Secure communication between devices is paramount in the modern, increasingly connected world. Especially in the automotive field, the rapidly increasing inter- and intra-vehicle communication requires encryption to ensure safe driving and confidentiality of user data. Mathematically secure encryption algorithms have been developed. But in practice, being mathematically secure is not enough. Execution on real hardware leads to physical emanations like power, electromagnetic, or timing variations. Side-channel attacks exploit these emanations to discover secrets, like encryption keys. Hence, for secure communication, robustness against side-channel attacks is mandatory. Evaluating the robustness of cryptography algorithms and countermeasures against side-channel attacks needs encryption hardware and additional equipment, e.g., to measure power or electromagnetic emanations. However, neither is always available and commonly requires a complex and expensive setup. Virtual Prototypes, which enable high-speed full-system simulation and software debugging even before RTL is available, can perfectly fulfill this gap. In our work, we focus on power side-channel attack simulation. We enable their simulation in the well-known simulator gem5, integrating power modeling for power measurements. To evaluate our work, we implemented DES and RSA cryptography algorithms and showed successful execution of Differential Power Analysis (DPA) power side-channel attacks on them in gem5. Our proposed approach enables the evaluation of side-channel attack robustness quickly without requiring complex setups and encryption hardware. To the best of our knowledge, this is the first approach successfully enabling power side-channel attack simulation on gem5, extending its application scenario in the security domain.
In the modern more and more connected world, secure communication between devices is of upmost importance. Especially in the automotive field, the largely increasing inter- and intra-vehicle communication requires encryption to ensure safe driving and confidentiality of user data. Mathematically secure encryption algorithms have been developed. But in practice, being mathematically secure is not enough. Execution on real hardware leads to physical emanations like power, electromagnetic or timing variations. Side-channel attacks exploit these emanations to find out secrets, like encryption keys. Hence, for secure communication, robustness against side-channel attacks is mandatory. Evaluating robustness of cryptography algorithms and of countermeasures against side-channel attacks needs encryption hardware. Additionally, sometimes equipment is required, e.g. to measure power or electromagnetic emanations. But both encryption hardware and equipment are not always available. Virtual Prototying, which enables high-speed full-system simulation even before RTL is available, can perfectly fulfill this gap. In our work we focus on power side-channel attacks. We enable their simulation in the well-known simulator GEM5 using power modellings and extend GEM5 with SystemC/TLM. We present in this paper an outline of our work and first positive results. Our work allows evaluation of side-channel attack robustness even during hardware design, when the hardware is not available. Besides improving speed of software development, this also allows to improve the hardware immediately, which saves time and costs.
Processor design and manufacturing is often done globally, involving multiple companies, some of which can be untrustworthy. This lack of trust leads to the threat of malicious modifications like Hardware Trojans. Hardware Trojans can cause drastic consequences and even endanger human lives. Hence, effective countermeasures against Hardware Trojans are urgently needed. To develop countermeasures, Hardware Trojans and their properties have to be understood well. For this reason, we describe and characterize Hardware Trojans in detail in this paper. We perform a theoretical analysis of Hardware Trojans for processors. Afterwards, we present a new classification of processor constituents, which can be used to derive several triggers and payloads and compare them with previously published Hardware Trojans. This shows in detail possible attack vectors for processors and gaps in existing processor Hardware Trojan landscape. No previous work presents such a detailed investigation of Hardware Trojans for processors. With this work, we intend to improve understanding of Hardware Trojans in processors, supporting the development of new countermeasures and prevention techniques.
