Method based on end-to-end communication protection, electronic equipment and storage medium
By generating and managing the serial number and message length of transmitted data in the on-board communication system, the signal failure problem in on-board communication is solved, and the timely, correct and complete data transmission is achieved, which is suitable for secure communication between ECUs.
Patent Information
- Application Number
- CN202510657236.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-06-27
AI Technical Summary
In the field of in-vehicle communication, the existing end-to-end protection mechanism is difficult to effectively solve communication failure problems such as signal duplication, loss, damage, delay, reception asymmetry, additional signal insertion, and forged signals, especially in the interaction of security-related functional information between ECUs.
By obtaining the time information of the on-board communication system and network load, the serial number of the first frame message of the transmission data is generated, and the message length is determined according to the network load. It is arranged in the frame structure of end-to-end communication, and after sending messages to the data receiving end, the serial number is incremented in sequence to ensure the timeliness, correctness and integrity of the data.
It realizes that in the on-board communication system, errors in communication are detected through network packet transmission, timeliness, correctness and integrity of data are ensured, and is suitable for communication between components with high functional safety requirements.
Smart Images

Figure CN120223433A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular, to a method, system, device, and medium for end-to-end communication protection. Background Art
[0002] In the field of vehicle-mounted communications, when signals are transmitted, communication failures such as signal duplication, loss, damage, delay, reception asymmetry, extra signal insertion, forged signals, incorrect signal addresses, incorrect signal sequences, and channel blockage may occur. Therefore, for communications between components with high functional safety requirements, a secure data transmission mechanism is required.
[0003] The end-to-end protection mechanism refers to ensuring the timeliness, correctness, and integrity of data during the transmission of information between nodes in the vehicle communication system through a specified specific monitoring mechanism. Existing end-to-end protection usually performs secure communication and privacy data protection through a series of encryption technologies. However, this method does not suit the scenarios and service requirements of vehicle-mounted communications. Therefore, an end-to-end protection mechanism suitable for ensuring the interaction of safety-related function information between ECUs is needed to ensure the timeliness, correctness, and integrity of data through network message transmission. Summary of the Invention
[0004] In view of the above-mentioned disadvantages of the prior art, this application provides a method, system, device, and medium for end-to-end communication protection to solve the above technical problems.
[0005] The method for end-to-end communication protection provided by this application includes: obtaining the time information and network load of the current vehicle-mounted communication system; generating a sequence number of the first frame message of the transmitted data based on the time information, and determining the message length of the transmitted data based on the network load; the message length is configured in the length field in the frame structure of end-to-end communication, and the sequence number is configured in the sequence number field in the frame structure; after sending the first frame message to the data receiving end, the sequence number of each subsequent frame message is incremented in turn.
[0006] In an embodiment of this application, the frame structure further includes: a protocol type field for indicating the protocol type of the transmitted data message, where the protocol type includes the Diagnostic over Internet Protocol (DoIP) based on Ethernet and the Service-Oriented Middleware over IP (SOME / IP); a protocol header field for configuring the header corresponding to the protocol.
[0007] In an embodiment of this application, if the sequence number exceeds a preset range threshold, the sequence number is regenerated according to the current time information.
[0008] In one embodiment of the present application, the first field configured to represent the priority of message calculation and processing; and the second field configured to represent the destination address, so that the data receiving end determines whether the target address is legal based on the parsed address field.
[0009] In one embodiment of the present application, the time of the current vehicle-mounted communication system is subjected to hash calculation to obtain the sequence number of the first-frame message; the current remaining bandwidth capacity of the vehicle-mounted communication system is detected, and the message length of the transmitted data is determined based on the network load and the remaining bandwidth capacity.
[0010] The present application also provides a method based on end-to-end communication protection, including: receiving the transmission data from the data sending end and performing parsing to obtain the sequence number of each frame of the parsed transmission data; determining whether the received data times out or does not time out based on a preset message timing; determining whether the received data is correct or incorrect according to the sequence number of the parsed first-frame message and the incremental change of the sequence number of each subsequent frame of the message. The sequence number of the first-frame message is generated based on the time of the vehicle-mounted communication system when the data sending end sends data, and the message length of the transmitted data is determined based on the network load; the message length is configured in the length field in the frame structure of end-to-end communication, and the sequence number is configured in the sequence number field in the frame structure.
