Anti-counterfeiting node communication method and device, equipment and storage medium

By introducing the authorization and authentication mechanism of vehicle fault diagnosis equipment into the car cockpit control system, the risk of communication between IVI nodes and CGW being forged by hackers is solved, and the effect of improving system security is achieved.

CN120223334APending Publication Date: 2025-06-27SHANGHAI HECHENG TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311811825.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In modern car cockpit control systems, there is a risk of hacker forgery communication between IVI nodes and CGWs. Traditional solutions cannot effectively prevent the establishment of communication between the forged IVI nodes and CGWs, resulting in the security of the cockpit control system being threatened.

Method used

The authorized authentication protection of vehicle fault diagnosis equipment (such as after-sales diagnostic instrument) is established in advance through the central gateway and multiple vehicle data nodes (such as IVI nodes). Based on the notification status of the vehicle fault diagnosis equipment, whether the central gateway is allowed to communicate with the target vehicle data node to prevent the forged target vehicle data node from being allowed to communicate.

Benefits of technology

It effectively prevents hacker intrusion and the establishment of illegal communication, improves the security of the cockpit control system, and ensures that only authorized nodes can communicate with the central gateway.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223334A_ABST
    Figure CN120223334A_ABST
Patent Text Reader

Abstract

The invention provides an anti-fake node communication method, device and equipment and a storage medium, and relates to the technical field of Ethernet communication, and the method comprises the steps: building a communication connection between a central gateway and authorized vehicle fault diagnosis equipment, and receiving an authorization notice that safety verification passes; establishing a communication connection between the central gateway and the vehicle-mounted data node based on an address resolution protocol so as to obtain an authorized target vehicle-mounted data node; prohibiting or allowing the central gateway to communicate with the target vehicle-mounted data node according to the notification state of the vehicle fault diagnosis equipment; wherein the target vehicle-mounted data node comprises a forged target vehicle-mounted data node. By limiting that only the authorized after-sales diagnostic instrument can execute the ARP protocol communication, and the forged vehicle-mounted data node cannot obtain the physical address of the central gateway, illegal invasion and communication establishment are prevented, hacker invasion is effectively prevented, and the safety of the cabin control system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Ethernet communication technologies, and in particular, to an anti-counterfeiting node communication method, device, equipment, and storage medium. Background Art

[0002] Modern automotive electronic and electrical systems have gradually introduced Ethernet-based communication designs and perform functions such as control and display through Ethernet nodes. In this application context, the security of automotive control nodes and how to ensure the security of counterfeiting by counterfeit nodes in the event of a hacker intrusion are also technical points that need to be emphasized. In a typical automotive network architecture, a central gateway (CGW, represented by the Central control unit) node is mostly used as the node for interacting with the diagnostic instrument, and each node communicates with the CGW.

[0003] Regarding the requirement for anti-counterfeiting of automotive nodes, taking the IVI (Intelligent Cockpit Domain Controller) as an example, the IVI communicates with the CGW through Ethernet, mainly transmitting navigation data, IVI settings, and remote control instructions. However, due to the insecurity of the network environment, there is a risk that hackers can forge an IVI node to communicate with the CGW. The traditional solution cannot effectively prevent the establishment of communication between the forged IVI node and the CGW, posing a serious threat to the security of the cockpit control system. Summary of the Invention

[0004] In view of this, the purpose of the embodiments of this application is to provide an anti-counterfeiting node communication method, device, equipment, and storage medium. By establishing an authorization and authentication protection layer of a vehicle fault diagnosis device (such as an after-sales diagnostic instrument) between the central gateway and multiple in-vehicle data nodes (such as IVI nodes) in advance, it is determined whether to allow the central gateway to communicate with the target in-vehicle data node according to the notification status of the vehicle fault diagnosis device. The forged target in-vehicle data node will not receive the authorization notification from the vehicle fault diagnosis device and thus will not be allowed to communicate, thereby preventing illegal intrusion and the establishment of communication, effectively preventing hacker intrusion, and improving the security of the cockpit control system, thereby solving the above technical problems.

[0005] In a first aspect, an embodiment of this application provides an anti-counterfeiting node communication method, which is applied to an in-vehicle system. The in-vehicle system includes: a central gateway and multiple in-vehicle data nodes, and the central gateway is communicatively connected to the multiple in-vehicle data nodes; the method includes:

[0006] Establish a communication connection between the central gateway and an authorized vehicle fault diagnosis device, and receive an authorization notification that has passed the security verification;

[0007] Based on the Address Resolution Protocol, establish a communication connection between the central gateway and the in-vehicle data node to obtain an authorized target in-vehicle data node;

[0008] Prohibit or allow the central gateway to communicate with the target in-vehicle data node according to the notification status of the vehicle fault diagnosis device; wherein, the target in-vehicle data node includes: a forged target in-vehicle data node.

