Vehicle information display method and device, vehicle and storage medium

By performing double verification in the vehicle by combining actual operating information and environmental information, the problem of SecOC verification logic being tampered with by attackers is solved, and accurate display and timely updating of vehicle information are achieved.

CN120639334APending Publication Date: 2025-09-12GREAT WALL MOTOR CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510619108.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In the existing technology, after an attacker masters the SecOC verification logic, they can forge CAN messages, causing vehicle information to be displayed incorrectly, affecting the user experience, and failing to update vehicle information in a timely manner when verification fails.

Method used

The CAN message is double-checked based on the actual vehicle operation information and environmental information to ensure the accuracy of vehicle information through double verification, including SecOC verification and secondary verification based on the vehicle information inference model.

Benefits of technology

The accuracy of CAN message verification and vehicle information display has been improved, avoiding erroneous displays caused by message tampering and ensuring timely information updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639334A_ABST
    Figure CN120639334A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle information display method and device, a vehicle and a storage medium, and belongs to the technical field of vehicles. Comprising the steps that under the condition that a target CAN message is received, safety verification is conducted on the target CAN message, a target verification result is obtained, and the target CAN message comprises first vehicle information to be displayed; under the condition that the target verification result indicates that the safety verification is successful, performing secondary verification on the target CAN message based on at least one of the current operation information and the environment information of the target vehicle; and displaying the first vehicle information under the condition that the secondary verification is passed. According to the invention, secondary verification is carried out on the CAN message by combining at least one of the actual operation information and the environment information of the vehicle. Therefore, the authenticity of the CAN message is judged through double verification and the actual vehicle information, so that the verification accuracy of the CAN message can be improved, and the display accuracy of the vehicle information is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle technology, and in particular to a vehicle information display method, device, vehicle, and storage medium. Background Art

[0002] In modern automotive communication networks, the Controller Area Network (CAN) has become the mainstream standard for data exchange between various vehicle controllers. Furthermore, ensuring the secure transmission of data between controllers is crucial. Currently, after receiving a CAN message, a controller can perform a Security on CAN (SecOC) check on the message. Passing the SecOC check confirms that the CAN message has not been tampered with. For example, a head unit (HUT) can display the vehicle information in the data segment of a received CAN message if the SecOC check succeeds.

[0003] However, if an attacker masters the SecOC verification logic, they can forge CAN messages. In this case, after the HUT receives a CAN message, even if it performs SecOC verification, the verification may succeed. This will cause the HUT to display based on the tampered message, resulting in incorrect vehicle information, which is not conducive to the user experience. Summary of the Invention

[0004] This application provides a vehicle information display method, device, vehicle, and storage medium. These methods can perform secondary verification of CAN messages based on at least one of the vehicle's actual operating information and environmental information. If the secondary verification also passes, the vehicle information contained in the CAN message is then displayed. This method verifies the authenticity of CAN messages through dual verification and actual vehicle information, thereby improving the accuracy of CAN message verification and, in turn, the accuracy of vehicle information display. The technical solution includes the following.

[0005] In a first aspect, a vehicle information display method is provided, the method comprising:

[0006] When a target CAN message is received, a security check is performed on the target CAN message to obtain a target check result;

[0007] If the target verification result indicates that the safety verification is successful, performing a secondary verification on the target CAN message based on at least one of the current operating information and environmental information of the target vehicle;

[0008] If the secondary verification passes, the first vehicle information is displayed.

[0009] In the present application, upon receiving a target CAN message, a security check is first performed on the target CAN message to obtain a target check result. If the target check result indicates a successful security check, the target CAN message is checked again based on at least one of the current operating information and environmental information of the target vehicle. If the secondary check passes, the first vehicle information is displayed, that is, the vehicle information within the data segment of the target CAN message can be displayed. Since the vehicle's operating information and environmental information can reflect the actual vehicle information corresponding to the target function indicated by the target CAN message, the target CAN message can be accurately checked using the current operating information and environmental information of the target vehicle. The present application performs a secondary check on the target CAN message by combining at least one of the current operating information and environmental information of the target vehicle. If the secondary check also passes, the vehicle information contained in the target CAN message is displayed. In this way, the authenticity of the target CAN message is determined by dual verification and actual vehicle information, thereby improving the accuracy of the target CAN message verification and, in turn, the accuracy of the vehicle information display.

[0010] Optionally, the performing secondary verification on the target CAN message based on at least one of current operating information and environmental information of the target vehicle includes:

[0011] determining second vehicle information based on at least one of the current operation information and the environmental information, where the second vehicle information is actual vehicle information corresponding to the target function indicated by the target CAN message;

[0012] If the second vehicle information is consistent with the first vehicle information, determining that the secondary verification is passed;

[0013] When the second vehicle information is inconsistent with the first vehicle information, it is determined that the secondary verification has failed.

[0014] Optionally, the determining the second vehicle information based on at least one of the current operating information and the environmental information includes:

[0015] inputting at least one of the current operation information and the environmental information into a vehicle information inference model, processing at least one of the current operation information and the environmental information using the vehicle information inference model to obtain a plurality of reference vehicle information and probabilities corresponding to the plurality of reference vehicle information;

[0016] The reference vehicle information with the highest probability among the plurality of reference vehicle information is determined as the second vehicle information by using the vehicle information estimation model, and the second vehicle information is output.

[0017] In the above method, the second vehicle information is determined by combining the current operating information of the target vehicle and at least one of the environmental information through the vehicle information prediction model, making the determination process of the second vehicle information more intelligent, and the second vehicle information can be determined more quickly through the vehicle information inference model, thereby improving the efficiency of determining the second vehicle information.

[0018] Optionally, the method further includes:

[0019] If the target verification result indicates a safety verification failure, determining second vehicle information based on at least one of the current operation information and the environmental information, where the second vehicle information is actual vehicle information corresponding to the target function indicated by the target CAN message;

[0020] The second vehicle information is displayed.

[0021] In the above method, when the target verification result indicates that the safety verification has failed, the second vehicle information is determined based on the current operating information and at least one of the environmental information, and the second vehicle information is displayed. Even if the target CAN message is tampered with, relatively accurate vehicle information can be displayed, avoiding the phenomenon of untimely vehicle information update caused by discarding the CAN message after the verification fails, thereby providing users with more accurate vehicle information and improving user experience.

[0022] Optionally, the security check includes a SecOC check, and when a target CAN message is received, performing a security check on the target CAN message to obtain a target check result includes:

[0023] Upon receiving the target CAN message, obtaining the current load rate;

[0024] When the current load rate is greater than or equal to a preset load rate threshold, if the target CAN message is a CAN message that undergoes SecOC verification, SecOC verification is performed on the target CAN message to obtain the target verification result.

[0025] In the above approach, when a target CAN message is received and it is a CAN message that undergoes SecOC verification, it indicates that the function corresponding to the target CAN message is more important. When the current load rate is greater than or equal to the preset load rate threshold, the target CAN message is directly subjected to SecOC verification, allowing the target CAN message to be processed first. This prevents the target CAN message from being delayed, and the function corresponding to the target CAN message is responded to promptly, thereby improving the operational performance of the HUT.