[0011] In one embodiment of the present application, the sequence number of each received frame of the message is compared with the sequence number of the previous frame of the message. If it is an increment of one, it is determined that the received data is correct; if it is not an increment of one and the data exceeds a preset counting error tolerance threshold, it is determined that the received data is incorrect.
[0012] In one embodiment of the present application, the type identification field and the check field of the parsed transmission data are obtained. The type identification field includes a first field for representing the priority of message calculation and processing and a second field for representing the destination address; the type identification field is subjected to a first check, and the first check result is subjected to a second check with the data part in the frame structure of end-to-end communication to obtain a second check result; the second check result is compared with the check field. If the comparison results are the same, it is determined that the transmission data is normal.
[0013] The present application also provides a method for end-to-end communication protection, including: obtaining the time information and network load of the current vehicle-mounted communication system; generating a sequence number of the first-frame message of the transmitted data based on the time information, and determining the message length of the transmitted data based on the network load; after sending the first-frame message to the data receiving end, incrementing the sequence number of each subsequent frame message in turn; receiving the transmitted data and performing parsing to obtain the sequence number of each frame message of the parsed transmitted data, determining whether the received data times out or does not time out based on a preset message timing, and determining whether the received data is correct or incorrect according to the incremental change of the sequence number.
[0014] The present application also provides a system for end-to-end communication protection, including: an information collection module for obtaining the time information and network load of the current vehicle-mounted communication system; a data sending end for generating a sequence number of the first-frame message of the transmitted data based on the time information, determining the message length of the transmitted data based on the network load, and after sending the first-frame message to the data receiving end, incrementing the sequence number of each subsequent frame message in turn; a data receiving end for receiving the transmitted data and performing parsing to obtain the sequence number of each frame message of the parsed transmitted data, determining whether the received data times out or does not time out based on a preset message timing, and determining whether the received data is correct or incorrect according to the incremental change of the sequence number.
[0015] The present application also provides an electronic device, including: one or more processors; a storage device for storing one or more programs, which, when executed by the one or more processors, cause the electronic device to implement the method for end-to-end communication protection as described above.
[0016] The present application also provides a computer-readable storage medium, on which computer-readable instructions are stored, which, when executed by a processor of a computer, cause the computer to execute the method for end-to-end communication protection as described above.
[0017] The beneficial effects of the present application: generating a sequence number of the first-frame message of the transmitted data through the time information, after sending the first-frame message to the data receiving end, incrementing the sequence number of each subsequent frame message in turn, and after receiving and parsing the transmitted data, determining whether the received data is correct or incorrect according to the incremental change of the sequence number of each frame message of the parsed transmitted data; by using the present application to attach extended information to the transmitted message, errors in communication can be detected, and the timeliness, correctness, and integrity of data are ensured during the transmission of network messages from end to end in vehicle-mounted communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 is a schematic flowchart of the sending end in the method for end-to-end communication protection in an embodiment of the present application; Figure 2 It is a schematic diagram of a DoIP message carried by an Ethernet message in the method for end-to-end communication protection in the embodiments of the present application; Figure 3 It is a schematic diagram of a SOMEIP message carried by an Ethernet message in the method for end-to-end communication protection in the embodiments of the present application; Figure 4 It is a schematic diagram of the process at the receiving end in the method for end-to-end communication protection in the embodiments of the present application; Figure 5 It is a schematic diagram of the process of data verification at the receiving end in the method for end-to-end communication protection in the embodiments of the present application; Figure 6 It is a schematic diagram of the overall process in the method for end-to-end communication protection in the embodiments of the present application; Figure 7 It is a principle block diagram of a system for end-to-end communication protection shown in an exemplary embodiment of the present application; Figure 8 It is a schematic diagram of the architecture of a system for end-to-end communication protection in the embodiments of the present application; Figure 9 It is a schematic diagram of the structure of a computer system of an electronic device in the embodiments of the present application. Detailed implementation manners
[0019] The following uses specific specific examples to illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0020] It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present application in a schematic manner. Therefore, only the components related to the present application are shown in the diagrams, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0021] In the following description, a large number of details are explored to provide a more thorough explanation of the embodiments of the present application. However, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present application difficult to understand.
