Vehicle-mounted terminal information security protection system
By introducing modules such as multi-dimensional information collection, threat analysis and decision-making, and resource perception and scheduling into the vehicle terminal information security protection system, and dynamically scheduling resources and response strategies, the system solves the problem of insufficient adaptability of vehicle terminals in complex scenarios, maximizes security protection effectiveness and optimizes resource utilization, and improves the safety and reliability of intelligent connected vehicles.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 天津布尔科技有限公司
- Filing Date
- 2026-02-24
- Publication Date
- 2026-04-21
AI Technical Summary
Existing vehicle terminal information security protection systems are not adaptable to dynamic resources and complex scenarios, have limited computing resources, are disconnected from vehicle driving safety scenarios, and lack intelligent scheduling for data collection and analysis, leading to resource exhaustion or security degradation.
It employs a multi-dimensional information acquisition module, a threat analysis and decision-making module, a proactive response execution module, a resource perception and scheduling module, a trusted and secure communication module, and a trusted and secure storage module, combined with a scenario perception unit, a resource monitoring unit, and a policy scheduling unit, a dynamic scheduling analysis engine, and data acquisition strategies to achieve optimized resource allocation and differentiated response.
Prioritizing the security of core vehicle control functions under resource constraints improves security protection effectiveness and resource utilization efficiency, enhances the overall reliability and security of the system, and achieves efficient protection of vehicles against complex network attacks.
Smart Images

Figure CN121907602A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent connected vehicle information security technology, and in particular to an in-vehicle terminal information security protection system. Background Technology
[0002] With the rapid development of intelligent connected vehicle technology, in-vehicle terminals are deeply integrated into vehicle control, infotainment, and vehicle-road-cloud collaborative networks, becoming key nodes integrating complex embedded systems, high-speed in-vehicle networks, and various wireless communication interfaces. Currently, in-vehicle information security protection technology has evolved from traditional firewalls and intrusion detection systems (IDS) to a defense-in-depth system, commonly employing multi-layered detection methods that combine signature-matching-based static rule engines with machine learning-based anomaly behavior analysis to address known threats and unknown attacks. Simultaneously, vehicle-cloud collaborative security architecture has become mainstream, providing threat intelligence updates and partial computational offloading capabilities to in-vehicle terminals through a cloud-based security operations center.
[0003] However, existing technological solutions face significant bottlenecks. First, the contradiction between rigid resource requirements and the dynamic nature of the in-vehicle environment is prominent: the computing resources, memory, and power consumption of in-vehicle terminals are strictly limited, while advanced behavioral analysis models (such as deep learning) have huge computational overhead, making it difficult to operate continuously and efficiently under all vehicle lifecycle conditions (such as high-speed driving, congestion, and parking), often falling into the dilemma of "high-performance analysis leads to resource exhaustion, while preserving resources leads to security degradation." Second, safety response strategies are disconnected from vehicle driving safety scenarios: existing systems typically use fixed response thresholds and actions, failing to dynamically adjust according to real-time vehicle status (such as vehicle speed and driving mode). For example, adopting a lengthy confirmation process for threats to the powertrain system during high-speed driving, or performing excessive network isolation when parked, may both lead to new safety or functional risks. Furthermore, data collection and analysis lack intelligent scheduling: systems often collect and analyze full data at a fixed frequency and granularity, which can easily lead to missed detection of critical vehicle control data or system overload when resources are scarce.
[0004] Therefore, there is an urgent need for an intelligent safety protection system that can adaptively schedule its safety capabilities under the stringent and dynamically changing resource constraints and driving scenarios of the vehicle terminal, ensure optimal protection of core safety objectives (especially power system safety), and guarantee vehicle driving safety. Summary of the Invention
[0005] The purpose of this invention is to provide an in-vehicle terminal information security protection system that overcomes the problem of insufficient adaptability of existing technologies under dynamic resources and complex scenarios. It can monitor the computing resources, power consumption status and vehicle operation scenarios of the in-vehicle terminal in real time, and always prioritize the security of the vehicle's core control functions under resource-constrained conditions, thereby maximizing security protection effectiveness and optimizing resource utilization, and improving the overall security and operational reliability of intelligent connected vehicles in the face of complex network attacks.
