论文标题
嵌入式警务和政策执法在下一代汽车电子产品的数字物理融合时代
Embedded Policing and Policy Enforcement based Security in the era of Digital-Physical Convergence for Next-Generation Vehicular Electronics
论文作者
论文摘要
包含复杂功能的智能,连接的车辆的出现通过提高车辆运输的安全性,安全性和效率来使社会受益匪浅。其中的大部分是通过嵌入式系统体系结构的技术进步来实现的,这些进步为车辆制造商提供了实施智能车辆服务并在少量灵活且可集成的域控制器中巩固它们的机会。因此,允许越来越集中的操作包括新的和遗留功能。尽管关键和非关键车辆服务的数字化合物融合时代在降低了车辆电子产品的成本和电子足迹方面具有优势,但它带来了重大的安全性和安全性挑战。解决这一研究问题的一种方法是引入可以检测到由攻击或故障引起的意外或恶意行为的故障机制,并积极地对控制和最大程度地响应身体损害或安全危害。本文介绍了一种新颖的嵌入式警务和政策执法平台体系结构,以及下一代内车内域控制器的随附的安全建模方法。为了证明所提出的方法,进行了连接的车辆案例研究。已经考虑了一种现实的攻击方案来得出安全策略,并由拟议的安全平台强制执行,以为特定于域的功能提供安全性和安全性。
The emergence of intelligent, connected vehicles, containing complex functionality has potential to greatly benefit society by improving safety, security and efficiency of vehicular transportation. Much of this has been enabled by technological advancements in embedded system architectures, which provided opportunities for vehicle manufacturers to implement intelligent vehicle services and consolidate them within a small number of flexible and integrable domain controllers. Thus allowing for increasingly centralised operations consisting of both new and legacy functionalities. While this era of digital-physical convergence of critical and non-critical vehicle services presents advantages in terms of reducing the cost and electronic footprint of vehicular electronics, it has produced significant security and safety challenges. One approach to this research problem is to introduce fail-over mechanisms that can detect unexpected or malicious behaviours, caused by attack or malfunction, and pro-actively respond to control and minimise physical damage or safety hazards. This paper presents a novel embedded policing and policy enforcement platform architecture and the accompanied security modelling approach for next-generation in-vehicle domain controllers. To demonstrate the proposed approach, a connected vehicle case study is conducted. A realistic attack scenarios have been considered to derive security policies and enforced by the proposed security platform to provide security and safety to domain-specific features.