An information security testing method and system for an in-vehicle information interaction system
By establishing a remote information security testing system in the on-board information interaction system, the existing testing methods are solved, efficient and secure information security testing is achieved, and the overall security of the on-board system is improved.
Patent Information
- Application Number
- CN202210713509.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-22
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-06-22
AI Technical Summary
The existing safety testing methods are inefficient, easily cause damage to the vehicle system, and it is difficult to effectively test the information security of the on-board information interaction system.
Provides a method and system for information security testing of vehicle information interaction systems, collects test task information through human-computer interaction interface, uses simulation simulation module to download the firmware to be tested and builds a simulated running environment in the virtual machine, automatically conducts tests, and generates a test report.
The remote testing system isolates the dangers of local testing, improves testing efficiency and personalization, improves the overall security of the on-board interactive system, and eliminates irregular user behavior during the test.
Smart Images

Figure CN115185823B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the technical field of information security testing, and in particular, to a method and system for information security testing of an in-vehicle information interaction system. Background Art
[0002] Currently, with the development and popularization of intelligent connected vehicle technology, the intelligent level of automobiles has been continuously improved. The understanding of automobile safety can no longer be limited to ensuring the functional safety of traditional automobiles. More and more malicious attackers have started to target intelligent connected vehicles.
[0003] Due to the particularity of automobiles as manned transportation equipment, automobile information security is closely related to functional safety. The breach of a certain link not only means the theft of user data and the leakage of information, but also may directly lead to the control of the in-vehicle bus network and the imitation of in-vehicle information, thus threatening the safety of passengers themselves.
[0004] Existing security testing methods generally conduct tests directly on the in-vehicle infotainment system (IVI), such as injecting faults into the IVI system to test whether the IVI can start normally. This testing method is inefficient and easily damages the IVI system. Summary of the Invention
[0005] The present invention provides a method and system for information security testing of an in-vehicle information interaction system, which is used to remotely test the security of the IVI firmware, reduce manual operations through an automated process, and complete the test without the need for testers to know the underlying mechanism.
[0006] In a first aspect, the present invention provides an information security testing system for an in-vehicle information interaction system, including:
[0007] A human-machine interaction interface for collecting information of a test task in response to a user's operation, where the information of the test task at least includes test cases;
[0008] A simulation module for downloading the firmware under test to the local from the firmware under test through a communication link with the IVI to be tested; and building a simulated operating environment of the firmware under test in a local virtual machine according to the information of the firmware under test;
[0009] A testing module for automatically testing the firmware under test according to the test cases in the simulated operating environment;
[0010] A report generation module for automatically generating a test report according to the test results.
[0011] In a second aspect, the present invention provides a method for information security testing of an in-vehicle information interaction system, including:
[0012] Collect information of a test task in response to an operation of a user on a human - machine interaction interface, where the information of the test task includes at least test cases;
[0013] Download the firmware under test from the vehicle unit under test to the local through a communication link with the vehicle unit under test; build a simulated running environment of the firmware under test in a local virtual machine according to the information of the firmware under test;
[0014] Automatically test the firmware under test according to the test cases in the simulated running environment;
[0015] Automatically generate a test report according to the test results.
[0016] By establishing an information security test system for a remote vehicle - to - everything system, the present invention effectively isolates the risks of local system testing. At the same time, through comprehensive systematic testing, it improves the efficiency and personalization of the test process, and enhances the overall security of the vehicle - to - vehicle interaction system. Through a highly automated test process, irregular behaviors of users during the test are eliminated. Brief Description of the Drawings
[0017] In order to more clearly illustrate the technical solutions in the present invention or related technologies, the following will briefly introduce the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings in the following description are only embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0018] Figure 1 It is a schematic structural diagram of an information security test system for a vehicle - to - vehicle interaction system provided by an embodiment of the present invention;
[0019] Figure 2 It is a schematic flowchart of an information security test method for a vehicle - to - vehicle interaction system provided by an embodiment of the present invention. Detailed Embodiments
[0020] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the following further elaborates on the present invention in detail with reference to specific embodiments and the accompanying drawings.
[0021] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present invention should have the ordinary meanings understood by those with ordinary skills in the field to which the present invention belongs. The "first", "second" and similar terms used in the embodiments of the present invention do not indicate any order, quantity or importance, but are only used to distinguish different components. Words such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. Words such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect.
