Data processing method, electronic device, storage medium and computer program product
By using digital certificate authentication and permission policies, the compatibility and security issues of in-vehicle data interfaces have been resolved, achieving secure, reliable, and compatible data interaction between the vehicle's interior and exterior.
Patent Information
- Application Number
- CN202511065255.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-11-07
AI Technical Summary
Current vehicle data interfaces suffer from insufficient cross-device compatibility due to heterogeneous bus protocols and proprietary data formats, and lack a system-level security architecture. Malicious devices can impersonate legitimate identities to access the system, posing a risk of vehicle control hijacking.
Digital certificate authentication ensures the legitimacy of external device identities, operation permissions are assigned based on preset permission policies, data is extracted and converted into a standardized and universal data format, and data is transmitted in encrypted form to establish a trusted authentication chain for device identities.
It improves cross-device compatibility, prevents malicious devices from accessing the system, ensures the confidentiality and integrity of data transmission, avoids the risk of vehicle control hijacking, and enhances system security and stability.
Smart Images

Figure CN120915516A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to a data processing method, electronic device, storage medium and computer program product. Background Technology
[0002] With the rapid development of intelligent connected vehicles, the demand for data interaction between the vehicle's interior and exterior is growing exponentially, involving the exchange of high-value data across multiple dimensions, including vehicle control commands, environmental perception information, and user entertainment data. However, current in-vehicle data interfaces suffer from insufficient cross-device compatibility due to the use of heterogeneous bus protocols (such as CAN / LIN / MOST) and proprietary data formats by different manufacturers and vehicle models. External devices need to customize their parsing logic for different vehicle models. Furthermore, existing in-vehicle data interfaces generally lack a system-level security architecture and have not established a trusted authentication chain for device identities. Malicious devices can impersonate legitimate identities to access the system, allowing attackers to gain unauthorized access to critical control domains (such as steering / braking commands), potentially leading to vehicle control hijacking risks. Therefore, current in-vehicle data interfaces suffer from poor data processing performance.
[0003] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention
[0004] The main objective of this application is to provide a data processing method, electronic device, storage medium, and computer program product, which aims to solve the technical problem of poor data processing performance.
[0005] To achieve the above objectives, this application proposes a data processing method, which includes:
[0006] In response to an external device access signal, perform digital certificate authentication on the external device;
[0007] If the external device passes digital certificate authentication, corresponding operation permissions are assigned to the external device based on a preset permission policy.
[0008] When interacting with external devices, the core parameters of the data to be transmitted are extracted, and the core parameters are converted into a standardized general data format to obtain standardized data. The standardized data is then encrypted and transmitted to the external device.
[0009] In one embodiment, the step of performing digital certificate authentication on the external device includes:
[0010] The system receives an encrypted digital certificate sent by the external device, decrypts the encrypted digital certificate based on an asymmetric decryption algorithm to obtain a target digital certificate, and verifies the validity and integrity of the target digital certificate.
[0011] In the case that the target digital certificate is valid and complete, a target device identifier of the target digital certificate is extracted and matched with a preset device physical feature code;
[0012] In the case that the target device identifier matches the preset device physical feature code, it is determined that the digital certificate authentication of the external device is passed.
[0013] In an embodiment, the step of assigning the external device with corresponding operation permissions based on the preset permission policy comprises:
[0014] determining a device type corresponding to the external device;
[0015] In the case that the device type is a diagnostic device, the external device is assigned with data read-write permissions except for a critical control instruction domain based on the preset permission policy;
[0016] In the case that the device type is a mobile device, the external device is assigned with non-secure data access permissions and the acquisition range of real-time location information is limited based on the preset permission policy;
[0017] In the case that the device type is an entertainment device, the external device is assigned with multimedia data stream access permissions and media control instruction execution permissions based on the preset permission policy.
[0018] In an embodiment, the step of assigning the external device with corresponding operation permissions based on the preset permission policy further comprises:
[0019] real-time monitoring of a data operation instruction stream issued by the external device and extraction of behavior features of the data operation instruction stream;
[0020] comparison of the behavior features with a preset set of legal operation modes to determine whether the data operation instruction stream has an overreach behavior;
[0021] In the case that the data operation instruction stream has an overreach behavior, an execution process of the data operation instruction stream is terminated and a security trust level of the external device is adjusted according to a severity of the overreach behavior and a historical violation record.
[0022] In an embodiment, the step of adjusting the security trust level of the external device according to the severity of the overreach behavior and the historical violation record comprises:
[0023] identification of an overreach type of the overreach behavior and query of a historical violation record of the external device to count a cumulative violation frequency of the external device;
[0024] In a case where the overreach type is a critical control domain overreach or the accumulated violation frequency reaches a preset accumulated number of times, the security trust level of the external device is reduced to a lowest level, and the external device is marked as permanently blocked.
[0025] In a case where the overreach type is a non-critical control domain overreach and the accumulated violation frequency does not reach the preset accumulated number of times, a sensitive degree of the overreach behavior associated data field is determined, sensitive data fields reaching a preset sensitive threshold are screened, an access channel of the sensitive data fields is closed, and the security trust level of the external device is reduced by one level.
[0026] In an embodiment, the core parameters include power control parameters, chassis state parameters, and safety information parameters, and the step of extracting the core parameters of the to-be-transmitted data includes:
[0027] Based on a preset protocol feature template library, a length identifier of the to-be-transmitted data is extracted;
[0028] Based on the length identifier, binary data streams in the to-be-transmitted data are segmented into discrete data packets;
[0029] Power control parameters, chassis state parameters, and safety information parameters in the discrete data packets are screened.
[0030] In an embodiment, the step of converting the core parameters into a standardized universal data format to obtain standardized data includes:
[0031] The core parameters are mapped into a standard data frame structure;
[0032] A bus load state is monitored in real time, a transmission rate of the standard data frame structure is adjusted according to the bus load state, and an error detection code based on a hash algorithm is embedded into a frame tail of the standard data frame structure to obtain a reorganized data frame;
[0033] The reorganized data frame is packaged into standardized data in a standardized universal data format.
[0034] In addition, to achieve the above object, the present application further provides a data processing system, which comprises:
[0035] An identity authentication module is configured to perform digital certificate authentication on the external device in response to an external device access signal;
[0036] A permission allocation module is configured to allocate corresponding operation permissions to the external device based on a preset permission policy in a case where the digital certificate authentication on the external device is passed;
[0037] The data interaction module is configured to extract core parameters of to-be-transmitted data when data interaction with the external device is performed, convert the core parameters into a standardized universal data format to obtain standardized data, encrypt the standardized data, and transmit the encrypted standardized data to the external device.
[0038] In addition, to achieve the above object, the present application further provides an electronic device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program is configured to implement the steps of the data processing method as described above.
[0039] In addition, to achieve the above object, the present application further provides a storage medium, which is a computer-readable storage medium, and the storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the data processing method as described above.
[0040] In addition, to achieve the above object, the present application further provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the steps of the data processing method as described above.
[0041] The present application provides a data processing method, which comprises: responding to an external device access signal, performing digital certificate authentication on the external device; in the case that the digital certificate authentication on the external device is passed, assigning corresponding operation permission to the external device based on a preset permission policy; in the case of data interaction with the external device, extracting core parameters of to-be-transmitted data, converting the core parameters into a standardized universal data format to obtain standardized data, encrypting the standardized data, and transmitting the encrypted standardized data to the external device.
