A scene self-sensing vehicle-mounted cross-domain gateway dynamic security policy generation system
Patent Information
- Application Number
- CN202611048722.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-15
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2046-07-15
AI Technical Summary
[0004]为了解决不同时刻下的感知数据的优劣不同,若采用静态策略与固定的融合权重,则会缺乏对车辆实际运行状态和复杂场景的动态感知能力,造成策略生成不准确,容易造成误判的技术问题,本发明的目的在于提供一种场景自感知的车载跨域网关动态安全策略生成系统,所采用的技术方案具体如下:
首先分别获取当前时段及历史时段内每个时刻下的多源感知数据、场景威胁指示值、总线负载率以及告警数据。在跨域路由过程中,攻击者常会向车内注入合法但违背物理规律的伪造控制指令,所以通过提取每种感知数据对应的密码学验证强度与物理合理性得分,并结合数据分布特征构建时刻级特征向量,能够从密码学安全性与物理逻辑合理性两个独立维度对感知数据进行量化评估。在获取每种感知数据在每个时刻下的特征向量后,若采用静态权重相加,将无法应对动态演变的跨域攻击场景,同时,由于车载跨域网关作为连接异构网络的枢纽,其面临的攻击绝非孤立的单点异常,所以通过在历史时段内分析告警数据的数量特征与安全域跳变特征,并结合总线负载率计算攻击威胁指标,能够有效捕捉攻击行为在时间上的聚集性与跨安全域蔓延的跳变特征,进而利用攻击威胁指标对当前时段内每个时刻下所有感知数据的特征向量进行融合分析,得到每个时刻的动态可信度,便于自动降低可疑数据的影响。进一步地,通过基于与攻击威胁指标正相关的门限在当前时段中筛选高可信时刻,防止被污染的感知数据干扰策略生成。最后通过利用高可信时刻的动态可信度对各种感知数据的场景威胁指示值进行融合分析,得到融合威胁状态值,能够更准确地反映当前场景的真实风险水平。通过基于融合威胁状态值生成安全策略,使安全策略的强度与当前场景的实际风险精准匹配。
Smart Images

Figure CN122554246B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle safety technology, specifically to a scene-aware dynamic security policy generation system for in-vehicle cross-domain gateways. Background Technology
[0002] As automotive electronic and electrical architecture evolves from distributed to domain-centralized and cross-domain convergence, the in-vehicle cross-domain gateway, as a core hub connecting different security domains (such as powertrain domain, chassis domain, cockpit domain, and intelligent driving domain), undertakes key functions such as message routing, protocol conversion, and security isolation. The security policy of the cross-domain gateway directly determines the granularity of access control and the strength of message authentication between various domains within the vehicle, and is closely related to the network security of the entire vehicle.
[0003] Existing technologies generally adopt a mode of directly fusing multi-source perception data with static policy matching and fixed weight fusion when generating security policies. However, in actual vehicle network scenarios, the vehicle's operating status changes and the environment changes accordingly. Therefore, the quality of perception data varies at different times. If a static policy and fixed fusion weight are used, there will be a lack of dynamic perception capabilities for the actual operating status of the vehicle and complex scenarios, resulting in inaccurate policy generation and easy misjudgment. Summary of the Invention
[0004] To address the issue of varying quality in perception data at different times, using static strategies and fixed fusion weights lacks the dynamic perception capability to understand the actual operating state of the vehicle and complex scenarios. This leads to inaccurate strategy generation and a high risk of misjudgment. The present invention aims to provide a scene-aware dynamic security policy generation system for in-vehicle cross-domain gateways. The specific technical solution adopted is as follows: This invention proposes a scene-aware dynamic security policy generation system for vehicle-mounted cross-domain gateways, the system comprising: The data acquisition module is used to acquire multi-source sensing data and their corresponding scene threat indication values at each moment in the current time period and historical time periods; and to acquire bus load rate and alarm data at each moment. The feature extraction and analysis module is used to extract the cryptographic verification strength and physical rationality score corresponding to each type of sensing data, and construct the feature vector of each type of sensing data at each time point by combining the data distribution characteristics of the sensing data; within the historical period, it analyzes the quantitative characteristics of alarm data and the jump characteristics of the security domain to which the alarm data belongs, and calculates the attack threat index by combining the bus load rate; using the attack threat index, it performs a fusion analysis on the feature vectors of all sensing data at each time point in the current period to obtain the dynamic credibility at each time point; An adaptive policy generation module is used to filter high-confidence moments in the current time period based on dynamic credibility and a threshold positively correlated with the attack threat index; to perform fusion analysis on the scene threat indication values of various perception data using the dynamic credibility of the high-confidence moments to obtain a fused threat status value; and to generate a security policy based on the fused threat status value.
