SecMonQ: An HSM based security monitoring approach for protecting AUTOSAR safety-critical systems

被引:4
|
作者
Nasser, Ahmad M. K. [1 ]
Ma, Di [1 ]
机构
[1] Univ Michigan, Comp Informat Sci, Dearborn, MI 48128 USA
关键词
Cyber physical systems; HSM; Trusted computing; Security monitors; Safety-critical systems;
D O I
10.1016/j.vehcom.2019.100201
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Many attacks on vehicle systems that result in a safety hazard follow a general pattern in which ECU firmware is modified, or code is injected in order to send spoofed CAN messages to safety-critical components causing an unsafe driving situation. There is a general consensus that protecting vehicles requires a defense in depth approach where protections are added at each layer of the vehicle data architecture. At the vehicle CAN bus layer, two powerful countermeasures exist: message authentication/encryption and network intrusion detection systems. The two approaches assume that an attacker has already managed to reach the CAN bus and therefore attempt to limit his impact. To defend against CAN injection attacks, we propose an alternative approach which aims at stopping a CAN injection attack before it reaches the vehicle bus. The proposed approach, working at the ECU level, leverages the embedded hardware security module (HSM), available in modern automotive ECUs, to implement four security monitors (SecMonQ) that run within the HSM firmware. SecMonQ performs continuous monitoring activities of the ECU firmware integrity, communication peripherals, periodic task timing, and flow sequence of certain critical functions. It is designed to detect an active attack and bring the system back to a safe state within the safety defined fault tolerant time. We implement SecMonQ on an automotive development environment which consists of an Elektrobit AUTOSAR stack and a Renesas RH850 F1KM micro-controller. We evaluate SecMonQ against the CAN masquerading attack to demonstrate efficacy while maintaining compatibility with AUTOSAR. (C) 2019 Elsevier Inc. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Towards a Formal Approach to Analysing Security of Safety-Critical Systems
    Vistbakka, Inna
    Troubitsyna, Elena
    [J]. 2018 14TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2018), 2018, : 182 - 189
  • [2] A UML Model-Based Approach for Replication Assessment of AUTOSAR Safety-Critical Applications
    Tucci-Piergiovanni, Sara
    Mraidha, Chokri
    Wozniak, Ernest
    Lanusse, Agnes
    Gerard, Sebastien
    [J]. TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 1176 - 1187
  • [3] SaSeVAL: A Safety/Security-Aware Approach for Validation of Safety-Critical Systems
    Wolschke, Christian
    Sangchoolie, Behrooz
    Simon, Jacob
    Marksteiner, Stefan
    Braun, Tobias
    Hamazaryan, Hayk
    [J]. 51ST ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN-W 2021), 2021, : 27 - 34
  • [4] Security Risk Analysis Approach for Safety-Critical Systems of Connected Vehicles
    Luo, Feng
    Hou, Shuo
    Zhang, Xuan
    Yang, Zhenyu
    Pan, Wenwen
    [J]. ELECTRONICS, 2020, 9 (08) : 1 - 20
  • [5] A consequence-based approach to safety-critical systems
    Perico-Cortés, A
    [J]. SAFETY INTEGRITY: THE IMPLICATIONS OF IEC 61508 AND OTHER STANDARDS FOR THE PROCESS INDUSTRIES, PROCEEDINGS, 2000, : 29 - 40
  • [6] Thermal monitoring of safety-critical integrated systems
    Szekely, V
    Rencz, M
    Karam, JM
    Lubaszewski, M
    Courtois, B
    [J]. PROCEEDINGS OF THE FIFTH ASIAN TEST SYMPOSIUM (ATS '96), 1996, : 282 - 288
  • [7] Utilising Redundancy to Enhance Security of Safety-Critical Systems
    Troubitsyna, Elena
    [J]. COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2023 WORKSHOPS, 2023, 14182 : 188 - 196
  • [8] An active inference approach to on-line agent monitoring in safety-critical systems
    Avila, Luis
    Martinez, Ernesto
    [J]. ADVANCED ENGINEERING INFORMATICS, 2015, 29 (04) : 1083 - 1095
  • [9] A Comparative Analysis of Security Patterns for Enhancing Security in Safety-Critical Systems
    Yengec-Tasdemir, Sena Busra
    Siddiqui, Fahad
    Sezer, Sakir
    Hui, Henry
    McLaughlin, Kieran
    Sonigara, Balmukund
    [J]. 2023 IEEE 36TH INTERNATIONAL SYSTEM-ON-CHIP CONFERENCE, SOCC, 2023, : 72 - 77
  • [10] Security and Safety-Critical Learning-Based Collaborative Control for Multiagent Systems
    Yan, Bing
    Shi, Peng
    Lim, Chee Peng
    Sun, Yuan
    Agarwal, Ramesh K.
    [J]. IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, : 1 - 12