Automobile private remote communication protocol security test method and device and storage medium
By analyzing and judging the communication message data information in the automotive remote communication protocol and generating a test report, the problem of cumbersome testing process and inefficient efficiency in the existing technology is solved, and efficient security evaluation of the automotive private remote communication protocol is achieved.
Patent Information
- Application Number
- CN202510359581.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-10
AI Technical Summary
The test method of automobile remote communication protocol in the prior art is cumbersome and inefficient, making it difficult to effectively evaluate the security and stability of automobile private remote communication protocol.
By obtaining the communication message data information generated in the target communication scenario, analyzing and determining whether the execution action of the communication message data information meets the preset conditions, and generating a test report, including the communication message data information, log data information, the execution result information of the test script and the performance data information of the vehicle to be detected.
The automated test script is implemented to comprehensively evaluate the security and stability of the car's private remote communication protocol in key update, encryption and transmission, improve testing efficiency, reduce labor costs, and ensure the security of intelligent connected car remote communication.
Smart Images

Figure CN120128513A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of automotive safety testing. Specifically, the present invention relates to a method, device, and storage medium for testing the security of an automotive private remote communication protocol. Background Art
[0002] The in-vehicle communication network can be divided into an in-vehicle wired connection network and an out-of-vehicle wireless connection network. With the development of intelligent connected vehicles, the demand for out-of-vehicle communication is increasing, which also promotes the development of out-of-vehicle networks. In vehicle wireless communication technology, remote wireless communication generally refers to a mobile communication network, represented by 4G and 5G, which mainly provides functions such as communication and navigation, serving intelligent driving and intelligent cockpit functions. As the in-vehicle networking and intelligent functions of vehicles are increasing, there are also many custom private remote communication protocols in automotive IVI remote communication. Therefore, it is necessary to test the security of these private remote communication protocols to ensure the stability and security of automotive remote communication protocols to the greatest extent.
[0003] Currently, there are some traditional testing methods and systems on the market. However, these methods and systems have the problems of cumbersome testing processes and long time consumption.
[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a method, device, and storage medium for testing the security of an automotive private remote communication protocol, so as to at least solve the technical problems of cumbersome testing processes and low efficiency in the prior art for testing remote communication protocols.
[0006] According to one aspect of the embodiments of the present invention, to achieve the above object, according to one aspect of the present invention, there is provided a method for testing the security of an automotive private remote communication protocol, including: obtaining communication message data information generated in a target communication scenario; parsing the communication message data information to obtain a parsing result; based on the parsing result, determining whether the execution actions of the communication message data information of the vehicle to be detected in the target communication scenario meet preset conditions, to obtain a determination result, where the execution actions at least include an update action, an encryption action, and a transmission action of the communication message data information; and generating a test report based on the determination result, where the test report includes at least one of communication message data information, log data information, execution result information of a test script, and performance data information of the vehicle to be detected.
[0007] Optionally, parse the communication message data information to obtain a parsing result, including: parse the key derivation strategy in the communication message data information to obtain the key encryption result in the parsing result; parse the update strategy in the communication message data information to obtain the update result in the parsing result; parse the transmission strategy in the communication message data information to obtain the transmission result in the parsing result.
[0008] Optionally, based on the parsing result, determine whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions, and obtain a judgment result, including: in the case where the parsing result is determined to be the key encryption result, based on the preset encryption algorithm, determine whether the key encryption result meets the preset security strength, and obtain a judgment result, where the preset encryption algorithm is at least one of the AES algorithm, the RSA algorithm, and the ECDH algorithm.
[0009] Optionally, based on the parsing result, determine whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions, and obtain a judgment result, including: in the case where the parsing result is determined to be the update result, based on the preset update standard, determine whether the update result meets the preset update standard, and obtain a judgment result, where the update standard is the key update frequency, the key update time, and the key update trigger condition.
[0010] Optionally, based on the parsing result, determine whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions, and obtain a judgment result, including: in the case where the parsing result is determined to be the transmission result, based on the preset transmission channel, determine whether the transmission result meets the preset security check, and obtain a judgment result, where the preset transmission channel is at least one of the HTTPS channel and the TLS channel.
[0011] Optionally, in the process of determining whether the update result meets the preset update standard based on the preset update standard in the case where the parsing result is determined to be the update result and obtaining a judgment result, it includes: using a log analysis tool to obtain the log data information of the vehicle to be detected; based on the log data information, confirm whether the key update event is recorded; in the case where the key update event is determined to be recorded, parse the key update event to obtain the log update information of the key update event; based on the log update information, determine whether the key update frequency, the key update time, and the key update trigger condition meet the log preset update standard.
[0012] Optionally, when it is determined that the parsing result is an update result, in the process of determining whether the update result meets the preset update criteria based on the preset update criteria and obtaining the judgment result, it includes: when it is determined that the update result meets the preset update criteria, accessing simulated abnormal scenario information to obtain a simulation result, where the simulated abnormal scenario information is used to simulate at least one of a network interruption scenario, an authentication failure scenario, and a transmission error scenario; based on the simulation result, determining whether the test system of the vehicle to be detected supports a preset processing mechanism, where the preset processing mechanism includes a key rollback protection mechanism, an exception handling mechanism, and a retransmission mechanism.