[0009] In the above implementation process, a layer of authorization and authentication protection of the vehicle fault diagnosis device (such as an after-sales diagnostic instrument) is established in advance between the central gateway and multiple in-vehicle data nodes (such as IVI nodes). By restricting that only authorized after-sales diagnostic instruments can execute ARP protocol communication, the forged IVI node cannot obtain the MAC address of the CGW, preventing illegal intrusion and the establishment of communication, effectively preventing hacker intrusion, and improving the security of the cockpit control system.

[0010] Optionally, establishing the communication connection between the central gateway and the authorized vehicle fault diagnosis device and receiving the authorization notification passed through security verification includes:

[0011] Identifying and verifying the authorization status of the vehicle fault diagnosis device;

[0012] Establishing a communication connection between the central gateway and the vehicle fault diagnosis device;

[0013] Performing security verification on the central gateway and the vehicle fault diagnosis device based on the transport layer security protocol;

[0014] If the security verification passes, the central gateway receives the authorization notification from the vehicle fault diagnosis device.

[0015] In the above implementation process, by identifying the authorized vehicle fault diagnosis device and establishing a secure communication connection with the central gateway, and performing security authentication during the connection establishment process, the communication security between the central gateway and the authorized vehicle fault diagnosis device is improved.

[0016] Optionally, the performing security verification on the central gateway and the vehicle fault diagnosis device based on the transport layer security protocol includes:

[0017] The vehicle fault diagnosis device generates a random number and sends it to the central gateway;

[0018] The central gateway generates a digital certificate for encryption verification and feeds it back to the vehicle fault diagnosis device;

[0019] The vehicle fault diagnosis device verifies the credibility of the digital certificate, generates a temporary key, and sends it to the central gateway;

[0020] The central gateway negotiates a session key with the vehicle fault diagnosis device and performs symmetric encryption communication based on the session key.

[0021] In the above implementation process, encryption transmission is achieved through security authentication during the establishment of a TLS connection between the central gateway and the authorized vehicle fault diagnosis device, improving communication security.

[0022] Optionally, establishing the communication connection between the central gateway and the in-vehicle data node based on the Address Resolution Protocol to obtain the authorized target in-vehicle data node includes:

[0023] The central gateway broadcasts an ARP request message to the multiple in-vehicle data nodes on the local area network and receives the return message of the ARP request message; wherein, the ARP request message contains the target IP address of the in-vehicle data node, and the return message contains the target physical address of the target IP address;

[0024] Establish the communication connection between the central gateway and the in-vehicle data node through the target physical address;

[0025] The central gateway records the target in-vehicle data node corresponding to the target physical address; wherein, the target in-vehicle data node corresponding to the target physical address is recognized as authorized.

[0026] In the above implementation process, after the central gateway and the vehicle fault diagnosis device establish an authorization authentication, the central gateway executes the ARP protocol, which can realize the authorization authentication of the target in-vehicle data node and improve the communication security.

[0027] Optionally, judging whether the central gateway communicates with the target in-vehicle data node according to the notification status of the vehicle fault diagnosis device includes:

[0028] If the target in-vehicle data node is not notified through the authorized vehicle fault diagnosis device, the central gateway is prohibited from performing data communication with the target in-vehicle data node; wherein, the target in-vehicle data node is a forged target in-vehicle data node;

[0029] If the target in-vehicle data node is notified through the authorized vehicle fault diagnosis device, the central gateway is allowed to perform data communication with the target in-vehicle data node; wherein, the target in-vehicle data node is a real target in-vehicle data node.

[0030] In the above implementation process, by adding a layer of authorization authentication protection of the vehicle fault diagnosis device (such as an after-sales diagnostic instrument) between the central gateway and multiple in-vehicle data nodes (such as IVI nodes), the communication of forged target in-vehicle data nodes is effectively prevented, improving the security of vehicle communication.

[0031] Optionally, the multiple in-vehicle data nodes include: multiple IVI nodes.

[0032] In the above implementation process, by adding security verification to multiple IVI nodes, it prevents hackers from invading through the communication nodes that customers often access, and improves the security of using the in-vehicle entertainment system.

[0033] Optionally, the IP addresses of the multiple in-vehicle data nodes and the central gateway are predefined, and the IP address corresponds to a unique physical address.

[0034] In the above implementation process, by predefining the IP addresses and physical addresses of the multiple in-vehicle data nodes and the central gateway, it avoids the situation of communication failure caused by not obtaining a valid physical address during ARP communication.

[0035] In a second aspect, an embodiment of the present application provides an anti-counterfeiting node communication device, which is applied to an in-vehicle system. The in-vehicle system includes: a central gateway and multiple in-vehicle data nodes, and the central gateway is communicatively connected to the multiple in-vehicle data nodes; the device includes: an authorization notification module, configured to establish a communication connection between the central gateway and an authorized vehicle fault diagnosis device, and receive an authorization notification that passes security verification; an ARP communication establishment module, configured to establish a communication connection between the central gateway and the in-vehicle data node based on the address resolution protocol to obtain an authorized target in-vehicle data node; an anti-counterfeiting communication module, configured to prohibit or allow communication between the central gateway and the target in-vehicle data node according to the notification status of the vehicle fault diagnosis device; where the target in-vehicle data node includes: a forged target in-vehicle data node.

[0036] In a third aspect, an embodiment of the present application further provides an electronic device, including: a processor and a memory. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, when the machine-readable instructions are executed by the processor, the steps of the above method are executed.

[0037] In a fourth aspect, an embodiment of the present application provides a storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the above method are executed.

[0038] To make the above objects, features, and advantages of the present application more obvious and understandable, specific embodiments are hereinafter given, and in conjunction with the accompanying drawings, the detailed description is as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0040] Figure 1 Flowchart of an anti-counterfeiting node communication method provided by an embodiment of the present application;

[0041] Figure 2 Schematic diagram of establishing a connection between an after-sales diagnostic instrument and a CGW provided by an embodiment of the present application;

[0042] Figure 3 Schematic diagram of security verification between an after-sales diagnostic instrument and a CGW provided by an embodiment of the present application;

[0043] Figure 4 Schematic diagram of functional modules of an anti-counterfeiting node communication device provided by an embodiment of the present application;

[0044] Figure 5 Block diagram of an electronic device of an anti-counterfeiting node communication device provided by an embodiment of the present application.

[0045] Icons: 210 - Authorization notification module; 220 - ARP communication establishment module; 230 - Anti-counterfeiting communication module; 300 - Electronic device; 311 - Memory; 312 - Storage controller; 313 - Processor; 314 - Peripheral interface; 315 - Input / output unit; 316 - Display unit. Detailed implementation manners

[0046] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. The components of the embodiments of the present application described and illustrated in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0047] It should be noted that like reference numerals and letters refer to like items in the following figures. Thus, once an item is defined in one figure, further definition and explanation thereof is not required in subsequent figures. The terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or apparatus comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or apparatus. Without further limitation, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element. The terms "first", "second", etc. are used only for descriptive distinction and should not be construed as indicating or implying relative importance.

[0048] Before introducing the embodiments of the present application, a brief introduction to the technical concepts involved in the present application will be given first.

[0049] CGW is the abbreviation of the English "Central Gateway", which means "Central Gateway". In the automotive field, the central gateway is an electronic control unit (ECU) that is mainly responsible for tasks such as data routing, protocol conversion, diagnosis and calibration of all networks inside the vehicle, as well as communication with remote servers; it is one of the core components in the automotive network architecture and is responsible for coordinating and managing various network communications and data transmissions inside the vehicle.

[0050] The IVI node is a node in the In-Vehicle Infotainment (IVI for short) system. The in-vehicle infotainment system is an important part inside the vehicle, integrating various functions such as audio, video, navigation, telephone, voice recognition, etc., aiming to provide entertainment, information and convenience for passengers. In the in-vehicle infotainment system, each component such as audio equipment, display screen, navigation system, etc. needs to communicate and coordinate with each other to achieve various functions. The connections and communications between these components constitute the nodes in the IVI system, and each node has specific functions and interfaces and can perform data transmission and sharing with other nodes.

[0051] The inventors of the present application have noticed that due to the insecurity of the network environment, there is a vulnerability risk that hackers can forge IVI nodes to communicate with the CGW in the Ethernet communication protocol used by modern vehicles. Hackers can forge IVI nodes, communicate with the CGW, and obtain access rights to the cockpit control system. The traditional solutions cannot effectively prevent the establishment of communication between the forged IVI node and the CGW, which poses a serious threat to the security of the cockpit control system. The traditional solutions cannot prevent the forged IVI node because an unauthorized forged IVI node can establish a communication association with the CGW by sending forged ARP information to the CGW. Therefore, unauthorized access poses a threat to the safety of vehicle use. Once a hacker forges an IVI node and successfully establishes a communication association with the CGW, it can perform unauthorized access and manipulation on the cockpit control system, which may lead to security problems such as malicious operations, remote attacks, and data leakage, posing risks to the safety and privacy of passengers. In summary, the current technology faces serious problems regarding the communication security between the IVI node and the CGW in the modern vehicle cockpit control system. For the traditional solutions that cannot effectively prevent hackers from forging the communication between the IVI node and the CGW, resulting in unauthorized access threatening the security of the system, there is currently no effective way to solve the problem. In view of this, the embodiments of the present application provide an anti-counterfeiting node communication method, device, equipment, and storage medium as introduced below.

[0052] Please refer to Figure 1 , Figure 1 which is a flowchart of an anti-counterfeiting node communication method provided by an embodiment of the present application. The embodiments of the present application will be described in detail below. This method is applied to an in-vehicle system, which includes: a central gateway and multiple in-vehicle data nodes, and the central gateway is communicatively connected to the multiple in-vehicle data nodes; this method includes: step 100, step 120, and step 140.

[0053] Step 100: Establish a communication connection between the central gateway and an authorized vehicle fault diagnosis device, and receive an authorization notice that passes the security verification;

[0054] Step 120: Based on the Address Resolution Protocol, establish a communication connection between the central gateway and the in-vehicle data node to obtain an authorized target in-vehicle data node;

[0055] Step 140: Prohibit or allow the central gateway to communicate with the target in-vehicle data node according to the notification status of the vehicle fault diagnosis device; wherein, the target in-vehicle data node includes: a forged target in-vehicle data node.

[0056] Exemplarily, the vehicle fault diagnosis device can be a hardware device such as an after-sales diagnostic instrument that provides a specific authorization and authentication similar function. For example, an after-sales diagnostic instrument can be a hardware device designed specifically for after-sales service, equipped with powerful diagnostic functions, capable of reading and clearing fault codes, performing circuit tests, and providing various information about the vehicle. Through the after-sales diagnostic instrument, technicians can connect to the vehicle's OBD-II diagnostic port to obtain the vehicle's fault information; an authorized after-sales diagnostic instrument refers to a dedicated device that has been certified by the manufacturer or official and can be used for after-sales service diagnosis. The Address Resolution Protocol can be the ARP (Address Resolution Protocol), which is a TCP / IP protocol for obtaining the physical address based on the IP address. When the host sends information, it broadcasts an ARP request containing the target IP address to all hosts on the local area network and receives the return message to determine the physical address of the target. The in-vehicle data nodes can be various automotive network nodes such as the engine controller ECU, the automatic transmission controller ATCU, the anti-lock braking system controller ABS, the multimedia controller node, the navigation controller node, and the nodes in the in-vehicle infotainment system (In-Vehicle Infotainment, abbreviated as IVI).

[0057] Optionally, the vehicle fault diagnosis device is introduced by taking the after-sales diagnostic instrument as an example, and the in-vehicle data node is introduced by taking the IVI node as an example. In the automotive communication environment, if two nodes want to establish communication, they need to know the MAC addresses of both sides. Therefore, it is necessary to find the MAC address based on the IP address through the ARP protocol. Only when both communication parties (such as IVI and CGW) know the IP addresses and MAC addresses of both sides can they establish effective communication. The Central Gateway CGW first establishes a secure communication connection with the after-sales diagnostic instrument certified by the manufacturer or official and conducts a security verification. When the security verification passes, it will send an authorization notice to the CGW. The authorization notice can include signatures, encryption, or other security mechanisms to ensure the authenticity and integrity of the notice. After receiving the authorization notice, the CGW allows the execution of the ARP protocol. Through the ARP protocol, the CGW obtains the MAC address of the valid IVI node, and then can perform data communication with the valid and authorized IVI node. Hackers may replace the original vehicle's IVI node and try to forge a new IVI node (the forged target in-vehicle data node) to communicate with the CGW. Since this node has not been notified by the authorized after-sales diagnostic instrument, it will not be permitted to communicate with the CGW.

[0058] Establish authorization and authentication protection for vehicle fault diagnosis devices (such as after-sales diagnostic instruments) with multiple in-vehicle data nodes (such as IVI nodes) through the central gateway. By restricting only authorized after-sales diagnostic instruments to execute ARP protocol communication, forged IVI nodes cannot obtain the MAC address of the CGW, preventing illegal intrusion and the establishment of communication, effectively preventing hacker intrusion, and improving the security of the cockpit control system.

[0059] In one embodiment, step 100 may include: step 101, step 102, step 103, and step 104.

[0060] Step 101: Identify and verify the authorization status of the vehicle fault diagnosis device;

[0061] Step 102: Establish a communication connection between the central gateway and the vehicle fault diagnosis device;

[0062] Step 103: Based on the Transport Layer Security protocol, perform security verification on the central gateway and the vehicle fault diagnosis device;

[0063] Step 104: If the security verification passes, the central gateway receives the authorization notice from the vehicle fault diagnosis device.

[0064] Exemplarily, an after-sales diagnostic instrument generally has specific identification information, such as a security certificate, digital signature, etc., for verifying its legitimacy. The CGW can identify and verify the legitimacy and authorization status of the after-sales diagnostic instrument by communicating with the authorized after-sales diagnostic instrument. The after-sales diagnostic instrument establishes a secure communication connection with the CGW and sends an authorization notice to the CGW. As Figure 2 shown, a process of establishing a communication connection between an after-sales diagnostic instrument and the central gateway CGW is shown. The after-sales diagnostic instrument detects the connection and configures its own IP address. At the same time, the CGW detects the connection and configures its own IP address. The vehicle system corresponding to the CGW discovers the after-sales diagnostic instrument with the configured IP address. The after-sales diagnostic instrument also selects the vehicle where the CGW is located to establish a TCP connection and sends a request for a series of communication activations or authentications. This process includes the process of security verification between the CGW and the after-sales diagnostic instrument. The CGW makes a communication activation response, and after the authentication passes, the CGW receives the authorization notice from the after-sales diagnostic instrument.

[0065] By identifying authorized vehicle fault diagnosis devices and establishing a secure communication connection with the central gateway, and performing security authentication during the connection establishment process, the communication security between the central gateway and the authorized vehicle fault diagnosis devices is improved.

[0066] In one embodiment, step 103 may include: step 1031, step 1032, step 1033, and step 1034.

[0067] Step 1031: The vehicle fault diagnosis device generates a random number and sends it to the central gateway;

[0068] Step 1032: The central gateway generates an encrypted and verified digital certificate and feeds it back to the vehicle fault diagnosis device;

[0069] Step 1033: The vehicle fault diagnosis device verifies the credibility of the digital certificate, generates a temporary key, and sends it to the central gateway;

[0070] Step 1034: The central gateway negotiates a session key with the vehicle fault diagnosis device and conducts symmetric encryption communication based on the session key.

[0071] Exemplarily, TLS (Transport Layer Security Protocol) can be: responsible for providing encryption and data integrity protection in network communication, built on top of the transport layer protocol (such as TCP), providing a secure channel for communication between applications. The TLS protocol establishes an encrypted connection between the two communicating parties to ensure the confidentiality and integrity during the data transmission process. As Figure 3 shown, the security verification between the after-sales diagnostic instrument and the CGW can adopt the TLS method. When the after-sales diagnostic instrument and the CGW establish a TLS connection, the ARP protocol can be used to obtain the physical address of the CGW to ensure that the data can be correctly transmitted to the target host. The specific process can be: The after-sales diagnostic instrument, as the client, generates a random number 1 and sends a connection request to the CGW. The CGW, as the server, receives the connection request, generates a random number 2, and returns a welcome message, including the server certificate and the optional client certificate. The after-sales diagnostic instrument verifies the random number 2 and the server certificate to ensure that a connection is established with the correct CGW. The CGW generates an encrypted and verified digital certificate and feeds it back to the after-sales diagnostic instrument. The after-sales diagnostic instrument verifies the digital certificate, adds the random number 3 using the public key of the certificate, generates a temporary key prekey, and sends it to the CGW. The CGW decrypts the temporary key prekey using the private key of the server certificate to obtain the random number 3. The after-sales diagnostic instrument uses the random number 1, the random number 2, and the random number 3 to calculate the symmetric key sessionkey based on the DH algorithm (Diffie-Hellman algorithm). The after-sales diagnostic instrument and the CGW start using the symmetric key for encrypted communication to achieve data transmission.

[0072] By conducting security authentication during the process of establishing a TLS connection between the central gateway and the authorized vehicle fault diagnosis device, encrypted transmission is achieved, improving the communication security.

[0073] In one embodiment, step 120 may include: step 121, step 122, and step 123.

[0074] Step 121: The central gateway broadcasts the ARP request message to multiple in-vehicle data nodes on the local area network and receives the return message of the ARP request message; wherein, the ARP request message contains the target IP address of the in-vehicle data node, and the return message contains the target physical address of the target IP address.

[0075] Step 122: Establish a communication connection between the central gateway and the in-vehicle data node through the target physical address.

[0076] Step 123: The central gateway records the target in-vehicle data node corresponding to the target physical address; wherein, the target in-vehicle data node corresponding to the target physical address is recognized as authorized.

[0077] Exemplarily, after receiving the authorization notice, the CGW allows the execution of the ARP protocol and establishes a legal ARP association for communication with the IVI node. The process of the CGW executing the ARP protocol can be as follows: Assume that the IP address of the target in-vehicle data node is 10.1.1.0 and the MAC address is 00::11::22::33::44::55. The CGW broadcasts the ARP request message to multiple IVI nodes and receives the return message of the target IVI node for the ARP request message; wherein, the ARP request message contains the target IP address 10.1.1.0 of the target in-vehicle data node, and the return message contains the target physical address of the target IP address: 00::11::22::33::44::55. By executing the ARP protocol, the CGW can obtain the MAC address of the target IVI node and realize data communication with the IVI node. Repeating the above authorization process, the CGW records the MAC addresses of the authorized IVI nodes for subsequent communication use.

[0078] After establishing authorization authentication between the central gateway and the vehicle fault diagnosis device, the central gateway executes the ARP protocol, which can realize the authorization authentication of the target in-vehicle data node and improve the security of communication.

[0079] In one embodiment, step 140 may include: step 141 and step 142.

[0080] Step 141: If the target in-vehicle data node is not notified by an authorized vehicle fault diagnosis device, prohibit the central gateway from performing data communication with the target in-vehicle data node; wherein, the target in-vehicle data node is a forged target in-vehicle data node.

[0081] Step 142: If the target in-vehicle data node is notified by an authorized vehicle fault diagnosis device, allow the central gateway to perform data communication with the target in-vehicle data node; wherein, the target in-vehicle data node is a genuine target in-vehicle data node.

[0082] Exemplarily, a hacker may replace the original vehicle's target IVI node and attempt to forge a new target IVI node to communicate with the CGW. The hacker attempts to obtain information such as the IP address and port number of the target IVI node and the CGW in order to establish a connection with the CGW. If the hacker does not notify through an authorized after-sales diagnostic instrument, the CGW will be prohibited from performing ARP protocol communication with the forged IVI node because the CGW has not obtained the authorization of the after-sales diagnostic instrument. In this case, the CGW will not execute the ARP protocol, thus unable to obtain the MAC address of the IVI node and unable to perform communication between the CGW and the IVI. The CGW will refuse to establish a communication association with an unauthorized IVI node because the CGW has not obtained the authorization of the after-sales diagnostic instrument. In this case, the CGW will not execute the ARP protocol, thereby protecting the security of the cockpit control system. If notified through an authorized after-sales diagnostic instrument, the CGW will allow ARP protocol communication with a normal IVI node.

[0083] By adding this layer of authorization and authentication protection of vehicle fault diagnosis equipment (such as an after-sales diagnostic instrument) between the central gateway and multiple in-vehicle data nodes (such as: IVI nodes), communication of forged target in-vehicle data nodes is effectively prevented, improving the security of vehicle communication.

[0084] In one embodiment, the multiple in-vehicle data nodes include: multiple IVI nodes.

[0085] Exemplarily, the multiple IVI nodes may be: nodes corresponding to multiple functions such as audio, video, navigation, telephone, and voice recognition in the in-vehicle infotainment system. In the in-vehicle infotainment system, each component such as an audio device, a display screen, and a navigation system needs to communicate and coordinate with each other to achieve various functions. The connections and communications between these components constitute multiple nodes in the IVI system. Each node has a specific function and interface and can perform data transmission and sharing with other nodes. By adding security verification to the multiple IVI nodes, hackers are prevented from invading through the communication nodes that customers often access, enhancing the security of using the in-vehicle entertainment system.

[0086] In one embodiment, the IP addresses of the multiple in-vehicle data nodes and the central gateway are predefined, and the IP address corresponds to a unique physical address.

[0087] Exemplarily, in an automotive communication environment, the IP addresses of each control node (such as IVI and CGW) need to be determined in advance, that is, preset in advance. The physical address (MAC address) is unique for each network card. Therefore, to establish communication between two nodes, one-to-one determined communication can be achieved based on the MAC addresses of both parties. The ARP protocol can be used to find the MAC address based on the IP address. The communication parties (IVI and CGW) know the IP addresses and MAC addresses of both parties to establish determined and effective communication. By pre-defining the IP addresses and physical addresses of multiple in-vehicle data nodes and the central gateway, the situation of communication failure caused by not obtaining a valid physical address during ARP communication can be avoided.

[0088] Please refer to Figure 4 , Figure 4 FIG. is a schematic diagram of the functional modules of an anti-counterfeiting node communication device provided by an embodiment of the present application, which is applied to an in-vehicle system. The in-vehicle system includes: a central gateway and multiple in-vehicle data nodes, and the central gateway is communicatively connected to the multiple in-vehicle data nodes; the device includes:

[0089] An authorization notification module 210, configured to establish a communication connection between the central gateway and an authorized vehicle fault diagnosis device, and receive an authorization notification passed through security verification;

[0090] An ARP communication establishment module 220, configured to establish a communication connection between the central gateway and an in-vehicle data node based on the address resolution protocol to obtain an authorized target in-vehicle data node;

[0091] An anti-counterfeiting communication module 230, configured to prohibit or allow communication between the central gateway and the target in-vehicle data node according to the notification status of the vehicle fault diagnosis device; wherein, the target in-vehicle data node includes: a forged target in-vehicle data node.

[0092] Optionally, the authorization notification module 210 may be configured to:

[0093] Identify and verify the authorization status of the vehicle fault diagnosis device;

[0094] Establish a communication connection between the central gateway and the vehicle fault diagnosis device;

[0095] Perform security verification on the central gateway and the vehicle fault diagnosis device based on the transport layer security protocol;

[0096] If the security verification passes, the central gateway receives the authorization notification from the vehicle fault diagnosis device.

[0097] Optionally, the authorization notification module 210 may be configured to:

[0098] Generate a random number by the vehicle fault diagnosis device and send it to the central gateway;

[0099] The central gateway generates an encrypted and verified digital certificate and feeds it back to the vehicle fault diagnosis device;

[0100] The vehicle fault diagnosis device verifies the credibility of the digital certificate, generates a temporary key, and sends it to the central gateway;

[0101] The central gateway negotiates a session key with the vehicle fault diagnosis device and conducts symmetric encryption communication based on the session key.

[0102] Optionally, the ARP communication establishment module 220 can be used for:

[0103] The central gateway broadcasts an ARP request message to the multiple in-vehicle data nodes on the local area network and receives the return message of the ARP request message; wherein, the ARP request message includes the target IP address of the in-vehicle data node, and the return message includes the target physical address of the target IP address;

[0104] Establish a communication connection between the central gateway and the in-vehicle data node through the target physical address;

[0105] The central gateway records the target in-vehicle data node corresponding to the target physical address; wherein, the target in-vehicle data node corresponding to the target physical address is recognized as authorized.

[0106] Optionally, the anti-counterfeiting communication module 230 can be used for:

[0107] If the target in-vehicle data node is not notified through an authorized vehicle fault diagnosis device, the central gateway is prohibited from performing data communication with the target in-vehicle data node; wherein, the target in-vehicle data node is a forged target in-vehicle data node;

[0108] If the target in-vehicle data node is notified through an authorized vehicle fault diagnosis device, the central gateway is allowed to perform data communication with the target in-vehicle data node; wherein, the target in-vehicle data node is a genuine target in-vehicle data node.

[0109] Optionally, the multiple in-vehicle data nodes include: multiple IVI nodes.

[0110] Optionally, the IP addresses of the multiple in-vehicle data nodes and the central gateway are predefined, and the IP address corresponds to a unique physical address.

[0111] Please refer to Figure 4 , Figure 4It is a block diagram of an electronic device. The electronic device 300 may include a memory 311, a storage controller 312, a processor 313, a peripheral interface 314, an input / output unit 315, and a display unit 316. Those of ordinary skill in the art can understand that Figure 4 the structure shown is only illustrative and does not limit the structure of the electronic device 300. For example, the electronic device 300 may further include more or fewer components than those Figure 4 shown, or have a different configuration from that Figure 4 shown.

[0112] The above-mentioned memory 311, storage controller 312, processor 313, peripheral interface 314, input / output unit 315, and display unit 316 are electrically connected to each other directly or indirectly to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses or signal lines. The above-mentioned processor 313 is used to execute the executable module stored in the memory.

[0113] Among them, the memory 311 can be, but is not limited to, a random access memory (Random Access Memory, abbreviated as RAM), a read-only memory (Read Only Memory, abbreviated as ROM), a programmable read-only memory (Programmable Read-Only Memory, abbreviated as PROM), an erasable programmable read-only memory (Erasable Programmable Read-Only Memory, abbreviated as EPROM), an electrically erasable programmable read-only memory (Electric Erasable Programmable Read-Only Memory, abbreviated as EEPROM), etc. Among them, the memory 311 is used to store a program, and after receiving an execution instruction, the processor 313 executes the program. The method executed by the electronic device 300 defined by the process disclosed in any embodiment of the present application can be applied to the processor 313 or implemented by the processor 313.

[0114] The above-mentioned processor 313 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor 313 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0115] The above-mentioned peripheral interface 314 couples various input / output devices to the processor 313 and the memory 311. In some embodiments, the peripheral interface 314, the processor 313, and the memory controller 312 may be implemented on a single chip. In some other instances, they may be implemented by separate chips.

[0116] The above-mentioned input / output unit 315 is used to provide input data to the user. The input / output unit 315 may be, but is not limited to, a mouse, a keyboard, etc.

[0117] The above-mentioned display unit 316 provides an interaction interface (such as a user operation interface) between the electronic device 300 and the user for the user to refer to. In this embodiment, the display unit 316 may be a liquid crystal display or a touch display. The liquid crystal display or the touch display can display the process of the processor executing the program.

[0118] The electronic device 300 in this embodiment can be used to execute each step in the various methods provided in the embodiments of the present application.

[0119] In addition, the embodiments of the present application also provide a storage medium, on which a computer program is stored, and when the computer program is run by a processor, it executes the steps in the above method embodiments.

[0120] The computer program product of the above method provided by the embodiments of the present application includes a storage medium storing program code, and the instructions included in the program code can be used to execute the steps in the above method embodiments. For details, refer to the above method embodiments and will not be elaborated here.

