Diagnostic equipment access processing methods and devices, vehicles and storage media

CN122578438APending Publication Date: 2026-08-14CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-22
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

相关技术中,车辆诊断接口的接入处理机制主要是通过公钥算法或者非对称私钥算法完成认证之后,对于诊断设备需要开放的诊断权限多采用固定白名单方式放行,开放范围较大导致车辆攻击面显著增大,且存在策略配置灵活性不足的问题

Benefits of technology

[0015]本申请实施例至少包括以下有益效果:本申请提供一种诊断设备的接入处理方法和装置、车辆及存储介质,该方案在诊断设备接入时触发诊断许可与权限配置流程,可根据实际需求灵活设定授权时限与授权范围,精准限定诊断设备可通信的目标控制器及对应诊断权限,并基于上述配置生成接入认证信息下发至网关执行。因此,本实施例使得网关能够依据接入认证信息对诊断设备与目标控制器之间的通信进行约束控制,既满足诊断场景下差异化诊断需求,又大幅缩小车辆对外攻击面,提升OBD接口接入安全性与权限管理灵活性,同时避免固定白名单等传统方式权限开放过大、策略僵化等问题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122578438A_ABST
    Figure CN122578438A_ABST
Patent Text Reader

Abstract

This application provides a method and apparatus for access processing of diagnostic devices, a vehicle, and a storage medium, belonging to the field of vehicle communication technology. The method includes: receiving a diagnostic request; responding to a diagnostic permission instruction in the diagnostic request by outputting an access permission configuration interface; responding to configuration operations on the access permission configuration interface by generating permission configuration information; wherein the permission configuration information includes a target authorization time and a target authorization scope, the target authorization scope representing the target controller authorized for communication by the diagnostic device and the target diagnostic permissions of the target controller; generating access authentication information based on the target authorization time, the target controller, and the target diagnostic permissions; and sending the access authentication information to a gateway, enabling the gateway to control the communication operations between the diagnostic device and the target controller based on the access authentication information. This application can improve the security and flexibility of OBD interface access and permission management, reducing problems such as excessive permission opening and rigid policies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle communication technology, and in particular to a method and apparatus for access processing of diagnostic equipment, a vehicle, and a storage medium. Background Technology

[0002] The vehicle diagnostic interface, also known as the OBD interface, serves as a crucial access point for the vehicle's external interfaces and internal communication bus. The access processing mechanism of diagnostic devices through this interface is extremely important in the field of vehicle communication. In related technologies, the access processing mechanism of the vehicle diagnostic interface primarily uses public-key algorithms or asymmetric private-key algorithms for authentication. Diagnostic permissions that need to be granted to diagnostic devices are often granted using a fixed whitelist approach. This broad scope of access significantly increases the vehicle's attack surface and suffers from insufficient flexibility in policy configuration.

[0003] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the Invention

[0004] The main objective of this application is to propose a method and apparatus for access processing of diagnostic devices, as well as a vehicle and storage medium, which aims to improve the security and flexibility of OBD interface access and reduce problems such as excessive access permissions and rigid policies.

[0005] To achieve the above objectives, one aspect of this application proposes an access processing method for a diagnostic device, applied to a vehicle, wherein the vehicle includes a vehicle diagnostic interface, and the method includes: Receive diagnostic requests; wherein, the diagnostic requests are sent by the gateway in response to the diagnostic device accessing the vehicle diagnostic interface; In response to the diagnostic request, a diagnostic permission instruction is output, and an access permission configuration interface is displayed. In response to the configuration operation of the access permission configuration interface, permission configuration information is generated; wherein, the permission configuration information includes target authorization time and target authorization scope, and the target authorization scope represents the target controller for authorized communication of the diagnostic device and the target diagnostic permissions of the target controller; Generate access authentication information based on the target authorization time, the target controller, and the target diagnostic permissions; The access authentication information is sent to the gateway so that the gateway controls the communication operation between the diagnostic device and the target controller based on the access authentication information.

[0006] In some embodiments, generating permission configuration information in response to the configuration operation of the access permission configuration interface includes: In response to the configuration mode selection operation of the access permission configuration interface, the current configuration interface is output; wherein, the current configuration interface includes a fixed configuration interface and a flexible configuration interface; In response to the parameter configuration operation of the current configuration interface, permission configuration information is generated.

[0007] In some embodiments, if the current configuration interface is the fixed configuration interface, generating permission configuration information in response to parameter configuration operations on the current configuration interface includes: In response to the permission level selection command in the fixed configuration interface, generate the current permission level information; Preliminary configuration information is selected from preset candidate configuration information based on the current permission level information; wherein, the preliminary configuration information includes preliminary authorization time and preliminary authorization scope, and the preliminary authorization scope represents the preliminary controller authorized to communicate with the diagnostic device and the preliminary diagnostic permissions of the preliminary controller; In response to the modification instructions for the initial authorization time, the initial controller, and the initial diagnostic permissions, the permission configuration information is generated.

[0008] In some embodiments, if the current configuration interface is a flexible configuration interface, generating permission configuration information in response to parameter configuration operations on the current configuration interface includes: In response to the controller selection command for the flexible configuration interface, a target controller is generated; In response to the diagnostic permission configuration instruction of the target controller, the target diagnostic permissions of the target controller are generated; wherein, the target diagnostic permissions include at least one of the following: data read permission, function control permission, configuration write permission, and software upgrade permission; In response to the time configuration command of the target controller, the target authorized time is generated; The target controller, the target diagnostic permissions, and the target authorization time are concatenated to obtain the permission configuration information.

