Information security test method and device for vehicle, electronic equipment and readable storage medium
By building multiple functional scenarios in the network target range, testing the vehicle's V2X communication information security and identifying forged messages, the problem of incomplete V2X technology information security testing was solved, and a comprehensive assessment of vehicle communication security and anti-interference capabilities was achieved.
Patent Information
- Application Number
- CN202411154577.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-21
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-08-21
AI Technical Summary
In existing technologies, information security testing of V2X technology fails to fully cover various scenarios and security threats that may be encountered in actual applications, resulting in incomplete vehicle information security testing.
By building a variety of functional scenarios in the network target range, the security status of the vehicle's V2X communication information in different scenarios is tested. Abnormal communication messages are sent after the vehicle moves to identify forged messages, so as to comprehensively evaluate the vehicle's communication security and anti-interference capabilities.
Comprehensive information security testing of vehicles in different scenarios was achieved, and the vehicle's communication capabilities and anti-interference capabilities during actual driving were evaluated, ensuring the vehicle's communication security in complex environments.
Smart Images

Figure CN118890622B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle communication technology, and in particular to a vehicle information security testing method, device, electronic device and readable storage medium. Background Art
[0002] With the rapid development of autonomous driving, vehicle-to-everything (V2X) technology has become a key enabler of autonomous driving. V2X can overcome the limited line-of-sight capabilities of traditional on-board sensors like cameras and radar, improving vehicle perception in challenging conditions like intersections and inclement weather. Through vehicle-infrastructure collaboration, it can significantly mitigate the challenges inherent in single-vehicle intelligence and reduce the cost of autonomous driving. However, because V2X transmits data via wireless communication, it carries potential security risks.
[0003] In related technologies, when testing the information security of V2X technology during communication, most of the tests are conducted on the vehicle's V2X communication function in a simulation environment, or on the communication protocol. However, such tests focus on specific scenarios or performance parameters and fail to fully cover the various scenarios and security threats that V2X technology may encounter in actual applications. Therefore, there is a technical problem of incomplete vehicle information security testing.
[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0005] Embodiments of the present invention provide a vehicle information security testing method, device, electronic device, and readable storage medium to at least solve the technical problem of incomplete vehicle information security testing.
[0006] According to one aspect of an embodiment of the present invention, a vehicle information security testing method is provided. The method includes: in response to a communication function of a vehicle under test being in a normal state, testing the communication status of the vehicle under test's communication information in a current function scenario under test, wherein the communication information is generated during communication by the vehicle under test in the current function scenario under test, the function scenario under test being used to indicate a scenario in which communication is performed between the vehicle and other traffic participants, and the communication status being used to indicate whether the communication information is in a safe state or in an unsafe state during the communication process; in response to the communication status being in a safe state, traversing the remaining function scenarios under test except the current function scenario under test in a plurality of function scenarios under test, and testing the communication status of the vehicle under test's communication information in the remaining function scenarios under test; in response to the communication status of the vehicle under test's communication information in the remaining function scenarios under test being in a safe state, controlling the vehicle under test to move; sending abnormal communication messages to the vehicle under test after it moves in each of the plurality of function scenarios under test, wherein the abnormal communication messages are used to indicate messages containing abnormal information; and in response to the vehicle under test identifying the abnormal communication messages, determining that the information security test of the vehicle under test is successful.
[0007] Optionally, testing the communication status of the communication information of the vehicle under test in the current functional scenario to be tested includes: sending a first communication message to the vehicle under test, wherein the first communication message is a message signed by the private key of the digital certificate; obtaining a first signature verification result of the first communication message by the vehicle under test, wherein the first signature verification result is obtained by the vehicle under test using the public key in the digital certificate to verify the signature of the first communication message; based on the first signature verification result, determining the communication status of the communication information of the vehicle under test in the current functional scenario to be tested.
[0008] Optionally, obtaining a first signature verification result of the vehicle under test for the first communication message includes: obtaining a verification result of the digital certificate in the first communication message by the vehicle under test, wherein the verification result is used to indicate the legality and validity of the digital certificate; in response to the verification result indicating that the digital certificate is legal and valid, obtaining the first signature verification result.
[0009] Optionally, based on the first signature verification result, determining the communication status of the communication information of the vehicle to be tested in the functional scenario to be tested includes: in response to the first signature verification result indicating that the first communication message is secure during transmission, determining that the communication information of the vehicle to be tested is in a secure state when communicating in the functional scenario to be tested.
[0010] Optionally, in response to the communication information being in the safe state, the remaining function scenarios in the plurality of function scenarios to be tested, except for the current function scenario to be tested, are traversed, including: in response to the communication information of the vehicle to be tested being in the safe state in the current function scenario to be tested, a second communication message fed back by the vehicle to be tested is acquired, wherein the second communication message corresponds to the first communication message; a time interval between sending the first communication message and receiving the second communication message is determined; in response to the time interval being less than a preset time threshold, a next function scenario to be tested is traversed to test a communication state of the communication information of the vehicle to be tested in the next function scenario to be tested.
[0011] Optionally, the information security testing method of the vehicle further includes: counterfeiting the private key and the public key in the digital certificate to obtain a counterfeited private key and a counterfeited public key; signing the first communication message by using the counterfeited private key; sending the first communication message signed by using the counterfeited private key to the vehicle to be tested; acquiring a second signature verification result of the vehicle to be tested on the first communication message; and in response to the second signature verification result indicating that the vehicle to be tested identifies the counterfeited private key and the counterfeited public key, determining that the security authentication function of the vehicle to be tested is normal.
[0012] Optionally, after the vehicle to be tested is moved and the abnormal communication message is sent to the vehicle to be tested, the information security testing method of the vehicle further includes: acquiring an identification result of the vehicle to be tested on the abnormal communication message; and in response to the identification result indicating that the vehicle to be tested identifies the abnormal communication message, determining that the information security testing of the vehicle to be tested is successful.
[0013] Optionally, the information security testing method of the vehicle further includes: sending a request message to the vehicle to be tested; and in response to receiving a response message fed back by the vehicle to be tested, determining that the communication function of the vehicle to be tested is in a normal state.
[0014] According to another aspect of an embodiment of the present invention, a vehicle information security testing device is also provided. The device includes: a first testing unit for testing the communication status of the communication information of the vehicle to be tested in the current function scenario to be tested in response to the communication function of the vehicle to be tested being in a normal state, wherein the communication information is generated during the communication process of the vehicle to be tested in the current function scenario to be tested, the function scenario to be tested is used to indicate the scenario of communication between the vehicle and other traffic participants, and the communication status is used to indicate that the communication information is in a safe state during the communication process, or that the communication information is in an unsafe state during the communication process; a second testing unit for traversing multiple function scenarios to be tested in response to the communication status being a safe state. The remaining functional scenarios to be tested except the current functional scenario to be tested are used to test the communication status of the communication information of the vehicle to be tested in the remaining functional scenarios to be tested; a control unit is used to control the movement of the vehicle to be tested in response to the communication status of the communication information of the vehicle to be tested being a safe state when communicating in the remaining functional scenarios to be tested; a third test unit is used to send abnormal communication messages to the moved vehicle to be tested in multiple functional scenarios to be tested, wherein the abnormal communication messages are used to indicate messages containing abnormal information; a determination unit is used to determine that the information security test of the vehicle to be tested is successful in response to the vehicle to be tested identifying the abnormal communication messages.
