Intelligent connected vehicle fusion safety analysis method, device, product and terminal

By integrating safety analysis methods for intelligent connected vehicles, the failure modes of target functions are obtained and analyzed in an integrated manner, which solves the problem of poor accuracy in safety analysis caused by independent analysis and achieves higher accuracy and completeness in safety analysis.

CN120705827BActive Publication Date: 2025-11-11CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511211823.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-11-11
Estimated Expiration
2045-08-28

AI Technical Summary

Technical Problem

In existing technologies, the safety analysis of intelligent connected vehicles involves separate analysis and evaluation of functional safety, expected functional safety, and information security, resulting in poor accuracy of the safety analysis.

Method used

This paper provides a method for integrated security analysis of intelligent connected vehicles. By acquiring the failure modes of the vehicle's target functions, the method determines the target security loss and performs integrated analysis based on the integrated security severity level, information use level, and controllability level to generate an integrated security requirement list.

Benefits of technology

It has improved the accuracy and completeness of safety analysis for intelligent connected vehicles, reduced development costs, and enhanced the accuracy of safety analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705827B_ABST
    Figure CN120705827B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, product, and terminal for integrated security analysis of intelligent connected vehicles, relating to the technical field of intelligent connected vehicles. The method includes acquiring the failure mode of any target function on the vehicle; determining the target safety loss corresponding to the failure mode of the target function, including personal injury and / or economic loss; determining the integrated security severity level, information usage level, and controllability level corresponding to the target safety loss; determining the integrated security level of the target safety loss based on the integrated security severity level, information usage level, and controllability level; determining the integrated security target based on the target safety loss of the target function; and performing loss analysis on the integrated security target based on functional safety, information security, and expected functional safety to obtain a list of integrated security requirements. This application aims to improve the accuracy of security analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of intelligent connected vehicles, and specifically to a method, device, product, and terminal for integrated security analysis of intelligent connected vehicles. Background Technology

[0002] With the deepening development of vehicle-road-cloud integration, the complex cyber-physical system characteristics of intelligent connected vehicles have become more prominent, exhibiting the characteristics of multi-dimensional safety coupling, interweaving, and mutual influence. However, in the current process of vehicle safety analysis, different safety aspects, such as functional safety, expected functions, and expected functional safety, are analyzed and evaluated independently, resulting in poor accuracy of safety analysis. Summary of the Invention

[0003] This invention provides a method, device, product, and terminal for integrated security analysis of intelligent connected vehicles, aiming to improve the accuracy of security analysis.

[0004] The first aspect of this invention provides a method for integrated security analysis of intelligent connected vehicles, the method comprising:

[0005] Acquire the failure mode of any target function on the vehicle, determine the target safety loss corresponding to the failure mode of the target function, and the target safety loss includes personal injury and / or economic loss.

[0006] The severity level of the target security loss, the information usage level, and the controllability level are determined respectively. Based on the severity level of the target security loss, the information usage level, and the controllability level, the overall security level of the target security loss is determined. The severity level of the target security loss is determined by classifying personal injury and economic loss. The information usage level is obtained by classifying the usage of interactive information between functions.

[0007] Based on the target security loss of the target function, the integrated security target is determined, and a loss analysis is performed on the integrated security target based on functional safety, information security and expected functional safety to obtain a list of integrated security requirements.

[0008] A second aspect of the present invention provides a fusion security analysis device for intelligent connected vehicles, the device comprising:

[0009] A safety loss determination module is used to acquire the failure mode of any target function on the vehicle and determine the target safety loss corresponding to the failure mode of the target function, wherein the target safety loss includes personal injury and / or economic loss.

[0010] The integrated security level determination module is used to determine the integrated security severity level, information usage level, and controllability level corresponding to the target security loss, and to determine the integrated security level of the target security loss based on the integrated security severity level, the information usage level, and the controllability level. The integrated security severity level is determined by classifying personal injury and economic loss; the information usage level is obtained by classifying the usage of interactive information between one function and another.

[0011] The integrated security requirements derivation module is used to determine the integrated security objectives based on the target security losses of the target functions, and to perform loss analysis on the integrated security objectives based on functional safety, information security, and expected functional safety to obtain a list of integrated security requirements.

[0012] A third aspect of the present invention provides an electronic device, comprising: at least one processor and a memory storing a computer program executable on the processor, wherein the processor executes the computer program to perform the intelligent connected vehicle fusion security analysis method described in the first aspect of the present invention.

[0013] A fourth aspect of the present invention provides a non-volatile readable storage medium storing a computer program, wherein the computer program, when executed by a processor, performs the intelligent connected vehicle fusion security analysis method described in the first aspect of the present invention.

[0014] The fifth aspect of the present invention provides a computer program product, including a computer program / instruction that, when executed by a processor, implements the intelligent connected vehicle fusion security analysis method described in the first aspect of the present invention.

[0015] The sixth aspect of the present invention provides a terminal for executing the intelligent connected vehicle fusion security analysis method described in the first aspect of the embodiments.

