Automotive Gateway CAN Upgrade Security Rollback Decision Management Method and System
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-10
- Publication Date
- 2026-04-03
AI Technical Summary
Existing technologies make it difficult to accurately identify the correlation between abnormal states caused by transient interference and overall compliance during the CAN upgrade process of automotive gateways. This leads to inaccurate rollback decisions and may result in misjudging security risks during the upgrade process or failing to detect persistent minor anomalies in a timely manner.
By receiving software update packages, parsing operational status parameters, generating sector determination areas and closed monitoring trajectories, calculating status calibration coefficients, calibrating verification parameters of the security status summary, generating compliance verification results, and automatically triggering rollback operations when non-compliance occurs.
It enhances the security of the online upgrade process for automotive gateways, accurately identifies security risks in software update packages, avoids verification errors caused by parameter deviations, and enables early identification and warning of potential risks.
Smart Images

Figure CN121070408B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method and system for managing the safe rollback decision of automotive gateway CAN upgrades. Background Technology
[0002] During State Over-The-Air (SOTA) software updates, automotive gateways typically receive software update packages via the CAN bus and perform upgrade operations. Existing technologies generally rely on preset security state summaries to determine version compliance and consider performing rollback operations when anomalies are detected. Due to the dynamic and complex nature of the in-vehicle network environment, existing methods may struggle to accurately distinguish the correlation between some abnormal states and overall compliance when determining whether the software state meets security requirements, potentially affecting the accuracy of rollback decisions. Specifically, existing technologies rely heavily on fixed thresholds or static verification parameters for evaluating software operating states, lacking effective tracking and calibration mechanisms for dynamic changes in operating states. For example, during SOTA upgrades of in-vehicle entertainment software, if the vehicle passes through an area with strong signal interference, causing some operating parameters to fluctuate momentarily and exceed preset thresholds, existing methods may sometimes fail to accurately identify the anomaly as being caused by momentary interference, potentially leading to a misjudgment of security risks during the upgrade process and triggering a rollback operation. Alternatively, they may fail to detect some genuine, persistent, minor anomalies in a timely manner. Summary of the Invention
[0003] The technical problem to be solved by this invention is to provide a method and system for safe rollback decision management of CAN upgrades for automotive gateways, which can effectively identify the security risks of software update packages and automatically trigger a fast and reliable rollback operation when verification fails, thereby improving the security of the online upgrade process of automotive gateways.
[0004] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows:
[0005] Firstly, a method for managing the safe rollback decision of a vehicle gateway CAN upgrade, the method comprising:
[0006] Step 1: Receive the software update package transmitted via the CAN bus. The software update package contains a security status summary.
[0007] Step 2: Parse the software update package, extract the running status parameters of the software update package, and convert the running status parameters into a set of running status data nodes;
[0008] Step 3: Determine the data reference center based on the set of running status data nodes, establish two reference direction vectors according to the data reference center, calculate the angle between the two reference direction vectors, and generate the sector determination area.
[0009] Step 4: Select the first observation point within the sector determination area and the second observation point outside the sector determination area. Generate a closed monitoring trajectory based on the chronological relationship between the first and second observation points in the time series.
[0010] Step 5: Calculate the state calibration coefficient based on the closed monitoring trajectory; use the state calibration coefficient to calibrate the verification parameters of the safety status summary, and verify the safety status summary to generate a compliance verification result;
[0011] Step 6: Make a rollback decision based on the compliance verification results. If the compliance verification results show that the requirements are not met, generate a rollback instruction.
[0012] Step 7: Based on the rollback command, block the installation process of the software update package and control the gateway to load the most recent compliant software version from the gateway storage area to achieve version rollback.
[0013] Secondly, the automotive gateway CAN upgrade security rollback decision management system includes:
[0014] The acquisition module is used to receive software update packages transmitted via the CAN bus. The software update packages contain a security status summary.
[0015] The parsing module is used to parse the software update package, extract the running status parameters of the software update package, and convert the running status parameters into a set of running status data nodes.
[0016] The calculation module is used to determine the data reference center based on the set of running status data nodes, establish two reference direction vectors based on the data reference center, calculate the angle between the two reference direction vectors, and generate the sector determination area.
[0017] The selection module is used to select a first observation point within the sector determination area and a second observation point outside the sector determination area, and to generate a closed monitoring trajectory based on the chronological relationship between the first and second observation points in the time series.
[0018] The calibration module is used to calculate the state calibration coefficient based on the closed monitoring trajectory; to calibrate the verification parameters of the safety status summary using the state calibration coefficient, and to verify the safety status summary and generate compliance verification results.
[0019] The decision module is used to make rollback decisions based on the compliance verification results. If the compliance verification results show that the requirements are not met, a rollback instruction is generated.
[0020] The execution module is used to block the installation process of software update packages and control the gateway based on rollback instructions, load the most recent compliant software version from the gateway storage area, and realize version rollback.
[0021] Thirdly, a computing device includes:
[0022] One or more processors;
[0023] A storage device for storing one or more programs that, when executed by one or more processors, cause the one or more processors to implement the method.
[0024] Fourthly, a computer-readable storage medium storing a program that, when executed by a processor, implements the method.
[0025] The above-described solution of the present invention has at least the following beneficial effects:
[0026] By converting operational status parameters into a set of data nodes and constructing a dynamic sector determination region and closed monitoring trajectory, this method can accurately calculate the status calibration coefficient, thereby effectively calibrating the verification parameters of the security summary. This improves the accuracy of security status verification and the ability to identify potential risks, avoiding verification errors caused by parameter deviations. Based on the analysis of the closed monitoring trajectory with spatiotemporal relationships, this method can capture the dynamic change trend of the software update package's operational status, enabling early identification and warning of potential security risks. Attached Figure Description
[0027] Figure 1 This is a schematic diagram of the automotive gateway CAN upgrade security rollback decision management method provided in an embodiment of the present invention.
