Vehicle communication security test method, device and equipment and readable storage medium

By collecting and analyzing behavioral data of vehicle communication systems when using illegal digital certificates, detecting the security attributes of the certificates and comparing the handling strategies, the problem of the inability to fully verify the security response capabilities of vehicle communication systems in existing technologies is solved, and a comprehensive security response assessment of vehicle communication systems is achieved.

CN122247634APending Publication Date: 2026-06-19XIANGYANG DAAN AUTOMOBILE TEST CENT

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XIANGYANG DAAN AUTOMOBILE TEST CENT
Filing Date
2026-04-30
Publication Date
2026-06-19

AI Technical Summary

Technical Problem

Existing technologies only verify whether a vehicle communication system can communicate successfully when faced with an illegal certificate, and cannot comprehensively and effectively verify its security response capabilities.

Method used

The system collects behavioral data on vehicle communication systems when using illegal digital certificates. By detecting the certificate's validity period, certificate chain integrity, signature validity, and revocation status, it determines security attribute identifiers. Based on these security attribute identifiers, it determines the expected handling strategy and compares the actual handling behavior with the expected handling strategy to assess the security response capability.

Benefits of technology

It enables comprehensive and effective detection of vehicle communication systems under different security risk conditions when facing illegal digital certificates, can identify potential risks of improper security response, and improves the practical value and reliability of vehicle-to-everything (V2X) communication security testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122247634A_ABST
    Figure CN122247634A_ABST
Patent Text Reader

Abstract

A vehicle communication security testing method, apparatus, device, and readable storage medium are disclosed. The vehicle communication security testing method includes: collecting behavioral data of the vehicle communication system during communication testing using a digital certificate, wherein the vehicle communication system is injected with the digital certificate, and the digital certificate is an invalid digital certificate; determining the actual processing behavior of the vehicle communication system based on the behavioral data; determining the security attribute identifier of the digital certificate by detecting its validity period, certificate chain integrity, signature validity, and revocation status; determining the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier; and determining whether the security response capability of the vehicle communication system passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy. This application enables a comprehensive and effective testing of the security response capability of a vehicle communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle communication security technology, and in particular to a vehicle communication security testing method, apparatus, device, and readable storage medium. Background Technology

[0002] With the rapid development of intelligent connected vehicle technology, communication between vehicles has become increasingly complex. Especially in in-vehicle communication systems, the validity of certificates directly impacts the security of vehicle-to-the-world communication. Currently, intelligent connected vehicles widely rely on digital certificates to ensure communication security, such as in-vehicle communication and V2X (Vehicle to Everything) communication. Digital certificates may become invalid, revoked, or tampered with, thus creating security vulnerabilities in vehicle communication.

[0003] However, existing technologies only verify whether a vehicle communication system can communicate successfully when faced with an illegal certificate, and cannot comprehensively and effectively verify the security response capabilities of a vehicle communication system. Summary of the Invention

[0004] This application provides a vehicle communication security testing method, apparatus, device, and readable storage medium, aiming to solve the technical problem that existing technologies only simply verify whether a vehicle communication system can communicate successfully when faced with an illegal certificate, and cannot comprehensively and effectively verify the security response capabilities of a vehicle communication system.

[0005] In a first aspect, embodiments of this application provide a vehicle communication security testing method, the vehicle communication security testing method comprising: During the communication test between the vehicle communication system and the digital certificate, behavioral data of the vehicle communication system is collected, wherein the vehicle communication system is injected with the digital certificate, and the digital certificate is an illegal digital certificate; Based on the behavioral data, the actual processing behavior of the vehicle communication system is determined; By detecting the validity period, certificate chain integrity, signature validity, and revocation status of the digital certificate, the security attribute identifier of the digital certificate is determined, and based on the security attribute identifier, the expected handling strategy corresponding to the vehicle communication system is determined. By comparing whether the actual handling behavior is consistent with the expected handling strategy, it is determined whether the safety response capability of the vehicle communication system passes the test.

[0006] Optionally, after determining whether the safety response capability of the vehicle communication system passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy, the process includes: A legitimate digital certificate is injected into the vehicle communication system for communication testing, in order to test the communication recovery capability of the vehicle communication system.

[0007] Optionally, the security attribute identifier includes identity trustworthiness, authorization validity, integrity, and time consistency. Determining the security attribute identifier of the digital certificate by detecting its validity period, certificate chain integrity, signature validity, and revocation status includes: The authenticity of the digital certificate is determined by detecting the integrity of the certificate chain and the validity of the signature. The authorization validity of the digital certificate is determined by detecting the revocation status of the digital certificate; The integrity of the digital certificate is determined by checking the signature validity of the digital certificate; The time consistency of the digital certificate is determined by comparing its validity period with the system time.

