Vehicle USB anti-virus method, device and system and vehicle

By monitoring the access behavior of external storage devices through the vehicle's USB interface using an antivirus engine, and combining cloud verification and user authorization, the system can scan and isolate viruses, thus solving the problem of virus intrusion through the vehicle's USB interface and ensuring the security of the vehicle's infotainment system.

CN121637494APending Publication Date: 2026-03-10CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-27
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

In existing technologies, the USB interface of the vehicle's infotainment system is vulnerable to virus intrusion, leading to security risks, and there is a lack of effective protection measures.

Method used

The antivirus engine monitors the access behavior of external storage devices to determine the vehicle status. A scan reminder window pops up through the human-computer interaction interface. After the user authorizes the scan, the virus is scanned and processed. Encrypted communication and cloud verification are used to ensure the legality of the authorization, and the virus files are processed in the quarantine area.

Benefits of technology

It effectively prevents viruses from invading through the vehicle's USB interface, protects the vehicle's system security, ensures the legality of operations through user authorization, and isolates virus files to prevent them from affecting the operation of the vehicle's system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121637494A_ABST
    Figure CN121637494A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle USB anti-virus method, device and system and a vehicle. The method comprises the steps that it is determined that an anti-virus engine passes authorization of a cloud; monitoring whether an external storage device access behavior exists in the USB interface of the vehicle-mounted terminal or not; if yes, whether the current driving state meets the set state condition or not is judged; when the set state condition is met, popping up a virus scanning reminding window in a human-computer interaction interface of the vehicle machine; performing file scanning on external storage equipment to determine a virus file; when determining that the virus file exists, popping up a processing window; and according to the triggering of the user on the option control in the processing window, pointedly processing the virus file. According to the method, the access behavior of the external storage device is monitored through the anti-virus engine, and the external storage device is scanned, so that the virus file is determined and processed. And the safety of the vehicle machine is protected. The invention is mainly used in the technical field of vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of vehicles, in particular to a car machine USB anti-virus method, device, system and vehicle. BACKGROUND

[0002] At present, the car machine is the main entrance for virus delivery of the vehicle, especially the car machine USB port is open, which can read and write external storage device files, and the external files without detection exist the risk of being infected with viruses, so it is necessary to monitor the car machine USB virus intrusion behavior. Therefore, how to avoid viruses entering through the USB interface of the car machine to cause safety hazards to the car machine is a technical problem urgently needed to be researched in the industry. SUMMARY

[0003] The present application provides a car machine USB anti-virus method, device, system and vehicle to solve the problem that viruses enter through the USB interface of the car machine to cause safety hazards to the car machine in the prior art, and at least provides a beneficial choice or creates conditions.

[0004] The present application provides a car machine USB anti-virus method, which comprises the following steps: monitoring whether there is an external storage device access behavior to the USB interface of the car machine; when it is determined that there is an external storage device access behavior to the USB interface of the car machine, determining whether the current driving state meets the set state condition; when the set state condition is met, popping up a virus scanning reminder window in the human-computer interaction interface of the car machine; when the virus scanning reminder window is triggered, scanning the files of the external storage device to determine virus files; when it is determined that there are virus files, popping up a processing window in the human-computer interaction interface of the car machine; According to the triggering of the option control in the processing window by the user, the virus files are processed.

[0005] Further, the determination that the anti-virus engine passes the authorization of the cloud end specifically comprises: determining that the vehicle end meets the conditions, which include that the vehicle end integrates a PKI certificate management component; the vehicle end is pre-installed with a PKI primary root certificate and a secondary root certificate, or a root certificate chain is pre-installed; and the vehicle end integrates an encryption and decryption component; determining that the cloud end meets the conditions, which include that the cloud end integrates a PKI certificate management component; the cloud end is pre-installed with a PKI primary root certificate and a secondary root certificate, or a root certificate chain is pre-installed; the cloud end integrates an encryption and decryption component; and the cloud end inputs VIN, SN, PNO, AU_KEY vehicle binding information; The vehicle end initiates a bidirectional verification request to the cloud end, and after the bidirectional verification of the vehicle end and the cloud end is completed, the vehicle end and the cloud end establish encrypted communication; The vehicle end initiates an authorization application to the cloud end through the encrypted communication, wherein the application data includes: VIN, SN, PNO; The cloud end performs validity verification according to the application data, and when the verification is correct, the cloud end sends an encrypted authorization code AU KEY to the vehicle end. After receiving the authorization code, the vehicle end uses a decryption key to decrypt the authorization code to obtain a plaintext authorization code, and inputs the authorization code into the anti-virus engine. The anti-virus engine sends the plaintext authorization code to the cloud end through a heartbeat packet. When the cloud end verifies that the plaintext authorization code is correct, the cloud end responds that the verification is successful, and allows the anti-virus engine to start loading.

