7 Intelligent and Connected Cyber-Physical Systems: A Perspective. . .
387
Fig. 7.13 A simplified SCMS architecture design [29]
(CAs) establishing a chain of trust and issuing certificates with different lifetime
validity to form the basis of secure communication between connected vehicles and
vehicular infrastructure. Onboard Equipment (OBE), Road Side Entity (RSE), and
Aftermarket Safety Device (ASD) must be registered in the system and must obtain
certificates. Then message exchange can be protected by public and private keys. As
a proof-of-concept system, there are still some detailed design issues which should
be addressed. Please refer to one previous publication for those issues [30].
It should be mentioned that a key management system should be integrated with
the underlying communication protocols. There are two main approaches to realize
the connectivity. One is based on Dedicated Short-Range Communications (DSRC),
and the other one is based on cellular networks. The DSRC has a longer history, and
many field tests have been done by automotive makers. The DSRC provides security
services at the middle layers (network layer, transport layer, and message sublayer)
[31]. Message authentication is supported by using the Elliptic Curve Digital
Signature Algorithm (ECDSA), which is an asymmetric cryptographic algorithm.
When a vehicle intends to send a message, it signs the message with its private key
and sends the message with its signature and certificate digest. A vehicle receiving
the message then uses the public key corresponding to the private key to verify
the message. The generation time of a message and the location of a vehicle are
optionally included in a signed message to protect against replay attacks. Besides
DSRC, many automotive makers and high-tech companies have also formed the 5G
Automotive Association (5GAA). It is necessary to further investigate its security
services.
7.3.2.4 Intrusion Detection System
Besides a key management system which can detect abnormal security key usage
(probably by outsider attackers), an intrusion detection system is needed to monitor
systems, networks, and/or information between vehicles and infrastructures. We
expect an architecture where cloud servers and edge servers can also install intrusion
detection systems, as shown in Fig. 7.14.
Précédent

- 392/647

Suivant