Vehicle network security protection method, device and system and vehicle

By calculating the correlation of data traffic on the vehicle bus, the network security status can be determined and the vehicle can be controlled, solving the problem of timely response to network attacks in the field of autonomous driving and ensuring customer safety.

CN121283706APending Publication Date: 2026-01-06MERCEDES BENZ GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511382575.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-25
Publication Date
2026-01-06

AI Technical Summary

Technical Problem

In the field of autonomous driving, when vehicles are attacked by cybersecurity, it is impossible to take timely and targeted measures to deal with cybersecurity threats, resulting in the theft of customer data or the vehicle being controlled by outsiders, posing threats to property and life safety.

Method used

By acquiring the data traffic on the vehicle's preset bus, calculating the correlation between component data traffic and vehicle control domain data traffic, determining the network security status, and issuing control commands to the vehicle control system to control the vehicle, including takeover commands, disabling autonomous driving commands, and disconnecting network commands.

Benefits of technology

This enables vehicles to take timely and targeted measures to protect customer safety and avoid losses in the event of a cybersecurity attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121283706A_ABST
    Figure CN121283706A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle network security protection method, device and system and a vehicle, and relates to the technical field of automatic driving, the method comprises the following steps: obtaining data traffic on a preset bus of the vehicle in a preset time period, the data traffic comprising component data traffic and vehicle control domain data traffic; determining the number of data traffic acquisition times in a preset time period and arrangement positions of the component data traffic and the vehicle control domain data traffic corresponding to the same data acquisition moment; based on the arrangement position and the number of data traffic acquisition times, calculating the data correlation between the component data traffic and the vehicle control domain data traffic; and according to the data correlation degree, determining a network security state of the vehicle, and issuing a control instruction corresponding to the network security state to a vehicle control system, so that the vehicle control system controls the vehicle based on the control instruction. In the field of automatic driving, when the vehicle is threatened by network security attacks, a targeted scheme can be adopted in time to deal with the threatening of the network security attacks of the vehicle, and the security of customers is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of autonomous driving technology, and in particular to a vehicle network security protection method, device, system and vehicle. Background Technology

[0002] Currently, vehicle cybersecurity is a major concern for modern connected cars, especially in the field of autonomous driving, where cybersecurity is an indispensable element. If security vulnerabilities exist in the vehicle's communication or electronic software, it is extremely vulnerable to attack. In the current connected car market, if a vehicle is attacked by cybersecurity hackers, customers are unlikely to notice, and targeted solutions, such as software or algorithm optimizations, are only implemented after substantial consequences have occurred. By then, customers have already suffered losses (such as stolen customer data), and there is even the possibility of more serious consequences, such as the autonomous driving system being compromised, the vehicle being controlled by outsiders, threatening the customer's property and even life. Therefore, in the field of autonomous driving, when a vehicle is threatened by cybersecurity attacks, it is impossible to take timely and targeted measures to deal with the cybersecurity threats. Summary of the Invention

[0003] In view of this, embodiments of this application provide a vehicle network security protection method, device, system, and vehicle. The method involves acquiring data traffic on a preset bus of the vehicle within a preset time period, including component data traffic and vehicle control domain data traffic; determining the number of data traffic acquisitions within the preset time period and the arrangement positions of component data traffic and vehicle control domain data traffic corresponding to the same data acquisition time; calculating the data correlation between component data traffic and vehicle control domain data traffic based on the arrangement positions and the number of data traffic acquisitions; determining the vehicle's network security status based on the data correlation; and issuing control commands corresponding to the network security status to the vehicle control system, enabling the vehicle control system to control the vehicle based on the control commands. This addresses the technical problem in the existing field of autonomous driving where vehicles cannot promptly take targeted measures to deal with network security attack threats when they are attacked.

[0004] To achieve the above objectives, according to one aspect of the embodiments of this application, a vehicle network security protection method is provided, comprising:

[0005] Acquire the data flow on the vehicle's preset bus within a preset time period. The data flow includes component data flow and vehicle control domain data flow.

[0006] Determine the number of data traffic collections within a preset time period and the arrangement of component data traffic and vehicle control domain data traffic corresponding to the same data collection time.

[0007] Based on the arrangement position and the number of data traffic collections, the data correlation between component data traffic and vehicle control domain data traffic is calculated;

[0008] Based on data relevance, the network security status of the vehicle is determined, and control commands corresponding to the network security status are sent to the vehicle control system so that the vehicle control system can control the vehicle based on the control commands.

[0009] Optionally, determining the arrangement of component data traffic and vehicle control domain data traffic corresponding to the same data acquisition time within a preset time period includes:

[0010] Select multiple data collection times within a preset time period;

[0011] Arrange the vehicle control domain data traffic corresponding to multiple data acquisition times according to a preset sorting rule;

[0012] For the component data traffic of each type of component, the component data traffic corresponding to multiple data acquisition times is arranged according to a preset sorting rule.

[0013] For each data acquisition moment, determine the arrangement position of the vehicle control domain data traffic and the arrangement position of the component data traffic corresponding to that moment;

[0014] Preferably, the component data traffic includes: component data traffic corresponding to the vehicle infotainment system and component data traffic corresponding to the communication control unit.

[0015] Optionally, the data correlation between component data traffic and vehicle control domain data traffic is calculated, including:

[0016] For each component's data flow at each data acquisition moment, perform the following: determine the level difference between the arrangement position of the component's data flow at the data acquisition moment and the arrangement position of the vehicle control domain data flow at the same data acquisition moment;

[0017] Based on the grade difference, number of data traffic collection times, and preset data correlation calculation formula of component data traffic at each data collection time, the data correlation between component data traffic and vehicle control domain data traffic within a preset time period is calculated.

[0018] Preferably,

[0019] Preset data correlation calculation formula:

[0020]

[0021] Where, d iThe rank difference between the arrangement position of the component data flow at the i-th data acquisition time and the arrangement position of the vehicle control domain data flow at the i-th data acquisition time within the preset time period is represented by n, which represents the number of data flow acquisitions within the preset time period, and δ is the data correlation between the component data flow of each type of component included in the calculated component data flow and the vehicle control domain data flow within the preset time period.

[0022] Optionally, the number of data traffic collections within a preset time period is determined, including:

[0023] Determine the preset data traffic collection time interval, and based on the preset time period and the data traffic collection time interval, determine the number of data traffic collections.

[0024] Optionally, the control commands include one or more of the following: vehicle takeover command, disabling autonomous driving command, and disconnection command;

[0025] The method also includes: configuring a first preset threshold range, a second preset threshold range, and a third preset threshold range related to data relevance, and mapping different network security states to the first preset threshold range, the second preset threshold range, and the third preset threshold range respectively, wherein the upper limit of the first preset threshold range is less than or equal to the lower limit of the second preset threshold range, and the upper limit of the second preset threshold range is less than or equal to the lower limit of the third preset threshold range.

[0026] Based on data relevance, determine the vehicle's cybersecurity status, including:

[0027] Match the data relevance to one of the first preset threshold range, the second preset threshold range, and the third preset threshold range;

[0028] The network security status of a vehicle is determined by mapping a preset threshold range that matches the relevance of the data.

[0029] Optionally, determining the network security status of the vehicle as the network security status mapped to a preset threshold range that matches the data relevance includes:

[0030] In response to the data relevance matching the first preset threshold range, the network security status of the vehicle is determined to be that there is a potential danger in the in-vehicle network;

[0031] In response to the data relevance matching the second preset threshold range, the network security status of the vehicle is determined to be that a security event targeting autonomous driving has occurred in the in-vehicle network;

[0032] In response to the data relevance matching the third preset threshold range, the vehicle's cybersecurity status is determined to be a serious remote attack on the in-vehicle network during an autonomous driving event.

[0033] Optionally, control commands corresponding to the network security status are sent to the vehicle control system, so that the vehicle control system controls the vehicle based on the control commands, including:

[0034] If a potential danger is found in the vehicle's in-vehicle network, a vehicle takeover command is issued to the vehicle's control system, so that the control system can provide a voice prompt to the user to take over the vehicle based on the vehicle takeover command.

[0035] If a safety incident affecting autonomous driving has occurred in the vehicle's in-vehicle network, a vehicle takeover command and an autonomous driving disable command are issued to the vehicle's vehicle control system. The vehicle control system then uses the vehicle takeover command to provide a voice prompt to the user to take over the vehicle and controls the intelligent driver assistance system to disable the vehicle's autonomous driving function based on the autonomous driving disable command.

[0036] In the event that a serious remote attack on the vehicle's in-vehicle network has occurred during an autonomous driving event, a vehicle takeover command, an autonomous driving disable command, and a network disconnect command are issued to the vehicle's vehicle control system. This allows the vehicle control system to provide a voice prompt to the user to take over the vehicle based on the vehicle takeover command, and to control the intelligent driver assistance system to disable the vehicle's autonomous driving function based on the autonomous driving disable command, and to control the communication control unit to disconnect the vehicle from the network based on the network disconnect command.

[0037] Optionally, the data traffic on a preset bus of the vehicle within a preset time period is acquired, including:

[0038] In response to the activation of the vehicle's autonomous driving function, the data traffic on the vehicle's preset bus within a preset time period is acquired according to a preset data traffic acquisition time interval.

[0039] Optionally, the vehicle control system includes a communication control unit;

[0040] Sending control commands corresponding to the network security status to the vehicle control system includes: forwarding the control commands corresponding to the network security status to the device in the vehicle control system that executes the control commands through the communication control unit.

