A Bluetooth diagnostic encryption level test evaluation method, system and device

By obtaining and decrypting the link key in the Bluetooth communication message and combining it with data comparison, the accuracy problem of Bluetooth diagnostic encryption level assessment is solved, and the accurate identification of the Bluetooth communication encryption level is achieved.

CN119383613BActive Publication Date: 2025-09-19XIANGYANG DAAN AUTOMOBILE TEST CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411493750.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-24
Publication Date
2025-09-19
Estimated Expiration
2044-10-24

AI Technical Summary

Technical Problem

The existing technology lacks an accurate Bluetooth diagnostic encryption level assessment method, and is unable to effectively determine whether Bluetooth communications have undergone encryption processing at the link layer and application layer.

Method used

By obtaining the Bluetooth communication message between the diagnostic instrument and the vehicle, it is determined whether the link key can be extracted, and the link key is used to decrypt the second Bluetooth communication message. Combined with the comparison of the first Bluetooth diagnostic data and the second Bluetooth diagnostic data, it is determined whether the Bluetooth diagnosis uses link layer and application layer encryption.

Benefits of technology

It achieves accurate assessment of Bluetooth diagnostic encryption levels and can identify whether Bluetooth communications are encrypted only at the link layer or both at the link layer and application layer, improving the accuracy and consistency of the assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119383613B_ABST
    Figure CN119383613B_ABST
Patent Text Reader

Abstract

A Bluetooth diagnostic encryption level test and evaluation method, system, and device belong to the field of information security testing, including obtaining a first Bluetooth communication message stored on the diagnostic instrument side and a second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument; determining whether a link key can be extracted from the first Bluetooth communication message, and if so, extracting first Bluetooth diagnostic data from the first Bluetooth communication message and using the link key to decrypt the second Bluetooth communication message to obtain second Bluetooth diagnostic data; if not, determining that the Bluetooth communication is unencrypted; determining whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent, and if so, determining that the Bluetooth diagnosis uses link layer encryption and application layer encryption when the first Bluetooth diagnostic data is in an encrypted state, and determining that the Bluetooth diagnosis uses link layer encryption when the first Bluetooth diagnostic data is in an unencrypted state; if not, determining that the Bluetooth diagnosis is unencrypted. This application can accurately analyze the specific encryption level of Bluetooth diagnosis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security testing, and specifically to a Bluetooth diagnostic encryption level test and evaluation method, system, and device. Background Art

[0002] In addition to using the OBD (On-Board Diagnostics) physical interface to directly connect to the diagnostic instrument, automotive diagnostic technology also considers its physical space expansion issues and adopts wireless diagnostic methods such as remote diagnosis and Bluetooth diagnosis. Among them, some car companies tend to use Bluetooth diagnosis methods considering the stability and cost issues of remote networks.

[0003] As the number of external communication interfaces in vehicles increases, IoV information security issues are becoming more frequent, with short-range communication security being a key concern. Many IoV information security standards include encryption requirements for IoV Bluetooth communications. For example, GB / T 40856, "Technical Requirements and Test Methods for Information Security of In-Vehicle Information Interaction Systems," mandates encryption of data for high-security in-vehicle Bluetooth communication functions. International regulation WP.29R155 also mandates that confidential data transmitted to or from the vehicle be protected in the event of information surveillance leaks.

[0004] Regarding encryption security testing in automotive Bluetooth diagnostic scenarios, there are currently few test cases, and the industry only stipulates that data transmitted through Bluetooth communications must be encrypted, but there is no requirement for the encryption mechanism level, whether only link layer encryption is performed or application layer encryption is also required. Therefore, a standardized testing method is needed for Bluetooth diagnostic encryption level assessment. Summary of the Invention

[0005] The present application provides a Bluetooth diagnostic encryption level test and evaluation method, system and device, which can solve the technical problem in the prior art of being unable to accurately grasp the security encryption level of Bluetooth diagnosis.

