Vehicle control method and device, vehicle and computer readable storage medium
By introducing the SecOC module into the vehicle communication system, the vehicle control messages are security verified and the target messages are generated, which solves the problem of vehicle function interruption caused by message verification failure and achieves stable operation and safety improvement of the vehicle under security threats.
Patent Information
- Application Number
- CN202510619109.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-09-12
AI Technical Summary
Existing vehicle communication systems directly discard messages when verification fails, resulting in interruption of vehicle functions that rely on these messages and affecting safe driving.
By introducing a secure on-board communication module (SecOC) into the vehicle communication system, the vehicle control messages are security verified, target messages are generated and replaced with messages that fail security verification, ensuring that the task type of the target message is the same as the failed message, ensuring the normal operation of vehicle functions.
It ensures the stable operation of the vehicle under security threats, improves the safety of vehicle communication and driving, and enhances the user experience.
Smart Images

Figure CN120639335A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicles, and more particularly, to a vehicle control method, a vehicle control device, a vehicle, and a computer-readable storage medium in the field of vehicles. Background Art
[0002] As vehicles become increasingly intelligent and connected, vehicle communication systems are becoming increasingly complex and face various potential security threats. To ensure the security of vehicle communication systems, security verification of messages transmitted within them is required.
[0003] However, existing security verification mechanisms often directly discard messages when verification fails. Directly discarding messages that fail verification will cause vehicle functions that rely on these messages to be interrupted, and vehicle functions cannot be executed normally, affecting the safe driving of the vehicle. Summary of the Invention
[0004] The present application provides a vehicle control method, device, vehicle and computer-readable storage medium. The present application can enable the normal operation of vehicle functions that rely on the execution of vehicle control messages due to security verification failures, avoid the interruption of vehicle functions that rely on the execution of vehicle control messages due to security verification failures, ensure the stable operation of the vehicle under security threats, improve the safety of vehicle communications and driving, and enhance the user experience.
[0005] In a first aspect, a vehicle control method is provided, which is applied to a secure vehicle-mounted communication module, the method comprising: upon receiving a vehicle control message, verifying the security of the vehicle control message; if the security verification of the vehicle control message fails, obtaining the task type of the target task carried by the vehicle control message; generating a target message according to the task type, the target message being used to instruct a target execution unit in the vehicle to execute the target task; and sending the target message to the target execution unit so that the target execution unit executes the target task according to the target message.
[0006] In this embodiment, by verifying the security of the received vehicle control message, when the security verification of the vehicle control message fails, the task type of the target task carried by the vehicle control message is obtained; a target message is generated according to the task type, and the target message includes a technical solution for instructing the target execution unit in the vehicle to execute the target task, so that the task type of the generated target message is the same as the task type of the vehicle control message that fails the security verification, thereby ensuring that the vehicle function that depends on the generated target message to be executed is the same as the vehicle function that depends on the vehicle control message that fails the security verification to be executed, and by sending the target message to the target execution unit, so that the target execution unit executes the target task according to the target message. The technical solution for executing the target task of the document sends the target that is the same as the vehicle function executed by the vehicle control message that fails the safety verification to the target execution unit, so that the target execution unit executes the target task according to the target message, ensuring that the vehicle function executed by the vehicle control message that fails the safety verification runs normally and is not interrupted due to the failure of the vehicle control message verification. This method can enable the vehicle function executed by the vehicle control message that fails the safety verification to run normally, avoids the vehicle function executed by the vehicle control message that fails the safety verification from being interrupted, ensures the stable operation of the vehicle under security threats, improves the safety of vehicle communication and driving, and enhances user experience.
[0007] In combination with the first aspect, in some possible implementations, generating the target message according to the task type includes: acquiring vehicle driving data related to the task type; and determining the target message according to the vehicle driving data.
[0008] In this embodiment, by obtaining vehicle driving data related to the task type and determining the target message based on the vehicle driving data, a better match can be achieved between the generated target message and the behavior of the vehicle function that depends on the execution of the vehicle control message, thereby avoiding sending target messages containing erroneous tasks in inappropriate situations and optimizing the safety and reliability of vehicle driving.
[0009] In combination with the first aspect and the above-mentioned implementation methods, in some possible implementation methods, determining the target message based on the vehicle driving data includes: obtaining the preset vehicle control message corresponding to the task type and the vehicle driving data from the mapping relationship between the preset task type, the preset vehicle driving data and the preset vehicle control message, and obtaining the target message.
[0010] In this embodiment, the target message is determined from the mapping relationship between the preset task type, preset vehicle driving data and preset vehicle control message through the task type and vehicle driving data. This not only shortens the time required to generate the target message, but also helps the target execution unit to complete the corresponding operation more efficiently, thereby enhancing the continuity of vehicle functions and improving the response speed and reliability of the system while ensuring driving safety.
[0011] In combination with the first aspect and the above-mentioned implementation methods, in some possible implementation methods, determining the target message based on the vehicle driving data includes: using the vehicle driving data to update the data segment in the vehicle control message to obtain the updated vehicle control message; and using the updated vehicle control message as the target message.
[0012] In this embodiment, the data segment in the vehicle control message is updated by the vehicle driving data to obtain an updated vehicle control message, and the updated vehicle control message is used as the target message. This not only makes the target message closer to actual needs, but also reduces the complexity of data processing and the possibility of errors through local updates, thereby improving the overall stability and reliability of the system.
[0013] In combination with the first aspect and the above-mentioned implementation methods, in some possible implementation methods, the verification of the security of the vehicle control message includes: detecting whether the vehicle control message carries a security verification identifier; if so, verifying the security of the vehicle control message.
[0014] In this embodiment, by detecting whether the vehicle control message carries a security verification identifier, it is possible to quickly distinguish between vehicle control messages that require security verification and vehicle control messages that do not require security verification. Only when the vehicle control message carries a security verification identifier is the security of the vehicle control message verified, which can save computing resources, reduce processing delays, and thereby improve communication efficiency.
