Communication method between vehicle-mounted electronic control units and vehicle

By adopting the decentralized identity authentication method of zero-knowledge proof and blockchain verification nodes between the on-board electronic control units, the problem of insufficient identity authentication security between the on-board electronic control units is solved, and higher communication security and reliability are achieved.

CN120474722AActive Publication Date: 2025-08-12CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510862770.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-08-12
Estimated Expiration
2045-06-25

AI Technical Summary

Technical Problem

The security of identity authentication between on-board electronic control units is low, and there is a risk of centralized dependence, resulting in insufficient communication security.

Method used

Identity authentication is used to be authenticated by zero-knowledge proof and blockchain technology, decentralized authentication is performed through blockchain verification nodes, and dynamic adjustment of global parameters and delay thresholds is improved to improve the security and reliability of authentication.

Benefits of technology

It improves the identity authentication security and communication reliability between the on-board electronic control units, reduces the risk of authentication failure caused by network delay or fluctuations, and enhances the stability and robustness of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474722A_ABST
    Figure CN120474722A_ABST
Patent Text Reader

Abstract

The invention provides a communication method between vehicle-mounted electronic control units and a vehicle, and relates to the technical field of information security. The method is applied to a first electronic control unit. The method comprises the following steps: sending an identity authentication request to a second electronic control unit, so that the second electronic control unit sends the identity authentication request to a block chain verification node; the identity authentication request is used for indicating the block chain verification node to authenticate the identity of the first electronic control unit; the identity authentication request comprises an identity label, and the identity label is generated by the first electronic control unit through zero-knowledge proof; receiving a session connection request sent by a second electronic control unit; and establishing a secure session with the second electronic control unit according to the session connection request, and communicating with the second electronic control unit. According to the invention, before different electronic control units communicate, identity authentication is completed in combination with zero-knowledge proof and the block chain, so that the security of identity authentication is improved, and thus the communication security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a communication method between vehicle-mounted electronic control units and a vehicle. Background Art

[0002] With the development of intelligent and connected new energy vehicles, communication security between various onboard electronic control units (ECUs) is crucial. In traditional authentication processes, ECU identity information is typically transmitted in plain text or encrypted using a fixed key. Cloud servers are often used as the authentication center for authentication, which poses a risk of centralized dependency, resulting in lower authentication security between ECUs and, ultimately, lower communication security. Summary of the Invention

[0003] The purpose of the embodiments of the present application is to provide a communication method and vehicle between on-board electronic control units, which are used to combine zero-knowledge proof and blockchain to complete identity authentication before different electronic control units communicate, thereby improving the security of identity authentication and thus improving communication security.

[0004] In a first aspect, an embodiment of the present application provides a communication method between vehicle-mounted electronic control units, which is applied to a first electronic control unit; the method includes: sending an identity authentication request to a second electronic control unit, so that the second electronic control unit sends an identity authentication request to a blockchain verification node; the identity authentication request is used to instruct the blockchain verification node to authenticate the identity of the first electronic control unit; the identity authentication request includes an identity identifier, which is generated by the first electronic control unit using zero-knowledge proof; receiving a session connection request sent by the second electronic control unit; the session connection request is generated after the second electronic control unit receives the authentication pass identifier sent by the blockchain verification node; establishing a secure session with the second electronic control unit according to the session connection request, and communicating with the second electronic control unit.

[0005] In the embodiment of the present application, since zero-knowledge proof allows the prover to prove his or her legitimacy to the verifier without revealing his or her own identity, the first electronic control unit sends an identity authentication request containing an identity identifier generated using zero-knowledge proof to the second electronic control unit, allowing the first electronic control unit to perform authentication without revealing its own identity, thereby improving the security of identity authentication. In addition, considering that traditional authentication methods have the risk of single point failure caused by centralized dependence, the second electronic control unit sends the identity authentication request to the blockchain verification node for authentication, so as to achieve decentralized identity authentication through the distributed characteristics of the blockchain, further improving the security of identity authentication, and thus improving communication security.

[0006] In some embodiments, the blockchain verification node authenticates the identity of the first electronic control unit, including: the blockchain verification node obtains the authentication duration of a recent preset number of historical identity authentication requests; the blockchain verification node calculates the delay variance based on multiple authentication durations; the blockchain verification node calculates the timeout period based on the authentication duration and delay variance of the most recent historical identity authentication request; if the authentication duration of the blockchain verification node for authenticating the identity of the first electronic control unit is not greater than the timeout period, the blockchain verification node sends an authentication pass identifier to the second electronic control unit.

[0007] In the embodiment of the present application, the timeout period is calculated based on the authentication duration of a preset number of recent historical identity authentication requests. This allows the blockchain verification node to dynamically adjust the timeout period based on the real-time status of the blockchain network, reducing authentication failures caused by network delays or fluctuations and improving authentication reliability. Furthermore, if authentication is completed within the timeout period, an authentication pass indicator is sent to the second electronic control unit to inform the second electronic control unit that the first electronic control unit's identity is legitimate and secure communication is possible, thereby improving communication reliability.

[0008] In some embodiments, the method further includes: if the authentication time of the blockchain verification node for authenticating the identity of the first electronic control unit is longer than the timeout period, the blockchain verification node sends an alarm prompt to the second electronic control unit.

[0009] In the embodiment of the present application, an alarm is sent to inform the second electronic control unit that the authentication has failed, indicating that the identity of the first electronic control unit may be illegal, so as to prevent potential malicious attacks and improve communication reliability.