[0006] In a first aspect, an embodiment of the present application provides a Bluetooth diagnostic encryption level test and evaluation method, the method comprising:

[0007] When performing Bluetooth diagnosis on a vehicle using a diagnostic instrument, obtaining a first Bluetooth communication message stored on the diagnostic instrument side and a second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument;

[0008] Determining whether a link key can be extracted from the first Bluetooth communication message, if so, extracting the first Bluetooth diagnostic data from the first Bluetooth communication message, and decrypting the second Bluetooth communication message using the link key to obtain the second Bluetooth diagnostic data; if not, determining that the Bluetooth communication is not encrypted;

[0009] Determine whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent. If so, determine that the Bluetooth diagnosis adopts link layer encryption and application layer encryption when the first Bluetooth diagnostic data is in an encrypted state; and determine that the Bluetooth diagnosis adopts link layer encryption when the first Bluetooth diagnostic data is in an unencrypted state; if not, determine that the Bluetooth diagnosis does not adopt encryption processing.

[0010] In conjunction with the first aspect, in one embodiment, the method includes:

[0011] The second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument is obtained by using an air packet capture device.

[0012] In conjunction with the first aspect, in one embodiment, the method includes:

[0013] All Bluetooth frequency bands are monitored to obtain the second Bluetooth communication message.

[0014] In conjunction with the first aspect, in one embodiment, the method includes:

[0015] Obtain a host control interface HCI log from the diagnostic instrument side, and extract the first Bluetooth communication message from the HCI log.

[0016] In conjunction with the first aspect, in one embodiment, obtaining the HCI log specifically includes the following steps:

[0017] Connect the universal serial bus (USB) interface on the diagnostic instrument to a data acquisition device with a USB cable, and the data acquisition device sends a debug bridge ABD instruction to obtain the HCI log from the diagnostic instrument side.

[0018] In conjunction with the first aspect, in one embodiment, obtaining the HCI log specifically includes the following steps:

[0019] Connect the wireless communication interface on the diagnostic instrument to a data acquisition device with wireless communication function, and the data acquisition device sends the debug bridge ABD command or remote port debugging command to obtain the HCI log from the diagnostic instrument side.

[0020] In conjunction with the first aspect, in one implementation, extracting the first Bluetooth communication message specifically includes the following steps:

[0021] Filter the HCI log by link key feature matching to filter out the link key exchange process data and the first Bluetooth diagnostic data;

[0022] Extract the link key from the link key exchange process data.

[0023] In conjunction with the first aspect, in one embodiment, the method includes:

[0024] When it is determined that the first Bluetooth diagnostic data contains diagnostic plaintext information, the first Bluetooth diagnostic data is determined to be in an unencrypted state; when it is determined that the first Bluetooth diagnostic data does not contain diagnostic plaintext information, the first Bluetooth diagnostic data is determined to be in an encrypted state.

[0025] In a second aspect, an embodiment of the present application provides a Bluetooth diagnostic encryption level test and evaluation system, the system comprising:

[0026] A data acquisition module, which is used to acquire a first Bluetooth communication message stored on the diagnostic instrument side and a second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument when the diagnostic instrument is used to perform Bluetooth diagnosis on the vehicle;

[0027] A data processing module, which is used to determine whether a link key can be extracted from a first Bluetooth communication message. If so, first Bluetooth diagnostic data is extracted from the first Bluetooth communication message, and the second Bluetooth communication message is decrypted using the link key to obtain second Bluetooth diagnostic data; if not, it is determined that the Bluetooth communication does not adopt encryption processing; it is also used to determine whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent. If so, it is determined that the Bluetooth diagnosis adopts link layer encryption and application layer encryption when the first Bluetooth diagnostic data is in an encrypted state, and when the first Bluetooth diagnostic data is in an unencrypted state, it is determined that the Bluetooth diagnosis adopts link layer encryption; if not, it is determined that the Bluetooth diagnosis does not adopt encryption processing.

[0028] In the third aspect, an embodiment of the present application provides a Bluetooth diagnostic encryption level test and evaluation device, which includes a processor, a memory, and a Bluetooth diagnostic encryption level test and evaluation program stored on the memory and executable by the processor, wherein when the Bluetooth diagnostic encryption level test and evaluation program is executed by the processor, the steps of the Bluetooth diagnostic encryption level test and evaluation method are implemented.

