Intelligent networked automobile data and information security evaluation method and system
Through a multi-level security architecture and a multi-dimensional evaluation system, combined with static and dynamic testing environments, an intelligent connected vehicle safety evaluation model is built and a standardized risk assessment report is generated, which solves the shortcomings of existing evaluation methods and achieves a comprehensive, accurate and efficient evaluation of the data and information security of intelligent connected vehicle.
Patent Information
- Application Number
- CN202510782617.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-08-15
AI Technical Summary
The existing data and information security evaluation methods for intelligent connected vehicles have problems such as separate evaluation, static rule construction, inconsistent risk grading and inefficient manual evaluation, which is difficult to meet the needs of rapid iteration and development of intelligent connected vehicles.
Using a multi-level security architecture and a multi-dimensional evaluation system, by obtaining security test data for wireless communications, on-board networks, application software and information interactions, combining static and dynamic testing environments, an intelligent connected vehicle safety evaluation model is built, a standardized security risk assessment report is generated, and a repair plan is formulated for verification.
It realizes comprehensive monitoring and accurate identification of the comprehensive safety conditions of intelligent connected vehicles, generates objective risk assessment reports, provides clear safety reinforcement guidance, improves the degree of automation of evaluation and the accuracy of results, and meets the needs of rapid iterative development.
Smart Images

Figure CN120498828A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle network security technology, and in particular to a method and system for evaluating data and information security of intelligent connected vehicles. Background Art
[0002] With the rapid development of automotive electronics, networking, and intelligence, intelligent connected vehicles (ICVs), a product of the deep integration of modern information technology and the traditional automotive industry, have become a key development direction for the automotive industry. Using onboard sensors, controllers, actuators, and other devices, combined with modern communications and network technologies, ICVs enable information exchange and sharing between vehicles, between vehicles and roads, between vehicles and people, and between vehicles and cloud platforms. However, with the rapid development of ICV technology, data and information security issues are becoming increasingly prominent. According to relevant research statistics, cyberattacks targeting ICVs are increasing year by year, and attack methods are evolving from single-source communication interception to diversified and complex attacks, including wireless communication hijacking, in-vehicle network intrusion, application software vulnerability exploitation, and information exchange interference. These security threats not only lead to user privacy leaks but also potentially affect vehicle operation and even cause serious traffic accidents, posing a serious challenge to the healthy development of the ICV industry.
[0003] Existing data and information security assessment methods for intelligent connected vehicles (ICVs) suffer from the following key shortcomings: First, traditional assessment methods often employ a separate evaluation strategy, evaluating wireless communication security, in-vehicle network security, application software security, and information interaction security as independent dimensions. This ignores the interconnectedness between these security domains, leading to significant discrepancies between the overall assessment results and the actual security situation. Second, existing assessment models are often based on static rules, lacking adaptability to dynamically changing security threats and incapable of addressing increasingly complex attack vectors. Third, assessment results are often limited to identifying risk points, lacking systematic risk grading standards and targeted security protection recommendations, making it difficult to guide subsequent security reinforcement efforts. Finally, existing assessment methods often rely on expert experience for risk analysis, resulting in inefficient assessments and highly subjective results, making them unable to meet the demands of the rapid, iterative development of ICVs. These issues severely hinder the development of an ICV data and information security assurance system, necessitating a more systematic, intelligent, and standardized assessment method and system. Summary of the Invention
[0004] In view of the problems existing in the prior art, the present invention is proposed.
[0005] Therefore, the problem to be solved by the present invention is how to solve the following technical problems: First, how to realize the comprehensive collection and analysis of multi-dimensional security data of intelligent connected vehicles, and establish a comprehensive security assessment system covering dimensions such as wireless communication, vehicle network, application software and information interaction; second, how to build a highly adaptable security assessment model to achieve accurate identification of potential security risks of intelligent connected vehicles; third, how to generate standardized and highly operational security risk assessment reports to provide effective guidance for the security reinforcement of intelligent connected vehicles; fourth, how to improve the degree of automation of the assessment process and the objectivity of the assessment results to meet the needs of rapid iterative development of intelligent connected vehicles. By solving the above problems, the present invention can effectively improve the level of data and information security protection of intelligent connected vehicles, and provide technical support for the healthy development of the intelligent connected vehicle industry.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: In a first aspect, an embodiment of the present invention provides a method for evaluating data and information security of an intelligent connected vehicle, comprising obtaining security test data of the intelligent connected vehicle, wherein the security test data includes at least wireless communication security data, vehicle network security data, vehicle application software security data, and information interaction security data; Analyze the safety test data using an intelligent connected vehicle safety assessment model to identify potential safety risk points; Based on the identified security risk points, a security risk assessment report is generated, including risk level, risk type and security protection recommendations.
[0007] As a preferred solution of the intelligent connected vehicle data and information security assessment method described in the present invention, the security test data includes data collected by the intelligent connected vehicle in a static test environment and a dynamic test environment.
