Vehicle intelligent communication terminal data testing method, device, medium and equipment

By scanning the internal ports of the vehicle's intelligent communication terminal to determine the testing dimensions and conducting multi-dimensional testing, the problem of low testing efficiency in existing technologies has been solved, achieving precise positioning and improving the testing efficiency for information security and data security.

CN121644401APending Publication Date: 2026-03-10CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-10
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing technologies make it difficult to conduct intelligent positioning analysis and testing of vehicle intelligent communication terminals, resulting in low efficiency in information security and data security testing and an inability to accurately pinpoint the source of problems.

Method used

By scanning the internal ports of smart communication terminals, test dimensions are determined, and based on the scan results, password penetration testing, login compliance testing, operating system testing, storage security testing, communication security testing, or data security testing are conducted to generate test reports.

Benefits of technology

It enables intelligent testing of vehicle intelligent communication terminals, improves testing positioning accuracy and efficiency, can quickly locate problems, and ensures information and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644401A_ABST
    Figure CN121644401A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent testing, and particularly provides a vehicle intelligent communication terminal data testing method and device, a medium and equipment, and the method can comprise the steps: scanning an internal port of an intelligent communication terminal, and obtaining a scanning result; based on the scanning result, determining a test dimension for testing the intelligent communication terminal; wherein the test dimension comprises a password penetration test, a login compliance test, an operating system test, a storage security test, a communication security test or a data security test; and testing at least one test item in the test dimension to obtain a test report of the intelligent communication terminal. According to the embodiment of the invention, intelligent testing of the vehicle intelligent communication terminal can be realized, and the testing efficiency is high.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of intelligent testing, in particular to a method and device for testing data of a vehicle intelligent communication terminal, a medium and equipment. BACKGROUND

[0002] The vehicle intelligent communication terminal is a control unit of the vehicle body networking, and undertakes the mission of monitoring and controlling the vehicle body state. As an online channel of the intelligent vehicle, the TSP (Telematics Service Provider) background and the third-party server, the information security and data security of the vehicle intelligent communication terminal are particularly important.

[0003] As an external communication interface of the whole vehicle, all data need to flow through the intelligent communication terminal. However, in most cases, the intelligent communication terminal is used as an online channel, and the connection initiation is generally initiated by the information controller. In the traditional vehicle data security test method, the whole vehicle is tested, that is, the data packets transmitted by the whole vehicle are analyzed. However, this test method cannot locate the problem source, and cannot realize intelligent positioning analysis test.

[0004] Therefore, how to provide a technical scheme of a vehicle intelligent communication terminal data test method with high intelligence degree becomes a technical problem to be solved. SUMMARY

[0005] Some embodiments of the present application aim to provide a method, device, medium and equipment for testing data of a vehicle intelligent communication terminal. Through the technical scheme of the embodiments of the present application, the vehicle intelligent communication terminal can be intelligently tested from multiple dimensions, and the test positioning accuracy and test efficiency are improved.

[0006] In a first aspect, some embodiments of the present application provide a method for testing data of a vehicle intelligent communication terminal, comprising: scanning an internal port of the intelligent communication terminal to obtain a scanning result; determining a test dimension for testing the intelligent communication terminal based on the scanning result; wherein the test dimension includes password penetration testing, login compliance testing, operating system testing, storage security testing, communication security testing or data security testing; testing at least one test item in the test dimension to obtain a test report of the intelligent communication terminal.

[0007] Some embodiments of the present application determine the test dimension of the intelligent communication terminal through the scanning result of the internal port of the intelligent communication terminal, and test the test items under the test dimension to obtain the test report. The embodiments of the present application can intelligently test the vehicle intelligent communication terminal from multiple optional dimensions, and improve the test positioning accuracy and test efficiency.

[0008] In some embodiments, the determining the test dimension for the intelligent communication terminal based on the scanning result comprises: when the scanning result indicates that the intelligent communication terminal has a debugging service, determining that all the test dimensions are used to test the intelligent communication terminal.

[0009] Some embodiments of the present application determine that all the test dimensions are used to test the intelligent communication terminal when the scanning result indicates that the intelligent communication terminal has a debugging service, so as to realize comprehensive intelligent testing of the intelligent communication terminal.

[0010] In some embodiments, the determining the test dimension for the intelligent communication terminal based on the scanning result comprises: when the scanning result indicates that the intelligent communication terminal has a debugging service, determining that all the test dimensions are used to test the intelligent communication terminal.