[0006] Further, the monitoring of whether there is an external storage device access behavior to the USB interface of the vehicle machine is performed; when it is determined that there is an external storage device access behavior to the USB interface of the vehicle machine, it is determined whether the current driving state meets the set state condition; when the set state condition is met, a virus scanning reminder window is popped up in the man-machine interaction interface of the vehicle machine, which specifically includes: after detecting that there is an external storage device accessing the USB port of the vehicle machine, the anti-virus engine sends a data request to the vehicle machine system to inquire whether the vehicle is driving; the vehicle machine system receives the inquiry sent by the anti-virus engine and returns a state code STU CODE according to the current driving state; after receiving the state code STU CODE, the anti-virus engine determines the driving state of the vehicle according to the state code STU CODE. If the vehicle is driving, it is selected to be silent, and the request is continued after ten minutes; otherwise, a virus scanning reminder window is popped up in the man-machine interaction interface of the vehicle machine to remind the user whether to perform virus scanning on the files in the external storage device connected to the USB interface of the vehicle machine.

[0007] Further, when the virus scanning reminder window is triggered, the files in the external storage device are scanned to determine the virus files, which specifically includes: when the virus scanning reminder window is triggered, the anti-virus engine connects with the external storage device using the USB communication protocol, the anti-virus engine starts to traverse the file HASH and metadata information, pre-processes the data, extracts the virus features, and matches them with the values in the feature library. If the matching is successful, the file is classified as a virus and a log is recorded; if the matching fails or it is detected that the file is armored or encrypted, the file is isolated to a sandbox environment for execution to analyze its behavior; if it is detected that the behavior conforms to the virus features, the file is classified as a virus and a log is recorded, otherwise, the file is considered not to be a virus.

[0008] Further, according to the triggering of the option control in the processing window by the user, the virus files are processed specifically, which includes: the option control in the processing window includes: an option control reflecting the acceptance of risks, and an option control reflecting the avoidance of risks; When it is determined that the user selects the option control reflecting the acceptance of risks, the anti-virus engine does not process the virus files determined, and by default allows the virus files to execute; When it is determined that the user selects the option control reflecting the risk avoidance, the anti-virus engine will classify the virus file into a specific isolation area, and the file in the isolation area is prohibited from reading, writing and executing, and is isolated from the operation environment of the vehicle machine system.

[0009] In another aspect, a vehicle machine USB anti-virus device is provided, comprising a processor and a memory for storing a computer readable program; when the computer readable program is executed by the processor, the processor implements the vehicle machine USB anti-virus method as described in any of the above technical solutions.

[0010] In another aspect, a vehicle machine USB anti-virus system is provided, comprising a first determination module, a monitoring module, a scanning module, a second determination module and a processing module. The first determination module is configured to determine that the anti-virus engine passes the authorization of the cloud. The monitoring module is configured to monitor whether there is an external storage device access behavior of the USB interface of the vehicle machine; when it is determined that there is an external storage device access behavior of the USB interface of the vehicle machine, it is determined whether the current driving state meets the set state condition; when the set state condition is met, a virus scanning reminder window is popped up in the human-computer interaction interface of the vehicle machine. The scanning module is configured to scan the files of the external storage device to determine the virus file when the virus scanning reminder window is triggered. The second determination module is configured to pop up a processing window in the human-computer interaction interface of the vehicle machine when it is determined that there is a virus file. The processing module is configured to process the virus file according to the user's triggering of the option control in the processing window.

[0011] Further, in the first determination module, the determination that the anti-virus engine passes the authorization of the cloud includes: determining that the vehicle end meets the conditions, including: the vehicle end integrates a PKI certificate management component; the vehicle end is pre-installed with a PKI primary root certificate and a secondary root certificate, or a root certificate chain; and the vehicle end integrates an encryption and decryption component. The determination that the cloud meets the conditions includes: the cloud integrates a PKI certificate management component; the cloud is pre-installed with a PKI primary root certificate and a secondary root certificate, or a root certificate chain; the cloud integrates an encryption and decryption component; and the cloud inputs VIN, SN, PNO, AU_KEY vehicle binding information. The vehicle end initiates a bidirectional verification request to the cloud, and after the bidirectional verification of the vehicle end and the cloud is completed, the vehicle end and the cloud establish encrypted communication. The vehicle end initiates an authorization application to the cloud through the encrypted communication, wherein the application data includes VIN, SN, PNO. The cloud end performs validity verification according to the application data, and when the verification is correct, the cloud end sends an encrypted authorization code AU KEY to the vehicle end, the vehicle end receives the encrypted authorization code AU KEY and decrypts the authorization code using a decryption key to obtain a plaintext authorization code, and inputs the authorization code into the anti-virus engine, the anti-virus engine sends the plaintext authorization code to the cloud end through a heartbeat packet, and the cloud end responds to the verification success when the verification is correct, and allows the anti-virus engine to start loading.

[0012] Further, in the monitoring module, whether the USB interface of the vehicle machine has an external storage device access behavior is monitored; when it is determined that the USB interface of the vehicle machine has an external storage device access behavior, whether the current driving state meets the set state condition is judged; when the set state condition is met, a virus scanning reminder window is popped up in the man-machine interface of the vehicle machine, specifically including: after detecting that an external storage device accesses the USB port of the vehicle machine, the anti-virus engine sends a data request to the vehicle machine system to inquire whether the vehicle is driving; the vehicle machine system receives the inquiry sent by the anti-virus engine and returns a state code STU CODE according to the current driving state; after receiving the state code STU CODE, the anti-virus engine judges the vehicle driving state according to the state code STU CODE, and if the vehicle is driving, it is selected to be silent, and the request is continued after ten minutes; otherwise, a virus scanning reminder window is popped up in the man-machine interface of the vehicle machine to remind the user whether to scan the files in the external storage device connected to the USB interface of the vehicle machine.

