A new energy vehicle TBOX data decryption method and its system
The method of extracting and decrypting T-BOX data through image analysis and gdb tools addresses the challenge of encrypted data in new energy vehicles, enhancing forensic and accident analysis capabilities.
Patent Information
- Application Number
- CN202211293836.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-10-21
AI Technical Summary
The existing technology cannot effectively decrypt the encrypted data in the TBOX of new energy vehicles, and cannot meet the needs of automotive forensics security and accident analysis.
By reversely analyzing the TBOX image, using the adb command to enter the operating system, running executable programs related to data encryption, importing the gdb debugging tool to read the memory data under the virtual address, and decrypting it with a special data location key.
It has realized the decryption of encrypted data in TBOX, solved the problem of electronic data evidence collection in new energy vehicles, and is of great significance.
Smart Images

Figure CN115510470B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of automotive forensic security, and particularly relates to a method and system for decrypting TBOX data of new energy vehicles. Background Art
[0002] As a "black box" widely used in new energy vehicles, with the development of vehicle networking technology, the technology for recovering deleted data of the T-BOX module will be a hot topic attracting much attention in the fields of automotive safety and network information security.
[0003] Currently, there is no method in the industry to decrypt the encrypted data in the TBOX, which cannot meet the urgent needs of the automotive forensic security field and the analysis of new energy vehicle accidents.
[0004] In view of this, it is very meaningful to propose a method and system for decrypting TBOX data of new energy vehicles. Summary of the Invention
[0005] In order to solve the problem of being unable to effectively decrypt the encrypted data in the TBOX, the present invention provides a method and system for decrypting TBOX data of new energy vehicles to solve the above-mentioned existing technical defect problems.
[0006] In a first aspect, the present invention proposes a method for decrypting TBOX data of new energy vehicles, which includes the following steps:
[0007] S1. Obtain and analyze the image of the TBOX, and reversely analyze the encryption algorithm of the TBOX;
[0008] S2. Enter the operating system of the TBOX using the adb command;
[0009] S3. Further run the executable program related to data encryption;
[0010] S4. Start and run a cmd window, and view the process number of the executable program in S3;
[0011] S5. View the virtual address space allocation of the process number, and find the virtual address occupied by the dynamic library used for encryption;
[0012] S6. By importing the gdb debugging tool into the operating system of the TBOX, read and export the memory data under the virtual address;
[0013] S7. Analyze the exported data, locate the key through special data, and complete decryption.
[0014] Preferably, S1 specifically includes: analyzing the TBOX image, searching for executable programs and dynamic libraries related to data encryption, and reversely analyzing the encryption algorithm and process.
[0015] More preferably, S2 specifically includes: connecting the TBOX and the forensic device through a serial cable and entering the operating system of the TBOX using the adb command.
[0016] More preferably, S3 specifically includes: running the executable program related to data encryption and keeping the program in a running state.
[0017] More preferably, S5 specifically includes: checking the virtual address space allocation corresponding to the process ID obtained in S4 and finding the virtual addresses occupied by the dynamic libraries related to data encryption.
[0018] More preferably, S6 specifically includes: importing the gdb debugging tool and related dependent libraries into the TBOX using the adb command, reading the memory data under the virtual addresses occupied by the dynamic libraries related to data encryption using the dump command in the gdb debugging tool, and exporting the memory data to the forensic device using the adb command.
[0019] More preferably, S7 specifically includes: analyzing the exported memory data, retrieving the required special data from the memory data, locating the key used for encryption from the memory data based on the positional relationship between the obtained data and the key storage during reverse analysis, and completing data decryption in combination with the encryption algorithm obtained through reverse analysis.
[0020] In a second aspect, an embodiment of the present invention further provides a new energy vehicle TBOX data decryption system, including:
[0021] An acquisition module: used to acquire the image of the TBOX;
[0022] An analysis module: used to analyze the image of the TBOX, reversely analyze the encryption algorithm of the TBOX, and analyze the exported data;
[0023] An execution module: used to import the gdb debugging tool into the operating system of the TBOX, read the memory data under the virtual address and export it;
[0024] A decryption module: used to locate the key through special data and complete decryption.
[0025] In a third aspect, an embodiment of the present invention provides an electronic device, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner of the first aspect.
[0026] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any implementation manner of the first aspect is implemented.
