Detection method and apparatus, and vehicle

By deploying master-slave firewall modules in the vehicle and collaboratively detecting the message payload and header within the vehicle, the problem of insufficient vehicle application layer defense is solved, achieving efficient intrusion defense and driving safety assurance.

WO2025195167A1PCT designated stage Publication Date: 2025-09-25YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/080504
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-22
Filing Date
2025-03-04
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

Existing vehicle defense measures are unable to parse application layer messages, resulting in insufficient intrusion defense capabilities of the in-vehicle Ethernet protocol. Components with low resource richness cannot bear too many security measures and are vulnerable to attacks, affecting the normal use of the vehicle.

Method used

By deploying master-slave firewall modules in the vehicle, the master module is responsible for checking the message payload and message header, and coordinating with the slave module to detect attacks, reducing resource usage and achieving collaborative defense between components in the vehicle.

Benefits of technology

It improves the intrusion prevention capability of the Ethernet application layer protocol in the vehicle, protects the vehicle from malicious attacks, ensures driving safety, and reduces the computing burden of components with lower resource richness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025080504_25092025_PF_FP_ABST
    Figure CN2025080504_25092025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a detection method and apparatus, and a vehicle. The method can be applied to the field of intelligent vehicles. The method comprises: receiving first information and a first message, which are sent by a second component, wherein the first information is used for requesting that a first component checks the load of the first message, the first message is a message associated with a first device, and the first device is a device interacting with an external network; checking the load of the first message on the basis of the first information, so as to obtain a first detection result, wherein the first detection result is used for indicating whether the load of the first message has been tampered with; and sending the first detection result to the second component. By means of the method, cooperative defense between components in a vehicle can be realized, thereby facilitating an improvement in the intrusion prevention capability of an in-vehicle Ethernet application layer protocol.
Need to check novelty before this filing date? Find Prior Art

Description

Detection method, device and vehicle

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on March 22, 2024, with application number 202410339914.4 and application name “Detection Method, Device and Vehicle”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of smart vehicles, and more specifically, to a detection method, device, and vehicle. Background Art

[0003] As vehicles become increasingly intelligent and connected, in-vehicle Ethernet and its underlying application-layer protocols (e.g., scalable service-oriented middleware over IP protocol (SOME / IP), diagnostic communication over IP (DOIP), and data distribution service (DDS)) are being introduced into vehicles. These in-vehicle application-layer protocols ensure the rapid implementation of new intelligent services. However, the use of these application-layer protocols inevitably introduces new attack surfaces.

[0004] Currently, vehicle-side defenses only cover layers 2-4 of the Open System Interconnection Reference Model (OSI). These defenses are unable to parse application-layer messages, much less implement application-layer defenses. While deploying security probes at various nodes within the vehicle can address these issues, the in-vehicle Ethernet network is a unified whole constructed by the collaboration of various components. Once a component is compromised, other nodes may be compromised, potentially affecting the normal operation of the vehicle. Summary of the Invention

[0005] The present application provides a detection method, device, and vehicle that can achieve collaborative defense between components within the vehicle, helping to improve the intrusion defense capabilities of the Ethernet application layer protocol within the vehicle.

[0006] In a first aspect, a detection method is provided, which is applied to a first component, wherein the first component includes a first firewall module, and the first firewall module is used to check the message header and payload of the message. The method includes: receiving first information and a first message sent by a second component, the first information being used to request the first component to check the payload of the first message, the first message being a message associated with a first device, and the first device being a device that interacts with an external network; checking the payload of the first message according to the first information to obtain a first detection result, the first detection result being used to indicate whether the payload of the first message has been tampered with; and sending the first detection result to the second component.

[0007] In this application, the first firewall module may also be referred to as the main firewall module, the first component may be a component with relatively high resource richness, such as a microprocessor unit (MPU); the second component may be a component with relatively low resource richness, such as a microcontroller unit (MCU).

[0008] In one possible implementation, the first device may be located inside the vehicle. For example, the first device may be a vehicle-mounted network communication terminal (telematics-box, T-Box), a cockpit domain controller (CDC), or a Bluetooth key controller.

[0009] In one possible implementation, the external network may refer to a network to which the vehicle is connected, such as a cellular network, a Bluetooth network, a local area network, or a short-range communication network.

[0010] In a possible implementation, the first message may be a message sent by the first device.

[0011] In this embodiment of the present application, a first component can detect the payload of a first message sent by a second component and send the first detection result to the second component, so that the second component can process the first message based on the first detection result. In this way, collaborative defense can be achieved between components within the vehicle, helping to improve the intrusion prevention capabilities of the Ethernet application layer protocol within the vehicle. In addition, this processing method can also enhance the defense capabilities of components with lower resource richness (for example, the second component) without excessively occupying the computing resources of the component.

[0012] In combination with the first aspect, in certain implementations of the first aspect, the method further includes: obtaining a second message, the second message being a message associated with a second device, and the second device being a device that interacts with the external network; checking the message header and payload of the second message to obtain a second detection result, the second detection result being used to indicate whether the message format of the message header of the second message corresponds to a preset message format, and whether the payload of the second message has been tampered with; and processing the second message according to the second detection result.

[0013] In one possible implementation, the second device may be located inside the vehicle. The second device and the first device may be the same device or different devices. For example, the first device and the second device may both be T-Boxes. For another example, the first device may be a T-box and the second device may be a CDC.

[0014] In a possible implementation, the second message may be a message sent by the second device.

[0015] In an embodiment of the present application, the first component can check the message header and payload of the second message and process the second message based on the second detection result. In this way, the first component can promptly detect attacks against the application layer and take corresponding countermeasures in a timely manner.

[0016] In combination with the first aspect, in certain implementations of the first aspect, processing the second message according to the second detection result includes: when the second detection result indicates that the message format of the message header of the second message corresponds to the preset message format and the payload of the second message has not been tampered with, parsing the second message according to the second detection result, or discarding the second message according to the second detection result when the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format, and / or the payload of the second message has been tampered with.

