Modern cars are no longer purely mechanical devices but shelter so much digital technology that they resemble a network of computers. Electronic Control Units (ECUs) need to exchange a large amount of data for the various functions of the car to work, and such data must be made secure if we want those functions to work as intended despite malicious activity by attackers. TOUCAN is a new security protocol designed to be secure and at the same time both CAN and AUTOSAR compliant. It achieves security in terms of authenticity, integrity and confidentiality, yet without the need to upgrade (the hardware of) existing ECUs or enrich the network with novel components. The overhead is tiny, namely a reduction of the size of the Data field of a frame. A prototype implementation exhibits promising performance on a STM32F407Discovery board.
翻译:电子控制单位(ECUs)需要为汽车的各种功能交换大量数据,而如果我们希望这些功能能像攻击者恶意活动所预期的那样发挥作用,则这些数据必须安全。TOUCAN是一项新的安全议定书,旨在既安全又同时符合CAN和AUTOSAR的要求。它实现了真实性、完整性和保密性方面的安全,但无需更新现有的ECU(硬件)或用新的部件丰富网络。管理费用很小,即缩小框架数据字段的大小。一个原型的执行显示STM32F407 Discovery董事会有望取得良好的业绩。