[0029] The beneficial effects of the technical solutions provided in the embodiments of the present application include:

[0030] When link layer encryption is adopted, the diagnostic instrument will automatically extract the link key and decrypt the message after receiving the second Bluetooth communication message sent by the vehicle to obtain the first Bluetooth diagnostic data. The link key and the first Bluetooth diagnostic data are stored in the diagnostic instrument as the first Bluetooth communication message. If link layer encryption is not adopted, the link key cannot be extracted. However, in some special cases, the link key can be extracted even if link layer encryption is adopted but the encryption operation is unsuccessful. At this time, the encryption level can be analyzed based on subsequent judgment operations.

[0031] Since the link key will not change during transmission, if link layer encryption is adopted, the second Bluetooth diagnostic data obtained after decrypting the second Bluetooth communication message using the link key should theoretically be consistent with the first Bluetooth diagnostic data. If the first Bluetooth diagnostic message is in an unencrypted state, it means that application layer encryption has not been performed on the basis of link layer encryption. If the first Bluetooth diagnostic message is in an encrypted state, it means that application layer encryption has been performed on the basis of link layer encryption. Through the above multiple judgments, the specific encryption level of Bluetooth diagnosis can be accurately analyzed. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 This is a flowchart of an embodiment of a Bluetooth diagnostic encryption level test and evaluation method of the present application;

[0033] Figure 2 This is a schematic diagram of the architecture of an embodiment of a Bluetooth diagnostic encryption level test and evaluation system of the present application;

[0034] Figure 3 This is a schematic diagram of the hardware structure of the Bluetooth diagnostic encryption level test and evaluation device involved in the embodiment of the present application. DETAILED DESCRIPTION

[0035] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0036] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0037] In a first aspect, an embodiment of the present application provides a Bluetooth diagnostic encryption level test and evaluation method.

[0038] In one embodiment, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the Bluetooth diagnostic encryption level test and evaluation method of this application. Figure 1 As shown, the Bluetooth diagnostic encryption level test evaluation method includes:

[0039] Step S1: When using a diagnostic instrument to perform Bluetooth diagnosis on a vehicle, a first Bluetooth communication message stored on the diagnostic instrument side and a second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument are obtained.

[0040] Step S2: Determine whether the link key can be extracted from the first Bluetooth communication message. If so, extract the first Bluetooth diagnostic data from the first Bluetooth communication message and decrypt the second Bluetooth communication message using the link key to obtain the second Bluetooth diagnostic data. If not, determine that the Bluetooth communication is not encrypted.

[0041] Step S3: Determine whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent. If so, determine that the Bluetooth diagnostic data uses link layer encryption and application layer encryption if the first Bluetooth diagnostic data is encrypted. If the first Bluetooth diagnostic data is unencrypted, determine that the Bluetooth diagnostic data uses link layer encryption. If not, determine that the Bluetooth diagnostic data does not use encryption.

[0042] In this embodiment, when a diagnostic instrument performs Bluetooth diagnostics on a vehicle, Bluetooth communication messages are exchanged between the instrument and the vehicle. For example, the instrument sends a Bluetooth diagnostic data acquisition request message to the vehicle, and the vehicle returns a message containing Bluetooth diagnostic data to the instrument. During Bluetooth diagnostic operations, Bluetooth diagnostic encryption levels can be categorized as unencrypted, link-layer encryption only, and link-layer encryption supplemented by application-layer encryption. Identifying and analyzing these encryption levels is crucial for assessing the security and accuracy of Bluetooth diagnostics.

[0043] The principle of the test and evaluation method is explained. The Bluetooth communication message transmitted between the vehicle and the diagnostic instrument is defined as the second Bluetooth communication message. The first Bluetooth communication message is defined as the result of the diagnostic instrument receiving and processing the second Bluetooth communication message. If encryption is not performed, the link key cannot be extracted from the first Bluetooth communication message. In step S2, if the link key cannot be extracted, it is directly determined that encryption measures have not been adopted. However, in some special cases, for example, the diagnostic instrument and the vehicle will negotiate to obtain a link key, but this link key is not effectively used for link-layer encryption during Bluetooth diagnosis. In this case, the link key can also be extracted from the first Bluetooth communication message, and then the encryption level needs to be further analyzed in the subsequent step S3.