[0015] According to another aspect of an embodiment of the present invention, an electronic device is provided, including: a memory storing an executable program; and a processor for running the program, wherein the vehicle information security testing method in each embodiment of the present invention is executed when the program is running.
[0016] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is further provided, which includes a stored executable program, wherein when the executable program is running, the device where the computer-readable storage medium is located is controlled to execute the vehicle information security testing method in each embodiment of the present invention.
[0017] According to another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the vehicle information security testing method in each embodiment of the present invention is implemented.
[0018] According to another aspect of an embodiment of the present invention, a computer program product is also provided, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the vehicle information security testing method in each embodiment of the present invention is implemented.
[0019] According to another aspect of an embodiment of the present invention, a computer program is further provided. When the computer program is executed by a processor, the vehicle information security testing method in each embodiment of the present invention is implemented.
[0020] In an embodiment of the present invention, when the communication function of the vehicle under test is in a normal state, multiple test function scenarios are traversed to test the communication status of the communication information of the vehicle under test when communicating in the multiple test function scenarios. This allows for a comprehensive evaluation of the communication function of the vehicle under test in different scenarios to ensure the communication security of the vehicle under test in different scenarios. When the communication status of the communication information of the vehicle under test in the multiple test function scenarios is all in a safe state, the vehicle is controlled to move, and after the vehicle moves, the communication function of the vehicle is tested in the multiple test function scenarios. This helps to evaluate the communication capability of the vehicle during actual driving. By identifying abnormal communication messages, it can be determined whether the information security test of the vehicle under test is successful, which helps to evaluate the anti-interference capability of the vehicle under test. That is to say, the security of the communication information of the vehicle under test during the communication process is tested separately in multiple functional scenarios to be tested. The communication security function of the vehicle under test can be comprehensively evaluated in different scenarios. After moving the vehicle under test, the vehicle under test's ability to recognize abnormal communication messages is tested, and the communication capability and anti-interference capability of the vehicle under test during driving are evaluated. By testing the information security performance of the vehicle under test in different functional scenarios, the technical effect of comprehensively testing the vehicle's information security function is achieved, thereby solving the technical problem of incomplete information security testing of the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0022] Figure 1 is a flow chart of a vehicle information security testing method according to an embodiment of the present invention;
[0023] Figure 2 is a schematic diagram of a V2X security detection platform according to an embodiment of the present application;
[0024] Figure 3 is a flowchart of a V2X message security testing method according to an embodiment of the present application;
[0025] Figure 4 is a flow chart of an information security testing method according to an embodiment of the present application;
[0026] Figure 5 2 is a schematic diagram of a vehicle information security testing device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] According to an embodiment of the present invention, an embodiment of a vehicle information security testing method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0030] Figure 1 FIG. 1 is a flow chart of a vehicle information security testing method according to an embodiment of the present invention. Figure 1 As shown, the method includes the following steps:
[0031] Step S101 : in response to the communication function of the vehicle to be tested being in a normal state, testing the communication state of the communication information of the vehicle to be tested in the current function scenario to be tested.
[0032] In the technical solution provided in step S101 of the present invention, the communication function of the vehicle under test being in a normal state indicates that the communication link of the vehicle under test can normally send and receive communication information. The communication information of the vehicle under test is generated during the communication process of the vehicle under test in the current function scenario under test. The function scenario under test is used to indicate the scenario of communication between the vehicle under test and other traffic participants. For example, the vehicle-to-vehicle communication (V2V) scenario, the vehicle-to-infrastructure communication (V2I) scenario, the vehicle-to-pedestrian communication (V2P) scenario, and the vehicle-to-network communication (V2N) scenario. The communication state is used to indicate that the communication information of the vehicle under test is in a safe state during the communication process, or that the communication information of the vehicle under test is in an unsafe state during the communication process. A safe state indicates that the vehicle's communication system is secure and reliable during communication. This means the system can effectively transmit and receive data, ensuring confidentiality and integrity. An unsafe state indicates that the vehicle's communication system has security risks or instability, potentially leading to information leakage, data tampering, or communication interruption.
[0033] In this embodiment, in order to determine whether the communication function of the vehicle to be tested is in a normal state, a request message can be sent to the vehicle to be tested. If the communication function of the vehicle to be tested is in a normal state, the vehicle to be tested will feedback a response message after receiving the request message. Based on this, if a response message is received from the vehicle to be tested, it is determined that the communication function of the vehicle to be tested is in a normal state.
[0034] Optionally, after determining that the communication function of the vehicle to be tested is in a normal state, the communication status of the communication information of the vehicle to be tested in the current function scenario to be tested can be tested, wherein the current function scenario to be tested can be any one of the V2V scenario, V2P scenario, V2I scenario and V2N scenario.
[0035] For example, the test system uses the private key of the digital certificate to sign the first communication message to be sent in the current functional scenario to be tested, and obtains the signed first communication message. Afterwards, the first communication message and the digital certificate are broadcast together. After receiving the first communication message, the vehicle to be tested can first extract the digital certificate in the first communication message. Afterwards, the legitimacy and validity of the digital certificate are verified to ensure that the first communication message has not been tampered with or forged during transmission. After the digital certificate is verified, the signature of the first communication message can be verified using the public key of the digital certificate to obtain a signature verification result. If the signature verification result passes, it means that the first communication message is secure, that is, the first communication message has not been tampered with during transmission. After the vehicle under test passes the signature verification of the first communication message, it can feedback a second communication message to the test system to notify the test system that the vehicle under test has successfully received and parsed the first communication message, wherein the first communication message and the second communication message can be cellular network-based vehicle-to-everything wireless communication (C-V2X).
[0036] Optionally, if the signature verification result of the first communication message by the vehicle under test passes, it indicates that the communication status of the communication information of the vehicle under test in the current functional scenario under test is secure. Conversely, if the signature verification result of the first communication message by the vehicle under test fails, it indicates that the communication status of the communication information of the vehicle under test in the current functional scenario under test is unsafe.
[0037] Step S102 , in response to the communication state being a safe state, traverse the remaining functional scenarios to be tested except the current functional scenario to be tested in the plurality of functional scenarios to be tested, and test the communication state of the communication information of the vehicle to be tested in the remaining functional scenarios to be tested.
[0038] In the technical solution provided by the above-mentioned step S102 of the present invention, after determining that the communication information of the vehicle to be tested is in a safe state through step S101, it means that the communication information of the vehicle to be tested in the current functional scenario to be tested is safe. In this case, the remaining functional scenarios to be tested in multiple functional scenarios to be tested except the current functional scenario to be tested can be traversed to further test the communication status of the communication information to be tested in the remaining functional scenarios to be tested.
[0039] In this embodiment, after receiving the second communication message sent by the vehicle under test, the test system may trigger the next functional scenario to be tested, that is, test whether the communication status of the communication information of the vehicle under test is a safe state in the next functional scenario to be tested.
[0040] For example, after triggering the next to-be-tested function scene, the test system can verify the pseudonym certificate and the digest policy in the message sent by the to-be-tested vehicle, and if the verification is passed, the next to-be-tested function scene is triggered until all the to-be-tested function scenes are traversed.
