A communication node determination method and device of a vehicle end detection system and a vehicle
By performing dual trustworthiness checks on the electronic control unit of the vehicle-side detection system through the server, the node with high trustworthiness becomes the master node. This solves the problems of insufficient information security protection capabilities and high resource consumption in traditional vehicle intrusion detection systems, and achieves a balance between security performance and resource utilization.
Patent Information
- Application Number
- CN202510805139.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-06-16
AI Technical Summary
Traditional vehicle intrusion detection systems lack sufficient information security protection in master-slave deployments, while distributed deployments consume too much resources, and there is a lack of effective solutions.
The server performs dual trustworthiness checks on the electronic control unit of the vehicle-side detection system to ensure that only nodes with high trustworthiness are set as master nodes. The master node is determined through negotiation via master node declaration messages, thus achieving multi-master detection.
It improves the security performance and resource allocation efficiency of the vehicle intrusion detection system, balances information security protection capabilities with resource consumption, and enhances the system's adaptability and reliability.
Smart Images

Figure CN120455145B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method, apparatus and vehicle for determining communication nodes in a vehicle-side detection system. Background Technology
[0002] With the development of intelligent connected vehicles, the level of vehicle intelligence is increasing, leading to higher demands on network security. Traditional vehicle intrusion detection systems typically employ master-slave or distributed deployments. Because master-slave deployments offer extremely high information security protection, when a vehicle is compromised and the master node of the intrusion detection system malfunctions, even if other slave nodes survive, they cannot complete data upload operations. In contrast, in distributed deployments, all nodes are directly connected to the server for data transmission, resulting in significant resource consumption.
[0003] There are currently no effective solutions to the technical problems of the extremely high information security protection capabilities of the master-slave deployed vehicle intrusion detection system and the extremely high resource consumption of the distributed deployed vehicle intrusion detection system. Summary of the Invention
[0004] This application provides a method, apparatus, and vehicle for determining communication nodes in a vehicle-side detection system, aiming to improve the technical problems of high protection levels and high resource consumption in related technologies for vehicle intrusion detection systems.
[0005] According to one aspect of the present invention, a method for determining communication nodes in a vehicle-side detection system is provided, comprising: performing a credibility detection on a current node based on a server to obtain a first detection result, wherein the current node is an electronic control unit (ECU) in the vehicle-side detection system; responding to the first detection result satisfying a preset condition, performing a credibility detection on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition indicates that the credibility value of the current node is greater than a preset threshold within a preset period; responding to the second detection result satisfying the preset condition, controlling the current node to send a master node declaration message to the other nodes to obtain a transmission result, wherein the master node declaration message declares the current node as the master node, and the other nodes are the other ECUs in the vehicle-side detection system excluding the current ECU; responding to the transmission result indicating that the other nodes have all received the master node declaration message, setting the current node as the master node, wherein the master node is used to communicate with the server.
[0006] By combining the above technical solutions with dual detection from both the server and vehicle-side detection systems, and by determining whether all other nodes have received the master node declaration message, it is ensured that only rigorously verified and highly reliable electronic control units can be set as master nodes, thus significantly improving the security performance of the vehicle intrusion detection system and optimizing resource allocation.
[0007] According to another aspect of the present invention, a communication node determination device for a vehicle-side detection system is also provided, comprising: a first detection module, configured to perform credibility detection on a current node based on a server to obtain a first detection result, wherein the current node is an electronic control unit in the vehicle-side detection system; a second detection module, configured to perform credibility detection on the current node based on the vehicle-side detection system in response to the first detection result satisfying a preset condition to obtain a second detection result, wherein the preset condition indicates that the credibility value of the current node is greater than a preset threshold within a preset period; a sending module, configured to control the current node to send a master node declaration message to the other nodes in response to the second detection result satisfying the preset condition to obtain a sending result, wherein the master node declaration message declares the current node as the master node, and the other nodes are the other electronic control units in the vehicle-side detection system excluding the current electronic control unit; and a setting module, configured to set the current node as the master node in response to the sending result indicating that the other nodes have all received the master node declaration message, wherein the master node is used to communicate with the server.
[0008] According to another aspect of the present invention, a vehicle is also provided, the vehicle comprising: a memory storing an executable program; and a processor for running the program, wherein the program executes the communication node determination method of the vehicle-end detection system described above when it runs.
[0009] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein the storage medium stores a computer program, wherein the computer program is configured to execute the communication node determination method of the vehicle-end detection system described above when running on a computer or processor.
[0010] According to another aspect of the present invention, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the communication node determination method of the vehicle-end detection system described in any of the preceding embodiments.
