Message transmission method and system in CAN bus, storage medium and automobile

By using encrypted signals, ID hopping, and random byte-filled configuration messages on the CAN bus, the information leakage problem caused by ECU plaintext transmission is solved, and high-security message transmission on the CAN bus is achieved.

CN120675829APending Publication Date: 2025-09-19ZERON AUTOMOBILE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510666987.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Multiple electronic control units (ECUs) in a car use plain text when transmitting messages on the CAN bus, resulting in a high risk of information leakage.

Method used

The master ECU is used to send configuration messages, which include encryption signals, ID jump signals, and random byte filling signals. Each slave ECU determines the corresponding rules based on these signals to generate encrypted messages, and uses the master ECU to detect whether the encrypted messages have been tampered with. If tampered with, the transmission rules are updated.

Benefits of technology

Through the combination of ID hopping, random byte filling and encryption, the security of the CAN bus is significantly improved, preventing illegal device intrusion and ensuring the security of message transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675829A_ABST
    Figure CN120675829A_ABST
Patent Text Reader

Abstract

The invention discloses a message transmission method and system in a CAN bus, a storage medium and an automobile, and belongs to the technical field of communication. Each slave ECU determines an encryption rule according to the encryption signal in the configuration message sent by the master ECU, determines an ID hopping rule according to the ID hopping signal, and determines a random byte filling rule according to the random byte filling signal; the first slave ECU generates an encrypted message according to a rule indicated by the configuration message, and sends the encrypted message to the CAN bus; the main ECU receives the encrypted message and detects whether the encrypted message is tampered or not according to the encryption rule and the ID hopping rule; and if it is determined that the encrypted message is tampered, a detection result is reported to a background, and a new configuration message is sent to each slave ECU. Through the combination of ID hopping, random byte filling and encryption detection, illegal equipment can be prevented from invading the CAN bus and interfering with the whole vehicle message, and the safety of the CAN bus is remarkably improved at extremely low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a message transmission method, system, storage medium and automobile in a CAN bus. Background Art

[0002] The Controller Area Network (CAN) bus is a serial communication protocol bus designed for real-time applications. It is one of the most widely used fieldbuses in the world. The CAN bus is used to communicate between various components in a car, replacing expensive and bulky wiring harnesses.

[0003] In related technologies, multiple electronic control units (ECUs) in a car usually transmit messages in plain text on the CAN bus, making it easy for attackers to monitor key data, leading to information leakage. Summary of the Invention