[0016] Beneficial effects:

[0017] The analysis method provided in this application determines the target safety loss corresponding to the failure mode of any target function of the vehicle when any target function is in failure mode. The target safety loss includes personal injury and / or economic loss. Then, based on the fusion safety severity level, information use level, and controllability level corresponding to the target safety loss, the fusion safety level of the target safety loss is determined. After determining the fusion safety target based on the target safety loss of the target function, loss analysis is performed on the fusion safety target based on functional safety, information security, and expected functional safety to obtain a list of fusion safety requirements. This enables integrated analysis of information security, functional safety, and expected functional safety in the safety dimensions of intelligent connected vehicles, improving the accuracy and completeness of safety analysis. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a flowchart illustrating the steps of a fusion security analysis method for intelligent connected vehicles according to an embodiment of the present invention;

[0020] Figure 2 This is a schematic diagram of the data flow of a driver monitoring system according to an embodiment of the present invention;

[0021] Figure 3 This is a schematic diagram of a fused security loss tree according to an embodiment of the present invention;

[0022] Figure 4 This is a functional block diagram of an intelligent connected vehicle fusion safety analysis device according to an embodiment of the present invention. Detailed Implementation

[0023] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.

[0024] With the deepening development of vehicle-road-cloud integration, the complex cyber-physical system characteristics of intelligent connected vehicles are becoming more prominent, exhibiting the characteristics of multi-dimensional security coupling, interweaving, and mutual influence.

[0025] However, in the current security analysis process, different dimensions of security, such as functional safety, expected function, and expected functional safety, are analyzed and evaluated independently, resulting in poor accuracy of security analysis results.

[0026] Therefore, this application provides a method for integrated safety analysis of intelligent connected vehicles, which can perform integrated analysis of functional safety, expected functions, and expected functional safety. Compared with the method of analyzing and evaluating different safety aspects independently, this method can not only reduce development costs but also improve the accuracy of safety analysis.

[0027] Reference Figure 1 This document illustrates a flowchart of a method for integrated security analysis of intelligent connected vehicles provided in an embodiment of this application. The method specifically includes the following steps:

[0028] S101: Obtain the failure mode of any target function on the vehicle, and determine the target safety loss corresponding to the failure mode of the target function, wherein the target safety loss includes personal injury and / or economic loss.

[0029] When planning and designing the various systems and functions of a vehicle, a functional definition document is predefined. The functional definition document includes the components of each system, all functions of each system, and the data flow of each function. Before development is carried out according to the design in the functional definition document, a safety analysis is first required to assess whether there are any dangers or deficiencies in the currently designed system and its functions. This allows for targeted solutions and treatments during the development phase, thereby improving vehicle safety.

[0030] In the actual implementation process, the first step is to determine the target function of this security analysis. The target function can be any function in the function definition document, or one or more functions can be selected as the target function of this security analysis. Then, the failure mode of any target function is obtained.

[0031] In one feasible implementation, obtaining the failure mode of any target function on the vehicle includes the following steps:

[0032] A1: Obtain the vehicle's functional definition document.

[0033] The functional definition document records the components of each system of the vehicle, all functions of each system, and the data flow of each function, on a system-by-system basis. The components corresponding to a system are used to characterize the hardware boundary of the system. All components involved in the system include, but are not limited to, sensors, controllers, actuators, communication modules, and power supply units. A system may include multiple functions, and the data flow corresponding to each function refers to the signal transmission link when implementing that function.

[0034] Reference Figure 2 The diagram illustrates the data flow of the driver monitoring system provided in this application embodiment. Taking the DMS (Driver Monitoring System) as an example, the components of the DMS system and the data flow transmission are shown below:

[0035] The DMS camera is used to capture images of the driver and send the image signals to the DMS controller via the MIPI interface;

[0036] The DMS controller is used to receive image signals captured by the DMS camera, perform driver image processing, such as performing corresponding algorithm processing for functions such as driver identification, fatigue monitoring and in-loop monitoring, and output DMS data information, including driver status signals, video signals and alarm signals.

[0037] Low-voltage power supply, used to provide low-voltage power to the DMS system and related components via hard wiring;

[0038] The gateway is used to receive DMS data information sent by the DMS controller via Ethernet and distribute it to relevant controllers, such as intelligent driving modules, instrument display modules and vehicle terminals via CAN network.

[0039] The instrument display module receives and displays DMS data information from the gateway;

[0040] The intelligent driving module receives DMS data from the gateway and performs intelligent driving control or active safety control.

[0041] The vehicle-mounted terminal receives DMS data from the gateway and transmits it to the cloud platform via cellular communication for background analysis or monitoring.

[0042] The vehicle status module provides vehicle status signals, which are forwarded to the DMS controller via the gateway as input signals to the DMS controller.

[0043] A2: Track and analyze the data flow of the target function in any system and the components of the system to determine the failure mode of the target function.

[0044] Based on the components of each system, all functions of each system, and the data flow of each function recorded in the functional definition document, the data flow of the target function in any system and the components of the system are tracked and analyzed to determine whether the target function has a failure mode. If a failure mode exists, the failure mode of the target function is determined. The failure mode includes loss and error.

[0045] When the target function is not present, the failure mode of the target function is loss.

[0046] When any error mode exists in the target function, the failure mode of the target function is error.

[0047] The error modes include: the target function output is greater than the expected function output; the target function output is less than the expected function output; the logic is opposite to the expected function; the output is not the expected function; the target function output is earlier than the expected function output; the target function output is later than the expected function output; and the target function is stuck. The expected function is the function planned during the design of the target function.

[0048] In one feasible implementation, the process of determining the target security loss corresponding to the failure mode of the target function includes the following steps:

[0049] B1: Check the loss database to see if there are any records of personal injury and / or economic loss corresponding to the failure mode of the target function.

[0050] The loss database pre-stores personal injury records and / or economic loss records corresponding to different failure modes of any function.

[0051] In actual implementation, the aforementioned loss database can be constructed, specifically:

[0052] In response to a personal injury configuration operation corresponding to the failure mode of any function, obtain the personal injury record corresponding to the failure mode of that function, and / or in response to an economic loss configuration operation corresponding to the failure mode of any function, obtain the economic loss record corresponding to the failure mode of that function; add the personal injury record and / or economic loss record corresponding to the failure mode of that function to the loss database.

[0053] B2: When the loss database contains personal injury records and / or economic loss records corresponding to the failure mode of the target function, the target safety loss corresponding to the failure mode of the target function is generated based on the personal injury records and / or economic loss records corresponding to the failure mode of the target function.

[0054] When the failure mode of the target function involves personal injury and / or economic loss, it indicates that the failure mode of the target function has safety loss. Based on the personal injury records and / or economic loss records corresponding to the failure mode of the target function, the target safety loss corresponding to the failure mode of the target function is obtained by combining them.

[0055] When the failure mode of a target does not involve personal injury or economic loss, the failure mode characterizing the target function does not involve safety loss, and safety analysis of the target function is no longer required.

[0056] In actual implementation, when there is a security loss to the target function, a list of security losses to the target function can also be generated.

[0057] For example, taking the driver identification function, driver fatigue monitoring function, and driver in-the-loop monitoring function in the DMS system as examples, the records of personal injury, economic loss, and safety loss for any of these functions are shown in Table 1 below.

[0058] Table 1 Examples of Safety Losses

[0059]

[0060] This application embodiment assesses the target security loss corresponding to the function of the failure mode by combining the potential personal injury and / or economic loss that may occur when the function is lost or malfunctions, and determines the assessment and analysis of the converged security level based on the target security loss and converged security requirements.

[0061] S102: Determine the fusion security severity level, information use level, and controllability level corresponding to the target security loss, and determine the fusion security level of the target security loss based on the fusion security severity level, the information use level, and the controllability level.

[0062] In current security analysis processes, functional safety and information security analysis and assessment are usually conducted independently. Functional safety typically does not consider the impact of information security during hazard analysis and risk assessment. With the continuous improvement of vehicle intelligence and connectivity, information security attacks are becoming more diverse and feasible. Traditional functional safety analysis methods can no longer meet the relevant security analysis needs. Therefore, this method takes into account that the essence of intelligent connected vehicle security is to reduce security risks and losses. Based on the mutual influence of information security, functional safety, and expected functional safety, a new integrated security level assessment method is proposed on the basis of functional safety ASIL level.

[0063] The convergence security level assessment method provided in this application introduces three indicators: convergence security severity (S), information use (U), and controllability (C). After determining the level of each of the three indicators, the convergence security level is comprehensively determined. The convergence security severity level is determined by classifying personal injury and economic loss. The information use level is obtained by classifying the use of interactive information between functions. The controllability level is obtained by classifying the degree of controllability of the loss.

[0064] Specifically, in the current assessment of functional safety and expected functional safety, the severity considers personal injury; in the assessment of information security, the severity of information security hazards considers economic loss. In the embodiments of this application, when dividing the fused security severity, the severity in functional safety and expected functional safety as well as the severity of information security hazards are considered together, and the fused security severity is obtained by classifying according to personal injury and economic loss.

[0065] In one feasible implementation, the fusion security severity can be divided into 4 levels across 3 dimensions. The 3 dimensions include personal injury, property damage, and both personal injury and property damage. The higher the fusion security severity level, the more severe the personal injury and property damage.

[0066] For example, the classification of security severity levels is shown in Table 2.

[0067] Table 2 Classification of Security Severity Levels

[0068]

[0069] In actual implementation, the three dimensions can be divided into four levels according to the needs of the actual application to obtain the fusion security severity. This application does not impose any restrictions.

[0070] In this embodiment of the application, an information usage level is added to evaluate the importance of the information usage of any function. Specifically, the information usage level is obtained by classifying the usage of the interaction information between the function and another function. The interaction information is the output information of the function, which will be used by other functions as input information.

[0071] For example, the information used in the functional interaction can be divided into four categories based on its purpose. Each category corresponds to a level of information purpose, as shown in Table 3 below.

[0072] Table 3 Classification of Information Use Levels

[0073]

[0074] Among them, the information use level U0 corresponds to the use classification of vehicle entertainment system. This type of information, after being attacked or tampered with, will not directly cause safety accidents that cause personal injury, such as music playback and map navigation in the cockpit system.

[0075] In actual implementation, when the information usage level of the target function is U0, the severity of information security can be considered to be medium or below, and there is no need to determine the fusion security level, so the subsequent fusion security analysis process is not required.

[0076] Information usage level U1 corresponds to the usage classification of being used to remind and alarm the driver. This type of information may remind the driver through the screen, voice system, and vibration of the in-vehicle cockpit system, but the information will not enter the vehicle's control domain. This type of information is mainly used to inform the driver of vehicle fault information and status in a timely manner. All operation and influence of the vehicle still needs to be done by the driver, but some false warnings and missed warnings may still lead to safety risks.

[0077] Information use level U2 corresponds to the use classification as input reference information for controlling the vehicle. This type of information will enter the vehicle's perception and control domain. For example, the information is used in the ADAS system to provide informational reference for the ADAS system. Usually, this type of information may be used as part of the basis for vehicle control commands, but it is not the only decisive input. It is usually used for cross-validation of control decisions. When the information is attacked or tampered with, it will not directly lead to security risks.

[0078] Information usage level U3 corresponds to the usage classification of direct use for vehicle control. This type of information will enter the vehicle's perception and control domain and will directly participate in the vehicle's control and decision-making process. This type of information will be directly transmitted to the control execution module, such as longitudinal acceleration and deceleration control and lateral steering wheel angle control requested by intelligent driving. When the information is attacked or tampered with, it may directly lead to security risks.

