Vehicle diagnosis 27 service safety detection method, device, equipment and medium
By detecting whether the 27 authentication function of the 27 service is implemented and effective, the problem of inaccurate detection results in the prior art is solved, and the security of the 27 service is improved.
Patent Information
- Application Number
- CN202311512656.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-05-23
AI Technical Summary
In the prior art, the method of detecting the security of 27 services is single, resulting in inaccurate judgment results, and the security of 27 services is low.
By detecting whether the 27 authentication function of the 27 service is implemented and valid, if the authentication function is not implemented or invalid, it is determined that the 27 service is not safe.
Through two aspects of testing, the accuracy of the test results is improved and the security of 27 services is enhanced.
Smart Images

Figure CN120029888A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of information security technology, and in particular, relates to a method, device, equipment and medium for detecting the security of vehicle diagnostic 27 services. Background Art
[0002] The purpose of Unified Diagnostic Services (UDS) is to quickly and accurately determine the faults and causes of a vehicle or a controller, thereby providing a reliable basis for maintenance. UDS diagnostic services include 6 categories, a total of 26 types, and 27 services are one of these 26 services, also known as secure access services. The vehicle's Electronic Control Unit (ECU) is locked by default and can only be unlocked and flashed after passing the 27 authentication of the 27 service. Therefore, the security of the 27 service is extremely important.
[0003] In the related art, the length and randomness of the seed obtained during the 27 authentication process are detected to determine whether the 27 service is secure. However, due to the single detection method, the judgment result is not accurate enough, and the security of the 27 service is low. Summary of the invention
[0004] The purpose of the embodiments of the present application is to provide a method, device, equipment and medium for detecting the safety of vehicle diagnostic 27 services, so as to solve the problem in the related art that the judgment results are not accurate enough and the safety of 27 services is low due to the single detection method.
[0005] To achieve the above objectives, the present application embodiment adopts the following technical solutions:
[0006] In a first aspect, an embodiment of the present application provides a method for detecting the security of a vehicle diagnostic 27 service, including: detecting whether a 27 authentication function of the 27 service is implemented; detecting whether the 27 authentication function is valid; if the 27 authentication function is not implemented, or the 27 authentication function is invalid, determining that the 27 service is unsafe.
[0007] In the second aspect, an embodiment of the present application provides a detection device for the security of a vehicle diagnostic 27 service, including: a first detection module, used to detect whether a 27 authentication function of the 27 service is implemented; a second detection module, used to detect whether the 27 authentication function is valid; a determination module, used to determine that the 27 service is unsafe if the 27 authentication function is not implemented or the 27 authentication function is invalid.
[0008] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the method described in the embodiment of the first aspect of the present application.
[0009] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the embodiment of the first aspect of the present application are implemented.
[0010] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects:
[0011] When testing the security of the 27 service, the embodiment of the present application tests whether the 27 authentication function of the 27 service is implemented and whether the 27 authentication function is valid. If the 27 authentication function is not implemented or the 27 authentication function is invalid, the 27 service is determined to be unsafe. The embodiment of the present application determines the security of the 27 service by testing the 27 service in two aspects (whether the 27 authentication function is implemented and whether it is valid). The two-angle detection method realizes the diversification of the detection method, thereby improving the accuracy of the detection result and making the 27 service more secure. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0013] Figure 1 A schematic flow chart of a method for detecting the safety of a vehicle diagnostic 27 service provided in accordance with an embodiment of the present application;
[0014] Figure 2 A flowchart of a method for detecting the safety of a vehicle diagnostic 27 service provided in accordance with another embodiment of the present application;
[0015] Figure 3 A flowchart of a method for detecting the safety of a vehicle diagnostic 27 service provided in accordance with another embodiment of the present application;
[0016] Figure 4 A flowchart of a method for detecting the safety of a vehicle diagnostic 27 service provided in accordance with another embodiment of the present application;
[0017] Figure 5 A schematic diagram of the overall process of a method for detecting the safety of a vehicle diagnostic 27 service provided by an embodiment of the present application;
[0018] Figure 6 A schematic diagram of the structure of a detection device for vehicle diagnostic 27 service safety provided by one embodiment of the present application;
[0019] Figure 7 A schematic diagram of the structure of a detection device for vehicle diagnostic 27 service safety provided in another embodiment of the present application;
[0020] Figure 8 A schematic diagram of the structure of an electronic device provided for one embodiment of the present application. DETAILED DESCRIPTION
[0021] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0022] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here. In addition, the "and / or" in this application represents at least one of the connected objects, and the character " / " generally represents that the front and back associated objects are in an "or" relationship. It should be noted that the data involved in this application are all obtained on the premise of obtaining user authorization.
