Distributed vehicle intrusion detection system and automobile

By deploying multiple IDS components in the automotive distributed controller network, the problem of incomplete monitoring by a single controller is solved, and multi-dimensional safety monitoring and information security protection of the entire vehicle are achieved.

CN121547261APending Publication Date: 2026-02-17CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511787949.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-02-17

AI Technical Summary

Technical Problem

Existing vehicle intrusion detection technologies are based on a single controller, resulting in incomplete security monitoring and an inability to accurately identify hidden information security risks.

Method used

Multiple IDS components are deployed in the distributed controller network of the vehicle. Each component independently monitors the network traffic and logs of its controller, parses security events through specific rules, and uploads alarm information to the cloud-based situational awareness platform for unified management.

Benefits of technology

It enables security monitoring of multiple deployment nodes throughout the vehicle, improves the comprehensiveness of intrusion attack detection and defense, and ensures information security and data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121547261A_ABST
    Figure CN121547261A_ABST
Patent Text Reader

Abstract

According to the distributed vehicle intrusion detection system and the automobile, intrusion detection assemblies, namely, IDS assemblies, are distributed and deployed on all controllers of a distributed controller network of the automobile, and each IDS assembly can monitor network traffic, vehicle end logs, CAN events and the like of the controller where the IDS assembly is located; related events are analyzed through specific rules, related warning and early warning information is uploaded to the cloud situation awareness platform, the cloud situation awareness platform manages and displays the warning information in a unified mode, and therefore safety monitoring of a plurality of arrangement nodes, namely a plurality of controllers, of a whole vehicle can be achieved, and the safety of the whole vehicle is improved. Therefore, a safety protection strategy is provided for a plurality of arrangement nodes of the whole vehicle, the comprehensiveness of detection and defense of intrusion attacks on the vehicle is improved, and operation and maintenance of subsequent intrusion detection work are supported. The invention is widely applied to the technical field of automobiles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive technology, and in particular to a distributed vehicle intrusion detection system and a vehicle. Background Technology

[0002] As vehicles become increasingly intelligent and connected, they face growing challenges to information security. Meanwhile, sustainable network and information security risk management is becoming a requirement for VTA (Vehicle Type Approval). However, while current vehicle intrusion detection technologies can monitor network attacks on vehicles, they also suffer from incomplete security detection and fail to accurately identify some hidden information security risks. Summary of the Invention

[0003] In view of at least one of the above-mentioned technical problems, the purpose of the present invention is to provide a distributed vehicle intrusion detection system and a car.

[0004] On one hand, embodiments of the present invention include a distributed vehicle intrusion detection system, the distributed vehicle intrusion detection system comprising: Vehicle controller; Multiple IDS components; each IDS component is distributed across multiple deployment nodes on the vehicle, each IDS component is used to establish a communication link, perform security monitoring to obtain security events, and establish communication with the vehicle controller through the communication link to send the security events to the vehicle controller.

[0005] Furthermore, the vehicle controller is connected to a cloud-based situational awareness platform.

[0006] Furthermore, establishing communication with the vehicle controller includes: Register on the situational awareness platform through the vehicle controller to obtain the registration key and the authentication code of the registration key assigned by the situational awareness platform; The vehicle controller uses the registration key to negotiate a session key with the situational awareness platform. The vehicle controller retrieves a configuration file from the situational awareness platform and uses the configuration file to configure itself. The session key is used to communicate with the vehicle controller.

[0007] Furthermore, the step of communicating with the vehicle controller using the session key includes: Get the content of the sent session; The session key is used to encrypt the content of the sending session to obtain the ciphertext information. The encrypted transmission information is sent to the vehicle controller; Receive encrypted information sent by the vehicle controller; Using the session key, the received encrypted information is decrypted to obtain the received session content.

[0008] Furthermore, the step of communicating with the vehicle controller using the session key also includes: The authentication code is used to verify the integrity of the received session content.

[0009] Furthermore, the deployment node is a controller in a distributed controller network.

[0010] Furthermore, establishing a communication link includes: Each of the IDS components establishes a communication link directly connected to the vehicle controller.