[0044] If link layer encryption is used, first, after receiving the second Bluetooth communication message, the diagnostic instrument will automatically extract the link key to decrypt the message to obtain the first Bluetooth diagnostic data. The link key and the first Bluetooth diagnostic data are stored in the diagnostic instrument as the first Bluetooth communication message. Secondly, the second Bluetooth diagnostic data after decrypting the second Bluetooth communication message using the link key should theoretically be consistent with the first Bluetooth diagnostic data, because the Bluetooth diagnostic data decrypted according to the same link layer encryption and decryption protocol should be the same. If they are inconsistent, it means that the link layer encryption operation is not used, because the first Bluetooth diagnostic data extracted from the first Bluetooth communication message is data that is not decrypted using the link key and is directly extracted data, while the second Bluetooth diagnostic data extracted from the second Bluetooth communication message is data decrypted using the link key and is data that has been decrypted. Therefore, the two will not be consistent.

[0045] After determining whether to perform encryption operation based on whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent, if the two are consistent, determine whether application layer encryption is performed on the basis of link layer encryption based on whether the first Bluetooth diagnostic data is in an encrypted state. If it is in an encrypted state, application layer encryption is performed; if it is in an unencrypted state, application layer encryption is not performed.

[0046] Through these multiple assessments, we can meet the requirements for testing and evaluating the encryption security level in connected vehicle scenarios using Bluetooth diagnostics. We can analyze whether encryption is actually being used between the diagnostic instrument and the vehicle when using Bluetooth diagnostics, and can also detect and evaluate the encryption level, whether only link-layer encryption is used, or whether both the link and application layers are encrypted. Furthermore, by standardizing the test steps and process methods, we can address the issues of inaccurate and inconsistent test and evaluation results caused by human factors.

[0047] Furthermore, in one embodiment, the method includes:

[0048] The second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument is obtained by using an air packet capture device.

[0049] In this embodiment, by calling a Bluetooth broadband sniffing device, that is, an air packet capture device, to capture the Bluetooth broadcast communication message, that is, the second Bluetooth communication message, when the diagnostic instrument and the vehicle perform Bluetooth diagnostic communication, the data in transmission is directly captured and intercepted, thereby improving data acquisition efficiency.

[0050] Furthermore, in one embodiment, the method includes:

[0051] All Bluetooth frequency bands are monitored to obtain the second Bluetooth communication message.

[0052] In this embodiment, the air packet capture device starts working, sniffing the Bluetooth MAC addresses of the diagnostic instrument and the vehicle, and detecting whether the target object is in an activated state. When the Bluetooth of both parties is activated, the air packet capture device starts broadband sniffing and monitors the messages on 79 Bluetooth frequency band channels at the same time to obtain all types of Bluetooth communication messages.

[0053] Furthermore, in one embodiment, the method includes:

[0054] A host control interface (HCI) log is obtained from the diagnostic instrument, and the first Bluetooth communication message is extracted from the HCI log.

[0055] In this embodiment, after the diagnostic instrument receives the second Bluetooth communication message, if link layer encryption is used, the message is automatically decrypted and stored in the HCI log. If encryption is not used, the message is processed in other ways and stored in the HCI log. In other embodiments, in addition to the HCI log, data can also be stored in other storage units.

[0056] In a specific embodiment, the diagnostic instrument HCI layer log message is recorded and collected based on the Bluetooth module log printing function in the Android developer mode of the diagnostic instrument, and the log content is based on the Bluetooth HCI layer.

[0057] Furthermore, in one embodiment, the above-mentioned obtaining of HCI logs specifically includes the following steps:

[0058] Connect the universal serial bus (USB) interface on the diagnostic instrument to a data acquisition device with a USB cable, and the data acquisition device sends a debug bridge ABD instruction to obtain the HCI log from the diagnostic instrument side.

[0059] In this embodiment, if the tester integrates the local ADB (Android Debug Bridge) debugging function, the data acquisition device is directly connected to the physical interface of the diagnostic instrument through a USB (Universal Serial Bus) debugging line, and then uses the ADB debugging command to export the Bluetooth HCI log file of the diagnostic instrument system side.

