A test system
The automated testing system solves the problems of low efficiency and accuracy in the testing of the SecOC mechanism controller, and enables the generation of efficient and accurate test reports.
Patent Information
- Application Number
- CN202310560919.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-18
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2043-05-18
AI Technical Summary
In existing technologies, the testing efficiency and accuracy of controllers configured with the SecOC mechanism are low, mainly because the test scripts need to be written and judged manually.
A testing system is provided, including a message construction module, a message configuration module, a testing module, and a report generation module. It automatically constructs and configures messages to test the controller and generate test reports, thereby improving testing efficiency and accuracy.
The automated message construction and testing process improves the efficiency and accuracy of testing controllers configured with the SecOC mechanism, and generates detailed test reports.
Smart Images

Figure CN116668334B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of vehicles, and particularly relates to a test system. BACKGROUND
[0002] A Security Onboard Communication (SecOC) mechanism is a commonly used data security protection mechanism of a controller. With the rapid development of vehicle network technology, vehicle data is threatened more and more, and people pay more and more attention to the security of vehicle data. Therefore, it is necessary to test the controller deployed with the data security protection mechanism to ensure the security of related data involved in the controller.
[0003] However, in the prior art, the controller configured with the SecOC mechanism is connected with test software, and a related test script is written in the test software to test the SecOC mechanism deployed in the controller to obtain test data. However, the test script needs to be written manually, and after the test software outputs the test data, a person needs to make a judgment to obtain a conclusion, which not only leads to low test efficiency when testing the controller configured with the SecOC mechanism, but also leads to low test accuracy. SUMMARY
[0004] The embodiments of the application provide a test system, which not only improves the test efficiency when testing the controller configured with the SecOC mechanism, but also improves the test accuracy.
[0005] In a first aspect, the embodiments of the application provide a test system, which comprises: a test system connected with a tested controller, the tested controller being configured with a data security protection mechanism, and the test system comprising:
[0006] a message construction module configured to construct a first message, the first message comprising a normal message or an abnormal message, and send the first message to a test module;
[0007] a message configuration module configured to configure message information of the first message, and send the message information of the first message to the test module;
[0008] the test module configured to send the first message and the message information of the first message to the tested controller;
[0009] a report generation module configured to receive message feedback information sent by the tested controller, and generate a first test report based on the message feedback information.
[0010] In an optional implementation of the first aspect, the message information of the first message comprises a sending time, a sending period and a duration.
[0011] In an optional implementation of the first aspect, the test system comprises:
[0012] The message analysis module is configured to receive the second message sent by the controller under test, analyze the second message, and obtain message information of the second message, wherein the message information of the second message comprises message interception information, and send the message interception information to the message management module.
[0013] The message management module is configured to process the message interception information, obtain complete message information, check the complete message information, generate a check result, and send the check result to the report generation module.
[0014] The report generation module is configured to generate a second test report according to the check result.
[0015] In an optional implementation of the first aspect, the message interception information comprises a freshness interception value, and the message management module comprises:
[0016] The freshness management module is configured to process the freshness interception value by using a preset freshness construction method, obtain a freshness value, check the freshness value, and generate a first check result.
[0017] In an optional implementation of the first aspect, the message interception information comprises a MAC interception value, and the message management module comprises:
[0018] The freshness management module is configured to send the freshness value to the MAC management module.
[0019] The freshness management module is configured to process the MAC interception value by using a preset MAC construction method, obtain a MAC value, check the MAC value based on the message information of the second message and the freshness value, and obtain a second check result.
[0020] In an optional implementation of the first aspect, the second message is a synchronization message, and the message information of the second message further comprises a first message identifier.
[0021] The MAC management module is configured to process the first message identifier and the freshness value by using a MAC check algorithm, obtain a first MAC verification value, check the MAC value based on the first MAC verification value, and obtain a second check result.
[0022] In an optional implementation of the first aspect, the second message is a security message, and the message information of the second message comprises a first message identifier and first message content.
[0023] The MAC management module is configured to process the first message identifier, the first message content, and the freshness value by using a MAC verification algorithm, obtain a second MAC verification value, check the MAC value based on the second MAC verification value, and obtain a second check result.
[0024] In an optional implementation of the first aspect, the message configuration module is further configured to configure test information, the test information being used to test the measured controller.
[0025] In an optional implementation of the first aspect, the test system comprises a freshness value length, a MAC verification algorithm, and a MAC length.
[0026] In an optional implementation of the first aspect, the data security protection mechanism comprises a board-side encryption communication SecOC mechanism.