[0041] Optionally, when triggering the next to-be-tested function scene, the test system can further determine the time interval between sending the first communication message and receiving the second communication message in the previous to-be-tested function scene, and then determine whether the time interval is within a preset time threshold range. If the time interval is within the preset time range, the next to-be-tested function scene is triggered. The preset time threshold can be 300s, which is only an example and does not limit the specific value of the preset time threshold.
[0042] Optionally, if the time interval is not within the preset time range, it means that the communication message may encounter network congestion or instability during transmission, resulting in actual transmission time exceeding the expected time. In this case, the problem encountered by the communication message during transmission can be further investigated, and appropriate measures can be taken to solve it. Then, the next to-be-tested function scene is triggered, and the communication security of the to-be-tested vehicle is tested in the next to-be-tested function scene.
[0043] Step S103, in response to the communication state of the communication information of the to-be-tested vehicle being in the safe state when communicating in the remaining to-be-tested function scenes, controlling the to-be-tested vehicle to move.
[0044] In the technical solution provided by the above step S103 of the present application, when the communication state of the communication information of the to-be-tested vehicle is tested in the remaining to-be-tested function scenes, and it is determined that the communication state of the communication information of the to-be-tested vehicle is in the safe state when communicating in the remaining to-be-tested function scenes, the vehicle can be controlled to move, and then the communication security of the to-be-tested vehicle in multiple to-be-tested scenes is tested.
[0045] In this embodiment, the to-be-tested vehicle is controlled to move a target distance at a time, and after each movement, the communication security of the moved to-be-tested vehicle in multiple to-be-tested function scenes is tested to test the communication capability of the vehicle in the actual driving process.
[0046] Step S104, respectively sending abnormal communication messages to the moved to-be-tested vehicle in multiple to-be-tested function scenes.
[0047] In the technical solution provided in the above step S104 of the present invention, when the cumulative moving distance of the vehicle exceeds the preset distance threshold, an abnormal communication message can be sent to the vehicle to be tested after it moves in multiple functional scenarios to be tested, wherein the abnormal communication message can be a tampered or forged message, wherein the preset distance threshold can be 10km, which is only an illustrative example and does not limit the specific value of the preset distance threshold.
[0048] In this embodiment, in response to the cumulative movement distance of the vehicle to be tested exceeding a preset distance threshold, an abnormal communication message is sent to the vehicle to be tested according to the functional scenario to be tested, and the recognition result of the abnormal communication message by the vehicle to be tested is determined based on whether the vehicle to be tested communicates after receiving the abnormal communication message.
[0049] Step S105 , in response to the vehicle to be tested identifying the abnormal communication message, determining that the information security test of the vehicle to be tested is successful.
[0050] In the technical solution provided in the above-mentioned step S105 of the present invention, after sending the abnormal communication message to the vehicle to be tested, it can be determined whether the vehicle to be tested communicates after receiving the abnormal communication message. If the vehicle to be tested does not communicate after receiving the abnormal communication message, that is, the vehicle to be tested does not trigger the communication function, it means that the vehicle to be tested has identified the abnormal communication message.
[0051] In this embodiment, after testing the ability of the vehicle to be tested to identify abnormal communication messages in a functional scenario to be tested, the next functional scenario to be tested can be continued to be traversed to determine whether the vehicle to be tested will trigger the communication function after receiving the abnormal communication message in the next functional scenario to be tested, until all functional scenarios to be tested are tested and the vehicle to be tested does not trigger the communication function. In this case, it means that the information security test of the vehicle to be tested is successful, that is, the communication information of the vehicle to be tested is secure, and the vehicle to be tested can identify the abnormal communication message received during the communication process.
[0052] Optionally, the functional scenarios to be tested in steps S101 to S105 can be created in a cyber range. A cyber range is a type of network technology simulation and verification platform that combines a virtual environment with real equipment to simulate a real-world testing environment. Based on this, the test system can use the cyber range to test the communication security of the vehicle under test in different functional scenarios.
[0053] Optionally, the communication security test of the vehicle to be tested can be performed in a laboratory scenario or an outdoor scenario, and the testing method is relatively flexible.
[0054] It should be noted that the above-mentioned communication security test on the vehicle to be tested is aimed at the device under test in the vehicle to be tested, such as the On-Board Unit (OBU).
[0055] Through the above steps S101 to S105, when the communication function of the vehicle under test is in a normal state, multiple test function scenarios are traversed to test the communication status of the communication information of the vehicle under test when communicating in the multiple test function scenarios. This can comprehensively evaluate the communication function of the vehicle under test in different scenarios and ensure the communication security of the vehicle under test in different scenarios. When the communication status of the communication information of the vehicle under test in multiple test function scenarios is all safe, the vehicle is controlled to move, and after the vehicle moves, the vehicle's communication function is tested in multiple test function scenarios. This helps to evaluate the vehicle's communication capabilities during actual driving. By identifying abnormal communication messages, it can be determined whether the information security test of the vehicle under test is successful, which helps to evaluate the anti-interference capability of the vehicle under test. That is to say, the security of the communication information of the vehicle under test during the communication process is tested separately in multiple functional scenarios to be tested. The communication security function of the vehicle under test can be comprehensively evaluated in different scenarios. After moving the vehicle under test, the vehicle under test's ability to recognize abnormal communication messages is tested, and the communication capability and anti-interference capability of the vehicle under test during driving are evaluated. By testing the information security performance of the vehicle under test in different functional scenarios, the technical effect of comprehensively testing the vehicle's information security function is achieved, thereby solving the technical problem of incomplete information security testing of the vehicle.
[0056] The above method of this embodiment is further introduced below.
[0057] As an optional implementation, step S101 tests the communication status of the communication information of the vehicle under test in the current functional scenario to be tested, including: sending a first communication message to the vehicle under test, wherein the first communication message is a message signed by the private key of the digital certificate; obtaining a first signature verification result of the first communication message by the vehicle under test, wherein the first signature verification result is obtained by the vehicle under test using the public key in the digital certificate to verify the signature of the first communication message; based on the first signature verification result, determining the communication status of the communication information of the vehicle under test in the current functional scenario to be tested.
[0058] In this embodiment, the current functional scenario to be tested can be any scenario in the V2X scenario. When testing the communication status of the communication information of the vehicle to be tested in the current functional scenario to be tested, the private key of the digital certificate can be used to sign the first communication message. Then, the first communication message and the digital certificate are broadcast. After receiving the first communication message, the vehicle to be tested can perform signature verification on the first communication message to obtain a first signature verification result to determine whether the first communication message has been tampered with during transmission.
[0059] Optionally, after performing signature verification on the first communication message, the vehicle under test may determine the communication status of the vehicle under test's communication information in the current functional scenario under test based on the first signature verification result. If the first signature verification result indicates that the signature verification of the first communication message has passed, then the communication status of the vehicle under test's communication information in the current functional scenario under test is secure, i.e., the first communication message has not been tampered with during transmission. Conversely, if the first signature verification result indicates that the signature verification of the first communication message has failed, then the communication status of the vehicle under test's communication information in the current functional scenario under test is unsecure, i.e., the first communication message may have been tampered with during transmission.