[0008] As a preferred solution of the intelligent connected vehicle data and information security assessment method described in the present invention, the static test environment includes a simulated computer network attack environment and a simulated physical security intrusion environment; the dynamic test environment includes an actual road driving environment and a simulated complex traffic scene environment.
[0009] As a preferred solution of the intelligent connected vehicle data and information security assessment method described in the present invention, the intelligent connected vehicle security assessment model is constructed based on industry standard security specifications and historical security event data, supporting automatic identification of security vulnerabilities and automatic assessment of risk levels.
[0010] As a preferred solution of the intelligent connected vehicle data and information security assessment method described in the present invention, the risk levels in the security risk assessment report are divided into emergency risk, high risk, medium risk and low risk; the risk types include at least identity authentication risk, data transmission risk, data encryption risk, authorized access risk and software update risk.
[0011] As a preferred solution of the intelligent connected vehicle data and information security assessment method described in the present invention, it also includes the step of formulating a repair plan based on the security risk assessment report, and the repair plan includes security patch updates, security policy adjustments and security protection mechanism enhancements.
[0012] As a preferred solution of the intelligent connected vehicle data and information security assessment method described in the present invention, it also includes: a re-inspection step for the intelligent connected vehicle for which the repair plan has been implemented, verifying the repair effect and updating the security risk assessment report.
[0013] In a second aspect, an embodiment of the present invention provides an intelligent connected vehicle data and information security assessment system, which includes a security test data acquisition module for acquiring security test data of the intelligent connected vehicle, wherein the security test data includes at least wireless communication security data, vehicle network security data, vehicle application software security data, and information interaction security data; A safety risk analysis module, configured to analyze the safety test data using an intelligent connected vehicle safety assessment model to identify potential safety risk points; The security assessment report generation module is used to generate a security risk assessment report based on the identified security risk points, including risk level, risk type and security protection recommendations.
[0014] In a third aspect, an embodiment of the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program instructions are executed by the processor, the steps of the intelligent connected vehicle data and information security assessment method as described in the first aspect of the present invention are implemented.
[0015] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program instructions are executed by a processor, the steps of the intelligent connected vehicle data and information security assessment method as described in the first aspect of the present invention are implemented.
[0016] The beneficial effects of the present invention are as follows: the intelligent connected vehicle data and information security assessment method and system provided by the present invention effectively solve the problems of separate evaluation, static rule construction, inconsistent risk classification, and low efficiency of manual assessment existing in traditional assessment methods by comprehensively adopting a multi-level security architecture and a multi-dimensional assessment system, thereby realizing a comprehensive and systematic assessment of the data and information security of intelligent connected vehicles.
[0017] Specifically, by acquiring multi-dimensional security test data, including wireless communication security data, in-vehicle network security data, in-vehicle application software security data, and information interaction security data, this method achieves comprehensive monitoring of the all-around security status of intelligent connected vehicles, avoiding the security blind spots caused by the independent assessment of each security area in traditional methods. This step combines static and dynamic test environments, not only identifying potential security vulnerabilities under controlled conditions, but also verifying the safety performance of vehicles in actual operation, significantly improving the comprehensiveness and authenticity of security test data.
[0018] By building an intelligent connected vehicle (ICV) safety assessment model that integrates industry-standard safety specifications and historical security incident data, this invention achieves accurate identification and automated assessment of potential security risks, effectively addressing the complex and ever-changing challenges of ICV security threats. This model utilizes a multi-layered security assessment architecture encompassing the network, system, application, and data layers. This model not only enables in-depth analysis of specific security issues at each layer, but also comprehensively assesses the vehicle's safety protection capabilities, significantly improving the accuracy and comprehensiveness of risk identification.
[0019] By generating a standardized security risk assessment report that includes risk levels, risk types, and security recommendations, this invention provides clear guidance and specific measures for security reinforcement in intelligent connected vehicles. The report categorizes risk levels into critical, high, medium, and low risks, with risk types covering key security areas such as identity authentication, data transmission, data encryption, authorized access, and software updates. Security recommendations offer comprehensive guidance from both technical and management perspectives, standardizing the presentation of assessment results and enhancing their practicality.
[0020] Furthermore, by developing remediation plans based on security risk assessment reports and verifying their effectiveness, this invention forms a complete security assessment-remediation-verification closed loop, ensuring effective resolution and continuous improvement of security issues. The remediation plan includes security patch updates, security policy adjustments, and enhanced security protection mechanisms, covering every aspect from specific vulnerability fixes to overall security improvements. The recheck step ensures the effectiveness of the remediation through rigorous verification testing, achieving closed-loop management of security risks.