[0079] In actual implementation, the usage classification and the mapping relationship between the usage classification and the information usage level can also be determined according to the actual application needs. This application embodiment does not impose any restrictions.

[0080] The usage classification of the output information of any function can be preset. When the output information of a function has multiple usage classifications, the highest information usage level of the multiple usage classifications is taken as the information usage level of the function.

[0081] If the purpose classification of the output information of a function includes both for vehicle entertainment system and for direct vehicle control, then the information purpose level that can be determined for the output information of that function includes U0 and U4, and U4 is selected as the information purpose level of the function to be detected.

[0082] The controllability level is determined by classifying the degree to which the loss is controllable, such as classifying the controllability level based on the driver or other potentially at-risk personnel regarding the controllability of the hazardous event.

[0083] Controllability levels can be classified according to the controllability level classification method used for both current functional safety and expected functional safety. For example, controllability C can be divided into 4 levels: C0, C1, C2 and C3, with controllability gradually decreasing from C0 to C3.

[0084] In actual implementation, based on the classification criteria of integration severity, information use, and controllability, the integration security severity level, information use level, and controllability level corresponding to each security loss of any function are determined in advance and then stored in the level database.

[0085] In one feasible implementation, during the process of determining the fusion security severity level, information use level, and controllability level corresponding to the target security loss, the fusion security severity level, information use level, and controllability level corresponding to the target security loss can be matched in the level database.

[0086] Then, based on the fusion security severity level, the information usage level, and the controllability level, the fusion security level of the target security loss is determined.

[0087] Specifically, based on the fusion security severity level, information usage level, and controllability level corresponding to the target security loss, the target fusion security score of the target security loss is searched in a preset fusion security score matrix.

[0088] The fusion security level corresponding to the target fusion security score is determined based on the range of fusion security scores preset for any fusion security level.

[0089] Specifically, the preset fusion security score matrix includes fusion security scores corresponding to different combinations of fusion security severity levels, information use levels, and controllability levels.

[0090] The fusion security score matrix can be defined according to the needs of actual applications. For example, the fusion security score 'a' can be 2-9. If the fusion security score 'a' is less than 2, it is considered that the security loss of the function to be detected does not involve fusion security. The fusion security score matrix can be shown in Table 4 below.

[0091] Table 4. Fusion Security Score Matrix

[0092]

[0093] The range of the preset convergence security score for any convergence security level can be set according to the needs of actual applications. For example, the division of convergence security levels can be shown in Table 5 below.

[0094] Table 5. Convergence Security Levels

[0095]

[0096] In actual implementation, after querying and determining the fusion security severity level, information usage level, and controllability level corresponding to the target security loss, the fusion security level corresponding to the target security loss of the target function in the failure mode can be determined based on the fusion security score matrix and the range of fusion security scores preset for any fusion security level.

[0097] S103: Based on the target security loss of the target function, determine the integrated security target, and perform a loss analysis on the integrated security target based on functional safety, information security and expected functional safety to obtain a list of integrated security requirements.

[0098] First, determine the fusion security target corresponding to the target security loss of the target function.

[0099] In actual implementation, a fusion security target corresponding to any security loss can be predefined. The fusion security target represents the security loss to be avoided. All fusion security targets corresponding to any security loss of any function are stored in the fusion security target database. When determining the target security loss of the target function and determining the fusion security target, the fusion security target corresponding to the target security loss of the target function can be found in the fusion security target database.

[0100] In one feasible implementation, after determining the fusion security objective, the method further includes:

[0101] Generate a fusion security analysis table corresponding to the target function. The fusion security analysis table includes the target security loss corresponding to the target function, the fusion security severity level, the information usage level, the controllability level, the fusion security level, and the fusion security target.

[0102] The integrated safety analysis table can intuitively reflect the current safety loss, integrated safety level, and integrated safety goal of any target function. For example, taking the DMS system as an example, when the failure mode of the driver-in-the-loop monitoring function is error, the safety loss of this function is: incorrectly judging the driver not in the loop as the driver in the loop, the intelligent driving function is activated for a long time without alarm, and the driver is not reminded to take over in certain triggering scenarios, resulting in a collision. Based on the safety loss of this function, the integrated safety goal matched in the integrated safety goal database is: to avoid safety losses caused by driver-in-the-loop status monitoring errors due to function failure, tampering, or insufficient function. The generated integrated safety analysis table is shown in Table 6 below.

[0103] Table 6. Safety Analysis of Driver-in-the-Earth Monitoring Function in Error Mode

[0104]

[0105] The exposure scenarios corresponding to security losses in the integrated security analysis table are also predefined. In actual implementation, the expert experience base can be called. When building the expert experience base, the scenarios in which a function will be used will be considered in advance.

[0106] Next, a loss analysis is performed on the integrated security objectives based on functional safety, information security, and expected functional safety to obtain a list of integrated security requirements.

[0107] Specifically, each failure event corresponding to the integrated security objective is analyzed layer by layer. The failure events include failure events corresponding to functional safety, failure events corresponding to information security, and failure events corresponding to expected functional safety. Any failure event refers to an event that can cause the integrated security objective to fail.

[0108] Then, based on each failure event corresponding to the fusion security objective, a fusion security loss tree for the fusion security objective is constructed; based on each underlying failure event of the fusion security loss tree, multiple fusion security requirements are determined to obtain a list of fusion security requirements.