[0042] Compared with related solutions, the present application lacks a system-level security architecture and a device identity trusted authentication chain, and different manufacturers and vehicle models use heterogeneous bus protocols and private data formats, resulting in insufficient cross-device compatibility. The present application ensures the legal identity of the accessed external device through digital certificate authentication, effectively prevents malicious device impersonation access, protects the security of the system, avoids vehicle control hijacking risks, assigns operation permissions according to a preset permission policy, accurately controls the access range and operation ability of the external device to the system, prevents unauthorized access, further enhances the security and stability of the system, extracts core parameters and converts them into a standardized universal data format, eliminates differences caused by different protocols and data formats, enables external devices of different manufacturers and vehicle models to perform data interaction without customizing parsing logic, improves cross-device compatibility, reduces development costs and use difficulty, encrypts the standardized data for transmission, ensures the confidentiality and integrity of the data during transmission, prevents data from being stolen or tampered with, and ensures the security and reliability of data interaction inside and outside the vehicle. BRIEF DESCRIPTION OF DRAWINGS
[0043] The accompanying drawings, which are incorporated herein and constitute part of the specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the application.
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings required by the embodiments or the prior art description will be briefly introduced as follows. Obviously, for those of ordinary skill in the art, the other drawings can also be obtained based on these drawings without any creative work.
[0045] Figure 1 A flowchart provided for the data processing method of the first embodiment of the present application;
[0046] Figure 2 A flowchart provided for the data processing method of the second embodiment of the present application;
[0047] Figure 3 A flowchart provided for the data processing method of the third embodiment of the present application;
[0048] Figure 4 A module structure diagram of the data processing system of the embodiment of the present application;
[0049] Figure 5 A device structure diagram of the hardware running environment involved in the data processing method in the embodiment of the present application.
[0050] The object implementation, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION
[0051] It should be understood that the first embodiment described herein is only used to explain the technical solutions of the present application, and is not used to limit the present application.
[0052] In order to better understand the technical solutions of the present application, the following will be described in detail in combination with the drawings in the specification and specific embodiments.
[0053] The main solution of the first embodiment of the present application is: in response to an external device access signal, performing digital certificate authentication on the external device; in the case that the digital certificate authentication of the external device is passed, assigning corresponding operation permission to the external device based on a preset permission policy; in the case of data interaction with the external device, extracting the core parameters of the to-be-transmitted data, and converting the core parameters into a standardized general data format to obtain standardized data, encrypting the standardized data and transmitting it to the external device.
[0054] In the first embodiment, for the convenience of description, the following describes the data processing system as the execution subject.
[0055] Due to the current vehicle-mounted data interface in data processing, due to different manufacturers and vehicle models using heterogeneous bus protocols (such as CAN / LIN / MOST) and private data formats, resulting in insufficient cross-device compatibility, external devices need to customize analysis logic for different vehicle models; At the same time, the existing vehicle-mounted data interface generally lacks a system-level security architecture, and the device identity authentication chain is not established, and malicious devices can simulate legal access to the system, so that attackers can access the key control domain (such as steering / brake instructions), causing vehicle control hijacking risk.
[0056] The present application provides a solution, through digital certificate authentication, to ensure the legal identity of the accessed external device, effectively prevent malicious device simulation access, protect the security of the system, avoid vehicle control hijacking risk, distribute operation permissions according to the preset permission policy, can accurately control the access range and operation ability of external devices to the system, prevent unauthorized access, further enhance the security and stability of the system, by extracting core parameters and converting them into standardized general data format, eliminating the differences brought by different protocols and data formats, so that external devices of different manufacturers and vehicle models can interact without customizing analysis logic, improve cross-device compatibility, reduce development cost and difficulty of use, encrypt the transmission of standardized data, ensure the confidentiality and integrity of the data during transmission, prevent data from being stolen or tampered with, and ensure the security and reliability of vehicle internal and external data interaction.
[0057] It should be noted that the execution subject of the first embodiment can be a computing service device with data processing, network communication and program running functions, such as tablet computers, personal computers, mobile phones and other electronic devices, or a system, application, program, etc. that can realize the above functions. The following takes the data processing system as an example to explain the first embodiment and the following embodiments.
[0058] All actions of obtaining signals, information or data in this application are carried out in accordance with the corresponding data protection regulations and policies of the country where the device is located, and with the authorization of the corresponding device owner.
[0059] Based on this, the data processing method provided by the embodiments of the present application is provided with reference to Figure 1 , Figure 1 The flowchart of the first embodiment of the data processing method of the present application is shown in the figure.
[0060] In this embodiment, the data processing method includes steps S01-S03:
[0061] Step S01, in response to the external device access signal, the digital certificate authentication of the external device is carried out;
[0062] It should be noted that when an external device attempts to establish a connection with the system, the system will monitor and respond to the access signal sent by the external device in real time. The external device access signal is a notification signal sent by the external device to the system indicating that it wants to establish a connection. For example, when a user connects a smartphone to a car control system via Bluetooth, the smartphone will send a specific access signal to inform the car control system that a device wants to connect. The external device refers to a non-vehicle body device that attempts to interact with the system, such as a smartphone, smartwatch, dashcam, USB drive, etc. Once the system detects the external device access signal, it will immediately start the digital certificate authentication process. A digital certificate is an electronic file issued by an authoritative agency (e.g., CA, Certificate Authority digital certificate authentication center) that contains device identity information, public key, and other key data, just like a device's "electronic ID card". The system will strictly verify the digital certificate provided by the external device, checking the validity of the certificate, whether the issuing agency is trustworthy, whether the certificate is within the valid period, and whether the device identity information in the certificate matches the actual access device, etc.
[0063] It can be understood that step S01 establishes a trusted identity recognition mechanism for the accessed external device through digital certificate authentication. Only devices with legal and valid digital certificates can access the system, effectively preventing malicious device impersonation access and establishing a device identity trusted authentication chain, thereby ensuring the security of the system from the source and reducing the likelihood of vehicle hijacking.
[0064] Step S02, in the case where the digital certificate authentication of the external device is passed, the corresponding operation permission is assigned to the external device based on the preset permission policy;
[0065] It should be noted that if the digital certificate authentication of the external device is successfully passed, it means that the device identity is legal and trustworthy. At this time, the system will assign the corresponding operation permission to the external device based on the preset permission policy. The preset permission policy is a series of rules designed and planned, which clearly defines the operation range that different types of devices or different identity devices can perform in the system. For example, for a normal user's smartphone, only basic functions such as accessing the car system's music playback and navigation information viewing are allowed, while for a professional device of a car maintenance personnel, higher operation permissions such as accessing vehicle fault diagnosis information and performing system debugging may be granted. Operation permission refers to the operation range and functions that the external device is allowed to perform in the system.
[0066] It can be understood that the step S02 assigns the operation permission based on the preset permission policy, which can accurately limit the operation range and function permission of each access device. For example, the entertainment device can only access and operate the data and functions related to entertainment, and the key permission related to vehicle control is strictly limited within the range of specific authorized devices, which not only ensures that the device can normally play its function, but also prevents unauthorized access and misoperation, further enhancing the security and stability of the system.
[0067] Step S03, in the case of data interaction with the external device, extracting the core parameters of the data to be transmitted, and converting the core parameters into a standardized universal data format to obtain standardized data, encrypting the standardized data and transmitting it to the external device.
[0068] It should be noted that in the process of data interaction with the external device, the system will extract the core parameters from the data to be transmitted. The data to be transmitted refers to the data that needs to be sent from the system to the external device or received from the external device in the process of data interaction with the external device. These data cover vehicle control instructions, environmental perception information, user entertainment data and other aspects, for example, vehicle control instructions may include acceleration, braking, steering and other instructions; environmental perception information may include camera images around the vehicle, radar data, etc.; user entertainment data may include music, video and other files. The core parameters are the key components of the data to be transmitted, which can accurately express the main content and intention of the data. Taking the environmental perception data of the vehicle as an example, if the data is about the information of the obstacle in front, then the distance, size and relative speed of the obstacle are the core parameters; in user entertainment data, the playing time and volume of music can also be regarded as core parameters.
