Automobile ECU (Electronic Control Unit) network security test method
By simulating the exchange and certification of the whole vehicle and the ECU network by the upper computer, and using the CAN analyzer to simulate the transmission and reception of messages, the problem of difficult to effectively test the security of the automotive ECU network in the existing technology without the need for the whole vehicle is solved, and efficient and low-cost ECU network security testing is achieved.
Patent Information
- Application Number
- CN202510300874.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to effectively test the security of the automotive ECU network without the need for a complete vehicle, resulting in high testing costs and inconvenience.
Through the upper computer, the switching authentication between the entire vehicle and the ECU network is simulated, and the CAN analyzer is used to simulate packet transmission and reception, verify whether the security encryption of the ECU network is correct, thereby debugging the vehicle's ECU network security.
It realizes verification of the correctness of the encryption and decryption algorithm of the ECU network without the need for a complete vehicle, reduces the testing cost, simplifies the testing process, and improves the testing efficiency.
Smart Images

Figure CN120075112A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for testing the network security of an automotive ECU. Background Art
[0002] With the accelerating advancement of the networking of intelligent vehicles, more in-vehicle software is vulnerable to external attacks, such as the acquisition of telematics and data, and this data includes personal data, vehicle data, environmental data, and interaction-related data; for the protection of network security, it is necessary to prevent illegal control of the vehicle and protect relevant privacy data of individuals and vehicles.
[0003] In the existing market, new energy vehicles have begun to be highly favored, and the main focus of new energy is also the in-vehicle network. More advanced software control means a more comprehensive intelligent vehicle, which while providing convenience to users also increases the burden of network security. Therefore, more attention is paid to the network security of the entire vehicle.
[0004] Since the in-vehicle ECU controls the safety and reliability of the vehicle, its security is higher than that of other systems, and its encryption algorithm also needs to be key tested.
[0005] However, in order to reduce the production cost of automobiles, automobile production is carried out in a production line and in batches. Therefore, the control software used for products in the same batch is the same. However, testing the software system of the entire vehicle cannot rely on complete vehicles, which will undoubtedly increase the cost of the enterprise. Moreover, once debugging is required after testing, the software system originally entered into the vehicle body needs to be downloaded and uploaded again, which is not only inconvenient but also increases the testing cost. Summary of the Invention
[0006] The technical problem to be solved by the present invention is: to provide a method for testing the network security of an automotive ECU, which, without the need for an entire vehicle, uses a host computer to simulate the exchange authentication between the entire vehicle and the ECU network, thereby verifying whether the security encryption of the ECU network is correct, and then debugging the network security of the vehicle's ECU to determine the correctness of the encryption and decryption algorithms of the ECU network.
[0007] To solve the above technical problem, the technical solution of the present invention is: A method for testing the network security of an automotive ECU includes a host computer for simulating the network program of the entire vehicle and obtaining reference data by operating on the original key; it also includes a vehicle host for loading the ECU security network to be detected and for encrypting and decrypting data with the host computer; it further includes a CAN analyzer for serving as an intermediate carrier to receive the data sent after the calculation by the host computer and to return the data encrypted by the ECU security network in the vehicle host, connecting the host computer and the vehicle host; This test method includes: First, the host computer calculates the original key to generate five groups of reference data, uses the first three groups of data as input, and the last two groups of data as reference data; Then, the CAN analyzer simulates message sending and receiving, inputs the first three groups of data into the ECU network in the host computer, and allows the ECU network to perform encryption and decryption; the last two groups of data are obtained; Finally, the last two groups of data are sent back; the host computer compares the two groups of data sent back with the last two groups of data that have been calculated. If they are the same, it is concluded that the user key is successfully loaded; if they are different, the ECU network of the vehicle host needs to be rewritten or adjusted until the test is successful.
[0008] Furthermore, the test method is developed based on the C language platform on the host computer.
[0009] Furthermore, a hardware security module (i.e., Csec module) is set in the vehicle host for key loading, and the loaded hardware security module is used for the secure use of the ECU network.
[0010] Furthermore, the input key is calculated from the original key and is not directly input into the vehicle host.