[0027] In the embodiments of the present application, the test system is connected with the measured controller, and the measured controller is configured with a data security protection mechanism. In addition, the test system mentioned above can comprise a message construction module, a message configuration module, a test module, and a report generation module. Based on the structure, the message construction module mentioned above can construct a first message and send the first message to the test module, the message configuration module can configure message information of the first message and send the message information of the first message to the test module, the test module can send the first message and the message information of the first message to the measured controller, and the report generation module can receive message feedback information sent by the measured controller after receiving the first message and the message information of the first message, and generate a first test report based on the message feedback information. In this way, the ability of the measured controller configured with the data security protection mechanism to verify whether the message is abnormal can be tested, which not only improves the test efficiency, but also improves the test accuracy. BRIEF DESCRIPTION OF DRAWINGS
[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced. For those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0029] Figure 1 is a structural schematic diagram of a test system provided by the embodiments of the present application;
[0030] Figure 2 is a structural schematic diagram of another test system provided by the embodiments of the present application. DETAILED DESCRIPTION
[0031] The features and exemplary embodiments of the various aspects of the present application will be described in detail below with reference to the drawings. For the purpose of clarity, the description is divided into the following sections: technical scheme, technical effects, and specific embodiments. The specific embodiments described herein are merely intended to explain the present application, and are not intended to limit the present application. The present application can be implemented without some of the specific details described below. The following description of the embodiments is merely intended to provide a better understanding of the present application by showing examples of the present application.
[0032] It should be noted that, in this document, the terms such as first and second are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between such entities or operations. Also, the terms "comprises", "comprising", or any other variations thereof are intended to cover non-exclusive inclusions, so that a process, method, article, or device that includes a list of elements does not only include those elements, but also includes other elements not explicitly listed, or further includes elements inherent in such a process, method, article, or device. Without more limitations, the elements defined by the statement "comprise" do not exclude the presence of other identical elements in the process, method, article, or device that includes the elements.
[0033] In this document, the term "and / or" is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone.
[0034] The Security Onboard Communication (SecOC) mechanism is a commonly used data security protection mechanism for controllers. With the rapid development of vehicle network technology, vehicle data is increasingly threatened, and people pay more and more attention to the security of vehicle data. Therefore, it is necessary to test the controller with the data security protection mechanism deployed therein to ensure the security of the related data involved in the controller.
[0035] However, in the prior art, the controller configured with the SecOC mechanism is generally connected with the test software, and the SecOC mechanism deployed in the controller is tested by writing a related test script in the test software, and test data is obtained. However, since the test script involved above needs to be written manually, and after the test software outputs the test data, a person needs to make a judgment to obtain a conclusion, which not only leads to low test efficiency when testing the controller configured with the SecOC mechanism, but also leads to low test accuracy.
[0036] To address the aforementioned issues, this application provides a testing system connected to a controller under test (DUT), which is configured with a data security protection mechanism. Furthermore, the aforementioned testing system may include a message construction module, a message configuration module, a testing module, and a report generation module. Based on this structure, the message construction module can construct a first message and send it to the testing module. The message configuration module can configure the message information of the first message and send it to the testing module. The testing module can send the first message and its message information to the DUT. The report generation module can receive message feedback information sent by the DUT after receiving the first message and its message information, and generate a first test report based on this feedback information. This allows for testing the ability of a DUT configured with a data security protection mechanism to verify message anomalies, improving both testing efficiency and accuracy.
[0037] The testing system provided in this application will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0038] Figure 1 This is a schematic diagram of the structure of a testing system provided in an embodiment of this application.
[0039] like Figure 1 As shown, the test system 100 is connected to the controller under test 200, which is configured with a SecOC mechanism. The test system 100 may include a message construction module 110, a message configuration module 120, a test module 130, and a report generation module 140.
[0040] The message construction module 110 is used to construct the first message and send the first message to the test module.
[0041] The message configuration module 120 is used to configure the message information of the first message and send the message information of the first message to the test module.
[0042] Test module 130 is used to send a first message and the message information of the first message to the controller under test;
[0043] The report generation module 140 is used to receive the message feedback information sent by the controller under test and generate the first test report based on the message feedback information.
[0044] The first message mentioned above includes normal messages or abnormal messages. In some embodiments, the message information of the first message may include the sending time, sending period, and duration, which are not specifically limited here. In some embodiments, the data security protection mechanism mentioned above includes the board-side encrypted communication SecOC mechanism.