[0011] Some embodiments of the present application determine that all the test dimensions are used to test the intelligent communication terminal when the scanning result indicates that the intelligent communication terminal has a debugging service, so as to realize comprehensive intelligent testing of the intelligent communication terminal.

[0012] In some embodiments, the testing at least one test item in the test dimension and obtaining a test report of the intelligent communication terminal comprises: testing each test item under each test dimension to obtain a test result of each test item under each test dimension; and integrating the test results of each test item under each test dimension to obtain the test report.

[0013] Some embodiments of the present application test different test items under different test dimensions to obtain corresponding test results, integrate all the test results to obtain a test report, so as to realize comprehensive intelligent testing of the intelligent communication terminal and improve the positioning accuracy and efficiency of testing.

[0014] In some embodiments, when the test dimension is the data security test, the test item comprises a data collection switch test; and the testing at least one test item in the test dimension and obtaining a test report of the intelligent communication terminal comprises: after the data collection switch is turned off, obtaining data content sent to the cloud; obtaining a test result by confirming whether there is sensitive data in the data content; and generating the test report corresponding to the test result.

[0015] Some embodiments of the present application test the data content sent after the data collection switch is turned off to obtain a test result in the dimension of the data security test, and then generate a test report, so as to realize targeted testing of data security.

[0016] In some embodiments, the testing of each test item under each of the test dimensions comprises: when the test dimension is the password penetration test and the login compliance test, performing a penetration test on a password for logging into an operating system through a debugging service of the intelligent communication terminal to obtain a password test result; and performing a login operation on the operating system using correct login information and incorrect login information, and then obtaining a login test result by detecting security log content.

[0017] Some embodiments of the present application can obtain a password test result and a login test result through a password penetration test and a login compliance test, implement multi-dimensional testing, and improve testing comprehensiveness.

[0018] In some embodiments, the testing of each test item under each of the test dimensions comprises: when the test dimension is the operating system test, performing a scan on an Ethernet port to identify whether there is a specification undefined port to obtain a port test result; checking whether a target permission is enabled to obtain a permission test result; testing a system firewall configuration list to obtain a firewall test result; and detecting a working state of a security log to obtain a log test result.

[0019] Some embodiments of the present application can test each item inside an operating system from an operating system test dimension, facilitate positioning of a current problem, and improve testing positioning accuracy.

[0020] In some embodiments, the testing of each test item under each of the test dimensions comprises: when the test dimension is the storage security test, confirming that there is sensitive information; wherein the sensitive information comprises location information, communication key information, certificate information, password information, a vehicle Internet backend, or a network access address; and obtaining a storage test result by confirming whether the sensitive information is stored in an encrypted manner.

[0021] Some embodiments of the present application can ensure data security through testing from a storage security dimension to prevent data leakage.

[0022] In some embodiments, the testing of each test item under each of the test dimensions comprises: when the test dimension is the communication security test, detecting whether a backend connection uses a secure communication protocol to obtain a communication test result.

[0023] Some embodiments of the present application can ensure communication security and realize data safe transmission by testing from the communication security dimension.

[0024] In a second aspect, some embodiments of the present application provide a device for testing data of a vehicle intelligent communication terminal, comprising: a scanning module configured to scan internal ports of the intelligent communication terminal and obtain a scanning result; a determining module configured to determine a test dimension for testing the intelligent communication terminal based on the scanning result; wherein the test dimension comprises password penetration testing, login compliance testing, operating system testing, storage security testing, communication security testing or data security testing; and a testing module configured to test at least one test item in the test dimension and obtain a test report of the intelligent communication terminal.

[0025] In a third aspect, some embodiments of the present application provide a computer readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, can implement the method according to any one of the first aspect.

[0026] In a fourth aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the method according to any one of the first aspect.

[0027] In a fifth aspect, some embodiments of the present application provide a computer program product comprising a computer program, wherein the computer program, when executed by a processor, can implement the method according to any one of the first aspect. BRIEF DESCRIPTION OF DRAWINGS

[0028] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the following will briefly introduce the drawings needed to be used in some embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor.

[0029] Figure 1 One of the method flowcharts for testing data of a vehicle intelligent communication terminal provided by some embodiments of the present application; Figure 2 The second method flowchart for testing data of a vehicle intelligent communication terminal provided by some embodiments of the present application; Figure 3 The device composition block diagram for testing data of a vehicle intelligent communication terminal provided by some embodiments of the present application; Figure 4A schematic diagram of an electronic device provided for some embodiments of this application. Detailed Implementation

[0030] The technical solutions of some embodiments of this application will now be described with reference to the accompanying drawings.