[0009] In some embodiments, after receiving the diagnostic request, the method further includes: Collect user identity information; The user identity information is authenticated based on preset reference authentication information to obtain identity authentication information; If the identity authentication information indicates that the user's identity information has been successfully authenticated, and in response to the diagnostic permission instruction of the diagnostic request, the access permission configuration interface is output; If the authentication information indicates that the user's identity information authentication has failed, the communication between the diagnostic device and the vehicle diagnostic interface is cut off.

[0010] In some embodiments, after receiving the diagnostic request, the method further includes: In response to the diagnostic rejection instruction of the diagnostic request, virtual vehicle status data is generated according to preset feedback configuration information; wherein, the virtual vehicle status data is data that is unrelated to the actual vehicle status; The virtual vehicle status data is sent to the gateway, which then sends the virtual vehicle status data to the diagnostic device.

[0011] In some embodiments, the diagnostic rejection instruction of the diagnostic request generates virtual vehicle status data based on preset feedback configuration information, including: In response to the diagnostic rejection instruction of the diagnostic request, the diagnostic equipment is classified into risk levels to obtain the current risk level; Selected feedback configuration information is filtered from the preset feedback configuration information based on the current risk level; The virtual vehicle status data is generated based on the selected feedback configuration information.

[0012] To achieve the above objectives, another aspect of this application provides an access processing apparatus for a diagnostic device, the apparatus being applied to a vehicle, the vehicle including a vehicle diagnostic interface, the apparatus comprising: A receiving module is used to receive diagnostic requests; wherein the diagnostic request is sent by the gateway in response to the diagnostic device accessing the vehicle diagnostic interface; The interface output module is used to respond to the diagnostic permission instruction of the diagnostic request and output the access permission configuration interface; The permission configuration module is used to generate permission configuration information in response to the configuration operation of the access permission configuration interface; wherein, the permission configuration information includes target authorization time and target authorization scope, and the target authorization scope represents the target controller that authorizes the diagnostic device to communicate and the target diagnostic permissions of the target controller; The information generation module is used to generate access authentication information based on the target authorization time, the target controller, and the target diagnostic permissions; The sending module is used to send the access authentication information to the gateway, so that the gateway controls the communication operation between the diagnostic device and the target controller according to the access authentication information.

[0013] To achieve the above objectives, another aspect of this application provides a vehicle, which includes an in-vehicle terminal, a display screen, a gateway, and a vehicle diagnostic interface. The in-vehicle terminal includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method.

[0014] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.

[0015] The embodiments of this application include at least the following beneficial effects: This application provides a method and apparatus for access processing of diagnostic devices, a vehicle, and a storage medium. This solution triggers a diagnostic permission and authorization configuration process when a diagnostic device accesses the system. The authorization time limit and scope can be flexibly set according to actual needs, precisely limiting the target controllers that the diagnostic device can communicate with and their corresponding diagnostic permissions. Based on the above configuration, access authentication information is generated and sent to the gateway for execution. Therefore, this embodiment enables the gateway to constrain and control the communication between the diagnostic device and the target controller based on the access authentication information. This not only meets the differentiated diagnostic needs in diagnostic scenarios but also significantly reduces the vehicle's external attack surface, improves the security of OBD interface access and the flexibility of permission management, while avoiding problems such as excessive permission opening and rigid policies associated with traditional methods like fixed whitelists. Attached Figure Description

[0016] Figure 1 This is a system architecture diagram of the access processing method for diagnostic devices provided in the embodiments of this application; Figure 2 This is a flowchart of the access processing method for diagnostic devices provided in the embodiments of this application; Figure 3 This is a schematic diagram of a diagnostic request in the access processing method of a diagnostic device provided in an embodiment of this application; Figure 4 This is a schematic diagram of the access permission configuration interface in the access processing method for diagnostic devices provided in this application embodiment; Figure 5 This is a schematic diagram of the fixed configuration interface in the access processing method for diagnostic devices provided in the embodiments of this application; Figure 6 This is a schematic diagram of the flexible configuration interface in the access processing method for diagnostic devices provided in the embodiments of this application; Figure 7 This is an overall interactive flowchart of the access processing method for diagnostic devices provided in the embodiments of this application; Figure 8 This is a schematic diagram of the access processing device for the diagnostic equipment provided in the embodiments of this application; Figure 9 This is a schematic diagram of the hardware structure of the vehicle terminal provided in the embodiments of this application. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0018] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various concepts, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if,” “when,” or “in response to a determination” as used herein may be interpreted as “when…” or “when…” or “in response to a determination.”

[0019] As used in this application, the terms "at least one", "multiple", "each", "any", etc., "at least one" includes one, two or more, "multiple" includes two or more, "each" refers to each of the corresponding multiples, and "any" refers to any one of the multiples.

[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0021] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.

[0022] 1) The On-Board Diagnostics (OBD) interface is the standard communication interface for on-board diagnostic systems.

[0023] 2) Electronic Control Unit (ECU): By receiving real-time signals from various engine sensors, the internal microprocessor performs high-speed calculations and judgments according to preset programs, and finally outputs commands to precisely control actuators such as fuel injection, ignition, and idling speed.

[0024] 3) The Central Gateway (CGW) is the core communication hub of modern intelligent vehicles. Its main functions are as follows: network interconnection (protocol conversion), data routing and management, network security, and diagnosis and access control.