[0109] Based on the fault tree analysis commonly used in functional safety and expected functional safety, this application provides a loss analysis method that integrates information security. The integrated security loss tree constructed in this application takes into account the faults caused by failures in functional safety, the attack paths and levels in information security, and the triggering conditions in expected functional safety. The analysis method of the integrated security loss tree is a more complete analysis method that includes all security analyses of system security, including functional safety, information security, and expected functional safety.

[0110] Reference Figure 3 The diagram illustrates a fusion safety loss tree provided in an embodiment of this application. Taking the driver-in-the-loop monitoring function of the DMS system as an example, when the failure mode of this function is error, the safety loss is: incorrectly judging the driver not in the loop as the driver in the loop, the intelligent driving function being activated for a long time without alarming, and failing to remind the driver to take over in certain triggering scenarios, resulting in a collision. The fusion safety goal is: to avoid safety losses caused by driver-in-the-loop status monitoring errors due to functional failure, tampering, or insufficient functions.

[0111] When constructing the fusion security loss tree, the fusion security objective is placed at the top of the fusion security loss tree.

[0112] Furthermore, the failure events corresponding to functional safety are identified, and the control chain of this function is divided into three parts: sensors, controllers, and actuators for fault analysis. This part represents the functional safety faults and requirements, such as... Figure 3 Failure events such as "communication failure" and "MCU calculation error" are failure events corresponding to functional safety.

[0113] Furthermore, attack path analysis is conducted during information storage and transmission to identify information security failure events, such as... Figure 3 The tampering events such as "image being tampered with", "being tampered with in front of the camera", and "image being tampered with during transmission" are failure events corresponding to information security.

[0114] Furthermore, an analysis of the expected functional safety trigger conditions is conducted to identify the failure events corresponding to the expected functional safety, primarily focusing on failure events caused by functional deficiencies, such as... Figure 3 The failure events such as "insufficient intelligent driving function" and "exposed to the triggering scenario" are failure events corresponding to the expected functional safety.

[0115] Constructing a fusion-based security loss tree involves performing loss analysis based on functional safety, information security, and anticipated functional safety simultaneously, resulting in more accurate loss analysis results.

[0116] Each underlying failure event of the fusion security loss tree can be derived as a fusion security requirement. For example, if the image is tampered with during transmission, the fusion security goal may not be achieved. Therefore, preventing the image from being tampered with during transmission can be considered a fusion security requirement.

[0117] In one feasible implementation, after determining multiple fusion security requirements based on each underlying failure event of the fusion security loss tree and obtaining a list of fusion security requirements, the method further includes taking the fusion security level of the target security loss as the requirement level of the fusion security target, and then determining the requirement level of the fusion security requirement corresponding to any underlying failure event based on the logical operation relationship of any underlying failure event in the fusion security loss tree.

[0118] The requirement level is used to characterize the importance of any converged security requirement. The higher the requirement level of a converged security requirement, the greater the attention and processing cost of that converged security requirement in the downstream development process.

[0119] Specifically, when determining the requirement level of the fusion security requirement corresponding to any bottom-level failure event based on the logical operation relationship in the fusion security loss tree, if the logical operation relationship between any bottom-level failure event and the failure event of the previous level is an OR logical operation, the requirement level of the fusion security requirement corresponding to the bottom-level failure event is the requirement level of the fusion security target.

[0120] When the logical operation relationship between any underlying failure event and the failure event of the previous level is an AND operation, the requirement level of the fusion security target is decomposed among one or more underlying failure events that are ANDed with the underlying failure event to obtain the requirement level of the fusion security requirement corresponding to each underlying failure event, and the sum of the requirement levels of the fusion security requirement corresponding to each underlying failure event is the requirement level of the fusion security target.

[0121] For example, a decomposition strategy for integrating the requirement levels of security objectives can be:

[0122] FSIL4=FSIL2+FSIL2=FSIL1+FSIL3;

[0123] FSIL3 = FSIL2 + FSIL1;

[0124] FSIL2 = FSIL1 + FSIL1.

[0125] For example, if the fusion security level of the target security loss is FSIL4, then the requirement level of the fusion security target is also FSIL4.

[0126] Assume that the underlying failure event 1 and the underlying failure event 2 are connected to the failure event of the next higher level through an OR gate, indicating that the occurrence of either the underlying failure event 1 or the underlying failure event 2 alone will lead to the failure event of the next higher level. Therefore, the two underlying failure events are of equal importance and no requirement level decomposition is performed. The requirement level of the underlying failure event 1 or the underlying failure event 2 is FSIL4.

[0127] The underlying failure events 3 and 4 correspond to the failure events of the next higher level through AND gates. This indicates that the failure event of the next higher level will only occur when both underlying failure events 3 and 4 occur simultaneously. The probability of underlying failure events 3 and 4 occurring simultaneously is relatively small. The requirement level FSIL4 of the fusion security target can be decomposed, and the sum of the decomposed requirement levels is FSIL4. Therefore, the requirement level FSIL4 of the fusion security target can be decomposed into FSIL2+FSIL2 or FSIL1+FSIL3.

[0128] In actual implementation, the required level after decomposition can be determined based on the probability of occurrence of underlying failure event 3 and underlying failure event 4. If the probability of occurrence of underlying failure event 3 and underlying failure event 4 is similar, it can be decomposed into FSIL2+FSIL2, that is, the required level of the fusion security requirement corresponding to underlying failure event 3 and underlying failure event 4 is FSIL2.

