Method and system for remote diagnostics and debugging of vehicle

The method and system provide secure and cost-effective remote vehicle debugging by establishing tunnels through internal networks using encryption and authentication, addressing security vulnerabilities in existing technologies.

RU2865648C1Active Publication Date: 2026-07-07CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
RU · RU
Patent Type
Patents
Current Assignee / Owner
CHONGQING CHANGAN AUTOMOBILE CO LTD
Filing Date
2024-12-27
Publication Date
2026-07-07

AI Technical Summary

Technical Problem

Existing remote vehicle debugging technologies lack security, as they are susceptible to internal and external attacks through debug channels, and require complex protocol conversions and custom software development.

Method used

A method and system for remote vehicle diagnostics and debugging that uses a cloud tunnel center to establish secure tunnels through internal networks, employing encryption and authentication mechanisms, such as FRP or NPS, without the need for additional vehicle component development, and includes diagnostic debug codes and whitelists to verify authenticity and prevent malicious access.

Benefits of technology

Ensures secure and cost-effective remote vehicle debugging by preventing fraudulent attacks and reducing development costs, while enabling convenient deployment and secure execution of remote debugging instructions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_ABST
    Figure 00000001_ABST
Patent Text Reader

Abstract

FIELD: vehicle debugging.SUBSTANCE: present invention discloses a method and system for remote diagnostics and debugging of a vehicle. The method includes sending information about a part to be debugged by a vehicle via a debugging centre on the vehicle side to a cloud debugging centre, which in response requests information about a tunnel connection from the cloud tunnel centre on the cloud platform. The vehicle then receives the specified tunnel connection information through its debug centre and forwards it to the target debug centre of the specific part. After this, the target part debug centre enables the target tunnel client on the vehicle side. This target tunnel client, comprising tunnel connection information, requests a debug tunnel from the cloud tunnel centre. After successfully verifying the tunnel connection information, the cloud tunnel centre establishes a debug channel. At the end of the process, the vehicle receives a remote debugging instruction sent by the cloud platform via the established debugging tunnel.EFFECT: increase in the safety and security of the process of remote debugging of vehicle components in a public intranet environment by preventing external and internal malicious attacks on on-board electronic systems, as well as an increase in the convenience of deploying a software communications infrastructure on board a vehicle while simultaneously reducing the labour intensity and overall costs of developing application software.12 cl, 6 dwg
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese Patent Application No. 202410006860.X, entitled "VEHICLE REMOTE DIAGNOSIS AND DEBUGGING METHOD AND SYSTEM", filed with the China National Intellectual Property Administration (CNIPA) on January 2, 2024, the contents of which are incorporated herein by reference in their entirety.

[0003] FIELD OF TECHNOLOGY

[0004] The present invention relates to the technical field of vehicle debugging, and in particular relates to a method and system for remote diagnosis and debugging of a vehicle.

[0005] STATE OF THE ART

[0006] With the development of vehicle platformization, vehicle diagnostics and debugging have become an integral part of both vehicle development and vehicle maintenance. However, offline debugging in 4S (Sales, Service, Spare Parts, Surveys) stores often lacks the ability to obtain real-time data, leading to the development of remote diagnostics and debugging. Traditional remote vehicle diagnostics technology requires the vehicle to be connected to a public network cloud server. Debugging instructions from the cloud server are then sent to the vehicle via the public network. The command protocol is then converted by the vehicle into CAN network messages for transmission to the vehicle.Due to the complexity of the vehicle network environment and the difficulty of developing conversion protocols, the complexity of remote diagnostics also increases. Some technologies establish a debug channel between the server and the vehicle using corporate VPN technology to enable remote vehicle debugging. Vehicle debugging does not require the development of integrated custom software or a customized protocol for secure data exchange. The only requirement is the integration of the vehicle controller's native debugging service and the configuration of the controller's debugging service. However, remote debugging is susceptible to internal and external attacks, and such attacks can be directed at the vehicle through the debug channel. Therefore, the security of remote vehicle debugging is not yet guaranteed.

[0007] DISCLOSURE OF THE INVENTION

[0008] In view of the above, the present invention provides a method and system for remote diagnostics and debugging of a vehicle to solve the problem of low security of remote debugging of a vehicle under debugging conditions over an internal network.

[0009] According to the first aspect, the present invention provides a method for remotely diagnosing and debugging a vehicle. The method is applied to a vehicle, and the method includes: sending information about a part to be debugged by a debugging center on the vehicle side to a cloud debugging center, so that the cloud debugging center, in response to the information about the part to be debugged, requests tunnel connection information from the cloud tunnel center on the cloud platform, wherein the debugging center on the vehicle side and the cloud debugging center located on the cloud platform are software modules configured to exchange data with each other over a public network, and the cloud tunnel center is a server configured to establish a tunnel to penetrate the internal network;receiving tunnel connection information returned by the cloud debugging center, by the debugging center on the vehicle side; forwarding the tunnel connection information by the debugging center on the vehicle side to the target debugging center of the part to be debugged, wherein each debuggable part in the vehicle is provided with a debugging center of the part configured to control the switching on and off of a tunnel client located on the vehicle side, corresponding to each debuggable part, wherein the tunnel client on the vehicle side is a client configured to establish a tunnel for penetrating the internal network;The target vehicle-side tunnel client is turned on by the target part debugging center and the target vehicle-side tunnel client requests a debugging tunnel from the cloud tunnel center containing tunnel connection information, so that after successfully checking the tunnel connection information, the cloud tunnel center establishes a debugging tunnel; and the target vehicle-side tunnel client receives a remote debugging instruction sent by the cloud platform based on the information of the part to be debugged, and debugs the part to be debugged in accordance with the remote debugging instruction. 0010. In accordance with the above technical means, embodiments of the present invention provide a vehicle-side debugging center and a cloud debugging center on the vehicle and cloud platform, respectively, for exchanging data with each other over a public network, provide a cloud tunnel center on the cloud platform for establishing a tunnel to penetrate the internal network, and provide a vehicle-side tunnel client on each part of the vehicle. Thus, when a user requires an engineer to remotely debug one or more parts of the vehicle, information about the part to be debugged is first sent over the public user network to the cloud platform.The cloud platform then uses the received debugging information to request tunnel connection information from the cloud tunnel center and then returns the tunnel connection information to the vehicle. The vehicle then requests a tunnel to penetrate the internal network from the cloud tunnel center via the vehicle-side debugging tunnel client containing the tunnel connection information. The cloud tunnel center establishes the debug tunnel only after successfully decrypting and verifying the tunnel connection information, which enables the use of encryption in the debug tunnel and ensures the security of the debug tunnel.In addition, the present invention enables the implementation of the establishment of a debug tunnel using conventional tunnel creation means such as FRP or NPS, without the need for additional development for vehicle parts and provides the advantage of more convenient deployment compared to the remote debugging methods known in the art in this industry, while reducing the costs of developing remote debugging.

