Method and system for improving safety of vehicle
By acquiring IDS event information and vehicle operating status, and combining network security and functional safety factors, response strategies are determined and implemented, solving the problem of protecting the safety of drivers and passengers during vehicle network attacks, and achieving timely and effective security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-01
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies cannot effectively and timely integrate cybersecurity and functional safety considerations in the event of a vehicle cyberattack, resulting in an inability to effectively protect the safety of drivers and passengers.
By acquiring IDS event information and vehicle operating status, and combining the influencing factors of network security and functional safety, response strategies are determined and implemented, including acquisition modules, analysis modules, and response modules, to promptly handle network attacks.
In the event of a vehicle cyberattack, timely response strategies can be implemented to effectively protect the safety of the vehicle and its occupants, and avoid or mitigate harm.
Smart Images

Figure CN121893886A_ABST
Abstract
Description
[0001] This application is a divisional application. The original application has the application number 202080005094.5 and the original application date is September 1, 2020. The entire contents of the original application are incorporated herein by reference. Technical Field
[0002] This application relates to the automotive field, and more particularly to a method and system for improving vehicle safety. Background Technology
[0003] After decades of evolution, the automotive industry has matured in traditional electronic and mechanical technologies. In recent years, innovations in related technologies have mainly revolved around the demands for vehicle electrification, intelligentization, connectivity, and sharing. During this process, information technology and the internet have continuously integrated with the automotive industry, achieving comprehensive network connectivity within vehicles, between vehicles and people, between vehicles, and between vehicles and roads. An increasing number of vehicles now possess network access capabilities.
[0004] On July 23, 2015, Chris Valasek and Charlie Miller exploited a security vulnerability in the in-vehicle infotainment system to remotely control the vehicle via a wireless base station, re-flashing a security-risked firmware and sending dashboard control, steering, braking, and transmission commands to the CAN bus. This was a landmark security incident involving remote attacks on automobiles, leading to a global recall of over 1.4 million vehicles of the affected models by Chrysler. In recent years, reports of remote cyberattacks on vehicles have become increasingly frequent. Because cyberattacks on automobiles can affect functional safety and thus threaten the lives of drivers and passengers, automotive cybersecurity has received increasing attention from automakers, users, and regulatory agencies, and has become a pressing issue to be addressed in the evolution of automobiles towards intelligence and connectivity. Summary of the Invention
[0005] This application provides a method and system for improving vehicle safety, which can promptly execute response strategies to ensure the safety of the vehicle and its occupants in the event of a cyberattack on the vehicle.
[0006] In a first aspect, embodiments of this application provide a method for improving vehicle safety, including: Obtain the first IDS (Intrusion Detection System) event information and the first vehicle operating status; The first response strategy is determined based on the first IDS event information and the first vehicle operating status. Send the first response strategy to the first onboard component.
[0007] In the embodiments of this application, an IDS event refers to a security warning message generated by an intrusion detection system when the triggering conditions of the intrusion detection system are met. The triggering conditions of the intrusion detection system are IDS event detection rules, and the set of IDS event detection rules is the IDS event detection rule set. A response strategy refers to the processing rules for responding to the aforementioned IDS event information and the vehicle's operating status. The set of response strategies is the response strategy set, and the aforementioned first response strategy belongs to this response strategy set.
[0008] According to the technical solution of this application embodiment, a step of acquiring and analyzing information related to the vehicle's operating status is added to the IDS event handling process. In the event of an IDS event, by comprehensively considering the impact factors of network security and functional safety, a response strategy can be determined and executed promptly at the vehicle end, effectively ensuring the safety of the vehicle and its occupants.
[0009] Secondly, embodiments of this application provide a system for improving vehicle safety, the system comprising: a data acquisition module, an analysis module, and a response module; The acquisition module is used to obtain the first IDS event information and the first vehicle operating status; The analysis module is used to determine the first response strategy based on the first IDS event information and the first vehicle operating status; The response module is used to send a first response strategy to the first vehicle-mounted component.
[0010] In conjunction with the second aspect, in one possible implementation, the system includes one or more sensors, and / or the acquisition module includes one or more sensors, and / or the first vehicle-mounted component includes one or more sensors.
[0011] In conjunction with the second aspect, in one possible implementation, the analysis module is integrated into the vehicle component, or the analysis module is a separate vehicle component.
[0012] In conjunction with the second aspect, in one possible implementation, the system further includes an execution module for receiving at least one of a first response strategy or a second response strategy, and / or executing at least one of the first response strategy or the second response strategy.
