Securing Automotive Architectures with Named Data Networking
Securing Automotive Architectures with Named Data Networking
复制标题
DOI:
10.1109/itsc55140.2022.9922194
复制
发表时间:
2022-06
期刊:
影响因子:
--
通讯作者:
Zachariah Threet;C. Papadopoulos;W. Lambert;P. Podder;Spiros Thanasoulas;Alexander Afanasyev;Sheikh K. Ghafoor;Susmit Shannigrahi
中科院分区:
文献类型:
--
作者:
Zachariah Threet;C. Papadopoulos;W. Lambert;P. Podder;Spiros Thanasoulas;Alexander Afanasyev;Sheikh K. Ghafoor;Susmit Shannigrahi
As in-vehicle communication becomes more complex, the automotive community is exploring various architectural options such as centralized and zonal architectures for their numerous benefits. Common characteristics of these architectures include the need for high-bandwidth communication and security, which have been elusive with standard automotive architectures. Further, as automotive communication technologies evolve, it is also likely that multiple link-layer technologies such as CAN and Automotive Ethernet will co-exist. These alternative architectures promise to integrate these diverse sets of technologies. However, architectures that allow such co-existence have not been adequately explored. In this work we explore a new network architecture called Named Data Networking (NDN) to achieve multiple goals: provide a foundational security infrastructure and bridge different link layer protocols such as CAN, LIN, and automotive Ethernet into a unified communication system. We have created a proof-of-concept bench-top testbed using CAN HATS and Raspberry PIs that replay real traffic over CAN and Ethernet to demonstrate how NDN can provide a secure, high-speed bridge between different automotive link layers. We also show how NDN can support communication between centralized or zonal high-power compute components. Security is achieved through digitally signing all Data packets between these components, preventing unauthorized ECUs from injecting arbitrary data into the network. We also demonstrate NDN's ability to prevent DoS and replay attacks between different network segments connected through NDN.