Ensuring Safety and Security in CAN-Based Automotive Embedded Systems: A Combination of Design Optimization and Secure Communication

被引:38
作者
Mun, Hyeran [1 ]
Han, Kyusuk [2 ]
Lee, Dong Hoon [1 ]
机构
[1] Korea Univ Seoul, Grad Sch Informat Secur, Seoul 02841, South Korea
[2] LG Elect Seocho Res & Dev Campus, Seoul 06772, South Korea
关键词
Security; Task analysis; Safety; Automotive engineering; Timing; Protocols; In-vehicle network; controller area network (CAN); electronic control unit (ECU); safety; security; optimization of task allocation; authentication; AUTHENTICATION;
D O I
10.1109/TVT.2020.2989808
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
As automotive embedded systems comprised of electronic control units (ECUs) connected via a controller area network (CAN) have continued to develop, the volume of information these systems are required to handle has also rapidly increased. Cyber attacks targeting vulnerable points of automotive embedded systems in particular are on the rise to hinder normal operation of a vehicle. However, adding security mechanisms to defend against attacks cannot neglect timing requirements in terms of vehicle safety. This is because it may lead to a violation of automobile safety. In short, both sides of this issue must be addressed from the outset of the system design stage to provide optimal security and safety. As a response to this pressing issue, we propose a novel and efficient scheme. The design optimization during the system design phase not only ensures all the real-time applications are executed within their deadline but also reduces the number of transmitted messages over the CAN bus. After optimization, we apply a hash message authentication code (HMAC) to specific messages, providing secure communication between ECUs and protecting against cyber attacks. Security analysis and experimental results prove that the proposed scheme can counter attacks on the CAN bus while meeting timing requirements. Therefore, our proposed scheme is effective in satisfying improvement of both safety and security.
引用
收藏
页码:7078 / 7091
页数:14
相关论文
共 58 条
[1]  
[Anonymous], 2017, AUTOSAR SPECIFICATIO
[2]  
[Anonymous], 2011, P 20 USENIX SEC S SA
[3]  
[Anonymous], 2011, TRANCTION CONTROL SY
[4]  
[Anonymous], 2015, ELECT CONTROL
[5]  
[Anonymous], 2012, MIXED CRITICALITY SY
[6]  
[Anonymous], 2010, RECALL 2010 TOYOTA P
[7]  
[Anonymous], 2010, TOYOTA ACKNOWLEDGES
[8]  
[Anonymous], 2012, P 10 ESCAR C EMBEDDE
[9]  
[Anonymous], 2017, SAFETY SECURITY CORE
[10]  
[Anonymous], 2010, TOYOTA SOFTWARE BLAM