Data transmission security test method, device, medium and program product

By capturing the transmission data between devices and service platforms and generating simulated event data, specific events in real-world scenarios are automatically simulated, solving the problems of low test comprehensiveness and automation in existing technologies, and achieving more efficient data transmission security performance testing.

CN120512697BActive Publication Date: 2026-04-17BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TOPSEC NETWORK SECURITY TECH
Filing Date
2025-07-01
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies lack comprehensiveness and automation in testing the security performance of device data transmission, failing to effectively simulate real-world threats and scenarios, resulting in low testing efficiency.

Method used

By capturing the transmission data between the device under test and the service platform, simulated event data is generated and sent to the device to automatically simulate specific events in real-world usage scenarios, including tampering and replay attacks. The security test results are determined by combining the device's response status.

Benefits of technology

It improves the comprehensiveness and efficiency of equipment testing, ensuring the accuracy and coverage of testing, especially the data transmission security during OTA upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120512697B_ABST
    Figure CN120512697B_ABST
Patent Text Reader

Abstract

This application provides a data transmission security testing method, device, medium, and program product, relating to the field of security testing technology. The method includes: capturing transmission data between the device under test (DUT) and a service platform; generating simulated event data based on the transmission data; sending the simulated event data to the DUT; determining the response status of the DUT to the simulated event data; and determining the security test result of the DUT based on the response status. This application, by capturing transmission data between the device and the service platform and generating simulated event data, can automatically simulate specific events in real-world usage scenarios and test the device's response status, thereby effectively improving the comprehensiveness and efficiency of device testing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security testing technology, and more specifically, to a data transmission security testing method, device, medium, and program product. Background Technology

[0002] With the development of mobile communications and smart devices, OTA (Over-The-Air) upgrades have become a common method for remote firmware updates. Based on this technology, device manufacturers or service providers can push firmware updates to user devices via wireless networks to fix vulnerabilities, improve performance, and add new features. OTA upgrades have become a particularly important function in fields such as smartphones, embedded systems, and automotive electronics.

[0003] In pre-shipment testing scenarios, it is often necessary to test the data transmission security performance of the device under different business functions, such as testing the data transmission security performance of the device in OTA upgrade scenarios. Currently, the data transmission security performance testing of the device is limited to passive packet capture and static analysis, lacking the ability to actively simulate specific events, resulting in low test comprehensiveness; in addition, the high dependence on manual operation during the testing process leads to low automation and low testing efficiency. Summary of the Invention

[0004] The purpose of this application is to provide a data transmission security testing method, device, medium, and program product to improve the comprehensiveness and efficiency of testing the data transmission security performance of devices.

[0005] In a first aspect, embodiments of this application provide a data transmission security testing method, including:

[0006] Capture the transmission data between the device under test and the service platform;

[0007] Simulated event data is generated based on the transmitted data;

[0008] Send the simulated event data to the device under test;

[0009] Determine the response status of the device under test to the simulated event data;

[0010] The safety test result of the device under test is determined based on the response status.

[0011] In this embodiment of the application, by capturing the transmission data between the device and the service platform and generating simulated event data, it is possible to automatically simulate specific events in actual use scenarios and test the response status of the device, thereby effectively improving the comprehensiveness and efficiency of device testing.

[0012] In some possible embodiments, the device under test communicates with the service platform via a simulated base station;

[0013] The capture of data transmitted between the device under test and the service platform includes:

[0014] The data application unit of the simulated base station is used to capture the transmission data of the communication between the device under test and the service platform.

[0015] In this embodiment of the application, by using a simulated base station as the communication medium between the device under test and the service platform, the communication transmission data between the device under test and the service platform can be automatically captured by the data application unit based on the simulated base station, thereby further improving the accuracy of transmission security testing.

[0016] In some possible embodiments, sending the simulated event data to the device under test includes:

[0017] The simulated event data is imported into the simulated base station so that the simulated base station sends the simulated event data to the device under test.

[0018] In this embodiment of the application, by using a simulated base station to send simulated event data, it is possible to simulate specific events in a real transmission scenario and perform performance testing, thereby further improving the accuracy of transmission security testing.

[0019] In some possible embodiments, generating simulated event data based on the transmitted data includes:

[0020] The transmitted data is modified according to the preset data tampering test cases to obtain the corresponding simulated event data.