[0025] 4) In-Vehicle Infotainment (IVI) is a human-machine interface for drivers and passengers, serving as the central hub for all information, entertainment, and vehicle control functions within the vehicle.

[0026] Currently, the OBD interface, as a critical external interface for the vehicle and an important access point for the in-vehicle communication bus, has significant shortcomings in its diagnostic device access processing mechanism: after a diagnostic device connects to the vehicle's diagnostic interface, authentication is completed using either a public-key algorithm or an asymmetric algorithm. After successful authentication, the diagnostic permissions that the vehicle's diagnostic interface needs to grant are mostly granted through a fixed whitelist. This not only leads to a large scope of access, significantly expanding the vehicle's attack surface, but also suffers from insufficient policy configuration flexibility and difficulty in adapting to diverse diagnostic needs. Therefore, there is an urgent need for a diagnostic permission configuration method that can reduce the vehicle's attack surface and adapt to different diagnostic requirements.

[0027] Based on this, a method and apparatus for access processing of diagnostic devices, a vehicle, and a storage medium are disclosed. When a diagnostic device accesses the system, a diagnostic permission and authorization configuration process is triggered. The authorization time limit and scope can be flexibly set according to actual needs, precisely limiting the target controllers that the diagnostic device can communicate with and their corresponding diagnostic permissions. Based on the above configuration, access authentication information is generated and sent to the gateway for execution. Therefore, this embodiment enables the gateway to constrain and control the communication between the diagnostic device and the target controller based on the access authentication information. This not only meets the differentiated diagnostic needs in diagnostic scenarios but also significantly reduces the vehicle's external attack surface, improves the security of OBD interface access and the flexibility of permission management, while avoiding the problems of excessive permission opening and rigid policies associated with traditional methods such as fixed whitelists.

[0028] The diagnostic device access processing method provided in this application relates to the field of vehicle communication technology. This diagnostic device access processing method can be applied to a terminal, a server, or software running on a terminal or server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, or in-vehicle terminal, but is not limited to these. The server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network. The software can be an application implementing the diagnostic device access processing method, but is not limited to the above forms.

[0029] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0030] Figure 1 A system framework diagram illustrating the access processing method for diagnostic equipment is shown, comprising a vehicle, diagnostic equipment, and a terminal. The vehicle includes a vehicle diagnostic interface, at least one electronic control unit, and a gateway, also known as a central gateway, defined as CGW. Figure 1 As shown, the diagnostic device connects to the gateway through the vehicle diagnostic interface. Specifically, the diagnostic device accesses the vehicle diagnostic interface, the gateway sends a diagnostic request to the terminal, the terminal responds to the diagnostic request and further confirms whether to authenticate the access of the added diagnostic device, and after successful authentication, sets the communication permissions of the diagnostic device to realize personalized interface communication permission settings, which makes the security of vehicle diagnostic interface access and the flexibility of permission management higher.

[0031] Figure 2This is an optional flowchart of the access processing method for diagnostic devices provided in the embodiments of this application. Figure 2 The method described above is applied to vehicles and is specifically executed by a terminal. The terminal can be any of the following: an in-vehicle terminal, a smartphone, a tablet computer, a laptop computer, or a desktop computer. This embodiment uses an in-vehicle terminal as an example for illustration. Figure 2 The method may include, but is not limited to, steps S201 to S205.

[0032] Step S201: Receive a diagnostic request; wherein the diagnostic request is sent by the gateway in response to the diagnostic device accessing the vehicle diagnostic interface.

[0033] In some embodiments, before receiving a diagnostic request, the terminal needs to download a vehicle-matched application, install the vehicle application on the terminal to obtain a vehicle application platform, register an account on the vehicle application platform, and enter vehicle information and basic identity information, including age, gender, address, etc. This embodiment does not limit the basic identity information. After completing the vehicle information entry, the terminal and the vehicle's gateway can communicate through a preset communication method, which can be any one of WIFI, Bluetooth, wired communication, or NFC communication. This embodiment does not limit the preset communication method. After the terminal and gateway establish a communication connection, if the gateway recognizes that a diagnostic device has accessed the vehicle's diagnostic interface, the gateway generates a diagnostic request and sends the diagnostic request to the terminal. Specifically, the diagnostic request includes the diagnostic device's device information and access time. The device information includes the diagnostic device's ID and IP address, and the diagnostic request is displayed on the terminal's interface in a pop-up window. Figure 3 As shown, after the terminal receives the diagnostic request, the diagnostic request is displayed in a pop-up window on the vehicle application platform, and the pop-up window content is "Connected to OBD interface at XX:XX diagnostic device (XXX)". The information of the diagnostic device being connected to the vehicle diagnostic interface can be clearly seen through the pop-up window content.

[0034] Upon receiving a diagnostic request, the pop-up window includes authentication and ignore options. If the user clicks the authentication option button, the vehicle application platform interface will redirect to the authentication screen. It should be noted that the authentication screen is generated based on the authentication mode pre-set by the user on the vehicle application platform. These authentication modes include iris authentication, password authentication, facial recognition, and voice authentication, etc. This embodiment does not limit the specific authentication mode.

[0035] In some embodiments, prior to step S201, the access processing method for the diagnostic device may also include, but is not limited to, the following: Collect user identity information; The user's identity information is authenticated based on the preset reference authentication information to obtain identity authentication information; If the authentication information indicates that the user's identity information has been successfully authenticated, and in response to the diagnostic permission instruction of the diagnostic request, the access permission configuration interface is output. If the authentication information indicates that the user's identity information authentication has failed, communication between the diagnostic equipment and the vehicle diagnostic interface will be cut off.