[0069] In addition, it should be noted that after extracting the core parameters, the system will convert these parameters into a standardized universal data format. The standardized universal data format is a unified data expression specification that does not depend on specific devices, systems, or programming languages, and has wide applicability and compatibility. Using standardized universal data formats can enable smooth data interaction between different manufacturers and different types of devices. For example, the XML (Extensible Markup Language) format is also a commonly used standardized universal data format. It describes the structure and content of data through custom tags, making data more readable and extensible. Alternatively, the JSON (JavaScript Object Notation) format is used, which represents data in a simple text form, easy to read and parse, supported by many programming languages and systems. After converting the core parameters into a standardized universal data format, standardized data is obtained. Standardized data has a unified structure and specification, making it easy for different devices and systems to process and analyze. The system will finally encrypt the standardized data using encryption algorithms such as AES (Advanced Encryption Standard) to convert the data into ciphertext. Only external devices with the corresponding decryption key can restore the ciphertext to the original data, ensuring the security and confidentiality of the data during transmission. Encrypted standardized data will be transmitted to external devices.
[0070] In addition, it should be noted that the data interface applied to the system also defines a unified physical layer interface specification, covering mechanical dimensions, electrical characteristics, connection methods, etc., to ensure the physical compatibility of different devices. For example, for mechanical dimension specifications, the data interface determines the overall shape and size of the connector to conform to ergonomic principles, making it easy for operators to plug and unplug, and specifies the number and arrangement of pins, allocating pin functions according to device function requirements and data transmission requirements. For electrical characteristic specifications, the interface defines the operating voltage range to ensure that different devices can work normally within this voltage range, and specifies signal level standards, anti-interference ability, transmission rate, and bandwidth. For connection method specifications, users can choose the appropriate connector type according to the device's use environment and installation requirements.
[0071] It can be understood that step S03 eliminates the differences between different protocols and data formats by extracting the core parameters of the to-be-transmitted data and converting them into a standardized universal data format, enabling interaction based on unified standardized data regardless of the manufacturer of the external device or the vehicle model to which it is applied, without the need to customize parsing logic for different vehicle models, greatly improving cross-device compatibility. At the same time, the standardized data is transmitted after encryption, ensuring the confidentiality and integrity of the data during transmission, preventing data from being stolen or tampered with, ensuring the security and reliability of data interaction, thereby improving the overall data processing effect.
[0072] In a feasible implementation, the step of authenticating the external device with a digital certificate in step S01 includes steps A01-A03:
[0073] Step A01, receiving the encrypted digital certificate sent by the external device, decrypting the encrypted digital certificate based on an asymmetric decryption algorithm to obtain a target digital certificate, and verifying the validity and integrity of the target digital certificate;
[0074] It should be noted that when the external device attempts to access the system, it will encrypt the digital certificate it holds using the public key of the system that is publicly disclosed in advance, and then send the encrypted digital certificate to the system. After the system receives the encrypted digital certificate, it uses the corresponding private key saved by itself to perform decryption operation on the encrypted digital certificate through an asymmetric decryption algorithm (such as RSA decryption algorithm). After successful decryption, the target digital certificate is obtained. The target digital certificate is a digital certificate file sent by the external device to the system after decryption, which contains important information such as the identity information, public key, and signature of the certificate authority (CA) of the external device, which is used to prove the legal identity and authenticity of the external device. The system will verify the validity of the target digital certificate to check whether the certificate is within the valid period, because the digital certificate usually has a set start and end time, and the certificate beyond this time range will be considered invalid. At the same time, the integrity of the certificate will also be verified by checking whether the digital signature in the certificate is consistent with the expected one to ensure that the certificate has not been tampered with during transmission. For example, the vehicle system will use the public key of the certificate authority to decrypt the signature in the certificate, and then compare the decrypted result with other information in the certificate. If they are consistent, it means that the certificate is complete and has not been tampered with.
[0075] Step A02, under the condition that the target digital certificate is valid and complete, extracting the target device identifier of the target digital certificate and performing matching verification with the preset device physical feature code;
[0076] It should be noted that once the system confirms that the target digital certificate is valid and complete, the target device identifier is extracted from the target digital certificate, which is a string or code extracted from the target digital certificate for uniquely identifying the external device, which can be a serial number, MAC address, IMEI number, etc. with unique information, through which the system can accurately identify the accessed device, and the system will search the pre-stored preset device physical feature code database corresponding to the external device type. The pre-device physical feature code is a physical feature information corresponding to the legal access device pre-stored in the system, which is determined during the production process of the device and has uniqueness and tamper resistance, which can be matched and verified with the target device identifier to ensure the legality of the access device. The extracted target device identifier is compared with the found preset device physical feature code one by one to verify whether they are completely matched.
[0077] Step A03, in the case that the target device identifier matches the preset device physical feature code, it is determined that the digital certificate authentication of the external device is passed.
[0078] It should be noted that when the target device identifier completely matches the pre-device physical feature code, the system will determine that the digital certificate authentication of the external device is passed, at which time the system will record the information of the passed authentication and prepare for subsequent allocation of corresponding operation permissions to the external device based on the preset permission policy.
[0079] In this embodiment, the encrypted digital certificate is decrypted by the asymmetric decryption algorithm, ensuring the confidentiality of the digital certificate during transmission, effectively preventing certificate information leakage and tampering, and verifying the validity and integrity of the target digital certificate to identify expired, revoked or incomplete certificates in time. Only real, valid and complete certificates can enter the subsequent authentication process, avoiding illegal device access to the system, ensuring data interaction between the system and the legal device, improving the accuracy and reliability of data processing, and extracting the target device identifier in the target digital certificate and matching it with the pre-device physical feature code to accurately determine whether the accessed device is a legal and real device. The physical feature code as a unique identifier of the device is not affected by the possible repetition or conflict of the certificate or identifier, and the device identifier and physical feature code are verified twice, only the device that matches both can be identified as a legal device, effectively preventing device identity fraud, avoiding data processing confusion caused by device identification errors, ensuring data interaction between the system and the correct device, and improving the pertinence and accuracy of data processing.
[0080] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as the above first embodiment can be referred to the above introduction, and the subsequent will not be described. On this basis, please refer to Figure 2 In step S02, the step of assigning the corresponding operation permission to the external device based on the preset permission policy includes steps S11-S14:
[0081] Step S11, determine the device type corresponding to the external device;
[0082] It should be noted that the device type is a classification identification of the external device accessing the system according to its function, purpose and other characteristics, different device types have different operation requirements and security risk levels, for example, diagnostic devices (such as automobile fault diagnosis instrument), mobile devices (such as smart phones, tablet computers), entertainment devices (such as car DVD player) and the like. The system reads the device identification information sent by the external device, which contains the type code of the device, and the vehicle-mounted system queries and determines the device type corresponding to the external device according to the preset correspondence table of device type code and device type, for example, if the type code in the device identification information sent by the external device is "01", the correspondence table shows that "01" represents diagnostic device, then the system will determine that the device is a diagnostic device.
[0083] Step S12, in the case of diagnostic device, assign data read-write permission to the external device except the key control instruction domain based on the preset permission policy;
[0084] It should be noted that the diagnostic device is mainly used for fault detection, performance evaluation and system debugging of the vehicle, and such devices usually need to access the key data inside the vehicle to accurately diagnose the vehicle condition, but in order to prevent misoperation or malicious attack on the key control system of the vehicle, the operation permission needs to be strictly limited, for example, the professional diagnostic instrument used in automobile repair shop, which can be connected to the OBD (On-Board Diagnostics) interface of the vehicle to read the fault code, sensor data and other information of the vehicle. When the system determines that the external device is a diagnostic device, it will find the permission policy corresponding to the diagnostic device from the preset permission policy library, and according to the policy, the system assigns data read-write permission to the diagnostic device, but excludes the permission of key control instruction domain. Data read-write permission refers to the permission range of external device for reading and writing operation of data in the system, different data read-write permission determines which data the device can access and modify, so as to protect the security and integrity of the data. The key control instruction domain is a collection area of instructions related to the core control function of the vehicle in the vehicle-mounted system, these instructions are directly related to the key aspects of vehicle driving safety, power control, etc., once being executed or tampered with, it may cause serious safety accidents.