[0004] This application provides a method, system, storage medium, and vehicle for transmitting messages on a CAN bus, which are used to solve the problem of information leakage when multiple ECUs transmit messages using plain text on the CAN bus. The technical solution is as follows: According to a first aspect of the present application, a message transmission method in a CAN bus is provided, which is used in a control system including a CAN bus, a master electronic control unit (ECU), and a plurality of slave ECUs, the method comprising: The master ECU sends a configuration message to each slave ECU on the CAN bus, wherein the configuration message includes a configuration signal for transmitting the message within the current cycle, and the configuration signal includes at least an encryption signal, an identification ID jump signal, and a random byte filling signal; Each slave ECU receives the configuration message on the CAN bus, determines an encryption rule according to the encryption signal, determines an ID jump rule according to the ID jump signal, and determines a random byte filling rule according to the random byte filling signal; When the first slave ECU needs to send a message to the second slave ECU on the CAN bus, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message, and sends the encrypted message to the CAN bus; The master ECU receives the encrypted message on the CAN bus, and detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; If it is determined that the encrypted message has been tampered with, the master ECU reports the detection result to the background, and sends a new configuration message to each slave ECU on the CAN bus, so that each slave ECU transmits messages according to the new configuration message. In a possible implementation, the first slave ECU generates an encrypted message according to a rule indicated by the configuration message, including: The first slave ECU generates a message ID according to its own node ID and the ID jump rule; The first slave ECU combines the data to be transmitted and the random bytes into a data segment according to the random byte filling rule, and fills the message ID and the data segment into the message; The first slave ECU encrypts the message using the encryption rule to obtain an encrypted message. In a possible implementation, the method further includes: The second slave ECU receives the encrypted message on the CAN bus; The second slave ECU detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; If it is determined that the encrypted message has not been tampered with, the second slave ECU reads the data to be transmitted from the data segment according to the random byte filling rule. In a possible implementation, reading the data to be transmitted from the data segment according to the random byte filling rule includes: The second slave ECU determines a filling position of the random byte according to the random byte filling rule; The second slave ECU reads data at a position other than the filling position from the data segment. In a possible implementation, detecting whether the encrypted message has been tampered with according to the encryption rule and the ID hopping rule includes: Decrypting the encrypted message according to the decryption rule corresponding to the encryption rule; If the decryption is successful, the message ID is restored according to the ID jump rule. If the restored ID is a node ID of a slave ECU, it is determined that the encrypted message has not been tampered with; If the decryption fails, and / or if the recovered ID is not the node ID of any slave ECU, it is determined that the encrypted message has been tampered with. In a possible implementation, the method further includes: An encryption list, an ID jump list, and a random byte filling list are pre-configured in each slave ECU. The encryption list includes the correspondence between encryption signals and encryption rules, the ID jump list includes the correspondence between ID jump signals and ID jump rules, and the random byte filling list includes the correspondence between random byte filling signals and random byte filling rules. In a possible implementation, the master ECU sends a configuration message to each slave ECU on the CAN bus, including: After the car is powered on, the master ECU sends a configuration message to each slave ECU on the CAN bus. According to a second aspect of the present application, a control system is provided, comprising a CAN bus, a master electronic control unit ECU, and a plurality of slave ECUs; The master ECU is configured to send a configuration message to each slave ECU on the CAN bus, wherein the configuration message includes a configuration signal for transmitting the message within the current cycle, and the configuration signal includes at least an encryption signal, an identification ID jump signal, and a random byte filling signal; Each slave ECU is configured to receive the configuration message on the CAN bus, determine an encryption rule according to the encryption signal, determine an ID jump rule according to the ID jump signal, and determine a random byte filling rule according to the random byte filling signal; When the first slave ECU needs to send a message to the second slave ECU on the CAN bus, the first slave ECU is further configured to generate an encrypted message according to the rule indicated by the configuration message and send the encrypted message to the CAN bus; The master ECU is further configured to receive the encrypted message on the CAN bus and detect whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; If it is determined that the encrypted message has been tampered with, the master ECU is further configured to report the detection result to the background, and send a new configuration message to each slave ECU on the CAN bus, so that each slave ECU transmits messages according to the new configuration message. According to a third aspect of the present application, a computer-readable storage medium is provided, in which at least one instruction is stored. The at least one instruction is loaded and executed by a processor to implement the message transmission method in the CAN bus as described above. According to a fourth aspect of the present application, a car is provided, comprising the above-mentioned control system. The beneficial effects of the technical solution provided by this application include at least: The master ECU sends a configuration message to each slave ECU on the CAN bus. Each slave ECU determines the encryption rule according to the encryption signal in the configuration message, determines the ID jump rule according to the ID jump signal, and determines the random byte padding rule according to the random byte padding signal. Then, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message and sends the encrypted message to the CAN bus. The master ECU detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule. If it is determined that the encrypted message has been tampered with, the detection result is reported to the background, and a new configuration message is sent to each slave ECU on the CAN bus, so that each slave ECU transmits the message according to the new configuration message. In this way, the combination of ID jump, random byte padding and encryption detection can prevent illegal devices from invading the CAN bus and interfering with the vehicle message, significantly improving the security of the CAN bus at a very low cost. BRIEF DESCRIPTION OF THE DRAWINGS

[0005] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0006] Figure 1 is a schematic diagram of a control system provided by an embodiment of the present application; Figure 2 This is a flowchart of a message transmission method in a CAN bus provided by an embodiment of the present application; Figure 3 This is a flowchart of a message transmission method in a CAN bus provided by an embodiment of the present application; Figure 4 This is a structural block diagram of a control system provided by an embodiment of the present application. DETAILED DESCRIPTION

[0007] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings. The control system in a car consists of at least one CAN bus and multiple ECUs, each of which transmits messages on the CAN bus. To improve the security of message transmission and prevent the CAN bus from being compromised, one of these ECUs can be selected as the master ECU, with the remaining ECUs acting as slaves. This allows the master ECU to regularly update its message transmission rules, and the slave ECUs to transmit messages on the CAN bus according to these rules. The master ECU can also detect tampering with messages transmitted on the CAN bus based on the specified transmission rules. If so, it alerts the backend for further action.

