A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CAN

A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CAN
复制标题

DOI:
10.1109/tits.2014.2351612
复制
发表时间:
2015-04-01
影响因子:
8.5
通讯作者:
Lee, Dong Hoon
Lee, Dong Hoon
中科院分区:
工程技术1区
文献类型:
--
作者:
Woo, Samuel;Jo, Hyo Jin;Lee, Dong Hoon

文献摘要

被引文献

相似文献

车辆-IT融合技术是现代车辆的一个迅速崛起的范例,其中电子控制单元(ECU)用于控制车辆电气系统,并且控制器局域网(CAN),一种车载网络,通常用于构建ECU的高效网络。不幸的是,安全问题在CAN中没有得到适当的处理,尽管CAN控制消息可能是生命攸关的。随着联网汽车环境的出现,车载网络(例如,CAN)现在连接到外部网络(例如,3G/4G移动的网络),使对手能够利用CAN漏洞进行远程无线攻击。在本文中,我们表明,远程无线攻击在物理上是可能的,使用真实的车辆和恶意智能手机应用程序在连接的汽车环境中。我们还提出了一个安全协议,CAN作为一种对策,根据目前的CAN规范设计。我们使用CANoe软件和DSP-F28335微控制器评估所提出的安全协议的可行性。我们的研究结果表明,所提出的安全协议是更有效的认证延迟和通信负载方面比现有的安全协议。
Vehicle-IT convergence technology is a rapidly rising paradigm of modern vehicles, in which an electronic control unit (ECU) is used to control the vehicle electrical systems, and the controller area network (CAN), an in-vehicle network, is commonly used to construct an efficient network of ECUs. Unfortunately, security issues have not been treated properly in CAN, although CAN control messages could be life-critical. With the appearance of the connected car environment, in-vehicle networks (e.g., CAN) are now connected to external networks (e.g., 3G/4G mobile networks), enabling an adversary to perform a long-range wireless attack using CAN vulnerabilities. In this paper we show that a long-range wireless attack is physically possible using a real vehicle and malicious smartphone application in a connected car environment. We also propose a security protocol for CAN as a countermeasure designed in accordance with current CAN specifications. We evaluate the feasibility of the proposed security protocol using CANoe software and a DSP-F28335 microcontroller. Our results show that the proposed security protocol is more efficient than existing security protocols with respect to authentication delay and communication load.