[0027] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0028] (1) By reading the memory data occupied by the executable program and dynamic library related to data encryption, and using a special data positioning key to complete data decryption. The present invention can solve the problem that encrypted data in the TBOX cannot be parsed, which is of great significance for the forensic analysis of electronic data of new energy vehicles. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated in and constitute a part of this specification. The drawings illustrate the embodiments and together with the description are used to explain the principles of the present invention. Other embodiments and many of the intended advantages of the embodiments will be readily apparent as they become better understood by reference to the following detailed description. The elements of the drawings are not necessarily to scale with each other. The same reference numerals refer to corresponding like parts.
[0030] Figure 1 is an exemplary device architecture diagram to which an embodiment of the present invention can be applied;
[0031] Figure 2 is a schematic flowchart of the method for decrypting new energy vehicle TBOX data according to an embodiment of the present invention;
[0032] Figure 3 is a schematic flowchart of the system for decrypting new energy vehicle TBOX data according to an embodiment of the present invention;
[0033] Figure 4 is a schematic structural diagram of a computer device of an electronic device suitable for implementing an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] In the following detailed description, reference is made to the accompanying drawings which form a part hereof and in which are shown by way of illustration specific exemplary embodiments in which the invention may be practiced. In this regard, directional terms such as "top", "bottom", "left", "right", "up", "down", etc. are used with reference to the orientation of the described drawings. Since the components of the embodiments can be positioned in several different orientations, for purposes of illustration the directional terms are used and are in no way limiting. It should be understood that other embodiments may be utilized or logical changes may be made without departing from the scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is defined by the appended claims.
[0035] It should be understood that Figure 1 the numbers of the terminal devices, networks, and servers in [[ ]] are merely illustrative. According to actual requirements, there can be any number of terminal devices, networks, and servers.
[0036] Figure 1 An exemplary system architecture 100 for a method of processing information or an apparatus for processing information to which embodiments of the present invention can be applied is shown.
[0037] As Figure 1 shown, the system architecture 100 may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0038] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 101, 102, 103, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0039] The terminal devices 101, 102, 103 may be various electronic devices with communication functions, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0040] The server 105 may be a server that provides various services, such as a background information processing server that processes the verification request information sent by the terminal devices 101, 102, 103. The background information processing server may analyze and process the received verification request information and obtain a processing result (such as a verification success information indicating that the verification request is a legal request).
[0041] It should be noted that the method for processing information provided by the embodiments of the present invention is generally executed by the server 105. Correspondingly, the apparatus for processing information is generally provided in the server 105. In addition, the method for sending information provided by the embodiments of the present invention is generally executed by the terminal devices 101, 102, 103. Correspondingly, the apparatus for sending information is generally provided in the terminal devices 101, 102, 103.
[0042] It should be noted that the server can be hardware or software. When the server is hardware, it can be implemented as a distributed server cluster composed of multiple servers or as a single server. When the server is software, it can be implemented as multiple software or software modules (such as for providing distributed services), or as a single software or multiple software modules, and no specific limitation is made here.
[0043] As a "black box" widely used in new energy vehicles, with the development of vehicle networking technology, the technology for recovering deleted data of the T - BOX module will be a hot topic attracting much attention in the fields of automotive safety and network information security. Currently, there is no method in the industry to decrypt the encrypted data in the T - BOX, which cannot meet the urgent needs of the automotive forensics security field and the accident analysis of new energy vehicles.
[0044] Figure 2 The embodiments of the present invention disclose a method for decrypting T - BOX data of a new energy vehicle, as Figure 2 shown, the method includes the following steps:
[0045] S1. Obtain the image of the T - BOX and analyze it, and reversely analyze the encryption algorithm of the T - BOX;
[0046] S2. Use the adb command to enter the operating system of the T - BOX;
[0047] S3. Further run the executable program related to data encryption;
[0048] S4. Start and run a cmd window to view the process ID of the executable program in S3;
[0049] S5. View the virtual address space allocation of the process ID, and find the virtual address occupied by the dynamic library used for encryption;
[0050] S6. By importing the gdb debugging tool into the operating system of the T - BOX, read the memory data under the virtual address and export it;
[0051] S7. Analyze the exported data, locate the key through special data and complete decryption.
[0052] The T-BOX module is an in-vehicle electronic module that is mandatory for new energy vehicles. According to the national standard "GB-T-32960", various vehicle statuses and vehicle driving data are stored on it, and these data are of great significance for analyzing the causes of new energy vehicle accidents. For some data in the TBOX, manufacturers usually encrypt it. Based on reverse engineering the executable programs and dynamic libraries related to data encryption in the TBOX, this paper proposes a method for decrypting new energy vehicle TBOX data based on memory reading. This method locates and obtains the key used during encryption from memory through certain special data, and decrypts the encrypted data in the TBOX.
