Vehicle diagnostic security firewall policies, systems, and storage media

By embedding a hierarchical firewall module into the vehicle diagnostic system, the system identifies and monitors diagnostic devices, classifies permission levels, and performs dynamic verification. This solves the problems of insufficient verification of the legality of diagnostic devices and unreasonable permission control in existing technologies, achieving precise permission management and full-process security control, and improving the safety of vehicle ECUs and maintenance efficiency.

CN122394879APending Publication Date: 2026-07-14SHENZHEN BONOR TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN BONOR TECH CO LTD
Filing Date
2026-04-20
Publication Date
2026-07-14

AI Technical Summary

Technical Problem

Existing vehicle diagnostic systems lack effective verification of the legitimacy of diagnostic equipment and operating permissions, leading to the risk of unauthorized ECU tampering. Furthermore, unreasonable access control and incompatibility with third-party diagnostic equipment affect repair efficiency and safety.

Method used

An embedded hierarchical firewall module is used in the vehicle diagnostic system to identify the hardware information and identity of the diagnostic equipment, divide it into N permission levels, monitor the operation behavior in real time, and perform dynamic verification and security control, including disconnection, locking ECU operation, and logging.

Benefits of technology

It enables refined access control for different diagnostic devices and operating functions, ensures ECU security, is compatible with manufacturer and third-party devices, improves diagnostic efficiency and security, and provides traceability and reliability of operating behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122394879A_ABST
    Figure CN122394879A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of vehicle diagnosis security, and particularly relates to a vehicle diagnosis security firewall strategy, a system and a storage medium.The vehicle diagnosis security firewall strategy comprises: an embedded firewall module integrated in a vehicle self-diagnosis system, which establishes a communication link with a vehicle ECU and is used for performing access detection of a diagnosis device, permission level verification and operation behavior monitoring; a diagnosis function grading module which divides diagnosis functions into N permission levels according to the safety risk level of diagnosis operation, and each level corresponds to a specific operation range and verification standard; a verification and control module which is used for receiving an operation request of the diagnosis device, extracting the function level corresponding to the request and comparing with the preset verification standard, and opening the operation permission of the corresponding level after verification.The present application realizes accurate permission verification and whole-process dynamic security control of diagnosis operation, and solves the problem that different diagnosis devices and different operation functions cannot be finely controlled.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle diagnostic security technology, and in particular to a vehicle diagnostic security firewall strategy, system, and storage medium. Background Technology

[0002] With the continuous improvement of automotive electronics and intelligence, core vehicle control functions (such as power control, braking control, and body control) all rely on the onboard ECU, making the ECU a core component for safe vehicle operation. Currently, automotive fault diagnosis scenarios mainly fall into two categories: first, after-sales repair and diagnosis designated by the vehicle manufacturer, using manufacturer-specific diagnostic equipment and possessing compliant diagnostic permissions and operating procedures; second, repair and diagnosis by third-party repair shops, which, due to limitations such as cost and authorization, typically use non-manufacturer-specific diagnostic equipment and lack unified standards for access control.

[0003] With the rapid development of the third-party repair market, the use of non-manufacturer diagnostic equipment is becoming increasingly widespread. However, existing vehicle diagnostic systems and related protection technologies have the following core pain points: Lack of security protection: Most existing vehicle diagnostic systems only implement the "diagnostic connection" function and do not effectively verify the legitimacy of diagnostic equipment and operating permissions. Third-party, non-manufacturer diagnostic equipment can be freely connected to the vehicle's ECU, posing a risk of malicious operation and illegal tampering.

[0004] Inadequate access control: Traditional diagnostic access control often follows a binary model of "full access" or "no access," failing to assign corresponding permissions based on the actual functions performed by the diagnostic equipment (such as basic fault reading, ECU parameter modification, core program refresh, etc.). This "one-size-fits-all" approach either restricts normal repair operations or excessively grants permissions, leading to safety hazards.

[0005] ECU security risks are significant: As the core control unit of a vehicle, unauthorized modification of its parameters and programs can directly affect vehicle operational safety, potentially leading to loss of control, frequent malfunctions, and other safety incidents. Current technology cannot effectively mitigate these risks.

[0006] Poor compatibility: Some existing protection technologies are only compatible with the manufacturer's proprietary diagnostic equipment and cannot meet the normal diagnostic needs of third-party diagnostic equipment. This affects the efficiency of third-party repairs and fails to achieve full-scenario diagnostic security protection. Summary of the Invention

[0007] To address the shortcomings of existing technologies, this invention proposes a vehicle diagnostic security firewall strategy, system, and storage medium, aiming to solve the problem of not being able to perform fine-grained access control for different diagnostic devices and different operating functions.