[0028] Figure 2 This is a schematic diagram of the automotive gateway CAN upgrade security rollback decision management system provided in an embodiment of the present invention. Detailed Implementation
[0029] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0030] like Figure 1 As shown, embodiments of the present invention propose a method for managing the secure rollback decision of a vehicle gateway CAN upgrade, the method comprising the following steps:
[0031] Step 1: Receive the software update package transmitted via the CAN bus. The software update package contains a security status summary.
[0032] Step 2: Parse the software update package, extract the running status parameters of the software update package, and convert the running status parameters into a set of running status data nodes;
[0033] Step 3: Determine the data reference center based on the set of running status data nodes, establish two reference direction vectors according to the data reference center, calculate the angle between the two reference direction vectors, and generate the sector determination area.
[0034] Step 4: Select the first observation point within the sector determination area and the second observation point outside the sector determination area. Generate a closed monitoring trajectory based on the chronological relationship between the first and second observation points in the time series.
[0035] Step 5: Calculate the state calibration coefficient based on the closed monitoring trajectory; use the state calibration coefficient to calibrate the verification parameters of the safety status summary, and verify the safety status summary to generate a compliance verification result;
[0036] Step 6: Make a rollback decision based on the compliance verification results. If the compliance verification results show that the requirements are not met, generate a rollback instruction.
[0037] Step 7: Based on the rollback command, block the installation process of the software update package and control the gateway to load the most recent compliant software version from the gateway storage area to achieve version rollback.
[0038] In this embodiment of the invention, by converting the running status parameters into a set of data nodes and constructing a dynamic sector determination area and a closed monitoring trajectory, the method can accurately calculate the status calibration coefficient, thereby effectively calibrating the verification parameters of the security summary. This improves the accuracy of security status verification and the ability to identify potential risks, avoiding verification errors caused by parameter deviations. Based on the analysis of the closed monitoring trajectory with spatiotemporal relationships, the method can capture the dynamic change trend of the running status of the software update package, and realize early identification and warning of potential security risks.
[0039] In a preferred embodiment of the present invention, step 1 involves receiving a software update package transmitted via the CAN bus. The software update package contains a security status digest. Specifically, the vehicle gateway receives the software update package through its built-in CAN bus interface. These update packages originate from a remote server or the vehicle control unit and are transmitted via differential signals on the CAN bus. During reception, the gateway performs frame verification on each transmitted data packet. Specifically, it checks whether the frame start bit conforms to the 0-to-1 transition rule, whether the frame end bit consists of seven consecutive dominant bits, and verifies whether the cyclic redundancy check (CRC) code matches the data packet content, ensuring that no bytes are lost or bit flips occur during transmission. This software update package is used to upgrade a specific electronic control unit of the vehicle, such as the body control module or powertrain control unit. The security status digest within the package is a structured collection of information, including the major and minor version numbers of the software, a security check value based on the SHA256 algorithm, and a declaration of the current encryption key's validity and expiration date.
[0040] This embodiment avoids verification errors caused by corrupted update packages or missing critical security information by performing frame verification and clarifying the content of the security status summary when receiving software update packages, thus adapting to the dynamic environment in which data transmission in vehicular networks may be interfered with.
[0041] In a preferred embodiment of the present invention, step 2, parsing the software update package, extracting the running status parameters of the software update package, and converting the running status parameters into a set of running status data nodes, may include:
[0042] Step 201: Perform data packet parsing on the software update package to extract the security status summary and operating status parameters. Classify and organize the operating status parameters to generate a set of operating status parameters. Specifically, the vehicle gateway uses its built-in data packet parsing function to parse the software update package according to the 2.0B frame format specified by the CAN bus protocol. During parsing, first read the frame ID, and determine the functional domain of the data based on the high 7 bits of the frame ID. For example, if the high 7 bits are 0x100, it corresponds to power-related data. Then, extract information layer by layer from the data field, first separating the security status summary and storing it in the gateway's encrypted storage partition, while simultaneously extracting the operating status parameters. These parameters include the real-time load rate of the processor during software runtime, i.e., the ratio of the current processor time to the total time per unit of time; and memory usage, i.e., the amount of memory used and the amount of memory consumed. The parameters include: the proportion of total memory space; the one-way latency when communicating with other control units, i.e., the time interval from sending a data request to receiving a feedback response; the data transmission error rate, i.e., the ratio of the total number of bit errors, stuffing errors, and CRC errors to the total number of data frames transmitted; and the response time of critical functions such as security verification, i.e., the time from receiving an authentication request to returning an authentication result. The gateway categorizes parameters based on their associated functional attributes, classifying processor load rate and memory usage as hardware resources, as these directly reflect the utilization of ECU hardware resources; classifying communication latency and data transmission error rate as bus communication, as these are directly related to the communication quality of the CAN bus; and classifying security verification response time as security functions, as these involve core information security functions. This classification forms a set of operating status parameters.
