Data processing method and device for vehicle bus and vehicle
By encrypting the communication data between vehicle controllers in the vehicle bus communication system, the data security problem caused by plain text transmission is solved, secure data transmission between vehicle controllers is realized, and the overall security of the vehicle is enhanced.
Patent Information
- Application Number
- CN202510257288.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-03
AI Technical Summary
In the prior art, communication data between vehicle controllers is transmitted in plain text, resulting in insufficient data security and is easily maliciously cracked, causing vehicle security threats.
By applying encryption technology in the vehicle bus communication system, the first vehicle controller obtains the mask information sent by the control center, encrypts the plain text communication data to be sent, generates the cipher text communication data, and inserts it into the plain text communication data, forms the target communication data, and transmits it to the second vehicle controller through the vehicle bus.
It realizes the secure transmission of communication data between vehicle controllers, enhances the confidentiality and integrity of data, prevents data leakage and malicious attacks, and improves the overall security of the vehicle.
Smart Images

Figure CN120090848A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle communication, and particularly to a data processing method, apparatus and vehicle for a vehicle bus. Background Art
[0002] With the continuous progress of technology, the automobile, as an important means of transportation in modern society, is gradually developing towards the intelligent direction. An intelligent vehicle can not only provide basic driving functions, but also greatly improve driving safety and convenience by integrating a variety of advanced technologies, such as automatic driving, automatic parking, lane departure warning, etc. To implement these complex functions, a complex in-vehicle network system is built inside the vehicle, which realizes communication and coordinated work between devices by connecting various processing devices and sensor devices, thereby ensuring the smooth execution of various functions.
[0003] However, with the rapid development of automotive electronics technology and the increasing complexity of vehicle functions, the number of in-vehicle controllers has increased from only a few in the past to hundreds now. Based on functional requirements, these controllers need to perform a large amount of data interaction at all times.
[0004] In the related art, the communication data between vehicle controllers is directly transmitted in plain text. Although this transmission method is simple, the protection of communication data is very limited and it is easily cracked maliciously, thus posing a serious threat to vehicle safety. Summary of the Invention
[0005] The present application provides a data processing method, apparatus and vehicle for a vehicle bus, aiming to solve the data security problem that may occur when vehicle controllers transmit communication data in plain text in the prior art. The specific technical solutions are as follows:
[0006] In the first aspect of the implementation of the present application, first, a data processing method for a vehicle bus is provided, which is characterized in that it is applied to a first vehicle controller, the first vehicle controller is communicatively connected to a control center, the data processing involves a first vehicle controller and a second vehicle controller communicatively connected based on the vehicle bus, and the method includes:
[0007] Obtain first mask information sent by the control center;
[0008] In response to a trigger event, determine first plaintext communication data to be sent, encrypt the first plaintext communication data according to the first mask information to obtain first ciphertext communication data;
[0009] Insert the first ciphertext communication data into the first plaintext communication data to obtain target communication data;
[0010] Transmit the target communication data to the second vehicle controller via the vehicle bus.
[0011] In an alternative embodiment of the present application, the plaintext communication data includes first communication identification information and first payload data. Encrypting the first plaintext communication data according to the first mask information to obtain first ciphertext communication data includes:
[0012] Perform a hash calculation on the first mask information and the first communication identification information to obtain a first data identifier;
[0013] Perform a hash calculation on the first payload data and the first data identifier to obtain the first ciphertext communication data.
[0014] In an alternative embodiment of the present application, inserting the first ciphertext communication data into the first plaintext communication data to obtain target communication data includes:
[0015] Obtain first encryption interleaving information sent by the control center, and determine a first target position of the first payload data according to the first encryption interleaving information;
[0016] Insert the first ciphertext communication data into the first target position of the first payload data to obtain target communication data.
[0017] In an alternative embodiment of the present application, the vehicle bus is a Controller Area Network Protocol version 3 bus.
[0018] In a second aspect of the implementation of the present application, there is also provided a method for processing data of a vehicle bus, which is characterized in that it is applied to a second vehicle controller. The second vehicle controller is communicatively connected to a control center. The data processing involves a first vehicle controller and a second vehicle controller communicatively connected via the vehicle bus. The method includes:
[0019] Obtain second mask information sent by the control center;
[0020] In the case of receiving target communication data sent by the first vehicle controller via the vehicle bus, determine second plaintext communication data and second ciphertext communication data from the target communication data;
[0021] Encrypt the second plaintext communication data according to the second mask information to obtain encrypted verification data;
[0022] In the case of determining that the encrypted verification data is consistent with the second ciphertext communication data, process the second plaintext communication data.
[0023] In an alternative embodiment of the present application, the target communication data includes second payload data. Determining the second plaintext communication data and the second ciphertext communication data from the target communication data includes:
[0024] Obtain the second encryption interleaving information sent by the control center, and determine the second target position of the second payload data from the second encryption interleaving information;
[0025] Split the target communication data according to the second target position of the second payload data to obtain the second plaintext communication data and the second ciphertext communication data.
[0026] In an alternative embodiment of the present application, the second plaintext communication data further includes second communication identification information and third payload information. Encrypting the second plaintext communication data according to the second mask information to obtain encrypted verification data includes:
[0027] Perform a hash calculation on the second mask information and the second communication identification information to obtain a second data identifier;
[0028] Perform a hash calculation on the second payload data and the second data identifier to obtain the encrypted verification data.
[0029] In a third aspect of the implementation of the present application, there is also provided a data processing method for a vehicle bus, which is characterized in that it is applied to a control center, and the control center is communicatively connected to a vehicle first controller and a vehicle second controller. The method includes:
[0030] Obtain the interaction information on the vehicle bus;
[0031] Determine a target communication message from the interaction information;
[0032] Determine the vehicle first controller and the vehicle second controller corresponding to the target communication message;
[0033] Generate a first mask information and a second mask information;
[0034] Send the first mask information to the vehicle first controller, so that when the vehicle first controller sends the first plaintext communication data to the vehicle second controller, encrypt the first plaintext communication data according to the first mask information to obtain the first ciphertext communication data;
[0035] Send the second mask information to the vehicle second controller, so that when the vehicle second controller receives the target communication data sent by the vehicle first controller, process the target communication data according to the second mask information.
[0036] In an alternative embodiment of the present application, the method further includes:
[0037] Generating first encrypted interleaved information and second encrypted interleaved information;
[0038] Sending the first encrypted interleaved information to the first vehicle controller, so that the first vehicle controller inserts the first encrypted communication data into the first plaintext communication data according to the first encrypted interleaved information to obtain target communication data;
[0039] Sending the second encrypted interleaved information to the second vehicle controller, so that the second vehicle controller splits the target communication data according to the second encrypted interleaved information to obtain second plaintext communication data and second encrypted communication data.