[0011] In an optional embodiment, the information about the part to be debugged contains information about an attribute of the part to be debugged and a diagnostic debug code, wherein the information about the attribute of the part to be debugged is configured to describe the part to be debugged, and the diagnostic debug code is configured to be returned by the cloud debugging center to the debugging center on the vehicle side together with the tunnel connection information, so that the debugging center on the vehicle side checks whether the received diagnostic debug code matches the sent diagnostic debug code.

[0012] According to the above technical means, when the user requires a technician to perform remote diagnosis and debugging, the vehicle also sends a diagnostic debug code to the cloud platform. Subsequently, when the cloud platform returns tunnel connection information, the diagnostic debug code is also included for return to the vehicle. The vehicle then determines whether the tunnel connection information was returned by the appropriate cloud debugging center based on the match between the sent diagnostic debug code and the received diagnostic debug code, thereby preventing damage caused by the returned tunnel connection information being fraudulent information sent by external hackers.

[0013] In an optional embodiment, the diagnostic debug code is generated as follows: calculating and obtaining a hash value using the current timestamp, a unique vehicle identifier, and screen coordinates, wherein the screen coordinates are specified by the user by clicking on the screen on the side of the vehicle when the user requests the generation of the diagnostic debug code; and randomly extracting a data value of a predetermined bit length from the hash value to form the diagnostic debug code.

[0014] According to the above technical means, compared to the method for generating conventional verification codes, the diagnostic debug code additionally includes the coordinates of the click on the screen. Because the start button is an area with a range of coordinates, and the process of the vehicle user specifying the coordinates on the screen by clicking is more random, the random verification code generated in this way has a higher degree of randomness, is more resistant to hacking, and provides higher security than conventional random verification codes.

[0015] In an optional embodiment, the tunnel connection information comprises a tunnel connection code and information for verifying the authenticity of the tunnel identification data.

[0016] According to the above technical means, the tunnel connection information provided by the embodiments of the present invention comprises a tunnel connection code and tunnel identity authentication information. The tunnel connection code is configured to pair the vehicle-side tunnel client with the cloud tunnel center to establish a debugging channel. The tunnel identity authentication information is configured to enable the cloud tunnel center to verify that the tunnel connection code sent by the vehicle-side tunnel client is the same as the code previously sent by the cloud platform and not the tunnel connection code sent by a hacker in an attempt to carry out an attack, thereby further ensuring the security of the tunnel.

[0017] In an optional embodiment, the step of receiving a remote debugging instruction sent by the cloud platform based on the information of the part to be debugged by the target tunnel client on the vehicle side includes: receiving the remote debugging instruction and auditing the remote debugging instruction based on the instruction whitelist and the parameter whitelist; if the audit result is negative, refusing to debug the part to be debugged in accordance with the remote debugging instruction; and if the audit result is positive, performing the step of debugging the part to be debugged in accordance with the remote debugging instruction.

[0018] According to the above technical measures, before a vehicle performs remote debugging according to a remote debugging instruction sent by the cloud platform, the remote debugging instruction is audited against a command whitelist and parameter whitelist. Only instructions with a positive audit result are executed for remote debugging, further preventing internal engineers from entering malicious debugging instructions that could damage the vehicle, thereby solving the internal security issue.

[0019] In an optional embodiment, the method further includes: turning off the target tunnel client on the vehicle side by the target part debug center and destroying the tunnel connection information and the debug diagnostic code to close the debug tunnel when the cloud tunnel center detects that the debug tunnel does not transmit data for longer than a specified duration.

[0020] According to the above technical means, a safe and convenient mechanism for exiting the debug tunnel is provided.

[0021] In an optional embodiment, after the vehicle-side debugging center checks that the received diagnostic debug code matches the sent diagnostic debug code, the method further includes: disabling the local USB debugging mechanism and deleting the diagnostic debug code by the vehicle-side debugging center.

[0022] According to the above technical means, by introducing the step of disabling the local USB debugging mechanism, it can more effectively prevent malicious users from accessing the tunnel to attack the cloud platform compared with conventional remote debugging mechanisms of offline debugging.

[0023] According to the second aspect, an embodiment of the present invention provides a method for remotely diagnosing and debugging a vehicle. The method is applied to a vehicle, and the method comprises: receiving information about a part to be debugged sent by a debugging center on the vehicle side, by a cloud debugging center, wherein the debugging center on the vehicle side and the cloud debugging center are software modules configured to exchange data with each other over a public network, and the debugging center on the vehicle side is located in the vehicle; in response to the information about the part to be debugged, requesting tunnel connection information from the cloud tunnel center by the cloud debugging center, wherein the cloud tunnel center is a server that is located on a cloud platform and is configured to establish a tunnel to penetrate the internal network;sending tunnel connection information to a vehicle-side debugging center by a cloud debugging center, so that the vehicle-side debugging center forwards the tunnel connection information to a target debugging center of a part to be debugged, in order to allow the target debugging center of the part to turn on a target tunnel client on the vehicle side, wherein each debuggable part in the vehicle is provided with a debugging center of the part, configured to control turning on and off a tunnel client on the vehicle side corresponding to each debuggable part, and the tunnel client on the vehicle side is a client configured to establish a tunnel for penetrating an internal network;receiving tunnel connection information sent by a target tunnel client on the vehicle side, the cloud tunnel center and checking the tunnel connection information; after successfully checking the tunnel connection information, establishing a debug tunnel by the cloud tunnel center; and sending a remote debugging instruction generated based on the information of the part to be debugged, through the debugging tunnel to the target tunnel client on the vehicle side, so that the vehicle debugs the part to be debugged according to the remote debugging instruction.

