A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CAN
- Authors
- Woo, Samuel; Jo, Hyo Jin; Lee, Dong Hoon
- Issue Date
- 4월-2015
- Publisher
- IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
- Keywords
- Connected car; controller area network (CAN); in-vehicle network security; key management
- Citation
- IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, v.16, no.2, pp.993 - 1006
- Indexed
- SCIE
SCOPUS
- Journal Title
- IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS
- Volume
- 16
- Number
- 2
- Start Page
- 993
- End Page
- 1006
- URI
- https://scholar.korea.ac.kr/handle/2021.sw.korea/93890
- DOI
- 10.1109/TITS.2014.2351612
- ISSN
- 1524-9050
- Abstract
- Vehicle-IT convergence technology is a rapidly rising paradigm of modern vehicles, in which an electronic control unit (ECU) is used to control the vehicle electrical systems, and the controller area network (CAN), an in-vehicle network, is commonly used to construct an efficient network of ECUs. Unfortunately, security issues have not been treated properly in CAN, although CAN control messages could be life-critical. With the appearance of the connected car environment, in-vehicle networks (e.g., CAN) are now connected to external networks (e.g., 3G/4G mobile networks), enabling an adversary to perform a long-range wireless attack using CAN vulnerabilities. In this paper we show that a long-range wireless attack is physically possible using a real vehicle and malicious smartphone application in a connected car environment. We also propose a security protocol for CAN as a countermeasure designed in accordance with current CAN specifications. We evaluate the feasibility of the proposed security protocol using CANoe software and a DSP-F28335 microcontroller. Our results show that the proposed security protocol is more efficient than existing security protocols with respect to authentication delay and communication load.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - School of Cyber Security > Department of Information Security > 1. Journal Articles
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.