<div class="csl-bib-body">
<div class="csl-entry">Maragkou, S., Grammatikakis, M., Papatheodorou, N., & Jantsch, A. (2025). Secure Authentication in the Presence of Malicious Messages and Packet Reorders: Study on CAN Bus. In <i>2025 IEEE 15th Annual Computing and Communication Workshop and Conference (CCWC)</i> (pp. 952–959). https://doi.org/10.1109/CCWC62904.2025.10903953</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/217088
-
dc.description.abstract
Message authentication is fundamental for securing modern automotive networks. Our work focuses on integrating buffering in existing authentication protocols to sustain the presence of malicious or corrupt messages, and arbitrary packet swaps in the in-vehicle network. The proposed extension applies to the popular vatiCAN protocol, and other CAN bus authentication protocols, which use separate messages for transferring packet information and authentication data. The proposed extension uses one or more, independent Finite State Machines (FSMs) at each receiver node to temporarily store and subsequently validate message pairs, i.e., a legitimate data packet L with its hashed-based message authentication code (HMAC) packet H. The proposed methodology is evaluated experimentally on a Raspberry Pi-based Electronic Control Unit (ECU) with CAN interfaces. We examine key design parameters, such as the LH swap rate, the malicious rate, and queue configuration options, such as the queue size and flush policy. Results show that the protocol extension improves authentication. When the queue size is below 5, the LH swap rate is up to 50%, and 50% of malicious packets are introduced, the validated packet rate is low (5%). However, if the queue size exceeds 20, the verified packet rate reaches 100%, regardless of other parameters. The increased queue size has a minimal effect on latency, which increases by a few ms on average, and on false positives, which remain below 10-9. Statistical models help evaluate queue size bounds for worst-case scenarios, strengthening our experimental findings.
en
dc.language.iso
en
-
dc.subject
automotive security
en
dc.subject
CAN bus
en
dc.subject
FSM
en
dc.subject
hash-based authentication
en
dc.subject
in-vehicle networks
en
dc.subject
reliability
en
dc.title
Secure Authentication in the Presence of Malicious Messages and Packet Reorders: Study on CAN Bus
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.contributor.affiliation
Hellenic Mediterranean University, Greece
-
dc.relation.isbn
9798331507695
-
dc.relation.doi
10.1109/CCWC62904.2025
-
dc.description.startpage
952
-
dc.description.endpage
959
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
2025 IEEE 15th Annual Computing and Communication Workshop and Conference (CCWC)
-
tuw.peerreviewed
true
-
tuw.researchTopic.id
I7
-
tuw.researchTopic.id
I2
-
tuw.researchTopic.name
Telecommunication
-
tuw.researchTopic.name
Computer Engineering and Software-Intensive Systems
-
tuw.researchTopic.value
50
-
tuw.researchTopic.value
50
-
tuw.publication.orgunit
E384-01 - Forschungsbereich Software-intensive Systems
-
tuw.publication.orgunit
E056-10 - Fachbereich SecInt-Secure and Intelligent Human-Centric Digital Technologies
-
tuw.publication.orgunit
E056-16 - Fachbereich SafeSeclab
-
tuw.publisher.doi
10.1109/CCWC62904.2025.10903953
-
dc.description.numberOfPages
8
-
tuw.author.orcid
0000-0001-6823-4223
-
tuw.author.orcid
0000-0002-8746-4232
-
tuw.author.orcid
0000-0001-8396-1023
-
tuw.author.orcid
0000-0003-2251-0004
-
tuw.event.name
2025 IEEE 15th Annual Computing and Communication Workshop and Conference (CCWC)
en
tuw.event.startdate
06-01-2025
-
tuw.event.enddate
08-01-2025
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
Las Vegas, Nevada
-
tuw.event.country
US
-
tuw.event.presenter
Maragkou, Sofia
-
wb.sciencebranch
Elektrotechnik, Elektronik, Informationstechnik
-
wb.sciencebranch.oefos
2020
-
wb.sciencebranch.value
100
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.grantfulltext
restricted
-
item.cerifentitytype
Publications
-
item.languageiso639-1
en
-
item.fulltext
no Fulltext
-
item.openairetype
conference paper
-
crisitem.author.dept
E384-01 - Forschungsbereich Software-intensive Systems