[0024] In an optional embodiment, the step of requesting tunnel connection information from the cloud tunnel center by the cloud debugging center in response to information on the part to be debugged includes: when the cloud tunnel center receives a request message sent by the cloud debugging center, checking whether the IP information of the cloud debugging center is included in the previously stored IP information; if the IP information is included in the previously stored IP information, performing two-way authentication based on a certificate in the cloud debugging center by the cloud tunnel center; if the two-way authentication based on a certificate passes, verifying the account and password sent by the cloud debugging center by the cloud tunnel center; and if the account and password verification passes, then, in response to the request message, sending the tunnel connection information by the cloud tunnel center to the cloud debugging center.

[0025] According to the above technical measures, when the cloud debugging center requests tunnel connection information from the cloud tunneling center, a minimal virtual domain is established to verify the cloud debugging center by the cloud tunneling center by defining an IP address range. In this case, domain security is ensured by both certificate-based authentication and account and password authentication to verify the authenticity of the cloud debugging center. This prevents damage caused by hackers sending tunnel connection information requests and, compared with conventional token-based authentication methods, prevents the risk of malicious access due to token leakage.

[0026] In an optional embodiment, the step of sending a remote debugging instruction generated based on the information of the part to be debugged through a debugging tunnel to a target tunnel client on the vehicle side includes: auditing the remote debugging instruction based on an instruction whitelist and a parameter whitelist; if the audit result is negative, refusing to send the remote debugging instruction; and if the audit result is positive, sending the remote debugging instruction.

[0027] In an optional embodiment, the method further includes: sending a logout message by the cloud debugging center to the cloud tunnel center; in response to the logout message, closing the debugging tunnel and destroying the tunnel connection information by the cloud tunnel center; and destroying the tunnel connection information by the cloud debugging center and sending a logout command to the vehicle-side debugging center so that the vehicle-side debugging center forwards the logout command to the target part debugging center to allow the target part debugging center to turn off the target vehicle-side tunnel client and destroy the tunnel connection information.

[0028] According to a third aspect, the present invention provides a system for remote diagnosis and debugging of a vehicle. The system comprises a vehicle and a cloud platform, wherein: the vehicle is configured to send information about a part to be debugged via a debugging center on the vehicle side to a cloud debugging center on the cloud platform, wherein the debugging center on the vehicle side and the cloud debugging center are software modules configured to exchange data with each other over a public network;the cloud platform is configured to request, in response to information about the part to be debugged, information about the tunnel connection from the cloud tunnel center via the cloud debug center, wherein the cloud tunnel center is a server that is located on the cloud platform and is configured to establish a tunnel for penetrating the internal network; the cloud platform is configured to send information about the tunnel connection to the debug center on the vehicle side via the cloud debug center;the vehicle is configured to forward tunnel connection information via a debugging center on the vehicle side to a target debugging center of a part of the part to be debugged, wherein each part in the vehicle configured to be debugged is provided with a debugging center of a part configured to control the switching on and off of a tunnel client on the vehicle side corresponding to each part configured to be debugged, and the tunnel client on the vehicle side is a client configured to establish a tunnel for penetrating an internal network; the vehicle is configured to turn on the target tunnel client on the vehicle side via the target debugging center of the part;The vehicle is configured to send tunnel connection information to a cloud tunnel center via a target tunnel client on the vehicle side; the cloud platform is configured to check the tunnel connection information via the cloud tunnel center and, after successfully checking the tunnel connection information, to establish a debug tunnel; the cloud platform is configured to send a remote debug instruction generated based on the information on the part to be debugged via the debug tunnel to the target tunnel client on the vehicle side; and the vehicle is configured to debug the part to be debugged in accordance with the remote debug instruction.

[0029] The technical solutions proposed in the present invention have the following advantages:

[0030] (1) Embodiments of the present invention provide a vehicle-side debugging center and a cloud debugging center on the vehicle and a cloud platform, respectively, for exchanging data with each other over a public network, provide a cloud tunnel center on the cloud platform for establishing a tunnel to penetrate the internal network, and provide a tunnel client on the vehicle side on each part of the vehicle. Thus, when a user requires an engineer to remotely debug one or more parts of the vehicle, information about the part to be debugged is first sent over the public user network to the cloud platform. The cloud platform then uses the received information about the part to be debugged to request tunnel connection information from the cloud tunnel center and then returns the tunnel connection information to the vehicle.The vehicle then requests a tunnel to penetrate the internal network from the cloud tunnel center via the vehicle-side tunnel client of the debugging portion, which contains the tunnel connection information. The cloud tunnel center establishes the debug tunnel only after successfully decrypting and verifying the tunnel connection information, which enables the use of an encryption mechanism in the debug tunnel and ensures the security of the debug tunnel. Furthermore, the present invention enables the establishment of a debug tunnel using conventional tunnel creation tools, such as FRP or NPS, without the need for additional development for vehicle components and offers the advantage of more convenient deployment compared to prior art remote debugging methods in this industry, while reducing the development costs of remote debugging.

[0031] (2) According to the above technical means, when the user requires an engineer to perform remote diagnosis and debugging, the vehicle also sends a diagnostic debug code to the cloud platform. Subsequently, when the cloud platform returns tunnel connection information, the diagnostic debug code is also included for return to the vehicle. The vehicle then determines whether the tunnel connection information was returned by the appropriate cloud debugging center based on the match between the sent diagnostic debug code and the received diagnostic debug code, thereby preventing damage due to a situation in which the returned tunnel connection information is information sent through a fraudulent attack by external hackers.

[0032] (3) Compared with the method for generating conventional verification codes, the diagnostic debug code provided by the embodiments of the present invention additionally inputs the coordinates of a click on the screen. Since the start button is an area having a range of coordinates, and the process of a vehicle user specifying coordinates on the screen by clicking is more random, the random verification code generated in this way has a higher degree of randomness, is more resistant to hacking, and provides higher security compared to a conventional random verification code.

[0033] (4) The tunnel connection information provided by the embodiments of the present invention comprises a tunnel connection code and tunnel identity authentication information. The tunnel connection code is configured to pair the vehicle-side tunnel client with the cloud tunnel center to establish a debugging channel. The tunnel identity authentication information is configured to enable the cloud tunnel center to verify that the tunnel connection code sent by the vehicle-side tunnel client is the same as the code previously sent by the cloud platform and not the tunnel connection code sent by a hacker in an attempt to carry out an attack, thereby further ensuring the security of the tunnel.

[0034] (5) In embodiments of the present invention, before a vehicle performs remote debugging according to a remote debugging instruction sent by the cloud platform, the remote debugging instruction is audited against a command whitelist and parameter whitelist. Only instructions with a positive audit result are executed for remote debugging, further preventing internal engineers from entering malicious debugging instructions that could damage the vehicle, thereby solving the internal security issue.

