My Account Log in

1 option

Optimizing CAN Bus Security with In-Place Cryptography Karamba Security

SAE Technical Papers (1906-current) Available online

View online
Format:
Book
Conference/Event
Author/Creator:
Harel, Harel, author.
Contributor:
Hezberg, Amir
Conference Name:
SAE Connected and Automated Vehicle Conference Israel (2019-01-16 : Tel Aviv, Israel)
Language:
English
Physical Description:
1 online resource cm
Place of Publication:
Warrendale, PA SAE International 2019
Summary:
Today's vehicles rely on multiple interconnected networks of Electronic Control Units (ECUs) that govern almost every automotive function - from engine timing and traction control to side-mirror adjustment and GPS. In-vehicle networks used for inter-ECU communication, most commonly the CAN bus, were not designed with cybersecurity in mind, and as a result, communication by corrupt devices connected to the bus is not authenticated.A multitude of attack vectors allow attackers to control a device on the bus; reports abound of successful hacking of vehicles, by exploiting vulnerable devices and by spoofing messages.Such remote-connectivity and physical-access exploit types must be prevented, to mitigate the threats of impersonation, eavesdropping, replay and reversing.We present the IVAS, In-Vehicle Authentication Scheme. IVAS is an in-place cryptographic scheme: the first CAN messaging solution to ensure both authentication and confidentiality without additional data such as authentication tags.When adequate encryption is used, an adversary's chances of successfully injecting a spoofed message are equal to the chances for a random message. There is a need for a validation method that deterministically differentiates between random messages and legitimate CAN commands.We take advantage of both static and dynamic redundancy existing in CAN bus traffic, eliminating the need for extra bandwidth.A mathematical proof of the security level of our AE (Authenticated Encryption) scheme is presented, showing that both confidentiality and authenticity are included.No changes to the application code, protocol or chipset are entailed, and runtime key exchange is not required. In addition, any type of serial data bus can be secured by IVAS, so that varied ECUs can work together.The IVAS solution for securing the CAN bus stands out in its ability to authenticate sender integrity and data integrity, blocking malicious messages without adding payloads
Notes:
Vendor supplied data
Publisher Number:
2019-01-0098
Access Restriction:
Restricted for use by site license

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account