[0005] Furthermore, the method for obtaining the feature vector includes: The perception data includes at least in-vehicle bus messages, environmental perception data, V2X messages, and cloud-based threat intelligence. During the current time period, at each moment, the verification result of the hash value of each type of perceived data is analyzed by the hardware security module. If the verification is successful, the cryptographic verification strength is set to 1; otherwise, it is set to 0. At each time point, the scene threat indication value corresponding to each type of sensing data is compared with the corresponding preset threat threshold to determine the physical rationality score of each type of sensing data; Based on the data distribution characteristics of the perceived data, determine the data consistency score at each moment within the current time period; Within the current time period, at each time point, a feature vector is formed by combining the cryptographic verification strength, physical rationality score, and data consistency score of each type of perceived data.
[0006] Furthermore, the method for obtaining the data consistency score includes: The absolute value of the difference between the scene threat indication values of each pair of different types of perception data at each moment in the current time period is used as the distance factor, and the reciprocal of the mean of the distance factors between each type of perception data and all other types of perception data is used as the weight of that type of perception data. By utilizing the weights of various sensing data, a weighted average of the scene threat indication values of all sensing data at each time moment is calculated to obtain the mean center point. Within the current time period, at each time point, the absolute value of the difference between the scene threat indication value and the mean center point of each type of perception data is calculated as a distance parameter, and the value of the distance parameter after negative correlation mapping is used as the data consistency score of that type of perception data.
[0007] Furthermore, the method for obtaining the attack threat indicator includes: Within a historical period, a dynamic attenuation coefficient is constructed based on the bus load rate at each historical moment, wherein the bus load rate is negatively correlated with the dynamic attenuation coefficient; Within a historical period, the time interval between each historical moment and the first moment in the current period is calculated as the time factor corresponding to each historical moment. The number of alarm data between each historical moment and the first moment in the current period is used as the quantity factor. The ratio of the quantity factor to the time factor corresponding to each historical moment is used as the alarm density. The dynamic attenuation coefficient of each historical moment is multiplied by the alarm density to obtain the alarm burst factor of each historical moment. The average of the alarm burst factors corresponding to all historical moments is used as the alarm burst density index. The cross-domain collaborative mutation index is calculated by checking whether the security domains of the destination addresses of alarm data at two adjacent moments within the historical period are the same. If they are the same, no jump has occurred; if they are different, a jump has occurred. The ratio of the sum of the jump counts at all adjacent moments to the total number of alarm data is used as the cross-domain collaborative mutation index. When the total number of alarm data is 0, the cross-domain collaborative mutation index is set to 0. The value obtained by multiplying the alarm burst density index, the cross-domain collaborative mutation index, and the time empirical constant, and then normalizing the result, is used as the attack threat index.
[0008] Furthermore, the method for obtaining the dynamic credibility includes: Dynamic fusion weights for cryptographic verification strength, physical plausibility score, and data consistency score are determined based on attack threat indicators; Within the current time period, at each time point, the dynamic fusion weights corresponding to each data value in the feature vector are used to perform a weighted summation of multiple data values in the feature vector corresponding to each type of perceived data at each time point. The summation result is then divided by the sum of all the dynamic fusion weights to calculate the dynamic credibility factor of each type of perceived data at each time point. The mean of the dynamic credibility factors of all types of perceived data at each time point is taken as the dynamic credibility of each time point.
[0009] Furthermore, the method for obtaining the dynamic fusion weights includes: Calculate the difference between constant 1 and the attack threat index, multiply the difference by the preset base weight of the cryptographic verification strength to obtain the dynamic fusion weight of the cryptographic verification strength, multiply the attack threat index by the preset base weight of the physical rationality score to obtain the dynamic fusion weight of the physical rationality score, and use the preset base weight of the data consistency score as the dynamic fusion weight.
[0010] Furthermore, the method for obtaining the high-confidence moment includes: Preset the initial value of the basic safety threshold and the threshold adjustment coefficient; Multiply the threshold adjustment coefficient by the attack threat index, and add the product to the initial value of the basic security threshold to obtain the dynamic trustworthiness threshold; The dynamic credibility of each moment within the current time period is compared with the dynamic credibility threshold. If the dynamic credibility is greater than or equal to the dynamic credibility threshold, the moment is retained as a high-credibility moment; if the dynamic credibility is less than the dynamic credibility threshold, it is discarded.
[0011] Furthermore, the method for obtaining the fused threat status value includes: For any high-confidence moment, the dynamic confidence level of that high-confidence moment is weighted and summed with the scene threat indication value corresponding to each type of perception data at that high-confidence moment. The normalized value of the weighted sum is then used as the fusion threat state factor. The average of the fusion threat state factors at all high-confidence moments is taken as the fusion threat state value.
