Vehicle remote diagnosis and debugging method and system

By deploying special debugging centers and tunnel centers on vehicles and cloud platforms, creating intranet penetration tunnels, the problem of low security in remote diagnosis and debugging of vehicles is solved, safe and convenient remote debugging is achieved, and development costs are reduced.

WO2025145977A1PCT designated stage expired Publication Date: 2025-07-10CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/143169
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-02
Filing Date
2024-12-27
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

The existing vehicle remote diagnosis and debugging technology is low in security under the intranet debugging conditions, and there is a possibility of internal and external attacks. It is difficult to develop remotely and has high cost.

Method used

The vehicle debugging center and the cloud debugging center are deployed on the vehicle and cloud platforms respectively. The cloud tunnel center is used to create an intranet penetration tunnel. Through the encryption mechanism and authentication mechanism of the vehicle tunnel client and the cloud tunnel center, the security of the debugging tunnel is ensured, and general tunnel tools such as FRP and NPS are used to realize the deployment of the debugging tunnel to avoid secondary development.

Benefits of technology

It improves the security and deployment convenience of vehicle remote debugging, reduces the cost of remote debugging and development, prevents malicious attacks, and ensures the encryption mechanism and identity authentication of debug tunnels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024143169_10072025_PF_FP_ABST
    Figure CN2024143169_10072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of vehicle debugging, and discloses a vehicle remote diagnosis and debugging method and system. The method comprises: a vehicle sends information about a part to be debugged to a cloud debugging center by means of a vehicle-end debugging center, so that the cloud debugging center applies to a cloud tunnel center on a cloud platform for tunnel connection information in response to the information about said part; the vehicle receives, by means of the vehicle-end debugging center, the tunnel connection information returned by the cloud debugging center, and then forwards the tunnel connection information to a target part debugging center of said part; the vehicle then starts a target vehicle-end tunnel client by means of the target part debugging center, and uses the target vehicle-end tunnel client to carry the tunnel connection information to apply to the cloud tunnel center for a debugging tunnel, so that the cloud tunnel center creates the debugging tunnel when the verification of the tunnel connection information succeeds; and the vehicle receives, by means of the debugging tunnel, a remote debugging instruction issued by the cloud platform. The present application solves the problem of low vehicle remote debugging security under intranet debugging conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle remote diagnosis and debugging method and system

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on January 2, 2024, with application number 202410006860.X and invention name “A vehicle remote diagnosis and debugging method and system”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present invention relates to the technical field of vehicle debugging, and in particular to a vehicle remote diagnosis and debugging method and system. Background Art

[0004] With the shift to platform-based vehicles, vehicle diagnostics and debugging have become an integral part of vehicle development and maintenance. However, offline debugging at 4S dealerships often fails to capture real-time data, leading to the rise of remote diagnostics and debugging. Traditional vehicle remote diagnostics require the vehicle to connect to a public cloud server. Debugging commands from the cloud server are then transmitted to the vehicle via the public network. The vehicle then converts the command protocol into CAN messages for in-vehicle transmission. The complexity of the vehicle network environment and the difficulty of developing conversion protocols also complicate remote diagnostics. Some technologies, based on intranet VPN technology, establish a debugging link between the server and the vehicle, enabling remote vehicle debugging. The vehicle under debugging requires no custom software or proprietary protocols; instead, the vehicle's native controller debugging tool service is integrated and its configuration can be modified. However, remote debugging presents the potential for internal and external attacks, potentially launching attacks against the vehicle through the link. Therefore, the security of remote vehicle debugging remains uncertain. Summary of the Invention

[0005] In view of this, the present application provides a vehicle remote diagnosis and debugging method and system to solve the problem of low security of vehicle remote debugging under intranet debugging conditions.

[0006] In a first aspect, the present application provides a vehicle remote diagnosis and debugging method, which is applied to a vehicle and includes: sending information about a part to be debugged via a vehicle-side debugging center to a cloud-side debugging center, so that the cloud-side debugging center, in response to the information about the part to be debugged, requests tunnel connection information from a cloud-side tunnel center on a cloud platform, wherein the vehicle-side debugging center and the cloud-side debugging center deployed on the cloud platform are software modules for communicating with each other over the public network, and the cloud-side tunnel center is a server for establishing an intranet-penetrating tunnel; receiving tunnel connection information returned by the cloud-side debugging center via the vehicle-side debugging center; forwarding the tunnel connection information to a target component debugging center for the part to be debugged via the vehicle-side debugging center, wherein each debuggable part on the vehicle is deployed with a component debugging center for controlling the opening or closing of a corresponding vehicle-side tunnel client of the debuggable part, and the vehicle-side tunnel client is a client for establishing an intranet-penetrating tunnel; opening a target vehicle-side tunnel client via the target component debugging center, and applying for a debugging tunnel from the cloud-side tunnel center via the target vehicle-side tunnel client carrying the tunnel connection information, wherein the debugging tunnel is established after the cloud-side tunnel center verifies the tunnel connection information; receiving a remote debugging instruction issued by the cloud platform based on the information about the part to be debugged via the target vehicle-side tunnel client, and debugging the part to be debugged using the remote debugging instruction.

[0007] Based on the above technical means, the embodiments of the present application deploy a vehicle-side debugging center and a cloud-side debugging center for public network communication on the vehicle and cloud platform, respectively. A cloud-side tunnel center for establishing an intranet penetration tunnel is then deployed on the cloud platform, and a vehicle-side tunnel client is deployed on each vehicle-side component. Thus, when a user requires an engineer to remotely debug one or more vehicle components, the user first sends the information about the component to be debugged to the cloud platform via the public network. The cloud platform uses the received information about the component to be debugged to request tunnel connection information from the cloud-side tunnel center, which then returns the tunnel connection information to the vehicle. The vehicle then uses the vehicle-side tunnel client for the component to be debugged, along with the tunnel connection information, to request an intranet penetration tunnel from the cloud-side tunnel center. Only after the cloud-side tunnel center decrypts and verifies the tunnel connection information is the debugging tunnel established, providing the debugging tunnel with an encryption mechanism and ensuring its security. Furthermore, the present application can implement debugging tunnel deployment using common tunneling tools such as FRP and NPS, eliminating the need for secondary component development. This makes deployment easier than current remote debugging methods in the industry, while also reducing remote debugging development costs.

