Automotive cyber-physical systems are in transition from the closed-systems to open-networking systems. As a result, in-vehicle networks such as the controller area network (CAN) have become essential to connect to inter-vehicle networks through the various rich interfaces. Newly exposed security concerns derived from this requirement may cause in-vehicle networks to pose threats to automotive security and driver's safety. In this paper, to ensure a high level of security of the in-vehicle network for automotive CPS, we propose a novel lightweight and practical cyber defense platform, referred to as CANon (CAN with origin authentication and non-repudiation), to be enabled to detect cyber-attacks in real-time. CANon is designed based on the hierarchical approach of centralized-session management and distributed-origin authentication. In the former, a gateway node manages each initialization vector and session of origin-centric groups consisting of two more sending and receiving nodes. In the latter, the receiving nodes belonging to the given origin-centric group individually perform the symmetric key-based detection against cyber-attacks by verifying each message received from the sending node, namely origin authentication, in real-time. To improve the control security, CANon employs a one-time local key selected from a sequential hash chain (SHC) for authentication of an origin node in a distributed mode and exploits the iterative hash operations with randomness. Since the SHC can constantly generate and consume hash values regardless of their memory capacities, it is very effective for resource-limited nodes for in-vehicle networks. In addition, through implicit key synchronization within a given group, CANon addresses the challenges of a key exposure problem and a complex key distribution mechanism when performing symmetric key-based authentication. To achieve lightweight cyber-attack detection without imposing an additive load on CAN, CANon uses a keyed-message authentication code (KMAC) activated within a given group. The detection performance of CANon is evaluated under an actual node of Freescale S12XF and virtual nodes operating on the well-known CANoe tool. It is seen that the detection rate of CANon against brute-force and replay attacks reaches 100% when the length of KMAC is over 16 bits. It demonstrates that CANon ensures high security and is sufficient to operate in real-time even on low-performance ECUs. Moreover, CANon based on several software modules operates without an additive hardware security module at an upper layer of the CAN protocol and can be directly ported to CAN-FD (CAN with Flexible Data rate) so that it achieves the practical cyber defense platform.

Download full-text PDF

Source
http://www.ncbi.nlm.nih.gov/pmc/articles/PMC9003419PMC
http://dx.doi.org/10.3390/s22072636DOI Listing

Publication Analysis

Top Keywords

in-vehicle networks
12
canon
10
lightweight practical
8
cyber-attack detection
8
controller area
8
practical cyber
8
cyber defense
8
defense platform
8
origin authentication
8
receiving nodes
8

Similar Publications

Anxiety disorders are one of the top contributors to psychiatric burden worldwide. Recent years have seen a dramatic rise in the potential anxiolytic properties ascribed to cannabidiol (CBD), a non-intoxicating constituent of the Cannabis Sativa plant. This has led to several clinical trials underway to examine the therapeutic potential of CBD for anxiety disorders.

View Article and Find Full Text PDF

Road Traffic Gesture Autonomous Integrity Monitoring Using Fuzzy Logic.

Sensors (Basel)

December 2024

Computer Engineering, Brandenburg University of Technology, Cottbus-Senftenberg, 03046 Cottbus, Germany.

Occasionally, four cars arrive at the four legs of an unsignalized intersection at the same time or almost at the same time. If each lane has a stop sign, all four cars are required to stop. In such instances, gestures are used to communicate approval for one vehicle to leave.

View Article and Find Full Text PDF

The rapid development of Internet of Things technology has promoted the popularization of Internet of Vehicles, and its safety and reliability have become the focus of intelligent transportation system research. Vehicle-road collaboration relies on the collaborative computing and storage resources of the vehicle on-board unit (OBU), which are usually limited. When the vehicle in the edge area needs to do computing tasks such as intelligent driving, but its own computing resources are insufficient.

View Article and Find Full Text PDF

Deep Learning-Based Method for Detecting Traffic Flow Parameters Under Snowfall.

J Imaging

November 2024

Jiangsu Province Collaborative Innovation Center of Modern Urban Traffic Technologies, Southeast University, Nanjing 211189, China.

In recent years, advancements in computer vision have yielded new prospects for intelligent transportation applications, specifically in the realm of automated traffic flow data collection. Within this emerging trend, the ability to swiftly and accurately detect vehicles and extract traffic flow parameters from videos captured during snowfall conditions has become imperative for numerous future applications. This paper proposes a new analytical framework designed to extract traffic flow parameters from traffic flow videos recorded under snowfall conditions.

View Article and Find Full Text PDF

Drowsiness while driving is a major factor contributing to traffic accidents, resulting in reduced cognitive performance and increased risk. This article gives a complete analysis of a real-time, non-intrusive sleepiness detection system based on convolutional neural networks (CNNs). The device analyses video data recorded from an in-vehicle camera to monitor drivers' facial expressions and detect fatigue indicators such as yawning and eye states.

View Article and Find Full Text PDF

Want AI Summaries of new PubMed Abstracts delivered to your In-box?

Enter search terms and have AI summaries delivered each week - change queries or unsubscribe any time!