Valid

GB 44495-2024Technical Requirements for Vehicle Cybersecurity (English PDF)

汽车整车信息安全技术要求

Preview — first pages of GB 44495-2024 (full document: 27 pages)

Open the GB 44495-2024 preview as PDF

This is a limited preview

Buy now to download the full PDF (27 pages)

Issued by

SAMR / SAC

Level / Type

National · Mandatory

Issue date

August 23, 2024

Implementation date

January 1, 2026

Scope

GB 44495-2024 is the English-translated version of 汽车整车信息安全技术要求.

Specifies requirements for vehicle cybersecurity management systems, basic cybersecurity requirements, and technical cybersecurity requirements for category M and N motor vehicles equipped with electronic control units.

Document preview — GB 44495-2024

National Standard of the People's Republic of China

ICS
43.020

Issued by: State Administration for Market Regulation; Standardization Administration of the People’s Republic of China.

Contents

  • Foreword3
  • 1 Scope4
  • 2 Normative references4
  • 3 Terms and definitions4
  • 4 Abbreviated terms6
  • 5 Requirements for vehicle cybersecurity management system7
  • 6 Basic requirements for cybersecurity8
  • 7 Technical requirements for cybersecurity9
  • 8 Inspection and test methods14
  • 9 Same type determination26
  • 10 Implementation of standards27
  • Bibliography28

Foreword

This document was drafted in accordance with the rules given in GB/T 1.1-2020, Directives for standardization - Part 1: Rules for the structure and drafting of standardizing documents.

The technical content of this document refers to the United Nations Technical Regulation UN R155 Uniform rules for the approval of vehicle cybersecurity and cybersecurity management system.

Please note that some of the contents of this document may involve patents. The issuing organization of this document is not responsible for identifying patents.

This document is proposed and managed by the Ministry of Industry and Information Technology of the People's Republic of China.

1 Scope

This document specifies the requirements for vehicle cybersecurity management system, basic requirements for cybersecurity, technical requirements for cybersecurity and same type identification, and describes the corresponding inspection and test methods.

This document applies to category M and category N vehicles, as well as category O vehicles that are equipped with at least one electronic control unit.

2 Normative references

The following documents are referred to in the text in such a way that some or all of their content constitutes requirements of this document. For dated references, only the version corresponding to that date is applicable to this document; for undated references, the latest version (including all amendments) is applicable to this document.

3 Terms and definitions

Terms and definitions given in GB/T 40861, GB/T 44373 and GB 44496, as well as the following, are applicable to this document.

The state where the vehicle's electrical and electronic systems, components and functions are protected from asset threats.

risks associated with vehicle cyber threats and to protect vehicles from cyberattacks.

The process of discovering, identifying and describing risks, understanding the nature of risks and determining the level of risks, and comparing the results of risk analysis with risk criteria to determine whether the risks are acceptable.

Potential causes of unexpected events that may result in harm to systems, organizations, or individuals.

Weakness that can be utilized by one or more threats in an asset or mitigation.

Software and hardware installed on the vehicle side that are capable of directly receiving, distributing and verifying upgrade packages from outside the vehicle, etc., to achieve software upgrade functions.

Software upgrade that is transferred to the vehicle wirelessly rather than using cables or other local connections.

“Over-the-air upgrade” is also called “remote upgrade”.

“Local connection” generally refers to the physical connection made through the on-board diagnostics (OBD) interface, universal serial bus (USB) interface, etc.

Software upgrade other than over-the-air upgrade.

Personal information that, once leaked or used illegally, may lead to discrimination against vehicle owners, drivers, passengers, people outside the vehicle, etc., or serious harm to their personal or property security.

4 Abbreviated terms

5 Requirements for vehicle cybersecurity management system

5.1 Vehicle manufacturers shall have a cybersecurity management system for the entire vehicle life cycle.

The entire vehicle life cycle includes the vehicle development phase, production phase and post-production phase.

-- Establish a process for vehicle cybersecurity management inside the enterprise.

-- Establish a process for identifying, assessing, classifying, and handling vehicle cybersecurity risks and verifying that identified risks are handled, and ensure that vehicle risk assessments are kept up to date.

-- Establish a process for vehicle cybersecurity testing.