[0043] Step 202: Standardize the various parameters in the operational status parameter classification set to generate a standardized parameter data sequence; map the standardized parameter data sequence into data nodes with spatial coordinate characteristics to generate an operational status data node set. Specifically, taking hardware resource parameters as an example, the gateway first retrieves records of this type of parameter from its own historical database during the past 50 normal upgrades, and filters out the minimum processor load rate of 20% and the maximum of 90%, and the minimum memory usage of 10% and the maximum of 80%. For the currently collected processor load rate of 40%, subtract 20% from 40% to get 20%, then divide this difference by the difference of 90% minus 20% (70%) to calculate a standardized value of approximately 0.29; for the currently collected memory usage of 30%, subtract 20% from 30% to get a standardized value of approximately 0.29. The difference is reduced by 10% to 20%. This difference is then divided by 80% minus the 10% difference (70%) to obtain a standardized value of approximately 0.29. This transforms the values of these parameters to between 0 and 1, forming a standardized parameter data sequence. The gateway maps each type of standardized parameter to a spatial data node. For example, the hardware resource category includes two parameters: processor load rate and memory usage. The standardized values of these two parameters are used as the x-axis and y-axis coordinates of a point in two-dimensional space, respectively, i.e., (0.29, 0.29). If the bus communication category includes three parameters: communication latency, data transmission error rate, and bus load rate, the standardized values of these three parameters are used as the x-axis, y-axis, and z-axis coordinates of a point in three-dimensional space, respectively. In this way, all categories of parameters are converted into spatial nodes, generating a set of running status data nodes.
[0044] In this embodiment, standardization eliminates the dimensional differences between parameters, allowing different types of parameters to be analyzed in the same dimension, while spatial coordinate mapping transforms abstract parameter data into intuitive spatial nodes, solving the problem that static parameter evaluation is difficult to adapt to dynamic changes.
[0045] In a preferred embodiment of the present invention, step 3, determining a data reference center based on the set of running status data nodes, establishing two reference direction vectors based on the data reference center, calculating the angle between the two reference direction vectors, and generating a sector determination region, may include:
[0046] Step 301: Collect the coordinate data of each data node in the running status data node set to generate a node coordinate dataset; calculate the weighted average of all coordinate values in the node coordinate dataset to obtain the data distribution centroid, and use the data distribution centroid as the data reference center. Specifically, the vehicle gateway extracts the coordinate data of each node from the running status data node set. For example, the coordinates of hardware resource nodes are (0.29, 0.29), the coordinates of bus communication nodes are (0.4, 0.3, 0.5), and the coordinates of safety function nodes are (0.35, 0.4). Each dimension of these coordinates corresponds to the standardized value of a specific parameter. After summarizing, a node coordinate dataset is formed. The gateway calculates the data distribution centroid. Before the calculation, weights are assigned to different dimensions. The dimension containing the safety function parameters is directly related to information security, and its weight ranges from 0.6 to 0.8. The weights of the dimensions containing the parameters range from 0.2 to 0.4. In this process, the weight of the security function dimension is 0.7, and the weights of the hardware resource and bus communication dimensions are 0.3. Taking the processor load rate of the hardware resource dimension on the x-axis as an example, there are five nodes with coordinate values of 0.29, 0.35, 0.4, 0.32, and 0.38. Multiplying each coordinate value by the weight 0.3 yields 0.087, 0.105, 0.12, 0.096, and 0.114. Adding these products together gives a total of 0.522. Dividing this total by the total weight of this dimension (i.e., 0.3 multiplied by 5, resulting in 1.5) gives the average coordinate value of the x-axis, 0.348. The same method is used to calculate the average coordinate values of other dimensions, such as memory usage on the y-axis and response time of security verification functions on the z-axis. The average coordinate values of all dimensions together constitute the centroid of the data distribution, which is determined as the data reference center.
[0047] Step 302: Establish a reference coordinate system with the data reference center as the origin. Within this reference coordinate system, select two different directions to construct a first reference direction vector and a second reference direction vector. Specifically, the vehicle gateway establishes a reference coordinate system with the data reference center as the origin. The x-axis corresponds to the dimension of hardware resource parameters, encompassing standardized values of processor load rate and memory usage; the y-axis corresponds to the dimension of bus communication parameters, encompassing standardized values of communication latency, data transmission error rate, and bus load rate; the z-axis corresponds to the dimension of security function parameters, encompassing standardized values of security verification function response time and key verification time. Within this reference coordinate system, the gateway selects two different directions to construct reference direction vectors. The first vector is selected from the most... The first reference direction vector reflects the direction of load changes, pointing from the origin to the normal load node that appears most frequently in the historical operation record. The coordinates of this node are (0.5, 0.4, 0.3), which corresponds to the normalized values of processor load rate (0.5), memory usage (0.4), and security check function response time (0.3). The second reference direction vector is selected from the direction that best reflects communication stability in bus communication, pointing from the origin to the stable node with the lowest communication error rate and the lowest latency in the historical operation record. The coordinates of this node are (0.3, 0.2, 0.3), which corresponds to the normalized values of communication latency (0.3), data transmission error rate (0.2), and security check function response time (0.3). The second reference direction vector is formed by this.
[0048] Step 303: Based on the spatial geometric relationship between the two reference direction vectors, the spatial azimuth angle between the two reference direction vectors is calculated using vector dot product operation to generate the sector determination region. Specifically, the components of the first reference direction vector are x1 = 0.5, y1 = 0.4, and z1 = 0.3, and the components of the second reference direction vector are x2 = 0.3, y2 = 0.2, and z2 = 0.3. The calculation first involves finding the dot product of the two vectors: x1 multiplied by x2 equals 0.15, y1 multiplied by y2 equals 0.08, and z1 multiplied by z2 equals 0.09. These three results are then added together to obtain the total dot product value of 0.32. Next, the magnitudes of the two vectors are calculated separately. The magnitude of the first vector is calculated as the square of x1, which is 0.2. 5. The squares of y1 (0.16) and z1 (0.09) are added together to get a total of 0.5. The square root of this sum gives a modulus of approximately 0.707. The modulus of the second vector is calculated by adding the squares of x2 (0.09), y2 (0.04), and z2 (0.09) to get a total of 0.22. The square root of this sum gives a modulus of approximately 0.47. The total dot product of 0.32 is divided by the product of the moduli of the two vectors, i.e., 0.707 multiplied by 0.47, which gives approximately 0.332. This yields a cosine of the angle of approximately 0.964. Based on the relationship between the cosine and the angle, the spatial orientation angle between the two vectors is approximately 15 degrees. The sector formed by this 15-degree angle in the reference coordinate system is the sector determination region.