[0060] Furthermore, in one embodiment, the above-mentioned obtaining of HCI logs specifically includes the following steps:

[0061] Connect the wireless communication interface on the diagnostic instrument to a data acquisition device with wireless communication function, and the data acquisition device sends the debug bridge ABD command or remote port debugging command to obtain the HCI log from the diagnostic instrument side.

[0062] In this embodiment, if the tester integrates commonly used remote port debugging such as the scp (used to copy files between the local computer and the remote server) function in the SSH (Secure Shell) service, the data acquisition device can also be wirelessly networked with the diagnostic instrument via WiFi or Ethernet, and use remote debugging instructions such as the scp instruction of port 22 (SSH service) or the adb pull instruction of port 5555 (remote ADB debugging service) through the remote debugging port service to export the Bluetooth HCI log file collected by the diagnostic instrument system end according to the Bluetooth HCI log address of the diagnostic instrument.

[0063] Furthermore, in one embodiment, the extracting of the first Bluetooth communication message specifically includes the following steps:

[0064] Filter the HCI log by link key feature matching to filter out the link key exchange process data and the first Bluetooth diagnostic data.

[0065] Extract the link key from the link key exchange process data.

[0066] In this embodiment, HCI log messages are filtered by link key feature matching to screen out the link key exchange process data between the diagnostic instrument and the vehicle and extract the 32-bit link key between the diagnostic instrument and the vehicle.

[0067] According to the principle of the Bluetooth protocol stack, the application layer data messages in the HCI log in which the communicating parties complete the key negotiation, start sending the connection request and perform the Bluetooth diagnosis normally are filtered out, and the corresponding content of the first Bluetooth diagnostic data is extracted.

[0068] The extracted link key is imported into the corresponding host computer software of the air packet capture device, and the link key encryption and decryption algorithm specified in the Bluetooth protocol is applied to the Bluetooth broadcast message decryption, and the decrypted payload content, that is, the second Bluetooth diagnostic data, is extracted.

[0069] Furthermore, in one embodiment, the method includes:

[0070] When it is determined that the first Bluetooth diagnostic data contains diagnostic plaintext information, the first Bluetooth diagnostic data is determined to be in an unencrypted state; when it is determined that the first Bluetooth diagnostic data does not contain diagnostic plaintext information, the first Bluetooth diagnostic data is determined to be in an encrypted state.

[0071] In this embodiment, the application layer data in the Bluetooth HCI log is analyzed based on the diagnostic protocol to determine whether there is any leakage of plaintext information related to the diagnostic service, so as to determine whether the application layer encryption processing mechanism is adopted when the diagnostic instrument and the vehicle end perform Bluetooth diagnostic communication, and output the corresponding results.

[0072] In a specific embodiment, a diagnostic service ID and a diagnostic command identifier (DID) are predefined according to the general diagnostic protocol specification. The diagnostic service ID and DID service are specified in the ISO 14229-1 standard, including the scope of use and the content represented by some commonly used DIDs. For example, the read operation service ID is 0x22, and the DID used for the vehicle VIN (Vehicle Identification Number) is F190. "22F1 90..." indicates that the diagnostic instrument wishes to read the vehicle VIN number as Bluetooth diagnostic data. The vehicle responds with "62F1 90" followed by the VIN code, which is the Bluetooth diagnostic data. If the first Bluetooth diagnostic data extracted from the first Bluetooth communication message is determined to be plaintext information, it indicates that the Bluetooth diagnostic only uses link-layer encryption. If not, it indicates that the Bluetooth diagnostic also uses application-layer encryption in addition to link-layer encryption.

[0073] In summary, the present invention discloses a method for assessing the security level of Bluetooth diagnostic encryption in connected vehicles. This method extracts a link key and applies it to decrypt Bluetooth broadcast sniffing data. The decrypted Bluetooth broadcast sniffing data is then compared and analyzed with data in the Bluetooth HCI log to verify whether the link key is effectively used for link-layer data encryption during communication between the two parties. Furthermore, the Bluetooth diagnostic communication data is analyzed according to the diagnostic protocol to verify whether the application-layer data encryption mechanism is employed.

[0074] In a second aspect, an embodiment of the present application also provides a Bluetooth diagnostic encryption level test and evaluation system.