[0045] In some embodiments, the first message mentioned above can be a synchronization message or a security message. Specifically, if the controller under test is a slave node of the SecOC mechanism, correct and abnormal synchronization messages need to be sent to the controller under test respectively to verify whether the controller under test can correctly verify that the synchronization message belongs to an abnormal message or a normal message; if the controller under test is a receiving node of the SecOC mechanism, correct and abnormal security messages need to be sent to the controller under test respectively to verify whether the controller under test can correctly receive and verify that the security message belongs to a normal message or an abnormal message.
[0046] Specifically, the message construction module mentioned above can construct a first message and send the first message to the test module, the message configuration module can configure message information of the first message and send the message information of the first message to the test module, the test module can send the first message and the message information of the first message to the controller under test, the controller under test will verify the first message after receiving the first message and the message information of the first message to determine whether the received first message is a normal message or an abnormal message, and send message feedback information to the report generation module, and the report generation module can receive the message feedback information and generate a first test report based on the message feedback information.
[0047] It should be noted that the controller under test can verify the message content, freshness value and MAC value of the first message when verifying the first message, which is not limited herein. It should be further noted that the message construction module needs to obtain the freshness value and MAC value configured by the test system in the process of constructing the message, and construct the message corresponding to the obtained freshness value and MAC value.
[0048] In the embodiments of the present application, the test system is connected with the controller under test, and the controller under test is configured with a data security protection mechanism. In addition, the test system mentioned above can include a message construction module, a message configuration module, a test module and a report generation module. Based on the structure, the message construction module mentioned above can construct a first message and send the first message to the test module, the message configuration module can configure message information of the first message and send the message information of the first message to the test module, the test module can send the first message and the message information of the first message to the controller under test, and the report generation module can receive message feedback information sent by the controller under test after receiving the first message and the message information of the first message, and generate a first test report based on the message feedback information. In this way, the ability of the controller under test configured with the data security protection mechanism to verify whether the message is abnormal can be tested, which not only improves the test efficiency, but also improves the test accuracy.
[0049] To more accurately describe the test system provided by the embodiments of the present application, as shown in Figure 2 The test system 100 described above can include a packet parsing module 101, a packet management module 102, a packet construction module 103 (corresponding to the packet construction module 110 in Figure 1 ), a packet configuration module 104 (corresponding to the packet configuration module 120 in Figure 1 ), a test module 105 (corresponding to the test module 130 in Figure 1 ), and a report generation module 106 (corresponding to the report generation module 140 in Figure 1 ).
[0050] It should be noted that the packet management module 102 described above includes a freshness management module 1022 and a MAC management module 1021. The packet parsing module 101 described above is connected to the freshness management module 1022 and the MAC management module 1021, respectively. The freshness management module 1022 described above is connected to the MAC management module 1021 and the packet construction module 103, respectively. The MAC management module 1021 described above is connected to the packet construction module 103 and the test module 105, respectively. The packet construction module 103 described above is connected to the packet configuration module 104. The packet configuration module 104 is connected to the test module 105. The test module 105 is connected to the report generation module 105.
[0051] Based on this, in one embodiment, the test system 100 described above can further include:
[0052] The packet parsing module 101 is configured to receive a second packet sent by a controller under test, parse the second packet to obtain packet information of the second packet, the packet information of the second packet including packet interception information, and send the packet interception information to the packet management module.
[0053] The packet management module 102 is configured to process the packet interception information to obtain complete packet information, check the complete packet information to generate a check result, and send the check result to the report generation module.
[0054] The report generation module 106 is configured to generate a second test report according to the check result.
[0055] Specifically, based on the structure of the test system, in the case that the second message is sent by the tested controller to the test system, the message parsing module in the test system can receive the second message sent by the tested controller, and parse the second message to obtain the message information of the second message. Since the message information of the second message only includes the message interception information, the message parsing module can send the message interception information to the message management module, so that the message management module can process the message interception information to obtain the complete message information corresponding to the message interception information after receiving the message interception information, and then can check the complete message information to generate a check result, and send the check result to the report generation module, so as to generate a second test report based on the check result. The second message can be a synchronization message or a security message, which is not limited here.
[0056] In this embodiment, based on the structure of the test system, the message interception information can be obtained by parsing the message sent by the tested controller, the complete message information can be obtained, and the test report can be generated by checking the complete message information, so as to realize the test of the tested controller configured with the data security protection mechanism, thereby improving the test efficiency and the test accuracy.
[0057] Based on this, in one embodiment, the message interception information can include a freshness interception value, and the message management module 102 includes:
[0058] The freshness management module 1022 is configured to process the freshness interception value by using a preset freshness construction method to obtain a freshness value, and check the freshness value to generate a first check result.