[0053] Specifically, the symmetric encryption algorithm is a relatively early and mature encryption algorithm. In the symmetric encryption algorithm, the data sender encrypts the plaintext into complex ciphertext through the key. After the receiver receives the ciphertext, the same key is used to decrypt the ciphertext into plaintext. Its biggest feature is that the encryption party and the decryption party use the same key, so the encryption speed is fast and the encryption efficiency is high, which is suitable for use in cases with a large amount of data. Commonly used symmetric encryption algorithms mainly include AES, DES, 3DES, RC, etc.
[0054] By reverse analyzing the executable programs and dynamic libraries related to data encryption in the TBOX image, it is possible to roughly know which encryption algorithm the TBOX uses. However, for the key used during encryption, manufacturers always try to hide it, resulting in difficult decryption. During the operation of the executable program related to data encryption, the key is transmitted to the memory occupied by the program through inter-process communication. Through the gdb debugging tool, the memory data occupied by the specified process can be read. Combining with the special data used in the encryption algorithm (such as the padding array used in the AES algorithm), the key can be located from the huge amount of memory data, thus completing the decryption of the encrypted data.
[0055] Specifically, in this embodiment, the new energy vehicle TBOX data decryption process is described as follows:
[0056] Step 1: Analyze the TBOX image, find the executable programs and dynamic libraries related to data encryption, and reverse analyze the encryption algorithm and process;
[0057] Step 2: Connect the TBOX and the forensic device through a serial cable, and use the adb command to enter the operating system of the TBOX;
[0058] Step 3: Run the executable program related to data encryption and keep the program running;
[0059] Step 4: Run another cmd window, also enter the operating system of the TBOX, and view the process ID of the program running in Step 3;
[0060] Step 5: Check the virtual address space allocation corresponding to the process ID obtained in Step 4, and find the virtual addresses occupied by the dynamic libraries related to data encryption;
[0061] Step 6: Import the gdb debugging tool and related dependent libraries into the TBOX through the adb command. Use the dump command in the gdb debugging tool to read the memory data under the virtual addresses occupied by the dynamic libraries related to data encryption, and export the memory data to the forensic device through the adb command;
[0062] Step 7: By reverse-engineering the executable program and dynamic libraries for data encryption, it can be known that during the encryption process, some special data (such as padding arrays) used will not change during the process. Analyze the exported memory data, retrieve this special data in the memory data, and based on the positional relationship between this data and the storage location of the key analyzed during reverse-engineering, further locate the key used during encryption from the memory data, and combine with the encryption algorithm analyzed by reverse-engineering to complete data decryption;
[0063] Step 8: The process ends here.
[0064] In a second aspect, an embodiment of the present invention also discloses a data decryption system for a new energy vehicle TBOX, as Figure 3 shown, including:
[0065] An acquisition module 31: configured to acquire the image of the TBOX;
[0066] An analysis module 32: configured to analyze the image of the TBOX, reverse-engineer the encryption algorithm of the TBOX, and analyze the exported data;
[0067] An execution module 33: configured to import the gdb debugging tool into the operating system of the TBOX, read the memory data under the virtual address and export it;
[0068] A decryption module 34: configured to locate the key through special data and complete decryption.
[0069] As an important terminal of a new energy vehicle, the importance of the data in the TBOX is self-evident. This patent proposes a forensic technology for data decryption based on reading keys from memory. This method reads the memory data occupied by the executable program and dynamic libraries related to data encryption, locates the key through special data, and completes data decryption. This technology can solve the problem of inability to parse encrypted data in the TBOX, and has great significance for the forensic analysis of electronic data of new energy vehicles.
[0070] Next, refer to Figure 4 , which shows an electronic device suitable for implementing the embodiments of the present invention (for example Figure 1Schematic structural diagram of a computer device 600 (such as the server or terminal device shown). Figure 4 The electronic device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present invention.
[0071] As Figure 4 As shown, the computer device 600 includes a central processing unit (CPU) 601 and a graphics processing unit (GPU) 602, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 603 or the program loaded from the storage section 609 into the random access memory (RAM) 606. In the RAM 604, various programs and data required for the operation of the device 600 are also stored. The CPU 601, GPU 602, ROM 603, and RAM 604 are connected to each other via a bus 605. The input / output (I / O) interface 606 is also connected to the bus 605.
