Secure Mobile Platforms for Connected Vehicle Ecosystems: A Synthesis of Threats, Detection, and Governance

Authors

  • Ruturajsinh Kiritsinh Jadeja

Keywords:

connected vehicles; automotive cybersecurity; Controller Area Network; intrusion detection system; Bluetooth infotainment; over-the-air updates; vehicular ad hoc network; blockchain authentication; ISO/SAE 21434; telematics; mobile vehicle key; risk assessment

Abstract

The modern car is not just a vehicle with an internal Controller Area Network (CAN) bus, but can have a proliferation of smartphone-based vehicle keys, Bluetooth-paired infotainment units, cellular telematics control units, and over-the-air (OTA) update channels, and that has expanded the attack surface. This paper reviews and consolidates the results of 27 peer reviewed publications from the literature on mobile connectivity and its impact on automotive cybersecurity risks and the literature's response in terms of detection, authentication, and governance mechanisms, through to 2023. The CAN bus proved to be a safety-critical asset with no built-in authentication capabilities through early experiments that showed an attacker could stop the vehicle when they could access a single electronic control unit (ECU). Later studies on Bluetooth infotainment pairing have found that phonebook and message information can be recovered from paired devices, and near-field-communication (NFC) key schemes using a smartphone can be suggested as replacements for mechanical and radio-frequency (RF) immobilizers. On the defense side, in this paper, we find that a machine-learning and deep-learning based intrusion detection system (IDS) achieves up to 99.995 percent accuracy when detecting CAN traffic and 99.88-99.99 percent accuracy with intra-vehicle and external network datasets, although the values are dataset dependent and do not necessarily align between studies. The paper also draws parallels between the complementary layers of a secure mobile platform that are the paper's topics, namely blockchain-based credential management, provably secure authentication protocols, Bayesian game-theoretic defense allocation, and the ISO/SAE 21434 risk-engineering standard. To organize these mechanisms, a five-layer reference architecture is proposed, and comparison of the various detection, cryptographic, and governance approaches shows that, despite these advances, there are still challenges with cross-dataset validation, the real-time computational viability of embedded devices, and the harmonization of regulations for OTA software updates. The authors conclude that only a layered approach of combined anomaly detection, paired mutual authentication, and standards-based risk management can provide sufficient security for connected vehicles, as attackers are increasingly coming from paired mobile devices instead of the vehicle itself. 

DOI: https://doi.org/10.17762/ijisae.v12i22s.6520

Downloads

Download data is not yet available.

References

O. Y. Al-Jarrah, C. Maple, M. Dianati, D. Oxtoby, and A. Mouzakitis, “Intrusion detection systems for intra-vehicle networks: A review,” IEEE Access, vol. 7, pp. 21266–21289, 2019.

S. AL-Sultan, M. M. Al-Doori, A. H. Al-Bayatti, and H. Zedan, “A comprehensive survey on vehicular ad hoc network,” J. Netw. Comput. Appl., vol. 37, pp. 380–392, 2014.

G. Bloom, “Anomaly detection approach using adaptive cumulative sum algorithm for controller area network,” in Proc. ACM Workshop Automotive Cybersecurity (AutoSec), 2019, pp. 25–30.

M. Bozdal, M. Samie, and I. K. Jennions, “WINDS: A wavelet-based intrusion detection system for controller area network (CAN),” IEEE Access, vol. 9, pp. 58621–58633, 2021.

C. Busold, A. Taha, C. Wachsmann, A. Dmitrienko, H. Seudié, M. Sobhani, and A.-R. Sadeghi, “Smart keys for cyber-cars: Secure smartphone-based NFC-enabled car immobilizer,” in Proc. 3rd ACM Conf. Data Appl. Security Privacy, 2013, pp. 233–242.

P. F. De Araujo-Filho, A. J. Pinheiro, G. Kaddoum, D. R. Campelo, and F. L. Soares, “An efficient intrusion prevention system for CAN: Hindering cyber-attacks with a low-cost platform,” IEEE Access, vol. 9, pp. 166855–166869, 2021.

A. A. Elkhail, R. U. D. Refat, R. Habre, A. Hafeez, A. Bacha, and H. Malik, “Vehicle security: A survey of security issues and vulnerabilities, malware attacks and defenses,” IEEE Access, vol. 9, pp. 162401–162437, 2021.

C. Gao, G. Wang, W. Shi, Z. Wang, and Y. Chen, “Autonomous driving security: State of the art and challenges,” IEEE Internet Things J., vol. 9, no. 9, pp. 7572–7595, 2022.

