{"title":"汽车无线更新的安全问题","authors":"J. Howden, L. Maglaras, M. Ferrag","doi":"10.4018/ijcwt.2020040104","DOIUrl":null,"url":null,"abstract":"Over-the-air(OTA)updateisamethodforvehiclemanufacturerstoremotelydistributemaintenance updates,performance,andfeatureenhancementsthroughthevehicle’slifespan.Recallsofvehicles costthemanufacturesalotofmoney.OTAsolvestherecallissue,whileallowingconsumerstopay forservicesandfeaturesviaanupdate.TheOTAecosystemincludesthecoderswhofirstdeveloped the firmware, the 1st Tier suppliers, the vehicle manufacturers, and the vehicle itself. Currently, manufacturersdesignedthenetworksforspeedandresponsiveness,andnotsecurity.Thisarticle examinestheseelementsanddrillsintothesecurityavailableforeach.Theslowestandoneofthe mostvulnerablepartsofthesystemisthecommunicationswithinthevehicle.Thevehiclenetworks mustensuretheintegrityandauthenticityofmessagestransmittedtoguaranteesoftwareprogrammed ontoECUsareauthorizedandtamper-free.Specialisthardwarewithinthevehiclemakesthispossible inanoperationenvironment,suchashardwaresecuritymodules. KeyWORdS Electronic Control Units, Automated Cars, Over-The-Air Updates, Connected Vehicles, Security, Cryptography, Hardware Security Module, Trust","PeriodicalId":41462,"journal":{"name":"International Journal of Cyber Warfare and Terrorism","volume":"27 1","pages":"64-81"},"PeriodicalIF":0.2000,"publicationDate":"2020-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"The Security Aspects of Automotive Over-the-Air Updates\",\"authors\":\"J. Howden, L. Maglaras, M. Ferrag\",\"doi\":\"10.4018/ijcwt.2020040104\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Over-the-air(OTA)updateisamethodforvehiclemanufacturerstoremotelydistributemaintenance updates,performance,andfeatureenhancementsthroughthevehicle’slifespan.Recallsofvehicles costthemanufacturesalotofmoney.OTAsolvestherecallissue,whileallowingconsumerstopay forservicesandfeaturesviaanupdate.TheOTAecosystemincludesthecoderswhofirstdeveloped the firmware, the 1st Tier suppliers, the vehicle manufacturers, and the vehicle itself. Currently, manufacturersdesignedthenetworksforspeedandresponsiveness,andnotsecurity.Thisarticle examinestheseelementsanddrillsintothesecurityavailableforeach.Theslowestandoneofthe mostvulnerablepartsofthesystemisthecommunicationswithinthevehicle.Thevehiclenetworks mustensuretheintegrityandauthenticityofmessagestransmittedtoguaranteesoftwareprogrammed ontoECUsareauthorizedandtamper-free.Specialisthardwarewithinthevehiclemakesthispossible inanoperationenvironment,suchashardwaresecuritymodules. KeyWORdS Electronic Control Units, Automated Cars, Over-The-Air Updates, Connected Vehicles, Security, Cryptography, Hardware Security Module, Trust\",\"PeriodicalId\":41462,\"journal\":{\"name\":\"International Journal of Cyber Warfare and Terrorism\",\"volume\":\"27 1\",\"pages\":\"64-81\"},\"PeriodicalIF\":0.2000,\"publicationDate\":\"2020-04-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Cyber Warfare and Terrorism\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.4018/ijcwt.2020040104\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"POLITICAL SCIENCE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Cyber Warfare and Terrorism","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/ijcwt.2020040104","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"POLITICAL SCIENCE","Score":null,"Total":0}
引用次数: 6
The Security Aspects of Automotive Over-the-Air Updates
Over-the-air(OTA)updateisamethodforvehiclemanufacturerstoremotelydistributemaintenance updates,performance,andfeatureenhancementsthroughthevehicle’slifespan.Recallsofvehicles costthemanufacturesalotofmoney.OTAsolvestherecallissue,whileallowingconsumerstopay forservicesandfeaturesviaanupdate.TheOTAecosystemincludesthecoderswhofirstdeveloped the firmware, the 1st Tier suppliers, the vehicle manufacturers, and the vehicle itself. Currently, manufacturersdesignedthenetworksforspeedandresponsiveness,andnotsecurity.Thisarticle examinestheseelementsanddrillsintothesecurityavailableforeach.Theslowestandoneofthe mostvulnerablepartsofthesystemisthecommunicationswithinthevehicle.Thevehiclenetworks mustensuretheintegrityandauthenticityofmessagestransmittedtoguaranteesoftwareprogrammed ontoECUsareauthorizedandtamper-free.Specialisthardwarewithinthevehiclemakesthispossible inanoperationenvironment,suchashardwaresecuritymodules. KeyWORdS Electronic Control Units, Automated Cars, Over-The-Air Updates, Connected Vehicles, Security, Cryptography, Hardware Security Module, Trust