[0017] In an embodiment of the present application, the first component can parse or discard the second message based on the second detection result. In this way, through strict inspection and filtering, malicious messages can be prevented from causing damage or interference to the vehicle, and the efficiency of the first component in processing messages can be improved.

[0018] In combination with the first aspect, in certain implementations of the first aspect, the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format, and / or the payload of the second message is tampered with, and the method also includes: stopping processing messages associated with non-driving related components.

[0019] In one possible implementation, non-driving-related components may refer to components that are not directly involved in vehicle control and operation, but rather provide comfort, entertainment, and convenience for passengers. For example, components related to the vehicle audio system, vehicle air conditioning system, seat adjustment system, or vehicle lighting system.

[0020] In an embodiment of the present application, when the first component discovers that the application layer has been attacked, the first component can stop processing messages associated with non-driving related components. In this way, the vehicle's driving can be protected from interference from malicious attacks, thereby ensuring the user's driving safety.

[0021] In combination with the first aspect, in certain implementations of the first aspect, the first detection result indicates that the payload of the first message has been tampered with, and the method further includes: sending second information to the second component, the second information being used to instruct the second component to stop processing messages associated with non-driving-related components.

[0022] In an embodiment of the present application, when the first component discovers that the application layer has been attacked, the first component can send a second message to the second component, instructing the second component to stop processing messages associated with non-driving related components. In this way, the intrusion defense capability of the Ethernet application layer protocol in the vehicle can be further improved, and the situation where other components inside the vehicle are controlled by the attacker after a component inside the vehicle is invaded can be avoided.

[0023] In combination with the first aspect, in certain implementations of the first aspect, the first detection result is used to indicate whether the load of the first message has been tampered with, including: when a first character is included in the load of the first message, or the size of the load of the first message is not within a preset range, the first detection result is used to indicate that the load of the first message has been tampered with.

[0024] In a possible implementation, the first character may be, for example, a control character, a special symbol, or an escape character.

[0025] In combination with the first aspect, in certain implementations of the first aspect, the first message includes a payload that supports a character string format.

[0026] In combination with the first aspect, in some implementations of the first aspect, before receiving the first information and the first message sent by the second component, the method further includes: enabling a master-slave firewall module collaboration function.

[0027] In a second aspect, a detection method is provided, which is applied to a second component, wherein the second component includes a second firewall module, and the second firewall module is used to check the message header of the message. The method includes: obtaining a third message; sending a first information and a first message to the first component based on the third message, wherein the first information is used to request the first component to check the load of the first message, and the first message and the third message are messages associated with a first device, and the first device is a device that interacts with an external network; receiving a first detection result sent by the first component, wherein the first detection result is used to indicate whether the load of the first message has been tampered with; and processing the first message based on the first detection result.

[0028] In this application, the second firewall module may also be referred to as a slave firewall module.

[0029] In a possible implementation, the first message and the third message may be completely identical messages, that is, in this case the second component plays the role of forwarding the message.

[0030] In a possible implementation, the first message and the third message may be associated messages. For example, the first message is a message corresponding to the application layer portion of the third message.

[0031] In this embodiment of the present application, the second component can send the payload of the first message to the first component and process the first message based on the first detection result sent by the first component. In this way, collaborative defense can be achieved between components in the vehicle, helping to improve the intrusion prevention capabilities of the Ethernet application layer protocol in the vehicle. In addition, this processing method can also enhance the defense capabilities of components with lower resource richness (such as the second component) without excessively occupying the computing resources of the component.

[0032] In combination with the second aspect, in certain implementations of the second aspect, before sending the first information and the first message to the first component based on the third message, the method also includes: checking the message header of the first message to obtain a third detection result, and the third detection result is used to indicate whether the message format of the message header of the first message corresponds to the preset message format; processing the first message based on the first detection result includes: processing the first message based on the first detection result and the third detection result.

[0033] In an embodiment of the present application, the second component can process the first message based on its own third detection result on the first message and the first detection result sent by the first component. Since the detection of the message header only requires a small amount of computing resources, this processing method can enhance the defense capability of components with lower resource richness (for example, the second component) without excessively occupying the computing resources of the component.

[0034] In combination with the second aspect, in certain implementations of the second aspect, the processing of the first message according to the first detection result and the third detection result includes: when the first detection result indicates that the payload of the first message has not been tampered with and the third detection result indicates that the message format of the message header of the first message corresponds to the preset message format, parsing the first message according to the first detection result and the third detection result, or discarding the first message according to the first detection result and the third detection result when the first detection result indicates that the payload of the first message has been tampered with and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format.

[0035] In an embodiment of the present application, the second component can parse or discard the first message based on the first detection result and the third detection result. In this way, through strict inspection and filtering, malicious messages can be prevented from causing damage or interference to the vehicle, and the efficiency of the second component in processing messages can be improved.

[0036] In combination with the second aspect, in certain implementations of the second aspect, the first detection result indicates that the payload of the first message has been tampered with, and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format, and the method further includes: receiving second information sent by the first component, the second information being used to instruct the second component to stop processing messages associated with non-driving related components; and stopping processing the messages associated with the non-driving related components according to the second information.

[0037] In an embodiment of the present application, after receiving the second information, the second component can stop processing messages from non-driving related components according to the second information. In this way, the vehicle driving can be protected from interference from malicious attacks, thereby ensuring the user's driving safety.

[0038] In combination with the second aspect, in certain implementations of the second aspect, the first detection result is used to indicate whether the load of the first message has been tampered with, including: when a first character is included in the load of the first message, or the size of the load of the first message is not within a preset range, the first detection result is used to indicate that the load of the first message has been tampered with.

[0039] In combination with the second aspect, in certain implementations of the second aspect, the first message includes a payload that supports a character string format.