[0040] In a fourth aspect of the implementation of the present application, there is also provided a data processing device for a vehicle bus, characterized in that it is applied to a first vehicle controller, the first vehicle controller is communicatively connected to a control center, and data processing involves the first vehicle controller and the second vehicle controller communicatively connected based on the vehicle bus. The device includes:
[0041] A first mask acquisition module, configured to acquire first mask information sent by the control center;
[0042] A first encryption module, configured to, in response to a trigger event, determine first plaintext communication data to be sent, and encrypt the first plaintext communication data according to the first mask information to obtain first encrypted communication data;
[0043] A data insertion module, configured to insert the first encrypted communication data into the first plaintext communication data to obtain target communication data;
[0044] A data sending module, configured to transmit the target communication data to the second vehicle controller through the vehicle bus.
[0045] In a fifth aspect of the implementation of the present application, there is also provided a data processing device for a vehicle bus, characterized in that it is applied to a second vehicle controller, the second vehicle controller is communicatively connected to a control center, and the data processing involves the first vehicle controller and the second vehicle controller communicatively connected based on the vehicle bus. The method device:
[0046] A second mask acquisition module, configured to acquire second mask information sent by the control center;
[0047] A data receiving module, configured to, when receiving the target communication data sent by the first vehicle controller through the vehicle bus, determine second plaintext communication data and second encrypted communication data from the target communication data;
[0048] A second encryption module, configured to encrypt the second plaintext communication data according to the second mask information to obtain encrypted verification data;
[0049] A data verification module, configured to process the second plaintext communication data when it is determined that the encrypted verification data is consistent with the second ciphertext communication data.
[0050] In a sixth aspect of the implementation of the present application, there is also provided a data processing device for a vehicle bus, characterized in that it is applied to a control center, the control center is communicatively connected to a vehicle first controller and a vehicle second controller, and the device includes:
[0051] An interaction information acquisition module, configured to acquire the interaction information on the vehicle bus;
[0052] A screening module, configured to determine a target communication message from the interaction information;
[0053] A target determination module, configured to determine the vehicle first controller and the vehicle second controller corresponding to the target communication message;
[0054] A mask generation module, configured to generate first mask information and second mask information;
[0055] A first sending module, configured to send the first mask information to the vehicle first controller, so that when the vehicle first controller sends first plaintext communication data to the vehicle second controller, encrypt the first plaintext communication data according to the first mask information to obtain first ciphertext communication data;
[0056] A second sending module, configured to send the second mask information to the vehicle second controller, so that when the vehicle second controller receives the target communication data sent by the vehicle first controller, process the target communication data according to the second mask information.
[0057] In a seventh aspect of the implementation of the present application, there is also provided a vehicle, characterized in that it includes
[0058] One or more processors; and
[0059] One or more memories storing instructions thereon, the instructions stored in the memories are readable, compiled and executable by the processors to implement the method as described above.
[0060] The embodiments of the present application have the following advantages:
[0061] By obtaining the first mask information sent by the control center, in response to a trigger event, determining the first plaintext communication data to be sent, encrypting the first plaintext communication data according to the first mask information to obtain the first ciphertext communication data, inserting the first ciphertext communication data into the first plaintext communication data to obtain the target communication data, and transmitting the target communication data to the vehicle second controller through the vehicle bus, the secure transmission of communication data between vehicle controllers is ensured. Description of the Drawings
[0062] In order to more clearly illustrate the technical solutions of the present application, the drawings required for the description of the present application will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0063] Figure 1 is a flowchart of the steps of a method for processing data of a vehicle bus provided by some embodiments of the present application;
[0064] Figure 2 is a flowchart of the steps of another method for processing data of a vehicle bus provided by some embodiments of the present application;
[0065] Figure 3 is a flowchart of the steps of another method for processing data of a vehicle bus provided by some embodiments of the present application;
[0066] Figure 4 is a flowchart of the steps of another method for processing data of a vehicle bus provided by some embodiments of the present application;
[0067] Figure 5 is a flowchart of the steps of another method for processing data of a vehicle bus provided by some embodiments of the present application;
[0068] Figure 6 is a block diagram of the structure of a device for processing data of a vehicle bus provided by some embodiments of the present application;
[0069] Figure 7 is a block diagram of the structure of another device for processing data of a vehicle bus provided by some embodiments of the present application;
[0070] Figure 8 is a block diagram of the structure of another device for processing data of a vehicle bus provided by some embodiments of the present application. Detailed Embodiments
[0071] To make the above objects, features, and advantages of the present application more apparent and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts fall within the scope of protection of the present application.
[0072] Referring to Figure 1 , a step flowchart of a data processing method for a vehicle bus provided by an embodiment of the present application is shown. It is applied to a vehicle first controller, and the vehicle first controller is communicatively connected to a control center. The data processing involves the vehicle first controller and the vehicle second controller communicatively connected based on the vehicle bus. Specifically, it may include the following steps:
[0073] Step 101: Obtain the first mask information sent by the control center.
[0074] Among them, the vehicle bus is a communication system for data communication between various electronic control units inside the vehicle, similar to the bus in a computer network, allowing information sharing between different controllers and sensors. The main function of the vehicle bus is to achieve data exchange between various controllers inside the vehicle, such as engine control, braking system, dashboard display, etc. The vehicle first controller refers to an electronic control unit in the vehicle bus system, responsible for executing specific vehicle control functions. It communicates with other controllers (such as the vehicle second controller) through the vehicle bus. The vehicle first controller may be responsible for tasks such as engine control, transmission control, and body electronics system. The vehicle second controller is another electronic control unit in the vehicle bus system, communicating with the vehicle first controller through the vehicle bus. The vehicle second controller may be responsible for different vehicle functions, such as the braking system, steering system, and air conditioning system. The control center may refer to the central control system inside the vehicle or the control center or data center outside the vehicle. The control center outside the vehicle may refer to a central control system located outside the vehicle, responsible for monitoring, managing, and controlling vehicle functions. The control center outside the vehicle may be an independent device, server, or cloud platform for communicating and interacting with the vehicle. The first mask information refers to a series of binary digits. For example, the first mask information may be 1111000000000000. In the embodiments of the present application, the first mask information (Mask Information) is used to encrypt the data that the vehicle first controller needs to send.
[0075] In some embodiments of this embodiment, when the vehicle's first controller sends data to the vehicle's second controller, the data can be encrypted by the first mask information, and the encrypted data is sent to the vehicle's second controller via the vehicle bus to improve data security.
[0076] Step 102: In response to a trigger event, determine the first plaintext communication data to be sent, and encrypt the first plaintext communication data according to the first mask information to obtain the first ciphertext communication data.
