Extended security intrusion test system, method and equipment oriented to network and physical double spaces

The extended security intrusion testing system, which integrates a first processing unit, a second processing unit, and a modular bus, simplifies the structure of traditional security testing equipment, enables convenient multi-functional testing, solves the problem of cumbersome traditional equipment, and improves testing efficiency.

CN122069104APending Publication Date: 2026-05-19SHENZHEN FENGZHENG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN FENGZHENG TECHNOLOGY CO LTD
Filing Date
2026-04-02
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Traditional safety testing equipment is complex and cumbersome, requiring multiple devices to be used in conjunction, which makes it inconvenient to use.

Method used

An extended security intrusion testing system oriented towards both network and physical spaces is adopted, including a first processing unit, a second processing unit, and a modular bus. It achieves pluggable connection through a high-speed virtual channel and integrates functional sub-modules such as radio frequency module, broadband SDR module, and Ethernet PoE module. It uses an AI intelligent agent module to parse natural language instructions and generate execution plan instructions to drive the functional sub-modules to work, and perform signal acquisition and calculation processing.

Benefits of technology

The simplified test equipment structure reduced the number of portable devices, improved operational convenience, and enabled rapid replacement and efficient test result generation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122069104A_ABST
    Figure CN122069104A_ABST
Patent Text Reader

Abstract

The invention discloses an extended security intrusion test system, method and equipment for network physical double spaces. The test system comprises a first processing unit, a second processing unit and a modular bus, the first processing unit and the second processing unit are connected through a modular bus; the first processing unit is configured to receive a task execution instruction and generate an execution plan instruction according to the task execution instruction; the second processing unit is configured to respond to the execution plan instruction to drive the function sub-module to work and receive an acquisition signal fed back by the function sub-module; the first processing unit is further configured to collect signals and perform calculation processing according to the corresponding model based on the execution plan instruction to obtain a test result. According to the technology, a dual-mode structure of the first processing unit and the second processing unit is adopted, calculation and front-end data collection functions are integrated, and the problem that a traditional testing device is isolated and tedious in structure is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an extended security intrusion testing system, method and device for both network and physical spaces. Background Technology

[0002] Cybersecurity and information security have become unavoidable issues in today's information society. To ensure that various application systems can withstand risks and protect information security and safe operation during actual operation, it is necessary to conduct security testing on these systems. Furthermore, according to the provisions of A.8.28 (Managing Security Testing) and A.8.8 (Managing Technical Vulnerabilities) of the "Information Security, Cybersecurity and Privacy Protection—Information Security Management System—Requirements," it is necessary to test these application systems through penetration testing.

[0003] These application systems typically include, but are not limited to, access control systems, smart homes, emergency response systems, industrial control systems, IoT device development systems, and radio education and testing systems.

[0004] Traditional security testing equipment typically requires a laptop and corresponding external tools. For example, testing an access control system requires a laptop and an RFID instrument. If testing different scenarios simultaneously, such as adapting to radio frequency, hardware interface, or network attack scenarios, additional equipment such as Flipper Zero, USB Rubber Ducky, SDR receivers, and Wi-Fi hacking devices are needed. Therefore, existing equipment is complex and cumbersome, making it inconvenient for security monitoring.

[0005] Therefore, the aforementioned technical problems need to be solved. Summary of the Invention

[0006] The main objective of this invention is to provide an extended security intrusion testing system, method, and device for both network and physical spaces, aiming to optimize the existing testing equipment structure and make it more convenient to use.

[0007] To achieve the above objectives, one aspect of the present invention proposes an extended security intrusion testing system oriented towards both network and physical spaces, comprising: An extended security intrusion testing system for both network and physical spaces includes: The system comprises a first processing unit, a second processing unit, a modular bus, and functional sub-modules. The first processing unit and the second processing unit are connected via the modular bus; The functional submodule is selectively connected to the first processing unit or the second processing unit and is used to interact with the system under test to acquire the collected signals; The first processing unit is configured to: receive an execution task instruction, generate an execution plan instruction based on the execution task instruction, and transmit the execution plan instruction to the second processing unit via the modular bus; The second processing unit is configured to: respond to the execution plan instruction to drive at least one functional submodule to work, and receive the acquisition signal fed back by the functional submodule; The first processing unit is further configured to: receive the acquisition signal transmitted by the second processing unit and perform calculation processing based on the execution plan instruction according to a preset model to obtain test results.

[0008] Furthermore, the first processing unit and the second processing unit are pluggably connected via the high-speed virtual channel of the modular bus, specifically including: The first processing unit and the second processing unit establish a physical connection through the high-speed board-to-board connector of the modular bus; The second processing unit encapsulates the acquired signal according to a custom frame format to generate a data frame; The first processing unit runs the kernel driver module, receives the data frame, parses the received data frame, and maps it to the standard device of the operating system.

[0009] Furthermore, the modular bus uses a UART interface or an SPI interface to connect the first processing unit and the second processing unit.

[0010] Furthermore, the custom frame format includes a frame header field, a command code field, a data field, and a check field, wherein the command code field is used to identify the operation type of the functional submodule corresponding to the data frame; The first processing unit runs the kernel driver module, receives the data frame, parses the received data frame, and maps it to the standard device of the operating system, specifically as follows: The first processing unit runs the kernel driver module, receives the data frame and parses the received data frame, extracts the command code field and data field, and maps the content of the data field to the standard device of the operating system according to the command code field.

[0011] Furthermore, the functional sub-modules include at least one of the following: radio frequency module, wideband SDR module, Ethernet PoE module, Bluetooth sniffing module, NFC module, RFID module, Bluetooth module, WIFI module, and infrared recognition module.