[0060] Optionally, if the communication information of the vehicle to be tested is in a safe state in the current functional scenario to be tested, the remaining functional scenarios to be tested can be traversed to determine whether the communication information of the vehicle to be tested is in a safe state in the remaining functional scenarios to be tested, so as to achieve a comprehensive assessment of the security of the communication information of the vehicle to be tested.
[0061] As an optional implementation, obtaining the first signature verification result of the vehicle under test for the first communication message includes: obtaining the verification result of the digital certificate in the first communication message by the vehicle under test, wherein the verification result is used to indicate the legality and validity of the digital certificate; in response to the verification result indicating that the digital certificate is legal and valid, obtaining the first signature verification result.
[0062] In this embodiment, when the vehicle under test receives the first communication message and performs signature verification on the first communication message, it is necessary to first verify the digital certificate that signs the first communication message to determine the legitimacy and validity of the digital certificate that signs the first communication message. After the digital certificate is verified, the public key in the digital certificate is used to verify the private key that signs the first communication message to obtain a first signature verification result.
[0063] Optionally, when performing signature verification on the first communication message, the digital certificate of the first communication message is first verified to ensure the legitimacy and validity of the certificate. After the digital certificate verification is passed, the public key in the certificate is used to perform signature verification on the communication message, thereby enhancing the security of the communication, ensuring the integrity and authenticity of the communication, and preventing unauthorized access and tampering.
[0064] As an optional implementation, based on the first signature verification result, the communication status of the communication information of the vehicle to be tested in the functional scenario to be tested is determined, including: in response to the first signature verification result indicating that the first communication message is secure during transmission, determining that the communication information of the vehicle to be tested is in a secure state when communicating in the functional scenario to be tested.
[0065] In this embodiment, after the vehicle under test performs signature verification on the first communication message and obtains a first signature verification result, if the first signature verification result indicates that the first communication message is secure during transmission, it can be determined that the first communication message has not been tampered with during transmission. In this case, it can be determined that the communication information of the vehicle under test is in a secure state when communicating in the functional scenario under test.
[0066] In this step, by performing signature verification on the first communication message, the security of the communication message during transmission is ensured, which helps prevent malicious tampering or theft of information.
[0067] As an optional implementation, in response to the communication information being in a safe state, traverse the remaining functional scenarios to be tested except the current functional scenario to be tested in multiple functional scenarios to be tested, including: in response to the communication information of the vehicle to be tested being in a safe state in the current functional scenario to be tested, obtain a second communication message fed back by the vehicle to be tested, wherein the second communication message corresponds to the first communication message; determine the interval duration between sending the first communication message and receiving the second communication message; in response to the interval duration being less than a preset duration threshold, traverse the next functional scenario to be tested, and test the communication status of the communication information of the vehicle to be tested in the next functional scenario to be tested.
[0068] In this embodiment, when testing the communication status of a vehicle's communication information in a functional scenario under test, if the vehicle's communication information is in a safe state in the current functional scenario under test, the vehicle under test may feedback a second communication message. After receiving the second communication message, the test system may further determine the time interval between the time the second communication message was received and the time the first communication message was sent, and then compare this time interval with a preset duration threshold. If the time interval is within the preset duration threshold, it indicates that the network status is good. In this case, the test system may proceed to the next functional scenario under test to test the communication status of the vehicle's communication information in the next functional scenario under test.
[0069] Optionally, by comparing the time interval between receiving the second communication message and sending the first communication message, the communication performance of the vehicle can be measured more accurately and the network status of the vehicle communication can be determined.
[0070] As an optional implementation, the vehicle information security testing method also includes: forging the private key and the public key in the digital certificate to obtain a forged private key and a forged public key; signing a first communication message using the forged private key; sending the first communication message signed using the forged private key to the vehicle to be tested; obtaining a second signature verification result of the first communication message from the vehicle to be tested; and in response to the second signature verification result indicating that the vehicle to be tested has identified the forged private key and the forged public key, determining that the security authentication function of the vehicle to be tested is normal.
[0071] In this embodiment, in order to test whether the security authentication function of the vehicle to be tested is normal, a denial of service attack (DoS) can be carried out on the vehicle to be tested by constructing a malformed message to test whether the security authentication function of the vehicle to be tested is normal.
[0072] For example, when sending a communication message to a vehicle under test, the private key in the digital certificate is used to sign the message. Upon receiving the message, the vehicle under test verifies the signature using the public key in the digital certificate. In this case, to fully test the vehicle's security authentication capabilities, the private and public keys in the digital certificate can be forged to verify whether the vehicle under test can detect forged private and public keys.
[0073] Optionally, after forging the private key and public key of the digital certificate, the forged private key can be used to sign the first communication message, and then the signed first communication message is sent to the vehicle under test, and a second signature verification result of the first communication message by the vehicle under test is obtained.
[0074] Optionally, if the second signature verification result indicates that the vehicle under test recognizes the forged private key and public key, it means that the vehicle under test successfully detects the forged private key and the forged public key. In this case, it is determined that the security authentication function of the vehicle under test is normal.
[0075] As an optional implementation, after sending an abnormal communication message to the moved vehicle to be tested, the vehicle information security testing method also includes: obtaining the recognition result of the abnormal communication message by the moved vehicle to be tested; in response to the recognition result indicating that the moved vehicle to be tested has recognized the abnormal communication message, determining that the information security test of the vehicle to be tested is successful.
[0076] In this embodiment, after moving the vehicle to be tested and sending an abnormal communication message to the moved vehicle to be tested, the client obtains the recognition result of the abnormal communication message by the vehicle to be tested. If the vehicle to be tested can recognize the abnormal communication message, it is determined that the information security test of the vehicle to be tested is successful.
[0077] Optionally, when sending abnormal communication messages to the vehicle under test, the abnormal communication messages may be mixed with normal communication messages, so as to verify the recognition ability of the vehicle under test for abnormal communication messages.
[0078] As an optional implementation, the vehicle information security testing method further includes: sending a request message to the vehicle to be tested; and determining that the communication function of the vehicle to be tested is in a normal state in response to receiving a response message fed back by the vehicle to be tested.
[0079] In this embodiment, when testing the communication security of the vehicle under test, it is first necessary to ensure that the vehicle under test can communicate normally. For example, a request message can be sent to the vehicle under test to determine whether a response message is received from the vehicle under test. If a response message is received from the vehicle under test, it indicates that the communication function of the vehicle under test is normal.
[0080] In the above steps, when the communication function of the vehicle under test is in a normal state, multiple test function scenarios are traversed to test the communication status of the communication information of the vehicle under test when communicating in the multiple test function scenarios. This can comprehensively evaluate the communication function of the vehicle under test in different scenarios and ensure the communication security of the vehicle under test in different scenarios. When the communication status of the communication information of the vehicle under test in multiple test function scenarios is all safe, the vehicle is controlled to move, and after the vehicle moves, the communication function of the vehicle is tested in multiple test function scenarios. This helps to evaluate the communication capability of the vehicle during actual driving. By identifying abnormal communication messages, it can be determined whether the information security test of the vehicle under test is successful, which helps to evaluate the anti-interference capability of the vehicle under test. That is to say, the security of the communication information of the vehicle under test during the communication process is tested separately in multiple functional scenarios to be tested. The communication security function of the vehicle under test can be comprehensively evaluated in different scenarios. After moving the vehicle under test, the vehicle under test's ability to recognize abnormal communication messages is tested, and the communication capability and anti-interference capability of the vehicle under test during driving are evaluated. By testing the information security performance of the vehicle under test in different functional scenarios, the technical effect of comprehensively testing the vehicle's information security function is achieved, thereby solving the technical problem of incomplete information security testing of the vehicle.