[0077] Among them, the trigger event refers to the condition or signal that causes a certain operation or process to start. In the vehicle bus communication system, the trigger event may be a certain state change, sensor data reaching a threshold, user operation, or other external signals. In this application, the trigger event is used to start the data processing flow and generate the plaintext communication data to be sent. Plaintext communication data is the basis of communication, but if the plaintext communication data is directly used for transmission during the transmission process, it may cause data loss or be maliciously stolen. Encrypting the plaintext communication data is used to protect the confidentiality and integrity of the communication data and prevent data leakage or malicious attacks. Ciphertext communication data refers to the data after encryption processing and cannot be directly read or understood.
[0078] In some embodiments of this embodiment, the first plaintext communication data refers to the unencrypted original communication data sent by the vehicle's first controller as the data sender. It can be directly read or understood. Specifically, it can be a control instruction, sensor data, or other information that needs to be transmitted in the network. The first ciphertext communication data refers to the encrypted data obtained by encrypting the first plaintext communication data or part of the data in the first plaintext communication data, which is used to ensure that the data will not be stolen or tampered with during the transmission process.
[0079] Step 103: Insert the first ciphertext communication data into the first plaintext communication data to obtain the target communication data.
[0080] Among them, the target communication data refers to the final communication data after processing.
[0081] In some embodiments of this embodiment, the target communication data refers to the data obtained by inserting the first ciphertext communication data into the first plaintext communication data. Therefore, in this application, the target communication data includes plaintext communication data and ciphertext communication data, which are mixed in a certain way, that is, the target communication data includes sensitive information that needs to be encrypted and protected and ordinary information that does not need to be encrypted.
[0082] Step 104: Transmit the target communication data to the vehicle's second controller via the vehicle bus.
[0083] As can be seen from the above, the main function of the vehicle bus is to realize data exchange between various controllers inside the vehicle, such as engine control, transmission control, braking system, dashboard display, etc.
[0084] In this application, by transmitting the target communication data to the vehicle second controller through the vehicle bus, data exchange and collaborative work between various controllers inside the vehicle can be realized.
[0085] In some embodiments of this embodiment, the vehicle bus uses a CANXL (Controller Area Network Extended Limits) bus to replace the traditional CAN / CANFD (Controller Area Network Flexible Data-Rate, an extended version of the CAN bus) bus to achieve high-speed transmission and large-data transmission of the vehicle bus.
[0086] In the embodiment of this application, by obtaining the first mask information sent by the control center, in response to a trigger event, determining the first plaintext communication data to be sent, encrypting the first plaintext communication data according to the first mask information to obtain the first ciphertext communication data, inserting the first ciphertext communication data into the first plaintext communication data to obtain the target communication data, and transmitting the target communication data to the vehicle second controller through the vehicle bus, the secure transmission of communication data between vehicle controllers is ensured.
[0087] Refer to Figure 2 , which shows the step flowchart of another data processing method for a vehicle bus provided by an embodiment of this application, and specifically may include the following steps:
[0088] Step 201: Obtain the first mask information sent by the control center;
[0089] Step 202: In response to a trigger event, determine the first plaintext communication data to be sent, perform a hash calculation on the first mask information and the first communication identification information to obtain a first data identification, and perform a hash calculation on the first payload data and the first data identification to obtain the first ciphertext communication data;
[0090] Among them, step 201 is the same as step 101 and will not be elaborated here. In some embodiments of the present application, the first plaintext communication data includes first communication identification information and first payload data. The first communication identification information is used to distinguish different communication messages, ensure that the messages can be correctly transmitted and processed, and the communication identification information can also help the receiving party identify the purpose and processing method of the message. The first payload data is the core content of the communication and is the effective data part actually carried in the first plaintext communication data. The first payload data can be sensor readings, control instructions, status information, etc., and can be specifically reflected in the DATA part of the first plaintext communication data.
[0091] In some embodiments of this embodiment, the first communication identification information in the first plaintext communication data refers to the unique communication identifier carried when the first vehicle controller sends data to the second vehicle controller. For example, the first vehicle controller is an ECU (Electronic Control Unit) of the vehicle, assumed to be ECU1, and the second vehicle controller is another ECU in the vehicle, assumed to be ECU2. When ECU1 sends data to ECU2, the first communication identification information can be ID 12 .
[0092] Perform a hash calculation on the first mask information and the first communication identification information to obtain a first data identifier. Continuing with the above example, assume that the first mask information used by the first vehicle controller ECU1 when sending data to ECU2 obtained from the control center is MASK1_2, and the first communication identification information when ECU1 sends data to ECU2 is ID 1_2 , and the first payload data in the first plaintext communication data to be sent is DATA1. First, the first mask information MASK1_2 and the first communication message identifier ID 1_2 can be subjected to a first hash algorithm to obtain a first data identifier HASH1, and then the first payload data DATA1 to be sent and the first data identifier HASH1 are subjected to a second hash algorithm to obtain the first ciphertext communication data HASH11.
[0093] Among them, the first hash algorithm and the second hash algorithm can be the same hash algorithm or different hash algorithms. In specific implementation, the hash algorithm can be a second-generation hash algorithm. The second-generation hash algorithm is designed to be collision-resistant, making it difficult to find two different inputs that produce the same hash value, and some second-generation hash algorithms consider the threat of quantum computing and are designed to be quantum-resistant. SHA-2 (including SHA-256 and SHA-512) is a typical representative of the second-generation hash algorithm, with output lengths of 256 bits and 512 bits respectively, and has relatively high security. No effective collision attacks have been found yet.
[0094] Step 203: Obtain the first encrypted interleaved information sent by the control center, and determine the first target position of the first payload data based on the first encrypted interleaved information.
[0095] Among them, the first encrypted interleaved information is used to ensure that the ciphertext communication data can be correctly embedded into the target position of the payload data, so as to form the target communication data.
[0096] In some embodiments of this embodiment, the first encrypted interleaved information may include the mapping relationship between the first communication identification information and the first target position. Since the first communication identification information is unique, therefore, it is possible to determine which position of the first payload data in the first plaintext communication data needs to insert the first ciphertext communication data according to the first communication identification information, that is, to determine the first target position of the first payload data. In addition, the first encrypted interleaved information may also include the insertion method, encryption algorithm parameters, etc. In a specific implementation, the control center can set the complexity of the first encrypted interleaved information and the second encrypted interleaved information in the following text according to actual needs. For example, the higher the data security requirement between the first vehicle controller and the second vehicle controller, the higher the complexity of generating the first encrypted interleaved information, and the higher the security of the target communication data transmission, and the more difficult it is to be cracked.
[0097] Step 204: Insert the first ciphertext communication data into the first target position of the first payload data to obtain the target communication data.
[0098] Suppose the first payload data DATA1 is a data with a length of 100 bytes. According to the first encrypted interleaved information, the first target position of the first payload data is the 32nd byte from high to low of the first payload data. Then, the first ciphertext communication data HASH11 obtained in the previous step needs to be inserted at the 32nd byte of the first payload data DATA1 to obtain the final target communication data for sending.