[0008] Optionally, the expected handling strategy includes normal communication, degraded communication, delayed verification, communication rejection, and forced interruption with recording of security alarms. The step of determining the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier includes: Based on the identity trustworthiness, authorization validity, integrity, and time consistency of the digital certificate, the expected handling strategy corresponding to the vehicle communication system is determined by searching a preset judgment matrix. The preset judgment matrix includes the mapping relationship between identity trustworthiness, authorization validity, integrity, and time consistency and normal communication, downgraded communication, delayed verification, communication rejection, and forced interruption and recording of security alarms.

[0009] Optionally, determining whether the vehicle communication system's safety response capability passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy includes: When the actual handling behavior is consistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have passed the test. When the actual handling behavior is inconsistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have failed the test.

[0010] Secondly, embodiments of this application provide a vehicle communication security testing device, the vehicle communication security testing device comprising: The data acquisition module is used to collect behavioral data of the vehicle communication system during communication testing with the vehicle communication system using a digital certificate, wherein the vehicle communication system is injected with the digital certificate, and the digital certificate is an invalid digital certificate. The behavior determination module is used to determine the actual processing behavior of the vehicle communication system based on the behavior data. The strategy determination module is used to determine the security attribute identifier of the digital certificate by detecting the validity period, certificate chain integrity, signature validity and revocation status of the digital certificate, and determine the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier. The comparison and detection module is used to determine whether the safety response capability of the vehicle communication system passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy.

[0011] Optionally, the vehicle communication security testing device further includes a resilience testing module, used for: A legitimate digital certificate is injected into the vehicle communication system for communication testing, in order to test the communication recovery capability of the vehicle communication system.

[0012] Optionally, the security attribute identifier includes identity trustworthiness, authorization validity, integrity, and time consistency. Determining the security attribute identifier of the digital certificate by detecting its validity period, certificate chain integrity, signature validity, and revocation status is used for: The authenticity of the digital certificate is determined by detecting the integrity of the certificate chain and the validity of the signature. The authorization validity of the digital certificate is determined by detecting the revocation status of the digital certificate; The integrity of the digital certificate is determined by checking the signature validity of the digital certificate; The time consistency of the digital certificate is determined by comparing its validity period with the system time.

[0013] Thirdly, this application provides a vehicle communication security testing device, which includes a processor, a memory, and a vehicle communication security testing program stored in the memory and executable by the processor. When the vehicle communication security testing program is executed by the processor, it implements the steps of the vehicle communication security testing method described above.

[0014] Fourthly, embodiments of this application provide a readable storage medium storing a vehicle communication security test program, wherein when the vehicle communication security test program is executed by a processor, it implements the steps of the vehicle communication security test method as described above.

[0015] The beneficial effects of the technical solutions provided in this application include: In this embodiment, behavioral data of the vehicle communication system is collected during communication testing using a digital certificate. The vehicle communication system is injected with the digital certificate, which is an invalid digital certificate. Based on the behavioral data, the actual processing behavior of the vehicle communication system is determined. By detecting the validity period, certificate chain integrity, signature validity, and revocation status of the digital certificate, the security attribute identifier of the digital certificate is determined. Based on the security attribute identifier, the expected handling strategy corresponding to the vehicle communication system is determined. By comparing whether the actual processing behavior is consistent with the expected handling strategy, it is determined whether the security response capability of the vehicle communication system passes the test. Through the embodiments of this application, illegal digital certificates include, for example, expired certificates, revoked certificates, forged certificates, and time-offset certificates. Compared with the prior art, which simply verifies whether the vehicle communication system can communicate successfully when faced with illegal certificates, this application determines the security attribute identifier of the illegal digital certificate by detecting and analyzing its validity period, certificate chain integrity, signature validity, and revocation status. The security attribute identifier includes, for example, identity trustworthiness, authorization validity, integrity, and time consistency. The security attribute identifier can reflect the security risk level of the communication. Then, the vehicle communication system should adopt the corresponding expected handling strategy. The expected handling strategy includes, for example, normal communication, downgraded communication, delayed verification, communication rejection, and forced interruption and recording of security alarms. By comparing whether the actual processing behavior of the vehicle communication system is consistent with the expected handling strategy, it is determined whether the security response capability of the vehicle communication system passes the test. This can comprehensively and effectively detect the security response capability of the vehicle communication system under different security risk conditions of illegal digital certificates. Attached Figure Description

[0016] Figure 1 This is a flowchart illustrating an embodiment of the vehicle communication security testing method of this application; Figure 2 This is a schematic diagram of the test system architecture of an embodiment of the vehicle communication security test method of this application. Figure 3 This is another flowchart illustrating an embodiment of the vehicle communication security testing method of this application; Figure 4 This is a functional module diagram of an embodiment of the vehicle communication security testing device of this application; Figure 5 This is a schematic diagram of the hardware structure of the vehicle communication security testing equipment involved in the embodiments of this application. Detailed Implementation

[0017] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0019] In a first aspect, embodiments of this application provide a vehicle communication security testing method.