[0012] Furthermore, the first processing unit is configured to either have a built-in AI agent module or communicate and interact with an AI agent module in the cloud. The AI ​​agent modules located in the first processing unit or the cloud all have: The natural language parsing module is configured to receive execution task instructions in natural language form and separate them into structured information; The vector retrieval module is configured to retrieve online or offline knowledge base content based on the structured information to match task plan instructions; Inference module: Configured to infer specific task plan instructions from structured information; Command execution module: It is configured to transmit task plan instructions to the second processing unit, receive the acquisition signals from the second processing unit, select a preset model to execute or execute directly in the device according to the acquisition signals, perform result acceptance and feedback, and update the task ranking in the knowledge base.

[0013] Furthermore, the AI ​​agent module is configured to perform an extended collaboration step, which is specifically as follows: The acquired user instructions are parsed, an execution plan instruction containing at least one execution step is generated, and the execution plan instruction is sent to the second processing unit; The second processing unit responds to the execution plan instruction by scheduling the corresponding functional sub-module to perform the corresponding functional operation and returns the test result; If the current test result does not meet the expected result, other extended hardware modules connected to the modular bus are invoked to perform low-level signal analysis, or an updated processing strategy is obtained from the cloud to regenerate a new execution plan instruction to retry the test.

[0014] Furthermore, the execution plan instructions include at least two types of instructions for controlling different functional sub-modules.

[0015] Another aspect of the present invention proposes a network-physical dual-space extended security intrusion testing method, which includes the following steps: Obtain the user's task execution instructions; The first processing unit generates an execution plan instruction based on the execution task instruction; The first processing unit transmits the execution plan instruction to the second processing unit through the high-speed board-to-board connector; The second processing unit responds to the execution plan instruction to drive at least one functional sub-module to work and receives the acquisition signal fed back by the functional sub-module; The second processing unit transmits the acquired signal to the first processing unit through a high-speed board-to-board connector. The first processing unit performs calculations based on the acquired signals and the execution plan instructions according to a preset model to obtain test results.

[0016] Finally, this invention proposes an extended detection device for both network and physical spaces, including a device motherboard, on which any of the aforementioned extended security intrusion testing systems for both network and physical spaces are installed.

[0017] The beneficial effects that this invention can achieve are: This invention proposes an extended security intrusion testing system, method, and device for both network and physical spaces. The testing system includes a first processing unit, a second processing unit, and a modular bus. The first and second processing units are connected via a high-speed virtual channel on the modular bus. The first processing unit is configured to: receive execution task instructions, generate execution plan instructions based on the execution task instructions, and transmit the execution plan instructions to the second processing unit via the high-speed virtual channel. The second processing unit is configured to: respond to the execution plan instructions to drive at least one functional sub-module and receive acquisition signals fed back by the functional sub-module. The first processing unit is further configured to: receive the acquisition signals transmitted by the second processing unit and perform calculations based on the execution plan instructions and a corresponding model to obtain test results. This technology integrates computation and front-end data collection functions through a dual-mode structure of the first and second processing units, solving the problem of isolated and cumbersome structures in traditional testing equipment, and enabling rapid replacement through pluggable connections. Attached Figure Description

[0018] Figure 1 A schematic diagram of the hardware architecture of an extended security intrusion testing system; Figure 2 This is a schematic diagram illustrating the principle of an extended security intrusion testing method. Detailed Implementation

[0019] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0020] As described in the background section, in existing technologies, security testing typically requires a separate computer and corresponding data acquisition instruments. When testing multiple different systems or different modules of the same system simultaneously, even more data acquisition is often needed. This makes it very inconvenient for users.

[0021] Reference Figures 1-2This invention proposes an extended security intrusion testing system for both network and physical spaces. The core of this system is to construct a dual-master architecture by using a first processing unit and a second processing unit. This allows the first processing unit to focus on computation, while the second processing unit is responsible for physical interaction and front-end signal processing. This optimizes the entire testing process and also optimizes the structure, eliminating the need to carry large computers and additional specialized instruments and equipment. This simplifies the entire operation and reduces the workload for users.

[0022] Detailed, such as Figure 1 The security intrusion testing system shown includes a first processing unit 100, a second processing unit 200, and a modular bus 300; the first processing unit 100 and the second processing unit 200 are connected through the modular bus 300 to achieve data and information interaction. Specifically, in one embodiment, the first processing unit 100 and the second processing unit 200 are pluggably connected through a high-speed virtual channel of the modular bus 300.

[0023] In this embodiment, the first processing unit 100 is configured as a general-purpose operating system, serving as the core decision-making and intelligent hub of the entire security testing system. The first processing unit 100 is, for example, an RK3588 processor. The second processing unit 200 runs a real-time operating system, primarily responsible for interaction with external devices and front-end signal processing. The second processing unit 200 is, for example, an STM32 processor. It should be understood that the models of the first processing unit 100 and the second processing unit 200 are not limited to these; different configurations can be applied, and simple model replacement techniques should also fall within the protection scope of this invention.

[0024] Both the first processing unit 100 and the second processing unit 200 are mounted on a single PCB motherboard. This PCB motherboard preferentially integrates at least one of the following: a radio frequency (RF) module, a wideband SDR module, an Ethernet PoE module, and a Bluetooth sniffing module. The RF module, wideband SDR module, Ethernet PoE module, and Bluetooth sniffing module can be connected to the first processing unit 100 via the modular bus 300. Specifically, in this embodiment, the PCB motherboard integrates at least an RF module and a wideband SDR module. For example, the RF module in this embodiment uses a C1101 chip to acquire RF signals. This embodiment also includes an NFC module, an RFID module, a Bluetooth module, a WIFI module, and an infrared recognition module. These modules are integrated on the motherboard and communicate with the second processing unit 200 to achieve data interaction. That is, the functional sub-modules are selectively connected to either the first processing unit or the second processing unit. Specifically, some functional sub-modules can be connected to the first processing unit 100, and some of the first processing unit can be connected to the second processing unit 200.