[0049] In this embodiment, a weighted average data reference center is calculated, and the weights of parameter importance are combined to enable the center to more accurately reflect the parameter distribution characteristics during normal software operation.
[0050] In a preferred embodiment of the present invention, step 4, selecting a first observation point within the sector determination area and a second observation point outside the sector determination area, and generating a closed monitoring trajectory based on the temporal relationship between the first and second observation points, may include:
[0051] Step 401: Based on the boundary range of the sector determination area, select the location point closest to the data reference center within the sector determination area as the first observation point; based on the location coordinates of the first observation point, select the location point outside the sector determination area with the maximum distance from the first observation point as the second observation point. Specifically, this includes: based on the boundary coordinate range of the sector determination area (e.g., x-axis 0 to 1, y-axis 0 to 1 in two-dimensional coordinates, and additional z-axis 0 to 1 in three-dimensional coordinates), the automotive gateway first obtains the coordinates of all operating status data nodes within the area, typically 10 to 20 nodes; calculates the spatial distance between each node and the data reference center. If it is a three-dimensional coordinate (covering hardware resources, bus communication, and security function dimensions), the calculation method is to subtract the x-axis coordinate of the node. The x-dimensional difference is obtained by subtracting the reference center's y-axis coordinate from the node's y-axis coordinate, and the z-dimensional difference is obtained by subtracting the reference center's y-axis coordinate from the node's z-axis coordinate. The squares of the differences in the x, y, and z dimensions are added together, and the square root of the sum is taken to obtain the distance value from each node to the reference center. From these distance values (usually ranging from 0.05 to 0.5), the smallest distance value (e.g., 0.08) is selected, and the corresponding node is the first observation point. The gateway obtains the operating status data nodes outside the sector determination area (usually 8 to 15 in number), calculates the spatial distance between each external node and the first observation point in the same way, and selects the external node corresponding to the largest distance value (usually ranging from 0.6 to 1.2) to determine the second observation point.
[0052] Step 402: Collect position data of the first and second observation points over a continuous time series to generate a movement trajectory data set. Based on the time sequence of each position point in the movement trajectory data set, connect adjacent position points sequentially to obtain a continuous trajectory path. Specifically, this includes: collecting the position coordinates of the first and second observation points at fixed time intervals, with the time interval ranging from 50 milliseconds to 200 milliseconds; in this process, 100 milliseconds is selected as the collection interval. The preset number of continuous collections ranges from 30 to 80 times; in this process, 50 times is selected as the collection interval. The data collection process involves several steps: During data collection, a timestamp accurate to milliseconds is recorded for each coordinate. The 50 collected coordinate sets are arranged chronologically to generate a motion trajectory data set. Adjacent coordinates are connected by straight lines in chronological order. For example, if the first collected coordinates are 0.29, 0.29, 0.3, and the second collected coordinates are 0.3, 0.3, 0.31, these two sets of coordinates are connected. Then, the coordinates from the second and third collected coordinates are connected, and so on, until all 50 sets of coordinates are connected, ultimately forming a continuous trajectory path.
[0053] Step 403: Connect the starting and ending points of the continuous trajectory path to generate a closed monitoring trajectory. Specifically, this includes: identifying the starting and ending points of the continuous trajectory path, where the starting point is the coordinate of the first acquisition and the ending point is the coordinate of the 50th acquisition; connecting the starting and ending points directly with a straight line to form a closed polygon from the original linear trajectory. The number of vertices of this polygon is consistent with the number of acquisitions, which is 50. The trajectory corresponding to this closed polygon is the closed monitoring trajectory.
[0054] This embodiment ensures comprehensive coverage of monitoring points and timely capture of dynamic data by specifying the number of nodes, collection intervals, and number of times. It adapts to the fluctuation characteristics of vehicle network parameters and avoids misjudgments caused by single static data.
[0055] In a preferred embodiment of the present invention, step 5, calculating the state calibration coefficient based on the closed monitoring trajectory; calibrating the verification parameters of the safety state summary using the state calibration coefficient, and verifying the safety state summary to generate a compliance verification result, may include:
[0056] Step 501: Analyze the closed monitoring trajectory to obtain the area of the region enclosed by the closed monitoring trajectory and the total path length of the closed monitoring trajectory; calculate the ratio of the area to the total path length to obtain the trajectory complexity index; obtain a pre-established calibration benchmark set, which contains multiple trajectory complexity reference values and corresponding calibration adjustment amounts, specifically including: analyzing the closed monitoring trajectory, extracting the coordinates of 50 vertices on the trajectory, and sorting these coordinates according to the acquisition order; substituting the sorted coordinates into the polygon area calculation formula, taking two adjacent vertices in sequence during the calculation, such as vertex 1 with coordinates x1, y1, z1, and vertex 2 with coordinates x2, y2, z2, and subtracting the result of x2 multiplied by y1 from the result of x1 multiplied by y2; taking vertex 2 and vertex 3, subtracting the result of x3 multiplied by y2 from the result of x2 multiplied by y3, and so on until all 50 vertices have been processed. Calculate vertex 1; sum all the calculation results, take the absolute value of the sum and divide by 2 to obtain the area enclosed by the closed monitoring trajectory. The area ranges from 0.02 square meters to 0.1 square meters, and the specific value will vary depending on the coordinate range. At the same time, calculate the total path length of the closed monitoring trajectory. The calculation method is the same as the spatial distance calculation method in step 401. First, calculate the straight-line distance between each adjacent vertex segment. For example, the distance between the first segment and the second segment is 0.015, and the distance between the second segment and the third segment is 0.012. Then, sum up the distances of 50 segments to obtain the total path length. The total path length ranges from 0.5 meters to 1.5 meters. Divide the area enclosed by the closed monitoring trajectory by the total path length to obtain the trajectory complexity index. The trajectory complexity index ranges from 0.4 to 1.2. In this process, the index value is 0.65.