[0035] (6) Provides a safe and convenient mechanism for exiting the debug tunnel.

[0036] (7) By introducing a step to disable the local USB debugging mechanism, we can more effectively prevent malicious users from accessing the tunnel to attack the cloud platform compared to conventional remote debugging mechanisms of offline debugging.

[0037] (8) When the cloud debugging center requests tunnel connection information from the cloud tunneling center, a minimal virtual domain is established to verify the cloud debugging center by the cloud tunneling center by defining an IP address range. Security within the domain is then ensured by both certificate-based authentication and account and password authentication to verify the authenticity of the cloud debugging center. This prevents damage caused by hackers sending tunnel connection information requests and, compared with conventional token-based authentication methods, prevents the risk of malicious access due to token leakage.

[0038] BRIEF DESCRIPTION OF DRAWINGS

[0039] To more clearly illustrate the technical solutions in specific embodiments of the present invention or the prior art, the accompanying drawings will be briefly described below. It is obvious that the drawings described below represent only specific embodiments of the present invention. Based on these drawings, other drawings can be derived by those skilled in the art without creative efforts.

[0040] FIG. 1 is a schematic diagram of the structure of a remote diagnostic and debugging system for a vehicle according to an embodiment of the present invention.

[0041] FIG. 2 is a flow chart of a method for remotely diagnosing and debugging a vehicle according to an embodiment of the present invention.

[0042] FIG. 3 is another flow chart of a method for remotely diagnosing and debugging a vehicle according to an embodiment of the present invention.

[0043] FIG. 4 is another flow chart of a method for remotely diagnosing and debugging a vehicle according to an embodiment of the present invention.

[0044] FIG. 5 is another flow chart of a method for remotely diagnosing and debugging a vehicle according to an embodiment of the present invention.

[0045] FIG. 6 is another flow chart of a method for remotely diagnosing and debugging a vehicle according to an embodiment of the present invention.

[0046] IMPLEMENTATION OF THE INVENTION

[0047] In order to more clearly understand the objectives, technical solutions, and advantages of the embodiments of the present invention, the technical solutions of the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings of the embodiments of the present invention. It is obvious that the described embodiments represent only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by persons skilled in the art based on the embodiments described in this application, without creative efforts, fall within the scope of protection of the present invention.

[0048] According to embodiments of the present invention, a method for remote diagnostics and debugging is provided. It should be noted that the steps shown in the flow charts in the drawings can be executed on a computer system, such as a computer with a set of computer-executable instructions. Furthermore, although the flow charts show a logical sequence, under certain circumstances, the steps shown or described may be performed in an order different from that shown herein.

[0049] Embodiments of the present invention provide a method for remotely diagnosing and debugging a vehicle, which is applied to a remote diagnosis and debugging system for a vehicle. As shown in FIG. 1, the remote diagnosis and debugging system for a vehicle provided by embodiments of the present invention comprises a vehicle and a cloud platform. A vehicle-side debugging center is provided on the vehicle side, and a cloud debugging center is provided on the cloud platform. The vehicle-side debugging center and the cloud debugging center are software modules configured to exchange data with each other over a public network. For example, the vehicle-side debugging center and the cloud debugging center can exchange data with each other over a public network and transmit data via a T-Box.The cloud debugging center is primarily designed to interact with operations and maintenance personnel and verify their identities. It also serves as the coordination center for establishing and disabling debugging tunnels on the cloud platform. The vehicle-side debugging center is also designed to facilitate interaction between the vehicle and users.

[0050] Furthermore, a debugging center is provided for each debuggable part in the vehicle system. In FIG. 1, a QNX part, a TBOX part, and an EDC part are shown as an example, and each debuggable part is separately provided with a debugging center for the part configured to enable, configure, and disable a tunnel client on the vehicle side and debugging services such as SSH and ADB. In addition, a tunnel client is provided for each part in the vehicle system on the vehicle side, and a cloud tunnel center is provided on the cloud platform. The cloud tunnel center is a server configured to establish a tunnel to penetrate the internal network, and the tunnel client on the vehicle side is a client configured to establish a tunnel to penetrate the internal network.For example, a cloud tunnel center can use a fast reverse proxy server (FRPS), a network policy server (NPS), etc. A tunnel client on the vehicle side can use a fast reverse proxy server (FRPS), a network policy server (NPS), etc. The vehicle parts are called over the internal network, viewed, diagnosed, and debugged by the cloud platform on the external network through a tunnel to penetrate the internal network.

[0051] Based on the above system, when a user requires an engineer to remotely debug a part in a vehicle, the vehicle-side debug center can send a debugging request to the cloud debug center. The cloud debug center then enables the cloud tunnel center. The vehicle then enables the corresponding vehicle-side tunnel client and executes a debugging service program, such as Secure Shell (SSH) or Android Debug Bridge (ADB), through the debug center of the part to be debugged to establish a tunnel to penetrate the internal network through the vehicle-side tunnel client and the cloud tunnel center, both of which are already enabled. The engineer can then remotely debug the specified part based on the established tunnel to penetrate the internal network.The tunnel for penetrating the internal network does not require protocol conversion between the public network and CAN, reducing the complexity of developing a remote debugging program. Furthermore, the present invention enables the establishment of a debugging tunnel for remote debugging of the specified component using conventional tunneling tools, such as FRP or NPS, without the need for additional development for vehicle components. This has the advantage of being more easily deployed than prior art remote debugging methods, while reducing the cost of developing the remote debugging system.

[0052] Furthermore, the remote diagnosis and debugging method provided by the embodiments of the present invention based on the above-mentioned system can further improve the security of remote debugging. As shown in FIG. 2, the remote diagnosis and debugging method provided by the embodiments of the present invention comprises steps S101-S105 and steps S201-S206, wherein steps S101-S105 are applied to a vehicle, and steps S201-S206 are applied to a cloud platform. Specific process steps are as follows:

[0053] Step S101: Sending the information of the part to be debugged from the vehicle-side debugging center to the cloud debugging center.

[0054] Step S201: Receiving the information of the part to be debugged sent by the vehicle-side debugging center by the cloud debugging center.

[0055] Step S202: In response to the information about the part to be debugged, the cloud debugging center requests tunnel connection information from the cloud tunnel center.

[0056] Step S203: Sending tunnel connection information to the vehicle-side debugging center by the cloud debugging center.

