Valid

GB/T 40857-2021Technical requirements and test methods for cyber security of vehicle gateway

汽⻋网关信息安全技术要求及试验方法

Preview — first pages of GB/T 40857-2021 (full document: 20 pages)

This is a limited preview

Buy now to download the full PDF (20 pages)

Issued by

SAC

Level / Type

National · Recommended

Issue date

October 11, 2021

Implementation date

May 1, 2022

Scope

GB/T 40857-2021 is the English-translated version of 汽⻋网关信息安全技术要求及试验方法.

This Standard specifies cyber security technical requirements and test methods for vehicle gateway product hardware, communication, firmware, data. This Standard is applicable to the design and implementation of cyber security of vehicle gateway products. It is also applicable to product testing, evaluation and management.

Document preview — GB/T 40857-2021

National Standard of the People's Republic of China

ICS
43.020

Issued by: State Administration for Market Regulation; Standardization Administration of the People's Republic of China.

Contents

  • Foreword3
  • 1 Scope4
  • 2 Normative references4
  • 3 Terms and definitions4
  • 4 Abbreviations5
  • 5 Vehicle gateway network topology6
  • 6 Technical requirements7
  • 7 Test methods11
  • Annex A Example of vehicle gateway topology
  • Annex B Examples of typical attacks
  • Bibliography21

Foreword

This Standard was drafted in accordance with the rules given in GB/T 1.1-2020 “Directives for standardization - Part 1: Rules for the structure and drafting of standardizing documents”.

Attention is drawn to the possibility that some of the elements of this Standard may be the subject of patent rights. The issuing authority shall not be held responsible for identifying any or all such patent rights.

This Standard was proposed by Ministry of Industry and Information Technology of the People's Republic of China.

This Standard shall be under the jurisdiction of National Technical Committee on Automobiles of Standardization Administration of China (SAC/TC 114).

The drafting organizations of this Standard: Guangzhou Automobile Group Co., Ltd., China Automotive Technology and Research Center Co., Ltd., Pan Asia Automotive Technology Center Co., Ltd., SAIC Motor Technology Center, Beijing Automotive Research Institute Co., Ltd., Daimler Greater China Investment Co., Ltd., Geely Automobile Research Institute (Ningbo) Co., Ltd., Neusoft Group Co., Ltd., Chongqing Changan Automobile Co., Ltd., Dongfeng Motor Group Co., Ltd. Technology Center, Ministry of Transport Highway Research Institute.

Main drafters of this Standard: Shang Jin, Sun Hang, Gu Jijie, Li Baotian, Feng Haitao, Fei Xiao, Chen Xin, Lu Ming, Yang Chenghao, Chen Jingxiang, He Kexun, He Wen, Cheng Zhou, Liu Zhichao.

1 Scope

This Standard specifies cyber security technical requirements and test methods for vehicle gateway product hardware, communication, firmware, data.

This Standard is applicable to the design and implementation of cyber security of vehicle gateway products. It is also applicable to product testing, evaluation and management.

2 Normative references

The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.

3 Terms and definitions

3.1 vehicle gateway

an electronic control unit of which the main function is to safely and reliably forward and transmit data between multiple networks in the vehicle conversion between different communication protocols. Information can be exchanged among the functional domains that share communication data.

3.3 entity of root of trust

A functional module that is used to support the establishment and transmission of the trust chain of the trusted computing platform that can provide external services such as integrity measurement, secure storage, and cryptographic computing.

4 Abbreviations

5 Vehicle gateway network topology

5.1 CAN gateway

The vehicle gateways in this type of structure mainly have CAN and/or CAN- FD bus interfaces, which can be called CAN gateways.

The typical CAN gateway topology is shown in Figure A.1 in Annex A.

5.2 Ethernet gateway

The vehicle gateway in this type of structure mainly has an Ethernet interface, which can be called an Ethernet gateway.

The typical Ethernet gateway topology is shown in Figure A.2.

6 Technical requirements

6.1 Hardware cyber security requirements

6.1.1 Test according to 7.1a). The gateway shall not have backdoors or hidden interfaces.

6.1.2 Test according to 7.1b). The debugging interface of the gateway shall be disabled or set up security access control.

6.2 Communication cyber security requirements

6.2.1 CAN gateway communication cyber security requirements
6.2.1.1 Access control

The gateway shall establish a communication matrix between each CAN network. Establish an access control strategy based on CAN data frame identifier (CANID). After testing according to 7.2.1a), the data frame sent by the source port shall be detected at the destination port specified in the list. After testing according to 7.2.1b), data frames that do not meet the definition shall be discarded or logged.

6.2.1.2 Denial of service attack detection

The gateway shall perform CAN bus DoS attack detection on the CAN channel of the vehicle's external communication interface (for example: the channel connected to the OBD-II port and the channel connected to the vehicle information interaction system).

The gateway shall have a DoS attack detection function based on the CAN bus interface load. It shall have a DoS attack detection function based on one or more CANID data frame periods.

