A UDS security access evaluation system based on an automatic explosion and seed collection fusion mechanism
The UDS security access assessment system, which integrates automated blasting and seed collection mechanisms, solves the problem of insufficient assessment of the randomness and predictability of UDS seeds in existing technologies. It achieves stable sample collection and standardized assessment under ECU delay and locking mechanisms, and provides a comprehensive and reproducible security strength evaluation of UDS security access.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ANHUI JIANGHUAI AUTOMOBILE GRP CORP LTD
- Filing Date
- 2026-05-07
- Publication Date
- 2026-07-31
AI Technical Summary
Existing technologies lack quantitative analysis of the randomness and predictability of seed generation algorithms when evaluating UDS secure access services. They also have low automation levels and cannot fully reflect the true security level of UDS secure access mechanisms. In particular, testing is difficult to automate continuously under ECU delay and locking mechanisms.
A UDS security access assessment system based on an automated brute-force and seed collection fusion mechanism is adopted. Through a multi-mode brute-force engine, a dynamic seed collection and caching module, an incremental statistical detection and decision scheduling engine, combined with sliding window randomness detection, it realizes automated collection and randomness detection of UDS seeds and outputs a standardized assessment report.
It achieves stable acquisition of UDS seed samples under ECU delay and locking mechanism, and generates a comprehensive and reproducible security access strength evaluation through multi-mode blasting and randomness detection, providing a standardized quantitative assessment report.
Smart Images

Figure CN122496258A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of vehicle electronic control technology, specifically relating to a UDS security access assessment system based on an automated blasting and seed collection fusion mechanism. Background Technology
[0002] With the rapid development of automotive electronics and intelligence, the number of on-board electronic control units (ECUs) is constantly increasing. To realize in-vehicle diagnostics, communication, and firmware management, the international standard ISO 14229 defines the Unified Diagnostic Services (UDS) protocol.
[0003] In the UDS protocol, the Secure Access Service (Service 0x27) is a key mechanism for preventing unauthorized access. It is based on a "Seed-Key" authentication process.
[0004] (1) The tester sends a request (Request Seed);
[0005] (2) The ECU returns a random seed;
[0006] (3) The tester calculates the key according to the algorithm and returns it for verification;
[0007] (4) If the verification is successful, the protected functions can be accessed.
[0008] Current research and evaluation of UDS security primarily focus on brute-force testing, i.e., verifying whether it can be cracked. However, with the deepening of research on automotive security, this single security verification method has gradually exposed the following problems:
[0009] Focusing solely on cracking capabilities while ignoring randomness: lacking an assessment of the randomness and predictability of seed generation algorithms.
[0010] Low level of automation: Due to the influence of ECU protection mechanisms (such as time-delay locking and access limit), the testing process requires a lot of manual intervention.
[0011] Lack of quantitative standards: There is currently no unified randomness testing system for assessing the security strength of UDS seeds.
[0012] Therefore, existing testing methods cannot fully reflect the true security level of the UDS secure access mechanism, especially in terms of the randomness and anti-predictability of the seed generation algorithm.
[0013] To address the aforementioned problems, the main technical approaches currently include:
[0014] (1) General diagnostic analysis tools: such as Vector CANoe / CANalyzer, which can realize UDS service calls and simple brute-force attacks through CAPL scripts.
[0015] (2) Open source diagnostic frameworks: such as the Python library udsoncan, which can perform basic Seed-Key processes, but lacks automation and security analysis capabilities.
[0016] (3) Randomness detection tools: such as the NIST SP 800-22 Statistical Test Suite, which can be used to evaluate the quality of pseudo-random number generators, but has not yet been applied to the field of randomness detection of UDS seeds.
[0017] Based on a comprehensive analysis of the existing technologies mentioned above, their main shortcomings are reflected in the following five aspects:
[0018] (1) Insufficient functional targeting: Unable to automatically assess the security strength of UDS 0x27 service.
