Browse Topic: Vehicle networking

Items (633)
The emergence of AI-driven autonomy in modern vehicles marks a pivotal evolution in transportation, but it also introduces deep system-level vulnerabilities that span from sensor interface tampering to compute unit compromise and untrusted communication links. Autonomous vehicles (AVs) operate as distributed intelligent systems, relying on real-time data exchange between zonal gateways, AI compute platforms, and safety-critical electronic control units (ECUs). These interactions must be protected from hardware-based attacks that could compromise functional safety, system integrity, or operational availability. The deployment of AI-driven AVs introduces unprecedented levels of complexity. Sensors, AI compute clusters, and actuators communicate over multiple interfaces including Ethernet, PCIe, and MIPI, exposing vehicles to potential cybersecurity attacks. This paper proposes a unified, layered hardware security architecture tailored for AI-powered automated vehicles. Grounded in current automotive Ethernet and zonal architectures, it provides end-to-end trust using hardware interface security, accelerated- cryptography, and SRAM PUF-based key provisioning. All security primitives are anchored to hardware root of trust, delivering cryptographic identity, secure boot enforcement, and trusted key storage across the entire vehicle lifecycle.
C Suriyanarayanan, PavIacob, Radu
The objective of this paper is to understand the effort required to integrate the hardware and software of in-vehicle cybersecurity systems. The in-vehicle cybersecurity method discussed is the SAE J1939-91C, which involves Network formation, Rekeying, and secure Message Exchange between Electronic Control Units (ECUs). The SAE J1939-91C network security protocol operates over a CAN-FD network to perform necessary cryptographic operations and key generation. To evaluate the method, test vectors were created to validate SAE J1939-91C key generations and cryptographic operations on the simulated ECU in-vehicle network system hardware (such as the Beacon or Pi devices). We introduce a lightweight, transport-agnostic benchmark comprising deterministic AES-CMAC test vectors and a simple verification utility, requiring no specialized hardware or build system. This minimal artifact set enables reproducible and machine-parsable validation of SAE J1939-91C security across diverse lab environments.
Zachos, MarkMedam, Krishna Teja
Microchip Technology and Hyundai Motor Group recently announced a collaboration to test 10BASE-T1S Single Pair Ethernet (SPE) technology for advanced in-vehicle networks to provide improved ADAS and connected-vehicle features. HMG told SAE Media it is working with multiple technology partners to review the overall applicability of 10BASE-T1S technology and hopes 10BASE-T1S can help optimize the deployment of gateways and switches. The technology's ethernet-based networking concepts might also contribute to simplifying network design and implementation for future zonal architectures. We also spoke with Matthias Kaestner, corporate vice president of Microchip Technology's data center, networking and automotive business units, about the partnership, via email.
Blanco, Sebastian
Modern vehicles require sophisticated, secure communication systems to handle the growing complexity of automotive technology. As in-vehicle networks become more integrated with external wireless services, they face increasing cybersecurity vulnerabilities. This paper introduces a specialized Proxy based security architecture designed specifically for Internet Protocol (IP) based communication within vehicles. The framework utilizes proxy servers as security gatekeepers that mediate data exchanges between Electronic Control Units (ECUs) and outside networks. At its foundation, this architecture implements comprehensive traffic management capabilities including filtering, validation, and encryption to ensure only legitimate data traverses the vehicle's internal systems. By embedding proxies within the automotive middleware layer, the framework enables advanced protective measures such as intrusion detection systems, granular access controls, and protected over-the-air (OTA) update channels. This strategy enhances both data security and system isolation, creating protective boundaries between critical vehicle operations and potential external attacks. The architecture particularly excels in supporting Vehicle-to-Everything (V2X) connectivity, facilitating seamless information exchange between vehicles, roadside infrastructure, and pedestrians. This capability is essential for enhancing roadway safety, optimizing traffic flow, and supporting autonomous driving technologies. The system incorporates dedicated proxy modules for specialized protocols including Trivial File Transfer Protocol (TFTP), Diagnostic Over Internet Protocol (Doip), and Message Queuing Telemetry Transport (MQTT), each fulfilling specific functions in vehicle diagnostics, software updates, and telemetry data management. Performance evaluations will measure latency and throughput metrics to validate the architecture's efficiency and reliability. The framework's modular design aims to provide scalability and adaptability to accommodate both technological advancements and emerging security challenges. The proxy-based security framework presented offers a holistic and forward-looking approach to safeguarding in-vehicle networks. It provides automotive manufacturers with the tools to develop connected vehicles that combine intelligence and efficiency with robust protection against diverse cybersecurity threats.