[0013] On the other hand, a vehicle integrated with the vehicle machine USB anti-virus system of any of the above technical solutions is provided.

[0014] The method of the application has at least the following beneficial effects: the method of the application monitors the external storage device access behavior through the anti-virus engine, and forms a window in the man-machine interface of the vehicle machine to obtain the authorization of the user, so as to scan the external storage device and determine the virus file. Finally, the processing of the virus file is realized by obtaining the authorization of the user. The safety of the vehicle machine is protected. At the same time, the application also provides corresponding devices, systems and vehicles, and the beneficial effects of the devices, systems and vehicles are similar to those of the method, which will not be described here. The application is mainly used in the field of vehicle technology. BRIEF DESCRIPTION OF DRAWINGS

[0015] The accompanying drawings are used to provide a further understanding of the technical solutions of the application, and constitute a part of the specification, and are used together with embodiments of the application to explain the technical solutions of the application, and do not constitute a limitation on the technical solutions of the application.

[0016] Figure 1 is a step flow chart of the vehicle machine USB anti-virus method; Figure 2is a structural schematic diagram of a car machine USB anti-virus device; Figure 3 is a hardware structure of a car machine USB anti-virus device of another embodiment; Figure 4 is a system connection structure schematic diagram of a car machine USB anti-virus system; Figure 5 is a step flow chart of a specific embodiment of the anti-virus engine passing the authorization of the cloud; Figure 6 is a step flow chart of a specific embodiment of the anti-virus engine performing scanning; Figure 7 is a step flow chart of a specific embodiment of the anti-virus engine processing a virus file. DETAILED DESCRIPTION

[0017] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0018] It should be noted that although the functional modules are divided in the system schematic diagram and the logical order is shown in the flow chart, in some cases, the steps shown or described can be performed in a different order than the module division in the system or the order in the flow chart. The terms "first", "second", etc. in the specification and claims and the above drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.

[0019] Before the embodiments of the present application are described in detail, first, some nouns and terms involved in the embodiments of the present application will be explained, and the nouns and terms involved in the embodiments of the present application are applicable to the following explanations.

[0020] The car end refers to the vehicle itself and all hardware and software systems installed on the vehicle for data acquisition, communication and execution.

[0021] The cloud refers to a remote, centralized data center server cluster that provides computing, storage and application services for a large number of vehicles through a network.

[0022] In the related art of vehicles, how to avoid the influence of external storage devices on the safety of the car machine through the USB interface is a technical problem that needs to be studied in the industry.

[0023] Please refer to Figure 1 , Figure 5 , Figure 6 and Figure 7 , Figure 1is a flow chart of steps of a car machine USB anti-virus method. Figure 5 is a flow chart of steps of a specific embodiment of an anti-virus engine passing authorization of a cloud. Figure 6 is a flow chart of steps of a specific embodiment of an anti-virus engine performing scanning. Figure 7 is a flow chart of steps of a specific embodiment of an anti-virus engine processing a virus file.

[0024] The present application discloses a car machine USB anti-virus method, which can be executed by a software program. When the software program is executed, the steps implemented by the software program include: step 1, determining that an anti-virus engine passes authorization of a cloud.

[0025] When performing car machine USB anti-virus, it mainly relies on an anti-virus engine, and the use of the anti-virus engine needs to be authorized by the cloud. Therefore, the software program needs to obtain authorization through the cloud to load the anti-virus engine.

[0026] In some further specific embodiments, determining that the anti-virus engine passes authorization of the cloud specifically includes: determining that the anti-virus engine passes authorization of the cloud specifically includes: determining that the car end satisfies the conditions includes: the car end integrates a PKI certificate management component; the car end is pre-installed with a PKI primary root certificate and a secondary root certificate, or a root certificate chain; and the car end integrates an encryption and decryption component.

[0027] Determining that the cloud satisfies the conditions includes: the cloud integrates a PKI certificate management component; the cloud is pre-installed with a PKI primary root certificate and a secondary root certificate, or a root certificate chain; the cloud integrates an encryption and decryption component; and the cloud inputs VIN, SN, PNO, and AU_KEY vehicle model binding information.

[0028] The car end initiates a bidirectional verification request to the cloud. After bidirectional verification of the car end and the cloud is completed, the car end and the cloud establish encrypted communication.

[0029] The car end initiates an authorization application to the cloud through the encrypted communication. The application data includes: VIN, SN, and PNO.

[0030] The cloud performs validity verification according to the application data. When the verification is correct, the cloud sends an encrypted authorization code AU_KEY to the car end. After the car end receives the encrypted authorization code AU_KEY, the car end uses a decryption key to decrypt the authorization code to obtain a plaintext authorization code. The car end inputs the authorization code to the anti-virus engine. The anti-virus engine sends the plaintext authorization code to the cloud through a heartbeat packet. After the cloud verifies that the plaintext authorization code is correct, the cloud responds that the verification is successful, and allows the anti-virus engine to start loading.