[0023] The Unified Diagnostic Services (UDS) diagnostic protocol is a requirement specification for diagnostic communications in the automotive industry, defined by the ISO-14229 series of standards. The UDS diagnostic protocol is applied to the application layer (layer 7) of the Open System Interconnect (OSI) seven-layer model. Since it only specifies service requirements related to diagnosis and does not involve communication mechanisms, it can be implemented on different automotive buses, such as the Controller Area Network (CAN) bus, Local Interconnect Network (LIN) bus, Flexray bus, Ethernet bus, and K-line bus.
[0024] The purpose of UDS is to quickly and accurately determine the faults and causes of a vehicle or a controller, thereby providing a reliable basis for maintenance. UDS diagnostic services include 6 categories, a total of 26 types, and 27 services are one of these 26 services. 27 services are also called secure access services, which provide a method for accessing data or diagnostic services. Only through the Seed-key unlocking link can specific services and functions be executed. This service provides a protection mechanism that is used to protect diagnostic services with access restrictions.
[0025] The vehicle's Electronic Control Unit (ECU) is locked by default and can only be unlocked and flashed after passing the 27 authentication of the 27 service. Therefore, the security of the 27 service is extremely important.
[0026] The 27 authentication method is developed by ECU developers according to the requirements of car companies. The 27 authentication process is generally as follows: 1) The client (Tester) requests the 27 seed from the ECU, 2) The ECU replies with the 27 seed (generally generated randomly), 3) After the Tester receives the seed, it calculates and processes it through the previously built-in algorithm, and sends the processed key (KEY) to the ECU, 4) After the ECU receives the KEY sent by the Tester, it compares it with the internally calculated KEY. If the KEY is correct, it replies with a correct response code and unlocks successfully; if the KEY is wrong, it replies with a negative response code and unlocks unsuccessfully.
[0027] In the related art, the length and randomness of the seed obtained during the 27 authentication process are detected to determine whether the 27 service is safe. However, due to the single detection method, the judgment result is not accurate enough, and the security of the 27 service is low. To this end, the present application proposes a detection method, device, electronic device and storage medium for the security of vehicle diagnosis 27 service, so as to solve the problem in the related art that due to the single detection method, the judgment result is not accurate enough and the security of the 27 service is low.
[0028] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.
[0029] Figure 1 A flow chart of a method for detecting the safety of a vehicle diagnostic service 27 provided in one embodiment of the present application. Figure 1 As shown, the method for detecting the safety of the vehicle diagnosis service 27 in the embodiment of the present application may specifically include the following steps:
[0030] S101, checking whether the 27 authentication function of the 27 service is realized.
[0031] In the embodiment of the present application, the execution subject of the detection method of the vehicle diagnosis 27 service safety of the embodiment of the present application is the detection device of the vehicle diagnosis 27 service safety, and the detection device of the vehicle diagnosis 27 service safety can be set in an electronic device. The electronic device can be a terminal device or a server. Among them, the terminal device can be a mobile phone, a tablet computer, a desktop computer, a portable notebook, a vehicle-mounted device, etc.; the server can be an independent server or a server cluster composed of multiple servers.
[0032] Whether the 27 authentication function is implemented, that is, whether the 27 authentication function has been developed and deployed in the ECU, and whether the 27 authentication process can be executed normally, that is, whether the following functions have been developed and deployed in the ECU: the ECU is in a locked state by default, and if the 27 authentication is successful, the ECU is unlocked and can be flashed; if the 27 authentication fails, the ECU is not unlocked and cannot be flashed.
[0033] Whether the 27 authentication function of the 27 service is implemented is detected to obtain a corresponding first detection result. The first detection result may specifically include two types: the 27 authentication function is not implemented and the 27 authentication function is implemented.
[0034] S102, checking whether the authentication function 27 is valid.
[0035] In the embodiment of the present application, whether the 27 authentication function is valid, that is, whether the authentication accuracy or authentication effect of the 27 authentication function meets the requirements, that is, whether the protection effect of the ECU after executing the 27 authentication process meets the requirements, or whether the execution of the 27 authentication process really plays a role in protecting the ECU and avoiding hacker attacks.
[0036] Whether the 27 authentication function of the 27 service is valid is detected to obtain a corresponding second detection result. The second detection result may specifically include two types: the 27 authentication function is valid and the 27 authentication function is invalid.
[0037] S103: If the 27 authentication function is not implemented or the 27 authentication function is invalid, it is determined that the 27 service is not safe.
[0038] In the embodiment of the present application, whether the service 27 is safe is comprehensively determined based on whether the two detection results (the first detection result and the second detection result) meet the requirements.