M, ArvindPraneetha, Appana DurgaRemalli, Ravi Teja
The invention tackles the main drawback of traditional electric vehicle charge ports which use Vehicle Control Unit (VCU) communication intensively and tend to have separate actuators to fulfill the locking function and requirements. These existing systems do not only limit autonomous operation of the charging lid in ignition-off condition but they also add mechanical complexity and packaging space, as well. To overcome these limitations, this research work introduces a Smart Charge Port Housing (CPH), which combines a rotary actuator with an onboard microcontroller and single shaft self-locking device, which allows intelligent and autonomous control of the flaps without relying on vehicle wide control networks. The actuator can remember the last position that the charging lid was in so it can be operated even while the VCU is in the inactive state. The integrated self-locking functionality is achieved by using a specially designed hinge shaft that allows a certain free play for rotation of the shaft at a specific angular range allowing the lock-unlocking functionality to be performed without any extra actuators. Various use cases supported by the system are manual close, auto-close with anti-pinch detection and LIN-based communication (only during the ignition on and VCU active states), IP69 sealing, laser-welded joints. Improved waterproofing features allow the charging bowl to handle the unfavorable environmental conditions. This solution provides a considerable upgrade in user experience, security, and design integration of modern EV cars because of the blend of mechanical reliability and intelligence incorporated in the control architecture. The architecture is scalable, space-efficient and can be used on next generation of electric vehicle platforms requiring both a functional and aesthetic step change in the user accessible charging systems.
Mohunta, SanjayKhadake, Sagar
With the increasing connectivity of modern vehicles, cybersecurity threats have become a critical concern. Intrusion Detection Systems (IDS) play a vital role in securing in-vehicle networks and embedded vehicle computers from malicious attacks. This presentation shares about an IDS framework designed specifically for POSIX-based operating systems used in vehicle computers, leveraging system-level monitoring, anomaly detection, and signature-based methods to identify potential security breaches. The proposed IDS integrates lightweight behavioral analysis to ensure minimal computational overhead while effectively detecting unauthorized access, privilege escalation, communication interface monitoring etc. By employing a combination of rule-based and OS datapoints, the system enhances threat detection accuracy without compromising real-time performance. Practical series deployments demonstrate the effectiveness of this approach in mitigating cyber threats in automotive environments, ensuring safer and more resilient vehicle systems.
Shukla, SiddharthChatterjee lng, Avik
The rapid adoption of connected vehicle technologies and advanced driver assistance systems (ADAS) necessitates robust security mechanisms capable of identifying and mitigating sophisticated cyber threats in real-time. Traditional signature-based intrusion detection systems (IDS) are often inadequate in addressing the dynamic and evolving nature of automotive cybersecurity threats, particularly in modern vehicle networks like Controller Area Network (CAN), CAN with Flexible Data-Rate (CAN-FD), and Automotive Ethernet. This research introduces a novel Real-time Intrusion Detection System utilizing advanced Machine Learning (ML) techniques designed specifically for automotive network environments. The proposed IDS framework employs supervised and unsupervised ML algorithms, including anomaly detection, behavioral analytics, and predictive threat modeling, to achieve high accuracy and rapid threat identification capabilities. Through extensive testing in simulated and actual vehicle network scenarios, the developed IDS model demonstrates significant improvements over conventional detection methods, notably in precision, recall, detection latency, and adaptability to zero-day threats. This research further evaluates the proposed system’s alignment with critical regulatory standards such as AIS 189 and UNECE WP.29, ensuring its practical applicability within automotive industry cybersecurity compliance frameworks. The findings highlight the potential for ML-driven IDS solutions to substantially enhance automotive cybersecurity posture, providing OEMs and stakeholders with actionable insights for proactive threat management.
Chaudhary lng, VikashDesai, ManojChatterjee, Avik
The rapid evolution of in-vehicle electronic systems toward zonal based architectures introduces a new layer of complexity in automotive diagnostics. Traditional architectures, built on Controller Area Network (CAN) and Local Interconnect Network (LIN) protocols, operate on a uniform Real-Time Operating System (RTOS), enabling simplified and consistent diagnostic workflows across Electronic Control Units (ECUs). However, next-generation platforms must accommodate diverse communication protocols (e.g., CAN, LIN, DoIP, SOME/IP) and heterogeneous operating systems (e.g., RTOS, Linux, QNX), resulting in fragmented and inflexible diagnostic processes. This paper presents a Diagnostic controller that addresses these challenges by enabling unified, scalable, and adaptive diagnostic capabilities across modern vehicle platforms. The proposed system consolidates protocol handling at the application level, abstracts diagnostic complexities, and allows cross-platform communication through hypervisor-based services. Diagnostic configurations are decoupled from static software builds and delivered dynamically as configuration files, supporting real-time adaptability to software updates and Over-The-Air (OTA) changes. This architecture also facilitates seamless interoperability across operating systems and enables service-based diagnostics in line with the industry’s move toward software-defined vehicles. The result is a robust, future-ready diagnostic solution optimized for high software variability, platform heterogeneity, and increasing system complexity in modern automotive ecosystems.