[0011] Furthermore, establishing a communication link includes: Each of the IDS components is clustered to obtain multiple component combinations; each component combination includes at least one of the IDS components. For any of the component combinations, a communication link corresponding to the component combination is established; when the component combination includes one IDS component, the communication link connects the IDS component to the vehicle controller; when the component combination includes multiple IDS components, the communication link connects each IDS component to the vehicle controller in series.

[0012] Furthermore, the process of obtaining security events through security monitoring includes: For any of the IDS components, the IDS component acquires the operational data of the corresponding deployment node. When there is a previous hop in the communication link where the IDS component is located, it receives the previous hop data sent by the previous hop through the communication link, performs security monitoring on the operational data and the previous hop data, obtains the security event, and sends the operational data, the previous hop data, and the security event to the next hop of the communication link. Conversely, it performs security monitoring on the operational data, obtains the security event, and sends the operational data and the security event to the next hop of the communication link.

[0013] On the other hand, embodiments of the present invention also include a vehicle that includes the distributed vehicle intrusion detection system described in the embodiments.

[0014] The beneficial effects of the embodiments of the present invention are as follows: The distributed vehicle intrusion detection system in the embodiments deploys intrusion detection components, i.e., IDS components, on all controllers of the vehicle's distributed controller network. Since each IDS component can monitor network traffic, vehicle logs, CAN events, etc. of the controller it is located on, and parses relevant events through specific rules, it uploads relevant alarms and warning information to the cloud situational awareness platform. The cloud situational awareness platform manages and displays the alarm information in a unified manner. Therefore, it can realize the security monitoring of multiple deployment nodes, i.e., multiple controllers of the whole vehicle, thereby providing security protection strategies for multiple deployment nodes of the whole vehicle, improving the comprehensiveness of detection and defense against intrusion attacks on the vehicle, and supporting the operation and maintenance of subsequent intrusion detection work. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of the distributed vehicle intrusion detection system in the embodiment; Figure 2 This is a flowchart illustrating steps P1-P3 in the embodiment; Figure 3 This is a schematic diagram of the registration key process in the embodiment; Figure 4 This is a schematic diagram of the session negotiation process in the embodiment; Figure 5 This is a schematic diagram illustrating the workflow of the distributed vehicle intrusion detection system in this embodiment; Figure 6 This is a schematic diagram of the second method for establishing a communication link in the embodiment. Detailed Implementation

[0016] Terminology Explanation: CAN: Controller Area Network, is a serial communication protocol bus used for real-time applications and can be used for communication between various components in a car. Intrusion detection: Detection of network intrusions using malicious data, implanted viruses, or abnormal traffic; IDS: Intrusion Detection System, is a network security device that monitors network transmissions in real time and issues alarms or takes proactive measures when suspicious transmissions are detected. VDC: Vehicle Domain Controller, is a key component in modern automotive electronic architecture. It is responsible for integrating and managing multiple electronic control units (ECUs) to improve the intelligence and automation level of the vehicle.

[0017] Current vehicle intrusion detection technologies are all based on single controller detection. They assess the overall network security status of a vehicle by identifying risks in a single controller. An IDS (Intrusion Detection System) component integrated into a single controller monitors network traffic and analyzes vehicle logs to identify abnormal traffic and activity, and uploads relevant alarm information to a situational awareness platform. However, single-controller-based vehicle intrusion detection systems suffer from incomplete monitoring capabilities.

[0018] Based on the above principles, this embodiment provides a distributed vehicle intrusion detection system. This distributed vehicle intrusion detection system can be applied to vehicles equipped with a distributed controller network. The distributed controller network includes multiple controllers distributed across multiple locations on the vehicle body, each controlling corresponding functional components or sensor components. For example, referring to… Figure 1 The distributed controller network includes controller 1, controller 2, controller 3, ... controller n, etc. Controller 1 can be a window controller to control the operation of the window motor; controller 2 can be a steering controller to control the operation of the steering motor; controller 3 can be a water temperature controller to connect to the water temperature sensor and receive the temperature data detected by the water temperature sensor; ... controller n can be an audio-visual entertainment controller to control the display screen and player to achieve audio-visual playback.

