A safety test method, device, system, medium and product of a vehicle-mounted system

By introducing an artificial intelligence module combined with an access module and a safety testing module into the vehicle system, fully automated safety testing of the vehicle system is achieved, solving the problem of low automation in existing technologies and improving the comprehensiveness and accuracy of the testing.

CN119814464BActive Publication Date: 2026-05-01CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHONGQING CHANGAN AUTOMOBILE CO LTD
Filing Date
2025-01-14
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Current technologies lack automation in safety testing of vehicle systems, with most tests requiring manual intervention and exhibiting a low degree of automation.

Method used

A security testing method for in-vehicle systems is designed, which combines an artificial intelligence module with an access module and security testing modules for different information security testing types. Test data is obtained through the access module, the corresponding security testing modules are called to perform tests, and security analysis is performed based on pre-integrated in-vehicle system security standards to achieve automated security testing.

Benefits of technology

It has enabled fully automated safety testing of vehicle systems, improving the comprehensiveness and accuracy of testing, reducing manual intervention, and increasing testing efficiency and precision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814464B_ABST
    Figure CN119814464B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of vehicle information security testing, and discloses a safety testing method, device, system, medium and product for a vehicle system. An artificial intelligence module designed by the present application responds to a test instruction of a task to be tested selected by a user, obtains first test data corresponding to the vehicle system through an access module, and / or calls a safety testing module corresponding to the task to be tested to test the vehicle system for the corresponding task and obtain second test data fed back after the corresponding safety testing module completes the test. Based on a pre-integrated safety standard for the vehicle system, the first test data and / or the second test data are subjected to safety analysis to determine a safety test result of the vehicle system, thereby realizing automatic safety information testing of the vehicle system without manual intervention.
Need to check novelty before this filing date? Find Prior Art

Description

A method, apparatus, system, medium, and product for safety testing of an in-vehicle system. Technical Field

[0001] This invention relates to the field of vehicle information security testing technology, specifically to a security testing method, device, system, medium, and product for vehicle systems. Background Technology

[0002] In-vehicle information service system refers to a communication system installed in a vehicle. It is an information interaction or entertainment service device. Externally, it can communicate with external terminals or service platforms such as base stations and keys. Internally, it can communicate with in-vehicle electronic systems such as gateways and ECUs to complete functions such as information collection, data exchange, and command issuance.

[0003] Currently, the "Technical Requirements and Test Methods for Information Security of In-Vehicle Information Interaction Systems" has been published, which guides the automotive industry in proposing technical requirements and tests for in-vehicle information service systems. It has been widely used in the industry. Existing technology-designed security testing systems have pre-set test items that comply with national standards. Information security testing covers national standards, meets compliance requirements, and saves manpower and time costs. However, existing technology has not formed an automated testing system. It only has corresponding methods for testing, and the various tests are relatively separate. Most tests require manual intervention, and the degree of automation is low. Summary of the Invention

[0004] In view of this, the present invention provides a method, apparatus, system, medium and product for safety testing of vehicle systems, in order to solve the problems of existing technologies that have not formed automated testing, only have corresponding methods for testing, the various tests are relatively separate, most tests require manual intervention, and the degree of automation is low.

[0005] In a first aspect, the present invention provides a security testing method for an in-vehicle system, applied to an artificial intelligence module in an in-vehicle system security testing system. The in-vehicle system security testing system further includes an access module and security testing modules corresponding to different information security testing types of the in-vehicle system. The access module establishes a corresponding connection with the in-vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information testing type. The method includes: responding to a test instruction for a user-selected test task, obtaining first test data corresponding to the in-vehicle system through the access module based on the user-selected test task requirements, and / or calling the security testing module corresponding to the test task requirements to perform the corresponding task test on the in-vehicle system, and obtaining second test data fed back by the corresponding security testing module after completing the test; and performing security analysis on the first test data and / or the second test data based on a pre-integrated in-vehicle system security testing standard to determine the security test result of the in-vehicle system.

[0006] The present invention provides a method for safety testing of an in-vehicle system. An artificial intelligence module responds to a user-selected test command for a task to be tested, acquires first test data corresponding to the in-vehicle system through an access module, and / or calls a safety test module corresponding to the requirements of the task to be tested to perform the corresponding test on the in-vehicle system, and acquires second test data fed back by the corresponding safety test module after completing the test. Based on pre-integrated in-vehicle system safety standards, a safety analysis is performed on the first and / or second test data to determine the safety test results of the in-vehicle system, thus achieving automatic safety information testing of the in-vehicle system without human intervention.

[0007] In one optional implementation, the security testing modules corresponding to the different information security testing types include at least a hardware security testing module, a communication security testing module, an operating system security testing module, an application software security testing module, and a data security testing module.

[0008] This invention designs security testing modules corresponding to different information security testing types based on vehicle information security standards, which can realize security testing of all information interactions in the vehicle system and ensure the comprehensiveness of vehicle system security testing.

[0009] In one optional implementation, the hardware security testing module integrates tools for accessing and operating the vehicle system's debugging interface. If the task to be tested includes testing the hardware security of the vehicle system, the steps of obtaining the first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task to be tested to perform the corresponding task test on the vehicle system, and obtaining the second test data fed back by the corresponding security testing module after completing the test, include: sending control information input to the vehicle system to the hardware security testing module; calling the hardware security testing module to access the debugging interface of the vehicle system and inputting the control information into the vehicle system; obtaining the process data fed back by the hardware security testing module after completing the access to the debugging interface of the vehicle system and inputting the control information; and / or obtaining the development board image in the vehicle system through the access module, wherein the access module includes an image acquisition device for connecting to the debugging interface of the vehicle system to obtain the development board image.

[0010] This invention tests the hardware security of in-vehicle systems. It can directly obtain the development board screen through the access module, or call the hardware security test module to access the debugging interface of the in-vehicle system and input control information to obtain the overall process data, thereby obtaining more comprehensive test data and improving the comprehensiveness of in-vehicle system security testing.

[0011] In one optional implementation, the communication security testing module integrates at least network card hardware, port scanning tools, packet capture tools, and data packet tampering tools. If the task to be tested includes testing the cellular network security of the vehicle system, the access module connects to the cellular network of the vehicle system. The steps of obtaining the first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task to be tested to perform the corresponding task test on the vehicle system, and obtaining the second test data fed back by the corresponding security testing module after completing the test, include: calling the communication security testing module to scan the cellular network address of the vehicle system and connecting it to an open port; obtaining the connection result of the communication security testing module with the open port, and / or controlling the vehicle system to communicate using the cellular network through the access module, using the packet capture tool of the communication security testing module to capture data packets during the communication process, and / or sending the data packet to be tampered to the communication security testing module, calling the communication security testing module to tamper with the data packets of the vehicle system based on the data packet to be tampered, and obtaining the response status of the vehicle system to the data packet to be tampered.

[0012] In one optional implementation, the communication security testing module integrates at least WIFI network hardware, a WIFI packet capture tool, and a brute-force attack tool. If the task to be tested includes testing the WIFI security of the vehicle system, the access module connects to the WIFI of the vehicle system. The steps of obtaining the first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task to be tested to perform the corresponding task test on the vehicle system, and obtaining the second test data fed back by the corresponding security testing module after completing the test, include: entering the WIFI settings interface of the vehicle system through the access module and obtaining WIFI settings information, and / or changing the WIFI password of the vehicle system to a password that does not meet the settings requirements through the access module and obtaining the WIFI password change response information, and / or calling the communication security testing module to perform brute-force attack on the WIFI password and obtaining the attack result of the brute-force attack on the WIFI password by the communication security testing module, and / or calling the communication security testing module to capture data packets using WIFI communication.

[0013] In one optional implementation, the communication security testing module integrates at least Bluetooth hardware, a Bluetooth packet capture tool, and a port scanning tool. If the task to be tested includes testing the Bluetooth security of the vehicle system, the access module connects to the Bluetooth of the vehicle system. The steps of obtaining the first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task to be tested to perform the corresponding task test on the vehicle system, and obtaining the second test data fed back by the corresponding security testing module after completing the test, include: connecting to the Bluetooth of the vehicle system through the access module, obtaining the Bluetooth connection process data, and / or calling the communication security testing module to traverse the Bluetooth of the vehicle system to obtain the device connection information of the Bluetooth port, and / or calling the communication security testing module to capture data packets using Bluetooth communication.

[0014] The communication security test of the vehicle system designed in this invention is divided into cellular network test, WIFI test and Bluetooth test. Users can select more detailed test tasks, and the artificial intelligence module will then perform the corresponding process test based on different test tasks to meet the test requirements.

