Communication node determination method and device of vehicle end detection system, and vehicle
Through multi-main detection technology, combined with the dual reliability detection of the server and vehicle-side detection system, it ensures that only nodes with high credibility become master nodes in the vehicle intrusion detection system, which solves the problems of high protection levels and high resource consumption in traditional systems, and achieves a balance between security performance and resource utilization.
Patent Information
- Application Number
- CN202510805139.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-06-16
AI Technical Summary
Traditional vehicle intrusion detection systems have extremely high information security protection capabilities in master-slave deployments, while distributed deployments consume a lot of resources and lack effective solutions.
Multi-master detection technology is adopted to conduct dual reliability detection on the current node through the server, ensuring that only strictly verified electronic control units can be set as master nodes, and node confirmation is used for node declaration messages, and the master node is quickly replaced if necessary.
It improves the safety performance and resource allocation efficiency of the vehicle intrusion detection system, balances protection level and resource consumption, and enhances the adaptability and reliability of the system.
Smart Images

Figure CN120455145A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of network security technology, and in particular to a method, device, and vehicle for determining a communication node of a vehicle-side detection system. Background Art
[0002] With the development of intelligent connected vehicles, vehicles are becoming increasingly intelligent, placing increasing demands on network security. Traditional vehicle intrusion detection systems typically employ either a master-slave or distributed deployment model. Because master-slave deployments offer extremely high information security protection, if a vehicle is compromised and the master node of the system fails, even if the remaining slave nodes are still alive, they will be unable to upload data. In contrast, distributed deployments require nodes that directly connect to the server for data transmission, resulting in significant resource consumption.
[0003] There is currently no effective solution to the technical problems of the extremely high information security protection capabilities of the above-mentioned master-slave deployed vehicle intrusion detection system and the extremely high resource consumption of the distributed deployed vehicle intrusion detection system. Summary of the Invention
[0004] The embodiments of the present application provide a method, device and vehicle for determining the communication nodes of a vehicle-side detection system, aiming to improve the technical problems of high protection level and high resource consumption of vehicle intrusion detection systems in related technologies.
[0005] According to one aspect of an embodiment of the present invention, a method for determining a communication node of a vehicle-side detection system is provided, comprising: performing a credibility check on a current node based on a server to obtain a first detection result, wherein the current node is an electronic control unit in the vehicle-side detection system; in response to the first detection result satisfying a preset condition, performing a credibility check on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; in response to the second detection result satisfying the preset condition, controlling the current node to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; in response to the sending result indicating that the remaining nodes have received the master node declaration message, setting the current node as the master node, wherein the master node is used to communicate with the server.
[0006] Through the above technical solution as a whole, combined with the dual detection of the server and vehicle-side detection systems, and by judging whether the remaining nodes have received the master node declaration message, it is ensured that only strictly verified and highly reliable electronic control units can be set as master nodes, significantly improving the safety performance of the vehicle intrusion detection system and optimizing resource allocation.
[0007] According to another aspect of an embodiment of the present invention, a communication node determination device of a vehicle-side detection system is also provided, including: a first detection module, the first detection module is used to perform credibility detection on the current node based on the server to obtain a first detection result, wherein the current node is an electronic control unit in the vehicle-side detection system; a second detection module, the second detection module is used to perform credibility detection on the current node based on the vehicle-side detection system in response to the first detection result meeting the preset condition to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; a sending module, the sending module is used to control the current node to send a master node declaration message to the remaining nodes in response to the second detection result meeting the preset condition to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; a setting module, the setting module is used to set the current node as the master node in response to the sending result indicating that the remaining nodes have received the master node declaration message, wherein the master node is used to communicate with the server.
[0008] According to another aspect of an embodiment of the present invention, a vehicle is also provided, comprising: a memory storing an executable program; and a processor for running the program, wherein when the program runs, the communication node determination method of the vehicle-side detection system in any of the above items is executed.
[0009] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided, in which a computer program is stored, wherein the computer program is configured to execute the communication node determination method of the vehicle-side detection system in any of the above items when running on a computer or processor.
[0010] According to another aspect of an embodiment of the present invention, an electronic device is also provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the communication node determination method of the vehicle-side detection system in any of the above items.
[0011] In an embodiment of the present invention, a multi-master detection technology is adopted, and a first detection result is obtained by performing a credibility check on the current node based on a server, wherein the current node is an electronic control unit in a vehicle-side detection system; in response to the first detection result satisfying a preset condition, a credibility check is performed on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; in response to the second detection result satisfying the preset condition, the current node is controlled to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; in response to the sending result indicating that the remaining nodes have received the master node declaration message, the current node is set as the master node, wherein the overall technical solution of the master node being used to communicate with the server achieves the purpose of improving system adaptability, reliability and resource utilization efficiency, thereby achieving the technical effect of balancing resource consumption and information security protection capabilities, and thus solving the technical problems of high protection level and high resource consumption of vehicle intrusion detection systems in related technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 This is a structural diagram of a distributed deployment detection system in the prior art;
[0013] Figure 2 This is a structural diagram of a master-slave deployment detection system in the prior art;
[0014] Figure 3 This is a flowchart of a method for determining a communication node of a vehicle-side detection system provided by an embodiment of the present application;
[0015] Figure 4 This is a system structure diagram of the multi-active detection technology provided by an embodiment of the present application;
[0016] Figure 5 This is a flowchart of a master node determination rule provided by an embodiment of the present application;
[0017] Figure 6 This is a structural diagram of a communication node determination device of a vehicle-side detection system provided in one embodiment of the present application;
[0018] Figure 7 is a structural diagram of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0019] In order to make the technical problems, technical solutions and beneficial effects solved by this application more clearly understood, this application is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0020] In order to help those skilled in the art better understand the present technical solution, the following terminology is explained:
[0021] An intrusion detection system (IDS) is a network security device used to monitor anomalies in a network or computer system and generate warnings. In connected vehicles, IDSs monitor the vehicle's operating system, external interfaces, and network connections to promptly detect and report potential security threats or intrusions.