[0022] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0023] The flowcharts shown in the drawings are only exemplary descriptions, and do not necessarily include all content and operations / steps, nor do they necessarily need to be executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined. Therefore, the actual execution order may change according to the actual situation.
[0024] In this application, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the front and rear associated objects.
[0025] It should be noted that the electronic and electrical architecture in the solution of this application adopts an Ethernet ring network architecture design. The ring network architecture can support SOA (Service-Oriented Architecture) serviceization and communication channel protection, support each ECU (Electric Control Unit) component to be connected nearby according to function classification, and save wiring harness costs. The CDC (Cockpit Domain Controller) can be connected to the cloud through 4G / 5G and WIFI channels, which is the communication channel between the vehicle and the outside world. The VIU (Vehicle Information Unit) can be connected through Ethernet to form a ring network structure and hang relevant ECUs below. Various ECUs with different function types can be composed of those that support Ethernet and those that do not support Ethernet (such as those that support CAN communication).
[0026] In the field of vehicle communication, signal failures usually occur in the following situations: a) Signal repetition: The receiving end receives the information more than once; b) Signal loss: All or part of the information in the information stream sent by the sending end is lost; c) Signal delay: The signal is not received within the expected time; d) Extra signal insertion: Extra information is inserted into the information stream sent by the sending end; e) Forged signal: Unauthenticated information is received by the receiving end as authenticated information; f) Signal address error: A type of channel fault, indicating that the characterization information is sent by the wrong sender or received by the wrong receiver; g) Signal sequence error: In a transmitted information stream, the order of the information is modified; h) Signal corruption: The information is changed; i) Asymmetric signal reception: Different receivers receive different information from the same sender; j) Some receivers do not receive the expected signal: Among several receivers, only some receive the information; k) Signal channel blockage: Access to the communication channel is blocked.
[0027] Figure 1 is a schematic diagram of the process of the sender in the method for end-to-end communication protection of this application, Figure 2 is a schematic diagram of the DoIP message carried by the Ethernet message in the method for end-to-end communication protection of this application, Figure 3 is a schematic diagram of the SOMEIP message carried by the Ethernet message in the method for end-to-end communication protection of this application.
[0028] As Figure 1 shown, the method for end-to-end communication protection in this embodiment includes at least steps S110 to S130, specifically as follows: S110. Obtain the time information and network load of the current vehicle-mounted communication system.
[0029] In an embodiment of the present application, taking the DoIP message carried by an Ethernet message as an example, the Ethernet Head, IPHead, and TCP / UDP Head are the header information of Ethernet, IP, and TCP / UDP frames, which can include multiple key fields for identifying and transmitting data. The FCS (Frame Check Sequence) is the frame tail, and Data is the end-to-end transmitted data. The fields of E2E (end-to-end) are defined customarily in the data field of the Ethernet message. Among them, the "protocol type: 0x01" field can be defined to represent the DoIP protocol type, the "DoIP head" field represents the header format of the DoIP protocol stack message, the "E2E LEN" field represents the length (including User data + E2E Header), and the "E2E TYPEID" field represents that each piece of data protected by E2E (such as diagnostic messages, upgrade file messages, ordinary messages, etc.) has a specific ID (for example: upgrade file message: 0x1000~0x1fff, ordinary message: 0x2000~0x6fff, diagnostic message: 0x7000~0x7fff). Among them, the high bits (BIT:15~BIT12) represent the priority of the protection ability, and the smaller the number, the higher the priority. The low bits BIT:11~BIT0 represent the address of the ECU, indicating the protected ID. The "E2E SEQ" field represents the sequence number counter of the protected data message, which is a sequence number used to count the sending and receiving behaviors of the data. For the sending end, after initialization is completed, when transmitting for the first time, the SEQ value is initialized to the value obtained by performing a hash calculation on the "absolute value of the current time (accurate to microseconds)". When the sending end sends the first frame message, the value obtained by obtaining the absolute value of the current system time and performing a hash calculation is used as the sequence number (SEQ) of the first frame. By using this method that does not start counting from 1, it can prevent attackers from obtaining the entire message and causing information leakage, as Figure 2 shown.