[0013] Optionally, the method further includes: when it is determined that the transmission structure meets the preset security verification, simulating an insecure transmission environment based on the target communication scenario to verify whether the test system of the vehicle to be detected rejects the insecure transmission request, where the preset security verification includes two-way identity verification and data integrity verification.
[0014] According to another aspect of the embodiments of the present invention, there is also provided a security testing device for an automotive private remote communication protocol, including: a packet capture tool for obtaining communication packet data information generated in a target communication scenario; a test module for parsing the communication packet data to obtain a parsing result; a judgment module for determining, based on the parsing result, whether the execution actions of the communication packet data information of the vehicle to be detected in the target communication scenario meet the preset conditions to obtain a judgment result, where the execution actions at least include an update action, an encryption action, and a transmission action of the communication packet data information; a generation module for generating a test report based on the judgment result, where the test report includes at least one of communication packet data information, log data information, execution result information of a test script, and performance data information of the vehicle to be detected.
[0015] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium, which includes an executable program stored therein. When the executable program runs, it controls the device where the computer-readable storage medium is located to execute the above-mentioned security testing method for an automotive private remote communication protocol.
[0016] In the embodiments of the present invention, by adopting the method of an automated test script, by obtaining and parsing the communication packet data information generated in the target communication scenario, the purpose of comprehensively evaluating the security and stability of the automotive private remote communication protocol in the process of key update, encryption, and transmission is achieved, thereby realizing the technical effects of improving the test efficiency, reducing the labor cost, and ensuring the security of the remote communication of intelligent connected vehicles, and further solving the technical problems of the cumbersome process and low efficiency of the remote communication protocol testing method in the prior art. Description of the Drawings
[0017] The accompanying drawings described herein are used to provide a further understanding of the present invention and form a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0018] Figure 1 A hardware structure block diagram of a vehicle terminal according to one embodiment of the present invention is shown;
[0019] Figure 2 A flowchart of a method for testing the security of an automotive private remote communication protocol according to one alternative embodiment of the present invention is shown;
[0020] Figure 3 A structure block diagram of a device for testing the security of an automotive private remote communication protocol according to one alternative embodiment of the present invention is shown;
[0021] Figure 4 A flowchart of a method for testing the security of an automotive private remote communication protocol according to one alternative embodiment of the present invention is shown;
[0022] Figure 5 A structure block diagram of an embodiment of a device for testing the security of an automotive private remote communication protocol according to one alternative embodiment of the present invention is shown;
[0023] Figure 6 A flowchart of a method for testing the security of an automotive private remote communication protocol according to one alternative embodiment of the present invention is shown. Detailed implementation manners
[0024] In order to enable those skilled in the art of this technology to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.
[0025] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0026] According to an embodiment of the present invention, a method embodiment of a security test method for an automotive private remote communication protocol is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0027] This method embodiment can be executed in an electronic device or a similar computing device including a memory and a processor. As Figure 1As shown, taking the operation on the vehicle terminal as an example, the vehicle terminal may include one or more processors 102 (the processor may include, but is not limited to, a processing device such as a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Digital Signal Processing (DSP) chip, a Micro Controller Unit (MCU), a Field Programmable Gate Array (FPGA), a Neural-network Processor Unit (NPU), a Tensor Processing Unit (TPU), an Artificial Intelligence (AI) type processor, etc.) and a memory 104 for storing data. Optionally, the above vehicle terminal may further include a transmission device 106 for communication functions, an input / output device 108, and a display 110. Those of ordinary skill in the art can understand that the above structural description is only illustrative and does not limit the structure of the above vehicle terminal. For example, the terminal may further include more or fewer components than the above structural description, or have a configuration different from the above structural description.
[0028] The memory 104 can be used to store computer programs, for example, software programs and modules of application software. The processor executes various functional applications and data processing by running the computer programs stored in the memory 104. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely located relative to the processor, and these remote memories can be connected to the mobile terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0029] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of a mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 may be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0030] The display 110 can be, for example, a touch-screen liquid crystal display (Liquid Crystal Display, LCD) and a touch display (also referred to as a "touch screen" or "touch display screen"). The liquid crystal display enables a user to interact with the user interface of the mobile terminal. In some embodiments, the above mobile terminal has a graphical user interface (Graphical User Interface, GUI), and the user can perform human-computer interaction with the GUI through finger contacts and / or gestures on the touch-sensitive surface. The human-computer interaction function may optionally include the following interactions: creating web pages, drawing, word processing, creating electronic documents, games, video conferencing, instant messaging, sending and receiving emails, call interfaces, playing digital videos, playing digital music, and / or web browsing, etc. Executable instructions for performing the above human-computer interaction functions are configured / stored in a computer program product or readable storage medium executable by one or more processors.