[0010] In some embodiments, during the process of communicating with the second electronic control unit, the method also includes: obtaining global parameters and the most recent historical delay threshold; the global parameters include the number of historical attacks on the vehicle system to which the first electronic control unit belongs, the network load parameters of the network to which the first electronic control unit and the second electronic control unit belong, and the health status parameters of the first electronic control unit and the second electronic control unit; calculating a new delay threshold based on the global parameters; if the delay change rate of the new delay threshold and the historical delay threshold is greater than the preset change rate threshold, updating the historical delay threshold according to the new delay threshold; the new delay threshold is used to determine whether the communication duration between the first electronic control unit and the second electronic control unit is normal.

[0011] In the embodiment of the present application, during communication between a first electronic control unit and a second electronic control unit, a new delay threshold is calculated in real time by acquiring global parameters. Furthermore, when the rate of change of the new delay threshold is greater than that of the previous historical delay threshold, the historical delay threshold is updated. This allows the threshold to be dynamically adjusted based on the network environment and the state of the electronic control units, improving the adaptability of the delay threshold. Furthermore, the delay threshold is used to determine whether the communication duration between the first and second electronic control units is normal. Because the delay threshold changes dynamically, misjudgments of communication anomalies are reduced, improving the continuity and robustness of the communication process.

[0012] In some embodiments, calculating a new delay threshold based on the global parameter includes: Calculate the new delay threshold; where, Indicates the new latency threshold, represents the initial delay threshold, represents the adjustment coefficient, Indicates the global parameters, Indicates the The weight coefficients of the global parameters, Indicates the number of global parameters.

[0013] The embodiment of the present application calculates a new delay threshold based on global parameters, so that the threshold can be dynamically adjusted according to the network environment and the status of the electronic control unit, thereby improving the adaptability of the delay threshold.

[0014] In some embodiments, after updating the historical delay threshold according to the new delay threshold, the method also includes: sending a pending request to the second electronic control unit; the pending request includes a first timestamp; if the time from the first timestamp to receiving the response request sent by the second electronic control unit is greater than the new delay threshold, an abnormal information is issued.

[0015] In the embodiment of the present application, when the communication duration between the first electronic control unit and the second electronic control unit is greater than the new delay threshold, an abnormality message is issued, thereby improving the security of the communication process.

[0016] In a second aspect, an embodiment of the present application provides another communication method between vehicle-mounted electronic control units, the method comprising: a first electronic control unit sends an identity authentication request to a second electronic control unit; the identity authentication request includes an identity identifier, which is generated by the first electronic control unit using zero-knowledge proof; the second electronic control unit sends an identity authentication request to a blockchain verification node, so that the blockchain verification node authenticates the identity of the first electronic control unit based on the identity authentication request; the blockchain verification node sends a verification result to the second electronic control unit; if the verification result indicates that the verification is passed, the second electronic control unit sends a session connection request to the first electronic control unit; the first electronic control unit establishes a secure session with the second electronic control unit according to the session connection request, and communicates with the second electronic control unit.

[0017] In the embodiment of the present application, since zero-knowledge proof allows the prover to prove his or her legitimacy to the verifier without revealing his or her own identity, the first electronic control unit sends an identity authentication request containing an identity identifier generated using zero-knowledge proof to the second electronic control unit, allowing the first electronic control unit to perform authentication without revealing its own identity, thereby improving the security of identity authentication. In addition, considering that traditional authentication methods have the risk of single point failure caused by centralized dependence, the second electronic control unit sends the identity authentication request to the blockchain verification node for authentication, so as to achieve decentralized identity authentication through the distributed characteristics of the blockchain, further improving the security of identity authentication, and thus improving communication security.

[0018] In a third aspect, an embodiment of the present application provides a communication device between vehicle-mounted electronic control units, the device comprising: a sending module for sending an identity authentication request to a second electronic control unit, so that the second electronic control unit sends an identity authentication request to a blockchain verification node; the identity authentication request is used to instruct the blockchain verification node to authenticate the identity of the first electronic control unit; the identity authentication request includes an identity identifier, which is generated by the first electronic control unit using zero-knowledge proof; a receiving module for receiving a session connection request sent by the second electronic control unit; the session connection request is generated after the second electronic control unit receives the authentication pass identifier sent by the blockchain verification node; a communication module for establishing a secure session with the second electronic control unit according to the session connection request, and communicating with the second electronic control unit.

[0019] In a fourth aspect, an embodiment of the present application provides an electronic control unit, comprising: a processor and a memory, the memory storing machine-readable instructions executable by the processor, and the machine-readable instructions, when executed by the processor, can execute the method steps of any one of the embodiments of the first aspect, the second aspect, or both aspects.

[0020] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, comprising: computer program instructions are stored on the computer-readable storage medium, and when the computer program instructions are executed by a processor, the method steps of any one embodiment of the first aspect, the second aspect, or both aspects are executed.

[0021] In a sixth aspect, an embodiment of the present application provides a computer program product, comprising: computer program instructions, which, when executed by a processor, execute the method steps of the embodiment of the first aspect, the second aspect, or any one of the two aspects.

[0022] In the seventh aspect, an embodiment of the present application provides a vehicle, the vehicle including a first electronic control unit and a second electronic control unit, the first electronic control unit and the second electronic control unit being communicatively connected; the first electronic control unit is used to execute the method steps of any one embodiment of the first aspect, the second aspect or both aspects.