[0081] The technical solutions of the embodiments of the present invention are described below with reference to preferred implementation methods.
[0082] Currently, V2X technology has become a key enabler for autonomous driving. It enables communication between vehicles (V2V), between vehicles and infrastructure (V2I), between vehicles and pedestrians, bicycles, and other vehicles (V2P), and between vehicles and the network (V2N). It provides crucial support for the development of autonomous vehicles and intelligent transportation systems, compensating for the limited line-of-sight of traditional on-board sensors such as cameras and radar, and improving vehicle perception in special conditions like intersections and inclement weather. However, because V2X technology transmits data via wireless communication, it carries potential information security risks.
[0083] Related technologies mainly test the vehicle's V2X communication function in a simulation environment, or test the communication protocol. However, this type of test focuses on specific scenarios or performance parameters and fails to fully cover the various scenarios and security threats that V2X technology may encounter in actual applications. Therefore, there is a technical problem of incomplete vehicle information security testing.
[0084] However, the present invention provides a vehicle information security testing method, which constructs a realistic smart car scenario through a network target range, and tests the V2X communication function of the tested vehicle in each functional scenario in turn to determine whether the communication information of the tested vehicle is secure during the communication process. If the communication information of the tested vehicle is in a secure state during communication in each functional scenario, the tested vehicle is moved a target distance, and then continues to traverse each functional scenario to test whether the tested vehicle can identify forged messages to determine the tested vehicle's ability to identify forged messages. By testing the communication information security of the tested vehicle and its ability to identify forged messages in each functional scenario, the vehicle's communication security can be tested in all scenarios, achieving the technical effect of comprehensive testing of the vehicle's communication information, thereby solving the technical problem of incomplete vehicle information security testing.
[0085] Next, we will further introduce the network target range.
[0086] A cyber range is a type of network technology simulation and verification platform used for attack and defense drills, product security assessments, and new technology verification to enhance and strengthen system security, stability, and performance. It is core infrastructure in the cyberspace security field. By combining a virtual environment with real equipment, a cyber range can simulate a real-world test environment. In this application, a cyber range is used to construct a variety of test scenarios to test the vehicle's communication security performance, allowing for unlimited test scenarios.
[0087] The network range architecture includes: infrastructure, range basic platform, vehicle access system, resource library, emergency response center, etc.
[0088] Infrastructure includes: laboratories, large display screens, server clusters, and a laboratory exhibition hall that integrates automotive network development and verification capabilities, shooting range attack and defense drills, and test equipment displays.
[0089] Range basic platform: used to realize core functions such as large-scale network construction, real-time test command, user behavior monitoring, situation display and range interconnection.
[0090] Vehicle Access System: This system connects the range platform to the actual vehicle and test bench, providing multiple physical access interfaces to achieve virtual-real connectivity. It also provides the software interfaces required to access the purely virtual environment, enabling remote access and vehicle control of the test bench and electronic control unit (ECU) within the purely virtual environment through the range platform.
[0091] Resource library: Bringing together test cases, test tools, virtual and real targets, knowledge graphs, etc., can build a large-scale resource library.
[0092] Emergency Response Center: This center handles network attacks and security incidents. By monitoring network traffic and system logs, it promptly detects and responds to malicious activity, protecting network and system security. When security incidents occur, it quickly implements measures to investigate and address them, restoring normal system operations as quickly as possible. In cyber ranges, the Emergency Response Center is a crucial component of ensuring network security.
[0093] Next, we will further introduce the V2X security testing platform.
[0094] Figure 2 Schematic diagram of a V2X security detection platform according to an embodiment of the present application. Figure 2 As shown, the V2X security testing platform 200 includes: a testing system (TS) 201 and a device under test (DUT) 202.
[0095] The test system 201 includes a test system report generation module 2011, a test system management module 2012, a test system execution module 2013, a test environment infrastructure platform 2014, a test control system 2015, a test case library 2016, and a test simulation system 2017. The test environment infrastructure platform 2014 includes driving data simulation for field and laboratory testing, as well as V2X and Long-Term Evolution (LTE-PC5) data simulation. The test control system 2015 includes a project wizard, a core editor, underlying resources, and a test component design and execution module.
[0096] The system under test 202 includes: a vehicle 2021, an on-board unit (OBU) / roadside unit (RSU) 2022 and a safety demonstration system 2023.
[0097] Optionally, the V2X data simulation includes a V2X message encapsulation and parsing module, which can generate and parse V2X data and provide V2X data simulation functions, support LTE-PC5 data simulation, and support LTE-V2X network data transmission and reception simulation functions.
[0098] Driving data simulation supports both laboratory and field testing scenarios. In field testing, the vehicle uses satellite positioning signals to guide driving behavior according to the test case requirements, and then drives in the field test site to complete the test execution.
[0099] During laboratory testing, a Global Navigation Satellite System (GNSS) signal amplifier (ANA) provides the necessary satellite signals for communication modules and completes testing of the device under test (DUT), which can be either an OBU or a RSU. A GPS signal amplifier is used as a GNSS signal amplifier to achieve comprehensive functionality. When the indoor GPS signal is weak, the ANA can transmit the outdoor GPS signal indoors or in other environments where GPS reception is unavailable. This provides GPS signals to communication modules, OBUs, RSUs, and other devices, enabling V2X testing requiring GPS to be completed indoors.
[0100] Next, the V2X information security testing process is further introduced.
[0101] During direct V2X communication, the test system uses the private key of the digital certificate to sign the message to be sent. The signed message is then broadcast along with the digital certificate. Upon receiving the message, the device under test extracts the digital certificate. First, the legitimacy and validity of the digital certificate are verified to ensure the message has not been tampered with or forged. The message signature is then verified using the public key in the verified digital certificate. Simulating V2X data allows testing of the controller's signature verification mechanism, constructing malformed messages, conducting DoS attacks, verifying the integrity of secure messages, and testing cross-domain mutual recognition mechanisms through scenario simulation.
[0102] Figure 3 This is a flow chart of a V2X message security testing method according to an embodiment of the present application. Figure 3As shown, the method includes the following steps:
[0103] Step S301: Send a request frame.
[0104] In this embodiment, the test system may send a request frame to the instruction forwarding module of the device under test through a control channel.
[0105] Step S302: Send a request message.
[0106] In this embodiment, after receiving the request frame sent by the test system, the instruction forwarding module in the device under test may generate a request message according to the request frame, and send the request message to the network protocol stack in the device under test.
[0107] Step S303: Feedback a response message.
[0108] In this embodiment, after receiving the request message, the network protocol stack in the device under test may feed back a response message to the instruction forwarding module of the device under test.
[0109] Step S304: Feedback a response frame.
[0110] In this embodiment, after receiving the response message, the instruction forwarding module in the device under test may generate a response frame according to the response message and feed the response frame back to the test system to inform the test system that the communication link of the device under test is unobstructed.
[0111] Step S305: Send a C-V2X message.
[0112] In this embodiment, after the test system determines that the communication link of the device under test is unobstructed, a C-V2X message may be sent to the network protocol stack of the device under test.