● Including vulnerability management mechanism, clearly defining the activities of vulnerability collection, analysis, informing, handling, release, and reporting;

● Establishing a process to provide relevant data and analyze cyber-attacks, such as analyzing and detecting cyber-attacks, threats and vulnerabilities through vehicle data and vehicle logs;

● Establishing a process to ensure continuous monitoring of cyber-attacks, cyber threats and vulnerabilities, and the vehicle shall be included in the monitoring scope no later than the time of vehicle registration;

● Establishing a process to ensure that identified cyber-attacks, cyber threats and vulnerabilities are responded to and addressed within a time frame;

● Establishing a process to evaluate whether implemented cybersecurity measures remain effective in the event of the discovery of new cyberattacks, cyber threats, and vulnerabilities.

-- Establish a process to manage cybersecurity dependencies between the enterprise and contract suppliers, service providers, and vehicle manufacturer sub-organizations.

6 Basic requirements for cybersecurity

The scope of risk assessment includes the various elements of the vehicle and their interactions, and further considers the interactions with external systems.

Key elements include, but are not limited to, elements that contribute to vehicle security, environmental protection or theft prevention, as well as system components that provide connectivity or parts of the vehicle architecture that are critical to cybersecurity.

6.4 The vehicle manufacturer shall take measures based on the requirements of Chapter 7 to protect the vehicle from the risks identified in the risk assessment. If the measures are not relevant to the identified risks, the vehicle manufacturer shall explain their irrelevance. If the measures are not sufficient to address the identified risks, the vehicle manufacturer shall implement other measures and explain the rationality of the measures used.

6.5 If there is a dedicated environment, the vehicle manufacturer shall take measures to protect the dedicated environment used by the vehicle to store and execute postinstalled software, services, applications or data.

Such as sandbox dedicated environment, etc.

-- Ability to identify vehicle cyber-attacks;

-- Monitoring and data forensics capabilities for vehicle-related cyber-attacks, cyber threats and vulnerabilities.

-- Adopt cryptographic modules that comply with international, national or industry standards;

-- For the cryptographic modules not adopting international, national or industry standards, explain the rationality.

6.10 Vehicles shall adopt default security settings. For example, the default connection password of WLAN shall meet the complexity requirements.

6.11 Requirements such as in-vehicle data processing, non-collection by default, application of accuracy range, desensitization processing, personal consent and prominent notification in motor vehicle data processing activities shall comply with the provisions of 4.2.2 in GB/T 44464-2024.

7 Technical requirements for cybersecurity

7.1 Security requirements for external connections

7.1.1 General security requirements

7.1.1.1 Vehicle-side systems with remote control functions, authorized third-party applications and other external connection systems shall not have high-risk or higher security vulnerabilities that have been announced by the authoritative vulnerability platforms of the automotive industry for 6 months and have not been handled.

Authoritative vulnerability platforms of the automotive industry refer to NVDB-CAVD, a vulnerability database specifically for Internet of Vehicles, and other vulnerability platforms approved by government authorities.

Handling includes methods such as eliminating loopholes and formulating mitigation measures.

7.1.1.2 Vehicles shall turn off network ports that are not essential for service operations.

7.1.2 Security requirements for remote controls

7.1.2.2 Access control shall be set for remote control commands to disable unauthorized remote-control commands. 7.1.2.3 A security log function shall be available to record remote control commands. […]

7.1.3 Security requirements for third party applications

Third-party applications refer to applications provided by entities – other than vehicle manufacturers and their suppliers – who supply services to users, including third-party entertainment applications.

7.1.3.2 Prompts shall be given before the installation of unauthorized third-party applications, and access control shall be performed on installed unauthorized thirdparty applications to restrict such applications from directly accessing system resources, personal information, etc.

7.2 Communication security requirements

7.2.1 When a vehicle communicates with the vehicle manufacturer’s cloud platform, the authenticity of the identity of the communication partner shall be verified. 7.2.2 When vehicles conduct V2X direct communications with other vehicles, road side units, mobile terminals, etc., the validity and legality of the certificates shall be verified. 7.2.3 Vehicles shall use integrity protection mechanisms to protect external wireless communication channels other than RFID and NFC. include code injection, data manipulation, data overwriting, data erasing and data writing commands. side can verify the validity or uniqueness of such commands through the gateway. property security, including but not limited to vehicle control command data. information interaction systems, etc. […]

7.3 Security requirements for software upgrade

7.3.1 General security requirements

7.3.1.1 The on-board software update system shall use security protection mechanisms to protect the trusted root, boot loader, and system firmware of the on-board software update system from being tampered with; if tampered with, the security protection mechanism shall be used to prevent them from starting normally. 7.3.1. […]

7.3.2 Security requirements for over-the-air upgrade

7.3.2.3 Cybersecurity event logs that occur during the over-the-air upgrade process shall be recorded and the log storage period shall be no less than 6 months.