[0020] In one embodiment, reference is made to Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the vehicle communication security testing method of this application, as shown below. Figure 1 As shown, the vehicle communication security testing method includes: Step S10: Collect behavioral data of the vehicle communication system during the communication test using a digital certificate with the vehicle communication system, wherein the vehicle communication system is injected with the digital certificate, and the digital certificate is an illegal digital certificate.

[0021] In this embodiment, refer to Figure 2 , Figure 2 This is a schematic diagram of the test system architecture of an embodiment of the vehicle communication security test method of this application, as shown below. Figure 2 As shown, the V2X certificate validity testing system includes a certificate management system, a communication testing system, and a test result analysis system. The certificate management system includes a certificate generation module and a certificate injection module, which are used to generate digital certificates and inject the generated digital certificates into the vehicle communication system so that the vehicle communication system can use the injected digital certificates for communication. The communication testing system includes a test OBU (an external module) that sends requests to the test vehicle communication system to conduct communication tests. The communication status monitoring module is deployed on the test vehicle to collect behavioral data of the vehicle communication system during the communication test process and provide communication logs for the test result analysis system to determine the security response capability of the vehicle communication system in the face of various digital certificates.

[0022] In practice, the certificate management system generates invalid digital certificates for testing, including expired certificates, revoked certificates, forged certificates, and time-offset certificates. The certificate injection module writes the digital certificates generated by the certificate management system into the certificate storage area of ​​the test vehicle through a dedicated interface, enabling the test vehicle's communication system to use the injected digital certificates for communication. This process employs non-intrusive injection technology to ensure that the original communication function configuration of the test vehicle is not altered. After the digital certificate injection is complete, the test OBU of the communication test system, as an external module relative to the test vehicle, uses the generated digital certificate to establish a communication connection with the test vehicle's communication system and sends V2X communication data according to a preset communication frequency. The communication status monitoring module is deployed inside the test vehicle to collect behavioral data such as the communication establishment status, communication interruption status, and anomaly handling status of the vehicle's communication system in real time. This collection process employs a multi-dimensional monitoring mechanism, not only recording the data packet interaction at the communication layer but also simultaneously collecting the security logs, certificate verification results, and system status information within the vehicle's communication module, ensuring the integrity and accuracy of the behavioral data. This comprehensive data collection method provides a sufficient information foundation for subsequent analysis, avoiding the single-dimensional assessment shortcomings of existing technologies that only focus on whether communication is successful. It enables all-round observation of vehicle communication safety response behavior and lays a data foundation for accurately determining vehicle safety response capabilities.

[0023] Step S20: Based on the behavioral data, determine the actual processing behavior of the vehicle communication system.

[0024] In this embodiment, the collected behavioral data can be structured and semantically recognized. For example, the collected communication and security logs are first preprocessed to filter out noise data and extract key events. Then, based on a preset behavioral pattern library, the key events in the logs are mapped to specific communication processing behaviors. For example, if a "certificate verification failure" log is followed by a "communication connection refused" operation, the actual processing behavior of the vehicle communication system is determined to be "communication refused" behavior; if a "certificate verification warning" is detected but a communication connection is still established but some functions are restricted, the actual processing behavior of the vehicle communication system is determined to be "degraded communication" behavior. This process can use a state machine model for behavior recognition. By defining key state nodes and state transition conditions in the communication process, the actual processing behavior of the vehicle under different safety attribute states can be accurately identified. Compared with traditional testing methods that only focus on the outcome indicator of whether communication is successful, this embodiment can more comprehensively evaluate the safety response capability of the vehicle communication system by deeply analyzing the intermediate states and behavioral decision-making logic in the communication process. This fine-grained behavior recognition mechanism allows the test results to reflect whether the internal logic of the vehicle safety decision-making system is reasonable, providing technical assurance for discovering potential safety hazards.

[0025] Step S30: By detecting the validity period, certificate chain integrity, signature validity and revocation status of the digital certificate, the security attribute identifier of the digital certificate is determined, and based on the security attribute identifier, the expected handling strategy corresponding to the vehicle communication system is determined.

