首页> 外文OA文献 >Security analysis of an open car immobilizer Protocol Stack
【2h】

Security analysis of an open car immobilizer Protocol Stack

机译:开放式汽车防盗器协议栈的安全性分析

摘要

Openness is a key criterion of security algorithms and protocols which enable them to be subjected to scrutiny by independent security experts. The alternative "methodology" of secret proprietary algorithms and protocols has often ended in practical breaks, e.g. of the MIFARE Oyster cards for public transport or the KeeLoq remote control systems. Open evaluation is common for general applications of security, e.g. the NIST competitions for selection of the Advanced Encryption Standard (AES) and the Secure Hash Algorithm 3 (SHA-3). Nowadays an increasing number of embedded security applications apply the principle of open evaluation as well. A recent example is the specification of an open security protocol stack for car immobilizer applications by Atmel, which has been presented at ESCAR 2010. This stack is primarily intended to be used in conjunction with automotive transponder chips of this manufacturer, but could in principle be deployed on any suitable type of transponder chip. In this paper we analyze the security of this protocol stack. We were able to uncover a number of potential security vulnerabilities, for which we suggest fixes.
机译:开放性是安全算法和协议的关键标准,可让它们受到独立安全专家的审查。秘密专有算法和协议的替代“方法”通常以实际的中断而告终,例如用于公共运输或KeeLoq远程控制系统的MIFARE Oyster卡。对于一般的安全应用,例如在NIST竞赛中选择了高级加密标准(AES)和安全哈希算法3(SHA-3)。如今,越来越多的嵌入式安全应用程序也采用开放评估的原理。最近的一个例子是Atmel针对汽车防盗器应用开放式安全协议栈的规范,该规范已在ESCAR 2010上提出。该协议栈最初旨在与该制造商的汽车应答器芯片配合使用,但原则上可以部署在任何合适类型的应答器芯片上。在本文中,我们分析了该协议栈的安全性。我们能够发现许多潜在的安全漏洞,并建议修复这些漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号