[0057] The vehicle gateway acquires a pre-established calibration benchmark set, which requires three steps to establish. The first step involves collecting trajectory data recorded during the past 1000 software updates, selecting nine sets of data with trajectory complexities of 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, 1.0, 1.1, and 1.2, each set containing at least 500 trajectory records corresponding to its complexity. The second step calculates the parameter deviation for each set of data. First, the standard parameter values during normal software operation are determined. Then, the actual parameter values for each trajectory in each set are subtracted from the standard parameter values to obtain the deviation of a single trajectory. The deviations of all single trajectories within a set are summed and divided by the number of trajectories to obtain the average deviation for that set. The third step calculates the calibration adjustment amount based on the average deviation, which is the average deviation multiplied by 0.4. (The coefficients are determined based on the interference intensity test in the vehicle environment). Calculations show that the average deviation for a complexity of 0.4 is 0.2, multiplied by 0.4 to get 0.08; for 0.5, the average deviation is 0.25, multiplied by 0.4 to get 0.1; for 0.6, the average deviation is 0.3, multiplied by 0.4 to get 0.12; for 0.7, the average deviation is 0.35, multiplied by 0.4 to get 0.14; for 0.8, the average deviation is 0.4, multiplied by 0.4 to get 0.16; for 0.9, the average deviation is 0.45, multiplied by 0.4 to get 0.18; for 1.0, the average deviation is 0.5, multiplied by 0.4 to get 0.2; for 1.1, the average deviation is 0.525, multiplied by 0.4 to get 0.21; and for 1.2, the average deviation is 0.55, multiplied by 0.4 to get 0.22. This forms a unique calibration adjustment amount corresponding to each reference value.
[0058] Step 502: Match the trajectory complexity index with the trajectory complexity reference values in the calibration benchmark set to obtain the corresponding calibration adjustment amount; synthesize the calibration adjustment amount with the preset benchmark calibration value to obtain the state calibration coefficient. Specifically, this includes: comparing the calculated trajectory complexity index 0.65 with the trajectory complexity reference values in the calibration benchmark set one by one, finding the two reference values closest to 0.65, which are 0.6 and 0.7; extracting the calibration adjustment amount corresponding to these two reference values, the adjustment amount corresponding to 0.6 is 0.12, and the adjustment amount corresponding to 0.7 is 0.14. Add these two adjustment amounts and divide by 2, that is, the sum of 0.12 and 0.14 divided by 2, to obtain the result 0.13. The result is used as the calibration adjustment amount; a composite calculation is performed, with the weight of the calibration adjustment amount ranging from 0.2 to 0.4, and 0.3 is selected as the weight in this process; the preset reference calibration value ranges from 0.4 to 0.6, and 0.5 is selected as the reference calibration value in this process; the weight of the reference calibration value is 1 minus the weight of the calibration adjustment amount, that is, 1 minus 0.3 equals 0.7; the composite calculation method is to multiply the calibration adjustment amount by its weight, and add the reference calibration value multiplied by its weight, that is, the result of 0.13 multiplied by 0.3 plus the result of 0.5 multiplied by 0.7, 0.13 multiplied by 0.3 equals 0.039, 0.5 multiplied by 0.7 equals 0.35, and the two are added together to get 0.389, which is the state calibration coefficient.
[0059] Step 503: Extract the predefined set of verification parameters from the security status digest. Weight and fuse the status calibration coefficient with each parameter in the verification parameter set to generate a calibrated set of verification parameters. Specifically, this includes: extracting the predefined set of verification parameters from the security status digest. This set includes software version consistency, key validity, communication bus authentication status, and compliance policy matching degree. The value of software version consistency ranges from 0.8 to 1.0, and in this process, the value is 0.9; the value of key validity ranges from 0.7 to 1.0, and in this process, the value is 0.92; the value of communication bus authentication status ranges from 0.85 to 1.0, and in this process, the value is 0.95. The matching degree of the compliance policy ranges from 0.8 to 1.0, and in this process, the value of this parameter is 0.98. The status calibration coefficient of 0.389 is weighted and fused with each parameter in the verification parameter set. The fusion method is to multiply the value of each parameter by the status calibration coefficient. For example, the software version consistency parameter value of 0.9 multiplied by 0.389 gives a value of 0.3501 after calibration. The key validity parameter value of 0.92 multiplied by 0.389 gives a value of 0.35788 after calibration. The communication bus authentication status and compliance policy matching degree after calibration are calculated in the same way. All parameters are weighted and fused to generate a calibrated verification parameter set.
[0060] Step 504: Compare each parameter in the calibrated verification parameter set with the security threshold, and comprehensively determine whether the information security status of the software update package is compliant, generating a compliance verification result. Specifically, this includes: the standard threshold for software version consistency ranges from 0.9 to 0.98, with 0.95 selected as the standard threshold in this process; the standard threshold for key validity ranges from 0.85 to 0.95, with 0.9 selected as the standard threshold in this process; the standard threshold for communication bus authentication status ranges from 0.95 to 1.0, with 0.98 selected as the standard threshold in this process; compliance... The standard threshold for policy matching degree ranges from 0.9 to 0.98, and 0.95 was selected as the standard threshold in this process. After comparison, it was found that the calibrated software version consistency value of 0.3501 is less than 0.95, and the calibrated communication bus authentication status value is 0.95 multiplied by 0.389, which equals 0.37055, which is also less than 0.98. The values of the other parameters after calibration all meet the corresponding standard threshold requirements. Based on these comparison results, the information security status of the software update package is determined to be non-compliant, and a compliance verification result including the two non-compliant items of software version consistency and communication bus authentication status is generated.
