A method for determining the priority of a security event in vehicle network access

CN122824831APending Publication Date: 2026-09-25SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202611225922.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-13
Publication Date
2026-09-25

AI Technical Summary

Benefits of technology

1、在车载网络访问安全事件中,通过提取底层网络安全协议栈的通信握手状态标识并生成对应协议规范下的状态抑制信令,利用该信令诱导对端发送节点主动挂起重传定时器或降级发送窗口,从底层协议的因果链条上消除因本地资源强行剥夺而诱发的协议重传风暴,避免非预期重传报文对车载总线物理带宽的次生拥塞干扰,保障高安全等级事件在获得本地算力的同时具备确定的通信信道响应时延。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122824831A_ABST
    Figure CN122824831A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security protocols, and discloses a kind of priority response decision method of vehicle network access security event, comprising: obtaining security event message and identifying second security event;Parsing protocol header extracts vehicle identification, determines first security integrity level parameter;When determining that it is higher than second security event parameter, read handshake state identification and construct state inhibition signaling;The signaling is fed back to the opposite end sending node, indicates that the receiving window is 0, makes it suspend retransmission timer and enters the backoff state;Release second security event resource and distribute to pending message processing queue, the application eliminates retransmission storm through the state inhibition mechanism of underlying protocol stack, avoids the congestion interference of unexpected retransmission message to bus bandwidth, and guarantees that high security level event has determined communication response delay.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security protocol technology, and in particular relates to a priority response and decision method for vehicle network access security events. Background Technology

[0002] Currently, in-vehicle Ethernet and service-oriented architectures are widely used in intelligent connected vehicles. In-vehicle network security protocols, as the core of ensuring the authenticity and integrity of data interaction, play an important role in the overall vehicle security defense system. In-vehicle security processing platforms typically adopt resource management strategies based on the vehicle's security integrity level. Under conditions where system resources are limited, the processor prioritizes ensuring the computing resources and network bandwidth required for high-security-level related events. Relying on hardware computing power stacking or physical bandwidth expansion is insufficient to eliminate protocol-level race conditions in complex network environments. Software-level traffic scheduling strategies face deterministic challenges. For example, Chinese invention patent application CN121334081A discloses a data transmission method, device, equipment, and medium in an in-vehicle network. It establishes a time scheduling plan based on a preset transmission period in the user space and uses a gating mechanism to achieve deterministic data stream transmission.

[0003] However, the vehicle network protocol stack has obvious state dependencies. There is a causal relationship between the local computing power allocation action and the protocol state machine of the communication peer. When the system releases the processing resources occupied by low-priority events, the communication peer determines that there is packet loss in the current logical link because it has not received the protocol confirmation acknowledgment within the preset period. This situation will inevitably trigger the retransmission mechanism of the peer sending node. Unexpected retransmission messages quickly occupy the bus physical bandwidth. Even if the processor performance is improved or the bus bandwidth is expanded, the retransmission inducement at the protocol level has not been eliminated. Under extreme conditions, the system still cannot guarantee the real-time response of the core driving function safety link. This reverse constraint at the protocol layer caused by resource contention has become a common limitation to improving the defense effectiveness of the vehicle network.

[0004] Therefore, how to eliminate retransmission storms through the state suppression mechanism of the underlying protocol stack, thereby maintaining the time-deterministic nature of security event response in a complex resource preemption environment, has become the technical problem to be solved by this invention. Summary of the Invention

[0005] This invention provides a method for prioritizing responses to security events related to in-vehicle network access, comprising the following steps: Step 101: Obtain the security event data packet to be analyzed captured via the network interface, and identify the second security event currently being processed; Step 102: Parse the protocol header structure of the security event data message to be analyzed in order to extract the vehicle function identifier associated with the security event data message to be analyzed, and determine the first vehicle safety integrity level parameter corresponding to the security event data message to be analyzed according to the preset vehicle safety integrity level mapping table. Step 103: When it is determined that the first vehicle security integrity level parameter is higher than the second vehicle security integrity level parameter corresponding to the second security event, read the communication handshake status identifier of the second security event in the underlying network security protocol stack. Step 104: Based on the communication handshake state identifier, construct the state suppression signaling under the corresponding protocol specification. The state suppression signaling is used to send a node indicating to the peer of the second security event that the receiving window of the logical link is 0. Step 105: The state suppression signaling is fed back to the peer sending node via the underlying network security protocol stack, so that the peer sending node suspends the retransmission timer and enters the protocol backoff state. Step 106: When it is determined that the peer sending node is in the protocol backoff state, release the computing and storage resources occupied by the second security event, and reallocate the released computing and storage resources to the message processing queue corresponding to the security event data message to be analyzed.