[0026] In this embodiment, the injected test certificate undergoes multi-dimensional testing, including digital certificate validity, certificate chain integrity, signature validity, and revocation status, resulting in one or more security attribute identifiers for the corresponding digital certificate. These security attribute identifiers include, for example, identity trustworthiness, authorization validity, integrity, and time consistency. These testing processes are independent yet logically interconnected, collectively constituting a comprehensive assessment of the certificate's security status and reflecting the level of communication security risks. Subsequently, the testing system, based on a preset judgment matrix, searches for the expected handling strategy corresponding to the combination of security attributes. By decomposing the certificate's security status into multi-dimensional attributes and establishing an attribute-policy mapping relationship, this method overcomes the limitations of traditional testing that uses only certificate validity as a binary judgment criterion. It enables differentiated testing and evaluation for security risks of different dimensions, significantly improving the relevance and effectiveness of the testing. By introducing security attributes as intermediate technical variables, this embodiment achieves fine-grained verifiable testing of vehicle security decision-making logic, providing a scientific basis for evaluating the security response capabilities of vehicle communication systems.

[0027] Step S40: By comparing whether the actual handling behavior is consistent with the expected handling strategy, determine whether the safety response capability of the vehicle communication system passes the test.

[0028] In this embodiment, the actual processing behavior is compared with the expected handling strategy. If they match, the test is considered passed; otherwise, it is considered failed. Compared with the simple "communication success / failure" binary judgment in the prior art, this embodiment introduces a mapping relationship between security attributes and handling strategies, which can more accurately evaluate the response capability of the vehicle communication system in the face of complex security threats. It effectively identifies potential risks that can establish communication but have inappropriate security responses, greatly improving the practical value and reliability of vehicle network communication security testing.

[0029] In this embodiment, a comprehensive data acquisition approach provides a sufficient information foundation for subsequent analysis, avoiding the single-dimensional assessment shortcomings of existing technologies that only focus on the success of communication. This enables a holistic observation of vehicle communication safety response behavior, laying a data foundation for accurately determining vehicle safety response capabilities. In-depth analysis of intermediate states and behavioral decision-making logic during the communication process allows for a more comprehensive evaluation of the vehicle communication system's safety response capabilities. A fine-grained behavior recognition mechanism enables test results to reflect the rationality of the vehicle safety decision-making system's internal logic, providing technical support for identifying potential safety hazards. By decomposing certificate security status into multi-dimensional attributes and establishing attribute-policy mapping relationships, the method overcomes the limitations of traditional testing that uses only certificate validity as a binary criterion. This allows for differentiated testing and evaluation for different dimensions of security risks, significantly improving the relevance and effectiveness of the testing. By introducing security attributes as intermediate technical variables, this embodiment achieves fine-grained verifiable testing of vehicle safety decision-making logic, providing a scientific basis for evaluating the safety response capabilities of the vehicle communication system. Compared to the simple "communication success / failure" binary judgment in existing technologies, this embodiment introduces a mapping relationship between security attributes and handling strategies, which can more accurately assess the response capability of vehicle communication systems in the face of complex security threats, effectively identify potential risks that can establish communication but have inappropriate security responses, and greatly improve the practical value and reliability of vehicle network communication security testing.

[0030] Furthermore, in one embodiment, reference is made to Figure 3 , Figure 3 This is another flowchart illustrating an embodiment of the vehicle communication security testing method of this application, as shown below. Figure 3 As shown, after step S40, the following steps are included: Step S50: Inject a valid digital certificate into the vehicle communication system for communication testing, in order to test the communication recovery capability of the vehicle communication system.

[0031] In this embodiment, after testing the abnormal certificate, the certificate management system generates a valid digital certificate and re-injects it into the vehicle communication system to verify the system's communication recovery capability after the certificate anomaly is resolved. Specifically, the valid certificate is written to the vehicle certificate storage area via the certificate injection module. Subsequently, the communication test system initiates a V2X communication request again to monitor whether the vehicle can resume normal communication. This process not only verifies the recovery of communication functions but also focuses on checking whether the system has cleared the previous abnormal state markers, reset the security counters, and correctly processed the communication data missed during the anomaly. This recovery capability test is an important component of the test loop of this invention, simulating the scenario after certificate issues are resolved in a real-world vehicle network environment. Through this continuous anomaly-recovery test process, the security performance of the vehicle communication system throughout the entire lifecycle of a certificate anomaly can be comprehensively evaluated, avoiding the shortcomings of existing testing methods that only focus on the anomaly scenario and ignore the recovery process. Test practice shows that many security vulnerabilities not only exist in the anomaly handling stage but may also be exposed during system recovery. Therefore, the recovery capability test mechanism of this embodiment is of great value in discovering deep-seated security problems, significantly improving the completeness and reliability of vehicle network communication security testing.