[0085] For example, when the device type is a diagnostic device, the vehicle system opens the reading permission of fault codes, the reading permission of real-time data flow, and the writing permission of part of configuration parameters of each ECU (Electronic Control Unit) of the vehicle, but strictly limits the permission of critical control instruction domains such as engine start / stop instructions and brake system control instructions, and does not allow the diagnostic device to perform read / write operations.
[0086] In step S13, when the device type is a mobile device, the non-safe data access permission is assigned to the external device based on the preset permission policy, and the acquisition range of real-time location information is limited.
[0087] It should be noted that the mobile device generally refers to a device with mobility and capable of connecting and interacting with the system, such as a smart phone, a tablet computer, etc. When such a device accesses the system, it may involve the access of user privacy data, and therefore the access permission thereof needs to be reasonably limited to protect user privacy. For example, a user's smart phone is connected to the system through Bluetooth or USB for playing music or navigation. When the system identifies that the access device is a mobile device, a preset permission policy template is also called, and the mobile device is assigned the access permission of non-safe data according to the template. The non-safe data access permission refers to the permission of the external device to access data in the vehicle system that does not involve vehicle safety critical information. These data mainly include some regular vehicle state information and user setting information, and do not directly affect the driving safety of the vehicle. For example, vehicle fuel consumption statistical information and in-vehicle temperature setting are non-safe data. At the same time, for real-time location information (geographical location data that is constantly updated during vehicle driving), the system sets specific acquisition conditions and time range limits. For example, the mobile device is only allowed to acquire the real-time location information of the vehicle within a certain time range under the authorization of the user, and can only use the information for specific application programs (such as navigation software).
[0088] In step S14, when the device type is an entertainment device, the multimedia data stream access permission and media control instruction execution permission are assigned to the external device based on the preset permission policy.
[0089] It should be noted that the entertainment device is mainly used to provide entertainment function for the people in the vehicle, such as vehicle-mounted multimedia player, intelligent sound, etc. Such devices mainly involve the playing and control of multimedia data, and have less impact on the safety of the vehicle, but also need to reasonably allocate permissions to ensure its normal operation and user experience. For example, the vehicle-mounted DVD player can play multimedia content such as movies and music. After determining that the access device is an entertainment device, the system opens the multimedia data stream access permission and the media control instruction execution permission for the device according to the preset permission policy. The multimedia data stream access permission refers to the permission of the entertainment device to read and play the multimedia data (such as audio and video files) stored or transmitted in the system. By giving the entertainment device the multimedia data stream access permission, it can normally play the entertainment content required by the user. For example, the vehicle-mounted intelligent sound can access the music files stored in the vehicle-mounted hard disk or the connected mobile phone to play. The media control instruction execution permission allows the entertainment device to execute control instructions related to multimedia playing, such as playing, pausing, stopping, fast forwarding, and fast rewinding. The execution of these instructions can achieve flexible control of multimedia content and improve user experience.
[0090] In this embodiment, by accurately determining the type of external device, a foundation is laid for subsequent reasonable operation permission allocation based on device type, so that the system can control the data access and operation range of different devices according to their characteristics, improve the accuracy and rationality of permission allocation, reduce data processing conflicts and errors caused by unreasonable permission allocation, improve the orderliness of data processing, meet the needs of diagnostic devices to access vehicle data for fault diagnosis, ensure the normal development of diagnostic work, and strictly limit the operation of key control instruction domain, effectively prevent vehicle safety accidents caused by misoperation or malicious attacks of diagnostic devices, allow mobile devices to access non-safe data to meet the needs of users to interact with the system through mobile devices, while strictly limiting the access range of real-time location information to protect the privacy of the vehicle owner and the safety of the vehicle, reduce the security risks in the data processing process, reduce potential problems caused by sensitive data leakage, give appropriate permissions to entertainment devices to allow them to access multimedia data streams and execute media control instructions, and since the permission allocation is clear, it avoids conflicts with other device permissions, reduces interference and errors in the data processing process, improves the processing efficiency and quality of entertainment data by the system, and improves the user's entertainment experience.
[0091] In a feasible implementation, after the step of allocating corresponding operation permissions to the external device based on the preset permission policy in step S02, steps B01-B03 are further included.
[0092] Step B01, real-time monitoring of data operation instruction stream issued by external device, and extracting behavior characteristics of data operation instruction stream;
[0093] It should be noted that the data operation instruction stream refers to a series of instructions for reading, writing, modifying, deleting, etc. vehicle data issued by the external device in the process of interacting with the vehicle system. These instructions are combined according to certain order and logic to form a continuous instruction sequence to achieve a specific function or operation. For example, when the external device (such as a smart phone) is connected with the vehicle navigation system and wants to update the navigation map data, it will issue a series of instructions, including requesting to read the current map version information, downloading new map data, writing new map data to the vehicle storage device, etc. These instructions constitute the data operation instruction stream. After the external device accesses and starts data operation, the system will start a special monitoring unit to capture the data operation instruction stream in real time, analyze each instruction, extract the type, operation object, and issuance time of the instruction, and analyze the order and frequency relationship between the instructions according to these information, so as to extract the behavior characteristics of the data operation instruction stream. The behavior characteristics are the abstraction and generalization of the characteristics of each instruction in the data operation instruction stream and the relationship between the instructions. It can be extracted from multiple dimensions, such as the type of instruction (reading, writing, etc.), the object of operation (a specific data area or file), the frequency of instruction (the number of instructions issued per unit time), the order of instruction, etc. For example, the monitoring unit will record which ECUs are accessed in turn by a diagnostic device when reading vehicle fault codes, and the time interval between each read instruction, etc. to extract its behavior characteristics.
[0094] Step B02, comparing the behavior characteristics with the preset legal operation mode set to determine whether the data operation instruction stream has an unauthorized behavior;
[0095] It should be noted that the preset legal operation mode set is a series of legal data operation instruction flow mode sets defined in advance according to the normal operation requirements and safety specifications of different types of external devices. These modes cover the types, sequences, frequencies, and other characteristics of instructions in various normal operation scenarios, for example, for the interaction of mobile devices (such as tablets) with car entertainment systems, the preset legal operation mode set may include normal music playing instruction modes (such as reasonable order and frequency of instructions such as selecting songs, playing, pausing, adjusting volume, etc.), video playing instruction modes, etc. The extracted behavior characteristics are compared one by one with the corresponding modes in the preset legal operation mode set, and the comparison content includes instruction type, operation object, instruction sequence, instruction frequency, etc. If the behavior characteristics completely match or are within the allowed error range of the modes in the preset legal operation mode set, the data operation instruction flow is considered legal; otherwise, if there is a significant difference, it is judged that there is an overreach behavior. Overreach behavior refers to the data operation instruction flow issued by the external device exceeding its operation permission range based on the preset permission policy, for example, a normal diagnostic device may read the fault codes of each electronic control unit (ECU) in a specific order and with a relatively stable reading frequency when reading the fault codes of the vehicle; while a malicious device may frequently and randomly send reading instructions to try to obtain more data.
[0096] Step B03, in the case of overreach behavior in the data operation instruction flow, terminate the execution process of the data operation instruction flow, and adjust the security trust level of the external device according to the severity of the overreach behavior and the historical violation record.
[0097] It should be noted that when the system judges that the data operation instruction stream has an unauthorized behavior, it will immediately send a termination instruction to the external device to stop the execution process of the current data operation instruction stream. At the same time, the system will evaluate the severity of the unauthorized behavior and query the historical violation record of the external device. The severity is a quantitative evaluation of the nature and impact of the unauthorized behavior, which can be determined according to the data sensitivity involved in the unauthorized behavior, the potential threat to system security and function, etc. The historical violation record is detailed information recording all unauthorized behaviors of the external device during past interactions with the system, including the time, type, severity of the unauthorized behavior, etc. The security trust level of the external device is adjusted according to the severity of the unauthorized behavior and the historical violation record. The security trust level is an evaluation index of the security and trustworthiness of the external device in the system, which is dynamically adjusted according to the type of the external device, historical behavior performance (including historical violation record), etc. The higher the security trust level, the more secure and trustworthy the external device, and the less likely the system will limit its operation. Conversely, the lower the security trust level, the more security risks the external device has, and the system will impose stricter restrictions on its operation. For example, if the unauthorized behavior is serious and the external device has multiple violation records, its security trust level will be significantly reduced; if the unauthorized behavior is light and it is the first violation, the security trust level will be appropriately reduced.