[0041] In addition, this application also provides a vehicle network security protection device, including:

[0042] The acquisition unit is configured to acquire data traffic on a preset bus of the vehicle within a preset time period, including component data traffic and vehicle control domain data traffic;

[0043] The data traffic analysis unit is configured to determine the number of data traffic collections within a preset time period and the arrangement of component data traffic and vehicle control domain data traffic corresponding to the same data collection time.

[0044] The data correlation calculation unit is configured to calculate the data correlation between component data traffic and vehicle control domain data traffic based on the arrangement position and the number of data traffic collections.

[0045] The network security status determination unit is configured to determine the network security status of the vehicle based on data correlation, and issue control commands corresponding to the network security status to the vehicle control system so that the vehicle control system can control the vehicle based on the control commands.

[0046] Optionally, the data traffic analysis unit is further configured to:

[0047] Select multiple data collection times within a preset time period;

[0048] Arrange the vehicle control domain data traffic corresponding to multiple data acquisition times according to a preset sorting rule;

[0049] For the component data traffic of each type of component, the component data traffic corresponding to multiple data acquisition times is arranged according to a preset sorting rule.

[0050] For each data acquisition moment, determine the arrangement position of the vehicle control domain data traffic and the arrangement position of the component data traffic corresponding to that moment;

[0051] Preferably, the component data traffic includes: component data traffic corresponding to the vehicle infotainment system and component data traffic corresponding to the communication control unit.

[0052] Optionally, the data relevance calculation unit is further configured to:

[0053] For each component's data flow at each data acquisition moment, perform the following: determine the level difference between the arrangement position of the component's data flow at the data acquisition moment and the arrangement position of the vehicle control domain data flow at the same data acquisition moment;

[0054] Based on the grade difference, number of data traffic collection times, and preset data correlation calculation formula of component data traffic at each data collection time, the data correlation between component data traffic and vehicle control domain data traffic within a preset time period is calculated.

[0055] Preferably,

[0056] Preset data correlation calculation formula:

[0057]

[0058] Where, d iThe rank difference between the arrangement position of the component data flow at the i-th data acquisition time and the arrangement position of the vehicle control domain data flow at the i-th data acquisition time within the preset time period is represented by n, which represents the number of data flow acquisitions within the preset time period, and δ is the data correlation between the component data flow of each type of component included in the calculated component data flow and the vehicle control domain data flow within the preset time period.

[0059] Optionally, the data traffic analysis unit is further configured to:

[0060] Determine the preset data traffic collection time interval, and based on the preset time period and the data traffic collection time interval, determine the number of data traffic collections.

[0061] Optionally, the control commands include one or more of the following: vehicle takeover command, disabling autonomous driving command, and disconnection command;

[0062] The vehicle network security protection device is equipped with a first preset threshold range, a second preset threshold range and a third preset threshold range related to data correlation, and maps different network security states to the first preset threshold range, the second preset threshold range and the third preset threshold range respectively. The upper limit of the first preset threshold range is less than or equal to the lower limit of the second preset threshold range, and the upper limit of the second preset threshold range is less than or equal to the lower limit of the third preset threshold range.

[0063] The network security status determination unit is further configured to:

[0064] Match the data relevance to one of the first preset threshold range, the second preset threshold range, and the third preset threshold range;

[0065] The network security status of a vehicle is determined by mapping a preset threshold range that matches the relevance of the data.

[0066] Optionally, the network security status determination unit is further configured to:

[0067] In response to the data relevance matching the first preset threshold range, the network security status of the vehicle is determined to be that there is a potential danger in the in-vehicle network;

[0068] In response to the data relevance matching the second preset threshold range, the network security status of the vehicle is determined to be that a security event targeting autonomous driving has occurred in the in-vehicle network;

[0069] In response to the data relevance matching the third preset threshold range, the vehicle's cybersecurity status is determined to be a serious remote attack on the in-vehicle network during an autonomous driving event.

[0070] Optionally, the network security status determination unit is further configured to:

[0071] If a potential danger is found in the vehicle's in-vehicle network, a vehicle takeover command is issued to the vehicle's control system, so that the control system can provide a voice prompt to the user to take over the vehicle based on the vehicle takeover command.

[0072] If a safety incident affecting autonomous driving has occurred in the vehicle's in-vehicle network, a vehicle takeover command and an autonomous driving disable command are issued to the vehicle's vehicle control system. The vehicle control system then uses the vehicle takeover command to provide a voice prompt to the user to take over the vehicle and controls the intelligent driver assistance system to disable the vehicle's autonomous driving function based on the autonomous driving disable command.

[0073] In the event that a serious remote attack on the vehicle's in-vehicle network has occurred during an autonomous driving event, a vehicle takeover command, an autonomous driving disable command, and a network disconnect command are issued to the vehicle's vehicle control system. This allows the vehicle control system to provide a voice prompt to the user to take over the vehicle based on the vehicle takeover command, and to control the intelligent driver assistance system to disable the vehicle's autonomous driving function based on the autonomous driving disable command, and to control the communication control unit to disconnect the vehicle from the network based on the network disconnect command.

[0074] Optionally, the acquisition unit is further configured to:

[0075] In response to the activation of the vehicle's autonomous driving function, the data traffic on the vehicle's preset bus within a preset time period is acquired according to a preset data traffic acquisition time interval.

[0076] Optionally, the vehicle control system includes a communication control unit;

[0077] The network security status determination unit is further configured to forward control commands corresponding to the network security status to the vehicle control system via the communication control unit for executing the control commands.

[0078] In addition, this application provides a vehicle network security protection system, including: the vehicle network security protection device as described above and a vehicle control system installed in the vehicle;

[0079] The vehicle control system is used to collect data traffic on the vehicle's preset bus within a preset time period and upload it to the vehicle's network security protection device;

[0080] The vehicle network security protection device acquires data traffic on a preset bus of the vehicle uploaded by the vehicle control system within a preset time period. The data traffic includes component data traffic and vehicle control domain data traffic. It determines the number of data traffic acquisitions within the preset time period and the arrangement position of component data traffic and vehicle control domain data traffic corresponding to the same data acquisition time. Based on the arrangement position and the number of data traffic acquisitions, it calculates the data correlation between component data traffic and vehicle control domain data traffic. Based on the data correlation, it determines the network security status of the vehicle and issues control commands corresponding to the network security status to the vehicle control system.

[0081] The vehicle control system receives control commands from the vehicle's network security protection device to control the vehicle based on these commands.

[0082] Optionally, the vehicle control system includes a communication control unit, a vehicle infotainment system, an intelligent driver assistance system, and a vehicle controller.

[0083] The communication control unit communicates with the vehicle's infotainment system, intelligent driver assistance system, vehicle controller, and vehicle network security protection devices.

[0084] The vehicle's infotainment system communicates with the intelligent driver assistance system.

[0085] The intelligent driver assistance system communicates with the vehicle controller;

[0086] The communication control unit is used to receive vehicle takeover commands issued by the vehicle network security protection device and forward the vehicle takeover commands to the vehicle infotainment system, so that the vehicle infotainment system can provide voice prompts to the user to take over the vehicle based on the vehicle takeover commands.

[0087] The communication control unit is also used to receive the disabling autonomous driving command issued by the vehicle network security protection device, and forward the disabling autonomous driving command to the intelligent driver assistance system, so that the intelligent driver assistance system disables the vehicle's autonomous driving function based on the disabling autonomous driving command, and then the vehicle controller controls the vehicle's driving according to the user's operation of the vehicle.

[0088] The communication control unit is also used to receive network disconnection commands issued by the vehicle's network security protection device and disconnect the vehicle from the network based on the network disconnection commands.

[0089] In addition, this application provides a vehicle including the vehicle network security protection device or the vehicle network security protection system as described above.

[0090] In addition, this application also provides a vehicle network security protection electronic device, including: one or more processors; and a storage device for storing one or more programs, which, when executed by one or more processors, enable the one or more processors to implement the vehicle network security protection method as described above.

[0091] In addition, this application also provides a computer-readable medium storing a computer program for implementing vehicle network security protection. When the computer program is executed by an on-board processor, it implements the vehicle network security protection method described above.

[0092] To achieve the above objectives, according to another aspect of the embodiments of this application, a computer program product is provided.

[0093] A computer program product according to an embodiment of this application includes a computer program that, when executed by a processor, implements the vehicle network security protection method provided in an embodiment of this application.

[0094] One embodiment of the above invention has the following advantages or beneficial effects: This application acquires data traffic on a preset bus of a vehicle within a preset time period, including component data traffic and vehicle control domain data traffic; determines the number of data traffic acquisitions within the preset time period and the arrangement positions of component data traffic and vehicle control domain data traffic corresponding to the same data acquisition time; calculates the data correlation between component data traffic and vehicle control domain data traffic based on the arrangement positions and the number of data traffic acquisitions; determines the vehicle's network security status based on the data correlation, and issues control commands corresponding to the network security status to the vehicle control system, so that the vehicle control system controls the vehicle based on the control commands. Thus, in the field of autonomous driving, when a vehicle is threatened by a network security attack, the vehicle can promptly take targeted measures to deal with the vehicle's network security attack threat, ensuring customer safety and effectively avoiding customer losses.

