A Name-Based Secure Communications Architecture for Vehicular Networks

A Name-Based Secure Communications Architecture for Vehicular Networks
复制标题

基于名称的车载网络安全通信架构

DOI:
10.1109/vnc52810.2021.9644625
复制
发表时间:
2021
期刊:
2021 IEEE Vehicular Networking Conference (VNC)
影响因子:
--
通讯作者:
Susmit Shannigrahi
Susmit Shannigrahi
中科院分区:
--
文献类型:
--
作者:
C. Papadopoulos;Alexander Afanasyev;Susmit Shannigrahi

文献摘要

被引文献

相似文献

即将出台的汽车网络安全标准(如ISO 21434)和法规(如WP.29)使得汽车制造商必须通过设计建立网络安全实践。车辆通信网络安全(车内和车外)对于实现这一目标至关重要。随着汽车以太网的采用,汽车制造商正在转向互联网协议套件(IP)以实现所需的网络安全属性。然而,安全性始终是互联网协议的附加组件,导致了众所周知的安全弱点,如欺骗、拒绝服务攻击、缺乏身份验证等。这些弱点可能会在不知不觉中被带到汽车领域。在这份立场文件中,我们认为汽车行业应该研究除IP之外的其他网络架构,因为它们正在远离现有的架构,如CAN。具体来说,我们提出命名数据网络(NDN),一个架构,采用统一的安全设计,从网络到应用程序层。虽然NDN尚未用于车载通信,但我们的立场是,它比IP更优越,特别是在安全性方面,使其成为一个强有力的候选者。与保护两个实体之间通信通道的IP不同,NDN通过数字签名保护内容,数字签名将名称加密绑定到内容,确保身份验证和数据的完整性。NDN类似于发布-订阅模型,可以直接在L2或L3层上实现。
Forthcoming automotive cybersecurity standards such as ISO 21434 and regulations such as WP.29 make it imperative that automakers establish cybersecurity-by-design practices. Vehicle communication cybersecurity (both in- and out-of-vehicle) is crucial in achieving this goal. With the adoption of automotive Ethernet, automakers are turning to the Internet protocol suite (IP) to achieve the desired cybersecurity properties. However, security was always an add-on to Internet protocols, resulting in well-known security weaknesses such as spoofing, denial of service attacks, lack of authentication and more. Such weaknesses may unwittingly be brought to the automotive space.In this position paper we take the position that the automotive industry should investigate other networking architectures besides IP as they move away from existing architectures such as CAN. Specifically, we propose Named Data Networking (NDN), an architecture that incorporates unified security-by-design from the network to the application layers. While NDN has not yet been used for in-vehicle communication, our position is that its superiority to IP, especially in security, makes it a strong candidate. Unlike IP, which secures the communication channel between two entities, NDN secures the content through digital signatures that cryptographically bind a name to the content, ensuring both authentication and integrity of the data. NDN is analogous to a pub-sub model and can be implemented directly over L2 or L3 layers.