[0008] In an optional embodiment, the information of the part to be debugged includes attribute information of the part to be debugged and a diagnostic debugging code. The attribute information of the part to be debugged is used to describe the part to be debugged, and the diagnostic debugging code is used to be returned to the vehicle-side debugging center by the cloud debugging center together with the tunnel connection information, so that the vehicle-side debugging center can verify whether the received diagnostic debugging code is consistent with the issued diagnostic debugging code.

[0009] According to the above technical means, when the user needs an engineer to perform remote diagnosis and debugging, the vehicle also sends a diagnostic debugging code to the cloud platform. When the cloud platform subsequently returns the tunnel connection information, it will carry the diagnostic debugging code back to the vehicle. The vehicle can then determine whether the tunnel connection information is returned by the correct cloud debugging center based on the consistency of the diagnostic debugging code sent and received, to avoid the returned tunnel connection information being false attack information sent by external hackers.

[0010] In an optional embodiment, the diagnostic debug code is generated in the following manner: a hash value is calculated using the current timestamp, the vehicle's unique identifier, and the screen coordinates, where the screen coordinates are the coordinate values ​​clicked on the vehicle screen when the user requests to generate the diagnostic debug code; a preset number of digits is randomly extracted from the hash value as the diagnostic debug code.

[0011] According to the above technical means, the diagnostic debugging code introduces screen click coordinates compared to the general verification code. Because the trigger button is a coordinate area, and the process of the vehicle user clicking the screen coordinates is more random, the random verification code generated by this method is more random, more difficult to crack, and more secure than the traditional random verification code.

[0012] In an optional implementation, the tunnel connection information includes a tunnel connection code and tunnel identity authentication information.

[0013] According to the above technical means, the tunnel connection information provided in the embodiment of the present application includes a tunnel connection code and tunnel identity authentication information. The tunnel connection code is used to pair the vehicle-side tunnel client and the cloud-side tunnel center to create a debugging channel. The tunnel identity authentication information is used by the cloud-side tunnel center to verify that the tunnel connection code sent by the vehicle-side tunnel client comes from the tunnel connection code sent by the cloud platform before, rather than the tunnel connection code sent by a hacker in an attempt to attack, thereby further ensuring the security of the tunnel.

[0014] In an optional implementation, a remote debugging instruction issued by the cloud platform according to the information of the part to be debugged is received through the target vehicle-side tunnel client, including: receiving the remote debugging instruction and auditing the remote debugging instruction according to the instruction whitelist and the parameter whitelist; when the audit fails, refusing to debug the part to be debugged through the remote debugging instruction; when the audit passes, executing the step of debugging the part to be debugged through the remote debugging instruction.

[0015] According to the above technical means, before the vehicle is remotely debugged according to the remote debugging instructions issued by the cloud platform, the remote debugging instructions are first audited through the instruction whitelist and parameter whitelist. Only the instructions that pass the audit are remotely debugged, thereby further preventing internal engineers from entering malicious debugging instructions to cause damage to the vehicle and solving internal security issues.

[0016] In an optional embodiment, the method further includes: closing the target vehicle-side tunnel client through the target component debugging center, and destroying the tunnel connection information and diagnostic debugging code, so that the cloud tunnel center closes the debugging tunnel when the monitoring debugging tunnel has not transmitted data for a preset time period.

[0017] Based on the above technical means, a safe and convenient debugging tunnel logout mechanism is provided.

[0018] In an optional implementation, after the vehicle-side debugging center verifies that the received diagnostic debugging code is consistent with the issued diagnostic debugging code, the method further includes: disabling the USB short-range debugging mechanism through the vehicle-side debugging center and destroying the diagnostic debugging code.

[0019] According to the above technical means, the introduction of the USB short-range debugging disabling mechanism can more effectively prevent malicious users from accessing the tunnel and launching attacks on the cloud compared to traditional remote debugging and offline debugging mechanisms.

[0020] In a second aspect, the present application provides a vehicle remote diagnosis and debugging method, which is applied to a cloud platform. The method includes: receiving, through a cloud debugging center, information about parts to be debugged sent by a vehicle-side debugging center, where the vehicle-side debugging center and the cloud debugging center are software modules for communicating with each other over a public network, and the vehicle-side debugging center is deployed on a vehicle; requesting tunnel connection information from a cloud tunnel center in response to the information about parts to be debugged, where the cloud tunnel center is a service end deployed on a cloud platform for creating an intranet penetration tunnel; sending the tunnel connection information to the vehicle-side debugging center through the cloud debugging center, so that the vehicle-side debugging center forwards the tunnel connection information to a target component debugging center for the part to be debugged. And make the target component debugging center open the target vehicle-side tunnel client, where each debuggable component on the vehicle is deployed with a component debugging center, which is used to control the vehicle-side tunnel client corresponding to the debuggable component to be opened or closed. The vehicle-side tunnel client is a client used to create an intranet penetration tunnel; the tunnel connection information sent by the target vehicle-side tunnel client is received through the cloud tunnel center, and the tunnel connection information is verified; when the tunnel connection information is verified, a debugging tunnel is created through the cloud tunnel center; the remote debugging instructions generated according to the information of the part to be debugged are sent to the target vehicle-side tunnel client through the debugging tunnel, so that the vehicle can debug the part to be debugged through the remote debugging instructions.