[0031] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0032] In related technologies, vehicle intelligent communication terminals, serving as the internet access channel between intelligent vehicles and TSP backends and third-party servers, pose serious information and data security risks. Without necessary information security testing and protection, hackers could remotely control vehicles, steal owner information, and steal vehicle information through intelligent communication terminals. Without necessary data security testing and protection, vehicles could transmit data overseas, leak owner information, steal and analyze owner driving trajectories, or illegally collect owner information.

[0033] Existing testing methods have the following drawbacks: Data security testing targets the entire vehicle rather than individual components: analyzing data packets transmitted by the entire vehicle makes it difficult to pinpoint the source of problems. Since the intelligent communication terminal serves as the vehicle's external communication interface, all data must flow through it. However, in most cases, the intelligent communication terminal acts as an internet access channel, with connections typically initiated by the infotainment controller. Simply capturing data packets from the entire vehicle is insufficient to locate the problem. Information security testing focuses on operating system security, permission configuration, secure storage, and port scanning. Existing testing tools for these areas can be reused for data security testing, but separating information security and data security testing leads to significant testing redundancy. For example, information security requires logging non-security events in a security log and securely storing sensitive information. Data security requires log file sizes not to exceed 3GB, new security logs to overwrite old ones, and security logs to be retained for at least 6 months. These types of tests could be combined using the same testing tools; the current separate testing approach results in low testing efficiency, and there is a lack of comprehensive automated testing solutions.

[0034] In view of this, some embodiments of this application provide a method for testing data of a vehicle intelligent communication terminal. This method determines the testing dimensions of the intelligent communication terminal by scanning the internal ports of the intelligent communication terminal, and then tests the intelligent communication terminal based on these testing dimensions to obtain a test report. Embodiments of this application can achieve intelligent testing of intelligent communication terminals from multiple testing dimensions. By using multiple testing dimensions, existing problems can be quickly located, improving the accuracy and efficiency of test location.

[0035] The following is in conjunction with the appendix Figure 1 This application provides an exemplary embodiment of the implementation process of vehicle intelligent communication terminal data testing performed by a testing device. The testing device can establish a communication connection with the intelligent communication terminal to acquire relevant data information, thereby achieving accurate and effective testing of the intelligent communication terminal.

[0036] Please see the appendix Figure 1 , Figure 1 A flowchart illustrating a method for testing data from a vehicle intelligent communication terminal, provided for some embodiments of this application. This method for testing data from a vehicle intelligent communication terminal may include: S110 scans the internal ports of the intelligent communication terminal and obtains the scan results.

[0037] For example, in a specific embodiment of this application, after the data acquisition switch is turned on, an internal port scan is first performed using nmap (NetworkMapper) software, covering all IPs; the scan determines whether an SSH service (as a specific example of a debugging service) exists.

[0038] S120, based on the scan results, determine the test dimensions for testing the smart communication terminal; wherein, the test dimensions include password penetration testing, login compliance testing, operating system testing, storage security testing, communication security testing, or data security testing.

[0039] For example, in a specific embodiment of this application, the test dimensions for the smart communication terminal are determined by the scan results obtained above regarding whether SSH service exists.

[0040] In some embodiments of this application, S120 may include: when the scan result indicates that the smart communication terminal does not have a debugging service, determining the test dimension for testing the smart communication terminal as the data security test.

[0041] For example, in a specific embodiment of this application, if the scan results indicate that there is no SSH service, then only the smart communication terminal is subjected to data security testing.

[0042] In some embodiments of this application, S120 may include: when the scan result indicates that the smart communication terminal has a debugging service, determining to test the smart communication terminal using all the test dimensions.

[0043] For example, in a specific embodiment of this application, if the scan results indicate the presence of an SSH service, then the smart communication terminal is tested across all testing dimensions, namely, password penetration testing, login compliance testing, operating system testing, storage security testing, communication security testing, and data security testing. It is understood that the testing dimensions can be flexibly expanded according to actual needs, and the embodiments of this application are not limited thereto.

[0044] S130, perform tests on at least one test item in the test dimension and obtain a test report for the smart communication terminal.

[0045] For example, in a specific embodiment of this application, each test dimension may contain one or more different test items. By testing different test items, the final test report of the smart communication terminal is obtained.