[0057] Step S102: Receiving the tunnel connection information returned by the cloud debugging center by the vehicle-side debugging center.

[0058] Step S103: The debugging center on the vehicle side forwards the tunnel connection information to the part debugging center of the part to be debugged.

[0059] Step S104: The target vehicle-side tunnel client is turned on by the target part debugging center, and the target vehicle-side tunnel client requests a debug tunnel from the cloud tunnel center containing the tunnel connection information.

[0060] Step S204: The cloud tunnel center receives the tunnel connection information sent by the target tunnel client on the vehicle side and checks the tunnel connection information.

[0061] Step S205: After the tunnel connection information is successfully verified, the cloud tunnel center establishes a debugging tunnel.

[0062] Step S206: Send a remote debugging instruction generated based on the information of the part to be debugged through the debugging channel to the target tunnel client on the vehicle side.

[0063] Step S 105: The target tunnel client on the vehicle side receives a remote debugging instruction sent by the cloud platform based on the information of the part to be debugged, and debugs the part to be debugged according to the remote debugging instruction.

[0064] In particular, in an embodiment of the present invention, when a user requires an engineer to remotely debug one or more parts of a vehicle, information about the part to be debugged is first sent to the cloud platform via a shared user network. The cloud platform then uses the received information about the part to be debugged to request tunnel connection information from the cloud tunnel center and then returns the tunnel connection information to the vehicle. The vehicle then requests a tunnel to penetrate the internal network from the cloud tunnel center via a tunnel client located on the vehicle side for the part to be debugged, which contains the tunnel connection information.The cloud tunnel center establishes a debug tunnel only after successfully decrypting and verifying the tunnel connection information, enabling the use of an encryption mechanism in the debug tunnel and ensuring the security of the debug tunnel. Finally, the cloud tunnel center initiates debug commands, such as SSH login, ADB login, debugging a part, and the like, over the debug tunnel. The present invention enables debug tunnel establishment using conventional tunnel creation tools, such as FRP or NPS, without the need for additional development for vehicle parts. This approach offers the advantage of being more easily deployed than prior art remote debugging methods, while reducing remote debugging development costs.

[0065] Furthermore, in some optional embodiments, the tunnel connection information comprises a tunnel connection code and information for verifying the authenticity of the tunnel identification data.

[0066] In particular, the tunnel connection information provided by embodiments of the present invention comprises a tunnel connection code and tunnel identity authentication information. The tunnel connection code is configured to pair a vehicle-side tunnel client with a cloud tunnel center to establish a debugging channel. The tunnel identity authentication information is configured to enable the cloud tunnel center to verify that the tunnel connection code sent by the vehicle-side tunnel client is the same as the code previously sent by the cloud platform and not a tunnel connection code sent by a hacker attempting to carry out an attack, thereby further ensuring tunnel security.

[0067] In some optional embodiments, the information about the part to be debugged sent by the vehicle-side debug center to the cloud debug center contains attribute information about the part to be debugged and a diagnostic debug code, wherein the attribute information about the part to be debugged is configured to describe the part to be debugged, for example, the part to be debugged is described as a QNX part, a TBOX part, or an EDC part. After the diagnostic debug code, which serves as a verification code, is sent to the cloud debug center, the cloud debug center returns both the diagnostic debug code and the tunnel connection information to the vehicle-side debug center, so that the vehicle-side debug center, after receiving the diagnostic debug code, decrypts it and checks whether the received diagnostic debug code matches the sent diagnostic debug code.If the received debugging diagnostic code does not match the sent debugging diagnostic code, this indicates that the tunnel connection information received by the vehicle-side debugging center may be malicious attack data. After this, the vehicle refuses to perform subsequent debugging tunnel establishment steps, further enhancing the security of remote vehicle debugging.

[0068] Furthermore, in some optional embodiments, if the diagnostic debug code check passes, the vehicle-side debugging center prompts the vehicle user to reconfirm the part to be debugged via a pop-up window on the vehicle's on-board display. After the user consents by clicking the button in the pop-up window on the vehicle's on-board display, the vehicle-side debugging center forwards the tunnel connection information to the part's debugging center. By adding user permission, the security of remote vehicle debugging is further enhanced.

[0069] Furthermore, in some optional implementations, when the vehicle-side debug center and the part debug center communicate with each other, two-way certificate-based authentication is required. This means that the part debug center stores the vehicle-side debug center's certificate, and the vehicle-side debug center stores the part debug center's certificate. This two-way authentication is accomplished by exchanging certificates and verifying that the received certificate matches the previously stored certificate. Only after identity authentication has been completed does the part debug center enable the vehicle-side tunnel client and execute debugging services such as SSH and ADB, further enhancing the security of remote debugging.

[0070] It should be noted that the vehicle-side debugging center can send the attribute information of the part to be debugged and the diagnostic debug code to the cloud debugging center in two ways: either the vehicle-side debugging center directly sends them to the cloud debugging center, or the vehicle user first generates the corresponding attribute information of the part to be debugged and the diagnostic debug code using the vehicle-side debugging center in the vehicle, and then sends the attribute information of the part to be debugged and the diagnostic debug code via SMS, telephone, network messaging, etc. to the engineer's client (such as the engineer's mobile phone or personal computer), after which the engineer manually enters the received attribute information of the part to be debugged and the received diagnostic debug code into the cloud debugging center.Before the engineer manually enters the received attribute information of the part to be debugged and the received diagnostic debug code into the cloud debug center, the engineer's identity can be verified, and the engineer is only allowed to perform the input after the verification is successful, which reduces the risk of information theft or unauthorized access during the direct transmission of the information of the part to be debugged from the debug center on the vehicle side to the cloud debug center, and thereby further improves the security of remote diagnosis and debugging.

[0071] In some optional embodiments, the diagnostic debug code is generated as follows:

[0072] Step a1: Calculate and obtain a hash value using the current timestamp, the unique vehicle identifier, and the screen coordinates, where the screen coordinates are the coordinates of the location on the screen on the side of the vehicle where the user clicks when generating the diagnostic debug code.

[0073] Step a2: Randomly extract a data value of a specified bit length from the hash value to generate a debug diagnostic code.