Functional safety is considered as one of the utmost requirements of the future autonomous vehicle, which consumes an ample amount of safety-critical data exchange among sensors, actuators and controllers through the in-vehicle network (IVN). IVN should provide enough guarantees to satisfy the high-reliability requirement of such autonomous vehicle applications. To avoid packet failures, Time-sensitive Network (TSN) proposes a fault-tolerant mechanism called frame replication and elimination for reliability (FRER) in IEEE 802.1CB standard. The main idea of FRER is to transmit safety-critical data via multiple disjoint paths between source and destination so that if one path fails to transmit the safety-critical data, the other path can still deliver the packet to its destination. In this paper, four different dynamic scheduling and routing heuristics are analyzed to support FRER functionality in TSN based IVN. These heuristics use combined score value, each score value is dedicated for a single path, as a measure to schedule and route incoming flow in multiple redundant paths on the fly. One of the algorithms, the Fault-Tolerant Bottleneck Heuristic (FTBH) outperforms others in terms of schedulability and response time. It schedules around 3.0–7.0% more flows as compared to other developed heuristics depending on the network load.
Hardware Security and trustworthiness are becoming ever more important, especially for security-critical applications like autonomous driving and service robots. With the increase in distribution of RISC-V processors, security issues in them arise. Security vulnerabilities and design flaws in processors can be exploited by attackers, e.g. by running software exploiting the vulnerabilities. This can lead to drastic consequences like damaging whole system functionality and even human lives can be endangered. Hence, it is very important to verify compliance of processors with the design specification and microarchitecture intent to harden the hardware against malicious attacks. Detection and removal of design bugs results in improved processor security. Therefore, we formally verify in this paper the security-critical functionality of a commercial RISC-V processor using model checking based formal verification with the formal verification tool Jasper. For this, we determined and implemented a comprehensive list of properties for security-critical functionality, derived from RISC-V specification and processor microarchitecture intent. The properties cover the security-critical functionality within a RISC-V processor. With our verification experiments, we detected design bugs which have been confirmed by the design team.
Reliability is considered the paramount requirement of the future vehicle which requires a huge amount of safety-critical data traversing through the in-vehicle network (IVN). To achieve reliability in Ethernet-based IVN, time-sensitive network (TSN) proposes a fault-tolerant mechanism called frame replication and elimination for reliability (FRER) in IEEE 802.1 CB standard. In this paper, fault-tolerant joint scheduling and routing of static applications is developed which considers TSN's time-aware shaper (TAS) and FRER standards. The fault-tolerant scheduling and routing problem is formulated as a mixed-integer programming (MIP) model and solved with a CPLEX optimizer. Furthermore, a cuckoo search based meta-heuristic is developed to achieve scalable schedule solutions. Experimental results show that the cuckoo search takes 5.7 min to schedules 90 flows and utilizes 8% more bins as compared to the optimal solution.
There are more and more ‘connected’ vehicles on the streets, and they run increasingly more safety critical applications. To meet the connectivity requirements of these vehicles, network providers need to not only ensure the quality of service (QoS) but also to predict any upcoming changes in the QoS and inform the vehicle(s) about it. This concept is called predictive-QoS (P-QoS) and is being heavily discussed in various organizations, e.g. 3GPP, 5GAA. To allow a seamless service to vehicles, some issues such as handling multiple mobile network operators (MNOs), while roaming for example, need to be addressed. For example, if prediction about QoS is available for multiple MNOs simultaneously for a specific area, this could be beneficial for the vehicle in selecting an MNO for further operation in specific scenarios, e.g. roaming, driving through an area where the current MNO is predictive to have poor QoS. In this paper, we introduce an entity, that takes the QoS prediction about multiple MNOs and makes decision about how to manage the connectivity in a vehicle, e.g. selecting a set of MNOs for further connectivity including a preference for each, making an “MNO usage timeplan” based on the QoS comparison etc.
The future autonomous vehicle is not only processing the copious amount of indispensable data generated by its onboard sensors but also utilizing the data from other vehicles, roadside unit (RSU) etc. Managing the mixed-criticality data requires intelligent time-sensitive scheduling and routing within the in-vehicle network (IVN) infrastructure. Use-cases related to self-adaptivity (including vehicular communication), partial networking and embedded virtualization require to change the configuration of the IVN at runtime. State-of-the-art IEEE Time-Sensitive Networking (TSN) standards possess a grave challenge in handling runtime reconfigurations. Above mentioned use-cases foster the development of scalable and efficient dynamic scheduling and routing algorithms for TSN based IVN. In this paper, four meticulously designed heuristics are analyzed for dynamic scheduling and routing on-the-fly in TSN based IVN. One of the algorithms, Bottleneck heuristic outperforms others in term of schedulability and response time. It schedules around 16 − 22% more flows as compared to other developed heuristics depending on the network load.