[0021] Overall, this invention achieves a comprehensive, accurate, and efficient assessment of the data and information security of intelligent connected vehicles through a systematic evaluation method and intelligent analysis model, providing strong technical support for the healthy development of the intelligent connected vehicle industry. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0023] Figure 1 A flowchart of the data and information security assessment method for intelligent connected vehicles; Figure 2 A diagram of computer equipment for the data and information security assessment method for intelligent connected vehicles. DETAILED DESCRIPTION
[0024] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0025] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0026] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it constitute a separate or selective embodiment that is mutually exclusive with other embodiments. Example
[0027] Reference Figures 1 and 2 , which is the first embodiment of the present invention, provides a method for evaluating data and information security of intelligent connected vehicles, including: S100: Acquire security test data of the intelligent connected vehicle, where the security test data includes at least wireless communication security data, vehicle network security data, vehicle application software security data, and information interaction security data; S200: Analyzes safety test data using the intelligent connected vehicle safety assessment model to identify potential safety risks. S300: Generate a security risk assessment report based on the identified security risk points, including risk level, risk type and security protection recommendations.
[0028] It should be noted that intelligent connected vehicles, as a product of the deep integration of information and network technologies with the automotive industry, present increasingly prominent data and information security issues. On the one hand, the increasingly complex system architecture of intelligent connected vehicles, involving multiple layers of communication interfaces and data exchange nodes, continuously expands the attack surface. On the other hand, existing security assessment methods suffer from single-dimensional assessments, static rule-based construction, inconsistent risk grading standards, and inefficient manual assessments. Especially when vehicles exchange information with the outside world through V2X technology, wireless communication interfaces are vulnerable to man-in-the-middle attacks and replay attacks, threatening the integrity and authenticity of communications. In-vehicle network systems such as the CAN bus and Ethernet are exposed to threats such as malicious message injection and denial-of-service attacks, which can cause vehicle control system anomalies. In-vehicle application software may contain code vulnerabilities and improper permission management, providing infiltration points for attackers. Inadequate data encryption and lack of authentication mechanisms during information exchange can lead to the leakage or tampering of sensitive data. These security risks not only threaten user privacy but also potentially impact vehicle safety and even cause serious traffic accidents.
[0029] Therefore, to address the above-mentioned problems, through steps S100-S300, we have achieved the comprehensive collection and analysis of multi-dimensional security data of intelligent connected vehicles, established a security assessment system covering various dimensions such as wireless communication, in-vehicle networks, application software, and information interaction, and avoided the security blind spots caused by single-dimensional assessments; constructed a highly adaptable security assessment model that can accurately identify potential security risk points and improve the ability to respond to complex attack methods; generated a standardized security risk assessment report containing risk levels, risk types, and security protection recommendations, providing clear guidance for subsequent security reinforcement work; the entire assessment process is highly automated, and the assessment results are objective and quantifiable, effectively meeting the needs of the rapid iterative development of intelligent connected vehicles. Through this systematic, intelligent, and standardized assessment method, the level of security protection of intelligent connected vehicle data and information can be effectively improved, ensuring the healthy and sustainable development of the intelligent connected vehicle industry. Example
[0030] Reference Figure 1-Figure 2 , which is the second embodiment of the present invention.
[0031] In the embodiment of the present application, step S100 obtains security test data of the intelligent connected vehicle, where the security test data includes at least wireless communication security data, vehicle network security data, vehicle application software security data, and information interaction security data, including the following steps A1-A2: A1: Safety test data includes data collected by intelligent connected vehicles in static test environments and dynamic test environments.
[0032] A2: The static test environment includes a simulated computer network attack environment and a simulated physical security intrusion environment; the dynamic test environment includes an actual road driving environment and a simulated complex traffic scenario environment.
[0033] Specifically, in A1, the static test environment is primarily used to conduct a basic assessment of the cybersecurity protection capabilities of intelligent connected vehicles and identify potential security vulnerabilities in controlled test scenarios. This environment comprehensively tests the vehicle's security protection mechanisms by simulating various cyberattacks and physical intrusion scenarios. The dynamic test environment is primarily used to evaluate the security protection performance of intelligent connected vehicles during actual operation, verifying their safety and stability under different driving conditions and traffic scenarios, and thus identifying potential security risks.
[0034] In an optional implementation, security test data can also be collected through regular remote updates. This involves utilizing OTA (Over-The-Air) technology to monitor the safety status of deployed connected vehicles in real time and collect safety-related data from their actual use. This approach not only captures a large amount of real-world security test data but also enables timely detection and response to emerging security threats, providing data support for the continuous optimization of security assessment models.
[0035] In another alternative implementation, security test data can be collected through public security testing. This involves inviting professional security researchers to conduct security penetration tests on various system components of intelligent connected vehicles, simulating hacker attack strategies and methods to identify potential security vulnerabilities and risk points. This approach fully leverages the expertise and experience of security experts, uncovering security issues that might be overlooked in conventional testing and enhancing the comprehensiveness and representativeness of the data.
[0036] In the embodiment of the present application, the simulated computer network attack environment in A2 is specifically implemented by building a dedicated network security testing platform that integrates a variety of network attack tools and vulnerability scanners and can simulate various network attack scenarios, including but not limited to: Man-in-the-middle attack, signal interference and hijacking tests on Bluetooth and Wi-Fi interfaces; Network penetration and packet injection testing of in-vehicle Ethernet and CAN bus; Vulnerability scanning and exploitation testing of in-vehicle applications; Security verification and attack testing of V2X communication protocols; Security access control testing of the on-board diagnostic interface (OBD-II).