[0013] According to the technical solution of the above implementation method, the vehicle can execute the response strategy in a timely manner, thereby effectively avoiding or mitigating the damage to the vehicle and the driver and passengers.
[0014] In one possible implementation, in combination with any of the above aspects or possible implementation methods, the first IDS event information includes one or more of the following: event type, event description, risk level, event source, and attacked component.
[0015] In one possible implementation, combining any of the above aspects or possible implementation methods, the vehicle operating state includes intelligent driving level and driving scenario.
[0016] In one possible implementation, combining any of the above aspects or possible implementation methods, the driving scenario is defined by one or more parameters including driving speed, terrain, road conditions, driving environment, traffic conditions, and driving time period.
[0017] In combination with any of the above aspects or possible implementation methods, in one possible implementation, the vehicle's driving scenario includes at least one of Highway Cruise (HWP), Adaptive Cruise Control (ACC), Automated Valet Parking (AVP), Traffic Jam Automated Driving (TJP), Manual High-Speed Driving, Manual Low-Speed Driving, and Stationary Driving.
[0018] In combination with any of the above aspects or possible implementations, in one possible implementation, the first response strategy is associated with at least one IDS event information and at least one vehicle operating state, wherein the first IDS event belongs to one of the at least one IDS events and the first vehicle operating state belongs to one of the at least one vehicle operating states.
[0019] In combination with any of the above aspects or possible implementations, in one possible implementation, the first response strategy includes a processing strategy, or the first response strategy includes a processing strategy and a processing timing.
[0020] In this possible implementation, the first response strategy considers both the processing strategy and the corresponding processing timing. In the event of a cyberattack that affects the functional safety of the vehicle and may affect the personal safety of the driver and passengers, the response strategy can be executed in a timely manner, thereby improving the overall safety of the vehicle and the drivers and passengers.
[0021] In combination with any of the above aspects or possible implementation methods, in one possible implementation, the processing strategy includes one or more of the following: implementing the lowest risk strategy, indicating an anomaly, suggesting the driver to pull over, indicating the automatic driving function to exit, alarming the safety operation module, powering down the vehicle, and blocking illegal requests; the processing timing includes one or more of the following: immediate execution, execution after pulling over, and execution when the function is next activated.
[0022] In combination with any of the above aspects or possible implementations, in one possible implementation, the method or system for improving vehicle safety further includes: an analysis module determining a first failure mode based on first IDS event information and a first vehicle operating state, a first response strategy associated with at least one failure mode, and the first failure mode belonging to one of the at least one failure modes.
[0023] In this possible implementation, the failure mode determination process incorporates both cybersecurity and functional safety factors. Therefore, implementing the associated response strategies enables the vehicle to simultaneously defend against cyberattacks and protect the safety of drivers and passengers.
[0024] In combination with any of the above aspects or possible implementation methods, in one possible implementation method, the aforementioned vehicle components include one or more of the following: a Telematics Box (T-Box), an In-Vehicle Infotainment (IVI), a Body Control Module (BCM), a Vehicle Control Unit (VCU), a Transmission Control Unit (TCU), a Motor Control Unit (MCU), a Cockpit Domain Controller (CDC), a Mobile Data Center (MDC), and a Vehicle Integrated Unit (VIU).
[0025] In combination with any of the above aspects or possible implementations, in one possible implementation, the method or system for improving vehicle safety further includes: interacting with a safety operation module, which receives first IDS event information and sends a second response strategy to a response module based on the first IDS event information.
[0026] In this possible implementation, the second response strategy is a processing rule for responding to the first IDS event information at the network device end.
[0027] In combination with any of the above aspects or possible implementations, in one possible implementation, the second response strategy includes: Update at least one of the firmware or software of the vehicle components; And / or update at least one rule in the IDS event detection rule set; And / or update at least one of the response strategies in the set.
[0028] Thirdly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the methods in the first aspect or possible implementations described above.
[0029] Fourthly, embodiments of this application provide an electronic device including a processor coupled to a memory storing a computer program, the processor being configured to execute the computer program stored in the memory to implement the methods in the first aspect or possible implementations described above.
[0030] Fifthly, embodiments of this application provide a vehicle that includes the system for improving vehicle safety described in the second aspect or possible implementations above.