[0015] In combination with the first aspect and the above-mentioned implementation methods, in some possible implementation methods, the method also includes: if the security verification of the vehicle control message fails, verifying the reliability of the vehicle control message; if the reliability verification of the vehicle control message passes, executing the step of obtaining the task type of the target task carried by the vehicle control message.
[0016] In this embodiment, by verifying the reliability of the vehicle control message when the security verification of the vehicle control message fails, it is possible to determine whether the arrangement order of the data segments in the vehicle control message is correct. When the reliability verification of the vehicle control message passes, the step of obtaining the task type of the target task carried by the vehicle control message is executed, which can ensure that the arrangement order of the data segments in the vehicle control message is correct, and further ensure that the task type of the vehicle control message has not changed, so that the vehicle function that depends on the vehicle control message that fails the security verification is the expected vehicle function, and the normal operation of the vehicle function that depends on the vehicle control message that fails the security verification is achieved.
[0017] In combination with the first aspect and the above implementations, in some possible implementations, the vehicle's in-vehicle network includes multiple network segments, and each network segment is deployed with one of the secure in-vehicle communication modules.
[0018] In this embodiment, by deploying a secure vehicle communication module in each network segment, the secure vehicle communication module is separated from each electronic control unit, thereby reducing the deployment volume of SecOC modules, thereby reducing the burden on the entire vehicle electrical system, and reducing the computing and storage resource requirements of each ECU, reducing resource consumption, saving costs, and improving the overall performance of the vehicle electrical system.
[0019] In a second aspect, a vehicle control device is provided, the device comprising:
[0020] A verification module, configured to verify the security of a vehicle control message upon receipt of the vehicle control message;
[0021] an acquisition module, configured to acquire a task type of a target task carried in the vehicle control message if the security verification of the vehicle control message fails;
[0022] A generating module, configured to generate a target message according to the task type, wherein the target message is used to instruct a target execution unit in the vehicle to execute the target task;
[0023] A sending module is used to send the target message to the target execution unit, so that the target execution unit executes the target task according to the target message.
[0024] In a third aspect, a vehicle is provided, comprising:
[0025] a memory for storing executable program code;
[0026] A processor is used to call and run the executable program code from the memory, so that the vehicle executes the method in the above-mentioned first aspect or any possible implementation of the first aspect.
[0027] In a fourth aspect, a computer program product is provided, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the method in the first aspect or any possible implementation of the first aspect.
[0028] In a fifth aspect, a computer-readable storage medium is provided, which stores a computer program code. When the computer program code runs on a computer, the computer executes the method in the above-mentioned first aspect or any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 A system architecture diagram of a vehicle control system provided by an embodiment of the present application is shown;
[0030] Figure 2 A schematic flow chart of a vehicle control method provided in an embodiment of the present application is shown;
[0031] Figure 3 A schematic diagram of part of the electronic and electrical architecture of a vehicle provided by an embodiment of the present application is shown;
[0032] Figure 4 A schematic structural diagram of a vehicle control device provided in an embodiment of the present application is shown;
[0033] Figure 5 A structural schematic diagram of a vehicle provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0034] The following will clearly and thoroughly describe the technical solutions in this application in conjunction with the accompanying drawings. In the description of the embodiments of this application, unless otherwise specified, " / " means or, for example, A / B can mean A or B: "and / or" in the text is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more than two.
[0035] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.
[0036] As vehicles become increasingly intelligent and connected, vehicle communication systems are becoming increasingly complex and face various potential security threats. To ensure the security of vehicle communication systems, security verification of messages transmitted within them is required.
[0037] However, existing security verification mechanisms often directly discard messages when verification fails. Directly discarding messages that fail verification will cause vehicle functions that rely on these messages to be interrupted, and vehicle functions cannot be executed normally, affecting the safe driving of the vehicle.
[0038] Based on the above problems, the present application provides a vehicle control method, device, vehicle and computer storage medium. The present application generates a new message based on the task type carried by the security verification failure message in the vehicle communication system, replaces the security verification failure message with the new message, and transmits the new message to the execution unit corresponding to the security verification failure message. The execution unit executes the task corresponding to the new message. Since the task type assigned when the message is created does not change depending on the security verification result, a new message is generated based on the task type of the security verification failure message, so that the task type corresponding to the new message is the same as the task type of the security verification failure message, and then the vehicle function that depends on the execution of the new message is the same as the vehicle function that depends on the execution of the security verification failure message. The new message is sent to the execution unit corresponding to the security verification failure message for execution, so that the vehicle function that depends on the execution of the security verification failure message runs normally, avoids the interruption of the vehicle function that depends on the execution of the security verification failure message, ensures the stable operation of the vehicle under security threats, improves the safety of vehicle communication and driving, and enhances user experience.
[0039] like Figure 1 As shown, Figure 1 A system architecture diagram of a vehicle control system provided in an embodiment of the present application is shown. The vehicle control system includes an on-board diagnostic device 110, a terminal device 120 and a communication link 130.
[0040] The on-board diagnostic device 110, also known as On-Board Diagnostic (OBD), is a vehicle's own diagnostic system. This system can monitor various vehicle operating parameters in real time, including engine speed, fuel consumption, temperature, fault codes, and so on. Each electronic control unit (ECU) on the vehicle can provide relevant operating data through the OBD interface. This data can be read by external diagnostic tools for fault detection, repair, or vehicle performance optimization. While the vehicle is in motion, the OBD device can be used to collect vehicle operating data, such as vehicle speed, acceleration, engine load, and engine speed, in order to generate target messages.
[0041] Terminal device 120 is responsible for receiving vehicle operation data from the OBD device, executing the vehicle control program, and generating target messages for vehicle control. Terminal device 120 can be located on or off the vehicle and includes, but is not limited to, a personal computer, tablet computer, handheld device, in-vehicle device, wearable device, computing device, or other processing device connected to a wireless modem.