[0095] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description

[0096] The accompanying drawings are provided to better understand this application and do not constitute an undue limitation thereof. Wherein:

[0097] Figure 1 This is a schematic diagram of the main flow of a vehicle network security protection method provided according to an embodiment of this application;

[0098] Figure 2 This is a schematic diagram of the main flow of a vehicle network security protection method provided according to an embodiment of this application;

[0099] Figure 3 This is a schematic diagram of the main flow of a vehicle network security protection method provided according to an embodiment of this application;

[0100] Figure 4 This is a schematic diagram of the main units of a vehicle network security protection device according to an embodiment of this application;

[0101] Figure 5This is an interactive schematic diagram of a vehicle network security protection system according to an embodiment of this application;

[0102] Figure 6 This is a schematic diagram of the structure of a vehicle according to an embodiment of this application;

[0103] Figure 7 This is an exemplary vehicle system architecture diagram to which embodiments of this application can be applied;

[0104] Figure 8 This is a schematic diagram of the structure of a computer system suitable for implementing the embodiments of this application. Detailed Implementation

[0105] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description. The acquisition, storage, use, and processing of data in the technical solutions of this application all comply with relevant national laws and regulations.

[0106] It should be noted that, unless otherwise specified, the embodiments of this application and the technical features thereof can be combined with each other.

[0107] Furthermore, the terms "first," "second," and "third," etc., included in the terminology of this application's embodiments are used to distinguish similar objects and are not necessarily used to describe a specific number or order. It should be understood that such terms can be used interchangeably where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application.

[0108] Furthermore, the vehicles involved in the embodiments of this application may be internal combustion engine vehicles that use an engine as a power source, hybrid vehicles that use an engine and an electric motor as power sources, electric vehicles that use an electric motor as a power source, etc.

[0109] Figure 1 This is a schematic diagram of the main flow of a vehicle network security protection method provided according to an embodiment of this application, as shown below. Figure 1 As shown, the vehicle network security protection method mainly includes the following steps S101-S104.

[0110] Step S101: Obtain the data traffic on the vehicle's preset bus within a preset time period. The data traffic includes component data traffic and vehicle control domain data traffic.

[0111] In this embodiment, the entity executing the vehicle network security protection method (e.g., it can be the cloud or the backend, or it can be the engine control unit (ECU) in the vehicle) can obtain the data traffic (A, B, and C) collected by the data acquisition module of the ADAS controller from the three preset buses: the communication control unit (TCU) - intelligent driver assistance system ADAS, the vehicle infotainment unit (HU) - intelligent driver assistance system ADAS, and the intelligent driver assistance system ADAS - vehicle control system (Vehicle Control). Among them, the data traffic A on the preset bus of communication control unit (TCU) - intelligent driver assistance system ADAS and the data traffic B on the preset bus of vehicle infotainment unit (HU) - intelligent driver assistance system ADAS belong to component data traffic, and the data traffic C on the preset bus of intelligent driver assistance system ADAS - vehicle control system (Vehicle Control) belongs to vehicle control domain data traffic.

[0112] Specifically, acquiring data traffic on a preset bus of the vehicle within a preset time period includes: in response to the activation of the vehicle's autonomous driving function, acquiring data traffic (e.g., A, B, and C respectively) on the vehicle's preset bus (e.g., Communication Control Unit TCU - Intelligent Assisted Driving System ADAS, Vehicle HU - Intelligent Assisted Driving System ADAS, Intelligent Assisted Driving System ADAS - Vehicle Control) within a preset time period (e.g., 9:00-9:20) according to a preset data traffic acquisition time interval (e.g., 5 minutes).

[0113] Step S102: Determine the number of data traffic collections within a preset time period and the arrangement of component data traffic and vehicle control domain data traffic corresponding to the same data collection time.

[0114] Specifically, determining the number of data traffic collections within a preset time period includes: determining a preset data traffic collection time interval (e.g., 5 minutes), and based on the preset time period (e.g., 9:00-9:20) and the data traffic collection time interval (e.g., 5 minutes), determining the number of data traffic collections (e.g., 5 times, specifically once at 9:00, once at 9:05, once at 9:10, once at 9:15, and once at 9:20).

[0115] In this embodiment, the arrangement position of component data traffic (e.g., A) and vehicle control domain data traffic (e.g., C) corresponding to the same data acquisition time (e.g., 9:00, 9:05, 9:10, 9:15 or 9:20) is determined.

[0116] For example, within the preset time period of 9:00-9:20, A and C are sorted in descending order to obtain the following sorted positions: A at 9:00 (position 1) and C at 9:05 (position 2); A at 9:10 (position 3); A at 9:15 (position 4); and A at 9:20 (position 5). See Table 1 below for details.

[0117] Table 1

[0118] Time A(frame / s) The arrangement position of A C(frame / s) The arrangement of C 9:00 3000 1 2000 1 9:05 2900 2 1900 2 9:10 2800 3 1800 3 9:15 2700 4 1700 4 9:20 2600 5 1600 5

[0119] In this embodiment, the arrangement position of component data traffic (e.g., B) and vehicle control domain data traffic (e.g., C) corresponding to the same data acquisition time (e.g., 9:00, 9:05, 9:10, 9:15 or 9:20) is determined.

[0120] For example, within the preset time period of 9:00-9:20, B and C are sorted in descending order to obtain the following sorted positions: 1 for B and 1 for C at the same data acquisition time of 9:00; 2 for B and 2 for C at the same data acquisition time of 9:05; 3 for B and 3 for C at the same data acquisition time of 9:10; 4 for B and 4 for C at the same data acquisition time of 9:15; and 5 for B and 5 for C at the same data acquisition time of 9:20. See Table 2 below for details.

[0121] Table 2

[0122] Time B (frame / s) The position of B C(frame / s) The arrangement of C 9:00 2900 1 2000 1 9:05 2800 2 1900 2 9:10 2700 3 1800 3 9:15 2600 4 1700 4 9:20 2500 5 1600 5

[0123] Step S103: Based on the arrangement position and the number of data traffic collections, calculate the data correlation between the component data traffic and the vehicle control domain data traffic.

[0124] The correlation between component data traffic and vehicle control domain data traffic is calculated using a data correlation algorithm. This is based on the ranking difference (for example, this difference can be 0, 1, 2, 3, ..., n) calculated from the arrangement of component data traffic and vehicle control domain data traffic corresponding to the same data acquisition time. The correlation can be calculated as follows: Under normal vehicle network conditions, there is no correlation between data traffic A on the TCU-ADAS bus, data traffic B on the HU-ADAS bus, and data traffic C on the ADAS-Vehicle Control bus. However, when a remote attack occurs on the vehicle network, the traffic between A and C, and between B and C, tends to be positively correlated. Therefore, the vehicle's network security status can be determined more accurately based on the data correlation.

[0125] Step S104: Determine the network security status of the vehicle based on the data correlation, and send the control command corresponding to the network security status to the vehicle control system so that the vehicle control system can control the vehicle based on the control command.

[0126] The cybersecurity status of a vehicle can include potential dangers to the in-vehicle network, security incidents targeting autonomous driving that have occurred on the in-vehicle network, and serious remote attacks on autonomous driving incidents that have occurred on the in-vehicle network.

[0127] Specifically, the control commands include one or more of the following: vehicle takeover command, disabling autonomous driving command, and network disconnection command; the vehicle network security protection method further includes: configuring a first preset threshold range (e.g., 0.5≤δ<0.7), a second preset threshold range (e.g., 0.7≤δ<0.9), and a third preset threshold range (e.g., 0.9≤δ≤1) related to data correlation δ, and mapping different network security states to the first preset threshold range, the second preset threshold range, and the third preset threshold range respectively, and saving them as preset mapping relationships, wherein the upper limit of the first preset threshold range is less than or equal to the lower limit of the second preset threshold range, and the upper limit of the second preset threshold range is less than or equal to the lower limit of the third preset threshold range; for example, the preset mapping relationship is as follows: mapping the first preset threshold range (e.g., 0.5≤δ<0.7) to a potential danger in the in-vehicle network, mapping the second preset threshold range (e.g., 0.7≤δ<0.9) to a security event targeting autonomous driving that has occurred in the in-vehicle network, and mapping the third preset threshold range (e.g., 0.9≤δ≤1) to a serious remote attack on autonomous driving event that has occurred in the in-vehicle network. Based on data relevance, determine the network security status of the vehicle, including: matching the data relevance to one of a first preset threshold range, a second preset threshold range, and a third preset threshold range; and determining the network security status mapped to the preset threshold range matched with the data relevance as the network security status of the vehicle.

[0128] Specifically, determining the network security status of a vehicle based on a preset threshold range that matches data relevance includes: determining the vehicle's network security status as having a potential danger in the in-vehicle network based on a preset mapping relationship when the data relevance matches a first preset threshold range (e.g., 0.5 ≤ δ < 0.7); determining the vehicle's network security status as having a potential danger in the in-vehicle network based on a preset mapping relationship when the data relevance matches a second preset threshold range (e.g., 0.7 ≤ δ < 0.9); and determining the vehicle's network security status as having experienced a security event targeting autonomous driving in the in-vehicle network based on a preset mapping relationship when the data relevance matches a third preset threshold range (e.g., 0.9 ≤ δ ≤ 1). This improves the accuracy of determining the vehicle's network security status.