Mukherjee, SoumyadeepRaman, Kothanda
This technology solves a long-standing ergonomic and aesthetic problem in automotive and consumer interface design, as the use of mechanical switches disrupts the clean look of modern interiors and tends to attract dust and wear. Currently available technologies, such as capacitive touch buttons and mechanical push switches, do not provide the corresponding tactile feedback or clear indication of touch, and usually contain visible openings that interrupt the design flow. Moreover, traditional switches are made up of multiple built-in components, which results in complicated construction and difficult maintenance. To address these drawbacks, we propose a Seamlessly Integrated, Selectively Elevated Fabric Switch that remains flush with the surface when not in use and automatically rises to form a tactile interface when required. The system is a multi-layer construction consisting of an outer fabric upholstery layer, a tactile actuation membrane, and a smart electromagnetic actuator layer. Permanent magnets and electromagnets are used in combination in the system so that they repel the switch surface upward when necessary. The actuation sequence is triggered through proximity sensing or capacitive detection mechanisms, thus eliminating the necessity for responsive and user-friendly interfaces without sacrificing mechanical functionality. To ensure safe and deliberate interaction, the switch is designed not to be eligible for activation until the total thickness of the fabric and tactile layers reaches a predetermined threshold. The system is appropriate for smart appliances, next-generation user interface systems, and car interiors because it is not only conceptually elegant, which improves aesthetic integration, but it is also robust, dustproof, and easy to use. This invention sets a new standard for intelligent, adaptive user interfaces and supports upcoming advancements like haptic feedback and programmable elevation zones.
Mohunta, SanjayPanchal, GirishPuthran, Shaunak
The efficient tracking and management of goods within light commercial vehicles (LCVs) is crucial for various industries, particularly craftsmen and parcel delivery services. This article explores the integration of artificial intelligence (AI) and sensor technologies to enhance item tracking and optimize logistical operations in LCVs. Two technological approaches are examined: a Bluetooth-based tracking system and a camera-based parcel identification framework. The Bluetooth-based solution is designed primarily for craftsmen. It employs Bluetooth tags, vehicle connectivity gateways (VCGs), and a centralized server to provide real-time inventory monitoring and prevent tool misplacement. The camera-based system is aimed at parcel carriers. It utilizes AI-driven object detection and pose estimation to localize and identify parcels within the vehicle. Experimental evaluations show that Bluetooth tracking ensures reliability in tool management and the AI-based vision system holds promise for future scalability in parcel logistics. The findings underscore the need for adaptive tracking methodologies to improve efficiency, reduce operational costs, and support the digital transformation of commercial vehicle ecosystems.
Aslandere, TurgayLens, MathijsKirchhof, Jörg ChristianRobberechts, PieterGrein, MarcelMeert, WannesVandewalle, PatrickDavis, JesseRumpe, BernhardGoedemé, Toon
With the rapid development of Internet of Vehicles (IoV) and cyber-physical systems (CPS), connected autonomous vehicles (CAVs) have also developed rapidly. However, at the same time, in-vehicle networks also face more security challenges, mainly in terms of resource constraints, dynamic attacks, protocol heterogeneity, and high real-time requirements. Firstly, the trade-offs between lightweight encryption primitives and their software and hardware collaborative design in terms of performance, resource overhead, and security strength are analyzed. Secondly, the resource efficiency of AI-based intrusion detection system (IDS) is evaluated at the edge. Finally, we propose a dynamic adaptive collaborative defense framework (DACDF), which integrates federated learning with dynamic weight distillation, blockchain authentication with lightweight verifiable delay function (Light-VDF) and cross-domain IDS with hierarchical attention feature fusion to deal with collaborative attacks in resource-constrained environments. At the same time, we also identify future research directions, including the migration path of quantum-resistant cryptography (PQC) and the application challenges of explainable AI (XAI) in security-critical authentication.
Zhou, YouZhang, JiguiDing, KaniYang, Guozhi
TOC
Tobolski, Sue
In view of the contradiction between the best engine monomer performance and the poor vehicle performance existing energy management strategies, the objective of this study is to leverage deep reinforcement learning to incorporate the thermal characteristics of the engine into the optimization process of energy management strategies, thereby enhancing fuel economy under real-world vehicle operating conditions. Combining the real-time road condition information provided by the vehicle network system, the state space and action space are formulated based on the Soft Actor-Critic (SAC) reinforcement learning algorithm, taking into account energy power and engine cooling constraints, while a generalized reward function design methodology is proposed. Based on bench test data, this paper establishes a series hybrid electric vehicle model with integrated engine thermal characteristics, and validates the effectiveness of the algorithm under actual road conditions by using the engine bench test. The results show that the proposed control strategy can improve fuel economy by more than 3.4% under -10°C environment compared with the traditional SAC enhanced learning energy management strategy without considering engine thermal characteristics. Fuel economy can be improved by more than 4.0% compared to rule-based energy management strategies.