[0021] In an optional embodiment, the cloud debugging center applies for tunnel connection information from the cloud tunnel center in response to the information of the part to be debugged, including: when the cloud tunnel center receives the application message sent by the cloud debugging center, verifying whether the IP information of the cloud debugging center is within the pre-stored IP information; when the IP information is within the pre-stored IP information, performing two-way certificate authentication on the cloud debugging center through the cloud tunnel center; when the two-way certificate authentication passes, verifying the account and password sent by the cloud debugging center through the cloud tunnel center; when the account and password authentication passes, responding to the application message through the cloud tunnel center, and feeding back the tunnel connection information to the cloud debugging center.

[0022] According to the above technical means, when the cloud debugging center applies for tunnel connection information from the cloud tunnel center, the cloud tunnel center forms a minimum virtual domain for the cloud debugging center by limiting the IP, and then uses certificate and account password authentication to ensure domain security and authenticate the identity of the cloud debugging center to avoid the request for tunnel connection information being issued by a hacker. Compared with the traditional token authentication method, it avoids the risk of malicious access caused by token leakage.

[0023] In an optional implementation, a remote debugging instruction generated according to the information of the part to be debugged is sent to the target vehicle-side tunnel client through the debugging tunnel, including: auditing the remote debugging instruction according to the instruction whitelist and the parameter whitelist; when the audit passes, sending the remote debugging instruction; when the audit fails, refusing to send the remote debugging instruction.

[0024] In an optional embodiment, the method also includes: sending a logout command to the cloud tunnel center through the cloud debugging center; closing the debugging tunnel and destroying the tunnel connection information in response to the logout command through the cloud tunnel center; destroying the tunnel connection information through the cloud debugging center, and sending a logout command to the vehicle-side debugging center, so that the vehicle-side debugging center forwards the logout command to the target component debugging center, so that the target component debugging center closes the target vehicle-side tunnel client and destroys the tunnel connection information.

[0025] In a third aspect, the present application provides a vehicle remote diagnosis and debugging system, which includes a vehicle and a cloud platform, wherein: the vehicle sends information about parts to be debugged to the cloud debugging center of the cloud platform through the vehicle-side debugging center, and the vehicle-side debugging center and the cloud debugging center are software modules for mutual public network communication; the cloud platform responds to the information about parts to be debugged by requesting tunnel connection information from the cloud tunnel center through the cloud debugging center, and the cloud tunnel center is a service end deployed on the cloud platform for creating an intranet penetration tunnel; the cloud platform sends tunnel connection information to the vehicle-side debugging center through the cloud debugging center; the vehicle forwards the tunnel connection information to the target component debugging center of the part to be debugged through the vehicle-side debugging center, wherein Each debuggable part on the vehicle is deployed with a part debugging center, which is used to control the vehicle-side tunnel client corresponding to the debuggable part to be turned on or off. The vehicle-side tunnel client is a client used to create an intranet penetration tunnel; the vehicle turns on the target vehicle-side tunnel client through the target part debugging center; the vehicle sends tunnel connection information to the cloud tunnel center through the target vehicle-side tunnel client; the cloud platform verifies the tunnel connection information through the cloud tunnel center and creates a debugging tunnel when the tunnel connection information verification is successful; the cloud platform sends remote debugging instructions generated based on the information of the part to be debugged to the target vehicle-side tunnel client through the debugging tunnel; the vehicle debugs the part to be debugged using the remote debugging instructions.

[0026] The technical solution provided by this application has the following advantages:

[0027] (1) The embodiment of the present application deploys a vehicle-side debugging center and a cloud-side debugging center for public network communication on the vehicle side and the cloud platform respectively, then deploys a cloud-side tunnel center for establishing an intranet penetration tunnel on the cloud platform, and deploys a vehicle-side tunnel client on each vehicle-side component. Thus, when a user requires an engineer to remotely debug one or more vehicle parts, the information of the parts to be debugged is first sent to the cloud platform via the public network. The cloud platform uses the received information of the parts to be debugged to apply for tunnel connection information from the cloud-side tunnel center, and then returns the tunnel connection information to the vehicle. The vehicle uses the vehicle-side tunnel client of the parts to be debugged to carry the tunnel connection information and apply for an intranet penetration tunnel with the cloud-side tunnel center. Only after the cloud-side tunnel center decrypts and verifies the tunnel connection information is it created, so that the debugging tunnel has an encryption mechanism, ensuring the security of the debugging tunnel. In addition, the present application can realize the deployment of the debugging tunnel through common tunnel tools such as FRP and NPS, without the need for secondary development of components. Compared with the current remote debugging methods in the industry, it has the advantage of being easier to deploy and also reduces the development cost of remote debugging.

[0028] (2) According to the above technical means, when the user needs an engineer to perform remote diagnosis and debugging, the vehicle also sends a diagnostic debugging code to the cloud platform. When the cloud platform subsequently returns the tunnel connection information, it will carry the diagnostic debugging code back to the vehicle. The vehicle can then determine whether the tunnel connection information is returned by the correct cloud debugging center based on the consistency of the diagnostic debugging code sent and received, thereby preventing the returned tunnel connection information from being false attack information sent by external hackers.

[0029] (3) The diagnostic debugging code provided in the embodiment of the present application introduces screen click coordinates compared to general verification codes. Since the trigger button is a coordinate area, and the process of the vehicle user clicking the screen coordinates is more random, the random verification code generated in this way is more random, more difficult to crack, and more secure than the traditional random verification code.

[0030] (4) The tunnel connection information provided in the embodiment of the present application includes a tunnel connection code and tunnel identity authentication information. The tunnel connection code is used to pair the vehicle-side tunnel client and the cloud-side tunnel center to create a debugging channel. The tunnel identity authentication information is used by the cloud-side tunnel center to verify that the tunnel connection code sent by the vehicle-side tunnel client comes from the tunnel connection code previously sent by the cloud platform, rather than the tunnel connection code sent by a hacker in an attempt to attack, thereby further ensuring the security of the tunnel.

[0031] (5) In the embodiment of the present application, before the vehicle is remotely debugged according to the remote debugging instruction issued by the cloud platform, the remote debugging instruction is first audited through the instruction whitelist and parameter whitelist. Only the instructions that pass the audit are remotely debugged, thereby further preventing internal engineers from inputting malicious debugging instructions to cause damage to the vehicle and solving internal security issues.

[0032] (6) Provides a safe and convenient debugging tunnel logout mechanism.

[0033] (7) The introduction of the USB short-range debugging mechanism can more effectively prevent malicious users from accessing the tunnel and launching attacks on the cloud compared to traditional remote debugging and offline debugging mechanisms.

[0034] (8) When the cloud debugging center applies for tunnel connection information from the cloud tunnel center, the cloud tunnel connection center forms a minimum virtual domain with the cloud diagnosis and debugging center by limiting the IP address. Then, the security within the domain is guaranteed by using the certificate and account password authentication method. The identity of the cloud debugging center is authenticated to avoid the request for tunnel connection information being issued by a hacker. Compared with the traditional token authentication method, it avoids the risk of malicious access caused by token leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the specific implementation methods or the description of the prior art. Obviously, the drawings described below are some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0036] FIG1 is a schematic structural diagram of a vehicle remote diagnosis and debugging system according to an embodiment of the present application;

[0037] FIG2 is a flow chart of a vehicle remote diagnosis and debugging method according to an embodiment of the present application;

[0038] FIG3 is another flow chart of a vehicle remote diagnosis and debugging method according to an embodiment of the present application;

[0039] FIG4 is another flow chart of a vehicle remote diagnosis and debugging method according to an embodiment of the present application;

[0040] FIG5 is another flow chart of a vehicle remote diagnosis and debugging method according to an embodiment of the present application;

[0041] FIG6 is another flowchart of a vehicle remote diagnosis and debugging method according to an embodiment of the present application. DETAILED DESCRIPTION

[0042] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.

[0043] According to an embodiment of the present application, an embodiment of a vehicle remote diagnosis and debugging method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0044] In this embodiment, a vehicle remote diagnosis and debugging method is provided, which is applied to a vehicle remote diagnosis and debugging system. As shown in FIG1 , the vehicle remote diagnosis and debugging system provided in the embodiment of the present application includes a vehicle and a cloud platform. A vehicle-side debugging center is deployed on the vehicle side, and a cloud-side debugging center is deployed on the cloud platform. The vehicle-side debugging center and the cloud-side debugging center are software modules used to communicate with each other over the public network. For example, the vehicle-side debugging center and the cloud-side debugging center can communicate over the public network and transmit data through a T-Box. The cloud-side debugging center is mainly used for interaction and identity authentication of operation and maintenance personnel. It is the coordination center for creating and destroying debugging tunnels on the cloud platform. The vehicle-side debugging center is also used for interaction between vehicles and users.

[0045] Furthermore, for each debuggable component in the vehicle, a component debugging center is deployed within the system. Figure 1 uses QNX, TBOX, and EDC components as examples. Each component has a separate component debugging center deployed. This debugging center is used to enable, configure, and disable the vehicle-side tunnel client, as well as debugging services such as SSH and ADB. Furthermore, a vehicle-side tunnel client is deployed in each vehicle component system, and a cloud-based tunnel center is deployed on the cloud platform. The cloud-based tunnel center is the server for creating intranet-penetrating tunnels, while the vehicle-side tunnel client is the client for creating intranet-penetrating tunnels. For example, the cloud-based tunnel center can utilize FRPS (Fast Reverse Proxy Server) or NPS (Network Policy Server), while the vehicle-side tunnel client can utilize FRPC (Fast Reverse Proxy Client) or NPC (Network Policy Server). Through the intranet-penetrating tunnel, components on the vehicle's internal network can be accessed, viewed, diagnosed, and debugged by the cloud platform on the external network.

[0046] Based on the above system, when users need engineers to remotely debug vehicle parts, they can send a debugging request to the cloud debugging center through the vehicle-side debugging center, so that the cloud debugging center opens the cloud tunnel center. The vehicle opens the corresponding vehicle-side tunnel client and SSH (Secure Shell, Secure Shell Protocol), ADB (Android Debug Bridge) and other debugging service programs through the component debugging center of the part to be debugged, so that the opened vehicle-side tunnel client and the opened cloud tunnel center establish an intranet penetration tunnel. Engineers can remotely debug the specified parts based on the established intranet penetration tunnel. The intranet penetration tunnel does not involve protocol conversion between the public network and the CAN communication protocol, which reduces the difficulty of developing remote debugging programs. At the same time, this application realizes remote debugging tunnels for parts through general tunnel tools such as FRPS and NPS, without the need for secondary development of parts. Compared with the current remote debugging methods in the industry, it has the advantage of being easier to deploy and also reduces the development cost of remote debugging.

[0047] In addition, a vehicle remote diagnosis and debugging method provided by the embodiment of the present application based on the above system can further improve the security of remote debugging. As shown in FIG2 , the vehicle remote diagnosis and debugging method provided by the embodiment of the present application includes steps S101 to S105 and steps S201 to S206, wherein steps S101 to S105 are applied to the vehicle, and steps S201 to S206 are applied to the cloud platform. The steps included in the process are as follows:

[0048] Step S101: Send the information of the part to be debugged to the cloud debugging center through the vehicle debugging center;

[0049] Step S201: receiving information about parts to be debugged sent by the vehicle-side debugging center through the cloud debugging center;

[0050] Step S202 , the cloud debugging center applies for tunnel connection information from the cloud tunnel center in response to the information of the part to be debugged;

[0051] Step S203: Sending tunnel connection information to the vehicle-side debugging center via the cloud-side debugging center;

[0052] Step S102: receiving tunnel connection information returned by the cloud debugging center through the vehicle-side debugging center;

[0053] Step S103, forwarding the tunnel connection information to the target component debugging center of the part to be debugged through the vehicle-side debugging center;

[0054] Step S104: Open the target vehicle-side tunnel client through the target component debugging center, and apply to the cloud tunnel center for debugging the tunnel by carrying the tunnel connection information through the target vehicle-side tunnel client;

[0055] Step S204: receiving the tunnel connection information sent by the target vehicle-side tunnel client through the cloud tunnel center and verifying the tunnel connection information;

[0056] Step S205: When the tunnel connection information is verified, a debugging tunnel is created through the cloud tunnel center;

[0057] Step S206: Sending a remote debugging instruction generated according to the information of the part to be debugged to the target vehicle-side tunnel client through the debugging tunnel;

[0058] Step S105: receiving the remote debugging instruction issued by the cloud platform according to the information of the part to be debugged through the target vehicle-side tunnel client, and debugging the part to be debugged through the remote debugging instruction.