[0129] Specifically, control commands corresponding to the network security status are sent to the vehicle control system, enabling the system to control the vehicle based on these commands. This includes: when a potential danger is identified in the vehicle's in-vehicle network, a vehicle takeover command is sent to the vehicle control system, prompting the user to take over the vehicle via voice prompt. For example, the user can be prompted to take over the vehicle via the in-vehicle infotainment system (HU, Head-Up Display) or other in-vehicle playback devices, such as speakers. When a safety event affecting autonomous driving has occurred in the vehicle's in-vehicle network, a vehicle takeover command and a command to disable autonomous driving are sent to the vehicle. The vehicle control system is configured to issue a vehicle takeover command via voice prompt to the user to take over the vehicle, and to control the Advanced Driver Assistance System (ADAS) to disable the vehicle's autonomous driving functions via a disable autonomous driving command. In the event of a serious remote attack on the vehicle's in-vehicle network, the system issues a vehicle takeover command, a disable autonomous driving command, and a network disconnection command (e.g., firewall rules) to the vehicle control system. This allows the system to issue a takeover command via voice prompt to the user to take over the vehicle, control the ADAS to disable the autonomous driving functions via the disable autonomous driving command, and control the TCU to disconnect the vehicle from the network via a network disconnection command. This enables the system to issue real-time security control commands after accurately determining the vehicle's network security status, protecting the information security, life, and property safety of passengers inside the vehicle.

[0130] Specifically, the vehicle control system includes a communication control unit (TCU); issuing control commands corresponding to the network security status to the vehicle control system includes: forwarding the control commands corresponding to the network security status to the device in the vehicle control system that executes the control commands through the communication control unit (TCU), such as the vehicle infotainment system (HU) or the advanced driver assistance system (ADAS).

[0131] This embodiment acquires data traffic on a preset bus of the vehicle within a preset time period. This data traffic includes component data traffic and vehicle control domain data traffic. It determines the number of data traffic acquisitions within the preset time period and the arrangement of component and vehicle control domain data traffic corresponding to the same acquisition time. Based on the arrangement and acquisition frequency, it calculates the data correlation between component and vehicle control domain data traffic. Based on the data correlation, it determines the vehicle's network security status and issues control commands corresponding to the network security status to the vehicle control system, enabling the system to control the vehicle based on these commands. This allows the vehicle to promptly take targeted measures to address network security threats when threatened in the field of autonomous driving, ensuring customer safety and effectively preventing customer losses.

[0132] Figure 2 This is a schematic diagram of the main flow of a vehicle network security protection method according to an embodiment of this application, such as... Figure 2 As shown, the vehicle network security protection method mainly includes the following steps S201-S208. There is no execution correlation between steps S202 and steps S203-S206, and they can be executed before or after any of the steps S203-S206.

[0133] Step S201: Obtain the data traffic on the vehicle's preset bus within a preset time period. The data traffic includes component data traffic and vehicle control domain data traffic.

[0134] At the same data acquisition moment, component data traffic (e.g., A, B) and vehicle control domain data traffic (e.g., C) on the vehicle's preset bus must be collected simultaneously. This is to accurately determine the vehicle's network security status based on the calculation results of the data correlation between AC and BC. This allows for timely and targeted solutions to address vehicle network security threats based on the accurately determined network security status, ensuring customer safety and effectively preventing customer losses.

[0135] Step S202: Determine the number of data traffic collections within a preset time period.

[0136] The number of times data traffic is collected within a preset time period, for example, 5 times.

[0137] Step S203: Select multiple data collection times within a preset time period.

[0138] The preset time period includes data acquisition times and non-data acquisition times. For example, the preset time period is 9:00-9:20, where data acquisition times are 9:00, 9:05, 9:10, 9:15, and 9:20; non-data acquisition times are all times within 9:00-9:20 except for 9:00, 9:05, 9:10, 9:15, and 9:20. All data acquisition times within the preset time period (e.g., 9:00-9:20), such as 9:00, 9:05, 9:10, 9:15, and 9:20, are filtered out. This ensures the accuracy of the subsequent calculation of the correlation between component data traffic and vehicle control domain data traffic within the preset time period.

[0139] Step S204: Arrange the vehicle control domain data traffic corresponding to multiple data acquisition times according to a preset sorting rule.

[0140] For example, the vehicle control domain data traffic (i.e., C, for example, 2000 frames / s corresponding to 9:00, 1900 frames / s corresponding to 9:05, 9:10, 9:15, and 9:20) at multiple data collection times (e.g., 9:00, 9:05, 9:10, 9:15, and 9:20) is arranged according to a preset sorting rule (e.g., descending sorting rule). The sorting results are shown in Table 3 below.

[0141] Table 3

[0142] Time C(frame / s) 9:00 2000 9:05 1900 9:10 1800 9:15 1700 9:20 1600

[0143] Step S205: For the component data traffic of each type of component included in the component data traffic, arrange the component data traffic corresponding to multiple data acquisition times according to a preset sorting rule.

[0144] In this application, the communication control unit (TCU) and the vehicle infotainment system (HU) are components, and A and B are component data flows.

[0145] For example, for each component (e.g., TCU, HU) included in the component data traffic, the component data traffic corresponding to multiple data acquisition times (e.g., 9:00, 9:05, 9:10, 9:15, 9:20) is arranged according to a preset sorting rule.

[0146] For example, for component data traffic A of component TCU, the component data traffic corresponding to multiple data acquisition times is arranged according to a preset sorting rule (e.g., descending sorting rule), and the sorting results are shown in Table 4 below:

[0147] Table 4

[0148] Time A(frame / s) 9:00 3000 9:05 2900 9:10 2800 9:15 2700 9:20 2600

[0149] For example, for component data traffic B of component HU, the component data traffic corresponding to multiple data acquisition times is arranged according to a preset sorting rule (e.g., descending sorting rule), and the sorting results are shown in Table 5 below:

[0150] Table 5

[0151] Time B (frame / s) 9:00 2900 9:055 2800 9:10 2700 9:15 2600 9:200 2500

[0152] Step S206: For each data acquisition moment, determine the arrangement position of the vehicle control domain data flow and the arrangement position of the component data flow corresponding to the data acquisition moment.

[0153] Preferably, the component data traffic includes: component data traffic (e.g., B) corresponding to the vehicle infotainment system (e.g., HU) and component data traffic (e.g., A) corresponding to the communication control unit (e.g., TCU).

[0154] For each component (e.g., communication control unit TCU) included in the component data traffic (e.g., A), at each data acquisition time, the arrangement position of the vehicle control domain data traffic (e.g., C) and the arrangement position of the component data traffic (e.g., A) corresponding to that data acquisition time are determined, as shown in Table 6 below:

[0155] Table 6

[0156] Time A(frame / s) The arrangement position of A C(frame / s) The arrangement of C 9:00 3000 1 2000 1 9:05 2900 2 1900 2 9:10 2800 3 1800 3 9:15 2700 4 1700 4 9:20 2600 5 1600 5

[0157] For each component data traffic (e.g., vehicle infotainment system HU) included in the component data traffic (e.g., B), at each data acquisition time, the arrangement position of the vehicle control domain data traffic (e.g., C) and the arrangement position of the component data traffic (e.g., B) corresponding to that data acquisition time are determined, as shown in Table 7 below:

[0158] Table 7

[0159] Time B (frame / s) The position of B C(frame / s) The arrangement of C 9:00 2900 1 2000 1 9:05 2800 2 1900 2 9:10 2700 3 1800 3 9:15 2600 4 1700 4 9:20 2500 5 1600 5

[0160] Step S207: Based on the arrangement position and the number of data traffic collections, calculate the data correlation between the component data traffic and the vehicle control domain data traffic.

[0161] For example, for each component (e.g., communication control unit TCU) included in the component data traffic (e.g., A), at each data acquisition time, a grade difference is calculated based on the arrangement position of A and the arrangement position of C. Based on the calculated grade difference and the number of data traffic acquisitions within a preset time period, the data correlation between the component data traffic (e.g., the component data traffic (e.g., A) corresponding to the communication control unit (e.g., TCU)) and the vehicle control domain data traffic (e.g., C) within the preset time period is calculated.

[0162] For example, for each component (e.g., vehicle infotainment system HU) included in the component data traffic, the component data traffic (e.g., B) is calculated at each data acquisition time based on the arrangement position of B and the arrangement position of C. Based on the calculated level difference and the number of data traffic acquisitions within a preset time period, the data correlation between the component data traffic (e.g., the component data traffic (e.g., B) corresponding to the vehicle infotainment system (e.g., HU)) and the vehicle control domain data traffic (e.g., C) within the preset time period is calculated.

[0163] Step S208: Determine the network security status of the vehicle based on data correlation, and send control commands corresponding to the network security status to the vehicle control system so that the vehicle control system can control the vehicle based on the control commands.

[0164] The embodiments of this application enable vehicles to take timely and targeted measures to deal with cybersecurity attacks when they are threatened in the field of autonomous driving, thereby ensuring customer safety and effectively preventing customer losses.

[0165] Figure 3 This is a schematic diagram of the main flow of a vehicle network security protection method according to an embodiment of this application, such as... Figure 3 As shown, the vehicle network security protection method mainly includes the following steps S301-S309. There is no execution correlation between steps S302 and steps 303-306, which can be executed before or after any of the steps 303-306.

[0166] Step S301: Obtain the data traffic on the vehicle's preset bus within a preset time period. The data traffic includes component data traffic and vehicle control domain data traffic.

[0167] Step S302: Determine the number of data traffic collections within a preset time period.

[0168] Step S303: Select multiple data collection times within a preset time period.

[0169] Step S304: Arrange the vehicle control domain data traffic corresponding to multiple data acquisition times according to a preset sorting rule.

[0170] Step S305: For the component data traffic of each type of component included in the component data traffic, arrange the component data traffic corresponding to multiple data acquisition times according to a preset sorting rule.