[0015] In one optional implementation, the operating system security testing module integrates at least a remote access tool, a software debugging tool, and an operating system vulnerability scanning tool. The access module connects to the operating system in the vehicle system. The process of obtaining first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task under test to perform corresponding task testing on the vehicle system, and obtaining second test data fed back by the corresponding security testing module after completing the test, includes: calling the operating system security testing module to access the operating system, obtaining account information in the operating system, and / or sending the operating system account to the operating system security testing module, calling the operating system security testing module to log in to the system, obtaining the system login result, and if the system login result is password protected, calling the operating system security testing module to perform brute-force attack on the operating system, obtaining the operating system attack result, and / or calling the operating system security testing module to perform brute-force attack on the operating system, obtaining the operating system attack result, and / or calling the operating system security testing module to perform brute-force attack on the operating system. The testing module performs system privilege escalation operations on the operating system account and obtains the system privilege escalation operation results; and / or, accesses the operating system's runtime attribute information through the access module and obtains the access display data of the runtime attribute information, which includes at least location, SMS, and telephone information; and / or, sends the information related to the software to be tampered with to the operating system security testing module, calls the operating system security testing module to debug the operating system software based on the information related to the software to be tampered with, and obtains the debugging results of the operating system security testing module on the operating system software; and / or, calls the operating system security testing module to perform system updates on the operating system and obtains the operating system's response data to the system update; and / or, calls the operating system security testing module to modify the logs stored in the operating system and obtains the operating system's response data to the modified logs; and / or, calls the operating system security testing module to perform vulnerability scanning on the operating system and obtains the vulnerability scanning results of the operating system.

[0016] The artificial intelligence module of this invention automatically calls the access module and / or the operating system security testing module to perform security testing on the operating system of the vehicle system based on the requirements of the task to be tested, thereby realizing fully automatic security testing of the vehicle system.

[0017] In one optional implementation, the application software security testing module integrates at least an application installation tool, an application address scanning tool, a vulnerability scanning tool, an application reverse engineering tool, and an application internet security detection tool. The step of obtaining first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task requirements to perform corresponding task tests on the vehicle system, and obtaining second test data fed back by the corresponding security testing module after completing the test, includes: sending an unauthorized application to the application software security testing module, calling the application software testing module to install the unauthorized application on the vehicle system, obtaining the vehicle system's response data to the installation of the unauthorized application, and / or calling the application software security testing module to access... The system queries the application's data storage address to enable the application software security testing module to scan the application data for sensitive information, obtains the scanning results of the application software security testing module on sensitive information in the data, and / or calls the application software security testing module to perform vulnerability scans on various applications of the vehicle system, obtains the vulnerability scan results of the application software security testing module on various applications of the vehicle system, and / or calls the application software security testing module to use application reverse engineering tools to detect the security of the application's runtime code, obtains the detection results of the application software security testing module using application reverse engineering tools on the security of the application's runtime code, and / or calls the application software security testing module to trigger the internet access function of each application, obtains the data during the internet access process of each application.

[0018] This invention utilizes various tools in the access module and application software security testing module to perform security testing on application software in the vehicle system based on the user-selected test task requirements.

[0019] In one optional implementation, the data security testing module integrates at least a storage address access tool, a data packet capture tool, a file operation tool, and a data deletion function. The steps of obtaining first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task under test to perform corresponding task testing on the vehicle system, and obtaining second test data fed back by the corresponding security testing module after completing the test, include: calling the data security testing module to access the data storage address in the vehicle system to enable the data security testing module to detect whether there is sensitive information in the data; obtaining the detection result of the data security testing module on whether there is sensitive information in the data, and / or calling the data security testing module to perform unauthorized operations on the stored files in the vehicle system, obtaining the response data of the vehicle system to the unauthorized operation on the stored files, and / or calling the data packet capture tool in the data security testing module to obtain data packets during data transmission, and / or calling the data security testing module to delete target data in the vehicle system; after receiving feedback from the data security testing module after deleting the target data in the vehicle system, calling the data security testing module to access the data storage address in the vehicle system to obtain the storage information of the target data in the vehicle system.

[0020] This invention can automatically call the access module and data security detection module to perform security monitoring based on the user-selected test task requirements, thereby realizing the security testing of data in the vehicle system.

[0021] In one optional implementation, the artificial intelligence module integrates security test models corresponding to different task requirements. The step of performing security analysis on the first test data and / or the second test data based on pre-integrated vehicle system security test standards to determine the vehicle system security test results includes: inputting the first test data and / or the second test data obtained based on the requirements of the task to be tested into the corresponding security test model, and outputting the vehicle system security test results; the security test model is trained through the following steps: obtaining a test dataset for vehicle system testing corresponding to the current task, the test dataset including test data and corresponding security test results, the test data including normal test procedures and abnormal test data, the security test results being determined by analyzing the test data based on vehicle system security test standards; using the test dataset for vehicle system testing corresponding to the current task to train a preset initial security test model corresponding to the current task, obtaining a trained security test model corresponding to the current task, so that the trained security test model corresponding to the current task integrates the normal test procedures and abnormal test data corresponding to the current task.

[0022] The artificial intelligence module designed in this invention integrates different security test models corresponding to different information security test types. The security test model integrates normal test processes and abnormal test data corresponding to different tasks. Based on the corresponding security test model, the test data is tested and the security test results of the vehicle system are output. Compared with direct comparison test based on information security standards, it is more efficient and more accurate.

[0023] In one optional implementation, the step of obtaining first test data corresponding to the vehicle system through the access module based on the user-selected test task requirement, and / or calling the security test module corresponding to the test task requirement to perform corresponding task testing on the vehicle system, and obtaining second test data fed back by the corresponding security test module after completing the test, includes: determining the normal test process corresponding to the test task requirement based on the user-selected test task requirement; generating a first test instruction based on the security test sequence in the normal test process, and sending the first test instruction to the access module according to the content of the first test instruction, obtaining the test data corresponding to the vehicle system through the access module, and / or sending the first test instruction to the security test module corresponding to the test task requirement to perform corresponding task testing; wherein, the first test instruction is used to obtain the test data corresponding to the vehicle system through the access module to perform corresponding task testing on the vehicle system through the access module; wherein, the first test instruction is used to obtain the test data corresponding to the vehicle system based on the user-selected test task requirement, and / or calling the security test module corresponding to the test task requirement to perform corresponding task testing on the vehicle system through the access module to perform corresponding task testing on the vehicle system ... obtain the test data corresponding to the vehicle system, and / or calling the security test module corresponding to the test task requirement to perform corresponding task testing on the vehicle system through the access module to obtain the test data corresponding to the vehicle system, and / or calling the security test module corresponding to the test task requirement to perform corresponding task testing on the vehicle system through the access module to obtain the test data corresponding to the vehicle system, and / or calling the security test module corresponding to the test task requirement to perform corresponding task testing on the vehicle system through the access Sending a test instruction to the security test module corresponding to the task under test to perform the corresponding task test includes: directly calling the security test module corresponding to the task under test to perform the corresponding task test on the vehicle system, and / or calling the task under test to perform the corresponding task test on the vehicle system using the abnormal test data in the first test instruction; after obtaining the test data obtained through the access module, and / or the test data fed back by the corresponding security test module after completing the test, generating a second test instruction according to the security test sequence and the test data, and replacing the first test instruction with the second test instruction, repeating the step of sending the first test instruction to the access module according to the content of the first test instruction, until the normal test process is completed and the first test data and the second test data corresponding to the task under test are obtained.

[0024] In this embodiment of the invention, the artificial intelligence module serves as the unified input and output interface of the system. It acquires the resources and permissions of the object under test through the access module and distributes execution instructions to other test modules sequentially and in a single order according to the actual task requirements. Different test modules execute the instructions in parallel and feed back the execution results to the artificial intelligence module for analysis. Unified management by the artificial intelligence module facilitates the execution control of the entire automated testing process, accurately analyzes the situation of each execution process, improves testing accuracy, and increases testing efficiency through parallel operation of each module.

[0025] In an optional implementation, the method further includes: responding to a self-functional error message sent by the safety test module to be corrected, setting the function of the safety test module to be corrected to an unavailable state, and prompting the user with the self-functional error message of the safety test module to be corrected, so that the user can correct the error of the safety test module to be corrected. The self-functional error message is sent by each safety test module to the artificial intelligence module after the vehicle system's safety test system is powered on and it determines that its own safety test function cannot operate normally.

[0026] Each module in this embodiment of the invention performs a self-test after power-on, which can ensure the normal operation of the safety test and the accuracy of the test results, and avoid erroneous test results due to module errors.

[0027] Secondly, the present invention provides a security testing device for an in-vehicle system, applied to an artificial intelligence module in an in-vehicle system security testing system. The in-vehicle system security testing system further includes an access module and security testing modules corresponding to different information security testing types of the in-vehicle system. The access module establishes a corresponding connection with the in-vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information testing type. The device includes: a task testing module, used to respond to a test instruction for a user-selected test task, obtain first test data corresponding to the in-vehicle system through the access module based on the user-selected test task requirements, and / or call the security testing module corresponding to the test task requirements to perform corresponding task testing on the in-vehicle system, and obtain second test data fed back by the corresponding security testing module after completing the test; and an in-vehicle system security testing module, used to perform security analysis on the first test data and / or the second test data based on pre-integrated in-vehicle system security testing standards, to determine the security test results of the in-vehicle system.