[0042] The communication link 130 is used to provide data transmission between the on-board diagnostic device 110 and the terminal device 120. The communication link 130 may include various types of wired communication links or wireless communication links. For example, the wired communication link includes a Universal Serial Bus (USB), and the wireless communication link includes a Bluetooth communication link, a Wireless-Fidelity (Wi-Fi) communication link, or a microwave communication link.
[0043] Next, combine Figure 1 The system architecture shown introduces the vehicle control method provided by the embodiment of the present application. The vehicle control method provided by the embodiment of the present application is applied to the Secure Onboard Communication (SecOC) module. The SecOC module is a secure communication module. By introducing a security mechanism into the communication protocol of the vehicle communication system, it ensures whether the transmitted message is correct and whether it has been tampered with. That is, the SecOC module integrates security functions into the vehicle communication system. Through encryption and authentication mechanisms, it ensures that the message is not tampered with or stolen during transmission, thereby verifying the overall security of the vehicle communication system and thus ensuring the security of the vehicle communication system. Figure 2 As shown, Figure 2 A flow chart of a vehicle control method provided in an embodiment of the present application is shown. The vehicle control method provided in the present application includes the following S210-S240.
[0044] S210 , when the SecOC module receives the vehicle control message, it verifies the security of the vehicle control message.
[0045] The vehicle's electronic and electrical architecture adopts a multi-segment design. Each segment is connected to other segments through a gateway. Each segment is equipped with multiple Electronic Control Units (ECUs). The multiple ECUs configured in each segment have similar functions or are located in close areas of the vehicle, sharing the same communication protocol and rate. The multiple ECUs configured in each segment work together to achieve the specific functions that the segment is responsible for. In order to ensure the security of the vehicle communication system, a SecOC module can be deployed in each ECU to verify the security of the vehicle control messages transmitted to each ECU through the SecOC module. For example, Figure 3 As shown, Figure 3 A schematic diagram of part of the electronic and electrical architecture of a vehicle provided in an embodiment of the present application is shown. A high-usage test (HUT) unit and a telematics-box (T-box) unit are configured on the service communication network segment (SC segment), and a transmission control unit (TCU) unit is configured on the powertrain network segment (PT segment). To ensure the security of the vehicle communication system, SecOC modules are deployed in the HUT unit, T-box unit, and TCU unit. The SecOC modules deployed in the HUT unit, T-box unit, and TCU unit respectively verify the security of vehicle control messages transmitted to the HUT unit, T-box unit, and TCU unit.
[0046] Vehicle control messages are used to instruct specific ECUs in the vehicle to perform specific tasks. Specifically, they contain information instructing the receiving ECU to perform a certain operation. This information includes specific operation commands and parameters, allowing the receiving ECU to accurately determine what operation to perform and how to execute it. For example, when the driver depresses the brake pedal, the brake pedal module ECU generates a brake control message based on the pedal displacement. This brake control message instructs the vehicle's brake system ECU to adjust the brake pressure. There are many types of vehicle control messages, including those for lighting control, wiper control, mirror folding, window and door lock control, steering mode, braking control, and energy recovery control.
[0047] To verify the security of vehicle control messages transmitted to each ECU, the messages are first received by the SecOC module. After receiving the messages, the SecOC module verifies the security of the messages. The components of the vehicle control messages include: (1) a counter value / timestamp, which is used to ensure the freshness of the vehicle control messages; and (2) a message authentication code (MAC) value, which is used to verify the integrity of the messages. The security of the vehicle control message can be verified specifically as follows: the SecOC module parses the received vehicle control message and obtains the MAC value and counter value carried in the vehicle control message; the SecOC module uses the pre-shared key and encryption algorithm to recalculate the MAC value of the actual transmission content in the vehicle control message, compares the recalculated MAC value with the MAC value carried in the vehicle control message, and compares the latest counter value stored locally with the counter value carried in the vehicle control message. If the recalculated MAC value is consistent with the MAC value carried in the vehicle control message and the latest counter value stored locally is greater than the counter value carried in the vehicle control message, the security verification of the vehicle control message is considered to be passed. Otherwise, the vehicle The vehicle control message security verification fails, that is, when the MAC value recalculated by the SecOC module is inconsistent with the MAC value carried in the vehicle control message, and the latest counter value stored locally is greater than the counter value carried in the vehicle control message, or the MAC value recalculated by the SecOC module is consistent with the MAC value carried in the vehicle control message, but the latest counter value stored locally is less than or equal to the counter value carried in the vehicle control message, or the MAC value recalculated by the SecOC module is inconsistent with the MAC value carried in the vehicle control message and the latest counter value stored locally is less than or equal to the counter value carried in the vehicle control message, it is considered that the vehicle control message security verification fails.
[0048] S220 , when the security verification of the vehicle control message fails, the SecOC module obtains the task type of the target task carried in the vehicle control message.
[0049] In order to avoid the failure of security verification of the vehicle control message, which leads to the interruption of the vehicle function that depends on the vehicle control message that fails security verification, it is necessary to ensure that the vehicle function that depends on the target message and the vehicle control message that fails security verification are the same. Therefore, the task type of the target message needs to be the same as the task type of the vehicle control message that fails security verification. Therefore, the SecOC module needs to obtain the task type of the target task carried by the vehicle control message that fails security verification. When the SecOC module obtains the task type of the target task carried by the vehicle control message, it can obtain it from the components of the vehicle control message, where the components of the vehicle control message also include: (3) identifiers, which are used to distinguish different vehicle control message types or senders; (4) data segments, which contain the actual transmitted data, which may include task-related commands, parameters, etc. For example, when the SecOC module obtains the task type of the target task carried by the vehicle control message, it can pre-construct a mapping relationship between a preset vehicle control message identifier and a preset task type. When the security verification of the vehicle control message fails, the SecOC module analyzes the identifier of the vehicle control message that failed security verification, and in the pre-constructed mapping relationship between the preset vehicle control message identifier and the preset task type, determines the task type that matches the vehicle control message identifier that failed security verification, and determines the task type as the task type of the target task. Alternatively, when the SecOC module obtains the task type of the target task carried by the vehicle control message, it can parse the specific content of the data segment in the vehicle control message that failed security verification, find the task code corresponding to the specific content of the data segment, and determine the task type of the target task based on the task code.