As the mobile and automotive industries move towards autonomous vehicles, many advanced driving applications have been developed. These driving applications may require different levels of intelligence, communication capabilities, and processing power from the communication network and processing platform. These advanced driving applications can be grouped into static, which runs all the time as the engine starts and dynamic, which runs for a duration of time depending on the vehicle conditions. After the emergence of IEEE Time-Sensitive Networking (TSN) features for Ethernet technology, the automotive industry started to move towards the usage of TSN for advanced driving applications. However, IEEE TSN poses a challenge in streamlining the schedules and routes of the dynamic traffic since they require swift and fast determination of transmission schedules and routes on-the-fly. In this paper, we mainly focus on static traffic and device a novel static scheduling and routing algorithm that would be conducive for dynamic traffic requirements. In this approach, we have developed Mixed-integer programming (MIP) based joint scheduling and routing of static applications with the aim of load balancing such that more dynamic traffic would be schedulable as the vehicle drives off. We proposed two load-balancing based objective functions and conducted an experimental analysis of objective functions with six different vehicle network configurations in two scales of zonal architecture. Experimental evaluations show the efficacy of our developed algorithm, in which the load is balanced in the egress port of the network, which in turn can schedule more dynamic traffic.
Cooperative intelligent transportation systems (cITS) are a promising technology to enhance driving safety and efficiency. Vehicles communicate wirelessly with other vehicles and infrastructure, thereby creating a highly dynamic and heterogeneously managed ad-hoc network. It is these network properties that make it a challenging task to protect integrity of the data and guarantee its correctness. A major component is the problem that traditional security mechanisms like public key infrastructure (PKI)-based asymmetric cryptography only exclude outsider attackers that do not possess key material. However, because attackers can be insiders within the network (i.e., possess valid key material), this approach cannot detect all possible attacks. In this survey, we present misbehavior detection mechanisms that can detect such insider attacks based on attacker behavior and information analysis. In contrast to well-known intrusion detection for classical IT systems, these misbehavior detection mechanisms analyze information semantics to detect attacks, which aligns better with highly application-tailored communication protocols foreseen for cITS. In our survey, we provide an extensive introduction to the cITS ecosystem and discuss shortcomings of PKI-based security. We derive and discuss a classification for misbehavior detection mechanisms, provide an in-depth overview of seminal papers on the topic, and highlight open issues and possible future research trends.
The chapter provides an overview of the use cases, the communication technologies, the stakeholders, the past and current R&D activities, and the future plans for CAD in Europe. The evolution towards CAD is spanning over more than two decades, a clear indication that Europe has a rich R&D history in the domain and that it will continue driving the future definition of CAD in the wider sense of 'cooperative, connected, and automated mobility.
The idea behind collective perception is to improve vehicles' awareness about their surroundings. Every vehicle shares information describing its perceived environment by means of V2X communication. Similar to other information shared using V2X communication, collective perception information is potentially safety relevant, which means there is a need to assess the reliability and quality of received information before further processing. Transmitted information may have been forged by attackers or contain inconsistencies e.g. caused by malfunctions. This paper introduces a novel approach for estimating a belief that a pair of entities, e.g. two remote vehicles or the host vehicle and a remote vehicle, within a Vehicular ad hoc Network (VANET) are both trustworthy. The method updates the belief based on the consistency of the data that both entities provide. The evaluation shows that the proposed method is able to identify forged information.