Fu, WeiqiLei, NuoZhang, Hao
Ongoing research and development in the field of electric vehicles (EVs) have resulted in a continuous expansion of their range. Additionally, advancements in vehicle connectivity have created new opportunities for intelligent driving assistance and energy optimization, particularly through the use of cloud data. However, the integration of eco-driving assistance with numerical optimization of speed trajectories remains challenging due to the high computational demands of these methods. To address this challenge and make such a system feasible for integration into vehicle systems, the computational effort required for an optimized driving trajectory must be minimized. This paper presents a method to accelerate speed trajectory optimization using pre-calculated energy and time consumption maps. For this purpose, a dynamic discretization of the anticipated driving profile is applied. Initial results show a substantial reduction in computation time, varying with different scenarios. Furthermore, trajectory optimizations have led to energy consumption reductions between 5% and 30% in simulation trials. The structure of this paper is as follows: First, the vehicle model, implemented in MATLAB/Simulink, and the longitudinal dynamics, with a focus on key components, are explained. Next, the numerical optimization implementation using Dynamic Programming, the Ford-Bellman Algorithm, and the necessary discretization of the driving profile to be optimized are described. This is followed by an explanation of the hybrid energy consumption calculation. Then, the functional implementation of the algorithm in MATLAB pseudocode is presented. Various optimized driving trajectories for a predefined route are then generated with the optimizer, and the simulation results are analyzed, including the computational effort required for optimization. Finally, the results are summarized, and an outlook on the optimizer’s potential future applications is provided.
Schilling Johnson, ReneHenke, Markus
IEEE-1394b, Interface Requirements for Military and Aerospace Vehicle Applications, establishes the requirements for the use of IEEE Std 1394™-2008 as a data bus network in military and aerospace vehicles. The portion of IEEE Std 1394™-2008 standard used by AS5643 is referred to as IEEE-1394 Beta (formerly referred to as IEEE-1394b.) It defines the concept of operations and information flow on the network. As discussed in 1.4, this specification contains extensions/restrictions to “off-the-shelf” IEEE-1394 standards and assumes the reader already has a working knowledge of IEEE-1394. This document is referred to as the “base” specification, containing the generic requirements that specify data bus characteristics, data formats, and node operation. It is important to note that this specification is not designed to be stand-alone; several requirements leave the details to the implementations and delegate the actual implementation to be specified by the network architect/integrator for a particular vehicle application. This information is typically contained in a “network profile” slash sheet that is compliant with this base specification. In a similar manner, the electrical characteristics of the bus media, as well as connector information, is contained in a “physical layer” slash sheet that also may be unique to a particular vehicle application. In summary, full understanding of this specification requires knowledge of IEEE Std 1394™-2008 standards and access to the physical layer slash sheets, slash sheets, and handbook for the target application.
AS-1A Avionic Networks Committee
This document was prepared by the SAE AS-1A2 Committee to establish techniques for validating the Network Terminal (NT) complies with the NT requirements specified in AS5653, Revision B. Note that this verification document only verifies the specific requirements from AS5653 and does not verify all the requirements invoked by documents that are referenced by AS5653. The procuring authority may require further testing to verify the requirements not explicitly defined in AS5653 and in this verification document.
AS-1A Avionic Networks Committee
This document was prepared by the SAE AS-1A2 Committee to establish techniques for verifying that Network Controllers (NCs), Network Terminals (NTs), switches, cables, and connectors comply with the physical layer requirements specified in AS5653B. Note that this verification document only verifies the specific requirements from AS5653B and does not verify all of the requirements invoked by documents that are referenced by AS5653B. The procuring authority may require further testing to verify the requirements not explicitly defined in AS5653B and in this verification document.
AS-1A Avionic Networks Committee
This document establishes test plans/procedures for the AS5643 Standard that by itself defines guidelines for the use of IEEE-1394b as a data bus network in military and aerospace vehicles. This test specification defines procedures and criteria for testing device compliance with the AS5643 Standard.
AS-1A Avionic Networks Committee
The trends of intelligence and connectivity are continuously driving innovation in automotive technology. With the deployment of more safety-critical applications, the demand for communication reliability in in-vehicle networks (IVNs) has increased significantly. As a result, Time-Sensitive Networking (TSN) standards have been adopted in the automotive domain to ensure highly reliable and real-time data transmission. IEEE 802.1CB is one of the TSN standards that proposes a Frame Replication and Elimination for Reliability (FRER) mechanism. With FRER, streams requiring reliable transmission are duplicated and sent over disjoint paths in the network. FRER enhances reliability without sacrificing real-time data transmission through redundancy in both temporal and spatial dimensions, in contrast to the acknowledgment and retransmission mechanisms used in traditional Ethernet. However, previous studies have demonstrated that, under specific conditions, FRER can lead to traffic bursts and out-of-order, which are intolerable for safety-critical applications. Current research has analyzed the causes of traffic bursts and out-of-order delivery, but effective preventive solutions have yet to be proposed. To address these issues, this paper first employs a formal method to demonstrate that intermittent streams cannot satisfy the conditions for generating traffic bursts and out-of-order delivery. Subsequently, a novel intermittent stream constraint is proposed and basic constraints for time-aware shaper (TAS) are extended to support redundant communication. Finally, a TAS-based method is implemented, which ensures that traffic is shaped into intermittent streams when FRER is used. Simulation results in OMNET++ indicate that the TAS-based method proposed effectively avoids traffic bursts and out-of-order issues after recovery from link failures.