[0025] In one embodiment, the NFC module, RFID module, Bluetooth module, WIFI module, and infrared recognition module constitute a functional submodule of the second processing unit 200. The functional submodule includes at least one of the following: NFC module, RFID module, Bluetooth module, WIFI module, and infrared recognition module.

[0026] In other words, the RF module, broadband SDR module, Ethernet PoE module, Bluetooth sniffing module, NFC module, RFID module, Bluetooth module, WIFI module, and infrared recognition module are integrated on the PCB motherboard, eliminating the need for additional instruments to achieve the corresponding functions as in traditional testing technologies. The entire security testing system integrates the functions of a traditional computer and various external acquisition instruments. This achieves an integrated layout, simplifying the structure of traditional security testing equipment and facilitating user operation through the integrated design of the first processing unit 100, the second processing unit 200, and various functional sub-modules.

[0027] It should also be noted that in this technical solution, the first processing unit 100, the second processing unit 200, the modular bus 300, and various functional sub-modules can be integrated on the same motherboard, or they can be integrated on different motherboards according to different needs. The different motherboards can be arranged in a stacked manner with alternating vertical layers. For example, the first processing unit 100 and the second processing unit 200 can be concentrated on the same motherboard, while other functional modules can be integrated on other motherboards. This is beneficial for heat dissipation and also helps to mitigate the impact of various frequencies and signals on the first processing unit 100 and the second processing unit 200.

[0028] Specifically, the first processing unit is configured to: receive an execution task instruction, generate an execution plan instruction based on the execution task instruction, and transmit the execution plan instruction to the second processing unit via the modular bus; the second processing unit is configured to: respond to the execution plan instruction to drive at least one functional sub-module to work, and receive the acquisition signal fed back by the functional sub-module; the first processing unit is further configured to: receive the acquisition signal transmitted by the second processing unit and perform calculation processing based on the execution plan instruction according to a preset model to obtain test results.

[0029] This embodiment proposes a security testing method to meet the operational mechanism of the extended security intrusion testing system oriented towards both network and physical spaces.

[0030] The first processing unit 100 acts as the central hub, enabling interaction with the user and acquiring corresponding requests to control the operation of the entire security intrusion testing system.

[0031] In detail, the first processing unit 100 is capable of accepting and executing task instructions. Specifically, the first processing unit 100 can interact with the user through an input port. This input port can be, for example, a voice recognition module or a keypad module. The keypad module can be, for example, a touchscreen or a keyboard. In actual operation, a specific task instruction is input through the input port, such as "crash this RFID access card". After receiving the task instruction, the first processing unit 100 generates an execution plan instruction.

[0032] The first processing unit is configured to either have a built-in AI agent module or communicate with an AI agent module in the cloud. The AI ​​agent module located in the first processing unit or in the cloud typically includes: a natural language parsing module configured to receive task execution instructions in natural language form and separate them into structured information; a vector retrieval module configured to retrieve online or offline knowledge base content based on the structured information to match the task plan instructions; a reasoning module configured to reason about specific task plan instructions based on the structured information; and a command execution module configured to transmit the task plan instructions to the second processing unit, receive acquisition signals from the second processing unit, select a preset model for execution based on the acquisition signals, or execute directly on the device, perform result acceptance and feedback, and update the task ranking in the knowledge base.

[0033] In this technical solution, the AI ​​agent module can be located in the first processing unit or on a cloud server. When located in the first processing unit, it can be executed locally. When located on a cloud server, the first processing unit 100 interacts with the cloud server through a communication module to implement the AI ​​function. Specifically, whether the AI ​​agent module is located in the first processing unit 100 or on the cloud server, it has the same function.

[0034] The natural language parsing module of this AI agent is a lightweight large language model for parsing natural language. Specifically, this lightweight large language model can be implemented using existing language parsing techniques.

[0035] The vector retrieval module is used to search the pre-stored knowledge base to screen the structured information obtained by the natural language parsing module and obtain a task instruction. This technical solution reduces subsequent inference execution, thus improving processing efficiency. Generally, the knowledge base pre-stores different instructions and their corresponding execution plan instructions. For example, if the task instruction is "check access control," then "check access control" corresponds to a specific execution plan instruction to control different functional sub-modules, such as controlling the RFID module and the NFC module. Of course, the knowledge base also stores test result data after each execution test to enrich the knowledge base. If a task instruction to crack an access control card has been pre-stored or executed before, the execution plan instruction for cracking the access control card will be remembered and stored in the knowledge base. When the AI ​​agent module recognizes the same or similar natural language instruction as "cracking the access control card," it directly calls the execution plan instruction corresponding to that "cracking the access control card."

[0036] The inference module is configured to infer specific task plan instructions from structured information. That is, it infers executable task plan instructions from structured information for the command execution module to transmit to the second processing unit 200 for execution.

[0037] After receiving the task plan instruction from the vector retrieval module or the inference module, the command execution module transmits it to the second processing unit. The second processing unit 200 executes the corresponding instruction and calls the corresponding functional submodules to complete the interaction with the system under test. After acquiring the collected signal, the second processing unit 200 feeds it back to the first processing unit 100, where the command execution module selects a preset model to execute or executes it directly in the device. Finally, the command execution module performs result acceptance and feedback, and updates the task ranking in the knowledge base.

[0038] In other words, the AI ​​agent module of the first processing unit 100 is used to recognize the user's natural language commands and form execution plan commands for the second processing unit 200 to execute. For example, if it is necessary to "break into the access control card system", then the command will be recognized by the AI ​​agent module and a specific functional sub-module for interacting with the access control card system will be generated. This functional sub-module for interacting with the access control card system will be controlled and executed by the second processing unit 200.