Test according to 7.2.1c) and d). When the gateway detects a DoS attack on one or more CAN channels, it shall meet the following requirements:

channel of the gateway shall not be affected;

6.2.1.3 Data frame health detection

The gateway shall check the data frame according to the signal definition in the communication matrix. The checking content includes DLC field, signal value validity. Test according to 7.2.1e), f). Discard or log data frames that do not meet the definition of the communication matrix.

6.2.1.4 Data frame anomaly detection

The gateway shall have a data frame abnormality detection function, that is, the mechanism for checking and recording the sending and receiving relationship between data frames is tested in accordance with 7.2.1g). Discard or log the abnormal data frames.

When the gateway detects that the transmission frequency of a data frame within a certain period of time is far from the predefined frequency, or the signal value content of the same data frame at adjacent times conflicts or jumps abnormally, discard or log data frames.

6.2.2 Ethernet gateway communication cyber security requirements

6.3 Firmware cyber security requirements

7 Test methods

7.1 Hardware cyber security test

The gateway hardware cyber security test is carried out in sequence according to the following procedures and requirements:

a) Disassemble the shell of the equipment under test. Take out the PCB board.

Check whether the PCB board hardware has a back door or hidden interface;

b) Check whether there are debugging interfaces such as JTAG, USB, UART, SPI exposed on the PCB board. If it exists, use the test tool to try to obtain debugging permission.

7.2 Communication cyber security test

7.2.1 CAN gateway communication cyber security test

The CAN gateway communication cyber security test is carried out in sequence according to the following procedures and requirements. a) Set the access control strategy specified in 6.2.1.1 (if the access control strategy of the tested sample cannot be modified through the software configuration, the sample sender will provide a list of preset access control strategies). The detection device sends data frames that comply with the policy to the source port specified in the list. Detect the received data frame at the destination port specified in the list. b) Set the access control strategy specified in 6.2.1.1 (if the access control strategy of the tested sample cannot be modified through the software configuration, the sample sender will provide a list of preset access control strategies). The detection device sends data frames that do not comply with the policy to the source port specified in the list. Detect the received data frame at the destination port specified in the list, and collect sample logs. vehicle's external communication interface. The detection device sends a flood attack data frame conforming to the communication matrix with a bus load rate greater than 80% on this channel. Detect the received data frame at the designated destination port and collect sample logs. If there are multiple channels of this type, they are tested separately in turn. uses a 1ms cycle for this channel. Send a CANID data frame conforming to the communication matrix. Detect the received data frame at the designated destination port and collect sample logs. If there are multiple channels of this type, they are tested separately in turn. […]

7.2.3 Cyber security test for hybrid gateway communication

Annex A Example of vehicle gateway topology

Figure A.1~Figure A.3 show examples of related topological structures of vehicle gateways.

Annex B Examples of typical attacks

B.1 Ping of death

An attack by sending malformed or other malicious ping protocol packets to the computer, also known as the ping of death. For example, the attacker deliberately sends IP packets larger than 65536 bits to the attacked, causing the attacked to be unable to process or even the system to crash.

B.2 ICMP flood attack

A simple denial of service attack, also known as ping flood attack. The attacker uses "reply to request" (ping) packet to submerge the attacked.

B.3 UDP flood attack

A denial-of-service attack that uses UDP protocol (a session-less, connectionless transport layer protocol).

B.4 TCP SYN attack

A denial-of-service attack. The attacker sends a series of SYN requests to the target system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic.

B.5 Teardrop attack

In the header of the IP packet, one of the fields is slice displacement. This field indicates the starting position or offset of the fragmented data packet in the original unfragmented data packet. […]

B.7 IP spoofing attack

IP address spoofing means that the attacker sends data packets by impersonating the IP address of a legitimate host, so as to achieve the purpose of obtaining the trust of the attacker or hiding the real IP address of the attacker.

B.8 ICMP Smurf attack

This attack method uses a combination of IP spoofing attacks and ICMP flooding attacks. The attacker forges the source address of the ICMP packet. Set the destination address of the data packet to the broadcast address of the network. […]

B.9 IP address scanning

IP address scanning is a basic network scanning technology. It is sued to determine which addresses in the address range have active computer hosts. A typical address scanning is to send a ping request to each address in a certain address range to try to get a response.

B.10 Port scan

Port scan refers to the attacker trying to establish a communication session with each port on the target host. If the session connection on a certain port is successful, it means that the target host has an open service on that port.

B.11 Malware

Malware refers to the installation of ransomware, viruses, worms, Trojan horses, adware, spyware and other programs that perform malicious tasks on computer systems.

Bibliography

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 20 pages — is available in the English PDF.

How to Buy GB/T 40857-2021

  1. 1Add to cart. Click the "Buy GB/T 40857-2021" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery. Within seconds you'll receive an email with a secure download link for GB/T 40857-2021 (English PDF). The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

$235.00

USD · One-time purchase

English PDF
20 pages
Instant delivery (9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe