Security-Aware Obfuscated Priority Assignment for Automotive CAN Platforms

被引:22
|
作者
Lukasiewycz, Martin [1 ]
Mundhenk, Philipp [1 ]
Steinhorst, Sebastian [1 ]
机构
[1] TUM CREATE Ltd, Singapore, Singapore
基金
新加坡国家研究基金会;
关键词
Design; Algorithms; Performance; CAN; priority assignment; automotive; security; CONTROLLER-AREA-NETWORK; OPTIMIZATION;
D O I
10.1145/2831232
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security in automotive in-vehicle networks is an increasing problem with the growing connectedness of road vehicles. This article proposes a security-aware priority assignment for automotive controller area network (CAN) platforms with the aim of mitigating scaling effects of attacks on vehicle fleets. CAN is the dominating field bus in the automotive domain due to its simplicity, low cost, and robustness. While messages might be encrypted to enhance the security of CAN systems, their priorities are usually identical for automotive platforms, comprising generally a large number of vehicle models. As a result, the identifier uniquely defines which message is sent, allowing attacks to scale across a fleet of vehicles with the same platform. As a remedy, we propose a methodology that is capable of determining obfuscated message identifiers for each individual vehicle. Since identifiers directly represent message priorities, the approach has to take the resulting response time variations into account while satisfying application deadlines for each vehicle schedule separately. Our approach relies on Quadratically Constrained Quadratic Program (QCQP) solving in two stages, specifying first a set of feasible fixed priorities and subsequently bounded priorities for each message. With the obtained bounds, obfuscated identifiers are determined, using a very fast randomized sampling. The experimental results, consisting of a large set of synthetic test cases and a realistic case study, give evidence of the efficiency of the proposed approach in terms of scalability. The results also show that the diversity of obtained identifiers is effectively optimized with our approach, resulting in a very good obfuscation of CAN messages in in-vehicle communication.
引用
收藏
页数:27
相关论文
共 50 条
  • [1] Security-Aware Obfuscated Priority Assignment for CAN FD Messages in Real-Time Parallel Automotive Applications
    Xie, Guoqi
    Li, Renfa
    Hu, Shiyan
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2020, 39 (12) : 4413 - 4425
  • [2] Security-Aware Design Methodology and Optimization for Automotive Systems
    Lin, Chung-Wei
    Zheng, Bowen
    Zhu, Qi
    Sangiovanni-Vincentelli, Alberto
    ACM TRANSACTIONS ON DESIGN AUTOMATION OF ELECTRONIC SYSTEMS, 2015, 21 (01)
  • [3] ID Hopping CAN Controller Design with Obfuscated Priority Assignment
    Ding, Shan
    Zhao, Tong
    Kurachi, Ryo
    Zeng, Gang
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 94 - 99
  • [4] Timing Analysis of CAN FD for Security-Aware Automotive Cyber-Physical Systems
    Xie, Yong
    Zeng, Gang
    Kurachi, Ryo
    Xiao, Fu
    Takada, Hiroaki
    Hu, Shiyan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (04) : 3064 - 3078
  • [5] Security-Aware CAN-FD Message Packing in Intelligent Automotive Cyber-Physical Systems
    Ma, Wenhong
    Liu, Yan
    Xie, Guoqi
    Li, Renfa
    Yang, Laurence T.
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (22) : 22343 - 22356
  • [6] Security-aware Signal Packing Algorithm for CAN-based Automotive Cyber-physical Systems
    Yong Xie
    Liangjiao Liu
    Renfa Li
    Jianqiang Hu
    Yong Han
    Xin Peng
    IEEE/CAA Journal of Automatica Sinica, 2015, 2 (04) : 422 - 430
  • [7] SEDAN: Security-Aware Design of Time-Critical Automotive Networks
    Kukkala, Vipin Kumar
    Pasricha, Sudeep
    Bradley, Thomas
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2020, 69 (08) : 9017 - 9030
  • [8] Security-Aware Modeling and Efficient Mapping for CAN-Based Real-Time Distributed Automotive Systems
    Lin, Chung-Wei
    Zhu, Qi
    Sangiovanni-Vincentelli, Alberto
    IEEE EMBEDDED SYSTEMS LETTERS, 2015, 7 (01) : 11 - 14
  • [9] Testbed Validation of Security-Aware Channel Assignment in Cognitive Radio IoT Networks
    Khadr, Monette H.
    Salameh, Haythem Bany
    Ayyash, Moussa
    Almajali, Sufyan
    Elgala, Hany
    2020 IEEE 6TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2020,
  • [10] Security-Aware Scheduling for TTEthernet-Based Real-Time Automotive Systems
    Zhao, Rui
    Qin, Guihe
    Lyu, Ying
    Yan, Jie
    IEEE ACCESS, 2019, 7 : 85971 - 85984