[0039] Specifically, if the first test result is that the 27 authentication function is not implemented, or the second test result is that the 27 authentication function is invalid, then the 27 service is determined to be unsafe. If the first test result is that the 27 authentication function is implemented, and the second test result is that the 27 authentication function is valid, then the 27 service is determined to be safe.
[0040] In summary, the method for detecting the safety of the vehicle diagnosis 27 service of the embodiment of the present application, when detecting the safety of the 27 service, detects whether the 27 authentication function of the 27 service is realized, and detects whether the 27 authentication function is valid. If the 27 authentication function is not realized, or the 27 authentication function is invalid, it is determined that the 27 service is unsafe. The embodiment of the present application determines the safety of the 27 service by detecting two aspects of the 27 service (whether the 27 authentication function is realized and whether it is valid). The detection method from two angles realizes the diversification of the detection method, thereby improving the accuracy of the detection result, making the 27 service more secure.
[0041] Figure 2 A flow chart of a method for detecting the safety of a vehicle diagnostic service 27 is provided as another embodiment of the present application. Figure 2 As shown, in Figure 1 Based on the illustrated embodiment, the method for detecting the safety of the vehicle diagnosis service 27 in the embodiment of the present application may specifically include the following steps:
[0042] In the above embodiment, step S101 “detecting whether the 27 authentication function of the 27 service is implemented” may specifically include the following steps S201-S203.
[0043] S201, before performing 27 authentication, the electronic control unit of the vehicle is flashed.
[0044] In the embodiment of the present application, under normal circumstances, the ECU is in a locked state by default. When flashing the ECU, it must first pass 27 authentication. After the ECU is unlocked, the flashing operation can be performed on the ECU.
[0045] In the embodiment of the present application, in order to detect whether the 27 authentication function is realized, the ECU can be directly flashed without performing 27 authentication, that is, without going through the 27 authentication process, that is, before performing 27 authentication.
[0046] S202, if the flashing is successful, it is determined that the authentication function 27 is not implemented.
[0047] In the embodiment of the present application, under normal circumstances, the ECU is in a locked state by default. Only after 27 authentication and successful authentication, the ECU will be unlocked and the ECU can be flashed.
[0048] In the embodiment of the present application, the ECU is directly flashed without going through 27 authentication, and the flashing is successful, which indicates that the ECU is in an unlocked state by default and can be flashed at will. Even if it has not gone through 27 authentication, or has gone through 27 authentication but failed, the flashing operation on the ECU can be performed. Therefore, it can be determined that the following functions have not been developed and deployed in the ECU: the ECU is in a locked state by default, the 27 authentication is successful, the ECU is unlocked, and can be flashed; the 27 authentication fails, the ECU is not unlocked and cannot be flashed, that is, the 27 authentication function is not implemented, and the 27 service is unsafe in this case.
[0049] S203, if the flashing is unsuccessful, it is determined that the authentication function has been implemented.
[0050] In the embodiment of the present application, the ECU is directly flashed without going through the 27 authentication, but the flashing fails, which indicates that the ECU is in a locked state by default and cannot be flashed at will. Only after the 27 authentication and the authentication is successful, can the flashing operation on the ECU be performed. Therefore, it can be determined that the following functions have been developed and deployed in the ECU: the ECU is in a locked state by default, the 27 authentication is successful, the ECU is unlocked, and can be flashed; if the 27 authentication fails, the ECU is not unlocked and cannot be flashed, that is, the 27 authentication function has been implemented, and the 27 service is relatively safe in this case.
[0051] In the above embodiment, step S102 “detecting whether the authentication function is valid” may specifically include the following steps S204-S208.
[0052] S204, checking whether the 27 seeds are completely random.
[0053] In the embodiment of the present application, in step 2) of the 27 authentication process, the ECU replies 27 a seed (generally generated randomly) to the Tester.
[0054] The 27 seeds replied by the ECU to the tester are obtained, and the 27 seeds are tested to see whether they are completely random, to obtain a third test result. The third test result may specifically include two types: the 27 seeds are completely random and the 27 seeds are not completely random.
[0055] like Figure 3 As shown, the 27 seeds may be tested for regularity and repeated seeds to determine whether the 27 seeds are completely random, which may specifically include the following steps:
[0056] S301, obtaining a set number of 27 seeds, where the set number is equal to or greater than a preset number threshold.
[0057] In the embodiment of the present application, the minimum number of 27 seeds to be obtained can be preset, that is, the number threshold of obtaining 27 seeds can be preset. The number threshold can be set according to user needs, but it cannot be set too small to avoid the detection error of regularity and repeated seeds due to the small number of 27 seeds and the inability to fully reflect the characteristics of 27 seeds.