[0019] In this embodiment, the structure of the distributed vehicle intrusion detection system is as follows: Figure 1 As shown. (Refer to...) Figure 1 The distributed vehicle intrusion detection system includes a vehicle domain controller (VDC) and multiple IDS components. Each IDS component specifically includes components such as a HIDS (Host-based Intrusion Detection System) and a NIDS (Network Intrusion Detection System).

[0020] In this embodiment, the controllers in the distributed controller network are used as deployment nodes, and a corresponding IDS component is deployed on each controller. For example, refer to... Figure 1 Controllers 1, 2 and 3 are equipped with IDS components consisting of Host Intrusion Detection System (HIDS) and Network Intrusion Detection System (NIDS), respectively. These three IDS components are independent of each other.

[0021] Specifically, each IDS component with a hardware entity can be installed at the location of the controller, or multiple IDS components can be centrally configured to establish a correspondence between the IDS components and the controller.

[0022] In this embodiment, refer to Figure 1 Furthermore, a situational awareness platform is deployed in the cloud. This platform can function as part of a distributed vehicle intrusion detection system (VDC) or as a separate component. The vehicle controller (VDC) establishes a communication connection with the situational awareness platform via HTTPS sockets or TLS interfaces to transmit relevant data.

[0023] In this embodiment, each IDS component establishes a communication link to connect with the vehicle controller (VDC). Specifically, each IDS component establishes a communication link directly connected to the vehicle controller. For example, refer to... Figure 1 The IDS components on controllers 1, 2 and 3 establish communication links with the vehicle controller VDC through TCP Socket channels, so that the IDS components on each controller can communicate with the vehicle controller VDC independently.

[0024] In this embodiment, taking one of the IDS components (e.g., the IDS component on controller 3) as an example, when this IDS component establishes communication with the vehicle controller, the following steps can be performed: P1. Register on the situational awareness platform through the vehicle controller and obtain the registration key and authentication code of the registration key assigned by the situational awareness platform; P2. Through the vehicle controller, a session key is negotiated with the situational awareness platform using the registration key; P3. The vehicle controller retrieves the configuration file from the situational awareness platform and uses the configuration file to configure itself. P4. Use session keys to communicate with the vehicle controller.

[0025] The process for steps P1-P3 is as follows: Figure 2 As shown, the IDS component and the situational awareness platform communicate via the vehicle controller (VDC) to perform device registration, session negotiation, configuration retrieval, and event uploading.

[0026] Step P1 is the step in the device registration process. The process of step P1 is as follows: Figure 3 As shown.

[0027] Reference Figure 3 In step P1, the registration key process is as follows: 1. The IDS component obtains its own terminal's unique device identification number (SN) and transmits the SN to the vehicle controller (VDC). The VDC then forwards the SN to the situational awareness platform for registration. 2. After verifying the correctness of the device's unique identification number (SN), the situational awareness platform calculates the registration key (RK) of the IDS component based on the unique identification number (SN). 3. After saving the registration key (RK), the situational awareness platform returns the registration key (RK) and its HMAC (Hash-based Message Authentication Code) value to the vehicle controller (VDC), which then forwards it to the IDS component of controller 3. 4. After the IDS component completes verification, the registration key (RK) and authentication code (HMAC value) assigned by the platform are stored in encrypted storage.

[0028] Step P2 is the step in the process of implementing session negotiation. The process of step P2 is as follows: Figure 4 As shown.

[0029] Reference Figure 4 In step P2, the session negotiation process is as follows: 1. The IDS component carries a unique device identifier (SN) and a randomly generated 8-byte number, which is encrypted by the registration key (RK). After the ciphertext is signed by HMAC, it is sent to the vehicle controller (VDC) and forwarded to the situational awareness platform to start negotiating the session key. 2. The situational awareness platform decrypts the device registration key (RK) obtained from the SN and verifies the validity of the authentication code (HMAC value). Then, it calculates and generates a session key (SK). The situational awareness platform encrypts the session key (SK) with the registration key (RK) and transmits it to the VDC for forwarding to each controller. 3. All subsequent HTTPS session content will be encrypted and transmitted using the session key (SK), and integrity will be verified using the authentication code (HMAC value); 4. Each session key (SK) is valid for 24 hours. Once the session key expires, it needs to be negotiated again.