[0171] Step S306: For each data acquisition moment, determine the arrangement position of the vehicle control domain data flow and the arrangement position of the component data flow corresponding to the data acquisition moment.

[0172] The principles of steps S301 to S306 are similar to those of steps S201 to S206, and will not be repeated here.

[0173] Preferably, the component data traffic includes: component data traffic corresponding to the vehicle infotainment system and component data traffic corresponding to the communication control unit.

[0174] Step S307: For the component data flow at each data acquisition time for each type of component, perform the following: Determine the level difference between the arrangement position of the component data flow at the data acquisition time and the arrangement position of the vehicle control domain data flow at the same data acquisition time.

[0175] The difference in level can be represented by d. i This indicates that each component can be a communication control unit or a vehicle infotainment system.

[0176] When the component is a communication control unit, the calculated arrangement position of the component's data flow (e.g., A) at each data acquisition moment (i.e., the arrangement position of A) and the arrangement position of the vehicle control domain data flow (e.g., C) at the same data acquisition moment (i.e., the arrangement position of C) are related by the level difference (i.e., d). i As shown in Table 8 below:

[0177] Table 8

[0178] Time A(frame / s) The arrangement position of A C(frame / s) The arrangement of C <![CDATA[d i ]]> 9:00 3000 1 2000 1 1-1=0 9:05 2900 2 1900 2 2-2=0 9:10 2800 3 1800 3 3-3=0 9:15 2700 4 1700 4 4-4=0 9:20 2600 5 1600 5 5-5=0

[0179] When the component is an in-vehicle infotainment system, the calculated arrangement position of the component's data flow (e.g., B) at each data acquisition moment (i.e., the arrangement position of B) and the arrangement position of the vehicle control domain data flow (e.g., C) at the same data acquisition moment (i.e., the arrangement position of C) are related by the level difference (i.e., d). i As shown in Table 9 below:

[0180] Table 9

[0181] Time B (frame / s) The position of B C(frame / s) The arrangement of C <![CDATA[d i ]]> 9:00 2900 1 2000 1 1-1=0 9:05 2800 2 1900 2 2-2=0 9:10 2700 3 1800 3 3-3=0 9:15 2600 4 1700 4 4-4=0 9:20 2500 5 1600 5 5-5=0

[0182] Step S308: Based on the grade difference of component data traffic at each data acquisition moment, the number of data traffic acquisitions, and the preset data correlation calculation formula, the data correlation between component data traffic and vehicle control domain data traffic within a preset time period is calculated.

[0183] Preferably,

[0184] Preset data correlation calculation formula:

[0185]

[0186] Where, d iThe order of component data traffic (e.g., A or B) at the i-th data acquisition time (e.g., the first data acquisition time, i.e., 9:00) within a preset time period (e.g., 9:00-9:20) is the difference in order between the order of component data traffic (e.g., A or B) at the i-th data acquisition time (e.g., the first data acquisition time, i.e., 9:00) and the order of vehicle control domain data traffic (e.g., C). n represents the number of data traffic acquisitions within the preset time period, and δ is the data correlation between the component data traffic (e.g., A or B) of each component included in the calculated component data traffic and the vehicle control domain data traffic (e.g., C) within the preset time period (e.g., 9:00-9:20).

[0187] Step S309: Determine the network security status of the vehicle based on the data correlation, and send the control command corresponding to the network security status to the vehicle control system so that the vehicle control system can control the vehicle based on the control command.

[0188] The embodiments of this application enable vehicles to take timely and targeted measures to deal with cybersecurity attacks when they are threatened in the field of autonomous driving, thereby ensuring customer safety and effectively preventing customer losses.

[0189] Figure 4 This is a schematic diagram of the main units of a vehicle network security protection device according to an embodiment of this application. Figure 4 As shown, the vehicle network security protection device 400 includes an acquisition unit 401, a data traffic analysis unit 402, a data correlation calculation unit 403, and a network security status determination unit 404.

[0190] The acquisition unit 401 is configured to acquire the data flow on the vehicle's preset bus within a preset time period, including component data flow and vehicle control domain data flow.

[0191] The data flow analysis unit 402 is configured to determine the number of data flow collections within a preset time period and the arrangement of component data flow and vehicle control domain data flow corresponding to the same data collection time.

[0192] The data correlation calculation unit 403 is configured to calculate the data correlation between the component data traffic and the vehicle control domain data traffic based on the arrangement position and the number of data traffic acquisitions.

[0193] The network security status determination unit 404 is configured to determine the network security status of the vehicle based on data correlation, and issue control commands corresponding to the network security status to the vehicle control system so that the vehicle control system can control the vehicle based on the control commands.

[0194] In some embodiments, the data traffic analysis unit 402 is further configured to: filter out multiple data acquisition times within a preset time period; arrange the vehicle control domain data traffic corresponding to the multiple data acquisition times according to a preset sorting rule; for the component data traffic including the component data traffic of each type of component, arrange the component data traffic corresponding to the multiple data acquisition times according to a preset sorting rule; for each data acquisition time, determine the arrangement position of the vehicle control domain data traffic and the arrangement position of the component data traffic corresponding to the data acquisition time; preferably, the component data traffic includes: component data traffic corresponding to the vehicle infotainment system and component data traffic corresponding to the communication control unit.

[0195] In some embodiments, the data correlation calculation unit 403 is further configured to: for the component data flow at each data acquisition time for each type of component, perform the following: determine the level difference between the arrangement position of the component data flow at the data acquisition time and the arrangement position of the vehicle control domain data flow at the same data acquisition time; calculate the data correlation between the component data flow and the vehicle control domain data flow within a preset time period based on the level difference of the component data flow at each data acquisition time, the number of data flow acquisitions, and a preset data correlation calculation formula; preferably, the preset data correlation calculation formula is:

[0196]

[0197] Where, d i The rank difference between the arrangement position of the component data flow at the i-th data acquisition time and the arrangement position of the vehicle control domain data flow at the i-th data acquisition time within the preset time period is represented by n, which represents the number of data flow acquisitions within the preset time period, and δ is the data correlation between the component data flow of each type of component included in the calculated component data flow and the vehicle control domain data flow within the preset time period.

[0198] In some embodiments, the data traffic analysis unit 402 is further configured to: determine a preset data traffic collection time interval, and determine the number of data traffic collections based on the preset time interval and the data traffic collection time interval.

[0199] In some embodiments, the control commands include one or more of a vehicle takeover command, a disabling autonomous driving command, and a network disconnection command; the vehicle network security protection device is configured with a first preset threshold range, a second preset threshold range, and a third preset threshold range related to data relevance, and maps different network security states to the first preset threshold range, the second preset threshold range, and the third preset threshold range respectively, wherein the upper limit of the first preset threshold range is less than or equal to the lower limit of the second preset threshold range, and the upper limit of the second preset threshold range is less than or equal to the lower limit of the third preset threshold range; the network security state determination unit 404 is further configured to: match one of the first preset threshold range, the second preset threshold range, and the third preset threshold range for data relevance; and determine the network security state mapped by the preset threshold range matched with the data relevance as the network security state of the vehicle.

[0200] In some embodiments, the network security status determination unit 404 is further configured to: determine that the network security status of the vehicle is that there is a potential danger in the in-vehicle network in response to the data correlation matching a first preset threshold range; determine that the network security status of the vehicle is that a security event targeting autonomous driving has occurred in the in-vehicle network in response to the data correlation matching a second preset threshold range; and determine that the network security status of the vehicle is that a serious remote attack on autonomous driving event has occurred in the in-vehicle network in response to the data correlation matching a third preset threshold range.

[0201] In some embodiments, the network security status determination unit 404 is further configured to: when it is determined that there is a potential danger in the vehicle's in-vehicle network, issue a vehicle takeover command to the vehicle's vehicle control system, so that the vehicle control system can verbally prompt the user to take over the vehicle based on the vehicle takeover command; when it is determined that a safety event targeting autonomous driving has occurred in the vehicle's in-vehicle network, issue a vehicle takeover command and a disable autonomous driving command to the vehicle's vehicle control system, so that the vehicle control system can verbally prompt the user to take over the vehicle based on the vehicle takeover command, and control the intelligent driver assistance system to disable the vehicle's autonomous driving function based on the disable autonomous driving command; when it is determined that a serious remote attack autonomous driving event has occurred in the vehicle's in-vehicle network, issue a vehicle takeover command, a disable autonomous driving command, and a network disconnection command to the vehicle's vehicle control system, so that the vehicle control system can verbally prompt the user to take over the vehicle based on the vehicle takeover command, and control the intelligent driver assistance system to disable the vehicle's autonomous driving function based on the disable autonomous driving command, and control the communication control unit to disconnect the vehicle from the network based on the network disconnection command.

[0202] In some embodiments, the acquisition unit 401 is further configured to: in response to the activation of the vehicle's autonomous driving function, acquire the data traffic on the vehicle's preset bus within a preset time period according to a preset data traffic acquisition time interval.

[0203] In some embodiments, the vehicle control system includes a communication control unit; the network security status determination unit 404 is further configured to forward control commands corresponding to the network security status to the means in the vehicle control system for executing the control commands via the communication control unit.

[0204] It should be noted that the vehicle network security protection method and vehicle network security protection device in this application are related in terms of specific implementation content, so the repeated content will not be described again.