[0058] According to the set quantity threshold, set the actual number of 27 seeds to be obtained, which is recorded as the set number. The set number must be greater than the quantity threshold. Periodically (for example, with a period of 100 milliseconds) obtain 27 seeds. When the number of 27 seeds obtained reaches the set number, stop obtaining.
[0059] S302, determining whether there is regularity among the set number of 27 seeds, and whether there are repeated seeds.
[0060] In the embodiment of the present application, it is determined whether there is regularity among the set number of 27 seeds. For example, if the set number of 27 seeds are arranged in an arithmetic progression, it is determined that there is regularity among the set number of 27 seeds.
[0061] It is determined whether there are duplicate seeds among the set number of 27 seeds. For example, if the first seed and the tenth seed are the same, it is determined that there are duplicate seeds among the set number of 27 seeds.
[0062] S303, if there is no regularity and no repeated seeds, determine that the 27 seeds are completely random.
[0063] In the embodiment of the present application, if there is no regularity in the set number of 27 seeds and there are no repeated seeds, it is determined that the 27 seeds are completely random. In this case, the 27 service is relatively safe.
[0064] S304: If there is a regularity, determine that the 27 seeds are not completely random.
[0065] In the embodiment of the present application, if there is regularity in the set number of 27 seeds, it is determined that the 27 seeds are not completely random, and there is a certain security risk.
[0066] S305, if there are duplicate seeds, then reacquire a set number of 27 seeds, and determine whether there are duplicate seeds in the set number of 27 seeds; if so, then determine that the 27 seeds are not completely random; if not, then determine that the 27 seeds are completely random.
[0067] In the embodiment of the present application, if there are duplicate seeds among the set number of 27 seeds, in order to exclude the possibility that the duplicate seeds occur randomly and accidentally rather than frequently, a second judgment of the duplicate seeds may be performed, i.e., the set number of 27 seeds are obtained again to determine whether there are duplicate seeds among the set number of 27 seeds.
[0068] If there are still repeated seeds in the set number of 27 seeds that are re-acquired, it is determined that the repeated seeds and the previous repeated seeds did not appear randomly by chance, and further determined that the 27 seeds are not completely random.
[0069] If there are no repeated seeds in the set number of 27 seeds that are re-obtained, it is determined that the previous repetition occurred randomly by chance, and further that the 27 seeds are completely random.
[0070] S205, checking whether the authentication function 27 allows blasting.
[0071] In the embodiment of the present application, unlike the normal unlocking process (the ECU compares the KEY calculated based on the 27 seeds with the KEY calculated by the Tester based on the 27 seeds, and unlocks if the comparison is consistent), the 27 authentication function is blasted, that is, by sending a specific KEY to the ECU, the ECU is forcibly controlled to unlock.
[0072] If this forced unlocking process is set in the ECU, the 27 authentication function allows the blasting. If this forced unlocking process is not set in the ECU, the 27 authentication function does not allow the blasting.
[0073] Whether the 27 authentication function allows blasting is detected to obtain a fourth detection result. The fourth detection result may specifically include two types: the 27 authentication function allows blasting and the 27 authentication function does not allow blasting.
[0074] Specifically, the following steps can be used to detect whether the 27 authentication function allows cracking: In step 3) of the 27 authentication process, any KEY can be sent to the ECU to receive the negative response code returned by the ECU. If the returned negative response code includes a negative response code indicating that the cracking is impossible, it is determined that the 27 authentication function does not allow cracking. If the returned negative response code does not include a negative response code indicating that the cracking is impossible, it is determined that the 27 authentication function allows cracking. For example, according to ISO-14229, if the negative response code includes 35, 36 and / or 37 negative response codes indicating that the cracking is impossible, it means that the ECU cannot be cracked, and in this case the 27 service is relatively safe; if the negative response code does not include 35, 36 and / or 37 negative response codes indicating that the cracking is impossible, it means that the ECU allows cracking, and in this case there is a certain security risk in the 27 service.
[0075] S206, detecting whether the authentication function 27 is a fixed key blasting.
[0076] In the embodiment of the present application, if it is determined in step S205 that the 27 authentication function allows blasting, it is possible to further detect whether the 27 authentication function is a fixed KEY blasting to obtain a fifth detection result. The fifth detection result may specifically include two types: the 27 authentication function is a fixed KEY blasting and the 27 authentication function is a non-fixed KEY blasting.
[0077] If the ECU is cracked using a fixed KEY, the ECU can be cracked by enumerating the KEY, which poses a certain security risk. Therefore, it is necessary to test whether the ECU can be cracked using a fixed KEY. Figure 4 As shown, the following steps may be specifically included:
[0078] S401, when the 27 authentication function allows blasting, a blasting test is performed by sequentially sending keys in a key set to an electronic control unit of the vehicle to obtain a blasting test result.