[0006] To achieve the above objectives, the present invention provides an in-vehicle terminal information security protection system, comprising: The multi-dimensional information acquisition module is used to collect data in real time.
[0007] The threat analysis and decision-making module, connected to the multi-dimensional information acquisition module, is used to integrate and analyze data and generate protection commands.
[0008] The proactive response execution module, connected to the threat analysis and decision-making module, is used to execute protection commands.
[0009] The resource awareness and scheduling module, connected to the threat analysis and decision-making module and the multi-dimensional information acquisition module, is used to monitor resources and scenarios in real time and dynamically schedule the working strategies of the threat analysis and decision-making module and the multi-dimensional information acquisition module.
[0010] The trusted and secure communication module is used to provide secure communication channels both within the system and to the outside world.
[0011] A trusted and secure storage module is used for encrypted storage of system data; The security protection main control module is connected to the multi-dimensional information acquisition module, threat analysis and decision-making module, proactive response execution module, resource perception and scheduling module, trusted secure communication module, and trusted secure storage module, respectively, for coordination and management among the modules.
[0012] Preferably, the data collected in real time by the multi-dimensional information acquisition module includes vehicle control bus data, as well as at least one other data source from vehicle Ethernet, vehicle diagnostic interface, global positioning system, or vehicle camera.
[0013] Preferably, the resource awareness and scheduling module includes: The scene perception unit is used to determine the current safety protection scene based on vehicle speed, network connection status, power mode and user driving mode information; the safety protection scene includes at least the parking standby scene, urban driving scene, highway driving scene and congestion scene.
[0014] The resource monitoring unit is used to monitor the utilization rate, memory usage rate and system power consumption of the vehicle terminal's central processing unit in real time.
[0015] The strategy scheduling unit, connected to the scenario awareness unit and the resource monitoring unit, is used to generate and issue resource scheduling instructions to the threat analysis and decision-making module based on the security protection scenario and real-time resource status.
[0016] Preferably, the threat analysis and decision-making module has at least two built-in analysis engines with different computational complexities; the policy scheduling unit controls the threat analysis and decision-making module to switch between the currently active analysis engines through resource scheduling instructions.
[0017] Preferably, at least two analytics engines include: A rule matching engine for fast matching based on a static rule base.
[0018] A behavior analysis engine for detecting abnormal behavior based on machine learning models.
[0019] Preferably, the policy scheduling unit is configured to execute the following scheduling logic: When the scene perception unit determines that the vehicle is in a parking standby scene and the resource monitoring unit shows that resources are scarce, the scheduling threat analysis and decision-making module runs the rule matching engine and reduces the data collection frequency of the multi-dimensional information collection module.
[0020] When the scene perception unit determines that the vehicle is in a high-speed driving scenario, the scheduling threat analysis and decision-making module enables the behavior analysis engine on the vehicle control bus data.
[0021] When the resource monitoring unit detects that the system power consumption exceeds a predetermined threshold, it dynamically reduces the workload of the behavior analysis engine.
[0022] Preferably, the policy scheduling unit is further configured to: authorize the active response execution module with corresponding response policies based on the security protection scenario, wherein the response policies include: In urban driving or congested scenarios, for medium- to high-level threats affecting the vehicle's powertrain, a gradual response is authorized.
[0023] In high-speed driving scenarios, for threats of the same level that affect the vehicle's power system, an immediate blocking response is authorized.
[0024] Preferably, the system further includes: The cloud-based collaborative management module connects to the cloud-based security operations center via a trusted and secure communication module, and is used for security data reporting and policy synchronization.
[0025] The security policy management module connects to the threat analysis and decision-making module and is used to receive and update the static rule base from the cloud security center.
[0026] Preferably, the static rule base contains at least one of known malicious code characteristics, network attack signatures, or abnormal message patterns.