[0022] In an intrusion detection system, credibility assessment is a quantitative evaluation of a node's security status. By analyzing whether a node has a history of being attacked, the type of attack, and its severity, a node is assigned a corresponding credibility value. Nodes with high credibility are more likely to be selected as master nodes.
[0023] The cloud-based vehicle security operation center is a cloud-based vehicle security monitoring and response platform that communicates with the on-board intrusion detection system to collect security event logs, conduct data analysis, predict future network security situations, and guide vehicles to take corresponding safety measures.
[0024] Electronic Control Units (ECUs) are used to control various automotive subsystems, such as the engine, braking system, and entertainment system. In the field of intrusion detection, ECUs can also integrate intrusion detection capabilities and function as slave or master nodes to monitor and respond to potential cyberattacks.
[0025] Figure 1 This is a structural diagram of a distributed deployment detection system in the prior art, such as Figure 1 As shown, each component node has its own intrusion detection system deployed independently. The intrusion detection system interacts with the vehicle security operations center system in the cloud on a component-by-component basis. The disadvantages of a distributed detection system are high resource consumption and high cloud concurrency. For example, if each vehicle has several intrusion detection system nodes deployed, there will be several concurrent connections to the cloud, resulting in system redundancy. The advantage is low information security protection. If a vehicle is attacked and an intrusion detection system node is shut down, other nodes remain active and can complete data collection and upload operations.
[0026] Figure 2 This is a diagram of the master-slave deployment detection system structure in the prior art, such as Figure 2As shown in the figure, the vehicle's intrusion detection system is deployed using a master-slave model across its components. Only one node is selected on the vehicle as the master node, and all other nodes are slaves. Data collected by the slave nodes is transmitted to the master node via bus communication. The master node then communicates with the cloud-based vehicle security operations center system, including data upload and download. This master-slave deployment significantly reduces resource consumption for distributed deployments. The concurrency of vehicle-to-cloud communication is reduced from three links to one, significantly reducing the concurrency of the cloud system. However, this approach has the disadvantage of extremely high information security protection capabilities. If a vehicle is attacked and the master node's intrusion detection system is shut down, even if the remaining slave nodes survive, they will be unable to complete data collection and upload operations.
[0027] An embodiment of the present application provides a method for determining a communication node of a vehicle-side detection system, including: performing a credibility check on a current node based on a server to obtain a first detection result, wherein the current node is an electronic control unit in the vehicle-side detection system; in response to the first detection result satisfying a preset condition, performing a credibility check on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; in response to the second detection result satisfying the preset condition, controlling the current node to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; in response to the sending result indicating that the remaining nodes have received the master node declaration message, setting the current node as the master node, wherein the master node is used to communicate with the server.
[0028] Through the above technical solution as a whole, combined with the dual detection of the server and vehicle-side detection systems, and by judging whether the remaining nodes have received the master node declaration message, it is ensured that only strictly verified and highly reliable electronic control units can be set as master nodes, significantly improving the safety performance of the vehicle intrusion detection system and optimizing resource allocation.
[0029] Figure 3 This is a flow chart of a method for determining a communication node of a vehicle-side detection system provided by an embodiment of the present application. Figure 3 As shown, the following steps are included:
[0030] Step S30: performing a credibility check on the current node based on the server to obtain a first test result, wherein the current node is an electronic control unit in the vehicle-side detection system;
[0031] In this embodiment of the present invention, the server can be understood as a cloud-based server cluster or platform, primarily responsible for collecting, analyzing, and managing large amounts of safety data from vehicles. The server possesses powerful data processing capabilities and storage resources, capable of executing complex algorithms to assess the trustworthiness of nodes. The server interacts with the vehicle's on-board detection system via the network, receiving and analyzing security event logs and other vehicle status information to determine whether each node in the vehicle-based detection system is in a safe state.
[0032] The current node can be understood as the electronic control unit that is undergoing credibility testing. For example, the current node can be the master node that has been initially negotiated and determined, or any electronic control unit that needs to be re-evaluated under abnormal circumstances, which is not limited here.
[0033] Credibility testing can be understood as a safety assessment of any node. This involves analyzing the node's current security status and examining historical security events, intrusion detection records, and other relevant indicators to determine whether the node has been attacked and the extent of the attack. The credibility test results determine whether the node can continue to function as a master node or whether it should be downgraded to a slave node.