[0008] The technical solution proposed in this invention is: A vehicle diagnostic security firewall policy includes: The embedded firewall module is integrated into the vehicle's own diagnostic system and establishes a communication link with the vehicle's ECU to perform access detection of diagnostic equipment, permission level verification, and operation behavior monitoring. The diagnostic function classification module divides the diagnostic function into N permission levels based on the security risk level of the diagnostic operation. Each level corresponds to a clear operation scope and verification standard. The verification and control module is used to receive operation requests from diagnostic equipment, extract the corresponding function level of the request and compare it with the preset verification standard. After the verification is passed, the corresponding level of operation permission is granted.

[0009] Furthermore, the embedded firewall module includes: The self-diagnostic unit is used to detect the firewall's own operating status in real time. Access detection unit, used to identify the hardware information and identity of diagnostic equipment; The permission level verification unit is used to compare the execution function level with the verification standard. The operation behavior monitoring unit is used to monitor the operation behavior of the diagnostic equipment in real time throughout the entire diagnostic operation process.

[0010] Furthermore, the diagnostic function grading module divides the diagnostic function into five levels: Level 1: Basic fault reading permissions; Level 2: Access to clear fault codes and view basic parameters; Level 3: Standard parameter configuration and detection permissions; Level 4: Permission to modify non-core ECU parameters; Level 5: ECU core program refresh and key parameter configuration permissions.

[0011] Furthermore, the verification and control module implements a dynamic verification mechanism: it performs an initial verification when the diagnostic device is connected, and continuously performs dynamic verification throughout the entire diagnostic operation; when an operation is detected to exceed the corresponding level of permission, a security control action is immediately triggered.

[0012] Furthermore, the safety control actions include at least one of the following: disconnecting the diagnostic connection, locking ECU-related operations, triggering a vehicle alarm, or recording an anomaly log.

[0013] Furthermore, the embedded firewall module has compatibility and adaptability capabilities: it can identify manufacturer-specific diagnostic devices and third-party non-manufacturer diagnostic devices, and perform differentiated verification standards for different types of diagnostic devices.

[0014] Furthermore, the diagnostic function grading module supports customizable permission levels: for different brands or different vehicle models, the operation range and verification standards of each level can be customized.

[0015] The present invention also provides a vehicle diagnostic security firewall system, comprising: Onboard ECU control unit; The embedded firewall module is integrated into the vehicle's own diagnostic system and communicates with both the diagnostic equipment and the on-board ECU control unit. The diagnostic function classification module is connected to the embedded firewall module and stores preset permission level classification rules. The verification and control module is connected to the embedded firewall module and the diagnostic function hierarchical module respectively to perform permission verification and operation control.

[0016] Furthermore, the verification and control module includes: The request receiving unit is used to receive access requests and operation instructions from diagnostic equipment. The permission granting unit is used to grant the corresponding level of operation permissions after verification. The anomaly logging unit is used to perform security control actions and record logs when abnormal behavior is detected.

[0017] The present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of any of the strategies described above.

[0018] Based on the above technical solution, the beneficial effects of this invention are as follows: It abandons the traditional "one-size-fits-all" diagnostic permission control mode, and by embedding and integrating a hierarchical firewall mechanism into the vehicle's own diagnostic system, it divides the permission level according to the danger level of the function performed by the diagnostic equipment, realizes accurate permission verification and dynamic security control of the entire process of diagnostic operations, and solves the problem of not being able to carry out fine-grained permission control for different diagnostic equipment and different operating functions. Attached Figure Description

[0019] Figure 1 This is a functional block diagram of the vehicle diagnostic security firewall provided in the embodiments of the present invention; Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0021] like Figure 1 As shown, this embodiment of the invention proposes a vehicle diagnostic security firewall strategy, including: The embedded firewall module is integrated into the vehicle's own diagnostic system and establishes a communication link with the vehicle's ECU to perform access detection of diagnostic equipment, permission level verification, and operation behavior monitoring. The diagnostic function classification module divides the diagnostic function into N permission levels based on the security risk level of the diagnostic operation. Each level corresponds to a clear operation scope and verification standard. The verification and control module is used to receive operation requests from diagnostic equipment, extract the corresponding function level of the request and compare it with the preset verification standard. After the verification is passed, the corresponding level of operation permission is granted.