[0022] An information security testing system for an in-vehicle information interaction system according to an embodiment of the present invention is used to perform security testing on firmware (such as startup files, system files, etc.) in a vehicle head unit system. Among them, the in-vehicle information interaction system includes Android and Linux systems. The test scenarios of the vehicle head unit to be tested include:
[0023] 1) The vehicle-integrated environment is used to perform information security testing on the remote in-vehicle information interaction system (T-Box), the in-vehicle integrated information processing system (IVI), and their hybrids in the vehicle-integrated environment.
[0024] 2) The in-vehicle information interaction system component test scenario is used to perform information security testing on components of the remote in-vehicle information interaction system (T-Box), the in-vehicle integrated information processing system (IVI), and their hybrids.
[0025] 3) The system file test scenario of the in-vehicle information interaction system is used to perform information security testing on system files extracted from the remote in-vehicle information interaction system (T-Box), the in-vehicle integrated information processing system (IVI), and their hybrids in the vehicle-integrated environment.
[0026] The structure diagram of this system is shown in Figure 1 , and includes: a human-machine interaction interface, a simulation module, a test module, and a report generation module. The specific functions of each part are introduced below.
[0027] The human-machine interaction interface is used to collect information of a test task in response to a user's operation, and the information of the test task includes at least test cases.
[0028] In a specific embodiment, the user creates a test project on the human-machine interaction interface, adds a test task under this project, and selects to collect information of this test task, including at least test cases. Optionally, the information of the test task further includes a login method, a login port, a username, a password, a task name, a test time, and the user's physiological signals: a heartbeat signal and a pulse signal.
[0029] The simulation module is used to download the firmware under test to the local through the communication link with the vehicle head unit under test; and build a simulated running environment of the firmware under test in the local virtual machine according to the information of the firmware under test. Optionally, the simulation module includes a communication unit, an encryption and decryption unit, and a simulation unit.
[0030] Among them, the communication unit is used to build a communication link with the vehicle head unit under test; the communication link can be in a wired form or a wireless form, and the ports for logging in to the vehicle head unit include adb, ftp, ssh, telnet, and serial, etc. The encryption and decryption unit is used to generate an encryption key and a decryption key according to the task name, the test time, and the physiological signal of the user; access the vehicle head unit under test through the communication link with the vehicle head unit under test, and encrypt the firmware under test with the encryption key. Among them, the user can remotely log in to the vehicle head unit to encrypt and package the firmware, or automatically encrypt and package the firmware through a script. Send the encrypted firmware under test to the local, and decrypt it with the decryption key to obtain the firmware under test. If the firmware under test is packaged, it also needs to be decompressed. The following details the generation process of the encryption key and the decryption key:
[0031] Pre - operation: Denoise the pulse signal and the heartbeat signal; extract the features of the pulse signal and the features of the heartbeat signal. The features include the main wave peak value of the signal and the corresponding time.
[0032] The first step: Generate a first binary random number sequence according to the features of the pulse signal, and generate a second binary random number sequence according to the first binary random number sequence and the features of the heartbeat signal;
[0033] T1' = T1(n + 1)-T1(n)
[0034] T1”(n)=T1'(n + 1)-T1'(n)
[0035] Among them, n is the serial number of the main wave peak, T1(n) represents the time coordinate sequence of the main wave peak of the pulse signal, T1'(n) represents the time interval sequence between two adjacent main wave peaks, and T1”(n) represents the difference in the main wave peak time interval, that is, the pulse sequence I;
[0036]
[0037] Among them, I j represents the j - th value in the pulse sequence, is a bit. When j traverses from 1 to n, a first binary random number sequence S = {S1, S2, S3,...} is obtained.
[0038] Obtain the last 3 decimal places of the main wave peak value of the heartbeat signal, expand it by 1000 times, and convert the time points of the collected heartbeat signal into integers with the unit of seconds. The processed main wave peak value and time point value form a one-dimensional feature vector. In this way, multiple one-dimensional feature vectors can be obtained at multiple acquisition moments. Concatenate multiple one-dimensional feature vectors to form a positive integer sequence, and convert each value in the positive integer sequence into a binary sequence to obtain the heartbeat sequence Q.
[0039] Perform a sum or exclusive OR calculation on the first binary random number sequence S and the heartbeat sequence Q to obtain the second binary random number sequence Y.