[0034] The first test result can be understood as a quantitative assessment of the server's credibility after testing the current node. The first test result reflects the security status of the current node. For example, the first test result is usually expressed in a graded manner, such as from very high (such as 5 points) to very low (such as 0 points), to determine whether the current node is suitable for becoming a master node. This is not limited here.
[0035] The on-board detection system can be understood as a network monitoring and intrusion detection system deployed within the vehicle. It consists of multiple electronic control units (ECUs), which monitor the vehicle network for abnormal behavior, such as packet anomalies, communication failures, or malicious code injection. By monitoring and analyzing network traffic and system behavior in real time, the on-board detection system can identify security threats and take appropriate measures, such as reporting alerts or blocking malicious communications.
[0036] The server-based credibility check of the current node and the resulting first detection result can be understood as a comprehensive security assessment of the current node on the vehicle performed by the server. The first detection result reflects whether the current node has been attacked, as well as the type and severity of the attack, thereby determining the node's credibility level.
[0037] In the embodiment of the present invention, the server performs credibility detection on the current node to obtain a first detection result, aiming to determine the security status and credibility of the current node, thereby ensuring the security of the system and the reliability of the data transmission process.
[0038] Step S32: In response to the first detection result satisfying a preset condition, a credibility check is performed on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period;
[0039] In an embodiment of the present invention, the preset condition can be understood as a specific requirement that the credibility detection result of the server on the current node needs to meet in order to determine whether to further perform credibility detection on the current node based on the vehicle-side detection system.
[0040] The second detection result can be understood as the result of further credibility testing of the current node by the vehicle-side detection system. The second detection result provides a second confirmation of the current node's safety status based on the vehicle-side real-time monitoring data and a more detailed safety assessment.
[0041] The preset period can be understood as a time window. During this period, the server continuously monitors the current node's activity and security status to assess its trustworthiness. The selection of the preset period requires a comprehensive consideration of the system's response speed, the node's activity frequency, and the potential duration of the attack. For example, the preset period can be set to one week to ensure that the assessment covers sufficient historical behavior and environmental changes, but this is not a limitation here.
[0042] The preset threshold can be understood as a standard value set by the system when evaluating the current node's trustworthiness, used to determine whether the node's security status meets the requirements for being a master node. For example, the trustworthiness level can range from 0 to 5, with 5 indicating no attack and 0 indicating a severe attack. The preset threshold might be set to 2, meaning that the node will only be subject to further vehicle-side testing if the server-assessed trustworthiness level is greater than 2. This is not a restriction here.
[0043] In response to the first detection result meeting the preset conditions, the credibility check is performed on the current node based on the vehicle-side detection system, and the second detection result is obtained. It can be understood that when the server preliminarily evaluates that the first detection result of the current node shows that the node has not experienced a serious security incident within the preset period, and the credibility value is higher than the preset threshold, the credibility check is performed again on the security status of the current node based on the vehicle-side detection system to obtain the second detection result.
[0044] In an embodiment of the present invention, in response to the first detection result meeting the preset conditions, a credibility check is performed on the current node based on the vehicle-side detection system to obtain a second detection result, thereby utilizing the complementary advantages of the cloud-side and vehicle-side detection systems to ensure that the credibility of the master node is not only based on the analysis of historical data, but also on the confirmation of real-time security status, thereby enhancing the application effect of multi-master detection technology in the field of safety protection of intelligent connected vehicles.
[0045] Step S34: In response to the second detection result meeting the preset condition, controlling the current node to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit;
[0046] In an embodiment of the present invention, the master node declaration message can be understood as a communication message sent by the current node that is confirmed to have sufficient credibility in the vehicle-side detection system. The main content of the master node declaration message is to declare that the current node has been selected as the master node, indicating that the current node will assume the responsibility of managing data collection, aggregation and uploading to the cloud. The master node declaration message contains the identification information of its own node, the credibility level, and other necessary information that may be used to confirm its master node identity. The remaining nodes that receive this message will adjust their own status according to the content of the message to cooperate with the master node in subsequent data processing and security monitoring.
[0047] The "send result" can be understood as the response of the remaining nodes in the system to the master node declaration message sent by the current node. For example, a successful send result means that the remaining nodes have received and understood the master node declaration message, and will recognize the current node's master node status and begin transferring data to it or performing other slave node tasks. A failed send result, on the other hand, may indicate a communication issue or that some nodes are unresponsive, requiring further troubleshooting or re-election of the master node, which is not limited here.
[0048] In response to the second detection result meeting the preset conditions, the current node is controlled to send the master node declaration message to the remaining nodes. The sending result can be understood as when the second detection result obtained by the vehicle-side detection system performing a credibility check on the current node shows that the credibility of the node meets the preset conditions, indicating that the current node is sufficient to serve as the master node. At this time, the system will control the current node to send the master node declaration message to the remaining nodes in the system through the vehicle's internal network (such as CAN bus, Ethernet, etc.) to obtain the sending result.
[0049] In an embodiment of the present invention, in response to the second detection result meeting the preset conditions, the current node is controlled to send a master node declaration message to the remaining nodes to obtain the sending result, thereby enhancing the system's response speed and resistance to security incidents, and helping to protect intelligent connected vehicles from network threats.
[0050] Step S36: In response to the sending result indicating that the remaining nodes have received the master node declaration message, the current node is set as the master node, where the master node is used to communicate with the server.