[0098] In this embodiment, by monitoring and extracting the behavior characteristics of the data operation instruction stream in real time, the system can timely grasp the operation dynamics of the external device, provide a basis for subsequent judgment of whether there is an unauthorized behavior, help to timely discover potential security threats, and protect the safety and stability of the data processing process. By comparing the behavior characteristics with the preset legal operation mode set, the system can accurately and quickly judge whether the data operation instruction stream of the external device has an unauthorized behavior, improve the identification ability of the system to unauthorized behaviors, and enhance the safety and compliance of data processing. By terminating the execution process of the unauthorized data operation instruction stream, further malicious attacks on the system by malicious devices can be prevented in time, and the safety of the data and the stability of the system are protected. According to the severity of the unauthorized behavior and the historical violation record, the security trust level of the external device is adjusted to realize dynamic management and differentiated restriction of the external device, which helps to improve the safety management level of the system to the external device, create a safe and reliable data processing environment, and solve the problem of poor data processing effect in the current vehicle-mounted data interface.
[0099] In a feasible implementation, in step B03, the step of adjusting the security trust level of the external device according to the severity of the unauthorized behavior and the historical violation record includes steps B11-B13:
[0100] Step B11, identify the overreach type of the overreach behavior, and query the historical violation records of the external device, and count the cumulative violation frequency of the external device;
[0101] It should be noted that after the security monitoring unit of the system detects that the external device has an overreach behavior, it will analyze the overreach behavior in detail, identify the overreach type of the overreach behavior, and the overreach type refers to the specific operation category and nature involved in the overreach behavior of the external device. It can be classified based on the difference in its impact on the key degree of the vehicle-mounted system and data security. At the same time, the security monitoring unit will access the database storing the historical violation records of the external device, query all the past violation behavior information of the external device, and count the number of violations to obtain the cumulative violation frequency. For example, if the external device attempts to modify the anti-lock braking system (ABS) parameters of the vehicle, the security monitoring unit identifies that it is a key control domain overreach behavior by comparing the pre-set key control domain operation characteristics. Then, it queries the database and finds that the device has a previous violation record of reading sensitive data of the vehicle engine control unit (ECU) 1 time, and the cumulative violation frequency is 2 times.
[0102] In addition, it should be noted that in identifying the overreach type of the overreach behavior, the operation object identifier in the behavior characteristics is extracted, and the pre-set sensitive operation rule library is matched based on the operation object identifier to determine whether the operation object of the overreach behavior belongs to the key control domain or the non-key data domain. When the operation object identifier matches the key control domain rule, it is determined that the operation object of the overreach behavior belongs to the key control domain, i.e. the overreach type is key control domain overreach, otherwise, it is determined that the operation object of the overreach behavior belongs to the non-key control domain, i.e. the overreach type is non-key control domain overreach.
[0103] Step B12, in the case of key control domain overreach or cumulative violation frequency reaching the pre-set cumulative number of times, the security trust level of the external device is reduced to the lowest level, and the external device is marked as permanently blocked;
[0104] It should be noted that the key control domain override refers to the override behavior of the external device involving the area in the vehicle system which plays a key control role in vehicle safety, performance, core function, etc. When the safety monitoring unit judges that the override type of the external device is a key control domain override, or the cumulative violation frequency reaches the preset cumulative number, it will send a corresponding signal to the safety management center of the vehicle system. Among them, the preset cumulative number is a value (for example, 3 times) preset in advance, which is used to measure the cumulative degree of historical violation behavior of the external device. When the cumulative violation frequency of the external device reaches this preset value, it indicates that the device has a high safety risk and needs to be controlled more strictly. After receiving the signal, the safety management center immediately adjusts the security trust level of the external device to the lowest level, and marks the device as permanently blocked in the device management database. Permanent blocking means permanently prohibiting the external device from accessing the vehicle system and cutting off all communication connections and data interaction channels between the external device and the vehicle system. For example, if the preset cumulative number is 3 times, and the cumulative violation frequency of the external device reaches 3 times, regardless of the override type, the safety management center will reduce its security trust level to the lowest level and mark it as permanently blocked. After that, the device will no longer be able to access the vehicle system.
[0105] Step B13, in the case of non-key control domain override and cumulative violation frequency not reaching the preset cumulative number, determine the sensitivity of the override behavior associated data domain, filter the sensitive data domain whose sensitivity reaches the preset sensitivity threshold, close the access channel of the sensitive data domain, and reduce the security trust level of the external device by one level.
[0106] It should be noted that the non-critical control domain override is opposite to the critical control domain override, which means that the override behavior of the external device involves the area in the vehicle system that has less impact on the safety, performance and core function of the vehicle. When the safety monitoring unit determines that the override type of the external device is a non-critical control domain override, and the accumulated violation frequency does not reach the preset accumulated number of times, the data domain involved in the override behavior will be analyzed, and the sensitivity of the associated data domain will be determined by querying the sensitivity identification information of the data domain. The sensitivity is used to measure the importance and confidentiality of the data in the data domain. Different data domains contain data with different sensitivity, for example, the real-time location information of the vehicle, the user identity information, etc. belong to highly sensitive data, while the music playlist in the vehicle entertainment system belongs to low sensitivity data. Compare the sensitivity with the preset sensitivity threshold value, filter out the sensitive data domain whose sensitivity reaches or exceeds the threshold value, the preset sensitivity threshold value is a standard value of the sensitivity degree set in advance, which is used to judge whether the sensitivity of the data domain reaches the degree that special protection measures need to be taken, when the sensitivity of the data domain reaches or exceeds this threshold value, the access to the data domain needs to be strictly limited. The access control unit of the system will close the access channel of the sensitive data domain to prevent the external device from accessing the data, the access channel is the path and interface between the external device and the specific data domain in the system for data transmission and interaction, through the access channel, the external device can read, write or modify the data in the data domain, at the same time, the safety management center will reduce the security trust level of the external device by one level. For example, the external device reads part of the song list in the vehicle entertainment system (non-critical control domain override), and the accumulated violation frequency is 1 time (does not reach the preset accumulated number of times 3 times), but it contains user-defined sensitive audio classification information (sensitivity reaches the preset threshold value), the access control unit will close the access channel of the sensitive audio classification data domain, and reduce the security trust level of the external device by one level.
[0107] In this embodiment, by identifying the unauthorized type and statistically accumulating the violation frequency, the system can comprehensively understand the unauthorized behavior characteristics and historical performance of the external device, provide accurate basis for subsequent targeted processing measures, help to realize the fine management of the external device, improve the accuracy and effectiveness of safety control, protect the data processing safety of the vehicle-mounted data interface, completely prevent the re-access and operation of the high-risk external device to the vehicle-mounted system by reducing the safety trust level to the lowest level and marking as permanent blocking, effectively protect the key functions and data safety of the vehicle, improve the prevention ability of the vehicle-mounted system to serious security threats, create a safe and reliable vehicle-mounted data environment, solve the problems of poor data processing effect and security risks caused by high-risk device access, by closing the access channel of the sensitive data domain and reducing the safety trust level, the system can effectively protect the safety of sensitive data and user privacy without affecting the normal access of external devices to non-sensitive data, realize the fine management of the access permission of external devices, improve the data processing safety and reliability of the vehicle-mounted data interface, and solve the problems of poor data processing effect and user trust caused by sensitive data leakage.