[0031] In this embodiment, a security test method for an automotive private remote communication protocol running on the above vehicle terminal is provided. Figure 2 It is a flowchart of a security test method for an automotive private remote communication protocol according to an embodiment of the present invention, as Figure 2 shown. The process includes the following steps:
[0032] Step S102, obtaining communication message data information generated in a target communication scenario;
[0033] Step S104, parsing the communication message data information to obtain a parsing result;
[0034] Step S106, based on the parsing result, determining whether the execution actions of the communication message data information of the vehicle to be detected in the target communication scenario meet preset conditions, and obtaining a determination result, where the execution actions at least include an update action, an encryption action, and a transmission action of the communication message data information;
[0035] Step S108, generate a test report based on the judgment result, where the test report includes at least one of communication message data information, log data information, execution result information of the test script, and performance data information of the vehicle to be detected.
[0036] Through the above steps, in the embodiment of the present invention, by adopting the method of an automated test script, and by obtaining and parsing the communication message data information generated in the target communication scenario, the purpose of comprehensively evaluating the security and stability of the automotive private remote communication protocol in the process of key update, encryption, and transmission is achieved, thereby realizing the technical effects of improving the test efficiency, reducing the labor cost, and ensuring the security of the remote communication of intelligent connected vehicles, and further solving the technical problem of the cumbersome process and low efficiency of the remote communication protocol test method in the prior art.
[0037] Optionally, parse the communication message data information to obtain a parsing result, including: parse the key derivation strategy in the communication message data information to obtain the key encryption result in the parsing result; parse the update strategy in the communication message data information to obtain the update result in the parsing result; parse the transmission strategy in the communication message data information to obtain the transmission result in the parsing result. By parsing the key security strategies in the communication message data information, the security of the automotive remote communication protocol is ensured, the security problems of data transmission and key management in automotive remote communication are solved, and the security and stability of the automotive remote communication system are improved.
[0038] Optionally, based on the parsing result, judge whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions to obtain a judgment result, including: in the case where the parsing result is determined to be the key encryption result, based on the preset encryption algorithm, judge whether the key encryption result meets the preset security strength, and obtain the judgment result, where the preset encryption algorithm is at least one of the AES algorithm, RSA algorithm, and ECDH algorithm. By accurately identifying the encryption algorithm used in the communication message data information and checking whether it is one of the preset algorithms (AES, RSA, ECDH), the security risks caused by improper algorithm selection are avoided.
[0039] In this embodiment, by using an automated test script to deeply analyze the key encryption result in the communication message data information and compare it with the preset encryption algorithm, it is possible to accurately judge whether the key encryption reaches the expected security strength. The test script automatically executes the above judgment and summarizes the results in the test report. The report includes the usage of the encryption algorithm, key strength analysis, and abnormal or non-compliant situations during the encryption process, which is convenient for quickly identifying security hazards and taking measures.
[0040] As an alternative implementation, when verifying whether the key generation and update of the in-vehicle infotainment (IVI) system are strictly based on the AES algorithm and whether the key encryption structure meets the preset security strength when using a private remote communication protocol, use a network data capture tool to capture the communication message data information between the IVI system and the remote server. Pay particular attention to the messages related to key derivation. Parse the captured communication message data information through an automated test script to check whether the AES algorithm is used during the key derivation process. The test script further confirms whether the length of the AES key meets the AES-128, AES-192, or AES-256 standard to ensure that the encryption strength complies with the security standard. The 128 in "AES-128" refers to the length of the key. The longer the key length, the more possible key combinations there are, and the more difficult and time-consuming it is to crack, so the higher the encryption security. In the security test of the in-vehicle private remote communication protocol, checking whether the IVI system supports the key lengths of AES-128, AES-192, or AES-256 is to verify whether its key management mechanism can provide sufficient security protection to prevent unauthorized access and data leakage.
[0041] In a specific embodiment, based on the RSA algorithm, determine whether the key encryption result meets the preset security strength and obtain the judgment result. The specific implementation is similar to the AES algorithm embodiment. Initialize the test environment, connect the IVI system, and prepare to execute the automated test script. Capture the communication message data information, especially pay attention to the key pair information during the key derivation process. The script checks whether the key pair in the captured message is generated and verified using the RSA algorithm, and at the same time confirms whether the length of the RSA key reaches 2048 bits or higher.
[0042] In another specific embodiment, based on the ECDH algorithm, determine whether the key encryption result meets the preset security strength and obtain the judgment result. Parse the communication message through an automated test script to check whether the ECDH protocol is used for key negotiation. The ECDH protocol usually includes elliptic curve parameters and public key information in the data packet to negotiate a shared key between the two communicating parties. Check whether there is an exchange of elliptic curve parameters in the data packet and whether key negotiation is performed based on these parameters, and at the same time verify whether the elliptic curve used meets the NIST P-256 or P-384 standard to ensure the security of the key negotiation process.