[0037] The simulated physical security intrusion environment is mainly used to evaluate the protection capabilities of intelligent connected vehicles against physical attacks, including but not limited to: Unauthorized access testing of vehicle physical interfaces (such as USB ports and OBD interfaces); Interference and deception testing of vehicle-mounted sensors, such as GPS signal deception, radar jamming, etc. Security testing of vehicle key systems, such as encryption strength testing of keyless entry systems and smart key systems; Physical extraction and data recovery testing of vehicle-mounted storage media; Hardware-level security testing of vehicle ECUs (electronic control units), such as side-channel attacks and fault injection.
[0038] The actual road driving environment refers to the safety testing of intelligent connected vehicles under actual traffic conditions, mainly evaluating the safety protection performance of the vehicle under real driving conditions. The test content includes but is not limited to: Safety system stability test of the vehicle under different driving conditions (such as high-speed driving, sharp turns, emergency braking, etc.); V2X communication safety testing of vehicles in actual urban roads, highways and other environments; Vehicle remote communication security testing under different wireless network coverage conditions; Vehicle sensor data security testing under different weather conditions (such as rainy days, foggy days, nighttime, etc.); Test the vehicle's ability to detect and respond to abnormal attack behaviors during actual driving.
[0039] The simulated complex traffic scene environment is a variety of complex traffic scenes constructed using high-precision driving simulators and virtual reality technology to evaluate the safety performance of intelligent connected vehicles under special traffic conditions. Test contents include but are not limited to: V2V (vehicle-to-vehicle) communication security testing on congested roads; V2I (vehicle-to-infrastructure) communication security testing in traffic light failure scenarios; Data interaction security testing during multi-vehicle collaborative driving; Safety testing of decision-making systems in emergency risk avoidance scenarios; Comprehensive security testing when cyber attacks and physical environment changes occur simultaneously.
[0040] It should be noted that the four test environments above complement and work together to form a comprehensive, systematic safety testing environment. The static test environment focuses on the fundamental evaluation of individual safety protection mechanisms, while the dynamic test environment prioritizes the verification of comprehensive safety performance. The combined use of these two environments enables a comprehensive assessment of the safety protection capabilities of intelligent connected vehicles in various scenarios, providing reliable data support for the identification and assessment of safety risks.
[0041] In the embodiment of the present application, step S200 uses the intelligent connected vehicle safety assessment model to analyze the safety test data and identify potential safety risk points, including the following steps B1-B2: B1: The intelligent connected vehicle safety assessment model is built based on industry standard safety specifications and historical security incident data, supporting automatic identification of security vulnerabilities and automatic assessment of risk levels.
[0042] B2: The intelligent connected vehicle security assessment model adopts a multi-layered security assessment architecture, including network layer security, system layer security, application layer security, and data layer security assessment. By comprehensively analyzing the security status of each layer, a comprehensive assessment of the overall security risks of intelligent connected vehicles can be achieved.
[0043] Specifically, in B1, the intelligent connected vehicle safety assessment model is mainly constructed based on the following industry standard safety specifications: ISO / SAE 21434:2021, Road Vehicle Cybersecurity Engineering, which specifies the requirements, processes, and assessment methods for vehicle cybersecurity risk management; UNECE WP.29, "Uniform Technical Regulation on Vehicle Cybersecurity and Software Updates," sets out specific requirements for vehicle cybersecurity management systems and software update management systems; AUTO-ISAC's "Security Best Practices for Automotive Information Sharing and Analysis Centers," a practical guide that provides design, implementation, and testing recommendations for vehicle cybersecurity; NIST SP 800-30, "Risk Assessment Guide," provides a general methodology and process for information system risk assessment.
[0044] At the same time, the model also integrates a large amount of historical security event data, including: Publicly available security vulnerability information for connected vehicles, such as relevant records in the CVE (Common Vulnerabilities and Exposures) database; Typical security incidents recorded in domestic and international intelligent connected vehicle security research reports and technical white papers; Security vulnerability and threat intelligence collected by the Producer Security Response Center (PSIRT); Intelligent connected vehicle security research results and vulnerability disclosure reports released by security researchers; Safety abnormal event data collected during actual road tests.
[0045] These industry standards and historical event data provide the model with a rich security knowledge base, enabling it to accurately identify and assess various security risks.
[0046] In B2, the multi-level security assessment architecture specifically includes: Network-layer security assessment: This primarily evaluates the security of the vehicle's external communication interfaces and internal networks, including the security protection capabilities of wireless communication interfaces (such as Bluetooth, Wi-Fi, and cellular networks) and in-vehicle networks (such as the CAN bus, FlexRay, and Ethernet). The assessment covers communication encryption strength, identity authentication mechanisms, intrusion detection capabilities, and denial-of-service attack protection.
[0047] System-level security assessment: This primarily evaluates the security of the vehicle's operating system and ECU firmware, including security measures in areas such as system privilege management, secure boot mechanisms, memory protection, and patch management. The assessment covers the effectiveness of system privilege isolation, firmware encryption signature verification, and secure update mechanisms.