[0108] Based on the first and second embodiments of the present application, in the third embodiment of the present application, the same or similar contents as the above first and second embodiments can be referred to the above introduction, and will not be described in detail. On this basis, please refer to Figure 3 In step S03, the core parameters include power control parameters, chassis state parameters and safety information parameters, and the step of extracting the core parameters of the to-be-transmitted data includes steps S21-S23:
[0109] In step S21, based on the preset protocol feature template library, the length identifier of the to-be-transmitted data is extracted.
[0110] It should be noted that the preset protocol feature template library is a pre-constructed database, which stores the feature information of various communication protocols, including the format, data structure, identifier rule, etc. of the protocol, which is used to identify and analyze the communication protocol followed by the to-be-transmitted data. The system matches the received to-be-transmitted data with various protocol features in the preset protocol feature template library, analyzes the starting bit, identifier format and other features of the data, determines the communication protocol used by the data, and once the communication protocol is determined, the system can extract the length identifier from the data frame according to the rules of the protocol. The length identifier is a specific field or identifier in the communication protocol used to indicate the length of the data, usually located at the beginning of the data frame, used to tell the length of the subsequent data to the receiver, so that the receiver can accurately segment and analyze the data. For example, if it is determined that the data uses CAN protocol, the system will read the data length code (DLC) field in the data frame to obtain the length information of the subsequent data segment.
[0111] Step S22, based on the length identifier, the binary data stream in the data to be transmitted is segmented into discrete data packets;
[0112] It should be noted that according to the extracted length identifier, the system can accurately know the length of each data packet, and the continuous binary data stream is segmented according to the length identifier to obtain independent discrete data packets. The binary data stream is a continuous data sequence composed of 0 and 1, which is the basic form of data transmission and storage between computers and electronic devices. In vehicle system communication, vehicle state information and control instructions collected by various sensors will be converted into binary data stream for transmission. Discrete data packets are data units with independent meaning obtained by segmenting continuous binary data stream according to length identifier. Each discrete data packet contains specific type of information for easy processing and analysis by the system. For example, if the length identifier indicates that the length of the data packet is 8 bytes, the system will segment the data stream every 8 bytes to obtain multiple 8-byte discrete data packets.
[0113] Step S23, screening power control parameters, chassis state parameters and safety information parameters in discrete data packets.
[0114] It should be noted that the system further analyzes each discrete data packet, and according to the preset parameter screening rule, it is judged whether the data packet contains power control parameters, chassis state parameters or safety information parameters. The power control parameter is a key data for accurately regulating the running state of the vehicle power system, which covers various control instructions and state feedback information of power sources such as engine and motor, and directly determines important indicators such as power output, fuel economy and emission performance of the vehicle. The chassis state parameter reflects the real-time running condition and performance index of the vehicle chassis system, which includes suspension, braking and steering subsystems. Chassis state parameters play a crucial role in the controllability, stability and safety of the vehicle. Safety information parameters are various data related to vehicle safety, including state information of active safety system and passive safety system. These parameters are used to monitor the safety status of the vehicle in real time, discover potential safety hazards in time, and trigger corresponding safety protection measures when necessary.
[0115] In addition, it should be noted that the screening rule can be customized according to different communication protocols and data formats. For example, for CAN protocol data packet, the system can determine the type of data packet according to the range of identifier. If the identifier falls within the range related to power control, the power control parameter in the data packet is extracted; if the identifier is related to chassis state, the chassis state parameter is extracted; if the identifier corresponds to safety information, the safety information parameter is extracted.
[0116] In the embodiment, through the preset protocol feature template library, the system can quickly match the protocol used by the to-be-transmitted data and accurately extract the length identifier. This provides key basic information for subsequent data processing, ensures correct analysis of different protocol data, packet segmentation based on the length identifier, ensures that each data packet contains complete information, avoids incorrect segmentation or merging of data, provides accurate data units for subsequent screening of core parameters, improves the accuracy of parameter extraction, accurately extracts power control parameters, chassis state parameters and safety information parameters from discrete data packets, provides key information for monitoring and control of the vehicle, helps to discover vehicle faults in time, optimize vehicle performance and ensure driving safety.
[0117] In a feasible embodiment, in step S03, the step of converting the core parameters into a standardized universal data format to obtain standardized data includes steps C01-C03:
[0118] Step C01, mapping the core parameters into a standard data frame structure;
[0119] It should be noted that the core parameters are mapped into the standard data frame structure based on the correspondence between the core parameters and the standard data frame structure. The standard data frame structure is a pre-defined data organization form which specifies the meaning, length and arrangement order of each part of the data. Mapping the core parameters into this structure is like arranging and arranging the data according to a specific template, so that each parameter can find its fixed position in the standard data frame.
[0120] Step C02, real-time monitoring of bus load state, adjusting the transmission rate of the standard data frame structure according to the bus load state, and embedding an error detection code based on a hash algorithm at the end of the standard data frame structure to obtain a reorganized data frame;
[0121] It should be noted that the bus is a channel for data transmission between various modules in the vehicle system, and the bus load state reflects the current data transmission amount and the degree of busy on the bus. Real-time monitoring of the bus load state means that the system needs to constantly obtain information such as data flow and transmission delay on the bus to understand the use of the bus. According to the real-time monitored bus load state, the system will dynamically adjust the transmission rate of the standard data frame structure. When the bus load is low, the transmission rate can be appropriately increased to transmit data faster; when the bus load is high, the transmission rate is reduced to avoid bus congestion and ensure reliable data transmission. For example, assuming that the system presets three transmission rate levels: high speed (100 frames per second), medium speed (50 frames per second), and low speed (20 frames per second), when the bus load rate is less than 30%, the system adjusts the transmission rate to high speed; when the bus load rate is between 30% and 70%, the medium speed transmission is used; when the bus load rate is higher than 70%, the low speed transmission is switched to.
[0122] Specifically, the step of adjusting the transmission rate of the standard data frame structure according to the bus load state includes: capturing the signal transition frequency and the duty cycle characteristics in the bus physical layer in real time, performing weighted calculation based on the signal transition frequency and its corresponding first weight, and the duty cycle characteristics and its corresponding second weight to obtain the synergistic influence coefficient of the signal transition frequency and the duty cycle characteristics, in the case that the synergistic influence coefficient is lower than the first influence threshold, determining that the bus load state is in the low load level, in the case that the synergistic influence coefficient is not lower than the first influence threshold and not higher than the second influence threshold, determining that the bus load state is in the medium load level, in the case that the synergistic influence coefficient is higher than the second influence threshold, determining that the bus load state is in the high load level, and matching the target transmission rate corresponding to the bus load state based on the preset level-rate mapping rule.
[0123] In addition, it should be noted that the hash algorithm is an algorithm for mapping data of any length to a fixed length hash value. Embedding the error detection code based on the hash algorithm in the frame tail of the standard data frame structure is to calculate the hash value of the effective data (excluding the frame header and the frame tail itself) in the data frame by hash calculation, and add a fixed length hash value as the error detection code to the frame tail. The receiving party will recalculate the hash value of the effective data after receiving the data frame, and compare it with the hash value carried in the frame tail. If they are inconsistent, it means that an error has occurred in the data transmission process.