[0008] In one example, a control system includes CAN1, CAN2, a master ECU, and six slave ECUs: ECU1, ECU2, ECU3, ECU4, ECU5, and ECU6. ECU1, ECU2, and ECU3 are connected to the master ECU via CAN1, while ECU4, ECU5, and ECU6 are connected to the master ECU via CAN2. The transmission rules used on CAN1 and CAN2 can be the same or different, and the update cycles for the transmission rules on CAN1 and CAN2 can be the same or different. like Figure 2 As shown, it shows a method flow chart of a message transmission method in a CAN bus provided by an embodiment of the present application. The message transmission method in the CAN bus can be applied in automobiles. The message transmission method in the CAN bus may include: In step 201 , the master ECU sends a configuration message to each slave ECU on the CAN bus. The configuration message includes a configuration signal for message transmission in this cycle. The configuration signal includes at least an encryption signal, an ID jump signal, and a random byte filling signal.

[0009] Under specific triggering conditions, the master ECU generates a configuration message and sends it to the CAN bus. The triggering conditions described here can be set based on actual business needs. For example, the triggering conditions could be vehicle power-up, key exchange initiation, or the arrival of an update cycle, etc., though these are not limited in this embodiment.

[0010] The master ECU is pre-configured with an encryption list, an ID jump list, and a random byte padding list. The encryption list includes the correspondence between encryption signals and encryption rules, the ID jump list includes the correspondence between ID jump signals and ID jump rules, and the random byte padding list includes the correspondence between random byte padding signals and random byte padding rules. The encryption rule may be encryption using at least one encryption algorithm, for example, one encryption rule uses a symmetric encryption algorithm, another encryption rule uses an asymmetric encryption algorithm, and so on. The ID jump rule may be a method for transforming the ID of the slave ECU sending the message, for example, increasing the value at a predetermined position in the ID by a predetermined value, which may be a sequentially increasing value, or selecting the i-th ID from a pre-configured ID sequence, and so on. The random byte padding rule may indicate the padding position of the random number generated each time in the data segment, for example, the padding position is the last two bytes in the data segment, and so on.

[0011] When generating a configuration message, the main ECU can select an encryption signal from the encryption list, select an ID jump signal from the ID jump list, and select a random byte filling signal from the random byte filling list, and fill these three signals into the message according to their respective positions to obtain the configuration message.

[0012] In step 202 , each slave ECU receives a configuration message on the CAN bus, determines an encryption rule according to the encryption signal, determines an ID jump rule according to the ID jump signal, and determines a random byte filling rule according to the random byte filling signal.

[0013] Each slave ECU can receive the configuration message sent by the master ECU on the CAN bus, and then determine the encryption rule according to the encryption signal, determine the ID jump rule according to the ID jump signal, and determine the random byte filling rule according to the random byte filling signal.

[0014] Each slave ECU can transmit messages on the CAN bus. In this embodiment, the slave ECU that needs to send messages is called the first slave ECU, and the at least one slave ECU that needs to receive messages is called the second ECU.

[0015] Step 203: When the first slave ECU needs to send a message to the second slave ECU on the CAN bus, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message and sends the encrypted message to the CAN bus.

[0016] The first slave ECU may generate an encrypted message according to the determined encryption rule, ID jump rule, random byte filling rule and the data to be transmitted, and send the encrypted message to the CAN bus. The specific method for generating the encrypted message is described below.