[0129] If the probability of occurrence of underlying failure event 3 is greater than that of occurrence of underlying failure event 4, then the FSIL1+FSIL3 decomposition method is adopted, and the requirement level of the converged security requirement corresponding to underlying failure event 3 is determined as FSIL3, and the requirement level of the converged security requirement corresponding to underlying failure event 4 is determined as FSIL1.

[0130] like Figure 3 In this context, the required level of the fusion security target is FSIL4. The underlying failure events "image recognition algorithm defect" and "exposed to the triggering scenario" are associated with the failure event "image recognition error" through AND gates. Therefore, the required levels of the fusion security requirements corresponding to the underlying failure events "image recognition algorithm defect" and "exposed to the triggering scenario" can be decomposed into FSIL2+FSIL2.

[0131] The underlying failure events "tampered with in front of the camera" and "tampered with during image transmission" are associated with the failure event "image tampered with" through an OR gate. Therefore, the requirement level of the fusion security requirement corresponding to the underlying failure events "tampered with in front of the camera" and "tampered with during image transmission" cannot be decomposed and is FSIL4.

[0132] The intelligent connected vehicle integrated security analysis method provided in this application determines the target safety loss corresponding to the failure mode of any target function when any target function is in a failure mode. The target safety loss includes personal injury and / or economic loss. Then, based on the integrated security severity level, information use level, and controllability level corresponding to the target safety loss, the integrated security level of the target safety loss is determined. After determining the integrated security target based on the target safety loss of the target function, loss analysis is performed on the integrated security target based on functional safety, information security, and expected functional safety to obtain an integrated security requirement list. This method can realize the integrated analysis of information security, functional safety, and expected functional safety in the security dimensions of intelligent connected vehicles. Compared with the method of analyzing and evaluating different security aspects independently, it can not only reduce development costs but also improve the accuracy of security analysis.

[0133] Based on the same inventive concept, this application also provides an intelligent connected vehicle integrated safety analysis device.

[0134] Reference Figure 4 This diagram illustrates a functional block diagram of a smart connected vehicle fusion security analysis device provided in an embodiment of this application. The device includes:

[0135] The safety loss determination module 100 is used to acquire the failure mode of any target function on the vehicle and determine the target safety loss corresponding to the failure mode of the target function, wherein the target safety loss includes personal injury and / or economic loss.

[0136] The fusion security level determination module 200 is used to determine the fusion security severity level, information use level, and controllability level corresponding to the target security loss, and to determine the fusion security level of the target security loss based on the fusion security severity level, the information use level, and the controllability level.

[0137] The integrated security requirements export module 300 is used to determine the integrated security objectives based on the target security losses of the target functions, and to perform loss analysis on the integrated security objectives based on functional safety, information security and expected functional safety to obtain a list of integrated security requirements.

[0138] Optionally, the safety loss determination module includes a failure mode determination unit, used for:

[0139] Obtain the vehicle's functional definition document, which includes the components of each system of the vehicle, all functions of each system, and the data flow of each function;

[0140] The data flow of a target function in any system and the components of that system are tracked and analyzed to determine the failure mode of the target function.

[0141] Optionally, the failure mode determination unit is further configured to:

[0142] The data flow of a target function in any system and the components of that system are tracked and analyzed. When the target function is missing, the failure mode of the target function is loss; when the target function has any error mode, the failure mode of the target function is error.

[0143] The error modes include: the target function output is greater than the expected function output; the target function output is less than the expected function output; the logic is opposite to the expected function; the output is not the expected function; the target function output is earlier than the expected function output; the target function output is later than the expected function output; and the target function is stuck.

[0144] Optionally, the safety loss determination module includes a safety loss determination unit, used for:

[0145] The system searches the loss database for records of personal injury and / or economic loss corresponding to the failure modes of the target function. The loss database includes records of personal injury and / or economic loss corresponding to different failure modes of any function.

[0146] When the loss database contains personal injury records and / or economic loss records corresponding to the failure mode of the target function, the target safety loss corresponding to the failure mode of the target function is generated based on the personal injury records and / or economic loss records corresponding to the failure mode of the target function.

[0147] Optionally, the apparatus further includes a loss database establishment unit, used for:

[0148] In response to the personal injury configuration operation corresponding to the failure mode of any function, obtain the personal injury record corresponding to the failure mode of that function, and / or in response to the economic loss configuration operation corresponding to the failure mode of any function, obtain the economic loss record corresponding to the failure mode of that function.

[0149] Add the personal injury records and / or economic loss records corresponding to the failure modes of this function to the loss database.

[0150] Optionally, the fusion security level determination module includes a security level matching unit, used for:

[0151] In the grading database, the fusion security severity level, information use level, and controllability level corresponding to the target security loss are matched. The grading database stores the fusion security severity level, information use level, and controllability level corresponding to all security losses of any function.

[0152] The severity level of the integrated security is determined by classifying personal injury and economic loss; the information usage level is obtained by classifying the usage of interactive information between functions; and the controllability level is obtained by classifying the degree of controllability of the loss.

[0153] Optionally, the converged security level determination module includes a converged security level determination unit, used for:

[0154] Based on the fusion security severity level, information use level, and controllability level corresponding to the target security loss, the target fusion security score of the target security loss is searched in a preset fusion security score matrix; wherein, the preset fusion security score matrix includes fusion security scores corresponding to different combinations of fusion security severity level, information use level, and controllability level.

[0155] The fusion security level corresponding to the target fusion security score is determined based on the range of fusion security scores preset for any fusion security level.

[0156] Optionally, the fusion security requirements derivation module includes a fusion security target determination unit, used for:

[0157] Search the integrated security target database for the integrated security target corresponding to the target security loss of the target function;

[0158] The fusion security target database includes fusion security targets corresponding to all security losses of any function.