[0040] In combination with the second aspect, in certain implementations of the second aspect, before sending the first information and the first message to the first component according to the third message, the method further includes: enabling a master-slave firewall module collaboration function.

[0041] According to a third aspect, a detection device is provided, comprising: a transceiver unit and a processing unit; the transceiver unit is configured to receive first information and a first message sent by a second component, wherein the first information is used to request the first component to check a load of the first message, the first message is a message associated with a first device, and the first device is a device that interacts with an external network; the processing unit is configured to check the load of the first message according to the first information to obtain a first detection result, wherein the first detection result is used to indicate whether the load of the first message has been tampered with; the transceiver unit is further configured to send the first detection result to the second component.

[0042] In combination with the third aspect, in certain implementations of the third aspect, the device further includes: an acquisition unit; the acquisition unit is used to acquire a second message, where the second message is a message associated with a second device, and the second device is a device that interacts with the external network; the processing unit is also used to: check the message header and payload of the second message to obtain a second detection result, where the second detection result is used to indicate whether the message format of the message header of the second message corresponds to a preset message format, and whether the payload of the second message has been tampered with; and process the second message according to the second detection result.

[0043] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is specifically used to: parse the second message according to the second detection result when the second detection result indicates that the message format of the message header of the second message corresponds to the preset message format and the payload of the second message has not been tampered with; or discard the second message according to the second detection result when the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format and / or the payload of the second message has been tampered with.

[0044] In combination with the third aspect, in certain implementations of the third aspect, the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format, and / or the payload of the second message has been tampered with; the processing unit is also used to stop processing messages associated with non-driving related components.

[0045] In combination with the third aspect, in certain implementations of the third aspect, the first detection result indicates that the payload of the first message has been tampered with; the transceiver unit is also used to send second information to the second component, and the second information is used to instruct the second component to stop processing messages associated with non-driving related components.

[0046] In combination with the third aspect, in certain implementations of the third aspect, the first detection result is used to indicate whether the load of the first message has been tampered with, including: when a first character is included in the load of the first message, or the size of the load of the first message is not within a preset range, the first detection result is used to indicate that the load of the first message has been tampered with.

[0047] In combination with the third aspect, in certain implementations of the third aspect, the first message includes a payload that supports a character string format.

[0048] In combination with the third aspect, in some implementations of the third aspect, the processing unit is further used to enable a master-slave firewall module collaboration function.

[0049] In a fourth aspect, a detection device is provided, which includes: an acquisition unit, a transceiver unit and a processing unit; the acquisition unit is used to acquire a third message; the transceiver unit is used to: send first information and a first message to a first component based on the third message, the first information is used to request the first component to check the load of the first message, the first message and the third message are messages associated with a first device, and the first device is a device that interacts with an external network; receive a first detection result sent by the first component, the first detection result is used to indicate whether the load of the first message has been tampered with; the processing unit is used to process the first message based on the first detection result.

[0050] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is also used to check the message header of the first message to obtain a third detection result, and the third detection result is used to indicate whether the message format of the message header of the first message corresponds to a preset message format; the processing unit is specifically used to process the first message based on the first detection result and the third detection result.

[0051] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is specifically used to: parse the first message according to the first detection result and the third detection result when the first detection result indicates that the payload of the first message has not been tampered with and the third detection result indicates that the message format of the message header of the first message corresponds to the preset message format; or discard the first message according to the first detection result and the third detection result when the first detection result indicates that the payload of the first message has been tampered with and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format.

[0052] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first detection result indicates that the payload of the first message has been tampered with, and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format; the transceiver unit is also used to receive second information sent by the first component, and the second information is used to instruct the second component to stop processing messages associated with non-driving related components; the processing unit is also used to stop processing the messages associated with non-driving related components based on the second information.

[0053] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first detection result is used to indicate whether the load of the first message has been tampered with, including: when a first character is included in the load of the first message, or the size of the load of the first message is not within a preset range, the first detection result is used to indicate that the load of the first message has been tampered with.

[0054] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first message includes a payload that supports a character string format.

[0055] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to enable a master-slave firewall module collaboration function.

[0056] In a fifth aspect, a detection device is provided, comprising: at least one processor and a memory, wherein the at least one processor is coupled to the memory and is used to read and execute instructions in the memory, so that the device implements the method in any one of the implementation methods of the first aspect or the second aspect above.

[0057] In a sixth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a program code, and when the computer program code is run on a computer, the computer executes the method in any one of the implementation modes of the first aspect or the second aspect above.

[0058] In a seventh aspect, a chip is provided, which includes a circuit for executing the method in any one of the implementations of the first or second aspect above.

[0059] In an eighth aspect, a computer program product is provided, which includes a computer program. When the computer program is run by a processor, the method in any one of the implementation modes of the first aspect or the second aspect is executed.

[0060] In a ninth aspect, a system is provided, comprising: a device according to any one of the implementations of the third aspect, and a device according to any one of the implementations of the fourth aspect.

[0061] In a tenth aspect, a vehicle is provided, comprising: a device according to any one of the implementations of the third aspect, and a device according to any one of the implementations of the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] FIG1 is a functional schematic diagram of a vehicle provided in an embodiment of the present application;

[0063] FIG2 is a schematic diagram of the architecture of a vehicle-mounted intrusion detection system provided in an embodiment of the present application;

[0064] FIG3 is a system architecture applicable to the detection method provided in an embodiment of the present application;

[0065] FIG4 is a schematic flow chart of the detection method provided in an embodiment of the present application;

[0066] 5 is a schematic diagram of a master-slave firewall module dynamically cooperating to implement application layer intrusion defense according to an embodiment of the present application;

[0067] FIG6 is a schematic diagram of a detection device provided in an embodiment of the present application;

[0068] FIG7 is a schematic diagram of another detection device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0069] The technical solution in this application will be described below with reference to the accompanying drawings.