[0011] In this embodiment of the invention, a multi-master detection technology is employed. A first detection result is obtained by performing a trustworthiness detection on the current node based on a server. The current node is an electronic control unit (ECU) in the vehicle-side detection system. In response to the first detection result satisfying a preset condition, a second detection result is obtained by performing a trustworthiness detection on the current node based on the vehicle-side detection system. The preset condition indicates that the trustworthiness value of the current node is greater than a preset threshold within a preset period. In response to the second detection result satisfying the preset condition, the current node is controlled to send a master node declaration message to the remaining nodes, resulting in a transmission result. The master node declaration message declares the current node as the master node, and the remaining nodes are the other electronic control units (ECUs) in the vehicle-side detection system excluding the current ECU. In response to the transmission result indicating that all remaining nodes have received the master node declaration message, the current node is set as the master node. This overall technical solution, where the master node communicates with the server, achieves the goal of improving system adaptability, reliability, and resource utilization efficiency. This balances resource consumption with information security protection capabilities, thereby solving the technical problems of high protection levels and high resource consumption in related technologies for vehicle intrusion detection systems. Attached Figure Description
[0012] Figure 1 This is a structural diagram of a distributed deployment detection system in existing technology;
[0013] Figure 2 This is a diagram of the architecture of a master-slave deployed detection system in existing technology;
[0014] Figure 3 This is a flowchart of a method for determining communication nodes in a vehicle-end detection system according to an embodiment of this application;
[0015] Figure 4 This is a system architecture diagram of a multi-master detection technology provided in an embodiment of this application;
[0016] Figure 5 This is a flowchart of the master node determination rule provided in one embodiment of this application;
[0017] Figure 6 This is a structural diagram of a communication node determination device for a vehicle-end detection system provided in an embodiment of this application;
[0018] Figure 7 This is a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0019] To make the technical problems, technical solutions, and beneficial effects solved by this application clearer, the following detailed description is provided in conjunction with embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0020] To enable those skilled in the art to better understand this technical solution, the following terms are explained:
[0021] An intrusion detection system (IDS) is a network security device used to monitor for anomalies in a network or computer system and generate warning messages. In intelligent connected vehicles, IDS are used to monitor the vehicle's operating system, external interfaces, network connections, etc., to promptly detect and report potential security threats or intrusion attempts.
[0022] In intrusion detection systems, trustworthiness assessment is a quantitative evaluation of a node's security status. By analyzing whether a node has a history of attacks, the type of attack, and its severity, a corresponding trustworthiness value is assigned to the node. Nodes with higher trustworthiness are more likely to be selected as master nodes.
[0023] The cloud-based vehicle security operations center is a cloud-based vehicle security monitoring and response platform. Through communication with the vehicle intrusion detection system, it collects security event logs, performs data analysis, predicts future cybersecurity situations, and guides vehicles to take corresponding security measures.
[0024] An Electronic Control Unit (ECU) is used to control various subsystems of a vehicle, such as the engine, braking system, and entertainment system. In the field of intrusion detection, ECUs can also integrate intrusion detection functions, acting as slave or master nodes to monitor and respond to potential network attack events.
[0025] Figure 1 This is a diagram of the architecture of a distributed deployment detection system in existing technology, such as... Figure 1 As shown, each component node deploys an intrusion detection system independently, and these systems interact with the vehicle security operations center system in the cloud on a component-by-component basis. The disadvantages of this distributed deployment are extremely high resource consumption and high cloud concurrency; for example, if several intrusion detection system nodes are deployed on each vehicle, there will be several concurrent connections to the cloud, resulting in system redundancy. The advantage is lower information security protection capability; even if one intrusion detection system node is shut down due to an intrusion, other nodes remain active and can still complete data collection and uploading operations.
[0026] Figure 2 This is a diagram of the architecture of a master-slave deployment detection system in existing technology, such as... Figure 2As shown, the vehicle's intrusion detection system is deployed in a master-slave configuration on its components. Only one node is selected as the master node on the vehicle side, while the others are slave nodes. Data collected by the slave nodes is transmitted to the master node via bus communication. The master node then communicates with the vehicle security operations center system in the cloud, including data uploading and downloading. This master-slave deployment significantly reduces resource consumption compared to distributed deployments. The concurrency of communication between the vehicle and the cloud is reduced from multiple links to a single link, greatly reducing the concurrency load on the cloud system. However, the drawback is extremely high information security protection. If the vehicle is compromised and the master node of the intrusion detection system is shut down, even if the other slave nodes survive, they cannot complete data collection and uploading operations.
[0027] This application provides a method for determining communication nodes in a vehicle-side detection system, comprising: performing a credibility detection on a current node based on a server to obtain a first detection result, wherein the current node is an electronic control unit (ECU) in the vehicle-side detection system; responding to the first detection result satisfying a preset condition, performing a credibility detection on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition indicates that the credibility value of the current node is greater than a preset threshold within a preset period; responding to the second detection result satisfying the preset condition, controlling the current node to send a master node declaration message to the other nodes to obtain a sending result, wherein the master node declaration message declares the current node as the master node, and the other nodes are the other ECUs in the vehicle-side detection system excluding the current ECU; responding to the sending result indicating that the other nodes have all received the master node declaration message, setting the current node as the master node, wherein the master node is used to communicate with the server.
[0028] By combining the above technical solutions with dual detection from both the server and vehicle-side detection systems, and by determining whether all other nodes have received the master node declaration message, it is ensured that only rigorously verified and highly reliable electronic control units can be set as master nodes, thus significantly improving the security performance of the vehicle intrusion detection system and optimizing resource allocation.
[0029] Figure 3 This is a flowchart of a communication node determination method for a vehicle-side detection system according to an embodiment of this application, as shown below. Figure 3 As shown, it includes the following steps:
[0030] Step S30: Based on the server, perform a credibility test on the current node to obtain the first test result, wherein the current node is the electronic control unit in the vehicle detection system;
[0031] In this embodiment of the invention, the server can be understood as a server cluster or platform located in the cloud, primarily responsible for collecting, analyzing, and managing large amounts of security data from vehicles. The server possesses powerful data processing capabilities and storage resources, enabling it to execute complex algorithms to evaluate the trustworthiness of nodes. The server interacts with the vehicle-side detection system on the vehicle via a network, receiving and analyzing security event logs and other vehicle status information to determine whether each node of the vehicle-side detection system is in a secure state.