[0124] In addition, it should be noted that in the case of monitoring the bus load state, the safe running state signal in the bus is collected in real time; in the case where the safe running state signal reaches the high-risk working condition threshold, the lightweight encryption algorithm is switched to perform encryption operation on the standardized data, and the log recording of the non-critical security audit function is suspended, and the operation resources are preferentially allocated to the vehicle control command transmission task; when the safe running state signal recovers to the safe working condition range, the high-strength encryption algorithm is re-enabled to perform encryption operation, and the complete security audit function is restored and the encryption log is recorded. The safe running state signal is a comprehensive reflection of a series of data indicators reflecting the overall running safety of the vehicle, which can cover the running parameters of multiple key systems and components, and can timely and accurately reflect whether the vehicle is in a safe running state through real-time monitoring and analysis of these parameters, providing a basis for subsequent decision-making. The high-risk working condition threshold is used to judge whether the vehicle is in a high-risk running condition, when each key indicator in the safe running state signal reaches or exceeds this threshold, it indicates that the vehicle is facing serious safety risks, and immediate measures need to be taken to protect the safety of the vehicle and passengers, for example, the engine high-risk working condition threshold set by the vehicle manufacturer is 120°C. When the monitored engine temperature reaches or exceeds 120°C, it indicates that the engine is in a high-risk running state, which may cause engine damage, vehicle out of control and other serious consequences, at this time, the system will trigger the corresponding safety measures according to the pre-set rules. The lightweight encryption algorithm is an algorithm that can quickly and efficiently encrypt and decrypt data in the case of limited computing resources, which usually has lower computational complexity and smaller storage requirements, and is suitable for scenarios with high real-time requirements and relatively tight computing resources, such as simplified version of AES-128, SPECK, etc. The non-critical security audit function refers to the security audit related functions that can be temporarily suspended or reduced in priority in emergency situations. These functions are mainly used to monitor and record the daily operation of the system to facilitate traceability and analysis in case of problems, but they are not the key factors to ensure vehicle safety when the vehicle is in a high-risk working condition. The safe working condition range refers to the value range of the parameters of each key system and component of the vehicle in the normal running process, when each indicator in the safe running state signal is within this range, it indicates that the vehicle is in a safe running condition, and no additional emergency safety measures are needed. High-strength encryption algorithm is an encryption algorithm with high security and complexity, which can provide stronger data protection capability to prevent data from being stolen or tampered with during transmission and storage. High-strength encryption algorithms usually require more computing resources and time to complete encryption and decryption operations, and are suitable for scenarios with high data security requirements, such as RSA, ECC (Elliptic Curve Encryption), AES-256, etc.
[0125] Step C03, encapsulating the recombined data frame into standardized data of a standardized universal data format.
[0126] It should be noted that encapsulating the recombined data frame into standardized data of a standardized universal data format involves further packaging and organizing the recombined data frame according to the requirements of the universal format, adding some necessary metadata information such as data source, timestamp, data type, etc.
[0127] In this embodiment, by mapping the core parameters into a standard data frame structure, the preliminary standardization and unification of data are achieved. The core parameters collected by different sensors may have different data formats and lengths, but after mapping, they all follow a unified standard data frame structure, which facilitates subsequent processing and transmission. At the same time, the definition of each field in the standard data frame structure is clear, making data parsing and understanding easier and improving data readability and maintainability. By monitoring the bus load state in real time, the system can learn about the running status of the bus in a timely manner, providing a basis for subsequent transmission rate adjustment. By dynamically adjusting the transmission rate according to the bus load state, load balancing of the bus can be achieved, improving the utilization of the bus and the overall performance of the system. At the same time, data loss and transmission errors caused by bus congestion are avoided, ensuring reliable data transmission. The embedded error detection code based on the hash algorithm can effectively detect whether errors have occurred in the data during transmission. Since the hash algorithm has uniqueness and sensitivity, even if only one bit in the data changes, the calculated hash value will also change greatly. Therefore, by comparing the hash values calculated by the sender and the receiver, data transmission errors can be detected in a timely manner, and appropriate measures such as retransmission can be taken to improve the reliability of data transmission.
[0128] It should be noted that the above examples are only for understanding the present application and do not constitute a limitation on the data processing method of the present application. More forms of simple changes based on this technical concept are within the scope of protection of the present application.
[0129] The present application also provides a data processing system, please refer to Figure 4 The data processing system comprises:
[0130] The identity authentication module 10 is configured to perform digital certificate authentication on the external device in response to an external device access signal.
[0131] The permission allocation module 20 is configured to allocate corresponding operation permissions to the external device based on a preset permission policy if the digital certificate authentication on the external device is passed.
[0132] The data interaction module 30 is used to extract the core parameters of the data to be transmitted when interacting with external devices, convert the core parameters into a standardized general data format to obtain standardized data, encrypt the standardized data and transmit it to the external device.
[0133] Optionally, the identity authentication module 10 is also used for:
[0134] Receive encrypted digital certificates sent by external devices, decrypt the encrypted digital certificates based on asymmetric decryption algorithms to obtain the target digital certificate, and verify the validity and integrity of the target digital certificate;
[0135] If the target digital certificate is valid and complete, extract the target device identifier from the target digital certificate and match and verify it with the preset device physical feature code;
[0136] If the target device identifier matches the preset device physical signature code, the digital certificate authentication of the external device is deemed successful.
[0137] Optionally, the permission allocation module 20 is also used for:
[0138] Determine the device type corresponding to the external device;
[0139] When the device type is a diagnostic device, data read and write permissions, excluding critical control command fields, are assigned to the external device based on a preset permission policy.
[0140] When the device type is a mobile device, non-security data access permissions are assigned to external devices based on preset permission policies, and the scope of real-time location information acquisition is restricted.
[0141] When the device type is an entertainment device, multimedia data stream access permissions and media control command execution permissions are assigned to external devices based on preset permission policies.
[0142] Optionally, the data processing system further includes an unauthorized access detection module 40, which is used for:
[0143] Real-time monitoring of data operation command streams issued by external devices, and extraction of behavioral characteristics of the data operation command streams;
[0144] The behavioral characteristics are compared with a preset set of legal operation modes to determine whether there is any unauthorized behavior in the data operation instruction stream.
[0145] If unauthorized behavior occurs in the data operation command stream, the execution process of the data operation command stream will be terminated, and the security trust level of the external device will be adjusted according to the severity of the unauthorized behavior and historical violation records.
[0146] Optionally, the unauthorized access detection module 40 is also used for:
[0147] identify the type of the unauthorized behavior, and query the historical violation records of the external device to count the cumulative violation frequency of the external device;
[0148] in the case that the type of the unauthorized behavior is a critical control domain unauthorized behavior or the cumulative violation frequency reaches a preset cumulative number of times, the security trust level of the external device is reduced to the lowest level, and the external device is marked as permanently blocked;
[0149] in the case that the type of the unauthorized behavior is a non-critical control domain unauthorized behavior and the cumulative violation frequency does not reach the preset cumulative number of times, the sensitivity of the unauthorized behavior associated data field is determined, the sensitive data field with a sensitivity reaching a preset sensitivity threshold is screened, the access channel of the sensitive data field is closed, and the security trust level of the external device is reduced by one level.
[0150] Optionally, the core parameters include power control parameters, chassis state parameters and safety information parameters, and the data interaction module 30 is further configured to:
[0151] extract a length identifier of the to-be-transmitted data based on a preset protocol feature template library;
[0152] segment a binary data stream in the to-be-transmitted data into discrete data packets based on the length identifier;
[0153] screen the power control parameters, the chassis state parameters and the safety information parameters in the discrete data packets.
[0154] Optionally, the data interaction module 30 is further configured to:
[0155] map the core parameters into a standard data frame structure;
[0156] monitor a bus load state in real time, adjust a transmission rate of the standard data frame structure according to the bus load state, and embed an error detection code based on a hash algorithm into a frame tail of the standard data frame structure to obtain a reorganized data frame;
[0157] encapsulate the reorganized data frame into standardized data of a standardized universal data format.
[0158] The data processing system provided in the application adopts the data processing method in the above embodiments, and can solve the technical problem of poor data processing effect. Compared with the prior art, the data processing system provided in the application has the same beneficial effects as the data processing method provided in the above embodiments, and other technical features in the data processing system are the same as the features disclosed in the above embodiments, which will not be repeated here.
[0159] The application provides an electronic device, comprising: at least one processor; and a memory connected with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the data processing method in the above embodiment one.
[0160] Reference is made below in conjunction with Figure 5 which shows a structural schematic diagram of an electronic device suitable for implementing the embodiments of the application. The electronic device in the embodiments of the application can include, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a PAD (Portable Application Description: tablet computer), a vehicle-mounted terminal (for example, a vehicle-mounted navigation terminal), and the like, and a fixed terminal such as a digital TV, a desktop computer, and the like. Figure 5 The electronic device shown is merely an example and should not bring any limitation to the functions and use range of the embodiments of the application.