[0021] In this embodiment of the application, the response and security of the device are tested by simulating data tampering events, thereby further improving the comprehensiveness of data transmission security performance testing.

[0022] In some possible embodiments, generating simulated event data based on the transmitted data includes:

[0023] Based on the transmitted data, corresponding simulated event data is generated according to preset replay test cases.

[0024] In this embodiment of the application, the response and security of the device are tested by simulating the replay of attack events, thereby further improving the comprehensiveness of data transmission security performance testing.

[0025] In some possible embodiments, the transmitted data is the data required by the device under test during the execution of a preset OTA upgrade process.

[0026] In this embodiment of the application, by simulating the transmission data in the OTA upgrade scenario, the data transmission security during the OTA upgrade process can be accurately tested.

[0027] In some possible embodiments, determining the security test result of the device under test based on the response state includes:

[0028] Perform data initialization on the device under test;

[0029] The device under test is triggered to re-execute the preset OTA upgrade process;

[0030] Determine the second response state of the device under test when it re-executes the preset OTA upgrade process;

[0031] The safety test result of the device under test is determined based on the response state and the second response state.

[0032] In this embodiment of the application, after simulating data transmission testing, the data of the device under test is initialized and the normal OTA upgrade process is re-executed. The security test result is determined by comprehensively considering the response status of the simulated event test process and the normal test process, thereby further improving the accuracy of transmission security testing.

[0033] Secondly, embodiments of this application provide a data transmission security testing apparatus, comprising:

[0034] The data capture module is used to capture the transmission data between the device under test and the service platform;

[0035] The simulation generation module is used to generate simulated event data based on the transmitted data;

[0036] The data transmission module is used to send the simulated event data to the device under test;

[0037] The response determination module is used to determine the response status of the device under test in response to the simulated event data;

[0038] The result determination module is used to determine the safety test result of the device under test based on the response status.

[0039] Thirdly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the method described in any embodiment of the first aspect.

[0040] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.

[0041] Fifthly, embodiments of this application provide a computer program product, the computer program product including a computer program, wherein when the computer program is executed by a processor, it can implement the method described in any embodiment of the first aspect. Attached Figure Description

[0042] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0043] Figure 1 A flowchart illustrating a data transmission security testing method provided in this application embodiment;

[0044] Figure 2 This is a test topology diagram of the data transmission security testing method provided in the embodiments of this application;

[0045] Figure 3 This is a schematic diagram of the structure of a data transmission security testing device provided in an embodiment of this application;

[0046] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0047] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0048] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0049] It should be noted that smart devices or automotive systems undergo a variety of tests before leaving the factory. In addition to basic mechanical performance and electrical safety tests, functional and performance tests are often required. For example, data transmission security is tested, including the data transmission security during OTA (Over-The-Air) upgrades.

[0050] Currently, in data transmission security performance testing, traditional solutions are mainly based on preset fixed transmission scenarios. They capture data packets during transmission to perform basic security analysis on communication link status, encryption protocols, and sensitive information. Because these solutions only involve passive packet capture and static analysis, they cannot simulate real-world threats such as man-in-the-middle attacks and data tampering, resulting in limited testing comprehensiveness. Furthermore, the testing process is highly dependent on manual operation, with low automation, which impacts efficiency and fails to meet the rapidly evolving testing needs of connected vehicles.

[0051] To address the problems existing in the prior art, this application provides a data transmission security testing method that can not only effectively increase the coverage of test scenarios and improve the comprehensiveness of testing, but also improve the automation level of the testing process, thereby improving testing efficiency.

[0052] like Figure 1 As shown in the figure, this application provides a data transmission security testing method, which may include the following steps:

[0053] S1. Capture the transmission data between the device under test and the service platform.

[0054] The method in this application embodiment can be executed by an automated testing device, which can be a PC testing device, in which one or more testing tools can be deployed.

[0055] For example, by connecting automated testing equipment, the device under test, and the service platform to the same communication network, the devices can communicate with each other.

[0056] Based on this, the service platform and the device under test can perform data communication for specific functions, such as the service platform initiating / receiving instructions or requests with the device under test, the device under test downloading data from the service platform, and the device under test uploading data to the service platform.

