A secure message communication method for Internet of Vehicles based on feature vectors

By adopting the methods of feature vector processing and cloud-based anomaly analysis in the Internet of Vehicles system, the problems of low efficiency and privacy information leakage in the Internet of Vehicles system when detecting complex network attacks are solved, and efficient and secure security incident analysis is achieved.

CN120455166BActive Publication Date: 2025-09-30UNIV OF SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510937692.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-08
Publication Date
2025-09-30
Estimated Expiration
2045-07-08

AI Technical Summary

Technical Problem

Existing Internet of Vehicles systems have problems with low efficiency and poor accuracy when detecting and identifying complex network attacks. At the same time, there is a high risk of privacy information leakage during log data transmission.

Method used

A feature vector-based secure message communication method is adopted to vectorize security event logs through distributed probes and transmit them to the main probe in the vehicle using a specified message sequence. The cloud then performs anomaly analysis and uses pre-trained vector models to identify cross-domain abnormal behaviors and attack patterns.

Benefits of technology

While reducing bandwidth resource consumption, it improves the efficiency and accuracy of secure message communication, reduces the risk of log packet loss, and improves the analysis accuracy of complex network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455166B_ABST
    Figure CN120455166B_ABST
Patent Text Reader

Abstract

The present invention discloses a vehicle network security message communication method based on feature vectors, which belongs to the field of vehicle network technology. The distributed probes deployed in the vehicle will vectorize the generated security event logs, and then send the vectorized logs to the main probe in the vehicle through a specified message sequence; the main probe in the vehicle collects the vectorized log messages of the entire vehicle and sends the vectorized log messages that meet the conditions through a specified message sequence to the cloud; the cloud uses a pre-trained vector model to perform anomaly analysis on the received vectorized log messages, and analyzes and judges the multi-domain abnormal behaviors, attack patterns or complex security events in the vehicle, and feeds the analysis results back to the main probe in the vehicle. This method can improve the efficiency of security message communication while reducing the consumption of bandwidth resources inside and outside the vehicle, and indirectly improve the accuracy of security event analysis while ensuring that the logs are transmitted without packet loss.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle networking, and in particular to a vehicle networking security message communication method based on feature vectors. Background Art

[0002] The Internet of Vehicles (IoV) is an intelligent transportation system that interconnects vehicles, road infrastructure, pedestrians, networks, and service platforms through wireless communication technologies. The core goal of the IoV is to achieve vehicle automation, intelligence, and networking through data exchange and intelligent processing, thereby improving traffic safety, optimizing traffic efficiency, providing a better user experience, and ultimately facilitating the development of autonomous driving. Currently, the detection and identification of IoV attacks has also become increasingly important. The diverse network connections within and outside the vehicle, including 4G / 5G, V2X, Wi-Fi, Bluetooth, and satellite communications, provide additional avenues for attack. Ransomware attacks, unauthorized access, and virus injection are rapidly infiltrating the IoV sector, compromising the security of multiple end-point systems, including multiple modules within the vehicle, including but not limited to the infotainment system, control units (ECUs), network interfaces (such as the CAN bus), OTA update modules, and V2X communication modules.

[0003] Therefore, when physical anomalies (such as abnormal braking or steering angle), trajectory anomalies (such as route changes or unusual geographic locations), and network anomalies (such as malicious code or vulnerability exploitation logs in the cockpit domain) occur within the vehicle, multi-domain and multi-sensor logs must be aggregated for comprehensive analysis to determine the attack type (e.g., simple hardware failure, network attack), analyze the attack source (e.g., from the powertrain domain itself, external attackers, remote V2X network attackers), and assess the attack impact (e.g., impact on the vehicle domain, all domains, or V2X worm-like properties). For complex network attacks, especially those with worm-like properties or when cloud-based assessment requires broader correlation, further collaborative analysis and global response are conducted with cloud-based analysis platforms such as the connected vehicle VSOC.