Luo, FengRen, YiZhu, YianWang, ZitongGuo, YiYang, Zhenyu
SAE J1939 is a CAN-based standard used for connecting various ECUs together within a vehicle. There are also some related protocols sharing many of the features of SAE J1939 across other industries including ISO11783, RVC and NMEA 2000. The standard has enabled the easy integration of electronic devices into a vehicle. However, as with all CAN-based protocols, several vulnerabilities to cyberattacks have been identified and are discussed in this paper. Many are at the CAN-level, whilst others are in common with those protocols from the SAE J1939 family of protocols. This paper reviews the known vulnerabilities that have been identified with the SAE J1939 protocol at CAN and J1939-levels, along with proposed mitigation strategies that can be implemented in software. At the CAN-level, the weaknesses include ways to spoof the network by exploiting parts of the protocol. Denial of Service is also possible at the CAN-level. At the SAE J1939-level, weaknesses include Denial of Service type attacks, exploiting the transport protocol and address claim features, and leaving the ECU inoperable. Finally, the implementation of covert communication channels using methods based on steganography is discussed. It is highlighted how this can be used as a means of attack and also as a means to protect a network.
Quigley, Christopher
This document provides recommendations to vehicle manufacturers, ECU developers, and other device suppliers in securing the SAE J1939 network from cybersecurity risks. This document focuses on security measures related to on-vehicle network architecture and security measures for communication interfaces between devices, ECUs, or networks. The focus is on security related to network communications on the vehicle side of off-vehicle interfaces, such as the SAE J1939-13 connector. The recommendations in this document aim to address cybersecurity risks presented by communication between the vehicle and the rest of the supporting ecosystem via the vehicle networks. The risk focus is on safety and operational risks, although other risks are possible. This document should be used as a reference to current best practices for addressing off-vehicle communication security. This document focuses on recommendations related to the Secure Architecture and Secure Connectivity aspects of vehicle security; it is the first in a family of security-related documents. Recommendations for secure on-board communications between ECUs and any other on-vehicle device will be defined in another document. While Secure ECU is out of scope for this document, this document does include some Secure ECU recommendations only to the extent needed to support the recommendations of topics that are in scope. Some of the described guidelines and measures described in this document include: Overview of the SAE J1939 layered security model Secure Architecture ○ Domain Separation ○ Vehicle Messaging Matrix (VMM) to document all network messaging ○ Multi-level security (MLS) policy, based on VMM, to control message flow between domains Secure Connectivity ○ Gateways and firewalls to isolate on-vehicle networks from off-vehicle networks and control message flow of incoming messages from off-vehicle ○ Firewall-based diagnostic services control ○ ECU-based diagnostic services control An alert service for reporting detected imposter messaging activity It is recognized that not every application of SAE J1939 networks requires the same level of cybersecurity measures. Techniques to determine the level of cybersecurity measures required are out of scope for this document. Generally, higher-risk applications require higher levels of cybersecurity measures. Generally, there are three forms of communication methodologies used in current vehicles: 1 Open access to communication buses – security included inside each networked ECU 2 Communication buses isolated via a gateway – central security interconnect ECU 3 Combinations of (1) and (2) This document provides guidelines for securing communications with any off-board device for vehicles utilizing any of these methodologies.
Truck and Bus Control and Communications Network Committee
The SAE J1939 communications network is developed for use in heavy-duty environments and is suitable for horizontally integrated vehicle industries. The SAE J1939 communications network is applicable for light-duty, medium-duty, and heavy-duty vehicles used on-road or off-road, and for appropriate stationary applications which use vehicle-derived components (e.g., generator sets). Vehicles of interest include, but are not limited to, on-highway and off-highway trucks and their trailers, construction equipment, and agricultural equipment and implements. SAE J1939-71 is the SAE J1939 reference document describing SAE J1939 parameter (SP) and message (PG) definitions, SLOT (standard data encoding) definitions, conventions and notations used to specify the parameter (SP) placement in PG data, conventions for text data parameters, and conventions for PG transmission rates. This document previously contained the majority of the SAE J1939 OSI application layer data parameters and messages for information exchange between the ECU applications connected to the SAE J1939 communications network. It also contained reference figures and reference information. The data parameters (SPs), messages (PGs), reference figures, and information previously published within this document are now published in SAE J1939DA. There are several SAE J1939-7X documents that collectively define all of the SAE J1939 application layer data parameters and messages. Diagnostic services and some industry-specific data parameters and messages are documented within other SAE J1939-7X application layer documents. An ECU may simultaneously use and support data parameters and messages from multiple SAE J1939-7X application layer documents.