[0032] The current node can be understood as an electronic control unit that is performing a trustworthiness check. For example, the current node can be the master node that was initially negotiated and determined or any electronic control unit that needs to be re-evaluated in abnormal circumstances; there is no limitation here.
[0033] Trustworthiness testing can be understood as a process of assessing the security level of any node. This includes analyzing the current node's security status by examining historical security events, intrusion detection records, and other relevant indicators to determine whether the node has been attacked and the extent of the attack. The trustworthiness testing result will determine whether the current node can continue to perform its duties as a master node or whether it needs to be demoted to a slave node.
[0034] The first detection result can be understood as a quantitative assessment obtained by the server after performing a trustworthiness test on the current node. The first detection result reflects the security status of the current node. For example, the first detection result is usually represented by a grade, such as from very high (e.g., 5 points) to very low (e.g., 0 points), to determine whether the current node is suitable to become the master node. There is no restriction here.
[0035] A vehicle-side detection system can be understood as a network monitoring and intrusion detection system deployed inside a vehicle. It consists of multiple electronic control units (ECUs), which are responsible for monitoring abnormal behavior within the vehicle network, such as abnormal data packets, communication failures, or malicious code injection. By monitoring and analyzing network traffic and system behavior in real time, the vehicle-side detection system can identify security threats and take appropriate measures, such as reporting alerts or blocking malicious communication.
[0036] The first detection result, obtained by the server performing a trustworthiness check on the current node, can be understood as the server performing a comprehensive security assessment on the current node on the vehicle, thus yielding the first detection result. This first detection result reflects whether the current node has been attacked, as well as the type and severity of the attack, thereby determining the node's trustworthiness level.
[0037] In this embodiment of the invention, the server performs a trustworthiness detection on the current node to obtain a first detection result, which aims to determine the security status and trustworthiness of the current node, thereby ensuring the security of the system and the reliability of data transmission.
[0038] Step S32: In response to the first detection result satisfying the preset condition, perform credibility detection on the current node based on the vehicle-side detection system to obtain the second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than the preset threshold within a preset period.
[0039] In this embodiment of the invention, the preset conditions can be understood as specific requirements that the server needs to meet for the credibility detection result of the current node, in order to decide whether to further perform credibility detection on the current node based on the vehicle-side detection system.
[0040] The second detection result can be understood as the result obtained after the current node undergoes further credibility testing through the vehicle-side detection system. Based on real-time monitoring data from the vehicle and a more detailed security assessment, the second detection result provides a secondary confirmation of the current node's security status.
[0041] The preset period can be understood as a time window. Within the preset period, the server continuously monitors the activity and security status of the current node to assess its trustworthiness. The selection of the preset period needs to comprehensively consider the system's response speed, the node's activity frequency, and the possible duration of the attack. For example, the preset period can be set to one week to ensure that the assessment covers sufficient historical behavior and environmental changes; this is not a limitation here.
[0042] The preset threshold can be understood as a standard value set by the system when evaluating the trustworthiness of the current node, used to distinguish whether the node's security status meets the conditions for being a master node. For example, the trustworthiness level can range from 0 to 5, where 5 indicates no attack and 0 indicates a severe attack. The preset threshold might be set to 2, meaning that the node will only undergo further detection by the vehicle if the server-assessed trustworthiness level is greater than 2; this is not a restriction here.
[0043] In response to the first detection result meeting the preset conditions, the credibility detection of the current node is performed based on the vehicle-side detection system to obtain the second detection result. This can be understood as follows: when the server initially assesses that the first detection result of the current node indicates that the node has not experienced a serious security event within the preset period and the credibility value is higher than the preset threshold, the credibility detection of the current node's security status is performed again based on the vehicle-side detection system to obtain the second detection result.
[0044] In this embodiment of the invention, in response to the first detection result meeting the preset conditions, the credibility of the current node is detected based on the vehicle-side detection system to obtain the second detection result. This utilizes the complementary advantages of the cloud and vehicle-side detection systems to ensure that the credibility of the master node is based not only on the analysis of historical data but also on the confirmation of real-time security status, thereby enhancing the application effect of multi-master detection technology in the field of intelligent connected vehicle security protection.
[0045] Step S34: In response to the second detection result meeting the preset conditions, control the current node to send a master node declaration message to the other nodes and obtain the sending result. The master node declaration message is used to declare the current node as the master node, and the other nodes are the other electronic control units in the vehicle detection system other than the current electronic control unit.
[0046] In this embodiment of the invention, the master node declaration message can be understood as a communication message sent by the current node in the vehicle-side detection system that has been confirmed to have sufficient credibility. The main content of the master node declaration message is a declaration that the current node has been selected as the master node, indicating that the current node will assume responsibility for managing data collection, aggregation, and uploading to the cloud. The master node declaration message includes its own node identification information, credibility level, and other necessary information that may be used to confirm its master node identity. The other nodes receiving this message will adjust their status according to the message content to cooperate with the master node in subsequent data processing and security monitoring.
[0047] The sending result can be understood as the response of the remaining nodes in the system to the master node declaration message sent by the current node. For example, a successful sending result means that the remaining nodes have received and understood the master node declaration message, and will recognize the current node's master node status, beginning to transmit data to it or execute other slave node tasks. A failed sending result may indicate a communication problem or that some nodes are not responding, requiring further troubleshooting or a re-election of a master node; however, this is not a limitation here.
[0048] In response to the second detection result meeting the preset conditions, the system controls the current node to send a master node declaration message to the other nodes. The result can be understood as follows: when the second detection result obtained by the vehicle-side detection system for the current node shows that the node's credibility meets the preset conditions, indicating that the current node is qualified to act as the master node, the system will control the current node to send a master node declaration message to the other nodes in the system through the vehicle's internal network (such as CAN bus, Ethernet, etc.) and obtain the result.