[0031] The technical solution of this application, in the event of a network intrusion incident, determines a response strategy by taking into account the influencing factors of network security and functional safety, and can execute the response strategy in a timely manner at the vehicle end, thereby protecting network security while better protecting the safety of drivers and passengers. Attached Figure Description
[0032] Figure 1 It is an intrusion detection system for intelligent connected vehicles; Figure 2 This is a schematic flowchart of a method for improving vehicle safety provided in an embodiment of this application; Figure 3 This is a schematic structural diagram of a system for improving vehicle safety performance provided in an embodiment of this application. Detailed Implementation
[0033] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the present application and are not intended to limit the present application.
[0034] Figure 1 This is an intrusion detection system for intelligent connected vehicles. The system includes an intrusion detection system (IDS) on the vehicle side and a cloud-based operations analysis center. The vehicle-side IDS can be deployed in vehicle components such as IVI, T-Box, or TCU. The vehicle-side intrusion detection system includes modules for data acquisition, IDS detection, and IDS management.
[0035] The acquisition module is used to obtain the status of on-board components and vehicle system data. For example, vehicle system data can come from Controller Area Network (CAN), Ethernet messages, or Electronic Control Unit (ECU) messages.
[0036] The IDS detection module acquires a set of detection rules corresponding to the state of the aforementioned vehicle-mounted components, and compares the feature information of the data acquired by the acquisition module with the valid states predefined in the detection rules. For example, the valid state can be a signature or a range of feature parameters. The IDS detection module can also perform AI-based model-based recognition on the data acquired by the acquisition module.
[0037] When the IDS event triggering conditions are met, i.e. the IDS event detection rules are met, the IDS management module creates an IDS event and sends the IDS event information to the cloud-based operations analysis center.
[0038] The cloud-based operations analysis center receives and analyzes IDS event information, and sends response strategies to in-vehicle components based on the analysis results. As an example, this response strategy could be: upgrading and fixing system vulnerabilities via Over-The-Air (OTA) technology.
[0039] The aforementioned technical solution, in the event of a cyberattack, involves the intrusion detection system detecting and recording the intrusion event, sending the information to the cloud, where it is analyzed by the cloud-based operations and analysis center before a response strategy is issued. However, this approach cannot respond to cyberattacks in a timely manner, and the response strategy does not integrate considerations for vehicle network security and functional safety, making it difficult to guarantee the safety of drivers and passengers.
[0040] Figure 2 This is a schematic flowchart of a method for improving vehicle safety provided in an embodiment of this application. The corresponding process will be described below in conjunction with specific vehicle components.
[0041] Step 210: Obtain the first IDS event information and the first vehicle operating status.
[0042] Specifically, the first IDS event information is associated with the first IDS event. The first IDS event information indicates one or more of the following: event type, event description, risk level, event source, and attacked component. It is understood that the event source and the attacked component can be the same in-vehicle component or different in-vehicle components. For example, in the case where the gateway is attacked and the message sent by the gateway is detected by the MDC, the event source component is the MDC, and the attacked component is the gateway. The event source and / or the attacked component can be one in-vehicle component or multiple in-vehicle components; this application does not impose any restrictions.
[0043] Specifically, the first IDS event information is one of at least one IDS event information. Each IDS event information is associated with one IDS event. Table 1 lists some examples of IDS event information.
[0044] Table 1. Examples of IDS event information
[0045] Understandably, the event descriptions in Table 1 above can be considered as event descriptions of an IDS event, that is, they can characterize an IDS event.
[0046] As shown in Table 1 above, the event types include: (I) Vehicle control attacks: Attacks that exploit vulnerabilities in the software or the overall vehicle architecture to gain control of the vehicle or interfere with the user's normal operation; for example, sending forged steering commands to the chassis CAN bus is a vehicle control attack.
[0047] (II) Non-vehicle-controlled attacks: Stealing or tampering with user data, conducting reconnaissance activities such as port scanning and network sniffing. These network attacks do not affect vehicle control; for example, failure to decrypt high-precision map encrypted channel data, external network port scanning, etc. are non-vehicle-controlled attacks.
[0048] (III) Unauthorized Use of Advanced Functions: Attackers exploit or disable expiration detection mechanisms to illegally use specific functions. For example, paid functions such as real-time traffic updates, karaoke, cinema mode, music services, and satellite maps are classified as advanced functions. Attackers obtain the security measures employed to access advanced functions, such as access control, and bypass these measures to illegally use the functions. It is understood that the scope of advanced functions can also be defined according to other criteria, and this application does not impose specific limitations on these definitions.