[0028] Thirdly, the present invention provides a security testing system for an in-vehicle system. The in-vehicle system security testing system includes an artificial intelligence module, an access module, and security testing modules corresponding to different information security testing types of the in-vehicle system. The access module establishes a corresponding connection with the in-vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information testing type. The artificial intelligence module includes a memory and a processor, which are interconnected. The memory stores computer instructions, and the processor executes the computer instructions to perform the in-vehicle system security testing method described in the first aspect or any corresponding embodiment.

[0029] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the safety testing method for an in-vehicle system according to the first aspect or any corresponding embodiment thereof.

[0030] Fifthly, the present invention provides a computer program product, including computer instructions, which are used to cause a computer to execute the safety testing method for an in-vehicle system according to the first aspect or any corresponding embodiment described above.

[0031] The present invention provides a method for safety testing of an in-vehicle system. An artificial intelligence module responds to a user-selected test command for a task to be tested, acquires first test data corresponding to the in-vehicle system through an access module, and / or calls a safety test module corresponding to the requirements of the task to be tested to perform the corresponding test on the in-vehicle system, and acquires second test data fed back by the corresponding safety test module after completing the test. Based on pre-integrated in-vehicle system safety standards, a safety analysis is performed on the first and / or second test data to determine the safety test results of the in-vehicle system, thus achieving automatic safety information testing of the in-vehicle system without human intervention. Attached Figure Description

[0032] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0033] Figure 1 is an example diagram of the integration tool for the access module according to an embodiment of the present invention;

[0034] Figure 2 is a flowchart illustrating a safety testing method for an in-vehicle system according to an embodiment of the present invention;

[0035] Figure 3 is a flowchart illustrating a safety testing method for another vehicle-mounted system according to an embodiment of the present invention;

[0036] Figure 4 is a structural example diagram of a safety testing system for an in-vehicle system according to an embodiment of the present invention;

[0037] Figure 5 is a functional example diagram of the artificial intelligence module according to an embodiment of the present invention;

[0038] Figure 6 is an example diagram of an integrated tool for a hardware security testing module according to an embodiment of the present invention;

[0039] Figure 7 is an example diagram of an integrated tool for a communication security testing module according to an embodiment of the present invention;

[0040] Figure 8 is an example diagram of an integrated tool for an operating system security testing module according to an embodiment of the present invention;

[0041] Figure 9 is an example diagram of the integrated tool for the application software security testing module according to an embodiment of the present invention;

[0042] Figure 10 is an example diagram of an integrated tool for a data security testing module according to an embodiment of the present invention;

[0043] Figure 11 is an example diagram of the training process of a security testing model according to an embodiment of the present invention;

[0044] Figure 12 is a schematic diagram of a safety testing system for an in-vehicle system according to an embodiment of the present invention;

[0045] Figure 13 is a structural block diagram of a safety testing device for an in-vehicle system according to an embodiment of the present invention;

[0046] Figure 14 is a schematic diagram of the hardware structure of the artificial intelligence module according to an embodiment of the present invention. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0048] According to an embodiment of the present invention, a safety testing method for an in-vehicle system is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0049] This embodiment provides a security testing method for an in-vehicle system, applied to an artificial intelligence module within the in-vehicle system's security testing system. The in-vehicle system's security testing system also includes an access module and security testing modules corresponding to different information security test types. The access module establishes a connection with the in-vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information test type. The in-vehicle system can be an in-vehicle information service system, but this is only an example.

[0050] The vehicle-mounted system security testing system designed in this embodiment of the invention includes an access module, an artificial intelligence module, and security testing modules corresponding to different information security testing types of the vehicle-mounted system. The design of security testing modules corresponding to different information security testing types is not limited and can be updated in real time according to the information security testing types involved in the actually released information security technical requirements of the vehicle-mounted information interaction system. Examples include user authentication testing, security log testing, live network testing, hardware security testing, and encryption testing. These are merely examples; different information security testing types can be designed with their corresponding security testing modules, which integrate testing tools for their corresponding functions.

[0051] The access module designed in this embodiment of the invention undertakes all wired and wireless connections, information acquisition and transmission, operation execution, and other functions, as shown in Figure 1. The access module hardware includes a high-definition camera, a lighting lamp, and a hardware environment with a signal shielding box. Wireless interfaces include Bluetooth and Wi-Fi communication interfaces, a software-integrated terminal emulation program, and tools such as Monkey (a command-line tool that sends pseudo-random event streams to the system) and MonkeyRunner (a tool included in the Android SDK that allows control of device operation or execution of automated tests via the Android API on a PC). It also has various wired interfaces, including a Universal Serial Bus (USB) interface and a Controller Area Network (CAN) interface. The system includes network (CAN) interfaces, Ethernet interfaces, video interfaces, and power supply interfaces, as well as supporting software to drive the hardware. For example, the access module allows the user to establish a connection with the vehicle system based on the user-selected test requirements. For instance, in hardware security testing of the vehicle system, the user (or staff) can remove the vehicle system's casing, leaving only the development board, and place it in a designated location to connect to the access module's power supply, video, and USB interfaces. This is just one example.

[0052] The artificial intelligence module designed in this embodiment of the invention is pre-integrated with the latest vehicle system security testing standards. It establishes independent connections with the access module and the security testing modules corresponding to the various security information test types. The artificial intelligence module can select to call the access module or the corresponding security testing module to perform the test based on the requirements of the task to be tested, and obtain the test data for analysis and processing to determine the security test results of the vehicle system.

[0053] Figure 2 is a flowchart of a safety testing method for an in-vehicle system according to an embodiment of the present invention. As shown in Figure 2, the process includes the following steps:

[0054] Step S201: In response to the test instruction of the user-selected test task, based on the user-selected test task requirements, the system obtains the first test data corresponding to the vehicle system through the access module, and / or calls the security test module corresponding to the test task requirements to perform the corresponding task test on the vehicle system, and obtains the second test data fed back by the corresponding security test module after completing the test.

[0055] In this embodiment of the invention, the user can select the test task to be tested through the interactive interface of the vehicle system security testing system. For example, if the network security of the vehicle system needs to be tested, the artificial intelligence module can, based on the test instructions of the user-selected test task, choose to obtain the first test data corresponding to the vehicle system through the access module, and / or call the security test module corresponding to the test task requirements to perform the corresponding test on the vehicle system, and obtain the second test data fed back by the security test module after the test is completed. The decision to select whether to obtain data through the access module or call the corresponding security test module for testing can be made according to the actual test task. For example, based on the user's selection of network security testing for the vehicle system, the artificial intelligence module can pre-determine which tests need to be performed, such as directly obtaining the network address (Internet address) of the vehicle system through the access module. The system can utilize Protocol (IP) and can also call corresponding network security testing modules to capture data packets during network communication. The artificial intelligence module can automatically determine the target test data corresponding to the task under test based on the requirements of the task and its own integrated test data for different task requirements. This target test data is then sent to the corresponding security testing module, which performs tests on the in-vehicle system based on the target test data. The system then obtains the test results from the security testing module. For example, it can pre-set network settings to be modified, send these settings to the network security testing module, and then modify the network settings based on these settings to obtain the in-vehicle system's performance. The modified response settings are provided as an example only. Alternatively, based on the requirements of the task under test, it can be determined that no test data is needed, and the corresponding security test module can be directly called to test the vehicle system. This operation requires the AI ​​module to make its own decision based on the requirements of the task under test. If the user only selects to perform security testing on the network address IP of the vehicle system, the AI ​​module can also obtain the current network address IP of the vehicle system simply through the access module. Before the access module feeds back the first test data corresponding to the vehicle system, or the security test module feeds back the second test data, to the AI ​​module, the test data needs to be converted into one or more formats, i.e., data formats that the AI ​​module can analyze, so that the AI ​​module can analyze the test data. There are no restrictions on this.

[0056] Step S202: Based on the pre-integrated vehicle system safety testing standards, perform safety analysis on the first test data and / or the second test data to determine the safety test results of the vehicle system.

[0057] After the artificial intelligence module of this invention obtains test data through the access module and / or the corresponding security testing module, it can determine whether the test data is secure based on its pre-integrated vehicle system security testing standards. The vehicle system security testing standards include various types of data requirements that meet information security. For example, if the data is transmitted through the network of the vehicle system, the data needs to be encrypted and the Transport Layer Security (TLS) version needs to be correct. The system can compare the data obtained from the test with the data requirements corresponding to the information security in the vehicle system security testing standards. If the operation process and data encryption attributes are consistent with the information security data requirements, the security test result of the vehicle system can be determined to be secure, and then a prompt can be given to the user through the interactive interface.

[0058] The vehicle system security testing method provided in this embodiment involves an artificial intelligence module responding to a user-selected test command for a task to be tested. This module obtains first test data corresponding to the vehicle system through an access module, and / or calls a security test module corresponding to the task requirements to perform the corresponding test on the vehicle system. It also obtains second test data fed back by the corresponding security test module after completing the test. Based on pre-integrated vehicle system security standards, it performs security analysis on the first and / or second test data to determine the security test results of the vehicle system, thus achieving automatic security information testing of the vehicle system without manual intervention.

