Automotive softwarization is progressing and future cars are expected to operate a Service-Oriented Architecture on multipurpose compute units, which are interconnected via a high-speed Ethernet backbone. The AUTOSAR architecture foresees a universal middleware called SOME/IP that provides the service primitives, interfaces, and application protocols on top of Ethernet and IP. SOME/IP lacks a robust security architecture, even though security is an essential in future Internet-connected vehicles. In this paper, we augment the SOME/IP service discovery with an authentication and certificate management scheme based on DNSSEC and DANE. We argue that the deployment of well-proven, widely tested standard protocols should serve as an appropriate basis for a robust and reliable security infrastructure in cars. Our solution enables on-demand service authentication in offline scenarios, easy online updates, and remains free of attestation collisions. We evaluate our extension of the common vsomeip stack and find performance values that fully comply with car operations.
翻译:汽车软件化正在进展,未来的汽车预计将在互联网的高速Ethernet骨干网上运行多用途计算单元的面向服务体系结构。AUTOSAR体系结构预测,将提供在以太网和IP上的服务基元、接口和应用程序协议的通用中间件称为SOME/IP。虽然安全是未来连接互联网的汽车所必需的,但SOME/IP缺乏一个强大的安全体系结构。本文将基于DNSSEC和DANE的身份验证和证书管理方案与SOME/IP服务发现相结合。我们认为,在汽车中部署经过充分检验、广泛测试的标准协议应该成为汽车中稳健可靠的安全基础设施的适当基础。我们的解决方案使离线场景下的按需服务认证、易于在线更新,并且不产生认证冲突。我们评估了我们所提出的常用vsomeip堆栈的扩展,并得到与汽车操作完全符合的性能值。