[0074] Specifically, in the embodiments of the present invention, when generating a diagnostic debug code, the user clicks on the interactive interface of the vehicle-side debug center to initiate the diagnostic debug code generation command. The vehicle-side debug center then calculates and obtains a hash value (e.g., 32 bits) using the current timestamp, vehicle identification number, and the coordinates of the location on the screen where the user clicks, and randomly allocates a data value of a predetermined bit length (e.g., 10 bits) to generate the diagnostic debug code. The algorithm formula is as follows:

[0075] Diagnostic debug code = RANDOM(HASH(Vehicle Identification Number + Current Timestamp + Screen Coordinates), Specified Number of Bits).

[0076] Compared with the method for generating conventional verification codes, the diagnostic debug code provided by the embodiments of the present invention additionally inputs the coordinates of a click on the screen. Since the start button is an area with a range of coordinates, and the process of a vehicle user specifying coordinates on the screen by clicking is largely random, the random verification code generated in this way has a higher degree of randomness, is more resistant to hacking, and provides higher security than conventional random verification codes currently on the market.

[0077] In some optional embodiments, step S202 includes:

[0078] Step e1: Check whether the IP information of the cloud debugging center is included in the pre-stored IP information when the cloud tunnel center receives the request message sent by the cloud debugging center.

[0079] Step e2: Perform two-way certificate-based authentication on the cloud debugging center by the cloud tunnel center if the IP information is included in the pre-stored IP information.

[0080] Step e3: Check the account and password sent by the cloud debugging center by the cloud tunnel center if the two-way certificate-based authentication passes.

[0081] Step e4: Send tunnel connection information from cloud tunnel center to cloud debug center in response to the request message if the account and password verification passes.

[0082] In particular, in the embodiments of the present invention, when a cloud debugging center requests tunnel connection information from a cloud tunneling center, a minimum virtual domain is established for the cloud tunneling center to verify the cloud debugging center by determining a range of IP addresses. A range of IP addresses accessible to the cloud tunneling center is determined, wherein the accessible range of IP addresses corresponds to some or all of the cloud debugging centers. In this case, security within the domain is ensured through both certificate-based authentication and account and password authentication (the steps of the two-way certificate-based authentication are the same as in the embodiments described above and are not repeated here).Only after the cloud debug center is authenticated in the above manner, the tunnel connection information is sent by the cloud tunnel center to the cloud debug center in response to the request message, which prevents damage due to the situation in which the tunnel connection information request message is sent by hackers, and, compared with conventional token authentication methods, prevents the risk of malicious access due to token leakage.

[0083] Furthermore, in some optional embodiments, the verification described in steps e1-e3 is performed during each interaction between the cloud debugging center and the cloud tunnel center, significantly enhancing the security of remote vehicle debugging. Similarly, the identity verification described in steps e1-e3 may also be performed during each interaction between the vehicle-side tunnel client and the cloud tunnel center.

[0084] In some optional embodiments, after the debug center on the vehicle side verifies that the received diagnostic debug code matches the sent diagnostic debug code, the method further includes:

[0085] Step c1: Disable the local USB debugging mechanism and clear the debug diagnostic code by the debug center on the vehicle side.

[0086] In particular, in the embodiments of the present invention, by disabling the local USB debugging mechanism and destroying the debugging diagnostic code, it is possible to more effectively prevent malicious users from accessing the tunnel to attack the cloud platform compared with conventional remote debugging and offline debugging mechanisms, thereby improving the security of remote diagnosis and debugging of the vehicle.

[0087] In the embodiment of the specific application scenario as shown in FIGS. 3 and 4, the complete list of steps for setting up a debugging tunnel provided by the technical solution of the embodiments of the present invention is as follows:

[0088] 1. The user reports the problem to the engineer via the customer or vehicle.

[0089] 2. The user, under the guidance of the engineer, performs operations on the interactive interface of the debugging center on the vehicle side in the vehicle to generate a one-time debugging diagnostic code, which is valid for 10 minutes, and information about the part to be debugged.

[0090] 3. The user sends the debug diagnostic code and the information of the part to be debugged to the engineer's client via the terminal on the vehicle or client side.

[0091] 4. The engineer logs into the cloud debugging center. After passing identity verification, the engineer enters the debugging diagnostic code and information about the part to be debugged into the cloud debugging center.

[0092] 5. After receiving the debug diagnostic code and the information of the part to be debugged, the cloud debug center requests the tunnel connection information from the cloud tunnel center.

[0093] 6. After all checks—IP address verification, two-way certificate-based authentication, and cloud debugging center account and password verification—are successfully completed, the cloud tunneling center sends tunnel connection information to the cloud debugging center. The tunnel connection information contains a one-time tunnel channel code valid for 10 minutes and tunnel identity authentication information.

[0094] 7. After confirming the receipt of the tunnel connection information, the cloud debugging center packages and encrypts the configuration information, including the tunnel connection information, debug diagnostic code, and certain certificates, and sends the packaged and encrypted configuration information via the T-Box over the public network to the debugging center on the vehicle side.

[0095] 8. The vehicle-side debug center decrypts the received packaged and encrypted configuration information and performs authentication verification of the cloud debug center identity using verification methods such as certificate-based two-way authentication, debug diagnostic code verification, etc.

[0096] 9. After the identity authentication is passed, an authentication confirmation window will pop up on the vehicle-side debugging center interface, and the user can manually allow remote debugging.

[0097] 10. After the user manually enables remote debugging, the vehicle-side debug center sends tunnel connection information to the part debug center corresponding to the part to be debugged.

[0098] 11. The debug center of the part similarly checks the debug center on the vehicle side using verification methods such as IP address verification, two-way certificate-based authentication, account and password verification, etc. After successful verification, the corresponding tunnel client on the user side is enabled and the corresponding debugging services, such as SSH and ADB, are launched.

[0099] 12. The debug center part disables the local USB debugging mechanism and clears the debug diagnostic code.

[0100] 13. The tunnel client on the vehicle side sends a request message containing the encrypted tunnel connection information provided by the part debug center to the cloud tunnel center to request the establishment of a debug tunnel.

[0101] 14. The cloud tunnel center decrypts the tunnel connection information and verifies the tunnel connection information, including performing two-way certificate-based authentication, tunnel channel code authentication, and channel identity authentication information verification.

[0102] 15. After successful verification, the cloud tunnel center establishes a tunnel to penetrate the internal network to exchange data with the tunnel client on the vehicle side and destroys the tunnel channel code in the tunnel connection information.

[0103] In some optional embodiments, step S206 includes:

[0104] Stage f1: Audit remote debugging instruction based on instruction whitelist and parameter whitelist.

[0105] Step f2: Refuse to send remote debugging instruction if the audit result is negative.

