Browse Topic: Cryptography
Researchers discover texts, phone calls, military communication, internal corporate networks all easily eavesdropped on using off-the-shelf equipment. University of California San Diego, La Jolla, CA With $800 of off-the-shelf equipment and months' worth of patience, a team of U.S. computer scientists set out to find out how well geostationary satellite communications are encrypted. And what they found was shocking. Close to half of the communications beamed from satellites to the ground that the researchers were able to listen in on were not encrypted. This included sensitive data including cellular text messages, voice calls, as well as sensitive military information, data from internal corporate and bank networks, and the in-flight online activity of airline passengers.
Researchers at the German Aerospace Center recently tested a quantum sensor in-flight on a Dornier 228 research aircraft. German Aerospace Center, Cologne, Germany It is not easy to transmit individual photons precisely from an aircraft, capture them in a ground station and detect them successfully. Researchers have, however, now managed to do exactly that. They have even measured, multiple times, various quantum channels between an aircraft and a ground station, sent photons to an ion trap and tested technologies for quantum key distribution (QKD). The flight experiment in question took place as part of the QuNET initiative, aimed at developing quantum-secure communication. Using photons - particles of light - it is possible to generate quantum encryption keys, which will make future communication eavesdrop-proof. The technologies behind this are also paving the way for a future quantum internet, connecting quantum computers with one another.
Data security remains an issue of the utmost concern in contested environments. Mechanisms such as data encryption, beam-forming antennas, and frequency-hopping radio have emerged to mitigate some of the concerns in radio-frequency (RF) communications, but they do not remove all risk. Consequently, there is still a consistent appetite for alternative solutions. This paper presents a case for the use of the free-space optical (FSO) communications technology ImpLi-Fi as one such alternative. FSO communication is promising because of the ease with which the signal beam may be steered and limited, making detection and interception more difficult than with RF, and ImpLi-Fi in particular is desirable for its exceptional outdoor performance and ease of integration into existing light sources. The paper briefly illustrates the origins of the contested logistics (CL) problem and CL use cases for secure communication channels, before describing the ImpLi-Fi technology in some detail; exploring how its field deployment might look, including a telling example with a handheld transmitter device; and foretelling additional potential areas of application. Throughout the paper, ImpLi-Fi is shown to have remarkably high potential utility in contested logistics and beyond.
The added connectivity and transmission of personal and payment information in electric vehicle (EV) charging technology creates larger attack surfaces and incentives for malicious hackers to act. As EV charging stations are a major and direct user interface in the charging infrastructure, ensuring cybersecurity of the personal and private data transmitted to and from chargers is a key component to the overall security. Researchers at Southwest Research Institute® (SwRI®) evaluated the security of direct current fast charging (DCFC) EV supply equipment (EVSE). Identified vulnerabilities included values such as the MAC addresses of both the EV and EVSE, either sent in plaintext or encrypted with a known algorithm. These values allowed for reprogramming of non-volatile memory of power-line communication (PLC) devices as well as the EV’s parameter information block (PIB). Discovering these values allowed the researchers to access the IPv6 layer on the connection between the EV and EVSE and use traditional ethernet penetration testing methods, including port and vulnerability scanning. Port scanning exposed open SSH and HTTP services, the latter of which was vulnerable and allowed unauthenticated retrieval of proprietary information. The ports should be secured, or closed if unneeded, to prevent this type of vulnerability.
Researchers are leveraging informatics approaches to tackle persistent challenges in data management and sharing, enabling real-world healthcare applications to enhance data security and accessibility.
Cybersecurity, particularly in the automotive sector, is of paramount importance in today’s digital age. With the advent of connected commercial vehicles, which leverage telematics for efficient fleet management, the landscape of automotive cybersecurity is rapidly evolving. These vehicles, integral to logistics and transportation businesses, are becoming increasingly connected, thereby escalating the risks associated with cybersecurity threats. These commercial vehicles are becoming prime targets for cyber-attacks due to their connectivity and the valuable data they hold. The potential consequences of these cyber-attacks can range from data breaches to disruptions in fleet operations, and even safety risks. This paper analyses the unique challenges faced by the commercial vehicle sector, such as the need for robust telematics systems, secure communication channels, and stringent data protection measures. Case studies of notable cybersecurity incidents involving commercial vehicles are presented, providing valuable insights into the modus operandi of cybercriminals. Strategies and best practices to mitigate these risks are proposed, emphasizing the need for secure vehicle architecture and design, intrusion detection systems, and regular OTA updates. The role of employee training programs in enhancing cybersecurity awareness is also highlighted. Emerging trends like AI and machine learning in threat detection, blockchain technology for secure data transmission, and collaborations with ethical hackers for vulnerability assessment are discussed. The paper reviews the current regulatory landscape, stressing the need for international standards specifically for connected commercial vehicles. It concludes with an outlook on anticipated developments in automotive cybersecurity, recommendations for industry stakeholders, and the assertion that prioritizing cybersecurity is crucial for the future of the commercial vehicle industry.
