Method and device for detecting information security production consistency of vehicle and electronic equipment

By performing key injection and penetration testing on components and verifying the effective closure of the debug port, the problem of being unable to verify whether the debug port of a component is closed in the existing technology is solved, and production consistency of component information security is achieved.

CN119109818BActive Publication Date: 2025-10-10CHERY AUTOMOBILE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411153819.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-21
Publication Date
2025-10-10
Estimated Expiration
2044-08-21

AI Technical Summary

Technical Problem

Existing technologies cannot effectively verify whether the debugging port of a component is truly closed, resulting in the inability to ensure production consistency of component information security.

Method used

By receiving key information, black box and white box testing are performed to determine the opening status and opening times of the debug port, and security test information is generated to verify the effective closing of the debug port.

Benefits of technology

Ensure production consistency of component information security, verify the effective closure of the debug port through key injection and penetration testing methods, and improve vehicle safety and production consistency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119109818B_ABST
    Figure CN119109818B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of vehicles, in particular to a method and device for detecting information security production consistency of a vehicle and electronic equipment, wherein the method comprises the following steps: receiving a target component injected with first key information, and performing black box testing on the target component to obtain a black box testing result; if the black box testing result meets first preset testing conditions, performing white box testing on the target component to generate a white box testing result of the target component; and if the white box testing result meets second preset conditions, generating security testing information of the target component. Thus, the method can verify whether a debugging port of a component is effectively closed, thereby guaranteeing the production consistency of the information security of the component.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle technology, and in particular to a method, device, and electronic equipment for detecting the consistency of vehicle information safety production. Background Art

[0002] With the in-depth development of the Internet of Vehicles and information security technologies, various information security attacks have occurred frequently, and the information security risks faced by vehicles are becoming increasingly severe. In particular, the debugging ports of various controllers in the vehicle are easily used as attack entrances for information security attacks, posing a great information security risk, thereby reducing the safety of the vehicle. Therefore, a security strategy for the information security debugging ports of components is imperative.

[0003] In related technologies, most of them use physical removal or software encryption to disable the debug port. However, after mass production, it is impossible to know whether the debug port of the component is truly and effectively closed. Therefore, the production consistency of the component information security cannot be guaranteed, which urgently needs to be solved. Summary of the Invention

[0004] The present application provides a method, device and electronic equipment for detecting the information safety production consistency of a vehicle, so as to solve the problem that the detection methods of related technologies cannot verify whether the debugging port of a component is effectively closed, thereby failing to ensure the production consistency of the component information safety.

[0005] A first embodiment of the present application provides a method for detecting vehicle information safety production consistency, comprising the following steps:

[0006] receiving a target component for injecting first key information;

[0007] Performing a black box test on the target component to obtain the black box test result, and if the black box test result meets a first preset test condition, performing a white box test on the target component to generate a white box test result for the target component;

[0008] Determine whether the white box test result meets a second preset condition, and if the white box test result meets the second preset condition, generate safety test information of the target component.

[0009] According to one embodiment of the present application, if the black box test result meets the first preset test condition, it includes:

[0010] Opening the debug port of the target component based on a preset number of openings and using a preset key cracking method;

[0011] If the debug port of the target component is not open, it is determined that the black box test result meets the first preset test condition; otherwise, it is determined that the black box test result does not meet the first preset test condition.

[0012] According to one embodiment of the present application, determining whether the white box test result meets the second preset condition includes:

[0013] Using the second key information to open the debug port of the target component;

[0014] If the debug port of the target component is open, it is determined that the white box test result meets the second preset condition; otherwise, it is determined that the white box test result does not meet the second preset test condition.

[0015] According to one embodiment of the present application, determining whether the white-box test result meets the second preset condition further includes:

[0016] Determining whether a preset opening count of the debug port of the target component is greater than a preset opening count threshold;

[0017] If the preset opening times are greater than the preset opening times threshold, the opening request of the debug port of the target component is closed, and it is determined that the white box test result meets the second preset condition.