[0079] In the embodiment of the present application, if it is determined in step S205 that the 27 authentication function allows cracking, the cracking test can be performed by enumerating each KEY in the KEY set, that is, each KEY in the KEY set is sent to the ECU for cracking test in sequence, and the cracking test result is obtained according to the result of whether the ECU is cracked. The cracking test result may specifically include the KEY corresponding to the cracking in the KEY set and the KEY corresponding to the cracking that does not exist.
[0080] S402: If the blasting test result shows that the key corresponding to the blasting exists in the key set, it is determined that the authentication function 27 is a fixed key blasting.
[0081] In the embodiment of the present application, if the blasting test result is that there is a KEY corresponding to the blasting in the KEY set, it means that the ECU can be blasted by enumerating the KEYs, and then it is determined that the 27 authentication function is a fixed KEY blasting.
[0082] S403: If the blasting test result is that the key corresponding to the blasting does not exist in the key set, it is determined that the 27 authentication function is a non-fixed key blasting.
[0083] In the embodiment of the present application, if the cracking test result is that the KEY corresponding to the cracking does not exist in the KEY set, it means that the cracking of the ECU cannot be achieved by enumerating the KEYs, and then it is determined that the 27 authentication function is a non-fixed KEY cracking.
[0084] S207, if the 27 seed is not completely random, or the 27 authentication function allows blasting and is a fixed key blasting, it is determined that the 27 authentication function is invalid.
[0085] In the embodiment of the present application, whether the 27 authentication function is valid is comprehensively determined based on whether the three test results (the third test result, the fourth test result and the fifth test result) meet the requirements.
[0086] Specifically, if any one of the following two conditions is met: 1) the third test result is that the 27 seed is not completely random, 2) the fourth test result is that the 27 authentication function allows brute force, and the fifth test result is that the 27 authentication function is a fixed key brute force, then it is determined that the 27 authentication function is invalid. In this case, there is a certain security risk in the 27 service.
[0087] S208, if the 27 seed is completely random and satisfies any of the following conditions: the 27 authentication function does not allow blasting, and the 27 authentication function allows blasting and is a non-fixed key blasting, then determine that the 27 authentication function is valid.
[0088] In the embodiment of the present application, if the following two conditions are met at the same time: 1) the third test result is that the 27 seed is completely random, 2) the fourth test result is that the 27 authentication function does not allow blasting, and the fifth test result is that the 27 authentication function is blasted with a non-fixed key, then it is determined that the 27 authentication function is valid, and in this case the 27 service is relatively safe.
[0089] S209: If the 27 authentication function is not implemented or the 27 authentication function is invalid, it is determined that the 27 service is not safe.
[0090] In the embodiment of the present application, step S209 is the same as step S103 in the above embodiment and will not be described again here.
[0091] In summary, the detection method for the safety of the vehicle diagnosis 27 service of the embodiment of the present application determines the safety of the 27 service by detecting two aspects of the 27 service (whether the 27 authentication function is realized and whether it is effective). The detection method of two angles realizes the diversification of the detection method, thereby improving the accuracy of the detection result, making the 27 service more secure. By flashing the ECU before performing the 27 authentication, it can be quickly and accurately determined whether the 27 authentication function is realized according to the operation result. By detecting three aspects of the 27 service (whether the 27 seed is completely random, whether the 27 authentication function allows blasting, and whether the 27 authentication function is a fixed KEY blasting), it can be quickly and accurately determined whether the 27 authentication function is valid according to the three detection results, and the detection method of three angles improves the accuracy of the effective determination result, making the 27 service more secure. By judging whether the 27 seed has regularity and repeated seeds, it can be quickly and accurately determined whether the 27 seed is completely random. By judging whether the negative response code returned by sending any KEYECU includes a negative response code for indicating that it cannot be blasted, it can be quickly and accurately determined whether the 27 authentication function allows blasting. When the ECU allows cracking, by enumerating the KEY, it is possible to quickly and accurately determine whether the 27 authentication function is a fixed KEY cracking.
[0092] To clearly illustrate the detection method of the vehicle diagnosis 27 service safety of the embodiment of the present application, the following is combined with Figure 5 The overall process of the vehicle diagnosis 27 service safety detection method of the embodiment of the present application is described in detail. Figure 5 As shown, the detection method of the vehicle diagnosis 27 service safety of the embodiment of the present application specifically includes the following steps:
[0093] S501, before performing 27 authentication, the electronic control unit of the vehicle is flashed.
[0094] S502, determine whether the flashing is successful. If yes, execute step S503. If no, execute step S504.
[0095] S503: Determine that the 27 authentication function is not implemented. Execute step S523.
[0096] S504, determine that the 27 authentication function has been implemented. Execute step S505.