[0049] As shown in Table 1 above, the risk level can also be referred to as the cybersecurity risk level. The type of IDS incident and its corresponding cybersecurity risk level can be assessed using dimensions commonly used in Threat Analysis and Risk Assessment (TARA), such as one or more of the four dimensions: Safety, Financial, Operational, and Privacy. Alternatively, a custom model can be used, such as one or more of the following: data compliance, legality, and vehicle type application scenario (commercial vehicle, passenger vehicle). For example, vehicle-related attacks have a high risk level; for non-vehicle-related attacks, the risk level of high-precision map encryption channel data decryption failure is high, while the risk level of external network port scanning is low. The risk level of unauthorized use of advanced functions can be low. It is understood that risk levels can also be assessed using other methods, and the embodiments in this application do not specifically limit this.
[0050] Optionally, a single IDS event can be associated with multiple IDS events. For example, a remote control IDS event may include a series of IDS events such as root privilege escalation (a regular user exploits a system vulnerability to elevate their privileges to root level), reverse shell (the controlling end listens on a TCP / UDP port, and the controlled end sends a request to that port, redirecting its command line input and output to the controlling end), sensitive file modification, and unauthorized vehicle control command transmission. In other words, this remote control IDS event information can be associated with multiple IDS events such as root privilege escalation, reverse shell, sensitive file modification, and unauthorized vehicle control command transmission.
[0051] Specifically, the first vehicle operating state can also be referred to as the first vehicle operating state, which includes at least one of the autonomous driving level and driving scenario.
[0052] As an example of the above specific implementation methods, the level of autonomous driving can refer to the vehicle intelligence classification standard formulated by the Society of Automotive Engineers (SAE). For example, Level 0 is manual driving, Level 1 is driver assistance, Level 2 is partial autonomous driving, Level 3 is conditional autonomous driving, Level 4 is highly autonomous driving, and Level 5 is fully autonomous driving. The above classification of autonomous driving levels is only for illustrative purposes, and the embodiments of this application do not limit the classification standards and levels of autonomous driving.
[0053] As another example of the above specific implementation methods, a driving scenario may include one or more parameters defined such as driving speed, terrain, road conditions, driving environment, traffic conditions, and driving time period. For example, the division of driving scenarios may include at least one of the following: Highway Pilot (HWP), Adaptive Cruise Control (ACC), Autonomous Valet Parking (AVP), Traffic Jam Pilot (TJP), manual high-speed driving, manual low-speed driving, and stationary driving. Taking Highway Pilot (HWP) as an example, the Operational Design Domain (ODD) of this driving scenario includes: the driver must hold a driver's license and pay attention to road conditions at all times; driving is only permitted on roads where two-way lanes are physically separated; the maximum speed is 120 km / h, with or without vehicles ahead, lane changes are allowed, and construction sites are permitted; driving can be done during the day or night, and in moderate rain or moderate snow conditions. For example, the speed ranges covered by manual high-speed, medium-speed, and low-speed driving scenarios can refer to industry-standard guidelines or relevant national laws, regulations, and rules; the embodiments of this application do not impose specific limitations. It is understandable that the definition of vehicle driving scenarios can also be divided according to other standards, and the embodiments of this application do not impose specific limitations.
[0054] Optionally, other indicators can be used to characterize the first vehicle operating state. For example, the first vehicle operating state may include at least one of vehicle driving state and vehicle service state. The vehicle driving state may include at least one of driving speed, acceleration parameters, braking parameters, and steering parameters. The vehicle service state may include one or more of intelligent driving level, high-precision map download status, driving road information, and driver status information. It is understood that the representation method of the vehicle operating state is not limited in the embodiments of this application.
[0055] It is understood that the specific methods for obtaining the first IDS event information and the first vehicle operating status are not limited in the various embodiments of this application.
[0056] Step 220: Determine the first response strategy based on the first IDS event information and the first vehicle operating status.
[0057] For example, the first response strategy is one of at least one response strategy, wherein each response strategy may include a processing strategy. The processing strategy may include one or more of the following: implementing a minimum risk strategy, alerting the driver to an anomaly, suggesting the driver pull over, prompting the driver to disengage the autonomous driving function, alerting the safety operations module, powering down the vehicle, and blocking unauthorized requests. For example, implementing a minimum risk strategy includes driver takeover of the vehicle. For different response strategies, at least one of the contents of the corresponding processing strategy will differ.
[0058] For example, each response strategy includes a processing strategy and a processing timing. The processing strategy is as described above, and the processing timing includes one or more of the following: immediate execution, execution after parking, and execution when the function is next enabled.