[0051] In an embodiment of the present invention, in response to the sending result indicating that the remaining nodes have received the master node declaration message, setting the current node as the master node can be understood as, when the system confirms that the sending result shows that all the remaining nodes have successfully received the master node declaration message sent by the current node, it indicates that the credibility and security status of the current node have met the requirements of being a master node, and the system will officially set the current node as the master node.
[0052] In an embodiment of the present invention, in response to the sending result indicating that the remaining nodes have received the master node declaration message, the current node is set as the master node, ensuring that the system can select the most suitable individual as the master node among the security nodes. Even if some nodes are attacked or abnormal, the overall security and functional integrity of the system can be maintained through rapid dynamic adjustments.
[0053] Figure 4 This is a system structure diagram of the multi-active detection technology provided by an embodiment of the present application. Figure 4 As shown, multiple nodes are deployed on a vehicle, and the system selects one node as the master node to aggregate and upload data. During normal vehicle operation, the master node, determined by the system, controls the slave nodes to complete data collection and connects to the cloud-based vehicle security operation center system to upload data, achieving a technical effect of balancing resource consumption and information security protection capabilities.
[0054] In an embodiment of the present invention, a multi-master detection technology is adopted, and a first detection result is obtained by performing a credibility check on the current node based on a server, wherein the current node is an electronic control unit in a vehicle-side detection system; in response to the first detection result satisfying a preset condition, a credibility check is performed on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; in response to the second detection result satisfying the preset condition, the current node is controlled to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; in response to the sending result indicating that the remaining nodes have received the master node declaration message, the current node is set as the master node, wherein the overall technical solution of the master node being used to communicate with the server achieves the purpose of improving system adaptability, reliability and resource utilization efficiency, thereby achieving the technical effect of balancing resource consumption and information security protection capabilities, and thus solving the technical problems of high protection level and high resource consumption of vehicle intrusion detection systems in related technologies.
[0055] Optionally, the communication node determination method of the vehicle-side detection system further includes: in response to the current node being invaded, determining a new master node from the remaining nodes.
[0056] In an embodiment of the present invention, in response to the current node being invaded, a new master node is determined from the remaining nodes. It can be understood that if the current node is found to be invaded, the node can no longer continue to perform normal security functions and data management duties. In order to avoid the negative impact of the system due to the failure of the master node, the vehicle-side detection system will immediately activate the emergency response mechanism and re-determine a new master node from the remaining nodes.
[0057] In an embodiment of the present invention, in response to the current node being invaded, a new master node is determined from the remaining nodes. The system can quickly adapt to security threats, avoid system paralysis caused by failure of a single node, and ensure the continuity of data collection and security monitoring.
[0058] Optionally, in step S30, performing a credibility check on the current node based on the server to obtain a first detection result includes the following steps:
[0059] Step S301: obtaining an information security record based on the server, wherein the information security record is an analysis result of an abnormality of any node in the vehicle-side detection system;
[0060] Step S302: determining a first credibility value of the current node based on the information security record;
[0061] Step S303: compare the first credibility value with a preset threshold to obtain a first detection result.
[0062] In this embodiment of the present invention, information security records can be understood as a series of data collected and analyzed by the server. Information security records reflect abnormal conditions and security events at any node in the vehicle-side detection system over a period of time. For example, information security records include various security indicators, such as the type of attack suffered by the node, the frequency and intensity of the attack, the system response and recovery status, and log analysis results, which are not limited here.
[0063] The first credibility value can be understood as a quantitative indicator calculated based on information security records, which is used to evaluate the historical safety factor of the current node.
[0064] Server-based acquisition of information security records can be understood as the server collecting and analyzing security status information from all nodes in the vehicle-side detection system to form an information security record. For example, the server receives data from vehicle-side nodes, including but not limited to log files, exception reports, and security event records; performs statistical analysis on the collected data to identify patterns, trends, and potential security risks; and, based on the analysis results, generates a detailed information security record to provide a basis for subsequent credibility assessments. This is not a limitation here.
[0065] Determining the first credibility value of the current node based on the information security record can be understood as that after obtaining the information security record, the system will determine the first credibility value of the current node based on the information in the information security record and a preset credibility calculation rule.
[0066] Comparing the first credibility value with the preset threshold to obtain the first detection result can be understood as the system comparing the calculated first credibility value with the preset threshold to determine whether the node meets the preliminary conditions for becoming a master node and obtain the first detection result.
[0067] In this embodiment of the present invention, a first credibility value for the current node is determined based on information security records collected by the server. This credibility value is then compared with a preset threshold to determine whether the current node is suitable for serving as a master node. By quantifying a node's historical security performance and dynamically adjusting its node attributes within the system, this effectively balances resource consumption with information security protection, enhancing the robustness and security of the vehicle intrusion detection system.
[0068] Optionally, in step S32, performing a credibility check on the current node based on the vehicle-side detection system to obtain a second detection result includes the following steps:
[0069] Step S321: obtaining an information security log of the current node based on the vehicle-side detection system, wherein the information security log is used to record abnormal conditions of the current node;
[0070] Step S322: determining a second credibility value of the current node based on the information security log;
[0071] Step S323: Compare the second credibility value with a preset threshold to obtain a second detection result.