[0106] Step f3: Send remote debugging instruction if the audit result is positive.

[0107] In particular, as shown in FIG. 5, in the embodiments of the present invention, before the cloud tunnel center sends a remote debugging instruction, the remote debugging instruction is audited based on the instruction whitelist and parameter whitelist stored in the cloud debugging center. Only instructions with a positive audit result are sent, which further prevents malicious debugging by internal engineers and thereby improves the security of remote debugging of the vehicle.

[0108] In some optional embodiments, step S105 includes:

[0109] Stage b1: Receive remote debugging instruction and audit remote debugging instruction based on the instruction whitelist and parameter whitelist.

[0110] Step b2: Refuse to debug the part to be debugged according to the remote debugging instruction if the audit fails.

[0111] Step b3: Perform the debugging step of the part to be debugged according to the remote debugging instruction if the audit result is positive.

[0112] Specifically, in embodiments of the present invention, an instruction whitelist and a parameter whitelist are also provided in the debugging center of the vehicle part. Before the vehicle performs remote debugging according to a remote debugging instruction sent by the cloud platform, the remote debugging instruction is audited against the instruction whitelist and parameter whitelist to determine whether the remote debugging instruction is genuine or not. Only instructions with a positive audit result are executed for remote debugging, and instructions with a negative audit result are not executed for subsequent debugging stages. This further prevents internal engineers from entering malicious debugging instructions that could damage the vehicle, thereby solving the internal security issue.

[0113] In some optional embodiments, the vehicle further performs the following steps:

[0114] Step d1: The target part debug center turns off the target vehicle-side tunnel client and destroys the tunnel connection information and debug diagnostic code to close the debug tunnel when the cloud tunnel center detects that the debug tunnel does not transmit data for longer than the specified duration.

[0115] In particular, in the embodiments of the present invention, by installing a debug tunnel closure mechanism, when the cloud tunnel center detects that the debug tunnel has not transmitted data for longer than a predetermined period of time, the user, in order to prevent an unfavorable development of the situation, turns off the target tunnel client on the vehicle side through the target part debug center and destroys the tunnel connection information and the debug diagnostic code, so that the debug tunnel is automatically closed after a long period of time without transmitting data, which reduces the consumption of communication resources, on the one hand, and also prevents malicious use of the debug tunnel, on the other hand, thereby implementing a circuit for automatically exiting the debug tunnel.

[0116] In some optional embodiments, the cloud platform also performs steps g1-g3, and the vehicle performs step g4. The specific steps are as follows:

[0117] Step g1: The cloud debug center sends a logout message to the cloud tunnel center.

[0118] Stage g2: In response to the exit message, close the debug tunnel and destroy the tunnel connection information by the cloud tunnel center.

[0119] Step g3: The cloud debugging center destroys the tunnel connection information and sends an exit command to the vehicle-side debugging center.

[0120] Step g4: The vehicle-side debug center forwards the exit command to the target part debug center, so that the target part debug center can shut down the target tunnel client and destroy the tunnel connection information.

[0121] In particular, as shown in FIG. 6, embodiments of the present invention provide an exit scheme in which the cloud platform exits the debug tunnel to prevent an unfavorable situation. An exit message is sent from the cloud debug center to the cloud tunnel center, and the cloud debug center sends an exit command to the vehicle-side debug center so that the cloud tunnel center and the target part debug center can close the debug tunnel, thereby improving the flexibility of remote debugging and diagnostic management.

[0122] Furthermore, in some optional embodiments, the cloud debug center periodically detects inactive tunnels that do not transmit data for longer than a specified duration of time through the cloud tunnel center to send exit commands to automatically exit the inactive tunnels.

[0123] The present invention also provides a computer-readable storage medium. The methods described above according to the embodiments of the present invention may be implemented in hardware or firmware, or may be implemented in the form of computer code that can be downloaded via a network from a remote storage medium or a physical computer-readable storage medium and subsequently stored on a local storage medium. Thus, the described method can be stored in the form of software on a storage medium using a general-purpose computer, a specialized processor, or programmable or specially designed hardware. In this case, the storage medium may comprise magnetic disks, optical disks, read-only memory, random access memory, flash memory, hard drives, solid-state drives, etc.; optionally, the storage medium may also contain combinations of storage devices of the above-mentioned types. It is understood that a computer, processor, microprocessor, controller, or programmable hardware includes a storage device configured to store or receive software or computer code, and when accessing the software or computer code and executing them by the computer, processor, or hardware, the method illustrated in the above-described embodiments is implemented.

[0124] Although embodiments of the present invention have been described with reference to the accompanying drawings, various modifications and changes can be made by those skilled in the art within the spirit and scope of the present invention, and such modifications and changes fall within the scope of legal protection defined by the appended claims.

Claims

1. A method for remote diagnostics and debugging of a vehicle, characterized in that it is applied to a vehicle and includes: sending information about the part to be debugged by the debugging center on the vehicle side to the cloud debugging center, so that the cloud debugging center, in response to the information about the part to be debugged, requests information about a tunnel connection from the cloud tunnel center on the cloud platform, wherein the debugging center on the vehicle side and the cloud debugging center located on the cloud platform are software modules configured to exchange data with each other over a public network, and the cloud tunnel center is a server configured to establish a tunnel to penetrate the internal network; receiving the tunnel connection information returned by the cloud debugging center by the vehicle-side debugging center; forwarding information about the tunnel connection by the debugging center on the vehicle side to the target debugging center of the part of the part to be debugged, wherein each debuggable part in the vehicle is provided with a debugging center of the part configured to control the switching on and off of a tunnel client on the vehicle side corresponding to each debuggable part, and the tunnel client on the vehicle side is a client configured to establish a tunnel for penetrating the internal network; enabling the target vehicle-side tunnel client by the target part debugging center and requesting a debug tunnel from the cloud tunnel center by the target vehicle-side tunnel client, so that after successfully checking the tunnel connection information, the cloud tunnel center establishes the debug tunnel; and receiving a remote debugging instruction sent by the cloud platform based on the information of the part to be debugged by the target tunnel client on the vehicle side, and debugging the part to be debugged according to the remote debugging instruction.

2. The method according to claim 1, characterized in that the information about the part to be debugged contains information about an attribute of the part to be debugged and a diagnostic debug code, wherein the information about the attribute of the part to be debugged is configured to describe the part to be debugged, and the diagnostic debug code is configured to be returned by the cloud debug center to the debug center on the vehicle side together with information about the tunnel connection, so that the debug center on the vehicle side checks whether the received diagnostic debug code matches the sent diagnostic debug code.