[0006] Preferably, in step 102, the process of determining the first vehicle safety integrity level parameter includes the following sub-steps: Step 1021, extracting the service identifier and operation code of the safety event data message to be analyzed; Step 1022, locating the business objects in the power control domain, chassis control domain, and autonomous driving domain pointed to by the vehicle function identifier based on the service identifier; Step 1023, quantifying the failure impact of the business objects under the current driving conditions in combination with the operation code, and determining the level parameter conforming to the ISO26262 standard as the first vehicle safety integrity level parameter.

[0007] Preferably, in step 103, it is determined whether there is physical resource preemption between the first vehicle safety integrity level parameter and the second vehicle safety integrity level parameter, and whether the second security event in the underlying network security protocol stack is in an uninterruptible atomic communication state.

[0008] Preferably, in step 105, for the second security event where the underlying transport layer protocol is in a connectionless state, the method further includes the following sub-steps: step 1051, extracting the anti-replay feature sequence of the data packet of the second security event; step 1052, storing the anti-replay feature sequence into a high-speed cache circular queue; step 1053, maintaining the anti-replay sliding window baseline of the underlying network security protocol stack when physically truncating the data payload of the second security event.

[0009] Preferably, the method further includes monitoring the physical bandwidth utilization of the vehicle Ethernet and controller area network bus, and increasing the frequency of sending state suppression signaling when the physical bandwidth utilization exceeds a preset 80% congestion threshold, so as to suppress protocol-level retransmission requests from the underlying protocol level.

[0010] Preferably, the method further includes monitoring the duration of cryptographic operators allocated to the processing of data packets of security events to be analyzed, and dynamically adjusting the allocation weight of computing resources in conjunction with bus interrupt idle time.

[0011] Preferably, in step 106, the process of releasing the storage resources occupied by the second security event includes the following sub-steps: step 1061, freezing the security context image of the second security event in the underlying network security protocol stack; step 1062, dumping the security context image to a non-volatile reserved partition; step 1063, remapping the vacated random storage space to the input buffer corresponding to the first vehicle safety integrity level parameter.

[0012] Preferably, the state suppression signaling is used to trigger the peer sending node to reduce the sending window to single message mode, so as to reduce the peer sending node's occupation of the vehicle network physical channel while maintaining the logical link connection.

[0013] Preferably, the method further includes dynamically skipping non-critical verification steps in the identity authentication process of the security event data packet to be analyzed based on the first vehicle safety integrity level parameter, so that the response latency of the security event data packet at the protocol layer is no more than 10ms.

[0014] Compared with existing technologies, the priority response determination method for vehicle network access security events of the present invention has the following advantages: 1. In vehicle network access security incidents, by extracting the communication handshake status identifier of the underlying network security protocol stack and generating the corresponding status suppression signaling under the protocol specification, the peer sending node is induced to actively suspend the retransmission timer or downgrade the sending window. This eliminates the protocol retransmission storm induced by the forced deprivation of local resources from the causal chain of the underlying protocol, avoids secondary congestion interference of unexpected retransmission messages on the physical bandwidth of the vehicle bus, and ensures that high-security events have a definite communication channel response delay while obtaining local computing power.

[0015] 2. By mapping the vehicle function identifier obtained through parsing to the preset vehicle safety integrity level quantification parameters, and linking the resource arbitration logic unit to read the real-time security context of the second security event in the protocol stack, the system can construct pseudo-saturation delay messages according to different network security protocol specifications. This achieves deep coupling between the local computing unit scheduling and the communication peer protocol state machine, breaking the limitations of traditional solutions that rely solely on the operating system level to deprive resources. It ensures the communication stability of the core driving function safety link without increasing additional network bandwidth.