[0050] S230, the SecOC module generates a target message according to the task type, and the target message is used to instruct the target execution unit in the vehicle to execute the target task.
[0051] After determining the task type of the target task, the SecOC module generates a target message according to the task type. This can be done by consulting the vehicle's communication protocol (such as a structured file for defining CAN (Controller Area Network) messages, a file for describing the design of an automotive electronic system, or a communication matrix) based on the task type to determine the message identifier, data segment (including the length, byte arrangement, and meaning of the target message's data segment), and verification mechanism (such as a counter value and MAC value, etc.) of the target message, and determining the task type as the message identifier; constructing the data segment of the target message byte by byte based on the task type and the communication protocol. When constructing the data segment of the target message, the target task to be executed by the target execution unit in the vehicle can be determined according to the task type, and the specific content of the data segment can be determined according to the target task to be executed by the target execution unit. The specific content is matched with the byte meaning in the data segment to obtain the data segment of the target message; a verification value of the data segment is calculated to obtain the verification mechanism of the target message; and the SecOC module combines the message identifier, data segment, and verification mechanism in the order specified by the communication protocol to form a complete message, thereby obtaining the target message.
[0052] Alternatively, the SecOC module parses the vehicle control message that fails security verification, obtains the message identifier, data segment and verification mechanism of the vehicle control message that fails security verification, and the SecOC module determines the message identifier, data segment and verification mechanism of the vehicle control message that fails security verification as the message identifier, data segment and verification mechanism of the target message, and determines the task type as the message identifier; the SecOC module determines the target task to be executed by the target execution unit in the instructed vehicle according to the task type, and the SecOC module determines the specific content of the data segment according to the target task to be executed by the target execution unit, matches the specific content with the byte meaning in the data segment, and obtains the data segment of the target message; the SecOC module calculates the verification value of the data segment and obtains the verification mechanism of the target message; the SecOC module combines the message identifier, data segment and verification mechanism in the order in the vehicle control message that fails security verification to form a complete message and obtain the target message.
[0053] S240: The SecOC module sends the target message to the target execution unit, so that the target execution unit executes the target task according to the target message.
[0054] After generating the target message, the SecOC module sends the generated target message to the target execution unit, where the target execution unit is the ECU that receives the vehicle control message that fails security verification; the ECU performs corresponding operations according to the preset logic corresponding to the target message, so that the vehicle functions that rely on the execution of the target message can operate normally, and further the vehicle functions that rely on the execution of the security verification failure message can operate normally, thus achieving stable operation of the vehicle under security threats.
[0055] The vehicle control method provided by this embodiment verifies the security of the received vehicle control message, and obtains the task type of the target task carried by the vehicle control message when the security verification of the vehicle control message fails; generates a target message according to the task type, and the target message is used to instruct the target execution unit in the vehicle to execute the target task. The technical solution makes the task type of the target message the same as the task type of the vehicle control message that fails the security verification, thereby ensuring that the vehicle function that depends on the target message to be executed is the same as the vehicle function that depends on the vehicle control message that fails the security verification. By sending the target message to the target execution unit, the target execution unit is caused to execute the target task according to the target task type. The technical solution for executing the target task through a message sends the target message that is the same as the vehicle function that is executed by the vehicle control message due to the failure of safety verification to the target execution unit, so that the target execution unit executes the target task according to the target message, ensuring that the vehicle function that is executed by the vehicle control message due to the failure of safety verification runs normally and is not interrupted due to the failure of vehicle control message verification. This method can enable the vehicle function that is executed by the vehicle control message due to the failure of safety verification to run normally, avoids the vehicle function that is executed by the vehicle control message due to the failure of safety verification to be interrupted, ensures the stable operation of the vehicle under security threats, improves the safety of vehicle communication and driving, and enhances the user experience.
[0056] In one possible implementation, the SecOC module generates a target message based on the task type, including:
[0057] The SecOC module obtains vehicle driving data related to the mission type;
[0058] The SecOC module determines the target message based on the vehicle driving data.
[0059] The vehicle driving data related to the task type is: vehicle operating status data and environmental data that can affect the vehicle function. The vehicle driving data related to the task type includes but is not limited to the vehicle's speed, acceleration, position and other operating status information, as well as weather conditions, road conditions and other environmental information. The vehicle driving data related to the task type can adjust or limit the behavior of the vehicle functions that rely on the vehicle control message execution to ensure that the vehicle operates as expected. Different vehicle driving data related to the task type will result in different behaviors of the vehicle functions that rely on the vehicle control message execution. When obtaining vehicle driving data related to the task type, a mapping relationship between a preset task type and a preset vehicle driving data type related to the task type can be pre-constructed, as shown in Table 1. Table 1 shows an example of a mapping relationship between some preset task types and preset vehicle driving data types related to the task type:
[0060] Table 1
[0061]
[0062]
[0063] After determining the task type of the vehicle control message that has failed the security verification, the SecOC module determines the vehicle driving data type corresponding to the task type based on the mapping relationship between the preset task type and the preset vehicle driving data related to the task type. After determining the vehicle driving data type corresponding to the task type, the SecOC module can read the vehicle driving data corresponding to each vehicle driving data type from the sensor corresponding to each vehicle driving data type corresponding to the task type, wherein the vehicle driving data related to the task type can be the current vehicle driving data. According to the current vehicle driving data and the task type, the data segment of the target message is determined, and then the target message is determined. The vehicle driving data related to the task type can also be historical vehicle driving data. The SecOC module predicts the vehicle driving data based on the historical vehicle driving data, and determines the data segment of the target message based on the predicted vehicle driving data and the task type, and then the target message is determined. For example, referring to Table 1 above, if the task type of the vehicle control message that failed safety verification is braking, the vehicle driving data types related to braking are vehicle speed, relative speed of the forward obstacle, and brake pedal opening. The current vehicle speed, relative speed of the forward obstacle, and current brake pedal opening are obtained, and a target message is generated based on these. If the task type of the vehicle control message that failed safety verification is shifting, the vehicle driving data types related to shifting are vehicle speed and engine speed. The current vehicle speed and current engine speed are obtained, and a target message is generated based on these current vehicle speed and current engine speed.