[0018] According to one embodiment of the present application, before receiving the target component injected with the first key information, the method further includes:

[0019] Reading the serial number of the target component;

[0020] The first key information and the second key information of the target component are generated according to the serial number.

[0021] According to the vehicle information security production consistency testing method of the embodiment of the present application, a target component is received with first key information injected, and a black-box test is performed on the target component to obtain a black-box test result. If the black-box test result meets a first preset test condition, a white-box test is performed on the target component to generate a white-box test result for the target component. If the white-box test result meets a second preset condition, security test information for the target component is generated. This solves the problem that related art testing methods cannot verify whether the component debug port is effectively closed, thereby failing to ensure the production consistency of component information security. By verifying the effective closure of the debug port through key injection and penetration testing of the component, the production consistency of component information security is ensured.

[0022] A second embodiment of the present application provides a device for detecting vehicle information safety production consistency, including:

[0023] A receiving module, configured to receive a target component into which the first key information is injected;

[0024] a testing module, configured to perform a black box test on the target component to obtain the black box test result; and if the black box test result satisfies a first preset test condition, perform a white box test on the target component to generate a white box test result for the target component;

[0025] A generating module is used to determine whether the white box test result meets a second preset condition, and if the white box test result meets the second preset condition, generate safety test information of the target component.

[0026] According to one embodiment of the present application, the testing module is specifically used to:

[0027] Opening the debug port of the target component based on a preset number of openings and using a preset key cracking method;

[0028] If the debug port of the target component is not open, it is determined that the black box test result meets the first preset test condition; otherwise, it is determined that the black box test result does not meet the first preset test condition.

[0029] According to one embodiment of the present application, the generating module is specifically configured to:

[0030] Using the second key information to open the debug port of the target component;

[0031] If the debug port of the target component is open, it is determined that the white box test result meets the second preset condition; otherwise, it is determined that the white box test result does not meet the second preset test condition.

[0032] According to one embodiment of the present application, the generating module is further configured to:

[0033] Determining whether a preset opening count of the debug port of the target component is greater than a preset opening count threshold;

[0034] If the preset opening times are greater than the preset opening times threshold, the opening request of the debug port of the target component is closed, and it is determined that the white box test result meets the second preset condition.

[0035] According to one embodiment of the present application, before receiving the target component injected with the first key information, the receiving module is further configured to:

[0036] Reading the serial number of the target component;

[0037] The first key information and the second key information of the target component are generated according to the serial number.

[0038] According to the vehicle information security production consistency detection device of the embodiment of the present application, a target component is received with first key information injected, and a black-box test is performed on the target component to obtain a black-box test result. If the black-box test result meets a first preset test condition, a white-box test is performed on the target component to generate a white-box test result for the target component. If the white-box test result meets a second preset condition, security test information for the target component is generated. This solves the problem that related art detection methods cannot verify whether the component debug port is effectively closed, thereby failing to ensure the production consistency of component information security. By verifying the effective closure of the debug port through key injection and penetration testing of the component, the production consistency of component information security is ensured.

[0039] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the program to implement a method for detecting the information safety production consistency of a vehicle as described in the above embodiment.

[0040] The fourth aspect of the present application provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the method for detecting the information safety production consistency of the vehicle as described in the above embodiment.

[0041] The fifth embodiment of the present application provides a computer program product, including a computer program, which is executed to implement the vehicle information safety production consistency detection method described in the above embodiment.