[0039] The execution plan instruction obtained after being parsed by the AI ​​intelligent agent module will be transmitted to the second processing unit 200 via the modular bus 300. Upon receiving the execution plan instruction, the second processing unit 200 will control the corresponding functional sub-modules to obtain the corresponding acquisition signals. For example, if the corresponding execution plan instruction is "crash the access card," then the second processing unit 200 will call the corresponding RFID module to interact with the access card system and obtain its acquisition signals. If the corresponding execution plan instruction is "crash the wireless network connection," the second processing unit 200 will call the SDR module to scan the corresponding frequency band and identify the SSID, encryption method, and signal strength of all APs. This information will be transmitted to the first processing unit 100 via the high-speed virtual channel of the modular bus 200.

[0040] It should be noted that in this embodiment, the first processing unit 100 and the second processing unit 200 can achieve fast data transmission and interaction. Specifically, the first processing unit and the second processing unit are physically connected through the high-speed virtual channel of the modular bus 300 to meet high-speed data transmission needs.

[0041] Specifically, the modular bus 300 has a high-speed board-to-board connector that physically connects the first processing unit 100 and the second processing unit 200. More specifically, the high-speed board-to-board connector has a corresponding low-level hardware interface for an analog Bluetooth protocol stack; this interface can be a UART interface or an SPI interface. The high-speed board-to-board connector runs a high-speed serial communication protocol. Specifically, taking the UART interface as an example, this UART interface is virtualized as a high-speed, full-duplex virtual Bluetooth or virtual serial port channel, i.e., the high-speed virtual channel. In addition, the high-speed board-to-board connector integrates an integrated USB 3.0 interface, a PCIe Lane interface, a GPIO interface, and a power interface.

[0042] In detail, the specific implementation method for the first processing unit and the second processing unit to establish a physical connection through the high-speed board-to-board connector of the modular bus is as follows: The second processing unit encapsulates the acquired signal according to a custom frame format to generate a data frame; The first processing unit runs the kernel driver module, receives the data frame, parses the received data frame, and maps it to the standard device of the operating system.

[0043] The custom frame format includes a frame header field, a command code field, a data field, and a check field. The command code field is used to identify the operation type of the functional sub-module corresponding to the data frame. Specifically, the first processing unit runs a kernel driver module, receives the data frame, parses the received data frame, and maps it to the standard device of the operating system. The first processing unit runs the kernel driver module, receives the data frame and parses the received data frame, extracts the command code field and data field, and maps the content of the data field to the standard device of the operating system according to the command code field.

[0044] This approach enables actual data transfer rates to reach the USB 2.0 Full-Speed ​​(12 Mbps) level.

[0045] To better illustrate the data processing process of this high-speed transmission channel, the first processing unit 100 of model RK3588 and the second processing unit 200 of model STM32WB55RG are used as examples to explain the radio frequency signal processing.

[0046] Data encapsulation and transmission standards of the second processing unit 200: The second processing unit 200 has a custom frame structure. After the STM32WB55RG obtains the RF data from the functional submodule (RF) through its ARM Cortex-M4 core, it encapsulates it into a unified binary frame, with the following format: [Frame Header 0xAA][Length 1 byte][Command Code 1 byte][Data Field N bytes][CRC16 Checksum 2 bytes] Command codes define hardware operation types (e.g., 0x01 indicates GPIO control, 0x02 indicates RF signal transmission). The data field is dynamically adjusted according to the protocol. For example, a GPIO control frame contains a triplet of [pin number], [level state], and [delay in milliseconds]. The second processing unit 200 (STM32WB55RG) communicates with the first processing unit (RK3588) via a hardware SPI interface or USB CDC serial port protocol, with a clock frequency configured to 20MHz to ensure real-time performance.

[0047] Parsing and mapping of the first processing unit 100 (RK3588): Kernel driver loading The first processing unit 100 (RK3588) comes pre-installed with a dynamic kernel module (DKO) on its Android / Linux system. This dynamic kernel module has a registered character device / dev / interceptx and implements the ioctl interface to process custom frames sent from the STM32.

[0048] The specific analysis process is as follows: / / The example driver code snippet can be described as follows: case CMD_GPIO_CTRL: parse_gpio_frame(data, &pin, &state); gpiod_set_value(gpio_map[pin], state); / / Map to Linux GPIO subsystem Standard device mapping: Convert the physical pin numbers of the second processing unit 200 (STM32WB55RG) to Linux GPIO numbers (defined via the device tree gpio-map attribute). Virtual device creation: After parsing the radio frequency signal, the / dev / rf0 device file is generated for use by user-level tools (such as rfcat).

[0049] The above embodiments illustrate the data frame processing process for high-speed signal transmission between the first processing unit 100 and the second processing unit 200. In other words, this technical solution enables rapid data transmission between the first processing unit 100 and the second processing unit 200, with the second processing unit 200 performing front-end data acquisition and the first processing unit 100 performing centralized calculations.

[0050] In other words, in the above example, the corresponding modular bus 300 will upload information such as the SSID, encryption method and signal strength of all APs to the first processing unit 100 in the form of a data frame structure. The first processing unit 100 will simultaneously parse the data of the corresponding standard device, that is, obtain the information that the access card needs to be cracked.

[0051] Upon receiving the corresponding acquisition signal, the first processing unit is further configured to perform calculations based on the execution plan instructions and the corresponding model to obtain test results. Specifically, the AI ​​agent of the first processing unit 100 will perform calculations based on the corresponding model to obtain test results. It should be noted that the specific calculation model is pre-stored, and the AI ​​agent will perform calculations based on the acquisition data from the corresponding target device to obtain the corresponding test results. These test results may, for example, be a visual report. The calculation model can be implemented using existing cracking models.

[0052] It should be noted that in this embodiment, all calculations performed by the AI ​​agent module are completed on the NPU of the first processing unit 100 and saved locally, and are not uploaded to the cloud. This avoids transmitting sensitive data to the cloud and ensures data security.