[0064] By obtaining vehicle driving data related to the task type and determining the target message based on the vehicle driving data, the matching degree between the target message and the vehicle function execution can be improved, and the sending of target messages containing erroneous tasks in inappropriate scenarios can be avoided, thereby optimizing the vehicle's driving safety and reliability and providing more efficient protection for the driving experience.
[0065] In one possible implementation, the SecOC module determines the target message based on vehicle driving data, including:
[0066] The SecOC module obtains the preset vehicle control message corresponding to the task type and the vehicle driving data from the mapping relationship between the preset task type, the preset vehicle driving data and the preset vehicle control message, and obtains the target message.
[0067] In order to improve the overall performance of the vehicle and enhance the ability to cope with complex and changeable driving conditions, different vehicle control messages can be pre-set for different vehicle driving data under the same task type, wherein the task type in each vehicle control message is different, and the preset logic corresponding to different task types is different. The target execution unit performs different operations when executing different vehicle control messages. The SecOC module determines the target message through the task type and vehicle driving data, which can make the target execution unit in the vehicle perform different operations when executing different vehicle control messages, thereby making the executed operations more compatible with the current vehicle driving state, so that the vehicle functions that rely on the execution of vehicle control messages can adapt to various driving conditions more flexibly, which not only optimizes the vehicle's operational response, but also improves the safety and stability of driving. As shown in Table 2, Table 2 shows an example of the mapping relationship between some preset task types, preset vehicle driving data, and preset vehicle control messages provided in an embodiment of the present application:
[0068] Table 2
[0069]
[0070] After the SecOC module obtains the task type and vehicle driving data, it determines the vehicle control message corresponding to the task type and vehicle driving data in the mapping relationship among the preset task type, preset vehicle driving data, and preset vehicle control message shown in Table 2, and determines the vehicle control message as the target message. For example, referring to Table 2 above, when the task type is braking, if the acquired vehicle speed is equal to vehicle speed V1, the acquired relative speed of the front obstacle is equal to the relative speed a2 of the front obstacle, and the acquired brake pedal opening is equal to the brake pedal opening b3, then the target message is vehicle control message 1; if the acquired vehicle speed is equal to vehicle speed V2, the acquired relative speed of the front obstacle is equal to the relative speed a3 of the front obstacle, and the acquired brake pedal opening is equal to the brake pedal opening b1, then the target message is vehicle control message 2; if the acquired vehicle speed is equal to vehicle speed V3, the acquired relative speed of the front obstacle is equal to the relative speed a2 of the front obstacle, and the acquired brake pedal opening is equal to the brake pedal opening b2, then the target message is vehicle control message 3. When the task type is gear shifting, the preset vehicle control message corresponding to vehicle speed V4 and engine speed c1 is vehicle control message 4, and the preset vehicle control message corresponding to vehicle speed V5 and engine speed c2 is vehicle control message 5. If the acquired vehicle speed is equal to vehicle speed V4 and the acquired engine speed is equal to engine speed c1, then the target message is vehicle control message 4; if the acquired vehicle speed is equal to vehicle speed V5 and the acquired engine speed is equal to engine speed c2, then the target message is vehicle control message 5. The task in vehicle control message 4 can be shifting the gear to park, and the task in vehicle control message 5 can be shifting the gear to drive. If the acquired vehicle speed and engine speed are both 0 and last for more than 2 minutes, then vehicle control message 4 can be used as the target message; if the acquired vehicle speed and engine speed are both greater than 0, then vehicle control message 5 can be used as the target message.
[0071] Through the task type and vehicle driving data, the target message is determined from the mapping relationship between the preset task type, the preset vehicle driving data and the preset vehicle control message. This not only shortens the time required to generate the target message, but also helps the target execution unit to complete the corresponding operation more efficiently, thereby enhancing the continuity of vehicle functions and improving the response speed and reliability of the system while ensuring driving safety.
[0072] In one possible implementation, the SecOC module determines the target message based on vehicle driving data, including:
[0073] Using the vehicle driving data to update the data segment in the vehicle control message to obtain an updated vehicle control message;
[0074] The updated vehicle control message is used as the target message.
[0075] If a vehicle control message fails security verification, the SecOC module parses the security-verification-failed vehicle control message to obtain its message identifier, data segment, and verification mechanism. The module then predicts the operation to be performed by the target execution unit based on the task type and vehicle driving data. The module then determines the task type in the target message based on the operation to be performed by the target execution unit. The module then determines a new data segment based on the task type in the target message and replaces the original data segment in the security-verification-failed vehicle control message with the new data segment to obtain the target message. Specifically, the module updates the actual transmission data in the security-verification-failed vehicle control message based on the task type and vehicle driving data, ensuring a better match between the commands and parameters in the vehicle control message and the vehicle driving data, thereby improving control accuracy and response speed.
[0076] By updating the data segments in the vehicle control message through vehicle driving data, an updated vehicle control message is obtained. The updated vehicle control message is used as the target message. This not only makes the target message closer to actual needs, but also reduces the complexity of data processing and the possibility of errors through local updates, thereby improving the overall stability and reliability of the system.