[0099] Step 205: Transmit the target communication data to the second vehicle controller through the vehicle bus.
[0100] In some embodiments of this embodiment, after inserting the first ciphertext communication data HASH11 into the specified position of the first payload data DATA1 in the previous step to obtain DATA11, that is, to obtain the target communication data, and transmit the target communication data to the second vehicle controller through the vehicle bus. By interleaving the first ciphertext communication data in the first plaintext communication data, attackers cannot identify which are the real valid data; using the hash algorithm, the risk of data leakage and being cracked is eliminated, and through two hash algorithms, attackers cannot use simple decryption combinations to crack the encrypted information, further improving data security.
[0101] In some embodiments of the present application, the vehicle bus is a third-generation Controller Area Network Protocol bus, namely the CANXL bus. The maximum transmission rate of the traditional CAN bus is 1 Mbps, while the CANXL bus adopted in the present application can support a higher transmission rate, up to 10 Mbps, enabling the vehicle bus to handle more data volume and meet the growing demands of sensors and controllers in modern vehicles; the maximum data frame of the CAN bus is 8 bytes, while CANXL supports a larger data frame length, up to 2048 bytes, enabling CANXL to transmit more complex data packets, such as high-resolution sensor data, image data, or complex control instructions. In addition, the CANXL adopted in the present application takes into account the compatibility with the traditional CAN bus during design and can coexist with traditional CAN devices in the same network. CANXL can transmit data more efficiently and reduce communication latency. As the complexity of automotive electronic systems increases, such as autonomous driving, Advanced Driver Assistance Systems (ADAS), and in-vehicle entertainment systems, CANXL can better support these applications.
[0102] In an embodiment of the present application, by obtaining the first mask information sent by the control center, in response to a trigger event, determining the first plaintext communication data to be sent, encrypting the first plaintext communication data according to the first mask information to obtain the first ciphertext communication data, inserting the first ciphertext communication data into the first plaintext communication data to obtain the target communication data, and transmitting the target communication data to the vehicle second controller via the vehicle bus. The vehicle bus adopts the third-generation Controller Area Network Protocol bus, realizing high-rate data transmission. By interspersing the first ciphertext communication data in the first plaintext communication data, attackers cannot identify the real valid data; using the hash algorithm, the risk of data leakage being cracked is eliminated, and through two hash algorithms, attackers cannot use simple decryption combinations to crack the encrypted information, further enhancing the security of the transmitted data.
[0103] Refer to Figure 3 , which shows the step flowchart of another vehicle bus data processing method provided by an embodiment of the present application, applied to the vehicle second controller. The vehicle second controller is communicatively connected to the control center. The data processing involves the vehicle first controller and the vehicle second controller communicatively connected via the vehicle bus, and specifically may include the following steps:
[0104] Step 301: Obtain the second mask information sent by the control center.
[0105] Among them, the second mask information is obtained by the vehicle second controller from the control center, and the vehicle second controller uses the second mask information to verify the communication data sent by the first vehicle controller.
[0106] Step 302: When receiving the target communication data sent by the first vehicle controller via the vehicle bus, determine the second plaintext communication data and the second ciphertext communication data from the target communication data.
[0107] As can be seen from the foregoing embodiments, in order to ensure that the data is not maliciously tampered with, the first vehicle controller inserts the first ciphertext communication data into the first plaintext communication data to obtain the target communication data, and sends the obtained target communication data to the second controller.
[0108] When the second controller receives the target communication data sent by the first vehicle controller, it needs to determine the plaintext communication data and the ciphertext communication data therein from the received data. The determined plaintext communication data is called the second plaintext communication data, and the determined ciphertext communication data is called the second ciphertext communication data. If the target communication data received by the second vehicle controller indeed originates from the first vehicle controller and the target communication data is not tampered with during the transmission process, the second plaintext communication data and the first plaintext communication data should be the same, and the second ciphertext communication data and the first ciphertext communication data should also be the same. If the target communication data received by the second vehicle controller is tampered with during the transmission process, the second plaintext communication data is inconsistent with the first plaintext communication data sent by the first vehicle controller, and the second ciphertext communication data is also inconsistent with the first ciphertext communication data.
[0109] In some implementation manners of this embodiment, different data senders (i.e., different first vehicle controllers) correspond to different mask information in the second vehicle controller. Suppose there are ECU1, ECU3, and ECU5 in the first vehicle controller, and there are ECU2, ECU4, and ECU6 in the second vehicle controller. When the second vehicle controller ECU2 verifies the data sent by the first vehicle controller ECU1, the second mask information used is MASK1_2. When the second vehicle controller verifies the data sent by the first vehicle controller ECU3, the second mask information used is MASK3_2. When the second vehicle controller verifies the data sent by the first vehicle controller ECU5, the second mask information used is MASK5_2. Therefore, the first mask information that the first vehicle controller may obtain from the control center includes MASK1_2, MASK1_4, and MASK1_6. The second vehicle controller obtains not only the second mask information MASK1_2 from the control center, but also multiple other second mask information such as MASK3_2 and MASK5_2. It should be noted that the first mask information used when the first vehicle controller ECU1 sends data to the second vehicle controller ECU2 is the same as the second mask information used when the second vehicle controller receives data from the first vehicle controller, both of which are MASK1_2.
[0110] Step 303: Encrypt the second plaintext communication data according to the second mask information to obtain encrypted verification data.
[0111] Continuing with the above example, in order to verify the communication data sent by the vehicle's first controller ECU1, at the vehicle's second controller ECU2, the second plaintext communication data needs to be encrypted first using the second mask information MASK1_2 to obtain encrypted verification data, preparing for the subsequent verification process for data verification.
[0112] Step 304: Process the second plaintext communication data when it is determined that the encrypted verification data is consistent with the second ciphertext communication data.
[0113] Only when it is determined that the encrypted verification data for data verification is exactly the same as the second ciphertext communication data determined from the target communication data can it be determined that the received target communication data is indeed sent from the vehicle's first controller ECU1 to the vehicle's second controller ECU2 and the target communication data has not been maliciously tampered with. At this time, the split plaintext communication data will be processed; if they are inconsistent, the communication data needs to be discarded, and it can also be further determined whether the communication data is lost.
[0114] In the embodiment of the present application, the vehicle's second controller obtains the second mask information sent by the control center. When receiving the target communication data sent by the vehicle's first controller through the vehicle bus, the second plaintext communication data and the second ciphertext communication data are determined from the target communication data. The second plaintext communication data is encrypted according to the second mask information to obtain encrypted verification data. When it is determined that the encrypted verification data is consistent with the second ciphertext communication data, the second plaintext communication data is processed to ensure the identity authentication of both communication parties and the secure transmission of communication data.