[0032] Furthermore, in one embodiment, the illegal digital certificate includes expired certificates, revoked certificates, forged certificates, and time-offset certificates, and the vehicle communication security testing method further includes: By injecting expired certificates, revoked certificates, forged certificates, and time-offset certificates into the vehicle communication system for communication testing, a safety response capability test report of the vehicle communication system under expired certificates, revoked certificates, forged certificates, and time-offset certificates is obtained.

[0033] In this embodiment, the certificate management system switches between generating different types of illegal digital certificates and re-injecting them into the vehicle communication system for communication testing, thereby generating a report on the vehicle communication system's security response capabilities in the face of different types of illegal digital certificates. After each communication test using an illegal digital certificate, the system can switch back to a legitimate digital certificate to test the vehicle communication system's communication recovery capabilities in the face of different illegal digital certificates. The system employs differentiated testing strategies and evaluation focuses for different types of illegal digital certificates. For example, for expired certificate testing, the focus is on whether the system can identify certificate expiration issues and adopt appropriate downgrade or delayed verification strategies, rather than simply refusing communication, as clock synchronization errors may exist in real-world vehicle networking environments; for revoked certificate testing, the focus is on evaluating the system's timeliness in updating CRL / OCSP and its handling strategies for revoked certificates, especially its ability to handle batch revocation scenarios; for forged certificate testing, the focus is on checking the system's verification depth for certificate chain integrity and signature validity, as well as its ability to prevent man-in-the-middle attacks; for time-off certificate testing, the system's tolerance for clock deviations and the effectiveness of its synchronization mechanism are evaluated. During testing, the system automatically records detailed behavioral data for each abnormal scenario and generates a multi-dimensional detection report, including: response timeliness indicators (time from detecting an anomaly to taking action), strategy appropriateness scores (the degree of matching between actual behavior and expected strategy), system stability assessment (consistency in repeated testing), and recovery capability indicators. This categorized and targeted testing method, based on the principle of "threat modeling," designs test cases for the most likely certificate security threats encountered in the connected vehicle environment, making the test results more practically instructive. Compared with existing technologies, this embodiment not only tests whether the vehicle can detect illegal certificates but also assesses whether its security response meets the risk level, thereby providing a quantitative basis for improving vehicle safety design.

[0034] Further, in one embodiment, the security attribute identifier includes identity trustworthiness, authorization validity, integrity, and time consistency. Determining the security attribute identifier of the digital certificate by detecting its validity period, certificate chain integrity, signature validity, and revocation status includes: The authenticity of the digital certificate is determined by detecting the integrity of the certificate chain and the validity of the signature. The authorization validity of the digital certificate is determined by detecting the revocation status of the digital certificate; The integrity of the digital certificate is determined by checking the signature validity of the digital certificate; The time consistency of the digital certificate is determined by comparing its validity period with the system time.

[0035] In this embodiment, the process for determining security attribute identifiers is designed based on cryptographic principles and vehicle-to-everything (V2X) security specifications. In identity trustworthiness detection, the system verifies the integrity and signature validity of the certificate chain according to the X.509 certificate standard, verifying each level from the root certificate to ensure that the signature of each certificate can be correctly verified by the public key of its superior certificate, thereby confirming the authenticity and trustworthiness of the certificate holder's identity. Authorization validity detection follows the IEEE 1609.2 standard, confirming whether the certificate has been revoked by querying the CRL or OCSP response. This process considers the low latency requirements of the V2X environment and employs pre-caching and incremental update mechanisms to improve detection efficiency. Integrity detection verifies the certificate's signature algorithm and hash value to ensure that the certificate content has not been tampered with during transmission. Specifically addressing the risk of man-in-the-middle attacks in the V2X environment, an integrity check of the certificate's extended fields is added. Time consistency detection considers the clock synchronization issues caused by vehicle movement in the V2X environment, comparing not only the certificate validity period with the system time but also evaluating the tolerance for deviations between the system clock and standard time. This multi-dimensional security attribute detection mechanism decomposes the complex certificate security status into quantifiable technical indicators, making the testing process more objective and repeatable. Compared with existing technologies, this embodiment no longer simply classifies certificates as "legal" or "illegal," but rather identifies certificate risks that are misjudged as legitimate overall through fine-grained security attribute characterization. This significantly improves the sensitivity and accuracy of security testing, providing a more refined evaluation dimension for vehicle-to-everything (V2X) communication security. The identifiers and meanings of identity credibility, authorization validity, integrity, and time consistency in the security attribute identification are shown in Table 1.