[0159] Optionally, the device further includes:

[0160] The integrated security analysis table generation module is used to generate the corresponding integrated security analysis table for the target function;

[0161] The integrated security analysis table includes the target security loss corresponding to the target function, the integrated security severity level, the information usage level, the controllability level, the integrated security level, and the integrated security target.

[0162] Optionally, the fusion security requirement export module includes a fusion security requirement export unit, used for:

[0163] Each failure event corresponding to the integrated security objective is analyzed layer by layer. The failure events include failure events corresponding to functional safety, failure events corresponding to information security, and failure events corresponding to expected functional safety.

[0164] Based on each failure event corresponding to the fusion security objective, construct the fusion security loss tree of the fusion security objective;

[0165] Based on the various underlying failure events of the fusion security loss tree, multiple fusion security requirements are determined, resulting in a list of fusion security requirements.

[0166] Optionally, the fusion security requirement derivation module further includes a fusion security requirement decomposition unit, used for:

[0167] The fusion security level of the target security loss is taken as the requirement level of the fusion security target;

[0168] Based on the logical operation relationship of any underlying failure event in the fusion security loss tree, determine the requirement level of the fusion security requirement corresponding to that underlying failure event.

[0169] Optionally, the fusion security requirement decomposition unit is used for:

[0170] When the logical operation relationship between any underlying failure event and the failure event of the previous level is an OR logical operation, the requirement level of the fusion security requirement corresponding to the underlying failure event is the requirement level of the fusion security target.

[0171] When the logical operation relationship between any underlying failure event and the failure event of the previous level is an AND operation, the requirement level of the fusion security target is decomposed in one or more underlying failure events that are ANDed with the underlying failure event to obtain the requirement level of the fusion security requirement corresponding to each underlying failure event, and the sum of the requirement levels of the fusion security requirement corresponding to each underlying failure event is the requirement level of the fusion security target.

[0172] The requirement level is used to characterize the importance of any converged security requirement.

[0173] Based on the same inventive concept, this application also provides an electronic device, including: at least one processor and a memory, the memory storing a computer program that can run on the processor, wherein when the processor executes the computer program, it executes the intelligent connected vehicle fusion security analysis method described in the embodiment.

[0174] Based on the same inventive concept, this application also provides a non-volatile readable storage medium storing a computer program, wherein the computer program, when executed by a processor, performs the intelligent connected vehicle fusion security analysis method described in the embodiment.

[0175] Based on the same inventive concept, this application also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the intelligent connected vehicle fusion security analysis method described in the embodiments.

[0176] Based on the same inventive concept, this application also provides a terminal for executing the intelligent connected vehicle fusion security analysis method described in this embodiment.

[0177] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0178] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0179] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0180] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0181] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0182] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0183] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0184] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0185] The above provides a detailed description of the data processing method, apparatus, device, medium, and vehicle provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A fusion security analysis method for intelligent connected vehicles, characterized in that, The method includes: Acquire the failure mode of any target function on the vehicle, determine the target safety loss corresponding to the failure mode of the target function, and the target safety loss includes personal injury and / or economic loss. The following steps are taken to determine the fusion security severity level, information usage level, and controllability level corresponding to the target security loss, and to determine the fusion security level of the target security loss based on these levels. The fusion security severity level is determined by classifying personal injury and economic loss; the information usage level is obtained by classifying the usage of interactive information between functions. The process of determining the fusion security level of the target security loss includes: searching for a target fusion security score for the target security loss in a preset fusion security score matrix based on the fusion security severity level, information usage level, and controllability level corresponding to the target security loss; wherein the preset fusion security score matrix includes fusion security scores corresponding to different combinations of fusion security severity levels, information usage levels, and controllability levels; and determining the fusion security level corresponding to the target fusion security score based on the range of preset fusion security scores for any fusion security level. Based on the target security loss of the target function, a fusion security target is determined, and a loss analysis is performed on the fusion security target based on functional safety, information security, and expected functional safety to obtain a fusion security requirement list. The loss analysis of the fusion security target based on functional safety, information security, and expected functional safety to obtain the fusion security requirement list includes: performing a layer-by-layer analysis of each failure event corresponding to the fusion security target, where each failure event includes failure events corresponding to functional safety, information security, and expected functional safety; constructing a fusion security loss tree for the fusion security target based on each failure event corresponding to the fusion security target; and determining multiple fusion security requirements based on each bottom-level failure event of the fusion security loss tree to obtain the fusion security requirement list.

2. The method according to claim 1, characterized in that, Obtain the failure mode of any target function on the vehicle, including: Obtain the vehicle's functional definition document, which includes the components of each system of the vehicle, all functions of each system, and the data flow of each function; The data flow of a target function in any system and the components of that system are tracked and analyzed to determine the failure mode of the target function.

3. The method according to claim 2, characterized in that, The data flow of a target function in any system and the components of that system are traced and analyzed to determine the failure mode of the target function, including: The data flow of a target function in any system and the components of that system are tracked and analyzed. When the target function is missing, the failure mode of the target function is loss; when the target function has any error mode, the failure mode of the target function is error. The error modes include: the target function output is greater than the expected function output; the target function output is less than the expected function output; the logic is opposite to the expected function; the output is not the expected function; the target function output is earlier than the expected function output; the target function output is later than the expected function output; and the target function is stuck.