[0097] S505, periodically obtain a set number of 27 seeds.
[0098] S506, determine whether the 27 seeds have regularity. If yes, execute step S510. If no, execute step S507.
[0099] S507, determine whether there are duplicate seeds in the 27 seeds. If yes, execute step S508. If no, execute step S511.
[0100] S508, periodically reacquire a set number of 27 seeds.
[0101] S509, determine whether there are duplicate seeds in the set number of 27 seeds. If yes, execute step S510. If no, execute step S511.
[0102] S510, determine that the 27 seeds are not completely random. Execute step S521.
[0103] S511, determine that the 27 seeds are completely random. Execute step S512.
[0104] S512, sending an arbitrary key to the electronic control unit of the vehicle, and receiving a negative response code returned by the electronic control unit.
[0105] S513, determine whether the returned negative response code includes a negative response code indicating that the blasting cannot be performed. If yes, execute step S514. If no, execute step S515.
[0106] S514: Determine that the 27 authentication function does not allow blasting. Execute step S520.
[0107] S515, determine whether the 27 authentication function allows blasting. Execute step S516.
[0108] S516, performing a burst test by sequentially sending keys in the key set to an electronic control unit of the vehicle to obtain a burst test result.
[0109] S517, determine whether the brute force test result indicates that there is a key corresponding to the brute force in the key set. If so, execute step S518. If not, execute step S519.
[0110] S518, determine that the 27 authentication function is fixed key blasting. Execute step S521.
[0111] S519, determine that the 27 authentication function is a non-fixed key blasting. Execute step S520.
[0112] S520, determine that the 27 authentication function is valid. Execute step S522.
[0113] S521, determine that the 27 authentication function is invalid. Execute step S523.
[0114] S522, confirm that service 27 is secure.
[0115] S523, determining that service 27 is not secure.
[0116] Figure 6 A schematic diagram of a vehicle diagnostic service safety detection device provided by an embodiment of the present application. Figure 6 As shown, the detection device 600 for the vehicle diagnosis 27 service safety of the embodiment of the present application may specifically include: a first detection module 601 , a second detection module 602 and a determination module 603 .
[0117] in:
[0118] The first detection module 601 is used to detect whether the 27 authentication function of the 27 service is realized.
[0119] The second detection module 602 is used to detect whether the 27 authentication function is valid.
[0120] The determination module 603 is used to determine that the 27 service is not safe if the 27 authentication function is not implemented or the 27 authentication function is invalid.
[0121] In the embodiment of the present application, the specific process of each module and unit in the vehicle diagnosis 27 service safety detection device of the embodiment of the present application to realize its function can be referred to the relevant description in the above-mentioned vehicle diagnosis 27 service safety detection method embodiment, which will not be repeated here.
[0122] In summary, the detection device for the safety of the vehicle diagnosis 27 service of the embodiment of the present application detects whether the 27 authentication function of the 27 service is realized and whether the 27 authentication function is valid when detecting the safety of the 27 service. If the 27 authentication function is not realized or the 27 authentication function is invalid, it is determined that the 27 service is unsafe. The embodiment of the present application determines the safety of the 27 service by detecting two aspects of the 27 service (whether the 27 authentication function is realized and whether it is valid). The detection method from two angles realizes the diversification of the detection method, thereby improving the accuracy of the detection result and making the 27 service more secure.
[0123] Figure 7 This is a schematic diagram of a vehicle diagnostic service safety detection device provided by another embodiment of the present application. Figure 7 As shown, in Figure 6 On the basis of the illustrated embodiment, in the detection device 600 for the vehicle diagnosis 27 service safety of the embodiment of the present application, the first detection module 601 may specifically include: a flashing unit 701 and a determination unit 702, wherein:
[0124] The flashing unit 701 is used to flash the electronic control unit of the vehicle before performing 27 authentication.
[0125] The determination unit 702 is used to determine that the 27 authentication function has not been implemented if the flashing is successful; if the flashing is unsuccessful, determine that the 27 authentication function has been implemented.
[0126] In a feasible implementation manner of the embodiment of the present application, the second detection module 602 is further used to: detect whether the 27 seed is completely random; detect whether the 27 authentication function allows blasting; detect whether the 27 authentication function is a fixed key blasting; if the 27 seed is not completely random, or the 27 authentication function allows blasting and is a fixed key blasting, then determine that the 27 authentication function is invalid; if the 27 seed is completely random and meets any of the following conditions: the 27 authentication function does not allow blasting, and the 27 authentication function allows blasting and is a non-fixed key blasting, then determine that the 27 authentication function is valid.