[0057] For example, automated testing equipment can capture the data transmitted between the device under test and the service platform during the implementation of a certain communication function through a preset method, such as by accessing the data transmission and reception API interface of the device under test or the service platform.

[0058] For example, the captured transmission data can be PCAP packets. PCAP (Packet Capture) is a standard file format used to store captured network packets. It is widely used in network analysis, monitoring, and security, and is often generated by tools such as Wireshark (a network packet analysis software) and TCPDump (a network data acquisition and analysis tool). PCAP files record the raw data of network packets and their metadata (such as capture time and length), facilitating offline analysis.

[0059] It should be noted that automated testing equipment can capture transmitted data in series. This means the automated testing equipment can intercept the transmitted data between the device under test (DUT) and the service platform, and then control (or modify) the transmission and reception of this data. Alternatively, automated testing equipment can also capture transmitted data in parallel / bypass mode. Therefore, the process of the automated testing equipment capturing transmitted data does not affect the data transmission between the DUT and the service platform.

[0060] S2. Generate simulated event data based on transmitted data.

[0061] Based on the captured transmission data, automated testing equipment can generate corresponding simulated event data according to preset conversion rules. For example, simulated event data can be data that performs related operations on the transmission data, such as generating an event instruction set for illegally intercepting or attempting to crack the transmission data; or it can be secondary transmission data formed after modifying the transmission data.

[0062] S3. Send simulated event data to the device under test.

[0063] After generating simulated event data, the automated test equipment can send this simulated event data to the device under test.

[0064] For example, automated testing equipment can replace the original captured transmission data with simulated event data to send to the device under test; or it can keep the original transmission data transmission unaffected and send these simulated event data on top of that.

[0065] S4. Determine the response status of the device under test to the simulated event data.

[0066] For example, corresponding test items can be set for different simulated event data. After sending simulated event data to the device under test, the response status of the device under test to the simulated event data can be determined based on these test items.

[0067] For example, it is possible to test whether the device under test can identify the specific simulated event corresponding to the simulated event data; it is possible to test the device under test's performance in various aspects of data processing under the influence of simulated event data, such as transmission confidentiality, transmission efficiency, transmission duration, data integrity, and accuracy.

[0068] S5. Determine the safety test results of the device under test based on the response status.

[0069] For example, the security test results of the device under test can be determined based on its response status under different test items, and a corresponding test report can be generated.

[0070] For example, corresponding scoring rules and scoring contribution weights can be set according to the importance of different test items. Based on the response status of the device under test under different test items, the comprehensive score of the device under test is calculated in combination with the corresponding scoring rules and scoring contribution weights, and the safety test result of the device under test is determined accordingly.

[0071] It should be noted that the testing processes in the embodiments of this application can all be automatically executed through preset testing strategies, thereby effectively reducing manual intervention and improving testing efficiency and accuracy.

[0072] In this embodiment of the application, by capturing the transmission data between the device under test and the service platform during the implementation of functions, and generating simulated event data based on this data and sending it to the device under test, it is possible to automatically simulate specific events in actual use scenarios and test the device's response status, thereby effectively improving the comprehensiveness and efficiency of device testing.

[0073] In some possible embodiments, the device under test communicates with the service platform via a simulated base station;

[0074] Step S1, capturing the transmission data between the device under test and the service platform, may include:

[0075] S101. Using the data application unit of the simulated base station, capture the transmission data of the communication between the device under test and the service platform.

[0076] For example, the simulated base station can be the R&S-CMW500 (a comprehensive wireless communication tester). It is a test platform widely used in the research, development, certification, and production testing of wireless devices. It can simulate various wireless communication network environments and supports multiple communication standards, such as 2G, 3G, 4G, 5G, Wi-Fi, Bluetooth, etc.

[0077] It should be noted that by installing the CMW500 white card on the device under test (DUT), it can communicate with automated testing equipment and service platforms. The DUT and the service platform can communicate through a simulated base station (such as the CMW500). Based on this, the simulated base station can capture the transmission data of the communication between the DUT and the service platform through its Data Application Unit (DAU).