[0030] In an embodiment of the present application, taking the SOMEIP message carried by an Ethernet message as an example, the field definition of E2E (end-to-end) is customized in the data field of the Ethernet message. Among them, the "Protocol Type: 0x02" field definition indicates the SOMEIP protocol type, the "SOMEIP head" field indicates the message header format of the SOMEIP protocol stack, the "E2E LEN" field indicates the length (including User data + E2E Header), the "E2E TYPEID" field indicates that each piece of data protected by E2E (such as diagnostic messages, upgrade file messages, ordinary messages, etc.) has a specific ID (such as: upgrade file messages: 0x1000~0x1fff, ordinary messages, etc.: 0x2000~0x6fff, diagnostic messages: 0x7000~0x7fff). The high bits (BIT:15~BIT12) represent the priority of the protection ability, and the smaller the number, the higher the priority. BIT:11~BIT0 represents the address of the ECU, indicating the protected ID. The "E2ESEQ" field represents the sequence number counter of the protected data message, which is a sequence number used to count the sending and receiving behaviors of the data. For the sending end, after initialization is completed, when transmitting for the first time, the SEQ value should be initialized to the value obtained by hashing the "absolute value of the current time (accurate to microseconds)". When the sending end sends the first-frame message, the absolute value of the current system time is obtained as the sequence number (SEQ) of the first frame. By using this method that does not start counting from 1, it can prevent attackers from obtaining the entire message and causing information leakage, as Figure 3 shown.
[0031] In an embodiment of the present application, traditional end-to-end protection is a data security mechanism designed to protect the integrity and security of data during transmission and storage. In a vehicle communication system, through a specified specific monitoring mechanism to ensure information during the transmission process between nodes, it is even more necessary to ensure the timeliness, correctness, and integrity of data, especially for communication between components with high functional safety requirements. It is increasingly important to adopt a secure data transmission mechanism. In addition to the header information of Ethernet, IP, TCP / UDP frames, and the frame tail in the data frame format of the transmitted data in this application, the middle end-to-end frame structure mainly includes: a protocol type field, a protocol header field, a length field, a type identification field, a sequence number field, a priority field, a check field, and a data part field. Among them, the protocol type field is used to indicate the protocol type of the transmitted data message, and the protocol type can include the diagnostic communication protocol DOIP based on Ethernet and the extensible service-oriented middleware SOME / IP based on IP. The protocol header field is used to configure the header of the corresponding protocol. S120. Generate a sequence number for the first-frame message of the transmission data based on the time information, and determine the message length of the transmission data based on the network load; the message length is configured in the length field in the frame structure of the end-to-end communication, and the sequence number is configured in the sequence number field in the frame structure.
[0032] In an embodiment of the present application, when the sending end sends a message, it can perform a network load check to check the network load and the remaining bandwidth capacity, and then determine how long a data message to send according to the load situation. The length of the message can be represented by the above-mentioned "E2E LEN" field. In this embodiment, in addition to the length field (such as the "E2E LEN" field), the end-to-end communication frame structure further includes: a type identification field (such as the "E2E TYPEID" field) for indicating the protocol type of the transmission data message; a sequence number field (such as the "E2E SEQ" field) for carrying a sequence number for counting the sending and receiving behaviors of the data; a check field (such as the "E2E CRC" field) for performing a cyclic redundancy check on the transmission data; after configuring each field, send a message to the data receiving end based on the end-to-end communication frame structure, where the type identification field includes a first field for indicating the message priority and a second field for indicating the destination address.
[0033] S130. After sending the first-frame message to the data receiving end, increment the sequence number of each subsequent frame message in turn.
[0034] In an embodiment of the present application, after sending the first-frame message to the data receiving end, increment the sequence number of each subsequent frame message in turn, so that when the data receiving end receives a message for the first time, based on a preset message timing, it determines whether the received data times out or does not time out, and determines whether the received data is correct or incorrect according to the incremental change of the sequence number. Increment the sequence number of each subsequent frame message by one. When the sequence number exceeds a preset range threshold, initialize the sequence number and start incrementing and counting again. As Figure 2 、 3 shown, after each send, the SEQ value is incremented by 0x1; when the SEQ value reaches the maximum value of 0xFFFFFFFF, the next time it is sent, the SEQ value can be initialized and start cycling again.