[0012] Furthermore, the generated security policy includes: If the fusion threat status value is less than the preset policy strength threshold, a first security policy is generated. The first security policy includes maintaining normal routing and silent log recording and strengthening monitoring. If the fusion threat status value is greater than or equal to the preset policy strength threshold, a second security policy is generated. The second security policy includes access control isolation and full-frame message authentication code verification.
[0013] Furthermore, the preset strategy strength threshold ranges from [0.7, 1].
[0014] The present invention has the following beneficial effects: First, multi-source sensing data, scene threat indication values, bus load rates, and alarm data are acquired for each moment in the current and historical time periods. During cross-domain routing, attackers often inject legitimate but physically unsound forged control commands into the vehicle. Therefore, by extracting the cryptographic verification strength and physical plausibility scores corresponding to each type of sensing data, and constructing time-level feature vectors based on data distribution characteristics, the sensing data can be quantitatively evaluated from two independent dimensions: cryptographic security and physical logical plausibility. After acquiring the feature vectors of each type of sensing data at each moment, static weighting is insufficient to handle dynamically evolving cross-domain attack scenarios. Furthermore, since the vehicle-mounted cross-domain gateway acts as a hub connecting heterogeneous networks, the attacks it faces are never isolated single-point anomalies. Therefore, by analyzing the quantitative characteristics and security domain transition characteristics of alarm data in historical time periods, and combining this with bus load rates to calculate attack threat indicators, the temporal clustering and cross-security domain propagation transition characteristics of attack behavior can be effectively captured. Then, the attack threat indicators are used to fuse and analyze the feature vectors of all sensing data at each moment in the current time period to obtain the dynamic credibility of each moment, facilitating the automatic reduction of the impact of suspicious data. Furthermore, by filtering high-confidence moments within the current time period based on a threshold positively correlated with attack threat indicators, contaminated perception data is prevented from interfering with policy generation. Finally, by fusing and analyzing the scenario threat indication values of various perception data using the dynamic credibility of high-confidence moments, a fused threat state value is obtained, which more accurately reflects the true risk level of the current scenario. By generating security policies based on the fused threat state value, the strength of the security policies is precisely matched to the actual risks of the current scenario. Attached Figure Description
[0015] Figure 1 This is a system block diagram of a scene-aware vehicle cross-domain gateway dynamic security policy generation system provided in one embodiment of the present invention. Detailed Implementation
[0016] The following description, in conjunction with the accompanying drawings, details the specific solution of the scene-aware vehicle cross-domain gateway dynamic security policy generation system provided by the present invention.
[0017] Please see Figure 1 The diagram illustrates a system block diagram of a scene-aware vehicle cross-domain gateway dynamic security policy generation system according to an embodiment of the present invention. The system includes: a data acquisition module 101, a feature extraction and analysis module 102, and an adaptive policy generation module 103.
[0018] The data acquisition module 101 is used to acquire multi-source perception data and their corresponding scene threat indication values at each moment in the current time period and historical time periods; and to acquire bus load rate and alarm data at each moment.
[0019] At any given moment, the system collects CAN bus messages from the vehicle via the OBD interface and built-in CAN transceiver. These messages include message identifiers, data length codes, and timestamps. It also collects distance and image data of obstacles ahead using the vehicle's millimeter-wave radar and vision sensors as environmental perception data. Furthermore, it receives V2X messages broadcast by roadside units via the C-V2X communication module and periodically retrieves threat intelligence from the cloud via the vehicle's T-BOX. The collected data is then time-aligned by adding monotonically increasing timestamps, for example, using the sampling period of the in-vehicle CAN messages as the baseline time resolution for time division, and unified to the vehicle's coordinate system using a coordinate transformation matrix. The rear axle center coordinate system is spatially aligned to generate standardized multi-source perception data. To facilitate subsequent calculations using this multi-source perception data, each type of perception data is numerically quantized. Specifically, the multi-source perception data is decoded to extract physical observation parameters reflecting the vehicle's operational safety status. These physical observation parameters include external environmental parameters and internal control parameters. External environmental parameters include the relative distance to obstacles ahead and collision warning time obtained from millimeter-wave radar, visual sensors, or V2X message parsing. Internal control parameters include the requested deceleration and steering angle obtained from in-vehicle CAN bus message parsing. Next, based on the type of physical observation parameters, a corresponding preset feature mapping function is used to eliminate dimensional differences between the various physical observation parameters, uniformly mapping them to the [0,1] interval to obtain the scene threat indication value corresponding to each perception data. The larger the scene threat indication value, the higher the level of danger indicated by the data source. For perception data that is negatively correlated with the degree of driving danger, such as the relative distance to obstacles ahead and the collision warning time, an inverse proportional mapping function or a decreasing exponential function is used for conversion. The smaller the measured value, the closer the obtained scene threat indication value is to 1. For internal control mutation parameters that are positively correlated with the risk of vehicle loss of control, such as requested deceleration and steering angle, the absolute value of the difference between the parameter and the current vehicle stable operating state benchmark value is calculated, and a positive correlation normalization function is used for conversion. The larger the absolute value of the difference, the closer the obtained scene threat indication value is to 1.