[0023] Other features and advantages of the present application will be described in the subsequent description, and in part will become apparent from the description, or will be understood by practicing the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0025] Figure 1 A flow chart of a communication method between vehicle-mounted electronic control units provided in an embodiment of the present application; Figure 2 A flow chart of another method for communicating between vehicle-mounted electronic control units provided in an embodiment of the present application; Figure 3 A schematic diagram of the structure of a communication device between vehicle-mounted electronic control units provided in an embodiment of the present application; Figure 4 A schematic structural diagram of an electronic control unit provided in an embodiment of the present application. DETAILED DESCRIPTION

[0026] The following embodiments of the technical solution of the present application will be described in detail with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present application and are therefore only examples and are not intended to limit the scope of protection of the present application.

[0027] It should be noted that all technical and scientific terms used herein have the same meanings as those commonly understood by technicians in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" in the specification and claims of this application and the above-mentioned figure descriptions and any variations thereof are intended to cover non-exclusive inclusions.

[0028] In the description of the embodiments of this application, the technical terms "first" and "second" are used only to distinguish different objects and should not be understood to indicate or imply relative importance or implicitly specify the quantity, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "plurality" is more than two, unless otherwise clearly and specifically defined.

[0029] Figure 1 This is a flow chart illustrating a method for communication between onboard electronic control units (ECUs) according to an embodiment of the present application. The method is applied to a first ECU. The first ECU is installed on a vehicle and is used to collect vehicle data (such as speed and temperature) through sensors, process it using a built-in algorithm, and then drive actuators to perform physical operations. Furthermore, as a node in the vehicle network, it exchanges data with other onboard ECUs in the vehicle to achieve collaboration.

[0030] For example, the engine's electronic control unit (ECU) controls fuel injection, ignition timing, and optimizes power output based on accelerator pedal signals and oxygen sensor data. The brake ECU receives signals from wheel speed sensors and triggers the anti-lock braking system (ABS) to prevent wheel lock.

[0031] like Figure 1 As shown, the method includes: In step S101, the first electronic control unit sends an identity authentication request to the second electronic control unit, so that the second electronic control unit sends an identity authentication request to the blockchain verification node; the identity authentication request is used to instruct the blockchain verification node to authenticate the identity of the first electronic control unit; the identity authentication request includes an identity identifier, and the identity identifier is generated by the first electronic control unit using zero-knowledge proof.

[0032] In a specific implementation, the second electronic control unit is also an on-board electronic control unit, and cooperates with the first electronic control unit to control the vehicle.

[0033] For example, a first electronic control unit controls a vehicle's powertrain system, while a second electronic control unit controls a vehicle's automated driving assistance system. The first and second electronic control units communicate to coordinate power output and automated driving assistance functions.

[0034] It should be noted that the second electronic control unit can also serve as the first electronic control unit, and the first electronic control unit can also serve as the second electronic control unit. Specifically, the electronic control unit that initiates the identity authentication request is regarded as the first electronic control unit, and the electronic control unit that receives the identity authentication request is regarded as the second electronic control unit.

[0035] During the vehicle production process, each electronic control unit on the vehicle is assigned a unique private key and a corresponding public key, which are stored in their respective Hardware Security Modules (HSMs).

[0036] Considering the limited computing power of the vehicle's electronic control unit, the identity authentication process is implemented by remotely calling an external node. Therefore, the vehicle manufacturer deploys blockchain verification nodes at the base station to form a distributed authentication network to verify the identity of the first electronic control unit.

[0037] The identity identifier is used to uniquely identify the identity of the first electronic control unit.

[0038] An identity authentication request is a request sent by a first electronic control unit to a second electronic control unit to verify the legitimacy of the first electronic control unit. The identity authentication request includes an identity identifier and may also include at least one of the following information: a timestamp and a random number to prevent replay attacks.

[0039] The first electronic control unit also includes a zero-knowledge proof generation module, which is used to use its own private key and the corresponding public key to generate an identity through a zero-knowledge proof algorithm.

[0040] The zero-knowledge proof algorithm may be a Schnorr proof algorithm, a Feige-Fiat-Shamir proof algorithm, or other commonly used algorithms.

[0041] To understand how to generate an identity, let’s take the Schnorr proof algorithm as an example: According to the formula Generate an identity. Indicates identity, represents the private key of the first electronic control unit, Indicates the public key of the first electronic control unit. The public key is public information. The blockchain verification node can verify the legality of the identity of the first electronic control unit through the public key. Represents a hash function.

[0042] According to the formula The specific steps to generate an identity are as follows: (1) Randomly select parameters ,calculate ; A one-time random number used to provide unpredictability and uniqueness during the proof process, ensuring that each proof is different and preventing attackers from forging identities by reusing proofs. Represents the generator, which is a public parameter. Indicated by go through The value obtained by the power operation is used to generate the random challenge parameter in the proof process.

[0043] (2) Calculation ; Indicates the public key of the first electronic control unit, during the authentication process, To verify the legitimacy of the certificate. represents a hash function, Represents the random challenge parameter.

[0044] (3) Calculation ; represents the private key of the first electronic control unit, Indicates the response parameter.

[0045] (4) Generate proof ; It represents the final zero-knowledge proof and also refers to identity identification.

[0046] After the first electronic control unit uses zero-knowledge proof to generate an identity identifier, it generates an identity authentication request based on the identity identifier and sends the identity authentication request to the second electronic control unit. The second electronic control unit then forwards the identity authentication request to the blockchain verification node so that the blockchain verification node authenticates the identity of the first electronic control unit.