[0027] Therefore, the present invention employs the above-mentioned vehicle terminal information security protection system, and the beneficial technical effects are as follows: (1) By setting up a resource perception and scheduling module, the present invention integrates a scene perception unit, a resource monitoring unit and a strategy scheduling unit, which can perceive the vehicle operation scene and system resource status in real time, and dynamically schedule the analysis engine of the threat analysis and decision module and the data acquisition strategy of the multi-dimensional information acquisition module accordingly. Thus, under the condition of severely limited vehicle terminal resources, the limited computing resources are intelligently allocated to the most critical protection tasks, and the security protection effectiveness and resource utilization efficiency are significantly improved.
[0028] (2) This invention achieves deep coupling between response logic and vehicle driving safety by authorizing differentiated response strategies to the active response execution module based on the safety protection scenario (such as high-speed driving or urban congestion) through the strategy scheduling unit. In high-speed scenarios, threats affecting the vehicle's power system are authorized to be blocked immediately, while in urban or congested scenarios, a gradual response with warnings is adopted. This effectively avoids secondary safety risks that may be caused by the safety operation itself and enhances the overall reliability and safety of the system.
[0029] (3) By clearly distinguishing the data collected by the multi-dimensional information acquisition module into vehicle control bus data and other data, and by instructing the strategy scheduling unit to force the use of the behavior analysis engine for vehicle control bus data in key scenarios (such as high-speed driving), the present invention ensures that the system always focuses the highest level of analysis resources on the core power and control domain of the vehicle, which greatly improves the detection and protection capabilities against attacks on the core functions of the vehicle.
[0030] (4) This invention integrates a cloud-based collaborative management module and a security policy management module to construct a sustainable security capability maintenance system for vehicle-cloud collaboration. The system can receive and update the static rule base from the cloud-based security operation center, enabling the local rule matching engine to continuously evolve. At the same time, it provides a channel for cloud-based offloading of analysis tasks when resources are insufficient, thereby achieving the complementary advantages of local lightweight and fast response and cloud-based deep analysis capabilities, enhancing the long-term adaptability and protection depth of the system. Attached Figure Description
[0031] Figure 1 This is a framework diagram of an in-vehicle terminal information security protection system according to the present invention; Figure 2 This is a schematic diagram of the analysis engine scheduling for the threat analysis and decision-making module. Figure 3 Workflow diagram for the resource awareness and scheduling module; Figure 4This is a collaborative workflow diagram of an in-vehicle terminal information security protection system in a high-speed driving scenario according to the present invention. Detailed Implementation
[0032] The technical solution of the present invention will be further described below with reference to the accompanying drawings and embodiments.
[0033] Unless otherwise defined, the technical or scientific terms used in this invention shall have the ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains.
[0034] Example 1 like Figure 1 As shown, a vehicle-mounted terminal information security protection system includes: The multi-dimensional information acquisition module is used to collect data in real time.
[0035] The multi-dimensional information acquisition module collects data in real time, including vehicle control bus data, as well as at least one other data source from vehicle Ethernet, vehicle diagnostic interface, GPS, or vehicle camera.
[0036] The threat analysis and decision-making module, connected to the multi-dimensional information acquisition module, is used to fuse and analyze data and generate protection commands. For example, Figure 2 As shown, the threat analysis and decision-making module has at least two built-in analysis engines with different computational complexities, including: The rule matching engine is used for fast matching based on a static rule base. This static rule base contains at least one of the following: known malicious code characteristics, network attack signatures, or abnormal message patterns. The rule matching engine employs efficient algorithms such as Aho-Corasick automata or regular expressions, enabling it to identify well-defined known threats with minimal resource overhead. It is suitable for scenarios with stringent real-time requirements or limited system resources.