[0019] (2) Single evaluation dimension: lack of seed randomness and predictability detection.
[0020] (3) Low level of automation: unable to cope with the delay and locking mechanism of ECU.
[0021] (4) Significant sample limitations: NIST SP 800-22 testing requires a large number of samples, while UDS seed length is short and collection speed is slow.
[0022] (5) Results are not quantifiable: There is a lack of standardized scoring and reporting systems.
[0023] Therefore, there is an urgent need for a comprehensive evaluation method that combines automated blasting capabilities with seed randomness / predictability detection. This method should provide a more comprehensive, quantifiable, and reproducible evaluation of the security access strength of UDS 0x27 from two dimensions: "cracking capability" and "randomness strength," and should be able to be stably implemented under protection constraints such as ECU delay and locking. Summary of the Invention
[0024] The purpose of this invention is to provide a UDS security access assessment system based on an automated brute-force attack and seed collection fusion mechanism. This addresses the problems of existing assessment methods for UDS security access services (Service 0x27) that typically only focus on "whether it can be successfully brute-forced," lacking quantitative analysis of the randomness and predictability of seeds; and the difficulties in sample collection, continuous automated testing, and the lack of unified and comparable quantitative indicators for assessment conclusions caused by ECU delay / locking and other protective mechanisms. The invention aims to achieve the following:
[0025] (1) A large number of UDS 0x27 Seed samples were continuously and stably collected during the automated blasting test.
[0026] (2) By using the sliding window splicing algorithm, scattered and short-length seeds are organized into detection sequences that are compatible with NIST SP800-22, so as to realize the statistical test of the randomness and predictability of seeds.
[0027] (3) Construct multi-mode brute-force / deduction capabilities (such as exhaustive search, common shift / rotation, XOR and other modes), and integrate the "randomness / predictability detection results" with the "success difficulty and cost under different attack modes" to form a comprehensive scoring algorithm and output a standardized quantitative evaluation report, thereby obtaining a more comprehensive, reproducible and comparable UDS 0x27 security access strength evaluation conclusion.
[0028] To achieve the above objectives, this application employs the following technical solution:
[0029] A UDS security access assessment system based on an automated brute-force attack and seed acquisition fusion mechanism includes:
[0030] The UDS communication and service enumeration module is used to automatically identify the communication parameters and security level services of the target ECU.
[0031] A multi-mode automated brute-force engine is used to support multiple brute-force modes and schedule execution according to a strategy, and supports key brute-force cracking, delay adaptation and recovery mechanism;
[0032] A dynamic seed acquisition and caching module is used to capture seed response data in real time during the blasting process;
[0033] Incremental statistical detection module, based on the sliding window randomness detection principle of NIST SP800-22;
[0034] The decision scheduling engine is used to adjust the blasting strategy and sampling frequency based on real-time detection results;
[0035] The state persistence and breakpoint recovery module is used to record test status and progress;
[0036] The comprehensive report generation module is used to output standardized security assessment results.
[0037] Furthermore, the assessment method adopts the following steps:
[0038] S1, Automated seed collection and blasting fusion;
[0039] S2, Incremental randomness detection, adopts a randomness detection mechanism of initial accumulation + sliding window + incremental update + multi-window robust convergence;
[0040] S3. State persistence and recovery mechanism: The system continuously records and saves key state information and supports breakpoint recovery, making the testing process traceable and reproducible, and facilitating long-term or phased testing.
[0041] S4. Output a quantitative report. After the termination conditions are met, the system generates a standardized evaluation report and outputs a comprehensive strength score.
[0042] S5. After the system initializes and identifies the ECU and the 0x27 security level, it starts the parallel process: continuously triggers and collects Seeds. The randomness detection module starts generating windows and executing SP800-22 after L≥W, continuously outputting R and key degradation window information. The decision scheduling engine dynamically adjusts the strategy based on randomness and attack progress, and performs backoff and recovery when encountering delay / lock. After the test is completed, the system generates a standardized report.