[0046] In some embodiments of this application, S130 may include: S131, testing each test item under each test dimension in the test dimension to obtain the test results of each test item under each test dimension; S132, integrating the test results of each test item under each test dimension to obtain the test report.

[0047] For example, in a specific embodiment of this application, the intelligent communication terminal is tested for each test item under each test dimension, resulting in different test results. Finally, the test results are integrated to generate a test report. The test report clearly shows which test items are normal and which are abnormal, accurately locating problems in the test and improving test location efficiency.

[0048] In some embodiments of this application, when the testing dimension is data security testing, the test items include data acquisition switch testing; wherein, S130 may include: after turning off the data acquisition switch, acquiring the data content sent to the cloud; obtaining the test result by confirming whether there is sensitive data in the data content; and generating the test report corresponding to the test result.

[0049] For example, in a specific embodiment of this application, as can be seen from the above, data security testing is a necessary testing dimension regardless of the presence or absence of SSH service. To improve testing efficiency, information security and data security are merged in the data security testing process; that is, data security testing also includes related information security testing content. For example, data transmission, data storage, and data deletion in data security are combined with information security testing for secure communication transmission, secure storage, and secure operating systems. For example, data transmission requires the use of the TLSv1.3 protocol, and secure communication also requires the use of TLSv1.3; a single test can cover both requirements. These tests are all conducted with the data acquisition switch off. The specific testing process includes, after the data acquisition switch is off, cyclically triggering ECALL, security events, remote upgrades, and remote vehicle control scenarios, recording the log content generated during the triggering process. This log content can be generated during transmission, storage, or deletion. The test results are obtained by detecting the data content recorded in the log content that is transmitted or stored to the cloud. Specifically, if the data content includes sensitive personal data, the test result is abnormal; otherwise, it is normal. In the absence of SSH service, a test report is directly generated based on this test result. In cases where SSH service is included, this test result will be included as part of the test report.

[0050] In some embodiments of this application, S131 may include: when the test dimensions are the password penetration test and the login compliance test, performing a penetration test on the password of the smart communication terminal's debugging service login operating system to obtain the password test result; after performing the login operation of the operating system using correct login information and incorrect login information, obtaining the login test result by detecting the security log content.

[0051] For example, in a specific embodiment of this application, the operating system is logged in via SSH service, and the password policy, strength, and length of the SSH service are tested simultaneously (i.e., password penetration testing). The specific testing process includes: during password penetration testing, an attempt is made to brute-force the password. If it can be easily cracked, the password test result is low security strength; otherwise, the test result is high security strength. Then, a compliance test is performed on the login. Positive verification is performed using the provided correct account and password (as a specific example of correct login information), and attempts are made to log in using incorrect information (as a specific example of incorrect login information). The login test result is obtained by checking whether the security log records relevant content; if the security log accurately records all login cases, the login test result is normal; otherwise, an anomaly exists.

[0052] In some embodiments of this application, S131 may include: when the test dimension is the operating system test, scanning the Ethernet ports to identify whether there are undefined ports in the specification, and obtaining port test results; checking whether the system permissions have enabled the target permissions, and obtaining permission test results; testing the system firewall configuration list, and obtaining firewall test results; and detecting the working status of the security logs, and obtaining log test results.

[0053] For example, in a specific embodiment of this application, after entering the operating system, the Ethernet ports are scanned using netstat to identify whether there are any undefined ports in the specification. For example, by scanning, many ports are visible, and it is checked whether the ports are consistent with the specification definition. If they are consistent, the port test result is normal; otherwise, it is abnormal, and the port information of the undefined ports is listed. The permission test result is obtained by checking whether the system permissions are configured correctly (comparing the system permissions with the permissions that need to be enabled); for example, checking whether root permissions are used (i.e., root is the permission that needs to be enabled), etc. If root permissions are used, the permission test result is normal; otherwise, it is abnormal. The system firewall configuration is tested to see if it is correct; specifically, the whitelist and blacklist access lists are tested. If it is determined that it can correctly identify the contents of the whitelist and blacklist, the firewall test result is normal; otherwise, it is abnormal (for example, the firewall does not block a certain account in the blacklist). Test whether the system security log is turned off (as a specific example of the working state). Under normal circumstances, the system security log should record unexpected events, such as ECALL triggering, ECU upgrades, remote vehicle control, etc. In particular, it is necessary to record failure situations, such as the reason for OTA upgrade failure, non-whitelist access, etc., and the system security log should record events for more than 6 months. If it is in the turned-on state, the log test result is normal; if it is in the turned-off state, the log test result is abnormal.