[0047] The blockchain verification node parses the identity authentication request, obtains the identity identifier, and then uses the verification equation to perform identity authentication.

[0048] Specifically, taking the Schnorr proof algorithm as an example, the process of blockchain verification node authentication is as follows: According to the formula · c Perform identity authentication, where ≟ indicates that the equality needs to be verified. Represents the generator, which is a public parameter. Indicates the response parameters, represents the public key of the first electronic control unit, Indicated by go through The value obtained by the power operation is used to generate the random challenge parameter in the proof process. Represents the random challenge parameter.

[0049] if equal · c , then the equation holds, the proof is valid, and the authentication is successful. Otherwise, the authentication fails.

[0050] In step S102, the first electronic control unit receives a session connection request sent by the second electronic control unit; the session connection request is generated after the second electronic control unit receives an authentication pass identifier sent by the blockchain verification node.

[0051] In step S103 , the first electronic control unit establishes a secure session with the second electronic control unit according to the session connection request, and communicates with the second electronic control unit.

[0052] During the specific implementation process, after the identity authentication is passed, the blockchain verification node sends an authentication pass identifier to the second electronic control unit to inform the second electronic control unit that the identity of the first electronic control unit is legal and communication is possible.

[0053] The second electronic control unit sends a session connection request to the first electronic control unit to request to establish a session connection with the first electronic control unit. The session connection request includes session parameters such as a random number and a supported encryption algorithm.

[0054] After receiving the session connection request, the first electronic control unit returns a confirmation and its own parameters (such as a random number, a selected encryption algorithm, etc.) to the second electronic control unit to complete the key negotiation.

[0055] The first electronic control unit and the second electronic control unit generate a shared session key based on the exchanged parameters for subsequent encrypted communication.

[0056] In the embodiment of the present application, since zero-knowledge proof allows the prover to prove his or her legitimacy to the verifier without revealing his or her own identity, the first electronic control unit sends an identity authentication request containing an identity identifier generated using zero-knowledge proof to the second electronic control unit, allowing the first electronic control unit to perform authentication without revealing its own identity, thereby improving the security of identity authentication. In addition, considering that traditional authentication methods have the risk of single point failure caused by centralized dependence, the second electronic control unit sends the identity authentication request to the blockchain verification node for authentication, so as to achieve decentralized identity authentication through the distributed characteristics of the blockchain, further improving the security of identity authentication, and thus improving communication security.

[0057] In some embodiments, the blockchain verification node authenticates the identity of the first electronic control unit, including: the blockchain verification node obtains the authentication durations of a preset number of recent historical identity authentication requests; the blockchain verification node calculates a delay variance based on the multiple authentication durations; the blockchain verification node calculates a timeout period based on the authentication duration and delay variance of the most recent historical identity authentication request; if the authentication duration of the blockchain verification node authenticating the identity of the first electronic control unit is not greater than the timeout period, the blockchain verification node sends an authentication pass flag to the second electronic control unit. If the authentication duration of the blockchain verification node authenticating the identity of the first electronic control unit is greater than the timeout period, the blockchain verification node sends an alarm to the second electronic control unit.

[0058] During the process of the blockchain verification node authenticating the identity of the first electronic control unit, a timeout is set to measure whether the identity authentication process is within a reasonable time, thereby avoiding the situation of waiting indefinitely for the identity authentication result.

[0059] The structure of a blockchain verification node is as follows: { "block_hash": "0x...", "prev_hash": "0x...", "nonce": 12345, "timestamp": 1629876543, "transactions": [ { "ecu_id": "0x1234", "proof": "0xabc...", "status": "valid" } ] } Where block_hash represents the hash value of the blockchain verification node, which is obtained by hashing all the data in the blockchain verification node. The hash value is used to uniquely identify the blockchain verification node and ensure the integrity and immutability of the blockchain verification node data.

[0060] prev_hash represents the hash value of the previous blockchain verification node. By including the hash value of the previous blockchain verification node in the current blockchain verification node, a chain structure of the blockchain is formed. This structure ensures that any modification of the data of the previous blockchain verification node will cause the hash value of all subsequent blockchain verification nodes to change, thus ensuring the immutability of the blockchain.

[0061] A nonce represents a random number. During the blockchain mining process, blockchain verification nodes continuously try different nonce values to ensure that the hash value of the blockchain verification node meets certain conditions (such as being less than a certain threshold). The role of the nonce is to ensure the security and fairness of the blockchain.

[0062] Timestamp represents a timestamp, which records the creation time of the blockchain verification node. Timestamp can be used to verify the order of blockchain verification nodes and ensure the consistency of the blockchain.

[0063] Transactions represent a list of transactions, including all authenticated transactions recorded by blockchain verification nodes. Each transaction contains an ecu_id (the identity of the second electronic control unit), a proof (zero-knowledge proof), and a status (authentication status, such as valid, indicating successful authentication).

[0064] The preset number is a pre-set value, for example, obtaining the authentication durations of the last five historical identity authentication requests, or obtaining the authentication durations of the last ten historical identity authentication requests. Specific values may be set based on actual circumstances.