[0072] In this embodiment of the present invention, the information security log can be understood as a security record generated by the vehicle-side detection system, which is used to record the immediate abnormal conditions and security events of the current node. For example, the information security log includes but is not limited to system operation anomalies, network activity anomalies, intrusion detection warnings, etc.
[0073] The second credibility value can be understood as a quantitative indicator calculated based on the information security log, which is used to evaluate the safety factor of the current node at this time.
[0074] Obtaining the information security log of the current node based on the vehicle-side detection system can be understood as the vehicle-side detection system recording and capturing all abnormal behaviors and security events of the current node in real time during operation to form an information security log.
[0075] Determining the second credibility value of the current node based on the information security log can be understood as the system obtaining the second credibility value of the current node based on the preset credibility calculation rules according to the type and severity of abnormal events in the information security log and the node's response to these events.
[0076] Comparing the second credibility value with the preset threshold to obtain the second detection result can be understood as the system comparing the calculated second credibility value with the preset threshold to determine whether the security level of the current node meets the standards of being a master node, thereby obtaining the second detection result.
[0077] In an embodiment of the present invention, an information security log of abnormal conditions of the current node is obtained through the vehicle-side detection system, and a second credibility value of the current node is determined based on log analysis. Finally, by comparing the second credibility value with a preset threshold, a second detection result is obtained, ensuring that the main node is always the safest choice, thereby achieving dual protection of security and resource optimization.
[0078] Optionally, the communication node determination method of the vehicle-side detection system further includes the following steps:
[0079] Set the remaining nodes as slave nodes;
[0080] Control any slave node to send a slave node declaration message to nodes other than any slave node, wherein the slave node declaration message is used to declare any node among the remaining nodes as a slave node.
[0081] In the embodiment of the present invention, the slave node declaration message can be understood as a communication message sent by the slave node to other nodes in the system, which is used to declare and confirm the slave node status.
[0082] Setting the remaining nodes as slave nodes can be understood as follows: after the master node is determined, the other nodes in the system are automatically or through instructions configured as slave nodes. Slave nodes are primarily used to assist the master node, performing tasks such as data collection and preliminary analysis, and transmitting this information to the master node via the system bus.
[0083] Controlling any slave node to send a slave node declaration message to nodes other than any slave node can be understood as, if any node is identified as a slave node, the slave node will send a slave node declaration message to all nodes in the system.
[0084] In an embodiment of the present invention, after determining the master node through negotiation, the system sets other nodes as slave nodes and triggers any slave node to broadcast a slave node declaration message, ensuring a clear network structure and optimized communication paths, which not only improves data transmission efficiency but also enhances the system's ability to quickly recover when the master node fails.
[0085] Optionally, the communication node determination method of the vehicle-side detection system further includes the following steps:
[0086] In response to the first detection result not meeting the preset condition, performing a credibility detection on a next node of the current node based on the server to obtain a third detection result;
[0087] Determine a master node in the vehicle-side detection system based on the third detection result; or
[0088] In response to the second detection result not meeting the preset condition, performing a credibility detection on a node next to the current node based on the server to obtain a fourth detection result;
[0089] Determine the master node in the vehicle-side detection system based on the fourth detection result.
[0090] In an embodiment of the present invention, the third detection result can be understood as the result obtained by the server after performing a credibility check on the next node of the current node when the current master node is considered untrustworthy or unable to serve as the master node by the server, which is used to determine whether the next node is sufficiently safe and reliable.
[0091] The fourth detection result can be understood as the result produced by the server performing a credibility assessment on the next node if the vehicle-side detection system determines that the current node does not meet the preset conditions.
[0092] In response to the first detection result not meeting the preset conditions, the server performs a credibility check on the next node of the current node, and the third detection result is obtained. It can be understood that if the credibility value of the currently selected main node fails to pass the server's detection, the system uses the server to perform a credibility assessment on the next node to obtain the third detection result.
[0093] Determining the master node in the vehicle-side detection system based on the third test result can be understood as: based on the third test result, the system will analyze and determine the security status and credibility of the next node. If the third test result shows that the node meets the conditions for becoming a master node, the vehicle-side detection system will then conduct another credibility check on this node. If the third test result shows that the node does not meet the conditions for becoming a master node, the server will continue to conduct credibility assessments on the next candidate node until the master node is selected.
[0094] In response to the second detection result not meeting the preset conditions, the server performs a credibility check on the next node of the current node, and obtains the fourth detection result. It can be understood that when the vehicle-side detection system performs a credibility check on the current node, the credibility value of the current node fails to meet the preset conditions, that is, the current node may have been attacked or has a security vulnerability. The server performs credibility verification on the next node and obtains the fourth detection result.
[0095] Determining the master node in the vehicle-side detection system based on the fourth test result can be understood as follows: based on the fourth test result, the system will analyze and determine the security status and credibility of the next node. If the fourth test result shows that the node meets the conditions for becoming a master node, the vehicle-side detection system will then conduct another credibility check on this node. If the fourth test result shows that the node does not meet the conditions for becoming a master node, the server will continue to conduct credibility assessments on the next candidate node until the master node is selected.