[0048] Application-layer security assessment: This primarily evaluates the security of in-vehicle application software, including third-party application security management, application interface security, and data access control. This assessment includes application vulnerability scanning, API security checks, and code security audits.
[0049] Data layer security assessment: This primarily evaluates the security of vehicle data, including security measures for data storage, transmission, processing, and sharing. The assessment covers data encryption methods, sensitive data handling, data access control, and privacy protection mechanisms.
[0050] The automatic identification of security vulnerabilities is mainly based on the following technologies: Rule-based vulnerability scanning: Based on known security vulnerability characteristics and attack patterns, a rule library is established to identify potential security vulnerabilities through matching detection; Risk identification based on anomaly detection: Using machine learning algorithms to build a normal behavior model for vehicle systems, detect abnormal activities that deviate from normal behavior, and identify potential safety risks; Risk identification based on threat intelligence: Integrate threat intelligence data from various channels to identify the latest security threats and vulnerabilities related to vehicle systems; Static security code analysis: Perform static analysis on vehicle software code to detect potential security vulnerabilities and coding issues; Dynamic security testing: By simulating attack behaviors, dynamic security testing is performed on the vehicle system to verify the actual protection capabilities.
[0051] The automatic risk level assessment function is mainly based on the following factors for comprehensive evaluation: Threat impact scope: Assess the scope of vehicle systems and potential number of users that a security vulnerability could affect; Security impact severity: Assess the severity of the consequences that may result from the exploitation of security vulnerabilities, especially the impact on vehicle safety control systems; Attack complexity: Assess the technical difficulty and resources required to exploit the vulnerability; Exploitability: Assess the likelihood that the vulnerability can be exploited, taking into account factors such as known attack methods and publicly available vulnerability information; Repair Difficulty: Assess the technical difficulty and resources required to repair the security vulnerability.
[0052] In an optional implementation, the intelligent connected vehicle safety assessment model can also adopt a security analysis method based on a knowledge graph to construct a vehicle safety knowledge graph to describe the complex relationship between vehicle system components, security vulnerabilities, attack methods and security protection measures, and analyze potential attack paths and risk propagation chains through graph algorithms to achieve a more in-depth security risk analysis.
[0053] In another optional implementation, the intelligent connected vehicle safety assessment model can also adopt a scenario-based security simulation analysis method to build a virtual security test environment, simulate various security attack scenarios, analyze the security protection performance of the vehicle system under different attack scenarios, and identify potential security weaknesses and risk points.
[0054] It should be noted that the intelligent connected vehicle security assessment model utilizes a modular design. Assessment modules at each level can operate independently or collaboratively, allowing for flexible configuration based on assessment requirements. The model supports incremental updates and can be continuously optimized and improved based on new security standards and threat intelligence, maintaining its ability to identify the latest security threats. Furthermore, the model includes a built-in security knowledge base containing a large number of known security vulnerabilities and attack pattern descriptions, providing a foundation for the automated identification of security vulnerabilities.
[0055] In the embodiment of the present application, step S300 generates a security risk assessment report based on the identified security risk points, including risk level, risk type and security protection suggestions, including the following steps C1-C3: C1: The risk levels in the security risk assessment report are divided into emergency risk, high risk, medium risk and low risk; the risk types include at least identity authentication risk, data transmission risk, data encryption risk, authorized access risk and software update risk.
[0056] C2: It also includes steps to develop a repair plan based on the security risk assessment report. The repair plan includes security patch updates, security policy adjustments, and security protection mechanism enhancements.
[0057] C3: It also includes the steps of re-inspecting the intelligent connected vehicles for which the repair plan has been implemented, verifying the repair effect and updating the safety risk assessment report.
[0058] Specifically, in C1, the risk level classification criteria are as follows: Emergency risks: These risks could cause critical vehicle safety systems to fail, directly threatening the lives of drivers and passengers, or potentially leading to large-scale data breaches. These risks typically have severe security implications, are characterized by low attack complexity, and a high likelihood of exploitation. Immediate remediation measures are required, such as temporarily disabling related functions or implementing emergency patches.
[0059] High risk refers to security risks that could cause non-critical vehicle systems to malfunction, impacting normal vehicle operation, or potentially leaking important sensitive data. These risks have a significant security impact, are of medium attack complexity, and have a high likelihood of exploitation. They require priority remediation, typically completed within a short period of time (e.g., within 7 days).
[0060] Medium risk: This refers to security risks that could potentially restrict some non-core vehicle functions or cause limited data leakage. These risks have limited security impact, high attack complexity, and a moderate likelihood of exploitation. They require remediation during regular maintenance, typically within one month.
[0061] Low risk refers to security risks that may degrade the vehicle user experience but not affect normal vehicle functionality or could lead to the leakage of non-sensitive data. These risks have minimal security impact, high attack complexity, and a low likelihood of exploitation. Fixes can be scheduled as part of long-term maintenance plans or addressed through regular system updates.