[0017] The master ECU and each slave ECU can monitor encrypted messages transmitted on the CAN bus. Each slave ECU can detect whether the encrypted message is addressed to it. If it determines that the encrypted message is addressed to it, it continues to process the encrypted message. If it determines that the encrypted message is not addressed to it, it discards the encrypted message. The master ECU can then make a risk assessment based on the encrypted message, executing steps 204-205.

[0018] In step 204 , the master ECU receives the encrypted message on the CAN bus and detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule.

[0019] The main ECU may detect the encrypted message according to the previously selected encryption rule and ID jump rule; if the detection result is that the encrypted message has been tampered with, step 205 is executed; if the detection result is that the encrypted message has not been tampered with, step 204 is continued.

[0020] In step 205 , if it is determined that the encrypted message has been tampered with, the master ECU reports the detection result to the backend and sends a new configuration message to each slave ECU on the CAN bus, so that each slave ECU transmits messages according to the new configuration message.

[0021] After the main ECU determines that the encrypted message has been tampered with, it determines that the CAN bus is at risk of being invaded and can report the detection results to the background to remind the background personnel to handle it.

[0022] In order to improve the security of message transmission, the master ECU can regenerate a new configuration message and notify each slave ECU to transmit the message according to the transmission strategy specified in the new configuration message.

[0023] To sum up, the message transmission method in the CAN bus provided by the embodiment of the present application is that the master ECU sends a configuration message to each slave ECU on the CAN bus, and each slave ECU determines the encryption rule according to the encryption signal in the configuration message, determines the ID jump rule according to the ID jump signal, and determines the random byte filling rule according to the random byte filling signal; then, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message, and sends the encrypted message to the CAN bus; the master ECU detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; if it is determined that the encrypted message has been tampered with, the detection result is reported to the background, and a new configuration message is sent to each slave ECU on the CAN bus, so that each slave ECU transmits the message according to the new configuration message, thereby preventing illegal devices from invading the CAN bus and interfering with the vehicle message through the combination of ID jump, random byte filling and encryption detection, thereby significantly improving the security of the CAN bus at an extremely low cost. like Figure 3 FIG2 shows a flowchart of a message transmission method in a CAN bus provided by an embodiment of the present application. The message transmission method in the CAN bus can be applied to automobiles. The message transmission method in the CAN bus can include: In step 301, the master ECU sends a configuration message to each slave ECU on the CAN bus. The configuration message includes a configuration signal for message transmission in this cycle. The configuration signal includes at least an encryption signal, an ID jump signal, and a random byte filling signal.

[0024] Under specific triggering conditions, the master ECU generates a configuration message and sends it to the CAN bus. The triggering conditions can be set based on actual business needs. For example, the triggering condition could be the vehicle power-up, whereupon the master ECU sends a configuration message to each slave ECU on the CAN bus. Alternatively, the triggering condition could be the initiation of a key exchange, the arrival of an update cycle, and so on, all of which are not limited in this embodiment.

[0025] The master ECU is pre-configured with an encryption list, an ID jump list, and a random byte padding list. The encryption list includes the correspondence between encryption signals and encryption rules, the ID jump list includes the correspondence between ID jump signals and ID jump rules, and the random byte padding list includes the correspondence between random byte padding signals and random byte padding rules. The encryption rule may be encryption using at least one encryption algorithm, for example, one encryption rule uses a symmetric encryption algorithm, another encryption rule uses an asymmetric encryption algorithm, and so on. The ID jump rule may be a method for transforming the ID of the slave ECU sending the message, for example, increasing the value at a predetermined position in the ID by a predetermined value, which may be a sequentially increasing value, or selecting the i-th ID from a pre-configured ID sequence, and so on. The random byte padding rule may indicate the padding position of the random number generated each time in the data segment, for example, the padding position is the last two bytes in the data segment, and so on.

[0026] When generating a configuration message, the main ECU can select an encryption signal from the encryption list, select an ID jump signal from the ID jump list, and select a random byte filling signal from the random byte filling list, and fill these three signals into the message according to their respective positions to obtain the configuration message.