[0030] Step P3 is the step in the process of pulling configuration information. The process for pulling configuration information in step P3 is as follows: 1. After the vehicle controller (VDC) starts the IDS component, the IDS component automatically calls the configuration pull interface to perform the configuration pull process. The following processes are all implemented through the configuration pull interface. 2. After the IDS component starts up and completes the above-mentioned registration and session negotiation processes, the IDS component pulls the configuration and sends the message to the situational awareness platform. 3. The situational awareness platform generates the latest configuration and forwards it to the IDS components of each controller through the vehicle controller VDC; 4. IDS components are updated to use the new configuration file.

[0031] After completing device registration, session negotiation, and configuration retrieval via steps P1-P3, within the validity period of the session key (SK), the IDS component can execute step P4 to communicate with the vehicle controller (VDC) using the session key (SK), ultimately enabling communication between the IDS component and the situational awareness platform. Specifically, the IDS component can perform the following steps: P401. Obtain the content of the sent session; P402. Use the session key to encrypt the content of the sent session to obtain the ciphertext information; P403. Send encrypted information to the vehicle controller; P404. Receive encrypted information sent by the vehicle controller; P405. Use the session key to decrypt the received ciphertext information and obtain the received session content; P406. Use authentication codes to verify the integrity of received session content.

[0032] In step P401, the session content to be sent is the information that the IDS component needs to send to the vehicle controller (VDC) or situational awareness platform, such as basic information collected by the IDS component or detected security events.

[0033] In step P402, the IDS component encrypts the transmitted session content using the session key (SK) to obtain the transmitted ciphertext information. In step P403, the encrypted transmitted ciphertext information is sent to the vehicle controller (VDC). The VDC can then forward the transmitted ciphertext information to the situational awareness platform. Because the transmitted ciphertext information is encrypted, even if intercepted, the true information will not be leaked, thus ensuring information security.

[0034] In step P404, if the situational awareness platform has information to send to the vehicle controller, it can encrypt the content using the session key (SK) to obtain the received ciphertext information. This ciphertext information is then sent to the vehicle controller (VDC), which forwards it to the IDS component. The IDS component executes step P404 to receive the ciphertext information. In step P405, the IDS component decrypts the ciphertext information using the session key (SK) to obtain the received session content, thus obtaining the information sent by the situational awareness platform. Because the received ciphertext information is encrypted, even if intercepted, the true information will not be leaked, thereby ensuring information security.

[0035] In this embodiment, after executing step P405, the IDS component can also execute step P406, using the authentication code (HMAC value) to perform integrity verification on the received session content, thereby preventing the received session content from being tampered with.

[0036] In this embodiment, based on Figure 1 The communication link shown passes through Figure 2 , Figure 3 and Figure 4 After setting up steps P1-P3 as shown, each IDS component can collect data and upload the collected data to the situational awareness platform. Specifically, the IDS component can collect two types of data: one is basic controller information, such as system and version, which is reported once by the IDS component through the vehicle controller VDC during its operating cycle; the other is various potential security events, such as network attack alarms, which are uploaded to the situational awareness platform through the vehicle controller VDC after they occur.

[0037] For example, refer to Figure 5 Each IDS component can perform security monitoring functions on its corresponding controller, including network activity security monitoring, system resource security monitoring, file activity security monitoring, system configuration integrity monitoring, traffic monitoring, process security monitoring, and virus detection. This generates security events, which indicate detected security risks that could potentially constitute an attack on the entire vehicle system or a single controller. Each IDS component sends security events to the vehicle controller (VDC) via its communication link, and the VDC then forwards these events to the cloud-based situational awareness platform. The situational awareness platform can monitor and issue alerts for the security events uploaded by each IDS component.