[0065] In one embodiment, according to the formula Calculate the timeout period, where Indicates the timeout period. Indicates the authentication duration of the most recent historical identity authentication request, reflecting the latency of the blockchain verification node's network during the most recent historical identity authentication. Delay variance is used to measure the fluctuation of network delay. and They represent preset weight coefficients, which are used to reflect the impact of the authentication duration and delay variance of the most recent historical identity authentication on the timeout period. The specific values can be adaptively set according to historical verification conditions.

[0066] For example, the authentication durations of the last five historical identity authentication requests are obtained, where the authentication durations are [10ms, 15ms, 12ms, 18ms, 20ms], and the authentication duration of the most recent historical identity authentication request is 20ms. , .

[0067] The process of calculating the delay variance based on multiple authentication durations is as follows: (1) Calculate the average value: (10 + 15 + 12 + 18 + 20) / 5 = 15ms; (2) Calculate the square of the difference between each value and the mean: (10-15) 2 =25, (15-15) 2 =0, (12-15) 2 =9, (18-15) 2 =9, (20-15) 2 =25; (3) Calculate the delay variance: (25+0+9+9+25) / 5=13.6ms 2 .

[0068] The authentication time of the most recent historical identity authentication request is 20ms, and the delay variance is 13.6ms. 2 and , Substituting this into the above formula, we obtain a timeout of 36.8ms.

[0069] If the blockchain verification node completes the identity authentication within 36.8ms, it sends an authentication pass mark to the second electronic control unit; otherwise, it sends an alarm prompt to the second electronic control unit.

[0070] The above formula dynamically adjusts the timeout based on the real-time status of the blockchain verification node's network, preventing authentication failures caused by network delays or fluctuations. For example, in times of network congestion, authentication duration and delay variance increase, and the timeout calculated by the formula will also increase accordingly. This gives the blockchain verification node more time to complete the authentication operation, improving authentication stability and reliability.

[0071] Therefore, the embodiment of the present application calculates the timeout period based on the authentication duration of the most recent preset number of historical identity authentication requests, so that the blockchain verification node can dynamically adjust the timeout period according to the real-time status of the network to which the blockchain belongs, thereby reducing authentication failures caused by network delays or fluctuations and improving the stability and reliability of authentication. In addition, if the authentication is complete within the timeout period, an authentication pass mark is sent to the second electronic control unit to inform the second electronic control unit that the identity of the first electronic control unit is legal and that secure communication can be carried out, thereby improving the reliability of communication. By sending an alarm prompt to inform the second electronic control unit that the authentication failed, it is indicated that the identity of the first electronic control unit may be illegal, thereby preventing potential malicious attacks and improving the reliability of communication.

[0072] In some embodiments, when the first electronic control unit is communicating with the second electronic control unit, the method further includes: the first electronic control unit obtains global parameters and the most recent historical delay threshold; the global parameters include the number of historical attacks on the vehicle system to which the first electronic control unit belongs, the network load parameters of the network to which the first electronic control unit and the second electronic control unit belong, and the health status parameters of the first electronic control unit and the second electronic control unit; the first electronic control unit calculates a new delay threshold based on the global parameters; if the delay change rate between the new delay threshold and the historical delay threshold is greater than the preset change rate threshold, the historical delay threshold is updated according to the new delay threshold; the new delay threshold is used to determine whether the communication duration between the first electronic control unit and the second electronic control unit is normal.

[0073] On the basis of the legality of the identity of the first electronic control unit, it is further judged whether the communication duration between the first electronic control unit and the second electronic control unit is normal, so as to evaluate the entire communication process between the first electronic control unit and the second electronic control unit, thereby improving the continuity and robustness of the communication process.

[0074] During a specific implementation, the first electronic control unit obtains the global parameters and the most recent historical delay threshold.

[0075] Global parameters refer to a set of indicators used by the first and second electronic control units in a vehicle to comprehensively evaluate communication security and reliability during the communication authentication process.

[0076] The global parameters include the number of historical attacks on the vehicle system to which the first electronic control unit belongs, network load parameters of the network to which the first electronic control unit and the second electronic control unit belong, and health status parameters of the first electronic control unit and the second electronic control unit.

[0077] The number of historical attacks refers to the number of times the vehicle system has been attacked in the past period of time, which is obtained by querying the security log file of the vehicle system.

[0078] The network load parameter refers to the amount of communication traffic in the current network and reflects the network's busyness. For example, when the network load exceeds 80%, the network may be congested, affecting the real-time performance and reliability of communication.

[0079] The health status parameter is used to measure whether the first or second electronic control unit is faulty and is represented by 0 or 1, where 0 indicates no fault and 1 indicates a fault. This is determined by detecting the fault code of the first or second electronic control unit. It should be noted that the health status parameter is 0 only when both the first and second electronic control units are fault-free; otherwise, the health status parameter is 1.

[0080] It should be noted that the global parameters may also include the communication frequency between the first electronic control unit and the second electronic control unit and the time when the communication occurs.

[0081] The historical delay threshold refers to a threshold that is most recently used to determine whether the communication duration between the first electronic control unit and the second electronic control unit is normal.

[0082] The new delay threshold is a threshold used to determine whether the current communication duration between the first electronic control unit and the second electronic control unit is normal.

[0083] The communication duration is the length of time from when the first electronic control unit sends the request to be processed to when the response request returned by the second electronic control unit is received.

[0084] The first electronic control unit calculates a new delay threshold according to the global parameters, which can be calculated according to the formula Calculate the new delay threshold; where, Indicates the new delay threshold; Indicates the initial delay threshold, which is the default communication duration set when the vehicle system is initialized; Represents the adjustment coefficient, which is used to control the amplitude of the delay threshold adjustment; Indicates the global parameters, Indicates the The weight coefficient of a global parameter reflects the importance of a global parameter in the delay threshold calculation. Different global parameters are assigned different weights according to their influence on the delay threshold. Indicates the number of global parameters.