[0020] Simultaneously, the bus load rate at various times was also obtained: at each time point, the ratio of the actual number of bits transmitted in the in-vehicle CAN bus message to the theoretical maximum number of bits transmitted on the bus was calculated and normalized to 0~1, which was used as the bus load rate at each time point. Alarm data at various times was also obtained: alarm data at various times was collected using a lightweight intrusion detection probe deployed inside the in-vehicle cross-domain gateway. The alarm data includes the discrete timestamp of the alarm event trigger and the security domain identifier to which the destination address of the alarm event belongs. In this embodiment of the invention, the security domain includes the power domain, chassis domain, cockpit domain, and intelligent driving domain.
[0021] It should be noted that, in this embodiment of the present invention, the time period for acquiring data is divided into the current time period and the historical time period. The current time period is set as a time period that traces back 100ms from the current time to the past, and the historical time period can be set as a time period of 500ms that is adjacent to but does not overlap with the current time period.
[0022] The feature extraction and analysis module 102 is used to extract the cryptographic verification strength and physical rationality score corresponding to each type of sensing data, and construct the feature vector of each type of sensing data at each time step by combining the data distribution characteristics of the sensing data; within the historical period, it analyzes the quantitative characteristics of alarm data and the jump characteristics of the security domain to which the alarm data belongs, and calculates the attack threat index by combining the bus load rate; using the attack threat index, it performs a fusion analysis on the feature vectors of all sensing data at each time step in the current period to obtain the dynamic credibility at each time step.
[0023] Traditional vehicle gateway defenses rely heavily on cryptography (such as certificates or MAC codes). However, once vulnerabilities or key leaks occur (such as the OBD interface being cracked), attackers can inject legitimate but physically unreliable forged commands into the vehicle. The physical and dynamic limits of a vehicle (such as the maximum deceleration determined by the maximum tire grip) are extremely difficult for attackers to perfectly forge. Therefore, in this embodiment of the invention, the cryptographic verification strength and physical plausibility score corresponding to each type of sensing data can be extracted. At the same time, by combining the data distribution characteristics of the sensing data, a feature vector of each type of sensing data at each moment can be constructed to avoid misjudgment caused by interference from single-dimensional data.
[0024] Preferably, in one embodiment of the present invention, the method for obtaining the feature vector includes: The perception data includes at least in-vehicle bus messages, environmental perception data, V2X messages, and cloud-based threat intelligence.
[0025] Within the current time period, at each moment, the verification result of the hash value of each type of perceived data is analyzed by the hardware security module (HSM, a dedicated cryptographic hardware embedded within the cross-domain gateway). The HSM provides hardware-level isolation; the key does not leave the chip, and software attacks cannot forge the verification result. The signature is either valid or invalid. Therefore, if the verification passes, the cryptographic verification strength is directly set to 1; otherwise, it is set to 0. It should be noted that if certain types of perceived data do not have a hash signature, their cryptographic verification strength is assigned a neutral value of 0.5.
[0026] If the key is stolen through a vulnerability, a legitimate hash signature can be forged. However, the physical properties of the vehicle are objectively real. Therefore, at each moment, the scene threat indication value corresponding to each type of perception data is compared with the corresponding preset threat threshold to determine the physical rationality score of each type of perception data. Specifically, the difference between the preset threat threshold and the scene threat indication value for each type of perception data is calculated. If the difference is positive, it means that the actual scene threat indication value is less than the preset threat threshold and is within a reasonable range. The larger the value, the more secure it is. Conversely, if the difference is negative, it means that the actual scene threat indication value is greater than the preset threat threshold and exceeds a reasonable range. The smaller the value, the less secure it is. Therefore, the Sigmoid function is used to normalize this difference to obtain the physical rationality score. The larger the value, the higher the rationality.
[0027] It should be noted that the preset threat threshold value corresponding to each scenario threat indication value is between 0 and 1. The specific value can be adjusted according to the implementation scenario, and is not limited here.
[0028] Based on the data distribution characteristics of the sensing data, the data consistency score at each moment in the current period is determined: For multi-source observation data of the same scene element (such as the distance to the obstacle in front), due to the different attenuation mechanisms of heterogeneous sensors to environmental interference (such as the large number of discrete noise generated by the scattering of water droplets by lidar in heavy rain, while millimeter-wave radar is less affected), simple mean comparison cannot reveal the conflict nature inside the data distribution.
