Securing Automotive Architectures with Named Data Networking

Securing Automotive Architectures with Named Data Networking
复制标题

DOI:
10.1109/itsc55140.2022.9922194
复制
发表时间:
2022-06
期刊:
2022 IEEE 25th International Conference on Intelligent Transportation Systems (ITSC)
影响因子:
--
通讯作者:
Zachariah Threet;C. Papadopoulos;W. Lambert;P. Podder;Spiros Thanasoulas;Alexander Afanasyev;Sheikh K. Ghafoor;Susmit Shannigrahi
Zachariah Threet;C. Papadopoulos;W. Lambert;P. Podder;Spiros Thanasoulas;Alexander Afanasyev;Sheikh K. Ghafoor;Susmit Shannigrahi
中科院分区:
其他
文献类型:
--
作者:
Zachariah Threet;C. Papadopoulos;W. Lambert;P. Podder;Spiros Thanasoulas;Alexander Afanasyev;Sheikh K. Ghafoor;Susmit Shannigrahi

文献摘要

相似文献

随着车载通信变得越来越复杂,汽车行业正在探索各种架构选项,例如集中式和分区架构,以获得众多优势。这些架构的共同特征包括对高带宽通信和安全性的需求,这在标准汽车架构中是难以实现的。此外,随着汽车通信技术的发展,CAN和汽车以太网等多种链路层技术也可能共存。这些替代架构承诺集成这些不同的技术。然而,允许这种共存的架构还没有得到充分的探讨。在这项工作中,我们探索了一种名为命名数据网络(NDN)的新网络架构,以实现多个目标:提供基础安全基础设施,并将不同的链路层协议(如CAN,LIN和汽车以太网)桥接到统一的通信系统中。我们使用CAN HATS和Raspberry PI创建了一个概念验证的台式测试平台,通过CAN和以太网重放真实的流量,以演示NDN如何在不同的汽车链路层之间提供安全、高速的桥梁。我们还展示了NDN如何支持集中式或分区高功率计算组件之间的通信。通过对这些组件之间的所有数据包进行数字签名来实现安全性,防止未经授权的ECU将任意数据注入网络。我们还展示了NDN的能力,以防止通过NDN连接的不同网段之间的拒绝服务和重放攻击。
As in-vehicle communication becomes more complex, the automotive community is exploring various architectural options such as centralized and zonal architectures for their numerous benefits. Common characteristics of these architectures include the need for high-bandwidth communication and security, which have been elusive with standard automotive architectures. Further, as automotive communication technologies evolve, it is also likely that multiple link-layer technologies such as CAN and Automotive Ethernet will co-exist. These alternative architectures promise to integrate these diverse sets of technologies. However, architectures that allow such co-existence have not been adequately explored. In this work we explore a new network architecture called Named Data Networking (NDN) to achieve multiple goals: provide a foundational security infrastructure and bridge different link layer protocols such as CAN, LIN, and automotive Ethernet into a unified communication system. We have created a proof-of-concept bench-top testbed using CAN HATS and Raspberry PIs that replay real traffic over CAN and Ethernet to demonstrate how NDN can provide a secure, high-speed bridge between different automotive link layers. We also show how NDN can support communication between centralized or zonal high-power compute components. Security is achieved through digitally signing all Data packets between these components, preventing unauthorized ECUs from injecting arbitrary data into the network. We also demonstrate NDN's ability to prevent DoS and replay attacks between different network segments connected through NDN.