[0037] The behavior analysis engine is used for abnormal behavior detection based on machine learning models. For example, for time-series control commands on a vehicle control bus, time-series models such as Long Short-Term Memory (LSTM) networks or autoencoders can be used to learn a baseline of normal behavior; for network traffic, algorithms such as Isolation Forest can be applied to discover abnormal patterns. During runtime, the behavior analysis engine inputs real-time data sequences into the trained model, calculates an anomaly score, and determines an anomaly when the score exceeds a preset security threshold. The outputs of the two analysis engines are comprehensively evaluated by the threat analysis and decision-making module, employing strategies such as logical decision-making or weighted scoring, to ultimately generate a unified protection command with a confidence level, such as isolating suspicious network nodes, recording relevant logs, and generating corresponding event reports to the platform server. This significantly improves the ability to detect new and complex attacks while ensuring detection efficiency.
[0038] The proactive response execution module, connected to the threat analysis and decision-making module, is used to execute protection commands.
[0039] The resource awareness and scheduling module, connected to the threat analysis and decision-making module and the multi-dimensional information acquisition module, is used to monitor resources and scenarios in real time and dynamically schedule the working strategies of the threat analysis and decision-making module and the multi-dimensional information acquisition module, such as... Figure 3 As shown, it includes: The scene perception unit is used to determine the current safety protection scene based on vehicle speed, network connection status, power mode and user driving mode information; the safety protection scene includes at least the parking standby scene, urban driving scene, highway driving scene and congestion scene.
[0040] The resource monitoring unit is used to monitor the utilization rate, memory usage rate and system power consumption of the vehicle terminal's central processing unit in real time.
[0041] The strategy scheduling unit, connected to the scenario awareness unit and the resource monitoring unit, is used to generate and issue resource scheduling instructions to the threat analysis and decision-making module based on the security protection scenario and real-time resource status.
[0042] The policy scheduling unit controls the switching between currently active analysis engines in the threat analysis and decision-making module via resource scheduling commands. The policy scheduling unit is configured to execute the following scheduling logic: When the scene perception unit determines that the vehicle is in a parking standby scene and the resource monitoring unit shows that resources are scarce, the scheduling threat analysis and decision-making module runs the rule matching engine and reduces the data collection frequency of the multi-dimensional information collection module.
[0043] When the scene perception unit determines that the vehicle is in a high-speed driving scenario, the scheduling threat analysis and decision-making module enables the behavior analysis engine on the vehicle control bus data.
[0044] When the resource monitoring unit detects that the system power consumption exceeds a predetermined threshold, it dynamically reduces the workload of the behavior analysis engine.
[0045] In addition, the policy scheduling unit is also configured to: authorize the corresponding response policy to the proactive response execution module according to the security protection scenario. The response policy includes: In urban driving or congested scenarios, for medium- to high-level threats affecting the vehicle's powertrain, a gradual response is authorized.
[0046] In high-speed driving scenarios, for threats of the same level that affect the vehicle's power system, an immediate blocking response is authorized.
[0047] The trusted and secure communication module is used to provide secure communication channels both within the system and to the outside world.
[0048] A trusted and secure storage module is used to encrypt and store system data. Specifically, this module uses a hardware encryption chip or a software encryption engine to encrypt and store system data of, but not limited to, the following types: (1) System configuration parameters and operating status information; (2) User privacy and identity authentication data; (3) Security policies and rule bases issued from the cloud security operations center; (4) Security event logs and data to be reported generated during system operation.
[0049] This module provides a role-based access control mechanism to ensure that each functional module can only access the stored data within its authorized scope, preventing data leakage and tampering.
[0050] The security protection main control module is connected to the multi-dimensional information acquisition module, threat analysis and decision-making module, proactive response execution module, resource perception and scheduling module, trusted secure communication module, and trusted secure storage module, respectively, for coordination and management among the modules.
[0051] A vehicle-mounted terminal information security protection system further includes: The cloud-based collaborative management module connects to the cloud-based security operations center via a trusted and secure communication module, and is used for security data reporting and policy synchronization.
[0052] The security policy management module connects to the threat analysis and decision-making module and is used to receive and update the static rule base from the cloud security center.
[0053] The following section uses a specific operational scenario to explain in detail the workflow and inter-module interaction process of this system in a real-world in-vehicle environment.