[0042] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0044] Figure 1 A flowchart of a method for detecting vehicle information safety production consistency according to an embodiment of the present application;

[0045] Figure 2 This is a specific control diagram of component debugging port safety detection according to one embodiment of the present application;

[0046] Figure 3 This is an example diagram of a device for detecting vehicle information safety production consistency according to an embodiment of the present application;

[0047] Figure 4 Schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0048] The following describes in detail embodiments of the present application. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0049] The following describes the vehicle information security production consistency detection method, device, and electronic device according to the embodiment of the present application with reference to the accompanying drawings. In response to the problem that the detection method of the related art mentioned in the background art cannot verify whether the debug port of a component is effectively closed, and thus cannot ensure the production consistency of the component information security, the present application provides a vehicle information security production consistency detection method. In this method, a black box test result is obtained. If the black box test result meets a first preset test condition, a white box test is performed on the target component to generate a white box test result of the target component. If the white box test result meets a second preset condition, security test information of the target component is generated. Thus, the problem that the detection method of the related art cannot verify whether the debug port of a component is effectively closed, and thus cannot ensure the production consistency of the component information security, is solved. By verifying the effective closure of the debug port through key injection and penetration testing of the component, the production consistency of the component information security is ensured.

[0050] Specifically, Figure 1 A flowchart of a method for detecting the consistency of vehicle information production safety provided in an embodiment of the present application.

[0051] like Figure 1 As shown, the method for detecting the information safety production consistency of the vehicle includes the following steps:

[0052] In step S101, a target component into which first key information is injected is received.

[0053] According to one embodiment of the present application, before receiving the target component injected with the first key information, it also includes: reading the serial number of the target component; generating the first key information and the second key information of the target component according to the serial number.

[0054] Specifically, in order to improve the safety of vehicles (for example, the development of vehicle functions should be based on regulations first, and meet regulatory requirements such as the EU R155 regulation and the domestic GB vehicle information security technical requirements), strengthen the consistency of the production of target vehicle parts (for example, ensure that the target parts produced and installed are compliant parts, and there will be no production consistency non-compliance issues in the after-sales market) and improve the technological sense of vehicle manufacturing (for example, meet daily needs and ensure driving safety), this application implements a vehicle information security consistency detection scheme, which mainly includes key injection equipment, penetration testing tools (penetration equipment) and target parts.

[0055] Among them, the key injection device is used to inject keys into the target components on the production line, and supports synchronous transmission of the key information of the target components to the penetration device, and supports information feedback showing the key injection results; the penetration testing tool is mainly used to perform penetration testing on the target components, such as performing key blasting black box testing on the target components, and feeding back the results of the penetration test. At the same time, it can receive the key information of the target components sent by the key injection device to support white box testing on the target component equipment, and can display the results of the white box test. At the same time, it supports exiting the penetration test mode, and the target components exit the debug port mode at the same time. After exiting the penetration test mode, the collected key information is automatically cleared to ensure the security of the key and prevent it from being leaked; the component (ie, the target component) is the tested unit of the black box test and the white box test. After the test is completed, the debugging mode of the component debug port can be exited, so that the key authentication needs to be re-performed the next time the debugging mode is entered.

[0056] Specifically, if Figure 2 As shown, when the target component of the embodiment of the present application is undergoing production safety consistency testing, first, the target component enters the component key injection station, and the SN (Serial Number) number of the target component is read by the key injection device. The key injection device generates the first key information (private key information) and the second key information (public key information) of the target component through the SN number and the key algorithm. The first key information and the second key information are the unique passwords for the target component test; secondly, the first key information, that is, the private key information, is injected into the target component through the key injection device, and the second key information, that is, the public key information, is encrypted and sent to the penetration testing tool in a secure transmission manner; finally, after receiving the first key information injection request, the target component activates the debug port closing function of the target component. At this time, the debug port of the target component is closed, and after the debug port of the target component is closed, the internal status of the target component and the activation information, that is, the second key information, are transmitted to the key injection device and displayed. The subsequent debug port of the target component requires the second key information to be opened.

[0057] In step S102, a black box test is performed on the target component to obtain a black box test result. If the black box test result meets the first preset test condition, a white box test is performed on the target component to generate a white box test result of the target component.

[0058] According to one embodiment of the present application, if the black box test result meets the first preset test condition, it includes: opening the debug port of the target component based on a preset number of openings and using a preset key blasting method; if the debug port of the target component is not opened, then it is determined that the black box test result meets the first preset test condition; otherwise, it is determined that the black box test result does not meet the first preset test condition.