[0096] In this embodiment of the present invention, if the server fails the credibility check for the current node, the server immediately evaluates the credibility of the next node, resulting in a third test result. Alternatively, if the current node fails the credibility check for the vehicle-side detection system, the server immediately evaluates the credibility of the next node, resulting in a fourth test result. Based on the third or fourth test results, the vehicle-side detection system designates a new master node, enabling immediate adjustment and optimization of security mechanisms. This effectively enhances the system's self-healing capabilities and overall security in the face of threats, maintaining the continuity and stability of data transmission.
[0097] Optionally, the communication node determination method of the vehicle-side detection system further includes the following steps:
[0098] In response to the sending result indicating that any of the remaining nodes has not received the master node declaration message, performing a credibility check on a next node of the current node based on the server to obtain a fifth detection result;
[0099] Determine the master node in the vehicle-side detection system based on the fifth detection result.
[0100] In an embodiment of the present invention, the fifth detection result can be understood as the result of the credibility check performed by the server on the next node when the current node passes the detection of the server and the vehicle-side detection system, but fails to successfully send the master node declaration message to all other nodes, or other nodes do not receive the declaration message.
[0101] In response to the sending result indicating that any of the remaining nodes has not received the master node declaration message, the server performs a credibility check on the next node of the current node, and the fifth detection result can be understood as follows: if the current node attempts to send its identity declaration message to all other nodes, if it is detected that at least one slave node fails to correctly receive this information, then the current node cannot serve as the master node, and the server will immediately perform a credibility analysis on the next node to obtain the fifth detection result.
[0102] Determining the master node in the vehicle-side detection system based on the fifth test result can be understood as follows: based on the fifth test result, the system will analyze and determine the security status and credibility of the next node. If the fifth test result shows that the node meets the conditions for becoming a master node, the vehicle-side detection system will then conduct another credibility check on this node. If the fifth test result shows that the node does not meet the conditions for becoming a master node, the server will continue to conduct credibility assessments on the next candidate node until the master node is selected.
[0103] In this embodiment of the present invention, if the master node declaration message sent by the current node is not received and confirmed by all other nodes, the cloud immediately performs a credibility check on the next node, obtaining a fifth credibility check result. Based on this credibility check result, the system selects a node whose credibility value meets the preset criteria as the new master node, enhancing system security resilience and data transmission continuity, and improving overall risk resistance.
[0104] Optionally, before performing credibility detection on the current node based on the server to obtain the first detection result, the communication node determination method of the vehicle-side detection system further includes the following steps:
[0105] Initialize the server and vehicle-side detection system;
[0106] Establish a communication connection between the server and the vehicle-side detection system.
[0107] In the embodiments of the present invention, initializing the server and vehicle-side detection system can be understood as the process of checking and configuring the server and vehicle-side detection system's internal status and functionality upon system startup or reconfiguration to ensure proper operation and execution of their designated security monitoring tasks. The initialization process may include loading software, updating the security rule base, performing self-tests to confirm the integrity of hardware and software components, and setting parameters for communication with other nodes in the network, all of which are not limited herein.
[0108] Establishing a communication connection between the server and the vehicle-side detection system can be understood as establishing a reliable data exchange path between the vehicle-side detection system and the server, enabling the two systems to send and receive information in real time or periodically. For example, the data exchanged between the server and the vehicle-side detection system includes, but is not limited to, security logs, threat intelligence, system status updates, and control instructions. Establishing a communication connection is fundamental to enabling remote monitoring and response, data synchronization, and system management functions. It ensures that the vehicle-side detection system can promptly upload detected security incidents, while the cloud system can distribute the latest security policies or updates, keeping the vehicle's network security defense mechanisms up to date.
[0109] In an embodiment of the present invention, by initializing the server and the vehicle-side detection system and establishing a communication connection between the two, it is possible to ensure that their functions are complete and the security rules are synchronized, thereby achieving real-time data exchange and command response, enhancing the vehicle network security monitoring capability, quickly responding to threats, and improving the overall protection efficiency of the system.
[0110] Figure 5 This is a flow chart of the master node determination rule provided by an embodiment of the present application. Figure 5 As shown, after each electronic control unit in the vehicle-side detection system completes initialization and cloud registration, the server needs to detect whether the vehicle has been attacked within the past week (not limited here), whether the current node can act as a master node to report data, and determine whether the node is a trusted node. Only nodes determined to be trusted can upload data. The vehicle-side detection system checks the vehicle's own information security log to determine whether it has been attacked and whether the current node is a trusted node. If the current node is a trusted node, it is designated as the master node and a communication message containing the current node code (such as ECU1) is sent to other nodes, notifying ECU1 of its status as the master node. After receiving the notification, the remaining nodes are set as slave nodes and control any slave node to send slave node messages. If the master node in the vehicle-side detection system is shut down or experiences an abnormality (such as loss of communication), the system performs a credibility check on the remaining nodes and determines a new master node. The security status of the electronic control unit with the abnormal master node is then transmitted to the bus. The system tends to select nodes that have not been attacked or nodes that have suffered the least attack as master nodes. When the master node function is activated, the master node will summarize the data collected from the nodes and upload them to the server.
[0111] For example, Table 1 shows information for multiple electronic control units. As shown in Table 1, Byte 0 indicates the address of ECU 1, which is 0xE1. Byte 1 is the master / slave node identifier, with 1 indicating a master node and 0 indicating a slave node. Byte 2 indicates the trustworthiness of the electronic control unit. Bytes 2 through Byte 7 are reserved for adding new functions.