[0038] The distributed vehicle intrusion detection system in this embodiment deploys intrusion detection components (IDS) across all controllers in the vehicle's distributed controller network. Each IDS component can monitor network traffic, vehicle logs, CAN events, etc., of its assigned controller. It parses relevant events using specific rules and uploads related alarms and warnings to a cloud-based situational awareness platform. This platform then manages and displays the alarm information. By integrating IDS components across multiple deployment nodes in the vehicle, security monitoring of all deployment nodes (controllers) can be achieved, enabling multi-dimensional vehicle monitoring. This solves the problem of incomplete security monitoring and provides security protection strategies for multiple deployment nodes, improving the comprehensiveness of intrusion attack detection and defense, and supporting subsequent intrusion detection operations and maintenance.

[0039] In this implementation, when each IDS component establishes a communication link, it can also be like this: Figure 6 As shown, the various IDS components are clustered into multiple component groups, and each component group includes at least one IDS component. For example, refer to... Figure 6 The IDS components of controller 1, controller 2, and controller 3 are divided into two component combinations, including a component combination consisting of the IDS components of controller 1 and controller 3, and a component combination consisting solely of the IDS component of controller 2.

[0040] After determining each component combination, a corresponding communication link is established for each component combination. For example, refer to... Figure 6 For a component combination consisting solely of the IDS component of controller 2, since it includes only one IDS component (the IDS component of controller 2), a TCP Socket-based channel (TCP Socket 2) is established as the communication link for this component combination. This communication link connects the unique IDS component in this component combination to the vehicle controller VDC. For component combinations including multiple IDS components, such as... Figure 6 In a component combination consisting of the IDS component of controller 1 and the IDS component of controller 3, another TCP Socket-based channel (TCP Socket 1) is established as the communication link corresponding to this component combination. This communication link connects each IDS component in this component combination with the vehicle controller in series, for example, referring to... Figure 6 This communication link connects the IDS component of controller 1, the IDS component of controller 3, and the vehicle controller VDC in sequence. If the IDS component of controller 1 needs to communicate with the vehicle controller VDC, the IDS component of controller 1 can first send the data to be sent to the IDS component of controller 3 through this communication link (TCP Socket 1), and then the IDS component of controller 3 can send it to the vehicle controller VDC through this communication link (TCP Socket 1).

[0041] In this embodiment, all IDS components can be grouped into the same component group and a communication link can be established to connect all IDS components in series. When one of the IDS components needs to send data to the vehicle controller (VDC), if this IDS component is not directly adjacent to the vehicle controller (VDC) on the communication link, then this IDS component can first send the data to the next IDS component on this communication link, and in this way, send the data to the vehicle controller (VDC).

[0042] In this embodiment, for the following Figure 6 The communication link established as shown allows each IDS component to obtain security events in a specific manner.

[0043] Specifically, refer to Figure 6 For IDS components like the one on controller 2, since they can exclusively use a communication link, their process of obtaining security events through security monitoring is similar to... Figure 1 The process of obtaining security events through security monitoring is the same for each IDS component. For IDS components located in the same component group, such as the IDS component on controller 1 and the IDS component on controller 3, different configurations can be made according to the position of the IDS in the communication link.

[0044] For example, taking the direction in which the IDS component sends data to the vehicle controller (VDC) as the direction reference for the communication link (TCP Socket 1), and since the IDS component on controller 1 does not have a previous hop, the IDS component on controller 1 obtains the corresponding deployment node, i.e., the operating data 1 of controller 1. It then performs security monitoring on the operating data 1, including network activity security monitoring, system resource security monitoring, file activity security monitoring, system configuration integrity monitoring, traffic monitoring, process security monitoring, and virus detection, obtaining the corresponding security event 1. The IDS component on controller 1 then sends the operating data 1 and security event 1 together to the next hop of the communication link, i.e., Figure 6 The IDS component on controller 3. For the IDS component on controller 3, there is a previous hop in the communication link, specifically the IDS component on controller 1. The IDS component on controller 3 receives the previous hop data, namely, the running data 1 and security event 1 sent by the IDS component on controller 1. On the other hand, the IDS component on controller 3 also detects the corresponding running data 3 at the corresponding deployment node, i.e., controller 3, and performs security monitoring on running data 3 and running data 1 in the previous hop data, obtaining security event 3. That is, security event 3 includes both the security monitoring results of running data 3 and running data 1 by the IDS component on controller 3. The IDS component on controller 3 sends the running data it detected (running data 3), the security event it detected (security event 3), and the previous hop data (running data 1 and security event 1) to the next hop in the communication link. If the next hop in the communication link is another IDS component, that IDS component continues to execute the same steps. Figure 6 In the process, the next hop of the IDS component on controller 3 is the vehicle controller VDC, which receives data sent by the IDS component on controller 3.