[0016] 3. For the second security event where the underlying transport layer protocol is in a connectionless state, the anti-replay feature sequence of its data packets is extracted and written into an independent high-speed cache circular queue. While physically truncating the data payload, the anti-replay sliding window benchmark of the local security protocol stack is maintained. This solves the problem that subsequent legitimate packets are misjudged as attacks due to packet loss in connectionless protocols under resource-constrained conditions, and achieves security verification state keep-alive and smooth recovery in low-power mode. Attached Figure Description

[0017] Figure 1 This is the overall execution flowchart of the priority response decision method of the present invention; Figure 2 This is the logical branch diagram of the security level determination linkage state suppression and resource scheduling of this invention. Detailed Implementation

[0018] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0019] It should be noted that all directional and positional terms used in this invention, such as: up, down, left, right, front, back, vertical, horizontal, inner, outer, top, bottom, transverse, longitudinal, center, etc., are only used to explain the relative positional relationship and connection between components in a specific state (as shown in the accompanying drawings). They are only for the convenience of describing this invention and do not require that this invention be constructed and operated in a specific orientation. Therefore, they should not be construed as limiting this invention. In addition, the descriptions of "first," "second," etc., in this invention are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated.

[0020] In the description of this invention, unless otherwise explicitly specified and limited, the terms installation, connection, and linking should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections; they can refer to direct connections or indirect connections through an intermediate medium; they can refer to the internal connection of two components. For those skilled in the art, the specific meaning of the above terms in this invention can be understood in conjunction with the specific circumstances.

[0021] In the description of this specification, references to the terms "an embodiment," "some embodiments," "illustrative embodiments," "examples," "specific examples," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example, and the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0022] A method for prioritizing responses to security events related to in-vehicle network access includes the following steps: Step 101: Obtain the security event data packet to be analyzed captured via the network interface, and identify the second security event currently being processed; Step 102: Parse the protocol header structure of the security event data message to be analyzed in order to extract the vehicle function identifier associated with the security event data message to be analyzed, and determine the first vehicle safety integrity level parameter corresponding to the security event data message to be analyzed according to the preset vehicle safety integrity level mapping table. Step 103: When it is determined that the first vehicle security integrity level parameter is higher than the second vehicle security integrity level parameter corresponding to the second security event, read the communication handshake status identifier of the second security event in the underlying network security protocol stack. Step 104: Based on the communication handshake state identifier, construct the state suppression signaling under the corresponding protocol specification. The state suppression signaling is used to send a node indicating to the peer of the second security event that the receiving window of the logical link is 0. Step 105: The state suppression signaling is fed back to the peer sending node via the underlying network security protocol stack, so that the peer sending node suspends the retransmission timer and enters the protocol backoff state. Step 106: When it is determined that the peer sending node is in the protocol backoff state, release the computing and storage resources occupied by the second security event, and reallocate the released computing and storage resources to the message processing queue corresponding to the security event data message to be analyzed.

[0023] Preferably, in step 102, the process of determining the first vehicle safety integrity level parameter includes the following sub-steps: Step 1021, extracting the service identifier and operation code of the safety event data message to be analyzed; Step 1022, locating the business objects in the power control domain, chassis control domain, and autonomous driving domain pointed to by the vehicle function identifier based on the service identifier; Step 1023, quantifying the failure impact of the business objects under the current driving conditions in combination with the operation code, and determining the level parameter conforming to the ISO26262 standard as the first vehicle safety integrity level parameter.

[0024] Preferably, in step 103, it is determined whether there is physical resource preemption between the first vehicle safety integrity level parameter and the second vehicle safety integrity level parameter, and whether the second security event in the underlying network security protocol stack is in an uninterruptible atomic communication state.

[0025] Preferably, in step 105, for the second security event where the underlying transport layer protocol is in a connectionless state, the method further includes the following sub-steps: step 1051, extracting the anti-replay feature sequence of the data packet of the second security event; step 1052, storing the anti-replay feature sequence into a high-speed cache circular queue; step 1053, maintaining the anti-replay sliding window baseline of the underlying network security protocol stack when physically truncating the data payload of the second security event.

[0026] Preferably, the method further includes monitoring the physical bandwidth utilization of the vehicle Ethernet and controller area network bus, and increasing the frequency of sending state suppression signaling when the physical bandwidth utilization exceeds a preset 80% congestion threshold, so as to suppress protocol-level retransmission requests from the underlying protocol level.

[0027] Preferably, the method further includes monitoring the duration of cryptographic operators allocated to the processing of data packets of security events to be analyzed, and dynamically adjusting the allocation weight of computing resources in conjunction with bus interrupt idle time.

[0028] Preferably, in step 106, the process of releasing the storage resources occupied by the second security event includes the following sub-steps: step 1061, freezing the security context image of the second security event in the underlying network security protocol stack; step 1062, dumping the security context image to a non-volatile reserved partition; step 1063, remapping the vacated random storage space to the input buffer corresponding to the first vehicle safety integrity level parameter.