[0043] Optionally, based on the parsing result, it is determined whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions, and a judgment result is obtained, including: in the case where the parsing result is determined to be an update result, based on the preset update criteria, it is judged whether the update result meets the preset update criteria, and a judgment result is obtained, where the update criteria are the key update frequency, the key update time, and the key update trigger condition. This solution particularly emphasizes the detailed evaluation of the update action. By setting specific key update frequencies, update times, and update trigger conditions as the preset update criteria, it realizes the accurate detection of the secure update mechanism of the communication protocol, ensures the regular replacement of keys, and prevents the security risks caused by long-term unchanged keys. For example, the key update frequency can be set to update once per hour, the key update time can be set when the vehicle starts or establishes a connection with the remote server, and the key update trigger condition can be set when the vehicle detects a network attack or data anomaly. This technical solution solves the problem of poor key management in vehicle remote communication and improves the security and stability of the vehicle remote communication system.
[0044] In a specific embodiment, through an automated test script, the key update result can be accurately and continuously monitored to ensure that the update result meets the preset update criteria, prevent security vulnerabilities caused by improper key updates. The automated test script does not require manual intervention during execution, can quickly cover a large number of test scenarios, reduces the test time, and at the same time ensures the diversity and comprehensiveness of the test scenarios, and more comprehensively evaluates the effectiveness of the security mechanism.
[0045] Optionally, based on the parsing result, it is determined whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions, and a judgment result is obtained, including in the case where the parsing result is determined to be a transmission result, based on the preset transmission channel, it is judged whether the transmission result meets the preset security verification, and a judgment result is obtained, where the preset transmission channel is at least one of the HTTPS channel and the TLS channel. Ensure that the communication message data is transmitted through encrypted channels such as HTTPS or TLS, avoid using insecure transmission protocols such as HTTP, and increase the confidentiality of data transmission.
[0046] In a specific embodiment, the automated test script parses the captured communication message data information to verify whether the key transmission is through the HTTPS channel. The script checks whether the message contains the characteristics of the HTTPS protocol, such as using TCP port 443, and whether there is an SSL / TLS handshake process to confirm the encryption of the transmission process.
[0047] Optionally, when it is determined that the parsing result is an update result, in the process of judging whether the update result meets the preset update criteria based on the preset update criteria and obtaining the judgment result, it includes: using a log analysis tool to obtain the log data information of the vehicle to be detected; based on the log data information, confirming whether the key update event is recorded; when it is determined that the key update event is recorded, parsing the key update event to obtain the log update information of the key update event; based on the log update information, judging whether the key update frequency, key update time, and key update trigger condition meet the log preset update criteria. By checking the key update records in the log, the correct execution of the key update policy is ensured, and the security risks caused by bypassing or not executing the key update policy are prevented.
[0048] In a specific embodiment, in the target communication scenario, the communication packet data information between the IVI and the server is captured by a network data capture tool. At the same time, a log analysis tool is used to obtain the log data information of the IVI system, with particular attention paid to the event records related to key updates. The automated test script first checks whether the key update event is recorded in the log data information to ensure that each update is accurately recorded by the system. If the record exists, the next step is entered; if the record is missing, it is determined that there is a defect in the update mechanism. For the recorded key update event, the script further parses the log update information to extract key information such as the update frequency, update time, and trigger condition, providing a specific basis for the judgment of the security criteria. According to the log update information, the test script strictly compares the preset update criteria, such as whether the key update frequency meets the preset time interval, whether the update time is within the safe period, and whether the trigger condition is reasonable, to ensure the security and compliance of the key update process. All judgment results and parsing information are summarized in the test report, which details the execution of the key update, the integrity of the log records, the comparison of the update details with the preset criteria, and the judgment result of whether the security criteria are met.
[0049] Optionally, when it is determined that the parsing result is an update result, in the process of determining whether the update result meets the preset update criteria based on the preset update criteria and obtaining the judgment result, it includes: when it is determined that the update result meets the preset update criteria, accessing simulated abnormal scenario information to obtain a simulation result, where the simulated abnormal scenario information is used to simulate at least one of a network interruption scenario, an authentication failure scenario, and a transmission error scenario; based on the simulation result, determining whether the test system of the vehicle to be detected supports a preset processing mechanism, where the preset processing mechanism includes a key rollback protection mechanism, an exception handling mechanism, and a retransmission mechanism. By means of the simulated abnormal scenario information, the present invention further comprehensively tests the security and stability of the in-vehicle private remote communication protocol. This simulation test technology not only verifies the secure update ability of the protocol under normal communication, but also ensures that in the face of abnormal situations such as network interruption, authentication failure, and transmission error, the reaction and processing mechanism of the system can effectively guarantee communication security.