[0127] In a feasible implementation manner of the embodiment of the present application, the second detection module 602 is further used to: obtain a set number of 27 seeds, the set number is equal to or greater than a preset number threshold; determine whether there is regularity in the set number of 27 seeds, and whether there are repeated seeds; if there is no regularity and no repeated seeds, determine that the 27 seeds are completely random; if there is regularity, determine that the 27 seeds are not completely random; if there are repeated seeds, re-acquire the set number of 27 seeds, and determine whether there are repeated seeds in the set number of 27 seeds; if so, determine that the 27 seeds are not completely random; if not, determine that the 27 seeds are completely random.
[0128] In a feasible implementation manner of the embodiment of the present application, the second detection module 602 is further configured to: periodically obtain 27 seeds.
[0129] In a feasible implementation manner of the embodiment of the present application, the second detection module 602 is further configured to: send any key to the electronic control unit of the vehicle; receive a negative response code returned by the electronic control unit; if the returned negative response code includes a negative response code indicating that blasting is not allowed, determine that the 27 authentication function does not allow blasting; if the returned negative response code does not include a negative response code indicating that blasting is not allowed, determine that the 27 authentication function allows blasting.
[0130] In a feasible implementation manner of the embodiment of the present application, the second detection module 602 is further configured to: when the 27 authentication function allows blasting, perform a blasting test by sequentially sending the keys in the key set to the electronic control unit of the vehicle to obtain a blasting test result; if the blasting test result is that there is a key corresponding to blasting in the key set, determine that the 27 authentication function is fixed-key blasting; if the blasting test result is that there is no key corresponding to blasting in the key set, determine that the 27 authentication function is non-fixed-key blasting.
[0131] In the embodiment of the present application, for the specific processes of each module and unit in the detection device for the security of the vehicle diagnosis 27 service in the embodiment of the present application to implement their functions, reference may be made to the relevant descriptions in the embodiment of the vehicle diagnosis 27 service security detection method described above, which will not be elaborated here.
[0132] In summary, the detection device for the safety of the vehicle diagnosis 27 service of the embodiment of the present application determines the safety of the 27 service by detecting two aspects of the 27 service (whether the 27 authentication function is realized and whether it is effective). The detection method of two angles realizes the diversification of the detection method, thereby improving the accuracy of the detection result, making the 27 service more secure. By flashing the ECU before performing the 27 authentication, it can be quickly and accurately determined whether the 27 authentication function is realized according to the operation result. By detecting three aspects of the 27 service (whether the 27 seed is completely random, whether the 27 authentication function allows blasting, and whether the 27 authentication function is a fixed KEY blasting), it can be quickly and accurately determined whether the 27 authentication function is valid according to the three detection results, and the detection method of three angles improves the accuracy of the effective determination result, making the 27 service more secure. By judging whether the 27 seed has regularity and repeated seeds, it can be quickly and accurately determined whether the 27 seed is completely random. By judging whether the negative response code returned by sending any KEYECU includes a negative response code for indicating that it cannot be blasted, it can be quickly and accurately determined whether the 27 authentication function allows blasting. When the ECU allows cracking, by enumerating the KEY, it is possible to quickly and accurately determine whether the 27 authentication function is a fixed KEY cracking.
[0133] The present application also provides an electronic device. Figure 8 As shown, the electronic device 800 may have relatively large differences due to different configurations or performances, and may include one or more processors 801 and memory 802, and the memory 802 may store one or more storage applications or data. Among them, the memory 802 may be a temporary storage or a permanent storage. The application stored in the memory 802 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instructions in the electronic device 800. Furthermore, the processor 801 may be configured to communicate with the memory 802 and execute a series of computer executable instructions in the memory 802 on the electronic device 800. The electronic device 800 may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input and output interfaces 805, and one or more keyboards 806.
[0134] Specifically in this embodiment, the electronic device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instructions for the electronic device, and the one or more programs are configured to be executed by one or more processors, including the following computer executable instructions:
[0135] Check whether the 27 authentication function of the 27 service is implemented;
[0136] Check whether the 27 authentication function is effective;
[0137] If the 27 authentication function is not implemented, or the 27 authentication function is invalid, it is determined that the 27 service is not secure.
[0138] The electronic device of the embodiment of the present application, when testing the security of the 27 service, tests whether the 27 authentication function of the 27 service is implemented and whether the 27 authentication function is valid. If the 27 authentication function is not implemented or the 27 authentication function is invalid, it is determined that the 27 service is unsafe. The embodiment of the present application determines the security of the 27 service by testing the 27 service in two aspects (whether the 27 authentication function is implemented and whether it is valid). The two-angle detection method realizes the diversification of the detection method, thereby improving the accuracy of the detection result and making the 27 service more secure.