[0040] Second step: Concatenate the second binary random number sequence with the binary representations of the task name and test time, and convert the concatenated result into an unsigned integer to obtain the encryption key and decryption key.
[0041] Among them, the task name can be represented by a number. Convert both the task name and test time into binary representations, and then concatenate them with the second binary random number sequence Y to obtain the key sequence. Take every 8 of the key sequence as a byte and convert it into an unsigned integer as the encryption key, and also as the decryption key.
[0042] The simulation unit is used to build a simulated operating environment of the firmware under test in a local virtual machine according to the information of the firmware under test.
[0043] Optionally, the in-vehicle information interaction system information security test system deploys multiple virtual machines, and each virtual machine is used to build a different simulated operating environment. The module operating environment includes the hardware environment and software environment required for the operation of the firmware under test. Exemplarily, the hardware environment information and software environment information corresponding to the information of the firmware under test are pre-stored. After obtaining the information of the firmware under test, query the corresponding hardware environment information and software environment information and deploy them on the virtual machine. When the firmware under test runs in the simulated operating environment of the virtual machine, the running effect is the same as that in the original vehicle system.
[0044] The test module is used to automatically test the firmware under test according to the test cases in the simulated operating environment.
[0045] After the user selects a test case on the human-computer interaction interface, no manual operation is required subsequently; instead, the test module automatically tests according to the selected test case.
[0046] Optionally, the test module includes a communication protocol and interface security test unit, a system security test unit, an application software security test unit, and a data security test unit. Each test unit is used to execute multiple test items (separated by semicolons), and each test item is executed by the corresponding test case. The test items of each test unit are introduced below.
[0047] A communication protocol and interface security testing unit is used to automatically perform security testing on communication protocols and interfaces according to the test cases in the simulated operating environment, including: verifying vulnerabilities in the Bluetooth and WiFi signals of the firmware under test according to a wireless protocol vulnerability database (including information on vulnerabilities in communication protocols); performing fuzz testing on communication protocols based on data packets generated by a mutation algorithm, discovering protocol vulnerabilities, and adding the discovered vulnerabilities to the wireless protocol vulnerability database.
[0048] A system security testing unit is used to automatically perform security testing on communication protocols and interfaces according to the test cases in the simulated operating environment, including: verifying system vulnerabilities in the simulated emulation environment according to a system vulnerability database (including information on system vulnerabilities); querying whether there is a plaintext key in the system files according to a key feature database (including features of plaintext keys, such as the username "username" or a combination of numbers and letters); obtaining and tampering with the secure boot code of the system firmware of the operating system, writing the tampered code to a specified area in the simulated operating environment, and checking the system operation; querying the system kernel version, analyzing and verifying the vulnerabilities existing in the current kernel version according to a kernel vulnerability database (including information on kernel vulnerabilities), and checking the status of kernel vulnerability repair.
[0049] An application software security testing unit is used to automatically perform security testing on communication protocols and interfaces according to the test cases in the simulated operating environment, including: decompiling the installation package of the application software in the vehicle information interaction system, analyzing the decompiled code according to a software reinforcement feature database (including features of reinforced application software code, such as the code having specific types of files or data), and detecting whether application software reinforcement is performed; calling internal system tools to query whether the simulated operating environment has a code security mechanism; analyzing the decompiled application software code according to an encryption algorithm feature database (including features of application software code using encryption algorithms, such as the code having an encryption algorithm name), detecting the encryption algorithm used by the application software, and querying whether there is a plaintext key; verifying application software vulnerabilities according to an application software vulnerability database (including information on application software vulnerabilities); querying the decompiled code of the application software according to an application software residual debugging information feature database (including features of debugging information in application software code, such as debugging interfaces and debugging commands), and detecting whether there is residual debugging information; and judging the security level of the software.
[0050] In a preferred embodiment, judging the security level of the software includes: obtaining the registered name of the application software and comparing it with the dangerous list in the expert database. If the application software is a non-dangerous software, the application software is executed; otherwise, the application software is frozen and the user is reminded to delete it. The dangerous list in the expert database includes a blacklist of fraudulent software.
