Demo: Securing Heavy Vehicle Diagnostics
Demo: Securing Heavy Vehicle Diagnostics
复制标题
演示:确保重型车辆诊断的安全
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Ben Ettlinger
中科院分区:
文献类型:
--
作者:
J. Daily;David Nnaji;Ben Ettlinger
get the requisite 16 bytes across the wire. Since the 16-byte enciphered CAN frame includes a CRC-16, incorrect deciphering will invalidate the CRC and the message is dropped. With this approach, exfiltration, manipulation, and pattern matching of CAN messages in the VDA communications are thwarted. Two modes of key exchange will be demonstrated. One mode uses an on-line server to compute the session key and share it with the PC Application using a TLS connection. An off-line mode requires the user to check out the keys needed for the ECDH. However, these private PEM keys are encrypted to minimize risk of being leaked. To decrypt the PEM keys needed for the ECDH, the gateway must be in the circuit. In other words, part of the PEM key encryption requires the hardware security module on the secure gateway. The demonstration will show how the secure channel will mitigate attacks on single CAN frames and multi-frame messages. A special version of the RP1210 driver is used as a shim DLL that looks for J1939 Engine Hours and manipulates that single frame message. Additionally, the shim DLL looks for a transport layer message carrying a VIN, which is altered. With the secure gateway in place and a compatible diagnostics software application, these attacks are mitigated. The result is increased confidence in the sanctity of vehicle diagnostics data as it flows through a Windows computer.