[0027] In step 302 , each slave ECU receives a configuration message on the CAN bus, determines an encryption rule according to the encryption signal, determines an ID jump rule according to the ID jump signal, and determines a random byte filling rule according to the random byte filling signal.

[0028] In this embodiment, an encryption list, ID jump list, and random byte padding list are preconfigured in each slave ECU. The encryption list includes the correspondence between encryption signals and encryption rules, the ID jump list includes the correspondence between ID jump signals and ID jump rules, and the random byte padding list includes the correspondence between random byte padding signals and random byte padding rules. The encryption list, ID jump list, and random byte padding list in the slave ECU are consistent with those in the master ECU.

[0029] Each slave ECU can receive the configuration message sent by the master ECU on the CAN bus, and then search for the encryption rule corresponding to the encryption signal in the encryption list, search for the ID jump rule corresponding to the ID jump signal in the ID jump list, and search for the random byte filling rule corresponding to the random byte filling signal in the random byte filling list.

[0030] Each slave ECU can transmit messages on the CAN bus. In this embodiment, the slave ECU that needs to send messages is called the first slave ECU, and the at least one slave ECU that needs to receive messages is called the second ECU.

[0031] Step 303: When the first slave ECU needs to send a message to the second slave ECU on the CAN bus, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message and sends the encrypted message to the CAN bus.

[0032] The first slave ECU may generate an encrypted message according to the determined encryption rule, ID jump rule, random byte filling rule and the data to be transmitted, and send the encrypted message to the CAN bus.

[0033] Specifically, the first slave ECU generates an encrypted message according to the rules indicated by the configuration message, which may include the following steps: (1) The first slave ECU generates a message ID based on its own node ID and ID jump rules.

[0034] Assume that the ID jump rule is to increase the value of the third-to-last digit in the node ID by 1, and the node ID of the first slave ECU is 0x18FFF127, then the message ID of the first slave ECU in this cycle is 0x18FFF227, the message ID of the first slave ECU in the next cycle is 0x18FFF327, the message ID of the first slave ECU in the next cycle is 0x18FFF427, and so on.

[0035] (2) The first slave ECU forms a data segment with the data to be transmitted and random bytes according to the random byte filling rule, and fills the message ID and data segment into the message.

[0036] Assume that the random byte padding rule is that the random number is padded to the last two bytes of the data segment, and the data to be transmitted is [0x12, 0x34, 0x56, 0x78, 0x9A, 0xBC], and the random number generated this time is [0xDE, 0xF0], then the generated data segment is [0x12, 0x34, 0x56, 0x78, 0x9A, 0xBC, 0xDE,0xF0].

[0037] First, the slave ECU fills the message ID and data segment into corresponding positions to obtain a message.

[0038] (3) The first slave ECU encrypts the message using encryption rules to obtain an encrypted message.

[0039] First, the slave ECU encrypts the message using an encryption algorithm corresponding to the encryption rule to obtain an encrypted message.

[0040] The master ECU and each slave ECU can monitor the encrypted messages transmitted on the CAN bus. The master ECU executes steps 304-305 to process the encrypted messages. Each slave ECU first executes step 306 to receive the encrypted message and detects whether the encrypted message is sent to itself. If it is determined that the encrypted message is sent to itself, it executes steps 307-308 to process the encrypted message. If it is determined that the encrypted message is not sent to itself, it discards the encrypted message.

[0041] In step 304 , the master ECU receives the encrypted message on the CAN bus and detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule.

[0042] Specifically, detecting whether the encrypted message has been tampered with according to the encryption rules and the ID jumping rules may include: decrypting the encrypted message according to the decryption rules corresponding to the encryption rules; if the decryption is successful, restoring the message ID according to the ID jumping rules, and if the restored ID is a node ID of a slave ECU, it is determined that the encrypted message has not been tampered with; if the decryption fails, and / or if the restored ID is not a node ID of any slave ECU, it is determined that the encrypted message has been tampered with.

[0043] If the detection result shows that the encrypted message has been tampered with, step 305 is executed; if the detection result shows that the encrypted message has not been tampered with, step 304 is continued to be executed.

