Requirements for the automated generation of attack trees to support automotive cybersecurity assurance

Although ISO/SAE 21434 recommends the development of an assurance case for cybersecurity, the precise nature of a cybersecurity case is not explicitly defined within the standard. ...In the case of cybersecurity, this problem is exacerbated by the increasing complexity of vehicular onboard systems, their inherent obscurity due to their heterogenous architecture, emergent behaviours, and the disparate motivations and resources of potential threat agents.
Technical Paper

Functional verification and validation of secure controller area network (CAN) communication

In agriculture industry, increasing use of Vehicle Internet of Things (IoT), telematics and emerging technologies are resulting in smarter machines with connected solutions. Inter and Intra Communication with vehicle to vehicle and inside vehicle - Electronic Control Unit (ECU) to ECU or ECU to sensor, requirement for flow of data increased in-turn resulting in increased need for secure communication. In this paper, we focus on functional verification and validation of secure Controller Area Network (CAN) for intra vehicular communication to establish confidentiality, integrity, authenticity, and freshness of data, supporting safety, advanced automation, protection of sensitive data and IP (Intellectual Property) protection. Network security algorithms and software security processes are the layers supporting to achieve our cause. Test environment setup with secured hardware and simulated models, test scenarios and test data created to achieve our objective.
Technical Paper

Integrating Fuzz Testing into a CI Pipeline for Automotive Systems

With the rapid development of connected and autonomous vehicles, more sophisticated automotive systems running large portions of software and implementing a variety of communication interfaces are being developed. The ever-expanding codebase increases the risk for software vulnerabilities, while at the same time the large number of communication interfaces make the systems more susceptible to be targeted by attackers. As such, it is of utmost importance for automotive organizations to identify potential vulnerabilities early and continuously in the development lifecycle in an automated manner. In this paper, we suggest a practical approach for integrating fuzz testing into a Continuous Integration (CI) pipeline for automotive systems. As a first step, we have performed a Threat Analysis and Risk Assessment (TARA) of a general E/E architecture to identify high-risk interfaces and functions.
Research Report

Unsettled Issues Concerning Automated Driving Services in the Smart City Infrastructure

Information and communication technology is fundamentally changing the way we live and operate in cities, such as instant access to events, transportation, bookings, payments, and other services. At the same time, three “megatrends” in the automotive industry—self-driving, electrification, and advanced manufacturing technology—are enabling the design of innovative, application-specific vehicles that capitalize on city connectivity. Applications could countless; however, they also need to be safe and securely integrated into a city’s physical and digital infrastructure, and into the overall urban ecosystem. Unsettled Issues Concerning Automated Driving Services in the Smart City Infrastructure examines the current state of the industry, the developments in automated driving and robotics, and how these new urban, self-driving city applications are different. It also analyzes higher level challenges for urban applications.
Technical Paper

Designing a Next Generation Trailer Braking System

Passenger vehicles have made astounding technological leaps in recent years. Unfortunately, little of that progress has trickled down to other segments of the transportation industry leaving opportunities for massive gains in safety and performance. In particular, the electric drum brakes on most consumer trailers differ little from those on trailers over 70 years ago. Careful examination of current production passenger vehicle hardware and trailering provided the opportunity to produce a design and test vehicle for a plausible, practical, and performant trailer braking system for the future. This study equips the trailer with high control frequency antilock braking and dynamic torque distribution through use of passenger vehicle grade apply hardware.
Research Report

Unsettled Legal Issues Facing Data in Autonomous, Connected, Electric, and Shared Vehicles

Modern automobiles collect around 25 gigabytes of data per hour and autonomous vehicles are expected to generate more than 100 times that number. In comparison, the Apollo Guidance Computer assisting in the moon launches had only a 32-kilobtye hard disk. Without question, the breadth of in-vehicle data has opened new possibilities and challenges. The potential for accessing this data has led many entrepreneurs to claim that data is more valuable than even the vehicle itself. These intrepid data-miners seek to explore business opportunities in predictive maintenance, pay-as-you-drive features, and infrastructure services. Yet, the use of data comes with inherent challenges: accessibility, ownership, security, and privacy. Unsettled Legal Issues Facing Data in Autonomous, Connected, Electric, and Shared Vehicles examines some of the pressing questions on the minds of both industry and consumers. Who owns the data and how can it be used?
Technical Paper

A Controller Area Network Bus Identity Authentication Method Based on Hash Algorithm

With the development of vehicle intelligence and the Internet of Vehicles, how to protect the safety of the vehicle network system has become a focus issue that needs to be solved urgently. The Controller Area Network (CAN) bus is currently a very widely used vehicle-mounted bus, and its security largely determines the degree of vehicle-mounted information security. The CAN bus lacks adequate protection mechanisms and is vulnerable to external attacks such as replay attacks, modifying attacks, and so on. On the basis of the existing work, this paper proposes an authentication method that combines Hash-based Message Authentication Code (HMAC)-SHA256 and Tiny Encryption Algorithm (TEA) algorithms. This method is based on dynamic identity authentication in challenge/response made and combined with the characteristics of the CAN bus itself as it achieves the identity authentication between the gateway and multiple electronic control units (ECUs).
Technical Paper