[0011] Furthermore, after the key is successfully loaded, the encryption and decryption functions of the ECU network are verified according to the written key value.
[0012] Furthermore, after the encryption and decryption verification is completed, the ECU network is verified for CMAC by inputting the CMAC seed.
[0013] Furthermore, the ECUI network supports two encryption and decryption methods: CBC and ECB.
[0014] Furthermore, the operation steps of this method are as follows: The first step is to connect the host computer and the CAN analyzer, power on the vehicle host, start the ECU network, and initialize the host computer; The second step is to select and input the original key in the host computer, calculate five groups of data, divided into the first three groups and the last two groups; The third step is to send the first three groups of data to the ECU network on the vehicle host and read the two groups of data calculated by the ECU; The fourth step is to compare the last two groups of data calculated by the host computer with the two groups of data obtained from the ECU. If they are the same, it indicates that the ECU is successfully loaded; if they are different, further debugging and modification are required; Step 5: Perform encryption and decryption verification on the ECU; first, enter the plaintext on the host computer, calculate the encrypted plaintext, and then input the plaintext into the ECU; Step 6: Select the encryption method of the ECU. After encryption by the ECU, ciphertext is formed. The host computer reads the ciphertext of the ECU and compares the two sets of ciphertext; Step 7: The host computer inputs the encrypted ciphertext into the ECU; Step 8: Select the decryption method of the ECU. After decrypting the ciphertext by the ECU, plaintext is formed. The host computer reads the plaintext of the ECU and compares the two sets of plaintext to complete the verification; Step 9: Perform CMAC verification on the ECU. Input the generated CMAC seed into the host computer to generate CMAC; Step 10: Input the CMAC seed into the ECU to let the ECU generate CMAC; Step 11: The host computer reads the CMAC produced by the ECU and compares it with the CMAC calculated by itself to complete the verification.
[0015] Furthermore, before performing the security test, a request for secure access needs to be sent to the ECU. At this time, the host computer sends an unlock request to the CAN analyzer, calculates the secret key in the host computer according to the seed replied by the CAN analyzer, and then feeds it back to the vehicle host. If the secret keys are consistent and the unlocking is successful, the test can be carried out.
[0016] Compared with the prior art, a method for testing the network security of an automotive ECU provided by the present invention simulates the key information given by a vehicle through a host computer, and then simulates sending a message to the ECU on the vehicle host through a CAN analyzer. By comparing data, it is judged whether the key loading in the ECU is correct, whether the encryption and decryption functions are successful, and whether the CMAC verification is perfect. In this way, the whole machine test is not required, and only the host computer and the CAN analyzer are needed to complete it, greatly reducing the cost. Moreover, the present invention is based on the C language platform, has high portability, is easy for secondary development, has a simple interface and convenient operation, and high test efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Attached Figure 1 Shows a schematic diagram of the test method of the present invention.
[0018] Attached Figure 2 Shows a schematic diagram of the hardware of the present invention.
[0019] Attached Figure 3 Shows a flowchart of the operation of the present invention.
[0020] Attached Figure 4 Shows a key verification interface of the present invention.
[0021] Appendix Figure 5 Shows the encryption, decryption, and verification interface of the present invention.
[0022] Appendix Figure 6 Shows the CMAC verification interface of the present invention. Detailed implementation manners
[0023] In one embodiment, taking AES128 as an example, AES128 is an encryption algorithm that divides the plaintext into data blocks of a fixed length. Each data block has a length of 128 bits and each data block is encrypted independently, so its security is higher.