[0059] This embodiment provides a safety testing method for an in-vehicle system, which can be used in the artificial intelligence module of the in-vehicle system safety testing system. Figure 3 is a flowchart of the artificial intelligence module method in the in-vehicle system safety testing system according to an embodiment of the present invention. As shown in Figure 3, the process includes the following steps:

[0060] Step S301: In response to the test instruction of the user-selected task to be tested, based on the user-selected task requirements, the system obtains the first test data corresponding to the vehicle system through the access module, and / or calls the security test module corresponding to the task requirements to perform the corresponding task test on the vehicle system, and obtains the second test data fed back by the corresponding security test module after completing the test.

[0061] Specifically, the security testing modules corresponding to different information security testing types include at least hardware security testing modules, communication security testing modules, operating system security testing modules, application software security testing modules, and data security testing modules.

[0062] This invention, in accordance with the requirements of GB / T 40856-2021 "Information Security Technical Requirements and Test Methods for Vehicle Information Interaction Systems," utilizes artificial intelligence for arbitration. Numerous testing tools are integrated into the device for auxiliary testing, automating the generation of vehicle system safety test results. As shown in Figure 4, the designed vehicle system safety test system includes: an artificial intelligence module that controls and makes decisions during the vehicle system safety test process; an access module for connecting to the vehicle system, including CAN, Ethernet, WIFI, Bluetooth, and other access-required components, and for acquiring information such as hardware chips and wiring on parts, enabling data transmission after connection; a hardware security test module to perform corresponding hardware security tests as specified in the standard; and a communication security test module to implement standard... The system includes modules for communication security testing, application software security testing, and data security testing. These are just examples; the system can be updated in real-time according to published vehicle system information security standards. The overall process for vehicle system security testing involves a wired / wireless connection to the vehicle system via an access module, capturing images of the development board and chips via a camera, which are then identified and processed by an AI module. This process calls various hardware security, communication security, and operating system security testing modules to perform tests, acquires test data, and combines this data with AI for comprehensive analysis, outputting the vehicle system's security test results.

[0063] This invention designs security testing modules corresponding to different information security testing types based on vehicle information security standards, which can realize security testing of all information interactions in the vehicle system and ensure the comprehensiveness of vehicle system security testing.

[0064] Furthermore, the hardware security testing module integrates tools that can access and operate the debugging port of the vehicle system. If the task to be tested requires testing the hardware security of the vehicle system, the first test data corresponding to the vehicle system is obtained through the access module, and / or, the security testing module corresponding to the task to be tested is called to perform the corresponding task test on the vehicle system, and the second test data fed back by the corresponding security testing module after completing the test is obtained, including: sending the control information input to the vehicle system to the hardware security testing module; calling the hardware security testing module to access the debugging interface of the vehicle system and inputting the control information into the vehicle system; obtaining the process data fed back by the hardware security testing module after completing the access to the debugging interface of the vehicle system and inputting the control information, and / or, obtaining the development board image in the vehicle system through the access module, the access module including an image acquisition device for connecting to the debugging interface of the vehicle system to obtain the development board image.

[0065] As shown in Figure 5, the artificial intelligence module designed in this embodiment of the invention dominates the test operation and mainly has three major functions: recognition, analysis and processing. It has the function of intelligent image recognition and analysis, recognizes the debugging port, and identifies the development board and chip. The recognizable information includes the chip, the silkscreen on the chip, the chip pins, and the wiring of the development board. The recognition is performed using artificial intelligence, which is only an example.

[0066] As shown in Figure 6, the hardware security testing module designed in this embodiment of the invention mainly performs access testing of the debug interface. It integrates a terminal emulation program (Secure CRT), serial port connection software (Putty), and Android Debug Bridge (adb) tools to realize the functions of accessing the debug port, inputting commands, and outputting results. This is only an example, and the tools integrated in the hardware security testing module can be updated in real time according to existing and updated task requirements and information security standards. If the user chooses to test the hardware security of the vehicle system, the vehicle system casing can be removed in advance, leaving only the development board, which is placed in a designated location and connected to the power supply interface, video interface, and USB interface of the access module to power the vehicle system and display the terminal.

[0067] After the test begins, the AI ​​module can call the hardware security test module to access the debugging interface of the vehicle system, obtain the access process data and results. If the access is successful, the control information input to the vehicle system can be set and sent to the hardware security test module. The hardware security test module then inputs the control information into the vehicle system, receives the input or executes the command, and displays the content on the vehicle system screen. It checks whether a password restriction is displayed on the screen. Vehicle information security standards require that a password input interface appear after inputting control commands. The presence of a password input interface indicates a password restriction, thus meeting the security requirements. If no password input interface appears, the security requirements are not met. Alternatively, the hardware security test module may not be able to verify the password input. Even if access to the vehicle system fails, it can still be determined that the security requirements are met; this is just an example. The access module connects to the debugging interface of the vehicle system and can acquire the development board image through a high-definition camera. The artificial intelligence module uses the development board image acquired by the access module to perform intelligent identification to determine whether there are exposed pins, exposed communication lines, and chip silkscreens, and to determine whether the security requirements are met. The security test results are recorded. Users can choose to perform overall hardware security testing, in which case the artificial intelligence module will perform the above test methods sequentially to obtain the hardware security test results. Users can also choose detailed hardware security test requirements, such as only performing hardware testing on the development board. In this case, the artificial intelligence does not need to call the hardware test module; it only needs to acquire the development board image through the access module for intelligent identification; this is just an example.

[0068] This invention tests the hardware security of in-vehicle systems. It can directly obtain the development board screen through the access module, or call the hardware security test module to access the debugging interface of the in-vehicle system and input control information to obtain the overall process data, thereby obtaining more comprehensive test data and improving the comprehensiveness of in-vehicle system security testing.

[0069] Furthermore, the communication security testing module integrates at least network card hardware, port scanning tools, packet capture tools, and data packet tampering tools. If the test task requires testing the cellular network security of the vehicle system, the access module connects to the vehicle system's cellular network, the artificial intelligence module calls the communication security testing module to scan the vehicle system's cellular network address and connect to open ports; obtains the connection results between the communication security testing module and the open ports, and / or controls the vehicle system to communicate using the cellular network through the access module, uses the packet capture tool of the communication security testing module to capture data packets during the communication process, and / or sends the data packets to be tampered with to the communication security testing module, calls the communication security testing module to tamper with the data packets of the vehicle system based on the data packets to be tampered with, and obtains the vehicle system's response to the data packets to be tampered with.

[0070] As shown in Figure 7, the communication security test module designed in this embodiment of the invention integrates Bluetooth, WIFI, wireless network card, bus development hardware (CAN open environment, CANoe), etc. on the hardware side, and integrates network packet capture tools (dump the traffic on a network, tcpdump), Wireshark, network packet analysis software (burpsuite), HTTP packet capture tool (fiddle), Bluetooth packet capture tool, WIFI packet capture tool, adb, port scanning tool, and supporting software for hardware drivers on the software side. It has functions such as packet forwarding and tampering of Bluetooth, WIFI, cellular network, CAN, and Ethernet. As an example only, the Bluetooth, WIFI, cellular network, CAN network, and Ethernet of the test object can be connected through the access module.

[0071] In response to user requests to test the cellular network of the in-vehicle system, the access module connects to the cellular network of the in-vehicle system. The in-vehicle system's security testing system and the in-vehicle system are on the same network. The artificial intelligence module calls the communication security testing module to scan the cellular network address (i.e., the cellular network IP) of the in-vehicle system, then checks its open ports and connects to them one by one. Finally, it obtains the connection results between the communication security testing module and the open ports. The artificial intelligence module can also trigger communication between the in-vehicle system and the backend via the cellular network through the access module, and call the packet capture tool of the communication security testing module to capture and analyze data packets during the communication process, checking for security authentication, encryption, TLS protocol version, and recording the test results. Furthermore, in response to user requests to test whether the in-vehicle system's data packets are tamper-proof, the artificial intelligence module can automatically forge data packets to be tampered with and send them to the communication security testing module. This allows the communication security testing module to modify or replay the data packets of the in-vehicle system based on the data packets to be tampered with. Finally, it obtains the in-vehicle system's response to the data packets to be tampered with and records the test results.

[0072] Furthermore, the communication security testing module integrates at least WIFI network hardware, WIFI packet capture tools, and brute-force cracking tools. If the test task requires testing the WIFI security of the vehicle system, the access module connects to the vehicle system's WIFI, and the artificial intelligence module enters the vehicle system's WIFI settings interface through the access module to obtain WIFI setting information, and / or changes the vehicle system's WIFI password to a password that does not meet the setting requirements through the access module, obtains the WIFI password change response information, and / or calls the communication security testing module to perform brute-force cracking on the WIFI password, obtains the cracking result of the brute-force cracking on the WIFI password by the communication security testing module, and / or calls the communication security testing module to capture data packets using WIFI communication.