[0085] Exemplary initial delay threshold =100ms, , global parameters include the number of historical attacks ( ), network load parameters ( ) and health status parameters ( ), where the number of historical attacks , , network load parameters , , health status parameters , , calculate the new delay threshold 110.2ms.

[0086] After calculating the new latency threshold using the above formula, calculate the latency change rate of the new latency threshold compared to the historical latency threshold. Specifically, latency change rate = (new latency threshold - historical latency threshold) / historical latency threshold * 100%.

[0087] The preset change rate threshold is a pre-set value. For example, the preset change rate threshold is 10%.

[0088] If the new delay threshold is 110.2ms and the historical delay threshold is 100ms, then the delay change rate = (110.2-100) / 100*100% = 10.2% > 10%. In this case, the new delay threshold is used to update the historical delay threshold. That is, the historical delay of 100ms is changed to 110.2ms to measure the communication duration of subsequent requests.

[0089] It should be noted that if the delay change rate between the new delay threshold and the historical delay threshold is not greater than the preset change rate threshold, the historical delay threshold is used as the new delay threshold.

[0090] In the embodiment of the present application, during communication between a first electronic control unit and a second electronic control unit, a new delay threshold is calculated in real time by acquiring global parameters. Furthermore, when the rate of change of the new delay threshold is greater than that of the previous historical delay threshold, the historical delay threshold is updated. This allows the threshold to be dynamically adjusted based on the network environment and the state of the electronic control units, improving the adaptability of the delay threshold. Furthermore, the delay threshold is used to determine whether the communication duration between the first and second electronic control units is normal. Because the delay threshold changes dynamically, misjudgments of communication anomalies are reduced, improving the continuity and robustness of the communication process.

[0091] In some embodiments, after the first electronic control unit updates the historical delay threshold according to the new delay threshold, the method further includes: the first electronic control unit sends a pending request to the second electronic control unit; the pending request includes a first timestamp; if the time from the first timestamp to the receipt of the response request sent by the second electronic control unit is greater than the new delay threshold, an abnormal information is issued.

[0092] In a specific implementation process, the pending request refers to a request that needs to be processed by the second electronic control unit.

[0093] If the communication time for processing the request to be processed is longer than the new delay threshold, the first electronic control unit issues an abnormality message to prompt the user.

[0094] If the communication time for processing the pending request is not greater than the new delay threshold, normal communication is performed.

[0095] In the embodiment of the present application, when the communication duration between the first electronic control unit and the second electronic control unit is greater than the new delay threshold, an abnormality message is issued, thereby improving the security of the communication process.

[0096] Figure 2 A flow chart of another communication method between vehicle-mounted electronic control units provided in an embodiment of the present application is shown as follows: Figure 2 As shown, the method includes: a first electronic control unit sends an identity authentication request to a second electronic control unit; the identity authentication request includes an identity identifier, and the identity identifier is generated by the first electronic control unit using zero-knowledge proof; the second electronic control unit sends an identity authentication request to a blockchain verification node, so that the blockchain verification node authenticates the identity of the first electronic control unit based on the identity authentication request; the blockchain verification node sends a verification result to the second electronic control unit; if the verification result indicates that the verification is passed, the second electronic control unit sends a session connection request to the first electronic control unit; the first electronic control unit establishes a secure session with the second electronic control unit according to the session connection request, and communicates with the second electronic control unit.

[0097] In the specific implementation process, the vehicle is equipped with multiple electronic control units, including the first electronic control unit (ECU1) responsible for the power system and the second electronic control unit (ECU2) responsible for the automated driving assistance system. Each of the first and second electronic control units is assigned a unique private key and corresponding public key. These key pairs are stored in the hardware security modules of the first and second electronic control units, respectively. Simultaneously, the vehicle manufacturer deploys blockchain verification nodes at the base station, forming a distributed authentication network.

[0098] After the vehicle starts, the first electronic control unit needs to communicate with the second electronic control unit to coordinate power output and automated driving assistance functions. At this point, the first electronic control unit invokes the zero-knowledge proof generation module, using its own private key, public key, and hash function H to generate an identity using the SchnorrProve algorithm. Based on the identity, it generates an authentication request and sends it to the second electronic control unit. The process for generating the identity is described in the previous embodiment and will not be repeated here.

[0099] After receiving the authentication request, the second electronic control unit forwards it to the blockchain verification node for authentication. During the authentication process, the blockchain verification node parses the authentication request, obtains the identity identifier, and verifies the identity identifier. The authentication process is described in the previous embodiment and will not be further described here.

[0100] The verification results include a pass mark and an alarm prompt.

[0101] During the identity authentication process, the blockchain verification node uses the formula A timeout is calculated. If the blockchain verification node completes identity verification within the timeout, it returns an authentication success indicator to the second electronic control unit. After receiving the authentication success result, the second electronic control unit establishes a secure session with the first electronic control unit.

[0102] If the blockchain verification node fails to complete identity authentication within the timeout period, an alarm is sent to the second electronic control unit.