[0029] The absolute value of the difference between the scene threat indication values of each pair of different types of sensing data at each time point within the current time period is calculated as the distance factor. The reciprocal of the mean of the distance factors between each type of sensing data and all other types of sensing data is used as the weight of that type of sensing data. It should be noted that if there is a special case where the mean of the distance factor is 0, the weight calculation process is set to add the mean to a preset minimum positive number, and the reciprocal of the sum is used as the weight of that type of sensing data. The preset minimum positive number can be set to 0.001, and the specific value can be adjusted according to the implementation scenario, which is not limited here.
[0030] Then, using the weights of various sensing data, a weighted average of the scene threat indication values of all sensing data at each time step is calculated to obtain the mean center point, which can be used to provide a state reference benchmark. Next, within the current time period, at each time step, the absolute value of the difference between the scene threat indication value of each type of sensing data and the mean center point is calculated as a distance parameter. The larger the distance parameter, the greater the deviation from the reference benchmark. This distance parameter is then subjected to negative correlation mapping to correct the logical relationship, thereby obtaining the data consistency score for that type of sensing data. It should be noted that the negative correlation mapping here can use... ,in, Let x represent an exponential function with the natural constant e as the base, and let x represent the independent variable.
[0031] Finally, within the current time period, at each time point, the cryptographic verification strength, physical rationality score, and data consistency score of each type of perceived data are combined to form a feature vector. This feature vector contains the legitimacy of the digital space, the feasibility of the physical space, and the consensus of the group space, thus providing a more comprehensive and accurate data foundation for subsequent analysis.
[0032] Because alarms caused by occasional errors or normal retransmissions in the vehicle network are usually sparsely distributed over time, while real attacks typically cause a surge in alarms within a very short period, the quantitative characteristics of alarm data over historical time periods can be used as a factor in quantifying attack threat indicators. Furthermore, while alarm density may be high within a single security domain, it doesn't necessarily immediately jeopardize vehicle physical safety. Truly dangerous attacks, however, will inevitably cross the trust boundaries between subnets of different security levels (e.g., penetrating the chassis CAN network from the Bluetooth channel). When alarm streams alternate between different security domains, it indicates that attackers are conducting cross-domain probing or command injection. Such cross-domain transitions break physical isolation, and even a small number of transitions foreshadow a highly dangerous penetration intent. Therefore, the transition characteristics of the security domain to which the alarm data belongs are also included in the calculation. When the vehicle is under severe conditions such as rapid acceleration or emergency braking, the bus load rate will also surge, greatly increasing the probability of packet collisions and retransmissions, inevitably causing a short-term surge in IDS alarms. Therefore, the bus load rate is also considered in the calculation of attack threat indicators.
[0033] Preferably, in one embodiment of the present invention, the method for obtaining the attack threat index includes: High bus load rates under heavy load conditions can trigger a surge in normal packet collisions and discrete false alarms. Therefore, a dynamic attenuation coefficient is constructed based on the bus load rate at each historical moment within a historical period. The bus load rate is negatively correlated with the dynamic attenuation coefficient; a smaller coefficient indicates a higher load, a lower likelihood of attack, and thus a reduction in alarm sensitivity and threat level. In this embodiment of the invention, the following can be utilized: Achieve a negative correlation mapping with bus load rate, where x represents the independent variable. This represents an exponential function with the natural constant e as its base.
[0034] Attacks are characterized by high-frequency bursts within a short period of time. Therefore, within a historical time period, the time interval between each historical moment and the first moment in the current time period is calculated as the time factor corresponding to each historical moment. At the same time, the number of alarm data between each historical moment and the first moment in the current time period is used as the quantity factor. The ratio of the quantity factor to the time factor corresponding to each historical moment is used as the alarm density. The higher the alarm density, the more pronounced the burst of alarm data. The dynamic attenuation coefficient of each historical moment is multiplied by the alarm density to obtain the alarm burst factor of each historical moment. The average of the alarm burst factors corresponding to all historical moments is used as the alarm burst density index. Based on the above analysis, it can be seen that the higher the alarm burst density index, the more frequent the burst growth of alarm data is without high load, and therefore the more likely it is to be attacked, and the higher the attack threat index.
[0035] While a large number of alerts from a single domain are relatively manageable, cross-domain jumps usually indicate high-risk penetration. Therefore, we analyze whether the security domains of the destination addresses of alert data at two adjacent moments in a historical period are the same. If they are the same, no jump has occurred; if they are different, a jump has occurred. The ratio of the sum of the number of jumps at all adjacent moments to the total number of alert data is used as the cross-domain collaborative mutation index. The larger the cross-domain collaborative mutation index, the higher the probability of being attacked. When the total number of alert data is 0, the cross-domain collaborative mutation index is set to 0.
[0036] Finally, the alarm burst density index, cross-domain collaborative mutation index, and time empirical constant are multiplied and normalized to obtain the attack threat index. Based on the aforementioned logic, a higher attack threat index indicates a higher probability of being attacked and a lower level of security. The normalization here can be achieved using the formula... Where x represents the independent variable, This represents an exponential function with the natural constant e as its base. It should be noted that in this embodiment of the invention, the time empirical constant serves to eliminate the influence of the time dimension on the alarm burst density index; its specific value can be set to 1, with the unit being time units.