[0073] In response to user requests to test the in-vehicle system's Wi-Fi, the AI ​​module can access the in-vehicle system's Wi-Fi settings interface via the access module to obtain Wi-Fi setting information. This information may include whether a password is set, the default password, and the set password. The AI ​​module checks whether the set password meets the complexity requirements and records the security test results. The AI ​​module can also change the in-vehicle system's Wi-Fi password to a password that does not meet the requirements, such as a weak password. It can then obtain the in-vehicle system's response information after the password change, which may include the in-vehicle system's interface, indicating whether the change was successful or a message indicating that the password does not meet the requirements. The AI ​​module can also call the communication security test module to perform a brute-force attack on the Wi-Fi password, check if the attack is successful, and record the test results. Furthermore, the AI ​​module can call the communication security test module to capture data packets used for Wi-Fi communication. The AI ​​module analyzes the captured data packets to determine if they are encrypted, if they use secure protocols, etc., and records the test results to determine if the security requirements are met.

[0074] Furthermore, the communication security testing module integrates at least Bluetooth hardware, a Bluetooth packet capture tool, and a port scanning tool. If the task under test requires testing the Bluetooth security of the vehicle system, the access module connects to the Bluetooth of the vehicle system, and the artificial intelligence module connects to the Bluetooth of the vehicle system through the access module to obtain the Bluetooth connection process data, and / or calls the communication security testing module to traverse the Bluetooth of the vehicle system to obtain the device connection information of the Bluetooth port, and / or calls the communication security testing module to capture data packets using Bluetooth communication.

[0075] In response to user requests to test the Bluetooth of the in-vehicle system, the AI ​​module can connect to the in-vehicle system's Bluetooth using the access module, view the Bluetooth connection process data, and determine whether pairing authentication exists during the process (this is just an example; the test results are recorded). The AI ​​module can also call the communication security test module to traverse the in-vehicle system's Bluetooth, obtain device connection data of the Bluetooth port, determine whether there are other hidden devices, record the test results, and capture data packets using Bluetooth communication, analyze them, check whether the communication data is encrypted, analyze the security mode used, and record the test results.

[0076] The communication security test of the vehicle system designed in this invention is divided into cellular network test, WIFI test and Bluetooth test. Users can select more detailed test tasks, and the artificial intelligence module will then perform the corresponding process test based on different test tasks to meet the test requirements.

[0077] Furthermore, the operating system security testing module integrates at least remote access tools, software debugging tools, and operating system vulnerability scanning tools. The access module connects to the operating system in the vehicle system. The artificial intelligence module calls the operating system security testing module to access the operating system, obtain account information from the operating system, and / or send the operating system account to the operating system security testing module, call the operating system security testing module to log in to the system, obtain the system login result, if the system login result is password protected, call the operating system security testing module to perform brute-force attack on the operating system, obtain the operating system attack result, and / or call the operating system security testing module to perform system privilege escalation operations on the operating system account, obtain the system privilege escalation operation result, and / or access the operating system's runtime through the access module. The system retrieves and displays access data for runtime attribute information, which includes at least location, SMS, and telephone information. It also sends information about the software to be tampered with to the operating system security testing module, calls the module to debug the operating system based on this information, and obtains the debugging results. Additionally, it calls the module to update the operating system and obtains the response data. Furthermore, it modifies the logs stored in the operating system and obtains the response data. Finally, it performs a vulnerability scan on the operating system and obtains the results.

[0078] As shown in Figure 8, the operating system security testing module integrates remote access tools, software debugging tools, and operating system vulnerability scanning tools, and has functions such as viewing the system, brute-force attack, system privilege escalation, software debugging, system tampering, and tampering with upgrade packages.

[0079] In response to user requests for security testing of the vehicle system's operating system, the AI ​​module connects to the operating system via the access module. It can then use the access tools in the operating system security testing module to view the operating system's account information, check for redundant accounts, and record the test results. The AI ​​module sends the found accounts (excluding passwords) to the operating system security testing module to log in and obtain the login result. Based on the login result, the AI ​​module determines whether the operating system has password protection. If login fails, password protection is present, meeting security requirements. In this case, the AI ​​module can further call the operating system security testing module to perform brute-force attacks on the operating system, obtaining the attack results. If unsuccessful, security requirements are met. The AI ​​module can also call the operating system security testing module to perform privilege escalation operations on the operating system's accounts, obtaining the results and recording whether the privilege escalation was successful. Furthermore, the AI ​​module can access the operating system's file permissions via the access module to check for appropriate allocation. It can also access the operating system's... The system's operational attribute information, including but not limited to the test object's phone calls, SMS messages, MMS messages, mobile network data, and location, can be accessed and displayed on the interface to analyze whether corresponding information is displayed and record the test results. The AI ​​module can also send information about the software to be tampered with to the operating system security testing module. This information may include, but is not limited to, modifying secure boot code, operating system signatures, and trusted roots. The AI ​​module then calls the operating system security testing module to debug the operating system based on this information and obtain the debugging results. Furthermore, the AI ​​module can call the operating system security testing module to update the operating system. This update may include, but is not limited to, updating upgrade packages, downgrading upgrade package versions, or changing signatures, and obtain the operating system's response data to the update. The AI ​​module can also call the operating system security testing module to read the log storage address, attempt to delete or overwrite logs, and obtain the operating system's response data to the log changes. Finally, the AI ​​module can call the operating system security testing module to perform vulnerability scanning on the operating system and obtain the vulnerability scan results. Users can choose to test the overall operating system security or any specific security detail. The AI ​​module only needs to respond to the user's selected test task by calling the corresponding access module or operating system security testing module. This is just an example.

[0080] The artificial intelligence module of this invention automatically calls the access module and / or the operating system security testing module to perform security testing on the operating system of the vehicle system based on the requirements of the task to be tested, thereby realizing fully automatic security testing of the vehicle system.

[0081] Furthermore, the application software security testing module integrates at least an application installation tool, an application address scanning tool, a vulnerability scanning tool, an application reverse engineering tool, and an application internet security detection tool. The artificial intelligence module sends unauthorized applications to the application software security testing module, calls the application software testing module to install unauthorized applications on the vehicle system, obtains the vehicle system's response data to the installation of unauthorized applications, and / or calls the application software security testing module to access the application data storage address so that the application software security testing module can scan for sensitive information in the application data and obtain the scanning results of the application software security testing module for sensitive information in the data, and / or calls the application software security testing module to perform vulnerability scans on various applications of the vehicle system and obtains the vulnerability scan results of the application software security testing module for various applications of the vehicle system, and / or calls the application software security testing module to use the application reverse engineering tool to detect the security of the application's running code and obtains the detection results of the application software security testing module using the application reverse engineering tool to detect the security of the application's running code, and / or calls the application software security testing module to trigger the internet access function of various applications and obtains the data of each application during the internet access process.

[0082] As shown in Figure 9, the application software security testing module designed in this embodiment of the invention integrates application (app) vulnerability scanning tools, app detection tools, session content analysis tools, app reverse engineering tools, binary reverse engineering tools, app code scanning tools, app debugging tools, fuzzing tools, process communication interception tools, and network data packet capture tools. It has functions such as scanning sensitive information, installing apps, scanning vulnerabilities, and detecting app internet access. This is just an example.

[0083] In response to user requests for security testing of in-vehicle system application software, the AI ​​module connects to the in-vehicle system via an access module. It automatically sends pre-installed unauthorized applications for testing to the application software security testing module, which then installs the unauthorized applications on the in-vehicle system and retrieves the system's response data. The AI ​​module accesses the application software's data storage address, scans for sensitive information, and retrieves the results. It can also use the ADB tool in the application software security testing module to export applications from the in-vehicle system and perform vulnerability scans, obtaining the results. Furthermore, based on user-selected task requirements, the AI ​​module can use application reverse engineering tools to reverse engineer the applications, checking for familiarity with debug mode and examining the software code for sensitive information or other security parameters. Finally, the AI ​​module can trigger the internet access functions of various applications to check for security during internet access.

[0084] This invention utilizes various tools within the access module and application software security testing module to perform security testing on application software within the vehicle system.

[0085] Furthermore, the data security testing module integrates at least a storage address access tool, a data packet capture tool, a file operation tool, and a data deletion function. The artificial intelligence module calls the data security testing module to access the data storage address in the vehicle system so that the data security testing module can detect whether there is sensitive information in the data; obtain the detection results of the data security testing module on whether there is sensitive information in the data, and / or, call the data security testing module to perform unauthorized operations on the stored files in the vehicle system and obtain the response data of the vehicle system to the unauthorized operation on the stored files, and / or, call the data packet capture tool in the data security testing module to obtain data packets during data transmission, and / or, call the data security testing module to delete target data in the vehicle system; after receiving feedback from the data security testing module that the target data in the vehicle system has been deleted, call the data security testing module to access the data storage address in the vehicle system and obtain the storage information of the target data in the vehicle system.

[0086] As shown in Figure 10, the data security testing module software designed in this embodiment of the invention integrates adb and network packet capture tools, and has functions such as accessing memory, accessing, tampering with, deleting files, capturing network data packets, and analyzing data packets.

