<p>Connected vehicles have software that must be updated to fix vulnerabilities or add new functionalities. While over-the-air updates prevent car owners from bringing their vehicles to a service center, they introduce significant security risks. This paper proposes a vehicular over-the-air update architecture combining the two most adopted trusted execution environment solutions: Intel SGX at the server and ARM TrustZone at the client. The main contribution is the protection of software updates from attackers that manipulate the entire operating system at both ends aiming to reverse engineering the software or introducing a malicious behavior. The implementation uses a device with OP-TEE and a software repository implemented with CACIC-DevKit. The paper also extends our previous work by evaluating an alternative server implementation using Gramine-SGX. Our experiments reveal that the impact of the TEE is negligible, even for small software block transfers. Compared with CACIC-DevKit, Gramine-SGX doubles the latency, despite the development simplification. This indicates that CACIC-DevKit better suits a high mobility scenario, such as vehicular networks, where the connection with the server may be short term.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

End-to-end trusted computing architecture for vehicular over-the-air updates

  • Guilherme A. Thomaz,
  • Thierno Barry,
  • Matteo Sammarco,
  • Miguel Elias M. Campista

摘要

Connected vehicles have software that must be updated to fix vulnerabilities or add new functionalities. While over-the-air updates prevent car owners from bringing their vehicles to a service center, they introduce significant security risks. This paper proposes a vehicular over-the-air update architecture combining the two most adopted trusted execution environment solutions: Intel SGX at the server and ARM TrustZone at the client. The main contribution is the protection of software updates from attackers that manipulate the entire operating system at both ends aiming to reverse engineering the software or introducing a malicious behavior. The implementation uses a device with OP-TEE and a software repository implemented with CACIC-DevKit. The paper also extends our previous work by evaluating an alternative server implementation using Gramine-SGX. Our experiments reveal that the impact of the TEE is negligible, even for small software block transfers. Compared with CACIC-DevKit, Gramine-SGX doubles the latency, despite the development simplification. This indicates that CACIC-DevKit better suits a high mobility scenario, such as vehicular networks, where the connection with the server may be short term.