[0029] Preferably, the state suppression signaling is used to trigger the peer sending node to reduce the sending window to single message mode, so as to reduce the peer sending node's occupation of the vehicle network physical channel while maintaining the logical link connection.

[0030] Preferably, the method further includes dynamically skipping non-critical verification steps in the identity authentication process of the security event data packet to be analyzed based on the first vehicle safety integrity level parameter, so that the response latency of the security event data packet at the protocol layer is no more than 10ms.

[0031] Example 1: In the underlying communication scenario of intelligent connected vehicles facing multi-source concurrent network scanning and high-frequency data interaction, the vehicle network is under high load. The network interface captures a security event data packet related to the core instructions of the chassis control domain that needs to be analyzed. At this time, the local computing unit is fully loaded with processing a second security event related to the background certificate verification of the infotainment domain. If the scheduling strategy of directly cutting off the local computing process of the second security event is adopted, the forced suspension will cause the sending node of the infotainment domain to trigger the retransmission mechanism due to the failure to receive the acknowledgment frame after timeout. The retransmission message quickly saturates the physical bandwidth of the vehicle bus, causing a protocol layer retransmission storm. As a result, the high-security level chassis control instructions cannot complete the underlying communication handshake due to network congestion, forming a situation where the local computing power advantage cannot be converted into the end-to-end transmission determinism. The resource arbitration logic unit parses the protocol header structure of the security event data packet to be analyzed, extracts the vehicle function identifier associated with the security event data packet to be analyzed, and determines the first vehicle safety integrity level parameter corresponding to the security event data packet to be analyzed according to the preset vehicle safety integrity level mapping table.

[0032] When the safety integrity level parameter of the first vehicle is determined to be higher than that of the second vehicle safety integrity level parameter corresponding to the second safety event, the resource arbitration logic unit reads the communication handshake state identifier of the second safety event in the underlying network security protocol stack. Based on the communication handshake state identifier, it constructs a state suppression signaling under the corresponding protocol specification. This state suppression signaling is used to indicate to the peer node of the second safety event that the receive window of the logical link is 0. According to the layered flow control mechanism of the network protocol stack, when the underlying transport layer protocol is identified as being in a connectionless state, the system does not use the receive window field, but constructs a global pause frame of the media access control layer as a state suppression signaling output to physically freeze the peer node's transmission queue. In the star-topology-based in-vehicle Ethernet switching architecture, this global pause frame of the media access control layer is encapsulated into a unicast flow control message with the MAC address of the second safety event source. It is routed to the specific physical port where the infotainment domain transmission node is located via the in-vehicle gateway switching chip. When the media access control layer of this physical port receives the flow control message, it only blocks the output of the transmission queue of this independent node toward the in-vehicle bus, while the chassis control layer... The independent physical port where the domain data resides and its corresponding high-priority Virtual Local Area Network (VLAN) forwarding channel are unaffected by the pause command, thus eliminating mutual exclusion on the physically isolated underlying links. This frees up the transmission medium without congestion for the data packets of the security events to be analyzed. The state suppression signaling is fed back to the peer sending node via the underlying network security protocol stack, triggering the peer sending node to suspend the retransmission timer and enter the protocol backoff state. The resource arbitration logic unit starts the local hardware observation timer, setting the timer overflow threshold to the maximum round-trip delay of packets between current network nodes. If the network interface does not capture the corresponding peer source physical address data packet before the timer overflows, the backoff is determined to be successful and the internal backoff state flag register is set. When the resource arbitration logic unit confirms that the peer sending node is in the protocol backoff state, it freezes the security context image of the second security event in the underlying network security protocol stack and dumps it to the non-volatile reserved partition, releases the computing and storage resources occupied by the second security event, and reallocates the released computing and storage resources to the packet processing queue corresponding to the data packets of the security events to be analyzed.