[0061] This embodiment refines the range of values for complexity indicators, calibration coefficients, and standard thresholds, making parameter calibration more accurate, effectively eliminating interference from the in-vehicle environment, ensuring the accuracy of software security status assessment, and avoiding security vulnerabilities.
[0062] In a preferred embodiment of the present invention, step 6, making a rollback decision based on the compliance verification result, and generating a rollback instruction if the compliance verification result indicates that the requirements are not met, may include:
[0063] Step 601: Analyze the compliance verification results to obtain the deviation values of each verification parameter from the corresponding security threshold; weight the deviation values of each verification parameter from the corresponding security threshold to obtain the comprehensive security deviation index, specifically including: the deviation value of software version consistency is 0.95 minus 0.3501 equals 0.5999. In actual vehicle scenarios, this type of deviation usually does not exceed 0.3, but here the deviation is large after calibration and exceeds the normal range; the deviation value of key validity is 0.9 minus 0.35788 equals 0.54212; the deviation value of communication bus authentication status is 0.98 minus 0.37055 equals 0.60945; the deviation value of compliance policy matching degree is 0.95 minus 0.38122 equals 0.56878; if the parameter calibration value is greater than or equal to the corresponding threshold, the deviation value is taken as 0.
[0064] The weight for software version consistency ranges from 0.3 to 0.5, and 0.4 is selected in this process; the weight for key validity ranges from 0.25 to 0.35, and 0.3 is selected in this process; the weight for communication bus authentication status ranges from 0.15 to 0.25, and 0.2 is selected in this process; the weight for compliance policy matching ranges from 0.05 to 0.15, and 0.1 is selected in this process; when calculating the comprehensive security deviation index, the deviation value of each parameter is multiplied by its corresponding weight, and then all products are added together; specifically, the result of 0.5999 multiplied by 0.4 is added to the result of 0.54212 multiplied by 0.3, the result of 0.60945 multiplied by 0.2 is added to the result of 0.56878 multiplied by 0.1. Among them, 0.5999 multiplied by 0.4 equals 0.23996, 0.54212 multiplied by 0.3 equals 0.162636, 0.60945 multiplied by 0.2 equals 0.12189, and 0.56878 multiplied by 0.1 equals 0.056878. Adding these four results together gives 0.581364, which is the comprehensive safety deviation index.
[0065] Step 602: Compare the comprehensive safety deviation index with the preset first-level safety threshold to obtain the preliminary risk assessment result; based on the preliminary risk assessment result, identify the verification parameters that need further analysis and generate a set of parameters to be assessed; classify the risk level of the set of parameters to be assessed to obtain the risk weight of each parameter, specifically including: comparing the comprehensive safety deviation index 0.581364 with the preset first-level safety threshold, the first-level safety threshold ranges from 0.05 to 0.15, and 0.1 is selected as the threshold in this process; since 0.581364 is greater than 0.1, the preliminary risk assessment result is high risk; based on the preliminary risk assessment result, identify four parameters with deviation values greater than 0, and classify these four parameters as follows: The set of parameters to be evaluated is used to classify the parameters in the set into risk levels. Key validity and communication bus authentication status are directly related to core information security functions and are classified as high-risk, with a weight range of 0.7 to 0.9. In this process, 0.8 is selected as the weight. Software version consistency is related to basic operational stability and is classified as medium-risk, with a weight range of 0.4 to 0.6. In this process, 0.5 is selected as the weight. Compliance policy matching degree has a relatively low impact and is classified as low-risk, with a weight range of 0.2 to 0.4. In this process, 0.3 is selected as the weight. Finally, the risk weights of each parameter are obtained.
[0066] Step 603: Combining the risk weights and deviation values of each parameter, calculate the comprehensive risk assessment value and compare it with the preset second-level security threshold to obtain the final decision result; generate corresponding control instructions based on the final decision result, and generate rollback instructions if rollback is required. Specifically, this includes: calculating the comprehensive risk assessment value by multiplying the deviation value of each parameter in the set of parameters to be evaluated by its corresponding risk weight, and then adding all the products; specifically, the calculation is the result of multiplying the deviation value of key validity (0.54212) by its risk weight (0.8), plus the deviation value of communication bus authentication status (0). The result of multiplying 60945 by its risk weight of 0.8, adding the deviation value of software version consistency of 0.5999 multiplied by its risk weight of 0.5, and adding the deviation value of compliance strategy matching degree of 0.56878 multiplied by its low-risk weight of 0.3, where 0.54212 multiplied by 0.8 equals 0.433696, 0.60945 multiplied by 0.8 equals 0.48756, 0.5999 multiplied by 0.5 equals 0.29995, and 0.56878 multiplied by 0.3 equals 0.170634, the sum of these four results is 1.39184, which is the comprehensive risk assessment value.
[0067] The comprehensive risk assessment value is compared with the preset second-level security threshold. The value of the second-level security threshold is between 0.08 and 0.12. In this process, 0.1 is selected as the threshold. Since 1.39184 is much greater than 0.1, the final decision is that a rollback is required, and a rollback instruction containing the target process identifier 0x001A and the rollback version identifier V2.3.1 is generated.