[0059] Specifically, in the embodiment of the present application, when a user requires an engineer to remotely debug one or more vehicle parts, the information of the parts to be debugged is first sent to the cloud platform via the public network. The cloud platform uses the received information of the parts to be debugged to apply for tunnel connection information from the cloud tunnel center, and then returns the tunnel connection information to the vehicle. The vehicle uses the vehicle-side tunnel client of the parts to be debugged to carry the encrypted tunnel connection information to apply to the cloud tunnel center for intranet penetration tunnel. Only after the cloud tunnel center decrypts and verifies the tunnel connection information, it creates a debugging tunnel, so that the debugging tunnel has an encryption mechanism, ensuring the security of the debugging tunnel. Finally, the cloud debugging center initiates debugging commands such as SSH login, ADB login, and parts debugging through the created tunnel. The present application implements the deployment of debugging tunnels through general tunnel tools such as FRP and NPS, without the need for secondary development of parts. Compared with the current remote debugging methods in the industry, it has the advantage of being easier to deploy, and also reduces the development cost of remote debugging.

[0060] In addition, in some optional implementations, the tunnel connection information includes a tunnel connection code and tunnel identity authentication information.

[0061] Specifically, the tunnel connection information provided in the embodiment of the present application includes a tunnel connection code and tunnel identity authentication information. The tunnel connection code is used to pair the vehicle-side tunnel client and the cloud-side tunnel center to create a debugging channel. The tunnel identity authentication information is used by the cloud-side tunnel center to verify that the tunnel connection code sent by the vehicle-side tunnel client is truly from the cloud platform, rather than a tunnel connection code sent by a hacker in an attempt to attack, thereby further ensuring the security of the tunnel.

[0062] In some optional implementations, the information about the part to be debugged sent by the vehicle-side debugging center to the cloud-side debugging center includes attribute information of the part to be debugged and a diagnostic debugging code. The attribute information of the part to be debugged is used to describe the part to be debugged, for example, describing whether the current part to be debugged is a QNX component, a TBOX component, and an EDC component. After the diagnostic debugging code is sent to the cloud-side debugging center as a verification code, the cloud-side debugging center returns the diagnostic debugging code and tunnel connection information to the vehicle-side debugging center. After receiving the diagnostic debugging code, the vehicle-side debugging center decrypts it and verifies whether the received diagnostic debugging code is consistent with the sent diagnostic debugging code. If they are inconsistent, it indicates that the tunnel connection information received by the vehicle-side debugging center may be malicious intrusion information, so that the vehicle refuses to execute the subsequent steps of creating a debugging tunnel, thereby further improving the security of vehicle remote debugging.

[0063] In addition, in some optional implementations, when the diagnostic debugging code verification is passed, the vehicle-side debugging center also prompts the vehicle user to reconfirm the authorization for the parts that need to be debugged by displaying a pop-up window on the vehicle computer. After the user authorizes the debugging by clicking the button in the pop-up window on the vehicle computer, the vehicle-side debugging center forwards the tunnel connection information to the parts debugging center. By adding a step of user authorization, the security of vehicle remote debugging is further improved.

[0064] Furthermore, in some optional implementations, bidirectional certificate authentication is required when the vehicle-side debugging center and the component debugging center interact. Specifically, the component debugging center stores the vehicle-side debugging center's certificate, and the vehicle-side debugging center stores the component debugging center's certificate. Bidirectional certificate authentication is achieved by exchanging certificates and verifying that the sent certificate matches the stored certificate. Only after identity authentication does the component debugging center enable the vehicle-side tunnel client and debugging services like SSH and ADB, further enhancing the security of remote debugging.

[0065] It should be noted that the vehicle-side debugging center can send the attribute information of the parts to be debugged and the diagnostic debugging code to the cloud debugging center in either a direct way or a way for the vehicle user to generate the corresponding attribute information of the parts to be debugged and the diagnostic debugging code by operating the vehicle-side debugging center on the vehicle. The vehicle user then sends the attribute information of the parts to be debugged and the diagnostic debugging code to the engineer's client (such as the engineer's mobile phone, personal computer, etc.) through SMS, phone call, network SMS, etc. The engineer then manually enters the received attribute information of the parts to be debugged and the diagnostic debugging code into the cloud debugging center. Before the engineer manually enters the attribute information of the parts to be debugged and the diagnostic debugging code into the cloud debugging center, the engineer's identity can be verified. Only after the verification is passed can the engineer be authorized to enter. This reduces the risk of information theft and information tampering caused by the vehicle-side debugging center directly sending the information of the parts to be debugged to the cloud debugging center, thereby further improving the security of vehicle remote diagnosis and debugging.

[0066] In some optional implementations, the diagnostic debugging code is generated as follows:

[0067] Step a1: Calculate a hash value using the current timestamp, the vehicle's unique identifier, and screen coordinates. The screen coordinates are the coordinates of the vehicle screen clicked when the user requested to generate a diagnostic debugging code.

[0068] Step a2: randomly extracting a preset number of digits from the hash value as a diagnostic debugging code.