[0087] In response to user requests for security testing of in-vehicle system data, the AI ​​module can call the data security testing module to access the data storage address, check for sensitive information in the data, and record the security test results. The AI ​​module can also call the data security testing module to perform unauthorized operations on stored files in the in-vehicle system. Unauthorized operations include, but are not limited to, unauthorized access, modification, and deletion, and the AI ​​module can obtain the in-vehicle system's response data to unauthorized operations on stored files. The AI ​​module can also trigger the data transmission function and call the packet capture tool of the data security testing module to obtain data packets, checking whether the data in the captured packets is encrypted or protected by other security measures. The AI ​​module can also trigger the in-vehicle system's data destruction function, then return to the storage address to check whether the data has been successfully destroyed, and record the test results. Users can choose to perform comprehensive data security testing or only test a specific task based on their actual needs. The AI ​​module only needs to select the access module and the data security testing module based on the user's chosen test task. This is just an example.

[0088] This invention utilizes various tools within the access module and data security testing module to perform security testing on the data in the vehicle system.

[0089] Step S302: Based on the pre-integrated vehicle system safety testing standards, perform safety analysis on the first test data and / or the second test data to determine the safety test results of the vehicle system.

[0090] Specifically, the artificial intelligence module integrates security test models corresponding to different task requirements, and step S302 above includes:

[0091] Step S3021: Input the first test data and / or the second test data obtained based on the requirements of the task to be tested into the corresponding safety test model, and output the vehicle system safety test results.

[0092] The safety test model is trained through the following steps: First, a test dataset for the vehicle system test corresponding to the current task is obtained. This dataset includes test data and corresponding safety test results, which are determined by analyzing the test data based on vehicle system safety test standards. Second, an initial safety test model for the current task is trained using the test dataset for the vehicle system test corresponding to the current task. This results in a trained safety test model for the current task, integrating the normal test process and abnormal test data for the current task. The test data includes both normal test processes and abnormal test data.

[0093] The artificial intelligence module designed in this embodiment of the invention dominates the operation of security testing. It integrates security test models corresponding to different information types. There is no limitation on the number of security test modules integrated or their corresponding prediction functions. Each type of information security test can correspond to one security test model, or each sub-task test under each security test type can correspond to one security test model. For example, based on the communication security test type, there can be one security test model. Alternatively, cellular network, WIFI, and Bluetooth tests can each correspond to one security test model. Or, each sub-task test under the cellular network test can correspond to one security test model. These are just examples.

[0094] Previously, the security test model needed to be trained. The training set mainly consisted of images and text, and should include different situations such as development boards, chips, silkscreen printing, wiring, and feedback results. For different functions to be implemented, corresponding training sets should be provided for training. For example, if image recognition function is required, then images from various scenarios should be used as the training set. The functionality can be referred to in the description of the subsequent testing process. All identification, analysis, and processing logic should be completed by the artificial intelligence module, as shown in Figure 11. For training the security test model, a large amount of relevant data needs to be collected first. Before using the relevant data to train the model, the data needs to be preprocessed, including cleaning, annotation, and transformation, to make the data more suitable for model learning. Then, according to the needs of the task and the characteristics of the data, a suitable artificial intelligence model is selected, including but not limited to neural networks, decision trees, or support vector machines. After selecting a suitable artificial intelligence model based on the actual application needs, the preprocessed data can be used to train the model. During the training process, the model parameters can be adjusted to minimize the loss function or maximize the prediction accuracy to obtain the trained security test model. The trained security test model can be evaluated using a validation set or a test set to measure the model's performance. Then, the security test model can be adjusted and optimized based on the evaluation results, such as adjusting model parameters or trying different model structures or training methods. This is just an example.

[0095] In the actual training process of the security test model, the test data can include normal test procedures and abnormal test data. The initial security test model for the current task is trained using the test dataset of the vehicle system test corresponding to the current task. For example, training the initial security test model using normal test procedures allows the security test model to perform sequential testing of normal test procedures in subsequent tests. For instance, when performing security testing on the normal login operation of the operating system, the normal procedure is to obtain the operating system's account information, log in to the operating system based on the account information, then determine if there is password protection. If there is password protection, a brute-force attack is performed on the system to determine if the brute-force attack is successful. This is only used as an example. For example, to ensure the order and accuracy of testing, the security testing model can be trained using abnormal test data. This allows the model to identify which test data is abnormal. For instance, if a strong password is required for Wi-Fi, then abnormal data would be weak passwords. When training the security testing model using weak passwords, the model can integrate these weak passwords based on the security test results. These integrated weak passwords can then be sent to the communication security testing module for Wi-Fi password setting requirement testing during subsequent tests. Finally, the test result is obtained, showing the vehicle system's response to the input weak password—whether it agrees to the change or indicates an incorrect password requirement. This is just one example.

[0096] Once optimized, the model can be deployed to real-world applications, such as using it for prediction or decision-making in software systems. Training the model is complex; however, this can be mitigated through customized development to reduce the types of training sets. For example, collecting data from a single manufacturer's in-vehicle infotainment system, whose development board specifications are relatively fixed, using a limited range of chips and wiring configurations, can reduce the number of training images needed, thus lowering the complexity of the data collection. Simultaneously, the AI ​​module needs analytical capabilities. After recognition, the extracted information is analyzed, such as silkscreen information analysis. Silkscreen typically contains manufacturer information but is not allowed to contain interface identifiers or other usable information. Interface-related information is also identified through intelligent recognition. This requires searching the internet for relevant publicly available information and identifying keywords to determine if the identifiers are related to debug ports, chip read / write operations, or other chip read / write capabilities. Finally, processing is performed, considering the order of testing and addressing different test phenomena or feedback results to generate the final test results.

[0097] The artificial intelligence module designed in this invention integrates different security test models corresponding to different information security test types. The security test model integrates normal test processes and abnormal test data corresponding to different tasks. Based on the corresponding security test model, the test data is tested and the security test results of the vehicle system are output. Compared with direct comparison test based on information security standards, it is more efficient and more accurate.

[0098] In one optional implementation, based on the user-selected task requirement, the system obtains first test data corresponding to the vehicle system through the access module, and / or calls the security test module corresponding to the task requirement to perform the corresponding task test on the vehicle system, and obtains second test data fed back by the corresponding security test module after completing the test, including: determining the normal test process corresponding to the task requirement based on the user-selected task requirement; generating a first test instruction based on the security test sequence in the normal test process, and sending the first test instruction to the access module according to the content of the first test instruction, obtaining the test data corresponding to the vehicle system through the access module, and / or sending the first test instruction to the security test module corresponding to the task requirement to perform the corresponding task test; wherein, the first... The test instruction is sent to the security test module corresponding to the task under test requirement to perform the corresponding task test. This includes: directly calling the security test module corresponding to the task under test requirement to perform the corresponding task test on the vehicle system, and / or calling the task under test requirement to perform the corresponding task test on the vehicle system using the abnormal test data in the first test instruction; after obtaining the test data obtained through the access module, and / or the test data fed back by the corresponding security test module after completing the test, a second test instruction is generated according to the security test sequence and the test data, and the second test instruction is replaced with the first test instruction. The steps of sending the first test instruction to the access module according to the content of the first test instruction are repeated until the normal test process is completed and the first test data and the second test data corresponding to the task under test requirement are obtained.

[0099] In this embodiment of the invention, after the artificial intelligence module responds to the user's selected test task requirement, it can determine the normal test process corresponding to the test task requirement based on the pre-trained security test model corresponding to the test task requirement. Then, based on the security test sequence in the normal test process, it distributes execution instructions to the access module and / or the corresponding security test module in a sequential order. Different test modules execute the instructions in parallel and feed back the execution results to the artificial intelligence module for analysis. For example, the artificial intelligence module generates a first test instruction corresponding to the first test based on the security test sequence and determines whether the content of the first test instruction is information that can be directly obtained through the access module, or whether it is necessary to directly call the test tools in the security test module for testing, or whether it is necessary to send the abnormal test data required for the task to the security test module before the security test module performs the corresponding task test.

[0100] After determining the content of the first test instruction, it can be sent to the corresponding module for security testing. After the test is completed, the access module and / or the corresponding security test module will feed back the test data, i.e. the execution result, to the artificial intelligence module. The artificial intelligence module can obtain the test data, analyze and make decisions, and then generate the second test instruction. Based on the content of the second test instruction, it calls the access module and / or the corresponding security test module to execute the corresponding test and obtain the test data. The above steps are repeated until the normal test process is completed, and the overall test data of the normal test process is obtained. The test data and execution results under each test instruction can also be obtained.

[0101] In this embodiment of the invention, the artificial intelligence module serves as the unified input and output interface of the system. It acquires the resources and permissions of the object under test through the access module and distributes execution instructions to other test modules sequentially and in a single order according to the actual task requirements. Different test modules execute the instructions in parallel and feed back the execution results to the artificial intelligence module for analysis. Unified management by the artificial intelligence module facilitates the execution control of the entire automated testing process, accurately analyzes the situation of each execution process, improves testing accuracy, and increases testing efficiency through parallel operation of each module.

[0102] In one alternative implementation, the artificial intelligence module responds to the self-functional error information sent by the security test module to be corrected, sets the function of the security test module to be corrected to an unavailable state, and prompts the user with the functional error information of the security test module to be corrected, so that the user can correct the error of the security test module to be corrected.