[0068] This embodiment achieves risk classification assessment by clearly defining the reasonable range of weights and two-level thresholds. This not only prevents minor deviations from triggering unnecessary update interruptions, but also ensures that serious risks are identified in a timely manner, thus balancing security and update efficiency.
[0069] In a preferred embodiment of the present invention, step 7, based on the rollback instruction, blocks the installation process of the software update package and controls the gateway to load the most recent compliant software version from the gateway storage area to achieve version rollback, may include:
[0070] Step 701: Parse the rollback instruction to obtain the target process identifier, terminate the corresponding software update installation process based on the target process identifier, and obtain the released runtime resources. Specifically, this includes: parsing the rollback instruction and extracting the target process identifier 0x001A contained in the instruction, which corresponds to the software update installation process; based on the target process identifier, the gateway terminates the corresponding software update installation process; during the termination process, the runtime resources occupied by the process are released, where the CPU utilization rate ranges from 5% to 30%, and in this process, the process occupies 20% of the CPU resources; the memory space ranges from 50MB to 200MB, and in this process, it occupies 150MB of memory space; at the same time, the CAN bus communication channel it occupies is released, with channel number 0x02.
[0071] Step 702: Based on the released runtime resources, query the version records in the gateway storage area to obtain the storage location information of the most recent compliant version and read the corresponding software data; perform integrity verification on the software data and obtain a version rollback completion report. Specifically, this includes: based on the released 150MB memory space, query the version records in the gateway storage area, where the address range is between 0x80000000 and 0x80FFFFFF; the version records are stored in chronological order of update time, and each record contains a software version number, storage address, and compliance identifier, which is divided into compliant and non-compliant; the gateway selects the version with the compliance identifier as compliant and the most recent update time from the version records, which is version V2.3.1, and its storage address is 0x80001200; read the corresponding software data according to the storage address, and the size of the software data is approximately 100MB.
[0072] During verification, the software data is first divided into several blocks of 512 bits each. If the last block is less than 512 bits long, padding is performed by adding a binary 1 to the end of the data, followed by several binary 0s, until the total data length is 64 bits less than a multiple of 512. Finally, a 64-bit binary number is added to the end to represent the total length of the original software data (in bits). The initial hash values specified by the SHA256 algorithm are loaded, initially consisting of eight fixed 32-bit hexadecimal numbers. Each 512-bit block of data is first broken down and expanded into 64 32-bit values. These values are then processed through 64 rounds of iterative computation, with each round using one... Using fixed constants and specific bitwise operation rules, the current hash value is updated, and the updated hash value serves as the basis for the next round of calculations. After processing all data blocks, the eight 32-bit hash values are concatenated sequentially to form a 256-bit hexadecimal string, which is the SHA256 hash value of the software data. The hash value calculated in this process is 0x12345678. The calculated hash value is compared with the version hash value 0x12345678 stored in the version record. The result is consistent, indicating that the software data is not corrupted. Finally, a version rollback completion report containing the rollback version V2.3.1 and the complete verification results is generated.
[0073] This embodiment ensures thorough process termination and accurate version reading by clearly defining the scope of resource usage and storage address, and guarantees that the software is not damaged after rollback by integrity verification, thus ensuring that the gateway can quickly return to a compliant operating state.
[0074] like Figure 2 As shown, embodiments of the present invention also provide a vehicle gateway CAN upgrade security rollback decision management system, including:
[0075] The acquisition module is used to receive software update packages transmitted via the CAN bus. The software update packages contain a security status summary.
[0076] The parsing module is used to parse the software update package, extract the running status parameters of the software update package, and convert the running status parameters into a set of running status data nodes.
[0077] The calculation module is used to determine the data reference center based on the set of running status data nodes, establish two reference direction vectors based on the data reference center, calculate the angle between the two reference direction vectors, and generate the sector determination area.
[0078] The selection module is used to select a first observation point within the sector determination area and a second observation point outside the sector determination area, and to generate a closed monitoring trajectory based on the chronological relationship between the first and second observation points in the time series.
[0079] The calibration module is used to calculate the state calibration coefficient based on the closed monitoring trajectory; to calibrate the verification parameters of the safety status summary using the state calibration coefficient, and to verify the safety status summary and generate compliance verification results.
[0080] The decision module is used to make rollback decisions based on the compliance verification results. If the compliance verification results show that the requirements are not met, a rollback instruction is generated.
[0081] The execution module is used to block the installation process of software update packages and control the gateway based on rollback instructions, load the most recent compliant software version from the gateway storage area, and realize version rollback.
[0082] It should be noted that this system is a system corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.
[0083] Embodiments of the present invention also provide a computing device, including: a processor and a memory storing a computer program, wherein the computer program, when executed by the processor, performs the method described above. All implementations in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.
[0084] Embodiments of the present invention also provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method described above. All implementations in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.
