• DocumentCode
    2267474
  • Title

    Enhancing security in CAN systems using a star coupling router

  • Author

    Kammerer, Roland ; Frömel, Bernhard ; Wasicek, Armin

  • Author_Institution
    Inst. for Comput. Eng., Vienna Univ. of Technol., Vienna, Austria
  • fYear
    2012
  • fDate
    20-22 June 2012
  • Firstpage
    237
  • Lastpage
    246
  • Abstract
    Controller Area Network (CAN) is the most widely used protocol in the automotive domain. Bus-based CAN does not provide any security mechanisms to counter manipulations like eavesdropping, fabrication of messages, or denial-of-service attacks. The vulnerabilities in bus-based CAN are alarming, because safety-critical subsystems (e.g., the power train) often deploy a CAN bus, and hence a failure propagation from the security domain to the safety domain can take place. In this paper we propose a star coupling router and a trust model for this router to overcome some of the security deficiencies present in bus-based CAN systems. The CAN router establishes a partitioning of a CAN bus into separate CAN segments and allows to rigorously check the traffic within the CAN system, including the value and time domains. We evaluate the introduced trust model on a prototype implementation of the CAN router by performing attacks that would be successful on classic bus-based CAN, but are detected and contained on router-based CAN. The router can consequently increase the security in automotive applications and render some of the attacks described in the literature (e.g., fuzzying attack) on a car useless. Since the CAN router offers ports that are compatible to standard CAN, the router can be used to increase the security of legacy CAN based systems.
  • Keywords
    computer network security; controller area networks; software maintenance; CAN router; CAN systems security; automotive applications; automotive domain; bus-based CAN; controller area network; denial-of-service attacks; eavesdropping; failure propagation; legacy CAN based systems; message fabrication; power train; router-based CAN; safety domain; safety-critical subsystems; star coupling router; trust model; Automotive engineering; Multicast communication; Routing; Security; Software; Topology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Industrial Embedded Systems (SIES), 2012 7th IEEE International Symposium on
  • Conference_Location
    Karlsruhe
  • Print_ISBN
    978-1-4673-2685-8
  • Electronic_ISBN
    978-1-4673-2683-4
  • Type

    conf

  • DOI
    10.1109/SIES.2012.6356590
  • Filename
    6356590