[0069] Specifically, when generating the diagnostic debugging code, the embodiment of the present application requires the user to click on the interactive interface of the vehicle-side debugging center to trigger the instruction to generate the diagnostic debugging code. Then, the vehicle-side debugging center calculates the hash value (for example, 32 bits) by using the current timestamp, the vehicle frame number, and the coordinate value of the user clicking the screen, and randomly selects a preset number of bits (for example, 10 bits) as the diagnostic debugging code. The algorithm formula is as follows:

[0070] Diagnostic debugging code = RANDOM (HASH (Vehicle number + current timestamp + screen coordinates), preset digits)

[0071] The diagnostic debugging code provided in the embodiment of the present application introduces screen click coordinates compared to general verification codes. Because the trigger button is a coordinate area, and the process of the vehicle-side user clicking the screen coordinates is more random, the random verification code generated by this method is more secure than the random verification code currently on the market due to its randomness.

[0072] In some optional implementations, step S202 includes:

[0073] In step e1, when the cloud tunnel center receives the application message sent by the cloud debugging center, it verifies whether the IP information of the cloud debugging center is within the pre-stored IP information.

[0074] In step e2, when the IP information is within the pre-stored IP information, a two-way certificate authentication is performed on the cloud debugging center through the cloud tunnel center.

[0075] In step e3, when the two-way certificate authentication is successful, the account and password sent by the cloud debugging center are verified through the cloud tunnel center.

[0076] In step e4, when the account and password authentication is passed, the cloud tunnel center responds to the application message and feeds back the tunnel connection information to the cloud debugging center.

[0077] Specifically, in this embodiment of the present application, when the cloud debugging center requests tunnel connection information from the cloud tunnel center, the cloud tunnel center is also limited to form a minimum virtual domain for the cloud debugging center by limiting the IP addresses that the cloud tunnel center can recognize. The recognized IP addresses correspond to some cloud debugging centers. Security within the domain is then ensured through certificate and account password authentication (the dual certificate authentication steps are the same as in the previous embodiment and will not be repeated here). After the identity of the cloud debugging center is authenticated, the cloud tunnel center responds to the request message and feeds back the tunnel connection information to the cloud debugging center. This solution prevents the request for tunnel connection information from being issued by a hacker and avoids the risk of malicious access due to token leakage compared to traditional token authentication methods.

[0078] Furthermore, in some optional implementations, whenever there is interaction between the cloud debugging center and the cloud tunnel center, the authentication steps e1 through e3 are performed, significantly improving the security of vehicle remote debugging. Similarly, the authentication steps e1 through e3 can also be performed for each interaction between the vehicle-side tunnel client and the cloud tunnel center.

[0079] In some optional implementations, after the vehicle-side debugging center verifies that the received diagnostic debugging code is consistent with the issued diagnostic debugging code, the method further includes:

[0080] Step c1: disable the USB short-range debugging mechanism through the vehicle-side debugging center and destroy the diagnostic debugging code.

[0081] Specifically, by disabling the USB short-range debugging mechanism and destroying the diagnostic debugging code, the embodiment of the present application can more effectively prevent malicious users from accessing the tunnel and launching attacks on the cloud compared to traditional remote debugging and offline debugging mechanisms, thereby further improving the security of vehicle remote debugging.

[0082] In a specific application scenario embodiment, as shown in FIG3 and FIG4 , the technical solution provided by the embodiment of the present application provides the following complete steps for creating a debug tunnel:

[0083] 1. The user reports the problem to the engineer through the client or vehicle;

[0084] 2. The engineer guides the user through the interactive interface of the vehicle debugging center to generate a one-time diagnostic debugging code and information about the parts to be debugged that is valid for 10 minutes.

[0085] 3. The user sends the diagnostic debugging code and the part information to be debugged to the engineer's client through the vehicle or client;

[0086] 4. The engineer logs in to the cloud debugging center and authenticates himself. Then, he enters the diagnostic debugging code and the part information to be debugged into the cloud debugging center.

[0087] 5. After receiving the diagnostic debugging code and the information of the parts to be debugged, the cloud debugging center applies for tunnel connection information from the cloud tunnel center;

[0088] 6. After the Cloud Tunnel Center verifies the IP address, two-way certificate, and account password of the Cloud Debug Center and passes them, it sends the tunnel connection information to the Cloud Debug Center. The tunnel connection information includes a one-time tunnel link code valid for 10 minutes and tunnel identity authentication information.

[0089] 7. After receiving the tunnel connection information, the cloud debugging center packages and encrypts the tunnel connection information, diagnostic debugging code, and some certificate configuration information, and sends it to the vehicle debugging center via the T-Box public network;

[0090] 8. The vehicle-side debugging center decrypts the received packaged information and then authenticates the cloud-based debugging center through authentication methods such as two-way certificate authentication and diagnostic debugging code.

[0091] 9. When identity authentication is passed, the vehicle debugging center pops up an authorization confirmation window on the interactive interface, asking the user to manually authorize remote debugging;

[0092] 10. After the user manually authorizes, the vehicle-side debugging center sends the tunnel connection information to the component debugging center corresponding to the part to be debugged;

[0093] 11. The component debugging center also verifies the vehicle-side debugging center through IP address verification, two-way certificate authentication, and account and password verification. After verification, the corresponding vehicle-side tunnel client is opened and the corresponding SSH, ADB and other debugging services are started;

[0094] 12. The Component Debugging Center disables the USB remote debugging mechanism and destroys the diagnostic debugging code;

[0095] 13. The vehicle-side tunnel client sends a request to the cloud-based tunnel center to create a debugging tunnel, carrying the encrypted tunnel connection information provided by the component debugging center.

[0096] 14. The cloud tunnel center decrypts the tunnel connection information and verifies the tunnel connection information, including two-way certificate authentication, tunnel link code authentication, and tunnel identity authentication information authentication;

[0097] 15. After verification, the cloud tunnel center creates an intranet penetration tunnel with the vehicle-side tunnel client and destroys the tunnel link code in the tunnel connection information.

[0098] In some optional implementations, the above step S206 includes:

[0099] Step f1: Audit the remote debugging instructions according to the instruction whitelist and parameter whitelist.