[0051] In a preferred embodiment, the verification of application software vulnerabilities based on the application software vulnerability database includes: obtaining multi-dimensional information of the software vulnerability scanning result; inputting the multi-dimensional information into a neural network model to obtain a classification result; performing similarity analysis in the high-risk vulnerability database according to the classification result to obtain high-risk vulnerabilities, as well as repair measures and corresponding links.
[0052] Among them, the multi-dimensional information includes the vulnerability name, discovery time, version number, etc. The classification result includes viruses, Trojans, and defects, etc. The neural network model is a network used to classify features, representing the mapping relationship from multi-dimensional information to the classification result.
[0053] The training method of the neural network model includes: forming an input feature vector from the multi-dimensional information, and training the neural network model according to the feature vector and its classification result label. After obtaining the classification result, search and match the vulnerability features in the corresponding classification in the high-risk vulnerability library to determine which specific high-risk vulnerability it is. Among them, the high-risk vulnerability library stores information on high-risk vulnerabilities, as well as corresponding repair measures and links. Jumping to the link to obtain the repair file for the high-risk vulnerability.
[0054] The data security test unit is used to detect whether the simulated operating environment contains personal sensitive information stored in plain text according to the personal sensitive information feature database (including features of personal sensitive information, such as ID numbers and mobile phone numbers); detect whether there is a plain text key in the file integrated into the hardware according to the key feature database; hard coding detection.
[0055] The report generation module automatically generates a test report according to the test results.
[0056] In a specific embodiment, the report generation module is used to score the test results of each test case in each test unit; in each test unit, the scores are weighted and summed according to the weights of each test case to obtain the score of each test unit; feedback the information security level of the vehicle machine under test according to the scores of each test unit, and automatically generate a test report.
[0057] Optionally, based on the above introduction to the functions of the test unit, the test results of each test case include different types of results such as whether there are vulnerabilities, security levels, whether there is a plaintext key, and software reinforcement. According to experience, scores are given to these different types of results. Based on the analytic hierarchy process, the weights of each test case in each test unit are obtained respectively, and then the scores are weighted and summed. Construct the target layer: information security, criterion layer: communication protocol and interface security, system security, application software security, and data security, and the bottom layer: multiple test cases under each criterion layer. Through expert scoring or questionnaires, appropriate scales are determined through pairwise comparisons between various factors and a judgment matrix is constructed. Calculate the eigenvector of this judgment matrix, and after normalization, obtain the weights of each test case. Finally, according to the scores after weighted summation, they are mapped to different information security levels, such as low risk, medium risk, and high risk. The content of the test report includes the name of the test project, execution time, user, overall score, the number of vulnerabilities in each unit, detailed information about the vulnerabilities, information security level, and repair suggestions.
[0058] The embodiments of the present invention have the following technical effects:
[0059] 1. By establishing a remote simulation test system, the present invention effectively isolates the danger of local system testing. At the same time, through comprehensive systematic testing, the efficiency and personalization of the test process are improved, and the overall security of the vehicle-mounted interaction system is enhanced.
[0060] 2. By constructing a key based on heartbeat signals and pulse signals, the present invention effectively improves the security and traceability of testing, and eliminates the non-standard behaviors of testers during the testing process.
[0061] 3. Through multi-dimensional testing of software, the present invention improves the recognition of software security, software vulnerability analysis, and subsequent repair efficiency.
[0062] Figure 2 is a flowchart of a method for testing the information security of a vehicle-mounted information interaction system provided by an embodiment of the present invention, which is applied to the vehicle-mounted information interaction system information security test system provided by any of the above embodiments. The method includes the following operations:
[0063] S110. In response to an operation by a user on a human-computer interaction interface, collect information about a test task, and the information about the test task includes at least test cases.
[0064] S120. Through a communication link with the vehicle unit under test, download the firmware under test to the local; according to the information of the firmware under test, build a simulated operating environment for the firmware under test in a local virtual machine.
[0065] S130. Automatically test the firmware under test according to the test cases in the simulated operating environment.
[0066] S140. Automatically generate a test report according to the test results.
[0067] For specific operations, refer to the descriptions in the above embodiments, which will not be elaborated here.
[0068] In actual application scenarios, the information security testing method includes the following operations:
[0069] S1. Create a test project on the human-machine interaction interface, add test tasks under this project, and select to collect the basic information of this test task, including login method, login port, username, password, task name, select test cases, and user physiological signals.