[0070] In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In this application, "at least one" refers to one or more, and "more than one" refers to two or more. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0071] In the embodiments of this application, prefixes such as "first" and "second" are used only to distinguish different description objects and have no limiting effect on the position, order, priority, quantity, or content of the described objects. The use of prefixes such as ordinal numbers in the embodiments of this application to distinguish description objects does not constitute a limitation on the described objects. For a statement of the described objects, please refer to the description in the context of the claims or embodiments, and the use of such prefixes should not constitute an unnecessary limitation.

[0072] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.

[0073] FIG1 is a functional schematic diagram of a vehicle 100 provided in an embodiment of the present application.

[0074] The vehicle 100 may include various subsystems, such as a perception system 120 and a computing platform 130. Alternatively, the vehicle 100 may include more or fewer subsystems, and each subsystem may include one or more components. Furthermore, each subsystem and component of the vehicle 100 may be interconnected via wired or wireless means.

[0075] The perception system 120 may include several sensors for sensing information about the environment surrounding the vehicle 100. For example, the perception system 120 may include a positioning system, which may be a global positioning system (GPS), a Beidou system, or other positioning systems. The perception system 120 may include one or more of an inertial measurement unit (IMU), a laser radar, a millimeter-wave radar, an ultrasonic radar, and a camera.

[0076] Some or all functions of the vehicle 100 may be controlled by a computing platform 130. The computing platform 130 may include processors 131 to 13n (n is a positive integer). A processor is a circuit capable of processing signals. In one implementation, the processor may be a circuit capable of reading and executing instructions, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor may implement certain functions through the logical relationships of a hardware circuit. The logical relationships of the hardware circuit may be fixed or reconfigurable. For example, the processor may be a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration file to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. In addition, the processor may also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc. In addition, the computing platform 130 may also include a memory for storing instructions, and some or all of the processors 131 to 13n may call the instructions in the memory to implement corresponding functions.

[0077] The computing platform 130 may control functions of the vehicle 100 based on input received from various subsystems, such as the perception system 120. In some embodiments, the computing platform 130 may be used to provide control over many aspects of the vehicle 100 and its subsystems.

[0078] Optionally, the above components are just an example. In actual applications, the components in the above modules may be added or deleted according to actual needs.

[0079] The vehicle 100 in this application may include: road vehicles, water vehicles, air vehicles, industrial equipment, agricultural equipment, or entertainment equipment, etc. For example, the vehicle 100 may be a vehicle (such as a commercial vehicle, a passenger car, a motorcycle, a flying car, a train, etc.), an industrial vehicle (such as a forklift, a trailer, a tractor, etc.), an engineering vehicle (such as an excavator, a bulldozer, a crane, etc.), agricultural equipment (such as a lawn mower, a harvester, etc.), amusement equipment, a toy vehicle, etc. The embodiments of this application do not specifically limit the type of vehicle.

[0080] The following takes vehicle 100 as an example of an intelligent vehicle to illustrate the technical problems to be solved by this application and the technical solutions adopted.

[0081] As vehicles become increasingly intelligent and connected, in-vehicle Ethernet and various upper-layer application-layer protocols (such as SOME / IP, DOIP, and DDS) are being introduced into the vehicle. These in-vehicle application-layer protocols ensure the rapid implementation of new intelligent services. However, the use of these various application-layer protocols inevitably introduces new attack surfaces. For example, if an attacker compromises external interaction devices (such as T-Box and CDC), they can unauthorizedly issue SOME / IP service calls or compromise the vehicle's domain controller by injecting malicious code (for example, exploit code) into the SOME / IP payload.

[0082] Currently, vehicle-side defense measures can only cover OSI layers 2-4 (for example, media access control security (MACSec) at the data link layer and Internet Protocol Security (IP Security, IPSec) at the network layer). These defense measures cannot parse application layer messages, let alone implement application layer defense.

[0083] Deploying security probes at various nodes within the vehicle can address the aforementioned situation. For example, one defense measure is shown in Figure 2. The architecture in Figure 2 may include: a system-on-a-chip (SOC), an intrusion detection system reporter (IdsR), an intrusion detection system manager (IdsM), security sensors (S), and a security event memory (Sem). In this system architecture, security probes can be deployed at each electronic control unit (ECU) node to collect security events (e.g., abnormal user logins, abnormal network traffic, or abnormal communication between components) in a side channel. The security events are then filtered by the IdsM and forwarded to the IdsR, which then centrally transmits the collected in-vehicle security events to the cloud-based SoC.

[0084] While this system architecture helps detect attacks, as a side-channel attack detection measure, it cannot provide real-time attack defense. Furthermore, the in-vehicle Ethernet network is a unified whole constructed by the collaboration of various components within the vehicle. Once a component is compromised, other nodes may be compromised, potentially affecting the normal operation of the vehicle. Furthermore, as components of the in-vehicle network, each ECU has varying levels of resource richness. Some weak devices (those with low resource richness), while carrying multiple important services, cannot afford security measures that consume excessive resources.

[0085] The present invention provides a detection method, device, and vehicle. By deploying master and slave firewall modules, these modules enable coordinated defense between vehicle components, helping to improve intrusion prevention capabilities for Ethernet application layer protocols within the vehicle. Furthermore, components deployed in the master firewall module can assist components deployed in the slave firewall module in attack detection, reducing resource usage by these components.

[0086] FIG3 is a system architecture applicable to the detection method provided in an embodiment of the present application.

[0087] As shown in FIG3 , the system architecture includes: a server, an untrusted area, a vehicle intranet unit (VIU0) to a vehicle intranet unit (VIU3), and a mobile data center (MDC).