[0078] Understandably, the DAU module is a crucial component of the CMW500, specifically designed for data application testing. It captures and analyzes data packets (transmitted data) during communication between wireless devices (e.g., between the device under test and a service platform), supporting functions such as packet capture, analysis, replay, and tampering. By utilizing the CMW500's DAU module to capture and analyze messages during inter-device communication, security during transmission can be verified more effectively.

[0079] For example, the DAU module can capture all data packets sent and received by the wireless device during the OTA upgrade process, including control information, firmware data, etc. For example, by analyzing the captured messages (transmission data), the integrity and security of data transmission can be checked, such as checking the version of the SSL / TLS protocol, the key exchange process, and the use of encryption algorithms.

[0080] Based on this, by building a simulated base station to realize communication between the device under test and the service platform, the data application unit of the simulated base station can automatically capture the communication transmission data between the device under test and the service platform, thereby further improving the accuracy of transmission security testing.

[0081] In some possible embodiments, step S3, sending simulated event data to the device under test, may include:

[0082] S301. Import the simulated event data into the simulated base station so that the simulated base station can send the simulated event data to the device under test.

[0083] It should be noted that automated testing equipment can import data into a simulated base station, and then use the simulated base station to call relevant API interfaces to send simulated event data to the device under test.

[0084] For example, after the automated testing equipment generates simulated event data, it can transmit and import the simulated event data to the simulated base station via wired, wireless, Bluetooth or WIFI communication methods.

[0085] Based on this, by using simulated base stations to transmit simulated event data, it is possible to more conveniently and efficiently simulate specific events in real transmission scenarios and conduct performance tests, thereby further improving the accuracy of transmission security testing.

[0086] In some possible embodiments, step S2, generating simulated event data based on the transmitted data, may include:

[0087] S201. Modify the transmitted data according to the preset data tampering test cases to obtain the corresponding simulated event data.

[0088] It should be noted that after capturing the transmission data between the device under test (DUT) and the service platform, the transmitted data can be tampered with based on a preset data tampering test. By sending the tampered message (simulated event data) to the DUT, the DUT's ability to detect and process tampered data can be tested.

[0089] For example, based on preset data tampering test cases, the transmitted data can be tampered with by adding preset data content tampering methods to obtain modified data, which can then be used as simulated event data.

[0090] For example, based on preset data tampering test cases, the transmitted data can be tampered with by deleting content to obtain the modified data, which can then be used as simulated event data.

[0091] For example, based on preset data tampering test cases, parameters or content in the transmitted data can also be changed according to preset rules (the tampering method of changing parameters and content), such as modifying the content of data packets, encryption algorithm parameters, etc., to obtain the modified data as simulated event data.

[0092] It should be noted that for simulated event data generated by different data tampering test cases, the response status of the device under test can be tested and obtained separately, and corresponding security test results can be generated based on different response statuses.

[0093] For example, different data tampering test cases refer to test cases with different tampering types (addition, deletion, or modification), or they can refer to test cases of the same tampering type but with different degrees of tampering. For example, for the tampering method of adding (deleting) preset data content, different amounts of data content to add (delete) can be set for different data tampering test cases; for the tampering method of changing parameter content, different change rules can be set for different data tampering test cases.

[0094] Based on this, corresponding simulated event data is generated through preset test cases to simulate data tampering events in real-world scenarios, thereby testing the device's response and security, and further improving the comprehensiveness of data transmission security performance testing.

[0095] In some possible embodiments, step S2, generating simulated event data based on the transmitted data, may include:

[0096] S211. Based on the transmitted data, generate corresponding simulated event data according to the preset replay test cases.

[0097] It should be noted that replay attacks, also known as replay attacks or replay attacks, refer to an attacker sending a packet that the target device has already received in order to deceive the system. This is primarily used in the authentication process to compromise the integrity of the authentication. Replay attacks can be launched by the attacker or by an adversary that intercepts and retransmits the data.

[0098] Based on automated testing equipment or the simulated base station itself, it is possible to simulate replay attack events in real-world scenarios.

[0099] For example, based on the captured transmission data, one can choose to replay the unmodified transmission data directly, or replay it based on the tampered data. By resending the captured packets (transmission data) to the device under test, the device's ability to handle duplicate data packets and its security in the face of replay attacks can be tested.