[0043] Furthermore, in step S1, the specific steps for the automated seed collection and blasting fusion are as follows:
[0044] When performing UDS 0x27 related interactions and attack attempts, the system adopts a parallel mechanism: on the one hand, it continuously triggers the ECU to return the Seed and collects and writes it into the sample pool; on the other hand, it performs attack attempts on the Seed-Key process under the same security level and records the number of attempts, time consumption, triggered NRC / lock information, and whether the unlocking was successful for each mode.
[0045] Furthermore, the multi-mode attack engine includes the following attack modes:
[0046] S11, Mode A is an exhaustive / enumeration mode. Under the condition that the key space range or key length is known, it tries according to a predetermined enumeration order. It is suitable for evaluating the "cost of pure brute force cracking".
[0047] S12 and Mode B are common shift / rotation derivation modes. Based on common transformation assumptions such as displacement, cyclic shift, splicing / truncation between Seed and Key, candidate Keys are constructed and verified. This mode belongs to low-cost heuristic derivation and is used to quickly identify weak algorithms.
[0048] S13, Mode C is the XOR deduction mode, which generates and verifies candidate keys based on the common XOR relationship between Seed and Key. This mode belongs to a common weak implementation of fast identification method.
[0049] S14 and Mode D are combined heuristic modes that combine the above operators such as shift / rotate, XOR, addition / subtraction, inversion, and byte swapping into a limited depth to form a constrained candidate generation space, so as to cover more common implementations under controllable cost.
[0050] Furthermore, in step S2, the incremental randomness detection process includes:
[0051] S21, Initial length threshold triggered;
[0052] S22. Sliding window construction and incremental update;
[0053] S23. Multi-window result aggregation and subtest score calculation;
[0054] S24, Overall window pass rate is used for local degradation positioning.
[0055] Furthermore, in step S3, the system continuously records and saves key status information, including at least the Seed sample pool summary, global bitstream construction progress, window parameters W, step size S, current total number of windows K, multi-mode attack engine attempt progress, and protection trigger statistics.
[0056] Furthermore, in step S4, the output quantitative report shall include at least: randomness analysis conclusions, multi-mode attack conclusions, protection performance conclusions, comprehensive score and level, evidence chain and rectification recommendations.
[0057] The beneficial effects of this invention are:
[0058] 1) Seed sliding window splicing and incremental randomness detection link: including seed bitization, global bit stream construction, threshold triggering that satisfies L≥W, generating window X_k according to W and S, and robustly aggregating and outputting R from the multi-window SP800-22 results.
[0059] 2) Multi-mode brute-force / deduction engine and scheduling mechanism: It includes at least exhaustive / enumeration, shift / round-robin deduction, and XOR deduction, and can be extended to combine heuristic and rule base patterns for hierarchical evaluation of cracking difficulty.
[0060] 3) Comprehensive scoring and report output mechanism: A comprehensive score is obtained based on the weighted fusion of R, B and D, and it supports the triggering of penalties and corrections for key defects, and finally outputs a standardized report and evidence chain. Attached Figure Description
[0061] Figure 1 This is a flowchart of the system operation of the present invention. Detailed Implementation
[0062] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings. The following embodiments are merely exemplary and can only be used to explain and illustrate the technical solution of the present invention, and should not be construed as limiting the technical solution of the present invention.
[0063] This application provides a UDS security access assessment system based on an automated brute-force attack and seed acquisition fusion mechanism, including:
[0064] The UDS communication and service enumeration module is used to automatically identify the communication parameters and security level services of the target ECU.
[0065] A multi-mode automated brute-force engine that supports multiple brute-force modes and schedules execution according to a strategy, supporting key brute-force cracking, delay adaptation, and recovery mechanisms.
[0066] The dynamic seed acquisition and caching module is used to capture seed response data in real time during the blasting process.
[0067] The incremental statistical detection module is based on the sliding window randomness detection principle of NIST SP800-22.
[0068] The decision scheduling engine is used to adjust the blasting strategy and sampling frequency based on real-time detection results.
[0069] The state persistence and breakpoint recovery module is used to record test status and progress.
[0070] The comprehensive report generation module is used to output standardized security assessment results.
[0071] like Figure 1 As shown, an evaluation method for a UDS security access assessment system based on an automated blasting and seed acquisition fusion mechanism adopts the following steps:
[0072] S1. Fusion of automated seed collection and explosive processing:
[0073] When performing UDS 0x27 related interactions and attack attempts, the system adopts a parallel mechanism: on the one hand, it continuously triggers the ECU to return the Seed and collects and writes it into the sample pool; on the other hand, it performs attack attempts on the Seed-Key process under the same security level and records the number of attempts, time consumption, triggered NRC / lock information, and whether the unlocking was successful for each mode.
[0074] The multi-mode attack engine includes the following attack modes:
[0075] S11, Mode A is an exhaustive / enumeration mode. Given the known range of Key space or Key length, it attempts according to a predetermined enumeration order, which is suitable for evaluating the "cost of pure brute-force cracking".
[0076] S12 and Mode B are common shift / rotation derivation modes. Based on common transformation assumptions between Seed and Key, such as displacement, cyclic shift (Rotate), splicing / truncation, etc., candidate Keys are constructed and verified. This mode belongs to low-cost heuristic derivation and is used to quickly identify weak algorithms.
[0077] S13, Mode C is an XOR derivation mode, which generates and verifies candidate keys based on the common XOR relationship between Seed and Key. This mode is a common, weakly implemented, fast identification method.
[0078] S14 and Mode D are combined heuristic modes that combine the above operators such as shift / rotate, XOR, addition / subtraction, inversion, and byte swapping into a limited depth to form a constrained candidate generation space, so as to cover more common implementations under controllable cost.
[0079] The system will log the "success mode", number of attempts, time taken and protection trigger status for each successful unlock, which will serve as an important input for subsequent comprehensive scoring.
[0080] S2, Incremental randomness detection:
[0081] To address the issue that UDS 0x27 Seeds are typically "short, small, and discrete," making it difficult to directly meet the NIST SP800-22 requirements for input sequence length and continuity, this application employs a randomness detection mechanism combining "initial accumulation + sliding window + incremental update + multi-window robust convergence." To avoid symbolic ambiguity, the variables involved in this section are defined uniformly:
[0082] The collected Seeds are converted into binary bit strings according to the preset byte order and bit order, and then continuously spliced together in the collection order to form a global bit stream; the current length of the global bit stream (in bits) is denoted as L.
[0083] Set the sliding window length (in bits) to W and the step size (in bits) to S.
[0084] When generating the k-th window sample (k is a non-negative integer starting from 0), the window sample is denoted as X. k Its corresponding interval in the global bitstream is [kS, kS+W).
[0085] The total number of windows currently participating in the statistics is denoted as K (i.e., k=0 to k=K-1).
[0086] The selected subtest set in SP800-22 is denoted as T = {t1, t2, …, t}. m}, where m is the number of subtests.
[0087] For any window X k AND subtest t i The SP800-22 outputs a p-value, denoted as p. k,i , denoted as b k,i ∈{0,1} (pass = 1, fail = 0).
[0088] Under the above definition, the detection process of this application includes:
[0089] Initial length threshold trigger: When the global bitstream length does not reach the window length (i.e., L < W), the system only performs seed accumulation and quality labeling, without generating window samples or executing SP800-22; when L ≥ W, the first window generation is triggered and the detection phase begins.
[0090] Sliding window construction and incremental update: Based on L ≥ W, the system generates a window sample set {X} with a step size S. k As new seeds are continuously added, causing L to grow, when a new available window appears, SP800-22 is only executed on the newly added window, and subsequent statistics are incrementally updated to avoid duplicate calculations for existing windows.