[0022] Abandoning the traditional "one-size-fits-all" diagnostic permission control model, this system integrates a hierarchical firewall mechanism embedded in the vehicle's own diagnostic system. Permission levels are divided according to the risk level of the functions performed by the diagnostic equipment, enabling precise permission verification and dynamic safety control throughout the diagnostic operation process. This solves the problem of not being able to perform refined permission control for different diagnostic equipment and different operating functions.

[0023] In this embodiment, the embedded firewall module includes: The self-diagnostic unit is used to detect the firewall's own operating status in real time. Access detection unit, used to identify the hardware information and identity of diagnostic equipment; The permission level verification unit is used to compare the execution function level with the verification standard. The operation behavior monitoring unit is used to monitor the operation behavior of the diagnostic equipment in real time throughout the entire diagnostic operation process.

[0024] The self-diagnostic unit periodically checks the firewall's operating status; the access detection unit listens for diagnostic device access events on the vehicle's OBD interface; the permission level verification unit executes permission comparison logic; and the operation behavior monitoring unit tracks diagnostic operations in real time.

[0025] In this embodiment, the diagnostic function grading module divides the diagnostic function into five levels: Level 1: Basic fault reading permissions; Level 2: Access to clear fault codes and view basic parameters; Level 3: Standard parameter configuration and detection permissions; Level 4: Permission to modify non-core ECU parameters; Level 5: ECU core program refresh and key parameter configuration permissions.

[0026] Basic fault reading, such as reading current fault codes and freeze frame data; fault code clearing and basic parameter viewing, such as reading VIN codes and software version numbers; routine parameter configuration and sensor detection, such as reading and writing adaptation values ​​and testing actuators; modification of non-core ECU parameters, such as adjusting body control module parameters; ECU core program refresh and key parameter configuration, such as rewriting engine control units and anti-theft matching.

[0027] In this embodiment, the verification and control module acts as the permission execution unit and works in conjunction with the firewall module.

[0028] In this embodiment, the verification and control module implements a dynamic verification mechanism: it performs an initial verification when the diagnostic device is connected, and continuously performs dynamic verification throughout the entire diagnostic operation; when the operation behavior is detected to exceed the corresponding level of permission, a security control action is immediately triggered.

[0029] In this embodiment, the safety control actions include at least one of the following: disconnecting the diagnostic connection, locking ECU-related operations, triggering a vehicle alarm, and recording an anomaly log.

[0030] In this embodiment, the embedded firewall module has compatibility and adaptability: it can identify manufacturer-specific diagnostic devices and third-party non-manufacturer diagnostic devices, and perform differentiated verification standards for different types of diagnostic devices.

[0031] In this embodiment, the diagnostic function classification module supports customizable permission levels: for different brands or different vehicle models, the operation range and verification standards of each level can be customized.

[0032] In this embodiment, after the vehicle is started (ignition switch ON), the embedded firewall module automatically starts, and the self-diagnostic unit performs a self-test to confirm the integrity of the firewall configuration file, the status of the communication link, and the log storage space. After the self-test passes, the firewall establishes a dedicated secure communication link with each ECU of the vehicle and synchronizes the ECU's security control parameters. The initialization of the five-level permission verification standards is as follows: for example, levels one and two only require verification of the basic device identifier; levels three and four require verification of the device digital certificate; and level five requires verification of both the authorization certificate and the operation password.

[0033] In this embodiment, if the diagnostic process ends normally, the diagnostic device sends a disconnect command. After confirming that no operation is in progress, the firewall closes the communication link, releases permissions, and updates the operation log (recording device information, operation time, and the level of function executed). If the diagnostic device disconnects abnormally (e.g., by directly unplugging the cable), the firewall automatically closes the link and locks permissions after a preset timeout period (e.g., 60 seconds). If the connection is forcibly severed due to unauthorized behavior, the firewall simultaneously locks the relevant ECU operation interfaces to prevent subsequent malicious access.

[0034] To make it easier to understand, let's illustrate with an example: If a manufacturer-specific diagnostic device is connected, after the device connects to the OBD interface, the access detection unit reads the device's hardware ID and digital certificate, identifies it as an authorized device, and sends an operation request to execute "ECU core program refresh" (corresponding to level 5 permission). The permission level verification unit extracts the request function level as level 5, triggering the highest-level verification process—verifying the validity of the device's authorization certificate and verifying the operator's temporary authorization code; after both verifications are successful, the verification passes. The permission granting unit grants the diagnostic device level 5 permission, allowing it to perform ECU flashing operations. Simultaneously, the operation behavior monitoring unit starts full-process monitoring, recording each erase and write operation. After flashing is complete, the diagnostic device actively disconnects. After the firewall detects no operation timeout (e.g., 30 seconds), it automatically closes the communication link and locks the permission.

