Intelligent Connected Vehicle (ICV) Cybersecurity Assessment

Intelligent Connected Vehicle (ICV) Cybersecurity Assessment
Details:
In response to the rapidly developing intelligent connected vehicle industry and the increasing emphasis on information security in domestic and international markets, GRGTEST, as a state-owned third-party metrology and testing institution, is committed to providing Intelligent Connected Vehicle (ICV) Cybersecurity Assessment services for automobiles in the process of the new four modernizations industry, and has built a "one-stop" intelligent connected vehicle information security evaluation system for automobile customers.
Send Inquiry
Download
Description
Technical Parameters

Service Scope

 

GRGTEST assists enterprises in establishing relevant process systems, improving development processes, and obtaining process certifications through technical consulting. At the same time, it can also provide technical consulting for product development (such as TARA analysis, security goal setting, etc.) for the corresponding products that the enterprise wants to develop, assist the enterprise in developing products that meet the corresponding information security requirements, and obtain product certification according to the needs.

 

product-600-450

 

Test service

 

GRGTEST has established an automotive information security testing laboratory, which can provide services such as compliance testing, functional testing, vulnerability scanning, fuzz testing, and penetration testing in the field of automotive information security.

 

product-1050-433

 

Compliance Test

Conduct compliance testing of automotive components in accordance with recommended national standards such as GB/T 40855, GB/T 40856, GB/T 40857, and GB/T41578. Conduct safety function testing and verification work item by item based on the standards, and issue a testing report recognized by the China National Accreditation Service for Conformity Assessment (CNAS). At the same time, type inspection tests for automotive information security can be conducted in accordance with the upcoming GB "Technical Requirements for Automotive Vehicle Information Security".

 

Security Test

Mainly based on the Cybersecurity Verification and Validation specification produced by ISO 21434, covering security performance testing, resource security testing, response security testing, interface security testing, control flow and data flow verification, etc. Generally, verification testing is performed by the enterprise security function development team, and in cases of limited resources, independent third-party technical organizations are commissioned for verification.

 

Vulnerability Scanning

Test for known vulnerabilities based on the latest vulnerability libraries such as CVE and CNVD, covering static code vulnerability scanning, firmware vulnerability scanning, component (third-party/open source) vulnerability scanning, system kernel vulnerability scanning, system port vulnerability scanning, application vulnerability scanning, communication protocol (WiFi, Bluetooth, etc.) vulnerability scanning, etc.

 

Penetration Test

The process of simulating real attack techniques to conduct practical testing on the entire vehicle and its components aims to further discover security risks that cannot be detected/overlooked using ordinary security analysis methods, including working through black box, gray box, and white box methods, covering different categories such as hardware security, system/hardware security, application software security data security, CAN/Ethernet/wireless communication security management platform security, etc.

 

Fuzz Test

The attack methods commonly used by hackers are also common methods for robustness analysis of complex logic, and have the advantage of discovering errors without false positives. Mainly targeting unknown vulnerabilities in interfaces and protocols through injecting random data analysis. Including hardware interface fuzz testing CAN fuzz testing, vehicle Ethernet fuzz testing, DolP fuzz testing, open port fuzz testing, Bluetooth fuzz testing, WiFi fuzz testing GNSS fuzz testing, sensor universal electromagnetic signal fuzz testing, MEMS sensor ultrasonic signal fuzz testing, etc.

 

Our Advantages

 

Complete hardware support

With a dedicated laboratory room of over 1000 square meters and dozens of testing tools, including mainstream static and dynamic testing tools, commonly used performance testing tools, vulnerability scanning tools, and a complete set of FPGA tools.

 

High end personnel team

A group of comprehensive talents with rich technical and management experience in software project management, quality assurance, lean measurement, software evaluation, etc. have been gathered. All testing personnel have undergone systematic training and regularly participate in relevant ability comparisons to ensure the scientificity and impartiality of testing and evaluation results,

 

Leading technical capabilities

Combining years of software evaluation experience, continuously iterating and updating the testing and training system based on the Lean Competency Roadmap, we have built testing level testing capabilities and multiple professional technical capabilities throughout the software lifecycle.

 

National Service Network

Relying on the GRGTEST National Service Platform, it can quickly respond to enterprise needs and provide on-site testing services nearby.

 

 

Hot Tags: intelligent connected vehicle (icv) cybersecurity assessment, China intelligent connected vehicle (icv) cybersecurity assessment service provider

Send Inquiry