GB/T 40855-2021Technical requirements and test methods for cybersecurity of remote service and management system for electric vehicles
电动汽⻋远程服务与管理系统信息安全 技术要求及试验方法
This is a limited preview
Buy now to download the full PDF (21 pages)
Issued by
SAC
Level / Type
National · Recommended
Issue date
October 11, 2021
Implementation date
May 1, 2022
Scope
GB/T 40855-2021 is the English-translated version of 电动汽⻋远程服务与管理系统信息安全 技术要求及试验方法.
This standard specifies the requirements and test methods for cybersecurity of remote service and management system for electric vehicles. This document applies to data communication between the on-board terminals of battery electric vehicles, plug-in hybrid electric vehicles and fuel-cell electric vehicles, vehicle enterprise service and management platforms and public service and management platforms.
Document preview — GB/T 40855-2021
National Standard of the People's Republic of China
- ICS
- 43.020
Issued by: State Administration for Market Regulation; Standardization Administration of the People’s Republic of China.
Contents
- Foreword2
- 1 Scope3
- 2 Normative references3
- 3 Terms and definitions3
- 4 Abbreviations5
- 5 Information security requirements5
- 6 Test method10
- Amendment No. 1 [2025XG1]20
Foreword
This document was drafted in accordance with the rules given in GB/T 1.1-2020, Directives for standardization - Part 1: Rules for the structure and drafting of standardizing documents.
Please note that some of the contents of this document may involve patents. The issuing organization of this document is not responsible for identifying patents.
This document was proposed by the Ministry of Industry and Information Technology of the People's Republic of China.
This document shall be under the jurisdiction of National Technical Committee of Auto Standardization (SAC/TC 114).
The drafting organizations of this document: Neusoft Corporation, China Automotive Technology and Research Center Co., Ltd., Beijing Institute of Technology Xinyuan Information Technology Co., Ltd., Daimler Greater China Ltd., Beijing Qihoo Technology Co., Ltd., Beijing Automotive Technology Center, National Computer Network Emergency Response Technical Team/Coordination Center of China, Volkswagen (China) Investment Co. Ltd., Ford Motor (China) Ltd., FAW Car Co., Ltd., Huawei Technologies Co., Ltd., Dongfeng Motor Corporation Technical Center, China Academy of Information and Communications Technology, SAIC-GM-Wuling Automobile.
The drafters of this document: Chen Jingxiang, Xie Hanguang, Liu Xiaochun, Fang Xiyu, Chen Yikun, Du Zhibin, Li Gang, Yan Minrui, Li Feng, Wang Hui, Zhang Lijia, Xiang Xiaoli, Li Muxi, Pan Kai, Chen Huarong, Gui Li, Feng Heng.
1 Scope
This document specifies the requirements and test methods for cybersecurity of remote service and management system for electric vehicles.
This document applies to data communication between the on-board terminals of battery electric vehicles, plug-in hybrid electric vehicles and fuel-cell electric vehicles, vehicle enterprise service and management platforms and public service and management platforms.
2 Normative references
The contents of the following documents constitute the indispensable clauses of this document through normative references in the text. For dated references, only the version corresponding to that date is applicable to this document; for undated references, the latest version (including all amendments) is applicable to this document.
3 Terms and definitions
Terms and definitions determined by GB/T 19596, GB/T 32960.1-2016, GB/T 32960.3-2016, and the following ones are applicable to this document.
A system for collecting, processing and managing electric vehicle information, and providing information services for networked users. It is composed of a public service and management platform, an enterprise service and management platform and an on-board terminal.
A platform, which is established by the state, local government or its designated agency, for data collection and unified management of electric vehicles within the jurisdiction.
A platform, which is established by the vehicle companies themselves, or by a thirdparty technical unit on a commission basis, to manage electric vehicles and users within the service range, and to provide safe operation services and management.
A device or system, which is installed on the motor vehicle to collect and save the key state parameters of the vehicle and system components, and to send it to the platform.
When data is exchanged between platforms, it serves as a remote service and management platform for the sender of vehicle data.
When data is exchanged between platforms, it serves as a remote service and management platform for the receiver of vehicle data.
Perform integrity verification on the target program of the device based on the root of trust.
4 Abbreviations
5 Information security requirements
5.1 Overall structure diagram
See Figure 1 for the overall structure of information security of the remote service and management system for electric vehicles.
5.2 Security requirements for on-board terminal
5.2.1 General requirements
The on-board terminal shall ensure the hardware, firmware, software systems, data storage, network port transmission, remote upgrades, logs, and system information security, and meet the basic requirements of confidentiality, integrity, and availability.
5.2.2 Functional requirements
5.2.2.1 On-board terminal hardware
The hardware security requirements of the on-board terminal are as follows:
a) There shall be no backdoors or hidden interfaces;
5.2.2.2 On-board terminal firmware
The on-board terminal shall be equipped with the function of security startup, and shall be able to protect the root of trust which is used for secure start, through the root of trust entity.
5.2.2.3 On-board terminal software system
The software system requirements of the on-board terminal are as follows:
a) It shall be equipped with the ability to determine and authorize application access and operation permissions to system resources;
b) Trusted verification should be carried out.
5.2.2.4 On-board terminal data storage
The data storage requirements of the on-board terminal are as follows: stored in accordance with the requirements of GB/T 32960.3-2016 shall be guaranteed; […]
5.2.2.6 On-board terminal remote upgrades
If the on-board terminal is provided with the remote upgrade function, the onboard terminal shall have an upgrade package verification mechanism to verify the integrity of the upgrade package and the authenticity of the source.