G. Gao, S. Meng, and M. V. Wüthrich, “What can we learn from telematics car driving data: A survey,” Insurance: Mathematics and Economics, vol. 104, pp. 185–199, 2022.

S. Gupta, C. Maple, and R. Passerone, “An investigation of cyber-attacks and security mechanisms for connected and autonomous vehicles,” IEEE Access, vol. 11, pp. 90641–90669, 2023.

T. Halabi, O. A. Wahab, R. Al Mallah, and M. Zulkernine, “Protecting the Internet of vehicles against advanced persistent threats: A Bayesian Stackelberg game,” IEEE Trans. Rel., vol. 70, no. 3, pp. 1–16, 2021.

M. D. Hossain, H. Inoue, H. Ochiai, D. Fall, and Y. Kadobayashi, “LSTM-based intrusion detection system for in-vehicle CAN bus communications,” IEEE Access, vol. 8, pp. 185489–185502, 2020.

J. Joy and M. Gerla, “Internet of vehicles and autonomous connected car privacy and security issues,” in Proc. 26th Int. Conf. Comput. Commun. Netw. (ICCCN), 2017, pp. 1–9.

K. Koscher et al., “Experimental security analysis of a modern automobile,” in Proc. IEEE Symp. Security Privacy, 2010, pp. 447–462.

C. Liu, C. Gu, and M. Guizani, “Formal verification for automotive software: A survey on methods and tools,” ACM Comput. Surv., vol. 54, no. 8, pp. 1–30, 2022.

F. Luo, Y. Jiang, Z. Zhang, Y. Ren, and S. Hou, “Threat analysis and risk assessment for connected vehicles: A survey,” Security Commun. Netw., vol. 2021, Art. 1263820, 2021.

S. Mahmood, H. N. Nguyen, and S. A. Shaikh, “Systematic threat assessment and security testing of automotive over-the-air (OTA) updates,” Veh. Commun., vol. 35, Art. 100468, 2022.

E. H. Nurkifli and T. Hwang, “Provably secure authentication for the Internet of vehicles,” J. King Saud Univ. Comput. Inf. Sci., vol. 35, no. 8, Art. 101721, 2023.

G. Rathee, A. Sharma, R. Iqbal, M. Aloqaily, N. Jaglan, and R. Kumar, “A blockchain framework for securing connected and autonomous vehicles,” Sensors, vol. 19, no. 14, Art. 3165, 2019.

V. Renganathan, E. Yurtsever, Q. Ahmed, and A. Yener, “Valet attack on privacy: A cybersecurity threat in automotive Bluetooth infotainment systems,” Cybersecurity, vol. 5, no. 1, Art. 30, 2022.

F. Sommer, R. Kriesten, and F. Kargl, “Survey of model-based security testing approaches in the automotive domain,” IEEE Access, vol. 11, pp. 55474–55514, 2023.

H. Sun, M. Chen, J. Weng, Z. Liu, and G. Geng, “Anomaly detection for in-vehicle network using CNN-LSTM with attention mechanism,” IEEE Trans. Veh. Technol., vol. 70, no. 10, pp. 10880–10893, 2021.

R. W. van der Heijden and E. Haber, “Policy and regulation for cyber-physical vehicle systems: State of the art and future directions,” Transp. Res. Part A, vol. 136, pp. 252–266, 2020.

A. Weimerskirch and M. Wolf, “Automotive cybersecurity: Review and outlook on ISO/SAE 21434,” SAE Int. J. Transp. Cybersecurity Privacy, vol. 4, no. 2, pp. 75–83, 2021.

Y. Xun, Y. Zhao, and J. Liu, “VehicleEIDS: A novel external intrusion detection system based on vehicle voltage signals,” IEEE Internet Things J., vol. 9, no. 3, pp. 2124–2133, 2021.

L. Yang, A. Moubayed, and A. Shami, “MTH-IDS: A multitiered hybrid intrusion detection system for Internet of Vehicles,” IEEE Internet Things J., vol. 9, no. 1, pp. 616–632, 2022.

C. Young, J. Zambreno, H. Olufowobi, and G. Bloom, “Survey of automotive controller area network intrusion detection systems,” IEEE Design Test, vol. 36, no. 6, pp. 48–55, 2019.

Downloads

Published

24.07.2024

How to Cite

Ruturajsinh Kiritsinh Jadeja. (2024). Secure Mobile Platforms for Connected Vehicle Ecosystems: A Synthesis of Threats, Detection, and Governance. International Journal of Intelligent Systems and Applications in Engineering, 12(22s), 554–562. Retrieved from https://ijisae.org/index.php/IJISAE/article/view/6520

Issue

Section

Research Article