[0161] As Figure 5 shown, the electronic device can include a processing apparatus 1001 (for example, a central processor, a graphics processor, and the like) which can perform various appropriate actions and processes according to programs stored in a read-only memory 1002 or loaded from a storage apparatus 1003 into a random access memory 1004. In the random access memory 1004, various programs and data required for operation of the electronic device are also stored. The processing apparatus 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. An input / output interface 1006 is also connected to the bus. Generally, the following systems can be connected to the input / output interface 1006: an input apparatus 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, and the like; an output apparatus 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; the storage apparatus 1003 including, for example, a magnetic tape, a hard disk, and the like; and a communication apparatus 1009. The communication apparatus 1009 can allow the electronic device to perform wireless or wired communication with other devices to exchange data. Although the electronic device with various systems is shown in the figure, it should be understood that all the systems shown are not required to be implemented or possessed. More or fewer systems can be alternatively implemented or possessed.
[0162] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the method shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network through a communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiments disclosed in the present application are executed.
[0163] The electronic device provided by the present application adopts the data processing method in the above-mentioned embodiments, and can solve the technical problem of poor data processing effect. Compared with the prior art, the electronic device provided by the present application has the same beneficial effects as the data processing method provided by the above-mentioned embodiments, and other technical features in the electronic device are the same as the features disclosed in the previous embodiment method, which will not be repeated here.
[0164] It should be understood that parts of the present application can be realized by hardware, software, firmware or a combination thereof. In the description of the above-mentioned embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0165] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0166] The present application provides a computer readable storage medium having stored thereon computer readable program instructions (i.e. computer program) for executing the data processing method in the above-mentioned embodiments.
[0167] The computer readable storage medium provided in the application may be, for example, a U disk, but is not limited to an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system or device, or any combination of the above. More specific examples of the computer readable storage medium may include, but are not limited to, an electric connection with one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiment, the computer readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system or device. The program code contained on the computer readable storage medium can be transmitted by any suitable medium, including but not limited to an electric wire, an optical cable, an RF (Radio Frequency), and the like, or any suitable combination of the above.
[0168] The computer readable storage medium described above may be contained in an electronic device, or may exist separately without being assembled into an electronic device.
[0169] The computer readable storage medium described above carries one or more programs, which, when executed by the electronic device, cause the data processing device to: in response to an external device access signal, perform digital certificate authentication on the external device; in the case that the external device passes the digital certificate authentication, assign the external device corresponding operation permissions based on a preset permission policy; in the case of data interaction with the external device, extract core parameters of the data to be transmitted, convert the core parameters into a standardized universal data format to obtain standardized data, encrypt the standardized data, and transmit the encrypted standardized data to the external device.
[0170] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0171] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0172] The modules involved in the embodiments of the present application can be implemented in the manner of software or hardware. Among them, the name of the module does not constitute the limitation of the unit itself in some cases.
[0173] The readable storage medium provided by the present application is a computer readable storage medium, which stores computer readable program instructions (i.e. computer program) for executing the above-mentioned data processing method, and can solve the technical problem of poor data processing effect. Compared with the prior art, the computer readable storage medium provided by the present application has the same beneficial effects as the data processing method provided by the above-mentioned embodiments, which will not be repeated here.
[0174] The application further provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of the data processing method as described above.
[0175] The computer program product provided by the application can solve the technical problem of poor data processing effect. Compared with the prior art, the beneficial effects of the computer program product provided by the application are the same as those of the data processing method provided by the above-mentioned embodiments, and are not described here.
[0176] The above only describes some embodiments of the application, and does not limit the patent scope of the application. Any equivalent structural transformation, direct / indirect application in other related technical fields, or direct / indirect application in other related technical fields based on the technical concept of the application and the content of the specification and drawings are included in the patent protection scope of the application.
Claims
1. A data processing method, characterized by, The data processing method comprises: In response to an external device access signal, performing digital certificate authentication on the external device; In the case where the digital certificate authentication of the external device is passed, assigning corresponding operation permissions to the external device based on a preset permission policy; In the case of data interaction with the external device, extracting core parameters of to-be-transmitted data, converting the core parameters into a standardized universal data format to obtain standardized data, encrypting the standardized data, and transmitting the standardized data to the external device.
2. The data processing method of claim 1, wherein, The step of performing digital certificate authentication on the external device comprises: Receiving an encrypted digital certificate sent by the external device, decrypting the encrypted digital certificate based on an asymmetric decryption algorithm to obtain a target digital certificate, and verifying the validity and integrity of the target digital certificate; In the case where the target digital certificate is valid and complete, extracting a target device identifier of the target digital certificate and performing matching verification with a preset device physical feature code; In the case where the target device identifier matches the preset device physical feature code, determining that the digital certificate authentication of the external device is passed.
3. The data processing method of claim 1, wherein, The step of assigning corresponding operation permissions to the external device based on a preset permission policy comprises: Determining the device type corresponding to the external device; In the case where the device type is a diagnostic device, assigning the external device data read-write permissions except for a critical control instruction domain based on the preset permission policy; In the case where the device type is a mobile device, assigning the external device non-safe data access permissions and limiting the acquisition range of real-time location information based on the preset permission policy; In the case where the device type is an entertainment device, assigning the external device multimedia data stream access permissions and media control instruction execution permissions based on the preset permission policy.
4. The data processing method of claim 3, wherein, The step of assigning corresponding operation permissions to the external device based on a preset permission policy further comprises: Real-time monitoring of data operation instruction streams issued by the external device, and extracting behavior characteristics of the data operation instruction streams; Comparing the behavior characteristics with a preset legal operation mode set to determine whether the data operation instruction streams have an overreach behavior; In the case where the data operation instruction streams have an overreach behavior, terminating the execution process of the data operation instruction streams, and adjusting the security trust level of the external device according to the severity of the overreach behavior and historical violation records.
5. The data processing method of claim 4, wherein, The step of adjusting the security trust level of the external device according to the severity of the overreach behavior and historical violation records comprises: Identifying the overreach type of the overreach behavior, and querying the historical violation records of the external device to count the cumulative violation frequency of the external device; In the case where the overreach type is a critical control domain overreach or the cumulative violation frequency reaches a preset cumulative number of times, lowering the security trust level of the external device to the lowest level, and marking the external device as permanently blocked. In a case where the overreach type is non-critical control domain overreach and the accumulated violation frequency does not reach the preset accumulated number of times, a sensitive degree of the overreach behavior associated data field is determined, sensitive data fields with a sensitive degree reaching a preset sensitive threshold are screened, an access channel of the sensitive data fields is closed, and a security trust level of the external device is reduced by one level.
6. The data processing method of claim 1, wherein, The core parameters include power control parameters, chassis state parameters, and safety information parameters, and the step of extracting the core parameters of the to-be-transmitted data includes: Based on a preset protocol feature template library, a length identifier of the to-be-transmitted data is extracted; Based on the length identifier, binary data streams in the to-be-transmitted data are segmented into discrete data packets; Power control parameters, chassis state parameters, and safety information parameters in the discrete data packets are screened.
7. The data processing method of claim 1, wherein, The step of converting the core parameters into standardized universal data formats to obtain standardized data includes: The core parameters are mapped into a standard data frame structure; A bus load state is monitored in real time, a transmission rate of the standard data frame structure is adjusted according to the bus load state, and an error detection code based on a hash algorithm is embedded into a frame tail of the standard data frame structure to obtain a reorganized data frame; The reorganized data frame is packaged into standardized data in a standardized universal data format.
8. An electronic device, comprising: The device includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the data processing method according to any one of claims 1 to 7.
9. A storage medium, characterized by The storage medium is a computer readable storage medium, and the storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the data processing method according to any one of claims 1 to 7.
10. A computer program product, characterised in that, The computer program product includes a computer program, and the computer program is executed by a processor to implement the steps of the data processing method according to any one of claims 1 to 7.