Data encryption is an essential part of keeping patient information private. It’s also remained relatively unchanged in recent decades — a rarity for anything in the cybersecurity space. The dawn of quantum computing will change that.
Aerospace is an industry where competition is high and the need to ensure safety and security while managing costs is foremost. Stakeholders, who gain the most by working together, do not necessarily trust each other. Changing backbone technologies that drive enterprise systems and secure historical records does not happen quickly (if at all). At best, businesses adapt incrementally, building customized applications on top of legacy systems. The complexity of these legacy systems leads to duplication of efforts and data storage, making them very inefficient. Technology that augments, rather than replaces, is needed to transform these complex systems into efficient, digital processes. Blockchain technology offers collaborative opportunities for solving some of the data problems that have long challenged the aerospace industry. The industry has been slow to adopt the technology even though experts agree that it has real potential to revolutionize the global supply chain—including maintenance, repair, and overhaul (MRO)—driving tremendous cost, excess inventory, and inefficiencies out of the system. This chapter discusses how the adoption of blockchain technology could have a significant impact on the aerospace industry and addresses some of the unsettled concerns surrounding the implementation of the technology.
The University of Detroit Mercy Vehicle Cyber Engineering (VCE) Laboratory together with The University of Arizona is supporting Secure Vehicle Embedded Systems research work and course projects. The University of Detroit Mercy VCE Laboratory has established several testbeds to cover experimental techniques to ensure the security of an embedded design that includes: data isolation, memory protection, virtual memory, secure scheduling, access control and capabilities, hypervisors and system virtualization, input/output virtualization, embedded cryptography implementation, authentication and access control, hacking techniques, malware, trusted computing, intrusion detection systems, cryptography, programming security and secure software/firmware updates. The VCE Laboratory testbeds are connected with an Amazon Web Services (AWS) cloud-based Cyber-security Labs as a Service (CLaaS) system, which allows students and researchers to access the testbeds from any place that has a secure internet connection. VCE students are assigned predefined virtual machines to perform designated cyber-security experiments. The CLaaS system has low administrative overhead associated with experiment setup and management. One of the testbeds in the VCE Lab is the TestCube vehicle simulator device. The TestCube is a programmable OBD-II vehicle gateway that can operate as an entire vehicle that is running on-board diagnostics communications sequences. VCE Laboratory CLaaS experiments have been developed for demonstrating man-in-the-middle cyber-security attacks from actual compromised hardware or software connected with the TestCube. This paper will describe the CLaaS system and experiments utilizing the TestCube testbed. In addition, we will show that the data transfer latency between experiments running on the VCE Laboratory testbed and the AWS Virtual Private Cloud (VPC) is a sustainable communication rate for operating the testbed. It is also worth noting that the CLaaS vehicle diagnostics security system testbed could be extended for use in applications to support a vehicle digital twin platform.
More than half a century has passed since the birth of quantum signal detection theory, which is the cornerstone of modern quantum communication theory. Quantum stream cipher, the quantum-noise-based direct encryption scheme for optical communications at the center of our research, is based on the foundations of quantum communication theory. For quantum cryptography to progress from a theoretical possibility to a more realistic technology, experimental and theoretical research must be complementary.
The new generation vehicles these days are managed by networked controllers. A large portion of the networks is planned with more security which has recently roused researchers to exhibit various attacks against the system. This paper talks about the liabilities of the Controller Area Network (CAN) inside In-vehicle communication protocol and a few potentials that could take due advantage of it. Moreover, this paper presents a few security measures proposed in the present examination status to defeat the attacks. In any case, the fundamental objective of this paper is to feature a comprehensive methodology known as Intrusion Detection System (IDS), which has been a significant device in getting network data in systems over many years. To the best of our insight, there is no recorded writing on a through outline of IDS execution explicitly in the CAN transport network system. Therefore, we proposed a top-down examination of IDS through a write-up based on the following perspectives: Detection draws near, Organization systems, going after methods, and technical challenges. Likewise, it has additionally arranged the abnormality-based IDS as per the strategies stated below, i.e. Frequency-based, AI-based, measurable-based, and statistical-based strategies as a component.
