arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

汽车硬件攻击:架构师的TARA指南

Automotive Hardware Attacks: An Architect's Guide to TARA

Jakub Breier, Xiaolu Hou

arXiv 2610.09697首次发表:更新:

发表机构

TTControl GmbH; Slovak University of Technology(TTControl有限公司; 斯洛伐克理工大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文针对ISO/SAE 21434中TARA对硬件攻击处理不一致的问题,提出硬件感知扩展,包括攻击者模型、路径支配关系、三级硬件相关性门及评级规则,并应用于网关架构和十项真实攻击验证。

AI 中文摘要

根据ISO/SAE 21434标准进行的威胁分析与风险评估(TARA)对实现层面的硬件攻击处理不一致。我们表明,标准中示例的三种攻击可行性方法中有两种在构造上将所有需要物理访问的攻击路径评定为非常低,与实现无关,而第三种方法则可以根据假定的攻击者知识状态和攻击者画像,将同一路径评为四种评级中的任意一种。本文提出了一种硬件感知的TARA扩展,涵盖侧信道分析(SCA)、故障注入攻击(FIA)以及调试和测试接口的滥用。它增加了车辆生命周期内物理访问的攻击者模型;攻击潜力因素上的路径支配关系,用于识别何时更简单的路径使复杂路径变得无关紧要;三级硬件相关性门(H0至H2),带有明确的决策规则,确定硬件步骤的抵抗性是否可以论证、必须记录或必须通过测试证明;以及一个评级规则,在该规则下,硬件步骤在所需证据存在之前不会因实现特定抵抗性而获得信用。该门相对于网络安全保障级别和目标攻击可行性进行定位。该方法应用于参考网关架构,并在十项已发表的汽车组件攻击中检查其结构输入。在十项研究中的七项中,所演示的攻击包括调试、编程、启动、诊断或更新机制,而只有四项研究包括对密码计算的攻击。

英文摘要

Threat analysis and risk assessment (TARA) according to ISO/SAE 21434 treats implementation-level hardware attacks inconsistently. We show that two of the three attack-feasibility approaches exemplified in the standard rate every attack path that requires physical access as very low by construction, independent of the implementation, while the third can assign the same path any of the four ratings, depending on the assumed state of attacker knowledge and on the attacker profile. This paper presents a hardware-aware extension of the TARA that covers side-channel analysis (SCA), fault-injection attacks (FIA), and abuse of debug and test interfaces. It adds an attacker model for physical access over the vehicle lifecycle; a path-dominance relation on the attack-potential factors that identifies when a simpler path makes a sophisticated one irrelevant; a three-level hardware relevance gate (H0 to H2) with an explicit decision rule that fixes whether resistance of a hardware step may be argued, must be documented, or must be demonstrated by test; and a rating rule under which a hardware step receives no credit for implementation-specific resistance until the required evidence exists. The gate is positioned relative to cybersecurity assurance levels and targeted attack feasibility. The method is applied to a reference gateway architecture, and its structural inputs are examined on ten published attacks on automotive components. In seven of the ten studies, the demonstrated attack included a debug, programming, boot, diagnostic, or update mechanism, whereas only four studies included an attack on a cryptographic computation.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