[0024] In one embodiment, as Figure 2 shown, a method for testing the network security of an automotive ECU includes a host computer for simulating the network program of the entire vehicle, calculating reference data by operating on the original key; and also includes a vehicle host for loading the ECU security network to be detected, for encrypting and decrypting data with the host computer; and also includes a CAN analyzer for serving as an intermediate carrier, receiving the data sent out after the calculation by the host computer, and transmitting back the data encrypted by the ECU security network in the vehicle host, connecting the host computer and the vehicle host. As Figure 1 shown, this test method includes: First, the host computer first calculates on the original key to generate five groups of reference data, uses the first three groups of data as inputs, and the last two groups of data as reference data. Then, simulate message sending and receiving through the CAN analyzer, input the first three groups of data into the ECU network in the host, and let the ECU network perform encryption and decryption to obtain the last two groups of data. Finally, transmit back the last two groups of data; the host computer compares the two groups of data transmitted back with the last two groups of data that have been calculated. If they are the same, it is concluded that the user key is successfully loaded; if they are different, the ECU network of the vehicle host needs to be rewritten or adjusted until the test is successful.
[0025] In one embodiment, the test method is developed based on the C language platform on the host computer; a hardware security module (i.e., the Csec module) is provided in the vehicle host for key loading, and the loaded hardware security module is used for the secure use of the ECU network.
[0026] When loading the user key into the CSEc module, the key plaintext is not directly loaded into the CSEc module. To ensure the confidentiality, integrity, authenticity of the key, and prevent replay attacks, a series of calculations are performed on the original key to generate a total of 5 groups of data, namely M1, M2, M3, M4, and M5, where M1 to M3 are used as inputs. Load it into the CSEc module. After the loading is completed, the CSEc module will return M4 and M5. Compare the returned M4 and M5 with the previously calculated ones. If the returned data is the same as the previously calculated data, it means that the key has been correctly loaded into the CSEc module.
[0027] Since the process of calculating the values of M1 to M5 from the original key is irreversible, the whole process is secure.
[0028] In one embodiment, the input key is calculated from the original key and is not directly input into the vehicle host. After successfully loading the key, verify the encryption and decryption functions of the ECU network according to the written key value. After completing the encryption and decryption verification, verify the CMAC of the ECU network by inputting the CMAC seed. The ECUI network supports two encryption and decryption methods, CBC and ECB.
[0029] In one embodiment, as Figure 3 shown, the operation steps of this method are as follows: First step, connect the host computer and the CAN analyzer, power on the vehicle host, start the ECU network, and initialize the host computer. Second step, select and input the original key in the host computer, calculate five groups of data, divided into the first three groups and the last two groups; namely, a total of five groups of data, M1, M2, M3, M4, and M5, where M1 to M3 are used as inputs. Third step, send the first three groups of data M1 to M3 to the ECU network on the vehicle host and read the two groups of data calculated by the ECU. Fourth step, compare the last two groups of data calculated by the host computer with the two groups of data obtained from reading the ECU. If they are the same, it indicates that the ECU has been successfully loaded, that is, the key has been correctly loaded into the hardware security module. If they are not the same, further debugging and modification are required. Fifth step, verify the encryption and decryption of the ECU; first input the plaintext on the host computer, calculate and encrypt the plaintext, and then input the plaintext into the ECU. Sixth step, select the encryption method of the ECU, form the ciphertext after encryption by the ECU, read the ciphertext of the ECU by the host computer, and compare the two groups of ciphertext. Seventh step, input the encrypted ciphertext into the ECU by the host computer. Eighth step, select the decryption method of the ECU, decrypt the ciphertext by the ECU to form the plaintext, read the plaintext of the ECU by the host computer, and compare the two groups of plaintext to complete the verification. Step 9: Conduct CMAC verification on the ECU. Input the generated CMAC seed into the host computer to generate CMAC. Step 10: Input the CMAC seed into the ECU to let the ECU generate CMAC. Step 11: The host computer reads the CMAC produced by the ECU and compares it with the CMAC calculated by itself to complete the verification.
[0030] In one embodiment, before conducting a security test, a request for secure access needs to be sent to the ECU. At this time, the host computer sends an unlock request to the CAN analyzer, calculates the secret key in the host computer according to the seed replied by the CAN analyzer, and then feeds it back to the vehicle host. If the secret keys are consistent and the unlocking is successful, the test can be carried out.
[0031] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than restrictive technical solutions. Those of ordinary skill in the art should understand that any modifications or equivalent replacements made to the technical solutions of the present invention without departing from the purpose and scope of the present technical solution should be covered by the scope of the claims of the present invention.