[0033] For the aforementioned connectionless underlying transport layer protocol, lacking a native connection acknowledgment mechanism, the resource arbitration logic unit extracts the plaintext sequence number from the network security header of the last received message of the second security event as an anti-replay feature sequence before physically truncating its data payload. This sequence number is then pushed sequentially into a high-speed cache circular queue independent of the system's main memory. The hardware state machine of the underlying network security protocol stack continuously polls the maximum value of the legitimate sequence number recorded in this circular queue, rigidly anchoring the left boundary of the local anti-replay sliding window to this maximum value. This ensures that delayed messages caused by blind transmissions from the peer during the truncation period are directly discarded by the underlying hardware after the window recovers, while new messages that legitimately increment within the sequence count are normally accepted by the window. This physically maintains the continuity of the anti-replay verification benchmark without activating complex decryption algorithms. Regarding bus timing conflicts caused by encryption verification, the resource arbitration logic unit continuously monitors the duration of cryptographic operators allocated to the data packet processing of the security event to be analyzed. It adjusts the allocation weight of computing resources based on the idle time windows of adjacent bus interruptions and limits the scheduling step size of the sub-matrix operation block to a specific value. ,in, This is a measure of the time span of the bus idle time window. The amount of basic physical time required for bus synchronization. To reflect the dimensionless constant of the protocol mapping state, the computational data blocks are discretized and distributed during the bus interrupt idle period. This ensures that the data verification process of the core driving function is adapted to the state benchmark of the underlying physical channel. Here, the dimensionality reduction conversion from the overall computing power allocation weight to the surface scheduling step size is achieved in collaboration with the timer interrupt divider of the underlying operating system. The system maps the original percentage-based resource allocation weight to the specific number of time ticks that the microcontroller is allowed to wake up the hardware encryption engine in a single bus idle cycle. Then, the scheduling step size value is used as the upper limit of the forced slice cycle of the hardware execution cryptographic operators. This mechanism constructs the precise conversion logic from abstract priority features to chip timing execution strategy, ensuring that the adjustment of the allocation weight can be seamlessly integrated into the underlying discrete time dimension physical operation sequence.

[0034] During the time window when the peer sending node is in the protocol backoff state, the data transmission action of the infotainment domain is suspended, and the physical bandwidth of the vehicle bus is transferred to the instruction transmission process of the chassis control domain. The data packets of the security events to be analyzed complete the network protocol handshake and logical verification in a channel environment without retransmission interference. The underlying communication channel maintains a stable connection state. In this logical verification process, in order to ensure that the response latency of high-priority packets is no more than 10ms, the system dynamically triggers the identity authentication acceleration command based on the first vehicle safety integrity level parameter. The system parses the authentication header of the data packets of the security events to be analyzed, marks the public key certificate trust chain tracing request and the hash tree traversal process of redundant long data blocks as non-critical verification links, and forces the corresponding asymmetric verification unit to bypass by writing a mask word to the control register of the cryptographic hardware accelerator. At the same time, only the message authentication code (MAC) extraction based on the preset symmetric session key and the single XOR comparison are retained as core verification operations. After receiving the interrupt signal of matching, the security state machine directly allows the network payload, which greatly reduces the computation time without breaking the closed loop of the communication state machine.

[0035] Example 2: In a hardware-in-the-loop test environment simulating an in-vehicle Ethernet architecture, the test platform is configured with network nodes having a bandwidth of 1000Mbps and a processor clock speed of 2.5GHz. Background random disturbance packets with a signal-to-noise ratio of 15dB are injected into the physical link. The scheduling step size for the submatrix operation blocks in the encryption verification process is set. The value of this parameter depends on the matching degree between the bus idle time and the cryptographic operator's computational capability. When the monitored bus idle time window... During narrowing, to reduce the probability of message collisions, a dimensionless constant reflecting the protocol mapping state is used. The value was reduced, and in this verification process, the value was selected. For 120μs and It was determined to be 15 μs. The value was 5, and the single scheduling step length was calculated to be 21 μs. Gradient loading tests covering the control group and the sample group of this invention were started. When setting the monitoring parameters of this gradient loading test, the test platform was based on the M / M / 1 network communication mathematical model in queuing theory and performed end-to-end delay derivation for the vehicle Ethernet bus in advance. The calculation results showed that when the physical bandwidth of the bus continuously exceeds the theoretical critical inflection point of 80%, the queuing length of the internal buffer queue of the switching node will increase exponentially in a nonlinear manner, causing subsequent control messages to trigger malicious retransmission due to buffer overflow. Therefore, the system establishes 80% as the congestion threshold for signaling frequency adjustment through physical modeling in order to achieve accurate feedforward intervention before the network enters the queuing avalanche state.