[0036] As previously disclosed, an authentication page is generated based on the authentication mode, and user identity information is collected based on the user's authentication actions on the authentication page. Specifically, if the authentication mode is iris authentication, the user's identity information is the user's iris information; if the authentication mode is password authentication, the user's identity information is the password entered by the user on the authentication page. Therefore, by pre-setting the authentication mode, the corresponding authentication interface is displayed, and the user's identity information matching the authentication mode is collected, enabling flexible setting of identity authentication to adapt to the authentication needs of different users.

[0037] In some embodiments, the reference authentication information is pre-set authentication information according to a preset authentication mode, used to verify user identity information. Specifically, the reference authentication information and user identity information are compared to obtain comparison information, and the identity authentication information is determined based on the comparison information and a preset error range. For example, if the user identity information is user iris information, and the reference authentication information is reference iris information (pre-set by the user), user iris features are extracted from the user iris information, and reference iris features are extracted from the reference iris information. The similarity between the user iris features and the reference iris features is calculated to obtain feature similarity. If the feature similarity is within the preset error range, the identity authentication information is determined to be valid; if the feature similarity is not within the preset error range, the identity authentication information is determined to be invalid. If the user identity information is an input password, and the reference authentication information is a reference password, the identity authentication information is determined to be valid if the input password and the reference password match.

[0038] It should be noted that whether the terminal performs user authentication upon receiving each diagnostic request depends on the user's settings on the vehicle application platform. If the user has configured it to perform user authentication upon receiving each diagnostic request, then user authentication will occur first upon receiving the request. If the user has configured it to perform authentication only once upon the same diagnostic device's access, then user authentication will only be performed once for the same diagnostic device, and diagnostic permission configuration will proceed directly upon the diagnostic device's second access to the vehicle's diagnostic interface. If the user has configured it so that no further authentication is required after a preset period following initial authentication, then no further authentication will be required after the preset period. Therefore, configuring multiple authentication methods increases the flexibility of the authentication process.

[0039] In some embodiments, if the authentication information indicates that the user's identity information has been successfully authenticated, it means that the user currently operating on the vehicle application platform can configure the access of the diagnostic device to make the access of the diagnostic device more secure. Therefore, in this embodiment, after confirming that the user's identity information has been successfully authenticated, a diagnostic permission request is further displayed in a pop-up window on the vehicle application platform. If the user clicks the "Diagnostic Permission" button on the interface corresponding to the diagnostic permission request, the terminal receives the diagnostic permission instruction and configures the access permissions of the diagnostic device according to the instruction. Therefore, an access permission configuration interface is output, and the access permission configuration of the diagnostic device is completed through the access permission configuration interface.

[0040] In some embodiments, if the authentication information indicates that the user's identity information authentication has failed, indicating that the user currently operating on the vehicle application platform does not have the access configuration for the diagnostic device, the terminal sends a disconnect command to the gateway, and the gateway disconnects the communication between the diagnostic device and the vehicle diagnostic interface according to the disconnect command. In addition, this embodiment can also pre-set feedback configuration information, and when the user's identity information authentication fails, perform a feedback operation on the diagnostic device according to the feedback configuration information. Furthermore, if the authentication information indicates that the user's identity information authentication has failed, an alarm procedure will also be triggered on the vehicle application platform to generate alarm information related to the diagnostic device's access to the vehicle diagnostic interface, prompting the user of unauthorized access to the diagnostic device.

[0041] Step S202: In response to the diagnostic permission instruction of the diagnostic request, the access permission configuration interface is output.

[0042] As previously disclosed, such as Figure 4 As shown, after successful user identity authentication, a diagnostic permission request interface pops up on the vehicle application platform. Clicking the "Diagnostic Permission" button on this interface displays the access permission configuration interface on the vehicle application platform. In this embodiment, the access permission configuration interface includes fixed and flexible configuration options. The fixed configuration option pre-sets multiple permission levels and candidate configuration information matching each permission level; specifically, it employs a hierarchical permission strategy, where each permission level matches a different controller and has a different permission scope, suitable for quickly completing diagnostic permission configuration. The flexible configuration option allows the user to automatically select a controller and set the permission scope and authorization time for each controller, suitable for more detailed diagnostic permission configuration.

[0043] Step S203: In response to the configuration operation of the access permission configuration interface, permission configuration information is generated; wherein, the permission configuration information includes target authorization time and target authorization scope, the target authorization scope represents the target controller authorized to communicate with the diagnostic device and the target diagnostic permissions of the target controller.

[0044] In some embodiments, the target authorization time is the communication time between the open diagnostic device and the target controller inside the vehicle. It can be flexibly configured or set according to a set time range, such as half an hour, one hour, or one and a half hours, or even precise to a specific point in time. This embodiment does not limit the setting method of the target authorization time. The target authorization range represents the target controller that the diagnostic device is allowed to communicate with and the target diagnostic permissions of the target controller. Specifically, the target diagnostic permissions are the diagnostic function categories set by the diagnostic device for the target controller. In this embodiment, the target diagnostic permissions include at least one of the following: data read permissions, function control permissions, configuration write permissions, and software upgrade permissions. It should be noted that data read permissions include reading fault codes, clearing fault codes, reading real-time / stored data, and reading the controller information of the target controller. Reading fault codes involves reading fault codes and real vehicle status data stored in the target controller; clearing fault codes involves clearing fault codes, freeze frames, and other information from the target controller; reading real-time / stored data involves reading information such as engine speed, vehicle speed, and software version stored in the target controller; and reading the controller information of the target controller involves reading the part number, hardware / software version, and other information stored in the target controller. Functional control permissions include: input / output control, execution of specific routines, and target controller reset. Input / output control is the forced control of the target controller, such as turning on headlights or testing fuel injectors. Executing specific routines involves executing preset programs within the target controller, such as throttle body matching or key learning. Target controller reset refers to performing a soft or hard reset on the target controller. Configuration write permission allows writing data to the target controller, while software upgrade permission allows firmware upgrades or program flashing on the target controller.