[0091] Multi-window result aggregation and subtest score calculation: To avoid overall misjudgment caused by "random fluctuations in a single window", the system aggregates the results of the same subtest in multiple windows to form a pass rate item and a stability item, and can introduce a continuous failure penalty item.
[0092] Subtest pass rate: Define the cross-window pass rate for each subtest ti:
[0093]
[0094] Stability metric: First, define the cross-window mean of the p-value:
[0095]
[0096] Redefining the cross-window volatility measure σ of p-value i (Standard deviation):
[0097]
[0098] And a scale parameter τ is introduced for normalization. p If >0, the stability term Stab is obtained. i ∈[0,1]:
[0099]
[0100] The function of min(·) is to trim the stability term to the [0,1] interval. The stability term is used to suppress occasional failures caused by short-term noise, improve the robustness of the conclusions, and thus reduce false alarms.
[0101] Consecutive failure penalty: Define FailRun i For sequence {b 0,i , b 1,i , …, b K-1,i The longest consecutive failure length in}; set the consecutive failure threshold M≥1 and the penalty intensity γ∈(0,1] (both configurable), and define the penalty factor:
[0102]
[0103] This penalty factor prevents "isolated failure" from excessively influencing the conclusion, while "persistent failure / local degradation" significantly reduces the score.
[0104] Subtest scores: Set the fusion weight α∈[0,1] (configurable) and define the pruning function:
[0105] clip(x,0,1)=min(1,max(0,x))
[0106] Subtest Score i (0–100) is defined as:
[0107]
[0108] If consecutive failure penalty is enabled, the subtest score after penalty is defined:
[0109] * = *
[0110] Otherwise
[0111] * =
[0112] Randomness Total Score Output: To differentiate the importance of different subtests, each subtest weight wi > 0 (configurable). The randomness total score R (0–100) is defined as follows:
[0113]
[0114] Overall window passthrough rate is used for local degradation localization: To locate locally degraded segments, the system can calculate the overall passthrough rate for each window.
[0115]
[0116] When multiple consecutive windows of WinPass appear k When the value is significantly lower, it can be determined that there is a persistent weak random characteristic, and the corresponding window interval is output as evidence in the report.
[0117] S3. State persistence and recovery mechanism:
[0118] The system continuously records and saves key status information (including Seed sample pool summary, global bitstream construction progress, window parameters W, step size S, current total number of windows K, multi-mode attack engine attempt progress, and protection trigger statistics, etc.), and supports breakpoint recovery, making the testing process traceable and reproducible, and facilitating long-term or phased testing.
[0119] S4. Output Quantitative Report:
[0120] After the termination conditions are met, the system generates a standardized assessment report and outputs a comprehensive strength score. The report must include at least: conclusions on randomness analysis, conclusions on multi-mode attacks, conclusions on protection performance, a comprehensive score and level, a chain of evidence, and remedial recommendations.
[0121] Randomness Dimension Score: The randomness dimension score uses the aforementioned total randomness score R, and is given in the report as: PassRate for each subtest. i Stability term Stab i Whether to trigger a consecutive failure penalty, and the critical degradation window range.
[0122] Attack Difficulty Score: The attack difficulty score is denoted as B (0–100). To reflect that "different success methods represent different levels of security," this embodiment designs B as a combination of "success mode stratification + cost adjustment." To avoid undefined variables, this section defines the following uniformly:
[0123] "Success Mode Type" refers to the attack mode used by the system when it finally unlocks (if it fails, it is recorded as "unsuccessful").
[0124] N represents the cumulative number of attempts in the successful mode (if unsuccessful, the cumulative number of attempts throughout the entire process is taken);
[0125] T represents the cumulative time taken in the successful mode (the unit can be seconds; if unsuccessful, the cumulative time taken for the entire process is used).