[0036] The test system injected data packets of the security events to be analyzed, corresponding to the first vehicle safety integrity level parameters, and second security event request packets, corresponding to the second vehicle safety integrity level parameters, through the network interface. The system then progressively increased the bus background traffic load in stages at 60%, 85%, and 95%. In the control group using a conventional local process suspension method, when the bus load reached 60%, the peer sending node in the infotainment domain initiated retransmissions at a rate of 12 frames / ms due to the lack of acknowledgment frames. When the load increased to 85%, the retransmission rate increased to 145 frames / ms, causing physical link issues. When congestion occurs on the path, in the prototype of this invention using the technical solution of this invention, the resource arbitration logic unit reads the communication handshake status identifier of the second security event and generates a state suppression signaling with a receive window of 0. Based on the carrier sense multiple access (CMA) conflict backoff principle, to avoid secondary link congestion caused by the state suppression signaling itself under extremely high physical bandwidth occupancy, the resource arbitration logic unit executes a transmission frequency clamping procedure, applies a truncated binary exponential backoff algorithm to the continuous transmission interval of the state suppression signaling, sets an initial transmission interval, and gradually increases the interval duration upon subsequent conflict triggering, which is fixed in the control register. The maximum transmission frequency limit is set. If the signaling transmission frequency exceeds the maximum limit due to dynamic load evolution, the signaling transmission action is forcibly suppressed by locking the state at the maximum limit. Data collected by the bus protocol analyzer shows that under 85% and 95% load conditions, the protocol-level retransmission request of the peer sending node in the sample group of this invention remains below 0.5 frames / ms, blocking the correlation path between computing resource preemption and network physical congestion. Monitoring data on peer communication response latency shows that under 85% load conditions, the processing latency of the security event data packets to be analyzed in the control group reaches 45.8ms. In this invention, after the peer sending node enters the protocol backoff state, the released storage and computing resources are allocated to the message processing queue corresponding to the security event data message to be analyzed. The measured response latency is 2.4ms. When the bus load increases to 95%, the processing latency of the present invention sample is locked at 2.7ms, exhibiting a non-linear anti-interference saturation plateau period. The experimental data confirms that the mechanism of feeding back the status suppression signaling to the peer sending node limits the network storm caused by the retransmission of low-level events and ensures the communication response efficiency of high-level messages under physical channel saturation conditions.

[0037] Example 3: In a regional gateway routing scenario based on vehicular Ethernet, the local computing unit and the peer sending node of the infotainment domain maintain an active encrypted secure session. When the bus load increases and the chassis control domain receives the security event data packet to be analyzed, the system performs a quantization conversion of the vehicle function identifier to priority parameters and suspends the existing encrypted network communication session. The resource arbitration logic unit extracts the service identifier and operation code of the security event data packet to be analyzed, and concatenates the feature bits of the service identifier and the control bits of the operation code according to the bit operation rules to generate an index vector. The dimensionless basic security value corresponding to the index vector is then queried in a preset two-dimensional mapping table. Simultaneously, the resource arbitration logic unit collects the current vehicle speed scalar. According to the relation The corresponding first vehicle safety integrity level parameters are calculated. ,in, As a compensation constant, As a dimensionless value, when the first vehicle security integrity level parameter is determined to be higher than the second vehicle security integrity level parameter corresponding to the second security event, for the encrypted security session of the second security event, the resource arbitration logic unit parses the transmission control protocol header and encapsulated security payload header of the underlying network security protocol stack, extracts the current sending sequence number and expected acknowledgment number as communication handshake status identifiers, and encapsulates the symmetric session key associated with the second security event, the sending sequence number counter value, and the physical starting address of the unacknowledged message buffer into a structured security context image.

[0038] The resource arbitration logic unit writes the security context image to the non-volatile reserved partition through the direct memory access channel. Based on the extracted expected acknowledgment number, it constructs a state suppression signaling containing a zero receive window field. The state suppression signaling containing the zero receive window field is sent to the peer sending node along the underlying network security protocol stack, triggering the peer sending node's sending window pointer locking mechanism. When the underlying network node interrupts the security session of the second security event, it retains the encrypted state parameters and sequence information, releases the computing and storage resources occupied by the second security event, and reallocates the released computing and storage resources to the packet processing queue corresponding to the data packet of the security event to be analyzed. After the data packet of the security event to be analyzed is processed, the system uses the security context image in the non-volatile reserved partition to restore the underlying security network link connection of the second security event.