CAN bus network proved to be efficient and dynamic for small compact cars as well as heavy-duty vehicles (HDV). However, HDVs are more susceptible to malicious attacks due to lack of security in their intra-vehicle communication protocols. SAE proposed a new standard named J1939-91C for CAN-FD networks which provides methods for establishing trust and securing mutual messages with optional encryption. J1939-91C ensures message authenticity, integrity, and confidentiality by implementing complex cryptographic operations including hash functions and random key generation. In this paper, the three main phases of J1939-91C, i.e., Network Formation, Rekeying, and Message Exchange, are simulated and tested on Electronic Control Units (ECUs) supporting CAN-FD network. Numerous test vectors were generated and validated to support SAE J1939-91C. The mentioned vectors were produced by simulating different encryption and hashing algorithms with variable message and key lengths. Moreover, the output vectors of each phase were passed to the subsequent phase to build up a complete scenario. The obtained simulation results will be used in the future for assessing the benefits of the standard as well as identifying potential strengths or possible shortcomings of the new protocol and to help suggest recommended enhancements and modifications.
ABSTRACT Currently there is no method to ensure that the software loaded on a vehicle has been compromised at the software level. Common practice is to use physical port security to secure all network and data bus connection points with physical devices requiring tool, keys, or damage to tamper evident devices to prevent, inhibit, or discourage unauthorized connection; turn off access to the ports in the BIOS and password protect the BIOS. As well as give non-admin access to user accounts and password protect the operating systems. All these countermeasures help to prevent access but there is no way to tell if the software was compromised if not detected by these methods. Blockchain technology ensures that the software has not been compromised by comparing a hash generated at start up and comparing it to the distributed ledger. This technology helps to bring Warfighter technology into the future.
The global big data market had a revenue of $162.6 billion in 2021.1 Data is becoming more valuable to companies than gold. However, this data has been used, historically, without contributors’ informed consent and without them seeing a penny from the discoveries the data led to. This article discusses how non-fungible tokens (NFTs) can provide a helpful tool for pharmaceutical companies to track contributed data and compensate contributors accordingly. NFTs are unique, untradable cryptographic assets that can be tracked on a blockchain. NFTs provide a unique traceable token that cannot be replicated, providing a perfect tool to store biodata. The term biodata refers to details regarding a patient’s history and behavioral patterns.
A powerful new generation of test and sim solutions aims to address specific security concerns associated with automotive designs. Today's vehicle is a mobile computer growing in complexity. From infotainment systems to propulsion, to advanced driver assistance systems (ADAS) and autonomous vehicles (AV), computers now drive how automobiles and trucks are designed, how they operate and how they're increasingly connected. For that reason, the transformation of vehicles, roadways and cities has created new design considerations for engineers. One aspect that can't be overlooked is cybersecurity and the need for an all-encompassing approach to ensure vehicle safety. A 2019 study conducted by SAE International (in conjunction with Synopsis) highlights the level of angst around securing the advanced technologies designed into automobiles. Eighty-four percent (84%) of survey respondents are concerned that cybersecurity practices are not keeping up with the security landscape. As worrisome, 63% of survey respondents admitted they test less than half of hardware, software and other technologies for security vulnerabilities.
Members of the electric vehicle industry gathered at the National Renewable Energy Laboratory (NREL) in early April to evaluate enhanced cybersecurity for the connections between EVs and charging infrastructure. As more EVs enter the market and connect to the electrical grid, potentially exposing cyber vulnerabilities, vehicle security is drawing increased interest. The collaborative event supports a two-year project led by SAE International to strengthen EV cybersecurity through wide industry engagement on pre-competitive research and technology prototyping in the EV charging space. The event, held at NREL's Golden, Colorado Energy Systems Integration Facility, was organized to evaluate the application of public key infrastructure (PKI) - a method for encrypting information exchange and certifying the trusted authenticity of devices - to help protect the connection between vehicles and charging stations. Although PKI had been adopted for many industries, this kind of authentication between different companies' electric vehicles and charging stations is not commonplace nor has it matured in the EV charging ecosystem.