5.2.2.7 On-board terminal log
The log function requirements of the on-board terminal are as follows:
the on-board terminal, such as the detection of cyber-attacks, shall be recorded;
include but not limited to: date and time (accurate to the second), vehicle unique identification code, and event type;
allowed to read by authorized applications in an authorized manner;
f) There shall be an upload mechanism for information security event logs, to use a secure communication protocol to send information security event log information to the enterprise platform.
5.2.2.8 On-board terminal system security
The on-board terminal shall not have high-risk and higher security vulnerabilities that were announced by authoritative vulnerability platforms 6 months ago and have not been dealt with.
5.3 Security requirements for communication between platforms
5.3.1 General requirements
The remote service and management system for electric vehicles shall meet the confidentiality, integrity and availability requirements of the transmitted data. The remote service and management system for electric vehicles shall perform two-way authentication with the server platform before the client platform performs platform login.
5.3.3 Secure communication protocol
Requirements for the secure communication protocol are as follows: a) A version of TLS 1.2 or above shall be used; c) TLS session renegotiation shall be disabled; […]
5.5 Platform security requirements
6 Test method
6.3 On-board terminal information security test environment
6.3.1 Hardware test environment
The topological structure of the on-board terminal information security hardware test is shown in Figure 3.
6.3.2 Communication test environment
The topological structure of the on-board terminal information security communication test and verification is shown in Figure 4.
6.4 On-board terminal information security test
6.4.2 On-board terminal firmware information security test
According to the access method and address range description of the root of trust storage area of the on-board terminal secure startup, use software or hardware debugging tools to write the data; verify whether the data can be written into the storage area repeatedly.
According to the access method and address range description of the root of trust storage area of the on-board terminal secure startup, use the software debugging tool to destroy the signature data of the Bootloader. If the signature data is successfully destroyed, use the secure flashing tool to flash the Bootloader whose signature is destroyed; if it is successfully written to the designated area in the onboard terminal, detect whether the on-board terminal chip verifies the Bootloader signature, and stop loading the next-stage system image when the verification is unsuccessful.
According to the access method and address range description of the root of trust storage area of the on-board terminal secure startup, try to use software debugging tools to tamper or replace the stored data in the Bootloader area; detect whether the on-board terminal prohibits writing the tampered or replaced Bootloader to the designated area within the on-board terminal.
Use software debugging tools to destroy the signature data of the system mirror image; write the system mirror image whose signature is destroyed to the designated area in the on-board terminal; check whether the on-board terminal verifies the system mirror image signature, and stop working when the verification is unsuccessful.
6.4.3 On-board terminal software system information security test
6.4.3.1 On-board terminal software system access control test
Create a software application without added access control rights in accordance with the access control rules; use the software application without added access control rights to try to access the protected software application resources; detect whether the protected software application resources can be accessed. According to the access method and address range description of the root of trust storage area of the on-board terminal secure startup, use the software debugging tool to write data into the root of trust storage area of the software system; verify whether the data can be written into the storage area repeatedly. […]
6.4.4 On-board terminal data storage information security test
6.4.5.1 On-board terminal
6.5 Communication security test between platforms
6.5.1 Verification of certification mechanism
Check whether there is an authentication mechanism for communication access between platforms.
Amendment No. 1 [2025XG1]
This amendment was approved by the State Administration for Market Regulation (National Standardization Management Committee) on October 31, 2025, and will be implemented from October 31, 2025.
“5.3.4 Data Unit Encryption" is modified as: "The remote service and management data required by GB/T 32960.3-2016, including at least the realtime information reporting data in 7.2 of GB/T 32960.3-2016, should meet the following encryption requirements:
than 128 bits, or other cryptographic algorithms of the same or higher level;
1. "5.4 Security requirements for communication between on-board terminal and platform" is modified as: "Communication between the vehicle terminal and the platform shall meet the requirements for identity authentication, integrity of transmitted data, and availability. When the vehicle terminal reports real-time information data to the platform as required by GB/T 32960.3-2016, it should preferably be encrypted according to 5.3.4. The secure communication protocol between the vehicle terminal and the platform should preferably meet the technical requirements of 5.3.3."
2. The title of 6.6.3 is modified as: "Vehicle terminal and platform communication and identity authentication test". The content is modified as: In the communication link, capture communication traffic packets between the vehicle terminal and the platform, analyze the captured data packets, and detect whether there are authentication methods such as certificate exchange traffic characteristics or security authentication heartbeat packet traffic characteristics.” The content of “6.4.2.1~6.4.2.4” in “6.4.2 On-board terminal firmware information security test” is replaced by: “Test personnel shall check whether the vehicle terminal meets the requirements of 5.2.2.2, based on the vehicle terminal’s documents provided by the vehicle manufacturer -root of trust, bootloader, and security certification documents of security protection mechanism of system firmware.”
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 21 pages — is available in the English PDF.
How to Buy GB/T 40855-2021
- 1Add to cart. Click the "Buy GB/T 40855-2021" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery. Within seconds you'll receive an email with a secure download link for GB/T 40855-2021 (English PDF). The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 20663-2026 — Accumulators
GB/T 19941.1-2025 — Leather and fur - Determination of formaldehyde content - Part 1: High-performance liquid chromatography method
GB/T 17593.2-2025 — Textile - Determination of Heavy Metals - Part 2: Inductively Coupled Plasma-optical Emission Spectrometry (ICP-OES) and Inductively Coupled Plasma-mass Spectrometry (ICP-MS)
$220.00
USD · One-time purchase
Secure payment via Stripe
Payments accepted