[0077] In one possible implementation, the SecOC module verifies the security of vehicle control messages, including:
[0078] The SecOC module detects whether the vehicle control message carries a security verification identifier;
[0079] If so, the SecOC module verifies the security of the vehicle control message.
[0080] Vehicle control messages that require the SecOC module to perform security verification generally carry a corresponding security verification identifier, where the security verification identifier is a signal indicating that the vehicle control message has been securely processed, such as a SecOC signal, that is, the vehicle control message includes a counter value and a MAC value. Based on this, after the SecOC module receives the vehicle control message, it first determines whether the vehicle control message carries a security verification identifier. If it is determined that the vehicle control message carries a security verification identifier, the security of the vehicle control message is verified. If it is determined that the vehicle control message does not carry a security verification identifier, the vehicle control message is directly transmitted to the target execution unit, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message. When determining whether the vehicle control message carries a security verification identifier, it can be determined whether the vehicle control message carries a SecOC signal. Specifically, it can be: obtaining the fields of the received vehicle control message, and detecting whether the fields of the vehicle control message contain fields carrying SecOC-related data (such as counter values, MAC values). If the fields of the vehicle control message contain fields carrying SecOC-related data, it is determined that the vehicle control message carries a SecOC signal, indicating that the vehicle control message needs to be security verified. Therefore, the security of the vehicle control message is verified through the SecOC module. If the security verification of the vehicle control message passes, the vehicle control message is sent to the target execution unit corresponding to the vehicle control message, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message. If the security verification of the vehicle control message fails, the above S120 to S140 are executed. If the field of the vehicle control message does not contain a field carrying SecOC-related data, it is determined that the vehicle control message does not carry a SecOC signal, indicating that the vehicle control message does not require security verification. Therefore, the vehicle control message is directly transmitted to the target execution unit, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message.
[0081] By detecting whether the vehicle control message carries a security verification identifier, it is possible to quickly distinguish between vehicle control messages that require security verification and vehicle control messages that do not require security verification. Only when the vehicle control message carries a security verification identifier is the security of the vehicle control message verified, which can save computing resources, reduce processing delays, and thus improve communication efficiency.
[0082] In a possible implementation, the method further includes:
[0083] If the security verification of the vehicle control message fails, the SecOC module verifies the reliability of the vehicle control message;
[0084] When the reliability verification of the vehicle control message passes, the SecOC module executes the step of obtaining the task type of the target task carried in the vehicle control message.
[0085] When the security verification of the vehicle control message fails, the SecOC module verifies the reliability of the vehicle control message. When verifying the reliability of the vehicle control message, the reliability check value of the received vehicle control message is calculated, and the calculated reliability check value is compared with the reliability check value carried in the vehicle control message. If the calculated reliability check value is consistent with the reliability check value carried in the vehicle control message, it means that the reliability verification of the vehicle control message has passed, and the arrangement order of the data segments in the vehicle control message is correct, that is, it means that the arrangement order of the data segments in the vehicle control message has not changed, and then it can be determined that the task type of the vehicle control message has not changed. When the reliability verification of the vehicle control message passes, the SecOC module obtains the task type of the target task carried by the vehicle control message, generates a target message according to the task type, and sends the target message to the target execution unit, so that the target execution unit executes the target task according to the target message; ensure that the task type of the target message is the task type of the vehicle control message that fails the security verification. If the calculated reliability check value is inconsistent with the reliability check value carried in the vehicle control message, it means that the reliability verification of the vehicle control message has failed, which means that during the transmission of the vehicle control message, the arrangement order of the data segments in the vehicle control message has changed, resulting in a change in the task type of the vehicle control message. If the target message is generated according to the task type corresponding to the vehicle control message that has failed the reliability verification, it may cause the vehicle function that depends on the target message to be different from the vehicle function that depends on the vehicle control message that has failed the safety verification to be executed. Therefore, if the vehicle control message fails the safety verification and the reliability verification, the vehicle control message can be retransmitted.
[0086] By verifying the reliability of the vehicle control message when the security verification of the vehicle control message fails, it is possible to determine whether the arrangement order of the data segments in the vehicle control message is correct. When the reliability verification of the vehicle control message passes, the step of obtaining the task type of the target task carried by the vehicle control message is executed to ensure that the arrangement order of the data segments in the vehicle control message is correct, and further ensure that the task type of the vehicle control message has not changed, so that the vehicle function that depends on the vehicle control message that fails the security verification is the expected vehicle function, and the normal operation of the vehicle function that depends on the vehicle control message that fails the security verification is achieved.
[0087] In one possible implementation, the vehicle's in-vehicle network includes multiple network segments, and each network segment is deployed with a secure in-vehicle communication module.
[0088] Driven by intelligent connected technology, the number of ECU nodes in the vehicle architecture has increased dramatically. The surge in the number of ECU nodes has led to an increase in the complexity of the vehicle network topology. By deploying the SecOC module in each ECU and verifying the security of the vehicle control messages transmitted to each ECU, the deployment of SecOC modules has increased dramatically, which has brought a burden to the electrical system of the entire vehicle. In addition, each ECU needs to run the SecOC module, which increases the computing and storage resource requirements of each ECU and leads to excessive resource consumption.