[0115] Refer to Figure 4 , which shows the step flowchart of another data processing method for a vehicle bus provided by an embodiment of the present application, applied to the vehicle's second controller. The vehicle's second controller is communicatively connected to the control center. The data processing involves the vehicle's first controller and the vehicle's second controller communicatively connected based on the vehicle bus. Specifically, it may include the following steps:
[0116] Step 401: Obtain the second mask information sent by the control center.
[0117] Step 402: When receiving the target communication data sent by the vehicle's first controller through the vehicle bus, determine the second plaintext communication data and the second ciphertext communication data from the target communication data.
[0118] Among them, step 401 is the same as the aforementioned step 301 and will not be elaborated here.
[0119] In some embodiments of the present application, the target communication data includes second payload data. The step of "determining the second plaintext communication data and the second ciphertext communication data from the target communication data" in step 402 includes the following sub-steps:
[0120] Sub-step 11: Obtain the second encryption interleaving information sent by the control center, and determine the second target position of the second payload data from the second encryption interleaving information.
[0121] Sub-step 12: Split the target communication data according to the second target position of the second payload data to obtain the second plaintext communication data and the second ciphertext communication data.
[0122] As can be seen from the foregoing, in order to ensure that the data is not maliciously tampered with, when the second controller receives the target communication data sent by the first vehicle controller, it is necessary to verify the target communication data. Then, the second vehicle controller needs to obtain the second encryption interleaving information pre-generated by the control center for the first vehicle controller to send data to the second vehicle controller. The second encryption interleaving information can be obtained at any time before the first vehicle controller and the second vehicle controller perform data communication. The second encryption interleaving information includes the second target position of the second payload data in the target communication data. Assume that the first payload data part in the first plaintext communication data to be sent by the first vehicle controller is 100-byte long data. The first ciphertext communication data is inserted at the 32nd byte of the first payload data part (i.e., the first target position in the foregoing content) to obtain the target communication data. Then, the second vehicle controller needs to split the target communication data starting from the 32nd byte of the second payload data to obtain the second plaintext communication data and the second ciphertext communication data. It should be noted that the second payload data is different from the first payload data. The first ciphertext communication data is inserted at the first target position of the first payload data to obtain the second payload data. It is not difficult to understand that the second plaintext communication data includes payload information, which is called the third payload information. If the target communication data is not tampered with during transmission, the third payload data should be the same as the first payload data. In a specific implementation, the second encryption interleaving information can be a one-to-one mapping relationship between the second communication identification information and the second target position.
[0123] For example, the second vehicle controller receives the target communication data from the first vehicle controller. Assume that the second target position of the second payload data is the 32nd byte. If the length of the first ciphertext communication data is fixed at 256 bits, then 256 bits are intercepted from the 32nd byte from high to low of the second payload data in the target communication data. The obtained 256-bit data is the second ciphertext communication data, and the other remaining parts are combined to form the second plaintext communication data. The second plaintext communication data includes the second communication identification information and the third payload data.
[0124] Step 403: Perform a hash calculation on the second mask information and the second communication identification information to obtain a second data identifier.
[0125] In some embodiments of this embodiment, the vehicle's second controller uses the second mask information and the second communication identification determined in the foregoing steps to perform a hash algorithm to obtain a second data identifier.
[0126] Step 404: Perform a hash calculation on the third payload data and the second data identifier to obtain encrypted verification data.
[0127] In some embodiments of this embodiment, the second data identifier obtained in step 403 and the third payload data are again subjected to a hash algorithm to obtain encrypted verification data. Continuing with the example in Embodiment 2, if the target communication data is not tampered with during transmission, the second ciphertext communication data and the first ciphertext communication data split by the vehicle's second controller are the same, both being HASH11. The second communication message identifier in the second plaintext communication data split from the target communication data is ID1_2. The vehicle's second controller selects the second mask information MASK1_2 corresponding to the second communication identification information ID1_2, and calculates the second data identifier HASH2 by performing a hash algorithm on MASK1_2 and ID1_2; the second data identifier HASH2 and the third payload data DATA2 in the second plaintext data are subjected to a hash calculation to obtain encrypted verification data HASH22; compare whether the value of the encrypted verification data HASH22 is the same as the value of the second ciphertext communication data HASH11 split. If the target communication data is not tampered with during transmission and the second mask information used is the same as the first mask information, then HASH22 and HASH11 are the same. If the target communication data is tampered with during transmission, or the second mask information used by the vehicle's second controller is inconsistent with the first mask information, then the encrypted verification data HASH22 and the second ciphertext communication data HASH11 split must be different.
[0128] Step 405: Process the plaintext communication data when it is determined that the encrypted verification data is consistent with the second ciphertext communication data.
[0129] In some embodiments of this embodiment, compare whether the value of the encrypted verification data obtained in step 404 is the same as the value of the second ciphertext communication data split in step 401. If the values are the same, it indicates a valid message and proceed to the next step of processing. If they are different, the received target communication data can be discarded.
[0130] In the embodiment of the present application, the vehicle second controller obtains the second mask information sent by the control center. When receiving the target communication data sent by the vehicle first controller through the vehicle bus, the second plaintext communication data and the second ciphertext communication data are determined from the target communication data. The second plaintext communication data is encrypted according to the second mask information to obtain encrypted verification data. When it is determined that the encrypted verification data is consistent with the second ciphertext communication data, the second plaintext communication data is processed to ensure the identity authentication of both communication parties and the secure transmission of communication data.
[0131] Referring to Figure 5 , the flowchart of the steps of another data processing method for a vehicle bus provided by an embodiment of the present application is shown, which is applied to a control center. The control center is communicatively connected to the vehicle first controller and the vehicle second controller, and specifically may include the following steps:
[0132] Step 501: Obtain the interaction information on the vehicle bus.
[0133] In some embodiments of this embodiment, the communication interaction information on the CANXL bus is obtained. The communication interaction information specifically refers to the CANXL communication matrix. The CANXL communication matrix is a table or document used to describe the communication relationships and data transmission rules between various nodes (such as controllers, sensors, actuators, etc.) in the CANXL bus communication system. It defines which nodes can communicate with each other, the communication frequency, data type, priority, and the physical layer and protocol layer configurations of the communication. Among them, the node information lists all the nodes participating in the communication (such as controllers, sensors, actuators, etc.); the communication relationship defines which nodes can communicate with each other and the communication direction (send or receive); the data type describes the data type of each communication message (such as control instructions, sensor data, status information, etc.); the communication frequency defines the sending frequency of each communication message; the priority defines the priority of each communication message to ensure that high-priority messages can be transmitted first; the physical layer and protocol layer configurations describe the physical layer (such as transmission rate, voltage level, etc.) and protocol layer (such as data frame format, error detection mechanism, etc.) configurations of the CANXL bus.