[0139] The embodiment of the present application further proposes a readable storage medium, on which one or more computer programs are stored. The one or more computer programs include instructions. When the program or instruction is executed by a processor in an electronic device including multiple application programs, the processor in the electronic device can execute each process of the above-mentioned vehicle diagnostic 27 service safety detection method embodiment, and is specifically used to execute:
[0140] Check whether the 27 authentication function of the 27 service is implemented;
[0141] Check whether the 27 authentication function is effective;
[0142] If the 27 authentication function is not implemented, or the 27 authentication function is invalid, it is determined that the 27 service is not secure.
[0143] The readable storage medium of the embodiment of the present application detects whether the 27 authentication function of the 27 service is implemented and whether the 27 authentication function is valid when detecting the security of the 27 service. If the 27 authentication function is not implemented or the 27 authentication function is invalid, it is determined that the 27 service is unsafe. The embodiment of the present application determines the security of the 27 service by detecting two aspects of the 27 service (whether the 27 authentication function is implemented and whether it is valid). The detection method from two angles realizes the diversification of the detection method, thereby improving the accuracy of the detection result and making the 27 service more secure.
[0144] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0145] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0146] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0147] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0148] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0149] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0150] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0151] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0152] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0153] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0154] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0155] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0156] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A method for detecting the safety of a vehicle diagnostic service 27, It is characterized in that include: Check whether the 27 authentication function of the 27 service is implemented; Detecting whether the authentication function 27 is effective; If the 27 authentication function is not implemented, or the 27 authentication function is invalid, it is determined that the 27 service is not safe.
2. The method according to claim 1, It is characterized in that The detection of whether the 27 authentication function of the 27 service is realized includes: Before the 27 certification, the vehicle's electronic control unit is flashed; If the flashing is successful, it is determined that the 27 authentication function is not implemented; If the flashing is unsuccessful, it is determined that the 27 authentication function has been achieved.
3. The method according to claim 1, It is characterized in that The step of detecting whether the authentication function 27 is effective includes: Check whether the 27 seeds are completely random; Detecting whether the 27 authentication function allows blasting; Detect whether the 27 authentication function is a fixed key blasting; If the 27 seed is not completely random, or the 27 authentication function allows blasting and is a fixed key blasting, it is determined that the 27 authentication function is invalid; If the 27-bit seed is completely random and satisfies any of the following conditions: the 27-bit authentication function does not allow blasting, and the 27-bit authentication function allows blasting and is a non-fixed key blasting, then it is determined that the 27-bit authentication function is valid.
4. The method according to claim 3, It is characterized in that The detection of whether the 27 seeds are completely random includes: Obtaining a set number of the 27 seeds, where the set number is equal to or greater than a preset number threshold; Determine whether the set number of the 27 seeds has regularity, and whether there are repeated seeds; If there is no regularity and no repeated seeds, it is determined that the 27 seeds are completely random; If there is a regularity, it is determined that the 27 seeds are not completely random; If there are duplicate seeds, the set number of the 27 seeds are re-acquired to determine whether there are duplicate seeds among the set number of the 27 seeds; if so, it is determined that the 27 seeds are not completely random; if not, it is determined that the 27 seeds are completely random.
5. The method according to claim 4, It is characterized in that The step of obtaining a set number of the 27 seeds includes: The 27 seeds are obtained periodically.
6. The method according to claim 3, It is characterized in that The detecting whether the 27 authentication function allows blasting includes: Send any key to the vehicle's electronic control unit; receiving a negative response code returned by the electronic control unit; If the negative response code returned includes a negative response code indicating that the blasting is impossible, it is determined that the 27 authentication function does not allow blasting; If the negative response code returned does not include a negative response code for indicating that the blasting is impossible, it is determined that the 27 authentication function allows the blasting.
7. The method according to claim 3, It is characterized in that The detecting whether the 27 authentication function is a fixed key blasting comprises: When the authentication function 27 allows blasting, a blasting test is performed by sequentially sending keys in the key set to the electronic control unit of the vehicle to obtain a blasting test result; If the blasting test result is that the key corresponding to the blasting exists in the key set, it is determined that the 27 authentication function is a fixed key blasting; If the blasting test result is that the key corresponding to the blasting does not exist in the key set, it is determined that the 27 authentication function is a non-fixed key blasting.
8. A detection device for vehicle diagnostic 27 service safety, It is characterized in that include: The first detection module is used to detect whether the 27 authentication function of the 27 service is realized; A second detection module is used to detect whether the 27 authentication function is valid; The determination module is used to determine that the 27 service is not safe if the 27 authentication function is not implemented or the 27 authentication function is invalid.
9. An electronic device, It is characterized in that The method comprises a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the method according to any one of claims 1 to 7.
10. A readable storage medium, It is characterized in that The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.