8 Inspection and test methods

8.2 Inspection of basic requirements for cybersecurity

8.2.1 Inspection requirements

8.2.1. […]

8.2.2 Inspection methods

8.2.2.1 Inspect the documents submitted by the vehicle manufacturer and confirm the inspection plan, including the inspection scope, inspection method, inspection schedule, and the list of necessary supporting documents for on-site inspection.

8.2.2.2 Based on the inspection plan confirmed in 8.2.2.1, inspect the cybersecurityrelated process documents retained for reference on-site at the vehicle manufacturer, and confirm whether the vehicle meets the requirements of Chapter 6.

8.3 Test of technical requirements for cybersecurity

8.3.1 Test conditions
8.3.1.1 Test environment requirements

For tests involving wireless short-range communications, the vehicle shall be tested in a test environment without signal interference.

8.3.1.2 Test status requirements

The test samples include the whole vehicle and the parts involved in the test scope determined in 8.1. The following requirements shall be met:

-- During the test, if the test vehicle speed is greater than 0 km/h or the test vehicle may start unexpectedly, place the test vehicle on a complete vehicle rotating hub test bench or in a road environment that ensures safe operation of the test vehicle.

8.3.2 External connection security test
8.3.2.1 General security test
8.3.2.1.1 System vulnerability security test

The tester shall use vulnerability scanning tools to scan the vehicle's external connection system for vulnerabilities, and compare the test results with the list of highrisk and above security vulnerabilities published by the authoritative vulnerability platform of the automotive industry 6 months ago and the vehicle external connection system vulnerability treatment plan provided by the vehicle manufacturer to determine whether the vehicle meets the requirements of 7.1.1.1.

8.3.2.1.2 Non-service essential network port security test

The tester shall network the test vehicle with the scanning test equipment based on the vehicle service port list provided by the vehicle manufacturer through communication channels such as WLAN, vehicle Ethernet, and cellular networks, use the scanning test equipment to test the ports opened by the vehicle, and compare the vehicle open port list obtained from the test with the vehicle service port list to determine whether the vehicle meets the requirements of 7.1.1.2.

8.3.2.2 Remote control security test
8.3.2.2.1 Authenticity and integrity verification security test

The tester shall carry out the test in the following order to determine whether the vehicle meets the requirements of 7.1.2.1:

remote vehicle control commands can be triggered;

whether the commands can be forged or tampered with, and whether the vehicle executes the commands.

8.3.2.3 Third-party application security test
8.3.2.4 External interface security test
8.3.3 Communication security test
8.3.3.2 V2X communication identity authentication security test

The tester shall carry out the test in the following order to determine whether the vehicle meets the requirements of 7.2. […]

8.3.4 Software upgrade security test
8.3.4.1 General security requirements test
8.3.4.2 Over-the-air upgrade security test

9 Same type determination

9.1 Direct criteria for same-type-identification of cybersecurity

9.2 Criteria for same-type-identification after cybersecurity test verification

If the vehicle model is changed in accordance with 9.1, it is only necessary to conduct additional tests on the technical requirements related to the changed parameters when the following provisions are met, and the extension can be obtained after approval:

-- The vehicle controller hardware model and software version number (except those that do not affect the anonymization processing strategy) of the vehicle's anonymization algorithm are the same as those of the manufacturer;

-- The hardware model, main parameter configuration (sampling resolution, sampling field of view, sampling frame rate) of the vehicle's cameras and other acquisition equipment used to implement the anonymization function are the same as those of the manufacturer;

10 Implementation of standards

For new vehicle models applying for type approval, implementation will begin from the date of implementation of this document.

For vehicle models that have obtained type approval, implementation will begin on the 25th month from the date of implementation of this document.

Bibliography

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 27 pages — is available in the English PDF.

Referenced standards

How to Buy GB 44495-2024

  1. 1Add to cart. Click the "Buy GB 44495-2024" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

$280.00

USD · One-time purchase

English PDF
27 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB 44495-2024

$280.00

$240.00for partners