[0031] In some further specific embodiments, the specific authorization process steps for the software program to request the cloud include: the vehicle initiates a connection request to the cloud. Upon receiving the vehicle's request, the cloud responds, requesting the vehicle to provide its certificate and sending its own SSL certificate to the vehicle. The vehicle verifies the validity of the cloud's SSL certificate, including whether the certificate was issued by a trusted CA, whether the certificate has expired, and whether the certificate's domain name matches the server's domain name. If the verification is successful, the vehicle confirms the cloud's trustworthiness, returns an confirmation, and sends its own certificate to the cloud for verification. Upon receiving the data packet from the vehicle, the cloud verifies the vehicle's identity. If both the vehicle and the cloud correctly verify each other's certificates, they establish an encrypted communication connection using the SSL / TLS protocol. After the encrypted communication is established, the vehicle initiates an authorization request to the cloud, with the authorization request data packet carrying the VIN and SN. The cloud checks whether the binding relationship between the vehicle's VIN, SN, and the antivirus engine's PNO exists. If the binding relationship check fails, a failure code FAIL_CODE is returned, and after 5 failures, the cloud will not accept authorization requests from the vehicle for 30 minutes. If the check succeeds, an encrypted authorization code AU_KEY is returned to the vehicle. After receiving the encrypted authorization code AU_KEY, the vehicle uses the decryption key DE_KEY to decrypt the authorization code. Once the correct authorization code is obtained, it is imported into the antivirus engine, which can then load normally.

[0032] Step 2: Monitor whether there is any external storage device access behavior at the vehicle's USB interface; if it is determined that there is an external storage device access behavior at the vehicle's USB interface, determine whether the current driving status meets the set status conditions; if the set status conditions are met, a virus scan reminder window will pop up in the vehicle's human-machine interface.

[0033] After the software program completes cloud authorization for the antivirus engine, it needs to monitor the vehicle's USB port to determine if any external storage devices are connected. Once the antivirus engine is loaded, the software program calls the vehicle's system API to register an event handler, which is triggered when a USB device is detected. When an external storage device is connected to the USB port, the antivirus engine detects the hardware change and generates an event notification, requesting the vehicle's system to provide driving status feedback. Upon receiving the request, the vehicle's system informs the user whether the vehicle is currently in motion. If the vehicle is in motion, the antivirus engine remains silent; otherwise, it displays a pop-up notification to the user, asking if they wish to authorize a scan.

[0034] In some further specific embodiments, the system monitors whether an external storage device is connected to the vehicle's USB port. When it is determined that an external storage device is connected to the vehicle's USB port, it checks whether the current driving status meets set conditions. If the set conditions are met, a virus scan reminder window pops up in the vehicle's human-machine interface. Specifically, after detecting an external storage device connected to the vehicle's USB port, the anti-virus engine sends a data request to the vehicle system, inquiring whether the vehicle is in motion. Upon receiving the inquiry from the anti-virus engine, the vehicle system returns a status code STU_CODE based on the current driving status. After receiving the STU_CODE, the anti-virus engine determines the vehicle's driving status based on the STU_CODE. If the vehicle is in motion, it remains silent and continues the request after ten minutes. Otherwise, a virus scan reminder window pops up in the vehicle's human-machine interface to remind the user whether to scan the files on the external storage device connected to the vehicle's USB port for viruses.

[0035] Step 3: When the virus scan alert window is triggered, the external storage device is scanned for files to identify virus files.

[0036] When a user determines that a virus scan is needed, the corresponding control in the virus scan alert window will be triggered. Once the software program detects this trigger, it can request the antivirus engine to scan the external storage device for files. The virus files are then identified through this file scan.

[0037] In some further specific embodiments, when the virus scan alert window is triggered, the external storage device is scanned to identify virus files. Specifically, when the virus scan alert window is triggered, the antivirus engine connects to the external storage device using a USB communication protocol. The antivirus engine begins to traverse the file's hash and metadata information, preprocesses the data, extracts virus features, and matches them with values ​​in the feature library. If a match is successful, the file is classified as a virus and logged. If a match fails or the file is detected to be packed or encrypted, the file is isolated in a sandbox environment for execution, and its behavior is analyzed. If the detected behavior matches virus features, the file is classified as a virus and logged; otherwise, the file is considered not to be a virus.

[0038] In some further specific embodiments, the antivirus engine begins by connecting to an external storage device using a USB communication protocol to traverse file hashes and metadata. After collecting the data, it extracts feature values. First, it compares the file hash value with the most recent scan cache to see if it matches a virus-specific hash. If a new hash exists, it matches it against the virus signature database. If a match is found, the file is identified as a virus and recorded. Otherwise, it compares the file's metadata feature values. If a match is found, the file is identified as a virus and recorded. If the file is found to have been packed or otherwise encrypted, relying solely on feature value extraction is insufficient to effectively determine if the file contains virus code. In such cases, heuristic analysis is employed, using a program-specific behavior pattern. The virus file is sent to a cloud-based detection sandbox, where it is executed without affecting the actual vehicle infotainment system. Once virus behavior is identified as matching virus characteristics, the cloud engine extracts new virus feature data, adds it to the virus signature database, and synchronizes it to the vehicle's antivirus engine.

[0039] Step 4: Once a virus file is confirmed to exist, a processing window will pop up in the vehicle's human-machine interface.

[0040] In order to obtain user authorization to handle virus files, the software program, after confirming the existence of a virus file, will pop up a processing window through the vehicle's human-machine interface. The processing window will have corresponding option controls, which the user can trigger to inform the software program how to handle the virus file.