[0053] The technical solution of this invention enables the input of task execution instructions in the form of natural language. Upon receiving the task execution instruction, the first processing unit 100 parses it to obtain an execution plan instruction, which is then sent to the second processing unit 200. The second processing unit 200 calls specific functional sub-modules and obtains acquisition signals according to the execution plan instruction. These acquisition signals are transmitted to the first processing unit 100 through the high-speed virtual channel of the modular bus 300. The first processing unit 100 runs the corresponding model based on the corresponding acquisition signals of the target device to obtain test results. This technology integrates functions such as instruction input, instruction parsing, instruction execution, data acquisition, and model calculation, solving the problem of complex and redundant structures in traditional testing systems and greatly meeting the needs of society.

[0054] The following will illustrate this with several real-world test examples: Scenario 1: "Detecting Wi-Fi security vulnerabilities in the current room" AI Agent Module Analysis and Action Sequence: The system uses the SDR module to scan the 2.4GHz / 5GHz bands, identifying the SSID, encryption method, and signal strength of all access points (APs). It automatically matches the Kali toolchain (e.g., airodump-ng to capture handshake packets, hcxdumptool to detect WPS vulnerabilities). If a weakly encrypted WPA2 AP is found, a dictionary attack is initiated (hashcat uses the RK3588's NPU to accelerate the cracking process). A visual report is generated within 10 minutes, highlighting high-risk APs and suggesting hardening measures (e.g., disabling WPS).

[0055] Scenario 2: Automated attack chain orchestration in workflow orchestration module User command example: "Cracking this RFID access card" Workflow of AI agents: Physical space detection of the second processing unit: After receiving the corresponding execution plan instruction, the second processing unit 200 reads the card's UID and protocol type (such as MIFARE Classic) through the NFC module.

[0056] Historical experience matching: Search the built-in vulnerability database. If it is a known vulnerable protocol, call the mfoc tool to perform full sector cracking.

[0057] Dynamic adjustment: If an encrypted sector is encountered, it automatically switches to the GPIO probe driven by STM32 to carry out a hardware side-channel attack.

[0058] This technology can clone access cards and generate virtual copies, while recording the timing and power consumption characteristics during the cracking process for educational demonstrations.

[0059] Scenario 3: Cross-modal cooperative attack example User commands: "Take control of that smart light bulb" Multi-module scheduling of AI agent modules: Radio analysis: Use the CC1101 module to sniff out BLE broadcast packets from light bulbs and identify their GATT service characteristics.

[0060] Protocol Reverse Engineering: The unknown protocol is parsed by the corresponding model accelerated by the NPU of the first processing unit 100, and a fake pairing request is generated.

[0061] Persistent control: Inject malicious firmware update packages (BadUSB simulated keyboard input) to simulate red team vs. blue team hacking operations to hijack the device.

[0062] Results: Bypassing the manufacturer's encryption mechanism, remote and arbitrary control of the light bulb (such as brightness adjustment and firmware erasure) was achieved; the output report indicated that the smart system had a vulnerability.

[0063] Scenario 4: Smart Home Security Audit The user command was "Detect the wireless protocol vulnerability of my smart door lock".

[0064] The second processing unit 200 controls radio frequency scanning: specifically, it captures the Bluetooth / BLE communication frequency band of the door lock through the CC1101 module and identifies the key exchange process.

[0065] The first processing unit performs protocol reverse engineering: it uses an NPU-accelerated AI model to analyze encryption flaws (such as weak random number generation).

[0066] Finally, the first processing unit simulates an attack: replaying the pairing request and injecting a fake key to verify whether the lock accepts unauthorized access.

[0067] Generate a report, mark the risk of being "subject to relay attacks", and provide hardening suggestions (such as enabling two-way authentication).

[0068] Scenario 5: Penetration Testing of Industrial Control Systems The instruction is "Evaluate the Modbus-TCP security of this production line PLC".

[0069] The second processing unit 200 uses an RS485 probe extended via GPIO to monitor the communication flow between the PLC and HMI.

[0070] The first processing unit 100 has a built-in decoder that automatically identifies unencrypted register read / write instructions; it simulates the master station sending malicious instructions (such as forced shutdown) to test the PLC's input verification mechanism.

[0071] Results: A default password vulnerability was discovered, demonstrating how production parameters can be tampered with by forging data packets.

[0072] Scenario 6: Access Control Test Command: "Bypass the NFC access control system in the corporate office area".

[0073] The built-in NFC module of the second processing unit 200 reads the employee card UID and encrypted sector.

[0074] The first processing unit 100 calls the NPU-accelerated mfoc tool to crack the MIFARE Classic key; writes the cloned card data into a blank label, and synchronously generates an attack log for review.

[0075] Result: The access card was successfully copied and zero alarms were triggered, exposing a flaw in physical access control.

[0076] Scene 7: Radio Education Experiment

[0077] Command: "Teach me to decode the drone's image transmission signal."

[0078] The second processing unit 200 controls the SDR module to scan the 5.8GHz frequency band and visualize the frequency hopping pattern.

[0079] The first processing unit 100 records the control signal and performs noise reduction processing through the AI ​​intelligent agent module to extract the DSSS modulation parameters.

[0080] Results: A report was generated that allows students to interactively learn about radio protocol reverse engineering and understand the importance of physical layer security.

[0081] Scenario 8: Emergency Response Evidence Collection The command is "Extract the firmware of this suspicious router".

[0082] Connect to the router's UART debugging port via the USB-TTL interface.

[0083] The second processing unit 200 sends a specific timing pulse to bypass the protection and export the Flash content.

[0084] The AI ​​agent module of the first processing unit 100 cracks the Kali toolchain to detect backdoor accounts or unpatched CVEs in the firmware.

[0085] Result: Evidence of the malicious script implanted by the attacker was obtained through a legally authorized judicial institution.

[0086] Scenario 9: IoT Device Development and Debugging The instruction is "Simulate temperature and humidity sensors to deceive the smart home hub".

[0087] The second processing unit 200 outputs a fake PWM waveform to simulate sensor data via GPIO.