[0059] Among them, the first preset test condition, the preset key blasting method and the preset number of opening times can all be selected by those skilled in the art according to actual test requirements and are not specifically limited here.

[0060] Specifically, after the penetration testing tool receives the target component injected with the first key information, it is necessary to perform a penetration test on the target component, that is, a black box test (that is, a test based on the external functions of the software). After the target component is opened a preset number of times (for example, 5 times) and the information security black box test is performed, if the penetration test cannot open the debug port of the target component based on the preset key blasting method, then it means that the information security black box test of the target component is completed, that is, the black box test result meets the first preset test condition, thereby proving that the information security measures have been implemented for the debug port of the component at this time; if the penetration test can open the debug port of the target component based on the preset key blasting method, then it is determined that the black box test result does not meet the first preset test condition, that is, the information security black box test of the target component is not completed, which indicates that there are certain security risks in the debug port, such as unauthorized access, data leakage, malware injection and other risks.

[0061] It should be noted that the preset key blasting method adopted in this application is an anti-blasting attack mode. In order to ensure the testing security of the debug port, when the number of penetration tests of the target component reaches the preset number of opening times, the target component will no longer be able to make a debug port opening request in a short period of time, and will need to wait until the time limit is reached before making another opening request.

[0062] Among them, the key injection equipment and penetration testing tools need to maintain a certain interval, because when the anti-explosion mechanism of the target component is triggered, a certain time interval is required for the anti-explosion mechanism to reset.

[0063] Furthermore, after the black box test results of the embodiment of the present application meet the first preset test conditions, white box testing is performed on the target component (i.e., allowing the test engineer to check the logic and structure inside the software to ensure that all code paths are executed correctly) to generate white box test results for the target component.

[0064] In step S103 , it is determined whether the white box test result meets the second preset condition. If the white box test result meets the second preset condition, safety test information of the target component is generated.

[0065] According to one embodiment of the present application, determining whether a white box test result satisfies a second preset condition includes: using second key information to open a debug port of a target component; if the debug port of the target component is opened, determining that the white box test result satisfies the second preset condition; otherwise, determining that the white box test result does not satisfy the second preset test condition.

[0066] According to one embodiment of the present application, determining whether the white box test result meets the second preset condition further includes: determining whether the preset number of openings of the debug port of the target component is greater than the preset opening number threshold; if the preset opening number is greater than the preset opening number threshold, closing the opening request of the debug port of the target component, and determining that the white box test result meets the second preset condition.

[0067] The second preset condition and the preset opening times threshold can be selected by those skilled in the art according to actual test requirements and are not specifically limited here.

[0068] Specifically, in an embodiment of the present application, after the black box test of the information security of the target component is completed, the white box test of the information security of the target component is performed. First, the debug port function of the target component is opened by the penetration testing tool using the second key information transmitted by the key injection device, and the white box test of the information security of the target component is performed. If the debug port of the target component is opened, it means that the white box test of the information security of the target component is successful, that is, the white box test result meets the second preset condition, and the security test information of the target component is generated, and the opening information is returned to the key injection device. If the debug port of the target component is not opened, it is determined that the white box test result does not meet the second preset test condition.

[0069] Optionally, since the target component of the embodiment of the present application is designed with an anti-blasting attack mode, when the number of component penetration tests, that is, the preset number of openings of the debug port reaches a preset opening threshold, the target component will no longer be able to make a debug port opening request within a short period of time, and will need to wait until the time limit is reached before making another opening request. After triggering the preset opening threshold, the penetration testing tool cannot try again, and the white box test is determined to be successful at this time, that is, the white box test result meets the second preset condition.

[0070] Furthermore, in the embodiment of the present application, after the white box test of the target component is successful, the target component exits the penetration test mode. At this time, the component debugging port is closed, and the penetration test equipment deletes the second key information of the target component, that is, deletes the public key information, so that after the information security production consistency test is successful, the target component can enter the subsequent production and testing links.