[0026] Optionally, the method further includes:

[0027] Obtaining a function type of a target function indicated by the target CAN message;

[0028] Based on the function type, at least one of current operation information and environmental information of the target vehicle is obtained.

[0029] In the above method, by obtaining the functional type of the target function and based on the functional type of the target function, obtaining the current operating information of the target vehicle and at least one of the environmental information, the content that can accurately reflect the actual vehicle information corresponding to the target function can be obtained, so that more accurate second vehicle information can be determined subsequently.

[0030] Optionally, the function type includes an alarm indicator light display, a gear position display, and a vehicle speed display, and obtaining at least one of current operating information and environmental information of the target vehicle based on the function type includes:

[0031] When the function type is warning indicator light display or vehicle speed display, obtaining current operating information of the target vehicle;

[0032] When the function type is gear position display, the current operation information and the environmental information are obtained.

[0033] In a second aspect, a vehicle information display device is provided, the device comprising:

[0034] a first verification module, configured to, upon receiving a target CAN message, perform a security verification on the target CAN message to obtain a target verification result, wherein the target CAN message includes first vehicle information to be displayed;

[0035] A second verification module is configured to perform a secondary verification on the target CAN message based on at least one of current operating information and environmental information of the target vehicle when the target verification result indicates that the safety verification is successful;

[0036] The first display module is configured to display the first vehicle information if the secondary verification passes.

[0037] Optionally, the second verification module is used to:

[0038] determining second vehicle information based on at least one of the current operation information and the environmental information, where the second vehicle information is actual vehicle information corresponding to the target function indicated by the target CAN message;

[0039] If the second vehicle information is consistent with the first vehicle information, determining that the secondary verification is passed;

[0040] When the second vehicle information is inconsistent with the first vehicle information, it is determined that the secondary verification has failed.

[0041] Optionally, the second verification module is used to:

[0042] inputting at least one of the current operation information and the environmental information into a vehicle information inference model, processing at least one of the current operation information and the environmental information using the vehicle information inference model to obtain a plurality of reference vehicle information and probabilities corresponding to the plurality of reference vehicle information;

[0043] The reference vehicle information with the highest probability among the plurality of reference vehicle information is determined as the second vehicle information by using the vehicle information estimation model, and the second vehicle information is output.

[0044] Optionally, the device further comprises:

[0045] a determination module, configured to determine, when the target verification result indicates a safety verification failure, second vehicle information based on at least one of the current operation information and the environmental information, the second vehicle information being actual vehicle information corresponding to the target function indicated by the target CAN message;

[0046] The second display module is used to display the second vehicle information.

[0047] Optionally, the security verification includes SecOC verification, and the first verification module is configured to:

[0048] Upon receiving the target CAN message, obtaining the current load rate;

[0049] When the current load rate is greater than or equal to a preset load rate threshold, if the target CAN message is a CAN message that undergoes SecOC verification, SecOC verification is performed on the target CAN message to obtain the target verification result.

[0050] Optionally, the device further comprises:

[0051] A first acquisition module is used to obtain a function type of a target function indicated by the target CAN message;

[0052] The second acquisition module is used to acquire at least one of the current operation information and environmental information of the target vehicle based on the function type.

[0053] Optionally, the function types include warning indicator light display, gear position display, and vehicle speed display, and the second acquisition module is used to:

[0054] When the function type is warning indicator light display or vehicle speed display, obtaining current operating information of the target vehicle;

[0055] When the function type is gear position display, the current operation information and the environmental information are obtained.

[0056] In a third aspect, a vehicle is provided, comprising:

[0057] a memory for storing executable program code;

[0058] A processor is used to call and run the executable program code from the memory, so that the vehicle executes the above-mentioned information display method.

[0059] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned information display method is implemented.

[0060] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the steps of the above-mentioned information display method.

[0061] It can be understood that the beneficial effects of the second, third, fourth and fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0063] Figure 1 This is a schematic diagram of a scenario of a vehicle information display method provided by an embodiment of the present application;

[0064] Figure 2 This is a flow chart of a vehicle information display method provided by an embodiment of the present application;

[0065] Figure 3 is a flow chart of another vehicle information display method provided by an embodiment of the present application;

[0066] Figure 4 This is a structural diagram of a vehicle information display device provided in an embodiment of the present application;

[0067] Figure 5 It is a structural schematic diagram of a vehicle provided in an embodiment of the present application. DETAILED DESCRIPTION

[0068] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0069] It should be understood that the “multiple” mentioned in this application refers to two or more. In the description of this application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in order to facilitate the clear description of the technical solution of this application, words such as “first” and “second” are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art can understand that words such as “first” and “second” do not limit the quantity and execution order, and words such as “first” and “second” do not necessarily limit them to be different.

[0070] First, the terms involved in the embodiments of this application are explained.

[0071] 1. CAN message: A CAN message is an information unit used to transmit data on a controller area network. In other words, controllers communicate with each other by transmitting CAN messages. A CAN message consists of a start-of-frame, arbitration segment, control segment, data segment, cyclic redundancy check (CRC) segment, response segment, and end-of-frame segment. The data segment contains the actual vehicle information to be transmitted (such as the current gear position and speed).

[0072] 2. Secure Onboard Communication (SecOC) module

[0073] The SecOC module is a key security module within the AUTOSAR (Automotive Open System Architecture) standard, ensuring the security of in-vehicle network communications. The SecOC module is specifically designed to perform SecOC verification on received CAN messages. It uses message authentication codes or digital signatures to verify the identities of both communicating parties, preventing unauthorized access and data forgery. It also utilizes freshness mechanisms such as timestamps and serial numbers to ensure data timeliness and defend against replay attacks.

[0074] 3.SecOC verification: SecOC verification is a mechanism used in automotive electronic systems to ensure communication security and integrity, designed to prevent communications between controllers from being tampered with, eavesdropped on, or forged.

[0075] SecOC verification involves the generation of a message authentication code (MAC) and a freshness value (FV).

[0076] Regarding the freshness value: it is a dynamically changing value, usually generated by a timestamp or timer, which ensures that each message is unique.

[0077] For the MAC value: the original message to be sent, the freshness value and the sender's key are usually calculated using a specific encryption algorithm.

[0078] When one controller wants to send a message to another, it first generates a freshness value and a message authentication code (MAC). It then appends the freshness value and MAC value to the message content, forming a CAN message, which is then sent to the other controller via the CAN bus. Upon receiving the CAN message, the other controller first recalculates the MAC value using the same key and encryption algorithm. It then compares the received MAC value with its own calculated MAC. If the two match, the verification is considered successful; if they do not, the verification fails.

[0079] When a function is protected by the SecOC mechanism, the CAN message corresponding to the function sent by the controller may include the MAC value and the freshness value in addition to the above parts.