[0103] Among them, the self-function error information is sent by each safety test module to the artificial intelligence module when it determines that its own safety test function cannot operate normally after the vehicle system's safety test system is powered on.

[0104] In this embodiment of the invention, each module performs a self-test after power-on to check whether the function is operating normally. If an error is found, the module will directly transmit the detailed parameters of the error to the artificial intelligence module. The artificial intelligence module will display the error information and set the corresponding module's function to an unavailable state. The module will only be available after the error is corrected. This ensures the normal operation of the safety test and the accuracy of the test results, avoiding errors in the test results caused by the module itself.

[0105] As shown in Figure 12, this embodiment also provides a vehicle system security testing system. This security testing system includes an artificial intelligence module, an access module, and security testing modules corresponding to different information security testing types of the vehicle system, such as security testing module 1, security testing module 2, ..., security testing module n (this is just an example). The access module establishes a corresponding connection with the vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information testing type. The artificial intelligence module includes a memory and a processor, which are interconnected. The memory stores computer instructions, and the processor executes these computer instructions to perform the vehicle system security testing method described in the above embodiment. For detailed explanation, please refer to the above embodiment; further details will not be repeated here.

[0106] This embodiment also provides a safety testing device for an in-vehicle system, which is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0107] This embodiment provides a security testing device for an in-vehicle system, applied to an artificial intelligence module within an in-vehicle system security testing system. The in-vehicle system security testing system also includes an access module and security testing modules corresponding to different information security testing types of the in-vehicle system. The access module establishes a connection with the in-vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information testing type, as shown in Figure 13. It includes: a task testing module 1301, used to respond to test instructions for the user-selected test task, obtain first test data corresponding to the in-vehicle system through the access module based on the user-selected test task requirements, and / or call the security testing module corresponding to the test task requirements to perform corresponding task testing on the in-vehicle system, and obtain second test data fed back by the corresponding security testing module after completing the test; and an in-vehicle system security testing module 1302, used to perform security analysis on the first test data and / or the second test data based on pre-integrated in-vehicle system security testing standards, and determine the security test results of the in-vehicle system.

[0108] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.

[0109] In this embodiment, the vehicle system safety testing device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.

[0110] This invention also provides an artificial intelligence module having the safety testing device for the vehicle system shown in Figure 13.

[0111] Please refer to Figure 14, which is a schematic diagram of the structure of an artificial intelligence module provided in an optional embodiment of the present invention. As shown in Figure 14, the artificial intelligence module includes: one or more processors 10, a memory 20, and interfaces for connecting the various components, including high-speed interfaces and low-speed interfaces. The various components communicate with each other using different buses and can be installed on a common motherboard or otherwise as needed. The processors can process instructions executed within the artificial intelligence module, including instructions stored in or on memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple artificial intelligence modules can be connected, each device providing some of the necessary operations (e.g., as a server array, a set of blade servers, or a multiprocessor system). Figure 14 uses one processor 10 as an example.

[0112] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0113] The memory 20 stores instructions executable by at least one processor 10 to cause at least one processor 10 to perform the method shown in the above embodiments.

[0114] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the artificial intelligence module. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories may be connected to the artificial intelligence module via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0115] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0116] The artificial intelligence module also includes an input device 30 and an output device 40. The processor 10, memory 20, input device 30 and output device 40 can be connected via a bus or other means, as shown in Figure 14, which illustrates a connection via a bus.

[0117] Input device 30 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the artificial intelligence module, such as a touchscreen, keypad, mouse, trackpad, touchpad, joystick, one or more mouse buttons, trackball, joystick, etc. Output device 40 may include display devices, auxiliary lighting devices (e.g., LEDs), and haptic feedback devices (e.g., vibration motors). The aforementioned display devices include, but are not limited to, liquid crystal displays, light-emitting diodes, displays, and plasma displays. In some alternative embodiments, the display device may be a touchscreen.

[0118] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.

[0119] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.

[0120] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A safety testing method for an in-vehicle system, characterized in that, An artificial intelligence module is applied to a security testing system for in-vehicle systems. The in-vehicle system security testing system also includes an access module and security testing modules corresponding to different information security test types of the in-vehicle system. The access module establishes a connection with the in-vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information test type. The method includes: responding to a test instruction for a user-selected test task, obtaining first test data corresponding to the in-vehicle system through the access module based on the user-selected test task requirements, and / or calling the security testing module corresponding to the test task requirements to perform the corresponding task test on the in-vehicle system. The system obtains second test data fed back by the corresponding security test module after completing the test. The artificial intelligence module makes a decision based on the task under test, choosing to obtain data through the access module or by calling the corresponding security test module. The artificial intelligence module integrates security test models corresponding to different task requirements. Based on pre-integrated vehicle system security test standards, the system performs security analysis on the first and / or second test data to determine the vehicle system security test results. This includes inputting the first and / or second test data obtained based on the requirements of the task under test into the corresponding security test model and outputting the vehicle system security test results. The security test model uses the following... The training process involves: acquiring a test dataset for the vehicle system test corresponding to the current task. This dataset includes test data and corresponding security test results. The test data includes normal test procedures and abnormal test data. The security test results are determined by analyzing the test data based on vehicle system security test standards. The initial security test model corresponding to the current task is trained using the test dataset to obtain a pre-trained security test model that integrates both normal test procedures and abnormal test data. The process is further refined based on the user-selected test task requirements. The module obtains the first test data corresponding to the vehicle system, and / or calls the security test module corresponding to the task requirement to perform the corresponding task test on the vehicle system, and obtains the second test data fed back by the corresponding security test module after the test is completed. This includes: determining the normal test process corresponding to the task requirement to be tested based on the user-selected task requirement; generating a first test instruction based on the security test sequence in the normal test process, and sending the first test instruction to the access module according to the content of the first test instruction; obtaining the test data corresponding to the vehicle system through the access module, and / or sending the first test instruction to the security test module corresponding to the task requirement to perform the corresponding task test.The process of sending the first test instruction to the security test module corresponding to the task under test includes: directly calling the security test module corresponding to the task under test to test the vehicle system for the corresponding task, and / or calling the task under test to test the vehicle system for the corresponding task using the abnormal test data in the first test instruction; after obtaining the test data obtained through the access module, and / or the test data fed back by the corresponding security test module after completing the test, generating a second test instruction according to the security test sequence and the test data, replacing the first test instruction with the second test instruction, and repeating the step of sending the first test instruction to the access module according to the content of the first test instruction, until the normal test process is completed and the first test data and second test data corresponding to the task under test are obtained; based on the pre-integrated vehicle system security test standard, performing security analysis on the first test data and / or the second test data to determine the security test result of the vehicle system.

2. The method according to claim 1, characterized in that, The security testing modules corresponding to the different information security testing types include at least a hardware security testing module, a communication security testing module, an operating system security testing module, an application software security testing module, and a data security testing module.

3. The method according to claim 2, wherein the hardware security testing module integrates tools that can access and operate the vehicle system debugging port, and if the task to be tested includes testing the hardware security of the vehicle system, the step of obtaining the first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task to be tested to perform the corresponding task test on the vehicle system, and obtaining the second test data fed back by the corresponding security testing module after completing the test, includes: The control information input to the vehicle system is sent to the hardware security test module, the hardware security test module is invoked to access the debugging interface of the vehicle system, and the control information is input to the vehicle system. The hardware security testing module obtains the process data fed back after accessing the debugging interface of the vehicle system and inputting the control information, and / or obtains the development board image in the vehicle system through the access module, the access module including an image acquisition device for connecting to the debugging interface of the vehicle system to obtain the development board image.

4. The method according to claim 2, characterized in that, The communication security testing module integrates at least network card hardware, port scanning tools, packet capture tools, and data packet tampering tools. If the task to be tested includes testing the cellular network security of the vehicle system, the access module connects to the cellular network of the vehicle system. The steps of obtaining the first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task to be tested to perform the corresponding task test on the vehicle system, and obtaining the second test data fed back by the corresponding security testing module after completing the test, include: calling the communication security testing module to scan the cellular network address of the vehicle system and connecting it to an open port; obtaining the connection result of the communication security testing module with the open port, and / or controlling the vehicle system to communicate using the cellular network through the access module, using the packet capture tool of the communication security testing module to capture data packets during the communication process, and / or sending the data packet to be tampered to the communication security testing module, calling the communication security testing module to tamper with the data packets of the vehicle system based on the data packet to be tampered, and obtaining the response status of the vehicle system to the data packet to be tampered.

5. The method according to claim 2, characterized in that, The communication security testing module integrates at least WIFI network hardware, WIFI packet capture tools, and brute-force cracking tools. If the task to be tested includes testing the WIFI security of the vehicle system, the access module connects to the WIFI of the vehicle system. The first test data corresponding to the vehicle system is obtained through the access module, and / or the security testing module corresponding to the task to be tested is invoked to perform the corresponding task test on the vehicle system, and the second test data fed back by the corresponding security testing module after the test is completed is obtained. This includes: entering the WIFI settings interface of the vehicle system through the access module and obtaining WIFI settings information, and / or changing the WIFI password of the vehicle system to a password that does not meet the settings requirements through the access module and obtaining the WIFI password change response information, and / or invoking the communication security testing module to perform brute-force cracking on the WIFI password and obtaining the cracking result of the brute-force cracking on the WIFI password by the communication security testing module, and / or invoking the communication security testing module to capture data packets using WIFI communication.

