TEECheck: Securing Intra-Vehicular Communication Using Trusted Execution

TEECheck: Securing Intra-Vehicular Communication Using Trusted Execution
复制标题

TEECheck:使用可信执行保护车内通信

DOI:
10.1145/3394810.3394822
复制
发表时间:
2020
期刊:
Proceedings of the 28th International Conference on Real-Time Networks and Systems
影响因子:
--
通讯作者:
Ryan M. Gerdes
Ryan M. Gerdes
中科院分区:
--
文献类型:
--
作者:
Tanmaya Mishra;Thidapat Chantem;Ryan M. Gerdes

文献摘要

参考文献

被引文献

相似文献

现代车辆具有大量的高级驾驶员辅助系统(例如自适应巡航控制和自动巷道),这些系统取决于及时通过各种ECU和传感器通过CAN总线交换的数据。考虑到罐头总线上的大量数据,CAN已成为希望控制车辆的恶意政党的利润目标。具体来说,攻击者可能会损害ECU以访问巴士。因此,必须通过受损的ECUS确保罐头总线免受破坏的措施,以确保其正确和及时的操作。我们为ECU设计了一种新的系统体系结构,该系统架构利用可信赖的执行环境并提出Teecheck,Teecheck是一种在设备的消息审查机制,以主动包含化妆舞会和拒绝服务攻击,并消除信息泄漏。我们方法的独特性在于,如果不需要可以访问CAN,则在接收器端不需要身份验证会增加任何开销。实验表明,无论工作量如何,我们的技术都有非常低和可预测的开销。
Modern vehicles have a large number of advanced driver assistance systems (e.g., adaptive cruise control and automatic lane keeping) that depend on the timely availability of data exchanged through the CAN bus from a variety of ECUs and sensors. Considering the large amount of data on the CAN bus, CAN has become a lucrative target for malicious parties wishing to take control of a vehicle. Specifically, an attacker may compromise an ECU to gain access to the bus. It is, thus, imperative that the CAN bus is secured from disruption by compromised ECUs to ensure its correct and timely operation. We design a new system architecture for ECUs that leverages trusted execution environments and propose TEECheck, an on-device message vetting mechanism to proactively contain masquerade and denial-of-service attacks, as well as eliminate information leakage. The uniqueness of our approach is that it require neither authentication at the receiver end adds any overhead if there is no need for CAN bus access. Experiments show that our technique has very low and predictable overhead, regardless of the workload.
DOI: 10.1145/3359789.3359834
发表时间: 2019-12
期刊: Proceedings of the 35th Annual Computer Security Applications Conference
影响因子: --
作者:
M. Foruhandeh;Yanmao Man;Ryan M. Gerdes;Ming Li;Thidapat Chantem
通讯作者: M. Foruhandeh;Yanmao Man;Ryan M. Gerdes;Ming Li;Thidapat Chantem