[0045] As previously disclosed, after the diagnostic device connects to the vehicle diagnostic interface, user identity information is collected and verified first to achieve secure access control before diagnostic access: only when the user's identity information is successfully authenticated is the user allowed to enter the access permission configuration process and the permission configuration interface is output for subsequent fine-grained configuration of diagnostic authorization parameters; if the identity authentication fails, the communication link between the diagnostic device and the vehicle diagnostic interface is directly cut off, and subsequent diagnostic access is denied. Therefore, by completing user identity authentication on the vehicle application platform, unauthorized users or devices are effectively prevented from accessing the vehicle bus through the vehicle diagnostic interface, significantly improving the security and controllability of vehicle diagnostic access, and laying a secure foundation for subsequent fine-grained permission management.

[0046] In some embodiments, in response to configuration operations on the access permission configuration interface, permission configuration information is generated, including: In response to the configuration mode selection operation of the access permission configuration interface, the current configuration interface is output; the current configuration interface includes a fixed configuration interface and a flexible configuration interface. In response to parameter configuration operations on the current configuration interface, generate permission configuration information.

[0047] As previously disclosed, the configuration mode selection operation is equivalent to clicking the fixed configuration option or flexible configuration option on the access permission configuration interface, and switching to the current configuration interface based on the configuration mode selection operation. The parameter configuration operation in response to the current configuration interface is equivalent to collecting the target controller, the target diagnostic permissions of the target controller, and the target authorization time entered by the user on the current configuration interface to obtain the permission configuration information.

[0048] As previously disclosed, by setting up a fixed configuration interface and a flexible configuration interface, the access permission configuration of the vehicle diagnostic interface can be made more flexible to adapt to different diagnostic permission configuration requirements.

[0049] In some embodiments, if the current configuration interface is a fixed configuration interface, in response to the parameter configuration operation of the current configuration interface, permission configuration information is generated, including: In response to the permission level selection command in the fixed configuration interface, generate the current permission level information; Preliminary configuration information is selected from preset candidate configuration information based on the current permission level information; wherein, the preliminary configuration information includes preliminary authorization time and preliminary authorization scope, and the preliminary authorization scope represents the preliminary controller authorized to communicate with the diagnostic device and the preliminary diagnostic permissions of the preliminary controller; In response to modification commands for initial authorization time, initial controller, and initial diagnostic permissions, permission configuration information is generated.

[0050] In some embodiments, the fixed configuration interface of this embodiment sets multiple permission level options. A permission level selection instruction is generated based on the user's selection of a permission level option on the fixed configuration interface, and the current permission level information is generated based on the permission level selection instruction. The number of permission level options in this embodiment is customizable. If six permission level options are set, each permission level option corresponds to one candidate configuration information. After determining the current permission level information, preliminary configuration information is filtered from the candidate configuration information based on the current permission level information. The preliminary configuration information has a pre-set preliminary authorization time and preliminary authorization scope.

[0051] For example, in this embodiment, if six permission level options are set, if the current permission level information is the first permission level information, the preliminary configuration information is determined as: enable functional addressing non-write / modify configuration state diagnostic services, which is equivalent to determining the preliminary controller and its preliminary diagnostic permissions as functional addressing non-write / modify configuration state. If the current permission level information is the second permission level information, the preliminary configuration information is determined as: enable functional addressing all diagnostic services, which is equivalent to setting the functional addressing of the preliminary controller. If the current permission level information is the third permission level information, the preliminary configuration information is determined as: enable non-write / modify configuration state diagnostic services for a specific controller, which is equivalent to the preliminary controller being a specific controller and its preliminary diagnostic permissions being non-write / modify configuration state. If the current permission level information is the fourth permission level information, the preliminary configuration information is determined as: enable non-write / modify configuration state diagnostic services for all controllers, which is equivalent to setting the preliminary diagnostic permissions for all controllers to non-write / modify configuration state. If the current permission level information is the fifth permission level information, the preliminary configuration information is determined as: enable all diagnostic permissions for a specific controller, which is equivalent to setting the preliminary diagnostic permissions for the specific controller to all permissions. If the current permission level is level six, the initial configuration is set to: grant all controllers full diagnostic permissions, which is equivalent to setting all controllers to full preliminary diagnostic permissions. Therefore, once the current permission level is determined, the initial authorization time, the initial controller, and the initial diagnostic permissions for the initial controller can be set directly, making diagnostic permission configuration faster.

[0052] Furthermore, to improve the accuracy of permission configuration, this embodiment can also modify the initial authorization time to obtain the target authorization time, modify the initial controller to obtain the target controller, and modify the initial diagnostic permissions to obtain the target diagnostic permissions. It should be noted that if the initial authorization time, initial controller, and initial diagnostic permissions are not modified, the initial authorization time can be directly used as the target authorization time, the initial controller as the target controller, and the initial diagnostic permissions as the target diagnostic permissions.