[0049] In this embodiment of the invention, in response to the second detection result meeting the preset conditions, the current node is controlled to send a master node declaration message to the other nodes to obtain the sending result, which enhances the system's response speed and resistance to security events and helps protect intelligent connected vehicles from network threats.
[0050] Step S36: In response to the transmission result indicating that all other nodes have received the master node declaration message, the current node is set as the master node, whereby the master node is used to communicate with the server.
[0051] In this embodiment of the invention, in response to the transmission result indicating that all other nodes have received the master node declaration message, setting the current node as the master node can be understood as follows: when the system confirms that the transmission result shows that all other nodes have successfully received the master node declaration message sent by the current node, it indicates that the current node's trustworthiness and security status have met the requirements for being a master node, and the system will officially set the current node as the master node.
[0052] In this embodiment of the invention, in response to the transmission result indicating that all other nodes have received the master node declaration message, the current node is set as the master node, ensuring that the system can select the most suitable individual as the master node among the secure nodes. Even if some nodes are attacked or abnormal, the system can maintain the overall security and functional integrity of the system through rapid dynamic adjustment.
[0053] Figure 4 This is a system architecture diagram of a multi-master detection technology provided in an embodiment of this application, as shown below. Figure 4 As shown, multiple nodes are deployed on a vehicle, and the system selects one node as the master node to complete the data aggregation and uploading. Under normal vehicle operation, the master node determined by the system is responsible for controlling the slave nodes to complete the data collection and connecting with the vehicle safety operation center system in the cloud to upload the data, thereby achieving a technical effect of balancing resource consumption and information security protection capabilities.
[0054] In this embodiment of the invention, a multi-master detection technology is employed. A first detection result is obtained by performing a trustworthiness detection on the current node based on a server. The current node is an electronic control unit (ECU) in the vehicle-side detection system. In response to the first detection result satisfying a preset condition, a second detection result is obtained by performing a trustworthiness detection on the current node based on the vehicle-side detection system. The preset condition indicates that the trustworthiness value of the current node is greater than a preset threshold within a preset period. In response to the second detection result satisfying the preset condition, the current node is controlled to send a master node declaration message to the remaining nodes, resulting in a transmission result. The master node declaration message declares the current node as the master node, and the remaining nodes are the other electronic control units (ECUs) in the vehicle-side detection system excluding the current ECU. In response to the transmission result indicating that all remaining nodes have received the master node declaration message, the current node is set as the master node. This overall technical solution, where the master node communicates with the server, achieves the goal of improving system adaptability, reliability, and resource utilization efficiency. This balances resource consumption with information security protection capabilities, thereby solving the technical problems of high protection levels and high resource consumption in related technologies for vehicle intrusion detection systems.
[0055] Optionally, the method for determining the communication node of the vehicle-side detection system further includes: in response to the current node being intruded upon, determining a new master node from the remaining nodes.
[0056] In this embodiment of the invention, determining a new master node from the remaining nodes in response to the current node being compromised can be understood as follows: if the current node is found to be compromised, then the node can no longer perform normal security functions and data management responsibilities. In order to avoid the negative impact of the system being compromised due to the failure of the master node, the vehicle-side detection system will immediately activate the emergency response mechanism to re-determine a new master node from the remaining nodes.
[0057] In this embodiment of the invention, in response to an intrusion into the current node, a new master node is determined from the remaining nodes. The system can quickly adapt to security threats, avoid system paralysis caused by the failure of a single node, and ensure the continuity of data collection and security monitoring.
[0058] Optionally, in step S30, based on the server's performance of a trustworthiness test on the current node, a first test result is obtained, including the following steps:
[0059] Step S301: Obtain information security records from the server, wherein the information security records are the analysis results of any abnormal situation of any node in the vehicle-side detection system;
[0060] Step S302: Determine the first trust value of the current node based on information security records;
[0061] Step S303: Compare the first confidence value with the preset threshold to obtain the first detection result.
[0062] In this embodiment of the invention, the information security record can be understood as a series of data collected and analyzed by the server. The information security record reflects the abnormal situations and security events of any node in the vehicle-side detection system over a period of time. For example, the information security record includes various security indicators, such as: the type of attack suffered by the node, the frequency and intensity of the attack, the system response and recovery status, log analysis results, etc., which are not limited here.
[0063] The first credibility value can be understood as a quantitative indicator calculated based on information security records, used to assess the security coefficient of the current node in history.
[0064] Information security records obtained from a server can be understood as the server collecting and analyzing the security status information of all nodes in the vehicle-side detection system to form an information security record. For example, the server receives data from vehicle-side nodes, including but not limited to log files, anomaly reports, and security event records; performs statistical analysis on the collected data to identify patterns, trends, and potential security risks; and generates a detailed information security record based on the analysis results to provide a basis for subsequent credibility assessments. No restrictions are imposed here.
[0065] Determining the first trust value of the current node based on information security records can be understood as follows: after obtaining information security records, the system will determine the first trust value of the current node based on the information in the information security records and the preset trust calculation rules.
[0066] The comparison between the first confidence value and the preset threshold to obtain the first detection result can be understood as the system comparing the calculated first confidence value with the preset threshold to determine whether the node meets the preliminary conditions for becoming a master node, and thus obtaining the first detection result.