[0205] Figure 5 This is an interactive diagram of a vehicle network security protection system according to an embodiment of this application. Figure 5 As shown, the vehicle network security protection system 500 includes: a vehicle network security protection device 400 and a vehicle control system 501 installed in the vehicle; the vehicle control system 501 is used to collect data traffic on a preset bus of the vehicle within a preset time period and upload it to the vehicle network security protection device 400; the vehicle network security protection device 400 obtains the data traffic on the preset bus of the vehicle within the preset time period (e.g., ...) uploaded by the vehicle control system 501. Figure 5 The system includes preset buses 502-504, 503-504, and 504-505. Here, 502 can represent the Communication Control Unit (TCU), 503 can represent the Vehicle Controller Unit (HU), 504 can represent the Advanced Driver Assistance System (ADAS), and 505 can represent the Vehicle Control Controller (VDC). The data traffic includes component data traffic A and B, and vehicle control domain data traffic C. The system determines the number of data traffic acquisitions within a preset time period and the arrangement of component and VDC data traffic at the same acquisition time. Based on the arrangement and acquisition frequency, it calculates the data correlation between component and VDC data traffic. Based on the correlation, it determines the vehicle's network security status and issues control commands corresponding to the network security status to the vehicle control system 501. The vehicle control system 501 receives the control commands from the vehicle network security protection device 400 and controls the vehicle based on these commands.

[0206] like Figure 5As shown, in some embodiments, the vehicle control system 501 includes a communication control unit 502, a vehicle infotainment system 503, an intelligent driver assistance system 504, and a vehicle controller 505. The communication control unit 502 is communicatively connected to the vehicle infotainment system 503, the intelligent driver assistance system 504, the vehicle controller 505, and the vehicle network security protection device 400. The vehicle infotainment system 503 is communicatively connected to the intelligent driver assistance system 504. The intelligent driver assistance system 504 is communicatively connected to the vehicle controller 505. The communication control unit 502 is used to receive vehicle takeover commands issued by the vehicle network security protection device 400 and forward the vehicle takeover commands to the vehicle infotainment system. 503, so that the vehicle infotainment system 504 can give a voice prompt to the user to take over the vehicle based on the vehicle takeover command; the communication control unit 502 is also used to receive the autonomous driving disabling command issued by the vehicle network security protection device 400, and forward the autonomous driving disabling command to the intelligent driver assistance system 504, so that the intelligent driver assistance system 504 can disable the vehicle's autonomous driving function based on the autonomous driving disabling command, and then the vehicle controller 505 can control the vehicle's driving according to the user's operation of the vehicle; the communication control unit 502 is also used to receive the network disconnection command issued by the vehicle network security protection device 400, and disconnect the network connected to the vehicle based on the network disconnection command.

[0207] Figure 6 This is a structural schematic diagram of a vehicle according to an embodiment of this application. For example... Figure 6 As shown, vehicle 600, including as Figure 4 The vehicle network security protection device 400 shown or such Figure 5 The vehicle network security protection system 500 shown is illustrated.

[0208] In this embodiment, the vehicle's network data (i.e., the data traffic on the vehicle's preset bus within a preset time period, as described in this application) can be remotely transmitted to the execution entity (e.g., the cloud or backend, or the in-vehicle engine control unit, ECU). The execution entity uses a data correlation algorithm to determine if the vehicle's network security has been attacked and takes certain measures to restore the vehicle's safety. The data correlation algorithm uses data traffic A on the preset bus between the communication control unit (TCU) and the advanced driver assistance system (ADAS), data traffic B on the preset bus between the vehicle's infotainment system (HU) and the ADAS, and data traffic C on the preset bus between the ADAS and the vehicle control domain (i.e., the vehicle controller, which controls steering, braking, etc.). The communication traffic between the TCU and HU and ADAS is chosen because these two components are often used as attack entry points by hackers, and the traffic between ADAS and the vehicle control domain is crucial for life safety. Under normal circumstances, there is no correlation between A, B, and C, but when a remote vehicle attack occurs, the traffic between A and C, and between B and C, tends to be positively correlated.

[0209] For example, in the vehicle network security protection method of this application, when the autonomous driving function is activated, the data acquisition module of the ADAS controller collects the data traffic (A, B, and C) on three preset buses: the communication control unit TCU-intelligent assisted driving system ADAS, the vehicle infotainment unit HU-intelligent assisted driving system ADAS, and the intelligent assisted driving system ADAS-vehicle control unit (Vehicle Control). The data acquisition module uploads the collected data to the execution entity through the communication control unit TCU every 5 minutes. The execution entity of this application can be, for example, the cloud or the backend, or the engine control unit (ECU) in the vehicle.

[0210] A big data model is deployed on the implementing entity to calculate vehicle cybersecurity risks, thereby accurately protecting vehicle cybersecurity. The specific calculation process is as follows:

[0211] The data traffic and ranking of A and C at the same time within a preset time period (e.g., 9:00-9:20) are sorted, and the sorting results are shown in Table 10 below;

[0212] Table 10

[0213] Time A(frame / s) The arrangement position of A C(frame / s) The arrangement of C <![CDATA[d i ]]> 9:00 3000 1 2000 1 1-1=0 9:05 2900 2 1900 2 2-2=0 9:10 2800 3 1800 3 3-3=0 9:15 2700 4 1700 4 4-4=0 9:20 2600 5 1600 5 5-5=0

[0214] Similarly, the data traffic and ranking corresponding to B and C at the same time are sorted, and the sorting results are shown in Table 11 below:

[0215] Table 11

[0216] Time B (frame / s) The position of B C(frame / s) The arrangement of C <![CDATA[d i ]]> 9:00 2900 1 2000 1 1-1=0 9:05 2800 2 1900 2 2-2=0 9:10 2700 3 1800 3 3-3=0 9:15 2600 4 1700 4 4-4=0 9:20 2500 5 1600 5 5-5=0

[0217] Using a data correlation algorithm (data correlation can be positive, negative, or no correlation; correlation is a quantitative indicator measuring the strength of the relationship between two things), the data correlation between A (i.e., data flow on the preset bus of the communication control unit TCU-ADAS intelligent driver assistance system) and C (i.e., data flow on the preset bus of the intelligent driver assistance system ADAS-Vehicle Control system) within a preset time period (e.g., 9:00-9:20) is calculated, as is the data correlation between B (i.e., data flow on the preset bus of the vehicle infotainment system HU-ADAS intelligent driver assistance system) and C (i.e., data flow on the preset bus of the intelligent driver assistance system ADAS-Vehicle Control system) within the preset time period (e.g., 9:00-9:20). In this application, the communication control unit TCU and the vehicle infotainment system HU are components, the vehicle control system (Vehicle Control) belongs to the vehicle control domain, A and B are component data flows, and C is the vehicle control domain data flow.

[0218] For example, the calculation formula for the data correlation algorithm is as follows:

[0219]

[0220] Where δ represents the correlation between the component data traffic of each type of component included in the calculated component data traffic and the vehicle control domain data traffic within a preset time period; n represents the number of data traffic collections within the preset time period, i.e., the number of sampling points within the preset time period (for example, how many times data traffic was collected within the preset time period of 9:00-9:20, for example, 5 times, then n equals 5), d i This represents the difference in ranking between the component data flow at the i-th data acquisition moment within a preset time period and the vehicle control domain data flow at the i-th data acquisition moment.

[0221] Example:

[0222] When δ < 0.5 for A and C, it indicates that the in-vehicle network security is good;

[0223] When 0.5 ≤ δ < 0.7 for both A and C, it indicates a potential danger in the vehicle's network, prompting the customer to take over the vehicle.

[0224] When 0.7 ≤ δ < 0.9 for both A and C, it indicates that a safety incident related to autonomous driving has occurred inside the vehicle. In this case, the customer should be prompted to take over the vehicle and disable the autonomous driving function.

[0225] When 0.9 ≤ δ ≤ 1 for A and C, it indicates that a serious remote attack on the autonomous driving system has occurred inside the vehicle. The customer must be prompted to take over the vehicle, disable the autonomous driving function, and disconnect the vehicle's network connectivity.

[0226] or,

[0227] When δ < 0.5 for B and C, it indicates that the in-vehicle network security is good;

[0228] When 0.5 ≤ δ < 0.7 for both B and C, it indicates a potential danger in the vehicle's network, prompting the customer to take over the vehicle.

[0229] When 0.7 ≤ δ < 0.9 for both B and C, it indicates that a safety incident related to autonomous driving has occurred inside the vehicle. In this case, the customer should be prompted to take over the vehicle and disable the autonomous driving function.

[0230] When 0.9 ≤ δ ≤ 1 for B and C, it indicates that a serious remote attack on the autonomous driving system has occurred inside the vehicle. The customer must be prompted to take over the vehicle, disable the autonomous driving function, and disconnect the vehicle's hotspot connection or the surrounding WIFI connection.

[0231] When the executing entity calculates the abnormal δ, the executing entity (the executing entity in this application may be, for example, the cloud or the backend, or the engine control unit (ECU) in the vehicle) handles it according to the following steps.

[0232] If δ < 0.5, no action is taken.

[0233] If 0.5≤δ<0.7, a vehicle takeover command is issued via HTTPS, forwarded to the HU by the TCU, and an audio prompt is issued to the user to take over the vehicle.

[0234] If 0.7≤δ<0.9, the vehicle takeover command and the command to disable autonomous driving are issued via HTTPS, forwarded to the HU by the TCU, and an audio prompt is issued to the user to take over the vehicle. At the same time, the TCU forwards the command to disable autonomous driving to the intelligent driver assistance system (ADAS).

[0235] With a value of 0.9≤δ≤1, in addition to issuing vehicle takeover commands and disabling autonomous driving commands, a network disconnection command is also issued. For example, a firewall rule is issued to the TCU to cut off the SIM card's network access capability, thereby fundamentally eliminating the possibility of the vehicle being remotely attacked.