[0088] The AI ​​agent module of the first processing unit 100 disguises itself as a legitimate device by broadcasting a custom GATT service via BLE.

[0089] Results: Verify the robustness of the input filtering mechanism of the IoT platform.

[0090] Scenario 10: Administrative / Judicial Evidence Collection Command "Get Audio and Video" The first processing unit 100 retrieves currently available sensors to generate instructions; The second processing unit 200 calls each sensor according to the instructions of the first processing unit 100 and saves the current data; for example, the Wi-Fi module is called to report all SSIDs in the current environment, the Bluetooth module reports the broadcast status of Bluetooth devices in the current environment, the microphone is called to report a sample of environmental audio, and the camera reports the captured bitmap.

[0091] The second processing unit 200 reports data to the first processing unit.

[0092] Result: A time-stamped, forensic "snapshot" package saved as a compressed file.

[0093] As illustrated by the above application examples, the technical solution of this invention, through the cooperation of functional sub-modules, the first processing unit 100, and the second processing unit 200, can test different products to obtain corresponding test results for actual use by users. Since only this system created by this invention is needed, the application scope of this invention is very wide, and it has outstanding practical effects compared to traditional technologies.

[0094] In other embodiments, to adapt to different application scenarios—specifically, scenarios requiring the simultaneous acquisition of different parameters for a particular scenario to achieve testing—the AI ​​agent module is configured to execute extended collaborative steps. That is, the execution plan instruction generated by the AI ​​agent module based on the corresponding execution task instruction simultaneously includes the control of multiple target devices (functional sub-modules). In this case, the corresponding second processing unit 200 can simultaneously schedule different functional sub-modules to interact with the devices in the target scenario according to the execution plan instruction. For example, it can simultaneously activate the NFC module or RFID module to interact with the access control card system. Furthermore, if the test results do not meet the conditions, other functional sub-modules can be called for testing. For example, signal acquisition can be performed using the SDR module.

[0095] Specifically, the steps for this extended collaboration are as follows: The acquired user instruction is parsed to generate an execution plan instruction containing at least one execution step, and then sent to the second processing unit. In this step, the first processing unit 100 identifies the corresponding user instruction and generates the corresponding execution plan instruction through its AI agent module. This method is consistent with the above description and will not be repeated here.

[0096] It should be understood that, in a more specific embodiment, the execution plan instruction includes control instructions for two or more target devices. For example, if the input natural language is "Help me evaluate the folding fan access control", the corresponding control instruction may simultaneously include a call instruction for the NFC module and a call instruction for the RFID module.

[0097] The corresponding execution plan instruction is transmitted from the first processing unit 100 to the second processing unit 200 via the high-speed virtual channel of the modular bus 200. The second processing unit, in response to the execution plan instruction, schedules the corresponding functional sub-modules to perform the corresponding functional operations and returns the test results. Specifically, in this step, the second processing unit 200 will call different functional sub-modules according to the corresponding plan instruction, such as simultaneously calling the NFC module and the RFID module to scan and sense the access control system. The NFC and RFID data obtained after sensing are then fed back to the first processing unit 100 for processing via the high-speed virtual channel.

[0098] Specifically, let's take the identification of the second processing unit 200 in an NFC access control hacking scenario as an example: Hardware architecture: RF module: ST25R3916 NFC transceiver (13.56MHz).

[0099] Coprocessor: The STM32WB55RG MCU drives the RF module, runs the protocol parsing algorithm through the ARM Cortex-M4 core, and utilizes its built-in Bluetooth LE 5.4 and 802.15.4 radio processors to assist in signal processing.

[0100] Detailed explanation of the cracking steps Signal Acquisition: When this system is close to the target access card or card reader, the ST25R3916 NFC transceiver scans the 13.56MHz frequency band in high-sensitivity mode to capture the raw radio frequency signal.

[0101] Protocol identification: The STM32 coprocessor decodes the signal in real time, matches it with the preset protocol libraries such as ISO14443A / B and MIFARE, and identifies the encryption type (such as AES or DES).

[0102] Data cloning / simulation: If the card is unencrypted, directly copy the UID and data block to the device storage; if encrypted, launch a pre-built exploit script (such as Nested Attack or Darkside Attack) to crack the key.

[0103] Replay attack: The radio frequency front-end controlled by the second processing unit 200 simulates a legitimate card signal and sends a tampered data packet to pass the access control verification.

[0104] In this embodiment, the Cortex-M0+ radio processor of the STM32WB55RG can process Bluetooth beacon interference in parallel, assisting in the stable transmission of NFC signals.

[0105] Once the corresponding acquisition signals are acquired, these signals will be transmitted to the first processing unit 100, which will then import these acquisition signals into the AI ​​intelligent agent module for processing to obtain the final result.

[0106] Specifically, we will still use the NFC access control hacking scenario mentioned above as an example for explanation.

[0107] When the second processing unit 200 receives the Mifare Classic signal, the AI ​​agent module calls the mfoc tool in Kali and interacts with the STM32's NFC chip through a high-speed virtual channel to perform the cracking.

[0108] In detail, the process of cracking the Mifare Classic card using NFC involves hardware collaboration, exploitation of protocol vulnerabilities, and AI-accelerated analysis. The specific process is as follows: 1. Target and Scenario Objective: To crack the encryption key of the Mifare Classic card (such as the default key or a weak key) and read / modify the data on the card (such as the access card's UID, permission bits, and user data area).

[0109] 2. Hardware Interaction Architecture Core components: NFC module: The ST25R3916 chip (13.56MHz) is responsible for physical layer signal transmission and reception.

[0110] Second processing unit 200: The second processing unit 200 is an STM32WB55RG, which controls the NFC module via the SPI bus and processes radio frequency signals in real time.

[0111] AI intelligent agent module of the first processing unit 100: The model of the first processing unit 100 is RK3588S.

[0112] The software tools of the first processing unit 100 are mfoc (Mifare Classic offline cracking tool) and libnfc driver library in Kali Linux.