Connected vehicles are an essential part of Intelligent Transport Systems (ITS). A number of communication technologies exist that can complement each other or serve as an alternative. Keeping that in mind, to get the most benefit for a connected vehicle, a hybrid communication paradigm where multiple communication technologies are used in parallel is considered as the natural way forward. To achieve this in practice, it is important to design vehicular communication architectures to be flexible but also reliable. Building upon an established theory of adaptation layer based architecture in literature, this paper discusses the specifics of a practical implementation of such architecture. This practical environment is provided within the European research project ADAS&ME. The paper discusses the practical assumptions while using an adaptation layer based hybrid communication architecture and presents the benefits of it while also critically mentioning the shortcomings.
Cooperative Intelligent Transport Systems (C-ITS) operating in the 5 GHz band in Europe is expected to use only a single communication channel during initial deployment phase. The initial deployment is focused on a limited set of applications assuming a rather small equipment rate of vehicles and road side stations. Current efforts spent on future C-ITS application research indicate considerable growth of C-ITS penetration in following years. The increasing C-ITS penetration rate and the introduction of novel applications will result in growing demand of communication bandwidth that can be addressed by utilizing multiple radio communication channels in parallel. This paper discusses requirements for multi-channel operation (MCO) in European C-ITS, analyzes boundary conditions in the designated frequency bands, presents a concept for offloading and backloading information from congested communication channels, and describes extensions to the GeoNetworking protocol to support MCO.
Initial deployment of basic safety related Cooperative-ITS applications in Europe is assumed to be realized via simple and cost effective V2X systems, generally consisting of single radio / single channel implementations. Subsequent deployment phases, are envisioned making use of multiple radios and multiple channels within the allocated frequency range. The present paper discusses options for channel usage beyond initial deployment, taking into account new applications, their requirements, cross channel interference, and impacts from decentralized congestion control (DCC). Systems deployed after initial deployment are assumed to be able to operate on multiple channels in parallel, e.g. receive and optionally transmit on at least two channels in parallel. Systems operating on two channels in parallel are usually referred to as dual radio systems (dual RX/TX), operation on multiple channels in general as multi-channel operation (MCO). As a result of the discussion the paper proposes components for a framework for MCO beyond initial deployment of V2X systems in Europe. The framework is flexible enough to accommodate future V2X applications in a communication resource efficient way.
In previous work, the authors investigated possibilities of an architecture for the functional distribution of a vehicle-to-x (V2X) system on two devices with different capabilities. One of the devices is an in-vehicle onboard unit (OBU), the other a personal portable device (PPD), such as a smartphone or tablet PC. The authors developed three different concepts to split workload between the devices, and investigated them regarding overall performance and flexibility. This work complements previous work with an in-depth security analysis. Security of V2X systems is challenging, especially in case parts of the system are not part of the physically reasonably well protected in-vehicle network domain. The security analysis unveils advantages and disadvantages of the three concepts. Based on the analysis, this work discusses how V2X security can be realized in the two-device setup, providing maximum security with minimum impact on the system performance. The conclusions summarize which level of security can be reached with each of the three approaches.
A decisive factor for effective driver awareness and warning systems is the visualization of important and safety critical information for the driver. In previous work, the authors introduced a flexible two- component system that can visualize real time data from vehicle-to-x (V2X) communication [1]. In order to maximize the overall performance and reliability, the system consists of a vehicle-integrated V2X communication unit (onboard unit, OBU), and a personal portable device (PPD) which is used for conveying the information to the driver. The focus of this paper is on the application running on the PPD. The mobile application supports some of the so-called ‘day-one use cases’ that are considered to create a sound basis at the beginning of V2X deployment. Based on experiences during the development and the results from a laboratory user study, key findings are summarized and recommendations for the design of a V2X-based visualization solution are given. The main aspect of the examination is the human-machine interface. Specifically, the user interface, text-to-speech support, mode of warning presentation and selection of itinerary-related information are considered.
Frank Kargl合作论文数the Distributed and Embedded Security Research Group at University of Twente in the Netherlands4
Markus Pilz合作论文数University of Zurich2