[0080] Before describing the vehicle information display method provided in the embodiment of the present application, the application scenario of the embodiment of the present application is first described.

[0081] For example, Figure 1 This is a scene diagram of a vehicle information display method provided by an embodiment of the present application, see Figure 1 , Figure 1 The vehicle-mounted multimedia system includes a vehicle-mounted multimedia main body 101 and multiple controllers 102.

[0082] The vehicle multimedia host 101 is used to control various functions of the multimedia system. It can control the display of screens such as the instrument screen and the central control screen. For example, it can display the basic status of the vehicle, such as the vehicle speed, gear position, tire pressure, etc. It can also display vehicle faults, such as displaying alarm indicator lights.

[0083] The multiple controllers 102 may be multiple controllers in a vehicle, for example, the multiple controllers 102 may be an engine controller, a transmission controller, a body controller, a tire pressure monitoring controller, a chassis controller, etc.

[0084] The multiple controllers 102 can communicate with the vehicle multimedia host 101 via a CAN network. The multiple controllers 102 can send CAN messages to the vehicle multimedia host 101 so that the vehicle multimedia host can learn the operating status of each controller 102 and display the operating status.

[0085] For example, when the user changes gears, such as from neutral to forward gear, the transmission controller can send the current gear position after the shift to the vehicle multimedia host 102, so that the vehicle multimedia host 102 controls the instrument screen to display the current gear position.

[0086] Specifically, when the transmission controller 101 sends the current gear to the vehicle multimedia host 102, a freshness value is first generated, and then the current gear, the freshness value and the private key of the transmission controller 101 are encrypted through a preset encryption algorithm to obtain a MAC value. After that, this freshness value and this MAC value are attached to the gear signal (current gear) to be sent, and the message is encapsulated to obtain a CAN message. After that, the transmission controller 101 can send the CAN message to the vehicle multimedia host 102.

[0087] After receiving the CAN message, the vehicle multimedia host 102 can perform a SecOC check on the CAN message. If the check passes, the vehicle multimedia host 102 can control the instrument panel to display the current gear position in the data segment of the CAN message, so that the user can clearly see the current gear position of the vehicle on the instrument panel. If the check fails, the vehicle multimedia host 102 will discard the CAN message and will not display the current gear position contained in the CAN message.

[0088] However, the above method has the following problems:

[0089] First, if an attacker masters the SecOC verification logic, they can tamper with the CAN message. In this case, after the SecOC verification of the CAN message is successful, the vehicle multimedia host 102 will display the tampered gear position, causing the vehicle multimedia host 102 to display incorrect vehicle information to the user.

[0090] Second, in the above method, when the verification fails, the CAN message is directly discarded and the current gear position is not displayed. This will cause the vehicle multimedia host to be unable to update the status in a timely manner. For example, when changing gears, the vehicle multimedia host cannot update the current gear position displayed on the instrument screen in a timely manner. For example, the vehicle speed cannot be displayed in real time.

[0091] To this end, an embodiment of the present application provides a vehicle information display method that performs a secondary verification of CAN messages based on at least one of the vehicle's actual operating information and environmental information. If the secondary verification also passes, the vehicle information contained in the CAN message is displayed. This method verifies the authenticity of CAN messages through dual verification and actual vehicle information, thereby improving the accuracy of CAN message verification and, in turn, the accuracy of vehicle information display.

[0092] It should be noted that, generally, each controller of the vehicle may include a SecOC module, and the on-board multimedia host 102 may also include a SecOC module. The SecOC module is specifically used to perform SecOC verification on the received CAN messages, that is, the SecOC module is specifically used to execute the corresponding SecOC verification logic. In the embodiment of the present application, the verification logic of the CAN message is modified, which also involves the modification of the internal logic of the SecOC module.

[0093] In the embodiment of the present application, the health performance monitoring of the SecOC module is also involved.

[0094] As a CAN message processing module, the SecOC module will remain in operation as long as there are CAN messages. Therefore, when the SecOC module works for too long, the processing speed of CAN messages may slow down due to reasons such as computing power and consumption, causing problems in the CAN message processing process.

[0095] In an embodiment of the present application, the message processing speed and operating time of the SecOC module will be detected in real time. When the message processing speed of the SecOC module is less than a preset speed threshold, its own cache can be cleared and the operating time of the SecOC module can be continuously detected. When the operating time of the SecOC module exceeds the preset time, a fault problem can be generated and a fault code can be recorded; and a target reminder message can be output to remind the user that there is a problem with the system performance and to request timely maintenance.

[0096] In this way, by monitoring the message processing speed and operation time of the SecOC module, corresponding processing methods can be executed according to the message processing speed and operation time, thereby ensuring the processing performance of the SecOC module as much as possible.

[0097] The vehicle information display method provided in the embodiment of the present application is explained in detail below.

[0098] Figure 2 This is a flow chart of a vehicle information display method provided by an embodiment of the present application. This method can be applied to a vehicle's onboard multimedia host HUT. Figure 2 The method includes the following steps 201-203.

[0099] Step 201: Upon receiving a target CAN message, the HUT performs a security check on the target CAN message to obtain a target check result. The target CAN message includes first vehicle information to be displayed.

[0100] The target CAN message may be a CAN message sent from another controller, wherein the target CAN message includes a data segment, and the data segment of the target CAN message includes the first vehicle information to be displayed.

[0101] In an embodiment of the present application, the target CAN message may further include a function signal, which may indicate the function corresponding to the target CAN message. In this case, the first vehicle information is the vehicle information corresponding to this function. As an example, if the function signal includes an identifier for a gear position display, then the target CAN message is a CAN message corresponding to the gear position display function. In other words, if the target CAN message is used for gear position display, then the first vehicle information contained in the data segment of the target CAN message is the specific gear position to be displayed.

[0102] The first vehicle information refers to the received vehicle information to be displayed, wherein the first vehicle information can be various vehicle information that can be displayed on the instrument screen. For example, the first vehicle information may include vehicle speed, tire pressure, various alarm signals, and status information of some functions (such as battery power, current gear position, current fuel level), etc.

[0103] The security check method can be pre-set. In the embodiment of the present application, the security check may include CRC check, frame format check, timestamp check, SecOC check, etc. Since the SecOC check adopts a timestamp-based freshness value mechanism and a key-encrypted MAC value mechanism to verify the identities of both communicating parties and defend against replay attacks, preferably, the security check may be the SecOC check, that is, the target CAN message is security-checked through the SecOC mechanism.

[0104] In the above manner, when the HUT receives a target CAN message, it first performs an initial security check on the target CAN message, so as to preliminarily determine whether the target CAN message has been tampered with.

[0105] In a possible manner, the operation of step 201 may be: when the HUT receives the target CAN message, it performs SecOC verification on the target CAN message to obtain a target verification result.

[0106] In this case, by performing SecOC verification on the target CAN message, the timeliness and authenticity of the target CAN message can be more accurately verified, thereby improving the verification accuracy of the target CAN message.

