386
W. Chang et al.
It should be emphasized that a non-malicious fault or error (the first and second
concerns) and a security attack (the third and fourth concerns) are different. The
source of a non-malicious fault or error can usually be measured by probability. In
contrast, a security attack is malicious, and it is possible to attack the weakest part
of a system.
In this case study, we will introduce the security challenges in connected vehicle
applications and discuss three important topics: key management system, intrusion
detection system, and system integration.
7.3.2.2 Security Challenges in Connected Vehicle Applications
As news reported that some cases that a vehicle can be successfully hacked and then
patched, security is a rising concern for automotive systems. However, there are still
many open questions, especially for connected autonomous vehicles (the security
of a single vehicle has been well studied [26, 27, 28]). This is because, inevitably,
autonomous vehicles will rely on decisions of vehicles themselves, and connected
vehicles will make decisions based on external information, so totally separating
internal and external networks cannot match the need. Furthermore, there is still a
gap for connected autonomous vehicles to be realized, and many applications are
still under development, which needs us to address security in advance. Last but not
least, traditional automotive design does not have security in mind, making system
integration more difficult and thus unresolved at this point.
There are many different kinds of security attacks. In this case study, we abstract
them to outsider attacks and insider attacks. An outsider attack is from an entity
which has not been authenticated, while an insider attack is from an entity which
has been authenticated but compromised. Some examples of insider attacks include
a tempered sensor, a discovered hardware or software implementation flaw, a leaked
security key, or a legitimate but malicious user. For outsider protection, a key
management system such as a Public Key Infrastructure (PKI) is the target system
in this chapter. For insider protection, an intrusion detection system is the target
system, as they focus on the information legitimacy which cannot be verified by a
key management system.
7.3.2.3 Key Management System
A key management system is fundamental to protection against outsider attacks.
The proof-of-concept of Secure Credential Management System (SCMS) [29] has
been proposed by the United States Department of Transportation (USDOT) in
recent years to establish trust between connected vehicles and vehicular infrastructures and then support security and privacy for vehicular networks. Based on
traditional PKIs, the goal of SCMS is to provide scalability to support millions of
vehicles and trade-offs between security, privacy, and efficiency. A simplified SCMS
architecture design is shown in Fig. 7.13. There are several Certificate Authorities
W. Chang et al.
It should be emphasized that a non-malicious fault or error (the first and second
concerns) and a security attack (the third and fourth concerns) are different. The
source of a non-malicious fault or error can usually be measured by probability. In
contrast, a security attack is malicious, and it is possible to attack the weakest part
of a system.
In this case study, we will introduce the security challenges in connected vehicle
applications and discuss three important topics: key management system, intrusion
detection system, and system integration.
7.3.2.2 Security Challenges in Connected Vehicle Applications
As news reported that some cases that a vehicle can be successfully hacked and then
patched, security is a rising concern for automotive systems. However, there are still
many open questions, especially for connected autonomous vehicles (the security
of a single vehicle has been well studied [26, 27, 28]). This is because, inevitably,
autonomous vehicles will rely on decisions of vehicles themselves, and connected
vehicles will make decisions based on external information, so totally separating
internal and external networks cannot match the need. Furthermore, there is still a
gap for connected autonomous vehicles to be realized, and many applications are
still under development, which needs us to address security in advance. Last but not
least, traditional automotive design does not have security in mind, making system
integration more difficult and thus unresolved at this point.
There are many different kinds of security attacks. In this case study, we abstract
them to outsider attacks and insider attacks. An outsider attack is from an entity
which has not been authenticated, while an insider attack is from an entity which
has been authenticated but compromised. Some examples of insider attacks include
a tempered sensor, a discovered hardware or software implementation flaw, a leaked
security key, or a legitimate but malicious user. For outsider protection, a key
management system such as a Public Key Infrastructure (PKI) is the target system
in this chapter. For insider protection, an intrusion detection system is the target
system, as they focus on the information legitimacy which cannot be verified by a
key management system.
7.3.2.3 Key Management System
A key management system is fundamental to protection against outsider attacks.
The proof-of-concept of Secure Credential Management System (SCMS) [29] has
been proposed by the United States Department of Transportation (USDOT) in
recent years to establish trust between connected vehicles and vehicular infrastructures and then support security and privacy for vehicular networks. Based on
traditional PKIs, the goal of SCMS is to provide scalability to support millions of
vehicles and trade-offs between security, privacy, and efficiency. A simplified SCMS
architecture design is shown in Fig. 7.13. There are several Certificate Authorities