[0121] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical or other forms. In the embodiments of the present application, each functional module can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0122] It should be noted that if the function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0123] In this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0124] The above are only the embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for anti-counterfeiting node communication, characterized in that Applied to a vehicle system, the vehicle system includes: a central gateway and a plurality of vehicle data nodes, and the central gateway is communicatively connected to the plurality of vehicle data nodes; the method includes: Establish a communication connection between the central gateway and an authorized vehicle fault diagnosis device, and receive an authorization notification that has passed security verification; Based on the Address Resolution Protocol, establish a communication connection between the central gateway and the vehicle data nodes to obtain authorized target vehicle data nodes; According to the notification status of the vehicle fault diagnosis device, prohibit or allow the central gateway to communicate with the target vehicle data nodes; wherein, the target vehicle data nodes include: forged target vehicle data nodes.

2. The method according to claim 1, characterized in that, The establishing a communication connection between the central gateway and an authorized vehicle fault diagnosis device, and receiving an authorization notification that has passed security verification, includes: Identify and verify the authorization status of the vehicle fault diagnosis device; Establish a communication connection between the central gateway and the vehicle fault diagnosis device; Based on the Transport Layer Security Protocol, perform security verification on the central gateway and the vehicle fault diagnosis device; If the security verification passes, the central gateway receives the authorization notification from the vehicle fault diagnosis device.

3. The method according to claim 2, characterized in that, The performing security verification on the central gateway and the vehicle fault diagnosis device based on the Transport Layer Security Protocol includes: The vehicle fault diagnosis device generates a random number and sends it to the central gateway; The central gateway generates a digital certificate for encrypted verification and feeds it back to the vehicle fault diagnosis device; The vehicle fault diagnosis device verifies the credibility of the digital certificate, generates a temporary key, and sends it to the central gateway; The central gateway and the vehicle fault diagnosis device negotiate a session key and perform symmetric encryption communication based on the session key.

4. The method according to claim 1, wherein The establishing a communication connection between the central gateway and the vehicle data nodes based on the Address Resolution Protocol to obtain authorized target vehicle data nodes includes: The central gateway broadcasts an ARP request message to the plurality of vehicle data nodes on the local area network and receives a return message of the ARP request message; wherein, the ARP request message contains the target IP address of the vehicle data node, and the return message contains the target physical address of the target IP address; Establish a communication connection between the central gateway and the vehicle data node through the target physical address; The central gateway records the target vehicle data node corresponding to the target physical address; wherein, the target vehicle data node corresponding to the target physical address is recognized as authorized.

5. The method according to claim 1, characterized in that Judging whether the central gateway communicates with the target vehicle data node according to the notification status of the vehicle fault diagnosis device includes: If the target vehicle data node is not notified by an authorized vehicle fault diagnosis device, prohibit the central gateway from performing data communication with the target vehicle data node; wherein, the target vehicle data node is a forged target vehicle data node; If the target vehicle-mounted data node is notified through an authorized vehicle fault diagnosis device, the central gateway is allowed to communicate with the target vehicle-mounted data node; wherein, the target vehicle-mounted data node is a real target vehicle-mounted data node.

6. The method according to any one of claims 1-5, characterized in that, Wherein, The multiple vehicle-mounted data nodes include: multiple IVI nodes.

7. The method according to any one of claims 1-5, characterized in that, Wherein, The IP addresses of the multiple vehicle-mounted data nodes and the central gateway are predefined, and the IP address corresponds to a unique physical address.

8. An anti-counterfeiting node communication device, characterized in that, Applied to a vehicle-mounted system, the vehicle-mounted system includes: a central gateway and multiple vehicle-mounted data nodes, and the central gateway is communicatively connected to the multiple vehicle-mounted data nodes; the device includes: An authorization notification module, configured to establish a communication connection between the central gateway and an authorized vehicle fault diagnosis device, and receive an authorization notification that has passed security verification; An ARP communication establishment module, configured to establish a communication connection between the central gateway and the vehicle-mounted data node based on the address resolution protocol to obtain an authorized target vehicle-mounted data node; An anti-counterfeiting communication module, configured to prohibit or allow the central gateway to communicate with the target vehicle-mounted data node according to the notification status of the vehicle fault diagnosis device; wherein, the target vehicle-mounted data node includes: a forged target vehicle-mounted data node.

9. An electronic device, characterized in that, Includes: A processor and a memory, the memory stores machine-readable instructions executable by the processor, and when the electronic device runs, the machine-readable instructions are executed by the processor to perform the steps of the method according to any one of claims 1 to 7.

10. A storage medium, characterized in that, A computer program is stored on the storage medium, and when the computer program is run by a processor, it performs the steps of the method according to any one of claims 1 to 7.