[0041] Step 5: Based on the user's triggering of the option controls in the processing window, the virus file is processed accordingly.

[0042] When a user triggers the corresponding option control, the software program will detect that the option control has been triggered and then process the virus file according to the trigger result.

[0043] In some further specific embodiments, the targeted processing of virus files based on user interaction with the option controls in the processing window specifically includes: the option controls in the processing window include: option controls reflecting reception risk and option controls reflecting risk avoidance. When the user selects the option control reflecting reception risk, the antivirus engine does not perform any processing on the identified virus file and allows its execution by default. When the user selects the option control reflecting risk avoidance, the antivirus engine places the virus file in a specific isolation area. Files within this isolation area are prohibited from reading, writing, and execution, thus isolating them from the vehicle's infotainment system operating environment.

[0044] In some further specific embodiments, regarding the handling of virus files, the software program will upload logs and samples of virus files identified through behavioral analysis from the vehicle to the cloud. The cloud will then learn new virus file characteristics and synchronize updates to the virus signature database to the cloud. After viewing the scan results, the user can choose "allow" to allow the virus file to execute, or isolate the virus file to prevent it from executing on the vehicle's infotainment system. The antivirus engine will log the handling events.

[0045] This invention monitors external storage device access via an anti-virus engine and utilizes the vehicle's human-machine interface to create a window, obtaining user authorization to scan the external storage device and identify virus files. Finally, user authorization is obtained to process the virus files, thus protecting the vehicle's security.

[0046] refer to Figure 2 , Figure 2 This is a schematic diagram of the structure of the vehicle's USB anti-virus device.

[0047] On the other hand, a vehicle-mounted USB anti-virus device is provided, comprising: a processor and a memory, the memory being used to store a computer-readable program. When the computer-readable program is executed by the processor, the processor causes the processor to implement the vehicle-mounted USB anti-virus method as described in any of the above specific embodiments.

[0048] Those skilled in the art will understand that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. As is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0049] Please see Figure 3 , Figure 3 This is another embodiment of the hardware structure of a vehicle-mounted USB anti-virus device. The vehicle-mounted USB anti-virus device includes: a processor 901, a memory 902, an input / output interface 903, a communication interface 904, and a bus 905.

[0050] The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the vehicle-mounted USB anti-virus method provided in the embodiments of this application.

[0051] The memory 902 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 902 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 using the methods described in the embodiments of this application.

[0052] The input / output interface 903 is used to implement information input and output.

[0053] The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0054] Bus 905 transmits information between various components of the device, such as processor 901, memory 902, input / output interface 903, and communication interface 904.

[0055] The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0056] On the other hand, reference Figure 4 , Figure 4 This is a schematic diagram of the system connection structure of the vehicle's USB anti-virus system.

[0057] A vehicle-mounted USB anti-virus system is provided, comprising: a first determination module, a monitoring module, a scanning module, a second determination module, and a processing module.

[0058] The first determining module is used to: determine that the antivirus engine has been authorized by the cloud.

[0059] When performing USB antivirus functionality in a vehicle's infotainment system, it primarily relies on an antivirus engine, which requires cloud-based authorization to function. Therefore, the first detection module needs to obtain authorization from the cloud in order to load the antivirus engine.

[0060] In some further specific embodiments, determining that the antivirus engine has been authorized by the cloud specifically includes: determining that the vehicle meets the following conditions: the vehicle integrates a PKI certificate management component; the vehicle has a pre-installed primary root certificate and secondary root certificate of PKI, or a pre-installed root certificate chain; the vehicle integrates an encryption / decryption component.

[0061] The conditions for cloud-based integration include: cloud-based integration of PKI certificate management components; cloud-based pre-configured primary and secondary root certificates of PKI, or pre-configured root certificate chains; cloud-based integration of encryption and decryption components; and cloud-based input of VIN, SN, PNO, and AU_KEY vehicle model binding information.

[0062] The vehicle initiates a two-way authentication request to the cloud. Once the two-way authentication between the vehicle and the cloud is completed, encrypted communication is established between the vehicle and the cloud.

[0063] The vehicle initiates an authorization request to the cloud via the encrypted communication, wherein the request data includes: VIN, SN, and PNO.

[0064] The cloud verifies the validity of the application data. If the verification is correct, the cloud sends an encrypted authorization code AU_KEY to the vehicle. After receiving the code, the vehicle uses the decryption key to decrypt it to obtain the plaintext authorization code and inputs it into the anti-virus engine. The anti-virus engine sends the plaintext authorization code to the cloud via a heartbeat packet. After the cloud verifies the code and finds it correct, it responds with a verification success message and allows the anti-virus engine to start loading.