[0067] In this embodiment of the invention, based on information security records collected by the server, a first credibility value for the current node is determined. This first credibility value is then compared with a preset threshold to determine whether the current node is suitable to be a master node. By quantifying the historical security performance of nodes, their node attributes in the system are dynamically adjusted, effectively balancing resource consumption and information security protection, and enhancing the robustness and security of the vehicle intrusion detection system.
[0068] Optionally, in step S32, a credibility test is performed on the current node based on the vehicle-side detection system to obtain a second detection result, including the following steps:
[0069] Step S321: Obtain the information security log of the current node based on the vehicle-side detection system, wherein the information security log is used to record abnormal situations of the current node;
[0070] Step S322: Determine the second trust value of the current node based on the information security log;
[0071] Step S323: Compare the second confidence value with the preset threshold to obtain the second detection result.
[0072] In this embodiment of the invention, the information security log can be understood as a security record generated by the vehicle-side detection system, used to record immediate anomalies and security events at the current node. Exemplarily, the information security log includes, but is not limited to, system malfunctions, network activity anomalies, and intrusion detection warnings, etc., and is not limited here.
[0073] The second credibility value can be understood as a quantitative indicator calculated based on information security logs, used to assess the security level of the current node at this time.
[0074] The information security log obtained from the vehicle-side detection system can be understood as the system recording and capturing all abnormal behaviors and security events of the current node in real time during operation, thus forming an information security log.
[0075] Determining the second trust value of the current node based on information security logs can be understood as the system obtaining the second trust value of the current node based on the type and severity of abnormal events in the information security logs and the node's response to these events, according to a preset trust calculation rule.
[0076] The comparison between the second confidence value and the preset threshold to obtain the second detection result can be understood as the system comparing the calculated second confidence value with the preset threshold to determine whether the security level of the current node meets the standard for being a master node, thereby obtaining the second detection result.
[0077] In this embodiment of the invention, the information security log of the current node's abnormal situation is obtained through the vehicle-side detection system, and the second credibility value of the current node is determined based on log analysis. Finally, the second credibility value is compared with a preset threshold to obtain the second detection result, ensuring that the master node is always the safest choice, thus achieving dual protection of security and resource optimization.
[0078] Optionally, the method for determining the communication node of the vehicle-side detection system further includes the following steps:
[0079] Set the remaining nodes as slave nodes;
[0080] Control any slave node to send a slave node declaration message to any node other than the slave node itself. The slave node declaration message is used to declare any of the remaining nodes as a slave node.
[0081] In this embodiment of the invention, the slave node declaration message can be understood as a communication message sent by the slave node to other nodes in the system, used to declare and confirm the slave node status.
[0082] Setting the remaining nodes as slave nodes can be understood as follows: after the master node is determined, other nodes in the system are automatically or configured as slave nodes through commands. Slave nodes primarily assist the master node by performing tasks such as data acquisition and preliminary analysis, and transmitting this information to the master node via the system bus.
[0083] Controlling any slave node to send a slave node declaration message to all nodes except for that slave node can be understood as follows: if any node is identified as a slave node, then that slave node will send a slave node declaration message to all nodes in the system.
[0084] In this embodiment of the invention, after the master node is determined through negotiation, the system sets other nodes as slave nodes and triggers any slave node to broadcast a slave node declaration message, ensuring a clear network structure and optimized communication path. This not only improves data transmission efficiency but also enhances the system's ability to recover quickly when the master node fails.
[0085] Optionally, the method for determining the communication node of the vehicle-side detection system further includes the following steps:
[0086] In response to the first detection result not meeting the preset conditions, the server performs a credibility check on the next node of the current node to obtain a third detection result;
[0087] The master node in the vehicle-side detection system is determined based on the third detection result; or
[0088] In response to the second detection result not meeting the preset conditions, the server performs a credibility test on the next node of the current node to obtain the fourth detection result;
[0089] The master node in the vehicle-side detection system is determined based on the fourth detection result.
[0090] In this embodiment of the invention, the third detection result can be understood as the result obtained by the server after performing a trustworthiness test on the next node of the current node when the current master node is considered untrustworthy or unable to serve as the master node. This result is used to determine whether the next node is sufficiently safe and reliable.
[0091] The fourth detection result can be understood as the result generated by the server's credibility assessment of the next node when the vehicle-side detection system determines that the current node has not met the preset conditions.
[0092] In response to the first detection result not meeting the preset conditions, the third detection result is obtained by the server performing a credibility test on the next node of the current node. This can be understood as follows: if the credibility value of the currently selected master node fails the server's test, the system uses the server to evaluate the credibility of the next node and obtains the third detection result.
[0093] Determining the master node in the vehicle-side detection system based on the third detection result can be understood as follows: Based on the aforementioned third detection result, the system analyzes and judges the security status and trustworthiness of the next node. If the third detection result shows that the node meets the conditions to become a master node, then the vehicle-side detection system will perform another trustworthiness check on this node. If the third detection result shows that the node does not meet the conditions to become a master node, then the server will continue to evaluate the trustworthiness of the next candidate node until a master node is selected.
[0094] In response to the second detection result not meeting the preset conditions, the server performs a credibility test on the next node of the current node to obtain the fourth detection result. This can be understood as follows: when the vehicle-side detection system performs a credibility test on the current node, the credibility value of the current node fails to meet the preset conditions, that is, the current node may have been attacked or has a security vulnerability. The server then performs a credibility verification on the next node to obtain the fourth detection result.