[0134] Step 502: Determine the target communication message from the interaction information.
[0135] In some embodiments of this embodiment, the CANXL communication matrix is sorted out, the relevant data is fused, and the important message data or the data that needs to be protected is screened out as the target communication message.
[0136] Step 503: Determine the vehicle first controller and the vehicle second controller corresponding to the target communication message.
[0137] In some embodiments of the present embodiment, after screening out important message data or data to be protected as target communication messages, it is necessary to confirm the two parties of the communication, that is, the vehicle first controller and the vehicle second controller corresponding to the target communication message, to prepare for data encryption and data verification during data communication between the two.
[0138] Step 504: Generate first mask information and second mask information.
[0139] Step 505: Send the first mask information to the vehicle first controller, so that when the vehicle first controller sends the first plaintext communication data to the vehicle second controller, encrypt the first plaintext communication data according to the first mask information to obtain the first ciphertext communication data.
[0140] Step 506: Send the second mask information to the vehicle second controller, so that when the vehicle second controller receives the target communication data sent by the vehicle first controller, process the target communication data according to the second mask information.
[0141] After determining the vehicle first controller and the vehicle second controller, the control center needs to formulate mask information required for the authentication process of the two communication parties.
[0142] In some embodiments of the present embodiment, a unique and independent multi-byte mask information can be assigned to each component (such as the vehicle first controller, the vehicle second controller, etc.), ensuring that the mask information of each component is numerically different and avoiding duplication. The length of the mask information can be set according to security requirements (such as 16 bits, 32 bits, etc.). There are various ways to generate the mask information. For example, the mask information can be generated according to the communication identifier of the target communication message. The generation method of the mask can be to set the high (or low) bits of the communication identifier to 1, indicating that these bits need to be strictly matched, and set the other bits of the communication identifier to 0, indicating that these bits can be ignored. For example, if the communication identifier is 1010101010101010, the mask can be generated as 1111000000000000, that is, the high 4 bits are 1 and the rest are 0. Another example is that a random number 1100110011001100 can be generated based on the timestamp or device status, and the generated mask is 1100110000000000 (the high 8 bits are the high 8 bits of the random number and the rest are 0). The specific generation method can be adjusted according to the actual situation.
[0143] Send the generated first mask information to the vehicle's first controller and the generated second mask information to the vehicle's second controller. For example, the first mask information used by the vehicle's first controller to send data to the vehicle's second controller can be sent to the vehicle's first controller, and the second mask information required by the vehicle's second controller to verify the data sent by the vehicle's first controller can be sent to the vehicle's second controller. At this time, the first mask information and the second mask information are the same binary digits, such as 1111000000000000. When the vehicle's first controller sends the first plaintext communication data to the vehicle's second controller, the first mask information is used to encrypt the first plaintext communication data to obtain the first ciphertext communication data. The vehicle's second controller uses the second mask information for verification when receiving the target communication data from the vehicle's first controller.
[0144] It should be noted that the control center will also generate the first mask information required for encrypting the data sent by the vehicle's second controller to the vehicle's first controller, and will also generate the second mask information required for the vehicle's first controller to verify the data sent by the vehicle's second controller. At this time, the first mask information and the second mask information are the same binary digits, such as 1100110000000000. Since both the vehicle's first controller and the vehicle's second controller have the mask information of the other party, encryption operations or verification operations can be performed whether sending or receiving data. It should be noted that the control center also needs to send multiple other first mask information to the vehicle's first controller and multiple other second mask information to the vehicle's second controller.
[0145] In some implementation manners of this embodiment, the control center only distributes the first mask information or the second mask for the two parties that need to communicate (such as the vehicle's first controller and the vehicle's second controller). To ensure that the mask information is not stolen, the mask information here includes the first mask information and the second mask information, and an encrypted secure channel can be used to send the mask information, and a secure channel is established between the vehicle's first controller, the vehicle's second controller, and the control center. For example, security protocols such as TLS (Transport Layer Security), IPsec (Internet Protocol Security), or CAN-TP (Controller Area Network Transport Protocol) are used to establish a secure channel between the control center and each vehicle controller.
[0146] In some embodiments of the present embodiment, the mask information can also be updated regularly to prevent the mask information from being tampered with and ensure the integrity of communication. For example, the update can be triggered according to a preset time, setting a fixed time interval (such as monthly or quarterly) to regularly generate new mask information. The update can also be triggered by an event. For example, when a security threat (such as mask information leakage) is detected, the update of the mask information is immediately triggered. Specifically, the control center generates new mask information, sends an update notification to each vehicle controller that needs to be updated through a secure channel, and distributes it to each vehicle controller through the secure channel. After receiving the new mask information, the vehicle controller updates the mask information stored locally.
[0147] In some embodiments of the present application, after step 506, the following steps may further be included:
[0148] S1: Generate first encrypted interleaved information and second encrypted interleaved information.
[0149] S2: Send the first encrypted interleaved information to the first vehicle controller, so that the first vehicle controller inserts the first ciphertext communication data into the first plaintext communication data according to the first encrypted interleaved information to obtain target communication data;
[0150] S3: Send the second encrypted interleaved information to the second vehicle controller, so that the second vehicle controller splits the target communication data according to the second encrypted interleaved information to obtain second plaintext communication data and second ciphertext communication data.
[0151] To improve data security, the control center can also generate corresponding first encrypted interleaved information and second encrypted interleaved information for the vehicle's first controller and the vehicle's second controller. When the vehicle's first controller sends data to the vehicle's second controller, the first encrypted interleaved information can be used to insert the generated first ciphertext communication data into the first plaintext communication data to obtain the target communication data finally used for transmission on the vehicle bus. When the vehicle's second controller receives the target communication data sent by the vehicle's first controller from the vehicle bus, the second encrypted interleaved information is used to split the target communication data. For example, the first encrypted interleaved information can be set such that when the first payload data in the first plaintext communication data is 100-byte long, the first ciphertext communication data is inserted at the 32nd byte of the first payload data to obtain the target communication data. Then, when the vehicle's second controller receives the target communication data from the vehicle's first controller, it needs to intercept the 32nd bit of the second payload data in the target communication data. Assuming the first ciphertext communication data is 256 bits, 256 bits are intercepted backward from the 32nd bit of the second payload data. These 256 bits of data are the second ciphertext communication data split, and the other part of the data is combined to form the second plaintext data. The payload data in the second plaintext data is the third payload data. Another example is that the first encrypted interleaved information can be set such that when the first payload data in the first plaintext communication data is 200-byte long, the first ciphertext communication data is inserted at the 96th byte of the first payload data. Assuming the length of the first ciphertext communication data is still 256 bits, the vehicle's second controller needs to intercept 256 bits backward from the 96th bit of the second payload data in the target communication data to obtain the second ciphertext communication data and the second plaintext communication data. In specific implementation, the control center can set the complexity of the first encrypted interleaved information and the second encrypted interleaved information according to actual needs.