[0075] In one embodiment, referring to Figure 2 , Figure 2 This is a functional module diagram of an embodiment of the Bluetooth diagnostic encryption level test and evaluation device of this application. Figure 2 As shown, the Bluetooth diagnostic encryption level test and evaluation device includes:

[0076] The data acquisition module 1 is used to acquire a first Bluetooth communication message stored on the diagnostic instrument side and a second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument when the diagnostic instrument is used to perform Bluetooth diagnosis on the vehicle.

[0077] Data processing module 2 is used to determine whether a link key can be extracted from the first Bluetooth communication message. If so, it extracts the first Bluetooth diagnostic data from the first Bluetooth communication message and decrypts the second Bluetooth communication message using the link key to obtain the second Bluetooth diagnostic data. If not, it determines that the Bluetooth communication does not employ encryption. It is also used to determine whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent. If so, it determines that the Bluetooth diagnosis employs link layer encryption and application layer encryption if the first Bluetooth diagnostic data is encrypted, and if the first Bluetooth diagnostic data is unencrypted, it determines that the Bluetooth diagnosis employs link layer encryption. If not, it determines that the Bluetooth diagnosis does not employ encryption.

[0078] In this embodiment, when a diagnostic instrument performs Bluetooth diagnostics on a vehicle, Bluetooth communication messages are exchanged between the instrument and the vehicle. For example, the instrument sends a Bluetooth diagnostic data acquisition request message to the vehicle, and the vehicle returns a message containing Bluetooth diagnostic data to the instrument. During Bluetooth diagnostic operations, Bluetooth diagnostic encryption levels can be categorized as unencrypted, link-layer encryption only, and link-layer encryption supplemented by application-layer encryption. Identifying and analyzing these encryption levels is crucial for assessing the security and accuracy of Bluetooth diagnostics.

[0079] The principle of the test and evaluation method is explained. The Bluetooth communication message transmitted between the vehicle and the diagnostic instrument is defined as the second Bluetooth communication message. The first Bluetooth communication message is defined as the result of the diagnostic instrument receiving and processing the second Bluetooth communication message. If encryption is not performed, the link key cannot be extracted from the first Bluetooth communication message. In step S2, if the link key cannot be extracted, it is directly determined that encryption measures have not been adopted. However, in some special cases, for example, the diagnostic instrument and the vehicle will negotiate to obtain a link key, but this link key is not effectively used for link-layer encryption during Bluetooth diagnosis. In this case, the link key can also be extracted from the first Bluetooth communication message, and then the encryption level needs to be further analyzed in the subsequent step S3.

[0080] If link layer encryption is used, first, after receiving the second Bluetooth communication message, the diagnostic instrument will automatically extract the link key to decrypt the message to obtain the first Bluetooth diagnostic data. The link key and the first Bluetooth diagnostic data are stored in the diagnostic instrument as the first Bluetooth communication message. Secondly, the second Bluetooth diagnostic data after decrypting the second Bluetooth communication message using the link key should theoretically be consistent with the first Bluetooth diagnostic data, because the Bluetooth diagnostic data decrypted according to the same link layer encryption and decryption protocol should be the same. If they are inconsistent, it means that the link layer encryption operation is not used, because the first Bluetooth diagnostic data extracted from the first Bluetooth communication message is data that is not decrypted using the link key and is directly extracted data, while the second Bluetooth diagnostic data extracted from the second Bluetooth communication message is data decrypted using the link key and is data that has been decrypted. Therefore, the two will not be consistent.

[0081] After determining whether to perform encryption operation based on whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent, if the two are consistent, determine whether application layer encryption is performed on the basis of link layer encryption based on whether the first Bluetooth diagnostic data is in an encrypted state. If it is in an encrypted state, application layer encryption is performed; if it is in an unencrypted state, application layer encryption is not performed.

[0082] Through these multiple assessments, we can meet the requirements for testing and evaluating the encryption security level in connected vehicle scenarios using Bluetooth diagnostics. We can analyze whether encryption is actually being used between the diagnostic instrument and the vehicle when using Bluetooth diagnostics, and can also detect and evaluate the encryption level, whether only link-layer encryption is used, or whether both the link and application layers are encrypted. Furthermore, by standardizing the test steps and process methods, we can address the issues of inaccurate and inconsistent test and evaluation results caused by human factors.