[0095] Determining the master node in the vehicle-side detection system based on the fourth detection result can be understood as follows: Based on the aforementioned fourth detection result, the system analyzes and judges the security status and trustworthiness of the next node. If the fourth detection result shows that the node meets the conditions to become a master node, then the vehicle-side detection system will perform another trustworthiness check on this node. If the fourth detection result shows that the node does not meet the conditions to become a master node, then the server will continue to evaluate the trustworthiness of the next candidate node until a master node is selected.
[0096] In this embodiment of the invention, if the current node's trustworthiness test fails the server's assessment, the server immediately evaluates the trustworthiness of the next node and obtains a third detection result. Alternatively, if the current node's trustworthiness test fails the vehicle-side detection system's assessment, the server immediately evaluates the trustworthiness of the next node and obtains a fourth detection result. Based on the third or fourth detection result, the vehicle-side detection system designates a new master node, enabling real-time adjustment and optimization of the security mechanism. This effectively enhances the system's self-healing capability and overall security in the face of threats, and maintains the continuity and stability of data transmission.
[0097] Optionally, the method for determining the communication node of the vehicle-side detection system further includes the following steps:
[0098] In response to the result indicating that none of the remaining nodes have received the master node declaration message, the server performs a trustworthiness check on the next node of the current node to obtain the fifth check result;
[0099] The master node in the vehicle-side detection system is determined based on the fifth detection result.
[0100] In this embodiment of the invention, the fifth detection result can be understood as the result of the server's credibility detection of the next node when the current node has passed the detection of the server and the vehicle-side detection system, but cannot successfully send the master node declaration message to all other nodes, or other nodes have not received the declaration message.
[0101] In response to the result indicating that none of the remaining nodes have received the master node declaration message, the server performs a trustworthiness check on the next node of the current node, and obtains the fifth detection result. This can be understood as follows: if the current node attempts to send its identity declaration message to all other nodes, and if it detects that at least one slave node has failed to receive this information correctly, then the current node cannot act as the master node. The server will immediately perform a trustworthiness analysis on the next node and obtain the fifth detection result.
[0102] Determining the master node in the vehicle-side detection system based on the fifth detection result can be understood as follows: Based on the fifth detection result, the system analyzes and judges the security status and trustworthiness of the next node. If the fifth detection result shows that the node meets the conditions to become a master node, then the vehicle-side detection system will perform another trustworthiness check on this node. If the fifth detection result shows that the node does not meet the conditions to become a master node, then the server will continue to evaluate the trustworthiness of the next candidate node until a master node is selected.
[0103] In this embodiment of the invention, if the master node declaration message sent by the current node is not received and acknowledged by all other nodes, the cloud immediately performs a trustworthiness check on the next node, obtaining a fifth check result. Based on this result, the system selects the node whose trustworthiness value meets the preset conditions as the new master node, enhancing the system's security resilience and data transmission continuity, and improving the overall risk resistance capability.
[0104] Optionally, before obtaining the first detection result by performing a credibility check on the current node based on the server, the communication node determination method of the vehicle-side detection system further includes the following steps:
[0105] Initialize the server and vehicle-side detection system;
[0106] Establish a communication connection between the server and the vehicle-side detection system.
[0107] In this embodiment of the invention, initializing the server and vehicle-side detection system can be understood as the server and vehicle-side detection system each checking and setting their internal states and functions during system startup or reconfiguration to ensure correct operation and execution of their designed safety monitoring tasks. The initialization process may include loading software, updating the security rule base, performing self-checks to confirm the integrity of hardware and software components, and setting parameters for communication with other nodes in the network, etc., which are not limited here.
[0108] Establishing a communication connection between the server and the vehicle-mounted detection system can be understood as creating a reliable data exchange pathway between the two systems, enabling them to send and receive information in real time or periodically. For example, the data exchanged between the server and the vehicle-mounted detection system includes, but is not limited to, security logs, threat intelligence, system status updates, and control commands. Establishing this communication connection is fundamental to enabling remote monitoring and response, data synchronization, and system management functions. It ensures that the vehicle-mounted detection system can promptly upload detected security events, while the cloud system can distribute the latest security policies or updates, keeping the vehicle's cybersecurity defense mechanisms up-to-date.
[0109] In this embodiment of the invention, by initializing the server and the vehicle-side detection system and establishing a communication connection between them, it is possible to ensure the completeness of their functions and the synchronization of security rules, thereby realizing real-time data exchange and command response, enhancing the vehicle network security monitoring capabilities, quickly responding to threats, and improving the overall protection effectiveness of the system.
[0110] Figure 5 This is a flowchart illustrating the master node determination rule provided in one embodiment of this application. For example... Figure 5 As shown, after each electronic control unit (ECU) in the vehicle-side detection system completes initialization and cloud registration, the server needs to check whether the vehicle has been attacked within the past week (no specific time limit), whether the current node can act as a master node to report data, and determine whether the node is a trusted node. Only nodes determined to be trusted can upload data. The vehicle-side detection system checks the vehicle's own information security logs, such as whether it has been attacked, and whether the current node is a trusted node. If the current node is a trusted node, it is defined as the master node, and a communication message containing the current node's code information (e.g., ECU1) is sent to other nodes to notify ECU1 that it is the master node. After receiving the notification, the system sets all other nodes as slave nodes and controls any slave node to send slave node messages. When the master node in the vehicle-side detection system is shut down or an abnormal situation occurs (e.g., communication loss), the system performs a trustworthiness check on the remaining nodes and determines a new master node, and sends the security status of the ECU of the abnormal master node to the bus. The system tends to select nodes that have not been attacked or have suffered the least damage as master nodes. When the master node's function is activated, it will aggregate the data collected from the nodes and upload it to the server.