[0035] In an embodiment of the present application, a type identification field for transmitting data is configured. The type identification field includes a first field and a second field, where: the first field configured to represent the calculation and processing priority of a message is used to calculate and process the transmitted data message in the order of priority when receiving data. Here, the calculation and processing priority is represented by the high bits of the type identification field ("E2ETYPEID" field), which is the priority representing the protection ability. In this embodiment, the smaller the number, the higher the priority; the second field configured to represent the destination address is used to determine whether the target address is legal based on the parsed address field at the data receiving end. As Figure 2 shown in 3, the priority field ("E2E Priority" field) represents the transmission priority of the message. Here, the transmission priority is 0 to 7. In this embodiment, the larger the number, the higher the priority. Messages with a higher priority are transmitted first. The check field ("E2E CRC" field) represents the CRC cyclic redundancy check. "Data" represents the transmitted data, that is, the data message of the Ethernet message.
[0036] Figure 4 is a schematic diagram of the receiving end process in the method for end-to-end communication protection of the present application. The method at least includes steps S410 to S430, which are introduced in detail as follows: S410. Receive the transmitted data from the data sending end and perform parsing to obtain the sequence number of each frame of the transmitted data after parsing.
[0037] In an embodiment of the present application, the receiving end can parse the E2E SEQ field in the transmitted data to obtain the sequence number SEQ of each frame of the transmitted data after parsing.
[0038] S420. Determine whether the received data times out or does not time out based on the preset message timing; In an embodiment of the present application, when the receiving end receives a message for the first time, a receiving timer is started to perform message timing. The timing time is determined according to the message timing time. When the receiving times out, it means that data has not been received within the agreed time, and the timeout is replied to the sending end. The sending end retransmits the data message to ensure that the data is not missed. If the data is received without timeout, it is processed in the next step.
[0039] S430. Determine whether the received data is correct or incorrect according to the sequence number of the first frame of the message after parsing and the increasing change of the sequence number of each subsequent frame of the message. The sequence number of the first frame of the message is generated based on the current in-vehicle communication system time when the data sending end sends the data. The message length of the transmitted data is determined based on the network load.
[0040] In an embodiment of the present application, each time the receiving end receives a frame of data SEQ, it compares it with the previous frame of data SEQ to check if it increases by one. When SEQ does not change incrementally and exceeds the pre-set counting error tolerance threshold range (the "counting error tolerance threshold" can be defined by the configuration specification), an error occurs in data reception.
[0041] Figure 5 It is a schematic diagram of the data verification process at the receiving end in the method for end-to-end communication protection of the present application.
[0042] As Figure 5 shown, in an embodiment of the present application, the type identification field and the cyclic redundancy check field of the parsed transmission data are obtained. The type identification field includes a first field for indicating the message priority and a second field for indicating the destination address; a first verification is performed on the type identification field, and a second verification is performed on the data part in the frame structure of the end-to-end communication according to the first verification result to obtain a second verification result. The second verification result is compared with the cyclic redundancy check field. If the comparison results are the same, it is determined that the transmission data is normal. In this embodiment, the receiving end parses the "E2E TYPEID" field. The high 4 bits of this field represent the priority of the calculation process, and the low 12 bits represent the legal ECU target address. It is checked whether the target address is legal. The CRC check is performed and then compared with the data for CRC check to see if the E2E CRC is equal. If it is equal, the data message is normal; if not, a communication error occurs. The "E2E CRC" field in the transmission data represents the CRC cyclic redundancy check. "Data" represents the data message of the Ethernet message. In addition, the end-to-end communication frame structure in this embodiment further includes a protocol type field for indicating different protocol type messages carried by the Ethernet message, such as DoIP, SOMEIP, DDS, TSN, etc. Different protocol types can be represented by different assignments. Those skilled in the art should be able to know that for different protocol types, the protocol header fields of the frame structure will be correspondingly set as the DDS head and TSN head fields. Figure 5 The headers in
[0043] Figure 6 is a schematic diagram of the overall process in the method for end-to-end communication protection of the present application. This method at least includes steps S610 to S640, which are introduced in detail as follows: S610. Obtain the time information and network load of the current vehicle-mounted communication system; S620. Generate the sequence number of the first-frame message for transmitting data based on time information, and determine the message length of the transmitted data based on network load; S630. After sending the first-frame message to the data receiving end, increment the sequence number of each subsequent frame message in turn; S640. Receive the transmitted data, parse it to obtain the sequence number of each frame message of the parsed transmitted data, determine whether the received data times out or does not time out based on a preset message timing, and determine whether the received data is correct or incorrect according to the incremental change of the sequence number.