[0107] In CAN communication, not all CAN messages are subject to SecOC verification for security protection. Instead, SecOC verification can be selectively performed based on the importance of each function. That is, CAN messages corresponding to some functions will undergo SecOC verification for security protection. Therefore, the CAN messages used for communication in the target vehicle may include messages that undergo SecOC verification or messages that do not undergo SecOC verification.

[0108] Then, when the HUT receives CAN messages without SecOC verification and CAN messages with SecOC verification, if the current load of the HUT is large, when processing the CAN messages in sequence, some CAN messages of important functions may not be processed in time, resulting in functional delays or timeouts, and thus functional problems.

[0109] In this case, the operation of the above step 201 can also be: when the HUT receives the target CAN message, it obtains the current load rate; when the current load rate is greater than or equal to the preset load rate threshold, if the target CAN message is a CAN message for SecOC verification, the target CAN message is subjected to SecOC verification to obtain the target verification result.

[0110] The current load rate is used to indicate the number of tasks currently being processed by the HUT and the number of tasks waiting to be processed, which can reflect the busyness of the HUT. It should be understood that a larger current load rate indicates a busier HUT, and a smaller current load rate indicates a less busy HUT.

[0111] In some embodiments, a performance monitoring unit may be integrated into the HUT, and the performance monitoring unit may monitor the current load rate.

[0112] The target CAN message may also include a SecOC signal, which is used to indicate whether to perform SecOC verification on the target CAN message. The SecOC signal may include 0 or 1. When the SecOC signal is 1, it indicates that the target CAN message is a message that undergoes SecOC verification. When the SecOC signal is 0, it indicates that the target CAN message is not a message that undergoes SecOC verification.

[0113] The preset load rate threshold can be set in advance, and the preset load rate threshold can be set to be relatively large, for example, the preset load rate threshold can be set to 50%.

[0114] When the current load rate is greater than or equal to the preset load rate threshold, it indicates that the current load rate is high, which means that the HUT is currently busy. In other words, the HUT currently has many CAN messages to process. If the CAN messages are processed in the order in which they are received, CAN messages corresponding to important functions may not be processed in a timely manner.

[0115] In this case, when the HUT receives a target CAN message, if the target CAN message is a CAN message that undergoes SecOC verification, it means that the function corresponding to the target CAN message is more important. When the current load rate is greater than or equal to the preset load rate threshold, the target CAN message is directly processed by SecOC verification, so that the target CAN message can be processed first, so that the target CAN message is not delayed. Then, the function corresponding to the target CAN message will be responded to in a timely manner, which can improve the operating performance of the HUT.

[0116] For example, a HUT receives multiple CAN messages over a period of time, including messages that undergo SecOC verification and messages that do not. Assuming the current load rate is 80%, the HUT can directly perform SecOC verification on the messages that undergo SecOC verification. That is, upon receiving a target CAN message, the HUT can directly process the target CAN message. Furthermore, assuming the current load rate is 40%, the HUT can process the multiple CAN messages sequentially and, when it is the target CAN message's turn to be processed, perform SecOC verification on the target CAN message.

[0117] Specifically, the HUT performs SecOC verification on the target CAN message, and the operation to obtain the target verification result can be: the HUT parses the target CAN message based on a preset format to obtain a first MAC value, a freshness value and first vehicle information; encrypts the first vehicle information, the freshness value and the sender's key of the target CAN message through a preset encryption algorithm to obtain a second MAC value; when the first MAC value and the second MAC value are the same, the target verification result is determined to be a security verification success; when the first MAC value and the second MAC value are different, the target verification result is determined to be a security verification failure.

[0118] The preset format may be a standard format of a CAN message, that is, a message format consisting of a frame start, an arbitration segment, a control segment, a data segment, a MAC value and a freshness value, a cyclic redundancy check CRC segment, a response segment, and a frame end.

[0119] The preset encryption algorithm can be pre-set. In one possible embodiment, the preset encryption algorithm can be a symmetric encryption algorithm or an asymmetric encryption algorithm. For example, the preset encryption algorithm can be the AES-128 algorithm. For another example, the preset encryption algorithm can be the Rivest-Shamir-Adleman algorithm (RSA algorithm).

[0120] It should be understood that each controller of the target vehicle can share its own public key. Before sending the target CAN message, it can use its own private key to encrypt the freshness value and the vehicle information to be sent to obtain a MAC value. Since each controller shares its own public key, the receiver (HUT) can encrypt the received freshness value and the first vehicle information using the sender's public key to obtain a MAC value. Therefore, the sender's private key can be the sender's public key.

[0121] The second MAC value is a MAC value determined by the receiver based on the first vehicle information and the freshness value contained in the target CAN message. When the first vehicle information and the freshness value remain unchanged, the MAC value calculated by the sender is the same as the MAC value calculated by the receiver. If the second MAC value is the same as the first MAC value, it means that the first vehicle information and the freshness value have not changed, that is, the target CAN message has not been tampered with, and it can be determined that the security verification is successful. If the second MAC value is different from the first MAC value, it means that the first vehicle information or the freshness value has changed, that is, the target CAN message may have been tampered with, and therefore there may be a problem with the first vehicle information contained in the target CAN message, and it can be determined that the security verification has failed.

[0122] Step 202: When the target verification result indicates that the safety verification is successful, the HUT performs a secondary verification on the target CAN message based on at least one of the current operation information and environmental information of the target vehicle.

[0123] The current operating information of the target vehicle is used to represent vehicle information during the operation of the target vehicle. For example, the current operating information may include various vehicle information during the operation of the target vehicle, such as vehicle speed, tire pressure of each tire, engine speed, current actual gear position, the operating status of the auxiliary driving function, etc. In some embodiments, the current operating information may also include the operating status of various components of the cabin, such as whether the seat belt is fastened and whether the door is closed. It should be understood that the operating status of various components of the cabin can be obtained by camera recognition, for example, the camera can be used to identify whether the seat belt is fastened.

[0124] In an embodiment of the present application, the target vehicle may include multiple sensor devices, and the multiple sensor devices may collect current operating information. Generally, different controllers may be connected to the relevant sensors, and the controllers may subsequently transmit the vehicle information to the HUT. However, to avoid the possibility of tampering during transmission, in an embodiment of the present application, the multiple sensor devices may be directly connected to the HUT, and the multiple sensor devices may directly send the collected data to the HUT, so that the HUT can directly obtain the vehicle information of the target vehicle during operation, that is, the current operating information.

[0125] This environmental information is used to represent the state of the target vehicle's environment. Therefore, this environmental information can indicate the presence of obstacles, pedestrians, vehicles, traffic light status, etc. around the target vehicle, as well as the relative speed and distance between the target vehicle and other vehicles if there are other vehicles around the target vehicle. In one possible approach, the target vehicle can be equipped with a camera to collect this environmental information. In another possible approach, the target vehicle can be equipped with a radar to also collect this environmental information.

[0126] Since the current operating information can represent vehicle information during the operation of the target vehicle, such as vehicle speed, acceleration, engine speed, door status, seat belt status, and other information, this information can reflect the actual operation of certain functions. For example, the door status can indicate whether the doors of the target vehicle are closed, and thus determine whether the door warning indicator on the instrument panel is lit. Therefore, based on the current operating information, the target CAN message can be accurately verified. Therefore, in the embodiment of the present application, the target CAN message can be secondary verified based on the current operating information of the target vehicle.

[0127] In addition, the environmental information represents the situation of the target vehicle's environment, such as whether there are obstacles in the target vehicle's environment, the relative motion relationship with other vehicles, etc. Through this environmental information, it is possible to infer the actual operating state of the target vehicle, thereby inferring the actual operating conditions of some functions. For example, if the target vehicle has accumulated 10 minutes of forward movement, and there is no red light or obstacle in front, and there are other vehicles following less than 10m behind the target vehicle, then it can be inferred that the gear position of the target vehicle may be the forward gear. Therefore, according to this environmental information, it is also possible to accurately verify the target CAN message, so that in the embodiment of the present application, the target CAN message can be secondary verified based on the environmental information of the target vehicle.

[0128] In other words, since the current operating information of the target vehicle and at least one of the environmental information can accurately reflect the actual operating conditions of some functions of the target vehicle, by combining the current operating information of the target vehicle and at least one of the environmental information, the actual vehicle information of the function indicated by the target CAN message can be determined more accurately, thereby achieving accurate verification of the target CAN message.

[0129] In the above method, by verifying the target CAN message in combination with at least one of the current operating information and environmental information of the target vehicle, it is possible to determine whether the first vehicle information contained in the target CAN message has been tampered with, thereby achieving accurate verification of the target CAN message.

[0130] In addition, when the target verification result indicates that the security verification is successful, it means that the target CAN message is preliminarily considered not to have been tampered with. Then, a secondary verification is performed, which is equivalent to judging the authenticity of the target CAN message through double verification, thereby improving the accuracy of the target CAN message verification and further improving the accuracy of the vehicle information display.

[0131] In one possible manner, the operation of step 202 may be: the HUT determines the second vehicle information based on at least one of the current operating information and the environmental information; if the second vehicle information is consistent with the first vehicle information, determines that the secondary verification has passed; if the second vehicle information is inconsistent with the first vehicle information, determines that the secondary verification has failed.

[0132] The second vehicle information is the actual vehicle information corresponding to the target function indicated by the target CAN message. The target function is the function indicated by the function signal contained in the target CAN message. For example, if the target function is gear position display, which indicates the current actual gear position, the second vehicle information corresponds to the current actual gear position.

[0133] Since the current operating information and environmental information of the target vehicle can reflect the actual operating state of the target vehicle, the corresponding actual vehicle information can be determined based on at least one of the current operating information and the environmental information.

[0134] When the second vehicle information is consistent with the first vehicle information, it means that the actual vehicle information corresponding to the target function is consistent with the first vehicle information contained in the target CAN message, that is, the actual vehicle information corresponding to the target function is consistent with the received vehicle information to be displayed, which also indicates that the target CAN message has not been tampered with, so it can be determined that the secondary verification has passed.

[0135] When the second vehicle information is inconsistent with the second vehicle information, it means that the actual vehicle information corresponding to the target function is inconsistent with the first vehicle information contained in the target CAN message, that is, the actual vehicle information corresponding to the target function is inconsistent with the received vehicle information to be displayed, which also indicates that the target CAN message may be tampered with. Therefore, it can be determined that the secondary verification has failed.

[0136] Among them, the operation of the HUT determining the second vehicle information based on at least one of the current operating information and environmental information of the target vehicle can be: the HUT inputs at least one of the current operating information and the environmental information into a vehicle information inference model, processes the current operating information and at least one of the environmental information through the vehicle information inference model, and obtains multiple reference vehicle information and probabilities corresponding to the multiple reference vehicle information; determines the reference vehicle information with the highest probability among the multiple reference vehicle information as the second vehicle information through the vehicle information inference model, and outputs the second vehicle information.

[0137] The vehicle information inference model is used to infer actual vehicle information corresponding to the target function.

[0138] The multiple reference vehicle information are vehicle information that may correspond to the target function predicted by the vehicle information inference model, and the probabilities corresponding to the multiple reference vehicle information are used to represent the probability that the corresponding reference vehicle information is actual vehicle information.

[0139] It should be understood that the reference vehicle information with the highest probability among the multiple reference vehicle information is most likely to be the actual vehicle information corresponding to the target function. Therefore, the reference vehicle information with the highest probability among the multiple reference vehicle information can be determined as the second vehicle information.

[0140] In the above method, the second vehicle information is determined by combining the current operating information of the target vehicle and at least one of the environmental information through the vehicle information prediction model, making the determination process of the second vehicle information more intelligent, and the second vehicle information can be determined more quickly through the vehicle information inference model, thereby improving the efficiency of determining the second vehicle information.

[0141] It is worth noting that before inputting at least one of the current operating information of the target vehicle and the environmental information into the vehicle information inference model, the vehicle information inference model may be trained first.

[0142] Specifically, the server can obtain multiple training samples and use the multiple training samples to train the neural network model to obtain the vehicle information inference model. The server is a computer device used to train the vehicle information inference model.

[0143] The plurality of training samples may be pre-set. Each of the plurality of training samples includes sample data and a sample label, wherein the sample data includes data of a driving scene corresponding to each function, and the sample label is actual vehicle information corresponding to the sample data.

[0144] The neural network model can include multiple layers, including an input layer, multiple hidden layers, and an output layer. The input layer receives input data; the output layer outputs processed data. Multiple hidden layers, located between the input and output layers, process the data and are invisible to the outside world. For example, the neural network model can be a long short-term memory model.

[0145] When the server trains the neural network model using multiple training samples, for each of the multiple training samples, the server may input the input data of the training sample into the neural network model to obtain output data; determine the loss value between the output data and the sample label of the training sample using a loss function; and adjust the parameters of the neural network model based on the loss value. After the parameters of the neural network model are adjusted based on each of the multiple training samples, the neural network model with the adjusted parameters becomes the vehicle information inference model.

[0146] Among them, the operation of the server adjusting the parameters in the neural network model according to the loss value can refer to the relevant technology, and the embodiments of the present application will not elaborate on this in detail.

[0147] For example, the server can use the formula To adjust any parameter in the neural network model. is the adjusted parameter. W is the parameter before adjustment. α is the learning rate, which can be preset, such as 0.001, 0.000001, etc., and is not limited to this in the present embodiment. dw is the derivative of the loss function with respect to W, which can be obtained based on the loss value.

[0148] Generally, the current operating information of the target vehicle may include various aspects of vehicle information, some of which may be relevant to the target function, while some may not be relevant to the target function. In some embodiments, the HUT may determine the second vehicle information based on the current operating information of the target vehicle and at least one of the environmental information. The HUT may obtain current operating information related to the target function from the current operating information, and then determine the second vehicle information based on at least one of the current operating information related to the target function and the environmental information.

