论文标题
在车辆中安全的时间敏感软件定义的网络
Secure Time-Sensitive Software-Defined Networking in Vehicles
论文作者
论文摘要
未来的车载网络(IVN)的当前设计为切换以太网骨架做准备,该骨架可以托管高级LAN技术,例如IEEE时间敏感网络(TSN)和软件定义的网络(SDN)。在本文中,我们提出了一个集成的时间敏感软件定义的网络(TSSDN)体系结构,同时可以控制所有IVN流量类别的同步和异步实时和最佳实时交流。尽管有中央SDN控制器,但我们可以验证控制可以在不适当映射的情况下对TSN流量进行延迟罚款。我们演示了TSSDN如何可靠地可靠地增强网络通信的网络安全性。对可能的控制流与交换以太网络的可能控制流集成的系统研究表明,这些策略允许塑造软件定义的IVN的攻击表面。我们讨论了控制流识别仪在不同层上的嵌入,涵盖了从完全裸露的映射到深层封装的范围。我们通过实验性地评估了生产工具中的这些策略,并将其映射到现代以太网拓扑。我们的发现表明,较低网络层上汽车控制流的可见性可以使整个网络基础架构的隔离和访问控制。这样的TSSDN主干可以在IVN内建立和调查信任区域,并在各种攻击情况下降低连接汽车的攻击表面。
Current designs of future In-Vehicle Networks (IVN) prepare for switched Ethernet backbones, which can host advanced LAN technologies such as IEEE Time-Sensitive Networking (TSN) and Software-Defined Networking (SDN). In this paper, we present an integrated Time-Sensitive Software-Defined Networking (TSSDN) architecture that simultaneously enables control of synchronous and asynchronous real-time and best-effort communication for all IVN traffic classes. Despite the central SDN controller, we can validate that control can operate without a delay penalty for TSN traffic, provided protocols are properly mapped. We demonstrate how TSSDN adaptably and reliably enhances network security for in-vehicle communication. A systematic investigation of the possible control flow integrations with switched Ether-networks reveals that these strategies allow for shaping the attack surface of a software-defined IVN. We discuss embeddings of control flow identifiers on different layers, covering the range from a fully exposed mapping to deep encapsulation. We experimentally evaluate these strategies in a production vehicle, which we map to a modern Ethernet topology. Our findings indicate that visibility of automotive control flows on lower network layers enables isolation and access control throughout the network infrastructure. Such a TSSDN backbone can establish and survey trust zones within the IVN and reduce the attack surface of connected cars in various attack scenarios.