Protecting Vehicles Against Unauthorised Diagnostics Sessions Using Trusted Third Parties

Pierre Kleberger (Institutionen för data- och informationsteknik, Nätverk och system (Chalmers) ) ; Tomas Olovsson (Institutionen för data- och informationsteknik, Nätverk och system (Chalmers) )
32nd International Conference on Computer Safety, Reliability, and Security (SAFECOMP), Toulouse, 24-27 September 2013 (0302-9743). Vol. Lecture Notes in Computer Science (2013), 8153, p. 70-81.
[Konferensbidrag, refereegranskat]

Wireless vehicle diagnostics is expected to provide great improvements to the maintenance of future cars. By using certificates, vehicles can identify diagnostics equipment for a diagnostics session, even over long distances. However, since the diagnostics equipment contains authentication keys used to authenticate such sessions, it is critical that neither the keys nor the equipment is lost. Such a loss can give unauthorised access to any vehicle accepting these keys until the theft is detected and the certificates are revoked. In this paper, we propose a method to protect vehicles against unauthorised diagnostics sessions. A trusted third party is introduced to authorise sessions, thus we do not rely solely on proper identification and authentication of diagnostics equipment. Our approach enables vehicles to verify the validity of diagnostics requests. It is transparent to the diagnostics protocol being used, supports different levels of trust, and can control what commands are permitted during diagnostics sessions.

Nyckelord: remote diagnostics; connected car; access control; authorisation protocol; trusted third party.