[0071] It should be noted that the key injection device used in the embodiment of the present application needs to be isolated from the external network to ensure that the key information will not be communicated with the external network, thereby ensuring the security of key transmission. At the same time, the key needs to be securely stored and transmitted in encrypted form to ensure that the key information cannot be easily read.

[0072] According to the vehicle information security production consistency testing method of the embodiment of the present application, a target component is received with first key information injected, and a black-box test is performed on the target component to obtain a black-box test result. If the black-box test result meets a first preset test condition, a white-box test is performed on the target component to generate a white-box test result for the target component. If the white-box test result meets a second preset condition, security test information for the target component is generated. This solves the problem that related art testing methods cannot verify whether the component debug port is effectively closed, thereby failing to ensure the production consistency of component information security. By verifying the effective closure of the debug port through key injection and penetration testing of the component, the production consistency of component information security is ensured.

[0073] Next, a device for detecting the consistency of vehicle information production safety proposed in an embodiment of the present application will be described with reference to the accompanying drawings.

[0074] Figure 3 It is a block diagram of a device for detecting the consistency of vehicle information safety production according to an embodiment of the present application.

[0075] like Figure 3 As shown, the vehicle information safety production consistency detection device 10 includes: a receiving module 100, a testing module 200 and a generating module 300.

[0076] The receiving module 100 is used to receive the target component injected with the first key information;

[0077] The testing module 200 is configured to perform a black box test on the target component to obtain a black box test result. If the black box test result satisfies a first preset test condition, a white box test is performed on the target component to generate a white box test result for the target component.

[0078] The generating module 300 is used to determine whether the white box test result meets the second preset condition, and if the white box test result meets the second preset condition, generate safety test information of the target component.

[0079] According to one embodiment of the present application, the testing module 200 is specifically configured to:

[0080] Open the debug port of the target component based on a preset number of openings and using a preset key cracking method;

[0081] If the debug port of the target component is not open, it is determined that the black box test result meets the first preset test condition; otherwise, it is determined that the black box test result does not meet the first preset test condition.

[0082] According to one embodiment of the present application, the generation module 300 is specifically configured to:

[0083] Using the second key information to open the debug port of the target component;

[0084] If the debug port of the target component is open, it is determined that the white box test result meets the second preset condition; otherwise, it is determined that the white box test result does not meet the second preset test condition.

[0085] According to one embodiment of the present application, the generating module 300 is further configured to:

[0086] Determine whether the preset opening times of the debug port of the target component is greater than the preset opening times threshold;

[0087] If the preset opening times are greater than the preset opening times threshold, the opening request of the debug port of the target component is closed, and it is determined that the white box test result meets the second preset condition.

[0088] According to one embodiment of the present application, before receiving the target component into which the first key information is injected, the receiving module 100 is further configured to:

[0089] Read the serial number of the target component;

[0090] The first key information and the second key information of the target component are generated according to the serial number.

[0091] According to the vehicle information security production consistency detection device of the embodiment of the present application, a target component is received with first key information injected, and a black-box test is performed on the target component to obtain a black-box test result. If the black-box test result meets a first preset test condition, a white-box test is performed on the target component to generate a white-box test result for the target component. If the white-box test result meets a second preset condition, security test information for the target component is generated. This solves the problem that related art detection methods cannot verify whether the component debug port is effectively closed, thereby failing to ensure the production consistency of component information security. By verifying the effective closure of the debug port through key injection and penetration testing of the component, the production consistency of component information security is ensured.

[0092] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include:

[0093] Memory 401 , processor 402 , and computer programs stored in the memory 401 and executable on the processor 402 .

[0094] When the processor 402 executes the program, the method for detecting the safety production consistency of the vehicle information provided in the above embodiment is implemented.

[0095] Furthermore, the electronic device further includes:

[0096] The communication interface 403 is used for communication between the memory 401 and the processor 402 .

[0097] The memory 401 is used to store computer programs that can be run on the processor 402 .