[0236] In one embodiment of the present invention, when the threshold ranges to which the δ between AC and BC calculated by the executing entity belong are different, the executing entity can perform corresponding security protection operations based on the security strategy corresponding to the interval to which the larger δ value belongs, so as to improve the security level of the vehicle network, or perform security protection operations for the corresponding threshold interval according to the preset priority (AC priority or BC priority).

[0237] This application combines the data traffic from different preset buses in a vehicle for calculation and analysis, enabling a more comprehensive and accurate assessment of the vehicle's security status. It also allows for real-time deployment of security measures based on varying network conditions within the vehicle, forming a closed-loop solution from detection to remediation. This solution can monitor and respond to cybersecurity attack threats to the vehicle in real time, preventing information leaks and protecting property and personal safety.

[0238] Figure 7 An exemplary vehicle system architecture 700 is shown, to which the vehicle network security protection method or vehicle network security protection device of the present application embodiments can be applied.

[0239] like Figure 7 As shown, the vehicle system architecture 700 may include various systems, such as a vehicle cybersecurity protection system 701, a power system 702, a sensor system 703, a control system 704, one or more peripheral devices 705, a power supply 706, a computer system 707, and a user interface 708. Optionally, the vehicle system architecture 700 may include more or fewer systems, and each system may include multiple components. Furthermore, each system and component of the vehicle system architecture 700 can be interconnected via wired or wireless means.

[0240] The vehicle system architecture 700 includes a vehicle cybersecurity protection system 701, which can be a complete or partial vehicle cybersecurity protection mode. For example, the vehicle cybersecurity protection system 701 can automatically control the vehicle to perform vehicle cybersecurity protection without human interaction; the vehicle cybersecurity protection system 701 can also control the vehicle to perform vehicle cybersecurity protection while in a vehicle cybersecurity protection mode, and can also adjust the vehicle cybersecurity protection behavior of the vehicle cybersecurity protection system 701 through human interaction. The vehicle network security protection system 701 includes: the vehicle network security protection device as described above and a vehicle control system installed in the vehicle; the vehicle control system is used to collect data traffic on a preset bus of the vehicle within a preset time period and upload it to the vehicle network security protection device; the vehicle network security protection device acquires the data traffic on the preset bus of the vehicle uploaded by the vehicle control system within the preset time period, the data traffic including component data traffic and vehicle control domain data traffic; determines the number of data traffic acquisitions within the preset time period and the arrangement position of component data traffic and vehicle control domain data traffic corresponding to the same data acquisition time; calculates the data correlation between component data traffic and vehicle control domain data traffic based on the arrangement position and the number of data traffic acquisitions; determines the network security status of the vehicle based on the data correlation and issues control commands corresponding to the network security status to the vehicle control system; the vehicle control system receives the control commands issued by the vehicle network security protection device to control the vehicle based on the control commands.

[0241] The powertrain 702 may include components that provide power to the vehicle. For example, the powertrain 702 may include an engine, an energy source, a transmission, wheels, tires, etc. The engine may be an internal combustion engine, an electric motor, an air-compressed engine, or other combinations of engines, such as a hybrid engine consisting of a gasoline engine and an electric motor, or a hybrid engine consisting of an internal combustion engine and an air-compressed engine. The engine converts the energy source into mechanical energy to supply the transmission. Examples of energy sources may include gasoline, diesel, other petroleum-based fuels, propane, other compressed gas-based fuels, ethanol, solar panels, batteries, and other electrical sources. The energy source may also provide energy to other systems in the vehicle. Furthermore, the transmission may include a gearbox, a differential, a drive shaft, and a clutch, etc.

[0242] Sensor system 703 may include sensors for sensing the vehicle's surrounding environment. Examples include a positioning system (which may be a Global Positioning System (GPS) system, a BeiDou system, or another positioning system), radar, a laser rangefinder, an inertial measurement unit (IMU), and a camera. The positioning system can be used to determine the vehicle's geographical location. The IMU is used to sense changes in the vehicle's position and orientation based on inertial acceleration. In one embodiment, the IMU may be a combination of an accelerometer and a gyroscope. Radar can use radio signals to sense objects in the vehicle's surrounding environment. In some embodiments, in addition to sensing objects, radar can also be used to sense the speed and / or direction of travel of objects.

[0243] To detect environmental information and objects located in front of, behind, or to the sides of the vehicle, radar, cameras, and other devices can be configured at appropriate locations on the exterior of the vehicle. For example, to acquire an image of the front of the vehicle, a camera can be configured inside the vehicle and close to the windshield. Alternatively, the camera can be configured around the front bumper or radiator grille. Similarly, to acquire an image of the rear of the vehicle, a camera can be configured inside the vehicle and close to the rear window. Alternatively, the camera can be configured around the rear bumper, trunk, or tailgate. To acquire images of the sides of the vehicle, a camera can be configured inside the vehicle and close to at least one of the side windows. Alternatively, the camera can be configured around the side mirrors, fenders, or doors.

[0244] Laser rangefinders use lasers to sense objects in the environment in which a vehicle is located.

[0245] A camera can be used to capture multiple images of the vehicle's surroundings. The camera can be a still camera or a video camera.

[0246] The control system 704 may include software systems for implementing vehicle cybersecurity protection, such as systems for vehicle cybersecurity monitoring, route planning, obstacle avoidance, and image analysis. The control system 704 may also include hardware systems such as throttle and steering wheel systems. Furthermore, the control system 704 may add or replace components other than those shown and described. Alternatively, some of the components shown above may be omitted.

[0247] The control system 704 interacts with external sensors, other vehicle cybersecurity devices, other computer systems, or users via peripheral devices 705. Peripheral devices 705 may include wireless communication systems, on-board computers, microphones, and / or speakers.

[0248] In some embodiments, peripheral device 705 provides a means for user interaction with the control system 704 via a user interface. For example, an onboard computer may provide information to a user of the vehicle. The user interface may also operate the onboard computer to receive user input. The onboard computer may be operated via a touchscreen. In other cases, peripheral device may provide a means for communicating with other devices located within the vehicle. For example, a microphone may receive audio (e.g., voice commands or other audio input) from a user of the control system 704. Similarly, a speaker may output audio to a user of the control system 704.

[0249] Wireless communication systems can communicate wirelessly with one or more devices, either directly or via a communication network. For example, wireless communication systems can use networks such as cellular networks, WiFi, and wireless local area networks (WLANs), or they can use infrared links, Bluetooth, or ZigBee to communicate directly with devices. Other wireless protocols include communication systems for various vehicle network security protections.

[0250] The power source 706 can provide power to various components of the vehicle. The power source 706 can be a rechargeable lithium-ion or lead-acid battery.

[0251] Some or all of the functions implementing vehicle cybersecurity protection are controlled by computer system 707. Computer system 707 may include at least one processor that executes instructions stored in a non-transitory computer-readable medium such as memory. Computer system 707 provides the execution code for implementing vehicle cybersecurity protection in the aforementioned vehicle cybersecurity protection system.

[0252] The processor can be any conventional processor, such as a commercially available central processing unit (CPU). Alternatively, the processor can be a special-purpose device such as an application-specific integrated circuit (ASIC) or other hardware-based processor. Those skilled in the art will understand that the processor, computer, or memory can actually include multiple processors, computers, or memories that may or may not be stored in the same physical housing. For example, memory can be a hard disk drive or other storage media located in a housing different from that of a computer. Therefore, references to processors or computers will be understood to include references to a collection of processors or computers or memories that may or may not operate in parallel. Unlike using a single processor to perform the steps described herein, some components, such as steering and deceleration components, may each have their own processor, which performs calculations only relevant to the function of a particular component.

[0253] User interface 708 is used to provide information to or receive information from users of the vehicle. Optionally, user interface 708 may include one or more input / output devices within a set of peripheral devices 705, such as wireless communication systems, on-board computers, microphones, and speakers.

[0254] It should be understood that the components described above are merely an example. In actual applications, components in the various modules or systems mentioned above may be added or removed as needed. Figure 7 This should not be construed as a limitation on the embodiments of this application.

[0255] The following is for reference. Figure 8 It shows a schematic diagram of the structure of a computer system 800 suitable for implementing embodiments of the present application. Figure 8 The computer system shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0256] like Figure 8 As shown, the computer system 800 includes a central processing unit (CPU) 801, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 802 or programs loaded from storage section 808 into random access memory (RAM) 803. The RAM 803 also stores various programs and data required for the operation of the system 800. The CPU 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0257] The following components are connected to I / O interface 805: an input section 806; an output section 807 including devices such as cathode ray tubes (CRTs), liquid crystal displays (LCDs), and speakers; a storage section 808 including devices such as hard disks; and a communication section 809 including network interface cards such as LAN cards and modems. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to I / O interface 805 as needed. A removable medium 811, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 810 as needed so that computer programs read from it can be installed into storage section 808 as needed.

[0258] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by central processing unit (CPU) 801, it performs the functions defined above in the system of this application.

[0259] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0260] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0261] The modules described in the embodiments of this application can be implemented in software or hardware. These modules can also be housed in a processor; for example, a processor may include an acquisition unit, a data traffic analysis unit, a data relevance calculation unit, and a network security status determination unit. The names of these modules do not necessarily limit the functionality of the module itself.