[0059] It should be noted that the freshness value can be a value indicating that the content of the message is fresh, and the freshness interception value can be a part of the freshness value. For example, the freshness value can be 16 bytes, and the freshness interception value can be two bytes, which is not limited here.
[0060] In some embodiments, the preset freshness construction method can be an algorithm pre-set according to actual situation or experience.
[0061] Specifically, since the message interception information can include a freshness interception value, and the message management module can include a freshness management module. Based on this, the freshness management module can process the freshness interception value by using a preset freshness construction method to obtain a freshness value, and then can check the freshness value to generate a first check result
[0062] In this embodiment, the message interception information can include the freshness interception value, and the message management module can include the freshness management module. Based on this, the test system can verify the freshness value of the message sent by the tested controller, thereby testing the tested controller configured with the data security protection mechanism, and thus improving the test efficiency and the test accuracy.
[0063] In another embodiment, the message interception information can include the MAC interception value, and based on this, the message management module 102 includes:
[0064] a freshness management module 1022, configured to send the freshness value to the MAC management module;
[0065] a MAC management module 1021, configured to process the MAC interception value by using a preset MAC construction method to obtain a MAC value, and verify the MAC value based on the message information and the freshness value of the second message to obtain a second verification result.
[0066] The MAC value can be the physical address of the tested controller on the network and has uniqueness. The MAC interception value is a part of the MAC value. The preset MAC construction method can be an algorithm pre-set according to actual conditions or experience.
[0067] Specifically, the message interception information can include the MAC interception value, and the message management module can include the MAC management module and the freshness management module. Based on this, the freshness management module can send the freshness value of the second message to the MAC management module, the MAC management module can process the MAC interception value by using a preset MAC construction method to obtain a MAC value, and then the MAC value can be verified based on the message information and the freshness value of the second message to obtain a second verification result.
[0068] In this embodiment, the message interception information can include the MAC interception value, and the message management module can include the MAC management module and the freshness management module. Based on this, the test system can verify the MAC value of the message sent by the tested controller, thereby testing the tested controller configured with the data security protection mechanism, and thus improving the test efficiency and the test accuracy.
[0069] Based on this, in one embodiment, if the second message is a synchronization message, the message information of the second message further includes a first message identifier.
[0070] The MAC management module 1021 is configured to process the first message identifier and the freshness value by using a MAC verification algorithm to obtain a first MAC verification value, and check the MAC value based on the first MAC verification value to obtain a second check result.
[0071] Specifically, since the second message involved above can be a synchronization message, the message information of the second message can include the first message identifier. Based on this, the MAC management module can process the first message identifier and the freshness value by using a MAC verification algorithm to obtain a first MAC verification value, and check the MAC value based on the first MAC verification value to obtain a second check result. The MAC verification algorithm can be preconfigured in the test system, which is not limited here.
[0072] In this embodiment, the test of the tested controller configured with the data security protection mechanism can be implemented when the second message is a synchronization message and the message information of the second message includes the first message identifier, thereby improving the test efficiency and the test accuracy.
[0073] In another embodiment, the second message is a security message, and the second message information includes the first message identifier and the first message content.
[0074] The MAC management module 1021 is configured to process the first message identifier, the first message content, and the freshness value by using a MAC verification algorithm to obtain a second MAC verification value, and check the MAC value based on the second MAC verification value to obtain a second check result.
[0075] Specifically, since the second message involved above can be a security message, the message information of the second message can include the first message identifier and the first message content. Based on this, the MAC management module can process the first message identifier, the first message content, and the freshness value by using a MAC verification algorithm to obtain a second MAC verification value, and check the MAC value based on the second MAC verification value to obtain a second check result.
[0076] In this embodiment, the test of the tested controller configured with the data security protection mechanism can be implemented when the second message is a security message and the message information of the second message includes the first message identifier and the first message content, thereby improving the test efficiency and the test accuracy.
[0077] In order to more accurately and comprehensively describe the test system provided by the embodiments of the present application, in one embodiment, the message configuration module 104 is further configured to configure test information, and the test information is used to test the tested controller.
[0078] In some embodiments, the test information includes a freshness value length, a MAC verification algorithm, and a MAC length. In addition, the test information described above can also include a key, which is not specifically limited herein.