[0059] Specifically, the first response strategy is determined based on the first IDS event information and the first vehicle operating status. The first response strategy can be one of at least one of the response strategies in the table below.
[0060] Table 2 below shows examples of determining different response strategies based on different IDS event information and different vehicle operating states.
[0061] Table 2. Examples of IDS event information, vehicle operating status, and response strategies
[0062] As a specific example, as shown in Table 1, a network attack event that sends a forged steering command to the chassis CAN bus is classified as a vehicle control attack, and the event source is the VCU. Therefore, the risk level of this IDS event is determined to be high. As shown in Table 2 above, under the conditions of L3 intelligent driving level and highway cruise HWP driving scenario, based on the aforementioned IDS event information and vehicle operating status, the handling strategies are determined as follows: 1. Execute the lowest risk strategy; 2. If the driver has taken over, indicate an anomaly and suggest the driver pull over; 3. Alarm the safety operation module. The timing for handling strategies 1 and 2 is immediate execution, while the timing for handling strategy 3 is execution after pulling over.
[0063] As another specific example, as shown in Table 1, for the event of failure to decrypt high-precision map encrypted channel data, the event type is non-vehicle control attack, and the event source is T-Box, thus determining the risk level of this IDS event to be high. As shown in Table 2 above, under the conditions of intelligent driving level L0 and a stationary driving scenario, based on the aforementioned IDS event information and vehicle operating status, the handling strategies are determined as follows: 1. Alarm the user, indicating an abnormality in the user's device; 2. Alarm the security operation module. The processing timing corresponding to handling strategies 1 and 2 is immediate execution.
[0064] Optionally, before determining the response strategy, embodiments of this application further include determining the failure mode. In embodiments of this application, failure refers to the state in which an on-board component loses its intended function. A failure mode refers to the entire failure process from the factors causing the failure, the failure mechanism, the failure development process to the arrival of the critical failure state; it is the manifestation of the failure.
[0065] Specifically, the first failure mode is determined based on the first IDS event information and the first vehicle operating status.
[0066] Furthermore, determining the first response strategy based on the first IDS event information and the first vehicle operating status includes: determining the first failure mode based on the first IDS event information and the first vehicle operating status, and then determining the first failure management measure based on the first failure mode. It is understood that in the various embodiments of this application, the first failure management measure corresponds to or has the same meaning as the first response strategy.
[0067] Table 3 below uses IDS event information 1 as an example to illustrate how different failure modes are determined based on IDS event information and different vehicle operating states, and how response strategies are further determined based on the determined failure modes. The first failure mode can be one of at least one failure mode in Table 3 below.
[0068] Table 3. Examples of IDS event information, vehicle operating status, failure modes, and response strategies
[0069] As another specific example, as shown in Table 1 above, a network attack event that sends a forged steering command to the chassis CAN bus is classified as a vehicle control attack, and the event source is the VCU. Therefore, the risk level of this IDS event is determined to be high. As shown in Table 2 above, under the conditions of L3 intelligent driving level and highway cruise HWP driving scenario, based on the aforementioned IDS event information and vehicle operating status, the determined failure mode is that the HWP function is subjected to a vehicle control attack and cannot control the vehicle normally. Further, the handling strategy determined according to this failure mode is: 1. Execute the lowest risk strategy; 2. If the driver has taken over, indicate the abnormality and suggest that the driver pull over; 3. Alarm the safety operation module. The timing of handling strategies 1 and 2 is immediate execution, while the timing of handling strategy 3 is execution after pulling over.
[0070] Step 230: Send the first response strategy to the first onboard component.
[0071] The first vehicle-mounted component can be one vehicle-mounted component or multiple vehicle-mounted components.
[0072] The first vehicle component can be the same as the vehicle component belonging to the source of the incident or the target of the attack, or a different vehicle component, or the same as one or more vehicle components belonging to the source of the incident or the target of the attack.
[0073] Furthermore, different response strategies for different IDS event information can be sent to different vehicle components.
[0074] For example, the vehicle-mounted components may include one or more of the following under the Electric / Electronic Architecture (EEA): VCU, T-Box, IVI, TCU, MCU, and BCM; or one or more of the following under the Computation / Communication Architecture (CCA): MDC, CDC, and VIU.
[0075] As a specific implementation method, according to the aforementioned processing strategy, a minimum risk state message is sent to the vehicle controller (VCU), and an alarm message is sent to the cockpit domain controller (CDC) to prompt the user to exit the autonomous driving function.
[0076] Optionally, the method may also include sending a first IDS event message to the network device.
[0077] For example, network devices can be cloud servers.