[0044] In step 305 , if it is determined that the encrypted message has been tampered with, the master ECU reports the detection result to the backend and sends a new configuration message to each slave ECU on the CAN bus, so that each slave ECU transmits messages according to the new configuration message.

[0045] After the main ECU determines that the encrypted message has been tampered with, it determines that the CAN bus is at risk of being invaded and can report the detection results to the background to remind the background personnel to handle it.

[0046] In order to improve the security of message transmission, the master ECU can regenerate a new configuration message and notify each slave ECU to transmit the message according to the transmission strategy specified in the new configuration message.

[0047] Step 306: The second slave ECU receives the encrypted message on the CAN bus.

[0048] Step 307: The second slave ECU detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule.

[0049] Specifically, detecting whether the encrypted message has been tampered with according to the encryption rules and the ID jumping rules may include: decrypting the encrypted message according to the decryption rules corresponding to the encryption rules; if the decryption is successful, restoring the message ID according to the ID jumping rules, and if the restored ID is a node ID of a slave ECU, it is determined that the encrypted message has not been tampered with; if the decryption fails, and / or if the restored ID is not a node ID of any slave ECU, it is determined that the encrypted message has been tampered with.

[0050] If the detection result shows that the encrypted message has been tampered with, the encrypted message is discarded; if the detection result shows that the encrypted message has not been tampered with, step 308 is continued.

[0051] Step 308: If it is determined that the encrypted message has not been tampered with, the second slave ECU reads the data to be transmitted from the data segment according to the random byte filling rule.

[0052] Specifically, reading the data to be transmitted from the data segment according to the random byte filling rule may include: the second slave ECU determining the filling position of the random byte according to the random byte filling rule; and the second slave ECU reading data at a position other than the filling position from the data segment.

[0053] Assume that the random byte filling rule is that the random number filling position in the data segment is the last two bytes in the data segment, and the data segment is [0x12, 0x34, 0x56, 0x78, 0x9A, 0xBC, 0xDE, 0xF0], then the read data is [0x12, 0x34, 0x56, 0x78, 0x9A, 0xBC].

[0054] To sum up, the message transmission method in the CAN bus provided by the embodiment of the present application is that the master ECU sends a configuration message to each slave ECU on the CAN bus, and each slave ECU determines the encryption rule according to the encryption signal in the configuration message, determines the ID jump rule according to the ID jump signal, and determines the random byte filling rule according to the random byte filling signal; then, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message, and sends the encrypted message to the CAN bus; the master ECU detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; if it is determined that the encrypted message has been tampered with, the detection result is reported to the background, and a new configuration message is sent to each slave ECU on the CAN bus, so that each slave ECU transmits the message according to the new configuration message, thereby preventing illegal devices from invading the CAN bus and interfering with the vehicle message through the combination of ID jump, random byte filling and encryption detection, thereby significantly improving the security of the CAN bus at an extremely low cost. like Figure 4, which shows a structural block diagram of a control system provided by an embodiment of the present application. The control system can be applied to an automobile. The control system includes a CAN bus 410, a master ECU 420, and multiple slave ECUs 430; The master ECU 420 is configured to send a configuration message to each slave ECU 430 on the CAN bus 410. The configuration message includes a configuration signal for the message transmitted within the current cycle. The configuration signal includes at least an encryption signal, an ID jump signal, and a random byte filling signal. Each slave ECU 430 is configured to receive a configuration message on the CAN bus 410 , determine an encryption rule according to the encryption signal, determine an ID jump rule according to the ID jump signal, and determine a random byte filling rule according to the random byte filling signal; When the first slave ECU 430 needs to send a message to the second slave ECU 430 on the CAN bus 410 , the first slave ECU 430 is further configured to generate an encrypted message according to the rule indicated by the configuration message and send the encrypted message to the CAN bus 410 ; The main ECU 420 is further configured to receive encrypted messages on the CAN bus 410 and detect whether the encrypted messages have been tampered with according to encryption rules and ID jump rules; If it is determined that the encrypted message has been tampered with, the master ECU 420 is also used to report the detection result to the background and send a new configuration message to each slave ECU 430 on the CAN bus 410, so that each slave ECU 430 transmits messages according to the new configuration message.