[0053] For example, such as Figure 5 As shown, when the user selects the third permission level option to confirm the third permission level, the system automatically matches the initial configuration information to enable diagnostic services for non-write / modify configuration states on a specific controller. It also automatically selects the specific controller, and for each specific controller, the initial diagnostic permission is set to the non-write / modify configuration state class. Therefore, by setting the initial configuration information to match the permission level, diagnostic permission configuration can be completed quickly, improving configuration efficiency.

[0054] As previously disclosed, the system first automatically matches the corresponding initial authorization time and scope based on the selected permission level, significantly improving the efficiency of permission configuration. Then, it personalizes the initial authorization time, initial controller, and initial diagnostic permissions, balancing the convenience of standardized configuration with the flexibility of differentiated scenarios. This reduces the complexity of manual configuration and accurately adapts to different diagnostic needs.

[0055] In some embodiments, if the current configuration interface is a flexible configuration interface, in response to parameter configuration operations on the current configuration interface, permission configuration information is generated, including: In response to the controller selection command for a flexible configuration interface, a target controller is generated; In response to the diagnostic permission configuration command of the target controller, the target diagnostic permissions of the target controller are generated; wherein, the target diagnostic permissions include at least one of the following: data read permission, function control permission, configuration write permission, and software upgrade permission; In response to the time configuration command from the target controller, generate the target authorized time; By concatenating the target controller, target diagnostic permissions, and target authorization time, the permission configuration information is obtained.

[0056] It should be noted that the flexible configuration interface allows setting controller options, diagnostic permission configuration options, and time configuration options. To obtain target diagnostic permissions, select the target controller in the controller options, then select the diagnostic configuration options for each target controller. Finally, set the time configuration options for diagnostic device communication to obtain the target authorized time. For example... Figure 6 As shown, Figure 6 The diagram shows a flexible configuration interface. It can be determined that the controller option, diagnostic permission configuration option, and time configuration option need to be manually clicked to generate controller selection instructions, diagnostic permission configuration instructions, and time configuration instructions, and then the target controller, target diagnostic permissions, and target authorized time are automatically displayed.

[0057] As previously disclosed, by setting up a flexible configuration interface, users can make more flexible diagnostic permission configurations, making the diagnostic permission configuration more detailed.

[0058] Step S204: Generate access authentication information based on the target authorization time, target controller, and target diagnostic permissions.

[0059] On the vehicle application platform, the target authorization time, target controller, and target diagnostic permissions are concatenated into access authentication information. The access authentication information serves as the user's authorized diagnostic service scope for the diagnostic device, indicating the target controller that the diagnostic device can communicate with, the diagnostic permissions for the target controller, and the diagnostic duration.

[0060] Step S205: Send access authentication information to the gateway so that the gateway controls the communication operation between the diagnostic device and the target controller based on the access authentication information.

[0061] In some embodiments, a vehicle application platform is set on the terminal, and an in-vehicle infotainment system is set within the vehicle application platform. The in-vehicle infotainment system interacts with the user to collect user authentication information and provide feedback on permission configuration information. Therefore, the in-vehicle infotainment system generates access authentication information and sends it to the gateway. The gateway determines the route to the target controller based on the access authentication information and determines the diagnostic permissions and access duration of the route, enabling communication between the diagnostic device and the target controller. This allows for the collection of real-time vehicle status data and the diagnosis of vehicle faults, achieving safe and flexible fault diagnosis.

[0062] Steps S201 to S205, as illustrated in this embodiment, trigger a diagnostic license and permission configuration process when the diagnostic device connects. Authorization time limits and scope are flexibly set according to actual needs, precisely limiting the target controllers that the diagnostic device can communicate with and their corresponding diagnostic permissions. Based on the above configuration, access authentication information is generated and sent to the gateway for execution. The gateway can constrain and control the communication between the diagnostic device and the target controller based on the access authentication information. This not only meets the differentiated diagnostic needs in after-sales scenarios but also significantly reduces the vehicle's external attack surface, improving the security and flexibility of OBD interface access and permission management. Simultaneously, it avoids problems such as excessive permission opening and rigid policies associated with traditional methods like fixed whitelists.

[0063] In some embodiments, after step S201, the access processing method for the diagnostic device may further include, but is not limited to, the following: In response to a diagnostic rejection command in response to a diagnostic request, virtual vehicle status data is generated based on preset feedback configuration information; wherein, the virtual vehicle status data is data that is unrelated to the actual vehicle status. The virtual vehicle status data is sent to the gateway, which then sends the virtual vehicle status data to the diagnostic device.

[0064] As previously disclosed, if the "Diagnosis Deny" button is clicked on the interface corresponding to the diagnostic permission request to generate a diagnostic denial instruction, the diagnostic permission configuration process is no longer entered; instead, feedback operations are directly performed on the diagnostic device based on the preset feedback configuration information. It should be noted that the preset feedback configuration information includes at least one of the following: no response and response; if a response is received, virtual vehicle status data is returned. In this embodiment, the virtual vehicle status data represents false vehicle status data and cannot reflect the true vehicle condition; it is equivalent to decoy data. Furthermore, the virtual vehicle status data can also contain attack data, which is used to attack the diagnostic device to improve vehicle security.