[0039] Example 4: In the scenario of calibrating the pre-delivery baseline for the underlying communication architecture of intelligent connected vehicles, the system faces the challenge of complex cross-domain control commands and a lack of unified evaluation benchmarks for quantified levels. The R&D testing platform extracts the service identifiers and corresponding operation codes invoked by the target vehicle's control domain under standard operating conditions. Based on hazard analysis standards, the R&D testing platform determines the controllability and severity parameters of each type of operation code failure state. By mapping the product of the controllability and severity parameters to a normalized dimensionless numerical range, the platform determines the dimensionless basic safety value corresponding to each type of control command. The test system extracts the feature bits of the service identifier and the control bits of the operation code, concatenates the bits to generate a discrete index vector, and then links the index vector with the corresponding basic security value. The data is stored in the non-volatile memory of the vehicle gateway processor to form a vehicle safety integrity level image table. When the system faces network communication fluctuations caused by chassis dynamic response characteristics, the calibration unit deploys pre-parameters at the closed test track calibration site. This calibration unit operates under conditions where the vehicle is at multiple constant driving speeds. In this state, continuously inject known basic security values ​​into the underlying network security protocol stack. The test message.

[0040] Based on the principles of system identification process control variables and interference isolation, the test message injection and calibration tests are limited to idle conditions where the bus physical bandwidth utilization is less than 5% and external background random traffic disturbances are shielded. A microsecond-level hardware timestamp recorder is used to extract the critical response time difference. The critical response time difference begins at the hardware-level transmission completion interruption moment when the local network interface completes the state suppression signaling transmission and ends at the hardware-level reception trigger interruption moment when the network interface first captures the unexpected retransmission message initiated by the peer node. The calibration unit records the critical response time difference that triggers protocol-level retransmissions at different speed levels. Based on the ratio of the critical response time difference to the vehicle wheelbase reference length, a speed compensation constant with the dimensions of time and length is calculated. This information is then written into the dynamic configuration register of the resource arbitration logic unit. In this conversion mechanism, the vehicle wheelbase reference length represents the limit of physical safety margin allowed by the chassis dynamic control system, while the critical response time difference characterizes the communication blind zone duration in which the chassis control domain loses effective control commands due to network congestion. This speed compensation constant essentially extracts the loss-of-control sensitivity rate of the chassis mechanical actuators due to vehicle physical displacement within a specific communication blind zone. By converting the microsecond-level network latency in the information domain into the displacement deviation ratio in the physical domain, the underlying network protocol can directly map the degradation cost of communication latency into the physical hazard weight of the underlying mechanical structure when implementing flow control degradation. After the vehicle is put into actual operation, the resource arbitration logic unit, based on the relational formula... Combined with real-time acquired driving speed scalar Output the first vehicle safety integrity level parameters The resource arbitration logic unit issues a state suppression signaling containing a zero receive window field based on the first vehicle safety integrity level parameters, causing the peer sending node to suspend the retransmission timer and complete the targeted reallocation of computing and storage resources.

[0041] Example 5: In the scenario of offline calibration of the security strategy for the area controller of intelligent connected vehicles, the system faces the problem of insufficient quantification of the consequences of business object failures and insufficient dispersion of the image table data structure. The R&D test platform collects the business message flow characteristics of the target vehicle when calling obstacle avoidance commands in the autonomous driving domain and braking requests in the chassis domain, and extracts the key components that affect the safe and controlled state of the vehicle. The R&D test platform determines the weighting vector based on the sensitivity coefficient of each key component in the vehicle runaway model, calculates the dot product of it with the discrete business influence factors, and obtains the dimensionless basic safety value corresponding to each type of control command. The R&D testing platform will extract the index vector and the corresponding basic security values. The non-volatile memory of the vehicle gateway is written to construct a consistent quantitative benchmark to support the priority determination of the resource arbitration logic unit. The above-mentioned business impact factors are specifically implemented as structured parameters in the form of a one-dimensional array. The data source is the hardware-in-the-loop test log performed according to the ISO26262 standard during the factory delivery stage. The array contains three fixed quantitative mapping rules: braking distance deviation rate, steering angle execution lag rate, and power torque output error ratio, which correspond to normalized floating-point values ​​between 0 and 1. By performing dot product operation in linear algebra, the system accurately extracts the failure deviation amplitude of the underlying mechanical sensors into scalar weights that can participate in network resource scheduling, realizing a seamless transformation from the state of impaired business functions to communication processing priority.