[0113] 3. Detailed Explanation of the Cracking Process Phase 1: Protocol Identification and Initialization The second processing unit 200 controls the ST25R3916 chip to scan the 13.56MHz frequency band. After detecting the Mifare Classic card, the second processing unit 200 completes anti-collision and card selection through the ISO14443-3 protocol.

[0114] Send the REQA / WUPA command to activate the card, obtain the UID and ATQA response, and confirm the card type.

[0115] Phase 2: Key Cracking Feature extraction of the AI ​​agent module of the first processing unit 100: The NPU of the first processing unit 100 (RK3588S) is used to analyze historical cracking data (such as common manufacturer default keys and timestamp patterns) and generate a probability weight key table.

[0116] Parallel computing: The NPU of the first processing unit 100 (RK3588S) is used to try multiple key combinations simultaneously (such as FFFF FF FF FF FF, A0 A1 A2 A3 A4 A5), and the AUTH command is sent to the NFC module for verification through the second processing unit 200.

[0117] Feedback learning: Failure responses (NAK) are recorded and used to optimize the next round of key generation, reducing cracking time to the second level.

[0118] Phase 3: Data Interaction After successful cracking, the second processing unit 200 sends a READ / WRITE command via the NFC module to manipulate the card data: Read all sector data (such as access control codes). Modify the content of a specific block (e.g., simulate a high-privilege card). Clone UID to a blank NTAG (card reader compatible required) The aforementioned NFC access control hacking scenarios could include, for example, access control system penetration testing to verify vulnerabilities in property card permission logic; transportation card balance reading to study payment protocol security; or cloning employee cards for red team drills of physical security defenses.

[0119] It should be noted that this technical solution is intended for use in security testing scenarios authorized by national authorities and must comply with local laws.

[0120] After the NFC and RFID data collected after sensing are fed back to the first processing unit 100 for processing through the high-speed virtual channel, the following steps may also be included: If the current test result does not meet the expected result, other extended hardware modules connected to the modular bus are invoked to perform low-level signal analysis, or an updated processing strategy is obtained from the cloud to regenerate a new execution plan instruction to retry the test.

[0121] That is, when a test fails, it can be retested using data from other functional sub-modules. Specifically, if the current test result does not meet expectations, such as if the cracking is unsuccessful, the AI ​​agent module of the first processing unit 100 issues a secondary call command to control the second processing unit 200 to acquire the acquisition signals from other functional sub-modules and send them back to the first processing unit 100 for retesting.

[0122] Let's take the NFC access control system mentioned above as an example for further explanation.

[0123] After a test failure, the AI ​​agent module of the first processing unit 100 calls the pluggable SDR module for lower-level model analysis, or obtains an updated processing strategy from a remote location to regenerate a new execution plan instruction to retry the test. Specifically, the raw signal is provided in real time by the ADC sampling data stream of the SDR module and hardware probes (such as a logic analyzer). The second processing unit 200 controls the GPIO / USB interface switching module (such as a relay array) according to the instructions of the AI ​​agent module of the first processing unit 100, dynamically loading drivers or switching the RF front end. The AI ​​agent module of the first processing unit 100 evaluates the attack success rate through a pre-set reinforcement learning model (such as DQN). If three consecutive attacks fail and the signal-to-noise ratio is >15dB, the SDR deep analysis mode is triggered. Specifically, when using cloud-based attack vectors, the following content is obtained from vulnerability databases (such as ExploitDB) or community crowdsourcing platforms: Protocol vulnerabilities: CRC check defects on specific devices, replay attack time windows; Payload templates: BadUSB script, RFID cloning parameter set.

[0124] Finally, the AI ​​agent module of the first processing unit 100 performs sandbox verification (simulating the target device response) on the attack vector; after being signed by the hardware security module (HSM) of the second processing unit 200, it is pushed to the execution unit.

[0125] The collaborative approach of this solution aims to achieve unified coordination with the operating methods of other functional sub-modules in order to optimize testing.

[0126] In another embodiment, the AI ​​agent module is further configured to operate autonomously. The specific steps are as follows: S10: The first processing unit 10 does not receive an operation instruction within a preset time; S20: Retrieve the pre-stored list of tasks and obtain the first task; S30: Generate a first task plan instruction based on the first work task; S40: Send the first task plan instruction to the second processing unit so that the second processing unit can control the corresponding functional sub-modules to work; S50: Receive the acquisition signal transmitted back by the second processing unit; S60: Perform calculations based on the acquired signals and a pre-stored model to obtain test results; S70: Complete the current test and call the next task in the pre-stored task list; Repeat steps S20 to S70.

[0127] Specifically, if the first processing unit 10 does not receive any natural language or other input instructions from the operator within one minute, it directly calls the pre-stored task list, which is stored in the knowledge base. The execution steps of specific steps S30-S60 are the same as the processing method described above and will not be repeated here. For example, during a network security verification test, if there is no operation within a predetermined time, the AI ​​agent module will process the network security test model according to the pre-stored task list. For example, if the task list includes 10 different test models, the AI ​​agent model will automatically and continuously execute the 10 test models in sequence to perform network security testing. Once all 10 test models are completed, the 10 test models will be repeatedly cycled.

[0128] The test results obtained after each test are stored and remembered for later review.

[0129] This technical solution ensures that the equipment is always working, enabling uninterrupted testing. Example 2

[0130] Another aspect of the present invention proposes a network-physical dual-space extended security intrusion testing method, which includes the following steps: Obtain the user's task execution instructions; The first processing unit generates an execution plan instruction based on the execution task instruction; The first processing unit transmits the execution plan instruction to the second processing unit through the high-speed board-to-board connector; The second processing unit responds to the execution plan instruction to drive the functional sub-module connected to the first processing unit to work and receives the acquisition signal fed back by the functional sub-module; The second processing unit transmits the acquired signal to the first processing unit through a high-speed board-to-board connector. The first processing unit performs calculations based on the acquired signals and the execution plan instructions according to the corresponding model to obtain the test results.