[0100] For example, replaying network packets in PCAP format can reproduce faults or test device performance, supporting IPv4 / IPv6 protocol stacks and filtered replay. For example, the replay process can also be implemented using testing tools such as Wireshark.

[0101] It should be noted that before replaying the data, the entire PCAP file can be replayed, or specific packets can be selectively replayed. For example, if testing the client's sending function or simulating a client-initiated attack, selectively replaying the client's sent packets is more suitable; if testing the entire interaction process, including the service platform's response, a full replay is more appropriate. Additionally, the choice can be made based on the size of the PCAP file: if the PCAP file is determined to be larger than a preset threshold, a selective replay method can be used to improve efficiency. Furthermore, if the network environment is complex and subject to interference, a full replay method can be used to better simulate the real environment.

[0102] It should be noted that by utilizing the automated testing process of this application embodiment, more testing scenarios can be covered, including tests for tampering and replaying transmitted data, effectively improving the comprehensiveness of the test.

[0103] Based on this, by simulating and replaying attack events to test the device's response and security, the comprehensiveness of data transmission security performance testing is further improved.

[0104] In some possible embodiments, the transmitted data is the data required by the device under test during the execution of a preset OTA upgrade process.

[0105] like Figure 2As shown, the service platform is a platform used to provide OTA upgrade functionality to the device under test. The device under test communicates with the service platform (OTA upgrade platform) through an installed white card and can respond to preset trigger commands to execute preset OTA upgrade procedures.

[0106] By capturing the transmission data between the device under test and the service platform during the execution of a preset OTA upgrade process, the captured transmission data can be analyzed using preset scripts, Wireshark tools, or the packet replay software built into the CMW500. For example, security analysis can be performed on PCAP packets. For instance, test items may include verifying the security of data transmission during the OTA upgrade process, such as analyzing SSL / TLS versions, checking key exchange and authentication methods, and evaluating symmetric encryption algorithms and integrity protection algorithms.

[0107] It should be noted that traditional device testing solutions are not optimized for OTA upgrade scenarios and lack specific testing for key aspects such as firmware signature verification and integrity checks. This application's embodiments, by testing specifically for OTA upgrade scenarios, add dedicated testing items such as signature verification and integrity checks to achieve testing of security aspects such as anti-tampering and anti-counterfeiting of upgrade packages.

[0108] It is understood that the automated testing method of this application embodiment can ensure that the data transmission of the device under test during the OTA upgrade process is more secure and protect the user device from attacks.

[0109] Based on this, by simulating data transmission in OTA upgrade scenarios, we can accurately test the data transmission security during the OTA upgrade process.

[0110] In some possible embodiments, step S5, determining the security test result of the device under test based on the response status, may include:

[0111] S501. Initialize the data of the device under test;

[0112] S502, Triggers the device under test to re-execute the preset OTA upgrade process;

[0113] S503. Determine the second response state of the device under test when re-executing the preset OTA upgrade process;

[0114] S504. Determine the safety test results of the device under test based on the response status and the second response status.

[0115] It should be noted that after completing the process of testing the device under test (DUT) based on simulated event data, the DUT can be initialized, that is, restored to the state before step S1 (before data transmission with the service platform). Then, the DUT is triggered to re-execute the preset OTA upgrade process. During the re-execution of the preset OTA upgrade process, no simulated event data is generated, and no other influence is exerted on the DUT. The DUT is in the second response state of re-executing the preset OTA upgrade process (that is, the response state of the DUT during normal execution of the preset OTA upgrade process). Finally, the security test result of the DUT is determined by combining the response state and the second response state.

[0116] For example, the response state characterizes the security performance of the device under test under the influence of attack events such as data tampering and replay during the OTA upgrade process, while the second response state characterizes the security performance of the device under test under the condition that it is not affected by other factors during the OTA upgrade process. Thus, by comparing the difference in security performance between the two states, the security test result of the device under test can be determined.

[0117] Based on this, after simulating data transmission testing, the data of the device under test is initialized and the normal OTA upgrade process is re-executed. The security test results are determined by comprehensively considering the response status of the simulated event test process and the normal test process, thereby further improving the accuracy of transmission security testing.