[0126] Reference upper limit N ref >0 and T ref >0 (all are configurable parameters used to normalize costs under different test conditions).
[0127] Cost weight β∈[0,100] (configurable, used to control the magnitude of the cost's impact on B).
[0128] Success Model Base Score B mode Assign base scores based on success mode (values are configurable ranges; using the following logic):
[0129] If success can be achieved using low-cost heuristics such as Pattern B / Pattern C, then B... mode Take the lower value range;
[0130] If it succeeds only in pattern D combined with the heuristic pattern, then B mode Take the middle value range;
[0131] If it succeeds only in mode A (exhaustive / enumeration mode), or fails consistently under limited resources, then B... mode Take the higher value range.
[0132] Cost normalization and cost adjustment terms: Define the normalization term for the number of attempts and the normalization term for the time spent:
[0133] CN = min(1, N / N ref ), CT = min(1, T / T) ref ), and define the comprehensive cost item C = (C N + C T ) / 2.
[0134] The larger the cost term C∈[0,1], the higher the cost of cracking. Define the pruning function:
[0135] clip(x,0,100)=min(100,max(0,x))
[0136] The attack difficulty dimension score is defined as follows:
[0137] B = clip(B mode + β*C, 0, 100)
[0138] Low-cost success with strong constraints: To prevent "inherently weak algorithms from having artificially high scores due to accidental high costs", when the success pattern type belongs to a low-cost heuristic pattern (such as shift / rotation or XOR, etc.), the system can impose an upper limit constraint or penalty on B to ensure that the attack difficulty score is consistent with security intuition.
[0139] Protection performance score: The protection performance score is denoted as D (0–100), which is obtained by normalizing the increase in attack cost caused by ECU delay, locking, and other protective behaviors.
[0140] Overall Strength Rating and Grade: Setting an overall weight wR w B w D ∈[0,1], and satisfy w R +w B +w D =1.
[0141] The overall strength score is denoted as Score (0–100), and is defined as follows:
[0142] Score = w R *R + w B *B + w D *D.
[0143] To highlight the dominant impact of key weaknesses, the system can set a trigger threshold R. min (Configurable) and penalty coefficient λ∈(0,1] (Configurable): when R < R min In the event of critical flaws such as the success of a low-cost heuristic model, the overall score will be revised to Score* = Score* λ, and Score* will be mapped to a grade conclusion (e.g., high / medium / low or A / B / C / D). The triggering reasons and evidence window will also be provided in the report.
[0144] Report Content: The report should include at least the following: test configuration (security level, sampling scale, window parameters W, S, total number of windows K, number of subtests m), randomness sub-items and R, attack mode execution logs and B, protection behavior summary and (optional) D, comprehensive score* and level, evidence chain (key window intervals and key attack events), and remediation recommendations.
[0145] S5. After system initialization and identification of the target ECU and security level 0x27, a parallel process is initiated: continuously triggering and collecting Seeds, while prioritizing low-cost heuristic modes such as Mode B / Mode C, and upgrading to Mode D and Mode A if necessary. The randomness detection module starts generating windows and executing SP800-22 after L≥W, continuously outputting R and key degradation window information. The decision scheduling engine dynamically adjusts the strategy based on randomness and attack progress, and performs backoff and recovery when encountering delays / lockouts. After the test, the system outputs R, B, D, and Score* as defined in step S4, generating a standardized report.
[0146] Although embodiments of this application have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of this application, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A UDS security access assessment system based on an automated blasting and seed acquisition fusion mechanism, characterized in that, include: The UDS communication and service enumeration module is used to automatically identify the communication parameters and security level services of the target ECU. A multi-mode automated brute-force engine is used to support multiple brute-force modes and schedule execution according to a strategy, and supports key brute-force cracking, delay adaptation and recovery mechanism; A dynamic seed acquisition and caching module is used to capture seed response data in real time during the blasting process; Incremental statistical detection module, based on the sliding window randomness detection principle of NIST SP800-22; The decision scheduling engine is used to adjust the blasting strategy and sampling frequency based on real-time detection results; The state persistence and breakpoint recovery module is used to record test status and progress; The comprehensive report generation module is used to output standardized security assessment results.