[0044] In an embodiment of the present application, the overall process can be carried out according to the following steps: 1. When the transceiver ends start, they each perform initialization. When the sending end sends the first-frame message, obtain the absolute value of the current system time as the sequence number (SEQ) of the first frame to prevent an attacker from obtaining the entire message and causing information leakage.
[0045] 2. When the sending end sends a message, the network load is checked for network load and remaining bandwidth capacity. The length of the data message to be sent is determined according to the load situation, and data messages with higher priorities are guaranteed to be transmitted first according to the message priority to ensure real-time and reliable transmission of the message and avoid message loss.
[0046] 3. For each frame message sent by the sending end, the sequence number (SEQ) is incremented by one. When SEQ exceeds 0xffffffff, the next time it is sent, SEQ takes the initial value and starts counting again in a loop.
[0047] 4. When the receiving end first receives a message, start a receiving timer for message timing. The timing time is determined according to the message timing time. When the reception times out, it means that the data has not been received within the agreed time, and the timeout is replied to the sending end. The sending end retransmits the data message to ensure that no data is missed, and the received data that does not time out is processed in the next step.
[0048] 5. For each frame of data received by the receiving end, the SEQ is compared with the SEQ of the previous frame of data to check whether it is incremented by one. When SEQ does not change incrementally and exceeds the range of the "counting error tolerance threshold" (the "counting error tolerance threshold" is defined by the configuration specification), an error occurs in the data reception. For specific errors, see Figure Six as shown.
[0049] 6. The receiving end parses the "E2E TYPEID" field. The high 4 bits of this field represent the priority of calculation and processing, and the low 12 bits represent the legal ECU target address. Check whether the target address is legal. Take out the CRC check and compare it with the data for CRC check to see if the E2E CRC is equal. If it is equal, the data message is normal; if not, a communication error occurs.
[0050] The following describes the system embodiments of the present application, which can be used to implement the protection method for end-to-end communication in the above embodiments of the present application. For details not disclosed in the system embodiments of the present application, please refer to the method embodiments of the present application above.
[0051] Figure 7 It is a schematic block diagram of a system based on end-to-end communication protection shown in an exemplary embodiment of the present application. This system can also be applied to other exemplary implementation environments and is specifically configured in other devices. The present embodiment does not limit the implementation environment applicable to this device.
[0052] As Figure 7 shown, the system based on end-to-end communication protection includes: An information acquisition module 701, configured to obtain the time information and network load of the current vehicle-mounted communication system; A data sending end 702, configured to generate a sequence number of the first-frame message of the transmitted data based on the time information, determine the message length of the transmitted data based on the network load, and after sending the first-frame message to the data receiving end, sequentially increment the sequence number of each subsequent frame message; A data receiving end 703, configured to receive the transmitted data, perform parsing to obtain the sequence number of each frame message of the parsed transmitted data, determine whether the received data times out or does not time out based on a preset message timing, and determine whether the received data is correct or incorrect according to the incremental change of the sequence number.
[0053] In an embodiment of the present application, it further includes a vehicle body information unit and an electronic control unit. A plurality of the vehicle body information units form an Ethernet ring network. A plurality of electronic control units are classified by function and are connected to the vehicle body information unit nearby. The electronic control units perform vehicle-mounted end-to-end communication through the data sending end and the data receiving end.
[0054] Figure 8 It is a schematic diagram of the architecture of the system based on end-to-end communication protection of the present application. As Figure 8As shown, the electronic and electrical architecture adopts an Ethernet ring network architecture design. The advantages of the ring network architecture are that it supports SOA service orientation and communication channel protection, supports the access of each ECU component according to function classification in the vicinity, and saves wiring harness costs. The CDC (Cockpit Domain Controller, intelligent cockpit) is connected to the cloud through 4G / 5G and WIFI channels, which is the communication channel between the vehicle and the outside world. The cloud in this embodiment is the OTA cloud platform. The full name of OTA is "Over-The-Air technology", that is, over-the-air download technology, which can realize the remote management of software through a mobile communication interface; the VIU (Vehicle Information Unit, body information unit) 1-4 are connected through Ethernet to form a ring network structure. The VDC (Vehicle Dynamics Control) and the CDC are respectively connected to the VIU, and relevant ECU (Electric Control Unit) components are hung under the VIU. The communication methods between the ECUs (ECU1-1... ECU1-n, ECU2-1... ECU2-n, ECU3-1... ECU3-n, ECU4-1... ECU4-n, ECU5-1... ECU5-n) include those that support Ethernet and those that do not support Ethernet (such as those that support CAN communication).