[0152] In the embodiment of this application, by obtaining the interaction information on the vehicle bus, determining the target communication message from the interaction information, determining the vehicle's first controller and the vehicle's second controller corresponding to the target communication message, generating the first mask information and the second mask information, sending the first mask information to the vehicle's first controller, so that when the vehicle's first controller sends the first plaintext communication data to the vehicle's second controller, encrypt the first plaintext communication data according to the first mask information to obtain the first ciphertext communication data; send the second mask information to the vehicle's second controller, so that when the vehicle's second controller receives the target communication data sent by the vehicle's first controller, process the target communication data according to the second mask information, which ensures the identity authentication of both communication parties of the vehicle's first controller and the vehicle's second controller and the secure transmission of communication data, improves the in-vehicle network communication performance and security, and ensures the secure and reliable transmission of important data.
[0153] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the embodiments of the present application are not limited by the described action sequences, because according to the embodiments of the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present application.
[0154] Referring to Figure 6 , a schematic structural diagram of a data processing device for a vehicle bus provided by an embodiment of the present application is shown. It is applied to a vehicle first controller, and the vehicle first controller is communicatively connected to a control center. Data processing involves the vehicle first controller and the vehicle second controller communicatively connected based on the vehicle bus, and specifically may include the following modules:
[0155] A first mask acquisition module 601, configured to acquire first mask information sent by the control center;
[0156] A first encryption module 602, configured to, in response to a trigger event, determine first plaintext communication data to be sent, and encrypt the first plaintext communication data according to the first mask information to obtain first ciphertext communication data;
[0157] A data insertion module 603, configured to insert the first ciphertext communication data into the first plaintext communication data to obtain target communication data;
[0158] A data sending module 604, configured to transmit the target communication data to the vehicle second controller through the vehicle bus.
[0159] In an alternative embodiment of the present application, the first plaintext communication data includes first communication identification information and first payload data. The first encryption module 602 includes:
[0160] A first encryption sub-module, configured to perform a hash calculation on the first mask information and the first communication identification information to obtain a first data identifier;
[0161] A second encryption sub-module, configured to perform a hash calculation on the first payload data and the first data identifier to obtain the first ciphertext communication data.
[0162] In an alternative embodiment of the present application, the data insertion module 603 includes:
[0163] A first insertion sub-module, configured to acquire first encryption interleaving information sent by the control center, and determine a first target position of the payload data according to the first encryption interleaving information;
[0164] A second insertion sub-module, configured to insert the first ciphertext communication data into a first target position of the first payload data to obtain target communication data.
[0165] In an alternative embodiment of the present application, the vehicle bus is a third-generation Controller Area Network (CAN) protocol bus.
[0166] Referring to Figure 7 , a schematic structural diagram of another data processing device for a vehicle bus provided by an embodiment of the present application is shown. The device is applied to a second vehicle controller, which is communicatively connected to a control center. Data processing involves a first vehicle controller and a second vehicle controller communicatively connected based on the vehicle bus, and specifically may include the following modules:
[0167] A second mask acquisition module 701, configured to acquire second mask information sent by the control center;
[0168] A data reception module 702, configured to determine second plaintext communication data and second ciphertext communication data from the target communication data when receiving the target communication data sent by the first vehicle controller through the vehicle bus;
[0169] A second encryption module 703, configured to encrypt the second plaintext communication data according to the second mask information to obtain encrypted verification data;
[0170] A data verification module 704, configured to process the second plaintext communication data when determining that the encrypted verification data is consistent with the second ciphertext communication data.
[0171] In an alternative embodiment of the present application, the target communication data includes second payload data, and the data reception module 702 includes:
[0172] A position determination sub-module, configured to acquire second encryption interleaving information sent by the control center and determine a second target position of the second payload data from the second encryption interleaving information;
[0173] A data splitting sub-module, configured to split the target communication data according to the second target position of the second payload data to obtain the second plaintext communication data and the second ciphertext communication data.
[0174] In an alternative embodiment of the present application, the second plaintext communication data further includes second communication identification information and third payload information, and the second encryption module 703 includes:
[0175] The third encryption sub-module is configured to perform a hashing calculation on the second mask information and the second communication identification information to obtain a second data identifier;
[0176] The fourth encryption sub-module is configured to perform a hashing calculation on the third payload data and the second data identifier to obtain the encrypted verification data.
[0177] Refer to Figure 8 , which shows a schematic structural diagram of another data processing device for a vehicle bus provided by an embodiment of the present application, applied to a control center. The control center is communicatively connected to a vehicle first controller and a vehicle second controller, and may specifically include the following modules:
[0178] The interaction information acquisition module 801 is configured to acquire the interaction information on the vehicle bus;
[0179] The screening module 802 is configured to determine a target communication message from the interaction information;
[0180] The target determination module 803 is configured to determine the vehicle first controller and the vehicle second controller corresponding to the target communication message;
[0181] The mask generation module 804 is configured to generate first mask information and second mask information;
[0182] The first sending module 805 is configured to send the first mask information to the vehicle first controller, so that when the vehicle first controller sends the first plaintext communication data to the vehicle second controller, encrypt the first plaintext communication data according to the first mask information to obtain first ciphertext communication data;
[0183] The second sending module 806 is configured to send the second mask information to the vehicle second controller, so that when the vehicle second controller receives the target communication data sent by the vehicle first controller, process the target communication data according to the second mask information.
[0184] In an alternative embodiment of the present application, the device further includes:
[0185] The interleaved information generation module is configured to generate first encrypted interleaved information and second encrypted interleaved information;
[0186] The third sending module is configured to send the first encrypted interleaved information to the vehicle first controller, so that the vehicle first controller inserts the first ciphertext communication data into the first plaintext communication data according to the first encrypted interleaved information to obtain target communication data;
[0187] A fourth sending module, configured to send the second encrypted interleaved information to the second vehicle controller, so that the second vehicle controller splits the target communication data according to the second encrypted interleaved information to obtain the second plaintext communication data and the second ciphertext communication data.
[0188] An embodiment of the present application further provides a vehicle, which may include one or more processors; and
[0189] One or more memories storing instructions, and the instructions stored in the memories are readable, compiled and executable by the processors to implement the data processing method of the vehicle bus as described above.
[0190] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the data processing method of the vehicle bus as described above is implemented.
[0191] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, refer to the partial description of the method embodiment.
[0192] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data need to comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entrances are provided for the user to choose to authorize or refuse.
[0193] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to describe the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.
[0194] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0195] Embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a device for implementing the functions specified in multiple blocks.
[0196] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or the functions specified in multiple blocks.
[0197] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, such that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or the functions specified in multiple blocks.