[0055] In an optional embodiment, the first slave ECU 430 is further configured to: Generates a message ID based on its own node ID and ID hopping rules; According to the random byte filling rule, the data to be transmitted and the random bytes are combined into a data segment, and the message ID and the data segment are filled into the message; The message is encrypted using the encryption rule to obtain an encrypted message.

[0056] In an optional embodiment, the second slave ECU 430 is configured to: Receiving an encrypted message on the CAN bus 410; Detect whether the encrypted message has been tampered with based on encryption rules and ID jump rules; If it is determined that the encrypted message has not been tampered with, the data to be transmitted is read from the data segment according to the random byte filling rule.

[0057] In an optional embodiment, the second slave ECU 430 is further configured to: Determine the filling position of the random bytes according to the random byte filling rule; Read data from the data segment at locations other than padding locations.

[0058] In an optional embodiment, the master ECU 420 or the second slave ECU 430 is further configured to: Decrypt the encrypted message according to the decryption rule corresponding to the encryption rule; If the decryption is successful, the message ID is restored according to the ID jump rule. If the restored ID is a node ID of the slave ECU 430, it is determined that the encrypted message has not been tampered with; If the decryption fails, and / or if the recovered ID is not the node ID of any slave ECU 430 , it is determined that the encrypted message has been tampered with.

[0059] In an optional embodiment, the control system is further configured to: An encryption list, an ID jump list, and a random byte filling list are pre-configured in each slave ECU 430. The encryption list includes the correspondence between encryption signals and encryption rules, the ID jump list includes the correspondence between ID jump signals and ID jump rules, and the random byte filling list includes the correspondence between random byte filling signals and random byte filling rules.

[0060] In an optional embodiment, the main ECU 420 is further configured to: After the car is powered on, a configuration message is sent to each slave ECU 430 on the CAN bus 410 .

[0061] To sum up, in the control system provided by the embodiment of the present application, the master ECU sends a configuration message to each slave ECU on the CAN bus, and each slave ECU determines the encryption rule according to the encryption signal in the configuration message, determines the ID jump rule according to the ID jump signal, and determines the random byte filling rule according to the random byte filling signal; then, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message, and sends the encrypted message to the CAN bus; the master ECU detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; if it is determined that the encrypted message has been tampered with, the detection result is reported to the background, and a new configuration message is sent to each slave ECU on the CAN bus, so that each slave ECU transmits the message according to the new configuration message, thereby preventing illegal devices from invading the CAN bus and interfering with the vehicle message through the combination of ID jump, random byte filling and encryption detection, thereby significantly improving the security of the CAN bus at an extremely low cost. One embodiment of the present application provides a computer-readable storage medium, wherein the storage medium stores at least one instruction, and the at least one instruction is loaded and executed by a processor to implement the message transmission method in the CAN bus as described above. One embodiment of the present application provides a car, which includes the above-mentioned control system. It should be noted that the control system provided in the above embodiment, when performing message transmission on the CAN bus, is merely illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the control system can be divided into different functional modules to complete all or part of the functions described above. In addition, the control system provided in the above embodiment and the embodiment of the method for message transmission on the CAN bus are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0062] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0063] The above description is not intended to limit the embodiments of the present application. Any adjustments, equivalent replacements, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the embodiments of the present application.

Claims

1. A message transmission method in a CAN bus, characterized in that: For use in a control system including a CAN bus, a master electronic control unit (ECU), and a plurality of slave ECUs, the method comprising: The master ECU sends a configuration message to each slave ECU on the CAN bus, wherein the configuration message includes a configuration signal for transmitting the message within the current cycle, and the configuration signal includes at least an encryption signal, an identification ID jump signal, and a random byte filling signal; Each slave ECU receives the configuration message on the CAN bus, determines an encryption rule according to the encryption signal, determines an ID jump rule according to the ID jump signal, and determines a random byte filling rule according to the random byte filling signal; When the first slave ECU needs to send a message to the second slave ECU on the CAN bus, the first slave ECU generates an encrypted message according to the rule indicated by the configuration message, and sends the encrypted message to the CAN bus; The master ECU receives the encrypted message on the CAN bus, and detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; If it is determined that the encrypted message has been tampered with, the master ECU reports the detection result to the background, and sends a new configuration message to each slave ECU on the CAN bus, so that each slave ECU transmits messages according to the new configuration message.