4. The method according to claim 1, characterized in that, Determining the target security loss corresponding to the failure mode of the target function includes: Search the loss database for records of personal injury and / or economic loss corresponding to the failure modes of the target function. The loss database includes records of personal injury and / or economic loss corresponding to different failure modes of any function. When the loss database contains personal injury records and / or economic loss records corresponding to the failure mode of the target function, the target safety loss corresponding to the failure mode of the target function is generated based on the personal injury records and / or economic loss records corresponding to the failure mode of the target function.

5. The method according to claim 4, characterized in that, The method further includes: In response to the personal injury configuration operation corresponding to the failure mode of any function, obtain the personal injury record corresponding to the failure mode of that function, and / or in response to the economic loss configuration operation corresponding to the failure mode of any function, obtain the economic loss record corresponding to the failure mode of that function. Add the personal injury records and / or economic loss records corresponding to the failure modes of this function to the loss database.

6. The method according to claim 1, characterized in that, The fusion security severity level, information use level, and controllability level corresponding to the target security loss are determined respectively, including: In the grading database, the fusion security severity level, information use level, and controllability level corresponding to the target security loss are matched. The grading database stores the fusion security severity level, information use level, and controllability level corresponding to all security losses of any function. The controllability level is obtained by classifying the degree of controllability of the loss.

7. The method according to claim 1, characterized in that, Based on the target security loss of the stated target function, the fusion security objectives are determined, including: Search the integrated security target database for the integrated security target corresponding to the target security loss of the target function; The fusion security target database includes fusion security targets corresponding to all security losses of any function.

8. The method according to claim 7, characterized in that, After determining the fusion security objective based on the target security loss of the target function, the method further includes: Generate the corresponding fusion security analysis table for the target function; The integrated security analysis table includes the target security loss corresponding to the target function, the integrated security severity level, the information usage level, the controllability level, the integrated security level, and the integrated security target.

9. The method according to claim 1, characterized in that, After determining multiple fusion security requirements based on the various underlying failure events of the fusion security loss tree and obtaining a list of fusion security requirements, the method further includes: The fusion security level of the target security loss is taken as the requirement level of the fusion security target; Based on the logical operation relationship of any underlying failure event in the fusion security loss tree, determine the requirement level of the fusion security requirement corresponding to that underlying failure event.

10. The method according to claim 9, characterized in that, Based on the logical operation relationship of any underlying failure event in the fusion security loss tree, determine the requirement level of the fusion security requirement corresponding to that underlying failure event, including: When the logical operation relationship between any underlying failure event and the failure event of the previous level is an OR logical operation, the requirement level of the fusion security requirement corresponding to the underlying failure event is the requirement level of the fusion security target. When the logical operation relationship between any underlying failure event and the failure event of the previous level is an AND operation, the requirement level of the fusion security target is decomposed in one or more underlying failure events that are ANDed with the underlying failure event to obtain the requirement level of the fusion security requirement corresponding to each underlying failure event, and the sum of the requirement levels of the fusion security requirement corresponding to each underlying failure event is the requirement level of the fusion security target. The requirement level is used to characterize the importance of any converged security requirement.

11. A smart connected vehicle integrated safety analysis device, characterized in that, The device includes: A safety loss determination module is used to acquire the failure mode of any target function on the vehicle and determine the target safety loss corresponding to the failure mode of the target function, wherein the target safety loss includes personal injury and / or economic loss. The integrated security level determination module is used to determine the integrated security severity level, information usage level, and controllability level corresponding to the target security loss, and to determine the integrated security level of the target security loss based on the integrated security severity level, the information usage level, and the controllability level. The integrated security severity level is determined by classifying personal injury and economic loss; the information usage level is obtained by classifying the usage of interactive information between functions. The process of determining the integrated security level of the target security loss includes: searching for a target integrated security score for the target security loss in a preset integrated security score matrix based on the integrated security severity level, the information usage level, and the controllability level corresponding to the target security loss; wherein the preset integrated security score matrix includes integrated security scores corresponding to different combinations of integrated security severity levels, information usage levels, and controllability levels; and determining the integrated security level corresponding to the target integrated security score based on the range of preset integrated security scores for any integrated security level. The integrated security requirement derivation module is used to determine integrated security objectives based on the target security losses of the target functions, and to perform loss analysis on the integrated security objectives based on functional safety, information security, and expected functional safety to obtain a list of integrated security requirements. The loss analysis of the integrated security objectives based on functional safety, information security, and expected functional safety to obtain the list of integrated security requirements includes: performing layer-by-layer analysis on each failure event corresponding to the integrated security objective, whereby the failure events include failure events corresponding to functional safety, failure events corresponding to information security, and failure events corresponding to expected functional safety; constructing an integrated security loss tree for the integrated security objective based on each failure event corresponding to the integrated security objective; and determining multiple integrated security requirements based on each bottom-level failure event of the integrated security loss tree to obtain the list of integrated security requirements.

12. An electronic device, characterized in that, include: At least one processor and a memory storing a computer program executable on the processor, wherein the processor executes the computer program to perform the intelligent connected vehicle fusion security analysis method according to any one of claims 1-10.

13. A non-volatile readable storage medium, characterized in that, The non-volatile readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it performs the intelligent connected vehicle fusion security analysis method according to any one of claims 1-10.

14. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the intelligent connected vehicle fusion security analysis method according to any one of claims 1-10.

15. A terminal, characterized in that, The terminal is used to execute the intelligent connected vehicle fusion security analysis method according to any one of claims 1-10.

Citation Information

Patent Citations

  • Comprehensive risk assessment method and device integrating information security and function security

    CN116362543A

  • Data processing method and device, vehicle-mounted terminal and medium

    CN116630060A