6. The method according to claim 2, characterized in that, The communication security testing module integrates at least Bluetooth hardware, a Bluetooth packet capture tool, and a port scanning tool. If the task to be tested includes testing the Bluetooth security of the vehicle system, the access module connects to the Bluetooth of the vehicle system. The steps of obtaining the first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task to be tested to perform the corresponding task test on the vehicle system, and obtaining the second test data fed back by the corresponding security testing module after completing the test, include: connecting to the Bluetooth of the vehicle system through the access module, obtaining the Bluetooth connection process data, and / or calling the communication security testing module to traverse the Bluetooth of the vehicle system to obtain the device connection information of the Bluetooth port, and / or calling the communication security testing module to capture data packets using Bluetooth communication.

7. The method according to claim 2, characterized in that, The operating system security testing module integrates at least a remote access tool, a software debugging tool, and an operating system vulnerability scanning tool. The access module connects to the operating system in the vehicle system. The process involves obtaining first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task under test to perform corresponding task testing on the vehicle system, and obtaining second test data returned by the corresponding security testing module after completing the test. This includes: calling the operating system security testing module to access the operating system, obtaining account information in the operating system, and / or sending the operating system account to the operating system security testing module, calling the operating system security testing module to log in to the system, obtaining the system login result, and if the system login result is password protected, calling the operating system security testing module to perform a brute-force attack on the operating system, obtaining the operating system attack result, and / or calling the operating system security testing module to perform a brute-force attack on the operating system. The system account performs system privilege escalation operations and obtains the system privilege escalation operation results; and / or, accesses the operating system's runtime attribute information through the access module and obtains the access display data of the runtime attribute information, wherein the runtime attribute information includes at least location, SMS, and telephone; and / or, sends information related to the software to be tampered with to the operating system security testing module, calls the operating system security testing module to debug the operating system software based on the information related to the software to be tampered with, and obtains the debugging results of the operating system security testing module on the operating system software; and / or, calls the operating system security testing module to perform system updates on the operating system and obtains the operating system's response data to the system update; and / or, calls the operating system security testing module to modify the logs stored in the operating system and obtains the operating system's response data to the modified logs; and / or, calls the operating system security testing module to perform vulnerability scanning on the operating system and obtains the vulnerability scanning results of the operating system.

8. The method according to claim 2, characterized in that, The application software security testing module integrates at least an application installation tool, an application address scanning tool, a vulnerability scanning tool, an application reverse engineering tool, and an application internet security detection tool. The process involves obtaining first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task requirements to perform corresponding task tests on the vehicle system, and obtaining second test data returned by the corresponding security testing module after completing the test. This includes: sending an unauthorized application to the application software security testing module, calling the application software testing module to install the unauthorized application on the vehicle system, obtaining the vehicle system's response data to the installation of the unauthorized application, and / or calling the application software security testing module to access application data storage. The application software security testing module can be used to scan application data for sensitive information, obtain the scanning results of the application software security testing module on sensitive information in the data, and / or, call the application software security testing module to perform vulnerability scans on various applications of the vehicle system, obtain the vulnerability scan results of the application software security testing module on various applications of the vehicle system, and / or, call the application software security testing module to use application reverse engineering tools to detect the security of the application's running code, obtain the detection results of the application software security testing module using application reverse engineering tools on the security of the application's running code, and / or, call the application software security testing module to trigger the internet access function of various applications, obtain the data of each application during the internet access process.

9. The method according to claim 2, characterized in that, The data security testing module integrates at least a storage address access tool, a data packet capture tool, a file operation tool, and a data deletion function. The process of obtaining first test data corresponding to the vehicle system through the access module, and / or calling the security testing module corresponding to the task requirements to perform corresponding task tests on the vehicle system, and obtaining second test data fed back by the corresponding security testing module after completing the test, includes: calling the data security testing module to access the data storage address in the vehicle system to allow the data security testing module to detect whether there is sensitive information in the data; obtaining the detection result of the data security testing module on whether there is sensitive information in the data, and / or calling the data security testing module to perform unauthorized operations on the storage files in the vehicle system, obtaining the response data of the vehicle system to the unauthorized operation on the storage files, and / or calling the data packet capture tool in the data security testing module to obtain data packets during data transmission, and / or calling the data security testing module to delete target data in the vehicle system; after receiving feedback from the data security testing module after deleting the target data in the vehicle system, calling the data security testing module to access the data storage address in the vehicle system to obtain the storage information of the target data in the vehicle system.

10. The method according to claim 1, characterized in that, The method further includes: responding to the self-function error information sent by the safety test module to be corrected, setting the function of the safety test module to be corrected to an unavailable state, and prompting the user with the self-function error information of the safety test module to be corrected, so that the user can correct the error of the safety test module to be corrected. The self-function error information is sent by each safety test module to the artificial intelligence module when it determines that its own safety test function cannot operate normally after the vehicle system's safety test system is powered on and performs a self-test.

11. A safety testing device for an in-vehicle system, characterized in that, An artificial intelligence module is applied to a security testing system for in-vehicle systems. The in-vehicle system security testing system also includes an access module and security testing modules corresponding to different information security test types of the in-vehicle system. The access module establishes a connection with the in-vehicle system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information test type. The device includes: a task testing module, used to respond to test instructions for the user-selected test task, and based on the user-selected test task requirements, obtain first test data corresponding to the in-vehicle system through the access module, and / or, call the security testing modules corresponding to the test task requirements to perform corresponding tests on the in-vehicle system. The system performs testing according to the task and obtains second test data fed back by the corresponding security testing module after the test is completed. The artificial intelligence module makes a decision based on the task under test, choosing to obtain data through the access module or by calling the corresponding security testing module. The artificial intelligence module integrates security testing models corresponding to different task requirements. Based on pre-integrated vehicle system security testing standards, the system performs security analysis on the first and / or second test data to determine the vehicle system security test results. This includes: inputting the first and / or second test data obtained based on the requirements of the task under test into the corresponding security testing model and outputting the vehicle system security test results. The model is trained through the following steps: First, a test dataset for the vehicle system test corresponding to the current task is obtained. This test dataset includes test data and corresponding security test results. The test data includes normal test procedures and abnormal test data. The security test results are determined by analyzing the test data based on vehicle system security test standards. Second, an initial security test model corresponding to the current task is trained using the test dataset for the vehicle system test corresponding to the current task. This results in a trained security test model that integrates the normal test procedures and abnormal test data corresponding to the current task. Third, based on the user-selected requirements of the test task, the model is further trained... The system acquires first test data corresponding to the vehicle system through the access module, and / or calls the security test module corresponding to the task requirement under test to perform corresponding task testing on the vehicle system, and acquires second test data fed back by the corresponding security test module after completing the test, including: determining the normal test process corresponding to the task requirement under test based on the user-selected task requirement under test; generating a first test instruction based on the security test sequence in the normal test process, and sending the first test instruction to the access module according to the content of the first test instruction; acquiring the test data corresponding to the vehicle system through the access module, and / or sending the first test instruction to the security test module corresponding to the task requirement under test to perform corresponding task testing;The process of sending the first test instruction to the security test module corresponding to the task under test includes: directly calling the security test module corresponding to the task under test to test the vehicle system for the corresponding task, and / or calling the task under test to test the vehicle system for the corresponding task using the abnormal test data in the first test instruction; after obtaining the test data obtained through the access module, and / or the test data fed back by the corresponding security test module after completing the test, generating a second test instruction according to the security test sequence and the test data, replacing the first test instruction with the second test instruction, and repeating the step of sending the first test instruction to the access module according to the content of the first test instruction, until the normal test process is completed and the first test data and second test data corresponding to the task under test are obtained; the vehicle system security test module is used to perform security analysis on the first test data and / or the second test data based on the pre-integrated vehicle system security test standard to determine the security test results of the vehicle system.

12. A safety testing system for an in-vehicle system, characterized in that, The vehicle-mounted system security testing system includes an artificial intelligence module, an access module, and security testing modules corresponding to different information security testing types of the vehicle-mounted system. The access module establishes a corresponding connection with the vehicle-mounted system based on the user-selected test task requirements. The artificial intelligence module establishes connections with the access module and the security testing modules corresponding to each different security information testing type. The artificial intelligence module includes a memory and a processor, which are interconnected. The memory stores computer instructions, and the processor executes the computer instructions to perform the vehicle-mounted system security testing method according to any one of claims 1 to 10.

13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the safety testing method for the vehicle system according to any one of claims 1 to 10.

14. A computer program product, characterized in that, It includes computer instructions for causing a computer to perform a safety testing method for an in-vehicle system as described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • Security test method for vehicle-mounted information service system

    CN115454684A

  • Universal information safety testing device and method for vehicle-mounted parts

    CN115481404A

  • Intelligent automobile, testing method and device thereof and electronic equipment

    CN116340168A