[0054] In some embodiments of this application, S131 may include: when the test dimension is the storage security test, confirming the existence of sensitive information; wherein, the sensitive information includes location information, communication key information, certificate information, password information, vehicle network backend or network access address; and obtaining the storage test result by confirming whether the sensitive information is stored encrypted.

[0055] For example, in a specific embodiment of this application, the presence of sensitive information is first checked, such as the TSP backend (i.e., the vehicle network backend), APN address (i.e., the network access address), location data, vehicle owner information, communication key information, certificate information, password information, etc. If at least one of the above sensitive information exists, it is necessary to confirm whether the above sensitive information is stored encrypted. Encryption can be achieved through obfuscated storage or access authentication; if encrypted storage is used, the storage test result is secure; otherwise, it is insecure.

[0056] In some embodiments of this application, S131 may include: when the test dimension is the communication security test, obtaining the communication test result by detecting whether the background connection uses a secure communication protocol.

[0057] For example, in a specific embodiment of this application, the test backend connection is tested to see if a secure communication protocol is used; for example, whether ACP transmission uses TLCP, whether HTTPS transmission uses TLSv1.2, and whether a two-way authentication mechanism exists; if so, the communication test result is secure, otherwise it is insecure.

[0058] The following is in conjunction with the appendix Figure 2 The present application provides an exemplary description of the specific process for testing vehicle intelligent communication terminal data according to some embodiments.

[0059] Please see the appendix Figure 2 , Figure 2 A flowchart illustrating a method for testing data from a vehicle intelligent communication terminal, provided for some embodiments of this application.

[0060] The above process is illustrated below by example.

[0061] S210: Turn on the data acquisition switch and scan the internal ports of the smart communication terminal.

[0062] S220: Determine if a debugging service exists. If yes, execute S230; otherwise, execute S280.

[0063] S230 tests the smart communication terminal from the perspective of cryptographic penetration testing to obtain cryptographic test results.

[0064] S240 tests the smart communication terminal from the perspective of login compliance testing, and obtains the login test results.

[0065] S250 tests the smart communication terminal from the perspective of operating system testing, and obtains system test results.

[0066] The system test results include port test results, permission test results, firewall test results, and log test results.

[0067] S260 tests the smart communication terminal from the perspective of storage security testing and obtains the storage test results.

[0068] S270 tests the smart communication terminal from the perspective of communication security testing and obtains the communication test results.

[0069] S280 tests the smart communication terminal from the perspective of data security testing and obtains the test results.

[0070] S290, Based on the above test results, generate a test report for the intelligent communication terminal.

[0071] It is understood that the specific implementation process of S210~S290 can refer to the method embodiments provided above. To avoid repetition, detailed descriptions are appropriately omitted here. As can be seen from the above embodiments of this application, this application can effectively improve the testing efficiency of information security and data security, while also improving the efficiency of problem location and tracing.

[0072] Please refer to Figure 3 , Figure 3 This document illustrates a block diagram of an apparatus for testing vehicle intelligent communication terminal data, provided in some embodiments of this application. It should be understood that this apparatus corresponds to the method embodiments described above and is capable of performing the various steps involved in the method embodiments. The specific functions of this apparatus can be found in the description above; detailed descriptions are omitted here to avoid repetition.

[0073] Figure 3 The device for testing vehicle intelligent communication terminal data includes at least one software function module that can be stored in a memory or embedded in the device in the form of software or firmware. The device includes: a scanning module 310 for scanning the internal ports of the intelligent communication terminal and obtaining scan results; a determination module 320 for determining the test dimensions for testing the intelligent communication terminal based on the scan results; wherein the test dimensions include password penetration testing, login compliance testing, operating system testing, storage security testing, communication security testing, or data security testing; and a testing module 330 for testing at least one test item in the test dimensions and obtaining a test report for the intelligent communication terminal.

[0074] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.

[0075] Some embodiments of this application also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can perform the operation of any of the methods corresponding to the methods provided in the above embodiments.

[0076] Some embodiments of this application also provide a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the operation of any of the methods corresponding to the above embodiments provided in the above embodiments.