[0065] In some further specific embodiments, the specific authorization process steps for the software program to request the cloud include: the vehicle initiates a connection request to the cloud; after receiving the vehicle's request, the cloud sends a response, requesting the vehicle to provide its certificate and sending its own SSL certificate to the vehicle. The vehicle verifies the validity of the cloud's SSL certificate, including whether the certificate was issued by a trusted CA, whether the certificate has expired, and whether the certificate's domain name matches the server's domain name. After successful verification, the vehicle confirms that the cloud is trustworthy, returns an confirmation, and sends its own certificate to the cloud for verification. After receiving the data packet from the vehicle, the cloud verifies the vehicle's identity. If both the vehicle and the cloud have correctly verified each other's certificates, they will establish an encrypted communication connection using the SSL / TLS protocol. After the encrypted communication is established, the vehicle initiates an authorization request to the cloud, with the authorization request data packet carrying the VIN and SN. The cloud checks whether the binding relationship between the vehicle's VIN and SN and the antivirus engine's PNO code exists. If the binding relationship check fails, a failure code FAIL_CODE is returned, and after 5 failures, the cloud will not accept authorization requests from the vehicle for 30 minutes. If the check is successful, an encrypted authorization code AU_KEY is returned to the vehicle terminal. After receiving the encrypted authorization code AU_KEY, the vehicle terminal uses the decryption key DE_KEY to decrypt the authorization code. After obtaining the correct authorization code, it imports it into the anti-virus engine, and the anti-virus engine can be loaded normally.

[0066] The monitoring module is used to: monitor whether there is external storage device access behavior at the USB interface of the vehicle system; when it is determined that there is external storage device access behavior at the USB interface of the vehicle system, it determines whether the current driving status meets the set status conditions; when the set status conditions are met, a virus scan reminder window pops up in the human-machine interface of the vehicle system.

[0067] After completing the cloud authorization for the antivirus engine, the monitoring module needs to monitor the vehicle's USB port to determine if any external storage devices are connected. Once the antivirus engine is loaded, the monitoring module calls the vehicle's system API to register an event handler, which is triggered when a USB device is detected. When an external storage device is connected to the USB port, the antivirus engine detects the hardware change and generates an event notification, requesting the vehicle's system to provide driving status feedback. Upon receiving the request, the vehicle's system informs the user whether the vehicle is currently in motion. If the vehicle is in motion, the antivirus engine remains silent; otherwise, it displays a pop-up notification to the user, asking if they wish to authorize a scan.

[0068] In some further specific embodiments, the system monitors whether an external storage device is connected to the vehicle's USB port. When it is determined that an external storage device is connected to the vehicle's USB port, it checks whether the current driving status meets set conditions. If the set conditions are met, a virus scan reminder window pops up in the vehicle's human-machine interface. Specifically, after detecting an external storage device connected to the vehicle's USB port, the anti-virus engine sends a data request to the vehicle system, inquiring whether the vehicle is in motion. Upon receiving the inquiry from the anti-virus engine, the vehicle system returns a status code STU_CODE based on the current driving status. After receiving the STU_CODE, the anti-virus engine determines the vehicle's driving status based on the STU_CODE. If the vehicle is in motion, it remains silent and continues the request after ten minutes. Otherwise, a virus scan reminder window pops up in the vehicle's human-machine interface to remind the user whether to scan the files on the external storage device connected to the vehicle's USB port for viruses.

[0069] The scanning module is used to scan the external storage device for files to identify virus files when the virus scan alert window is triggered.

[0070] When a user determines that a virus scan is needed, the corresponding control in the virus scan alert window will be triggered. Once the scanning module detects this trigger, it can request the antivirus engine to scan the external storage device for files. The virus files are then identified through this file scan.

[0071] In some further specific embodiments, when the virus scan alert window is triggered, the external storage device is scanned to identify virus files. Specifically, when the virus scan alert window is triggered, the antivirus engine connects to the external storage device using a USB communication protocol. The antivirus engine begins to traverse the file's hash and metadata information, preprocesses the data, extracts virus features, and matches them with values ​​in the feature library. If a match is successful, the file is classified as a virus and logged. If a match fails or the file is detected to be packed or encrypted, the file is isolated in a sandbox environment for execution, and its behavior is analyzed. If the detected behavior matches virus features, the file is classified as a virus and logged; otherwise, the file is considered not to be a virus.

[0072] In some further specific embodiments, the antivirus engine begins by connecting to an external storage device using a USB communication protocol to traverse file hashes and metadata. After collecting the data, it extracts feature values. First, it compares the file hash value with the most recent scan cache to see if it matches a virus-specific hash. If a new hash exists, it matches it against the virus signature database. If a match is found, the file is identified as a virus and recorded. Otherwise, it compares the file's metadata feature values. If a match is found, the file is identified as a virus and recorded. If the file is found to have been packed or otherwise encrypted, relying solely on feature value extraction is insufficient to effectively determine if the file contains virus code. In such cases, heuristic analysis is employed, using a program-specific behavior pattern. The virus file is sent to a cloud-based detection sandbox, where it is executed without affecting the actual vehicle infotainment system. Once virus behavior is identified as matching virus characteristics, the cloud engine extracts new virus feature data, adds it to the virus signature database, and synchronizes it to the vehicle's antivirus engine.

[0073] The second determining module is used to: when it is determined that a virus file exists, pop up a processing window in the human-machine interface of the vehicle system.

[0074] In order to obtain user authorization for handling virus files, the second confirmation module, after confirming the existence of a virus file, will pop up a processing window through the vehicle's human-machine interface. The processing window will have corresponding option controls, which the user can trigger to inform the processing module how to handle the virus file.

[0075] The processing module is used to: process virus files specifically based on user-triggered options controls in the processing window.

[0076] When a user triggers the corresponding option control, the processing module will detect that the option control has been triggered and then process the virus file according to the trigger result.

[0077] In some further specific embodiments, the targeted processing of virus files based on user interaction with the option controls in the processing window specifically includes: the option controls in the processing window include: option controls reflecting reception risk and option controls reflecting risk avoidance. When the user selects the option control reflecting reception risk, the antivirus engine does not perform any processing on the identified virus file and allows its execution by default. When the user selects the option control reflecting risk avoidance, the antivirus engine places the virus file in a specific isolation area. Files within this isolation area are prohibited from reading, writing, and execution, thus isolating them from the vehicle's infotainment system operating environment.

[0078] In some further specific embodiments, regarding the handling of virus files, the processing module will upload logs and samples of virus files identified through behavioral analysis from the vehicle to the cloud. The cloud will then learn new virus file characteristics and synchronize updates to the virus signature database to the cloud. After viewing the scan results, the user can choose "allow" to allow the virus file to execute, or isolate the virus file to prevent it from executing on the vehicle's infotainment system. The antivirus engine will log the handling events.

[0079] On the other hand, a vehicle is provided that integrates the in-vehicle USB antivirus system described in the above specific embodiments.

[0080] On the other hand, a computer-readable storage medium is provided, wherein a processor-executable program is stored, which, when executed by a processor, is used to implement the in-vehicle USB anti-virus method as described in any of the above specific embodiments.

[0081] This application also discloses a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. The processor of the computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the vehicle USB anti-virus method as described in any of the preceding embodiments.

[0082] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatuses.

[0083] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0084] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, apparatuses, or units, and may be electrical, mechanical, or other forms.

[0085] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0086] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0087] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0088] Although the description of this application has been quite detailed and particularly focused on several of the described embodiments, it is not intended to limit itself to any of these details or embodiments or any particular embodiment. Rather, it should be considered as effectively covering the intended scope of this application by referring to the appended claims and taking into account the prior art, which provides for a broad possible interpretation of these claims. Furthermore, the foregoing description of this application with respect to embodiments foreseeable by the inventors is intended to provide a useful description, and non-substantial modifications to this application that have not yet been foreseen may still represent equivalent modifications.

[0089] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.

Claims

1. A car machine USB anti-virus method, characterized in that, The application relates to a method for monitoring and processing virus files in a vehicle. The application comprises the following steps: determining that an anti-virus engine passes cloud authorization; monitoring whether an external storage device accesses a USB interface of a vehicle machine; when it is determined that the USB interface of the vehicle machine has the external storage device access behavior, judging whether a current driving state meets a set state condition; when the set state condition is met, a virus scanning reminding window is popped up in a man-machine interactive interface of the vehicle machine; when the virus scanning reminding window is triggered, scanning files in the external storage device to determine virus files; when it is determined that there are virus files, a processing window is popped up in the man-machine interactive interface of the vehicle machine; 2. The car-machine USB anti-virus method of claim 1, wherein, according to user triggering of an option control in the processing window, the virus files are processed. The method for determining that the anti-virus engine passes the cloud authorization specifically comprises the following steps: determining that the vehicle end meets the conditions, which include that the vehicle end integrates a PKI certificate management component; the vehicle end is preinstalled with a PKI first-level root certificate and a PKI second-level root certificate or a root certificate chain; and the vehicle end integrates an encryption and decryption component; determining that the cloud end meets the conditions, which include that the cloud end integrates the PKI certificate management component; the cloud end is preinstalled with the PKI first-level root certificate and the PKI second-level root certificate or the root certificate chain; the cloud end integrates the encryption and decryption component; the cloud end inputs VIN, SN, PNO and AU_KEY vehicle binding information; the vehicle end initiates a bidirectional verification request to the cloud end, and after bidirectional verification of the vehicle end and the cloud end is completed, the vehicle end and the cloud end establish encrypted communication; 3. The car-machine USB anti-virus method of claim 1, wherein, the vehicle end initiates an authorization application to the cloud end through the encrypted communication, wherein the application data contains VIN, SN and PNO; the cloud end performs validity inspection according to the application data, and after correct inspection, the cloud end sends an encrypted authorization code AU_KEY to the vehicle end; after the vehicle end receives the encrypted authorization code AU_KEY, the vehicle end uses a decryption key to decrypt the authorization code to obtain a plaintext authorization code, and inputs the authorization code into the anti-virus engine; the anti-virus engine sends the plaintext authorization code to the cloud end through a heartbeat packet; after the cloud end verifies that the plaintext authorization code is correct, the cloud end responds that the verification is successful, and allows the anti-virus engine to start loading. The method for monitoring whether the external storage device accesses the USB interface of the vehicle machine, and when it is determined that the USB interface of the vehicle machine has the external storage device access behavior, judging whether the current driving state meets the set state condition; when the set state condition is met, the virus scanning reminding window is popped up in the man-machine interactive interface of the vehicle machine, specifically comprises the following steps: after detecting that the external storage device accesses the USB port of the vehicle machine, the anti-virus engine sends a data request to the vehicle system to inquire whether the vehicle is driving; the vehicle system receives the inquiry sent by the anti-virus engine, and returns a state code STU_CODE according to the current driving state; after receiving the state code STU_CODE, the anti-virus engine judges the vehicle driving state according to the state code STU_CODE, for example, if the vehicle is driving, the anti-virus engine is silent, and the anti-virus engine continues to request after ten minutes; otherwise, the virus scanning reminding window is popped up in the man-machine interactive interface of the vehicle machine to remind the user whether to perform virus scanning on the files in the external storage device connected to the USB interface of the vehicle machine.

4. The car-machine USB anti-virus method of claim 1, wherein, When the virus scanning reminder window is triggered, the file scanning on the external storage device is performed to determine the virus file, specifically including: when the virus scanning reminder window is triggered, the anti-virus engine connects with the external storage device using the USB communication protocol, the anti-virus engine starts to traverse the file HASH and metadata information, and pre-processes the data, extracts the virus characteristics, and matches with the values in the characteristic library, if the matching is successful, the file is classified as a virus and the log is recorded; if the matching fails or it is detected that the file is armored or encrypted, the file is isolated to the sandbox environment for execution, and the behavior is analyzed; if it is detected that the behavior conforms to the virus characteristics, the file is classified as a virus and the log is recorded, otherwise, the file is considered not to be a virus.

5. The car-machine USB anti-virus method of claim 1, wherein, According to the triggering of the option control in the processing window by the user, the virus file is processed specifically, including: the option control in the processing window includes: an option control reflecting receiving risk, and an option control reflecting avoiding risk; When it is determined that the user selects the option control reflecting receiving risk, the anti-virus engine does not process the determined virus file, and by default allows the virus file to execute; When it is determined that the user selects the option control reflecting avoiding risk, the anti-virus engine will classify the virus file to a specific isolation area, and the file in the isolation area is prohibited from reading, writing and executing, and is isolated from the vehicle machine system running environment.

6. A car machine USB anti-virus device, characterized in that, It includes: a processor; a memory for storing a computer readable program; When the computer readable program is executed by the processor, the processor implements the vehicle machine USB anti-virus method according to any one of claims 1-5.

7. A car machine USB anti-virus system, characterized in that, It includes: a first determination module, a monitoring module, a scanning module, a second determination module and a processing module; The first determination module is used to determine that the anti-virus engine passes the authorization of the cloud; The monitoring module is used to monitor whether there is an external storage device access behavior on the USB interface of the vehicle machine; when it is determined that there is an external storage device access behavior on the USB interface of the vehicle machine, it is judged whether the current driving state meets the set state condition; when the set state condition is met, a virus scanning reminder window is popped up in the human-computer interaction interface of the vehicle machine; The scanning module is used to scan the file of the external storage device to determine the virus file when the virus scanning reminder window is triggered; The second determination module is used to pop up a processing window in the human-computer interaction interface of the vehicle machine when it is determined that there is a virus file; The processing module is used to process the virus file according to the triggering of the option control in the processing window by the user.

8. The car machine USB anti-virus system of claim 7, wherein, In the first determination module, the anti-virus engine passing the authorization of the cloud specifically includes: the vehicle end satisfying the condition includes: the vehicle end integrating a PKI certificate management component; the vehicle end pre-installing a PKI primary root certificate and a secondary root certificate, or pre-installing a root certificate chain; the vehicle end integrating an encryption and decryption component; The determining that the cloud satisfies the condition comprises: the cloud integrating a PKI certificate management component; the cloud preinstalling a first root certificate and a second root certificate of the PKI, or preinstalling a root certificate chain; the cloud integrating an encryption and decryption component; and the cloud inputting VIN, SN, PNO, and AU_KEY vehicle model binding information; The vehicle end initiates a bidirectional verification request to the cloud end, and when bidirectional verification of the vehicle end and the cloud end is completed, the vehicle end and the cloud end establish encrypted communication; The vehicle end initiates an authorization application to the cloud end through the encrypted communication, wherein the application data comprises VIN, SN, and PNO; The cloud end performs validity verification according to the application data, and when the verification is correct, the cloud end sends an encrypted authorization code AU_KEY to the vehicle end, and the vehicle end receives the encrypted authorization code AU_KEY and decrypts the authorization code using a decryption key to obtain a plaintext authorization code, and inputs the authorization code into the anti-virus engine, which sends the plaintext authorization code to the cloud end through a heartbeat packet, and the cloud end responds to the verification success when the verification is correct, and allows the anti-virus engine to start loading.

9. The car machine USB anti-virus system of claim 7, wherein, In the monitoring module, whether an external storage device accesses the USB interface of the vehicle machine is monitored; when it is determined that the external storage device accesses the USB interface of the vehicle machine, whether the current driving state satisfies a set state condition is judged; when the set state condition is satisfied, a virus scanning reminder window is popped up in the man-machine interface of the vehicle machine, specifically comprising: when it is detected that the external storage device accesses the USB port of the vehicle machine, the anti-virus engine sends a data request to the vehicle machine system to inquire whether the vehicle is driving; the vehicle machine system receives the inquiry sent by the anti-virus engine and returns a state code STU_CODE according to the current driving state; the anti-virus engine receives the state code STU_CODE and judges the driving state of the vehicle according to the state code STU_CODE, for example, if the vehicle is driving, the anti-virus engine is silent, and the request is continued after ten minutes; otherwise, the virus scanning reminder window is popped up in the man-machine interface of the vehicle machine to remind the user whether to perform virus scanning on the files in the external storage device connected to the USB interface of the vehicle machine.

10. A vehicle characterized by comprising: The vehicle machine USB anti-virus system integrated with any one of claims 7 to 9.