Runtime Security of Virtualization Platform for Cockpit Domain Controller

Fuente: Zenodo
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Hirano, Ryo, Kishikawa, Takeshi, Ujiie, Yoshihiro, Haga, Tomoyuki, Matsushima, Hideki, Imamoto, Yoshiharu, Yokota, Kaoru, Anzai, Jun
Format: Recurso digital
Langue:anglais
Publié: Zenodo 2022
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866902004843937792
author Hirano, Ryo
Kishikawa, Takeshi
Ujiie, Yoshihiro
Haga, Tomoyuki
Matsushima, Hideki
Imamoto, Yoshiharu
Yokota, Kaoru
Anzai, Jun
author_facet Hirano, Ryo
Kishikawa, Takeshi
Ujiie, Yoshihiro
Haga, Tomoyuki
Matsushima, Hideki
Imamoto, Yoshiharu
Yokota, Kaoru
Anzai, Jun
contents <p>A cockpit domain controller (CDC) has multiple roles, includ-ing instrument cluster panel, infotainment system, and heads-up display. Owing to its advantages, such as reduced development cost and vehicle weight and improved updatability, it has been gaining much attention. In general, CDC is supposed to host multiple virtual machines (VMs) ac-cording to their roles using virtualization technologies, such as hypervi-sors. However, there has been little discussion on the security risks posed by the modifications in the electronic control unit (ECU) architecture us-ing hypervisors. For example, multiple ECUs that were previously con-nected via a physical network could be connected via a virtual network controlled by hypervisors. By exploiting hypercall vulnerabilities, an at-tacker could compromise the virtual network and spread threats among VMs. In this paper, we analyze the security threats to the CDC architec-ture from the perspective of the system lifecycle and show that existing security mechanisms in the infotainment system are inadequate to deal with threats, especially during runtime. To address these challenges, we propose a multi-layered runtime assessment framework based on the root of trust and evaluate its effectiveness against runtime security threats. In development, car manufacturers and suppliers can apply this framework to CDCs to improve security resistance against runtime threats.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_18714517
institution Zenodo
language eng
publishDate 2022
publisher Zenodo
record_format zenodo
spellingShingle Runtime Security of Virtualization Platform for Cockpit Domain Controller
Hirano, Ryo
Kishikawa, Takeshi
Ujiie, Yoshihiro
Haga, Tomoyuki
Matsushima, Hideki
Imamoto, Yoshiharu
Yokota, Kaoru
Anzai, Jun
Cockpit Domain Controller
Threat Analysis
Hypervisor
Inter-VM Communication
Runtime Integrity
<p>A cockpit domain controller (CDC) has multiple roles, includ-ing instrument cluster panel, infotainment system, and heads-up display. Owing to its advantages, such as reduced development cost and vehicle weight and improved updatability, it has been gaining much attention. In general, CDC is supposed to host multiple virtual machines (VMs) ac-cording to their roles using virtualization technologies, such as hypervi-sors. However, there has been little discussion on the security risks posed by the modifications in the electronic control unit (ECU) architecture us-ing hypervisors. For example, multiple ECUs that were previously con-nected via a physical network could be connected via a virtual network controlled by hypervisors. By exploiting hypercall vulnerabilities, an at-tacker could compromise the virtual network and spread threats among VMs. In this paper, we analyze the security threats to the CDC architec-ture from the perspective of the system lifecycle and show that existing security mechanisms in the infotainment system are inadequate to deal with threats, especially during runtime. To address these challenges, we propose a multi-layered runtime assessment framework based on the root of trust and evaluate its effectiveness against runtime security threats. In development, car manufacturers and suppliers can apply this framework to CDCs to improve security resistance against runtime threats.</p>
title Runtime Security of Virtualization Platform for Cockpit Domain Controller
topic Cockpit Domain Controller
Threat Analysis
Hypervisor
Inter-VM Communication
Runtime Integrity
url https://doi.org/10.5281/zenodo.18714517