[0036] Table 1.

[0037] Furthermore, in one embodiment, the expected handling strategy includes normal communication, degraded communication, delayed verification, communication rejection, and forced interruption with recording of security alarms. The step of determining the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier includes: Based on the identity trustworthiness, authorization validity, integrity, and time consistency of the digital certificate, the expected handling strategy corresponding to the vehicle communication system is determined by searching a preset judgment matrix. The preset judgment matrix includes the mapping relationship between identity trustworthiness, authorization validity, integrity, and time consistency and normal communication, downgraded communication, delayed verification, communication rejection, and forced interruption and recording of security alarms.

[0038] In this embodiment, the meanings and identifiers of normal communication, degraded communication, delayed verification, communication rejection, and forced interruption with recording of security alarms in the expected handling strategy are shown in Table 2, and the preset judgment matrix is ​​shown in Table 3. The design of the preset judgment matrix is ​​based on best practices and risk assessment theories for vehicle network security. In specific implementation, the system first establishes a mapping relationship between security attributes and risk levels: abnormal identity credibility (A1) represents the highest risk, which may lead to a complete impersonation attack; abnormal integrity (A3) is the next highest risk, which may lead to data tampering; abnormal authorization validity (A2) indicates that the certificate has been revoked but not updated in time; abnormal time consistency (A4) is usually of low risk and may be a clock synchronization problem. Based on this risk assessment, the system constructs a multi-dimensional decision tree to map different combinations of security attributes to appropriate handling strategies. For example, when identity trustworthiness is abnormal (A1: abnormal), regardless of other attribute states, the S3 (deny communication) or S4 (force interruption and recording security alarm) strategy should be adopted, because untrustworthy identity means that the communicating party may be a malicious attacker. When only time consistency is abnormal (A4: abnormal), the S2 (delayed verification) or S1 (degraded communication) strategy can be adopted, giving the system some time for clock synchronization or secondary verification. The judgment matrix also considers the logical relationships between attributes; for example, integrity abnormality (A3: abnormal) inevitably leads to identity trustworthiness abnormality, so in actual judgment, more serious security attributes will be prioritized. This risk assessment-based handling strategy mapping mechanism allows the testing process to not only verify whether the vehicle "can communicate," but also whether it "communicates securely." Compared with traditional testing methods, this embodiment, by introducing a refined mapping of security attributes and handling strategies, can assess whether the vehicle's safety decision-making logic conforms to best practices, effectively identifying system defects that, although able to establish communication, have inappropriate security strategies, significantly improving the professionalism and practicality of vehicle network security testing.

[0039] Table 2.

[0040] Table 3.

[0041] Further, in one embodiment, step S40 includes: When the actual handling behavior is consistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have passed the test. When the actual handling behavior is inconsistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have failed the test.

[0042] In this embodiment, the comparison and judgment process can employ a dynamic threshold mechanism and context-aware technology. Specifically, the system not only compares the surface consistency between behavior and strategy, but also analyzes the context and time-series characteristics of the behavior. For example, when the expected handling strategy is S2 (delayed verification), the system checks whether the vehicle performed secondary verification during the delay period and whether the delay time is within a reasonable range; when the expected strategy is S1 (degraded communication), the system verifies whether the degree of degradation is appropriate and whether necessary safety functions are retained. Furthermore, the system introduces a behavior stability assessment: under the same safety attribute conditions, repeated testing is performed. If the vehicle exhibits inconsistent behavior patterns, it will be marked as a potential risk even if a single test passes. This refined comparison mechanism is based on the "defense-in-depth" security principle, which believes that a safety response requires not only correct decision-making but also reasonable execution details. Through this rigorous comparison and judgment, this embodiment can effectively identify systems that superficially meet safety requirements but actually have safety vulnerabilities, avoiding misjudgments caused by overly simplistic judgment criteria in existing testing methods. This multi-dimensional comparison-based security response capability assessment mechanism significantly improves the accuracy and reliability of vehicle-to-everything (V2X) security testing, providing vehicle manufacturers with more valuable security improvement suggestions.

[0043] Secondly, embodiments of this application also provide a vehicle communication security testing device.

[0044] In one embodiment, reference is made to Figure 4 , Figure 4 This is a functional module diagram of an embodiment of the vehicle communication security testing device of this application, as shown below. Figure 4 As shown, the vehicle communication security testing device includes: The acquisition module 10 is used to acquire behavioral data of the vehicle communication system during the communication test between the vehicle communication system and the digital certificate, wherein the vehicle communication system is injected with the digital certificate, and the digital certificate is an illegal digital certificate. The behavior determination module 20 is used to determine the actual processing behavior of the vehicle communication system based on the behavior data. The strategy determination module 30 is used to determine the security attribute identifier of the digital certificate by detecting the validity period, certificate chain integrity, signature validity and revocation status of the digital certificate, and determine the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier. The comparison and detection module 40 is used to determine whether the safety response capability of the vehicle communication system passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy.