[0103] During the communication between the first electronic control unit and the second electronic control unit, the first electronic control unit collects global parameters in real time (the number of historical attacks on the vehicle system to which the first electronic control unit belongs, the network load parameters of the network to which the first electronic control unit and the second electronic control unit belong, and the health status parameters of the first electronic control unit and the second electronic control unit). Calculate the new delay threshold and calculate the delay change rate between the new delay threshold and the most recent historical delay threshold. If the delay change rate is greater than the preset delay threshold, update the historical delay threshold according to the new delay threshold. Otherwise, use the historical delay threshold as the new delay threshold.

[0104] In the embodiment of the present application, since zero-knowledge proof allows the prover to prove his or her legitimacy to the verifier without revealing his or her own identity, the first electronic control unit sends an identity authentication request containing an identity identifier generated using zero-knowledge proof to the second electronic control unit, allowing the first electronic control unit to perform authentication without revealing its own identity, thereby improving the security of identity authentication. In addition, considering that traditional authentication methods have the risk of single point failure caused by centralized dependence, the second electronic control unit sends the identity authentication request to the blockchain verification node for authentication, so as to achieve decentralized identity authentication through the distributed characteristics of the blockchain, further improving the security of identity authentication, and thus improving communication security.

[0105] Figure 3 A schematic diagram of a communication device between vehicle-mounted electronic control units provided in an embodiment of the present application is shown in FIG. Figure 3 As shown, the device includes: a sending module 301, a receiving module 302 and a communication module 303; wherein, The sending module 301 is used to send an identity authentication request to the second electronic control unit, so that the second electronic control unit sends the identity authentication request to the blockchain verification node; the identity authentication request is used to instruct the blockchain verification node to authenticate the identity of the first electronic control unit; the identity authentication request includes an identity identifier, which is generated by the first electronic control unit using zero-knowledge proof; the receiving module 302 is used to receive a session connection request sent by the second electronic control unit; the session connection request is generated after the second electronic control unit receives the authentication pass identifier sent by the blockchain verification node; the communication module 303 is used to establish a secure session with the second electronic control unit according to the session connection request, and communicate with the second electronic control unit.

[0106] Based on the above embodiment, the device also includes an identity authentication module, which is used for the blockchain verification node to obtain the authentication duration of the most recent preset number of historical identity authentication requests; the blockchain verification node calculates the delay variance based on multiple authentication durations; the blockchain verification node calculates the timeout period based on the authentication duration and delay variance of the most recent historical identity authentication request; if the authentication duration of the blockchain verification node for authenticating the identity of the first electronic control unit is not greater than the timeout period, the blockchain verification node sends an authentication pass identifier to the second electronic control unit.

[0107] Based on the above embodiment, the identity authentication module is specifically used to send an alarm prompt to the second electronic control unit if the authentication time of the blockchain verification node for authenticating the identity of the first electronic control unit is greater than the timeout time.

[0108] Based on the above embodiment, the device also includes a threshold update module for obtaining global parameters and the most recent historical delay threshold; the global parameters include the number of historical attacks on the vehicle system to which the first electronic control unit belongs, the network load parameters of the network to which the first electronic control unit and the second electronic control unit belong, and the health status parameters of the first electronic control unit and the second electronic control unit; a new delay threshold is calculated based on the global parameters; if the delay change rate between the new delay threshold and the historical delay threshold is greater than the preset change rate threshold, the historical delay threshold is updated according to the new delay threshold; the new delay threshold is used to determine whether the communication duration between the first electronic control unit and the second electronic control unit is normal.

[0109] Based on the above embodiment, the threshold updating module is specifically used to: Calculate the new delay threshold; where, Indicates the new latency threshold, represents the initial delay threshold, represents the adjustment coefficient, Indicates the global parameters, Indicates the The weight coefficients of the global parameters, Indicates the number of global parameters.

[0110] Based on the above embodiment, the device also includes an abnormal reminder module for sending a pending request to the second electronic control unit; the pending request includes a first timestamp; if the time from the first timestamp to the receipt of the response request sent by the second electronic control unit is greater than the new delay threshold, an abnormal message is issued.

[0111] It should be understood that this device corresponds to the aforementioned embodiment of the method for communication between vehicle-mounted electronic control units and is capable of executing each of the steps involved in the aforementioned method embodiment. The specific functions of this device can be found in the description above; to avoid repetition, a detailed description is omitted here. The device includes at least one software functional module that can be stored in a memory in the form of software or firmware or embedded in the device's operating system (OS).

[0112] Figure 4 A schematic diagram of the structure of an electronic control unit provided in an embodiment of the present application is shown in FIG. Figure 4 As shown, the electronic control unit includes a processor 401 (processor), a memory 402 (memory), and a bus 403. The processor 401 and the memory 402 communicate with each other via the bus 403. The processor 401 is used to call program instructions in the memory 402 to execute the methods provided by the above-mentioned method embodiments.

[0113] Processor 401 can be an integrated circuit chip with signal processing capabilities. The processor 401 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.

[0114] The memory 402 can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0115] An embodiment of the present application provides a computer program product, including: computer program instructions, which, when executed by a processor, execute the methods provided by the above-mentioned method embodiments.

[0116] An embodiment of the present application provides a computer-readable storage medium, including: computer program instructions stored on the computer-readable storage medium, and the computer program instructions execute the methods provided by the above-mentioned method embodiments when executed by a processor.

[0117] An embodiment of the present application provides a vehicle, which includes a first electronic control unit and a second electronic control unit. The first electronic control unit and the second electronic control unit are communicatively connected, and the first electronic control unit is used to execute the methods provided by the above-mentioned method embodiments.