[0083] Among them, the functional implementation of each module in the above-mentioned Bluetooth diagnostic encryption level test and evaluation device corresponds to the various steps in the above-mentioned Bluetooth diagnostic encryption level test and evaluation method embodiment, and their functions and implementation processes are no longer repeated here.

[0084] In a third aspect, an embodiment of the present application provides a Bluetooth diagnostic encryption level test and evaluation device, which can be a personal computer (PC), a laptop computer, a server, or other device with data processing capabilities.

[0085] Reference Figure 3 , Figure 3 Schematic diagram of the hardware structure of the Bluetooth diagnostic encryption level test and evaluation device involved in the embodiment of the present application. In the embodiment of the present application, the Bluetooth diagnostic encryption level test and evaluation device may include a processor, a memory, a communication interface and a communication bus.

[0086] The communication bus may be of any type and is used to interconnect the processor, memory, and communication interface.

[0087] Communication interfaces include input / output (I / O) interfaces, physical interfaces, and logical interfaces, used to interconnect components within the Bluetooth diagnostic encryption level test and evaluation device, as well as interfaces used to interconnect the Bluetooth diagnostic encryption level test and evaluation device with other devices (such as other computing devices or user devices). Physical interfaces can include Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc. User devices can include displays, keyboards, etc.

[0088] The memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0089] The processor may be a general-purpose processor that can call a Bluetooth diagnostic encryption level test and evaluation program stored in a memory and execute the Bluetooth diagnostic encryption level test and evaluation method provided in the embodiments of the present application. For example, the general-purpose processor may be a central processing unit (CPU). The method executed when the Bluetooth diagnostic encryption level test and evaluation program is called can be referred to in the various embodiments of the Bluetooth diagnostic encryption level test and evaluation method of the present application, and will not be repeated here.

[0090] Those skilled in the art will understand that Figure 3 The hardware structure shown in the figure does not constitute a limitation to the present application and may include more or fewer components than shown in the figure, or a combination of certain components, or a different arrangement of components.

[0091] In a fourth aspect, an embodiment of the present application also provides a computer-readable storage medium.

[0092] The computer-readable storage medium of the present application stores a Bluetooth diagnostic encryption level test evaluation program, wherein when the above-mentioned Bluetooth diagnostic encryption level test evaluation program is executed by the processor, the steps of the above-mentioned Bluetooth diagnostic encryption level test evaluation method are implemented.

[0093] Among them, the method implemented when the Bluetooth diagnostic encryption level test evaluation program is executed can refer to the various embodiments of the Bluetooth diagnostic encryption level test evaluation method of this application, and will not be repeated here.

[0094] It should be noted that the serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0095] The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices. The terms "first", "second" and "third" are used to distinguish different objects, etc., and do not represent a sequence, nor do they limit the "first", "second" and "third" to different types.

[0096] In the description of the embodiments of this application, the words "exemplary," "for example," or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary," "for example," or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary," "for example," or "for example" is intended to present the relevant concepts in a concrete manner.

[0097] In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in the text is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, “multiple” refers to two or more than two.

[0098] In some processes described in the embodiments of the present application, multiple operations or steps are included that appear in a specific order. However, it should be understood that these operations or steps may not be performed in the order in which they appear in the embodiments of the present application or may be performed in parallel. The sequence numbers of the operations are only used to distinguish between different operations, and the sequence numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations or steps may be performed in sequence or in parallel, and these operations or steps may be combined.

[0099] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device to execute the methods described in each embodiment of the present application.

[0100] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A Bluetooth diagnostic encryption level test and evaluation method, characterized in that: The method comprises: When performing Bluetooth diagnosis on a vehicle using a diagnostic instrument, obtaining a first Bluetooth communication message stored on the diagnostic instrument side and a second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument; Determining whether a link key can be extracted from the first Bluetooth communication message, if so, extracting the first Bluetooth diagnostic data from the first Bluetooth communication message, and decrypting the second Bluetooth communication message using the link key to obtain the second Bluetooth diagnostic data; if not, determining that the Bluetooth communication is not encrypted; Determine whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent. If so, determine that the Bluetooth diagnosis adopts link layer encryption and application layer encryption when the first Bluetooth diagnostic data is in an encrypted state; and determine that the Bluetooth diagnosis adopts link layer encryption when the first Bluetooth diagnostic data is in an unencrypted state; if not, determine that the Bluetooth diagnosis does not adopt encryption processing.