[0045] Furthermore, in one embodiment, the vehicle communication security testing device further includes a resilience testing module, used for: A legitimate digital certificate is injected into the vehicle communication system for communication testing, in order to test the communication recovery capability of the vehicle communication system.

[0046] Further, in one embodiment, the security attribute identifier includes identity trustworthiness, authorization validity, integrity, and time consistency. The determination of the security attribute identifier of the digital certificate by detecting its validity period, certificate chain integrity, signature validity, and revocation status is used for: The authenticity of the digital certificate is determined by detecting the integrity of the certificate chain and the validity of the signature. The authorization validity of the digital certificate is determined by detecting the revocation status of the digital certificate; The integrity of the digital certificate is determined by checking the signature validity of the digital certificate; The time consistency of the digital certificate is determined by comparing its validity period with the system time.

[0047] Furthermore, in one embodiment, the expected handling strategy includes normal communication, degraded communication, delayed verification, communication rejection, and forced interruption with recording of security alarms. The step of determining the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier is used for: Based on the identity trustworthiness, authorization validity, integrity, and time consistency of the digital certificate, the expected handling strategy corresponding to the vehicle communication system is determined by searching a preset judgment matrix. The preset judgment matrix includes the mapping relationship between identity trustworthiness, authorization validity, integrity, and time consistency and normal communication, downgraded communication, delayed verification, communication rejection, and forced interruption and recording of security alarms.

[0048] Furthermore, in one embodiment, the comparison and detection module 40 is used for: When the actual handling behavior is consistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have passed the test. When the actual handling behavior is inconsistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have failed the test.

[0049] The functions of each module in the above-mentioned vehicle communication security testing device correspond to the steps in the above-mentioned vehicle communication security testing method embodiment, and their functions and implementation processes will not be described in detail here.

[0050] Thirdly, embodiments of this application provide a vehicle communication security testing device.

[0051] Reference Figure 5 , Figure 5This is a schematic diagram of the hardware structure of the vehicle communication security testing equipment involved in the embodiments of this application. In the embodiments of this application, the vehicle communication security testing equipment may include a processor, a memory, a communication interface, and a communication bus.

[0052] The communication bus can be of any type and is used to interconnect the processor, memory, and communication interface.

[0053] The communication interface includes input / output (I / O) interfaces, physical interfaces, and logical interfaces used for interconnecting internal components of the vehicle communication safety testing equipment, as well as interfaces used for interconnecting the vehicle communication safety testing equipment with other devices (such as other computing devices or user equipment). Physical interfaces can be Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc.; user equipment can be displays, keyboards, etc.

[0054] Memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0055] The processor can be a general-purpose processor, which can call the vehicle communication security test program stored in the memory and execute the vehicle communication security test method provided in the embodiments of this application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed when the vehicle communication security test program is called can be referred to in the various embodiments of the vehicle communication security test method of this application, and will not be repeated here.

[0056] Those skilled in the art will understand that Figure 5 The hardware structure shown does not constitute a limitation of this application and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0057] Fourthly, embodiments of this application also provide a readable storage medium.

[0058] The present application has a readable storage medium storing a vehicle communication security test program, wherein when the vehicle communication security test program is executed by a processor, it implements the steps of the vehicle communication security test method described above.

[0059] The method implemented when the vehicle communication security test program is executed can be referred to in various embodiments of the vehicle communication security test method of this application, and will not be repeated here.

[0060] It should be noted that the sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0061] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. The terms "first," "second," and "third," etc., are used to distinguish different objects, etc., and do not indicate a sequence, nor do they limit "first," "second," and "third" to different types.

[0062] In the description of the embodiments of this application, terms such as "exemplary," "for example," or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a concrete manner.

[0063] In the description of the embodiments of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.

[0064] In some processes described in the embodiments of this application, multiple operations or steps are included in a specific order. However, it should be understood that these operations or steps may not be executed in the order they appear in the embodiments of this application, or they may be executed in parallel. The sequence number of the operation is only used to distinguish different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed sequentially or in parallel, and these operations or steps may be combined.

[0065] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.