[0118] Please refer to Figure 3 , Figure 3 A block diagram illustrating the composition of a data transmission security testing apparatus provided in some embodiments of this application is shown. It should be understood that this data transmission security testing apparatus is similar to the one described above. Figure 1 Corresponding to the method embodiments, it is able to perform each step involved in the above method embodiments. The specific functions of the data transmission security testing device can be found in the description above. To avoid repetition, detailed descriptions are appropriately omitted here.

[0119] Figure 3 The data transmission security testing device includes at least one software functional module that can be stored in a memory or embedded in the data transmission security testing device in the form of software or firmware. The data transmission security testing device includes:

[0120] The data capture module 310 is used to capture the transmission data between the device under test and the service platform;

[0121] Simulation generation module 320 is used to generate simulated event data based on transmitted data;

[0122] Data transmission module 330 is used to send simulated event data to the device under test;

[0123] The response determination module 340 is used to determine the response status of the device under test to simulated event data.

[0124] The result determination module 350 is used to determine the safety test results of the device under test based on the response status.

[0125] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention. The data transmission security testing device provided by the embodiments of the present invention can implement the data transmission security testing method provided by any one of the method embodiments of the present invention.

[0126] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.

[0127] like Figure 4 As shown, some embodiments of this application provide an electronic device 400, which includes: a memory 410, a processor 420, and a computer program stored in the memory 410 and executable on the processor 420. When the processor 420 reads the program from the memory 410 via a bus 430 and executes the program, it can implement any of the methods included in the above-described data transmission security testing method.

[0128] Processor 420 can process digital signals and may include various computing architectures. For example, it may be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 420 may be a microprocessor.

[0129] Memory 410 can be used to store instructions executed by processor 420 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all of the functions of one or more modules described in the embodiments of this application. The processor 420 of this disclosure embodiment can be used to execute instructions in memory 410 to implement the methods shown above. Memory 410 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.

[0130] Some embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, describes the method described in the method embodiments.

[0131] Some embodiments of this application also provide a computer program product that, when run on a computer, causes the computer to perform the methods described in the method embodiments.

[0132] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For apparatus embodiments, since they are basically similar to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0133] It should be understood, in the several embodiments provided in this application, that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0134] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0135] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0136] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0137] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0138] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method of testing the security of data transmission, characterized by, include: Capture the transmission data between the device under test and the service platform; Simulated event data is generated based on the transmitted data; wherein, the simulated event data includes a set of event instructions for illegally intercepting or attempting to crack the transmitted data; Send the simulated event data to the device under test; Determine the response status of the device under test to the simulated event data; The safety test result of the device under test is determined based on the response status. The generation of simulated event data based on the transmitted data includes: Based on the transmitted data, corresponding simulated event data is generated according to preset replay test cases; wherein, based on the captured transmitted data, unmodified transmitted data is selected for direct replay, or replay is performed based on tampered data.

2. The data transmission security test method according to claim 1, characterized by, The device under test communicates with the service platform via a simulated base station; The capture of data transmitted between the device under test and the service platform includes: The data application unit of the simulated base station is used to capture the transmission data of the communication between the device under test and the service platform.

3. The data transmission security test method according to claim 2, characterized in that, Sending the simulated event data to the device under test includes: The simulated event data is imported into the simulated base station so that the simulated base station sends the simulated event data to the device under test.

4. The data transmission security test method of claim 1, wherein, The generation of simulated event data based on the transmitted data includes: The transmitted data is modified according to the preset data tampering test cases to obtain the corresponding simulated event data.

5. The data transmission security test method of claim 1, wherein, The transmitted data is the data required by the device under test during the execution of the preset OTA upgrade process.

6. The data transmission security test method according to claim 5, characterized by, Determining the security test result of the device under test based on the response status includes: Perform data initialization on the device under test; The device under test is triggered to re-execute the preset OTA upgrade process; Determine the second response state of the device under test when it re-executes the preset OTA upgrade process; The safety test result of the device under test is determined based on the response state and the second response state.

7. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor, when executing the program, can implement the data transmission security testing method according to any one of claims 1-6.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, performs the data transmission security testing method as described in any one of claims 1-6.

9. A computer program product, characterised in that, The computer program product includes a computer program that, when executed by a processor, implements the data transmission security testing method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Intelligent networked automobile data security test system and method

    CN116545903A

  • Security test method and device for equipment

    CN117527442A