Truck and Bus Control and Communications Network Committee
The increased connectivity of vehicles expands the attack surface of in-vehicle networks, enabling attackers to infiltrate through external interfaces and inject malicious traffic. These malicious flows often contain anomalous semantic information, potentially leading to misleading control instructions or erroneous decisions. While most semantic-based anomaly detection methods for in-vehicle networks focus on extracting semantic context, they often overlook interactions and associations between multiple semantics, resulting in a high false positive rate (FPR). To address these challenges, the Adaptive Structure Graph Attention Network Model (AS-GAT) is proposed for in-vehicle network anomaly detection. Our approach combines a semantic extractor with a continuously updated graph structure learning method based on attention weight similarity constraints. The semantic extractor identifies semantic features within messages, while the graph structure learning module adaptively updates the graph structure based on attention weights between semantics. This model effectively learns relationships between multiple semantics in in-vehicle network packets, thereby enhancing anomaly detection accuracy. A case study on a CAN-FD dataset from real vehicles demonstrates that using AS-GAT achieves an F1 score of 97.56% in anomaly detection, outperforming baseline methods by effectively identifying attack packets causing abnormal semantic time series changes, such as fuzzing, spoofing, and replay attacks. Additional experiments on two public datasets, SWaT and WADI, further validate AS-GAT’s superior anomaly detection performance compared to baseline models, highlighting the universal applicability of our approach.
Luo, FengLuo, ChengWang, JiajiaLi, Zhihao
Modern vehicles are increasingly integrating electronic control units (ECUs), enhancing their intelligence but also amplifying potential security threats. Vehicle network security testing is crucial for ensuring the safety of passengers and vehicles. ECUs communicate via the in-vehicle network, adhering to the Controller Area Network (CAN) bus protocol. Due to its exposed interfaces, lack of data encryption, and absence of identity authentication, the CAN network is susceptible to exploitation by attackers. Fuzz testing is a critical technique for uncovering vulnerabilities in CAN network. However, existing fuzz testing methods primarily generate message randomly, lacking learning from the data, which results in numerous ineffective test cases, affecting the efficiency of fuzz testing. To improve the effectiveness and specificity of testing, understanding of the CAN message format is essential. However, the communication matrix of CAN messages is proprietary to the Original Equipment Manufacturer (OEM) and varie s among different models of the same vehicle brand, requiring manual reverse analysis of the CAN protocol, which significantly increases the cost and complexity of an attack. To enhance the efficiency of fuzz testing data generation, a fuzz testing data generation algorithm based on Denoising Diffusion Probabilistic Models (DDPMs) is proposed. This method learns the distribution of existing CAN bus message data, enabling the generation of data messages similar to the original data distribution for testing purposes. Furthermore, the LoRA fine-tuning method is introduced to accommodate the differences between communication matrices of various vehicles. Comparative analysis indicates that this method can generate fuzz test messages that more closely resemble real message data than existing methods.
Shen, LinXiu, JiapengZhang, ZhuopengYang, Zhengqiu
Original equipment manufacturers, Tier 1 suppliers, and the rest of the value chain, including the semiconductor industry, are reshaping their product portfolios, development processes, and business models to support this transformation to software-defined vehicles (SDVs). The focus on software is rippling out through the automotive sector, forcing the industry to rethink organization, leadership, processes, and future roadmaps. The Software-defined Vehicle: Its Current Trajectory and Execution Challenges assesses the state of SDVs and explores the potential hurdles to execution and examines the work being done in the industry. The goal is to evaluate whether the implementation of SDVs will encounter the same fate as electrification or autonomous technologies, which after some level of disillusionment, are expected to pick up momentum in a more mature way. Click here to access the full SAE EDGETM Research Report portfolio.
Goswami, Partha
Based on advanced Automotive functionality, Vehicle networks has enabled the exchange of data to multiple domains and to meet these demands, more complex software applications, some of which require service-based cloud are developed. Exposure of data creates multiple threats for attacker to tamper security and privacy. Automotive cybersecurity topic has gained momentum based on multiple gaps identified in Automotive In vehicle and around the vehicle networks. In this paper, we provide an extensive overview on V2C (Vehicle to Cloud) and In-vehicle data protection, we also highlight methods to identify threats on any vehicle network connected to V2C and identify methods to verify security functionality using Fuzz or Penetration test protocol, we have identified gaps in existing security solutions and outline possible open issues and probable solution.
Panda, JyotiprakashJain, Rushabh Deepakchand
This document establishes methods to obtain, store, and access data about the health of a fiber optic network using commercially available inline optical power monitoring sensors. This document is intended for: Managers Engineers Technicians Contracting officers Third party maintenance agencies Quality assurance
AS-3 Fiber Optics and Applied Photonics Committee
With the development of automotive intelligence and networking, the communication architecture of automotive network is evolving toward Ethernet. To improve the real-time performance and reliability of data transmission in traditional Ethernet, time-sensitive network (TSN) has become the development direction of next-generation of automotive networks. The real-time advantage of TSN is based on accurate time synchronization. Therefore, a reliable time synchronization mechanism has become one of the key technologies for the application of automotive Ethernet technology. The protocol used to achieve accurate time synchronization in TSN is IEEE 802.1AS. This protocol defines a time synchronization mechanism suitable for automotive Ethernet. Through the master clock selection algorithm, peer link delay measurement, and clock synchronization and calibration mechanism, the time of each node in the vehicle network is synchronized to a reference master clock. In addition, the protocol clearly states the requirements for node synchronization accuracy in the vehicle network. In this article, it is proposed that an automated test methodology for time synchronization mechanism in the case of multi-device network topology for the IEEE 802.1AS protocol in TSN is applicable to in-vehicle environments. The test methodology automates the process of achieving time synchronization and automatically tests the time synchronization mechanism. In addition, a corresponding test system was designed and developed, and a physical test platform was built to physically test and verify the time synchronization mechanism of the protocol. The results show that the test method proposed can realize the automated testing of the time synchronization mechanism in the case of automotive Ethernet networks. The presented results can contribute to the practical application of automotive TSN technology.
