7 Intelligent and Connected Cyber-Physical Systems: A Perspective. . .
389
unstable connection topology (as vehicles are moving) and strict timing constraints.
However, connected autonomous vehicles have the feature that it is easier to identify
neighbors, which can support secure consensus algorithms.
7.3.2.5 System Integration
With a key management system, we can sign and verify messages and much
increase the difficulty for outsider to perform attacks. However, the resource on a
vehicle is usually limited, and there are tight and hard real-time deadlines, implying
that signing and verifying all messages are probably not applicable. One previous
piece of work explored the design space of receiving group assignment within a
single vehicle [36]. The receiving group assignment affects not only the number
of Message Authentication Codes (MACs) transmitted on the network but also the
level of security threats between nodes in the same receiving group. This concept
can be generalized to partial signing and verification without violating security and
other system constraints. This is doable as most messages in automotive systems are
periodic, so a few missing, corrupted, or fake messages may not lead to dangerous
states. In some cases, this can be taken care of by a proper controller design,
following the discussion in the beginning of this chapter.
In a more formal way, the problem of system integration can be formulated by the
Contact-Based Design (CBD) methodology [37, 38] and the Platform-Based Design
(PBD) paradigm [39]. The behavior of different subsystems and components,
including security mechanisms, can be defined by property specification languages,
e.g., Linear Temporal Logic (LTL) and its extensions. Then, formal verification with
assume-guarantee contracts can be applied to guarantee the correctness of system
design. Given that formal verification may have limited efficiency and scalability,
one alternative is the run-time verification which serves a similar role to an intrusion
detection system. On the other hand, the previous work applied the PBD paradigm to
security-aware system design [36]. As shown in Fig. 7.15, the application space and
the architecture space are abstracted (otherwise, they are too complicated and too
specific to be synthesized or analyzed) to models which keep relevant features but
remove irrelevant details. Similarly, security mechanisms also need to be abstracted
and fed into the mapping process to see if they can be integrated into the application
and the architecture. Based on the mapping process, we can select appropriate
security mechanisms, satisfy different kinds of design constraints, and guarantee
the correctness of system design.
7.3.2.6 Summary
Security is a rising concern for automotive systems. To address this concern, security
protection is needed at different layers including external networks (between
vehicles and infrastructures), gateways, in-vehicular networks, and components. In
this case study, we focused on the emerging connected autonomous vehicles and
389
unstable connection topology (as vehicles are moving) and strict timing constraints.
However, connected autonomous vehicles have the feature that it is easier to identify
neighbors, which can support secure consensus algorithms.
7.3.2.5 System Integration
With a key management system, we can sign and verify messages and much
increase the difficulty for outsider to perform attacks. However, the resource on a
vehicle is usually limited, and there are tight and hard real-time deadlines, implying
that signing and verifying all messages are probably not applicable. One previous
piece of work explored the design space of receiving group assignment within a
single vehicle [36]. The receiving group assignment affects not only the number
of Message Authentication Codes (MACs) transmitted on the network but also the
level of security threats between nodes in the same receiving group. This concept
can be generalized to partial signing and verification without violating security and
other system constraints. This is doable as most messages in automotive systems are
periodic, so a few missing, corrupted, or fake messages may not lead to dangerous
states. In some cases, this can be taken care of by a proper controller design,
following the discussion in the beginning of this chapter.
In a more formal way, the problem of system integration can be formulated by the
Contact-Based Design (CBD) methodology [37, 38] and the Platform-Based Design
(PBD) paradigm [39]. The behavior of different subsystems and components,
including security mechanisms, can be defined by property specification languages,
e.g., Linear Temporal Logic (LTL) and its extensions. Then, formal verification with
assume-guarantee contracts can be applied to guarantee the correctness of system
design. Given that formal verification may have limited efficiency and scalability,
one alternative is the run-time verification which serves a similar role to an intrusion
detection system. On the other hand, the previous work applied the PBD paradigm to
security-aware system design [36]. As shown in Fig. 7.15, the application space and
the architecture space are abstracted (otherwise, they are too complicated and too
specific to be synthesized or analyzed) to models which keep relevant features but
remove irrelevant details. Similarly, security mechanisms also need to be abstracted
and fed into the mapping process to see if they can be integrated into the application
and the architecture. Based on the mapping process, we can select appropriate
security mechanisms, satisfy different kinds of design constraints, and guarantee
the correctness of system design.
7.3.2.6 Summary
Security is a rising concern for automotive systems. To address this concern, security
protection is needed at different layers including external networks (between
vehicles and infrastructures), gateways, in-vehicular networks, and components. In
this case study, we focused on the emerging connected autonomous vehicles and