It Takes a Village: A Case Study of Business Development and Innovation in a UAS/AUS Ecosystem to Address Critical Industry Challenges

Entrepreneurial innovation that spurs economic development requires a collaborative cluster of cooperative effort, across a diverse ecosystem of partners. Literature provides resounding evidence to support the notion that an innovative, entrepreneurial ecosystem is critical to both successful economic development and industry sector growth. The UAS/AUS industry sector is a fast-growing sector across the United States, with regional leadership demonstrated in North Dakota, California, North Carolina, New York, Oklahoma, Texas and New Mexico. This case study is focused on investigating how the North Dakota autonomous systems ecosystem continues to evolves and develop mechanisms and partnerships to address industry pain points, facilitate cutting edge research, ensure high-quality UAS/AUS testing, and support an adaptive business development pipeline across the entrepreneurial life cycle.
Technical Paper

Safe Operations at Roadway Junctions - Design Principles from Automated Guideway Transit

This paper describes a system-level view of a fully automated transit system comprising a fleet of automated vehicles (AVs) in driverless operation, each with an SAE level 4 Automated Driving System, along with its related safety infrastructure and other system equipment. This AV system-level control is compared to the automatic train control system used in automated guideway transit technology, particularly that of communications-based train control (CBTC). Drawing from the safety principles, analysis methods, and risk assessments of CBTC systems, comparable functional subsystem definitions are proposed for AV fleets in driverless operation. With the prospect of multiple AV fleets operating within a single automated mobility district, the criticality of protecting roadway junctions requires an approach like that of automated fixed-guideway transit systems, in which a guideway switch zone “interlocking” at each junction location deconflicts railway traffic, affirming safe passage.
Research Report

Unsettled Issues Regarding Autonomous Vehicles and Open-source Software

Unsettled Issues Regarding Autonomous Vehicles and Open-source Software introduces the impact of software in advanced automotive applications, the role of open-source communities in accelerating innovation, and the important topic of safety and cybersecurity. As electronic functionality is captured in software and a bigger percentage of that software is open-source code, some critical challenges arise concerning security and validation.
Technical Paper

Vehicular Visual Sensor Blinding Detection by Integrating Variational Autoencoders with SVM

The advancements of autonomous vehicles or advanced driver assistance systems in terms of safety, driving experience, and comfort against manual driving results in extensive adoption of them across the modern automotive sector. The autonomous vehicles are equipped with numerous sensing and actuating components both inside as well as outside the vehicles to perceive the environment, perform path planning, and intelligently control the autonomous vehicles. The perception mechanism includes fused information of multiple sensors such as camera, RADAR, and LiDAR to effectively understand all the dynamic driving environments. Some of the intentional and unintentional mechanisms such as cyber-attacks and natural variations of the environment, etc., across the sensor's external interface with the environment cause the degradation of the perception mechanism.
Technical Paper

Adopting Aviation Safety Knowledge into the Discussions of Safe Implementation of Connected and Autonomous Road Vehicles

The development of connected and autonomous vehicles (CAVs) is progressing fast. Yet, safety and standardization-related discussions are limited due to the recent nature of the sector. Despite the effort that is initiated to kick-start the study, awareness among practitioners is still low. Hence, further effort is required to stimulate this discussion. Among the available works on CAV safety, some of them take inspiration from the aviation sector that has strict safety regulations. The underlying reason is the experience that has been gained over the decades. However, the literature still lacks a thorough association between automation in aviation and the CAV from the safety perspective. As such, this paper motivates the adoption of safe-automation knowledge from aviation to facilitate safer CAV systems.
Journal Article

Implementation Methodologies for Simulation as a Service (SaaS) to Develop ADAS Applications

Over the years, the complexity of autonomous vehicle development (and concurrently the verification and validation) has grown tremendously in terms of component-, subsystem- and system-level interactions between autonomy and the human users. Simulation-based testing holds significant promise in helping to identify both problematic interactions between component-, subsystem-, and system-levels as well as overcoming delays typically introduced by the default full-scale on-road testing. Software in Loop (SiL) simulation is utilized as an intermediate step towards software deployment for autonomous vehicles (AV) to make them reliable. SiL efforts can help reduce the resources required for successful deployment by helping to validate the software for millions of road miles. A key enabler for accelerating SiL processes is the ability to use Simulation as a Service (SaaS) rather than just isolated instances of software.
Journal Article

Using Delphi and System Dynamics for IoT Cybersecurity: Preliminary Airport Implications