[0118] Computer-readable storage media can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0119] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0120] In addition, the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0121] Furthermore, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0122] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, various modifications and variations of the present application are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A communication method between vehicle-mounted electronic control units, characterized in that: The method is applied to a first electronic control unit; the method comprises: Sending an identity authentication request to a second electronic control unit, so that the second electronic control unit sends the identity authentication request to a blockchain verification node; the identity authentication request is used to instruct the blockchain verification node to authenticate the identity of the first electronic control unit; the identity authentication request includes an identity identifier, and the identity identifier is generated by the first electronic control unit using zero-knowledge proof; Receiving a session connection request sent by the second electronic control unit; the session connection request is generated by the second electronic control unit after receiving the authentication pass identifier sent by the blockchain verification node; A secure session is established with the second electronic control unit according to the session connection request, and communication is performed with the second electronic control unit.

2. The method according to claim 1, characterized in that The blockchain verification node authenticates the identity of the first electronic control unit, including: The blockchain verification node obtains the authentication duration of a recent preset number of historical identity authentication requests; The blockchain verification node calculates the delay variance based on the multiple authentication durations; The blockchain verification node calculates a timeout period based on the authentication duration of the most recent historical identity authentication request and the delay variance; If the authentication time length of the blockchain verification node for authenticating the identity of the first electronic control unit is not greater than the timeout period, the blockchain verification node sends the authentication pass identifier to the second electronic control unit.

3. The method according to claim 2, characterized in that The method further comprises: If the blockchain verification node takes longer than the timeout period to authenticate the identity of the first electronic control unit, the blockchain verification node sends an alarm to the second electronic control unit.

4. The method according to any one of claims 1 to 3, characterized in that: During the communication with the second electronic control unit, the method further includes: Obtaining global parameters and a most recent historical delay threshold; the global parameters include the number of historical attacks on the vehicle system to which the first electronic control unit belongs, network load parameters of the network to which the first electronic control unit and the second electronic control unit belong, and health status parameters of the first electronic control unit and the second electronic control unit; Calculating a new delay threshold according to the global parameter; If the delay change rate between the new delay threshold and the historical delay threshold is greater than the preset change rate threshold, the historical delay threshold is updated according to the new delay threshold; the new delay threshold is used to determine whether the communication duration between the first electronic control unit and the second electronic control unit is normal.

5. The method according to claim 4, characterized in that The calculating a new delay threshold according to the global parameter includes: According to the formula Calculate and obtain the new delay threshold; wherein, represents the new delay threshold, represents the initial delay threshold, represents the adjustment coefficient, Indicates the The global parameters, Indicates the The weight coefficient of the global parameter, Indicates the number of global parameters.

6. The method according to claim 4, characterized in that After updating the historical delay threshold according to the new delay threshold, the method further includes: Sending the pending request to the second electronic control unit; the pending request including a first timestamp; If the time from the first timestamp to the receipt of the response request sent by the second electronic control unit is longer than the new delay threshold, an abnormality message is issued.

7. A communication method between vehicle-mounted electronic control units, characterized in that: The method comprises: The first electronic control unit sends an identity authentication request to the second electronic control unit; the identity authentication request includes an identity identifier, and the identity identifier is generated by the first electronic control unit using zero-knowledge proof; The second electronic control unit sends the identity authentication request to the blockchain verification node, so that the blockchain verification node authenticates the identity of the first electronic control unit based on the identity authentication request; the blockchain verification node sends a verification result to the second electronic control unit; If the verification result indicates that the verification is successful, the second electronic control unit sends a session connection request to the first electronic control unit; The first electronic control unit establishes a secure session with the second electronic control unit according to the session connection request, and communicates with the second electronic control unit.

8. A communication device between vehicle-mounted electronic control units, characterized in that: The device comprises: a sending module, configured to send an identity authentication request to a second electronic control unit, so that the second electronic control unit sends the identity authentication request to a blockchain verification node; the identity authentication request is used to instruct the blockchain verification node to authenticate the identity of the first electronic control unit; the identity authentication request includes an identity identifier, and the identity identifier is generated by the first electronic control unit using zero-knowledge proof; A receiving module, configured to receive a session connection request sent by the second electronic control unit; the session connection request is generated by the second electronic control unit after receiving an authentication pass identifier sent by the blockchain verification node; A communication module is used to establish a secure session with the second electronic control unit according to the session connection request and communicate with the second electronic control unit.

9. An electronic control unit, characterized in that: include: A processor and a memory, wherein the memory stores machine-readable instructions executable by the processor, and when the machine-readable instructions are executed by the processor, the method according to any one of claims 1 to 7 is performed.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, the method according to any one of claims 1 to 7 is executed.

11. A computer program product, characterized in that include: Computer program instructions, which, when executed by a processor, perform the method according to any one of claims 1 to 7.

12. A vehicle, characterized in that: The vehicle includes a first electronic control unit and a second electronic control unit, wherein the first electronic control unit and the second electronic control unit are communicatively connected; the first electronic control unit is configured to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Keyword automatically learning and updating method in rubbish short message

    CN101184259A

  • Vehicle-mounted network message authentication method and system based on block chain and ECC

    CN113300836A

  • Distributed digital identity verification system, method and related device

    CN115632794A

  • Vehicle-mounted CAN network security communication method, device, equipment and medium

    CN117595988A

  • Authentication interaction system and method based on block chain and digital identity

    CN118891619A