Demo: Securing Heavy Vehicle Diagnostics

Demo: Securing Heavy Vehicle Diagnostics
复制标题

演示:确保重型车辆诊断的安全

DOI:
--
复制
发表时间:
2021
期刊:
Proceedings Third International Workshop on Automotive and Autonomous Vehicle Security
影响因子:
--
通讯作者:
Ben Ettlinger
Ben Ettlinger
中科院分区:
--
文献类型:
--
作者:
J. Daily;David Nnaji;Ben Ettlinger

文献摘要

被引文献

相似文献

通过线路获取必需的 16 字节。由于 16 字节加密 CAN 帧包含 CRC-16,因此错误的解密将使 CRC 无效并且消息被丢弃。通过这种方法,可以阻止 VDA 通信中 CAN 消息的泄露、操纵和模式匹配。将演示两种密钥交换模式。一种模式使用在线服务器来计算会话密钥并使用 TLS 连接与 PC 应用程序共享。离线模式要求用户检查ECDH所需的密钥。但是,这些 PEM 私钥经过加密,以最大程度地降低泄露风险。要解密 ECDH 所需的 PEM 密钥,网关必须位于电路中。也就是说,部分PEM密钥加密需要安全网关上的硬件安全模块。该演示将展示安全通道如何减轻对单 CAN 帧和多帧消息的攻击。 RP1210 驱动程序的特殊版本用作垫片 DLL,用于查找 J1939 发动机小时并操作该单帧消息。此外,填充程序 DLL 还会查找携带已更改的 VIN 的传输层消息。有了安全网关和兼容的诊断软件应用程序,这些攻击就可以得到缓解。其结果是提高了人们对流经 Windows 计算机的车辆诊断数据的可靠性的信心。
get the requisite 16 bytes across the wire. Since the 16-byte enciphered CAN frame includes a CRC-16, incorrect deciphering will invalidate the CRC and the message is dropped. With this approach, exfiltration, manipulation, and pattern matching of CAN messages in the VDA communications are thwarted. Two modes of key exchange will be demonstrated. One mode uses an on-line server to compute the session key and share it with the PC Application using a TLS connection. An off-line mode requires the user to check out the keys needed for the ECDH. However, these private PEM keys are encrypted to minimize risk of being leaked. To decrypt the PEM keys needed for the ECDH, the gateway must be in the circuit. In other words, part of the PEM key encryption requires the hardware security module on the secure gateway. The demonstration will show how the secure channel will mitigate attacks on single CAN frames and multi-frame messages. A special version of the RP1210 driver is used as a shim DLL that looks for J1939 Engine Hours and manipulates that single frame message. Additionally, the shim DLL looks for a transport layer message carrying a VIN, which is altered. With the secure gateway in place and a compatible diagnostics software application, these attacks are mitigated. The result is increased confidence in the sanctity of vehicle diagnostics data as it flows through a Windows computer.