[0085] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for managing the safe rollback decision of a car gateway CAN upgrade, characterized in that: The method includes: Step 1: Receive the software update package transmitted via the CAN bus. The software update package contains a security status summary. Step 2: Parse the software update package, extract the running status parameters of the software update package, and convert the running status parameters into a set of running status data nodes; Step 3: Collect coordinate data of each data node in the running status data node set to generate a node coordinate dataset; calculate the weighted average of all coordinate values in the node coordinate dataset to obtain the data distribution centroid, and use the data distribution centroid as the data reference center; establish a reference coordinate system with the data reference center as the origin, and select two different directions in the reference coordinate system to construct the first reference direction vector and the second reference direction vector respectively; based on the spatial geometric relationship between the two reference direction vectors, use vector dot product operation to calculate the spatial azimuth angle between the two reference direction vectors, and generate the sector determination area. The first reference direction vector points from the origin to the normal load node with the highest frequency in the historical running records, and the second reference direction vector points from the origin to the stable node with the lowest communication error rate and the smallest latency in the historical running records. Step 4: Based on the boundary range of the sector determination area, select the location point closest to the data reference center within the sector determination area as the first observation point; based on the location coordinates of the first observation point, select the location point outside the sector determination area with the maximum distance from the first observation point as the second observation point; collect the location data of the first and second observation points in a continuous time series to generate a movement trajectory data set; based on the time order of each location point in the movement trajectory data set, connect adjacent location points sequentially to obtain a continuous trajectory path; connect the starting and ending location points of the continuous trajectory path to generate a closed monitoring trajectory. Step 5: Analyze the closed monitoring trajectory to obtain the area enclosed by the closed monitoring trajectory and the total path length of the closed monitoring trajectory; calculate the ratio of the area to the total path length to obtain the trajectory complexity index; obtain a pre-established calibration benchmark set, which contains multiple trajectory complexity reference values and corresponding calibration adjustment amounts; match the trajectory complexity index with the trajectory complexity reference values in the calibration benchmark set to obtain the corresponding calibration adjustment amounts; perform a synthesis operation with the preset benchmark calibration values to obtain the state calibration coefficient; extract the predefined verification parameter set from the security status summary, and perform weighted fusion of the state calibration coefficient with each parameter in the verification parameter set to generate a calibrated verification parameter set; compare each parameter in the calibrated verification parameter set with the security threshold, and comprehensively judge whether the information security status of the software update package is compliant to generate a compliance verification result; Step 6: Make a rollback decision based on the compliance verification results. If the compliance verification results show that the requirements are not met, generate a rollback instruction. Step 7: Based on the rollback command, block the installation process of the software update package and control the gateway to load the most recent compliant software version from the gateway storage area to achieve version rollback.
2. The automotive gateway CAN upgrade security rollback decision management method according to claim 1, characterized in that, The software update package is parsed and processed to extract its runtime status parameters. These parameters are then converted into a set of runtime status data nodes, including: Perform data packet parsing on the software update package to extract the security status summary and runtime status parameters from the software update package; classify and organize the runtime status parameters to generate a runtime status parameter classification set. Standardize the various parameters in the operational status parameter classification set to generate standardized parameter data sequences; map the standardized parameter data sequences into data nodes with spatial coordinate characteristics to generate a set of operational status data nodes.
3. The automotive gateway CAN upgrade security rollback decision management method according to claim 2, characterized in that, A rollback decision is made based on the compliance verification results. If the compliance verification results indicate that the requirements are not met, a rollback instruction is generated, including: The compliance verification results are analyzed to obtain the deviation values between each verification parameter and the corresponding safety threshold; the deviation values between each verification parameter and the corresponding safety threshold are weighted to obtain the comprehensive safety deviation index. By comparing the comprehensive safety deviation index with the preset first-level safety threshold, a preliminary risk assessment result is obtained. Based on the preliminary risk assessment result, verification parameters that need to be analyzed in depth are identified, and a set of parameters to be assessed is generated. The set of parameters to be assessed is classified into risk levels to obtain the risk weight of each parameter. By combining the risk weights and deviation values of various parameters, a comprehensive risk assessment value is calculated and compared with the preset second-level safety threshold to obtain the final decision result. Based on the final decision result, corresponding control instructions are generated, and a rollback instruction is generated if rollback is required.
4. The automotive gateway CAN upgrade security rollback decision management method according to claim 3, characterized in that, Based on the rollback command, the installation process of the software update package is blocked and the gateway is controlled. The most recent compliant software version is loaded from the gateway's storage area to achieve version rollback, including: The rollback instruction is parsed to obtain the target process identifier. Based on the target process identifier, the corresponding software update installation process is terminated, and the released runtime resources are obtained. Based on the released runtime resources, query the version records in the gateway storage area to obtain the storage location information of the most recent compliant version, and read the corresponding software data; perform integrity verification on the software data, and obtain a version rollback completion report.
5. A vehicle gateway CAN upgrade safety rollback decision management system, wherein the system implements the method as described in any one of claims 1 to 4, characterized in that, include: The acquisition module is used to receive software update packages transmitted via the CAN bus. The software update packages contain a security status summary. The parsing module is used to parse the software update package, extract the running status parameters of the software update package, and convert the running status parameters into a set of running status data nodes. The calculation module is used to determine the data reference center based on the set of running status data nodes, establish two reference direction vectors based on the data reference center, calculate the angle between the two reference direction vectors, and generate the sector determination area. The selection module is used to select a first observation point within the sector determination area and a second observation point outside the sector determination area, and to generate a closed monitoring trajectory based on the chronological relationship between the first and second observation points in the time series. The calibration module is used to calculate the state calibration coefficient based on the closed monitoring trajectory; to calibrate the verification parameters of the safety status summary using the state calibration coefficient, and to verify the safety status summary and generate compliance verification results. The decision module is used to make rollback decisions based on the compliance verification results. If the compliance verification results show that the requirements are not met, a rollback instruction is generated. The execution module is used to block the installation process of software update packages and control the gateway based on rollback instructions, load the most recent compliant software version from the gateway storage area, and realize version rollback.
6. A computing device, characterized in that, include: One or more processors; A storage device for storing one or more programs that, when executed by one or more processors, cause the one or more processors to implement the method as described in any one of claims 1 to 4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a program that, when executed by a processor, implements the method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Virtual local area network configuration method and device based on Ethernet gateway controller, equipment and medium
CN120750765A
Self-adaptive adjustment Internet operation and maintenance strategy generation method and self-adaptive adjustment Internet operation and maintenance strategy generation system
CN120811892A