Securing SOME/IP for In-Vehicle Service Protection

被引:29
作者
Iorio, Marco [1 ]
Reineri, Massimo [2 ]
Risso, Fulvio [1 ]
Sisto, Riccardo [1 ]
Valenza, Fulvio [1 ]
机构
[1] Politecn Torino DAUIN, Control & Comp Engn, I-10129 Turin, Italy
[2] Italdesign, I-10024 Turin, Italy
关键词
Protocols; Authentication; Automotive engineering; Service-oriented architecture; Logic gates; In-vehicle security; SOA protection; SOME; IP; CONTROLLER; IDENTIFICATION; AUTHENTICATION;
D O I
10.1109/TVT.2020.3028880
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Although high-speed in-vehicle networks are being increasingly adopted by the industry to support emerging use cases, previous research already demonstrated that car hacking is a real threat. This paper formalizes a novel framework proposed to provide improved security to the emerging SOME/IP middleware, without introducing at the same time limitations in the communication patterns available. Most notably, the entire traffic matrix is designed to be configured using simple high-level rules, clearly stating who can talk to whom according to the service abstraction adopted by SOME/IP. Three incremental security levels are made available, accounting for different services being associated with different requirements. The core security protocol, encompassing a session establishment phase followed by the transmission of secured SOME/IP messages, has been formally verified, to prove its correctness in terms of authentication and secrecy properties. Performance-wise, in-depth experimental evaluations conducted with an extended version of vsomeip confirmed the introduction of quite limited penalties compared to the bare unsecured implementation.
引用
收藏
页码:13450 / 13466
页数:17
相关论文
共 44 条
[1]  
[Anonymous], 2012, RFC 6347
[2]  
[Anonymous], 2011, 20 USENIX SEC S AUG
[3]  
[Anonymous], 2015, Handbook of driver assistance systems: Basic information, components and systems for active safety and comfort
[4]  
[Anonymous], 2016, IEEE Std 802.15.4-2015, P1, DOI [10.1109/IEEESTD.2016.7786995, DOI 10.1109/IEEESTD.2016.7786995, DOI 10.1109/IEEESTD.2016.7460875]
[5]  
AUTOSAR, 2017, SOME IP SERV DISC PR
[6]  
AUTOSAR, 2016, SOME IP PROT SPEC
[7]  
AUTOSAR, 2017, EXPL AD PLATF DES
[8]  
Bello LL., 2011, ACM SIGBED REV, V8, P7, DOI [DOI 10.1145/2095256.2095257, 10.1145/2095256.2095257]
[9]   An efficient cryptographic protocol verifier based on prolog rules [J].
Blanchet, B .
14TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 2001, :82-96
[10]  
Broy Manfred, 2006, ACM P INT C SOFTW EN, V28, P33