[0055] It can be understood that the overall process in this embodiment is the same as the communication method of the above-mentioned sender and receiver, except that the execution subject is different. Through the above end-to-end protection mechanism, it is possible to ensure the interaction of safety-related function information between each ECU. It can detect errors in communication, attach extended information such as a checksum and a sequence counter to the transmission message, and then transmit it through the network message, ensuring the timeliness, correctness, and integrity of the data.
[0056] The embodiment of the present application also provides an electronic device, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the electronic device implements the image processing method provided in each of the above embodiments.
[0057] Figure 9 The structural schematic diagram of the computer system of the electronic device suitable for implementing the embodiment of the present application is shown. It should be noted that Figure 9 The computer system of the electronic device shown is only an example and should not bring any restrictions to the functions and usage scope of the embodiment of the present application.
[0058] Such as Figure 9As shown, the computer system includes a Central Processing Unit (CPU) 901, which can perform various appropriate actions and processes according to the program stored in the Read-Only Memory (ROM) 902 or the program loaded from the storage section 908 into the Random Access Memory (RAM) 903, such as executing the methods described in the above embodiments. In the RAM 903, various programs and data required for system operation are also stored. The CPU 901, ROM 902, and RAM 903 are connected to each other via a bus 904. An Input / Output (I / O) interface 905 is also connected to the bus 904.
[0059] The following components are connected to the I / O interface 905: an input section 906 including a keyboard, a mouse, etc.; an output section 907 including, for example, a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc. and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read from it can be installed into the storage section 908 as needed.
[0060] Specifically, according to the embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments of the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the Central Processing Unit (CPU) 901, various functions defined in the system of the present application are executed.
[0061] It should be noted that the computer-readable medium shown in the embodiments of the present application may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0062] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0063] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the units themselves.
[0064] Another aspect of this application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the image processing method described above is implemented. The computer-readable storage medium can be included in the electronic device described in the above embodiments, or can exist separately without being assembled into the electronic device.
[0065] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0066] The above embodiments are only used to exemplarily illustrate the principles and effects of this application, rather than to limit this application. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of this application. Therefore, all equivalent modifications or changes completed by those with ordinary knowledge in the technical field without departing from the spirit and technical ideas disclosed in this application should still be covered by the claims of this application.
[0067] In the corresponding drawings of the above embodiments, the connection lines can represent the connection relationships between various components. To indicate more constituent signal paths and / or one or more ends of some lines have arrows to indicate the main information flow direction. As a kind of identifier, the connection lines are not a limitation on the solution itself, but using these lines in combination with one or more exemplary embodiments helps to more easily connect circuits or logic units. Any represented signal (determined by design requirements or preferences) can actually include one or more signals that can be transmitted in any direction and can be implemented with any appropriate type of signal scheme.
[0068] In the above embodiments, unless otherwise specified, when using serial numbers such as "first" and "second" to describe common objects, it only indicates different instances of the same object, rather than indicating that the objects to be described must be in a given order, whether in terms of time, space, sorting, or any other way.
[0069] In the above embodiments, the mention of "this embodiment", "an embodiment", "another embodiment", or "other embodiments" in the specification means that the specific features, structures, or characteristics described in connection with the embodiments are included in at least some embodiments, but not necessarily all embodiments. Multiple occurrences of "this embodiment", "an embodiment", or "another embodiment" do not necessarily all refer to the same embodiment. If the specification describes that a component, feature, structure, or characteristic "may", "might", or "could" be included, then that specific component, feature, structure, or characteristic is not necessarily included. If the specification or claims refer to "a" element, it does not mean there is only one element. If the specification or claims refer to "an additional" element, it does not exclude the existence of more than one additional element.