[0112] Table 1
[0113] Byte0 Byte1 Byte2 Byte3 Byte4 Byte5 Byte6 Byte7 ECU1 0xE1 1 0x00 0xAA 0xAA 0xAA 0xAA 0xAA ECU2 0xE2 0 0x00 0xAA 0xAA 0xAA 0xAA 0xAA ECUn 0xEn 0 0x00 0xAA 0xAA 0xAA 0xAA 0xAA
[0114] For example, in order to select nodes that have not been attacked or have suffered the least attack, it is necessary to classify and grade abnormal behaviors detected by the vehicle-side detection system. Table 2 shows the credibility assessment of nodes under different circumstances. As shown in Table 2, the credibility value is set to 6 levels from 0 to 5. When the certificate file is changed, the node function of the vehicle-side detection system is disabled, etc., it is judged to have suffered a serious attack. Even if the node is capable of uploading data, its credibility is 0. When the credibility drops to 2 or below, it will not be selected as the main node. When the credibility of all nodes on the vehicle drops below 2, the vehicle is judged to have suffered a serious attack and needs to go through the information security disposal process.
[0115] Table 2
[0116]
[0117] The present application also provides a communication node determination device 600 of a vehicle-side detection system. Figure 6 , including: a first detection module 601, the first detection module is used to perform credibility detection on the current node based on the server to obtain a first detection result, wherein the current node is an electronic control unit in the vehicle-side detection system; a second detection module 602, the second detection module is used to respond to the first detection result meeting the preset condition, perform credibility detection on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; a sending module 603, the sending module is used to respond to the second detection result meeting the preset condition, control the current node to send a master node declaration message to the remaining nodes, and obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; a setting module 604, the setting module is used to set the current node as the master node in response to the sending result indicating that the remaining nodes have received the master node declaration message, wherein the master node is used to communicate with the server.
[0118] Furthermore, the communication node determination device of the vehicle-side detection system also includes a determination module for determining a new master node from the remaining nodes in response to the current node being invaded.
[0119] Furthermore, the first detection module 601 is also used to obtain information security records based on the server, wherein the information security records are analysis results of abnormal conditions of any node in the vehicle-side detection system; determine the first credibility value of the current node based on the information security records; compare the first credibility value with a preset threshold to obtain a first detection result.
[0120] Furthermore, the second detection module 602 is also used to obtain the information security log of the current node based on the vehicle-side detection system, wherein the information security log is used to record abnormal conditions of the current node; determine the second credibility value of the current node based on the information security log; compare the second credibility value with the preset threshold to obtain a second detection result.
[0121] Furthermore, the setting module 604 is also used to set the remaining nodes as slave nodes; control any slave node to send a slave node declaration message to nodes other than any slave node, wherein the slave node declaration message is used to declare any node among the remaining nodes as a slave node.
[0122] Furthermore, the determination module is also used to, in response to the first detection result not meeting the preset conditions, perform a credibility check on the next node of the current node based on the server to obtain a third detection result; determine the main node in the vehicle-side detection system based on the third detection result; or in response to the second detection result not meeting the preset conditions, perform a credibility check on the next node of the current node based on the server to obtain a fourth detection result; and determine the main node in the vehicle-side detection system based on the fourth detection result.
[0123] Furthermore, the determination module is also used to respond to the sending result indicating that any of the remaining nodes has not received the master node declaration message, perform a credibility check on the next node of the current node based on the server, and obtain a fifth detection result; and determine the master node in the vehicle-side detection system based on the fifth detection result.
[0124] Furthermore, the communication node determination device of the vehicle-side detection system also includes an initialization module for initializing the server and the vehicle-side detection system; and establishing a communication connection between the server and the vehicle-side detection system.
[0125] According to another aspect of an embodiment of the present invention, a vehicle is also provided, comprising: a memory storing an executable program; and a processor for running the program, wherein when the program runs, the communication node determination method of the vehicle-side detection system in any of the above items is executed.
[0126] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided, in which a computer program is stored, wherein the computer program is configured to execute the communication node determination method of the vehicle-side detection system in any of the above items when running on a computer or processor.
[0127] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for performing the following steps:
[0128] Step S30: performing a credibility check on the current node based on the server to obtain a first test result, wherein the current node is an electronic control unit in the vehicle-side detection system;
[0129] Step S32: In response to the first detection result satisfying a preset condition, a credibility check is performed on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period;
[0130] Step S34: In response to the second detection result meeting the preset condition, controlling the current node to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit;
[0131] Step S36: In response to the sending result indicating that the remaining nodes have received the master node declaration message, the current node is set as the master node, where the master node is used to communicate with the server.
[0132] According to another aspect of the embodiment of the present invention, an electronic device 700 is further provided. Figure 7 As shown, it includes a memory 701 and a processor 702, the memory 701 stores a computer program, and the processor 702 is configured to run the computer program to execute any of the above-mentioned methods for determining a communication node of a vehicle-side detection system.
