Formal Security Analysis of Vehicle Diagnostic Protocols


연구 분야: Analysis



학회: ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security


초록

Diagnostic protocols for vehicles are important for maintenance, updates, etc. However, if they are not secure, an attacker can use them as an entry point to the vehicle or even directly access critical functionality. In this paper, we discuss the security of the vehicle diagnostics protocols Diagnostics over IP (DoIP) and Unified Diagnostic Services (UDS). For UDS, we provide a formal analysis of the included security protocols SecurityAccess service and the different variants of the new Authentication service introduced in the year 2020. We present two new vulnerabilities, we identified in our analyses, describe how they can be mitigated and formally verify our mitigations. Furthermore, we give recommendations on how to securely implement UDS and how future standards can be improved.


Author Profile
Timm Lauser

Darmstadt University of Applied Sciences Germany

Germany
Author Profile
Christoph Krauß

Darmstadt University of Applied Sciences Germany

Germany

📄 논문 정보

발행 연도 2023년
인용수 7
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (203건)