[0113] Step S306: Send a network protocol message.
[0114] In this embodiment, after the network protocol stack in the device under test receives the C-V2X message, it can generate a network protocol message based on the C-V2X message and send the network protocol message to the security module in the device under test.
[0115] Step S307: perform signature verification on the network protocol message.
[0116] In this embodiment, after receiving the network protocol message, the security module in the device under test may perform signature verification on the network protocol message to determine whether the network protocol message has been tampered with.
[0117] Step S308: Feedback the signature verification result.
[0118] In this embodiment, after performing security verification on the network protocol message, the security module in the device under test can feed back the signature verification result to the network protocol stack of the device under test.
[0119] Step S309: Feedback a notification message of the signature verification result.
[0120] In this embodiment, after receiving the signature verification result, the network protocol stack in the device under test can feed back the signature verification result to the instruction forwarding module of the device under test, and the instruction forwarding module then feeds back the signature verification result to the test system.
[0121] Optionally, the network protocol stack inside the device under test may also decide whether to continue processing the message based on the signature verification result of the security module.
[0122] Optionally, the above-mentioned test system may be a network target range, and the above-mentioned device under test may be an on-board unit in a vehicle to be tested. This is only an illustrative example and does not impose any specific limitations on the test system and the device under test.
[0123] In the above steps S301 to S309, the message transmission and feedback between the test system and the device under test are realized through the mutual interaction between the test system and the device under test, thereby ensuring the reliability and timeliness of communication. The security of communication data is ensured through the transmission and security verification of security layer messages, thereby preventing the risks of information leakage and network attacks.
[0124] Next, we will further introduce the vehicle information security testing method.
[0125] Figure 4 is a flow chart of an information security testing method according to an embodiment of the present application. Figure 4 As shown, the method includes the following steps:
[0126] Step S401: Start the device under test.
[0127] In this embodiment, when starting to test the information security of the device under test, the testing system may start the device under test, wherein the device under test may be a vehicle.
[0128] Step S402: determine whether the device under test can apply for a certificate.
[0129] In this embodiment, the test system can determine whether the device under test has the ability to apply for a certificate from a Certificate Authority (CA). If the application is possible, step S403 is executed. If the application is not possible, the information security test of the device under test is determined to have failed. The certificate can be a digital certificate.
[0130] Step S403: determine whether the device under test can download the certificate.
[0131] In this embodiment, after confirming that the device under test can apply for a certificate from the CA system, the test system may further confirm whether the device under test has the ability to download the certificate from the CA system. If so, step S404 is executed; otherwise, it is confirmed that the information security test of the device under test has failed.
[0132] Step S404: determine whether the CA system can resolve the pseudonym certificate and provide a response message.
[0133] In this embodiment, the test system can determine whether the CA system can parse the pseudonym certificate and give a response message to ensure that the CA system can effectively identify and process the pseudonym certificate, thereby improving the security and stability of the system. If so, step S405 is executed; otherwise, it is confirmed that the information security test of the device under test has failed.
[0134] Step S405: determine whether the device under test can detect forged signature private keys.
[0135] In this embodiment, the test system can determine whether the device under test can detect forged signature private keys. If so, this indicates that the device under test has an effective private key verification mechanism. In other words, the device under test can identify forged private keys, thereby ensuring data security and integrity. It should be noted that if the device under test can detect forged signature private keys, step S406 is executed. Otherwise, the information security test on the device under test is determined to have failed.
[0136] Step S406: determine whether the device under test can detect forged signature public keys.
[0137] In this embodiment, the test system can determine whether the device under test can detect forged signature public keys. If it can, it means that the device under test has certain security and protection mechanisms. In this case, step S407 can be executed. Otherwise, it is confirmed that the information security test of the device under test has failed.
[0138] Step S407: determine whether the device under test can detect whether the certificate has been tampered with.
[0139] In this embodiment, the test system can determine whether the device under test can detect whether the digital certificate has been tampered with. If it can, it means that the device under test has an effective certificate verification mechanism and can detect the integrity and authenticity of the digital certificate. In this case, step S408 can be continued. Otherwise, it is confirmed that the information security test of the device under test has failed.
[0140] Step S408: Send a message containing illegal information to the device under test.
[0141] In this embodiment, the test system can send messages containing illegal information to the device under test to test whether the device under test can identify illegal messages, monitor the security performance of the device under test, confirm whether the device under test can effectively prevent malicious attacks and data leakage, and further evaluate the performance and response capabilities of the device under test when facing various security threats. Among them, illegal messages may include: illegal security message version number, illegal generation time of the data to be signed, illegal hash algorithm of the data to be signed, illegal application information of the data to be signed, illegal security message signer type, illegal security message signature information, illegal security message certificate version, illegal security message certificate summary, illegal security message certificate validity period, illegal security message certificate chain, and illegal security message certificate signature.
[0142] Step S409: Determine whether the feedback message from the device under test is invalid.
[0143] In this embodiment, the test system can determine whether the device under test will feedback that the received message is invalid after receiving information containing an illegal message. If the device under test feedbacks that the received message is invalid, it means that the device under test has identified the illegal message in the information. In this case, it means that the security test of the device under test has passed, and step S410 can be continued. On the contrary, if the device under test does not feedback that the received message is invalid, it means that the device under test has not detected the illegal information in the message. In this case, it can be determined that the security test of the device under test has failed.
[0144] Step S410: Determine the time for the device under test to feed back a C-V2X message.
[0145] In this embodiment, the test system may send a C-V2X message to the device under test. After receiving the C-V2X message sent by the test system, the device under test may feedback a C-V2X message to the test system. If the interval between the time the test system sends the C-V2X message and the time the device under test feedbacks the C-V2X message is less than 300 seconds, it indicates that the information security test of the device under test is successful in the current functional scenario. In this case, step S411 may be executed to trigger the next functional scenario. The functional scenario may be a C-V2X functional scenario, which may include: V2V scenario, V2P scenario, V2I scenario, and V2N scenario.
[0146] Step S411, triggering the next functional scenario.
[0147] In this embodiment, after the information security test of the device under test is passed in the previous functional scenario, the next functional scenario can be traversed to test the information security function of the device under test in the next functional scenario until all functional scenarios are tested.
[0148] Step S412: Verify the pseudonym certificate and digest policy in the C-V2X message sent by the device under test.
[0149] In this embodiment, after the next functional scenario is triggered, the pseudonym certificate and the digest policy in the C-V2X message sent by the device under test may be verified in the functional scenario, and then step S413 is executed.
[0150] Step S413: Determine whether the pseudonym certificate and the digest policy have been verified.
[0151] In this embodiment, it can be determined whether the pseudonym certificate and the digest policy in the C-V2X message sent by the device under test are verified. If the verification is successful, step S414 is executed. If the verification fails, it is determined that the security test of the device under test has failed.
[0152] Step S414: determine whether all functional scenarios have been traversed.
[0153] In this embodiment, the test system can determine whether all functional scenarios have been traversed, that is, whether the information security functions of the vehicle under test have been tested in all functional scenarios. If all tests are completed, step S415 is executed; if not, step S410 is returned to be executed.
[0154] Step S415: Move the device under test.