[0089] Based on the above problems, in this embodiment, the SecOC module is separated from each ECU and only one SecOC module is deployed on each network segment. This can be understood as replacing one ECU in each network segment with a SecOC module. For example, see Figure 3 , separate the SecOC module from the HUT unit and T-BOX unit and set it up in the SC network segment. Figure 3 At point A of the SC network segment shown, the SecOC module at point A on the SC network segment verifies the security of all vehicle control messages transmitted to the SC network segment, that is, the SecOC module at point A on the SC network segment verifies all vehicle control messages transmitted to the HUT unit and the T-BOX unit. Each vehicle control message sent to the HUT unit and the T-BOX unit will first pass through the SecOC module. The SecOC module first detects whether the vehicle control message carries a SecOC signal. When the vehicle control message does not carry a SecOC signal, the vehicle control message is directly sent to the target execution unit, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message. When the vehicle control message carries a SecOC signal, the security of the vehicle control message is verified. When the security verification of the vehicle control message passes, the vehicle control message is directly sent to the target execution unit, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message. When the security verification of the vehicle control message fails, the above S110-S140 are executed. Separate the SecOC module from the TCU unit and deploy it on the PT network segment. Figure 3At B of the PT network segment shown, the SecOC module at position B on the PT network segment verifies the security of all vehicle control messages transmitted to the PT network segment, that is, the SecOC module at position B on the PT network segment verifies all vehicle control messages transmitted to the TCU unit. Each vehicle control message sent to the TCU unit will first pass through the SecOC module. The SecOC module first detects whether the vehicle control message carries a SecOC signal. When the vehicle control message does not carry a SecOC signal, the vehicle control message is directly sent to the target execution unit, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message. When the vehicle control message carries a SecOC signal, the security of the vehicle control message is verified. When the security verification of the vehicle control message passes, the vehicle control message is directly sent to the target execution unit, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message. When the security verification of the vehicle control message fails, the above S210-S240 are executed.
[0090] By deploying a secure in-vehicle communication module in each network segment and separating the secure in-vehicle communication module from each electronic control unit, the deployment of SecOC modules is reduced, thereby reducing the burden on the vehicle's electrical system and the computing and storage resource requirements of each ECU, reducing resource consumption, saving costs, and improving the overall performance of the vehicle's electrical system.
[0091] For example, a SecOC module is deployed on each network segment of the vehicle's electrical and electronic architecture. Each SecOC module first receives vehicle control messages transmitted to all ECUs in the corresponding network segment. After receiving the vehicle control message, it first detects whether the vehicle control message carries a SecOC signal. If the vehicle control message does not carry a SecOC signal, the vehicle control message is directly transmitted to the target execution unit, which then executes the task corresponding to the vehicle control message based on the vehicle control message. If the vehicle control message carries a SecOC signal, the security of the received vehicle control message is verified. This security verification can be performed by comparing the MAC value carried by the vehicle control message with the recalculated MAC value of the vehicle control message and comparing the counter value carried by the vehicle control message with the latest locally stored counter value. If the MAC value carried by the vehicle control message is consistent with the recalculated MAC value of the vehicle control message, and the latest locally stored counter value is greater than the counter value carried by the vehicle control message, the security verification of the vehicle control message passes. Otherwise, the security verification of the vehicle control message fails. When the security check of the vehicle control message passes, the vehicle control message is directly transmitted to the target execution unit, so that the target execution unit executes the task corresponding to the vehicle control message according to the vehicle control message. When the security check of the vehicle control message fails, the reliability of the vehicle control message is verified. When verifying the reliability of the vehicle control message, the reliability check value carried by the vehicle control message and the recalculated reliability check value can be compared. If the reliability check value carried by the vehicle control message is consistent with the recalculated reliability check value, it means that the reliability verification of the vehicle control message is passed, and the task type of the target task carried by the vehicle control message and the vehicle driving data related to the task type are obtained. From the mapping relationship between the preset task type, the preset vehicle driving data and the preset vehicle control message, the preset vehicle control message corresponding to the task type and the vehicle driving data is obtained to obtain the target message. The target message is used to instruct the target execution unit in the vehicle to execute the target task. The target message is sent to the target execution unit. The target execution unit performs corresponding operations according to the preset logic corresponding to the target message, so that the vehicle function that depends on the execution of the target message can operate normally, and then the vehicle function that depends on the execution of the message that failed the security verification can operate normally, thereby realizing stable operation of the vehicle under security threats.That is, by verifying the security of the received vehicle control message, when the security verification of the vehicle control message fails, the task type of the target task carried by the vehicle control message is obtained; a target message is generated according to the task type, so that the task type of the target message is the same as the task type of the vehicle control message that fails the security verification, thereby ensuring that the vehicle function that depends on the target message is the same as the vehicle function that depends on the vehicle control message that fails the security verification, and by sending the target message to the target execution unit, so that the target execution unit executes the target task according to the target message, and sending the target message that is the same as the vehicle function that depends on the vehicle control message that fails the security verification to the target execution unit, so that the target execution unit executes the target task according to the target message, ensuring that the vehicle function that depends on the vehicle control message that fails the security verification runs normally and is not interrupted due to the failure of the vehicle control message verification. This method can enable the vehicle function that depends on the vehicle control message that fails the security verification to run normally, avoids the vehicle function that depends on the vehicle control message that fails the security verification to be interrupted, ensures the stable operation of the vehicle under security threats, improves the safety of vehicle communication and driving, and enhances user experience.
[0092] The following are device embodiments of the present application, which can be used to execute method embodiments of the present application.
[0093] like Figure 4 As shown, Figure 4 A schematic structural diagram of a vehicle control device provided in an embodiment of the present application is shown.
[0094] For example, Figure 4 As shown, the apparatus 400 includes:
[0095] Verification module 401, for verifying the security of the vehicle control message when the vehicle control message is received;
[0096] An acquisition module 402 is configured to acquire a task type of a target task carried in the vehicle control message if the vehicle control message fails security verification;
[0097] A generating module 403 is configured to generate a target message according to the task type, wherein the target message includes instructions for a target execution unit in the vehicle to execute a target task;
[0098] The sending module 404 is configured to send the target message to the target execution unit so that the target execution unit executes the target task according to the target message.
[0099] In a possible implementation, the generating module 403 is further configured to:
[0100] Obtain vehicle driving data related to the task type;
[0101] Determine the target message based on vehicle driving data.
[0102] In a possible implementation, the generating module 403 is further configured to:
[0103] From the mapping relationship among the preset task type, the preset vehicle driving data and the preset vehicle control message, the preset vehicle control message corresponding to the task type and the vehicle driving data is obtained to obtain the target message.