[0054] Assume a smart connected vehicle is traveling at a high speed of 120 km / h, and the onboard terminal system resources are under moderate load (CPU utilization approximately 60%, memory usage 70%, power consumption within normal range). At this time, if... Figure 4 As shown, the system works collaboratively according to the following steps: Step 1: System initialization and basic data acquisition.
[0055] The security protection main control module completes system initialization, coordinating and activating the multi-dimensional information acquisition module, threat analysis and decision-making module, proactive response execution module, resource perception and scheduling module, trusted secure communication module, and trusted secure storage module, putting each module into a ready state. Specifically, the trusted secure storage module completes key loading, storage partition initialization, and access control policy loading, providing encrypted storage ready state for each module. Subsequently, the resource perception and scheduling module, as the scheduling core, begins operation: the scene perception unit directly obtains basic status signals for rapid initial judgment by accessing the vehicle system's underlying interface. In this embodiment, it obtains: real-time vehicle speed signal of 120km / h, network connection status of normal 5G connection, power mode of driving mode, and user driving mode of standard mode. Based on this information, it initially determines that the current situation is a "high-speed driving scenario."
[0056] The resource monitoring unit monitors system resources in real time through the operating system kernel interface, obtaining data showing that the utilization rate of the vehicle terminal's central processing unit is 62%, the memory usage rate is 72%, and the system power consumption is 45W. Furthermore, the system's preset power consumption threshold is 50W.
[0057] Step 2: Resource scheduling instruction generation and dynamic data acquisition.
[0058] The strategy scheduling unit receives input from the scene perception unit and the resource monitoring unit. Based on the built-in scheduling logic, and considering both the "high-speed driving scenario" and the "normal resource status," it generates and issues the following resource scheduling instructions: (1) Send the following resource scheduling instruction to the threat analysis and decision module: enable the behavior analysis engine for vehicle control bus data.
[0059] (2) Send an instruction to the multidimensional information acquisition module: maintain the current data acquisition frequency, but increase the acquisition priority of vehicle control bus data.
[0060] (3) Pre-authorize the active response execution module: execute an immediate blocking response for medium- to high-level threats affecting the power system.
[0061] After receiving the resource scheduling instruction, the multi-dimensional information acquisition module dynamically sets the acquisition frequency and priority of each data point according to the instruction content: Vehicle control bus data is acquired at a high frequency (100ms / time). This embodiment uses the currently mainstream CAN FD bus as a typical representative of vehicle control buses for illustration.
[0062] The vehicle Ethernet communication data is acquired at a medium frequency (500ms / time).
[0063] The on-board diagnostic interface data and GPS data are collected at a low frequency (1 second / time).
[0064] The collected data is sent to the threat analysis and decision-making module in real time via the internal bus, and a copy is simultaneously cached in the scenario awareness unit of the resource awareness and scheduling module for more refined scenario judgment. Meanwhile, the collected data copy is coordinated by the security protection main control module and written in real time to the event cache partition of the trusted secure storage module for encrypted temporary storage, for use in post-event auditing or to supplement reports in case of network outages.
[0065] Step 3: Data analysis, monitoring, and dynamic scheduling.
[0066] The resource awareness and scheduling module enters a continuous working cycle. The scene awareness unit can now combine richer real-time data from the multi-dimensional information acquisition module (such as the specific message content of CAN FD bus data) to verify and refine the scene (e.g., confirming that the vehicle is in cruise mode rather than temporarily accelerating). The resource monitoring unit continuously monitors the system resource status.
[0067] The threat analysis and decision-making module receives data collected in real time from the multi-dimensional information acquisition module and calls its built-in multiple analysis engines to perform fusion analysis on the data: The rule matching engine runs continuously, performing fast feature matching (such as known attack signatures, malicious code features, etc.) on all input data based on a static rule base.
[0068] The behavior analysis engine is activated according to the resource scheduling instruction in step two. Specifically targeting CAN FD bus data, it calls a pre-trained machine learning model (using a Long Short-Term Memory network in this embodiment) to perform abnormal behavior detection, including real-time sequence analysis and anomaly scoring. This model has learned control command sequence patterns under normal driving conditions.