The critical role of spectrum superiority in the success of battlefield campaigns is evidenced by the enormous investments being made in electronic warfare (EW) capabilities by governments worldwide. Communication technologies, such as 5G, are quickly being adopted by militaries in an attempt to satisfy the demand for exponentially larger amounts of data transmission in a shorter period of time. As quickly as secure communication strategies are being developed to encrypt mission critical data, so too are the technologies used to detect, decode, and disrupt such communications. The security and integrity of critical communications is of the utmost importance as the world progresses towards an increasingly networked theater of operations. The militaries of the world appear to be in widespread agreement that the critical communication infrastructure of tomorrow's battlefields need to be: Rapidly deployable and reconfigurable for mission readiness. Designed for minimal spectral footprint to minimize risk of detection. Secure against spectral manipulation tactics and immune to remote disruption. Ruggedized to survive harsh environment deployment, but small enough in form factor to enable maximum mobility. Open-source and future-proof to enable the seamless integration of next-generation systems and technologies.
The critical role of spectrum superiority in the success of battlefield campaigns is evidenced by the enormous investments being made in electronic warfare (EW) capabilities by governments worldwide. Communication technologies, such as 5G, are quickly being adopted by militaries in an attempt to satisfy the demand for exponentially larger amounts of data transmission in a shorter period of time. As quickly as secure communication strategies are being developed to encrypt mission critical data, so too are the technologies used to detect, decode, and disrupt such communications. The security and integrity of critical communications is of the utmost importance as the world progresses towards an increasingly networked theater of operations.
Security in encrypted communication is a top priority because of our highly connected and mobile society’s increasing reliance on the internet. Engineers at Department of Electrical Engineering and Computer Science and the Research Laboratory of Electronics, MIT, have developed a new protocol for high-speed communication between two parties with security vouchsafed by the laws of quantum physics. The protocol can also be used to distribute cryptographic keys, as in quantum key distribution (QKD) at much higher secure key rates than existing QKD methods.
Curtiss-Wright Defense Solutions Ashburn, VA 703-779-7800
To help address the issue of message authentication on the Controller Area Network (CAN) bus, researchers at Virginia Tech and Ford Motor Company have developed a proof-of-concept time-evolving watermark-based authentication mechanism that offers robust, cryptographically controlled confirmation of a CAN message's authenticity. This watermark is injected as a common-mode signal on both CAN-HI and CAN-LO bus voltages and has been proven using a low-cost software-defined radio (SDR) testbed. This paper extends prior analysis on the design and proof-of-concept to consider robustness testing over the range of voltages, both steady state drifts and transients, as are commonly witnessed within a vehicle. Overall performance results, along with a dynamic watermark amplitude control, validate the concept as being a practical near-term approach at improving authentication confidence of messages on the CAN bus.
Bitcoin and other digital currencies utilize blockchain. Blockchain, in summary, is a collection of blocks. Within each block is a collection of transactions. Each computer (node) has the same list of blocks and transactions, which they can see as the blocks are filled with the transactions. While this is the traditional application experienced, there are other applications relevant to cybersecurity. As part of the blockchain technology, the nodes are responsible for decision-making. The blockchain technology may be used for this function in these systems. In adjusting the data flow, this is an option to increase the cybersecurity for a complete system. This addition to the cybersecurity system provides a clear benefit.
The advancements of the automotive system in all the aspects from safety to user experience brings never ending list of electronics components into the system. One of the pure critical components in providing the vehicle safety is the digital key or wireless vehicle entry systems. This component is responsible for protecting all the other components of the vehicle and the vehicle itself from thieves and illegal usage of the vehicle. The compromisations of this critical component is equivalent to a compromisations of the entire vehicle along with some legal implications on the vehicle owner. There are numerous additional systems in automotive electronics which enhances the security of the critical, digital key/wireless vehicle entry system in protecting the vehicles from attackers. However, there is no component available in the market which does user/owner authentication considering its impact and criticality on both the vehicle and its owner. Either the lost key or the stolen key in the hands of the illegitimate person who may be an attacker or a thief result in the vehicle theft or the usage of the stolen vehicle for the illegal purposes. These situations cause legal circumstances on the legitimate owner of the vehicle. Hence, in this regard there is a need of user/owner authentication in the existing digital key/wireless vehicle entry systems. The proposed system tries to address this concern by combining the user/owner biometrics with the command passing from the user in-hand device. The proposed system transmits the cryptographically secure combined bio-crypto data from the user in-hand device to the vehicle, where the cryptographic verification if followed by a user verification before proceeding on executing the user requested commands on the vehicle. Upon successful user verification, the respective command actions will be undertaken. Otherwise, the command is considered to be from an illegitimate user using the in-hand device and is discarded. This system also proposes an infrastructure support and mechanism for the user biometric enrollments through Tier-1s and Original Equipment Manufacturers (OEMs).
Items per page:
50
1 – 50 of 148