[0078] The first IDS event information may include the first IDS event index, or the event type, event description, risk level, event source, and attacked component of the first IDS event.
[0079] Furthermore, the method also includes receiving a second response strategy sent by the network device.
[0080] Specifically, the second response strategy includes: updating at least one of the firmware or software of the vehicle component; and / or updating at least one of the IDS event detection rule set; and / or updating at least one of the response strategy set.
[0081] Furthermore, the method also includes sending a second response strategy to a second onboard component.
[0082] Specifically, the second vehicle-mounted component can be the same as the first vehicle-mounted component, or it can be a different vehicle-mounted component. For example, a first response strategy of implementing the minimum risk strategy is sent to the first vehicle-mounted component MDC, and a second response strategy of vehicle-mounted component software upgrade is sent to the second vehicle-mounted component T-Box.
[0083] It is understood that the sending or receiving response strategy in the various embodiments of this application refers to the information of the sending or receiving response strategy, which indicates the response strategy.
[0084] Figure 3 This is a schematic structural diagram of a system for improving vehicle safety performance provided in an embodiment of this application. The system includes a data acquisition module 310, an analysis module 320, and a response module 330, used for executing... Figure 2 The methods shown are for improving vehicle safety.
[0085] The acquisition module 310 is used to acquire the first IDS event information and the first vehicle operating status.
[0086] In one specific implementation, the acquisition module 310 includes one or more sensors, and / or the system includes one or more sensors, and / or the first vehicle-mounted component includes one or more sensors. The arrangement of the sensors can be determined according to the vehicle architecture deployment and module design requirements, and this application embodiment does not impose specific limitations.
[0087] For example, the vehicle-mounted component can be one or more of the following: vehicle information box (T-Box), in-vehicle infotainment system (IVI), transmission control unit (TCU), motor controller (MCU), vehicle control unit (VCU), body control module (BCM), cockpit domain controller (CDC), mobile data center (MDC), and vehicle integration unit (VIU).
[0088] As an example of this specific implementation, one or more sensors are arranged in the vehicle's VCU to collect vehicle driving status data, such as vehicle speed data, acceleration data, and steering data.
[0089] As another example of this specific implementation, sensors are placed in the MCU of the electric vehicle to collect motor speed data.
[0090] The analysis module 320 is used to determine the first response strategy based on the first IDS event information and the first vehicle operating status.
[0091] Optionally, the analysis module 320 is used to determine a first failure mode based on the first IDS event information and the first vehicle operating status, and the first response strategy is associated with at least one failure mode, wherein the first failure mode belongs to one of the at least one failure modes.
[0092] Optionally, the deployment method of the analysis module 320 can be selected according to the requirements of the vehicle system architecture. The analysis module 320 can be integrated into the vehicle component or the analysis module 320 can be an independent vehicle component.
[0093] The response module 330 is used to send information about the first response strategy to the vehicle-mounted components.
[0094] Optionally, the system further includes an execution module 340, which is used to receive information about the response strategy and execute the response strategy. For example, the execution module 340 is located at the vehicle end.
[0095] In one embodiment, the system further includes a sending module 350 for sending first IDS event information to the security operations module 360. It is understood that the security operations module 360 in this embodiment corresponds to the above... Figure 2 The network devices described herein.
[0096] Furthermore, the response module 330 is also used to receive a second response strategy from the security operations module 360.
[0097] In another embodiment, the system further includes a sending module 350 and a safety operation module 360. The sending module 350 sends first IDS event information to the safety operation module 360, which receives and analyzes the first IDS event information and sends a second response strategy to the response module 330 based on the analysis results. In this embodiment, the second response strategy is a processing rule for the system to respond to IDS event information and the overall vehicle operating status in order to improve vehicle safety.
[0098] Furthermore, the response module 330 receives a second response strategy.
[0099] Furthermore, the response module 330 sends a second response strategy to the execution module 340.
[0100] In various embodiments of this application, the second response strategy may include updating at least one of the firmware or software of the vehicle component. For example, in the event of a security vulnerability in the firmware and / or software of the vehicle component, the second response strategy may include upgrading the firmware or software involved in the security vulnerability via OTA (Over-The-Air).
[0101] Alternatively, the second response strategy may also include updating at least one of the IDS event detection rule set or response strategy set. For example, the response strategy can be configured through the management module of the external interface of the IDS via OTA, and then the response strategy can be distributed to the corresponding vehicle components.
