FOTA信息安全,一篇看不懂的綜述
作者 | 18號線不到安研路
來源 | 十一號組織
該技術在云端生成升級包元數據的簽名,元數據一般包括升級包的摘要和大小,并通過驗證這些元數據來阻止攻擊。TUF允許自由選擇對稱加密、非對稱加密或數字信封等加密方式來加密升級包,并圍繞如下四個關鍵原則進行設計:
TEE可信執行環境
對于當前軟硬件結合的安全趨勢,硬件安全模塊的研究也引起了科研人員的興趣,Idrees等人提出了一種利用硬件安全模塊(HSM)存儲加密密鑰并執行加密操作的協議[6]。HSM 為加密密鑰提供安全存儲,并為加密操作提供安全執行環境。但HSM 的主要缺點是它的總體成本和資源需求較高。類似地,Petri等人提出了一種基于可信平臺模塊(Trusted Platform Module,TPM)的安全軟件更新機制[7]。TPM的架構和啟動順序如下圖所示.
區塊鏈技術在FOTA安全中的應用
參考文獻:
[1] T. K. Kuppusamy, L. A. DeLong and J. Cappos, et al. Uptane: Security and Customizability of Software Updates for Vehicles[J]. IEEE Vehicular Technology Magazine, 2018, 13(1): 66-73.
[2] N. Asokan, T. Nyman, N. Rattanavipanon, et al. ASSURED: Architecture for Secure Software Update of Realistic Embedded Devices[J]. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2018, 37(11):2290-2300.
[3] A. Ghosal, S. Halder, M. Conti. STRIDE: Scalable and Secure Over-The-Air Software Update Scheme for Autonomous Vehicles[C]. ICC 2020-2020 IEEE International Conference on Communications (ICC), 2020, 1-6.
[4] J. Bethencourt, A. Sahai, B. Waters. Ciphertext-Policy Attribute-Based Encryption[C]. IEEE Symposium on Security & Privacy. IEEE, 2007, 321-334.
[5] M. L. Manna, L. Treccozzi, P. Perazzo, et al. Performance Evaluation of Attribute-Based Encryption in Automotive Embedded Platform for Secure Software Over-The-Air Update[J]. Sensors (Basel, Switzerland), 21(2): 515-521.
[6] M. Steger, M. Karner, J. Hillebrand, et al. Generic framework enabling secure and efficient automotive wireless SW updates[C]. 2016 IEEE 21st International Conference on Emerging Technologies and Factory Automation (ETFA), 2016, 1-8.
[7] R. Petri, M. Springer, D. Zelle, et al. Evaluation of lightweight TPMs for automotive software updates over the air[C]. The World's Leading Automotive Cyber Security Conference, 2016, 15.
[8] 趙國開. 基于Trustzone的汽車ECU安全OTA系統設計[J]. 科技創新導報,2019,16(21):94-96. DOI:10.16660/j.cnki.1674-098X.2019.21.094.
[9] M. Baza, M. Nabil, N. Lasla, et al. Blockchain-based Firmware Update Scheme Tailored for Autonomous Vehicles[J]. 2019 IEEE Wireless Communications and Networking Conference (WCNC), 2019, 1-7.
[10] M. Steger, A. Dorri, S. S. Kanhere, et al. Secure Wireless Automotive Software Updates Using Blockchains: A Proof of Concept[C]. Advanced Microsystems for Automotive Applications 2017, 2017, 137-149.
[11] X. He, S. Alqahtani, R. Gamble, et al. Securing Over-The-Air IoT Firmware Updates using Blockchain[C]. the International Conference, 2019, 164-171.
工程師必備
- 項目客服
- 培訓客服
- 平臺客服
TOP




