[0042] When the resource arbitration logic unit acquires the bus idle time window during operation... To suppress parameter drift caused by noise in the bus physical layer electrical signals, the system initiates a timestamp calibration procedure based on a sliding window; sensor nodes continuously... The transition times of the physical layer synchronization level are collected within each bus transmission cycle, among which The collected transition time sequence is input into the median filter operator to remove sampling points whose deviation exceeds the preset deviation threshold, using the preset sliding sampling window length as the value. The resource arbitration logic unit selects the mean of the filtered samples as the bus idle time window. The step size is then substituted into the formula for calculating the scheduling step size to generate the discretized submatrix operation block scheduling step size. Under bus load fluctuation conditions, the above calibration procedure maintains the smooth evolution of the scheduling step size as the bus channel state changes.

[0043] The embodiments of this application have been described above with reference to the accompanying drawings. Unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other. This application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit of this application and the scope of protection of this invention, and all of these forms are within the protection scope of this application.

Claims

1. A method for prioritizing response decisions for vehicular network access security events, characterized in that, Includes the following steps: Step 101: Obtain the security event data packet to be analyzed captured via the network interface, and identify the second security event currently being processed; Step 102: Parse the protocol header structure of the security event data message to be analyzed in order to extract the vehicle function identifier associated with the security event data message to be analyzed, and determine the first vehicle safety integrity level parameter corresponding to the security event data message to be analyzed according to the preset vehicle safety integrity level mapping table. Step 103: When it is determined that the first vehicle security integrity level parameter is higher than the second vehicle security integrity level parameter corresponding to the second security event, read the communication handshake status identifier of the second security event in the underlying network security protocol stack. Step 104: Based on the communication handshake state identifier, construct the state suppression signaling under the corresponding protocol specification. The state suppression signaling is used to send a node indication to the peer of the second security event that the receiving window of the logical link is 0. Step 105: The state suppression signaling is fed back to the peer sending node via the underlying network security protocol stack, so that the peer sending node suspends the retransmission timer and enters the protocol backoff state. Step 106: When it is determined that the peer sending node is in the protocol backoff state, release the computing and storage resources occupied by the second security event, and reallocate the released computing and storage resources to the message processing queue corresponding to the security event data message to be analyzed.

2. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, In step 102, the process of determining the first vehicle safety integrity level parameter includes the following sub-steps: Step 1021, extracting the service identifier and operation code of the safety event data message to be analyzed; Step 1022, locating the business objects in the power control domain, chassis control domain, and autonomous driving domain pointed to by the vehicle function identifier based on the service identifier; Step 1023, quantifying the failure impact of the business objects under the current driving conditions in combination with the operation code, and determining the level parameter conforming to the ISO26262 standard as the first vehicle safety integrity level parameter.

3. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, In step 103, it is determined whether there is physical resource preemption between the first vehicle safety integrity level parameter and the second vehicle safety integrity level parameter, and whether the second security event in the underlying network security protocol stack is in an uninterruptible atomic communication state.

4. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, In step 105, for the second security event where the underlying transport layer protocol is in a connectionless state, the method further includes the following sub-steps: Step 1051, extract the anti-replay feature sequence of the data packet of the second security event; Step 1052: Store the anti-replay feature sequence into a high-speed cache circular queue; Step 1053: When physically truncating the data payload of the second security event, maintain the anti-replay sliding window baseline of the underlying network security protocol stack.

5. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, The method also includes monitoring the physical bandwidth utilization of the vehicle Ethernet and controller area network bus, and increasing the frequency of state suppression signaling when the physical bandwidth utilization exceeds a preset 80% congestion threshold, so as to suppress protocol-level retransmission requests from the underlying protocol level.

6. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, The method also includes monitoring the duration of cryptographic operators allocated to the data packet processing of the security event to be analyzed, and dynamically adjusting the allocation weight of computing resources in conjunction with bus interrupt idle time.

7. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, In step 106, the process of releasing the storage resources occupied by the second security event includes the following sub-steps: Step 1061, freezing the security context image of the second security event in the underlying network security protocol stack; Step 1062: Dump the security context image to a non-volatile reserved partition; Step 1063: Remap the vacated random storage space to the input buffer corresponding to the first vehicle safety integrity level parameter.

8. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, State suppression signaling is used to trigger the peer sending node to reduce its sending window to single-message mode, thereby reducing the peer sending node's occupation of the vehicle network physical channel while maintaining the logical link connection.

9. The method for prioritizing response to security events related to vehicle network access according to claim 1, characterized in that, The method also includes dynamically skipping non-critical verification steps in the identity authentication process of the security event data packets to be analyzed, based on the first vehicle safety integrity level parameters.

Citation Information

Patent Citations

  • Data transmission method and device in vehicle-mounted network, equipment and medium

    CN121334081A