[0050] In a specific embodiment, it is assumed that a private remote communication protocol of an IVI system is being tested. This protocol supports the AES-256 encryption algorithm and can securely update keys under normal conditions. The following are the implementation steps based on a simulated network interruption scenario: Connect the IVI system to an automated test device, start the network data capture tool and the log analysis tool, and set up the power control system to maintain a stable system operating environment. Normal communication test: First, in a normal communication environment, test whether the system can accurately update keys according to the preset update standard (for example, update keys once every 24 hours). After confirming that there are no abnormalities in the normal update process, proceed to the next step. Through an automated test script, simulate a network interruption scenario, such as disconnecting the connection between the IVI system and the server, or setting up a firewall to reject some network requests, to observe the system's response in the case of communication interruption. After simulating the network interruption, use the script to check whether the system has a key rollback protection mechanism. For example, verify whether the system can roll back to the previous secure key state after the interruption is restored, preventing the use of keys that may have been tampered with during the interruption. Similarly, the script further checks whether the exception handling mechanism of the IVI system is effective in the simulated network interruption scenario. For example, verify whether the system can identify the network interruption and take appropriate measures, such as recording error logs, sending warning notifications, and attempting to re-establish the connection. Finally, test the retransmission mechanism of the system after the simulated network interruption. For example, check whether the system can automatically identify the packets with communication failures and retransmit them to ensure the integrity and continuity of data transmission. The results of all simulated tests are summarized in a test report, which details the execution of the security update mechanism, key rollback protection mechanism, exception handling mechanism, and retransmission mechanism of the IVI system in the simulated network interruption scenario, as well as whether they meet the requirements of the preset handling mechanisms. The present invention can ensure that the in-vehicle private remote communication protocol can not only securely update keys under normal conditions, but also enable the system to adopt appropriate handling mechanisms in the face of various abnormal scenarios, ensuring communication security and system stability.
[0051] Optionally, the method further includes: when it is determined that the transmission structure meets the preset security verification, simulating an insecure transmission environment based on the target communication scenario, and verifying whether the test system of the vehicle to be detected rejects insecure transmission requests, where the preset security verification includes two-way identity verification and data integrity verification. By implementing additional security verification steps, the security of the in-vehicle private remote communication protocol during data transmission is ensured. Specifically, the preset security verification includes two-way identity verification and data integrity verification, which ensure the authentication of both communication parties and the integrity of data during transmission, preventing man-in-the-middle attacks and data tampering. By simulating an insecure transmission environment, the present invention further verifies whether the IVI system can effectively reject insecure transmission requests in the face of potential security threats, thus ensuring the security and reliability of the entire communication system.
[0052] Specifically, for two-way identity verification: ensure that both communication parties identify each other through a secure authentication mechanism (such as certificate verification), and only devices that pass the verification can perform data transmission, preventing unauthorized devices from accessing. For data integrity verification: through algorithms such as HMAC (Hash Message Authentication Code) or CRC (Cyclic Redundancy Check), verify the integrity and untampered state of data during transmission, enhancing the security of data transmission.
[0053] In another specific embodiment: Suppose we test an IVI system that uses a private remote communication protocol, and the preset security verification includes HTTPS two-way certificate verification and HMAC data integrity verification. The following is an implementation step: Connect the IVI system to be tested to an automated test device, and ensure that the power control system and the network data capture tool are working properly. Start the automated test script to simulate a normal remote communication scenario. In the normal communication scenario, the script checks whether the communication process passes the two-way identity verification to ensure the authentication of both communication parties; at the same time, the integrity of the data packet is verified through the HMAC algorithm to ensure that the transmitted data has not been tampered with. The script further simulates an insecure transmission environment. For example, deliberately use an unauthenticated certificate for data transmission, or tamper with the HMAC value of the data packet to simulate the situation where the data is modified. After simulating the insecure environment, the script checks whether the test system can identify and reject these transmission requests. For example, when an incorrect certificate is used, the system should reject the connection; when the HMAC value of the data packet is tampered with, the system should identify the integrity problem of the data packet and reject the reception. All test results are recorded, including the security verification results in the normal communication scenario and the system's reaction in the simulated insecure environment. The automated test script summarizes this information into a test report, which details the process and results of the communication security verification and the system's handling ability in the face of insecure transmission requests.
[0054] It should be further noted that before obtaining the communication message data information generated in the target communication scenario, ensure that the in-vehicle infotainment system of the vehicle to be tested is connected to the power control system, configure the power parameters of the power control system based on the test script, and ensure that the vehicle to be tested operates normally under different test conditions. Among them, the power parameters include at least one of the following: voltage regulation range, regulation step size, and regulation time. Before conducting the security test of the in-vehicle private remote communication protocol of the present invention, the power parameters of the test vehicle are accurately configured through the power control system to ensure that the vehicle can maintain stable operation under various simulated conditions. This preparation of pre-test conditions is an important step to ensure the accuracy and reliability of the test results. The configuration of power parameters, such as voltage regulation range, regulation step size, and regulation time, can simulate the power state of the vehicle in different environments, such as low voltage, high voltage, or voltage fluctuation, which helps to test the performance of the in-vehicle infotainment system (IVI) under extreme conditions and ensure the stability and security of its communication protocol.
[0055] In a specific embodiment, assume that the security of the private remote communication protocol of an IVI system is being tested in a low-voltage environment. The following implementation steps are included: Connect the IVI system to be tested to the automated test equipment and simultaneously access the power control system to ensure that the network data capture tool and the log analysis tool are in a standby state. Based on the test script, the power control system is set to the low-voltage working condition. For example, the voltage regulation range is set to 10V to 12V, the regulation step size is 0.1V, and the regulation time is 1 second. Start the IVI system in the low-voltage environment and ensure that it starts and operates normally within the voltage range, including maintaining stable communication with the remote server. Use the network data capture tool to capture the communication message data information between the IVI system and the remote server, especially paying attention to the communication message data information related to key derivation, update, and transmission. At the same time, start the log analysis tool of the IVI system to record the operation log of the system in the low-voltage environment, including the record of key update events. Confirm whether the key derivation, update, and transmission processes are carried out normally, and whether the system can accurately record each key update event. After the low-voltage environment lasts for a period of time, the system simulates the voltage returning to normal and evaluates whether the IVI system can quickly recover and continue to conduct secure communication, especially paying attention to the recovery ability of the key management mechanism. All test results, including communication message data information, log data information, execution result information of the test script, etc., are summarized in the automated test report, which details the performance and security performance of the system.
[0056] Further, during the execution of the above test steps, the key update and transmission tests of the vehicle-mounted private remote communication protocol are performed according to a preset test process. Meanwhile, a performance monitoring tool is started to record the response time and resource consumption. When performing a key update or transmission operation, the test script records the timestamp when the operation starts. After the operation is completed, the timestamp when the operation ends is immediately recorded, and the difference between the two timestamps is used as the response time. The change trend of the response time under different network conditions and system loads can be further analyzed. During the operation process, the peak value of the system resource consumption is continuously monitored and recorded, especially the usage of CPU and memory. The response time and resource consumption data are summarized and analyzed to generate a test report.
[0057] It should be further noted that the test script first initializes the test environment, including connecting the IVI system under test to the power control system, setting the power parameters to ensure the stable operation of the system under test conditions, and starting the network data capture tool and log analysis tool. According to the preset test process, the script simulates the target communication scenario, such as triggering a key update event or a key transmission request, and creating an insecure transmission environment, etc., to conduct a comprehensive security function test. Under the simulated scenario, the automated test script calls the network data capture tool to capture all relevant communication message data information, and at the same time calls the log analysis tool to obtain the log data information, including but not limited to key update events, system operations, error messages, etc. The captured data is deeply parsed by the script. For the communication message data, the script will analyze information such as its key update policy, update frequency, update timestamp, transmission channel security, etc.; for the system log, the test script will check the integrity of the key update record, exception handling log, etc. The automated test script will also perform additional simulation tests, such as simulating network interruption and authentication failure scenarios, to verify the key rollback protection mechanism and exception handling mechanism of the system. The script also monitors and records the performance data of the system during the execution of key update and transmission, such as response time, resource consumption (CPU usage rate, memory occupancy), etc., to evaluate the resource consumption and response efficiency of the system, and finally generates a test report on the execution result of the test script.
[0058] Figure 6 is a flowchart of another method for testing the security of an automotive private remote communication protocol according to an embodiment of the present invention, as Figure 6 shown, the method includes the following steps:
[0059] Step S601, obtaining communication message data information generated in a target communication scenario;
[0060] Step S602, parsing the communication message data information to obtain a parsing result;
[0061] Step S603: Analyze the key derivation strategy in the communication message data information to obtain the key encryption result in the analysis result;
[0062] Step S604: Analyze the update strategy in the communication message data information to obtain the update result in the analysis result;
[0063] Step S605: Analyze the transmission strategy in the communication message data information to obtain the transmission result in the analysis result;
[0064] Step S606: Based on the analysis result, determine whether the execution actions of the communication message data information of the vehicle to be detected in the target communication scenario meet the preset conditions, and obtain the judgment result, where the execution actions at least include the update action, encryption action, and transmission action of the communication message data information;
[0065] Step S607: In the case where the analysis result is the key encryption result, based on the preset encryption algorithm, determine whether the key encryption result meets the preset security strength, and obtain the judgment result, where the preset encryption algorithm is at least one of the AES algorithm, RSA algorithm, and ECDH algorithm;
[0066] Step S608: In the case where the analysis result is the update result, based on the preset update standard, determine whether the update result meets the preset update standard, and obtain the judgment result, where the update standard is the key update frequency, key update time, and key update trigger condition;
[0067] Step S609: Use a log analysis tool to obtain the log data information of the vehicle to be detected;
[0068] Step S610: Based on the log data information, confirm whether the key update event is recorded;
[0069] Step S611: In the case where the key update event is recorded, analyze the key update event to obtain the log update information of the key update event;
[0070] Step S612: Based on the log update information, determine whether the key update frequency, key update time, and key update trigger condition meet the log preset update standard;
[0071] Step S613: In the case where the update result meets the preset update standard, access the simulated abnormal scenario information to obtain the simulation result, where the abnormal scenario information is used to simulate at least one of the network interruption scenario, authentication failure scenario, and transmission error scenario;
[0072] Step S614: Based on the simulation results, determine whether the test system of the vehicle to be detected supports a preset processing mechanism, where the preset processing mechanism includes a key rollback protection mechanism, an exception handling mechanism, and a retransmission mechanism;
[0073] Step S615: When it is determined that the parsing result is a transmission result, based on a preset transmission channel, determine whether the transmission result meets the preset security verification and obtain a judgment result, where the preset transmission channel is at least one of an HTTPS channel and a TLS channel;
[0074] Step S616: When it is determined that the transmission structure meets the preset security verification, simulate an insecure transmission environment based on the target communication scenario, and verify whether the test system of the vehicle to be detected rejects insecure transmission requests, where the preset security verification includes two-way identity verification and data integrity verification;
[0075] Step S617: Generate a test report based on the judgment result, where the test report includes at least one of communication message data information, log data information, execution result information of the test script, and performance data information of the vehicle to be detected.