[0079] In addition, it should be noted that the test system provided by the embodiments of the present application can also be used to test the stability of the tested controller configured with the SecOC mechanism. Specifically, a large number of correct or abnormal synchronization messages and security messages are constructed by the SecOC test system and sent to the tested controller under long time or under bus peak load of the tested controller. At the same time, the SecOC test system receives the message feedback information of the large number of normal or abnormal synchronization messages and security messages from the tested controller, and generates a test report.
[0080] Based on the test system provided by the embodiments of the present application, the blank of SecOC testing is filled. The start, duration and interruption time of SecOC message transmission are automatically and accurately controlled, the construction, receiving verification, message processing capability, freshness value management and mechanism stability of the security messages and synchronization messages of the controller SecOC mechanism are tested, and a test report is automatically generated. Not only is the test efficiency high and controllable, but also the test can be automatically performed through a program at the control end.
[0081] It should be clear that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted herein. In the above embodiments, a number of specific steps are described and shown as examples. However, the method processes of the present application are not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order of the steps, after understanding the spirit of the present application.
[0082] The functional blocks shown in the above structural block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted over a transmission medium or communication link carried by a carrier wave in a data request. The "machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segments can be downloaded via a computer network such as the Internet, an intranet, etc.
[0083] It should also be noted that the example embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps are performed simultaneously.
[0084] The computer program instructions can also be loaded onto a computer, other programmable electronic control unit, or other processing devices to cause a series of operational steps to be performed on the computer, other programmable electronic control unit, or other processing devices to generate a computer implemented process such that the instructions which execute on the computer or other programmable electronic control unit implement the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer program instructions can also be stored in a computer readable medium that can direct a computer, other programmable electronic control unit, or other processing devices to operate in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.
[0085] The above is merely specific implementation of the present application, and those skilled in the art can clearly understand the specific working process of the system, module and unit described above for the convenience and brevity of description, which can refer to the corresponding process in the foregoing method embodiments, and will not be described here. It should be understood that the protection scope of the present application is not limited to this, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.
Claims
1. A test system, characterized by, The test system is connected with a tested controller configured with a data security protection mechanism, and the test system comprises: a packet construction module, configured to construct a first packet, the first packet comprising a normal packet or an abnormal packet, and send the first packet to the test module; a packet configuration module, configured to configure packet information of the first packet, and send the packet information of the first packet to the test module; the test module, configured to send the first packet and the packet information of the first packet to the tested controller; a report generation module, configured to receive packet feedback information sent by the tested controller, and generate a first test report based on the packet feedback information; a packet analysis module, configured to receive a second packet sent by the tested controller, and analyze the second packet to obtain packet information of the second packet, the packet information of the second packet comprising packet interception information, and send the packet interception information to the packet management module; the packet management module, configured to process the packet interception information to obtain complete packet information, and check the complete packet information to generate a check result, and send the check result to the report generation module; the report generation module, configured to generate a second test report according to the check result.
2. The test system of claim 1, wherein, The packet information of the first packet comprises a sending time, a sending period and a duration.
3. The test system of claim 1, wherein, The packet interception information comprises a freshness interception value, and the packet management module comprises: a freshness management module, configured to process the freshness interception value by using a preset freshness construction method to obtain a freshness value, and check the freshness value to generate a first check result.
4. The test system of claim 3, wherein, The packet interception information comprises a MAC interception value, and the packet management module comprises: the freshness management module, configured to send the freshness value to the MAC management module; the MAC management module, configured to process the MAC interception value by using a preset MAC construction method to obtain a MAC value, and check the MAC value based on the packet information of the second packet and the freshness value to obtain a second check result.
5. The test system of claim 4, wherein, The second packet is a synchronization packet, and the packet information of the second packet further comprises the first packet identifier; the MAC management module, configured to process the first packet identifier and the freshness value by using a MAC check algorithm to obtain a first MAC verification value, and check the MAC value based on the first MAC verification value to obtain a second check result.
6. The test system of claim 4, wherein, The second packet is a security packet, and the packet information of the second packet comprises a first packet identifier and a first packet content; the MAC management module, configured to process the first packet identifier, the first packet content and the freshness value by using a MAC verification algorithm to obtain a second MAC verification value, and check the MAC value based on the second MAC verification value to obtain a second check result.
7. The test system of claim 1, wherein the packet configuration module is further configured to configure test information, the test information being used for testing the tested controller.
8. The test system of claim 7, wherein the test information includes a freshness value length, a MAC verification algorithm, and a MAC length.
9. The system of claim 1, wherein, The data security protection mechanism includes a board-side encrypted communication (SecOC) mechanism.
Citation Information
Patent Citations
Vehicle-mounted network security communication test method and system, electronic equipment and storage medium
CN115576302A