[0066] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A vehicle communication security testing method, characterized in that, The vehicle communication security testing method includes: During the communication test between the vehicle communication system and the digital certificate, behavioral data of the vehicle communication system is collected, wherein the vehicle communication system is injected with the digital certificate, and the digital certificate is an illegal digital certificate; Based on the behavioral data, the actual processing behavior of the vehicle communication system is determined; By detecting the validity period, certificate chain integrity, signature validity, and revocation status of the digital certificate, the security attribute identifier of the digital certificate is determined, and based on the security attribute identifier, the expected handling strategy corresponding to the vehicle communication system is determined. By comparing whether the actual handling behavior is consistent with the expected handling strategy, it is determined whether the safety response capability of the vehicle communication system passes the test.

2. The vehicle communication security testing method as described in claim 1, characterized in that, After determining whether the safety response capability of the vehicle communication system passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy, the following steps are included: A legitimate digital certificate is injected into the vehicle communication system for communication testing, in order to test the communication recovery capability of the vehicle communication system.

3. The vehicle communication security testing method as described in claim 1, characterized in that, The security attribute identifiers include identity trustworthiness, authorization validity, integrity, and time consistency. The process of determining the security attribute identifiers of the digital certificate by detecting its validity period, certificate chain integrity, signature validity, and revocation status includes: The authenticity of the digital certificate is determined by detecting the integrity of the certificate chain and the validity of the signature. The authorization validity of the digital certificate is determined by detecting the revocation status of the digital certificate; The integrity of the digital certificate is determined by checking the signature validity of the digital certificate; The time consistency of the digital certificate is determined by comparing its validity period with the system time.

4. The vehicle communication security testing method as described in claim 3, characterized in that, The expected handling strategies include normal communication, degraded communication, delayed verification, communication rejection, and forced interruption with recording of security alarms. The determination of the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier includes: Based on the identity trustworthiness, authorization validity, integrity, and time consistency of the digital certificate, the expected handling strategy corresponding to the vehicle communication system is determined by searching a preset judgment matrix. The preset judgment matrix includes the mapping relationship between identity trustworthiness, authorization validity, integrity, and time consistency and normal communication, downgraded communication, delayed verification, communication rejection, and forced interruption and recording of security alarms.

5. The vehicle communication security testing method as described in claim 1, characterized in that, The step of determining whether the safety response capability of the vehicle communication system passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy includes: When the actual handling behavior is consistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have passed the test. When the actual handling behavior is inconsistent with the expected handling strategy, the safety response capability of the vehicle communication system is deemed to have failed the test.

6. A vehicle communication security testing device, characterized in that, The vehicle communication security testing device includes: The data acquisition module is used to collect behavioral data of the vehicle communication system during communication testing with the vehicle communication system using a digital certificate, wherein the vehicle communication system is injected with the digital certificate, and the digital certificate is an invalid digital certificate. The behavior determination module is used to determine the actual processing behavior of the vehicle communication system based on the behavior data. The strategy determination module is used to determine the security attribute identifier of the digital certificate by detecting the validity period, certificate chain integrity, signature validity and revocation status of the digital certificate, and determine the expected handling strategy corresponding to the vehicle communication system based on the security attribute identifier. The comparison and detection module is used to determine whether the safety response capability of the vehicle communication system passes the test by comparing whether the actual processing behavior is consistent with the expected handling strategy.

7. The vehicle communication security testing device as described in claim 6, characterized in that, The vehicle communication security testing device also includes a resilience testing module, used for: A legitimate digital certificate is injected into the vehicle communication system for communication testing, in order to test the communication recovery capability of the vehicle communication system.

8. The vehicle communication security testing device as described in claim 6, characterized in that, The security attribute identifier includes identity trustworthiness, authorization validity, integrity, and time consistency. The process of determining the security attribute identifier of the digital certificate by detecting its validity period, certificate chain integrity, signature validity, and revocation status is used for: The authenticity of the digital certificate is determined by detecting the integrity of the certificate chain and the validity of the signature. The authorization validity of the digital certificate is determined by detecting the revocation status of the digital certificate; The integrity of the digital certificate is determined by checking the signature validity of the digital certificate; The time consistency of the digital certificate is determined by comparing its validity period with the system time.

9. A vehicle communication security testing device, characterized in that, The vehicle communication security testing device includes a processor, a memory, and a vehicle communication security testing program stored in the memory and executable by the processor, wherein when the vehicle communication security testing program is executed by the processor, it implements the steps of the vehicle communication security testing method as described in any one of claims 1 to 5.

10. A readable storage medium, characterized in that, The readable storage medium stores a vehicle communication security test program, wherein when the vehicle communication security test program is executed by a processor, it implements the steps of the vehicle communication security test method as described in any one of claims 1 to 5.