[0102] For the sake of convenience and brevity, the specific description in this embodiment can be referred to the foregoing. Figure 2 The descriptions in the corresponding method embodiments are not repeated here.
[0103] This application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the functionality described in this application. Figure 2 The method provided in the illustrated embodiment.
[0104] An electronic device provided in this application includes: One or more processors for executing computer programs stored in memory to implement the functions described in this application. Figure 2 The method provided in the illustrated embodiment.
[0105] Optionally, the memory is coupled to the processor.
[0106] Optionally, the electronic device may also include the aforementioned memory, on which a computer program is stored.
[0107] This application provides a vehicle, which includes the features described in this application. Figure 3 The system provided in the illustrated embodiment.
[0108] It should be noted that the above embodiments are illustrated using VCU as an in-vehicle component, but this does not constitute a limitation on this application. The above solutions can also be applied to the technical solutions of other in-vehicle components, and this application does not limit the specific type of in-vehicle component.
[0109] The terminology used in the detailed implementation section of this application is only for explaining the specific implementation of this application and is not intended to limit the embodiments of this application.
[0110] It should be noted that, for the purpose of clearly describing the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with essentially the same function and effect. For example, the first response and the second response strategy are only used to distinguish different response strategies, and unless otherwise explicitly specified and limited, they do not limit their order, nor should they be construed as indications or implications. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order.
[0111] In this application, the terms "automobile," "vehicle," and "complete vehicle," or other similar terms, include general motor vehicles, such as sedans, SUVs, MPVs, buses, trucks, and other freight or passenger vehicles; water transport vehicles, including various ships and boats; and aircraft, including hybrid vehicles, electric vehicles, gasoline vehicles, plug-in hybrid vehicles, fuel cell vehicles, and other alternative fuel vehicles. Hybrid vehicles refer to vehicles with two or more power sources, and electric vehicles include pure electric vehicles and range-extended electric vehicles; this application does not specifically limit their use.
[0112] Those skilled in the art will appreciate that the functionality described in conjunction with the various illustrative logic blocks, modules, and algorithmic steps disclosed herein can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functionality described by the various illustrative logic blocks, modules, and steps can be stored or transmitted as one or more instructions or codes on a computer-readable medium and executed by a hardware-based processing unit. The computer-readable medium may comprise a computer-readable storage medium, which corresponds to a tangible medium, such as a data storage medium, or a communication medium that includes any medium facilitating the transfer of a computer program from one place to another (e.g., according to a communication protocol). In this way, a computer-readable medium may substantially correspond to (1) a non-transitory tangible computer-readable storage medium, or (2) a communication medium, such as a signal or carrier wave. The data storage medium may be any available medium accessible by one or more computers or one or more processors to retrieve instructions, code, and / or data structures for implementing the techniques described in this application. A computer program product may comprise a computer-readable medium.
[0113] By way of example and not limitation, such computer-readable storage media may include RAM, ROM, EEPROM, CD-ROM or other optical disc storage devices, magnetic disk storage devices or other magnetic storage devices, flash memory, or any other medium that may be used to store desired program code in the form of instructions or data structures and is accessible by a computer. Furthermore, any connection is properly referred to as a computer-readable medium. For example, if instructions are transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. However, it should be understood that computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other temporary media, but are specifically addressed to non-temporary tangible storage media. As used herein, disks and optical discs include compact optical discs (CDs), laser optical discs, optical discs, digital versatile optical discs (DVDs), and Blu-ray discs, where disks typically reproduce data magnetically, while optical discs reproduce data optically using lasers. The combination of the above items should also be included within the scope of computer-readable media.
[0114] Instructions can be executed by one or more processors, such as digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable arrays (FPGAs), or other equivalent integrated or discrete logic circuits. Therefore, the term "processor" as used herein can refer to any of the foregoing structures or any other structures suitable for implementing the techniques described herein. Furthermore, in some aspects, the techniques can be fully implemented in one or more circuit or logic elements.
[0115] The technology of this application can be implemented in a wide variety of devices or equipment, including in-vehicle devices, integrated circuits (ICs), or a set of ICs (e.g., chipsets). The various components and modules described in this application are intended to emphasize functional aspects of the apparatus for performing the disclosed technology, but do not necessarily need to be implemented by different hardware. In fact, as described above, various modules can be combined with suitable software and / or firmware in hardware, or provided via interoperable hardware (including one or more processors as described above).
[0116] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0117] The above description is merely a specific embodiment of this application. Variations or substitutions that can be easily conceived by those skilled in the art within the scope of this application should all be included within the protection scope of this application. The protection scope of this application shall be determined by the scope of the claims.