[0100] Step f2: When the audit passes, a remote debugging instruction is issued.

[0101] In step f3, if the audit fails, the remote debugging instruction is refused to be issued.

[0102] Specifically, as shown in Figure 5, before the cloud tunnel center issues the remote debugging command, the embodiment of the present application uses the command whitelist and parameter whitelist saved by the cloud debugging center to audit the remote debugging command. Only the commands that pass the audit are issued, further avoiding the risk of malicious debugging by internal engineers and improving the security of vehicle remote debugging.

[0103] In some optional implementations, step S105 includes:

[0104] Step b1, receiving a remote debugging instruction and auditing the remote debugging instruction according to an instruction whitelist and a parameter whitelist;

[0105] Step b2: If the audit fails, the debugging part is refused to be debugged through the remote debugging instruction;

[0106] Step b3: When the audit is passed, the step of debugging the part to be debugged is executed through remote debugging instructions.

[0107] Specifically, this application also deploys a command whitelist and a parameter whitelist in the vehicle's component debugging center. Before the vehicle performs remote debugging according to the remote debugging command issued by the cloud platform, the remote debugging command is first audited through the command whitelist and the parameter whitelist to determine whether the remote debugging command is a legal command recorded in the whitelist. Only commands that pass the audit will be remotely debugged, and commands that fail the audit will not execute subsequent debugging steps, thereby further avoiding damage to the vehicle caused by internal engineers entering malicious debugging commands and solving internal security issues.

[0108] In some optional embodiments, the vehicle further performs the following steps:

[0109] In step d1, the target vehicle-side tunnel client is closed through the target component debugging center, and the tunnel connection information and diagnostic debugging code are destroyed, so that the cloud tunnel center closes the debugging tunnel when no data is transmitted in the debugging tunnel for a preset period of time.

[0110] Specifically, the embodiment of the present application sets up a mechanism for the cloud tunnel center to close the debugging tunnel when the monitoring debugging tunnel has not transmitted data for a preset time period, so that the user can actively close the target vehicle-side tunnel client at the target component debugging center and destroy the tunnel connection information and diagnostic debugging code, so that the debugging tunnel will automatically close after a long period of no data transmission. On the one hand, it reduces the loss of communication resources, and on the other hand, it can prevent the debugging tunnel from being maliciously used, thereby realizing a solution for automatic deregistration of the debugging tunnel.

[0111] In some optional implementations, the cloud platform further performs steps g1 to g3, and the vehicle further performs step g4. The specific steps are as follows:

[0112] Step g1: Send a deregistration command to the cloud tunnel center through the cloud debugging center;

[0113] Step g2: responding to the deregistration command through the cloud tunnel center, closing the debugging tunnel and destroying the tunnel connection information;

[0114] Step g3: Destroy the tunnel connection information through the cloud debugging center and send a deregistration command to the vehicle debugging center;

[0115] Step g4: forwarding a deregistration command to the target component debugging center through the vehicle-side debugging center, so as to close the target vehicle-side tunnel client and destroy the tunnel connection information through the target component debugging center.

[0116] Specifically, as shown in Figure 6, the embodiment of the present application also provides a cancellation solution for the cloud platform to actively cancel the debugging tunnel, which sends a cancellation command to the cloud tunnel center and the vehicle-side debugging center through the cloud debugging center, and at the same time makes the cloud tunnel center and the target component debugging center close the debugging tunnel, thereby improving the flexibility of remote debugging and diagnostic control of the vehicle.

[0117] In addition, in some optional implementations, the cloud debugging center will periodically detect inactive tunnels that have not transmitted data within a preset time period to the cloud tunnel center, and then issue a deregistration command to automatically deregister the inactive tunnels.

[0118] The embodiments of the present application also provide a computer-readable storage medium. The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; optionally, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0119] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.

Claims

1. A vehicle remote diagnosis and debugging method, characterized in that Applied to a vehicle, the method includes: Sending information of a part to be debugged to a cloud debugging center through a vehicle - end debugging center, so that the cloud debugging center applies for tunnel connection information from a cloud tunnel center on a cloud platform in response to the information of the part to be debugged. The vehicle - end debugging center and the cloud debugging center deployed on the cloud platform are software modules for mutual public - network communication, and the cloud tunnel center is a server for creating an intranet penetration tunnel; Receiving, by the vehicle - end debugging center, the tunnel connection information returned by the cloud debugging center; Forwarding, by the vehicle - end debugging center, the tunnel connection information to a target component debugging center of the part to be debugged. Each debuggable part on the vehicle is deployed with a component debugging center, which is used to control the opening or closing of a vehicle - end tunnel client corresponding to the debuggable part. The vehicle - end tunnel client is a client for creating an intranet penetration tunnel; Opening, by the target component debugging center, the target vehicle - end tunnel client, and applying for a debugging tunnel from the cloud tunnel center through the target vehicle - end tunnel client carrying the tunnel connection information, so as to create the debugging tunnel after the cloud tunnel center verifies the tunnel connection information; Receiving, by the target vehicle - end tunnel client, a remote debugging instruction sent by the cloud platform according to the information of the part to be debugged, and debugging the part to be debugged through the remote debugging instruction.

2. The method according to claim 1, wherein The information of the part to be debugged includes part attribute information to be debugged and a diagnostic debug code. The part attribute information to be debugged is used to describe the part to be debugged, and the diagnostic debug code is used to be returned by the cloud debugging center to the vehicle - end debugging center together with the tunnel connection information, so that the vehicle - end debugging center verifies whether the received diagnostic debug code is consistent with the sent diagnostic debug code.

3. The method according to claim 2, wherein The diagnostic debug code is generated in the following way: Calculating a hash value using the current timestamp, the unique vehicle identifier, and the screen coordinates. The screen coordinates are the coordinate values clicked on the vehicle - end screen when the user requests to generate the diagnostic debug code; Randomly extracting a preset number of digits from the hash value as the diagnostic debug code.