3. The method according to paragraph 2, characterized in that the diagnostic debug code is generated as follows: calculating and obtaining a hash value using the current timestamp, the unique identifier of the vehicle and the screen coordinates, wherein the screen coordinates are the coordinates of the location on the screen on the side of the vehicle where the user clicks when generating the diagnostic debug code; and randomly extracting a data value of a given bit length from the hash value to generate diagnostic debug code.

4. The method according to claim 1, characterized in that the information about the tunnel connection contains a tunnel connection code and information for verifying the authenticity of the tunnel identification data.

5. The method according to paragraph 1, characterized in that the step of receiving an instruction for remote processing sent by the cloud platform based on information about the part to be debugged by the target tunnel client on the vehicle side includes: Receiving remote debugging instruction and auditing remote debugging instruction based on instruction whitelist and parameter whitelist; failure to debug the debuggable part in accordance with the remote debugging instruction if the audit fails; and Performing the debugging phase of the part to be debugged in accordance with the remote debugging instruction if the audit result is positive.

6. The method according to paragraph 2, characterized in that the method additionally includes: Shutting down the target tunnel client on the vehicle side by the target part debug center and destroying the tunnel connection information and the debug diagnostic code to close the debug tunnel when the cloud tunnel center detects that the debug tunnel does not transmit data for longer than a specified duration.

7. The method according to paragraph 2, characterized in that, after the debugging center on the vehicle side checks that the received diagnostic debug code matches the sent diagnostic debug code, the method further includes: Disabling the local USB debugging mechanism and clearing the debug diagnostic code by the vehicle-side debugging center.

8. A method for remote diagnostics and debugging of a vehicle, characterized in that it is applied to a cloud platform and includes: receiving information about a part to be debugged, sent by a debugging center on the vehicle side, by a cloud debugging center, wherein the debugging center on the vehicle side and the cloud debugging center are software modules configured to exchange data with each other over a public network, and the debugging center on the vehicle side is located on the vehicle; a request, in response to information about the part to be debugged, for information about a tunnel connection from a cloud tunnel center by a cloud debug center, wherein the cloud tunnel center is a server located on a cloud platform and configured to establish a tunnel for penetrating an internal network; sending tunnel connection information to a vehicle-side debugging center by a cloud debugging center, so that the vehicle-side debugging center forwards the tunnel connection information to a target part debugging center of the part to be debugged, in order to allow the target part debugging center to turn on a target vehicle-side tunnel client, wherein each debuggable part in the vehicle is provided with a part debugging center configured to control turning on and off a vehicle-side tunnel client corresponding to each debuggable part, and the vehicle-side tunnel client is a client configured to establish a tunnel for penetrating an internal network; receiving tunnel connection information sent by the target tunnel client on the vehicle side, the cloud tunnel center, and checking the tunnel connection information; establishing, after successful verification of the tunnel connection information, a debugging tunnel by the cloud tunnel center; and sending a remote debugging instruction generated based on the information about the part to be debugged through the debugging tunnel to the target tunnel client on the vehicle side, so that the vehicle debugs the part to be debugged according to the remote debugging instruction.

9. The method according to paragraph 8, characterized in that the step of requesting, in response to information about the part to be debugged, information about the tunnel connection from the cloud tunnel center by the cloud debugging center includes: checking whether the IP information of the cloud debug center is included in the pre-stored IP information when the cloud tunnel center receives a request message sent by the cloud debug center; Performing two-way certificate-based authentication on the cloud debugging center by the cloud tunneling center if the IP information is included in the pre-stored IP information; verifying the account and password sent by the Cloud Debugging Center by the Cloud Tunneling Center if the two-way certificate-based authentication has passed; and sending tunnel connection information from the cloud tunnel center to the cloud debug center in response to a request message if the account and password verification was successful.

10. The method according to paragraph 8, characterized in that the step of sending a remote debugging instruction generated on the basis of information about the part to be debugged, via the debugging channel to the target tunnel client on the vehicle side includes: Remote debugging instruction audit based on instruction whitelist and parameter whitelist; refusing to send a remote debugging instruction if the audit result is negative; and sending remote debugging instructions if the audit result is positive.

11. The method according to paragraph 8, characterized in that the method additionally includes: sending an exit message from the cloud debugging center to the cloud tunneling center; closing, in response to the exit message, the debug tunnel and destroying the tunnel connection information by the cloud tunnel center; and destroying the tunnel connection information by the cloud debugging center and sending a logout command to the vehicle-side debugging center, so that the vehicle-side debugging center forwards the logout command to the target part debugging center to allow the target part debugging center to shut down the target vehicle-side tunnel client and destroy the tunnel connection information.

12. A system for remote diagnostics and debugging of a vehicle, characterized in that it comprises a vehicle and a cloud platform, wherein: the vehicle is configured to send information about the part to be debugged via a debugging center on the vehicle side to a cloud debugging center on a cloud platform, wherein the debugging center on the vehicle side and the cloud debugging center are software modules configured to exchange data with each other over a public network; the cloud platform is configured to request, in response to information about the part to be debugged, information about the tunnel connection from the cloud tunnel center by the cloud debugging center, wherein the cloud tunnel center is a server located on the cloud platform and configured to establish a tunnel for penetrating the internal network; the cloud platform is configured to send information about the tunnel connection to the debugging center on the vehicle side via the cloud debugging center; the vehicle is configured to transmit tunnel connection information by a debugging center on the vehicle side to a target debugging center of a part of the part to be debugged, wherein each part in the vehicle configured to be debugged is provided with a debugging center of a part configured to control the switching on and off of a tunnel client on the vehicle side corresponding to each part configured to be debugged, and the tunnel client on the vehicle side is a client configured to establish a tunnel for penetrating an internal network; the vehicle is configured to include a target tunnel client on the vehicle side via a target part debugging center; the vehicle is configured to send tunnel connection information to the cloud tunnel center via a tunnel client on the vehicle side; the cloud platform is configured to check the tunnel connection information through the cloud tunnel center and, after successfully checking the tunnel connection information, establish a debug tunnel; the cloud platform is configured to send a remote debugging instruction generated based on the information about the part to be debugged via a debugging channel to a target tunnel client on the vehicle side; and the vehicle is configured to allow debugging of the part to be debugged in accordance with the remote debugging instruction.