[0155] In this embodiment, the position of the device under test may be moved by a preset distance, wherein the preset distance may be 2 km. This is merely an example and does not impose any specific limitation on the distance the device under test may move.
[0156] Step S416: Check whether the distance moved by the device under test exceeds the target distance.
[0157] In this embodiment, it is possible to accumulate whether the distance moved by the device under test exceeds the target distance. If not, the functional scenarios are continued to be traversed, and step S411 is returned to be executed to test the information security function of the device under test. If the distance moved by the device under test exceeds the target distance, step S417 is executed, wherein the target distance can be 10 km. This is only an illustrative example and does not limit the specific value of the target distance moved by the device under test.
[0158] Step S417: Send the tampered C-V2X message to the device under test according to the functional scenario.
[0159] In this embodiment, if the distance moved by the device under test exceeds the target distance, a tampered C-V2X message is sent to the device under test according to the functional scenario to test the device under test's ability to recognize the tampered message.
[0160] Step S418, detecting whether the C-V2X function of the device under test is triggered.
[0161] In this embodiment, after sending the tampered C-V2X message to the device under test, it can be detected whether the C-V2X function of the device under test is triggered. If the C-V2X function of the device under test is not triggered, step S419 is performed to determine whether all function scenarios are traversed. If the C-V2X function of the device under test is triggered, it means that the device under test does not detect the tampered message, and it is determined that the information security test of the device under test fails.
[0162] Step S419, determining whether all function scenarios are traversed.
[0163] In this embodiment, after moving the device under test and sending the tampered C-V2X message to the device under test, it can be detected whether all function scenarios of the device under test are traversed. If all function scenarios of the device under test are not traversed, step S420 is performed to traverse the next function scenario. If all function scenarios of the device under test are traversed, it means that the device under test can recognize the tampered C-V2X message in all function scenarios, and in this case, it is determined that the information security test of the device under test succeeds.
[0164] In steps S401-S420 described above, by detecting whether the device under test has the recognition ability of the forged certificate, the forged private key and the forged public key, the security and credibility of the device under test can be determined. After determining that the device under test is safe, all function scenarios can be further traversed to test the information security of the device under test in all function scenarios, and then the device under test is moved to test the recognition ability of the device under test to the forged information in all function scenarios, so as to achieve the technical effect of comprehensively testing the device under test, and further solve the technical problem that the information security test of the device under test is not comprehensive.
[0165] According to the embodiments of the present application, a vehicle information security test device is also provided. It should be noted that the vehicle information security test device can be used to execute the vehicle information security test method in embodiment 1.
[0166] Figure 5 is a schematic diagram of a vehicle information security test device according to an embodiment of the present application. As shown in Figure 5 the vehicle information security test device 500 can include a first test unit 501, a second test unit 502, a control unit 503, a third test unit 504 and a determination unit 505.
[0167] The first test unit 501 is used to test the communication status of the communication information of the vehicle to be tested in the current function scenario to be tested in response to the communication function of the vehicle to be tested being in a normal state, wherein the communication information is generated during the communication process of the vehicle to be tested in the current function scenario to be tested, the function scenario to be tested is used to indicate the scenario of communication between the vehicle and other traffic participants, and the communication status is used to indicate that the communication information is in a safe state during the communication process, or the communication information is in an unsafe state during the communication process.
[0168] The second testing unit 502 is configured to, in response to the communication status being a safe status, traverse the remaining functional scenarios to be tested except the current functional scenario to be tested in the plurality of functional scenarios to be tested, and test the communication status of the communication information of the vehicle to be tested in the remaining functional scenarios to be tested.
[0169] The control unit 503 is configured to control the movement of the vehicle to be tested in response to the communication state of the communication information of the vehicle to be tested being a safe state when communicating in the remaining functional scenarios to be tested.
[0170] The third testing unit 504 is configured to send abnormal communication messages to the vehicle under test after it moves in a plurality of functional scenarios under test, wherein the abnormal communication messages are used to indicate messages containing abnormal information.
[0171] The determining unit 505 is configured to determine that the information security test on the vehicle to be tested is successful in response to the vehicle to be tested identifying the abnormal communication message.
[0172] Optionally, the first test unit 501 includes: a sending module for sending a first communication message to the vehicle to be tested, wherein the first communication message is a message signed by the private key of the digital certificate; an acquisition module for obtaining a first signature verification result of the first communication message by the vehicle to be tested, wherein the first signature verification result is obtained by the vehicle to be tested using the public key in the digital certificate to perform signature verification on the first communication message; a determination module for determining the communication status of the communication information of the vehicle to be tested in the current functional scenario to be tested based on the first signature verification result.
[0173] Optionally, the acquisition module is further used to: obtain the verification result of the digital certificate in the first communication message by the vehicle under test, wherein the verification result is used to indicate the legality and validity of the digital certificate; in response to the verification result indicating that the digital certificate is legal and valid, obtain the first signature verification result.
[0174] Optionally, the determination module is further configured to determine that communication information of the vehicle to be tested is in a secure state when communicating in the functional scenario to be tested, in response to the first signature verification result indicating that the first communication message is secure during transmission.
[0175] Optionally, the first test unit 501 is also used to: in response to the communication information of the vehicle to be tested being in a safe state in the current functional scenario to be tested, obtain a second communication message fed back by the vehicle to be tested, wherein the second communication message corresponds to the first communication message; determine the interval between sending the first communication message and receiving the second communication message; in response to the interval being less than a preset duration threshold, traverse the next functional scenario to be tested, and test the communication status of the communication information of the vehicle to be tested in the next functional scenario to be tested.
[0176] Optionally, the vehicle information security testing device 500 is also used to: forge the private key and the public key in the digital certificate to obtain a forged private key and a forged public key; use the forged private key to sign a first communication message; send the first communication message signed with the forged private key to the vehicle under test; obtain a second signature verification result of the first communication message from the vehicle under test; in response to the second signature verification result indicating that the vehicle under test has identified the forged private key and the forged public key, determine that the security authentication function of the vehicle under test is normal.
[0177] Optionally, the vehicle information security testing device 500 is further used to: obtain the recognition result of the abnormal communication message by the moved vehicle under test; in response to the recognition result indicating that the moved vehicle under test recognizes the abnormal communication message, determine that the information security test of the vehicle under test is successful.
[0178] Optionally, the vehicle information security testing device 500 is further configured to: send a request message to the vehicle under test; and determine, in response to receiving a response message fed back by the vehicle under test, whether the communication function of the vehicle under test is in a normal state.
[0179] In this embodiment, when the communication function of the vehicle under test is in a normal state, multiple test function scenarios are traversed to test the communication status of the communication information of the vehicle under test when communicating in the multiple test function scenarios. This allows for a comprehensive evaluation of the communication function of the vehicle under test in different scenarios to ensure the communication security of the vehicle under test in different scenarios. When the communication status of the communication information of the vehicle under test in the multiple test function scenarios is all safe, the vehicle is controlled to move, and after the vehicle moves, the communication function of the vehicle is tested in the multiple test function scenarios. This helps to evaluate the communication capability of the vehicle during actual driving. By identifying abnormal communication messages, it can be determined whether the information security test of the vehicle under test is successful, which helps to evaluate the anti-interference capability of the vehicle under test. That is to say, the security of the communication information of the vehicle under test during the communication process is tested separately in multiple functional scenarios to be tested. The communication security function of the vehicle under test can be comprehensively evaluated in different scenarios. After moving the vehicle under test, the vehicle under test's ability to recognize abnormal communication messages is tested, and the communication capability and anti-interference capability of the vehicle under test during driving are evaluated. By testing the information security performance of the vehicle under test in different functional scenarios, the technical effect of comprehensively testing the vehicle's information security function is achieved, thereby solving the technical problem of incomplete information security testing of the vehicle.