[0198] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application.
[0199] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the above elements.
[0200] The above has introduced in detail the data processing method, apparatus and vehicle provided. In this text, specific examples are used to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A data processing method for a vehicle bus, characterized in that: Applied to a first vehicle controller, the first vehicle controller is communicatively connected to a control center, data processing involves the first vehicle controller and a second vehicle controller communicatively connected based on the vehicle bus, the method comprising: Acquire first mask information sent by the control center; In response to a triggering event, determining first plaintext communication data to be sent, and encrypting the first plaintext communication data according to the first mask information to obtain first ciphertext communication data; Inserting the first ciphertext communication data into the first plaintext communication data to obtain target communication data; The target communication data is transmitted to the second vehicle controller via the vehicle bus.
2. The method according to claim 1, characterized in that The first plaintext communication data includes first communication identification information and first payload data, and the first plaintext communication data is encrypted according to the first mask information to obtain first ciphertext communication data, including: Performing a hash calculation on the first mask information and the first communication identification information to obtain a first data identification; A hash calculation is performed on the first payload data and the first data identifier to obtain the first ciphertext communication data.
3. The method according to claim 2, characterized in that The inserting the first ciphertext communication data into the first plaintext communication data to obtain target communication data includes: Acquire the first encrypted interleaved information sent by the control center, and determine the first target position of the first payload data according to the first encrypted interleaved information; Insert the first ciphertext communication data into the first target position of the first payload data to obtain target communication data.
4. The method according to any one of claims 1 to 3, characterized in that: The vehicle bus is a third generation controller area network protocol bus.
5. A vehicle bus data processing method, characterized in that: Applied to a second vehicle controller, the second vehicle controller is communicatively connected to a control center, data processing involves a first vehicle controller and the second vehicle controller which are communicatively connected based on the vehicle bus, the method comprising: Acquire the second mask information sent by the control center; Upon receiving target communication data sent by the first vehicle controller via the vehicle bus, determining second plaintext communication data and second ciphertext communication data from the target communication data; Encrypting the second plaintext communication data according to the second mask information to obtain encrypted verification data; When it is determined that the encrypted verification data is consistent with the second ciphertext communication data, the second plaintext communication data is processed.
6. The method according to claim 5, characterized in that The target communication data includes second payload data, and determining the second plaintext communication data and the second ciphertext communication data from the target communication data includes: Acquire the second encrypted interspersed information sent by the control center, and determine the second target position of the second payload data from the second encrypted interspersed information; The target communication data is split according to the second target position of the second payload data to obtain the second plaintext communication data and the second ciphertext communication data.
7. The method according to claim 6, characterized in that The second plaintext communication data further includes second communication identification information and third payload information, and the encrypting the second plaintext communication data according to the second mask information to obtain encrypted verification data includes: Performing a hash calculation on the second mask information and the second communication identification information to obtain a second data identification; A hash calculation is performed on the third payload data and the second data identifier to obtain the encrypted verification data.
8. A vehicle bus data processing method, characterized in that: Applied to a control center, the control center is in communication connection with a first vehicle controller and a second vehicle controller, the method comprising: Acquiring interaction information on the vehicle bus; Determining a target communication message from the interaction information; Determine the first vehicle controller and the second vehicle controller corresponding to the target communication message; generating first mask information and second mask information; Sending the first mask information to the first vehicle controller, so that when the first vehicle controller sends first plaintext communication data to the second vehicle controller, the first plaintext communication data is encrypted according to the first mask information to obtain first ciphertext communication data; The second mask information is sent to the second vehicle controller, so that the second vehicle controller processes the target communication data according to the second mask information when receiving the target communication data sent by the first vehicle controller.
9. The method according to claim 8, characterized in that The method further comprises: Generate first encrypted interleaved information and second encrypted interleaved information; Sending the first encrypted interspersed information to the first vehicle controller, so that the first vehicle controller inserts the first ciphertext communication data into the first plaintext communication data according to the first encrypted interspersed information to obtain target communication data; The second encrypted interspersed information is sent to the second controller of the vehicle, so that the second controller of the vehicle splits the target communication data according to the second encrypted interspersed information to obtain second plaintext communication data and second ciphertext communication data.
10. A data processing device for a vehicle bus, characterized in that: Applied to a first vehicle controller, the first vehicle controller is communicatively connected to a control center, data processing involves the first vehicle controller and a second vehicle controller based on the communication connection of the vehicle bus, the device comprises: A first mask acquisition module is configured to acquire first mask information sent by the control center; A first encryption module is configured to, in response to a trigger event, determine first plaintext communication data to be sent, and encrypt the first plaintext communication data according to the first mask information to obtain first ciphertext communication data; a data insertion module, configured to insert the first ciphertext communication data into the first plaintext communication data to obtain target communication data; The data sending module is configured to transmit the target communication data to the second vehicle controller through the vehicle bus.
11. A data processing device for a vehicle bus, characterized in that: Applied to a second vehicle controller, the second vehicle controller is communicatively connected to a control center, data processing involves a first vehicle controller and a second vehicle controller communicatively connected based on the vehicle bus, the device comprising: A second mask acquisition module is configured to acquire second mask information sent by the control center; a data receiving module configured to determine second plaintext communication data and second ciphertext communication data from the target communication data when receiving target communication data sent by the first controller of the vehicle through the vehicle bus; A second encryption module is configured to encrypt the second plaintext communication data according to the second mask information to obtain encrypted verification data; The data verification module is configured to process the second plaintext communication data when it is determined that the encrypted verification data is consistent with the second ciphertext communication data.
12. A data processing device for a vehicle bus, characterized in that: Applied to a control center, the control center is in communication connection with a first vehicle controller and a second vehicle controller, the device comprises: An interaction information acquisition module, configured to acquire interaction information on the vehicle bus; A screening module, configured to determine a target communication message from the interaction information; A target determination module, configured to determine the first vehicle controller and the second vehicle controller corresponding to the target communication message; A mask generating module, configured to generate first mask information and second mask information; A first sending module is configured to send the first mask information to the first vehicle controller, so that when the first vehicle controller sends first plaintext communication data to the second vehicle controller, the first plaintext communication data is encrypted according to the first mask information to obtain first ciphertext communication data; The second sending module is configured to send the second mask information to the second vehicle controller, so that the second vehicle controller processes the target communication data according to the second mask information when receiving the target communication data sent by the first vehicle controller.
13. A vehicle, characterized in that: include one or more processors; and One or more memories having instructions stored thereon, wherein the instructions stored in the memories can be read, compiled and executed by the processor to implement the method as described in any one of claims 1-4 or 5-7 or 8-9.
Citation Information
Cited By
Vehicle communication data encryption method, decryption method, device and system
CN120200857A
Vehicle communication data encryption method, decryption method, device and system
CN120200857B