[0065] It should be noted that if the identity authentication information indicates that the user's identity authentication has failed, virtual vehicle status data will also be generated according to the preset feedback configuration information and sent to the diagnostic device.

[0066] As previously disclosed, when a diagnostic rejection instruction is received, indicating that the user has not agreed to the authorization, the gateway does not respond to the diagnostic device directly. At the same time, it generates virtual vehicle status data based on the user's pre-configured feedback information and sends the virtual vehicle status data to the diagnostic device, thereby reducing the damage to vehicle data caused by the diagnostic device.

[0067] In some embodiments, the diagnostic rejection instruction of the diagnostic request generates virtual vehicle status data based on preset feedback configuration information, including: In response to a diagnostic rejection instruction for a diagnostic request, the diagnostic equipment is classified into risk levels to obtain the current risk level; Select the desired feedback configuration information from the preset feedback configuration information based on the current risk level; Virtual vehicle status data is generated based on the selected feedback configuration information.

[0068] It should be noted that the risk level classification specifically involves collecting device access information from diagnostic equipment. Threat assessment data is then obtained based on this access information, and the current risk level is determined based on this data and a preset assessment threshold. Specifically, the device access information includes the device ID, number of access attempts, access method, and number of unauthorized access attempts. A threat assessment model is pre-trained using access information that generates hazards for the vehicle, enabling accurate assessment of the threat posed by each diagnostic device to the vehicle.

[0069] The risk level corresponding to each preset feedback configuration information is set in advance. Specifically, if the current risk level is low, the preset feedback configuration information is set to no response; if the current risk level is medium, the preset feedback configuration information is set to return virtual vehicle status data; if the current risk level is high, the preset feedback configuration information is set to return virtual vehicle status data containing attack data.

[0070] As previously disclosed, when an unauthorized access to a diagnostic device is determined, the risk level of the diagnostic device is first assessed, and then targeted feedback is provided to achieve more accurate security protection and improve the security of vehicle diagnostic interface access processing.

[0071] Below, as Figure 7 As shown, the solution of this invention embodiment will be described in detail and explained in conjunction with a specific vehicle communication scenario: When the diagnostic device connects to the OBD interface, the gateway first pauses routing and forwards the diagnostic request sent by the diagnostic device to the vehicle terminal. The diagnostic request is then displayed as a pop-up on the vehicle application platform of the vehicle terminal. The user determines whether to unlock the diagnostics based on the pop-up. If unlocked, the vehicle terminal collects the user's identity information, such as iris scan or password, and authenticates the user's identity information according to preset reference identity information. If authentication passes, the access permission configuration interface is displayed on the vehicle application platform of the vehicle terminal. When the user selects the fixed configuration interface, the permission level strategy for the fixed configuration interface is: 1) Open function addressing for non-write / modify configuration status diagnostic services; 2) Open function addressing for all diagnostic services; 3) Open non-write / modify configuration status diagnostic services for specific controllers; 4) Open non-write / modify configuration status diagnostic services for all controllers; 5) Open all diagnostic permissions for specific controllers; 6) Open all diagnostic permissions for all controllers. The permission configuration information is further adjusted based on the user's selected permission level options. The vehicle terminal then sends the permission configuration information and identity authentication information to the gateway. The gateway determines whether to open the diagnostic route based on the permission configuration information and identity authentication information, and responds to the diagnostic device.

[0072] Therefore, this application proposes a security protection scheme for the OBD interface based on user consent. Users can manage open diagnostic permissions themselves, which facilitates after-sales diagnosis and allows for flexible configuration, making users feel secure and preventing the attack window from expanding.

[0073] Please see Figure 8 This application also provides an access processing device for diagnostic devices, which can implement the above-described access processing method for diagnostic devices. The device includes: The receiving module 801 is used to receive diagnostic requests; wherein, the diagnostic request is sent by the gateway in response to the diagnostic device accessing the vehicle diagnostic interface; The interface output module 802 is used to respond to the diagnostic permission instruction of the diagnostic request and output the access permission configuration interface; The permission configuration module 803 is used to generate permission configuration information in response to the configuration operation of the access permission configuration interface; wherein, the permission configuration information includes the target authorization time and the target authorization scope, the target authorization scope represents the target controller for authorized diagnostic device communication and the target diagnostic permissions of the target controller; Information generation module 804 is used to generate access authentication information based on the target authorization time, target controller and target diagnostic permissions; The sending module 805 is used to send access authentication information to the gateway so that the gateway controls the communication operation between the diagnostic device and the target controller according to the access authentication information.

[0074] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0075] This application also provides a vehicle, which includes an in-vehicle terminal, a display screen, a gateway, and a vehicle diagnostic interface. The in-vehicle terminal includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method. This electronic device can be any smart terminal, including a tablet computer, an in-vehicle computer, or similar device.

[0076] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0077] Please see Figure 9 , Figure 9 The hardware structure of an in-vehicle terminal according to another embodiment is illustrated. The in-vehicle terminal includes: The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 902 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 902 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 using the methods described in the embodiments of this application. The input / output interface 903 is used to implement information input and output; The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904); The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0078] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.

[0079] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0080] The diagnostic device access processing method and apparatus, vehicle, storage medium, and program product provided in this application trigger a diagnostic license and permission configuration process when the diagnostic device is accessed. It flexibly sets the authorization time limit and scope according to actual needs, precisely limiting the target controller and corresponding diagnostic permissions that the diagnostic device can communicate with. Based on the above configuration, it generates access authentication information and sends it to the gateway for execution. The gateway can constrain and control the communication between the diagnostic device and the target controller based on the access authentication information. This not only meets the differentiated diagnostic needs in after-sales scenarios but also significantly reduces the vehicle's external attack surface, improves the security and flexibility of OBD interface access and permission management, and avoids problems such as excessive permission opening and rigid policies associated with traditional methods like fixed whitelists.