[0037] Fixed-weight fusion cannot cope with the security degradation caused by key leakage. When the attack threat index rises, it indicates that the system is under high-intensity attack. Attackers can easily use stolen keys to forge legitimate messages. At this time, the cryptographic verification defense fails. Therefore, attack threat index is introduced to guide multi-feature fusion, thereby determining the dynamic credibility of data at each time point.
[0038] Preferably, in one embodiment of the present invention, the method for obtaining dynamic credibility includes: Cryptographic defenses are easily breached under high-intensity attacks, so it is necessary to appropriately reduce the weight of cryptographic verification strength. Therefore, the difference between the constant 1 and the attack threat index is calculated, and the difference is multiplied by the preset basic weight of cryptographic verification strength to obtain the dynamic fusion weight of cryptographic verification strength. Since physical laws are extremely difficult to forge, the attack threat index is directly multiplied by the preset basic weight of physical rationality score to obtain the dynamic fusion weight of physical rationality score. The preset basic weight of data consistency score is used as the dynamic fusion weight.
[0039] Then, within the current time period, at each time point, the dynamic fusion weights corresponding to each data value in the feature vector are used to perform a weighted summation of multiple data values in the feature vector corresponding to each type of perceived data at each time point. The summation result is then divided by the sum of all dynamic fusion weights to calculate the dynamic credibility factor of each type of perceived data at each time point. At this time, the dynamic credibility factor can automatically reduce the dependence on easily deceived cryptographic features under high attack conditions, and strengthen the examination of physical laws and group consistency. The larger the value, the less the perceived data is affected by environmental factors at that time point, and the higher the credibility. Finally, the mean of the dynamic credibility factors of all types of perceived data at each time point is taken as the dynamic credibility of each time point.
[0040] It should be noted that, in this embodiment of the present invention, the basic weights of both cryptographic verification strength and physical rationality scores are set to 0.4, indicating that they are of equal status as the main lines of defense, and the basic weight of data consistency score is set to 0.2, which serves as an auxiliary reference for multi-source consensus.
[0041] The adaptive policy generation module 103 is used to filter high-confidence moments in the current time period based on dynamic credibility and a threshold positively correlated with attack threat indicators; to perform fusion analysis on the scene threat indication values of various perception data using the dynamic credibility of high-confidence moments to obtain a fused threat status value; and to generate a security policy based on the fused threat status value.
[0042] Fixed filtering thresholds can easily lead to the accidental deletion of real jitter data under normal operating conditions, while preserving disguised data under high-risk attacks. However, based on the aforementioned module, the dynamic credibility corresponding to each moment within the current time period can be obtained. Therefore, in this module, high credibility moments can be filtered out within the current time period based on this indicator and a threshold that is positively correlated with the attack threat indicator, thus preserving the real data that has not been contaminated.
[0043] Preferably, in one embodiment of the present invention, the method for obtaining the high-confidence moment includes: First, preset the initial value of the basic safety threshold and the threshold adjustment coefficient.
[0044] The more intense the attack, the stricter the data screening criteria should be. Therefore, the threshold adjustment coefficient is multiplied by the attack threat index, and the resulting product is added to the initial value of the basic security threshold to obtain the dynamic credibility threshold, thereby increasing the strictness of the screening criteria under high-risk conditions.
[0045] Then, the dynamic credibility of each moment within the current time period is compared with the dynamic credibility threshold. If the dynamic credibility is greater than or equal to the dynamic credibility threshold, the moment is retained as a high-credibility moment; if the dynamic credibility is less than the dynamic credibility threshold, it is removed.
[0046] It should be noted that the initial value of the preset basic safety threshold can be set to 0.4, and the threshold adjustment coefficient can be set to 0.5. The specific values can be adjusted according to the implementation scenario, and no limitation is made here.
[0047] Even after the aforementioned dynamic threshold filtering and retention of high-confidence moments, the reliability of the data at different moments still varies. Therefore, the dynamic credibility of high-confidence moments is used to fuse the scene threat indication values of various perception data to obtain a fused threat status value, which is used to characterize the risk situation in the current period.
[0048] Preferably, in one embodiment of the present invention, the method for obtaining the fused threat status value includes: For any given high-confidence moment, the dynamic confidence level of that high-confidence moment is weighted and summed with the scene threat indication value corresponding to each type of perception data at that high-confidence moment. The normalized value of the weighted sum is then used as the fused threat state factor. This fused threat state value, after dynamic weighting, can more accurately represent the true comprehensive threat level faced by the vehicular network in the current time period. The average of the fused threat state factors from all high-confidence moments is used as the fused threat state value.