[0088] Among them, the T-BOX and CDC in the untrusted zone are components that interact with the vehicle externally, making them vulnerable to hijacking and invoking malicious services. Components within the vehicle, such as VIU0 through VIU3 and the MDC, host numerous services and become targets for these application-layer attacks. VIU0, as the main gateway, can be equipped with a SoC with rich computing resources and serve as the primary firewall module. VIU1 through VIU3 are weak devices with relatively limited computing resources and can be deployed with secondary firewall modules to collaborate with the primary firewall module to provide intrusion prevention against application-layer attacks.

[0089] The firewall main module can filter both application-layer message headers and malicious payloads. Furthermore, the firewall main module not only meets its own message filtering needs but also helps firewall slave modules process filtering requests (for example, assisting weak devices in checking message payloads). The firewall main module can also include a firewall management module responsible for locally developing local firewall rules and updating and configuring filtering rules. Specifically, in addition to receiving new rules from the cloud server, the firewall management module can also collect security events reported by each service firewall filtering engine and other in-vehicle security solutions (for example, an intrusion detection system (IDS)). This module can then configure new filtering rules for each service firewall filtering engine or switch to a different rule set (for example, switching between normal mode and restricted mode). Optionally, in normal mode, VIU0 through VIU3 and the MDC can receive and process messages sent by other components. In restricted mode, VIU0 through VIU3 and the MDC can stop processing messages related to non-driving-related components (for example, components in the entertainment domain).

[0090] The firewall module can deploy a business firewall filtering engine to filter the application layer message headers of local services (for example, filtering of malformed messages or filtering of unauthorized calls).

[0091] It should be understood that a message header is a data structure used in data communications, typically containing metadata about the data, such as the sender, recipient, data type, size, and timestamp. The message header helps the receiver correctly parse the data to ensure its integrity, correctness, and security. The message payload refers to the actual data carried in a data communication, excluding the message header. The message payload carries and transmits data information; it represents the actual content transmitted during the communication process.

[0092] It should also be understood that the system architecture shown in FIG3 is merely an exemplary illustration, and those skilled in the art may make corresponding changes to the architecture shown in FIG3 according to actual needs, for example, changing the manner or number of firewall slave module deployments.

[0093] FIG4 is a schematic flow chart of a detection method provided in an embodiment of the present application. Method 400 may include steps S401 to S405 .

[0094] S401: The second component obtains a third message.

[0095] Among them, the second component can be a component with relatively low resource richness, for example, the MCU in Figure 3, or VIU1 to VIU3; the second component can include a second firewall module, which can be used to check the message header of the message, and the second firewall module can also be called a slave firewall module.

[0096] The third message may be a message associated with the first device, and the first device is a device that interacts with an external network.

[0097] Optionally, the third message is a message sent by the first device, and the first device may be located inside the vehicle. For example, the first device may be the T-Box, CDC, or Bluetooth key controller in FIG. 3 .

[0098] Alternatively, the external network may refer to a network to which the vehicle is connected, such as a cellular network, a Bluetooth network, a local area network, or a short-range communication network.

[0099] S402: The second component sends first information and a first message to the first component.

[0100] Among them, the first component can be a component with relatively high resource richness, for example, the MPU in Figure 3, or VIU0; the first component can include a first firewall module, which is used to check the message header and payload of the message. The first firewall module can also be called the main firewall module.

[0101] The first information is used to request the first component to check the payload of the first message.

[0102] Optionally, the first message and the third message may be completely the same message, that is, in this case the second component plays the role of forwarding the message.

[0103] Optionally, the first message and the third message may be associated messages, for example, the first message is a message corresponding to the application layer part in the third message.

[0104] In a possible implementation, the first message includes a payload that supports a character string format.

[0105] In a possible implementation, before step S402, method 400 further includes: the first component and the second component enabling a master-slave firewall module collaboration function.

[0106] S403: The first component checks the payload of the first message according to the first information to obtain a first detection result.

[0107] The first detection result is used to indicate whether the payload of the first message has been tampered with.

[0108] In one possible implementation, when the payload of the first message includes a first character, or the size of the payload of the first message is not within a preset range, the first detection result is used to indicate that the payload of the first message has been tampered with; otherwise, the first detection result is used to indicate that the payload of the first message has not been tampered with.

[0109] For example, when the payload of the first message includes control characters, special symbols or escape characters, or the payload size of the first message is 1.5MB, which exceeds the preset range [0, 1]MB, the first detection result is used to indicate that the payload of the first message has been tampered with.

[0110] S404: The first component sends the first detection result to the second component.

[0111] In one possible implementation, in addition to helping the second component check the payload of the first message, the first component can also perform message inspection on its own. In this way, the first component can promptly detect attacks targeting the application layer and take corresponding countermeasures in a timely manner.

[0112] Specifically, the first component can obtain a second message, which is a message associated with a second device, and the second device is a device that interacts with an external network. The first component can check the message header and payload of the second message to obtain a second detection result, which is used to indicate whether the message format of the message header of the second message corresponds to the preset message format, and whether the payload of the second message has been tampered with; the first component can process the second message based on the second detection result.

[0113] Optionally, the second device may be located inside the vehicle, and the second device and the first device may be the same device or different devices. For example, the first device and the second device may both be T-Boxes, or for another example, the first device may be a T-box and the second device may be a CDC.

[0114] Optionally, the second message may be a message sent by the second device.

[0115] In one possible implementation, the first component processes the second message based on the second detection result, including: if the second detection result indicates that the message format of the message header of the second message corresponds to a preset message format and the payload of the second message has not been tampered with, the first component parses the second message based on the second detection result; or if the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format and / or the payload of the second message has been tampered with, the first component discards the second message based on the second detection result. In this way, through strict inspection and filtering, malicious messages can be prevented from causing damage or interference to the vehicle, and the efficiency of the first component in processing messages can be improved.

[0116] In one possible implementation, if the second detection result indicates that the message format of the second message's header does not conform to a preset message format and / or the second message's payload has been tampered with, the first component may stop processing messages associated with non-driving-related components. This protects the vehicle from malicious attacks, thereby ensuring user driving safety.