[0076] Based on the above steps S601 to S617, in the embodiment of the present invention, by using an automated test script, by obtaining and parsing the communication message data information generated in the target communication scenario, the purpose of comprehensively evaluating the security and stability of the automotive private remote communication protocol in the process of key update, encryption, and transmission is achieved, thereby realizing the technical effects of improving the test efficiency, reducing the labor cost, and ensuring the security of the remote communication of intelligent connected vehicles, and further solving the technical problems of cumbersome process and low efficiency in the existing remote communication protocol test method.
[0077] In this embodiment, a security test device for an automotive private remote communication protocol is further provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0078] Figure 3 is a structural block diagram of a security test device for an automotive private remote communication protocol according to an embodiment of the present invention. As Figure 3 shown, the device includes:
[0079] A packet capture tool, which is used to obtain the communication message data information generated in the target communication scenario;
[0080] A test module, which parses the communication message data to obtain a parsing result;
[0081] A judgment module that, based on the parsing result, judges whether the execution actions of the communication message data information of the vehicle to be detected in the target communication scenario meet the preset conditions, and obtains a judgment result. The execution actions at least include an update action, an encryption action, and a transmission action of the communication message data information.
[0082] A generation module that, based on the judgment result, generates a test report. The test report includes at least one of communication message data information, log data information, execution result information of a test script, and performance data information of the vehicle to be detected.
[0083] Through the above device, by adopting the method of an automated test script, by acquiring and parsing the communication message data information generated in the target communication scenario, the purpose of comprehensively evaluating the security and stability of the automotive private remote communication protocol in the process of key update, encryption, and transmission is achieved. Thus, the technical effects of improving the test efficiency, reducing the labor cost, and ensuring the security of the remote communication of intelligent connected vehicles are realized, and furthermore, the technical problem of the cumbersome process and low efficiency of the remote communication protocol test method in the prior art is solved.
[0084] In another embodiment of the present application, as Figure 5 shown, the automotive private remote communication protocol security test device includes a vehicle-mounted private remote communication protocol key update test module, a vehicle-mounted private remote communication protocol key transmission test module, and an automated execution test unit. The automated execution test unit includes a power control system and a network data capture tool. The automated execution test unit is electrically connected to the TBOX controller to be tested, controls the execution of the above test method, generates an automated test result based on the transmission test module and the update test module, and automatically generates an automated test report.
[0085] Using Figure 5 the device shown for the automotive private remote communication protocol security test, the process is as Figure 4 shown: Start the TBOX controller, configure system parameters through the automated execution test unit, provide a target communication scenario, acquire communication message data information, and then the transmission test module and the update test module parse the communication message data information, check whether the key derivation strategy, update strategy, and transmission strategy meet the preset security standards to generate a test result, and generate a test report with a qualified test result or an unqualified test result based on the test result.
[0086] It should be noted that the above-mentioned various modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to this: The above modules are all located in the same processor; or, the above-mentioned various modules are respectively located in different processors in any combination form.
[0087] An embodiment of the present application further provides a computer-readable storage medium, which includes a stored executable program. When the executable program runs, it controls the device where the computer-readable storage medium is located to execute the methods in various embodiments of the present invention.
[0088] Optionally, in this embodiment, the above storage medium may be set to store an executable program for performing the following steps:
[0089] Step S1, obtain communication message data information generated in a target communication scenario;
[0090] Step S2, parse the communication message data information to obtain a parsing result;
[0091] Step S3, based on the parsing result, determine whether the execution actions of the communication message data information of the vehicle to be detected in the target communication scenario meet preset conditions, and obtain a judgment result, where the execution actions at least include an update action, an encryption action, and a transmission action of the communication message data information;
[0092] Step S4, based on the judgment result, generate a test report, where the test report includes at least one of communication message data information, log data information, execution result information of a test script, and performance data information of the vehicle to be detected.
[0093] Optionally, in this embodiment, the above storage medium may include, but is not limited to: various media that can store computer programs such as a USB flash drive, a read-only memory (ROM for short), a random access memory (RAM for short), a mobile hard disk, a magnetic disk, or an optical disc.
[0094] An embodiment of the present invention further provides a processor, which is set to run a computer program to execute the steps in any one of the above method embodiments.