Claims
1. A method for improving vehicle safety, characterized in that, The method includes: Obtain the first IDS event information and the first vehicle operating status; The first response strategy is determined based on the first IDS event information and the first vehicle operating status. Send the first response strategy to the first vehicle-mounted component and send the second response strategy to the second vehicle-mounted component; The first response strategy includes: processing strategy and processing timing; The second response strategy includes updating at least one of the firmware or software of the vehicle component; And / or update at least one rule in the IDS event detection rule set; And / or update at least one of the response strategies in the set.
2. The method according to claim 1, characterized in that, The first IDS event information is used to indicate one or more of the following: event type, event description, risk level, event source, and attacked component.
3. The method according to claim 1 or 2, characterized in that, The first vehicle operating state includes at least one of the following: autonomous driving level and driving scenario.
4. The method according to claim 3, characterized in that, The driving scenario is defined by one or more parameters including driving speed, terrain, road conditions, driving environment, traffic conditions, and driving time period.
5. The method according to claim 4, characterized in that, The driving scenarios include one or more of the following: Highway Cruise (HWP), Adaptive Cruise Control (ACC), Automatic Valet Parking (AVP), Traffic Jam Automated Driving (TJP), Manual Highway Driving, Manual Low-Speed Driving, and Stationary Driving.
6. The method according to any one of claims 1-5, characterized in that, The first response strategy is associated with at least one IDS event information and at least one vehicle operating status, wherein the first IDS event information is one of the at least one IDS event information and the first vehicle operating status is one of the at least one vehicle operating status.
7. The method according to claim 1, characterized in that, The processing strategy includes one or more of the following: implementing the lowest risk strategy, alerting the driver to an anomaly, suggesting the driver pull over, prompting the driver to exit the autonomous driving function, alerting the safety operation module, powering down the vehicle, and blocking illegal requests; the processing timing includes one or more of the following: immediate execution, execution after pulling over, and execution when the function is next activated.
8. The method according to any one of claims 1-7, characterized in that, The step of determining the first response strategy based on the first IDS event information and the first vehicle operating status specifically includes: The first failure mode is determined based on the first IDS event information and the first vehicle operating status. Based on the first failure mode, a first response strategy is determined, wherein the first response strategy is associated with at least one failure mode, and the first failure mode belongs to one of the at least one failure modes.
9. The method according to any one of claims 1-8, characterized in that, The method further includes sending the first IDS event information to the network device.
10. The method according to claim 9, characterized in that, The method also includes receiving a second response policy from a network device.
11. A system for improving vehicle safety, characterized in that, The system includes a data acquisition module, an analysis module, and a response module; The acquisition module is used to acquire the first IDS event information and the first vehicle operating status; The analysis module is used to determine a first response strategy based on the first IDS event information and the first vehicle operating status; The response module is used to send the first response strategy to the first vehicle-mounted component and the second response strategy to the second vehicle-mounted component; The first response strategy includes: processing strategy and processing timing; The second response strategy includes updating at least one of the firmware or software of the vehicle component; And / or update at least one rule in the IDS event detection rule set; And / or update at least one of the response strategies in the set.
12. The system according to any one of claims 11, characterized in that, The vehicle-mounted components include one or more of the following: vehicle information box (T-Box), in-vehicle infotainment system (IVI), transmission control unit (TCU), motor controller (MCU), vehicle control unit (VCU), body control module (BCM), cockpit domain controller (CDC), mobile data center (MDC), and vehicle integration unit (VIU).
13. The system according to claim 11 or 12, characterized in that, The system also interacts with a security operations module, which receives the first IDS event information and sends the second response strategy to the response module based on the first IDS event information.
14. The system according to any one of claims 11-13, characterized in that, The analysis module is specifically used to determine a first failure mode based on the first IDS event information and the first vehicle operating status, and to determine a first response strategy based on the first failure mode, wherein the first response strategy is associated with at least one failure mode, and the first failure mode belongs to one of the at least one failure modes.
15. The system according to any one of claims 11-14, characterized in that, The system further includes an execution module, which is configured to receive at least one of the first response strategy or the second response strategy, and / or execute at least one of the first response strategy or the second response strategy.
16. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-10.
17. An electronic device, characterized in that, The method includes a processor coupled to a memory storing a computer program, the processor executing the computer program to implement the method as described in any one of claims 1-10.
18. A vehicle, characterized in that, The vehicle includes the system as described in any one of claims 11-15.