[0070] In the above embodiments, although the present application has been described in connection with specific embodiments of the present application, many substitutions, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other storage structures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed. Embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims.
[0071] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments.
[0072] The present application can be used in numerous general-purpose or special-purpose computing system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on.
[0073] The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
Claims
1. A method based on end-to-end communication protection, characterized in that: include: Obtain the time information and network load of the current vehicle communication system; Generate a sequence number of a first frame message of the transmission data based on the time information, and determine the message length of the transmission data based on the network load; the message length is configured in a length field in a frame structure of end-to-end communication, and the sequence number is configured in a sequence number field in the frame structure; After sending the first frame message to the data receiving end, the sequence number of each subsequent frame message is incremented in sequence.
2. The method based on end-to-end communication protection according to claim 1, characterized in that: The frame structure also includes: The protocol type field is used to indicate the protocol type of the transmitted data message, and the protocol type includes the Ethernet-based diagnostic communication protocol DoIP and the IP-based extensible service-oriented middleware SOMEIP; The protocol header field is used to configure the header of the corresponding protocol.
3. The method based on end-to-end communication protection according to claim 1, characterized in that: The method further comprises: If the sequence number exceeds a preset range threshold, the sequence number is regenerated according to the current time information.
4. The method based on end-to-end communication protection according to claim 1 or 2, characterized in that: The frame structure also includes a type identification field, and the type identification field includes a first field and a second field; before sending the first frame message to the data receiving end, it also includes: The first field is configured to represent the message calculation and processing priority; and the second field is configured to represent the destination address, so that the data receiving end determines whether the destination address is legal based on the resolved address field.
5. The method based on end-to-end communication protection according to claim 1 or 2, characterized in that: Generating a sequence number of a first frame message of the transmission data based on the time information, and determining a message length of the transmission data based on the network load, including: Perform hash calculation on the time of the current vehicle communication system to obtain the sequence number of the first frame message; The current remaining bandwidth capacity of the vehicle-mounted communication system is detected, and the message length of the transmission data is determined based on the network load and the remaining bandwidth capacity.
6. A method based on end-to-end communication protection, characterized in that: include: Receive the transmission data from the data sending end, parse it, and obtain the sequence number of each frame message of the parsed transmission data; Based on the preset message timing, determine whether the received data has timed out or not; Whether the received data is correct or incorrect is determined based on the serial number of the parsed first frame message and the incremental change of the serial number of each subsequent frame message, the serial number of the first frame message is generated based on the vehicle communication system time when the data sending end sends the data, and the message length of the transmitted data is determined based on the network load; the message length is configured in the length field in the frame structure of end-to-end communication, and the serial number is configured in the sequence number field in the frame structure.
7. The method based on end-to-end communication protection according to claim 6, characterized in that: The method further comprises: The sequence number of each received message frame is compared with the sequence number of the previous message frame. If it is incremented by one, the received data is determined to be correct; if it is not incremented by one and the data exceeds the preset counting fault tolerance threshold, the received data is determined to be wrong.
8. The method based on end-to-end communication protection according to claim 6, characterized in that: After receiving the transmission data from the data sending end and parsing it, the method further includes: Acquire a type identification field and a check field of the parsed transmission data, wherein the type identification field includes a first field for indicating a message calculation processing priority and a second field for indicating a destination address; Performing a first check on the type identification field, and performing a second check on the first check result and the data part in the frame structure of the end-to-end communication to obtain a second check result; The second check result is compared with the check field, and if the comparison results are the same, it is determined that the transmission data is normal.
9. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the electronic device to implement the method based on end-to-end communication protection as described in any one of claims 1 to 5, or implement the method based on end-to-end communication protection as described in any one of claims 6 to 8.
10. A computer-readable storage medium, characterized in that: Computer-readable instructions are stored thereon, and when the computer-readable instructions are executed by a processor of a computer, the computer is caused to execute the method based on end-to-end communication protection as described in any one of claims 1 to 5, or to execute the method based on end-to-end communication protection as described in any one of claims 6 to 8.
Citation Information
Patent Citations
Code stream transmission method and device
CN109617891A
Vehicle communication method and communication device
CN112585931A
Message transmission method and device applied to automobile, equipment and medium
CN116248231A
CAN communication transmission method and transmission device
CN118214621A
Video Transmission System
US20200280750A1