[0069] When the model calculates an anomaly score for the current data that exceeds a preset safety threshold (e.g., 0.85) (for example, identifying a sequence that deviates significantly from the learning pattern, such as "intensive torque requests during high-speed cruising,"), it is determined to be a high-level threat. The threat analysis and decision-making module integrates the results from both engines to generate a protection instruction: "Suspected power system attack detected. It is recommended to immediately block related messages and issue an alert."
[0070] Step 4: The proactive response execution module executes scenario-based responses.
[0071] The proactive response execution module receives protection instructions from the threat analysis and decision-making module and checks the response policies currently authorized by the policy scheduling unit: in this high-speed driving scenario, the response policy is immediate blocking. Then, the proactive response execution module immediately sends an instruction to the vehicle gateway to block the forwarding of the abnormal CAN FD message, preventing attack instructions from penetrating the vehicle control unit. Simultaneously, the proactive response execution module issues visual and audible warnings to the driver through the in-vehicle human-machine interface, displaying the message: "Abnormal control request detected, automatic protection in place."
[0072] Furthermore, the security incident was fully logged locally, encrypted and stored in the event log partition of the trusted secure storage module, employing append-only write and integrity verification mechanisms. It was also uploaded in real-time to the cloud security operations center via the trusted secure communication module for subsequent auditing and policy optimization. If the network is temporarily unavailable, the event log will be encrypted and cached in the trusted secure storage module, and automatically re-uploaded once the network is restored.
[0073] Step 5: Adaptive resource scheduling and cloud collaboration.
[0074] If the resource monitoring unit detects that the system power consumption has risen to 48W (close to the system's preset power consumption threshold of 50W), the policy scheduling unit will dynamically issue new instructions, such as "reduce the workload of the behavior analysis engine to 70%", thereby reducing the workload of the behavior analysis engine by reducing computational complexity, and thus ensuring that the system does not affect the vehicle control function due to overload of safety tasks.
[0075] The cloud-based collaborative management module, through the trusted and secure communication module, periodically uploads local logs, threat events, and system status to the cloud-based security operations center for backend analysis and tracing. Simultaneously, it receives updated policies (such as newly added attack signature rules) from the cloud-based security operations center.
[0076] The policy cache partition of the trusted and secure storage module receives and encrypts the static rule base update packages sent from the cloud. The security policy management module reads the decrypted update content from this partition and synchronizes it to the rule matching engine to ensure that local detection capabilities are continuously enhanced.
[0077] The security policy management module receives updates to the static rule base from the cloud-based security operations center and synchronizes them to the rule matching engine to ensure continuous enhancement of local detection capabilities.
[0078] Meanwhile, the resource awareness and scheduling module monitors the storage utilization and read / write load of the trusted security storage module. When the storage utilization exceeds a preset threshold (e.g., 80%), the policy scheduling unit issues a storage optimization command to the trusted security storage module, triggering automatic cleanup of expired cached data or compression of historical logs to ensure the sustainable use of storage resources.
[0079] Step Six: The security protection main control module coordinates the entire process.
[0080] The security protection master control module is responsible for communication synchronization, status monitoring, and anomaly handling among the modules. For example, if the trusted security communication module reports a network outage, the security protection master control module will notify all modules to switch to offline working mode and adjust resource scheduling strategies to prioritize local analysis capabilities. In this scenario, the security protection master control module will instruct the trusted security storage module to enter a high-priority caching mode, expand the cache space for event logs, and delay the storage operations of non-critical data to ensure that critical security events are not lost during network outages.
[0081] Therefore, the present invention adopts the above-mentioned vehicle terminal information security protection system, which overcomes the problem of insufficient adaptability of the existing technology under dynamic resources and complex scenarios. It can monitor the computing resources, power consumption status and vehicle operation scenarios of the vehicle terminal in real time, and always prioritize the security of the vehicle's core control functions under resource-constrained conditions. It maximizes the security protection effectiveness and optimizes resource utilization, thereby improving the overall security and operational reliability of intelligent connected vehicles in the face of complex network attacks.