[0098] The memory 401 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0099] If the memory 401, the processor 402, and the communication interface 403 are implemented independently, the communication interface 403, the memory 401, and the processor 402 can be connected to each other via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0100] Optionally, in a specific implementation, if the memory 401, the processor 402 and the communication interface 403 are integrated on a chip, the memory 401, the processor 402 and the communication interface 403 can communicate with each other through an internal interface.

[0101] The processor 402 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0102] This embodiment also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-mentioned method for detecting the safety production consistency of vehicle information.

[0103] This embodiment also provides a computer program product, including a computer program, which is executed to implement the method for detecting the safety production consistency of vehicle information in the above embodiment.

[0104] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0105] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Thus, a feature specified as "first" or "second" may explicitly or implicitly include at least one such feature. In the description of this application, "N" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0106] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.

[0107] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or N wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or otherwise processing it in a suitable manner if necessary, and then storing it in a computer memory.

[0108] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiment, the N steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0109] Those skilled in the art will appreciate that all or part of the steps in the method for implementing the above-mentioned embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0110] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0111] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present application. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A method for detecting the consistency of vehicle information production safety, characterized in that: The following steps are involved: receiving a target component for injecting first key information; Performing a black box test on the target component to obtain the black box test result, and if the black box test result meets a first preset test condition, performing a white box test on the target component to generate a white box test result for the target component; determining whether the white box test result satisfies a second preset test condition, and generating safety test information of the target component if the white box test result satisfies the second preset test condition; Wherein, if the black box test result satisfies a first preset test condition, the method includes: opening the debug port of the target component based on a preset number of openings and using a preset key cracking method; if the debug port of the target component is not opened, determining that the black box test result satisfies the first preset test condition; otherwise, determining that the black box test result does not satisfy the first preset test condition; Determining whether the white-box test result satisfies a second preset test condition includes: using second key information to open a debug port of the target component; if the debug port of the target component is opened, determining that the white-box test result satisfies the second preset test condition; otherwise, determining that the white-box test result does not satisfy the second preset test condition; The determining whether the white box test result satisfies the second preset test condition further includes: determining whether the preset opening times of the debug port of the target component is greater than a preset opening times threshold; if the preset opening times are greater than the preset opening times threshold, closing the opening request of the debug port of the target component, and determining that the white box test result satisfies the second preset test condition.

2. The method according to claim 1, characterized in that Before receiving the target component injected with the first key information, the method further includes: Reading the serial number of the target component; The first key information and the second key information of the target component are generated according to the serial number.

3. A detection device for vehicle information safety production consistency, characterized in that: include: A receiving module, configured to receive a target component into which the first key information is injected; a testing module, configured to perform a black box test on the target component to obtain the black box test result; and if the black box test result satisfies a first preset test condition, perform a white box test on the target component to generate a white box test result for the target component; a generating module, configured to determine whether the white box test result satisfies a second preset test condition, and if so, to generate safety test information of the target component; The test module is specifically configured to: open the debug port of the target component based on a preset number of openings and using a preset key cracking method; if the debug port of the target component is not opened, determine that the black box test result meets the first preset test condition; otherwise, determine that the black box test result does not meet the first preset test condition; The generating module is specifically configured to: use the second key information to open the debug port of the target component; if the debug port of the target component is opened, determine that the white box test result meets the second preset test condition; otherwise, determine that the white box test result does not meet the second preset test condition; The generation module is further configured to determine whether the preset number of times the debug port of the target component is opened is greater than a preset opening number threshold; if the preset number of times the debug port is opened is greater than the preset opening number threshold, close the opening request of the debug port of the target component, and determine that the white box test result meets the second preset test condition.

4. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method for detecting the information safety production consistency of a vehicle as described in any one of claims 1 to 2.

5. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the method for detecting the information safety production consistency of a vehicle as described in any one of claims 1-2.

Citation Information

Patent Citations

  • Data security test method and device, vehicle and storage medium

    CN117768354A

  • Network system penetration test method and device

    CN118316654A