[0077] likeFigure 4 As shown, some embodiments of this application provide an electronic device 400, which includes a memory 410, a processor 420, and a computer program stored in the memory 410 and executable on the processor 420. When the processor 420 reads the program from the memory 410 via a bus 430 and executes the program, it can implement the methods of any of the above embodiments.

[0078] Processor 420 can process digital signals and may include various computing architectures. For example, it may be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 420 may be a microprocessor.

[0079] Memory 410 can be used to store instructions executed by processor 420 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all of the functions of one or more modules described in the embodiments of this application. The processor 420 of this disclosure embodiment can be used to execute instructions in memory 410 to implement the methods shown above. Memory 410 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.

[0080] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0081] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0082] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method for testing data of a vehicle intelligent communication terminal, characterized in that, The method comprises the following steps: scanning an internal port of an intelligent communication terminal to obtain a scanning result; determining a test dimension for testing the intelligent communication terminal based on the scanning result, wherein the test dimension comprises a password penetration test, a login compliance test, an operating system test, a storage security test, a communication security test, or a data security test; testing at least one test item in the test dimension to obtain a test report of the intelligent communication terminal.

2. The method of claim 1, wherein, The step of determining the test dimension for testing the intelligent communication terminal based on the scanning result comprises: when the scanning result indicates that the intelligent communication terminal has a debugging service, determining that all the test dimensions are used to test the intelligent communication terminal.

3. The method of claim 1, wherein, The step of determining the test dimension for testing the intelligent communication terminal based on the scanning result comprises: when the scanning result indicates that the intelligent communication terminal does not have a debugging service, determining that the data security test is the test dimension for testing the intelligent communication terminal.

4. The method of claim 1 or 2, wherein, The step of testing at least one test item in the test dimension to obtain a test report of the intelligent communication terminal comprises: testing each test item under each test dimension to obtain a test result of each test item under each test dimension; integrating the test results of each test item under each test dimension to obtain the test report.

5. The method of any one of claims 1-3, wherein, When the test dimension is the data security test, the test item comprises a data collection switch test, and the step of testing at least one test item in the test dimension to obtain a test report of the intelligent communication terminal comprises: after the data collection switch is turned off, obtaining data content sent to the cloud; obtaining a test result by confirming whether sensitive data exists in the data content; generating the test report corresponding to the test result.

6. The method of claim 4, wherein, The step of testing each test item under each test dimension to obtain a test result of each test item under each test dimension comprises: when the test dimension is the password penetration test and the login compliance test, penetrating the password of the operating system of the intelligent communication terminal through the debugging service to obtain a password test result; after correct login information and incorrect login information are used to perform a login operation on the operating system, obtaining a login test result by detecting security log content.

7. The method of claim 4, wherein, The step of testing each test item under each test dimension to obtain a test result of each test item under each test dimension comprises: when the test dimension is the operating system test, obtaining a port test result by scanning an Ethernet port to identify whether a specification undefined port exists; obtaining a permission test result by checking whether a target permission is enabled; obtaining a firewall test result by testing a system firewall configuration list; obtaining a log test result by detecting a working state of a security log.

8. The method of claim 4, wherein, The testing of each test item under each test dimension in the test dimension obtains a test result of each test item under each test dimension, and includes: When the test dimension is the storage security test, Confirming that there is sensitive information; wherein the sensitive information includes positioning information, communication key information, certificate information, password information, Internet of Vehicles background or network access address; By confirming whether the sensitive information is encrypted storage, a storage test result is obtained.

9. The method of claim 4, wherein, The testing of each test item under each test dimension in the test dimension obtains a test result of each test item under each test dimension, and includes: When the test dimension is the communication security test, By detecting whether the background connection uses a secure communication protocol, a communication test result is obtained.

10. A device for testing data from a vehicle intelligent communication terminal, characterized in that, It includes: The scanning module is configured to scan the internal port of the intelligent communication terminal and obtain a scanning result. The determining module is configured to determine a test dimension for testing the intelligent communication terminal based on the scanning result, wherein the test dimension includes password penetration testing, login compliance testing, operating system testing, storage security testing, communication security testing, or data security testing. The testing module is configured to test at least one test item in the test dimension and obtain a test report of the intelligent communication terminal.

11. A computer readable storage medium, characterized in that, The computer readable storage medium stores a computer program, wherein the computer program is run by the processor to execute the method of any one of claims 1-9.

12. An electronic device, comprising: It includes a memory, a processor, and a computer program stored on the memory and run on the processor, wherein the computer program is run by the processor to execute the method of any one of claims 1-9.