[0035] If a third-party diagnostic device is connected, after connecting to the OBD interface, the access detection unit identifies it as a non-manufacturer device and marks it as a "third-party device." The diagnostic device sends operation requests to perform "clear fault codes" (corresponding to level 2 permission) and "adjust engine idle speed parameters" (corresponding to level 3 permission). For level 2 permission (clearing fault codes), the device's basic identifier is verified and level 2 permission is granted. For level 3 permission (adjusting idle speed parameters), verification reveals that the third-party device has not been authorized for level 3 permission, and verification fails. The firewall only grants level 1 and 2 permissions (basic fault reading and clearing) to the third-party device, prohibiting the execution of level 3 and above operations. The operation behavior monitoring unit records the device's attempts to perform unauthorized operations. If the device continues to attempt to send unauthorized commands, the anomaly handling unit triggers control: disconnecting the diagnostic connection, locking ECU operation for 30 minutes, and uploading the abnormal event to the vehicle network platform.

[0036] In this embodiment, the firewall does not perform verification only once upon access. Taking a manufacturer's device performing a level 5 flashing operation as an example: During the flashing process, the operation behavior monitoring unit analyzes the target address and operation type of each instruction in real time. If it detects that the diagnostic device is attempting to access an unauthorized address space (such as writing illegal data to a reserved area), it is immediately identified as abnormal behavior. The anomaly handling unit disconnects the diagnostic connection within milliseconds, locks the ECU flashing function, records a complete attack log, and triggers an alarm on the dashboard.

[0037] Compared with the prior art, the present invention has the following beneficial effects: Outstanding security: Through a tiered verification and dynamic control mechanism, it accurately avoids the risks of unauthorized tampering and malicious operation of the ECU by third-party diagnostic equipment, ensuring the safety of the vehicle ECU and the overall vehicle operation from the source, and solving the core pain point of the lack of protection in existing technologies. Even if high-level permissions are temporarily granted, the full-process behavior monitoring can still detect and block abnormal operations in a timely manner.

[0038] Highly practical: The five-level hierarchical access control design caters to the dual needs of both manufacturer after-sales service and third-party repair. Manufacturer-dedicated diagnostic equipment can quickly obtain high-level access through a preset high-efficiency verification channel, ensuring efficient after-sales diagnostics; third-party equipment obtains reasonable operating permissions within the regulated framework, avoiding the inconvenience of repairs caused by a "one-size-fits-all" approach.

[0039] Excellent compatibility: The embedded firewall is directly integrated into the vehicle's own diagnostic system, eliminating the need for external hardware and avoiding compatibility and stability issues associated with external protection devices. Furthermore, the firewall can recognize various diagnostic devices, requiring no large-scale vehicle modifications, making it easy to implement and compatible with various civilian and commercial vehicles equipped with ECUs.

[0040] High traceability: The operation log recording function can completely retain the access information, operation behavior, and timestamps of the diagnostic equipment. In case of security issues, the source can be quickly traced back to the specific equipment and operation, facilitating responsibility identification and problem troubleshooting.

[0041] High reliability: The firewall module has a self-diagnostic function, which can monitor its own operating status in real time. Once a firewall anomaly is detected, it can promptly take downgrade protection or alarm measures to prevent the vehicle from losing safety protection due to firewall failure.

[0042] The present invention also provides a vehicle diagnostic security firewall system, comprising: Onboard ECU control unit; The embedded firewall module is integrated into the vehicle's own diagnostic system and communicates with both the diagnostic equipment and the on-board ECU control unit. The diagnostic function classification module is connected to the embedded firewall module and stores preset permission level classification rules. The verification and control module is connected to the embedded firewall module and the diagnostic function hierarchical module respectively to perform permission verification and operation control.

[0043] Abandoning the traditional "one-size-fits-all" diagnostic permission control model, this system integrates a hierarchical firewall mechanism embedded in the vehicle's own diagnostic system. Permission levels are divided according to the risk level of the functions performed by the diagnostic equipment, enabling precise permission verification and dynamic safety control throughout the diagnostic operation process. This solves the problem of not being able to perform refined permission control for different diagnostic equipment and different operating functions.

[0044] In this embodiment, the verification and control module includes: The request receiving unit is used to receive access requests and operation instructions from diagnostic equipment. The permission granting unit is used to grant the corresponding level of operation permissions after verification. The anomaly logging unit is used to perform security control actions and record logs when abnormal behavior is detected.

