations
Method and device for vehicle network access control
CN105704102A
Vehicle CAN network data access method
CN106990726A
Maintenance system and maintenance method
CN110800249A
Segment of a communication network of a land motor vehicle, and associated land motor vehicle
CN112262555A
Improved safety electronics device
DE202025101108U1