[0049] It should be noted that the normalization here can be achieved using maximum and minimum value normalization, where the maximum and minimum values can be obtained using all high-confidence time points as the database.
[0050] Once the convergence threat status value for the current time period is obtained, a security strategy can be determined based on this indicator.
[0051] Preferably, in one embodiment of the present invention, determining a security strategy includes: If the merged threat status value is less than the preset policy strength threshold, it indicates a low threat state. At this time, only basic vigilance and log retention are required. Therefore, the first security policy is generated, which includes maintaining regular routing and silent log recording while strengthening monitoring.
[0052] If the fusion threat status value is greater than or equal to the preset policy strength threshold, it indicates that there is an extremely high security risk. Therefore, it is necessary to ensure the security bottom line and to implement strict full-frame message authentication verification. Thus, a second security policy is generated, which includes access control isolation and full-frame message authentication code verification.
[0053] It should be noted that in this embodiment of the present invention, the value range of the preset strategy strength threshold is set to [0.7, 1), and specifically it can be 0.8.
[0054] In summary, we first acquire multi-source sensing data, scene threat indicators, bus load rates, and alarm data for each moment in the current and historical time periods. During cross-domain routing, attackers often inject legitimate but physically unsound forged control commands into the vehicle. Therefore, by extracting the cryptographic verification strength and physical plausibility scores corresponding to each type of sensing data, and constructing time-level feature vectors based on data distribution characteristics, we can quantitatively evaluate the sensing data from two independent dimensions: cryptographic security and physical logical plausibility. After acquiring the feature vectors of each type of sensing data at each moment, static weighting is insufficient to handle dynamically evolving cross-domain attack scenarios. Furthermore, since the vehicle-mounted cross-domain gateway acts as a hub connecting heterogeneous networks, the attacks it faces are never isolated single-point anomalies. Therefore, by analyzing the quantitative characteristics and security domain transition characteristics of alarm data in historical time periods, and combining this with bus load rates to calculate attack threat indicators, we can effectively capture the temporal clustering and cross-security domain propagation transition characteristics of attack behavior. Then, by using the attack threat indicators to fuse and analyze the feature vectors of all sensing data at each moment in the current time period, we can obtain the dynamic credibility of each moment, facilitating the automatic reduction of the impact of suspicious data. Furthermore, by filtering high-confidence moments within the current time period based on a threshold positively correlated with attack threat indicators, contaminated perception data is prevented from interfering with policy generation. Finally, by fusing and analyzing the scenario threat indication values of various perception data using the dynamic credibility of high-confidence moments, a fused threat state value is obtained, which more accurately reflects the true risk level of the current scenario. By generating security policies based on the fused threat state value, the strength of the security policies is precisely matched to the actual risks of the current scenario.
[0055] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A scene-aware dynamic security policy generation system for vehicle-mounted cross-domain gateways, characterized in that, The system includes: The data acquisition module is used to acquire multi-source sensing data and their corresponding scene threat indication values at each moment in the current time period and historical time periods; and to acquire bus load rate and alarm data at each moment. The feature extraction and analysis module is used to extract the cryptographic verification strength and physical rationality score corresponding to each type of sensing data, and construct the feature vector of each type of sensing data at each time point by combining the data distribution characteristics of the sensing data; within the historical period, it analyzes the quantitative characteristics of alarm data and the jump characteristics of the security domain to which the alarm data belongs, and calculates the attack threat index by combining the bus load rate; using the attack threat index, it performs a fusion analysis on the feature vectors of all sensing data at each time point in the current period to obtain the dynamic credibility at each time point; An adaptive policy generation module is used to filter high-confidence moments in the current time period based on dynamic credibility and a threshold positively correlated with the attack threat index; to perform fusion analysis on the scene threat indication values of various perception data using the dynamic credibility of the high-confidence moments to obtain a fused threat status value; and to generate a security policy based on the fused threat status value.
2. The scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 1, characterized in that, The method for obtaining the feature vector includes: The perception data includes at least in-vehicle bus messages, environmental perception data, V2X messages, and cloud-based threat intelligence. During the current time period, at each moment, the verification result of the hash value of each type of perceived data is analyzed by the hardware security module. If the verification is successful, the cryptographic verification strength is set to 1; otherwise, it is set to 0. At each time point, the scene threat indication value corresponding to each type of sensing data is compared with the corresponding preset threat threshold to determine the physical rationality score of each type of sensing data; Based on the data distribution characteristics of the perceived data, determine the data consistency score at each moment within the current time period; Within the current time period, at each time point, a feature vector is formed by combining the cryptographic verification strength, physical rationality score, and data consistency score of each type of perceived data.
