Numerous examples of automotive vulnerabilities have been provided, and the diagnostic functions in the on-board electronic control unit (ECU) have been used as an avenue of attack and analysis. Many ECUs are equipped with security access services that protect crucial diagnostic functions. If these security access services contain vulnerabilities, however, the ECU may be falsified or improperly controlled through the controller area network. In this study, we analyze the means of attacking security access services and provide the results of evaluating actual ECUs
In automotive software development, secure coding is required to enhance the security level because the secure coding guidelines state that vulnerability of software must be eliminated. However, secure coding is difficult to incorporate because it provides different assumptions from the coding guidelines of product development for existing automobiles. More specifically, in the automobile industry, MISRA-C is applied to improve the reliability of software. To achieve higher dependability and security level, an original guideline was developed in this study for the AUTOSAR adaptive platform. In this paper, we discuss the secure coding guidelines for strengthening security in classic and adaptive platforms.
This paper proposes a user revocation scheme for decentralized networks. User revocation is a method to distribute a group decryption key that is shared by n users in a group so that all but d revoked users can obtain the key. In decentralized networks such as ad-hoc networks, mesh networks, and Peer to Peer (P2P) networks, a sender should revoke the access of a dishonest user or an unauthorized user as soon as possible to protect the security of group communication. However, if the sender distributes the group key to all users aside from the revoked user, it would take a long time to revoke a user in a large group. In addition, users must set shared group keys for each user without a privileged center. We propose a scheme in which the amount of transmission and the key storage of each user are small.
Recently, ubiquitous computing / networks have been studied actively. These networks provide services depending on real environments of mobile nodes. Especially, we expect location-based services (LBSs), which rely on location of mobile nodes, are anticipated to come into wide use in the future. High-value LBSs require cryptography to ensure security. Here, cryptographic LBSs comprise a key management function (e.g. key sharing with nodes) and a location management function (e.g. location verification of nodes). Cooperation between key and location management functions realizes cryptographic LBSs. However, these functions have mostly been studied individually. This study indicates that cryptographic LBSs are insecure if the cooperation is incomplete, and proposes a method of constructing secure cryptographic LBSs.
This paper proposes a new concept of Interaction key. An interaction key is a group public key that corresponds to a shared key shared by multiple users, and it has a new feature that an interaction key generator can verify the following: the shared key has been generated now, and the shared key has not existed before. In other words, the multiple users can prove them to the key generator. This feature is different from Time-stamp technology proves that a message existed at a point in time. Here, the key generator is a third party that can observe communications of the multiple users. Present technology only allows a group member or a privileged entity to generate a group public key. We are not presently aware of a technology where a third party can generate the group public key as above. The interaction key technology is useful both for generating public key certificates and for message certification. In a certificate generation, a certificate authority can issue a public key certificate with the shared key (i.e. secret key) to be used by the multiple users. In a message certification, the users can prove the signed message has not existed before, since the message is signed by the shared key corresponds to the interaction key.
Following requirements are necessary when implementing public key cryptography in a mobile telecommunication terminal. (1) simultaneous highspeed double modular exponentiation calculation, (2) small size and low power consumption, (3) resistance to side channel attacks. We have developed a coprocessor that provides these requirements. In this coprocessor, right-to-left binary exponentiation algorithm was extended for double modular exponentiations by designing new circuit configuration and new schedule control methods. We specified the desired power consumption of the circuit at the initial design stage. Our proposed method resists side channel attacks that extract secret exponent by analyzing the target’s power consumption and calculation time.
One of the greatest needs in the clinical bone field is a bioactive agent to stimulate bone formation. We previously reported that fibroblast growth factor-2 (FGF-2) exhibited strong anabolic actions on bone formation in models of rodents and dogs. Aiming at a clinical application, this study was undertaken to clarify the effect of a single local application of recombinant human FGF-2 on fracture healing in nonhuman primates. After a fracture was created at the midshaft of the right ulna of animals and stabilized with an intramedullary nail, gelatin hydrogel alone (n = 10) or gelatin hydrogel containing 200 microg FGF-2 (n = 10) was injected into the fracture site. Although 4 of 10 animals treated with the vehicle alone remained in a nonunion state even after 10 weeks, bone union was complete at 6 weeks in all 10 animals treated with FGF-2. Significant differences in bone mineral content and density at the fracture site between the vehicle and FGF-2 groups were seen at 6 weeks and thereafter. FGF-2 also increased the mechanical property of the fracture site. We conclude that FGF-2 accelerates fracture healing and prevents nonunion in primates, and therefore propose that it is a potent bone anabolic agent for clinical use.
This paper proposes a group key distribution scheme with a user exclusion. The user exclusion is how to distribute an encryption key over a broadcast channel shared by n users so that all but d excluded users can get the group key. In the broadcast channel such as Pay-TV, Internet multicast and a mobile telecommunication for a group, a manager should exclude a dishonest user or an unauthorized terminal as soon as possible to protect the secrecy of the group communication. However, it takes a long time for the user exclusion on a large group, if the distributor distributes the group key to each user except the excluded one. We propose a scheme in which the amount of transmission and the key storage of each user do not depend on the number of users of the group. Moreover, our scheme does not require a fixed and privileged distributor.
In this paper, we examine a broadcast exclusion problem, i.e., how to distribute an encryption key over a channel shared by n entities so that all but k excluded entities can get the key. Recently, J. Anzai, N. Matsuzaki and T. Matsumoto proposed a scheme that provides a solution to the broadcast exclusion problem. Their solution is to apply (k + 1, n + k) threshold cryptosystems. In this scheme, the transmission overhead is O (k) and each entity holds a fixed amount of secret key. However, each entity must compute the encryption key with k + 1 modular exponentiations. Therefore, a device with low computing power (e.g., a mobile terminal or a smart card) cannot calculate the broadcast key within a reasonable time. In this paper, we propose a new scheme in which each entity computes the key with only two modular exponentiations, regardless of n and k. We accomplish this by assuming a trusted key distributor, while retaining the advantages of Anzai-Matsuzaki-Matsumoto scheme, i.e., the transmission overhead is O (k), and each entity holds a fixed amount of secret key regardless of n and k.
This paper proposes a group key distribution scheme with an "entity revocation", which renews a group key of all the entities except one (or more) specific entity (ies). In broadcast systems such as Pay-TV, Internet multicast and mobile telecommunication for a group, a manager should revoke a dishonest entity or an unauthorized terminal as soon as possible to protect the secrecy of the group communication. However, it takes a long time for the "entity revocation" on a large group, if the manager distributes a group key to each entity except the revoked one. A recently published paper proposed a group key distribution scheme in which the amount of transmission and the delay do not rely on the number of entities of the group, using a type of secret sharing technique. This paper devises a novel key distribution scheme with "entity revocation" that makes frequent key distribution a practical reality. This scheme uses a technique similar to "threshold cryptosystems" and the one-pass Diffie-Hellman key exchange scheme.