[0104] In a possible implementation, the generating module 403 is further configured to:
[0105] Using the vehicle driving data to update the data segment in the vehicle control message to obtain an updated vehicle control message;
[0106] The updated vehicle control message is used as the target message.
[0107] In one possible implementation, the verification module 401 is further configured to:
[0108] Check whether the vehicle control message carries a security verification mark;
[0109] If so, verify the security of the vehicle control message.
[0110] In a possible implementation, the apparatus 400 further includes:
[0111] A reliability verification module, used to verify the reliability of the vehicle control message when the vehicle control message fails the security verification;
[0112] When the reliability verification of the vehicle control message passes, a step of obtaining the task type of the target task carried in the vehicle control message is performed.
[0113] In one possible implementation, the vehicle's in-vehicle network includes multiple network segments, and each network segment is deployed with a secure in-vehicle communication module.
[0114] It should be noted that the vehicle control device provided in the above embodiment only uses the division of the above-mentioned functional modules as an example when executing the vehicle control method. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0115] In addition, the vehicle control device and vehicle control method embodiments provided in the above embodiments belong to the same concept. Therefore, for details not disclosed in the device embodiments of this specification, please refer to the above-mentioned vehicle control method embodiments of this specification, and no further details will be given here.
[0116] like Figure 5 As shown, Figure 5 A structural schematic diagram of a vehicle provided in an embodiment of the present application is shown.
[0117] For example, Figure 5 As shown, the vehicle 500 includes: a memory 501 and a processor 502, wherein the memory 501 stores an executable program code 5011, and the processor 502 is used to call and execute the executable program code 5011 to perform a vehicle control method.
[0118] In addition, an embodiment of the present application also protects a device, which may include a memory and a processor, wherein the memory stores executable program code, and the processor is used to call and execute the executable program code to perform a vehicle control method provided by an embodiment of the present application.
[0119] In this embodiment, the device can be divided into functional modules based on the above-described method examples. For example, each functional module can be mapped to a specific functional module, or two or more functions can be integrated into a single processing module. The integrated module can be implemented in hardware. It should be noted that the module division in this embodiment is illustrative and represents only a logical functional division. In actual implementation, other division methods may be used.
[0120] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0121] It should be understood that the device provided in this embodiment is used to execute the above-mentioned vehicle control method, and thus can achieve the same effect as the above-mentioned implementation method.
[0122] In the case of an integrated unit, the device may include a processing module and a storage module. When the device is used in a vehicle, the processing module may be used to control and manage the vehicle's movements, while the storage module may be used to support the vehicle's execution of relevant program codes.
[0123] The processing module may be a processor or controller that implements or executes the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processing system (DSP) and a microprocessor, and the storage module may be a memory.
[0124] In addition, the device provided in the embodiments of the present application can specifically be a chip, component or module, and the chip may include a connected processor and memory; wherein the memory is used to store instructions, and when the processor calls and executes the instructions, the chip can execute a vehicle control method provided in the above embodiment.
[0125] This embodiment also provides a computer-readable storage medium, which stores computer program code. When the computer program code runs on a computer, the computer executes the above-mentioned related method steps to implement a vehicle control method provided by the above embodiment.
[0126] This embodiment also provides a computer program product. When the computer program product is run on a computer, it enables the computer to execute the above-mentioned related steps to implement a vehicle control method provided by the above embodiment.
[0127] Among them, the device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0128] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0129] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0130] The above content is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A vehicle control method, characterized in that: Applied to a secure vehicle communication module, the method includes: Upon receiving a vehicle control message, verifying the security of the vehicle control message; If the security verification of the vehicle control message fails, obtaining the task type of the target task carried by the vehicle control message; Generate a target message according to the task type, wherein the target message is used to instruct a target execution unit in the vehicle to execute the target task; The target message is sent to the target execution unit, so that the target execution unit executes the target task according to the target message.
2. The method according to claim 1, characterized in that Generating a target message according to the task type includes: Acquiring vehicle driving data related to the task type; The target message is determined according to the vehicle driving data.
3. The method according to claim 2, characterized in that The determining the target message according to the vehicle driving data includes: From a mapping relationship among a preset task type, preset vehicle driving data and a preset vehicle control message, a preset vehicle control message corresponding to the task type and the vehicle driving data is obtained to obtain the target message.
4. The method according to claim 2, characterized in that The determining the target message according to the vehicle driving data includes: Using the vehicle driving data to update the data segment in the vehicle control message to obtain the updated vehicle control message; The updated vehicle control message is used as the target message.
5. The method according to claim 1, characterized in that The verifying the security of the vehicle control message includes: Detecting whether the vehicle control message carries a security verification identifier; If so, the security of the vehicle control message is verified.
6. The method according to claim 1, characterized in that The method further comprises: If the security verification of the vehicle control message fails, verifying the reliability of the vehicle control message; In a case where the reliability verification of the vehicle control message is passed, the step of obtaining the task type of the target task carried by the vehicle control message is performed.
7. The method according to any one of claims 1 to 6, characterized in that The vehicle's on-board network includes multiple network segments, and each network segment is deployed with a secure on-board communication module.
8. A vehicle control device, characterized in that: The device comprises: A verification module, configured to verify the security of a vehicle control message upon receipt of the vehicle control message; an acquisition module, configured to acquire a task type of a target task carried in the vehicle control message if the security verification of the vehicle control message fails; A generating module, configured to generate a target message according to the task type, wherein the target message is used to instruct a target execution unit in the vehicle to execute the target task; A sending module is used to send the target message to the target execution unit, so that the target execution unit executes the target task according to the target message.
9. A vehicle, characterized in that: The vehicle comprises: a memory for storing executable program code; A processor is configured to call and run the executable program code from the memory, so that the vehicle executes the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 7 is implemented.