Current designs of future In-Vehicle Networks (IVN) prepare for switched Ethernet backbones, which can host advanced LAN technologies such as IEEE Time-Sensitive Networking (TSN) and Software-Defined Networking (SDN). In this paper, we present an integrated Time-Sensitive Software-Defined Networking (TSSDN) architecture that simultaneously enables control of synchronous and asynchronous real-time and best-effort communication for all IVN traffic classes. Despite the central SDN controller, we can validate that control can operate without a delay penalty for TSN traffic, provided protocols are properly mapped. We demonstrate how TSSDN adaptably and reliably enhances network security for in-vehicle communication. A systematic investigation of the possible control flow integrations with switched Ether-networks reveals that these strategies allow for shaping the attack surface of a software-defined IVN. We discuss embeddings of control flow identifiers on different layers, covering the range from a fully exposed mapping to deep encapsulation. We experimentally evaluate these strategies in a production vehicle, which we map to a modern Ethernet topology. Our findings indicate that visibility of automotive control flows on lower network layers enables isolation and access control throughout the network infrastructure. Such a TSSDN backbone can establish and survey trust zones within the IVN and reduce the attack surface of connected cars in various attack scenarios.
翻译:在本文中,我们提出了一个综合的、对时间敏感的软件-定义网络(TSSDN)结构,可以同时控制同步和不同步的实时和最佳努力通信,供所有IVN交通级别使用。尽管中央SDN控制器可以证实控制可以不受拖延地运行TSN交通的罚款,只要妥善地绘制协议。我们展示了TSSDN如何可适应和可靠地加强车辆通信的网络安全。对变换的Ether网络(TSDN)的可能控制流动整合进行系统调查表明,这些战略允许对软件定义的IVN网络的攻击面进行控制。我们讨论控制流动标识嵌入不同层次,从完全暴露的测绘到深层封封封。我们实验性地评估了这些战略,在一种生产工具中,我们绘制了对四号汽车攻击系统的升级,我们绘制了对四号网络的升级控制。