[0149] For example, the current operating information of the target vehicle may include vehicle speed, driving direction, tire pressure of each tire, and engine speed. If the target function is gear display, then the current operating information related to the target function obtained from the current operating information may include vehicle speed and driving direction (vehicle speed and driving direction can indicate the current vehicle status of the target vehicle, such as whether it is moving forward, backward, or stopped).

[0150] In the above method, the second vehicle information is determined based on the current operating information related to the target function and at least one of the environmental information, so that the determination of the second vehicle information can be achieved only in combination with the content related to the target function, thereby reducing the computational complexity and improving the efficiency of determining the second vehicle information.

[0151] Then, the operation of determining the second vehicle information based specifically on the current operating information related to the target function and at least one of the environmental information is as follows: the HUT inputs the current operating information related to the target function and at least one of the environmental information into the vehicle information inference model, processes the current operating information related to the target function and at least one of the environmental information through the vehicle information inference model, and obtains multiple reference vehicle information and probabilities corresponding to the multiple reference vehicle information; determines the reference vehicle information with the highest probability among the multiple reference vehicle information as the second vehicle information through the vehicle information inference model, and outputs the second vehicle information.

[0152] In this case, by inputting at least one of the current operating information and the environmental information related to the target function into the vehicle information inference model, the amount of data input to the model can be reduced, thereby reducing the complexity of the model calculation process and improving the model output efficiency.

[0153] It is worth noting that when the target verification result indicates that the safety verification is successful, the HUT can also first obtain the current operating information of the target vehicle and at least one of the environmental information, and then perform a secondary verification on the target CAN message based on the current operating information and at least one of the environmental information.

[0154] In one possible manner, the operation of the HUT obtaining the current operating information of the target vehicle and at least one of the environmental information can be: the HUT obtains the functional type of the target function indicated by the target CAN message; and based on the functional type of the target function, obtains the current operating information of the target vehicle and at least one of the environmental information.

[0155] The function type may include the type of function that can be displayed on the instrument panel, for example, the function type may include an alarm indicator light display, a gear position display, a vehicle speed display, a tire pressure display, an engine status display, etc.

[0156] Since the displayed content corresponding to different functions is different, the determination of the actual vehicle information is also different. The actual vehicle information corresponding to some functions depends only on the operating status of the vehicle itself, while the actual vehicle information corresponding to some functions can be determined by integrating multiple aspects of information. Therefore, the determination of the actual vehicle information corresponding to different functions can be achieved based on information from different aspects.

[0157] In the above method, by obtaining the functional type of the target function and based on the functional type of the target function, obtaining the current operating information of the target vehicle and at least one of the environmental information, the content that can accurately reflect the actual vehicle information corresponding to the target function can be obtained, so that more accurate second vehicle information can be determined subsequently.

[0158] Among them, the operation of the HUT to obtain at least one of the current operating information of the target vehicle and the environmental information based on the function type of the target function can be: when the function type is an alarm indicator light display or a vehicle speed display, the HUT obtains the current operating information of the target vehicle; when the function type is a gear display, the HUT obtains the current operating information and the environmental information.

[0159] Warning indicator light display refers to the display of corresponding warning indicators on the instrument panel. For example, warning indicators such as tire pressure warning indicator, seat belt warning indicator, vehicle stability system warning indicator, and fuel level warning indicator can be displayed. It should be understood that the display of warning indicators is related to the operating status of various aspects of the vehicle. Therefore, when the function type is warning indicator light display, the current operating information of the target vehicle can be obtained.

[0160] For vehicle speed display, the speed to be displayed is generally determined by the wheel speed or the speed collected by the speed sensor. These parameters are also related to the operating status of various aspects in the vehicle. Therefore, when the function type is vehicle speed display, the current operating information of the target vehicle can be obtained.

[0161] For the gear display, the vehicle gear can be judged by combining multiple aspects. For example, the vehicle gear can be judged by the driving direction and speed, or by the reference between the target vehicle and the surrounding objects. Therefore, for the gear display, the current operating information of the target vehicle and the environmental information can be obtained to determine a more accurate actual gear.

[0162] It should be noted that, in addition to the above-mentioned methods of obtaining the warning indicator light display, vehicle speed display and gear position display, at least one of the current operating information and the environmental information can also be obtained in the following situations.

[0163] When the function type is tire pressure display or engine status display, the HUT obtains the current operating information of the target vehicle.

[0164] Both the tire pressure display and the engine status display involve the internal operating parameters of the vehicle, such as the tire pressure of each tire and parameters such as engine speed and water temperature. Therefore, in this case, the current operating information of the target vehicle can be obtained.

[0165] It is worth noting that the target CAN message can be subjected to a secondary check in step 202 to determine whether the target CAN message has been tampered with during transmission. If the target CAN message has not been tampered with, the vehicle information contained in the target CAN message can be displayed, that is, the following step 203 can be continued.

[0166] Step 203: If the secondary verification is passed, the HUT displays the first vehicle information.

[0167] If the secondary verification passes, the actual vehicle information corresponding to the target function indicated by the target CAN message is consistent with the first vehicle information contained in the target CAN message, that is, the received vehicle information is consistent with the vehicle information actually reflected by the vehicle status, which means that the target CAN message has not been tampered with, and it can be determined that the first vehicle information contained in the target CAN message is accurate.

[0168] In this case, if the secondary verification is passed, the first vehicle information is displayed, so that the target vehicle can display accurate first vehicle information, so that the user can obtain accurate vehicle information, which can improve the user experience.

[0169] Specifically, when the secondary verification is passed, the HUT can control the instrument screen of the target vehicle to display the first vehicle information, so that the first vehicle information can be displayed on the instrument screen, so that the user can see the vehicle information.

[0170] Optionally, if the secondary verification fails, the HUT may display the second vehicle information.

[0171] Because the second vehicle information is determined based on at least one of the target vehicle's current operating information and the environmental information, the second vehicle information is relatively accurate actual vehicle information corresponding to the target function. Therefore, if the received vehicle information corresponding to the target function has been tampered with, the more accurate actual vehicle information, i.e., the second vehicle information, can be displayed.

[0172] In this case, by displaying the second vehicle information when the secondary verification fails, even if the target CAN message is tampered with, relatively accurate vehicle information can be displayed, avoiding the phenomenon of untimely vehicle information update caused by discarding the CAN message after the verification fails, thereby providing users with more accurate vehicle information and improving user experience.

[0173] It is worth noting that, when the target verification result in the above step 202 indicates that the safety verification has failed, the second vehicle information can also be determined based on the current operating information of the target vehicle and at least one of the environmental information; and the second vehicle information can be displayed.

[0174] When the target verification result indicates that the security verification has failed, it means that the initial verification of the target CAN message has failed. In this case, it can be directly determined that the target CAN message has been tampered with without the need for a secondary verification.