Guo, YiLuo, FengWang, ZitongGan, HaotianWu, MingzhiLiu, Hongqian
The controller area network (CAN) bus, the prevailing standard for in-vehicle networking (IVN), has been used for more than four decades, despite its simple architecture, to establish communications between electronic control units (ECUs). Weight, maintenance overheads, improved flexibility, and wiring complexity escalate as the quantity of ECUs rises, especially for high-demand autonomous vehicles (AVs). The primary objective of this study is to examine and discuss the significant challenges that arise during the migration from a wired CAN to a wireless CAN (WCAN). Suggested remedies include changing the configuration of the conventional ECU, creating a hidden wireless communication domain for each AV, and developing a plan to counteract the jamming signals. The simulation of the proposed WCAN was done using MATLAB and validated using OPNET analysis. The results showed that the packet loss of the eavesdropping electronic control unit ranged from 63% to 100%. Anti-jamming results show that when packet loss reaches 2% for a continuous period of time of 0.01 sec, the passive channel is automatically activated, ensuring secure data transmission.
Ali, ZeinaIbrahim , Qutaiba
Axiomatic AX141155, compact CAN-Bluetooth® Low Energy Converter, is IP67-rated, CE, FCC, and vibration compliant for off-highway. Operate in SAE J1939 interface or CAN (protocol independent) Bridge modes. Power from 12V, 24V or 48Vdc and temperature range from 30 to +85°C. Configure via the Axiomatic CAN2BT app on compatible Apple iOS or Android devices. axiomatic.com
Connected and autonomous vehicles (CAVs) and their productization are a major focus of the automotive and mobility industries as a whole. However, despite significant investments in this technology, CAVs are still at risk of collisions, particularly in unforeseen circumstances or “edge cases.” It is also critical to ensure that redundant environmental data are available to provide additional information for the autonomous driving software stack in case of emergencies. Additionally, vehicle-to-everything (V2X) technologies can be included in discussions on safer autonomous driving design. Recently, there has been a slight increase in interest in the use of responder-to-vehicle (R2V) technology for emergency vehicles, such as ambulances, fire trucks, and police cars. R2V technology allows for the exchange of information between different types of responder vehicles, including CAVs. It can be used in collision avoidance or emergency situations involving CAV responder vehicles. The benefits of R2V are not limited to fully autonomous vehicles (e.g., SAE Level 4), but can also be used in Level 2 CAV scenarios. However, despite the potential benefits of R2V, discussions on this topic are still limited. This chapter aims to provide an overview of R2V technology and its applications for CAV systems, particularly in the context of collision-avoidance features. The responder vehicles in question can be autonomous or non-autonomous. It is hoped that it will provide valuable information and knowledge on vehicle connectivity and automation in the current automotive and mobility ecosystem, enabling the development of safer and more reliable autonomous driving technology. The chapter is intended for both industrial and academic experts and is expected to stimulate further discussions on the development and standardization of R2V technology.
Abdul Hamid, Umar ZakirRoth, ChristianNickerson, JeffreyLyytinen, KalleKing, John Leslie
A new industry-first open platform for developing the software-defined vehicle (SDV) combines processing, vehicle networking and system power management with integrated software. NXP Semiconductors' new S32 CoreRide Platform was designed to run “multiple time-critical, safety-critical, security-critical applications in parallel,” Henri Ardevol, executive vice president and general manager of Automotive Embedded Systems for NXP Semiconductors, told SAE Media. NXP's new foundation platform for SDVs differs from the traditional approach of using multiple electronic control units (ECUs), each designed to handle specific vehicle system control tasks. Since each unit requires its own integration work, the integration workload exponentially increases with each additional ECU on a vehicle.