[0045] In this embodiment, using Figure 6 The principle behind the communication link with a serial topology shown, and the corresponding security event monitoring method performed by each IDS component, is as follows: through Figure 6The communication link and security event monitoring method shown can enable each IDS component to perform security monitoring not only on its own detected operational data but also on the operational data accumulated from the previous hop when multiple IDS components are connected to the communication link. After adding its own detected operational data, it sends the data to the next hop of the communication link, thereby accumulating operational data from multiple different deployment nodes, i.e., multiple controllers. Furthermore, each IDS component can perform security monitoring not only on the operational data of its corresponding deployment node but also on the operational data upstream of the communication link, thus achieving multiple security monitoring and re-inspection. This results in the situational awareness platform receiving data containing multiple operational data and the results of multiple security monitoring of some of these operational data. This allows the situational awareness platform to obtain sufficient data for comprehensive analysis, reducing security monitoring distortion caused by errors in individual IDS components, and facilitating accurate vehicle safety monitoring results, ultimately achieving comprehensive and high-precision vehicle detection.

[0046] In this embodiment, a computer device can be used, including a memory and a processor. The memory is used to store at least one program, and the processor is used to load at least one program to execute the distributed vehicle intrusion detection method, thereby achieving the effect of the distributed vehicle intrusion detection method.

[0047] In this embodiment, a computer program product, including a computer program, can be used to implement the distributed vehicle intrusion detection method in the embodiment when the computer program is executed by a processor.

[0048] It should be noted that, unless otherwise specified, when a feature is referred to as "fixed" or "connected" to another feature, it can be directly fixed or connected to the other feature, or indirectly fixed or connected to the other feature. Furthermore, the descriptions of "upper," "lower," "left," and "right" used in this disclosure are only relative to the relative positional relationships of the components of this disclosure in the accompanying drawings. The singular forms "a" and "the" used in this disclosure are also intended to include the plural forms, unless the context clearly indicates otherwise. Moreover, unless otherwise defined, all technical and scientific terms used in this embodiment have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this embodiment specification is only for describing specific embodiments and is not intended to limit the embodiments of the invention. The term "and / or" as used in this embodiment includes any combination of one or more of the associated listed items.

[0049] It should be understood that although the terms first, second, third, etc., may be used to describe various elements in this disclosure, these elements should not be limited to these terms. These terms are only used to distinguish elements of the same type from each other. For example, a first element may also be referred to as a second element without departing from the scope of this disclosure, and similarly, a second element may also be referred to as a first element. The use of any and all instances or exemplary language (“e.g.,” “such as,” etc.) provided in this embodiment is intended only to better illustrate embodiments of the invention and, unless otherwise required, does not impose a limitation on the scope of embodiments of the invention.

[0050] It should be recognized that embodiments of the present invention can be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer-readable storage medium. The method can be implemented using standard programming techniques—including a non-transitory computer-readable storage medium configured with a computer program, wherein such a storage medium causes the computer to operate in a specific and predefined manner—according to the methods and drawings described in the specific embodiments. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if desired, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. Furthermore, for this purpose, the program can run on a programmed application-specific integrated circuit (ASIC).

[0051] Furthermore, the procedures described in this embodiment can be performed in any suitable order unless otherwise indicated by this embodiment or otherwise obviously contradict the context. The procedures (or variations and / or combinations thereof) described in this embodiment can be executed under the control of one or more computer systems configured with executable instructions, and can be implemented by hardware or a combination thereof as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly executes on one or more processors. A computer program includes a plurality of instructions executable by one or more processors.