[0111] For example, Table 1 contains information about multiple electronic control units. As shown in Table 1, Byte 0 indicates that the address of ECU1 is 0xE1. Byte 1 is the master / slave node label, with 1 indicating the master node and 0 indicating the slave node. Byte 2 indicates the reliability of this electronic control unit. Bytes 2-7 are reserved bits for adding new functions.
[0112] Table 1
[0113] Byte0 Byte1 Byte2 Byte3 Byte4 Byte5 Byte6 Byte7 ECU1 0xE1 1 0x00 0xAA 0xAA 0xAA 0xAA 0xAA ECU2 0xE2 0 0x00 0xAA 0xAA 0xAA 0xAA 0xAA ECUn 0xEn 0 0x00 0xAA 0xAA 0xAA 0xAA 0xAA
[0114] For example, to select nodes that have not been attacked or have suffered the least damage, it is necessary to classify and grade the abnormal behaviors detected by the vehicle-side detection system. Table 2 shows the trustworthiness assessment of nodes under different conditions. As shown in Table 2, the trustworthiness value is set to 6 levels from 0 to 5. When the certificate file is changed, or the node function of the vehicle-side detection system is disabled, it is judged as a serious attack. Even if the node is capable of uploading data, its trustworthiness is 0. When the trustworthiness drops to 2 or below, it will not be selected as the primary node. When the trustworthiness of all nodes on the vehicle drops below 2, the vehicle is judged to have suffered a serious attack and information security handling procedures are required.
[0115] Table 2
[0116]
[0117] This application also provides a communication node determination device 600 for a vehicle-side detection system. Please refer to [link / reference]. Figure 6 The system includes: a first detection module 601, which performs a credibility detection on the current node based on the server to obtain a first detection result, wherein the current node is an electronic control unit in the vehicle-side detection system; a second detection module 602, which, in response to the first detection result meeting a preset condition, performs a credibility detection on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition indicates that the credibility value of the current node is greater than a preset threshold within a preset period; a sending module 603, which, in response to the second detection result meeting the preset condition, controls the current node to send a master node declaration message to the other nodes to obtain a sending result, wherein the master node declaration message declares the current node as the master node, and the other nodes are the other electronic control units in the vehicle-side detection system excluding the current electronic control unit; and a setting module 604, which, in response to the sending result indicating that the other nodes have received the master node declaration message, sets the current node as the master node, wherein the master node is used to communicate with the server.
[0118] Furthermore, the communication node determination device of the vehicle-side detection system also includes a determination module, which is used to determine a new master node from the remaining nodes in response to the current node being intruded upon.
[0119] Furthermore, the first detection module 601 is also used to obtain information security records based on the server, wherein the information security records are the analysis results of abnormal situations of any node in the vehicle-side detection system; determine the first confidence value of the current node based on the information security records; and compare the first confidence value with a preset threshold to obtain the first detection result.
[0120] Furthermore, the second detection module 602 is also used to obtain the information security log of the current node based on the vehicle-side detection system, wherein the information security log is used to record abnormal situations of the current node; determine the second credibility value of the current node based on the information security log; and compare the second credibility value with a preset threshold to obtain the second detection result.
[0121] Furthermore, the setting module 604 is also used to set the remaining nodes as slave nodes; and to control any slave node to send a slave node declaration message to any node other than any slave node, wherein the slave node declaration message is used to declare any of the remaining nodes as a slave node.
[0122] Furthermore, the determining module is also used to respond to the first detection result not meeting the preset conditions, perform a credibility test on the next node of the current node based on the server to obtain a third detection result; determine the master node in the vehicle detection system based on the third detection result; or respond to the second detection result not meeting the preset conditions, perform a credibility test on the next node of the current node based on the server to obtain a fourth detection result; determine the master node in the vehicle detection system based on the fourth detection result.
[0123] Furthermore, the determination module is also used to respond to the sending result indicating that any of the remaining nodes has not received the master node declaration message, and to perform a credibility test on the next node of the current node based on the server to obtain a fifth detection result; and to determine the master node in the vehicle-side detection system based on the fifth detection result.
[0124] Furthermore, the communication node determination device of the vehicle-side detection system also includes an initialization module for initializing the server and the vehicle-side detection system and establishing a communication connection between the server and the vehicle-side detection system.
[0125] According to another aspect of the present invention, a vehicle is also provided, the vehicle comprising: a memory storing an executable program; and a processor for running the program, wherein the program executes the communication node determination method of the vehicle-end detection system described above when it runs.
[0126] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein the storage medium stores a computer program, wherein the computer program is configured to execute the communication node determination method of the vehicle-end detection system described above when running on a computer or processor.
[0127] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for performing the following steps:
[0128] Step S30: Based on the server, perform a credibility test on the current node to obtain the first test result, wherein the current node is the electronic control unit in the vehicle detection system;
[0129] Step S32: In response to the first detection result satisfying the preset condition, perform credibility detection on the current node based on the vehicle-side detection system to obtain the second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than the preset threshold within a preset period.
[0130] Step S34: In response to the second detection result meeting the preset conditions, control the current node to send a master node declaration message to the other nodes and obtain the sending result. The master node declaration message is used to declare the current node as the master node, and the other nodes are the other electronic control units in the vehicle detection system other than the current electronic control unit.
[0131] Step S36: In response to the transmission result indicating that all other nodes have received the master node declaration message, the current node is set as the master node, whereby the master node is used to communicate with the server.
