GB/T 45496-2025Motor vehicle product recall — Guidelines for information defect assessment (English PDF)
汽车产品召回 信息缺陷评估指南
Open the GB/T 45496-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (15 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
March 28, 2025
Implementation date
March 28, 2025
Scope
GB/T 45496-2025 is the English-translated version of 汽车产品召回 信息缺陷评估指南.
GB/T 45496-2025 is the Chinese national standard covering when a vulnerability across the cloud, the network, the vehicle and the apps and chargers linked to it becomes a recallable defect — the evaluation process, the likelihood side scored from the attack vector, the trigger conditions, the privileges needed and the user interaction required, the severity, the resulting risk level, the defect determination, and the disposal that follows: a recall, a warning to owners, or an emergency response. First edition, in force from 28 March 2025. Issued on 28 March 2025, it has been in force since 28 March 2025.
Document preview — GB/T 45496-2025
National Standard of the People's Republic of China
- ICS
- 43.020
- Classification
- T 40
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceIII
- IntroductionIV
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Evaluation Process2
- 5 Assessment and Defect Identification3
- 5.1 Overview3
- 5.2 Possibility3
- 5.3 Severity5
- 5.4 Determine vulnerability risk level6
- 5.5 Defect Identification6
- 6 Disposal of evaluation results6
- 6.1 Implementation of recall6
- 6.2 Issuing warnings6
- 6.3 Emergency Response7
- Appendix A (Informative) Vulnerability Exploitation Methods8
- A.1 Attack vectors8
- A.2 Trigger conditions8
- A.3 Permission Requirements8
- A.4 User Interaction8
- References9
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document was proposed and coordinated by the National Technical Committee for Product Defects and Safety Management Standardization (SAC/TC463).
This document was drafted by: State Administration for Market Regulation Defective Product Recall Technology Center, Huawei Technologies Co., Ltd., China Automotive Industry Corporation China Automotive Engineering Research Institute Co., Ltd., China Society of Automotive Engineers, China Automotive (Beijing) Intelligent Connected Vehicle Research Institute Co., Ltd., Guangzhou Xiaopeng Motors Technology Co., Ltd., Tsinghua University, Zhejiang Tsinghua Yangtze River Delta Research Institute, Beijing China Automotive Research Institute Technology Co., Ltd., China Automotive Data Co., Ltd., Yutong Beijing Automobile Co., Ltd., Geely Automobile Group Co., Ltd., Beijing Mercedes-Benz Sales and Service Co., Ltd., Beijing Ideal Automobile Co., Ltd. company.
The main drafters of this document are: Li Yan, Dong Honglei, Xiao Lingyun, Tan Yuhan, Xia Guoqiang, Liang Xinmiao, Li Wenzhao, Xi Ming, He Xing, Zhang Yanan, Chen Guihua, Fang Rui, Ding Xu, Gao Yongqiang, Feng Yongqin, Zhang Heng, Qu Xianguo, Ren Yi, Sun Yingce, Peng Jianfen, Huang Rong, Liu Yahui, Wang Jian, Peng Yamin, Chen Jie, Shi Yan, Zhou Fanhua, Ma Chao, Guo Zhen, Yu Mingming, Ma Tao, Wang Peng, Chen Yupeng, and Wu Shengnan.
Introduction
With the cross-border integration of artificial intelligence, information communication and automotive technology, cars are no longer isolated electromechanical units, but have become an important part of the intelligent ecosystem.
As a carrier, cars have gradually evolved from information-isolated means of transportation to a digital space that integrates travel, entertainment, and services.
Security and information security risks are intertwined and superimposed, making the security situation more complex and severe.
The information security risks faced by automobiles come from "cloud-pipe-end-external links", namely cloud platforms, network transmission, vehicles and related external equipment.
Cloud platform information security risks include malicious theft and tampering of data by hackers, illegal access to sensitive data, etc. Network transmission security risks include But not limited to. 1) Transmission risk, sending wrong information; 2) Authentication risk, impersonating the identity of the verifier through identity forgery, dynamic hijacking, etc.
Information; 3) Protocol risk, attackers use false information to induce vehicle misjudgment. Vehicle-side information security risks include but are not limited to. 1) Software and hardware system
1) System security, such as exploiting vulnerabilities to attack vehicles; 2) Key security, such as attackers obtaining control information through plug-in debugging and reverse analysis, using scripts Control the vehicle through a digital key; 3) Architecture security, such as controlling the vehicle's electronic control unit (ECU) through a controller area network (CAN).
The security of externally linked devices includes, but is not limited to, risks caused by vulnerabilities in external ecological components such as manipulating apps and charging piles.
If there is a loophole in any link of the "link", it may affect driving safety, so automobile information defects need to be considered comprehensively from the perspective of system ecology.
Guidelines for evaluating automotive product recall information defects
1 Scope
This document provides recommendations for the evaluation of automotive product information defects, and outlines the evaluation process, evaluation and defect identification, and the handling of evaluation results.
This document is applicable to automobile manufacturers, parts manufacturers, system suppliers, data service providers, network operators, product recall The recall authorities, product recall technical institutions and other entities conduct defect analysis and defect judgment on the loopholes of the "cloud-pipe-end-external link" system of in-use vehicles.
Determination, risk warning and emergency response.
2 Normative references
GB/T 25069
GB/T 34402-2017
GB/T 40914
GB/T 43387
GB 44495
3 Terms and definitions
The terms and definitions defined in GB/T 25069, GB/T 43387, GB 44495 and the following apply to this document.
3.1 Information defect informationdefect
The vulnerability (3.3) in the cloud-pipe-end-external link system (3.2) was exploited, resulting in the same model, batch or category of vehicle products being Common situations that do not meet national standards or industry standards for protecting personal and property safety, or other situations that endanger personal safety (3.5), property Unreasonable risk to safety (3.6).
3.2 Cloud-channel-device-linksystem
A distribution layer system consisting of vehicle application environment and related information.
Note 1.“Cloud” refers to a network information service carrier, a layer system with connection management, capability exposure, data management and multi-business support capabilities.
Note 2.“Pipeline” refers to the layer system of network information transmission, including vehicle-mounted cellular network communication, LTE-V2X and 802.11p direct wireless communication.
Note 3.“End” refers to the network information application layer system, including vehicles and roadside facilities, automotive electronics, vehicle-mounted terminals and operating systems and other vehicle-related “end” layers.
Note 4.“External links” refer to external ecological components such as control applications and charging piles required for vehicle use.
3.3 Vulnerability
A weakness in an asset or mitigation measure that can be exploited by one or more threats (3.4) [Source. GB 44495-2024, 3.6]
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 15 pages — is available in the English PDF.
Referenced standards
Normative references
Editions of GB/T 45496
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 45496-2025 | Motor vehicle product recall - Guidelines for information defect assessment | current edition | Current |
This page sells the current edition, GB/T 45496-2025. Earlier editions are listed for reference only.
How to Buy GB/T 45496-2025
- 1Add to cart. Click the "Buy GB/T 45496-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB 44495-2024 — Technical Requirements for Vehicle Cybersecurity
GB/T 25069-2022 — Information security techniques—Terminology
GB/T 34402-2017 — Risk assessment and risk control of motor vehicle product safety
Secure payment via Stripe
Payments accepted
GB/T 45496-2025
$260.00