[0004] Currently, log transmission inside and outside the vehicle is done using the original log text. In-vehicle security components / probes (such as IDPS, terminal antivirus SDKs, and apps) perform physical and network security checks on various domains and sensors within the vehicle. These security logs are then aggregated and sent to centralized management devices like T-BOX, which then interacts with the cloud-based VSOC. This introduces new challenges. Firstly, the efficiency and accuracy of comprehensive analysis depend on accurate and efficient message transmission to analyze large amounts of logs. Secondly, logs carry a significant amount of private information about vehicle owners, and these new interactions inevitably introduce new security risks, such as hijacking during log data transmission, leaks during storage, and data security issues during multi-level transfer and use. If exploited maliciously, these risks could increase security risks for the connected vehicle and smart cars themselves. Summary of the Invention

[0005] The purpose of the present invention is to provide a vehicle network security message communication method based on feature vectors. This method can improve the efficiency of security message communication while reducing the consumption of bandwidth resources inside and outside the vehicle, and indirectly improve the accuracy of security event analysis while ensuring that logs are transmitted without packet loss.

[0006] The purpose of the present invention is achieved through the following technical solutions:

[0007] A method for secure message communication in an Internet of Vehicles based on a feature vector, the method comprising:

[0008] Step 1: The distributed probes deployed in the vehicle vectorize the generated security event logs and then send the vectorized logs to the master probe in the vehicle through a specified message sequence;

[0009] Step 2: The main probe in the vehicle collects vectorized log messages from the entire vehicle and sends the qualified vectorized log messages to the cloud through a specified message sequence;

[0010] The specified message sequence adopts a hierarchical structure design, including a message header, a message body and a message footer; the message header is used to describe the meta information of the message, including synchronization identifier, message type, priority, message length, sending node ID, timestamp and check code fields, and is designed with a fixed-length field; the message body stores actual security data, which is used to store the data content after log vectorization, has a variable length, supports encryption and data integrity verification, and includes data type, data content and data signature fields;

[0011] Step 3: The cloud uses a pre-trained vector model to perform anomaly analysis on the received vectorized log messages, analyze and judge multi-domain abnormal behaviors, attack patterns, or complex security incidents in the vehicle, and feed back the analysis results to the main probe in the vehicle.

[0012] It can be seen from the technical solution provided by the above-mentioned present invention that the above-mentioned method can improve the efficiency of security message communication while reducing the consumption of bandwidth resources inside and outside the vehicle, and indirectly improve the accuracy of security event analysis while ensuring that logs are transmitted without packet loss, providing an efficient and secure communication mechanism for the complex multi-layer cross-domain security log data fusion analysis of the Internet of Vehicles. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0014] Figure 1 A schematic diagram of a flow chart of a vehicle network security message communication method based on feature vectors provided in an embodiment of the present invention;

[0015] Figure 2 It is a schematic diagram of the overall structure of the example of the present invention. DETAILED DESCRIPTION

[0016] The following is a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments, and do not constitute a limitation of the present invention. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0017] like Figure 1 FIG2 is a flow chart of a method for secure message communication in an Internet of Vehicles based on feature vectors according to an embodiment of the present invention. The method includes:

[0018] Step 1: The distributed probes deployed in the vehicle vectorize the generated security event logs and then send the vectorized logs to the master probe in the vehicle through a specified message sequence;

[0019] In this step, the security event log includes: logs of physical security alarms (such as tire pressure alarms, brake abnormalities) and network security events (such as attack intrusions, virus infections) generated by various domains during vehicle driving.

[0020] In specific implementations, vectorization processing uses algorithms with appropriate resource overhead, such as Word2Vec (word to vector, an algorithm tool for training word vectors, mainly divided into two modes: CBOW and Skip-Gram), GloVe (Global Vectors for Word Representation, an unsupervised learning algorithm used to obtain vector representations of words, an extension of the Word2Vec model), or FastText (Bag of Tricks for Efficient Text Classification, an open source word vector and text classification tool, an efficient linear classification model with only one layer of neural network structure, a typical algorithm for lightweight text classification). There are no rigid requirements, and a global unified method can be used. The specific processing process is as follows:

[0021] First, pre-process the generated security event logs, extract key event words from the logs, and construct a "context window" (for example, "CAN abnormality" is often accompanied by "bus overload");

[0022] The model is then trained using the Skip-Gram model in the Word2Vec word vector training algorithm tool to learn inter-word relationships. This makes the vectors of co-occurring words (such as "attack" and "malicious IP") similar. The model then outputs the vectors, mapping the key event words in each log (such as "illegal access") into a dense vector of a fixed dimension. Words with similar semantics have similar vector distances.

[0023] Ultimately, the discrete security event log text is converted into computable numerical features, improving the automation capabilities of security analysis.

[0024] In addition, the distributed probes are installed on each domain controller or in-vehicle component, responsible for security monitoring within the domain and facility. They are in the form of IDS / IDPS SDK modules or antivirus apps installed in the vehicle.

[0025] The in-vehicle master probe is installed on the gateway, core domain control, vehicle computing platform MDC, or vehicle networking terminal T-BOX.

[0026] Step 2: The main probe in the vehicle collects vectorized log messages from the entire vehicle and sends the qualified vectorized log messages to the cloud through a specified message sequence;

[0027] In step 1 and step 2, the specified message sequence adopts a hierarchical structure design, including a message header, a message body and a message footer, wherein:

[0028] The message header is used to describe the message's metadata, including synchronization flag, message type, priority, message length, sending node ID, timestamp, and checksum fields. It uses a fixed-length field design to ensure fast parsing, as shown in Table 1 below:

[0029] Table 1 Message header field definition

[0030]

[0031] The synchronization identification field has a fixed length of 8 bits and uses a fixed value to mark the start of the message, such as 0xAA;

[0032] The message type field is a fixed length of 4 bits and is used to identify the message type, including physical anomalies (such as collision alerts and tire pressure abnormalities), network anomalies (such as network intrusion logs and virus logs), and unexplained anomalies.

[0033] The priority field is a fixed 4-bit field that identifies the message priority, ranging from 0 to 15. A higher value indicates a higher priority. This field is derived from or mapped to the importance of the original log. In situations where bandwidth and resources are competing, high-risk security incidents are prioritized.

[0034] The message length field is a fixed length of 16 bits, supporting messages up to 64KB in size.

[0035] The sending node ID field is the unique identifier of the node sending the message; for example, a sensor ID or a distributed probe ID.

[0036] The timestamp field is used to support event tracing and message sorting;

[0037] The checksum field is used for the cyclic redundancy check (CRC-16) of the message header.

[0038] The message body (Payload) stores actual security data and is used to store the data content after log vectorization. It has a variable length and supports encryption and data integrity verification. It includes data type, data content, and data signature fields, as shown in Table 2 below:

[0039] Table 2 Message body field definition

[0040]

[0041] The data type field is a fixed length of 8 bytes and is used to describe the type of data content. For example, 0x01 indicates a dangerous log message, and 0x02 indicates a general dangerous log message. It is divided into four levels (information, general, serious, and fatal).

[0042] The data content field is a variable-length field used to store actual security data. The content is defined based on the specific log vectorization algorithm used and supports JSON, XML, or binary formats.

[0043] The data signature field is a 128-byte optional field generated based on the sender's private key. It is used for identity authentication and tamper prevention and is mainly used for secondary and multi-level communications (i.e., sender identity verification for off-vehicle communications).

[0044] The message footer is used to mark the end of the message and provide data integrity verification, as shown in Table 3 below:

[0045] Table 3 Message tail field definition

[0046]

[0047] In the specific implementation, considering the security of extra-vehicle communication, digital signature and identity authentication mechanisms can be introduced in the specified message sequence to ensure the authenticity and integrity of the message.

[0048] Step 3: The cloud uses a pre-trained vector model to perform anomaly analysis on the received vectorized log messages, analyze and judge multi-domain abnormal behaviors, attack patterns, or complex security incidents in the vehicle, and feed back the analysis results to the main probe in the vehicle.

[0049] In this step, during the specific implementation process, a comprehensive analysis can be performed through the dual-S fusion analysis model of the physical domain and the network security domain. Other algorithms that can complete log vector detection and analysis are also feasible.

[0050] The process of comprehensive analysis and judgment using the dual-S fusion analysis model of the physical and network security domains is as follows:

[0051] The cloud performs anomaly analysis on received vectorized log messages and determines whether the vector directions of network security domain logs and physical domain logs are similar through similarity matching.

[0052] If they are close, we will conduct graph network analysis, build an attack vector association graph, identify cross-domain attack paths, and finally analyze the attack scenario and attack pattern.

[0053] For example, a distributed probe receives routine security alerts from the physical domain (such as the power domain) and the network security domain (such as the entertainment domain) within a certain period of time, including the following information:

[0054] Power domain: "CAN bus injection attack", "motor control command tampering", "battery temperature abnormality";

[0055] And in the entertainment domain: "Malicious APP installation", "Unauthorized access to USB interface", "OTA upgrade package signature invalid";

[0056] The distributed probe then uses vectorization processing, such as the Word2Vec model, to convert keywords (such as "injection," "tampering," and "malicious") in each security event log into a dense vector.

[0057] The cloud performs an anomaly analysis on the received vectorized log messages. Through similarity matching, it finds that the vector directions of the entertainment domain log "Malicious APP Privilege Escalation" and the power domain "CAN Command Anomaly" are similar (both contain the "unauthorized" semantics). Graph network analysis is then performed to construct an attack vector association diagram and identify cross-domain attack paths (such as entertainment domain → gateway → power domain). The final attack scenario and attack mode are analyzed as follows: the attacker infiltrates the power domain (CAN bus) through a vulnerability in the entertainment domain (such as a malicious app). The predicted attack risk is: controlling the vehicle's speed or direction, and the source of the attack can be deduced to be the malicious replacement of the OTA upgrade package or the bundling of a Trojan horse.

[0058] In addition, the cloud will synchronize the analysis results to each distributed probe as needed to facilitate coordinated processing of the entire vehicle.

[0059] An embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the method.

[0060] An embodiment of the present invention further provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the method.

[0061] The method of the embodiment of the present invention is described in detail below with specific examples. Figure 2 The figure shows a schematic diagram of the overall structure of the example of the present invention, including multiple in-vehicle distributed probes installed in the vehicle, one in-vehicle master probe, and a processing center (i.e., VSOC / cloud security capability center) installed outside the vehicle.

[0062] based on Figure 2 In the system structure, suppose that when a vehicle is driving, an abnormal braking in the power domain triggers a collision alarm in the ADAS domain. After the log is reported to the safety probe of the domain (power domain, ADAS domain), it will also be reported to the main probe in the vehicle using the above message format.

[0063] Taking the ADAS domain reporting message as an example, it can be expressed as follows:

[0064] Header: / / message header

[0065] - Sync: 0xAA / / Message content: synchronization flag, fixed value, identifies the processing start position

[0066] - Type: 0x01 (Physical Security Message: Collision Alert) / / Message type: includes physical domain, network domain exceptions, and unknown exception messages (pre-defined, such as 01 for physical domain exceptions)

[0067] - Priority: 0xF (highest priority) / / Priority: The larger the value, the higher the priority, ensuring that high-risk events can be handled immediately

[0068] - Length: 0x0030 (message body length 48 bytes) / / Message length: the content length of this message, maximum supported 64KB

[0069] - SenderID: 0x0012 / / Sending node ID, indicating which sensor and security probe the message comes from

[0070] - Timestamp: 0x5F5E100 (1,600,000 milliseconds) / / Timestamp: used to support timing analysis and correlation sorting during event tracing

[0071] - Header CRC: 0x1A2B / / Header checksum: Use CRC to check the integrity of the header

[0072] Payload: / / message body

[0073] - DataType: 0x03 (Severe Security Information) / / Indicates the message type level, which is convenient for classification and assessment. Generally, there are four levels: fatal, severe, general, and warning.

[0074] - Data: {vectorized data of ADAS domain collision warning log} / / The content of sensor safety log is vectorized and supports various formats

[0075] - Signature:null / / Digital signature: optional; if present, it can be the sender's private key signature, used for identity verification by the receiver. If left blank, no signature verification is required.

[0076] - Payload CRC: 0x3C4D / / Payload CRC check, used to verify the integrity of the message content

[0077] The cloud uses a pre-trained vector model to perform anomaly analysis on the received vectorized log messages, analyze and judge multi-domain abnormal behaviors, attack patterns or complex security incidents in the vehicle, and feed back the analysis results to the main probe in the vehicle.

[0078] It should be noted that the contents not described in detail in the embodiments of the present invention belong to the prior art known to those skilled in the art.

[0079] In summary, compared with compression, the method described in the embodiment of the present invention does not require secondary processing of vectorized messages at the receiving end and can be used immediately after receiving. Compared with sampling, the method has good message integrity and high analysis accuracy. Vectorization is inherently irreversible and can resist certain hijacking attacks and data leaks.

[0080] At the same time, the method of the present invention can improve the efficiency of security message communication while reducing the consumption of bandwidth resources inside and outside the vehicle, and indirectly improve the accuracy of security event analysis while ensuring that logs are transmitted without packet loss, providing an efficient and secure communication mechanism for the complex multi-layer cross-domain security log data fusion analysis of the Internet of Vehicles.

[0081] In addition, those skilled in the art will understand that all or part of the steps in the above-mentioned embodiment method can be implemented by instructing the relevant hardware through a program, and the corresponding program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a disk or an optical disk, etc.