[0070] S2. Establish a connection between the vehicle information interaction system and the information security detection system through the communication unit. The connection methods include wired and wireless methods, and the login ports include adb, ftp, ssh, telnet, serial, etc.
[0071] S3. The information security detection system of the vehicle information interaction system encrypts and packages the firmware of the vehicle new information interaction system through an automated script, downloads it to the local of the information security detection system, and decrypts and decompresses it; the encryption key and decryption key are automatically generated according to the task name, the task time, and the user physiological signals.
[0072] S4. Generate a simulated operating environment of the vehicle information interaction system in the virtual machine according to the system firmware extracted or the system firmware manually packaged and uploaded by the user.
[0073] S5. Perform information security testing on communication protocol and interface security, system security, application software security, and data security according to the test cases selected for the test task.
[0074] S6. Statistically analyze the test results of each test case of each detection unit, calculate the information security scores of the communication protocol and interface, system, application software, and data according to the weights of each test case, and generate a detection report.
[0075] This method has the same technical means and technical effects as the system, which will not be elaborated here.
[0076] The embodiments of the present invention are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present invention shall be included within the protection scope of the present invention.
Claims
1. An information security testing system for an in-vehicle information interaction system, characterized in that, Comprising: A human-computer interaction interface for collecting information of a test task in response to a user's operation, where the information of the test task at least includes test cases, task name, test time, and the user's physiological signals; The physiological signals include pulse signals and heartbeat signals; A simulation module for downloading the firmware under test to the local from the vehicle unit under test through a communication link with the vehicle unit under test; building a simulated running environment of the firmware under test in a local virtual machine according to the information of the firmware under test; A test module for automatically testing the firmware under test according to the test cases in the simulated running environment; A report generation module for automatically generating a test report according to the test results; The simulation module includes a communication unit, an encryption / decryption unit, and a simulation unit; The communication unit is used to build a communication link with the vehicle unit under test; The encryption / decryption unit is used to generate an encryption key and a decryption key according to the task name, test time, and the user's physiological signals; Access the vehicle unit under test through the communication link with the vehicle unit under test, encrypt the firmware under test with the encryption key; send the encrypted firmware under test to the local, and decrypt it with the decryption key to obtain the firmware under test; The simulation unit is used to build a simulated running environment of the firmware under test in a local virtual machine according to the information of the firmware under test; The generating the encryption key and the decryption key according to the task name, test time, and the user's physiological signals includes: Generating a first binary random number sequence according to the characteristics of the pulse signal, and generating a second binary random number sequence according to the first binary random number sequence and the characteristics of the heartbeat signal; Concatenating the second binary random number sequence with the binary representations of the task name and test time, and converting the concatenated result into an unsigned integer to obtain the encryption key and the decryption key.
2. The system according to claim 1, characterized in that, The test module includes a communication protocol and interface security test unit, a system security test unit, an application software security test unit, and a data security test unit; The communication protocol and interface security test unit is used to automatically perform security tests on the communication protocol and interface according to the test cases in the simulated running environment, including: verifying vulnerabilities of the Bluetooth and WiFi signals of the firmware under test according to a wireless protocol vulnerability database; performing fuzz testing on the communication protocol with data packets generated by a mutation algorithm, discovering protocol vulnerabilities, and adding the discovered vulnerabilities to the wireless protocol vulnerability database; The system security testing unit is used to automatically perform security testing on communication protocols and interfaces according to the test cases in the simulated operating environment, including: verifying system vulnerabilities in the simulation environment according to the system vulnerability database; querying whether there is a plaintext key in the system files according to the key feature database; obtaining and tampering with the secure boot code of the system firmware of the operating system, writing the tampered code into the specified area in the simulated operating environment, and checking the system running status; querying the system kernel version, analyzing the vulnerabilities existing in the current kernel version according to the kernel vulnerability database and verifying them, and checking the status of kernel vulnerability repair; The application software security testing unit is used to automatically perform security testing on communication protocols and interfaces according to the test cases in the simulated operating environment, including: decompiling the application software installation package in the vehicle information interaction system, analyzing the decompiled code according to the software hardening feature database, and detecting whether the application software is hardened; calling the internal tools of the system to query whether the simulated operating environment has a code security mechanism; analyzing the decompiled application software code according to the encryption algorithm feature database, detecting the encryption algorithm used by the application software, and querying whether there is a plaintext key; verifying application software vulnerabilities according to the application software vulnerability database; querying the decompiled code of the application software according to the application software residual debugging information feature database to detect whether there is residual debugging information; judging the security level of the software; The data security testing unit is used to detect whether the simulated operating environment contains personal sensitive information stored in plaintext according to the personal sensitive information feature database; detecting whether there is a plaintext key in the files integrated into the hardware according to the key feature database; hard-coding detection.