[0180] An embodiment of the present application further provides an electronic device, comprising: a memory storing an executable program; and a processor for running the program, wherein the vehicle information security testing method in each embodiment of the present invention is executed when the program is running.
[0181] An embodiment of the present application also provides a computer-readable storage medium, which includes a stored executable program, wherein when the executable program is running, the device where the computer-readable storage medium is located is controlled to execute the vehicle information security testing method in each embodiment of the present invention.
[0182] An embodiment of the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements the vehicle information security testing method in various embodiments of the present invention.
[0183] An embodiment of the present application also provides a computer program product, including a non-volatile computer-readable storage medium, which is used to store a computer program. When the computer program is executed by a processor, it implements the vehicle information security testing method in various embodiments of the present invention.
[0184] An embodiment of the present application further provides a computer program, which, when executed by a processor, implements the vehicle information security testing method in each of the above-mentioned embodiments of the present invention.
[0185] An embodiment of the present application also provides a vehicle, which is used to execute the vehicle information security testing method in each embodiment of the present invention.
[0186] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0187] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0188] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0189] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0190] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0191] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.
[0192] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A vehicle information security testing method, characterized in that: include: In response to the communication function of the vehicle under test being in a normal state, testing the communication state of the communication information of the vehicle under test in the current function scenario under test, wherein the communication information is generated by the vehicle under test during communication in the current function scenario under test, the function scenario under test is used to indicate a scenario in which communication is performed between the vehicle under test and other traffic participants, and the communication state is used to indicate that the communication information is in a safe state during the communication process, or that the communication information is in an unsafe state during the communication process; In response to the communication state being the safe state, traversing the remaining function scenarios to be tested except the current function scenario to be tested in a plurality of function scenarios to be tested, and testing the communication state of the communication information of the vehicle to be tested in the remaining function scenarios to be tested; In response to the communication state of the vehicle under test being the safe state when communicating in the remaining functional scenarios under test, controlling the vehicle under test to move; sending abnormal communication messages to the vehicle under test after it moves in each of the plurality of functional scenarios under test, wherein the abnormal communication messages are used to indicate messages containing abnormal information; In response to the vehicle to be tested identifying the abnormal communication message, it is determined that the information security test of the vehicle to be tested is successful.
2. The method according to claim 1, characterized in that Testing the communication status of the communication information of the vehicle to be tested in the current functional scenario to be tested includes: Sending a first communication message to the vehicle to be tested, wherein the first communication message is a message signed by a private key of a digital certificate; Obtaining a first signature verification result of the first communication message by the vehicle under test, wherein the first signature verification result is obtained by the vehicle under test performing signature verification on the first communication message using the public key in the digital certificate; Based on the first signature verification result, a communication status of the communication information of the vehicle to be tested in the current function scenario to be tested is determined.
3. The method according to claim 2, characterized in that Obtaining a first signature verification result of the first communication message by the vehicle under test, including: Obtaining a verification result of the digital certificate in the first communication message by the vehicle under test, wherein the verification result is used to indicate the legitimacy and validity of the digital certificate; In response to the verification result indicating that the digital certificate is legal and valid, the first signature verification result is obtained.
4. The method according to claim 2, characterized in that Determining, based on the first signature verification result, a communication status of the communication information of the vehicle to be tested in the functional scenario to be tested, including: In response to the first signature verification result indicating that the first communication message is secure during transmission, it is determined that the communication information is in the secure state when the vehicle to be tested communicates in the functional scenario to be tested.
5. The method according to claim 2, characterized in that In response to the communication state being the secure state, traversing the remaining function scenarios to be tested except the current function scenario to be tested in the plurality of function scenarios to be tested, including: In response to the communication information of the vehicle under test being in the safe state in the current functional scenario under test, obtaining a second communication message fed back by the vehicle under test, wherein the second communication message corresponds to the first communication message; Determining an interval between sending the first communication message and receiving the second communication message; In response to the interval duration being less than a preset duration threshold, traversing the next function scenario to be tested, and testing the communication status of the communication information of the vehicle to be tested in the next function scenario to be tested.
6. The method according to claim 2, characterized in that The method further comprises: Forging the private key and the public key in the digital certificate to obtain the forged private key and the forged public key; Signing the first communication message using the forged private key; Sending the first communication message signed by the forged private key to the vehicle to be tested; Obtaining a second signature verification result of the first communication message by the vehicle under test; In response to the second signature verification result indicating that the vehicle under test recognizes the forged private key and the forged public key, it is determined that the security authentication function of the vehicle under test is normal.
7. The method according to claim 1, characterized in that After sending the abnormal communication message to the vehicle to be tested after moving, the method further includes: Obtaining a recognition result of the abnormal communication message by the vehicle to be tested after moving; In response to the recognition result indicating that the moved vehicle to be tested recognizes the abnormal communication message, it is determined that the information security test of the vehicle to be tested is successful.
8. The method according to claim 1, characterized in that The method further comprises: Sending a request message to the vehicle to be tested; In response to receiving a response message fed back by the vehicle to be tested, it is determined that the communication function of the vehicle to be tested is in a normal state.
9. A vehicle information security testing device, characterized in that: include: a first testing unit, configured to test, in response to a communication function of the vehicle under test being in a normal state, a communication state of communication information of the vehicle under test in a current function scenario under test, wherein the communication information is generated by the vehicle under test during communication in the current function scenario under test, the function scenario under test being used to indicate a scenario in which communication is performed between the vehicle under test and other traffic participants, and the communication state being used to indicate that the communication information is in a safe state during the communication process, or that the communication information is in an unsafe state during the communication process; a second testing unit, configured to, in response to the communication state being the safe state, traverse remaining function scenarios to be tested except the current function scenario to be tested in a plurality of function scenarios to be tested, and test the communication state of the communication information of the vehicle to be tested in the remaining function scenarios to be tested; a control unit, configured to control the movement of the vehicle to be tested in response to the communication state of the vehicle to be tested being the safe state when communicating in the remaining functional scenarios to be tested; A third testing unit is configured to send abnormal communication messages to the vehicle under test after it moves in each of the plurality of functional scenarios under test, wherein the abnormal communication messages are used to indicate messages containing abnormal information; A determination unit is configured to determine that the information security test on the vehicle to be tested is successful in response to the vehicle to be tested identifying the abnormal communication message.
10. An electronic device, characterized in that: include: a memory storing an executable program; A processor, configured to run the program, wherein the program executes the method according to any one of claims 1 to 8 when running.
11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores an executable program, wherein when the executable program is running, the device where the storage medium is located is controlled to execute the method according to any one of claims 1 to 8.
12. A computer program product, characterized in that The invention comprises a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Penetration test method and device of vehicle-mounted network, test equipment and storage medium
CN116389024A
Communication performance test method and device, computer equipment and storage medium
CN117915358A