[0082] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by any person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims. The information disclosed in the background technology section of this article is only intended to deepen the understanding of the overall background technology of the present invention, and should not be regarded as an admission or any form of implication that the information constitutes prior art already known to those skilled in the art.

Claims

1. A vehicle network security message communication method based on feature vectors, characterized in that: The method comprises: Step 1: The distributed probes deployed in the vehicle vectorize the generated security event logs and then send the vectorized logs to the master probe in the vehicle through a specified message sequence; In step 1, the vectorization process is as follows: First, pre-process the generated security event logs, extract key event words from the logs, and build a "context window"; We then use the Skip-Gram model in the Word2Vec word vector training algorithm tool to train the model, learn the relationship between words, and make the co-occurring word vectors similar. We then output the vectors and map the key event words in each log to a dense vector of a fixed dimension. The vectors of words with similar semantics are close to each other. Finally, the discrete security event log text is converted into computable numerical features; Step 2: The main probe in the vehicle collects vectorized log messages from the entire vehicle and sends the qualified vectorized log messages to the cloud through a specified message sequence; The specified message sequence adopts a hierarchical structure design, including a message header, a message body and a message footer; the message header is used to describe the meta information of the message, including synchronization identifier, message type, priority, message length, sending node ID, timestamp and check code fields, and is designed with a fixed-length field; the message body stores actual security data, which is used to store the data content after log vectorization, has a variable length, supports encryption and data integrity verification, and includes data type, data content and data signature fields; Step 3: The cloud uses a pre-trained vector model to perform anomaly analysis on the received vectorized log messages, analyze and judge multi-domain abnormal behaviors, attack patterns, or complex security incidents in the vehicle, and feed back the analysis results to the main probe in the vehicle.

2. The vehicle network security message communication method based on feature vector according to claim 1 is characterized in that: In step 1, the security event log includes: a log of physical security alarms and network security events generated by each domain during vehicle driving.

3. The vehicle network security message communication method based on feature vector according to claim 1, characterized in that: The synchronization identification field has a fixed length of 8 bits and uses a fixed value to mark the start of the message; The message type field is a fixed length of 4 bits and is used to identify the message type, including physical anomaly, network anomaly, and unexplained anomaly. The priority field is a fixed 4-bit field that identifies the message priority. A higher value indicates a higher priority. This field is derived from or mapped to the importance of the original log. In situations where bandwidth and resources are competing, high-risk security incidents are prioritized. The message length field is a fixed length of 16 bits, supporting messages up to 64KB in size. The sending node ID field is the unique identifier of the node sending the message; The timestamp field is used to support event tracing and message sorting; The checksum field is used for cyclic redundancy check of the message header.

4. The vehicle network security message communication method based on feature vector according to claim 1, characterized in that: The data type field has a fixed length of 8 bytes and is used to describe the type of data content; The data content field is a variable-length field used to store actual security data. The content is defined based on the specific log vectorization algorithm used and supports JSON, XML, or binary formats. The data signature field is a 128-byte optional field generated based on the sender's private key for identity authentication and tamper prevention.

5. The vehicle network security message communication method based on feature vector according to claim 1, characterized in that: The message tail is used to mark the end of the message and provide data integrity verification.

6. The vehicle network security message communication method based on feature vector according to claim 1, characterized in that: In step 3, the cloud uses a pre-trained vector model to perform anomaly analysis on the received vectorized log messages, identifying multi-domain abnormal behaviors, attack patterns, or complex security incidents within the vehicle. The specific process is as follows: The cloud performs anomaly analysis on received vectorized log messages using a dual-S fusion analysis model of the physical and network security domains. It uses similarity matching to determine whether the vector directions of network security domain logs and physical domain logs are similar. If they are close, we conduct graph network analysis, build an attack vector association graph, identify cross-domain attack paths, and ultimately analyze the attack scenario and attack pattern. The cloud synchronizes the analysis results to each distributed probe as needed.

7. The vehicle network security message communication method based on feature vector according to claim 1, characterized in that: The distributed probes are installed on each domain controller or vehicle component and are responsible for security monitoring within the domain and facility. The in-vehicle master probe is installed on a gateway, core domain control, vehicle computing platform, or vehicle-connected network terminal.

8. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 7.

9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Security processing method and server

    CN112437056A

  • SecOC communication security event processing method and device and electronic control unit

    CN117040865A