[0082] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A vehicle-mounted terminal information security protection system, characterized in that, include: A multi-dimensional information acquisition module is used for real-time data collection; The threat analysis and decision-making module, connected to the multi-dimensional information acquisition module, is used to fuse and analyze data and generate protection commands. The proactive response execution module, connected to the threat analysis and decision-making module, is used to execute protection commands; The resource awareness and scheduling module, connected to the threat analysis and decision-making module and the multi-dimensional information acquisition module, is used to monitor resources and scenarios in real time and dynamically schedule the working strategies of the threat analysis and decision-making module and the multi-dimensional information acquisition module. A trusted and secure communication module is used to provide secure communication channels both within and outside the system. A trusted and secure storage module is used for encrypted storage of system data; The security protection main control module is connected to the multi-dimensional information acquisition module, threat analysis and decision-making module, proactive response execution module, resource perception and scheduling module, trusted secure communication module, and trusted secure storage module, respectively, for coordination and management among the modules.
2. The vehicle-mounted terminal information security protection system according to claim 1, characterized in that, The multi-dimensional information acquisition module collects data in real time, including vehicle control bus data, as well as at least one other data source from vehicle Ethernet, vehicle diagnostic interface, GPS, or vehicle camera.
3. The vehicle-mounted terminal information security protection system according to claim 1, characterized in that, The resource awareness and scheduling module includes: The scene perception unit is used to determine the current safety protection scene based on vehicle speed, network connection status, power mode and user driving mode information; the safety protection scene includes at least the parking standby scene, urban driving scene, highway driving scene and congestion scene; The resource monitoring unit is used to monitor the utilization rate, memory usage rate and system power consumption of the vehicle terminal's central processing unit in real time. The strategy scheduling unit, connected to the scenario awareness unit and the resource monitoring unit, is used to generate and issue resource scheduling instructions to the threat analysis and decision-making module based on the security protection scenario and real-time resource status.
4. The vehicle-mounted terminal information security protection system according to claim 3, characterized in that, The threat analysis and decision-making module has at least two built-in analysis engines with different computational complexities; the policy scheduling unit controls the threat analysis and decision-making module to switch between the currently active analysis engines through resource scheduling instructions.
5. The vehicle-mounted terminal information security protection system according to claim 4, characterized in that, At least two analytics engines are included: A rule matching engine for fast matching based on a static rule base; A behavior analysis engine for detecting abnormal behavior based on machine learning models.
6. The vehicle-mounted terminal information security protection system according to claim 3, characterized in that, The policy scheduling unit is configured to execute the following scheduling logic: When the scene perception unit determines that the vehicle is in a parking standby scene and the resource monitoring unit shows that resources are scarce, the scheduling threat analysis and decision-making module runs the rule matching engine and reduces the data collection frequency of the multi-dimensional information collection module. When the scene perception unit determines that the vehicle is in a high-speed driving scene, the scheduling threat analysis and decision-making module activates the behavior analysis engine for the vehicle control bus data. When the resource monitoring unit detects that the system power consumption exceeds a predetermined threshold, it dynamically reduces the workload of the behavior analysis engine.
7. The vehicle-mounted terminal information security protection system according to claim 3, characterized in that, The policy scheduling unit is also configured to: authorize the corresponding response policy to the proactive response execution module based on the security protection scenario. The response policy includes: In urban driving or congested scenarios, for medium- to high-level threats affecting the vehicle's powertrain, a gradual response is authorized; In high-speed driving scenarios, for threats of the same level that affect the vehicle's power system, an immediate blocking response is authorized.
8. The vehicle-mounted terminal information security protection system according to claim 1, characterized in that, Also includes: The cloud-based collaborative management module connects to the cloud-based security operations center via a trusted and secure communication module, and is used for security data reporting and policy synchronization. The security policy management module connects to the threat analysis and decision-making module and is used to receive and update the static rule base from the cloud security center.
9. The vehicle-mounted terminal information security protection system according to claim 5, characterized in that, The static rule base contains at least one of the following: known malicious code characteristics, network attack signatures, or abnormal message patterns.