2. The message transmission method in the CAN bus according to claim 1, characterized in that: The first slave ECU generates an encrypted message according to a rule indicated by the configuration message, including: The first slave ECU generates a message ID according to its own node ID and the ID jump rule; The first slave ECU combines the data to be transmitted and the random bytes into a data segment according to the random byte filling rule, and fills the message ID and the data segment into the message; The first slave ECU encrypts the message using the encryption rule to obtain an encrypted message.

3. The message transmission method in the CAN bus according to claim 2, characterized in that: The method further comprises: The second slave ECU receives the encrypted message on the CAN bus; The second slave ECU detects whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; If it is determined that the encrypted message has not been tampered with, the second slave ECU reads the data to be transmitted from the data segment according to the random byte filling rule.

4. The message transmission method in the CAN bus according to claim 3, characterized in that: The reading the data to be transmitted from the data segment according to the random byte filling rule includes: The second slave ECU determines a filling position of the random byte according to the random byte filling rule; The second slave ECU reads data at a position other than the filling position from the data segment.

5. The message transmission method in the CAN bus according to claim 1 or 3, characterized in that: The detecting whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule includes: Decrypting the encrypted message according to the decryption rule corresponding to the encryption rule; If the decryption is successful, the message ID is restored according to the ID jump rule. If the restored ID is a node ID of a slave ECU, it is determined that the encrypted message has not been tampered with; If the decryption fails, and / or if the recovered ID is not the node ID of any slave ECU, it is determined that the encrypted message has been tampered with.

6. The message transmission method in the CAN bus according to claim 1, characterized in that: The method further comprises: An encryption list, an ID jump list, and a random byte filling list are pre-configured in each slave ECU. The encryption list includes the correspondence between encryption signals and encryption rules, the ID jump list includes the correspondence between ID jump signals and ID jump rules, and the random byte filling list includes the correspondence between random byte filling signals and random byte filling rules.

7. The message transmission method in the CAN bus according to any one of claims 1 to 6, characterized in that: The master ECU sends a configuration message to each slave ECU on the CAN bus, including: After the car is powered on, the master ECU sends a configuration message to each slave ECU on the CAN bus.

8. A control system, characterized in that: The control system includes a CAN bus, a master electronic control unit ECU and a plurality of slave ECUs; The master ECU is configured to send a configuration message to each slave ECU on the CAN bus, wherein the configuration message includes a configuration signal for transmitting the message within the current cycle, and the configuration signal includes at least an encryption signal, an identification ID jump signal, and a random byte filling signal; Each slave ECU is configured to receive the configuration message on the CAN bus, determine an encryption rule according to the encryption signal, determine an ID jump rule according to the ID jump signal, and determine a random byte filling rule according to the random byte filling signal; When the first slave ECU needs to send a message to the second slave ECU on the CAN bus, the first slave ECU is further configured to generate an encrypted message according to the rule indicated by the configuration message and send the encrypted message to the CAN bus; The master ECU is further configured to receive the encrypted message on the CAN bus and detect whether the encrypted message has been tampered with according to the encryption rule and the ID jump rule; If it is determined that the encrypted message has been tampered with, the master ECU is further configured to report the detection result to the background, and send a new configuration message to each slave ECU on the CAN bus, so that each slave ECU transmits messages according to the new configuration message.

9. A computer-readable storage medium, characterized in that The storage medium stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the message transmission method in the CAN bus according to any one of claims 1 to 7.

10. An automobile, characterized in that: The automobile includes the control system according to claim 8.