[0072] The following components are connected to the I / O interface 606: an input section 607 including a keyboard, a mouse, etc.; an output section 608 including, for example, a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 609 including a hard disk, etc.; and a communication section 610 including a network interface card such as a LAN card, a modem, etc. The communication section 610 performs communication processing via a network such as the Internet. A drive 611 may also be connected to the I / O interface 606 as needed. A removable medium 612, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 611 as needed so that a computer program read from it can be installed into the storage section 609 as needed.
[0073] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 610 and / or installed from the removable medium 612. When the computer program is executed by the central processing unit (CPU) 601 and the graphics processing unit (GPU) 602, the above-described functions defined in the method of the present invention are executed.
[0074] It should be noted that the computer-readable medium described in the present invention can be a computer-readable signal medium, a computer-readable medium, or any combination of the two. The computer-readable medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor device, apparatus, or component, or any combination of the above. More specific examples of the computer-readable medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution device, apparatus, or component. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution device, apparatus, or component. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0075] The computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0076] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of devices, methods, and computer program products according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram may represent a module, a program segment, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the boxes may occur in a different order than that marked in the accompanying drawings. For example, two consecutive boxes shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, as well as combinations of boxes in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based device that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0077] The modules described in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor.
[0078] As another aspect, the present invention also provides a computer-readable medium, which can be included in the electronic device described in the above embodiments; or can exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the one or more programs are executed by the electronic device, the electronic device is caused to perform the method steps described in the first aspect of the embodiments of the present invention.
[0079] The above description is only the preferred embodiments of the present invention and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present invention is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features having similar functions disclosed in the present invention.
Claims
1. A method for decrypting TBOX data of a new energy vehicle, characterized in that, The method includes the following steps: S1. Obtain and analyze the image of the TBOX, and reverse-analyze the encryption algorithm of the TBOX; S2. Use the adb command to enter the operating system of the TBOX; S3. Further run the executable program related to data encryption; S4. Start and run a cmd window to view the process ID of the executable program in S3; S5. View the virtual address space allocation of the process ID, and find the virtual address occupied by the dynamic library used for encryption; S6. Import the gdb debugging tool into the operating system of the TBOX, read the memory data under the virtual address and export it; S7. Analyze the exported data, locate the key through special data and complete decryption, where the special data is a padding array.
2. The new energy vehicle TBOX data decryption method according to claim 1, wherein S1 specifically includes: Analyze the TBOX image, search for executable programs and dynamic libraries related to data encryption, and reverse-analyze the encryption algorithm and process.
3. The new energy vehicle TBOX data decryption method according to claim 2, wherein, S2 specifically includes: Connect the TBOX and the forensic device through a serial cable, and use the adb command to enter the operating system of the TBOX.
4. The new energy vehicle TBOX data decryption method according to claim 3, wherein S3 specifically includes: Run the executable program related to data encryption and keep the program running.
5. The new energy vehicle TBOX data decryption method according to claim 4, characterized in that S5 specifically includes: View the virtual address space allocation corresponding to the process ID obtained in S4, and find the virtual address occupied by the dynamic library related to data encryption.
6. The new energy vehicle TBOX data decryption method according to claim 5, wherein S6 specifically includes: Import the gdb debugging tool and related dependent libraries into the TBOX through the adb command, use the dump command in the gdb debugging tool to read the memory data under the virtual address occupied by the dynamic library related to data encryption, and export the memory data to the forensic device through the adb command.
7. The new energy vehicle TBOX data decryption method according to claim 6, characterized in that, S7 specifically includes: Analyze the exported memory data, retrieve the required special data in the memory data, locate the key used for encryption from the memory data based on the positional relationship between the data and the key obtained by reverse analysis, and combine the encryption algorithm obtained by reverse analysis to complete data decryption.
8. A new energy vehicle TBOX data decryption system, characterized in that, For implementing the method described in any one of claims 1-7, it includes: An acquisition module: used to acquire the image of the TBOX; An analysis module: used to analyze the image of the TBOX, reverse-analyze the encryption algorithm of the TBOX, and analyze the exported data; An execution module: used to import the gdb debugging tool into the operating system of the TBOX, read the memory data under the virtual address and export it; A decryption module: used to locate the key through special data and complete decryption.
9. An electronic device, including: One or more processors; A storage device, used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method described in any one of claims 1 to 7.
Citation Information
Patent Citations
Vehicle-mounted TBOX access method and authentication equipment
CN112468294A
Intelligent networked automobile data and information security evaluation system
CN113325825A