[0095] Optionally, in this embodiment, the above processor may be set to execute the following steps through a computer program:
[0096] Step S1, obtain communication message data information generated in a target communication scenario;
[0097] Step S2, parse the communication message data information to obtain a parsing result;
[0098] Step S3: Based on the parsing result, determine whether the execution actions of the communication message data information of the vehicle to be detected in the target communication scenario meet the preset conditions, and obtain a judgment result. The execution actions at least include the update action, encryption action, and transmission action of the communication message data information.
[0099] Step S4: Based on the judgment result, generate a test report. The test report includes at least one of the communication message data information, log data information, execution result information of the test script, and performance data information of the vehicle to be detected.
[0100] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0101] In several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.
[0102] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0103] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0104] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.
[0105] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. A method for security testing of a private remote communication protocol for an automobile, characterized in that: include: Obtain communication message data information generated in the target communication scenario; Parsing the communication message data information to obtain a parsing result; Based on the analysis result, determine whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions, and obtain a determination result, wherein the execution action at least includes an update action, an encryption action, and a transmission action of the communication message data information; Based on the judgment result, a test report is generated, wherein the test report includes at least one of the communication message data information, log data information, execution result information of the test script and performance data information of the vehicle to be tested.
2. The automobile private remote communication protocol security testing method according to claim 1 is characterized in that: Parsing the communication message data information to obtain the parsing result includes: Parsing the key derivation strategy in the communication message data information to obtain the key encryption result in the parsing result; Parsing the update strategy in the communication message data information to obtain an update result in the parsing result; The transmission strategy in the communication message data information is parsed to obtain the transmission result in the parsing result.
3. The automobile private remote communication protocol security testing method according to claim 2 is characterized in that: Based on the analysis result, determining whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets a preset condition, and obtaining the determination result includes: When it is determined that the analysis result is the key encryption result, based on a preset encryption algorithm, it is judged whether the key encryption result meets a preset security strength, and the judgment result is obtained, wherein the preset encryption algorithm is at least one of an AES algorithm, an RSA algorithm and an ECDH algorithm.
4. The automobile private remote communication protocol security testing method according to claim 2 is characterized in that: Based on the analysis result, determining whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets a preset condition, and obtaining the determination result includes: When it is determined that the analysis result is the update result, based on a preset update standard, it is judged whether the update result meets the preset update standard, and the judgment result is obtained, wherein the update standard is the key update frequency, the key update time, and the key update trigger condition.
5. The automobile private remote communication protocol security testing method according to claim 2 is characterized in that: Based on the analysis result, it is determined whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets the preset conditions, and the determination result is obtained, including When it is determined that the analysis result is the transmission result, based on a preset transmission channel, it is judged whether the transmission result satisfies a preset security check, and the judgment result is obtained, wherein the preset transmission channel is at least one of an HTTPS channel and a TLS channel.
6. The automobile private remote communication protocol security testing method according to claim 4 is characterized in that: In the case where it is determined that the parsing result is the update result, judging whether the update result meets the preset update standard based on the preset update standard, and obtaining the judgment result includes: Using a log analysis tool to obtain the log data information of the vehicle to be detected; Based on the log data information, confirm whether the key update event is recorded; When it is determined that the key update event is recorded, parsing the key update event to obtain log update information of the key update event; Based on the log update information, it is determined whether the key update frequency, the key update time, and the key update trigger condition meet the preset update standard.
7. The automobile private remote communication protocol security testing method according to claim 5 is characterized in that: In the case where it is determined that the parsing result is the update result, judging whether the update result meets the preset update standard based on the preset update standard, and obtaining the judgment result includes: When it is determined that the update result meets the preset update standard, access the simulated abnormal scenario information to obtain a simulation result, wherein the simulated abnormal scenario information is used to simulate at least one of a network interruption scenario, an authentication failure scenario, and a transmission error scenario; Based on the simulation result, it is determined whether the test system of the vehicle to be tested supports a preset processing mechanism, wherein the preset processing mechanism includes a key rollback protection mechanism, an exception handling mechanism, and a retransmission mechanism.
8. The automobile private remote communication protocol security testing method according to claim 7 is characterized in that: The method further comprises: When it is determined that the transmission result satisfies the preset security check, an unsafe transmission environment is simulated based on the target communication scenario to verify whether the test system of the vehicle to be tested rejects the unsafe transmission request, wherein the preset security check includes a bidirectional identity check and a data integrity check.
9. A vehicle private remote communication protocol security testing device, characterized in that: include: A packet capture tool, which is used to obtain communication message data information generated in a target communication scenario; A test module, the test module is used to parse the communication message data to obtain a parsing result; A judgment module, the judgment module is used to judge whether the execution action of the communication message data information of the vehicle to be detected in the target communication scenario meets a preset condition based on the analysis result, and obtain a judgment result, wherein the execution action at least includes an update action, an encryption action, and a transmission action of the communication message data information; A generation module, the generation module is used to generate a test report based on the judgment result, wherein the test report includes at least one of the communication message data information, log data information, execution result information of the test script and performance data information of the vehicle to be tested.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is executed, the device where the storage medium is located is controlled to execute the method according to any one of claims 1 to 8.