首页> 外文会议>SAE World Congress Experience >Security Mechanisms Design of Automotive Gateway Firewall
【24h】

Security Mechanisms Design of Automotive Gateway Firewall

机译:汽车网关防火墙的安全机制设计

获取原文

摘要

Automotive security has become one of important topics in recent years under new automotive Electronic and Electrical Architecture (EEA). With the development of Intelligent Connected Vehicle (ICV), it has become possible to hack an automotive through in-vehicle networks. The introduction of Information Communications Technology (ICT) brings more risk threats to automotive. Researchers have shown that an attacker can easily tamper with many automotive functions via On-Board Diagnostic II (OBD-II) or In-Vehicle Infotainment (IVI). In order to protect automotive against malicious attacks, automotive security risks were analyzed and then security mechanisms based on network firewall were designed in this paper. Automotive network firewall is a security system that monitors and controls incoming and outgoing network traffics of automotive based on predetermined security rules. The main functions of network firewall include packet filter, anti-DoS and access control. Because of deferent security requirements of in-vehicle networks, CAN/FD and Ethernet were divided into two domains respectively. Packet filter mechanisms were designed to monitor CAN/FD, in which security level and time delay were considered. Ethernet firewall mechanisms were designed based on Stateful Packet Filter (SPF) technology. Beside packet filter mechanisms, anti-DoS and access control mechanisms were also designed. Security Real Time Operating System (SRTOS) was introduced to ensure lower layer security. Considering the ECU constraint, Hardware Security Module (HSM) is chosen to implement cryptography function. At last, proposed automotive network firewall were implemented base on a multicore MCU with HSM. The system is evaluated in several aspects such as packet throughput, time delay, anti-attack and memory usage. The evaluation results show that the automotive network firewall is effective and efficient.
机译:汽车安全已成为新汽车电子和电气建筑(EEA)下近年来的重要主题之一。随着智能连接车辆(ICV)的发展,可以通过车载网络破解汽车。信息通信技术(ICT)引入为汽车带来了更多的风险威胁。研究人员表明,攻击者可以通过板载诊断II(OBD-II)或车载信息娱乐(IVI)轻松地篡改许多汽车功能。为了保护汽车防止恶意攻击,分析了汽车安全风险,然后在本文中设计了基于网络防火墙的安全机制。汽车网络防火墙是一种安全系统,可根据预定的安全规则监控和控制汽车的传入和传出网络流量。网络防火墙的主要功能包括数据包过滤器,防DOS和访问控制。由于车载网络的推迟安全要求,CAN / FD和以太网分别分为两个域。数据包过滤机制被设计为监视CAN / FD,其中考虑了安全级别和时间延迟。以太网防火墙机制是基于有状态分组过滤器(SPF)技术而设计的。除了数据包过滤器机制,还设计了防DOS和门禁机制。引入安全实时操作系统(SRTOS)以确保较低的层安全性。考虑到ECU约束,选择硬件安全模块(HSM)来实现加密功能。最后,建议的汽车网络防火墙在具有HSM的多核MCU上实现了基础。该系统在若干方面进行评估,例如数据包吞吐量,时间延迟,反攻击和内存使用情况。评估结果表明,汽车网络防火墙是有效且有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号