[0062] The specific contents of the risk types are as follows: Identity authentication risk: refers to the security risks that exist in the vehicle or vehicle system during the user authentication process, such as weak password policies, lack of multi-factor authentication, improper session management, etc., which may lead to unauthorized access to the vehicle system.
[0063] Data transmission risk: refers to the security risks that exist in the vehicle data transmission process, such as unencrypted transmission channels, loopholes in transmission protocols, etc., which may cause data to be eavesdropped, tampered with or interrupted.
[0064] Data encryption risk: refers to encryption-related risks during the vehicle's data storage and processing process, such as encryption algorithm weaknesses and improper key management, which may lead to the cracking of encrypted data or the leakage of keys.
[0065] Authorized access risk: refers to the security risk of the vehicle system in resource access control, such as improper permission settings, unauthorized access vulnerabilities, etc., which may lead to unauthorized operations or resource abuse.
[0066] Software update risk: refers to security risks in the vehicle software update mechanism, such as insufficient integrity verification of update packages and lack of rollback mechanism, which may cause malware to invade the vehicle system through the update channel.
[0067] In addition to the above risk types, the security risk assessment report also includes the following risk types: Network communication risk: refers to the security risks during the communication between the vehicle and the external network, such as communication protocol vulnerabilities, improper network configuration, etc., which may lead to network attacks or communication hijacking.
[0068] System configuration risk: refers to security risks in the vehicle system configuration, such as insecure default configurations and enabling non-essential services, which may increase the system attack surface.
[0069] Physical security risks: refers to the security risks of the vehicle's physical interfaces and devices, such as unprotected diagnostic interfaces and improper management of removable storage media, which may lead to attacks through physical contact.
[0070] Supply chain security risks: refers to security risks from the vehicle parts and software supply chain, such as backdoors in components and vulnerabilities in third-party libraries, which may introduce additional security risks.
[0071] Privacy protection risk: refers to the risk of vehicles processing user privacy data, such as excessive data collection, failure to obtain clear authorization, etc., which may lead to user privacy leakage or violation of regulatory requirements.
[0072] Safety protection recommendations are specific safety reinforcement measures and best practices provided to automakers and operators based on identified safety risk points. The recommendations include: Technical security reinforcement suggestions: such as encryption algorithm upgrades, authentication mechanism enhancements, and firewall rule optimizations; Management-level security measures recommendations: such as security policy improvement, security response process optimization, and security audit requirements; Special solutions for specific risks: such as specialized repair solutions for certain communication protocol vulnerabilities; Industry security best practices reference: For example, refer to the successful security protection experience of similar products; Long-term security planning recommendations: such as security architecture improvement plans and security capability building plans.
[0073] In C2, the remediation plan based on the security risk assessment report mainly includes three aspects: Security patch updates: Develop and deploy security patches to address identified security vulnerabilities. Specific measures include: Critical system patches: Develop specialized security patches for security vulnerabilities in critical vehicle control systems; Communication protocol patches: address security flaws in vehicle communication protocols by updating protocol implementations or adding security mechanisms; Application software patches: Release application updates or patches to address security vulnerabilities in in-vehicle applications; Firmware Update: Release firmware security updates for security issues in ECU firmware.
[0074] Security policy adjustment: Adjust and optimize relevant policies based on system configuration and security policy issues. Specific measures include: Permission policy adjustment: Optimize the access permission settings of various components of the vehicle system and implement the principle of least privilege; Network isolation strategy: Adjust vehicle network partitioning and isolation strategies to reduce attack surfaces and risk propagation; Password policy optimization: Enhance password strength requirements and management policies to improve identity authentication security; Data processing strategy: Adjust data collection, storage and processing strategies to strengthen data security protection.
[0075] Enhanced security protection mechanism: To address the deficiencies in the overall security protection capabilities of the system, we will increase or strengthen the security protection mechanism. Specific measures include: Intrusion detection system: Deploy or upgrade vehicle-mounted intrusion detection systems to improve the ability to identify abnormal behavior; Security audit mechanism: Enhance the system security audit function to achieve comprehensive recording and traceability of key operations; Encryption mechanism upgrade: Upgrade data encryption algorithm and key management mechanism to improve data protection strength; Safety Monitoring Center: Establish or improve a safety monitoring center to centrally monitor vehicle safety status. The priority of remediation plans is typically determined based on risk level. Urgent risks require immediate remediation, high-risk areas are prioritized, and medium and low-risk areas can be incorporated into regular update plans.
[0076] In C3, the re-inspection of intelligent connected vehicles for which the repair plan has been implemented mainly includes the following steps: Repair verification test: Re-test the repaired security vulnerabilities to verify whether the repair is effective. Testing methods include: Vulnerability reproduction test: try to reproduce the original vulnerability to verify whether the vulnerability has been effectively fixed; Penetration testing: Conduct professional security penetration testing to verify the security of the repaired system; Functional verification testing: ensuring that repair measures do not affect the normal functions and performance of the system; Regression testing: Perform regression testing on the entire system to ensure that the repair measures do not introduce new problems.