[0132] According to another aspect of the embodiments of the present invention, an electronic device 700 is also provided, such as... Figure 7 As shown, it includes a memory 701 and a processor 702. The memory 701 stores a computer program, and the processor 702 is configured to run the computer program to execute the communication node determination method of the vehicle-end detection system in any of the above-mentioned embodiments.
[0133] Optionally, in this embodiment, the processor in the above-described electronic device may be configured to run a computer program to perform the following steps:
[0134] Step S30: Based on the server, perform a credibility test on the current node to obtain the first test result, wherein the current node is the electronic control unit in the vehicle detection system;
[0135] Step S32: In response to the first detection result satisfying the preset condition, perform credibility detection on the current node based on the vehicle-side detection system to obtain the second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than the preset threshold within a preset period.
[0136] Step S34: In response to the second detection result meeting the preset conditions, control the current node to send a master node declaration message to the other nodes and obtain the sending result. The master node declaration message is used to declare the current node as the master node, and the other nodes are the other electronic control units in the vehicle detection system other than the current electronic control unit.
[0137] Step S36: In response to the transmission result indicating that all other nodes have received the master node declaration message, the current node is set as the master node, whereby the master node is used to communicate with the server.
[0138] In this application, "multiple" refers to two or more.
[0139] In this application, unless otherwise expressly defined, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0140] The terms “first,” “second,” “third,” “fourth,” etc., in this application (if present) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0141] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, in this application, the character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0142] Unless otherwise specified, all steps in this application may be performed sequentially or randomly. For example, if the method includes steps A and B, it means that the method may include steps A and B performed sequentially, or it may include steps B and A performed sequentially. For example, if the method may also include step C, it means that step C may be added to the method in any order. For example, the method may include steps A, B, and C, or it may include steps A, C, and B, or it may include steps C, A, and B, etc.
[0143] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A method for determining communication nodes in a vehicle-end detection system, characterized in that, include: The server performs a credibility test on the current node to obtain a first detection result, wherein the current node is an electronic control unit in the vehicle detection system; In response to the first detection result satisfying the preset condition, the credibility detection of the current node is performed based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period. In response to the second detection result satisfying the preset condition, the current node is controlled to send a master node declaration message to the other nodes to obtain the sending result. The master node declaration message is used to declare the current node as the master node, and the other nodes are the other electronic control units in the vehicle detection system other than the current electronic control unit. In response to the transmission result indicating that all other nodes have received the master node declaration message, the current node is set as the master node, wherein the master node is used to communicate with the server.
2. The method according to claim 1, characterized in that, The method further includes: In response to the current node being compromised, a new master node is determined from the remaining nodes.
3. The method according to claim 1, characterized in that, The first detection result obtained by performing a trustworthiness check on the current node based on the server includes: Information security records are obtained based on the server, wherein the information security records are the analysis results of abnormal situations of any node in the vehicle-side detection system; A first credibility value for the current node is determined based on the information security record; The first confidence value and the preset threshold are compared to obtain the first detection result.
4. The method according to claim 1, characterized in that, The step of performing credibility detection on the current node based on the vehicle-side detection system to obtain a second detection result includes: The information security log of the current node is obtained based on the vehicle-side detection system, wherein the information security log is used to record abnormal situations of the current node; A second trust value for the current node is determined based on the information security log; The second confidence value is compared with the preset threshold to obtain the second detection result.
5. The method according to claim 1, characterized in that, The method further includes: Set the remaining nodes as slave nodes; Control any slave node to send a slave node declaration message to any node other than the slave node itself, wherein the slave node declaration message is used to declare any of the remaining nodes as a slave node.
6. The method according to claim 1, characterized in that, The method further includes: In response to the first detection result not meeting the preset condition, the server performs a credibility detection on the next node of the current node to obtain a third detection result; The master node in the vehicle-side detection system is determined based on the third detection result; or In response to the second detection result not meeting the preset condition, the server performs a credibility detection on the next node of the current node to obtain a fourth detection result; The master node in the vehicle-side detection system is determined based on the fourth detection result.
7. The method according to claim 1, characterized in that, The method further includes: In response to the transmission result indicating that none of the remaining nodes have received the master node declaration message, the server performs a trustworthiness check on the next node of the current node to obtain a fifth detection result. The master node in the vehicle-side detection system is determined based on the fifth detection result.
8. A communication node determination device for a vehicle-end detection system, characterized in that, The device includes: The first detection module is used to perform credibility detection on the current node based on the server and obtain a first detection result, wherein the current node is an electronic control unit in the vehicle detection system. The second detection module is used to respond to the first detection result satisfying a preset condition by performing a credibility detection on the current node based on the vehicle-side detection system to obtain a second detection result, wherein the preset condition is used to indicate that the credibility value of the current node is greater than a preset threshold within a preset period. The sending module is used to control the current node to send a master node declaration message to the other nodes in response to the second detection result satisfying the preset condition, and to obtain the sending result. The master node declaration message is used to declare the current node as the master node, and the other nodes are the other electronic control units in the vehicle detection system other than the current electronic control unit. The setting module is used to set the current node as the master node in response to the sending result indicating that all other nodes have received the master node declaration message, wherein the master node is used to communicate with the server.
9. A vehicle, characterized in that, The vehicle includes: a memory storing an executable program; and a processor for running the program, wherein the program executes the communication node determination method of the vehicle-end detection system according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, wherein the computer program is configured to execute the communication node determination method of the vehicle-end detection system as described in any one of claims 1 to 7 when running on a computer or processor.
Citation Information
Patent Citations
Apparatus and method for detection error recovery of trust-based routing
KR1020150062136A
Method for adjusting node detection parameters, node, and mesh network
WO2018192288A1