2. The Bluetooth diagnostic encryption level test and evaluation method according to claim 1, wherein: The method comprises: The second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument is obtained by using an air packet capture device.

3. The Bluetooth diagnostic encryption level test and evaluation method according to claim 1, wherein: The method comprises: All Bluetooth frequency bands are monitored to obtain the second Bluetooth communication message.

4. The Bluetooth diagnostic encryption level test and evaluation method according to claim 1, wherein: The method comprises: Obtain a host control interface HCI log from the diagnostic instrument side, and extract the first Bluetooth communication message from the HCI log.

5. The Bluetooth diagnostic encryption level test and evaluation method according to claim 4, wherein: Obtaining the HCI log specifically includes the following steps: Connect the universal serial bus (USB) interface on the diagnostic instrument to a data acquisition device with a USB cable, and the data acquisition device sends a debug bridge ABD instruction to obtain the HCI log from the diagnostic instrument side.

6. The Bluetooth diagnostic encryption level test and evaluation method according to claim 4, wherein: Obtaining the HCI log specifically includes the following steps: Connect the wireless communication interface on the diagnostic instrument to a data acquisition device with wireless communication function, and the data acquisition device sends the debug bridge ABD command or remote port debugging command to obtain the HCI log from the diagnostic instrument side.

7. The Bluetooth diagnostic encryption level test and evaluation method according to claim 4, wherein: The extracting of the first Bluetooth communication message specifically includes the following steps: Filter the HCI log by link key feature matching to filter out the link key exchange process data and the first Bluetooth diagnostic data; Extract the link key from the link key exchange process data.

8. The Bluetooth diagnostic encryption level test and evaluation method according to claim 1, wherein: The method comprises: When it is determined that the first Bluetooth diagnostic data contains diagnostic plaintext information, the first Bluetooth diagnostic data is determined to be in an unencrypted state; when it is determined that the first Bluetooth diagnostic data does not contain diagnostic plaintext information, the first Bluetooth diagnostic data is determined to be in an encrypted state.

9. A Bluetooth diagnostic encryption level test and evaluation system, characterized in that: The system comprises: A data acquisition module, which is used to acquire a first Bluetooth communication message stored on the diagnostic instrument side and a second Bluetooth communication message transmitted between the vehicle and the diagnostic instrument when the diagnostic instrument is used to perform Bluetooth diagnosis on the vehicle; A data processing module, which is used to determine whether a link key can be extracted from a first Bluetooth communication message. If so, first Bluetooth diagnostic data is extracted from the first Bluetooth communication message, and the second Bluetooth communication message is decrypted using the link key to obtain second Bluetooth diagnostic data; if not, it is determined that the Bluetooth communication does not adopt encryption processing; it is also used to determine whether the first Bluetooth diagnostic data and the second Bluetooth diagnostic data are consistent. If so, it is determined that the Bluetooth diagnosis adopts link layer encryption and application layer encryption when the first Bluetooth diagnostic data is in an encrypted state, and when the first Bluetooth diagnostic data is in an unencrypted state, it is determined that the Bluetooth diagnosis adopts link layer encryption; if not, it is determined that the Bluetooth diagnosis does not adopt encryption processing.

10. A Bluetooth diagnostic encryption level test and evaluation device, characterized in that: The Bluetooth diagnostic encryption level test and evaluation device includes a processor, a memory, and a Bluetooth diagnostic encryption level test and evaluation program stored in the memory and executable by the processor, wherein when the Bluetooth diagnostic encryption level test and evaluation program is executed by the processor, the steps of the Bluetooth diagnostic encryption level test and evaluation method as described in any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Safety test system based on IPv6 wireless sensor network

    CN104837150A

  • Data security testing method and device

    CN107819650A