Buchholz, Kami
Since the early 1990’s, commercial vehicles have suffered from repeated vulnerability exploitations that resulted in a need for improved automotive cybersecurity. This paper outlines the strategies and challenges of implementing an automotive Zero Trust Architecture (ZTA) to secure intra-vehicle networks. Zero Trust (ZT) originated as an Information Technology (IT) principle of “never trust, always verify”; it is the concept that a network must never assume assets can be trusted regardless of their ownership or network location. This research focused on drastically improving security of the cyber-physical vehicle network, with minimal performance impact measured as timing, bandwidth, and processing power. The automotive ZTA was tested using a software-in-the-loop vehicle simulation paired with resource constrained hardware that closely emulated a production vehicle network. For example, the vehicle’s Advanced Gateway electronic control unit (ECU) is utilized to enforce cyber policy, monitor the network, distribute keys, and implement network segmentation. The technical approach applied other security solutions, including Secure Onboard Communication (SecOC) for authentication and verification of network traffic, and Secure Boot to ensure the system is running authentic software. Implementing these elements and the other security controls was complicated by cost, resource constraints, and the complexity of building and maintaining vehicles. The project team identified four metrics to demonstrate performance success and feasibility of the implementation. They are as follows: 1) Error monitoring system detected 100% of illicit messages, 2) ECUs refused unauthorized firmware 100% of the time, 3) ECUs discarded unauthenticated messages 100% of the time, 4) Latency at first ignition cycle was less than one second. This research successfully met the four requirements and demonstrated that using ZT principles in an on-vehicle network greatly improved the cybersecurity posture with manageable impact to system performance and deployment.
Shipman, Maggie E.Millwater, NathanOwens, KyleSmith, Seth
The automotive industry is currently undergoing a significant transformation characterized by technological and commercial trends involving autonomous driving, connectivity, electrification, and shared service. Vehicles are becoming an integral part of a much broader ecosystem. In light of various new developments, the Software-Defined Vehicle (SDV) concept is gaining substantial attention and momentum. SDV emphasizes the central role of software in realizing and enhancing vehicle functions, enriching features, improving performance, adapting to surrounding environment and external conditions, customizing user experience, addressing changing customer needs, and enabling vehicles to dynamically evolve over their entire life cycle. The advancements in vehicle Electrical/Electronic (E/E) architecture and various key technologies serve as the technical foundation for the emergence of SDV. This paper gives a definition of the SDV concept, provides views from different aspects, discusses the progress in vehicle E/E architecture, especially zone-based architecture with centralized computation, and various technologies including High-Performance Computing (HPC) platform, standardized vehicle software architecture, advanced onboard communication, Over-The-Air (OTA) update, and cybersecurity etc. that collectively enable the realization of SDV.
Jiang, Shugang
The NMFTA’s Vehicle Cybersecurity Requirements Woking Group (VCRWG), comprised of fleets, OEMs and cybersecurity experts, has worked the past few years to produce security requirements for Vehicle Network Gateways. Vehicle Network Gateways play an important role in vehicle cybersecurity – they are the component responsible for assuring vehicle network operations in the presence of untrustworthy devices on the aftermarket or diagnostics connectors. This paper offers security requirements for these gateways in design, implementation and operation. The requirements are specified at levels of abstraction applicable to all vehicle networks down to CAN networks specifically. These requirements were captured using the https://github.com/strictdoc-project/strictdoc requirements management tool and will be made available also as a ReqIF format along with the paper at https://github.com/nmfta-repo/vcr-experiment.
Gardiner, BenMaag, JohnTindell, Ken
Inverter is the power electronics component that drives the electrical motor of the electrical driven compressor (EDC) and communicates with the car network. The main function of the inverter is to convert the direct current (DC) voltage of the car battery into alternating current (AC) voltage, which is used to drive the three-phase electric motor. In recent days, inverters are present in all automotive products due to electrification. Inverter contains a printed circuit board (PCB) and electronic components, which are mounted inside a mechanical housing and enclosed by a protective cover. The performance of the electrical drive depends upon the functioning of the inverter. There is a strong demand from the customer to withstand the harsh environmental and testing conditions during its lifetime such as leakage, dust, vibration, thermal tests etc. The failure of the inverter leads to malfunction of the product, hence proper sealing and validation is necessary for inverters to protect the electronic components. Generally, a metallic gasket and rubber gaskets are used as a sealant to protect the electronic components. The influence of design parameters which impact the gasket pressure by selecting the type of screws, number of screws required, minimum distance between the screws and minimum preload required to withstand the thermal conditions are studied and discussed in this paper. The simulation results predict the gasket pressure due to compression, shape of gasket and compressive ratio. The gasket pressure measured from pressure sensitive film test results are well correlated with simulation gasket pressure results. Finally, this robust methodology supports us to virtually validate the gasket design by reducing the number of design iterations and quick evaluation of products.
Duraipandi, Arumuga PandianLeon, RenanRibot, HerveRaja, Antony VinothFarooqui, AltafhussainChandrasekaran, Vinoth-Roy
SAE J1939-82 compliance describes the compliance tests and procedures to verify an SAE J1939 electronic control unit (ECU) operates correctly on a SAE J1939 network. The purpose of these compliance procedures is to generate one or more test documents that outline the tests needed to assure that an ECU that is designed to operate as a node on a SAE J1939 network would do so correctly. SAE does not certify devices and these tests and their results do not constitute endorsement by SAE of any particular ECU. These tests are presented to allow testing of an ECU to determine self-compliance by the manufacturer of an ECU. The manufacturer can use its record of what procedures were run successfully to show the level of compliance with SAE J1939.
Truck and Bus Control and Communications Network Committee
Items per page:
1 – 50 of 633