Day by day, airports adopt more IoT devices. However, airports are not exempt from possible failures due to malware’s proliferation that can abuse vulnerabilities. Computer criminals can access, corrupt, and extract information from individuals or companies. This paper explains the development of a propagation model, which started with a Delphi process. We discuss the preliminary implications for airports of the simulation model built from the Delphi recommendations.
Technical Paper

Technical Trends of the Intelligent Connected Vehicle and Development Stage Division for Freeway Traffic Control

It is deemed that currently the intelligent connected vehicle (ICV) is in its early stage of development, and it will go through multiple development stages in the future to realize its final goal—autonomous driving. Based on the existing ICV researches, this paper believes that ICV can be used to improve the efficiency and safety of freeway. The current research of ICV has two main directions: one focuses on the traffic flow characteristics of vehicles with different attributes, the other is concerned with using ICV to reduce congestion. From the policies issued by countries around the world and the development plans promoted by major vehicle manufacturers, the future development trends and challenges of ICV are analyzed. ICV must overcome all the shortcomings to achieve its final goal, including insufficient hardware capabilities or excessive cost, and the degree of intelligence that needs to be improved.
Technical Paper

Service Analysis of Autonomous Driving

Autonomous driving represents the ultimate goal of future automobile development. As a collaborative application that integrates vehicles, road infrastructure, network and cloud, autonomous driving business requires a high-degree dynamic cooperation among multiple resources such as data, computing and communications that are distributed throughout the system. In order to meet the anticipated high demand for resources and performance requirements of autonomous driving, and to ensure the safety and comfort of the vehicle users and pedestrians, a top concern of autonomous driving is to understand the system requirements for resources and conduct an in-depth analysis of the autonomous driving business. In this context, this paper presents a comprehensive analysis of the typical business for autonomous driving and establishes an analysis model for five common capabilities, i.e. collection, transmission, intelligent computing, human-machine interaction (HMI), and security.
Research Report

Unsettled Topics Concerning Human and Autonomous Vehicle Interaction

This report examines the current interaction points between humans and autonomous systems, with a particular focus on advanced driver assistance systems (ADAS), the requirements for human-machine interfaces as imposed by human perception, and finally, the progress being made to close the gap. Autonomous technology has the potential to benefit personal transportation, last-mile delivery, logistics, and many other mobility applications enormously. In many of these applications, the mobility infrastructure is a shared resource in which all the players must cooperate. In fact, the driving task has been described as a “tango” where we—as humans—cooperate naturally to enable a robust transportation system. Can autonomous systems participate in this tango? Does that even make sense? And if so, how do we make it happen? Click here to access the full SAE EDGETM Research Report portfolio.
Research Report

Unsettled Topics Concerning Autonomous Public Transportation Systems

With billions of dollars of investment and events like DARPA’s Grand Challenges automated driving technology has been making its way toward commercialization. While the enabling technology for SAE Level 4 and 5 automated vehicles (AV) has not yet matured, specific restricted-use models such as “robo-taxis” and automated truck convoying show great promise. Now, cities are across the world are looking to AVs to solve their public transportation issues. With low speeds and fixed route, public transportation is an ideal application for AVs. From a business angle, AVs could leverage existing public transport models and infrastructure while providing superior quality of service for disadvantaged communities. Yet, dense urban environments—which would benefit from automated transportation the most—present unique challenges and public sector requirements. This SAE EDGE™ Research Report by Dr.
Research Report

Unsettled Topics in the Application of Satellite Navigation to Air Traffic Management

Contemporary air traffic management (ATM) challenges are both (1) acute and (2) growing at rates far outpacing established ways for absorbing technological innovation. Lack of timely response will guarantee failure to meet demands. Immediately that creates a necessity to identify means of coping and judging new technologies based on possible speed of adoption. Paralleling the challenges are developments in capability, both recent and decades old. Some steps (e.g., Global Positioning System (GPS) backup) are well known and, in fact, should have progressed further long ago. Others (e.g., sharing raw measurements instead of position fixes) are equally well known and, if followed by further flight tests initiated (and successful) years ago, would have produced a wealth of in-flight experience by now if development had continued. Other possibilities (e.g., automated pilot override) are much less common and are considered largely experimental.
Journal Article

A Novel Assessment and Administration Method of Autonomous Vehicle

As a promising strategic industry group that is rapidly evolving around the world, autonomous vehicle is entering a critical phase of commercialization from demonstration to end markets. The global automotive industry and governments are facing new common topics and challenges brought by autonomous vehicle, such as how to test, assess, and administrate the autonomous vehicle to ensure their safe running in real traffic situations and proper interactions with other road users. Starting from the facts that the way to autonomous driving is the process of a robot or a machine taking over driving tasks from a human. This paper summarizes the main characteristics of autonomous vehicle which are different from traditional one, then demonstrates the limitations of the existing certification mechanism and related testing methods when applied to autonomous vehicle.