[0133] Optionally, in this embodiment, the processor in the electronic device may be configured to run a computer program to perform the following steps:
[0134] Step S30: performing a credibility check on the current node based on the server to obtain a first test result, wherein the current node is an electronic control unit in the vehicle-side detection system;
[0135] Step S32: In response to the first detection result satisfying a preset condition, a credibility check is performed on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period;
[0136] Step S34: In response to the second detection result meeting the preset condition, controlling the current node to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit;
[0137] Step S36: In response to the sending result indicating that the remaining nodes have received the master node declaration message, the current node is set as the master node, where the master node is used to communicate with the server.
[0138] In this application, a plurality refers to two or more.
[0139] In this application, unless otherwise expressly defined, the terms "mounted," "connected," and "connected" should be interpreted broadly. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediary; and internal communication between two components. A person of ordinary skill in the art will understand the specific meanings of these terms in this application.
[0140] The terms "first," "second," "third," "fourth," etc. (if any) in this application are used to distinguish similar objects and are not necessarily used to describe a particular sequential order.
[0141] The term "and / or" in this application simply describes an association between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this application generally indicates that the related objects are in an "or" relationship.
[0142] Unless otherwise specified, all steps of the present application may be performed sequentially or randomly. For example, a statement that the method includes steps A and B indicates that the method may include steps A and B performed sequentially, or steps B and A performed sequentially. For example, a statement that the method may also include step C indicates that step C may be added to the method in any order, for example, the method may include steps A, B, and C, or steps A, C, and B, or steps C, A, and B, etc.
[0143] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A method for determining a communication node of a vehicle-side detection system, characterized in that: include: Performing a credibility test on a current node based on the server to obtain a first test result, wherein the current node is an electronic control unit in a vehicle-side detection system; In response to the first detection result satisfying a preset condition, performing a credibility check on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; In response to the second detection result satisfying the preset condition, controlling the current node to send a master node declaration message to the remaining nodes to obtain a sending result, wherein the master node declaration message is used to declare the current node as the master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; In response to the sending result indicating that the remaining nodes have all received the master node declaration message, the current node is set as the master node, wherein the master node is used to communicate with the server.
2. The method according to claim 1, characterized in that The method further comprises: In response to the current node being invaded, a new master node is determined from the remaining nodes.
3. The method according to claim 1, characterized in that The server-based credibility test on the current node to obtain a first test result includes: Obtaining an information security record based on the server, wherein the information security record is an analysis result of an abnormality of any node in the vehicle-side detection system; Determining a first credibility value of the current node based on the information security record; The first credibility value is compared with the preset threshold to obtain the first detection result.
4. The method according to claim 1, wherein The performing credibility detection on the current node based on the vehicle-side detection system to obtain a second detection result includes: Obtaining an information security log of the current node based on the vehicle-side detection system, wherein the information security log is used to record abnormal conditions of the current node; Determining a second credibility value of the current node based on the information security log; The second credibility value is compared with the preset threshold to obtain the second detection result.
5. The method according to claim 1, characterized in that The method further comprises: Setting the remaining nodes as slave nodes; Control any slave node to send a slave node declaration message to nodes other than the any slave node, wherein the slave node declaration message is used to declare any node among the remaining nodes as a slave node.
6. The method according to claim 1, characterized in that The method further comprises: In response to the first detection result not meeting the preset condition, performing a credibility detection on a node next to the current node based on the server to obtain a third detection result; Determining a master node in the vehicle-side detection system based on the third detection result; or In response to the second detection result not meeting the preset condition, performing a credibility detection on a node next to the current node based on the server to obtain a fourth detection result; The master node in the vehicle-side detection system is determined based on the fourth detection result.
7. The method according to claim 1, characterized in that The method further comprises: In response to the sending result indicating that any of the remaining nodes has not received the master node declaration message, performing a credibility check on a next node of the current node based on the server to obtain a fifth detection result; The master node in the vehicle-side detection system is determined based on the fifth detection result.
8. A communication node determination device for a vehicle-side detection system, characterized in that: The device comprises: a first detection module, configured to perform a credibility detection on a current node based on a server to obtain a first detection result, wherein the current node is an electronic control unit in a vehicle-side detection system; a second detection module, configured to, in response to the first detection result satisfying a preset condition, perform a credibility check on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period; a sending module, the sending module being configured to control the current node to send a master node declaration message to the remaining nodes in response to the second detection result satisfying the preset condition, to obtain a sending result, wherein the master node declaration message is used to declare the current node as a master node, and the remaining nodes are the remaining electronic control units in the vehicle-side detection system except the current electronic control unit; A setting module is configured to set the current node as a master node in response to the sending result indicating that the remaining nodes have received the master node declaration message, wherein the master node is configured to communicate with the server.
9. A vehicle, characterized in that: The vehicle includes: a memory storing an executable program; and a processor for running the program, wherein when the program is running, the communication node determination method of the vehicle-side detection system described in any one of claims 1 to 7 is executed.
10. A computer-readable storage medium, characterized in that The storage medium stores a computer program, wherein the computer program is configured to execute the communication node determination method of the vehicle-side detection system described in any one of claims 1 to 7 when running on a computer or processor.
Citation Information
Patent Citations
Controller node detection method and device, control system, vehicle and storage medium
CN115454015A
Apparatus and method for detection error recovery of trust-based routing
KR1020150062136A
Systems, apparatus, and methods of event monitoring for an event candidate related to an id node within a wireless node network
US20170012719A1
Method for adjusting node detection parameters, node, and mesh network
WO2018192288A1