[0077] Restoration effect evaluation: Comprehensive evaluation of the effects of restoration measures, including: Security improvement assessment: Evaluate the degree of improvement in system security after repair; Performance impact assessment: Evaluate the impact of repair measures on system performance; User experience impact assessment: Evaluate the impact of repair measures on user experience; Compliance assessment: Evaluate whether the repaired system complies with relevant safety standards and regulatory requirements.
[0078] Safety Risk Assessment Report Update: Based on the review results, the safety risk assessment report is updated, including: Repair status update: Update the repair status of each security risk point; Residual risk description: Description of the residual risks that may exist after repair; New suggestions provided: Provide suggestions for new issues found during the re-inspection process; Safety status summary: Summarize and evaluate the vehicle's current overall safety status.
[0079] The restoration effect verification adopts multiple evaluation criteria, including: Technical effectiveness: Evaluate whether the fix effectively solves the security issue technically; Coverage completeness: Evaluate whether the repair measures cover all identified security risk points; Implementation stability: assess whether the implementation of the remediation measures is stable and reliable, without introducing new problems; Long-term adaptability: Assess whether the restoration measures have long-term adaptability and can cope with environmental changes.
[0080] In an optional implementation, the security risk assessment report may also include a security maturity assessment section, using a maturity model similar to the BSIMM (Building Security In Maturity Model) to evaluate the maturity level of intelligent connected vehicle safety management from four dimensions: governance, intelligence, engineering, and verification, and provide automakers with systematic security capability improvement recommendations.
[0081] In another optional implementation, the safety risk assessment report can also include a safety trend analysis section. By analyzing historical safety assessment data over time, this section identifies safety risk trends and patterns of change, predicts emerging new security threats, and provides automakers with forward-looking safety protection recommendations. This approach not only focuses on current safety conditions but also future safety developments, offering greater foresight and guidance.
[0082] It should be noted that the safety risk assessment report is generated using a combination of templates and customization, ensuring a standardized report format while allowing for flexible adjustments to suit different vehicle models and assessment requirements. The report provides comprehensive safety assessment results from both technical and management perspectives, including detailed technical risk analysis and management-level safety recommendations to meet the needs of diverse user groups. Furthermore, the report utilizes risk visualization technology, visually displaying the distribution and severity of safety risks through charts and heat maps, enhancing its readability and practicality.
[0083] In the implementation of this application, the implementation process of security patch updates follows strict security practices, including the complete process of patch development, testing, verification, deployment, and monitoring. For critical security vulnerabilities, a multiple verification mechanism is used to ensure the effectiveness and reliability of the patch. At the same time, differentiated deployment strategies are formulated for different types of patch updates, such as forced OTA push of critical patches and release of non-critical patches through regular update channels to ensure the timeliness and applicability of security fixes.
[0084] Security policy adjustments are primarily implemented through the configuration management system, using a centralized policy management model to ensure consistency and traceability of policy adjustments. For key security policies such as permission policies and network isolation policies, pre-change simulations are conducted to ensure that policy adjustments will not adversely impact system operations. Furthermore, security policy adjustments utilize a risk-based decision-making approach, comprehensively considering multiple factors, including security improvements, operational performance impacts, and user experience changes.
[0085] Enhanced security mechanisms focus on improving the system's overall security capabilities. This is achieved through the introduction of new security technologies and products, or by upgrading existing security components. The selection and deployment of security mechanisms adhere to the principle of defense in depth, building a multi-layered, multi-dimensional security perimeter to effectively address various security threats. Furthermore, these enhanced security mechanisms prioritize compatibility and synergy with other vehicle systems, ensuring that overall system performance and user experience are not compromised while improving safety.
[0086] During the remediation verification phase, established security testing methods and processes are employed to ensure comprehensiveness and accuracy. The security testing environment remains consistent with the initial evaluation environment to ensure comparability of test results. For complex security risks, a combination of multiple testing methods is employed to verify the effectiveness of remediation from various perspectives. Furthermore, verification testing not only focuses on remediation of known security risks but also examines whether new security issues have been introduced, ensuring the comprehensiveness and effectiveness of remediation measures.
[0087] The remediation effectiveness assessment utilizes a combination of quantitative and qualitative methods, using safety metrics to quantitatively assess the security improvement effect, and qualitatively evaluating the user experience and overall security status through user feedback and expert review. The results are presented in a standardized report, providing a reference and basis for subsequent security work.
[0088] Security risk assessment reports are updated incrementally, focusing on changes in security status and residual risk analysis after remediation. Automated tools are used to assist in the report update process, improving efficiency and accuracy. Updated reports are reviewed and confirmed by a professional security team to ensure accuracy and professionalism. Report updates also include a summary and evaluation of the entire remediation process, providing valuable insights for subsequent security efforts.