[0262] In another aspect, this application also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs that, when executed by the device, cause the device to acquire data traffic on a preset bus of a vehicle within a preset time period, the data traffic including component data traffic and vehicle control domain data traffic; determine the number of data traffic acquisitions within the preset time period and the arrangement positions of component data traffic and vehicle control domain data traffic corresponding to the same data acquisition time; calculate the data correlation between component data traffic and vehicle control domain data traffic based on the arrangement positions and the number of data traffic acquisitions; determine the network security status of the vehicle based on the data correlation; and issue control commands corresponding to the network security status to the vehicle control system so that the vehicle control system controls the vehicle based on the control commands.

[0263] The computer program product of this application includes a computer program that, when executed by a processor, implements the vehicle network security protection method in the embodiments of this application.

[0264] According to the technical solution of the embodiments of this application, when a vehicle is threatened by a cybersecurity attack in the field of autonomous driving, the vehicle can take timely and targeted measures to deal with the cybersecurity attack threat, ensure customer safety, and effectively avoid customer losses.

[0265] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A vehicle cyber security protection method, characterized by, The method comprises: acquiring data flow on a preset bus of a vehicle within a preset time period, the data flow comprising component data flow and vehicle control domain data flow; determining data flow acquisition times within the preset time period and arrangement positions of the component data flow and the vehicle control domain data flow corresponding to the same data acquisition time; calculating data correlation of the component data flow and the vehicle control domain data flow based on the arrangement positions and the data flow acquisition times; determining a network security state of the vehicle according to the data correlation, and issuing a control instruction corresponding to the network security state to a vehicle control system to enable the vehicle control system to control the vehicle based on the control instruction.

2. The method of claim 1, wherein, The determination of the arrangement positions of the component data flow and the vehicle control domain data flow corresponding to the same data acquisition time within the preset time period comprises: screening a plurality of data acquisition times within the preset time period; arranging vehicle control domain data flow corresponding to the plurality of data acquisition times according to a preset sorting rule; arranging component data flow corresponding to each type of part for each data acquisition time according to the preset sorting rule; determining arrangement positions of the vehicle control domain data flow and the part data flow corresponding to each data acquisition time; Preferably, the component data flow comprises part data flow corresponding to a vehicle machine and part data flow corresponding to a communication control unit.

3. The method of claim 2, wherein, The calculation of the data correlation of the component data flow and the vehicle control domain data flow comprises: for each data acquisition time of each type of part, determining a rank difference between the arrangement position of the part data flow corresponding to the data acquisition time and the arrangement position of the vehicle control domain data flow corresponding to the same data acquisition time; based on the rank difference of the part data flow of each type of part corresponding to each data acquisition time, the data flow acquisition times and a preset data correlation calculation formula, the data correlation of the component data flow and the vehicle control domain data flow within the preset time period is calculated; Preferably, The preset data correlation calculation formula is: wherein d i a rank difference between an arrangement position of the component data flow corresponding to the i th data collection time in the preset time period and an arrangement position of the vehicle control domain data flow corresponding to the i th data collection time, n represents a data flow collection number in the preset time period, and δ is a data relevance of the component data flow of each component included in the component data flow and the vehicle control domain data flow in the preset time period.

4. The method of claim 1, wherein, The determination of the data flow acquisition times within the preset time period comprises: determining a preset data flow acquisition time interval, and determining the data flow acquisition times based on the preset time period and the data flow acquisition time interval.

5. The method of claim 1, wherein, The control instruction comprises one or more of a vehicle takeover instruction, a disable automatic driving instruction and a network disconnection instruction. The method further comprises: configuring a first preset threshold range, a second preset threshold range and a third preset threshold range related to the data correlation, and mapping different network security states to the first preset threshold range, the second preset threshold range and the third preset threshold range respectively, wherein the upper limit of the first preset threshold range is less than or equal to the lower limit of the second preset threshold range, and the upper limit of the second preset threshold range is less than or equal to the lower limit of the third preset threshold range; The method further comprises: determining the network security state of the vehicle according to the data correlation, comprising: matching the data correlation with one of the first preset threshold range, the second preset threshold range and the third preset threshold range; determining the network security state mapped by the preset threshold range matched with the data correlation as the network security state of the vehicle.

6. The method of claim 5, wherein, The method further comprises: determining the network security state of the vehicle according to the data correlation, comprising: in response to the data correlation matching the first preset threshold range, determining that the network security state of the vehicle is that there is a potential danger in the in-vehicle network; in response to the data correlation matching the second preset threshold range, determining that the network security state of the vehicle is that a security event against automatic driving has occurred in the in-vehicle network; in response to the data correlation matching the third preset threshold range, determining that the network security state of the vehicle is that a serious remote attack against automatic driving event has occurred in the in-vehicle network.

7. The method of claim 6, wherein, The method further comprises: issuing the control instruction corresponding to the network security state to the vehicle control system, so that the vehicle control system controls the vehicle based on the control instruction, comprising: in the case where it is determined that there is a potential danger in the in-vehicle network of the vehicle, issuing a vehicle takeover instruction to the vehicle control system, so that the vehicle control system prompts the user to take over the vehicle based on the vehicle takeover instruction; in the case where it is determined that a security event against automatic driving has occurred in the in-vehicle network of the vehicle, issuing a vehicle takeover instruction and a disable automatic driving instruction to the vehicle control system, so that the vehicle control system prompts the user to take over the vehicle based on the vehicle takeover instruction, and controls the intelligent auxiliary driving system to disable the automatic driving function of the vehicle based on the disable automatic driving instruction; in the case where it is determined that a serious remote attack against automatic driving event has occurred in the in-vehicle network of the vehicle, issuing a vehicle takeover instruction, a disable automatic driving instruction and a network disconnect instruction to the vehicle control system, so that the vehicle control system prompts the user to take over the vehicle based on the vehicle takeover instruction, and controls the intelligent auxiliary driving system to disable the automatic driving function of the vehicle based on the disable automatic driving instruction, and controls the communication control unit to disconnect the network connected by the vehicle based on the network disconnect instruction.

8. The method of claim 1, wherein, The method further comprises: acquiring the data flow on the preset bus of the vehicle within a preset time period, comprising: in response to the activation of the automatic driving function of the vehicle, acquiring the data flow on the preset bus of the vehicle within a preset time period at a preset data flow acquisition time interval.

9. The method of any one of claims 1-8, wherein: the vehicle control system comprises a communication control unit; the step of issuing the control instruction corresponding to the network security state to the vehicle control system comprises forwarding the control instruction corresponding to the network security state to a device in the vehicle control system for executing the control instruction via the communication control unit.

10. A vehicle cyber security shield apparatus, characterized by, comprising: an acquisition unit configured to acquire data traffic on a preset bus of the vehicle within a preset time period, the data traffic comprising component data traffic and vehicle control domain data traffic; a data traffic analysis unit configured to determine a data traffic acquisition frequency within the preset time period and an arrangement position of the component data traffic and the vehicle control domain data traffic corresponding to a same data acquisition time; a data correlation calculation unit configured to calculate a data correlation of the component data traffic and the vehicle control domain data traffic based on the arrangement position and the data traffic acquisition frequency; a network security state determination unit configured to determine a network security state of the vehicle according to the data correlation, and issue a control instruction corresponding to the network security state to the vehicle control system, so that the vehicle control system controls the vehicle based on the control instruction.

11. A vehicle cyber-security protection system, characterized by, comprising: the vehicle network security protection device of claim 10 and a vehicle control system installed in a vehicle; the vehicle control system is configured to acquire data traffic on a preset bus of the vehicle within a preset time period and upload the data traffic to the vehicle network security protection device; the vehicle network security protection device acquires the data traffic on the preset bus of the vehicle within the preset time period uploaded by the vehicle control system, the data traffic comprising component data traffic and vehicle control domain data traffic; determining a data traffic acquisition frequency within the preset time period and an arrangement position of the component data traffic and the vehicle control domain data traffic corresponding to a same data acquisition time; calculating a data correlation of the component data traffic and the vehicle control domain data traffic based on the arrangement position and the data traffic acquisition frequency; determining a network security state of the vehicle according to the data correlation, and issuing a control instruction corresponding to the network security state to the vehicle control system; the vehicle control system receives the control instruction issued by the vehicle network security protection device to control the vehicle based on the control instruction.

12. The system of claim 11, wherein: the vehicle control system comprises a communication control unit, a vehicle machine, an intelligent auxiliary driving system, and a vehicle controller, the communication control unit is in communication connection with the vehicle machine, the intelligent auxiliary driving system, the vehicle controller, and the vehicle network security protection device; the vehicle machine is in communication connection with the intelligent auxiliary driving system; the intelligent auxiliary driving system is in communication connection with the vehicle controller; the communication control unit is configured to receive a vehicle takeover instruction issued by the vehicle network security protection device, and forward the vehicle takeover instruction to the vehicle machine, so that the vehicle machine prompts a user to take over the vehicle based on the vehicle takeover instruction. The communication control unit is further configured to receive a disable automatic driving instruction issued by the vehicle network security protection device, and forward the disable automatic driving instruction to the intelligent auxiliary driving system, so that the intelligent auxiliary driving system disables the automatic driving function of the vehicle based on the disable automatic driving instruction, and then the vehicle controller controls driving of the vehicle according to user operation on the vehicle. The communication control unit is further configured to receive a network disconnection instruction issued by the vehicle network security protection device, and disconnect the network connected by the vehicle based on the network disconnection instruction.

13. A vehicle characterized by comprising: The vehicle network security protection device of claim 10 or the vehicle network security protection system of any one of claims 11-12.