2. The UDS security access assessment system based on the fusion mechanism of automated blasting and seed acquisition as described in claim 1, characterized in that, The assessment method adopts the following steps: S1, Automated seed collection and blasting fusion; S2, Incremental randomness detection, adopts a randomness detection mechanism of initial accumulation + sliding window + incremental update + multi-window robust convergence; S3. State persistence and recovery mechanism: The system continuously records and saves key state information and supports breakpoint recovery, making the testing process traceable and reproducible, and facilitating long-term or phased testing. S4. Output a quantitative report. After the termination conditions are met, the system generates a standardized evaluation report and outputs a comprehensive strength score. S5. After the system initializes and identifies the ECU and the 0x27 security level, it starts the parallel process: continuously triggers and collects Seeds. The randomness detection module starts generating windows and executing SP800-22 after L≥W, continuously outputting R and key degradation window information. The decision scheduling engine dynamically adjusts the strategy based on randomness and attack progress, and performs backoff and recovery when encountering delay / lock. After the test is completed, the system generates a standardized report.
3. The UDS secure access evaluation system based on the fusion mechanism of automatic explosion and seed collection according to claim 2, characterized in that, In step S1, the specific steps for the automated seed collection and blasting fusion are as follows: When performing UDS 0x27 related interactions and attack attempts, the system adopts a parallel mechanism: on the one hand, it continuously triggers the ECU to return the Seed and collects and writes it into the sample pool; on the other hand, it performs attack attempts on the Seed-Key process under the same security level and records the number of attempts, time consumption, triggered NRC / lock information, and whether the unlocking was successful for each mode.
4. The UDS secure access evaluation system based on the fusion mechanism of automatic blasting and seed collection according to claim 3, characterized in that, The multi-mode attack engine includes the following attack modes: S11, Mode A is an exhaustive / enumeration mode. Given the known range of Key space or Key length, it attempts according to a predetermined enumeration order. It is suitable for evaluating the "cost of pure brute-force cracking". S12 and Mode B are common shift / rotation derivation modes. Based on common transformation assumptions such as displacement, cyclic shift, splicing / truncation between Seed and Key, candidate Keys are constructed and verified. This mode belongs to low-cost heuristic derivation and is used to quickly identify weak algorithms. S13, Mode C is the XOR derivation mode, which generates and verifies candidate keys based on the common XOR relationship between Seed and Key. This mode belongs to a common weak implementation of fast identification method. S14 and Mode D are combined heuristic modes that combine the above operators such as shift / rotate, XOR, addition / subtraction, inversion, and byte swapping into a limited depth to form a constrained candidate generation space, so as to cover more common implementations under controllable cost.
5. The UDS secure access evaluation system based on the fusion mechanism of automatic explosion and seed collection according to claim 2, characterized in that, In step S2, the incremental randomness detection process includes: S21, Initial length threshold triggered; S22. Sliding window construction and incremental update; S23. Multi-window result aggregation and subtest score calculation; S24, Overall window pass rate is used for local degradation positioning.
6. The UDS secure access evaluation system based on the fusion mechanism of automatic explosion and seed collection according to claim 2, characterized in that, In step S3, the system continuously records and saves key status information, including at least the Seed sample pool summary, global bitstream construction progress, window parameters W, step size S, current total number of windows K, multi-mode attack engine attempt progress, and protection trigger statistics.
7. The UDS secure access evaluation system based on the fusion mechanism of automatic explosion and seed collection according to claim 2, characterized in that, In step S4, the output quantitative report shall include at least: randomness analysis conclusions, multi-mode attack conclusions, protection performance conclusions, comprehensive score and level, evidence chain and rectification recommendations.