[0089] In summary, the present invention achieves comprehensive monitoring of the multi-dimensional safety status of intelligent connected vehicles by constructing a comprehensive security test data collection system covering static and dynamic test environments; achieves accurate identification and assessment of potential safety risks by constructing a safety assessment model based on industry standards and historical data; achieves effective repair and management of identified safety risks by generating detailed safety risk assessment reports and formulating and implementing targeted repair plans based on the reports; and achieves comprehensive assessment and continuous optimization of safety repair effects by implementing post-repair re-inspection verification and report updates. This series of technical solutions together constitutes a set of systematic, intelligent, and standardized intelligent connected vehicle data and information security assessment methods, which effectively solves the problems existing in intelligent connected vehicle safety assessment, such as separate assessment, static rule construction, inconsistent risk classification, and low manual assessment efficiency, and provides strong support for the healthy development of the intelligent connected vehicle industry. Example
[0090] The above is a schematic diagram of a method for evaluating data and information security for intelligent connected vehicles. It should be noted that the technical solutions for this intelligent connected vehicle data and information security evaluation system and the technical solutions for the aforementioned intelligent connected vehicle data and information security evaluation method are based on the same concept. For details not described in detail in the technical solution for the intelligent connected vehicle data and information security evaluation system in this embodiment, please refer to the description of the technical solution for the aforementioned intelligent connected vehicle data and information security evaluation method.
[0091] This embodiment also provides a data and information security assessment system for intelligent connected vehicles, including: A security test data acquisition module is used to obtain security test data of intelligent connected vehicles, wherein the security test data includes at least wireless communication security data, vehicle network security data, vehicle application software security data, and information interaction security data; A safety risk analysis module, configured to analyze the safety test data using an intelligent connected vehicle safety assessment model to identify potential safety risk points; The security assessment report generation module is used to generate a security risk assessment report based on the identified security risk points, including risk level, risk type and security protection recommendations.
[0092] This embodiment also provides an electronic device suitable for intelligent connected vehicle data and information security assessment, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement the intelligent connected vehicle data and information security assessment method proposed in the above embodiment.
[0093] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the method for implementing the intelligent connected vehicle data and information security assessment proposed in the above embodiment is implemented.
[0094] The storage medium proposed in this embodiment and the method for implementing intelligent connected vehicle data and information security assessment proposed in the above embodiment belong to the same inventive concept. For technical details not fully described in this embodiment, please refer to the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.
[0095] From the above description of the embodiments, those skilled in the art will clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, can also be implemented using hardware. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This software product can be stored on a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk, or optical disk, and includes instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods of various embodiments of the present invention.
[0096] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A method for evaluating data and information security of intelligent connected vehicles, characterized by: include, Obtaining security test data of intelligent connected vehicles, the security test data including at least wireless communication security data, vehicle network security data, vehicle application software security data, and information interaction security data; Analyze the safety test data using an intelligent connected vehicle safety assessment model to identify potential safety risk points; Based on the identified security risk points, a security risk assessment report is generated, including risk level, risk type and security protection recommendations.
2. The intelligent connected vehicle data and information security assessment method according to claim 1, wherein: The safety test data includes data collected by intelligent connected vehicles in static test environments and dynamic test environments.
3. The intelligent connected vehicle data and information security assessment method according to claim 2, wherein: The static test environment includes a simulated computer network attack environment and a simulated physical security intrusion environment; the dynamic test environment includes an actual road driving environment and a simulated complex traffic scene environment.
4. The intelligent connected vehicle data and information security assessment method according to claim 3, wherein: The intelligent connected vehicle safety assessment model is constructed based on industry standard safety specifications and historical security incident data, and supports automatic identification of security vulnerabilities and automatic assessment of risk levels.
5. The intelligent connected vehicle data and information security assessment method according to claim 4, wherein: The risk levels in the security risk assessment report are divided into emergency risk, high risk, medium risk and low risk; the risk types include at least identity authentication risk, data transmission risk, data encryption risk, authorized access risk and software update risk.
6. The intelligent connected vehicle data and information security assessment method according to claim 5, wherein: It also includes the step of formulating a repair plan based on the security risk assessment report, and the repair plan includes security patch updates, security policy adjustments and security protection mechanism enhancements.
7. The intelligent connected vehicle data and information security assessment method according to claim 6, wherein: It also includes re-inspection steps for smart connected vehicles that have implemented repair plans, verifying the repair effects and updating the safety risk assessment report.
8. An intelligent connected vehicle data and information security assessment system, based on the intelligent connected vehicle data and information security assessment method according to any one of claims 1 to 7, characterized in that: It also includes a security test data acquisition module for obtaining security test data of the intelligent connected vehicle, wherein the security test data includes at least wireless communication security data, vehicle network security data, vehicle application software security data and information interaction security data; A safety risk analysis module, configured to analyze the safety test data using an intelligent connected vehicle safety assessment model to identify potential safety risk points; The security assessment report generation module is used to generate a security risk assessment report based on the identified security risk points, including risk level, risk type and security protection recommendations.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the intelligent connected vehicle data and information security assessment method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the intelligent connected vehicle data and information security assessment method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Automobile part data life cycle safety test system
CN120781366A