[0052] Furthermore, the method can be implemented in any suitable type of computing platform, including but not limited to personal computers, minicomputers, mainframes, workstations, networked or distributed computing environments, standalone or integrated computer platforms, or in communication with charged particle tools or other imaging devices, etc. Aspects of embodiments of the invention can be implemented as machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, optical read and / or write storage medium, RAM, ROM, etc., such that it is readable by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the processes described herein. Furthermore, the machine-readable code, or portions thereof, can be transmitted via wired or wireless networks. The invention of this embodiment includes these and other different types of non-transitory computer-readable storage media when such media comprises instructions or programs that implement the steps above in conjunction with a microprocessor or other data processor. Embodiments of the invention also include the computer itself when programmed according to the methods and techniques of embodiments of the invention.

[0053] A computer program can be applied to input data to perform the functions of this embodiment, thereby transforming the input data to generate output data stored in non-volatile memory. The output information can also be applied to one or more output devices, such as a display. In a preferred embodiment of the invention, the transformed data represents physical and tangible objects, including a specific visual depiction of physical and tangible objects generated on the display.

[0054] The above are merely preferred embodiments of the present invention. The embodiments of the present invention are not limited to the above-described implementations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the embodiments of the present invention, as long as they achieve the same technical effects, should be included within the scope of protection of the embodiments of the present invention. Within the scope of protection of the embodiments of the present invention, the technical solutions and / or implementation methods can have various modifications and variations.

Claims

1. A distributed vehicle intrusion detection system, characterized in that, The distributed vehicle intrusion detection system comprises: a vehicle controller; a plurality of IDS components; each of the IDS components is arranged at a plurality of arrangement nodes distributed on the vehicle, each of the IDS components is configured to establish a communication link, to obtain a security event by performing security monitoring, and to transmit the security event to the vehicle controller through the communication link.

2. The distributed vehicle intrusion detection system of claim 1, wherein, The vehicle controller is connected to a cloud-based situation awareness platform.

3. The distributed vehicle intrusion detection system of claim 1, wherein, The communication with the vehicle controller comprises: registering with the situation awareness platform through the vehicle controller, obtaining a registration key and an authentication code of the registration key assigned by the situation awareness platform; negotiating a session key with the situation awareness platform through the vehicle controller using the registration key; pulling a configuration file from the situation awareness platform through the vehicle controller, and configuring itself using the configuration file; communicating with the vehicle controller using the session key.

4. The distributed vehicle intrusion detection system of claim 3, wherein, The communication with the vehicle controller using the session key comprises: obtaining sending session content; encrypting the sending session content using the session key to obtain sending ciphertext information; sending the sending ciphertext information to the vehicle controller; receiving receiving ciphertext information sent by the vehicle controller; decrypting the receiving ciphertext information using the session key to obtain receiving session content.

5. The distributed vehicle intrusion detection system of claim 4, wherein, The communication with the vehicle controller using the session key further comprises: performing integrity verification on the receiving session content using the authentication code.

6. The distributed vehicle intrusion detection system of any one of claims 1-5, wherein, The arrangement node is a controller in a distributed controller network.

7. The distributed vehicle intrusion detection system of claim 6, wherein, The communication link comprises: each of the IDS components establishes the communication link directly connected to the vehicle controller.

8. The distributed vehicle intrusion detection system of claim 6, wherein, The communication link comprises: clustering each of the IDS components to obtain a plurality of component combinations; each of the component combinations comprises at least one of the IDS components; for any of the component combinations, establishing the communication link corresponding to the component combination; when the component combination comprises one of the IDS components, the communication link connects the IDS component and the vehicle controller; when the component combination comprises a plurality of the IDS components, the communication link connects each of the IDS components and the vehicle controller in series.

9. The distributed vehicle intrusion detection system of claim 8, wherein, The security monitoring comprises: for any of the IDS components, the IDS component obtains running data of the corresponding arrangement node; when the IDS component is located on a communication link having a previous hop, the IDS component receives previous hop data sent by the previous hop through the communication link, performs security monitoring on the running data and the previous hop data to obtain the security event, and transmits the running data, the previous hop data and the security event to a next hop of the communication link; otherwise, the IDS component performs security monitoring on the running data to obtain the security event, and transmits the running data and the security event to the next hop of the communication link.

10. An automobile characterized by comprising: The vehicle comprises the distributed vehicle intrusion detection system according to any one of claims 1-9.