4. The method according to claim 1, wherein The tunnel connection information includes a tunnel connection code and tunnel identity authentication information.

5. The method according to claim 1, wherein The step of receiving, by the target vehicle - end tunnel client, the remote debugging instruction sent by the cloud platform according to the information of the part to be debugged includes: Receiving the remote debugging instruction and auditing the remote debugging instruction according to an instruction white list and a parameter white list; When the audit fails, rejecting to debug the part to be debugged through the remote debugging instruction; When the audit passes, executing the step of debugging the part to be debugged through the remote debugging instruction.

6. The method according to claim 2, wherein The method further includes: Closing, by the target component debugging center, the target vehicle - end tunnel client, and destroying the tunnel connection information and the diagnostic debug code, so that when the cloud tunnel center monitors that no data is transmitted through the debugging tunnel after a preset time period, the cloud tunnel center closes the debugging tunnel.

7. The method according to claim 2, wherein After verifying that the received diagnostic debug code and the sent diagnostic debug code are consistent at the vehicle-end debugging center, the method further includes: Disabling the USB short-range debugging mechanism through the vehicle-end debugging center and destroying the diagnostic debug code.

8. A vehicle remote diagnosis and debugging method, characterized in that, Applied to the cloud platform, the method includes: Receiving, by the cloud debugging center, the information of the parts to be debugged sent by the vehicle-end debugging center. The vehicle-end debugging center and the cloud debugging center are software modules for mutual public network communication, and the vehicle-end debugging center is deployed on the vehicle; Applying, by the cloud debugging center, for tunnel connection information from the cloud tunnel center in response to the information of the parts to be debugged. The cloud tunnel center is a server deployed on the cloud platform for creating an intranet penetration tunnel; Sending, by the cloud debugging center, the tunnel connection information to the vehicle-end debugging center, so that the vehicle-end debugging center forwards the tunnel connection information to the target component debugging center of the part to be debugged, and enables the target component debugging center to start the target vehicle-end tunnel client. Each debuggable part on the vehicle is deployed with a component debugging center for controlling the opening or closing of the corresponding vehicle-end tunnel client of the debuggable part. The vehicle-end tunnel client is a client for creating an intranet penetration tunnel; Receiving, by the cloud tunnel center, the tunnel connection information sent by the target vehicle-end tunnel client and verifying the tunnel connection information; Creating a debug tunnel through the cloud tunnel center when the tunnel connection information is verified; Issuing, through the debug tunnel, a remote debug instruction generated according to the information of the parts to be debugged to the target vehicle-end tunnel client, so that the vehicle debugs the parts to be debugged through the remote debug instruction.

9. The method according to claim 8, wherein The applying, by the cloud debugging center, for tunnel connection information from the cloud tunnel center in response to the information of the parts to be debugged includes: When the cloud tunnel center receives the application message sent by the cloud debugging center, verifying whether the IP information of the cloud debugging center is within the pre-stored IP information; When the IP information is within the pre-stored IP information, performing two-way certificate authentication on the cloud debugging center through the cloud tunnel center; When the two-way certificate authentication passes, verifying the account and password sent by the cloud debugging center through the cloud tunnel center; When the account and password authentication passes, responding to the application message through the cloud tunnel center and feeding back the tunnel connection information to the cloud debugging center.

10. The method according to claim 8, characterized in that The issuing, through the debug tunnel, a remote debug instruction generated according to the information of the parts to be debugged to the target vehicle-end tunnel client includes: Auditing the remote debug instruction according to the instruction white list and the parameter white list; Issuing the remote debug instruction when the audit passes; Refusing to issue the remote debug instruction when the audit fails.

11. The method according to claim 8, wherein The method further includes: Sending a logout command from the cloud debugging center to the cloud tunnel center; Responding to the logout command through the cloud tunnel center, closing the debug tunnel and destroying the tunnel connection information. Destroy the tunnel connection information through the cloud debugging center, and send a cancellation command to the vehicle-side debugging center, so that the vehicle-side debugging center forwards the cancellation command to the target component debugging center, so that the target component debugging center closes the target vehicle-side tunnel client and destroys the tunnel connection information.

12. A vehicle remote diagnosis and debugging system, characterized in that, The system includes a vehicle and a cloud platform, where: The vehicle sends information of parts to be debugged to the cloud debugging center of the cloud platform through the vehicle-side debugging center. The vehicle-side debugging center and the cloud debugging center are software modules for mutual public network communication. The cloud platform applies for tunnel connection information from the cloud tunnel center in response to the information of parts to be debugged through the cloud debugging center. The cloud tunnel center is a server deployed on the cloud platform for creating an intranet penetration tunnel. The cloud platform sends the tunnel connection information to the vehicle-side debugging center through the cloud debugging center. The vehicle forwards the tunnel connection information to the target component debugging center of the part to be debugged through the vehicle-side debugging center. Each adjustable part on the vehicle is equipped with a component debugging center for controlling the opening or closing of the vehicle-side tunnel client corresponding to the adjustable part. The vehicle-side tunnel client is a client for creating an intranet penetration tunnel. The vehicle opens the target vehicle-side tunnel client through the target component debugging center. The vehicle sends the tunnel connection information to the cloud tunnel center through the target vehicle-side tunnel client. The cloud platform verifies the tunnel connection information through the cloud tunnel center, and creates a debugging tunnel when the tunnel connection information is verified. The cloud platform sends a remote debugging instruction generated according to the information of parts to be debugged to the target vehicle-side tunnel client through the debugging tunnel. The vehicle debugs the part to be debugged through the remote debugging instruction.

Citation Information

Patent Citations

  • Vehicle-mounted multimedia equipment with diagnosis function and diagnosis method

    CN113960988A

  • Information security protection system and method and storage medium

    CN115001870A

  • Systems, methods, and apparatus for managing vehicle data collection

    CN115443637A

  • Vehicle remote debugging system and method

    CN116828009A

  • Vehicle-mounted terminal remote debugging method, server, device, terminal and system

    CN116996548A