3. The scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 2, characterized in that, The methods for obtaining the data consistency score include: The absolute value of the difference between the scene threat indication values of each pair of different types of perception data at each moment in the current time period is used as the distance factor, and the reciprocal of the mean of the distance factors between each type of perception data and all other types of perception data is used as the weight of that type of perception data. By utilizing the weights of various sensing data, a weighted average of the scene threat indication values of all sensing data at each time moment is calculated to obtain the mean center point. Within the current time period, at each time point, the absolute value of the difference between the scene threat indication value and the mean center point of each type of perception data is calculated as a distance parameter, and the value of the distance parameter after negative correlation mapping is used as the data consistency score of that type of perception data.
4. The scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 1, characterized in that, The methods for obtaining the attack threat indicators include: Within a historical period, a dynamic attenuation coefficient is constructed based on the bus load rate at each historical moment, wherein the bus load rate is negatively correlated with the dynamic attenuation coefficient; Within a historical period, the time interval between each historical moment and the first moment in the current period is calculated as the time factor corresponding to each historical moment. The number of alarm data between each historical moment and the first moment in the current period is used as the quantity factor. The ratio of the quantity factor to the time factor corresponding to each historical moment is used as the alarm density. The dynamic attenuation coefficient of each historical moment is multiplied by the alarm density to obtain the alarm burst factor of each historical moment. The average of the alarm burst factors corresponding to all historical moments is used as the alarm burst density index. The cross-domain collaborative mutation index is calculated by checking whether the security domains of the destination addresses of alarm data at two adjacent moments within the historical period are the same. If they are the same, no jump has occurred; if they are different, a jump has occurred. The ratio of the sum of the jump counts at all adjacent moments to the total number of alarm data is used as the cross-domain collaborative mutation index. When the total number of alarm data is 0, the cross-domain collaborative mutation index is set to 0. The value obtained by multiplying the alarm burst density index, the cross-domain collaborative mutation index, and the time empirical constant, and then normalizing the result, is used as the attack threat index.
5. The scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 2, characterized in that, The method for obtaining the dynamic credibility includes: Dynamic fusion weights for cryptographic verification strength, physical plausibility score, and data consistency score are determined based on attack threat indicators; Within the current time period, at each time point, the dynamic fusion weights corresponding to each data value in the feature vector are used to perform a weighted summation of multiple data values in the feature vector corresponding to each type of perceived data at each time point. The summation result is then divided by the sum of all the dynamic fusion weights to calculate the dynamic credibility factor of each type of perceived data at each time point. The mean of the dynamic credibility factors of all types of perceived data at each time point is taken as the dynamic credibility of each time point.
6. The scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 5, characterized in that, The method for obtaining the dynamic fusion weights includes: Calculate the difference between constant 1 and the attack threat index, multiply the difference by the preset base weight of the cryptographic verification strength to obtain the dynamic fusion weight of the cryptographic verification strength, multiply the attack threat index by the preset base weight of the physical rationality score to obtain the dynamic fusion weight of the physical rationality score, and use the preset base weight of the data consistency score as the dynamic fusion weight.
7. The scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 1, characterized in that, The method for obtaining the high-confidence moment includes: Preset the initial value of the basic safety threshold and the threshold adjustment coefficient; Multiply the threshold adjustment coefficient by the attack threat index, and add the product to the initial value of the basic security threshold to obtain the dynamic trustworthiness threshold; The dynamic credibility of each moment within the current time period is compared with the dynamic credibility threshold. If the dynamic credibility is greater than or equal to the dynamic credibility threshold, the moment is retained as a high-credibility moment; if the dynamic credibility is less than the dynamic credibility threshold, it is discarded.
8. The scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 1, characterized in that, The method for obtaining the fusion threat status value includes: For any high-confidence moment, the dynamic confidence level of that high-confidence moment is weighted and summed with the scene threat indication value corresponding to each type of perception data at that high-confidence moment. The normalized value of the weighted sum is then used as the fusion threat state factor. The average of the fusion threat state factors at all high-confidence moments is taken as the fusion threat state value.
9. A scene-aware dynamic security policy generation system for vehicle cross-domain gateways according to claim 1, characterized in that, The generated security policy includes: If the fusion threat status value is less than the preset policy strength threshold, a first security policy is generated. The first security policy includes maintaining normal routing and silent log recording and strengthening monitoring. If the fusion threat status value is greater than or equal to the preset policy strength threshold, a second security policy is generated. The second security policy includes access control isolation and full-frame message authentication code verification.
10. A scene-aware, vehicle-mounted cross-domain gateway dynamic security policy generation system according to claim 9, characterized in that, The preset strategy strength threshold ranges from [0.7, 1].
Citation Information
Patent Citations
Internet of vehicles communication security situation assessment and decision optimization method based on reinforcement learning
CN122027353A
IP threat level judgment method and device based on large model semantic operator adaptive arrangement
CN122221264A