3. The system according to claim 2, characterized in that, The judging the security level of the software includes: Obtaining the registered name of the application software, comparing it with the dangerous list in the expert database, if the application software is a non-dangerous software, then execute the application software; otherwise, freeze the application software and remind the user to delete it; The verifying application software vulnerabilities according to the application software vulnerability database includes: Obtaining multi-dimensional information of the software vulnerability scanning results; Inputting the multi-dimensional information into a neural network model to obtain a classification result; Performing similarity analysis in the high-risk vulnerability library according to the classification result to obtain high-risk vulnerabilities, repair measures and corresponding links.
4. The system according to claim 3, wherein The wireless protocol vulnerability database includes information on vulnerabilities of communication protocols; The system vulnerability database includes information on system vulnerabilities; The key feature database includes features of plaintext keys; The kernel vulnerability database includes information on kernel vulnerabilities; The software hardening feature database includes features of hardened application software code; The encryption algorithm feature database includes features of application software code using encryption algorithms; The application software vulnerability database includes information on vulnerabilities of application software; The application software residual debugging information feature database includes features of debugging information in application software code; The personal sensitive information feature database includes features of personal sensitive information.
5. The system according to claim 1, wherein The test module includes a communication protocol and interface security test unit, a system security test unit, an application software security test unit, and a data security test unit; The report generation module is used for: Scoring the test results of each test case in each test unit; In each test unit, performing weighted summation on the scores according to the weights of each test case to obtain the score of each test unit; Feedbacking the information security level of the vehicle head unit under test according to the scores of each test unit, and automatically generating a test report.
6. The system according to claim 5, characterized in that Before performing weighted summation on the scores according to the weights of each test case to obtain the score of each test unit in each test unit, it further includes: Obtaining the weights of each test case in each test unit respectively according to the analytic hierarchy process.
7. The system according to any one of claims 1-6, characterized in that, The test scenarios of the vehicle head unit under test include: the whole vehicle environment, the test scenario of components of the in-vehicle information interaction system, and the test scenario of system files of the in-vehicle information interaction system.
8. A method for testing the information security of an in-vehicle information interaction system, characterized in that, It includes: Collecting information of the test task in response to an operation of the user on the human-computer interaction interface, where the information of the test task includes at least test cases, task name, test time, and the physiological signals of the user; The physiological signals include pulse signals and heartbeat signals; Downloading the firmware under test to the local from the vehicle head unit under test through a communication link with the vehicle head unit under test; building a simulated running environment of the firmware under test in a local virtual machine according to the information of the firmware under test; Automatically testing the firmware under test according to the test cases in the simulated running environment; Automatically generating a test report according to the test results; Among them, downloading the firmware under test to the local from the vehicle head unit under test through a communication link with the vehicle head unit under test; building a simulated running environment of the firmware under test in a local virtual machine according to the information of the firmware under test includes: Building a communication link with the vehicle head unit under test; generating an encryption key and a decryption key according to the task name, test time, and the physiological signals of the user; accessing the vehicle head unit under test through the communication link with the vehicle head unit under test, encrypting the firmware under test with the encryption key; sending the encrypted firmware under test to the local and decrypting it with the decryption key to obtain the firmware under test; building a simulated running environment of the firmware under test in a local virtual machine according to the information of the firmware under test; Generating an encryption key and a decryption key according to the task name, test time, and the physiological signals of the user includes: Generating a first binary random number sequence according to the characteristics of the pulse signal, and generating a second binary random number sequence according to the characteristics of the first binary random number sequence and the heartbeat signal; splicing the second binary random number sequence with the binary representations of the task name and test time, and converting the spliced result into an unsigned integer to obtain the encryption key and the decryption key.
Citation Information
Patent Citations
Key generation, certification and data transmission method based on physiological features
CN103944725A
Electric power Internet-of-things terminal vulnerability detection method and system based on firmware analysis
CN112134761A