[0045] An embodiment of the present invention also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements a vehicle diagnostic security firewall strategy, specifically as follows: The embedded firewall module is integrated into the vehicle's own diagnostic system and establishes a communication link with the vehicle's ECU to perform access detection of diagnostic equipment, permission level verification, and operation behavior monitoring. The diagnostic function classification module divides the diagnostic function into N permission levels based on the security risk level of the diagnostic operation. Each level corresponds to a clear operation scope and verification standard. The verification and control module is used to receive operation requests from diagnostic equipment, extract the corresponding function level of the request and compare it with the preset verification standard. After the verification is passed, the corresponding level of operation permission is granted.

[0046] The storage medium of this invention abandons the traditional "one-size-fits-all" diagnostic permission control mode. By embedding a hierarchical firewall mechanism into the vehicle's own diagnostic system, permission levels are divided according to the danger level of the functions performed by the diagnostic equipment. This enables precise permission verification and dynamic security control of the entire diagnostic operation process, solving the problem of not being able to perform fine-grained permission control for different diagnostic equipment and different operating functions.

[0047] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the present invention and embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual-rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0048] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A vehicle diagnostic security firewall strategy, characterized in that, include: The embedded firewall module is integrated into the vehicle's own diagnostic system and establishes a communication link with the vehicle's ECU to perform access detection of diagnostic equipment, permission level verification, and operation behavior monitoring. The diagnostic function classification module divides the diagnostic function into N permission levels based on the security risk level of the diagnostic operation. Each level corresponds to a clear operation scope and verification standard. The verification and control module is used to receive operation requests from diagnostic equipment, extract the corresponding function level of the request and compare it with the preset verification standard. After the verification is passed, the corresponding level of operation permission is granted.

2. The vehicle diagnostic security firewall strategy according to claim 1, characterized in that, The embedded firewall module includes: The self-diagnostic unit is used to detect the firewall's own operating status in real time. Access detection unit, used to identify the hardware information and identity of diagnostic equipment; The permission level verification unit is used to compare the execution function level with the verification standard. The operation behavior monitoring unit is used to monitor the operation behavior of the diagnostic equipment in real time throughout the entire diagnostic operation process.

3. The vehicle diagnostic security firewall strategy according to claim 2, characterized in that, The diagnostic function classification module divides diagnostic functions into five levels: Level 1: Basic fault reading permissions; Level 2: Access to clear fault codes and view basic parameters; Level 3: Standard parameter configuration and detection permissions; Level 4: Permission to modify non-core ECU parameters; Level 5: ECU core program refresh and key parameter configuration permissions.

4. The vehicle diagnostic security firewall strategy according to claim 1, characterized in that, The verification and control module implements a dynamic verification mechanism: it performs an initial verification when the diagnostic device is connected, and continuously performs dynamic verification throughout the entire diagnostic operation; when an operation is detected to exceed the corresponding level of permission, a security control action is immediately triggered.

5. The vehicle diagnostic security firewall strategy according to claim 4, characterized in that, The safety control actions include at least one of the following: disconnecting the diagnostic connection, locking ECU-related operations, triggering a vehicle alarm, or recording an anomaly log.

6. The vehicle diagnostic security firewall strategy according to claim 1, characterized in that, The embedded firewall module has compatibility and adaptability capabilities: it can identify manufacturer-specific diagnostic devices and third-party non-manufacturer diagnostic devices, and perform differentiated verification standards for different types of diagnostic devices.

7. The vehicle diagnostic security firewall strategy according to claim 2, characterized in that, The diagnostic function grading module supports customizable permission levels: for different brands or different vehicle models, the operation range and verification standards of each level can be customized.

8. A vehicle diagnostic security firewall system, characterized in that, include: Onboard ECU control unit; The embedded firewall module is integrated into the vehicle's own diagnostic system and communicates with both the diagnostic equipment and the on-board ECU control unit. The diagnostic function classification module is connected to the embedded firewall module and stores preset permission level classification rules. The verification and control module is connected to the embedded firewall module and the diagnostic function hierarchical module respectively to perform permission verification and operation control.

9. The vehicle diagnostic security firewall system according to claim 8, characterized in that, The verification and control module includes: The request receiving unit is used to receive access requests and operation instructions from diagnostic equipment. The permission granting unit is used to grant the corresponding level of operation permissions after verification. The anomaly logging unit is used to perform security control actions and record logs when abnormal behavior is detected.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the strategy according to any one of claims 1 to 7.