Claims
1. A method for testing the network security of an automobile ECU, characterized in that: It includes a host computer, which is used to simulate the network program of the whole vehicle, and obtain reference data by calculating the original key; it also includes a vehicle host, which is used to load the ECU security network that needs to be detected, and is used to encrypt and decrypt the data of the host computer; it also includes a CAN analyzer, which is used as an intermediate carrier to receive the data sent by the host computer after calculation, and return the data encrypted by the security network of the ECU in the vehicle host, and connect the host computer and the vehicle host; This test method includes: First, the host computer generates five sets of reference data by calculating the original key, taking the first three sets of data as input and the last two sets of data as reference data; Then, the CAN analyzer is used to simulate the message transmission and reception, and the first three groups of data are input into the ECU network in the host, so that the ECU network performs encryption and decryption, and the last two groups of data are obtained; Finally, the last two sets of data are transmitted back; the host computer compares the two sets of data transmitted back with the calculated last two sets of data, and if the two are the same, it is concluded that the user key has been loaded successfully; if the two are different, the ECU network of the vehicle host needs to be rewritten or adjusted until the test is successful.
2. The automotive ECU network security testing method according to claim 1 is characterized in that: The test method is based on the C language platform development on the host computer.
3. The automotive ECU network security testing method according to claim 1 is characterized in that: The vehicle host is provided with a hardware security module (ie, Csec module) for key loading. The loaded hardware security module is used for the safe use of the ECU network.
4. The automotive ECU network security testing method according to claim 1 is characterized in that: The key entered is calculated from the original secret key and is not directly entered into the vehicle host.
5. The automotive ECU network security testing method according to claim 1 is characterized in that: After the key is successfully loaded, the encryption and decryption functions of the ECU network are verified according to the written key value.
6. The automotive ECU network security testing method according to claim 5 is characterized in that: After completing the encryption and decryption verification, the CMAC of the ECU network is verified by inputting the CMAC seed.
7. The automotive ECU network security testing method according to claim 5 is characterized in that: The ECUI network supports two encryption and decryption methods: CBC and ECB.
8. A method for testing automobile ECU network security according to any one of claims 1 to 7, characterized in that: The steps of this method are as follows: The first step is to connect the host computer and the CAN analyzer, power on the vehicle host, start the ECU network, and initialize the host computer; The second step is to select and input the original secret key in the host computer, and calculate five groups of data, which are divided into the first three groups and the last two groups; The third step is to send the first three sets of data to the ECU network on the vehicle host, and read the two sets of data calculated by the ECU; The fourth step is to compare the last two sets of data calculated by the host computer with the two sets of data obtained by reading the ECU to see if they are consistent. If they are consistent, it means that the ECU is loaded successfully. If they are inconsistent, further debugging and modification are required. The fifth step is to perform encryption and decryption verification on the ECU; first input the plain text on the host computer, encrypt the plain text through calculation, and then input the plain text into the ECU; Step 6: Select the encryption method of the ECU. After the ECU encrypts the ciphertext, the host computer reads the ciphertext of the ECU and compares the two sets of ciphertexts. Step 7: The host computer inputs the encrypted ciphertext into the ECU; Step 8: Select the decryption method of ECU. After ECU decrypts the ciphertext to form plaintext, the host computer reads the plaintext of ECU, compares the two sets of plaintext, and completes the verification. The ninth step is to perform CMAC verification on the ECU, input the generated CMAC seed into the host computer, and then generate CMAC; Step 10: Input the CMAC seed into the ECU and let the ECU generate the CMAC; In the eleventh step, the host computer reads the CMAC produced by the ECU, compares it with the CMAC calculated by itself, and completes the verification.
9. The automotive ECU network security testing method according to claim 8 is characterized in that: Before conducting a security test, it is necessary to request security access to the ECU. At this time, the host computer sends an unlock request to the CAN analyzer, and calculates the secret key in the host computer based on the seed replied by the CAN analyzer, and then feeds it back to the vehicle host. Only when the secret keys are consistent and unlocked successfully can the test be carried out.