[0117] Alternatively, non-driving related components may refer to components that are not directly involved in vehicle control and operation, but rather provide comfort, entertainment, and convenience for passengers, such as components related to the vehicle audio system, vehicle air conditioning system, seat adjustment system, or vehicle lighting system.

[0118] In one possible implementation, when a first detection result indicates that the payload of a first message has been tampered with, the first component can send a second message to a second component, instructing the second component to stop processing messages related to non-driving components. Upon receiving the second message, the second component can stop processing messages related to non-driving components. This can further enhance the intrusion prevention capabilities of the in-vehicle Ethernet application layer protocol, preventing a situation where a compromised component could lead to the attacker taking control of other components within the vehicle.

[0119] S405: The second component processes the first message according to the first detection result.

[0120] In one possible implementation, when the first detection result indicates that the payload of the first message has not been tampered with, the second component may parse the first message based on the first detection result; when the first detection result indicates that the payload of the first message has been tampered with, the second component may discard the first message based on the first detection result.

[0121] In one possible implementation, before step S402, the second component may inspect the header of the first message and obtain a third inspection result. This third inspection result indicates whether the format of the first message's header matches a preset header format. Then, in step S405, the second component may process the first message based on the first and third inspection results. This rigorous inspection and filtering prevents malicious messages from causing damage or interference to the vehicle and improves the efficiency of the second component's message processing.

[0122] Specifically, when the first detection result indicates that the payload of the first message has not been tampered with, and the third detection result indicates that the message format of the message header of the first message corresponds to the preset message format, the second component may parse the first message according to the first detection result and the third detection result, or when the first detection result indicates that the payload of the first message has been tampered with, and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format, the second component may discard the first message according to the first detection result and the third detection result.

[0123] Alternatively, when the third detection result is used to indicate that the message format of the message header of the first message does not correspond to the preset message format, the second component may not send the first information and the first message to the first component, and the second component may directly discard the first message based on the third detection result.

[0124] In this embodiment of the present application, a first component can detect the payload of a first message sent by a second component and send the first detection result to the second component, so that the second component can process the first message based on the first detection result. In this way, collaborative defense can be achieved between components within the vehicle, helping to improve the intrusion prevention capabilities of the Ethernet application layer protocol within the vehicle. In addition, this processing method can also enhance the defense capabilities of components with lower resource richness (for example, the second component) without excessively occupying the computing resources of the component.

[0125] It should be understood that in the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced by each other, and the technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

[0126] FIG5 is a schematic diagram of the dynamic collaboration of master-slave firewall modules to implement application layer intrusion defense according to an embodiment of the present application. This schematic diagram may be a detailed introduction to the system architecture and method 400 shown in FIG3 .

[0127] As shown in Figure 5, since the attack entry point can be T-BOX or CDC, filtering rules can be generated based on the behavior models of these two components. In particular, filtering rules can be automatically generated based on the corresponding application layer communication protocol behavior definition file. For example, whether there are special characters in the payload of the message to determine whether the message has been tampered with, or whether the CDC has the permission to call a service in VIU0.

[0128] The firewall master module can include the global behavior model of the T-BOX or CDC, that is, it can provide filtering rules for local services. It can also include filtering rules of the firewall slave module to help process inspection requests from the firewall slave module. The firewall slave module can include local service-related rules to minimize the use of weak device platform resources (for example, the resources of the second component). In particular, to avoid excessive use of the computing resources of weak devices, the filtering engine of the firewall slave module can only filter the message header and hand over the message payload to the firewall master module for inspection.

[0129] The firewall master module and the firewall slave module can regularly synchronize security events to the rule central management module in the firewall master module. The rule central management module can dynamically coordinate the rule updates of each firewall module based on the policies issued by the cloud and the security events of each firewall module. For example, when the hit technical indicators reported by the firewall slave module show obvious abnormalities, the rule central management module can configure new rules for the firewall slave module (for example, adjust the way the firewall slave module detects the message header), or switch the filtering mode of the firewall slave module from normal mode to restricted mode. In addition, the rule central management module can also adjust the rules or modes of other firewall modules that carry related services according to predefined policies (for example, predefining a firewall slave module as restricted mode) to achieve timely blocking of in-vehicle intrusion behaviors.

[0130] In one possible implementation, the central rule management module dynamically adjusts filtering rules to include not only rules based on packet headers and content, but also call context rules based on application-layer protocol characteristics. For example, some SOME / IP services have significant periodicity. If the interval between two service requests does not meet this period, it indicates a possible attack. Furthermore, the central rule management module can identify attack behaviors in other call contexts based on Table 1.

[0131] Table 1

[0132] It should be understood that in the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced by each other, and the technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

[0133] Figure 6 is a schematic diagram of a detection device 600 provided in an embodiment of the present application. The device 600 may include a transceiver unit 610, an acquisition unit 620, and a processing unit 630. The transceiver unit 610 is configured to implement corresponding data transceiver functions, receiving and sending corresponding instructions and / or data; the acquisition unit 620 is configured to acquire instructions and / or data; and the processing unit 630 is configured to perform data processing, so that the device 600 implements the aforementioned detection method.

[0134] Optionally, the device 600 further includes a storage unit, which is used to implement a corresponding storage function and store corresponding instructions and / or data.

[0135] As a design, the device 600 is used to execute the actions performed by the first component in the aforementioned method embodiment.

[0136] In one embodiment, the device 600 includes: a transceiver unit 610 and a processing unit 630; the transceiver unit 610 is used to receive a first information and a first message sent by the second component, the first information is used to request the first component to check the load of the first message, the first message is a message associated with a first device, and the first device is a device that interacts with an external network; the processing unit 630 is used to check the load of the first message according to the first information to obtain a first detection result, and the first detection result is used to indicate whether the load of the first message has been tampered with; the transceiver unit 610 is also used to send the first detection result to the second component.

