首页> 外文会议>International Congress Electronics in Vehicles >Enhancing In-Vehicle Communication by Authentication and Security: An incremental approach with an example for CAN message authentication
【24h】

Enhancing In-Vehicle Communication by Authentication and Security: An incremental approach with an example for CAN message authentication

机译:通过身份验证和安全性增强车载通信:具有CAN消息认证的示例的增量方法

获取原文

摘要

Modern automotive E/E architectures consist of a huge number of nodes communicating over an openly accessible network inside the car. To ensure authenticity, integrity and protection against external attacks, a secure communication is mandatory. The challenge is to manage the complexity and variety of different communication protocols and nodes, as well as interoperability between different vendors. Rearchitecting a complete E/E architecture to ensure 100% of secured nodes is almost infeasible. This paper presents a flexible and scalable approach for enhancing security in an in-vehicle network. The solution scales very well across all in-vehicle communication networks, from CAN to Ethernet communication with support for TLS. An example of CAN message authentication is shown in detail. One can selectively decide which ECUs need to be re-architected and which ECUs can remain almost unchanged. This minimally intrusive approach allows the system architect to better adjust the overall network architecture to the security needs with incremental change. Consequently, this reduces effort and risk while significantly reducing re-qualification efforts. Legacy ECUs can be preserved when needed, while feature-rich ECUs may undergo an architecture redesign.
机译:现代汽车E / e架构由大量的节点组成,在汽车内部的公开访问网络上通信。为确保对外部攻击的真实性,完整性和保护,必须安全的通信是强制性的。挑战是管理不同通信协议和节点以及不同供应商之间的互操作性的复杂性和多样性。 Rechanting完整的E / E架构,以确保100%的安全节点几乎是不可行的。本文提出了一种灵活且可扩展的方法,可在车载网络中提升安全性。解决方案在所有车载通信网络中缩放得很好,从CAN到以太网通信与支持TLS。可以详细示出CAN消息认证的示例。人们可以选择性地确定需要重新归档哪些ECU,并且哪些ECU可以保持几乎不变。这种最小侵入性的方法允许系统架构师通过增量变化更好地将整体网络架构调整到安全需求。因此,这减少了努力和风险,同时大大减少了重新认证努力。在需要时,可以保留遗留ECU,而功能丰富的ECU可能会进行重新设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号