[0175] In addition, in order to ensure that the displayed vehicle information is updated in a timely manner, the actual vehicle information corresponding to the target function indicated by the target CAN message can be determined in combination with the current actual operating status of the target vehicle, so that the second vehicle information can be determined based on the current operating information and at least one of the environmental information.

[0176] In this case, when the target verification result indicates that the safety verification has failed, the second vehicle information is determined based on the current operating information and at least one of the environmental information, and the second vehicle information is displayed. This allows relatively accurate vehicle information to be displayed even if the target CAN message is tampered with, thereby avoiding the phenomenon of untimely vehicle information updates caused by discarding CAN messages after verification failure, thereby providing users with relatively accurate vehicle information and improving user experience.

[0177] Among them, the operation of determining the second vehicle information based on the current operating information of the target vehicle and at least one of the environmental information is similar to the operation of determining the second vehicle information based on the current operating information of the target vehicle and at least one of the environmental information in the above step 202, and will not be repeated here.

[0178] It is worth noting that the vehicle information display method provided in the embodiment of the present application can verify the CAN message according to the actual operating status of the target vehicle and the current road conditions, which can improve the verification accuracy of the CAN message, thereby strengthening the security protection capability of the vehicle network. In terms of fault tolerance, the fault tolerance and reliability of the system are improved through real-time monitoring and early warning of health performance. In terms of data processing efficiency, by giving priority to the processing of SecOC-verified CAN messages under high-load conditions, the data verification and transmission efficiency of the vehicle network under high-load conditions can be ensured, thereby improving the processing efficiency of important messages, and enhancing the flexibility and adaptability of data processing, which can ensure the normal operation of system functions.

[0179] For ease of understanding, let's take the transmission controller sending the target CAN message of the gear display function to the HUT as an example. Figure 3 The vehicle information display method provided in the embodiment of the present application is exemplarily described. Figure 3 The method includes steps 301 to 308.

[0180] Step 301: The HUT receives a target CAN message with the current gear position being “D”.

[0181] Step 302: The HUT obtains the current load rate and determines whether the current load rate is greater than or equal to a preset load rate threshold.

[0182] Step 303: If the current load rate of the HUT is greater than or equal to the preset load rate threshold, and the target CAN message is a CAN message that requires SecOC verification, the HUT performs SecOC verification on the target CAN message and obtains a target verification result. If the target verification result indicates that the security verification is successful, the HUT executes steps 304-306. If the target verification result indicates that the security verification fails, the HUT executes steps 307-308.

[0183] Step 304: The HUT obtains the current operating information of the target vehicle, such as the current speed and direction of travel, as well as the environmental information of the target vehicle. For example, the environmental information and current operating status of the target vehicle include "the target vehicle has been moving forward for 10 minutes, there are no red lights or obstacles ahead, and there are other vehicles following the target vehicle less than 10 meters behind it."

[0184] Step 305: The HUT performs a secondary verification of the target CAN message based on the target vehicle's current operating information and the environmental information. For example, the environmental information and current operating status of "10 minutes of cumulative forward movement, no red lights or obstacles ahead, and a vehicle less than 10 meters behind the target vehicle" indicate that the target vehicle is currently in motion and moving forward. Therefore, the HUT can determine that the current gear position is "D," which matches the "D" position in the target CAN message. Therefore, the secondary verification is considered successful.

[0185] Step 306: If the secondary verification is passed, the HUT displays the current gear position “D” in the target CAN message.

[0186] Step 307: The HUT determines second vehicle information based on the current operating information and the environmental information.

[0187] Step 308: The HUT displays the second vehicle information.

[0188] In an embodiment of the present application, upon receiving a target CAN message, the HUT first performs a security check on the target CAN message to obtain a target check result. If the target check result indicates a successful security check, the target CAN message is rechecked based on at least one of the target vehicle's current operating information and environmental information. If the secondary check passes, the first vehicle information is displayed, that is, the vehicle information within the data segment of the target CAN message can be displayed. Because the vehicle's operating information and environmental information can reflect the actual vehicle information corresponding to the target function indicated by the target CAN message, the target CAN message can be accurately checked using the target vehicle's current operating information and environmental information. The present application performs a secondary check on the target CAN message by combining at least one of the target vehicle's current operating information and environmental information. If the secondary check also passes, the vehicle information contained in the target CAN message is displayed. In this way, the authenticity of the target CAN message is determined through dual verification and actual vehicle information, thereby improving the accuracy of the target CAN message verification and, in turn, the accuracy of the vehicle information display.

[0189] Figure 4 This is a schematic diagram of the structure of a vehicle information display device provided by an embodiment of the present application. The vehicle information display device can be implemented as part or all of a vehicle by software, hardware, or a combination of both. The vehicle can be as follows Figure 5 Vehicle shown. Figure 4 The device includes: a first verification module 401, a second verification module 402 and a first display module 403.

[0190] A first verification module 401 is configured to perform a security verification on a target CAN message upon receiving the target CAN message, and obtain a target verification result, wherein the target CAN message includes the first vehicle information to be displayed;

[0191] A second verification module 402 is configured to perform a secondary verification on the target CAN message based on at least one of the current operating information and environmental information of the target vehicle when the target verification result indicates that the safety verification is successful;

[0192] The first display module 403 is configured to display the first vehicle information if the secondary verification passes.

[0193] Optionally, the second verification module 402 is configured to:

[0194] Determining second vehicle information based on at least one of the current operating information and the environmental information, where the second vehicle information is actual vehicle information corresponding to the target function indicated by the target CAN message;

[0195] If the second vehicle information is consistent with the first vehicle information, determining that the secondary verification is passed;

[0196] When the second vehicle information is inconsistent with the first vehicle information, it is determined that the secondary verification has failed.

[0197] Optionally, the second verification module 402 is configured to:

[0198] Inputting at least one of the current operating information and the environmental information into a vehicle information inference model, processing at least one of the current operating information and the environmental information using the vehicle information inference model to obtain a plurality of reference vehicle information and probabilities corresponding to the plurality of reference vehicle information;

[0199] The reference vehicle information with the highest probability among the plurality of reference vehicle information is determined as the second vehicle information through the vehicle information estimation model, and the second vehicle information is output.

[0200] Optionally, the device further comprises:

[0201] a determination module, configured to determine, when the target verification result indicates a safety verification failure, second vehicle information based on at least one of the current operation information and the environmental information, the second vehicle information being actual vehicle information corresponding to the target function indicated by the target CAN message;

[0202] The second display module is used to display the second vehicle information.

[0203] Optionally, the security check includes SecOC check, and the first check module 401 is configured to:

[0204] When the target CAN message is received, the current load rate is obtained;

[0205] When the current load rate is greater than or equal to the preset load rate threshold, if the target CAN message is a CAN message that is subject to SecOC verification, SecOC verification is performed on the target CAN message to obtain a target verification result.

[0206] Optionally, the device further comprises:

[0207] A first acquisition module is used to obtain a function type of a target function indicated by a target CAN message;

[0208] The second acquisition module is used to acquire at least one of current operation information and environmental information of the target vehicle based on the function type.

[0209] Optionally, the function type includes warning indicator light display, gear position display, and vehicle speed display, and the second acquisition module is used to:

[0210] When the function type is warning indicator light display or vehicle speed display, obtain the current operating information of the target vehicle;

[0211] When the function type is gear display, the current operation information and the environment information are obtained.

[0212] In an embodiment of the present application, upon receiving a target CAN message, a security check is first performed on the target CAN message to obtain a target check result. If the target check result indicates that the security check is successful, the target CAN message is checked again based on at least one of the current operating information and environmental information of the target vehicle. If the secondary check passes, the first vehicle information is displayed, that is, the vehicle information within the data segment of the target CAN message can be displayed. Since the vehicle's operating information and environmental information can reflect the actual vehicle information corresponding to the target function indicated by the target CAN message, the target CAN message can be accurately checked using the current operating information and environmental information of the target vehicle. The present application performs a secondary check on the target CAN message by combining at least one of the current operating information and environmental information of the target vehicle. If the secondary check also passes, the vehicle information contained in the target CAN message is displayed. In this way, the authenticity of the target CAN message is determined by dual verification and actual vehicle information, thereby improving the accuracy of the target CAN message verification and, in turn, the accuracy of the vehicle information display.

[0213] It should be noted that: when the vehicle information display device provided in the above embodiment displays vehicle information, it only uses the division of the above-mentioned functional modules as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0214] The functional units and modules in the above embodiments may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The above integrated units may be implemented in the form of hardware or software functional units. In addition, the specific names of the functional units and modules are only for the purpose of distinguishing them from each other and are not intended to limit the scope of protection of the embodiments of this application.

[0215] The vehicle information display device and the vehicle information display method provided in the above embodiments belong to the same concept. The specific working process of the units and modules in the above embodiments and the technical effects brought about can be found in the method embodiment part and will not be repeated here.

[0216] Figure 5 It is a structural schematic diagram of a vehicle provided in an embodiment of the present application.

[0217] For example, Figure 5 As shown, the vehicle 500 includes: a memory 51 and a processor 50, wherein the memory 51 stores an executable program code 52, and the processor 50 is used to call and execute the executable program code 52 to perform the above-mentioned vehicle information display method.

[0218] This embodiment can divide the vehicle into functional modules based on the above-described method example. For example, each functional module can be mapped to a specific function, or two or more functions can be integrated into a single processing module. The integrated module can be implemented in hardware. It should be noted that the module division in this embodiment is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used.

[0219] In the case of dividing each functional module into corresponding functional modules, the vehicle may include: a first verification module, a second verification module, and a first display module. It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0220] The vehicle provided in this embodiment is used to execute the above-mentioned vehicle information display method, and thus can achieve the same effect as the above-mentioned implementation method.

[0221] When an integrated unit is used, the vehicle may include a processing module and a storage module. The processing module may be used to control and manage the vehicle's movements, while the storage module may be used to support the vehicle in executing corresponding program codes and data.

[0222] The processing module may be a processor or controller that implements or executes the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processing system (DSP) and a microprocessor, and the storage module may be a memory.

[0223] This embodiment also provides a computer-readable storage medium, which stores computer program code. When the computer program code runs on a computer, the computer executes the above-mentioned related method steps to implement the above-mentioned vehicle information display method in the above-mentioned embodiment.

[0224] This embodiment also provides a computer program product. When the computer program product is run on a computer, it enables the computer to execute the above-mentioned related steps to implement the above-mentioned vehicle information display method in the above-mentioned embodiment.

[0225] Among them, the vehicle, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the method provided above and will not be repeated here.

[0226] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and brevity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0227] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0228] The above content is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A vehicle information display method, characterized in that: The method comprises: When a target CAN message is received, performing a security check on the target CAN message to obtain a target check result, wherein the target CAN message includes the first vehicle information to be displayed; If the target verification result indicates that the safety verification is successful, performing a secondary verification on the target CAN message based on at least one of the current operating information and environmental information of the target vehicle; If the secondary verification passes, the first vehicle information is displayed.

2. The method according to claim 1, wherein The secondary verification of the target CAN message based on at least one of the current operation information and the environmental information of the target vehicle includes: determining second vehicle information based on at least one of the current operation information and the environmental information, where the second vehicle information is actual vehicle information corresponding to the target function indicated by the target CAN message; If the second vehicle information is consistent with the first vehicle information, determining that the secondary verification is passed; When the second vehicle information is inconsistent with the first vehicle information, it is determined that the secondary verification has failed.

3. The method according to claim 2, wherein The determining the second vehicle information based on at least one of the current operation information and the environmental information includes: inputting at least one of the current operation information and the environmental information into a vehicle information inference model, processing at least one of the current operation information and the environmental information using the vehicle information inference model to obtain a plurality of reference vehicle information and probabilities corresponding to the plurality of reference vehicle information; The reference vehicle information with the highest probability among the plurality of reference vehicle information is determined as the second vehicle information by using the vehicle information estimation model, and the second vehicle information is output.

4. The method according to claim 1, wherein The method further comprises: If the target verification result indicates a safety verification failure, determining second vehicle information based on at least one of the current operation information and the environmental information, where the second vehicle information is actual vehicle information corresponding to the target function indicated by the target CAN message; The second vehicle information is displayed.

5. The method according to claim 1, wherein The security check includes a SecOC check. When a target CAN message is received, the security check is performed on the target CAN message to obtain a target check result, including: Upon receiving the target CAN message, obtaining the current load rate; When the current load rate is greater than or equal to a preset load rate threshold, if the target CAN message is a CAN message that undergoes SecOC verification, SecOC verification is performed on the target CAN message to obtain the target verification result.

6. The method according to claim 1, wherein The method further comprises: Obtaining a function type of a target function indicated by the target CAN message; Based on the function type, at least one of current operation information and environmental information of the target vehicle is obtained.

7. The method according to claim 6, wherein The function types include warning indicator light display, gear position display, and vehicle speed display. The acquiring, based on the function types, at least one of current operating information and environmental information of the target vehicle includes: When the function type is warning indicator light display or vehicle speed display, obtaining current operating information of the target vehicle; When the function type is gear position display, the current operation information and the environmental information are obtained.

8. A vehicle information display device, characterized in that: The device comprises: a first verification module, configured to, upon receiving a target CAN message, perform a security verification on the target CAN message to obtain a target verification result, wherein the target CAN message includes first vehicle information to be displayed; A second verification module is configured to perform a secondary verification on the target CAN message based on at least one of current operating information and environmental information of the target vehicle when the target verification result indicates that the safety verification is successful; The first display module is configured to display the first vehicle information if the secondary verification passes.

9. A vehicle, characterized in that: The vehicle comprises: a memory for storing executable program code; A processor is configured to call and run the executable program code from the memory, so that the vehicle executes the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.