[0137] In one possible implementation, the device 600 also includes: an acquisition unit 620; the acquisition unit 620 is used to obtain a second message, the second message is a message associated with a second device, and the second device is a device that interacts with an external network; the processing unit 630 is also used to: check the message header and load of the second message to obtain a second detection result, the second detection result is used to indicate whether the message format of the message header of the second message corresponds to the preset message format, and whether the load of the second message has been tampered with; according to the second detection result, process the second message.

[0138] In one possible implementation, the processing unit 630 is specifically used to: parse the second message according to the second detection result when the second detection result indicates that the message format of the message header of the second message corresponds to the preset message format and the payload of the second message has not been tampered with; or discard the second message according to the second detection result when the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format and / or the payload of the second message has been tampered with.

[0139] In one possible implementation, the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format, and / or the payload of the second message is tampered with; the processing unit 630 is also used to stop processing messages associated with non-driving related components.

[0140] In one possible implementation, the first detection result indicates that the payload of the first message has been tampered with; the transceiver unit 610 is further used to send second information to the second component, and the second information is used to instruct the second component to stop processing messages associated with non-driving related components.

[0141] In one possible implementation, the first detection result is used to indicate whether the payload of the first message has been tampered with, including: when the first character is included in the payload of the first message, or the size of the payload of the first message is not within a preset range, the first detection result is used to indicate that the payload of the first message has been tampered with.

[0142] In a possible implementation, the first message includes a payload that supports a character string format.

[0143] In a possible implementation, the processing unit 630 is further configured to enable a master-slave firewall module collaboration function.

[0144] As a design, the device 600 is used to execute the actions performed by the second component in the aforementioned method embodiment.

[0145] The device 600 includes: a transceiver unit 610, an acquisition unit 620 and a processing unit 630; the acquisition unit 620 is used to acquire a third message; the transceiver unit 610 is used to: send a first message and a first message to the first component according to the third message, the first information is used to request the first component to check the load of the first message, the first message and the third message are messages associated with the first device, and the first device is a device that interacts with an external network; receive a first detection result sent by the first component, the first detection result is used to indicate whether the load of the first message has been tampered with; the processing unit 630 is used to process the first message according to the first detection result.

[0146] In one possible implementation, the processing unit 630 is also used to check the message header of the first message to obtain a third detection result, and the third detection result is used to indicate whether the message format of the message header of the first message corresponds to the preset message format; the processing unit 630 is specifically used to process the first message based on the first detection result and the third detection result.

[0147] In one possible implementation, the processing unit 630 is specifically used to: parse the first message according to the first detection result and the third detection result when the first detection result indicates that the payload of the first message has not been tampered with and the third detection result indicates that the message format of the message header of the first message corresponds to the preset message format; or discard the first message according to the first detection result and the third detection result when the first detection result indicates that the payload of the first message has been tampered with and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format.

[0148] In one possible implementation, the first detection result indicates that the payload of the first message has been tampered with, and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format; the transceiver unit 610 is also used to receive the second information sent by the first component, and the second information is used to instruct the second component to stop processing messages associated with non-driving related components; the processing unit 630 is also used to stop processing messages associated with non-driving related components based on the second information.

[0149] In one possible implementation, the first detection result is used to indicate whether the payload of the first message has been tampered with, including: when the first character is included in the payload of the first message, or the size of the payload of the first message is not within a preset range, the first detection result is used to indicate that the payload of the first message has been tampered with.

[0150] In a possible implementation, the first message includes a payload that supports a character string format.

[0151] In a possible implementation, the processing unit 630 is further configured to enable a master-slave firewall module collaboration function.

[0152] Optionally, if the device 600 is located in the vehicle 100 , the processing unit 630 may be the processor 131 shown in FIG. 1 .

[0153] FIG7 is a schematic diagram of another detection device 700 provided in an embodiment of the present application.

[0154] The device 700 includes a memory 710, a processor 720, and a communication interface 730. The memory 710, processor 720, and communication interface 730 are connected via an internal connection path. The memory 710 is used to store instructions, and the processor 720 is used to execute the instructions stored in the memory 710 to control the communication interface 730 to obtain information, so that the device 700 implements the aforementioned detection method. Optionally, the memory 710 can be coupled to the processor 720 via an interface or integrated with the processor 720.

[0155] It should be noted that the communication interface 730 may be a transceiver, for example but not limited to a transceiver, and may further include an input / output interface.

[0156] The processor 720 stores one or more computer programs, which include instructions. When the instructions are executed by the processor 720, the detection device 700 executes the detection method in each of the above embodiments.

[0157] During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the processor 720 or by instructions in the form of software. The method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 710, and the processor 720 reads the information in the memory 710 and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.

[0158] Optionally, the communication interface 730 in FIG. 7 may implement the transceiver unit 610 and the acquisition unit 620 in FIG. 6 , and the processor 720 in FIG. 7 may implement the processing unit 630 in FIG. 6 .

[0159] Alternatively, the device 600 or the device 700 may be located in the vehicle 100 in FIG. 1 .

[0160] Optionally, the device 600 or the device 700 may be the computing platform 130 in the vehicle of FIG. 1 .

[0161] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a program code. When the computer program code is executed on a computer, the computer executes the method of FIG. 4 or FIG. 5 .

[0162] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the method of Figure 4 or Figure 5 is executed.

[0163] An embodiment of the present application further provides a chip, comprising: a circuit, which is used to execute the method shown in FIG. 4 or FIG. 5 .

[0164] An embodiment of the present application also provides a system, including a detection device as shown in FIG6 or FIG7 .

[0165] An embodiment of the present application also provides a vehicle, including a detection device as shown in FIG. 6 or FIG. 7 .

[0166] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0167] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0168] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0169] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0170] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0171] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0172] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A detection method, characterized in that: The method is applied to a first component, the first component including a first firewall module, the first firewall module being configured to check a message header and a payload of a message, the method comprising: receiving first information and a first message sent by a second component, wherein the first information is used to request the first component to check a load of the first message, the first message is a message associated with a first device, and the first device is a device that interacts with an external network; checking the payload of the first message according to the first information to obtain a first detection result, where the first detection result is used to indicate whether the payload of the first message has been tampered with; The first detection result is sent to the second component.

2. The method according to claim 1, wherein The method further comprises: Obtaining a second message, where the second message is a message associated with a second device, and the second device is a device interacting with the external network; Checking a message header and a payload of the second message to obtain a second detection result, where the second detection result is used to indicate whether a message format of the message header of the second message corresponds to a preset message format and whether the payload of the second message has been tampered with; Process the second message according to the second detection result.

3. The method according to claim 2, wherein The processing of the second message according to the second detection result includes: If the second detection result indicates that the message format of the message header of the second message corresponds to the preset message format and the payload of the second message has not been tampered with, parsing the second message according to the second detection result, or When the second detection result indicates that the message format of the message header of the second message does not correspond to the preset message format, and / or the payload of the second message is tampered with, the second message is discarded according to the second detection result.

4. The method according to claim 3, wherein The second detection result indicates that a message format of a message header of the second message does not correspond to the preset message format, and / or a payload of the second message is tampered with, and the method further includes: Stop processing messages associated with non-driving related components.

5. The method according to any one of claims 1 to 4, characterized in that The first detection result indicates that the payload of the first message has been tampered with, and the method further includes: Second information is sent to the second component, where the second information is used to instruct the second component to stop processing messages associated with non-driving related components.

6. The method according to any one of claims 1 to 5, characterized in that The first detection result is used to indicate whether the payload of the first message has been tampered with, including: When the payload of the first message includes a first character, or the size of the payload of the first message is not within a preset range, the first detection result is used to indicate that the payload of the first message has been tampered with.

7. The method according to any one of claims 1 to 6, characterized in that The first message includes a payload supporting a character string format.

8. The method according to any one of claims 1 to 7, characterized in that Before receiving the first information and the first message sent by the second component, the method further includes: Enable the master-slave firewall module collaboration function.

9. A detection method, characterized in that: The method is applied to a second component, the second component includes a second firewall module, the second firewall module is used to check the message header of the message, and the method includes: Obtain the third message; Sending, according to the third message, first information and a first message to a first component, wherein the first information is used to request the first component to check a load of the first message, the first message and the third message being messages associated with a first device, and the first device being a device interacting with an external network; receiving a first detection result sent by the first component, where the first detection result is used to indicate whether a payload of the first message has been tampered with; Process the first message according to the first detection result.

10. The method according to claim 9, wherein Before sending the first information and the first message to the first component according to the third message, the method further includes: Checking a message header of the first message to obtain a third detection result, where the third detection result is used to indicate whether a message format of the message header of the first message corresponds to a preset message format; The processing of the first message according to the first detection result includes: Process the first message according to the first detection result and the third detection result.

11. The method according to claim 10, wherein The processing of the first message according to the first detection result and the third detection result includes: If the first detection result indicates that the payload of the first message has not been tampered with, and the third detection result indicates that the message format of the message header of the first message corresponds to the preset message format, parsing the first message according to the first detection result and the third detection result, or When the first detection result indicates that the payload of the first message has been tampered with, and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format, the first message is discarded based on the first detection result and the third detection result.

12. The method according to claim 11, wherein The first detection result indicates that the payload of the first message is tampered with, and / or the third detection result indicates that the message format of the message header of the first message does not correspond to the preset message format, and the method further includes: receiving second information sent by the first component, where the second information is used to instruct the second component to stop processing messages associated with non-driving related components; According to the second information, processing of the message associated with the non-driving related component is stopped.

13. The method according to any one of claims 9 to 12, characterized in that The first detection result is used to indicate whether the payload of the first message has been tampered with, including: When the payload of the first message includes a first character, or the size of the payload of the first message is not within a preset range, the first detection result is used to indicate that the payload of the first message has been tampered with.

14. The method according to any one of claims 9 to 13, characterized in that The first message includes a payload supporting a character string format.

15. The method according to any one of claims 9 to 14, characterized in that Before sending the first information and the first message to the first component according to the third message, the method further includes: Enable the master-slave firewall module collaboration function.

16. A detection device, characterized in that: The apparatus includes: a unit or module for executing the method according to any one of claims 1 to 8 or 9 to 15.

17. A detection device, characterized in that: The method comprises a processor and a memory, wherein the processor is coupled to the memory, the memory is used to store computer programs or instructions, and the processor is used to execute the computer program or instructions in the memory, so that the method according to any one of claims 1 to 8 is executed.

18. A detection device, characterized in that: The method comprises a processor and a memory, wherein the processor is coupled to the memory, the memory is used to store computer programs or instructions, and the processor is used to execute the computer program or instructions in the memory, so that the method according to any one of claims 9 to 15 is executed.

19. A chip, characterized in that: The chip comprises a circuit for performing the method according to any one of claims 1 to 15 .

20. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a program code, and when the computer program code is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 15 .

21. A computer program product, characterized in that The computer product comprises a computer program, which, when executed by a processor, causes the method according to any one of claims 1 to 15 to be performed.

22. A detection system, characterized in that: The system comprises the apparatus according to claims 17 and 18.

23. A vehicle, characterized in that: The vehicle comprises the apparatus according to any one of claims 16 to 18 or comprises the detection system according to claim 22 .

Citation Information

Patent Citations

  • Synergistic learning invasion detection method used for data gridding

    CN101431416A

  • Internet of Vehicles traffic identification method and device

    CN112367326A

  • Vehicle-mounted Ethernet firewall system and communication delay determination method and device

    CN112637152A

  • Intrusion detection method and device, storage medium and electronic equipment

    CN113259351A

  • Abnormal flow detection method, system and device based on vehicle state and medium

    CN117729011A