[0081] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0082] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0083] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0084] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0085] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0086] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0087] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0088] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0089] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0090] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0091] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for processing the access of a diagnostic device, characterized in that, Applied to a vehicle, the vehicle including a vehicle diagnostic interface, the method includes: Receive diagnostic requests; wherein, the diagnostic requests are sent by the gateway in response to the diagnostic device accessing the vehicle diagnostic interface; In response to the diagnostic request, a diagnostic permission instruction is output, and an access permission configuration interface is displayed. In response to the configuration operation of the access permission configuration interface, permission configuration information is generated; wherein, the permission configuration information includes target authorization time and target authorization scope, and the target authorization scope represents the target controller for authorized communication of the diagnostic device and the target diagnostic permissions of the target controller; Generate access authentication information based on the target authorization time, the target controller, and the target diagnostic permissions; The access authentication information is sent to the gateway so that the gateway controls the communication operation between the diagnostic device and the target controller based on the access authentication information.

2. The method according to claim 1, characterized in that, The configuration operation in response to the access permission configuration interface generates permission configuration information, including: In response to the configuration mode selection operation of the access permission configuration interface, the current configuration interface is output; wherein, the current configuration interface includes a fixed configuration interface and a flexible configuration interface; In response to the parameter configuration operation of the current configuration interface, permission configuration information is generated.

3. The method according to claim 2, characterized in that, If the current configuration interface is the fixed configuration interface, the parameter configuration operation in response to the current configuration interface, generating permission configuration information, includes: In response to the permission level selection command in the fixed configuration interface, generate the current permission level information; Preliminary configuration information is selected from preset candidate configuration information based on the current permission level information; wherein, the preliminary configuration information includes preliminary authorization time and preliminary authorization scope, and the preliminary authorization scope represents the preliminary controller authorized to communicate with the diagnostic device and the preliminary diagnostic permissions of the preliminary controller; In response to the modification instructions for the initial authorization time, the initial controller, and the initial diagnostic permissions, the permission configuration information is generated.

4. The method according to claim 2, characterized in that, If the current configuration interface is a flexible configuration interface, the parameter configuration operation in response to the current configuration interface, generating permission configuration information, includes: In response to the controller selection command for the flexible configuration interface, a target controller is generated; In response to the diagnostic permission configuration instruction of the target controller, the target diagnostic permissions of the target controller are generated; wherein, the target diagnostic permissions include at least one of the following: data read permission, function control permission, configuration write permission, and software upgrade permission; In response to the time configuration command of the target controller, the target authorized time is generated; The target controller, the target diagnostic permissions, and the target authorization time are concatenated to obtain the permission configuration information.

5. The method according to any one of claims 1 to 4, characterized in that, After receiving the diagnostic request, the method further includes: Collect user identity information; The user identity information is authenticated based on preset reference authentication information to obtain identity authentication information; If the identity authentication information indicates that the user's identity information has been successfully authenticated, and in response to the diagnostic permission instruction of the diagnostic request, the access permission configuration interface is output; If the authentication information indicates that the user's identity information authentication has failed, the communication between the diagnostic device and the vehicle diagnostic interface is cut off.

6. The method according to any one of claims 1 to 4, characterized in that, After receiving the diagnostic request, the method further includes: In response to the diagnostic rejection instruction of the diagnostic request, virtual vehicle status data is generated according to preset feedback configuration information; wherein, the virtual vehicle status data is data that is unrelated to the actual vehicle status; The virtual vehicle status data is sent to the gateway, which then sends the virtual vehicle status data to the diagnostic device.

7. The method according to claim 6, characterized in that, The diagnostic rejection instruction of the diagnostic request generates virtual vehicle status data based on preset feedback configuration information, including: In response to the diagnostic rejection instruction of the diagnostic request, the diagnostic equipment is classified into risk levels to obtain the current risk level; Selected feedback configuration information is filtered from the preset feedback configuration information based on the current risk level; The virtual vehicle status data is generated based on the selected feedback configuration information.

8. An access processing device for a diagnostic device, characterized in that, The device is applied to a vehicle, the vehicle including a vehicle diagnostic interface, and the device includes: A receiving module is used to receive diagnostic requests; wherein the diagnostic request is sent by the gateway in response to the diagnostic device accessing the vehicle diagnostic interface; The interface output module is used to respond to the diagnostic permission instruction of the diagnostic request and output the access permission configuration interface; The permission configuration module is used to generate permission configuration information in response to the configuration operation of the access permission configuration interface; wherein, the permission configuration information includes target authorization time and target authorization scope, and the target authorization scope represents the target controller that authorizes the diagnostic device to communicate and the target diagnostic permissions of the target controller; The information generation module is used to generate access authentication information based on the target authorization time, the target controller, and the target diagnostic permissions; The sending module is used to send the access authentication information to the gateway, so that the gateway controls the communication operation between the diagnostic device and the target controller according to the access authentication information.

9. A vehicle, characterized in that, The vehicle includes an in-vehicle terminal, a display screen, a gateway, and a vehicle diagnostic interface. The in-vehicle terminal includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.