[0131] This method enables security testing of both network and physical spaces in different scenarios, eliminating the need for multiple different devices to be used as in traditional technologies, making testing more convenient. Example 3

[0132] This invention proposes an extended detection device for both network and physical spaces, including a device motherboard on which any of the aforementioned extended security intrusion testing systems for both network and physical spaces are installed. The detection device may further include a housing and a power supply. The power supply is connected to the power supply terminal of the first processing unit 100 to power the entire device. In this embodiment, the entire device motherboard and power supply are housed within the housing to form a single, complete structure.

[0133] The extended testing device of this embodiment integrates almost all functional structures into the device motherboard, which is small in size and can perform scene testing without the use of external special instruments, making it very convenient to use.

[0134] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0135] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0136] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0137] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

[0138] Based on the disclosure and teachings of the foregoing specification, those skilled in the art can make changes and modifications to the above embodiments. Therefore, the present invention is not limited to the specific embodiments disclosed and described above, and some modifications and changes to the present invention should also fall within the protection scope of the claims of the present invention. Furthermore, although some specific terms are used in this specification, these terms are only for convenience of explanation and do not constitute any limitation on the present invention.

Claims

1. An extended security intrusion testing system for both network and physical spaces, characterized in that, include: The system comprises a first processing unit, a second processing unit, a modular bus, and functional sub-modules. The first processing unit and the second processing unit are connected via the modular bus; The functional submodules are selectively connected to the first processing unit or the second processing unit and are used to interact with the system under test to acquire acquisition signals; the first processing unit is configured to: accept execution task instructions, generate execution plan instructions according to the execution task instructions, and transmit the execution plan instructions to the second processing unit through the modular bus; the second processing unit is configured to: respond to the execution plan instructions to drive at least one functional submodule to work, and receive acquisition signals fed back by the functional submodule; the first processing unit is further configured to: receive the acquisition signals transmitted by the second processing unit and perform calculation processing based on the execution plan instructions according to a preset model to obtain test results.

2. The extended security intrusion testing system for network and physical dual spaces as described in claim 1, characterized in that: The first processing unit and the second processing unit are connected in a pluggable manner through the high-speed virtual channel of the modular bus. Specifically, the first processing unit and the second processing unit establish a physical connection through the high-speed board-to-board connector of the modular bus; the second processing unit encapsulates the acquired signal according to a custom frame format to generate a data frame; the first processing unit runs the kernel driver module, receives the data frame, parses the received data frame, and maps it to the standard device of the operating system.

3. The extended security intrusion testing system for network and physical dual spaces as described in claim 2, characterized in that: The modular bus uses either a UART or SPI interface to connect the first processing unit and the second processing unit.

4. The extended security intrusion testing system for both network and physical spaces as described in claim 2, characterized in that: in, The custom frame format includes a frame header field, a command code field, a data field, and a checksum field. The command code field is used to identify the operation type of the functional submodule corresponding to the data frame. Specifically, the first processing unit runs the kernel driver module, receives the data frame, parses the received data frame, and maps it to the standard device of the operating system.

5. The extended security intrusion testing system for network and physical dual spaces as described in claim 1, characterized in that: The functional sub-modules include at least one of the following: radio frequency module, broadband SDR module, Ethernet PoE module, Bluetooth sniffing module, NFC module, RFID module, Bluetooth module, WIFI module, and infrared recognition module.

6. The extended security intrusion testing system for network and physical dual spaces as described in claim 1, characterized in that: The first processing unit is configured to either have a built-in AI agent module or communicate and interact with an AI agent module in the cloud. The AI ​​agent module located in the first processing unit or in the cloud has a natural language parsing module, which is configured to receive execution task instructions in natural language form and separate them into structured information. The vector retrieval module is configured to retrieve online or offline knowledge base content based on the structured information to match task plan instructions; the reasoning module is configured to reason about specific task plan instructions based on the structured information. Command execution module: It is configured to transmit task plan instructions to the second processing unit, receive the acquisition signals from the second processing unit, select a preset model to execute or execute directly in the device according to the acquisition signals, perform result acceptance and feedback, and update the task ranking in the knowledge base.

7. The extended security intrusion testing system for network and physical dual spaces as described in claim 6, characterized in that: The AI ​​agent module is configured to execute extended collaborative steps, which are as follows: parsing the acquired user instructions, generating an execution plan instruction containing at least one execution step, and sending the execution plan instruction to the second processing unit; the second processing unit responds to the execution plan instruction by scheduling the corresponding functional sub-module to execute the corresponding functional operation and returning the test result; if the current test result does not meet the expected result, it calls other extended hardware modules connected to the modular bus to perform low-level signal analysis, or obtains an updated processing strategy from the cloud to regenerate a new execution plan instruction to retry the test.

8. The extended security intrusion testing system for network and physical dual spaces as described in claim 7, characterized in that: The execution plan instructions include at least two types of instructions for controlling different functional sub-modules.

9. A network-physical dual-space extended security intrusion testing method, characterized in that, The testing method includes the following steps: obtaining the user's execution task instruction; a first processing unit generating an execution plan instruction based on the execution task instruction; and the first processing unit transmitting the execution plan instruction to a second processing unit through the high-speed board-to-board connector. The second processing unit responds to the execution plan instruction to drive at least one functional sub-module to work and receives the acquisition signal fed back by the functional sub-module; The second processing unit transmits the acquired signal to the first processing unit through a high-speed board-to-board connector. The first processing unit performs calculations based on the acquired signals and the execution plan instructions according to a preset model to obtain test results.

10. An extended detection device for both network and physical spaces, comprising a device motherboard, characterized in that: The device motherboard is equipped with an extended security intrusion testing system for both network and physical spaces as described in any one of claims 1-8.